Key processing method, and communication device and storage medium
By using a key to protect key parameters during the mobility triggering process at Layer 1/L2, the problem of key parameter tampering and leakage during transmission is solved, thereby improving security and compatibility.
Patent Information
- Application Number
- PCT/CN2024/105053
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-07-11
- Publication Date
- 2026-01-15
AI Technical Summary
During the Layer 1/L2 triggered mobility process, existing technologies cannot effectively protect key parameters from tampering and leakage during transmission, resulting in insufficient communication security.
The first parameter is protected by using a first key to ensure that it is not tampered with or leaked during transmission. Specific methods include encapsulating the key parameter in a sub-PDU of the MAC message and protecting it with an integrity key, or performing confidentiality protection in the RRC message.
It enables secure transmission of key parameters during the activation of mobility at Layer 1/L2, preventing tampering and leakage, and improving the security and compatibility of communication devices.
Smart Images

Figure CN2024105053_15012026_PF_FP_ABST
Abstract
Description
Key processing methods, communication devices and storage media Technical Field
[0001] This disclosure relates to the field of communication technology, and in particular to a key processing method, communication device and storage medium. Background Technology
[0002] Layer 1 / L2 Triggered Mobility (LTM) refers to a process in which a network, based on Layer 1 (L1) measurement results, triggers a cell switch between the primary cell (PCell) and the primary sencodary cell (PSCell) through the Media Access Control (MAC) control element (CE).
[0003] Summary of the Invention
[0004] This disclosure provides a key processing method, a communication device, and a storage medium.
[0005] According to a first aspect of the present disclosure, a key processing method is provided, executed by a first node, the method comprising: sending a first message to a user equipment (UE); the first message including a first parameter, the first parameter being used by the UE to determine a second key for communication with a second cell; the first parameter being protected by a first key; the first key being a key for communication between the UE and the first cell.
[0006] According to a second aspect of the present disclosure, a key processing method is provided, wherein the method is executed by a user equipment (UE), the method comprising: receiving a first message sent by a first node of a first cell; the first message including a first parameter, the first parameter being used by the UE to determine a second key for communication with a second cell; the first parameter being protected by the first key; the first key being a key for communication between the UE and the first cell.
[0007] A third aspect of the present disclosure provides a first node of a first cell, wherein the first node includes:
[0008] The sending module is configured to send a first message to a user equipment (UE); the first message includes a first parameter, which is used by the UE to determine a second key for communication with a second cell; the first parameter is protected by the first key; the first key is the key for communication between the UE and the first cell.
[0009] A user equipment (UE) is provided according to a fourth aspect of the present disclosure, wherein the UE includes:
[0010] The receiving module is configured to receive a first message sent by a first node of a first cell; the first message includes a first parameter, which is used by the UE to determine a second key for communication with a second cell; the first parameter is protected by the first key; the first key is the key for communication between the UE and the first cell.
[0011] A communication device is provided according to a fifth aspect of the present disclosure, wherein the communication device includes: one or more processors; wherein the processors are configured to invoke instructions to cause the communication device to execute the key processing method provided by any of the technical means of the first to second aspects.
[0012] A sixth aspect of the present disclosure provides a storage medium storing instructions that, when executed on a communication device, cause the communication device to perform a key processing method provided by any one of the first or second aspects.
[0013] According to a seventh aspect of the present disclosure, a program product is provided, wherein the program product includes a computer program, and when the computer program is executed by a communication device, the communication device is able to implement the key processing method provided by any of the technical means of the first to second aspects.
[0014] The technical method provided in this disclosure uses a first key to protect the first parameter, which can prevent the first parameter from being tampered with or leaked during transmission.
[0015] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit the embodiments of this disclosure. Attached Figure Description
[0016] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of embodiments of this disclosure.
[0017] Figure 1A is a schematic diagram of the architecture of a communication system according to an exemplary embodiment;
[0018] Figure 1B is a schematic diagram of the LTM process according to an exemplary embodiment;
[0019] Figure 1C is a schematic diagram illustrating a key derivation process according to an exemplary embodiment;
[0020] Figure 1D is a schematic diagram of a Media Access Control (MAC) control unit (CE) according to an exemplary embodiment;
[0021] Figure 2A is a flowchart illustrating a key processing method according to an exemplary embodiment;
[0022] Figure 2B is a schematic diagram illustrating a MAC message according to an exemplary embodiment;
[0023] Figure 2C is a schematic diagram illustrating a MAC message according to an exemplary embodiment;
[0024] Figure 3 is a flowchart illustrating a key processing method according to an exemplary embodiment;
[0025] Figure 4 is a flowchart illustrating a key processing method according to an exemplary embodiment;
[0026] Figure 5A is a flowchart illustrating a key processing method according to an exemplary embodiment;
[0027] Figure 5B is an information diagram illustrating a first message according to an exemplary embodiment;
[0028] Figure 6A is a schematic diagram of the structure of a first node according to an exemplary embodiment;
[0029] Figure 6B is a schematic diagram of the structure of a UE according to an exemplary embodiment;
[0030] Figure 7A is a schematic diagram of the structure of a communication device according to an exemplary embodiment;
[0031] Figure 7B is a schematic diagram of the structure of a chip according to an exemplary embodiment. Detailed Implementation
[0032] This disclosure provides a key processing method, a communication device, a communication system, and a storage medium.
[0033] The first aspect provides a key processing method, wherein the method is executed by a first node of a first cell, the method comprising:
[0034] Send a first message to the user equipment (UE); the first message includes a first parameter, which is used by the UE to determine a second key for communication with the second cell; the first parameter is protected by the first key; the first key is the key for communication between the UE and the first cell.
[0035] Based on the above scheme, using the first key to protect the first parameter can prevent the first parameter from being tampered with or leaked during transmission.
[0036] In some embodiments of the first aspect, the first message is a Media Access Control (MAC) message; the MAC message includes at least a first sub-protocol data unit (PDU); the first PDU includes a cell change command; the cell change command is used to instruct the UE to access a second cell.
[0037] Thus, using the first message to send the first parameter protected by the first key is simple to implement and highly compatible with related technologies.
[0038] In some embodiments of the first aspect, the first sub-PDU further includes a first parameter. Thus, the first sub-PDU includes the first parameter, meaning that the first parameter and the cell change command are carried in the same sub-PDU within the MAC message. In this way, the UE can simultaneously obtain the cell change command and the first parameter through the first sub-PDU, which is simple to implement.
[0039] In some embodiments of the first aspect, the first key is an integrity key, and at least the first parameter is protected for integrity by the first key.
[0040] The above scheme stipulates that if the first key is an integrity key, then at least the first parameter will be protected for integrity.
[0041] In some embodiments of the first aspect, the first parameter is protected by the integrity of the first key; exemplarily, the first parameter is protected by the integrity of the first key alone; or, the first parameter and the first identifier are protected by the integrity of the first key; the first identifier is associated with the first node.
[0042] The above scheme limits the integrity key to either protecting the integrity of the first parameter alone or protecting the integrity of the first parameter and the first identifier together.
[0043] In some embodiments of the first aspect, the first identifier includes at least one of the following:
[0044] Node identifier, used to indicate the first node;
[0045] Cell identifier, used to identify the cell of the first node to which the UE accesses;
[0046] Configuration identifier, used to identify the cell configuration of the first node accessed by the UE.
[0047] The above scheme may include node identifier, cell identifier and / or configuration identifier, etc., along with the first parameter, but the specific implementation is not limited to the above examples.
[0048] In some embodiments of the first aspect, the MAC message includes a second sub-PDU in addition to a first sub-PDU; the second sub-PDU includes the first parameter.
[0049] The above scheme specifies that the first parameter is carried in the second sub-PDU of the MAC message. The second sub-PDU can be any sub-PDU different from the first sub-PDU. For example, the second sub-PDU can be a sub-PDU added to the MAC message, or a sub-PDU that already exists in the MAC message. In this way, the first parameter can be easily carried in the MAC message without modifying the first sub-PDU.
[0050] In some embodiments of the first aspect, the second sub-PDU includes a Radio Resource Control (RRC) message; the RRC message includes a first parameter.
[0051] Based on the above scheme, the second sub-PDU includes an RRC message, that is, the first parameter is encapsulated in the RRC message, and the RRC message is encapsulated in the second sub-PDU, which has the characteristics of being easy to implement.
[0052] In some embodiments of the first aspect, the first key is an integrity key, and the RRC message is protected for integrity by the first key; and / or, the first key is a confidentiality key, and the RRC message is protected for confidentiality by the first key.
[0053] Based on the above scheme, RRC messages can be protected for integrity and / or confidentiality, allowing for flexible selection as needed.
[0054] In some embodiments of the first aspect, the first message further includes a first indicator; the first indicator is used to indicate to the UE the parameter value for generating the second key.
[0055] Based on the above scheme, the first message also includes a first indicator, which can be used by the UE to specify how to generate the second key when generating the second key.
[0056] In some embodiments of the first aspect, the first indicator is used to indicate the switching type, and the parameter values used to generate the second key are different for different switching types; or, the first indicator is used to indicate the key update type, and the parameter values used to generate the second key are different for different key update types.
[0057] The above scheme defines the content format of the first indicator, which can be flexibly selected during implementation.
[0058] In some embodiments of the first aspect, the first parameter includes a next-hop link count (NCC); the first indicator has a first value, and the NCC is used by the UE to determine the parameter value for generating the second key.
[0059] The above scheme limits the first parameter and how it is used when generating the second key, and is easy to implement.
[0060] In some embodiments of the first aspect, if the access management function of the second cell is the same as that of the first cell and the key parameters generated by the access management function remain unchanged, then the first indicator has a first value; if the access management function of the second cell is different from that of the first cell, or if the access management function of the second cell is the same as that of the first cell and the key parameters generated by the access management function need to be updated, then the first indicator has a second value.
[0061] The above scheme makes it easier for the UE to generate a second key based on the corresponding parameters.
[0062] In some embodiments of the first aspect, the method further includes: encoding a first parameter using a first key at a Packet Data Convergence Protocol (PDCP) layer to obtain a first parameter protected by the first key; and assembling the first parameter protected by the first key into a first message at a Media Access Control (MAC) layer.
[0063] The above scheme specifies how to encapsulate the first message, allowing for flexible handling during subsequent implementation.
[0064] The second aspect provides a key processing method, wherein the method is executed by a user equipment (UE), and the method includes:
[0065] The UE receives a first message sent by a first node of the first cell; the first message includes a first parameter, which is used by the UE to determine a second key for communication with the second cell; the first parameter is protected by the first key; the first key is the key for the UE to communicate with the first cell.
[0066] In some embodiments of the second aspect, the first message is a Media Access Control (MAC) message; the MAC message includes at least a first sub-protocol data unit (PDU), the first sub-PDU including a cell change command; the cell change command is used to instruct the UE to access the second cell.
[0067] In some embodiments of the second aspect, the first sub-PDU further includes a first parameter.
[0068] In some embodiments of the second aspect, the first key is an integrity key, and at least the first parameter is protected for integrity by the first key.
[0069] In some embodiments of the second aspect, the first parameter is protected by the integrity of the first key; exemplarily, the first parameter is protected by the integrity of the first key alone; or, the first parameter and the first identifier are protected by the integrity of the first key; the first identifier is associated with the first node.
[0070] In some embodiments of the second aspect, the first identifier includes at least one of the following:
[0071] Node identifier, used to indicate the first node;
[0072] Cell identifier, used to identify the cell of the first node to which the UE accesses;
[0073] Configuration identifier, used to identify the cell configuration of the first node accessed by the UE.
[0074] In some embodiments of the second aspect, the MAC message further includes a second sub-PDU; the second sub-PDU includes the first parameter.
[0075] In some embodiments of the second aspect, the second sub-PDU includes a Radio Resource Control (RRC) message; the RRC message includes a first parameter.
[0076] In some embodiments of the second aspect, the first key is an integrity key, and the RRC message is protected for integrity by the first key; and / or,
[0077] The first key is a confidential key, and RRC messages are protected by the confidentiality of the first key.
[0078] In some embodiments of the second aspect, the first message further includes a first indicator; the first indicator is used to indicate to the UE the parameter value for generating the second key.
[0079] In some embodiments of the second aspect, the first indicator is used to indicate the switching type, and the parameter values used to generate the second key are different for different switching types; or,
[0080] The first indicator is used to indicate the key update type; different key update types use different parameter values to generate the second key.
[0081] In some embodiments of the second aspect, the first parameter includes the next-hop link count (NCC); the method further includes:
[0082] The first indicator has a first value, and the parameter value used by the second key is determined according to the NCC.
[0083] In some embodiments of the second aspect, if the access management function of the second cell is the same as that of the first cell and the key parameters generated by the access management function remain unchanged, then the first indicator has a first value.
[0084] The access management function of the second cell is different from that of the first cell, or the access management function of the second cell is the same as that of the first cell but the key parameters generated by the access management function need to be updated, and the first indicator has a second value.
[0085] In some embodiments of the second aspect, the method further includes:
[0086] The first parameter was received and verified at the Packet Data Convergence Protocol (PDCP) layer.
[0087] The third aspect provides a first node of a first cell, wherein the first node includes:
[0088] The sending module is configured to send a first message to a user equipment (UE); the first message includes a first parameter, which is used by the UE to determine a second key for communication with a second cell; the first parameter is protected by the first key; the first key is the key for communication between the UE and the first cell.
[0089] The fourth aspect provides a user equipment (UE), wherein the UE includes:
[0090] The receiving module is configured to receive a first message sent by a first node of a first cell; the first message includes a first parameter, which is used by the UE to determine a second key for communication with a second cell; the first parameter is protected by the first key; the first key is the key for communication between the UE and the first cell.
[0091] The fifth aspect provides a communication system, wherein the communication system includes a first node and a user equipment (UE);
[0092] The first node is used to execute the key processing method of any technical solution in the first aspect;
[0093] The UE is used to execute the key update method of any technical solution in the second aspect.
[0094] In a sixth aspect, embodiments of this disclosure provide a program product, wherein the program product includes a computer program, which, when executed by a communication device, enables the communication device to implement the key processing method described in the optional implementations of the first to second aspects.
[0095] In a seventh aspect, embodiments of this disclosure provide a computer program that, when run on a computer, causes the computer to perform the key processing method described in optional implementations of the first to second aspects.
[0096] It is understood that the UE, network device, communication system, program product, and computer program described above are all used to execute the methods provided in the embodiments of this disclosure. Therefore, the beneficial effects that can be achieved can be referred to the beneficial effects in the corresponding methods, and will not be repeated here.
[0097] This disclosure provides a key processing method, a communication device, a communication system, and a storage medium. The embodiments of this disclosure are not exhaustive, but merely illustrative of some embodiments, and are not intended to limit the scope of protection of this disclosure. Unless otherwise specified, each step in a particular embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, removing some steps from a particular embodiment can also be implemented as an independent embodiment, and the order of the steps in a particular embodiment can be arbitrarily interchanged. Furthermore, the optional implementations in a particular embodiment can be arbitrarily combined; moreover, the embodiments can be arbitrarily combined, for example, some or all steps of different embodiments can be arbitrarily combined, and a particular embodiment can be arbitrarily combined with optional implementations of other embodiments.
[0098] In each of the disclosed embodiments, unless otherwise specified or in case of logical conflict, the terminology and / or descriptions of the embodiments are consistent and can be referenced by each other. Technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships.
[0099] The terminology used in the embodiments of this disclosure is for the purpose of describing particular embodiments only and is not intended to limit the scope of this disclosure.
[0100] In this embodiment of the disclosure, unless otherwise stated, elements expressed in the singular form, such as "a," "an," "the," "the aforementioned," "this," etc., can mean "one and only one," or "one or more," "at least one," etc. For example, when using articles such as "a," "an," "the," etc. in translation, the noun following the article can be understood as either a singular expression or a plural expression.
[0101] In the embodiments disclosed herein, "multiple" refers to two or more.
[0102] In some embodiments, the terms “at least one of”, “one or more”, “a plurality of”, “multiple”, etc., may be used interchangeably.
[0103] In some embodiments, the notation "at least one of A and B", "A and / or B", "A in one case, B in another", "A in one case, B in another", etc., may include the following technical methods depending on the situation: in some embodiments, A (A is executed regardless of B); in some embodiments, B (B is executed regardless of A); in some embodiments, execution is selected from A and B (A and B are selectively executed); in some embodiments, A and B (both A and B are executed). The same applies when there are more branches such as A, B, C, etc.
[0104] In some embodiments, the notation "A or B" may include the following technical approaches, depending on the circumstances: in some embodiments, A (execution of A regardless of B); in some embodiments, B (execution of B regardless of A); in some embodiments, selective execution from A and B (A and B are selectively executed). The same applies when there are more branches such as A, B, C, etc.
[0105] The prefixes "first," "second," etc., used in the embodiments of this disclosure are merely for distinguishing different descriptive objects and do not impose restrictions on the position, order, priority, quantity, or content of the descriptive objects. The description of the descriptive objects is found in the claims or the context of the embodiments, and the use of prefixes should not constitute unnecessary restrictions. For example, if the descriptive object is a "field," the ordinal numbers preceding "field" in "first field" and "second field" do not restrict the position or order of the "fields." "First" and "second" do not restrict whether the "fields" they modify are in the same message, nor do they restrict the order of "first field" and "second field." Similarly, if the descriptive object is a "level," the ordinal numbers preceding "level" in "first level" and "second level" do not restrict the priority between "levels." Furthermore, the number of descriptive objects is not limited by ordinal numbers and can be one or more. For example, in "first device," the number of "devices" can be one or more. Furthermore, the objects modified by different prefixes can be the same or different. For example, if the object being described is "device", then "first device" and "second device" can be the same device or different devices, and their types can be the same or different. As another example, if the object being described is "information", then "first type of information" and "second type of information" can be the same information or different information, and their content can be the same or different.
[0106] In some embodiments, “including A,” “containing A,” “for indicating A,” and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.
[0107] In some embodiments, terms such as “…”, “determine…”, “in the case of…”, “when…”, “when…”, “if…”, etc. can be used interchangeably.
[0108] In some embodiments, the terms “greater than,” “greater than or equal to,” “not less than,” “more than,” “more than or equal to,” “not less than,” “higher than,” “higher than or equal to,” “not lower than,” and “above” can be used interchangeably, as can the terms “less than,” “less than or equal to,” “not greater than,” “less than,” “less than or equal to,” “not more than,” “lower than,” “lower than or equal to,” “not higher than,” and “below”.
[0109] In some embodiments, devices, etc., can be interpreted as physical or virtual, and their names are not limited to the names recorded in the embodiments. Terms such as “device”, “equipment”, “circuit”, “network element”, “node”, “function”, “unit”, “section”, “system”, “network”, “chip”, “chip system”, “entity”, and “subject” can be used interchangeably.
[0110] In some embodiments, "network" can be interpreted as devices included in a network (e.g., access network devices, core network devices, etc.).
[0111] In some embodiments, the terms "access network device (AN device)," "radio access network device (RAN device)," "base station (BS)," "radio base station," "fixed station," "node," "access point," "transmission point (TP)," "reception point (RP)," "transmission / reception point (TRP)," "panel," "antenna panel," "antenna array," "cell," "macro cell," "small cell," "femto cell," "pico cell," "sector," "cell group," "serving cell," "carrier," "component carrier," and "bandwidth part (BWP)" can be used interchangeably.
[0112] In some embodiments, the terms "UE (terminal)," "UE device," "user equipment (UE)," "user UE (user terminal)," "mobile station (MS)," "mobile UE (MT)," "subscriber station," "mobile unit," "subscriber unit," "wireless unit," "remote unit," "mobile device," "wireless communication device," "remote device," "mobile subscriber station," "access UE," "mobile UE," "wireless UE," "remote UE," "handset," "user agent," "mobile client," and "client" can be used interchangeably.
[0113] In some embodiments, the access network device, core network device, or network device can be replaced by a UE. For example, embodiments of this disclosure can also be applied to structures where communication between the access network device, core network device, or network device and the UE is replaced by communication between multiple UEs (e.g., device-to-device (D2D), vehicle-to-everything (V2X), etc.). In this case, the UE can also be configured to have all or some of the functions of the access network device. Furthermore, terms such as "uplink" and "downlink" can be replaced with terms corresponding to communication between UEs (e.g., "sidelink"). For example, uplink channel, downlink channel, etc., can be replaced with sidelink channel, and uplink link, downlink, etc., can be replaced with sidelink link.
[0114] In some embodiments, the UE can be replaced by an access network device, a core network device, or a network device. In this case, it can also be configured such that the access network device, core network device, or network device has all or some of the functions of the UE.
[0115] In some embodiments, the acquisition of data, information, etc., may comply with the laws and regulations of the country where the location is situated.
[0116] In some embodiments, data, information, etc., may be obtained with the user's consent.
[0117] Furthermore, each element, each row, or each column in the table of this disclosure can be implemented as an independent embodiment, and any combination of any element, any row, or any column can also be implemented as an independent embodiment.
[0118] Figure 1A is a schematic diagram of the architecture of a communication system according to an embodiment of the present disclosure.
[0119] As shown in Figure 1A, the communication system 100 includes a terminal 101 and a network device 102. The network device 102 may include access network equipment and / or core network equipment. The terminal is also referred to as a UE.
[0120] In some embodiments, terminal 101 includes, but is not limited to, at least one of the following: mobile phone, wearable device, Internet of Things device, car with communication function, smart car, tablet computer, computer with wireless transceiver function, virtual reality (VR) UE device, augmented reality (AR) UE device, wireless UE device in industrial control, wireless UE device in self-driving, wireless UE device in remote medical surgery, wireless UE device in smart grid, wireless UE device in transportation safety, wireless UE device in smart city, and wireless UE device in smart home.
[0121] In some embodiments, UE is also referred to as User Equipment (UE).
[0122] In some embodiments, the access network device may be a node or device that connects the UE to the wireless network. The access network device may include, but is not limited to, at least one of the following in a 5G communication system: evolved Node B (eNB), next generation eNB (ng-eNB), next generation Node B (gNB), node B (NB), home node B (HNB), home evolved node B (HeNB), radio backhaul device, radio network controller (RNC), base station controller (BSC), base transceiver station (BTS), base band unit (BBU), mobile switching center, base station in a 6G communication system, open RAN, cloud RAN, base station in other communication systems, and access node in a Wi-Fi system.
[0123] In some embodiments, the technical methods of this disclosure can be applied to the Open RAN architecture. In this case, the interfaces between or within access network devices involved in the embodiments of this disclosure can be transformed into internal interfaces of Open RAN. The processes and information interactions between these internal interfaces can be implemented by software or programs.
[0124] In some embodiments, the access network device may be composed of a central unit (CU) and a distributed unit (DU). The CU may also be called a control unit. The CU-DU structure can separate the protocol layer of the access network device. Some of the protocol layer functions are centrally controlled by the CU, while the remaining part or all of the protocol layer functions are distributed in the DU and centrally controlled by the CU. However, this is not the only possibility.
[0125] In some embodiments, the core network equipment can be a single device, including a first network element, or it can be multiple devices or a group of devices, each including a first network element. Network elements can be virtual or physical. The core network includes, for example, at least one of an Evolved Packet Core (EPC), a 5G Core Network (5GCN), and a Next Generation Core (NGC).
[0126] It is understood that the communication system described in this disclosure is for the purpose of more clearly illustrating the technical methods of this disclosure and does not constitute a limitation on the technical methods provided in this disclosure. As those skilled in the art will know, with the evolution of system architecture and the emergence of new business scenarios, the technical methods provided in this disclosure are also applicable to similar technical problems.
[0127] The following embodiments of this disclosure can be applied to the communication system 100 shown in FIG1A, or to some of the main bodies, but are not limited thereto. The main bodies shown in FIG1A are illustrative. The communication system may include all or some of the main bodies in FIG1A, or it may include other main bodies outside of FIG1A. The number and form of each main body are arbitrary. The connection relationship between the main bodies is illustrative. The main bodies may not be connected or may be connected. The connection can be in any way, it can be a direct connection or an indirect connection, it can be a wired connection or a wireless connection.
[0128] The embodiments disclosed herein can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New radio access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), and IEEE 802.20, Ultra-Wideband (UWB), Bluetooth (a registered trademark), Public Land Mobile Network (PLMN) networks, Device-to-Device (D2D) systems, Machine-to-Machine (M2M) systems, Internet of Things (IoT) systems, Vehicle-to-Everything (V2X) systems, systems utilizing configuration methods of other resources, and next-generation systems extended from them, etc. Furthermore, multiple systems can be combined (e.g., LTE and NR can be combined).
[0129] During a change of primary or secondary cell, the Master Cell Group (MCG) or Sencodary Cell Group (SCG) may also change. In LTM, the next-generation NodeB (gNB) receives L1 measurement reports from the User Equipment (UE). Based on this, the gNB changes the UE's serving cell via a cell switch command issued by the MAC CE. The cell switch command indicates an LTM candidate cell configuration that the gNB has pre-provided to the UE via Radio Resource Control (RRC) signaling. The UE accesses the target cell indicated in the cell switch command based on the received cell switch command. LTM can be used to reduce mobility latency. LTM candidate cell configurations can only be added, modified, and released by the network via RRC signaling. LTM supports subsequent LTM, which refers to LTM performed based on candidate cells without requiring RRC reconfiguration between network equipment and the UE. That is, after performing mobility operations, the UE will not delete the LTM configuration information on its own. The LTM configuration information can continue to be used to trigger subsequent LTMs even without RRC reconfiguration and updates. For example, the LTM configuration information may include information about candidate cells.
[0130] LTM supports intra-frequency or inter-frequency cell changes. In some scenarios, only LTM within a Distributed Unit (DU) and LTM within a DU are supported. In other scenarios, New Radio (NR) mobility enhancements are extended to inter-CU, inter-node, or inter-gNB LTM. For example, inter-CU, inter-node, or inter-gNB LTM supports the following scenarios:
[0131] Example 1: When no data center is configured, the CU acts as the MN;
[0132] Example 2: Configure NR-DC, with CU acting as SN and MCG remaining unchanged;
[0133] Example 3: When configuring NR-DC, the CU acts as the MN and the SCG remains unchanged or is released. For inter-CU LTM, multiple candidate gNB-CUs will participate in the migration flow.
[0134] The signaling flow of LTM can be shown in Figure 1B, including the following three stages:
[0135] Phase 1: Phase 1, also known as the LTM preparation phase, involves the initial gNB determining candidate cells and initiating cross-node interactions for LTM preparation across CUs based on the L3 RRM measurement report. Following these interactions, the initial gNB provides LTM configuration to the UE using the RRC configurations of multiple candidate cells.
[0136] The initial gNB determines candidate cells and initiates inter-node interaction to prepare for inter-CU LTM. After the interaction, the initial gNB provides LTM configuration to UEs with RRC configurations that have multiple candidate cells.
[0137] Phase 2: Phase 2 is also known as LTM initialization. In this phase, the UE sends its L1 measurement report to the initial gNB. After receiving the Cell Switching Command (MAC CE), the UE switches to a candidate cell. To support LTM without random access (RACH-less), the UE can synchronize with the candidate cell in advance. Specifically, before receiving the Cell Switching Command, the UE performs DL and UL synchronization with the candidate cell.
[0138] Phase 3: Subsequent LTM Phase. In the subsequent LTM phase, steps similar to steps 8-14 are performed. The subsequent LTM is triggered by the current serving gNB, which is itself one of the candidate gNBs for the candidate LTM.
[0139] During handover in non-LTM scenarios, key update synchronization between the UE and gNB can be achieved as follows: During handover in the inter-CU mobility process, the synchronization of the AS security key between the UE and the target gNB is achieved through the NCC value used by the source gNB, and then forwarded to the target gNB and UE in the RRC reconfiguration signaling. When it is necessary to establish an initial AS security context between the UE and gNB, the AMF and UE will derive the K... gNB And the next hop (NH) parameter (NCC (NH chain Counter) with each K gNB It is associated with the NH parameter. Each K gNB All of these are associated with NCC, which corresponds to the NH value.
[0140] During Xn switching, if the source gNB has an unused {NH, NCC} pair, vertical key derivation should be performed. The source gNB should first derivation from the currently active K. gNB (If it's a horizontal key derivation) or calculate K from NH (if it's a vertical key derivation) NG-RAN* Then, the source gNB will {K NG-RAN* The NCC forwards the data to the target gNB. The target gNB should directly forward the received K...NG-RAN* K as used with UE gNB The target gNB should receive the NCC value from the source gNB and match it with the K value. gNB Related. The target gNB includes the received NCC in a prepared Handover (HO) command message, which is sent to the source gNB using a transparent container, and then forwarded to the UE by the source gNB.
[0141] Regardless of whether a handover is performed within the gNB-CU, an Xn handover, or an N2 handover, the UE's behavior is the same. The only difference is that during an intra-gNB-CU handover, the UE may retain the same key according to the gNB's instructions. The UE's behavior is also the same under conditional handover scenarios; for example, if the UE should use K... NG-RAN* The parameters of the target cell selected in the derivation.
[0142] If the NCC value in the HO command message received by the UE from the target gNB via the source gNB is equal to the currently active K gNB The associated NCC value then the UE is from the currently active K gNB Derivation of K from the target PCI and its frequency (ARFCN-DL or EARFCN-DL) NG-RAN* .
[0143] If the NCC value received by the UE differs from the NCC value associated with the currently active gNB, the UE should first synchronize the locally stored NH parameters through iterative calculation and increment the NCC value until it matches the NCC value received from the source gNB via the HO command message. When the NCC values match, the UE calculates K using the synchronized NH parameters and the target Physical Cell Identity (PCI) and its Absolute Radio-Frequency Channel Number Downlink (ARFCN-DL) or the Absolute Radio Frequency Channel Number Downlink (EARFCN-DL) of the Universal Mobile Telecommunications System (UMTS) Terrestrial Radio Access Network (E-UTRAN). NG-RAN* .
[0144] When the UE communicates with the target gNB, it should use K. NG-RAN* As K gNB .
[0145] In the current cross-gNB handover process, the first step is to synchronize security-related configurations (such as NCC, K) between the source gNB and the target gNB. NG-RAN* The source gNB then sends the NCC to the UE during each handover. The UE uses the NCC to synchronize the key update with the target gNB. However, for mobility enhancement procedures defined for cross-gNB LTM, the RRC reconfiguration message is not sent by the source gNB during each handover. Therefore, how to update the NCC value and send it to the UE for key update synchronization during each handover becomes an open question. The following are some options:
[0146] Option 1: Use the new information in the MAC CE to transmit security information. Regardless of whether the UE uses horizontal or vertical key derivation, it is derived from this new information in the MAC CE, but the MAC CE is currently not securely protected.
[0147] Option 1A: The NCC value used during LTM execution between CUs is included in the LTM cell change command MAC CE.
[0148] Option 1B: A list of NCC values is pre-configured in the encrypted and integrity-protected RRC message, and the index of the NCC values in the list is included in the LTM cell switching command MAC CE.
[0149] Option 2: The UE uses integrity-protected and encrypted RRC messages to pre-configure a list of NCC values for each CU from the source gNB. It is anticipated that participating gNBs (CUs) will need to know this list and how the UE applies it during LTM cell handover; in this case, the MAC CE indicating cell handover will not contain the NCC index.
[0150] Option 2A: When performing LTM across CUs, the UE selects the first unused NCC for the target CU.
[0151] Option 2B: As an alternative to selecting the next unused NCC (as in Option 2A), if the LTM unit switching is between the same two CUs, then horizontal key derivation is used in this option.
[0152] Option 3: After the LTM cell replacement is performed between different areas, the participating gNBs are expected to be updated to the new K. gNB* This is for use in the next LTM cell handover between different areas. The UE and CN know how the UE will use the next NCC value.
[0153] Option 3A: After the subsequent CU-to-CU LTM execution, the UE determines the NCC value to be used this time. For example, the NCC value to be used this time can be the NCC value used last time plus 1.
[0154] Option 3B: The UE is pre-configured with a list of NCC values by the CN (via source gNB RRC signaling), and the UE selects the first unused NCC value as the next NCC value.
[0155] Option 4: After each inter-CU LTM cell handover is performed, provide the NCC value to the UE via RRC signaling so that the UE can use it for key derivation during the next inter-CU LTM cell handover.
[0156] Considering both feasibility and signaling overhead, option 1A is the preferred choice. However, the main problem with this option is that the MAC CE message is unprotected, therefore the NCC carried in the MAC CE message is unprotected. The unprotected NCC is vulnerable to tampering by attackers. When the NCC value received by the UE is modified, the key derived by the UE will differ from the key used by the target UE, which is received from the source gNB. This key update asynchrony between the UE and the target gNB will lead to handover failure.
[0157] During the current gNB handover process, security-related configurations (such as MasterKeyUpdate and / or NCC) are transmitted from the source gNB to the UE via RRC reconfiguration signaling on the Uu interface during the preparation phase of each handover. RRC reconfiguration is sent after AS security is established between the UE and the gNB; therefore, the entire RRC reconfiguration message is at least integrity protected and cannot be tampered with by attackers.
[0158] For LTM enhancement between CUs, the preparation phase is performed only by the initial gNB, not in each subsequent handover; that is, there is no preparation phase before each handover for LTM enhancement between CUs. With this design, RRC reconfiguration signaling is performed only by the initial gNB during the LTM preparation phase, and is replaced by MAC CE messages in each subsequent handover after LTM preparation. Since MAC CE messages are unprotected, the security-related configurations carried in them cannot be protected. Currently, the access stratum AS security established between the UE and gNB is performed at the PDCP layer on the Uu interface. The MAC layer below the PDCP layer does not support security-related calculations. Therefore, there is no existing security mechanism to protect MAC CE messages.
[0159] This disclosure provides a method to ensure that the NCC (security related parameter) sent from the gNB to the UE in the MAC CE is not tampered with or eavesdropped on.
[0160] As shown in Figure 2A, this embodiment of the disclosure provides a key processing method, executed by the communication system shown in Figure 1A. The method may include:
[0161] S2101: The first node uses the first key to encode the first parameter to obtain the first parameter protected by the first key.
[0162] In some embodiments, the first node may include an access network node (or access network device). For example, the first node may be the UE's current serving node. Also for example, the first node may be the UE's source node during cell switching, such as a source base station.
[0163] In some embodiments, the first key may be included in the (Access Stratum, AS) security context.
[0164] In some embodiments, the first key is a key for communication between the UE and the first cell. For example, the first key may be a root key, an intermediate key, or a session key for communication between the UE and the first cell. The session key may be a key derived from the root key or the intermediate key. The intermediate key may be a key derived from the root key and used to derive the session key.
[0165] In some embodiments, the first key may include one of an integrity key and / or a confidentiality key.
[0166] In some embodiments, the first key may be an integrity key, and at least the first parameter is protected for integrity by the first key.
[0167] In some embodiments, the first key is an integrity key, and the first parameter is protected for integrity solely by the first key; alternatively, the first parameter and the first content in the first message are identified for integrity. For example, the first content may be content known to the UE. The first content may be agreed upon by a protocol or pre-configured by the network device.
[0168] In some embodiments, the first key is an integrity key, and the RRC message is protected for integrity by the first key; and / or, the first key is a confidentiality key, and the RRC message is protected for confidentiality by the first key. The first parameter is included in the RRC message.
[0169] In some embodiments, the first parameter can be used to generate the second key.
[0170] In some embodiments, the first parameter may be used to indicate one of the parameters used to derive the second key.
[0171] In some embodiments, the second key may be a key used by the UE to communicate with the second cell after accessing it. For example, the second key may be a root key or an intermediate key for communication between the UE and the second cell. For example, the second key may be the root key of the second cell. After accessing the second cell, the UE generates an AS security context for communication with the second cell based on the second key, the physical cell identity (PCI) of the second cell, and the downlink (DL) frequency. This AS security context for communication with the second cell may include an integrity key, a confidentiality key, etc.
[0172] In some embodiments, the first parameter may include, but is not limited to, the Next Hop Chaining Counter parameter (NCC).
[0173] In some embodiments, the first node uses a first key to encode a first parameter at the PDCP layer to obtain a first parameter protected by the first key.
[0174] In some embodiments, the PDCP layer may be a protocol stack layer that applies the PDCP protocol. For example, the first node encoding a first parameter using a first key in the PDCP layer to obtain a first parameter protected by the first key may include: the first node's PDCP layer encoding the first parameter using the first key to obtain the first parameter protected by the first key.
[0175] In some embodiments, S2101 may include at least one of the following;
[0176] The first node uses the first key at the PDCP layer to perform integrity protection on the first parameter, and obtains the integrity protection verification code.
[0177] The first node uses the first key at the PDCP layer to protect the confidentiality of the first parameter, thus obtaining the confidential first parameter.
[0178] The first node uses the first key at the PDCP layer to perform confidentiality protection and integrity protection on the first parameter respectively, and obtains the confidentiality-protected first parameter;
[0179] The first node uses the first key at the PDCP layer to scramble and protect the first parameter and the first identifier, thus obtaining the scrambled and protected first parameter.
[0180] The first node uses the first key at the PDCP layer to perform integrity protection on the first parameter and the first identifier, and obtains an integrity-protected verification code.
[0181] The first node uses the first key at the PDCP layer to protect the confidentiality of the first parameter and the first identifier, thus obtaining the confidential first parameter.
[0182] The first node uses the first key at the PDCP layer to perform confidentiality protection and integrity protection on the first parameter and the first identifier respectively, and obtains the confidentiality-protected first parameter;
[0183] The first node uses the first key at the PDCP layer to scramble and protect the first parameter and the first identifier, thus obtaining the scrambled and protected first parameter.
[0184] In some embodiments, the first key is an integrity key, and the first parameter is protected for integrity by the first key. In some embodiments, the first parameter is protected for integrity by the first key alone; or, the first parameter and the first identifier are protected for integrity by the first key; the first identifier is associated with the first node.
[0185] In some embodiments, the first identifier includes at least one of the following:
[0186] Node identifier, used to indicate the first node;
[0187] Cell identifier, used to identify the cell of the first node to which the UE accesses;
[0188] Configuration identifier, used to identify the cell configuration of the first node accessed by the UE.
[0189] In some embodiments, the cell configuration may include an LTM-Candidate Information Element (IE). For example, the LTE-Candidate IE may include an LTM candidate ID, an LTM candidate physical cell identity (PCI), LTM early uplink synchronization configuration, LTM early downlink synchronization configuration, and LTM synchronization signal block (SSB) configuration, etc.
[0190] In some embodiments, during the initial LTM process or subsequent LTM processes of the UE, it is necessary to use the first key to encode the first parameter sent to the UE.
[0191] S2102: The first node sends the first message to the UE.
[0192] In some embodiments, the first message includes a first parameter.
[0193] In some embodiments, the first message may be any Access Stratum (AS) message sent by the access network node to the UE. For example, the AS message may include an RRC message, a MAC message, or a physical layer message. The MAC message may be a MAC layer message. MAC messages conform to the MAC layer protocol of the protocol stack.
[0194] In some embodiments, the first message may be a MAC message. Exemplarily, the MAC message may be a MAC message containing a cell change command. Exemplarily, the cell change command may include, but is not limited to, an LTM cell switch command. Also exemplaryly, the MAC message may include a first parameter. Exemplarily, the first parameter may be carried in a reserved field of the MAC message. Also exemplaryly, the first parameter may be carried in a new PDCP PDU / SDU of the MAC message.
[0195] In some embodiments, the MAC message may include one or more sub-PDUs. The cell change command and the first parameter may be contained in the same sub-PDU or different sub-PDUs.
[0196] In some embodiments, the MAC message may include a first sub-PDU. Exemplarily, the first sub-PDU may include a cell change command. Exemplarily, the first sub-PDU containing the cell change command is also known as the MAC CE sub-PDU.
[0197] In some embodiments, the cell change command may be a command that causes the UE to change its serving cell. For example, the cell change command may cause at least one serving cell of the UE to change, such as adding a serving cell of the UE or changing the serving cell while keeping the number of serving cells unchanged.
[0198] In some embodiments, the cell change command can enable the UE to access a second cell. The second cell may be different from the first cell.
[0199] In some embodiments, the first cell and the second cell may belong to the same access network node, in which case the UE's cell replacement can be an intra-node cell replacement. In some embodiments, the first cell and the second cell may belong to different access network nodes, in which case the UE's cell replacement can be a cross-node cell replacement. In other embodiments, the first cell and the second cell not only belong to different access nodes, but the AMF of the first cell and the AMF of the second cell may also be different.
[0200] In some embodiments, the MAC message may also include a second sub-PDU. This second sub-PDU is different from the first sub-PDU. For example, the second sub-PDU may include a first parameter.
[0201] Figure 1D shows a schematic diagram of a MAC message. In the MAC message shown in Figure 1D, the first parameter and the cell change command are carried together in the first sub-PDU.
[0202] Figure 2B shows a schematic diagram of another type of MAC message. In the MAC message shown in Figure 2B, the first parameter and the cell change command are carried in different sub-PDUs.
[0203] In some embodiments, the protected first parameter may be directly encapsulated in the MAC message. For example, the first parameter may be directly encapsulated in a sub-PDU of the MAC message.
[0204] In other embodiments, the protected first parameter may be encapsulated in an RRC message first, and then the RRC message may be encapsulated in a MAC message. For example, the protected first parameter may be encapsulated in an RRC container to obtain an RRC message, and then the RRC message may be encapsulated in a MAC message. Preferably, in the MAC message where the protected first parameter is first encapsulated in an RRC message, the first parameter and the cell change command may be carried in two sub-PDUs.
[0205] In some embodiments, the first message may further include a first indicator. The first indicator is used to indicate a switching type, where different parameter values are used to generate the second key for different switching types; or, the first indicator is used to indicate a key update type, where different parameter values are used to generate the second key for different key update types.
[0206] For example, the first indicator is used to indicate the handover type, which may include different types such as intra-node cell handover, inter-node cell handover, or inter-AMF cell handover. Different types use different parameters to generate the key for communication between the UE and the second cell.
[0207] In some embodiments, the first indicator is used to indicate the switching type, and the parameter values used to generate the second key are different for different switching types.
[0208] In some embodiments, the first indicator is used to indicate the switching type, where a portion of the parameter values used to generate the second key are the same and another portion of the parameter values are different for different switching types.
[0209] In some embodiments, the first indicator is used to indicate the key update type, and different key update types use different parameter values to generate the second key.
[0210] In some embodiments, the first indicator is used to indicate the key update type, where different key update types use different parameter values to generate the second key, while using the same parameter values for another part.
[0211] In some embodiments, the first indicator can be used to instruct the UE to determine the parameter values for generating the second key.
[0212] In some embodiments, the first indicator may include one or more bits, exemplarily having one or more values. For example, the first indicator may have a first value and a second value.
[0213] In some embodiments, the first indicator has a first value, and the NCC is used by the UE to determine the parameter value for generating the second key.
[0214] When the first indicator has a first value, it indicates that the parameter value for generating the second key is determined based on the NCC. For example, when the first indicator has a first value, it indicates that the second key is generated by the UE according to the NCC provided by the first node.
[0215] If the first indicator has a second value, it indicates that the parameter value for generating the second key is not determined based on the NCC. For example, if the first indicator has a second value, it indicates that the second key is determined by the UE based on K. AMF Generate. K AMF It is a key shared by the UE and AMF, and is an intermediate key used to generate the second key.
[0216] In some other embodiments, the first indicator may also have a third value, which indicates that the second key is the same as the first key. In this case, it can be assumed that there is no need to generate a second key.
[0217] In some embodiments, if the first message does not contain a first indicator, it may also indicate that a second key does not need to be generated.
[0218] Without generating a second key, the key used by the UE to communicate with the first cell is the first key.
[0219] For example, suppose the first indicator corresponds to a bit, and if the first value is "0", then the second value is "1", or if the first value is "1", then the second value is "0".
[0220] In some embodiments, the first indicator is used to indicate the switching type, and the parameter values used to generate the second key are different for different switching types.
[0221] In some embodiments, the first indicator is used to indicate the key update type, and different key update types use different parameter values to generate the second key.
[0222] In some embodiments, the first indicator can also be used to indicate whether the first message contains a first parameter or whether a second key needs to be generated. For example, in some scenarios, if the message containing the UE's cell change command for accessing another cell does not carry the first indicator, it indicates that a second key does not need to be generated. For example, in a cell change scenario triggered by LTM in different cells of the same base station, there may be a situation where a second key does not need to be generated.
[0223] In some embodiments, if the first message is a MAC message, then the first message is sent; the method may further include:
[0224] At the MAC layer, the first node assembles a first message from the first parameters protected by the first key. This assembly of the first message by the first node at the MAC layer can include: the first node's MAC layer assembling the first parameters protected by the first key into a MAC message. For example, the first node's MAC layer receives a PDCP Service Data Unit (SDU) from the first node's PDCP layer, the SDU containing the first parameters protected by the first key. After receiving the PDCP SDU, the first node's MAC layer assembles one or more PDCP SDUs into a MAC message.
[0225] Figure 2C shows the first node using a first key at the PDCP layer to protect the RRC message containing the NCC, and encapsulating the RRC message into a PDCP Service Data Unit (SDU). After encoding at the PDCP layer, the PDCP SDU is transmitted to the Radio Link Control (RLC) layer to obtain the RLC SDU. After encapsulation at the RLC layer, the RLC SDU is provided to the MAC layer. At the MAC layer, the MAC CE and NCC are encapsulated into different sub-PDUs. The MAC CE contains the cell change command. Multiple sub-PDUs can form a MAC PDU. This MAC PDU is one type of the aforementioned MAC message.
[0226] S2103: UE verification of the first parameter.
[0227] In some embodiments, the UE uses a locally stored first key to verify the first parameter.
[0228] In some embodiments, the UE uses a first key to verify the first parameter at the PDCP layer. For example, the UE uses the first key to verify the first parameter at the PDCP layer.
[0229] In some embodiments, the UE uses a first key to perform integrity verification, confidentiality verification, and / or scrambling verification on the first message.
[0230] In some embodiments, UE verification of the first parameter may include UE verifying the first parameter received from the first node at the PDCP layer, that is, UE's PDCP entity verifying the first parameter received from the first node.
[0231] In some embodiments, the UE's verification of the first parameter received from the first node at the PDCP layer may include, but is not limited to, at least one of the following: the UE uses a first key stored locally at the PDCPC layer to perform integrity verification of the first parameter received from the first node; the UE uses a first key stored locally at the PDCPC layer to perform confidentiality verification of the first parameter received from the first node; or the UE uses a first key stored locally at the PDCPC layer to perform scrambling verification of the first parameter received from the first node.
[0232] In some embodiments, the method may further include at least one of the following:
[0233] The first parameter is verified and the second key is generated based on the first parameter.
[0234] If the first parameter fails to be verified, request the first parameter again from the first node, or send a failure message to the first node.
[0235] In some embodiments, after the first parameter is verified, generating a second key based on the first parameter may include:
[0236] The first parameter verification is successful. The parameter value for generating the second key is determined according to the first indicator.
[0237] A second key is generated based on the determined parameter values.
[0238] For example, the first indicator has a first value, the parameter value of the generation parameter of the second key is determined according to the NCC corresponding to the first parameter, and the parameter value of the second key is generated according to the determined parameter value.
[0239] As shown in Figure 3, this embodiment of the disclosure provides a key update method, wherein the update is performed by a first node of a first cell. The method may include:
[0240] S3101: Encode the first parameter to obtain the encoded first parameter.
[0241] In some embodiments, a first parameter is obtained by encoding a first parameter using a first key. For example, the first parameter may be an NCC.
[0242] In some embodiments, the first key may be a key used by the first node to communicate with the first cell and the UE. A first parameter may be used to generate a second key. The second key may be a key used by the UE to communicate with the second cell.
[0243] In some embodiments, the optional real-time mode of S3101 can be found in any optional implementation of S2101 of the embodiment corresponding to FIG2A.
[0244] S3102: Send the first message.
[0245] In some embodiments, the optional real-time mode of S3102 can be found in any optional implementation of S2102 of the embodiment corresponding to FIG2A. In some embodiments, the message type of the first message can be found in the relevant description of the embodiment corresponding to FIG2A, and will not be repeated here.
[0246] As shown in Figure 4, this embodiment of the disclosure provides a key update method, wherein the update is performed by a user equipment (UE). The method may include:
[0247] S4101: Receive the first message.
[0248] In some embodiments, a first message sent by a first node is received. In some embodiments, the UE may receive the first message based on its connection with a first cell. A description of the first message in some embodiments can be found in the embodiment corresponding to Figure 2A, and will not be repeated here.
[0249] S4102: Verify the first parameter.
[0250] In some embodiments, the implementation method of verifying the first parameter can be found in S2103 of the corresponding example in Figure 2A, which will not be repeated here.
[0251] In some embodiments, the method may further include at least one of the following: if the first parameter is verified, a second key is generated based on the first parameter; if the first parameter is not verified, the first parameter is re-requested from the first node, or a failure message is sent to the first node.
[0252] In some embodiments, if the first parameter is verified and a second key is generated based on the first parameter, the process may include: if the first parameter is verified and a parameter value for generating the second key is determined based on a first indicator; and generating the second key based on the determined parameter value.
[0253] NCC protection is required during LTM operations across CUs. For example, to protect the integrity of the NCC value contained in the MAC PDU (MAC PDU (Network Side Control) = MAC Sub-PDU (RRC) + MAC Sub-PDU (MAC CE)), embodiments of this disclosure propose using K in the existing AS security context between the UE and the serving gNB. RRC_INT The NCC value can be contained in the MAC sub-PDU of the MAC CE, or it can be contained in a separate MAC sub-PDU of the RRC associated with the MAC CE.
[0254] As shown in Figure 5A, the method provided in this embodiment may include:
[0255] 1. LTM preparation operation between UE and service / source gNB.
[0256] 2. The UE sends the L1 measurement report to the serving / source gNB.
[0257] 3. After selecting the target gNB (candidate gNB1), the serving / source gNB decides whether to trigger the LTM procedure. If the serving / source gNB has no unused NH, it performs a level key derivation from K. gNB0 Derivative K NG-RAN* If the service / source gNB has an unused NH (associated with NCC1), the service / source gNB performs vertical key derivation to obtain the unused NH (i.e., K). NG-RAN* <——(NH1, Cell ID),) derives K NG-RAN* The derivation of the key can be shown in Figure 1C. NH1 is NH that has never been used before.
[0258] 4. The service / source gNB will derive the K NG-RAN* and used to derive K NG-RAN* The NCC value (NCC1) is sent to candidate gNB1. gNB1 uses K... NG-RAN* As K gNB1 And return the NCC value (NCC1) to the service / source gNB.
[0259] 5. After receiving the NCC value (NCC1) returned by candidate gNB1, the following operations may be included:
[0260] 5a. Service / source gNB uses K gNB0 The derived UE establishes an existing AS security context (K RRC_INT The NCC value is encoded to protect the integrity of the PDCP layer NCC value (NCC1).
[0261] 5b. The service / source gNB constructs an RRC message containing the NCC value (NCC1) and uses it via K gNB0 Derived existing AS security context (K RRC_INT K RRC_enc Protect the integrity of RRC messages at the PDCP layer.
[0262] 6. The serving / source gNB transmits the encoded NCC value or the encoded RRC message from the PDCP layer to the MAC layer, forming a MAC PDU which is then sent to the UE. Using [NCC] to represent the encoded NCC value, then [NCC] = NCC + MAC(NCC). MAC(NCC) represents the checksum included in the NCC integrity check.
[0263] 7. Upon receiving the administrative certification documents issued by the service / source gNB, steps 7.1 and / or 7.2 may be included.
[0264] Step 7.1 may include: a) The UE obtains the encoded NCC value [NCC1] from the MAC CE message, sends the encoded NCC value [NCC1] to the PDCP layer, and uses the K... gNB0 Derived existing AS security context (K RRC_INT ) Verify the NCC value [NCC1]. NCC verification = compare the MAC (received NCC) and XMAC (received MAC). Or, b). The UE retrieves the encoded RRC message containing the NCC value (NCC1) from the MAC sub-PDU, sends the encoded RRC message to the PDCP layer, and uses the AS security context (K) derived from KgNB0. RRC_INT K RRC_enc Verify the RRC message to determine the NCC value (NCC1). RRC_INT It is the integrity key. K RRC_enc It is a confidentiality key.
[0265] 7.2. If the decoded NCC value matches the currently active K gNB0 If the associated NCC values are the same, the UE performs horizontal key derivation (i.e., K). NG-RAN* K gNB0 (cell ID). If the decoded NCC value matches the currently active K gNB0 If the associated NCC values are different, the UE will derive NH and then execute K. NG-RAN* (i.e., NH1 = KDF(NH, K)) AMF ), K NG-RAN <——KDF(NH1, cell ID)) is used to derive the vertical key.
[0266] 7.3. Separate the UE from the serving / source gNB and apply the configuration of the target gNB (candidate gNB1), including setting K NG-RAN* As a K-type device used in conjunction with gNB1 gNB1 .
[0267] 8. The UE sends an RRC reconfiguration complete message to gNB1.
[0268] 9. The target gNB (gNB1) sends an N2 path exchange request to the AMF, and the AMF returns the new NH and NCC (NH2, NCC2) to gNB1.
[0269] 10. During the move, the UE sends the L1 measurement report to the serving / source gNB1.
[0270] 11. After selecting the target gNB (candidate gNB2), the serving gNB (gNB1) decides whether the LTM process needs to be triggered. The serving gNB1 further determines the NCC value (NCC2), which is used to derive K from the NH associated with the NCC value. NG-RAN* For horizontal key derivation, the NCC value = NCC1; for vertical key derivation, the NCC value = NCC2. Since the serving / source gNB has an unused NH (i.e., NH2 associated with NCC2), the serving / source gNB uses the unused NH (i.e., K) to... NG-RAN* <——(NH2, Cell ID)) derives K NG-RAN* To perform vertical key derivation.
[0271] Note: If a further intra-CU switch is triggered, the service / source gNB will not have any unused NH, therefore, via K... gNB1 Derivative K NG-RAN* (i.e., KNG-RAN*cell ID) performs horizontal key derivation.
[0272] 12. Service gNB1 will derive K NG-RAN* and used to derive K NG-RAN* The NCC value (NCC2) is sent to candidate gNB2. gNB2 uses K... NG-RAN* As K gNB2 Return the NCC value (NCC2) to gNB1.
[0273] 13. Upon receiving the NCC value (NCC2) returned by gNB2, steps 13a and / or 13b may be included.
[0274] 13a. Service gNB1 is used by K gNB1 Derived existing AS security context (K RRC_INT The NCC value is encoded to protect the integrity of the PDCP layer NCC (NCC2) value. Alternatively,
[0275] 13b. The service / source gNB constructs an RRC message containing the NCC value (NCC2) and uses it via K gNB1 Derived existing AS security context (K RRC_INT K RRC_enc Protect the integrity of RRC messages at the PDCP layer.
[0276] 14.gNB1 transmits the encoded NCC value [NCC2] or the encoded RRC message from the PDCP layer to the MAC layer, forming a MAC PDU and sending it to the UE.
[0277] 15. Upon receiving the administrative certification documents issued by the service / source gNB, steps 15.1 and / or 15.2 may be included.
[0278] Step 15.1 may include:
[0279] a) The UE retrieves the encoded NCC value [NCC2] from the MAC CE message, sends the encoded NCC value [NCC2] to the PDCP layer, and uses the K... gNB1 Derived existing AS security context (K RRC_INT Verify the NCC value [NCC2]. Or, b) The UE retrieves the encoded RRC message containing the NCC value (NCC2) from the MAC sub-PDU, sends the encoded RRC message to the PDCP layer, and uses the K... gNB1 Exported existing AS security context (K RRC_INT K RRC_enc Verify the RRC message to determine the NCC value (NCC2).
[0280] 15.2. If the decoded NCC value matches the currently active K gNB1 If the associated NCC values are the same, then horizontal key derivation (i.e., K) is performed. NG-RAN* K gNB1 (cell ID). If the decoded NCC value matches the currently active K gNB1 If the associated NCC values are different, the UE will derive NH and then execute K. NG-RAN *(i.e., NH2 = KDF(NH1, K) AMF ), K NG-RAN* Vertical key derivation is performed using <——(NH2, Cell ID)). Cell ID represents the cell identifier.
[0281] 15.3 The UE is offloaded from the serving / source gNB, and the configuration of the target gNB (candidate gNB2) is applied, including the K NG-RAN *As a K-type device used in conjunction with gNB2 gNB2 .
[0282] 16. The UE sends an RRC reconfiguration completed message to gNB2.
[0283] 17. The target gNB (gNB2) sends an N2 Path Switch Request to the AMF, and the AMF returns the new NH and NCC (NH3, NCC3) to gNB2.
[0284] 18. Complete the subsequent operations.
[0285] The gNB may send NCC to the UE in at least one of the following ways:
[0286] Option 1:
[0287] Incorporate the NCC directly into the MAC CE (e.g., LTM Cell Switch Command MAC CE), or introduce a new PDCP SDU or PDU and include the new PDCP SDU or PDU in the MAC CE.
[0288] For example, gNB can add a first indicator (keySetChangeIndicator) and an encoded NCC value to the MAC CE message, or add a new PDCP SDU / PDU containing a first indicator (keySetChangeIndicator) and an encoded NCC value to the MAC CE message.
[0289] For example, the MAC CE message here can be one of the aforementioned MAC messages. The MAC CE message can be a MAC message carrying the aforementioned first sub-PDU.
[0290] After receiving the Cell Switching Command (MAC CE) from the serving / source gNB, the UE's MAC layer should instruct the upper layer...
[0291] Triggering the LTM cell replacement process.
[0292] The target configuration ID is contained in the MAC CE of the LTM cell change command. The encoded NCC, such as the encoded NCC contained in the new PDCP PDU / SDU, is sent to the upper layer.
[0293] The PDCP layer performs integrity verification on the encoded NCC value, and then passes the decoded NCC value to the upper layer (e.g., the RRC layer).
[0294] When the LTM cell change process is determined to be triggered, the UE performs LTM cell replacement.
[0295] If the new PDCP PDU / SDU in the LTM cell change command MAC CE contains an NCC value and a keySetChangeIndicator, the UE performs an AS security key update.
[0296] Based on the NCC value (decoded NCC value) displayed in the MAC CE of the LTM cell change command, the UE determines the NCC value according to the specified current K. gNB Or NH determines the export of a new K gNB Store NCC values.
[0297] Option 2:
[0298] A single MAC PDU is used to send an RRC message (containing the NCC value) and a MAC CE (i.e., LTM Cell Switch Command MAC CE). The RRC message is contained within a MAC sub-PDU of the MAC PDU, and the MAC CE is another MAC sub-PDU. The gNB is required to ensure that an RRC MAC sub-PDU containing the NCC value and a MAC sub-PDU containing the MAC CE are constructed within a single MAC PDU. After receiving the MAC PDU containing the Cell Switch Command MAC CE from the serving / source gNB, the UE's MAC layer should inform the upper layer, triggering the LTM cell change process. The LTM Cell Switch Command MAC CE contains the cell configuration ID of the target cell. Optionally, the MAC CE message may include a first indicator to indicate the handover type or key update method. The encoded MAC sub-PDU contained in the MAC PDU is sent to the upper layer. The PDCP layer performs integrity verification on the encoded RRC message and passes the decoded RRC message to the upper layer (RRC layer).
[0299] The contents of the RRC message are shown in Figure 5B. In Figure 5B, "keySetChangeIndicator" represents the first indicator; "nextHopChainingCount" represents the first parameter; and "NextHopChainingCount" represents the value of the first parameter.
[0300] The first indicator is used to indicate to the UE whether to derive a new K. gNB If the RRC message includes a reconfigurationWithSync message carrying synchronization, then a value of false for reconfigurationWithSync indicates that from the current K... gNB Or obtain new K in NH gNB Key. The RRC message can be an RRC reconfiguration message. When the lower-level indicator triggers the LTM cell handover process at the RRC layer, the UE performs the LTM cell handover. After receiving the RRC message containing the NCC value, the UE performs the Access Layer AS security key update process.
[0301] Based on the NCC value displayed in the received RRC message (the RRC message and the LTM Cell Switch Command MAC CE are contained in the same MAC PDU), based on the current K... gNB Or NH can be used to derive K gNB Store the NCC value. The RRC layer may also include the following steps:
[0302] When the MAC entity indicates that an LTM cell handover procedure has been triggered, the UE executes the LTM cell handover procedure. If the first indicator in the LTM Cell Switch Command MAC CE indicates that a key update is required, the UE should wait for an RRC message containing the NCC value and execute the AS security key update procedure. If the LTM Cell Switch and AS security key updates are successful, the UE will send an RRCReconfigurationComplete message to the NW.
[0303] Alternatively, the NCC value can be encoded using the UE's C-RNTI assigned by the serving gNB, since only the UE and the serving gNB share the UE's C-RNTI, and the UE's C-RNTI is unknown to any other party.
[0304] [NCC] = NCC + MAC(NCC + C-RNTI). MAC(NCC + C-RNTI) represents the checksum for the integrity protection of NCC and C-RNTI.
[0305] During NCC verification, the MAC (received NCC + C-RNTI) can be compared with the XMAC (received MAC). If the received MAC and XMAC are the same after comparison, the integrity verification is successful. The gNB should be able to encode the NCC value using the existing AS security context, thereby protecting the integrity of the PDCP layer NCC value.
[0306] gNB should be able to construct the encoded NCC value as: encoded NCC value [NCC] = NCC + MAC(NCC) or encoded NCC value [NCC] = NCC + MAC(NCC + C - RNTI).
[0307] gNB should be able to construct RRC messages containing NCC values and protect the integrity of RRC messages containing NCC values at the PDCP layer using existing AS security contexts.
[0308] The gNB needs to be able to transmit the encoded NCC value or the encoded RRC message from the PDCP layer to the MAC layer to form a MAC PDU and send it to the UE.
[0309] gNB should be able to add a PDCP SDU / PDU containing a first indicator (keySetChangeIndicator) and an encoded NCC value to the MAC CE message.
[0310] gNB should be able to guarantee the construction of an RRC MAC subPDU containing the NCC value and a MAC subPDU containing the MAC CE in a MAC PDU.
[0311] The UE can retrieve the encoded NCC value from the MAC CE message, send the encoded NCC value to the PDCP layer, verify the NCC value using the existing AS security context, and then pass the decoded NCC value to the RRC layer.
[0312] The UE should be able to verify the encoded NCC value: NCC verification = compare the MAC (received NCC) with the XMAC (received MAC), or NCC verification = compare the MAC (received NCC + C - RNTI) with the XMAC (received MAC).
[0313] The UE should be able to verify the encoded RRC message containing the NCC value from the MAC sub-PDU in the MAC PDU, and then retrieve the NCC value from the RRC message after integrity verification.
[0314] The UE should be able to determine whether to perform a key update based on the first indicator (keySetChangeIndicator) and the NCC value contained in the MAC CE.
[0315] In the embodiments disclosed herein, some or all of the steps and their optional implementations may be arbitrarily combined with some or all of the steps in other embodiments, or may be arbitrarily combined with the optional implementations in other embodiments.
[0316] In the embodiments disclosed herein, some or all of the steps and their optional implementations may be arbitrarily combined with some or all of the steps in other embodiments, or may be arbitrarily combined with the optional implementations in other embodiments.
[0317] This disclosure also provides apparatus for implementing any of the above methods. For example, an apparatus is provided that includes units or modules for implementing the steps performed by the UE in any of the above methods. Alternatively, another apparatus is provided that includes units or modules for implementing the steps performed by a network device (e.g., an access network device, or a core network device) in any of the above methods.
[0318] It should be understood that the division of units or modules in the above device is only a logical functional division. In actual implementation, they can be fully or partially integrated into a single physical entity, or they can be physically separated. Furthermore, the units or modules in the device can be implemented by a processor calling software: for example, the device includes a processor connected to a memory containing instructions. The processor calls the instructions stored in the memory to implement any of the above methods or to implement the functions of the units or modules in the above device. The processor can be, for example, a general-purpose processor, such as a Central Processing Unit (CPU) or a microprocessor, and the memory can be internal or external to the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuits. The functionality of some or all of the units or modules can be achieved through the design of these hardware circuits, which can be understood as one or more processors. For example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC). The functionality of some or all of the units or modules is achieved through the design of the logical relationships between the components within the circuit. In another implementation, the hardware circuit can be implemented using a programmable logic device (PLD). Taking a field-programmable gate array (FPGA) as an example, it can include a large number of logic gates. The connection relationships between the logic gates are configured through configuration files, thereby achieving the functionality of some or all of the units or modules. All units or modules of the above device can be implemented entirely through processor-called software, entirely through hardware circuits, or partially through processor-called software with the remaining parts implemented through hardware circuits.
[0319] In this disclosure, the processor is a circuit with signal processing capabilities. In one implementation, the processor can be a circuit with instruction read and execute capabilities, such as a Central Processing Unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a type of microprocessor), or a digital signal processor (DSP). In another implementation, the processor can implement certain functions through the logical relationships of hardware circuits. The logical relationships of the aforementioned hardware circuits are fixed or reconfigurable. For example, the processor is a hardware circuit implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document and configuring the hardware circuit can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules. Furthermore, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a Neural Network Processing Unit (NPU), a Tensor Processing Unit (TPU), or a Deep Learning Processing Unit (DPU). Unit, DPU, etc.
[0320] As shown in Figure 6A, this embodiment of the present disclosure provides a first node, including:
[0321] The sending module 6101 is configured to send a first message to a user equipment (UE); the first message includes a first parameter, which is used by the UE to determine a second key for communication with a second cell; the first parameter is protected by the first key; the first key is the key for communication between the UE and the first cell.
[0322] In some embodiments, the transmitting module and / or receiving module may correspond to the network interface and / or transceiver antenna of the first node.
[0323] In some embodiments, the first node further includes a processing module.
[0324] In some embodiments, the processing module can be used by the first node to execute information processing-related steps in any key processing method.
[0325] In some embodiments, the sending module can be used by the first node to perform information sending-related steps in any key processing method.
[0326] In some embodiments, the receiving module can be used by the first node to perform information transmission-related steps in any key processing method.
[0327] In some embodiments, the first message is a Media Access Control (MAC) message; the MAC message includes at least a first sub-protocol data unit (PDU); the first PDU includes a cell change command; the cell change command is used to instruct the UE to access a second cell.
[0328] In some embodiments, the first sub-PDU further includes a first parameter.
[0329] In some embodiments, the first key is an integrity key, and at least the first parameter is protected for integrity by the first key.
[0330] In some embodiments, the first parameter is protected by the integrity of the first key. For example, the first parameter is protected by the integrity of the first key alone; or, the first parameter and the first identifier are protected by the integrity of the first key; the first identifier is associated with the first node.
[0331] In some embodiments, the first identifier includes at least one of the following:
[0332] Node identifier, used to indicate the first node;
[0333] Cell identifier, used to identify the cell of the first node to which the UE accesses;
[0334] Configuration identifier, used to identify the cell configuration of the first node accessed by the UE.
[0335] In some embodiments, the MAC message further includes a second sub-PDU; the second sub-PDU includes the first parameter.
[0336] In some embodiments, the second sub-PDU includes a Radio Resource Control (RRC) message; the RRC message includes a first parameter.
[0337] In some embodiments, the first key is an integrity key, and the RRC message is protected for integrity by the first key; and / or,
[0338] The first key is a confidential key, and RRC messages are protected by the confidentiality of the first key.
[0339] In some embodiments, the first message further includes a first indicator; the first indicator is used to indicate to the UE the parameter value for generating the second key.
[0340] In some embodiments, the first indicator is used to indicate the switching type, and different parameter values are used to generate the second key for different switching types; or...
[0341] The first indicator is used to indicate the key update type; different key update types use different parameter values to generate the second key.
[0342] In some embodiments, the first parameter includes the next-hop link count (NCC).
[0343] The first indicator has a first value, and the NCC is used by the UE to determine the parameter value for generating the second key.
[0344] In some embodiments, if the access management function of the second cell is the same as that of the first cell and the key parameters generated by the access management function remain unchanged, then the first indicator has a first value; if the access management function of the second cell is different from that of the first cell, or if the access management function of the second cell is the same as that of the first cell but the key parameters generated by the access management function need to be updated, then the first indicator has a second value.
[0345] In some embodiments, the processing module of the first node is configured to encode the first parameter using the first key at the Packet Data Convergence Protocol (PDCP) layer to obtain the first parameter protected by the first key; and to assemble the first parameter protected by the first key into a first message at the Media Access Control (MAC) layer.
[0346] As shown in Figure 6B, this embodiment of the present disclosure provides a UE, which may include:
[0347] The receiving module 6201 is configured to receive a first message sent by a first node of a first cell; the first message includes a first parameter, which is used by the UE to determine a second key for communication with a second cell; the first parameter is protected by the first key; the first key is the key for communication between the UE and the first cell.
[0348] In some embodiments, the transmitting module and / or receiving module may correspond to the network interface and / or transceiver antenna of the network node.
[0349] In some embodiments, the network node may include a processing module.
[0350] In some embodiments, the processing module can be used by a network node to perform information processing-related steps in any key processing method.
[0351] In some embodiments, the sending module can be used by a network node to perform information sending-related steps in any key processing method.
[0352] In some embodiments, the receiving module can be used by a network node to perform information transmission-related steps in any key processing method.
[0353] In some embodiments, the first message is a Media Access Control (MAC) message; the MAC message includes at least a first sub-protocol data unit (PDU). The first sub-PDU includes a cell change command; the cell change command is used to instruct the UE to access a second cell.
[0354] In some embodiments, the first sub-PDU further includes a first parameter.
[0355] In some embodiments, the first key is an integrity key, and at least the first parameter is protected for integrity by the first key.
[0356] In some embodiments, the first parameter is protected by the integrity of the first key. For example, the first parameter is protected by the integrity of the first key alone; or, the first parameter and the first identifier are protected by the integrity of the first key; the first identifier is associated with the first node.
[0357] In some embodiments, the first identifier includes at least one of the following: a node identifier for indicating a first node; a cell identifier for identifying the cell of the first node accessed by the UE; and a configuration identifier for identifying the cell configuration of the first node accessed by the UE.
[0358] In some embodiments, the MAC message further includes a second sub-PDU; the second sub-PDU includes the first parameter.
[0359] In some embodiments, the second sub-PDU includes a Radio Resource Control (RRC) message; the RRC message includes a first parameter.
[0360] In some embodiments, the first key is an integrity key, and the RRC message is protected by the integrity of the first key; and / or, the first key is a confidentiality key, and the RRC message is protected by the confidentiality of the first key.
[0361] In some embodiments, the first message further includes a first indicator; the first indicator is used to indicate to the UE the parameter value for generating the second key.
[0362] In some embodiments, the first indicator is used to indicate the switching type, and different parameter values are used to generate the second key for different switching types; or...
[0363] The first indicator is used to indicate the key update type; different key update types use different parameter values to generate the second key.
[0364] In some embodiments, the first parameter includes the next-hop link count (NCC); the processing module is configured such that the first indicator has a first value, and determines the parameter value used by the second key based on the NCC.
[0365] In some embodiments, if the access management function of the second cell is the same as that of the first cell and the key parameters generated by the access management function remain unchanged, then the first indicator has a first value; if the access management function of the second cell is different from that of the first cell, or if the access management function of the second cell is the same as that of the first cell but the key parameters generated by the access management function need to be updated, then the first indicator has a second value.
[0366] In some embodiments, the UE's processing module is further configured to verify the receipt of the first parameter at the Packet Data Convergence Protocol (PDCP) layer.
[0367] This disclosure also provides a communication device, which may include one or more processors; wherein the processors are configured to invoke instructions to cause the communication device to execute a key processing method that can be implemented in any of the foregoing embodiments.
[0368] In some embodiments, as shown in FIG7A and / or FIG7B, the communication device 8100 further includes one or more memories 8102 for storing instructions. Optionally, all or part of the memories 8102 may also be located outside the communication device 8100.
[0369] The communication device may be the aforementioned UE or network device. In some embodiments, the network device may be a primary node and / or a secondary node.
[0370] In some embodiments, the communication device 8100 further includes one or more transceivers 8103. When the communication device 8100 includes one or more transceivers 8103, the communication steps such as sending and receiving in the above method are performed by the transceivers 8103, and other steps are performed by the processor 8101.
[0371] In some embodiments, a transceiver may include a receiver and a transmitter, which may be separate or integrated. Optionally, the terms transceiver, transceiver unit, transceiver, transceiver circuit, etc., may be used interchangeably; the terms transmitter, transmitting unit, transmitter, transmitting circuit, etc., may be used interchangeably; and the terms receiver, receiving unit, receiver, receiving circuit, etc., may be used interchangeably.
[0372] Optionally, the communication device 8100 further includes one or more interface circuits 8104, which are connected to the memory 8102. The interface circuits 8104 can be used to receive signals from the memory 8102 or other devices, and can be used to send signals to the memory 8102 or other devices. For example, the interface circuits 8104 can read instructions stored in the memory 8102 and send the instructions to the processor 8101.
[0373] The communication device 8100 described in the above embodiments may be a network device or a UE, but the scope of the communication device 8100 described in this disclosure is not limited thereto, and the structure of the communication device 8100 may not be limited by FIG. 7A. The communication device may be a standalone device or a part of a larger device. For example, the communication device may be: (1) a standalone integrated circuit IC, or chip, or chip system or subsystem; (2) a collection of one or more ICs, optionally, the IC collection may also include storage components for storing data and programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, UE device, smart UE device, cellular phone, wireless device, handheld device, mobile unit, vehicle device, network device, cloud device, artificial intelligence device, etc.; (6) others, etc.
[0374] Figure 7B is a schematic diagram of the structure of chip 8200 provided in an embodiment of this disclosure. For cases where the communication device 8100 can be a chip or a chip system, please refer to the schematic diagram of chip 8200 shown in Figure 7B, but it is not limited thereto.
[0375] Chip 8200 includes one or more processors 8201, which are used to invoke instructions to cause chip 8200 to execute any of the above key processing methods.
[0376] In some embodiments, chip 8200 further includes one or more interface circuits 8202 connected to memory 8203. Interface circuits 8202 can be used to receive signals from memory 8203 or other devices, and can also be used to send signals to memory 8203 or other devices. For example, interface circuit 8202 can read instructions stored in memory 8203 and send those instructions to processor 8201. Optionally, terms such as interface circuit, interface, transceiver pin, and transceiver can be used interchangeably.
[0377] In some embodiments, chip 8200 further includes one or more memories 8203 for storing instructions. Optionally, all or part of the memories 8203 may be located outside of chip 8200.
[0378] This disclosure also provides a storage medium storing instructions that, when executed on a communication device 8100, cause the communication device 8100 to perform any of the methods described above. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer-readable storage medium, but it can also be a storage medium readable by other devices. Optionally, the storage medium can be a non-transitory storage medium, but it can also be a temporary storage medium.
[0379] This disclosure also provides a program product, which, when executed by a communication device 8100, causes the communication device 8100 to perform any of the above key processing methods. Optionally, the program product is a computer program product.
[0380] This disclosure also provides a computer program that, when run on a computer, causes the computer to perform any of the above key processing methods.
[0381] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of the embodiments of this disclosure that follow the general principles of the embodiments of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of the embodiments of this disclosure are indicated by the following claims.
[0382] It should be understood that the embodiments disclosed herein are not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from their scope. The scope of the embodiments disclosed herein is limited only by the appended claims.
Claims
A key processing method, wherein, The method, executed by the first node of the first cell, includes: A first message is sent to the user equipment (UE); the first message includes a first parameter, which is used by the UE to determine a second key for communicating with the second cell; the first parameter is protected by a first key; the first key is the key for the UE to communicate with the first cell. According to the method of claim 1, wherein, The first message is a Media Access Control (MAC) message; the MAC message includes at least a first sub-protocol data unit (PDU); the first sub-PDU includes a cell change command; the cell change command is used to instruct the UE to access the second cell. The method according to claim 2, wherein, The first sub-PDU also includes the first parameter. The method according to claim 3, wherein, The first key is an integrity key, and the first parameter is protected by the integrity of the first key; or, the first parameter and the first identifier are protected by the integrity of the first key. The first identifier is associated with the first node. The method according to claim 4, wherein, The first identifier includes at least one of the following: Node identifier, used to indicate the first node; Cell identifier, used to identify the cell of the first node to which the UE accesses; A configuration identifier is used to identify the cell configuration of the first node accessed by the UE. The method according to claim 2, wherein, The MAC message also includes a second sub-PDU; the second sub-PDU includes the first parameter. The method according to claim 6, wherein, The second sub-PDU includes a Radio Resource Control (RRC) message; the RRC message includes the first parameter. The method according to claim 7, wherein, The first key is an integrity key, and the RRC message is protected for integrity by the first key; And / or, The first key is a confidentiality key, and the RRC message is protected by the confidentiality of the first key. The method according to any one of claims 1 to 8, wherein, The first message also includes a first indicator; the first indicator is used to indicate to the UE the parameter value for generating the second key. The method according to claim 9, wherein, The first indicator is used to indicate the switching type, and the parameter values used to generate the second key are different for different switching types; or, The first indicator is used to indicate the key update type, and different key update types use different parameter values to generate the second key. The method according to claim 9 or 10, wherein, The first parameter includes the next-hop link count (NCC). The first indicator has a first value, and the NCC is used by the UE to determine the parameter value for generating the second key. The method according to claim 11, wherein, The access management function of the second cell is the same as that of the first cell, and the key parameters generated by the access management function remain unchanged. The first indicator has the first value. The access management function of the second cell is the same as that of the first cell, and the key parameters generated by the access management function need to be updated. The first indicator has a second value. The access management function of the second cell is different from that of the first cell, and the first indicator has the second value. The method according to any one of claims 1 to 12, wherein, The method further includes: The first parameter is encoded using the first key at the Packet Data Convergence Protocol (PDCP) layer; At the Media Access Control (MAC) layer, the first message is generated based on the first parameters encoded using the first key. A key processing method, wherein, Performed by a user equipment (UE), the method includes: The UE receives a first message sent by a first node of a first cell; the first message includes a first parameter, which is used by the UE to determine a second key for communication with a second cell; the first parameter is protected by a first key; the first key is the key for the UE to communicate with the first cell. The method according to claim 14, wherein, The first message is a Media Access Control (MAC) message; the MAC message includes at least a first sub-protocol data unit (PDU), the first sub-PDU including a cell change command; the cell change command is used to instruct the UE to access the second cell. The method according to claim 15, wherein, The first sub-PDU also includes the first parameter. The method according to claim 16, wherein, The first key is an integrity key, and the first parameter is protected by the integrity of the first key; or, the first parameter and the first identifier are protected by the integrity of the first key; the first identifier and The first node is associated. The method according to claim 17, wherein, The first identifier includes at least one of the following: Node identifier, used to indicate the first node; Cell identifier, used to identify the cell of the first node to which the UE accesses; A configuration identifier is used to identify the cell configuration of the first node accessed by the UE. The method according to claim 15, wherein, The MAC message also includes a second sub-PDU; the second sub-PDU includes the first parameter. The method according to claim 19, wherein, The second sub-PDU includes a Radio Resource Control (RRC) message; the RRC message includes the first parameter. The method according to claim 20, wherein, The first key is an integrity key, and the RRC message is protected for integrity by the first key; and / or, The first key is a confidentiality key, and the RRC message is protected by the confidentiality of the first key. The method according to any one of claims 14 to 21, wherein, The first message also includes a first indicator; the first indicator is used to indicate to the UE the parameter value for generating the second key. The method according to claim 22, wherein, The first indicator is used to indicate the switching type, and the parameter values used to generate the second key are different for different switching types; or, The first indicator is used to indicate the key update type, and different key update types use different parameter values to generate the second key. The method according to claim 21 or 22, wherein, The first parameter includes the next-hop link count (NCC); the method further includes: The first indicator has a first value, and the parameter value used by the second key is determined according to the NCC. The method according to claim 24, wherein, The access management function of the second cell is the same as that of the first cell, and the key parameters generated by the access management function remain unchanged. The first indicator has the first value. The access management function of the second cell is the same as that of the first cell, and the key parameters generated by the access management function need to be updated. The first indicator has a second value. The access management function of the second cell is different from that of the first cell, and the first indicator has the second value. The method according to any one of claims 14 to 25, wherein, The method further includes: The first parameter is verified to be received at the Packet Data Convergence Protocol (PDCP) layer. The first node of a first-cell community, wherein... The first node includes: The sending module is configured to send a first message to a user equipment (UE); the first message includes a first parameter, which is used by the UE to determine a second key for communication with a second cell; the first parameter is protected by a first key; the first key is a key for the UE to communicate with the first cell. A user equipment (UE), wherein, The UE includes: The receiving module is configured to receive a first message sent by a first node of a first cell; the first message includes a first parameter, which is used by the UE to determine a second key for communication with a second cell; the first parameter is protected by a first key; the first key is the key for the UE to communicate with the first cell. A communication system, wherein, The communication system includes a first node and a user equipment (UE); The first node is used to perform the method according to any one of claims 1 to 13; The UE is used to perform the method according to any one of claims 14 to 26. A communication device, wherein, The communication device includes: One or more processors; The processor is configured to invoke instructions to cause the communication device to execute the key processing method according to any one of claims 1 to 13 or 14 to 26. A storage medium, wherein, The storage medium stores instructions that, when executed on a communication device, cause the communication device to perform the key processing method according to any one of claims 1 to 13 or 14 to 26. A program product, wherein, The program product includes a computer program that, when executed by a communication device, enables the communication device to implement the key processing method described in any one of 1 to 13 or 14 to 26.
Citation Information
Patent Citations
Access stratum (AS) security for centralized radio access network (c-ran)
CN111971987A
Switching key determination method, switching method and device
CN116782211A
NR mobility – security considerations for l1 / l2 mobility switching of an spcell
WO2024031042A1