Key updating method, communication apparatus, and storage medium

By generating and sending security configuration information, including multiple updated keys and their link count values, the problem of extended key update time when the terminal device switches cells is solved, and fast and efficient key update is achieved.

WO2025208927A1PCT designated stage Publication Date: 2025-10-09HONOR DEVICE CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/139584
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-04-03
Filing Date
2024-12-16
Publication Date
2025-10-09

AI Technical Summary

Technical Problem

In the prior art, when a terminal device switches cells, the key update delay is long and the key update efficiency is low.

Method used

By generating security configuration information of the target cell, including multiple update keys and their link count values ​​and corresponding relationships, a switching request and reconfiguration instruction are sent to the target cell and terminal device, so that the terminal device and network device can quickly complete the key update.

Benefits of technology

This reduces the time required for terminal devices to update keys and improves key update efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024139584_09102025_PF_FP_ABST
    Figure CN2024139584_09102025_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a key updating method, a communication apparatus, and a storage medium, aiming to reduce the key updating delay of a terminal device and improve the key updating efficiency of the terminal device. The present application provides a key updating method, comprising: generating security configuration information of a target cell; sending a handover request to a second network device corresponding to the target cell; sending a reconfiguration instruction to a terminal device; and sending a handover instruction to the terminal device. In the implementation solution, a first network device can pre-generate the security configuration information comprising a plurality of update keys, and send the security configuration information to both the terminal device and the second network device that corresponds to the target cell, so that the terminal device and the second network device can rapidly update keys on the basis of the security configuration information comprising the plurality of update keys without the need to spend more time in performing derivation on the update keys, thereby reducing the key updating delay of the terminal device and improving the key updating efficiency of the terminal device.
Need to check novelty before this filing date? Find Prior Art

Description

Key updating method, communication device and storage medium

[0001] This application claims priority to the Chinese patent application filed with the China Patent Office on April 3, 2024, with application number 202410409047.7 and invention name “A key update method, communication device and storage medium”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of communication technology, and in particular to a key updating method, a communication device, and a storage medium. Background Art

[0003] When a terminal device is performing a cell handover and needs to switch from an original base station to a target base station, the security key used by the terminal device can be updated to ensure the security of communication between the terminal device and the target base station after the handover.

[0004] Currently, when updating the security key used by a terminal device, it takes a long time to derive the updated security key of the terminal device, resulting in a long delay in the key update of the terminal device and low key update efficiency. Summary of the Invention

[0005] The present application provides a key update method, a communication device, and a storage medium, the purpose of which is to reduce the key update delay of a terminal device and improve the key update efficiency of the terminal device.

[0006] In order to achieve the above objectives, this application provides the following technical solutions:

[0007] A first aspect of the present application provides a key updating method, applied to a first network device, the method comprising:

[0008] Generate security configuration information for a target cell, the security configuration information including multiple update keys and a correspondence between link count values ​​and the multiple update keys; send a handover request to a second network device corresponding to the target cell, so that the second network device corresponding to the target cell performs a key update based on the security configuration information, the handover request including the security configuration information; send a reconfiguration instruction to the terminal device, the reconfiguration instruction including the security configuration information; send a handover instruction to the terminal device, so that the terminal device performs a key update based on the security configuration information.

[0009] In the above implementation scheme, after generating security configuration information for the target cell, the first network device may send the security configuration information to the second network device corresponding to the target cell via a handover request, so that the second network device, after receiving the handover request including the security configuration information, can perform a key update based on the security configuration information. The first network device may also send the security configuration information to the terminal device via a reconfiguration instruction, and may send a handover instruction to the terminal device, so that the terminal device, after receiving the handover instruction, can perform a key update based on the security configuration information. In order to reduce the key update delay of the terminal device and improve the key update efficiency of the terminal device, the first network device may pre-generate security configuration information including multiple updated keys, and send the security configuration information to the terminal device and the second network device corresponding to the target cell, respectively, so that the terminal device and the second network device can quickly complete the key update based on the security configuration information including the multiple updated keys, without having to spend a lot of time to deduce the updated key, thereby reducing the time required for the terminal device to update the key, reducing the key update delay of the terminal device, and improving the key update efficiency of the terminal device.

[0010] In a possible implementation of the first aspect of the present application, the security configuration information further includes a link count value corresponding to each updated key. In the above implementation, the security configuration information generated by the first network device may further include link count values ​​corresponding to multiple updated keys, so that the terminal device and the second network device can quickly complete the key update based on the link count value, without spending a long time to derive the updated key, thereby reducing the time required for the terminal device to update the key, reducing the key update latency of the terminal device, and improving the key update efficiency of the terminal device.

[0011] In one possible implementation of the first aspect of the present application, the security configuration information further includes a link index, which is used to indicate the link count value. In this implementation, to improve the security of key updates, the security configuration information generated by the first network device may further include a link index. The terminal device and the second network device may first locate the corresponding link count value based on the link index, and then quickly complete the key update based on the link count value.

[0012] In a possible implementation of the first aspect of the present application, the security configuration information further includes an encryption algorithm index corresponding to the target cell. In the above implementation, the security configuration information generated by the first network device may further include an encryption algorithm index corresponding to the target cell. After determining the update key and the corresponding link count value, the terminal device and the second network device can quickly search for the corresponding encryption algorithm based on the encryption algorithm index corresponding to the target cell to generate an encryption key and an integrity protection key, thereby completing the key update.

[0013] In a possible implementation of the first aspect of the present application, the switching instruction includes a target link count value or a target link index, and the method further includes: when the switching instruction includes the target link count value, sending the target link count value and the unused link count value in the security configuration information to the second network device; when the switching instruction includes the target link index, sending the target link index and the unused link index in the security configuration information to the second network device. In the above implementation scheme, the first network device can lead the key update by specifying the target link count value or target link index when the key is updated, and sending the target link count value or target link index to the second network device and the terminal device respectively, so that the terminal device can quickly complete the key update without spending a lot of time to deduce the updated key, thereby reducing the time required for the terminal device to update the key, reducing the key update delay of the terminal device, and improving the key update efficiency of the terminal device. In addition, by sending the unused link count value or the unused link index in the security configuration information to the second network device, the first network device can avoid repeatedly specifying the same link count value as the target link count value or the same link index as the target link index during the key update process when the dominant terminal device is switched next time, and avoid using the same key in different key update processes, thereby improving the effectiveness of the key update.

[0014] In a possible implementation of the first aspect of the present application, the switching request includes a layer-two triggered mobility LTM switching request. In the above implementation scheme, since the current LTM mechanism does not involve switching between CUs, it does not involve the update of security keys. When the LTM mechanism supports switching between CUs in the future, security configuration information including multiple updated keys can be pre-generated by the first network device, and the security configuration information can be sent to the terminal device and the second network device corresponding to the target cell respectively, so that the terminal device and the second network device can quickly complete the key update according to the security configuration information, without spending more time to deduce the updated key, thereby reducing the time required for the terminal device to update the key, reducing the key update delay of the terminal device, and improving the key update efficiency of the terminal device.

[0015] A second aspect of the present application provides a key update method, applied to a terminal device, the method comprising:

[0016] receiving a reconfiguration instruction from a first network device, the reconfiguration instruction including security configuration information, the security configuration information including a plurality of update keys and a correspondence between a link count value and the plurality of update keys;

[0017] receiving a switching instruction from the first network device;

[0018] The key is updated based on the security configuration information.

[0019] In the above implementation scheme, in order to reduce the key update delay of the terminal device and improve the key update efficiency of the terminal device, the terminal device can receive security configuration information including multiple update keys pre-generated from the first network device, and can quickly update the key based on the security configuration information including multiple update keys, without spending a lot of time to derive the update key, thereby reducing the time required for the terminal device to update the key, reducing the key update delay of the terminal device, and improving the key update efficiency of the terminal device.

[0020] In a possible implementation manner of the second aspect of the present application, the security configuration information further includes a link count value corresponding to each updated key.

[0021] In a possible implementation manner of the second aspect of the present application, the security configuration information further includes a link index, and the link index is used to indicate the link count value.

[0022] In a possible implementation manner of the second aspect of the present application, the security configuration information further includes an encryption algorithm index corresponding to the target cell.

[0023] In a possible implementation of the second aspect of the present application, the key update based on the security configuration information includes: determining a target link count value; determining a target update key from the multiple update keys based on the target link count value; and generating an encryption key and an integrity protection key based on the target link count value and the target update key. The terminal device can first determine the target link count value to be used for this key update, then determine the target update key to be used for this update from the multiple update keys based on the target link count value, and finally generate an encryption key and an integrity protection key based on the target link count value and the target update key, thereby quickly completing the key update without spending a lot of time to derive the target update key from the update key, thereby reducing the time required for the terminal device to update the key, reducing the key update delay of the terminal device, and improving the key update efficiency of the terminal device.

[0024] In a possible implementation of the second aspect of the present application, when the security configuration information includes a link count value corresponding to each updated key, determining the target link count value includes determining the link count value with the smallest value as the target link count value. In the above implementation, after receiving the security configuration information including the link count values, the terminal device can sequentially determine the target link count value to be used for the current key update from the link count values, that is, can determine the link count value with the smallest value as the target link count value, thereby quickly completing the key update.

[0025] In a possible implementation of the second aspect of the present application, when the security configuration information includes a link index, determining the target link count value includes: determining the link index with the smallest value as the target link index; and determining the target link count value based on the target link index. In the above implementation, after receiving the security configuration information including the link index, the terminal device can first determine the target link index to be used for the current key update from the link count values ​​in order, and then determine the target link count value to be used for the current key update based on the target link index, thereby quickly completing the key update.

[0026] In a possible implementation of the second aspect of the present application, after the encryption key and the integrity protection key are generated based on the target link count and the target update key, the target link count or the target link index is deleted. In the above implementation, to improve the security of key updates, after the terminal device uses the target link count or the target link index to perform a key update, it can delete the target link count or the target link index to prevent the updated key from being reused, thereby quickly completing the key update.

[0027] In a possible implementation of the second aspect of the present application, when the handover instruction includes a target link count value, determining the target link count value includes obtaining the target link count value from the handover instruction. In the above implementation, when the first network device initiates the key update, the terminal device can directly obtain the target link count value to be used for the update from the handover instruction sent by the first network device, thereby quickly completing the key update.

[0028] In a possible implementation of the second aspect of the present application, when the switching instruction includes a target link index, determining the target link count value includes: obtaining the target link index from the switching instruction; and determining the target link count value based on the target link index. In the above implementation, when the first network device initiates the key update, the terminal device can directly obtain the target link index to be used for the update from the switching instruction sent by the first network device, and then determine the target link count value to be used for the key update based on the target link index, thereby quickly completing the key update.

[0029] In a possible implementation of the second aspect of the present application, after determining the target link count value, the method further includes: sending the target link count value to the second network device. In the above implementation, the terminal device can lead the key update. That is, after determining the target link count value, the terminal device can send the target link count value to the second network device so that the second network device can synchronize the key update with the terminal device, ensuring the validity of the updated key, thereby quickly completing the key update.

[0030] In a possible implementation of the second aspect of the present application, after determining the target link count value, the method further includes: sending a target link index corresponding to the target link count value to the second network device. In the above implementation, the terminal device can lead the key update. That is, after determining the target link count value, the terminal device can send the target link index corresponding to the target link count value to the second network device, so that the second network device can synchronize the key update with the terminal device, ensuring the validity of the updated key, and thus quickly completing the key update.

[0031] A third aspect of the present application provides a key update method, applied to a terminal device, the method comprising:

[0032] receiving a handover request from a first network device, the handover request including security configuration information, the security configuration information including a plurality of update keys and a correspondence between a link count value and the plurality of update keys;

[0033] The key is updated based on the security configuration information.

[0034] In the above implementation scheme, in order to reduce the key update delay of the terminal device and improve the key update efficiency of the terminal device, the second network device can receive the security configuration information including multiple update keys pre-generated from the first network device, and can quickly update the key based on the security configuration information including multiple update keys, without spending a lot of time to derive the update key with the terminal device, thereby reducing the time required for the terminal device to update the key, reducing the key update delay of the terminal device, and improving the key update efficiency of the terminal device.

[0035] In a possible implementation of the third aspect of the present application, the security configuration information further includes a link count value corresponding to each updated key.

[0036] In a possible implementation manner of the third aspect of the present application, the security configuration information further includes a link index, and the link index is used to indicate the link count value.

[0037] In a possible implementation of the third aspect of the present application, the security configuration information further includes an encryption algorithm index corresponding to the target cell.

[0038] In a possible implementation of the third aspect of the present application, the key update based on the security configuration information includes: determining a target link count value; determining a target update key from the multiple update keys based on the target link count value; and generating an encryption key and an integrity protection key based on the target link count value and the target update key.

[0039] In a possible implementation of the third aspect of the present application, when the security configuration information includes a link count value corresponding to each updated key, determining the target link count value includes: determining the link count value with the smallest value as the target link count value.

[0040] In a possible implementation of the third aspect of the present application, when the security configuration information includes a link index, determining the target link count value includes: determining the link index with the smallest value as the target link index; and determining the target link count value based on the target link index.

[0041] In a possible implementation manner of the third aspect of the present application, determining the target link count value includes: receiving the target link count value from the first network device or the terminal device.

[0042] In a possible implementation of the third aspect of the present application, determining the target link count value includes: receiving a target link index from a first network device or a terminal device; and determining the target link count value according to the target link index.

[0043] A fourth aspect of the present application provides a communication device, which is specifically a first network device, and includes:

[0044] A generating module, configured to generate security configuration information of a target cell, the security configuration information including a plurality of update keys and a correspondence between a link count value and the plurality of update keys;

[0045] a sending module, configured to send a handover request to a second network device corresponding to the target cell, so that the second network device corresponding to the target cell performs a key update based on the security configuration information, wherein the handover request includes the security configuration information;

[0046] The sending module is further configured to send a reconfiguration instruction to the terminal device, wherein the reconfiguration instruction includes the security configuration information;

[0047] The sending module is further configured to send a switching instruction to the terminal device, so that the terminal device updates the key based on the security configuration information.

[0048] A fifth aspect of the present application provides a communication device, which is specifically a terminal device, and includes:

[0049] a receiving module, configured to receive a reconfiguration instruction from a first network device, the reconfiguration instruction including security configuration information, the security configuration information including a plurality of update keys and a correspondence between a link count value and the plurality of update keys;

[0050] The receiving module is configured to receive a switching instruction from the first network device;

[0051] A key updating module is used to update the key based on the security configuration information.

[0052] A sixth aspect of the present application provides a communication device, which is specifically a second network device, and includes:

[0053] a receiving module, configured to receive a switching request from a first network device, the switching request including security configuration information, the security configuration information including a plurality of update keys and a correspondence between a link count value and the plurality of update keys;

[0054] A key updating module is used to update the key based on the security configuration information.

[0055] A seventh aspect of the present application provides a communication device, comprising: a memory and at least one processor. The memory is configured to store a program, and the at least one processor is configured to execute a computer program or computer instructions stored in the memory, so that the communication device implements the key update method provided in the first aspect of the present application.

[0056] An eighth aspect of the present application provides a communication device, comprising: a memory and at least one processor. The memory is configured to store a program, and the at least one processor is configured to execute a computer program or computer instructions stored in the memory, so that the communication device implements the key update method provided in the second aspect of the present application.

[0057] A ninth aspect of the present application provides a communication device comprising: a memory and at least one processor. The memory is configured to store a program, and the at least one processor is configured to execute a computer program or computer instruction stored in the memory, so that the communication device implements the key update method provided in the third aspect of the present application.

[0058] The tenth aspect of the present application is a computer storage medium for storing a computer program. When the computer program is executed, it is used to implement the key update method provided by the first aspect, the second aspect, or the third aspect of the present application.

[0059] The eleventh aspect of the present application provides a computer program product comprising instructions, which, when executed on a computer, enables the computer to execute the key updating method provided in the first, second or third aspect.

[0060] The twelfth aspect of the present application provides a chip system, which includes a processor for supporting a terminal device or a network device to implement the functions involved in the above aspects, for example, sending or processing the data and / or information involved in the above methods. In one possible design, the chip system also includes a memory, which is used to store program instructions and data necessary for the terminal device or network device. The chip system can be composed of chips or can include chips and other discrete devices. BRIEF DESCRIPTION OF THE DRAWINGS

[0061] FIG1 is a schematic diagram of the system architecture of a communication system provided in an embodiment of the present application;

[0062] FIG2 is a schematic diagram of a flow chart of an LTM mechanism provided in an embodiment of the present application;

[0063] FIG3 is a schematic diagram of a process flow of a key update mechanism provided in an embodiment of the present application;

[0064] FIG4 is a schematic diagram of a flow chart of a key updating method provided in an embodiment of the present application;

[0065] FIG5 is a schematic diagram of an interaction process between a first network device, a terminal device, and a second network device according to an embodiment of the present application;

[0066] FIG6a is a schematic diagram of data transmission among a first network device, a terminal device, a second network device, and a third network device according to an embodiment of the present application;

[0067] FIG6 b is a schematic diagram of data transmission among another first network device, a terminal device, a second network device, and a third network device according to an embodiment of the present application;

[0068] FIG7 is a schematic structural diagram of a communication device provided in an embodiment of the present application;

[0069] FIG8 is a schematic structural diagram of another communication device provided in an embodiment of the present application;

[0070] FIG9 is a schematic structural diagram of another communication device provided in an embodiment of the present application;

[0071] FIG10 is a structural diagram of an electronic device disclosed in an embodiment of the present application;

[0072] FIG11 is a structural diagram illustrating another electronic device disclosed in an embodiment of the present application. DETAILED DESCRIPTION

[0073] The technical solutions in the embodiments of the present application will be described clearly and completely below in conjunction with the drawings in the embodiments of the present application. The terms used in the following embodiments are only for the purpose of describing specific embodiments and are not intended to be limiting of the present application. As used in the specification and appended claims of the present application, the singular expressions "one", "a kind of", "said", "above", "the" and "this" are intended to also include expressions such as "one or more", unless there is a clear contrary indication in the context. It should also be understood that in the embodiments of the present application, "one or more" refers to one, two or more; "and / or" describes the association relationship of associated objects, indicating that three relationships may exist; for example, A and / or B can represent: the existence of A alone, the existence of A and B at the same time, and the existence of B alone, where A and B can be singular or plural. The character " / " generally indicates that the related objects before and after are in an "or" relationship.

[0074] References to "one embodiment" or "some embodiments" in this specification mean that a particular feature, structure, or characteristic described in conjunction with that embodiment is included in one or more embodiments of the present application. Thus, phrases such as "in one embodiment," "in some embodiments," "in other embodiments," and "in yet other embodiments" appearing in various places in this specification do not necessarily refer to the same embodiment, but rather mean "one or more but not all embodiments," unless otherwise specifically emphasized. The terms "including," "comprising," "having," and variations thereof mean "including but not limited to," unless otherwise specifically emphasized.

[0075] The "multiple" involved in the embodiments of the present application means greater than or equal to two. It should be noted that in the description of the embodiments of the present application, the words "first" and "second" are only used for the purpose of distinguishing the description and cannot be understood as indicating or implying relative importance or order.

[0076] The embodiments of the present application are applied to communication systems, which may be second-generation (2G) communication systems, third-generation (3G) communication systems, LTE systems, fifth-generation (5G) communication systems, LTE and 5G hybrid architectures, 5G New Radio (5G NR) systems, and new communication systems that may emerge in future communication developments.

[0077] The communication system includes a first device and a second device. The first device can be a device on the network side for providing network communication functions, which is sometimes also called a network device or a network element. The network device can generally be a base station (including a functional unit of a base station, or a combination of functional units of a base station) or a core network unit, wherein the core network unit can be a functional unit in the core network, including but not limited to an Access and Mobility Management Function (AMF) unit or a Session Management Function (SMF) unit. The second device can be a device for accessing the network, which can generally be a terminal device. An example of a communication system is shown in Figure 1, which includes a base station 11 and a terminal 12.

[0078] In the embodiments provided in the present application, the base station can be any device with wireless transceiver functions, including but not limited to: an evolved base station (NodeB or eNB or e-NodeB, evolutionary Node B) in long term evolution (LTE), a base station (gNodeB or gNB) or a transmission receiving point (TRP) in new radio (NR), a base station of subsequent evolution of 3GPP, an access node in a Wi-Fi system, a wireless relay node, a wireless backhaul node, etc. The base station can be: a macro base station, a micro base station, a pico base station, a small station, a relay station, or a balloon station, etc. The base station can include one or more co-site or non-co-site transmission points (Transmission Reception Point, TRP). The base station can also be a wireless controller, a centralized unit (CU), and / or a distributed unit (DU) in a cloud radio access network (CRAN) scenario. The base station can communicate with a terminal device, or communicate with the terminal device through a relay station. The terminal device can communicate with multiple base stations of different technologies. For example, the terminal device can communicate with a base station that supports the LTE network, and can also communicate with a base station that supports the 5G network. It can also establish dual connections with a base station that supports the LTE network and a base station that supports the 5G network.

[0079] In the embodiments provided herein, the terminal device may be in various forms, such as a mobile phone, a tablet computer, a computer with wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a vehicle-mounted terminal device, a wireless terminal device in self-driving, a wireless terminal device in remote medical, a wireless terminal device in smart grid, a wireless terminal device in transportation safety, a wireless terminal device in smart city, a wireless terminal device in smart home, a wearable terminal device, etc. The terminal device may also be sometimes referred to as a terminal device, user equipment (UE), an access terminal device, a vehicle-mounted terminal device, an industrial control terminal device, a UE unit, a UE station, a mobile station, a mobile station, a remote station, a remote terminal device, a mobile device, a UE terminal device, a terminal device, a wireless communication device, a UE agent, or a UE device, etc. The terminal device may also be a fixed terminal device or a mobile terminal device.

[0080] In communication systems, cell handovers are often necessary to ensure seamless mobile communication services for terminal devices. Cell handovers are the process by which a terminal device migrates its radio link connection from a source cell to a target cell under the control of the radio access network. Currently, cell handovers can be implemented in a variety of ways.

[0081] Layer 1 / 2 triggered mobility (LTM) mechanism is a method of cell handover. As shown in Figure 2, in the LTM mechanism, a terminal device in a connected state can report network quality measurement results to the network device. The network determines to execute LTM based on the terminal's support capability for LTM. The network device begins to send an LTM handover request to a candidate cell, such as a target cell and a potential target cell. The candidate cell configures the candidate cell information and sends the LTM handover request to the original cell. The original cell sends the candidate cell configuration information to the terminal device via a Radio Resource Control (RRC) reconfiguration message. After receiving the candidate cell configuration information, the terminal device can perform downlink synchronization and uplink synchronization for each candidate cell respectively. When performing uplink synchronization with the candidate cell, if the network device indicates in the RRC reconfiguration message that the terminal device measures the uplink timing advance independently, the terminal device measures the timing advance of the original cell and determines the timing advance of the candidate cell based on the reception time difference between the original cell and the candidate cell. Alternatively, the original cell triggers a contention-free random access (CFR) command via a physical downlink control channel (PDCCH). Random access of CFRA resource information is used to obtain the timing advance of the candidate cell. The terminal device initiates CFRA to the candidate cell to obtain the timing advance, and the network device manages the validity of the timing advance.

[0082] The terminal device performs layer 1 measurements on the original cell and candidate cells and reports the measurement results to the original cell. The original cell determines the target cell based on the measurement results and issues a handover instruction, namely, the LTM handover Media Access Control Layer Control Element (MAC CE) signaling; wherein the MAC CE signaling includes at least the following information: Timing Advance, Transmission Configuration Indication (TCI) state id, CFRA resource information, and configuration information identifier of the candidate cell. For the timing advance in the MAC CE, if the network device determines that the timing advance previously obtained by the terminal device is still valid, then the timing advance is included in the MAC CE signaling.

[0083] When the terminal device receives the LTM handover MAC CE signaling, if the MAC CE carries a timing advance, or when the timing advance is determined by the terminal device itself, the terminal device will initiate a handover without random access to the target cell, that is, the terminal device only needs to send an uplink signaling or the first uplink data packet to the target cell to indicate to the target cell that the access to the target cell is completed.

[0084] Currently, the LTM mechanism only supports switching within a CU and does not involve the update of security keys. When the LTM mechanism supports switching between CUs, the update of security keys needs to be considered.

[0085] Please refer to Figure 3. After completing the authentication between the terminal device and the network device, the anchor key K can be obtained first. SEAF , and further derived K AMF Among them, K SEAF It is an anchor key provided by the Authentication Server Function (AUSF) to the Service Endpoint Access Function (SEAF). During the initial establishment of the security context, the terminal device and the control plane network function unit (Access and Mobility Management Function, AMF) can obtain the K SEAF The original base station key K is derived from gNB and the next hop parameter (Next Hop, NH), where the NH link counter (Next Hop Link Counter, NCC) is associated with each K gNB Associated with NH parameters; when performing horizontal or vertical key derivation, the terminal device and the original base station further derive K gNB , where K is initially set gNB Associated with the NH parameter with NCC value equal to 0. After the handover occurs, the K used by the terminal device and the target base station gNB *From the current K gNB or NH parameter. K gNB * If the current K gNB When exporting, add NCC. If it is derived from NH parameters, indicate to the terminal device to add NCC. RRC signaling encryption key K RRCenc and integrity protection key K RRCint and the encryption key K for the uplink data packet UPenc and integrity protection key K UPint Based on K gNB * and security algorithms. The security algorithms are configured and determined based on the security capabilities of the terminal device.

[0086] Please refer to Figure 4. Currently, when updating the security key used by the terminal device, the terminal device needs to obtain K SEAF , and further derived K AMF During the security context establishment process, the AMF sends the security capabilities of the terminal device to the original base station. The original base station determines the security algorithm, including the integrity protection algorithm and the encryption algorithm, based on the security capabilities of the terminal device. The terminal and the AMF derive K gNB When a handover occurs, the original base station will carry the target base station algorithm and NCC in the handover instruction; the terminal device initiates random access to the target base station and gNB 、NCC derives K gNB *, further derive encryption and integrity protection keys based on the terminal's security algorithm.

[0087] As can be seen from the above content, when the security key used by the terminal device is currently updated, it takes a long time to derive the updated security key of the terminal device, resulting in a long key update delay for the terminal device and low key update efficiency.

[0088] In order to make the technical solution of the present application clearer and easier to understand, the key updating method of the embodiment of the present application is introduced below with reference to the accompanying drawings.

[0089] Please refer to FIG5 , which is a schematic diagram of an interaction process between a first network device, a terminal device, and a second network device according to an embodiment of the present application. A key update method according to an embodiment of the present application mainly includes the following steps:

[0090] 501. A first network device generates security configuration information for a target cell.

[0091] The security configuration information includes multiple update keys and a correspondence between link count values ​​and the multiple update keys.

[0092] In an embodiment of the present application, the first network device may be the original base station corresponding to the original cell to which the terminal device is connected before the cell handover. In order to reduce the key update delay of the terminal device and improve the terminal device, the first network device may first determine which cell the terminal device is about to switch from the original cell, that is, determine the target cell, and pre-configure the security configuration information of the target cell, so that the terminal device can quickly complete the key update according to the security configuration information, without spending a lot of time to deduce the updated key, thereby reducing the time required for the terminal device to update the key, reducing the key update delay of the terminal device, and improving the key update efficiency of the terminal device.

[0093] In an embodiment of the present application, after receiving the network quality measurement result from the terminal device, the first network device may first determine the candidate cells to which the terminal device can switch based on the cell switching capability of the terminal device and the network quality measurement result from the terminal device, wherein the candidate cells include the target cell, and configure security configuration information for each candidate cell to obtain the security configuration information of each candidate cell, so that the terminal device can subsequently quickly switch from the target cell to other candidate cells. In addition, different candidate cells may correspond to the same base station, and the security configuration information configured for the candidate cells in the same base station may be the same. Therefore, a candidate cell set may be generated based on the candidate cells corresponding to the same base station, and then the security configuration information may be configured for different candidate cell sets respectively.

[0094] Specifically, the first network device can use the key K currently used by the terminal device gNB The link count value NCC of the NH link counter is used to derive the update key K gNB *. Update key K gNB * can include multiple keys, that is, the first network device can gNB and multiple different NCCs to derive multiple update keys K gNB *, and each updated key K can be recorded gNB * and used to derive each update key K gNB *The corresponding relationship between the NCCs is used to obtain multiple updated keys K gNB *The corresponding relationship between NCC and finally update the key K based on multiple gNB * and multiple update keys K gNB *The corresponding relationship between the link count value NCC generates the security configuration information of the target cell.

[0095] In a possible implementation of the embodiment of the present application, the security configuration information further includes a link count value corresponding to each updated key. In the embodiment of the present application, the security configuration information generated by the first network device may further include a link count value corresponding to each updated key, that is, the security configuration information may include multiple updated keys, multiple link count values, and a correspondence between the link count value and the multiple updated keys; when the security configuration information includes multiple updated keys, the security configuration information may include multiple link count values, which can be represented by list{K gNB*, NCC} is represented so that when the terminal device and the second network device receive the security configuration information, they can quickly determine the target update key required for this key update from multiple update keys according to the link count value corresponding to each update key to complete the key update, without spending much time to deduce the target update key, thereby reducing the time required for the terminal device to update the key, reducing the key update delay of the terminal device, and improving the key update efficiency of the terminal device.

[0096] In a possible implementation of the embodiment of the present application, the security configuration information also includes a link index.

[0097] Among them, the link index is used to indicate the link count value. In the embodiment of the present application, the link index K_Index can be mapped one-to-one with the NCC, that is, each link index can be used to indicate a link count value. For example, when the link count value ranges from 0 to 7, the link index can also range from 0 to 7. In order to improve the security of key updates, the security configuration information generated by the first network device may not directly include the link count value NCC, but include the link index K_Index used to indicate the NCC, that is, the security configuration information may include multiple update keys, multiple link indices, and the correspondence between the link count value and the multiple update keys, which can be expressed using list{K gNB *, K_Index} is represented so that when the terminal device and the second network device receive the security configuration information, they can first determine the link count value required for this key update according to the link indication, and then quickly determine the target update key required for this key update from multiple update keys according to the link count value to complete the key update, without spending much time to derive the target update key, thereby reducing the time required for the terminal device to update the key, reducing the key update delay of the terminal device, and improving the key update efficiency of the terminal device.

[0098] In one possible implementation of the embodiment of the present application, the security configuration information further includes an encryption algorithm index corresponding to the target cell. In the embodiment of the present application, since different candidate cells may correspond to different encryption algorithms, the security configuration information generated by the first network device may further include the encryption algorithm corresponding to the target cell, so that after the terminal device and the second network device determine the update key and the corresponding link count value, they can quickly find the corresponding encryption algorithm based on the encryption algorithm index corresponding to the target cell to generate the encryption key and the integrity protection key, thereby completing the key update.

[0099] Specifically, the encryption algorithm index in the security configuration information may include multiple different encryption algorithm indexes. Since different link count values ​​may correspond to different encryption algorithm indexes, different link indices may correspond to different encryption algorithm indexes, different link count value sets may correspond to different encryption algorithm indexes, and different link index sets may correspond to different encryption algorithm indexes, the encryption algorithm index in the security configuration information may include the encryption algorithm index corresponding to each link count value, or the encryption algorithm index corresponding to each link index, or the encryption algorithm index corresponding to a set of multiple link count values, or the encryption algorithm index corresponding to a set of multiple link indices.

[0100] In one possible implementation of the embodiment of the present application, the security configuration parameters may also include update indication information.

[0101] The update indication information is used to instruct the terminal to take the lead in key update.

[0102] Specifically, the key update process of the terminal device can be led by the first network device or by the terminal device. When the key update process is led by the first network device, the first network device can determine the target link count value or target link index to be used for this key update, so that the terminal device and the second network device can determine the target update key to be used for this update from the update key based on the target link count value or target link index determined by the first network device, thereby completing the key update. When the key update process is led by the terminal device, the terminal device can determine the target link count value or target link index to be used for this key update, so that the terminal device and the second network device can determine the target update key to be used for this update from multiple update keys based on the target link count value or target link index determined by the first network device, thereby completing the key update.

[0103] 502. The first network device sends a handover request to the second network device corresponding to the target cell.

[0104] The switching request includes security configuration information.

[0105] In an embodiment of the present application, the second network device may be a target base station corresponding to a target cell to which the terminal device is connected after performing a cell handover. After the first network device pre-generates security configuration information for the target cell, it may send a handover request containing the security configuration information to the second network device, so that while notifying the second network device that the terminal device is about to be handed over from the original cell to the target cell, the second network device can quickly perform a key update based on the security configuration information without having to spend a lot of time deriving the updated key with the terminal device, thereby reducing the time required for the terminal device to update the key, reducing the key update delay of the terminal device, and improving the key update efficiency of the terminal device.

[0106] In one possible implementation of the embodiment of the present application, the switching request includes a layer 1 and layer 2 triggered mobility LTM switching request. In the embodiment of the present application, since the current LTM mechanism does not involve switching between CUs, it does not involve the update of security keys. When the LTM mechanism supports switching between CUs in the future, security configuration information including multiple updated keys can be pre-generated by the first network device, and the security configuration information can be sent to the terminal device and the second network device corresponding to the target cell respectively, so that the terminal device and the second network device can quickly complete the key update according to the security configuration information, without spending more time to deduce the updated key, thereby reducing the time required for the terminal device to update the key, reducing the key update delay of the terminal device, and improving the key update efficiency of the terminal device.

[0107] 503. The second network device receives a switching request from the first network device.

[0108] The switching request includes security configuration information, and the security configuration information includes a plurality of update keys and a correspondence between link count values ​​and the plurality of update keys.

[0109] In an embodiment of the present application, the first network device and the second network device can communicate with each other. After the first network device sends a switching request including security configuration information of the target cell to the second network device, the second network device can receive the switching request so that the key can be quickly updated according to the security configuration information in the switching request. There is no need to spend a lot of time to derive the updated key with the terminal device, thereby reducing the time required for the terminal device to update the key, reducing the key update delay of the terminal device, and improving the key update efficiency of the terminal device.

[0110] In a possible implementation of an embodiment of the present application, after receiving a switching request from a first network device, the second network device may return a switching request response to the first network device, wherein the switching request response may include a link count value in the security configuration information, so as to confirm with the first network device whether the received security configuration information is incorrect.

[0111] 504. The first network device sends a reconfiguration instruction to the terminal device.

[0112] The reconfiguration instruction includes security configuration information.

[0113] In an embodiment of the present application, after the first network device pre-generates security configuration information for the target cell, it can send a reconfiguration instruction including the security configuration information to the terminal device, so that while notifying the terminal device of the configuration information required for the terminal device during cell handover, the terminal device can quickly perform a key update based on the received security configuration information without spending a lot of time to derive the updated key, thereby reducing the time required for the terminal device to perform a key update, reducing the key update delay of the terminal device, and improving the key update efficiency of the terminal device. The reconfiguration instruction can be an RRC reconfiguration instruction.

[0114] 505. The terminal device receives a reconfiguration instruction from the first network device.

[0115] The reconfiguration instruction includes security configuration information, and the security configuration information includes a plurality of update keys and a correspondence between link count values ​​and the plurality of update keys.

[0116] In an embodiment of the present application, communication can be performed between the first network device and the terminal device. After the first network device sends a reconfiguration instruction including security configuration information of the target cell to the terminal device, the terminal device can receive the reconfiguration instruction, so that the terminal device can quickly update the key according to the received security configuration information while receiving the configuration information required for cell switching, without spending much time to derive the updated key, thereby reducing the time required for the terminal device to update the key, reducing the key update delay of the terminal device, and improving the key update efficiency of the terminal device.

[0117] In addition, after receiving the reconfiguration instruction from the first network device, the terminal device may return reconfiguration completion information to the first network device to notify the first network device that the reconfiguration instruction has been successfully received.

[0118] 506. The first network device sends a switching instruction to the terminal device.

[0119] In the embodiment of the present application, the first network device can notify the terminal device to switch from the currently connected original cell to the target cell by sending a handover instruction to the terminal device, and can also notify the terminal device to update the key. Because the second terminal device corresponding to the target cell to which the terminal device needs to switch is different from the first terminal device corresponding to the original cell, when the terminal device switches from the original cell to the target cell, a key update is also required to enable secure communication with the target cell.

[0120] In one possible implementation of the embodiment of the present application, the switching instruction includes a target link count value or a target link index. The key update method provided by the embodiment of the present application may also include: when the switching instruction includes the target link count value, sending the target link count value and the unused link count value in the security configuration information to the second network device; when the switching instruction includes the target link index, sending the target link index and the unused link index in the security configuration information to the second network device. In the embodiment of the present application, the first network device can take the lead in the key update process. When the first network device takes the lead in the key update process, the first network device can first specify the target link count value or target link index to be used for this key update based on the security configuration information of the target cell, and can send the target link count value or target link index to the terminal device through the switching instruction. When sending the target link count value or target link index to the terminal device through the switching instruction, the first network device can also synchronously send the target link count value or target link index to the second network device, so that the terminal device can quickly complete the key update without spending more time to deduce the updated key with the second network device, thereby reducing the time required for the terminal device to update the key, reducing the key update delay of the terminal device, and improving the key update efficiency of the terminal device.

[0121] In an embodiment of the present application, when the first network device sends a target link count value or a target link index to the second network device, it may also send to the second network device an unused link count value or an unused link index in the security configuration information, wherein the unused link count value in the security configuration information refers to a link count value that is not specified as a target link count value in the security configuration information, and the unused link index in the security configuration information refers to a link index that is not specified as a target link index in the security configuration information. It is understandable that before switching to the target cell, the terminal device may have experienced multiple cell handovers, that is, may have performed multiple key updates. When the terminal device completes the current cell switching and the current key update and needs to switch to the next cell, that is, use the second network device as the original base station to perform the key update, and the second network device leads the key update process, the first network device sends the unused link count value in the security configuration information or the unused link index in the security configuration information to the second network device, so that the second network device can avoid repeatedly specifying the same link count value as the target link count value or the same link index as the target link index when leading the key update process of the terminal device at the next switching, and avoid using the same key in different key update processes, so that when the terminal device subsequently switches from the target cell to other candidate cells and performs the key update, it can avoid repeatedly using the used update key for key update, thereby improving the effectiveness of the key update.

[0122] 507. The terminal device receives a switching instruction from the first network device.

[0123] In an embodiment of the present application, communication can be performed between the first network device and the terminal device. After the first network device sends a switching instruction to the terminal device, the terminal device can receive the switching instruction, so that while receiving the configuration information required for cell switching, the terminal device can quickly update the key according to the received security configuration information, without spending much time to derive the updated key, thereby reducing the time required for the terminal device to update the key, reducing the key update delay of the terminal device, and improving the key update efficiency of the terminal device.

[0124] 508. The terminal device updates the key based on the security configuration information.

[0125] In an embodiment of the present application, after receiving the switching instruction from the first network device, the terminal device can quickly update the key based on the received security configuration information of the target cell without spending a lot of time to derive the updated key, thereby reducing the time required for the terminal device to update the key, reducing the key update delay of the terminal device, and improving the key update efficiency of the terminal device.

[0126] In a possible implementation of the embodiment of the present application, step 508 of the terminal device updating the key based on the security configuration information includes:

[0127] A1. The terminal device determines the target link count value.

[0128] In an embodiment of the present application, during the process of key update, the terminal device can first determine the target link count value to be used for this key update, so that the target update key to be used for this key update can be determined from multiple update keys, and the encryption key and the integrity protection key can be further obtained, thereby quickly completing the key update without spending much time to derive the target update key in the update key, thereby reducing the time required for the terminal device to update the key, reducing the key update delay of the terminal device, and improving the key update efficiency of the terminal device.

[0129] In a possible implementation of the embodiment of the present application, when the security configuration information includes a link count value corresponding to each updated key, step A1, in which the terminal device determines a target link count value, includes:

[0130] a11. The terminal device determines the link count value with the smallest value as the target link count value.

[0131] In an embodiment of the present application, after receiving security configuration information including a link count value, the terminal device can determine a target link count value based on predefined rules. Specifically, the target link count value to be used for the current key update can be determined from the link count values ​​in order, that is, the link count value with the smallest value can be determined as the target link count value, thereby quickly completing the key update. For example, when the link count values ​​include 1, 2, and 3, the link count value of 1 can be determined as the target link count value.

[0132] In a possible implementation of the embodiment of the present application, when the security configuration information includes a link index, step A1, in which the terminal device determines a target link count value, includes:

[0133] a21. The terminal device determines the link index with the smallest value as the target link index.

[0134] a22. The terminal device determines the target link count value according to the target link index.

[0135] In an embodiment of the present application, after receiving security configuration information including a link count value, the terminal device can determine a target link count value based on predefined rules. Specifically, the target link index to be used for the current key update can be determined from the link count value in sequence, and then the target link count value to be used for the current key update can be determined based on the target link index, thereby quickly completing the key update. For example, when the link index includes 1, 2, and 3, the link index with a value of 1 can be determined as the target link index, and then the target link count value indicated by the target link index can be determined based on the corresponding relationship between the link index and the link count value.

[0136] In a possible implementation of the embodiment of the present application, when the switching instruction includes a target link count value, step A1, in which the terminal device determines the target link count value, includes:

[0137] a3. The terminal device obtains the target link count value from the switching instruction.

[0138] In an embodiment of the present application, when the first network device leads the key update, the terminal device can directly obtain the target link count value specified by the first network device to be used for this update from the switching instruction sent by the first network device, thereby quickly completing the key update.

[0139] In a possible implementation of the embodiment of the present application, when the switching instruction includes a target link index, step A1, in which the terminal device determines a target link count value, includes:

[0140] a41. The terminal device obtains the target link index from the switching instruction.

[0141] a42. The terminal device determines the target link count value according to the target link index.

[0142] In an embodiment of the present application, when the first network device leads the key update, the terminal device can directly obtain the target link index to be used for this update specified by the first network device from the switching instruction sent by the first network device, and then determine the target link count value to be used for this key update based on the target link index, thereby quickly completing the key update.

[0143] In a possible implementation of the embodiment of the present application, after the terminal device determines the target link count value in step A1, the key update method provided in the embodiment of the present application may further include:

[0144] B1. The terminal device sends a target link count value to the second network device.

[0145] In an embodiment of the present application, the terminal device can lead the key update process. That is, after determining the target link count value, the terminal device can send the target link count value to the second network device so that the second network device can synchronize the key update with the terminal device, ensuring the validity of the updated key, thereby quickly completing the key update. Specifically, the terminal device can specify the target link count value from multiple link count values ​​in the security configuration information, and then send the target link count value to the second network device.

[0146] In a possible implementation of the embodiment of the present application, after the terminal device determines the target link count value in step A1, the key update method provided in the embodiment of the present application may further include:

[0147] C1. The terminal device sends a target link index corresponding to the target link count value to the second network device.

[0148] In an embodiment of the present application, to improve the security of key updates, after determining the target link count value, the terminal device can send a target link index corresponding to the target link count value to the second network device to prevent the target link count value from being leaked during transmission. Specifically, the terminal device can specify the target link count value from multiple link count values ​​in the security configuration information, then determine the target link index used to indicate the target link count value, and send the target link index to the second network device. This allows the second network device to synchronize key updates with the terminal device, ensuring the validity and security of the updated key, thereby quickly completing the key update.

[0149] In a possible implementation of an embodiment of the present application, when the terminal device sends a target link count value or a target link index to the second network device, it can also send an unused link count value or an unused link index to the second network device, so that when the terminal device subsequently switches from the target cell to other candidate cells and performs a key update, it can avoid other candidate cells from reusing the used update key for key update.

[0150] A2. The terminal device determines a target update key from multiple update keys according to the target link count value.

[0151] In an embodiment of the present application, after determining the target link count value, the terminal device can determine the target update key corresponding to the target link count value from the multiple update keys based on the multiple update keys included in the security configuration information and the correspondence between the link count value and the multiple update keys, that is, the update key to be used for this key update.

[0152] A3. The terminal device generates an encryption key and an integrity protection key based on the target link count value and the target update key.

[0153] In an embodiment of the present application, after determining the target update key based on the target link count value, the terminal device can obtain the encryption algorithm corresponding to the target cell, and finally generate the encryption key and integrity protection key based on the encryption algorithm corresponding to the target cell, the target link count value, and the target update key. Specifically, the terminal device can obtain the encryption algorithm index corresponding to the target cell from the security configuration information, obtain the encryption algorithm corresponding to the target cell by inputting the target link count value into the encryption algorithm index, and then generate the encryption key and integrity protection key based on the encryption algorithm corresponding to the target cell, the target link count value, and the target update key, thereby quickly completing the key update without spending a lot of time to derive the target update key in the update key, thereby reducing the time required for the terminal device to update the key, reducing the key update delay of the terminal device, and improving the key update efficiency of the terminal device.

[0154] In one possible implementation of the embodiment of the present application, after the terminal device generates an encryption key and an integrity protection key according to the target link count value and the target update key, the key update method provided in the embodiment of the present application may further include:

[0155] D1. The terminal device deletes the target link count value or target link index.

[0156] In an embodiment of the present application, in order to improve the security of key update, after the terminal device uses the target link count value or target link index to update the key, it can delete the used target link count value or target link index to avoid the updated key being reused, resulting in a reduction in the effectiveness of the updated key, thereby quickly completing the key update.

[0157] 509. The second network device updates the key based on the security configuration information.

[0158] In an embodiment of the present application, after receiving a switching request from a terminal device, the second network device can quickly update the key based on the security configuration information of the target cell in the received switching request, without spending a lot of time to derive the updated key with the terminal device, thereby reducing the time required for the terminal device to update the key, reducing the key update delay of the terminal device, and improving the key update efficiency of the terminal device.

[0159] In a possible implementation of the embodiment of the present application, step 509 of the second network device performing key update based on the security configuration information includes:

[0160] E1. The second network device determines a target link count value.

[0161] In an embodiment of the present application, during the process of key update, the terminal device can first determine the target link count value to be used for this key update, so that the target update key to be used for this key update can be determined from multiple update keys, and the encryption key and the integrity protection key can be further obtained, thereby quickly completing the key update without spending much time to derive the target update key in the update key, thereby reducing the time required for the terminal device to update the key, reducing the key update delay of the terminal device, and improving the key update efficiency of the terminal device.

[0162] In a possible implementation of the embodiment of the present application, when the security configuration information includes a link count value corresponding to each updated key, step E1, in which the second network device determines a target link count value, includes:

[0163] e11. The second network device determines the link count value with the smallest value as the target link count value.

[0164] In an embodiment of the present application, after receiving security configuration information including a link count value, the second network device can determine a target link count value based on predefined rules. Specifically, the target link count value to be used for the current key update can be determined from the link count values ​​in order, that is, the link count value with the smallest value can be determined as the target link count value, thereby quickly completing the key update. For example, when the link count values ​​include 1, 2, and 3, the link count value of 1 can be determined as the target link count value.

[0165] In a possible implementation of the embodiment of the present application, when the security configuration information includes a link index, step E1, in which the second network device determines a target link count value, includes:

[0166] e21. The second network device determines the link index with the smallest value as the target link index.

[0167] e22. The second network device determines a target link count value according to the target link index.

[0168] In an embodiment of the present application, after receiving security configuration information including a link count value, the second network device can determine a target link count value based on predefined rules. Specifically, the target link index to be used for the current key update can be determined from the link count value in sequence, and then the target link count value to be used for the current key update can be determined based on the target link index, thereby quickly completing the key update. For example, when the link index includes 1, 2, and 3, the link index with a value of 1 can be determined as the target link index, and then the target link count value indicated by the target link index can be determined based on the corresponding relationship between the link index and the link count value.

[0169] In a possible implementation of the embodiment of the present application, step E1, in which the second network device determines a target link count value, includes:

[0170] e3. The second network device receives the target link count value from the first network device or the terminal device.

[0171] In an embodiment of the present application, when the first network device leads the key update process, the second network device can receive the target link count value from the first network device to obtain the target link count value specified by the first network device for the current update, thereby quickly completing the key update. When the terminal device leads the key update process, the second network device can receive the target link count value from the terminal device to obtain the target link count value specified by the terminal device for the current update, thereby quickly completing the key update.

[0172] In a possible implementation of the embodiment of the present application, step E1, in which the second network device determines a target link count value, includes:

[0173] e41. The second network device receives a target link index from the first network device or the terminal device.

[0174] e42. The second network device determines a target link count value according to the target link index.

[0175] In an embodiment of the present application, when the first network device initiates the key update, the second network device can receive the target link count value from the first network device to obtain the target link index specified by the first network device for the current update, and then determine the target link count value to be used for the current key update based on the target link index, thereby quickly completing the key update. When the terminal device initiates the key update, the second network device can receive the target link count value from the terminal device to obtain the target link index specified by the terminal device for the current update, and then determine the target link count value to be used for the current key update based on the target link index, thereby quickly completing the key update.

[0176] E2. The second network device determines a target update key from multiple update keys according to the target link count value.

[0177] In an embodiment of the present application, after determining the target link count value, the second network device can determine the target update key corresponding to the target link count value from the multiple update keys based on the multiple update keys included in the security configuration information and the correspondence between the link count value and the multiple update keys, that is, the update key to be used for this key update.

[0178] E3. The second network device generates an encryption key and an integrity protection key according to the target link count value and the target update key.

[0179] In an embodiment of the present application, after determining the target update key based on the target link count value, the second network device can obtain the encryption algorithm corresponding to the target cell, and finally generate the encryption key and integrity protection key based on the encryption algorithm corresponding to the target cell, the target link count value, and the target update key. Specifically, the second network device can obtain the encryption algorithm index corresponding to the target cell from the security configuration information, obtain the encryption algorithm corresponding to the target cell by inputting the target link count value into the encryption algorithm index, and then generate the encryption key and integrity protection key based on the encryption algorithm corresponding to the target cell, the target link count value, and the target update key, thereby quickly completing the key update without spending a lot of time to derive the target update key in the update key with the terminal device, thereby reducing the time required for the terminal device to update the key, reducing the key update delay of the terminal device, and improving the key update efficiency of the terminal device.

[0180] In one possible implementation of the embodiment of the present application, after executing step E3 where the second network device generates an encryption key and an integrity protection key based on the target link count value and the target update key, the key update method provided in the embodiment of the present application may further include:

[0181] F1. The second network device deletes the target link count value or the target link index.

[0182] In an embodiment of the present application, in order to improve the security of key update, the second network device can delete the used target link count value or target link index after using the target link count value or target link index to update the key, so as to avoid the updated key being reused, resulting in a reduction in the effectiveness of the updated key, thereby quickly completing the key update.

[0183] In an embodiment of the present application, after the terminal device and the second network device complete the key update, they can communicate based on the updated key, thereby enabling the terminal device to switch from the original cell to the target cell.

[0184] It can be seen from the examples of the aforementioned embodiments that in order to reduce the key update delay of the terminal device and improve the key update efficiency of the terminal device, the first network device can pre-generate security configuration information including multiple updated keys, and send the security configuration information to the terminal device and the second network device corresponding to the target cell respectively, so that the terminal device and the second network device can quickly complete the key update according to the security configuration information including multiple updated keys, without spending more time to deduce the updated key, thereby reducing the time required for the terminal device to update the key, reducing the key update delay of the terminal device, and improving the key update efficiency of the terminal device.

[0185] In order to make the technical solution of the present application clearer and easier to understand, the key update method of the present application is described in detail below in conjunction with a specific data transmission scenario of the first network device, the terminal device, and the second network device.

[0186] Referring to a data transmission diagram of a first network device, a terminal device, a second network device, and a third network device shown in FIG6a, wherein the first network device may be an original base station S-gNB corresponding to the original cell, the terminal device may be a UE, the second network device may be a target base station T-gNB corresponding to the target cell, and the third network device may be a potential target base station potential T-gNB corresponding to the potential target cell. The key update method in the embodiment of the present application includes the following steps:

[0187] S01. The UE reports the measurement results to the S-gNB.

[0188] In an embodiment of the present application, the UE may report network measurement results to the S-gNB, so that the S-gNB can determine the target cell and potential target cells from multiple candidate cells based on the network measurement results. The S-gNB can configure security configuration information for each candidate cell so that the UE can subsequently quickly switch from the target cell to other candidate cells. In addition, different candidate cells may correspond to the same base station, and the security configuration information configured for the candidate cells in the same base station may be the same. Therefore, a candidate cell set can be generated based on the candidate cells corresponding to the same base station, and then the security configuration information can be configured for different candidate cell sets respectively.

[0189] Specifically, each candidate cell set or each candidate cell corresponding security configuration information may include multiple update keys, multiple link count values, and the corresponding relationship between the link count value and the multiple update keys; when the security configuration information includes multiple update keys, the security configuration information may include multiple link count values, which can be represented by list{K gNB *, NCC} are indicated.

[0190] Alternatively, each candidate cell set or the security configuration information corresponding to each candidate cell may include multiple update keys, multiple link indices, and the corresponding relationship between the link count value and the multiple update keys, which can be expressed as list{K gNB *, K_Index}.

[0191] Alternatively, the security configuration information corresponding to each candidate cell set or each candidate cell may include multiple update keys, multiple link count values, a correspondence between the link count values ​​and the multiple update keys, and an encryption algorithm index corresponding to each candidate cell.

[0192] Alternatively, the security configuration information corresponding to each candidate cell set or each candidate cell may include multiple update keys, multiple link indexes, a correspondence between link count values ​​and multiple update keys, and an encryption algorithm index corresponding to each candidate cell.

[0193] S02. The S-gNB sends an LTM handover request to the T-gNB.

[0194] S03. The T-gNB returns an LTM handover request response to the S-gNB.

[0195] S04. The S-gNB sends an LTM handover request to the potential T-gNB.

[0196] S05. The potential T-gNB returns an LTM handover request response to the S-gNB.

[0197] In an embodiment of the present application, after configuring the security configuration information corresponding to each candidate cell set or each candidate cell, the S-gNB may send the security configuration information of the target cell to the T-gNB via an LTM handover request, and send the security configuration information of other candidate cells, i.e., potential target cells, to the potential T-gNB. Furthermore, the security capabilities of the terminal device may be sent to the target cell and the potential target cell. The LTM handover request response returned by the T-gNB and the potential T-gNB to the S-gNB may include the NCC or K_Index or the corresponding encryption algorithm index, so that the S-gNB can determine whether the T-gNB and the potential T-gNB have received the correct security configuration information, thereby completing the S-gNB's pre-configuration process for the security configuration information of the T-gNB and the potential T-gNB.

[0198] S06. The S-gNB sends an RRC reconfiguration command to the UE.

[0199] S07. The UE returns RRC reconfiguration completion information to the S-gNB.

[0200] In an embodiment of the present application, after the S-gNB pre-generates security configuration information for a candidate cell, it may send an RRC reconfiguration instruction including the security configuration information to the UE. This allows the UE to quickly perform a key update based on the received security configuration information while notifying the UE of the configuration information required for cell handover, without having to spend a long time deriving the updated key. This reduces the time required for the UE to perform a key update, reduces the key update latency of the terminal device, and improves the key update efficiency of the terminal device. After receiving the reconfiguration instruction from the S-gNB, the UE may return an RRC reconfiguration completion message to the S-gNB to notify the S-gNB that the reconfiguration instruction has been successfully received.

[0201] S08. The S-gNB sends an LTM switching command to the UE.

[0202] S09. The S-gNB notifies the T-gNB of the key update parameters.

[0203] In the embodiment of the present application, the S-gNB can lead the key update process. The S-gNB can specify the target link count value or target link index required for this key update, that is, specify the key update parameters, and send the key update parameters to the UE through the LTM handover instruction, and directly notify the key update parameters to the T-gNB, so that the UE and T-gNB can quickly complete the key update process according to the key update parameters and the security configuration parameters of the target cell. The S-gNB can also notify the T-gNB of the unused security configuration parameters of each candidate cell, that is, the unused list{K gNB *, NCC} and the unused list {K gNB *, K_Index}.

[0204] S10. The UE communicates with the T-gNB.

[0205] In an embodiment of the present application, after the UE and T-gNB complete the key update, they can communicate based on the updated key, thereby enabling the UE to switch from the original cell to the target cell.

[0206] It can be seen from the examples of the aforementioned embodiments that in order to reduce the key update delay of the terminal device and improve the key update efficiency of the terminal device, the S-gNB can pre-generate security configuration information including multiple updated keys, and send the security configuration information to the UE and the T-gNB corresponding to the target cell and the potential T-gNB corresponding to the potential candidate cell respectively. The S-gNB can lead the key update process, so that the UE and T-gNB can quickly complete the key update according to the security configuration information including multiple updated keys, without spending a lot of time to derive the updated key, thereby reducing the time required for the UE to update the key, reducing the UE's key update delay, and improving the UE's key update efficiency.

[0207] Referring to another data transmission diagram of a first network device, a terminal device, a second network device, and a third network device shown in FIG6b, the first network device may be an original base station S-gNB corresponding to the original cell, the terminal device may be a UE, the second network device may be a target base station T-gNB corresponding to the target cell, and the third network device may be a potential target base station potential T-gNB corresponding to the potential target cell. The key update method in the embodiment of the present application includes the following steps:

[0208] S11. The UE reports the measurement results to the S-gNB.

[0209] S12. The S-gNB sends an LTM handover request to the T-gNB.

[0210] S13. The S-gNB receives the LTM handover request response returned by the T-gNB.

[0211] S14. The S-gNB sends an LTM handover request to the potential T-gNB.

[0212] S15. The S-gNB receives the LTM handover request response returned by the potential T-gNB.

[0213] S16. The S-gNB sends an RRC reconfiguration command to the UE.

[0214] S17. The UE returns RRC reconfiguration completion information to the S-gNB.

[0215] The above steps S11 to S17 are similar to steps S01 to S07 in the above embodiment and will not be described in detail here.

[0216] S18. The S-gNB sends an LTM switching command to the UE.

[0217] S19. The UE determines a key update parameter.

[0218] S20. The UE notifies the T-gNB of key update parameters.

[0219] In the embodiment of the present application, the UE can take the lead in the key update process. After receiving the LTM handover instruction sent by the S-gNB, the UE can specify the target link count value or target link index required for this key update, that is, specify the key update parameters, and directly notify the T-gNB of the key update parameters, so that the UE and T-gNB can quickly complete the key update process based on the key update parameters and the security configuration parameters of the target cell. The UE can also notify the T-gNB of the unused security configuration parameters of each candidate cell, that is, the unused list{K gNB *, NCC} and the unused list {K gNB *, K_Index}.

[0220] S21. The UE communicates with the T-gNB.

[0221] In an embodiment of the present application, after the UE and T-gNB complete the key update, they can communicate based on the updated key, thereby enabling the UE to switch from the original cell to the target cell.

[0222] It can be seen from the examples of the aforementioned embodiments that in order to reduce the key update delay of the terminal device and improve the key update efficiency of the terminal device, the S-gNB can pre-generate security configuration information including multiple updated keys, and send the security configuration information to the UE and the T-gNB corresponding to the target cell and the potential T-gNB corresponding to the potential candidate cell respectively. The UE can lead the key update process, so that the UE and T-gNB can quickly complete the key update according to the security configuration information including multiple updated keys, without spending a lot of time to deduce the updated key, thereby reducing the time required for the UE to update the key, reducing the UE's key update delay, and improving the UE's key update efficiency.

[0223] FIG7 is a schematic diagram of the structure of a communication device provided in an embodiment of the present application. The communication device may be a first network device, and the communication device may include:

[0224] A generating module 701 is configured to generate security configuration information of a target cell, wherein the security configuration information includes a plurality of update keys and a correspondence between a link count value and the plurality of update keys;

[0225] a sending module 702, configured to send a handover request to a second network device corresponding to the target cell, so that the second network device corresponding to the target cell performs a key update based on the security configuration information, wherein the handover request includes the security configuration information;

[0226] The sending module 702 is further configured to send a reconfiguration instruction to the terminal device, where the reconfiguration instruction includes the security configuration information;

[0227] The sending module 702 is further configured to send a switching instruction to the terminal device, so that the terminal device updates the key based on the security configuration information.

[0228] In a possible implementation manner of the embodiment of the present application, the security configuration information further includes a link count value corresponding to each updated key.

[0229] In a possible implementation manner of the embodiment of the present application, the security configuration information further includes a link index, and the link index is used to indicate the link count value.

[0230] In a possible implementation manner of the embodiment of the present application, the security configuration information further includes an encryption algorithm index corresponding to the target cell.

[0231] In a possible implementation manner of the embodiment of the present application, the switching instruction includes a target link count value or a target link index, and the apparatus further includes:

[0232] When the switching instruction includes the target link count value, the sending module 702 is further configured to send the target link count value and unused link count values ​​in the security configuration information to the second network device;

[0233] When the switching instruction includes the target link index, the sending module 702 is further configured to send the target link index and an unused link index in the security configuration information to the second network device.

[0234] In a possible implementation manner of the embodiment of the present application, the handover request includes a Layer 1 / 2 Triggered Mobility LTM handover request.

[0235] FIG8 is a schematic diagram of the structure of another communication device provided in an embodiment of the present application. The communication device may be a terminal device, and the communication device may include:

[0236] A receiving module 801 is configured to receive a reconfiguration instruction from a first network device, wherein the reconfiguration instruction includes security configuration information, and the security configuration information includes a plurality of update keys and a correspondence between a link count value and the plurality of update keys;

[0237] The receiving module 801 is configured to receive a switching instruction from a first network device;

[0238] The key updating module 802 is configured to update the key based on the security configuration information.

[0239] In a possible implementation manner of the embodiment of the present application, the security configuration information further includes a link count value corresponding to each updated key.

[0240] In a possible implementation manner of the embodiment of the present application, the security configuration information further includes a link index, and the link index is used to indicate the link count value.

[0241] In a possible implementation manner of the embodiment of the present application, the security configuration information further includes an encryption algorithm index corresponding to the target cell.

[0242] In a possible implementation of the embodiment of the present application, the key update module 802 includes:

[0243] a determining unit, configured to determine a target link count value;

[0244] The determining unit is configured to determine a target update key from the multiple update keys according to the target link count value;

[0245] A generating unit is configured to generate an encryption key and an integrity protection key according to the target link count value and the target update key.

[0246] In a possible implementation manner of the embodiment of the present application, when the security configuration information includes a link count value corresponding to each updated key, the determining unit is specifically configured to:

[0247] The link count value with the smallest value is determined as the target link count value.

[0248] In a possible implementation manner of the embodiment of the present application, when the security configuration information includes a link index, the determining unit is specifically configured to:

[0249] Determine the link index with the smallest value as the target link index;

[0250] A target link count value is determined according to the target link index.

[0251] In a possible implementation of the embodiment of the present application, the apparatus further includes:

[0252] The deletion module is configured to delete the target link count value or the target link index.

[0253] In a possible implementation manner of the embodiment of the present application, when the switching instruction includes a target link count value, the determining unit is specifically configured to:

[0254] A target link count value is obtained from the switching instruction.

[0255] In a possible implementation manner of the embodiment of the present application, when the switching instruction includes a target link index, the determining unit is specifically configured to:

[0256] Obtaining a target link index from the switching instruction;

[0257] A target link count value is determined according to the target link index.

[0258] In a possible implementation of the embodiment of the present application, the apparatus further includes:

[0259] A sending module is used to send a target link index corresponding to the target link count value to the second network device.

[0260] In a possible implementation of the embodiment of the present application, the apparatus further includes:

[0261] A sending module is used to send a target link index corresponding to the target link count value to the second network device.

[0262] FIG9 is a schematic diagram of the structure of another communication device provided in an embodiment of the present application. The communication device may be a second network device, and the communication device may include:

[0263] A receiving module 901 is configured to receive a handover request from a first network device, the handover request including security configuration information, the security configuration information including a plurality of update keys and a correspondence between a link count value and the plurality of update keys;

[0264] The key updating module 902 is configured to update the key based on the security configuration information.

[0265] In a possible implementation manner of the embodiment of the present application, the security configuration information further includes a link count value corresponding to each updated key.

[0266] In a possible implementation manner of the embodiment of the present application, the security configuration information further includes a link index, and the link index is used to indicate the link count value.

[0267] In a possible implementation manner of the embodiment of the present application, the security configuration information further includes an encryption algorithm index corresponding to the target cell.

[0268] In a possible implementation of the embodiment of the present application, the key update module includes:

[0269] a determining unit, configured to determine a target link count value;

[0270] The determining unit is further configured to determine a target update key from the multiple update keys according to the target link count value;

[0271] A generating unit is configured to generate an encryption key and an integrity protection key according to the target link count value and the target update key.

[0272] In a possible implementation manner of the embodiment of the present application, when the security configuration information includes a link count value corresponding to each updated key, the determining unit is specifically configured to:

[0273] The link count value with the smallest value is determined as the target link count value.

[0274] In a possible implementation manner of the embodiment of the present application, when the security configuration information includes a link index, the determining unit is specifically configured to:

[0275] The link index with the smallest value is determined as the target link index;

[0276] A target link count value is determined according to the target link index.

[0277] In a possible implementation of the embodiment of the present application, the determining unit is specifically configured to:

[0278] A target link count value is received from the first network device or the terminal device.

[0279] In a possible implementation of the embodiment of the present application, the determining unit is specifically configured to:

[0280] receiving a target link index from the first network device or the terminal device;

[0281] A target link count value is determined according to the target link index.

[0282] Figure 10 is an example of the composition of an electronic device provided in an embodiment of the present application. The electronic device may be a first device, including but not limited to a base station and a core network unit. Figure 10 shows a simplified schematic diagram of the base station structure. The base station includes parts 1010, 1020, and 1030. Part 1010 is mainly used for baseband processing, controlling the base station, etc.; Part 1010 is usually the control center of the base station, which can usually be called a processor, and is used to control the base station to perform the processing operations on the first device side in the above method embodiment. Part 1020 is mainly used to store computer program code and data. Part 1030 is mainly used for receiving and transmitting radio frequency signals and converting radio frequency signals into baseband signals; Part 1030 can usually be called a transceiver module, a transceiver, a transceiver circuit, or a transceiver, etc. The transceiver module of part 1030, which can also be called a transceiver or a transceiver, etc., includes an antenna 1033 and a radio frequency circuit (not shown in the figure), wherein the radio frequency circuit is mainly used for radio frequency processing. Alternatively, the device for implementing the receiving function in section 1030 may be considered a receiver, and the device for implementing the transmitting function may be considered a transmitter, that is, section 1030 includes a receiver 1032 and a transmitter 1031. A receiver may also be referred to as a receiving module, a receiver, or a receiving circuit, and a transmitter may be referred to as a transmitting module, a transmitter, or a transmitting circuit.

[0283] Sections 1010 and 1020 may include one or more boards, each of which may include one or more processors and one or more memories. The processor is used to read and execute programs in the memory to implement baseband processing functions and control the base station. If multiple boards are present, the boards may be interconnected to enhance processing capabilities. As an optional implementation, multiple boards may share one or more processors, multiple boards may share one or more memories, or multiple boards may simultaneously share one or more processors.

[0284] For example, in one implementation, the transceiver module in part 1030 is used to execute the transceiver-related processes executed by the base station (first device) in the aforementioned method embodiment. The processor in part 1010 is used to execute the processing-related processes executed by the base station in the aforementioned method embodiment.

[0285] It should be understood that FIG10 is merely an example and not a limitation, and the network device including the processor, memory, and transceiver may not rely on the structure shown in FIG10 .

[0286] Figure 11 is an example of the composition of another electronic device provided in an embodiment of the present application. The electronic device can be a second device, which can be a terminal device, including but not limited to mobile phones, smart wearable devices (such as smart watches), and other electronic devices. Taking a mobile phone as an example, the electronic device may include a processor 310, an external memory interface 320, an internal memory 321, a display 330, a camera 340, an antenna 1, an antenna 2, a mobile communication module 350, and a wireless communication module 360, etc.

[0287] It should be understood that the structure illustrated in this embodiment does not constitute a specific limitation on the electronic device. In other embodiments, the electronic device may include more or fewer components than shown, or some components may be combined or separated, or the components may be arranged differently. The components shown in the figure may be implemented in hardware, software, or a combination of software and hardware.

[0288] The processor 310 may include one or more processing units. For example, the processor 310 may include an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU). The different processing units may be independent devices or integrated into one or more processors.

[0289] It is understood that the interface connection relationship between the modules illustrated in this embodiment is only a schematic illustration and does not constitute a structural limitation of the electronic device. In other embodiments of the present application, the electronic device may also adopt different interface connection methods in the above embodiments, or a combination of multiple interface connection methods.

[0290] External memory interface 320 can be used to connect an external memory card, such as a Micro SD card, to expand the storage capacity of the electronic device. The external memory card communicates with processor 310 via external memory interface 320 to implement data storage functions. For example, files such as music and videos can be stored on the external memory card.

[0291] The internal memory 321 can be used to store computer executable program code, and the executable program code includes instructions. The processor 310 executes various functional applications and data processing of the electronic device by running the instructions stored in the internal memory 321. The internal memory 321 may include a program storage area and a data storage area. Among them, the program storage area can store an operating system, an application required for at least one function (such as a sound playback function, an image playback function, etc.), etc. The data storage area can store data created during the use of the electronic device (such as audio data, a phone book, etc.), etc. In addition, the internal memory 321 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, a universal flash storage (UFS), etc. The processor 310 executes various functional applications and data processing of the electronic device by running the instructions stored in the internal memory 321, and / or the instructions stored in the memory provided in the processor.

[0292] The wireless communication function of the electronic device can be implemented through antenna 1, antenna 2, mobile communication module 350, wireless communication module 360, modem processor and baseband processor.

[0293] Antenna 1 and Antenna 2 are used to transmit and receive electromagnetic wave signals. Each antenna in an electronic device can be used to cover a single or multiple communication frequency bands. Different antennas can also be reused to improve antenna utilization. For example, antenna 1 can be reused as a diversity antenna for a wireless local area network. In other embodiments, the antennas can be used in conjunction with a tuning switch.

[0294] The mobile communication module 350 can provide solutions for wireless communications including 2G / 3G / 4G / 5G applied to electronic devices. The mobile communication module 350 may include at least one filter, a switch, a power amplifier, a low noise amplifier (LNA), etc. The mobile communication module 350 can receive electromagnetic waves from the antenna 1, and filter, amplify, and process the received electromagnetic waves, and transmit them to the modulation and demodulation processor for demodulation. The mobile communication module 350 can also amplify the signal modulated by the modulation and demodulation processor, and convert it into electromagnetic waves for radiation through the antenna 1. In some embodiments, at least some of the functional modules of the mobile communication module 350 can be set in the processor 310. In some embodiments, at least some of the functional modules of the mobile communication module 350 can be set in the same device as at least some of the modules of the processor 310.

[0295] In some embodiments, the electronic device initiates or receives a call request via the mobile communication module 350 and the antenna 1 .

[0296] Furthermore, an operating system runs on the aforementioned components, such as the iOS operating system, the Android operating system, and the Windows operating system. Application programs can be installed and run on the operating system. Those skilled in the art will clearly understand that, for ease of description and brevity, the explanation and beneficial effects of any of the aforementioned electronic devices can be referred to the corresponding method embodiments provided above, and will not be further elaborated here.

[0297] The present application also provides a communication system, which may include a first device as shown in FIG10 (for example, a network device such as a base station) and a second device as shown in FIG11 (for example, a terminal device such as a mobile phone).

[0298] In this application, a terminal device or network device may include a hardware layer, an operating system layer running on the hardware layer, and an application layer running on the operating system layer. The hardware layer may include hardware such as a central processing unit (CPU), a memory management unit (MMU), and memory (also known as main memory). The operating system of the operating system layer may be any one or more computer operating systems that implement business processing through processes, such as the Linux operating system, Unix operating system, Android operating system, iOS operating system, or Windows operating system. The application layer may include applications such as browsers, address books, word processing software, and instant messaging software.

[0299] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described systems, devices and modules can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0300] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the modules is merely a logical function division. In actual implementation, there may be other division methods, such as multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interface, device or module, which can be electrical, mechanical or other forms.

[0301] The modules described as separate components may or may not be physically separate, and the components shown as modules may or may not be physical modules, that is, they may be located in one place or distributed across multiple network modules. Some or all of the modules may be selected to achieve the purpose of the present embodiment according to actual needs.

[0302] In addition, the functional modules in the various embodiments of the present application may be integrated into a processing module, or each module may exist physically separately, or two or more modules may be integrated into a single module. The above-mentioned integrated modules may be implemented in the form of hardware or software functional modules.

[0303] If the integrated module is implemented in the form of a software functional module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the part that essentially contributes to the technical solution of the present application or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the process of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory, a random access memory, a magnetic disk or an optical disk.

[0304] As described above, the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the above embodiments, ordinary technicians in this field should understand that they can still modify the technical solutions recorded in the above embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present application.

Claims

1. A key update method, characterized in that: Applied to a first network device, the method includes: Generate security configuration information of the target cell, the security configuration information including a plurality of update keys and a correspondence between a link count value and the plurality of update keys; Sending a handover request to a second network device corresponding to the target cell, so that the second network device corresponding to the target cell performs a key update based on the security configuration information, wherein the handover request includes the security configuration information; Sending a reconfiguration instruction to the terminal device, where the reconfiguration instruction includes the security configuration information; A switching instruction is sent to the terminal device, so that the terminal device updates the key based on the security configuration information.

2. The method according to claim 1, characterized in that The security configuration information also includes a link count value corresponding to each updated key.

3. The method according to claim 1, characterized in that The security configuration information further includes a link index, where the link index is used to indicate the link count value.

4. The method according to any one of claims 1 to 3, characterized in that The security configuration information also includes an encryption algorithm index corresponding to the target cell.

5. The method according to claim 1, wherein The switching instruction includes a target link count value or a target link index, and the method further includes: When the switching instruction includes the target link count value, sending the target link count value and unused link count values ​​in the security configuration information to the second network device; When the switching instruction includes the target link index, the target link index and an unused link index in the security configuration information are sent to the second network device.

6. The method according to claim 1, characterized in that The handover request includes a layer 1 and layer 2 triggered mobility LTM handover request.

7. A key update method, characterized in that: Applied to a terminal device, the method includes: receiving a reconfiguration instruction from a first network device, the reconfiguration instruction including security configuration information, the security configuration information including a plurality of update keys and a correspondence between a link count value and the plurality of update keys; receiving a switching instruction from the first network device; The key is updated based on the security configuration information.

8. The method according to claim 7, characterized in that The security configuration information also includes a link count value corresponding to each updated key.

9. The method according to claim 7, characterized in that The security configuration information further includes a link index, where the link index is used to indicate the link count value.

10. The method according to any one of claims 7 to 9, characterized in that The security configuration information also includes an encryption algorithm index corresponding to the target cell.

11. The method according to any one of claims 7 to 9, characterized in that The updating of the key based on the security configuration information includes: determining a target link count value; determining a target update key from the plurality of update keys according to the target link count value; An encryption key and an integrity protection key are generated according to the target link count value and the target update key.

12. The method according to claim 11, characterized in that When the security configuration information includes a link count value corresponding to each updated key, determining the target link count value includes: The link count value with the smallest value is determined as the target link count value.

13. The method according to claim 11, characterized in that When the security configuration information includes a link index, determining the target link count value includes: Determine the link index with the smallest value as the target link index; A target link count value is determined according to the target link index.

14. The method according to claim 12 or 13, characterized in that After generating an encryption key and an integrity protection key according to the target link count value and the target update key, the method further includes: The target link count value or the target link index is deleted.

15. The method according to claim 11, characterized in that When the switching instruction includes a target link count value, determining the target link count value includes: A target link count value is obtained from the switching instruction.

16. The method according to claim 11, characterized in that When the switching instruction includes a target link index, determining the target link count value includes: Obtaining a target link index from the switching instruction; A target link count value is determined according to the target link index.

17. The method according to claim 11, characterized in that After determining the target link count value, the method further includes: The target link count value is sent to the second network device.

18. The method according to claim 11, characterized in that After determining the target link count value, the method further includes: Sending a target link index corresponding to the target link count value to the second network device.

19. A key update method, characterized in that: Applied to the second network device, the method includes: receiving a handover request from a first network device, the handover request including security configuration information, the security configuration information including a plurality of update keys and a correspondence between a link count value and the plurality of update keys; The key is updated based on the security configuration information.

20. The method according to claim 19, characterized in that The security configuration information also includes a link count value corresponding to each updated key.

21. The method according to claim 19, wherein The security configuration information further includes a link index, where the link index is used to indicate the link count value.

22. The method according to any one of claims 19 to 21, characterized in that The security configuration information also includes an encryption algorithm index corresponding to the target cell.

23. The method according to claim 19, wherein The updating of the key based on the security configuration information includes: determining a target link count value; determining a target update key from the plurality of update keys according to the target link count value; An encryption key and an integrity protection key are generated according to the target link count value and the target update key.

24. The method according to claim 23, wherein When the security configuration information includes a link count value corresponding to each updated key, determining the target link count value includes: The link count value with the smallest value is determined as the target link count value.

25. The method according to claim 23, characterized in that When the security configuration information includes a link index, determining the target link count value includes: The link index with the smallest value is determined as the target link index; A target link count value is determined according to the target link index.

26. The method according to claim 23, wherein Determining the target link count value includes: A target link count value is received from the first network device or the terminal device.

27. The method according to claim 23, wherein Determining the target link count value includes: receiving a target link index from the first network device or the terminal device; A target link count value is determined according to the target link index.

28. A communication device, characterized in that: The communication device is specifically a first network device, and the communication device includes: A generating module, configured to generate security configuration information of a target cell, the security configuration information including a plurality of update keys and a correspondence between a link count value and the plurality of update keys; a sending module, configured to send a handover request to a second network device corresponding to the target cell, so that the second network device corresponding to the target cell performs a key update based on the security configuration information, wherein the handover request includes the security configuration information; The sending module is further configured to send a reconfiguration instruction to the terminal device, wherein the reconfiguration instruction includes the security configuration information; The sending module is further configured to send a switching instruction to the terminal device, so that the terminal device updates the key based on the security configuration information.

29. A communication device, characterized in that: The communication device is specifically a terminal device, and the communication device includes: a receiving module, configured to receive a reconfiguration instruction from a first network device, the reconfiguration instruction including security configuration information, the security configuration information including a plurality of update keys and a correspondence between a link count value and the plurality of update keys; The receiving module is configured to receive a switching instruction from the first network device; A key updating module is used to update the key based on the security configuration information.

30. A communication device, characterized in that: The communication device is specifically a second network device, and the communication device includes: a receiving module, configured to receive a switching request from a first network device, the switching request including security configuration information, the security configuration information including a plurality of update keys and a correspondence between a link count value and the plurality of update keys; A key updating module is used to update the key based on the security configuration information.

31. A communication device, characterized in that: The communication device comprises: Memory for storing computer programs or computer instructions; A processor, configured to execute the computer program or computer instructions stored in the memory, so that the communication device performs the method according to any one of claims 1 to 6.

32. A communication device, characterized in that: The communication device comprises: Memory for storing computer programs or computer instructions; A processor, configured to execute a computer program or computer instruction stored in the memory, so that the communication device performs the method according to any one of claims 7 to 18.

33. A communication device, characterized in that: The communication device comprises: Memory for storing computer programs or computer instructions; A processor, configured to execute a computer program or computer instruction stored in the memory, so that the communication device performs the method according to any one of claims 19 to 27.

34. A computer storage medium for storing a computer program, wherein when the computer program is executed, it is used to implement the method according to any one of claims 1 to 6, or to implement the method according to any one of claims 7 to 18, or to implement the method according to any one of claims 19 to 27.

Citation Information

Patent Citations

  • Method, device and system for processing safe key in reconnection of RRC (Radio Resource Control)

    CN101945384A

  • Interaction method and device for security information

    CN101998388A

  • Secret key derivation method and device

    CN112543450A

  • Method and Apparatus for Handling Security Keys for Individual Bearers

    US20180376330A1