Information transmission method and apparatus, related device, storage medium, and computer program product
By pre-configuring candidate cell security information associated with the next-hop handover for the terminal, and using vertical derivation to generate keys and encryption/decryption algorithms, the security and signaling overhead issues of information transmission in L1/L2 triggered mobility are solved, achieving continuous transmission of security information and signaling optimization.
Patent Information
- Application Number
- PCT/CN2025/101885
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-06-21
- Filing Date
- 2025-06-18
- Publication Date
- 2025-12-26
Smart Images

Figure CN2025101885_26122025_PF_FP_ABST
Abstract
Description
Information transmission method and apparatus, related device, storage medium, and computer program product
[0001] Cross-reference to Related Applications
[0002] The present application is based on the Chinese patent publication No. 202410813772.0, published on June 21, 2024, and claims priority to the Chinese patent publication, the entire contents of which are hereby incorporated by reference into the present disclosure. TECHNICAL FIELD
[0003] The present disclosure relates to the field of wireless communication, and particularly relates to an information transmission method and apparatus, related device, storage medium and computer program product. BACKGROUND
[0004] In related technologies, Layer 1 (L1) / Layer 2 (L2) triggered mobility (LTM, L1 / L2 Triggered Mobility) is supported, i.e., cell switch (which can also be understood as change) based on L1 measurement. Specifically, the network side configures a plurality of LTM candidate cells (expressed in English as candidate cells) for a user equipment (UE, User Equipment), and issues a switching command (expressed in English as cell switch command) to the UE based on the L1 measurement result reported by the UE, to trigger the cell switch of the UE; after the UE receives the switching command issued by the network side, the execution of LTM is triggered.
[0005] In the above process of executing LTM, at least the update of security information used for information transmission between the UE and the LTM candidate cell is involved, so there is a risk of security information exposure. SUMMARY
[0006] To solve the problems in related technologies, the present disclosure provides an information transmission method and apparatus, related device, storage medium and computer program product.
[0007] The technical solutions of the embodiments of the present disclosure are implemented as follows:
[0008] According to a first aspect of the embodiments of the present disclosure, an information transmission method is provided, applied to a terminal, comprising: receiving first information sent by a network device, the first information containing at least security-related information of one or more first candidate cells, the one or more first candidate cells being associated with next-hop switching in an LTM process, and the security-related information being used for information transmission between the terminal and the one or more first candidate cells.
[0009] In some embodiments, the security-related information comprises one of: second information used to determine a first key; and third information used to determine the second information.
[0010] In some embodiments, the method further comprises: determining, by using the first information, a first key corresponding to the one or more first candidate cells, wherein the first key is generated based on a vertical derivation manner.
[0011] In some embodiments, the first information further comprises fourth information used to indicate a first algorithm; the method further comprises: in a case where the security-related information comprised in the first information is encrypted, performing decryption processing on the encrypted security-related information by using the first algorithm to obtain decrypted security-related information; and determining, by using the decrypted security-related information, the first key corresponding to the one or more first candidate cells.
[0012] In some embodiments, the determining, by using the first information, the first key corresponding to the one or more first candidate cells comprises: receiving fifth information sent by the network device, wherein the fifth information comprises at least one of a source cell and a target cell associated with the next-hop switching; and determining, by using the fifth information and the security-related information comprised in the first information, the first key corresponding to the one or more first candidate cells.
[0013] In some embodiments, the method further comprises: determining, by using the first information, a first key corresponding to the one or more first candidate cells, wherein the first key is generated based on a vertical derivation manner or a horizontal derivation manner.
[0014] According to a second aspect of the embodiments of the present disclosure, an information transmission method is provided, applied to a network device, comprising: sending first information to a terminal, wherein the first information comprises security-related information of one or more first candidate cells, the one or more first candidate cells are associated with next-hop switching in an LTM process, and the security-related information is used for information transmission between the terminal and the one or more first candidate cells.
[0015] In some embodiments, the security-related information comprises one of: second information used to determine a first key; and third information used to determine the second information.
[0016] In some embodiments, the first information is used to determine a first key corresponding to the one or more first candidate cells, and the first key is generated based on a vertical derivation manner.
[0017] In some embodiments, the first information further comprises fourth information, wherein the fourth information is used to indicate a first algorithm, the first algorithm is used to decrypt the security-related information processed by encryption to obtain decrypted security-related information, and the decrypted security-related information is used to determine the first key.
[0018] In some embodiments, the method further comprises: sending fifth information to the terminal, wherein the fifth information comprises at least one of a source cell and a target cell associated with the next hop switching, and the fifth information and the security-related information comprised in the first information are used to determine the first key.
[0019] In some embodiments, the first information is used to determine a first key corresponding to the one or more first candidate cells, and the first key is generated based on a vertical derivation or a horizontal derivation.
[0020] In some embodiments, the method further comprises: sending sixth information to a first network element, wherein the sixth information is used to request the first information, and the first network element is used at least for mobility management; and receiving the first information sent by the first network element.
[0021] In some embodiments, seventh information is sent to a first network element, wherein the seventh information is used to indicate one or more candidate cells associated with the LTM process.
[0022] According to a third aspect of embodiments of the present disclosure, an information transmission method is provided, applied to a first network element, comprising: receiving sixth information sent by a network device, wherein the sixth information is used to request first information, the first network element is used at least for mobility management, the first information comprises at least security-related information of one or more first candidate cells, the one or more first candidate cells are associated with next hop switching in an LTM process, and the security-related information is used for information transmission between the terminal and the one or more first candidate cells; and sending the first information to the network device.
[0023] In some embodiments, the method further comprises: generating the first information in a case where the sixth information is received.
[0024] In some embodiments, seventh information sent by the network device is received, wherein the seventh information is used to indicate one or more candidate cells associated with the LTM process; eighth information is generated by using the seventh information, wherein the eighth information comprises the one or more candidate cells and corresponding security-related information; and in a case where the sixth information is received, security-related information matched with the one or more first candidate cells is found from the eighth information to obtain the first information.
[0025] According to a fourth aspect of the embodiments of the present disclosure, an information transmission apparatus is provided, arranged in a terminal, comprising: a first receiving unit, configured to receive first information sent by a network device, wherein the first information comprises security-related information of one or more first candidate cells, the one or more first candidate cells are associated with next-hop switching in an LTM process, and the security-related information is used for information transmission between the terminal and the one or more first candidate cells.
[0026] According to a fifth aspect of the embodiments of the present disclosure, an information transmission apparatus is provided, arranged in a network device, comprising: a first sending unit, configured to send first information to a terminal, wherein the first information comprises security-related information of one or more first candidate cells, the one or more first candidate cells are associated with next-hop switching in an LTM process, and the security-related information is used for information transmission between the terminal and the one or more first candidate cells.
[0027] According to a sixth aspect of the embodiments of the present disclosure, an information transmission apparatus is provided, arranged in a first network element, comprising: a second receiving unit, configured to receive sixth information sent by a network device, wherein the sixth information is used for requesting first information, the first network element is used for at least mobility management, the first information comprises security-related information of one or more first candidate cells, the one or more first candidate cells are associated with next-hop switching in an LTM process, and the security-related information is used for information transmission between the terminal and the one or more first candidate cells; and a second sending unit, configured to send the first information to the network device.
[0028] According to a seventh aspect of the embodiments of the present disclosure, a terminal is provided, comprising: a first processor and a first communication interface; wherein the first communication interface is configured to receive first information sent by a network device, wherein the first information comprises security-related information of one or more first candidate cells, the one or more first candidate cells are associated with next-hop switching in an LTM process, and the security-related information is used for information transmission between the terminal and the one or more first candidate cells.
[0029] According to an eighth aspect of the embodiments of the present disclosure, a network device is provided, comprising: a second processor and a second communication interface; wherein the second communication interface is configured to send first information to a terminal, wherein the first information comprises security-related information of one or more first candidate cells, the one or more first candidate cells are associated with next-hop switching in an LTM process, and the security-related information is used for information transmission between the terminal and the one or more first candidate cells.
[0030] According to a ninth aspect of the embodiments of the present disclosure, a first network element is provided, comprising a third processor and a third communication interface; wherein the third communication interface is configured to receive sixth information transmitted by a network device, the sixth information being used for requesting first information, the first network element being used for at least mobility management, the first information comprising at least security-related information of one or more first candidate cells, the one or more first candidate cells being associated with next-hop switching in an LTM process, the security-related information being used for information transmission between the terminal and the one or more first candidate cells; and transmitting the first information to the network device.
[0031] According to a tenth aspect of the embodiments of the present disclosure, a terminal is provided, comprising a first processor and a first memory configured to store a computer program capable of running on the processor, wherein the first processor is configured to run the computer program to perform the steps of any of the above-mentioned methods on the terminal side.
[0032] According to an eleventh aspect of the embodiments of the present disclosure, a network device is provided, comprising a second processor and a second memory configured to store a computer program capable of running on the processor, wherein the second processor is configured to run the computer program to perform the steps of any of the above-mentioned methods on the network device side.
[0033] According to a twelfth aspect of the embodiments of the present disclosure, a first network element is provided, comprising a third processor and a third memory configured to store a computer program capable of running on the processor, wherein the third processor is configured to run the computer program to perform the steps of any of the above-mentioned methods on the first network element side.
[0034] According to a thirteenth aspect of the embodiments of the present disclosure, a storage medium is provided, having a computer program stored thereon, the computer program being configured to implement the steps of any of the above-mentioned methods on the terminal side, or implement the steps of any of the above-mentioned methods on the network device side, or implement the steps of any of the above-mentioned methods on the first network element side, when executed by a processor.
[0035] According to a fourteenth aspect of the embodiments of the present disclosure, a computer program product is provided, comprising a computer program, the computer program being configured to implement the steps of any of the above-mentioned methods on the terminal side, or implement the steps of any of the above-mentioned methods on the network device side, or implement the steps of any of the above-mentioned methods on the first network element side, when executed by a processor.
[0036] The information transmission method, apparatus, related device, storage medium and computer program product provided in the embodiments of the present disclosure, a terminal receives first information sent by a network device, the first information at least contains security related information of one or more first candidate cells, the one or more first candidate cells are associated with next hop switching in an LTM process, and the security related information is used for information transmission between the terminal and the one or more first candidate cells. The technical solution provided in the embodiments of the present disclosure, in the execution process of the LTM, the network side device provides security information of the candidate cell associated with the next hop LTM (which can also be understood as the next cell switching) for the terminal in advance, so that the terminal can automatically perform the next hop LTM, and the update of the security information through the network side device is not required each time the LTM process is performed. In this way, the risk of security information exposure can be reduced, and the signaling (such as radio resource control (RRC) signaling) overhead can also be reduced. BRIEF DESCRIPTION OF DRAWINGS
[0037] FIG. 1 is a structural schematic diagram of key update in the related art.
[0038] FIG. 2 is a flow schematic diagram of a first information transmission method in the embodiments of the present disclosure.
[0039] FIG. 3 is a flow schematic diagram of a second information transmission method in the embodiments of the present disclosure.
[0040] FIG. 4 is a flow schematic diagram of a third information transmission method in the embodiments of the present disclosure.
[0041] FIG. 5 is a flow schematic diagram of a method for performing LTM in an application example of the present disclosure.
[0042] FIG. 6 is a structural schematic diagram of a first information transmission apparatus in the embodiments of the present disclosure.
[0043] FIG. 7 is a structural schematic diagram of a second information transmission apparatus in the embodiments of the present disclosure.
[0044] FIG. 8 is a structural schematic diagram of a third information transmission apparatus in the embodiments of the present disclosure.
[0045] FIG. 9 is a structural schematic diagram of a terminal in the embodiments of the present disclosure.
[0046] FIG. 10 is a structural schematic diagram of a network device in the embodiments of the present disclosure.
[0047] FIG. 11 is a structural schematic diagram of a first network element in the embodiments of the present disclosure.
[0048] FIG. 12 is a structural schematic diagram of an information transmission system in the embodiments of the present disclosure. DETAILED DESCRIPTION
[0049] The present disclosure will be described in further detail below with reference to the drawings and examples.
[0050] In the process of performing LTM, the UE performs LTM based on complete random access (English can be expressed as RACH-based LTM) or not based on complete random access (English can be expressed as RACH-less LTM) based on whether there is a timing advance (TA) of the target cell. In the above process, the UE can use the following ways to obtain the TA of the target cell in advance:
[0051] 1) The network side device issues indication information to the UE to indicate whether the TA of the target cell is the same as the TA of the serving cell (English can be expressed as serving cell).
[0052] 2) Early-UL sync refers to the process in which the UE initiates a random access channel (RACH) to obtain the TA of the target cell based on the physical downlink control channel (PDCCH) order issued by the network side device.
[0053] 3) UE-Based TA measurement refers to the TA calculated by the UE according to the downlink synchronization information.
[0054] As can be seen from the above description, by performing LTM, fast switching of a cell (which can be expressed in English as cell) can be achieved, so that the FR2 scenario can be better adapted, but the related LTM mechanism is only applicable to the scenario of Intra-CU (Intra-CU) switching. When the UE performs cell switching, only the protocol stack such as the media access control (MAC, Media Access Control) layer, the radio link control (RLC, Radio Link Control) layer or the physical layer (PHY, Physical) needs to be fully or partially reset or reestablished, without the need to reset or reestablish the RRC layer or the packet data convergence protocol (PDCP, Packet Data Convergence Protocol) layer; wherein the MAC, RLC and PHY can be reset or reestablished according to network configuration. Since the PDCP layer is an entity that performs functions such as integrity protection, encryption or decryption processing, in the case where the PDCP layer does not need to be reset or reestablished, the update of security information is not involved; wherein the security information can include K gNB (understood as a root key), a next hop parameter (NH, Next Hop parameter), a next hop chaining counter (NCC, NH chaining Counter) or a sk-counter (understood as a security parameter), etc. The security information is used to generate a key (which can be expressed in English as key, also referred to as secret key), and the key is used for secure transmission between the UE and the base station.
[0055] On the other hand, the related art introduces a continuous conditional primary secondary cell (Pscell, Primary Secondary Cell) addition or change (CPAC, Conditional Pscell Additional / Change) mechanism, that is, the network side device can configure multiple candidate cells capable of CPAC for the UE at a time, and the UE does not release the related configuration after performing CPAC, that is, the UE can continuously perform CPAC. The purpose of introducing the CPAC mechanism is to reduce RRC reconfiguration, thereby reducing the signaling overhead of the Uu interface. Since CPAC can be performed across base stations, the UE may need to update the security information. Specifically, for the secondary node (SN, Secondary node), the sk-counter usually needs to be updated. In this case, the UE can be provided with the sk-counter through pre-configuration. In this way, when the UE accesses the corresponding base station, the first unused sk-counter corresponding to the base station accessed by the UE can be used.
[0056] As can be seen from the above description, in the CPAC scenario, the security information of the SN is generated based on the security information of the master node (MN), and the security information of the MN does not change, so the security information can be pre-configured and delivered in advance.
[0057] However, in the scenario of inter-CU handover, since the change of the base station (such as gNB) or centralized unit (CU) is involved, the update of the security information will be involved.
[0058] In the related art, as shown in FIG. 1, the update principle of the security information is that, in the initial access layer (AS) security context establishment process, the UE and the base station generate K AMF (which can be understood as a security parameter associated with the access and mobility management function (AMF)) based on K gNB and NH, each K gNB is associated with one NCC, and the NCC is associated with NH, such as K gNB is generated based on K AMF , and K gNB is associated with a virtual NH with NCC 0.
[0059] In the process of cell handover or switching from the inactive state (RRC_INACTIVE) to the connected state (RRC_CONNECTED), the key K NG-RAN used between the UE and the target base station can be obtained based on the currently used K gNB or NH (which can also be understood as K NG-RAN derived from the currently active K gNB or NH). If K gNB is generated based on the currently used K NG-RAN , this generation method can be referred to as horizontal derivation (also referred to as horizontal key derivation); if K NG-RAN is generated based on the currently used NH, this generation method can be referred to as vertical derivation (also referred to as vertical key derivation).
[0060] In the scenario of vertical derivation, since NH can only be generated by the UE and the AMF, the AMF can provide the NH to the source base station, so that the source base station generates K NG-RAN based on the vertical derivation and delivers K NG-RAN*Sent to the target base station. Specifically, during the Xn interface handover process, if there are unused NH and NCC, and K... AMF If no changes occur, the source base station can generate K through vertical derivation, based on NH, the target physical cell identifier (PCI, Physical Cell Identifier), and the corresponding frequency (which can be expressed as ARFCN-DL). NG-RAN *; Otherwise, the source base station can be horizontally derived based on K. gNB Target PCI and corresponding frequency, generate K NG-RAN *. Next, the source base station can transmit K NG-RAN * and the corresponding NCC are sent to the target base station, enabling the target base station to transmit K NG-RAN *This is used as security information when communicating with the terminal. The target base station receives K. NG-RAN After * and the corresponding NCC, K can be NG-RAN The terminal associates with the corresponding NCC and sends a Handover (HO) command message to the source base station, carrying the NCC information. Upon receiving the HO command message, the source base station transparently transmits it to the terminal so that the terminal is aware that the handover is complete.
[0061] After the handover is complete, the target base station can send a path switch request (NGAP PATH SWITCH REQUEST) to the AMF. Upon receiving the path switch request, the AMF will update the locally stored NCC value by incrementing it by 1. Simultaneously, it will calculate a new NH using a predefined function. The K value within the current security context can be used in this calculation. AMF The new NH is obtained using a predefined function. Then, the AMF sends the new NH and the corresponding NCC (also known as the (NH, NCC) parameter pair) to the target base station via a path switching notification (NGAP PATH SWITCH REQUEST ACKNOWLEDGE), enabling the target base station to store the NH and the corresponding NCC, and delete unused NH and the corresponding NCC.
[0062] In the above process, if AMF uses a new K AMF If a new security context is activated, but the UE's context modification process has not yet been successfully executed, the path switching notification may also include a New Security Context Indicator (NSCI). In this case, the AMF can base its notification on the new K... AMFand an uplink non-access stratum (NAS) counter (English can be expressed as COUNT), obtain a new initial K gNB and associate the new initial K gNB with a new NCC value with a value of 0; that is, if K AMF changes, K gNB and the NCC value will change, so that K NG-RAN changes. Then, the AMF will send the new initial K gNB and the associated new NCC as a newly calculated NH and the corresponding NCC to the target base station through the path switching notification; after receiving the path switching notification, the target base station sets the value of the first field (such as keySetChangeIndicator) to true, so that in the subsequent switching process, when the target base station detects that the value of the first field is true, it can immediately perform base station switching or internal CU switching based on the newly calculated NH, so that the newly calculated NH is put into use.
[0063] In summary, in the scenario of inter-station switching, the update of security information will be involved when LTM is performed, and there is a security problem of key leakage due to exposure of security information. In addition, the introduction of the LTM mechanism is to reduce the delay or overhead of RRC signaling, so it is also necessary to reduce the frequency of RRC reconfiguration.
[0064] Based on this, in various embodiments of the present disclosure, in the scenario of inter-station switching, considering a manner similar to the CPAC mechanism, the network side device can pre-configure security information of candidate cells associated with the next hop for the terminal, so that the terminal can continuously perform LTM, that is, after performing a cell switching, the security information (also can be called candidate cell configuration information) of the LTM candidate cell is not released, in this way, the risk of security information exposure can be reduced, and at the same time, the frequency of RRC reconfiguration can be reduced, thereby reducing the signaling overhead.
[0065] The embodiment of the present disclosure provides an information transmission method, as shown in FIG. 2, applied to a terminal, the method comprising step 201.
[0066] Step 201: receiving first information sent by a network device, the first information containing at least security-related information of one or more first candidate cells, the one or more first candidate cells being associated with next hop switching in an LTM process, and the security-related information being used for information transmission between the terminal and the one or more first candidate cells.
[0067] In actual application, the terminal can be referred to as a UE, a user or a user equipment, and the like. The name of the terminal is not limited in the embodiments of the present disclosure, as long as the function thereof is implemented. In addition, the network device can include a network device (such as a base station) or a cell currently accessed by the terminal. In the case where the network device includes a base station, the network device can be referred to as a source base station (expressed in English as source gNB).
[0068] It should be noted that the next hop switching (also referred to as next hop LTM) can be understood as the next switching in the LTM process performed by the terminal. For example, it is assumed that the terminal will be switched from a network device 1 to a network device 2, and then switched from the network device 2 to a network device 3. The above LTM can be referred to as a subsequent LTM (expressed in English as subsequent LTM), that is, the terminal performs switching of more than or equal to two hops. The switching from the network device 1 (which can be referred to as a source base station) to the network device 2 (which can be referred to as a target base station) can be referred to as a current switching, and the switching from the network device 2 to the network device 3 can be referred to as a next hop switching.
[0069] In actual application, before step 201, the network device can determine one or more candidate cells (expressed in English as candidate cells) of a candidate network device (such as a candidate base station (expressed in English as candidate gNB)) associated with the LTM, and send the determined candidate cells to the terminal, so that the terminal can generate security-related information corresponding to the one or more candidate cells, and then obtain a key corresponding to the one or more candidate cells. The one or more candidate cells can be understood as all candidate cells that the terminal can access in the LTM process, and the key is used for information transmission between the terminal and the candidate cell. That is, the terminal can pre-calculate the key corresponding to all candidate cells associated with the LTM process.
[0070] Then, the network device can provide the first information for the terminal when it is determined that the terminal performs the LTM. The one or more first candidate cells can be understood as candidate cells that the terminal can access in the next hop switching. That is, the network device can select one or more first candidate cells associated with the next hop switching from the one or more candidate cells, and obtain the first information based on the selected one or more first candidate cells, so as to provide the first information for the terminal.
[0071] In an embodiment, the receiving of the first information sent by the network device includes: receiving the first information sent by the network device in the case where a first condition is met, and the first condition represents that it is determined that the terminal performs the LTM process.
[0072] In an example, the first information can be received through signaling, and the signaling can include Medium Access Control (MAC) Control Element (CE) signaling. Illustratively, when the first condition is met, the terminal can receive the MAC CE signaling sent by the network device, and the MAC CE signaling carries the first information.
[0073] In an embodiment, the security-related information includes one of the following: second information used to determine a first key; and third information used to determine the second information.
[0074] The second information can include security parameters associated with the one or more first candidate cells (which can be understood as parameters used to calculate the first key corresponding to the next hop switching), and specifically can include NH and / or NCC. Alternatively, the second information can include a parameter difference (which can be referred to as a delta value) associated with the security parameters of the second candidate cell corresponding to the current switching in the LTM process, so that the terminal can determine the security parameters associated with the one or more first candidate cells according to the security parameters of the second candidate cell and the parameter difference, i.e., the second information can include update-related information of the security parameters associated with the second candidate cell. The first key is used for encryption and / or decryption processing of information transmitted between the terminal and the one or more first candidate cells, so as to ensure information transmission between the terminal and the first candidate cells.
[0075] In addition, the third information can include an index (expressed in English as index) associated with the security parameters of the one or more first candidate cells, i.e., through the third information, the terminal can determine (which can also be understood as calculating or obtaining) the second information.
[0076] In actual application, since there are two key generation methods, horizontal derivation and vertical derivation, the key generation method can be defined as vertical derivation in advance, so that the terminal can obtain the same first key as the first candidate cell, thereby ensuring the consistency of the key between the terminal and the first candidate cell when the terminal accesses the first candidate cell.
[0077] In an embodiment, as shown in FIG. 2, the method can further include:
[0078] Step 202: determining a first key corresponding to the one or more first candidate cells by using the first information, the first key being generated based on a vertical derivation method.
[0079] In actual application, in the case that the generation mode of the key is vertical derivation, the terminal can generate the key corresponding to the one or more candidate cells in advance based on the security-related information of the one or more candidate cells in a vertical derivation manner. In this way, after receiving the first information, the terminal can find the key matched with the one or more first candidate cells from the keys corresponding to the one or more candidate cells, thereby obtaining the first key corresponding to the one or more first candidate cells.
[0080] In actual application, in order to improve the security of information transmission, the first network element can select a first algorithm for the security-related information in the process of establishing the initial security context; the first algorithm can be understood as an encryption and / or decryption algorithm, the first network element is at least used for mobility management, and the first network element includes an AMF. The type of the first network element is not limited in the embodiments of the present disclosure, as long as the function is implemented. In addition, the first algorithm can be a calculation rule generated in a random manner, or can be selected based on the encryption and / or decryption algorithm supported by the terminal. The selection manner of the first algorithm is not limited in the embodiments of the present disclosure. In the embodiments of the present disclosure, "A and / or B" means at least one of A and B, that is, there is only A, only B, or A and B.
[0081] For example, in the case that the security-related information includes the second information, and the second information includes NH and NCC, the first network element can select different first algorithms for NH and NCC, that is, select a first algorithm 1 for NH and a first algorithm 2 for NCC; or the first network element can select the same first algorithm for NH and NCC, that is, select a first algorithm 1 for NH and NCC. In addition, for the security-related information of the plurality of first candidate cells, the first network element can select different first algorithms for the security-related information of different first candidate cells, such as selecting a first algorithm 3 for the first candidate cell 1 and a first algorithm 4 for the first candidate cell 2; or select the same first algorithm for the security-related information of different first candidate cells, such as selecting a first algorithm 3 for the first candidate cell 1 and the first candidate cell 2.
[0082] After the selection of the first algorithm is completed, the first network element can perform encryption processing on the security-related information by using the selected first algorithm, and transmit the encrypted security information to the terminal through the network device. At the same time, the first network element can also transmit the selected first algorithm to the terminal through the network device, so that the terminal can perform decryption processing on the encrypted security-related information transmitted subsequently. That is, the first information can also include fourth information, and the fourth information is used to indicate the first algorithm, that is, the fourth information can be understood as an algorithm identifier (such as ID).
[0083] In an embodiment, the method can further comprise: in a case that the security-related information contained in the first information is encrypted, decrypting the encrypted security-related information by using the first algorithm to obtain decrypted security-related information; and determining the first key corresponding to the one or more first candidate cells by using the decrypted security-related information.
[0084] In actual application, for the encrypted security-related information, the terminal can obtain the decrypted security-related information by using the first algorithm, and find the key matching the decrypted security-related information from the keys corresponding to the one or more candidate cells, thereby obtaining the first key corresponding to the one or more first candidate cells.
[0085] Exemplarily, in a case that the first network element selects different first algorithms for the security-related information of different first candidate cells, the terminal can determine the first algorithm corresponding to each encrypted security-related information by using the fourth information, and decrypt the corresponding encrypted security-related information by using the first algorithm, thereby obtaining the decrypted security-related information.
[0086] In actual application, in order to more efficiently find the first key corresponding to the one or more first candidate cells from the keys corresponding to the one or more candidate cells, the network device can provide the terminal with cell information associated with next-hop switching, so that the terminal takes the cell information associated with next-hop switching as an index, thereby quickly finding the first key corresponding to the one or more first candidate cells.
[0087] In an embodiment, the determining the first key corresponding to the one or more first candidate cells by using the first information comprises: receiving fifth information sent by the network device, the fifth information containing at least one of a source cell and a target cell associated with next-hop switching; and determining the first key corresponding to the one or more first candidate cells by using the fifth information and the security-related information contained in the first information.
[0088] In actual application, the terminal can generate a candidate list associated with the one or more candidate cells for the one or more candidate cells, which can include security-related information and corresponding keys for switching from one candidate cell to another candidate cell in the LTM process. For example, in the case of N candidate cells, the candidate list includes N*N security-related information and corresponding keys; where N is an integer greater than or equal to 1, the first column in the candidate list is used to indicate the security-related information and corresponding keys when switching from candidate cell 1 in the N candidate cells to the other N-1 candidate cells in the N candidate cells, and the second column in the candidate list is used to indicate the corresponding security-related information when switching from candidate cell 2 in the N candidate cells to the other N-1 candidate cells in the N candidate cells.
[0089] As can be seen from the above description, the index of the candidate list can be understood as the source cell and the target cell associated with each hop switching; in this case, the terminal uses the fifth information as the index to quickly find the corresponding security-related information from the candidate list; in the case that the found security-related information matches the security-related information, the first key corresponding to the one or more first candidate cells can be obtained from the candidate list.
[0090] For example, in the case that the fifth information includes the source cell associated with the next hop switching, the terminal can autonomously determine the target cell associated with the next hop switching, and then find the corresponding security-related information from the candidate list based on the source cell included in the fifth information and the determined target cell. In the case that the fifth information includes the target cell associated with the next hop switching, the terminal can autonomously determine the source cell associated with the next hop switching, and then find the corresponding security-related information from the candidate list based on the target cell included in the fifth information and the determined source cell. In the case that the fifth information includes the target cell and the source cell associated with the next hop switching, the terminal can find the corresponding security-related information from the candidate list based on the target cell and the source cell included in the fifth information.
[0091] In actual application, after step 202, the terminal can receive the ninth information sent by the network device to trigger the execution of the LTM; after the terminal completes the current switching in the LTM process (such as completing RACH access or sending uplink data), the terminal can send the tenth information to the first network element through the network device, so that the first network element judges whether the security-related information of the one or more first candidate cells needs to be updated based on the tenth information, and the tenth information includes the target cell identifier associated with the current switching.
[0092] Here, in a case that the first network element updates the security-related information of the one or more first candidate cells, the terminal can receive the updated security-related information of the one or more first candidate cells through the network device, and perform next-hop switching based on the updated security-related information of the one or more first candidate cells; in a case that the first network element does not update the security-related information of the one or more first candidate cells, the terminal can perform next-hop switching based on the security-related information of the one or more first candidate cells.
[0093] In actual application, the network device can provide the first information for the terminal before configuring the LTM for the terminal.
[0094] In an embodiment, the receiving the first information sent by the network device comprises: receiving the first information sent by the network device in a case that a second condition is satisfied, the second condition representing that the LTM configuration is determined to be issued to the terminal.
[0095] The second condition can be understood as that the network device decides to configure the LTM for the terminal, i.e., before configuring the LTM for the terminal, the network device interacts with the first network element to prepare to issue the LTM configuration to the terminal. In addition, in a case that the second condition is satisfied, the terminal can receive the first information through signaling, and the signaling can include RRC signaling. For example, in a case that the second condition is satisfied, the terminal receives RRC signaling sent by the network device, and the RRC signaling carries the first information.
[0096] In actual application, before configuring the LTM for the terminal, the generation manner of the key can be defined as vertical derivation or horizontal derivation, so that the terminal can obtain the same first key as the first candidate cell in the future, thereby ensuring the information transmission between the terminal and the first candidate cell.
[0097] In an embodiment, the method can further comprise: determining the first key corresponding to the one or more first candidate cells by using the first information, the first key being generated based on a vertical derivation or a horizontal derivation.
[0098] Here, in a case that the generation manner of the key is defined as vertical derivation, the terminal can obtain the first key corresponding to the one or more first candidate cells by using the first information through the vertical derivation; in a case that the generation manner of the key is defined as horizontal derivation, the terminal can obtain the first key corresponding to the one or more first candidate cells by using the first information through the horizontal derivation.
[0099] Then, the terminal can receive ninth information sent by the network device to trigger the execution of LTM; after completing the current handover in the LTM process, the terminal can switch from a source cell associated with the current handover to a target cell. In this case, if the first key corresponding to the one or more first candidate cells has been obtained, the terminal can perform next-hop handover based on the first key corresponding to the one or more first candidate cells; if the first key corresponding to the one or more first candidate cells has not been obtained, the terminal can perform next-hop handover using a second key corresponding to the target cell associated with the current handover, and after accessing the first candidate cell, obtain the corresponding first key through the accessed first candidate cell, and perform information transmission with the accessed first candidate cell using the obtained first key.
[0100] Exemplarily, when the network side decides to configure LTM for the terminal, the terminal can receive eleventh information sent by the network device, the eleventh information containing a second key corresponding to a target cell associated with the current handover, the second key being generated based on a vertical derivation or a horizontal derivation. After switching from a first candidate cell 1 of a network device 1 to a first candidate cell 2 of a network device 2, the terminal does not release the LTM configuration. Then, before switching from the first candidate cell 2 to a first candidate cell 3 of a network device 3, the terminal receives RRC signaling (the RRC signaling carries first information) sent by the network device 2, thereby obtaining the first key corresponding to the first candidate cell 3, that is, the RRC reconfiguration occurs before the next-hop handover; or, after switching from the first candidate cell 2 to the first candidate cell 3, the terminal receives RRC signaling (the RRC signaling carries first information) sent by the network device 3, thereby obtaining the first key corresponding to the first candidate cell 3, and performing information transmission with the first candidate cell 3 using the first key corresponding to the first candidate cell 3, that is, the RRC reconfiguration occurs after the next-hop handover.
[0101] Correspondingly, the embodiments of the present disclosure also provide an information transmission method, as shown in FIG. 3, applied to a network device, the method comprising the following steps:
[0102] Step 303: sending first information to a terminal, the first information containing security-related information of one or more first candidate cells, the one or more first candidate cells being associated with next-hop handover in an LTM process, the security-related information being used for information transmission between the terminal and the one or more first candidate cells.
[0103] In actual application, before step 303, the network device can determine one or more candidate cells of the candidate network device associated with the LTM, and obtain the security-related information corresponding to the one or more candidate cells through the first network element, so as to obtain the key corresponding to the one or more candidate cells, and then send the key corresponding to the one or more candidate cells to the corresponding candidate cell, so as to be used in subsequent access of the terminal to the candidate cell. That is, each candidate cell can obtain the key corresponding to the corresponding candidate cell through the network device.
[0104] Exemplarily, in a manner similar to conditional handover (CHO), before the network device requests the one or more determined candidate cells to configure the LTM, the network device can generate the key corresponding to the candidate cell when switching from the current source cell to the candidate cell through the first network element, and send the generated key to the corresponding candidate cell, so as to be used when the terminal switches to the candidate cell through the LTM.
[0105] In actual application, before step 303, the network device needs to obtain the first information.
[0106] Based on this, in an embodiment, the method can further include steps 301-302.
[0107] Step 301: sending sixth information to a first network element, the sixth information being used to request the first information, and the first network element being used for at least mobility management.
[0108] Step 302: receiving the first information sent by the first network element.
[0109] In actual application, the network device can obtain the first information from the first network element. Specifically, the network device can send the sixth information to the first network element after determining (which can also be understood as adding) the one or more candidate cells. The network device can also send the sixth information to the first network element before determining that the terminal performs the LTM, that is, the network device can inform the first network element that the LTM is about to occur, so as to obtain the first information from the first network element. In another example, the network device can also send the sixth information to the first network element after determining that the terminal performs the LTM, that is, the network device can inform the first network element that the terminal is about to switch from the source cell to a specific first candidate cell, so as to obtain the first information from the first network element and update the security-related information stored in the first network element.
[0110] Here, in order to obtain the first information more quickly, the network device can send the one or more candidate cells to the first network element after determining the one or more candidate cells, so that the first network element generates security-related information corresponding to the one or more candidate cells in advance. In this way, after the first network element receives the sixth information, the first information can be obtained from the security-related information generated in advance, and the first information is fed back to the network device.
[0111] Based on this, in an embodiment, the method can further include: sending seventh information to the first network element, wherein the seventh information is used to indicate one or more candidate cells associated with the LTM process.
[0112] In actual application, after obtaining the first information, the network device can provide the first information for the terminal in different cases; wherein the first information can be provided when it is determined to perform LTM for the terminal.
[0113] In an embodiment, the sending of the first information to the terminal includes: determining that a first condition is satisfied, the first condition representing that it is determined to perform LTM for the terminal; and sending the first information to the terminal.
[0114] The first information is used to determine a first key corresponding to the one or more first candidate cells, and the first key is generated based on a vertical derivation manner.
[0115] In actual application, in order to improve the security of information transmission, the first network element can select a security algorithm for security-related information contained in the first information, and perform encryption processing on the security-related information by using the selected security algorithm, so as to realize the secure transmission of information. That is, in the case where the security-related information contained in the first information is encrypted, the first information can further contain fourth information, and the fourth information is used to indicate a first algorithm, and the first algorithm is used to perform decryption processing on the encrypted security-related information.
[0116] Here, the first network element can select different first algorithms for different security-related information of different first candidate cells; in this case, different first algorithms can be indicated by the fourth information, so that in the subsequent LTM process, the first candidate cell can perform decryption processing on the encrypted security-related information corresponding to the first candidate cell based on the different first algorithms and obtain the corresponding key, and then realize the secure transmission between the candidate cell and the terminal.
[0117] Exemplarily, assuming that the first network element selects the first algorithm 3 for the first candidate cell 1 of the network device 1 and selects the first algorithm 4 for the first candidate cell 2 of the network device 2, when switching from the first candidate cell 1 to the first candidate cell 2, the first candidate cell 1 can determine the first algorithm 3 based on the fourth information, and then decrypt the security-related information corresponding to the first candidate cell 1 which is processed by encryption using the first algorithm 3 and obtain the corresponding key; when switching from the first candidate cell 2 to the first candidate cell 3 of the network device 3, the first candidate cell 2 can determine the first algorithm 4 based on the fourth information, and then decrypt the security-related information corresponding to the first candidate cell 2 which is processed by encryption using the first algorithm 4 and obtain the corresponding key. In this way, the first candidate cell 1 associated with the current switching can be prevented from learning the security-related information of the first candidate cell 3 associated with the next hop, so as to further protect the security of the key.
[0118] In actual application, after sending the first information, the network device can provide the terminal with cell information associated with the next-hop switching, so that the terminal takes the cell information associated with the next-hop switching as an index, thereby quickly obtaining the first key corresponding to the one or more first candidate cells.
[0119] Based on this, in an embodiment, the method can further include: sending fifth information to the terminal, the fifth information containing at least one of a source cell and a target cell associated with the next-hop switching.
[0120] In addition, before configuring the LTM for the terminal, the network device can provide the terminal with the first information.
[0121] In an embodiment, the sending of the first information to the terminal includes: determining that a second condition is satisfied, the second condition representing that the LTM configuration is determined to be issued to the terminal; and sending the first information to the terminal.
[0122] The first information is used to determine the first key corresponding to the one or more first candidate cells, and the first key is generated based on a vertical derivation or a horizontal derivation.
[0123] In actual application, in order to enable the first candidate cell to learn the corresponding first key, the network device can provide the one or more first candidate cells with corresponding security-related information, so that the one or more first candidate cells can save the security-related information and obtain the corresponding first key based on the security-related information.
[0124] Exemplarily, before the LTM execution, the network device sends corresponding security-related information to the one or more first candidate cells; or, after the LTM execution, the network device sends corresponding security-related information to a target candidate cell corresponding to the current handover; or, before the LTM execution, the network device sends security-related information of a source cell to a target candidate cell corresponding to the current handover, and the target candidate cell determines security-related information of the target candidate cell based on the security information of the source cell.
[0125] Correspondingly, the embodiment of the disclosure further provides an information transmission method, as shown in FIG. 4, applied to a first network element, the method comprising steps 401-402.
[0126] Step 401: receiving sixth information sent by a network device, the sixth information being used for requesting first information, the first network element being used for at least mobility management, the first information containing at least security-related information of one or more first candidate cells, the one or more first candidate cells being associated with next-hop switching in an LTM process, and the security-related information being used for information transmission between the terminal and the one or more first candidate cells;
[0127] Step 402: sending the first information to the network device.
[0128] In actual application, before step 402, the first network element needs to generate the first information; wherein, the first information can be generated after receiving the sixth information.
[0129] Based on this, in an embodiment, the method can further comprise: generating the first information in the case of receiving the sixth information.
[0130] In actual application, the first network element can also generate a candidate list in advance before receiving the sixth information, so as to subsequently find the first information from the candidate list.
[0131] Based on this, in an embodiment, the method can further comprise: receiving seventh information sent by the network device, wherein the seventh information is used for indicating one or more candidate cells associated with the LTM process; generating eighth information containing the one or more candidate cells and corresponding security-related information by using the seventh information; and finding security-related information matching the one or more first candidate cells from the eighth information to obtain the first information in the case of receiving the sixth information.
[0132] In actual application, after receiving the seventh information, the first network element can generate and save the eighth information, which can be understood as security-related information corresponding to the cell selection when switching from one candidate cell to another candidate cell in the LTM process; wherein different first algorithms can be selected for the security-related information corresponding to different candidate cells.
[0133] Here, for the eighth information, the first network element can associate the eighth information with the security-related information of the source cell corresponding to the current switching to obtain updated eighth information; in addition, the first network element can also update the eighth information using the related information of the first candidate cell (such as at least one of the PCI and frequency point information of the first candidate cell) to obtain updated eighth information. Then, the first network element can save the updated eighth information.
[0134] In actual application, in the case of receiving the sixth information, the first network element can find the security-related information matching the one or more first candidate cells from the saved eighth information; if the corresponding first algorithm is not selected, the first network element can directly return the found security-related information to the network device; if the corresponding first algorithm is selected, the first network element can use the selected first algorithm to encrypt the found security-related information, and return the first information containing the encrypted security-related information and the fourth information to the network device.
[0135] In actual application, in order to enable the first candidate cell to know the corresponding first key, the first network element can also provide the corresponding security-related information to the one or more first candidate cells, so that the one or more first candidate cells can save the security-related information and obtain the corresponding first key based on the security-related information.
[0136] The information transmission method provided by the embodiments of the present disclosure is that a terminal receives first information sent by a network device, the first information at least containing security-related information of one or more first candidate cells, the one or more first candidate cells being associated with next-hop switching in the LTM process, and the security-related information being used for information transmission between the terminal and the one or more first candidate cells. The technical solution provided by the embodiments of the present disclosure is that in the execution process of the LTM, the network side device pre-provides the terminal with security information of the candidate cell associated with the next-hop LTM (which can also be understood as the next cell switching), so that the terminal can automatically perform the next-hop LTM, without the need to update the security information through the network side device each time, which can reduce the risk of security information exposure, and also can reduce the signaling (such as RRC signaling) overhead.
[0137] The present disclosure will be described in further detail below with reference to application examples.
[0138] In the scenario of inter-station handover, there is a security problem of key leakage due to the update of security information when performing continuous LTM. If the required key is issued in advance, there may also be a problem of key exposure, and at the same time, there is a problem of large signaling overhead, i.e., the above problems cannot be solved. That is, during the execution of the related LTM, there is a risk of security information exposure, thereby causing the security problem of key leakage.
[0139] Therefore, in the application examples of the present disclosure, the network side pre-configures the security parameters (i.e., the above-mentioned security-related information) for the next-hop LTM for the UE, so that the UE can automatically perform the next-hop LTM (i.e., the above-mentioned next-hop handover) based on the security parameters.
[0140] Specifically, the process of the UE performing LTM is as shown in FIG. 5, including the following steps:
[0141] Step 501: The UE sends a measurement report request (Measurement report in English) to the source cell (source cell in English) of the base station 1 (i.e., the above-mentioned network device) to request the source cell to perform measurement on the UE;
[0142] Step 502: After receiving the measurement report request, the source cell can perform measurement on the UE and obtain the measurement result; based on the measurement result, the LTM result (LTM decision in English) is determined;
[0143] Here, in the case where the LTM result indicates that the LTM is configured for the UE, the source cell can determine the candidate cell (i.e., the above-mentioned one or more candidate cells) associated with the LTM, which specifically includes candidate cell 1 and candidate cell 2;
[0144] Step 503: The source cell sends an LTM configuration request (LTM candidate request in English) to the candidate cell 1 to request to configure the candidate cell for LTM; after receiving the LTM configuration request, the candidate cell 1 feeds back an acknowledgement character (ACK, Acknowledge character) to the source cell;
[0145] Here, after receiving the ACK, the source cell generates a key for switching from the source cell to the candidate cell 1, and sends the generated key to the candidate cell 1 for use when the UE switches to the candidate cell 1.
[0146] Step 504: The source cell sends an LTM configuration request to the candidate cell 2 to request to configure the LTM candidate cell; after receiving the LTM configuration request, the candidate cell 2 feeds back an ACK to the source cell;
[0147] Here, after receiving the ACK, the source cell generates the key for switching from the source cell to the candidate cell 2 by vertical derivation, and sends the generated key to the candidate cell 2 for use when the UE switches to the candidate cell 2. That is, each candidate cell has its own key.
[0148] In addition, the UE calculates the key used when accessing each candidate cell based on the security parameter of the source cell; wherein the UE can generate the key by vertical derivation.
[0149] Then, the source cell can perform step 505 or step 510 as needed.
[0150] Step 505: The source cell issues an LTM configuration to the UE;
[0151] Step 506: The source cell decides to perform LTM for the UE (i.e. the first condition described above), and performs step 507;
[0152] Step 507: The source cell sends a security information request (i.e. the sixth information described above) to the AMF (i.e. the first network element described above);
[0153] Step 508: After receiving the security information request, the AMF sends security information (i.e. the first information described above) to the source cell;
[0154] The security information includes the security parameters (also referred to as vertical derivation parameters) used when calculating the next hop LTM key after the current handover is completed, i.e. NH and NCC. For example, the security parameters can be a delta value based on the security parameters of the current source cell, or the security parameters used by the next hop LTM (i.e. the second information described above), or a pair of parameters (i.e. the third information described above) used to obtain the security parameters of the next hop LTM, such as a set of indexes. Taking NCC as an example, the AMF can perform an AND operation on NCC to obtain a specific NCC or a delta value of NCC. That is, the security parameters of each hop LTM will change.
[0155] Here, the AMF can select the encryption and decryption algorithm for the security information of the UE, and in another example, the AMF can also choose not to encrypt the security information. The command can select the same encryption and decryption algorithm or different encryption and decryption algorithms for NH and NCC when the encryption and decryption algorithm is selected.
[0156] Step 509: After receiving the security information, the source cell sends an LTM command to the UE to inform the UE to perform LTM, and the LTM command carries the security information.
[0157] Here, the source cell sends the security information to the UE through a MAC CE; that is, the LTM command is sent in the form of a MAC CE, and the MAC CE can carry one or two parameters in the security parameters or information for security parameter update.
[0158] After each LTM, the UE, the current source cell and the AMF need to update the stored security information to update the key derivation to perform the next hop LTM without RRC reconfiguration for security information update.
[0159] In addition, after deciding to switch to a candidate cell, the source cell can also generate security information by itself and inform the AMF of the generated security information to enable the AMF to update the stored security information.
[0160] Step 510: The source cell sends a security information request to the AMF.
[0161] Here, after the source cell determines the LTM candidate cell, the source cell can inform the AMF of all LTM candidate cells (i.e., the seventh information described above) to enable the AMF to generate a candidate list (i.e., the eighth information described above) based on the provided LTM candidate cells. Exemplarily, assuming that there are N candidate cells, the AMF can generate N*N security information; in the case where the current source cell can be configured as a candidate cell, the AMF can generate N*(N+1) security information; in addition, the security information corresponding to different candidate cells can be obtained based on different encryption algorithms.
[0162] Then, when the source cell determines that the UE needs to switch to a candidate cell, the source cell can send a security information request to the AMF, and the security information request carries at least one of the target cell and the source cell that needs to be switched (i.e., the fifth information described above).
[0163] Step 511: After receiving the security information request, the AMF sends security information to the source cell.
[0164] Here, the AMF can find the security information of the candidate cell corresponding to the security information request from the candidate list and send the found security information to the source cell. In the case where the security information is encrypted, the AMF can also send an algorithm ID (i.e., the fourth information described above) to the source cell, and the algorithm ID is used to indicate the encryption algorithm.
[0165] Step 512: After receiving the security information, the source cell sends the LTM configuration to the UE;
[0166] Step 513: The source cell decides to perform LTM for the UE, and performs step 514;
[0167] Step 514: The source cell sends an LTM command to the UE, and the LTM command carries an algorithm ID (English can be expressed as Algorithm ID);
[0168] The LTM command can also carry the source cell ID and the target cell ID (English can be expressed as target cell).
[0169] It should be noted that steps 505 to 509 and steps 510 to 514 can be understood as a parallel scheme; the source cell can select any one of the two schemes to provide security information for the UE.
[0170] Step 515: After receiving the LTM command, the UE performs LTM and switches to the candidate cell 1;
[0171] Here, when the UE receives the LTM command, the corresponding security information can be obtained from the security information generated by the UE based on the source cell and the target cell, and the algorithm ID is decrypted to obtain the security information corresponding to the next hop LTM.
[0172] Then, the UE can switch from the source cell to the candidate cell 1.
[0173] Step 516: The candidate cell 1 sends a security information update indication (English can be expressed as Security information update indication) to the AMF to update the security information.
[0174] When the UE completes the LTM, the candidate cell 1 can update the security information of the candidate cell 1 through the AMF. Specifically, the UE can send a path switch request (English can be expressed as path switch request) to the AMF, and the path switch request carries the candidate cell 1 identifier; the AMF receives the path switch request, determines the security information of the next hop LTM based on the candidate cell 1, and decides whether to update; if it needs to be updated, the AMF can update the security information of the next hop LTM, and configure it to the UE through the candidate cell 1.
[0175] In the application example of the present disclosure, the security information is provided to the UE in advance through RRC reconfiguration or MAC CE, so that the UE can calculate the key based on the security information, thereby realizing continuous LTM; in the above process, the exposure of security information between base stations can be avoided, and the frequency of RRC reconfiguration can be reduced.
[0176] To implement the method of the embodiments of the present disclosure, the embodiments of the present disclosure further provide an information transmission apparatus arranged on a terminal, as shown in FIG. 6, which comprises: a first receiving unit 601 configured to receive first information sent by a network device, wherein the first information comprises at least security-related information of one or more first candidate cells, the one or more first candidate cells being associated with next-hop switching in an LTM process, and the security-related information being used for information transmission between the terminal and the one or more first candidate cells.
[0177] In an embodiment, the first receiving unit 601 is configured to receive the first information sent by the network device in a case where a first condition is met, wherein the first condition represents a determination that the terminal performs the LTM.
[0178] In an embodiment, the apparatus can further comprise a determining unit 602. The determining unit 602 is configured to determine, by using the first information, a first key corresponding to the one or more first candidate cells, wherein the first key is generated based on a vertical derivation manner.
[0179] In an embodiment, the first information further comprises fourth information used for indicating a first algorithm; and the determining unit 602 is further configured to, in a case where the security-related information contained in the first information is encrypted, perform decryption processing on the encrypted security-related information by using the first algorithm to obtain decrypted security-related information, and determine the first key corresponding to the one or more first candidate cells by using the decrypted security-related information.
[0180] In an embodiment, the first receiving unit 601 is configured to receive fifth information sent by the network device, the fifth information comprising at least one of a source cell and a target cell associated with next-hop switching; and the determining unit 602 is configured to determine the first key corresponding to the one or more first candidate cells by using the fifth information and the security-related information contained in the first information.
[0181] In an embodiment, the first receiving unit 601 is configured to receive the first information sent by the network device in a case where a second condition is met, wherein the second condition represents a determination that an LTM configuration is issued to the terminal.
[0182] In an embodiment, the determining unit 602 is further configured to determine, by using the first information, a first key corresponding to the one or more first candidate cells, the first key being generated based on a vertical derivation manner or a horizontal derivation manner.
[0183] In practice, the first receiving unit 601 can be implemented by a communication interface in the information transmission device; and the determining unit 602 can be implemented by a processor in the information transmission device.
[0184] To implement the method of the embodiments of the present disclosure, the embodiments of the present disclosure further provide an information transmission device arranged on a network device, as shown in FIG. 7, the device comprises: a first sending unit 701 configured to send first information to a terminal, wherein the first information comprises security-related information of one or more first candidate cells, the one or more first candidate cells are associated with next-hop switching in an LTM process, and the security-related information is used for information transmission between the terminal and the one or more first candidate cells.
[0185] In an embodiment, the first sending unit 701 is configured to: determine that a first condition is met, wherein the first condition represents that it is determined that the terminal performs LTM; and send the first information to the terminal.
[0186] In an embodiment, the first sending unit 701 is further configured to: send fifth information to the terminal, wherein the fifth information comprises at least one of a source cell and a target cell associated with next-hop switching, and the fifth information and the security-related information contained in the first information are used to determine the first key.
[0187] In an embodiment, the first sending unit 701 is configured to: determine that a second condition is met, wherein the second condition represents that it is determined to issue an LTM configuration to the terminal; and send the first information to the terminal.
[0188] In an embodiment, the device can further comprise: a third sending unit 702 and a third receiving unit 703; wherein the third sending unit 702 is configured to send sixth information to a first network element, wherein the sixth information is used to request the first information, and the first network element is used for at least mobility management; and the third receiving unit 703 is configured to receive the first information sent by the first network element.
[0189] In an embodiment, the third sending unit 702 is further configured to send seventh information to the first network element, wherein the seventh information is used to indicate one or more candidate cells associated with the LTM process.
[0190] In practice, the first sending unit 701 can be implemented by a communication interface in the information transmission device in combination with a processor; and the third sending unit 702 and the third receiving unit 703 can be implemented by a communication interface in the information transmission device.
[0191] To implement the method of the embodiments of the present disclosure, the embodiments of the present disclosure further provide an information transmission apparatus arranged on a first network element, as shown in FIG. 8, the apparatus comprises: a second receiving unit 801 configured to receive sixth information sent by a network device, wherein the sixth information is used for requesting first information, the first network element is used for at least mobility management, the first information comprises at least security-related information of one or more first candidate cells, the one or more first candidate cells are associated with next-hop switching in an LTM process, and the security-related information is used for information transmission between the terminal and the one or more first candidate cells; and a second sending unit 802 configured to send the first information to the network device.
[0192] In an embodiment, the apparatus can further comprise a generating unit. The generating unit is configured to generate the first information upon receiving the sixth information.
[0193] In an embodiment, the second receiving unit 801 is further configured to receive seventh information sent by the network device, wherein the seventh information is used for indicating one or more candidate cells associated with the LTM process; the generating unit is further configured to generate eighth information by using the seventh information, the eighth information comprises the one or more candidate cells and corresponding security-related information; and find the security-related information matching the one or more first candidate cells from the eighth information to obtain the first information upon receiving the sixth information.
[0194] In actual application, the second receiving unit 801 and the second sending unit 802 can be implemented by a communication interface in the information transmission apparatus; and the generating unit can be implemented by a processor in the information transmission apparatus.
[0195] It should be noted that: the information transmission apparatus provided by the above embodiments is only taken as an example for illustrating the division of the above program modules in the information transmission, and in actual application, the above processing can be completed by different program modules according to needs, that is, the internal structure of the apparatus is divided into different program modules to complete all or part of the above processing. In addition, the information transmission apparatus and the information transmission method provided by the above embodiments belong to the same concept, and the specific implementation process is shown in the method embodiments, which will not be repeated here.
[0196] Based on the hardware implementation of the above program modules, and in order to implement the method on the terminal side of the embodiments of the present disclosure, the embodiments of the present disclosure further provide a terminal, as shown in FIG. 9, the terminal 900 comprises:
[0197] a first communication interface 901 capable of information interaction with a network device;
[0198] The first processor 902 is connected with the first communication interface 901 to realize information interaction with a network device, and is used for running a computer program to execute the method provided by one or more technical solutions of the terminal.
[0199] The first memory 903 stores the computer program.
[0200] Specifically, the first communication interface 901 is configured to receive first information sent by a network device, wherein the first information at least contains security-related information of one or more first candidate cells, the one or more first candidate cells are associated with next-hop switching in an LTM process, and the security-related information is used for information transmission between the terminal and the one or more first candidate cells.
[0201] In an embodiment, the first communication interface 901 is configured to receive the first information sent by the network device in a case where a first condition is met, and the first condition represents that it is determined that the terminal performs the LTM.
[0202] In an embodiment, the first processor 902 is configured to determine a first key corresponding to the one or more first candidate cells by using the first information, wherein the first key is generated based on a vertical derivation manner.
[0203] In an embodiment, the first information further contains fourth information used for indicating a first algorithm, and the first processor 902 is further configured to, in a case where the security-related information contained in the first information is encrypted, perform decryption processing on the encrypted security-related information by using the first algorithm to obtain decrypted security-related information, and determine the first key corresponding to the one or more first candidate cells by using the decrypted security-related information.
[0204] In an embodiment, the first communication interface 901 is configured to receive fifth information sent by the network device, wherein the fifth information contains at least one of a source cell and a target cell associated with next-hop switching; and the first processor 902 is configured to determine the first key corresponding to the one or more first candidate cells by using the fifth information and the security-related information contained in the first information.
[0205] In an embodiment, the first communication interface 901 is configured to receive the first information sent by the network device in a case where a second condition is met, and the second condition represents that an LTM configuration is issued to the terminal.
[0206] In an embodiment, the first processor 902 is further configured to determine, by using the first information, a first key corresponding to the one or more first candidate cells, wherein the first key is generated based on a vertical derivation or a horizontal derivation.
[0207] It should be noted that the specific processing procedures of the first processor 902 and the first communication interface 901 can be understood with reference to the above method.
[0208] Of course, in actual applications, various components in the terminal 900 are coupled together through the bus system 904. It can be understood that the bus system 904 is used to realize the connection and communication between the components. In addition to the data bus, the bus system 904 also includes a power bus, a control bus, and a status signal bus. However, for the purpose of clear illustration, various buses are marked as the bus system 904 in FIG. 9.
[0209] The first memory 903 in the embodiments of the present disclosure is used to store various types of data to support the operation of the terminal 900. Examples of these data include any computer programs used for operation on the terminal 900.
[0210] The method disclosed in the above embodiments of the present disclosure can be applied to the first processor 902 or implemented by the first processor 902. The first processor 902 can be an integrated circuit chip with signal processing capability. In the implementation process, each step of the above method can be completed by the integrated logic circuit of hardware or the instruction in the form of software in the first processor 902. The first processor 902 described above can be a general-purpose processor, a digital signal processor (DSP), or other programmable logic device, discrete gate or transistor logic device, discrete hardware component, etc. The first processor 902 can implement or execute the disclosed methods, steps, and logic block diagrams in the embodiments of the present disclosure. The general-purpose processor can be a microprocessor or any conventional processor, etc. In combination with the steps of the method disclosed in the embodiments of the present disclosure, the hardware decoding processor can be directly embodied as a hardware decoding processor to complete, or a combination of hardware and software modules in the decoding processor to complete. The software module can be located in the storage medium, which is located in the first memory 903, and the first processor 902 reads the information in the first memory 903, and combines the hardware to complete the steps of the above method.
[0211] In an exemplary embodiment, the terminal 900 can be implemented by one or more Application Specific Integrated Circuits (ASICs), DSPs, Programmable Logic Devices (PLDs), Complex Programmable Logic Devices (CPLDs), Field-Programmable Gate Arrays (FPGAs), general-purpose processors, controllers, microcontrollers (MCUs), microprocessors (Microprocessors), or other electronic elements for executing the foregoing methods.
[0212] Based on the hardware implementation of the foregoing program modules, and in order to implement the method on the network device side of the embodiments of the present disclosure, the embodiments of the present disclosure further provide a network device, as shown in FIG. 10, the network device 1000 comprises:
[0213] a second communication interface 1001 capable of information interaction with a terminal and a first network element;
[0214] a second processor 1002 connected with the second communication interface 1001 to realize information interaction with a terminal and a first network element, for running a computer program, and executing the method provided by one or more technical solutions on the network device side described above; and
[0215] a second memory 1003, wherein the computer program is stored in the second memory 1003.
[0216] Specifically, the second communication interface 1001 is configured to send first information to a terminal, wherein the first information contains security-related information of one or more first candidate cells, the one or more first candidate cells are associated with next-hop switching in the LTM process, and the security-related information is used for information transmission between the terminal and the one or more first candidate cells.
[0217] In an embodiment, the second processor 1002 is configured to determine that a first condition is satisfied, wherein the first condition represents that it is determined that the terminal performs LTM; and the second communication interface 1001 is configured to send the first information to the terminal.
[0218] In an embodiment, the second communication interface 1001 is further configured to send fifth information to the terminal, wherein the fifth information contains at least one of a source cell and a target cell associated with next-hop switching, and the fifth information and the security-related information contained in the first information are used to determine the first key.
[0219] In an embodiment, the second processor 1002 is configured to determine that a second condition is satisfied, the second condition representing that the terminal is determined to be configured with the LTM; and the second communication interface 1001 is configured to send the first information to the terminal.
[0220] In an embodiment, the second communication interface 1001 is further configured to send sixth information to a first network element, wherein the sixth information is used to request the first information, and the first network element is used for at least mobility management; and receive the first information sent by the first network element.
[0221] In an embodiment, the second communication interface 1001 is further configured to send seventh information to a first network element, wherein the seventh information is used to indicate one or more candidate cells associated with the LTM.
[0222] It should be noted that the specific processing procedures of the second communication interface 1001 and the second processor 1002 can be understood with reference to the above method.
[0223] Of course, in actual application, various components in the network device 1000 are coupled together through the bus system 1004. It can be understood that the bus system 1004 is used to realize the connection and communication between the components. The bus system 1004 includes not only a data bus, but also a power bus, a control bus and a status signal bus. However, in order to clearly illustrate, various buses are marked as the bus system 1004 in FIG. 10.
[0224] The second memory 1003 in the embodiment of the present disclosure is used to store various types of data to support the operation of the network device 1000. Examples of these data include: any computer programs used to operate on the network device 1000.
[0225] The method disclosed in the embodiments of the present disclosure can be applied to the second processor 1002 or implemented by the second processor 1002. The second processor 1002 can be an integrated circuit chip with signal processing capability. In the implementation process, each step of the above method can be completed by integrated logic circuits of hardware in the second processor 1002 or instructions in the form of software. The second processor 1002 described above can be a general processor, a DSP, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The second processor 1002 can implement or execute the disclosed methods, steps and logic block diagrams in the embodiments of the present disclosure. The general processor can be a microprocessor or any conventional processor, etc. In combination with the steps of the method disclosed in the embodiments of the present disclosure, the hardware decoding processor can be directly embodied to execute the steps of the foregoing method, or the combination of hardware and software modules in the decoding processor can be executed. The software module can be located in the storage medium, which is located in the second memory 1003, and the second processor 1002 reads the information in the second memory 1003 to complete the steps of the foregoing method in combination with the hardware.
[0226] In the exemplary embodiments, the network device 1000 can be implemented by one or more ASICs, DSPs, PLDs, CPLDs, FPGAs, general-purpose processors, controllers, MCUs, microprocessors, or other electronic elements for executing the foregoing method.
[0227] Based on the hardware implementation of the above program module, and in order to implement the method of the first network element side in the embodiments of the present disclosure, the embodiments of the present disclosure further provide a first network element, as shown in FIG. 11, the first network element 1100 includes:
[0228] The third communication interface 1101 can interact with the network device to exchange information;
[0229] The third processor 1102 is connected with the third communication interface 1101 to realize the information interaction with the network device, and is used to run the computer program to execute the method provided by one or more technical solutions of the first network element side; and
[0230] The third memory 1103 stores the computer program.
[0231] Specifically, the third communication interface 1101 is configured to receive sixth information sent by the network device, where the sixth information is used to request first information, the first network element is used for at least mobility management, the first information at least contains security-related information of one or more first candidate cells, the one or more first candidate cells are associated with next hop switching in the LTM process, and the security-related information is used for information transmission between the terminal and the one or more first candidate cells; and the third communication interface 1101 is configured to send the first information to the network device.
[0232] In an embodiment, the third processor 1102 is configured to generate the first information in a case where the sixth information is received.
[0233] In an embodiment, the third communication interface 1101 is configured to receive seventh information sent by the network device, where the seventh information is used to indicate one or more candidate cells associated with the LTM; the third processor 1102 is configured to generate eighth information by using the seventh information, where the eighth information contains the one or more candidate cells and corresponding security-related information; and in a case where the sixth information is received, the third processor 1102 is configured to find, from the eighth information, security-related information matching the one or more first candidate cells to obtain the first information.
[0234] It should be noted that the specific processing process of the third communication interface 1101 and the third processor 1102 can be understood with reference to the above method.
[0235] In actual application, various components in the first network element 1100 are coupled together through the bus system 1104. It can be understood that the bus system 1104 is used to realize the connection and communication between the components. The bus system 1104 includes not only a data bus, but also a power supply bus, a control bus and a status signal bus. However, for the purpose of clear illustration, various buses are marked as the bus system 1104 in FIG. 11.
[0236] The third memory 1103 in the embodiment of the present disclosure is used to store various types of data to support the operation of the first network element 1100. Examples of the data include any computer programs used for operation on the first network element 1100.
[0237] The method disclosed by the embodiments of the present disclosure can be applied to the third processor 1102 or implemented by the third processor 1102. The third processor 1102 can be an integrated circuit chip with signal processing capability. In the implementation process, each step of the above method can be completed by the integrated logic circuit of hardware in the third processor 1102 or the instruction in the form of software. The third processor 1102 disclosed above can be a general processor, a DSP, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The third processor 1102 can implement or execute the methods, steps and logic block diagrams disclosed in the embodiments of the present disclosure. The general processor can be a microprocessor or any conventional processor, etc. In combination with the steps of the method disclosed in the embodiments of the present disclosure, the hardware decoding processor can be directly embodied to execute the steps of the foregoing method, or the hardware and software modules in the decoding processor can be combined to execute the steps of the foregoing method. The software module can be located in the storage medium, which is located in the third memory 1103, and the third processor 1102 reads the information in the third memory 1103 to complete the steps of the foregoing method in combination with the hardware.
[0238] In the exemplary embodiments, the first network element 1100 can be implemented by one or more ASICs, DSPs, PLDs, CPLDs, FPGAs, general-purpose processors, controllers, MCUs, microprocessors, or other electronic elements, for executing the foregoing method.
[0239] It can be understood that the memory (the first memory 903, the second memory 1003, and the third memory 1103) of the embodiments of the present disclosure can be a volatile memory or a non-volatile memory, and can also include both volatile and non-volatile memories. The non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a ferromagnetic random access memory (FRAM), a flash memory, a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM). The magnetic surface memory can be a disk memory or a tape memory. The volatile memory can be a random access memory (RAM) used as an external cache.By way of example and not limitation, many forms of RAM are available, such as Static Random Access Memory (SRAM), Synchronous Static Random Access Memory (SSRAM), Dynamic Random Access Memory (DRAM), Synchronous Dynamic Random Access Memory (SDRAM), Double Data Rate Synchronous Dynamic Random Access Memory (DDR SDRAM), Enhanced Synchronous Dynamic Random Access Memory (ESDRAM), SyncLink Dynamic Random Access Memory (SLDRAM), and Direct Rambus Random Access Memory (DRRAM). The memory described in embodiments of the present disclosure is intended to include, but not be limited to, these and any other suitable types of memory.
[0240] To implement the method provided by the embodiments of the present disclosure, the embodiments of the present disclosure further provide an information transmission system, as shown in FIG. 12, which comprises a terminal 1201, a network device 1202 and a first network element 1203.
[0241] Here, it should be noted that the specific processing procedures of the terminal 1201, the network device 1202 and the first network element 1203 have been described in detail above, and will not be described here.
[0242] In an example embodiment, the embodiments of the present disclosure further provide a storage medium, i.e., a computer storage medium, specifically a computer readable storage medium, for example, a first memory 903 storing a computer program executable by the first processor 902 of the terminal 900 to perform the steps of the aforementioned terminal-side method, a second memory 1003 storing a computer program executable by the second processor 1002 of the network device 1000 to perform the steps of the aforementioned network device-side method, or a third memory 1103 storing a computer program executable by the third processor 1102 of the first network element 1100 to perform the steps of the aforementioned first network element-side method. The computer readable storage medium can be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disc, or CD-ROM.
[0243] In an example embodiment, the embodiments of the present disclosure further provide a computer program product comprising a computer program executable by the first processor 902 of the terminal 900 to perform the steps of the aforementioned terminal-side method, or executable by the second processor 1002 of the network device 1000 to perform the steps of the aforementioned network device-side method, or executable by the third processor 1102 of the first network element 1100 to perform the steps of the aforementioned first network element-side method.
[0244] It should be noted that "first", "second", and the like are used to distinguish similar objects, and do not necessarily have to describe a specific order or sequence.
[0245] In addition, the technical solutions described in the embodiments of the present disclosure can be combined arbitrarily without conflict.
[0246] The above is merely a preferred embodiment of the present disclosure and is not intended to limit the protection scope of the present disclosure.
Claims
1. An information transmission method, applied to a terminal, comprising: The terminal receives first information sent by a network device, wherein the first information includes at least one or more security-related information about first candidate cells, the one or more first candidate cells being associated with next-hop handover during the LTM (Location-Based Mobility Management) process triggered by Layer 1L1 / Layer 2L2, and the security-related information being used for information transmission between the terminal and the one or more first candidate cells.
2. The method according to claim 1, wherein, The security-related information includes one of the following: The second information is used to determine the first key; The third information is used to determine the second information.
3. The method according to claim 1, further comprising: Using the first information, a first key corresponding to the one or more first candidate cells is determined, wherein the first key is generated based on a vertical derivation method.
4. The method according to claim 3, wherein, The first information also includes fourth information, which is used to indicate the first algorithm; The method further includes: If the security-related information contained in the first information is encrypted, the first algorithm is used to decrypt the encrypted security-related information to obtain the decrypted security-related information; and Using the security-related information after decryption, the first key corresponding to the one or more first candidate cells is determined.
5. The method according to claim 3, wherein, The step of using the first information to determine the first key corresponding to the one or more first candidate cells includes: Receive fifth information sent by the network device, wherein the fifth information includes at least one of a source cell and a target cell associated with the next-hop handover; and Using the fifth information and the security-related information contained in the first information, the first key corresponding to the one or more first candidate cells is determined.
6. The method according to claim 1, further comprising: Using the first information, a first key corresponding to the one or more first candidate cells is determined, wherein the first key is generated based on vertical or horizontal derivation.
7. An information transmission method applied to a network device, comprising: Send first information to the terminal. The first information includes security-related information of one or more first candidate cells. The one or more first candidate cells are associated with the next-hop handover in the LTM (Low Mobility Time) process triggered by Layer 1L1 / Layer 2L2. The security-related information is used for information transmission between the terminal and the one or more first candidate cells.
8. The method according to claim 7, wherein, The security-related information includes one of the following: The second information is used to determine the first key; The third information is used to determine the second information.
9. The method according to claim 7, wherein, The first information is used to determine the first key corresponding to the one or more first candidate cells, and the first key is generated based on a vertical derivation method.
10. The method according to claim 9, wherein, The first information also includes fourth information, which is used to indicate a first algorithm. The first algorithm is used to decrypt the encrypted security-related information to obtain decrypted security-related information, and the decrypted security-related information is used to determine the first key.
11. The method of claim 9, further comprising: The terminal is sent fifth information, wherein the fifth information includes at least one of a source cell and a target cell associated with the next hop handover, and the security-related information contained in the fifth information and the first information is used to determine the first key.
12. The method according to claim 7, wherein, The first information is used to determine the first key corresponding to the one or more first candidate cells, and the first key is generated based on vertical or horizontal derivation.
13. The method according to any one of claims 7 to 12, further comprising: Send a sixth message to a first network element, wherein the sixth message is used to request the first message, and the first network element is used for mobility management at least; as well as Receive the first information sent by the first network element.
14. The method of claim 13, further comprising: A seventh message is sent to the first network element, wherein the seventh message is used to indicate one or more candidate cells associated with the LTM process.
15. An information transmission method, applied to a first network element, comprising: The terminal receives a sixth message sent by a network device, wherein the sixth message is used to request the first message, the first network element is used for mobility management at least, the first message contains at least one or more security-related information of a first candidate cell, the one or more first candidate cells are associated with the next-hop handover in the LTM (Layer 1L1 / Layer 2L2) mobility triggering process, and the security-related information is used for information transmission between the terminal and the one or more first candidate cells. as well as Send the first information to the network device.
16. The method of claim 15, further comprising: Upon receiving the sixth information, the first information is generated.
17. The method of claim 15, further comprising: Receive seventh information sent by the network device, wherein the seventh information is used to indicate one or more candidate cells associated with the LTM process; Using the seventh information, eighth information is generated, wherein the eighth information includes the one or more candidate cells and the corresponding security-related information; as well as Upon receiving the sixth information, the system searches for security-related information that matches the one or more first candidate cells from the eighth information to obtain the first information.
18. An information transmission device, installed in a terminal, comprising: The first receiving unit is configured to receive first information sent by a network device, wherein the first information includes at least one or more security-related information of first candidate cells, the one or more first candidate cells being associated with next-hop handover during the LTM (Location-Based Mobility Management) process triggered by Layer 1L1 / Layer 2L2, and the security-related information being used for information transmission between the terminal and the one or more first candidate cells.
19. An information transmission device, installed in a network device, comprising: The first sending unit is configured to send first information to the terminal, wherein the first information includes security-related information of one or more first candidate cells, the one or more first candidate cells are associated with the next-hop handover in the LTM (Location-Based Mobility Management) process triggered by Layer 1L1 / Layer 2L2, and the security-related information is used for information transmission between the terminal and the one or more first candidate cells.
20. An information transmission device, disposed in a first network element, comprising: The second receiving unit is used to receive sixth information sent by the network device, wherein the sixth information is used to request first information, the first network element is used at least for mobility management, the first information includes at least one or more first candidate cells with security-related information, the one or more first candidate cells are associated with the next-hop handover in the LTM (Layer 1L1 / Layer 2L2) mobility triggering process, and the security-related information is used for information transmission between the terminal and the one or more first candidate cells. as well as The second sending unit is used to send the first information to the network device.
21. A terminal, comprising: A first processor and a first communication interface; wherein the first communication interface is used to receive first information sent by a network device, the first information including at least one or more security-related information of first candidate cells, the one or more first candidate cells being associated with next-hop handover during the LTM (Location-Based Mobility Management) process triggered by Layer 1L1 / Layer 2L2, and the security-related information being used for information transmission between the terminal and the one or more first candidate cells.
22. A network device, comprising: A second processor and a second communication interface; wherein the second communication interface is used to send first information to the terminal, wherein the first information includes security-related information of one or more first candidate cells, the one or more first candidate cells are associated with the next-hop handover in the LTM (Location-Based Mobility Management) process triggered by Layer 1L1 / Layer 2L2, and the security-related information is used for information transmission between the terminal and the one or more first candidate cells.
23. A first network element, comprising: A third processor and a third communication interface; wherein the third communication interface is used to receive sixth information sent by a network device, wherein the sixth information is used to request first information, the first network element is used at least for mobility management, the first information includes at least one or more security-related information of first candidate cells, the one or more first candidate cells are associated with next-hop handover in the LTM (Layer 1L1 / Layer 2L2) mobility triggering process, the security-related information is used for information transmission between the terminal and the one or more first candidate cells; and to send the first information to the network device.
24. A terminal, comprising: A first processor and a first memory for storing a computer program capable of running on the processor, wherein the first processor, when running the computer program, performs the steps of the method according to any one of claims 1 to 6.
25. A network device, comprising: A second processor and a second memory for storing a computer program capable of running on the processor, wherein the second processor, when running the computer program, performs the steps of the method according to any one of claims 7 to 14.
26. A first network element, comprising: A third processor and a third memory for storing a computer program capable of running on the processor, wherein the third processor, when running the computer program, performs the steps of the method according to any one of claims 15 to 17.
27. A storage medium having a computer program stored thereon, wherein, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6, or the steps of the method according to any one of claims 7 to 14, or the steps of the method according to any one of claims 15 to 17.
28. A computer program product comprising a computer program, wherein, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6, or the steps of the method according to any one of claims 7 to 14, or the steps of the method according to any one of claims 15 to 17.
Citation Information
Patent Citations
Communication method and device
CN110557849A
Security information processing method and apparatus during handover process, network device, and terminal
WO2020155157A1