Information transmission method and apparatus, terminal, and network side device
By transmitting a portion of the MAC-I information in the handover command to indicate the NCC, the handover reliability issue caused by NCC tampering in MAC CE is resolved, thus improving the security and reliability of cell handover.
Patent Information
- Application Number
- PCT/CN2025/105252
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-07-12
- Filing Date
- 2025-06-30
- Publication Date
- 2026-01-15
AI Technical Summary
In communication systems, the reliability of cell handover is low because the NCC in the MAC CE may be tampered with.
The network-side device obtains the Message Authentication Code (MAC-I) and associates it with the Next Hop Link Count (NCC). It then transmits part of the MAC-I in the handover command to instruct the NCC. After the terminal performs integrity verification, it performs the mobility handover.
By protecting the integrity of the NCC, the reliability and security of cell handover are improved.
Smart Images

Figure CN2025105252_15012026_PF_FP_ABST
Abstract
Description
Information transmission methods, devices, terminals and network-side equipment
[0001] Cross-reference to related applications
[0002] This application claims priority to Chinese Patent Application No. 202410937207.5, filed on July 12, 2024, the entire contents of which are incorporated herein by reference. Technical Field
[0003] This application belongs to the field of communication technology, specifically relating to an information transmission method, apparatus, terminal, and network-side equipment. Background Technology
[0004] With the development of communication technology, in communication systems, network-side equipment can typically instruct terminals to perform cell handover via Layer 1 (L1) or L2-triggered mobility (LTM) handover commands. Currently, the LTM handover command usually carries a Next-hop Chaining Counter (NCC) in the Medium Access Control Element (MAC CE). The terminal uses the NCC to determine how to derive a new key to achieve cell handover. However, because the NCC in the MAC CE can be tampered with, the terminal may be unable to perform cell handover. Therefore, related technologies suffer from low reliability in cell handover. Summary of the Invention
[0005] This application provides an information transmission method, apparatus, terminal, and network-side equipment that can solve the problem of low reliability in cell handover.
[0006] Firstly, an information transmission method is provided, including:
[0007] The network-side device obtains a message verification code (MAC-I) for integrity, which is associated with the first next-hop link count (NCC).
[0008] The network-side device sends a handover command to the terminal. The handover command includes first information and second information. The first information includes at least a portion of the MAC-I. The second information is used to indicate the first NCC. The first NCC is used to derive the key of the target candidate cell.
[0009] Secondly, an information transmission method is provided, including:
[0010] The terminal receives a handover command from the network-side device. The handover command includes first information and second information. The first information includes at least a portion of the integrity verification code MAC-I. The second information is used to indicate the first next-hop link count (NCC). The first NCC is used to derive the key for the target candidate cell.
[0011] The terminal performs integrity verification based on the first information;
[0012] If the integrity verification passes, the terminal performs a mobility handover operation based on the second information.
[0013] Thirdly, an information transmission device is provided, comprising:
[0014] The first processing module is used for the network-side device to obtain a message verification code MAC-I for integrity, wherein the MAC-I is associated with the first next-hop link count NCC.
[0015] The sending module is used to send a handover command from the network-side device to the terminal. The handover command includes first information and second information. The first information includes at least a portion of the MAC-I. The second information is used to indicate the first NCC. The first NCC is used to derive the key of the target candidate cell.
[0016] Fourthly, an information transmission device is provided, comprising:
[0017] A receiving module is configured to receive a handover command from a network-side device. The handover command includes first information and second information. The first information includes at least a portion of the integrity verification code MAC-I. The second information is used to indicate a first next-hop link count (NCC). The first NCC is used to derive a key for the target candidate cell.
[0018] The second processing module is used to perform integrity verification based on the first information; if the integrity verification passes, it performs mobility handover operation based on the second information.
[0019] Fifthly, an information transmission apparatus is provided, the apparatus being configured to perform the steps of the method described in the first aspect, or to implement the steps of the method described in the second aspect.
[0020] In a sixth aspect, a terminal is provided, the terminal including a processor and a memory, the memory storing a program or instructions executable on the processor, the program or instructions, when executed by the processor, implementing the steps of the method as described in the first aspect.
[0021] In a seventh aspect, a terminal is provided, including a processor and a communication interface, wherein the communication interface is used to receive a handover command from a network-side device, the handover command including first information and second information, the first information including at least a portion of the integrity message verification code MAC-I, the second information being used to indicate a first next-hop link count (NCC), and the first NCC being used to derive a key for a target candidate cell;
[0022] The processor is used to perform integrity verification based on the first information; if the integrity verification passes, it performs mobility handover operation based on the second information.
[0023] Eighthly, a network-side device is provided, the network-side device including a processor and a memory, the memory storing a program or instructions executable on the processor, the program or instructions, when executed by the processor, implementing the steps of the method as described in the first aspect.
[0024] In a ninth aspect, a network-side device is provided, including a processor and a communication interface, wherein the processor is used by the network-side device to obtain a message verification code (MAC-I) for integrity, and the MAC-I is associated with a first next-hop link count (NCC).
[0025] The communication interface is used by the network-side device to send a handover command to the terminal. The handover command includes first information and second information. The first information includes at least a portion of the MAC-I content. The second information is used to indicate the first NCC. The first NCC is used to derive the key of the target candidate cell.
[0026] In a tenth aspect, a readable storage medium is provided, on which a program or instructions are stored, which, when executed by a processor, implement the steps of the method described in the first aspect, or implement the steps of the method described in the second aspect.
[0027] Eleventhly, a wireless communication system is provided, comprising: a terminal and a network-side device, wherein the terminal can be used to perform the steps of the method as described in the first aspect, and the network-side device can be used to perform the steps of the method as described in the second aspect.
[0028] In a twelfth aspect, a chip is provided, the chip including a processor and a communication interface coupled to the processor, the processor being configured to run programs or instructions to implement the method as described in the first aspect, or to implement the method as described in the second aspect.
[0029] In a thirteenth aspect, a computer program / program product is provided, which is stored in a storage medium and is executed by at least one processor to implement the steps of the method as described in the first aspect, or to implement the steps of the method as described in the second aspect.
[0030] This application embodiment obtains a Message Verification Code (MAC-I) for integrity via a network-side device. The MAC-I is associated with a first next-hop link count (NCC). The network-side device sends a handover command to the terminal. The handover command includes first information and second information. The first information includes at least a portion of the MAC-I, and the second information indicates the first NCC. The first NCC is used to derive the key for the target candidate cell. Thus, because the first information is transmitted simultaneously with indicating the first NCC, integrity protection of the NCC can be achieved based on the first information, improving the security of NCC transmission. Therefore, this application embodiment improves the reliability of cell handover. Attached Figure Description
[0031] Figure 1 is a block diagram of a wireless communication system applicable to an embodiment of this application;
[0032] Figure 2 shows the CU-DU architecture of a network-side device applicable to the embodiments of this application;
[0033] Figure 3 is a flowchart illustrating an information transmission method provided in an embodiment of this application;
[0034] Figure 4 is a flowchart illustrating another information transmission method provided in an embodiment of this application;
[0035] Figure 5 is a schematic diagram of the structure of an information transmission device provided in an embodiment of this application;
[0036] Figure 6 is a schematic diagram of another information transmission device provided in an embodiment of this application;
[0037] Figure 7 is a schematic diagram of the structure of a communication device provided in an embodiment of this application;
[0038] Figure 8 is a schematic diagram of the structure of a terminal provided in an embodiment of this application;
[0039] Figure 9 is a schematic diagram of the structure of a network-side device provided in an embodiment of this application. Detailed Implementation
[0040] The terms "first," "second," etc., used in this application are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such terms can be used interchangeably where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first" and "second" are generally of the same class, not limited in number; for example, the first object can be one or more. Furthermore, "or" in this application indicates at least one of the connected objects. For example, the scope of protection for "A or B" covers at least three scenarios: Scenario 1: including A but not B; Scenario 2: including B but not A; Scenario 3: including both A and B. In addition, the terms "A and / or B," "at least one of A and B," and "at least one of A or B" also cover at least the above three scenarios. The character " / " generally indicates that the preceding and following objects are in an "or" relationship.
[0041] The term "instruction" in this application can be either a direct instruction (or explicit instruction) or an indirect instruction (or implicit instruction). A direct instruction can be understood as one in which the sender explicitly informs the receiver of specific information, the operation to be performed, or the requested result, etc., in the instruction sent. An indirect instruction can be understood as one in which the receiver determines the corresponding information based on the instruction sent by the sender, or makes a judgment and determines the operation to be performed or the requested result, etc., based on the judgment result.
[0042] It is worth noting that the technologies described in this application are not limited to Long Term Evolution (LTE) / LTE-Advanced (LTE-A) systems, but can also be used in other wireless communication systems, such as Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single-carrier Frequency-Division Multiple Access (SC-FDMA), or other systems. The terms "system" and "network" in this application are often used interchangeably, and the described technologies can be used with the systems and radio technologies mentioned above, as well as with other systems and radio technologies. The following description describes New Radio (NR) systems for illustrative purposes, and the term NR is used in most of the following description; however, these technologies can also be applied to systems other than NR systems, such as 6th generation (6G) radio systems. th Generation 6G communication system.
[0043] Figure 1 shows a block diagram of a wireless communication system applicable to an embodiment of this application. The wireless communication system includes a terminal 11 and a network-side device 12. The terminal 11 can be a mobile phone, tablet computer, laptop computer, notebook computer, personal digital assistant (PDA), handheld computer, netbook, ultra-mobile personal computer (UMPC), mobile internet device (MID), augmented reality (AR), virtual reality (VR) device, robot, wearable device, flight vehicle, vehicle user equipment (VUE), shipboard equipment, pedestrian user equipment (PUE), smart home (home devices with wireless communication capabilities, such as refrigerators, televisions, washing machines, or furniture), game console, personal computer (PC), ATM, or self-service machine, etc. Wearable devices include: smartwatches, smart bracelets, smart headphones, smart glasses, smart jewelry (smart bracelets, smart chains, smart rings, smart necklaces, smart anklets, smart anklets, etc.), smart wristbands, smart clothing, etc. Among these, in-vehicle devices can also be referred to as in-vehicle terminals, in-vehicle controllers, in-vehicle modules, in-vehicle components, in-vehicle chips, or in-vehicle units, etc. It should be noted that the specific type of terminal 11 is not limited in this application embodiment. Network-side equipment 12 may include access network equipment or core network equipment, wherein access network equipment may also be referred to as Radio Access Network (RAN) equipment, radio access network function, or radio access network unit. Access network equipment may include base stations, Wireless Local Area Network (WLAN) access points (APs), or Wireless Fidelity (WiFi) nodes, etc.The term "base station" can be referred to as Node B (NB), Evolved Node B (eNB), Next Generation Node B (gNB), New Radio Node B (NR Node B), Access Point, Relay Base Station (RBS), Serving Base Station (SBS), Base Transceiver Station (BTS), Radio Base Station, Radio Transceiver, Basic Service Set (BSS), Extended Service Set (ESS), Home Node B (HNB), Home Evolved Node B, Transmit / Receive Point (TRP), or any other suitable term in the relevant field, as long as the same technical effect is achieved. The term "base station" is not limited to any specific technical terminology. It should be noted that this application embodiment only uses a base station in an NR system as an example for description and does not limit the specific type of base station.
[0044] For ease of understanding, the following describes some aspects of the embodiments of this application:
[0045] I. Centralized Unit (CU) - Distributed Unit (CU) Architecture.
[0046] The NR access network splits the gNB into a central unit (gNB-CU) and a distributed unit (gNB-DU), which are connected through the F1 interface. The architecture diagram of the CU-DU is shown in Figure 2.
[0047] A gNB contains only one CU, which contains one or more DUs. A DU contains one or more cells. The CU contains the Packet Data Convergence Protocol (PDCP) and higher protocol stacks, while the DU contains protocol stacks below the PDCP layer, such as Radio Link Control (RLC), MAC, and Physical (PHY) layer protocol stacks.
[0048] In the control plane, the CU includes the RRC and the control plane PDCP (PDCP-C). In the user plane, the CU includes the Service Data Adaptation Protocol (SDAP) and the user plane PDCP (PDCP-U).
[0049] II. 5G NR Access-stratum (AS) security.
[0050] In the NR access layer, data protection is implemented by PDCP, which includes two layers: ciphering and integrity protection. Simply put, ciphering involves the sender converting plaintext data into ciphertext before transmission to prevent eavesdropping. Integrity protection involves the sender generating a Message Authentication Code (MAC) from the data for the receiver to verify, preventing tampering (or replay attacks) by attackers.
[0051] In AS security, "control plane" data uses K RRCint and K RRCenc Protection, while "user plane" data uses K UPint and K UPenc Protection, where int represents integrity and enc represents encryption. These keys can be called AS direct keys, which are the keys directly used by the AS encryption and integrity algorithms.
[0052] The sending PDCP entity is responsible for integrity protection and encryption, while the receiving PDCP entity is responsible for decryption and integrity verification.
[0053] The key to encryption protection is generating the same keystream. Both the "sender" and "receiver" use the same encryption algorithm (Encryption Algorithm (EEA) or Network Encryption Algorithm (NEA), key, and parameters (COUNT, BEARER, DIRECTION, LENGTH) to calculate their respective keystreams. Theoretically, the keystreams should also be identical. The "sender" performs an exclusive OR (XOR) operation between the keystream and the "plaintext" to obtain the "ciphertext," and the "receiver" performs an XOR operation with the same keystream and the "ciphertext" to recover the "plaintext."
[0054] The key to integrity protection is generating identical MAC addresses. Both the "sender" and "receiver" use the same integrity algorithm (EIA or NIA), key, and parameters (including but not limited to count, bearer, direction, and message) to calculate their respective MAC addresses. The "sender" transmits its Message Authentication Code for Integrity (MAC-I) to the "receiver," which compares it with its own calculated XMAC-I. If the XMAC-I and MAC-I are identical, the integrity verification passes.
[0055] III. Integrity protection of Radio Resource Control (RRC) Reestablishment Request (RRCReestablishmentRequest) and Resume Request (RRCResumeRequest).
[0056] The RRCReestablishmentRequest message is sent by the terminal to the network-side device for RRC connection re-establishment. The message carries a short MAC-I (ShortMAC-I) for the network-side device to identify and verify the terminal. The ShortMAC-I is taken from the 16 least significant bits of the complete MAC-I.
[0057] The RRC ResumeRequest message is sent by the terminal to the network-side device to resume the RRC connection in the inactive state. The message carries resumeMAC-I, which is used by the network side to identify and verify the UE. resumeMAC-I is taken from the 16 least significant bits of the complete MAC-I.
[0058] The MAC-I during the RRC reconstruction process uses the source serving cell (source PCell) or the K of the cell that was in use before reconstruction. RRCint The integrity protection algorithm calculates the input parameters COUNT, BEARER, and DIRECTION, setting them to all binary 1s. The reconstruction request message is sent via Signalalling Radio Bearer (SRB) 0. Since SRB 0 does not have a PDCP entity, the integrity protection input parameters are not the message itself, but rather input parameters related to the terminal's valid identity and location information, such as VarShortMAC-Input, which includes:
[0059] sourcePhysCellId: The physical cell identifier (PCI) used to indicate the PCell to which the UE was connected before reconstruction;
[0060] targetCellIdentity: The identifier of the target cell that the UE is attempting to rebuild;
[0061] source-c-RNTI: Used to indicate the Cell Radio Network Temporary Identifier (C-RNTI) within the PCell to which the UE was connected before reconstruction.
[0062] The MAC-I during the RRC recovery process uses the K stored in the UE Inactive AS Context. RRCint The integrity protection algorithm is computed using the previously configured integrity protection algorithm. Similar to reconstruction, the input parameters COUNT, BEARER, and DIRECTION are set to all binary 1s. Instead of MESSAGE, VarResumeMAC-Input is used as the input, which includes:
[0063] sourcePhysCellId: Used to indicate the PCI of the PCell to which the UE was connected before the RRC connection was suspended;
[0064] targetCellIdentity: The identifier of the target cell that the UE is attempting to recover;
[0065] source-c-RNTI: Used to indicate the C-RNTI within the PCell to which the UE was connected before the RRC connection was suspended.
[0066] For LTE's shortResumeMAC-I calculation, there is also a 1-bit resumeDiscriminator indication, which is set to 1 to identify that the MAC-I calculation is for shortResumeMAC-I.
[0067] NCC stands for NextHopChainingCount. The terminal uses NCC to determine how to derive a new key.
[0068] IV. Key Derivation in the Switching Process
[0069] When the terminal performs a handover and applies the target cell's RRC configuration, the following behaviors are included:
[0070] If the NCC value received by the UE in the handover command and the currently used source cell key K gNB / K eNB If the associated NCC is the same, then the UE will use the current K. gNB / K eNB, The target cell key K is derived from the target PCI and frequency level. NG-RAN *;
[0071] If the NCC value received by the UE in the handover command is the same as the currently used K... gNB / K eNB If the associated NCCs are different, the UE first synchronizes the NCC and NH until they match the NCC indicated by the handover command. Then, the UE vertically derives K based on the synchronized NH, target PCI, and frequency point. NG-RAN *;
[0072] Terminal uses K NG-RAN *K used for communication with the target gNB / ng-eNB gNB / K eNB .
[0073] V. LTM Switching.
[0074] In the R18 mobility enhancement project, LTM was introduced. Based on the Layer 1 measurement results reported by the terminal, the DU uses L1 or L2 signaling to instruct the terminal to hand over to a suitable candidate cell. R18 LTM only supports cell handover within the same CU.
[0075] R19 LTM is discussing cell handover across CUs. After switching CUs, the UE needs to update its key. One approach to instructing the key update parameter NCC is to include the NCC in the LTM Cell Switch Command MAC CE.
[0076] For inter-CU LTM, one approach to indicate the NCC (Neural Code Control) is to include it in the LTM handover command MAC CE. However, the MAC CE lacks integrity protection, and including key-related information (such as the NCC) in the MAC CE could lead to NCC tampering and security issues. Therefore, how to ensure the integrity of the NCC when it is included in the LTM handover command to prevent security problems caused by NCC tampering remains a problem. To address this, the information transmission method of this application is proposed.
[0077] The information transmission method provided in this application will be described in detail below with reference to the accompanying drawings and through some embodiments and application scenarios.
[0078] Referring to FIG3, an embodiment of this application provides an information transmission method, as shown in FIG3, the information transmission method includes:
[0079] Step 301: The network-side device obtains a message verification code (MAC-I) for integrity, wherein the MAC-I is associated with the first next-hop link count (NCC).
[0080] Step 302: The network-side device sends a handover command to the terminal. The handover command includes first information and second information. The first information includes at least a portion of the MAC-I. The second information is used to indicate the first NCC. The first NCC is used to derive the key of the target candidate cell.
[0081] In this embodiment, the network-side device can obtain the MAC-I from other network-side devices or calculate the MAC-I itself. Optionally, the network-side device can calculate a MAC-I for each candidate cell, for example, it can calculate the MAC-I associated with each candidate cell based on the relevant information of each candidate cell; alternatively, it can calculate a unified MAC-I for all candidate cells, for example, it can calculate the MAC-I associated with all candidate serving cells based on the relevant information of the source serving cell. In other words, calculating the MAC-I by the network-side device can be understood as the network-side device calculating one or more MAC-Is.
[0082] Optionally, the switching commands mentioned above may include, but are not limited to, LTM switching commands.
[0083] Optionally, in some embodiments, the first information mentioned above may be a portion of the bits of the complete MAC-I, such as the 16 least significant bits of the complete MAC-I.
[0084] Optionally, the aforementioned target candidate cell can be understood as the target cell for which the terminal is instructed to perform cell handover based on the aforementioned handover command. The network-side device can determine the target candidate cell for terminal handover from a pre-configured pool of candidate cells, and then send second information and first information determined based on the MAC-I associated with the target candidate cell to the terminal. When the terminal receives the first and second information, it can perform an integrity check based on the first information. If the integrity check passes, the terminal performs a mobility handover operation based on the second information.
[0085] It should be noted that the terminal uses the same integrity protection key, integrity protection algorithm, and integrity input to calculate the first information based on the same integrity protection key as the network-side device. If the calculated first information is the same as the first information indicated in the handover command, the integrity verification passes.
[0086] This application embodiment obtains a Message Verification Code (MAC-I) for integrity via a network-side device. The MAC-I is associated with a first next-hop link count (NCC). The network-side device sends a handover command to the terminal. The handover command includes first information and second information. The first information includes at least a portion of the MAC-I, and the second information indicates the first NCC. The first NCC is used to derive the key for the target candidate cell. Thus, because the first information is transmitted simultaneously with indicating the first NCC, integrity protection of the NCC can be achieved based on the first information, improving the security of NCC transmission. Therefore, this application embodiment improves the reliability of cell handover.
[0087] Optionally, in some embodiments, the network-side device obtains the Message Verification Code (MAC-I) for integrity by:
[0088] Network-side devices calculate MAC-I based on the target key and the target integrity protection algorithm;
[0089] The target key includes the key used by the terminal in the first cell, and the target integrity protection algorithm includes the integrity protection algorithm used by the terminal in the first cell. The first cell includes at least one of a source serving cell or a candidate cell.
[0090] In this embodiment, the target key and the cell associated with the target integrity protection algorithm are the same cell. For example, when the number of MAC-Is calculated by the target integrity protection algorithm is 1, the target key can be the terminal's key in the source serving cell, and the target integrity protection algorithm is the terminal's integrity protection algorithm in the source serving cell. When the number of MAC-Is calculated by the target integrity protection algorithm is at least two, the target key can be the terminal's key in the source serving cell, and the target integrity protection algorithm is the terminal's integrity protection algorithm in the source serving cell, wherein the input of the integrity protection algorithm can include information associated with each candidate cell; or, the target key can be the terminal's key in the candidate serving cell, and the target integrity protection algorithm is the terminal's integrity protection algorithm in the candidate cell. For example, in some embodiments, when calculating the MAC-I associated with each candidate cell, the calculation can be based on the terminal's key in that candidate cell and the terminal's integrity protection algorithm in that candidate cell. In this way, each candidate cell uses its own key to generate a different MAC-I, thereby improving the security of the integrity protection operation.
[0091] Optionally, the target key mentioned above can be K. RRCInt .
[0092] Optionally, in some embodiments, the input parameters of the target integrity protection algorithm include at least one of the following:
[0093] The first NCC;
[0094] Target indication, the target indication being used to indicate that the MAC-I is used for switching;
[0095] Configuration identifier for candidate cells or candidate cell groups;
[0096] Identification of candidate communities;
[0097] The signage for the source service community;
[0098] The terminal's temporary identifier for the cell wireless network within the source serving cell, C-RNTI.
[0099] In this embodiment of the application, the above handover can be understood as LTM handover, and the configuration identifier of the above candidate cell or candidate cell group can be understood or replaced as LTM candidate identifier (Candidate ID).
[0100] Optionally, the identifiers of the aforementioned candidate cells may include, but are not limited to, at least one of the following: PCI and NR Cell Global Identifier (CGI).
[0101] It should be understood that when the input parameters of the target integrity protection algorithm include the first NCC, the first information generated by different NCCs is different, which helps to improve the security of transmission.
[0102] Optionally, in some embodiments, when the first cell is a candidate cell, the input parameters of the target integrity protection algorithm include the identifier of the candidate cell or the configuration identifier of the candidate cell group corresponding to the candidate cell.
[0103] In this embodiment of the application, if the MAC-I is calculated using a candidate cell key or the complete input includes a candidate cell identifier or a configuration identifier of a candidate cell (or candidate cell group), then a MAC-I and third information are calculated for each configured candidate cell, and the third information includes at least a portion of the calculated MAC-I; when calculating the MAC-I associated with each candidate cell, the key corresponding to the candidate cell and the candidate cell identifier or the configuration identifier of the candidate cell (or candidate cell group) are used for calculation.
[0104] Optionally, in some embodiments, the second information includes any of the following:
[0105] The first NCC;
[0106] The difference between the first NCC and the second NCC, where the second NCC is the NCC stored by the terminal for use in deriving the current serving cell key.
[0107] In this embodiment, assuming the first NCC value used to derive the target candidate cell key is 5, and the terminal currently stores a first NCC value of 4, the second information can directly indicate 5 or indicate a difference of 1. When the second information is the difference between the first NCC and the second NCC, it can help improve the security of NCC transmission.
[0108] Optionally, in some embodiments, the network-side device obtains the Message Verification Code (MAC-I) for integrity by:
[0109] The centralized unit (CU) of the network-side device calculates the MAC-I;
[0110] The CU of the network-side device sends a target message to the DU of the network-side device. The target message includes the second information and at least one third information. The third information includes at least a portion of the calculated MAC-I, and the first information is at least a portion of the MAC-I corresponding to the target candidate cell in the at least one third information.
[0111] It should be understood that on the network side, the DU and CU devices can be deployed separately and independently, or the functions of the DU and CU can be integrated together, for example, without distinguishing between the DU and CU. When the DU and CU are deployed separately and independently, the CU can calculate the MAC-I, and then the CU can send a second piece of information and at least one third piece of information to the DU.
[0112] In this embodiment of the application, when the target message includes one third piece of information, the content of the target message can be directly carried in the handover command; when the target message includes at least two pieces of third information, the first piece of information carried in the handover command is the third piece of information associated with the target candidate cell or the candidate cell group corresponding to the target candidate cell.
[0113] Optionally, in some embodiments, when the target message includes at least two third pieces of information, the target message also includes a configuration identifier of the candidate cell or a configuration identifier of the candidate cell group associated with each of the third pieces of information.
[0114] In this embodiment of the application, the DU can determine the first information carried by the handover command from at least two third information based on the configuration identifier of the candidate cell or the configuration identifier of the candidate cell group associated with each of the third information and the target candidate cell for handover.
[0115] Optionally, in some embodiments, the method further includes:
[0116] The network-side device or the CU of the network-side device encrypts the third information and the second information.
[0117] The switching command carries encrypted third and second information, and the encryption process satisfies at least one of the following:
[0118] Encryption is performed based on the key of the terminal in the source serving cell;
[0119] Encryption is performed using the encryption algorithm of the terminal in the source serving cell;
[0120] The lengths of the first NCC and the third information are used as encryption inputs for encryption.
[0121] In this embodiment, the encrypted input may further include COUNT, BEARER, and DIRECTION, all of which can be set to 1. Because the first and second information are encrypted, eavesdropping by attackers is prevented, thereby further improving the security of the transmission of the first and second information.
[0122] Referring to FIG4, this application embodiment also provides an information transmission method, as shown in FIG4, the information transmission method includes:
[0123] Step 401: The terminal receives a handover command from the network-side device. The handover command includes first information and second information. The first information includes at least a portion of the integrity verification code MAC-I. The second information is used to indicate the first next-hop link count (NCC). The first NCC is used to derive the key of the target candidate cell.
[0124] Step 402: The terminal performs an integrity check based on the first information;
[0125] Step 403: If the integrity verification passes, the terminal performs a mobility handover operation based on the second information.
[0126] Optionally, before the terminal performs integrity verification based on the first information, the method further includes:
[0127] The terminal decrypts the first information and the second information.
[0128] The decryption process includes at least one of the following:
[0129] Decryption is performed based on the key of the terminal in the source serving cell;
[0130] Decryption is performed based on the encryption algorithm of the terminal in the source serving cell;
[0131] Decryption is performed using the length of the first NCC and the first information as decryption input.
[0132] Optionally, if the integrity verification passes, the terminal performing a mobility handover operation based on the second information includes:
[0133] If the integrity verification passes, the terminal determines the first NCC based on the second information;
[0134] The terminal derives the key of the target candidate cell based on the first NCC and performs a mobility handover operation.
[0135] Optionally, the MAC-I is determined based on a target key and a target integrity protection algorithm, wherein the target key includes the key used by the terminal in the first cell, and the target integrity protection algorithm includes the integrity protection algorithm used by the terminal in the first cell, and the first cell includes at least one of a source serving cell or a candidate cell.
[0136] Optionally, the input parameters of the target integrity protection algorithm include at least one of the following:
[0137] The first NCC;
[0138] Target indication, the target indication being used to indicate that the MAC-I is used for switching;
[0139] Configuration identifier for candidate cells or candidate cell groups;
[0140] Identification of candidate communities;
[0141] The signage for the source service community;
[0142] The terminal's temporary identifier for the cell wireless network within the source serving cell, C-RNTI.
[0143] Optionally, when the first cell is a candidate cell, the input parameters of the target integrity protection algorithm include the identifier of the candidate cell or the configuration identifier of the candidate cell group corresponding to the candidate cell.
[0144] Optionally, the second information includes any of the following:
[0145] The first NCC;
[0146] The difference between the first NCC and the second NCC, where the second NCC is the NCC stored by the terminal for use in deriving the current serving cell key.
[0147] The information transmission method provided in this application can be executed by an information transmission device. This application uses an information transmission device executing the information transmission method as an example to illustrate the information transmission device provided in this application.
[0148] This application provides an information transmission device. As an example, the information transmission device may be a communication device or a component within a communication device, such as a chip. The communication device may be a terminal, a network-side device, or a server, etc. Exemplarily, the terminal may include, but is not limited to, the type of terminal 11 listed above, and the network-side device may include, but is not limited to, the type of network-side device 12 listed above. This application does not impose specific limitations.
[0149] The information transmission device includes a receiving module, a transmitting module, and a processing module. These modules can be implemented in software or hardware. When implemented in hardware, the processing module can be implemented by a processor. For example, the processor can include general-purpose processors, special-purpose processors, such as a Central Processing Unit (CPU), microprocessor, Digital Signal Processor (DSP), Artificial Intelligence (AI) processor, Graphics Processing Unit (GPU), Application Specific Integrated Circuit (ASIC), Network Processor (NP), Field Programmable Gate Array (FPGA), or other programmable logic devices, gate circuits, transistors, discrete hardware components, etc. The receiving and transmitting modules can be implemented by a communication interface, which can include one or more of the following: transceiver, pins, circuits, bus, radio frequency unit, etc.
[0150] Specifically, referring to Figure 5, when the information transmission device is a network-side device or a component within a network-side device, the information transmission device 500 includes:
[0151] The first processing module 501 is used by the network-side device to calculate the integrity message verification code MAC-I, wherein the MAC-I is associated with the first next-hop link count NCC.
[0152] The sending module 502 is used to send a handover command from the network-side device to the terminal. The handover command includes first information and second information. The first information includes at least a portion of the MAC-I content. The second information is used to indicate the first NCC. The first NCC is used to derive the key of the target candidate cell.
[0153] Optionally, the first processing module 501 is specifically used by the network-side device to calculate MAC-I based on the target key and the target integrity protection algorithm;
[0154] The target key includes the key used by the terminal in the first cell, and the target integrity protection algorithm includes the integrity protection algorithm used by the terminal in the first cell. The first cell includes at least one of a source serving cell or a candidate cell.
[0155] Optionally, the input parameters of the target integrity protection algorithm include at least one of the following:
[0156] The first NCC;
[0157] Target indication, the target indication being used to indicate that the MAC-I is used for switching;
[0158] Configuration identifier for candidate cells or candidate cell groups;
[0159] Identification of candidate communities;
[0160] The signage for the source service community;
[0161] The terminal's temporary identifier for the cell wireless network within the source serving cell, C-RNTI.
[0162] Optionally, when the first cell is a candidate cell, the input parameters of the target integrity protection algorithm include the identifier of the candidate cell or the configuration identifier of the candidate cell group corresponding to the candidate cell.
[0163] Optionally, the second information includes any of the following:
[0164] The first NCC;
[0165] The difference between the first NCC and the second NCC, where the second NCC is the NCC stored by the terminal for use in deriving the current serving cell key.
[0166] Optionally, the first processing module is specifically used by the centralized unit (CU) of the network-side device to calculate the MAC-I;
[0167] The sending module is specifically used to perform the following operations: the CU of the network-side device sends a target message to the distribution unit DU of the network-side device, the target message including the second information and at least one third information; the third information includes at least a portion of the calculated MAC-I, and the first information is at least a portion of the MAC-I corresponding to the target candidate cell in the at least one third information.
[0168] Optionally, if the target message includes at least two third pieces of information, the target message may also include a configuration identifier of the candidate cell or a configuration identifier of the candidate cell group associated with each of the third pieces of information.
[0169] Optionally, the first processing module is further configured to encrypt the third information and the second information by the network-side device or the CU of the network-side device;
[0170] The switching command carries encrypted third and second information, and the encryption process satisfies at least one of the following:
[0171] Encryption is performed based on the key of the terminal in the source serving cell;
[0172] Encryption is performed using the encryption algorithm of the terminal in the source serving cell;
[0173] The lengths of the first NCC and the third information are used as encryption inputs for encryption.
[0174] Referring to Figure 6, when the information transmission device is a terminal or a component within a terminal, the information transmission device 600 includes:
[0175] The receiving module 601 is configured to receive a handover command from a network-side device. The handover command includes first information and second information. The first information includes at least a portion of the integrity verification code MAC-I. The second information is used to indicate a first next-hop link count (NCC). The first NCC is used to derive the key for the target candidate cell.
[0176] The second processing module 602 is used to perform integrity verification based on the first information; if the integrity verification passes, it performs mobility handover operation based on the second information.
[0177] Optionally, the second processing module 602 is further configured to decrypt the first information and the second information;
[0178] The decryption process includes at least one of the following:
[0179] Decryption is performed based on the key of the terminal in the source serving cell;
[0180] Decryption is performed based on the encryption algorithm of the terminal in the source serving cell;
[0181] Decryption is performed using the length of the first NCC and the first information as decryption input.
[0182] Optionally, the second processing module 602 is specifically used to determine the first NCC based on the second information when the integrity verification passes; derive the key of the target candidate cell according to the first NCC; and perform a mobility handover operation.
[0183] Optionally, the MAC-I is determined based on a target key and a target integrity protection algorithm, wherein the target key includes the key used by the terminal in the first cell, and the target integrity protection algorithm includes the integrity protection algorithm used by the terminal in the first cell, and the first cell includes at least one of a source serving cell or a candidate cell.
[0184] Optionally, the input parameters of the target integrity protection algorithm include at least one of the following:
[0185] The first NCC;
[0186] Target indication, the target indication being used to indicate that the MAC-I is used for switching;
[0187] Configuration identifier for candidate cells or candidate cell groups;
[0188] Identification of candidate communities;
[0189] The signage for the source service community;
[0190] The terminal's temporary identifier for the cell wireless network within the source serving cell, C-RNTI.
[0191] Optionally, when the first cell is a candidate cell, the input parameters of the target integrity protection algorithm include the identifier of the candidate cell or the configuration identifier of the candidate cell group corresponding to the candidate cell.
[0192] Optionally, the second information includes any of the following:
[0193] The first NCC;
[0194] The difference between the first NCC and the second NCC, where the second NCC is the NCC stored by the terminal for use in deriving the current serving cell key.
[0195] The information transmission device provided in this application embodiment can implement the various processes implemented in the method embodiments of Figures 3 to 4 and achieve the same technical effect. To avoid repetition, it will not be described again here.
[0196] As shown in Figure 7, this application embodiment also provides a communication device 700, including a processor 701 and a memory 702. The memory 702 stores a program or instructions that can run on the processor 701. When the program or instructions are executed by the processor 701, they implement the various steps of the above-described information transmission method embodiment and can achieve the same technical effect. To avoid repetition, they will not be described again here.
[0197] This application also provides a terminal, including a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the steps in the method embodiment shown in FIG4. This terminal embodiment corresponds to the above-described terminal-side method embodiment, and all implementation processes and methods of the above-described method embodiments can be applied to this terminal embodiment and can achieve the same technical effect. The terminal may be the information transmission device shown in FIG6. Specifically, FIG8 is a schematic diagram of the hardware structure of a terminal implementing an embodiment of this application.
[0198] The terminal 800 includes, but is not limited to, at least some of the following components: radio frequency unit 801, network module 802, audio output unit 803, input unit 804, sensor 805, display unit 806, user input unit 807, interface unit 808, memory 809, and processor 810.
[0199] Those skilled in the art will understand that the terminal 800 may also include a power supply (such as a battery) for powering various components. The power supply can be logically connected to the processor 810 through a power management system, thereby enabling functions such as charging, discharging, and power consumption management through the power management system. The terminal structure shown in Figure 8 does not constitute a limitation on the terminal. The terminal may include more or fewer components than shown, or combine certain components, or have different component arrangements, which will not be elaborated here.
[0200] It should be understood that, in this embodiment, the input unit 804 may include a graphics processor 8041 and a microphone 8042. The graphics processor 8041 processes image data of still images or videos obtained by an image capture device (such as a camera) in video capture mode or image capture mode. The display unit 806 may include a display panel 8061, which may be configured in the form of a liquid crystal display, an organic light-emitting diode, or the like. The user input unit 807 includes at least one of a touch panel 8071 and other input devices 8072. The touch panel 8071 is also called a touch screen. The touch panel 8071 may include two parts: a touch detection device and a touch controller. Other input devices 8072 may include, but are not limited to, physical keyboards, function keys (such as volume control buttons, power buttons, etc.), trackballs, mice, and joysticks, which will not be described in detail here.
[0201] In this embodiment, after receiving downlink data from the network-side device, the radio frequency unit 801 can transmit it to the processor 810 for processing; in addition, the radio frequency unit 801 can send uplink data to the network-side device. Typically, the radio frequency unit 801 includes, but is not limited to, antennas, amplifiers, transceivers, couplers, low-noise amplifiers, duplexers, etc.
[0202] The memory 809 can be used to store software programs or instructions, as well as various data. The memory 809 may primarily include a first storage area for storing programs or instructions and a second storage area for storing data. The first storage area may store the operating system, application programs or instructions required for at least one function (such as sound playback, image playback, etc.). Furthermore, the memory 809 may include volatile memory or non-volatile memory. The non-volatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory can be random access memory (RAM), static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct memory bus RAM (DRRAM). The memory 809 in the embodiments of this application includes, but is not limited to, these and any other suitable types of memory.
[0203] Processor 810 may include one or more processing units; optionally, processor 810 integrates an application processor and a modem processor, wherein the application processor mainly handles operations involving the operating system, user interface, and applications, and the modem processor mainly handles wireless communication signals, such as a baseband processor. It is understood that the aforementioned modem processor may also not be integrated into processor 810.
[0204] The radio frequency unit 801 is used to receive a handover command from a network-side device. The handover command includes first information and second information. The first information includes at least a portion of the integrity verification code MAC-I. The second information is used to indicate a first next-hop link count (NCC). The first NCC is used to derive the key for the target candidate cell.
[0205] The processor 810 is configured to perform an integrity check based on the first information; and if the integrity check passes, to perform a mobility handover operation based on the second information.
[0206] It is understood that the implementation process of each implementation method mentioned in this embodiment can refer to the relevant description of the terminal side method embodiment and achieve the same or corresponding technical effects. To avoid repetition, it will not be described again here.
[0207] This application also provides a network-side device, including a processor and a communication interface. The communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the steps of the method embodiment shown in FIG3. This network-side device embodiment corresponds to the above-described network-side device method embodiment. All implementation processes and methods of the above-described method embodiments can be applied to this network-side device embodiment and can achieve the same technical effect.
[0208] Specifically, this application embodiment also provides a network-side device, which can be the information transmission device shown in FIG5. As shown in FIG9, the network-side device 900 includes: an antenna 901, a radio frequency device 902, a baseband device 903, a processor 904, and a memory 905. The antenna 901 is connected to the radio frequency device 902. In the uplink direction, the radio frequency device 902 receives information through the antenna 901 and sends the received information to the baseband device 903 for processing. In the downlink direction, the baseband device 903 processes the information to be transmitted and sends it to the radio frequency device 902, which processes the received information and then transmits it through the antenna 901.
[0209] The method executed by the network-side device in the above embodiments can be implemented in the baseband device 903, which includes a baseband processor.
[0210] The baseband device 903 may include at least one baseband board, on which multiple chips are disposed, as shown in FIG9. One of the chips is, for example, a baseband processor, which is connected to the memory 905 via a bus interface to call the program in the memory 905 to execute the network-side device operations shown in the above method embodiments.
[0211] The network-side device may also include a network interface 906, such as a Common Public Radio Interface (CPRI).
[0212] Specifically, the network-side device 900 in this application embodiment further includes: instructions or programs stored in memory 905 and executable on processor 904. Processor 904 calls the instructions or programs in memory 905 to execute the methods executed by each module shown in FIG5 and achieve the same technical effect. To avoid repetition, it will not be described in detail here.
[0213] This application also provides a readable storage medium storing a program or instructions. When the program or instructions are executed by a processor, they implement the various processes of the above-described information transmission method embodiments and achieve the same technical effects. To avoid repetition, they will not be described again here.
[0214] The processor mentioned above is the processor in the terminal described in the above embodiments. The readable storage medium includes computer-readable storage media, such as computer read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk. In some examples, the readable storage medium may be a non-transient readable storage medium.
[0215] This application embodiment also provides a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor. The processor is used to run programs or instructions to implement the various processes of the above-described information transmission method embodiments and can achieve the same technical effect. To avoid repetition, it will not be described again here.
[0216] It should be understood that the chip mentioned in the embodiments of this application may also be referred to as a system-on-a-chip, system chip, chip system, or system-on-a-chip, etc.
[0217] This application also provides a computer program / program product, which includes computer instructions. The computer program / program product is executed by at least one processor to implement the various processes of the above-described information transmission method embodiments and can achieve the same technical effect. To avoid repetition, it will not be described again here.
[0218] This application also provides a wireless communication system, including: a terminal and a network-side device, wherein the terminal can be used to perform the steps of the information transmission method described above, and the network-side device can be used to perform the steps of the information transmission method described above.
[0219] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element. Furthermore, it should be noted that the scope of the methods and apparatuses in the embodiments of this application is not limited to performing functions in the order shown or discussed, but may also include performing functions substantially simultaneously or in the reverse order, depending on the functions involved. For example, the described methods may be performed in a different order than described, and various steps may be added, omitted, or combined. Additionally, features described with reference to certain examples may be combined in other examples.
[0220] From the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of computer software products plus necessary general-purpose hardware platforms, and of course, they can also be implemented by hardware. The computer software product is stored in a storage medium (such as ROM, RAM, magnetic disk, optical disk, etc.) and includes several instructions to cause the terminal or network-side device to execute the methods described in the various embodiments of this application.
[0221] The embodiments of this application have been described above with reference to the accompanying drawings. However, this application is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other implementations under the guidance of this application without departing from the spirit and scope of the claims. All of these implementations are within the protection scope of this application.
Claims
1. An information transmission method, comprising: The network-side device obtains a message verification code (MAC-I) for integrity, which is associated with the first next-hop link count (NCC). The network-side device sends a handover command to the terminal. The handover command includes first information and second information. The first information includes at least a portion of the MAC-I. The second information is used to indicate the first NCC. The first NCC is used to derive the key of the target candidate cell.
2. The method according to claim 1, wherein, The network-side device obtains the MAC-I message verification code used for integrity, including: Network-side devices calculate MAC-I based on the target key and the target integrity protection algorithm; The target key includes the key used by the terminal in the first cell, and the target integrity protection algorithm includes the integrity protection algorithm used by the terminal in the first cell. The first cell includes at least one of a source serving cell or a candidate cell.
3. The method according to claim 2, wherein, The input parameters of the target integrity protection algorithm include at least one of the following: The first NCC; Target indication, the target indication being used to indicate that the MAC-I is used for switching; Configuration identifier for candidate cells or candidate cell groups; Identification of candidate communities; The signage for the source service community; The terminal's temporary identifier for the cell wireless network within the source serving cell, C-RNTI.
4. The method according to claim 3, wherein, When the first cell is a candidate cell, the input parameters of the target integrity protection algorithm include the identifier of the candidate cell or the configuration identifier of the candidate cell group corresponding to the candidate cell.
5. The method according to any one of claims 1 to 4, wherein, The second information includes any one of the following: The first NCC; The difference between the first NCC and the second NCC, where the second NCC is the NCC stored by the terminal for use in deriving the current serving cell key.
6. The method according to any one of claims 1 to 5, wherein, The network-side device obtains the MAC-I message verification code used for integrity, including: The centralized unit (CU) of the network-side device calculates the MAC-I; The CU of the network-side device sends a target message to the DU of the network-side device. The target message includes the second information and at least one third information. The third information includes at least a portion of the calculated MAC-I, and the first information is at least a portion of the MAC-I corresponding to the target candidate cell in the at least one third information.
7. The method according to claim 6, wherein, When the target message includes at least two third pieces of information, the target message also includes the configuration identifier of the candidate cell or the configuration identifier of the candidate cell group associated with each of the third pieces of information.
8. The method according to claim 6, further comprising: The network-side device or the CU of the network-side device encrypts the third information and the second information. The switching command carries encrypted third and second information, and the encryption process satisfies at least one of the following: Encryption is performed based on the key of the terminal in the source serving cell; Encryption is performed using the encryption algorithm of the terminal in the source serving cell; The lengths of the first NCC and the third information are used as encryption inputs for encryption.
9. An information transmission method, comprising: The terminal receives a handover command from the network-side device. The handover command includes first information and second information. The first information includes at least a portion of the integrity verification code MAC-I. The second information is used to indicate the first next-hop link count (NCC). The first NCC is used to derive the key for the target candidate cell. The terminal performs integrity verification based on the first information; If the integrity verification passes, the terminal performs a mobility handover operation based on the second information.
10. The method according to claim 9, wherein, Before the terminal performs integrity verification based on the first information, the method further includes: The terminal decrypts the first information and the second information. The decryption process includes at least one of the following: Decryption is performed based on the key of the terminal in the source serving cell; Decryption is performed based on the encryption algorithm of the terminal in the source serving cell; Decryption is performed using the length of the first NCC and the first information as decryption input.
11. The method according to claim 9 or 10, wherein, If the integrity verification passes, the terminal performing the mobility handover operation based on the second information includes: If the integrity verification passes, the terminal determines the first NCC based on the second information; The terminal derives the key of the target candidate cell based on the first NCC and performs a mobility handover operation.
12. The method according to any one of claims 9 to 11, wherein, The MAC-I is determined based on a target key and a target integrity protection algorithm, wherein the target key includes the key used by the terminal in the first cell, and the target integrity protection algorithm includes the integrity protection algorithm used by the terminal in the first cell, and the first cell includes at least one of a source serving cell or a candidate cell.
13. The method according to claim 12, wherein, The input parameters of the target integrity protection algorithm include at least one of the following: The first NCC; Target indication, the target indication being used to indicate that the MAC-I is used for switching; Configuration identifier for candidate cells or candidate cell groups; Identification of candidate communities; The signage for the source service community; The terminal's temporary identifier for the cell wireless network within the source serving cell, C-RNTI.
14. The method according to claim 13, wherein, When the first cell is a candidate cell, the input parameters of the target integrity protection algorithm include the identifier of the candidate cell or the configuration identifier of the candidate cell group corresponding to the candidate cell.
15. The method according to any one of claims 9 to 14, wherein, The second information includes any one of the following: The first NCC; The difference between the first NCC and the second NCC, where the second NCC is the NCC stored by the terminal for use in deriving the current serving cell key.
16. An information transmission device, comprising: The first processing module is used for the network-side device to obtain a message verification code MAC-I for integrity, wherein the MAC-I is associated with the first next-hop link count NCC. The sending module is used to send a handover command from the network-side device to the terminal. The handover command includes first information and second information. The first information includes at least a portion of the MAC-I. The second information is used to indicate the first NCC. The first NCC is used to derive the key of the target candidate cell.
17. The apparatus according to claim 16, wherein, The first processing module is specifically used by the network-side device to calculate MAC-I based on the target key and the target integrity protection algorithm; The target key includes the key used by the terminal in the first cell, and the target integrity protection algorithm includes the integrity protection algorithm used by the terminal in the first cell. The first cell includes at least one of a source serving cell or a candidate cell.
18. The apparatus according to claim 16 or 17, wherein, The first processing module is specifically used by the centralized unit (CU) of the network-side device to calculate the MAC-I associated with the NCC; The sending module is specifically used to perform the following operations: the CU of the network-side device sends a target message to the distribution unit DU of the network-side device, the target message including the second information and at least one third information; the third information includes at least a portion of the calculated MAC-I, and the first information is at least a portion of the MAC-I corresponding to the target candidate cell in the at least one third information.
19. An information transmission device, comprising: A receiving module is configured to receive a handover command from a network-side device. The handover command includes first information and second information. The first information includes at least a portion of the integrity verification code MAC-I. The second information is used to indicate a first next-hop link count (NCC). The first NCC is used to derive a key for the target candidate cell. The second processing module is used to perform integrity verification based on the first information; if the integrity verification passes, it performs mobility handover operation based on the second information.
20. The apparatus according to claim 19, wherein, The second processing module is specifically used to determine the first NCC based on the second information when the integrity verification passes; derive the key of the target candidate cell based on the first NCC; and perform a mobility handover operation.
21. A terminal comprising a processor and a memory, the memory storing a program or instructions executable on the processor, the program or instructions, when executed by the processor, implementing the steps of the information transmission method as claimed in any one of claims 9 to 15.
22. A network-side device, comprising a processor and a memory, the memory storing a program or instructions executable on the processor, the program or instructions, when executed by the processor, implementing the steps of the information transmission method as claimed in any one of claims 1 to 8.
23. A readable storage medium storing a program or instructions that, when executed by a processor, implement the steps of the information transmission method as described in any one of claims 1 to 15.
24. A computer program product comprising computer instructions that, when executed by a processor, implement the steps of the information transmission method as described in any one of claims 1 to 15.
Citation Information
Patent Citations
Method and apparatus for communication in next-generation mobile communication system
CN109792347A
Security updating method, network equipment and terminal
CN110830988A
Communication method and device
CN111182539A
Downlink data of small data transmission procedure
WO2022087115A1