Key updating method and device

By flexibly determining the key derivative method during the LTM switching process by the terminal device, the problem of not being able to support continuous key updates in the prior art is solved, and the effect of reducing handover delay and ensuring business continuity is achieved.

WO2025166567A1PCT designated stage Publication Date: 2025-08-14GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/076438
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-02-06
Publication Date
2025-08-14

AI Technical Summary

Technical Problem

In the L1/L2 triggered mobility (LTM) switch process, existing communication systems cannot support continuous key updates, resulting in an increase in handover delay and affecting business continuity.

Method used

When the terminal device needs to perform key updates, it flexibly performs key updates by determining the key derivative method, including horizontal key derivatives and vertical key derivatives, supporting continuous switching between central units.

Benefits of technology

It realizes flexible key updates during the mobility switching process of layer one/layer two trigger, reducing the switching delay and ensuring the continuity and security of services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024076438_14082025_PF_FP_ABST
    Figure CN2024076438_14082025_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to a key updating method. The method comprises: when there is a need to execute key updating, a terminal device determines a key derivation mode. According to the embodiments of the present application, when there is a need to execute key updating, a terminal device can flexibly determine a key derivation mode, thereby performing key updating more flexibly.
Need to check novelty before this filing date? Find Prior Art

Description

Key updating method and device Technical Field

[0001] The present application relates to the field of communications, and more specifically, to a key updating method and device. Background Art

[0002] To further reduce handover latency and ensure service continuity, the 3rd Generation Partnership Project (3GPP) Release 18 (R18) supports a handover process based on Layer 1 / Layer 2 (L1 / L2) triggering, known as Layer 1 / L2 triggered mobility (LTM). LTM enables continuous handover between configured candidate cells. Before the introduction of LTM, traditional handover processes did not support continuous handover.

[0003] Summary of the Invention

[0004] The embodiments of the present application provide a key updating method and device, which can perform key updating more flexibly.

[0005] This embodiment of the present application provides a key update method, including:

[0006] When a key update is required, the terminal device determines the key derivation method.

[0007] This embodiment of the present application provides a key update method, including:

[0008] The first network device sends one or more first messages, where the first messages include key information associated with one or more candidate cells.

[0009] This embodiment of the present application provides a key update method, including:

[0010] One or more second network devices receive a first message, where the first message includes key information associated with one or more candidate cells.

[0011] This embodiment of the present application provides a key update method, including:

[0012] When the terminal device successfully accesses the third network device after the handover, the third network device performs a key update based on the new key information, where the new key information comes from the fourth network device.

[0013] An embodiment of the present application provides a terminal device, including:

[0014] The processing unit is configured to determine a key derivation method when a key update is required.

[0015] An embodiment of the present application provides a first network device, including:

[0016] The sending unit is configured to send one or more first messages, where the first messages include key information associated with one or more candidate cells.

[0017] An embodiment of the present application provides a second network device, including:

[0018] The receiving unit is configured to receive a first message, where the first message includes key information associated with one or more candidate cells.

[0019] This embodiment of the present application provides a third network device, including:

[0020] The processing unit is used to perform key update based on new key information when the terminal device successfully accesses after switching, and the new key information comes from the fourth network device.

[0021] An embodiment of the present application provides a terminal device, comprising: a transceiver, a processor, and a memory. The memory is used to store a computer program, the transceiver is used to communicate with other devices, and the processor is used to call and execute the computer program stored in the memory, so that the terminal device performs the above-mentioned key update method.

[0022] An embodiment of the present application provides a network device, comprising: a transceiver, a processor, and a memory. The memory is used to store a computer program, the transceiver is used to communicate with other devices, and the processor is used to call and execute the computer program stored in the memory to enable the network device to perform the above-mentioned key update method.

[0023] An embodiment of the present application provides a chip for implementing the above-mentioned key update method.

[0024] Specifically, the chip includes: a processor, configured to call and run a computer program from a memory, so that a device equipped with the chip executes the above-mentioned key updating method.

[0025] An embodiment of the present application provides a computer-readable storage medium for storing a computer program. When the computer program is executed by a device, the device executes the above-mentioned key update method.

[0026] An embodiment of the present application provides a computer program product, including computer program instructions, which enable a computer to execute the above-mentioned key update method.

[0027] An embodiment of the present application provides a computer program, which, when executed on a computer, enables the computer to execute the above-mentioned key updating method.

[0028] In the embodiment of the present application, when a key update needs to be performed, the terminal device can flexibly determine the key derivation method, thereby performing the key update more flexibly. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] FIG1 is a schematic diagram of an application scenario according to an embodiment of the present application.

[0030] FIG2 is an example diagram of the specific process of LTM.

[0031] FIG3 is a schematic diagram of security key derivation during the switching process.

[0032] FIG4 is a schematic diagram of execution of the source base station.

[0033] FIG5 is a schematic flowchart of a key updating method according to an embodiment of the present application.

[0034] FIG6 is a schematic flowchart of a key updating method according to an embodiment of the present application.

[0035] FIG7 is a schematic flowchart of a key updating method according to an embodiment of the present application.

[0036] FIG8 is a schematic flowchart of a key updating method according to an embodiment of the present application.

[0037] FIG9 is a schematic diagram of an implementation method of the first embodiment of the present application.

[0038] FIG10 is a schematic diagram of method 1 of embodiment 1 of the present application.

[0039] FIG11 is a schematic diagram of Method 2 of Example 1 of the present application.

[0040] FIG12 is a schematic block diagram of a terminal device according to an embodiment of the present application.

[0041] FIG13 is a schematic block diagram of a first network device according to an embodiment of the present application.

[0042] FIG14 is a schematic block diagram of a second network device according to an embodiment of the present application.

[0043] FIG15 is a schematic block diagram of a third network device according to an embodiment of the present application.

[0044] FIG16 is a schematic block diagram of a communication device according to an embodiment of the present application.

[0045] FIG17 is a schematic block diagram of a chip according to an embodiment of the present application.

[0046] FIG18 is a schematic block diagram of a communication system according to an embodiment of the present application. DETAILED DESCRIPTION

[0047] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.

[0048] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as: Long Term Evolution (LTE) system, Advanced Long Term Evolution (LTE-A) system, New Radio (NR) system, NR system evolution system, LTE on unlicensed spectrum (LTE-U) system, NR on unlicensed spectrum (NR-based access to unlicensed spectrum, NR-U) system, Non-Terrestrial Networks (NTN) system, Universal Mobile Telecommunication System (UMTS), Wireless Local Area Networks (WLAN), Wireless Fidelity (WiFi), Fifth Generation (5G) system or other communication systems.

[0049] Generally speaking, traditional communication systems support a limited number of connections and are easy to implement. However, with the development of communication technology, mobile communication systems will not only support traditional communications, but will also support, for example, device-to-device (D2D) communication, machine-to-machine (M2M) communication, machine-type communication (MTC), vehicle-to-vehicle (V2V) communication, or vehicle-to-everything (V2X) communication, etc. The embodiments of the present application can also be applied to these communication systems.

[0050] In one embodiment, the communication system in the embodiment of the present application can be applied to a carrier aggregation (CA) scenario, a dual connectivity (DC) scenario, and a standalone (SA) networking scenario.

[0051] In one embodiment, the communication system in the embodiment of the present application can be applied to an unlicensed spectrum, wherein the unlicensed spectrum can also be considered as a shared spectrum; or, the communication system in the embodiment of the present application can also be applied to an authorized spectrum, wherein the authorized spectrum can also be considered as an unshared spectrum.

[0052] The embodiments of the present application describe various embodiments in conjunction with network devices and terminal devices, wherein the terminal device may also be referred to as user equipment (UE), access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent or user device, etc.

[0053] The terminal device can be a station (STAION, ST) in a WLAN, a cellular phone, a cordless phone, a Session Initiation Protocol (SIP) phone, a Wireless Local Loop (WLL) station, a Personal Digital Assistant (PDA) device, a handheld device with wireless communication capabilities, a computing device or other processing device connected to a wireless modem, a vehicle-mounted device, a wearable device, a terminal device in a next-generation communication system such as an NR network, or a terminal device in a future evolved Public Land Mobile Network (PLMN) network, etc.

[0054] In an embodiment of the present application, the terminal device can be deployed on land, including indoors or outdoors, handheld, wearable or vehicle-mounted; it can also be deployed on the water surface (such as ships, etc.); it can also be deployed in the air (such as airplanes, balloons and satellites, etc.).

[0055] In an embodiment of the present application, the terminal device may be a mobile phone, a tablet computer, a computer with wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical, a wireless terminal device in a smart grid, a wireless terminal device in transportation safety, a wireless terminal device in a smart city, or a wireless terminal device in a smart home, etc.

[0056] As an example and not a limitation, in the embodiment of the present application, the terminal device may also be a wearable device. Wearable devices may also be called wearable smart devices, which are a general term for wearable devices that are intelligently designed and developed using wearable technology for daily wear, such as glasses, gloves, watches, clothing, and shoes. A wearable device is a portable device that is worn directly on the body or integrated into the user's clothes or accessories. Wearable devices are not only hardware devices, but also achieve powerful functions through software support, data interaction, and cloud interaction. Broadly speaking, wearable smart devices include those that are fully functional, large in size, and can achieve complete or partial functions without relying on smartphones, such as smart watches or smart glasses, as well as those that only focus on a certain type of application function and need to be used in conjunction with other devices such as smartphones, such as various smart bracelets and smart jewelry for vital sign monitoring.

[0057] In an embodiment of the present application, the network device may be a device for communicating with a mobile device. The network device may be an access point (AP) in a WLAN, an evolved base station (eNB or eNodeB) in LTE, or a relay station or access point, or a vehicle-mounted device, a wearable device, and a network device (gNB) in an NR network, or a network device in a future evolved PLMN network or a network device in an NTN network, etc.

[0058] As an example and not a limitation, in an embodiment of the present application, the network device may have a mobile feature, for example, the network device may be a mobile device. Alternatively, the network device may be a satellite or a balloon station. For example, the satellite may be a low earth orbit (LEO) satellite, a medium earth orbit (MEO) satellite, a geostationary earth orbit (GEO) satellite, a high elliptical orbit (HEO) satellite, etc. Optionally, the network device may also be a base station set up in a location such as land or water.

[0059] In an embodiment of the present application, the network device can provide services for a cell, and the terminal device communicates with the network device through the transmission resources used by the cell (for example, frequency domain resources, or spectrum resources). The cell can be a cell corresponding to the network device (for example, a base station). The cell can belong to a macro base station or a base station corresponding to a small cell. The small cells here may include: metro cells, micro cells, pico cells, femto cells, etc. These small cells have the characteristics of small coverage and low transmission power, and are suitable for providing high-speed data transmission services.

[0060] FIG1 exemplarily illustrates a communication system 100. The communication system includes a network device 110 and two terminal devices 120. In one embodiment, the communication system 100 may include multiple network devices 110, and each network device 110 may include a different number of terminal devices 120 within its coverage area, which is not limited in this embodiment of the present application.

[0061] In one embodiment, the communication system 100 may further include other network entities such as a Mobility Management Entity (MME) and an Access and Mobility Management Function (AMF), which is not limited in this embodiment of the present application.

[0062] Among them, the network equipment may include access network equipment and core network equipment. That is, the wireless communication system also includes multiple core networks for communicating with the access network equipment. The access network equipment can be an evolutionary base station (evolutional node B, abbreviated as eNB or e-NodeB) macro base station, micro base station (also called "small base station"), pico base station, access point (AP), transmission point (TP) or new generation base station (new generation Node B, gNodeB), etc. in a long-term evolution (LTE) system, a next-generation (mobile communication system) (next radio, NR) system or an authorized auxiliary access long-term evolution (LAA-LTE) system.

[0063] It should be understood that in the embodiments of the present application, a device having a communication function in a network / system may be referred to as a communication device. Taking the communication system shown in Figure 1 as an example, the communication device may include a network device and a terminal device having a communication function. The network device and the terminal device may be specific devices in the embodiments of the present application and will not be described in detail here. The communication device may also include other devices in the communication system, such as a network controller, a mobility management entity, and other network entities, which are not limited in the embodiments of the present application.

[0064] It should be understood that the terms "system" and "network" are often used interchangeably herein. The term "and / or" is simply a description of an association between related objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A exists alone, A and B exist simultaneously, or B exists alone. Furthermore, the character " / " generally indicates that the related objects are in an "or" relationship.

[0065] It should be understood that the "indication" mentioned in the embodiments of this application can be a direct indication, an indirect indication, or an indication of an association. For example, "A indicates B" can mean that A directly indicates B, for example, B can be obtained through A; it can also mean that A indirectly indicates B, for example, A indicates C, and B can be obtained through C; it can also mean that there is an association between A and B.

[0066] In the description of the embodiments of the present application, the term "corresponding" may indicate a direct or indirect correspondence between the two, or an association relationship between the two, or a relationship between indication and being indicated, configuration and being configured, etc.

[0067] To facilitate understanding of the technical solutions of the embodiments of the present application, the relevant technologies of the embodiments of the present application are described below. The following relevant technologies can be arbitrarily combined with the technical solutions of the embodiments of the present application as optional solutions, and they all fall within the protection scope of the embodiments of the present application.

[0068] 1. Long-Term Transaction (LTM)

[0069] An example of a specific LTM process is shown in Figure 2. The LTM execution steps may include the following parts: LTM preparation, early synchronization, LTM execution, and LTM completion. The specific steps of LTM are as follows:

[0070] A UE, such as one in an RRC connected state, sends a measurement report to a base station, such as a gNB, reporting Layer 3 (L3) measurement results. The base station determines to initiate a LTM process and triggers candidate cell preparation (referred to as LTM candidate preparation).

[0071] The base station sends an RRC message (eg, an RRC reconfiguration message) including an LTM candidate cell configuration (which may be referred to as LTM candidate configuration) to the UE, where the number of candidate cells is one or more.

[0072] The UE stores the LTM candidate cell configuration and feeds back a reconfiguration complete message (eg, an RRC Reconfiguration Complete message) to the network.

[0073] Before receiving the LTM cell handover command, the UE can perform uplink / downlink synchronization with the candidate cell in advance to reduce the interruption delay of the handover process. In step 4a, the UE synchronizes with the candidate cell in the downlink (DL synchronization) and in step 4b, the UE synchronizes with the candidate cell in the uplink (UL synchronization).

[0074] The UE performs L1 measurement on each candidate cell and reports the L1 measurement result, such as an L1 measurement report, to the network.

[0075] The base station determines the target cell based on the L1 measurement results reported by the UE and instructs the UE to switch to the target cell via a MAC CE. For example, after the base station makes an LTM decision, in step 6, it may send a cell switching command (MAC CE) to the UE.

[0076] After receiving the cell handover command, the UE can detach from the source and apply the target configurations. If the UE does not currently have a valid timing advance (TA) or transmission configuration indication (TCI) state identifier (ID) for the target cell, the UE initiates a random access procedure (RACH procedure) to the target cell after receiving the LTM handover indication.

[0077] The UE sends an indication message indicating successful completion of LTM to the target cell.

[0078] 2. Key Update during Xn Switching

[0079] There are two types of security key derivation during the handover process, as shown in Figure 3:

[0080] Horizontal derivation (or horizontal key derivation): Based on the initial key such as K gNB / K eNB , the physical cell identifier (PCI) of the target cell and the downlink frequency to generate the target key such as K eNB* / K NG-RAN* .

[0081] Vertical derivation (or vertical key derivation): Generate the next hop key (NH) based on the next hop chaining count (NCC), and generate the target key such as K based on NH, the PCI of the target cell and the downlink frequency. eNB* / K NG-RAN* .

[0082] Among them, K gNB / K eNB is the key used by the source base station, K eNB* / K NG-RAN* The key used by the target base station.

[0083] As shown in FIG4 , the source base station may perform the following steps:

[0084] 1. First, generate the key K based on the target PCI and the target downlink frequency eNB* / K NG-RAN* ; If there is unused {NH, NCC}, use NH to generate a key or as a key; if there is no unused {NH, NCC}, use the current key K gNB / K eNB .

[0085] 2. The generated K eNB* / K NG-RAN* Forward to the target base station; use K after switching eNB* / K NG-RAN* As K gNB / K eNB ; Carry the K in the switch command eNB* / K NG-RAN* of NCC.

[0086] For example, referring to Figure 4, the source side S-gNB sends a handover request (HO requst) to the target side, which may include UE security capabilities, source side algorithm, K eNB* , NCC, etc.

[0087] The target base station may perform the following steps:

[0088] 1. The target base station will receive KeNB* / KNG-RAN* and communicate with the UE as KgNB / KeNB;

[0089] 2. Associate the NCC received from the source base station with the KgNB / KeNB;

[0090] 3. Include the NCC in the handover command and send it to the UE via the source base station;

[0091] 4. After the handover is completed, the target base station sends a path switch request to the MME.

[0092] As shown in Figure 4, the target side T-gNB can eNB* As the new K eNB and associate it with the NCC for storage. After the HO from the UE to the T-gNB is complete (HO complete), the T-gNB may send a path switch request to the target AMF (T-AMF) or MME. The T-AMF may calculate the NH based on the NCC, for example, by adding 1 to the NCC to determine the corresponding NH. The T-AMF may return a path switch request acknowledgment (Path switch request ACK) to the T-gNB (which may carry {NCC, NH}). The T-gNB may save {NCC, NH} for future handover. The T-gNB and the UE perform an intra-cell HO procedure.

[0093] The UE may perform the following steps:

[0094] After receiving the handover command, the UE can synchronize NH according to the received NCC and calculate K gNB / K eNB , and save it in association with the NCC. The specific example is as follows:

[0095] 1. If the NCC received by the UE in the handover command is the same as the current UE side K gNB / K eNB The associated NCC values ​​are equal, based on K gNB / K eNB And the target cell PCI and downlink frequency generate K eNB* / K NG-RAN* .

[0096] 2. If the NCC received by the UE in the handover command is the same as the current UE side K gNB / K eNB The associated NCC value is different. The next hop NH can be generated based on the saved NH, and the K can be generated based on the generated NH, the target cell PCI and the downlink frequency. eNB* / KNG-RAN* .

[0097] 3.UE will use the generated K eNB* / K NG-RAN* Will be K gNB / K eNB Communicate with the target base station.

[0098] If Release 18 LTM is limited to intra-CU (centralized unit) scenarios, the UE does not need to perform a key update when performing consecutive handovers based on the LTM configuration. To further expand the scenarios supported by LTM, inter-CU LTM can be supported. Unlike intra-CU LTM, inter-CU LTM involves a change in the Packet Data Convergence Protocol (PDCP) anchor, and therefore requires a key update procedure.

[0099] Prior to the introduction of Release 18 LTM, traditional handover processes did not support continuity. If the handover process involved a key update, the network could include the key update information directly in the handover command. To reduce the signaling overhead associated with repeatedly providing handover configurations, Release 18 LTM supports continuity. This means that after executing LTM once, the UE can retain the LTM candidate configuration for subsequent cell handovers. Similarly, the design of inter-CU LTM can also consider LTM process continuity.

[0100] However, the related secure key update mechanism can only support a one-shot key update process. The embodiments of this application provide one or more solutions that can perform continuous key updates during the inter-CULTM process. The relevant content of LTM is as follows:

[0101] Specify support for inter-CU Layer 2 Mobility (LTM) [RAN2, RAN3]

[0102] Priority is given to scenarios where the CU serves as the master node (MN) in non-DC configurations.

[0103] As secondary priority, support the case when NR-DC is configured and CU is acting as SN and MCG is unchanged.

[0104] As secondary priority, support the case when NR-DC is configured, CU is acting as MN and SCG is unchanged or SCG is released.

[0105] Note: The case that LTM is configured in both MCG and SCG is excluded.

[0106] Specify support for subsequent LTM mobility procedures aiming to avoid RRC configuration between cell switches as per Rel-18 LTM.

[0107] Coordination with SA3 needed with respect to security key handling.

[0108] Note: Rel.18 intra-CU LTM procedure is considered as baseline for adding inter-CU support.

[0109] FIG5 is a schematic flow chart of a key update method 500 according to an embodiment of the present application. The method can optionally be applied to the system shown in FIG1 , but is not limited thereto. The method includes at least part of the following contents.

[0110] S510: When a key update is required, the terminal device determines a key derivation method.

[0111] In one embodiment, the terminal device needs to perform a key update during an inter-CU layer 1 or layer 2 triggered mobility LTM process between central units. In an embodiment of the present application, if the terminal device determines that a key update needs to be performed during a continuous handover process, such as an inter-CU LTM process, a key update method can be determined in various ways, such as a key derivation method.

[0112] In one embodiment, the method further includes: the terminal device receiving a first indication, where the first indication is used to indicate whether the terminal device needs to perform a key update.

[0113] In one embodiment, the first indication is in the LTM cell handover command. For example, the LTM cell handover MAC CE (which may carry the LTM cell handover command) sent by the source network device, such as the S-gNB, to the UE may carry the first indication, indicating whether the UE needs to perform a key update. Optionally, the first indication may also indicate a key update method.

[0114] In one embodiment, the method further includes: the terminal device receives a first RRC message, and the first RRC message includes configuration information of one or more candidate cells. For example, the first RRC message may be an RRC message. The terminal device may receive an RRC message carrying one or more LTM candidate cell configurations from a source network device, such as an S-gNB. If the LTM cell switching MAC CE sent by the S-gNB indicates that the UE needs to perform a key update, the UE may initiate an LTM process to the target cell and / or T-gNB based on the candidate cell configuration. If the first RRC message includes only configuration information of one candidate cell, the candidate cell may be used as the target cell. If the first RRC message includes configuration information of multiple candidate cells, one of the multiple candidate cells may be used as the target cell.

[0115] In one embodiment, the configuration information of the one or more candidate cells includes group information associated with the one or more candidate cells. For example, a CU may include multiple candidate cells, and the configuration information of the candidate cells includes information such as the identifier of the CU associated with the candidate cells.

[0116] In one embodiment, when the group information associated with the target cell and / or the group information associated with the one or more candidate cells is different from the group information associated with the current serving cell of the terminal device, the terminal device determines that a key update needs to be performed or the current LTM process is an inter-CU LTM process. For example, if the identifiers of the CUs associated with the candidate cells in the RRC message are different from the identifiers of the CUs associated with the UE's current serving cell, the UE may determine that the current group needs to perform a key update, or determine that the current LTM process is an inter-CU LTM process. For another example, if the identifier of the CU associated with the target cell indicated in the LTM cell switching MAC CE is different from the identifier of the CU associated with the UE's current serving cell, the UE may determine that the current group needs to perform a key update, or determine that the current LTM process is an inter-CU LTM process.

[0117] In one embodiment, the method further includes: the terminal device receiving a second indication, the second indication being used to indicate a key derivation method, the key derivation method including horizontal key derivation or vertical key derivation. In this embodiment of the present application, the terminal device may receive the second indication from a source network device, such as an S-gNB. The terminal device may also receive the second indication from a T-gNB (new S-gNB) after completing LTM and successfully accessing a target network device, such as a T-gNB.

[0118] In one embodiment, the second indication is used in the LTM cell handover command to indicate the key derivation method of the current inter-CU LTM process of the terminal device. For example, the LTM cell handover MAC CE includes a first indication and a second indication, the first indication is used to indicate that the current inter-CU LTM process of the UE needs to perform a key update, and the second indication is used to indicate whether the key derivation method of the current inter-CU LTM process of the UE is vertical derivation or horizontal derivation.

[0119] In one embodiment, the second indication is included in the first RRC message or MAC CE to indicate a key derivation method for the next inter-CU LTM process. For example, the second indication may be included in an RRC message sent by the T-gNB (new S-gNB (e.g., S-gNB-DU)) to the UE to indicate a key derivation method for the next inter-CU LTM process.

[0120] In one embodiment, the method further includes: the terminal device performs horizontal key derivation based on the source network device key (initial key), the physical cell identifier (PCI) of the target cell, and the downlink frequency of the target cell. For example, the UE stores the key K generated by the S-gNB. gNB , the horizontal key derivation method (method 1) can include: according to K gNB , the PCI of the target cell and the downlink frequency of the target cell generate the update key K NG-RAN* .

[0121] In one embodiment, the method further includes: the terminal device performs vertical key derivation based on the next hop key (NH), the PCI of the target cell and the downlink frequency of the target cell, wherein the NH is based on the core network key (K AMF For example, the UE obtains NH, and the vertical key derivation method (method 2) may include: generating an update key K according to NH, the PCI of the target cell, and the downlink frequency of the target cell. NG-RAN* .

[0122] In one embodiment, the method further includes: the terminal device updating and storing a next hop link count (NCC). For example, after performing vertical key derivation, the UE may store a new NCC after adding 1 to the NCC.

[0123] In one embodiment, the default key derivation method of the terminal device includes one of the following: horizontal key derivation, vertical key derivation, and the key derivation method indicated by the second indication. For example, if the UE defaults to horizontal key derivation, after receiving the first RRC message, you can refer to the example of the above-mentioned method 1 to perform a key update. If the UE defaults to vertical key derivation, after receiving the first RRC message, you can refer to the example of the above-mentioned method 2 to perform a key update. If the UE defaults to the key derivation method indicated by the second indication (method 3), and the second indication specifically indicates horizontal key derivation, after receiving the second indication, you can refer to the example of the above-mentioned method 1 to perform a key update. If the UE defaults to the key derivation method indicated by the second indication (method 3), and the second indication specifically indicates vertical key derivation, after receiving the second indication, you can refer to the example of the above-mentioned method 2 to perform a key update.

[0124] In one embodiment, the method further includes: the terminal device receives a third indication, and the third indication is used to indicate that the key derivation method of the terminal device includes at least one of the following: horizontal key derivation, vertical key derivation, and the key derivation method indicated by the second indication. In an embodiment of the present application, the third indication may use one or more bits to indicate the key derivation method used by the UE. For example, a bit of the third indication takes a value of 1 to indicate horizontal key derivation (see method 1), a value of 0 to indicate vertical key derivation (see method 2), and a default indication of the key derivation method indicated by the second indication (see method 3). For another example, the two bits of the third indication take a value of 01 to indicate horizontal key derivation (see method 1), a value of 10 to indicate vertical key derivation (see method 2), and a value of 11 to indicate the key derivation method indicated by the second indication (see method 3).

[0125] In one embodiment, the third indication is in a first RRC message used to configure the candidate cell. For example, the RRC message received by the UE carries the third indication and configuration information of one or more candidate cells.

[0126] In one embodiment, the key derivation method of the inter-CU LTM process indicated by the third indication includes the key derivation method of the initial inter-CU LTM process and / or the key derivation method of the subsequent inter-CU LTM process. In the embodiment of the present disclosure, the third indication may indicate a key derivation process of multiple stages. If the third indication indicates the key derivation method of the initial inter-CU LTM process (initial stage) and the subsequent inter-CU LTM process (subsequent stage). For example, the UE may perform at least one inter-CU LTM process based on the first RRC message. The first LTM process performed based on the first RRC message is the initial inter-CU LTM process, and the inter-CU LTM process other than the first one (for example, the second or third time) performed based on the first RRC message is the subsequent inter-CU LTM process. The key derivation methods of different stages may be the same or different. For example, the key derivation method of the initial stage is horizontal key derivation (see method 1), and the key derivation method of the subsequent stage is vertical key derivation (see method 2). For another example, the key derivation method in the initial stage is vertical key derivation (see method 2), and the key derivation method in the subsequent stage is the key derivation method indicated by the second indication (see method 3).

[0127] In one embodiment, the key derivation method of the inter-CU LTM process indicated by the third indication includes the key derivation method of the initial inter-CU LTM process, and the key derivation method of the subsequent inter-CU LTM process is the default. In the embodiment of the present disclosure, the third indication can indicate the key derivation process of one stage, and the key derivation methods of other stages can be the default.

[0128] In one embodiment, the method further includes: the terminal device receiving a third indication and a fourth indication, wherein the key derivation method for the inter-CU LTM process indicated by the third indication includes the key derivation method for the initial inter-CU LTM process, and the key derivation method for the inter-CU LTM process indicated by the fourth indication includes the key derivation method for subsequent inter-CU LTM processes. In the embodiment of the present disclosure, different indication information can be used to indicate key derivation processes at different stages. For example, the third indication and the fourth indication indicate the key derivation methods for the initial stage and the subsequent stage, respectively. The third indication and the fourth indication can be carried in the same message or in different messages.

[0129] In one embodiment, the granularity of the third indication is a cell group, and one cell group corresponds to one key derivation method. In an embodiment of the present application, a CU can be associated with multiple candidate cells, and a candidate cell can belong to one CU. The third indication can indicate the key derivation methods of multiple candidate cells (e.g., MCG) under one CU.

[0130] FIG6 is a schematic flow chart of a key update method 600 according to an embodiment of the present application. The method can optionally be applied to the system shown in FIG1 , but is not limited thereto. The method includes at least part of the following contents.

[0131] S610. The first network device sends one or more first messages, each of which includes key information associated with one or more candidate cells. In this embodiment of the present application, the first network device may send one or more first messages to one or more terminal devices. The first network device may send one or more first messages to one or more second network devices. The first network device may be a source network device. The second network device may be a candidate network device. For example, the S-gNB sends the first message to UE1. For another example, the S-gNB sends the first message to UE1 and UE2 respectively. For another example, the S-gNB sends the first message to C-gNB1 and C-gNB2 respectively. If the first message includes key information associated with a candidate cell, the UE may use the key information associated with the candidate cell for key update. If the first message includes key information associated with multiple candidate cells, the UE may determine a target cell from the multiple candidate cells and use the key information associated with the target cell for key update.

[0132] In one embodiment, the key information associated with the one or more candidate cells includes at least one of the following:

[0133] An update key for the one or more candidate cells, where the update key is generated based on a source network device key, a PCI of the candidate cell, and a downlink frequency of the candidate cell, or the update key is generated based on a NH, a PCI of the candidate cell, and a downlink frequency of the candidate cell;

[0134] NCC.

[0135] In the embodiment of the present application, the terminal device can use the source network device key, such as the initial key K gNB , the PCI of the candidate cell and the downlink frequency of the candidate cell, perform horizontal key derivation to generate the update key K of the candidate cell gNB* The terminal device can perform horizontal key derivation based on the NH, the PCI of the candidate cell and the downlink frequency of the candidate cell to generate the update key K of the candidate cell. gNB* Optionally, the key information associated with the candidate cell in the first message may also include an NCC.

[0136] In one embodiment, the method further includes: the first network device sending a first RRC message, where the first RRC message includes configuration information of one or more candidate cells. For example, the first RRC message sent by the second network device to the terminal device may be an RRC message. For details, see the relevant description in the embodiment of the key update method performed by the terminal device.

[0137] For a specific example of the first network device executing the method 600 of this embodiment, reference may be made to the relevant description of the first network device in the above method 500 , which will not be repeated here for the sake of brevity.

[0138] FIG7 is a schematic flow chart of a key update method 700 according to an embodiment of the present application. The method can optionally be applied to the system shown in FIG1 , but is not limited thereto. The method includes at least part of the following contents.

[0139] S710: One or more second network devices receive a first message, where the first message includes key information associated with one or more candidate cells. In an embodiment of the present application, one or more second network devices, such as candidate network devices, may receive the first message from the first network device.

[0140] In one embodiment, the method further includes: the one or more second network devices storing the received key information associated with the one or more candidate cells.

[0141] In one embodiment, the method further includes: the one or more second network devices deleting previously stored key information associated with the candidate cell. For example, if a candidate network device receives a new NCC, it may delete its currently stored NCC and store the new NCC. For another example, if a candidate network device receives an updated key for at least one candidate cell, it may delete the currently stored key associated with the candidate cell and store the received updated key for the candidate cell.

[0142] For a specific example of the second network device executing the method 700 of this embodiment, reference may be made to the relevant descriptions of the second network device in the above methods 500 and 600 , which will not be repeated here for the sake of brevity.

[0143] FIG8 is a schematic flow chart of a key update method 800 according to an embodiment of the present application. The method can optionally be applied to the system shown in FIG1 , but is not limited thereto. The method includes at least part of the following contents.

[0144] S810: When the terminal device successfully accesses the third network device after the handover, the third network device performs a key update based on the new key information from the fourth network device. In this embodiment of the present application, after the LTM process is completed, the terminal device can successfully access the third network device, such as the target network device. The third network device can perform a key update based on the new key information.

[0145] In one embodiment, the method further includes: the third network device sending one or more first messages, wherein the first messages include key information associated with one or more candidate cells. In this embodiment of the present application, after the terminal device completes the LTM process and successfully connects to the third network device, the role of the third network device can be changed from a target network device to a source network device. The third network device can then continue to execute S510 and send the first message to one or more terminal devices and / or candidate network devices, thereby continuously updating the key during the continuous handover process.

[0146] In one embodiment, the new key information further includes a new NH and a new NCC, and the key information associated with the one or more candidate cells includes at least one of the following:

[0147] an update key of the one or more candidate cells;

[0148] The new NCC.

[0149] In one embodiment, the method further comprises:

[0150] The third network device generates an update key of the source network device based on the new NH;

[0151] The third network device generates an update key for the candidate cell based on the update key of the source network device, the PCI of the candidate cell, and the downlink frequency of the candidate cell.

[0152] In an embodiment of the present application, after the UE successfully accesses, the third network device, such as T-gNB, can perform a path switching (PATH SWITCH) process with the fourth network device, such as AMF. In this process, AMF can provide new key information such as NH and NCC pair ({NH, NCC} pair) to T-gNB. Based on the new {NH, NCC} pair, T-gNB can perform actions related to key update. For example, method 1 (horizontal key derivation): T-gNB generates a new key KgNB* based on NH, and then generates an update key K for each candidate cell based on KgNB* and the PCI and downlink frequency of each candidate cell. NG-RAN* .

[0153] In one embodiment, the method further includes: the third network device sends a second RRC message to the terminal device, the second RRC message is used to instruct the terminal device to perform a key update, and the second RRC message includes the new NCC. For example, after the third network device completes the key update using the above-mentioned method 1, it can send an RRC message to the UE, and the RRC message can instruct the terminal device to also perform a key update using method 1, and can carry a new NCC obtained from the AMF. After the UE performs a key update using method 1 according to the RRC message, it can add 1 to the NCC and save it. The examples of method 2 and method 3 are similar and will not be repeated.

[0154] In one embodiment, the new key information includes a new NH, and the method further includes: the third network device generates an update key for the candidate cell based on the new NH, the PCI of the candidate cell, and the downlink frequency of the candidate cell. For example, mode 2 (vertical key derivation): the T-gNB generates an update key K for each candidate cell based on the NH and the PCI and downlink frequency of each candidate cell. NG-RAN* .

[0155] In one embodiment, the method further includes: the third network device sending a second indication to the terminal device, where the second indication is used to indicate a key derivation method, where the key derivation method includes horizontal key derivation or vertical key derivation. For example, in Method 3 (Indication), the T-gNB (new S-gNB) determines to perform at least one of Method 1 or Method 2 based on the implementation, and informs the UE whether horizontal derivation or vertical derivation is required for the next inter-CU LTM process.

[0156] In one embodiment, the second indication is in the LTM cell switching command, and is used to indicate the key derivation method of the current inter-CU LTM process of the terminal device.

[0157] In one implementation, the second indication is in an RRC message or a MAC CE, and is used to indicate a key derivation method for the next inter-CU LTM process.

[0158] In one embodiment, the method further includes: the central unit of the third network device sending a second message to the data unit of the third network device, where the second message is used to indicate a key derivation method for the next inter-CU LTM process. For example, the CU of the T-gNB (new S-gNB) may send the second message to the DU of the T-gNB (new S-gNB) to indicate a key derivation method (e.g., method 1, method 2, or method 3) for the next inter-CU LTM process of the UE. The DU may send indication information to the UE to indicate a key derivation method for the next inter-CU LTM process of the UE.

[0159] In one embodiment, the second message includes group information corresponding to the candidate cell, which is used to determine whether the LTM process is an inter-CU LTM process or an intra-CU LTM process between central units. For example, the DU can send group information corresponding to a candidate cell (or multiple candidate cells) to the UE. If the group information corresponding to the candidate cell is the same as the UE's current serving cell, it can be determined as an intra-CU LTM process. If the group information corresponding to the candidate cell is different from the UE's current serving cell, it can be determined as an inter-CU LTM process.

[0160] For a specific example of the third network device executing the method 800 of this embodiment, reference may be made to the relevant descriptions of the third network device in the above methods 500 , 600 , and 700 , which will not be repeated here for the sake of brevity.

[0161] In one example, the terminal device may be a UE, the first network device may be a source network device, the second network device may be a candidate network device, the third network device may be a target network device, and the fourth network device may be an AMF.

[0162] For example, the source network device may include a source base station (Source gNB, S-gNB), which may be the gNB to which the UE currently accesses the cell; the candidate network device may include a candidate base station (Candidate gNB, C-gNB), which may be the gNB to which the LTM candidate cell belongs; the target network device may include a target base station (Target gNB, T-gNB), which may be the gNB to which the target cell performing the LTM process belongs.

[0163] The key update method of the embodiment of the present application may include a secure key update method for a continuous MCG replacement process, which may specifically include the following contents:

[0164] (1) During the LTM preparation phase, the S-gNB can generate a key K for each candidate cell. NG-RAN* .

[0165] (2) When executing inter-CU LTM, the UE performs horizontal key derivation or vertical key derivation, which may include at least one of the following methods:

[0166] Do horizontal key derivation every time;

[0167] Do vertical key derivation every time;

[0168] Determine the key derivation method based on dynamic network instructions.

[0169] (3) After the UE successfully accesses the T-gNB, the T-gNB (new S-gNB) can update the K for the next inter-CU LTM for each candidate cell. NG-RAN* .

[0170] Example 1:

[0171] 1. During the LTM preparation phase, the S-gNB sends a first message to at least one C-gNB. The first message includes the ID of at least one candidate cell and key information associated with the candidate cell. The ID can be at least one of the candidate cell ID, PCI, and CGI. The key information associated with the candidate cell can include at least one of the following:

[0172] (1)K NG-RAN* ; Among them, S-gNB is based on K gNB / NH and candidate cell PCI and DL frequency generate K NG-RAN* The S-gNB determines the key derivation method based on whether the NH and NCC pair is currently unused (unused{NH, NCC} pair).

[0173] (2) NCC;

[0174] In one implementation (Option 1), the first message contains only the key information of one candidate cell. In another implementation (Option 2), the first message may contain the key information of at least one candidate cell, for example, the key information of all candidate cells under the C-gNB, such as the candidate cell ID and K associated with each candidate cell as shown in Figure 9. NG-RAN* .

[0175] 2. The S-gNB sends a first RRC message, such as an RRC Reconfiguration message, to the UE. The first RRC message includes at least one LTM candidate cell configuration. The UE sends an L1 measurement report to the S-gNB. The S-gNB sends an LTM Cell Switch MAC CE to the UE. Based on the candidate cell configuration and / or the LTM Cell Switch MAC CE sent by the S-gNB, the UE initiates an LTM procedure with the target cell and / or T-gNB. The LTM Cell Switch MAC CE may carry a first indication indicating whether the UE needs to perform a key update and / or the key update method.

[0176] 3. LTM execution and completion. For inter-CU LTM, the T-gNB (e.g., C-gNB#1) performs a path switch procedure with the AMF after the UE successfully accesses the LTM. During this procedure, the T-gNB sends a path switch request to the AMF. The AMF returns a path switch request acknowledgment to the T-gNB, providing a new {NH, NCC} pair. Based on the new {NH, NCC} pair, the T-gNB's behavior may include at least one of the following:

[0177] Method 1: T-gNB generates a new key K based on NH gNB* (Key update), and at the same time send a second RRC message to the UE, such as the RRC reconfiguration message for key update (including NCC) in Figure 10, to instruct the UE to perform key update. The second RRC message contains the new NCC. After completing the key update, the T-gNB (new S-gNB) performs the behavior in step 1 again (sending the first message to the C-gNB). In this way, the K corresponding to each candidate cell is NG-RAN* Based on K gNB* +PCI+DL frequency generation. For example, a new K is derived for each candidate cell NG-RAN* (Depends on horizontal derivation) NG-RAN* for each candidate cell (rely on horizontal derivation). Correspondingly, when the UE performs inter-CU LTM, it performs horizontal derivation (horizontal key derivation) by default. Method 1 is shown in Figure 10 below.

[0178] Method 2: T-gNB (new S-gNB) performs the behavior in step 1; in this method, the K corresponding to each candidate cell NG-RAN* Based on NH+PCI+DL frequency generation. For example, a new K is derived for each candidate cell. NG-RAN* (Depends on vertical derivatives) NG-RAN* for each candidate cell (rely on vertical derivation)). Correspondingly, when the UE performs inter-CU LTM, it performs vertical derivation (vertical key derivation) by default, as shown in Figure 11.

[0179] Method 3: The T-gNB determines to perform at least one of Method 1 or Method 2 based on implementation. In this method, the T-gNB (the new S-gNB) needs to inform the UE whether the next inter-CU LTM process should perform horizontal or vertical derivation. The indication method includes: sending a second indication to the UE.

[0180] Example 1: The second indication is included in the LTM cell switch command and is used to instruct the UE on the key derivation method for the current inter-CU LTM process.

[0181] In Example 2, the second indication is in an RRC message or MAC CE, indicating the key derivation method for the next inter-CU LTM process. (Unlike Example 1, the second indication in Example 2 can be sent before the next LTM is triggered.)

[0182] 4. Referring to Figures 10 and 11, after receiving the first message, the C-gNB can replace the K associated with each candidate cell. NG-RAN* For example, the C-gNB deletes the currently stored candidate cell key information and stores the most recently received candidate cell key information.

[0183] Example 2: Interaction between CU and DU (for example, can be combined with method 3 in Example 1)

[0184] The S-gNB-CU sends a second message to the S-gNB-DU. The second message indicates the key derivation method for the next inter-CU LTM process. Furthermore, the second message may include group information corresponding to the candidate cells, which the DU uses to determine whether the LTM process is inter-CU or intra-CU.

[0185] The S-gNB in ​​this embodiment may include a new S-gNB derived from a T-gNB. For example, after the S-gNB-CU performs vertical derivation or horizontal derivation, it may send a second message to the S-gNB-DU. The S-gNB-DU may send a second indication to the UE based on the key derivation method for the next inter-CU LTM process indicated in the second message, informing the UE whether horizontal derivation or vertical derivation is to be performed for the next inter-CU LTM process.

[0186] Example 3: UE-side behavior

[0187] Step 1. The UE receives a first RRC message containing at least one LTM candidate cell configuration. Based on the LTM Cell switch MAC CE or the evaluation results of the candidate cell execution conditions, the UE determines the target cell and initiates the LTM process to the target cell, including determining whether the current LTM process is inter-CU LTM or whether a key update is required. The determination method includes:

[0188] (1) Based on a first indication, the first indication is included in the LTM Cell switch MAC CE and is used to indicate whether the UE needs to perform a key update and / or a key update method. For example, if the LTM Cell switch MAC CE includes the first indication, the UE considers that the current LTM process is an inter-CU LTM or a key update is required. For example, if the first indication corresponds to the first value, the UE considers that the current LTM process is an inter-CU LTM or a key update is required.

[0189] (2) Based on the group information associated with the candidate cell and / or the current serving cell. For example, if the group ID associated with the candidate cell is different from the group ID associated with the current serving cell, the UE considers the current LTM process to be inter-CU LTM or requires a key update.

[0190] Step 2. Based on step 1, if the UE determines that a key update is required for the current LTM process, the UE's behavior further includes at least one of the following:

[0191] Behavior 1: Based on K gNB , target cell PCI and target cell downlink frequency (DL frequency) to perform horizontal key derivation.

[0192] Action 2: Determine NH based on KAMF and perform vertical key derivation based on NH, target cell PCI, and target cell DL frequency. Optionally, the UE increments the current NCC value by 1 and stores it.

[0193] Action 3: Determine the key derivation method based on the second indication. The second indication is included in the LTM Cell switch MAC CE, or the second indication is included in the RRC message / MAC CE.

[0194] For Behavior 1, Behavior 2, and Behavior 3, the UE's behavior also includes at least one of the following:

[0195] (1) By default, one of Behavior 1, Behavior 2, or Behavior 3 is executed.

[0196] (2) Based on the third indication, the UE determines that the key derivation rule is behavior 1, behavior 2, or behavior 3. For example, the third indication is included in the RRC message for configuring the LTM candidate cell.

[0197] Furthermore, the purpose of the third indication may include at least one of the following:

[0198] (2-1) The third indication is used to indicate the key derivation method (also called key derivation rule) of each inter-CU LTM process, including the initial method (initial) and the subsequent method (subsequent).

[0199] (2-2) The third indication is used to indicate the key derivation method of the initial inter-CU LTM process. The key derivation rule of the subsequent inter-CU LTM process is the default behavior.

[0200] (2-3) The third indication is used to indicate the key derivation method for the subsequent inter-CU LTM process. Furthermore, the fourth indication further indicates the key derivation method for the initial inter-CU LTM process. (Because the S-gNB cannot determine whether it has an unused {NH, NCC} pair when initiating LTM preparation, the key derivation method for the initial inter-CU LTM process may not be aligned with that for the subsequent process.)

[0201] (2-4) Based on (2-3), the granularity of the third indication can be cell groups, that is, each cell group corresponds to a key derivation rule. When the UE switches from the current cell group to another cell group, the key derivation rule is determined based on the third indication associated with the current cell group. (Since each cell group essentially corresponds to a CU, different CUs may have their own preferred methods.)

[0202] According to the solution provided in the embodiment of the present application, the key update problem during the continuous MCG replacement process is solved.

[0203] FIG12 is a schematic block diagram of a terminal device 1200 according to an embodiment of the present application. The terminal device 1200 may include:

[0204] The processing unit 1201 is configured to determine a key derivation method when a key update is required.

[0205] In one embodiment, the terminal device needs to perform a key update during an inter-CU layer 1 or layer 2 triggered mobility LTM process.

[0206] In one embodiment, the terminal device further includes:

[0207] The first receiving unit 1202 is configured to receive a first indication, where the first indication is used to indicate whether the terminal device needs to perform a key update.

[0208] In one embodiment, the first indication is in an LTM cell handover command.

[0209] In one embodiment, the terminal device further includes:

[0210] The second receiving unit 1203 is configured to receive a first RRC message, where the first RRC message includes configuration information of one or more candidate cells.

[0211] In one embodiment, the configuration information of the one or more candidate cells includes group information associated with the one or more candidate cells;

[0212] When the group information associated with the target cell and / or the group information associated with the one or more candidate cells is different from the group information associated with the current serving cell of the terminal device, the terminal device determines that a key update needs to be performed or the current LTM process is an inter-CU LTM process.

[0213] In one embodiment, the terminal device further includes:

[0214] The third receiving unit 1204 is configured to receive a second indication, where the second indication is used to indicate a key derivation method, where the key derivation method includes horizontal key derivation or vertical key derivation.

[0215] In one embodiment, the second indication is in the LTM cell handover command, and is used to indicate a key derivation method for the current inter-CU LTM process of the terminal device; or

[0216] The second indication is in the first RRC message or MAC CE and is used to indicate a key derivation method for the next inter-CU LTM process.

[0217] In one embodiment, the processing unit is further configured to perform horizontal key derivation based on the source network device key, the physical cell identifier PCI of the target cell, and the downlink frequency of the target cell.

[0218] In one embodiment, the processing unit 1201 is further configured to perform vertical key derivation based on the NH, the PCI of the target cell, and the downlink frequency of the target cell, where the NH is determined based on a core network key.

[0219] In one implementation, the processing unit 1201 is further configured to update and store the NCC.

[0220] In one embodiment, the default key derivation method of the terminal device includes one of the following: horizontal key derivation, vertical key derivation, and a key derivation method indicated by the second indication.

[0221] In one embodiment, the terminal device further includes:

[0222] The fourth receiving unit 1205 is used to receive a third indication, where the third indication is used to indicate that the key derivation method of the terminal device includes at least one of the following: horizontal key derivation, vertical key derivation, and the key derivation method indicated by the second indication.

[0223] In one implementation, the third indication is in a first RRC message used to configure the candidate cell.

[0224] In one embodiment, the key derivation method of the inter-CU LTM process indicated by the third indication includes the key derivation method of the initial inter-CU LTM process and / or the key derivation method of the subsequent inter-CU LTM process.

[0225] In one embodiment, the key derivation mode of the inter-CU LTM process indicated by the third indication includes the key derivation mode of the initial inter-CU LTM process, and the key derivation mode of subsequent inter-CU LTM processes is a default.

[0226] In one embodiment, the terminal device further includes:

[0227] The fifth receiving unit 1206 is used to receive a third indication and a fourth indication, where the key derivation method of the inter-CU LTM process indicated by the third indication includes the key derivation method of the initial inter-CU LTM process, and the key derivation method of the inter-CU LTM process indicated by the fourth indication includes the key derivation method of the subsequent inter-CULTM process.

[0228] In one embodiment, the granularity of the third indication is a cell group, and one cell group corresponds to one key derivation method.

[0229] The terminal device 1200 of the embodiment of the present application can implement the corresponding functions of the terminal device in the aforementioned method embodiment. The processes, functions, implementation methods and beneficial effects corresponding to the various modules (sub-modules, units or components, etc.) in the terminal device 1200 can be found in the corresponding descriptions in the above-mentioned method embodiments, and will not be repeated here. It should be noted that the functions described in the various modules (sub-modules, units or components, etc.) in the terminal device 1200 of the embodiment of the application can be implemented by different modules (sub-modules, units or components, etc.) or by the same module (sub-module, unit or component, etc.).

[0230] FIG13 is a schematic block diagram of a first network device 1300 according to an embodiment of the present application. The first network device 1300 may include:

[0231] The sending unit 1301 is configured to send one or more first messages, where the first messages include key information associated with one or more candidate cells.

[0232] In one embodiment, the key information associated with the one or more candidate cells includes at least one of the following:

[0233] An update key for the one or more candidate cells, where the update key is generated based on a source network device key, a PCI of the candidate cell, and a downlink frequency of the candidate cell, or the update key is generated based on a NH, a PCI of the candidate cell, and a downlink frequency of the candidate cell;

[0234] NCC.

[0235] In one implementation, the sending unit 1301 is further configured to send a first RRC message, where the first RRC message includes configuration information of one or more candidate cells.

[0236] The first network device 1300 of the embodiment of the present application can implement the corresponding functions of the first network device in the aforementioned method embodiment. The processes, functions, implementation methods and beneficial effects corresponding to each module (sub-module, unit or component, etc.) in the first network device 1300 can be found in the corresponding description in the above method embodiment, and will not be repeated here. It should be noted that the functions described in the various modules (sub-module, unit or component, etc.) in the first network device 1300 of the embodiment of the application can be implemented by different modules (sub-module, unit or component, etc.) or by the same module (sub-module, unit or component, etc.).

[0237] FIG14 is a schematic block diagram of a second network device 1400 according to an embodiment of the present application. The second network device 1400 may include:

[0238] The receiving unit 1401 is configured to receive a first message, where the first message includes key information associated with one or more candidate cells.

[0239] In one embodiment, the second network device further includes:

[0240] The processing unit 1402 is configured to store the received key information associated with the one or more candidate cells.

[0241] In one implementation, the processing unit 1402 is further configured to delete previously saved key information associated with the candidate cell.

[0242] The second network device 1400 of the embodiment of the present application can implement the corresponding functions of the second network device in the aforementioned method embodiment. The corresponding processes, functions, implementation methods and beneficial effects of each module (sub-module, unit or component, etc.) in the second network device 1400 can be found in the corresponding description in the above method embodiment, and will not be repeated here. It should be noted that the functions described in the various modules (sub-module, unit or component, etc.) in the second network device 1400 of the embodiment of the application can be implemented by different modules (sub-module, unit or component, etc.) or by the same module (sub-module, unit or component, etc.).

[0243] FIG15 is a schematic block diagram of a third network device 1500 according to an embodiment of the present application. The third network device 1500 may include:

[0244] The processing unit 1501 is configured to perform a key update based on new key information when the terminal device successfully accesses the network after switching, where the new key information comes from the fourth network device.

[0245] In one embodiment, the third network device further includes:

[0246] The first sending unit 1502 is configured to send one or more first messages, where the first messages include key information associated with one or more candidate cells.

[0247] In one embodiment, the new key information further includes a new NH and a new NCC, and the key information associated with the one or more candidate cells includes at least one of the following:

[0248] an update key of the one or more candidate cells;

[0249] The new NCC.

[0250] In one embodiment, the processing unit 1501 is further configured to generate an update key for the source network device based on the new NH; and generate an update key for the candidate cell based on the update key of the source network device, the PCI of the candidate cell, and the downlink frequency of the candidate cell.

[0251] In one embodiment, the third network device further includes:

[0252] The second sending unit 1503 is configured to send a second RRC message to the terminal device, where the second RRC message is used to instruct the terminal device to perform a key update, and the second RRC message includes the new NCC.

[0253] In one embodiment, the new key information includes a new NH, and the processing unit is further configured to generate an update key for the candidate cell based on the new NH, the PCI of the candidate cell, and the downlink frequency of the candidate cell.

[0254] In one embodiment, the third network device further includes:

[0255] The third sending unit 1504 is configured to send a second indication to the terminal device, where the second indication is used to indicate a key derivation method, where the key derivation method includes horizontal key derivation or vertical key derivation.

[0256] In one embodiment, the second indication is in the LTM cell handover command, and is used to indicate a key derivation method for the current inter-CU LTM process of the terminal device; or

[0257] The second indication is in the RRC message or MAC CE and is used to indicate the key derivation method for the next inter-CU LTM process.

[0258] In one embodiment, the third network device further includes:

[0259] The fourth sending unit 1505, in the central unit of the third network device, is further configured to send a second message to the data unit of the third network device, where the second message is used to indicate a key derivation method for the next inter-CU LTM process.

[0260] In one implementation, the second message includes group information corresponding to the candidate cells, which is used to determine whether the LTM process is an inter-CU LTM process or an intra-CU LTM process between central units.

[0261] The third network device 1500 of the embodiment of the present application can implement the corresponding functions of the third network device in the aforementioned method embodiment. The corresponding processes, functions, implementation methods and beneficial effects of each module (sub-module, unit or component, etc.) in the third network device 1500 can be found in the corresponding description in the above method embodiment, and will not be repeated here. It should be noted that the functions described in each module (sub-module, unit or component, etc.) in the third network device 1500 of the embodiment of the application can be implemented by different modules (sub-modules, units or components, etc.) or by the same module (sub-module, unit or component, etc.).

[0262] Figure 16 is a schematic structural diagram of a communication device 1600 according to an embodiment of the present application. The communication device 1600 includes a processor 1610, which can call and execute a computer program from a memory to enable the communication device 1600 to implement the method in the embodiment of the present application.

[0263] In one embodiment, the communication device 1600 may further include a memory 1620. The processor 1610 may call and execute a computer program from the memory 1620 to enable the communication device 1600 to implement the method in the embodiment of the present application.

[0264] The memory 1620 may be a separate device independent of the processor 1610 , or may be integrated into the processor 1610 .

[0265] In one embodiment, the communication device 1600 may further include a transceiver 1630 , and the processor 1610 may control the transceiver 1630 to communicate with other devices. Specifically, the transceiver 1630 may send information or data to other devices, or receive information or data sent by other devices.

[0266] The transceiver 1630 may include a transmitter and a receiver. The transceiver 1630 may further include an antenna, and the number of antennas may be one or more.

[0267] In one embodiment, the communication device 1600 may be a network device of an embodiment of the present application, and the communication device 1600 may implement the corresponding processes implemented by the network device in each method of the embodiment of the present application. For the sake of brevity, they will not be repeated here.

[0268] In one embodiment, the communication device 1600 may be a terminal device of an embodiment of the present application, and the communication device 1600 may implement the corresponding processes implemented by the terminal device in each method of the embodiment of the present application. For the sake of brevity, they will not be repeated here.

[0269] 17 is a schematic structural diagram of a chip 1700 according to an embodiment of the present application. The chip 1700 includes a processor 1710, which can call and execute a computer program from a memory to implement the method according to the embodiment of the present application.

[0270] In one embodiment, the chip 1700 may further include a memory 1720. The processor 1710 may call and execute a computer program from the memory 1720 to implement the method executed by the terminal device or the network device in the embodiment of the present application.

[0271] The memory 1720 may be a separate device independent of the processor 1710 , or may be integrated into the processor 1710 .

[0272] In one embodiment, the chip 1700 may further include an input interface 1730. The processor 1710 may control the input interface 1730 to communicate with other devices or chips, and specifically, may obtain information or data sent by other devices or chips.

[0273] In one embodiment, the chip 1700 may further include an output interface 1740. The processor 1710 may control the output interface 1740 to communicate with other devices or chips, and specifically, may output information or data to other devices or chips.

[0274] In one embodiment, the chip can be applied to the network device in the embodiments of the present application, and the chip can implement the corresponding processes implemented by the network device in each method of the embodiments of the present application. For the sake of brevity, they will not be repeated here.

[0275] In one embodiment, the chip can be applied to the terminal device in the embodiments of the present application, and the chip can implement the corresponding processes implemented by the terminal device in each method of the embodiments of the present application. For the sake of brevity, they will not be repeated here.

[0276] The chips used in the network device and the terminal device may be the same chip or different chips.

[0277] It should be understood that the chip mentioned in the embodiments of the present application can also be called a system-level chip, a system chip, a chip system or a system-on-chip chip, etc.

[0278] The processor mentioned above may be a general-purpose processor, a digital signal processor (DSP), a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), or other programmable logic devices, transistor logic devices, discrete hardware components, etc. The general-purpose processor mentioned above may be a microprocessor or any conventional processor, etc.

[0279] The memory mentioned above may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. The non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM).

[0280] It should be understood that the above-mentioned memories are exemplary but not restrictive. For example, the memories in the embodiments of the present application may also be static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct RAM bus random access memory (DRRAM). In other words, the memories in the embodiments of the present application are intended to include, but are not limited to, these and any other suitable types of memories.

[0281] 18 is a schematic block diagram of a communication system 1800 according to an embodiment of the present application. The communication system 1800 includes a terminal device 1810, a first network device 1820, a second network device 1830, and a third network device 1840.

[0282] The terminal device 1810 is used to determine a key derivation method when a key update is required.

[0283] The first network device 1820 is configured to send one or more first messages, where the first messages include key information associated with one or more candidate cells.

[0284] The second network device 1830 is configured to receive the first message.

[0285] The third network device 1840 is configured to perform key update based on new key information when the terminal device successfully accesses after switching, where the new key information comes from the fourth network device.

[0286] The terminal device 1810 can be used to implement the corresponding functions implemented by the terminal device in the above method, the first network device 1820 can be used to implement the corresponding functions implemented by the source network device in the above method, the second network device 1830 can be used to implement the corresponding functions implemented by the candidate network device in the above method, and the third network device 1840 can be used to implement the corresponding functions implemented by the target network device in the above method. For the sake of brevity, no further details are given here. In the above embodiments, all or part of them can be implemented using software, hardware, firmware, or any combination thereof. When implemented using software, they can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions according to the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more available media. The available medium may be a magnetic medium (e.g., a floppy disk, a hard disk, a magnetic tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive (SSD)).

[0287] It should be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0288] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0289] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any modifications or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present application should be included within the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.

Claims

1. A key update method, comprising: When a key update is required, the terminal device determines the key derivation method.

2. The method according to claim 1, wherein The terminal device needs to perform key update during the inter-CU layer 1 or layer 2 triggered mobility LTM process between central units.

3. The method according to claim 1 or 2, wherein: The method further comprises: The terminal device receives a first indication, where the first indication is used to indicate whether the terminal device needs to perform a key update.

4. The method according to claim 3, wherein: The first indication is in the LTM cell handover command.

5. The method according to any one of claims 1 to 4, wherein The method further comprises: The terminal device receives a first RRC message, which includes configuration information of one or more candidate cells.

6. The method according to claim 5, wherein: The configuration information of the one or more candidate cells includes group information associated with the one or more candidate cells; When the group information associated with the target cell and / or the group information associated with the one or more candidate cells is different from the group information associated with the current serving cell of the terminal device, the terminal device determines that a key update needs to be performed or the current LTM process is an inter-CU LTM process.

7. The method according to any one of claims 1 to 6, wherein The method further comprises: The terminal device receives a second indication, where the second indication is used to indicate a key derivation method, where the key derivation method includes horizontal key derivation or vertical key derivation.

8. The method according to claim 7, wherein: The second indication is in the LTM cell handover command, and is used to indicate a key derivation method for the current inter-CU LTM process of the terminal device; or The second indication is in the first RRC message or MAC CE, and is used to indicate a key derivation method for the next inter-CU LTM process.

9. The method according to any one of claims 1 to 6, wherein The method further comprises: The terminal device performs horizontal key derivation based on the source network device key, the physical cell identifier PCI of the target cell and the downlink frequency of the target cell.

10. The method according to any one of claims 1 to 6, wherein The method further comprises: The terminal device performs vertical key derivation based on the next hop key NH, the PCI of the target cell and the downlink frequency of the target cell, and the NH is determined based on the core network key.

11. The method according to claim 10, wherein: The method further comprises: The terminal device updates and stores the next hop link count NCC.

12. The method according to any one of claims 1 to 11, wherein The default key derivation method of the terminal device includes one of the following: horizontal key derivation, vertical key derivation, and the key derivation method indicated by the second indication.

13. The method according to any one of claims 1 to 11, wherein The method further comprises: The terminal device receives a third indication, where the third indication is used to indicate that a key derivation method of the terminal device includes at least one of the following: horizontal key derivation, vertical key derivation, and the key derivation method indicated by the second indication.

14. The method according to claim 13, wherein The third indication is in a first RRC message used to configure the candidate cell.

15. The method according to claim 13 or 14, wherein: The key derivation method of the inter-CU LTM process indicated by the third indication includes the key derivation method of the initial inter-CU LTM process and / or the key derivation method of the subsequent inter-CU LTM process.

16. The method according to claim 13 or 14, wherein: The key derivation mode of the inter-CU LTM process indicated by the third indication includes the key derivation mode of the initial inter-CU LTM process, and the key derivation mode of subsequent inter-CU LTM processes is a default.

17. The method according to any one of claims 1 to 11, wherein The method further comprises: The terminal device receives a third indication and a fourth indication, where the key derivation method of the inter-CU LTM process indicated by the third indication includes the key derivation method of the initial inter-CU LTM process, and the key derivation method of the inter-CU LTM process indicated by the fourth indication includes the key derivation method of the subsequent inter-CU LTM process.

18. The method according to any one of claims 13 to 17, wherein The granularity of the third indication is cell group, and one cell group corresponds to one key derivation method.

19. A key updating method, comprising: The first network device sends one or more first messages, where the first messages include key information associated with one or more candidate cells.

20. The method according to claim 19, wherein The key information associated with the one or more candidate cells includes at least one of the following: The update key of the one or more candidate cells, the update key is generated based on the source network device key, the PCI of the candidate cell and the downlink frequency of the candidate cell, or the update key is generated based on the NH, the PCI of the candidate cell and the downlink frequency of the candidate cell; NCC.

21. The method according to claim 19 or 20, wherein The method further comprises: The first network device sends a first RRC message, where the first RRC message includes configuration information of one or more candidate cells.

22. A key updating method, comprising: One or more second network devices receive a first message, where the first message includes key information associated with one or more candidate cells.

23. The method according to claim 22, wherein The method further comprises: The one or more second network devices save the received key information associated with the one or more candidate cells.

24. The method according to claim 22 or 23, wherein The method further comprises: The one or more second network devices delete the previously stored key information associated with the candidate cell.

25. A key updating method, comprising: When the terminal device successfully accesses after the handover, the third network device performs a key update based on the new key information, where the new key information comes from the fourth network device.

26. The method according to claim 25, wherein The method further comprises: The third network device sends one or more first messages, where the first messages include key information associated with one or more candidate cells.

27. The method according to claim 25 or 26, wherein The new key information also includes a new NH and a new NCC, and the key information associated with the one or more candidate cells includes at least one of the following: an update key of the one or more candidate cells; The new NCC.

28. The method according to claim 27, wherein The method further comprises: The third network device generates an update key of the source network device based on the new NH; The third network device generates an update key for the candidate cell based on the update key of the source network device, the PCI of the candidate cell, and the downlink frequency of the candidate cell.

29. The method according to claim 27 or 28, wherein The method further comprises: The third network device sends a second RRC message to the terminal device, where the second RRC message is used to instruct the terminal device to perform a key update, and the second RRC message includes the new NCC.

30. The method according to claim 25 or 26, wherein The new key information includes a new NH, and the method further includes: The third network device generates an update key for the candidate cell based on the new NH, the PCI of the candidate cell, and the downlink frequency of the candidate cell.

31. The method according to any one of claims 25 to 30, wherein The method further comprises: The third network device sends a second indication to the terminal device, where the second indication is used to indicate a key derivation method, where the key derivation method includes horizontal key derivation or vertical key derivation.

32. The method according to claim 31, wherein The second indication is in the LTM cell handover command, and is used to indicate a key derivation method for the current inter-CU LTM process of the terminal device; or The second indication is in the RRC message or MAC CE, and is used to indicate the key derivation method for the next inter-CU LTM process.

33. The method according to any one of claims 25 to 32, wherein The method further comprises: The central unit of the third network device sends a second message to the data unit of the third network device, where the second message is used to indicate a key derivation method for a next inter-CU LTM process.

34. The method according to claim 33, wherein The second message includes group information corresponding to the candidate cell, which is used to determine whether the LTM process is an inter-CU LTM process or an intra-CU LTM process between central units.

35. A terminal device comprising: The processing unit is configured to determine a key derivation method when a key update is required.

36. The terminal device according to claim 35, wherein: The terminal device needs to perform key update during the inter-CU layer 1 or layer 2 triggered mobility LTM process between central units.

37. The terminal device according to claim 35 or 36, wherein: The terminal device further includes: The first receiving unit is used to receive a first indication, where the first indication is used to indicate whether the terminal device needs to perform a key update.

38. The terminal device according to claim 37, wherein: The first indication is in the LTM cell handover command.

39. The terminal device according to any one of claims 35 to 38, wherein: The terminal device further includes: The second receiving unit is configured to receive a first RRC message, where the first RRC message includes configuration information of one or more candidate cells.

40. The terminal device according to claim 39, wherein: The configuration information of the one or more candidate cells includes group information associated with the one or more candidate cells; When the group information associated with the target cell and / or the group information associated with the one or more candidate cells is different from the group information associated with the current serving cell of the terminal device, the terminal device determines that a key update needs to be performed or the current LTM process is an inter-CU LTM process.

41. The terminal device according to any one of claims 35 to 40, wherein: The terminal device further includes: The third receiving unit is configured to receive a second indication, where the second indication is used to indicate a key derivation method, where the key derivation method includes horizontal key derivation or vertical key derivation.

42. The terminal device according to claim 41, wherein: The second indication is in the LTM cell handover command, and is used to indicate a key derivation method for the current inter-CU LTM process of the terminal device; or The second indication is in the first RRC message or MAC CE, and is used to indicate a key derivation method for the next inter-CU LTM process.

43. The terminal device according to any one of claims 35 to 40, wherein: The processing unit is further configured to perform horizontal key derivation based on the source network device key, the physical cell identifier PCI of the target cell, and the downlink frequency of the target cell.

44. The terminal device according to any one of claims 35 to 40, wherein: The processing unit is further configured to perform vertical key derivation based on the NH, the PCI of the target cell, and the downlink frequency of the target cell, wherein the NH is determined based on a core network key.

45. The terminal device according to claim 44, wherein: The processing unit is further configured to update and store the NCC.

46. The terminal device according to any one of claims 35 to 45, wherein: The default key derivation method of the terminal device includes one of the following: horizontal key derivation, vertical key derivation, and the key derivation method indicated by the second indication.

47. The terminal device according to any one of claims 35 to 46, wherein: The terminal device further includes: The fourth receiving unit is used to receive a third indication, where the third indication is used to indicate that the key derivation method of the terminal device includes at least one of the following: horizontal key derivation, vertical key derivation, and the key derivation method indicated by the second indication.

48. The terminal device according to claim 47, wherein: The third indication is in a first RRC message used to configure the candidate cell.

49. The terminal device according to claim 47 or 48, wherein: The key derivation method of the inter-CU LTM process indicated by the third indication includes the key derivation method of the initial inter-CU LTM process and / or the key derivation method of the subsequent inter-CU LTM process.

50. The terminal device according to claim 47 or 48, wherein: The key derivation mode of the inter-CU LTM process indicated by the third indication includes the key derivation mode of the initial inter-CU LTM process, and the key derivation mode of subsequent inter-CU LTM processes is a default.

51. The terminal device according to any one of claims 35 to 45, wherein: The terminal device further includes: A fifth receiving unit is configured to receive a third indication and a fourth indication, wherein the key derivation method of the inter-CU LTM process indicated by the third indication includes the key derivation method of the initial inter-CU LTM process, and the key derivation method of the inter-CU LTM process indicated by the fourth indication includes the key derivation method of the subsequent inter-CU LTM process.

52. The terminal device according to any one of claims 47 to 51, wherein: The granularity of the third indication is cell group, and one cell group corresponds to one key derivation method.

53. A first network device, comprising: The sending unit is configured to send one or more first messages, where the first messages include key information associated with one or more candidate cells.

54. The first network device according to claim 53, wherein: The key information associated with the one or more candidate cells includes at least one of the following: The update key of the one or more candidate cells, the update key is generated based on the source network device key, the PCI of the candidate cell and the downlink frequency of the candidate cell, or the update key is generated based on the NH, the PCI of the candidate cell and the downlink frequency of the candidate cell; NCC.

55. The first network device according to claim 53 or 54, wherein: The sending unit is further configured to send a first RRC message, where the first RRC message includes configuration information of one or more candidate cells.

56. A second network device comprising: The receiving unit is configured to receive a first message, where the first message includes key information associated with one or more candidate cells.

57. The second network device according to claim 56, wherein: The second network device further includes: The processing unit is configured to store the received key information associated with the one or more candidate cells.

58. The second network device according to claim 56 or 57, wherein: The processing unit is further configured to delete previously saved key information associated with the candidate cell.

59. A third network device, comprising: A processing unit is used to perform key update based on new key information when the terminal device successfully accesses after switching, and the new key information comes from the fourth network device.

60. The third network device according to claim 59, wherein: The third network device further includes: The first sending unit is configured to send one or more first messages, where the first messages include key information associated with one or more candidate cells.

61. The third network device according to claim 59 or 60, wherein: The new key information also includes a new NH and a new NCC, and the key information associated with the one or more candidate cells includes at least one of the following: an update key of the one or more candidate cells; The new NCC.

62. The third network device according to claim 61, wherein: The processing unit is further configured to generate an update key for the source network device based on the new NH; An update key for the candidate cell is generated based on the update key of the source network device, the PCI of the candidate cell, and the downlink frequency of the candidate cell.

63. The third network device according to claim 61 or 62, wherein: The third network device further includes: The second sending unit is used to send a second RRC message to the terminal device, where the second RRC message is used to instruct the terminal device to perform a key update, and the second RRC message includes the new NCC.

64. The third network device according to claim 59 or 60, wherein: The new key information includes a new NH, and the processing unit is further configured to generate an update key for the candidate cell based on the new NH, the PCI of the candidate cell, and the downlink frequency of the candidate cell.

65. The third network device according to any one of claims 59 to 64, wherein: The third network device further includes: The third sending unit is used to send a second indication to the terminal device, where the second indication is used to indicate a key derivation method, and the key derivation method includes horizontal key derivation or vertical key derivation.

66. The third network device according to claim 65, wherein: The second indication is in the LTM cell handover command, and is used to indicate a key derivation method for the current inter-CU LTM process of the terminal device; or The second indication is in the RRC message or MAC CE, and is used to indicate the key derivation method for the next inter-CU LTM process.

67. The third network device according to any one of claims 59 to 66, wherein: The third network device further includes: The fourth sending unit, in the central unit of the third network device, is further used to send a second message to the data unit of the third network device, where the second message is used to indicate a key derivation method for the next inter-CU LTM process.

68. The third network device according to claim 67, wherein: The second message includes group information corresponding to the candidate cell, which is used to determine whether the LTM process is an inter-CU LTM process or an intra-CU LTM process between central units.

69. A terminal device comprising: A transceiver, a processor and a memory, wherein the memory is used to store a computer program, the transceiver is used to communicate with other devices, and the processor is used to call and run the computer program stored in the memory so that the terminal device executes the method according to any one of claims 1 to 18.

70. A network device comprising: A transceiver, a processor and a memory, wherein the memory is used to store a computer program, the transceiver is used to communicate with other devices, and the processor is used to call and run the computer program stored in the memory to enable the network device to perform the method as described in any one of claims 19 to 34.

71. A chip comprising: A processor, configured to call and execute a computer program from a memory, so that a device equipped with the chip executes the method according to any one of claims 1 to 34.

72. A computer-readable storage medium for storing a computer program, which, when executed by a device, causes the device to perform the method according to any one of claims 1 to 34.

73. A computer program product comprising computer program instructions for causing a computer to perform the method of any one of claims 1 to 34.

74. A computer program causing a computer to perform the method of any one of claims 1 to 34.

75. A communication system comprising: A terminal device, configured to execute the method according to any one of claims 1 to 18; A first network device, configured to perform the method according to any one of claims 19 to 21; A second network device, configured to perform the method according to any one of claims 22 to 24; The third network device is configured to execute the method according to any one of claims 25 to 34.

Citation Information

Patent Citations

  • Secret key derivation method and device

    CN112543450A

  • Registration method and device

    CN115915114A

  • Generating a security key for handling data transmission from

    CN116114281A

  • Communication method, device and system

    CN116367153A

  • Security information processing method and apparatus during handover process, network device, and terminal

    WO2020155157A1