Key updating method, communication apparatus, and storage medium

By pre-generating and sending the security configuration information of the target cell, including multiple update keys and their link count relationships, the problem of delayed key updates during cell handover of terminal devices is solved, and the key update efficiency is improved.

WO2025208927A9PCT designated stage Publication Date: 2025-12-26HONOR DEVICE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/139584
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-04-03
Filing Date
2024-12-16
Publication Date
2025-12-26

AI Technical Summary

Technical Problem

In existing technologies, the key update delay is relatively long and the key update efficiency is low when terminal devices are switching cells.

Method used

By generating and pre-sending security configuration information for the target cell, including multiple update keys and their link count values ​​and corresponding relationships, the key update time for terminal devices and network devices is reduced.

Benefits of technology

This reduces the key update latency of terminal devices and improves key update efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024139584_26122025_PF_FP_ABST
    Figure CN2024139584_26122025_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a key updating method, a communication apparatus, and a storage medium, aiming to reduce the key updating delay of a terminal device and improve the key updating efficiency of the terminal device. The present application provides a key updating method, comprising: generating security configuration information of a target cell; sending a handover request to a second network device corresponding to the target cell; sending a reconfiguration instruction to a terminal device; and sending a handover instruction to the terminal device. In the implementation solution, a first network device can pre-generate the security configuration information comprising a plurality of update keys, and send the security configuration information to both the terminal device and the second network device that corresponds to the target cell, so that the terminal device and the second network device can rapidly update keys on the basis of the security configuration information comprising the plurality of update keys without the need to spend more time in performing derivation on the update keys, thereby reducing the key updating delay of the terminal device and improving the key updating efficiency of the terminal device.
Need to check novelty before this filing date? Find Prior Art

Description

A key update method, communication device and storage medium

[0001] This application claims priority to Chinese Patent Application No. 202410409047.7, filed on April 3, 2024, entitled "A Key Update Method, Communication Device and Storage Medium", the entire contents of which are incorporated herein by reference. Technical Field

[0002] This application relates to the field of communication technology, and in particular to a key update method, communication device and storage medium. Background Technology

[0003] When a terminal device is undergoing cell handover and needs to switch from the original base station to the target base station, the security key used by the terminal device can be updated to ensure the security of communication between the terminal device and the target base station after the handover.

[0004] Currently, updating the security key used by terminal devices requires a significant amount of time to derive the updated security key, resulting in long key update delays and low key update efficiency. Summary of the Invention

[0005] This application provides a key update method, communication device, and storage medium, with the aim of reducing the key update latency of terminal devices and improving the key update efficiency of terminal devices.

[0006] To achieve the above objectives, this application provides the following technical solution:

[0007] A first aspect of this application provides a key update method applied to a first network device, the method comprising:

[0008] The system generates security configuration information for a target cell, including multiple update keys and a correspondence between link count values ​​and the multiple update keys; it sends a handover request to a second network device corresponding to the target cell, causing the second network device to update its keys based on the security configuration information, the handover request including the security configuration information; it sends a reconfiguration instruction to the terminal device, the reconfiguration instruction including the security configuration information; and it sends a handover instruction to the terminal device, causing the terminal device to update its keys based on the security configuration information.

[0009] In the above implementation scheme, after generating the security configuration information of the target cell, the first network device can send the security configuration information to the second network device corresponding to the target cell through a handover request. This allows the second network device to update the key based on the security configuration information upon receiving the handover request. The first network device can also send the security configuration information to the terminal device via a reconfiguration command and send a handover command to the terminal device, enabling the terminal device to update the key based on the security configuration information upon receiving the handover command. To reduce the key update latency and improve the key update efficiency of the terminal device, the first network device can pre-generate security configuration information including multiple update keys and send this information to both the terminal device and the second network device corresponding to the target cell. This allows the terminal device and the second network device to quickly complete the key update based on the security configuration information including multiple update keys, without spending excessive time deducing the update keys. This reduces the time required for key updates by the terminal device, reduces key update latency, and improves the key update efficiency.

[0010] In one possible implementation of the first aspect of this application, the security configuration information further includes a link count value corresponding to each update key. In the above implementation, the security configuration information generated by the first network device may also include multiple link count values ​​corresponding to update keys, so that the terminal device and the second network device can quickly complete the key update based on the link count values, without spending a lot of time deducing the update key. This reduces the time required for the terminal device to update the key, reduces the key update latency of the terminal device, and improves the key update efficiency of the terminal device.

[0011] In one possible implementation of the first aspect of this application, the security configuration information further includes a link index, which indicates the link count value. In the above implementation, to improve the security of key updates, the security configuration information generated by the first network device may also include a link index. The terminal device and the second network device can first find the corresponding link count value based on the link index, and then quickly complete the key update based on the link count value.

[0012] In one possible implementation of the first aspect of this application, the security configuration information further includes an encryption algorithm index corresponding to the target cell. In the above implementation, the security configuration information generated by the first network device may also include an encryption algorithm index corresponding to the target cell. After determining the update key and the corresponding link count value, the terminal device and the second network device can quickly find the corresponding encryption algorithm based on the encryption algorithm index corresponding to the target cell to generate an encryption key and an integrity protection key, thereby completing the key update.

[0013] In one possible implementation of the first aspect of this application, the switching instruction includes a target link count value or a target link index. The method further includes: when the switching instruction includes the target link count value, sending the target link count value and an unused link count value from the security configuration information to the second network device; when the switching instruction includes the target link index, sending the target link index and an unused link index from the security configuration information to the second network device. In the above implementation, the first network device can lead the key update by specifying the target link count value or target link index for key update and sending the target link count value or target link index to the second network device and the terminal device respectively. This allows the terminal device to quickly complete the key update without spending a lot of time deducing the update key, thereby reducing the time required for the terminal device to update the key, reducing the key update latency of the terminal device, and improving the key update efficiency of the terminal device. Furthermore, by sending unused link count values ​​or unused link indices from the security configuration information to the second network device, the first network device can avoid repeatedly specifying the same link count value as the target link count value or the same link index as the target link index during the key update process when the second network device dominates the next handover of the terminal device, thus avoiding the use of the same key in different key update processes and improving the effectiveness of key updates.

[0014] In one possible implementation of the first aspect of this application, the handover request includes a Layer 1 or Layer 2 triggered Mobility LTM handover request. In the above implementation, the current LTM mechanism does not involve handover between CUs, nor does it involve updating security keys. When the LTM mechanism supports handover between CUs in the future, a first network device can pre-generate security configuration information including multiple update keys, and send the security configuration information to the terminal device and the second network device corresponding to the target cell. This allows the terminal device and the second network device to quickly update the keys based on the security configuration information, without spending excessive time deducing the update keys. This reduces the time required for key updates by the terminal device, reduces the key update latency of the terminal device, and improves the key update efficiency of the terminal device.

[0015] A second aspect of this application provides a key update method applied to a terminal device, the method comprising:

[0016] Receive a reconfiguration instruction from a first network device, the reconfiguration instruction including security configuration information, the security configuration information including multiple update keys and the correspondence between link count values ​​and the multiple update keys;

[0017] Receive a handover command from the first network device;

[0018] The key is updated based on the security configuration information.

[0019] In the above implementation scheme, in order to reduce the key update latency of the terminal device and improve the key update efficiency of the terminal device, the terminal device can receive security configuration information including multiple update keys pre-generated by the first network device, and can quickly update the key based on the security configuration information including multiple update keys, without spending a lot of time to deduce the update keys, thereby reducing the time required for the terminal device to update the key, reducing the key update latency of the terminal device, and improving the key update efficiency of the terminal device.

[0020] In one possible implementation of the second aspect of this application, the security configuration information further includes a link count value corresponding to each update key.

[0021] In one possible implementation of the second aspect of this application, the security configuration information further includes a link index, which is used to indicate the link count value.

[0022] In one possible implementation of the second aspect of this application, the security configuration information further includes an encryption algorithm index corresponding to the target cell.

[0023] In one possible implementation of the second aspect of this application, the key update based on the security configuration information includes: determining a target link count value; determining a target update key from a plurality of update keys based on the target link count value; and generating an encryption key and an integrity protection key based on the target link count value and the target update key. The terminal device can first determine the target link count value to be used in this key update, then determine the target update key to be used in this update from a plurality of update keys based on the target link count value, and finally generate an encryption key and an integrity protection key based on the target link count value and the target update key. This allows for rapid key updates without spending considerable time deriving the target update key from the update keys, thereby reducing the time required for key updates by the terminal device, reducing key update latency, and improving the key update efficiency of the terminal device.

[0024] In one possible implementation of the second aspect of this application, when the security configuration information includes a link count value corresponding to each update key, determining the target link count value includes: determining the link count value with the smallest value as the target link count value. In the above implementation, after receiving the security configuration information including the link count values, the terminal device can determine the target link count value to be used for this key update from the link count values ​​in sequence; that is, it can determine the link count value with the smallest value as the target link count value, thereby quickly completing the key update.

[0025] In one possible implementation of the second aspect of this application, when the security configuration information includes a link index, determining the target link count value includes: determining the link index with the smallest value as the target link index; and determining the target link count value based on the target link index. In the above implementation, after receiving the security configuration information including the link index, the terminal device can first determine the target link index to be used for this key update from the link count values ​​in sequence, and then determine the target link count value to be used for this key update based on the target link index, thereby quickly completing the key update.

[0026] In one possible implementation of the second aspect of this application, after generating the encryption key and integrity protection key based on the target link count value and the target update key, the target link count value or the target link index is deleted. In the above implementation, to improve the security of key updates, the terminal device can delete the target link count value or the target link index after using it to update the key, thus preventing the update key from being reused and enabling rapid key updates.

[0027] In one possible implementation of the second aspect of this application, when the switching instruction includes a target link count value, determining the target link count value includes: obtaining the target link count value from the switching instruction. In the above implementation, when the first network device initiates the key update, the terminal device can directly obtain the target link count value to be used for this update from the switching instruction sent by the first network device, thereby quickly completing the key update.

[0028] In one possible implementation of the second aspect of this application, when the switching instruction includes a target link index, determining the target link count value includes: obtaining the target link index from the switching instruction; and determining the target link count value based on the target link index. In the above implementation, when the first network device initiates the key update, the terminal device can directly obtain the target link index to be used for this update from the switching instruction sent by the first network device, and then determine the target link count value to be used for this key update based on the target link index, thereby quickly completing the key update.

[0029] In one possible implementation of the second aspect of this application, after determining the target link count value, the method further includes: sending the target link count value to the second network device. In the above implementation, the terminal device can lead the key update; that is, after determining the target link count value, the terminal device can send the target link count value to the second network device so that the second network device can synchronously update the key with the terminal device, ensuring the validity of the updated key and thus quickly completing the key update.

[0030] In one possible implementation of the second aspect of this application, after determining the target link count value, the method further includes: sending the target link index corresponding to the target link count value to the second network device. In the above implementation, the terminal device can lead the key update; that is, after determining the target link count value, the terminal device can send the target link index corresponding to the target link count value to the second network device, so that the second network device can synchronously update the key with the terminal device, ensuring the validity of the updated key and thus quickly completing the key update.

[0031] A third aspect of this application provides a key update method applied to a terminal device, the method comprising:

[0032] Receive a handover request from a first network device, the handover request including security configuration information, the security configuration information including multiple update keys and the correspondence between link count values ​​and the multiple update keys;

[0033] The key is updated based on the security configuration information.

[0034] In the above implementation scheme, in order to reduce the key update latency of the terminal device and improve the key update efficiency of the terminal device, the second network device can receive security configuration information including multiple update keys pre-generated by the first network device, and can quickly update the key based on the security configuration information including multiple update keys, without spending a lot of time deducing the update key with the terminal device, thereby reducing the time required for the terminal device to update the key, reducing the key update latency of the terminal device, and improving the key update efficiency of the terminal device.

[0035] In one possible implementation of the third aspect of this application, the security configuration information further includes a link count value corresponding to each update key.

[0036] In one possible implementation of the third aspect of this application, the security configuration information further includes a link index, which is used to indicate the link count value.

[0037] In one possible implementation of the third aspect of this application, the security configuration information further includes an encryption algorithm index corresponding to the target cell.

[0038] In one possible implementation of the third aspect of this application, the key update based on the security configuration information includes: determining a target link count value; determining a target update key from the plurality of update keys based on the target link count value; and generating an encryption key and an integrity protection key based on the target link count value and the target update key.

[0039] In one possible implementation of the third aspect of this application, when the security configuration information includes a link count value corresponding to each update key, determining the target link count value includes: determining the link count value with the smallest value as the target link count value.

[0040] In one possible implementation of the third aspect of this application, when the security configuration information includes a link index, determining the target link count value includes: determining the link index with the smallest value as the target link index; and determining the target link count value based on the target link index.

[0041] In one possible implementation of the third aspect of this application, determining the target link count value includes: receiving a target link count value from a first network device or a terminal device.

[0042] In one possible implementation of the third aspect of this application, determining the target link count value includes: receiving a target link index from a first network device or a terminal device; and determining the target link count value based on the target link index.

[0043] A fourth aspect of this application provides a communication device, specifically a first network device, the communication device comprising:

[0044] The generation module is used to generate security configuration information for the target cell, wherein the security configuration information includes multiple update keys and the correspondence between link count values ​​and the multiple update keys;

[0045] The sending module is configured to send a handover request to the second network device corresponding to the target cell, so that the second network device corresponding to the target cell can update the key based on the security configuration information, wherein the handover request includes the security configuration information.

[0046] The sending module is further configured to send a reconfiguration instruction to the terminal device, the reconfiguration instruction including the security configuration information;

[0047] The sending module is also used to send a switching instruction to the terminal device so that the terminal device can update the key based on the security configuration information.

[0048] The fifth aspect of this application provides a communication device, specifically a terminal device, the communication device comprising:

[0049] A receiving module is configured to receive a reconfiguration instruction from a first network device, the reconfiguration instruction including security configuration information, the security configuration information including multiple update keys and the correspondence between link count values ​​and the multiple update keys;

[0050] The receiving module is used to receive a switching instruction from the first network device;

[0051] The key update module is used to update the key based on the security configuration information.

[0052] A sixth aspect of this application provides a communication device, specifically a second network device, the communication device comprising:

[0053] A receiving module is configured to receive a handover request from a first network device, the handover request including security configuration information, the security configuration information including multiple update keys and the correspondence between link count values ​​and the multiple update keys;

[0054] The key update module is used to update the key based on the security configuration information.

[0055] A seventh aspect of this application provides a communication device, comprising: a memory and at least one processor. The memory is used to store a program, and the at least one processor is used to execute the computer program or computer instructions stored in the memory, so that the communication device implements the key update method provided in the first aspect of this application.

[0056] An eighth aspect of this application provides a communication device, comprising: a memory and at least one processor. The memory is used to store a program, and the at least one processor is used to execute the computer program or computer instructions stored in the memory, so that the communication device implements the key update method provided in the second aspect of this application.

[0057] A ninth aspect of this application provides a communication device, comprising: a memory and at least one processor. The memory is used to store a program, and the at least one processor is used to execute the computer program or computer instructions stored in the memory, so that the communication device implements the key update method provided in the third aspect of this application.

[0058] The tenth aspect of this application is a computer storage medium for storing a computer program, which, when executed, implements the key update method provided in the first, second, or third aspect of this application.

[0059] The eleventh aspect of this application provides a computer program product containing instructions that, when run on a computer, cause the computer to execute the key update method provided in the first, second, or third aspect described above.

[0060] The twelfth aspect of this application provides a chip system including a processor for supporting a terminal device or network device in implementing the functions involved in the above aspects, such as transmitting or processing data and / or information involved in the above methods. In one possible design, the chip system further includes a memory for storing program instructions and data necessary for the terminal device or network device. The chip system may be composed of chips or may include chips and other discrete devices. Attached Figure Description

[0061] Figure 1 is a schematic diagram of the system architecture of the communication system provided in an embodiment of this application;

[0062] Figure 2 is a flowchart illustrating an LTM mechanism provided in an embodiment of this application;

[0063] Figure 3 is a flowchart illustrating a key update mechanism provided in an embodiment of this application;

[0064] Figure 4 is a flowchart illustrating a key update method provided in an embodiment of this application;

[0065] Figure 5 is a schematic diagram of the interaction process between a first network device, a terminal device and a second network device provided in an embodiment of this application;

[0066] Figure 6a is a schematic diagram of data transmission of a first network device, a terminal device, a second network device, and a third network device according to an embodiment of this application;

[0067] Figure 6b is a schematic diagram of data transmission of another first network device, terminal device, second network device and third network device provided in an embodiment of this application;

[0068] Figure 7 is a schematic diagram of the structure of a communication device provided in an embodiment of this application;

[0069] Figure 8 is a schematic diagram of another communication device provided in an embodiment of this application;

[0070] Figure 9 is a schematic diagram of another communication device provided in an embodiment of this application;

[0071] Figure 10 is a structural example diagram of an electronic device disclosed in an embodiment of this application;

[0072] Figure 11 is a structural example diagram of another electronic device disclosed in an embodiment of this application. Detailed Implementation

[0073] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. The terminology used in the following embodiments is for the purpose of describing specific embodiments only and is not intended to be a limitation of this application. As used in the specification and appended claims of this application, the singular expressions "a," "an," "the," "the," "the," and "this" are intended to also include expressions such as "one or more," unless the context clearly indicates otherwise. It should also be understood that in the embodiments of this application, "one or more" refers to one, two, or more; "and / or" describes the relationship between related objects, indicating that three relationships may exist; for example, A and / or B can represent: A alone, A and B simultaneously, or B alone, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship.

[0074] References to "one embodiment" or "some embodiments" as described in this specification mean that one or more embodiments of this application include a specific feature, structure, or characteristic described in connection with that embodiment. Therefore, the phrases "in one embodiment," "in some embodiments," "in other embodiments," "in still other embodiments," etc., appearing in different parts of this specification do not necessarily refer to the same embodiment, but rather mean "one or more, but not all, embodiments," unless otherwise specifically emphasized. The terms "comprising," "including," "having," and variations thereof mean "including but not limited to," unless otherwise specifically emphasized.

[0075] The "multiple" mentioned in the embodiments of this application refers to two or more. It should be noted that in the description of the embodiments of this application, terms such as "first" and "second" are used only for the purpose of distinguishing descriptions and should not be construed as indicating or implying relative importance, nor should they be construed as indicating or implying order.

[0076] The embodiments of this application are applied to communication systems, which can be second-generation (2G) communication systems, third-generation (3G) communication systems, LTE systems, fifth-generation (5G) communication systems, LTE and 5G hybrid architectures, 5G New Radio (5G NR) systems, and new communication systems that will emerge in the future development of communication.

[0077] The communication system includes a first device and a second device. The first device can be a network-side device used to provide network communication functions; in some cases, it is also called a network device or network element. The network device can typically be a base station (including functional units of a base station, or a combination of functional units of a base station) or a core network unit. The core network unit can be a functional unit within the core network, including but not limited to Access and Mobility Management Function (AMF) units or Session Management Function (SMF) units. The second device can be a device accessing the network, typically a terminal device. An example of a communication system is shown in Figure 1, which includes a base station 11 and a terminal 12.

[0078] In the embodiments provided in this application, the base station can be any device with wireless transceiver capabilities, including but not limited to: evolved base stations (NodeB, eNB, or e-NodeB) in Long Term Evolution (LTE), base stations (gNodeB or gNB) or transmission receiving points / transmission reception points (TRPs) in New Radio (NR), base stations in subsequent 3GPP evolutions, access nodes in Wi-Fi systems, wireless relay nodes, wireless backhaul nodes, etc. The base station can be: macro base station, micro base station, pico base station, small cell, relay station, or balloon station, etc. The base station can include one or more co-located or non-co-located Transmission Reception Points (TRPs). The base station can also be a radio controller, centralized unit (CU), and / or distributed unit (DU) in a cloud radio access network (CRAN) scenario. The base station can communicate with terminal devices or communicate with terminal devices through relay stations. Terminal devices can communicate with multiple base stations using different technologies. For example, a terminal device can communicate with a base station that supports LTE networks, or with a base station that supports 5G networks, or even have dual connections with both LTE and 5G base stations.

[0079] In the embodiments provided in this application, the terminal device can take various forms, such as a mobile phone, tablet computer, computer with wireless transceiver capabilities, virtual reality (VR) terminal device, augmented reality (AR) terminal device, wireless terminal device in industrial control, vehicle-mounted terminal device, wireless terminal device in self-driving, wireless terminal device in remote medical care, wireless terminal device in smart grid, wireless terminal device in transportation safety, wireless terminal device in smart city, wireless terminal device in smart home, wearable terminal device, etc. The terminal device may also be referred to as a terminal device, user equipment (UE), access terminal device, vehicle-mounted terminal device, industrial control terminal device, UE unit, UE station, mobile station, mobile station, remote station, remote terminal device, mobile device, UE terminal device, terminal device, wireless communication device, UE agent, or UE device, etc. The terminal device can also be a fixed terminal device or a mobile terminal device.

[0080] In communication systems, cell handover is frequently required to ensure seamless mobile communication services for terminal devices. Cell handover refers to the process by which a terminal device, under the control of the radio access network, migrates its radio link connection from a source cell to a target cell. Currently, cell handover for terminal devices can be achieved in various ways.

[0081] Layer 1 / 2 triggered mobility (LTM) is a method of cell handover. As shown in Figure 2, in the LTM mechanism, for a terminal device in the connected state, it can report network quality measurement results to the network device. The network determines whether to execute LTM based on the terminal's LTM support capability. The network device starts sending LTM handover requests to candidate cells, such as the target cell and potential target cells. The candidate cells configure their information and send the LTM handover request to the original cell. The original cell sends the candidate cell configuration information to the terminal device via Radio Resource Control (RRC) reconfiguration messages. After receiving the candidate cell configuration information, the terminal device can perform downlink synchronization and uplink synchronization for each candidate cell. When performing uplink synchronization with the candidate cells, if the network device instructs the terminal device to measure the uplink timing advance in the RRC reconfiguration message, the terminal device measures the timing advance of the original cell and determines the timing advance of the candidate cell based on the reception time difference between the original cell and the candidate cell. Alternatively, the original cell can trigger contention-free random access (CLO) via a Physical Downlink Control Channel (PDCCH) command. Random access to access (CFRA) resource information is used to obtain the timing advance of candidate cells. The terminal device initiates CFRA to obtain the timing advance from the candidate cell, and the validity of the timing advance is managed by the network device.

[0082] The terminal device performs Layer 1 measurements on the original cell and the candidate cell, and reports the measurement results to the original cell. Based on the measurement results, the original cell determines the target cell and issues a handover command, i.e., LTM handover Media Access Control Layer Control Element (MAC CE) signaling. This MAC CE signaling includes at least the following information: Timing Advance, Transmission Configuration Indication (TCI) state id, CFRA resource information, and the configuration information identifier of the candidate cell. For the timing advance in the MAC CE, if the network device determines that the timing advance previously obtained by the terminal device is still valid, then that timing advance is included in the MAC CE signaling.

[0083] When a terminal device receives an LTM handover MAC CE signaling, if the MAC CE includes a timing advance, or if the timing advance is determined by the terminal device itself, the terminal device will initiate a handover to the target cell without random access. That is, the terminal device only needs to send one uplink signaling or the first uplink data packet to the target cell to indicate that it has completed access to the target cell.

[0084] Currently, the LTM mechanism only supports handover within a CU and does not involve the updating of security keys. When the LTM mechanism supports handover between CUs, the updating of security keys needs to be considered.

[0085] Please refer to Figure 3. After authentication is completed, the terminal device and the network device can first obtain the anchor key K. SEAF And further derived K AMF Among them, K SEAF It is an anchor key provided by the Authentication Server Function (AUSF) to the Service Endpoint Access Function (SEAF). During the initial establishment of the security context, the terminal device and the Access and Mobility Management Function (AMF) can obtain it from the K. SEAF The key K of the original base station was derived from this. gNB and the next hop parameter (Next Hop, NH), where the NH link counter (Next Hop Link Counter, NCC) is related to each K gNB Associated with NH parameters; during horizontal or vertical key export, K ​​is further exported by the terminal device and the original base station. gNB In the initial setup, K gNB Associated with the NH parameter when the NCC value is equal to 0. After the handover occurs, the K parameter used by the terminal equipment and the target base station... gNB *From the current K gNB Or NH parameter. K gNB *If the current K is not increasing gNB When exporting, add NCC. If exporting from NH parameters, instruct the terminal device to add NCC. RRC signaling encryption key K. RRCenc and integrity protection key K RRCint The encryption key K for the uplink data packet UPenc and integrity protection key K UPint Based on K gNB The * and security algorithms are derived. The security algorithms are configured and determined based on the security capabilities of the terminal device.

[0086] Please refer to Figure 4. Currently, when updating the security key used by a terminal device, the terminal device needs to first obtain K. SEAF And further derived K AMF During the security context establishment process, the AMF sends the terminal device's security capabilities to the original base station. Based on these capabilities, the original base station determines the security algorithm, including integrity protection and encryption algorithms. The terminal and AMF then derive K... gNB And NH. When a handover occurs, the original base station will carry the target base station's algorithm and NCC in the handover command; the terminal device initiates random access to the target base station, and according to K gNB NCC derived K gNB Furthermore, based on the security algorithms involved in the terminal, encryption and integrity protection keys were derived.

[0087] As can be seen from the above, currently, when updating the security key used by a terminal device, it takes a lot of time to deduce the updated security key, resulting in a long key update delay and low key update efficiency.

[0088] To make the technical solution of this application clearer and easier to understand, the key update method of the embodiments of this application will be described below with reference to the accompanying drawings.

[0089] Please refer to Figure 5. Figure 5 shows a schematic diagram of the interaction process between a first network device, a terminal device, and a second network device according to an embodiment of this application. The key update method provided in this embodiment mainly includes the following steps:

[0090] 501. The first network device generates the security configuration information for the target cell.

[0091] The security configuration information includes multiple update keys and the correspondence between link count values ​​and multiple update keys.

[0092] In this embodiment, the first network device can be the original base station corresponding to the original cell to which the terminal device was connected before cell handover. To reduce the key update latency of the terminal device, the first network device can first determine which cell the terminal device will be handover to, i.e., determine the target cell, and pre-configure the security configuration information of the target cell. This allows the terminal device to quickly complete the key update based on the security configuration information, without spending excessive time deducing the update key, thereby reducing the time required for key updates, reducing key update latency, and improving key update efficiency.

[0093] In this embodiment, after receiving network quality measurement results from a terminal device, the first network device first determines candidate cells for which the terminal device can handover, based on the terminal device's cell handover capability and the network quality measurement results. These candidate cells include a target cell. Security configuration information is then configured for each candidate cell to obtain security configuration information for each candidate cell, enabling the terminal device to quickly handover from the target cell to other candidate cells. Furthermore, different candidate cells may correspond to the same base station, and the security configuration information for candidate cells within the same base station can be identical. Therefore, a candidate cell set can be generated based on candidate cells corresponding to the same base station, and then security configuration information can be configured for different candidate cell sets.

[0094] Specifically, the first network device can use the key K currently used by the terminal device. gNB The update key K is derived from the link count value of the NH link counter NCC. gNB *. Update key K gNB *This can include multiple keys, meaning the first network device can use K... gNB Multiple update keys K are derived from multiple different NCCs. gNB *, and can record each update key K gNB * and used to derive each update key K gNB The correspondence between * and NCC is used to obtain multiple update keys K. gNB The correspondence between the key and the NCC is finally determined based on multiple update keys K. gNB *and multiple update keys K gNB * The mapping between the link count value (NCC) and the target cell's security configuration information is generated.

[0095] In one possible implementation of this application embodiment, the security configuration information further includes a link count value corresponding to each update key. In this application embodiment, the security configuration information generated by the first network device may also include a link count value corresponding to each update key; that is, the security configuration information may include multiple update keys, multiple link count values, and the correspondence between the link count values ​​and the multiple update keys. When the security configuration information includes multiple update keys, the security configuration information may include multiple link count values, which can be represented by list{K gNBThe *, NCC} representation allows the terminal device and the second network device to quickly determine the target update key required for this key update from multiple update keys based on the link count value corresponding to each update key when receiving security configuration information, thus completing the key update without spending a lot of time deducing the target update key. This reduces the time required for the terminal device to update the key, reduces the key update latency of the terminal device, and improves the key update efficiency of the terminal device.

[0096] In one possible implementation of this application embodiment, the security configuration information also includes a link index.

[0097] The link index is used to indicate the link count value. In this embodiment, the link index K_Index can be mapped one-to-one with the NCC, that is, each link index can be used to indicate a link count value. For example, when the link count value ranges from 0 to 7, the link index can also range from 0 to 7. To improve the security of key updates, the security configuration information generated by the first network device may not directly include the link count value NCC, but may include the link index K_Index used to indicate the NCC. That is, the security configuration information may include multiple update keys, multiple link indices, and the correspondence between the link count value and multiple update keys, which can be represented by list{K gNB The key update is represented by K_Index, so that when the terminal device and the second network device receive the security configuration information, they can first determine the link count value required for this key update based on the link indication, and then quickly determine the target update key required for this key update from multiple update keys based on the link count value to complete the key update. This eliminates the need to spend a lot of time deducing the target update key, thereby reducing the time required for the terminal device to update the key, reducing the key update latency of the terminal device, and improving the key update efficiency of the terminal device.

[0098] In one possible implementation of this application embodiment, the security configuration information further includes an encryption algorithm index corresponding to the target cell. In this embodiment, since different candidate cells can correspond to different encryption algorithms, the security configuration information generated by the first network device may also include the encryption algorithm corresponding to the target cell. This allows the terminal device and the second network device, after determining the update key and the corresponding link count value, to quickly find the corresponding encryption algorithm based on the encryption algorithm index corresponding to the target cell, generate an encryption key and an integrity protection key, and thus complete the key update.

[0099] Specifically, the encryption algorithm index in the security configuration information can include multiple different encryption algorithm indexes. Since different link count values ​​can correspond to different encryption algorithm indexes, different link indices can correspond to different encryption algorithm indexes, and different sets of link count values ​​and different sets of link indices can correspond to different encryption algorithm indexes, the encryption algorithm index in the security configuration information can include encryption algorithm indexes corresponding to each link count value, or encryption algorithm indexes corresponding to each link indices, or encryption algorithm indexes corresponding to a set of multiple link count values, or encryption algorithm indexes corresponding to a set of multiple link indices.

[0100] In one possible implementation of this application embodiment, the security configuration parameters may further include update indication information.

[0101] The update instruction information is used to instruct the terminal to update the master key.

[0102] Specifically, the key update process for the terminal device can be led by either the first network device or the terminal device itself. When the first network device leads the key update process, it determines the target link count or target link index to be used in this key update. This allows the terminal device and the second network device to determine the target update key from the update keys based on the target link count or target link index determined by the first network device, thus completing the key update. Conversely, when the terminal device leads the key update process, it determines the target link count or target link index to be used in this key update. This allows the terminal device and the second network device to determine the target update key from multiple update keys based on the target link count or target link index determined by the first network device, thus completing the key update.

[0103] 502. The first network device sends a handover request to the second network device corresponding to the target cell.

[0104] The switching request includes security configuration information.

[0105] In this embodiment, the second network device can be the target base station corresponding to the target cell to which the terminal device connects after cell handover. After the first network device pre-generates the security configuration information of the target cell, it can send a handover request containing the security configuration information to the second network device. This allows the second network device to quickly update the key based on the security configuration information while simultaneously notifying the second network device that the terminal device is about to handover from the original cell to the target cell. This eliminates the need for the second network device to spend considerable time deducing the update key with the terminal device, thereby reducing the time required for key updates, reducing key update latency, and improving key update efficiency.

[0106] In one possible implementation of this application embodiment, the handover request includes a Layer 1 or Layer 2 triggered Mobility LTM handover request. In this embodiment, the current LTM mechanism does not involve handover between CUs, nor does it involve updating security keys. When the LTM mechanism supports handover between CUs in the future, a first network device can pre-generate security configuration information including multiple update keys, and send this security configuration information to the terminal device and the second network device corresponding to the target cell. This allows the terminal device and the second network device to quickly update the keys based on the security configuration information, without spending excessive time deducing the update keys. This reduces the time required for key updates by the terminal device, reduces key update latency, and improves the key update efficiency of the terminal device.

[0107] 503. The second network device receives a handover request from the first network device.

[0108] The handover request includes security configuration information, which includes multiple update keys and the correspondence between link count values ​​and multiple update keys.

[0109] In this embodiment, the first network device and the second network device can communicate with each other. After the first network device sends a handover request including the security configuration information of the target cell to the second network device, the second network device can receive the handover request so that it can quickly update the key according to the security configuration information in the handover request. This eliminates the need to spend a lot of time deducing the update key with the terminal device, thereby reducing the time required for the terminal device to update the key, reducing the key update latency of the terminal device, and improving the key update efficiency of the terminal device.

[0110] In one possible implementation of this application embodiment, after receiving a handover request from the first network device, the second network device may return a handover request response to the first network device. The handover request response may include a link count value in the security configuration information to confirm with the first network device whether the received security configuration information is incorrect.

[0111] 504. The first network device sends a reconfiguration command to the terminal device.

[0112] The reconfiguration command includes security configuration information.

[0113] In this embodiment, after the first network device pre-generates the security configuration information of the target cell, it can send a reconfiguration command including the security configuration information to the terminal device. This allows the terminal device to quickly update its key based on the received security configuration information while simultaneously notifying the terminal device of the configuration information required during cell handover. This eliminates the need for extensive key derivation, reducing the time required for key updates, decreasing key update latency, and improving key update efficiency. The reconfiguration command can be an RRC reconfiguration command.

[0114] 505. The terminal device receives a reconfiguration command from the first network device.

[0115] The reconfiguration instruction includes security configuration information, which includes multiple update keys and the correspondence between the link count value and the multiple update keys.

[0116] In this embodiment, the first network device and the terminal device can communicate with each other. After the first network device sends a reconfiguration instruction including the security configuration information of the target cell to the terminal device, the terminal device can receive the reconfiguration instruction. This allows the terminal device to quickly update the key based on the received security configuration information while receiving the configuration information required for cell handover, without having to spend a lot of time deducing the update key. This reduces the time required for the terminal device to update the key, reduces the key update latency of the terminal device, and improves the key update efficiency of the terminal device.

[0117] In addition, after receiving the reconfiguration instruction from the first network device, the terminal device can return reconfiguration completion information to the first network device to notify the first network device that the reconfiguration instruction has been successfully received.

[0118] 506. The first network device sends a handover command to the terminal device.

[0119] In this embodiment, the first network device can notify the terminal device to switch from the currently connected original cell to the target cell by sending a handover command, and can also notify the terminal device to perform a key update. Since the second terminal device corresponding to the target cell to which the terminal device needs to switch is different from the first terminal device corresponding to the original cell, a key update is also required when the terminal device switches from the original cell to the target cell in order to enable secure communication with the target cell.

[0120] In one possible implementation of this application embodiment, the handover instruction includes a target link count value or a target link index. The key update method provided in this application embodiment may further include: when the handover instruction includes the target link count value, sending the target link count value and an unused link count value in the security configuration information to the second network device; when the handover instruction includes the target link index, sending the target link index and an unused link index in the security configuration information to the second network device. In this application embodiment, the first network device can lead the key update process. When the first network device leads the key update process, the first network device can first specify the target link count value or target link index to be used in this key update according to the security configuration information of the target cell, and can send the target link count value or target link index to the terminal device through a handover instruction. The first network device can send the target link count or target link index to the terminal device via a switching command. The first network device can also send the target link count or target link index to the second network device simultaneously. This allows the terminal device to quickly complete the key update without spending much time deducing the updated key with the second network device. This reduces the time required for the terminal device to update the key, reduces the key update latency of the terminal device, and improves the key update efficiency of the terminal device.

[0121] In this embodiment, when the first network device sends a target link count value or a target link index to the second network device, it may also send an unused link count value or an unused link index from the security configuration information. The unused link count value in the security configuration information refers to a link count value that has not been designated as the target link count value in the security configuration information, and the unused link index in the security configuration information refers to a link index that has not been designated as the target link index in the security configuration information. It is understood that the terminal device may have undergone multiple cell handovers before switching to the target cell, i.e., it may have performed multiple key updates. When a terminal device completes the current cell handover and key update, and needs to switch to the next cell (i.e., using the second network device as the original base station for key update, and the second network device leads the key update process), the first network device can send unused link count values ​​or unused link indices from the security configuration information to the second network device. This allows the second network device to avoid repeatedly specifying the same link count value or the same link index as the target link count value or the same link index as the target link index when leading the key update process of the terminal device's next handover. This also avoids using the same key in different key update processes, so that when the terminal device subsequently switches from the target cell to other candidate cells and performs key updates, it can avoid reusing the updated key that has already been used, thereby improving the effectiveness of key updates.

[0122] 507. The terminal device receives a handover instruction from the first network device.

[0123] In this embodiment, the first network device and the terminal device can communicate with each other. After the first network device sends a handover command to the terminal device, the terminal device can receive the handover command so that while receiving the configuration information required for cell handover, it can quickly update the key according to the received security configuration information without spending a lot of time deriving the update key, thereby reducing the time required for the terminal device to update the key, reducing the key update latency of the terminal device, and improving the key update efficiency of the terminal device.

[0124] 508. The terminal device updates the key based on the security configuration information.

[0125] In this embodiment, after receiving the handover instruction from the first network device, the terminal device can quickly update the key based on the security configuration information of the target cell, without having to spend a lot of time deducing the update key. This reduces the time required for the terminal device to update the key, reduces the key update latency of the terminal device, and improves the key update efficiency of the terminal device.

[0126] In one possible implementation of this application embodiment, step 508, where the terminal device updates the key based on security configuration information, includes:

[0127] A1. The terminal device determines the target link count value.

[0128] In this embodiment, during the key update process, the terminal device can first determine the target link count value to be used in this key update, so that it can determine the target update key to be used in this key update from multiple update keys, and further obtain the encryption key and integrity protection key, thereby quickly completing the key update without spending a lot of time deducing the target update key from the update keys. This reduces the time required for the terminal device to update the key, reduces the key update latency of the terminal device, and improves the key update efficiency of the terminal device.

[0129] In one possible implementation of this application embodiment, when the security configuration information includes the link count value corresponding to each update key, step A1, where the terminal device determines the target link count value, includes:

[0130] a11. The terminal device determines the link count value with the smallest value as the target link count value.

[0131] In this embodiment, after receiving security configuration information including link count values, the terminal device can determine the target link count value based on predefined rules. Specifically, the target link count value to be used for this key update can be determined sequentially from the link count values; that is, the link count value with the smallest value can be determined as the target link count value, thereby quickly completing the key update. For example, when the link count values ​​include 1, 2, and 3, the link count value of 1 can be determined as the target link count value.

[0132] In one possible implementation of this application embodiment, when the security configuration information includes a link index, step A1, where the terminal device determines the target link count value, includes:

[0133] a21. The terminal device determines the link index with the smallest value as the target link index.

[0134] a22. The terminal device determines the target link count value based on the target link index.

[0135] In this embodiment, after receiving security configuration information including link count values, the terminal device can determine the target link count value based on predefined rules. Specifically, the target link index to be used for this key update can be determined first from the link count values ​​in sequence, and then the target link count value to be used for this key update can be determined based on the target link index, thereby quickly completing the key update. For example, when the link index includes 1, 2, and 3, the link index with a value of 1 can be determined as the target link index, and then the target link count value indicated by the target link index can be determined according to the correspondence between the link index and the link count value.

[0136] In one possible implementation of this application embodiment, when the switching instruction includes a target link count value, step A1, the terminal device determines the target link count value, including:

[0137] a3. The terminal device obtains the target link count value from the handover command.

[0138] In this embodiment of the application, when the first network device initiates the key update, the terminal device can directly obtain the target link count value to be used for this update specified by the first network device from the switching instruction sent by the first network device, thereby quickly completing the key update.

[0139] In one possible implementation of this application embodiment, when the switching instruction includes a target link index, step A1, the terminal device determines the target link count value, including:

[0140] a41. The terminal device obtains the target link index from the switching command.

[0141] a42. The terminal device determines the target link count value based on the target link index.

[0142] In this embodiment of the application, when the first network device leads the key update, the terminal device can directly obtain the target link index to be used for this update specified by the first network device from the switching instruction sent by the first network device, and then determine the target link count value to be used for this key update based on the target link index, thereby quickly completing the key update.

[0143] In one possible implementation of this application embodiment, after the terminal device determines the target link count value in step A1, the key update method provided in this application embodiment may further include:

[0144] B1. The terminal device sends the target link count value to the second network device.

[0145] In this embodiment, the terminal device can lead the key update process. That is, after determining the target link count value, the terminal device can send the target link count value to the second network device, so that the second network device can synchronously update the key with the terminal device, ensuring the validity of the updated key and thus quickly completing the key update. Specifically, the terminal device can specify the target link count value from multiple link count values ​​in the security configuration information, and then send the target link count value to the second network device.

[0146] In one possible implementation of this application embodiment, after the terminal device determines the target link count value in step A1, the key update method provided in this application embodiment may further include:

[0147] C1. The terminal device sends the target link index corresponding to the target link count value to the second network device.

[0148] In this embodiment, to improve the security of key updates, after determining the target link count value, the terminal device can send the target link index corresponding to the target link count value to the second network device to prevent the target link count value from being leaked during transmission. Specifically, the terminal device can specify the target link count value from multiple link count values ​​in the security configuration information, then determine the target link index used to indicate the target link count value, and send the target link index to the second network device. This allows the second network device to synchronize key updates with the terminal device, ensuring the validity and security of the updated key, thereby quickly completing the key update.

[0149] In one possible implementation of this application, when the terminal device sends the target link count value or target link index to the second network device, it may also send an unused link count value or unused link index to the second network device. This is so that when the terminal device subsequently switches from the target cell to other candidate cells and performs a key update, other candidate cells can avoid repeatedly using the already used update key for key updates.

[0150] A2. The terminal device determines the target update key from multiple update keys based on the target link count value.

[0151] In this embodiment of the application, after determining the target link count value, the terminal device can determine the target update key corresponding to the target link count value from the multiple update keys included in the security configuration information and the correspondence between the link count value and the multiple update keys. That is, the update key to be used for this key update.

[0152] A3. The terminal device generates an encryption key and an integrity protection key based on the target link count value and the target update key.

[0153] In this embodiment, after determining the target update key based on the target link count value, the terminal device can obtain the encryption algorithm corresponding to the target cell. Finally, it generates an encryption key and an integrity protection key based on the encryption algorithm corresponding to the target cell, the target link count value, and the target update key. Specifically, the terminal device can obtain the encryption algorithm index corresponding to the target cell from the security configuration information. By inputting the target link count value into the encryption algorithm index, it obtains the encryption algorithm corresponding to the target cell. Then, based on the encryption algorithm corresponding to the target cell, the target link count value, and the target update key, it generates an encryption key and an integrity protection key, thereby quickly completing the key update. This eliminates the need to spend a lot of time deriving the target update key from the update key, thus reducing the time required for key updates, reducing the key update latency, and improving the key update efficiency of the terminal device.

[0154] In one possible implementation of this application embodiment, after the terminal device generates an encryption key and an integrity protection key based on the target link count value and the target update key, the key update method provided in this application embodiment may further include:

[0155] D1. The terminal device deletes the target link count or target link index.

[0156] In this embodiment of the application, in order to improve the security of key updates, after the terminal device updates the key using the target link count value or the target link index, it can delete the used target link count value or the target link index to prevent the update key from being reused and thus reducing the effectiveness of the update key, thereby quickly completing the key update.

[0157] 509. The second network device updates the key based on the security configuration information.

[0158] In this embodiment of the application, after receiving a handover request from a terminal device, the second network device can quickly update the key based on the security configuration information of the target cell in the received handover request, without having to spend a lot of time deducing the update key with the terminal device. This reduces the time required for the terminal device to update the key, reduces the key update latency of the terminal device, and improves the key update efficiency of the terminal device.

[0159] In one possible implementation of this application embodiment, step 509, where the second network device updates the key based on security configuration information, includes:

[0160] E1, the second network device determines the target link count value.

[0161] In this embodiment, during the key update process, the terminal device can first determine the target link count value to be used in this key update, so that it can determine the target update key to be used in this key update from multiple update keys, and further obtain the encryption key and integrity protection key, thereby quickly completing the key update without spending a lot of time deducing the target update key from the update keys. This reduces the time required for the terminal device to update the key, reduces the key update latency of the terminal device, and improves the key update efficiency of the terminal device.

[0162] In one possible implementation of this application embodiment, when the security configuration information includes the link count value corresponding to each update key, step E1, the second network device determines the target link count value, including:

[0163] e11. The second network device determines the link count value with the smallest value as the target link count value.

[0164] In this embodiment, after receiving security configuration information including link count values, the second network device can determine the target link count value based on predefined rules. Specifically, the target link count value to be used for this key update can be determined sequentially from the link count values; that is, the link count value with the smallest value can be determined as the target link count value, thereby quickly completing the key update. For example, when the link count values ​​include 1, 2, and 3, the link count value with a value of 1 can be determined as the target link count value.

[0165] In one possible implementation of this application embodiment, when the security configuration information includes a link index, step E1, the second network device determines the target link count value, including:

[0166] e21. The second network device determines the link index with the smallest value as the target link index.

[0167] e22. The second network device determines the target link count value based on the target link index.

[0168] In this embodiment, after receiving security configuration information including link count values, the second network device can determine the target link count value based on predefined rules. Specifically, it can first determine the target link index to be used for this key update from the link count values ​​in sequence, and then determine the target link count value to be used for this key update based on the target link index, thereby quickly completing the key update. For example, when the link index includes 1, 2, and 3, the link index with a value of 1 can be determined as the target link index, and then the target link count value indicated by the target link index can be determined according to the correspondence between the link index and the link count value.

[0169] In one possible implementation of this application embodiment, step E1, where the second network device determines the target link count value, includes:

[0170] e3. The second network device receives the target link count value from the first network device or terminal device.

[0171] In this embodiment, when the first network device leads the key update process, the second network device can receive the target link count value from the first network device to obtain the target link count value specified by the first network device for this update, thereby quickly completing the key update. When the terminal device leads the key update process, the second network device can receive the target link count value from the terminal device to obtain the target link count value specified by the terminal device for this update, thereby quickly completing the key update.

[0172] In one possible implementation of this application embodiment, step E1, where the second network device determines the target link count value, includes:

[0173] e41. The second network device receives the target link index from the first network device or terminal device.

[0174] e42. The second network device determines the target link count value based on the target link index.

[0175] In this embodiment, when the first network device initiates the key update, the second network device can receive the target link count value from the first network device to obtain the target link index specified by the first network device for this update, and then determine the target link count value to be used for this key update based on the target link index, thereby quickly completing the key update. When the terminal device initiates the key update, the second network device can receive the target link count value from the terminal device to obtain the target link index specified by the terminal device for this update, and then determine the target link count value to be used for this key update based on the target link index, thereby quickly completing the key update.

[0176] E2. The second network device determines the target update key from multiple update keys based on the target link count value.

[0177] In this embodiment of the application, after determining the target link count value, the second network device can determine the target update key corresponding to the target link count value from the multiple update keys included in the security configuration information and the correspondence between the link count value and the multiple update keys, which is the update key to be used for this key update.

[0178] E3. The second network device generates an encryption key and an integrity protection key based on the target link count and the target update key.

[0179] In this embodiment, after determining the target update key based on the target link count value, the second network device can obtain the encryption algorithm corresponding to the target cell. Finally, it generates an encryption key and an integrity protection key based on the encryption algorithm corresponding to the target cell, the target link count value, and the target update key. Specifically, the second network device can obtain the encryption algorithm index corresponding to the target cell from the security configuration information. By inputting the target link count value into the encryption algorithm index, it obtains the encryption algorithm corresponding to the target cell. Then, based on the encryption algorithm corresponding to the target cell, the target link count value, and the target update key, it generates an encryption key and an integrity protection key, thereby quickly completing the key update. This eliminates the need for the terminal device to deduce the target update key from the update key, thus reducing the time required for the terminal device to update the key, reducing the key update latency of the terminal device, and improving the key update efficiency of the terminal device.

[0180] In one possible implementation of this application embodiment, after the second network device generates an encryption key and an integrity protection key based on the target link count value and the target update key in step E3, the key update method provided in this application embodiment may further include:

[0181] F1. The second network device deletes the target link count or target link index.

[0182] In this embodiment of the application, in order to improve the security of key updates, the second network device can delete the used target link count value or target link index after updating the key using the target link count value or target link index, so as to prevent the update key from being reused and thus reducing the effectiveness of the update key, thereby quickly completing the key update.

[0183] In this embodiment of the application, after the terminal device and the second network device complete the key update, they can communicate based on the updated key, thereby enabling the terminal device to switch from the original cell to the target cell.

[0184] As illustrated by the foregoing embodiments, in order to reduce the key update latency of the terminal device and improve the key update efficiency of the terminal device, the first network device can pre-generate security configuration information including multiple update keys, and send the security configuration information to the terminal device and the second network device corresponding to the target cell respectively. This allows the terminal device and the second network device to quickly complete the key update based on the security configuration information including multiple update keys, without spending a lot of time deriving the update keys. This reduces the time required for the terminal device to update the key, reduces the key update latency of the terminal device, and improves the key update efficiency of the terminal device.

[0185] To make the technical solution of this application clearer and easier to understand, the key update method of this application will be explained in detail below with reference to specific data transmission scenarios of the first network device, the terminal device, and the second network device.

[0186] Referring to Figure 6a, which illustrates a data transmission diagram involving a first network device, a terminal device, a second network device, and a third network device, the first network device can be the original base station S-gNB corresponding to the original cell, the terminal device can be the UE, the second network device can be the target base station T-gNB corresponding to the target cell, and the third network device can be the potential target base station T-gNB corresponding to a potential target cell. The key update method in this embodiment includes the following steps:

[0187] S01, UE reports the measurement results to S-gNB.

[0188] In this embodiment, the UE can report network measurement results to the S-gNB, enabling the S-gNB to determine the target cell and potential target cells from multiple candidate cells based on the network measurement results. The S-gNB can configure the security configuration information for each candidate cell, allowing the UE to quickly switch from the target cell to other candidate cells. Furthermore, different candidate cells may correspond to the same base station, and the security configuration information for candidate cells within the same base station can be identical. Therefore, a candidate cell set can be generated based on candidate cells corresponding to the same base station, and then the security configuration information can be configured for different candidate cell sets.

[0189] Specifically, the security configuration information for each candidate cell set or each candidate cell may include multiple update keys, multiple link count values, and the correspondence between the link count values ​​and the multiple update keys; when the security configuration information includes multiple update keys, the security configuration information may include multiple link count values, which can be listed in list{K gNB *, NCC} are used for representation.

[0190] Alternatively, the security configuration information for each candidate cell set or each candidate cell may include multiple update keys, multiple link indices, and the correspondence between link count values ​​and multiple update keys, which can be represented as list{K gNB *, K_Index} are used for representation.

[0191] Alternatively, the security configuration information for each candidate cell set or each candidate cell may include multiple update keys, multiple link count values, the correspondence between the link count values ​​and multiple update keys, and the encryption algorithm index for each candidate cell.

[0192] Alternatively, the security configuration information for each candidate cell set or each candidate cell may include multiple update keys, multiple link indices, the correspondence between link count values ​​and multiple update keys, and the encryption algorithm index for each candidate cell.

[0193] S02, S-gNB sends an LTM handover request to T-gNB.

[0194] S03, T-gNB returns an LTM handover request response to S-gNB.

[0195] S04, S-gNB sends an LTM handover request to the potential T-gNB.

[0196] S05. The potential T-gNB returns an LTM handover request response to the S-gNB.

[0197] In this embodiment, after configuring the security configuration information for each candidate cell set or each candidate cell, the S-gNB can send the security configuration information of the target cell to the T-gNB via an LTM handover request, and send the security configuration information of other candidate cells, i.e., potential target cells, to potential T-gNBs. Furthermore, it can send the security capabilities of the terminal device to the target cell and potential target cells. The LTM handover request response returned by the T-gNB and potential T-gNB to the S-gNB may include NCC or K_Index or a corresponding encryption algorithm index, so that the S-gNB can determine whether the T-gNB and potential T-gNB have received the correct security configuration information, thereby completing the pre-configuration process of the S-gNB for the security configuration information of the T-gNB and potential T-gNBs.

[0198] S06, S-gNB sends an RRC reconfiguration command to the UE.

[0199] S07. The UE returns RRC reconfiguration completion information to the S-gNB.

[0200] In this embodiment, after the S-gNB pre-generates the security configuration information of the candidate cells, it can send an RRC reconfiguration command including the security configuration information to the UE. This allows the UE to quickly update its key based on the received security configuration information while simultaneously notifying the UE of the configuration information required during cell handover. This eliminates the need for extensive key derivation, reducing the time required for key updates, decreasing key update latency, and improving key update efficiency. After receiving the reconfiguration command from the S-gNB, the UE can return RRC reconfiguration completion information to the S-gNB, notifying it that the reconfiguration command has been successfully received.

[0201] S08 and S-gNB send LTM handover instructions to the UE.

[0202] S09, S-gNB notifies T-gNB of key update parameters.

[0203] In this embodiment, the S-gNB can lead the key update process. The S-gNB can specify the target link count or target link index to be used in this key update, i.e., specify the key update parameters, and send these parameters to the UE via LTM handover instructions. It also directly notifies the T-gNB of the key update parameters, enabling the UE and T-gNB to quickly complete the key update process based on the key update parameters and the security configuration parameters of the target cell. The S-gNB can also notify the T-gNB of the unused security configuration parameters of each candidate cell, i.e., the unused list{K}. gNB *, NCC} and unused list{K gNB *,K_Index}.

[0204] S10, UE communicates with T-gNB.

[0205] In this embodiment of the application, after the UE and T-gNB complete the key update, they can communicate based on the updated key, thereby enabling the UE to switch from the original cell to the target cell.

[0206] As illustrated by the examples in the foregoing embodiments, in order to reduce the key update latency of the terminal device and improve the key update efficiency of the terminal device, the S-gNB can pre-generate security configuration information including multiple update keys and send the security configuration information to the UE, the T-gNB corresponding to the target cell, and the potential T-gNB corresponding to the potential candidate cell, respectively. The S-gNB can lead the key update process, so that the UE and the T-gNB can quickly complete the key update based on the security configuration information including multiple update keys without spending a lot of time deriving the update keys. This reduces the time required for the UE to update the key, reduces the key update latency of the UE, and improves the key update efficiency of the UE.

[0207] Referring to Figure 6b, which shows another data transmission diagram involving a first network device, a terminal device, a second network device, and a third network device, the first network device can be the original base station S-gNB corresponding to the original cell, the terminal device can be the UE, the second network device can be the target base station T-gNB corresponding to the target cell, and the third network device can be the potential target base station T-gNB corresponding to the potential target cell. The key update method in this embodiment includes the following steps:

[0208] S11, UE reports measurement results to S-gNB.

[0209] S12, S-gNB sends an LTM handover request to T-gNB.

[0210] S13, S-gNB receives the LTM handover request response returned by T-gNB.

[0211] S14, S-gNB sends an LTM handover request to the potential T-gNB.

[0212] S15, S-gNB receives the LTM handover request response returned by the potential T-gNB.

[0213] S16, S-gNB sends an RRC reconfiguration command to the UE.

[0214] S17. The UE returns RRC reconfiguration completion information to the S-gNB.

[0215] The steps S11 to S17 described above are similar to steps S01 to S07 in the previous embodiments, and will not be described in detail here.

[0216] S18 and S-gNB send LTM handover instructions to the UE.

[0217] S19, UE determines key update parameters.

[0218] S20, the UE notifies the T-gNB of the key update parameters.

[0219] In this embodiment, the UE can lead the key update process. After receiving the LTM handover command sent by the S-gNB, the UE can specify the target link count or target link index to be used for this key update, i.e., specify the key update parameters, and directly notify the T-gNB of the key update parameters. This allows the UE and T-gNB to quickly complete the key update process based on the key update parameters and the security configuration parameters of the target cell. The UE can also notify the T-gNB of the unused security configuration parameters of each candidate cell, i.e., the unused list{K}. gNB *, NCC} and unused list{K gNB *,K_Index}.

[0220] S21, the UE communicates with the T-gNB.

[0221] In this embodiment of the application, after the UE and T-gNB complete the key update, they can communicate based on the updated key, thereby enabling the UE to switch from the original cell to the target cell.

[0222] As illustrated by the examples in the foregoing embodiments, in order to reduce the key update latency of the terminal device and improve the key update efficiency of the terminal device, the S-gNB can pre-generate security configuration information including multiple update keys and send the security configuration information to the UE, the T-gNB corresponding to the target cell, and the potential T-gNB corresponding to the potential candidate cell, respectively. The UE can lead the key update process, so that the UE and the T-gNB can quickly complete the key update based on the security configuration information including multiple update keys without spending a lot of time deriving the update keys. This reduces the time required for the UE to update the key, reduces the key update latency of the UE, and improves the key update efficiency of the UE.

[0223] Figure 7 is a schematic diagram of a communication device provided in an embodiment of this application. The communication device can specifically be a first network device, and the communication device specifically includes:

[0224] The generation module 701 is used to generate security configuration information for the target cell, wherein the security configuration information includes multiple update keys and the correspondence between the link count value and the multiple update keys;

[0225] The sending module 702 is used to send a handover request to the second network device corresponding to the target cell, so that the second network device corresponding to the target cell can update the key based on the security configuration information, wherein the handover request includes the security configuration information.

[0226] The sending module 702 is further configured to send a reconfiguration instruction to the terminal device, the reconfiguration instruction including the security configuration information;

[0227] The sending module 702 is further configured to send a switching instruction to the terminal device so that the terminal device can update the key based on the security configuration information.

[0228] In one possible implementation of this application embodiment, the security configuration information further includes a link count value corresponding to each update key.

[0229] In one possible implementation of this application embodiment, the security configuration information further includes a link index, which is used to indicate the link count value.

[0230] In one possible implementation of this application embodiment, the security configuration information further includes the encryption algorithm index corresponding to the target cell.

[0231] In one possible implementation of this application embodiment, the switching instruction includes a target link count value or a target link index, and the device further includes:

[0232] When the switching instruction includes the target link count value, the sending module 702 is further configured to send the target link count value and the unused link count value in the security configuration information to the second network device;

[0233] When the switching instruction includes the target link index, the sending module 702 is further configured to send the target link index and the unused link index in the security configuration information to the second network device.

[0234] In one possible implementation of this application, the handover request includes a Layer 1 or Layer 2 triggered Mobility LTM handover request.

[0235] Figure 8 is a schematic diagram of another communication device provided in an embodiment of this application. The communication device can specifically be a terminal device, and the communication device specifically includes:

[0236] The receiving module 801 is configured to receive a reconfiguration instruction from a first network device, the reconfiguration instruction including security configuration information, the security configuration information including multiple update keys and the correspondence between link count values ​​and the multiple update keys;

[0237] The receiving module 801 is used to receive a switching instruction from the first network device;

[0238] The key update module 802 is used to update the key based on the security configuration information.

[0239] In one possible implementation of this application embodiment, the security configuration information further includes a link count value corresponding to each update key.

[0240] In one possible implementation of this application embodiment, the security configuration information further includes a link index, which is used to indicate the link count value.

[0241] In one possible implementation of this application embodiment, the security configuration information further includes the encryption algorithm index corresponding to the target cell.

[0242] In one possible implementation of this application embodiment, the key update module 802 includes:

[0243] The determining unit is used to determine the target link count value;

[0244] The determining unit is configured to determine a target update key from the plurality of update keys based on the target link count value;

[0245] The generation unit is used to generate an encryption key and an integrity protection key based on the target link count value and the target update key.

[0246] In one possible implementation of this application embodiment, when the security configuration information includes a link count value corresponding to each update key, the determining unit is specifically used for:

[0247] The link count value with the smallest value is determined as the target link count value.

[0248] In one possible implementation of this application embodiment, when the security configuration information includes a link index, the determining unit is specifically used for:

[0249] The link index with the smallest value is determined as the target link index;

[0250] The target link count value is determined based on the target link index.

[0251] In one possible implementation of this application embodiment, the apparatus further includes:

[0252] The deletion module is used to delete the target link count value or the target link index.

[0253] In one possible implementation of this application embodiment, when the switching instruction includes a target link count value, the determining unit is specifically used for:

[0254] Obtain the target link count value from the switching command.

[0255] In one possible implementation of this application embodiment, when the switching instruction includes a target link index, the determining unit is specifically used for:

[0256] Obtain the target link index from the switching instruction;

[0257] The target link count value is determined based on the target link index.

[0258] In one possible implementation of this application embodiment, the apparatus further includes:

[0259] The sending module is used to send the target link index corresponding to the target link count value to the second network device.

[0260] In one possible implementation of this application embodiment, the apparatus further includes:

[0261] The sending module is used to send the target link index corresponding to the target link count value to the second network device.

[0262] Figure 9 is a schematic diagram of another communication device provided in an embodiment of this application. The communication device can specifically be a second network device, and the communication device specifically includes:

[0263] The receiving module 901 is configured to receive a handover request from a first network device, the handover request including security configuration information, the security configuration information including multiple update keys and the correspondence between link count values ​​and the multiple update keys;

[0264] The key update module 902 is used to update the key based on the security configuration information.

[0265] In one possible implementation of this application embodiment, the security configuration information further includes a link count value corresponding to each update key.

[0266] In one possible implementation of this application embodiment, the security configuration information further includes a link index, which is used to indicate the link count value.

[0267] In one possible implementation of this application embodiment, the security configuration information further includes the encryption algorithm index corresponding to the target cell.

[0268] In one possible implementation of this application embodiment, the key update module includes:

[0269] The determining unit is used to determine the target link count value;

[0270] The determining unit is further configured to determine a target update key from the plurality of update keys based on the target link count value;

[0271] The generation unit is used to generate an encryption key and an integrity protection key based on the target link count value and the target update key.

[0272] In one possible implementation of this application embodiment, when the security configuration information includes a link count value corresponding to each update key, the determining unit is specifically used for:

[0273] The link count value with the smallest value is determined as the target link count value.

[0274] In one possible implementation of this application embodiment, when the security configuration information includes a link index, the determining unit is specifically used for:

[0275] The link index with the smallest value is determined as the target link index;

[0276] The target link count value is determined based on the target link index.

[0277] In one possible implementation of this application embodiment, the determining unit is specifically used for:

[0278] Receive the target link count value from the first network device or terminal device.

[0279] In one possible implementation of this application embodiment, the determining unit is specifically used for:

[0280] Receive the target link index from the first network device or terminal device;

[0281] The target link count value is determined based on the target link index.

[0282] Figure 10 illustrates an example of the composition of an electronic device provided in an embodiment of this application. This electronic device may be a first device, including but not limited to a base station and a core network unit. Figure 10 shows a simplified schematic diagram of a base station structure. The base station includes parts 1010, 1020, and 1030. Part 1010 is mainly used for baseband processing and controlling the base station; part 1010 is typically the control center of the base station, often referred to as a processor, used to control the base station to perform the processing operations on the first device side in the above method embodiments. Part 1020 is mainly used for storing computer program code and data. Part 1030 is mainly used for transmitting and receiving radio frequency signals and converting radio frequency signals to baseband signals; part 1030 is often referred to as a transceiver module, transceiver, transceiver circuit, or transceiver. The transceiver module of part 1030, also referred to as a transceiver or transceiver, includes an antenna 1033 and a radio frequency circuit (not shown in the figure), wherein the radio frequency circuit is mainly used for radio frequency processing. Optionally, the device used to implement the receiving function in part 1030 can be regarded as a receiver, and the device used to implement the transmitting function can be regarded as a transmitter. That is, part 1030 includes receiver 1032 and transmitter 1031. The receiver can also be called a receiving module, receiver, or receiving circuit, etc., and the transmitter can be called a transmitting module, transmitter, or transmitting circuit, etc.

[0283] Sections 1010 and 1020 may include one or more single boards, each of which may include one or more processors and one or more memories. The processors are used to read and execute programs in the memories to implement baseband processing functions and control the base station. If multiple single boards exist, they can be interconnected to enhance processing capabilities. As an optional implementation, multiple single boards may share one or more processors, or multiple single boards may share one or more memories, or multiple single boards may simultaneously share one or more processors.

[0284] For example, in one implementation, the transceiver module of section 1030 is used to execute the transceiver-related processes performed by the base station (first device) in the aforementioned method embodiments. The processor of section 1010 is used to execute the processing-related processes performed by the base station in the aforementioned method embodiments.

[0285] It should be understood that Figure 10 is merely an example and not a limitation, and the network devices described above, including processors, memory, and transceivers, may not depend on the structure shown in Figure 10.

[0286] Figure 11 illustrates another example of the composition of an electronic device provided in an embodiment of this application. This electronic device can be a second device, which can be a terminal device, including but not limited to mobile phones, smart wearable devices (such as smartwatches), and other electronic devices. Taking a mobile phone as an example, the electronic device may include a processor 310, an external memory interface 320, an internal memory 321, a display screen 330, a camera 340, antenna 1, antenna 2, a mobile communication module 350, and a wireless communication module 360, etc.

[0287] It is understood that the structure illustrated in this embodiment does not constitute a specific limitation on the electronic device. In other embodiments, the electronic device may include more or fewer components than illustrated, or combine some components, or split some components, or have different component arrangements. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.

[0288] Processor 310 may include one or more processing units, such as: application processor (AP), modem processor, graphics processing unit (GPU), image signal processor (ISP), controller, video codec, digital signal processor (DSP), baseband processor, and / or neural network processing unit (NPU), etc. Different processing units may be independent devices or integrated into one or more processors.

[0289] It is understood that the interface connection relationships between the modules illustrated in this embodiment are merely illustrative and do not constitute a limitation on the structure of the electronic device. In other embodiments of this application, the electronic device may also employ different interface connection methods or combinations of multiple interface connection methods as described in the above embodiments.

[0290] The external storage interface 320 can be used to connect an external memory card, such as a Micro SD card, to expand the storage capacity of the electronic device. The external memory card communicates with the processor 310 through the external storage interface 320 to perform data storage functions. For example, music, video, and other files can be saved on the external memory card.

[0291] Internal memory 321 can be used to store executable program code, including instructions. Processor 310 executes various functional applications and data processing of the electronic device by running the instructions stored in internal memory 321. Internal memory 321 may include a program storage area and a data storage area. The program storage area may store the operating system, at least one application program required for a function (such as sound playback, image playback, etc.), etc. The data storage area may store data created during the use of the electronic device (such as audio data, phonebook, etc.). Furthermore, internal memory 321 may include high-speed random access memory, and may also include non-volatile memory, such as at least one disk storage device, flash memory device, universal flash storage (UFS), etc. Processor 310 executes various functional applications and data processing of the electronic device by running instructions stored in internal memory 321 and / or instructions stored in memory located within the processor.

[0292] The wireless communication function of electronic devices can be realized through antenna 1, antenna 2, mobile communication module 350, wireless communication module 360, modem processor and baseband processor, etc.

[0293] Antenna 1 and antenna 2 are used to transmit and receive electromagnetic wave signals. Each antenna in the electronic device can be used to cover one or more communication frequency bands. Different antennas can also be reused to improve antenna utilization. For example, antenna 1 can be reused as a diversity antenna for a wireless local area network. In some other embodiments, the antennas can be used in conjunction with a tuning switch.

[0294] The mobile communication module 350 can provide solutions for wireless communication applications including 2G / 3G / 4G / 5G in electronic devices. The mobile communication module 350 may include at least one filter, switch, power amplifier, low noise amplifier (LNA), etc. The mobile communication module 350 can receive electromagnetic waves via antenna 1, and perform filtering, amplification, and other processing on the received electromagnetic waves before transmitting them to a modem processor for demodulation. The mobile communication module 350 can also amplify the signal modulated by the modem processor and convert it into electromagnetic waves for radiation via antenna 1. In some embodiments, at least some functional modules of the mobile communication module 350 may be housed in the processor 310. In some embodiments, at least some functional modules of the mobile communication module 350 and at least some modules of the processor 310 may be housed in the same device.

[0295] In some embodiments, the electronic device initiates or receives call requests via the mobile communication module 350 and the antenna 1.

[0296] Furthermore, an operating system runs on top of the aforementioned components. Examples include iOS, Android, and Windows operating systems. Applications can be installed and run on this operating system. Those skilled in the art will understand that, for the sake of convenience and brevity, explanations and beneficial effects of the relevant content in any of the above-described electronic devices can be found in the corresponding method embodiments provided above, and will not be repeated here.

[0297] This application also provides a communication system, which may include a first device (such as a network device such as a base station) as shown in FIG10 and a second device (such as a terminal device such as a mobile phone) as shown in FIG11.

[0298] In this application, the terminal device or network device may include a hardware layer, an operating system layer running on top of the hardware layer, and an application layer running on top of the operating system layer. The hardware layer may include hardware such as a central processing unit (CPU), a memory management unit (MMU), and memory (also known as main memory). The operating system layer may be any one or more computer operating systems that implement business processing through processes, such as Linux, Unix, Android, iOS, or Windows. The application layer may include applications such as browsers, address books, word processing software, and instant messaging software.

[0299] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and modules described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0300] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative; for instance, the division of modules is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple modules or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces, or indirect coupling or communication connection between devices or modules, and may be electrical, mechanical, or other forms.

[0301] The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical modules; that is, they may be located in one place or distributed across multiple network modules. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.

[0302] Furthermore, the functional modules in the various embodiments of this application can be integrated into one processing module, or each module can exist physically separately, or two or more modules can be integrated into one module. The integrated modules described above can be implemented in hardware or as software functional modules.

[0303] If the integrated module is implemented as a software functional module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the essential contribution of the technical solution of this application, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the processes of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory, random access memory, magnetic disks, or optical disks.

[0304] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit it. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.

Claims

1. A key update method, characterized in that, Applied to a first network device, the method includes: Generate security configuration information for the target cell, the security configuration information including multiple update keys and the correspondence between link count values ​​and the multiple update keys; A handover request is sent to the second network device corresponding to the target cell, so that the second network device corresponding to the target cell can update the key based on the security configuration information, wherein the handover request includes the security configuration information; Send a reconfiguration command to the terminal device, the reconfiguration command including the security configuration information; A switching command is sent to the terminal device so that the terminal device can update the key based on the security configuration information.

2. The method according to claim 1, characterized in that, The security configuration information also includes the link count value corresponding to each update key.

3. The method according to claim 1, characterized in that, The security configuration information also includes a link index, which is used to indicate the link count value.

4. The method according to any one of claims 1 to 3, characterized in that, The security configuration information also includes the encryption algorithm index corresponding to the target cell.

5. The method according to claim 1, characterized in that, The switching instruction includes a target link count or a target link index, and the method further includes: When the switching instruction includes the target link count value, the target link count value and the unused link count value in the security configuration information are sent to the second network device. When the switching instruction includes the target link index, the target link index and the unused link index in the security configuration information are sent to the second network device.

6. The method according to claim 1, characterized in that, The handover request includes a Layer 1 or Layer 2 triggered Mobility LTM handover request.

7. A key update method, characterized in that, Applied to a terminal device, the method includes: Receive a reconfiguration instruction from a first network device, the reconfiguration instruction including security configuration information, the security configuration information including multiple update keys and the correspondence between link count values ​​and the multiple update keys; Receive a handover command from the first network device; The key is updated based on the security configuration information.

8. The method according to claim 7, characterized in that, The security configuration information also includes the link count value corresponding to each update key.

9. The method according to claim 7, characterized in that, The security configuration information also includes a link index, which is used to indicate the link count value.

10. The method according to any one of claims 7 to 9, characterized in that, The security configuration information also includes the encryption algorithm index corresponding to the target cell.

11. The method according to any one of claims 7 to 9, characterized in that, The key update based on the security configuration information includes: Determine the target link count value; The target update key is determined from the plurality of update keys based on the target link count value; An encryption key and an integrity protection key are generated based on the target link count value and the target update key.

12. The method according to claim 11, characterized in that, When the security configuration information includes the link count value corresponding to each update key, determining the target link count value includes: The link count value with the smallest value is determined as the target link count value.

13. The method according to claim 11, characterized in that, When the security configuration information includes a link index, determining the target link count value includes: The link index with the smallest value is determined as the target link index; The target link count value is determined based on the target link index.

14. The method according to claim 12 or 13, characterized in that, After generating the encryption key and integrity protection key based on the target link count value and the target update key, the method further includes: Delete the target link count or the target link index.

15. The method according to claim 11, characterized in that, When the switching instruction includes a target link count value, determining the target link count value includes: Obtain the target link count value from the switching command.

16. The method according to claim 11, characterized in that, When the switching instruction includes a target link index, determining the target link count value includes: Obtain the target link index from the switching instruction; The target link count value is determined based on the target link index.

17. The method according to claim 11, characterized in that, After determining the target link count value, the method further includes: The target link count value is sent to the second network device.

18. The method according to claim 11, characterized in that, After determining the target link count value, the method further includes: Send the target link index corresponding to the target link count value to the second network device.

19. A key update method, characterized in that, Applied to a second network device, the method includes: Receive a handover request from a first network device, the handover request including security configuration information, the security configuration information including multiple update keys and the correspondence between link count values ​​and the multiple update keys; The key is updated based on the security configuration information.

20. The method according to claim 19, characterized in that, The security configuration information also includes the link count value corresponding to each update key.

21. The method according to claim 19, characterized in that, The security configuration information also includes a link index, which is used to indicate the link count value.

22. The method according to any one of claims 19 to 21, characterized in that, The security configuration information also includes the encryption algorithm index corresponding to the target cell.

23. The method according to claim 19, characterized in that, The key update based on the security configuration information includes: Determine the target link count value; The target update key is determined from the plurality of update keys based on the target link count value; An encryption key and an integrity protection key are generated based on the target link count value and the target update key.

24. The method according to claim 23, characterized in that, When the security configuration information includes the link count value corresponding to each update key, determining the target link count value includes: The link count value with the smallest value is determined as the target link count value.

25. The method according to claim 23, characterized in that, When the security configuration information includes a link index, determining the target link count value includes: The link index with the smallest value is determined as the target link index; The target link count value is determined based on the target link index.

26. The method according to claim 23, characterized in that, Determining the target link count value includes: Receive the target link count value from the first network device or terminal device.

27. The method according to claim 23, characterized in that, Determining the target link count value includes: Receive the target link index from the first network device or terminal device; The target link count value is determined based on the target link index.

28. A communication device, characterized in that, The communication device is specifically a first network device, which includes: The generation module is used to generate security configuration information for the target cell, wherein the security configuration information includes multiple update keys and the correspondence between link count values ​​and the multiple update keys; The sending module is configured to send a handover request to the second network device corresponding to the target cell, so that the second network device corresponding to the target cell can update the key based on the security configuration information, wherein the handover request includes the security configuration information. The sending module is further configured to send a reconfiguration instruction to the terminal device, the reconfiguration instruction including the security configuration information; The sending module is also used to send a switching instruction to the terminal device so that the terminal device can update the key based on the security configuration information.

29. A communication device, characterized in that, The communication device is specifically a terminal device, and the communication device includes: A receiving module is configured to receive a reconfiguration instruction from a first network device, the reconfiguration instruction including security configuration information, the security configuration information including multiple update keys and the correspondence between link count values ​​and the multiple update keys; The receiving module is used to receive a switching instruction from the first network device; The key update module is used to update the key based on the security configuration information.

30. A communication device, characterized in that, The communication device is specifically a second network device, and the communication device includes: A receiving module is configured to receive a handover request from a first network device, the handover request including security configuration information, the security configuration information including multiple update keys and the correspondence between link count values ​​and the multiple update keys; The key update module is used to update the key based on the security configuration information.

31. A communication device, characterized in that, The communication device includes: Memory is used to store computer programs or computer instructions; A processor for executing a computer program or computer instructions stored in the memory, causing the communication device to perform the method as described in any one of claims 1 to 6.

32. A communication device, characterized in that, The communication device includes: Memory is used to store computer programs or computer instructions; A processor for executing a computer program or computer instructions stored in the memory, causing the communication device to perform the method as described in any one of claims 7 to 18.

33. A communication device, characterized in that, The communication device includes: Memory is used to store computer programs or computer instructions; A processor for executing a computer program or computer instructions stored in the memory, causing the communication device to perform the method as described in any one of claims 19 to 27.

34. A computer storage medium for storing a computer program, which, when executed, is used to implement the method of any one of claims 1 to 6, or to implement the method of any one of claims 7 to 18, or to implement the method of any one of claims 19 to 27.