Communication method, first network device, terminal, communication system, and storage medium
By introducing security mechanisms into the communication system and utilizing information confirmation and verification information generation between network devices, the problem of data being easily tampered with between terminals and base stations is solved, thus achieving data transmission security.
Patent Information
- Application Number
- PCT/CN2024/103771
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-07-05
- Publication Date
- 2026-01-08
Smart Images

Figure CN2024103771_08012026_PF_FP_ABST
Abstract
Description
Communication method, first network device, terminal, communication system and storage medium TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of communication, and in particular to a communication method, a first network device, a terminal, a communication system and a storage medium. BACKGROUND
[0002] In the technical field of communication, the interface established between a terminal and a base station transmits data, and due to the fact that some protocol layers do not support security-related calculations, the transmitted data can not be protected, which can lead to tampering of the transmitted data and cause security risks.
[0003] SUMMARY
[0004] In view of the mechanism that data is not protected, a security mechanism needs to be introduced to protect the data.
[0005] Embodiments of the present disclosure provide a communication method, a first network device, a terminal, a communication system and a storage medium.
[0006] According to a first aspect of embodiments of the present disclosure, a communication method is provided, the method being performed by a first network device, and the method comprising:
[0007] sending first information to a terminal;
[0008] The first information comprises second information and third information; the second information is information confirmed by a second network device; the third information is information generated based on the second information and fourth information; the third information and the fourth information are used to verify the second information; the fourth information is information associated with a first identifier; the first identifier is an identifier allocated to the terminal; the first network device is a serving network device of the terminal, and the second network device is a candidate network device performing handover for the terminal.
[0009] According to a second aspect of embodiments of the present disclosure, a communication method is provided, the method being performed by a terminal, and the method comprising:
[0010] receiving first information sent by a first network device;
[0011] The first information comprises second information and third information; the second information is information confirmed by a second network device; the third information is information generated based on the second information and fourth information; the third information and the fourth information are used to verify the second information; the fourth information is information associated with a first identifier; the first identifier is an identifier allocated to the terminal; the first network device is a serving network device of the terminal, and the second network device is a candidate network device performing handover for the terminal.
[0012] According to a third aspect of the embodiments of the present disclosure, a communication method is provided, the method further includes:
[0013] sending, by a first network device, first information to a terminal;
[0014] The first information includes second information and third information, the second information is information confirmed by a second network device, the third information is information generated based on the second information and fourth information, the third information and the fourth information are used to verify the second information, the fourth information is information associated with a first identifier, the first identifier is an identifier allocated to the terminal, the first network device is a serving network device of the terminal, and the second network device is a candidate network device performing handover for the terminal.
[0015] According to a fourth aspect of the embodiments of the present disclosure, a first network device is provided, the first network device includes:
[0016] a transceiver module configured to:
[0017] send first information to a terminal;
[0018] The first information includes second information and third information, the second information is information confirmed by a second network device, the third information is information generated based on the second information and fourth information, the third information and the fourth information are used to verify the second information, the fourth information is information associated with a first identifier, the first identifier is an identifier allocated to the terminal, the first network device is a serving network device of the terminal, and the second network device is a candidate network device performing handover for the terminal.
[0019] According to a fifth aspect of the embodiments of the present disclosure, a terminal is provided, the terminal includes:
[0020] a transceiver module configured to:
[0021] receive first information sent by a first network device;
[0022] The first information includes second information and third information, the second information is information confirmed by a second network device, the third information is information generated based on the second information and fourth information, the third information and the fourth information are used to verify the second information, the fourth information is information associated with a first identifier, the first identifier is an identifier allocated to the terminal, the first network device is a serving network device of the terminal, and the second network device is a candidate network device performing handover for the terminal.
[0023] According to a sixth aspect of the embodiments of the present disclosure, a communication system is provided, the communication system comprising a first network device and a terminal, wherein the first network device is configured to perform the communication method according to the first aspect; and the terminal is configured to perform the communication method according to the second aspect.
[0024] According to a seventh aspect of the embodiments of the present disclosure, a first network device is provided, the first network device comprising:
[0025] one or more processors;
[0026] The first network device is configured to perform the communication method according to the first aspect.
[0027] According to an eighth aspect of the embodiments of the present disclosure, a terminal is provided, the terminal comprising:
[0028] one or more processors;
[0029] The terminal is configured to perform the communication method according to the second aspect.
[0030] According to a ninth aspect of the embodiments of the present disclosure, a storage medium is provided, the storage medium storing instructions, when the instructions are executed on a communication device, causing the communication device to perform the communication method according to the first aspect and / or the second aspect.
[0031] The communication mechanism of the technical solutions provided by the embodiments of the present disclosure can protect the data transmitted between the network device and the terminal.
[0032] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the embodiments of the present disclosure. BRIEF DESCRIPTION OF DRAWINGS
[0033] The accompanying drawings, which are incorporated into the specification and constitute a part of the specification, illustrate the embodiments consistent with the present disclosure, and together with the specification, serve to explain the principles of the embodiments of the present disclosure.
[0034] FIG. 1a is a schematic diagram of an architecture of a communication system according to an exemplary embodiment;
[0035] FIG. 1b is a schematic diagram of a communication method according to an exemplary embodiment;
[0036] FIG. 1c is a schematic diagram of a security processing according to an exemplary embodiment;
[0037] FIG. 1d is a schematic diagram of a MAC CE signaling according to an exemplary embodiment;
[0038] FIG. 1e is a schematic diagram of a communication method according to an exemplary embodiment;
[0039] FIG. 1f is a schematic diagram illustrating a communication method according to an example embodiment;
[0040] FIG. 2a is a flow diagram illustrating a communication method according to an example embodiment;
[0041] FIG. 3a is a flow diagram illustrating a communication method according to an example embodiment;
[0042] FIG. 3b is a flow diagram illustrating a communication method according to an example embodiment;
[0043] FIG. 4a is a flow diagram illustrating a communication method according to an example embodiment;
[0044] FIG. 4b is a flow diagram illustrating a communication method according to an example embodiment;
[0045] FIG. 5a is a flow diagram illustrating a communication method according to an example embodiment;
[0046] FIG. 6a is a flow diagram illustrating a communication method according to an example embodiment;
[0047] FIG. 6b is a schematic diagram illustrating a MAC CE according to an example embodiment;
[0048] FIG. 7a is a schematic diagram illustrating a structure of a first network device according to an example embodiment;
[0049] FIG. 7b is a schematic diagram illustrating a structure of a terminal according to an example embodiment;
[0050] FIG. 8a is a schematic diagram illustrating a structure of a UE according to an example embodiment;
[0051] FIG. 8b is a schematic diagram illustrating a structure of a communication device according to an example embodiment. DETAILED DESCRIPTION
[0052] Embodiments of the present disclosure provide a communication method, a first network device, a terminal, a communication system and a storage medium.
[0053] In a first aspect, embodiments of the present disclosure provide a communication method, performed by a first network device, the method comprising:
[0054] sending first information to a terminal;
[0055] The first information includes second information and third information, the second information is information confirmed by the second network device, the third information is information generated based on the second information and fourth information, the third information and the fourth information are used to verify the second information, the fourth information is information associated with a first identifier, the first identifier is an identifier allocated to the terminal, the first network device is a serving network device of the terminal, and the second network device is a candidate network device performing handover of the terminal.
[0056] In the above embodiment, since the first information includes the confirmed second information obtained from the second network device and the third information generated based on the second information and the fourth information, after the first information is sent to the terminal, the terminal can verify the second information based on the third information and the fourth information, ensuring that the received second information is not tampered with, so that subsequent processing based on the second information is more secure.
[0057] In combination with some embodiments of the first aspect, in some embodiments, the first identifier is a terminal identifier allocated by an initial network device to a serving network device in a layer 1 (L1) or layer 2 (L2) triggered mobility (LTM) procedure.
[0058] In the above embodiment, the initial access device in the LTM procedure can allocate the terminal identifier to the first network device.
[0059] In combination with some embodiments of the first aspect, in some embodiments, the sending of the first information to the terminal includes:
[0060] sending a first medium access control (MAC) control element (CE) message to the terminal;
[0061] The first MAC CE message includes the first information.
[0062] In the above embodiment, the first information can be sent to the terminal through the first MAC CE message, and MAC CE messages can be multiplexed to reduce signaling overhead.
[0063] In combination with some embodiments of the first aspect, in some embodiments, the sending of the first information to the terminal includes:
[0064] The first information is sent to the terminal in an inter-base station LTM procedure performed by the terminal and the first network device.
[0065] In the above embodiment, the first information can be sent to the terminal in the inter-base station LTM procedure performed by the terminal and the first network device.
[0066] In some embodiments of the first aspect, in some embodiments, the sending, to the terminal, the first information in the inter-base station LTM procedure performed by the terminal and the first network device comprises at least one of:
[0067] sending, to the terminal, the first information in an initial inter-base station LTM procedure performed by the terminal and the first network device;
[0068] sending, to the terminal, the first information in a subsequent inter-base station LTM procedure performed by the terminal and the first network device.
[0069] In the above embodiments, the first information can be sent to the terminal in an initial inter-base station LTM procedure performed by the terminal and the first network device or in a subsequent inter-base station LTM procedure performed by the terminal and the first network device, and the sending manner is more flexible.
[0070] In some embodiments of the first aspect, in some embodiments, the method further comprises:
[0071] determining the second information;
[0072] sending, to the second network device, the second information;
[0073] receiving the second information confirmed by the second network device.
[0074] In the above embodiments, the second information is sent to the second network device for confirmation after the second information is determined, so that the second information is the second information confirmed by the second network device.
[0075] In some embodiments of the first aspect, in some embodiments, the method comprises:
[0076] generating the third information based on the second information and the fourth information.
[0077] In the above embodiments, the third information can be generated based on the second information and the fourth information, so that after the terminal receives the first information, the terminal can verify the second information based on the third information and the fourth information.
[0078] In some embodiments of the first aspect, in some embodiments, the second information is a first next hop change counter NCC, and the generating the third information based on the second information and the fourth information comprises:
[0079] encoding the first NCC using the fourth information to obtain the third information.
[0080] In the above embodiment, the first NCC can be encoded based on the fourth information to obtain the encoded third information.
[0081] In combination with some embodiments of the first aspect, in some embodiments, the encoding the first NCC based on the fourth information to obtain the third information comprises:
[0082] performing an exclusive or operation between the fourth information and the first NCC to obtain the third information.
[0083] In the above embodiment, the first NCC can be encoded by performing the exclusive or operation between the fourth information and the first NCC to obtain the encoded third information.
[0084] In combination with some embodiments of the first aspect, in some embodiments, the method further comprises:
[0085] performing hash processing on the first identifier to obtain the fourth information.
[0086] In the above embodiment, the fourth information can be obtained by performing the hash processing on the first identifier.
[0087] In combination with some embodiments of the first aspect, in some embodiments, the first identifier is at least one of:
[0088] a cell radio network temporary identifier (C-RNTI) allocated to the terminal;
[0089] an LTM dedicated identifier allocated to the terminal;
[0090] a random number allocated to the terminal.
[0091] In the above embodiment, the selection of the first identifier can be more flexible.
[0092] In a second aspect, the embodiments of the present disclosure provide a communication method, the method being performed by a terminal, and the method comprising:
[0093] receiving first information sent by a first network device;
[0094] The first information comprises second information and third information; the second information is information confirmed by a second network device; the third information is information generated based on the second information and fourth information; the third information and the fourth information are used to verify the second information; the fourth information is information associated with a first identifier; the first identifier is an identifier allocated to the terminal; the first network device is a serving network device of the terminal, and the second network device is a candidate network device performing handover for the terminal.
[0095] In some embodiments, in combination with the embodiments of the second aspect, the first identifier is a terminal identifier allocated by the initial network device to the service network device in the LTM procedure.
[0096] In some embodiments, in combination with the embodiments of the second aspect, the receiving the first information sent by the first network device comprises:
[0097] receiving a first MAC CE message sent by the first network device.
[0098] The first MAC CE message contains the first information.
[0099] In some embodiments, in combination with the embodiments of the second aspect, the receiving the first information sent by the first network device comprises:
[0100] In the inter-base station LTM procedure performed by the terminal and the first network device, the first information sent by the first network device is received.
[0101] In some embodiments, in combination with the embodiments of the second aspect, the receiving the first information sent by the first network device in the inter-base station LTM procedure comprises:
[0102] In the initial inter-base station LTM procedure performed by the terminal and the first network device, the first information sent by the first network device is received.
[0103] In the subsequent inter-base station LTM procedure performed by the terminal and the first network device, the first information sent by the first network device is received.
[0104] In some embodiments, in combination with the embodiments of the second aspect, the second information is a first next hop change counter parameter NCC, and the third information is security information obtained by encoding the first NCC using the fourth information.
[0105] In some embodiments, in combination with the embodiments of the second aspect, the third information is security information obtained by performing an exclusive OR operation on the first NCC and the fourth information.
[0106] In some embodiments, in combination with the embodiments of the second aspect, the fourth information is information obtained by performing a hash processing on the first identifier.
[0107] In some embodiments, in combination with the embodiments of the second aspect, the first identifier is at least one of:
[0108] a cell radio network temporary identifier C-RNTI allocated to the terminal.
[0109] a LTM dedicated identity assigned to the terminal;
[0110] a random number assigned to the terminal.
[0111] With reference to the embodiments of the second aspect, in some embodiments, the method further includes:
[0112] verifying the second information based on the second information, the third information and the fourth information;
[0113] wherein the first network device and the terminal share the fourth information.
[0114] With reference to the embodiments of the second aspect, in some embodiments, the verifying the second information based on the second information, the third information and the fourth information includes:
[0115] decoding the third information based on the fourth information to obtain fifth information;
[0116] determining whether the second information passes the verification based on a comparison result of the second information and the fifth information.
[0117] With reference to the embodiments of the second aspect, in some embodiments, the determining whether the second information passes the verification based on the comparison result of the second information and the fifth information includes at least one of:
[0118] determining that the second information is identical to the fifth information, and determining that the second information passes the verification;
[0119] determining that the second information is different from the fifth information, and determining that the second information fails the verification.
[0120] With reference to the embodiments of the second aspect, in some embodiments, the verifying the second information based on the second information, the third information and the fourth information includes:
[0121] encoding the second information based on the fourth information to obtain sixth information;
[0122] determining whether the second information passes the verification based on a comparison result of the third information and the sixth information.
[0123] With reference to the embodiments of the second aspect, in some embodiments, the determining whether the second information passes the verification based on the comparison result of the third information and the sixth information includes:
[0124] determining that the third information is identical to the sixth information, and determining that the second information passes the verification;
[0125] determining that the third information is different from the sixth information, and determining that the second information is not verified.
[0126] With reference to the embodiments of the second aspect, in some embodiments, the method further includes:
[0127] performing hash processing on the first identifier to obtain the third information.
[0128] In a third aspect, the embodiments of the present disclosure provide a communication method, and the method further includes:
[0129] sending, by a first network device, first information to a terminal;
[0130] The first information includes second information and third information. The second information is information confirmed by a second network device. The third information is information generated based on the second information and fourth information. The third information and the fourth information are used to verify the second information. The fourth information is information associated with a first identifier. The first identifier is an identifier allocated to the terminal. The first network device is a serving network device of the terminal, and the second network device is a candidate network device performing handover for the terminal.
[0131] In a fourth aspect, the embodiments of the present disclosure provide a first network device, and the first network device includes:
[0132] a transceiver module configured to:
[0133] send, by the first network device, first information to a terminal;
[0134] The first information includes second information and third information. The second information is information confirmed by a second network device. The third information is information generated based on the second information and fourth information. The third information and the fourth information are used to verify the second information. The fourth information is information associated with a first identifier. The first identifier is an identifier allocated to the terminal. The first network device is a serving network device of the terminal, and the second network device is a candidate network device performing handover for the terminal.
[0135] In a fifth aspect, the embodiments of the present disclosure provide a terminal, and the terminal includes:
[0136] a transceiver module configured to:
[0137] receive, by the terminal, first information sent by a first network device;
[0138] The first information includes second information and third information, the second information is information confirmed by a second network device, the third information is information generated based on the second information and fourth information, the third information and the fourth information are used for verifying the second information, the fourth information is information associated with a first identifier, the first identifier is an identifier allocated to the terminal, the first network device is a serving network device of the terminal, and the second network device is a candidate network device performing handover for the terminal.
[0139] In a sixth aspect, an embodiment of the present disclosure provides a communication system, the communication system comprising a first network device and a terminal, wherein the first network device is configured to perform the communication method of the first aspect; and the terminal is configured to perform the communication method of the second aspect.
[0140] In a seventh aspect, an embodiment of the present disclosure provides a first network device, the first network device comprising:
[0141] one or more processors;
[0142] The first network device is configured to perform the communication method of the first aspect.
[0143] In an eighth aspect, an embodiment of the present disclosure provides a terminal, the terminal comprising:
[0144] one or more processors;
[0145] The terminal is configured to perform the communication method of the second aspect.
[0146] In a ninth aspect, an embodiment of the present disclosure provides a storage medium, wherein the storage medium stores instructions, when the instructions are executed on a communication device, the communication device performs the communication method described in the optional implementation manner of the first aspect and / or the second aspect.
[0147] In a tenth aspect, an embodiment of the present disclosure provides a program product, when the program product is executed on a communication device, the communication device performs the method described in the optional implementation manner of the first aspect and / or the second aspect.
[0148] In an eleventh aspect, an embodiment of the present disclosure provides a computer program, when the computer program is executed on a computer, the computer performs the method described in the optional implementation manner of the first aspect and / or the second aspect.
[0149] In a twelfth aspect, an embodiment of the present disclosure provides a chip or a chip system. The chip or the chip system comprises a processing circuit configured to perform the method described in the optional implementation manner of the first aspect and / or the second aspect.
[0150] It can be understood that the first network device, the terminal, the communication system, the storage medium, the program product, the computer program, the chip or the chip system are used to execute the method provided by the embodiments of the present disclosure. Therefore, the beneficial effects achieved by the above-mentioned network device, terminal, communication system, storage medium, program product, computer program, chip or chip system can refer to the beneficial effects in the corresponding method, which will not be repeated here.
[0151] The embodiments of the present disclosure provide a communication method. In some embodiments, the communication method can be replaced by the terms such as information indication method, information processing method, information transmission method, and the communication system can be replaced by the terms such as information processing system.
[0152] The embodiments of the present disclosure are not exhaustive, but only illustrate some embodiments, and are not specific limitations on the protection scope of the present disclosure. In the case of no contradiction, each step in an embodiment can be implemented as an independent embodiment, and the steps can be combined arbitrarily, for example, the scheme after removing some steps in an embodiment can also be implemented as an independent embodiment, and the order of the steps in an embodiment can be exchanged arbitrarily, in addition, the optional implementation manners in an embodiment can be combined arbitrarily; in addition, the embodiments can be combined arbitrarily, for example, some or all steps of different embodiments can be combined arbitrarily, an embodiment can be combined with the optional implementation manners of other embodiments.
[0153] In the embodiments of the present disclosure, the terms and / or descriptions between the embodiments are consistent and can be referred to each other if there is no special description and logical conflict, and the technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationship.
[0154] The terms used in the embodiments of the present disclosure are only for the purpose of describing specific embodiments, and not as a limitation on the present disclosure.
[0155] In the embodiments of the present disclosure, unless otherwise specified, the elements expressed in singular form, such as "one", "one", "the", "above", "said", "above", "this" and the like, can represent "one and only one", and can also represent "one or more", "at least one" and the like. For example, in the case of using articles such as "a", "an", "the" and the like in English, the noun after the article can be understood as singular expression, and can also be understood as plural expression.
[0156] In the embodiments of the present disclosure, "a plurality of" means two or more.
[0157] In some embodiments, the terms “at least one of,” “one or more of,” “a plurality of,” “multiple,” and the like can be used interchangeably.
[0158] In some embodiments, the recitations such as “at least one of A, B,” “A and / or B,” “in one case A, in another case B,” “in response to a case A, in response to a case B,” and the like can include the following technical solutions according to the case: in some embodiments A (A is executed regardless of B); in some embodiments B (B is executed regardless of A); in some embodiments A and B are selectively executed (A and B are selectively executed); in some embodiments A and B (A and B are both executed). When there are more branches such as A, B, C, and the like, the above is similar.
[0159] In some embodiments, the recitations such as “A or B” and the like can include the following technical solutions according to the case: in some embodiments A (A is executed regardless of B); in some embodiments B (B is executed regardless of A); in some embodiments A and B are selectively executed (A and B are selectively executed). When there are more branches such as A, B, C, and the like, the above is similar.
[0160] The prefix words “first,” “second,” and the like in the embodiments of the present disclosure are merely used to distinguish different description objects, and do not constitute a limitation on the position, order, priority, quantity, or content of the description objects. The description of the description objects should refer to the description in the context of the claims or embodiments, and should not constitute an unnecessary limitation because of the use of the prefix words. For example, the description objects are “fields,” and the ordinal words before “fields” in “first field” and “second field” do not limit the position or order between “fields,” and “first” and “second” do not limit whether the “fields” modified thereby are in the same message or not, nor limit the order of “first field” and “second field.” For another example, the description objects are “levels,” and the ordinal words before “levels” in “first level” and “second level” do not limit the priority between “levels.” For another example, the quantity of the description objects is not limited by the ordinal words, and can be one or more. For example, “first device,” where the quantity of “devices” can be one or more. In addition, the objects modified by different prefix words can be the same or different, for example, the description objects are “devices,” and “first device” and “second device” can be the same device or different devices, and the types thereof can be the same or different; for another example, the description objects are “information,” and “first information” and “second information” can be the same information or different information, and the content thereof can be the same or different.
[0161] In some embodiments, “comprising A”, “including A”, “for indicating A”, “carrying A” can be interpreted as directly carrying A, or can be interpreted as indirectly indicating A.
[0162] In some embodiments, the terms “time / frequency”, “time / frequency domain” and the like refer to the time domain and / or the frequency domain.
[0163] In some embodiments, the terms “in response to”, “in response to determining”, “in the case of”, “when”, “when”, “if”, “if” and the like can be replaced with each other.
[0164] In some embodiments, the terms “greater than”, “greater than or equal to”, “not less than”, “more than”, “more than or equal to”, “not less than”, “higher than”, “higher than or equal to”, “not lower than”, “above” and the like can be replaced with each other, and the terms “less than”, “less than or equal to”, “not greater than”, “less than”, “less than or equal to”, “not more than”, “lower than”, “lower than or equal to”, “not higher than”, “below” and the like can be replaced with each other.
[0165] In some embodiments, the apparatus and the like can be interpreted as physical or virtual, and the name thereof is not limited to the name recorded in the embodiments. The terms “apparatus”, “equipment”, “device”, “circuit”, “network element”, “node”, “function”, “unit”, “section”, “system”, “network”, “chip”, “chip system”, “entity”, “subject” and the like can be replaced with each other.
[0166] In some embodiments, “network” can be interpreted as an apparatus (for example, access network device, core network device and the like) contained in the network.
[0167] In some embodiments, the terms “access network device (AN device),” “radio access network device (RAN device),” “base station (BS),” “radio base station,” “fixed station,” “node,” “access point,” “transmission point (TP),” “reception point (RP),” “transmission / reception point (TRP),” “panel,” “antenna panel,” “antenna array,” “cell,” “macro cell,” “small cell,” “femto cell,” “pico cell,” “sector,” “cell group,” “serving cell,” “carrier,” “component carrier,” “bandwidth part (BWP),” and the like can be used interchangeably.
[0168] In some embodiments, the terms "terminal," "terminal device," "user equipment (UE)," "user terminal," "mobile station (MS)," "mobile terminal (MT)," "subscriber station," "mobile unit," "subscriber unit," "wireless unit," "remote unit," "mobile device," "wireless device," "wireless communication device," "remote device," "mobile subscriber station," "access terminal," "mobile terminal," "wireless terminal," "remote terminal," "handset," "user agent," "mobile client," "client," and so on can be replaced with each other.
[0169] In some embodiments, the access network device, the core network device, or the network device can be replaced with a terminal. For example, the embodiments of the present disclosure can also be applied to a structure in which communication between the access network device, the core network device, or the network device and the terminal is replaced with communication between a plurality of terminals (e.g., device-to-device (D2D), vehicle-to-everything (V2X), etc.). In this case, the terminal can also be configured to have all or part of the functions of the access network device. In addition, the terms "uplink," "downlink," and the like can also be replaced with terms corresponding to the inter-terminal communication (e.g., "side"). For example, the uplink channel, the downlink channel, and the like can be replaced with the side channel, and the uplink, the downlink, and the like can be replaced with the sidelink.
[0170] In some embodiments, the terminal can be replaced with the access network device, the core network device, or the network device. In this case, the access network device, the core network device, or the network device can also be configured to have all or part of the functions of the terminal.
[0171] In some embodiments, the data, information, etc. can be obtained in compliance with the laws and regulations of the country where the location is situated.
[0172] In some embodiments, the data, information, etc. can be obtained after obtaining the consent of the user.
[0173] In addition, each element, each row, or each column in the table of the embodiments of the present disclosure can be implemented as an independent embodiment, and any combination of any element, any row, or any column can also be implemented as an independent embodiment.
[0174] FIG. 1a is a schematic diagram of an architecture of a communication system according to an embodiment of the present disclosure.
[0175] As shown in FIG. 1a, the communication system 100 includes a terminal 101 and a network device 102.
[0176] In some embodiments, the network device 102 can be an access network device or a core network device.
[0177] In some embodiments, the terminal 101 includes at least one of a mobile phone, a wearable device, an Internet of Things device, a car with communication function, a smart car, a tablet computer (Pad), a computer with wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in smart grid, a wireless terminal device in transportation safety, a wireless terminal device in smart city, a wireless terminal device in smart home, etc., but is not limited thereto.
[0178] In some embodiments, the access network device is, for example, a node or device that accesses a terminal to a wireless network, and the access network device can include at least one of an evolved NodeB (eNB) in a 5G communication system, a next generation eNB (ng-eNB), a next generation NodeB (gNB), a node B (NB), a home node B (HNB), a home evolved node B (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an open base station (Open RAN), a cloud base station (Cloud RAN), a base station in other communication systems, an access node in a Wi-Fi system, but is not limited thereto.
[0179] In some embodiments, the technical solutions of the present disclosure can be applied to an Open RAN architecture, at this time, the interfaces between or within the access network devices involved in the embodiments of the present disclosure can become internal interfaces of the Open RAN, and the processes and information interactions between these internal interfaces can be realized through software or programs.
[0180] In some embodiments, the access network device can be composed of a central unit (CU) and a distributed unit (DU), wherein the CU can also be referred to as a control unit (control unit). The CU-DU structure can split the protocol layers of the access network device, and part of the functions of the protocol layers are controlled by the CU, and the remaining part or all of the functions of the protocol layers are distributed in the DU and controlled by the CU, but the present disclosure is not limited thereto.
[0181] In some embodiments, the core network device can be one device including a first network element, a second network element, etc., or can be multiple devices or device groups, respectively including all or part of the first network element, the second network element, etc. The network element can be virtual or physical. The core network includes, for example, at least one of an evolved packet core (EPC), a 5G core network (5GCN), and a next generation core (NGC).
[0182] In some embodiments, the first network element is, for example, a Mobility Management Entity (MME).
[0183] In some embodiments, the first network element is used for signaling processing, and the name is not limited thereto.
[0184] In some embodiments, the second network element is, for example, a Home Subscriber Server (HSS).
[0185] In some embodiments, the second network element is used for storing subscriber information, and the name is not limited thereto.
[0186] In some embodiments, the third network element is, for example, a Policy and Charging Rules Function (PCRF).
[0187] In some embodiments, the third network element is used for policy provision and charging, and the name is not limited thereto.
[0188] In some embodiments, the first network element, the second network element, and / or the third network element can be independent of the core network device.
[0189] In some embodiments, the first network element, the second network element, and / or the third network element can be part of the core network device.
[0190] It can be understood that the communication system described in the embodiments of the present disclosure is for more clearly illustrating the technical solutions of the embodiments of the present disclosure, and does not constitute a limitation on the technical solutions proposed by the embodiments of the present disclosure. It can be known by those skilled in the art that, with the evolution of system architecture and the appearance of new business scenarios, the technical solutions proposed by the embodiments of the present disclosure are also applicable to similar technical problems.
[0191] The following embodiments of the present disclosure can be applied to the communication system 100 shown in FIG. 1a or part of the subject, but are not limited thereto. The subjects shown in FIG. 1a are examples, and the communication system can include all or part of the subjects in FIG. 1a, or other subjects other than FIG. 1a. The number and form of each subject is arbitrary, each subject can be real or virtual, the connection relationship between each subject is an example, each subject can not be connected or can be connected, and the connection can be in any way, can be direct connection or indirect connection, can be wired connection or wireless connection.
[0192] Embodiments of the present disclosure can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New radio access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (Bluetooth (registered trademark)), Public Land Mobile Network (PLMN) network, Device-to-Device (D2D) system, Machine to Machine (M2M) system, Internet of Things (IoT) system, Vehicle-to-Everything (V2X), system using other communication methods, next-generation system expanded based thereon, and the like. Further, a plurality of systems can be applied in combination (for example, combination of LTE or LTE-A and 5G, and the like).
[0193] In some embodiments, Layer 1 or Layer 2 triggered mobility (LTM, L1 / L2 Triggered Mobility) refers to a process in which a network triggers a primary cell (Pcell, Primary Cell) or primary secondary cell (PSCell, Primary Secondary Cell) cell switch based on L1 measurement results through a media access control (MAC, Media Access Control) control element (CE, Control Element), which can be accompanied by a master cell group (MCG, Master Cell group) or secondary cell group (SCG, Secondary Cell group) change.
[0194] In some embodiments, in LTM, a gNB receives an L1 measurement report from a UE, based on which the gNB changes the serving cell of the UE through a cell switch command issued by a MAC CE. The cell switch command indicates an LTM candidate cell configuration that the gNB previously provides to the UE through radio resource control (RRC, Radio Resource Control) signaling. The UE accesses the target cell indicated in the cell switch command according to the received cell switch command. LTM can be used to reduce mobility latency. Among them, the LTM candidate cell configuration can only be added, modified and released by the network through RRC signaling. The LTM process can be used to reduce mobility delay.
[0195] In some embodiments, LTM supports subsequent LTM, where subsequent LTM refers to a subsequent LTM cell switching process between candidate cells without RRC reconfiguration by the network in between. That is, after performing a mobility operation, the UE does not autonomously delete the configuration information of LTM, which can continue to be used even without RRC reconfiguration and update, for triggering subsequent LTM (Subsequent LTM).
[0196] In some embodiments, LTM supports intra-frequency and inter-frequency mobility, including mobility to inter-frequency cells that are not the current serving cell. Rel-18 only supports intra-distributed unit (DU, Distributed Unit) and intra-central unit (CU, Central processing Unit) LTM. Rel-19 extends NR mobility enhancements to inter-CU (inter-node or gNB) LTM, which supports the following scenarios:
[0197] Case 1: CU acts as a network master node (MN, Master Node) when no DC is configured;
[0198] Case 2: CU acts as a network secondary node (SN, Secondary Node) when NR-DC is configured and MCG is unchanged;
[0199] Case 3: CU acts as a MN when NR-DC is configured and SCG is unchanged or SCG is released.
[0200] In some embodiments, for inter-CU LTM, more than one candidate gNB-CU will be involved in the mobility flow. Based on the overall procedure of Rel-18 intra-CU LTM, the signaling procedure of Rel-19 inter-CU LTM is shown in Figure 1b and includes the following three stages:
[0201] Stage 1 (LTM preparation): Based on L3 radio resource management (RRM, Radio Resource Management) measurement reports, the initial gNB decides candidate cells and initiates inter-node interaction for inter-CU LTM preparation. After the interaction, the initial gNB provides the UE with an RRC configured LTM configuration with multiple candidate cells.
[0202] Stage 2 (initial LTM execution): As in Rel-18 intra-CU LTM, the UE sends L1 measurement reports to the initial gNB. After receiving the cell handover command MAC CE, the UE switches to one candidate gNB (e.g., C-gNB1). To support random access channel (RACH, Random Access CHannel) free LTM, DL and UL early synchronization with candidate cells can be performed before receiving the cell handover command.
[0203] Stage 3 (subsequent LTM execution): In the subsequent LTM execution stage, similar steps as in stage 2 are performed. And the subsequent LTM is triggered by the current serving gNB, which is one candidate gNB (e.g., C-gNB1).
[0204] In some embodiments, referring to Figure 1c, during handover for legacy inter-CU mobility procedures, synchronization of access stratum (AS, Access Stratum) security keys between the UE and the target gNB is achieved via the next hop chaining counter (NCC, Next hop Chaining Counter) value used by the source gNB, which is then forwarded to the target gNB and the UE in RRC reconfiguration signaling.
[0205] In some embodiments, referring to Figure 1c, whenever an initial AS security context needs to be established between the UE and the gNB, the Access and Mobility Management Function (AMF) and the UE shall derive K gNB and the Next Hop parameter (NH). The NCC is associated with each K gNB and NH parameter. Each K gNB is associated with the NCC corresponding to the NH value from which it is derived.
[0206] In some embodiments, referring to Figure 1c, in Xn handover, if the source gNB has an unused {NH, NCC} pair, the source gNB shall perform vertical key derivation. As specified in Annex A.11 / A.12 of 3GPP TS 33.501 [1], the source gNB shall first compute K gNB from the currently active K NG-RAN *, or K NG-RAN * from NH in case of vertical key derivation.
[0207] In some embodiments, the source gNB shall forward the {K NG-RAN *, NCC} pair to the target gNB. The target gNB shall use the received K NG-RAN * directly as the K gNB to be used with the UE. The target gNB shall associate the NCC value received from the source gNB with K gNB . The target gNB shall include the received NCC in the prepared Handover (HO) command message, which is sent back to the source gNB in a transparent container and forwarded by the source gNB to the UE.
[0208] In some embodiments, the UE behavior is the same for handover whether it is gNB-CU intra handover, Xn or N2, except that during gNB-CU intra handover, the UE can retain the same key based on an indication from the gNB. The UE behavior is also the same in case of conditional handover, as specified in 3GPP TS 38.300 [2], i.e., the UE shall use the parameters of the selected target cell in the K NG-RAN derivation.
[0209] In some embodiments, if the UE receives the NCC value from the target gNB in the HO command message via the source gNB that is equal to the NCC value associated with the currently active K gNB , the UE shall use the functions defined in Annex A.11 and A.12 of 3GPP TS 33.501 [1] to derive K gNBand the Physical Cell Identifier (PCI) and its downlink frequency Absolute Radio Frequency Channel Number (ARFCN) or E-UTRA Absolute Radio Frequency Channel Number (EARFCN) derive K NG-RAN *.
[0210] In some embodiments, if the UE receives a different NCC value associated with the currently active K gNB , the UE shall first synchronize the locally maintained NH parameter by iteratively computing the function defined in Annex A.10 of 3GPP TS 33.501 [1] (and incrementing the NCC value until it matches the NCC value received from the source gNB via the HO command message). When the NCC values match, the UE shall compute K NG-RAN *.
[0211] In some embodiments, the UE shall use K NG-RAN * as K gNB .
[0212] In some embodiments, during the current inter-gNB handover procedure, the security related configurations (e.g., NCC, K NG-RAN *) are first synchronized between the source and target gNBs, and then the NCC is sent by the source gNB to the UE in RRC reconfiguration at each handover. As mentioned above, the NCC is used by the UE for key reset synchronization with the target gNB. However, with the mobility enhancement procedure defined for inter-gNB LTM, the source gNB does not send RRC reconfiguration at each handover. Then, how to update the NCC value at each handover and send it to the UE for key update synchronization becomes an open issue, and several options are studied by 3GPP for this purpose, one of which is as follows.
[0213] Option 1: See Figure 1d, use a new information in MAC CE to deliver security information. Whether the UE uses horizontal key derivation or vertical key derivation is derived from this new information in MAC CE (which is currently neither integrity protected nor ciphered).
[0214] Option 1A: Include the NCC value used when inter-CU LTM is performed in the LTM cell handover command MAC CE.
[0215] In some embodiments, considering the impact of the options on the existing system, Option 1A (i.e., carrying NCC value in LTM cell switch command MAC CE) is considered as the option with the least impact in terms of feasibility and signaling overhead. However, the main problem of this option is that the MAC CE message is not protected, so that the NCC carried in the MAC CE message is not protected. The unprotected NCC will face the risk of being tampered with by the attacker. When the NCC value received by the UE is tampered with, the key derived by the UE will be different from the key received and derived by the target gNB from the source gNB. This desynchronization of the key reset between the UE and the target gNB will lead to a handover failure.
[0216] In some embodiments, in the current inter-gNB handover procedure, the security related configuration (e.g., MasterKeyUpdate, NCC) is sent from the source gNB to the UE via RRC reconfiguration signaling over the Uu interface at the preparation phase of each handover. The RRC reconfiguration is sent after the AS security establishment between the UE and the gNB, so the whole RRC reconfiguration message is at least integrity protected and cannot be tampered with by the attacker.
[0217] In some embodiments, for inter-CU LTM enhancement, the preparation phase is only performed by the initial gNB and is not performed for each subsequent handover, i.e., there is no preparation phase before each handover for inter-CU LTM enhancement. Based on this design, the RRC reconfiguration signaling is only performed by the initial gNB of the LTM preparation phase, but is replaced by the MAC CE message at each handover after the LTM preparation. Since the MAC CE message is not protected, the security related configuration carried in the MAC CE message cannot be protected. Currently, the AS security established between the UE and the gNB is performed on the Packet Data Convergence Protocol (PDCP) layer on the Uu interface. The MAC layer below the PDCP layer does not support security related calculation. Therefore, there is no existing security mechanism to protect the MAC CE message.
[0218] Therefore, how to ensure that the security related parameters (e.g., NCC) sent from the gNB to the UE in the MAC CE are protected from tampering is a problem that needs to be considered.
[0219] In some embodiments, when a UE attaches to a gNB, the serving or source gNB will assign a cell radio network temporary identifier (C-RNTI) to the attaching UE. The current C-RNTI is only known to the serving or source gNB and the assigned UE before the UE is handed over to the target gNB, but not to any other party. During a conventional inter-gNB handover, the serving or source gNB needs to send the current C-RNTI to the target gNB in the handover request, and the target gNB needs to return the current or old C-RNTI allocated by the serving or source gNB and the new C-RNTI allocated by the target gNB in the handover request acknowledgement to the serving or source gNB, which forwards to the UE. With this handover procedure, both the serving or source and target gNBs know the old and new C-RNTI values, see e.g. the last 3 steps of Fig. 1e.
[0220] In some embodiments, according to the enhancement of inter-gNB LTM, the C-RNTI values (including the C-RNTI values used by the initial or source gNB and the candidate gNBs) are all allocated by the initial gNB and delivered to the UE in the LTM preparation phase (i.e. see step #5 in Fig. 1f). Therefore, there is no need to send the old and new C-RNTI values during the inter-gNB handover procedure as described above. This means that all candidate gNBs only know the C-RNTI value used by itself, and no gNB other than the initial or source gNB can know the C-RNTI values used by other gNBs.
[0221] In some embodiments, the C-RNTI value can be regarded as a key shared between the serving gNB and the UE. The initial or source gNB, which owns all C-RNTI values of the candidate gNBs, actually owns even more critical information than the C-RNTI values, so that an attacked initial or source gNB will attack all LTM executions and subsequent LTM executions. Therefore, the discussion of NCC protection is based on the assumption that the initial or source gNB will never be attacked. Under such an assumption, the present disclosure proposes to use the C-RNTI shared between the UE and the serving gNB to protect the integrity of the NCC value contained in the MAC CE message.
[0222] Fig. 2a is an interaction diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in Fig. 2a, the embodiment of the present disclosure relates to a communication method for a communication system 100, and the method comprises:
[0223] Step S2101: The first network device sends a first identifier to the terminal.
[0224] In some embodiments, the first network device allocates the first identifier to the terminal.
[0225] In some embodiments, the first network device can be an initial network device.
[0226] In some embodiments, the initial network device can be an initial base station.
[0227] In some embodiments, the initial network device can be a source base station (e.g., source gnb0) in an LTM procedure.
[0228] In some embodiments, the initial network device sends the information containing the first identifier to the terminal.
[0229] In some embodiments, the initial network device sends the information containing the first identifier to the terminal in an LTM preparation (LTM, Preraration) procedure.
[0230] In some embodiments, the first identifier is at least one of:
[0231] a cell radio network temporary identifier (C-RNTI) allocated to the terminal;
[0232] an LTM-specific identifier allocated to the terminal;
[0233] a random number allocated to the terminal.
[0234] Exemplarily, the first identifier can include C-RNTI_0, C-RNTI_1, and C-RNTI_2.
[0235] In some embodiments, the initial network device can send the information containing the first identifier to the terminal through a radio resource control (RRC) configuration message.
[0236] In some embodiments, the first identifier is an identifier allocated to the terminal connected with the first network device.
[0237] In some embodiments, the first identifier is a terminal identifier allocated by the initial network device to a serving network device in an LTM procedure.
[0238] Step S2102: The first network device acquires second information.
[0239] In some embodiments, the second information is information confirmed by the second network device.
[0240] Exemplarily, the second information is first security information.
[0241] In some embodiments, the second information is a first NCC.
[0242] In some embodiments, the first network device is an access network device.
[0243] In some embodiments, the first network device is an initial base station, a source base station, and / or a serving base station in the LTM Execution phase.
[0244] In some embodiments, the first network device is a serving base station in the Subsequent LTM Execution phase.
[0245] In some embodiments, the first network device determines the second information.
[0246] In some embodiments, the first network device selects the second information.
[0247] In some embodiments, the first network device sends the second information to the second network device.
[0248] In some embodiments, the first network device receives the second information confirmed by the second network device.
[0249] For example, the first network device selects the second information; the first network device sends the second information to the second network device; the second network device confirms the second information; and the second network device sends the second information to the first network device.
[0250] In some embodiments, the second network device is a candidate access network device, e.g., a candidate base station, for performing handover for the terminal.
[0251] Step S2103: The first network device generates third information.
[0252] In some embodiments, the first network device generates the third information based on the second information and fourth information.
[0253] In some embodiments, the third information is second security information.
[0254] In some embodiments, the fourth information is information associated with the first identifier.
[0255] In some embodiments, the fourth information is information obtained by performing hash processing on the first identifier.
[0256] In some embodiments, the first network device performs hash processing on the first identifier to obtain the fourth information.
[0257] Exemplarily, the first network device performs a hash processing on the first identity to obtain the fourth information; and the first network device generates the third information based on the second information and the fourth information.
[0258] In some embodiments, the third information and the fourth information are used to verify the second information.
[0259] In some embodiments, the second information is a first NCC (e.g., NCC1); and the first NCC is encoded by using the fourth information to obtain the third information.
[0260] Exemplarily, the second information is a first NCC; the first network device performs a hash processing on the first identity to obtain the fourth information; and the first NCC is encoded by using the fourth information to obtain the third information.
[0261] In some embodiments, an exclusive OR operation is performed on the fourth information and the first NCC to obtain the third information.
[0262] Step S2104: The first network device sends the first information to the terminal.
[0263] In some embodiments, the terminal receives the first information sent by the first network device.
[0264] Exemplarily, the first information is third security information.
[0265] In some embodiments, the first information includes: second information and third information.
[0266] In some embodiments, a first media access control (MAC) control element (CE) message is sent to the terminal, and the first MAC CE message includes the first information.
[0267] In some embodiments, the first information is sent to the terminal in an inter-base station LTM procedure performed by the terminal and the first network device.
[0268] In some embodiments, the inter-base station LTM procedure includes an initial inter-base station LTM procedure and a subsequent inter-base station LTM procedure.
[0269] In some embodiments, the first information is sent to the terminal in the inter-base station LTM procedure performed by the terminal and the first network device, including at least one of: the first information is sent to the terminal in an initial inter-base station LTM procedure performed by the terminal and the first network device; and the first information is sent to the terminal in a subsequent inter-base station LTM procedure performed by the terminal and the first network device.
[0270] In some embodiments, the first information is sent to the terminal in an initial inter-base station LTM procedure performed by the terminal and the first network device; wherein the inter-base station LTM procedure comprises the initial inter-base station LTM procedure.
[0271] In some embodiments, the first information is sent to the terminal in a subsequent inter-base station LTM procedure performed by the terminal and the first network device; wherein the inter-base station LTM procedure comprises the subsequent inter-base station LTM procedure.
[0272] Step S2105: The terminal verifies the second information.
[0273] In some embodiments, after receiving the first information, the terminal verifies the second information based on the second information, the third information and the fourth information.
[0274] In some embodiments, the first network device and the terminal share the fourth information.
[0275] In some embodiments, the terminal decodes the third information based on the fourth information to obtain fifth information.
[0276] In some embodiments, the terminal determines whether the second information passes verification based on a comparison result of the second information and the fifth information.
[0277] In some embodiments, the second information and the fifth information can be the same or different.
[0278] In some embodiments, the terminal determines whether the second information passes verification based on a comparison result of the second information and the fifth information, comprising at least one of: the terminal determines that the second information is the same as the fifth information, and the terminal determines that the second information passes verification; the terminal determines that the second information is different from the fifth information, and the terminal determines that the second information fails verification.
[0279] In some embodiments, the terminal determines that the second information is the same as the fifth information, and the terminal determines that the second information passes verification.
[0280] In some embodiments, the terminal determines that the second information is different from the fifth information, and the terminal determines that the second information fails verification.
[0281] In some embodiments, the terminal encodes the second information based on the fourth information to obtain sixth information.
[0282] In some embodiments, the terminal determines whether the second information passes verification based on a comparison result of the third information and the sixth information.
[0283] In some embodiments, the third information and the sixth information can be the same or different.
[0284] In some embodiments, the terminal determines whether the second information passes the verification based on a comparison result of the third information and the sixth information, including: when the terminal determines that the third information is the same as the sixth information, the terminal determines that the second information passes the verification; and when the terminal determines that the third information is different from the sixth information, the terminal determines that the second information does not pass the verification.
[0285] In some embodiments, the terminal determines that the third information is the same as the sixth information, and determines that the second information passes the verification.
[0286] In some embodiments, the terminal determines that the third information is different from the sixth information, and determines that the second information does not pass the verification.
[0287] In some embodiments, the term "information" can be replaced by the terms "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "field", "data", and the like.
[0288] In some embodiments, the term "send" can be replaced by the terms "transmit", "report", "transport", and the like.
[0289] The communication method related to the embodiments of the present disclosure can include at least one of steps S2101 to S2105. For example, step S2102 can be implemented as an independent embodiment, step S2104 can be implemented as an independent embodiment, and step S2105 can be implemented as an independent embodiment. For example, step S2104 in combination with step S2105 can be implemented as an independent embodiment, step S2103 in combination with step S2104 and step S2105 can be implemented as an independent embodiment, step S2102 in combination with step S2103, step S2104 and step S2105 can be implemented as an independent embodiment, and step S2101 in combination with step S2102, step S2103, step S2104 and step S2105 can be implemented as an independent embodiment, but not limited thereto. It should be noted that each step can be independently implemented, or can be arbitrarily exchanged in order and freely combined for implementation without contradiction.
[0290] FIG. 3a is a flow diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 3a, the embodiment of the present disclosure relates to a communication method, which is performed by a first network device, and the method comprises the following steps.
[0291] Step S3101: allocating a first identifier to the terminal.
[0292] In some embodiments, optional implementation of step S3101 can refer to optional implementation of step S2101 in FIG. 2a and other associated parts in the embodiments related to FIG. 2a, which will not be repeated here.
[0293] Step S3102: obtaining second information.
[0294] In some embodiments, the first network device receives the second information sent by the second network device, but is not limited thereto, and can also receive the second information sent by other subjects.
[0295] In some embodiments, the first network device obtains the second information specified by a protocol.
[0296] In some embodiments, the first network device obtains the second information from upper layer(s).
[0297] In some embodiments, the first network device processes to obtain the second information.
[0298] In some embodiments, step S3102 is omitted, and the first network device autonomously implements the function indicated by the second information, or the above function is default or default.
[0299] In some embodiments, optional implementation of step S3102 can refer to optional implementation of step S2102 in FIG. 2a and other associated parts in the embodiments related to FIG. 2a, which will not be repeated here.
[0300] Step S3103: generating third information.
[0301] In some embodiments, optional implementation of step S3103 can refer to optional implementation of step S2103 in FIG. 2a and other associated parts in the embodiments related to FIG. 2a, which will not be repeated here.
[0302] Step S3104: sending the first information to the terminal.
[0303] In some embodiments, optional implementation of step S3104 can refer to optional implementation of step S2104 in FIG. 2a and other associated parts in the embodiments related to FIG. 2a, which will not be repeated here.
[0304] The communication method related to the embodiments of the present disclosure can include at least one of steps S3101 to S3104. For example, step S3101 can be implemented as an independent embodiment, step S3102 can be implemented as an independent embodiment, step S3103 can be implemented as an independent embodiment, and step S3104 can be implemented as an independent embodiment. For example, step S3103 in combination with step S3104 can be implemented as an independent embodiment, step S3101 in combination with step S3103 and step S3104 can be implemented as an independent embodiment, and step S3101 in combination with step S3102, step S3103 and step S3104 can be implemented as an independent embodiment, but the present disclosure is not limited thereto. It should be noted that each step can be implemented independently, or in the case of no contradiction, the order can be arbitrarily exchanged and combined freely.
[0305] FIG. 3b is a flow diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 3b, the embodiments of the present disclosure relate to a communication method, which is performed by a first network device, and the above method includes the following steps.
[0306] Step S3201: sending first information to a terminal.
[0307] In some embodiments, the first information includes second information and third information; the second information is information confirmed by a second network device; the third information is information generated based on the second information and fourth information; the third information and the fourth information are used to verify the second information; the fourth information is information associated with a first identifier; the first identifier is an identifier allocated to the terminal; the first network device is a serving network device of the terminal, and the second network device is a candidate network device performing handover for the terminal.
[0308] In some embodiments, the optional implementation of step S3201 can refer to the optional implementation of step S2104 in FIG. 2a and other associated parts in the embodiments related to FIG. 2a, which will not be described here.
[0309] In some embodiments, the first identifier is an identifier allocated to the terminal by a serving network device in a layer 1 (L1) or layer 2 (L2) triggered mobility (LTM) process.
[0310] In some embodiments, the sending of the first information to the terminal includes:
[0311] sending a first medium access control (MAC) control element (CE) message to the terminal;
[0312] The first MAC CE message includes the first information.
[0313] In some embodiments, the sending the first information to the terminal comprises:
[0314] The first information is sent to the terminal in an inter-base station LTM procedure performed by the terminal and the first network device.
[0315] In some embodiments, the sending the first information to the terminal in the inter-base station LTM procedure performed by the terminal and the first network device comprises at least one of:
[0316] The first information is sent to the terminal in an initial inter-base station LTM procedure performed by the terminal and the first network device.
[0317] The first information is sent to the terminal in a subsequent inter-base station LTM procedure performed by the terminal and the first network device.
[0318] In some embodiments, the method further comprises:
[0319] Determining the second information;
[0320] Sending the second information to the second network device;
[0321] Receiving the second information confirmed by the second network device.
[0322] In some embodiments, the method comprises:
[0323] Generating the third information based on the second information and the fourth information.
[0324] In some embodiments, the second information is a first next hop change counter parameter NCC, and the generating the third information based on the second information and the fourth information comprises:
[0325] Encoding the first NCC by using the fourth information to obtain the third information.
[0326] In some embodiments, the encoding the first NCC by using the fourth information to obtain the third information comprises:
[0327] Performing an exclusive or operation of the fourth information and the first NCC to obtain the third information.
[0328] In some embodiments, the method further comprises:
[0329] Performing hash processing on the first identifier to obtain the fourth information.
[0330] In some embodiments, the first identifier is at least one of:
[0331] a cell radio network temporary identifier (C-RNTI) assigned to the terminal;
[0332] an LTM dedicated identifier assigned to the terminal;
[0333] a random number assigned to the terminal.
[0334] FIG. 4a is a flow diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 4a, the embodiment of the present disclosure relates to a communication method, which is performed by a terminal, and the above method comprises:
[0335] Step S4101: obtaining first information.
[0336] In some embodiments, the terminal receives the first information sent by the first network device, but is not limited thereto, and can also receive the first information sent by other subjects.
[0337] In some embodiments, the terminal obtains the first information specified by a protocol.
[0338] In some embodiments, the terminal obtains the first information from upper layer(s).
[0339] In some embodiments, the terminal processes to obtain the first information.
[0340] In some embodiments, step S4101 is omitted, and the terminal autonomously implements the function indicated by the second information, or the above function is default or default.
[0341] In some embodiments, the optional implementation of step S4101 can refer to the optional implementation of step S2104 of FIG. 2a and other associated parts in the embodiments related to FIG. 2a, which will not be repeated here.
[0342] Step S4102: verifying the second information.
[0343] In some embodiments, the optional implementation of step S4102 can refer to the optional implementation of step S2105 of FIG. 2a and other associated parts in the embodiments related to FIG. 2a, which will not be repeated here.
[0344] FIG. 4b is a flow diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 4b, the embodiment of the present disclosure relates to a communication method, which is performed by a terminal, and the above method comprises:
[0345] Step S4201: receiving first information sent by a first network device.
[0346] In some embodiments, the first information comprises: second information and third information; the second information is information confirmed by the second network device; the third information is information generated based on the second information and fourth information; the third information and the fourth information are used for verifying the second information; the fourth information is information associated with a first identifier; the first identifier is an identifier assigned to the terminal; the first network device is a serving network device of the terminal, and the second network device is a candidate network device performing handover for the terminal.
[0347] In some embodiments, the optional implementation of step S4201 can refer to the optional implementation of step S2105 in FIG. 2a and other associated parts in the embodiments involved in FIG. 2a, which will not be repeated here.
[0348] In some embodiments, the first identifier is an identifier assigned to the terminal by a serving network device in an LTM process.
[0349] In some embodiments, the receiving of the first information sent by the first network device comprises:
[0350] receiving a first MAC CE message sent by the first network device.
[0351] The first MAC CE message contains the first information.
[0352] In some embodiments, the receiving of the first information sent by the first network device comprises:
[0353] In some embodiments, the receiving of the first information sent by the first network device comprises:
[0354] In some embodiments, the receiving of the first information sent by the first network device comprises:
[0355] In some embodiments, the receiving of the first information sent by the first network device comprises:
[0356] In some embodiments, the receiving of the first information sent by the first network device comprises:
[0357] In some embodiments, the second information is a first next hop counter NCC, and the third information is security information obtained by encoding the first NCC using the fourth information.
[0358] In some embodiments, the third information is security information obtained after performing XOR operation between the first NCC and the fourth information.
[0359] In some embodiments, the fourth information is information obtained after performing hash processing on the first identifier.
[0360] In some embodiments, the first identifier is at least one of:
[0361] a cell radio network temporary identifier (C-RNTI) allocated to the terminal;
[0362] an LTM dedicated identifier allocated to the terminal;
[0363] a random number allocated to the terminal.
[0364] In some embodiments, the method further comprises:
[0365] verifying the second information based on the second information, the third information and the fourth information;
[0366] wherein the first network device and the terminal share the fourth information.
[0367] In some embodiments, the verifying the second information based on the second information, the third information and the fourth information comprises:
[0368] decoding the third information based on the fourth information to obtain fifth information;
[0369] determining whether the second information passes the verification based on a comparison result of the second information and the fifth information.
[0370] In some embodiments, the determining whether the second information passes the verification based on the comparison result of the second information and the fifth information comprises at least one of:
[0371] determining that the second information passes the verification when the second information is identical to the fifth information;
[0372] determining that the second information does not pass the verification when the second information is different from the fifth information.
[0373] In some embodiments, the verifying the second information based on the second information, the third information and the fourth information comprises:
[0374] encoding the second information based on the fourth information to obtain sixth information;
[0375] determine whether the second information passes verification based on a comparison result of the third information and the sixth information.
[0376] In some embodiments, the determining whether the second information passes verification based on the comparison result of the third information and the sixth information comprises:
[0377] determining that the third information is the same as the sixth information, and determining that the second information passes verification;
[0378] determining that the third information is different from the sixth information, and determining that the second information does not pass verification.
[0379] In some embodiments, the method further comprises:
[0380] performing hash processing on the first identifier to obtain the third information.
[0381] FIG. 5a is an interaction schematic diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 5a, the embodiment of the present disclosure relates to a communication method, which is used in a communication system, and the method comprises one of the following steps:
[0382] Step S5101: The first network device sends first information to the terminal.
[0383] In some embodiments, the first information comprises second information and third information; the second information is information confirmed by a second network device; the third information is information generated based on the second information and fourth information; the third information and the fourth information are used to verify the second information; the fourth information is information associated with a first identifier; the first identifier is an identifier allocated to the terminal; the first network device is a serving network device of the terminal, and the second network device is a candidate network device performing handover for the terminal.
[0384] The optional implementation of step S5101 can refer to the optional implementation of step S2104 in FIG. 2a and other associated parts in the embodiments involved in FIG. 2a, which will not be described here.
[0385] In some embodiments, the above method can comprise the method of the above-mentioned communication system side, terminal side, network device side and the like embodiments, which will not be described here.
[0386] In order to better understand the embodiments of the present disclosure, the technical solutions of the present disclosure are further described below through an exemplary embodiment:
[0387] Example 1
[0388] Please refer to FIG. 6a, which provides a communication method, the communication method comprising:
[0389] Step S6101: allocating C-RNTI.
[0390] In some embodiments, during LTM preparation between the UE and the serving or source gNB (corresponding to the initial network device in the present disclosure), the UE is allocated a C-RNTI value (e.g., C-RNTI_0, C-RNTI_1 and / or C-RNTI_2, corresponding to the first identity in the present disclosure) to be used with all candidate gNBs.
[0391] Step S6102: L1 measurement report.
[0392] In some embodiments, when the UE moves, the UE sends an L1 measurement report to the serving or source gNB.
[0393] Step S6103: determining NCC1.
[0394] In some embodiments, after selecting the target gNB (candidate gNB1, corresponding to the second network device in the present disclosure), the serving or source gNB (corresponding to the first network device in the present disclosure) determines whether to trigger the LTM procedure. If the serving or source gNB does not have any unused NH, the serving or source gNB derives K gNB0 Deriving K NG-RAN *(i.e. K NG-RAN *←KDF(K gNB0 , cell ID)). If the serving or source gNB has an unused NH (associated with NCC1), the serving or source gNB derives K NG-RAN *(i.e. K NG-RAN *←KDF(NH1, cell ID)).
[0395] Step S6104: the serving or source gNB sends the derived K NG-RAN *and the NCC value (NCC1) used for K NG-RAN *derivation to candidate gNB1. gNB1 uses K NG-RAN *as K gNB1 . And returns the NCC value (NCC1) to the serving or source gNB.
[0396] Step S6104 includes:
[0397] Step S6104a: sending a handshaking request containing NCC1;
[0398] Step S6104b: obtaining K gNB1 ;
[0399] Step S6104c: sending a handshaking request response containing NCC1.
[0400] Step S6105: encode NCC1.
[0401] In some embodiments, upon receiving the NCC value (NCC1) returned by the candidate gNB1, the serving or source gNB first performs a hash operation on the C-RNTI value assigned to the UE (i.e., C-RNTI_0), and then encodes NCC1 by performing XOR operation between the hash operation result value of C-RNTI (i.e., H(C-RNTI_0)) and NCC1.
[0402] Exemplarily, the encoded NCC value [NCC1] = NCC1 xor H(C-RNTI_0).
[0403] Step S6106: send the MAC CE.
[0404] In some embodiments, the serving or source gNB includes the plaintext of NCC1 and the encoded NCC value [NCC1] in the MAC CE sent to the UE. The mechanism of the MAC CE is shown in FIG. 6b.
[0405] Step S6107: perform verification.
[0406] In some embodiments, the verification is performed upon receiving the MAC CE from the serving or source gNB.
[0407] Exemplarily, the UE first retrieves the plaintext of NCC1 and the encoded NCC value [NCC1] from the MAC CE message, performs a hash operation on the C-RNTI value assigned by the serving or source gNB0 (C-RNTI_0), and uses the operation result of C-RNTI_0 to verify the NCC value [NCC1].
[0408] For example, the NCC verification can be to compare [received NCC1 xor H(C-RNTI_0)] with the received [NCC1].
[0409] In some embodiments, if the decoded NCC value is the same as the K gNB0 associated with the current active NCC, the UE performs horizontal key derivation (i.e., K NG-RAN *←KDF(K gNB0 ,cell ID)). If the decoded NCC value is different from the K gNB0 associated with the current active NCC, the UE derives NH, and then derives K NG-RAN *(i.e., NH1=KDF(NH,K AMF ), K NG-RAN *←KDF(NH1,cell ID)).
[0410] In some embodiments, the UE detaches from the serving or source gNB and applies the configuration of the target gNB (candidate gNB1), including setting K NG-RAN *As K gNB1 Used with gNB1.
[0411] Step S6108: The UE sends an RRC reconfiguration complete message to gNB1.
[0412] Step S6109: N2 path switching.
[0413] In some embodiments, the target gNB (gNB1) sends an N2 path switching request to the AMF, and the AMF returns new NH and NCC (NH2, NCC2) to gNB1.
[0414] Step S6110: L1 Measurement Report.
[0415] In some embodiments, when the UE remains mobile, the UE sends an L1 measurement report to the serving or source gNB (gNB1).
[0416] Step S6111: Determine NCC2.
[0417] In some embodiments, after selecting the target gNB (candidate gNB2), the serving gNB (gNB1) determines whether the LTM process needs to be triggered.
[0418] In some embodiments, service gNB1 further determines K for deriving from NH associated with the NCC value. NG-RAN The NCC value (NCC2).
[0419] In some embodiments, the NCC value = NCC1 is used for horizontal key export; the NCC value = NCC2 is used for vertical key export.
[0420] In some embodiments, because the service or source gNB has unused NH (i.e., NH2 associated with NCC2), the service or source gNB derives K from the unused NH. NG-RAN *(ieK NG-RAN *←KDF(K gNB1 (cell ID)).
[0421] Note: If a further intra-CU switch is triggered, neither the service nor the source gNB will have any unused NH, therefore from K gNB1 Export K NG-RAN *(ieK NG-RAN *←KDF(K gNB1 (cell ID)).
[0422] Step S6112: The serving gNB1 sends the derived K NG-RAN *and the NCC value (NCC2) to the candidate gNB2. The gNB2 sends K NG-RAN *as K NG-RAN *and returns the NCC value (NCC2) to the gNB1. gNB2
[0423] Step S6112 includes:
[0424] Step S6112a: Send Handshake Request containing NCC2;
[0425] Step S6112b: Obtain K gNB2 ;
[0426] Step S6112c: Send Handshake Response containing NCC2.
[0427] Step S6113: Encode NCC2.
[0428] In some embodiments, when receiving the NCC value (NCC2) returned by the gNB2, the serving gNB1 first performs a hash operation on the configured C-RNTI value (i.e. C-RNTI_1) assigned to the UE, and then encodes the NCC2 by performing XOR operation between the NCC2 and the operation result of the C-RNTI (i.e. H(C-RNTI_1)).
[0429] Illustratively, the encoded NCC value [NCC2] = NCC2 xor H(C-RNTI_1).
[0430] Step S6114: Send MAC CE.
[0431] In some embodiments, the gNB1 includes the plaintext of the NCC2 and the encoded NCC value [NCC2] in the MAC CE sent to the UE.
[0432] Step S6115: Perform verification.
[0433] In some embodiments, the verification is performed when receiving the MAC CE from the serving or source gNB.
[0434] In some embodiments, the UE first retrieves the plaintext of the NCC2 and the encoded NCC value [NCC2] from the MAC CE message, performs a hash operation on the C-RNTI value assigned to the serving or source gNB1 (C-RNTI_1), and uses the operation result value of the C-RNTI_1 to verify the NCC value [NCC2].
[0435] For example, the NCC verification can be a comparison of [received NCC2 xor H(C-RNTI_1)] with received [NCC2].
[0436] In some embodiments, if the decoded NCC value is the same as the NCC associated with the currently active K gNB1 , the UE performs horizontal key derivation (i.e., K NG-RAN * = KDF (K gNB1 , Cell ID)). If the decoded NCC value is different from the NCC associated with the currently active K gNB1 , the UE performs vertical key derivation by deriving NH and then deriving K NG-RAN * (i.e., NH2 = KDF (NH1, K AMF ), K NG-RAN * = KDF (NH2, Cell ID)).
[0437] In some embodiments, the UE detaches from the serving or source gNB and applies the configuration of the target gNB (candidate gNB2), including using K NG-RAN * as K gNB2 to use with gNB2.
[0438] Step S6116: The UE sends an RRC reconfiguration complete message to gNB2.
[0439] Step S6117: N2 path switch.
[0440] In some embodiments, the target gNB (gNB2) sends an N2 path switch request to the AMF, which returns a new NH and NCC (NH3, NCC3) to gNB2.
[0441] Step S6118: Perform subsequent procedures.
[0442] With the above procedure, even if an attacker tampers with the NCC value sent via the MAC CE message (e.g., changes NCC1 to NCCx), the attacker cannot encode NCCx using the C-RNTI known only to the UE and the serving gNB. Then, the verification of the received NCCx performed by the UE will never be successful because the UE does not receive the correctly encoded NCCx value xored with the C-RNTI.
[0443] Embodiments of the present disclosure also propose apparatuses for implementing any of the above methods, for example, propose an apparatus including units or modules to implement each step performed by a terminal in any of the above methods. For another example, another apparatus is also proposed, including units or modules to implement each step performed by a network device (e.g., an access network device, a core network function node, a core network device, etc.) in any of the above methods.
[0444] It should be understood that the division of each unit or module in the above apparatus is only a logical function division, and all or part of them can be integrated into a physical entity or physically separated in actual implementation. In addition, the units or modules in the apparatus can be implemented in the form of processor calling software: for example, the apparatus includes a processor connected with a memory, the memory stores instructions, and the processor calls the instructions stored in the memory to implement any of the above methods or realize the functions of the units or modules of the above apparatus, wherein the processor is a general processor such as a central processing unit (CPU) or a microprocessor, and the memory is a memory in the apparatus or a memory outside the apparatus. Alternatively, the units or modules in the apparatus can be implemented in the form of hardware circuit, and the functions of part or all of the units or modules can be realized by the design of the hardware circuit. The above hardware circuit can be understood as one or more processors; for example, in one implementation, the above hardware circuit is an application-specific integrated circuit (ASIC), and the functions of part or all of the units or modules are realized by the design of the logical relationship of the elements in the circuit; for another example, in another implementation, the above hardware circuit is a programmable logic device (PLD), and a field programmable gate array (FPGA) is taken as an example, which can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by a configuration file, so as to realize the functions of part or all of the units or modules. All units or modules of the above apparatus can be implemented in the form of processor calling software, or all units or modules can be implemented in the form of hardware circuit, or part of the units or modules are implemented in the form of processor calling software, and the remaining part is implemented in the form of hardware circuit.
[0445] In the embodiments of the present disclosure, the processor is a circuit with signal processing capability. In one implementation, the processor can be a circuit with instruction reading and running capability, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), a digital signal processor (DSP), and the like. In another implementation, the processor can implement certain functions through a logical relationship of hardware circuit, and the logical relationship of the hardware circuit is fixed or reconfigurable. For example, the processor is a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In the reconfigurable hardware circuit, the processor loads a configuration document to implement the configuration of the hardware circuit. It can be understood that the processor loads instructions to implement the functions of the above part or all units or modules. In addition, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), and the like.
[0446] FIG. 7a is a structural schematic diagram of the first network device 7100 according to an embodiment of the present disclosure. As shown in FIG. 7a, the first network device 7100 can include at least one of a transceiver module 7101, a processing module 7102, and the like. Optionally, the transceiver module is configured to perform at least one of the communication steps, such as transmitting and / or receiving, performed by the first network device 7100 in any of the above methods, and details are not described herein again. Optionally, the processing module is configured to perform at least one of the other steps performed by the first network device 7100 in any of the above methods, and details are not described herein again.
[0447] FIG. 7b is a structural schematic diagram of the terminal 7200 according to an embodiment of the present disclosure. As shown in FIG. 7b, the terminal 7200 can include at least one of a transceiver module 7201, a processing module 7202, and the like. Optionally, the transceiver module is configured to perform at least one of the communication steps such as sending and / or receiving performed by the terminal 7200 in any of the above methods, details of which are not repeated here. In some embodiments, the transceiver module can include a sending module and / or a receiving module, which can be separate or integrated together. Optionally, the transceiver module can be mutually replaced with a transceiver. Optionally, the processing module is configured to perform at least one of the other steps performed by the terminal 7200 in any of the above methods, details of which are not repeated here.
[0448] In some embodiments, the processing module can be a module or can include multiple sub-modules. Optionally, the multiple sub-modules perform all or part of the steps required to be performed by the processing module, respectively. Optionally, the processing module can be mutually replaced with a processor.
[0449] FIG. 8a is a structural schematic diagram of a communication device 8100 according to an embodiment of the present disclosure. The communication device 8100 can be a network device (such as an access network device, a core network device, and the like), a terminal (such as a user equipment, and the like), a chip, a chip system, or a processor supporting the network device to implement any of the above methods, or a chip, a chip system, or a processor supporting the terminal to implement any of the above methods. The communication device 8100 can be used to implement the methods described in the above method embodiments, which can be referred to the descriptions in the above method embodiments.
[0450] As shown in FIG. 8a, the communication device 8100 includes one or more processors 8101. The processor 8101 can be a general purpose processor or a special purpose processor, for example, a baseband processor or a central processing unit. The baseband processor can be configured to process communication protocols and communication data, and the central processing unit can be configured to control the communication device (such as a base station, a baseband chip, a terminal device, a terminal device chip, a DU or a CU, and the like), execute programs, and process data of the programs. The communication device 8100 is configured to execute any of the above methods.
[0451] In some embodiments, the communication device 8100 further includes one or more memories 8102 configured to store instructions. Optionally, all or part of the memory 8102 can also be outside the communication device 8100.
[0452] In some embodiments, the communication device 8100 further includes one or more transceivers 8103. When the communication device 8100 includes one or more transceivers 8103, the transceiver 8103 performs at least one of the communication steps such as sending and / or receiving in the above methods, and the processor 8101 performs at least one of the other steps.
[0453] In some embodiments, the transceiver can include a receiver and / or a transmitter, which can be separate or integrated together. Optionally, the terms transceiver, transceiving unit, transceiver, transceiving circuit, etc. can be replaced by each other, the terms transmitter, transmitting unit, transmitter, transmitting circuit, etc. can be replaced by each other, and the terms receiver, receiving unit, receiver, receiving circuit, etc. can be replaced by each other.
[0454] In some embodiments, the communication device 8100 can include one or more interface circuits 8104. Optionally, the interface circuit 8104 is connected with the memory 8102, and the interface circuit 8104 can be used to receive signals from the memory 8102 or other devices, and can be used to send signals to the memory 8102 or other devices. For example, the interface circuit 8104 can read instructions stored in the memory 8102 and send the instructions to the processor 8101.
[0455] The communication device 8100 described in the above embodiments can be a network device or a terminal, but the scope of the communication device 8100 described in the present disclosure is not limited thereto, and the structure of the communication device 8100 can not be limited by Figure 8a. The communication device can be a standalone device or can be part of a larger device. For example, the communication device can be: 1) a standalone integrated circuit (IC), or a chip, or a chip system or subsystem; (2) a set of one or more ICs, which can optionally also include storage components for storing data, programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, terminal device, smart terminal device, cellular phone, wireless device, handset, mobile unit, vehicle-mounted device, network device, cloud device, artificial intelligence device, etc.; (6) other, etc.
[0456] Figure 8b is a structural schematic diagram of a chip 8200 according to an embodiment of the present disclosure. For the case where the communication device 8100 is a chip or a chip system, the structural schematic diagram of the chip 8200 shown in Figure 8b can be referred to, but is not limited thereto.
[0457] The chip 8200 includes one or more processors 8201, and the chip 8200 is configured to execute any of the above methods.
[0458] In some embodiments, the chip 8200 further includes one or more interface circuits 8202. Optionally, the interface circuits 8202 are connected with the memory 8203, and the interface circuits 8202 can be configured to receive signals from the memory 8203 or other devices, and the interface circuits 8202 can be configured to send signals to the memory 8203 or other devices. For example, the interface circuits 8202 can read instructions stored in the memory 8203 and send the instructions to the processor 8201.
[0459] In some embodiments, the interface circuits 8202 perform at least one of the communication steps (for example, step S2101, step S3101, but not limited thereto) in the above-described methods, and the processor 8201 performs at least one of the other steps.
[0460] In some embodiments, the interface circuits, interfaces, transceiver pins, transceivers, and the like can be replaced with each other.
[0461] In some embodiments, the chip 8200 further includes one or more memories 8203 for storing instructions. Optionally, all or part of the memories 8203 can be outside the chip 8200.
[0462] The present disclosure further proposes a storage medium, and the above-mentioned storage medium stores instructions, and when the above-mentioned instructions run on the communication device 8100, the communication device 8100 executes any one of the above methods. Optionally, the above-mentioned storage medium is an electronic storage medium. Optionally, the above-mentioned storage medium is a computer readable storage medium, but not limited thereto, and it can also be a storage medium readable by other devices. Optionally, the above-mentioned storage medium can be a non-transitory storage medium, but not limited thereto, and it can also be a transitory storage medium.
[0463] The present disclosure further proposes a program product, and the above-mentioned program product is executed by the communication device 8100, so that the communication device 8100 executes any one of the above methods. Optionally, the above-mentioned program product is a computer program product.
[0464] The present disclosure further proposes a computer program, and when it runs on a computer, it makes the computer execute any one of the above methods.
Claims
1. A communication method characterized by comprising: The method is performed by a first network device, and the method comprises: sending first information to a terminal; wherein the first information comprises second information and third information; the second information is information confirmed by a second network device; the third information is information generated based on the second information and fourth information; the third information and the fourth information are used for verifying the second information; the fourth information is information associated with a first identifier; the first identifier is an identifier allocated to the terminal; the first network device is a serving network device of the terminal, and the second network device is a candidate network device performing handover for the terminal.
2. The method of claim 1, wherein, The first identifier is an identifier allocated to the terminal by an initial network device in a layer 1 (L1) or layer 2 (L2) triggered mobility (LTM) procedure.
3. The method according to claim 1 or 2, characterized in that, The method further comprises: determining the second information; sending the second information to the second network device; receiving the confirmed second information sent by the second network device.
4. The method according to any one of claims 1 to 3, characterized in that, The method comprises: generating the third information based on the second information and the fourth information.
5. The method according to any one of claims 1 to 4, characterized in that, The second information is a first next hop count counter (NCC) parameter. The generating of the third information based on the second information and the fourth information comprises: encoding the first NCC by using the fourth information to obtain the third information.
6. The method of claim 5, wherein, The encoding of the first NCC by using the fourth information to obtain the third information comprises: performing an exclusive or operation of the fourth information and the first NCC to obtain the third information.
7. The method according to any one of claims 1 to 6, characterized in that, The method further comprises: performing hash processing on the first identifier to obtain the fourth information.
8. The method according to any one of claims 1 to 7, characterized in that, The sending of the first information to the terminal comprises: sending a first medium access control (MAC) control element (CE) message to the terminal; wherein the first MAC CE message comprises the first information.
9. The method of any one of claim 8, wherein, The sending of the first information to the terminal comprises: sending the first information to the terminal in an inter-base station LTM procedure performed by the terminal and the first network device.
10. The method of claim 9, wherein, The sending of the first information to the terminal in the inter-base station LTM procedure performed by the terminal and the first network device comprises at least one of: sending the first information to the terminal in an initial inter-base station LTM procedure performed by the terminal and the first network device; sending the first information to the terminal in a subsequent inter-base station LTM procedure performed by the terminal and the first network device.
11. The method according to any one of claims 1 to 10, characterized in that, The first identifier is at least one of: a cell radio network temporary identifier (C-RNTI) allocated to the terminal; an LTM dedicated identifier allocated to the terminal; a random number allocated to the terminal.
12. A communication method characterized by comprising: The method is performed by a terminal, and the method comprises: receiving first information sent by a first network device; The first information includes second information and third information; the second information is information confirmed by a second network device; the third information is information generated based on the second information and fourth information; the third information and the fourth information are used to verify the second information; the fourth information is information associated with a first identifier; the first identifier is an identifier assigned to the terminal; the first network device is a serving network device of the terminal, and the second network device is a candidate network device performing handover of the terminal.
13. The method of claim 12, wherein, The first identifier is a terminal identifier assigned by an initial network device to a serving network device in an LTM process.
14. The method according to claim 12 or 13, characterized in that, The second information is a first next hop count counter parameter NCC, and the third information is security information obtained by encoding the first NCC using the fourth information.
15. The method of claim 14, wherein, The third information is security information obtained by performing an exclusive OR operation on the first NCC and the fourth information.
16. The method according to any one of claims 12 to 15, characterized in that, The fourth information is information obtained by performing a hash process on the first identifier.
17. The method according to any one of claims 12 to 16, characterized in that, The method further includes: verifying the second information based on the second information, the third information, and the fourth information; The first network device and the terminal share the fourth information.
18. The method of claim 17, wherein, The verification of the second information based on the second information, the third information, and the fourth information includes: decoding the third information based on the fourth information to obtain fifth information; determining whether the second information passes verification based on a comparison result of the second information and the fifth information.
19. The method of claim 18, wherein, The determination of whether the second information passes verification based on the comparison result of the second information and the fifth information includes at least one of: determining that the second information and the fifth information are the same, and determining that the second information passes verification; determining that the second information and the fifth information are different, and determining that the second information does not pass verification.
20. The method of claim 17, wherein, The verification of the second information based on the second information, the third information, and the fourth information includes: encoding the second information based on the fourth information to obtain sixth information; determining whether the second information passes verification based on a comparison result of the third information and the sixth information.
21. The method of claim 20, wherein, The determination of whether the second information passes verification based on the comparison result of the third information and the sixth information includes: determining that the third information and the sixth information are the same, and determining that the second information passes verification; determining that the third information and the sixth information are different, and determining that the second information does not pass verification.
22. The method of any one of claims 17-21, wherein, The method further includes: performing a hash process on the first identifier to obtain the third information.
23. The method of any one of claims 12 to 22, wherein, The receiving of the first information sent by the first network device includes: receiving a first MAC CE message sent by the first network device; The first MAC CE message includes the first information.
24. The method of any one of claims 12-23, wherein, The receiving of the first information sent by the first network device includes: receiving the first information sent by the first network device in an inter-base station LTM process performed by the terminal and the first network device.
25. The method of claim 24, wherein, The receiving the first information sent by the first network device in the process of performing inter-base station LTM between the terminal and the first network device includes: The receiving the first information sent by the first network device in the process of performing initial inter-base station LTM between the terminal and the first network device includes: The receiving the first information sent by the first network device in the process of performing subsequent inter-base station LTM between the terminal and the first network device includes.
26. The method of any one of claims 12-25, wherein, The first identifier is at least one of: A cell radio network temporary identifier (C-RNTI) allocated to the terminal; An LTM-specific identifier allocated to the terminal; A random number allocated to the terminal.
27. A method of communication, comprising: The method further includes: The first network device sends first information to the terminal. The first information includes second information and third information; the second information is information confirmed by a second network device; the third information is information generated based on the second information and fourth information; the third information and the fourth information are used to verify the second information; the fourth information is information associated with a first identifier; the first identifier is an identifier allocated to the terminal; the first network device is a serving network device of the terminal, and the second network device is a candidate network device performing handover for the terminal.
28. A first network device, comprising: The first network device includes: The transceiver module is configured to: Send first information to the terminal. The first information includes second information and third information; the second information is information confirmed by a second network device; the third information is information generated based on the second information and fourth information; the third information and the fourth information are used to verify the second information; the fourth information is information associated with a first identifier; the first identifier is an identifier allocated to the terminal; the first network device is a serving network device of the terminal, and the second network device is a candidate network device performing handover for the terminal. The terminal includes:
29. A terminal, characterized by The transceiver module is configured to: Receive first information sent by the first network device. The first information includes second information and third information; the second information is information confirmed by a second network device; the third information is information generated based on the second information and fourth information; the third information and the fourth information are used to verify the second information; the fourth information is information associated with a first identifier; the first identifier is an identifier allocated to the terminal; the first network device is a serving network device of the terminal, and the second network device is a candidate network device performing handover for the terminal. The communication system includes a first network device and a terminal, wherein the first network device is configured to perform the communication method of any one of claims 1 to 11; and the terminal is configured to perform the communication method of any one of claims 12 to 26.
30. A communication system, characterized by The first network device includes:
31. A first network device, comprising: One or more processors; The first network function is used to perform the communication method of any one of claims 1 to 11. The terminal includes:
32. A terminal, characterized by One or more processors; The second network function is configured to perform the communication method of any one of claims 12 to 26.
33. A storage medium characterized by The storage medium stores instructions which, when executed on the communication device, cause the communication device to perform the communication method of any one of claims 1 to 11 and / or claims 12 to 26.
Citation Information
Patent Citations
Information processing method, terminal, communication system and storage medium
CN117136615A
Beam indication method and device, and storage medium
CN117813855A
Communication method, device and system
CN117998495A
Method and apparatus for verifying network
WO2023147767A1