Communication method, apparatus, and system
By using different NCCs and NHs in LTM cross-site handover, the problem of secure communication between terminals and network devices is solved, secure continuous communication is achieved and signaling overhead is reduced.
Patent Information
- Application Number
- PCT/CN2025/073688
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-02
- Filing Date
- 2025-01-21
- Publication Date
- 2025-08-07
AI Technical Summary
In the LTM cross-site switching scenario, the existing technology still needs further research on how to achieve secure communication between terminals and network devices.
By using different next-hop link counters (NCC) and next-hop (NH) during multiple handovers, there is no need to pass security-related information through RRC reconfiguration messages, and secure communication between terminals and network devices is achieved.
In the LTM cross-site switching scenario, secure and continuous communication between the terminal and the network device is ensured, signaling overhead is reduced, and security is improved.
Smart Images

Figure CN2025073688_07082025_PF_FP_ABST
Abstract
Description
Communication method, device and system
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of the People's Republic of China on February 2, 2024, with application number 202410154755.0 and application name "A Communication Method, Device and System", the entire contents of which are incorporated by reference into this application. Technical Field
[0003] The present application relates to the field of communication technology, and in particular to a communication method, device, and system. Background Art
[0004] Cell switching is a very important feature in communication systems. It mainly involves the network equipment switching the terminal device to a neighboring cell with better signal quality before the signal quality of the serving cell becomes poor, thereby providing lossless or packet loss-free communication services.
[0005] In order to reduce the switching delay, layer 1 / layer 2 triggered mobility (L1 / L2 triggered mobility, LTM) switching is currently introduced. LTM switching can be triggered by layer 1 / layer 2 signaling.
[0006] However, how to achieve secure communication between terminals and network devices in LTM cross-site switching scenarios still needs further research. Summary of the Invention
[0007] The present application provides a communication method, apparatus, and system for implementing secure communication between a terminal and a network device.
[0008] In a first aspect, an embodiment of the present application provides a communication method, which can be applied to a terminal-side device, where the terminal-side device can be a terminal or a component in the terminal (such as a chip or circuit). For example, in this method, the terminal-side device accesses a first network-side device; uses a first next-hop link counter NCC to communicate with the first network-side device, where the first NCC is obtained by adding 1 to the second NCC of the terminal-side device; the second NCC is the NCC used by the terminal-side device to communicate with the second network-side device, or the second NCC is the NCC used for the last access to the first network-side device.
[0009] Using the above method, different NHs can be used for multiple switches to the same network device, thereby eliminating the need to transmit security-related information to the terminal through RRC reconfiguration messages, facilitating secure communication between the terminal and the network device in the LTM cross-site handover scenario and ensuring secure communication for continuous cross-site handovers.
[0010] In one possible design, the method further includes receiving a first message, where the first message includes the second NCC.
[0011] In one possible design, the first message also includes identification information associated with the first network side device; the method also includes: based on the identification information associated with the first network side device (i.e., the identification information associated with the target cell) and the identification information associated with the second network side device (i.e., the identification information associated with the source cell), determining that the key needs to be updated, and the key update includes: determining the first NCC and the next hop NH associated with the first NCC.
[0012] It is understandable that the “need to update the key” here can also be understood as “need to perform vertical deduction of NH” or “need to replace NH”.
[0013] In a possible design, the identification information associated with the first network side device is associated with the second NCC, or the cell of the first network side device (such as the above-mentioned target cell) is associated with the second NCC.
[0014] In one possible design, the first message also includes root key information associated with the second NCC.
[0015] In this way, when the root key is replaced, the root key information can be sent to the terminal through the first message, and security can be effectively improved by replacing the root key.
[0016] The communication method provided in the first aspect above can be replaced by: the terminal side device receives a first message, where the first message is used to indicate N NCCs, where N is an integer greater than 1; accesses a first network side device; uses a first NCC to communicate with the first network side device, where the first NCC is one of the N NCCs, and the NH associated with the first NCC is an unused NH.
[0017] In one possible design, the first message includes N NCCs; or, the first message includes a starting NCC and a value of N among the N NCCs, and the N NCCs are continuous.
[0018] In one possible design, the first message includes identification information associated with the first network side device; the method also includes: determining that a key needs to be updated based on the identification information associated with the first network side device and the identification information associated with the second network side device, and the key update includes: determining the first NCC and the NH associated with the first NCC.
[0019] In a possible design, the identification information associated with the first network side device is associated with the N NCCs, or in other words, the cell of the first network side device (such as the target cell) is associated with N NCCs.
[0020] In one possible design, the first message also includes root key information associated with the N NCCs.
[0021] In one possible design, accessing the first network side device includes: initiating layer 1 / layer 2 triggered mobility LTM switching to access the first network side device; or, after the LTM switching fails, accessing the first network side device through LTM configuration.
[0022] In a second aspect, an embodiment of the present application provides a communication method, which can be applied to a first network-side device, which can be a first network device or a component (such as a chip or circuit) in the first network device. For example, in this method, the first network-side device receives a second message, which includes N NHs, where N is an integer greater than or equal to 1; determines that a terminal-side device accesses the first network-side device; and uses a first NH of the N NHs to communicate with the terminal-side device, where the first NH is an unused NH of the N NHs.
[0023] Using the above method, different NHs can be used for multiple switches to the first network device, thereby eliminating the need to transmit security-related information to the terminal through RRC reconfiguration messages, thereby facilitating secure communication between the terminal and the network device in the LTM cross-site switching scenario and ensuring secure communication for continuous cross-site switching.
[0024] In a possible design, the N NHs are sorted in a first order, and the first NH is the first unused NH among the N NHs.
[0025] In one possible design, the method further includes determining the first order based on the second message.
[0026] In one possible design, the N NHs included in the second message are sorted in a first order.
[0027] In a possible design, the second message is used to indicate the NCC associated with the N NHs; sorting the N NHs according to the first order includes: sorting the N NHs from small to large based on the NCC associated with the N NHs.
[0028] In one possible design, determining that the terminal side device is connected to the first network side device includes: determining that the terminal side device initiates LTM switching to access the first network side device; or determining that the terminal side device accesses the first network side device through LTM configuration after the LTM switching fails.
[0029] In one possible design, the method also includes: sending a third message to the core network network element, the third message being used to request providing NH to the first network side device; receiving the second message, including: receiving the second message from the core network network element, the second message being a response message to the third message.
[0030] In one possible design, the third message includes quantity information of NHs.
[0031] In one possible design, sending a third message to the core network network element includes: receiving a fourth message from a third network side device, the fourth message being used to request the LTM configuration of the first network side device; and sending the third message to the core network network element in response to the fourth message.
[0032] Here, the fourth message is used to request the LTM configuration of the first network side device. It can be understood that the fourth message is used to request the LTM configuration of a candidate cell of the first network side device. The fourth message can include identification information of the candidate cell, such as CGI.
[0033] In one possible design, the method further includes: sending a first message to the terminal side device, where the first message is used to indicate the NCC associated with the N NHs.
[0034] In one possible design, the first message includes the NCC associated with the N NHs; or, the first message includes a second NCC, the N NHs are sorted from small to large based on the NCCs associated with the N NHs, the NCCs associated with the N NHs are continuous, and the second NCC is the NCC associated with the starting NH among the N NHs.
[0035] In one possible design, the first message also includes identification information associated with the first network side device, the identification information associated with the first network side device is associated with the second NCC, or the identification information associated with the first network side device is associated with the NCC associated with the N NHs.
[0036] In one possible design, the method further includes: sending a fifth message to the core network element, the fifth message being used to request path switching, and the fifth message being further used to indicate not to update NH.
[0037] In a third aspect, an embodiment of the present application provides a communication method, which can be applied to a third network-side device, which can be a third network device or a component (such as a chip or circuit) in the third network device. For example, in this method, the third network-side device receives a sixth message from a core network element, wherein the sixth message includes W NHs, where W is an integer greater than 1; sends a second message to a first network-side device, wherein the second message includes N NHs, wherein the W NHs include the N NHs, where N is an integer greater than or equal to 1; and sends a first message to a terminal-side device, wherein the first message is used to indicate the NCC associated with the N NHs.
[0038] Using the above method, the third network device requests NH from the core network network element and distributes the requested multiple NHs to each candidate network device. Then, for multiple switches to the same network device, different NHs can be used. There is no need to transmit security-related information to the terminal through the RRC reconfiguration message, which facilitates secure communication between the terminal and the network device in the LTM cross-site switching scenario, improves the security of continuous cross-site switching, and ensures secure communication of continuous cross-site switching.
[0039] In one possible design, the first message includes the NCC associated with the N NHs; or, the first message includes a second NCC, the N NHs are sorted from small to large based on the NCCs associated with the N NHs, the NCCs associated with the N NHs are continuous, and the second NCC is the NCC associated with the starting NH among the N NHs.
[0040] In one possible design, the first message also includes identification information associated with the first network side device, the identification information associated with the first network side device is associated with the second NCC, or the identification information associated with the first network side device is associated with the NCC associated with the N NHs.
[0041] In one possible design, the W NHs also include M NHs, and the M NHs are different from the N NHs; the method also includes: determining that the terminal side device accesses the third network side device; using a second NH among the M NHs to communicate with the terminal side device, and the second NH is an unused NH among the M NHs.
[0042] In a fourth aspect, an embodiment of the present application provides a communication method, which can be applied to a third network-side device, which can be a third network device or a component (such as a chip or circuit) in the third network device. For example, in this method, the third network-side device receives a sixth message from a core network element, the sixth message including W NHs, where W is an integer greater than 1; receives a seventh message, the seventh message being used to request security information; and in response to the seventh message, sends the security information, the security information including the first NH among the W NHs or the index of the first NH or a key derived based on the first NH, the first NH being an unused NH among the W NHs.
[0043] Using the above method, the third network device requests W NHs from the core network element. During each handover, the third network device allocates an unused NH to the target network device of the current handover, so that a different NH can be used for each handover. There is no need to transmit security-related information to the terminal through the RRC reconfiguration message, which facilitates secure communication between the terminal and the network device in the LTM cross-site handover scenario, improves the security of continuous cross-site handovers, and ensures secure communication in continuous cross-site handovers.
[0044] In a possible design, the W NHs are sorted in a first order, and the first NH is the first unused NH among the W NHs.
[0045] In one possible design, the method further includes: determining an order of the W NHs based on the second message.
[0046] In one possible design, the W NHs included in the second message are sorted in a first order.
[0047] In one possible design, the second message includes the NCCs associated with the W NHs; and sorting the W NHs according to the first order includes sorting the W NHs from small to large based on the NCCs associated with the W NHs.
[0048] In one possible design, the method further includes: sending a first message to the terminal side device, where the first message is used to indicate the NCC associated with the W NHs.
[0049] In one possible design, the first message includes the NCC associated with the W NHs; or, the first message includes a second NCC, the W NHs are sorted from small to large based on the NCCs associated with the W NHs, the NCCs associated with the W NHs are continuous, and the second NCC is the NCC associated with the starting NH among the W NHs.
[0050] In one possible design, the method further includes sending the W NHs, wherein the index of the first NH is used to determine the first NH from the W NHs.
[0051] In a fifth aspect, an embodiment of the present application provides a communication method, which can be applied to a first network-side device, which can be a first network device or a component (such as a chip or circuit) in the first network device. For example, in this method, the first network-side device determines that the terminal-side device is connected to the first network-side device; sends a seventh message, the seventh message is used to request security information; receives security information, the security information includes a first NH or an index of the first NH or a key derived based on the first NH; and uses the security information to communicate with the terminal-side device.
[0052] In one possible design, determining that the terminal side device is connected to the first network side device includes: determining that the terminal side device initiates LTM switching to access the first network side device; or determining that the terminal side device accesses the first network side device through LTM configuration after the LTM switching fails.
[0053] In one possible design, the method further includes: sending a fifth message to the core network element, the fifth message being used to request path switching, and the fifth message being further used to indicate not to update NH.
[0054] It can be understood that the communication methods provided in the second to fifth aspects correspond to the first aspect, and the beneficial effects of the relevant technical features in the second to fifth aspects can be referred to the description of the first aspect and will not be repeated here.
[0055] In a sixth aspect, the present application provides a communication device, which has the ability to implement the functions involved in any one of the first to fifth aspects above. For example, the communication device includes modules or units or means corresponding to the operations involved in any one of the first to fifth aspects above. The functions or units or means can be implemented through software, or through hardware, or the corresponding software can be implemented through hardware.
[0056] In one possible design, the communication device includes a processing unit and a communication unit. The communication unit can be used to send and receive signals to enable communication between the communication device and other devices; the processing unit can be used to perform certain internal operations of the communication device. The functions performed by the processing unit and the communication unit can correspond to the operations described in any of the first to fifth aspects above.
[0057] In one possible design, the communication device includes a processor, which can be coupled to a memory. The memory can store the necessary computer programs or instructions for implementing the functions of any of the first to fifth aspects. The processor can execute the computer programs or instructions stored in the memory. When the computer programs or instructions are executed, the communication device implements the method of any possible design or implementation of the first to fifth aspects.
[0058] In one possible design, the communication device includes a processor and a memory, and the memory may store the necessary computer programs or instructions for implementing the functions of any of the first to fifth aspects described above. The processor may execute the computer program or instructions stored in the memory. When the computer program or instructions are executed, the communication device implements the method of any possible design or implementation of the first to fifth aspects described above.
[0059] In one possible design, the communication device includes a processor and an interface circuit, wherein the processor is used to communicate with other devices through the interface circuit and execute the method in any possible design or implementation of the first to fifth aspects above.
[0060] It can be understood that in the sixth aspect above, the processor can be implemented by hardware or by software. When implemented by hardware, the processor can be a logic circuit, an integrated circuit, etc.; when implemented by software, the processor can be a general-purpose processor, which is implemented by reading the software code stored in the memory. In addition, the above processors can be one or more, and the memories can be one or more. The memory can be integrated with the processor, or the memory and the processor can be set separately. In the specific implementation process, the memory can be integrated with the processor on the same chip, or can be set on different chips respectively. The embodiment of the present application does not limit the type of memory and the setting method of the memory and the processor.
[0061] In a seventh aspect, the present application provides a communication system, which may include a terminal-side device and a first network-side device; wherein the terminal-side device is configured to execute the method described in the first aspect, and the first network-side device is configured to execute the method described in the second aspect. Optionally, the communication system further includes a third network-side device configured to execute the method described in the third aspect.
[0062] Alternatively, the communication system includes a terminal-side device and a third network-side device, wherein the terminal-side device is configured to execute the method described in the first aspect, and the first network-side device is configured to execute the method described in the fourth aspect. Optionally, the communication system further includes a first network-side device, and the first network-side device is configured to execute the method described in the fifth aspect.
[0063] In an eighth aspect, the present application provides a computer-readable storage medium, in which computer-readable instructions are stored. When a computer reads and executes the computer-readable instructions, the computer executes the method in any possible design of the first to fifth aspects above.
[0064] Exemplarily, a computer-readable storage medium can be any available medium that can be accessed by a computer. By way of example and not limitation, a computer-readable medium can include a non-transitory computer-readable medium, a random-access memory (RAM), a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), a CD-ROM or other optical disk storage, a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer.
[0065] In a ninth aspect, the present application provides a computer program product, which, when read and executed by a computer, enables the computer to execute the method in any possible design of the first to fifth aspects above.
[0066] In the tenth aspect, the present application provides a chip (or chip system), which includes a processor, and the processor is coupled to a memory, and is used to read and execute a software program stored in the memory to implement the method in any possible design of the first to fifth aspects above. BRIEF DESCRIPTION OF THE DRAWINGS
[0067] FIG1 is a schematic diagram of a communication system applicable to an embodiment of the present application;
[0068] FIG2 is a schematic diagram of key deduction provided in an embodiment of the present application;
[0069] FIG3 is a schematic diagram of a possible process of a common cross-site handover provided in an embodiment of the present application;
[0070] FIG4 is a schematic diagram of a flow chart associated with the communication method provided in Example 1 of the present application;
[0071] FIG5A is a schematic diagram of a flow chart associated with a communication method provided in Example 2 of the present application;
[0072] FIG5B is a schematic diagram of NH provided in an embodiment of the present application;
[0073] FIG6 is a schematic diagram of a flow chart associated with the communication method provided in Example 3 of the present application;
[0074] FIG7 is a schematic diagram of a flow chart associated with the communication method provided in Example 4 of the present application;
[0075] FIG8 is a schematic diagram of a flow chart associated with the communication method provided in Example 5 of the present application;
[0076] FIG9 is a schematic diagram of a flow chart associated with a communication method provided in Example 6 of the present application;
[0077] FIG10 is a possible exemplary block diagram of a device involved in an embodiment of the present application;
[0078] FIG11 is a schematic structural diagram of a network-side device provided in an embodiment of the present application;
[0079] FIG12 is a schematic structural diagram of a terminal-side device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0080] The technical solutions in the embodiments of the present application will be described below in conjunction with the accompanying drawings in the embodiments of the present application. The technical solutions in the embodiments of the present application can be applied to various communication systems, such as universal mobile telecommunications system (UMTS), wireless local area network (WLAN), wireless fidelity (Wi-Fi) system, 4th generation (4G) mobile communication system, such as long term evolution (LTE) system, fifth generation (5G) mobile communication system, such as new radio (NR) system, and future evolved communication systems, such as sixth generation (6G) mobile communication system.
[0081] This application will present various aspects, embodiments, or features in the context of systems that may include multiple devices, components, modules, etc. It should be understood and appreciated that each system may include additional devices, components, modules, etc., and / or may not include all of the devices, components, modules, etc. discussed in conjunction with the figures. Furthermore, combinations of these aspects may also be used.
[0082] In addition, in the embodiments of the present application, words such as "exemplarily" and "such as" are used to indicate examples, illustrations or descriptions. Any embodiment or design described as an "example" in this application should not be interpreted as being more preferred or more advantageous than other embodiments or designs. Specifically, the use of the word "example" is intended to present concepts in a concrete way. In the embodiments of the present application, "of", "corresponding, relevant" and "corresponding" can sometimes be used interchangeably. It should be noted that when the distinction between them is not emphasized, the meanings to be expressed are consistent.
[0083] To facilitate understanding of the embodiments of the present application, the communication system applicable to the embodiments of the present application is first described in detail using the communication system shown in FIG1 as an example. As shown in FIG1 , the communication system 10 includes a wireless access network 100, and optionally, a core network 200. The wireless access network 100 may include at least one network device, such as 110a and 110b in FIG1 , and may also include at least one terminal, such as 120a-120j in FIG1 . 110a is a base station, 110b is a micro station, 120a, 120e, 120f, and 120j are mobile phones, 120b is a car, 120c is a gas pump, 120d is a home access point (HAP) arranged indoors or outdoors, 120g is a laptop computer, 120h is a printer, and 120i is a drone.
[0084] In Figure 1, terminals can be connected to network devices, and network devices can be connected to core network devices in the core network. The core network devices and network devices can be independent, distinct physical devices, or they can integrate the core network device's functions and the network device's logical functions into the same physical device. Alternatively, a single physical device can integrate some core network device functions and some network device functions. Terminals and network devices can be connected to each other via wired or wireless means. Figure 1 is merely a schematic diagram; the communication system may also include other devices, such as wireless relay devices and wireless backhaul devices, which are not shown in Figure 1.
[0085] (1) Terminal
[0086] A terminal can be a device that accesses the above-mentioned communication system and has wireless transceiver capabilities. A terminal may also be called user equipment (UE), terminal equipment, user device, access terminal, user unit, user station, mobile station, mobile station (MS), remote station, remote terminal, mobile device, user terminal, terminal unit, terminal station, terminal device, wireless communication device, user agent, or user device.
[0087] For example, the terminal in the embodiment of the present application can be a mobile phone, a personal digital assistant (PDA), a laptop computer, a tablet computer, a drone, a computer with wireless transceiver function, a machine type communication (MTC) terminal, a virtual reality (VR) terminal, an augmented reality (AR) terminal, an Internet of Things (IoT) terminal, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, a wireless terminal in a smart home (such as a game console, a smart TV, a smart speaker, a smart refrigerator, and fitness equipment, etc.), a vehicle-mounted terminal, and an RSU with terminal function.
[0088] (2) Network equipment
[0089] A network device is a device located on the network side of the communication system and has wireless transceiver capabilities. A network device can also be called an access network node, access network device, or wireless access network device.
[0090] In one possible scenario, the network device may be a base station, an evolved NodeB (eNB), an access point (AP), a transmission reception point (TRP), a next generation-evolved NodeB (ng-eNB), a next generation NodeB (gNB), a next generation base station in a 6G mobile communication system, a base station in a future mobile communication system, or an access node in a WiFi system. The network device may be a macro base station (such as 110a in Figure 1), a micro base station or an indoor station (such as 110b in Figure 1), a relay node, or a donor node. Optionally, the network device may also be a server, a wearable device, a vehicle, or an on-board device. For example, the network device in vehicle to everything (V2X) technology may be a road side unit (RSU).
[0091] In another possible scenario, multiple network devices collaborate to assist the terminal in achieving wireless access, and different network devices respectively implement part of the functions of the base station. For example, the network device can be a centralized unit (CU), a distributed unit (DU), a CU-control plane (CP), a CU-user plane (UP), or a radio unit (RU). The CU and DU can be set separately, or they can be included in the same network element, such as a baseband unit (BBU). The RU can be included in a radio frequency device or radio frequency unit, such as a remote radio unit (RRU), an active antenna unit (AAU), or a remote radio head (RRH).
[0092] In the embodiment of the present application, when the wireless access network 100 includes multiple network devices, the multiple network devices may be connected via Xn interfaces.
[0093] (3) Core network elements
[0094] The core network 200 may include one or more core network elements, such as an access and mobility management function (AMF) network element, a user plane function (UPF) network element, a session management function (SMF) network element, a policy control function (PCF) network element, etc. Among them, network devices and core network elements in the core network can be connected through NG interfaces, such as a network device and an AMF network element through an NG-C interface, and a network device and a UPF network element through an NG-U interface.
[0095] The UPF network element is mainly responsible for connecting to the external network and forwarding user data packets according to the routing rules of the SMF network element, such as sending uplink data to the data network or other UPF network elements, and sending downlink data to other UPF network elements or access network devices.
[0096] The AMF network element is mainly responsible for the access management and mobility management of terminal devices, such as the status maintenance of terminal devices, the reachability management of terminal devices, the forwarding of non-mobility management access layer (mobility management non-access-stratum, MM NAS) messages, and the forwarding of session management (session management, SM) N2 messages.
[0097] The SMF network element is primarily responsible for session management in mobile networks, including establishing sessions for terminal devices and allocating and releasing resources for sessions, including session quality of service (QoS), session paths, and forwarding rules. For example, it allocates Internet Protocol (IP) addresses to terminal devices and selects the UPF network element that provides packet forwarding functions.
[0098] The PCF network element is mainly responsible for user policy management, including the generation of policy authorization, service quality and billing rules, and sends the corresponding rules to the UPF network element through the SMF network element to complete the installation of the corresponding policies and rules.
[0099] Although not shown, the core network may also include other possible network elements, which are not specifically limited.
[0100] The network elements in the above-mentioned communication system can be network components in hardware devices, software functions running on dedicated hardware, or virtualized functions instantiated on a platform (e.g., a cloud platform). Optionally, the above-mentioned network elements can be implemented by a single device, or by multiple devices, or can be different functional modules within a single device, which is not specifically limited in the embodiments of the present application.
[0101] The network architecture and business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. Ordinary technicians in this field can know that with the evolution of communication system architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.
[0102] The following first explains the relevant terms involved in the embodiments of this application. When not specifically explained, these explanations are intended to support the meaning of the relevant terms and make the embodiments of this application easier to understand, and should not be regarded as strict limitations on the relevant terms in the scope of protection claimed by this application.
[0103] (1) Key deduction
[0104] To ensure secure data transmission between the terminal and the network, both the terminal and the network must perform the same key derivation to ensure they use the same key. "Network" may include network devices (such as access network devices or gNBs). "Derivation" can be replaced with "derived" or other terms without limitation.
[0105] Parameters related to key deduction include the next hop (NH) and the NH chaining counter (NCC).
[0106] NH: Intermediate key, based on the root key KAMF, obtained by chain deduction.
[0107] NCC: The number of times NH is deduced in a chain deduction. NCC is associated with NH. One NCC can uniquely identify one NH.
[0108] Specifically, NH is derived by the terminal and AMF network element using a chain derivation. That is, the NH generated this time will be used to generate the next NH. The AMF network can send the derived NH and NCC to the network device to facilitate secure communication between the network device and the terminal based on the NH. The root key KAMF can be understood as the core network key.
[0109] In one example, the NCC in the embodiment of the present application may include 3 bits and can identify up to 8 NHs. In another example, the NCC in the embodiment of the present application may also be replaced by NCC', where NCC' is a combination of NCC and H-NCC, or NCC' is a newly defined NCC. Among them, H-NCC is based on NCC, with a few higher bits added to identify more NHs. For example, NCC can identify up to 8 NHs, but H-NCC is also 3 bits, then NCC' is 6 bits, which can identify 64 NHs.
[0110] FIG2 is a flow chart showing the process of performing key deduction by a network device and a terminal.
[0111] Horizontal deduction:
[0112] During initial access, the network device can deduce the initial key KgNB (initial KgNB) based on the root key (i.e., KAMF), and deduce KgNB1 based on the initial key KgNB. Subsequently, if horizontal deduction is to be performed, the network device deduces the key KgNB2 based on KgNB1, the physical cell identifier (PCI) of the cell where the terminal currently resides, and the frequency, such as the downlink frequency. If horizontal deduction continues, the network device can deduce the key KgNB3 based on the key KgNB2, the PCI of the cell where the terminal currently resides, and the frequency. And so on, the key KgNB is iteratively updated to ensure communication security.
[0113] Vertical deduction:
[0114] This deduction method is a vertical deduction for NH. The AMF network element can update the NCC (for example, when a path switch occurs during the switching process, the AMF network element can update the NCC). If NCC1 is updated to NCC2, the AMF network element deduces NH2 based on KAMF and NCC2. NH2 is associated with NCC2 as a new pair of {NH2, NCC2}. The AMF network element can send {NH2, NCC2} to the network device. After receiving {NH2, NCC2}, the network device can perform vertical deduction when it needs to deduce the key, that is, deduce the key KgNB4 based on NH2, the PCI of the cell where the terminal is currently located, and the frequency, and so on.
[0115] As shown in Figure 2, the number of vertical deductions can be determined by the difference between the NCC value before and after the update. For example, if the NCC value is updated from NCC0 to NCC1, one vertical deduction can be performed based on NH0 associated with NCC0 to obtain NH1 associated with NCC1. If the NCC value is updated from NCC0 to NCC2, two vertical deductions can be performed based on NH0 associated with NCC0 to obtain NH2 associated with NCC2. If the NCC value is updated from NCC2 to NCC3, one vertical deduction can be performed based on NH2 associated with NCC2 to obtain NH3 associated with NCC3.
[0116] (2) Cell switching
[0117] Cell switching (switch or handover) can be divided into two types, one of which is cell switching based on layer 1 / layer 2, which can be called layer 1 / layer 2 switching or LTM switching, and the other is cell switching based on layer 3, which can be called layer 3 switching (L3 handover) or ordinary switching. Among them, layer 1 can refer to the physical layer, layer 2 can refer to any layer or multiple layers of the packet data convergence protocol (PDCP) layer, the radio link control (RLC) layer, and the media access control (MAC) layer, and layer 3 can refer to the radio resource control (RRC) layer. Since layer 1 / layer 2 is located at a lower level of the protocol stack than the RRC layer (layer 3), layer 1 / layer 2 switching can also be called low-layer switching, bottom layer switching, or lower-layer switching. This application does not limit the name of the specific switching technology.
[0118] Compared with layer 3 switching, LTM switching can effectively reduce switching delay. The reason is: for layer 3 switching, in the CU-DU separation architecture, the CU receives the measurement results of the terminal (the measurement results are forwarded to the CU through the DU), and determines whether to initiate switching based on the measurement results. If it is determined to initiate switching, the switching command message (such as RRC message) is sent to the DU, and the DU sends it to the terminal. Since this process involves communication interaction between the CU and the DU (that is, the interaction of the F1 interface), and the maximum transmission delay of the F1 interface is approximately 3ms to 10ms, it will cause a certain switching delay. The switching decision of LTM switching is sent from the CU to the DU, that is, the DU determines whether to initiate LTM switching based on the measurement results of the terminal. If it is determined to initiate switching, the switching command message (such as a MAC layer message) is sent to the terminal, which can effectively reduce F1 interaction and reduce switching delay.
[0119] (3) Cell switching scenarios
[0120] When a terminal switches between different cells, there may be multiple specific switching scenarios. For example, the switching scenarios may be divided according to the positional relationship between the source cell and the target cell.
[0121] Scenario 1: A terminal switches from a cell on network device 1 to a cell on network device 2. In this scenario, network device 1 is called the source network device, and network device 2 is called the target network device. In other words, the source and target cells of the terminal belong to different network devices. The cell handover associated with Scenario 1 is called an inter-gNB handover.
[0122] For example, when a CU-DU separation architecture is adopted (for example, a network device includes one CU and multiple DUs, the multiple DUs are centrally controlled by one CU, and each of the multiple DUs may include one or more cells), network device 1 includes CU1 and DU1, and network device 2 includes CU2 and DU2. The above scenario 1 can also be described as: the terminal switches from a cell of DU1 controlled by CU1 to a cell of DU2 controlled by CU2, that is, the source cell and target cell of the terminal belong to different CUs. Therefore, cross-site switching can also be understood as inter-CU switching.
[0123] Scenario 2: A terminal switches from one cell of a network device to another cell of the same network device. In other words, the source and target cells of the terminal belong to the same network device. The cell handover associated with Scenario 2 is known as intra-gNB handover.
[0124] In the embodiment of the present application, the cross-site switching implemented based on layer 3 is called ordinary cross-site switching, and the cross-site switching implemented based on layer 1 / layer 2 is called LTM cross-site switching.
[0125] (4) Secure communication for general cross-site switching
[0126] Figure 3 is a possible flow diagram of a common cross-site handover. The cross-site handover shown in Figure 3 includes a terminal switching from network device 0 to network device 1, and then switching from network device 1 to network device 2. As shown in Figure 3, the process includes:
[0127] S301, the terminal is connected to the core network through network device 0.
[0128] The terminal can access network device 0 through the initial access process or other possible processes, and access the core network through network device 0. Furthermore, the terminal and network device 0 respectively store the keys KgNB (referred to as K0 for ease of description) and NCC0 (K0 is associated with NCC0), and the AMF network element stores NCC0.
[0129] It should be noted that in any embodiment of the present application, the number after NCC is only used to distinguish different NCCs and does not represent a specific NCC value; for example, NCC0 is used to represent the NCC value used on network device 0, and does not limit the NCC value to 0. The symbols K0, K1 or K2 used in the embodiments of the present application are * etc., all refer to the keys for security protection between the terminal and the network equipment, such as KgNB, KgNB1 to KgNB12 involved in Figure 2, while K0, K1 or K2 * Specifically, it refers to which KgNB can be related to the scenario, and the embodiments of this application do not limit this.
[0130] S302: Network device 0 determines that the terminal needs to be switched.
[0131] As the terminal moves, for example, as it gradually moves away from network device 0, network device 0 may sense that the terminal's signal strength gradually weakens. When the terminal's signal strength weakens to a certain extent, network device 0 determines that the terminal needs to be switched to a network device with better signal strength, and thus selects a network device with better signal strength from multiple candidate network devices, such as network device 1.
[0132] S303 : Network device 0 sends a handover request message to network device 1 . Correspondingly, network device 1 receives the handover request message from network device 0 .
[0133] For example, network device 0 can horizontally derive key K1 based on K0, the PCI of the cell on network device 1, and the frequency. A handover request message can include NCC0 and K1, and is used to request handover of the terminal to network device 1. After receiving the handover request message, network device 1 can save NCC0 and K1.
[0134] S304 : Network device 1 sends a handover response message to network device 0 . Correspondingly, network device 0 receives the handover response message from network device 1 .
[0135] For example, the handover response message is a handover request ACK message, which is used to indicate that network device 1 allows the terminal to switch. The handover request ACK message may include configuration information 1, which includes parameters for the terminal to switch to network device 1 and the NCC0 received by the above network device 1.
[0136] S305 , the network device 0 sends a switching command message to the terminal; correspondingly, the terminal receives the switching command message.
[0137] The handover command message may be an RRC reconfiguration message, and the RRC reconfiguration message carries configuration information 1 .
[0138] S306, the terminal deduces the key.
[0139] The terminal can obtain NCC0 from the above configuration information 1. If the NCC0 obtained from the configuration information 1 is the same as the NCC value stored locally in the terminal, the terminal can perform horizontal deduction, that is, derive the key K1 based on K0, the PCI of the cell on network device 1, and the frequency. In this way, the terminal and network device 1 maintain the same key, namely K1.
[0140] S307: The terminal sends a handover completion message to the network device 1. Correspondingly, the network device 1 receives the handover completion message from the terminal.
[0141] The handover complete message may be an RRC reconfiguration complete message.
[0142] S308, network device 1 sends a path switching request message to the AMF network element; accordingly, the AMF network element receives the path switching request message.
[0143] S309, the AMF network element sends a path switching response message to network device 1; accordingly, network device 1 receives the path switching response message and completes the path switching.
[0144] Path switching refers to the switching of the terminal's data transmission path from "UPF network element - network device 0 - terminal" to "UPF network element - network device 1 - terminal." That is, before the path switch, downlink data is sent from the UPF network element to network device 0, which is then sent from network device 0 to the terminal; uplink data is sent from the terminal to network device 0, which is then sent from network device 0 to the UPF network element. After the path switch, downlink data is sent from the UPF network element to network device 1, which is then sent from network device 1 to the terminal; uplink data is sent from the terminal to network device 1, which is then sent from network device 1 to the UPF network element.
[0145] After receiving the Path Switch Request message, the AMF network element can update the locally stored NCC value by adding 1 to obtain an updated NCC (called NCC1), and perform key deduction based on the updated NCC to obtain an updated NH (called NH1). NCC1 and NH1 are associated as an updated pair {NH1, NCC1}.
[0146] The path switch response message includes {NH1, NCC1}. After receiving the path switch response message, the network device 1 may save {NH1, NCC1}.
[0147] S310, the terminal communicates with the network device 1 using the key K1.
[0148] Here, "the terminal and network device 1 communicate using key K1" can mean: the terminal and network device 1 communicate using key K1 itself; or it can mean: the terminal and network device 1 communicate using Krrc and Kup derived from key K1. Krrc is used for encryption, decryption, and integrity protection of control messages, and Kup is used for encryption, decryption, and integrity protection of user data. Other similar descriptions below in this application can be handled similarly.
[0149] S311, network device 1 determines that the terminal needs to be switched.
[0150] The specific implementation of network device 1 determining that the terminal needs to switch can refer to the description of network device 0 determining that the terminal needs to switch. Network device 1 can select a network device with relatively good signal strength from multiple candidate network devices, such as network device 2.
[0151] S312 , network device 1 sends a switching request message to network device 2 . Correspondingly, network device 2 receives the switching request message from network device 1 .
[0152] Network device 1 can deduce the key K2 based on the PCI and frequency of the cell on NH1 and network device 2. * , and sends a handover request message to network device 2. The handover request message is used to request that the terminal be handed over to network device 2. The handover request message may include NCC1 and K2 * After receiving the switching request message, network device 1 can save NCC1 and K2 * .
[0153] S313 , network device 2 sends a switching response message to network device 1 . Correspondingly, network device 1 receives the switching response message from network device 2 .
[0154] For example, the switching response message is a switching request confirmation message, which is used to indicate that network device 2 allows the terminal to switch. The switching request confirmation message may include configuration information 2, configuration information 2, configuration information 2 including parameters for the terminal to switch to network device 2 and the NCC1 received by the above network device 2.
[0155] S314, network device 1 sends a switching command message to the terminal; correspondingly, the terminal receives the switching command message.
[0156] The handover command message may be an RRC reconfiguration message, which carries the configuration information 2 mentioned above.
[0157] S315, the terminal deduces the key.
[0158] The terminal can obtain NCC1 from the above configuration information 2. Since the NCC1 obtained from the configuration information 2 is different from the NCC0 stored locally in the terminal, the terminal performs a corresponding number of vertical deductions based on the difference between NCC1 and NCC0 to obtain the corresponding NH (i.e., NH1). Then, based on NH1, the PCI of the cell on the network device 2, and the frequency, the key K2 is deduced. * In this way, the terminal and network device 2 maintain the same key, namely K2 * .
[0159] S316: The terminal sends a handover completion message to the network device 2. Correspondingly, the network device 2 receives the handover completion message from the terminal.
[0160] S317, network device 2 sends a path switching request message to the AMF network element; accordingly, the AMF network element receives the path switching request message.
[0161] S318, the AMF network element sends a path switching response message to network device 2; accordingly, network device 2 receives the path switching response message and completes the path switching.
[0162] Path switching means that the data transmission path of the terminal is switched from "UPF network element─network device 1─terminal" to "UPF network element─network device 2─terminal".
[0163] After receiving the path switch request message, the AMF network element can update the locally stored NCC value by 1 to obtain an updated NCC (called NCC2). Based on the updated NCC, it performs deduction to obtain an updated NH (called NH2). NCC2 and NH2 are associated as an updated pair {NH2, NCC2}.
[0164] The path switch response message includes {NH2, NCC2}. After receiving the path switch response message, the network device 2 may save {NH2, NCC2}.
[0165] S319, the terminal and network device 2 use key K2 * to communicate.
[0166] It is understandable that the terminal may subsequently switch from network device 2 to other network devices (such as network device 3 or network device 1). For specific implementation, reference may be made to the description of the terminal switching from network device 1 to network device 2.
[0167] According to the above introduction, in a normal cross-site handover, the source access network device can select a target access network device and instruct the terminal to switch to the target access network device through an RRC reconfiguration message. After the terminal switches to the target access network device, the current handover ends. In the next handover, the terminal will receive a new RRC reconfiguration message; that is, each handover triggers the RRC reconfiguration process, and each handover transmits security-related information to the terminal through the RRC reconfiguration message. In contrast, in an LTM cross-site handover, the source access network device instructs the terminal to switch to the target access network device through Layer 1 / Layer 2 signaling (such as a MAC control element (CE)). That is, each handover does not trigger the RRC reconfiguration process, resulting in the inability to transmit security-related information to the terminal through the RRC reconfiguration message, posing a security issue.
[0168] Based on this, the embodiment of the present application will study the relevant implementation of secure communication between the terminal and the network device in the LTM cross-site switching scenario. The communication method provided in the embodiment of the present application involves a terminal side device and at least one network side device (such as a first network side device, a second network side device and a third network side device), wherein the "terminal side device" can be a terminal, or it can also be a component in the terminal, such as a chip or chip system provided in the terminal; the "network side device" can be a network device, or it can also be a component in the network device, such as a chip or chip system provided in the network device. The network device can be an access network node, or the network device includes a CU of an access network node and a DU of an access network node. In the embodiment of the present application, "the terminal side device is a terminal, the network side device is a network device (that is, the first network side device is a first network device, the second network side device is a second network device, and the third network side device is a third network device)" will be described as an example.
[0169] For example, the communication method provided in the embodiment of the present application includes three possible schemes (Scheme 1, Scheme 2 and Scheme 3). These three schemes are briefly introduced here. The introduction here is only to make the embodiment of the present application easier to understand, and should not be regarded as a strict limitation of the technical features in the scope of protection required by this application, that is, not all of the technical features introduced here are necessary technical features.
[0170] Solution 1, Configuration Phase (or Handover Preparation Phase): The core network element provides at least one NH and at least one NCC to different network devices. Each network device maintains its own at least one NH and sends at least one NCC obtained from the core network element to the terminal. Handover Phase: If a terminal accesses the same network device multiple times, both the terminal and the network device can identify unused NHs from the at least one NH of the network device.
[0171] Solution 2, Configuration Phase: The core network element provides W NHs and W NCCs to a third network device, where W is an integer greater than 1. The third network device distributes these W NHs and W NCCs to other network devices (optionally, also to the third network device itself). Different network devices maintain at least one NH and transmit at least one NCC obtained from the third network device to the terminal. Handover Phase: If a terminal accesses the same network device multiple times, both the terminal and the network device can determine an unused NH from the at least one NH of the network device.
[0172] Solution 3: During the configuration phase, the core network element provides W NHs and W NCCs to the third network device, which then sends the W NCCs to the terminal. During the handover phase, during each handover, the target network device requests an unused NH from the third network device and securely communicates with the terminal based on the NH.
[0173] By adopting any of the above-mentioned solutions 1 to 3, there is no need to transmit security-related information to the terminal through RRC reconfiguration messages during multiple switching, thereby reducing signaling overhead while ensuring secure communication between the terminal and the network device.
[0174] The embodiments of the present application are described in detail below in conjunction with Examples 1 to 6.
[0175] Example 1
[0176] In the first embodiment, the first solution will be described.
[0177] FIG4 is a flow chart of the communication method provided in Example 1 of the present application. As shown in FIG4 , the flow may include:
[0178] S401: A core network element sends a second message for a terminal to a first network device, where the second message includes N NHs, where N is an integer greater than 1 or equal to 1; accordingly, the first network device receives the second message.
[0179] Exemplarily, the core network element determines N NHs, and then sends a second message to the first network device. The core network element is an AMF element, and the first network device is the initial source network device or candidate network device of the terminal (see below for details), and the candidate network device is different from the initial source network device. After the terminal accesses the core network element through the initial source network device, the terminal and the core network element store the same root key KAMF (such as KAMF0), and the terminal uses NCC0 (different from the first NCC and the second NCC below) to communicate with the initial source network device, and the initial source network device uses the NH associated with NCC0 to communicate with the terminal.
[0180] (1) Describe "the core network element sends a second message for the terminal to the first network device".
[0181] Exemplarily, the first network device sends a third message to the core network element, and the third message is used to request to provide the NH for the terminal to the first network device; in response to the third message, the core network element determines N NHs, and sends a second message for the terminal to the first network device, that is, the second message is a response message to the third message.
[0182] Optionally, the third message includes the quantity information of the NH, and the quantity information of the NH is used to indicate that the quantity of the requested NH is Q, and Q is an integer greater than or equal to 1. N may be equal to Q, or may be greater than Q, or may be less than Q. The embodiments of the present application do not limit the size relationship between Q and N; that is, the core network element may provide the same quantity of NHs (i.e., N = Q) to the first network device according to the quantity information carried in the third message, or may also provide different quantities of NHs (i.e., N is not equal to Q) to the first network device. In addition, if the third message does not include the quantity information of the NH, then the core network element determines the quantity of the NH by itself.
[0183] It can be understood that here the first network device is taken as an example for description, and other network devices may also request the NH for the terminal from the core network element respectively. Furthermore, the core network element provides at least one NH to different network devices respectively, and the NHs provided by the core network element to different network devices are different, and the quantities of the NHs provided by the core network element to different network devices may be the same or different.
[0184] (2) Describe "the core network element determines N NHs".
[0185] For example, in response to the third message, the core network element determines whether to replace the root key (i.e., KAMF). When it is determined not to replace KAMF, the core network element derives K NHs (the specific derivation may be before or after the third message, without limitation) based on the initial KgNB, and these K NHs are all unused NHs. When it is determined to replace KAMF, the core network element derives a new KAMF (such as KAMF1) based on the current KAMF (such as KAMF0), and then derives K NHs based on KAMF1. Among them, the K NHs can be expressed as NH(i), 0 <= i <= K - 1, NH(i) is associated with NCC(i) one by one, and K is an integer greater than or equal to N.
[0186] Furthermore, method 1: the core network element selects N consecutive NHs from K NHs, that is, the NCCs associated with the N NHs are continuous, and NH(i) is derived by taking NH(i-1) as input. Method 2: the core network element selects N non-continuous NHs from K NHs, that is, the NCCs associated with the N NHs are non-continuous. Furthermore, the core network element sends the selected N NHs to the first network device through a second message. From the perspective of the core network element, the status of the N NHs changes from unused NHs to used NHs. Optionally, after allocating N NHs to the first network device, the core network element updates the current NH in the core network element to the last NH of the N NHs, so as to allocate different N NHs to different network devices.
[0187] (3) Introduce the content of the second message.
[0188] As described above, the second message includes N NHs.
[0189] As a possible implementation, the second message also includes N NH-associated NCCs (i.e., N NCCs), which can be consecutive or non-consecutive. For example, if N=3, the N NH-associated NCCs are consecutive, and the second message includes {NH1, NCC1}, {NH2, NCC2}, and {NH3, NCC3}. For another example, if N=3, the N NH-associated NCCs are non-consecutive, and the second message includes {NH1, NCC1}, {NH3, NCC3}, and {NH5, NCC5}.
[0190] As another implementation, the second message also includes the second NCC and the value of N. The NCCs associated with the N NHs are consecutive (for example, sorted from smallest to largest), and the second NCC is the NCC associated with the initial NH among the N NHs (or the second NCC is the smallest NCC among the N NH-associated NCCs). For example, if N=3, the second message includes three NHs (i.e., NH1, NH2, and NH3), the second NCC, and the value of N. The second NCC is associated with NH1, the NCC associated with NH2 is the second NCC plus 1, and the NCC associated with NH3 is the second NCC plus 2.
[0191] In addition, if the core network element replaces the root key with KAMF1, the second message may further include root key information. The root key information may be information used to identify KAMF1, such as identification information of KAMF1.
[0192] S402: The third network device sends a first message to the terminal; accordingly, the terminal receives the first message.
[0193] Exemplarily, the third network device is the original source network device of the terminal, and the original source network device determines to initiate LTM configuration based on the measurement result reported by the terminal. The first message may be an RRC message, such as an RRC reconfiguration message.
[0194] (1) In combination with Example 1 and Example 2, “the third network device sends a first message to the terminal” is introduced.
[0195] Example 1: The first network device is the initial source network device of the terminal, that is, the first network device and the third network device are the same network device.
[0196] In this case, for example, when determining to initiate LTM configuration, the first network device determines cell 1 as a candidate cell for the terminal, where cell 1 is the cell of the first network device, and the first network device sends a third message for the terminal to the core network element. In addition, if it is determined that the cell of the first network device is not a candidate cell for the terminal, the first network device does not need to send the third message for the terminal to the core network element.
[0197] Furthermore, after receiving the second message from the core network element, the first network device sends a first message (i.e., an RRC reconfiguration message) to the terminal. The first message includes the LTM configuration of cell 1 (for example, including at least one of early synchronization configuration, CSI report configuration, and TCI state configuration) and NCC information 1 associated with cell 1.
[0198] Optionally, the RRC reconfiguration message may further include LTM configurations of other candidate cells, other NCC information, and identification information associated with other network devices.
[0199] Example 2: The first network device is a candidate network device of the terminal, and the candidate network device is different from the original source network device (ie, the third network device), that is, the first network device and the third network device are different network devices.
[0200] In this case, for example, when it is determined that LTM configuration is initiated, the third network device sends a fourth message to the first network device (for example, the fourth message is a handover request message, referred to herein as handover request message 1 for ease of description). Handover request message 1 is used to request cell 1 as a candidate cell for the terminal (i.e., requesting LTM configuration for cell 1 of the first network device). In response to handover request message 1, the first network device accepts cell 1 as a candidate cell for the terminal, cell 1 is the cell of the first network device, and sends the third message to the core network element. In addition, if it is determined that the cell of the first network device is not a candidate cell for the terminal, the first network device does not need to send the third message to the core network element.
[0201] Furthermore, after receiving the second message for the terminal from the core network network element, the first network device sends a handover response message 1 to the third network device. The handover response message 1 includes the LTM configuration of cell 1 and NCC information 1 associated with cell 1. Furthermore, after receiving the handover response message 1, the third network device sends a first message (e.g., an RRC reconfiguration message) to the terminal. The first message includes the LTM configuration of cell 1 and NCC information 1 associated with cell 1.
[0202] In Example 2, if cell 2 is also a cell of the first network device, the third network device may further send a handover request message 2 for the terminal to the first network device, where the handover request message 2 is used to request the LTM configuration of cell 2 (for example, including at least one of early synchronization configuration, CSI report configuration, and TCI state configuration); in response to the handover request message 2, the first network device determines that the NCC associated with cell 1 and cell 2 is the same, and sends a handover response message 2 to the third network device, where the handover response message 2 includes the LTM configuration of cell 2 and also includes information indicating that the NCC associated with cell 1 and cell 2 are the same (for example, the same group identification information). In this case, after receiving the handover response message 1 and the handover response message 2, the third network device may send a first message to the terminal, where the first message includes the LTM configuration of cell 1, NCC information 1 associated with cell 1, the LTM configuration of cell 2, and information indicating that the NCC associated with cell 1 and cell 2 are the same (for example, the group identification information corresponding to cell 2 and cell 1 is the same).
[0203] In the above two examples, the association between cell 1 and NCC information 1 can be indicated to the terminal in any of the following ways: Way 1, including NCC information 1 in the configuration of cell 1 to indicate that cell 1 is associated with NCC information 1; Way 2, including cell 1 information in the configuration of NCC information 1 to indicate that cell 1 is associated with NCC information 1. The information of cell 1 can be the identification information of the first network device, the identification information of cell 1, or the group identification information corresponding to cell 1.
[0204] (2) Introduce the security-related content of the first message (such as NCC information 1).
[0205] The NCC information 1 is used to indicate N NH-associated NCCs (eg, N NCCs) or a second NCC.
[0206] Specifically, if the second message includes N NH-associated NCCs (e.g., N NCCs associated one-to-one with the N NHs), then NCC information 1 includes N NH-associated NCCs (e.g., N NCCs associated one-to-one with the N NHs). If the second message includes a second NCC, then NCC information 1 includes the second NCC and, optionally, the value of N. In the case of including the value of N, the second NCC and the values of N can jointly indicate the N NH-associated NCCs.
[0207] It can be understood that the first message may further include NCC information associated with other cells. The content included in the NCC information associated with other cells may refer to the description of NCC information 1.
[0208] Optionally, the first message also includes identification information associated with cell 1, and the identification information associated with cell 1 is used to determine whether the terminal performs vertical key deduction for NH when switching to the first network device (for example, cell 1). The identification information associated with cell 1 can be the above-mentioned NCC information 1, or the identification information of the first network device, or the group identification information corresponding to cell 1, or other possible information, without limitation. For example, when the identification information associated with the source cell and the identification information associated with the target cell are different, the terminal performs vertical key deduction for NH. In the cross-site switching scenario, "identification information associated with cell 1" can be replaced with "identification information associated with the first network device", and "identification information associated with the source cell" can be replaced with "identification information associated with the source network device", and "identification information associated with the target cell" can be replaced with "identity associated with the target network device".
[0209] In addition, when the second message includes root key information, the first message also includes root key information, and the root key information is associated with cell 1, or in other words, the root key information is associated with NCC1 information 1. The root key information is used to instruct the terminal to determine the root key KAMF when switching to cell 1, and then perform vertical key deduction for NH based on the root key determined by the root key information.
[0210] S403: The terminal accesses the first network device; accordingly, the first network device determines that the terminal accesses the first network device.
[0211] For example, the terminal accesses the cell of the first network device, that is, cell 1.
[0212] There are multiple scenarios in which a terminal accesses the first network device. One possible scenario (Scenario 1) is: the terminal initiates a mobility LTM handover to access the first network device; specifically, the terminal receives a handover command message, which is used to instruct handover to the first network device (e.g., cell 1), and in response to the handover command message, the terminal accesses the first network device. Another possible scenario (Scenario 2) is: after the LTM handover fails, the terminal accesses the first network device through the LTM configuration; specifically, the terminal determines that the handover fails (e.g., the handover to another network device fails), and in response to the handover failure, the terminal chooses to access the first network device, and accesses the first network device based on the LTM configuration of the first network device.
[0213] Exemplarily, the manner in which a terminal accesses a first network device may include: Mode 1, in which the terminal accesses the first network device via random access, for example, the terminal accesses the first network device via a physical random access channel (RACH) resource; after completing random access, the first network device determines that the terminal accesses the first network device (i.e., the terminal accesses the first network device via LTM configuration). For example, random access message 3 includes identification information of the terminal, which is carried in the LTM configuration. Therefore, the first network device can determine that the terminal accesses the first network device via LTM configuration. Mode 2, in which the terminal accesses the first network device via a random access-free manner, for example, the terminal accesses the first network device via a physical uplink shared channel (PUSCH) resource. The PUSCH resource may be a configured grant (CG) resource or a dynamic grant (DG) resource; accordingly, the first network device determines that the terminal accesses the first network device (i.e., the terminal accesses the first network device via LTM configuration) based on transmission on the PUSCH resource. For example, the PUSCH resource is indicated to the terminal in the LTM configuration. Therefore, the first network device can determine, through the PUSCH resource, that the terminal accesses the first network device through the LTM configuration.
[0214] In addition, the first network device can determine the scenario based on which the terminal accesses the first network device based on whether the cell switching notification message is received. For example, if the first network device receives a cell switching notification message from the source network device (the cell switching notification message corresponds to LTM switching), it is determined that the terminal accesses the first network device based on scenario 1; if the first network device does not receive the cell switching notification message from the source network device, it is determined that the terminal accesses the first network device based on scenario 2.
[0215] S404: The first network device and the terminal perform secure communication.
[0216] The following describes "secure communication between the first network device and the terminal" from the perspective of the first network device and the perspective of the terminal respectively.
[0217] (1) Introduction from the perspective of the first network device.
[0218] From the perspective of the first network device, secure communication between the first network device and the terminal may include: for a cross-site handover, based on the N NHs, determining a currently unused NH, and securely processing the terminal's data using the determined NH (including at least one of integrity protection, integrity protection confirmation, encryption, or decryption). Specifically, the first network device determines the NH used for the current cross-site handover, i.e., the first NH, from the N NHs. The first NH is an NH that has not been used in previous cross-site handovers, i.e., a previously used NH is no longer used, thereby ensuring that different NHs are used for multiple cross-site handovers to the first network device.
[0219] For example, N NHs may be sorted in a first order, where the first NH is the first unused NH among the N NHs. For example, the N NHs are NH1, NH2, and NH3, NH1 is a used NH (for example, when the terminal last accessed the first network device, the NH used by the first network device was NH1), and the remaining NHs are unused NHs, in which case the first NH is NH2. The first order is the ascending order of the NCC or the order of the N NHs indicated by the core network element.
[0220] Exemplarily, the first network device may determine the first order based on the second message. Two possible approaches are described below in combination with approach 1 and approach 2.
[0221] Method 1: The N NHs included in the second message are sorted according to the first order. That is, the core network element indicates the first order through the second message, and the first network device directly obtains the N NHs sorted according to the first order from the second message. In this case, sorting the N NHs according to the first order may mean sorting the N NHs from smallest to largest based on the NCCs associated with the N NHs; or it may refer to other possible sorting methods, which are not specifically limited.
[0222] Method 2: The second message includes N NHs and NCCs associated with the N NHs. The first network device sorts the N NHs in ascending order based on the NCCs associated with the N NHs. In this case, sorting the N NHs in the first order may mean sorting the N NHs in ascending order based on the NCCs associated with the N NHs.
[0223] It is understandable that, based on the order of the N NHs, the first message includes ordering information of the N NCCs, and the N NHs are associated one-to-one with the N NCCs. Specifically, when the NCC information 1 includes N NH-associated NCCs, the N NH-associated NCCs are also sorted in the first order, so that the NH used by the terminal and the NH used by the first network device during a certain handover are the same.
[0224] (2) Introduce from the perspective of the terminal.
[0225] From the perspective of the terminal, the secure communication between the first network device and the terminal may include: after receiving NCC information 1, for cross-site switching, the terminal determines the NCC used for the current cross-site switching (i.e., switching to cell 1) based on the NCC information 1 associated with cell 1, i.e., the first NCC, and uses the first NCC to communicate with the first network device. It should be noted that the NCC used for the previous cross-site switching is no longer used for this cross-site switching. Using the first NCC to communicate with the first network device, specifically: the terminal determines the first NH based on the first NCC (i.e., for the same switching, the NH determined by the terminal is the same as the NH determined by the first network device) and uses the first NH to securely process the terminal's data (including at least one of integrity protection, integrity protection confirmation, encryption or decryption), and the first NCC is associated with the first NH.
[0226] In one example, if the NCC information 1 includes N NH-associated NCCs (i.e., N NCCs), the first NCC is one of the N NCCs, and the NH associated with the first NCC is an unused NH. For example, the N NCCs are sorted in a first order, and the first NCC is the first unused NCC among the N NCCs. For example, the N NCCs are NCC1 (associated with NH1), NCC2 (associated with NH2), and NCC3 (associated with NH3), NCC1 is a used NCC (for example, the last time the terminal accessed the first network device, the NCC used by the terminal was NCC1), and the remaining NCCs are unused NCCs, then the first NCC is NCC2.
[0227] For this example, when N NCCs are consecutive, it can also be understood that: the first NCC is obtained by adding 1 to the second NCC, and the second NCC is the NCC used for the last access to the first network device.
[0228] In another example, if the above-mentioned NCC information 1 includes a second NCC, when the terminal accesses the first network device for the first time, the second NCC can be used to communicate with the first network device; thereafter, when the terminal accesses the first network device again, 1 can be added to the second NCC to obtain the first NCC, and then the first NCC can be used to communicate with the first network device; and so on.
[0229] Optionally, from the perspective of the terminal, the secure communication between the first network device and the terminal may include: the terminal determines whether it is necessary to update the key based on the identification information associated with the source cell and the identification information associated with the target cell (i.e., cell 1), or determines whether it is necessary to perform vertical deduction for NH. For example, if the identification information associated with the source cell and the identification information associated with the target cell (i.e., cell 1) are different (cross-site switching), the terminal determines that it is necessary to perform vertical deduction for NH; if the identification information associated with the source cell and the identification information associated with the target cell (i.e., cell 1) are the same (intra-site switching), the terminal determines that it is not necessary to perform vertical deduction for NH, that is, NH does not change. A specific example is: if the NCC associated with the source cell is different from the NCC associated with the target cell, the terminal determines that it is necessary to perform vertical deduction for NH; if the NCC associated with the source cell is the same as the NCC associated with the target cell, the terminal determines that it is not necessary to perform vertical deduction for NH. Therefore, cross-site switching can also be understood as switching that requires changing NH, and intra-site switching can also be understood as switching that does not require changing NH.
[0230] For example, when the network device to which the source cell belongs is a second network device, and the second network device is different from the first network device, the terminal determines that vertical deduction for NH is required; when the network device to which the source cell belongs is the first network device, the terminal determines that vertical deduction for NH is not required. In the embodiment of the present application, the scenario of "key deduction method is vertical deduction" is described as an example. Therefore, updating the key may include the above-mentioned determination of the first NCC and the first NH associated with the first NCC. In addition, the embodiment of the present application does not limit the specific timing of the terminal updating the key.
[0231] When the first message includes root key information, the terminal determines the updated root key KAMF based on the root key information, and then deduces the NH of this switch (such as the first NH) based on the updated root key KAMF and the corresponding NCC (such as the first NCC).
[0232] Based on the above method, after the first network device and the terminal determine the first NH, the first network device and the terminal respectively perform the following operations: take the first NH and the target cell information of this switching (such as the PCI and downlink frequency of the cell) as input parameters, deduce the KgNB of the target cell, and then deduce Kup and Krrc based on KgNB, and use Kup and Krrc for secure communication between the first network device and the terminal.
[0233] It is understood that, during the process of the terminal accessing the first network device in S403 above, the terminal and the first network device may also communicate securely in the manner described in S404. That is, S404 can apply to communications after the terminal accesses the first network device, as well as communications during the process of the terminal accessing the first network device. Other embodiments may be understood with reference to this.
[0234] Optionally, the above method also includes S405.
[0235] S405 , the first network device sends a fifth message to the core network element. The fifth message is used to request path switching and is also used to indicate not to update NH. Accordingly, the core network element receives the fifth message.
[0236] For example, the fifth message is a path switching request message, and the fifth message includes address information of the downlink data. In response to S403, the first network device sends the fifth message to the core network element. After receiving the fifth message, the core network element may not update the NH, and then send a path switching response message to the first network device. The path switching response message does not include the NH and NCC. It should be noted that in the existing path switching response message, the NH and NCC must be carried. In this application, the NH and NCC have been provided to the first network device in the previous step, and there is no need to provide the NH and NCC in this message.
[0237] After receiving the fifth message, the core network network element (for example, the AMF network element) notifies other core network network elements (for example, the UPF network element) to use the address information of the above-mentioned downlink data to send downlink data to the first network device.
[0238] It is understood that, taking the first network device as an example, the first network device is associated with N NHs. Each time the terminal switches to the first network device, it uses an NH from the N NHs that has not been used in the previous switch. If the first network device determines that the N NHs are about to be used up or have been used up, the first network device can again request a new NH from the core network element and send the NCC information associated with the new NH to the terminal to facilitate subsequent switching. Other network devices can refer to the first network device for processing.
[0239] With this method, different NHs can be used for multiple switches to the same network device, eliminating the need to pass security-related information to the terminal through RRC reconfiguration messages. This facilitates secure communication between the terminal and the network device in the LTM cross-site handover scenario and ensures secure communication for continuous cross-site handovers.
[0240] Example 2
[0241] In the second embodiment ( FIG5A ), a possible implementation process will be described based on the above-mentioned first embodiment. That is, the second embodiment can be combined with the first embodiment, and the specific implementation of the relevant steps in the second embodiment can refer to the first embodiment.
[0242] FIG5A is a schematic diagram of a process flow associated with the communication method provided in Example 2 of the present application. The LTM cross-site handover illustrated in FIG5A includes a terminal switching from network device 0 to network device 1 (a first handover), and then switching from network device 1 to network device 2 (a second handover). Network device 0 is the initial source network device (e.g., the third network device in Example 1). As shown in FIG5A , the process may include:
[0243] S501: The terminal is connected to the core network through network device 0.
[0244] The terminal can access network device 0 through the initial access process or other possible processes, and access the core network through network device 0. Furthermore, the terminal and the core network element store the same root key KAMF (such as KAMF0), the terminal uses NCC0 (different from NCC1 to NCC7 below) to communicate with network device 0, and network device 0 uses NH associated with NCC0 to communicate with the terminal.
[0245] S502: Network device 0 determines multiple candidate cells (or multiple candidate network devices) for LTM handover.
[0246] For example, if network device 0 determines to initiate LTM configuration based on the measurement results reported by the terminal, it can determine multiple candidate cells for LTM handover. For example, the multiple candidate cells determined include cell a, cell b1, cell b2, and cell c. Cell a is the cell of network device 0, cells b1 and cell b2 are the cells of network device 1, and cell c is the cell of network device 2. In other words, the multiple candidate network devices include network device 0, network device 1, and network device 2.
[0247] S503 , network device 0 sends message 1 to the core network element. Message 1 is used to request the core network element to provide NH to network device 0 .
[0248] Here, message 1 is used to request the core network element to provide NH to network device 0, which can also be replaced by "message 1 is used to request the core network element to provide NH and NCC to network device 0".
[0249] Optionally, Message 1 includes information about the number of NHs. Since NCCs are associated one-to-one with NHs, "information about the number of NHs" can be replaced with "information about the number of NCCs." For example, Network Device 0 can estimate the number of times a terminal performs an inter-site handover and switches to Network Device 1, and then determine the number of NHs or NCCs based on this number.
[0250] S504 , the core network element sends a message 2 to the network device 0 , where the message 2 includes M NHs.
[0251] For example, as shown in FIG5B , the core network element derives K NHs, which include NH1 to NH7 (i.e., K=7). The core network element allocates M NHs out of the K NHs to network device 0. The M NHs may be consecutive or non-consecutive. For specific implementation, reference may be made to the description of S401 in Example 1. For example, the M NHs include NH1 and NH2.
[0252] Optionally, message 2 also includes NCC information associated with M NHs (referred to as NCC information a). NCC information a includes the NCCs associated with the M NHs, such as NCC1 and NCC2; or the M NHs included in message 2 are sorted from small to large based on the NCCs associated with the M NHs, and the NCCs associated with the M NHs are continuous, then NCC information a includes the NCC associated with the initial NH among the M NHs (i.e., the minimum NCC among the NCCs associated with the M NHs), such as NCC1, and optionally, also includes the value of M. For NCC information a (as well as the following NCC information b and NCC information c), refer to the relevant description of "NCC information 1" in Example 1.
[0253] S505 , network device 0 sends a switching request message to network device 1 ; correspondingly, network device 1 receives the switching request message from network device 0 .
[0254] Here, the handover request message is used to request the LTM configuration of the cell b1. For example, the handover request message includes LTM indication information and the cell global identifier (CGI) of the cell b1.
[0255] S506 , the network device 1 sends a message 3 to the core network element. The message 3 is used to request the core network element to provide NH to the network device 1 .
[0256] Optionally, the message 3 includes the quantity information of NHs.
[0257] S507 , the core network element sends a message 4 to the network device 1 , where the message 4 includes P NHs.
[0258] For example, as shown in Figure 5B , the core network element allocates P NHs out of (KN) NHs to network device 1. The P NHs can be consecutive or non-consecutive. For specific implementation, refer to the description of S401 in Example 1. For example, the P NHs include NH3 and NH4. It is understood that if KN = 0 or the number of KNs is small, the core network element can continue to deduce more NHs and further allocate P NHs to network device 1.
[0259] Optionally, message 4 also includes NCC information associated with P NHs (referred to as NCC information b). NCC information b includes the NCCs associated with the P NHs, such as NCC3 and NCC4. Alternatively, if the P NHs included in message 4 are sorted from small to large based on the NCCs associated with the P NHs, and the NCCs associated with the P NHs are continuous, then NCC information b includes the NCC associated with the initial NH among the P NHs (i.e., the minimum NCC among the NCCs associated with the P NHs), such as NCC3, and optionally, the value of P.
[0260] S508 , network device 1 sends a switching response message to network device 0 ; correspondingly, network device 0 receives the switching response message from network device 1 .
[0261] Exemplarily, the handover response message includes the LTM configuration of cell b1 and NCC information b. The LTM configuration of cell b1 includes a transmission configuration indication (TCI) state configuration, a cell group configuration (such as group identification information corresponding to cell b1), and may also include other possible configurations.
[0262] It is understandable that network device 0 may also send a handover request message to network device 1 for cell b2. The handover request message is used to request the LTM configuration of cell b2. In response to the handover request message, network device 1 sends a handover response message to network device 0. The handover response message includes the LTM configuration of cell b2 and also includes information indicating that the NCC associated with cell b2 is the same as that associated with cell b1. Both cell b2 and cell b1 are associated with NCC information b, and both cell b2 and cell b1 are associated with P NHs.
[0263] S509 , network device 0 sends a switching request message to network device 2 . Correspondingly, network device 2 receives the switching request message from network device 0 .
[0264] Here, the handover request message is used to request the LTM configuration of cell c.
[0265] S510 , network device 2 sends message 5 to the core network element. Message 5 is used to request the core network element to provide NH to network device 2 .
[0266] Optionally, the message 5 includes the quantity information of NHs.
[0267] S511 , the core network element sends message 6 to network device 2 , where message 6 includes N NHs; accordingly, network device 2 receives message 6 .
[0268] For example, as shown in Figure 5B , the core network element allocates N (N=KMP) NHs to network device 2. The N NHs can be consecutive or non-consecutive. For specific implementation, refer to the description of S401 in Example 1. For example, the N NHs include NH5, NH6, and NH7. It is understood that if KMP=0 or the number of KMPs is small, the core network element can continue to deduce more NHs, thereby allocating N NHs to network device 2.
[0269] Optionally, message 6 also includes NCC information associated with N NHs (referred to as NCC information c). NCC information c includes NCCs associated with the N NHs, such as NCC5, NCC6, and NCC7; or the N NHs included in message 6 are sorted from small to large based on the NCCs associated with the N NHs, and the NCCs associated with the N NHs are continuous, then NCC information c includes the NCC associated with the initial NH among the N NHs (i.e., the minimum NCC among the N NH-associated NCCs), such as NCC5, and optionally, also includes the value of N.
[0270] S512 , network device 2 sends a switching response message to network device 0 ; correspondingly, network device 0 receives the switching response message from network device 2 .
[0271] Exemplarily, the handover response message includes the LTM configuration of cell c and NCC information c.
[0272] S513, network device 0 sends an RRC reconfiguration message to the terminal; correspondingly, the terminal receives the RRC reconfiguration message.
[0273] Exemplarily, the RRC reconfiguration message includes the LTM configuration of cell a, the NCC information a associated with cell a, the LTM configuration of cell b1, the LTM configuration of cell b2, the NCC information b associated with cells b1 and b2, and the LTM configuration of cell c and the NCC information c associated with cell c.
[0274] Optionally, the first message also includes identification information associated with cell 1 (ie, identification information associated with network device 0), identification information associated with cells b1 / b2 (ie, identification information associated with network device 1), and identification information associated with cell c (ie, identification information associated with network device 2).
[0275] S514 , network device 0 determines that the terminal needs to be switched, and the target network device for switching is network device 1 .
[0276] There are many specific implementations for network device 0 to determine the target network device, which are not limited in this embodiment of the present application. For example, network device 0 may determine that the target network device is network device 1 based on the measurement report reported by the terminal.
[0277] S515: Network device 0 sends a handover command message to the terminal. Correspondingly, the terminal receives the handover command message from network device 0.
[0278] For example, the handover command message is a MAC CE, and the handover command message includes identification information of the target cell (such as cell b1).
[0279] S516 , in response to the switching command message, the terminal switches to network device 1 .
[0280] S517, network device 1 sends a path switching request message to the AMF network element, and the path switching request message is used to indicate that NH is not updated; accordingly, the AMF network element receives the path switching request message.
[0281] S518, the AMF network element sends a path switching response message to network device 1; accordingly, network device 1 receives the path switching response message and completes the path switching.
[0282] Here, path switching means that the data transmission path of the terminal is switched from "UPF network element─network device 0─terminal" to "UPF network element─network device 1─terminal". The path switching response message does not include NH and NCC.
[0283] S519, the terminal communicates securely with the network device 1.
[0284] From the perspective of network device 1, network device 1 uses the first unused NH (ie, NH3) among the P NHs to perform security processing (including at least one of integrity protection, integrity protection confirmation, encryption, or decryption) on the terminal data.
[0285] From the perspective of the terminal, since cell b1 is associated with NCC information b, the terminal uses the first unused NCC (i.e., NCC3) to communicate with network device 1 based on NCC information b (for example, NCC information b includes NCC3 and NCC4); specifically, the terminal determines NH3 associated with NCC3 based on NCC3, and then uses NH3 to securely process the terminal data.
[0286] In this way, it can be ensured that the keys used by the network device 1 and the terminal are the same, thereby enabling secure communication between the network device 1 and the terminal. The specific implementation of S519 can refer to S404 in the first embodiment.
[0287] It can be understood that if the terminal switches to network device 1 next time, network device 1 uses the first unused NH (i.e., NH4) among P NHs to communicate with the terminal; the terminal uses the first unused NCC (i.e., NCC4) to communicate with network device 1, or the terminal adds 1 to NCC4 (i.e., the NCC used by the last access network device 1) to obtain NCC4, and then uses NCC4 to communicate with network device 1.
[0288] S520 , network device 1 determines that the terminal needs to be switched, and the target network device for switching is network device 2 .
[0289] S521: Network device 1 sends a handover command message to the terminal. Correspondingly, the terminal receives the handover command message from network device 1.
[0290] For example, the handover command message is a MAC CE, and the handover command message includes identification information of the target cell (eg, cell c).
[0291] S522 , in response to the switching command message, the terminal switches to network device 2 .
[0292] S523, network device 2 sends a path switching request message to the AMF network element, and the path switching request message is used to indicate that NH is not updated; accordingly, the AMF network element receives the path switching request message.
[0293] S524, the AMF network element sends a path switching response message to network device 2; accordingly, network device 2 receives the path switching response message and completes the path switching.
[0294] Here, path switching means that the data transmission path of the terminal is switched from "UPF network element─network device 1─terminal" to "UPF network element─network device 2─terminal". The path switching response message does not include NH and NCC.
[0295] S525, the terminal communicates securely with the network device 2.
[0296] From the perspective of the network device 2, the network device 2 uses the first unused NH (ie, NH5) among the N NHs to perform security processing on the data of the terminal.
[0297] From the perspective of the terminal, since cell c is associated with NCC information c, the terminal uses the first unused NCC (i.e., NCC5) to communicate with network device 2 based on NCC information c (for example, NCC information c includes NCC5, NCC6, and NCC7); specifically, the terminal determines NH5 associated with NCC5 based on NCC5, and then uses NH5 to securely process the terminal data.
[0298] In this way, it can be ensured that the keys used by the network device 2 and the terminal are the same, thereby enabling secure communication between the network device 2 and the terminal. The specific implementation of S525 can refer to S404 in the first embodiment.
[0299] It can be understood that if the terminal switches to network device 2 next time, since NH5 has been used, network device 2 uses the first unused NH (i.e., NH6) among N NHs to communicate with the terminal; since NCC6 has been used, the terminal uses the first unused NCC (i.e., NCC6) to communicate with network device 2, or the terminal adds 1 to NCC5 (i.e., the NCC used by the last access network device 2) to obtain NCC6, and then uses NCC6 to communicate with network device 2.
[0300] It can be understood that the subsequent terminal can also switch from network device 2 to network device 0 or network device 1. The specific implementation can refer to the description of the terminal switching from network device 1 to network device 2; or, if the candidate network devices for LTM switching also include network device 3, the subsequent terminal can also switch from network device 2 to network device 3. The specific implementation can refer to the description of the terminal switching from network device 1 to network device 2.
[0301] Example 3
[0302] In the third embodiment, the second solution will be described.
[0303] FIG6 is a flow chart of the communication method provided in Example 3 of the present application. As shown in FIG6 , the flow may include:
[0304] S601: A core network element sends a sixth message to a third network device, where the sixth message includes W NHs, where W is an integer greater than 1. Accordingly, the third network device receives the sixth message.
[0305] The core network element is the AMF element, and the third network device is the initial source network device of the terminal. After the terminal accesses the core network element through the initial source network device, the terminal and the core network element store the same root key KAMF (such as KAMF0).
[0306] If the third network device determines to initiate LTM configuration based on the measurement results reported by the terminal, it may determine multiple candidate cells and then send a third message to the core network element. The third message is used to request that the third network device be provided with NH. Unlike the first embodiment, the third network device sends the third message to the core network element regardless of whether the multiple candidate cells include the third network device. In response to the third message, the core network element sends a sixth message to the third network device, i.e., the sixth message is a response message to the third message. The third message can be described in the first embodiment.
[0307] In response to the third message, the core network element determines W NHs and sends a sixth message to the third network device. The NCCs associated with the W NHs can be consecutive. For example, in response to the third message, the core network element determines whether to replace the root key (i.e., KAMF). In the case of determining not to replace KAMF, the core network element derives W NHs based on the initial KgNB, and these W NHs are all unused NHs. In the case of determining to replace KAMF, the core network element derives a new KAMF (such as KAMF1) based on the current KAMF (such as KAMF0), and then derives W NHs based on KAMF1. The W NHs can be expressed as NH(i), where 0 <= i <= W - 1, and NH(i) is associated with NCC(i) one by one. Furthermore, the core network element sends the W NHs to the third network device through the sixth message. From the perspective of the core network element, the status of the W NHs changes from unused NHs to used NHs.
[0308] Exemplarily, the sixth message further includes NCC information 2. For example, NCC information 2 includes the NCCs associated with the W NHs (i.e., N NCCs); or, NCC information 2 includes a second NCC, and the W NHs included in the sixth message are sorted in ascending order based on the NCCs associated with the W NHs, and the second NCC is the NCC associated with the initial NH among the W NHs. In addition, if the core network element replaces the root key with KAMF1, the sixth message may further include root key information, and the root key information can be information used to identify KAMF1. Specifically, reference can be made to the description of the "second message" in Embodiment 1.
[0309] S602, the third network device sends a second message to the first network device, and the second message includes N NHs; correspondingly, the first network device receives the second message.
[0310] Here, the first network device is a candidate network device of the terminal, and this candidate network device is different from the initial source network device (i.e., the third network device), that is, the first network device and the third network device are different network devices.
[0311] For example, the third network device determines a cell as a candidate cell for the terminal, and cell 1 is the cell of the first network device. After the third network device obtains W NHs, it can allocate N NHs out of the W NHs to the first network device and send a second message to the first network device. The second message is a handover request message, and the second message is also used to request the LTM configuration of cell 1 of the first network device. Optionally, the second message also includes NCC information 1 associated with cell 1, and specifically refer to the description of embodiment 1. After receiving the second message, the first network device can obtain N NHs and send a handover response message to the third network device. The handover response message includes the LTM configuration of the first cell, and optionally, also includes NCC information 1 associated with cell 1.
[0312] Optionally, the third network device can also allocate NHs to the network devices to which other candidate cells belong. For example, if the network devices to which other candidate cells belong include the second network device and the third network device, the third network device can also allocate P NHs to the second network device from the remaining (WN) NHs, and allocate M NHs to the third network device itself, and send the allocated P NHs to the second network device.
[0313] S603: The third network device sends a first message to the terminal; correspondingly, the terminal receives the first message from the third network device.
[0314] The first message may be an RRC message, such as an RRC reconfiguration message. For example, the first message includes the LTM configuration of cell 1 and NCC information 1 associated with cell 1.
[0315] Exemplarily, NCC information 1 includes NCCs associated with N NHs; or, NCC information 1 includes a second NCC, N NHs are sorted from small to large based on the NCCs associated with the N NHs, the NCCs associated with the N NHs are continuous, and the second NCC is the NCC associated with the initial NH among the N NHs.
[0316] It is understandable that the first message may also include other possible information. Please refer to the description of the first message in Example 1 for details.
[0317] S604: The terminal accesses the first network device; accordingly, the first network device may determine that the terminal accesses the first network device.
[0318] S605: The first network device and the terminal perform secure communication.
[0319] Optionally, the above method also includes S606.
[0320] S606 , the first network device sends a fifth message to the core network element. The fifth message is used to request path switching and is also used to indicate not to update NH. Accordingly, the core network element receives the fifth message.
[0321] The above S604 to S606 can refer to the description of S403 to S405 in embodiment 1. The above S601 to S603 focus on the differences between embodiment 3 and embodiment 1. Except for the differences, the other contents of the two embodiments can refer to each other.
[0322] It can be understood that, taking the first network device as an example, the first network device is associated with N NHs, and each time the terminal switches to the first network device, it uses the NHs among the N NHs that have not been used by the previous switch. If the first network device determines that the N NHs are about to run out or have been used up, the first network device can request a new NH from the core network element again, and send the NCC information associated with the new NH to the terminal to facilitate subsequent switching. Alternatively, if the first network device determines that the N NHs are about to run out or have been used up, the first network device can request a new NH from the third network device, and then the third network device can request a new NH from the core network element and send the new NH to the first network device. Other network devices can refer to the processing of the first network device.
[0323] Using this method, the initial source network device of the terminal requests NH from the core network network element, and distributes the requested multiple NHs to each candidate network device, and the initial source network device sends the NCC information associated with each candidate cell to the terminal through an RRC message. Therefore, different NHs can be used for multiple switches to the same network device, and there is no need to transmit security-related information to the terminal through an RRC reconfiguration message. This facilitates secure communication between the terminal and the network device in the LTM cross-site handover scenario, improves the security of continuous cross-site handovers, and ensures secure communication of continuous cross-site handovers.
[0324] Example 4
[0325] In the fourth embodiment ( FIG. 7 ), a possible implementation process will be described based on the above-mentioned second embodiment. That is, the fourth embodiment can be combined with the third embodiment, and the specific implementation of the relevant steps in the fourth embodiment can refer to the third embodiment and the second embodiment.
[0326] FIG7 is a flow chart of the communication method provided in Example 4 of the present application. The LTM cross-site handover shown in FIG7 includes a terminal switching from network device 0 to network device 1 (first handover), and then switching from network device 1 to network device 2 (second handover). Wherein, network device 0 is the initial source network device (such as the third network device in Example 3). As shown in FIG7, the process may include:
[0327] S701: The terminal is connected to the core network through network device 0.
[0328] The terminal can access network device 0 through the initial access process or other possible processes, and access the core network through network device 0. Furthermore, the terminal and the core network element store the same root key KAMF (such as KAMF0), the terminal uses NCC0 (different from NCC1 to NCC7 below) to communicate with network device 0, and network device 0 uses NH associated with NCC0 to communicate with the terminal.
[0329] S702: Network device 0 determines multiple candidate cells (or multiple candidate network devices) for LTM handover.
[0330] For example, if network device 0 determines to initiate LTM configuration based on the measurement results reported by the terminal, it can determine multiple candidate cells for LTM handover. For example, the multiple candidate cells determined include cell a, cell b1, cell b2, and cell c. Cell 0 is the cell of network device 0, cells b1 and cell b2 are the cells of network device 1, and cell c is the cell of network device 2. In other words, the multiple candidate network devices include network device 0, network device 1, and network device 2.
[0331] S703 , network device 0 sends message 1 to the core network element. Message 1 is used to request the core network element to provide NH to network device 0 .
[0332] Optionally, the message 1 includes the quantity information of NHs.
[0333] S704 , the core network element sends message 2 to network device 0 , where message 2 includes W NHs; accordingly, network device 0 receives message 2 .
[0334] For example, the core network element deduces W NHs, the NCCs associated with the W NHs may be continuous, the W NHs include NH1 to NH7 (ie, W=7), and the W NHs are sent to the network device 0 through message 2.
[0335] Optionally, message 2 also includes NCC information associated with the W NHs (i.e., NCC information 2). NCC information 2 includes the NCCs associated with the W NHs, such as NCC1 to NCC7; or the W NHs included in message 2 are sorted from small to large based on the NCCs associated with the W NHs, and NCC information 2 includes the NCC associated with the initial NH among the W NHs (i.e., the minimum NCC among the NCCs associated with the W NHs), such as NCC1, and optionally also includes the value of W.
[0336] Since the network device 0 is a candidate network device of the terminal, the network device 0 may allocate M NHs out of the W NHs to itself. For example, the M NHs include NH1 and NH2.
[0337] S705 , network device 0 sends a switching request message to network device 1 ; correspondingly, network device 1 receives the switching request message from network device 0 .
[0338] Here, the handover request message is used to request the LTM configuration of the cell b1.
[0339] Exemplarily, network device 0 allocates P NHs out of (WM) NHs to network device 1, and the handover request message includes the P NHs and NCC information b. For example, the P NHs include NH3 and NH4. The NCC information b includes the NCCs associated with the P NHs, such as NCC3 and NCC4; alternatively, the P NHs included in message 4 are sorted from small to large based on the NCCs associated with the P NHs, and the NCCs associated with the P NHs are continuous. In this case, the NCC information b includes the NCC associated with the initial NH among the P NHs (i.e., the minimum NCC among the NCCs associated with the P NHs), such as NCC3, and optionally, the value of P.
[0340] S706 , network device 1 sends a switching response message to network device 0 ; correspondingly, network device 0 receives the switching response message from network device 1 .
[0341] Exemplarily, the handover response message includes the LTM configuration of the cell b1 and the NCC information b associated with the cell b1.
[0342] It can be understood that network device 0 can also send a switching request message to network device 1 for cell b2, and the switching request message is used to request the LTM configuration of cell b2; in response to the switching request message, network device 1 sends a switching response message to network device 0, and the switching response message includes the LTM configuration of cell b2, and also includes information indicating that the NCC associated with cell b2 and cell b1 is the same.
[0343] S707 , network device 0 sends a switching request message to network device 2 . Correspondingly, network device 2 receives the switching request message from network device 0 .
[0344] Here, the handover request message is used to request the LTM configuration of cell c.
[0345] Exemplarily, network device 0 allocates N (N=WMP) NHs to network device 2, and the handover request message includes the N NHs and NCC information c. For example, the N NHs include NH5, NH6, and NH7. The NCC information c includes the NCCs associated with the N NHs, such as NCC5, NCC6, and NCC7; or if the N NHs included in message 6 are sorted from small to large based on the NCCs associated with the N NHs, and the NCCs associated with the N NHs are continuous, then the NCC information c includes the NCC associated with the initial NH among the N NHs (i.e., the minimum NCC among the N NH-associated NCCs), such as NCC5, and optionally, the value of N.
[0346] S708 , network device 2 sends a switching response message to network device 0 ; correspondingly, network device 0 receives the switching response message from network device 2 .
[0347] Exemplarily, the handover response message includes the LTM configuration of cell c and NCC information c associated with cell c.
[0348] S709 , the network device 0 sends an RRC reconfiguration message to the terminal; correspondingly, the terminal receives the RRC reconfiguration message.
[0349] Exemplarily, the RRC reconfiguration message includes the LTM configuration of cell a, NCC information a associated with cell a (refer to the description of Example 2), the LTM configuration of cell b1, the LTM configuration of cell b2, NCC information b associated with cells b1 and b2, and the LTM configuration of cell c, and NCC information c associated with cell c. Optionally, the first message also includes identification information associated with cell 1 (i.e., identification information associated with network device 0), identification information associated with cells b1 / b2 (i.e., identification information associated with network device 1), and identification information associated with cell c (i.e., identification information associated with network device 2).
[0350] Optionally, the first message also includes identification information associated with cell 1 (ie, identification information associated with network device 0), identification information associated with cells b1 / b2 (ie, identification information associated with network device 1), and identification information associated with cell c (ie, identification information associated with network device 2).
[0351] S710 to S721 refer to the description of S514 to S525 in the third embodiment and are not repeated here.
[0352] Example 5
[0353] In the fifth embodiment, the third solution will be described.
[0354] FIG8 is a flow chart of the communication method provided in Example 5 of the present application. As shown in FIG8 , the flow may include:
[0355] S801. A core network element sends a sixth message to a third network device. The sixth message includes W NHs, where W is an integer greater than 1. Accordingly, the third network device receives the sixth message.
[0356] Exemplarily, the core network element determines W NHs and then sends a sixth message to the third network device. The NCCs associated with the W NHs may be continuous. The core network element is an AMF element, and the third network device is the initial source network device of the terminal. After the terminal accesses the core network element through the initial source network device, the terminal and the core network element store the same root key KAMF (e.g., KAMF0).
[0357] The content included in the sixth message can refer to the description in the third embodiment, and the specific implementation of S801 can refer to the description of S601.
[0358] S802: The third network device sends a first message to the terminal; accordingly, the terminal receives the first message.
[0359] The first message may be an RRC message, such as an RRC reconfiguration message. For example, the first message includes LTM configurations and NCC information 2 of multiple candidate cells. Optionally, the first message also includes identification information associated with the multiple candidate cells (such as identification information of network devices to which the candidate cells belong, or group identification information associated with the candidate cells, or other possible information).
[0360] The NCC information 2 includes NCCs associated with W NHs; or, the NCC information 2 includes a second NCC, the W NHs are sorted from small to large based on the NCCs associated with the W NHs, and the second NCC is the NCC associated with the initial NH among the W NHs.
[0361] S803, the terminal accesses the first network device; accordingly, the first network device may determine that the terminal accesses the first network device.
[0362] The specific implementation of the above S803 can refer to the description of S403.
[0363] S804: The first network device sends a seventh message to the third network device, where the seventh message is used to request security information. Correspondingly, the third network device receives the seventh message.
[0364] S805 , in response to the seventh message, the third network device sends an eighth message to the first network device, where the eighth message includes security information.
[0365] (1) Introduce safety information.
[0366] Exemplarily, the security information includes the first NH among the W NHs, where the first NH is an unused NH among the W NHs. Alternatively, the security information includes the index of the first NH. In this case, the third network device may also send the W NHs to the first network device, where the index of the first NH is used by the first network device to determine the first NH from the W NHs. For example, the third network device may send the W NHs to the first network device via a handover request message. Alternatively, the third network device may derive a key based on the first NH, and the security information may include the key derived based on the first NH.
[0367] The W NHs are sorted in a first order, where the first NH is the first unused NH among the W NHs. The first NH is the NH that was not used in a previous cross-site handover, meaning that a previously used NH is no longer used, thereby ensuring that different NHs are used for multiple cross-site handovers to the first network device. For example, the W NHs are NH1, NH2, NH3, NH4, NH5, NH6, and NH7, where NH1 is a used NH (for example, when a terminal communicates with a second network device, the NH used by the second network device is NH1), and the remaining NHs are unused NHs, in which case the first NH is NH2. The first order is the ascending order of the NCC or the order of the W NHs indicated by the core network element.
[0368] Exemplarily, the third network device may determine the first order based on the sixth message. Two possible approaches are described below in combination with approach 1 and approach 2.
[0369] Method 1: The W NHs included in the sixth message are sorted in the first order. That is, the core network element indicates the first order through the sixth message, and the first network device directly obtains the W NHs sorted in the first order from the sixth message. In this case, sorting the W NHs in the first order may mean sorting the W NHs in ascending order based on the NCCs associated with the W NHs; or may refer to other possible sorting methods, which are not specifically limited.
[0370] Method 2: The sixth message includes W NHs and the NCCs associated with the W NHs. The first network device sorts the W NHs in ascending order based on the NCCs associated with the W NHs. In this case, sorting the W NHs in the first order may mean sorting the W NHs in ascending order based on the NCCs associated with the W NHs.
[0371] It is understandable that, based on the order of the W NHs, the first message includes order information of the W NCCs, and the W NHs are associated one-to-one with the W NCCs. Specifically, when the NCC information 2 includes the NCCs associated with the W NHs, the NCCs associated with the W NHs are also ordered according to the first order, so that the NH used by the terminal and the NH used by the first network device are the same during a certain handover.
[0372] (2) Introduce “the first network device sending the seventh message to the third network device”.
[0373] For example, the first network device may send the seventh message to the third network device after determining that the terminal has accessed the first network device; or the first network device may send the seventh message to the third network device when determining that the terminal is about to access the first network device. For example, the first network device sends the seventh message to the third network device after receiving the cell handover notification message. The embodiments of the present application do not limit the specific timing of the first network device sending the seventh message.
[0374] Alternatively, the second network device sends a seventh message to the third network device; in response to the seventh message, the third network device sends security information to the second network device; then, the second network device sends the security information to the first network device, such as through a cell switching notification message, to send the security information to the first network device, without specific limitation.
[0375] Alternatively, the second network device sends a seventh message to the third network device, where the seventh message includes identification information associated with the first network device (see above for details); in response to the seventh message, the third network device sends security information to the first network device.
[0376] S806: The first network device and the terminal perform secure communication.
[0377] The following describes "secure communication between the first network device and the terminal" from the perspective of the first network device and the perspective of the terminal respectively.
[0378] (1) Introduction from the perspective of the first network device.
[0379] From the perspective of the first network device, after receiving the security information, the first network device uses the security information to perform security processing (including at least one of integrity protection, integrity protection confirmation, encryption or decryption) on the terminal data.
[0380] (2) Introduce from the perspective of the terminal.
[0381] From the perspective of the terminal, secure communication between the first network device and the terminal may mean that: after receiving NCC information 2, for cross-site switching, the terminal determines the NCC used for the current cross-site switching, that is, the first NCC, based on NCC information 2, and uses the first NCC to communicate with the first network device. It should be noted that the NCC used for the previous cross-site switching is no longer used for this cross-site switching. Using the first NCC to communicate with the first network device specifically means that: the terminal determines the first NH based on the first NCC (that is, for the same switching, the NH determined by the terminal is the same as the NH determined by the first network device) and uses the first NH to securely process the terminal's data (including at least one of integrity protection, integrity protection confirmation, encryption or decryption), and the first NCC is associated with the first NH.
[0382] In one example, if the above-mentioned NCC information 2 includes W NH-associated NCCs (i.e., W NCCs), the first NCC is one of the W NCCs, and the NH associated with the first NCC is an unused NH. For example, the W NCCs are sorted in the first order, and the first NCC is the first unused NCC among the W NCCs. For example, the W NCCs are NCC1 (associated with NH1), NCC2 (associated with NH2), NCC3 (associated with NH3), NCC4 (associated with NH4), NCC5 (associated with NH5), NCC6 (associated with NH6), and NCC7 (associated with NH7), and NCC1 is a used NCC (for example, the NCC used for communication between the terminal and the second network device (i.e., the source access network device currently switched) is NCC1), and the remaining NCCs are unused NCCs, then the first NCC is NCC2.
[0383] For this example, when W NCCs are consecutive, it can also be understood that the first NCC is obtained by adding 1 to the second NCC, and the second NCC is the NCC used by the terminal to communicate with the second network device (ie, the current source access network device).
[0384] In another example, if the above-mentioned NCC information 2 includes a second NCC, when the terminal switches for the first time, the second NCC can be used to communicate with the target network device of the switch; thereafter, when the terminal switches again, 1 can be added to the second NCC to obtain the first NCC, and then the first NCC can be used to communicate with the target network device of the switch; and so on.
[0385] Based on the above method, after the first network device and the terminal determine the first NH, the first network device and the terminal respectively perform the following operations: take the first NH and the target cell information of this switching (such as the PCI and downlink frequency of the cell) as input parameters, deduce the KgNB of the target cell, and then deduce Kup and Krrc based on KgNB, and use Kup and Krrc for secure communication between the first network device and the terminal.
[0386] It is understood that in the above S803, during the process of the terminal accessing the first network device, the terminal and the first network device can also communicate securely in the manner described in S806. In other words, S806 can apply to communications after the terminal accesses the first network device, and can also apply to communications during the process of the terminal accessing the first network device.
[0387] Optionally, the above method also includes S807.
[0388] S807 , the first network device sends a fifth message to the core network element. The fifth message is used to request path switching and is also used to indicate not to update NH. Accordingly, the core network element receives the fifth message.
[0389] For the above S806 , reference may be made to the description of S405 in the first embodiment.
[0390] It is understood that after the third network device obtains W NHs from the core network element, each time the terminal switches, the third network device may allocate an unused NH from the N NHs to the target network device for switching. If the third network device determines that the W NHs are about to be used up or have been used up, the third network device may request a new NH and NCC from the core network element and send the new NCC to the terminal to facilitate subsequent switching.
[0391] Using this method, the initial source network device of the terminal requests W NHs from the core network element and sends NCC information 2 to the terminal; then, during each handover, the initial source network device allocates an unused NH to the target network device currently being handed over, and the terminal uses an unused NCC to communicate with the target network device currently being handed over, so that a different NH can be used for each handover, eliminating the need to transmit security-related information to the terminal through an RRC reconfiguration message, facilitating secure communication between the terminal and the network device in LTM cross-site handover scenarios, improving the security of continuous cross-site handovers, and ensuring secure communication for continuous cross-site handovers.
[0392] Example 6
[0393] In the sixth embodiment ( FIG. 9 ), a possible implementation process will be described based on the fifth embodiment. That is, the sixth embodiment can be combined with the fifth embodiment, and the specific implementation of the relevant steps in the sixth embodiment can refer to the fifth embodiment.
[0394] FIG9 is a flow chart of the communication method provided in Example 6 of the present application. The LTM cross-site handover shown in FIG9 includes a terminal switching from network device 0 to network device 1 (first handover), and then switching from network device 1 to network device 2 (second handover). Wherein, network device 0 is the initial source network device (such as the third network device in Example 5). As shown in FIG9, the process may include:
[0395] S901: The terminal is connected to the core network through network device 0.
[0396] The terminal can access network device 0 through the initial access process or other possible processes, and access the core network through network device 0. Furthermore, the terminal and the core network element store the same root key KAMF (such as KAMF0), the terminal uses NCC0 (different from NCC1 to NCC7 below) to communicate with network device 0, and network device 0 uses NH associated with NCC0 to communicate with the terminal.
[0397] S902: Network device 0 determines multiple candidate cells (or multiple candidate network devices) for LTM handover.
[0398] For example, if network device 0 determines to initiate LTM configuration based on the measurement results reported by the terminal, it can determine multiple candidate cells for LTM handover. For example, the multiple candidate cells determined include cell a, cell b1, cell b2, and cell c. Cell 0 is the cell of network device 0, cells b1 and cell b2 are the cells of network device 1, and cell c is the cell of network device 2. In other words, the multiple candidate network devices include network device 0, network device 1, and network device 2.
[0399] S903 , network device 0 sends message 1 to the core network element. Message 1 is used to request the core network element to provide NH to network device 0 .
[0400] Optionally, the message 1 includes the quantity information of NHs.
[0401] S904 , the core network element sends message 2 to network device 0 , where message 2 includes W NHs; accordingly, network device 0 receives message 2 .
[0402] For example, the core network element deduces W NHs, the NCCs associated with the W NHs are continuous, the W NHs include NH1 to NH7 (ie, W=7), and the W NHs are sent to the network device 0 through message 2.
[0403] Optionally, message 2 also includes NCC information associated with the W NHs (i.e., NCC information 2). NCC information 2 includes the NCCs associated with the W NHs, such as NCC1 to NCC7; or the W NHs included in message 2 are sorted from small to large based on the NCCs associated with the W NHs, and NCC information 2 includes the NCC associated with the initial NH among the W NHs, such as NCC1, and optionally also includes the value of W.
[0404] S905 , network device 0 sends a switching request message to network device 1 ; correspondingly, network device 1 receives the switching request message from network device 0 .
[0405] Here, the handover request message is used to request the LTM configuration of the cell b1.
[0406] S906 , network device 1 sends a switching response message to network device 0 ; correspondingly, network device 0 receives the switching response message from network device 1 .
[0407] Exemplarily, the handover response message includes the LTM configuration of the cell b1.
[0408] It can be understood that network device 0 can also send a switching request message to network device 1 for cell b2, and the switching request message is used to request the LTM configuration of cell b2; in response to the switching request message, network device 1 sends a switching response message to network device 0, and the switching response message includes the LTM configuration of cell b2.
[0409] S907 , network device 0 sends a switching request message to network device 2 . Correspondingly, network device 2 receives the switching request message from network device 0 .
[0410] Here, the handover request message is used to request the LTM configuration of cell c.
[0411] S908 , network device 2 sends a switching response message to network device 0 ; correspondingly, network device 0 receives the switching response message from network device 2 .
[0412] Exemplarily, the handover response message includes the LTM configuration of cell c.
[0413] S909 , the network device 0 sends an RRC reconfiguration message to the terminal; correspondingly, the terminal receives the RRC reconfiguration message.
[0414] Exemplarily, the RRC reconfiguration message includes the LTM configuration of cell a, the LTM configuration of cell b1, the LTM configuration of cell b2, the LTM configuration of cell c, and NCC information 2.
[0415] S910 , network device 0 determines that the terminal needs to be switched, and the target network device for switching is network device 1 .
[0416] There are many specific implementations for network device 0 to determine the target network device, which are not limited in this embodiment of the present application. For example, network device 0 may determine that the target network device is network device 1 based on the measurement report reported by the terminal.
[0417] S911: Network device 0 sends a handover command message to the terminal. Correspondingly, the terminal receives the handover command message from network device 0.
[0418] For example, the handover command message is a MAC CE, and the handover command message includes identification information of the target cell (such as cell b1).
[0419] S912, network device 0 sends a cell handover notification message to network device 1, where the cell handover notification message is used to indicate that a handover command has been initiated for the terminal; accordingly, network device 1 receives the cell handover notification message.
[0420] S913 , in response to the cell switching notification message, network device 1 sends a request message 1 to network device 0 , where the request message 1 is used to request security information; accordingly, network device 0 receives the request message 1 .
[0421] S914 , network device 0 sends security information 1 to network device 1 ; correspondingly, network device 1 receives security information 1 .
[0422] Exemplarily, network device 0 allocates the first unused NH (ie, NH1) among W NHs to network device 1, and then sends security information 1 to network device 1. Security information 1 includes NH1, or an index of NH1, or a key KgNB derived based on NH1.
[0423] S915 , in response to the switching command message, the terminal switches to network device 1 .
[0424] S916, network device 1 sends a path switching request message to the AMF network element, and the path switching request message is used to indicate that NH is not updated; accordingly, the AMF network element receives the path switching request message.
[0425] S917, the AMF network element sends a path switching response message to network device 1; accordingly, network device 1 receives the path switching response message and completes the path switching.
[0426] Here, path switching means that the data transmission path of the terminal is switched from "UPF network element─network device 0─terminal" to "UPF network element─network device 1─terminal". The path switching response message does not include NH and NCC.
[0427] S918, the terminal communicates securely with network device 1.
[0428] From the perspective of the network device 1 , the network device 1 communicates with the terminal using the received security information 1 .
[0429] From the perspective of the terminal, the terminal uses the first unused NCC (i.e., NCC1) based on NCC information 2 (e.g., NCC information 2 includes NCC1 to NCC7) to communicate with network device 1. Specifically, the terminal determines NH1 associated with NCC1 based on NCC1, and then uses NH1 to securely process the terminal's data.
[0430] In this way, it can be ensured that the keys used by the network device 1 and the terminal are the same, thereby enabling secure communication between the network device 1 and the terminal.
[0431] S919 , network device 1 determines that the terminal needs to be switched, and the target network device for switching is network device 2 .
[0432] S920: Network device 1 sends a handover command message to the terminal. Correspondingly, the terminal receives the handover command message from network device 1.
[0433] For example, the handover command message is a MAC CE, and the handover command message includes identification information of the target cell (eg, cell c).
[0434] S921 , network device 1 sends a cell handover notification message to network device 2 , where the cell handover notification message is used to indicate that a handover command has been initiated for the terminal; accordingly, network device 2 receives the cell handover notification message.
[0435] S922 , in response to the cell switching notification message, network device 2 sends a request message 2 to network device 0 , where the request message 2 is used to request security information; accordingly, network device 0 receives the request message 2 .
[0436] S923 , network device 0 sends security information 2 to network device 2 ; correspondingly, network device 2 receives security information 2 .
[0437] Exemplarily, network device 0 allocates the first unused NH (i.e., NH2, NH1 has been used) among W NHs to network device 2, and then sends security information 2 to network device 2. Security information 2 includes NH2, or an index of NH2, or a key KgNB derived based on NH2.
[0438] S924 , in response to the switching command message, the terminal switches to network device 2 .
[0439] S925, network device 2 sends a path switching request message to the AMF network element, and the path switching request message is used to indicate that NH is not updated; accordingly, the AMF network element receives the path switching request message.
[0440] S926, the AMF network element sends a path switching response message to network device 2; accordingly, network device 2 receives the path switching response message and completes the path switching.
[0441] Here, path switching means that the data transmission path of the terminal is switched from "UPF network element─network device 1─terminal" to "UPF network element─network device 2─terminal". The path switching response message does not include NH and NCC.
[0442] S927: The terminal communicates securely with the network device 2.
[0443] From the perspective of the network device 2 , the network device 2 uses the received security information 2 to communicate with the terminal.
[0444] From the perspective of the terminal, based on NCC information 2 (e.g., NCC information 2 includes NCC1 to NCC7), the terminal uses the first unused NCC (i.e., NCC2; NCC1 has already been used) to communicate with network device 2. Specifically, based on NCC2, the terminal determines NH2 associated with NCC2 and then uses NH2 to securely process the terminal's data.
[0445] In this way, it can be ensured that the keys used by the network device 2 and the terminal are the same, thereby enabling secure communication between the network device 2 and the terminal.
[0446] It can be understood that the subsequent terminal can also switch from network device 2 to network device 0 or network device 1. The specific implementation can refer to the description of the terminal switching from network device 1 to network device 2; or, if the candidate network devices for LTM switching also include network device 3, the subsequent terminal can also switch from network device 2 to network device 3. The specific implementation can refer to the description of the terminal switching from network device 1 to network device 2.
[0447] With respect to the above embodiments, it can be understood that:
[0448] (1) In any embodiment of the present invention, "in response to A (message), execute B (action)" can be understood as "according to A, execute B" or "because of A, execute B". In any embodiment of the present invention, if A is associated with B, and B is associated with C, then A can be considered to be associated with C. "Associate" and "correspond" are interchangeable.
[0449] (2) In the various embodiments of this application, unless otherwise specified or logically conflicting, the terms and / or descriptions between different embodiments are consistent and may be referenced to each other. The technical features in different embodiments may be combined to form new embodiments based on their inherent logical relationships. In addition, within the same embodiment, different implementations or different examples may also reference or refer to each other.
[0450] (3) The various numerical numbers involved in this application are only for the convenience of description and are not used to limit the scope of this application. The step numbers of the above-mentioned flowcharts are only an example of the execution process and do not constitute a restriction on the order of execution of the steps. That is, the size of the step numbers does not mean the order of execution. The execution order of each step should be determined by its function and internal logic. In addition, not all the steps shown in the flowcharts are required to be executed. Some steps can be added or deleted based on actual needs.
[0451] The above mainly introduces the solution provided by the embodiment of the present application from the perspective of the interaction between the network side device and the terminal side device. It can be understood that in order to realize the above functions, the network side device and the terminal side device may include hardware structures and / or software modules corresponding to the execution of each function. It should be easy for those skilled in the art to realize that, in combination with the units and algorithm steps of each example described in the embodiments disclosed herein, the embodiments of the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0452] In the embodiments of the present application, the network-side device and the terminal-side device can be divided into functional units according to the above-mentioned method examples. For example, each functional unit can be divided according to each function, or two or more functions can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or software functional units.
[0453] In the case of adopting an integrated unit, Figure 10 shows a possible exemplary block diagram of the device involved in the embodiments of the present application. As shown in Figure 10, the device 1000 may include: a processing unit 1002 and a communication unit 1003. The processing unit 1002 is used to control and manage the actions of the device 1000. The communication unit 1003 is used to support the communication between the device 1000 and other devices. Optionally, the communication unit 1003 is also called a transceiver unit, and may include a receiving unit and / or a sending unit, which are used to perform receiving and sending operations respectively. The device 1000 may also include a storage unit 1001 for storing program code and / or data of the device 1000.
[0454] (1) The apparatus 1000 may be a terminal-side apparatus (e.g., a terminal) in the above-described embodiments. The processing unit 1002 may support the apparatus 1000 in executing the terminal actions in the above-described method examples. Alternatively, the processing unit 1002 primarily executes the internal actions of the terminal in the method examples, and the communication unit 1003 may support communication between the apparatus 1000 and other devices.
[0455] In one embodiment, the processing unit 1002 is used to: access a first network side device; communicate with the first network side device using a first next-hop link counter NCC, where the first NCC is obtained by adding 1 to the second NCC of the terminal side device; the second NCC is the NCC used by the terminal side device to communicate with the second network side device, or the second NCC is the NCC used for the last access to the first network side device.
[0456] In one possible design, the communication unit 1003 is used to: receive a first message, where the first message includes the second NCC.
[0457] In one possible design, the first message also includes identification information associated with the first network side device; the method also includes: based on the identification information associated with the first network side device and the identification information associated with the second network side device, determining that the key needs to be updated, and the key update includes: determining the first NCC and the next hop NH associated with the first NCC.
[0458] In one possible design, the identification information associated with the first network-side device is associated with the second NCC.
[0459] In one possible design, the first message also includes root key information associated with the second NCC.
[0460] In another embodiment, the communication unit 1003 is used to: receive a first message, where the first message is used to indicate N NCCs, where N is an integer greater than 1; the processing unit 1002 is used to: access a first network side device; use a first NCC to communicate with the first network side device, where the first NCC is one of the N NCCs, and the NH associated with the first NCC is an unused NH.
[0461] In one possible design, the first message includes N NCCs; or, the first message includes a starting NCC and a value of N among the N NCCs, and the N NCCs are continuous.
[0462] In one possible design, the first message includes identification information associated with the first network side device; the method also includes: determining that a key needs to be updated based on the identification information associated with the first network side device and the identification information associated with the second network side device, and the key update includes: determining the first NCC and the NH associated with the first NCC.
[0463] In one possible design, the identification information associated with the first network-side device is associated with the N NCCs.
[0464] In one possible design, the first message also includes root key information associated with the N NCCs.
[0465] In one possible design, the processing unit 1002 is specifically used to: initiate layer 1 / layer 2 triggered mobility LTM switching to access the first network side device; or, after the LTM switching fails, access the first network side device through LTM configuration.
[0466] (2) The apparatus 1000 may be a network-side apparatus (e.g., a first network device) in the above-described embodiments. The processing unit 1002 may support the apparatus 1000 in executing the actions of the first network device in each of the above-described method examples. Alternatively, the processing unit 1002 may primarily execute the internal actions of the first network device in the method examples, and the communication unit 1003 may support communication between the apparatus 1000 and other devices.
[0467] In one embodiment, the communication unit 1003 is used to: receive a second message, the second message including N NHs, N being an integer greater than or equal to 1; determine that the terminal side device is accessed to the first network side device; use the first NH among the N NHs to communicate with the terminal side device, the first NH being an unused NH among the N NHs.
[0468] In a possible design, the N NHs are sorted in a first order, and the first NH is the first unused NH among the N NHs.
[0469] In one possible design, the processing unit 1002 is used to determine the first order based on the second message.
[0470] In one possible design, the N NHs included in the second message are sorted in a first order.
[0471] In a possible design, the second message is used to indicate the NCC associated with the N NHs; sorting the N NHs according to the first order includes: sorting the N NHs from small to large based on the NCC associated with the N NHs.
[0472] In one possible design, the processing unit 1002 is specifically used to: determine that the terminal side device initiates LTM switching to access the first network side device; or, determine that the terminal side device accesses the first network side device through LTM configuration after the LTM switching fails.
[0473] In one possible design, the communication unit 1003 is also used to: send a third message to the core network network element, wherein the third message is used to request that NH be provided to the first network side device; and receive the second message from the core network network element, wherein the second message is a response message to the third message.
[0474] In one possible design, the third message includes quantity information of NHs.
[0475] In one possible design, the communication unit 1003 is also used to: receive a fourth message from a third network side device, wherein the fourth message is used to request the LTM configuration of the first network side device; and send the third message to the core network network element in response to the fourth message.
[0476] In a possible design, the communication unit 1003 is further used to: send a first message to the terminal side device, where the first message is used to indicate the NCC associated with the N NHs.
[0477] In one possible design, the first message includes the NCC associated with the N NHs; or, the first message includes a second NCC, the N NHs are sorted from small to large based on the NCCs associated with the N NHs, the NCCs associated with the N NHs are continuous, and the second NCC is the NCC associated with the starting NH among the N NHs.
[0478] In one possible design, the first message also includes identification information associated with the first network side device, the identification information associated with the first network side device is associated with the second NCC, or the identification information associated with the first network side device is associated with the NCC associated with the N NHs.
[0479] In one possible design, the communication unit 1003 is further used to: send a fifth message to the core network network element, where the fifth message is used to request path switching, and the fifth message is also used to indicate that the NH is not updated.
[0480] It should be understood that the division of units in the above device is merely a division of logical functions. In actual implementation, they can be fully or partially integrated into one physical entity, or they can be physically separated. Moreover, the units in the device can all be implemented in the form of software calling through processing elements; or they can all be implemented in the form of hardware; or some units can be implemented in the form of software calling through processing elements, and some units can be implemented in the form of hardware. For example, each unit can be a separately established processing element, or it can be integrated into a certain chip of the device. In addition, it can also be stored in the memory in the form of a program, called by a certain processing element of the device and execute the function of the unit. In addition, all or part of these units can be integrated together, or they can be implemented independently. The processing element described here can also be a processor, which can be an integrated circuit with signal processing capabilities. In the implementation process, each operation of the above method or each unit above can be implemented by the integrated logic circuit of the hardware in the processor element or in the form of software calling through the processing element.
[0481] In one example, the unit in any of the above devices may be one or more integrated circuits configured to implement the above method, such as one or more application specific integrated circuits (ASICs), or one or more digital singnal processors (DSPs), or one or more field programmable gate arrays (FPGAs), or a combination of at least two of these integrated circuit forms. For another example, when the unit in the device can be implemented in the form of a processing element scheduler, the processing element can be a processor, such as a general-purpose central processing unit (CPU), or other processor that can call a program. For another example, these units can be integrated together and implemented in the form of a system-on-a-chip (SOC).
[0482] The above-mentioned receiving unit is an interface circuit of the device, which is used to receive signals from other devices. For example, when the device is implemented as a chip, the receiving unit is the interface circuit of the chip used to receive signals from other chips or devices. The above-mentioned sending unit is an interface circuit of the device, which is used to send signals to other devices. For example, when the device is implemented as a chip, the sending unit is the interface circuit of the chip used to send signals to other chips or devices.
[0483] Referring to Figure 11, a structural diagram of a network-side device (such as a network device) provided in an embodiment of the present application, which can be applied to the communication system shown in Figure 1 to perform the functions of the network device in the above method embodiment. As shown in Figure 11, the network device 110 can be an access network node, and the network device 110 may include one or more DUs 1101 and one or more CUs 1102. The DU 1101 may include at least one antenna 11011, at least one radio frequency unit 11012, at least one processor 11013 and at least one memory 11014. The DU 1101 is mainly used for receiving and transmitting radio frequency signals, converting radio frequency signals into baseband signals, and partial baseband processing. CU1102 may include at least one processor 11022 and at least one memory 11021.
[0484] The CU 1102 is primarily used for baseband processing and controlling network devices. The DU 1101 and CU 1102 can be physically located together or separately, i.e., in a distributed base station. The CU 1102 is the control center of the network device, also known as a processing unit, and is primarily used to perform baseband processing. For example, the CU 1102 can be used to control the network device to execute the network device operation process described in the above method embodiments.
[0485] In addition, optionally, the network device 110 may include one or more radio frequency units, one or more DUs, and one or more CUs. The DU may include at least one processor 11013 and at least one memory 11014, the radio frequency unit may include at least one antenna 11011 and at least one radio frequency unit 11012, and the CU may include at least one processor 11022 and at least one memory 11021.
[0486] In one example, the CU1102 may be composed of one or more single boards, and the multiple single boards may jointly support a wireless access network with a single access indication (such as a 5G network), or may respectively support wireless access networks with different access standards (such as an LTE network, a 5G network, or other networks). The memory 11021 and the processor 11022 may serve one or more single boards. That is, a memory and a processor may be separately set on each single board. It is also possible that multiple single boards share the same memory and processor. In addition, necessary circuits may be provided on each single board. The DU1101 may be composed of one or more single boards, and the multiple single boards may jointly support a wireless access network with a single access indication (such as a 5G network), or may respectively support wireless access networks with different access standards (such as an LTE network, a 5G network, or other networks). The memory 11014 and the processor 11013 may serve one or more single boards. That is, a memory and a processor may be separately set on each single board. It is also possible that multiple single boards share the same memory and processor. In addition, necessary circuits may be provided on each single board.
[0487] The network device shown in Figure 11 is capable of implementing the various processes involved in the network device in the above-described method embodiments. The operations and / or functions of the various modules in the network device shown in Figure 11 are for implementing the corresponding processes in the above-described method embodiments. For details, please refer to the description in the above-described method embodiments; to avoid repetition, detailed descriptions are omitted here.
[0488] Refer to Figure 12, which is a structural diagram of a terminal-side device (such as a terminal) provided in an embodiment of the present application. The terminal can be applied to the communication system shown in Figure 1 to implement the operation of the terminal in the above embodiment. As shown in Figure 12, the terminal includes: an antenna 1210, a radio frequency part 1220, and a signal processing part 1230. The antenna 1210 is connected to the radio frequency part 1220. In the downlink direction, the radio frequency part 1220 receives information sent by the network device through the antenna 1210, and sends the information sent by the network device to the signal processing part 1230 for processing. In the uplink direction, the signal processing part 1230 processes the information of the terminal and sends it to the radio frequency part 1220. The radio frequency part 1220 processes the information of the terminal and sends it to the network device through the antenna 1210.
[0489] The signal processing unit 1230 may include a modem subsystem for processing data at various communication protocol layers; a central processing unit for processing the terminal operating system and application layers; and other subsystems, such as a multimedia subsystem for controlling the terminal camera and screen display, and a peripheral subsystem for connecting to other devices. The modem subsystem may be a separate chip.
[0490] The modem subsystem may include one or more processing elements 1231, such as a main control CPU and other integrated circuits. Furthermore, the modem subsystem may include a storage element 1232 and an interface circuit 1233. Storage element 1232 is used to store data and programs. However, the program used to execute the method executed by the terminal in the above method may not be stored in storage element 1232 but in a memory external to the modem subsystem, and loaded by the modem subsystem when in use. Interface circuit 1233 is used to communicate with other subsystems.
[0491] The modem subsystem can be implemented using a chip comprising at least one processing element and an interface circuit. The processing element is configured to execute each step of any of the methods performed by the terminal, and the interface circuit is configured to communicate with other devices. In one implementation, the unit that performs each step of the method can be implemented as a processing element scheduler. For example, the terminal device includes a processing element and a storage element, and the processing element invokes a program stored in the storage element to execute the method performed by the terminal in the above method embodiments. The storage element can be a storage element located on the same chip as the processing element, i.e., an on-chip storage element.
[0492] In another implementation, the program for executing the method executed by the terminal in the above method can be stored in a memory element on a different chip from the processing element, i.e., an off-chip memory element. In this case, the processing element calls or loads the program from the off-chip memory element to the on-chip memory element to call and execute the method executed by the terminal in the above method embodiment.
[0493] In another implementation, the unit implementing each step of the above method in the terminal may be configured as one or more processing elements, which are provided in the modem subsystem. The processing elements may be integrated circuits, such as one or more ASICs, one or more DSPs, one or more FPGAs, or a combination of these integrated circuits. These integrated circuits may be integrated together to form a chip.
[0494] The units that implement the various steps of the above method in the terminal can be integrated together and implemented in the form of a SOC chip, which is used to implement the above method. The chip can integrate at least one processing element and a storage element, and the processing element can call the program stored in the storage element to implement the above terminal execution method; alternatively, the chip can integrate at least one integrated circuit to implement the above terminal execution method; or, a combination of the above implementation methods can be used, with the functions of some units implemented by the processing element calling the program, and the functions of some units implemented by the integrated circuit.
[0495] As can be seen, the above-mentioned terminal device may include at least one processing element and an interface circuit, wherein the at least one processing element is used to execute any of the terminal-executed methods provided in the above method embodiments. The processing element may execute some or all of the steps executed by the terminal in a first manner: by calling a program stored in a storage element; or in a second manner: by combining hardware integrated logic circuits in the processor element with instructions to execute some or all of the steps executed by the terminal. Of course, the first and second manners may also be combined to execute some or all of the steps executed by the terminal.
[0496] The processing element here is the same as described above and can be implemented by a processor. The function of the processing element can be the same as that of the processing unit described in Figure 10. For example, the processing element can be a general-purpose processor, such as a CPU, or one or more integrated circuits configured to implement the above method, such as one or more ASICs, or one or more microprocessors DSPs, or one or more FPGAs, or a combination of at least two of these integrated circuit forms. The storage element can be implemented by a memory, and the function of the storage element can be the same as that of the storage unit described in Figure 10. The storage element can be a single memory or a collective term for multiple memories.
[0497] The terminal shown in FIG12 is capable of implementing the various processes involved in the terminal in the above-described method embodiment. The operations and / or functions of the various modules in the terminal shown in FIG12 are respectively for implementing the corresponding processes in the above-described method embodiment. For details, please refer to the description of the above-described method embodiment. To avoid repetition, detailed description is omitted here.
[0498] An embodiment of the present application also provides a communication system, which includes the terminal in the above method embodiment, the first network device in the above method embodiment, and optionally, the third network device in the above method embodiment.
[0499] The terms "system" and "network" in the embodiments of the present application can be used interchangeably. "At least one" refers to one or more, and "plurality" refers to two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can represent: the existence of A alone, the existence of A and B at the same time, and the existence of B alone, where A and B can be singular or plural. The character " / " generally indicates that the associated objects before and after are in an "or" relationship. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, "at least one of A, B or C" includes A, B, C, AB, AC, BC or ABC, and "at least one of A, B and C" can also be understood to include A, B, C, AB, AC, BC or ABC. And, unless otherwise specified, the ordinal numbers such as "first" and "second" mentioned in the embodiments of the present application are used to distinguish multiple objects and are not used to limit the order, timing, priority or importance of multiple objects.
[0500] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, optical storage, etc.) that contain computer-usable program code.
[0501] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the present application. It should be understood that each flow and / or box in the flow chart and / or block diagram, as well as the combination of the flow chart and / or box in the flow chart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device produce a device for implementing the functions specified in one or more flow charts and / or one or more boxes in the block diagram.
[0502] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a product including an instruction device that implements the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0503] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
Claims
1. A communication method, characterized in that: The method is applied to a terminal-side device, and includes: Accessing a first network-side device; communicating with the first network-side device using a first next-hop link counter NCC, where the first NCC is obtained by adding 1 to the second NCC by the terminal-side device; The second NCC is the NCC used by the terminal-side device to communicate with the second network-side device, or the second NCC is the NCC used for the last access to the first network-side device.
2. The method according to claim 1, characterized in that The method further comprises: A first message is received, where the first message includes the second NCC.
3. The method according to claim 2, characterized in that The first message further includes identification information associated with the first network-side device; The method further comprises: Based on the identification information associated with the first network side device and the identification information associated with the second network side device, it is determined that a key needs to be updated, and the key updating includes: determining the first NCC and a next hop NH associated with the first NCC.
4. The method according to claim 3, characterized in that The identification information associated with the first network-side device is associated with the second NCC.
5. The method according to any one of claims 2 to 4, characterized in that The first message also includes root key information associated with the second NCC.
6. A communication method, characterized in that: The method is applied to a terminal-side device, and includes: receiving a first message, where the first message is used to indicate N NCCs, where N is an integer greater than 1; Accessing a first network-side device; A first NCC is used to communicate with the first network-side device, where the first NCC is one of the N NCCs, and a NH associated with the first NCC is an unused NH.
7. The method according to claim 6, characterized in that The first message includes N NCCs; or, The first message includes a starting NCC and a value of N among the N NCCs, and the N NCCs are continuous.
8. The method according to claim 6 or 7, characterized in that The first message includes identification information associated with the first network-side device; The method further comprises: Based on the identification information associated with the first network side device and the identification information associated with the second network side device, it is determined that a key needs to be updated, and the key updating includes: determining the first NCC and the NH associated with the first NCC.
9. The method according to claim 8, characterized in that The identification information associated with the first network-side device is associated with the N NCCs.
10. The method according to any one of claims 6 to 9, characterized in that The first message also includes root key information associated with the N NCCs.
11. The method according to any one of claims 1 to 10, characterized in that Accessing the first network-side device includes: Initiate a layer 1 / layer 2 triggered mobility LTM handover to access the first network side device; or, After the LTM switching fails, the first network-side device is accessed through the LTM configuration.
12. A communication method, characterized in that: The method is applied to a first network-side device, and includes: receiving a second message including N NHs, where N is an integer greater than or equal to 1; Determining that the terminal-side device is connected to the first network-side device; A first NH among the N NHs is used to communicate with the terminal-side device, where the first NH is an unused NH among the N NHs.
13. The method according to claim 12, characterized in that The N NHs are sorted in a first order, and the first NH is the first unused NH among the N NHs.
14. The method according to claim 13, characterized in that The method further comprises: Based on the second message, the first order is determined.
15. The method according to claim 14, characterized in that The N NHs included in the second message are sorted in a first order.
16. The method according to claim 14, characterized in that The second message is used to indicate the NCC associated with the N NHs; Sorting the N NHs according to the first order includes: sorting the N NHs from small to large based on NCCs associated with the N NHs.
17. The method according to any one of claims 12 to 16, characterized in that Determining that the terminal-side device is connected to the first network-side device includes: Determine that the terminal-side device initiates LTM switching to access the first network-side device; or, After determining that the terminal side device fails in LTM switching, access to the first network side device is performed through LTM configuration.
18. The method according to any one of claims 12 to 17, characterized in that The method further includes: sending a third message to a core network element, wherein the third message is used to request that the first network side device provide NH; Receiving the second message includes: receiving the second message from the core network element, where the second message is a response message to the third message.
19. The method according to claim 18, characterized in that The third message includes the quantity information of NHs.
20. The method according to claim 18 or 19, characterized in that Sending a third message to the core network element includes: receiving a fourth message from a third network-side device, wherein the fourth message is used to request LTM configuration of the first network-side device; In response to the fourth message, the third message is sent to the core network element.
21. The method according to any one of claims 12 to 19, characterized in that The method further comprises: A first message is sent to a terminal side device, where the first message is used to indicate the NCC associated with the N NHs.
22. The method according to claim 21, characterized in that The first message includes the NCC associated with the N NHs; or, The first message includes a second NCC, the N NHs are sorted from small to large based on NCCs associated with the N NHs, the NCCs associated with the N NHs are continuous, and the second NCC is the NCC associated with the starting NH among the N NHs.
23. The method according to claim 22, characterized in that The first message also includes identification information associated with the first network side device, where the identification information associated with the first network side device is associated with the second NCC, or the identification information associated with the first network side device is associated with the NCC associated with the N NHs.
24. The method according to any one of claims 13 to 23, characterized in that The method further comprises: A fifth message is sent to the core network element, where the fifth message is used to request path switching and is further used to indicate not to update the NH.
25. A communication device, characterized in that: The method comprises a module for executing the method according to any one of claims 1 to 11, or a module for executing the method according to any one of claims 12 to 24.
26. A communication device, characterized in that: The communication device comprises a processor coupled to a memory, wherein a computer program is stored in the memory; the processor is used to call the computer program in the memory so that the communication device executes the method according to any one of claims 1 to 11, or the method according to any one of claims 12 to 24.
27. A communication system, characterized in that: The communication system includes a network side device and a terminal side device; wherein the terminal side device is used to execute the method described in any one of claims 1 to 11, and the network side device is used to execute the method described in any one of claims 12 to 24.
28. A computer-readable storage medium, characterized in that The storage medium stores a computer program or instruction. When the computer program or instruction is executed by a computer, the method according to any one of claims 1 to 11 or the method according to any one of claims 12 to 24 is implemented.
29. A computer program product, characterized in that When a computer reads and executes the computer program product, the method according to any one of claims 1 to 11 is executed, or the method according to any one of claims 12 to 24 is executed.
Citation Information
Patent Citations
Method and system for generating keys in switching process
CN101925059A
System and method for communicating with provisioned security protection
CN111448813A
Access stratum (AS) security for a centralized radio access network (c-ran)
US20190320352A1