Communication method and apparatus, user equipment, base station, and storage medium
By encrypting the NCC of the RRC re-establishment message during the RRC re-establishment process, the problem that the UE cannot update the key is solved, the security of the RRC re-establishment message is improved, and the integrity and encryption of the communication process are ensured.
Patent Information
- Application Number
- PCT/CN2025/071569
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-01-12
- Filing Date
- 2025-01-09
- Publication Date
- 2025-07-17
AI Technical Summary
During the RRC re-establishment process, the security of RRC re-establishment messages is low because the UE cannot obtain the next jump link count (NCC) under the message encryption, resulting in the key update failure.
After the UE sends an RRC re-establishment request message to the base station, the base station sends a first MAC CE including the NCC and the encrypted RRC re-establishment message to ensure that the UE can update the key and improve message security.
By encrypting the NCC in the RRC re-establishment message, the UE can successfully update the key, improving the security of the RRC re-establishment message and ensuring the integrity and encryption of the communication process.
Smart Images

Figure CN2025071569_17072025_PF_FP_ABST
Abstract
Description
Communication method, device, user equipment, base station and storage medium
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims priority to Chinese patent application number 202410052512.6 filed in China on January 12, 2024, the entire contents of which are incorporated herein by reference. Technical Field
[0003] The present application belongs to the field of communication technology, and specifically relates to a communication method, device, user equipment, base station and storage medium. Background Art
[0004] Currently, user equipment (UE) and base stations update the keys used during the radio resource control (RRC) re-establishment process. Specifically, on the UE side, the UE can receive an RRC re-establishment message sent by the base station. The RRC re-establishment message carries a next hop chaining count (NCC). The UE can update the keys used by the UE based on the NCC carried in the RRC re-establishment message. Since the UE needs to use the NCC to update the keys, the RRC re-establishment message sent by the base station cannot be encrypted. If it is encrypted, the UE cannot obtain the NCC and thus cannot update the keys used. As a result, the security of the RRC re-establishment message is relatively low. Therefore, how to improve the security of the RRC re-establishment message is an urgent problem to be solved in this application. Summary of the Invention
[0005] Embodiments of the present application provide a communication method, apparatus, user equipment, base station, and storage medium, which can improve the security of RRC re-establishment messages.
[0006] In a first aspect, a communication method is provided, the method comprising: a UE sends an RRC re-establishment request message to a base station; a medium access control (MAC) layer of the UE receives a first medium access control element (MAC Control Element, MAC CE) from the base station; wherein the first MAC CE includes an NCC and a first byte stream, the first byte stream includes an encrypted RRC re-establishment message, and the RRC re-establishment message is used to instruct the UE to re-establish an RRC connection.
[0007] In a second aspect, a communication method is provided, which includes: a base station receives an RRC re-establishment request message from a UE; a MAC layer of the base station sends a first MAC CE to the UE; wherein the first MAC CE includes an NCC and a first byte stream, the first byte stream includes an encrypted RRC re-establishment message, and the RRC re-establishment message is used to instruct the UE to re-establish the RRC connection.
[0008] In a third aspect, a communication method is provided, which includes: a UE sends an RRC re-establishment request message to a base station; the UE receives a first signaling from the base station, the first signaling being used to request the UE to update the key used by the UE, the first signaling including an NCC, and the first signaling being a second MAC CE or a PDCP control PDU; the RRC layer of the UE updates the key used by the UE based on the NCC, and generates a first encryption key and a first integrity protection key based on the updated key; the RRC layer of the UE instructs the Packet Data Convergence Protocol (PDCP) layer of the UE to use the first encryption key and the first integrity protection key to restore integrity protection and encryption; after the PDCP layer of the UE uses the first encryption key and the first integrity protection key to restore integrity protection and encryption, the PDCP layer of the UE processes a second PDCP Protocol Data Unit (PDU) from the base station, the second PDCP PDU including an integrity-protected and encrypted RRC re-establishment message, and the RRC re-establishment message is used to instruct the UE to re-establish the RRC connection.
[0009] In a fourth aspect, a communication method is provided, which includes: a base station receives an RRC re-establishment request message from a UE; the base station sends a first signaling to the UE, the first signaling being used to request the UE to update the key used by the UE, the first signaling including an NCC, and the first signaling being a second MAC CE or a PDCP control PDU; the base station sends a second PDCP PDU to the UE, the second PDCP PDU including an integrity-protected and encrypted RRC re-establishment message, and the RRC re-establishment message being used to instruct the UE to re-establish the RRC connection.
[0010] In a fifth aspect, a communications device is provided, applied to a UE, the device comprising: a transmitting module and a receiving module. The transmitting module is configured to transmit an RRC re-establishment request message to a base station. The receiving module is configured to receive a first MAC CE from the base station; the first MAC CE includes an NCC and a first byte stream, the first byte stream including an encrypted RRC re-establishment message, and the RRC re-establishment message is configured to instruct the UE to re-establish an RRC connection.
[0011] In a sixth aspect, a communications device is provided, applied to a base station, the device comprising: a receiving module and a sending module. The receiving module is configured to receive an RRC re-establishment request message from a UE. The sending module is configured to send a first MAC CE to the UE; wherein the first MAC CE includes an NCC and a first byte stream, the first byte stream including an encrypted RRC re-establishment message, and the RRC re-establishment message is used to instruct the UE to re-establish an RRC connection.
[0012] In the seventh aspect, a communication device is provided, which is applied to a UE. The device includes: a sending module, a receiving module, a processing module and an indication module. The sending module is used to send an RRC re-establishment request message to the base station. The receiving module is used to receive a first signaling from the base station, the first signaling is used to request the UE to update the key used by the UE, the first signaling includes an NCC, and the first signaling is a second MAC CE or a PDCP control PDU. The processing module is used to update the key used by the UE based on the NCC, and generate a first encryption key and a first integrity protection key based on the updated key. The request module is used to instruct the PDCP layer of the UE to use the first encryption key and the first integrity protection key generated by the processing module to restore integrity protection and encryption. The processing module is also used to process a second PDCP PDU from the base station after the PDCP layer of the UE uses the first encryption key and the first integrity protection key to restore integrity protection and encryption. The second PDCP PDU includes an integrity-protected and encrypted RRC re-establishment message, and the RRC re-establishment message is used to instruct the UE to re-establish the RRC connection.
[0013] In an eighth aspect, a communications device is provided, comprising: a receiving module and a sending module. The receiving module is configured to receive an RRC re-establishment request message from a UE. The sending module is configured to send a first signaling to the UE, the first signaling being configured to request the UE to update a key used by the UE, the first signaling including an NCC, the first signaling being a second MAC CE or a PDCP control PDU; and to send a second PDCP PDU to the UE, the second PDCP PDU including an integrity-protected and encrypted RRC re-establishment message, the RRC re-establishment message being configured to instruct the UE to re-establish an RRC connection.
[0014] In a ninth aspect, a UE is provided, which includes a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the program or instructions are executed by the processor, the steps of the method described in the first aspect are implemented.
[0015] In the tenth aspect, a UE is provided, including a processor and a communication interface, wherein the communication interface is used to send an RRC re-establishment request message to a base station; and receive a first MAC CE from the base station; wherein the first MAC CE includes an NCC and a first byte stream, the first byte stream includes an encrypted RRC re-establishment message, and the RRC re-establishment message is used to instruct the UE to re-establish the RRC connection.
[0016] In the eleventh aspect, a base station is provided, which includes a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the program or instructions are executed by the processor, the steps of the method described in the second aspect are implemented.
[0017] In the twelfth aspect, a base station is provided, including a processor and a communication interface, wherein the communication interface is used to receive an RRC re-establishment request message from a UE; and send a first MAC CE to the UE; wherein the first MAC CE includes an NCC and a first byte stream, the first byte stream includes an encrypted RRC re-establishment message, and the RRC re-establishment message is used to instruct the UE to re-establish the RRC connection.
[0018] In the thirteenth aspect, a UE is provided, which includes a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the program or instructions are executed by the processor, the steps of the method described in the third aspect are implemented.
[0019] In the fourteenth aspect, a UE is provided, including a processor and a communication interface, wherein the communication interface is used to send an RRC re-establishment request message to a base station; and receive a first signaling from the base station, the first signaling being used to request the UE to update the key used by the UE, the first signaling including the NCC, and the first signaling being a second MAC CE or a PDCP control PDU; the processor is used to update the key used by the UE based on the NCC, and generate a first encryption key and a first integrity protection key based on the updated key; and instruct the PDCP layer of the UE to use the first encryption key and the first integrity protection key to restore integrity protection and encryption; and after the PDCP layer of the UE uses the first encryption key and the first integrity protection key to restore integrity protection and encryption, process a second PDCP PDU from the base station, the second PDCP PDU including an integrity-protected and encrypted RRC re-establishment message, the RRC re-establishment message being used to instruct the UE to re-establish the RRC connection.
[0020] In the fifteenth aspect, a base station is provided, which includes a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the program or instructions are executed by the processor, the steps of the method described in the fourth aspect are implemented.
[0021] In the sixteenth aspect, a base station is provided, including a processor and a communication interface, wherein the communication interface is used to receive an RRC re-establishment request message from a UE; and send a first signaling to the UE, the first signaling being used to request the UE to update the key used by the UE, the first signaling including an NCC, the first signaling being a second MAC CE or a PDCP control PDU; and send a second PDCP PDU to the UE, the second PDCP PDU including an integrity-protected and encrypted RRC re-establishment message, the RRC re-establishment message being used to instruct the UE to re-establish the RRC connection.
[0022] In the seventeenth aspect, a readable storage medium is provided, on which a program or instruction is stored. When the program or instruction is executed by a processor, the steps of the method described in the first aspect are implemented, or the steps of the method described in the second aspect are implemented, or the steps of the method described in the third aspect are implemented, or the steps of the method described in the fourth aspect are implemented.
[0023] In aspect 18, a wireless communication system is provided, including: a UE and a base station, wherein the UE can be used to execute the steps of the method described in aspect 1, or execute the steps of the method described in aspect 3, and the base station can be used to execute the steps of the method described in aspect 2, or execute the steps of the method described in aspect 4.
[0024] In the nineteenth aspect, a chip is provided, comprising a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the method as described in the first aspect, or the method as described in the second aspect, or the method as described in the third aspect, or the method as described in the fourth aspect.
[0025] In the twentieth aspect, a computer program / program product is provided, which is stored in a storage medium, and the program / program product is executed by at least one processor to implement the steps of the communication method described in the first aspect, or the steps of the communication method described in the second aspect, or the steps of the communication method described in the third aspect, or the steps of the communication method described in the fourth aspect.
[0026] In an embodiment of the present application, a UE sends an RRC re-establishment request message to a base station; the UE's medium access control (MAC) layer receives a first media access control element (MAC CE) from the base station; wherein the first MAC CE includes an NCC and a first byte stream, the first byte stream includes an encrypted RRC re-establishment message, and the RRC re-establishment message is used to instruct the UE to re-establish an RRC connection. In this solution, after the UE sends the RRC re-establishment request message to the base station, the base station can send a first MAC CE including an NCC and a first byte stream to the UE, and the first byte stream includes an encrypted RRC re-establishment message, that is, the base station can carry the NCC outside the encrypted RRC re-establishment message. Therefore, while the UE obtains the NCC update key, the security of the RRC re-establishment message is also improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] FIG1 is a schematic diagram of the architecture of a wireless communication system provided in an embodiment of the present application;
[0028] FIG2 is a flow chart of a communication method according to an embodiment of the present application;
[0029] FIG3 is a second flow chart of a communication method provided in an embodiment of the present application;
[0030] FIG4 is a structural diagram of a first MAC CE provided in an embodiment of the present application;
[0031] FIG5 is a schematic structural diagram of a first PDCP PDU provided in an embodiment of the present application;
[0032] FIG6 is a second structural diagram of a first MAC CE provided in an embodiment of the present application;
[0033] FIG7 is a third flow chart of a communication method provided in an embodiment of the present application;
[0034] FIG8 is a schematic diagram of a structure of a communication device according to an embodiment of the present application;
[0035] FIG9 is a second structural diagram of a communication device provided in an embodiment of the present application;
[0036] FIG10 is a fourth flow chart of a communication method provided in an embodiment of the present application;
[0037] FIG11 is a fifth flow chart of a communication method provided in an embodiment of the present application;
[0038] FIG12 is a schematic structural diagram of a PDCP control PDU provided in an embodiment of the present application;
[0039] FIG13 is a sixth flow chart of a communication method provided in an embodiment of the present application;
[0040] FIG14 is a seventh flow chart of a communication method provided in an embodiment of the present application;
[0041] FIG15 is a third structural diagram of a communication device provided in an embodiment of the present application;
[0042] FIG16 is a fourth structural diagram of a communication device provided in an embodiment of the present application;
[0043] FIG17 is a schematic diagram of the hardware structure of a communication device provided in an embodiment of the present application;
[0044] FIG18 is a schematic diagram of the hardware structure of a UE provided in an embodiment of the present application;
[0045] Figure 19 is a schematic diagram of the hardware structure of a base station provided in an embodiment of the present application. DETAILED DESCRIPTION
[0046] The following will be combined with the accompanying drawings in the embodiments of this application to clearly describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field are within the scope of protection of this application.
[0047] The terms "first", "second", etc. in this application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the terms used in this way are interchangeable where appropriate, so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first" and "second" are generally of the same type, and do not limit the number of objects, for example, the first object can be one or more. In addition, "or" in this application represents at least one of the connected objects. For example, "A or B" covers three options, namely, Option 1: including A but not including B; Option 2: including B but not including A; Option 3: including both A and B. The character " / " generally indicates that the objects associated before and after are in an "or" relationship.
[0048] The term "indication" in this application can be either a direct indication (or explicit indication) or an indirect indication (or implicit indication). A direct indication can be understood as the sender explicitly informing the receiver of specific information, the operation to be performed, or the requested result, etc. in the instruction sent; an indirect indication can be understood as the receiver determining the corresponding information based on the instruction sent by the sender, or making a judgment and determining the operation to be performed or the requested result, etc. based on the judgment result.
[0049] The terms "at least one" and "at least one of" in this application refer to any one, any two, or a combination of more than two of the objects included. For example, at least one of a, b, and c can be represented by: "a", "b", "c", "a and b", "a and c", "b and c", and "a, b, and c", where a, b, and c can be single or multiple. Similarly, "at least two" means two or more, and its meaning is similar to "at least one".
[0050] It is worth noting that the technology described in the embodiments of the present application is not limited to the Long Term Evolution (LTE) / LTE-Advanced (LTE-A) system, but can also be used in other wireless communication systems, such as Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single-carrier Frequency Division Multiple Access (SC-FDMA) or other systems. The terms "system" and "network" in the embodiments of the present application are often used interchangeably, and the described technology can be used for the systems and radio technologies mentioned above, as well as for other systems and radio technologies. The following description describes a New Radio (NR) system for example purposes, and NR terminology is used in most of the following description, but these technologies can also be applied to systems other than NR systems, such as 6th Generation (6G) communication systems.
[0051] FIG1 shows a block diagram of a wireless communication system applicable to an embodiment of the present application. The wireless communication system includes a terminal 11 and a network-side device 12. The terminal 11 may be a UE, a mobile phone, a tablet computer (Tablet Personal Computer), a laptop computer (Laptop Computer), a notebook computer, a personal digital assistant (PDA), a handheld computer, a netbook, an ultra-mobile personal computer (UMPC), a mobile internet device (MID), an augmented reality (AR), a virtual reality (VR) device, a robot, a wearable device, an aircraft (flight vehicle), a vehicle user equipment (VUE), a ship-borne device, a pedestrian user equipment (PUE), a smart home (home appliances with wireless communication capabilities, such as refrigerators, televisions, washing machines, or furniture), a game console, a personal computer (PC), a teller machine, or a self-service machine, or other terminal-side devices. Wearable devices include: smart watches, smart bracelets, smart headphones, smart glasses, smart jewelry (smart bracelets, smart bracelets, smart rings, smart necklaces, smart anklets, smart anklets, etc.), smart wristbands, smart clothing, etc. Among them, the vehicle-mounted device can also be called a vehicle-mounted terminal, a vehicle-mounted controller, a vehicle-mounted module, a vehicle-mounted component, a vehicle-mounted chip or a vehicle-mounted unit, etc. It should be noted that the specific type of the terminal 11 is not limited in the embodiment of the present application. The network side device 12 may include an access network device or a core network device, wherein the access network device may also be called a radio access network (Radio Access Network, RAN) device, a radio access network function or a radio access network unit. The access network device may include a base station, a wireless local area network (Wireless Local Area Network, WLAN) access point (Access Point, AP) or a wireless fidelity (Wireless Fidelity, WiFi) node, etc.Among them, the base station can be referred to as Node B (NB), Evolved Node B (eNB), the next generation Node B (gNB), New Radio Node B (NR Node B), access point, Relay Base Station (RBS), Serving Base Station (SBS), Base Transceiver Station (BTS), radio base station, radio transceiver, Basic Service Set (BSS), Extended Service Set (ESS), Home Node B (HNB), Home evolved Node B (home evolved Node B), Transmission Reception Point (TRP) or other appropriate terms in the relevant field. As long as the same technical effect is achieved, the base station is not limited to specific technical vocabulary. It should be noted that in the embodiment of the present application, only the base station in the NR system is used as an example for introduction, and the specific type of the base station is not limited.
[0052] The following is an explanation of some concepts and / or terms involved in the communication method provided in the embodiments of the present application.
[0053] 1. RRC re-establishment: When the UE is in the RRC connected state, but a radio link failure or integrity check failure occurs, the UE can perform a cell selection process to select a target cell to initiate the RRC re-establishment process and send an RRC Reestablishment Request to the base station where the target cell is located through SRB0.
[0054] 2. Radio interface control plane protocol stack: The radio interface control plane protocol stack is from top to bottom: RRC layer, PDCP layer, RLC layer, MAC layer and PHY layer.
[0055] 3. The PDUs at the PDCP layer are divided into two types: Data PDUs and Control PDUs. The Data PDU is used to transmit user and control plane data, as well as the digitally signed MAC-I for integrity protection. The Control PDU is generated by the PDCP layer itself and is used to transmit, for example, PDCP status reports and decompression feedback messages generated by the compression / decompression module. The data packets received by the PDCP layer from the upper layer are called PDCP Service Data Units (SDUs). The PDCP layer processes them to generate PDCP Data PDUs, which are then passed to the next layer for processing.
[0056] The communication method provided in the embodiments of the present application is described in detail below through some embodiments and their application scenarios in conjunction with the accompanying drawings.
[0057] Currently, the UE and the base station update the keys used during the RRC re-establishment process. Specifically, on the UE side, the UE can receive an RRC re-establishment message sent by the base station, which carries the NCC. The UE can then update the keys used by the UE based on the NCC carried in the RRC re-establishment message. Since the UE needs the NCC to update the keys, the RRC re-establishment message sent by the base station cannot be encrypted. If it is encrypted, the UE cannot obtain the NCC and thus cannot update the keys used. Specifically, on the base station side, if the NCC corresponding to the current key is the same as the NCC stored in the UE context of the UE, the key is updated based on the current key. Otherwise, the key is updated based on the next hop (NH) corresponding to the NCC stored in the UE context of the UE. The encryption key and integrity protection key are generated based on the updated key, and the PDCP layer is configured to resume integrity protection using the new integrity protection key. The NCC and its corresponding NH stored in the UE context may be those sent to the base station by the core network during the last handover process. The RRC layer generates an RRC message, RRC Reestablishment. The RRC Reestablishment message carries the NCC and is delivered as a PDCP SDU to the PDCP entity corresponding to SRB1. The PDCP entity uses the new integrity protection key for integrity protection, but does not perform encryption. It then generates a PDCP PDU and delivers the generated PDCP PDU to the Radio Link Control (RLC) layer for transmission to the UE. It can be seen that the RRC Reestablishment message is integrity protected but not encrypted. Furthermore, the base station configures the PDCP layer to resume encryption using the new encryption key. On the UE side, after receiving the RRC Reestablishment message, the UE generates new encryption and integrity protection keys based on the NCC update key carried in the message, and then requests the PDCP layer to verify the message based on the new integrity protection key. If the verification is successful, the PDCP layer is configured to resume integrity protection and encryption using the new integrity protection and encryption keys. It can be seen that because the UE needs to use the NCC update key, the RRC Reestablishment message can only be integrity protected, but not encrypted. Otherwise, the UE cannot decrypt the RRC Reestablishment message and obtain the NCC, which further leads to the inability to update the key. In this way, the security of the RRC re-establishment message is relatively low. Therefore, how to improve the security of the RRC re-establishment message is an urgent problem to be solved in this application.
[0058] In an embodiment of the present application, after the UE sends an RRC re-establishment request message to the base station, the base station can send a first MAC CE including an NCC and a first byte stream to the UE, and the first byte stream includes an encrypted RRC re-establishment message, that is, the base station can carry the NCC outside the encrypted RRC re-establishment message. Therefore, while the UE obtains the NCC update key, the security of the RRC re-establishment message is also improved.
[0059] The present invention provides a communication method, and Figure 2 shows a flow chart of the communication method provided by the present invention. As shown in Figure 2, the communication method provided by the present invention may include the following steps 201 and 202.
[0060] Step 201: The UE sends an RRC re-establishment request message to the base station.
[0061] In some embodiments of the present application, when the UE is in an RRC connected state, but the RRC connection needs to be re-established, for example, when a radio link failure or an integrity check failure occurs in the UE in the connected state, the UE can perform a cell selection process to select a target cell to initiate an RRC re-establishment process, and send an RRC Reestablishment Request, i.e., an RRC re-establishment request message, to the base station where the target cell is located through SRB0.
[0062] Step 202: The MAC layer of the UE receives a first MAC CE from the base station.
[0063] In an embodiment of the present application, the first MAC CE includes an NCC and a first byte stream, the first byte stream includes an encrypted RRC re-establishment message, and the RRC re-establishment message is used to instruct the UE to re-establish the RRC connection.
[0064] In some embodiments of the present application, NCC is used to instruct the UE how to update the key used by the UE. Specifically, it can be described with reference to Figure 6.9.2.1.1-1 in the 3GPP TS33.501 protocol: If the NCC corresponding to the current key (i.e., a certain KgNB in the figure) is the same as the NCC received above, a new key is generated based on the current key, i.e., horizontal derivation in the figure; if the NCC corresponding to the current key is different from the NCC received above, a new key is generated based on the NH corresponding to the above-received NCC, i.e., vertical derivation in the figure. Further, the UE generates a first encryption key and a first integrity protection key based on the updated key.
[0065] In some embodiments of the present application, the UE may use the first encryption key and the first integrity protection key to restore integrity protection and encryption.
[0066] It can be understood that after the base station receives the RRC re-establishment request sent by the UE, it can send a first MAC CE to the UE, so that the UE can update the key used by the UE based on the NCC in the first MAC CE, and generate a first encryption key and a first integrity protection key based on the updated key, and re-establish the RRC connection based on the first byte stream in the first MAC CE.
[0067] An embodiment of the present application provides a communication method. After the UE sends an RRC re-establishment request message to the base station, the base station can send a first MAC CE including an NCC and a first byte stream to the UE. The first byte stream includes an encrypted RRC re-establishment message, that is, the base station can carry the NCC outside the encrypted RRC re-establishment message. Therefore, while the UE obtains the NCC update key, the security of the RRC re-establishment message is also improved.
[0068] In some embodiments of the present application, after the above step 202, the communication method provided by the embodiment of the present application further includes the following steps 203 to 207.
[0069] Step 203: The MAC layer of the UE parses the first MAC CE to obtain the NCC and the first byte stream.
[0070] Step 204: The MAC layer of the UE transfers the NCC and the first byte stream to the RRC layer of the UE.
[0071] It can be understood that after receiving the first MAC CE, the MAC layer of the UE can parse the first MAC CE to obtain the NCC and the first byte stream, and pass the NCC and the first byte stream to the RRC layer of the UE through inter-layer interaction.
[0072] In some embodiments of the present application, if the first MAC CE also carries the first information or other message integrity authentication code MAC-I, the MAC layer of the UE can pass it to the RRC layer of the UE.
[0073] Step 205: The RRC layer of the UE updates the key used by the UE based on the NCC, and generates a first encryption key and a first integrity protection key based on the updated key.
[0074] In some embodiments of the present application, when the NCC corresponding to the current key is the same as the NCC in the first MAC CE, the RRC layer of the UE can update the key used by the UE based on the current key; otherwise, the key used by the UE can be updated based on the NH corresponding to the NCC in the first MAC CE.
[0075] Step 206: The RRC layer of the UE requests the PDCP layer of the UE to process the first byte stream based on the first encryption key and the first integrity protection key.
[0076] Step 207: The PDCP layer of the UE processes the first byte stream based on the first encryption key and the first integrity protection key.
[0077] In some embodiments of the present application, after the above step 207, the communication method provided by the embodiment of the present application further includes the following step 301 or step 302.
[0078] Step 301: When the integrity protection verification operation performed by the PDCP layer of the UE fails, the UE enters the idle state.
[0079] Step 302: If the integrity protection verification operation performed by the PDCP layer of the UE passes, the PDCP layer of the UE transmits the decrypted RRC re-establishment message to the RRC layer of the UE.
[0080] In some embodiments of the present application, after the above step 302, the communication method provided by the embodiment of the present application further includes the following steps 303 and 304.
[0081] Step 303: The RRC layer of the UE re-establishes the RRC connection based on the decrypted RRC re-establishment message.
[0082] It can be understood that the RRC layer of the UE can process the decrypted RRC re-establishment message and re-establish the RRC connection according to the RRC re-establishment message.
[0083] In some embodiments of the present application, the above step 303 can be specifically implemented through the following step 303a.
[0084] Step 303a: When the NCC in the first MAC CE is the same as the NCC in the RRC re-establishment message, the RRC layer of the UE re-establishes the RRC connection according to the decrypted RRC re-establishment message.
[0085] In some embodiments of the present application, when the RRC re-establishment message includes NCC, the RRC layer of the UE can further verify whether the NCC in the first MAC CE is the same as the NCC in the RRC re-establishment message. If they are different, the verification fails and the UE enters the idle state; if they are the same, the RRC layer of the UE re-establishes the RRC connection according to the decrypted RRC re-establishment message.
[0086] In this way, since the RRC re-establishment message includes the NCC, it is possible to verify based on the NCC whether the NCC included in the first MAC CE is consistent with the NCC included in the RRC re-establishment message, thereby improving security.
[0087] Step 304: The UE sends an RRC re-establishment completion message to the base station.
[0088] In an embodiment of the present application, the RRC re-establishment completion message is a message processed by the PDCP layer of the UE using the first encryption key and the first integrity protection key.
[0089] It can be understood that the UE can send an RRC Reestablishment Complete message to the base station, that is, an RRC reestablishment complete message, which is encrypted and integrity protected and transmitted on SRB1.
[0090] In some embodiments of the present application, the above-mentioned first byte stream corresponds to a first PDCP PDU, and the first PDCP PDU includes an encrypted first MAC-I, and the encrypted first MAC-I is generated by the PDCP layer of the base station by performing an integrity protection operation on the RRC re-establishment message; the above-mentioned step 207 can be specifically implemented through the following steps 207a to 207c.
[0091] Step 207a: The PDCP layer of the UE parses the first PDCP PDU to obtain the encrypted RRC re-establishment message and the encrypted first MAC-I.
[0092] Step 207b: The PDCP layer of the UE performs a decryption operation on the encrypted RRC re-establishment message and the encrypted first MAC-I using the first encryption key to obtain a decrypted RRC re-establishment message and the decrypted first MAC-I.
[0093] Step 207c: The PDCP layer of the UE performs an integrity protection verification operation on the decrypted RRC re-establishment message using the first integrity protection key and the decrypted first MAC-I.
[0094] In some embodiments of the present application, when the PDCP layer of the UE fails to perform an integrity protection verification operation, the UE may enter an idle state.
[0095] In some embodiments of the present application, when the PDCP layer of the UE passes the integrity protection verification operation, the PDCP layer of the UE can pass the decrypted RRC re-establishment message to the RRC layer of the UE, and the RRC layer of the UE configures the PDCP layer of the UE to use the first encryption key and the first integrity protection key to restore integrity protection and encryption.
[0096] Specifically, the PDCP layer of the UE can parse the first PDCP PDU, obtain the "PDCP SN", "Data" and "MAC-I", and use the first encryption key to decrypt the two information elements of "Data" and "MAC-I". Then, the first integrity protection key and the decrypted "MAC-I" are used to perform integrity protection verification on the decrypted "Data" information element. If the verification fails, the UE can enter the idle state and the process ends. If the verification passes, the PDCP layer of the UE can return the decrypted "Data" to the RRC layer. Among them, "Data" corresponds to the encrypted RRC re-establishment message, and "MAC-I" corresponds to the encrypted first MAC-I.
[0097] In some embodiments of the present application, the parameters used by the PDCP layer of the UE to perform decryption operations and integrity protection verification operations are first parameters or a first parameter set.
[0098] In some embodiments of the present application, the above-mentioned first parameter or first parameter set includes at least one of the following: COUNT value is 0, BEARER is the bearer identifier of the radio signaling bearer SRB1, and DIRECTION is the downlink direction.
[0099] In some embodiments of the present application, the value of the downlink direction is 1.
[0100] In some embodiments of the present application, the communication method provided by the embodiments of the present application may further include the following step 208.
[0101] Step 208: The PDCP layer of the UE sets the first variable maintained by the PDCP entity corresponding to SRB1 to 1 or increases it by 1.
[0102] In the embodiment of the present application, the first variable is a variable corresponding to the COUNT value of the next PDCP SDU expected to be received.
[0103] In some embodiments of the present application, the first variable may be understood as a RX_NEXT variable.
[0104] It can be understood that the PDCP entity of SRB1 of the UE considers that it has successfully received the PDCP SDU with a COUNT value of 0. The RRC layer of the UE configures the PDCP layer of the UE to resume integrity protection and encryption using the first encryption key and the first integrity protection key.
[0105] In some embodiments of the present application, the parameters used by the PDCP layer of the UE to perform decryption operations and integrity protection verification operations are second parameters or a second parameter set.
[0106] In some embodiments of the present application, the above-mentioned second parameter or second parameter set includes at least one of the following: all bits of the COUNT value are 1, all bits of the BEARER value are 1, and DIRECTION is a downlink direction.
[0107] It should be noted that the parameters used by the UE to perform the integrity protection verification operation and the decryption operation are the same as the parameters used by the base station to perform the integrity protection operation and the encryption operation.
[0108] In some embodiments of the present application, the first MAC CE includes first information, which is a MAC-I generated by performing an integrity protection operation on the RRC re-establishment message; the step 207 can be specifically implemented through the following steps 207d and 207e.
[0109] Step 207d: The PDCP layer of the UE performs a decryption operation on the first byte stream using the first encryption key to obtain a decrypted RRC re-establishment message.
[0110] Step 207e: The PDCP layer of the UE performs an integrity protection verification operation on the decrypted RRC re-establishment message using the first integrity protection key and the first information.
[0111] In some embodiments of the present application, when the PDCP layer of the UE fails to perform an integrity protection verification operation, the UE may enter an idle state.
[0112] In some embodiments of the present application, when the PDCP layer of the UE passes the integrity protection verification operation, the PDCP layer of the UE can pass the decrypted RRC re-establishment message to the RRC layer of the UE, and configure the PDCP layer to use the first encryption key and the first integrity protection key to restore integrity protection and encryption.
[0113] In some embodiments of the present application, the first MAC CE includes second information, which is a MAC-I generated by performing an integrity protection operation on the NCC and the first byte stream; the step 207 can be specifically implemented by the following steps 207f and 207g.
[0114] Step 207f: The PDCP layer of the UE performs an integrity protection verification operation on the NCC and the first byte stream using the first integrity protection key and the second information.
[0115] Step 207g: When the PDCP layer of the UE performs integrity protection verification on the NCC and the first byte stream and passes the verification, the PDCP layer of the UE performs a decryption operation on the first byte stream using the first encryption key to obtain a decrypted RRC re-establishment message.
[0116] In some embodiments of the present application, when the PDCP layer of the UE fails to perform an integrity protection verification operation, the UE may enter an idle state.
[0117] In some embodiments of the present application, when the PDCP layer of the UE passes the integrity protection verification operation, the PDCP layer of the UE can pass the decrypted RRC re-establishment message to the RRC layer of the UE, and configure the PDCP layer to use the first encryption key and the first integrity protection key to restore integrity protection and encryption.
[0118] It should be noted that the parameters used by the PDCP layer of the UE to perform the decryption operation and integrity protection verification operation in the embodiment of the present application are any of the following: the first parameter, the first parameter set, the second parameter, and the second parameter set, which are not further described in this embodiment of the present application. In addition, the parameters used by the UE to perform the integrity protection verification operation and the decryption operation are the same as the parameters used by the base station to perform the integrity protection operation and the encryption operation.
[0119] The present invention provides a communication method, and Figure 3 shows a flow chart of the communication method provided by the present invention. As shown in Figure 3, the communication method provided by the present invention may include the following steps 401 and 402.
[0120] Step 401: The base station receives an RRC re-establishment request message from a UE.
[0121] Step 402: The MAC layer of the base station sends a first MAC CE to the UE.
[0122] In an embodiment of the present application, the first MAC CE includes an NCC and a first byte stream, the first byte stream includes an encrypted RRC re-establishment message, and the RRC re-establishment message is used to instruct the UE to re-establish the RRC connection.
[0123] In some embodiments of the present application, the first MAC CE is used to send the NCC and the encrypted RRC re-establishment message to the UE.
[0124] It can be understood that after the base station receives the RRC re-establishment request sent by the UE, it can send a first MAC CE to the UE, so that the UE can update the key used by the UE based on the NCC in the first MAC CE, and generate a first encryption key and a first integrity protection key based on the updated key, and re-establish the RRC connection based on the first byte stream in the first MAC CE.
[0125] In some embodiments of the present application, the first MAC CE corresponds to a dedicated logical channel identifier (LCID), that is, an LCID is assigned to the first MAC CE. After receiving a MAC PDU including the first MAC CE, the UE can determine that it is the first MAC CE through the LCID in the MAC subheader in the MAC PDU.
[0126] An embodiment of the present application provides a communication method. After the base station receives the RRC re-establishment request message sent by the UE, it can send a first MAC CE including an NCC and a first byte stream to the UE. The first byte stream includes an encrypted RRC re-establishment message. That is, the base station can send the NCC to the UE separately and does not carry it in the RRC re-establishment message. Therefore, when the UE obtains the NCC update key, the security of the RRC re-establishment message is also improved.
[0127] In some embodiments of the present application, after the above step 401, the communication method provided by the embodiment of the present application further includes the following steps 403 to 405.
[0128] Step 403: The RRC layer of the base station updates the key used by the base station, and generates a first encryption key and a first integrity protection key based on the updated key.
[0129] In some embodiments of the present application, after receiving the RRC re-establishment request message, the RRC layer of the base station can obtain the NCC stored in the UE context of the UE, and update the key used by the base station based on the NCC.
[0130] Step 404: The RRC layer of the base station instructs the PDCP layer of the base station to restore integrity protection and encryption using the first encryption key and the first integrity protection key.
[0131] Step 405: The RRC layer of the base station generates an RRC re-establishment message and requests the PDCP layer of the base station to perform security protection on the RRC re-establishment message.
[0132] It can be understood that after the PDCP layer of the base station uses the first encryption key and the first integrity protection key to restore integrity protection and encryption, the RRC layer of the base station can generate an RRC re-establishment message and request the PDCP layer of the base station to perform security protection on the RRC re-establishment message.
[0133] In some embodiments of the present application, after the above step 405, the communication method provided by the embodiment of the present application further includes the following steps 406 to 408.
[0134] Step 406: The PDCP layer of the base station performs security protection on the RRC re-establishment message, generates a first byte stream, and transmits the first byte stream to the RRC layer of the base station.
[0135] In an embodiment of the present application, the above-mentioned first byte stream includes an RRC re-establishment message that has been security protected, and the security protection includes at least one of the following: an encryption operation and an integrity protection operation.
[0136] Step 407: The RRC layer of the base station transfers the first byte stream and the NCC stored in the UE context of the UE to the MAC layer of the base station.
[0137] Step 408: The MAC layer of the base station generates a first MAC CE based on the NCC and the first byte stream.
[0138] In some embodiments of the present application, the first MAC CE is used to instruct the UE to re-establish the RRC connection, or to send the NCC and the security-protected RRC re-establishment message to the UE.
[0139] It can be understood that after the MAC layer of the base station generates the first MAC CE based on the NCC and the first byte stream, the MAC layer of the base station can send the first MAC CE including the NCC and the first byte stream to the UE.
[0140] Exemplarily, as shown in FIG4 , which is a structural diagram of a first MAC CE provided in an embodiment of the present application, the first MAC CE includes R, NCC and a first byte stream, where R represents reserved bits.
[0141] In some embodiments of the present application, in the above step 406, "the PDCP layer of the base station performs security protection on the RRC re-establishment message and generates a first byte stream" can be specifically implemented through the following steps 406a and 406b.
[0142] Step 406a: The PDCP layer of the base station performs an integrity protection operation on the RRC re-establishment message using the first integrity protection key to generate a first MAC-I.
[0143] Step 406b: The PDCP layer of the base station performs an encryption operation on the RRC re-establishment message and the first MAC-I using the first encryption key to generate a first PDCP PDU.
[0144] In an embodiment of the present application, the first PDCP PDU corresponds to a first byte stream, and the first PDCP PDU includes an encrypted RRC re-establishment message and a first MAC-I.
[0145] In some embodiments of the present application, the first PDCP PDU may be understood as the first byte stream, that is, the first PDCP PDU is the first byte stream.
[0146] It can be understood that in this embodiment, the PDCP layer of the base station performs security protection on the RRC re-establishment message, and the security protection includes an encryption operation and an integrity protection operation.
[0147] For example, as shown in Figure 5, which is a structural diagram of a first PDCP PDU provided in an embodiment of the present application, the "PDCP SN" element of the above-mentioned first PDCP PDU is 0, the "Data" element corresponds to the encrypted RRC re-establishment message, and the "MAC-I" element corresponds to the encrypted first MAC-I.
[0148] In this way, after the PDCP layer of the base station generates the first MAC-I, it also performs an encryption operation on the first MAC-I using the first encryption key, thereby improving security.
[0149] In some embodiments of the present application, the parameters used by the PDCP layer of the base station to perform encryption operations and integrity protection operations are first parameters or a first parameter set.
[0150] In some embodiments of the present application, the above-mentioned first parameter or first parameter set includes at least one of the following: COUNT value is 0, BEARER is the bearer identifier of the radio signaling bearer SRB1, and DIRECTION is the downlink direction.
[0151] In some embodiments of the present application, the value of the downlink direction is 1.
[0152] In some embodiments of the present application, the communication method provided by the embodiments of the present application may further include the following step 409.
[0153] Step 409: The PDCP layer of the base station sets the second variable maintained by the PDCP entity corresponding to SRB1 to 1 or increases it by 1.
[0154] In the embodiment of the present application, the second variable is a variable corresponding to the COUNT value of the next PDCP SDU to be sent.
[0155] In some embodiments of the present application, the second variable may be understood as a TX_NEXT variable.
[0156] It can be understood that the PDCP entity of SRB1 assigns a COUNT value (i.e., 0) to the RRC re-establishment message and performs security protection processing. After processing, it is not submitted to the RLC layer but returned to the RRC layer, and the TX_NEXT variable is set to 1 or increased by 1, thereby avoiding the problem of reduced security caused by the use of the same security protection parameters in subsequent RRC messages sent in SRB1.
[0157] In some embodiments of the present application, the parameters used by the PDCP layer of the above-mentioned base station to perform encryption operations and integrity protection operations are second parameters or a second parameter set.
[0158] In some embodiments of the present application, the above-mentioned second parameter or second parameter set includes at least one of the following: all bits of the COUNT value are 1, all bits of the BEARER value are 1, and DIRECTION is a downlink direction.
[0159] In some embodiments of the present application, the above step 406 can be specifically implemented through the following steps 406c to 406e.
[0160] Step 406c: The PDCP layer of the base station performs an encryption operation on the RRC re-establishment message using the first encryption key to generate a first byte stream.
[0161] It can be understood that the above-mentioned first byte stream includes the encrypted RRC re-establishment message.
[0162] Step 406d: The PDCP layer of the base station performs an integrity protection operation on the RRC re-establishment message using the first integrity protection key to generate first information.
[0163] In an embodiment of the present application, the above-mentioned first information is a MAC-I generated by performing an integrity protection operation on the RRC re-establishment message.
[0164] It can be understood that in this embodiment, the PDCP layer of the base station performs security protection on the RRC re-establishment message, and the security protection includes an encryption operation and an integrity protection operation.
[0165] In some embodiments of the present application, the MAC-I generated when the PDCP layer of the base station uses the first parameter or the first parameter set to perform an integrity protection operation on the RRC re-establishment message is different from the MAC-I generated when the PDCP layer of the base station uses the second parameter or the second parameter set to perform an integrity protection operation on the RRC re-establishment message.
[0166] Step 406e: The PDCP layer of the base station transmits the first byte stream and the first information to the RRC layer of the base station.
[0167] In an embodiment of the present application, the first MAC CE generated by the MAC layer of the base station includes a first byte stream, an NCC and first information, and the first information is transmitted from the RRC layer of the base station to the MAC layer of the base station.
[0168] It can be understood that after the RRC layer of the base station requests the PDCP layer of the base station to perform security protection on the RRC re-establishment message, and the PDCP layer of the base station performs encryption operations and integrity protection operations on the RRC re-establishment message to generate the first byte stream and the first information, the PDCP layer of the base station can return the first byte stream and the first information to the RRC layer of the base station, and then the RRC layer of the base station can pass the first byte stream, NCC and the first information to the MAC layer of the base station, so that the MAC layer of the base station can generate a first MAC CE based on the NCC, the first byte stream and the first information.
[0169] In some embodiments of the present application, when the RRC layer of the base station requests the PDCP layer of the base station to perform security protection on the RRC re-establishment message, the PDCP layer of the base station may only perform encryption operations on the RRC re-establishment message.
[0170] In some embodiments of the present application, the PDCP layer of the base station may only transmit the first byte stream to the RRC layer of the base station.
[0171] In some embodiments of the present application, before the above step 407, the communication method provided in the embodiment of the present application further includes the following steps 407a and 407b.
[0172] Step 407a: The RRC layer of the base station requests the PDCP layer of the base station to perform integrity protection operations on the NCC and the first byte stream.
[0173] In some embodiments of the present application, when the RRC layer of the base station requests the PDCP layer of the base station to perform security protection on the RRC re-establishment message, and the RRC layer of the base station only receives the first byte stream returned by the PDCP layer of the base station, that is, the PDCP layer of the base station does not perform integrity protection operations on the RRC re-establishment message, the RRC layer of the base station can request the PDCP layer of the base station to perform integrity protection operations on the NCC and the first byte stream.
[0174] In some embodiments of the present application, the RRC layer of the base station may transmit the NCC and the first byte stream to the PDCP layer of the base station.
[0175] Step 407b: The PDCP layer of the base station performs an integrity protection operation on the NCC and the first byte stream using the first integrity protection key, generates a second MAC-I, and transmits the second MAC-I to the RRC layer of the base station.
[0176] In an embodiment of the present application, the first MAC CE generated by the MAC layer of the base station includes a first byte stream, an NCC and a second MAC-I, and the second MAC-I is transmitted by the RRC layer of the base station to the MAC layer of the base station.
[0177] It can be understood that when the RRC layer of the base station receives the second MAC-I returned by the PDCP layer of the base station, it can pass the first byte stream, NCC and the second MAC-I to the MAC layer of the base station, so that the MAC layer of the base station can generate a first MAC CE based on the NCC, the first byte stream and the second MAC-I.
[0178] In some embodiments of the present application, the second MAC-I may be second information.
[0179] In some embodiments of the present application, the parameters used by the PDCP layer of the base station when performing integrity protection on the NCC and the first byte stream using the first integrity protection key are the same as the parameters used when performing encryption operations on the RRC re-establishment message using the first encryption key.
[0180] In this way, since the PDCP layer of the base station does not perform integrity protection operations on the RRC re-establishment message, the RRC layer of the base station can request the PDCP layer of the base station to perform integrity protection operations on the NCC and the first byte stream to generate a second MAC-I, and then the first byte stream, NCC and the second MAC-I can be passed to the MAC layer of the base station, so that the MAC layer of the base station generates a first MAC CE, thereby improving the flexibility and reliability of the base station in generating the first MAC CE.
[0181] In some embodiments of the present application, before the above step 408, the communication method provided by the embodiment of the present application further includes the following steps 408a and 408b.
[0182] Step 408a: The MAC layer of the base station requests the PDCP layer of the base station to perform an integrity protection operation on the NCC and the first byte stream.
[0183] In some embodiments of the present application, when the MAC layer of the base station only receives the first byte stream and NCC transmitted by the RRC layer of the base station, that is, when the PDCP layer of the base station does not perform integrity protection operations on the RRC re-establishment message, the MAC layer of the base station can request the PDCP layer of the base station to perform integrity protection operations on the first byte stream and NCC.
[0184] In some embodiments of the present application, the MAC layer of the base station may transmit the NCC and the first byte stream to the PDCP layer of the base station.
[0185] Step 408b: The PDCP layer of the base station performs integrity protection on the NCC and the first byte stream using the first integrity protection key, generates a third MAC-I, and transmits the third MAC-I to the MAC layer of the base station.
[0186] In an embodiment of the present application, the first MAC CE generated by the MAC layer of the above-mentioned base station includes a first byte stream, an NCC and a third MAC-I.
[0187] It can be understood that when the MAC layer of the base station receives the third MAC-I returned by the PDCP layer of the base station, the MAC layer of the base station can generate a first MAC CE based on the NCC, the first byte stream and the third MAC-I.
[0188] In some embodiments of the present application, the third MAC-I may be the second information.
[0189] In some embodiments of the present application, the parameters used by the PDCP layer of the base station when performing integrity protection on the NCC and the first byte stream using the first integrity protection key are the same as the parameters used when performing encryption operations on the RRC re-establishment message using the first encryption key.
[0190] In this way, when the base station's PDCP layer does not perform integrity protection on the RRC re-establishment message, the base station's MAC layer can request the base station's PDCP layer to perform integrity protection on the NCC and the first byte stream to generate a third MAC-I. The base station's MAC layer can then generate a first MAC CE based on the NCC, the first byte stream, and the third MAC-I returned by the base station's PDCP layer. This improves the flexibility and reliability of the base station's generation of the first MAC CE. Furthermore, in addition to the first byte stream, the NCC is also integrity protected, thereby improving security.
[0191] It should be noted that the parameters used by the PDCP layer of the base station in the embodiment of the present application to perform encryption operations and integrity protection operations are any one of the following: a first parameter, a first parameter set, a second parameter, and a second parameter set.
[0192] Exemplarily, as shown in FIG6 , which is a structural diagram of a first MAC CE provided in an embodiment of the present application, the first MAC CE includes R, NCC, a first byte stream and MAC-I, where R represents reserved bits.
[0193] In some embodiments of the present application, the RRC re-establishment message is no longer transmitted via SRB1 like a conventional RRC message. Instead, the RRC layer of the base station performs security protection on the message through inter-layer interaction with the PDCP layer. The RRC re-establishment message after security protection is then delivered to the MAC layer through inter-layer interaction with the MAC layer. The message is carried in a MAC CE as a byte stream and sent to the UE. The MAC CE also carries an NCC for key update. Correspondingly, the UE first updates the key used by the UE based on the NCC in the MAC CE, and then performs security-related processing on the RRC re-establishment message based on the updated key.
[0194] In some embodiments of the present application, as shown in FIG7 , the communication method provided in the embodiment of the present application may include the following steps A1 to A14.
[0195] A1. The UE is in connected state and the RRC layer connection needs to be re-established.
[0196] A2. The UE sends an RRC re-establishment request message to the base station.
[0197] A3. The base station receives an RRC re-establishment request message from the UE.
[0198] A4. The RRC layer of the base station updates the key used by the base station, generates a first encryption key and a first integrity protection key based on the updated key, and instructs the PDCP layer of the base station to use the first encryption key and the first integrity protection key to restore integrity protection and encryption.
[0199] A5. The RRC layer of the base station generates an RRC re-establishment message and requests the PDCP layer of the base station to perform security protection on the RRC re-establishment message.
[0200] A6. The PDCP layer RRC re-establishment message of the base station performs security protection, generates a first byte stream, and transmits the first byte stream to the RRC layer of the base station.
[0201] A7. The RRC layer of the base station transfers the first byte stream and the NCC stored in the UE context of the UE to the MAC layer of the base station.
[0202] A8. The MAC layer of the base station generates a first MAC CE based on the NCC and the first byte stream.
[0203] A9. The MAC layer of the base station sends a first MAC CE to the UE.
[0204] A10. The MAC layer of the UE parses the first MAC CE, obtains the NCC and the first byte stream, and passes the NCC and the first byte stream to the RRC layer of the UE.
[0205] A11. The RRC layer of the UE updates the key used by the UE based on the NCC, generates a first encryption key and a first integrity protection key based on the updated key, and requests the PDCP layer of the UE to process the first byte stream based on the first encryption key and the first integrity protection key.
[0206] A12. The PDCP layer of the UE processes the first byte stream based on the first encryption key and the first integrity protection key to obtain a decrypted RRC re-establishment message, and passes the decrypted RRC re-establishment message to the RRC layer of the UE.
[0207] A13. The RRC layer of the UE re-establishes the RRC connection based on the decrypted RRC re-establishment message.
[0208] A14. The UE sends an RRC re-establishment completion message to the base station.
[0209] It should be noted that, for the relevant explanations in the above steps A1 to A14, reference can be made to the description in the above embodiment, which will not be repeated here.
[0210] Each of the above-mentioned method embodiments, or various possible implementation methods in each method embodiment, can be executed separately, or any two or more of them can be executed in combination with each other. The specific implementation can be determined according to actual usage requirements, and the embodiments of this application do not limit this.
[0211] The communication method provided in the embodiment of the present application can be executed by a communication device. In the embodiment of the present application, the communication device provided in the embodiment of the present application is described by taking the communication method executed by the communication device as an example.
[0212] FIG8 shows a possible structural diagram of a communication device involved in an embodiment of the present application, which is applied to a UE. As shown in FIG8 , a communication device 40 may include: a sending module 41 and a receiving module 42 .
[0213] The sending module 41 is configured to send an RRC re-establishment request message to the base station.
[0214] The receiving module 42 is configured to receive a first MAC CE from a base station; wherein the first MAC CE includes an NCC and a first byte stream, the first byte stream includes an encrypted RRC re-establishment message, and the RRC re-establishment message is used to instruct the UE to re-establish the RRC connection.
[0215] An embodiment of the present application provides a communication device. After the UE sends an RRC re-establishment request message to the base station, the base station can send a first MAC CE including an NCC and a first byte stream to the UE. The first byte stream includes an encrypted RRC re-establishment message, that is, the base station can carry the NCC outside the encrypted RRC re-establishment message. Therefore, when the UE obtains the NCC update key, the security of the RRC re-establishment message is also improved.
[0216] In one possible implementation, the communication device provided by the embodiment of the present application further includes: a parsing module, a transmission module, a processing module, and a request module. The parsing module is used to parse the first MAC CE after the receiving module 42 receives the first MAC CE from the base station to obtain the NCC and the first byte stream. The transmission module is used to transmit the NCC and the first byte stream parsed by the parsing module to the RRC layer of the UE. The processing module is used to update the key used by the UE based on the NCC transmitted by the transmission module, and generate a first encryption key and a first integrity protection key based on the updated key. The request module is used to request the PDCP layer of the UE to process the first byte stream based on the first encryption key and the first integrity protection key. The processing module is also used to process the first byte stream based on the first encryption key and the first integrity protection key.
[0217] In one possible implementation, the first byte stream corresponds to a first PDCP PDU, the first PDCP PDU includes an encrypted first MAC-I, and the encrypted first MAC-I is generated by the PDCP layer of the base station by performing an integrity protection operation on the RRC re-establishment message; the processing module is specifically used to parse the first PDCP PDU to obtain the encrypted RRC re-establishment message and the encrypted first MAC-I; and perform a decryption operation on the encrypted RRC re-establishment message and the encrypted first MAC-I through the first encryption key to obtain the decrypted RRC re-establishment message and the decrypted first MAC-I; and perform an integrity protection verification operation on the decrypted RRC re-establishment message through the first integrity protection key and the decrypted first MAC-I.
[0218] In one possible implementation, the first MAC CE includes first information, which is a MAC-I generated by performing an integrity protection operation on the RRC re-establishment message; a processing module, specifically used to perform a decryption operation on the first byte stream using a first encryption key to obtain a decrypted RRC re-establishment message; and perform an integrity protection verification operation on the decrypted RRC re-establishment message using the first integrity protection key and the first information.
[0219] In one possible implementation, the first MAC CE includes second information, where the second information is a MAC-I generated by performing an integrity protection operation on the NCC and the first byte stream; a processing module is specifically used to perform an integrity protection verification operation on the NCC and the first byte stream using the first integrity protection key and the second information; and when the integrity protection verification operation on the NCC and the first byte stream is performed successfully at the PDCP layer of the UE, a decryption operation is performed on the first byte stream using the first encryption key to obtain a decrypted RRC re-establishment message.
[0220] In one possible implementation, the parameter used by the UE's PDCP layer to perform decryption operations and integrity protection verification operations is a first parameter or a first parameter set; wherein the first parameter or the first parameter set includes at least one of the following: the COUNT value is 0, BEARER is the bearer identifier of the wireless signaling bearer SRB1, and DIRECTION is the downlink direction.
[0221] In a possible implementation, the processing module is further configured to set a first variable maintained by the PDCP entity corresponding to SRB1 to 1 or increase it by 1, where the first variable is a variable corresponding to the COUNT value of the next PDCP service data unit SDU expected to be received.
[0222] In one possible implementation, the parameter used by the UE's PDCP layer to perform decryption operations and integrity protection verification operations is a second parameter or a second parameter set; wherein the second parameter or the second parameter set includes at least one of the following: all bits of the COUNT value are 1, all bits of the BEARER value are 1, and DIRECTION is the downlink direction.
[0223] In one possible implementation, the processing module is further used to, after processing the first byte stream based on the first encryption key and the first integrity protection key, enter an idle state if the integrity protection verification operation performed at the PDCP layer of the UE fails; the delivery module is further used to, after the processing module processes the first byte stream based on the first encryption key and the first integrity protection key, pass the decrypted RRC re-establishment message to the RRC layer of the UE if the integrity protection verification operation performed at the PDCP layer of the UE passes.
[0224] In one possible implementation, the processing module is further used to re-establish the RRC connection based on the decrypted RRC re-establishment message after the transmission module transmits the decrypted RRC re-establishment message to the RRC layer of the UE; the sending module 41 is further used to send an RRC re-establishment completion message to the base station, and the RRC re-establishment completion message is a message processed by the UE's PDCP layer using the first encryption key and the first integrity protection key.
[0225] In a possible implementation manner, the processing module is specifically configured to re-establish the RRC connection according to the decrypted RRC re-establishment message when the NCC in the first MAC CE is the same as the NCC in the RRC re-establishment message.
[0226] The communication device provided in the embodiment of the present application can implement each process implemented by the UE in the above method embodiment and achieve the same technical effect. To avoid repetition, it will not be repeated here.
[0227] FIG9 shows another possible structural diagram of a communication device involved in an embodiment of the present application, which is applied to a base station. As shown in FIG9 , a communication device 50 may include: a receiving module 51 and a sending module 52 .
[0228] The receiving module 51 is configured to receive an RRC re-establishment request message from a UE.
[0229] The sending module 52 is configured to send a first MAC CE to the UE; wherein the first MAC CE includes an NCC and a first byte stream, the first byte stream includes an encrypted RRC re-establishment message, and the RRC re-establishment message is used to instruct the UE to re-establish the RRC connection.
[0230] An embodiment of the present application provides a communication device. After the base station receives the RRC re-establishment request message sent by the UE, it can send a first MAC CE including an NCC and a first byte stream to the UE. The first byte stream includes an encrypted RRC re-establishment message, that is, the base station can send the NCC to the UE separately and does not carry it in the RRC re-establishment message. Therefore, when the UE obtains the NCC update key, the security of the RRC re-establishment message is also improved.
[0231] In one possible implementation, the communication device provided in an embodiment of the present application further includes: a processing module and an indication module. The processing module is configured to update the key used by the base station after the receiving module 51 receives the RRC re-establishment request message from the UE, and to generate a first encryption key and a first integrity protection key based on the updated key. The indication module is configured to instruct the PDCP layer of the base station to restore integrity protection and encryption using the first encryption key and the first integrity protection key generated by the processing module. The processing module is further configured to generate an RRC re-establishment message and request the PDCP layer of the base station to perform security protection on the RRC re-establishment message.
[0232] In one possible implementation, the communication device provided by the embodiment of the present application also includes: a transmission module and a generation module. The processing module is further used to perform security protection on the RRC re-establishment message after generating an RRC re-establishment message and requesting the PDCP layer of the base station to perform security protection on the RRC re-establishment message, generate a first byte stream, and transmit the first byte stream to the RRC layer of the base station. The first byte stream includes the RRC re-establishment message after security protection, and the security protection includes at least one of the following: encryption operation, integrity protection operation. The transmission module is used to transmit the first byte stream and the NCC saved in the UE context of the UE to the MAC layer of the base station. The generation module is used to generate a first MAC CE based on the NCC and the first byte stream.
[0233] In one possible implementation, the generation module is specifically used to perform an integrity protection operation on the RRC re-establishment message through a first integrity protection key to generate a first MAC-I; and perform an encryption operation on the RRC re-establishment message and the first MAC-I through a first encryption key to generate a first PDCP PDU, the first PDCP PDU corresponds to a first byte stream, and the first PDCP PDU includes the encrypted RRC re-establishment message and the first MAC-I.
[0234] In one possible implementation, the processing module is specifically used to perform an encryption operation on the RRC re-establishment message using a first encryption key to generate a first byte stream; and perform an integrity protection operation on the RRC re-establishment message using a first integrity protection key to generate first information, where the first information is a MAC-I generated by performing the integrity protection operation on the RRC re-establishment message; and transmit the first byte stream and the first information to the RRC layer of the base station; wherein the first MAC CE generated by the MAC layer of the base station includes the first byte stream, NCC and the first information, and the first information is transmitted by the RRC layer of the base station to the MAC layer of the base station.
[0235] In one possible implementation, the communication device provided by the embodiment of the present application further includes: a request module. The request module is configured to request the PDCP layer of the base station to perform an integrity protection operation on the NCC and the first byte stream before the delivery module delivers the first byte stream and the NCC stored in the UE context of the UE to the MAC layer of the base station. The processing module is further configured to perform an integrity protection operation on the NCC and the first byte stream using a first integrity protection key, generate a second MAC-I, and deliver the second MAC-I to the RRC layer of the base station; wherein the first MAC CE generated by the MAC layer of the base station includes the first byte stream, the NCC, and the second MAC-I, and the second MAC-I is delivered by the RRC layer of the base station to the MAC layer of the base station.
[0236] In one possible implementation, the communication device provided in an embodiment of the present application further includes: a request module. The request module is configured to request the PDCP layer of the base station to perform integrity protection on the NCC and the first byte stream before the generation module generates a first MAC CE based on the NCC and the first byte stream. The processing module is configured to perform integrity protection on the NCC and the first byte stream using a first integrity protection key, generate a third MAC-I, and transmit the third MAC-I to the MAC layer of the base station; wherein the first MAC CE generated by the MAC layer of the base station includes the first byte stream, the NCC, and the third MAC-I.
[0237] In one possible implementation, the parameter used by the PDCP layer of the base station to perform encryption operations and integrity protection operations is a first parameter or a first parameter set; wherein the first parameter or the first parameter set includes at least one of the following: the COUNT value is 0, BEARER is the bearer identifier of the wireless signaling bearer SRB1, and DIRECTION is the downlink direction.
[0238] In a possible implementation, the processing module is further configured to set a second variable maintained by the PDCP entity corresponding to SRB1 to 1 or increase it by 1, where the second variable is a variable corresponding to the COUNT value of the next PDCP service data unit SDU to be sent.
[0239] In a possible implementation, a parameter used by the PDCP layer of the base station to perform the encryption operation and the integrity protection operation is a second parameter or a second parameter set;
[0240] The second parameter or the second parameter set includes at least one of the following: all bits of the COUNT value are 1, all bits of the BEARER value are 1, and DIRECTION is the downlink direction.
[0241] The communication device provided in the embodiment of the present application can implement the various processes implemented by the base station in the above method embodiment and achieve the same technical effect. To avoid repetition, it will not be repeated here.
[0242] The present invention provides a communication method, and Figure 10 shows a flow chart of the communication method provided by the present invention. As shown in Figure 10, the communication method provided by the present invention may include the following steps 501 to 505.
[0243] Step 501: The UE sends an RRC re-establishment request message to the base station.
[0244] In some embodiments of the present application, when the UE is in an RRC connected state, but the RRC connection needs to be re-established, for example, when a radio link failure or an integrity check failure occurs in the UE in the connected state, the UE can perform a cell selection process to select a target cell to initiate an RRC re-establishment process, and send an RRC re-establishment request message to the base station where the target cell is located through SRB0.
[0245] Step 502: The UE receives first signaling from the base station.
[0246] In an embodiment of the present application, the above-mentioned first signaling is used to request the UE to update the key used by the UE, the first signaling includes the NCC, and the first signaling is the second MAC CE or PDCP control PDU.
[0247] Step 503: The RRC layer of the UE updates the key used by the UE based on the NCC, and generates a first encryption key and a first integrity protection key based on the updated key.
[0248] In some embodiments of the present application, after receiving the first signaling, the RRC of the UE may parse the first signaling to obtain the above-mentioned NCC.
[0249] In some embodiments of the present application, when the NCC corresponding to the current key is the same as the NCC in the second MAC CE, the RRC layer of the UE can update the key used by the UE based on the current key; otherwise, the key used by the UE can be updated based on the NH corresponding to the NCC in the second MAC CE.
[0250] In some embodiments of the present application, when the NCC corresponding to the current key is the same as the NCC in the PDCP control PDU, the RRC layer of the UE can update the key used by the UE based on the current key, otherwise the key used by the UE can be updated based on the NH corresponding to the NCC in the PDCP control PDU.
[0251] Step 504: The RRC layer of the UE instructs the PDCP layer of the UE to resume integrity protection and encryption using the first encryption key and the first integrity protection key.
[0252] Step 505: After the PDCP layer of the UE uses the first encryption key and the first integrity protection key to restore integrity protection and encryption, the PDCP layer of the UE processes the second PDCP PDU from the base station.
[0253] It should be noted that before the UE's PDCP layer uses the first encryption key and the first integrity protection key to restore integrity protection and encryption, if the PDCP entity corresponding to the UE's SRB1 receives the PDCP PDU, for example: the second PDCP PDU is received first due to the retransmission of the first signaling, the PDCP entity corresponding to the UE's SRB1 will not process the second PDCP PDU first until the first signaling is received and the UE's PDCP layer uses the first encryption key and the first integrity protection key to restore integrity protection and encryption. Only then can the UE's PDCP layer process the second PDCP PDU.
[0254] In an embodiment of the present application, the second PDCP PDU includes an integrity-protected and encrypted RRC re-establishment message, and the RRC re-establishment message is used to instruct the UE to re-establish the RRC connection.
[0255] It can be understood that the PDCP layer of the UE processes the second PDCP PDU from the base station after using the first encryption key and the first integrity protection key to restore integrity protection and encryption.
[0256] An embodiment of the present application provides a communication method. After the UE sends an RRC re-establishment request message to the base station, it can receive a first signaling from the base station for requesting the UE to update the key used by the UE. The first signaling includes an NCC. Therefore, the RRC layer of the UE can update the key used by the UE based on the NCC included in the first signaling, and generate a first encryption key and a first integrity protection key based on the updated key, and instruct the PDCP layer of the UE to use the first encryption key and the first integrity protection key to restore integrity protection and encryption. Then, after the PDCP layer of the UE restores integrity protection and encryption using the first encryption key and the first integrity protection key, it can process a second PDCP PDU from the base station. The second PDCP PDU includes an RRC re-establishment message that is integrity protected and encrypted. The RRC re-establishment message is used to instruct the UE to re-establish the RRC connection. That is, the PDCP layer of the UE first restores integrity protection and encryption, and then processes the second PDCP PDU from the base station. Therefore, the RRC re-establishment message can be integrity protected and encrypted, thereby improving the security of the RRC re-establishment message.
[0257] In some embodiments of the present application, when the first signaling is the second MAC CE, the step 502 may be implemented through the following steps 502a and 502b.
[0258] Step 502a: The MAC layer of the UE receives a second MAC CE from the base station.
[0259] Step 502b: The MAC layer of the UE parses the second MAC CE, obtains the NCC, and submits the NCC to the RRC layer of the UE.
[0260] It can be understood that after receiving the second MAC CE, the MAC layer of the UE can parse the second MAC CE to obtain the above-mentioned NCC, and deliver the NCC to the RRC layer of the UE through inter-layer interaction.
[0261] In some embodiments of the present application, if the second MAC CE also carries other MAC-Is, the MAC layer of the UE can pass them to the RRC layer of the UE.
[0262] In some embodiments of the present application, when the first signaling is a PDCP control PDU, the above step 502 can be specifically implemented through the following steps 502c and 502d.
[0263] Step 502c: The PDCP layer of the UE receives the PDCP control PDU from the base station.
[0264] Step 502d: The PDCP layer of the UE parses the PDCP control PDU, obtains the NCC, and submits the NCC to the RRC layer of the UE.
[0265] It can be understood that after receiving the PDCP control PDU, the PDCP layer of the UE can parse the PDCP control PDU to obtain the above-mentioned NCC, and deliver the NCC to the RRC layer of the UE through inter-layer interaction.
[0266] In some embodiments of the present application, the PDCP layer of the UE may specifically be a PDCP entity corresponding to SRB1.
[0267] In some embodiments of the present application, if the PDCP control PDU also carries other MAC-Is, the PDCP layer of the UE can pass them to the RRC layer of the UE.
[0268] In some embodiments of the present application, the first signaling includes third information, where the third information is a MAC-I generated by performing an integrity protection operation on the NCC. The step 504 can be specifically implemented through the following steps 504a to 504c.
[0269] Step 504a: The RRC layer of the UE requests the PDCP layer of the UE to perform an integrity protection verification operation on the NCC using the first integrity protection key and the third information.
[0270] Step 504b: The PDCP layer of the UE performs an integrity protection verification operation on the NCC using the first integrity protection key and the third information.
[0271] Step 504c: When the integrity protection verification operation performed by the PDCP layer of the UE on the NCC passes, the RRC layer of the UE instructs the PDCP layer of the UE to resume integrity protection and encryption using the first encryption key and the first integrity protection key.
[0272] In some embodiments of the present application, when the above-mentioned first signaling is the second MAC CE, the RRC layer of the UE may request the PDCP layer of the UE to perform integrity protection verification operations on the NCC using the first integrity protection key and the MAC-I included in the second MAC CE.
[0273] In some embodiments of the present application, when the above-mentioned first signaling is a PDCP control PDU, the RRC layer of the UE may request the PDCP layer of the UE to perform integrity protection verification operations on the NCC using the first integrity protection key and the MAC-I included in the PDCP control PDU.
[0274] In some embodiments of the present application, the parameter used by the PDCP layer of the UE to perform the integrity protection verification operation on the NCC is a second parameter or a second parameter set.
[0275] In some embodiments of the present application, the above-mentioned second parameter or second parameter set includes at least one of the following: all bits of the COUNT value are 1, all bits of the BEARER value are 1, and DIRECTION is a downlink direction.
[0276] In some embodiments of the present application, the communication method provided by the embodiments of the present application may further include the following step 506.
[0277] Step 506: When the PDCP layer of the UE fails to perform integrity protection verification on the NCC, the UE enters the idle state.
[0278] In some embodiments of the present application, when the PDCP layer of the UE passes the integrity protection verification operation performed on the NCC, the PDCP layer of the UE can be configured to use the first encryption key and the first integrity protection key to restore integrity protection and encryption.
[0279] In some embodiments of the present application, "the PDCP layer of the UE processes the second PDCP PDU from the base station" in the above step 505 can be specifically implemented through the following step 505a.
[0280] Step 505a: The PDCP layer of the UE uses the first encryption key and the first integrity protection key to perform a decryption operation and an integrity protection verification operation on the second PDCP PDU, and delivers the decrypted RRC re-establishment message to the RRC layer of the UE.
[0281] It can be understood that since the UE's PDCP layer uses the first encryption key and the first integrity protection key to restore integrity protection and encryption, the UE's PDCP layer can perform decryption operations and integrity protection verification operations on the received PDCP PDU, obtain the decrypted RRC re-establishment message, and submit the decrypted RRC re-establishment message to the UE's RRC layer.
[0282] In some embodiments of the present application, the communication method provided in the embodiments of the present application may further include the following steps 601 and 602.
[0283] Step 601: The RRC layer of the UE re-establishes the RRC connection based on the decrypted RRC re-establishment message.
[0284] It can be understood that the RRC layer of the UE can process the decrypted RRC re-establishment message and re-establish the RRC connection according to the RRC re-establishment message.
[0285] Step 602: The UE sends an RRC re-establishment completion message to the base station.
[0286] In an embodiment of the present application, the RRC re-establishment completion message is a message processed by the PDCP layer of the UE using the first encryption key and the first integrity protection key.
[0287] It can be understood that the UE can send an RRC re-establishment completion message to the base station, which is encrypted and integrity protected and transmitted on SRB1.
[0288] The present invention provides a communication method, and Figure 11 shows a flow chart of the communication method provided by the present invention. As shown in Figure 11, the communication method provided by the present invention may include the following steps 701 to 703.
[0289] Step 701: The base station receives an RRC re-establishment request message from a UE.
[0290] Step 702: The base station sends a first signaling to the UE.
[0291] In an embodiment of the present application, the above-mentioned first signaling is used to request the UE to update the key used by the UE, the first signaling includes the NCC, and the first signaling is the second MAC CE or PDCP control PDU.
[0292] Step 703: The base station sends a second PDCP PDU to the UE.
[0293] In an embodiment of the present application, the second PDCP PDU includes an integrity-protected and encrypted RRC re-establishment message, and the RRC re-establishment message is used to instruct the UE to re-establish the RRC connection.
[0294] An embodiment of the present application provides a communication method. After the base station receives the RRC re-establishment request message sent by the UE, it can send a first signaling to the UE for requesting the UE to update the key used by the UE, the first signaling includes the NCC, and a second PDCP PDU is sent to the UE to instruct the UE to re-establish the RRC connection. The second PDCP PDU includes an RRC re-establishment message that is integrity protected and encrypted, that is, the NCC and the RRC re-establishment message are separate, thereby improving the security of the RRC re-establishment message.
[0295] In some embodiments of the present application, before the above step 703, the communication method provided by the embodiment of the present application further includes the following steps 704 and 705.
[0296] Step 704: The RRC layer of the base station updates the key used by the base station, and generates a first encryption key and a first integrity protection key based on the updated key.
[0297] In some embodiments of the present application, after the RRC layer of the base station receives the RRC re-establishment request message sent by the UE, it can obtain the NCC stored in the UE context of the UE, and then update the key used by the base station based on the NCC.
[0298] Step 705: The RRC layer of the base station instructs the PDCP layer of the base station to use the first encryption key and the first integrity protection key to restore integrity protection and encryption.
[0299] It should be noted that, when generating the first encryption key and the first integrity protection key, the RRC layer of the base station may instruct the PDCP layer of the base station to use the first encryption key and the first integrity protection key to restore integrity protection and encryption, or, before the PDCP layer of the base station generates the PDCP control PDU, the RRC layer of the base station may instruct the PDCP layer of the base station to use the first encryption key and the first integrity protection key to restore integrity protection and encryption, or, before the base station sends the PDCP control PDU to the UE, the RRC layer of the base station may instruct the PDCP layer of the base station to use the first encryption key and the first integrity protection key to restore integrity protection and encryption. The embodiments of the present application do not limit this.
[0300] In some embodiments of the present application, the above step 702 can be specifically implemented through the following steps 702a to 702c.
[0301] Step 702a: The RRC layer of the base station transfers the NCC stored in the UE context of the UE to the MAC layer of the base station.
[0302] In some embodiments of the present application, the RRC layer of the base station may deliver the NCC to the MAC layer of the UE through inter-layer interaction.
[0303] Step 702b: The MAC layer of the base station generates a second MAC CE based on the NCC.
[0304] In an embodiment of the present application, the second MAC CE is used to request the UE to update the key used by the UE, and the second MAC CE includes the NCC.
[0305] In some embodiments of the present application, the second MAC CE is used to send the NCC to the UE.
[0306] Step 702c: The base station sends a second MAC CE to the UE.
[0307] In some embodiments of the present application, the second MAC CE corresponds to a dedicated LCID. That is, an LCID is assigned to the second MAC CE. Upon receiving a MAC PDU containing the second MAC CE, the UE can detect the second MAC CE based on the LCID in the MAC subheader of the MAC PDU. This eliminates the need to use at least two bits to indicate the message being sent, thereby reducing signaling overhead.
[0308] In some embodiments of the present application, the above step 702a can be specifically implemented through the following steps 702a1 to 702a3.
[0309] Step 702a1: The RRC layer of the base station requests the PDCP layer of the base station to perform an integrity protection operation on the NCC using the first integrity protection key.
[0310] Step 702a2: The PDCP layer of the base station performs an integrity protection operation on the NCC using the first integrity protection key, generates a fourth MAC-I, and transmits it to the RRC layer of the base station.
[0311] In some embodiments of the present application, the fourth MAC-I may be the third information.
[0312] Step 702a3: The RRC layer of the base station transfers the NCC and the fourth MAC-I to the MAC layer of the base station.
[0313] In some embodiments of the present application, the second MAC CE includes an NCC and a fourth MAC-I.
[0314] It can be understood that the MAC layer of the base station can generate the second MAC CE based on the NCC and the fourth MAC-I.
[0315] In some embodiments of the present application, the parameter used by the PDCP layer of the above-mentioned base station to perform integrity protection operation on the NCC is a second parameter or a second parameter set.
[0316] In some embodiments of the present application, the above-mentioned second parameter or second parameter set includes at least one of the following: all bits of the COUNT value are 1, all bits of the BEARER value are 1, and DIRECTION is a downlink direction.
[0317] In this way, since the NCC is integrity protected, security is improved.
[0318] In some embodiments of the present application, the above step 702b can be specifically implemented through the following steps 702b1 to 702b3.
[0319] Step 702b1: The MAC layer of the base station requests the PDCP layer of the base station to perform an integrity protection operation on the NCC using the first integrity protection key.
[0320] Step 702b2: The PDCP layer of the base station performs an integrity protection operation on the NCC using the first integrity protection key, generates a fifth MAC-I, and transmits it to the MAC layer of the base station.
[0321] In some embodiments of the present application, the fifth MAC-I may be the third information.
[0322] Step 702b3: The MAC layer of the base station generates a second MAC CE based on the NCC and the fifth MAC-I.
[0323] In an embodiment of the present application, the above-mentioned second MAC CE includes NCC and the fifth MAC-I.
[0324] In some embodiments of the present application, when the RRC layer of the base station only passes the NCC stored in the UE context of the UE to the MAC layer of the base station, that is, the NCC does not perform integrity protection operations, the MAC layer of the base station can request the PDCP layer of the UE to perform integrity protection operations on the NCC through the first integrity protection key, or perform integrity protection operations on the bytes or byte streams containing the NCC.
[0325] In this way, since the NCC is integrity protected, security is improved.
[0326] In some embodiments of the present application, the above step 702 can be specifically implemented through the following steps 702d to 702f.
[0327] Step 702d: The RRC layer of the base station transfers the NCC stored in the UE context of the UE to the PDCP layer of the base station.
[0328] In some embodiments of the present application, after receiving the RRC re-establishment message, the RRC layer of the base station can obtain the NCC stored in the UE context of the UE.
[0329] In some embodiments of the present application, the RRC layer of the base station may update the key used by the base station based on the NCC, and generate a first encryption key and a first integrity protection key based on the updated key.
[0330] In some embodiments of the present application, the RRC layer of the base station may deliver the NCC to the PDCP layer of the UE through inter-layer interaction.
[0331] Step 702e: The PDCP layer of the base station generates a PDCP control PDU based on the NCC.
[0332] In an embodiment of the present application, the PDCP control PDU is used to request the UE to update the key used by the UE, and the PDCP control PDU includes the NCC.
[0333] In some embodiments of the present application, the PDCP control PDU corresponds to a dedicated PDU Type value, that is, a PDU Type value is assigned to the PDCP control PDU. When a UE receives a PDCP control PDU and the PDU Type value of the PDCP control PDU is the dedicated PDU Type value, the UE can determine that it is a PDCP control PDU.
[0334] For example, as shown in Figure 12, a structural diagram of a PDCP control PDU provided in an embodiment of the present application is provided, wherein: D / C is used to indicate whether it is a control PDU or a data PDU, PDU Type is used to indicate the type of control PDU, R is a reserved bit, and NCC is the NCC submitted by the upper layer.
[0335] Step 702f: The base station sends a PDCP control PDU to the UE.
[0336] In some embodiments of the present application, the PDCP control PDU is used to request the UE to update the key used by the UE.
[0337] In some embodiments of the present application, the above step 702e can be specifically implemented through the following steps 702e1 and 702e2.
[0338] Step 702e1: The PDCP layer of the base station performs an integrity protection operation on the NCC using the first integrity protection key to generate a sixth MAC-I.
[0339] In some embodiments of the present application, the sixth MAC-I may be the third information.
[0340] Step 702e2: The PDCP layer of the base station generates a PDCP control PDU based on the NCC and the sixth MAC-I.
[0341] In an embodiment of the present application, the above-mentioned PDCP control PDU includes a sixth MAC-I.
[0342] In some embodiments of the present application, the parameter used by the PDCP layer of the above-mentioned base station to perform integrity protection operation on the NCC is a second parameter or a second parameter set.
[0343] In this way, since the NCC is integrity protected, security is improved.
[0344] In some embodiments of the present application, the above step 703 can be specifically implemented through the following steps 703a to 703d.
[0345] Step 703a: The RRC layer of the base station generates an RRC re-establishment message and transmits it to the PDCP layer of the base station.
[0346] In some embodiments of the present application, after the RRC layer of the base station generates an RRC re-establishment message, the RRC re-establishment message may be delivered to the PDCP layer corresponding to SRB1 as a PDCP SDU.
[0347] Step 703b: The PDCP layer of the base station performs an encryption operation and an integrity protection operation on the RRC re-establishment message using the first encryption key and the first integrity protection key to generate a second PDCP PDU.
[0348] Step 703c: The PDCP layer of the base station transfers the second PDCP PDU to the RLC layer of the base station.
[0349] Step 703d: The RLC layer of the base station sends a second PDCP PDU to the UE.
[0350] It can be understood that since the PDCP layer of the base station is configured to use the first encryption key and the first integrity protection key to restore integrity protection and encryption, the PDCP layer of the base station can perform encryption operations and integrity protection operations on the RRC re-establishment message through the first encryption key and the first integrity protection key, generate a second PDCP PDU, and pass the second PDCP PDU to the RLC layer of the base station to send it to the UE.
[0351] In some embodiments of the present application, the above step 703 can be specifically implemented through the following step 703e.
[0352] Step 703e: After the first signaling is sent, or after the first signaling is successfully sent, or after the base station receives a reception confirmation message of the first signaling, the base station sends a second PDCP PDU to the UE.
[0353] In some embodiments of the present application, as shown in FIG13 , the communication method provided in the embodiment of the present application may include the following steps B1 to B12.
[0354] B1. The UE is in connected state and the RRC layer connection needs to be re-established.
[0355] B2. The UE sends an RRC re-establishment request message to the base station.
[0356] B3. The base station receives the RRC re-establishment request message from the UE.
[0357] B4. The RRC layer of the base station passes the NCC stored in the UE context of the UE to the MAC layer of the base station.
[0358] B5. The MAC layer of the base station generates a second MAC CE including the NCC based on the NCC.
[0359] B6. The base station sends a second MAC CE to the UE.
[0360] B7. The UE receives a second MAC CE from the base station.
[0361] B8. The RRC layer of the UE updates the key used by the UE based on the NCC included in the second MAC CE, generates a first encryption key and a first integrity protection key based on the updated key, and instructs the PDCP layer of the UE to use the first encryption key and the first integrity protection key to restore integrity protection and encryption.
[0362] B9. The base station sends a second PDCP PDU to the UE.
[0363] B10. The PDCP layer of the UE performs a decryption operation and an integrity protection verification operation on the second PDCP PDU using the first encryption key and the first integrity protection key, and delivers the decrypted RRC re-establishment message to the RRC layer of the UE.
[0364] B11. The RRC layer of the UE re-establishes the RRC connection based on the decrypted RRC re-establishment message.
[0365] B12. The UE sends an RRC re-establishment complete message to the base station.
[0366] It should be noted that, for the relevant explanations in the above steps B1 to B12, reference can be made to the description in the above embodiment, which will not be repeated here.
[0367] It should be noted that in the above steps, "the RRC layer of the base station generates an RRC re-establishment message and passes it to the PDCP layer of the base station, the PDCP layer of the base station performs encryption operations and integrity protection operations on the RRC re-establishment message through the first encryption key and the first integrity protection key, generates a second PDCP PDU, and passes the second PDCP PDU to the RLC layer of the base station" and "the base station generates a second MAC CE" can be executed at the same time, but the base station needs to send the second MAC CE to the UE first, and then send the second PDCP PDU to the UE. Alternatively, the base station can put the subPDU corresponding to the second MAC CE and the subPDU corresponding to the second PDCP PDU in one MAC PDU and send it to the UE, but the subPDU corresponding to the second MAC CE is placed in front. In short, it is necessary to ensure that the UE processes the second MAC CE first, and only after the PDCP layer of the UE uses the first encryption key and the first integrity protection key to restore integrity protection and encryption, the PDCP layer of the UE can process the second PDCP PDU.
[0368] It should be noted that before the UE's PDCP layer uses the first encryption key and the first integrity protection key to restore integrity protection and encryption, if the PDCP entity corresponding to the UE's SRB1 receives the PDCP PDU, for example: the second PDCP PDU is received first due to the retransmission of the second MAC CE, the PDCP entity corresponding to the UE's SRB1 will not process the second PDCP PDU first until the second MAC CE is received and the UE's PDCP layer uses the first encryption key and the first integrity protection key to restore integrity protection and encryption. Only then can the UE's PDCP layer process the second PDCP PDU.
[0369] In some embodiments of the present application, as shown in FIG14 , the communication method provided in the embodiment of the present application may include the following steps C1 to C12.
[0370] C1. The UE is in connected state and the RRC layer connection needs to be re-established.
[0371] C2. The UE sends an RRC re-establishment request message to the base station.
[0372] C3. The base station receives an RRC re-establishment request message from the UE.
[0373] C4. The RRC layer of the base station transfers the NCC stored in the UE context of the UE to the PDCP layer of the base station.
[0374] C5. The PDCP layer of the base station generates a PDCP control PDU including the NCC based on the NCC.
[0375] C6. The base station sends a PDCP control PDU to the UE.
[0376] C7. The UE receives the PDCP control PDU from the base station.
[0377] C8. The RRC layer of the UE updates the key used by the UE based on the NCC included in the PDCP control PDU, generates a first encryption key and a first integrity protection key based on the updated key, and instructs the PDCP layer of the UE to use the first encryption key and the first integrity protection key to restore integrity protection and encryption.
[0378] C9. The base station sends a second PDCP PDU to the UE.
[0379] C10. The PDCP layer of the UE performs a decryption operation and an integrity protection verification operation on the second PDCP PDU using the first encryption key and the first integrity protection key, and delivers the decrypted RRC re-establishment message to the RRC layer of the UE.
[0380] C11. The RRC layer of the UE re-establishes the RRC connection based on the decrypted RRC re-establishment message.
[0381] C12. The UE sends an RRC re-establishment complete message to the base station.
[0382] It should be noted that, for the relevant explanations in the above steps C1 to C12, reference can be made to the description in the above embodiment, which will not be repeated here.
[0383] Each of the above-mentioned method embodiments, or various possible implementation methods in each method embodiment, can be executed separately, or any two or more of them can be executed in combination with each other. The specific implementation can be determined according to actual usage requirements, and the embodiments of this application do not limit this.
[0384] The communication method provided in the embodiment of the present application can be executed by a communication device. In the embodiment of the present application, the communication device provided in the embodiment of the present application is described by taking the communication method executed by the communication device as an example.
[0385] FIG15 shows a possible structural diagram of a communication device involved in an embodiment of the present application, which is applied to a UE. As shown in FIG15 , a communication device 60 may include: a sending module 61 , a receiving module 62 , a processing module 63 and an indicating module 64 .
[0386] The sending module 61 is configured to send an RRC re-establishment request message to the base station.
[0387] The receiving module 62 is configured to receive a first signaling from a base station, where the first signaling is used to request the UE to update a key used by the UE, the first signaling includes an NCC, and the first signaling is a second MAC CE or a PDCP control PDU.
[0388] The processing module 63 is configured to update the key used by the UE based on the NCC, and generate a first encryption key and a first integrity protection key based on the updated key.
[0389] The instructing module 64 is configured to instruct the PDCP layer of the UE to restore integrity protection and encryption using the first encryption key and the first integrity protection key generated by the processing module 63 .
[0390] The processing module 63 is also used to process the second PDCP PDU from the base station after the PDCP layer of the UE uses the first encryption key and the first integrity protection key to restore integrity protection and encryption, and the second PDCP PDU includes an RRC re-establishment message that is integrity protected and encrypted, and the RRC re-establishment message is used to instruct the UE to re-establish the RRC connection.
[0391] An embodiment of the present application provides a communication device. Since the UE can receive a first signaling from the base station for requesting the UE to update the key used by the UE after sending an RRC re-establishment request message to the base station, the RRC layer of the UE can update the key used by the UE based on the NCC included in the first signaling, and generate a first encryption key and a first integrity protection key based on the updated key, and instruct the PDCP layer of the UE to use the first encryption key and the first integrity protection key to restore integrity protection and encryption. Then, after the PDCP layer of the UE restores integrity protection and encryption using the first encryption key and the first integrity protection key, it can process the second PDCP PDU from the base station, which includes an RRC re-establishment message that is integrity protected and encrypted. The RRC re-establishment message is used to instruct the UE to re-establish the RRC connection. That is, the PDCP layer of the UE first restores integrity protection and encryption, and then processes the second PDCP PDU from the base station. Therefore, the RRC re-establishment message can be integrity protected and encrypted, thereby improving the security of the RRC re-establishment message.
[0392] In one possible implementation, the first signaling includes third information, which is a MAC-I generated by performing an integrity protection operation on the NCC; an indication module 64 is specifically used to request the UE's PDCP layer to use the first integrity protection key and the third information to perform an integrity protection verification operation on the NCC; and to perform an integrity protection verification operation on the NCC using the first integrity protection key and the third information; and when the UE's PDCP layer passes the integrity protection verification operation on the NCC, the UE's RRC layer instructs the UE's PDCP layer to use the first encryption key and the first integrity protection key to restore integrity protection and encryption.
[0393] In a possible implementation, the processing module 63 is further configured to enter the idle state when the PDCP layer of the UE fails to perform an integrity protection verification operation on the NCC.
[0394] In one possible implementation, the parameter used by the PDCP layer of the UE to perform integrity protection verification operations on the NCC is a second parameter or a second parameter set; wherein the second parameter or the second parameter set includes at least one of the following: all bits of the COUNT value are 1, all bits of the BEARER value are 1, and DIRECTION is the downlink direction.
[0395] In a possible implementation, when the first signaling is a second MAC CE, the receiving module 62 is specifically configured to receive the second MAC CE from the base station, parse the second MAC CE, obtain the NCC, and submit the NCC to the RRC layer of the UE.
[0396] In a possible implementation, when the first signaling is a PDCP control PDU, the receiving module 62 is specifically configured to receive a PDCP control PDU from a base station, parse the PDCP control PDU, obtain an NCC, and submit the NCC to the RRC layer of the UE.
[0397] In a possible implementation, the processing module 63 is specifically configured to perform a decryption operation and an integrity protection verification operation on the second PDCP PDU using the first encryption key and the first integrity protection key, and deliver the decrypted RRC re-establishment message to the RRC layer of the UE.
[0398] In one possible implementation, the processing module 63 is further used to re-establish the RRC connection based on the decrypted RRC re-establishment message; the sending module 61 is further used to send an RRC re-establishment completion message to the base station, where the RRC re-establishment completion message is a message processed by the UE's PDCP layer using the first encryption key and the first integrity protection key.
[0399] The communication device provided in the embodiment of the present application can implement the various processes implemented by the UE in the above method embodiment and achieve the same technical effect. To avoid repetition, it will not be repeated here.
[0400] FIG16 shows another possible structural diagram of a communication device involved in an embodiment of the present application, which is applied to a base station. As shown in FIG16 , a communication device 70 may include: a receiving module 71 and a sending module 72 .
[0401] The receiving module 71 is configured to receive an RRC re-establishment request message from a UE.
[0402] A sending module 72 is configured to send a first signaling to the UE, where the first signaling is used to request the UE to update the key used by the UE, the first signaling includes an NCC, and the first signaling is a second MAC CE or a PDCP control PDU; and send a second PDCP PDU to the UE, where the second PDCP PDU includes an integrity-protected and encrypted RRC re-establishment message, and the RRC re-establishment message is used to instruct the UE to re-establish the RRC connection.
[0403] An embodiment of the present application provides a communication device. After the base station receives the RRC re-establishment request message sent by the UE, it can send a first signaling to the UE for requesting the UE to update the key used by the UE, the first signaling includes the NCC, and a second PDCP PDU is sent to the UE to instruct the UE to re-establish the RRC connection. The second PDCP PDU includes an RRC re-establishment message that is integrity protected and encrypted, that is, the NCC and the RRC re-establishment message are separate, thereby improving the security of the RRC re-establishment message.
[0404] In one possible implementation, the communication device provided in an embodiment of the present application further includes: a processing module and an instruction module; the processing module is configured to update a key used by the base station and generate a first encryption key and a first integrity protection key based on the updated key before the sending module 72 sends the second PDCP PDU to the UE; and the instruction module is configured to instruct the PDCP layer of the base station to resume integrity protection and encryption using the first encryption key and the first integrity protection key generated by the processing module.
[0405] In one possible implementation, the communication device provided in an embodiment of the present application further includes: a transmission module and a generation module. The transmission module is configured to transmit the NCC stored in the UE context of the UE to the MAC layer of the base station. The generation module is configured to generate a second MAC CE based on the NCC transmitted by the transmission module. The second MAC CE is used to request the UE to update a key used by the UE, and the second MAC CE includes the NCC. A sending module 72 is specifically configured to transmit the second MAC CE generated by the generation module to the UE.
[0406] In one possible implementation, the delivery module is specifically used to request the PDCP layer of the base station to perform an integrity protection operation on the NCC through a first integrity protection key; and perform an integrity protection operation on the NCC through the first integrity protection key to generate a fourth MAC-I, and pass it to the RRC layer of the base station; and pass the NCC and the fourth MAC-I to the MAC layer of the base station; wherein the second MAC CE includes the NCC and the fourth MAC-I.
[0407] In one possible implementation, the generation module is specifically used to request the PDCP layer of the base station to perform an integrity protection operation on the NCC through a first integrity protection key; and perform an integrity protection operation on the NCC through the first integrity protection key to generate a fifth MAC-I, and pass it to the MAC layer of the base station; and generate a second MAC CE based on the NCC and the fifth MAC-I, the second MAC CE including the NCC and the fifth MAC-I.
[0408] In one possible implementation, the communication device provided in an embodiment of the present application further includes: a transmission module and a generation module; the transmission module is configured to transmit the NCC stored in the UE context of the UE to the PDCP layer of the base station; the generation module is configured to generate a PDCP control PDU based on the NCC transmitted by the transmission module; the PDCP control PDU is used to request the UE to update the key used by the UE, and the PDCP control PDU includes the NCC; and a transmission module 72 is specifically configured to transmit the PDCP control PDU generated by the generation module to the UE.
[0409] In one possible implementation, the generation module is specifically configured to perform an integrity protection operation on the NCC using a first integrity protection key to generate a sixth MAC-I; and generate a PDCP control PDU based on the NCC and the sixth MAC-I, wherein the PDCP control PDU includes the sixth MAC-I.
[0410] In one possible implementation, the parameter used by the PDCP layer of the base station to perform integrity protection operations on the NCC is a second parameter or a second parameter set; wherein the second parameter or the second parameter set includes at least one of the following: all bits of the COUNT value are 1, all bits of the BEARER value are 1, and DIRECTION is the downlink direction.
[0411] In one possible implementation, the sending module 72 is specifically used to generate an RRC re-establishment message and pass it to the PDCP layer of the base station; and perform encryption operations and integrity protection operations on the RRC re-establishment message using a first encryption key and a first integrity protection key to generate a second PDCP PDU; and pass the second PDCP PDU to the radio link control RLC layer of the base station; and send the second PDCP PDU to the UE.
[0412] In a possible implementation, the sending module 72 is specifically configured to send the second PDCP PDU to the UE after the first signaling is sent, or after the first signaling is successfully sent, or after the base station receives a reception confirmation message of the first signaling.
[0413] The communication device provided in the embodiment of the present application can implement the various processes implemented by the base station in the above method embodiment and achieve the same technical effect. To avoid repetition, it will not be repeated here.
[0414] Optionally, as shown in Figure 17, an embodiment of the present application further provides a communication device 5000, including a processor 5001 and a memory 5002, wherein the memory 5002 stores a program or instruction that can be run on the processor 5001. For example, when the communication device 5000 is a UE, the program or instruction is executed by the processor 5001 to implement the various steps of the above-mentioned UE-side method embodiment and can achieve the same technical effect. When the communication device 5000 is a base station, the program or instruction is executed by the processor 5001 to implement the various steps of the above-mentioned base station method embodiment and can achieve the same technical effect. To avoid repetition, it will not be repeated here.
[0415] The present application also provides a UE, including a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is configured to execute a program or instruction to implement the steps in the above-described method embodiment. This UE embodiment corresponds to the above-described UE-side method embodiment, and each implementation process and implementation method of the above-described method embodiment is applicable to this UE embodiment and can achieve the same technical effects.
[0416] Specifically, Figure 18 is a schematic diagram of the hardware structure of a UE implementing an embodiment of the present application.
[0417] The UE 100 includes but is not limited to at least some of the components including a radio frequency unit 101 , a network module 102 , an audio output unit 103 , an input unit 104 , a sensor 105 , a display unit 106 , a user input unit 107 , an interface unit 108 , a memory 109 and a processor 110 .
[0418] Those skilled in the art will appreciate that UE 100 may further include a power supply (such as a battery) for powering various components. The power supply may be logically connected to processor 110 via a power management system, thereby enabling the power management system to manage charging, discharging, and power consumption. The UE structure shown in FIG18 does not limit the UE. The UE may include more or fewer components than shown, or may combine certain components, or have different component arrangements, which will not be described in detail here.
[0419] It should be understood that in an embodiment of the present application, the input unit 104 may include a graphics processing unit (GPU) 1041 and a microphone 1042, and the graphics processor 1041 processes the image data of a static picture or video obtained by an image capture device (such as a camera) in a video capture mode or an image capture mode. The display unit 106 may include a display panel 1061, and the display panel 1061 may be configured in the form of a liquid crystal display, an organic light emitting diode, etc. The user input unit 107 includes a touch panel 1071 and at least one of other input devices 1072. The touch panel 1071 is also called a touch screen. The touch panel 1071 may include two parts: a touch detection device and a touch controller. Other input devices 1072 may include, but are not limited to, a physical keyboard, function keys (such as volume control keys, switch keys, etc.), a trackball, a mouse, and a joystick, which will not be repeated here.
[0420] In the embodiment of the present application, after receiving downlink data from a network-side device, the RF unit 101 may transmit the data to the processor 110 for processing. Furthermore, the RF unit 101 may send uplink data to the network-side device. Typically, the RF unit 101 includes, but is not limited to, an antenna, an amplifier, a transceiver, a coupler, a low-noise amplifier, a duplexer, and the like.
[0421] The memory 109 can be used to store software programs or instructions and various data. The memory 109 may mainly include a first storage area for storing programs or instructions and a second storage area for storing data, wherein the first storage area may store an operating system, applications or instructions required for at least one function (such as a sound playback function, an image playback function, etc.), etc. In addition, the memory 109 may include a volatile memory or a non-volatile memory, or the memory 109 may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), a static random access memory (SRAM), a dynamic random access memory (DRAM), a synchronous dynamic random access memory (SDRAM), a double data rate synchronous dynamic random access memory (DDRSDRAM), an enhanced synchronous dynamic random access memory (ESDRAM), a synchronous link dynamic random access memory (SLDRAM), and a direct memory bus random access memory (DRRAM). The memory 109 in the embodiment of the present application includes but is not limited to these and any other suitable types of memory.
[0422] Processor 110 may include one or more processing units. Optionally, processor 110 integrates an application processor and a modem processor. The application processor primarily handles operations related to the operating system, user interface, and application programs, while the modem processor primarily processes wireless communication signals, such as a baseband processor. It is understood that the modem processor may not be integrated into processor 110.
[0423] The UE provided in the embodiment of the present application can implement each process implemented by the terminal in the above method embodiment and achieve the same technical effect. To avoid repetition, it will not be repeated here.
[0424] The present application also provides a base station, including a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is configured to execute a program or instruction to implement the steps of the above-described method embodiment. This base station embodiment corresponds to the above-described base station method embodiment, and each implementation process and implementation method of the above-described method embodiment are applicable to this base station embodiment and can achieve the same technical effects.
[0425] Specifically, an embodiment of the present application also provides a base station. As shown in Figure 19, the base station 600 includes: an antenna 61, a radio frequency device 62, a baseband device 63, a processor 64, and a memory 65. The antenna 61 is connected to the radio frequency device 62. In the uplink direction, the radio frequency device 62 receives information via the antenna 61 and sends the received information to the baseband device 63 for processing. In the downlink direction, the baseband device 63 processes the information to be transmitted and sends it to the radio frequency device 62. The radio frequency device 62 processes the received information and then sends it through the antenna 61.
[0426] The method executed by the base station in the above embodiment may be implemented in the baseband device 63 , which includes a baseband processor.
[0427] The base station provided in the embodiment of the present application can implement the various processes implemented by the base station in the above method embodiment and achieve the same technical effect. To avoid repetition, it will not be repeated here.
[0428] The baseband device 63 may include, for example, at least one baseband board, on which multiple chips are arranged, as shown in Figure 19, one of the chips is, for example, a baseband processor, which is connected to the memory 65 through a bus interface to call the program in the memory 65 and execute the network device operations shown in the above method embodiment.
[0429] The base station may further include a network interface 66, such as a common public radio interface (CPRI).
[0430] Specifically, the base station 600 of the embodiment of the present application also includes: instructions or programs stored in the memory 65 and executable on the processor 64. The processor 64 calls the instructions or programs in the memory 65 to execute the methods executed by the modules shown in FIG19 and achieve the same technical effect. To avoid repetition, it will not be elaborated here.
[0431] An embodiment of the present application also provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, the various processes of the above-mentioned method embodiment are implemented and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.
[0432] The processor is the processor in the communication device described in the above embodiment. The readable storage medium includes a computer-readable storage medium, such as a computer read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0433] An embodiment of the present application further provides a chip, which includes a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the various processes of the above-mentioned method embodiment and achieve the same technical effect. To avoid repetition, it will not be repeated here.
[0434] It should be understood that the chip mentioned in the embodiments of the present application can also be called a system-level chip, a system chip, a chip system or a system-on-chip chip, etc.
[0435] An embodiment of the present application further provides a computer program / program product, which is stored in a storage medium. The computer program / program product is executed by at least one processor to implement the various processes of the above-mentioned method embodiment and can achieve the same technical effect. To avoid repetition, it will not be repeated here.
[0436] An embodiment of the present application further provides a communication system, including: a UE and a terminal, wherein the UE can be used to execute the steps of the communication method described above, and the terminal can be used to execute the steps of the communication method described above.
[0437] It should be noted that, in this article, the terms "comprise", "include" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the statement "comprises a ..." does not exclude the presence of other identical elements in the process, method, article or device comprising the element. In addition, it should be noted that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed, and may also include performing functions in a substantially simultaneous manner or in the opposite order according to the functions involved. For example, the described method may be performed in an order different from that described, and various steps may also be added, omitted, or combined. In addition, the features described with reference to certain examples may be combined in other examples.
[0438] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, can be embodied in the form of a computer software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes a number of instructions for enabling a terminal (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in each embodiment of the present application.
[0439] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of this application, ordinary technicians in this field can also make many forms without departing from the purpose of this application and the scope of protection of the claims, all of which are within the protection of this application.
Claims
1. A communication method, the method comprising: A user equipment (UE) sends a radio resource control (RRC) re - establishment request message to a base station; The media access control (MAC) layer of the UE receives a first media access control control element (MAC CE) from the base station; Wherein, the first MAC CE includes a next - hop chain count (NCC) and a first byte stream, the first byte stream includes an encrypted RRC re - establishment message, and the RRC re - establishment message is used to instruct the UE to re - establish an RRC connection.
2. The method according to claim 1, wherein After the MAC layer of the UE receives the first MAC CE from the base station, the method further includes: The MAC layer of the UE parses the first MAC CE to obtain the NCC and the first byte stream; The MAC layer of the UE passes the NCC and the first byte stream to the RRC layer of the UE; The RRC layer of the UE updates the key used by the UE based on the NCC, and generates a first encryption key and a first integrity protection key based on the updated key; The RRC layer of the UE requests the packet data convergence protocol (PDCP) layer of the UE to process the first byte stream based on the first encryption key and the first integrity protection key; The PDCP layer of the UE processes the first byte stream based on the first encryption key and the first integrity protection key.
3. The method according to claim 2, wherein The first byte stream corresponds to a first PDCP protocol data unit (PDU), the first PDCP PDU includes an encrypted first message authentication code (MAC - I), and the encrypted first MAC - I is generated by the PDCP layer of the base station by performing an integrity protection operation on the RRC re - establishment message; The PDCP layer of the UE processes the first byte stream based on the first encryption key and the first integrity protection key, including: The PDCP layer of the UE parses the first PDCP PDU to obtain the encrypted RRC re - establishment message and the encrypted first MAC - I; The PDCP layer of the UE performs a decryption operation on the encrypted RRC re - establishment message and the encrypted first MAC - I through the first encryption key to obtain the decrypted RRC re - establishment message and the decrypted first MAC - I; The PDCP layer of the UE performs an integrity protection verification operation on the decrypted RRC re - establishment message through the first integrity protection key and the decrypted first MAC - I.
4. The method according to claim 2, wherein, The first MAC CE includes first information, and the first information is a MAC - I generated by performing an integrity protection operation on the RRC re - establishment message; The PDCP layer of the UE processes the first byte stream based on the first encryption key and the first integrity protection key, including: The PDCP layer of the UE performs a decryption operation on the first byte stream through the first encryption key to obtain the decrypted RRC re - establishment message; The PDCP layer of the UE performs an integrity protection verification operation on the decrypted RRC re - establishment message by using the first integrity protection key and the first information.
5. The method according to claim 2, wherein, The first MAC CE includes second information, where the second information is MAC - I generated by performing an integrity protection operation on the NCC and the first byte stream. The PDCP layer of the UE processes the first byte stream based on the first encryption key and the first integrity protection key, including: The PDCP layer of the UE performs an integrity protection verification operation on the NCC and the first byte stream by using the first integrity protection key and the second information. When the integrity protection verification operation performed by the PDCP layer of the UE on the NCC and the first byte stream passes, the PDCP layer of the UE performs a decryption operation on the first byte stream by using the first encryption key to obtain the decrypted RRC re - establishment message.
6. The method according to any one of claims 3 to 5, wherein The parameters used by the PDCP layer of the UE for performing the decryption operation and the integrity protection verification operation are the first parameter or the first parameter set. Wherein, the first parameter or the first parameter set includes at least one of the following: the COUNT value is 0, the BEARER is the bearer identifier of the radio signaling bearer SRB1, and the DIRECTION is the downlink direction.
7. The method according to claim 6, wherein, The method further includes: The PDCP layer of the UE sets the first variable maintained by the PDCP entity corresponding to SRB1 to 1 or increments it by 1, where the first variable is the variable corresponding to the COUNT value of the next expected received PDCP service data unit (SDU).
8. The method according to claim 4 or 5, wherein The parameters used by the PDCP layer of the UE for performing the decryption operation and the integrity protection verification operation are the second parameter or the second parameter set. Wherein, the second parameter or the second parameter set includes at least one of the following: all bits of the COUNT value are 1, all bits of the BEARER value are 1, and the DIRECTION is the downlink direction.
9. The method according to any one of claims 3 to 5, wherein After the PDCP layer of the UE processes the first byte stream based on the first encryption key and the first integrity protection key, the method further includes: When the integrity protection verification operation performed by the PDCP layer of the UE fails, the UE enters the idle state. When the integrity protection verification operation performed by the PDCP layer of the UE passes, the PDCP layer of the UE passes the decrypted RRC re - establishment message to the RRC layer of the UE.
10. The method according to claim 9, wherein, After the PDCP layer of the UE passes the decrypted RRC re - establishment message to the RRC layer of the UE, the method further includes: The RRC layer of the UE re - establishes an RRC connection based on the decrypted RRC re - establishment message. The UE sends an RRC re - establishment complete message to the base station, where the RRC re - establishment complete message is the message processed by the PDCP layer of the UE by using the first encryption key and the first integrity protection key.
11. The method according to claim 10, wherein The RRC layer of the UE re - establishes an RRC connection based on the decrypted RRC re - establishment message, including: When the NCC in the first MAC CE is the same as the NCC in the RRC re - establishment message, the RRC layer of the UE re - establishes the RRC connection according to the decrypted RRC re - establishment message.
12. A communication method, the method includes: The base station receives an RRC re - establishment request message from a UE; The MAC layer of the base station sends a first MAC CE to the UE; Wherein, the first MAC CE includes an NCC and a first byte stream, and the first byte stream includes an encrypted RRC re - establishment message, and the RRC re - establishment message is used to instruct the UE to re - establish an RRC connection.
13. The method according to claim 12, wherein After the base station receives the RRC re - establishment request message from the UE, the method further includes: The RRC layer of the base station updates the key used by the base station, and generates a first encryption key and a first integrity protection key based on the updated key; The RRC layer of the base station instructs the PDCP layer of the base station to use the first encryption key and the first integrity protection key to restore integrity protection and encryption; The RRC layer of the base station generates the RRC re - establishment message, and requests the PDCP layer of the base station to perform security protection on the RRC re - establishment message.
14. The method according to claim 13, wherein, After the RRC layer of the base station generates the RRC re - establishment message, and requests the PDCP layer of the base station to perform security protection on the RRC re - establishment message, the method further includes: The PDCP layer of the base station performs security protection on the RRC re - establishment message, generates the first byte stream, and passes the first byte stream to the RRC layer of the base station. The first byte stream includes the RRC re - establishment message after security protection, and the security protection includes at least one of the following: encryption operation, integrity protection operation; The RRC layer of the base station passes the first byte stream and the NCC saved in the UE context of the UE to the MAC layer of the base station; The MAC layer of the base station generates the first MAC CE based on the NCC and the first byte stream.
15. The method according to claim 14, wherein, The PDCP layer of the base station performs security protection on the RRC re - establishment message, and generates the first byte stream, including: The PDCP layer of the base station performs an integrity protection operation on the RRC re - establishment message through the first integrity protection key, and generates a first MAC - I; The PDCP layer of the base station performs an encryption operation on the RRC re - establishment message and the first MAC - I through the first encryption key, generates a first PDCP PDU, the first PDCP PDU corresponds to the first byte stream, and the first PDCP PDU includes the encrypted RRC re - establishment message and the first MAC - I.
16. The method according to claim 14, wherein, The PDCP layer of the base station performs security protection on the RRC re - establishment message, generates the first byte stream, and passes the first byte stream to the RRC layer of the base station, including: The PDCP layer of the base station performs an encryption operation on the RRC re - establishment message through the first encryption key, and generates the first byte stream; The PDCP layer of the base station performs an integrity protection operation on the RRC re - establishment message using the first integrity protection key, generating a first piece of information, where the first piece of information is the MAC - I generated by performing the integrity protection operation on the RRC re - establishment message; The PDCP layer of the base station transfers the first byte stream and the first piece of information to the RRC layer of the base station; Among them, the first MAC CE generated by the MAC layer of the base station includes the first byte stream, the NCC, and the first piece of information, and the first piece of information is transferred from the RRC layer of the base station to the MAC layer of the base station.
17. The method according to claim 14, wherein Before the RRC layer of the base station transfers the first byte stream and the NCC saved in the UE context of the UE to the MAC layer of the base station, the method further includes: The RRC layer of the base station requests the PDCP layer of the base station to perform an integrity protection operation on the NCC and the first byte stream; The PDCP layer of the base station performs an integrity protection operation on the NCC and the first byte stream using the first integrity protection key, generating a second MAC - I, and transfers the second MAC - I to the RRC layer of the base station; Among them, the first MAC CE generated by the MAC layer of the base station includes the first byte stream, the NCC, and the second MAC - I, and the second MAC - I is transferred from the RRC layer of the base station to the MAC layer of the base station.
18. The method according to claim 14, wherein, Before the MAC layer of the base station generates the first MAC CE based on the NCC and the first byte stream, the method further includes: The MAC layer of the base station requests the PDCP layer of the base station to perform an integrity protection operation on the NCC and the first byte stream; The PDCP layer of the base station performs integrity protection on the NCC and the first byte stream using the first integrity protection key, generating a third MAC - I, and transfers the third MAC - I to the MAC layer of the base station; Among them, the first MAC CE generated by the MAC layer of the base station includes the first byte stream, the NCC, and the third MAC - I.
19. The method according to any one of claims 15 to 18, wherein, The parameters used by the PDCP layer of the base station to perform the encryption operation and the integrity protection operation are the first parameter or the first parameter set; Among them, the first parameter or the first parameter set includes at least one of the following: the COUNT value is 0, the BEARER is the bearer identifier of the radio signaling bearer SRB1, and the DIRECTION is the downlink direction.
20. The method according to claim 19, wherein, The method further includes: The PDCP layer of the base station sets the second variable maintained by the PDCP entity corresponding to SRB1 to 1 or increments it by 1, and the second variable is the variable corresponding to the COUNT value of the next PDCP service data unit (SDU) to be sent.
21. The method according to any one of claims 16 to 18, wherein The parameters used by the PDCP layer of the base station to perform the encryption operation and the integrity protection operation are the second parameter or the second parameter set; Wherein, the second parameter or the set of second parameters includes at least one of the following: all bits of the COUNT value are 1, all bits of the BEARER value are 1, and the DIRECTION is the downlink direction.
22. A communication method, the method comprising: The UE sends an RRC reestablishment request message to the base station; The UE receives a first signaling from the base station, the first signaling being used to request the UE to update the key used by the UE, the first signaling including an NCC, and the first signaling being a second MAC CE or a PDCP control PDU; The RRC layer of the UE updates the key used by the UE based on the NCC, and generates a first encryption key and a first integrity protection key based on the updated key; The RRC layer of the UE instructs the PDCP layer of the UE to use the first encryption key and the first integrity protection key to restore integrity protection and encryption; After the PDCP layer of the UE uses the first encryption key and the first integrity protection key to restore integrity protection and encryption, the PDCP layer of the UE processes a second PDCP PDU from the base station, and the second PDCP PDU includes an RRC reestablishment message that is integrity protected and encrypted, and the RRC reestablishment message is used to instruct the UE to reestablish an RRC connection.
23. The method according to claim 22, wherein The first signaling includes third information, and the third information is a MAC-I generated by performing an integrity protection operation on the NCC; the RRC layer of the UE instructing the PDCP layer of the UE to use the first encryption key and the first integrity protection key to restore integrity protection and encryption includes: The RRC layer of the UE requests the PDCP layer of the UE to perform an integrity protection verification operation on the NCC using the first integrity protection key and the third information; The PDCP layer of the UE performs an integrity protection verification operation on the NCC using the first integrity protection key and the third information; When the integrity protection verification operation on the NCC by the PDCP layer of the UE is passed, the RRC layer of the UE instructs the PDCP layer of the UE to use the first encryption key and the first integrity protection key to restore integrity protection and encryption.
24. The method according to claim 23, wherein The method further includes: When the integrity protection verification operation on the NCC by the PDCP layer of the UE fails, the UE enters the idle state.
25. The method according to claim 23, wherein, The parameters used by the PDCP layer of the UE to perform the integrity protection verification operation on the NCC are a second parameter or a set of second parameters; Wherein, the second parameter or the set of second parameters includes at least one of the following: all bits of the COUNT value are 1, all bits of the BEARER value are 1, and the DIRECTION is the downlink direction.
26. The method according to claim 22, wherein, When the first signaling is a second MAC CE, the UE receiving the first signaling from the base station includes: The MAC layer of the UE receives the second MAC CE from the base station; The MAC layer of the UE parses the second MAC CE to obtain the NCC, and delivers the NCC to the RRC layer of the UE.
27. The method according to claim 22, wherein, When the first signaling is a PDCP control PDU, the UE receives the first signaling from the base station, including: The PDCP layer of the UE receives the PDCP control PDU from the base station; The PDCP layer of the UE parses the PDCP control PDU to obtain the NCC, and delivers the NCC to the RRC layer of the UE.
28. The method according to claim 22, wherein, The PDCP layer of the UE processes the second PDCP PDU from the base station, including: The PDCP layer of the UE performs a decryption operation and an integrity protection verification operation on the second PDCP PDU using the first encryption key and the first integrity protection key, and delivers the decrypted RRC reestablishment message to the RRC layer of the UE.
29. The method according to claim 28, wherein, The method further includes: The RRC layer of the UE reestablishes the RRC connection based on the decrypted RRC reestablishment message; The UE sends the RRC reestablishment complete message to the base station, and the RRC reestablishment complete message is a message processed by the PDCP layer of the UE using the first encryption key and the first integrity protection key.
30. A communication method, the method includes: The base station receives an RRC reestablishment request message from the UE; The base station sends the first signaling to the UE, the first signaling is used to request the UE to update the key used by the UE, the first signaling includes the NCC, and the first signaling is the second MAC CE or a PDCP control PDU; The base station sends a second PDCP PDU to the UE, and the second PDCP PDU includes an integrity-protected and encrypted RRC reestablishment message, and the RRC reestablishment message is used to instruct the UE to reestablish the RRC connection.
31. The method according to claim 30, wherein, Before the base station sends the second PDCP PDU to the UE, the method further includes: The RRC layer of the base station updates the key used by the base station, and generates a first encryption key and a first integrity protection key based on the updated key; The RRC layer of the base station instructs the PDCP layer of the base station to restore integrity protection and encryption using the first encryption key and the first integrity protection key.
32. The method according to claim 30, wherein The base station sends the first signaling to the UE, including: The RRC layer of the base station delivers the NCC saved in the UE context of the UE to the MAC layer of the base station; The MAC layer of the base station generates the second MAC CE based on the NCC, and the second MAC CE is used to request the UE to update the key used by the UE, and the second MAC CE includes the NCC; The base station sends the second MAC CE to the UE.
33. The method according to claim 32, wherein, The RRC layer of the base station delivers the NCC saved in the UE context of the UE to the MAC layer of the base station, including: The RRC layer of the base station requests the PDCP layer of the base station to perform an integrity protection operation on the NCC using the first integrity protection key; The PDCP layer of the base station performs an integrity protection operation on the NCC using the first integrity protection key, generates a fourth MAC-I, and transfers it to the RRC layer of the base station; The RRC layer of the base station transfers the NCC and the fourth MAC-I to the MAC layer of the base station; Wherein, the second MAC CE includes the NCC and the fourth MAC-I.
34. The method according to claim 32, wherein The MAC layer of the base station generates the second MAC CE based on the NCC, including: The MAC layer of the base station requests the PDCP layer of the base station to perform an integrity protection operation on the NCC using the first integrity protection key; The PDCP layer of the base station performs an integrity protection operation on the NCC using the first integrity protection key, generates a fifth MAC-I, and transfers it to the MAC layer of the base station; The MAC layer of the base station generates the second MAC CE based on the NCC and the fifth MAC-I, and the second MAC CE includes the NCC and the fifth MAC-I.
35. The method according to claim 30, wherein, The base station sends a first signaling to the UE, including: The RRC layer of the base station transfers the NCC stored in the UE context of the UE to the PDCP layer of the base station; The PDCP layer of the base station generates the PDCP control PDU based on the NCC, and the PDCP control PDU is used to request the UE to update the key used by the UE, and the PDCP control PDU includes the NCC; The base station sends the PDCP control PDU to the UE.
36. The method according to claim 35, wherein The PDCP layer of the base station generates the PDCP control PDU based on the NCC, including: The PDCP layer of the base station performs an integrity protection operation on the NCC using the first integrity protection key, generates a sixth MAC-I; The PDCP layer of the base station generates the PDCP control PDU based on the NCC and the sixth MAC-I, and the PDCP control PDU includes the sixth MAC-I.
37. The method according to claim 33 or 34 or 36, wherein, The parameters used by the PDCP layer of the base station to perform the integrity protection operation on the NCC are the second parameter or the second parameter set; Wherein, the second parameter or the second parameter set includes at least one of the following: all bits of the COUNT value are 1, all bits of the BEARER value are 1, and the DIRECTION is the downlink direction.
38. The method according to claim 31, wherein The base station sends a second PDCP PDU to the UE, including: The RRC layer of the base station generates the RRC reestablishment message and transfers it to the PDCP layer of the base station; The PDCP layer of the base station performs an encryption operation and an integrity protection operation on the RRC reestablishment message using the first encryption key and the first integrity protection key, and generates the second PDCP PDU; The PDCP layer of the base station transfers the second PDCP PDU to the radio link control RLC layer of the base station; The RLC layer of the base station sends the second PDCP PDU to the UE.
39. The method according to any one of claims 31 to 38, wherein, The base station sends the second PDCP PDU to the UE, including: After the first signaling is sent, or after the first signaling is successfully sent, or after the base station receives the reception confirmation message of the first signaling, the base station sends the second PDCP PDU to the UE.
40. A communication device, the device comprising: A sending module and a receiving module; The sending module is used to send an RRC reestablishment request message to the base station; The receiving module is used to receive the first MAC CE from the base station; Wherein, the first MAC CE includes an NCC and a first byte stream, the first byte stream includes an encrypted RRC reestablishment message, and the RRC reestablishment message is used to instruct the UE to reestablish an RRC connection.
41. The apparatus according to claim 40, wherein, The device further includes: a parsing module, a transmission module, a processing module, and a request module; The parsing module is used to parse the first MAC CE to obtain the NCC and the first byte stream after the receiving module receives the first MAC CE from the base station; The transmission module is used to transmit the NCC and the first byte stream parsed by the parsing module to the RRC layer of the UE; The processing module is used to update the key used by the UE based on the NCC transmitted by the transmission module, and generate a first encryption key and a first integrity protection key based on the updated key; The request module is used to request the PDCP layer of the UE to process the first byte stream based on the first encryption key and the first integrity protection key; The processing module is further used to process the first byte stream based on the first encryption key and the first integrity protection key.
42. The apparatus according to claim 41, wherein, The first byte stream corresponds to a first PDCP PDU, the first PDCP PDU includes an encrypted first MAC-I, and the encrypted first MAC-I is generated by the PDCP layer of the base station by performing an integrity protection operation on the RRC reestablishment message; The processing module is specifically used to parse the first PDCP PDU to obtain the encrypted RRC reestablishment message and the encrypted first MAC-I; and perform a decryption operation on the encrypted RRC reestablishment message and the encrypted first MAC-I through the first encryption key to obtain the decrypted RRC reestablishment message and the decrypted first MAC-I; And perform an integrity protection verification operation on the decrypted RRC reestablishment message through the first integrity protection key and the decrypted first MAC-I.
43. The apparatus according to claim 41, wherein, The first MAC CE includes first information, and the first information is a MAC-I generated by performing an integrity protection operation on the RRC reestablishment message. The processing module is specifically configured to perform a decryption operation on the first byte stream by using the first encryption key to obtain the decrypted RRC reestablishment message; and perform an integrity protection verification operation on the decrypted RRC reestablishment message by using the first integrity protection key and the first information.
44. The device according to claim 41, wherein, The first MAC CE includes second information, and the second information is a MAC-I generated by performing an integrity protection operation on the NCC and the first byte stream. The processing module is specifically configured to perform an integrity protection verification operation on the NCC and the first byte stream by using the first integrity protection key and the second information. And when the integrity protection verification operation on the NCC and the first byte stream performed by the PDCP layer of the UE passes, perform a decryption operation on the first byte stream by using the first encryption key to obtain the decrypted RRC reestablishment message.
45. The apparatus according to any one of claims 42 to 44, wherein, The parameters used by the PDCP layer of the UE to perform the decryption operation and the integrity protection verification operation are the first parameter or the first parameter set. Wherein, the first parameter or the first parameter set includes at least one of the following: the COUNT value is 0, the BEARER is the bearer identifier of the radio signaling bearer SRB1, and the DIRECTION is the downlink direction.
46. The apparatus according to claim 45, wherein, The processing module is further configured to set the first variable maintained by the PDCP entity corresponding to the SRB1 to 1 or increment it by 1, and the first variable is a variable corresponding to the COUNT value of the next expected received PDCP service data unit (SDU).
47. The device according to claim 43 or 44, wherein, The parameters used by the PDCP layer of the UE to perform the decryption operation and the integrity protection verification operation are the second parameter or the second parameter set. Wherein, the second parameter or the second parameter set includes at least one of the following: all bits of the COUNT value are 1, all bits of the BEARER value are 1, and the DIRECTION is the downlink direction.
48. The device according to any one of claims 42 to 44, wherein, The processing module is further configured to enter the idle state when the integrity protection verification operation fails in the PDCP layer of the UE after processing the first byte stream based on the first encryption key and the first integrity protection key. The transmission module is further configured to transmit the decrypted RRC reestablishment message to the RRC layer of the UE when the integrity protection verification operation passes in the PDCP layer of the UE after the processing module processes the first byte stream based on the first encryption key and the first integrity protection key.
49. The apparatus according to claim 48, wherein, The processing module is further configured to reestablish an RRC connection based on the decrypted RRC reestablishment message after the transmission module transmits the decrypted RRC reestablishment message to the RRC layer of the UE. The sending module is further configured to send an RRC reestablishment complete message to the base station, and the RRC reestablishment complete message is a message processed by the PDCP layer of the UE by using the first encryption key and the first integrity protection key.
50. The apparatus according to claim 49, wherein, The processing module is specifically configured to re - establish an RRC connection according to the decrypted RRC re - establishment message when the NCC in the first MAC CE is the same as the NCC in the RRC re - establishment message.
51. A communication device, the device comprising: A receiving module and a sending module; The receiving module is configured to receive an RRC re - establishment request message from a UE; The sending module is configured to send a first MAC CE to the UE; Wherein, the first MAC CE includes an NCC and a first byte stream, and the first byte stream includes an encrypted RRC re - establishment message, and the RRC re - establishment message is used to instruct the UE to re - establish an RRC connection.
52. The apparatus according to claim 51, wherein, The apparatus further includes: a processing module and an indication module; The processing module is configured to update the key used by the base station and generate a first encryption key and a first integrity protection key based on the updated key after the receiving module receives an RRC re - establishment request message from the UE; The indication module is configured to instruct the PDCP layer of the base station to restore integrity protection and encryption using the first encryption key and the first integrity protection key generated by the processing module; The processing module is further configured to generate the RRC re - establishment message and request the PDCP layer of the base station to perform security protection on the RRC re - establishment message.
53. The apparatus according to claim 52, wherein, The apparatus further includes: a transfer module and a generation module; The processing module is further configured to perform security protection on the RRC re - establishment message, generate the first byte stream, and transfer the first byte stream to the RRC layer of the base station after generating the RRC re - establishment message and requesting the PDCP layer of the base station to perform security protection on the RRC re - establishment message. The first byte stream includes the RRC re - establishment message protected by security, and the security protection includes at least one of the following: an encryption operation, an integrity protection operation; The transfer module is configured to transfer the first byte stream and the NCC saved in the UE context of the UE to the MAC layer of the base station; The generation module is configured to generate the first MAC CE based on the NCC and the first byte stream.
54. The apparatus according to claim 53, wherein, The generation module is specifically configured to perform an integrity protection operation on the RRC re - establishment message through the first integrity protection key to generate a first MAC - I; and perform an encryption operation on the RRC re - establishment message and the first MAC - I through the first encryption key to generate a first PDCP PDU. The first PDCP PDU corresponds to the first byte stream, and the first PDCP PDU includes the encrypted RRC re - establishment message and the first MAC - I.
55. The device according to claim 53, wherein, The processing module is specifically configured to perform an encryption operation on the RRC re - establishment message through the first encryption key to generate the first byte stream; and perform an integrity protection operation on the RRC re - establishment message through the first integrity protection key to generate a first piece of information, and the first piece of information is a MAC - I generated by performing an integrity protection operation on the RRC re - establishment message. and transmitting the first byte stream and the first information to the RRC layer of the base station; Wherein, the first MAC CE generated by the MAC layer of the base station includes the first byte stream, the NCC, and the first information, and the first information is transmitted by the RRC layer of the base station to the MAC layer of the base station.
56. The device according to claim 53, wherein, The apparatus further comprises: a request module; The request module is configured to request the PDCP layer of the base station to perform an integrity protection operation on the NCC and the first byte stream before the transmission module transmits the first byte stream and the NCC saved in the UE context of the UE to the MAC layer of the base station; The processing module is further configured to perform an integrity protection operation on the NCC and the first byte stream by using the first integrity protection key, generate a second MAC-I, and transmit the second MAC-I to the RRC layer of the base station; Wherein, the first MAC CE generated by the MAC layer of the base station includes the first byte stream, the NCC, and the second MAC-I, and the second MAC-I is transmitted by the RRC layer of the base station to the MAC layer of the base station.
57. The apparatus according to claim 53, wherein, The apparatus further comprises: a request module; The request module is configured to request the PDCP layer of the base station to perform an integrity protection operation on the NCC and the first byte stream before the generation module generates the first MAC CE based on the NCC and the first byte stream; The processing module is configured to perform integrity protection on the NCC and the first byte stream by using the first integrity protection key, generate a third MAC-I, and transmit the third MAC-I to the MAC layer of the base station; Wherein, the first MAC CE generated by the MAC layer of the base station includes the first byte stream, the NCC, and the third MAC-I.
58. The apparatus according to any one of claims 54 to 57, wherein, The parameters used by the PDCP layer of the base station to perform encryption operations and integrity protection operations are the first parameter or the first parameter set; Wherein, the first parameter or the first parameter set includes at least one of the following: the COUNT value is 0, the BEARER is the bearer identifier of the radio signaling bearer SRB1, and the DIRECTION is the downlink direction.
59. The apparatus according to claim 58, wherein, The processing module is further configured to set the second variable maintained by the PDCP entity corresponding to the SRB1 to 1 or increment it by 1, and the second variable is the variable corresponding to the COUNT value of the next PDCP service data unit SDU to be sent.
60. The apparatus according to any one of claims 55 to 57, wherein, The parameters used by the PDCP layer of the base station to perform encryption operations and integrity protection operations are the second parameter or the second parameter set; Wherein, the second parameter or the second parameter set includes at least one of the following: all bits of the COUNT value are 1, all bits of the BEARER value are 1, and the DIRECTION is the downlink direction.
61. A communication device, the device comprising: A transmission module, a reception module, a processing module, and an indication module; The transmission module is configured to send an RRC reestablishment request message to the base station; The receiving module is configured to receive a first signaling from the base station, where the first signaling is used to request the UE to update the key used by the UE, the first signaling includes an NCC, and the first signaling is a second MAC CE or a PDCP control PDU; The processing module is configured to update the key used by the UE based on the NCC, and generate a first encryption key and a first integrity protection key based on the updated key; The indicating module is configured to instruct the PDCP layer of the UE to use the first encryption key and the first integrity protection key generated by the processing module to restore integrity protection and encryption; The processing module is further configured to, after the PDCP layer of the UE restores integrity protection and encryption using the first encryption key and the first integrity protection key, process a second PDCP PDU from the base station, where the second PDCP PDU includes an RRC reestablishment message that is integrity-protected and encrypted, and the RRC reestablishment message is used to instruct the UE to reestablish an RRC connection.
62. The device according to claim 61, wherein, The first signaling includes a third information, where the third information is a MAC-I generated by performing an integrity protection operation on the NCC; the indicating module is specifically configured to request the PDCP layer of the UE to perform an integrity protection verification operation on the NCC using the first integrity protection key and the third information; and perform an integrity protection verification operation on the NCC using the first integrity protection key and the third information; And in the case that the integrity protection verification operation on the NCC by the PDCP layer of the UE is passed, the RRC layer of the UE instructs the PDCP layer of the UE to restore integrity protection and encryption using the first encryption key and the first integrity protection key.
63. The device according to claim 62, wherein, The processing module is further configured to enter an idle state in the case that the integrity protection verification operation on the NCC by the PDCP layer of the UE fails.
64. The apparatus according to claim 62, wherein, The parameters used by the PDCP layer of the UE to perform the integrity protection verification operation on the NCC are a second parameter or a second parameter set; Wherein, the second parameter or the second parameter set includes at least one of the following: all bits of the COUNT value are 1, all bits of the BEARER value are 1, and the DIRECTION is a downlink direction.
65. The apparatus according to claim 61, wherein, In the case that the first signaling is a second MAC CE, the receiving module is specifically configured to receive the second MAC CE from the base station; and parse the second MAC CE to obtain the NCC, and deliver the NCC to the RRC layer of the UE.
66. The apparatus according to claim 61, wherein, In the case that the first signaling is a PDCP control PDU, the receiving module is specifically configured to receive a PDCP control PDU from the base station; and parse the PDCP control PDU to obtain the NCC, and deliver the NCC to the RRC layer of the UE.
67. The device according to claim 61, wherein, The processing module is specifically configured to perform a decryption operation and an integrity protection verification operation on the second PDCP PDU by using the first encryption key and the first integrity protection key, and deliver the decrypted RRC reestablishment message to the RRC layer of the UE.
68. The apparatus according to claim 67, wherein The processing module is further configured to reestablish an RRC connection based on the decrypted RRC reestablishment message; The sending module is further configured to send the RRC reestablishment complete message to the base station, where the RRC reestablishment complete message is a message processed by the PDCP layer of the UE by using the first encryption key and the first integrity protection key.
69. A communication device, the device comprising: A receiving module and a sending module; The receiving module is configured to receive an RRC reestablishment request message from the UE; The sending module is configured to send a first signaling to the UE, where the first signaling is used to request the UE to update the key used by the UE, the first signaling includes an NCC, and the first signaling is a second MAC CE or a PDCP control PDU; And send a second PDCP PDU to the UE, where the second PDCP PDU includes an integrity-protected and encrypted RRC reestablishment message, and the RRC reestablishment message is used to instruct the UE to reestablish an RRC connection.
70. The apparatus according to claim 69, wherein, The apparatus further includes: a processing module and an indication module; the processing module is configured to update the key used by the base station and generate a first encryption key and a first integrity protection key based on the updated key before the sending module sends the second PDCP PDU to the UE; The indication module is configured to instruct the PDCP layer of the base station to restore integrity protection and encryption by using the first encryption key and the first integrity protection key generated by the processing module.
71. The apparatus according to claim 69, wherein, The apparatus further includes: a transfer module and a generation module; The transfer module is configured to transfer the NCC saved in the UE context of the UE to the MAC layer of the base station; The generation module is configured to generate the second MAC CE based on the NCC transferred by the transfer module, where the second MAC CE is used to request the UE to update the key used by the UE, and the second MAC CE includes the NCC; The sending module is specifically configured to send the second MAC CE generated by the generation module to the UE.
72. The apparatus according to claim 71, wherein, The transfer module is specifically configured to request the PDCP layer of the base station to perform an integrity protection operation on the NCC by using the first integrity protection key; and perform an integrity protection operation on the NCC by using the first integrity protection key to generate a fourth MAC-I, and transfer it to the RRC layer of the base station; and transfer the NCC and the fourth MAC-I to the MAC layer of the base station; Wherein, the second MAC CE includes the NCC and the fourth MAC-I.
73. The apparatus according to claim 71, wherein, The generating module is specifically configured to request the PDCP layer of the base station to perform an integrity protection operation on the NCC by using the first integrity protection key; and perform an integrity protection operation on the NCC by using the first integrity protection key to generate a fifth MAC-I, and transmit it to the MAC layer of the base station; and generate the second MAC CE based on the NCC and the fifth MAC-I, where the second MAC CE includes the NCC and the fifth MAC-I.
74. The apparatus according to claim 69, wherein, The apparatus further includes: a transmission module and a generating module; The transmission module is configured to transmit the NCC saved in the UE context of the UE to the PDCP layer of the base station; The generating module is configured to generate the PDCP control PDU based on the NCC transmitted by the transmission module, where the PDCP control PDU is used to request the UE to update the key used by the UE, and the PDCP control PDU includes the NCC; The sending module is specifically configured to send the PDCP control PDU generated by the generating module to the UE.
75. The apparatus according to claim 74, wherein, The generating module is specifically configured to perform an integrity protection operation on the NCC by using the first integrity protection key to generate a sixth MAC-I; and generate the PDCP control PDU based on the NCC and the sixth MAC-I, where the PDCP control PDU includes the sixth MAC-I.
76. The device according to claim 72 or 73 or 75, wherein, The parameters used by the PDCP layer of the base station to perform an integrity protection operation on the NCC are the second parameter or the second parameter set; wherein, the second parameter or the second parameter set includes at least one of the following: all bits of the COUNT value are 1, all bits of the BEARER value are 1, and the DIRECTION is the downlink direction.
77. The apparatus according to claim 70, wherein, The sending module is specifically configured to generate the RRC reestablishment message and transmit it to the PDCP layer of the base station; and perform an encryption operation and an integrity protection operation on the RRC reestablishment message by using the first encryption key and the first integrity protection key to generate the second PDCP PDU; and transmit the second PDCP PDU to the radio link control RLC layer of the base station; and send the second PDCP PDU to the UE.
78. The apparatus according to any one of claims 70 to 77, wherein, The sending module is specifically configured to send the second PDCP PDU to the UE after the first signaling is sent, or after the first signaling is successfully sent, or after the base station receives the reception confirmation message of the first signaling.
79. A user equipment, including a processor and a memory, where the memory stores a program or instruction that can run on the processor, and when the program or instruction is executed by the processor, the steps of the communication method according to any one of claims 1 to 11 are implemented.
80. A user equipment, including a processor and a memory, where the memory stores a program or instruction that can run on the processor, and when the program or instruction is executed by the processor, the steps of the communication method according to any one of claims 22 to 29 are implemented.
81. A base station, comprising a processor and a memory, wherein the memory stores a program or instructions that can be run on the processor, and when the program or instructions are executed by the processor, the steps of the communication method according to any one of claims 12 to 21 are implemented.
82. A base station, comprising a processor and a memory, wherein the memory stores a program or instructions that can be run on the processor, and when the program or instructions are executed by the processor, the steps of the communication method according to any one of claims 30 to 39 are implemented.
83. A readable storage medium, on which a program or instructions are stored, and when the program or instructions are executed by a processor, the steps of the communication method according to any one of claims 1 to 11 are implemented, or the steps of the communication method according to any one of claims 12 to 21 are implemented, or the steps of the communication method according to any one of claims 22 to 29 are implemented, or the steps of the communication method according to any one of claims 30 to 39 are implemented.
Citation Information
Patent Citations
Network access method, terminal equipment and network equipment
CN109802809A
Security updating method, network equipment and terminal
CN110830988A
Method for reconstructing RRC connection, base station, mobile terminal and storage medium
CN110831255A