Communication method, terminal, network device, communication system, and storage medium
By generating new keys through terminal-triggered key update operations in 5G mobile communications, the key reuse problem is solved, communication security is improved, and the security of mobility operations is enhanced.
Patent Information
- Application Number
- PCT/CN2024/080848
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-08
- Publication Date
- 2025-09-11
AI Technical Summary
In 5G mobile communications, existing technologies have failed to effectively solve the key update problem, resulting in the risk of key reuse and affecting communication security.
When a mobility operation is triggered, the terminal determines that a key needs to be updated, and performs a key update operation to generate a new key to avoid key reuse.
Through the key update operation, the security of communication is improved, the risk of key reuse is avoided, and the security of mobility operations is enhanced.
Smart Images

Figure CN2024080848_12092025_PF_FP_ABST
Abstract
Description
Communication method, terminal, network device, communication system and storage medium Technical Field
[0001] The present disclosure relates to the field of communication technologies, and in particular to a communication method, a terminal, a network device, a communication system, and a storage medium. Background Art
[0002] The fifth generation mobile communication technology (5G) introduces a variety of mobility enhancement technologies, such as conditional handover (CHO), conditional PSCell Addition / Change (CPAC), and layer L1 / L2 triggered mobility (LTM).
[0003] Summary of the Invention
[0004] The embodiments of the present disclosure provide a communication method, a terminal, a network device, a communication system, and a storage medium.
[0005] According to a first aspect of an embodiment of the present disclosure, a communication method is proposed, which is executed by a terminal. The method includes: triggering a mobility operation, determining that a key needs to be updated, and performing a key update operation.
[0006] According to a second aspect of an embodiment of the present disclosure, a communication method is proposed, which is executed by a network device. The method includes: instructing a terminal to perform a key update operation if it is determined that a key needs to be updated when a mobility operation is triggered.
[0007] According to a third aspect of an embodiment of the present disclosure, a terminal is proposed, including: a processing module, configured to trigger a mobility operation, determine that a key needs to be updated, and perform a key update operation.
[0008] According to a fourth aspect of an embodiment of the present disclosure, a network device is proposed, including: a transceiver module, configured to instruct a terminal to perform a key update operation if it is determined that a key needs to be updated when a mobility operation is triggered.
[0009] According to the fifth aspect of an embodiment of the present disclosure, a terminal is proposed, comprising: one or more processors; a memory coupled to the processor, wherein the memory stores executable instructions, and when the executable instructions are executed by the processor, the terminal executes the communication method described in the first aspect.
[0010] According to the sixth aspect of an embodiment of the present disclosure, a network device is proposed, comprising: one or more processors; a memory coupled to the processor, wherein the memory stores executable instructions, and when the executable instructions are executed by the processor, the network device executes the communication method described in the second aspect.
[0011] According to the seventh aspect of an embodiment of the present disclosure, a communication system is proposed, comprising a terminal and a network device, wherein the terminal is configured to implement the communication method described in the first aspect, and the network device is configured to implement the communication method described in the second aspect.
[0012] According to an eighth aspect of an embodiment of the present disclosure, a storage medium is proposed, which stores instructions. When the instructions are executed on a communication device, the communication device executes the communication method described in the first aspect or the second aspect.
[0013] By adopting the above technical solution of the present disclosure, at least the following beneficial technical effects can be achieved:
[0014] In response to triggering the mobility operation, the terminal performs a key update operation when determining that a key update is required, thereby avoiding key reuse and improving security. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure, the following drawings required for describing the embodiments are introduced. The following drawings are merely some embodiments of the present disclosure and do not impose specific limitations on the protection scope of the present disclosure.
[0016] FIG1A is a schematic diagram showing the architecture of a communication system according to an embodiment of the present disclosure.
[0017] FIG1B is a schematic diagram of a network architecture according to an embodiment of the present disclosure.
[0018] FIG1C is a schematic diagram of a network architecture according to an embodiment of the present disclosure.
[0019] FIG1D is a schematic diagram of a network architecture according to an embodiment of the present disclosure.
[0020] FIG1E is a schematic diagram showing a key update according to an embodiment of the present disclosure.
[0021] FIG1F is a schematic diagram showing a key update configuration according to an embodiment of the present disclosure.
[0022] FIG2A is an interactive schematic diagram illustrating a communication method according to an embodiment of the present disclosure.
[0023] FIG2B is an interactive diagram illustrating a communication method according to an embodiment of the present disclosure.
[0024] FIG2C is an interactive diagram illustrating a communication method according to an embodiment of the present disclosure.
[0025] FIG2D is an interactive schematic diagram of a communication method according to an embodiment of the present disclosure.
[0026] FIG3A is a flow chart illustrating a communication method according to an embodiment of the present disclosure.
[0027] FIG3B is a flow chart illustrating a communication method according to an embodiment of the present disclosure.
[0028] FIG3C is a flow chart illustrating a communication method according to an embodiment of the present disclosure.
[0029] FIG3D is a flow chart of a communication method according to an embodiment of the present disclosure.
[0030] FIG3E is a flow chart of a communication method according to an embodiment of the present disclosure.
[0031] FIG4A is a flow chart showing a communication method according to an embodiment of the present disclosure.
[0032] FIG4B is a flow chart illustrating a communication method according to an embodiment of the present disclosure.
[0033] FIG5 is an interactive diagram illustrating a communication method according to an embodiment of the present disclosure.
[0034] FIG6A is a schematic diagram showing a key update according to an embodiment of the present disclosure.
[0035] FIG6B is a schematic diagram showing a key update according to an embodiment of the present disclosure.
[0036] FIG6C is a schematic diagram showing a key update according to an embodiment of the present disclosure.
[0037] FIG6D is a schematic diagram showing a key update according to an embodiment of the present disclosure.
[0038] FIG7A is a schematic diagram of the structure of a terminal proposed in an embodiment of the present disclosure.
[0039] FIG7B is a schematic diagram of the structure of the network device proposed in an embodiment of the present disclosure.
[0040] FIG8A is a schematic structural diagram of a communication device proposed in an embodiment of the present disclosure.
[0041] FIG8B is a schematic diagram of the structure of the chip proposed in an embodiment of the present disclosure. DETAILED DESCRIPTION
[0042] The embodiments of the present disclosure provide a communication method, a terminal, a network device, a communication system, and a storage medium.
[0043] In a first aspect, an embodiment of the present disclosure proposes a communication method, which is executed by a terminal. The method includes: triggering a mobility operation, determining that a key needs to be updated, and performing a key update operation.
[0044] In the above embodiment, in response to triggering the mobility operation, the terminal performs a key update operation when determining that a key needs to be updated, thereby avoiding key reuse and improving security.
[0045] In combination with some embodiments of the first aspect, in some embodiments, the performing of the key update operation includes: generating a first key, where the first key is the key used by the terminal after successfully accessing the second cell from the currently accessed first cell; successfully accessing the second cell, and using the first key as the activation key.
[0046] In the above embodiment, when switching from a first cell to a second cell, a first key can be generated for the second cell, and when accessing the second cell successfully, the first key can be used as an activation key. This avoids the terminal using the same key as the first cell when staying in the second cell, thereby improving security.
[0047] In conjunction with some embodiments of the first aspect, in some embodiments, generating the first key includes: performing at least one of the following operations to generate the first key:
[0048] First operation;
[0049] Second operation;
[0050] The third operation.
[0051] In the above embodiment, the corresponding operation can be flexibly selected according to needs to generate the first key.
[0052] In combination with some embodiments of the first aspect, in some embodiments, generating the first key includes: determining a first next-hop chain counter parameter NCC; determining to perform a corresponding operation to generate the first key based on whether the first NCC is the same as the second NCC, the second NCC is an NCC associated with the second key, and the second key is the key used when the terminal resides in the first cell.
[0053] In the above embodiment, by determining the first NCC and determining whether the first NCC is the same as the second NCC associated with the second key used when the terminal resides in the first cell, the operation to be performed can be determined, and then the corresponding operation is performed to generate a first key different from the second key, thereby ensuring communication security.
[0054] In combination with some embodiments of the first aspect, in some embodiments, triggering the mobility operation includes: receiving a first indication sent by a network device to trigger the mobility operation.
[0055] In the above embodiment, the network device may enable the terminal to trigger a mobility operation by sending a first indication to the terminal.
[0056] In combination with some embodiments of the first aspect, in some embodiments, the first indication includes a specific NCC; and the determining the first NCC includes: determining the specific NCC as the first NCC.
[0057] In the above embodiment, by configuring a specific NCC in the first indication, the terminal can be instructed to trigger the mobility operation and the terminal can be facilitated to determine the first NCC, thereby improving the utilization rate of the first indication.
[0058] In combination with some embodiments of the first aspect, in some embodiments, determining the first NCC includes: determining the second NCC as the first NCC.
[0059] In the above embodiment, an implementation method of using the second NCC as the first NCC is proposed.
[0060] In combination with some embodiments of the first aspect, in some embodiments, determining the first NCC includes: increasing the second NCC by N to obtain the first NCC, where N is a natural number greater than 0.
[0061] In the above embodiment, an implementation method of obtaining the first NCC by increasing the second NCC is proposed.
[0062] In combination with some embodiments of the first aspect, in some embodiments, an NCC sequence is configured on the terminal; and determining the first NCC includes: determining a first unused NCC in the NCC sequence as the first NCC.
[0063] In the above embodiment, by configuring an NCC sequence on the terminal, the terminal can determine the first unused NCC in the NCC sequence as the first NCC.
[0064] Optionally, after determining the first unused NCC in the NCC sequence as the first NCC, the first NCC is deleted from the NCC sequence, or the first NCC in the NCC sequence is marked as used.
[0065] In combination with some embodiments of the first aspect, in some embodiments, multiple NCC sequences are configured on the terminal, and one NCC sequence corresponds to a cell set; determining the first NCC includes: determining the first unused NCC in the NCC sequence corresponding to the cell set to which the second cell belongs as the first NCC.
[0066] In the above embodiment, multiple NCC sequences are configured on the terminal, and one NCC sequence is configured to correspond to one cell set, so that the terminal can determine the first unused NCC in the NCC sequence corresponding to the cell set to which the second cell belongs as the first NCC.
[0067] Optionally, after determining the first unused NCC in the NCC sequence corresponding to the cell set to which the second cell belongs as the first NCC, the first NCC is deleted from the corresponding NCC sequence, or the first NCC in the corresponding NCC sequence is marked as used.
[0068] In combination with some embodiments of the first aspect, in some embodiments, multiple NCC sequences are configured on the terminal, and one NCC sequence corresponds to one cell; determining the first NCC includes: determining the first unused NCC in the NCC sequence corresponding to the second cell as the first NCC.
[0069] In the above embodiment, by configuring multiple NCC sequences on the terminal and configuring one NCC sequence to correspond to one cell, the terminal can determine the first unused NCC in the NCC sequence corresponding to the second cell as the first NCC.
[0070] Optionally, after determining the first unused NCC in the NCC sequence corresponding to the second cell as the first NCC, the first NCC is deleted from the corresponding NCC sequence, or the first NCC in the corresponding NCC sequence is marked as used.
[0071] In combination with some embodiments of the first aspect, in some embodiments, multiple NCCs are configured on the terminal, and one NCC corresponds to one cell; and determining the first NCC includes: determining the NCC corresponding to the second cell among the multiple NCCs as the first NCC.
[0072] In the above embodiment, by configuring multiple NCCs on the terminal and configuring one NCC to correspond to one cell, the terminal can determine the NCC corresponding to the second cell among the multiple NCCs as the first NCC.
[0073] In combination with some embodiments of the first aspect, in some embodiments, before determining the first NCC, it includes: judging whether it is the first time to access the second cell; determining the first NCC includes: accessing the second cell for the first time and determining the first NCC.
[0074] In the above embodiment, it is specified that when multiple NCCs are configured on the terminal and one NCC is configured to correspond to one cell, if the second cell is accessed for the first time, the NCC corresponding to the second cell among the multiple NCCs is determined as the first NCC.
[0075] In combination with some embodiments of the first aspect, in some embodiments, multiple NCCs are configured on the terminal, and one NCC corresponds to a cell set; determining the first NCC includes: determining the NCC corresponding to the cell set to which the second cell belongs among the multiple NCCs as the first NCC.
[0076] In the above embodiment, by configuring multiple NCCs on the terminal and configuring one NCC to correspond to one cell set, the terminal can determine the NCC corresponding to the cell set to which the second cell belongs among the multiple NCCs as the first NCC.
[0077] In combination with some embodiments of the first aspect, in some embodiments, before determining the first NCC, it includes: judging whether the second cell is the first cell accessed by the terminal in the cell set corresponding to the second cell; determining the first NCC includes: the second cell is the first cell accessed by the terminal in the cell set corresponding to the second cell, and determining the first NCC.
[0078] In the above embodiment, it is specified that when multiple NCCs are configured on the terminal and one NCC is configured to correspond to a cell set, if the second cell is the first cell accessed by the terminal in the cell set corresponding to the second cell, the NCC corresponding to the cell set to which the second cell belongs in the multiple NCCs is determined as the first NCC.
[0079] In combination with some embodiments of the first aspect, in some embodiments, cells in a cell set correspond to the same access network device.
[0080] In the above embodiment, it is specified that cells in a cell set correspond to the same access network device.
[0081] In combination with some embodiments of the first aspect, in some embodiments, determining to perform a corresponding operation to generate the first key based on whether the first NCC is the same as the second NCC includes: when the first NCC is the same as the second NCC, performing a first operation to generate the first key.
[0082] In the above embodiment, if it is determined that the first NCC is the same as the second NCC, a first key different from the second key may be generated by performing the first operation, thereby improving the security of the mobility operation.
[0083] In combination with some embodiments of the first aspect, in some embodiments, determining to perform a corresponding operation to generate the first key based on whether the first NCC is the same as the second NCC includes: if the first NCC is not the same as the second NCC, performing a second operation to generate the first key.
[0084] In the above embodiment, if the first NCC is different from the second NCC, a first key different from the second key may be generated by performing the second operation, thereby improving the security of the mobility operation.
[0085] In combination with some embodiments of the first aspect, in some embodiments, the method further includes: associating the first key with the second cell; or, associating the first key with the cell set to which the second cell belongs; or, associating the first key with the access network device corresponding to the second cell.
[0086] In the above embodiment, by associating the first key with the second cell; or, by associating the first key with the cell set to which the second cell belongs; or, by associating the first key with the access network device corresponding to the second cell, it is possible to facilitate the terminal to determine a new first key when the mobility operation is triggered next time.
[0087] In combination with some embodiments of the first aspect, in some embodiments, the first indication also includes a second indication, and the second indication is used to indicate whether the access and mobility management function AMF key is changed; before determining the first NCC, it includes: determining whether the AMF key is changed according to the second indication; determining the first NCC includes: determining that the AMF key has not been changed according to the second indication, and determining the first NCC.
[0088] In the above embodiment, if the first indication also includes a second indication, the first NCC can be determined according to the specific NCC in the first indication when the second indication clearly indicates that the AMF key has not been changed, and then the first key different from the second key can be determined.
[0089] In combination with some embodiments of the first aspect, in some embodiments, the method further includes: determining the AMF key change according to the second indication, and generating the first key based on the changed AMF key.
[0090] In the above embodiment, it is specified that if the first indication includes the second indication and does not include a specific NCC, the first key is generated according to the information of the AMF key change indicated by the second indication and the changed AMF key, thereby enhancing mobility.
[0091] In combination with some embodiments of the first aspect, in some embodiments, the method further includes: determining a specific NCC and / or a second indication according to a first field in the first indication.
[0092] In the above embodiment, it is specified that the specific NCC and / or the second indication is determined according to the first field in the first indication.
[0093] In combination with some embodiments of the first aspect, in some embodiments, the first indication is a cell switching command MACCE, and the first field is a reserved field.
[0094] In the above embodiment, if the first indication is a cell handover command MAC CE, the first field may refer to a reserved field in the cell handover command MAC CE.
[0095] In combination with some embodiments of the first aspect, in some embodiments, the method further includes: performing a third operation to generate the first key when accessing the second cell is not the first time.
[0096] In the above embodiment, by configuring multiple NCCs on the terminal and configuring one NCC to correspond to one cell, the terminal can generate the first key by performing the third operation when it is not the first time to access the second cell.
[0097] In combination with some embodiments of the first aspect, in some embodiments, the method further includes: the second cell is not the first cell accessed by the terminal in the cell set corresponding to the second cell, and performing a third operation to generate the first key.
[0098] In the above embodiment, by configuring multiple NCCs on the terminal and configuring one NCC to correspond to one cell set, the terminal generates the first key by performing the third operation when the second cell is not the first cell accessed by the terminal in the cell set corresponding to the second cell.
[0099] In combination with some embodiments of the first aspect, in some embodiments, performing the first operation to generate the first key includes: generating the first key according to the second key, an identifier of the second cell, and frequency information of the second cell.
[0100] In the above embodiment, the first operation is specified as an operation of generating the first key according to the second key, the identifier of the second cell, and the frequency information of the second cell.
[0101] In combination with some embodiments of the first aspect, in some embodiments, the execution of the second operation to generate the first key includes: determining the first next hop parameter NH corresponding to the first NCC; generating the first key based on the first NH, the identifier of the second cell, and the frequency information of the second cell.
[0102] In the above embodiment, the second operation is specified as determining a first next hop parameter NH corresponding to the first NCC, and generating a first key according to the first NH, an identifier of the second cell, and frequency information of the second cell.
[0103] In combination with some embodiments of the first aspect, in some embodiments, performing the third operation to generate the first key includes: generating the first key according to the third key, the identifier of the second cell, and the frequency information of the second cell, wherein the third key is at least one of the following keys:
[0104] a key associated with the second cell;
[0105] a key associated with the cell set to which the second cell belongs;
[0106] A key associated with the access network device corresponding to the second cell.
[0107] In the above embodiment, the third operation is specified as an operation of generating the first key according to the third key, the identifier of the second cell, and the frequency information of the second cell.
[0108] In combination with some embodiments of the first aspect, in some embodiments, before determining that a key needs to be updated, it is included: determining that the first indication includes first information, where the first information is a specific NCC and / or a second indication.
[0109] In the above embodiment, it is specified that, when the first indication includes a specific NCC and / or a second indication, it is determined that a key update is required.
[0110] In combination with some embodiments of the first aspect, in some embodiments, before determining that a key update is required, the method includes: determining that a key update indication sent by the network device is received.
[0111] In the above embodiment, it is specified that the key needs to be updated when a key update instruction sent by a network device is received.
[0112] In conjunction with some embodiments of the first aspect, in some embodiments, the mobility operation includes at least one of the following:
[0113] Mobility LTM cell switching based on layer L1 / L2 triggering;
[0114] Condition-based switching CHO.
[0115] In the above embodiment, the mobility operation of the terminal is standardized as LTM cell handover or CHO.
[0116] In a second aspect, an embodiment of the present disclosure proposes a communication method, which is executed by a network device. The method includes: instructing a terminal to perform a key update operation if it is determined that a key needs to be updated when a mobility operation is triggered.
[0117] In a third aspect, an embodiment of the present disclosure proposes a terminal, which includes at least one of a transceiver module and a processing module; wherein the terminal is used to execute the optional implementation method of the first aspect.
[0118] In a fourth aspect, an embodiment of the present disclosure proposes a network device, which includes at least one of a transceiver module and a processing module; wherein the network device is used to execute the optional implementation method of the second aspect.
[0119] In a fifth aspect, an embodiment of the present disclosure proposes a terminal, which includes one or more processors; a memory coupled to the processor, on which executable instructions are stored, and when the executable instructions are executed by the processor, the terminal executes an optional implementation method of the first aspect.
[0120] In a sixth aspect, an embodiment of the present disclosure proposes a network device, which includes one or more processors; a memory coupled to the processor, on which executable instructions are stored, and when the executable instructions are executed by the processor, the network device executes the optional implementation method of the second aspect.
[0121] In the seventh aspect, an embodiment of the present disclosure proposes a communication system, which includes a terminal and a network device, wherein the terminal is configured to execute the communication method described in the optional implementation manner of the first aspect, and the network device is configured to execute the communication method described in the optional implementation manner of the second aspect.
[0122] In an eighth aspect, an embodiment of the present disclosure proposes a storage medium, wherein the storage medium stores instructions. When the instructions are executed on a communication device, the communication device executes the method described in the optional implementation of the first and second aspects.
[0123] In a ninth aspect, an embodiment of the present disclosure proposes a program product. When the program product is executed by a communication device, the communication device executes the method described in the optional implementation of the first and second aspects.
[0124] In a tenth aspect, an embodiment of the present disclosure proposes a computer program, which, when executed on a computer, enables the computer to execute the method described in the optional implementation of the first and second aspects.
[0125] In an eleventh aspect, an embodiment of the present disclosure provides a chip or a chip system, wherein the chip or chip system includes a processing circuit configured to execute the method described in the optional implementation of the first and second aspects above.
[0126] It is understandable that the above-mentioned terminals, network devices, communication systems, storage media, program products, computer programs, chips, or chip systems are all used to perform the methods proposed in the embodiments of the present disclosure. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects of the corresponding methods and will not be repeated here.
[0127] The present disclosure provides a communication method, terminal, network device, communication system, and storage medium. In some embodiments, the terms "communication method," "information processing method," and "key update method" are interchangeable; the terms "communication device," "information processing device," and "key update device" are interchangeable; and the terms "communication system," "information processing system," and "key update system" are interchangeable.
[0128] The embodiments of the present disclosure are not exhaustive and are merely illustrative of some embodiments, and are not intended to be a specific limitation on the scope of protection of the present disclosure. In the absence of contradiction, each step in a certain embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a certain embodiment can also be implemented as an independent embodiment, and the order of the steps in a certain embodiment can be arbitrarily exchanged. In addition, the optional implementation methods in a certain embodiment can be arbitrarily combined; in addition, the embodiments can be arbitrarily combined. For example, some or all steps of different embodiments can be arbitrarily combined, and a certain embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.
[0129] In each embodiment of the present disclosure, unless otherwise specified or provided for by logic, the terms and / or descriptions between the embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form a new embodiment based on their inherent logical relationships.
[0130] The terms used in the embodiments of the present disclosure are only for the purpose of describing specific embodiments and are not intended to limit the present disclosure.
[0131] In the embodiments of the present disclosure, unless otherwise specified, elements expressed in the singular, such as "a", "an", "the", "above", "said", "the", "the", etc., may mean "one and only one", or "one or more", "at least one", etc. For example, when using articles such as "a", "an", "the" in English in translation, the noun following the article may be understood as a singular expression or a plural expression.
[0132] In the embodiments of the present disclosure, “plurality” refers to two or more.
[0133] In some embodiments, the terms "at least one," "one or more," "a plurality of," "multiple," etc. may be used interchangeably.
[0134] In some embodiments, descriptions such as "at least one of A and B," "A and / or B," "A in one case, B in another case," or "in response to one case A, in response to another case B" may include the following technical solutions depending on the situation: in some embodiments, A (A is executed independently of B); in some embodiments, B (B is executed independently of A); in some embodiments, execution is selected from A and B (A and B are selectively executed); and in some embodiments, A and B (both A and B are executed). The above is also applicable when there are more branches such as A, B, and C.
[0135] In some embodiments, "A or B" and other descriptions may include the following technical solutions depending on the situation: in some embodiments, A (A is executed independently of B); in some embodiments, B (B is executed independently of A); in some embodiments, execution is selected from A and B (A and B are selectively executed). The above is also applicable when there are more branches such as A, B, C, etc.
[0136] The prefixes such as "first" and "second" in the embodiments of the present disclosure are only used to distinguish different description objects and do not constitute any restriction on the position, order, priority, quantity or content of the description objects. For the statement of the description object, please refer to the description in the context of the claims or embodiments, and no unnecessary restriction should be constituted due to the use of prefixes. For example, if the description object is a "field", the ordinal number before the "field" in the "first field" and the "second field" does not limit the position or order between the "fields". "First" and "second" do not limit whether the "fields" they modify are in the same message, nor do they limit the order of the "first field" and the "second field". For another example, if the description object is a "level", the ordinal number before the "level" in the "first level" and the "second level" does not limit the priority between the "levels". For another example, the number of description objects is not limited by the ordinal number and can be one or more. Taking "first device" as an example, the number of "devices" can be one or more. In addition, the objects modified by different prefixes can be the same or different. For example, if the description object is "device", then the "first device" and the "second device" can be the same device or different devices, and their types can be the same or different; for another example, if the description object is "information", then the "first information" and the "second information" can be the same information or different information, and their contents can be the same or different.
[0137] In some embodiments, “including A,” “comprising A,” “used to indicate A,” and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.
[0138] In some embodiments, terms such as "in response to...", "in response to determining...", "in the case of...", "at the time of...", "when...", "if...", "if...", etc. can be used interchangeably.
[0139] In some embodiments, terms such as "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not less than", and "above" can be replaced with each other, and terms such as "less than", "less than or equal to", "not greater than", "less than", "less than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", and "below" can be replaced with each other.
[0140] In some embodiments, devices, etc. can be interpreted as physical or virtual, and their names are not limited to the names recorded in the embodiments. Terms such as "device", "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", and "subject" can be used interchangeably.
[0141] In some embodiments, "network" can be interpreted as devices included in the network (eg, access network equipment, core network equipment, etc.).
[0142] In some embodiments, the terms "access network device (AN device)", "radio access network device (RAN device)", "base station (BS)", "radio base station" "fixed station", "node", "access point", "transmission point (TP)", "reception point (RP)", "transmission / reception point (TRP)" "panel", "antenna panel", "antenna array", "cell", "macro cell", "small cell", "femto cell", "pico cell", "sector", "cell group", "serving cell", "carrier", "component carrier", "bandwidth part (BWP)" and the like may be used interchangeably.
[0143] In some embodiments, the terms "terminal", "terminal device", "user equipment (UE)", "user terminal", "mobile station (MS)", "mobile terminal (MT)", subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, handset, user agent, mobile client, client, etc. can be used interchangeably.
[0144] In some embodiments, the access network device, the core network device, or the network device can be replaced by a terminal. For example, the various embodiments of the present disclosure can also be applied to a structure in which the communication between the access network device, the core network device, or the network device and the terminal is replaced by communication between multiple terminals (for example, device-to-device (D2D), vehicle-to-everything (V2X), etc.). In this case, it is also possible to set the structure in which the terminal has all or part of the functions of the access network device. In addition, terms such as "uplink" and "downlink" can also be replaced by terms corresponding to communication between terminals (for example, "side"). For example, uplink channels, downlink channels, etc. can be replaced by side channels, and uplinks, downlinks, etc. can be replaced by side links.
[0145] In some embodiments, the terminal may be replaced by an access network device, a core network device, or a network device. In this case, the access network device, the core network device, or the network device may have a structure that has all or part of the functions of the terminal.
[0146] In some embodiments, obtaining data, information, etc. may comply with the laws and regulations of the country where the data is obtained.
[0147] In some embodiments, data, information, etc. may be obtained with the user's consent.
[0148] In addition, each element, each row, or each column in the table of the embodiment of the present disclosure can be implemented as an independent embodiment, and the combination of any elements, any rows, and any columns can also be implemented as an independent embodiment.
[0149] FIG1A is a schematic diagram illustrating an architecture of a communication system according to an embodiment of the present disclosure. As shown in FIG1A , the communication system 100 may include a terminal 101 and a network device 102 .
[0150] In some embodiments, the terminal 101 includes, for example, a mobile phone, a wearable device, an Internet of Things device, a car with communication function, a smart car, a tablet computer, a computer with wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in a smart grid, a wireless terminal device in transportation safety, a wireless terminal device in a smart city, and at least one of a wireless terminal device in a smart home, but is not limited thereto.
[0151] In some embodiments, the network device 102 may include at least one of an access network device and a core network device.
[0152] Optionally, the network device 102 is an access network device. Optionally, the access network device is, for example, a node or device that connects a terminal to a wireless network. The access network device may include at least one of an evolved NodeB (eNB), a next generation evolved NodeB (ng-eNB), a next generation NodeB (gNB), a node B (NB), a home nodeB (HNB), a home evolved nodeB (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an open RAN, a cloud RAN, a base station in other communication systems, and an access node in a Wi-Fi system, but is not limited thereto.
[0153] In some embodiments, the network device 102 is a base station. Optionally, the base station is, for example, a macro base station, a micro base station (also known as a small base station), a relay station, an access point, a 5G base station or a future base station, a satellite, a transmission point (TRP), a transmission point (TP), a mobile switching center, or other devices that perform base station functions in a communication system, etc., which are not specifically limited in the embodiments of the present disclosure. For ease of description, in all embodiments of the present disclosure, devices that provide wireless communication functions for terminal devices are collectively referred to as network devices or base stations.
[0154] In some embodiments, network device 102 is a core network device. Optionally, the core network device can be a single device including a first network element, a second network element, etc., or can be multiple devices or a group of devices, each including all or part of the first network element, the second network element, etc. The network element can be virtual or physical. The core network includes, for example, at least one of an Evolved Packet Core (EPC), a 5G Core Network (5GCN), and a Next Generation Core (NGC).
[0155] In some embodiments, the technical solution of the present disclosure can be applied to the Open RAN architecture. In this case, the interfaces between or within the access network devices involved in the embodiments of the present disclosure can be transformed into internal interfaces of the Open RAN, and the processes and information interactions between these internal interfaces can be implemented through software or programs.
[0156] In some embodiments, the access network device can be composed of a centralized unit (CU) and a distributed unit (DU), where the CU can also be called a control unit. The CU-DU structure can be used to split the protocol layer of the access network device, with the functions of some protocol layers centrally controlled by the CU, and the functions of the remaining part or all of the protocol layers distributed in the DU, which is centrally controlled by the CU, but is not limited to this.
[0157] It can be understood that the communication system described in the embodiment of the present disclosure is for the purpose of more clearly illustrating the technical solution of the embodiment of the present disclosure, and does not constitute a limitation on the technical solution proposed in the embodiment of the present disclosure. Ordinary technicians in this field can know that with the evolution of the system architecture and the emergence of new business scenarios, the technical solution proposed in the embodiment of the present disclosure is also applicable to similar technical problems.
[0158] The following embodiments of the present disclosure may be applied to the communication system 100 shown in FIG1A , or a portion thereof, but are not limited thereto. The entities shown in FIG1A are illustrative only. The communication system may include all or part of the entities shown in FIG1A , or may include other entities other than those shown in FIG1A . The number and form of the entities may be arbitrary, and the entities may be physical or virtual. The connection relationships between the entities are illustrative only. The entities may be connected or disconnected, and the connection may be in any manner, including direct or indirect, wired or wireless.
[0159] The embodiments of the present disclosure can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), future radio access (FRA), new radio access technology (RAT), new radio (NR), new radio access (NX), future generation radio access (FX), Global System for Mobile Communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (registered trademark), Public Land Mobile Network (PLMN) networks, Device-to-Device (D2D) systems, Machine-to-Machine (M2M) systems, Internet of Things (IoT) systems, Vehicle-to-Everything (V2X), systems utilizing other communication methods, and next-generation systems based on and extending these methods. Furthermore, multiple systems may be combined (for example, a combination of LTE or LTE-A with 5G).
[0160] In some embodiments, MR-DC (Multi-Radio Dual Connectivity) is a generalized Intra-E-UTRA (Intra Evolved Universal Terrestrial Radio Access, intra-node evolved universal mobile telecommunications system (Universal Mobile Telecommunications System, UMTS) terrestrial radio access) dual connectivity, in which the UE can utilize the radio resources provided by two different schedulers, which are located on two different NG-RAN (New Generation Radio Access Network) nodes, connected through non-ideal backhaul, one providing NR (New Radio) access and the other providing E-UTRA or NR access. One acts as MN (MasterNode) and the other as SN (Secondary Node). The MN and SN are connected through a network interface, where at least one MN is connected to the core network.
[0161] In some embodiments, MR-DC and EPC (Evolved Packet Core, i.e., 4G core network):
[0162] Evolved UMTS Terrestrial Radio Access Network (E-UTRAN) supports MR-DC through E-UTRA-NR DC (EN-DC), in which the UE connects to an eNB (eNodeB) acting as a mobile network (MN) and an en-gNB (en-gNB), acting as a network (SN). The eNB connects to the EPC (Packet Core) via the S1 interface (the S1 interface is the communication interface between the LTE eNodeB (base station) and the EPC) and to the en-gNB via the X2 interface (the X2 interface is the interconnection interface between e-NodeBs, supporting direct data and signaling transmission). The en-gNB can also connect to the EPC via the S1-U interface (the interface between the eNodeB and the S-GW, which is the user plane interface for data message transmission) and to other en-gNBs via the X2-U interface. The EN-DC architecture is shown in Figure 1B.
[0163] In some embodiments, the MR-DC of the 5G core network (5GC) includes one of the following:
[0164] A)E-UTRA-NR Dual Connectivity NGEN-DC:
[0165] NG-RAN supports NG-RAN E-UTRA-NR Dual Connectivity (NGEN-DC), where the UE is connected to a ng-eNB as a mobile node and a gNB as a network node. The ng-eNB is connected to the 5GC, and the gNB is connected to the ng-eNB via the Xn interface.
[0166] B)NR-E-UTRA Dual Connectivity NE-DC:
[0167] NG-RAN supports NR-E-UTRA DC (NE-DC), where the UE is connected to a gNB acting as a mobile node and an ng-eNB acting as a network node. The gNB is connected to the 5GC, and the ng-eNB is connected to the gNB via the Xn interface.
[0168] C)NR-NR Dual Connectivity:
[0169] NG-RAN supports NR-NR DC (NR-DC), in which a UE connects to a gNB acting as a mobile node and another gNB acting as a network node. The primary gNB connects to the 5GC via the NG interface, and the two gNBs are connected via the Xn interface. The secondary gNB can also connect to the 5GC via the NG-U interface. NR-DC can also be used for UEs to access a single gNB acting as both a mobile node and a network node, with both a mobile group and a network group configured. The NR-DC architecture is shown in Figure 1C.
[0170] In some embodiments, under dual connectivity, the UE can access two cell groups, namely the main cell group MCG and the secondary cell group SCG. Under the MCG, there may be many cells, among which there is a cell used to initiate initial access, which is called PCell (Primary Cell). As the name implies, PCell is the most "main" cell in the MCG. The PCell under the MCG and the SCell (Secondary Cell) under the MCG are combined through CA (Carrier Aggregation). The primary cell in the MCG is the PCell, and the secondary cell is the SCell; the primary and secondary cells in the SCG are the PSCell (Primary Secondary Cell), and the secondary cell is the SCell. Because many signalings are only sent on the PCell and PSCell, for the convenience of description, the protocol also defines a concept of special cell sPCell (special Cell). PCell and PSCell are collectively referred to as sPCell. Please refer to Figure 1D for details.
[0171] In some embodiments, LTM (L1 / L2 Triggered Mobility) is defined as follows:
[0172] Rel-18 LTM refers to a PCell / PSCell cell change (cell switch) process triggered by the network through MAC CE based on L1 measurement results, which may be accompanied by a change of MCG / SCG.
[0173] In Rel-18 LTM, the gNB receives Layer 1 (L1) measurement reports from the UE. Based on these reports, the gNB issues a cell change command (e.g., a Cell Switch Command) via a Medium Access Control Element (MAC CE) to change the UE's serving cell. The Cell Switch Command indicates an LTM candidate cell configuration that the gNB has previously provided to the UE via RRC signaling. Based on the received Cell Switch Command, the UE accesses the target cell indicated in the Cell Change Command. LTM can be used to reduce mobility latency.
[0174] The LTM candidate cell configuration can only be added, modified, and released by the network through RRC (Radio Resource Control) signaling. The LTM process can be used to reduce mobility delays.
[0175] For LTM, Rel-18 LTM supports subsequent LTM, where Subsequent LTM refers to subsequent LTM cell switch procedures between candidate cells without RRC reconfiguration by the network in between. That is, after performing the mobility operation, the UE will not autonomously delete the LTM configuration information. The LTM configuration information can continue to be used to trigger subsequent LTM (Subsequent LTM) even without RRC reconfiguration and update.
[0176] In some embodiments, a gNB can include a centralized unit (CU) and a distributed unit (DU). This splits base station functionality, deploying some functions in a gNB-CU and the remaining functions in a gNB-DU. Multiple gNB-DUs share a single gNB-CU, saving costs and facilitating network expansion. RE1-18LTM supports the following scenarios:
[0177] LTM supports intra-gNB-DU and intra-gNB-CU inter-gNB-DU mobility. LTM supports intra-frequency and inter-frequency mobility, including mobility to an inter-frequency cell that is not the current serving cell. The following scenarios are supported:
[0178] Changes in PCell in non-CA and non-DC scenarios;
[0179] PCell changes in CA scenarios;
[0180] In the dual connectivity solution, MCG PCell changes and SCG PSCell changes are performed without MN participation (i.e., PSCell changes within SN). Simultaneous changes of PCell and PSCell LTM are not supported.
[0181] In some embodiments, only intra-DU and inter-DU intra-CU LTMs are supported in Rel-18. However, Rel-19 will expand support for inter-CU (inter-node / gNB) LTMs. The mobile network (MN) participates in inter-CU (inter-node / gNB) LTMs for SCG PSCell changes. The MN is responsible for coordinating the configuration of candidate PSCells across different CUs.
[0182] In some embodiments, the LTM is configured as follows:
[0183] In Rel-18, LTM uses LTM-Config to configure LTM configuration information.
[0184] The LTM configuration information may include, but is not limited to, one or more of the following:
[0185] LTM reference configuration;
[0186] One or more candidate cell configurations (using ltm-CandidateToReleaseList and ltm-CandidateToAddModList to add, modify, or delete candidate cell configurations);
[0187] LTM CSI (Channel State Information, CSI) resource configuration;
[0188] ·wait.
[0189] The candidate cell configuration can be configured through LTM-Candidate, which includes but is not limited to one or more of the following information:
[0190] Candidate configuration identification;
[0191] Candidate cell identifier;
[0192] Candidate configuration (expressed via RRCReconfiguration);
[0193] ·wait.
[0194] In some embodiments, an LTM candidate configuration is the configuration portion of an RRCReconfiguration message associated with a candidate cell, e.g., for LTM or subsequent CPAC. The candidate configuration can be a complete candidate configuration or an incremental configuration relative to a reference configuration.
[0195] In some embodiments, the LTM reference configuration is: a configuration provided by the network to the UE, which is a common configuration of a set of configured incomplete candidate configurations within the same cell group.
[0196] In some embodiments, currently R18 LTM only supports intra-DU and inter-DU intra-CU LTM. In R19 LTM, RAN 2 determines that the following scenarios are supported:
[0197] Scenario 1: When no DC is configured, the CU acts as the MN.
[0198] Scenario 2: When configuring NR-DC, the CU serves as the SN and the MCG remains unchanged.
[0199] Scenario 3: When NR-DC is configured, the CU acts as the MN, and the SCG remains unchanged or is released.
[0200] In some embodiments, referring to FIG. 1E , the MN's Key is updated during the handover process as follows:
[0201] In some embodiments, in an Xn handover, the source gNB / ng eNB shall perform vertical key derivation if it has an unused {NH, NCC} pair. NH stands for the Next Hop parameter. NCC stands for the Next Hop Chaining Counter parameter. As described in A.11 / A.12, the source gNB / ng eNB shall first calculate KNG-RAN* based on the target PCI (Physical Cell Identifier), its frequency ARFCN-DL / EARFCN-DL, and the currently active KgNB in the case of horizontal key derivation, or based on NH in the case of vertical key derivation. ARFCN stands for Absolute Radio-Frequency Channel Number. EARFCN stands for E-UTRA Absolute Radio Frequency Channel Number.
[0202] In some embodiments, the source gNB / ng eNB shall then forward the {KNG-RAN*, NCC} pair to the target gNB / ngeNB. The target gNB / ng eNB shall directly use the received KNG-RAN* as the KgNB to be used with the UE. The target gNB / ng eNB shall associate the NCC value received from the source gNB / ngeNB with the KgNB. The target gNB / ng eNB shall include the received NCC in a Prepared Hand Over (HO) Command message, which is sent back to the source gNB / ngeNB in a transparent container and forwarded by the source gNB / ng eNB to the UE.
[0203] In some embodiments, the UE behavior is the same regardless of whether the handover is intra-gNB-CU, intra-ng-eNB, Xn, or N2 (Interface between RAN nodes), except that during intra-gNB-CU handover, the UE may retain the same keys based on instructions from the gNB. In the case of conditional handover, the UE behavior is also the same, as described in TS 38.300
[0052] , i.e., the UE shall use the parameters of the selected target cell in the KNG-RAN* derivation.
[0204] In some embodiments, if the NCC value received by the UE from the target ng eNB / g NB via the source ng eNB / gNB in the HO Command message is equal to the NCC value associated with the currently active KgNB / KeNB, the UE shall derive KNG-RAN* from the currently activated KgNB / KeNB and the target PCI and its frequency ARFCN-DL / EARFCN-DL using the functions defined in A.11 and A.12.
[0205] In some embodiments, if the UE receives an NCC value that is different from the NCC associated with the currently active KgNB / KeNB, the UE shall first synchronize the locally maintained NH parameters by iteratively calculating the function defined in A.10 (and increasing the NCC value until it matches the NCC value received from the source ng eNB / gNB via the HO Command message. When the NCC values match, the UE shall calculate KNG-RAN* based on the synchronized NH parameters and the target PCI and its frequency ARFCN-DL / EARFCN-DL using the function defined in A.11 / A.12.
[0206] In some embodiments, the UE shall use KNG-RAN* as KgNB when communicating with the target gNB and use KeNB when communicating with the target ngeNB.
[0207] In some embodiments, A.10 is an NH derivation function comprising:
[0208] When from K AMF When deriving NH, the following parameters should be used to form the input S of the KDF:
[0209] -FC=0x6F;
[0210] -P0=SYNC-input;
[0211] -L0=length of SYNC-input (ie0x00 0x20).
[0212] In some embodiments, the SYNC input parameter should be the newly derived K during the initial NH derivation. gNB , and the previous NH at all subsequent deriving times. This forms an NH chain, where the next NH is always new and is derived from the previous NH.
[0213] In some embodiments, the input key KEY should be 256 bits K AMF .
[0214] In some embodiments, A.11 is the K of the target gNB NG-RAN *Derivative function (K NG-RAN *derivation function for target gNB), including:
[0215] When switching from the current K gNB Or derive K from the new NH and target physical cell ID in UE and NG-RAN NG-RAN * and on transition from RRC_INACTIVE to RRC_CONNECTED state, the following parameters shall be used to form the input S to the KDF:
[0216] FC=0x70
[0217] -P0=PCI(target physical cell id);
[0218] -L0=length of PCI(ie0x00 0x02);
[0219] -P1=ARFCN-DL(the absolute frequency of SSB of the target PCell as specified in clause13.3of TS 38.300
[0052] );
[0220] -L1=length of ARFCN-DL (ie0x00 0x03).
[0221] In some embodiments, when the index NCC in the handover increases, the input key KEY should be 256 bits NH, otherwise it should be the current 256 bits K gNB (when the source is a gNB) or K eNB (When the source is ng-eNB).
[0222] In some embodiments, the UE receiving RRCReconfiguration includes:
[0223] The UE shall perform the following actions when receiving RRCReconfiguration, performing conditional reconfiguration (CHO, CPA or CPC) or performing LTM cell handover:
[0224] 1> If RRCReconfiguration includes masterKeyUpdate:
[0225] 2> Execute the AS security key update procedure specified in 5.3.5.7;
[0226] …
[0227] In some embodiments, implementation of AS security key update includes:
[0228] The UE shall:
[0229] 1> If the UE is connected to E-UTRA / EPC or E-UTRA / 5GC:
[0230] 2> Upon receiving the sk-Counter specified in TS 36.331
[0010] :
[0231] 3> Update the S-KgNB key based on the KeNB key and using the received sk-Counter value as specified in TS 33.401
[0030] for EN-DC or TS 33.501
[0011] for NGEN-DC;
[0232] 3> Generate KRRCenc and KUPenc keys according to TS 33.401
[0030] of EN-DC or TS 33.501
[0011] of NGEN-DC;
[0233] 3> Derive the KRRCint and KUPint keys as specified in TS 33.401
[0030] for EN-DC or TS 33.501
[0011] for NGEN-DC.
[0234] 1> Otherwise, if the program was started due to receiving a masterKeyUpdate:
[0235] 2> If the received masterKeyUpdate contains nas-Container:
[0236] 3>Forward the nas-Container to the upper layer;
[0237] 2>If keySetChangeIndicator is set to true:
[0238] 3> Generate or update KgNB keys based on KAMF keys in accordance with TS 33.501
[0011] ;
[0239] 2> Otherwise:
[0240] 3> Generate or update the KgNB key based on the current KgNB key or NH using the nextHopChainingCount value indicated in the received masterKeyUpdate, as specified in TS 33.501
[0011] ;
[0241] 2>Store nextHopChainingCount value;
[0242] 2>Export the keys related to KgNB keys as follows:
[0243] In some embodiments, lgorithmConfig is included in SecurityConfig:
[0244] 4> Generate the KRRCenc and KUPenc keys associated with the encryption algorithm indicated in the securityAlgorithmConfig as specified in TS 33.501
[0011] ;
[0245] 4> Generate the KRRCint and KUPint keys associated with the integrityProtAlgorithm indicated in the security algorithm configuration as specified in TS 33.501
[0011] ;
[0246] 3> Otherwise:
[0247] 4> Generate the KRRCenc and KUPenc keys associated with the current encryption algorithm as specified in TS 33.501
[0011] ;
[0248] 4> According to the provisions of TS 33.501
[0011] , derive the KRRCint and KUPint keys associated with the current integrityProtAlgorithm.
[0249] Note 1: Encryption and integrity protection of DRBs are optional configurations in some embodiments.
[0250] 1> Otherwise, if the procedure was initiated due to reception of sk-Counter (UE is in NE-DC or NR-DC, or SN terminated bearer is configured), or if the procedure was initiated due to selection of sk-Counter for subsequent conditional reconfiguration of CPAC (UE is in NR-DC):
[0251] 2> Generate or update the secondary key (S-KgNB or S-KeNB) based on the KgNB key and using the received or selected sk-Counter value in accordance with TS 33.501
[0011] ;
[0252] 2> Generate the KRRCenc key and KUPenc key specified in TS 33.501
[0011] using the encryption algorithm indicated in RadioBearerConfig associated with the secondary key (S-KgNB or S-KeNB) indicated by keyToUse;
[0253] 2> Use the integrity protection algorithm indicated in RadioBearerConfig associated with the secondary key (S-KgNB or S-KeNB) indicated by keyToUse to derive the KRRCint key and KUPint key specified in TS 33.501
[0011] ;
[0254] In some embodiments, NOTE 2: If the UE does not configure a radio bearer with keyToUse set to secondary, and receives sk-Counter without any RadioBearerConfig and with keyToUse set to secondary, the UE shall not consider it as an invalid reconfiguration.
[0255] In some embodiments, the Master Key change configuration is shown in FIG1F .
[0256] In some embodiments, the key set change indication (keySetChangeIndicator) indicates whether the UE should generate a new KgNB. If reconfigurationWithSync is included, a value of true indicates that the KgNB key is derived from the KAMF key used by the most recently successful NAS SMC procedure or N2 handover procedure, such as the KgNB rekey described in TS 33.501
[0011] . A value of false indicates that the new KgNB key is derived from the current KgNB key or NH described in TS 33.501
[0011] .
[0257] In some embodiments, the nextHopChainingCount parameter NCC: See TS33.501
[0011] , conditionally present: MasterKeyChange. If the masterCellGroup includes ReconfigurationWithSync (with synchronous reconfiguration) and the RadioBearerConfig includes SecurityConfig (with SecurityAlgorithmConfig), then this field must be present to indicate that the AS security algorithm associated with the master key has changed. If ReconfigurationWithSync is part of the LTM-Candidate IE associated with the MCG, then this field is not present. Otherwise, this field is not present.
[0258] In some embodiments, inter-gNB LTM is not involved in LTM. Therefore, during the cell switch process supported by Rel-18 LTM, the KgNB does not need to be updated because the serving gNB has not changed. The original KgNB can be used in different candidate cells. For Rel-18 MCG LTM candidate configuration, the gNB Key update indication masterKeyUpdate is not included.
[0259] In some embodiments, if the existing key handling scheme is continued during inter-gNB LTM and Subsequent CHO, the UE will use the same security key before and after executing inter-gNB LTM or Subsequent CHO. This will lead to security key reuse, which is not allowed.
[0260] In view of this, the embodiments of the present disclosure provide a communication method, terminal, network device, communication system, and storage medium. The communication method is a key update method applicable to mobility operations such as MCG LTM and Subsequent CHO, which can avoid key reuse.
[0261] FIG2A is an interactive diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG2A , the embodiment of the present disclosure relates to a communication method, and the method includes:
[0262] Step S2101 , the network device 102 sends a first instruction to the terminal 101 .
[0263] In some embodiments, the terminal receives a first indication sent by the network device.
[0264] In some embodiments, the first indication is used to indicate whether the terminal needs to update the key. Optionally, the first indication is used to indicate that the terminal needs to update the key; optionally, the first indication is used to indicate that the terminal does not need to update the key.
[0265] In some embodiments, the first indication is used to indicate key update related information to the terminal. Optionally, the key update related information includes a specific NCC and / or the second indication.
[0266] In some embodiments, the name of the first indication is not limited, and it can be, for example, an LTM switching command, a key update instruction, a switching command, etc.
[0267] In some embodiments, the first indication is sent via at least one of a physical layer PHY message, a medium access control MAC layer message, and a radio resource control RRC message.
[0268] In some embodiments, the first indication is used to determine a specific NCC and / or a second indication. For example, the first indication includes a specific NCC and / or a second indication. Optionally, the specific NCC is the NCC indicated by the network device for generating the key corresponding to the key used by the terminal after successfully accessing the second cell from the currently accessed first cell (i.e., the current serving cell). Optionally, the second indication is used to indicate whether the AMF key has changed. Optionally, the name of the second indication is not limited, and it is, for example, a key set change indication (keySetChangeIndicator). Optionally, the second cell is the target cell or the cell corresponding to the candidate configuration indirectly or directly indicated in the handover command, or the second cell is the target handover cell that meets the requirements selected by the terminal based on the handover conditions. The present disclosure does not limit the method for determining the second cell that the terminal will access. Optionally, the second cell may also be one of the candidate cells, and the candidate cell may be the cell corresponding to the mobility operation to be triggered that is pre-configured by the network device side for the UE. The network device side or the UE may trigger the corresponding mobility operation to access any one or more of these cells.
[0269] In some embodiments, the specific NCC and / or the second indication is determined based on a first field in the first indication.
[0270] In some embodiments, if the first indication is a cell switch command media access control element (Cell Switch Command MAC CE), then the design of the LTM Cell Switch Command MAC CE for carrying the first field may be as follows:
[0271] For example, the first field is a reserved field in the existing Cell Switch Command MAC CE, that is, one or more bits in the reserved bits in the existing Cell Switch Command MAC CE can be used to transmit the first field. The first field may include NCC value and / or second indication
[0272] For example, the first field is a reserved field in the existing Cell Switch Command MAC CE, as shown in Table 1 below. The 3 bits in the reserved field in the existing Cell Switch Command MAC CE can be used to transmit a specific NCC value, where the specific NCC value ranges from 0 to 7.
[0273] Table 1
[0274] Exemplarily, a new LTM Cell Switch Command MAC CE may be designed. The new LTM Cell Switch Command MAC CE includes a first field. The first field is used to indicate a specific NCC and / or a second indication.
[0275] Exemplarily, the first field is a reserved field in the existing Cell Switch Command MAC CE, that is, 1 bit in the reserved bits in the existing Cell Switch Command MAC CE can be used to transmit the second indication, such as transmitting a keySetChangeIndicator.
[0276] In step S2102, the terminal 101 triggers a mobility operation and determines that a key needs to be updated.
[0277] In some embodiments, the mobility operation includes LTM cell handover and / or CHO, wherein CHO includes but is not limited to subsequent CHO.
[0278] Exemplarily, the LTM cell switching may indicate LTM for PCell and / or LTM for MCG.
[0279] In some embodiments, mobility operations include LTM (for PSCells and / or SCGs) and / or CPA / CPC. CPA / CPC includes, but is not limited to, subsequent CPC / CPA (subsequent CPA, Subsequent CPC). CPA / CPC may also be referred to as CPAC; Subsequent CPA and Subsequent CPC may also be referred to as Subsequent CPAC.
[0280] In some embodiments, the mobility operation may be triggered by an indication from the network device and / or detection of a condition that satisfies the mobility operation. For example, the mobility operation is triggered in response to receiving a first indication sent by the network device.
[0281] In some embodiments, when the first indication sent by the network device includes the first information, it may be determined that the terminal needs to update the key. Optionally, the first information is a specific NCC and / or the second indication. In some embodiments, the network device may send the first indication including the first information to the terminal if it determines that the second cell to be accessed by the terminal corresponds to a different access network device, such as a gNB, than the first cell in which the terminal is currently stationed.
[0282] In some embodiments, when the terminal determines that a key update is required, the terminal performs a key update operation. Optionally, the implementation of the key update operation includes: generating a first key, the first key being a key used by the terminal after successfully accessing a second cell from a currently accessed first cell; and upon successfully accessing the second cell, using the first key as an activation key.
[0283] It should be noted here that, when the terminal determines that the key does not need to be updated, it does not perform the key update operation, that is, the terminal can continue to use the key used in the first cell in the second cell.
[0284] In some embodiments, the method of generating the first key includes: determining a first NCC and, based on whether the first NCC is the same as a second NCC, determining to perform a corresponding operation to generate the first key. Optionally, the second NCC is an NCC associated with a second key, and the second key is a key used when the terminal is stationed in the first cell.
[0285] In some embodiments, if the first indication includes a specific NCC, step S2103 may be executed to determine the first NCC, and based on whether the first NCC is the same as the second NCC, determine to perform a corresponding operation to generate the first key.
[0286] In some embodiments, if the first indication includes a specific NCC and a second indication, and the second indication indicates that the AMF key has not been changed, step S2103 can be executed to determine the first NCC, and based on whether the first NCC is the same as the second NCC, determine to perform a corresponding operation to generate the first key.
[0287] In some embodiments, if the first indication includes a second indication, and the second indication indicates an AMF key change, steps S2103 to S2105 may be replaced by steps of generating a first key based on the changed AMF key. Alternatively, in some embodiments, if the first indication includes a second indication, and the second indication indicates an AMF key change, steps S2103 to S2105 may be omitted, and the first key may be generated based on the changed AMF key. AMF ) The implementation method of generating the first key may include, according to the corresponding provisions, AMF Generate or update the terminal activation key K gNB .
[0288] In step S2103 , the terminal 101 determines the specific NCC in the first indication as the first NCC.
[0289] In some embodiments, if the first indication includes a specific NCC, the specific NCC may be directly determined as the first NCC.
[0290] In some embodiments, if the first indication includes a specific NCC and a second indication, the specific NCC may be determined as the first NCC if the second indication indicates that the AMF key has not been changed.
[0291] After step S2103, one of step S2104 and step S2105 is executed.
[0292] Step S2104: When the first NCC is the same as the second NCC, the terminal 101 performs a first operation to generate a first key.
[0293] In some embodiments, the terminal determines, based on whether the first NCC and the second NCC are the same, whether to perform a corresponding operation to generate the first key, including: if the first NCC and the second NCC are the same, performing the first operation to generate the first key.
[0294] In some embodiments, the name of the first operation is not limited, and it is, for example, a horizontal key generation operation. Optionally, the principle of the horizontal key generation operation can refer to the horizontal key derivation process shown in FIG1E .
[0295] In some embodiments, an implementation in which the terminal performs the first operation to generate the first key includes: the terminal generating the first key based on the second key, an identifier of the second cell, and frequency information of the second cell. The identifier of the second cell is, for example, a PCI. The frequency information of the second cell is, for example, an ARFCN-DL (Absolute Radio Frequency Channel Number) and / or an EARFCN-DL (E-UTRA Absolute Radio Frequency Channel Number).
[0296] In some embodiments, after generating the first key, the first key is associated with the second cell; or, the first key is associated with an access network device corresponding to the second cell, such as a gNB (or MN).
[0297] After step S2104, execute step S2106.
[0298] In step S2105 , when the first NCC is different from the second NCC, the terminal 101 performs a second operation to generate a first key.
[0299] In some embodiments, the terminal determines, based on whether the first NCC and the second NCC are the same, whether to perform a corresponding operation to generate the first key, including: if the first NCC and the second NCC are not the same, performing the second operation to generate the first key.
[0300] In some embodiments, the name of the second operation is not limited, and it is, for example, a vertical key generation operation. Optionally, the principle of the vertical key generation operation can refer to the vertical key derivation process shown in FIG1E .
[0301] In some embodiments, the terminal performs the second operation to generate the first key, including: the terminal determines the first NH corresponding to the first NCC, and generates the first key according to the first NH, the identifier of the second cell, and the frequency information of the second cell.
[0302] In some embodiments, after generating the first key, the first key is associated with the second cell; the first key is associated with an access network device corresponding to the second cell, such as a gNB (or MN).
[0303] After step S2105, execute step S2106.
[0304] In step S2106, when the terminal 101 successfully accesses the second cell, the terminal 101 uses the first key as the activation key.
[0305] In some embodiments, when the terminal successfully accesses the second cell, the first key is used as the terminal's currently activated key, that is, the terminal uses the first key while camping on the second cell. The terminal's currently activated key may also be referred to as a key associated with the currently accessed second cell and / or a node corresponding to the second cell.
[0306] Among them, the key currently activated by the terminal is K gNB , K gNB It can be called Master Key or MN Key, etc., and this disclosure does not limit it.
[0307] In some embodiments, the names of information, etc. are not limited to the names described in the embodiments, and terms such as "information", "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "domain", "field", "symbol", "symbol", "codeword", "codebook", "codeword", "codepoint", "bit", "data", "program", and "chip" can be used interchangeably.
[0308] In some embodiments, "obtain", "get", "get", "receive", "transmit", "bidirectional transmission", "send and / or receive" can be interchangeable, and can be interpreted as receiving from other entities, obtaining from protocols, obtaining from higher layers, obtaining by self-processing, autonomous implementation, etc.
[0309] In some embodiments, terms such as "send", "transmit", "report", "download", "transmit", "bidirectional transmission", "send and / or receive" can be used interchangeably.
[0310] In some embodiments, terms such as "certain", "preset", "preset", "setting", "indicated", "a certain", "any", and "first" can be interchangeable. "Specific A", "preset A", "preset A", "setting A", "indicated A", "a certain A", "any A", and "first A" can be interpreted as A pre-specified in a protocol, etc., or as A obtained through setting, configuration, or indication, etc., or as specific A, a certain A, any A, or first A, etc., but not limited to this.
[0311] In some embodiments, the determination or judgment can be performed by a value represented by 1 bit (0 or 1), or by a true or false value (Boolean value) represented by true or false, or by comparison of numerical values (for example, comparison with a predetermined value), but is not limited thereto.
[0312] In some embodiments, "not expecting to receive" can be interpreted as not receiving on time domain resources and / or frequency domain resources, or as not performing subsequent processing on the data after receiving it; "not expecting to send" can be interpreted as not sending, or as sending but not expecting the recipient to respond to the content sent.
[0313] The communication method according to the embodiments of the present disclosure may include at least one of steps S2101 to S2106. For example, step S2101 may be implemented as an independent embodiment, steps S2103, S2104, and S2106 may be implemented as independent embodiments, and steps S2103, S2105, and S2106 may be implemented as independent embodiments, but are not limited thereto.
[0314] In some embodiments, any two steps in steps S2101 to S2106 can be executed in an interchangeable order or simultaneously. For example, steps S2101 and S2102 can be executed in an interchangeable order or simultaneously.
[0315] In some embodiments, at least one of steps S2101 to S2106 is optional. For example, steps S2102 to S2106 are optional, and one or more of these steps may be omitted or replaced in different embodiments.
[0316] In some embodiments, reference may be made to other optional implementations described before or after the description corresponding to FIG. 2A .
[0317] FIG2B is an interactive diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG2B , the embodiment of the present disclosure relates to a communication method, and the method includes:
[0318] Step S2201 : The network device 102 sends a first configuration to the terminal 101 .
[0319] In some embodiments, the terminal receives a first configuration.
[0320] In some embodiments, the first configuration is used to configure key update related information. Optionally, the key update related information includes one or more NCCs. Optionally, the key update related information includes one or more NCC sequences.
[0321] In some embodiments, the name of the first configuration is not limited, and it can be, for example, pre-configuration information, candidate NCC configuration, etc.
[0322] In some embodiments, the first configuration is sent via at least one of a physical layer PHY message, a medium access control MAC layer message, and a radio resource control RRC message.
[0323] Step S2202: Terminal 101 configures key update related information according to the first configuration.
[0324] In some embodiments, the terminal configures the key update related information according to the first configuration, including configuring an NCC sequence on the terminal. Optionally, the NCCs in the NCC sequence are different.
[0325] In some embodiments, configuring key update-related information by a terminal according to the first configuration includes configuring multiple NCC sequences on the terminal, and configuring each NCC sequence to correspond to a group of cells, which may also be referred to as a cell set. Optionally, cells in a group of cells or a cell set correspond to the same access network device, such as a gNB or mobile network. Optionally, the NCC in each NCC sequence is different.
[0326] Illustratively, a group of cells or a cell set may include one or more cells, that is, one cell may be a group or a set, or multiple cells may constitute a cell group or a set.
[0327] In some embodiments, the terminal configures the key update related information according to the first configuration, including configuring multiple NCC sequences on the terminal, and configuring one NCC sequence to correspond to one cell. Optionally, the NCCs in each NCC sequence are different.
[0328] In step S2203, the terminal 101 triggers a mobility operation and determines that a key needs to be updated.
[0329] The optional implementation of step S2203 can refer to the optional implementation of step S2102 in Figure 2A and other related parts in the embodiment involved in Figure 2A, which will not be repeated here.
[0330] In some embodiments, the terminal may determine that a key needs to be updated in response to receiving a key update indication sent by the network device.
[0331] Step S2204: Terminal 101 determines a first NCC according to key update related information.
[0332] In some embodiments, if the key update-related information indicates that an NCC sequence is configured on the terminal, the implementation of determining the first NCC includes: determining the first unused NCC in the NCC sequence as the first NCC. Optionally, after determining the first unused NCC in the NCC sequence as the first NCC, the first NCC may be deleted from the NCC sequence, or the first NCC in the NCC sequence may be marked as used.
[0333] In some embodiments, if the key update-related information indicates that multiple NCC sequences are configured on the terminal, and one NCC sequence corresponds to a cell set (or a group of cells), then the implementation method of determining the first NCC includes: determining the first unused NCC in the NCC sequence corresponding to the cell set to which the second cell belongs as the first NCC. Optionally, after determining the first unused NCC in the corresponding NCC sequence as the first NCC, deleting the first NCC from the NCC sequence, or marking the first NCC in the NCC sequence as used.
[0334] In some embodiments, if the key update-related information indicates that multiple NCC sequences are configured on the terminal, and each NCC sequence corresponds to one cell, the implementation method of determining the first NCC includes: determining the first unused NCC in the NCC sequence corresponding to the second cell as the first NCC. Optionally, after determining the first unused NCC in the NCC sequence as the first NCC, deleting the first NCC from the NCC sequence, or marking the first NCC in the NCC sequence as used.
[0335] After step S2204, one of step S2205 and step S2206 is executed.
[0336] Step S2205 : When the first NCC is the same as the second NCC, the terminal 101 performs a first operation to generate a first key.
[0337] In some embodiments, after generating the first key, the first key is associated with the second cell; or, the first key is associated with the cell set to which the second cell belongs; or, the first key is associated with an access network device corresponding to the second cell, such as a gNB (or MN).
[0338] The optional implementation of step S2205 can refer to the optional implementation of step S2104 in Figure 2A and other related parts in the embodiment involved in Figure 2A, which will not be repeated here.
[0339] Step S2206: When the first NCC is different from the second NCC, the terminal 101 performs a second operation to generate a first key.
[0340] In some embodiments, after generating the first key, the first key is associated with the second cell; or, the first key is associated with the cell set to which the second cell belongs; or, the first key is associated with an access network device corresponding to the second cell, such as a gNB (or MN).
[0341] The optional implementation of step S2206 can refer to the optional implementation of step S2105 in Figure 2A and other related parts in the embodiment involved in Figure 2A, which will not be repeated here.
[0342] In step S2207, when the terminal 101 successfully accesses the second cell, the terminal 101 uses the first key as the activation key.
[0343] The optional implementation of step S2207 can refer to the optional implementation of step S2106 in Figure 2A and other related parts in the embodiment involved in Figure 2A, which will not be repeated here.
[0344] For the explanation of terms such as the first cell, the second cell, the mobility operation, and the cell set in the embodiments of the present disclosure, please refer to the relevant description in the optional embodiment of Figure 2A and will not be repeated here.
[0345] The communication method according to the embodiments of the present disclosure may include at least one of steps S2201 to S2207. For example, step S2201 may be implemented as an independent embodiment, steps S2203, S2204, and S2205 may be implemented as independent embodiments, and steps S2203, S2204, and S2206 may be implemented as independent embodiments, but are not limited thereto.
[0346] In some embodiments, any two steps in steps S2201 to S2207 can be executed in an interchangeable order or simultaneously. For example, steps S2201 and S2202 can be executed in an interchangeable order or simultaneously.
[0347] In some embodiments, at least one of steps S2201 to S2207 is optional. For example, steps S2202 to S2207 are optional, and one or more of these steps may be omitted or replaced in different embodiments.
[0348] In some embodiments, reference may be made to other optional implementations described before or after the description corresponding to FIG. 2B .
[0349] FIG2C is an interactive diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG2C , the embodiment of the present disclosure relates to a communication method, and the method includes:
[0350] Step S2301 : The network device 102 sends a first configuration to the terminal 101 .
[0351] The optional implementation of step S2301 can refer to the optional implementation of step S2201 in Figure 2B and other related parts in the embodiment involved in Figure 2B, which will not be repeated here.
[0352] Step S2302: Terminal 101 configures key update related information according to the first configuration.
[0353] In some embodiments, the terminal configures the key update related information according to the first configuration, including configuring multiple NCCs on the terminal, and configuring one NCC to correspond to one cell. Optionally, the multiple NCCs configured on the terminal are different.
[0354] In some embodiments, configuring key update-related information according to the first configuration on the terminal includes configuring multiple NCCs on the terminal, with each NCC corresponding to a cell set. Optionally, cells in a cell set correspond to the same access network device, such as a gNB. In some embodiments, configuring one NCC to correspond to a cell set is equivalent to configuring one NCC to correspond to a gNB.
[0355] Step S2303: Terminal 101 triggers a mobility operation and determines that a key needs to be updated.
[0356] The optional implementation of step S2303 can refer to the optional implementation of step S2102 in Figure 2A and other related parts in the embodiment involved in Figure 2A, which will not be repeated here.
[0357] After step S2303, the terminal determines whether it is the first time to access the second cell, and executes one of steps S2304 and S2307.
[0358] Step S2304: Terminal 101 accesses the second cell for the first time and determines the first NCC according to key update related information.
[0359] In some embodiments, if the key update related information indicates that multiple NCCs are configured on the terminal and one NCC corresponds to one cell, when the terminal accesses the second cell for the first time, the NCC corresponding to the second cell among the multiple NCCs is determined as the first NCC.
[0360] In some embodiments, after step S2303, the terminal may also determine whether this is the first time accessing a cell in the cell set to which the second cell belongs. Accordingly, step S2304 may be replaced with the following: If the key update-related information indicates that multiple NCCs are configured on the terminal, and each NCC corresponds to a cell set, then when terminal 101 first accesses a cell in the cell set to which the second cell belongs, i.e., when terminal 101 determines the gNB corresponding to the cell set to which the second cell belongs is first accessed, i.e., when terminal 101 determines that the second cell is the first cell accessed by the terminal in the cell set corresponding to the second cell, the NCC corresponding to the cell set to which the second cell belongs, among the multiple NCCs, is determined as the first NCC. In some embodiments, a cell set may be referred to as a cell group. Exemplarily, a cell group or a cell set may include one or more cells. That is, a cell may be a group or a set, or multiple cells may constitute a cell group or a set.
[0361] After step S2304, one of step S2305 and step S2306 is executed.
[0362] Step S2305: When the first NCC is the same as the second NCC, the terminal 101 performs a first operation to generate a first key.
[0363] In some embodiments, after generating the first key, the first key is associated with the second cell; or, the first key is associated with the cell set to which the second cell belongs; or, the first key is associated with an access network device corresponding to the second cell, such as a gNB (MN).
[0364] The optional implementation of step S2305 can refer to the optional implementation of step S2104 in Figure 2A and other related parts in the embodiment involved in Figure 2A, which will not be repeated here.
[0365] After step S2305, execute step S2308.
[0366] Step S2306: When the first NCC is different from the second NCC, the terminal 101 performs a second operation to generate a first key.
[0367] In some embodiments, after generating the first key, the first key is associated with the second cell; or, the first key is associated with the cell set to which the second cell belongs; or, the first key is associated with an access network device corresponding to the second cell, such as a gNB (MN).
[0368] The optional implementation of step S2306 can refer to the optional implementation of step S2105 in Figure 2A and other related parts in the embodiment involved in Figure 2A, which will not be repeated here.
[0369] After step S2306, execute step S2308.
[0370] Step S2307 : The terminal 101 determines that this is not the first time accessing the second cell, and performs a third operation to generate a first key.
[0371] In some embodiments, step S2307 may be replaced by performing a third operation to generate a first key when the second cell is not the first cell accessed by the terminal in the cell set corresponding to the second cell.
[0372] In some embodiments, after the first key is generated, the first key is associated with the second cell; or, the first key is associated with the cell set to which the second cell belongs; or, the first key is associated with the gNB corresponding to the second cell.
[0373] In some embodiments, the name of the third operation is not limited, and it is, for example, a horizontal key generation operation. Optionally, the horizontal key generation operation can be an operation similar in principle to the horizontal key derivation process shown in FIG. 1E .
[0374] In some embodiments, performing the third operation to generate the first key includes generating the first key according to the third key, an identifier of the second cell, and frequency information of the second cell.
[0375] Optionally, the third key is at least one of the following keys:
[0376] a key associated with the second cell;
[0377] a key associated with the set of cells to which the second cell belongs;
[0378] A key associated with the access network device corresponding to the second cell.
[0379] In some embodiments, after the first key is generated, the key associated with the second cell is updated, eg, after the first key is generated, the first key is associated with the second cell.
[0380] In some embodiments, after the first key is generated, the key associated with the cell set to which the second cell belongs is updated, for example, after the first key is generated, the first key is associated with the cell set to which the second cell belongs.
[0381] In some embodiments, after the first key is generated, the key associated with the gNB corresponding to the second cell is updated, for example, after the first key is generated, the first key is associated with the gNB corresponding to the second cell.
[0382] After step S2307, execute step S2308.
[0383] In step S2308, when the terminal 101 successfully accesses the second cell, the terminal 101 uses the first key as the activation key.
[0384] The optional implementation of step S2308 can refer to the optional implementation of step S2106 in Figure 2A and other related parts in the embodiment involved in Figure 2A, which will not be repeated here.
[0385] For the explanation of terms such as the first cell, the second cell, the mobility operation, and the cell set in the embodiments of the present disclosure, please refer to the relevant description in the optional embodiment of Figure 2A and will not be repeated here.
[0386] The communication method involved in the embodiments of the present disclosure may include at least one of steps S2301 to S2308. For example, step S2301 may be implemented as an independent embodiment, step S2307 may be implemented as an independent embodiment, steps S2304 and S2305 may be implemented as independent embodiments, and steps S2304 and S2306 may be implemented as independent embodiments, but are not limited thereto.
[0387] In some embodiments, any two steps in steps S2301 to S2308 can be executed in an interchangeable order or simultaneously. For example, steps S2301 and S2302 can be executed in an interchangeable order or simultaneously.
[0388] In some embodiments, at least one of steps S2301 to S2308 is optional. For example, steps S2302 to S2308 are optional, and one or more of these steps may be omitted or replaced in different embodiments.
[0389] In some embodiments, reference may be made to other optional implementations described before or after the description corresponding to FIG. 2C .
[0390] FIG2D is an interactive diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG2D , the embodiment of the present disclosure relates to a communication method, and the method includes:
[0391] Step S2401: Terminal 101 triggers a mobility operation and determines that a key needs to be updated.
[0392] The optional implementation of step S2401 can refer to the optional implementation of step S2102 in Figure 2A and other related parts in the embodiment involved in Figure 2A, which will not be repeated here.
[0393] In step S2402, the terminal 101 performs corresponding operations to generate a first key.
[0394] In some embodiments, the terminal performs a corresponding operation to generate the first key in an embodiment that the terminal performs a corresponding operation instructed by the network device to generate the first key. In some embodiments, the terminal performs a corresponding operation to generate the first key in an embodiment that the terminal performs a default corresponding operation to generate the first key.
[0395] In some embodiments, the implementation of generating the first key may include performing at least one of the following operations: a first operation, a second operation, and a third operation.
[0396] In some embodiments, the first operation is a horizontal key generation operation based on the second key. Optionally, the second key is a key corresponding to the current serving cell (ie, the first cell) of the terminal.
[0397] In some embodiments, the second operation is a vertical key generation operation.
[0398] In some embodiments, the third operation is a horizontal key generation operation based on a third key. Optionally, the third key is at least one of the following keys:
[0399] a key associated with the second cell;
[0400] a key associated with the set of cells to which the second cell belongs;
[0401] A key associated with the access network device corresponding to the second cell.
[0402] Optionally, the second cell is a cell that the terminal will access.
[0403] In some embodiments, the specific implementation of the first operation, the second operation, and the third operation can be found in the description of the first operation, the second operation, and the third operation in the embodiments in Figures 2A, 2B, and 2C, and will not be repeated here.
[0404] For example, an embodiment of generating a first key includes: determining a first NCC, and based on whether the first NCC is the same as a second NCC, determining an operation to perform, and performing the corresponding operation to generate the first NCC. Optionally, determining the second NCC as the first NCC, and performing a first operation to generate the first key. Optionally, increasing the second NCC by N to obtain the first NCC, and performing a second operation to generate the first key. Optionally, N is preferably 1.
[0405] Illustratively, the implementation of generating the first key includes: directly executing the first operation to generate the first key.
[0406] Illustratively, the implementation of generating the first key includes: directly executing the second operation to generate the first key.
[0407] Illustratively, the implementation of generating the first key includes: directly performing the third operation to generate the first key.
[0408] In step S2403, when the terminal 101 successfully accesses the second cell, the terminal 101 uses the first key as the activation key.
[0409] The optional implementation of step S2403 can refer to the optional implementation of step S2106 in Figure 2A and other related parts in the embodiment involved in Figure 2A, which will not be repeated here.
[0410] For the explanation of terms such as the first cell, the second cell, the mobility operation, and the cell set in the embodiments of the present disclosure, please refer to the relevant description in the optional embodiment of Figure 2A and will not be repeated here.
[0411] The communication method involved in the embodiment of the present disclosure may include at least one of steps S2401 to S2403. For example, step S2401 may be implemented as an independent embodiment, step S2402 may be implemented as an independent embodiment, and step S2403 may be implemented as an independent embodiment, but is not limited thereto.
[0412] In some embodiments, any two steps in steps S2401 to S2403 can be executed in an interchangeable order or simultaneously. For example, steps S2401 and S2402 can be executed in an interchangeable order or simultaneously.
[0413] In some embodiments, at least one of steps S2401 to S2403 is optional. For example, steps S2402 and S2403 are optional, and one or more of these steps may be omitted or replaced in different embodiments.
[0414] In some embodiments, reference may be made to other optional implementations described before or after the description corresponding to FIG. 2D .
[0415] FIG3A is a flow chart of a communication method according to an embodiment of the present disclosure. As shown in FIG3A , the present disclosure embodiment relates to a communication method, which is executed by the terminal side, and the method includes:
[0416] Step S3101: Receive a first instruction.
[0417] The optional implementation of step S3101 can refer to the optional implementation of step S2101 in Figure 2A and other related parts in the embodiment involved in Figure 2A, which will not be repeated here.
[0418] In some embodiments, the terminal 101 receives the first indication sent by the network device 102, but is not limited thereto and may also receive the first indication sent by other entities.
[0419] In some embodiments, terminal 101 obtains a first indication specified by a protocol.
[0420] In some embodiments, terminal 101 obtains the first indication from upper layer(s).
[0421] In some embodiments, terminal 101 performs processing to obtain the first indication.
[0422] In some embodiments, step S3101 is omitted, and the terminal 101 autonomously implements the function indicated by the first indication, or the above function is default or acquiescent.
[0423] Step S3102: triggering a mobility operation and determining that a key needs to be updated.
[0424] The optional implementation of step S3102 can refer to the optional implementation of step S2102 in Figure 2A and other related parts in the embodiment involved in Figure 2A, which will not be repeated here.
[0425] Step S3103: Determine the specific NCC in the first indication as the first NCC.
[0426] The optional implementation of step S3103 can refer to the optional implementation of step S2103 in Figure 2A and other related parts in the embodiment involved in Figure 2A, which will not be repeated here.
[0427] Step S3104: The first NCC is the same as the second NCC and performs a first operation to generate a first key.
[0428] The optional implementation of step S3104 can refer to the optional implementation of step S2104 in Figure 2A and other related parts in the embodiment involved in Figure 2A, which will not be repeated here.
[0429] In some embodiments, step S3104 is replaced by the first NCC being different from the second NCC, and performing the second operation to generate the first key. For alternative implementations of the replaced step S3104, see the alternative implementations of step S2105 of FIG. 2A and other related parts of the embodiment involved in FIG. 2A , which will not be repeated here.
[0430] Step S3105: Successfully access the second cell and use the first key as the activation key.
[0431] The optional implementation of step S3105 can refer to the optional implementation of step S2106 in Figure 2A and other related parts in the embodiment involved in Figure 2A, which will not be repeated here.
[0432] The communication method involved in the embodiment of the present disclosure may include at least one of steps S3101 to S3105. For example, step S3101 may be implemented as an independent embodiment, and step S3104 may be implemented as an independent embodiment, but the present invention is not limited thereto.
[0433] In some embodiments, any two steps in steps S3101 to S3105 can be executed in an interchangeable order or simultaneously. For example, steps S3101 and S3102 can be executed in an interchangeable order or simultaneously.
[0434] In some embodiments, at least one of steps S3101 to S3105 is optional. For example, steps S3101 to S3103 and S3105 are optional, and one or more of these steps may be omitted or replaced in different embodiments.
[0435] The present disclosure provides a communication method, which is executed by a terminal side and includes:
[0436] Step 1: Trigger the mobility operation and determine that the key needs to be updated.
[0437] The optional implementation of step 1 can refer to step S2102 of Figure 2A, the optional implementation of step S3102 of Figure 3A, and other related parts in the embodiments involved in Figures 2A and 3A, which will not be repeated here.
[0438] Step 2: Determine the specific NCC as the first NCC.
[0439] The optional implementation of step 2 can refer to step S2103 of Figure 2A, the optional implementation of step S3103 of Figure 3A, and other related parts in the embodiments involved in Figures 2A and 3A, which will not be repeated here.
[0440] Step 3: The first NCC is the same as the second NCC and performs a first operation to generate a first key.
[0441] The optional implementation of step 3 can be found in step S2104 of FIG. 2A , the optional implementation of step S3104 of FIG. 3A , and other related parts in the embodiments involved in FIG. 2A and FIG. 3A , which will not be described in detail here.
[0442] Step 4: Successfully access the second cell and use the first key as the activation key.
[0443] The optional implementation of step 4 can refer to the optional implementation of step S2106 in Figure 2A, step S3105 in Figure 3A, and other related parts in the embodiments involved in Figures 2A and 3A, which will not be repeated here.
[0444] The communication method involved in the embodiments of the present disclosure may include at least one of steps 1 to 4. For example, step 1 may be implemented as an independent embodiment, and step 4 may be implemented as an independent embodiment, but the present invention is not limited thereto.
[0445] In some embodiments, any two steps in steps 1 to 4 can be swapped in order or performed simultaneously.
[0446] In some embodiments, at least one of steps 1 to 4 is optional.
[0447] The present disclosure provides a communication method, which is executed by a terminal side and includes:
[0448] Step 1: Trigger the mobility operation and determine that the key needs to be updated.
[0449] The optional implementation of step 1 can refer to step S2102 of Figure 2A, the optional implementation of step S3102 of Figure 3A, and other related parts in the embodiments involved in Figures 2A and 3A, which will not be repeated here.
[0450] Step 2: Determine the specific NCC as the first NCC.
[0451] The optional implementation of step 2 can refer to step S2103 of Figure 2A, the optional implementation of step S3103 of Figure 3A, and other related parts in the embodiments involved in Figures 2A and 3A, which will not be repeated here.
[0452] Step 3: If the first NCC is different from the second NCC, a second operation is performed to generate a first key.
[0453] The optional implementation of step 3 can be found in step S2105 of FIG. 2A and other related parts of the embodiment involved in FIG. 2A , which will not be described in detail here.
[0454] Step 4: Successfully access the second cell and use the first key as the activation key.
[0455] The optional implementation of step 4 can refer to the optional implementation of step S2106 in Figure 2A, step S3105 in Figure 3A, and other related parts in the embodiments involved in Figures 2A and 3A, which will not be repeated here.
[0456] The communication method involved in the embodiments of the present disclosure may include at least one of steps 1 to 4. For example, step 1 may be implemented as an independent embodiment, and step 4 may be implemented as an independent embodiment, but the present invention is not limited thereto.
[0457] In some embodiments, any two steps in steps 1 to 4 can be swapped in order or performed simultaneously.
[0458] In some embodiments, at least one of steps 1 to 4 is optional.
[0459] The present disclosure provides a communication method, which is executed by a terminal side and includes:
[0460] Step 1: Determine the first NCC.
[0461] The optional implementation of step 1 can refer to step S2103 of Figure 2A, the optional implementation of step S3103 of Figure 3A, and other related parts in the embodiments involved in Figures 2A and 3A, which will not be repeated here.
[0462] Step 2: The first NCC is the same as the second NCC and performs a first operation to generate a first key.
[0463] The optional implementation of step 2 can refer to the optional implementation of step S2104 in Figure 2A, step S3104 in Figure 3A, and other related parts in the embodiments involved in Figures 2A and 3A, which will not be repeated here.
[0464] Step 3: Successfully access the second cell and use the first key as the activation key.
[0465] The optional implementation of step 3 can refer to the optional implementation of step S2106 in Figure 2A, step S3105 in Figure 3A, and other related parts in the embodiments involved in Figures 2A and 3A, which will not be repeated here.
[0466] The communication method involved in the embodiment of the present disclosure may include at least one of steps 1 to 3. For example, step 1 may be implemented as an independent embodiment, and step 3 may be implemented as an independent embodiment, but the present invention is not limited thereto.
[0467] In some embodiments, any two steps in steps 1 to 3 can be swapped in order or performed simultaneously.
[0468] In some embodiments, at least one of steps 1 to 3 is optional.
[0469] The present disclosure provides a communication method, which is executed by a terminal side and includes:
[0470] Step 1: Determine the first NCC.
[0471] The optional implementation of step 1 can refer to step S2103 of Figure 2A, the optional implementation of step S3103 of Figure 3A, and other related parts in the embodiments involved in Figures 2A and 3A, which will not be repeated here.
[0472] Step 2: The first NCC is different from the second NCC, and a second operation is performed to generate a first key.
[0473] The optional implementation of step 2 can refer to the optional implementation of step S2105 in Figure 2A, step S3104 in Figure 3A, and other related parts in the embodiments involved in Figures 2A and 3A, which will not be repeated here.
[0474] Step 3: Successfully access the second cell and use the first key as the activation key.
[0475] The optional implementation of step 3 can refer to the optional implementation of step S2106 in Figure 2A, step S3105 in Figure 3A, and other related parts in the embodiments involved in Figures 2A and 3A, which will not be repeated here.
[0476] The communication method involved in the embodiment of the present disclosure may include at least one of steps 1 to 3. For example, step 1 may be implemented as an independent embodiment, and step 3 may be implemented as an independent embodiment, but the present invention is not limited thereto.
[0477] In some embodiments, any two steps in steps 1 to 3 can be swapped in order or performed simultaneously.
[0478] In some embodiments, at least one of steps 1 to 3 is optional.
[0479] The present disclosure provides a communication method, which is executed by a terminal side and includes:
[0480] Step 1: Determine the first NCC.
[0481] The optional implementation of step 1 can refer to step S2103 of Figure 2A, the optional implementation of step S3103 of Figure 3A, and other related parts in the embodiments involved in Figures 2A and 3A, which will not be repeated here.
[0482] The present disclosure provides a communication method, which is executed by a terminal side and includes:
[0483] Step 1: The first NCC is the same as the second NCC and performs a first operation to generate a first key.
[0484] The present disclosure provides a communication method, which is executed by a terminal side and includes:
[0485] Step 1: The first NCC and the second NCC are different, and a second operation is performed to generate a first key.
[0486] The present disclosure provides a communication method, which is executed by a terminal side and includes:
[0487] Step 3: Successfully access the second cell and use the first key as the activation key.
[0488] FIG3B is a flow chart of a communication method according to an embodiment of the present disclosure. As shown in FIG3B , the present disclosure embodiment relates to a communication method, which is executed by the terminal side, and the method includes:
[0489] Step S3201: Receive a first configuration.
[0490] The optional implementation of step S3201 can refer to the optional implementation of step S2201 in Figure 2B and other related parts in the embodiment involved in Figure 2B, which will not be repeated here.
[0491] In some embodiments, the terminal 101 receives the first configuration sent by the network device 102, but is not limited thereto and may also receive the first configuration sent by other entities.
[0492] In some embodiments, terminal 101 obtains a first configuration specified by a protocol.
[0493] In some embodiments, terminal 101 obtains the first configuration from upper layer(s).
[0494] In some embodiments, terminal 101 performs processing to obtain the first configuration.
[0495] In some embodiments, step S3201 is omitted, and the terminal 101 autonomously implements the function indicated by the first configuration, or the above function is default or by default.
[0496] Step S3202: Configure key update related information according to the first configuration.
[0497] The optional implementation of step S3202 can refer to the optional implementation of step S2202 in Figure 2B and other related parts in the embodiment involved in Figure 2B, which will not be repeated here.
[0498] Step S3203: triggering a mobility operation and determining that a key needs to be updated.
[0499] The optional implementation of step S3203 can refer to the optional implementation of step S2203 in Figure 2B and other related parts in the embodiment involved in Figure 2B, which will not be repeated here.
[0500] Step S3204: Determine the first NCC according to the key update related information.
[0501] The optional implementation of step S3204 can refer to the optional implementation of step S2204 in Figure 2B and other related parts in the embodiment involved in Figure 2B, which will not be repeated here.
[0502] Step S3205: The first NCC is the same as the second NCC and performs a first operation to generate a first key.
[0503] The optional implementation of step S3205 can refer to the optional implementation of step S2205 in Figure 2B and other related parts in the embodiment involved in Figure 2B, which will not be repeated here.
[0504] In some embodiments, step S3205 can be replaced by the first NCC being different from the second NCC, and performing the second operation to generate the first key. The optional implementation of the replaced step S3205 can be referred to the optional implementation of step S2206 in Figure 2B and other related parts in the embodiment involved in Figure 2B, which will not be repeated here.
[0505] Step S3206: Successfully access the second cell and use the first key as the activation key.
[0506] The optional implementation of step S3206 can refer to the optional implementation of step S2207 in Figure 2B and other related parts in the embodiment involved in Figure 2B, which will not be repeated here.
[0507] The communication method involved in the embodiment of the present disclosure may include at least one of steps S3201 to S3206. For example, step S3201 may be implemented as an independent embodiment, and step S3205 may be implemented as an independent embodiment, but the present invention is not limited thereto.
[0508] In some embodiments, any two steps in steps S3201 to S3206 can be executed in an interchangeable order or simultaneously. For example, steps S3201 and S3202 can be executed in an interchangeable order or simultaneously.
[0509] In some embodiments, at least one of steps S3201 to S3206 is optional. For example, steps S3201 to S3204 and S3106 are optional, and one or more of these steps may be omitted or replaced in different embodiments.
[0510] The present disclosure provides a communication method, which is executed by a terminal side and includes:
[0511] Step 1: Trigger the mobility operation and determine that the key needs to be updated.
[0512] The optional implementation of step 1 can refer to the optional implementation of step S2203 in Figure 2B, step S3203 in Figure 3B, and other related parts in the embodiments involved in Figures 2B and 3B, which will not be repeated here.
[0513] Step 2: Determine the first unused NCC in the NCC sequence as the first NCC.
[0514] The optional implementation of step 2 can refer to the optional implementation of step S2204 in Figure 2B, step S3204 in Figure 3B, and other related parts in the embodiments involved in Figures 2B and 3B, which will not be repeated here.
[0515] Step 3: Based on whether the first NCC and the second NCC are the same, perform corresponding operations to generate a first key.
[0516] The optional implementation of step 3 can be found in step S2205 and step S2206 of FIG. 2B , the optional implementation of step S3205 of FIG. 3B , and other related parts in the embodiments involved in FIG. 2B and FIG. 3B , which will not be repeated here.
[0517] The communication method involved in the embodiment of the present disclosure may include at least one of steps 1 to 3. For example, step 1 may be implemented as an independent embodiment, and step 3 may be implemented as an independent embodiment, but the present invention is not limited thereto.
[0518] In some embodiments, any two steps in steps 1 to 3 can be swapped in order or performed simultaneously.
[0519] In some embodiments, at least one of steps 1 to 3 is optional.
[0520] The present disclosure provides a communication method, which is executed by a terminal side and includes:
[0521] Step 1: Trigger the mobility operation and determine that the key needs to be updated.
[0522] The optional implementation of step 1 can refer to the optional implementation of step S2203 in Figure 2B, step S3203 in Figure 3B, and other related parts in the embodiments involved in Figures 2B and 3B, which will not be repeated here.
[0523] Step 2: Determine the first unused NCC in the NCC sequence corresponding to the second cell as the first NCC.
[0524] The optional implementation of step 2 can refer to the optional implementation of step S2204 in Figure 2B, step S3204 in Figure 3B, and other related parts in the embodiments involved in Figures 2B and 3B, which will not be repeated here.
[0525] Step 3: Based on whether the first NCC and the second NCC are the same, perform corresponding operations to generate a first key.
[0526] The optional implementation of step 3 can be found in step S2205 and step S2206 of FIG. 2B , the optional implementation of step S3205 of FIG. 3B , and other related parts in the embodiments involved in FIG. 2B and FIG. 3B , which will not be repeated here.
[0527] The communication method involved in the embodiment of the present disclosure may include at least one of steps 1 to 3. For example, step 1 may be implemented as an independent embodiment, and step 3 may be implemented as an independent embodiment, but the present invention is not limited thereto.
[0528] In some embodiments, any two steps in steps 1 to 3 can be swapped in order or performed simultaneously.
[0529] In some embodiments, at least one of steps 1 to 3 is optional.
[0530] The present disclosure provides a communication method, which is executed by a terminal side and includes:
[0531] Step 1: Trigger the mobility operation and determine that the key needs to be updated.
[0532] The optional implementation of step 1 can refer to the optional implementation of step S2203 in Figure 2B, step S3203 in Figure 3B, and other related parts in the embodiments involved in Figures 2B and 3B, which will not be repeated here.
[0533] Step 2: Determine the first NCC according to the key update related information.
[0534] The optional implementation of step 2 can refer to the optional implementation of step S2204 in Figure 2B, step S3204 in Figure 3B, and other related parts in the embodiments involved in Figures 2B and 3B, which will not be repeated here.
[0535] Step 3: The first NCC is the same as the second NCC and performs a first operation to generate a first key.
[0536] The optional implementation of step 3 can be found in step S2205 of FIG. 2B , the optional implementation of step S3205 of FIG. 3B , and other related parts in the embodiments involved in FIG. 2B and FIG. 3B , which will not be described in detail here.
[0537] Step 4: Successfully access the second cell and use the first key as the activation key.
[0538] The optional implementation of step 4 can refer to the optional implementation of step S2207 in Figure 2B, step S3206 in Figure 3B, and other related parts in the embodiments involved in Figures 2B and 3B, which will not be repeated here.
[0539] The communication method involved in the embodiments of the present disclosure may include at least one of steps 1 to 4. For example, step 1 may be implemented as an independent embodiment, and step 4 may be implemented as an independent embodiment, but the present invention is not limited thereto.
[0540] In some embodiments, any two steps in steps 1 to 4 can be swapped in order or performed simultaneously.
[0541] In some embodiments, at least one of steps 1 to 4 is optional.
[0542] The present disclosure provides a communication method, which is executed by a terminal side and includes:
[0543] Step 1: Trigger the mobility operation and determine that the key needs to be updated.
[0544] The optional implementation of step 1 can refer to the optional implementation of step S2203 in Figure 2B, step S3203 in Figure 3B, and other related parts in the embodiments involved in Figures 2B and 3B, which will not be repeated here.
[0545] Step 2: Determine the first NCC according to the key update related information.
[0546] The optional implementation of step 2 can refer to the optional implementation of step S2204 in Figure 2B, step S3204 in Figure 3B, and other related parts in the embodiments involved in Figures 2B and 3B, which will not be repeated here.
[0547] Step 3: If the first NCC is different from the second NCC, a second operation is performed to generate a first key.
[0548] The optional implementation of step 3 can be found in step S2205 of FIG. 2B , the optional implementation of step S3205 of FIG. 3B , and other related parts in the embodiments involved in FIG. 2B and FIG. 3B , which will not be described in detail here.
[0549] Step 4: Successfully access the second cell and use the first key as the activation key.
[0550] The optional implementation of step 4 can refer to the optional implementation of step S2207 in Figure 2B, step S3206 in Figure 3B, and other related parts in the embodiments involved in Figures 2B and 3B, which will not be repeated here.
[0551] The communication method involved in the embodiments of the present disclosure may include at least one of steps 1 to 4. For example, step 1 may be implemented as an independent embodiment, and step 4 may be implemented as an independent embodiment, but the present invention is not limited thereto.
[0552] In some embodiments, any two steps in steps 1 to 4 can be swapped in order or performed simultaneously.
[0553] In some embodiments, at least one of steps 1 to 4 is optional.
[0554] The present disclosure provides a communication method, which is executed by a terminal side and includes:
[0555] Step 1: Determine a first NCC based on key update related information.
[0556] The optional implementation of step 1 can refer to the optional implementation of step S2204 in Figure 2B, step S3204 in Figure 3B, and other related parts in the embodiments involved in Figures 2B and 3B, which will not be repeated here.
[0557] Step 2: The first NCC is the same as the second NCC and performs a first operation to generate a first key.
[0558] The optional implementation of step 2 can refer to the optional implementation of step S2205 in Figure 2B, step S3205 in Figure 3B, and other related parts in the embodiments involved in Figures 2B and 3B, which will not be repeated here.
[0559] The communication method involved in the embodiment of the present disclosure may include at least one of step 1 and step 2. For example, step 1 may be implemented as an independent embodiment, and step 2 may be implemented as an independent embodiment, but the present invention is not limited thereto.
[0560] In some embodiments, any two steps in step 1 and step 2 can be swapped in order or performed simultaneously.
[0561] In some embodiments, at least one of step 1 and step 2 is optional.
[0562] The present disclosure provides a communication method, which is executed by a terminal side and includes:
[0563] Step 1: Determine a first NCC based on key update related information.
[0564] The optional implementation of step 1 can refer to the optional implementation of step S2204 in Figure 2B, step S3204 in Figure 3B, and other related parts in the embodiments involved in Figures 2B and 3B, which will not be repeated here.
[0565] Step 2: The first NCC is different from the second NCC, and a second operation is performed to generate a first key.
[0566] The optional implementation of step 2 can refer to the optional implementation of step S2206 in Figure 2B and other related parts in the embodiment involved in Figure 2B, which will not be repeated here.
[0567] The communication method involved in the embodiment of the present disclosure may include at least one of step 1 and step 2. For example, step 1 may be implemented as an independent embodiment, and step 2 may be implemented as an independent embodiment, but the present invention is not limited thereto.
[0568] In some embodiments, any two steps in step 1 and step 2 can be swapped in order or performed simultaneously.
[0569] In some embodiments, at least one of step 1 and step 2 is optional.
[0570] The present disclosure provides a communication method, which is executed by a terminal side and includes:
[0571] Step 1: Determine a first NCC based on key update related information.
[0572] The optional implementation of step 1 can refer to the optional implementation of step S2204 in Figure 2B, step S3204 in Figure 3B, and other related parts in the embodiments involved in Figures 2B and 3B, which will not be repeated here.
[0573] FIG3C is a flow chart of a communication method according to an embodiment of the present disclosure. As shown in FIG3C , the present disclosure embodiment relates to a communication method, which is executed by the terminal side, and the method includes:
[0574] Step S3301: Receive a first configuration.
[0575] The optional implementation of step S3301 can refer to the optional implementation of step S2201 in Figure 2B and other related parts in the embodiment involved in Figure 2B, which will not be repeated here.
[0576] Step S3302: Configure key update related information according to the first configuration.
[0577] The optional implementation of step S3302 can refer to the optional implementation of step S2202 in Figure 2B and other related parts in the embodiment involved in Figure 2B, which will not be repeated here.
[0578] Step S3303: triggering a mobility operation and determining that a key needs to be updated.
[0579] The optional implementation of step S3303 can refer to the optional implementation of step S2203 in Figure 2B and other related parts in the embodiment involved in Figure 2B, which will not be repeated here.
[0580] Step S3304: Access the second cell for the first time and determine the first NCC based on key update related information.
[0581] The optional implementation of step S3304 can refer to the optional implementation of step S2304 in Figure 2C and other related parts in the embodiment involved in Figure 2C, which will not be repeated here.
[0582] In some embodiments, step S3304 can be replaced by accessing the cell set to which the second cell belongs for the first time or accessing the gNB corresponding to the second cell for the first time, and determining the first NCC based on key update related information.
[0583] Step S3305: The first NCC is the same as the second NCC and performs a first operation to generate a first key.
[0584] The optional implementation of step S3305 can refer to the optional implementation of step S2104 in Figure 2A and other related parts in the embodiment involved in Figure 2A, which will not be repeated here.
[0585] In some embodiments, step S3205 can be replaced by the first NCC and the second NCC being different, and performing the second operation to generate the first key. The optional implementation of the replaced step S3205 can be referred to the optional implementation of step S2105 in Figure 2A and other related parts in the embodiment involved in Figure 2A, which will not be repeated here.
[0586] Step S3306: Successfully access the second cell and use the first key as the activation key.
[0587] The optional implementation of step S3306 can refer to the optional implementation of step S2207 in Figure 2B and other related parts in the embodiment involved in Figure 2B, which will not be repeated here.
[0588] The communication method involved in the embodiment of the present disclosure may include at least one of steps S3301 to S3306. For example, step S3301 may be implemented as an independent embodiment, and step S3305 may be implemented as an independent embodiment, but the present invention is not limited thereto.
[0589] In some embodiments, any two steps in steps S3301 to S3306 can be executed in an interchangeable order or simultaneously. For example, steps S3301 and S3302 can be executed in an interchangeable order or simultaneously.
[0590] In some embodiments, at least one of steps S3301 to S3306 is optional. For example, steps S3301 to S3304 and step S3306 are optional, and one or more of these steps may be omitted or replaced in different embodiments.
[0591] FIG3D is a flow chart of a communication method according to an embodiment of the present disclosure. As shown in FIG3D , the present disclosure embodiment relates to a communication method, which is executed by the terminal side, and the method includes:
[0592] Step S3401: triggering a mobility operation and determining that a key needs to be updated.
[0593] The optional implementation of step S3401 can refer to the optional implementation of step S2203 in Figure 2B and other related parts in the embodiment involved in Figure 2B, which will not be repeated here.
[0594] Step S3402: This is not the first time the second cell is accessed, and a third operation is performed to generate a first key.
[0595] The optional implementation of step S3402 can refer to the optional implementation of step S2307 in Figure 2C and other related parts in the embodiment involved in Figure 2C, which will not be repeated here.
[0596] Step S3403: Successfully access the second cell and use the first key as the activation key.
[0597] The optional implementation of step S3403 can refer to the optional implementation of step S2308 in Figure 2C and other related parts in the embodiment involved in Figure 2C, which will not be repeated here.
[0598] The communication method involved in the embodiment of the present disclosure may include at least one of steps S3401 to S3403. For example, step S3401 may be implemented as an independent embodiment, and step S3402 may be implemented as an independent embodiment, but the present invention is not limited thereto.
[0599] In some embodiments, any two steps in step S3401 to step S3403 can be swapped in order or executed simultaneously.
[0600] In some embodiments, at least one of steps S3401 to S3403 is optional. For example, steps S3101 and S3403 are optional, and one or more of these steps may be omitted or replaced in different embodiments.
[0601] The present disclosure provides a communication method, which is executed by a terminal side and includes:
[0602] Step 1: Access the second cell for the first time and determine the first NCC according to key update related information.
[0603] The optional implementation of step 1 can refer to the optional implementation of step S2304 in Figure 2C and other related parts in the embodiment involved in Figure 2C, which will not be repeated here.
[0604] Step 2: Successfully access the second cell and use the first key as the activation key.
[0605] The optional implementation of step 2 can refer to the optional implementation of step S2308 in Figure 2C and other related parts in the embodiment involved in Figure 2C, which will not be repeated here.
[0606] The communication method involved in the embodiment of the present disclosure may include at least one of step 1 and step 2. For example, step 1 may be implemented as an independent embodiment, and step 2 may be implemented as an independent embodiment, but the present invention is not limited thereto.
[0607] In some embodiments, any two steps in step 1 and step 2 can be swapped in order or performed simultaneously.
[0608] In some embodiments, at least one of step 1 and step 2 is optional.
[0609] The present disclosure provides a communication method, which is executed by a terminal side and includes:
[0610] Step 1: Access the second cell for the first time, and determine the NCC corresponding to the second cell as the first NCC.
[0611] The optional implementation of step 1 can refer to the optional implementation of step S2304 in Figure 2C and other related parts in the embodiment involved in Figure 2C, which will not be repeated here.
[0612] Step 2: Successfully access the second cell and use the first key as the activation key.
[0613] The optional implementation of step 2 can refer to the optional implementation of step S2308 in Figure 2C and other related parts in the embodiment involved in Figure 2C, which will not be repeated here.
[0614] The communication method involved in the embodiment of the present disclosure may include at least one of step 1 and step 2. For example, step 1 may be implemented as an independent embodiment, and step 2 may be implemented as an independent embodiment, but the present invention is not limited thereto.
[0615] In some embodiments, any two steps in step 1 and step 2 can be swapped in order or performed simultaneously.
[0616] In some embodiments, at least one of step 1 and step 2 is optional.
[0617] The present disclosure provides a communication method, which is executed by a terminal side and includes:
[0618] Step 1: Access the gNB corresponding to the second cell for the first time and determine the first NCC based on the key update related information.
[0619] The optional implementation of step 1 can refer to the optional implementation of step S2304 in Figure 2C and other related parts in the embodiment involved in Figure 2C, which will not be repeated here.
[0620] Step 2: Successfully access the second cell and use the first key as the activation key.
[0621] The optional implementation of step 2 can refer to the optional implementation of step S2308 in Figure 2C and other related parts in the embodiment involved in Figure 2C, which will not be repeated here.
[0622] The communication method involved in the embodiment of the present disclosure may include at least one of step 1 and step 2. For example, step 1 may be implemented as an independent embodiment, and step 2 may be implemented as an independent embodiment, but the present invention is not limited thereto.
[0623] In some embodiments, any two steps in step 1 and step 2 can be swapped in order or performed simultaneously.
[0624] In some embodiments, at least one of step 1 and step 2 is optional.
[0625] The present disclosure provides a communication method, which is executed by a terminal side and includes:
[0626] Step 1: Access the gNB corresponding to the second cell for the first time, and determine the NCC corresponding to the gNB as the first NCC.
[0627] The optional implementation of step 1 can refer to the optional implementation of step S2304 in Figure 2C and other related parts in the embodiment involved in Figure 2C, which will not be repeated here.
[0628] Step 2: Successfully access the second cell and use the first key as the activation key.
[0629] The optional implementation of step 2 can refer to the optional implementation of step S2308 in Figure 2C and other related parts in the embodiment involved in Figure 2C, which will not be repeated here.
[0630] The communication method involved in the embodiment of the present disclosure may include at least one of step 1 and step 2. For example, step 1 may be implemented as an independent embodiment, and step 2 may be implemented as an independent embodiment, but the present invention is not limited thereto.
[0631] In some embodiments, any two steps in step 1 and step 2 can be swapped in order or performed simultaneously.
[0632] In some embodiments, at least one of step 1 and step 2 is optional.
[0633] The present disclosure provides a communication method, which is executed by a terminal side and includes:
[0634] Step 1: When accessing the second cell not for the first time, perform the third operation to generate a first key.
[0635] The optional implementation of step 1 can refer to the optional implementation of step S2307 in Figure 2C and other related parts in the embodiment involved in Figure 2C, which will not be repeated here.
[0636] Step 2: Successfully access the second cell and use the first key as the activation key.
[0637] The optional implementation of step 2 can refer to the optional implementation of step S2308 in Figure 2C and other related parts in the embodiment involved in Figure 2C, which will not be repeated here.
[0638] The communication method involved in the embodiment of the present disclosure may include at least one of step 1 and step 2. For example, step 1 may be implemented as an independent embodiment, and step 2 may be implemented as an independent embodiment, but the present invention is not limited thereto.
[0639] In some embodiments, any two steps in step 1 and step 2 can be swapped in order or performed simultaneously.
[0640] In some embodiments, at least one of step 1 and step 2 is optional.
[0641] The present disclosure provides a communication method, which is executed by a terminal side and includes:
[0642] Step 1: When accessing the gNB corresponding to the second cell (not the first time), perform the third operation to generate the first key.
[0643] The optional implementation of step 1 can refer to the optional implementation of step S2307 in Figure 2C and other related parts in the embodiment involved in Figure 2C, which will not be repeated here.
[0644] Step 2: Successfully access the second cell and use the first key as the activation key.
[0645] The optional implementation of step 2 can refer to the optional implementation of step S2308 in Figure 2C and other related parts in the embodiment involved in Figure 2C, which will not be repeated here.
[0646] The communication method involved in the embodiment of the present disclosure may include at least one of step 1 and step 2. For example, step 1 may be implemented as an independent embodiment, and step 2 may be implemented as an independent embodiment, but the present invention is not limited thereto.
[0647] In some embodiments, any two steps in step 1 and step 2 can be swapped in order or performed simultaneously.
[0648] In some embodiments, at least one of step 1 and step 2 is optional.
[0649] The present disclosure provides a communication method, which is executed by a terminal side and includes:
[0650] Step 1: Access the second cell for the first time and determine the first NCC according to key update related information.
[0651] The optional implementation of step 1 can refer to the optional implementation of step S2304 in Figure 2C and other related parts in the embodiment involved in Figure 2C, which will not be repeated here.
[0652] The present disclosure provides a communication method, which is executed by a terminal side and includes:
[0653] Step 1: Access the gNB corresponding to the second cell for the first time and determine the first NCC based on the key update related information.
[0654] The optional implementation of step 1 can refer to the optional implementation of step S2304 in Figure 2C and other related parts in the embodiment involved in Figure 2C, which will not be repeated here.
[0655] The present disclosure provides a communication method, which is executed by a terminal side and includes:
[0656] Step 1: When accessing the second cell not for the first time, perform the third operation to generate a first key.
[0657] The optional implementation of step 1 can refer to the optional implementation of step S2307 in Figure 2C and other related parts in the embodiment involved in Figure 2C, which will not be repeated here.
[0658] The present disclosure provides a communication method, which is executed by a terminal side and includes:
[0659] Step 1: When accessing the gNB corresponding to the second cell (not the first time), perform the third operation to generate the first key.
[0660] The optional implementation of step 1 can refer to the optional implementation of step S2307 in Figure 2C and other related parts in the embodiment involved in Figure 2C, which will not be repeated here.
[0661] The present disclosure provides a communication method, which is executed by a terminal side and includes:
[0662] Step 1: Trigger the mobility operation and determine that the key needs to be updated.
[0663] The optional implementation of step 1 can refer to the optional implementation of step S2401 in Figure 2D and other related parts in the embodiment involved in Figure 2D, which will not be repeated here.
[0664] Step 2: Execute a first operation to generate a first key.
[0665] The optional implementation of step 2 can refer to the optional implementation of step S2402 in Figure 2D and other related parts in the embodiment involved in Figure 2D, which will not be repeated here.
[0666] In some embodiments, any two steps in step 1 and step 2 can be swapped in order or performed simultaneously.
[0667] In some embodiments, at least one of step 1 and step 2 is optional.
[0668] The present disclosure provides a communication method, which is executed by a terminal side and includes:
[0669] Step 1: Trigger the mobility operation and determine that the key needs to be updated.
[0670] The optional implementation of step 1 can refer to the optional implementation of step S2401 in Figure 2D and other related parts in the embodiment involved in Figure 2D, which will not be repeated here.
[0671] Step 2: Execute the second operation to generate the first key.
[0672] The optional implementation of step 2 can refer to the optional implementation of step S2402 in Figure 2D and other related parts in the embodiment involved in Figure 2D, which will not be repeated here.
[0673] The communication method involved in the embodiment of the present disclosure may include at least one of step 1 and step 2. For example, step 1 may be implemented as an independent embodiment, and step 2 may be implemented as an independent embodiment, but the present invention is not limited thereto.
[0674] In some embodiments, any two steps in step 1 and step 2 can be swapped in order or performed simultaneously.
[0675] In some embodiments, at least one of step 1 and step 2 is optional.
[0676] The present disclosure provides a communication method, which is executed by a terminal side and includes:
[0677] Step 1: Trigger the mobility operation and determine that the key needs to be updated.
[0678] The optional implementation of step 1 can refer to the optional implementation of step S2401 in Figure 2D and other related parts in the embodiment involved in Figure 2D, which will not be repeated here.
[0679] Step 2: Execute the third operation to generate the first key.
[0680] The optional implementation of step 2 can refer to the optional implementation of step S2402 in Figure 2D and other related parts in the embodiment involved in Figure 2D, which will not be repeated here.
[0681] The communication method involved in the embodiment of the present disclosure may include at least one of step 1 and step 2. For example, step 1 may be implemented as an independent embodiment, and step 2 may be implemented as an independent embodiment, but the present invention is not limited thereto.
[0682] In some embodiments, any two steps in step 1 and step 2 can be swapped in order or performed simultaneously.
[0683] In some embodiments, at least one of step 1 and step 2 is optional.
[0684] FIG3E is a flow chart of a communication method according to an embodiment of the present disclosure. As shown in FIG3E , the present disclosure embodiment relates to a communication method, which is executed by the terminal side, and the method includes:
[0685] Step S3501: triggering a mobility operation, determining that a key needs to be updated, and performing a key update operation.
[0686] The optional implementation methods of step S3501 can be found in steps S2103 to S2106 of Figure 2A, steps S2204 to S2207 of Figure 2B, the optional implementation methods of steps S2304 to S2308 of Figure 2C, steps S2402 and S2403 of Figure 2D, and other related parts in the embodiments involved in Figures 2A, 2B, 2C, and 2D, which will not be repeated here.
[0687] FIG4A is a flow chart of a communication method according to an embodiment of the present disclosure. As shown in FIG4A , the present disclosure embodiment relates to a communication method, which is executed by a network device, and the method includes:
[0688] Step S4101: Send a first instruction.
[0689] The optional implementation of step S4101 can refer to the optional implementation of step S2101 in Figure 2A and other related parts in the embodiment involved in Figure 2A, which will not be repeated here.
[0690] In some embodiments, the network device sends the first indication to the terminal, but is not limited thereto, and the first indication may also be sent to other entities.
[0691] FIG4B is a flow chart of a communication method according to an embodiment of the present disclosure. As shown in FIG4B , the present disclosure embodiment relates to a communication method, which is executed by a network device, and the method includes:
[0692] Step S4201: Send the first configuration.
[0693] The optional implementation of step S4201 can refer to the optional implementation of step S2201 in Figure 2B and other related parts in the embodiment involved in Figure 2B, which will not be repeated here.
[0694] In some embodiments, the network device sends the first configuration to the terminal, but is not limited thereto, and the first configuration may also be sent to other entities.
[0695] Figure 5 is an interactive diagram of a communication method according to an embodiment of the present disclosure. As shown in Figure 5, the embodiment of the present disclosure relates to a communication method, which is executed by a network device. The method includes:
[0696] Step S501: The network device instructs the terminal to perform a key update operation if it is determined that a key needs to be updated when a mobility operation is triggered.
[0697] Step S502: The terminal triggers a mobility operation, determines that a key needs to be updated, and performs a key update operation.
[0698] For the optional implementation of step S502, please refer to the optional implementation of steps S2103 to S2106 in Figure 2A, steps S2204 to S2207 in Figure 2B, steps S2304 to S2308 in Figure 2C, steps S2402 and S2403 in Figure 2D, and other related parts in the embodiments involved in Figures 2A, 2B, 2C, and 2D, which will not be repeated here.
[0699] In some embodiments, the above method may include the method described in the above embodiments of the terminal side, communication system side, network equipment side, access network equipment side, etc., which will not be repeated here.
[0700] In some embodiments, in the first embodiment, key update is performed based on the key update related configuration carried in the LTM Cell Switch Command. That is, the key is updated during the LTM execution process based on the key update related configuration carried in the LTM switch command.
[0701] In some embodiments, when the UE receives an LTM Cell Switch trigger indication, the UE performs an LTM Cell Switch procedure.
[0702] Optionally, the LTM Cell Switch trigger indication is an LTM Cell Switch Command MAC CE, and the message is a MAC layer message. The network can instruct the UE to perform the LTM cell switch process by sending the LTM cell switch Command MAC CE.
[0703] In some embodiments, if the LTM Cell Switch Command includes key update related information, the UE performs a security key update procedure to obtain an updated security key for the target cell.
[0704] Optionally, the key update-related information may include an NCC value. If the NCC value is equal to the NCC value associated with the UE's currently activated key (KgNB / also known as Master Key, MN Key, etc., hereinafter referred to as KgNB), the UE obtains a new KgNB based on the currently activated KgNB. The specific process is as follows: Horizontal key generation: The UE obtains the KNG-RAN* based on the currently activated KgNB and the PCI and frequency information ARFCN-DL / EARFCN-DL of the target cell based on the function described in Background A.11, and uses the KNG-RAN* as the KgNB of the target gNB.
[0705] Optionally, the key update related information may include an NCC value. If the NCC value UE is different from the NCC value associated with the currently activated KgNB, the UE determines the NH parameter synchronized with this NCC value. The UE generates a new KgNB based on this NH parameter (the specific process is vertical key generation: the UE first synchronizes the locally stored NH parameter based on the function shown in background A.10 (increases the NCC value associated with the previously activated KgNB until it matches the NCC value received through the LTM Cell Switch Command message). When the NCC values match, the UE calculates KNG-RAN* based on the synchronized NH parameter and the target PCI and its frequency ARFCN-DL / EARFCN-DL. The UE uses KNG-RAN* as the KgNB when communicating with the target gNB based on the function shown in the aforementioned A.11).
[0706] In some embodiments, if the key update related information in the LTM Cell Switch Command includes a keySetChangeIndicator, if the indication information is true, then K AMF Changed, based on the new K AMF Generate or update KgNB keys.
[0707] In some embodiments, if the LTM Cell Switch Command does not include key update related information, the UE does not need to perform a security key update procedure, and the currently activated security key can also be used for the current target cell.
[0708] In some embodiments, the design of the LTM Cell Switch Command MAC CE carrying the NCC is as follows:
[0709] For example, 3 bits of the reserved bits of the existing Cell Switch Command MAC CE are used to transmit the NCC value (the NCC value ranges from 0 to 7). Please refer to Table 1 for details.
[0710] Exemplarily, a new LTM Cell Switch Command MAC CE is introduced, which includes an NCC and / or a keySetChangeIndicator.
[0711] Exemplarily, one bit in the reserved bits of the existing Cell Switch Command MAC CE is used to transmit the keySetChangeIndicator.
[0712] In some embodiments, the UE stores the NCC received through the LTM Cell Switch Command MAC CE and uses it as the NCC value associated with the currently activated KgNB (updated KgNB).
[0713] In some embodiments, the LTM Cell Switch trigger indication received by the UE may also be a physical layer message or an RRC layer message, and the above message may include an NCC value and / or a keySetChangeIndicator. The specific process of the UE updating the key is the same as above.
[0714] In some embodiments, embodiment 2, the UE updates the key based on specific criteria.
[0715] Optionally, vertical key generation, when performing LTM-triggered handover, the UE side increases the NCC associated with the currently stored serving KgNB by 1, determines the corresponding NH based on the increased NCC, and generates a new KgNB based on the NCC, NH, target cell identifier and corresponding frequency.
[0716] Optionally, horizontal key generation, when performing LTM-triggered handover, a new KgNB is generated based on the current serving KgNB and the target cell identity and corresponding frequency.
[0717] In some embodiments, based on a vertical key generation scheme, the UE side executes NCC*=NCC+1 and obtains an updated key based on the updated NCC*.
[0718] For example, referring to Figure 6A, assuming that the current NCC = 2, when the UE accesses the new gNB2, then NCC = 3, and the new KgNB is KgNB2.
[0719] In some embodiments, in response to the UE performing an LTM Cell Switch, the UE updates a key.
[0720] In some embodiments, the key update process includes the following steps:
[0721] 1. The UE automatically increases the currently stored NCC to NCC+1.
[0722] 2. Based on the updated NCC, the UE determines the (corresponding) NH parameter synchronized with the NCC value; the UE generates a new KgNB based on the NH parameter;
[0723] 3 The UE stores the new NCC value.
[0724] Exemplarily, during the key update process, in response to the key update being caused by LTM triggering, the NCC is equal to the NCC currently stored by the UE increased by 1, and the UE determines the NH parameter synchronized with the updated NCC value; the UE generates a new KgNB based on this NH parameter (for detailed scheme, see the vertical key generation in the invention point 1)
[0725] In some embodiments, the UE determines whether a key update is required during the LTM Cell Switch process based on the configuration (or indication information) on the network side. (If the gNB remains unchanged before and after the Cell Switch, no key update is required, that is, the current serving cell and the target cell are cells under the same gNB.)
[0726] In some embodiments, based on a horizontal key generation scheme, the UE obtains an updated key based on the currently activated key.
[0727] For example, referring to Figure 6B, assuming that the current NCC = 2 and the activated key is KgNB1, then when the UE accesses the new gNB2, the NCC remains unchanged and the new KgNB is KgNB2.
[0728] In some embodiments, in response to the UE performing an LTM Cell Switch, the UE updates a key.
[0729] In some embodiments, the key update process includes the following steps:
[0730] 1. If the NCC remains unchanged, the UE obtains a new KgNB based on the currently activated KgNB;
[0731] Exemplarily, during the key update process, in response to the key update being caused by LTM triggering, the NCC is equal to the NCC currently stored by the UE, and the UE obtains a new KgNB based on the currently activated KgNB.
[0732] In some embodiments, the UE determines whether a key update is required during an LTM Cell Switch based on network-side configuration (or indication). If the gNB remains unchanged before and after the Cell Switch, no key update is required, i.e., the current serving cell and the target cell are cells under the same gNB.
[0733] In some embodiments, in embodiment three, the UE updates the key based on key update related information preconfigured by the network side.
[0734] In some embodiments, vertical key generation: the network side preconfigures a set of NCC value lists for the UE. When the UE performs LTM-triggered handover, it selects the first unused NCC and generates a new KgNB based on this NCC.
[0735] In some embodiments, the network side pre-configures multiple groups of NCC value lists for the UE, each NCC value list is associated with a Candidate gNB. When the UE performs LTM-triggered handover, it selects the first unused NCC associated with the target cell or target gNB, and generates a new KgNB based on this NCC.
[0736] In some embodiments, vertical and horizontal key generation: the network side configures an NCC for each candidate cell (or candidate gNB). When the UE accesses this candidate cell (or candidate gNB) for the first time through LTM, a new KgNB (KgNB1) is generated based on this NCC. When the UE subsequently accesses this candidate cell (or candidate gNB) again, a new KgNB is generated based on the KgNB used last time in this candidate cell (or candidate gNB).
[0737] In some embodiments, the candidate cell group may also be a candidate cell (eg, a candidate MCG or a candidate PCell).
[0738] In some embodiments, based on a vertical key generation scheme: during the execution of LTM Cell Switch, the network side preconfigures multiple NCC values for the UE, and the UE selects the first unused NCC and performs key update based on this NCC.
[0739] In the embodiment, see Figure 6C. Assuming that the current NCC = 2, when the UE accesses the new gNB2, the first unused NCC in the NCC value list corresponding to gNB2 is NCC = 3, and the new KgNB is KgNB2.
[0740] In some embodiments, when performing LTM configuration, the network side pre-configures multiple NCC values for the UE, which can be represented by an NCC value list.
[0741] Optionally, the network side may configure an NCC value list for the UE.
[0742] Optionally, the network side can configure multiple NCC value lists for the UE, each NCC value list corresponds to a cell set, and the candidate cells in the same set are cells under the same candidate gNB.
[0743] It should be noted that the NCC values in one or more NCC value lists configured by the network side for the UE are not repeated.
[0744] In some embodiments, in response to the UE performing an LTM Cell Switch, the UE updates a key.
[0745] In some embodiments, the key update process includes the following steps:
[0746] 1 The UE selects the first unused NCC value in the NCC value list;
[0747] Optionally, the UE selects the first unused NCC value in this NCC value list.
[0748] Optionally, the UE selects the first unused NCC value in the NCC Value List corresponding to the cell set where the target cell to be accessed is located.
[0749] 2 Based on the selected NCC value, the UE determines the (corresponding) NH parameter synchronized with this NCC value; the UE generates a new KgNB based on this NH parameter.
[0750] 3 The UE stores the selected NCC value as the NCC value corresponding to the current KgNB.
[0751] 4 The UE deletes the selected NCC value in the corresponding NCC value List.
[0752] Exemplarily, during the key update process, in response to the key update being triggered by LTM, the UE selects the first unused NCC value in the NCC value list corresponding to the candidate cell pre-configured by the network side, and the UE determines the NH parameter synchronized with the updated NCC value; the UE generates a new KgNB based on this NH parameter (for detailed scheme, see the vertical key generation in the invention point 1).
[0753] In some embodiments, the UE determines whether the key needs to be updated during the LTM Cell Switch process based on the configuration (or indication information) on the network side (if the gNB remains unchanged before and after the Cell Switch, no key update is required, that is, the current serving cell and the target cell are cells under the same gNB).
[0754] In some embodiments, based on the vertical and horizontal key generation scheme: the network side configures an NCC for each candidate cell (or candidate gNB). When the UE accesses this candidate cell (or candidate gNB) for the first time through LTM, a new KgNB (KgNB1) is generated based on this NCC. When the UE subsequently accesses this candidate cell (or candidate gNB) again, a new KgNB is generated based on the KgNB used last time in this candidate cell (or candidate gNB).
[0755] For example, referring to Figure 6D, assuming that candidate cell 1 corresponds to gNB1 and the corresponding NCC = 2, candidate cell 2 corresponds to gNB2 and the corresponding NCC = 3, the UE first performs LTM access to gNB1, and the UE generates KgNB1-1 based on NCC = 2; then the UE performs LTM access to gNB2, and the UE generates KgNB2-1 based on NCC = 3; then the UE performs LTM access to gNB1, and the UE generates KgNB1-2 based on KgNB1-1; then the UE performs LTM access to gNB2, and the UE generates KgNB2-2 based on KgNB2-1.
[0756] In some embodiments, when performing LTM configuration, the network side pre-configures multiple NCC values for the UE.
[0757] Optionally, the network side may configure an NCC value for each candidate cell (ie, each LTM candidate configuration). For example, the NCC value may be included in the configuration associated with each candidate cell (LTM-Candidate) or the candidate cell configuration (ltm-CandidateConfig).
[0758] Optionally, the network side can configure an NCC value for each cell set (i.e., each candidate gNB), and the candidate cells in the same set are cells under the same candidate gNB.
[0759] It should be noted that the multiple NCC values configured by the network side for the UE are not repeated.
[0760] In some embodiments, in response to the UE performing an LTM Cell Switch, the UE updates a key.
[0761] In some embodiments, the key update process includes the following steps:
[0762] 1. When the UE performs a key update during an LTM Cell Switch, the UE selects the NCC value corresponding to the candidate cell (or the cell set in which the candidate cell is located);
[0763] Optionally, if this NCC value has not been used before (i.e., the UE accesses this candidate cell (or this candidate gNB) for the first time), the UE uses the vertical generation method, and based on the selected NCC value, the UE determines the (corresponding) NH parameter synchronized with this NCC value; the UE generates a new KgNB based on this NH parameter; the UE stores this KgNB and uses this KgNB as the KgNB associated with this candidate cell (or this candidate gNB).
[0764] Optionally, if this NCC value has been used before (i.e., this is not the first time that the UE accesses this candidate cell (or this candidate gNB), the UE determines the KgNB associated with this candidate cell (or this candidate gNB); the UE uses the horizontal generation method to generate a new KgNB based on this KgNB; the UE stores this KgNB and updates this KgNB to the KgNB associated with this candidate cell (or this candidate gNB).
[0765] 2 The UE stores the NCC value selected in 3.1 as the NCC value corresponding to the current KgNB.
[0766] In some embodiments, the UE determines whether the key needs to be updated during the LTM Cell Switch process based on the configuration (or indication information) on the network side (if the gNB remains unchanged before and after the Cell Switch, no key update is required, that is, the current serving cell and the target cell are cells under the same gNB).
[0767] In the embodiments of the present disclosure, some or all of the steps and their optional implementations may be arbitrarily combined with some or all of the steps in other embodiments, or may be arbitrarily combined with the optional implementations of other embodiments.
[0768] The embodiments of the present disclosure further provide an apparatus for implementing any of the above methods. For example, an apparatus is provided, comprising units or modules for implementing each step performed by a terminal in any of the above methods. For another example, another apparatus is provided, comprising units or modules for implementing each step performed by a network device (e.g., an access network device, a core network function node, a core network device, etc.) in any of the above methods.
[0769] It should be understood that the division of the various units or modules in the above device is merely a division of logical functions. In actual implementation, they may be fully or partially integrated into a physical entity, or they may be physically separated. In addition, the units or modules in the device may be implemented in the form of a processor calling software: for example, the device includes a processor, the processor is connected to a memory, and the memory stores instructions. The processor calls the instructions stored in the memory to implement any of the above methods or implement the functions of the various units or modules of the above device, wherein the processor is, for example, a general-purpose processor, such as a central processing unit (CPU) or a microprocessor, and the memory is a memory within the device or a memory outside the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuits, and the functions of some or all of the units or modules can be realized by designing the hardware circuits. The above-mentioned hardware circuits can be understood as one or more processors; for example, in one implementation, the above-mentioned hardware circuit is an application-specific integrated circuit (ASIC), which realizes the functions of some or all of the above units or modules by designing the logical relationship of the components in the circuit; for example, in another implementation, the above-mentioned hardware circuit can be realized by a programmable logic device (PLD). Taking a field programmable gate array (FPGA) as an example, it can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by configuring the configuration file, thereby realizing the functions of some or all of the above units or modules. All units or modules of the above devices can be realized in the form of software called by the processor, or in the form of hardware circuits, or in part by the form of software called by the processor, and the rest by hardware circuits.
[0770] In the embodiments of the present disclosure, the processor is a circuit with signal processing capabilities. In one implementation, the processor can be a circuit with instruction reading and execution capabilities, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), or a digital signal processor (DSP). In another implementation, the processor can implement certain functions through the logical relationship of the hardware circuit. The logical relationship of the above-mentioned hardware circuit is fixed or reconfigurable. For example, the processor is a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document and implementing the hardware circuit configuration can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules. In addition, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), etc.
[0771] Figure 7A is a schematic diagram of the structure of the terminal proposed in an embodiment of the present disclosure. As shown in Figure 7A, the terminal 6100 may include: at least one of a transceiver module 6101, a processing module 6102, etc. In some embodiments, the processing module is used to trigger a mobility operation, determine that a key needs to be updated, and perform a key update operation. Optionally, the transceiver module is used to execute at least one of the communication steps such as sending and / or receiving (for example, step S2101, step S2201, step S2301, but not limited to these) executed by the terminal 101 in any of the above methods, which are not repeated here. Optionally, the processing module is used to execute at least one of the other steps (for example, steps S2102 to S2106, steps S2202 to S2207, steps S2302 to S2308, steps S2401 to S2403, but not limited to these) executed by the terminal 101 in any of the above methods, which are not repeated here.
[0772] FIG7B is a schematic diagram of the structure of a network device proposed in an embodiment of the present disclosure. As shown in FIG7B , the network device 7100 may include: at least one of a transceiver module 7101 and a processing module 7102. In some embodiments, the transceiver module is configured to instruct the terminal to perform a key update operation if it determines that a key update is required when a mobility operation is triggered. Optionally, the transceiver module is configured to perform at least one of the communication steps such as sending and / or receiving performed by the network device 102 in any of the above methods (e.g., steps S2101, S2201, and S2301, but not limited thereto), which are not described in detail here. Optionally, the processing module is configured to perform at least one of the other steps performed by the network device 102 in any of the above methods (e.g., steps S2102 to S2106, steps S2202 to S2207, steps S2302 to S2308, and steps S2401 to S2403, but not limited thereto), which are not described in detail here.
[0773] In some embodiments, the transceiver module may include a transmitting module and / or a receiving module, and the transmitting module and the receiving module may be separate or integrated. Optionally, the transceiver module may be interchangeable with the transceiver.
[0774] In some embodiments, the processing module can be a single module or can include multiple submodules. Optionally, the multiple submodules respectively execute all or part of the steps required to be executed by the processing module. Optionally, the processing module can be interchangeable with the processor.
[0775] Figure 8A is a schematic diagram of the structure of a communication device 8100 proposed in an embodiment of the present disclosure. Communication device 8100 can be a network device (e.g., an access network device, a core network device, etc.), a terminal (e.g., a user equipment, etc.), a chip, a chip system, or a processor that supports a network device to implement any of the above methods, or a chip, a chip system, or a processor that supports a terminal to implement any of the above methods. Communication device 8100 can be used to implement the methods described in the above method embodiments. For details, please refer to the description of the above method embodiments.
[0776] As shown in Figure 8A, the communication device 8100 includes one or more processors 8101. The processor 8101 can be a general-purpose processor or a dedicated processor, for example, a baseband processor or a central processing unit. The baseband processor can be used to process the communication protocol and communication data, and the central processing unit can be used to control the communication device (such as a base station, a baseband chip, a terminal device, a terminal device chip, a DU or a CU, etc.), execute programs, and process program data. Optionally, the communication device 8100 is used to perform any of the above methods. Optionally, one or more processors 8101 are used to call instructions to enable the communication device 8100 to perform any of the above methods.
[0777] In some embodiments, the communication device 8100 further includes one or more transceivers 8102. When the communication device 8100 includes one or more transceivers 8102, the transceiver 8102 performs at least one of the communication steps (e.g., steps S2101, S2201, and S2301, but not limited thereto) of sending and / or receiving in the above method, and the processor 8101 performs at least one of the other steps (e.g., steps S2102 to S2106, steps S2202 to S2207, steps S2302 to S2308, and steps S2401 to S2403, but not limited thereto). In an optional embodiment, the transceiver may include a receiver and / or a transmitter, and the receiver and transmitter may be separate or integrated. Optionally, terms such as transceiver, transceiver unit, transceiver, transceiver circuit, interface circuit, and interface can be replaced with each other, terms such as transmitter, transmitting unit, transmitter, and transmitting circuit can be replaced with each other, and terms such as receiver, receiving unit, receiver, and receiving circuit can be replaced with each other.
[0778] In some embodiments, the communication device 8100 also includes one or more memories 8103 for storing data. Alternatively, all or part of the memories 8103 may be located outside the communication device 8100. In alternative embodiments, the communication device 8100 may include one or more interface circuits 8104. Optionally, the interface circuits 8104 are connected to the transceiver 8102 and may be configured to receive data from the transceiver 8102 or other devices, or to transmit data to the transceiver 8102 or other devices. For example, the interface circuits 8104 may read data stored in the transceiver 8102 and transmit the data to the processor 8101.
[0779] The communication device 8100 described in the above embodiment may be a network device or a terminal, but the scope of the communication device 8100 described in the present disclosure is not limited thereto, and the structure of the communication device 8100 may not be limited by FIG. 8A. The communication device may be an independent device or may be part of a larger device. For example, the communication device may be: 1) an independent integrated circuit IC, or a chip, or a chip system or subsystem; (2) a collection of one or more ICs, optionally, the above IC collection may also include a storage component for storing data or programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, a terminal device, an intelligent terminal device, a cellular phone, a wireless device, a handheld device, a mobile unit, an in-vehicle device, a network device, a cloud device, an artificial intelligence device, etc.; (6) others, etc.
[0780] FIG8B is a schematic diagram of the structure of a chip 8200 according to an embodiment of the present disclosure. If the communication device 8100 can be a chip or a chip system, please refer to the schematic diagram of the structure of the chip 8200 shown in FIG8B , but the present disclosure is not limited thereto.
[0781] The chip 8200 includes one or more processors 8201. The chip 8200 is configured to execute any of the above methods.
[0782] In some embodiments, chip 8200 further includes one or more interface circuits 8202. Terms such as interface circuit, interface, and transceiver pins may be used interchangeably. In some embodiments, chip 8200 further includes one or more memories 8203 for storing data. Alternatively, all or part of memory 8203 may be located external to chip 8200. Optionally, interface circuit 8202 is connected to memory 8203 and may be used to receive data from memory 8203 or other devices, or may be used to send data to memory 8203 or other devices. For example, interface circuit 8202 may read data stored in memory 8203 and send the data to processor 8201.
[0783] In some embodiments, the interface circuit 8202 performs at least one of the communication steps such as sending and / or receiving in the above method (e.g., step S2101, step S2201, step S2301, but not limited thereto). The interface circuit 8202 performing the communication steps such as sending and / or receiving in the above method, for example, means that the interface circuit 8202 performs data exchange between the processor 8201, the chip 8200, the memory 8203, or the transceiver device. In some embodiments, the processor 8201 performs at least one of the other steps (e.g., steps S2102 to S2106, steps S2202 to S2207, steps S2302 to S2308, steps S2401 to S2403, but not limited thereto).
[0784] The modules and / or devices described in various embodiments, such as virtual devices, physical devices, and chips, can be arbitrarily combined or separated according to circumstances. Optionally, some or all steps can also be performed collaboratively by multiple modules and / or devices, which is not limited here.
[0785] The present disclosure also proposes a storage medium having instructions stored thereon, which, when executed on the communication device 8100, causes the communication device 8100 to execute any of the above methods. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer-readable storage medium, but is not limited thereto, and may also be a storage medium readable by other devices. Optionally, the storage medium may be a non-transitory storage medium, but is not limited thereto, and may also be a temporary storage medium.
[0786] The present disclosure also provides a program product, which, when executed by the communication device 8100, enables the communication device 8100 to perform any of the above methods. Optionally, the program product is a computer program product.
[0787] The present disclosure also proposes a computer program, which, when executed on a computer, causes the computer to perform any one of the above methods.
Claims
1. A communication method, characterized in that: Executed by a terminal, the method includes: Trigger the mobility operation, determine that the key needs to be updated, and perform the key update operation.
2. The method according to claim 1, characterized in that The performing of the key update operation includes: generating a first key, where the first key is a key used by the terminal after successfully accessing a second cell from a currently accessed first cell; Successfully access the second cell and use the first key as the activation key.
3. The method according to claim 2, characterized in that Generating the first key includes: Perform at least one of the following operations to generate the first key: First operation; Second operation; The third operation.
4. The method according to claim 2 or 3, characterized in that Generating the first key includes: Determine a first next hop chain counter parameter NCC; According to whether the first NCC is the same as the second NCC, it is determined to perform a corresponding operation to generate the first key, where the second NCC is an NCC associated with a second key, and the second key is a key used by the terminal when camping on the first cell.
5. The method according to claim 4, characterized in that The triggering of the mobility operation includes: A first indication sent by a network device is received, and the mobility operation is triggered.
6. The method according to claim 5, characterized in that The first indication includes a specific NCC; The determining of the first NCC includes: The specific NCC is determined as the first NCC.
7. The method according to claim 4, characterized in that The determining of the first NCC includes: The second NCC is determined as the first NCC.
8. The method according to claim 4, characterized in that The determining of the first NCC includes: The second NCC is increased by N to obtain the first NCC, where N is a natural number greater than 0.
9. The method according to claim 4, characterized in that The terminal is configured with an NCC sequence; The determining of the first NCC includes: A first unused NCC in the NCC sequence is determined as the first NCC.
10. The method according to claim 4, characterized in that The terminal is configured with multiple NCC sequences, and one NCC sequence corresponds to one cell set; The determining of the first NCC includes: A first unused NCC in the NCC sequence corresponding to the cell set to which the second cell belongs is determined as the first NCC.
11. The method according to claim 4, characterized in that The terminal is configured with multiple NCC sequences, one NCC sequence corresponding to one cell; The determining of the first NCC includes: A first unused NCC in the NCC sequence corresponding to the second cell is determined as the first NCC.
12. The method according to claim 4, characterized in that The terminal is configured with multiple NCCs, one NCC corresponding to one cell; The determining of the first NCC includes: An NCC corresponding to the second cell among the multiple NCCs is determined as a first NCC.
13. The method according to claim 12, characterized in that Before determining the first NCC, the method includes: Determining whether the second cell is accessed for the first time; The determining of the first NCC includes: Accessing the second cell for the first time, and determining the first NCC.
14. The method according to claim 4, characterized in that The terminal is configured with multiple NCCs, one NCC corresponding to one cell set; The determining of the first NCC includes: An NCC corresponding to the cell set to which the second cell belongs among the multiple NCCs is determined as a first NCC.
15. The method according to claim 14, characterized in that Before determining the first NCC, the method includes: Determining whether the second cell is the first cell accessed by the terminal in the cell set corresponding to the second cell; The determining of the first NCC includes: The second cell is the first cell accessed by the terminal in the cell set corresponding to the second cell, and the first NCC is determined.
16. The method according to any one of claims 10, 14, and 15, characterized in that: The cells in one cell set correspond to the same access network device.
17. The method according to any one of claims 4 to 16, characterized in that The determining, based on whether the first NCC is the same as the second NCC, to perform a corresponding operation to generate the first key includes: The first NCC is the same as the second NCC and performs a first operation to generate the first key.
18. The method according to any one of claims 4 to 16, characterized in that The determining, based on whether the first NCC is the same as the second NCC, to perform a corresponding operation to generate the first key includes: The first NCC is different from the second NCC, and a second operation is performed to generate the first key.
19. The method according to claim 17 or 18, characterized in that The method further comprises: Associating the first key with the second cell; or, Associating the first key with the cell set to which the second cell belongs; or, The first key is associated with an access network device corresponding to the second cell.
20. The method according to claim 5, characterized in that The first indication also includes a second indication, where the second indication is used to indicate whether the access and mobility management function AMF key is changed; Before determining the first NCC, the method includes: Determining whether the AMF key is changed according to the second indication; The determining of the first NCC includes: Determine, according to the second indication, that the AMF key has not been changed, and determine the first NCC.
21. The method according to claim 20, characterized in that The method further comprises: Determine the AMF key change according to the second indication, and generate the first key according to the changed AMF key.
22. The method according to any one of claims 5, 6, 20 and 21, characterized in that The method further comprises: The specific NCC and / or the second indication is determined according to the first field in the first indication.
23. The method according to claim 22, characterized in that The first indication is a cell handover command medium access control element MAC CE, and the first field is a reserved field.
24. The method according to claim 13, wherein The method further comprises: This is not the first time accessing the second cell, and performing the third operation to generate the first key.
25. The method according to claim 15, wherein The method further comprises: The second cell is not the first cell accessed by the terminal in the cell set corresponding to the second cell, and a third operation is performed to generate the first key.
26. The method according to claim 17, wherein The performing the first operation to generate the first key includes: The first key is generated according to the second key, the identifier of the second cell, and the frequency information of the second cell.
27. The method according to claim 18, wherein The performing the second operation to generate the first key includes: Determine a first next hop parameter NH corresponding to the first NCC; The first key is generated according to the first NH, the identifier of the second cell, and the frequency information of the second cell.
28. The method according to claim 24 or 25, characterized in that The performing the third operation to generate the first key includes: The first key is generated according to a third key, an identifier of the second cell, and frequency information of the second cell.
29. The method according to claim 28, characterized in that The third key is at least one of the following keys: a key associated with the second cell; a key associated with the cell set to which the second cell belongs; A key associated with the access network device corresponding to the second cell.
30. The method according to any one of claims 5, 6, 20-22, characterized in that Before determining that a key needs to be updated, the following steps are included: It is determined that the first indication includes first information, where the first information is a specific NCC and / or a second indication.
31. The method according to any one of claims 1 to 29, wherein Before determining that a key needs to be updated, the method includes: Determine whether a key update instruction sent by the network device is received.
32. The method according to any one of claims 1 to 31, characterized in that The mobility operation includes at least one of the following: Mobility LTM cell switching based on layer L1 / L2 triggering; Condition-based switching CHO.
33. A communication method, characterized in that: Executed by a network device, the method includes: Instructs the terminal to perform a key update operation if it determines that a key update is required when a mobility operation is triggered.
34. A terminal, characterized in that: include: The processing module is used to trigger the mobility operation, determine that the key needs to be updated, and perform the key update operation.
35. A network device, characterized in that: include: The transceiver module is used to instruct the terminal to perform a key update operation if it is determined that the key needs to be updated when the mobility operation is triggered.
36. A terminal, characterized in that: include: one or more processors; A memory coupled to the processor, wherein the memory stores executable instructions, and when the executable instructions are executed by the processor, the terminal executes the communication method according to any one of claims 1 to 32.
37. A network device, characterized in that: include: one or more processors; A memory coupled to the processor, wherein executable instructions are stored in the memory, and when the executable instructions are executed by the processor, the network device executes the communication method described in claim 33.
38. A communication system, characterized in that: The invention comprises a terminal and a network device, wherein the terminal is configured to implement the communication method according to any one of claims 1 to 32, and the network device is configured to implement the communication method according to any one of claim 33.
39. A storage medium storing instructions, characterized in that: When the instruction is executed on a communication device, the communication device is caused to execute the communication method according to any one of claims 1 to 33.
Citation Information
Patent Citations
Release of conditional primary-secondary cell addition / modification configuration
CN114521347A
Information processing method, terminal, communication system and storage medium
CN117136615A
Method and apparatus for performing handover in wireless communication system
US20210136635A1
Release of configurations for conditional handovers based on security configurations
US20220330125A1