Security information configuration method and system, and apparatus

By configuring security algorithms for terminal devices in the 5G network, the problem of unverified emergency services not being able to proceed normally during the switching process is solved, the reliability and continuity of emergency calls are achieved, and regulatory requirements are met.

WO2025200323A1PCT designated stage Publication Date: 2025-10-02CHINA TELECOM INTELLIGENT NETWORK TECHNOLOGY CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/118453
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-29
Filing Date
2024-09-12
Publication Date
2025-10-02

AI Technical Summary

Technical Problem

In 5G networks, unverified emergency service requirements prevent terminal devices from effectively configuring security algorithms during the handover process, resulting in emergency calls being unable to proceed normally. Especially when identity authentication is not passed, existing technologies cannot meet regulatory requirements in some regions.

Method used

A security information configuration method is provided to enable a terminal device to ensure the provision of emergency services in a 5G network by using either the security algorithm of a first wireless standard or the security algorithm of a second wireless standard during a handover process, even if the terminal device has not passed identity verification. The method includes configuring integrity protection and encryption algorithms for signaling and data radio bearers in RRC messages to ensure security and continuity of emergency services during the handover process.

Benefits of technology

It enables terminal devices to make emergency calls normally in 5G networks without authentication, meets the requirements of unauthenticated emergency services, and ensures the reliability and continuity of emergency services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024118453_02102025_PF_FP_ABST
    Figure CN2024118453_02102025_PF_FP_ABST
Patent Text Reader

Abstract

The present application discloses a security information configuration method and system, and an apparatus. The method comprises: when a terminal device does not have valid subscription information of a second wireless standard and the Internet protocol multimedia subsystem (IMS) emergency service of the terminal device is activated, it is determined by a core network of the second wireless standard that the terminal device has not passed identity verification; and when the terminal device has completed the switching action and a second base station supports providing the IMS emergency service for the terminal device which has not passed the identity verification, the terminal device uses at least one of a null integrity protection algorithm and a null encryption algorithm.
Need to check novelty before this filing date? Find Prior Art

Description

Security information configuration method, system, and device

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application is based on and claims priority to an application filed in China with application number 202410382315.0, filed on March 29, 2024. The disclosure of the application in China is hereby incorporated as a whole into this application. Technical Field

[0003] The present application relates to the field of wireless communication technology, and in particular to a method, system, and device for configuring security information. Background Art

[0004] Compared with the fourth generation mobile communication technology (4G) network, the fifth generation mobile communication technology (5G) wireless network introduces a design architecture that separates the control plane entity (CP) and the user plane entity (UP).

[0005] Figure 1 shows a 5G base station architecture with separate control plane and user plane entities. As shown in Figure 1, the gNB is the next generation NodeB (i.e., a 5G base station), and the eNB is the evolved NodeB (i.e., a 4G base station). The centralized unit-control plane (CU-CP) entity supports the Service Data Adaptation Protocol (SDAP) and Packet Data Convergence Protocol (PDCP), while the centralized unit-user plane (CU-UP) entity supports the Radio Resource Control (RRC) layer protocols. The distributed unit (DU) supports the physical layer, medium access control (MAC) layer, and radio link control (RLC) layer protocols. The CU-CP and CU-UP communicate using the E1 interface.

[0006] Emergency Calling, a special service developed after the widespread availability of telephone services, allows mobile users to dial a number in an emergency to the emergency service center closest to their current base station. Emergency Calling requires the network to forward the call to a specific emergency service center number. This service takes precedence over other services and allows successful calls even when a user is in arrears or their service is disconnected, demonstrating the operator's commitment to social responsibility.

[0007] Telecom operators have a long history of deploying emergency call services, offering services since the circuit-switched era. In the early days of 4G network deployment, operators typically implemented a circuit-switched fallback (CSFB) solution for emergency calls. Specifically, a terminal initiated a standard Voice over Long Term Evolution (VoLTE) call. Upon reaching the Session Border Controller (SBC), the caller configured an emergency call list and responded with a 380 message for the relevant call. Upon receiving the message, the terminal then performed CSFB. This approach is still used in some regions today, so compatibility with this networking approach remains a concern.

[0008] Currently, 5G emergency calls include four methods, and the current 3rd Generation Partnership Project (3GPP) agreement mainly describes the first two methods.

[0009] Voice over New Radio (VoNR): An Emergency-Packet Data Unit (E-PDU) is established directly over the New Radio (NR). The E-PDU then uses it to provide emergency call control (ECC) services to the IP Multimedia Subsystem Emergency Communication Service (IMS). The network must set EM Cindicator to True in the 5G MM Registration Accept field.

[0010] Evolved Packet System FallBack (EPSFB): An attempt is made to establish E-PDUs on NR. The network actively triggers a handover (HO) or redirection procedure to bring the user equipment (UE) to LTE. IMS ECC is then completed over the Emergency Packet Data Network (E-PDN). The network sets the EM Cindicator (Emergency Mode Cindicator) to True in the 5G MM (Mobility Management) Registration Accept.

[0011] There is a special service in emergency calls, namely unauthenticated emergency services. In this application, "unauthenticated" is used to represent the meaning of unauthenticated. Unauthenticated emergency services are intended to meet regulatory requirements in certain regions. 5G systems should support unauthenticated emergency service access. This requirement applies to all terminal devices and only to service networks with regulatory requirements for unauthenticated emergency services. Service networks located in areas where unauthenticated emergency services are prohibited should not support this feature.

[0012] The security algorithms used in 4G / 5G are based on the following three algorithms: Snow 3G, Advanced Encryption Standard (AES), and Zu Chongzhi Stream Cipher Algorithm (ZUC). The security algorithm selection in 4G / 5G refers to these three algorithms, which are encapsulated in 4G / 5G to implement integrity protection / verification and encryption / decryption processes. Their corresponding names are as follows.

[0013] Snow 3G: "4G encryption / decryption algorithm" 128-EEA1 (EEA stands for EPS Encryption Algorithm, Evolved Packet System Encryption Algorithm) and "5G encryption / decryption algorithm" 128-NEA1 (NEA stands for NR Encryption Algorithm, New Air Interface Encryption Algorithm); "4G integrity protection / verification algorithm" 128-EIA1 (EIA stands for EPS Integrity Algorithm, Evolved Packet System Integrity Algorithm) and "5G integrity protection / verification algorithm" 128-NIA1 (NIA stands for NR Integrity Algorithm, New Air Interface Integrity Algorithm).

[0014] AES: "4G encryption / decryption algorithm" 128-EEA2 and "5G encryption / decryption algorithm" 128-NEA2; "4G integrity protection / verification algorithm" 128-EIA2 and "5G integrity protection / verification algorithm" 128-NIA2.

[0015] ZUC: "4G encryption / decryption algorithm" 128-EEA3 and "5G encryption / decryption algorithm" 128-NEA3; "4G integrity protection / verification algorithm" 128-EIA3 and "5G integrity protection / verification algorithm" 128-NIA3.

[0016] In the current RRC message, the 5G base station side can configure the following encryption and integrity protection algorithms for the UE through RRC messages:

[0017] Currently, for integrity protection algorithms, the base station side only supports nia0, nia1, nia2, and nia3, and the encryption algorithm only supports nea0, nea1, nea2, and nea3.

[0018] As shown in Figure 2, during the bearer establishment or bearer modification process between the CU-CP and the CU-UP, it is also necessary to configure the security algorithm for the user plane on the base station side. The specific parameter configuration is shown in Table 1:

[0019] Table 1

[0020] Summary of the Invention

[0021] According to one aspect of an embodiment of the present application, a method for configuring security information is provided, including: when a terminal device does not have valid subscription information of a second wireless standard and the Internet Protocol Multimedia Subsystem IMS emergency service of the terminal device is activated, the terminal device is determined by the core network of the second wireless standard as failing to pass identity authentication; after the terminal device completes the switching action, and when the second base station supports providing IMS emergency services to terminal devices that have not passed identity authentication, the terminal device uses at least one of a null integrity protection algorithm and a null encryption algorithm, wherein the switching action includes: switching from a first base station of a first wireless standard to a second base station of a second wireless standard, or switching within a cell within the second base station, or switching between cells within the second base station, or switching from a third base station of the second wireless standard to a second base station of the second wireless standard, the null encryption algorithm includes: the null encryption algorithm of the first wireless standard or the null encryption algorithm of the second wireless standard, and the null integrity protection algorithm includes: the null integrity protection algorithm of the first wireless standard or the null integrity protection algorithm of the second wireless standard.

[0022] Optionally, the second wireless standard is a wireless standard subsequent to the first wireless standard.

[0023] Optionally, the first wireless standard includes: 4th Generation Mobile Communication Technology Long Term Evolution (4G LTE) or 5th Generation Mobile Communication Technology New Radio (5GNR); the second wireless standard includes: 5th Generation Mobile Communication Technology New Radio 5G NR or 6th Generation Mobile Communication Technology (6G); the core network of the second wireless standard includes: 5G control plane entity or 6G control plane entity, wherein the 5G control plane entity includes: Access and Mobility Management Function (AMF).

[0024] Optionally, the signaling radio bearer SRB and the data radio bearer DRB between the terminal device and the second base station are configured in the radio resource control RRC message to use at least one of the empty integrity protection algorithm and the empty encryption algorithm; or, when the RRC message is not configured with any integrity protection algorithm or any encryption algorithm, the terminal device adopts at least one of the integrity protection algorithm and the encryption algorithm used before completing the switching action.

[0025] Optionally, when the RRC switching command message or RRC reconfiguration message received by the terminal device does not carry a security algorithm, the terminal device adopts the security algorithm used before switching to the second base station, wherein the RRC switching command message or RRC reconfiguration message is sent by the second base station or the second base station control plane entity.

[0026] Optionally, when the terminal device receives an RRC switching command message at the first base station instructing the terminal device to switch to the second base station, and the RRC switching command message does not carry a new security algorithm, after switching to the second base station, the terminal device adopts at least one of the integrity protection algorithm of the first wireless standard and the encryption algorithm of the first wireless standard.

[0027] Optionally, the security algorithm includes: at least one of an integrity protection algorithm and an encryption algorithm, wherein the integrity protection algorithm is a 128-bit integrity protection algorithm or a 256-bit integrity protection algorithm; the encryption algorithm is a 128-bit encryption algorithm or a 256-bit encryption algorithm; the integrity protection algorithm includes at least one of the following: one or more integrity protection algorithms of the first wireless standard, one or more integrity protection algorithms of the second wireless standard; the encryption algorithm includes at least one of the following: one or more encryption algorithms of the second wireless standard, one or more encryption algorithms of the second wireless standard.

[0028] Optionally, the integrity protection algorithm of the SRB includes: the null integrity protection algorithm of the first wireless standard or the null integrity protection algorithm of the second wireless standard; the integrity protection algorithm of the DRB does not include: the null integrity protection algorithm of the first wireless standard or the null integrity protection algorithm of the second wireless standard.

[0029] Optionally, the RRC switching command message or RRC reconfiguration message is generated by the second base station or the first base station; the RRC switching command message or RRC reconfiguration message is used to instruct the terminal device to switch between cells within the second base station, or to switch from the first base station to the second base station.

[0030] Optionally, the RRC handover command or the RRC reconfiguration message includes one of the following: a target cell identifier, second security configuration information, wherein the second security configuration information carries or does not carry a new security algorithm.

[0031] Optionally, the RRC switching command or RRC reconfiguration message further includes at least one of the following: identification information of one or more SRBs, identification information of one or more DRBs, Packet Data Convergence Protocol (PDCP) configuration information, and key configuration information.

[0032] Optionally, the PDCP configuration information is based on the second wireless standard; the key configuration information is a primary key configuration or a secondary key configuration based on the second wireless standard; the target cell identifier is the first cell identifier within the second base station when switching from the first base station to the second base station, or the second cell identifier when switching within the second base station.

[0033] Optionally, when the second security configuration information carries an integrity protection algorithm, the integrity protection algorithm includes at least one of the following: a null integrity protection algorithm of the first wireless standard, a null integrity protection algorithm of the second wireless standard, wherein the null integrity protection algorithm is used for SRB.

[0034] Optionally, when the encryption algorithm is carried in the second security configuration information, the encryption algorithm includes at least one of the following: a null encryption algorithm of the first wireless standard, a null encryption algorithm of the second wireless standard, wherein the encryption algorithm is used for SRB and DRB.

[0035] Optionally, after the terminal device adopts the security algorithm used before switching to the second base station, the method also includes: the terminal device configures the SRB according to the second security configuration information; the terminal device configures the DRB according to the second security configuration information.

[0036] Optionally, the terminal device configures the SRB according to the second security configuration information, including: if the identification information of the SRB currently adopted by the terminal device is not included in the second security configuration information, performing the following steps: establishing a PDCP entity of the SRB, configuring at least one of the integrity protection algorithm and the encryption algorithm adopted by the PDCP entity of the SRB to be the security configuration algorithm indicated in the second security configuration information, and applying a primary key or a secondary key, wherein the integrity protection algorithm is the empty integrity protection algorithm of the first wireless standard, and the encryption algorithm is the empty encryption algorithm of the first wireless standard; when the current configuration of the terminal device is the configuration of the first wireless standard and the identification information of the SRB currently adopted by the terminal device is included in the second security configuration information, deleting the PDCP configuration of the first wireless standard associated with the identification information of the SRB currently adopted by the terminal device.

[0037] Optionally, the terminal device configures the SRB according to the second security configuration information, including: if the identification information of the SRB currently used by the terminal device is included in the second security configuration information, performing the following steps: establishing a PDCP entity of the SRB; configuring at least one of the integrity protection and encryption algorithms used by the PDCP entity of the SRB to be the security configuration algorithm indicated in the information in the second security configuration, and applying a primary key or a secondary key, wherein the integrity protection algorithm is the null integrity protection algorithm of the first wireless standard, and the encryption algorithm is the null encryption algorithm of the first wireless standard.

[0038] Optionally, the terminal device configures the DRB according to the second security configuration information, including: if the identification information of the DRB currently used by the terminal device is not included in the second security configuration information, performing the following steps: establishing a PDCP entity for the DRB, configuring the encryption algorithm used by the PDCP entity of the DRB to be the security configuration algorithm indicated in the second security configuration information, and applying a primary key or a secondary key, wherein the integrity protection algorithm is the empty integrity protection algorithm of the first wireless standard, and the encryption algorithm is the empty encryption algorithm of the first wireless standard; when the current configuration of the terminal device is the configuration of the first wireless standard and the identification information of the DRB currently used by the terminal device is included in the second security configuration information, deleting the PDCP configuration of the first wireless standard associated with the identification information of the DRB currently used by the terminal device.

[0039] Optionally, the terminal device configures the DRB according to the second security configuration information, including: if the identification information of the DRB currently used by the terminal device is included in the second security configuration information, executing the following steps: establishing a PDCP entity for the DRB; configuring the encryption algorithm used by the PDCP entity of the DRB to be the security configuration algorithm indicated in the second security configuration information, and applying a primary key or a secondary key, wherein the integrity protection algorithm is the null integrity protection algorithm of the first wireless standard, and the encryption algorithm is the null encryption algorithm of the first wireless standard.

[0040] Optionally, after the terminal device switches to the second base station and adopts at least one of the integrity protection algorithm of the first wireless standard and the encryption algorithm of the first wireless standard, the method also includes: the terminal device configures the SRB according to the second security configuration information; the terminal device configures the DRB according to the second security configuration information.

[0041] Optionally, the terminal device configures the SRB according to the second security configuration information, including: if the identification information of the SRB currently used by the terminal device is not included in the second security configuration information, performing the following steps: establishing a PDCP entity of the SRB; configuring at least one of the integrity protection algorithm and encryption algorithm used by the PDCP entity of the SRB to be the algorithm currently used in the first wireless standard, and applying a primary key or a secondary key, wherein the integrity protection algorithm is the empty integrity protection algorithm of the first wireless standard, and the encryption algorithm is the empty encryption algorithm of the first wireless standard.

[0042] Optionally, if the current configuration of the terminal device is a configuration of the first wireless standard, and the identification information of the SRB currently used by the terminal device is included in the second security configuration information, perform the following steps: delete the PDCP configuration of the first wireless standard associated with the identification information of the SRB currently used by the terminal device.

[0043] Optionally, the terminal device configures the SRB according to the second security configuration information, including: if the identification information of the SRB currently adopted by the terminal device is included in the second security configuration information, performing the following steps: establishing a PDCP entity of the SRB; configuring at least one of the integrity protection and encryption algorithms adopted by the PDCP entity of the SRB to be the algorithm currently used in the first wireless standard, and applying a primary key or a secondary key, wherein the integrity protection algorithm is the null integrity protection algorithm of the first wireless standard, and the encryption algorithm is the null encryption algorithm of the first wireless standard.

[0044] Optionally, the terminal device configures the DRB according to the second security configuration information, including: if the identification information of the DRB currently used by the terminal device is included in the second security configuration information, executing the following steps: establishing a PDCP entity for the DRB; configuring the encryption algorithm used by the PDCP entity of the DRB to be the algorithm currently used in the first wireless standard, and applying a primary key or a secondary key, wherein the integrity protection algorithm is the null integrity protection algorithm of the first wireless standard, and the encryption algorithm is the null encryption algorithm of the first wireless standard.

[0045] Optionally, if the current configuration of the terminal device is a configuration of the first wireless standard, and the identification information of the DRB currently used by the terminal device is included in the second security configuration information, perform the following steps: delete the PDCP configuration of the first wireless standard associated with the identification information of the DRB currently used by the terminal device.

[0046] Optionally, the terminal device configures the DRB according to the second security configuration information, including: if the identification information of the DRB currently used by the terminal device is included in the second security configuration information, executing the following steps: establishing a PDCP entity for the DRB; configuring the encryption algorithm used by the PDCP entity of the DRB to be the algorithm currently used in the first wireless standard, and applying a primary key or a secondary key, wherein the integrity protection algorithm is the null integrity protection algorithm of the first wireless standard, and the encryption algorithm is the null encryption algorithm of the first wireless standard.

[0047] Optionally, after the terminal device configures the DRB according to the second security configuration information, the method also includes: accessing the second base station or the second cell in the second base station.

[0048] Optionally, when the null integrity protection algorithm of the first wireless standard is configured, the value of the non-access stratum counter (NAS COUNT) is flipped, and the updated key has not been configured before the value of the NAS COUNT is flipped, the terminal device maintains a NAS connection with the core network of the second wireless standard.

[0049] According to another aspect of the embodiments of the present application, a method for configuring security information is provided, including:

[0050] After receiving the switching request message, configure at least one of the empty security algorithm of the first wireless standard and the empty security algorithm of the second wireless standard for the terminal device, and send the empty security algorithm of the first wireless standard or the empty security algorithm of the second wireless standard or the security configuration information that does not carry any integrity protection algorithm or encryption algorithm to the core network or the third base station of the second wireless standard through a switching response message, wherein the switching request message includes at least one of the following: identification information assigned to the terminal device in the core network, security algorithm configuration adopted by the terminal device in the first base station of the first wireless standard or the third base station of the second wireless standard, and wireless bearer configuration; the empty security algorithm includes: empty integrity protection algorithm; The security algorithm configuration includes at least one of the following: at least one of the null integrity protection algorithm and the null encryption algorithm of the first wireless standard, and at least one of the null integrity protection algorithm and the null encryption algorithm of the second wireless standard; the wireless bearer configuration includes at least one of the following: Internet Protocol Multimedia Subsystem IMS bearer configuration information and service bearer configuration information; the IMS bearer configuration information includes at least one of the following: the quality of service QoS identifier, allocation information and retention priority information of the first wireless standard or the second wireless standard; the numerical values ​​in the allocation information and the retention priority information are used to indicate the purpose of the IMS emergency service in the 5G access network.

[0051] Optionally, the second wireless standard is a wireless standard subsequent to the first wireless standard.

[0052] Optionally, the first wireless standard includes: the fourth generation mobile communication technology long term evolution 4G LTE or the fifth generation mobile communication technology new air interface 5G NR; the second wireless standard includes: the fifth generation mobile communication technology new air interface 5G NR or the sixth generation mobile communication technology 6G; the core network of the second wireless standard includes: a 5G control plane entity or a 6G control plane entity, wherein the 5G control plane entity includes: an access and mobility management function entity AMF.

[0053] Optionally, if the switching request message is a message sent by the first base station and forwarded by the core network control plane entity, or the switching request message is a message sent by the first base station using the second wireless standard, the switching request message is received through a direct interface between the first base station and the second base station.

[0054] Optionally, the broadcast message of the second base station indicates whether the cell supports provision of IMS emergency services to terminal devices that have not passed identity authentication.

[0055] Optionally, after receiving the switching request message, and when the second base station supports the provision of IMS emergency services to terminal devices that have not passed identity authentication and the second base station supports the null security algorithm of the first wireless standard, the first security configuration information and the service bearer configuration information are notified to the user plane entity of the second base station through a request message within the first base station, wherein the first security configuration information includes at least one of the following: the null encryption algorithm of the first wireless standard, the null encryption algorithm of the second wireless standard; the service bearer configuration information includes: wireless bearer configuration.

[0056] Optionally, the switching request message also includes at least one of the following: the security capabilities of the terminal device and the currently used key, wherein the integrity protection algorithm in the security capability includes: the empty integrity protection algorithm of the first wireless standard, and the encryption algorithm in the security capability includes at least one of the following: the empty encryption algorithm of the first wireless standard and the empty encryption algorithm of the second wireless standard.

[0057] Optionally, after receiving the switching request message, if the broadcast message of the second base station indicates that the cell supports providing IMS emergency services to terminal devices that have not passed identity authentication, the integrity protection algorithm, encryption algorithm and update key after the terminal device switches to the second base station are determined according to the integrity protection algorithm in the security capability.

[0058] Optionally, after receiving the switching request message, if the control plane entity of the second base station does not support the null security algorithm of the first wireless standard, or the broadcast message of the second base station indicates that the cell does not support the provision of IMS emergency services to terminal devices that have not passed the authentication, or the broadcast message of the second base station does not configure whether the cell supports the provision of IMS emergency services to terminal devices that have not passed the authentication, a switching failure message is generated.

[0059] Optionally, the switching failure message includes: a first failure reason, and the first failure reason includes at least one of the following: the integrity protection algorithm cannot be supported, and the null encryption algorithm cannot be supported.

[0060] Optionally, the first security configuration information includes: an encryption algorithm, the encryption algorithm includes at least one of the following: an empty encryption algorithm of the first wireless standard, an empty encryption algorithm of the second wireless standard, wherein the second base station user plane entity is used to receive the first security configuration information, configure the encryption algorithm of the terminal device according to the first security configuration information, and determine whether the terminal device adopts an IMS emergency service that has not passed authentication based on the configured empty integrity protection algorithm of the first wireless standard, at least one of the encryption algorithms, the allocation information in the IMS bearer configuration information, and the numerical value in the retention priority information.

[0061] Optionally, when it is determined that the terminal device uses an IMS emergency service that has not passed authentication, a first base station confirmation message sent by a second base station user plane entity is received, wherein the second base station user plane entity is used to maintain a different wireless side key from the terminal device, and the first base station confirmation message is used to confirm that the security configuration of the terminal device is completed, wherein the second base station user plane entity is used to send the first base station failure message to the second base station control plane entity when it is confirmed that the empty security algorithm of the first wireless standard cannot be supported based on the first security configuration information in the first base station request message, wherein the first base station failure message is used to confirm that the empty security algorithm of the first wireless standard cannot be supported, and the first base station failure message includes: a second failure reason, and the second failure reason includes: the empty encryption algorithm cannot be supported.

[0062] Optionally, after receiving the first base station confirmation message sent by the second base station user plane entity, if the switching request message comes from the core network, a switching confirmation message is sent to the first base station through the core network, or, after receiving the first base station failure message, a switching failure message is sent to the first base station.

[0063] Optionally, the switching failure message includes: a first failure reason, wherein the first failure reason is determined based on the second failure reason. When the second failure reason is that the empty encryption algorithm cannot be supported, the first failure reason is set to that the empty encryption algorithm cannot be supported.

[0064] Optionally, an RRC reconfiguration message is generated in the handover confirmation message and sent to the terminal device, wherein the RRC reconfiguration message includes: second security configuration information of the terminal device.

[0065] Optionally, the integrity protection algorithm in the second security configuration information includes at least one of the following: an empty integrity protection algorithm of the first wireless standard, the encryption algorithm in the second security configuration information is an empty encryption algorithm of the first wireless standard, and the encryption algorithm in the second security configuration information is an empty encryption algorithm of the second wireless standard.

[0066] Optionally, a switching confirmation message or a switching failure message is sent to the core network, wherein the core network is used to forward the switching confirmation message or the switching failure message to the first base station, and the first base station is used to send the switching confirmation message to the terminal device through an RRC message after receiving the switching confirmation message, and the switching confirmation message includes: second security configuration information, wherein the first base station is used to determine the security support capability of the second base station according to the first failure cause in the switching failure message after receiving the switching failure message, wherein the security support capability includes at least one of the following: the air integrity protection algorithm of the first wireless standard, the encryption algorithm of the first wireless standard; the first base station is also used to add the security support capability of the second base station to the neighboring cell list information of the first base station and the second base station.

[0067] Optionally, a path switching response message sent by the core network is received, wherein the path switching response message includes: user plane security configuration, and policies for encryption and integrity protection in the user plane security configuration are both set to "No Needed" mode.

[0068] According to another aspect of the embodiment of the present application, a security information configuration system is also provided, including: a terminal device, a first base station, a core network, and a second base station, the second base station including: a second base station control plane entity and a second base station user plane entity, wherein the terminal device is used to be determined by the core network of the second wireless standard as failing to pass identity authentication when there is no valid contract information of the second wireless standard and the Internet Protocol Multimedia Subsystem IMS emergency service is activated; the terminal device is also used to use at least one of an empty integrity protection algorithm and an empty encryption algorithm after completing the switching action and when the second base station supports the provision of IMS emergency services to terminal devices that have not passed identity authentication, wherein the switching action includes: switching from a first base station of the first wireless standard to a second base station of the second wireless standard, or switching within a cell within the second base station, or switching between cells within the second base station, or switching from a third base station of the second wireless standard to a second base station of the second wireless standard, the empty encryption algorithm includes: the first wireless standard The empty encryption algorithm of the first wireless standard or the empty encryption algorithm of the second wireless standard, the empty integrity protection algorithm includes: the empty integrity protection algorithm of the first wireless standard or the empty integrity protection algorithm of the second wireless standard; the first base station is connected to the second base station through the core network; the second base station control plane entity is used to configure the empty security algorithm of the first wireless standard and the empty security algorithm of the second wireless standard for the terminal device after receiving the switching request message, and send the empty security algorithm of the first wireless standard or the empty security algorithm of the second wireless standard or the security configuration information that does not carry any integrity protection algorithm or encryption algorithm to the core network or the third base station of the second wireless standard through the switching response message; the second base station user plane entity is used to receive the first security configuration information and service bearer configuration information sent by the second base station control plane entity after the second base station control plane entity receives the switching request message, and when the second base station supports the provision of IMS emergency services to terminal devices that have not passed authentication and the second base station supports the empty security algorithm of the first wireless standard.

[0069] Optionally, the second wireless standard is a wireless standard subsequent to the first wireless standard.

[0070] Optionally, the first wireless standard includes: the fourth generation mobile communication technology long term evolution 4G LTE or the fifth generation mobile communication technology new air interface 5G NR; the second wireless standard includes: the fifth generation mobile communication technology new air interface 5G NR or the sixth generation mobile communication technology 6G; the core network of the second wireless standard includes: a 5G control plane entity or a 6G control plane entity, wherein the 5G control plane entity includes: an access and mobility management function entity AMF.

[0071] Optionally, the signaling radio bearer SRB and the data radio bearer DRB between the terminal device and the second base station are configured in the radio resource control RRC message to use at least one of an empty integrity protection algorithm and an empty encryption algorithm; or, when the RRC message is not configured with any integrity protection algorithm or any encryption algorithm, the terminal device is configured to adopt at least one of the integrity protection algorithm and encryption algorithm used before completing the switching action.

[0072] Optionally, the terminal device is configured to adopt the security algorithm used before switching to the second base station when the RRC switching command message or RRC reconfiguration message received by the terminal device does not carry a new security algorithm, wherein the RRC switching command message or RRC reconfiguration message is sent by the second base station or the second base station control plane entity.

[0073] Optionally, the terminal device is configured to adopt at least one of the integrity protection algorithm of the first wireless standard and the encryption algorithm of the first wireless standard after switching to the second base station if the terminal device receives an RRC switching command message at the first base station instructing the terminal device to switch to the second base station, and the RRC switching command message does not carry a new security algorithm.

[0074] Optionally, the security algorithm includes: at least one of an integrity protection algorithm and an encryption algorithm, wherein the integrity protection algorithm is a 128-bit integrity protection algorithm or a 256-bit integrity protection algorithm; the encryption algorithm is a 128-bit encryption algorithm or a 256-bit encryption algorithm; the integrity protection algorithm includes at least one of the following: one or more integrity protection algorithms of the first wireless standard, one or more integrity protection algorithms of the second wireless standard; the encryption algorithm includes at least one of the following: one or more encryption algorithms of the second wireless standard, one or more encryption algorithms of the second wireless standard.

[0075] Optionally, the integrity protection algorithm of the SRB includes: the null integrity protection algorithm of the first wireless standard or the null integrity protection algorithm of the second wireless standard; the integrity protection algorithm of the DRB does not include: the null integrity protection algorithm of the first wireless standard or the null integrity protection algorithm of the second wireless standard.

[0076] Optionally, the RRC switching command message or RRC reconfiguration message is generated by the second base station or the first base station; the RRC switching command message or RRC reconfiguration message is used to instruct the terminal device to switch between cells within the second base station, or to switch from the first base station to the second base station.

[0077] Optionally, the RRC handover command or the RRC reconfiguration message includes one of the following: a target cell identifier, second security configuration information, wherein the second security configuration information carries or does not carry a new security algorithm.

[0078] Optionally, the RRC switching command or RRC reconfiguration message further includes at least one of the following: identification information of one or more SRBs, identification information of one or more DRBs, Packet Data Convergence Protocol PDCP configuration information, and key configuration information.

[0079] Optionally, the PDCP configuration information is based on the second wireless standard; the key configuration information is a primary key configuration or a secondary key configuration based on the second wireless standard; the target cell identifier is the first cell identifier within the second base station when switching from the first base station to the second base station, or the second cell identifier when switching within the second base station.

[0080] Optionally, when the second security configuration information carries an integrity protection algorithm, a null integrity protection algorithm is used for SRB, and the integrity protection algorithm includes at least one of the following: a null integrity protection algorithm of the first wireless standard, and a null integrity protection algorithm of the second wireless standard.

[0081] Optionally, when the second security configuration information carries an integrity protection algorithm, the integrity protection algorithm includes at least one of the following: an empty integrity protection algorithm of the first wireless standard, an empty integrity protection algorithm of the second wireless standard, wherein the empty integrity protection algorithm is used for SRB; when the second security configuration information carries an integrity protection algorithm, the integrity protection algorithm includes at least one of the following: an empty integrity protection algorithm of the first wireless standard, an empty integrity protection algorithm of the second wireless standard, wherein the empty integrity protection algorithm is used for SRB.

[0082] Optionally, the terminal device is configured to maintain a NAS connection with the core network of the second wireless standard when the null integrity protection algorithm of the first wireless standard is configured, the value of the non-access layer counter NAS COUNT is flipped, and the updated key has not been configured before the value of the NAS COUNT is flipped.

[0083] Optionally, the switching request message includes at least one of the following: identification information assigned to the terminal device in the core network, security algorithm configuration and wireless bearer configuration adopted by the terminal device in the first base station of the first wireless standard or the third base station of the second wireless standard; the empty security algorithm includes: at least one of the empty integrity protection algorithm and the empty encryption algorithm; the security algorithm configuration includes at least one of the following: at least one of the empty integrity protection algorithm and the empty encryption algorithm of the first wireless standard, and at least one of the empty integrity protection algorithm and the empty encryption algorithm of the second wireless standard; the wireless bearer configuration includes at least one of the following: Internet Protocol Multimedia Subsystem IMS bearer configuration information and service bearer configuration information; the IMS bearer configuration information includes at least one of the following: quality of service QoS identifier, allocation information and retention priority information of the first wireless standard or the second wireless standard; the numerical values ​​in the allocation information and the retention priority information are used to indicate the purpose of IMS emergency services in the 5G access network.

[0084] Optionally, the second base station control plane entity is configured to receive the switching request message through a direct interface between the first base station and the second base station if the switching request message is a message sent by the first base station and forwarded by the core network control plane entity, or if the switching request message is a message sent by the first base station using the second wireless standard.

[0085] Optionally, the broadcast message of the second base station indicates whether the cell supports provision of IMS emergency services to terminal devices that have not passed identity authentication.

[0086] Optionally, the second base station control plane entity is configured to, after receiving the switching request message, and when the second base station supports the provision of IMS emergency services to terminal devices that have not passed identity authentication and the second base station supports the null security algorithm of the first wireless standard, notify the second base station user plane entity of the first security configuration information and the service bearer configuration information through a request message within the first base station, wherein the first security configuration information includes at least one of the following: the null encryption algorithm of the first wireless standard, the null encryption algorithm of the second wireless standard; the service bearer configuration information includes: wireless bearer configuration.

[0087] Optionally, the switching request message also includes at least one of the following: the security capabilities of the terminal device and the currently used key, wherein the integrity protection algorithm in the security capability includes: the empty integrity protection algorithm of the first wireless standard, and the encryption algorithm in the security capability includes at least one of the following: the empty encryption algorithm of the first wireless standard and the empty encryption algorithm of the second wireless standard.

[0088] Optionally, the second base station control plane entity is configured to, after receiving the switching request message, determine the integrity protection algorithm, encryption algorithm and update key after the terminal device is switched to the second base station based on the integrity protection algorithm in the security capability if the broadcast message of the second base station indicates that the cell supports providing IMS emergency services to terminal devices that have not passed identity authentication.

[0089] Optionally, the second base station control plane entity is configured to generate a switching failure message after receiving the switching request message, if the second base station control plane entity does not support the null security algorithm of the first wireless standard, or the broadcast message of the second base station indicates that the cell does not support the provision of IMS emergency services to terminal devices that have not passed identity authentication, or the broadcast message of the second base station does not configure whether the cell supports the provision of IMS emergency services to terminal devices that have not passed identity authentication.

[0090] Optionally, the switching failure message includes: a first failure reason, and the first failure reason includes at least one of the following: the integrity protection algorithm cannot be supported, and the null encryption algorithm cannot be supported.

[0091] According to another aspect of the embodiment of the present application, a security information configuration device is also provided, including: a first control module, used to control the terminal device to be determined as having failed authentication by the core network of the second wireless standard when the terminal device does not have valid subscription information of the second wireless standard and the Internet Protocol Multimedia Subsystem IMS emergency service of the terminal device is activated; a second control module, used to control the terminal device to use at least one of a null integrity protection algorithm and a null encryption algorithm after the terminal device completes the switching action and when the second base station supports the provision of IMS emergency services to terminal devices that have not passed authentication, wherein the switching action includes: switching from a first base station of the first wireless standard to a second base station of the second wireless standard, or switching within a cell within the second base station, or switching between cells within the second base station, or switching from a third base station of the second wireless standard to a second base station of the second wireless standard, the null encryption algorithm includes: the null encryption algorithm of the first wireless standard or the null encryption algorithm of the second wireless standard, and the null integrity protection algorithm includes: the null integrity protection algorithm of the first wireless standard or the null integrity protection algorithm of the second wireless standard.

[0092] Optionally, the device also includes: a third control module, used to configure the signaling radio bearer SRB and the data radio bearer DRB between the terminal device and the second base station to use at least one of the empty integrity protection algorithm and the empty encryption algorithm in the radio resource control RRC message, or, when the RRC message is not configured with any integrity protection algorithm or any encryption algorithm, control the terminal device to use at least one of the integrity protection algorithm and encryption algorithm used before completing the switching action.

[0093] Optionally, the device also includes: a fourth control module, used to control the terminal device to adopt the security algorithm used before switching to the second base station when the RRC switching command message or RRC reconfiguration message received by the terminal device does not carry a new security algorithm, wherein the RRC switching command message or RRC reconfiguration message is sent by the second base station or the second base station control plane entity.

[0094] Optionally, the device also includes: a fifth control module, which is used to control the terminal device to adopt at least one of the integrity protection algorithm of the first wireless standard and the encryption algorithm of the first wireless standard after switching to the second base station if the terminal device receives an RRC switching command message instructing the terminal device to switch to the second base station at the first base station, and the RRC switching command message does not carry a new security algorithm.

[0095] According to another aspect of the embodiment of the present application, a security information configuration device is also provided, including: a sixth control module, which is used to control the second base station control plane entity to configure at least one of the empty security algorithm of the first wireless standard and the empty security algorithm of the second wireless standard for the terminal device after receiving the switching request message, and send the empty security algorithm of the first wireless standard or the empty security algorithm of the second wireless standard or the security configuration information that does not carry any integrity protection algorithm or encryption algorithm to the core network or the third base station of the second wireless standard through a switching response message, wherein the switching request message includes at least one of the following: identification information assigned to the terminal device in the core network, the terminal device in the first base station of the first wireless standard or the third base station of the second wireless standard The used security algorithm configuration and wireless bearer configuration; the empty security algorithm includes: at least one of the empty integrity protection algorithm and the empty encryption algorithm; the security algorithm configuration includes at least one of the following: at least one of the empty integrity protection algorithm and the empty encryption algorithm of the first wireless standard, and at least one of the empty integrity protection algorithm and the empty encryption algorithm of the second wireless standard; the wireless bearer configuration includes at least one of the following: Internet Protocol Multimedia Subsystem IMS bearer configuration information and service bearer configuration information; the IMS bearer configuration information includes at least one of the following: the quality of service QoS identifier, allocation information and retention priority information of the first wireless standard or the second wireless standard; the numerical values ​​in the allocation information and the retention priority information are used to indicate the use of IMS emergency services in the 5G access network.

[0096] Optionally, the device also includes: a seventh control module, which is used to control the second base station control plane entity to receive the switching request message through the direct interface between the first base station and the second base station if the switching request message is a message sent by the first base station forwarded by the core network control plane entity, or the switching request message is a message sent by the first base station using the second wireless standard.

[0097] Optionally, the device also includes: an eighth control module, which is used to control the second base station control plane entity to notify the second base station user plane entity of the first security configuration information and service bearer configuration information through a request message within the first base station after receiving the switching request message and when the second base station supports the provision of IMS emergency services to terminal devices that have not passed identity authentication and the second base station supports the null security algorithm of the first wireless standard, wherein the first security configuration information includes at least one of the following: the null encryption algorithm of the first wireless standard, the null encryption algorithm of the second wireless standard; the service bearer configuration information includes: wireless bearer configuration.

[0098] Optionally, the device also includes: a ninth control module, which is used to control the control plane entity of the second base station to determine the integrity protection algorithm, encryption algorithm and update key after the terminal device switches to the second base station according to the integrity protection algorithm in the security capability after receiving the switching request message, if the broadcast message of the second base station indicates that the cell supports providing IMS emergency services to terminal devices that have not passed identity authentication.

[0099] Optionally, the device also includes: a tenth control module, which is used to control the second base station control plane entity to generate a switching failure message after receiving the switching request message, if the second base station control plane entity does not support the null security algorithm of the first wireless standard, or the broadcast message of the second base station indicates that the cell does not support the provision of IMS emergency services to terminal devices that have not passed identity authentication, or the broadcast message of the second base station does not configure whether the cell supports the provision of IMS emergency services to terminal devices that have not passed identity authentication.

[0100] According to another aspect of the embodiments of the present application, a computer-readable storage medium is further provided, the storage medium including a stored program, wherein when the program is run, the device where the storage medium is located is controlled to execute the above security information configuration method.

[0101] According to another aspect of the embodiments of the present application, an electronic device is provided, including: a memory and a processor, the processor being configured to run a program stored in the memory, wherein the above security information configuration method is executed when the program is running.

[0102] According to yet another aspect of the embodiments of the present application, a computer program is further provided, wherein when the computer program is executed by a processor, the above security information configuration method is implemented.

[0103] According to another aspect of the embodiments of the present application, a computer program product is also provided, which includes a non-volatile computer-readable storage medium, wherein the non-volatile computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the above security information configuration method is implemented. BRIEF DESCRIPTION OF THE DRAWINGS

[0104] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0105] FIG1 shows a schematic diagram of a 5G base station architecture in which a control plane entity and a user plane entity are separated;

[0106] FIG2 shows an interaction diagram of a CU-CP and CU-UP bearer context setup process;

[0107] FIG3 is a flowchart of a method for configuring security information according to an embodiment of the present application;

[0108] FIG4 is a structural diagram of a security information configuration system according to an embodiment of the present application;

[0109] 5 is a signaling interaction flow chart of a method for configuring security information according to an embodiment of the present application;

[0110] FIG6 is a structural diagram of a security information device according to an embodiment of the present application. DETAILED DESCRIPTION

[0111] In order to enable those skilled in the art to better understand the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments in the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of this application.

[0112] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in a sequence other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0113] Before a terminal device switches from 4G to 5G, if it cannot pass the core network authentication on the 5G side, for example, if the terminal device does not use a 5G Subscriber Identity Module (SIM) card, then the terminal device generally cannot support NIA0. As IMS services can theoretically only support EIA0, it is necessary to simultaneously support 4G integrity protection mode EIA0 on the 5G side. Similarly, if a null integrity protection algorithm is configured according to protocol requirements, a null algorithm should also be configured for the encryption algorithm. However, the current terminal device and base station side protocols have the following problems.

[0114] 1. The RRC protocol on the base station side does not support the configuration of EIA0 (a null integrity protection algorithm) and EEA0 (a null encryption algorithm): Currently, terminal devices can only be configured with NIA0 in the protocol and cannot support EIA0. In addition, for this type of terminal device, the bearer configuration must always be configured in accordance with EIA0 during the subsequent 5G system handover process.

[0115] CU-CP and CU-UP in 2.5G do not support EIA0 and EEA0 configuration in 5G: The current protocol TS38.473 does not support EEA0 configuration in 5G regarding security algorithms, and CU-UP in 5G does not currently support EEA0 capabilities. Therefore, when the security encryption capability cannot be configured, CU-CP cannot know the corresponding reason. Similarly, during the handover process, there is currently no relevant reason value in the handover error reason given by 5G to 4G.

[0116] 3. Unverified emergency services cannot be switched from 4G to 5G: Since the 5G base station side does not support EIA0 and EEA0 capabilities, the security capability negotiation will fail during the switching process, resulting in the inability to guarantee calls for emergency call users.

[0117] Based on the above requirements and reason analysis, the current 3GPP Rel-15 and subsequent versions of the protocol still have defects when it comes to unverified emergency services, and need to be enhanced in new ways in 5G to meet the needs of network deployment and optimization.

[0118] The embodiments of the present application provide a method, system, and device for configuring security information to at least solve the technical problem that the continuity of unverified emergency services cannot be guaranteed when switching from 4G to 5G due to the fact that the current 5G standard still has defects in supporting EIA0 and EEA0 for unverified emergency services.

[0119] According to an embodiment of the present application, a method embodiment of a method for configuring security information is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0120] FIG3 is a flowchart of a method for configuring security information according to an embodiment of the present application. As shown in FIG3 , the method includes steps S302 to S304 .

[0121] Step S302: When the terminal device does not have valid subscription information of the second wireless standard and the Internet Protocol Multimedia Subsystem IMS emergency service of the terminal device is activated, the terminal device is determined by the core network of the second wireless standard to have failed identity authentication.

[0122] It should be noted that, in this application, CU-CP is referred to as a base station control plane entity, CU-UP is referred to as a base station user plane entity, and DU is referred to as a base station separation entity.

[0123] Wireless standards refer to the technical standards or specifications used in wireless network communications, which define how wireless devices transmit data. IMS is a system composed of all functional entities that can provide multimedia services. IMS includes a collection of functional entities related to signaling and bearer. IMS uses packet switching domains and multimedia bearers to implement multimedia services. This enables operators to provide their users with multimedia services based on Internet applications, services and protocols. IMS is independent of the underlying IP access network. For example, 3GPP, 3GPP2 and I-WLAN can all access the IMS system to establish associations, QoS and billing management between Session Initiation Protocol (SIP) dialogues and General Packet Radio Service (GPRS) sessions.

[0124] Step S304, after the terminal device completes the switching action, and when the second base station supports the provision of IMS emergency services to terminal devices that have not passed identity authentication, the terminal device uses at least one of the null integrity protection algorithm and the null encryption algorithm, wherein the switching action includes: switching from a first base station of a first wireless standard to a second base station of a second wireless standard, or, switching within a cell within the second base station, or, switching between cells within the second base station, or, switching from a third base station of the second wireless standard to a second base station of the second wireless standard, the null encryption algorithm includes: the null encryption algorithm of the first wireless standard or the null encryption algorithm of the second wireless standard, and the null integrity protection algorithm includes: the null integrity protection algorithm of the first wireless standard or the null integrity protection algorithm of the second wireless standard.

[0125] In other words, after the terminal device switches from a first base station of a first wireless standard to a second base station of a second wireless standard, or after switching within a cell or between cells within the second base station of the second wireless standard, or after switching from a third base station of the second wireless standard to a second base station of the second wireless standard, and when the second base station supports the provision of IMS emergency services (functions) to terminal devices that have not passed authentication, the terminal device uses a null integrity protection algorithm and / or a null encryption algorithm.

[0126] The second wireless standard is a wireless standard subsequent to the first wireless standard. The first wireless standard includes: the fourth generation mobile communication technology Long Term Evolution (4G LTE) or the fifth generation mobile communication technology New Radio (5G NR); the second wireless standard includes: the fifth generation mobile communication technology New Radio (5G NR) or the sixth generation mobile communication technology (6G); the core network of the second wireless standard includes: a 5G control plane entity or a 6G control plane entity, wherein the 5G control plane entity includes: an access and mobility management function entity (AMF).

[0127] In an embodiment of the present application, when the terminal device does not have valid contract information of the second wireless standard and the Internet Protocol Multimedia Subsystem IMS emergency service of the terminal device is activated, the terminal device is determined by the core network of the second wireless standard as failing to pass identity authentication; after the terminal device completes the switching action, and when the second base station supports the provision of IMS emergency services to terminal devices that have not passed identity authentication, the terminal device uses an empty integrity protection algorithm and / or an empty encryption algorithm, wherein the switching action includes: switching from a first base station of the first wireless standard to a second base station of the second wireless standard, or switching within a cell within the second base station, or switching between cells within the second base station, or switching from a third base station of the second wireless standard. To the second base station of the second wireless standard, the empty encryption algorithm includes: the empty encryption algorithm of the first wireless standard or the empty encryption algorithm of the second wireless standard, and the empty integrity protection algorithm includes: the empty integrity protection algorithm of the first wireless standard or the empty integrity protection algorithm of the second wireless standard. The purpose of supporting the configuration of security algorithms for unverified emergency services in interaction between base stations and terminal equipment, and between base station separation entities and base station centralized entities is achieved, thereby achieving the technical effect of ensuring the continuity of emergency call services, and further solving the technical problem that the continuity of unverified emergency services cannot be guaranteed when switching from 4G to 5G due to the current 5G standard's defects in supporting EIA0 and EEA0 for unverified emergency services.

[0128] In some preferred embodiments, the signaling radio bearer SRB and the data radio bearer DRB between the terminal device and the second base station are configured in the radio resource control RRC message to use an empty integrity protection algorithm and / or an empty encryption algorithm; or, when the RRC message is not configured with any integrity protection algorithm and / or any encryption algorithm, the terminal device adopts the integrity protection algorithm and / or encryption algorithm used before completing the switching action.

[0129] In other words, if the empty integrity protection algorithm and / or empty encryption algorithm used by the SRB and DRB between the terminal device and the second base station are configured through an RRC message, the terminal device adopts the algorithm configured in the RRC message; or, if the RRC message does not configure any integrity protection algorithm and / or any encryption algorithm, the terminal device continues to adopt the integrity protection algorithm and / or encryption algorithm before the switching action in step S304.

[0130] SRBs and DRBs are two different types of radio bearers in 5G wireless communications, differing in their transmission methods and uses. SRBs are primarily used to transmit control information, responsible for establishing and maintaining RRC connections and transmitting system-level signaling messages such as paging and authentication. They use the PDCCH (Physical Downlink Control Channel) and PUCCH (Physical Uplink Control Channel) on the physical layer to transmit control information. In 5G NR, there are four types of SRBs: SRB0, SRB1, SRB2, and SRB3. Each SRB has a specific purpose. For example, SRB0 is used for RRC messaging using the Common Control Channel (CCCH) logical channel, while SRB2 is used for NAS messaging using the Dedicated Control Channel (DCCH) logical channel. DRBs, on the other hand, are primarily used to transmit user data, including the actual data traffic generated by applications such as VoIP, video streaming, and web browsing. The DRB is part of the wireless network's access stratum (AS) and is responsible for packet processing within the radio interface. In 5G networks, user DRBs provide the same packet forwarding processing for user data packets. Furthermore, the gNB in ​​the wireless network maps the DRB to a QoS flow based on the QFI (QoS Flow Identifier) ​​and the associated QoS profile (i.e., QoS parameters and characteristics).

[0131] According to some optional embodiments of the present application, when an RRC handover command message or an RRC reconfiguration message received by a terminal device does not carry a security algorithm, the terminal device adopts the security algorithm used before handover to the second base station, wherein the RRC handover command message or the RRC reconfiguration message is sent by the second base station or the second base station control plane entity. The security algorithm refers to an integrity protection algorithm and an encryption algorithm.

[0132] In other words, the second base station or the second base station control plane entity sends an RRC switching command message or an RRC reconfiguration message, and the terminal device receives the RRC switching command message or the RRC reconfiguration message. If the received RRC switching command message or the RRC reconfiguration message does not carry a security algorithm, the terminal device adopts the security algorithm used before switching to the second base station.

[0133] According to other optional embodiments of the present application, if a terminal device receives an RRC switching command message at a first base station instructing the terminal device to switch to a second base station, and the RRC switching command message does not carry a security algorithm, the terminal device adopts the integrity protection algorithm of the first wireless standard and / or the encryption algorithm of the first wireless standard after switching to the second base station.

[0134] Preferably, the security algorithm includes: an integrity protection algorithm and / or an encryption algorithm, wherein the integrity protection algorithm is a 128-bit integrity protection algorithm or a 256-bit integrity protection algorithm; the encryption algorithm is a 128-bit encryption algorithm or a 256-bit encryption algorithm; the integrity protection algorithm includes at least one of the following: one or more integrity protection algorithms of the first wireless standard, one or more integrity protection algorithms of the second wireless standard; the encryption algorithm includes at least one of the following: one or more encryption algorithms of the second wireless standard, one or more encryption algorithms of the second wireless standard.

[0135] That is to say, the security algorithm includes: an integrity protection algorithm or an encryption algorithm, wherein the integrity protection algorithm can be a 128-bit integrity protection algorithm or a 256-bit integrity protection algorithm, and the encryption algorithm can be a 128-bit encryption algorithm or a 256-bit encryption algorithm; the integrity protection algorithm includes at least one of one or more integrity protection algorithms under the first wireless standard and one or more integrity protection algorithms under the second wireless standard; the encryption algorithm includes at least one of one or more encryption algorithms under the second wireless standard and one or more encryption algorithms under the second wireless standard.

[0136] Preferably, the integrity protection algorithm of SRB includes: the null integrity protection algorithm of the first wireless standard or the null integrity protection algorithm of the second wireless standard; the integrity protection algorithm of DRB does not include: the null integrity protection algorithm of the first wireless standard or the null integrity protection algorithm of the second wireless standard.

[0137] In some optional embodiments of the present application, the RRC switching command message or the RRC reconfiguration message is generated by the second base station or the first base station; the RRC switching command message or the RRC reconfiguration message is used to instruct the terminal device to switch between cells within the second base station, or to switch from the first base station to the second base station.

[0138] That is, the terminal device receives and responds to the RRC switching command message or the RRC reconfiguration message, switches between cells within the second base station, or switches from the first base station to the second base station, wherein the RRC switching command message or the RRC reconfiguration message is generated by the second base station or the first base station.

[0139] Preferably, the RRC handover command or the RRC reconfiguration message includes one of the following: a target cell identifier, and second security configuration information, wherein the second security configuration information carries or does not carry a security algorithm.

[0140] In addition, the RRC switching command or RRC reconfiguration message also includes at least one of the following: identification information of one or more SRBs, identification information of one or more DRBs, Packet Data Convergence Protocol PDCP configuration information, and key configuration information.

[0141] Among them, the PDCP configuration information is based on the second wireless standard; the key configuration information is the primary key configuration or secondary key configuration based on the second wireless standard; the target cell identifier is the first cell identifier within the second base station when switching from the first base station to the second base station, or the second cell identifier when switching within the second base station.

[0142] Preferably, when the second security configuration information carries an integrity protection algorithm, the integrity protection algorithm includes at least one of the following: a null integrity protection algorithm for the first wireless standard, or a null integrity protection algorithm for the second wireless standard, wherein the null integrity protection algorithm is used for SRB. When the second security configuration information carries an encryption algorithm, the encryption algorithm includes at least one of the following: a null encryption algorithm for the first wireless standard, or a null encryption algorithm for the second wireless standard, wherein the null encryption algorithm is used for SRB and DRB.

[0143] As some optional embodiments of the present application, after the terminal device adopts the security algorithm used before switching to the second base station, it is also necessary to perform the following steps: the terminal device configures the SRB according to the second security configuration information; the terminal device configures the DRB according to the second security configuration information.

[0144] After the terminal device adopts the security algorithm used before switching to the second base station, it configures the SRB and the DRB according to the second security configuration information, which can be specifically achieved through the following method.

[0145] 1. If the identification information of the SRB currently adopted by the terminal device is not included in the second security configuration information, perform the following steps: establish a PDCP entity of the SRB; configure the integrity protection algorithm and / or encryption algorithm adopted by the PDCP entity of the SRB to be the security configuration algorithm indicated in the second security configuration information, and apply the primary key or the secondary key, wherein the integrity protection algorithm is the empty integrity protection algorithm of the first wireless standard, and the encryption algorithm is the empty encryption algorithm of the first wireless standard; when the current configuration of the terminal device is the configuration of the first wireless standard and the identification information of the SRB currently adopted by the terminal device is included in the second security configuration information, delete the PDCP configuration of the first wireless standard associated with the identification information of the SRB currently adopted by the terminal device.

[0146] It can be understood that, when the SRB identifier currently used by the terminal device is not included in the second security configuration information, the SRB is configured using the following method:

[0147] (1) Establishing a PDCP bearer;

[0148] (2) Configuring the integrity protection and / or encryption algorithm used by the PDCP entity to be the security configuration algorithm indicated in the second security configuration, and applying the primary key or secondary key;

[0149] If the terminal device is currently configured with the configuration of the first wireless standard, and the currently used SRB identifier is also included in the second security configuration information, the PDCP configuration of the first wireless standard associated with the SRB is deleted.

[0150] 2. If the identification information of the SRB currently used by the terminal device is included in the second security configuration information, perform the following steps: establish the PDCP entity of the SRB; configure the integrity protection and / or encryption algorithm used by the PDCP entity of the SRB to be the security configuration algorithm indicated in the information in the second security configuration, and apply the primary key or secondary key, wherein the integrity protection algorithm is the null integrity protection algorithm of the first wireless standard, and the encryption algorithm is the null encryption algorithm of the first wireless standard.

[0151] 3. If the identification information of the DRB currently used by the terminal device is not included in the second security configuration information, perform the following steps: establish a PDCP entity for the DRB; configure the encryption algorithm used by the PDCP entity of the DRB to be the security configuration algorithm indicated in the second security configuration information, and apply the primary key or the secondary key, wherein the integrity protection algorithm is the empty integrity protection algorithm of the first wireless standard, and the encryption algorithm is the empty encryption algorithm of the first wireless standard; when the current configuration of the terminal device is the configuration of the first wireless standard and the identification information of the DRB currently used by the terminal device is included in the second security configuration information, delete the PDCP configuration of the first wireless standard associated with the identification information of the DRB currently used by the terminal device.

[0152] In other words, when the DRB identifier currently used by the terminal device is not included in the second security configuration information, the DRB is configured using the following method:

[0153] (1) Establishing a PDCP bearer;

[0154] (2) Configuring the encryption algorithm used by the PDCP entity to be the security configuration algorithm indicated in the second security configuration, and applying the primary key or the secondary key;

[0155] If the terminal device is currently configured with the configuration of the first wireless standard, and the currently used DRB identifier is also included in the second security configuration information, the PDCP configuration of the first wireless standard associated with the DRB is deleted.

[0156] 4. If the identification information of the DRB currently used by the terminal device is included in the second security configuration information, perform the following steps: establish the PDCP entity of the DRB; configure the encryption algorithm used by the PDCP entity of the DRB to be the security configuration algorithm indicated in the second security configuration information, and apply the primary key or the secondary key, wherein the integrity protection algorithm is the null integrity protection algorithm of the first wireless standard, and the encryption algorithm is the null encryption algorithm of the first wireless standard.

[0157] In some optional embodiments of the present application, after switching to the second base station, the terminal device adopts the integrity protection algorithm of the first wireless standard and / or the encryption algorithm of the first wireless standard, and also needs to perform the following steps: the terminal device configures the SRB according to the second security configuration information; the terminal device configures the DRB according to the second security configuration information.

[0158] After switching to the second base station, the terminal device adopts the integrity protection algorithm of the first wireless standard and / or the encryption algorithm of the first wireless standard, and configures the SRB and the DRB according to the second security configuration information, which can be specifically implemented by the following method:

[0159] 1. If the identification information of the SRB currently used by the terminal device is not included in the second security configuration information, perform the following steps: establish a PDCP entity for the SRB; configure the integrity protection algorithm and / or encryption algorithm used by the PDCP entity of the SRB to be the algorithm currently used in the first wireless standard, and apply a primary key or a secondary key, wherein the integrity protection algorithm is the null integrity protection algorithm of the first wireless standard, and the encryption algorithm is the null encryption algorithm of the first wireless standard. If the current configuration of the terminal device is the configuration of the first wireless standard, and the identification information of the SRB currently used by the terminal device is included in the second security configuration information, perform the following steps: delete the PDCP configuration of the first wireless standard associated with the identification information of the SRB currently used by the terminal device.

[0160] In other words, when the SRB identifier currently used by the terminal device is not included in the second security configuration information, the SRB is configured using the following method:

[0161] (1) Establishing a PDCP bearer;

[0162] (2) Configuring the integrity protection and / or encryption algorithm used by the PDCP entity to be the algorithm currently used in the first radio standard, and applying the primary key or secondary key;

[0163] If the terminal device is currently configured with the configuration of the first wireless standard, and the currently used SRB identifier is also included in the second security configuration information, the PDCP configuration of the first wireless standard associated with the SRB is deleted.

[0164] 2. The terminal device configures the SRB according to the second security configuration information, including: if the identification information of the SRB currently used by the terminal device is included in the second security configuration information, performing the following steps: establishing a PDCP entity of the SRB; configuring the integrity protection and / or encryption algorithm used by the PDCP entity of the SRB to be the algorithm currently used in the first wireless standard, and applying a primary key or a secondary key, wherein the integrity protection algorithm is the null integrity protection algorithm of the first wireless standard, and the encryption algorithm is the null encryption algorithm of the first wireless standard.

[0165] 3. The terminal device configures the DRB according to the second security configuration information, including: if the identification information of the DRB currently used by the terminal device is included in the second security configuration information, executing the following steps: establishing a PDCP entity for the DRB; configuring the encryption algorithm used by the PDCP entity of the DRB to be the algorithm currently used in the first wireless standard, and applying a primary key or a secondary key, wherein the integrity protection algorithm is the null integrity protection algorithm of the first wireless standard, and the encryption algorithm is the null encryption algorithm of the first wireless standard. If the current configuration of the terminal device is the configuration of the first wireless standard, and the identification information of the DRB currently used by the terminal device is included in the second security configuration information, executing the following steps: deleting the PDCP configuration of the first wireless standard associated with the identification information of the DRB currently used by the terminal device.

[0166] In other words, when the DRB identifier currently used by the terminal device is not included in the second security configuration information, the DRB is configured using the following method:

[0167] (1) Establishing a PDCP bearer;

[0168] (2) Configuring the encryption algorithm used by the PDCP entity to be the algorithm currently used in the first wireless standard, and applying the primary key or the secondary key;

[0169] If the terminal device is currently configured with the configuration of the first wireless standard, and the currently used DRB identifier is also included in the second security configuration information, the PDCP configuration of the first wireless standard associated with the DRB is deleted.

[0170] 4. The terminal device configures the DRB according to the second security configuration information, including: if the identification information of the DRB currently used by the terminal device is included in the second security configuration information, executing the following steps: establishing a PDCP entity for the DRB; configuring the encryption algorithm used by the PDCP entity of the DRB to be the algorithm currently used in the first wireless standard, and applying a primary key or a secondary key, wherein the integrity protection algorithm is the null integrity protection algorithm of the first wireless standard, and the encryption algorithm is the null encryption algorithm of the first wireless standard.

[0171] Furthermore, after the terminal device configures the DRB according to the second security configuration information, it is also necessary to perform the following steps: access the second base station or the second cell in the second base station.

[0172] In some optional embodiments of the present application, when the null integrity protection algorithm of the first wireless standard is configured, the value of the non-access layer counter NAS COUNT is flipped, and the updated key has not been configured before the value of the NAS COUNT is flipped, the terminal device maintains a NAS connection with the core network of the second wireless standard.

[0173] According to another aspect of an embodiment of the present application, a method for configuring security information implemented by a second base station control plane entity is also provided, including:

[0174] After receiving the handover request message, the second base station control plane entity configures the null security algorithm of the first wireless standard and / or the null security algorithm of the second wireless standard for the terminal device, and sends the null security algorithm of the first wireless standard or the null security algorithm of the second wireless standard or the security configuration information that does not carry any integrity protection algorithm and / or encryption algorithm to the core network or the third base station of the second wireless standard through a handover response message, wherein,

[0175] The handover request message includes at least one of the following: identification information assigned to the terminal device in the core network, a security algorithm configuration and a radio bearer configuration adopted by the terminal device in the first base station of the first wireless standard or the third base station of the second wireless standard;

[0176] Null security algorithms include: null integrity protection algorithms and / or null encryption algorithms;

[0177] The security algorithm configuration includes at least one of the following: the null integrity protection algorithm and / or null encryption algorithm of the first wireless standard, the null integrity protection algorithm and / or null encryption algorithm of the second wireless standard; the wireless bearer configuration includes at least one of the following: Internet Protocol Multimedia Subsystem IMS bearer configuration information, service bearer configuration information; the IMS bearer configuration information includes at least one of the following: the quality of service QoS identifier, allocation information and retention priority information of the first wireless standard or the second wireless standard; the numerical values ​​in the allocation information and the retention priority information are used to indicate the use of IMS emergency services in the 5G access network.

[0178] Preferably, the broadcast message of the second base station indicates whether the cell supports providing IMS emergency services to terminal devices that have not passed identity authentication. In other words, whether the cell supports providing IMS emergency services to terminal devices that have not passed identity authentication is indicated by the broadcast message of the second base station.

[0179] According to some optional embodiments of the present application, if the switching request message is a message sent by the first base station and forwarded by the core network control plane entity, or the switching request message is a message sent by the first base station using the second wireless standard, the second base station control plane entity receives the switching request message through a direct interface between the first base station and the second base station.

[0180] After receiving the handover request message, and in the case that the second base station supports provision of IMS emergency services to terminal devices that have not passed identity authentication and the second base station supports the null security algorithm of the first wireless standard, the second base station control plane entity performs the following steps:

[0181] The first security configuration information and the service bearer configuration information are notified to the second base station user plane entity through a request message within the first base station.

[0182] The first security configuration information includes at least one of the following: a null encryption algorithm of the first wireless standard, a null encryption algorithm of the second wireless standard; and the service bearer configuration information includes: wireless bearer configuration.

[0183] In addition, the switching request message also includes at least one of the following: the security capabilities of the terminal device and the currently used key, wherein the integrity protection algorithm in the security capability includes: the empty integrity protection algorithm of the first wireless standard, and the encryption algorithm in the security capability includes at least one of the following: the empty encryption algorithm of the first wireless standard and the empty encryption algorithm of the second wireless standard.

[0184] According to some optional embodiments of the present application, after receiving the handover request message, if the broadcast message of the second base station indicates that the cell supports providing IMS emergency services to terminal devices that have not passed identity authentication, the second base station control plane entity performs the following steps:

[0185] According to the integrity protection algorithm in the security capability, determine the integrity protection algorithm, encryption algorithm and update key after the terminal device switches to the second base station.

[0186] In addition, after receiving the handover request message, if the second base station control plane entity does not support the null security algorithm of the first wireless standard, or the broadcast message of the second base station indicates that the cell does not support the provision of IMS emergency services to terminal devices that have not passed identity authentication, or the broadcast message of the second base station does not configure whether the cell supports the provision of IMS emergency services to terminal devices that have not passed identity authentication, the second base station control plane entity performs the following steps:

[0187] Generates a handover failure message.

[0188] The switching failure message includes: a first failure reason, and the first failure reason includes at least one of the following: the integrity protection algorithm cannot be supported, and the null encryption algorithm cannot be supported.

[0189] Preferably, the first security configuration information includes: an encryption algorithm, and the encryption algorithm includes at least one of the following: a null encryption algorithm of the first wireless standard and a null encryption algorithm of the second wireless standard.

[0190] The second base station user plane entity is used to receive the first security configuration information, configure the encryption algorithm of the terminal device according to the first security configuration information, and determine whether the terminal device adopts the IMS emergency service that has not passed the authentication based on the configured air integrity protection algorithm and / or encryption algorithm of the first wireless standard, the allocation information in the IMS bearer configuration information, and the numerical value in the retention priority information.

[0191] In some optional embodiments of the present application, when it is determined that the terminal device uses an IMS emergency service that has not passed identity authentication, the second base station control plane entity performs the following steps:

[0192] A first intra-base station confirmation message sent by a second base station user plane entity is received.

[0193] The second base station user plane entity is used to maintain a different wireless side key from the terminal device, and the confirmation message within the first base station is used to confirm the completion of the security configuration of the terminal device.

[0194] The second base station user plane entity is used to send a first base station failure message to the second base station control plane entity when it is confirmed that the null security algorithm of the first wireless standard cannot be supported based on the first security configuration information in the request message within the first base station, wherein the first base station failure message is used to confirm that the null security algorithm of the first wireless standard cannot be supported, and the first base station failure message includes: a second failure reason, and the second failure reason includes: the null encryption algorithm cannot be supported.

[0195] As some optional embodiments of the present application, after receiving the first base station confirmation message sent by the second base station user plane entity, if the handover request message comes from the core network, the second base station control plane entity performs the following steps:

[0196] A handover confirmation message is sent to the first base station through the core network, or a handover failure message is sent to the first base station after receiving a failure message within the first base station.

[0197] Among them, the switching failure message includes: a first failure reason, wherein the first failure reason is determined according to the second failure reason. When the second failure reason is that the empty encryption algorithm cannot be supported, the first failure reason is set to that the empty encryption algorithm cannot be supported.

[0198] In some optional embodiments of the present application, the second base station control plane entity may also generate an RRC reconfiguration message in the handover confirmation message and send it to the terminal device.

[0199] Among them, the RRC reconfiguration message includes: the second security configuration information of the terminal device.

[0200] The integrity protection algorithm in the second security configuration information includes at least one of the following: the empty integrity protection algorithm of the first wireless standard, the encryption algorithm in the second security configuration information is the empty encryption algorithm of the first wireless standard, and the encryption algorithm in the second security configuration information is the empty encryption algorithm of the second wireless standard.

[0201] In addition, the second base station control plane entity may also send a handover confirmation message or a handover failure message to the core network.

[0202] The core network is used to forward the switching confirmation message or the switching failure message to the first base station. After receiving the switching confirmation message, the first base station is used to send the switching confirmation message to the terminal device through the RRC message. The switching confirmation message includes: second security configuration information.

[0203] The first base station is further configured to, after receiving the handover failure message, determine the security support capability of the second base station according to the first failure cause in the handover failure message.

[0204] Among them, the security support capability includes at least one of the following: the null integrity protection algorithm of the first wireless standard, the encryption algorithm of the first wireless standard; the first base station is also used to add the security support capability of the second base station to the neighboring cell list information of the first base station and the second base station.

[0205] As other optional embodiments of the present application, the second base station control plane entity is also used to receive a path switching response message sent by the core network, wherein the path switching response message includes: user plane security configuration, and the policies for encryption and integrity protection in the user plane security configuration are all set to "No Needed" mode.

[0206] According to the above steps, when the terminal device does not have valid contract information of the second wireless standard and the Internet Protocol Multimedia Subsystem IMS emergency service of the terminal device is activated, the terminal device is determined by the core network of the second wireless standard as having failed authentication; after the terminal device completes the switching action, and when the second base station supports the provision of IMS emergency services to terminal devices that have not passed authentication, the terminal device uses a null integrity protection algorithm and / or a null encryption algorithm, wherein the switching action includes: switching from a first base station of a first wireless standard to a second base station of a second wireless standard, or switching within a cell within the second base station, or switching between cells within the second base station, or switching from a third base station of the second wireless standard to a second base station of the second wireless standard, the null encryption algorithm includes: the null encryption algorithm of the first wireless standard or the null encryption algorithm of the second wireless standard, and the null integrity protection algorithm includes: the null integrity protection algorithm of the first wireless standard or the null integrity protection algorithm of the second wireless standard, thereby achieving the purpose of supporting the interaction between the base station and the terminal device, and between the base station separation entity and the base station centralized entity for the configuration of security algorithms for unverified emergency services, thereby achieving the technical effect of ensuring the continuity of emergency call services.

[0207] In some preferred embodiments, a comprehensive process for handover of unverified emergency services from 4G to 5G is provided, where the 4G cell is Cell 1 and the 5G cell is Cell 2. The 5G base station uses a CP / UP split architecture, namely gNB-CU-CP and gNB-CU-UP. Both gNB-CU-CP and gNB-CU-UP support EIA0 and EEA0 configurations, and the core network entity is a joint entity of the Mobile Management Entity (MME) and the AMF.

[0208] Specifically, the overall process of switching from 4G to 5G can be implemented through the following steps S11 to S112.

[0209] In step S11, the gNB (second base station) sets ims-EmergencySupport to True in the System Information Block (SIB) 1 in the broadcast message, where the gNB adopts the NR radio access technology (RAT).

[0210] In step S12, after the UE accesses the eNB (first base station) and the IMS emergency service is activated, the core network entity determines that the UE cannot pass the identity authentication in NR and can only pass the identity authentication in LTE.

[0211] In step S13, the eNB initiates a handover request (handover request message) corresponding to the UE to the gNB. The handover request carries the security capabilities of the UE. The security capabilities only include EIA0 for the integrity protection algorithm, and include EEA0 for the encryption algorithm.

[0212] In step S14, after receiving the handover request sent by the eNB, the gNB-CU-CP (second base station control plane entity) determines that the integrity protection algorithm and encryption algorithm of the UE after the handover are EIA0 and EEA0 respectively according to the integrity protection algorithm in the security capability.

[0213] In step S15, the gNB-CU-CP sends security configuration information to the gNB-CU-UP (second base station user plane entity) via a Bearer Context Setup Request. The security configuration information includes an encryption algorithm, and the encryption algorithm includes EEA0.

[0214] In step S16, the gNB-CU-UP completes the encryption algorithm configuration for the UE based on the first security configuration information carried in the intra-eNB request message. Furthermore, because the first security configuration information does not include an integrity protection algorithm and the configured encryption algorithm is EEA0, the gNB-CU-UP determines that the UE uses unverified emergency services. Therefore, the gNB-CU-UP and the UE may maintain different radio side keys. The gNB-CU-UP then sends an intra-eNB confirmation message (the first intra-eNB confirmation message) to the gNB-CU-CP, confirming that the security configuration is complete.

[0215] In step S17, upon receiving the confirmation message within the eNB, the gNB-CU-CP feeds back a handover confirmation message to the eNB. The handover confirmation message includes: the second security configuration information sent by the gNB to the UE, the integrity protection algorithm in the second security configuration information is EIA0, the encryption algorithm in the second security configuration information is EEA0, and the key portion in the second security configuration information includes the key calculated by the gNB.

[0216] Step S18: The eNB sends a handover command message including the second security configuration information to the UE through an RRC message.

[0217] In step S19, the UE completes the configuration of the integrity protection algorithm and the encryption algorithm according to the second security configuration information, and completes the key update, and then accesses the gNB.

[0218] In step S110, the gNB-CU-CP receives the user plane security configuration sent by the core network in the path switching response message. The user plane security configuration sets the encryption and integrity protection policies to "No Needed" mode.

[0219] In step S111, the gNB-CU-CP sends the user plane security configuration to the gNB-CU-UP via an intra-gNB request message (first intra-base station request message).

[0220] In step S112, when the UE configures the null integrity protection algorithm of the first standard and the NAS COUNT value rolls over, if the new first key has not been configured before the NAS COUNT value rolls over, the connection between the UE and the NAS of the core network will continue to be maintained.

[0221] In other preferred embodiments, a failure process for unauthenticated (failed) emergency service handover from 4G to 5G is provided, where the 4G cell is Cell 1 and the 5G cell is Cell 2. The 5G base station uses a CP / UP split architecture, namely gNB-CU-CP and gNB-CU-UP. The gNB-CU-UP does not support EEA0. The core network entity is a joint entity of the MME and AMF.

[0222] Specifically, the failure process of switching from 4G to 5G can be implemented through the following steps S21 to S27.

[0223] In step S21, the gNB sets ims-EmergencySupport to True in the broadcast message SIB1, where the gNB adopts NR RAT.

[0224] In step S22, after the UE accesses the eNB and the IMS emergency service is activated, the core network entity determines that the UE cannot pass the authentication in NR and can only pass the authentication in LTE.

[0225] In step S23, the eNB initiates a handover request (handover request message) for the UE to the gNB. The handover request carries the security capabilities of the UE. The security capabilities only include EIA0 for the integrity protection algorithm, and include EEA0 for the encryption algorithm.

[0226] In step S24, after receiving the handover request sent by the eNB, the gNB-CU-CP determines that the integrity protection algorithm and encryption algorithm of the UE after the handover are EIA0 and EEA0 respectively based on the integrity protection algorithm in the security capability.

[0227] In step S25, the gNB-CU-CP sends security configuration information to the gNB-CU-UP via a Bearer Context Setup Request. The security configuration information includes an encryption algorithm, and the encryption algorithm includes EEA0.

[0228] In step S26, if the gNB-CU-UP determines that the UE's security algorithm configuration is not supported based on the first security configuration information carried in the intra-eNB request message, it sends an intra-eNB failure message (first intra-eNB failure message) to the gNB-CU-CP to confirm that the security algorithm is not supported. The intra-eNB failure message carries the first failure cause, which is EEA0 not supported.

[0229] In step S27, after receiving the Bearer Context Setup Failure message, the gNB-CU-CP feeds back a handover failure message to the eNB along with the second failure cause. The second failure cause can be determined based on the first failure cause, i.e., the second failure cause is that EEA0 is not supported.

[0230] In summary, the technical solution provided by this application solves the problem that 5G base stations support the configuration of EIA0 and EEA0, thereby supporting the security configuration problem adopted after switching between 4G and 5G for unauthenticated emergency service services. In addition, this application solves the problem that some existing base stations or base station user plane entities do not support the configuration of EIA0 and EEA0, and can indicate the correct failure reason of 4G base stations and base station control plane entities, thereby avoiding the subsequent triggering of similar switching processes, thereby ensuring the continuity of switching. It is worth noting that the technical solution provided by this application is based on the modification of the existing protocol, has good forward compatibility, and is easy to deploy and implement in the network.

[0231] FIG4 is a structural diagram of a security information configuration system according to an embodiment of the present application. As shown in FIG4 , the system includes: a terminal device 41, a first base station 42, a core network 43, and a second base station 44, wherein the second base station 44 includes: a second base station control plane entity 441 and a second base station user plane entity 442, wherein,

[0232] The terminal device 41 is configured to be determined by the core network 43 of the second wireless standard as failing identity authentication when there is no valid subscription information of the second wireless standard and the Internet Protocol Multimedia Subsystem IMS emergency service is activated;

[0233] The terminal device 41 is further configured to use a null integrity protection algorithm and / or a null encryption algorithm after completing the handover action and when the second base station 44 supports providing IMS emergency services to the terminal device 41 that has not passed authentication, wherein the handover action includes: handover from a first base station 42 of a first wireless standard to a second base station 44 of a second wireless standard, or handover within a cell within the second base station 44, or handover between cells within the second base station 44, or handover from a third base station of the second wireless standard to a second base station 44 of the second wireless standard, the null encryption algorithm includes: a null encryption algorithm of the first wireless standard or a null encryption algorithm of the second wireless standard, and the null integrity protection algorithm includes: a null integrity protection algorithm of the first wireless standard or a null integrity protection algorithm of the second wireless standard;

[0234] The first base station 42 is in communication with the second base station 44 via the core network 43;

[0235] The second base station control plane entity 441 is configured to, after receiving the handover request message, configure the null security algorithm of the first wireless standard and / or the null security algorithm of the second wireless standard for the terminal device 41, and send the null security algorithm of the first wireless standard or the null security algorithm of the second wireless standard or the security configuration information that does not carry any integrity protection algorithm and / or encryption algorithm to the core network 43 or the third base station terminal device 41 of the second wireless standard through a handover response message;

[0236] The second base station user plane entity 442 is used to receive the first security configuration information and service bearer configuration information sent by the second base station control plane entity 441 after the second base station control plane entity 441 receives the switching request message, and when the second base station 44 supports the provision of IMS emergency services to terminal devices 41 that have not passed identity authentication and the second base station 44 supports the null security algorithm of the first wireless standard.

[0237] Specifically, the terminal device 41 is configured to execute the following steps S302 to S304 .

[0238] In step S302 , when the terminal device 41 does not have valid subscription information of the second wireless standard and the Internet Protocol Multimedia Subsystem IMS emergency service of the terminal device 41 is activated, the terminal device 41 is determined by the core network 43 of the second wireless standard to have failed identity authentication.

[0239] It should be noted that, in this application, CU-CP is referred to as a base station control plane entity, CU-UP is referred to as a base station user plane entity, and DU is referred to as a base station separation entity.

[0240] Wireless standards refer to the technical standards or specifications used in wireless network communications, which define how wireless devices transmit data. IMS is a system composed of all functional entities that can provide multimedia services. IMS includes a collection of functional entities related to signaling and bearer. IMS uses packet switching domains and multimedia bearers to implement multimedia services. This enables operators to provide their users with multimedia services based on Internet applications, services and protocols. IMS is independent of the underlying IP access network. For example, 3GPP, 3GPP2 and I-WLAN can all access the IMS system to establish associations, QoS and billing management between Session Initiation Protocol (SIP) dialogues and General Packet Radio Service (GPRS) sessions.

[0241] Step S304, after the terminal device 41 completes the switching action, and when the second base station 44 supports the provision of IMS emergency services to the terminal device 41 that has not passed the authentication, the terminal device 41 uses at least one of the null integrity protection algorithm and the null encryption algorithm, wherein the switching action includes: switching from the first base station 42 of the first wireless standard to the second base station 44 of the second wireless standard, or, switching within a cell within the second base station 44, or, switching between cells within the second base station 44, or, switching from the third base station of the second wireless standard to the second base station 44 of the second wireless standard, the null encryption algorithm includes: the null encryption algorithm of the first wireless standard or the null encryption algorithm of the second wireless standard, and the null integrity protection algorithm includes: the null integrity protection algorithm of the first wireless standard or the null integrity protection algorithm of the second wireless standard.

[0242] In other words, after the terminal device 41 switches from the first base station 42 of the first wireless standard to the second base station 44 of the second wireless standard, or switches within a cell or between cells within the second base station 44 of the second wireless standard, or switches from the third base station of the second wireless standard to the second base station of the second wireless standard, and when the second base station 44 supports the provision of IMS emergency services (functions) to the terminal device 41 that has not passed the authentication, the terminal device 41 uses a null integrity protection algorithm and / or a null encryption algorithm.

[0243] The second wireless standard is a wireless standard subsequent to the first wireless standard. The first wireless standard includes: the fourth generation mobile communication technology Long Term Evolution (4G LTE) or the fifth generation mobile communication technology New Radio (5G NR); the second wireless standard includes: the fifth generation mobile communication technology New Radio (5G NR) or the sixth generation mobile communication technology (6G); the core network 43 of the second wireless standard includes: a 5G control plane entity or a 6G control plane entity, wherein the 5G control plane entity includes: an access and mobility management function entity (AMF).

[0244] In some preferred embodiments, the signaling radio bearer SRB and the data radio bearer DRB between the terminal device 41 and the second base station 44 are configured in the radio resource control RRC message to use an empty integrity protection algorithm and / or an empty encryption algorithm; or, when the RRC message is not configured with any integrity protection algorithm and / or any encryption algorithm, the terminal device 41 adopts the integrity protection algorithm and / or encryption algorithm used before completing the switching action.

[0245] In other words, if the empty integrity protection algorithm and / or empty encryption algorithm used by the SRB and DRB between the terminal device 41 and the second base station 44 are configured through an RRC message, the terminal device adopts the algorithm configured in the RRC message; or, if the RRC message does not configure any integrity protection algorithm and / or any encryption algorithm, the terminal device 41 continues to adopt the integrity protection algorithm and / or encryption algorithm before the switching action in step S304.

[0246] SRBs and DRBs are two different types of radio bearers in 5G wireless communications, differing in their transmission methods and uses. SRBs are primarily used to transmit control information, responsible for establishing and maintaining RRC connections and transmitting system-level signaling messages such as paging and authentication. They use the PDCCH (Physical Downlink Control Channel) and PUCCH (Physical Uplink Control Channel) on the physical layer to transmit control information. In 5G NR, there are four types of SRBs: SRB0, SRB1, SRB2, and SRB3. Each SRB has a specific purpose. For example, SRB0 is used for RRC messaging using the Common Control Channel (CCCH) logical channel, while SRB2 is used for NAS messaging using the Dedicated Control Channel (DCCH) logical channel. DRBs, on the other hand, are primarily used to transmit user data, including the actual data traffic generated by applications such as VoIP, video streaming, and web browsing. The DRB is part of the radio network's access stratum (AS) and is responsible for packet processing within the radio interface. In 5G networks, user DRBs provide the same packet forwarding processing for user packets. Furthermore, the gNB in ​​the radio network maps the DRB to a QoS flow based on the QFI and associated QoS profile (i.e., QoS parameters and characteristics).

[0247] According to some optional embodiments of the present application, when the RRC switching command message or RRC reconfiguration message received by the terminal device 41 does not carry a security algorithm, the terminal device 41 adopts the security algorithm used before switching to the second base station 44, wherein the RRC switching command message or RRC reconfiguration message is sent by the second base station 44 or the second base station control plane entity 441.

[0248] In other words, the second base station 44 or the second base station control plane entity 441 sends an RRC switching command message or an RRC reconfiguration message, and the terminal device 41 receives the RRC switching command message or the RRC reconfiguration. If the received RRC switching command message or the RRC reconfiguration message does not carry a new security algorithm, the terminal device 41 adopts the security algorithm used before switching to the second base station 44.

[0249] According to other optional embodiments of the present application, if the terminal device 41 receives an RRC switching command message at the first base station 42 instructing the terminal device 41 to switch to the second base station 44, and the RRC switching command message does not carry a new security algorithm, the terminal device 41 adopts the integrity protection algorithm of the first wireless standard and / or the encryption algorithm of the first wireless standard after switching to the second base station 44.

[0250] Preferably, the security algorithm includes: an integrity protection algorithm and / or an encryption algorithm, wherein the integrity protection algorithm is a 128-bit integrity protection algorithm or a 256-bit integrity protection algorithm; the encryption algorithm is a 128-bit encryption algorithm or a 256-bit encryption algorithm; the integrity protection algorithm includes at least one of the following: one or more integrity protection algorithms of the first wireless standard, one or more integrity protection algorithms of the second wireless standard; the encryption algorithm includes at least one of the following: one or more encryption algorithms of the second wireless standard, one or more encryption algorithms of the second wireless standard.

[0251] That is to say, the security algorithm includes: an integrity protection algorithm or an encryption algorithm, wherein the integrity protection algorithm can be a 128-bit integrity protection algorithm or a 256-bit integrity protection algorithm, and the encryption algorithm can be a 128-bit encryption algorithm or a 256-bit encryption algorithm; the integrity protection algorithm includes at least one of one or more integrity protection algorithms under the first wireless standard and one or more integrity protection algorithms under the second wireless standard; the encryption algorithm includes at least one of one or more encryption algorithms under the second wireless standard and one or more encryption algorithms under the second wireless standard.

[0252] Preferably, the integrity protection algorithm of SRB includes: the null integrity protection algorithm of the first wireless standard or the null integrity protection algorithm of the second wireless standard; the integrity protection algorithm of DRB does not include: the null integrity protection algorithm of the first wireless standard or the null integrity protection algorithm of the second wireless standard.

[0253] In some optional embodiments of the present application, the RRC switching command message or the RRC reconfiguration message is generated by the second base station 44 or the first base station 42; the RRC switching command message or the RRC reconfiguration message is used to instruct the terminal device 41 to switch between cells within the second base station 44, or to switch from the first base station 42 to the second base station 44.

[0254] That is, the terminal device 41 receives and responds to the RRC switching command message or the RRC reconfiguration message, switches between cells within the second base station 44, or switches from the first base station 42 to the second base station 44, wherein the RRC switching command message or the RRC reconfiguration message is generated by the second base station 44 or the first base station 42.

[0255] Preferably, the RRC handover command or the RRC reconfiguration message includes one of the following: a target cell identifier, and second security configuration information, wherein the second security configuration information carries or does not carry a security algorithm.

[0256] In addition, the RRC switching command or RRC reconfiguration message also includes at least one of the following: identification information of one or more SRBs, identification information of one or more DRBs, Packet Data Convergence Protocol PDCP configuration information, and key configuration information.

[0257] Among them, the PDCP configuration information is based on the second wireless standard; the key configuration information is the primary key configuration or secondary key configuration based on the second wireless standard; the target cell identifier is the first cell identifier within the second base station 44 when switching from the first base station 42 to the second base station 44, or the second cell identifier when switching within the second base station 44.

[0258] Preferably, when the second security configuration information carries an integrity protection algorithm, the integrity protection algorithm includes at least one of the following: a null integrity protection algorithm for the first wireless standard, or a null integrity protection algorithm for the second wireless standard, wherein the null integrity protection algorithm is used for SRB. When the second security configuration information carries an encryption algorithm, the encryption algorithm includes at least one of the following: a null encryption algorithm for the first wireless standard, or a null encryption algorithm for the second wireless standard, wherein the null encryption algorithm is used for SRB and DRB.

[0259] As some optional embodiments of the present application, after the terminal device 41 adopts the security algorithm used before switching to the second base station 44, it is also necessary to perform the following steps: the terminal device 41 configures the SRB according to the second security configuration information; the terminal device 41 configures the DRB according to the second security configuration information.

[0260] After the terminal device 41 adopts the security algorithm used before switching to the second base station 44, it configures the SRB and the DRB according to the second security configuration information, which can be specifically implemented by the following method:

[0261] 1. If the identification information of the SRB currently adopted by the terminal device 41 is not included in the second security configuration information, perform the following steps: establish a PDCP entity of the SRB; configure the integrity protection algorithm and / or encryption algorithm adopted by the PDCP entity of the SRB to be the security configuration algorithm indicated in the second security configuration information, and apply the primary key or the secondary key, wherein the integrity protection algorithm is the empty integrity protection algorithm of the first wireless standard, and the encryption algorithm is the empty encryption algorithm of the first wireless standard; when the current configuration of the terminal device 41 is the configuration of the first wireless standard and the identification information of the SRB currently adopted by the terminal device 41 is included in the second security configuration information, delete the PDCP configuration of the first wireless standard associated with the identification information of the SRB currently adopted by the terminal device 41.

[0262] It can be understood that, when the SRB identifier currently used by the terminal device 41 is not included in the second security configuration information, the SRB is configured using the following method:

[0263] (1) Establishing a PDCP bearer;

[0264] (2) Configuring the integrity protection and / or encryption algorithm used by the PDCP entity to be the security configuration algorithm indicated in the second security configuration, and applying the primary key or secondary key;

[0265] If the terminal device 41 is currently configured with the configuration of the first wireless standard, and the currently used SRB identifier is also included in the second security configuration information, the PDCP configuration of the first wireless standard associated with the SRB is deleted.

[0266] 2. If the identification information of the SRB currently used by the terminal device 41 is included in the second security configuration information, perform the following steps: establish the PDCP entity of the SRB; configure the integrity protection and / or encryption algorithm used by the PDCP entity of the SRB to be the security configuration algorithm indicated in the information in the second security configuration, and apply the primary key or secondary key, wherein the integrity protection algorithm is the null integrity protection algorithm of the first wireless standard, and the encryption algorithm is the null encryption algorithm of the first wireless standard.

[0267] 3. If the identification information of the DRB currently used by the terminal device 41 is not included in the second security configuration information, perform the following steps: establish a PDCP entity for the DRB; configure the encryption algorithm used by the PDCP entity of the DRB to be the security configuration algorithm indicated in the second security configuration information, and apply the primary key or the secondary key, wherein the integrity protection algorithm is the empty integrity protection algorithm of the first wireless standard, and the encryption algorithm is the empty encryption algorithm of the first wireless standard; when the current configuration of the terminal device 41 is the configuration of the first wireless standard, and the identification information of the DRB currently used by the terminal device 41 is included in the second security configuration information, delete the PDCP configuration of the first wireless standard associated with the identification information of the DRB currently used by the terminal device 41.

[0268] In other words, when the DRB identifier currently used by the terminal device 41 is not included in the second security configuration information, the DRB is configured using the following method:

[0269] (1) Establishing a PDCP bearer;

[0270] (2) Configuring the encryption algorithm used by the PDCP entity to be the security configuration algorithm indicated in the second security configuration, and applying the primary key or the secondary key;

[0271] If the terminal device 41 is currently configured with the configuration of the first wireless standard, and the currently used DRB identifier is also included in the second security configuration information, the PDCP configuration of the first wireless standard associated with the DRB is deleted.

[0272] 4. If the identification information of the DRB currently used by the terminal device 41 is included in the second security configuration information, perform the following steps: establish the PDCP entity of the DRB; configure the encryption algorithm used by the PDCP entity of the DRB to be the security configuration algorithm indicated in the second security configuration information, and apply the primary key or the secondary key, wherein the integrity protection algorithm is the null integrity protection algorithm of the first wireless standard, and the encryption algorithm is the null encryption algorithm of the first wireless standard.

[0273] In some optional embodiments of the present application, after switching to the second base station 44, the terminal device 41 adopts the integrity protection algorithm of the first wireless standard and / or the encryption algorithm of the first wireless standard, and also needs to perform the following steps: the terminal device 41 configures the SRB according to the second security configuration information; the terminal device 41 configures the DRB according to the second security configuration information.

[0274] After switching to the second base station 44, the terminal device 41 adopts the integrity protection algorithm of the first wireless standard and / or the encryption algorithm of the first wireless standard, and configures the SRB and the DRB according to the second security configuration information, which can be specifically implemented by the following method:

[0275] 1. If the identification information of the SRB currently used by the terminal device 41 is not included in the second security configuration information, perform the following steps: establish a PDCP entity for the SRB; configure the integrity protection algorithm and / or encryption algorithm used by the PDCP entity of the SRB to be the algorithm currently used in the first wireless standard, and apply a primary key or a secondary key, wherein the integrity protection algorithm is the null integrity protection algorithm of the first wireless standard, and the encryption algorithm is the null encryption algorithm of the first wireless standard. If the current configuration of the terminal device 41 is the configuration of the first wireless standard, and the identification information of the SRB currently used by the terminal device 41 is included in the second security configuration information, perform the following steps: delete the PDCP configuration of the first wireless standard associated with the identification information of the SRB currently used by the terminal device 41.

[0276] In other words, when the SRB identifier currently used by the terminal device 41 is not included in the second security configuration information, the SRB is configured using the following method:

[0277] (1) Establishing a PDCP bearer;

[0278] (2) Configuring the integrity protection and / or encryption algorithm used by the PDCP entity to be the algorithm currently used in the first radio standard, and applying the primary key or secondary key;

[0279] If the terminal device 41 is currently configured with the configuration of the first wireless standard, and the currently used SRB identifier is also included in the second security configuration information, the PDCP configuration of the first wireless standard associated with the SRB is deleted.

[0280] 2. The terminal device 41 configures the SRB according to the second security configuration information, including: if the identification information of the SRB currently used by the terminal device 41 is included in the second security configuration information, performing the following steps: establishing a PDCP entity of the SRB; configuring the integrity protection and / or encryption algorithm used by the PDCP entity of the SRB to be the algorithm currently used in the first wireless standard, and applying a primary key or a secondary key, wherein the integrity protection algorithm is the null integrity protection algorithm of the first wireless standard, and the encryption algorithm is the null encryption algorithm of the first wireless standard.

[0281] 3. The terminal device 41 configures the DRB according to the second security configuration information, including: if the identification information of the DRB currently used by the terminal device 41 is included in the second security configuration information, executing the following steps: establishing a PDCP entity for the DRB; configuring the encryption algorithm used by the PDCP entity of the DRB to be the algorithm currently used in the first wireless standard, and applying a primary key or a secondary key, wherein the integrity protection algorithm is the null integrity protection algorithm of the first wireless standard, and the encryption algorithm is the null encryption algorithm of the first wireless standard. If the current configuration of the terminal device 41 is the configuration of the first wireless standard, and the identification information of the DRB currently used by the terminal device 41 is included in the second security configuration information, executing the following steps: deleting the PDCP configuration of the first wireless standard associated with the identification information of the DRB currently used by the terminal device 41.

[0282] In other words, when the DRB identifier currently used by the terminal device 41 is not included in the second security configuration information, the DRB is configured using the following method:

[0283] (1) Establishing a PDCP bearer;

[0284] (2) Configuring the encryption algorithm used by the PDCP entity to be the algorithm currently used in the first wireless standard, and applying the primary key or the secondary key;

[0285] If the terminal device 41 is currently configured with the configuration of the first wireless standard, and the currently used DRB identifier is also included in the second security configuration information, the PDCP configuration of the first wireless standard associated with the DRB is deleted.

[0286] 4. The terminal device 41 configures the DRB according to the second security configuration information, including: if the identification information of the DRB currently used by the terminal device 41 is included in the second security configuration information, executing the following steps: establishing a PDCP entity for the DRB; configuring the encryption algorithm used by the PDCP entity of the DRB to be the algorithm currently used in the first wireless standard, and applying a primary key or a secondary key, wherein the integrity protection algorithm is the null integrity protection algorithm of the first wireless standard, and the encryption algorithm is the null encryption algorithm of the first wireless standard.

[0287] Furthermore, after the terminal device 41 configures the DRB according to the second security configuration information, it is also necessary to perform the following steps: access the second base station 44 or the second cell in the second base station 44.

[0288] In some optional embodiments of the present application, when the null integrity protection algorithm of the first wireless standard is configured, the value of the non-access layer counter NAS COUNT is flipped, and the updated key has not been configured before the value of the NAS COUNT is flipped, the terminal device 41 core network 43 terminal device 41 maintains a NAS connection with the core network 43 of the second wireless standard.

[0289] Furthermore, the second control plane entity is configured to perform the following steps:

[0290] After receiving the handover request message, the second base station control plane entity 441 configures the null security algorithm of the first wireless standard and / or the null security algorithm of the second wireless standard for the terminal device 41, and sends the null security algorithm of the first wireless standard or the null security algorithm of the second wireless standard or the security configuration information that does not carry any integrity protection algorithm and / or encryption algorithm to the core network 43 or the third base station of the second wireless standard through a handover response message, wherein,

[0291] The handover request message includes at least one of the following: identification information assigned to the terminal device 41 in the core network 43, a security algorithm configuration and a radio bearer configuration used by the terminal device 41 in the first base station 42 of the first wireless standard or the third base station of the second wireless standard;

[0292] Null security algorithms include: null integrity protection algorithms and / or null encryption algorithms;

[0293] The security algorithm configuration includes at least one of the following: the null integrity protection algorithm and / or null encryption algorithm of the first wireless standard, the null integrity protection algorithm and / or null encryption algorithm of the second wireless standard; the wireless bearer configuration includes at least one of the following: Internet Protocol Multimedia Subsystem IMS bearer configuration information, service bearer configuration information; the IMS bearer configuration information includes at least one of the following: the quality of service QoS identifier, allocation information and retention priority information of the first wireless standard or the second wireless standard; the numerical values ​​in the allocation information and the retention priority information are used to indicate the use of IMS emergency services in the 5G access network.

[0294] Preferably, the broadcast message of the second base station 44 indicates whether the cell supports providing IMS emergency services to the terminal device 41 that has not passed the authentication. In other words, whether the cell supports providing IMS emergency services to the terminal device 41 that has not passed the authentication is indicated by the broadcast message of the second base station 44.

[0295] According to some optional embodiments of the present application, if the switching request message is a message sent by the first base station 42 and forwarded by the control plane entity of the core network 43, or the switching request message is a message sent by the first base station 42 using the second wireless standard, the second base station control plane entity 441 receives the switching request message through the direct interface between the first base station 42 and the second base station 44.

[0296] After receiving the handover request message, and in the case where the second base station 44 supports providing IMS emergency services to the terminal device 41 that has not passed the authentication, and the second base station 44 supports the null security algorithm of the first wireless standard, the second base station control plane entity 441 performs the following steps:

[0297] The first security configuration information and the service bearer configuration information are notified to the second base station user plane entity 442 through a request message within the first base station 42 .

[0298] The first security configuration information includes at least one of the following: a null encryption algorithm of the first wireless standard, a null encryption algorithm of the second wireless standard; and the service bearer configuration information includes: wireless bearer configuration.

[0299] In addition, the switching request message also includes at least one of the following: the security capabilities of the terminal device 41 and the currently used key, wherein the integrity protection algorithm in the security capability includes: the empty integrity protection algorithm of the first wireless standard, and the encryption algorithm in the security capability includes at least one of the following: the empty encryption algorithm of the first wireless standard, and the empty encryption algorithm of the second wireless standard.

[0300] According to some optional embodiments of the present application, after receiving the handover request message, if the broadcast message of the second base station 44 indicates that the cell supports providing IMS emergency services to the terminal device 41 that has not passed the authentication, the second base station control plane entity 441 performs the following steps:

[0301] According to the integrity protection algorithm in the security capability, the integrity protection algorithm, encryption algorithm and update key after the terminal device 41 switches to the second base station 44 are determined.

[0302] In addition, after receiving the handover request message, if the second base station control plane entity 441 does not support the null security algorithm of the first wireless standard, or the broadcast message of the second base station 44 indicates that the cell does not support the provision of IMS emergency services to the terminal device 41 that has not passed the authentication, or the broadcast message of the second base station 44 does not configure whether the cell supports the provision of IMS emergency services to the terminal device 41 that has not passed the authentication, the second base station control plane entity 441 performs the following steps:

[0303] Generates a handover failure message.

[0304] The switching failure message includes: a first failure reason, and the first failure reason includes at least one of the following: the integrity protection algorithm cannot be supported, and the null encryption algorithm cannot be supported.

[0305] Preferably, the first security configuration information includes: an encryption algorithm, and the encryption algorithm includes at least one of the following: a null encryption algorithm of the first wireless standard and a null encryption algorithm of the second wireless standard.

[0306] The second base station user plane entity 442 is used to receive the first security configuration information, configure the encryption algorithm of the terminal device 41 according to the first security configuration information, and determine whether the terminal device 41 adopts the IMS emergency service that has not passed the authentication based on the configured air integrity protection algorithm and / or encryption algorithm of the first wireless standard, the allocation information in the IMS bearer configuration information, and the numerical value in the retention priority information.

[0307] In some optional embodiments of the present application, when it is determined that the terminal device 41 uses an IMS emergency service that has not passed identity authentication, the second base station control plane entity 441 performs the following steps:

[0308] Receive an internal confirmation message within the first base station 42 sent by the second base station user plane entity 442.

[0309] The second base station user plane entity 442 is used to maintain a different wireless side key from the terminal device 41 , and the confirmation message in the first base station 42 is used to confirm the completion of the security configuration of the terminal device 41 .

[0310] The second base station user plane entity 442 is used to send a failure message within the first base station 42 to the second base station control plane entity 441 when it is confirmed that the null security algorithm of the first wireless standard cannot be supported based on the first security configuration information in the request message within the first base station 42. The failure message within the first base station 42 is used to confirm that the null security algorithm of the first wireless standard cannot be supported. The failure message of the first base station 42 includes: a second failure reason, and the second failure reason includes: the null encryption algorithm cannot be supported.

[0311] As some optional embodiments of the present application, after receiving the confirmation message within the first base station 42 sent by the second base station user plane entity 442, if the handover request message comes from the core network 43, the second base station control plane entity 441 performs the following steps:

[0312] A handover confirmation message is sent to the first base station 42 through the core network 43 , or a handover failure message is sent to the first base station 42 after receiving a failure message from the first base station 42 .

[0313] Among them, the switching failure message includes: a first failure reason, wherein the first failure reason is determined according to the second failure reason. When the second failure reason is that the empty encryption algorithm cannot be supported, the first failure reason is set to that the empty encryption algorithm cannot be supported.

[0314] In some optional embodiments of the present application, the second base station control plane entity 441 may also generate an RRC reconfiguration message in the handover confirmation message and send it to the terminal device 41.

[0315] Among them, the RRC reconfiguration message includes: the second security configuration information of the terminal device 41.

[0316] The integrity protection algorithm in the second security configuration information includes at least one of the following: the empty integrity protection algorithm of the first wireless standard, the encryption algorithm in the second security configuration information is the empty encryption algorithm of the first wireless standard, and the encryption algorithm in the second security configuration information is the empty encryption algorithm of the second wireless standard.

[0317] In addition, the second base station control plane entity 441 may also send a handover confirmation message or a handover failure message to the core network 43 .

[0318] The core network 43 is used to forward the switching confirmation message or the switching failure message to the first base station 42. After receiving the switching confirmation message, the first base station 42 is used to send the switching confirmation message to the terminal device 41 through the RRC message. The switching confirmation message includes: the second security configuration information.

[0319] The first base station 42 is further configured to determine the security support capability of the second base station 44 according to the first failure cause in the handover failure message after receiving the handover failure message.

[0320] Among them, the security support capability includes at least one of the following: the air integrity protection algorithm of the first wireless standard, the encryption algorithm of the first wireless standard; the first base station 42 is also used to add the security support capability of the second base station 44 to the neighboring cell list information of the first base station 42 and the second base station 44.

[0321] As other optional embodiments of the present application, the second base station control plane entity 441 is also used to receive a path switching response message sent by the core network 43, wherein the path switching response message includes: user plane security configuration, and the policies for encryption and integrity protection in the user plane security configuration are all set to "No Needed" mode.

[0322] Figure 5 is a signaling interaction flowchart of a security information configuration method according to an embodiment of the present application. As shown in Figure 5, the systems relied upon by the security information configuration method include: UE, eNB, MME / AMF, and gNB. Among them, the gNB includes: gNB-CU-CP and gNB-CU-UP. Among them, the UE is communicated with the eNB, and the eNB is communicated with the gNB through the MME / AMF.

[0323] Based on the above system, the specific configuration method of security information is shown in steps S501 to S517. Some steps belong to the internal processing of the device and are therefore not shown in Figure 5.

[0324] In step S501, when the terminal device does not have valid subscription information of the second wireless standard and the Internet Protocol Multimedia Subsystem IMS emergency service of the terminal device is activated, the terminal device is determined by the core network of the second wireless standard as having failed identity authentication. After the terminal device completes the switching action, and when the second base station supports the provision of IMS emergency services to terminal devices that have not passed identity authentication, the terminal device uses a null integrity protection algorithm and / or a null encryption algorithm, wherein the switching action includes: switching from a first base station of a first wireless standard to a second base station of a second wireless standard, or switching within a cell within the second base station, or switching between cells within the second base station, or switching from a third base station of the second wireless standard to a second base station of the second wireless standard, the null encryption algorithm includes: the null encryption algorithm of the first wireless standard or the null encryption algorithm of the second wireless standard, and the null integrity protection algorithm includes: the null integrity protection algorithm of the first wireless standard or the null integrity protection algorithm of the second wireless standard.

[0325] Step S502: Indicate, via a broadcast message from the second base station, whether the cell supports provision of IMS emergency services to terminal devices that have not passed identity authentication.

[0326] In step S503, after the terminal device accesses the first base station and the IMS emergency service is activated, the core network entity determines that the terminal device cannot pass identity authentication in the second standard and can only pass identity authentication in the first wireless standard. The second wireless standard is a wireless standard subsequent to the first wireless standard. The first wireless standard includes: the fourth generation mobile communication technology Long Term Evolution 4G LTE or the fifth generation mobile communication technology New Radio 5G NR; the second wireless standard includes: the fifth generation mobile communication technology New Radio 5G NR or the sixth generation mobile communication technology 6G.

[0327] In step S504, the first base station initiates a handover request message (Handover Required) for the terminal device to the second base station. The handover request message carries at least one of the terminal device's security capabilities and the currently used key. The security capabilities include only the null integrity protection algorithm (e.g., EIA0) for the integrity protection algorithm of the first wireless standard, and the security capabilities include at least one of the null encryption algorithm of the first wireless standard and the null encryption algorithm of the second wireless standard for the encryption algorithm. For example, the security capabilities include EEA0 for the encryption algorithm.

[0328] In step S505, after receiving the handover request message sent by the first base station and forwarded by the core network, the second base station control plane entity determines the integrity protection algorithm, encryption algorithm, and updated key of the terminal device after the handover based on the integrity protection algorithm EIA0 in the security capability. When the second base station control plane entity cannot support at least one of the null integrity protection algorithm of the first wireless standard or the null encryption algorithm of the first wireless standard, a handover failure message is generated. The handover failure message includes: a first failure reason, which includes at least one of not supporting the null integrity protection algorithm of the first wireless standard and not supporting the null encryption algorithm of the first wireless standard.

[0329] In step S506, the control plane entity of the second base station sends first security configuration information (EEA0, UP Security configuration) to the user plane entity of the second base station through a request message (Bearer Context Setup Request) within the first base station, when supporting the null integrity protection algorithm of the first wireless standard and the null encryption algorithm of the first wireless standard. The first security configuration information includes an encryption algorithm, and the encryption algorithm includes at least one of the null encryption algorithm of the first wireless standard and the null encryption algorithm of the second wireless standard.

[0330] Step S507: The second base station user plane entity completes the encryption algorithm configuration of the terminal device according to the first security configuration information carried in the request message within the first base station, and determines that the terminal device uses an unverified emergency service based on the configured empty integrity protection algorithm of the first wireless standard and / or the empty encryption algorithm of the first wireless standard and the empty encryption algorithm of the second wireless standard. The second base station user plane entity can maintain a different wireless side key from the terminal device, and the second base station user plane entity sends a first base station confirmation message (Bearer Context Setup Response) to the second base station control plane entity to confirm that the security configuration has been completed.

[0331] In step S508, when the user plane entity of the second base station confirms that the security algorithm configuration of the terminal device cannot be supported based on the first security configuration information carried in the request message within the first base station, it sends a failure message within the first base station to the control plane entity of the second base station to confirm that the security algorithm cannot be supported, wherein the failure message within the first base station carries the second failure reason, and the first failure reason is that the empty encryption protection algorithm of the first wireless standard is not supported.

[0332] In step S509, after receiving the confirmation message within the first base station, the control plane entity of the second base station feeds back a handover confirmation message (Handover Request ACK) to the first base station, or, after receiving the failure message within the first base station, feeds back a handover failure message (Handover Failure) to the first base station and carries the first failure cause. It should be noted that the first failure cause is determined based on the second failure cause, wherein, when the second failure cause is that the null encryption protection algorithm of the first wireless standard is not supported, the first failure cause is set to be that the null encryption protection algorithm of the first wireless standard is not supported.

[0333] In step S510, the second base station control plane entity generates an RRC reconfiguration message in the switching confirmation message and sends it to the terminal device, that is, the switching confirmation message includes the RRC reconfiguration message, the RRC reconfiguration message includes the second security configuration of the terminal device, the integrity protection algorithm in the second security configuration is the empty integrity protection algorithm of the first wireless standard, and the encryption algorithm in the second security configuration is at least one of the empty encryption algorithm of the first wireless standard and the empty encryption algorithm of the second wireless standard.

[0334] In step S511, the second base station sends a handover confirmation message or a handover failure message to a core network entity, and the core network entity sends a handover confirmation message or a handover failure message to the first base station.

[0335] Step S512: After receiving the handover confirmation message, the first base station sends a handover command message including the second security configuration information to the terminal device via an RRC message.

[0336] In step S513, after the terminal device completes the configuration of the integrity protection algorithm and the encryption algorithm according to the second security configuration information and completes the key update, it accesses the second base station and uses the integrity protection algorithm configuration and the encryption algorithm configuration indicated by the second security configuration information to perform security configuration for the SRB and DRB of the terminal device.

[0337] Step S514: The second base station control plane entity sends a path switch request (Path Switch Request) to the core network.

[0338] In step S515, the control plane entity of the second base station receives the user plane security configuration sent by the core network in the path switch response message (Path Switch Response), in which the encryption and integrity protection policies are both set to "No Needed" mode.

[0339] In step S516, when the terminal device configures the first-standard null integrity protection algorithm and the NAS COUNT value rolls over, if the new first key has not been configured before the NAS COUNT value rolls over, the connection between the terminal device and the NAS of the core network will continue to be maintained.

[0340] Step S517: When the first base station receives a handover failure, it determines the security support capability of the second base station based on the reason for the handover failure. The security support capability includes at least one of the air integrity protection algorithm of the first wireless standard and the encryption algorithm of the first wireless standard, and adds the security support capability of the second base station to the neighboring cell list information of the first base station and the second base station.

[0341] FIG6 is a structural diagram of a security information device according to an embodiment of the present application. As shown in FIG6 , the device includes:

[0342] The first control module 60 is configured to control the terminal device to be determined as failing identity authentication by the core network of the second wireless standard when the terminal device does not have valid subscription information of the second wireless standard and the Internet Protocol Multimedia Subsystem IMS emergency service of the terminal device is activated.

[0343] The second control module 62 is used to, after the terminal device completes the switching action and when the second base station supports the provision of IMS emergency services to terminal devices that have not passed identity authentication, the terminal device uses a null integrity protection algorithm and / or a null encryption algorithm, wherein the switching action includes: switching from a first base station of a first wireless standard to a second base station of a second wireless standard, or switching within a cell within the second base station, or switching between cells within the second base station, or switching from a third base station of the second wireless standard to a second base station of the second wireless standard, the null encryption algorithm includes: the null encryption algorithm of the first wireless standard or the null encryption algorithm of the second wireless standard, and the null integrity protection algorithm includes: the null integrity protection algorithm of the first wireless standard or the null integrity protection algorithm of the second wireless standard.

[0344] Furthermore, the above-mentioned device also includes: a third control module, used to configure the signaling radio bearer SRB and data radio bearer DRB between the terminal device and the second base station to use an empty integrity protection algorithm and / or an empty encryption algorithm in the radio resource control RRC message, or, when the RRC message is not configured with any integrity protection algorithm and / or any encryption algorithm, control the terminal device to adopt the integrity protection algorithm and / or encryption algorithm used before completing the switching action.

[0345] Furthermore, the above-mentioned device also includes: a fourth control module, used to control the terminal device to adopt the security algorithm used before switching to the second base station when the RRC switching command message or RRC reconfiguration message received by the terminal device does not carry a security algorithm, wherein the RRC switching command message or RRC reconfiguration message is sent by the second base station or the second base station control plane entity.

[0346] Furthermore, the above-mentioned device also includes: a fifth control module, which is used to control the terminal device to adopt the integrity protection algorithm of the first wireless standard and / or the encryption algorithm of the first wireless standard after switching to the second base station if the terminal device receives an RRC switching command message instructing the terminal device to switch to the second base station at the first base station, and the RRC switching command message does not carry a security algorithm.

[0347] It should be noted that the various modules in Figure 6 above can be program modules (for example, a set of program instructions that implement a certain specific function) or hardware modules. For the latter, it can be expressed in the following form, but is not limited to this: the expression form of each of the above modules is a processor, or the functions of each of the above modules are implemented by a processor.

[0348] It should be noted that the preferred implementation of the embodiment shown in FIG6 can refer to the relevant descriptions of the embodiments shown in FIG3 to FIG5 , which will not be repeated here.

[0349] According to another aspect of the embodiments of the present application, a device for configuring security information is provided, including:

[0350] The sixth control module is used to control the second base station control plane entity to configure the empty security algorithm of the first wireless standard and / or the empty security algorithm of the second wireless standard for the terminal device after receiving the switching request message, and send the empty security algorithm of the first wireless standard or the empty security algorithm of the second wireless standard or the security configuration information that does not carry any integrity protection algorithm and / or encryption algorithm to the core network or the third base station of the second wireless standard through a switching response message, wherein the switching request message includes at least one of the following: identification information assigned to the terminal device in the core network, security algorithm configuration adopted by the terminal device in the first base station of the first wireless standard or the third base station of the second wireless standard, wireless bearer Carrier configuration; the null security algorithm includes: null integrity protection algorithm and / or null encryption algorithm; the security algorithm configuration includes at least one of the following: the null integrity protection algorithm and / or null encryption algorithm of the first wireless standard, the null integrity protection algorithm and / or null encryption algorithm of the second wireless standard; the wireless bearer configuration includes at least one of the following: Internet Protocol Multimedia Subsystem IMS bearer configuration information, service bearer configuration information; the IMS bearer configuration information includes at least one of the following: the quality of service QoS identifier, allocation information and retention priority information of the first wireless standard or the second wireless standard; the values ​​in the allocation information and the retention priority information are used to indicate the use of IMS emergency services in the 5G access network.

[0351] Furthermore, the above-mentioned device also includes: a seventh control module, which is used to control the second base station control plane entity to receive the switching request message through the direct interface between the first base station and the second base station if the switching request message is a message sent by the first base station forwarded by the core network control plane entity, or the switching request message is a message sent by the first base station using the second wireless standard.

[0352] Furthermore, the above-mentioned device also includes: an eighth control module, which is used to control the second base station control plane entity to notify the second base station user plane entity of the first security configuration information and service bearer configuration information through a request message within the first base station after receiving the switching request message, and when the second base station supports the provision of IMS emergency services to terminal devices that have not passed identity authentication and the second base station supports the null security algorithm of the first wireless standard, wherein the first security configuration information includes at least one of the following: the null encryption algorithm of the first wireless standard, the null encryption algorithm of the second wireless standard; the service bearer configuration information includes: wireless bearer configuration.

[0353] Furthermore, the above-mentioned device also includes: a ninth control module, which is used to control the second base station control plane entity to determine the integrity protection algorithm, encryption algorithm and update key after the terminal device switches to the second base station according to the integrity protection algorithm in the security capability after receiving the switching request message, if the broadcast message of the second base station indicates that the cell supports providing IMS emergency services to terminal devices that have not passed identity authentication.

[0354] Furthermore, the above-mentioned device also includes: a tenth control module, which is used to control the second base station control plane entity to generate a switching failure message after receiving the switching request message, if the second base station control plane entity does not support the null security algorithm of the first wireless standard, or the broadcast message of the second base station indicates that the cell does not support the provision of IMS emergency services to terminal devices that have not passed identity authentication, or the broadcast message of the second base station does not configure whether the cell supports the provision of IMS emergency services to terminal devices that have not passed identity authentication.

[0355] In summary, the technical solution provided by this application solves the problem that 5G base stations support the configuration of EIA0 and EEA0, thereby supporting the security configuration problem adopted after switching between 4G and 5G for unauthenticated emergency service services. In addition, this application solves the problem that some existing base stations or base station user plane entities do not support the configuration of EIA0 and EEA0, and can indicate the correct failure reason of 4G base stations and base station control plane entities, thereby avoiding the subsequent triggering of similar switching processes, thereby ensuring the continuity of switching. It is worth noting that the technical solution provided by this application is based on the modification of the existing protocol, has good forward compatibility, and is easy to deploy and implement in the network.

[0356] It should be noted that the preferred implementation of the above embodiments can be found in the relevant descriptions of the embodiments shown in Figures 3 to 5, and will not be repeated here.

[0357] An embodiment of the present application further provides a non-volatile storage medium, which includes a stored program, wherein when the program is running, the device where the storage medium is located is controlled to execute the above security information configuration method.

[0358] A program for a non-volatile storage medium to perform the following functions: when the terminal device does not have valid subscription information of the second wireless standard and the Internet Protocol Multimedia Subsystem IMS emergency service of the terminal device is activated, the terminal device is determined by the core network of the second wireless standard as failing to pass authentication; after the terminal device completes the switching action, and when the second base station supports the provision of IMS emergency services to terminal devices that have not passed authentication, the terminal device uses a null integrity protection algorithm and / or a null encryption algorithm, wherein the switching action includes: switching from a first base station of a first wireless standard to a second base station of a second wireless standard, or switching within a cell within the second base station, or switching between cells within the second base station, or switching from a third base station of the second wireless standard to a second base station of the second wireless standard, the null encryption algorithm includes: the null encryption algorithm of the first wireless standard or the null encryption algorithm of the second wireless standard, and the null integrity protection algorithm includes: the null integrity protection algorithm of the first wireless standard or the null integrity protection algorithm of the second wireless standard.

[0359] An embodiment of the present application further provides an electronic device, comprising: a memory and a processor, wherein the processor is configured to run a program stored in the memory, wherein the above security information configuration method is executed when the program is running.

[0360] The processor is used to run a program that performs the following functions: when the terminal device does not have valid subscription information of the second wireless standard and the Internet Protocol Multimedia Subsystem IMS emergency service of the terminal device is activated, the terminal device is determined by the core network of the second wireless standard as failing to pass authentication; after the terminal device completes the switching action, and when the second base station supports the provision of IMS emergency services to terminal devices that have not passed authentication, the terminal device uses a null integrity protection algorithm and / or a null encryption algorithm, wherein the switching action includes: switching from a first base station of a first wireless standard to a second base station of a second wireless standard, or switching within a cell within the second base station, or switching between cells within the second base station, or switching from a third base station of the second wireless standard to a second base station of the second wireless standard, the null encryption algorithm includes: the null encryption algorithm of the first wireless standard or the null encryption algorithm of the second wireless standard, and the null integrity protection algorithm includes: the null integrity protection algorithm of the first wireless standard or the null integrity protection algorithm of the second wireless standard.

[0361] The serial numbers of the above-mentioned embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.

[0362] In the above embodiments of the present application, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, please refer to the relevant description of other embodiments.

[0363] In the above-mentioned embodiments of the present application, the collected information is information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of the relevant data comply with the relevant laws, regulations and standards of the relevant countries and regions, take necessary confidentiality measures, do not violate public order and good customs, and provide corresponding operation entrances for users to choose to authorize or refuse.

[0364] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only exemplary. For example, the division of the units can be a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.

[0365] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple units. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.

[0366] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0367] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the relevant technology or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk.

[0368] The above is only a preferred embodiment of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.

Claims

1. A method for configuring security information, applied to a terminal device, comprising: When the terminal device does not have valid subscription information of the second wireless standard and the Internet Protocol Multimedia Subsystem IMS emergency service of the terminal device is activated, the terminal device is determined by the core network of the second wireless standard to have failed authentication; After the terminal device completes the switching action, and when the second base station supports providing the IMS emergency service to the terminal device that has not passed the authentication, the terminal device uses at least one of a null integrity protection algorithm and a null encryption algorithm, wherein the switching action includes: switching from a first base station of a first wireless standard to a second base station of a second wireless standard, or, switching within a cell within the second base station, or, switching between cells within the second base station, or, switching from a third base station of the second wireless standard to a second base station of the second wireless standard, the null encryption algorithm includes: the null encryption algorithm of the first wireless standard or the null encryption algorithm of the second wireless standard, and the null integrity protection algorithm includes: the null integrity protection algorithm of the first wireless standard or the null integrity protection algorithm of the second wireless standard.

2. The method according to claim 1, wherein: The second wireless standard is a wireless standard subsequent to the first wireless standard.

3. The method according to claim 2, wherein: The first wireless standard includes: the fourth generation mobile communication technology Long Term Evolution 4G LTE or the fifth generation mobile communication technology New Radio 5G NR; The second wireless standard includes: the fifth generation mobile communication technology new air interface 5G NR or the sixth generation mobile communication technology 6G; The core network of the second wireless standard includes: a 5G control plane entity or a 6G control plane entity, wherein the 5G control plane entity includes: an access and mobility management function entity AMF.

4. The method according to claim 1, further comprising: In the radio resource control RRC message, the signaling radio bearer SRB and the data radio bearer DRB between the terminal device and the second base station are configured to use at least one of the empty integrity protection algorithm and the empty encryption algorithm; or, when the RRC message is not configured with any integrity protection algorithm or any encryption algorithm, the terminal device adopts at least one of the integrity protection algorithm and the encryption algorithm used before completing the switching action.

5. The method according to claim 1, further comprising: The RRC handover command message or RRC reconfiguration message received by the terminal device does not carry a security algorithm In this case, the terminal device adopts the security algorithm used before switching to the second base station, wherein the RRC switching command message or the RRC reconfiguration message is sent by the second base station or the second base station control plane entity.

6. The method according to claim 5, characterized in that include: When the terminal device receives an RRC switching command message at the first base station instructing the terminal device to switch to the second base station, and the RRC switching command message does not carry a security algorithm, the terminal device adopts at least one of the integrity protection algorithm of the first wireless standard and the encryption algorithm of the first wireless standard after switching to the second base station.

7. The method according to claim 6, wherein: The security algorithm includes: at least one of the integrity protection algorithm and the encryption algorithm, wherein: The integrity protection algorithm is a 128-bit integrity protection algorithm or a 256-bit integrity protection algorithm; The encryption algorithm is a 128-bit encryption algorithm or a 256-bit encryption algorithm; The integrity protection algorithm includes at least one of the following: one or more integrity protection algorithms of the first wireless standard, one or more integrity protection algorithms of the second wireless standard; The encryption algorithm includes at least one of the following: one or more encryption algorithms of the second wireless standard, and one or more encryption algorithms of the second wireless standard.

8. The method according to claim 7, wherein: The integrity protection algorithm of the SRB includes: a null integrity protection algorithm of the first wireless standard or a null integrity protection algorithm of the second wireless standard; The integrity protection algorithm of the DRB does not include: the null integrity protection algorithm of the first wireless standard or the null integrity protection algorithm of the second wireless standard.

9. The method according to claim 5, wherein: The RRC handover command message or the RRC reconfiguration message is generated by the second base station or the first base station; The RRC switching command message or the RRC reconfiguration message is used to instruct the terminal device to switch between cells within the second base station, or to switch from the first base station to the second base station.

10. The method according to claim 9, wherein: The RRC handover command or the RRC reconfiguration message includes one of the following: a target cell identifier, and second security configuration information, wherein the second security configuration information carries or does not carry the security algorithm.

11. The method according to claim 10, wherein: The RRC switching command or the RRC reconfiguration message further includes at least one of the following: identification information of one or more SRBs, identification information of one or more DRBs, Packet Data Convergence Protocol PDCP configuration information, and key configuration information.

12. The method according to claim 11, wherein: The PDCP configuration information is based on a second wireless standard; The key configuration information is a primary key configuration or a secondary key configuration based on the second wireless standard; The target cell identifier is the first cell identifier within the second base station when switching from the first base station to the second base station, or the second cell identifier when switching within the second base station.

13. The method according to claim 11, wherein When the second security configuration information carries an integrity protection algorithm, the integrity protection algorithm includes at least one of the following: a null integrity protection algorithm of the first wireless standard, a null integrity protection algorithm of the second wireless standard, wherein the null integrity protection algorithm is used for SRB.

14. The method according to claim 11, wherein When the second security configuration information carries an encryption algorithm, the encryption algorithm includes at least one of the following: a null encryption algorithm of the first wireless standard, a null encryption algorithm of the second wireless standard, wherein the encryption algorithm is used for SRB and DRB.

15. The method according to claim 11, wherein After the terminal device adopts the security algorithm used before switching to the second base station, the method further includes: The terminal device configures the SRB according to the second security configuration information; The terminal device configures the DRB according to the second security configuration information.

16. The method according to claim 15, wherein The terminal device configures the SRB according to the second security configuration information, including: If the identification information of the SRB currently used by the terminal device is not included in the second security configuration information, perform the following steps: PDCP entity that establishes SRB; Configuring at least one of an integrity protection algorithm and an encryption algorithm adopted by the PDCP entity of the SRB as the security configuration algorithm indicated in the second security configuration information, and applying a primary key or a secondary key, wherein the integrity protection algorithm is a null integrity protection algorithm of the first wireless standard, and the encryption algorithm is a null encryption algorithm of the first wireless standard; When the current configuration of the terminal device is a configuration of the first wireless standard and the identification information of the SRB currently used by the terminal device is included in the second security configuration information, the PDCP configuration of the first wireless standard associated with the identification information of the SRB currently used by the terminal device is deleted.

17. The method according to claim 15 or 16, wherein The terminal device configures the SRB according to the second security configuration information, including: If the identification information of the SRB currently used by the terminal device is included in the second security configuration information, perform the following steps: PDCP entity that establishes SRB; At least one of the integrity protection and encryption algorithms adopted by the PDCP entity configuring the SRB is the security configuration algorithm indicated in the information in the second security configuration, and a primary key or a secondary key is applied, wherein the integrity protection algorithm is the empty integrity protection algorithm of the first wireless standard, and the encryption algorithm is the empty encryption algorithm of the first wireless standard.

18. The method according to claim 15, wherein The terminal device configures the DRB according to the second security configuration information, including: If the identification information of the DRB currently used by the terminal device is not included in the second security configuration information, perform the following steps: PDCP entity that establishes DRB; The encryption algorithm used by the PDCP entity configuring the DRB is the security configuration algorithm indicated in the second security configuration information, and a primary key or a secondary key is applied, wherein the integrity protection algorithm is the null integrity protection algorithm of the first wireless standard, and the encryption algorithm is the null encryption algorithm of the first wireless standard; When the current configuration of the terminal device is a configuration of the first wireless standard and the identification information of the DRB currently used by the terminal device is included in the second security configuration information, the PDCP configuration of the first wireless standard associated with the identification information of the DRB currently used by the terminal device is deleted.

19. The method according to claim 15 or 18, wherein The terminal device configures the DRB according to the second security configuration information, including: If the identification information of the DRB currently used by the terminal device is included in the second security configuration information, perform the following steps: PDCP entity that establishes DRB; The encryption algorithm used by the PDCP entity configuring the DRB is the security configuration algorithm indicated in the second security configuration information, and the primary key or the secondary key is applied, wherein the integrity protection algorithm is the first wireless The encryption algorithm is the null encryption algorithm of the first wireless standard.

20. The method according to claim 11, characterized in that After the terminal device switches to the second base station, the method further includes: The terminal device configures the SRB according to the second security configuration information; The terminal device configures the DRB according to the second security configuration information.

21. The method according to claim 20, characterized in that The terminal device configures the SRB according to the second security configuration information, including: If the identification information of the SRB currently used by the terminal device is not included in the second security configuration information, perform the following steps: PDCP entity that establishes SRB; At least one of the integrity protection algorithm and encryption algorithm adopted by the PDCP entity configuring the SRB is the algorithm currently used in the first wireless standard, and a primary key or a secondary key is applied, wherein the integrity protection algorithm is the empty integrity protection algorithm of the first wireless standard, and the encryption algorithm is the empty encryption algorithm of the first wireless standard.

22. The method according to claim 21, further comprising: If the current configuration of the terminal device is a configuration of the first wireless standard, and the identification information of the SRB currently used by the terminal device is included in the second security configuration information, Delete the PDCP configuration of the first wireless standard associated with the identification information of the SRB currently used by the terminal device.

23. The method according to claim 20 or 21, characterized in that The terminal device configures the SRB according to the second security configuration information, including: If the identification information of the SRB currently used by the terminal device is included in the second security configuration information, perform the following steps: PDCP entity that establishes SRB; At least one of the integrity protection and encryption algorithms adopted by the PDCP entity configuring the SRB is the algorithm currently used in the first wireless standard, and a primary key or a secondary key is applied, wherein the integrity protection algorithm is the empty integrity protection algorithm of the first wireless standard, and the encryption algorithm is the empty encryption algorithm of the first wireless standard.

24. The method according to claim 20, wherein The terminal device configures the DRB according to the second security configuration information, including: If the identification information of the DRB currently used by the terminal device is included in the second security configuration information, perform the following steps: PDCP entity that establishes DRB; The encryption algorithm used by the PDCP entity that configures the DRB is the algorithm currently used in the first wireless standard, and a primary key or a secondary key is applied, wherein the integrity protection algorithm is the empty integrity protection algorithm of the first wireless standard, and the encryption algorithm is the empty encryption algorithm of the first wireless standard.

25. The method according to claim 24, further comprising: If the current configuration of the terminal device is the configuration of the first wireless standard, and the identification information of the DRB currently used by the terminal device is included in the second security configuration information, Delete the PDCP configuration of the first wireless standard associated with the identification information of the DRB currently used by the terminal device.

26. The method according to claim 20 or 24, characterized in that The terminal device configures the DRB according to the second security configuration information, including: If the identification information of the DRB currently used by the terminal device is included in the second security configuration information, perform the following steps: PDCP entity that establishes DRB; The encryption algorithm used by the PDCP entity that configures the DRB is the algorithm currently used in the first wireless standard, and a primary key or a secondary key is applied, wherein the integrity protection algorithm is the empty integrity protection algorithm of the first wireless standard, and the encryption algorithm is the empty encryption algorithm of the first wireless standard.

27. The method according to claim 15 or 20, further comprising: After the terminal device configures the DRB according to the second security configuration information, Access the second base station or a second cell in the second base station.

28. The method of claim 1, wherein: When the null integrity protection algorithm of the first wireless standard is configured, the value of the non-access layer counter NAS COUNT is flipped, and the updated key has not been configured before the value of NAS COUNT is flipped, the terminal device maintains the NAS connection with the core network of the second wireless standard.

29. A method for configuring security information, applied to a second base station control plane entity, comprising: After receiving the handover request message, configure at least one of the null security algorithm of the first wireless standard and the null security algorithm of the second wireless standard for the terminal device, and change the null security algorithm of the first wireless standard to the null security algorithm of the second wireless standard through the handover response message. The security algorithm or the null security algorithm of the second wireless standard or the security configuration information not carrying any integrity protection algorithm or encryption algorithm is sent to the core network or the third base station of the second wireless standard, wherein, The handover request message includes at least one of the following: identification information of the terminal device allocated in the core network, security algorithm configuration and radio bearer configuration adopted by the terminal device in the first base station of the first wireless standard or the third base station of the second wireless standard; The null security algorithm includes: at least one of a null integrity protection algorithm and a null encryption algorithm; The security algorithm configuration includes at least one of the following: at least one of the null integrity protection algorithm and the null encryption algorithm of the first wireless standard, and at least one of the null integrity protection algorithm and the null encryption algorithm of the second wireless standard; the wireless bearer configuration includes at least one of the following: Internet Protocol Multimedia Subsystem IMS bearer configuration information and service bearer configuration information; the IMS bearer configuration information includes at least one of the following: the quality of service QoS identifier, allocation information and retention priority information of the first wireless standard or the second wireless standard; the numerical values ​​in the allocation information and the retention priority information are used to indicate the use of IMS emergency services in the 5G access network.

30. The method of claim 29, wherein: The second wireless standard is a wireless standard subsequent to the first wireless standard.

31. The method of claim 30, wherein: The first wireless standard includes: the fourth generation mobile communication technology Long Term Evolution 4G LTE or the fifth generation mobile communication technology New Radio 5G NR; The second wireless standard includes: the fifth generation mobile communication technology new air interface 5G NR or the sixth generation mobile communication technology 6G; The core network of the second wireless standard includes: a 5G control plane entity or a 6G control plane entity, wherein the 5G control plane entity includes: an access and mobility management function entity AMF.

32. The method of claim 29, further comprising: If the switching request message is a message sent by the first base station and forwarded by a core network control plane entity, or the switching request message is a message sent by the first base station using a second wireless standard, the switching request message is received through a direct interface between the first base station and the second base station.

33. The method of claim 32, further comprising: The broadcast message of the second base station indicates whether the cell supports providing the IMS emergency service to the terminal device that has not passed the identity authentication.

34. The method of claim 33, further comprising: After receiving the handover request message, and when the second base station supports the authentication of the When the terminal device provides the IMS emergency service and the second base station supports the null security algorithm of the first wireless standard, the first security configuration information and the service bearer configuration information are notified to the second base station user plane entity through a request message within the first base station, wherein, The first security configuration information includes at least one of the following: a null encryption algorithm of the first wireless standard, a null encryption algorithm of the second wireless standard; The service bearer configuration information includes: the radio bearer configuration.

35. The method of claim 34, wherein: The switching request message also includes at least one of the following: the security capabilities of the terminal device and the currently used key, wherein the integrity protection algorithm in the security capability includes: the empty integrity protection algorithm of the first wireless standard, and the encryption algorithm in the security capability includes at least one of the following: the empty encryption algorithm of the first wireless standard and the empty encryption algorithm of the second wireless standard.

36. The method of claim 35, further comprising: After receiving the switching request message, if the broadcast message of the second base station indicates that the cell supports providing the IMS emergency service to the terminal device that has not passed the authentication, the integrity protection algorithm, encryption algorithm and update key after the terminal device switches to the second base station are determined according to the integrity protection algorithm in the security capability.

37. The method of claim 35, further comprising: After receiving the switching request message, if the control plane entity of the second base station does not support the null security algorithm of the first wireless standard, or the broadcast message of the second base station indicates that the cell does not support the provision of the IMS emergency service to the terminal device that has not passed the authentication, or the broadcast message of the second base station does not configure whether the cell supports the provision of the IMS emergency service to the terminal device that has not passed the authentication, a switching failure message is generated.

38. The method of claim 37, wherein: The switching failure message includes: a first failure reason, and the first failure reason includes at least one of the following: the integrity protection algorithm cannot be supported, and the null encryption algorithm cannot be supported.

39. The method of claim 38, wherein: The first security configuration information includes: an encryption algorithm, the encryption algorithm includes at least one of the following: a null encryption algorithm of the first wireless standard, a null encryption algorithm of the second wireless standard, wherein: The second base station user plane entity is used to receive the first security configuration information, configure the encryption algorithm of the terminal device according to the first security configuration information, and complete the encryption according to the configured first wireless standard. The terminal device determines whether to use an IMS emergency service that has not passed identity authentication based on the integrity protection algorithm, at least one of the encryption algorithms, the allocation information in the IMS bearer configuration information, and a value in the retention priority information.

40. The method of claim 39, further comprising: In a case where it is determined that the terminal device adopts the IMS emergency service that has not passed the authentication, a first base station confirmation message sent by the second base station user plane entity is received, wherein the second base station user plane entity is used to maintain a different radio side key from the terminal device, and the first base station confirmation message is used to confirm the completion of the security configuration of the terminal device, wherein, The second base station user plane entity is used to send a first base station failure message to the second base station control plane entity when it is confirmed that the null security algorithm of the first wireless standard cannot be supported based on the first security configuration information in the request message within the first base station, wherein the failure message within the first base station is used to confirm that the null security algorithm of the first wireless standard cannot be supported, and the failure message within the first base station includes: a second failure reason, and the second failure reason includes: the null encryption algorithm cannot be supported.

41. The method of claim 40, further comprising: After receiving the first base station internal confirmation message sent by the second base station user plane entity, if the handover request message comes from the core network, send a handover confirmation message to the first base station through the core network, or, After receiving the first base station internal failure message, the handover failure message is sent to the first base station.

42. The method of claim 41 , wherein: The switching failure message includes: the first failure cause, wherein the first failure cause is determined based on the second failure cause. When the second failure cause is that the empty encryption algorithm cannot be supported, the first failure cause is set to that the empty encryption algorithm cannot be supported.

43. The method of claim 42, further comprising: An RRC reconfiguration message is generated in the handover confirmation message and sent to the terminal device, wherein the RRC reconfiguration message includes: second security configuration information of the terminal device.

44. The method of claim 43, wherein: The integrity protection algorithm in the second security configuration information includes at least one of the following: the empty integrity protection algorithm of the first wireless standard, the encryption algorithm in the second security configuration information is the empty encryption algorithm of the first wireless standard, and the encryption algorithm in the second security configuration information is the empty encryption algorithm of the second wireless standard.

45. The method of claim 44, further comprising: The handover confirmation message or the handover failure message is sent to the core network, wherein the core network is used to forward the handover confirmation message or the handover failure message to the first base station, and the first base station is used to send the handover confirmation message to the terminal device through an RRC message after receiving the handover confirmation message, wherein the handover confirmation message includes: the second security configuration information, wherein, The first base station is configured to, after receiving the handover failure message, determine, according to the first failure cause in the handover failure message, a security support capability of the second base station, wherein the security support capability includes at least one of the following: a null integrity protection algorithm of the first wireless standard, and an encryption algorithm of the first wireless standard; The first base station is further configured to add the security support capability of the second base station to the neighbor list information of the first base station and the second base station.

46. ​​The method of claim 45, further comprising: Receive a path switching response message sent by the core network, wherein the path switching response message includes: user plane security configuration, and the policies for encryption and integrity protection in the user plane security configuration are both set to "No Needed" mode.

47. A security information configuration system comprising: A terminal device, a first base station, a core network, and a second base station, wherein the second base station includes: a second base station control plane entity and a second base station user plane entity, wherein: The terminal device is configured to be determined by the core network of the second wireless standard as failing identity authentication when there is no valid subscription information of the second wireless standard and an Internet Protocol Multimedia Subsystem IMS emergency service is activated; The terminal device is further configured to, after completing the switching action and when the second base station supports providing the IMS emergency service to the terminal device that has not passed the authentication, use at least one of a null integrity protection algorithm and a null encryption algorithm, wherein the switching action includes: switching from a first base station of a first wireless standard to a second base station of a second wireless standard, or switching within a cell within the second base station, or switching between cells within the second base station, or switching from a third base station of the second wireless standard to a second base station of the second wireless standard, the null encryption algorithm includes: a null encryption algorithm of the first wireless standard or a null encryption algorithm of the second wireless standard, and the null integrity protection algorithm includes: a null integrity protection algorithm of the first wireless standard or a null integrity protection algorithm of the second wireless standard; The first base station is communicatively connected to the second base station via the core network; The second base station control plane entity is used to configure at least one of the null safety algorithm of the first wireless standard and the null safety algorithm of the second wireless standard for the terminal device after receiving the handover request message, and The message sends the empty security algorithm of the first wireless standard or the empty security algorithm of the second wireless standard or the security configuration information that does not carry any integrity protection algorithm or encryption algorithm to the core network or the third base station of the second wireless standard; The second base station user plane entity is used to receive the first security configuration information and service bearer configuration information sent by the second base station control plane entity after the second base station control plane entity receives the switching request message, and when the second base station supports the provision of the IMS emergency service to the terminal device that has not passed the authentication and the second base station supports the null security algorithm of the first wireless standard.

48. The system of claim 47, wherein: The second wireless standard is a wireless standard subsequent to the first wireless standard.

49. The system of claim 48, wherein: The first wireless standard includes: the fourth generation mobile communication technology Long Term Evolution 4G LTE or the fifth generation mobile communication technology New Radio 5G NR; The second wireless standard includes: the fifth generation mobile communication technology new air interface 5G NR or the sixth generation mobile communication technology 6G; The core network of the second wireless standard includes: a 5G control plane entity or a 6G control plane entity, wherein the 5G control plane entity includes: an access and mobility management function entity AMF.

50. The system of claim 47, wherein: The signaling radio bearer SRB and the data radio bearer DRB between the terminal device and the second base station are configured in the radio resource control RRC message to use at least one of an empty integrity protection algorithm and an empty encryption algorithm; or, when the RRC message is not configured with any integrity protection algorithm or any encryption algorithm, the terminal device is configured to adopt at least one of the integrity protection algorithm and the encryption algorithm used before completing the switching action.

51. The system of claim 47, wherein: The terminal device is configured to adopt the security algorithm used before switching to the second base station when the RRC switching command message or the RRC reconfiguration message received by the terminal device does not carry a security algorithm, wherein the RRC switching command message or the RRC reconfiguration message is sent by the second base station or the second base station control plane entity.

52. The system of claim 51 , wherein: The terminal device is configured to, if the terminal device receives an RRC handover command message for instructing the terminal device to switch to the second base station at the first base station, and the RRC handover command message does not carry In the case of a security algorithm, after switching to the second base station, at least one of the integrity protection algorithm of the first wireless standard and the encryption algorithm of the first wireless standard is adopted.

53. The system of claim 52, wherein: The security algorithm includes: at least one of the integrity protection algorithm and the encryption algorithm, wherein: The integrity protection algorithm is a 128-bit integrity protection algorithm or a 256-bit integrity protection algorithm; The encryption algorithm is a 128-bit encryption algorithm or a 256-bit encryption algorithm; The integrity protection algorithm includes at least one of the following: one or more integrity protection algorithms of the first wireless standard, one or more integrity protection algorithms of the second wireless standard; The encryption algorithm includes at least one of the following: one or more encryption algorithms of the second wireless standard, and one or more encryption algorithms of the second wireless standard.

54. The system of claim 53, wherein: The integrity protection algorithm of the SRB includes: a null integrity protection algorithm of the first wireless standard or a null integrity protection algorithm of the second wireless standard; The integrity protection algorithm of the DRB does not include: the null integrity protection algorithm of the first wireless standard or the null integrity protection algorithm of the second wireless standard.

55. The system of claim 54, wherein: The RRC handover command message or the RRC reconfiguration message is generated by the second base station or the first base station; The RRC switching command message or the RRC reconfiguration message is used to instruct the terminal device to switch between cells within the second base station, or to switch from the first base station to the second base station.

56. The system of claim 55, wherein: The RRC handover command or the RRC reconfiguration message includes one of the following: a target cell identifier, and second security configuration information, wherein the second security configuration information carries or does not carry the security algorithm.

57. The system of claim 56, wherein: The RRC switching command or the RRC reconfiguration message further includes at least one of the following: identification information of one or more SRBs, identification information of one or more DRBs, Packet Data Convergence Protocol PDCP configuration information, and key configuration information.

58. The system of claim 57, wherein: The PDCP configuration information is based on a second wireless standard; The key configuration information is a primary key configuration or a secondary key configuration based on the second wireless standard; The target cell identifier is the first cell identifier within the second base station when switching from the first base station to the second base station, or the second cell identifier when switching within the second base station.

59. The system of claim 58, wherein: When the second security configuration information carries an integrity protection algorithm, the null integrity protection algorithm is used for SRB, and the integrity protection algorithm includes at least one of the following: the null integrity protection algorithm of the first wireless standard and the null integrity protection algorithm of the second wireless standard.

60. The system of claim 59, wherein: When the second security configuration information carries an integrity protection algorithm, the integrity protection algorithm includes at least one of the following: a null integrity protection algorithm of the first wireless standard, a null integrity protection algorithm of the second wireless standard, and the null integrity protection algorithm is used for SRB; When the second security configuration information carries an integrity protection algorithm, the integrity protection algorithm includes at least one of the following: a null integrity protection algorithm of the first wireless standard, a null integrity protection algorithm of the second wireless standard, and the null integrity protection algorithm is used for SRB.

61. The system of claim 60, wherein: The terminal device is configured to maintain a NAS connection with the core network of the second wireless standard when the null integrity protection algorithm of the first wireless standard is configured, the value of the non-access layer counter NAS COUNT is flipped, and the updated key has not been configured before the value of the NAS COUNT is flipped.

62. The system of claim 48, wherein: The handover request message includes at least one of the following: identification information of the terminal device allocated in the core network, security algorithm configuration and radio bearer configuration adopted by the terminal device in the first base station of the first wireless standard or the third base station of the second wireless standard; The null security algorithm includes: at least one of a null integrity protection algorithm and a null encryption algorithm; The security algorithm configuration includes at least one of the following: at least one of the null integrity protection algorithm and the null encryption algorithm of the first wireless standard, and at least one of the null integrity protection algorithm and the null encryption algorithm of the second wireless standard; the wireless bearer configuration includes at least one of the following: Internet Protocol Multimedia Subsystem IMS bearer configuration information and service bearer configuration information; the IMS bearer configuration information includes at least one of the following: the quality of service QoS identifier, allocation information and retention priority information of the first wireless standard or the second wireless standard; the numerical values ​​in the allocation information and the retention priority information are used to indicate the use of IMS emergency services in the 5G access network.

63. The system of claim 62, wherein: The second base station control plane entity is configured to receive the switching request message through a direct interface between the first base station and the second base station if the switching request message is a message sent by the first base station and forwarded by the core network control plane entity, or if the switching request message is a message sent by the first base station using the second wireless standard.

64. The system of claim 63, wherein: The broadcast message of the second base station indicates whether the cell supports providing IMS emergency services to terminal devices that have not passed identity authentication.

65. The system of claim 64, wherein: The second base station control plane entity is configured to, after receiving the handover request message, and if the second base station supports providing the IMS emergency service to the terminal device that has not passed the authentication and the second base station supports the null security algorithm of the first wireless standard, notify the second base station user plane entity of the first security configuration information and the service bearer configuration information through a first base station internal request message, wherein, The first security configuration information includes at least one of the following: a null encryption algorithm of the first wireless standard, a null encryption algorithm of the second wireless standard; The service bearer configuration information includes: the radio bearer configuration.

66. The system of claim 65, wherein: The switching request message also includes at least one of the following: the security capabilities of the terminal device and the currently used key, wherein the integrity protection algorithm in the security capability includes: the empty integrity protection algorithm of the first wireless standard, and the encryption algorithm in the security capability includes at least one of the following: the empty encryption algorithm of the first wireless standard and the empty encryption algorithm of the second wireless standard.

67. The system according to claim 66, characterized in that include: The second base station control plane entity is configured to, after receiving the switching request message, determine the integrity protection algorithm, encryption algorithm and update key after the terminal device switches to the second base station according to the integrity protection algorithm in the security capability if the broadcast message of the second base station indicates that the cell supports providing the IMS emergency service to the terminal device that has not passed the authentication.

68. The system according to claim 67, wherein: include: The second base station control plane entity is configured to, after receiving the handover request message, if the second base station control plane entity does not support the null security algorithm of the first wireless standard, or the second base station broadcast message indicates that the cell does not support the provision of the IMS emergency service to the terminal device that has not passed the authentication, or the second base station broadcast message does not configure whether the cell supports the terminal device that has not passed the authentication The device provides the IMS emergency service and generates a handover failure message.

69. The system of claim 68, wherein: The switching failure message includes: a first failure reason, and the first failure reason includes at least one of the following: the integrity protection algorithm cannot be supported, and the null encryption algorithm cannot be supported.

70. A security information configuration device, comprising: a first control module, configured to, when the terminal device does not have valid subscription information for the second wireless standard and an Internet Protocol Multimedia Subsystem (IMS) emergency service of the terminal device is activated, control the terminal device to be determined by the core network of the second wireless standard as failing identity authentication; The second control module is used to control the terminal device to use at least one of a null integrity protection algorithm and a null encryption algorithm after the terminal device completes the switching action and when the second base station supports providing the IMS emergency service to the terminal device that has not passed the authentication, wherein the switching action includes: switching from a first base station of a first wireless standard to a second base station of a second wireless standard, or switching within a cell within the second base station, or switching between cells within the second base station, or switching from a third base station of the second wireless standard to a second base station of the second wireless standard, the null encryption algorithm includes: the null encryption algorithm of the first wireless standard or the null encryption algorithm of the second wireless standard, and the null integrity protection algorithm includes: the null integrity protection algorithm of the first wireless standard or the null integrity protection algorithm of the second wireless standard.

71. The apparatus of claim 70, further comprising: The third control module is used to configure the signaling radio bearer SRB and the data radio bearer DRB between the terminal device and the second base station to use at least one of the empty integrity protection algorithm and the empty encryption algorithm in the radio resource control RRC message, or, when the RRC message is not configured with any integrity protection algorithm or any encryption algorithm, control the terminal device to use at least one of the integrity protection algorithm and encryption algorithm used before completing the switching action.

72. The apparatus of claim 71 , further comprising: The fourth control module is used to control the terminal device to adopt the security algorithm used before switching to the second base station when the RRC switching command message or RRC reconfiguration message received by the terminal device does not carry a security algorithm, wherein the RRC switching command message or the RRC reconfiguration message is sent by the second base station or the second base station control plane entity.

73. The apparatus of claim 72, further comprising: The fifth control module is used for: if the terminal device receives an RRC handover command message for instructing the terminal device to switch to the second base station at the first base station, and the RRC handover command message does not carry an installation In the case of the full algorithm, the terminal device is controlled to adopt at least one of the integrity protection algorithm of the first wireless standard and the encryption algorithm of the first wireless standard after switching to the second base station.

74. A security information configuration device, comprising: A sixth control module is configured to, after receiving the handover request message, control the second base station control plane entity to configure at least one of the null security algorithm of the first wireless standard and the null security algorithm of the second wireless standard for the terminal device, and send the null security algorithm of the first wireless standard or the null security algorithm of the second wireless standard or the security configuration information that does not carry any integrity protection algorithm or encryption algorithm to the core network or the third base station of the second wireless standard through a handover response message, wherein, The handover request message includes at least one of the following: identification information of the terminal device allocated in the core network, security algorithm configuration and radio bearer configuration adopted by the terminal device in the first base station of the first wireless standard or the third base station of the second wireless standard; The null security algorithm includes: at least one of a null integrity protection algorithm and a null encryption algorithm; The security algorithm configuration includes at least one of the following: at least one of the null integrity protection algorithm and the null encryption algorithm of the first wireless standard, and at least one of the null integrity protection algorithm and the null encryption algorithm of the second wireless standard; the wireless bearer configuration includes at least one of the following: Internet Protocol Multimedia Subsystem IMS bearer configuration information and service bearer configuration information; the IMS bearer configuration information includes at least one of the following: the quality of service QoS identifier, allocation information and retention priority information of the first wireless standard or the second wireless standard; the numerical values ​​in the allocation information and the retention priority information are used to indicate the use of IMS emergency services in the 5G access network.

75. The apparatus of claim 74, further comprising: The seventh control module is used to control the second base station control plane entity to receive the switching request message through a direct interface between the first base station and the second base station if the switching request message is a message sent by the first base station and forwarded by the core network control plane entity, or the switching request message is a message sent by the first base station using the second wireless standard.

76. The apparatus of claim 75, further comprising: An eighth control module is configured to, after receiving the handover request message, and when the second base station supports providing the IMS emergency service to the terminal device that has not passed the authentication and the second base station supports the null security algorithm of the first wireless standard, control the second base station control plane entity to notify the second base station user plane entity of the first security configuration information and the service bearer configuration information through a first base station internal request message, wherein, The first security configuration information includes at least one of the following: a null encryption algorithm of the first wireless standard, a null encryption algorithm of the second wireless standard; The service bearer configuration information includes: the radio bearer configuration.

77. The apparatus of claim 76, further comprising: The ninth control module is used to control the control plane entity of the second base station to determine the integrity protection algorithm, encryption algorithm and key update after the terminal device switches to the second base station according to the integrity protection algorithm in the security capability after receiving the switching request message, if the broadcast message of the second base station indicates that the cell supports providing the IMS emergency service to the terminal device that has not passed the authentication.

78. The apparatus of claim 77, further comprising: The tenth control module is used to control the second base station control plane entity to generate a switching failure message after receiving the switching request message, if the second base station control plane entity does not support the null security algorithm of the first wireless standard, or the broadcast message of the second base station indicates that the cell does not support the provision of the IMS emergency service to the terminal device that has not passed the authentication, or the broadcast message of the second base station does not configure whether the cell supports the provision of the IMS emergency service to the terminal device that has not passed the authentication.

79. An electronic device comprising: Memory; as well as A processor coupled to the memory, the processor being configured to execute the security information configuration method according to any one of claims 1 to 46 based on instructions stored in the memory.

80. A computer-readable storage medium having a computer program stored thereon, wherein when the program is executed by a processor, the method for configuring security information according to any one of claims 1 to 46 is implemented.

81. A computer program comprising: Instructions, when executed by a processor, cause the processor to perform the security information configuration method according to any one of claims 1 to 46.

Citation Information

Patent Citations

  • Methods providing management of emergency sessions and related devices and nodes

    CN113748695A

  • Security control method and device in a mobile communication system supporting emergency calls, and a system therefor

    US20130102270A1

  • Emergency call establishment system, communication apparatus, emergency call establishment method, and nontemporary computer readable medium

    WO2014083724A1

  • Improvements in and relating to improving disaster roaming service

    WO2023080679A1