Communication method and apparatus

WO2025214318A1PCT designated stage Publication Date: 2025-10-16HUAWEI TECH CO LTD
View PDF -1 Cites -1 Cited by

Patent Information

Application Number
PCT/CN2025/087609
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-04-08
Filing Date
2025-04-07
Publication Date
2025-10-16

AI Technical Summary

Technical Problem

In non-terrestrial network communication scenarios, how to ensure the communication security between the terminal and the base station under the base station-to-satellite architecture, especially to achieve identity authentication between the terminal and the base station when there is no access layer security context or access layer security is not established.

Method used

The core network device generates verification information based on the key shared between the terminal and it, and sends it to the access network device or terminal through the feeder link for identity authentication to ensure communication security.

Benefits of technology

In the absence of access layer security context, identity authentication is achieved between the terminal and the base station, ensuring the security and reliability of communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025087609_16102025_PF_FP_ABST
    Figure CN2025087609_16102025_PF_FP_ABST
Patent Text Reader

Abstract

A communication method and apparatus, which are used for ensuring the communication security between a terminal and a base station in an NTN scenario for the architecture where the base stations are deployed on a satellite. The method is applied to a discontinuous backhaul scenario, and comprises: determining first verification information and second verification information on the basis of a first shared key of a terminal and a core network device, wherein the first verification information is used for verifying the terminal, and the second verification information is used for verifying a first access network device; and when the backhaul link between the first access network device and the core network device is available, sending the first verification information and the second verification information to the first access network device.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method and apparatus

[0001] Cross-reference to Related Applications

[0002] This application claims priority to the Chinese Patent Application No. 202410421256.3, filed on April 8, 2024, and entitled “A Communication Method and Apparatus”, the entire contents of which are incorporated herein by reference. TECHNICAL FIELD

[0003] The present application relates to the field of mobile communication technology, and in particular to a communication method and apparatus. BACKGROUND

[0004] Currently, the 5th generation (5G) new radio (NR) technology is constantly evolving. At the same time, the NR technology has also entered the commercial deployment stage from the standardization stage. The NR standard protocol can be a wireless communication technology designed for terrestrial cellular network scenarios, which can provide users with ultra-low latency, ultra-reliability, ultra-high rate, and ultra-quantity connection wireless communication services. Compared with terrestrial communication, non-terrestrial network (NTN) communication has the characteristics of large coverage area and flexible networking, and can achieve seamless global network coverage. NTN communication includes networking using unmanned aerial vehicles, high-altitude platforms, satellites and other devices to provide data transmission, voice communication and other services for user equipment (UE).

[0005] In the NTN scenario, for the architecture of the base station on the satellite, how to ensure the communication security between the terminal and the base station is a problem to be solved. SUMMARY

[0006] The present application provides a communication method and apparatus to ensure the communication security between the terminal and the base station in the NTN scenario for the architecture of the base station on the satellite when there is no access stratum (AS) security or no AS security or no AS security context is established.

[0007] In a first aspect, a communication method is provided. The method can be implemented by a first communication device. The first communication device can be a core network device or a component in the core network device. The core network device can also be referred to as a core network network element, which can be an access and mobility management function (AMF) network element or a mobility management entity (MME), etc., and is not specifically limited. In the present application, the component can include at least one of a chip, a chip system, a processor, a transceiver, a processing unit, or a transceiving unit, for example. Taking the core network device as an example, the method can be applied in a feeding non-continuous scenario, including the following steps: determining, by the core network device, first authentication information and / or second authentication information according to a first shared key of a terminal and the core network device, the first authentication information being used to authenticate the terminal, and the second authentication information being used to authenticate the first access network device; and sending the first authentication information and / or the second authentication information to the first access network device in a case where a feeding link between the first access network device and the core network device is available.

[0008] Based on the method shown in the first aspect, in a case where there is no AS security or no AS security context is established between the terminal and the access network device, the core network device can generate the first authentication information for authenticating the terminal according to the first shared key of the terminal and the core network device, and generate the second authentication information for authenticating the first access network device. In addition, the core network device can send the first authentication information and / or the second authentication information to the first access network device. Accordingly, the first access network device can authenticate the terminal according to the first authentication information, and / or the terminal can authenticate the first access network device according to the second authentication information, to achieve identity security authentication between the terminal and the access network device. The first access network device can be an access network device that the terminal can access, or an access network device that the terminal can communicate with.

[0009] Specifically, the first authentication information can be used by the first access network device to verify that the terminal is legitimate or authentic, and the second authentication information can be used by the terminal to verify that the second access network device is legitimate or authentic.

[0010] It can be understood that the authentication of the terminal and the authentication of the access network device can also be performed independently. For example, in the first aspect, the core network device can generate the first authentication information according to the first shared key, and accordingly, the core network device sends only the first authentication information to the first access network device, which is used to perform the authentication of the terminal in the present application. For another example, in the first aspect, the core network device can generate the second authentication information according to the first shared key, and the core network device sends only the second authentication information to the first access network device, which is used to perform the authentication of the first access network device in the present application.

[0011] For example, if only the terminal needs to be verified, or the first access network device does not need to be verified, the core network device generates the first verification information, or the core network device sends the first verification information to the first access network device; in addition, the core network device can ignore generating the sixth verification information, or the core network device can ignore sending the second verification information to the first base station. If only the first access network device needs to be verified, or the terminal does not need to be verified, the core network device generates the second verification information, or the core network device sends the second verification information to the first access network device; in addition, the core network device can ignore generating the first verification information or does not need to generate the first verification information. In this application, ignoring performing an action can also be described as skipping or not performing the action.

[0012] In this application, the power feeding discontinuous scenario can also be described as a store and forward (S&F) scenario of a satellite, a power feeding discontinuous state, or as a scenario of accessing through a power feeding discontinuous access network device, and these several description manners can be replaced with each other.

[0013] In this application, the first shared key is a shared key between the terminal and the core network device maintained by the core network device, or can also be called a core network side shared key, or has other names. In addition, the shared key between the terminal and the core network device maintained by the terminal can be called a second shared key or a terminal side shared key, or has other names. It can be understood that in order to realize identity verification based on a shared key, the first shared key and the second shared key are the same key. The terminal and the core network device can store their respective shared keys in an authentication process.

[0014] For the case where the core network device determines to send a downlink NAS message to the terminal, in the first aspect, the core network device can determine the first verification information according to the first shared key between the terminal and the core network device, and send the first verification information to the first base station in the case where the feeder link is available. Or it can be said that for the case where the core network device determines to send a downlink NAS message to the terminal, the generation and sending of the second verification information can be ignored.

[0015] After the terminal and the first access network device are verified, the terminal can send an uplink non-access stratum (NAS) message to the first access network device, and / or the terminal can receive a downlink NAS message from the first access network device.

[0016] It can be understood that, in the present application, the action of the terminal sending information or a message to the access network device, and the action of the access network device sending information or a message to the terminal, can be performed in a case where a service link between the terminal and the access network device is available. In addition, the action of the core network device sending information or a message to the access network device, and the action of the access network device sending information or a message to the core network device, can be performed in a case where a feeder link between the core network device and the access network device is available.

[0017] In a possible implementation, the first verification information and / or the second verification information are sent to the first access network device in a case where a feeder link between the first access network device and the core network device is available.

[0018] It can also be understood that, in the present application, the feeder link can also be described as a link between the first access network device and a gateway station, which can be connected with the core network device, or a feeder link corresponding to the first access network device.

[0019] In a possible implementation, the core network device can further receive a NAS message of the terminal sent by a feeder discontinuous access network device. For example, before determining the first verification information and / or the second verification information according to the first shared key of the terminal and the core network device, or before sending the first verification information and / or the second verification information to the first access network device, the core network device can further receive the NAS message of the terminal sent by the feeder discontinuous access network device. The feeder discontinuous access network device can also be referred to as an access network device supporting a feeder discontinuous scenario, or an access network device supporting feeder discontinuity, and the like. The feeder discontinuous access network device can be an access network device accessed by the terminal when the terminal performs registration, for example, referred to as a second access network device. The access network device can determine that the terminal accesses the feeder discontinuous access network device, or determine that the terminal or the second access network device is in a feeder discontinuous scenario, according to the received NAS message sent by the second access network device, so as to trigger or start to perform the method shown in the first aspect, or in other words, trigger or start to determine the first verification information and / or the second verification information. Therefore, the core network device generates the corresponding verification code on demand.

[0020] In a possible implementation, the core network device can determine the first authentication information and / or the second authentication information according to the first shared key, the identity of the first access network device, and a first parameter, the first parameter comprising at least one of: a non-access stratum count value; an authentication count value maintained by the core network device for the terminal; and a random number. The first parameter can be used as a generation parameter of the authentication information. Based on this implementation, the corresponding first authentication information and / or second authentication information can be determined for the terminal and the first access network device. The first parameter can ensure that the core network device generates different authentication information when the terminal accesses the first access network device at different times, preventing the authentication information from being replayed. For other access network devices, the authentication information generated by the core network device can be different, to implement authentication between the terminal and different access network devices. For example, for other access network devices, the authentication information can be generated according to the first shared key, the identity of the other access network device, and the generation parameter. Different access network devices can correspond to different generation parameters.

[0021] In a possible implementation, the core network device can further send one or more of the non-access stratum count value, the authentication count value maintained by the core network device for the terminal, or the random number to the first access network device, or send first information to the first access network device, the first information being used to indicate one or more of the non-access stratum count value, the authentication count value maintained by the core network device for the terminal, or the random number. As an example, the first information can comprise part bits of the NAS count value to reduce indication overhead, for example, the last N1 bits of the NAS count value; and / or the first information can comprise the last N2 bits of the authentication count value, N1 and N2 can be positive integers, and N1 and N2 can be the same or different, which is not specifically limited. Based on this implementation, the core network device can flexibly indicate the count value to the terminal, and ensure that the terminal and the core network device generate the verification code using the same parameter.

[0022] In a possible implementation, before determining the first verification information and / or the second verification information according to the first shared key and the first parameter, the core network device can further receive one or more of the following from the terminal: the non-access stratum count value, the verification count value maintained by the terminal and the core network device, or a random number; or, the core network device can further receive second information from the terminal, the second information being used to indicate one or more of the following: the non-access stratum count value, the verification count value maintained by the terminal and the core network device, or a random number. As an example, the second information can include part of bits of the NAS count value to reduce indication overhead, such as the last N3 bits, and / or the second information can include the last N4 bits of the verification count value, N3 and N4 can be positive integers, and N3 and N4 can be the same or different, which are not specifically limited. Based on this implementation, flexible indication of the count value can be implemented, such as indicating only part of bits of the count value. Based on this implementation, the terminal can flexibly indicate the count value to the core network device, ensuring that the core network device generates the verification code using the same parameter as the terminal.

[0023] In a possible implementation, the core network device can send a first message to the first access network device, the first message including the first verification information and / or the second verification information, and including the identity of the terminal. Based on this implementation, the identity of the terminal, the first verification information, and / or the second verification information can be carried in the same message, so as to indicate the association between the terminal and the first verification information and / or the association between the terminal and the second verification information to the first access network device. The first access network device can determine that the first verification information can be used to verify the terminal according to the identity of the terminal, and / or determine that the terminal verifies the first access network device according to the second verification information. Therefore, the first access network device can verify the terminal according to the first verification information, and / or send the second verification information to the terminal.

[0024] In a possible implementation, the identifier of the terminal includes at least one of the following: an identifier of the terminal allocated by the access network; an identifier of the terminal allocated by the core network; a first identifier of the terminal, which is determined according to the identifier of the terminal allocated by the core network and the identifier of the first access network device; and a second identifier of the terminal, which is determined according to the identifier of the terminal allocated by the access network and the identifier of the first access network device. In a case where the core network device determines to transmit the data packet of the terminal through the control plane, the identifier of the terminal can include the identifier allocated by the access network or the core network, which can be referred to as an air interface identifier, and in this case, the access network device can determine to transmit the data packet of the terminal through the first access network device. In a case where the core network device cannot accurately determine the access network device that the terminal can access, for example, in a case where the core network device does not need to transmit the data packet of the terminal through the control plane, the core network device can determine a plurality of access network devices (for example, a plurality of satellite access network devices), which can include the first access network device, and in this case, the identifier of the terminal can be an identifier determined according to the air interface identifier and the identifier of the access network device, for example, referred to as a verification identifier. In this case, the verification identifier of the terminal is different for different access network devices, and therefore, the verification information used by different access network devices can be distinguished by the verification identifier of the terminal, so as to avoid repeated use of the verification information by the plurality of access network devices.

[0025] It can be understood that, for the first access network device, the identifier of the terminal can be obtained by processing the identifier allocated by the core network. For example, the processing of the identifier allocated by the core network includes truncation processing of the identifier allocated by the core network, and the first access network device can store a correspondence between the identifier of the terminal before and after the processing, for determining the terminal.

[0026] In a possible implementation, the core network device can send first time information to the first access network device in a case where a feeder link between the first access network device and the core network device is available, and the first time information is used to indicate a valid time of the first verification information and / or a valid time of the second verification information, so that the terminal and / or the access network device delete the verification information after the valid time of the verification information is exceeded, to save storage space.

[0027] In a possible implementation, before determining the first verification information and / or the second verification information according to the first shared key between the terminal and the first access network device, the core network device can further determine to transmit the data packet of the terminal through the control plane. Alternatively, it can be said that before determining the first verification information and / or the second verification information according to the first shared key between the terminal and the first access network device, the core network device can further determine that there is no AS security or no AS security is established between the terminal and the access network device (i.e., the second access network device or the access network device that is not continuously powered) serving the terminal. This implementation enables the core network device to accurately determine the terminal that needs to generate the verification information, avoiding missing the verification of the terminal. In addition, the core network device does not need to determine the corresponding verification information for all terminals, thereby reducing the processing overhead of the core network device.

[0028] In a possible implementation, the core network device can send an N2 message to the first access network device, and the N2 message includes the first verification information and / or the second verification information.

[0029] In a possible implementation, the N2 message further includes a NAS message. The NAS message can include a NAS security mode command or a registration accept (or referred to as a registration accept message), or a NAS message containing downlink data of the terminal. The downlink data can include user data and / or short message data, and therefore the user data and / or the short message data can be interacted using the payload of the NAS message. It can be understood that in each sending process of the NAS message, the identity authentication of the terminal based on the terminal verification information and / or the identity authentication of the access network device based on the verification information of the access network device can be performed, to ensure that each sending process of the NAS message is secure. For example, in the process of sending the NAS security mode command, the verification of the terminal and the first access network device is performed, and in the process of sending the registration accept message, the verification of the terminal and the first access network device is performed again.

[0030] In a possible implementation, the core network device can further determine the third authentication information and / or the fourth authentication information according to the first shared key between the terminal and the core network device, and send the third authentication information and / or the fourth authentication information to the third access network device, the third authentication information being used for the third access network device to authenticate the terminal, and the fourth authentication information being used for the terminal to authenticate the third access network device. The third access network device is different from the first access network device. For a scenario in which the core network device determines a plurality of access network devices including the first access network device and the third access network device, the core network device can further send the third authentication information and / or the fourth authentication information to the third access network device, for identity security authentication between the terminal and the third access network device. It can be understood that if only the terminal needs to be authenticated, the AMF can generate and send the third authentication information, and ignore the generation and / or sending of the fourth authentication information. It can be understood that if only the third access network device terminal needs to be authenticated, the AMF can generate and send the fourth authentication information, and ignore the generation and / or sending of the third authentication information.

[0031] The core network device can determine the third authentication information and / or the fourth authentication information according to the first shared key, the identifier of the third access network device, and a second parameter. Specifically, the third authentication information can be used for the third access network device to authenticate that the terminal is legitimate or real, and the fourth authentication information can be used for the terminal to authenticate that the third access network device is legitimate or real.

[0032] In a possible implementation, the determining the third authentication information and / or the fourth authentication information according to the first shared key between the terminal and the core network device includes: determining the third authentication information and / or the fourth authentication information according to the first shared key, the identifier of the third access network device, and a second parameter, the second parameter including at least one of the following: a non-access stratum count value; an authentication count value maintained by the terminal and the core network device; a random number. For a scenario in which the core network device determines a plurality of access network devices including the first access network device and the third access network device, the core network device can determine the third authentication information and / or the fourth authentication information according to the first shared key, the identifier of the third access network device, and a second parameter. The second parameter can be the same as or different from the first parameter. The second parameter can ensure that the core network device generates different authentication information when the terminal accesses the second access network device at different times, to prevent the authentication information from being replayed.

[0033] In a possible implementation, the core network device can further send one or more of the non-access stratum count value, the authentication count value maintained by the core network device for the terminal, or the random number to the third access network device; or the core network device can further send fourth information to the first access network device, the fourth information being used to indicate one or more of the non-access stratum count value, the authentication count value maintained by the core network device for the terminal, or the random number. The count value corresponding to the third access network device can be the same as or different from the count value corresponding to the first access network device. As an example, the fourth information can include part of bits of the NAS count value to reduce indication overhead, such as the last M1 bits, and / or the fourth information can include the last M1 bits of the authentication count value. M1 and M2 can be positive integers, and M1 and M2 can be the same or different, which is not specifically limited. Based on this implementation, flexible indication of the count value can be implemented, such as indicating only part of bits of the count value. Based on this implementation, the terminal can flexibly indicate the count value to the core network device, and ensure that the terminal and the core network device generate the verification code using the same parameters.

[0034] In a possible implementation, before the third verification information and the fourth verification information are determined according to the first shared key and the second parameter, the core network device can further receive one or more of the non-access stratum count value, the authentication count value maintained by the core network device for the terminal, or the random number from the terminal; or the core network device can further receive fifth information from the terminal, the fifth information being used to indicate one or more of the non-access stratum count value, the authentication count value maintained by the core network device for the terminal, or the random number. As an example, the fifth information can include part of bits of the NAS count value to reduce indication overhead, such as the last M3 bits, and / or the fifth information can include the last M4 bits of the authentication count value. M3 and M4 can be positive integers, and M3 and M4 can be the same or different, which is not specifically limited. Based on this implementation, flexible indication of the count value can be implemented, such as indicating only part of bits of the count value. Based on this implementation, the terminal can flexibly indicate the count value to the core network device, and ensure that the core network device generates the verification code using the same parameters as the terminal.

[0035] In a possible implementation, the core network device can send a third message to the third access network device, the third message comprising the message including the third authentication information and the fourth authentication information, and the message further comprising the identifier of the terminal. Based on this implementation, the identifier of the terminal, the third authentication information and / or the fourth authentication information can be carried in the same message, so as to indicate the association relationship between the terminal, the third authentication information and / or the fourth authentication information to the third access network device, and the third access network device can determine that the third authentication information can be used to authenticate the terminal according to the identifier of the terminal, and / or determine that the terminal authenticates the third access network device according to the fourth authentication information. Therefore, the third access network device can perform authentication of the terminal according to the third authentication information, and / or send the fourth authentication information to the terminal.

[0036] In a possible implementation, the identifier of the terminal comprises at least one of the following: the identifier of the terminal allocated by the access network; the identifier of the terminal allocated by the core network; a third identifier of the terminal, the third identifier being determined according to the identifier of the terminal allocated by the core network and the identifier of the third access network device; and a fourth identifier of the terminal, the fourth identifier being determined according to the identifier of the terminal allocated by the access network and the identifier of the third access network device.

[0037] In a possible implementation, the core network device can further send second time information to the third access network device, the second time information being used to indicate the valid time of the third authentication information and / or the valid time of the fourth authentication information, so as to facilitate the terminal and / or the access network device to delete the authentication information after the valid time of the authentication information is exceeded, thereby saving storage space.

[0038] In a possible implementation, the sending of the third authentication information and / or the fourth authentication information to the third access network device comprises: the core network device sending an N2 message to the third access network device, the N2 message comprising the third authentication information and the fourth authentication information.

[0039] In a possible implementation, the core network device can determine a plurality of candidate access network devices, for example, comprising the first access network device and the third access network device. The core network device can further indicate one or more candidate access network devices to the terminal, for the terminal to select an access candidate access network device.

[0040] In a possible implementation, the terminal can send an uplink NAS message to the third access network device after the authentication with the third access network device is passed.

[0041] In a second aspect, a communication method is provided. The method can be implemented by a second communication device. The second communication device can be a first access network device or a component in the first access network device. The first access network device can be a base station or the like, which is not specifically limited. Taking the first access network device as an execution subject for example, the method can be implemented by the following steps: the first access network device receives first authentication information and / or second authentication information from a core network device, the first authentication information is used to authenticate a terminal, the second authentication information is used to authenticate the first access network device, and the first authentication information and / or the second authentication information are determined by the core network device according to a first shared key between the terminal and the core network device; the first access network device can also receive fifth authentication information from the terminal, and the fifth authentication information is determined by the terminal according to a second shared key between the terminal and the core network device. The first access network device can also compare the first authentication information and the fifth authentication information, and determine whether the terminal passes the authentication according to a comparison result.

[0042] In a possible implementation, the first access network device can also send the second authentication information to the terminal according to an identifier of the terminal.

[0043] In the above method, if only the terminal needs to be authenticated, or the first access network device does not need to be authenticated, the terminal can generate the fifth authentication information according to the second shared key, the identifier of the first base station and the third parameter, and the terminal can ignore the generation of the sixth authentication information. If only the first access network device needs to be authenticated, or the terminal does not need to be authenticated, the terminal can generate the sixth authentication information according to the second shared key, the identifier of the first base station and the third parameter, and the terminal can ignore the generation of the fifth authentication information.

[0044] It can be understood that the present application does not limit the execution order of the first access network device sending the second authentication information and receiving the fifth authentication information from the terminal.

[0045] In a possible implementation, the first access network device can receive the identifier of the terminal from the terminal, so as to obtain the first authentication information for authenticating the terminal according to the identifier of the terminal, and / or obtain the second authentication information for authenticating the first access network device by the terminal.

[0046] In a possible implementation, the first access network device can receive the first authentication information and / or the second authentication information from the core network device when a feeder link between the first access network device and the core network device is available.

[0047] In a possible implementation, the first access network device can also store the first authentication information and / or the second authentication information.

[0048] In a possible implementation, the first access network device can send the second authentication information to the terminal in a case that a service link between the first access network device and the terminal is available; and the first access network device can receive the fifth authentication information from the terminal in the case that the service link between the first access network device and the terminal is available.

[0049] In a possible implementation, the first authentication information is determined by the core network device according to the first shared key, an identifier of the first access network device, and a first parameter, the first parameter comprising at least one of: a non-access stratum count value; an authentication count value maintained by the core network device for the terminal; a random number.

[0050] In a possible implementation, the first access network device can further receive one or more of the non-access stratum count value, the authentication count value maintained by the core network device for the terminal, or the random number from the core network device, or receive first information from the core network device, the first information being used to indicate one or more of the non-access stratum count value, the authentication count value maintained by the core network device for the terminal, or the random number.

[0051] In a possible implementation, the first access network device stores one or more of the non-access stratum count value, the authentication count value maintained by the core network device for the terminal, or the random number in a case that a service link between the first access network device and the terminal is unavailable. In addition, the first access network device can send one or more of the non-access stratum count value, the authentication count value maintained by the core network device for the terminal, or the random number to the terminal in a case that the service link between the first access network device and the terminal is available, or send third information to the terminal, the third information being used to indicate one or more of the non-access stratum count value, the authentication count value maintained by the core network device for the terminal, or the random number. The third information can be determined according to at least one of the non-access stratum count value, the authentication count value, or the first information. As an example, the third information can comprise part bits of the non-access stratum count value, such as the last N5 bits, and / or the first information can comprise the last N6 bits of the authentication count value, N5 and N6 can be positive integers, and N5 and N6 can be the same or different, which are not specifically limited. The third information can be determined according to the count value from the core network device, or can be determined according to the first information from the core network device.

[0052] In a possible implementation, the first access network device can send a radio resource control (RRC) connection setup response message to the terminal, where the RRC connection setup response message includes one or more of the non-access stratum count value, the authentication count value maintained by the terminal and the core network device, or the random number; or the first access network device can send an RRC connection setup response message to the terminal, where the RRC connection setup response message includes the third information.

[0053] In a possible implementation, the first access network device can receive an RRC connection setup complete message from the terminal, where the RRC connection setup complete message includes the fifth authentication information.

[0054] In a possible implementation, the first access network device can send an RRC connection setup response message to the terminal, where the RRC connection setup response message includes the second authentication information.

[0055] In a possible implementation, the first access network device may also receive an RRC connection establishment request message from the terminal, the RRC connection establishment request message including seventh verification information, the seventh verification information being used to verify the terminal, the RRC connection establishment request message also including a fourth parameter or indication information of the fourth parameter, the fourth parameter including a non-access layer count value and / or a verification count value maintained by the terminal and the core network device, the seventh verification information being determined by the terminal based on the second shared key between the terminal and the core network device and the fourth parameter; the first access network device may also, when it is determined that the terminal has failed the verification based on the seventh verification information and the first verification information, or when it is determined that the fourth parameter is different from the first parameter provided by the core network device, further include the first parameter or the third information in the RRC connection establishment response message, the first verification information and / or the second verification information being determined by the core network device based on the first shared key and the first parameter, the first parameter including a non-access layer count value and / or a verification count value maintained by the terminal and the core network device. Based on this implementation method, the terminal can determine the seventh verification information based on the fourth parameter maintained by itself, and optionally determine the eighth verification information, and provide the seventh verification information and the fourth parameter (or indication information of the fourth parameter) to the access network device. If the first access network device determines that the terminal verification fails based on the seventh verification information and the first verification information, or the first access network device determines that the fourth parameter is different from the first parameter provided by the core network device, the first parameter can be provided to the terminal, such as sending the first parameter or sending the third information. In addition, if the first access network device determines that the terminal verification passes based on the seventh verification information and the first verification information, the second verification information can be provided to the terminal, and the terminal verifies the first access network device based on the second verification information and the eighth verification information. It can also be understood that the seventh verification information can be used as the fifth verification information, the eighth verification information can be used as the sixth verification information, or it can be understood that the fourth parameter is the same as the first parameter at this time.

[0056] In a possible implementation manner, the first access network device may receive an RRC connection establishment request message from the terminal, where the RRC connection establishment request message includes the fifth verification information.

[0057] In a possible implementation, after determining that the terminal passes the verification according to the comparison result, the first access network device may send an RRC connection establishment response message to the terminal, where the RRC connection establishment response message includes the second verification information.

[0058] In a possible implementation, the receiving the first verification information and / or the second verification information from the core network device includes:

[0059] receiving a first message from the core network device, the first message comprising an identity of the terminal, and comprising the first authentication information and / or the second authentication information; the receiving the fifth authentication information from the terminal comprises: receiving a second message from the core network device, the second message comprising the fifth authentication information, the second message further comprising the identity of the terminal.

[0060] In a possible implementation, the identity of the terminal comprises at least one of: the identity of the terminal allocated by the access network; the identity of the terminal allocated by the core network; an identity determined or generated according to the identity (such as terminal identity) allocated by the core network; a second identity of the terminal, the second identity being determined according to the identity of the terminal allocated by the access network and the identity of the first access network device. The identity determined according to the identity allocated by the core network comprises a first identity of the terminal, the first identity being determined according to the identity of the terminal allocated by the core network and the identity of the first access network device.

[0061] It can be understood that, for the first access network device, the first identity of the terminal can be obtained according to the identity allocated by the core network. For example, the processing of the identity allocated by the core network by the first access network device comprises truncation processing, etc., and the first access network device can store the correspondence between the identities of the terminal before and after the processing, for determining the identities of the terminal before and after the processing. For another example, the core network device can obtain the first identity of the terminal according to the identity allocated by the core network and the identity of the first access network device.

[0062] In a possible implementation, the first access network device can receive first time information from the core network device in a case that a feeder link between the first access network device and the core network device is available, the first time information being used to indicate the valid time of the first authentication information and / or the valid time of the second authentication information; the first access network device can send the first time information to the terminal in a case that a service link between the first access network device and the terminal is available.

[0063] In a possible implementation, the receiving the first authentication information and / or the second authentication information from the core network device comprises: receiving an N2 message from the core network device, the N2 message comprising the first authentication information and / or the second authentication information.

[0064] In a possible implementation, the N2 message further comprises a first NAS message.

[0065] In a possible implementation, the first NAS message is sent to the terminal in a case that a service link between the first access network device and the terminal is available.

[0066] In a possible implementation, the first access network device further receives a second NAS message from the terminal in a case that a service link between the first access network device and the terminal is available. The second NAS message is an uplink NAS message.

[0067] The beneficial effects of the above second aspect and each possible implementation thereof can refer to the description of the beneficial effects of the first aspect and the corresponding implementation, and will not be repeated here.

[0068] In a third aspect, a communication method is provided. The method can be implemented by a third communication apparatus. The third communication apparatus can be a terminal or a component in the terminal. Taking the terminal as an execution subject for example, the method can be implemented by the following steps: receiving, by the terminal, second authentication information from a first access network device in a case that a service link between the first access network device and the terminal is available, the second authentication information being determined by a core network device according to a first shared key between the terminal and the core network device, and the second authentication information being used to authenticate the first access network device; obtaining, by the terminal, sixth authentication information, the sixth authentication information being determined by the terminal according to a second shared key between the terminal and the core network device, and the sixth authentication information being used to authenticate the first access network device; and sending, by the terminal, a NAS message to the first access network device in a case that the first access network device is determined to pass authentication according to the second authentication information and the sixth authentication information.

[0069] In a possible implementation, the terminal further sends fifth authentication information to the first access network device in a case that a service link between the first access network device and the terminal is available, the fifth authentication information being determined by the terminal according to the second shared key between the terminal and the core network device, and the fifth authentication information being used to authenticate the terminal.

[0070] In a possible implementation, the terminal further determines the fifth authentication information and the sixth authentication information according to the second shared key, the fifth authentication information being used to authenticate the terminal.

[0071] In a possible implementation, the terminal determines the fifth authentication information and the sixth authentication information according to the second shared key, an identifier of the first access network device, and a third parameter, the third parameter including at least one of the following: a non-access stratum count value; an authentication count value maintained by the terminal and the core network device; a random number.

[0072] In a possible implementation, the terminal can further receive one or more of the non-access stratum count value, the authentication count value maintained by the terminal and the core network device, or the random number from the first access network device in a case that a service link between the first access network device and the terminal is available; or the terminal can further receive third information from the first access network device in a case that a service link between the first access network device and the terminal is available, where the third information is used to indicate one or more of the non-access stratum count value, the authentication count value maintained by the terminal and the core network device, or the random number.

[0073] In a possible implementation, the terminal can receive an RRC connection setup response message from the first access network device, where the RRC connection setup response message includes one or more of the non-access stratum count value, the authentication count value maintained by the terminal and the core network device, or the random number; or the terminal can receive an RRC connection setup response message from the first access network device, where the RRC connection setup response message includes the third information.

[0074] In a possible implementation, the terminal can send an RRC connection setup complete message to the first access network device after determining that the first access network device passes the verification according to the comparison result, where the RRC connection setup complete message includes the fifth authentication information.

[0075] In a possible implementation, the terminal can receive an RRC connection setup response message from the first access network device, where the RRC connection setup response message includes the second authentication information.

[0076] In a possible implementation, the terminal can further send an RRC connection setup request message to the first access network device, where the RRC connection setup request message can include seventh authentication information and can further include a fourth parameter or indication information of the fourth parameter, the seventh authentication information being determined by the terminal according to a second shared key of the terminal and the core network device and the fourth parameter, and the fourth parameter including a non-access stratum count value and / or an authentication count value maintained by the terminal and the core network device; and the terminal can further receive an RRC connection setup response message from the first access network device, where the RRC connection setup response message further includes a first parameter or third information used to notify or indicate the first parameter, and the first authentication information and / or the second authentication information are determined by the core network device according to the first shared key and the first parameter, and the first parameter includes a non-access stratum count value and / or an authentication count value maintained by the terminal and the core network device, or the first parameter includes a non-access stratum count value and / or an authentication count value maintained by the terminal and the core network device.

[0077] In a possible implementation manner, the terminal may send an RRC connection establishment request message to the first access network device, where the RRC connection establishment request message includes the fifth verification information.

[0078] In a possible implementation manner, the terminal may receive an RRC connection establishment response message from the first access network device, where the RRC connection establishment response message includes the second verification information.

[0079] In a possible implementation, the terminal may send a second message to the first access network device, where the second message includes the fifth verification information and an identifier of the terminal.

[0080] In one possible implementation, the terminal identifier includes at least one of the following: an identifier of the terminal assigned by the access network; an identifier of the terminal assigned by the core network; an identifier determined or generated based on the identifier assigned by the core network (such as a terminal identifier); a second identifier of the terminal, the second identifier being determined based on the identifier of the terminal assigned by the access network and the identifier of the first access network device. The identifier determined based on the identifier assigned by the core network includes the first identifier of the terminal, the first identifier being determined based on the identifier of the terminal assigned by the core network and the identifier of the first access network device.

[0081] For example, the identifier determined based on the identifier of the terminal assigned by the core network may be an identifier obtained by the first access network device performing a truncation or other processing on the identifier assigned by the core network. For another example, the identifier determined based on the identifier of the terminal assigned by the core network may be the first identifier of the terminal obtained by the core network device by processing the identifier assigned by the core network and the identifier of the first access network device.

[0082] In one possible implementation, the terminal may also receive first time information from the first access network device when the service link between the first access network device and the terminal is available, where the first time information is used to indicate the validity time of the first verification information and / or the validity time of the second verification information.

[0083] In a possible implementation, the terminal may further receive a first NAS message from the first access network device when a service link between the first access network device and the terminal is available. The first NAS message is a downlink NAS message.

[0084] In a possible implementation, the terminal may further send a second NAS message to the first access network device when a service link between the first access network device and the terminal is available. The second NAS message is an uplink NAS message.

[0085] The advantages of the third aspect and its possible implementation manners can be referred to the description of the advantages of the first aspect or the second aspect and their corresponding implementation manners, and will not be repeated here.

[0086] In a fourth aspect, a communication apparatus is provided. The apparatus can implement the method described in any of the first aspect to the third aspect and any of their possible implementation manners. The apparatus has the functions of the first communication apparatus, the second communication apparatus, or the third communication apparatus. The apparatus is, for example, a terminal device, or a functional module in a terminal device, or a network device or a functional module in a network device, etc.

[0087] In an optional implementation, the apparatus can include a module corresponding to each of the methods / operations / steps / actions described in any of the first aspect to the third aspect and any of their possible implementation manners. The module can be a hardware circuit, or software, or a combination of hardware circuit and software. In an optional implementation, the apparatus includes a processing unit (sometimes also referred to as a processing module) and a communication unit (sometimes also referred to as a transceiving module, a communication module, etc.). The transceiving unit can implement a sending function and a receiving function. When the transceiving unit implements the sending function, it can be referred to as a sending unit (sometimes also referred to as a sending module). When the transceiving unit implements the receiving function, it can be referred to as a receiving unit (sometimes also referred to as a receiving module). The sending unit and the receiving unit can be the same functional module, which is referred to as a transceiving unit and can implement the sending function and the receiving function. Alternatively, the sending unit and the receiving unit can be different functional modules, and the transceiving unit is a general term for these functional modules.

[0088] For example, when the apparatus is used to execute the method described in any of the first aspect to the third aspect, the apparatus can include a communication unit and a processing unit.

[0089] In a fifth aspect, the embodiments of the present disclosure also provide a communication apparatus, including a processor configured to execute a computer program (or computer executable instructions) stored in a memory, when the computer program (or computer executable instructions) is executed, causing the apparatus to perform the method described in any of the first aspect to the third aspect and any of their possible implementation manners.

[0090] In a possible implementation, the processor and the memory are integrated together.

[0091] In another possible implementation, the memory is located outside the communication apparatus.

[0092] The communication device also includes a communication interface for the communication device to communicate with other devices, such as transmitting or receiving data and / or signals. Exemplarily, the communication interface can be a transceiver, a circuit, a bus, a module, or other types of communication interfaces.

[0093] In a sixth aspect, a computer readable storage medium is provided for storing a computer program or instructions which, when executed, cause the method of any of the first aspect to the third aspect and any possible implementation thereof, and the method as shown in any possible implementation thereof, to be implemented.

[0094] In a seventh aspect, a computer program product containing instructions which, when executed on a computer, cause the method of any of the first aspect to the third aspect and any possible implementation thereof to be implemented.

[0095] In an eighth aspect, the embodiments of the present application also provide a communication device for executing the method of any of the first aspect to the third aspect and any possible implementation thereof.

[0096] In a ninth aspect, a chip system is provided, which includes a logic circuit (or it is understood that the chip system includes a processor, which can include a logic circuit, etc.), and can also include an input / output interface. The input / output interface can be used for inputting messages, and can also be used for outputting messages. The input / output interface can be the same interface, that is, the same interface can realize both the sending function and the receiving function; or the input / output interface includes an input interface and an output interface, the input interface is used to realize the receiving function, that is, to receive messages; the output interface is used to realize the sending function, that is, to send messages. The logic circuit can be used to perform operations other than the transceiving function in the method of any of the first aspect to the third aspect and any possible implementation thereof; the logic circuit can also be used to transmit messages to the input / output interface, or receive messages from other communication devices from the input / output interface. The chip system can be used to implement the method of any of the first aspect to the third aspect and any possible implementation thereof. The chip system can be composed of a chip, or can include a chip and other discrete devices.

[0097] Optionally, the chip system can also include a memory, which can be used to store instructions, and the logic circuit can call the instructions stored in the memory to realize corresponding functions.

[0098] In a tenth aspect, a communication method is provided. The communication method can include the method implemented by the first communication device of the first aspect and any possible implementation thereof, the method implemented by the second communication device of the second aspect and any possible implementation thereof. Optionally, the communication method can further include the method implemented by the third communication device of the third aspect and any possible implementation thereof.

[0099] In an eleventh aspect, a communication system is provided. The communication system can include a first communication device and a second communication device. Optionally, the communication system can further include a third communication device. The first communication device can be configured to implement the method of the first aspect and any possible implementation thereof, the second communication device can be configured to implement the method of the second aspect and any possible implementation thereof, and the third communication device can be configured to implement the method of the third aspect and any possible implementation thereof.

[0100] The technical effects brought by the fourth aspect to the eleventh aspect above can be referred to the description of the beneficial effects of the corresponding solutions in the first aspect to the third aspect above, which will not be repeated here. BRIEF DESCRIPTION OF DRAWINGS

[0101] FIG. 1A is a schematic diagram of an architecture of a wireless communication system;

[0102] FIG. 1B is a schematic diagram of an architecture of an NTN system;

[0103] FIG. 1C is a schematic diagram of an architecture of a 5G wireless communication system;

[0104] FIG. 1D is a schematic diagram of an architecture of a non-continuous feeding scenario;

[0105] FIG. 2A is a schematic diagram of a terminal attachment process in a non-continuous feeding scenario;

[0106] FIG. 2B is a schematic diagram of a downlink data transmission process in a non-continuous feeding scenario;

[0107] FIG. 2C is a schematic diagram of an uplink data transmission process in a non-continuous feeding scenario;

[0108] FIG. 2D is a schematic diagram of a terminal and base station verification process;

[0109] FIG. 2E is a schematic diagram of a verification information generation method;

[0110] FIG. 3 is a schematic diagram of a communication method according to an embodiment of the present application;

[0111] FIG. 4 is a schematic diagram of a verification information generation method according to an embodiment of the present application;

[0112] FIG. 5 is a schematic diagram of another communication method according to an embodiment of the present application;

[0113] FIG. 6 is a flow diagram of another communication method according to an embodiment of the present application;

[0114] FIG. 7 is a flow diagram of another communication method according to an embodiment of the present application;

[0115] FIG. 8 is a flow diagram of another communication method according to an embodiment of the present application;

[0116] FIG. 9 is a flow diagram of another communication method according to an embodiment of the present application;

[0117] FIG. 10 is a flow diagram of another communication method according to an embodiment of the present application;

[0118] FIG. 11 is a flow diagram of another communication method according to an embodiment of the present application;

[0119] FIG. 12 is a flow diagram of another communication method according to an embodiment of the present application;

[0120] FIG. 13 is a schematic diagram of a communication apparatus according to an embodiment of the present application;

[0121] FIG. 14 is a schematic diagram of another communication apparatus according to an embodiment of the present application. DETAILED DESCRIPTION

[0122] The method provided by the embodiments of the present application can be applied to an NTN communication scenario. In the NTN communication scenario, non-ground access network devices such as unmanned aerial vehicles, high altitude platform stations (HAPS), satellites, etc. can provide data transmission, voice communication and other services for terminals. In the following, a satellite base station is mainly described, but this does not mean that it is limited to this. In addition, the NTN system can also include other non-ground access network devices, which are not limited by the present application. The NTN communication scenario can also support various mobile communication systems, such as new radio (NR) systems, long term evolution (LTE) systems or future communication systems and other communication systems, which are not limited here.

[0123] The method provided by the embodiments of the present application can be applied to at least one of the following: a fourth generation (4th generation, 4G) communication system (for example, an LTE system), a fifth generation (5th generation, 5G) communication system (for example, an NR system), or various communication systems in the future (for example, a sixth generation (6th generation, 6G) communication system). The communication method provided by the embodiments of the present application can also be applied to the fields of vehicle to everything (V2X) communication, Internet of Vehicles, autonomous driving or assisted driving, etc.

[0124] The present application will present various aspects, embodiments or features around a system including a plurality of devices, components, modules, etc. It should be understood and appreciated that each system can include additional devices, components, modules, etc., and / or can not include all of the devices, components, modules, etc. discussed in conjunction with the attached drawings. In addition, combinations of these schemes can also be used.

[0125] For ease of understanding, first, a communication system to which the embodiments of the present application can be applied is described.

[0126] FIG. 1A is a schematic diagram of a communication system to which the embodiments of the present application can be applied. As shown in FIG. 1A, the communication system can include at least one access network device (such as 110a, 110b, 110c in FIG. 1A), and can also include at least one terminal (such as 120a-120g in FIG. 1A). Among them, the terminal can be mobile or fixed. Each access network device can provide communication coverage for a specific geographic area, and can communicate with terminals located in the coverage area. The access network device and the access network device, the access network device and the terminal, and the terminal and the terminal can be connected to each other by wire or wirelessly. FIG. 1A is only a schematic diagram, and the communication system can also include other devices, such as wireless relay devices and wireless backhaul devices, etc.

[0127] The embodiments of the present application can be applied to a communication system in which a terrestrial communication system and a satellite communication system are fused, which can also be referred to as an NTN communication system.

[0128] Among them, the terrestrial communication system can be, for example, an LTE system, a 5G communication system, or various communication systems in the future (for example, a 6G communication system), etc., which is not limited here.

[0129] Among them, the satellite communication system has a wider coverage range than the traditional communication system, and can overcome natural geographical obstacles such as oceans, deserts, and mountains. In order to overcome the shortcomings of the traditional communication system, the satellite communication system can be an effective supplement to the traditional communication system. According to the different orbital heights, the satellite communication system can be divided into the following three kinds: high-orbit (geostationary earth orbit, GEO) satellite communication system, medium-orbit (medium earth orbit, MEO) satellite communication system, and low-orbit (low earth orbit, LEO) satellite communication system. The GEO satellite communication system can also be called the synchronous orbit satellite system. It is generally considered that, compared with terrestrial communication, NTN has different channel characteristics (for example, large transmission delay, large Doppler frequency offset, etc.). Exemplarily, the round-trip delay of the GEO satellite communication system is 238-270 milliseconds (ms), and the round-trip delay of the LEO satellite communication system is 8-20 ms.

[0130] The working mode of the satellite can be divided into a transparent mode and a regenerative mode. When the satellite works in the transparent mode, the satellite has the function of relay forwarding. The gateway station has part or all of the functions of the base station, and at this time the gateway station can be regarded as the base station. Or the base station is independently deployed and has a wired connection with the gateway station. Among them, the gateway station can also be called the gateway station. When the satellite works in the regenerative mode, the satellite has data processing capability and has part or all of the functions of the base station, and at this time the satellite can be regarded as the base station.

[0131] FIG. 1B is a schematic diagram of an NTN in a regenerative mode. As shown in FIG. 1B, the satellite has part or all of the functions of a base station, which can be referred to as a satellite base station, and the satellite base station can provide a wireless access service and schedule wireless resources for terminals accessing the network through the satellite base station. The satellite base station and the terminals can communicate through a user-universal terrestrial radio access network (Uu) interface. The satellite base station and the core network (CN) can communicate through a next generation (NG) interface, and the satellite base station and the core network can exchange NAS signaling between the terminals and the core network and service data of the user through the NG interface. The satellite radio interface (SRI) is a feeder link (or feeder connection or feed connection, etc.) between the NTN gateway and the satellite, and the NTN gateway can also be referred to as a gateway, which can support a connection with the CN. In addition, the link between the satellite base station and the terminals is referred to as a service link (or service connection). The terminals can include Internet of Things terminals, mobile phone terminals, high-altitude aircraft, and the like, and the terminals can also be other forms and performance terminals, etc., which are not limited here. In FIG. 1B, the SRI interface can be used as part of the next generation (NG) interface to realize communication interaction between the satellite base station and the core network. The satellite base station is, for example, 110a shown in FIG. 1A. It should be noted that the embodiments of the present application can also be applied to other satellite communication scenarios based on FIG. 1B.

[0132] As an example, the NTN network can be implemented in combination with an architecture of the 5th generation system (5GS). For example, the access network device in the 5GS architecture can be a satellite base station in the NTN network, or in other words, the satellite base station implements the function of the access network device in the 5GS architecture. In addition, it can also be said that the terminal can access the 5GS through the satellite base station in the NTN network. FIG. 1C shows an example of a possible 5GS architecture. The architecture of the system can include: a terminal device, a (radio) access network ((R)AN), and a core network. For example, in the architecture of the communication system, the access network device can be included in the radio access network. The core network can include: a network exposure function (NEF) network element, a unified data management (UDM) network element, an application function (AF) network element, an access and mobility management function (AMF) network element, a session management function (SMF) network element, and a user plane function (UPF) network element. Among them, the AMF network element and the access network device can be connected through the N2 interface, the access network device and the UPF can be connected through the N3 interface, the SMF and the UPF can be connected through the N4 interface, the AMF network element and the UE can be connected through the N1 interface, and the UPF can be connected with the DN through the N6 interface. The interface name is only an example, and the embodiments of the present application are not limited to this. It should be understood that the embodiments of the present application are not limited to the communication system shown in FIG. 1C, and the names of the network elements shown in FIG. 1C are only an example and do not limit the network elements included in the communication system architecture to which the methods of the present application are applicable. The functions of each network element or device in the communication system are described in detail below:

[0133] The terminal device, which can be referred to as a terminal, can also be referred to as a UE, a mobile station (MS), a mobile terminal (MT), or the like, or a device for providing voice or data connectivity to a user, or an Internet of Things device. For example, the terminal device includes a handheld device having a wireless connection function, a vehicle-mounted device, and the like. At present, the terminal device can be a mobile phone, a tablet computer, a notebook computer, a palm computer, a mobile Internet device (MID), a wearable device (for example, a smart watch, a smart bracelet, a pedometer, and the like), a vehicle-mounted device (for example, a car, a bicycle, an electric vehicle, an airplane, a ship, a train, a high-speed rail, and the like), a virtual reality (VR) device, an augmented reality (AR) device, a smart point of sale (POS) machine, a customer-premises equipment (CPE), a wireless terminal in industrial control, a smart home device (for example, a refrigerator, a television, an air conditioner, an electricity meter, and the like), a smart robot, a mechanical arm, a workshop device, a wireless terminal in unmanned driving, a wireless terminal in telemedicine, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, or a wireless terminal in a smart home, a flight device (for example, a smart robot, a hot air balloon, a drone, an airplane), and the like. The terminal device can also be other devices having a terminal function, for example, the terminal device can also be a device assuming a terminal function in D2D communication. In this application, the terminal device having a wireless transceiver function and the chip that can be provided in the terminal device are collectively referred to as a terminal device. The embodiments of the present application do not limit the device form of the terminal.

[0134] (R)AN device: access network device, device providing access for terminal device, including radio access network (AN) device and access network (AN) device. The RAN device is mainly the wireless network device of the 3GPP network, and the AN can be the access network device defined by non-3GPP. The RAN device is mainly responsible for the functions of wireless resource management, quality of service (QoS) management, data compression and encryption, and the like on the air interface side. In systems using different wireless access technologies, the name of the device with the function of a base station may be different, for example, in a 5G system, it is called a RAN or a next generation NodeB (gNB / 5G NodeB) in 5G, and the like. For the NTN scenario, the access network device can be a satellite base station or a non-ground access network device in the form of a non-ground access network device, and the like, which is not specifically limited.

[0135] In a possible scenario, the (R)AN device can be a base station, an evolved NodeB (eNodeB) in 4G, an access point (AP), a transmission reception point (TRP), an evolutional nodeB (eNB or eNodeB) in an LTE system, a gNB in a 5G system, a base station in a 6th generation (6G) mobile communication system, a base station in a future mobile communication system, a satellite, or an access node in a WiFi system, etc. The network device can be a macro base station, a micro base station or an indoor station, a relay node or a donor node, or a wireless controller in a CRAN scenario. The (R)AN device can also be a device that plays a base station function in device to device (D2D) communication, vehicle networking communication, machine communication. Optionally, the (R)AN device can also be a server, a wearable device, a vehicle or a vehicle-mounted device, etc. For example, the access network device in vehicle to everything (V2X) technology can be a road side unit (RSU). The (R)AN device can also be a network device in an open access network (open RAN, O-RAN or ORAN) system.

[0136] In another possible scenario, a terminal is assisted by multiple (R)AN devices to implement wireless access in cooperation, and different (R)AN devices respectively implement part of functions of a base station. For example, the (R)AN device can be a central unit (CU), a distributed unit (DU), a CU-control plane (CP), a CU-user plane (UP), or a radio unit (RU), etc. The CU and the DU can be separately arranged, or can be included in the same network element, such as a baseband unit (BBU). The RU can be included in a radio frequency device or a radio frequency unit, such as a remote radio unit (RRU), an active antenna processing unit (AAU), or a remote radio head (RRH). It can be understood that the (R)AN device can be a CU node, or a DU node, or a device including a CU node and a DU node. In addition, the CU can be divided into a network device in the access network RAN, or the CU can be divided into a network device in the core network CN, which is not limited here.

[0137] For example, in an open access network system, the CU can also be referred to as an open CU (O-CU), the DU can also be referred to as an O-DU, the CU-CP can also be referred to as an O-CU-CP, the CU-UP can also be referred to as an O-CU-UP, and the RU can also be referred to as an O-RU. For the convenience of description, the CU, the CU-CP, the CU-UP, the DU, and the RU are taken as examples for description in this application. Any one of the CU (or the CU-CP, the CU-UP), the DU, and the RU in this application can be implemented by a software module, a hardware module, or a combination of a software module and a hardware module.

[0138] In different systems, the CU (or the CU-CP and the CU-UP), the DU, or the RU can also have different names, but those skilled in the art can understand their meanings. For example, in an ORAN system, the CU can also be referred to as an O-CU (open CU), the DU can also be referred to as an O-DU, the CU-CP can also be referred to as an O-CU-CP, the CU-UP can also be referred to as an O-CU-UP, and the RU can also be referred to as an O-RU. For the convenience of description, the CU, the CU-CP, the CU-UP, the DU, and the RU are taken as examples for description in this application. Any one of the CU (or the CU-CP, the CU-UP), the DU, and the RU in this application can be implemented by a software module, a hardware module, or a combination of a software module and a hardware module.

[0139] In addition, the access and mobility management function network element can be used for access control and mobility management of the terminal device. In actual application, it includes the mobility management function in the mobility management entity (MME) in the network framework in long term evolution (LTE), and adds an access management function. Specifically, it can be responsible for terminal device registration, mobility management, tracking area update process, reachability detection, session management function network element selection, mobile state conversion management, etc. For example, in 5G, the access and mobility management function network element can be an AMF network element, as shown in FIG. 1C; in future communication, such as 6G, the access and mobility management function network element can still be an AMF network element, or have other names, which are not limited by the present application. When the access and mobility management function network element is an AMF network element, the AMF can provide the Namf service.

[0140] In addition, the present application does not exclude the combination of 4G network architecture and NTN architecture, for example, the terminal accesses the 4G network through the satellite base station in the NTN network.

[0141] Hereinafter, for the convenience of description, the satellite base station and the like can be simply referred to as a base station. That is, except for special description, the base station in the following can be understood as a satellite base station in a regenerative mode, or a base station in a feeder discontinuous scenario.

[0142] In the NTN scenario, there is a feeder discontinuous scenario in the regenerative repeater satellite architecture. In this scenario, the service link between the terminal and the base station and / or the feeder link between the base station and the core network is not available at all times. For example, as shown in FIG. 1D, as the position of the satellite changes, at some times, the service link is available and the feeder link is not available, at other times, the service link is not available and the feeder link is available, and at other times, both the service link and the feeder link are not available. Among them, the satellite in the regenerative repeater satellite architecture supports processing of received signals, including demodulation, decoding, encoding, modulation, and information processing, etc., that is, the satellite has the functions of all access network devices (such as gNB or eNB, etc.). In the present application, the feeder discontinuous scenario can also be described as a store-and-forward scenario of the satellite, a feeder discontinuous state, or a scenario accessed by a feeder discontinuous access network device, which can be replaced with each other.

[0143] Specifically, when the terminal accesses the regenerative repeater satellite, if the feeder link is unavailable, the base station needs to store the uplink information from the terminal, and when the feeder link is available, the base station forwards the stored uplink information to the core network. For downlink, the ground core network sends downlink information to the regenerative repeater satellite, and if the service link is unavailable at this time, the regenerative repeater satellite needs to store the downlink information from the ground core network, and when the service link between the terminal and the base station is available, the base station forwards the stored downlink information to the terminal. The working mode of the base station in this scenario can be referred to as the S&F satellite operation mode.

[0144] In the S&F satellite operation mode, the operation mode in which the service satellite provides communication services (stores and forwards information) to the terminal in a time period and / or a geographical area in which the service satellite is not connected to the ground network through the feeder link or the inter-satellite link (ISL). For uplink, storage refers to on-board storage of uplink information from the terminal, and forwarding refers to forwarding the stored uplink information to the ground network. For downlink, storage refers to on-board storage of downlink information from the ground network, and forwarding refers to forwarding the stored downlink information to the terminal.

[0145] In the S&F satellite operation mode, the operation mode in which the service satellite provides communication services (stores and forwards information) to the terminal in a time period and / or a geographical area in which the service satellite is not connected to the ground network through the feeder link or the inter-satellite link (ISL). For uplink, storage refers to on-board storage of uplink information from the terminal, and forwarding refers to forwarding the stored uplink information to the ground network. For downlink, storage refers to on-board storage of downlink information from the ground network, and forwarding refers to forwarding the stored downlink information to the terminal.

[0146] In the feeder discontinuous scenario, if the service link between the terminal and the base station changes from unavailable to available, the RRC connection needs to be established between the terminal and the access network device, and the establishment of the RRC connection can occur after the terminal is registered (or attached) in the core network (such as MME or AMF).

[0147] As shown in FIG. 2A, taking eNB as the base station and MME as the core network device as an example, the attachment process of the terminal in the feeder discontinuous scenario is introduced. FIG. 2A can include the following steps:

[0148] S1: When the service link is available, the terminal establishes an RRC connection with the base station, and the terminal sends an RRC message containing an attachment request to the eNB.

[0149] The timeout time of the NAS message should be adjusted to the time of the S&F scenario (for example, several hours).

[0150] S2: The base station providing the service link (source base station) can select a target base station, which can be used for the terminal to continue the process and exchange subsequent NAS messages. The base station (or source base station) selects the next base station based on the ephemeris and the terminal location.

[0151] It can be understood that the source base station can select itself as the target base station.

[0152] When only a single base station in the satellite constellation can provide a service link to the terminal, the base station (or source base station) always selects itself as the target base station.

[0153] After selecting the target base station, the base station (or source base station) determines a next access timer for the terminal, indicating when the target base station provides a service link for the terminal.

[0154] S3: The base station provides the next access timer to the terminal. Before the next access timer expires, the terminal can stop monitoring broadcast and paging messages to start a power saving function.

[0155] S4-a: The terminal stores a terminal context. The terminal context includes at least an identity of the terminal performing the attach procedure. The identity of the terminal is, for example, a combination of a cell-radio network temporary identifier (C-RNTI) and a global base station identity. The global base station identity is, for example, used to uniquely identify a base station globally. The terminal context can be used to resume an RRC connection between the base station providing the service link and the terminal.

[0156] S4-b: The base station stores the terminal context, the uplink NAS message (i.e. the attach request) and a terminal location information (ULI). The ULI can be generated by the base station when the terminal performs a random access (RA) (or RA over random access channel (RACH)) procedure to create or resume a connection. The connection is created or resumed, for example, by sending the uplink NAS message, such as an attach request.

[0157] Details of the terminal context used to resume the connection will be determined by the base station.

[0158] S5: When the feeder link is available, the base station sends the uplink NAS message (i.e. the attach request) and related information to the MME. The related information includes, for example, the terminal location information, the terminal context and an identity of the target base station, as described in 3GPP technical specification (TS) 23.401 clause 5.3.2.1.

[0159] S6: The MME interacts with the core evolved packet core (EPC) network element, processes the uplink NAS message received from the terminal, and performs process handling. For example, for the attach process, the MME interacts with the home subscriber server (HSS) to perform authentication, and the HSS can be one of the EPC network elements.

[0160] S7: When the feeder link of the target base station is available, the MME sends the downlink NAS message to the target base station. The MME should also start a specific NAS timer applicable to S&F, for example, considering the delay of the S&F operation.

[0161] For the case of multiple base stations, the terminal context and the terminal location information can also be included in the S1AP message containing the downlink NAS message sent by the MME to the target base station. The location information of the terminal can be used by the target base station to page the terminal.

[0162] S8: When the service link of the target base station is available (i.e., the next access timer stored in the terminal expires and the target base station is available for the terminal), the target base station pages the terminal, triggers the RRC connection resume based on the identifier of the terminal stored in the terminal context, and resumes the RRC connection between the terminal and the target base station.

[0163] S9: For the next uplink NAS message in the process, steps S1-S4 are repeated. S4 can include S4-a and S4-b.

[0164] S10: When the feeder link of the uplink NAS message source base station is available, steps S5 and S6 are repeated.

[0165] S11: When the feeder link is available to the target base station, steps S7 are repeated for the next downlink NAS message.

[0166] Steps S8-S11 are iterated as many times as required by the process. In the case of the attach process, in the subsequent step of one iteration, the MME will request the serving gateway (SGW) to create a session, and after further iterations, the process will terminate.

[0167] Still taking the same 4G as an example, after the attachment, the terminal performs the transmission process of the NAS message in the feeder discontinuous scenario, which can refer to FIGS. 2B and 2C. FIG. 2B shows a downlink NAS message transmission scenario, and FIG. 2C shows an uplink NAS message transmission scenario.

[0168] FIG. 2B can include the following steps:

[0169] S1: When the SGW receives downlink data, it forwards the data to the MME. The downlink data can come from a packet data network (PDN) gateway (PGW).

[0170] Wherein, as described in steps 1, 2 and 7-11 of clause 5.3.4B.3 of 3GPP TS 23.401 [5], it can be assumed that the radio access technology (RAT) type has not changed compared with the last access.

[0171] S2: The MME determines that the terminal is working in the S&F mode (for example, based on the subscription data and its attachment mode), and selects a base station that is most suitable for transmitting a downlink NAS packet data unit (PDU) containing the downlink data. The MME can determine the base station according to factors such as ephemeris information, location information of the terminal, or whether the base station is in the S&F monitoring list, etc.

[0172] According to step 12 of clause 5.3.4B.3 of 3GPP TS 23.401 [5], the MME can prepare the downlink NAS PDU for sending to the terminal, for example, performing encryption and integrity protection on the NAS PDU, or performing internet protocol (IP) header compression, etc.

[0173] S3: When the feeder link between the selected base station and the MME is available, the MME sends the downlink NAS PDU to the selected base station.

[0174] S4: When the service link between the selected base station and the terminal is available, and after the RRC connection with the terminal is established, the base station sends the downlink NAS PDU to the terminal.

[0175] S5: If the base station determines that all the downlink data stored for the terminal has been delivered, the base station can release the RRC connection and send a sleep indication to the terminal, which informs the terminal that it will not be paged by the base station for the remaining time during which the current base station provides coverage.

[0176] S6: During the remaining time during which the current base station provides coverage, the terminal can stop monitoring paging.

[0177] S7: When the feeder link is available, the base station sends a NAS delivery indication to the MME upon request, as described in step 15 of clause 5.3.4B.3 of 3GPP TS 23.401 [5].

[0178] Figure 2C can include the following steps:

[0179] S1: The UE establishes an RRC connection with the base station existing in the S&F monitoring list, and sends an uplink NAS PDU containing uplink data. S1 is similar to step 1 of clause 5.3.4B.2 of 3GPP TS 23.401 [5], which can be referred to for implementation.

[0180] S2: The base station stores the uplink NAS PDU due to the disconnection of the feeder link.

[0181] In addition, the base station can release the RRC connection, and can send a sleep indicator to the terminal, which informs the terminal that it will not be paged by the base station within the remaining time in which the base station provides coverage.

[0182] S3: When the feeder link is available, the NAS PDU sent in S1 is sent to the MME.

[0183] S4: According to step 3 of clause 5.3.4B.2 of 3GPP TS 23.401, the uplink NAS PDU is integrity-verified and decrypted, and any header decompression is applied as needed.

[0184] S5: According to steps 4 to 8 of clause 5.3.4B.2 of TS 23.401, the uplink data is sent to the PGW through the SGW.

[0185] S6: Send downlink NAS message or perform data delivery. Among them, if there is downlink data to be sent to the terminal, the process in FIG. 2B can be performed.

[0186] Currently, for the scenario of using control plane to transmit user plane data, that is, using NAS message to transmit data packets between core network elements and terminals, the data packets are protected using the keys of the NAS layer. Its protection mode includes encryption protection and integrity protection. For terminals in connected state, no AS security is established between the terminal and the access network device, that is, no security key for protecting the information of the AS is established between the terminal and the access network device, and the RRC message is transmitted in plaintext between the terminal and the access network device.

[0187] However, when the base station sends downlink control plane data to the terminal, since the connection between the terminal and the base station is established later, the base station cannot guarantee that the accessed terminal is legitimate, which may cause the base station to send data packets to malicious terminals, thereby causing legitimate terminals to be unable to obtain data packets.

[0188] In addition, in the scenario that the terminal uses the optimized control plane transmission data, when the radio link of the terminal fails, the AS layer of the terminal can trigger the RRC connection reestablishment process. At this time, since there is no AS layer security, the RRC connection reestablishment process cannot be performed based on the security key of the AS. In order to protect the reestablishment process, the AS layer of the terminal will provide the uplink NAS message authentication code (MAC) (denoted as UL_NAS_MAC) and the downlink NAS message authentication code (denoted as XDL_NAS_MAC), which is used to ensure that the terminal is connected to the real network. As shown in FIG. 2D, the security protection process can include the following steps:

[0189] S0: The terminal determines that the radio link fails.

[0190] S1: The terminal generates UL_NAS_MAC and XDL_NAS_MAC. The specific generation method is shown in FIG. 2E. Among them, the Message can be used to represent the information value (message), which can be set as the target cell identifier; the COUNT can be used to represent the count value (counter), which can be set as the evaluated uplink NAS counter value, referred to as the NAS counter value; the Direction can be used to represent the direction value (direction), which can be set as 0; the Key represents the shared key (key), for example, using KNASint; the BEARER represents the bearer value (bearer), which can include 5 bits, for example, which can be set as 0x01. The algorithm uses the integrity protection algorithm selected in the NAS security protection. The generated MAC length is 32 bits, of which the high 16 bits form UL_NAS_MAC, and the low 16 bits form XDL_NAS_MAC.

[0191] S2: The terminal sends the RRC connection establishment request (RRCConnectionRestablishmentRequest) message to the base station, which includes the temporary mobile subscription identifier (S-TMSI), UL_NAS_MAC, and the low 5-bit value of the NAS counter value.

[0192] S3: The base station sends the CP relocation indication message to the MME, which can include the S-TMSI, UL_NAS_MAC, the low 5 bits of the NAS counter value, and the target cell identifier, which is the identifier of the cell currently accessed by the terminal.

[0193] The MME acquires KNASint in the context of the terminal according to the S-TMSI, and uses KNASint and parameters such as the received target cell identifier, NAS counter value low 5 bits, to generate a NAS-MAC in the same way as in step 1, wherein the high 16 bits of the NAS-MAC are XNAS_MAC, and the low 16 bits of the NAS-MAC are DL_NAS_MAC. The received UL_NAS_MAC is verified using XNAS_MAC, that is, whether the two values are the same is compared, and if the same, the verification is successful, that is, the terminal is a legitimate terminal.

[0194] S4: The MME sends a connection establishment indication to the base station, which contains DL_NAS_MAC.

[0195] S5: The base station sends an RRC connection establishment response (RRCConnectionRestablishmentResponse) message to the terminal, which contains DL_NAS_MAC.

[0196] S6: The terminal verifies DL_NAS_MAC using the stored XDL_NAS_MAC, that is, whether the two values are the same is compared, and if the same, the verification is successful. That is, the base station accessed by the terminal is a real legitimate one.

[0197] Correspondingly, the security of the above scenario in the 5G network uses the above similar method, the main difference is that: the eNB is replaced by gNB, the MME is replaced by AMF, and the S-TMSI is replaced by the 5G shortened-temporary mobile subscription identifier (5G-S-TMSI).

[0198] As can be seen, the verification process shown in FIG. 2D is performed by the core network (such as the MME), and in the power feeding discontinuous scenario, the service link and the power feeding link may not exist (or be available) at the same time. When the power feeding link is unavailable, the base station cannot request the core network to verify the terminal through the process shown in FIG. 2D.

[0199] In summary, for the power feeding discontinuous scenario, since there is no AS layer security between the terminal and the access network device, how to ensure the security of communication between the terminal and the base station without AS security is a problem to be solved urgently.

[0200] In order to ensure secure communication between a terminal and a base station in the case that there is no or no AS connection security established between the terminal and the base station, the present application provides a communication method. The communication method can be implemented by one or more of a terminal (or device, electronic device, etc.), a first network entity (or a component in the first network entity) or a second network entity (or a component in the second network entity), or an apparatus in the one or more network elements or devices. The first network entity can be a core network element, such as an AMF or an MME, etc. The second network entity can be an access network device, such as a base station. Specifically, the scheme shown in the present application can also be applied in a discontinuous feeding scenario to ensure secure communication between a terminal and a base station in the case that there is no or no AS connection security established in the discontinuous feeding scenario.

[0201] Hereinafter, the AMF is taken as the first network entity and the base station is taken as the second network entity for example. The AMF, core network device, MME or first network entity described in the following can be replaced with each other, and the base station, satellite base station, access network device or second network entity described in the following can be replaced with each other.

[0202] As shown in FIG. 3, the communication method provided by the embodiments of the present application can include steps S101-S106.

[0203] S101: The AMF determines first authentication information and / or second authentication information according to a first shared key between the terminal and the AMF.

[0204] In the present application, the first authentication information can be used to authenticate the terminal, or in other words, the first authentication information belongs to the authentication information of the terminal, and the second authentication information can be used to authenticate the base station, or in other words, the second authentication information belongs to the authentication information of the base station. It can be understood that, unless otherwise specified, the authentication information in the following can be collectively referred to as the authentication information of the terminal and the authentication information of the base station.

[0205] The authentication information for authenticating the terminal and the authentication information for authenticating the base station can be a pair of authentication information for mutual authentication between a specific terminal and a specific base station. For example, the first authentication information and the second authentication information are a pair of authentication information.

[0206] Specifically, the first authentication information can be used by the first access network device to verify that the terminal is legal or real, and the second authentication information can be used by the terminal to verify that the second access network device is legal or real.

[0207] In an implementation of the present application, if only the terminal needs to be verified, or the first base station does not need to be verified, in S101, the AMF can determine the first verification information according to the first shared key. In addition, the AMF can ignore generating the second verification information. For example, if there is a downlink NAS message of the terminal, the AMF can determine that only the terminal needs to be verified, or the AMF can determine that the first base station does not need to be verified. For another example, the terminal and the AMF can default that the base station is secure, and thus only the first base station needs to determine that the terminal passes the verification, which can ensure the security between the terminal and the first base station, and the terminal does not need to verify the first base station. It can be understood that ignoring performing an action can also be described as skipping, not performing, or not needing to perform the action.

[0208] If only the first access network device needs to be verified, or the terminal does not need to be verified, in S101, the AMF can determine the second verification information according to the first shared key. In addition, the AMF can ignore generating the first verification information. For example, if there is an uplink NAS message of the terminal, the AMF can determine that only the first base station needs to be verified, or the AMF can determine that the terminal does not need to be verified.

[0209] In another implementation, the AMF can generate the first verification information and the second verification information through S101 to support the verification of the terminal through the first verification information, and support the verification of the first base station through the second verification information.

[0210] In addition, the AMF can also default to generate the first verification information and the second verification information, and before S102, the AMF can determine whether to send the first verification information to the first base station according to whether the terminal needs to be verified, and determine whether to send the second verification information to the first base station according to whether the first base station needs to be verified.

[0211] The following describes the generation of the verification information for verifying the terminal and the verification information for verifying the base station.

[0212] In the present application, the verification information for verifying the terminal and the verification information for verifying the base station can be verification information generated by the AMF based on the shared key between the terminal and the AMF, the identifier of the first base station, and the verification information generation parameter.

[0213] Here, the shared key, the identifier of the first base station, and the verification information generation parameter are introduced respectively.

[0214] (1) The shared key can be used to generate authentication information between the terminal and the base station, and the shared key corresponds to the terminal and the AMF. For different base stations, the shared key between the terminal and the AMF can be the same. That is, when the terminal accesses different base stations, the shared key between the terminal and the AMF is the same. The shared key can be a shared key obtained by the terminal and the AMF respectively in an authentication process between the terminal and the core network. For example, the shared key can be a K NASint , K amf , K seaf or K 验证 key, which is not specifically limited. Among them, K NASint is a key for NAS signaling integrity protection. K amf may be an AMF key of the terminal. K seaf serves as an anchor key. K 验证 may be a key for generating authentication information between the terminal and the base station, such as a new key.

[0215] Among them, if the shared key is K 验证 , the AMF can generate K 验证 in the case that the base station (such as the second base station) providing services for the terminal exists a power feeding discontinuous state, and can ignore the generation of K 验证 if the base station providing services for the terminal does not exist a power feeding discontinuous state, so as to reduce the processing complexity of the AMF. Optionally, in the present application, the AMF can receive the NAS message of the terminal sent by the second base station, determine that the terminal accesses through a discontinuous access network device, or determine that the terminal or the second access network device is in a power feeding discontinuous scenario, so as to trigger or start S101.

[0216] It can be understood that before S101, the terminal can initiate a registration request to the AMF through the base station. The base station through which the terminal initiates the registration request can be referred to as a second base station. The second base station can be the same as or different from the first base station, which is not specifically required.

[0217] In the present application, in order to distinguish the shared key stored and / or maintained by the AMF and the shared key stored and / or maintained by the terminal, the shared key stored and / or maintained by the AMF can be referred to as a first shared key, and the shared key stored and / or maintained by the terminal can be referred to as a second shared key. It can be understood that in order to realize identity authentication based on the shared key, the first shared key and the second shared key are the same key. The terminal and the core network device can store their respective shared keys in an authentication process.

[0218] (2) The first base station can be a base station that the terminal can access or a base station that needs to communicate, which is determined by the AMF. The identity of the first base station can be used to identify the first base station, for example, the identity of the first base station can be an identity that uniquely identifies the first base station in a network, or an identity that uniquely identifies the first base station globally. Wherein, when the identity of the first base station is used to globally uniquely identify the first base station, the identity can include a network identity such as a public land mobile network (PLMN) identity (ID), which is not specifically limited. The AMF can obtain the identity of the first base station in the process of establishing a connection with the first base station, or obtain the identity of the first base station when interacting with the AMF specific information (such as terminal related information). As an example, if the AMF determines that there is downlink data to be sent to the terminal through control plane signaling, or the AMF determines to send downlink NAS signaling to the terminal, or the AMF determines that the terminal can access the base station according to the location of the terminal and the ephemeris information of the satellite, the base station can be the first base station.

[0219] In this application, the terminal data carried by the control plane signaling can be delay-tolerant or non-real-time service. The terminal data carried by the control plane signaling can be data of short message service (SMS) service, cellular internet of things (CIoT) or machine type communication (MTC) service.

[0220] It can be understood that if the AMF cannot determine when the terminal accesses the base station, the AMF can determine multiple base stations, which can include the first base station, the third base station or more base stations, that is, the AMF can determine the authentication information between the terminal and multiple base stations. In this application, the generation mode of the authentication information between the terminal and the first base station is taken as an example for introduction, and the authentication information between the terminal and other base stations can be referred to for implementation, which will not be described here.

[0221] (3) The authentication information generation parameter can be referred to as the generation parameter hereinafter, which can include a count value, a direction value or a bearer value, etc.

[0222] Wherein, the count value can be determined in any of the following ways:

[0223] 1. The count value is a NAS count value. For example, the count value is the latest NAS count value of the AMF and the terminal, such as using the downlink NAS count value when sending downlink NAS messages or downlink data packets. For the verification code scenario used when the terminal initiatively initiates uplink service, the uplink NAS count value can be used.

[0224] 2. The count value is a count value maintained between the terminal and the AMF for generating authentication information, which can be referred to as an authentication count value below. The authentication count value can start from 0 or 1 or other agreed values, and the authentication count value is incremented regularly, such as by 1 or 2, each time it is used (such as to generate a pair of authentication information). The authentication count value can be the same as or different from the NAS count value, that is, the AMF can separately maintain the authentication count value and the NAS count value, and similarly, the terminal can also separately maintain the authentication count value and the NAS count value. The uplink authentication count value and the downlink authentication count value can be maintained separately.

[0225] 3. The count value is a random number. The random number can be determined by the terminal or the AMF, and can be generated using a random number generator.

[0226] In addition, the count value can be a combination of multiple NAS count values, authentication count values, or random numbers, for example, using a combination of NAS count values, authentication values, and random numbers as the count value.

[0227] It can be understood that the count value used by the AMF in determining the authentication information is the same type as the count value used by the terminal in determining the authentication information, for example, both are NAS count values, both are authentication count values, or both are random numbers, or a combination of at least two of them.

[0228] In addition, the direction value can be set to 1. The bearer value can be set to a 5-bit value. The bearer value is determined according to the bearer identifier value, for example, set to 0X01 or other agreed values 11111 or 00000, etc.

[0229] It can be understood that in order to ensure that the terminal and the AMF use the same generation parameter to generate authentication information, the AMF can indicate the generation parameter to the terminal. Taking the count value as an example, the first parameter is sent by the AMF when the feeder link is available, or the indication information (which can be referred to as first information) indicating the first parameter is sent. Among them, the count value can include one or more of the non-access layer count value, the authentication count value maintained by the terminal and the core network device, or the random number, that is, the first information can be used to indicate one or more of the non-access layer count value, the authentication count value maintained by the terminal and the core network device, or the random number.

[0230] In addition, based on the same generation manner of the verification information, the terminal can generate the verification information required for verification between the terminal and the first base station according to the second shared key, the identity of the first base station, and the third parameter, which includes, for example, the sixth verification information in S104 and / or the fifth verification information in S105. It can be understood that the third parameter can be determined according to the first parameter or the first information sent by the AMF. For example, the terminal uses the received first parameter as a generation parameter when generating the fifth verification information and / or the sixth verification information. For another example, the terminal can determine the first parameter according to the first information, for example, the terminal can update the NAS count value by combining the low N1 bits of the NAS count value indicated by the first information and the NAS count value maintained by the terminal itself, and the updated NAS count value can be used as the count value used for generating the verification information. In addition, the third parameter can also be a generation parameter maintained by the terminal itself.

[0231] If only the terminal needs to be verified, or the first base station does not need to be verified, the terminal can generate the fifth verification information according to the second shared key, the identity of the first base station, and the third parameter, and can ignore the generation of the sixth verification information. If only the first base station needs to be verified, or the terminal does not need to be verified, the terminal can generate the sixth verification information according to the second shared key, the identity of the first base station, and the third parameter, and ignore the generation of the fifth verification information.

[0232] Taking the count value as an example, if the count value includes the NAS count value and / or the verification count value, the AMF indicates the count value to the terminal in the following manner, for example, the AMF sends the NAS count value and / or the verification count value, or sends the low N-bit value of the NAS count value and / or the verification count value, N is a positive integer. For example, the AMF can send the last N bits of the NAS count value and / or the last N' bits of the verification count value, N and N' are positive integers. For example, the above first information can include the last N1 bits of the NAS count value and / or the last N2 bits of the verification count value, N1 and N2 can be positive integers, the last N1 bits of the NAS count value can be used to indicate the NAS count value, or in other words, the terminal can compare the last N1 bits of the received NAS count value with the last N1 bits of the NAS count value maintained by the terminal itself, if they are different, the terminal can replace the last N1 bits of the NAS count value maintained by the terminal itself with the value of the last N1 bits of the received NAS count value, and determine the verification information according to the replaced NAS. Similarly, the last N2 bits of the verification count value can be used by the terminal to check the verification count value maintained by the terminal itself. If the count value includes a random number, the terminal can determine the random number and send it to the AMF, or the AMF can determine the random number and send it to the terminal.

[0233] Taking the terminal verifying with the first base station as an example, the AMF can send the counting value to the first base station when the feeder link is available, for example, the counting value can be carried in the N2 message sent by the AMF to the first base station. In addition, the first base station can send the counting value to the terminal or send indication information (which can be referred to as third information) indicating the counting value when the service link is available. The third information can be determined according to the first information, and the third information can be the same as or different from the first information, which is not specifically limited. The first base station can send the counting value to the terminal through an RRC message.

[0234] In addition, the terminal also indicates the generation parameter to the AMF, so that the AMF determines the first parameter used by the AMF according to the generation parameter. For example, the terminal can send the generation parameter (referred to as a third parameter) used (or maintained) by the terminal or indication information (referred to as second information) indicating the third parameter to the AMF through the second base station in the registration process. The second base station can be a base station serving the terminal, for example, the terminal requests the AMF to register through the second base station, and indicates the third parameter to the AMF through the second base station in the registration process. Referring to the description of the first parameter, the generation parameter maintained by the terminal can include the counting value. The counting value can be, for example, a NAS counting value, a verification counting value or a random number determined by the terminal. Referring to the description of the first information, the second information can include the last N3 bits of the NAS counting value and / or the last N4 bits of the verification counting value, and N3 and N4 can be positive integers. N1 and N3 can be the same or different, and N2 and N4 can be the same or different, which is not specifically limited.

[0235] In addition, in the process of generating the first verification information and / or the second verification information, an integrity protection algorithm (NIA) can be used.

[0236] As shown in FIG. 4, COUNT can be used to represent a count value, Direction can represent a direction value, and BEARER can be used to represent a bearer value. In addition, in FIG. 4, Message can be used to represent an information value, which can be set as an identifier of a base station (such as the first base station) that can provide services for the terminal, and key can be used to represent a shared key between the terminal and the AMF, such as the first shared key or the second shared key. The message authentication code (MAC) can represent an output result of an integrity protection algorithm. For a scenario in which the first verification information and the second verification information need to be generated, the verification information used to verify the terminal (such as the first verification information) and the verification information used to verify the base station (such as the second verification information) can be part of the MAC, respectively. For example, the length of the MAC value can be 32 bits, of which the upper 16 bits are the verification information used to verify the terminal, and the lower 16 bits are the verification information used to verify the base station; or the upper 16 bits are the verification information used to verify the base station, and the lower 16 bits are the verification information used to verify the terminal, and the specific division manner is not limited, as long as the length of the verification code meets the security requirement. The length of the MAC value can also be extended to other lengths, such as 54 bits or 64 bits, and the like, and is not specifically limited. In addition, the length of the verification information used to verify the terminal and the length of the verification information used to verify the base station can be the same or different, and no specific requirement is made. The sum of the length of the verification information used to verify the terminal and the length of the verification information used to verify the base station can be less than or equal to the MAC value. For a scenario in which the first verification information needs to be generated and the second verification information does not need to be generated, the MAC can be directly used as the first verification information, or a part of bits of the MAC can be extracted as the first verification information. For a scenario in which the second verification information needs to be generated and the first verification information does not need to be generated, the MAC can be directly used as the second verification information, or a part of bits of the MAC can be extracted as the second verification information.

[0237] Based on similar implementation manners, the AMF can generate authentication information for the terminal to authenticate other base stations. Taking the other base station as a third base station as an example, the AMF can determine third authentication information and / or fourth authentication information according to the first shared key between the terminal and the AMF, the identity of the third base station, and a second parameter. The second parameter can refer to the description of the first parameter, for example, the second parameter can be indicated by the AMF to the terminal through the third base station, or indicated by the terminal to the third base station. The second parameter can be the same as or different from the first parameter, that is, the generated parameters can be the same or different for different base stations, which is not specifically limited. The difference between the generated authentication information is that the value of Message is set to the identity of the third base station, in addition, the count value, the direction value and the bearer value can be determined in a similar manner, and the count value corresponding to the first base station can be the same as or different from the count value corresponding to the third base station, the direction value corresponding to the first base station can be the same as or different from the direction value corresponding to the third base station, and the bearer value corresponding to the first base station can be the same as or different from the bearer value corresponding to the third base station, which is not specifically limited. In addition, the terminal can generate fifth authentication information and / or sixth authentication information according to the second shared key according to similar implementation manners. The fifth authentication information and the second authentication information can be used by the terminal to authenticate the base station. The fifth authentication information and the first authentication information can be used by the base station to authenticate the terminal.

[0238] It can be understood that if only the terminal needs to be authenticated, or in other words, the third base station does not need to be authenticated, the AMF can generate and send the third authentication information, and ignore the generation and sending of the fourth authentication information. If only the third base station needs to be authenticated, or in other words, the terminal does not need to be authenticated, the AMF can generate and send the fourth authentication information, and ignore the generation and sending of the third authentication information.

[0239] The AMF can also send the third authentication information and / or the fourth authentication information to the third base station. The sending manner of the third authentication information and / or the fourth authentication information can refer to the manner in which the AMF sends the first authentication information and / or the second authentication information to the first base station, which will not be repeated. For example, the third authentication information and / or the fourth authentication information and the identity of the terminal can be carried in the N2 message. In addition, the authentication manner between the third base station and the terminal can refer to the description of the authentication manner between the first base station and the terminal in the present application, which will not be repeated.

[0240] In a possible implementation, the AMF can determine the first verification information and / or the second verification information in a case where it is determined that the base station (e.g., the second base station) providing services for the terminal has a power feeding discontinuous state. Alternatively, the AMF can determine the first verification information and / or the second verification information in a case where it is determined that the base station is in a power feeding link unavailable state when the terminal accesses the base station. As described in the present application, the terminal can send a registration request to the AMF through the second base station. The AMF can receive a terminal NAS message from the second base station, and determine that the terminal is served by the power feeding discontinuous base station, or that the second base station in a power feeding discontinuous state when providing services for the terminal, according to the NAS message. The AMF can determine the first verification information and / or the second verification information in the manner described above, for example, according to the first shared key between the terminal and the AMF, the identity of the first base station, and the verification information generation parameter.

[0241] In addition, the AMF can determine one or more candidate base stations, e.g., including the first base station and the third base station, through which the terminal can access or communicate, in a case where it is determined that the base station (e.g., the second base station) providing services for the terminal has a power feeding discontinuous state. In addition, the AMF can generate and send verification information for the candidate base stations to support verification between the candidate base stations and the terminal. The AMF can also indicate the candidate base stations to the terminal, so that the terminal determines the base station to access or communicate from the candidate base stations.

[0242] S102: The AMF sends the first verification information and / or the second verification information to the first base station.

[0243] It can be understood that in S102, the AMF can send the first verification information and / or the second verification information to the base station in a case where the power feeding link between the AMF and the base station is available.

[0244] In an implementation of the present application, if only the terminal needs to be verified, or the first base station does not need to be verified, the AMF can send the first verification information to the first base station in S102. In addition, the AMF can ignore sending the second verification information to the first base station. The case where only the terminal needs to be verified or the case where the first base station does not need to be verified can be referred to the description of the case in S101.

[0245] If only the first access network device needs to be verified, or the terminal does not need to be verified, the AMF can send the second verification information to the first base station in S101. In addition, the AMF can ignore sending the first verification information to the first base station. The case where only the first access network device needs to be verified or the case where the terminal does not need to be verified can be referred to the description of the case in S101.

[0246] In another implementation, the AMF can send the first authentication information and the second authentication information to the first base station through S102 to support authentication of the terminal through the first authentication information and support authentication of the first base station through the second authentication information. In addition, the AMF can also send the first authentication information and the second authentication information to the first base station through S102 by default after generating the first authentication information and the second authentication information.

[0247] It can also be understood that the application does not limit the timing of generating the first authentication information and / or the second authentication information and the timing of the available period of the feeder link between the AMF and the base station. For example, the timing of generating the first authentication information and / or the second authentication information (i.e. the actual execution of S101) can be before the starting timing of the available period of the feeder link. For another example, the timing of generating the first authentication information and / or the second authentication information can be within the available period of the feeder link (e.g. triggering the execution of S101 when the feeder link is available) and before sending the message carrying the first authentication information and / or the second authentication information to the base station. For another example, the timing of generating the first authentication information and / or the second authentication information can be triggered by S101 to generate the first authentication information and / or the second authentication information when the AMF determines to generate a downlink NAS message, for example, when the AMF determines to generate a downlink NAS message for the terminal.

[0248] Optionally, the first authentication information and / or the second authentication information can be carried in the N2 message sent by the AMF to the first base station. The N2 message can also carry a NAS message. The NAS message can be a NAS security mode command, a registration acceptance message, or a NAS message containing downlink data, which is not limited in particular. In addition, if the AMF needs to indicate the generation of a parameter (such as the first parameter) to the terminal, the N2 message can also include the first parameter or the first information.

[0249] As a possible implementation, the AMF can send the identity of the terminal, the first authentication information and the second authentication information to the first base station. The identity of the terminal can be used to indicate that the first authentication information can be used to authenticate the terminal, and in addition, the second authentication information can be used to authenticate the terminal to the base station. The identity of the terminal can be used for the terminal to obtain the first authentication information and the second authentication information corresponding to the terminal when the terminal sends a connection request to the first base station in the future.

[0250] Correspondingly, the first base station can determine the terminal authentication information used to authenticate the terminal and the base station authentication information used to authenticate the terminal to the first base station according to the identity of the terminal requesting to establish a connection.

[0251] In this application, the identifier of the terminal can be related to the identifier allocated by the access network for the terminal or the identifier allocated by the core network for the terminal. For the convenience of description, the identifier allocated by the access network or the core network for the terminal can be referred to as the air interface identifier of the terminal, which can be used between the terminal and the access network to identify the terminal. As an example, the identifier allocated by the access network for the terminal can be C-RNTI. As another example, the identifier allocated by the AMF can be a globally unique temporary identity (GUTI), or can also be a 5G-S-TMSI. In addition, the air interface identifier of the terminal can also be a new identifier obtained by the access network on the basis of the identifier allocated by the core network for the terminal.

[0252] As an implementation manner of the identifier of the terminal related to the air interface identifier, the identifier of the terminal can be the air interface identifier of the terminal. For example, in the terminal registration stage to the AMF, the air interface identifier is allocated to the terminal by the AMF. Correspondingly, in S101, the AMF can generate the first verification information and / or the second verification information based on the air interface identifier allocated by the AMF.

[0253] As another implementation manner of the identifier of the terminal related to the air interface identifier, the identifier of the terminal can be a new identifier (such as a verification identifier) further generated according to the air interface identifier, and the terminal can use the verification identifier for communication, such as communication for the verification process between the terminal and the base station. As an example implementation manner, the verification identifier can be obtained by intercepting or cyclically superimposing the air interface identifier. As another example implementation manner, the terminal can determine the verification identifier according to the identifier of the base station (such as the first base station) and the air interface identifier of the terminal. For example, the verification identifier of the terminal can be a combination of the air interface identifier and the identifier of the base station. For another example, a convention processing manner can be adopted to calculate the verification identifier of the terminal according to the air interface identifier of the terminal and the identifier of the base station. For example, the air interface identifier of the terminal and the identifier of the base station are subjected to XOR operation, and if the lengths of the identifiers are inconsistent, the XOR operation can be performed in a high-bit alignment or low-bit alignment manner. Here, it is not limited, and other ways can be used to process to obtain the verification identifier of the terminal. It can be understood that the terminal and the AMF can use the same way to determine the verification identifier of the terminal according to the air interface identifier of the terminal and the identifier of the base station, respectively.

[0254] If the authentication identifier of the terminal is determined according to the identifier of the base station and the air interface identifier of the terminal, in the case that the AMF cannot determine when the terminal accesses the network, the AMF can send the authentication information corresponding to the terminal to multiple base stations respectively, wherein different authentication information can be associated through different authentication identifiers of the terminal. That is, the terminal can use different authentication identifiers in the authentication process between different base stations, so that the authentication information associated through different authentication identifiers can be verified for different base stations, thereby improving the authentication reliability.

[0255] It can be understood that for different base stations, the identifier of the terminal can also use the same identifier, for example, both use the identifier allocated by the AMF for the terminal.

[0256] In one or more embodiments, the AMF can also determine the validity time of the first authentication information and / or the validity time of the second authentication information according to the ephemeris information, for indicating the validity time of the first authentication information and / or the validity time of the second authentication information. For example, the time information can be used to indicate the expiration time of the first authentication information and the expiration time of the second authentication information, such as the expiration time can be the termination time or expiration time point of the validity time, so that the base station deletes the corresponding authentication information according to the information after the validity time of the authentication information is exceeded. For example, the termination time can indicate May 1, 2024, that is, the validity time of the authentication information is until May 1, 2024. For another example, the time information can be used to indicate the time range of the validity time of the first authentication information and the time range of the validity time of the second authentication information. The time range can include a start time and a termination time, for example, the start time can be used to indicate April 6, 2024, and the termination time can be used to indicate May 1, 2024, that is, the validity time of the authentication information is from April 6, 2024, to May 1, 2024. For another example, the time information can be used to indicate the length of the validity time, such as the time information indicates that the authentication information will be invalid after 20 days.

[0257] Wherein, in the case that the feeder link between the AMF and the base station is available, the AMF can send the time information to the first base station, for example, the AMF can send the first authentication information, the second authentication information and the time information to the first base station. In addition, the first base station can send the time information to the terminal when the service link is available.

[0258] It can be understood that if only the terminal needs to be authenticated, or in other words, the first base station does not need to be authenticated, S103 and S104 can be subsequently executed. If only the first access network device needs to be authenticated, or in other words, the terminal does not need to be authenticated, S105 and S106 can be subsequently executed. If both the terminal and the first base station need to be authenticated, S103 to S104 can be executed.

[0259] S103: The first base station sends second authentication information to the terminal according to the identity of the terminal, for the terminal to authenticate the first base station. Correspondingly, the terminal can receive the second authentication information from the first base station.

[0260] The first base station can send the second authentication information to the terminal in a case where a service link between the terminal and the first base station is available.

[0261] Optionally, the second authentication information can be carried in an RRC message sent by the first base station to the terminal, for example, in an RRC connection setup response message.

[0262] In addition, if the AMF needs to indicate the count value to the terminal, the first base station can also include the count value or indication information (i.e., third information) indicating the count value in the RRC message. In other words, the first base station can send the count value or the third information to the terminal according to the identity of the terminal. For example, the first base station receives the identity of the terminal and the count value from the AMF, and after receiving the RRC message from the base station, the first base station can query the corresponding count value according to the identity of the terminal sending the RRC message, so the first base station can also send the count value or the third information to the terminal through the RRC message. For reference to the description of the first information, the third information can include the last N5 bits of the NAS count value and / or the last N6 bits of the authentication count value, and N5 and N6 can be positive integers. N5 can be the same as or different from N3 or N1, and N6 can be the same as or different from N2 or N4, which is not specifically limited.

[0263] S104: The terminal authenticates the first base station according to the second authentication information and the sixth authentication information.

[0264] The terminal can compare the second authentication information and the sixth authentication information, and if the comparison is consistent, it is determined that the first base station is authenticated.

[0265] The terminal can query and obtain the sixth authentication information according to the identity of the first base station. For example, the terminal can store the correspondence between the first base station, the fifth authentication information, and / or the sixth authentication information after generating the fifth authentication information and / or the sixth authentication information according to the second shared key, the identity of the first base station, and the third parameter. When the terminal receives the second authentication information from the first base station, it queries and obtains the sixth authentication information according to the identity of the first base station. The identity of the first base station can be obtained by the terminal according to the system message received from the first base station. The system message of the first base station, for example, the first base station broadcasts a system message, which can include a cell identity, and the cell identity can include the identity of the base station.

[0266] In a possible implementation, the terminal can perform the verification of the first base station through the AS layer. For example, the NAS layer of the terminal can send the identity of the first base station and the second verification information to the AS layer. The AS layer can query the sixth verification information through the identity of the first base station, and perform the verification of the second verification information and the sixth verification information. Optionally, the NAS layer of the terminal can generate the fifth verification information and / or the sixth verification information according to the second shared key, the identity of the first base station, and the third parameter, and send the fifth verification information and / or the sixth verification information to the AS layer for storage.

[0267] In another possible implementation, the terminal can perform the verification of the first base station through the NAS layer. For example, the AS of the terminal can send the received second verification information to the NAS layer, so that the NAS layer performs the verification of the second verification information and the sixth verification information.

[0268] It can be understood that the verification of the terminal to the base station can be implemented based on S103 and S104.

[0269] S105: The terminal sends the fifth verification information to the first base station. Correspondingly, the first base station receives the fifth verification information from the terminal.

[0270] The fifth verification information and the sixth verification information can be verification information generated by the terminal, where the fifth verification information can be used to verify the terminal, and the sixth verification information can be used to verify the first base station. For example, the terminal can generate the fifth verification information and / or the sixth verification information according to the second shared key, the identity of the first base station, and the third parameter.

[0271] The terminal can send the fifth verification information to the first base station when a service link between the terminal and the first base station is available.

[0272] The fifth verification information can be carried in an RRC message, which can be, for example, an RRC connection setup request message, an RRC connection setup complete message, or an RRC connection resume message.

[0273] In this application, the RRC connection setup request message can be sent by the terminal after the terminal determines to access the network. For example, the terminal can determine to access the network when receiving a paging message or when there is uplink data, or in other words, the terminal can send the RRC connection setup request message when receiving a paging message or when there is uplink data.

[0274] S106: The first base station verifies the terminal according to the first verification information and the fifth verification information.

[0275] The first base station can compare the first verification information and the fifth verification information, and if the comparison is consistent, it is determined that the terminal passes the verification.

[0276] It can be understood that the base station can verify the terminal based on S105 and S106.

[0277] Based on the flow shown in FIG. 3, the terminal can be verified by the first verification information generated by the AMF, and / or the base station can be verified according to the second verification information, and the security establishment between the terminal and the base station can be realized in the case that the AS connection security is absent between the terminal and the base station. After the verification, the NAS message can be transmitted between the terminal and the base station, including that the terminal sends the uplink NAS message to the base station, and / or the base station sends the downlink NAS message to the terminal.

[0278] In various embodiments of the present application, the execution order between S103 and S104, and S105 and S106 is not limited. For example, S103 and / or S104 can be performed before S105 and / or S106, or S105 and / or S106 can be performed before S103 and / or S104.

[0279] As an example, when the terminal generates the fifth verification information and / or the sixth verification information, the generated parameters from the AMF need to be used, then S103 and S104 can be performed first, and then S105 and S106 can be performed.

[0280] It can be understood that the generation parameter from the AMF needs to be used, which can mean that the terminal and the AMF cannot maintain the same generation parameter respectively, for example, the count value adopts the random number determined by the AMF. As shown in FIG. 5, if S103 and S104 are performed first and S105 and S106 are performed later, the terminal can send an RRC connection establishment request message to the first base station, and the request can include the identity of the terminal. After receiving the RRC connection establishment request message, the first base station can determine the first verification information and / or the second verification information according to the identity of the terminal carried in the message. As an example of S103, the first base station can send an RRC connection establishment response message to the terminal, which carries the second verification information. Wherein, the AMF needs to indicate the count value to the terminal, and the first parameter or the third information for indicating the third parameter can also be carried in the RRC connection establishment response message. The first parameter includes the count value, for example. Wherein, the first base station can receive and store the identity of the terminal and the first verification information and / or the second verification information from the AMF before or after receiving the RRC connection establishment request message, or store the relationship between the identity of the terminal and the first verification information and / or the second verification information. In addition, the first base station can also receive the first parameter or the first information for indicating the first parameter from the AMF, and the first parameter is the generation parameter used by the AMF to generate the first verification information and / or the second verification information. Wherein, the third information can be obtained by the first base station according to the first parameter or the first information for indicating the first parameter. Correspondingly, the terminal can obtain the second verification information after receiving the RRC connection establishment response message. Optionally, the terminal can obtain the count value carried in the RRC connection establishment response message, or determine the count value according to the third information in the RRC connection establishment response message, and generate the fifth verification information and / or the sixth verification information according to the count value. As an example of S104, the terminal can verify the first base station according to the second verification information and the sixth verification information. If the terminal determines that the first base station passes the verification, as an example of S105, the terminal can send an RRC connection establishment complete message to the first base station, which can carry the fifth verification information. Correspondingly, according to S106, the first base station can verify the terminal according to the fifth verification information in the RRC connection establishment complete message and the first verification information. Wherein, the fifth verification information and the sixth verification information can be generated by the terminal before or after receiving the RRC connection establishment response message, which is not limited in particular.

[0281] In addition, the generation parameter from the AMF needs to be used, which can mean that the terminal uses the generation parameter maintained by itself to determine the verification information corresponding to the verification failure, for example, if the terminal verification based on the verification information generated based on the generation parameter maintained by the terminal fails and / or the base station verification fails, the terminal can generate the verification information again according to the generation parameter from the AMF and perform the verification again.

[0282] For example, as shown in FIG. 6, the first base station can store the identity of the terminal, the first authentication information, the second authentication information, and the generation parameter (i.e., the first parameter) used by the AMF to generate the first authentication information and / or the second authentication information, which can include the first count value, which can include the NAS count value and / or the authentication count value. The terminal generates authentication information according to the second shared key, the identity of the first base station, and the generation parameter (e.g., the fourth parameter) maintained by itself, obtains the seventh authentication information and / or the eighth authentication information, the seventh authentication information can be used for authentication of the terminal, and the eighth authentication information can be used for authentication of the base station. The fourth parameter can refer to the description of the first parameter, for example, the fourth parameter can include the second count value, which can include the NAS count value and / or the authentication count value. The generation method of the seventh authentication information and / or the eighth authentication information can refer to the description of the generation method of the first authentication information and / or the second authentication information. In addition, in FIG. 6, the terminal can send an RRC connection establishment request message to the first base station, which can include the identity of the terminal and the seventh authentication information. Alternatively, the RRC connection establishment request message can also carry the fourth parameter. For example, the fourth parameter includes the NAS count value and / or the authentication count value, and the indication information of the fourth parameter includes the last N7 bits of the NAS count value and / or the last N8 bits of the authentication count value, N7 and N8 are positive integers.

[0283] If only the terminal needs to be authenticated, or the first base station does not need to be authenticated, the terminal can generate the seventh authentication information and ignore the generation of the eighth authentication information. If only the first access network device needs to be authenticated, or the terminal does not need to be authenticated, the terminal can generate the eighth authentication information and ignore the generation of the seventh authentication information.

[0284] Correspondingly, the first base station can determine the first authentication information according to the identity of the terminal in the RRC connection establishment request message, for example, the first base station can query the stored identity of the terminal, the first authentication information, and / or the second authentication information according to the identity of the terminal, and obtain the second authentication information. The first base station can authenticate the terminal according to the seventh authentication information in the RRC connection establishment request and the first authentication information. If it is determined that the terminal authentication fails, for example, the first authentication information and the seventh authentication information are different in value, the first base station can send an RRC connection establishment response message to the terminal, which can carry the first parameter from the AMF or the indication information (e.g., the third information) of the first parameter. In addition, the first base station can also compare the first count value and the second count value carried in the RRC connection establishment request message, if they are inconsistent, the first base station can send an RRC connection establishment response message to the terminal, which can carry the first parameter from the AMF or the third information.

[0285] As shown in FIG. 6, the terminal can generate the fifth authentication information and / or the sixth authentication information according to the first parameter in the RRC connection setup response message. For example, the terminal generates the authentication information again according to the first parameter (e.g., the first count value) to obtain the fifth authentication information and / or the sixth authentication information. It can be understood that the first parameter is taken as the third parameter here as an example, rather than the only implementation manner. For example, the first information is carried in the RRC connection setup response message, and the terminal can determine the third parameter according to the first information. As an example of S103, the RRC connection setup response message can further include the second authentication information. As an example of S104, the terminal can verify the first base station according to the second authentication information in the RRC connection setup response message and the sixth authentication information. As an example of S105, the terminal can send an RRC connection setup complete message to the first base station, which carries the fifth authentication information and the identity of the terminal. Correspondingly, the first base station can obtain the first authentication information according to the identity of the terminal in the RRC connection setup complete message. As an example of S106, the first base station can verify the terminal according to the fifth authentication information in the RRC connection complete request and the first authentication information. As an example of S103, after the terminal passes the verification, the first base station can send the RRC connection setup response message to the terminal, which can carry the second authentication information.

[0286] Based on the flow shown in FIG. 6, the terminal can implement efficient verification of the terminal and the base station in the case that the count value maintained by the terminal is inconsistent with the count value maintained by the AMF. In addition, it can be understood that the seventh authentication information received by the first base station in FIG. 6 can be taken as an example of S105, and the action of verifying the terminal by the first base station according to the seventh authentication information and the first authentication information can be taken as an example of S106. In addition, if the first base station determines that the terminal passes the verification according to the seventh authentication information and the first authentication information, the second authentication information can be provided to the terminal, and the terminal verifies the first base station according to the second authentication information and the eighth authentication information. It can also be understood that the seventh authentication information can be taken as the fifth authentication information, and the eighth authentication information can be taken as the sixth authentication information at this time, or it can be understood that the fourth parameter is the same as the third parameter at this time. It can be understood that if the terminal passes the verification according to the first authentication information and the seventh authentication information, it can also be understood that the fourth parameter is the same as the first parameter, that is, the terminal and the AMF generate the authentication information by using the same generation parameter.

[0287] As another example, when the terminal generates the fifth authentication information and / or the sixth authentication information, the terminal can perform S105 and S106 first, and then perform S103 and S104, according to the third parameter maintained by the terminal itself, i.e., without using the first parameter or the first information from the AMF. As shown in FIG. 7, without using the generation parameter from the AMF, it can mean that the terminal and the AMF can each maintain the generation parameter, for example, the third parameter includes the NAS count value or the authentication count value maintained by the terminal, or can include a random number, such as the random number has been provided by the terminal to the AMF in the terminal registration process with the AMF.

[0288] As shown in FIG. 7, when the terminal requests to access the first base station, the terminal can generate the fifth authentication information and / or the sixth authentication information according to the second shared key, the identity of the first base station, and the third parameter (such as the first parameter, or the same generation parameter as the first parameter) maintained by the terminal, i.e., the terminal does not need to generate the fifth authentication information and / or the sixth authentication information depending on the generation parameter from the AMF. As an example of S105, the terminal can send an RRC connection setup request message to the first base station, which carries the fifth authentication information and the identity of the terminal. Correspondingly, the first base station can obtain the first authentication information according to the identity of the terminal in the RRC connection setup request message. As an example of S106, the first base station can authenticate the terminal according to the fifth authentication information in the RRC connection setup request and the first authentication information. As an example of S103, after the terminal is authenticated, the first base station can send an RRC connection setup response message to the terminal, which can carry the second authentication information. Optionally, the RRC connection setup response message can also carry a NAS message. As an example of S104, the terminal can authenticate the first base station according to the second authentication information in the RRC connection setup response message and the sixth authentication information. Optionally, if the terminal determines that the first base station passes the authentication, the terminal can send an RRC connection setup complete message to the first base station. Optionally, the RRC connection setup complete message can carry a NAS message. For example, the RRC connection setup response message can carry a NAS security mode command, and the NAS message in the RRC connection setup complete message can be a NAS security mode command complete message, such as the NAS security mode command complete message can carry a random number for the next authentication.

[0289] In addition, it can be understood that the terminal verifying the base station shown in S103 and S104 is decoupled from the base station verifying the terminal shown in S105 and S106. That is, either of the two can be independently executed. For example, in some cases, the terminal can be verified by the base station, and the terminal does not need to perform verification of the base station. For example, in the case where S106 is performed prior to S103, if the base station determines that the terminal does not pass the verification through S106, the terminal verifying the base station shown in S103 and S104 can be ignored. For another example, the base station can be assumed to be secure, and therefore only the base station needs to determine that the terminal passes the verification, and then the secure connection between the terminal and the base station can be established, and the terminal does not need to verify the base station. For another example, if there is only downlink transmission of the terminal, only the base station needs to verify the terminal, and the terminal verifying the base station can be ignored.

[0290] In some other cases, the terminal can verify the base station, and the base station verifying the terminal does not need to be performed. For example, in the case where S104 is performed prior to S105, if the terminal determines that the base station passes the verification through S104, the terminal can send the fifth verification information to the base station through S105, and if the terminal determines that the base station does not pass the verification in S104, S105 and S106 can be ignored. For another example, if there is only uplink transmission of the terminal, only the terminal needs to verify the base station, and the base station verifying the terminal can be ignored.

[0291] Optionally, if only the terminal verifying the base station needs to be performed, only the verification information of the base station needs to be obtained according to the MAC, and the verification information of the terminal and the verification information of the base station do not need to be obtained according to the MAC, for example, part or all bits of the MAC can be used as the verification information of the base station. Similarly, if only the base station verifying the terminal needs to be performed, only the verification information of the base station needs to be obtained according to the MAC, for example, part or all bits of the MAC can be used as the verification information of the terminal.

[0292] In the following, the communication method provided by the present application will be introduced in combination with the embodiments shown in FIG. 8 to FIG. 12. In the embodiments shown in FIG. 8 and FIG. 9, the AMF can generate the first verification information and the second verification information in the case of determining to transmit the data packet of the terminal through the control plane, and send the first verification information and the second verification information to the first base station, which is a base station that the terminal can access. In addition, the difference between the embodiments of FIG. 8 and FIG. 9 is that, in the embodiment shown in FIG. 8, the generation parameter is indicated to the terminal by the AMF, and the terminal determines the verification information after receiving the generation parameter, while in FIG. 9, the terminal can determine the verification information according to the generation parameter maintained by itself, and thus does not necessarily receive the generation parameter indicated by the AMF. That is, the flow shown in FIG. 8 corresponds to the scheme in which the execution timing of S103 and S104 is before the execution timing of S105 and S106, and the flow shown in FIG. 9 corresponds to the scheme in which the execution timing of S105 and S106 is before the execution timing of S103 and S104. In addition, the scheme of only performing terminal verification is introduced in FIG. 12, at this time, the AMF can generate the first verification information, the first base station verifies the terminal according to the first verification information, and the terminal does not need to verify the first base station, and the terminal can directly process the received NAS message. In addition, the terminal can generate the fifth verification information, and does not need to generate the sixth verification information.

[0293] In the embodiments of FIG. 10 and FIG. 11, the AMF cannot determine when the terminal accesses the network, and thus can determine the verification information between the terminal and multiple base stations. In the embodiments of FIG. 10 and FIG. 11, the first base station and the second base station are taken as examples for illustration, and more base stations can be referred to for implementation, which will not be described herein. The difference between the embodiments of FIG. 10 and FIG. 11 is that, in the embodiment shown in FIG. 10, the generation parameter is indicated to the terminal by the AMF, and the terminal determines the verification information according to the generation parameter after receiving the indication of the generation parameter, while in FIG. 11, the terminal can determine the verification information according to the generation parameter maintained by itself, and thus does not necessarily receive the generation parameter indicated by the AMF. That is, the flow shown in FIG. 10 corresponds to the scheme in which the execution timing of S103 and S104 is before the execution timing of S105 and S106, and the flow shown in FIG. 11 corresponds to the scheme in which the execution timing of S105 and S106 is before the execution timing of S103 and S104.

[0294] As shown in FIG. 8, the communication method provided by the embodiment of the present application can include the following steps:

[0295] S201: The terminal initiates a registration request message to the core network through the second base station, and the terminal performs an authentication procedure with the network through the AMF. After the terminal is authenticated, the terminal and the AMF obtain a shared key between the terminal and the AMF, i.e., the terminal can store the second shared key, and the AMF can store the first shared key. For example, the authentication procedure of the terminal can refer to the description in section of 3GPP TS 33.501, which is not specifically limited in the present application. Among them, the second base station is a base station with discontinuous power feeding. The AMF can determine that the second base station is a base station with discontinuous power feeding according to the uplink NAS message from the second base station.

[0296] In S201, the shared key can refer to the description in S101. For example, the shared key can be K NASint , K amf , K seaf or K 验证 , etc. Among them, if the shared key is K 验证 , the AMF can generate K 验证 in the case of determining that the base station (such as the second base station) providing services for the terminal exists a discontinuous power feeding state. Optionally, if the base station providing services for the terminal does not exist a discontinuous power feeding state, K 验证 can be ignored.

[0297] Among them, the second base station can be a base station with discontinuous power feeding, for example, the second base station is a satellite base station working in a regenerative mode.

[0298] S202: Optionally, the AMF generates a NAS security context and generates a NAS security mode command message. Among them, the NAS security context can include an integrity protection algorithm, an encryption algorithm, K NASenc , or K NASint , etc. For example, the generation method of the NAS security context and / or the NAS security mode command message can refer to the description in section 6.7.2 of 3GPP TS 33.501, which is not specifically limited in the present application.

[0299] S203: In the case of determining to transmit the data packet of the terminal through the control plane, the AMF generates first verification information and second verification information according to the first shared key.

[0300] The generation method of the first verification information and the second verification information by the AMF can refer to the description in S103. For example, the AMF determines the first verification information and the second verification information according to the first shared key, the identifier of the first base station and the first parameter. Among them, the first parameter includes a count value, for example.

[0301] The count value can include a NAS count value, a verification count value, or a random number. The random number can be determined by the terminal or the AMF. If the random number is determined by the terminal, the terminal can send the random number to the AMF in a registration procedure initiated by the terminal to the AMF, so that the terminal and the AMF maintain the same count value. If the random number is determined by the AMF, the AMF can send the random number to the terminal.

[0302] It can be understood that S203 can be an example of S101.

[0303] S204: When the feeder link between the AMF and the first base station is available, the AMF sends an N2 message to the first base station, and the N2 message can include a NAS security mode command, first verification information, and second verification information.

[0304] Optionally, the N2 message can also include the identity of the terminal, such as the air interface identity of the terminal. If the first base station is a base station that stores the context of the terminal, the AMF can not need to send the identity of the terminal, and in this case the first base station can obtain the identity of the terminal locally through other associated identities in the N2 message. The first base station can be a base station that the AMF determines that the terminal can access or a base station that needs to communicate.

[0305] In addition, the N2 message can also include a first parameter or indication information (i.e., first information) used by the AMF to generate the first verification information and the second verification information, such as a count value or indication information of the first value. For example, if the count value used by the AMF includes a NAS count value and / or a verification count value, the N2 message can also include the count value or the first information, and the first information can be the last N bits of the count value, such as the last 5 bits. For another example, if the count value used by the AMF includes a random number maintained by the AMF, the N2 message can also include the random number.

[0306] Correspondingly, the first base station can store the correspondence between the identity of the terminal, the first verification information, and the second verification information. Optionally, the first base station can store the correspondence between the identity of the terminal, the first verification information, the second verification information, and the first parameter.

[0307] Optionally, the N2 message can also include time information indicating the validity time of the first verification information and the validity time of the second verification information.

[0308] It can be understood that S204 can be an example of S102.

[0309] S205: When the service link between the terminal and the first base station is available, the terminal can send an RRC connection establishment request message to the first base station.

[0310] The RRC connection establishment request message can include the identity of the terminal, such as the air interface identity of the terminal.

[0311] Specifically, the terminal can determine to access the first base station according to a local context or a paging message sent by the first base station, perform a random access procedure, and send an RRC connection establishment request message to the first base station.

[0312] S206: The first base station obtains the first authentication information and the second authentication information according to the identifier of the terminal in the RRC connection establishment request message.

[0313] Optionally, if the first parameter or the first information is included in the N2 message, the first base station can also obtain the first parameter according to the identifier of the terminal in the RRC connection establishment request message.

[0314] S207: The first base station sends an RRC connection establishment response message to the terminal, and the RRC connection establishment response message includes the second authentication information.

[0315] Optionally, the RRC connection establishment response message can also include the first parameter or indication information (i.e., third information) of the first parameter.

[0316] It can be understood that S207 can be an example of S103.

[0317] S208: The terminal generates fifth authentication information and sixth authentication information according to the second shared key.

[0318] The AMF generates the first authentication information and the second authentication information in S204 in the same way as the terminal generates the fifth authentication information and the sixth authentication information according to the second shared key. For example, the AMF and the terminal use the same shared key, base station identifier, and generation parameter.

[0319] S208 can be performed by the NAS layer of the terminal. For example, the NAS layer can send the fifth authentication information and the sixth authentication information to the AS layer after generating the fifth authentication information and the sixth authentication information.

[0320] Optionally, if the N2 message in S204 includes the NAS security mode command, the fifth authentication information and the sixth authentication information can be generated using a preset algorithm in S208. The algorithm of the subsequent authentication information can reuse the preset algorithm or use the algorithm negotiated in the NAS security mode command.

[0321] S209: The terminal verifies the first base station according to the second authentication information and the sixth authentication information.

[0322] If the second authentication information and the sixth authentication information are consistent, it can be determined that the first base station passes the verification.

[0323] In S209, the terminal can compare the second authentication information and the sixth authentication information through the AS layer to achieve authentication of the first base station.

[0324] It can be understood that S209 can be an example of S104.

[0325] S210: The terminal sends an RRC connection establishment completion message to the first base station, which carries the fifth authentication information.

[0326] It can be understood that S210 can be an example of S105.

[0327] S211: The first base station authenticates the terminal according to the first authentication information and the fifth authentication information.

[0328] The first base station can compare the first authentication information and the fifth authentication information, and if the comparison is consistent, it is determined that the terminal passes the authentication.

[0329] S211 can be an example of S106.

[0330] S212: In the case where the first base station determines that the terminal passes the authentication, the first base station sends a downlink RRC message to the terminal, and the RRC message can include a NAS security mode command.

[0331] S213: The terminal processes the NAS security mode command and generates a NAS security mode completion message.

[0332] S214: The terminal sends an uplink RRC message to the first base station, and the uplink RRC message includes the NAS security mode completion message.

[0333] S215: The first base station stores the NAS security mode completion message. For example, when the feeder link of the first base station is unavailable, the first base station stores the NAS security mode completion message.

[0334] S216: When the feeder link of the first base station is available, the first base station sends an N2 message to the AMF, and the N2 message includes the NAS security mode completion message.

[0335] S217: The AMF processes the NAS security mode completion message and interacts with the core network.

[0336] The AMF can further generate new authentication information, including new terminal authentication information and base station authentication information. The new terminal authentication information and base station authentication information can be generated in the same way as in S203.

[0337] Optionally, one of the differences between S217 and S203 can be that a different count value is used in S217 than in S203. For example, if the count value includes a NAS count value and / or a verification count value, the count value used in S217 is one greater than the count value used in S202. For another example, if the count value includes a random number, the count value used in S217 can be different than the count value used in S202.

[0338] In addition, the second difference between S217 and S203 can be that the identity of the base station used to generate the verification information in S217 can be the identity of the first base station or the identity of another base station. If the identity of the base station is the identity of another base station other than the first base station, the verification information can be used by the terminal to verify the other base station or can be used by the other base station to verify the terminal.

[0339] S218: When the feeder link of the first base station is available, the AMF sends an N2 message to the first base station, the N2 message including a registration accept message, the verification information of the new terminal, and the verification information of the base station. In addition, the N2 message can also include the air interface identity of the terminal and / or a generation parameter, which can be used to generate the new verification information.

[0340] Correspondingly, the first base station can store the correspondence between the identity of the terminal, the verification information of the new terminal, and the verification information of the new base station. Optionally, the first base station can store the correspondence between the identity of the terminal, the verification information of the new terminal, the verification information of the new base station, and the count value.

[0341] S219: When the service link between the terminal and the first base station is available, the terminal accesses the network and performs verification between the terminal and the first base station.

[0342] S219 can be implemented with reference to S205 to S211, with the difference that the NAS security mode command is replaced by the registration accept message, and details are not repeated.

[0343] In addition, the first base station in S218 to S219 can also be replaced by another base station, for example, by another base station other than the first base station that supports service for the terminal.

[0344] It can be seen that based on the flowchart shown in FIG. 8, the secure connection between the terminal and the first base station can be implemented in the scenario where the AMF determines that there is a downlink NAS message (such as a NAS security mode command, a registration accept message, a NAS message for carrying downlink data, or other NAS messages) of the terminal. In addition, in S209 shown in FIG. 8, the terminal first verifies the verification information of the first base station, and the terminal can perform S210, i.e., provide the fifth verification information to the first base station, after determining that the first base station is verified.

[0345] FIG. 9, another communication method provided by the embodiments of the present application can include the following steps:

[0346] S301-S304 can be repeated with reference to the description in S201-S204 in FIG. 8, and the repeated parts will not be described herein. The difference is that in S203, the AMF generates the count value of the authentication information, which includes the NAS count value and / or the authentication count value, i.e., the terminal maintains the count value, and the AMF can not need to provide the count value to the terminal; in addition, in S304, the N2 message does not need to carry the first parameter or the indication information thereof.

[0347] S305: The terminal can generate the fifth authentication information and the sixth authentication information according to the second shared key.

[0348] The way in which the AMF generates the first authentication information and the second authentication information in S303 is the same as the way in which the terminal generates the fifth authentication information and the sixth authentication information according to the shared key. For example, the AMF and the terminal use the same shared key, the identifier of the base station, and other generation parameters.

[0349] S305 can be performed by the NAS of the terminal. For example, the NAS layer can send the fifth authentication information and the sixth authentication information to the AS layer after generating the fifth authentication information and the sixth authentication information.

[0350] The difference between S305 and S208 is that in S305, the terminal can generate the authentication information according to the count value maintained by itself.

[0351] Optionally, the terminal can generate the fifth authentication information and the sixth authentication information in the case that the service link between the terminal and the first base station is available or unavailable, which is not specifically limited.

[0352] S306: When the service link between the terminal and the first base station is available, the terminal sends an RRC connection establishment request message to the first base station, which includes the identifier of the terminal and the fifth authentication information.

[0353] Specifically, the terminal can determine to access the first base station according to the local context or the paging message sent by the first base station, perform a random access procedure, and send an RRC connection establishment request message to the first base station.

[0354] It can be understood that S306 can be used as an example of S105.

[0355] S307: The first base station acquires the first authentication information and the second authentication information according to the identifier of the terminal in the RRC connection establishment request message.

[0356] S308: The first base station verifies the terminal according to the first authentication information and the fifth authentication information.

[0357] The first base station can compare the first authentication information and the fifth authentication information. If the comparison is consistent, the terminal is determined to pass the authentication.

[0358] S308 can be an example of S106.

[0359] S309: In the case where the first base station determines that the terminal passes the authentication, and when the service link is available, the first base station sends an RRC connection establishment response message to the terminal, the RRC connection establishment response message containing the second authentication information and the NAS security mode command.

[0360] S310: The terminal authenticates the first base station according to the second authentication information and the sixth authentication information.

[0361] In S310, the terminal can compare the second authentication information and the sixth authentication information through the AS layer to achieve authentication of the first base station.

[0362] S311: In the case where the first base station passes the authentication, the terminal processes the NAS security mode command and generates a NAS security mode complete message.

[0363] Optionally, if the random number generated by the terminal is used as the count value in the authentication information generation process, the terminal can generate a new random number and carry the random number in the NAS security mode complete message for generating authentication information next time.

[0364] S312: When the service link is available, the terminal sends an RRC connection establishment complete message to the first base station, the message containing the NAS security command complete message.

[0365] Optionally, the NAS security command complete message contains the NAS verification code.

[0366] S313: The first base station stores the NAS security command complete message. For example, when the power supply link of the first base station is unavailable, the first base station stores the NAS security mode complete message.

[0367] S314: When the power supply link is available, the first base station sends an N2 message to the AMF, which includes the NAS security command complete message.

[0368] S315 to S317 can refer to the description of S217 to S219, and will not be repeated here.

[0369] It can be seen that based on the flow shown in FIG. 9, the secure connection between the terminal and the first base station can be realized in the scenario where the AMF determines that there is a downlink NAS message (such as a NAS security mode command, a registration acceptance message, a NAS message for carrying downlink data, or other NAS messages) of the terminal. In addition, in S308 shown in FIG. 9, the first base station first verifies the verification information provided by the terminal, and the first base station can provide the second verification information to the terminal after determining that the terminal passes the verification.

[0370] FIG. 10, another communication method provided by the embodiment of the application can include the following steps:

[0371] S401 can refer to the description in S201.

[0372] S402: The AMF determines the base stations that the terminal can access, including the first base station and the third base station.

[0373] S403: The AMF determines the first verification information and the second verification information according to the first shared key and the identifier of the first base station, and determines the third verification information and the fourth verification information according to the first shared key and the identifier of the third base station. The third verification information can be used for the third base station to verify the terminal, and the fourth verification information can be used for the terminal to verify the third base station. The third verification information and the fourth verification information can refer to the description of the first verification information and the second verification information, and the difference is only that the identifiers of the base stations used can be different.

[0374] The determination methods of the first verification information and the second verification information, and the determination methods of the third verification information and the fourth verification information can refer to the description of S202. When the AMF determines the first verification information and the second verification information, the same or different counting values, orientation values, or bearing values can be used.

[0375] Optionally, the AMF can determine the identifier of the terminal corresponding to the first base station according to the air interface identifier of the terminal and the identifier of the first base station, and determine the identifier of the terminal corresponding to the third base station according to the air interface identifier of the terminal and the identifier of the third base station.

[0376] The counting value can include a NAS counting value, a verification counting value, or a random number. The random number can be determined by the terminal or the AMF. If the random number is determined by the terminal, the terminal can send the random number to the AMF in the registration process initiated by the terminal to the AMF, so that the terminal and the AMF maintain the same counting value. If the random number is determined by the AMF, the AMF can send the random number to the terminal.

[0377] It can be understood that S403 can be an example of S101.

[0378] S404: When the feeder link between the AMF and the first base station is available, the AMF sends a first N2 message to the first base station, which can include the NAS security mode command, the first authentication information, and the second authentication information. In addition, when the feeder link between the AMF and the third base station is available, the AMF sends a second N2 message to the third base station, which can include the NAS security mode command, the third authentication information, and the fourth authentication information.

[0379] Optionally, the first N2 message can further include the identity of the terminal corresponding to the first base station. The second N2 message can further include the identity of the terminal corresponding to the third base station.

[0380] In addition, the first N2 message can further include the first parameter or the indication information (i.e., the first information) used by the AMF to generate the first authentication information and the second authentication information. The second N2 message can further include the second parameter or the indication information used by the AMF to generate the third authentication information and the fourth authentication information. For example, if the count value used by the AMF includes a random number maintained by the AMF, the first N2 message and / or the first N2 message can further include the random number.

[0381] Correspondingly, the first base station can store the correspondence between the identity of the terminal corresponding to the first base station, the first authentication information, and the second authentication information, and can further store the corresponding first parameter or the first information. The third base station can store the correspondence between the identity of the terminal corresponding to the third base station, the third authentication information, and the fourth authentication information, and can further store the corresponding second parameter or the indication information of the second parameter.

[0382] Optionally, the first base station can store the correspondence between the identity of the terminal corresponding to the first base station, the first authentication information, the second authentication information, and the count value. Optionally, the third base station can store the correspondence between the identity of the terminal corresponding to the third base station, the third authentication information, the fourth authentication information, and the count value.

[0383] Optionally, the N2 message sent by the AMF to the first base station can further include first time information indicating the validity time of the first authentication information and the validity time of the second authentication information. The N2 message sent by the AMF to the third base station can further include second time information indicating the validity time of the third authentication information and the validity time of the fourth authentication information.

[0384] It can be understood that S404 can be an example of S102.

[0385] S405: When the service link between the terminal and the first base station is available, the terminal sends an RRC connection establishment request message to the first base station, which can carry the identity of the terminal.

[0386] The identity of the terminal is the identity of the terminal corresponding to the first base station, and the terminal can determine the identity of the terminal according to the identity of the terminal in the air interface and the identity of the first base station. For example, the terminal can use the same method as when the AMF generates the identity of the terminal corresponding to the first base station, to obtain the identity of the terminal corresponding to the first base station according to the identity of the terminal in the air interface and the identity of the first base station.

[0387] Specifically, the terminal can determine to access the first base station according to the local context or the paging message sent by the first base station, and the terminal performs a random access procedure and sends an RRC connection establishment request message to the first base station.

[0388] S406: The first base station obtains the first authentication information and the second authentication information according to the identity of the terminal in the RRC connection establishment request message.

[0389] Optionally, if the first N2 message received by the first base station contains the count value or the first information, the first base station can also obtain the count value according to the identity of the terminal in the RRC connection establishment request message.

[0390] S407 to S409 can refer to the descriptions of S207 to S209, respectively.

[0391] S410: In the case where the service link is available, the terminal sends an RRC connection establishment completion message to the first base station, which includes the fifth authentication information and an uplink NAS message.

[0392] The uplink NAS message can include uplink data of the terminal, or can also be other NAS messages, which is not specifically limited.

[0393] S411: The first base station verifies the terminal according to the first authentication information and the fifth authentication information.

[0394] S411 can refer to S211.

[0395] In the case where the first base station determines that the terminal passes the verification, S412 and / or S413 can be performed.

[0396] S412: The first base station stores the uplink NAS message. For example, in the case where the power feeding link is not available, the first base station can store the uplink NAS message and wait for the power feeding link to be available.

[0397] S413: In the case where the power feeding link is available, the first base station sends an N2 message to the AMF, which includes the uplink NAS message.

[0398] S414: The AMF processes the uplink NAS message. Optionally, the AMF can generate new authentication information (or authentication information used subsequently) for the verification between the terminal and the base station in subsequent terminal transmission.

[0399] It can be seen that based on the flow shown in FIG. 10, the secure connection between the terminal and the first base station can be realized in the case that the AMF cannot determine when the terminal accesses the network. In addition, in S409 shown in FIG. 10, the terminal first verifies the verification information of the first base station, and the terminal can perform S410, i.e., providing the fifth verification information to the first base station, after determining that the verification of the first base station is passed, and the first base station performs the verification of the terminal according to the first verification information and the fifth verification information in S411.

[0400] FIG. 11, another communication method provided by an embodiment of the present application can include the following steps:

[0401] S501 to S504 can refer to the description of S401 to S404 in FIG. 10 respectively, and the repeated parts will not be described herein. The difference is that in S403, the count value used by the AMF to generate the verification information includes the NAS count value or the verification count value, i.e., the terminal maintains the count value, and the AMF can not need to provide the count value to the terminal; in addition, in S504, the first N2 message does not need to carry the first parameter or the first information.

[0402] S505 to S508 can refer to the description of S305 to S308 respectively. The difference is that the identifier of the terminal is replaced by the identifier of the terminal corresponding to the first base station.

[0403] S509: In the case that the service link is available, the first base station sends an RRC connection establishment response message to the terminal, which includes the second verification information.

[0404] S510: The terminal verifies the first base station according to the sixth verification information and the second verification information.

[0405] S510 can refer to S209.

[0406] In the case that the first base station determines that the terminal passes the verification, S511 can be performed.

[0407] S511: The terminal sends an RRC connection establishment complete message to the first base station, which carries the uplink NAS message.

[0408] The uplink NAS message can include the uplink data of the terminal, or can also be other NAS messages, which is not specifically limited.

[0409] S512 to S514 can refer to the description of S412 to S414, which will not be described herein.

[0410] It can be seen that based on the flow shown in FIG. 11, the secure connection between the terminal and the first base station can be realized in the case that the AMF cannot determine when the terminal accesses the network. In addition, in S508 shown in FIG. 11, the first base station first verifies the verification information provided by the terminal. The first base station can provide the second verification information to the terminal after determining that the terminal passes the verification, and the terminal performs the verification of the first base station according to the sixth verification information and the second verification information in S510.

[0411] FIG. 12, when the AMF determines that there is a downlink NAS message, another communication method provided by the embodiment of the application can include the following steps:

[0412] S601 can refer to S201.

[0413] S602: When the AMF determines to send a downlink NAS message to the terminal, the AMF generates first verification information according to a first shared key.

[0414] As an example, the AMF can generate the first verification information according to the first shared key, the identity of the first base station and the first parameter. Referring to the description in the present application, the first parameter can include a count value, a direction value or a bearer value, etc. Among them, the count value can be a NAS count value or a verification count value. In addition, the count value can also be a random number.

[0415] For example, the AMF can generate a MAC using the algorithm shown in FIG. 4, take the MAC as the first verification information, or take part of the bits in the MAC as the first verification information.

[0416] It can be understood that S602 can be an example of S101.

[0417] S603: When the feeder link between the AMF and the first base station is available, the AMF sends an N2 message to the first base station, and the N2 message can include the downlink NAS message and the first verification information.

[0418] Among them, the downlink NAS message can be a NAS security mode command, a registration acceptance message, etc., or a NAS message containing downlink data, which is not specifically limited.

[0419] Optionally, the N2 message can also include the first parameter or the indication information (i.e. the first information) used by the AMF to generate the first verification information.

[0420] S603 can be implemented by referring to S204, and the difference is that the N2 message in S603 can not carry the second verification information.

[0421] Correspondingly, the first base station can store a correspondence between the identity of the terminal and the first authentication information. Optionally, the first base station can store a correspondence between the identity of the terminal, the first authentication information, and the first parameter.

[0422] Optionally, the N2 message can further include time information, used to indicate a valid time of the first authentication information.

[0423] It can be understood that S603 can be an example of S102.

[0424] S604: When the service link between the terminal and the first base station is available, the terminal can send an RRC connection establishment request message to the first base station.

[0425] The RRC connection establishment request message can include the identity of the terminal, such as the air interface identity of the terminal.

[0426] Optionally, the RRC connection establishment request message can be sent based on a paging message sent by the first base station. The paging message can be used to page the terminal. The paging message is sent when the service link between the terminal and the first base station is available.

[0427] S605: The first base station obtains the first authentication information according to the identity of the terminal in the RRC connection establishment request message.

[0428] Optionally, if the N2 message includes the first parameter or the first information, the first base station can further obtain the first parameter according to the identity of the terminal in the RRC connection establishment request message.

[0429] S606: The first base station sends an RRC connection establishment response message to the terminal, and the RRC connection establishment response message includes the first parameter or the third information.

[0430] Correspondingly, the terminal can determine the first parameter or the first information according to the first parameter or the first information in the RRC connection establishment response message.

[0431] It can be understood that S606 can be an example of S103.

[0432] S607: The terminal generates a fifth authentication information according to the second shared key and the first parameter.

[0433] S608: The terminal sends an RRC connection establishment completion message to the first base station, where the fifth authentication information is carried.

[0434] It can be understood that S608 can be an example of S105.

[0435] S609: The first base station verifies the terminal according to the first authentication information and the fifth authentication information.

[0436] The first base station can compare the first authentication information and the fifth authentication information. If the comparison is consistent, it is determined that the terminal passes the authentication.

[0437] S609 can be an example of S106.

[0438] S610: In the case where the first base station determines that the terminal passes the authentication, the first base station sends a downlink RRC message to the terminal, and the RRC message can include a downlink NAS message.

[0439] S611: When the feeder link between the AMF and the first base station is available, the first base station sends an N2 message to the AMF, and the N2 message includes a sending notification, which can be used to indicate that the downlink NAS message has been sent.

[0440] As can be seen, based on the flow shown in FIG. 12, the AMF can determine the first authentication information in the presence of the downlink NAS message of the terminal, so that the first base station authenticates the terminal according to the first authentication information. In this example, the authentication of the terminal to the first base station does not need to be performed, and therefore the second authentication information does not need to be generated.

[0441] It can be understood that FIG. 12 shows a flow that does not perform authentication related to the second authentication information. In this flow, the terminal can obtain the first parameter provided by the AMF according to the RRC connection establishment response message in S607 and generate the fifth authentication information, and then send the fifth authentication information to the first base station through the RRC connection establishment completion message.

[0442] In addition, the terminal can also generate the fifth authentication information according to the third parameter maintained by itself, for example, generate the fifth authentication information according to the description of S305 shown in FIG. 9. At this time, the terminal can send the fifth authentication information to the first base station through the RRC connection establishment request message, so as to simplify the authentication process.

[0443] It can be understood that the above examples in FIG. 3, FIG. 8 to FIG. 12 take the AMF as the core network equipment. If in the 4G network system, the AMF can be replaced by the MME, and the NAS message can be replaced by the NAS PDU.

[0444] It can be understood that in order to implement the functions in the above embodiments, the base station and the terminal include the corresponding hardware structure and / or software modules for executing each function. Those skilled in the art should easily realize that the units and method steps of the examples described in combination with the embodiments disclosed in the present application can be realized in the form of hardware or hardware and computer software. Whether a certain function is executed in hardware or computer software driven hardware depends on the specific application scenario and design constraints of the technical solution.

[0445] FIG. 13 and FIG. 14 are structural schematic diagrams of possible communication apparatuses provided by embodiments of the present application. The communication apparatuses can be used to implement the functions of the terminal, the first network entity (such as a core network device like AMF) or the second network entity (such as an access network device like base station) in the above method embodiments, and thus can also achieve the beneficial effects possessed by the above method embodiments. In embodiments of the present application, the communication apparatus can be a terminal, a core network device or an access network device, and can also be a component applied to the above modules or network elements, such as a functional module or chip in a terminal, AMF or base station.

[0446] As shown in FIG. 13, the communication apparatus 1300 includes a processing unit 1310 and a transceiver unit 1320. The communication apparatus 1300 is configured to implement the actions of the terminal, the AMF or the first base station in the above method embodiments shown in any of FIG. 3 or FIG. 5 to FIG. 12.

[0447] Taking FIG. 3 as an example, when the communication apparatus 1300 is configured to implement the functions of the AMF in the method embodiment shown in FIG. 3, the processing unit 1310 can be configured to perform S101, i.e., determining the first authentication information and the second authentication information according to the first shared key. The transceiver unit 1320 can be configured to perform S102, i.e., sending the first authentication information and the second authentication information to the first base station.

[0448] When the communication apparatus 1300 is configured to implement the functions of the first base station in the method embodiment shown in FIG. 3, the transceiver unit 1320 can be configured to perform S102, i.e., receiving the first authentication information and the second authentication information from the AMF. In addition, the transceiver unit 1320 can also be configured to perform S103, i.e., sending the second authentication information to the terminal. In addition, the transceiver unit 1320 can also be configured to perform S105, i.e., receiving the fifth authentication information from the terminal. The processing unit 1310 can be configured to perform S106, i.e., verifying the terminal according to the first authentication information and the fifth authentication information.

[0449] When the communication apparatus 1300 is configured to implement the functions of the terminal in the method embodiment shown in FIG. 3, the transceiver unit 1320 can be configured to perform S103, i.e., receiving the second authentication information from the first base station. In addition, the transceiver unit 1320 can also be configured to perform S105, i.e., sending the fifth authentication information to the first base station. The processing unit 1310 can be configured to perform S104, i.e., verifying the first base station according to the second authentication information and the sixth authentication information. Optionally, the processing unit 1310 can also be configured to generate the fifth authentication information and the sixth authentication information according to the second shared key.

[0450] It can be understood that the above transceiver unit 1320 can also be used to perform the actions of transmitting and receiving of the terminal, the base station or the AMF in various embodiments and implementation of the present application, not limited to the examples herein. The above processing unit 1310 can also be used to perform actions other than the transceiving of the terminal, the base station or the AMF in various embodiments and implementation of the present application, not limited to the examples herein.

[0451] For more detailed description of the above processing unit 1310 and transceiver unit 1320, please refer to the relevant description in any of the method embodiments shown in FIG. 3 and FIG. 5 to FIG. 12.

[0452] As shown in FIG. 14, the communication apparatus 1400 includes a processor 1410 and an interface circuit 1420. The processor 1410 and the interface circuit 1420 are coupled to each other. It can be understood that the interface circuit 1420 can be a transceiver or an input / output interface. Optionally, the communication apparatus 1400 can further include a memory 1430 for storing instructions executed by the processor 1410 or storing input data required by the processor 1410 to run instructions or storing data generated after the processor 1410 runs instructions. For example, the processor 1410 can be used to implement the functions of the above processing unit 1310, and the interface circuit 1420 can be used to implement the functions of the above transceiver unit 1320.

[0453] For example, when the above communication apparatus is a chip applied to a terminal, a first network entity or a second network entity, the chip implements the functions of the terminal, the first network entity or the second network entity in the above method embodiments. The chip can receive information sent by other network elements or devices to the terminal, the first network entity or the second network entity through other modules (such as a communication interface) in the terminal, the first network entity or the second network entity, or the chip sends information to other modules (such as a communication interface) in the terminal, the first network entity or the second network entity. Wherein, the information is sent by the terminal, the first network entity or the second network entity to other network elements or devices.

[0454] It can be understood that the processor in the embodiments of the present application can be a central processing unit (CPU), and can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, transistor logic devices, hardware components or any combination thereof. The general-purpose processor can be a microprocessor or any conventional processor.

[0455] The method steps in the embodiments of the present application can be implemented in hardware or in software instructions executable by a processor. The software instructions can be composed of corresponding software modules, which can be stored in a random access memory, a flash memory, a read-only memory, a programmable read-only memory, an electrically erasable programmable read-only memory, a register, a hard disk, a mobile hard disk, a CD-ROM, or any other form of storage medium well known in the art. An exemplary storage medium is coupled to the processor, so that the processor can read information from and write information to the storage medium. The storage medium can also be an integral part of the processor. The processor and the storage medium can be located in an ASIC. In addition, the ASIC can be located in a sensing device or a terminal device. The processor and the storage medium can also exist as discrete components in the sensing device or the terminal device.

[0456] The embodiments of the present application also provide a communication system, which includes one or more devices or apparatuses in a terminal, a first network entity or a second network entity for implementing the above-mentioned method embodiments to implement any method in FIG. 3 or FIG. 5 to FIG. 12. For example, in the method shown in FIG. 3, the communication system can include a terminal, a first base station and an AMF.

[0457] The embodiments of the present application also provide a computer readable storage medium for storing a computer program or instructions, which, when executed, cause the method shown in the above-mentioned method embodiments to be implemented.

[0458] The embodiments of the present application also provide a computer program product, which, when executed on a computer, causes the method shown in the method embodiments to be implemented.

[0459] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware or any combination thereof. When implemented by software, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer programs or instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments are performed. The computer can be a general purpose computer, a special purpose computer, a computer network, a network device, a user equipment or other programmable apparatus. The computer programs or instructions can be stored in a computer readable storage medium or transferred from one computer readable storage medium to another computer readable storage medium, for example, the computer programs or instructions can be transferred from one website site, computer, server or data center to another website site, computer, server or data center through wired or wireless manner. The computer readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server, data center and the like integrated with one or more available media. The available media can be a magnetic medium, such as a floppy disk, a hard disk, a magnetic tape; or an optical medium, such as a digital video disc; or a semiconductor medium, such as a solid state disk. The computer readable storage medium can be a volatile or non-volatile storage medium, or can include both volatile and non-volatile storage media.

[0460] In various embodiments of the present application, the terms and / or descriptions of different embodiments are consistent and can be referred to each other if there is no special description and logical conflict, and the technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationship.

[0461] In the present application, "at least one" means one or more, and "multiple" means two or more. The "and / or" describes the association relationship between the associated objects, which means that there can be three kinds of relationships, for example, A and / or B, which can represent the following cases: A exists alone, A and B exist together, B exists alone, where A and B can be singular or plural. In the literal description of the present application, the character " / ", generally represents that the associated objects before and after are in an "or" relationship; in the formula of the present application, the character " / ", represents that the associated objects before and after are in a "division" relationship. "Including at least one of A, B and C" can mean: including A; including B; including C; including A and B; including A and C; including B and C; including A, B and C.

[0462] It can be understood that various numbers involved in the embodiments of the present application are only distinguished for convenience of description, and are not used to limit the scope of the embodiments of the present application. The size of the serial number of the above processes does not mean the order of execution, and the execution order of the processes should be determined according to their functions and inherent logic.

Claims

1. A communication method, characterized in that: Applicable to discontinuous power feeding scenarios, including: Determine first verification information and second verification information according to a first shared key between the terminal and the core network device, where the first verification information is used to verify the terminal, and the second verification information is used to verify the first access network device; When a feeder link between the first access network device and the core network device is available, first verification information and second verification information are sent to the first access network device.

2. The method according to claim 1, wherein Before determining the first verification information and the second verification information according to the first shared key between the terminal and the core network device, the method further includes: A non-access stratum (NAS) message of the terminal is received and sent by a discontinuously powered access network device.

3. The method according to claim 1 or 2, wherein: The determining the first verification information and the second verification information according to the first shared key between the terminal and the core network device includes: The first verification information and the second verification information are determined according to the first shared key, the identifier of the first access network device, and a first parameter, where the first parameter includes at least one of the following: Non-access layer count value; A verification count value maintained by the terminal and the core network device; Random number.

4. The method according to claim 3, wherein The method further comprises: Sending one or more of the non-access layer count value, the verification count value maintained by the terminal and the core network device, or a random number to the first access network device; or, First information is sent to the first access network device, where the first information is used to indicate one or more of the non-access layer count value, the verification count value maintained by the terminal and the core network device, or a random number.

5. The method according to claim 3 or 4, wherein: Before determining the first verification information and the second verification information according to the first shared key and the first parameter, the method further includes: receiving one or more of the non-access layer count value from the terminal, the verification count value maintained by the terminal and the core network device, or a random number; or, Second information is received from the terminal, where the second information is used to indicate one or more of the non-access layer count value, the verification count value maintained by the terminal and the core network device, or a random number.

6. The method according to any one of claims 1 to 5, wherein: The sending the first verification information and the second verification information to the first access network device includes: A first message is sent to the first access network device, where the first message includes the first verification information, the second verification information, and an identifier of the terminal.

7. The method according to claim 6, wherein The terminal identifier includes at least one of the following: an identifier of the terminal assigned by the access network; The identifier of the terminal assigned by the core network; a first identifier of the terminal, where the first identifier is determined according to an identifier of the terminal assigned by the core network and an identifier of the first access network device; The second identifier of the terminal is determined according to the identifier of the terminal allocated by the access network and the identifier of the first access network device.

8. The method according to any one of claims 1 to 7, wherein: The method further comprises: When a feeder link between the first access network device and the core network device is available, first time information is sent to the first access network device, where the first time information is used to indicate the valid time of the first verification information and / or the valid time of the second verification information.

9. The method according to any one of claims 1 to 8, wherein: The method further comprises: Determine to transmit the data packet of the terminal through the control plane.

10. The method according to any one of claims 1 to 9, wherein: The sending the first verification information and the second verification information to the first access network device includes: An N2 message is sent to the first access network device, where the N2 message includes the first verification information and the second verification information.

11. The method according to claim 10, wherein The N2 message also includes a NAS message.

12. The method according to any one of claims 1 to 11, wherein: The method further comprises: Determine third verification information and fourth verification information according to the first shared key between the terminal and the core network device; Send third verification information and fourth verification information to the third access network device, the third verification information is used by the third access network device to verify the terminal, and the fourth verification information is used by the terminal to verify the third access network device, and the third access network device and the first access network device are different access network devices.

13. A communication method, characterized in that: Applicable to discontinuous power feeding scenarios, including: When a feeder link between a first access network device and a core network device is available, receiving first verification information and second verification information from the core network device, where the first verification information is used to verify the terminal, and the second verification information is used to verify the first access network device, and the first verification information and the second verification information are determined by the core network device according to a first shared key between the terminal and the core network device; When a service link between the first access network device and the terminal is available, sending the second verification information to the terminal according to the identifier of the terminal; and receiving fifth verification information from the terminal, the fifth verification information being determined by the terminal according to a second shared key between the terminal and the core network device; The first verification information and the fifth verification information are compared, and whether the terminal passes the verification is determined according to the comparison result.

14. The method according to claim 13, wherein The method further comprises: An identification of the terminal is received from the terminal.

15. The method according to claim 13 or 14, characterized in that The method further comprises: The first verification information and the second verification information are stored.

16. The method according to any one of claims 13 to 15, wherein: The first verification information is determined by the core network device according to a first shared key between the terminal and the core network device, including: The first verification information is determined by the core network device according to the first shared key, the identifier of the first access network device, and a first parameter, where the first parameter includes at least one of the following: Non-access layer count value; A verification count value maintained by the terminal and the core network device; Random number.

17. The method according to claim 16, wherein The method further comprises: Receive one or more of the non-access layer count value, the verification count value maintained by the terminal and the core network device, or a random number from the core network device, or receive first information from the core network device, where the first information is used to indicate the non-access layer count value, the verification count value maintained by the terminal and the core network device, or one or more of the random numbers.

18. The method according to claim 17, wherein The method further comprises: When the service link between the first access network device and the terminal is unavailable, store one or more of the non-access layer count value of the core network device, the verification count value maintained by the terminal and the core network device, or a random number; When a service link between the first access network device and the terminal is available, sending one or more of the non-access layer count value, the verification count value maintained by the terminal and the core network device, or a random number to the terminal; or Sending third information to the terminal, where the third information is used to indicate one or more of the non-access layer count value, the verification count value maintained by the terminal and the core network device, or a random number.

19. The method according to claim 17 or 18, wherein: The sending one or more of the non-access layer count value, the verification count value maintained between the terminal and the core network device, or the random number to the terminal includes: Sending a radio resource control (RRC) connection establishment response message to the terminal, where the RRC connection establishment response message includes one or more of the non-access layer count value, the verification count value maintained by the terminal and the core network device, or a random number; or, The sending third information to the terminal includes: An RRC connection establishment response message is sent to the terminal, where the RRC connection establishment response message includes the third information.

20. The method according to any one of claims 13 to 19, wherein: The receiving fifth verification information from the terminal includes: An RRC connection establishment completion message is received from the terminal, where the RRC connection establishment completion message includes the fifth verification information.

21. The method according to claim 20, wherein The sending the second verification information to the terminal includes: An RRC connection establishment response message is sent to the terminal, where the RRC connection establishment response message includes the second verification information.

22. The method according to claim 20 or 21, wherein: The method further comprises: receiving an RRC connection establishment request message from the terminal, where the RRC connection establishment request message includes seventh verification information, where the seventh verification information is used to verify the terminal, and the RRC connection establishment request message further includes a fourth parameter or indication information of a fourth parameter, where the fourth parameter includes a non-access stratum count value and / or a verification count value maintained by the terminal and the core network device, and the seventh verification information is determined by the terminal based on the second shared key and the fourth parameter; When it is determined that the terminal has not passed the verification based on the seventh verification information and the first verification information, or when it is determined that the fourth parameter is different from the first parameter provided by the core network device, the RRC connection establishment response message also includes the first parameter or the third information, and the first verification information and the second verification information are determined by the core network device based on the second shared key and the first parameter. The first parameter includes a non-access layer count value and / or a verification count value maintained by the terminal and the core network device.

23. The method according to any one of claims 13 to 18, wherein: The receiving fifth verification information from the terminal includes: An RRC connection establishment request message is received from the terminal, where the RRC connection establishment request message includes the fifth verification information.

24. The method according to claim 23, wherein The sending the second verification information to the terminal includes: After determining that the terminal passes the verification according to the comparison result, an RRC connection establishment response message is sent to the terminal, where the RRC connection establishment response message includes the second verification information.

25. The method according to any one of claims 13 to 24, wherein: The terminal identifier includes at least one of the following: an identifier of the terminal assigned by the access network; The identifier of the terminal assigned by the core network; an identifier generated according to the identifier allocated by the core network; The second identifier of the terminal is determined according to the identifier of the terminal allocated by the access network and the identifier of the first access network device.

26. The method of claim 25, wherein: The identifier generated according to the identifier allocated by the core network includes the first identifier of the terminal, and the first identifier is determined according to the identifier of the terminal allocated by the core network and the identifier of the first access network device.

27. The method according to any one of claims 13 to 26, wherein: The method further comprises: When a feeder link between the first access network device and the core network device is available, receiving first time information from the core network device, where the first time information is used to indicate a valid time of the first verification information and / or a valid time of the second verification information; When a service link between the first access network device and the terminal is available, the first time information is sent to the terminal.

28. The method according to any one of claims 13 to 27, wherein: The receiving of the first verification information and the second verification information from the core network device includes: An N2 message is received from a core network device, where the N2 message includes the first verification information and the second verification information.

29. The method of claim 28, wherein The N2 message also includes a first NAS message.

30. The method of claim 29, wherein: The method further comprises: When a service link between the first access network device and the terminal is available, the first NAS message is sent to the terminal.

31. The method according to any one of claims 13 to 20, wherein: The method further comprises: In a case where a service link between the first access network device and the terminal is available, a second NAS message is received from the terminal.

32. A communication method, characterized in that: include: When a service link between the first access network device and the terminal is available, receiving second verification information from the first access network device, where the second verification information is determined by a core network device based on a first shared key between the terminal and the core network device, and the second verification information is used to verify the first access network device; obtaining sixth verification information, where the sixth verification information is determined by the terminal according to a second shared key between the terminal and the core network device, and the sixth verification information is used to verify the first access network device; When it is determined, based on the second verification information and the sixth verification information, that the first access network device has passed verification and the service link is available, the terminal sends a second NAS message to the first access network device.

33. The method of claim 32, wherein: The method further comprises: When the service link between the first access network device and the terminal is available, fifth verification information is sent to the first access network device, where the fifth verification information is determined by the terminal based on the second shared key between the terminal and the core network device, and is used to verify the terminal.

34. The method according to claim 32 or 33, wherein The method further comprises: The fifth verification information and the sixth verification information are determined according to the second shared key, and the fifth verification information is used to verify the terminal.

35. The method of claim 34, wherein: The determining the fifth verification information and the sixth verification information according to the second shared key includes: The fifth verification information and the sixth verification information are determined according to the second shared key, the identifier of the first access network device, and a third parameter, where the third parameter includes at least one of the following: Non-access layer count value; A verification count value maintained by the terminal and the core network device; Random number.

36. The method of claim 35, wherein: The method further comprises: When a service link between the first access network device and the terminal is available, receiving one or more of the non-access layer count value, the verification count value maintained by the terminal and the core network device, or a random number from the first access network device; or When the service link between the first access network device and the terminal is available, third information is received from the first access network device, where the third information is used to indicate one or more of the non-access layer count value, the verification count value maintained by the terminal and the core network device, or a random number.

37. The method of claim 36, wherein: The receiving one or more of the non-access layer count value from the first access network device, the verification count value maintained by the terminal and the core network device, or a random number includes: Receiving an RRC connection establishment response message from the first access network device, one or more of the non-access layer count value in the RRC connection establishment response message, the verification count value maintained by the terminal and the core network device, or a random number; or, The sending third information to the terminal includes: An RRC connection establishment response message is received from the first access network device, where the RRC connection establishment response message includes the third information.

38. The method according to any one of claims 33 to 37, wherein: The sending fifth verification information to the first access network device includes: After determining that the first access network device passes the verification based on the second verification information and the sixth verification information, an RRC connection establishment completion message is sent to the first access network device, where the RRC connection establishment completion message includes the fifth verification information.

39. The method of claim 38, wherein The receiving second verification information from the first access network device includes: An RRC connection establishment response message is received from the first access network device, where the RRC connection establishment response message includes the second verification information.

40. The method of claim 39, wherein The method further comprises: Sending an RRC connection establishment request message to the first access network device, where the RRC connection establishment request message includes seventh verification information and a fourth parameter or indication information of the fourth parameter, where the seventh verification information is determined by the terminal based on the second shared key between the terminal and the core network device and the fourth parameter, where the fourth parameter includes a non-access layer count value and / or a verification count value maintained by the terminal and the core network device; The RRC connection establishment response message also includes a first parameter or indication information of the first parameter. The first verification information and the second verification information are determined by the core network device based on the first shared key and the first parameter. The first parameter includes a non-access layer count value and / or a verification count value maintained by the terminal and the core network device.

41. The method according to any one of claims 33 to 37, wherein: The sending fifth verification information to the first access network device includes: An RRC connection establishment request message is sent to the first access network device, where the RRC connection establishment request message includes the fifth verification information.

42. The method of claim 41, wherein The receiving second verification information from the first access network device includes: Receive an RRC connection establishment response message from the first access network device, where the RRC connection establishment response message includes the second verification information.

43. The method according to any one of claims 32 to 42, wherein: The sending fifth verification information to the first access network device includes: A second message is sent to the first access network device, where the second message includes the fifth verification information and the identifier of the terminal.

44. The method of claim 43, wherein: The terminal identifier includes at least one of the following: an identifier of the terminal assigned by the access network; The identifier of the terminal assigned by the core network; an identifier generated according to the identifier allocated by the core network; The second identifier of the terminal is determined according to the identifier of the terminal allocated by the access network and the identifier of the first access network device.

45. The method of claim 44, wherein The identifier generated according to the identifier allocated by the core network includes the first identifier of the terminal, and the first identifier is determined according to the identifier of the terminal allocated by the core network and the identifier of the first access network device.

46. ​​The method according to any one of claims 32 to 45, wherein: The method further comprises: When a service link between the first access network device and the terminal is available, first time information is received from the first access network device, where the first time information is used to indicate a valid time of the first verification information and / or a valid time of the second verification information.

47. The method according to any one of claims 32 to 46, wherein: The method further comprises: In a case where a service link between the first access network device and the terminal is available, a first NAS message is received from the first access network device.

48. A communication device, characterized in that The method comprises a unit or module for executing the method according to any one of claims 1 to 12, or a unit or module for executing the method according to any one of claims 13 to 31, or a unit or module for executing the method according to any one of claims 32 to 47.

49. A communication device, characterized in that The method comprises a processor configured to execute a computer program or instructions to implement the method according to any one of claims 1 to 12, or to implement the method according to any one of claims 13 to 31, or to implement the method according to any one of claims 32 to 47.

50. A computer-readable storage medium, characterized in that The storage medium stores a computer program or instruction. When the computer program or instruction is executed by the communication device, the method according to any one of claims 1 to 12 is implemented, or the method according to any one of claims 13 to 31 is implemented, or the method according to any one of claims 32 to 47 is implemented.

51. A computer program product, characterized in that When the computer program product is executed by a computer, the computer executes the method according to any one of claims 1 to 12, or the method according to any one of claims 13 to 31, or the method according to any one of claims 32 to 47.

52. A communication system, characterized in that include: A core network element, configured to execute the method according to any one of claims 1 to 12; A first access network device, wherein the first access network device is configured to execute the method according to any one of claims 13 to 31.

53. The system of claim 52, wherein: Also includes: A terminal, configured to execute the method according to any one of claims 32 to 47.