Security key update method and apparatus
By performing security key updates during the LTM cell change process, the inter-cell mobility problem of LTM operations only supporting the same gNB is solved, and the security and communication interruption time between different gNBs are achieved.
Patent Information
- Application Number
- PCT/CN2024/075081
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-01-31
- Publication Date
- 2025-08-07
AI Technical Summary
Existing LTM operations only support inter-cell mobility of the same gNB, limiting its usage opportunities, and security updates must perform L3HO, resulting in a larger communication interruption time.
A security key update method and device are provided, which obtains AS security-related configurations from the first device through the receiving unit and performs security key updates during the LTM cell change process, supports inter-CU/gNB's LTM and subsequent LTM to ensure security while reducing communication interruptions.
Inter-cell LTM operation between different gNBs is realized, ensuring security and reducing communication interruption time.
Smart Images

Figure CN2024075081_07082025_PF_FP_ABST
Abstract
Description
Security key updating method and device Technical Field
[0001] The embodiments of the present application relate to the field of communication technologies. Background Art
[0002] Network-controlled mobility applies to connected terminals and can be categorized into two types: cell-level mobility and beam-level mobility. Figure 1 illustrates an inter-cell mobility scenario. As shown in Figure 1, when a terminal moves from one cell's coverage area to another, a serving cell change is required at some point.
[0003] Currently, serving cell changes are triggered by L3 measurements and completed via RRC (Radio Resource Control) signaling. Reconfiguration with Synchronization is also being triggered for PCell (Primary Cell) and PSCell (Special Cell) changes, as well as the release of SCells (Secondary Cells) when applicable. Cell-level mobility is now triggered by explicit RRC signaling, known as handover. The RRC-triggered handover mechanism requires the UE (terminal equipment, user equipment, terminal, user, etc.) to at least reset the MAC (Media Access Control) entity and re-establish the RLC (Radio Link Control). RRC-managed handovers are supported with and without re-establishment of the PDCP (Packet Data Convergence Protocol) entity. For DRBs (Data Radio Bearers) using RLC AM (RLC Acknowledged Mode), PDCP can either re-establish with security key update or initiate data recovery without key update. For DRBs using RLC UM (RLC Unacknowledged Mode), PDCP can re-establish with security key update or remain unchanged without key update. For SRBs (Signaling Radio Bearers), PDCP can remain unchanged without key update, discard stored PDCP PDUs (Packet Data Units) / SDUs (Service Data Units), or re-establish with security key update.
[0004] For RRC-triggered handover mechanisms, all cases involve a complete L2 (and L1) reset, resulting in longer latency, greater overhead, and longer disruption than beam switching mobility. The goal of L1 (Layer 1) / L2 (Layer 2) mobility enhancements is to ensure that serving cell changes via L1 / L2 signaling reduce latency, overhead, and disruption.
[0005] It should be noted that the above introduction to the technical background is merely intended to provide a clear and complete description of the technical solutions of this application and facilitate understanding by those skilled in the art. Simply because these solutions are described in the background technology section of this application, it should not be assumed that the above technical solutions are well known to those skilled in the art.
[0006] Summary of the Invention
[0007] Regarding New Radio (NR) mobility enhancements, Rel-18 introduced Layer 1 / 2 Triggered Mobility (LTM). Compared to Layer 3-based mobility, LTM can provide improvements in handover latency and interruption time. However, LTM introduced in Rel-18 also has some limitations compared to Layer 3-based mobility. The Rel-19 work item aims to eliminate these limitations.
[0008] Currently, LTM operation only supports inter-cell mobility within the same gNB (also known as base station, network equipment, or network) (same CU). This significantly limits the opportunities for LTM use, depending on network deployment scenarios. By enabling LTM operation between cells of different gNBs (i.e., inter-CU), the network will be able to reap the benefits of LTM for a wider range of handovers.
[0009] Layer 3 mobility has evolved over several releases, including conditional handover (CHO) and other conditional mobility procedures (such as CPAC and SCPAC). These procedures achieve high robustness by ensuring that no prior signaling interaction with the source cell is required. LTM, introduced in Release 18, offers short outage times but is not as robust as Layer 3 conditional mobility procedures.
[0010] In Rel-19, enhancements should be defined so that the system can benefit from high robustness and short outages. The objectives of this work item include: defining support for inter-CU Layer 2 Mobility (LTM), measurement-related enhancements to support LTM, defining support conditions for LTM, and, if necessary, defining RRM (Radio Resource Management) requirements related to the above objectives.
[0011] In the above objectives, support for inter-CU Layer 2 Mobility (LTM) is defined including:
[0012] Prioritize the case where the CU (Central Unit) acts as the MN (Master Node) when DC (Dual Connectivity) is not configured;
[0013] As a secondary priority, it supports the configuration of NR-DC, CU as SN (Secondary Node) and the MN remains unchanged;
[0014] As a secondary priority, it supports the configuration of NR-DC and CU as MN and the SCG (Secondary Cell Group) remains unchanged or is released. Note: This excludes the case where both MCG (Master Cell Group) and SCG are configured with LTM.
[0015] According to Rel-18 LTM, support for subsequent LTM mobility procedures is defined, with the goal of avoiding inter-cell RRC (Radio Resource Control) configuration; and security key handling is negotiated with SA3 (Security Group).
[0016] Among the above objectives, it is worth noting that the Rel-18 intra-CU LTM process is considered as a baseline for increasing inter-CU support.
[0017] In the above objectives, the definition of supporting conditions LTM includes:
[0018] Define the conditions for triggering LTM evaluated by the UE;
[0019] The goal is to support conditional LTM that includes subsequent LTM;
[0020] Prioritize intra-CU LTM;
[0021] RAN#105 is the checkpoint for the review. RAN WG work will not begin before this checkpoint.
[0022] Furthermore, LTM is a process in which the gNB receives L1 measurement reports from the UE. Based on these reports, the gNB changes the UE's serving cell via a cell change command sent via a MAC Control Element (MAC CE). The MAC-triggered cell change mechanism (i.e., LTM cell switch) requires the UE to at least reset the MAC entity. The RLC handling depends on the network configuration.
[0023] Figure 2 is a schematic diagram of the overall LTM process. The basic process over the air interface applies to both MCG LTM and SCG LTM. As shown in Figure 2, the process includes the following steps:
[0024] 1. The UE sends a MeasurementReport message to the gNB, in which the gNB-CU decides to configure LTM and initiates LTM preparation.
[0025] 2. The gNB sends an RRCReconfiguration message to the UE including the LTM candidate configuration.
[0026] 3. The UE stores the LTM candidate configuration and sends an RRCReconfigurationComplete message to the gNB.
[0027] 4a. Before receiving the cell change command, the UE performs DL (Downlink, downlink, referred to as downlink) synchronization with the candidate cell;
[0028] 4b. When UE-based TA (Timing Advance) measurement is configured, the UE obtains the TA value of the candidate cell through measurement;
[0029] It is worth noting that before receiving the cell change command, the UE performs an early TA acquisition with the candidate cell at the request of the network. This is done through CFRA (Contention Free Random Access), which is triggered by the PDCCH (Physical Downlink Control Channel) command of the source cell, and then the UE sends a preamble to the indicated candidate cell, as shown in Figure 3, which is a schematic diagram of the random access process. In order to minimize the data interruption of the source cell caused by the CFRA to the candidate cell, the UE does not receive a random access response from the network for the purpose of obtaining the TA value of the candidate cell indicated in the cell change command. The UE does not maintain the TA timer of the candidate cell, but relies on the network implementation to ensure the validity of the TA.
[0030] 5. The UE performs L1 measurements on the configured candidate cells and sends an L1 measurement report to the gNB. L1 measurements should be performed whenever RRC reconfiguration (step 2) is applicable.
[0031] 6. The gNB decides to perform a cell handover to a target cell and sends a MAC CE triggering a cell handover including the candidate configuration index of the target cell. The UE switches to the target cell and applies the configuration indicated by the candidate configuration index.
[0032] 7. If the UE does not have a valid TA for the target cell, the UE performs a random access procedure to the target cell;
[0033] 8. The UE completes the LTM cell handover process by sending an RRCReconfigurationComplete message to the target cell.
[0034] It is worth noting that if the UE performs a random access procedure in step 7, the UE considers the LTM cell handover to have been successfully completed when the random access procedure is successfully completed. For RACH-less LTM, that is, when step 7 is not performed, the UE considers the LTM cell handover to have been successfully completed when it determines that the network has successfully received its first UL data.
[0035] In addition, for the random access procedure on LTM candidate cells used for early UL TA acquisition, a CFRA triggered by a PDCCH order is used. The UE sends MSG1 (Message 1) to the cell and does not listen for responses from the cell. To support UE power ramping, the UE can retransmit MSG1 as instructed by the network.
[0036] In addition, for subsequent LTM, the LTM candidate configuration provided in step 2 can be used to perform steps 4 to 8 multiple times, that is, the subsequent LTM is achieved by repeating the early synchronization, LTM cell switching execution and LTM cell switching completion steps and not releasing other LTM candidate configurations after each LTM cell switching is completed.
[0037] The inventors have found that LTM operation only supports mobility between cells of the same gNB (same CU). The following situations are supported:
[0038] Case 1: Synchronous reconfiguration with LTM cell change (without security key refresh), and
[0039] Involving or not involving RA of target LTM candidate special cells according to network instructions;
[0040] MAC reset;
[0041] Depending on network indication, RLC re-establishment and PDCP data recovery (for AM DRB);
[0042] Case 2: Synchronous reconfiguration with LTM cell change (without security key refresh), and
[0043] Involving or not involving RA of target LTM candidate special cells according to network instructions;
[0044] MAC reset;
[0045] Depending on network indication, there is no RLC re-establishment.
[0046] When LTM cell change is executed, if the LTM is triggered on the MCG, the UE does not release or clear the access stratum (AS) security configuration associated with the master key. For each SRB / DRB using the master key in the current UE configuration, the associated PDCP and SDAP entities and their state variables, buffers, and timers are retained. All fields related to the SRB / DRB configuration except for the srb-Identity and drb-Identity are released. Therefore, the current LTM operation uses the same AS security before and after the cell change, that is, security updates / changes are not supported.
[0047] However, depending on the network deployment scenario, this significantly limits the opportunities for using LTM. By ensuring LTM operation between cells of different gNBs (i.e., inter-CU), the network will be able to benefit from LTM for many more handovers. In addition, security updates must be performed using L3HO, which incurs significant downtime.
[0048] To address at least one of the above problems or other similar problems, an embodiment of the present application provides a secure key update method and apparatus, which is used at least for inter-CU / gNB LTM and subsequent LTM, and can also be used for intra-CU / gNB LTM and subsequent LTM, to ensure security while reducing communication interruptions.
[0049] According to one aspect of an embodiment of the present application, a security key updating apparatus is configured on a second device, wherein the apparatus includes:
[0050] a receiving unit configured to receive a first configuration related to AS security from a first device;
[0051] A processing unit is configured to perform an LTM cell change process, wherein the LTM cell change process includes the second device performing a security key update process according to the first configuration and / or the first information.
[0052] One of the beneficial effects of the embodiments of the present application is that according to the embodiments of the present application, security is guaranteed while reducing communication interruptions.
[0053] With reference to the following description and accompanying drawings, specific embodiments of the present application are disclosed in detail, indicating the manner in which the principles of the present application can be employed. It should be understood that the embodiments of the present application are not limited in scope. Within the spirit and scope of the appended claims, the embodiments of the present application include many variations, modifications and equivalents.
[0054] Features described and / or illustrated with respect to one embodiment may be used in the same or similar manner in one or more other embodiments, combined with features in other embodiments, or substituted for features in other embodiments.
[0055] It should be emphasized that the term "include / comprising" when used herein refers to the presence of features, integers, steps or components, but does not exclude the presence or addition of one or more other features, integers, steps or components. BRIEF DESCRIPTION OF THE DRAWINGS
[0056] The elements and features described in one figure or one embodiment of the present application can be combined with the elements and features shown in one or more other figures or embodiments. In addition, in the accompanying drawings, similar reference numerals represent corresponding parts in several figures and can be used to indicate corresponding parts used in more than one embodiment.
[0057] FIG1 is a schematic diagram of an inter-cell mobility scenario based on L1 / L2;
[0058] FIG2 is a schematic diagram of the LTM process;
[0059] FIG3 is a schematic diagram of a random access process;
[0060] FIG4 is a schematic diagram of a key acquisition process;
[0061] FIG5 is a schematic diagram of a model for switching key chains;
[0062] FIG6 is a schematic diagram of an inter-CU LTM scenario;
[0063] FIG7 is a schematic diagram of an intra-CU LTM scenario;
[0064] FIG8 is a schematic diagram of a security key updating method according to an embodiment of the present application;
[0065] 9 to 13 are schematic diagrams of several examples of the second device performing the LTM cell change process according to the method of the embodiment of the present application;
[0066] FIG14 is a schematic diagram of a configuration method for security key update according to an embodiment of the present application;
[0067] FIG15 is a schematic diagram of a security key updating device according to an embodiment of the present application;
[0068] FIG16 is a schematic diagram of a configuration device for updating a security key according to an embodiment of the present application;
[0069] FIG17 is a schematic diagram of a communication system according to an embodiment of the present application;
[0070] FIG18 is a schematic diagram of a terminal device according to an embodiment of the present application;
[0071] Figure 19 is a schematic diagram of a network device according to an embodiment of the present application. DETAILED DESCRIPTION
[0072] The above and other features of the present application will become apparent through the following description with reference to the accompanying drawings. In the description and the accompanying drawings, specific embodiments of the present application are disclosed in detail, which illustrate some embodiments in which the principles of the present application can be adopted. It should be understood that the present application is not limited to the described embodiments. On the contrary, the present application includes all modifications, variations and equivalents that fall within the scope of the appended claims.
[0073] In the embodiments of the present application, the terms "first", "second", etc. are used to distinguish different elements from the name, but do not indicate the spatial arrangement or temporal order of these elements, and these elements should not be limited by these terms. The term "and / or" includes any one and all combinations of one or more of the associated listed terms. The terms "comprising", "including", "having", etc. refer to the presence of the stated features, elements, components or components, but do not exclude the presence or addition of one or more other features, elements, components or components.
[0074] In the embodiments of this application, the singular forms "a," "the," etc. include plural forms and should be broadly understood to mean "a" or "a type" rather than being limited to "one." Furthermore, the term "said" should be understood to include both singular and plural forms, unless the context clearly indicates otherwise. Furthermore, the term "according to" should be understood to mean "at least in part based on...", and the term "based on" should be understood to mean "at least in part based on...", unless the context clearly indicates otherwise.
[0075] In the embodiments of the present application, the term "communication network" or "wireless communication network" may refer to a network that complies with any of the following communication standards, such as Long Term Evolution (LTE), enhanced Long Term Evolution (LTE-A, LTE-Advanced), Wideband Code Division Multiple Access (WCDMA), High-Speed Packet Access (HSPA), etc.
[0076] Furthermore, communication between devices in the communication system may be carried out according to communication protocols of any stage, for example, including but not limited to the following communication protocols: 1G (generation), 2G, 2.5G, 2.75G, 3G, 4G, 4.5G and 5G, New Radio (NR), etc., and / or other communication protocols currently known or to be developed in the future.
[0077] In the embodiments of the present application, the term "network device" refers to, for example, a device in a communication system that connects a terminal device to the communication network and provides services to the terminal device. Network devices may include, but are not limited to, the following devices: base station (BS), access point (AP), transmission reception point (TRP), broadcast transmitter, mobile management entity (MME), gateway, server, radio network controller (RNC), base station controller (BSC), etc.
[0078] Base stations may include, but are not limited to, NodeBs (NBs), evolved NodeBs (eNodeBs or eNBs), and 5G base stations (gNBs), among others. They may also include remote radio heads (RRHs), remote radio units (RRUs), relays or low-power nodes (e.g., femeto, pico, etc.), IAB (Integrated Access and Backhaul) nodes, IAB-DUs, or IAB-donors. The term "base station" may include some or all of these functions, and each base station may provide communication coverage for a specific geographic area. The term "cell" may refer to a base station and / or its coverage area, depending on the context in which the term is used. The terms "cell" and "base station" are interchangeable to avoid confusion.
[0079] In the embodiments of the present application, the term "user equipment" (UE) or "terminal equipment" (TE) refers to, for example, a device that accesses a communication network through a network device and receives network services. A terminal device can be fixed or mobile and may also be referred to as a mobile station (MS), a terminal, a subscriber station (SS), an access terminal (AT), an IAB-MT (Mobile Terminal), a station, and so on.
[0080] Terminal devices may include, but are not limited to, the following devices: cellular phones, personal digital assistants (PDAs), wireless modems, wireless communication devices, handheld devices, machine-type communication devices, laptop computers, cordless phones, smartphones, smart watches, digital cameras, etc.
[0081] For another example, in scenarios such as the Internet of Things (IoT), the terminal device can also be a machine or device for monitoring or measurement, including but not limited to: machine type communication (MTC) terminal, vehicle-mounted communication terminal, device-to-device (D2D) terminal, machine-to-machine (M2M) terminal, and so on.
[0082] In addition, the term "network side" or "network device side" refers to one side of the network, which can be a base station or one or more network devices as described above. The term "user side" or "terminal side" or "terminal device side" refers to the user or terminal side, which can be a UE or one or more terminal devices as described above. Unless otherwise specified herein, "device" can refer to either network equipment or terminal equipment.
[0083] Currently, the following principles apply to secure NR connected to the 5G Core (5GC):
[0084] 1) For user data (DRBs), ciphering provides confidentiality and integrity protection provides integrity.
[0085] 2) For RRC signaling (SRBs), ciphering provides confidentiality of signaling data, and integrity protection provides integrity of signaling data;
[0086] Note: Ciphering and integrity protection are optional, except for RRC signaling, where integrity protection is always configured. Ciphering and integrity protection can be configured on a per-DRB basis, but integrity protection is configured for all DRBs belonging to the same PDU session where User Plane Security Enforcement information indicates that UP integrity protection is required.
[0087] 3) For key management and data processing, any entity handling cleartext will be protected from physical attacks and in a secure environment;
[0088] 4) gNB keys and 5GC (NAS) keys are cryptographically separated;
[0089] 5) Use separate AS (access stratum) and NAS (non-access stratum) level Security Mode Command (SMC) procedures;
[0090] 6) A sequence number (COUNT) is used as input for encryption and integrity protection. A given sequence number can only be used once for a given key in the same direction of the same radio bearer (unless it is the same retransmission).
[0091] For keys and key acquisition:
[0092] Keys include: AMF keys, NAS signaling keys, gNB keys, UP traffic keys, RRC signaling keys, intermediate keys, etc.
[0093] Among them, the AMF key is recorded as K AMF , which is ME and SEAF from K SEAF Derived; NAS signaling keys include K NASint and K NASenc , K NASint It is ME and AMF from K AMF The key obtained can only be used to protect NAS signaling with a specific integrity algorithm; K NASenc It is ME and AMF from K AMF The obtained key is only used to protect NAS signaling with a specific encryption algorithm; the gNB key is denoted as KgNB , which is ME and AMF from K AMF The obtained key is further obtained by the ME and the source gNB when performing horizontal or vertical key acquisition. gNB ;UP traffic keys include K UPenc and K UPint , K UPenc ME and gNB from K gNB The obtained key can only be used to protect UP traffic between ME and gNB with a specific encryption algorithm, K UPint ME and gNB from K gNB The key obtained is only used to protect UP traffic between ME and gNB with a specific integrity algorithm; RRC signaling keys include K RRCint and K RRCenc , K RRCint ME and gNB from K gNB The key obtained can only be used to protect RRC signaling with a specific integrity algorithm; K RRCenc ME and gNB from K gNB The obtained key is only used to protect RRC signaling with a specific encryption algorithm; Intermediate keys include NH and K gNB *, NH is the key obtained by ME and AMF to provide forward security, K gNB * is the key acquired by the ME and gNB when performing horizontal or vertical key acquisition.
[0094] Primary authentication ensures mutual authentication between UE and network and provides an anchor key, K SEAF From K SEAF During master authentication or NAS key re-keying and key refresh events, K is created. AMF Based on K AMF , when running a successful NAS SMC process, get K NASenc and K NASint .
[0095] When the initial AS security context needs to be established between the UE and gNB, the AMF and UE obtain K gNB and Next Hop parameter (NH). K gNB and NH by K AMF Get. An NCC (NH Chaining Counter) is associated with each K gNBand NH parameters. Each K gNB Correlate the NH value to the corresponding NCC, and from this NH value the K gNB .
[0096] At the initial establishment, from K AMF Directly obtain K gNB , and is considered to be associated with a virtual NH parameter with an NCC value of 0. During initial establishment, the obtained NH value is associated with NCC 1.
[0097] During handover, K is used between the UE and the target gNB. gNB The basis, namely K gNB *, from the currently activated K gNB Or obtained from NH parameters. If K gNB *From the currently activated K gNB This is called a horizontal key derivation and indicates an unincreased NCC to the UE. gNB * From the NH parameter, the derivation is called a vertical key derivation and indicates an increased NCC to the UE. Finally, the new K gNB Afterwards, based on K gNB , get K RRCint , K RRCenc , K UPint and K UPenc . As shown in Figure 4.
[0098] Using such key derivation, knowing K shared with UE gNB The gNB cannot calculate any previous K used by the same UE with the previous gNB gNB , thus providing backward security. Similarly, knowing the K shared with the UE gNB The gNB cannot predict any future K that will be used by another gNB after the same UE has been handed over to another gNB for n or more times. gNB (Because the NH parameter can only be calculated by UE and AMF).
[0099] When vertical key derivation (also called vertical key derivation) is used for mobility, the NH is further bound to the target PCI (physical cell identity) and its frequency ARFCN-DL, which is then used as the K in the target gNB. gNB When using Horizontal key derivation (also called horizontal key derivation) mobility, the currently activated KgNB It is further bound to the target PCI and its frequency ARFCN-DL, and then used as K in the target gNB gNB In both cases, ARFCN-DL is the absolute frequency of the SSB of the target PCell, as shown in Figure 5.
[0100] About AS security key update:
[0101] For MCG / SA:
[0102] If the process is initiated by receiving masterKeyUpdate, if keySetChangeIndicator is set to true, UE will AMF Get or update the key K gNB Otherwise, the UE will use the current key K gNB Or NH, use the nextHopChainingCount value indicated in the received masterKeyUpdate to obtain or update the key K gNB ; UE stores the nextHopChainingCount value; UE obtains the key K gNB The associated key.
[0103] Specifically,
[0104] If masterKeyUpdate in the HO command is set to true,
[0105] If the HO command includes the NASC parameter with K_AMF_change_flag set to 1:
[0106] UE will use the horizontally acquired K AMF and 2 32 -1 NAS COUNT value to derive temporary K gNB .
[0107] The UE will further process the temporary key;
[0108] Otherwise: perform UE processing related to key derivation
[0109] otherwise,
[0110] If the NCC value in the HO Command message received by the UE from the target gNB via the source gNB is equal to the currently active K gNB The associated NCC value, UE will start from the currently activated K gNB And the target PCI and its ARFCN-DL get K gNB * ;
[0111] If the NCC value received by the UE is different from the currently activated K gNB The UE will first synchronize the locally stored NH parameters by iteratively calculating the function defined in the Appendix and increasing the NCC value until it matches the NCC value received from the source gNB via the HO Command message. When the NCC values match, the UE will calculate K from the synchronized NH parameters and the target PCI and its frequency ARFCN-DL. gNB * .
[0112] When communicating with the target gNB, the UE will use K gNB * As K gNB .
[0113] For SCG:
[0114] If the process is initiated by receiving sk-Counter, or the process is initiated by sk-Counter selection performed by subsequent CPAC conditional reconfiguration, the UE will gNB , using the received or selected sk-Counter value, obtain or update the secondary key (SK gNB or SK eNB );UE obtains auxiliary key (SK gNB or SK eNB ) associated with the key.
[0115] Regarding parameter configuration, the standard has the following description:
[0116] Currently, the standard describes the fields of "RRCReconfiguration-IEs" as follows:
[0117] In addition, the standard explains "securityNASC" and "MasterKeyChange" as follows:
[0118] The standard describes "NextHopChainingCount" as follows:
[0119] The standard describes "RadioBearerConfig" as follows:
[0120] The standard describes the "DRB-ToAddMod" and "MRB-ToAddMod" fields as follows:
[0121] The standard describes the fields of "RadioBearerConfig" as follows:
[0122] The standard describes the fields of "SecurityConfig" as follows:
[0123] The standard describes the "SRB-ToAddMod field descriptions" as follows:
[0124] The application scenarios of the embodiments of the present application include inter-CU LTM and intra-CU LTM.
[0125] Figure 6 illustrates an inter-CU LTM scenario. As shown in Figure 6, the UE performs LTM from cell 2 to cell 3, i.e., inter-CU LTM. In inter-CU LTM, as shown in Figure 2, in step 2, the LTM candidate cell configuration includes at least the cell configurations of different CUs. In step 6, the cell change command (MAC CE) indicates that the candidate cell configurations are associated with an inter-CU cell.
[0126] Figure 7 illustrates an intra-CU LTM scenario. As shown in Figures 1 and 7, the UE performs LTM between cells in the same CU, known as intra-CU LTM. In intra-CU LTM, as shown in Figure 2, in step 2, the LTM candidate cell configuration includes at least the cell configuration of the same CU. In step 6, the cell change command (MAC CE) indicates that the candidate cell configuration is associated with an intra-CU cell.
[0127] In addition, in FIG6 , the LTM between cell 1 and cell 2, the LTM between cell 3 and cell 4, and the LTM between cell 5 and cell 6 are all intra-CU LTMs.
[0128] The following describes embodiments of the present application with reference to the accompanying drawings and specific embodiments. In the following description, "if," "in the case of," and "when" can be used interchangeably to avoid confusion. Embodiments of the present application are applicable to at least inter-CU / gNB LTM and subsequent LTM, and can also be applied to intra-CU / gNB LTM and subsequent LTM.
[0129] Embodiments of the first aspect
[0130] The embodiment of the present application provides a security key update method, which is described from the side of the second device. The second device can be a terminal device (UE), or an MT (Mobile Terminal, also known as NCR-MT) in NCR (Network Controlled Repeaters), or an IAB node in IAB (Integrated Access and Backhaul), such as a child node, etc. The following takes the second device as an example of a terminal device. Those skilled in the art should understand that the terminal device below can also be replaced by MT (NCR-MT) or IAB node (IAB node), etc. Correspondingly, the first device can be a network device (network device), or an Fwd (Forward, also known as NCR-Fwd) in NCR, or an IAB host (IAB-donor), IAB node (parent node), etc. in IAB. The following also takes the first device as an example of a network device for description.
[0131] FIG8 is a schematic diagram of a security key update method according to an embodiment of the present application. As shown in FIG8 , the method includes:
[0132] 810: The second device receives a first configuration related to AS security from the first device;
[0133] 820: The second device performs an LTM cell change process, where the LTM cell change process includes the second device performing a security key update process according to the first configuration and / or first information.
[0134] It is worth noting that FIG8 above only schematically illustrates the embodiment of the present application, and the present application is not limited thereto. For example, other operations may be added or some operations may be reduced. Those skilled in the art may make appropriate modifications based on the above content, and are not limited to the description of FIG8 above.
[0135] According to the above embodiment, the second device provides the first device with a first configuration related to AS security. When performing an LTM cell change, the second device performs a security key update process according to the first configuration or according to the first configuration and / or the first information, thereby ensuring security while reducing communication interruptions.
[0136] In some embodiments, the first configuration includes AS-related parameters, which may include at least one of the following:
[0137] One or more MasterKeyUpdate fields;
[0138] One or more {NH,nextHopChainingCount / NCC};
[0139] One or more NHs;
[0140] One or more NCCs.
[0141] In the above embodiment, when the AS-related parameter is one or more MasterKeyUpdate fields, the MasterKeyUpdate field only includes keySetChangeIndicator and nextHopChainingCount, but does not include nas-Container.
[0142] In some embodiments, the first configuration is associated with one or more LTM candidate configurations, and / or the first configuration includes a first identifier or a first index. The first identifier is used to identify the AS security-related parameters. The first index refers to the order in which the AS security-related parameters appear in the first configuration; for example, the first AS security-related parameter that appears first in the first configuration has a first index of 1, the second AS security-related parameter that appears second in the first configuration has a first index of 2, and so on.
[0143] In the above embodiment, the first configuration is associated with one or more LTM candidate configurations, for example, it means: in the LTM candidate configuration (for example, IE LTM-Candidate), the above-mentioned AS-related parameters are included, that is, at least one of the following: one or more MasterKeyUpdate domains; one or more {NH, nextHopChainingCount / NCC}; one or more NHs; one or more NCCs; or, it may also mean: in the LTM candidate configuration (for example, IE LTM-Candidate), at least one of the above-mentioned first identifiers or first indexes is included; or, it may also mean: the LTM candidate configuration includes one or more LTM candidate configuration identifiers (for example, IE LTM-CandidateId).
[0144] In some embodiments, the first configuration may be included in the IE LTM-Candidate.
[0145] In some other embodiments, the first configuration may be included in the IE LTM-Config. For example, the first configuration is in the IE LTM-Config but not in the field ltm-CandidateToAddModList or the IE LTM-Candidate. In other words, the first configuration is outside the field ltm-CandidateToAddModList or the IE LTM-Candidate.
[0146] In some other embodiments, the first configuration may be included in an RRCReconfiguration message. For example, the first configuration is not included in the IE LTM-Config, or the RRCReconfiguration message includes the IE LTM-Config and the first configuration is outside the IE LTM-Config. The first configuration is not included in the IE LTM-Config, which may mean that the RRCReconfiguration message including the first configuration does not include the IE LTM-Config.
[0147] The above embodiments only illustrate the location of the first configuration, but the present application is not limited thereto, and appropriate modifications can be made based on the above embodiments. For example, the above embodiments can be used alone, or one or more of the above embodiments can be combined.
[0148] In this embodiment of the present application, the first information is used to indicate one or more AS security-related parameters of the first configuration. The first information may be received by the second device from a third device. The third device and the first device may be the same or different. For example, the first device may be the gNB (e.g., gNB-CU) where the initial serving cell or source cell is located during the initial LTM, and the third device may be the gNB where the current serving cell or source cell is located during a subsequent (e.g., Inter-CU) LTM.
[0149] In the above embodiment, the first information and the first configuration may be the same, or may be a subset of the first configuration, or may be the first identifier or first index included in the first configuration, for example, the first information indicates the index or identifier of the NH and / or NCC in the first configuration.
[0150] In some possible implementations, the first information is carried by at least one of the following:
[0151] RRC (Radio Resource Control) messages;
[0152] PDCP (Packet Data Convergence Protocol) controls PDU (Packet Data Unit);
[0153] MAC CE (Media Access Control Element) or DCI (Downlink Control Information).
[0154] The RRC message is, for example, an RRCReconfiguration message. The RRCReconfiguration message may not include LTM-Config, but the present application is not limited thereto. The RRCReconfiguration message may also include LTM-Config but the first information is not in or outside the LTM-Config.
[0155] In an embodiment of the present application, in operation 820, the second device performs a security key update process according to the first configuration and / or the first information, and can reuse the existing method, that is, perform a security key update based on the HCC provided by the first configuration and / or the first information, or perform a security key update based on the NH or NH and HCC provided by the first configuration and / or the first information, and can further perform a security key update in combination with the group identifier and / or the cell identifier. The following are respectively explained. Among them, performing a security key update, for example, obtaining or deriving or deducing or determining K gNB For the convenience of explanation, it is collectively referred to as "determining K gNB ”.
[0156] In some embodiments, the second device determines K based on the NCC value included in the first configuration / first information. gNB .
[0157] For example, if the second NCC value received by the second device in the first configuration and / or the first information is equal to the first NCC value, the second device starts from the currently activated K gNB , the target PCI and its frequency ARFCN-DL are obtained (or derived or obtained, etc., the same descriptions below have the same meaning and are not listed one by one) K gNB * , using the K gNB * As the K communicated with the network device (called the first gNB) after the LTM cell change is completed gNB .
[0158] For another example, if the second NCC value received by the second device in the first configuration and / or the first information is different from the first NCC value, the second device first iteratively calculates and increases the NCC value until the increased NCC value matches the second NCC value, synchronizes the locally stored NH parameters, and when the NCC values match, the second device obtains K from the synchronized NH parameters, the target PCI, and its frequency ARFCN-DL. gNB * , using the K gNB *As the first K communicated by the gNB after the LTM cell change is completed gNB .
[0159] In the above example, the second NCC value can be the first NCC value received from the first configuration / first information, or it can be the NCC value selected by the second device from the first configuration / first information. The first NCC value is the current K gNB The associated NCC value, that is, the currently activated K gNB The associated NCC value.
[0160] In the above embodiment, the second device may store the second NCC value, or replace the first NCC value with the second NCC value.
[0161] In the above embodiment, the second device may further remove the second NCC value from the above first configuration / first information.
[0162] In the above embodiment, the second device may also obtain the above K gNB The associated key, such as K RRCenc , K UPenc , K RRCint , K UPint etc., for encryption and / or integrity protection. The relevant contents of these keys have been explained above and will not be repeated here.
[0163] In the above embodiment, the first configuration / first information includes at least one of: one or more MasterKeyUpdate fields; one or more {NH, nextHopChainingCount / NCC}; one or more NCC. Thus, the second device can determine K according to the above NCC value. gNB .
[0164] In the above embodiment, the second device may further determine the K based on a group ID and / or a cell ID. gNB The method is similar to the above embodiment and will not be described again here.
[0165] In the above embodiment, the first information is the same as the first configuration or is a subset of the first configuration.
[0166] In the above embodiment, when the first information is the first identifier and / or first index included in the first configuration, the second device determines the second NCC according to the first identifier and / or first index, and then performs the above judgment and processing, which will not be repeated here.
[0167] In some other embodiments, the second device determines K according to NH included in the first configuration and / or the first information.gNB .
[0168] For example, if the second device receives a second NH in the first configuration and / or the first message and / or the second NH received in the first configuration and / or the first message is different from the first NH or the currently activated K gNB The second device obtains K from the second NH, the target PCI and its frequency ARFCN-DL gNB * , using the K gNB * As the first K communicated by the gNB after the LTM cell change is completed gNB .
[0169] For another example, if the second device does not receive the second NH in the first configuration and / or the first message and / or the second NH received in the first configuration and / or the first message is inconsistent with the first NH or the currently activated K gNB The second device is activated from the first NH or the current K gNB , target PCI and its frequency ARFCN-DL to get K gNB * , using the K gNB * As the first K communicated by the gNB after the LTM cell change is completed gNB .
[0170] In the above example, the second NH value can be the first NH value received from the first configuration / first information, or any NH value received by the second device from the first configuration / first information. The first NH value is the current K gNB The associated NH value, that is, the currently activated K gNB The associated NH value.
[0171] In the above embodiment, the second device may use the second NH value as the activation K gNB , or change the currently activated K gNB Replace with the second NH value above.
[0172] In the above embodiment, the second device may also obtain the above K gNB The associated key, such as K RRCenc , K UPenc , K RRCint , K UPint etc., for encryption and / or integrity protection. The relevant contents of these keys have been explained above and will not be repeated here.
[0173] In the above embodiment, the first configuration and / or the first information includes at least one of the following: one or more {NH, nextHopChainingCount / NCC}; one or more NH. Thus, the second device can determine K according to the above NH value. gNB .
[0174] In the above embodiment, the second device may further determine the K based on a group ID and / or a cell ID. gNB The method is similar to the above embodiment and will not be described again here.
[0175] In the above embodiment, the first information is the same as the first configuration or is a subset of the first configuration.
[0176] In the above embodiment, when the first information is the first identifier and / or first index included in the first configuration, the second device determines the above second NH value based on the first identifier and / or first index, and then performs the above judgment and processing, which will not be repeated here.
[0177] In some further embodiments, the second device determines K based on the NH and NCC included in the first configuration and / or the first information. gNB .
[0178] For example, if the second device receives a second NH in the first configuration and / or the first message and / or the second NH received in the first configuration and / or the first message is different from the first NH or the currently activated K gNB , and if the second NCC associated with the second NH received by the second device in the first configuration and / or the first information is equal to 0 or equal to the currently activated K gNB The first NCC associated with the first NH is equal to the first NH. The second device obtains K from the second NH, the target PCI and its frequency ARFCN-DL. gNB * , using the K gNB * As the first K communicated by the gNB after the LTM cell change is completed gNB .
[0179] For another example, if the second device receives a second NH in the first configuration and / or the first information and / or the second NH received in the first configuration and / or the first information is different from the first NH or the currently activated K gNB , and if the second NCC associated with the second NH received by the second device in the first configuration and / or the first information is not equal to 0 or is different from the currently activated K gNBThe associated first NCC is equal to the first NH, the second device first iteratively calculates and increases the NCC value until the increased NCC value matches the second NCC value received in the first configuration and / or the first information, synchronizes the locally stored NH parameters, and when the NCC values match, the second device obtains K from the synchronized NH parameters, the target PCI and its frequency ARFCN-DL gNB * , using the K gNB * As the first K communicated by the gNB after the LTM cell change is completed gNB .
[0180] For another example, if the second device does not receive the second NH in the first configuration and / or the first message and / or the second NH received in the first configuration and / or the first message is equal to the currently activated K gNB or equal to the first NH, the second device uses the currently activated K gNB Or the first NH, target PCI and its frequency ARFCN-DL to get K gNB * , using the K gNB * As the first K communicated by the gNB after the LTM cell change is completed gNB .
[0181] In the above example, the meanings of the first NCC, the first NH, the second NCC, and the second NH are the same as those mentioned above and are not repeated here.
[0182] In the above embodiment, the second device may store the second NCC value, or replace the first NCC value with the second NCC value.
[0183] In the above embodiment, the second device may further remove the second NCC value from the above first configuration / first information.
[0184] In the above embodiment, the second device may also obtain the above K gNB The associated key, such as K RRCenc , K UPenc , K RRCint , K UPint etc., for encryption and / or integrity protection. The relevant contents of these keys have been explained above and will not be repeated here.
[0185] In the above embodiment, the first configuration and / or the first information at least includes one or more {NH, nextHopChainingCount / NCC} and one or more NCCs, or includes one or more NHs and one or more NCCs. Thus, the second device can determine K according to the above NH and NCC.gNB .
[0186] In the above embodiment, the second device may further determine the K based on a group ID and / or a cell ID. gNB The method is similar to the above embodiment and will not be described again here.
[0187] In the above embodiment, the first information is the same as the first configuration or is a subset of the first configuration.
[0188] In the above embodiment, when the first information is the first identifier and / or first index included in the first configuration, the second device determines the above-mentioned second NH value and second NCC based on the first identifier and / or first index, and then performs the above-mentioned judgment and processing, which will not be repeated here.
[0189] Figures 9 to 13 are schematic diagrams illustrating several examples of a second device performing an LTM cell change process according to the methods of embodiments of the present application. In the following description, the first device is, for example, the source cell or serving cell performing the initial LTM, or the gNB where such a cell is located, and the third device is, for example, the source cell or serving cell performing the initial LTM, or the source cell or serving cell performing the subsequent LTM, or the gNB where such a cell is located.
[0190] As shown in Figure 9, in some examples, the first device configures the NCC for the second device through the above-mentioned first configuration and / or the third device configures the NCC for the second device through the above-mentioned first information. The configuration can be performed after the second device completes the LTM cell change process each time, or it can be pre-configured. For example, the pre-configuration includes: the first device configures a group of NCCs through the first configuration, and the third device indicates or activates one of the NCCs through the first indication, for example, by indicating or activating one of the NCCs by including an index of a certain NCC in a group of NCCs. Therefore, after the second device completes the LTM cell change process each time, for example, changing from cell 1 to cell 2, or from cell 2 to cell 3, or from cell 3 to cell 1, or from cell 1 to cell 4, the second device will compare the configured NCC with the currently activated NCC. gNB The associated NCC is compared, and when the configured NCC is equal to the currently activated K gNB In the case of an associated NCC, from the currently activated K gNB , target PCI and its frequency ARFCN-DL to get K gNB *, use this K gNB *K for communication with the gNB in cell 2 gNB When the configured NCC is different from the currently activated K gNBIn the case of an associated NCC, the second device iteratively calculates and increases the NCC value until the increased NCC value matches the configured NCC value, synchronizes the locally saved NH parameters, and obtains K from the synchronized NH parameters, the target PCI and its frequency ARFCN-DL. gNB *.
[0191] As shown in FIG10 , in some examples, the first device configures multiple NCCs for the second device through the first configuration and / or the third device configures multiple NCCs through the first information, namely NCC1, NCC2, NCC3…. The second device performs the LTM cell change process. When moving from cell 1 to cell 2, the group identifier is not considered and K is determined according to the first configured NCC (NCC1). gNB , or according to the NCC indicated by the first information i , or an NCC selected from a plurality of NCCs in the first configuration according to the first information i Determine K gNB and remove the NCC1 or NCC from the first configuration i Next, when the second device moves from cell 2 to cell 3, or from cell 3 to cell 1, or from cell 1 to cell 4, the group identifier is also not considered, and only the current first NCC or the NCC indicated by the first information is used. k , or an NCC selected from a plurality of NCCs in the first configuration according to the first information k , determine K gNB .
[0192] As shown in FIG11 , in some examples, the first device configures multiple NCCs for the second device through the first configuration and / or the third device configures multiple NCCs for the second device through the first information, namely, NCC1, NCC2, NCC3…. The second device performs the LTM cell change process. When moving from cell 1 to cell 2, considering the group identifier, since cell 1 and cell 2 belong to the same group and have the same group identifier, the second device uses the currently activated K gNB As K gNB Determine K gNB Next, when moving from cell 2 to cell 3, considering the group ID, since cell 2 and cell 3 belong to different groups and have different group IDs, the second device uses the first configured NCC (NCC1) to determine K gNB , or according to the NCC indicated by the first information i , or an NCC selected from a plurality of NCCs in the first configuration according to the first information i Determine K gNB and remove the NCC1 or NCC from the first configuration i (If NCC iIncluding in the first configuration). Next, when moving from cell 3 to cell 1, considering the group ID, since cell 3 and cell 1 belong to different groups and have different group IDs, the second device uses the first configured NCC (NCC2) to determine K gNB , or according to the NCC indicated by the first information k , or an NCC selected from a plurality of NCCs in the first configuration according to the first information k Determine K gNB and remove the NCC2 or NCC from the first configuration k (If NCC k Including in the first configuration). Next, when moving from cell 1 to cell 4, considering the group ID, since cell 1 and cell 4 belong to different groups and have different group IDs, the second device uses the first configured NCC (NCC3) to determine K gNB , or according to the NCC indicated by the first information j , or an NCC selected from a plurality of NCCs in the first configuration according to the first information j Determine K gNB and remove the NCC3 or NCC from the first configuration j (If NCC j included in the first configuration).
[0193] As shown in FIG12, in some examples, the first device configures NH1 and multiple NCCs for the second device through the above-mentioned first configuration and / or the third device configures NH1 and multiple NCCs, namely NCC1, NCC2, NCC3..., for the second device through the above-mentioned first information. The second device performs the LTM cell change process. When moving from cell 1 to cell 2, regardless of the group identifier, the second device uses the configured first NCC (NCC1) to determine K gNB , or according to the NCC indicated by the first information i , or an NCC selected from a plurality of NCCs in the first configuration according to the first information i Determine K gNB and remove the NCC1 or NCC from the first configuration i (If NCC i Including in the first configuration), synchronize the locally saved NH to NH1-1. Next, when moving from cell 2 to cell 3, regardless of the group ID, the cell ID is different, and the second device uses the first NCC (NCC2) of the current configuration to determine K gNB , or according to the NCC indicated by the first information k , or an NCC selected from a plurality of NCCs in the first configuration according to the first information k Determine K gNB and remove the NCC2 or NCC from the first configuration k(If NCC k Including in the first configuration), synchronize the locally saved NH to NH1-2. Next, when moving from cell 3 to cell 1, regardless of the group ID, the cell ID is different, and the second device uses the configured NH (NH1) to determine K gNB , or according to the NCC indicated by the first information j , or an NCC selected from a plurality of NCCs in the first configuration according to the first information j Determine K gNB Next, when moving from cell 1 to cell 3, regardless of the group ID, the cell IDs are different, and the second device uses the locally stored NH (NH1-2) to determine K gNB , or according to the NCC indicated by the first information m , or an NCC selected from a plurality of NCCs in the first configuration according to the first information m Determine K gNB .
[0194] As shown in FIG13 , in some examples, the first device configures NH1 and multiple NCCs, namely NCC1, NCC2, NCC3…, for the second device through the first configuration and / or the third device through the first information. The second device performs the LTM cell change process. When moving from cell 1 to cell 2, the cell identifiers are different, but the group identifiers are the same. The second device uses the currently activated K gNB As K gNB Next, when moving from cell 2 to cell 3, the group ID is different and the cell ID is also different. The second device uses the first configured NCC (NCC1) to determine K gNB , or according to the NCC indicated by the first information k , or an NCC selected from a plurality of NCCs in the first configuration according to the first information k Determine K gNB and remove the NCC1 or NCC from the first configuration k (If NCC k Including in the first configuration), the NH stored locally is synchronized to NH1-1. Next, when moving from cell 3 to cell 1, the group ID is different, the cell ID is also different, but cell 1 is the previous serving cell of the second device, and the second device uses the previous NH (NH1) to determine K gNB Next, when moving from cell 1 to cell 3, the group ID is different, the cell ID is also different, but cell 3 is the previous serving cell of the second device, and the second device uses the locally stored NH (NH1-1) to determine K gNB Next, when moving from cell 3 to cell 4, the cell ID is different, but the group ID is the same. The second device uses the locally stored NH (NH1-1) to determine KgNB .
[0195] The above set ID includes dividing cells into different groups. Cells in the same group do not need to update security keys. Cells with different set IDs need to update security keys when switching. The set ID can also be other groupings, which will not be described here.
[0196] In the above example, if the target cell is the previous serving cell, the previous security key can be used.
[0197] The above is just an example. Based on the contents disclosed in the aforementioned embodiments, those skilled in the art can make reasonable changes, which will not be elaborated here.
[0198] In the embodiment of the present application, the LTM cell change process may be triggered by at least one of the following conditions:
[0199] Instructions from lower levels;
[0200] After RLF (Radio Link Failure) or HOF (Handover Failure);
[0201] Evaluation of the second device.
[0202] For example, upon receiving an indication from a lower layer (e.g., a MAC layer), the second device performs the LTM cell change procedure. For another example, after an RLF or HOF, the second device performs the LTM cell change procedure. For another example, the second device triggers the LTM cell change procedure based on an event evaluation. That is, based on the event evaluation, when the second device determines that a cell change is required, the LTM cell change procedure is triggered.
[0203] According to the aforementioned embodiment, after the LTM cell change process is triggered, the second device may perform a security key update process according to the first configuration and / or the first information.
[0204] The above embodiments are merely exemplary descriptions of the methods of the present application, but the present application is not limited thereto, and appropriate modifications may be made based on the above embodiments. For example, the above embodiments may be used individually, or one or more of the above embodiments may be combined.
[0205] This embodiment of the present application also provides a configuration method for security key updates, which is described from the perspective of a first device. This method is the first device-side processing corresponding to the method of the previous embodiment. The same content as the previous embodiment is not repeated here. The first device can be, for example, a network device, an IAB-donor, or an IAB node (parent node) in an IAB.
[0206] FIG14 is a schematic diagram of a configuration method for updating a security key according to an embodiment of the present application. As shown in FIG14 , the method includes:
[0207] 1410: The first device sends a first configuration related to AS security to the second device. The first configuration is used by the second device to perform a security key update process according to the first configuration and / or first information when performing an LTM cell change process.
[0208] In the above embodiment, the first device may send the above first configuration through RRC signaling. The relevant content of the first configuration has been explained above and will not be repeated here.
[0209] In some embodiments, after the second device completes the LTM cell change execution, the first device may further remove part of the configuration from the first configuration. The AS security-related configuration after the part of the configuration is removed may be the second configuration.
[0210] In some embodiments, the first device may further transmit the first configuration or the second configuration to a third device. The third device may send the first information to the second device.
[0211] In the above embodiment, the first device may be the gNB where the initial serving cell or source cell is located during the initial LTM, and the third device may be the gNB where the current serving cell or source cell is located during the subsequent LTM.
[0212] It is worth noting that FIG14 above only schematically illustrates the embodiment of the present application, and the present application is not limited thereto. For example, other operations may be added or some operations may be reduced. Those skilled in the art may make appropriate modifications based on the above content, and are not limited to the description of FIG14 above.
[0213] According to the method of the embodiment of the present application, security is guaranteed while communication interruptions are reduced.
[0214] Embodiments of the second aspect
[0215] The embodiments of the present application provide a secure key update device, which may be, for example, a second device, or one or more components or assemblies configured on the second device. The second device may be a terminal device, an NCR-MT, or an IAB node (subnode). Since the principle of solving the problem of the device is the same as that of the method shown in FIG. 8 of the embodiment of the first aspect, its specific implementation may refer to the implementation of the method shown in FIG. 8 of the embodiment of the first aspect, and the same content will not be repeated here.
[0216] FIG15 is a schematic diagram of a security key update device according to an embodiment of the present application. As shown in FIG15 , the device 1500 includes:
[0217] A receiving unit 1510 receives a first configuration related to AS security from a first device;
[0218] The processing unit 1520 performs an LTM cell change process, wherein the LTM cell change process includes the processing unit 1520 performing a security key update process according to the first configuration and / or the first information.
[0219] In some embodiments, the first configuration includes AS security-related parameters, and the AS security-related parameters include at least one of the following:
[0220] One or more MasterKeyUpdate fields;
[0221] One or more {NH,nextHopChainingCount / NCC};
[0222] One or more NHs;
[0223] One or more NCCs.
[0224] In the above embodiment, when the AS security-related parameters include one or more MasterKeyUpdate fields, the MasterKeyUpdate fields may include keySetChangeIndicator and nextHopChainingCount, that is, nas-Container is not included.
[0225] In some embodiments, the first configuration is associated with one or more LTM candidate configurations, and / or the first configuration includes a first identifier or a first index.
[0226] In the above embodiment, associating the first configuration with one or more LTM candidate configurations means:
[0227] In the LTM candidate configuration, at least one of the following is included: one or more MasterKeyUpdate fields; one or more {NH, nextHopChainingCount / NCC}; one or more NH; one or more NCC;
[0228] Alternatively, the LTM candidate configuration includes at least one of the above-mentioned first identifiers or first indexes;
[0229] Alternatively, the first configuration includes one or more LTM candidate configuration identifiers.
[0230] In some embodiments, the first configuration includes at least one of:
[0231] IE LTM-Candidate;
[0232] IE LTM-Config;
[0233] RRCReconfiguration message.
[0234] In the above embodiment, the first configuration is included in the IE LTM-Config, including:
[0235] The first configuration is not in the field ltm-CandidateToAddModList or IE LTM-Candidate, or,
[0236] The first configuration is outside the domain ltm-CandidateToAddModList or IE LTM-Candidate.
[0237] In the above embodiment, the first configuration is included in the RRCReconfiguration message, including:
[0238] The first configuration is not in IE LTM-Config, or,
[0239] The RRCReconfiguration message includes the IE LTM-Config, and the first configuration is outside the IE LTM-Config.
[0240] In some embodiments, the receiving unit 1510 further receives the first information from a third device; the first information is used to indicate one or more AS security-related parameters of the first configuration.
[0241] In the above embodiment, the first device may be the gNB where the initial serving cell or source cell is located during the initial LTM; the third device may be the gNB where the current serving cell or source cell is located during the subsequent LTM.
[0242] In some embodiments, the processing unit 1520 performs a security key update process according to the first configuration and / or the first information, including:
[0243] The processing unit 1520 determines K according to the NCC value included in the first configuration and / or the first information. gNB .
[0244] In the above embodiment, optionally, the first configuration and / or the first information may include at least one of the following: one or more MasterKeyUpdate fields; one or more {NH, nextHopChainingCount / NCC}; one or more NCCs.
[0245] In the above embodiment, optionally, the processing unit 1520 determines K according to the NCC value included in the first configuration and / or the first information. gNB , which may include:
[0246] If the second NCC value received by the receiving unit 1510 in the first configuration and / or the first information is equal to the first NCC value, the processing unit 1520 selects the currently activated K gNB , target PCI and its frequency ARFCN-DL to get K gNB * , using the K gNB * As the K for communication with the first gNB after the LTM cell change is completed gNB and / or,
[0247] If the second NCC value received by the receiving unit 1520 in the first configuration and / or the first information is different from the first NCC value, the processing unit 1520 first iteratively calculates and increases the NCC value until the increased NCC value matches the second NCC value, synchronizes the locally stored NH parameter, and when the NCC values match, obtains K from the synchronized NH parameter, the target PCI, and its frequency ARFCN-DL. gNB * , using the K gNB * As the first K communicated by the gNB after the LTM cell change is completed gNB .
[0248] In the above embodiment, optionally, the processing unit 1520 may further store the second NCC value or replace the first NCC value with the second NCC value.
[0249] In the above embodiment, optionally, the processing unit 1520 may further remove the second NCC value from the first configuration and / or the first information.
[0250] In the above embodiment, optionally, the processing unit 1520 may also obtain the above K gNB The associated key. K gNB The associated key may include, for example, at least one of the following: K RRCenc , K UPenc , K RRCint and K UPint .
[0251] In some embodiments, the processing unit 1520 performs a security key update process according to the first configuration and / or the first information, including:
[0252] The processing unit 1520 determines K according to NH included in the first configuration and / or the first information. gNB .
[0253] In the above embodiment, optionally, the first configuration and / or the first information may include at least one of the following: one or more {NH, nextHopChainingCount / NCC}; one or more NH.
[0254] In the above embodiment, optionally, the processing unit 1520 determines K according to NH included in the first configuration and / or the first information. gNB , which may include:
[0255] If the receiving unit 1510 receives a second NH in the first configuration and / or the first information and / or the second NH received in the first configuration and / or the first information is different from the first NH or the currently activated K gNB The processing unit 1520 obtains K from the second NH, the target PCI and its frequency ARFCN-DL gNB * , using the K gNB * As the first K communicated by the gNB after the LTM cell change is completed gNB and / or,
[0256] If the receiving unit 1510 does not receive the second NH in the first configuration and / or the first information and / or the second NH received in the first configuration and / or the first information is inconsistent with the first NH or the currently activated K gNB Similarly, the processing unit 1520 selects the first NH or the currently activated K gNB , target PCI and its frequency ARFCN-DL to get K gNB * , using the K gNB * As the first K communicated by the gNB after the LTM cell change is completed gNB .
[0257] In the above embodiment, optionally, the processing unit 1520 may also use the second NH as the activated K gNB , or change the currently activated K gNB Replaced with the above second NH.
[0258] In the above embodiment, optionally, the processing unit 1520 may also obtain the above K gNB The associated key. gNB The associated key may include, for example, at least one of the following: K RRCenc , K UPenc , K RRCint and K UPint .
[0259] In some embodiments, the processing unit 1520 performs a security key update process according to the first configuration and / or the first information, including:
[0260] The processing unit 1520 determines K according to the NH and NCC included in the first configuration and / or the first information. gNB .
[0261] In the above embodiment, optionally, the first configuration and / or the first information includes one or more {NH, nextHopChainingCount / NCC} and one or more NCCs, or includes one or more NHs and one or more NCCs.
[0262] In the above embodiment, optionally, the processing unit 1520 determines K according to the NH and NCC included in the first configuration and / or the first information. gNB , which may include:
[0263] If the receiving unit 1510 receives a second NH in the first configuration and / or the first information and / or the second NH received in the first configuration and / or the first information is different from the first NH or the currently activated K gNB ,
[0264] If the second NCC associated with the second NH received by the receiving unit 1510 in the first configuration and / or first information is equal to 0 or equal to the currently activated K gNB The associated first NCC is equal to the first NH, and the processing unit 1520 obtains K from the second NH, the target PCI and its frequency ARFCN-DL. gNB * , using the K gNB * As the first K communicated by the gNB after the LTM cell change is completed gNB and / or,
[0265] If the second NCC associated with the second NH received by the receiving unit 1510 in the first configuration and / or first information is not equal to 0 or is different from the currently activated K gNB The associated first NCC is equal to the first NH, the processing unit 1520 first iteratively calculates and increases the NCC value until the increased NCC value matches the second NCC value received in the first configuration and / or the first information, synchronizes the locally stored NH parameters, and when the NCC values match, obtains K from the synchronized NH parameters, the target PCI and its frequency ARFCN-DL gNB * , using the K gNB * As the first K communicated by the gNB after the LTM cell change is completed gNB ;
[0266] If the receiving unit 1510 does not receive the second NH in the first configuration and / or the first information and / or the second NH received in the first configuration and / or the first information is equal to the currently activated K gNB or equal to the first NH, the processing unit 1520 uses the current activation K gNB Or the first NH, target PCI and its frequency ARFCN-DL are obtained by gNB * , using the K gNB * As the first K communicated by the gNB after the LTM cell change is completed gNB .
[0267] In the above embodiment, optionally, the processing unit 1520 may further store the second NCC value or replace the first NCC value with the second NCC value.
[0268] In the above embodiment, optionally, the processing unit 1520 may further remove the second NCC value from the first configuration and / or the first information.
[0269] In the above embodiment, optionally, the processing unit 1520 may also obtain the above K gNB The associated key. gNB The associated key may include, for example, at least one of the following: K RRCenc , K UPenc , K RRCint and K UPint .
[0270] In some embodiments, the processing unit 1520 performs a security key update process according to the first configuration and / or the first information, including:
[0271] The processing unit 1520 determines K according to the NH and / or NCC and the group identifier and / or cell identifier included in the first configuration and / or the first information. gNB .
[0272] In some embodiments, the LTM cell change process is triggered by at least one of the following conditions:
[0273] Instructions from lower levels;
[0274] After RLF or HOF;
[0275] Evaluation of the second device.
[0276] In some embodiments, the first information is the same as the first configuration, or is a subset of the first configuration, or is a first identifier or a first index included in the first configuration.
[0277] In some embodiments, the first information is carried by at least one of the following:
[0278] RRC message;
[0279] PDCP control PDU;
[0280] MAC CE or DCI.
[0281] In the above embodiment, the RRC message is, for example, an RRCReconfiguration message; the RRCReconfiguration message may not include LTM-Config, or the RRCReconfiguration message includes LTM-Config but the above first information is not in the LTM-Config or is outside the LTM-Config.
[0282] The present application also provides a configuration device for updating security keys. The device may be a first device, or may be one or more components or assemblies configured on the first device. The first device may be a network device, an NCR-Fwd, an IAB host, or an IAB node (parent node). Since the principle of solving the problem of the device is the same as that of the method shown in FIG. 14 of the embodiment of the first aspect, its specific implementation may refer to the implementation of the method shown in FIG. 14 of the embodiment of the first aspect, and the same content will not be repeated here.
[0283] FIG16 is a schematic diagram of a configuration device for updating security keys according to an embodiment of the present application. As shown in FIG16 , the device 1600 includes:
[0284] The sending unit 1610 sends a first configuration related to AS security to the second device. The first configuration is used for the second device to perform a security key update process according to the first configuration and / or first information when performing an LTM cell change process.
[0285] In the above embodiment, the sending unit 1610 may send the above first configuration through RRC signaling.
[0286] In some embodiments, as shown in FIG16 , the apparatus 1600 further includes:
[0287] The processing unit 1620 is configured to remove part of the configuration from the first configuration after the second device completes the LTM cell change execution.
[0288] In some embodiments, the sending unit 1610 may further send the first configuration or the AS security-related configuration (second configuration) after removing part of the configuration to the third device.
[0289] In the above embodiment, the first device may be the gNB where the initial serving cell or source cell is located during the initial LTM, and the third device may be the gNB where the current serving cell or source cell is located during the subsequent LTM.
[0290] It is worth noting that the above description only describes the components or modules related to this application, but this application is not limited thereto. The above-mentioned device may also include other components or modules. For the specific content of these components or modules, please refer to the relevant art. In addition, the above-mentioned components or modules can be implemented by hardware facilities such as processors, memories, transmitters, and receivers; the implementation of this application is not limited to this.
[0291] The device according to the embodiment of the present application ensures security while reducing communication interruptions.
[0292] Embodiments of the fourth aspect
[0293] An embodiment of the present application also provides a communication system, including a network device and a terminal device.
[0294] FIG17 is a schematic diagram of a communication system according to an embodiment of the present application, schematically illustrating a situation using a terminal device and a network device as an example. As shown in FIG17 , a communication system 1700 may include a network device 1701 and terminal devices 1702 and 1703. For simplicity, FIG17 illustrates only two terminal devices and one network device as an example, but the embodiments of the present application are not limited thereto.
[0295] In the embodiment of the present application, existing services or future services can be transmitted between the network device 1701 and the terminal devices 1702 and 1703. For example, these services may include but are not limited to: enhanced mobile broadband (eMBB), massive machine type communication (mMTC), and ultra-reliable and low-latency communication (URLLC), etc.
[0296] It is worth noting that Figure 17 shows that both terminal devices 1702 and 1703 are within the coverage range of network device 1701, but the present application is not limited thereto. Both terminal devices 1702 and 1703 may not be within the coverage range of network device 1701, or one terminal device 1702 may be within the coverage range of network device 1701 while the other terminal device 1703 is outside the coverage range of network device 1701.
[0297] In some embodiments, the terminal device includes the apparatus 1500 described in the embodiment of the second aspect, and is configured to execute the method described in FIG8 of the embodiment of the first aspect. Since the method has been described in detail in the embodiment of the first aspect, its content is incorporated herein and will not be repeated.
[0298] The above-mentioned terminal device can be a UE in an intra-DU mobility scenario or an inter-DU mobility scenario, and executes the method described in Figure 8 of the embodiment of the first aspect.
[0299] In some embodiments, the network device includes the apparatus 1600 described in the embodiment of the second aspect, and is configured to execute the method described in FIG14 of the embodiment of the first aspect. Since the method has been described in detail in the embodiment of the first aspect, its content is incorporated herein and will not be repeated.
[0300] The above-mentioned network device can be an intra-DU mobility scenario, including a gNB-DU and a gNB-CU, or a gNB in an inter-DU mobility scenario, including a source gNB-DU, a candidate or target gNB-DU, and a gNB-CU, and executes the method described in Figure 14 of the embodiment of the first aspect.
[0301] An embodiment of the present application also provides a terminal device, which may be, for example, a UE, such as a UE in an intra-DU mobility scenario or an inter-DU mobility scenario, but the present application is not limited thereto and may also be other terminal devices.
[0302] Figure 18 is a schematic diagram of a terminal device according to an embodiment of the present application. As shown in Figure 18 , terminal device 1800 may include a processor 1801 and a memory 1802. Memory 1802 stores data and programs and is coupled to processor 1801. It should be noted that this diagram is exemplary; other types of structures may be used to supplement or replace this structure to implement telecommunication or other functions.
[0303] In some embodiments, the functions of the device 1500 of the embodiment of the second aspect can be integrated into the processor 1801, wherein the processor 1801 can be configured to execute a program to implement the method described in Figure 8 of the embodiment of the first aspect, the content of which is incorporated herein and will not be repeated here.
[0304] In other embodiments, the device 1500 of the embodiment of the second aspect can be configured separately from the processor 1801. For example, the device 1500 of the embodiment of the second aspect can be configured as a chip connected to the processor 1801, and the functions of the device 1500 of the embodiment of the second aspect can be realized through the control of the processor 1801.
[0305] As shown in Figure 18 , the terminal device 1800 may further include: a communication module 1803, an input unit 1804, a display 1805, and a power supply 1806. The functions of these components are similar to those in the prior art and are not described here in detail. It is worth noting that the terminal device 1800 does not necessarily include all of the components shown in Figure 18 , and these components are not essential. Furthermore, the terminal device 1800 may also include components not shown in Figure 18 , for which reference may be made to the relevant art.
[0306] An embodiment of the present application also provides a network device, which may be, for example, a base station, such as a gNB in an intra-DU mobility scenario or an inter-DU mobility scenario, but the present application is not limited thereto and may also be other network devices.
[0307] Figure 19 is a schematic diagram illustrating the structure of a network device according to an embodiment of the present application. As shown in Figure 19 , network device 1900 may include a processor 1901 and a memory 1902 ; the memory 1902 is coupled to the processor 1901 . The memory 1902 may store various data and information processing programs, which are executed under the control of the processor 1901 .
[0308] In some embodiments, the functions of the device 1600 of the embodiment of the second aspect can be integrated into the processor 1901, wherein the processor 1901 can be configured to execute a program to implement the method described in Figure 14 of the embodiment of the first aspect, the content of which is incorporated herein and will not be repeated here.
[0309] In other embodiments, the device 1600 of the embodiment of the second aspect can be configured separately from the processor 1901. For example, the device 1600 of the embodiment of the second aspect can be configured as a chip connected to the processor 1901, and the functions of the device 1600 of the embodiment of the second aspect can be realized through the control of the processor 1901.
[0310] Furthermore, as shown in FIG19 , network device 1900 may further include transceivers 1903 and 1904. The functions of these components are similar to those in the prior art and are not described in detail here. It is worth noting that network device 1900 does not necessarily include all of the components shown in FIG19 ; furthermore, network device 1900 may also include components not shown in FIG19 , for which reference may be made to the prior art.
[0311] An embodiment of the present application also provides a computer program, wherein when the program is executed in a terminal device, the program causes the terminal device to execute the method described in FIG8 of the embodiment of the first aspect.
[0312] An embodiment of the present application further provides a storage medium storing a computer program, wherein the computer program enables a terminal device to execute the method described in FIG. 8 of the embodiment of the first aspect.
[0313] An embodiment of the present application also provides a computer program, wherein when the program is executed in a network device, the program causes the network device to execute the method described in FIG14 of the embodiment of the first aspect.
[0314] An embodiment of the present application further provides a storage medium storing a computer program, wherein the computer program enables the network device to execute the method described in FIG. 14 of the embodiment of the first aspect.
[0315] The above devices and methods of the present application can be implemented by hardware or by a combination of hardware and software. The present application relates to such a computer-readable program that, when executed by a logic component, enables the logic component to implement the devices or components described above, or enables the logic component to implement the various methods or steps described above. The present application also relates to a storage medium for storing the above program, such as a hard disk, a magnetic disk, an optical disk, a DVD, a flash memory, etc.
[0316] The method / device described in conjunction with the embodiments of the present application can be directly embodied as hardware, a software module executed by a processor, or a combination of the two. For example, one or more of the functional block diagrams shown in the figure and / or one or more combinations of functional block diagrams can correspond to various software modules of the computer program flow or to various hardware modules. These software modules can respectively correspond to the various steps shown in the figure. These hardware modules can be implemented by solidifying these software modules, for example, using a field programmable gate array (FPGA).
[0317] The software module may be located in RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art. A storage medium may be coupled to a processor so that the processor can read information from the storage medium and write information to the storage medium; or the storage medium may be an integral part of the processor. The processor and the storage medium may be located in an ASIC. The software module may be stored in the memory of the mobile terminal or in a memory card that can be inserted into the mobile terminal. For example, if the device (such as a mobile terminal) uses a large-capacity MEGA-SIM card or a large-capacity flash memory device, the software module may be stored in the MEGA-SIM card or the large-capacity flash memory device.
[0318] One or more of the functional blocks and / or one or more combinations of functional blocks described in the accompanying drawings may be implemented as a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component, or any appropriate combination thereof for performing the functions described in this application. One or more of the functional blocks and / or one or more combinations of functional blocks described in the accompanying drawings may also be implemented as a combination of computing devices, such as a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors in communication with a DSP, or any other such configuration.
[0319] The present application has been described above in conjunction with specific embodiments. However, those skilled in the art should understand that these descriptions are merely illustrative and are not intended to limit the scope of protection of the present application. Those skilled in the art may make various modifications and variations to the present application based on the spirit and principles of the present application, and such modifications and variations are also within the scope of the present application.
[0320] Regarding the implementation methods including the above embodiments, the following additional notes are also disclosed:
[0321] 1. A method for updating a security key, wherein the method comprises:
[0322] The second device receives a first configuration related to AS security from the first device;
[0323] The second device performs an LTM cell change process, wherein the LTM cell change process includes the second device performing a security key update process according to the first configuration and / or first information.
[0324] 2. The method according to Supplement 1, wherein:
[0325] The first configuration is associated with one or more LTM candidate configurations, and / or the first configuration includes a first identifier or a first index;
[0326] The first configuration being associated with one or more LTM candidate configurations means:
[0327] In the LTM candidate configuration, at least one of the following is included: one or more MasterKeyUpdate fields; one or more {NH, nextHopChainingCount / NCC}; one or more NH; one or more NCC;
[0328] Alternatively, the LTM candidate configuration includes at least one of the first identifier or the first index;
[0329] Alternatively, the first configuration includes one or more LTM candidate configuration identifiers.
[0330] 3. The method according to Supplement 1, wherein:
[0331] The first configuration includes at least one of the following:
[0332] IE LTM-Candidate;
[0333] IE LTM-Config;
[0334] RRCReconfiguration message;
[0335] The first configuration is included in IE LTM-Config, including:
[0336] The first configuration is not in the field ltm-CandidateToAddModList or IE LTM-Candidate, or,
[0337] The first configuration is outside the domain ltm-CandidateToAddModList or IE LTM-Candidate;
[0338] The first configuration is included in the RRCReconfiguration message, including:
[0339] The first configuration is not in IE LTM-Config, or,
[0340] The RRCReconfiguration message includes IE LTM-Config, and the first configuration is outside the IE LTM-Config.
[0341] 4. The method according to any one of Notes 1 to 3, wherein the second device performs a security key update process according to the first configuration and / or the first information, comprising:
[0342] The second device determines K according to the NCC value included in the first configuration and / or the first information. gNB ,
[0343] The first configuration and / or the first information includes at least one of the following: one or more MasterKeyUpdate fields; one or more {NH, nextHopChainingCount / NCC}; one or more NCCs.
[0344] 5. The method according to any one of Notes 1 to 3, wherein the second device performs a security key update process according to the first configuration and / or the first information, comprising:
[0345] The second device determines K according to NH included in the first configuration and / or the first information gNB ,
[0346] The first configuration and / or the first information includes at least one of the following: one or more {NH, nextHopChainingCount / NCC}; one or more NH.
[0347] 6. The method according to any one of Notes 1 to 3, wherein the second device performs a security key update process according to the first configuration and / or the first information, comprising:
[0348] The second device determines K according to NH and NCC included in the first configuration and / or the first information. gNB ,
[0349] The first configuration and / or the first information includes one or more {NH, nextHopChainingCount / NCC} and one or more NCCs, or includes one or more NHs and one or more NCCs.
[0350] 7. The method according to Supplement 4 or 6, further comprising:
[0351] The second device stores the NCC in the first configuration and / or the first information, or replaces the first NCC value with the NCC value in the first configuration and / or the first information, or removes the NCC value from the first configuration and / or the first information.
[0352] 8. The method according to any one of Notes 4 to 6, further comprising:
[0353] The second device obtains the K gNB The associated key, the K gNB The associated key includes at least one of the following: K RRCenc , K UPenc , K RRCint and K UPint .
[0354] 9. The method according to any one of Notes 1 to 8, wherein:
[0355] The first information is the same as the first configuration, or is a subset of the first configuration, or is a first identifier or a first index included in the first configuration.
[0356] 10. The method according to any one of Notes 1 to 9, wherein the first information is carried by at least one of the following:
[0357] RRC message;
[0358] PDCP control PDU;
[0359] MAC CE or DCI,
[0360] in,
[0361] The RRC message is an RRCReconfiguration message;
[0362] The RRCReconfiguration message does not include LTM-Config, or the RRCReconfiguration message includes LTM-Config but the first information is not in the LTM-Config or is outside the LTM-Config.
Claims
1. A security key updating device, configured on a second device, wherein: The device comprises: a receiving unit configured to receive a first configuration related to access stratum (AS) security from a first device; A processing unit performs a layer 1 or layer 2 triggered mobility (LTM) cell change procedure, wherein the LTM cell change procedure includes the processing unit performing a security key update procedure according to the first configuration and / or the first information.
2. The device according to claim 1, wherein The first configuration includes parameters related to AS security, and the parameters related to AS security include at least one of the following: One or more MasterKeyUpdate fields; One or more {NH,nextHopChainingCount / NCC}; One or more next hop parameters (NH); One or more NH Chain Counters (NCC).
3. The device according to claim 2, wherein In the case where the AS security-related parameters include one or more MasterKeyUpdate fields, the MasterKeyUpdate fields include keySetChangeIndicator and nextHopChainingCount.
4. The device according to claim 1, wherein The first configuration is associated with one or more LTM candidate configurations, and / or the first configuration includes a first identifier or a first index.
5. The device according to claim 1, wherein The first configuration includes at least one of the following: IE LTM-Candidate; IE LTM-Config; RRCReconfiguration message.
6. The device according to claim 1, wherein The receiving unit further receives the first information from a third device; The first information is used to indicate one or more AS security-related parameters of the first configuration.
7. The device according to claim 6, wherein The first device is a network device (gNB) where the initial serving cell or source cell is located during the initial LTM; The third device is the network device (gNB) where the current serving cell or source cell is located during subsequent LTM.
8. The device according to claim 1, wherein The processing unit performs a security key update process according to the first configuration and / or the first information, including: The processing unit determines K according to the NCC value included in the first configuration and / or the first information gNB .
9. The device according to claim 8, wherein The processing unit determines K according to the NCC value included in the first configuration and / or the first information gNB ,include: If the second NCC value received by the receiving unit in the first configuration and / or the first information is equal to the first NCC value, the processing unit selects the currently activated K gNB , target physical cell identity (PCI) and its frequency ARFCN-DL to obtain K gNB * , using the K gNB * As the K communicated with the first network device after the LTM cell change is completed gNB and / or, If the second NCC value received by the receiving unit in the first configuration and / or the first information is different from the first NCC value, the processing unit first iteratively calculates and increases the NCC value until the increased NCC value matches the second NCC value, synchronizes the locally stored NH parameter, and when the NCC values match, the processing unit obtains K from the synchronized NH parameter, the target PCI and its frequency ARFCN-DL. gNB * , using the K gNB * As the first network device to communicate after the LTM cell change is completed gNB .
10. The device according to claim 9, wherein The processing unit further stores the second NCC value or replaces the first NCC value with the second NCC value.
11. The device according to claim 9, wherein The processing unit further removes the second NCC value from the first configuration and / or the first information.
12. The device according to claim 1, wherein The processing unit performing a security key update process according to the first configuration and / or the first information includes: The processing unit determines K based on NH included in the first configuration and / or the first information gNB .
13. The device according to claim 12, wherein The processing unit determines K based on NH included in the first configuration and / or the first information gNB ,include: If the receiving unit receives a second NH in the first configuration and / or the first information and / or the second NH received in the first configuration and / or the first information is different from the first NH or the currently activated K gNB The processing unit obtains K from the second NH, target PCI and its frequency ARFCN-DL gNB * , using the K gNB * As the first network device to communicate after the LTM cell change is completed gNB and / or, If the receiving unit does not receive the second NH in the first configuration and / or the first information and / or The second NH received in the first configuration and / or the first information is consistent with the first NH or the currently activated K gNB The same, the processing unit from the first NH or the current activation K gNB , target PCI and its frequency ARFCN-DL to get K gNB * , using the K gNB * As the first network device to communicate after the LTM cell change is completed gNB .
14. The device according to claim 1, wherein The processing unit performing a security key update process according to the first configuration and / or the first information includes: The processing unit determines K based on NH and NCC included in the first configuration and / or the first information gNB .
15. The device according to claim 14, wherein The processing unit determines K based on NH and NCC included in the first configuration and / or the first information gNB ,include: If the receiving unit receives a second NH in the first configuration and / or the first information and / or the second NH received in the first configuration and / or the first information is different from the first NH or the currently activated K gNB , If the second NCC associated with the second NH received by the receiving unit in the first configuration and / or the first information is equal to 0 or equal to the currently activated K gNB The first NCC associated with the first NH is equal to the first NH, and the processing unit obtains K from the second NH, the target PCI and its frequency ARFCN-DL. gNB * , using the K gNB * As the first network device to communicate after the LTM cell change is completed gNB and / or, If the second NCC associated with the second NH received by the receiving unit in the first configuration and / or the first information is not equal to 0 or is different from the currently activated K gNB The first NCC associated with the first NH is equal to the first NH, the processing unit first iteratively calculates and increases the NCC value until the increased NCC value matches the second NCC value received in the first configuration and / or the first information, synchronizes the locally stored NH parameters, and when the NCC values match, the processing unit obtains K from the synchronized NH parameters, the target PCI and its frequency ARFCN-DL gNB * , using the K gNB * As the first network device to communicate after the LTM cell change is completed gNB ; If the receiving unit does not receive the second NH in the first configuration and / or the first information and / or the second NH received in the first configuration and / or the first information is equal to the currently activated K gNB or equal to the first NH, the processing unit uses the current activation K gNB Or the first NH, target PCI and its frequency ARFCN-DL get K gNB * , using the K gNB * As the first network device to communicate after the LTM cell change is completed gNB .
16. The device according to claim 1, wherein The processing unit performing a security key update process according to the first configuration and / or the first information includes: The processing unit determines K according to the NH and / or NCC and the group identifier and / or cell identifier included in the first configuration and / or the first information gNB .
17. The device according to claim 1, wherein The LTM cell change process is triggered by at least one of the following conditions: Instructions from lower levels; After a radio link failure (RLF) or handover failure (HOF); Evaluation of the second device.
18. The device according to claim 1, wherein The first information is carried by at least one of the following: Radio Resource Control (RRC) messages; Packet Data Convergence Protocol (PDCP) controls packet data units (PDUs); Media Access Control Element (MAC CE) or Downlink Control Information (DCI).
19. A terminal device comprising a memory and a processor, wherein the memory stores a computer program, wherein: The processor is configured to execute the computer program to implement the following method: receiving a first configuration related to AS security from a first device; An LTM cell change procedure is performed, wherein the LTM cell change procedure includes executing a security key update procedure according to the first configuration and / or the first information.
20. A communication system, wherein: The communication system includes a network device and the terminal device according to claim 19.
Citation Information
Patent Citations
Configuration updating method and device, communication equipment, communication system and storage medium
CN116889017A
Information processing method, terminal, communication system and storage medium
CN117136615A
Methods and apparatus to improve UE experience with a new type of radio bearer during inter-du inter-cell beam management
US20230422123A1
Method for controlling cell change operation, and device thereof
WO2023128730A1