Wireless communication method and communication device

By determining the same encryption algorithm type based on security indicators in wireless communication systems, the problem of inconsistent encryption algorithm bits across different devices is solved, thereby enhancing the system's security protection and resisting quantum attacks.

WO2025161027A1PCT designated stage Publication Date: 2025-08-07GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/075837
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-02-04
Publication Date
2025-08-07

AI Technical Summary

Technical Problem

In wireless communication systems, the security protection strength of communication systems is inconsistent because different communication devices support different encryption algorithms with different bit widths. Especially when facing quantum attacks, it cannot be guaranteed that all devices can support 256-bit encryption algorithms, resulting in inconsistent security protection.

Method used

By receiving a security instruction from the second device, the first device determines that the same type of encryption algorithm is used with the terminal device, ensuring consistent security protection strength in the communication system.

Benefits of technology

It ensures that the same encryption algorithm type is used across different communication devices, thereby enhancing the security of the communication system and its ability to resist quantum attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024075837_07082025_PF_FP_ABST
    Figure CN2024075837_07082025_PF_FP_ABST
Patent Text Reader

Abstract

Provided are a wireless communication method and a communication device. The method comprises: a first device receives first information sent by a second device, the first information comprising a first security indication, the first security indication having a correspondence with the algorithm type of a first encryption algorithm, and the first encryption algorithm being an encryption algorithm used between the second device and a first terminal device; and the first device determines the algorithm type of a second encryption algorithm on the basis of the first security indication, the second encryption algorithm being an encryption algorithm used between the first device and the first terminal device, and the algorithm type of the second encryption algorithm being the same as that of the first encryption algorithm. The first device can determine an encryption algorithm between the first device and the first terminal device on the basis of the first security indication of the second device, and the algorithm type of the encryption algorithm between the first device and the first terminal device is the same as that of the encryption algorithm between the second device and the first terminal device, thereby ensuring the consistency of security protection strength in a communication system.
Need to check novelty before this filing date? Find Prior Art

Description

Wireless communication method and communication device Technical Field

[0001] The present application relates to the field of communication technology, and more specifically to a wireless communication method and communication device. Background Art

[0002] In wireless communication systems, the encryption algorithms used for symmetric encryption between communication devices are all 128 bits (or "bits"). However, to combat quantum attacks, wireless communication systems may introduce 256-bit encryption algorithms. Consequently, different communication devices may support encryption algorithms with different bit counts, potentially leading to inconsistent security protection strength within the communication system. In this case, ensuring consistent security protection strength within the communication system remains an unresolved issue.

[0003] Summary of the Invention

[0004] The present application provides a wireless communication method and a communication device. The following introduces various aspects involved in the present application.

[0005] In a first aspect, a wireless communication method is provided, including: a first device receives first information sent by a second device, the first information includes a first security indication, the first security indication is determined by a corresponding relationship with an algorithm type of a first encryption algorithm, and the first encryption algorithm is an encryption algorithm used between the second device and the first terminal device; the first device determines the algorithm type of a second encryption algorithm based on the first security indication, the second encryption algorithm is the encryption algorithm used between the first device and the first terminal device, and the second encryption algorithm is the same as the algorithm type of the first encryption algorithm.

[0006] In a second aspect, a wireless communication method is provided, including: a second device determines a first security indication based on the security capability of a first terminal device and / or the algorithm type of an encryption algorithm supported by the second device; the second device sends a first information to the first device, the first information including the first security indication, the first security indication corresponding to the algorithm type of the first encryption algorithm, and the first encryption algorithm is the encryption algorithm used between the second device and the first terminal device.

[0007] According to a third aspect, a communication device is provided, which is a first device and includes: a receiving module for receiving first information sent by a second device, the first information including a first security indication, the first security indication corresponding to the algorithm type of a first encryption algorithm, and the first encryption algorithm being the encryption algorithm used between the second device and the first terminal device; and a determination module for determining the algorithm type of a second encryption algorithm based on the first security indication, the second encryption algorithm being the encryption algorithm used between the first device and the first terminal device, and the second encryption algorithm having the same algorithm type as the first encryption algorithm.

[0008] In a fourth aspect, a communication device is provided, which is a second device, and includes: a determination module for determining a first security indication based on the security capability of the first terminal device and / or the algorithm type of the encryption algorithm supported by the second device; a sending module for sending first information to the first device, the first information including the first security indication, the first security indication corresponding to the algorithm type of the first encryption algorithm, and the first encryption algorithm being the encryption algorithm used between the second device and the first terminal device.

[0009] In a fifth aspect, a communication device is provided, comprising a memory and a processor, wherein the memory is used to store a program, and the processor is used to call the program in the memory so that the communication device executes the method described in the first aspect.

[0010] In a sixth aspect, a communication device is provided, comprising a memory and a processor, wherein the memory is used to store a program, and the processor is used to call the program in the memory so that the communication device executes the method described in the second aspect.

[0011] In a seventh aspect, a device is provided, comprising a processor for calling a program from a memory so that the device executes the method as described in the first aspect or the second aspect.

[0012] In an eighth aspect, a chip is provided, comprising a processor for calling a program from a memory so that a device equipped with the chip executes the method described in the first aspect or the second aspect.

[0013] In a ninth aspect, a computer-readable storage medium is provided, on which a program is stored, wherein the program enables a computer to execute the method as described in the first aspect or the second aspect.

[0014] In a tenth aspect, a computer program product is provided, comprising a program, wherein the program enables a computer to execute the method as described in the first aspect or the second aspect.

[0015] In an eleventh aspect, a computer program is provided, wherein the computer program enables a computer to execute the method as described in the first aspect or the second aspect.

[0016] In the present application, the first device can determine the encryption algorithm between the first device and the first terminal device based on the first security indication sent by the second device, and make the algorithm types of the encryption algorithms between the first device and the second device and the first terminal device respectively the same, thereby helping to ensure consistent security protection strength in the communication system. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] FIG1 is a schematic structural diagram of a wireless communication system to which an embodiment of the present application is applicable.

[0018] FIG2 is a schematic flowchart of the key generation process in the 5G security key architecture.

[0019] FIG3 is a schematic flow chart of the NAS security mode command process.

[0020] FIG4 is a schematic flow chart of the AS security mode command process.

[0021] FIG5 is a schematic flowchart of a wireless communication method provided in an embodiment of the present application.

[0022] FIG6 is a schematic flowchart of a wireless communication method provided in another embodiment of the present application.

[0023] FIG7 is a schematic flowchart of a wireless communication method provided in another embodiment of the present application.

[0024] FIG8 is a schematic flowchart of a wireless communication method provided in Embodiment 1 of the present application.

[0025] FIG9 is a schematic flowchart of a wireless communication method provided in Embodiment 2 of the present application.

[0026] 10A-10B are schematic flow charts of a wireless communication method provided in Embodiment 4 of the present application.

[0027] FIG11 is a schematic structural diagram of a communication device provided in an embodiment of the present application.

[0028] FIG12 is a schematic structural diagram of a communication device provided in another embodiment of the present application.

[0029] FIG13 is a schematic diagram of the structure of a communication device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0030] The technical solution in this application will be described below with reference to the accompanying drawings.

[0031] Communication system architecture

[0032] Figure 1 is a schematic diagram of a communication system architecture applicable to an embodiment of the present application. The network architecture may include terminal equipment, access network (AN) network elements, and core network network elements.

[0033] It should be understood that the technical solutions of the embodiments of the present application can be applied to various communication systems, such as: fifth generation (5G) system or new radio (NR), long term evolution (LTE) system, LTE frequency division duplex (FDD) system, LTE time division duplex (TDD), etc. The technical solutions provided in this application can also be applied to future communication systems, such as the sixth generation mobile communication system, satellite communication system, etc.

[0034] The terminal device in the embodiments of the present application may also be referred to as user equipment (UE), access terminal, user unit, user station, mobile station, mobile station (MS), mobile terminal (MT), remote station, remote terminal, mobile device, user terminal, terminal, wireless core network element, user agent or user device. The terminal device in the embodiments of the present application may refer to a device that provides voice and / or data connectivity to a user and can be used to connect people, objects and machines, such as a handheld device with wireless connection function, a vehicle-mounted device, etc. The terminal device in the embodiments of the present application can be a mobile phone, a tablet computer, a laptop computer, a PDA, a mobile internet device (MID), a wearable device, a virtual reality (VR) device, an augmented reality (AR) device, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical surgery, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, a wireless terminal in a smart home, etc. Optionally, the terminal device can be used to act as a base station. For example, the terminal device can act as a dispatching entity that provides sidelink signals between terminal devices in vehicle-to-everything (V2X) or device-to-device (D2D). For example, a cellular phone and a car communicate with each other using sidelink signals. The cellular phone and smart home devices communicate without relaying the communication signal through a base station.

[0035] An access network element can be an access network device. This device is used by terminals to wirelessly access the network architecture and is primarily responsible for radio resource management, quality of service (QoS) management, data compression, and encryption on the air interface side. An access network device can also be referred to as a radio access network (RAN) device. For example, an access network device can be a base station. A base station may broadly cover various names as follows, or be replaced with the following names, such as: NodeB, evolved NodeB (eNB), next generation NodeB (gNB), relay station, access point, transmitting and receiving point (TRP), transmitting point (TP), master eNB (MeNB), secondary eNB (SeNB), multi-standard radio (MSR) node, home base station, network controller, access node, wireless node, access point (AP), transmission node, transceiver node, baseband unit (BBU), remote radio unit (RRU), active antenna unit (AAU), remote radio head (RRH), central unit (CU), distributed unit (DU), positioning node, etc. A base station may be a macro base station, a micro base station, a relay node, a donor node, or the like, or a combination thereof. A base station may also refer to a communication module, modem, or chip used to be set in the aforementioned device or apparatus. A base station may also be a mobile switching center and a device that performs base station functions in D2D, V2X, and machine-to-machine (M2M) communications, a network-side device in a 6G network, or a device that performs base station functions in future communication systems. A base station may support networks with the same or different access technologies. The embodiments of this application do not limit the specific technology and specific device form used by the access network device.

[0036] Base stations can be fixed or mobile. For example, a helicopter or drone can be configured to act as a mobile base station, and one or more cells can move based on the location of the mobile base station. In other examples, a helicopter or drone can be configured to act as a device that communicates with another base station.

[0037] In some deployments, the access network device in the embodiments of the present application may refer to a CU or a DU, or the access network device may include a CU and a DU. The gNB may also include an AAU.

[0038] The types of core network elements may include user plane function (UPF) network elements, access and mobility management function (AMF) network elements, session management function (SMF) network elements, policy control function (PCF) network elements, application function (AF), data network (DN), network slice selection function (NSSF), authentication server function (AUSF), unified data management function (UDM), network exposure function (NEF), network repository function (NRF), and network slice-specific authentication and authorization function (NSSAAF). In addition, some networks (such as 5G networks) have added a network data analytics function (NWDAF) to the core network. NWDAF can be further divided into analytics logical function (AnLF) and model training logical function (MTLF). In some communication systems (such as 5G systems), core network elements may also be referred to as network functions (NFs).

[0039] The network elements in Figure 1 can be network elements in hardware devices, software functions running on dedicated hardware, or virtualized functions implemented on a platform (e.g., a cloud platform). It should be noted that the network architecture shown in the above figure is only an example of the network elements included in the entire network architecture. In the embodiments of the present application, the network elements included in the entire network architecture are not limited.

[0040] Those skilled in the art will appreciate that the network architecture shown in Figure 1 does not limit the network architecture. In a specific implementation, the network architecture may include more or fewer network elements than shown, or may combine certain network elements. It should be understood that in Figure 1, the AN or RAN is represented by (R)AN.

[0041] In some scenarios, network devices and terminal devices can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; they can also be deployed on water; they can also be deployed in the air on aircraft, balloons, and satellites. The embodiments of this application do not limit the scenarios in which network devices and terminal devices are located.

[0042] Symmetric encryption algorithm (ciphering algorithm) and key architecture

[0043] Symmetric encryption algorithms used in 5G security include 128-NEA1, 128-NEA2, and 128-NEA-3. These three symmetric encryption algorithms correspond to Snow 3G, the Advanced Encryption Standard (AES), and the Zu Chongzhi (ZUC) algorithm, respectively. Details of these three symmetric encryption algorithms are shown in Table 1. The fourth generation (4G) also uses these three symmetric encryption algorithms, named 128-EEA1, 128-EEA2, and 128-EEA3.

[0044] Table 1 Symmetric encryption algorithm table

[0045] In the 5G security key architecture, the length of the generated key can be shown in Figure 2. As shown in Figure 2, the length of the key used to protect the session (i.e., to protect the security of the NAS and AS layers) is 128 bits.

[0046] NAS algorithm negotiation

[0047] Each AMF can be configured through network management with a list of algorithms allowed to be used, namely a list of NAS integrity algorithms and a list of NAS encryption algorithms, which should be sorted according to the priority determined by the operator. In order to establish a NAS security context, the AMF can select a NAS encryption algorithm and a NAS integrity protection algorithm. The AMF can then initiate the NAS security mode command process and include the selected algorithm and UE security capabilities in the message sent to the UE (to detect attackers modifying the UE security capabilities). The AMF can select the NAS algorithm with the highest priority based on the sorted list.

[0048] The NAS security mode command process can be shown in Figure 3, including steps S310 to S360. In step S310, the AMF enables integrity protection. The AMF can select the corresponding security algorithm (encryption algorithm and integrity algorithm) to enable integrity protection based on the UE security capabilities and the locally configured algorithm list. In step S320, the AMF sends a NAS security mode command (SMC) message to the UE. The NAS SMC may include the algorithm selected by the AMF and the UE security capabilities, as well as a NAS key change indication (e.g., K_AMF_change_flag), a NAS key set identifier (ngKSI), an Anti-Bidding down Between Architectures (ABBA) parameter, a request initial NAS message flag, a NAS message authentication code (MAC), etc.

[0049] In step S330, the UE can verify the integrity of the NAS SMC message to confirm that the message has not been tampered with, and then confirm that it has not been subjected to a price reduction attack by checking the UE security capabilities returned by the AMF. After the UE verification is successful, the encryption and integrity protection of the NAS layer can be enabled using the algorithm selected by the AMF. In step S340, the AMF can enable uplink decryption. In step S350, the UE can send a NAS security mode complete message to the AMF, which may include a complete initial NAS message in the NAS container and a NAS MAC. In step S360, the AMF enables downlink encryption.

[0050] If a change of AMF occurs, such as N2 handover (HO) or mobile registration update, the source AMF may send the UE security capabilities to the target AMF, and the target AMF may send the selected algorithms to the UE. In the N2 handover scenario, the target AMF may use a NAS container to send this information to the UE via the source AMF. In the mobile registration update scenario, the target AMF and the UE may use the NAS SMC procedure to activate the selected algorithms.

[0051] AS algorithm negotiation

[0052] Each gNB / ng-eNB can be configured through network management with a list of allowed algorithms: an integrity algorithm list and a cipher algorithm list. These lists can be ordered according to operator-determined priorities. When establishing an AS security context between a gNB / ng-eNB and a UE, the AMF can send the UE's 5G security capabilities to the gNB / ng-eNB. The gNB / ng-eNB selects the algorithm with the highest priority from its configured list that is also present in the UE's 5G security capabilities. The selected algorithm can be indicated to the UE during the AS SMC procedure. The selected cipher algorithm can be used for ciphering user plane data and radio resource control (RRC) signaling. The selected integrity algorithm can be used for integrity protection of user plane data and RRC signaling.

[0053] The AS security mode command process may be shown in Figure 4 and include steps S410 to S470. In step S410, the gNB or ng-eNB enables RRC integrity protection. The gNB or ng-eNB may select the corresponding RRC and user plane (UP) protection security algorithms based on the UE security capabilities and the locally configured algorithm list to enable RRC integrity protection. In step S420, the gNB or ng-eNB may send an AS SMC message to the UE. The AS SMC message may include the algorithm selected by the gNB or ng-eNB, the UE security capabilities, and the message authentication code-integrity (MAC-I). In step S430, the gNB or ng-eNB may enable RRC downlink encryption. In step S440, the UE verifies the integrity of the AS SMC message. If verification is successful, RRC integrity protection and RRC downlink decryption are enabled. The UE can verify the integrity of the message using the MAC-I to confirm that it has not been tampered with. It can also verify that it has not been subjected to a price reduction attack by checking the UE security capabilities returned by the gNB or ng-eNB. After successful verification, the UE can enable RRC layer encryption and integrity protection, as well as downlink decryption, using the algorithm selected by the gNB or ng-eNB. In step S450, the UE can send an AS SMC message to the gNB or ng-eNB, which may include the MAC-I. In step S460, the UE can enable RRC uplink encryption. In step S470, the gNB or ng-eNB can enable RRC uplink decryption.

[0054] For the Xn handover process, the UE switches from the source base station to the target base station. The source base station can send the UE's security capabilities and the security algorithm used by the source cell to the target base station. The target base station can select an algorithm based on the UE security capabilities and the locally configured algorithm list. If a different algorithm is selected, the target base station can carry the selected algorithm in the handover command message sent by the source base station to the UE. When switching between a 4G base station and a 5G base station, the algorithm selected by the target base station must be carried. The target base station must send the UE security capabilities to the AMF for AMF verification. If it is inconsistent with the locally stored UE security capabilities, the path switch acknowledgement message sent by the AMF to the target base station carries the UE security capabilities. After the target base station reselects the algorithm, it uses intra-cell handover and UE update algorithms.

[0055] For N2 handover, the source AMF may send the UE's security capabilities to the target AMF, and the target AMF may send an NGAP HANDOVER REQUEST message to the target base station, which includes the UE's security capabilities. The source base station may send a source to target transparent container to the target base station, which includes the algorithm used by the source cell. The target base station may select an algorithm based on the UE's security capabilities and the locally configured algorithm list. If a different algorithm is selected, the target base station shall carry the selected algorithm in the handover command message sent to the UE.

[0056] Quantum-safe algorithms

[0057] A quantum computer is a device that exploits quantum mechanical phenomena (superposition and entanglement) to perform calculations and manipulate data. The security foundation of currently popular cryptographic algorithms rests on intractable mathematical problems. Due to the inherent parallel nature of quantum computers, some quantum algorithms can solve difficult mathematical problems more efficiently than classical algorithms, posing a serious and present security threat to contemporary cryptography. An attacker could use the Grover algorithm on a quantum computer to halve the effective key size, thereby halving the security strength of symmetric key algorithms. Therefore, to achieve quantum attack resistance, the key size of symmetric key algorithms must be doubled. 128-bit symmetric key algorithms such as AES-128, SNOW 3G, and ZUC-128 are fundamental to the security of NAS signaling, RRC signaling, and UP data. To mitigate quantum attacks, the introduction of 256-bit symmetric key algorithms into the system is a viable option. Whether a longer MAC is necessary requires further study.

[0058] As previously mentioned, the security protection algorithms for the AS and NAS in the UE of a communication system are negotiated separately with the gNB and AMF. Therefore, different security algorithms can be used, but all use 128-bit encryption. The AS and NAS can use different algorithms, such as the Snow 3G algorithm, AES, or ZUC. However, as the algorithm capabilities of terminals, radio access network equipment (e.g., gNB, ng-eNB), and core network equipment (e.g., AMF) increase, these communication entities may gradually enhance their algorithm capabilities to support 256-bit algorithms to protect against quantum attacks. However, the introduction of 256-bit algorithms may not guarantee that all UEs and existing radio access network equipment (gNB, ng-eNB), and core network equipment (AMF) will support 256-bit algorithms. Furthermore, it is not possible to guarantee that all 4G, 5G, and sixth-generation (6G) systems will simultaneously deploy equipment that supports 256-bit encryption algorithms. Furthermore, UEs may operate across multiple systems, such as switching between 6G and 5G networks, or between 5G and 4G networks, or between 6G and 4G networks. While the AS and NAS share the same security requirements, the different algorithm strengths supported by access network equipment and core network equipment may lead to different security protection strengths adopted by the AS and NAS. This should be avoided in communication systems. Therefore, ensuring consistent security protection strength across communication systems remains an unresolved issue.

[0059] Based on this, the wireless communication method of an embodiment of the present application is described in detail below. In the present application, the first device can determine the encryption algorithm between the first device and the first terminal device based on the first security indication sent by the second device, and make the algorithm type of the encryption algorithm between the first device and the second device and the first terminal device respectively the same, thereby helping to ensure consistent security protection strength in the communication system.

[0060] As shown in Figure 5, an embodiment of the present application provides a wireless communication method. The wireless communication method can be performed by a first device and a second device. The first device can be the access network device described above, such as a gNB. The second device can be the core network element (or "core network device") described above, such as an AMF.

[0061] The method shown in Figure 5 may include steps S510 to S520. In step S510, a first device receives first information sent by a second device. The first information may include a first security indication, which may correspond to the algorithm type of a first encryption algorithm used between the second device and the first terminal device. Specifically, the first security indication may correspond to the algorithm type of the encryption algorithm used between the second device and the first terminal device. When the first security indication is different, the algorithm types of the encryption algorithms used between the second device and the first terminal device are different. For example, a first security indication of 01 may correspond to a 128-bit encryption algorithm. Another example is a first security indication of 11, which may correspond to a 256-bit encryption algorithm. The second device may select an encryption algorithm for communication with the first terminal device and determine the first security indication based on the security capabilities of the first terminal device and / or the algorithm types of encryption algorithms supported by the second device. The security capabilities of the first terminal device may indicate the encryption algorithms supported by the first terminal device. In step S520, the first device determines the algorithm type of the second encryption algorithm based on the first security indication. The second encryption algorithm may be an encryption algorithm used between the first device and the first terminal device, and the second encryption algorithm may be of the same algorithm type as the first encryption algorithm. That is, the first device may determine the encryption algorithm used between the first device and the first terminal device based on the first security indication, and ensure that the encryption algorithms used between the first device and the second device and the first terminal device are of the same algorithm type.

[0062] The algorithm type of the first encryption algorithm or the second encryption algorithm can be either the first type or the second type, with the first type corresponding to a 128-bit encryption algorithm and the second type corresponding to a 256-bit encryption algorithm. When the first security indication corresponds to the first type, the encryption algorithm used between the second device and the first terminal device is a 128-bit encryption algorithm, and therefore the first device can select the 128-bit encryption algorithm as the encryption algorithm used between the first device and the first terminal device. When the first security indication corresponds to the second type, the encryption algorithm used between the second device and the first terminal device is a 256-bit encryption algorithm, and therefore the first device can select the 256-bit encryption algorithm as the encryption algorithm used between the first device and the first terminal device. It is worth noting that this application does not limit the form of the first security indication. Exemplarily, the first security indication can be an indication to use a 128-bit algorithm or an indication to use a 256-bit algorithm. Based on the first security indication, the first device can more efficiently determine the encryption algorithm to be used between the first terminal device and the first terminal device.

[0063] The first security indication can be determined based on the algorithm type of the encryption algorithm supported by the first device. That is, when determining the first security indication, the second device can also take the algorithm type of the encryption algorithm supported by the first device as a consideration. For example, when the first device, the second device and the first terminal device all support 256-bit encryption algorithms, the second device can determine that the first security indication corresponds to the second type of encryption algorithm. For another example, when the second device and the first terminal device both support 256-bit encryption algorithms, but the first device does not support 256-bit encryption algorithms, the second device can determine that the first security indication corresponds to the first type of encryption algorithm. Determining the first security indication based on the algorithm type of the encryption algorithm supported by the first device helps to ensure that the security protection strength between the first device and the second device and the first terminal device is consistent.

[0064] In some implementations, the algorithm type of the encryption algorithm supported by the first device can be indicated by the first device to the second device. As shown in Figure 6, before the first device receives the first information sent by the second device, the wireless communication method of the embodiment of the present application may also include step S610. In step S610, the first device sends second information to the second device, and the second information can be used to indicate the algorithm type of the encryption algorithm supported by the first device. That is, the first device can indicate the algorithm type of the encryption algorithm supported by it to the second device before the second device determines the first security indication, which helps the second device to determine a reasonable first security indication. Further, the second information may include an algorithm identifier of the encryption algorithm supported by the first device. Based on the algorithm identifier, the second device can determine the encryption algorithm supported by the first device, thereby further clarifying its algorithm type. Alternatively, the second information may include indication information of the algorithm type of the encryption algorithm supported by the first device, which helps the second device to more efficiently determine the algorithm type of the encryption algorithm supported by the first device.

[0065] In other implementations, the algorithm type of the encryption algorithm supported by the first device may be pre-stored by the second device. For example, the first device is an access network device, and the second device is a core network device, and the core network device may pre-store the algorithm type of the encryption algorithm supported by the access network device. The algorithm type of the encryption algorithm supported by the access network device stored by the core network device may be reported in advance by the access network device to the core network device, or may be obtained by the core network device from actual deployment (for example, if an operator purchases a series of base stations, the operator can understand the algorithm strength supported by the base stations).

[0066] In some implementations, the first information may further include a first security policy, which may be used to indicate the algorithm type of the encryption algorithm supported by the second device. That is, the second device may further indicate to the first device the type of encryption algorithm it supports, thereby helping to more effectively achieve consistent security protection strength across the communication system. For example, the first security policy may be information indicating that the second device supports 128-bit algorithms. Alternatively, the first security policy may be information indicating that the second device supports 256-bit algorithms. In some implementations, the first security policy may be referred to as the security capability of the second device.

[0067] Furthermore, as shown in Figure 7, the wireless communication method according to the embodiment of the present application may further include step S730. In step S730, the first device sends a first security policy to the third device. The first security policy may be used by the third device to determine the encryption algorithm to be used between the third device and the first terminal device. For example, when the first device is a gNB / ng-eNB, if the UE performs an Xn handover, resulting in a change of the gNB / ng-eNB, the source gNB / ng-eNB may indicate the first security policy to the target gNB / ng-eNB, thereby facilitating the target gNB / ng-eNB to determine the encryption algorithm type to be used between the target gNB / ng-eNB and the UE.

[0068] The wireless communication method of the embodiment of the present application is described below with examples in conjunction with Examples 1 to 4. It is worth noting that in the following embodiments, the first device is an access network device of gNB / ng-eNB / 6G, and the second device is an AMF / 6G core network device. For example, in each of the following embodiments, the first information may include a security policy (i.e., a first security policy) / instruction (i.e., a first security instruction).

[0069] Example 1

[0070] As shown in Figure 8, during the UE's initial access to the AMF, the AMF can negotiate NAS and AS layer encryption algorithms with the gNB / ng-eNB. In step S810, the UE reports its security capabilities to the AMF. The UE security capabilities can be used to negotiate NAS security protection algorithms with the AMF. The UE security capabilities can be carried in the UE's Registration Request message. In step S820, the AMF selects a NAS security protection algorithm and determines a security policy / indication based on at least one of the UE security capabilities, a locally configured algorithm list, and the algorithm types of encryption algorithms supported by the gNB / ng-eNB. If the AMF selects a 128-bit encryption algorithm, the security indication corresponds to the 128-bit encryption algorithm. If the AMF selects a 256-bit encryption algorithm, the security indication corresponds to the 256-bit encryption algorithm. For example, the security indication can be 01, indicating a 256-bit encryption algorithm. Alternatively, the security indication can be 11, indicating a 128-bit encryption algorithm. If the AMF supports the 256-bit encryption algorithm, the AMF may select the support of 256-bit algorithm as the security policy. If the AMF supports the 128-bit encryption algorithm, the AMF may select the support of 128-bit algorithm as the security policy. If the AMF supports both the 256-bit and 128-bit encryption algorithms, the AMF may select the support of 256-bit algorithm and the support of 128-bit algorithm as the security policy. In step S830, the AMF sends the UE security capabilities and security policy / indication to the gNB / ng-eNB. In step S840, the gNB / ng-eNB selects the AS security protection algorithm based on the UE security capabilities, security policy / indication, and at least one of the locally configured algorithm list.

[0071] Example 2

[0072] As shown in Figure 9, in an N2 handover scenario, the UE hands over to the target gNB / ng-eNB and AMF. The target AMF can negotiate the NAS and AS layer encryption algorithms with the target gNB / ng-eNB. In step S910, the source gNB / ng-eNB decides to perform the UE handover and sends an NGAP HANDOVER REQUIRED message to the source AMF. In step S920, the source AMF sends a Namf_Communication_CreateUEContext Request message to the target AMF. This message may include the UE security capabilities, the source AMF's security policy / indication, and the NAS security algorithm selected by the source AMF. In step S930, the target AMF selects a NAS security protection algorithm and determines the security policy / indication based on at least one of the UE security capabilities, the locally configured algorithm list, and the algorithm type of the encryption algorithm supported by the gNB / ng-eNB. If the AMF selects a 128-bit encryption algorithm, the security indication corresponds to the 128-bit encryption algorithm. If the AMF selects the 256-bit encryption algorithm, the security indication corresponds to the 256-bit encryption algorithm. If the AMF supports the 256-bit encryption algorithm, the AMF may select "support of 256-bit algorithm" as the security policy. If the AMF supports the 128-bit encryption algorithm, the AMF may select "support of 128-bit algorithm" as the security policy. If the AMF supports both the 256-bit and 128-bit encryption algorithms, the AMF may select "support of 256-bit algorithm" and "support of 128-bit algorithm" as the security policy. In step S940, the target AMF sends an NGAP HANDOVER REQUEST message to the target gNB / ng-eNB, which contains the UE security capabilities and security policy / indication. In step S950, the target gNB / ng-eNB receives the source-to-target transparent container sent by the source gNB / ng-eNB, which contains the AS security protection algorithm used by the source cell. In step S960, the target gNB / ng-eNB selects an AS security protection algorithm based on at least one of the AS algorithm used by the source cell, the UE security capabilities, security policies / indications, and a locally configured algorithm list. In step S970, the target gNB / ng-eNB sends a HO command message to the UE.

[0073] Example 3

[0074] In the mobile registration update scenario, in Example 3, the target AMF can negotiate the encryption algorithms for the NAS and AS layers with the target gNB / ng-eNB. The target AMF can send security policies / indications to the target gNB / ng-eNB. The method for selecting the AS security algorithm by the target gNB / ng-eNB can refer to Example 1 and is not further described here.

[0075] Based on the wireless communication methods shown in Examples 1 to 3, the wireless access network device can exchange security policies / indications of algorithm strength with the core network device, which helps to ensure that the security protection strength of the AS and NAS of the same UE is consistent.

[0076] Example 4

[0077] As shown in Figures 10A-10B, in an Xn handover scenario, the AMF serving the UE remains unchanged. When the UE switches from the source gNB / ng-eNB to the target gNB / ng-eNB, the source gNB / ng-eNB may synchronize the AMF's security policy with the target gNB / ng-eNB. In step S1010, the source gNB / ng-eNB sends the target gNB / ng-eNB the UE's security capabilities, the AS security protection algorithm used by the source cell, and the security policy. The source gNB / ng-eNB's security policy may be determined by the AMF during the UE's initial access to the source gNB / ng-eNB, as described in Example 1. If the AMF supports a 256-bit encryption algorithm, the AMF may select a 256-bit encryption algorithm as the security policy. If the AMF supports a 128-bit encryption algorithm, the AMF may select a 128-bit encryption algorithm as the security policy. In step S1020, the target gNB / ng-eNB selects the AS security protection algorithm based on the UE's security capabilities, the security policy, and at least one of the locally configured algorithm lists. If both the UE and the target gNB / ng-eNB support a 256-bit encryption algorithm and the security policy specifies support of a 256-bit algorithm, the target gNB / ng-eNB may select the 256-bit encryption algorithm as the AS security protection algorithm. Otherwise, the target gNB / ng-eNB selects the 128-bit encryption algorithm as the AS security protection algorithm. In step S1030, the target gNB / ng-eNB (via the source gNB / ng-eNB) sends a HO command message to the UE. If the AS encryption algorithm selected by the target gNB / ng-eNB is different from that used by the source cell, the message may carry the algorithm selected by the target gNB / ng-eNB; otherwise, it does not need to carry the algorithm. Furthermore, as shown in Figure 10B, the wireless communication method of embodiment 4 may further include steps S1040-S1060. In step S1040, the target gNB / ng-eNB sends an NGAP PATH SWITCH REQUEST message to the AMF, which may include the UE security capabilities and security policy. In step S1050, the AMF checks whether the UE security capabilities and security policy have been tampered with. If the AS security protection algorithm selected by the target gNB / ng-eNB differs from the AS security protection algorithm used between the source gNB / ng-eNB and the UE, the target gNB / ng-eNB may send the selected algorithm type to the AMF, allowing the AMF to use this type of algorithm to protect the NAS connection with the UE. In step S1060, the AMF sends an NGAP PATH SWITCH REQUEST ACKNOWLEDGE to the target gNB / ng-eNB.

[0078] Based on the wireless communication method shown in Example 4, when the access network device changes, the source access network device can synchronize the security policy of the core network device to the target access network device, which helps to ensure the consistency of the security protection strength of the AS and NAS of the same UE.

[0079] The method embodiment of the present application is described in detail above in conjunction with Figures 1 to 10B . The device embodiment of the present application is described in detail below in conjunction with Figures 11 to 13 . It should be understood that the description of the method embodiment corresponds to the description of the device embodiment. Therefore, for portions not described in detail, reference can be made to the above method embodiment.

[0080] Figure 11 is a schematic diagram of the structure of a communication device provided by an embodiment of the present application. The communication device 1100 shown in Figure 11 may include a receiving module 1110 and a determining module 1120. The receiving module 1110 may be used to receive first information sent by a second device, the first information including a first security indication, the first security indication corresponding to the algorithm type of the first encryption algorithm, and the first encryption algorithm is the encryption algorithm used between the second device and the first terminal device; the determining module 1120 may be used to determine the algorithm type of the second encryption algorithm based on the first security indication, the second encryption algorithm is the encryption algorithm used between the first device and the first terminal device, and the second encryption algorithm is the same as the algorithm type of the first encryption algorithm.

[0081] In some implementations, the algorithm type is a first type or a second type, the first type corresponds to a 128-bit encryption algorithm, and the second type corresponds to a 256-bit encryption algorithm.

[0082] In some implementations, the first security indication is determined based on an algorithm type of an encryption algorithm supported by the first device.

[0083] In some implementations, the communication device further includes a first sending module 1130. The first sending module 1130 is configured to send second information to the second device before the receiving module 1110 receives the first information sent by the second device, where the second information is configured to indicate the type of the encryption algorithm supported by the first device.

[0084] In some implementations, the first information further includes a first security policy, where the first security policy is used to indicate an algorithm type of an encryption algorithm supported by the second device.

[0085] In some implementations, the communication device further includes a second sending module 1140. The second sending module 1140 may be configured to send a first security policy to the third device, where the first security policy is used by the third device to determine an encryption algorithm used between the third device and the first terminal device.

[0086] In some implementations, the first device is an access network device, and the second device is a core network device.

[0087] Figure 12 is a schematic diagram of the structure of a communication device provided by another embodiment of the present application. The communication device 1200 shown in Figure 12 may include a determination module 1210 and a sending module 1220. The determination module 1210 can be used to determine a first security indication based on the security capabilities of the first terminal device and / or the algorithm type of the encryption algorithm supported by the second device. The sending module 1220 can be used to send a first message to the first device, the first message including a first security indication, the first security indication corresponding to the algorithm type of the first encryption algorithm, and the first encryption algorithm being the encryption algorithm used between the second device and the first terminal device.

[0088] In some implementations, the algorithm type is a first type or a second type, the first type corresponds to a 128-bit encryption algorithm, and the second type corresponds to a 256-bit encryption algorithm.

[0089] In some implementations, the first security indication is determined based on an algorithm type of an encryption algorithm supported by the first device.

[0090] In some implementations, the communication device further includes a receiving module 1230. The receiving module 1230 may be configured to receive second information sent by the first device before the sending module 1220 sends the first information to the first device, where the second information is used to indicate the algorithm type of the encryption algorithm supported by the first device.

[0091] In some implementations, the first information further includes a first security policy, where the first security policy is used to indicate an algorithm type of an encryption algorithm supported by the second device.

[0092] In some implementations, the first device is an access network device, and the second device is a core network device.

[0093] Figure 13 is a schematic diagram of the structure of a communication device according to an embodiment of the present application. The dashed lines in Figure 13 indicate that the unit or module is optional. Apparatus 1300 may be used to implement the method described in the above method embodiment. Apparatus 1300 may be a chip, a terminal device, or a network device.

[0094] The device 1300 may include one or more processors 1310. The processor 1310 may support the device 1300 to implement the method described in the above method embodiment. The processor 1310 may be a general-purpose processor or a special-purpose processor. For example, the processor may be a central processing unit (CPU). Alternatively, the processor may be another general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic device, discrete gate or transistor logic device, discrete hardware component, etc. The general-purpose processor may be a microprocessor or the processor may be any conventional processor, etc.

[0095] The apparatus 1300 may further include one or more memories 1320. The memories 1320 store programs that can be executed by the processor 1310, causing the processor 1310 to perform the methods described in the above method embodiments. The memories 1320 may be independent of the processor 1310 or integrated into the processor 1310.

[0096] The apparatus 1300 may further include a transceiver 1330. The processor 1310 may communicate with other devices or chips via the transceiver 1330. For example, the processor 1310 may transmit and receive data with other devices or chips via the transceiver 1330.

[0097] The present invention also provides a computer-readable storage medium for storing a program. The computer-readable storage medium can be applied to the communication device provided in the present invention, and the program enables a computer to execute the method in each embodiment of the present invention.

[0098] The present application also provides a computer program product. The computer program product includes a program. The computer program product can be applied to the communication device provided in the present application, and the program enables a computer to execute the method in each embodiment of the present application.

[0099] The embodiments of the present application also provide a computer program. The computer program can be applied to the communication device provided in the embodiments of the present application, and the computer program enables a computer to execute the methods in the various embodiments of the present application.

[0100] It should be understood that all or part of the functions of the communication device in this application can also be implemented through software functions running on hardware, or through virtualization functions instantiated on a platform (such as a cloud platform).

[0101] It should be understood that the terms "system" and "network" in this application can be used interchangeably. In addition, the terms used in this application are only used to explain the specific embodiments of this application and are not intended to limit this application. The terms "first," "second," "third," and "fourth," etc. in the specification and claims of this application and the accompanying drawings are used to distinguish different objects rather than to describe a specific order. In addition, the terms "including" and "having," as well as any variations thereof, are intended to cover non-exclusive inclusions.

[0102] In the embodiments of this application, the term "indication" may refer to a direct indication, an indirect indication, or an indication of an association. For example, "A indicates B" may refer to a direct indication of B, e.g., B can obtain information through A; it may refer to an indirect indication of B, e.g., A indicates C, e.g., B can obtain information through C; or it may refer to an association between A and B.

[0103] In the embodiment of the present application, "B corresponding to A" means that B is associated with A and B can be determined based on A. However, it should be understood that determining B based on A does not mean determining B based solely on A, but B can also be determined based on A and / or other information.

[0104] In the embodiments of the present application, the term "corresponding" may indicate a direct or indirect correspondence between the two, or an association relationship between the two, or a relationship between indication and indication, configuration and configuration, etc.

[0105] In the embodiments of the present application, "pre-definition" or "pre-configuration" may be implemented by pre-storing corresponding codes, tables, or other methods that can be used to indicate relevant information in a device (e.g., a terminal device and a network device). The present application does not limit the specific implementation method. For example, pre-definition may refer to information defined in a protocol.

[0106] In the embodiments of the present application, the “protocol” may refer to a standard protocol in the communications field, for example, it may include an LTE protocol, an NR protocol, and related protocols used in future communication systems, and the present application does not limit this.

[0107] In the embodiments of this application, the term "and / or" is simply a description of the association relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " in this document generally indicates that the related objects are in an "or" relationship.

[0108] In the embodiments of this application, the term "include" can refer to direct inclusion or indirect inclusion. Alternatively, the term "include" in the embodiments of this application can be replaced with "indicates" or "is used to determine." For example, "A includes B" can be replaced with "A indicates B" or "A is used to determine B."

[0109] In various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0110] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0111] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0112] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0113] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be read by a computer or a data storage device such as a server or data center that includes one or more available media integrated therein. The available medium may be a magnetic medium (eg, a floppy disk, a hard disk, a magnetic tape), an optical medium (eg, a digital versatile disc (DVD)), or a semiconductor medium (eg, a solid state disk (SSD)).

[0114] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

Claims

1. A wireless communication method, characterized in that: include: The first device receives first information sent by the second device, where the first information includes a first security indication, where the first security indication corresponds to an algorithm type of a first encryption algorithm, and the first encryption algorithm is an encryption algorithm used between the second device and the first terminal device; The first device determines an algorithm type of a second encryption algorithm based on the first security indication. The second encryption algorithm is an encryption algorithm used between the first device and the first terminal device. The second encryption algorithm is of the same algorithm type as the first encryption algorithm.

2. The method according to claim 1, characterized in that The algorithm type is the first type or the second type, the first type corresponds to a 128-bit encryption algorithm, and the second type corresponds to a 256-bit encryption algorithm.

3. The method according to claim 1 or 2, characterized in that The first security indication is determined based on an algorithm type of an encryption algorithm supported by the first device.

4. The method according to claim 3, characterized in that Before the first device receives the first information sent by the second device, the method further includes: The first device sends second information to the second device, where the second information is used to indicate an algorithm type of an encryption algorithm supported by the first device.

5. The method according to any one of claims 1 to 4, characterized in that The first information also includes a first security policy, where the first security policy is used to indicate an algorithm type of an encryption algorithm supported by the second device.

6. The method according to claim 5, characterized in that The method further comprises: The first device sends the first security policy to the third device, where the first security policy is used by the third device to determine an encryption algorithm used between the third device and the first terminal device.

7. The method according to any one of claims 1 to 6, characterized in that The first device is an access network device, and the second device is a core network device.

8. A wireless communication method, characterized in that: include: The second device determines a first security indication based on the security capability of the first terminal device and / or the algorithm type of the encryption algorithm supported by the second device; The second device sends first information to the first device, where the first information includes the first security indication. There is a correspondence between the first security indication and the algorithm type of the first encryption algorithm. The first encryption algorithm is the encryption algorithm used between the second device and the first terminal device.

9. The method according to claim 8, characterized in that The algorithm type is the first type or the second type, the first type corresponds to a 128-bit encryption algorithm, and the second type corresponds to a 256-bit encryption algorithm.

10. The method according to claim 8 or 9, characterized in that The first security indication is determined based on an algorithm type of an encryption algorithm supported by the first device.

11. The method according to claim 10, characterized in that Before the second device sends the first information to the first device, the method further includes: The second device receives second information sent by the first device, where the second information is used to indicate an algorithm type of an encryption algorithm supported by the first device.

12. The method according to any one of claims 8 to 11, characterized in that The first information also includes a first security policy, where the first security policy is used to indicate an algorithm type of an encryption algorithm supported by the second device.

13. The method according to any one of claims 8 to 12, characterized in that The first device is an access network device, and the second device is a core network device.

14. A communication device, characterized in that: The communication device is a first device, and the communication device includes: a receiving module, configured to receive first information sent by a second device, the first information including a first security indication, the first security indication corresponding to an algorithm type of a first encryption algorithm, the first encryption algorithm being an encryption algorithm used between the second device and the first terminal device; A determination module is used to determine the algorithm type of a second encryption algorithm based on the first security indication, where the second encryption algorithm is the encryption algorithm used between the first device and the first terminal device, and the second encryption algorithm is of the same algorithm type as the first encryption algorithm.

15. The communication device according to claim 14, wherein: The algorithm type is the first type or the second type, the first type corresponds to a 128-bit encryption algorithm, and the second type corresponds to a 256-bit encryption algorithm.

16. The communication device according to claim 14 or 15, characterized in that The first security indication is determined based on an algorithm type of an encryption algorithm supported by the first device.

17. The communication device according to claim 16, wherein: The communication device further includes: The first sending module is configured to send second information to the second device before the receiving module receives the first information sent by the second device, where the second information is used to indicate an algorithm type of an encryption algorithm supported by the first device.

18. The communication device according to any one of claims 14 to 17, characterized in that: The first information also includes a first security policy, where the first security policy is used to indicate an algorithm type of an encryption algorithm supported by the second device.

19. The communication device according to claim 18, wherein: The communication device further includes: The second sending module is used to send the first security policy to a third device, where the first security policy is used by the third device to determine an encryption algorithm used between the third device and the first terminal device.

20. The communication device according to any one of claims 14 to 19, characterized in that: The first device is an access network device, and the second device is a core network device.

21. A communication device, characterized in that: The communication device is a second device, and the communication device includes: a determination module, configured to determine a first security indication based on a security capability of the first terminal device and / or an algorithm type of an encryption algorithm supported by the second device; A sending module is used to send first information to the first device, where the first information includes the first security indication, and there is a corresponding relationship between the first security indication and the algorithm type of the first encryption algorithm, and the first encryption algorithm is the encryption algorithm used between the second device and the first terminal device.

22. The communication device according to claim 21, wherein: The algorithm type is the first type or the second type, the first type corresponds to a 128-bit encryption algorithm, and the second type corresponds to a 256-bit encryption algorithm.

23. The communication device according to claim 21 or 22, characterized in that The first security indication is determined based on an algorithm type of an encryption algorithm supported by the first device.

24. The communication device according to claim 23, wherein: The communication device further includes: The receiving module is used to receive second information sent by the first device before the sending module sends the first information to the first device, where the second information is used to indicate the algorithm type of the encryption algorithm supported by the first device.

25. The communication device according to any one of claims 21 to 24, characterized in that The first information also includes a first security policy, where the first security policy is used to indicate an algorithm type of an encryption algorithm supported by the second device.

26. The communication device according to any one of claims 21 to 24, characterized in that The first device is an access network device, and the second device is a core network device.

27. A communication device, characterized in that: The communication device comprises a transceiver, a memory and a processor, wherein the memory is used to store a program, and the processor is used to call the program in the memory and control the transceiver to receive or send a signal, so that the communication device executes the method according to any one of claims 1 to 7.

28. A communication device, characterized in that: The communication device comprises a transceiver, a memory and a processor, wherein the memory is used to store a program, and the processor is used to call the program in the memory and control the transceiver to receive or send a signal, so that the communication device executes the method according to any one of claims 8 to 13.

29. A device, characterized in that The device comprises a processor configured to call a program from a memory so as to cause the device to execute the method according to any one of claims 1 to 7 or 8 to 13.

30. A chip, characterized in that: The device comprises a processor configured to call a program from a memory so that a device equipped with the chip executes the method according to any one of claims 1 to 7 or 8 to 13.

31. A computer-readable storage medium, characterized in that A program is stored thereon, the program causing a computer to execute the method according to any one of claims 1 to 7 or 8 to 13.

32. A computer program product, characterized in that The method comprises a program for causing a computer to execute the method according to any one of claims 1 to 7 or 8 to 13.

33. A computer program, characterized in that The computer program enables a computer to execute the method according to any one of claims 1 to 7 or 8 to 13.

Citation Information

Patent Citations

  • Security protection method and device and access network equipment

    CN110167018A

  • Method and Device for Negotiating Security and Integrity Algorithms

    US20190082325A1

  • Communication method and apparatus

    WO2022198671A1