Information transmission method and apparatus, and communication device
By coordinating the operation of the target access network equipment and the core network equipment, the problem of security context synchronization during LTM handover was solved, ensuring the security and stability of communication equipment.
Patent Information
- Application Number
- PCT/CN2025/111349
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-07-30
- Filing Date
- 2025-07-30
- Publication Date
- 2026-02-05
Smart Images

Figure CN2025111349_05022026_PF_FP_ABST
Abstract
Description
Information transmission methods, devices and communication equipment
[0001] Cross-references to related applications
[0002] This application claims priority to Chinese Patent Application No. 202411033906.3, filed in China on July 30, 2024, the entire contents of which are incorporated herein by reference. Technical Field
[0003] This application belongs to the field of communication technology, specifically relating to an information transmission method, apparatus, and communication equipment. Background Technology
[0004] Mobility enhancement projects will support Layer 1 or Layer 2-triggered mobility (LTM) between central cells (inter-CUs). Inter-CU handover involves changes in base stations, which raises synchronization issues regarding security contexts (such as algorithms supported by user equipment (UE)), security protection strategies, and keys used).
[0005] However, LTM is triggered by L1 measurements, has a fast handover speed, and assumes that no Radio Resource Control (RRC) reconfiguration messages are sent to the UE during the handover process. Therefore, the UE cannot synchronize the security context with the network side. How to synchronize the security context in LTM scenarios is an urgent problem to be solved. Summary of the Invention
[0006] This application provides an information transmission method, apparatus, and communication device that can achieve secure synchronization in LTM scenarios.
[0007] Firstly, an information transmission method is provided, including:
[0008] The target access network device receives a terminal that triggers a mobility LTM handover access through Layer 1 or Layer 2, and sends a path switching message to the core network device. The path switching message is used to establish a signaling connection between the terminal and the core network device.
[0009] The target access network device receives a path switching confirmation message from the core network device, and the path switching confirmation message contains a first security parameter.
[0010] If the target access network device determines that the security context has lost synchronization based on the first security parameter, it shall perform at least one of the following:
[0011] Interrupt the LTM process of the terminal;
[0012] The security parameters of the terminal of the first access network device are updated. The first access network device includes at least one of the other access network devices, excluding the target access network device, among the access network devices configured for LTM for the terminal.
[0013] Secondly, an information transmission method is provided, including:
[0014] The core network device receives a first path switching message sent by the target access network device. The first path switching message is used to establish a signaling connection between the terminal and the core network device. The first path switching message includes first indication information.
[0015] If the core network device determines that the security context is not synchronized based on the first indication information, it delays the context synchronization with the terminal.
[0016] Thirdly, an information transmission method is provided, including:
[0017] The core network device receives a first message sent by the source access network device. The first message is used to request the core network device to configure the LTM configuration of the terminal. The first message includes second indication information.
[0018] If the core network device determines that the security context is not synchronized based on the second indication information, it shall complete the context synchronization with the terminal in advance.
[0019] Fourthly, an information transmission method is provided, including:
[0020] The terminal receives LTM configuration information sent from the source access network device;
[0021] The terminal receives a handover instruction sent from the source access network device;
[0022] The terminal switches to the target access network device via LTM according to the handover instruction;
[0023] The terminal receives a second RRC reconfiguration message from the target access network device. The second RRC reconfiguration message includes configuration information of a first access network device. The first access network device includes at least one of the other access network devices configured for LTM for the terminal, excluding the target access network device.
[0024] The terminal deduces the access layer key based on the second RRC reconfiguration message.
[0025] Fifthly, an information transmission device is provided, applied to a target access network device, comprising:
[0026] The first sending module is used to receive a path switching message sent by a terminal to the core network equipment through a mobility LTM handover access triggered by a layer 1 or layer 2. The path switching message is used to establish a signaling connection between the terminal and the core network equipment.
[0027] The first receiving module is configured to receive a path handover confirmation message from the core network device, wherein the path handover confirmation message contains a first security parameter.
[0028] The first processing module is configured to perform at least one of the following if, upon determining that the security context has lost synchronization based on the first security parameter:
[0029] Interrupt the LTM process of the terminal;
[0030] The security parameters of the terminal of the first access network device are updated. The first access network device includes at least one of the other access network devices, excluding the target access network device, among the access network devices configured for LTM for the terminal.
[0031] Sixthly, an information transmission device is provided, applied to core network equipment, comprising:
[0032] The second receiving module is used to receive a first path switching message sent by the target access network device. The first path switching message is used to establish a signaling connection between the terminal and the core network device. The first path switching message includes first indication information.
[0033] The second processing module is used to delay context synchronization with the terminal if it is determined from the first indication information that the security context is not synchronized.
[0034] Seventhly, an information transmission device is provided, applied to core network equipment, comprising:
[0035] The third receiving module is used to receive a first message sent by the source access network device. The first message is used to request the core network device to configure the LTM configuration of the terminal. The first message includes second indication information.
[0036] The third processing module is used to complete context synchronization with the terminal in advance if the security context is not synchronized based on the second indication information.
[0037] Eighthly, an information transmission device is provided for use in a terminal, comprising:
[0038] The fourth receiving module is used to receive LTM configuration information sent from the source access network device;
[0039] The fifth receiving module is used to receive a handover instruction sent from the source access network device;
[0040] The fourth processing module is used to switch to the target access network device via LTM according to the handover instruction;
[0041] The sixth receiving module is configured to receive a second RRC reconfiguration message sent from the target access network device. The second RRC reconfiguration message includes configuration information of the first access network device. The first access network device includes at least one of the other access network devices besides the target access network device among the access network devices configured for LTM for the terminal.
[0042] The fifth processing module is used to deduce the access layer key based on the second RRC reconfiguration message.
[0043] Ninth aspect, an information transmission apparatus is provided, the apparatus being configured to perform the steps of the method described in the first aspect, or implement the steps of the method described in the second aspect, or implement the steps of the method described in the third aspect, or implement the steps of the method described in the fourth aspect.
[0044] In a tenth aspect, a communication device is provided, which is a target access network device. The communication device includes a processor and a memory, the memory storing programs or instructions executable on the processor, which, when executed by the processor, implement the steps of the method described in the first aspect.
[0045] Eleventhly, a communication device is provided, which is a target access network device, including a processor and a communication interface, wherein the communication interface is used to receive a path switching message sent by a terminal to a core network device through a Layer 1 or Layer 2 mobility LTM handover access, the path switching message being used to establish a signaling connection between the terminal and the core network device; and to receive a path switching confirmation message from the core network device, the path switching confirmation message including a first security parameter;
[0046] The processor is configured to perform at least one of the following if it is determined that the security context has lost synchronization based on the first security parameter:
[0047] Interrupt the LTM process of the terminal;
[0048] The security parameters of the terminal of the first access network device are updated. The first access network device includes at least one of the other access network devices, excluding the target access network device, among the access network devices configured for LTM for the terminal.
[0049] In a twelfth aspect, a communication device is provided, which is a core network device. The communication device includes a processor and a memory, the memory storing programs or instructions that can run on the processor, the programs or instructions being executed by the processor to implement the steps of the method as described in the second aspect.
[0050] In a thirteenth aspect, a communication device is provided, which is a core network device, including a processor and a communication interface, wherein the communication interface is used to receive a first path switching message sent by a target access network device, the first path switching message is used to establish a signaling connection between a terminal and the core network device, and the first path switching message includes first indication information.
[0051] The processor is configured to delay context synchronization with the terminal if it determines, based on the first indication information, that the security context is not synchronized.
[0052] In a fourteenth aspect, a communication device is provided, which is a core network device, the communication device including a processor and a memory, the memory storing a program or instructions executable on the processor, the program or instructions, when executed by the processor, implementing the steps of the method as described in the third aspect.
[0053] In a fifteenth aspect, a communication device is provided, which is a core network device, including a processor and a communication interface, wherein the communication interface is used to receive a first message sent by a source access network device, the first message being used to request the core network device to configure the LTM configuration of a terminal, and the first message including second indication information.
[0054] The processor is used to perform context synchronization with the terminal in advance if it determines that the security context is not synchronized based on the second indication information.
[0055] In a sixteenth aspect, a communication device is provided, which is a terminal, the communication device including a processor and a memory, the memory storing a program or instructions executable on the processor, the program or instructions, when executed by the processor, implementing the steps of the method as described in the third aspect.
[0056] In a seventeenth aspect, a communication device is provided, which is a terminal, including a processor and a communication interface, wherein the communication interface is used to receive LTM configuration information sent from a source access network device; receive a handover indication sent from the source access network device; and the processor is used to hand over to a target access network device via LTM according to the handover indication.
[0057] The communication interface is used to receive a second RRC reconfiguration message sent from the target access network device. The second RRC reconfiguration message includes configuration information of a first access network device. The first access network device includes at least one of the other access network devices besides the target access network device among the access network devices configured for LTM for the terminal.
[0058] The processor is used to deduce the access layer key based on the second RRC reconfiguration message.
[0059] In an eighteenth aspect, a readable storage medium is provided, on which a program or instructions are stored, which, when executed by a processor, implement the steps of the method described in the first aspect, or the steps of the method described in the second aspect, or the steps of the method described in the third aspect, or the steps of the method described in the fourth aspect.
[0060] In a nineteenth aspect, a wireless communication system is provided, comprising: a target access network device and a terminal, wherein the target access network device is configured to perform the steps of the method described in the first aspect, and the terminal is configured to perform the steps of the method described in the fourth aspect.
[0061] In a twentieth aspect, a wireless communication system is provided, comprising: a target access network device, a source access network device, and a core network device, wherein the core network device is used to perform the steps of the method described in the second or third aspect.
[0062] In a twentieth aspect, a chip is provided, the chip including a processor and a communication interface coupled to the processor, the processor being configured to run programs or instructions to implement the method as described in the first aspect, or the method as described in the second aspect, or the method as described in the third aspect, or the method as described in the fourth aspect.
[0063] In a twenty-second aspect, a computer program / program product is provided, which is stored in a storage medium and is executed by at least one processor to implement the steps of the information transmission method as described in the first, second, third, or fourth aspects.
[0064] In one embodiment of this application, the target access network device can ensure secure synchronization in the LTM scenario and guarantee communication performance by interrupting the LTM process of the terminal or updating the security parameters of the terminal of the first access network device when the security context is out of sync. In another embodiment, the core network device can ensure secure synchronization in the LTM scenario and guarantee communication performance by delaying the context synchronization of the terminal or completing the context synchronization with the terminal in advance when it is determined that the security context is not synchronized. Attached Figure Description
[0065] Figure 1 is a block diagram of a wireless communication system applicable to an embodiment of this application;
[0066] Figure 2 is a flowchart illustrating one of the information transmission methods according to an embodiment of this application;
[0067] Figure 3 is one of the detailed application flow diagrams of an embodiment of this application;
[0068] Figure 4 is a second detailed application flow diagram of an embodiment of this application;
[0069] Figure 5 is a second schematic flowchart of the information transmission method according to an embodiment of this application;
[0070] Figure 6 is a detailed application flow diagram of an embodiment of this application;
[0071] Figure 7 is a third schematic flowchart of the information transmission method according to an embodiment of this application;
[0072] Figure 8 is a fourth detailed application flow diagram of an embodiment of this application;
[0073] Figure 9 is a fourth flowchart illustrating the information transmission method according to an embodiment of this application;
[0074] Figure 10 is a schematic diagram of one of the modules of the information transmission device according to an embodiment of this application;
[0075] Figure 11 is a second schematic diagram of the information transmission device according to an embodiment of this application;
[0076] Figure 12 is a third schematic diagram of the information transmission device according to an embodiment of this application;
[0077] Figure 13 is a fourth schematic diagram of the information transmission device according to an embodiment of this application;
[0078] Figure 14 is a schematic diagram of the structure of a communication device according to an embodiment of this application;
[0079] Figure 15 is a schematic diagram of the structure of the access network device according to an embodiment of this application;
[0080] Figure 16 is a schematic diagram of the core network device according to an embodiment of this application;
[0081] Figure 17 is a schematic diagram of the terminal structure according to an embodiment of this application. Detailed Implementation
[0082] The technical solutions of the embodiments of this application will be clearly described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application are within the scope of protection of this application.
[0083] The terms "first," "second," etc., used in this application are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such terms can be used interchangeably where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first" and "second" are generally of the same class, not limited in number; for example, the first object can be one or more. Furthermore, "or" in this application indicates at least one of the connected objects. For example, the scope of protection for "A or B" covers at least three scenarios: Scenario 1: including A but not B; Scenario 2: including B but not A; Scenario 3: including both A and B. In addition, the terms "A and / or B," "at least one of A and B," and "at least one of A or B" also cover at least the above three scenarios. The character " / " generally indicates that the preceding and following objects are in an "or" relationship.
[0084] The term "instruction" in this application can be either a direct instruction (or explicit instruction) or an indirect instruction (or implicit instruction). A direct instruction can be understood as one in which the sender explicitly informs the receiver of specific information, the operation to be performed, or the requested result, etc., in the instruction sent. An indirect instruction can be understood as one in which the receiver determines the corresponding information based on the instruction sent by the sender, or makes a judgment and determines the operation to be performed or the requested result, etc., based on the judgment result.
[0085] It is worth noting that the technologies described in this application are not limited to Long Term Evolution (LTE) / LTE-Advanced (LTE-A) systems, but can also be used in other wireless communication systems, such as Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single-carrier Frequency-Division Multiple Access (SC-FDMA), or other systems. The terms "system" and "network" in this application are often used interchangeably, and the described technologies can be used in the systems and radio technologies mentioned above, as well as in other systems and radio technologies. The following description describes New Radio (NR) systems for illustrative purposes, and the term NR is used in most of the following description; however, these technologies can also be applied to systems other than NR systems, such as 6th Generation (6G) communication systems.
[0086] Figure 1 shows a block diagram of a wireless communication system applicable to an embodiment of this application. The wireless communication system includes a terminal 11 and a network-side device 12. The terminal 11 can be a mobile phone, tablet computer, laptop computer, notebook computer, personal digital assistant (PDA), handheld computer, netbook, ultra-mobile personal computer (UMPC), mobile internet device (MID), augmented reality (AR), virtual reality (VR) device, robot, wearable device, flight vehicle, vehicle user equipment (VUE), shipboard equipment, pedestrian user equipment (PUE), smart home (home devices with wireless communication capabilities, such as refrigerators, televisions, washing machines, or furniture), game console, personal computer (PC), ATM, or self-service machine, etc. Wearable devices include: smartwatches, smart bracelets, smart headphones, smart glasses, smart jewelry (smart bracelets, smart chains, smart rings, smart necklaces, smart anklets, smart anklets, etc.), smart wristbands, smart clothing, etc. Among these, in-vehicle devices can also be referred to as in-vehicle terminals, in-vehicle controllers, in-vehicle modules, in-vehicle components, in-vehicle chips, or in-vehicle units, etc. It should be noted that the specific type of terminal 11 is not limited in this application embodiment. Network-side equipment 12 may include access network equipment or core network equipment, wherein access network equipment may also be referred to as Radio Access Network (RAN) equipment, radio access network function, or radio access network unit. Access network equipment may include base stations, Wireless Local Area Network (WLAN) access points (APs), or Wireless Fidelity (WiFi) nodes, etc.The term "base station" can be referred to as Node B (NB), Evolved Node B (eNB), Next Generation Node B (gNB), New Radio Node B (NR Node B), Access Point, Relay Base Station (RBS), Serving Base Station (SBS), Base Transceiver Station (BTS), Radio Base Station, Radio Transceiver, Basic Service Set (BSS), Extended Service Set (ESS), Home Node B (HNB), Home Evolved Node B, Transmit / Receive Point (TRP), or any other suitable term in the relevant field, as long as the same technical effect is achieved. The term "base station" is not limited to any specific technical terminology. It should be noted that this application embodiment only uses a base station in an NR system as an example for description and does not limit the specific type of base station.
[0087] Core network equipment, also known as core network nodes, core network functions, or core network elements, includes, but is not limited to, at least one of the following: Mobility Management Entity (MME), Access and Mobility Management Function (AMF), Session Management Function (SMF), User Plane Function (UPF), Policy Control Function (PCF), Policy and Charging Rules Function (PCRF), Edge Application Server Discovery Function (EASDF), Unified Data Management (UDM), Unified Data Repository (UDR), Home Subscriber Server (HSS), Centralized network configuration (CNC), Network Repository Function (NRF), Network Exposure Function (NEF), Local NEF (or L-NEF), and Binding Support. The core network functions include: BSF (Block Network Function), Application Function (AF), Location Management Function (LMF), Gateway Mobile Location Centre (GMLC), and Network Data Analytics Function (NWDAF). It should be noted that this application embodiment only uses core network equipment in the NR system as an example and does not limit the specific type of core network equipment. If the name of the core network equipment mentioned in this application embodiment changes in subsequent protocol versions (e.g., 6G), it will still be within the scope of protection of this application.
[0088] Optionally, the core network equipment can be implemented by one or more functional modules in a single device, or by multiple devices working together; this application does not specifically limit this. It is understood that the aforementioned functional modules can be network elements in hardware devices, software functional modules running on dedicated hardware, or virtualized functional modules instantiated on a platform (e.g., a cloud platform).
[0089] The information transmission method, apparatus, and communication equipment provided in this application will be described in detail below with reference to the accompanying drawings and through some embodiments and application scenarios.
[0090] As shown in Figure 2, this application embodiment provides an information transmission method, including:
[0091] Step 201: The target access network device receives the terminal's access via a Layer 1 or Layer 2 mobility LTM handover and sends a path handover message to the core network device.
[0092] The path switching message is used to establish a signaling connection between the terminal and the core network equipment.
[0093] Optionally, the path switching message can be a Path Switch message.
[0094] Optionally, the LTM handover access refers to: LTM handover aims to shorten terminal handover latency and interruption latency, and improve user experience. It introduces a new mechanism that allows the network to trigger the terminal to obtain the target cell timing advance (TA) through the physical downlink control channel (PDCCH) before cell handover, thereby completing uplink synchronization in advance.
[0095] For example, the UE reports the signal measurement results to the currently connected access network device (it should be noted that the currently connected access network device refers to the source access network device). The currently connected access network device sends a Layer 1 or Layer 2 instruction to the UE based on the signal measurement results, so that the UE switches to the target access network device according to the instruction, thereby realizing LTM handover access.
[0096] Optionally, the path switching message includes source-side security parameters, which include at least one of the following:
[0097] A01. The security capabilities of the source-side terminal are used to indicate the security algorithms supported by the terminal; the security capabilities of the source-side terminal are obtained by the target access network device from the source access network device.
[0098] A02. Source-side user plane security policy: The source-side user plane security policy is used to indicate whether user plane encryption protection or integrity protection of the terminal is enabled; the source-side user plane security policy is obtained by the target access network device from the source access network device.
[0099] Step 202: The target access network device receives a path handover confirmation message from the core network device, the path handover confirmation message containing a first security parameter;
[0100] Optionally, the first security parameter includes at least one of the following:
[0101] A11. The first security capability of the terminal, wherein the first security capability of the terminal is used to indicate the security algorithms supported by the terminal;
[0102] A12. First user plane security policy, wherein the first user plane security policy is used to indicate whether user plane encryption protection or integrity protection of the terminal is enabled;
[0103] A13. Key synchronization indication information, which is used to indicate that a key update is required.
[0104] Optionally, this key synchronization indication information refers to: the non-access stratum key (e.g., Kamf) on the current core network device has changed (possibly due to re-authentication, non-access stratum sequence number (NAS COUNT) flipping, etc.), but the access stratum key (e.g., K) on the access network device has changed. gNB The key is still generated using the old non-access stratum key and has not been updated. Therefore, the non-access stratum key and the access stratum key are out of sync. It is necessary to use the key to synchronize the information and instruct the target access network device so that the target access network device can instruct the terminal to update the access stratum key.
[0105] For example, the key synchronization indication information could be a New Security Context Indicator (NSCI).
[0106] Step 203: If the target access network device determines that the security context has lost synchronization based on the first security parameter, it shall perform at least one of the following:
[0107] A21. Interrupt the LTM process of the terminal;
[0108] It should be noted that in the case of security context loss of synchronization in this embodiment, the terminal is brought back to normal state by interrupting the LTM process of the terminal, thereby avoiding the problem of security loss of synchronization of the terminal in the LTM scenario and ensuring communication performance.
[0109] A22. Update the security parameters of the terminal of the first access network device, wherein the first access network device includes at least one of the other access network devices, excluding the target access network device, among the access network devices configured for LTM for the terminal;
[0110] For example, if the terminal is configured with LTM and access network devices A, B, C, D, and E are configured, where access network device A is the source access network device and access network device B is the target access network device, then the first access network device mentioned in this embodiment includes at least one of access network device A, access network device C, access network device D, and access network device E.
[0111] It should be noted that in the case of security context loss of synchronization in this embodiment, security context synchronization is achieved by updating the security parameters of the terminal of the first access network device, thereby ensuring security synchronization in the LTM scenario and guaranteeing communication performance.
[0112] It should be noted that the core network equipment mentioned in the embodiments of this application can be understood as a functional network element on the core network side used for access and mobility management. For example, the core network equipment can be an Access and Mobility Management Function (AMF). The source access network equipment refers to the access network equipment that the terminal accesses before performing LTM handover, and the target access network equipment refers to the access network equipment that the terminal accesses after performing LTM handover.
[0113] Optionally, the target access network device receives a path switching message from the terminal via LTM handover and sends it to the core network device. This path switching message typically includes the security capabilities currently used by the terminal and the user plane security policy. After receiving the path switching message, the core network device typically performs the following operations:
[0114] Operation 1: Is the security capability of the source terminal the same as the security capability of the terminal stored in the core network device? In different cases, it indicates that the source access network device may have tampered with the security capability of the terminal, causing the security capability of the terminal to be downgraded. Therefore, it is necessary to inform the target access network device of the real security capability of the terminal (i.e., the security capability of the terminal stored in the core network device). That is, the first security capability mentioned above is the terminal security capability stored in the core network device.
[0115] Operation 2: The source-side user plane security policy will be sent by the core network device to the core network device used for session management (e.g., Session Management Function (SMF)). The core network device used for session management will determine whether the source-side user plane security policy is the same as the stored user plane security policy. In different cases, it means that the source access network device may have tampered with the user plane security policy, which may mean that the terminal's user plane security protection is not enabled. Therefore, the core network device used for session management needs to inform the target access network device of the real user plane security policy (i.e., the user plane security policy stored by the core network device used for session management). That is, the first user plane security policy mentioned above is the user plane security policy stored by the core network device used for session management.
[0116] Operation 3: Does the core network device have a new non-access stratum key (i.e., Kamf) but has not yet updated the access stratum key (i.e., KgNB) on the source access network device through the UE context modification message? If so, it means that the non-access stratum key and the access stratum key are not synchronized. Therefore, the core network device needs to inform the terminal that it will carry the key synchronization indication information (NSCI) and the KgNB derived from Kamf (as NH) in the path switch ACK message.
[0117] Optionally, in one implementation, determining the security context out of step based on the first security parameter includes at least one of the following:
[0118] B11. If the first security algorithm determined based on the terminal's first security capability is inconsistent with the target security algorithm, the security context is determined to be out of sync.
[0119] Optionally, the target security algorithm can be understood as the security algorithm currently used by the terminal, that is, the security algorithm used by the terminal when the target access network device receives a path handover confirmation message from the core network device. This target security algorithm is determined by the target access network device based on the security capabilities of the source-side terminal.
[0120] B12. If the security activation state of the first user plane determined according to the first user plane security policy is inconsistent with the security activation state of the target user plane, the security context is out of sync.
[0121] Optionally, the target user plane security activation state can be understood as the user plane security activation state currently used by the terminal, that is, the user plane security activation state used by the terminal when the target access network device receives the path handover confirmation message from the core network device. This target user plane security activation state is determined by the target access network device according to the source-side user plane security policy.
[0122] B13. If the first security parameter includes key synchronization indication information, determine that the security context is out of sync.
[0123] It should be noted that the key synchronization indication information needs to be sent to the target access network device only after the core network device has updated the key. In other words, as long as the first security parameter received by the target access network device includes the key synchronization indication information, it means that the core network device has updated the key. Since the terminal and access network device have not yet performed key synchronization updates, it indicates that there is a loss of security context synchronization.
[0124] Optionally, in this embodiment of the application, the target access network device obtains the first access network device according to the context of the terminal.
[0125] The implementation details of A21 and A22 are explained below.
[0126] 1. Interrupt the LTM process of the terminal.
[0127] Optionally, in one implementation, the specific implementation of interrupting the LTM process of the terminal includes:
[0128] The target access network device sends a terminal context release message to the first access network device, the terminal context release message being used to release the context of the terminal.
[0129] Optionally, the context of the terminal includes LTM configuration information.
[0130] Optionally, the terminal context release message can be a UE context release message.
[0131] It should be noted that by sending a terminal context release message to the first access network device, the first access network device will no longer store the terminal context, meaning that the first access network device can no longer perform LTM handover access for the terminal, thus interrupting the terminal's LTM process.
[0132] Optionally, in one implementation, before interrupting the LTM process of the terminal, the method further includes:
[0133] The target access network device sends a first Radio Resource Control (RRC) reconfiguration message to the terminal. The first RRC reconfiguration message is used to reconfigure the RRC configuration of the terminal on the target access network device.
[0134] Optionally, the first RRC reconfiguration message may include at least one of the following: Key Inference Indication Information (KCI), a first security algorithm determined according to the first security capability of the terminal, and a first user plane security activation indication determined according to the first user plane security policy.
[0135] The key deduction indication information is generated by the target access network device based on the key synchronization indication information. For example, if the target access network device receives the key synchronization indication information, it will include the key deduction indication information in the first RRC reconfiguration message.
[0136] After receiving the first RRC reconfiguration message, the terminal performs at least one of the following actions:
[0137] Action 1: If the first RRC reconfiguration message carries KCI, the terminal derives KgNB (as NH) from Kamf, and then derives the currently used terminal-side access layer key (KgNB*) from NH.
[0138] Action 2: The terminal saves the first security algorithm, and subsequently uses the first security algorithm for RRC or user plane protection.
[0139] Action 3: The terminal saves the first user plane security activation instruction, and subsequently determines whether to enable user plane protection based on the first user plane security activation instruction.
[0140] The following section provides a detailed explanation of the implementation process in the case of using the access network equipment as the base station (e.g., gNB) and the core network equipment as the AMF.
[0141] As shown in Figure 3, the specific implementation process includes:
[0142] Step 30: Configure LTM;
[0143] It should be noted that the source base station (e.g., SgNB) uses a procedure similar to Xn handover or N2 handover to configure LTM, and the UE has saved the configuration information of each candidate base station.
[0144] It should be noted that Xn handover refers to signaling interaction through the Xn interface; N2 handover refers to signaling interaction through the N2 interface.
[0145] Optionally, the specific implementation process of LTM configuration based on a process similar to Xn handover is as follows: The SgNB selects multiple candidate base stations and then sends handover request messages to each candidate base station. The handover request message carries the terminal security capabilities and user plane security policies. The candidate base stations send handover response messages to the SgNB. The SgNB sends RRC reconfiguration messages to the terminal, and the terminal replies with an RRC reconfiguration completion message to each candidate base station. Through the above process, the SgNB obtains the RRC configuration of multiple candidate base stations and sends it to the UE for storage, thereby realizing LTM configuration.
[0146] Optionally, the specific implementation process of LTM configuration, similar to the N2 handover process, is as follows: The SgNB selects multiple candidate base stations and sends a handover request message to the AMF. The AMF performs at least one of the above operations one to three. The AMF sends a handover request message to each candidate base station, which carries terminal security capabilities and user plane security policies. The candidate base stations send a handover request confirmation message to the AMF, which carries RRC reconfiguration information. The AMF sends a handover command to the SgNB, which carries RRC reconfiguration information. The SgNB sends an RRC reconfiguration message to the terminal, and the terminal replies to the SgNB with an RRC reconfiguration completion message. Through the above process, the SgNB obtains the RRC configuration of multiple candidate base stations and sends it to the UE for storage, thereby realizing LTM configuration.
[0147] Step 31: The UE reports the Layer 1 measurement report to the SgNB;
[0148] Step 32: SgNB sends a Layer 1 message to UE based on the measurement report to instruct UE to access target base station 1 (TgNB1).
[0149] Specifically, the UE enables timer configuration based on the Layer 1 message.
[0150] Step 33: The UE sends an access message to TgNB1.
[0151] Step 34: After the UE successfully accesses TgNB1, TgNB1 sends a path switching message to AMF to switch the user plane.
[0152] Optionally, the path switching message typically includes the security capabilities currently used by the terminal and the user plane security policy.
[0153] Step 35: AMF executes the target operation based on the path switching message;
[0154] Optionally, the target operation includes at least one of operations one to three described above.
[0155] Step 36: AMF sends a path switching confirmation message to TgNB1;
[0156] Optionally, the message may contain at least one of the following:
[0157] The terminal's first security capability, first user plane security policy, and key synchronization indication information.
[0158] Step 37, TgNB1 determines whether the security context has lost synchronization;
[0159] Optionally, TgNB1 performs at least one of the following decision-making processes:
[0160] If the first security algorithm determined based on the terminal's first security capability is inconsistent with the target security algorithm, the security context is determined to be out of sync.
[0161] If the security activation state of the first user plane determined according to the first user plane security policy is inconsistent with the security activation state of the target user plane, the security context is determined to be out of sync.
[0162] If the first security parameter includes key synchronization indication information, it is determined that the security context has lost synchronization.
[0163] Step 38: TgNB1 reconfigures the UE's RRC configuration regarding TgNB1;
[0164] Specifically, in the event of a loss of security context synchronization, TgNB1 sends a first RRC reconfiguration message to the UE. This first RRC reconfiguration message may include at least one of the following: Key Inference Indication Information (KCI), a first security algorithm determined based on the terminal's first security capability, and a user plane security activation indication corresponding to the first user plane security activation state determined based on the first user plane security policy. Optionally, this reconfiguration is an intra-cell handover.
[0165] After the terminal is reconfigured, a reconfiguration completion message is sent to TgNB1.
[0166] Step 39: TgNB1 sends a terminal context release message to TgNB2;
[0167] Step 310: TgNB1 sends a terminal context release message to SgNB;
[0168] Specifically, in the event of security context out-of-sync, TgNB1 needs to send a terminal context release message to other candidate base stations configured for LTM (these candidate base stations are within the same equipment range defined by the first access network equipment mentioned above). Alternatively, in the event of security context out-of-sync, and after the RRC reconfiguration in step 38 is completed (optionally), TgNB1 needs to send a terminal context release message to other base stations configured for LTM to trigger the interruption of the UE's LTM process. Specifically, TgNB1 sends a terminal context release message to other candidate base stations according to the current candidate base station configuration. This terminal context release message is used to release the terminal's context, which contains LTM configuration information.
[0169] It should be noted that in continuous LTM scenarios, due to the lack of RRC message exchange, once a security context asynchrony occurs, the network side cannot update the context via RRC messages. Therefore, this implementation interrupts LTM to return to the normal state. In particular, if the target access network device receives terminal security capabilities and user plane security policies from the core network device, it indicates that the source access network device is no longer trustworthy. In this case, the RRC configurations of all candidate access network devices in this LTM may be problematic, thus requiring the release of the context of all candidate base stations to ensure security.
[0170] It should be noted that the other candidate base stations mentioned in the embodiments of this application are equivalent to the first access network device mentioned above.
[0171] II. Update the security parameters of the terminal of the first access network device.
[0172] Optionally, in one implementation, the specific implementation of updating the security parameters of the terminal in the first access network device includes:
[0173] The target access network device sends a terminal context update message to the first access network device. The terminal context update message updates the context of the terminal and includes a second security parameter. This second security parameter includes at least one of the following: the terminal's second security capability, a second user plane security policy, and a key used by the first access network device. Optionally, the second security capability refers to the security capability received by the target access network device from the core network device, such as the terminal's first security capability; the second user plane security policy refers to the user plane security policy received by the target access network device from the core network device, such as the first user plane security policy. The key used by the first access network device is determined by the target access network device based on the NH, the physical cell identifier (PCI) of the first access network device, and the ARFCN-DL of the first access network device.
[0174] Optionally, in one implementation, the specific implementation of updating the security parameters of the terminal in the first access network device further includes:
[0175] The target access network device sends a second RRC reconfiguration message to the terminal. The second RRC reconfiguration message is used to reconfigure the terminal's RRC configuration on the first access network device. The second RRC reconfiguration message includes the configuration information of the first access network device.
[0176] Optionally, if the first security parameter includes key synchronization indication information, the target access network device needs to instruct the terminal to update the access layer key, which can be done in one of the following ways:
[0177] Method 1: By including the reconfiguration of the terminal's RRC configuration and key derivation indication information on the first access network device in the second RRC reconfiguration message.
[0178] Optionally, the key derivation indication information is determined based on the key synchronization indication information in the first security parameter, and the key derivation indication information is used to indicate that a key update is required.
[0179] Optionally, in this implementation, if the first security parameter carries key synchronization indication information, the second RRC reconfiguration message also includes key deduction indication information;
[0180] For example, the second RRC reconfiguration message may include RRC reconfiguration of access network device A and access network device C, as well as a key derivation indication.
[0181] Alternatively, the second RRC reconfiguration message may further include third indication information, wherein the configuration information of the first access network device includes key deduction indication information, and the third indication information is used to instruct the terminal to enable the configuration information of the first access network device.
[0182] It should be noted that upon receiving the third instruction information, the terminal immediately activates the configuration information of the first access network device.
[0183] For example, the second RRC reconfiguration message may include RRC reconfiguration of access network device A and access network device C, as well as a third indication message, wherein the RRC configuration of access network device A includes a key derivation indication message, and the third indication message indicates that the configuration information of access network device A is enabled.
[0184] Optionally, the second RRC reconfiguration message is used to instruct the terminal to perform an intra-cell handover.
[0185] Method 2: Use a different RRC message than the second RRC reconfiguration message to indicate...
[0186] Optionally, if the first security parameter carries key synchronization indication information, the method further includes:
[0187] The target access network device sends a third RRC reconfiguration message to the terminal, which instructs the terminal to update the access layer key.
[0188] Optionally, the third RRC reconfiguration message is used to instruct the terminal to perform an intra-cell handover.
[0189] It should be noted that in this case, an additional RRC message is sent to indicate that the terminal needs to update the access stratum key; optionally, the third RRC reconfiguration message may include key deduction indication information.
[0190] Optionally, in the two implementation methods described above, after obtaining the key deduction indication information, the terminal needs to deduce the access layer key based on the key deduction indication information. Further, the terminal can also save the deduced access layer key into the configuration information of the first access network device.
[0191] The following section provides a detailed explanation of the implementation process in the case of using the access network equipment as the base station and the core network equipment as the AMF.
[0192] As shown in Figure 4, the specific implementation process includes:
[0193] Steps 40-47 are the same as steps 30-37 in Figure 3.
[0194] Step 48: TgNB1 sends a terminal context update message to TgNB2;
[0195] Step 49: After the terminal context update is completed, TgNB2 sends a terminal context update confirmation message to TgNB1.
[0196] Step 410: TgNB1 sends a terminal context update message to SgNB;
[0197] Step 411: After the terminal context update is completed, SgNB sends a terminal context update confirmation message to TgNB1.
[0198] Optionally, in the event of a loss of security context synchronization, TgNB1 needs to update the terminal context of other candidate base stations (including TgNB2 and SgNB). TgNB1 sends a terminal context update message to the other candidate base stations, which includes at least one of the following:
[0199] The terminal's second security capabilities, second user plane security policies, and keys used by other candidate base stations.
[0200] Optionally, TgNB1 can reuse existing handover request or handover request messages to update the terminal context of other candidate base stations.
[0201] Specifically, other candidate base stations update the UE's security context according to the terminal context update message. For example, they update the current UE's security capabilities to the second security capabilities of the UE contained in the terminal context update message; update the current user plane security policy to the second user plane security policy contained in the terminal context update message; and update the current NH to the NH contained in the terminal context update message.
[0202] Other candidate base stations update the terminal context message and regenerate their configuration information. This configuration information may include the second security algorithm and the second user plane security activation indication corresponding to the second user plane security policy.
[0203] The second security algorithm is determined by other candidate base stations based on the UE's second security capabilities. The second user plane security activation indication is determined by other candidate base stations based on the second user plane security policy.
[0204] Step 412, TgNB1 reconfigures the UE's RRC for all candidate base stations.
[0205] Optionally, in the event of a loss of synchronization in the security context, TgNB1 sends a second RRC reconfiguration message to the UE, which contains configuration information for all candidate base stations.
[0206] After receiving the second RRC reconfiguration message, the terminal performs at least one of the following actions:
[0207] Action 1: If the second RRC reconfiguration message carries KCI, the terminal derives KgNB (as NH) from Kamf, and then derives the currently used terminal-side access layer key (KgNB*) from NH.
[0208] Action 2: The terminal saves the first security algorithm, and subsequently uses the first security algorithm for RRC or user plane protection.
[0209] Action 3: The terminal saves the user plane security activation instruction, and subsequently determines whether to enable user plane protection based on the user plane security activation instruction.
[0210] Optionally, for the case where key synchronization indication information is carried in step 45, TgNB1 needs to instruct the UE to update the AS key. The following implementation methods are available:
[0211] Method 1: TgNB1 instructs the UE to update the AS key via a third RRC reconfiguration message. This third RRC reconfiguration message may carry key deduction indication information. This third RRC reconfiguration message can be sent before or after step 410, without restriction. This third RRC reconfiguration can instruct the UE to perform an intra-cell handover.
[0212] Method 2: TgNB1 simultaneously instructs the UE to update the AS key in the second RRC reconfiguration message.
[0213] It should be noted that, in the specific implementation, TgNB1 uses either method one or method two to instruct the UE to update the AS key.
[0214] Optionally, in one case, the configuration information of TgNB1 also includes key deduction indication information, and the second RRC reconfiguration message includes third indication information, which is used to instruct the UE to immediately enable the configuration information sent by TgNB1 so that the UE can re-derive the key used from Kamf according to the key deduction indication information.
[0215] For example, the second RRC reconfiguration message may include RRC reconfiguration of access network device A and access network device C, as well as a third indication message. The RRC configuration of access network device A includes a key derivation indication message, and the third indication message indicates that the configuration information of access network device A should be enabled. The UE immediately enables the RRC reconfiguration of access network device A based on the third indication message, and then re-derives the key used from Kamf based on the key derivation indication message it contains.
[0216] Alternatively, in another case, the second RRC reconfiguration information includes key derivation indication information, which instructs the UE to re-derive the key from Kamf.
[0217] For example, the second RRC reconfiguration message may include RRC reconfigurations for access network device A and access network device C, as well as key deduction indication information. The UE re-derives the key used by the target access network device from Kamf based on the key deduction indication information.
[0218] It should be noted that in continuous LTM scenarios, since there is no interaction of RRC messages, once a security context asynchrony occurs, the network side cannot update the context through RRC messages. This implementation adopts the context update method to update the security context of the UE and the candidate base station in a relatively mild way.
[0219] It should be noted that the embodiments of this application can guarantee secure synchronization in LTM scenarios and ensure communication performance.
[0220] As shown in Figure 5, this application embodiment provides an information transmission method, including:
[0221] Step 501: The core network device receives a first path switching message sent by the target access network device. The first path switching message is used to establish a signaling connection between the terminal and the core network device. The first path switching message includes first indication information.
[0222] Optionally, in one implementation, the first indication information is used to indicate that the terminal is performing an LTM handover. Alternatively, another alternative expression is that the first indication information is used to indicate that security context synchronization cannot be performed.
[0223] Step 502: If the core network device determines that the security context is not synchronized based on the first indication information, it delays the context synchronization with the terminal.
[0224] It should be noted that in this embodiment of the application, the context synchronization with the terminal is delayed when the security context is not synchronized, that is, the security context is not updated during the LTM process, thus avoiding the problem of key synchronization failure in the LTM scenario and the occurrence of security synchronization failure.
[0225] Optionally, the core network equipment mentioned in the embodiments of this application can be understood as a functional network element on the core network side used for access and mobility management. For example, the core network equipment can be an AMF.
[0226] Optionally, the security context not being synchronized includes one of the following:
[0227] C11. The core network device determines that a new non-access stratum key has been generated and the access stratum key has not been updated.
[0228] Alternatively, if the core network device determines that a new non-access stratum key has been generated and has not updated the access stratum key through the terminal context change procedure, the core network device considers the security context to be out of sync or unsynchronized.
[0229] C12. The core network equipment determines that the Non-Access Stratum (NAS) serial number is about to be flipped;
[0230] It should be noted that the non-access stratum sequence number refers to the non-access stratum sequence number currently used by the core network equipment.
[0231] Optionally, the core network device can perform re-authentication in advance based on the upcoming flip of the current NAS COUNT to generate a new non-access stratum key (e.g., Kamf) to determine that the core network device has updated the key. However, since the terminal and access network devices have not yet performed key synchronization updates, it indicates that there is a loss of security context synchronization or that the security context is not synchronized.
[0232] Optionally, the terminal context change procedure involves the core network device sending a terminal context update (UE context modification) request message to the target access network device. This terminal context update request message contains the updated access stratum key.
[0233] Optionally, in one implementation, the delay is synchronized with the context of the terminal, including:
[0234] The core network device sends a first path switching confirmation message to the target access network device. The first path switching confirmation message does not contain key synchronization indication information, which is used to indicate that a key update is required.
[0235] It should be noted that when the core network device sends the first path handover confirmation message to the target access network device, it does not carry key synchronization indication information. Therefore, the target access network device will not update the key, thus avoiding the loss of security context synchronization during the LTM process.
[0236] Optionally, after the core network device sends a first path handover confirmation message to the target access network device, the method further includes:
[0237] The core network device receives a second path switching message from the target access network device;
[0238] If the first indication information is not included in the second path switching message, the core network device sends a second path switching confirmation message to the target access network device, the second path switching confirmation message containing the key synchronization indication information.
[0239] It should be noted that if the second path switching message received by the core network device does not carry the first indication information, it indicates that the terminal is performing a non-LTM handover. In the absence of security context synchronization, if the second path switching confirmation message sent to the target access network device contains key synchronization indication information, the target access network device will update the key based on the key synchronization indication information, thereby achieving delayed synchronization of the security context.
[0240] Optionally, after the core network device sends a first path handover confirmation message to the target access network device, the method further includes:
[0241] The core network device triggers a terminal context change procedure to the target access network device, and the terminal context change procedure is used to update the access layer key of the terminal.
[0242] Optionally, by changing the terminal context, the access layer key of the terminal can be updated, thereby achieving delayed synchronization of the security context.
[0243] The following section provides a detailed explanation of the implementation process in the case of using the access network equipment as the base station and the core network equipment as the AMF.
[0244] As shown in Figure 6, the specific implementation process includes:
[0245] Steps 60-63 are the same as steps 30-33 in Figure 3.
[0246] Step 64: After the UE successfully accesses TgNB1, TgNB1 sends a first path switching message to AMF to establish a signaling connection between the terminal and AMF.
[0247] Optionally, if the UE switches to TgNB1 via LTM, the message contains a first indication information to indicate that the UE is currently switching via LTM, or the first indication information can be used to indicate that security context synchronization cannot be performed.
[0248] Step 65: AMF determines whether a security context synchronization failure has occurred;
[0249] Specifically, if an AMF has a new Kamf, but has not yet updated the AS key (KgNB) on the SgNB through a UE context modification message, the AMF will not send a key synchronization indication message according to the first indication information; alternatively, if the first path switching message does not contain the first indication information, then the key synchronization indication information will be sent.
[0250] Step 66: AMF sends a path switching confirmation message to TgNB1.
[0251] Optionally, in step 67, the AMF triggers a terminal context change procedure to TgNB1, which is used to update the access layer key of the terminal.
[0252] It should be noted that, in this embodiment of the application, compared to the UE security capabilities and UP security policy, the key synchronization indication information is not a security issue, but rather a problem that happens when the key is out of sync. Therefore, the key does not need to be updated immediately, but can be updated after the UE exits LTM mode. This can minimize interruptions and thus reduce the impact on performance.
[0253] As shown in Figure 7, this application embodiment provides an information transmission method, including:
[0254] Step 701: The core network device receives a first message sent by the source access network device. The first message is used to request the core network device to configure the LTM configuration of the terminal. The first message includes second indication information.
[0255] Optionally, the first message can be a HANDOVER REQUIRED message.
[0256] Optionally, in one implementation, the second indication information is used to indicate that the terminal is performing an LTM handover. Alternatively, the second indication information is used to indicate that security context synchronization cannot be performed.
[0257] Step 702: If the core network device determines that the security context is not synchronized based on the second indication information, it shall complete the context synchronization with the terminal in advance.
[0258] It should be noted that in this embodiment, context synchronization with the terminal is completed in advance even when the security context is not synchronized, ensuring that the terminal has achieved security synchronization after LTM configuration and avoiding the occurrence of security synchronization problems in LTM scenarios.
[0259] The core network equipment mentioned in this application embodiment can be understood as a functional network element on the core network side used for access and mobility management. For example, the core network equipment can be an AMF (Active Network Function).
[0260] Optionally, the security context not being synchronized includes one of the following:
[0261] D11. The core network device determines that a new non-access stratum key has been generated and the access stratum key has not been updated.
[0262] Alternatively, if the core network device determines that a new non-access stratum key has been generated and has not updated the access stratum key through the terminal context change procedure, the core network device considers the security context to be out of sync or unsynchronized.
[0263] D12. The core network equipment determines that the non-access stratum sequence number is about to be flipped.
[0264] It should be noted that the non-access stratum sequence number refers to the non-access stratum sequence number currently used by the core network equipment.
[0265] Optionally, the core network device can perform re-authentication in advance based on the upcoming flip of the current NAS COUNT to generate a new non-access stratum key (e.g., Kamf) to determine that the core network device has updated the key. However, since the terminal and access network devices have not yet performed key synchronization updates, it indicates that there is a loss of security context synchronization or that the security context is not synchronized.
[0266] Optionally, the core network device can also perform re-authentication in advance based on the upcoming flip of the current NAS COUNT to generate a new Kamf, in order to determine that the core network device has updated the key. However, since the terminal and access network devices have not yet performed key synchronization updates, it indicates that there is a loss of security context synchronization or that the security context is not synchronized.
[0267] Optionally, the advance completion of context synchronization with the terminal includes:
[0268] The core network device triggers a terminal context change procedure to the source access network device, and the terminal context change procedure is used to update the access layer key of the terminal.
[0269] Optionally, by changing the terminal context, the access layer key of the terminal can be updated, thereby achieving synchronization of the security context.
[0270] Optionally, the method further includes:
[0271] Before the terminal context change process is completed, the configuration of the LTM configuration for the terminal is paused.
[0272] It should be noted that during the LTM configuration process, if the terminal context change process is not completed, the LTM configuration will be paused. The LTM configuration will only continue after the terminal context change process is completed, in order to avoid context loss of synchronization after LTM configuration.
[0273] The following section provides a detailed explanation of the implementation process in the case of using the access network equipment as the base station and the core network equipment as the AMF.
[0274] As shown in Figure 8, the specific implementation process includes:
[0275] Step 81: The source gNB initiates a handover based on the measurement report and sends a handover request message to the AMF via the N2 interface.
[0276] Optionally, if the UE switches to TgNB1 via LTM, the handover request message includes a second indication information to indicate that the UE is currently performing an LTM handover, or the second indication information can be used to indicate that security context synchronization cannot be performed.
[0277] Step 82, AMF determines whether a security context synchronization failure has occurred;
[0278] Step 83: AMF triggers the UE context modification procedure;
[0279] Specifically, if an AMF has a new Kamf, but has not yet updated the AS key (KgNB) on the SgNB through a UE context modification message, the AMF will trigger the UE context modification procedure according to the second indication information. If the handover request message does not contain the second indication information, the key synchronization indication information will be sent according to the first indication information.
[0280] Optionally, the AMF may also suspend the LTM procedure and continue the LTM procedure after the UE context modification procedure. One way to suspend the LTM procedure is for the AMF to temporarily not respond to the HANDOVER REQUIRED message.
[0281] Step 84, LTM configuration process;
[0282] Optionally, the LTM configuration process here can be found in the detailed description of step 30 above, and will not be repeated here.
[0283] Step 85, perform LTM switching;
[0284] Specifically, the UE reports L1 measurements. The SgNB determines from the measurement report that the UE can switch to TgNB1, then uses an L1 message to notify the UE to switch to TgNB1. The UE then enables the RRC configuration of TgNB1 and accesses TgNB1. After successful access to TgNB1, the TgNB initiates a path handover procedure, enabling the AMF to establish a path from the TgNB to core network elements (AMF, UPF).
[0285] It should be noted that, in this embodiment of the application, compared to UE security capabilities and UP security policies, the key synchronization indication information is not a security issue, but rather a problem that happens when the key is out of sync. Therefore, the key does not need to be updated immediately. In the LTM scenario of N2 like-HO, AMF can make the judgment in advance during LTM configuration. Therefore, the key can be synchronized before the UE enters LTM mode, and LTM configuration can be performed later. This can minimize interruptions and reduce the impact on performance.
[0286] Optionally, it should also be noted that the information transmission methods described above for use on the core network equipment side are applied in different implementation processes. These two implementation methods can be used alone or in combination. That is, during the LTM configuration process, the configuration can be paused first to achieve synchronization, and then the LTM configuration can be continued. During the LTM handover process after the LTM configuration is completed, the synchronization can be paused first, and the key synchronization can be performed after exiting LTM, so as to ensure context synchronization in the LTM scenario.
[0287] As shown in Figure 9, this application embodiment provides an information transmission method, including:
[0288] Step 901: The terminal receives LTM configuration information sent from the source access network device;
[0289] Step 902: The terminal receives a handover instruction sent from the source access network device;
[0290] Step 903: The terminal switches to the target access network device via LTM according to the handover instruction;
[0291] Step 904, the terminal receives a second RRC reconfiguration message sent from the target access network device. The second RRC reconfiguration message includes configuration information of a first access network device. The first access network device includes at least one of the other access network devices besides the target access network device among the access network devices configured for LTM for the terminal.
[0292] Step 905: The terminal deduces the access layer key based on the second RRC reconfiguration message.
[0293] Optionally, in one implementation, the configuration information of the first access network device includes key deduction indication information, or the second RRC reconfiguration message further includes key deduction indication information; the key deduction indication information is used to indicate that a key update is required.
[0294] The terminal derives the access layer key based on the second RRC reconfiguration message, including:
[0295] The terminal deduces the access layer key based on the key deduction instruction information.
[0296] Optionally, in one implementation where the configuration information of the first access network device includes key deduction indication information, the second RRC reconfiguration message further includes third indication information, and the method further includes:
[0297] The terminal enables the configuration information of the first access network device according to the third indication information in the second RRC reconfiguration message.
[0298] Optionally, in one implementation, the method further includes:
[0299] The terminal saves the access layer key into the configuration information of the first access network device.
[0300] It should be noted that all descriptions of the terminal side in the above embodiments are applicable to the embodiments of the information transmission method applied to the terminal side, and can achieve the same technical effect, so they will not be repeated here.
[0301] This application provides an information transmission device. As an example, the information transmission device may be a communication device or a component within a communication device, such as a chip. The communication device may be a terminal, a network-side device, or a server, etc. Exemplarily, the terminal may include, but is not limited to, the type of terminal 11 listed above, and the network-side device may include, but is not limited to, the type of network-side device 12 listed above. This application does not impose specific limitations.
[0302] The information transmission device includes a receiving module, a transmitting module, and a processing module. These modules can be implemented in software or hardware. When implemented in hardware, the processing module can be implemented by a processor. For example, the processor can include general-purpose processors, special-purpose processors, such as a Central Processing Unit (CPU), microprocessor, Digital Signal Processor (DSP), Artificial Intelligence (AI) processor, Graphics Processing Unit (GPU), Application Specific Integrated Circuit (ASIC), Network Processor (NP), Field Programmable Gate Array (FPGA), or other programmable logic devices, gate circuits, transistors, discrete hardware components, etc. The receiving and transmitting modules can be implemented by a communication interface, which can include one or more of the following: transceiver, pins, circuits, bus, radio frequency unit, etc.
[0303] Specifically, referring to Figure 10, when the information transmission device is a target access network device or a component within the target access network device, the information transmission device 1000 includes:
[0304] The first sending module 1001 is used to receive a path switching message sent by a terminal to the core network equipment through a mobility LTM handover access triggered by a layer 1 or layer 2. The path switching message is used to establish a signaling connection between the terminal and the core network equipment.
[0305] The first receiving module 1002 is used to receive a path handover confirmation message from the core network device, the path handover confirmation message containing a first security parameter;
[0306] The first processing module 1003 is configured to perform at least one of the following when it is determined that the security context has lost synchronization based on the first security parameter:
[0307] Interrupt the LTM process of the terminal;
[0308] The security parameters of the terminal of the first access network device are updated. The first access network device includes at least one of the other access network devices, excluding the target access network device, among the access network devices configured for LTM for the terminal.
[0309] Optionally, the first security parameter includes at least one of the following:
[0310] The first security capability of the terminal is used to indicate the security algorithms supported by the terminal;
[0311] The first user plane security policy is used to indicate whether user plane encryption protection or integrity protection of the terminal is enabled.
[0312] Key synchronization indication information, which is used to indicate that a key update is required.
[0313] Optionally, determining security context out-of-sync based on the first security parameter includes at least one of the following:
[0314] If the first security algorithm determined based on the terminal's first security capability is inconsistent with the target security algorithm, the security context is determined to be out of sync.
[0315] If the security activation state of the first user plane determined according to the first user plane security policy is inconsistent with the security activation state of the target user plane, the security context is determined to be out of sync.
[0316] If the first security parameter includes key synchronization indication information, it is determined that the security context has lost synchronization.
[0317] Optionally, the first processing module 1003 executes the LTM process that interrupts the terminal, for the purpose of:
[0318] A terminal context release message is sent to the first access network device, the terminal context release message being used to release the context of the terminal.
[0319] Optionally, before interrupting the LTM process of the terminal, the device further includes:
[0320] The second sending module is used to send a first Radio Resource Control (RRC) reconfiguration message to the terminal. The first RRC reconfiguration message is used to reconfigure the RRC configuration of the terminal in the target access network device.
[0321] Optionally, the first processing module 1003 updates the security parameters of the terminal of the first access network device, for the purpose of:
[0322] A terminal context update message is sent to the first access network device. The terminal context update message is used to update the context of the terminal. The terminal context update message includes a second security parameter, which includes at least one of the following: the second security capability of the terminal, a second user plane security policy, and a key used by the first access network device.
[0323] Optionally, updating the security parameters of the terminal in the first access network device is further used for:
[0324] A second RRC reconfiguration message is sent to the terminal. The second RRC reconfiguration message is used to reconfigure the RRC configuration of the terminal in the first access network device. The second RRC reconfiguration message includes the configuration information of the first access network device.
[0325] Optionally, if the first security parameter carries key synchronization indication information, the second RRC reconfiguration message may further include key deduction indication information; or
[0326] The second RRC reconfiguration message also includes third indication information, and the configuration information of the first access network device includes key deduction indication information. The third indication information is used to instruct the terminal to enable the configuration information of the first access network device.
[0327] The key derivation indication information is determined based on the key synchronization indication information in the first security parameter, and the key derivation indication information is used to indicate that a key update is required.
[0328] Optionally, the second RRC reconfiguration message is used to instruct the terminal to perform an intra-cell handover.
[0329] Optionally, if the first security parameter carries key synchronization indication information, the device further includes:
[0330] A third RRC reconfiguration message is sent to the terminal, which instructs the terminal to update the access layer key.
[0331] Optionally, the third RRC reconfiguration message is used to instruct the terminal to perform an intra-cell handover.
[0332] Optionally, the device further includes:
[0333] The sixth processing module is used to obtain the first access network device based on the context of the terminal.
[0334] The information transmission device provided in this application embodiment can implement the various processes implemented in the method embodiment of FIG2 and achieve the same technical effect. To avoid repetition, it will not be described again here.
[0335] Referring to Figure 11, when the information transmission device is a core network device or a component of a core network device, the information transmission device 1100 includes:
[0336] The second receiving module 1101 is used to receive a first path switching message sent by the target access network device. The first path switching message is used to establish a signaling connection between the terminal and the core network device. The first path switching message includes first indication information.
[0337] The second processing module 1102 is used to delay context synchronization with the terminal if it is determined from the first indication information that the security context is not synchronized.
[0338] Optionally, the first indication information is used to indicate whether the terminal triggers a mobility LTM handover for Layer 1 or Layer 2.
[0339] Optionally, the security context is not synchronized, including:
[0340] It has been determined that a new non-access stratum key has been generated and the access stratum key has not been updated; or,
[0341] It has been determined that the non-access stratum sequence number is about to be flipped.
[0342] Optionally, the second processing module 1102 is used for:
[0343] A first path switching confirmation message is sent to the target access network device. The first path switching confirmation message does not contain key synchronization indication information, which is used to indicate that a key update is required.
[0344] Optionally, after the second receiving module 1101 sends a first path handover confirmation message to the target access network device, the apparatus further includes:
[0345] The seventh receiving module is used to receive a second path switching message from the target access network device;
[0346] The third sending module is used to send a second path switching confirmation message to the target access network device when the second path switching message does not include the first indication information. The second path switching confirmation message includes the key synchronization indication information.
[0347] Optionally, after the second receiving module 1101 sends a first path handover confirmation message to the target access network device, the apparatus further includes:
[0348] The seventh processing module is used to trigger a terminal context change procedure to the target access network device, wherein the terminal context change procedure is used to update the access layer key of the terminal.
[0349] The information transmission device provided in this application embodiment can implement the various processes implemented in the method embodiment of FIG5 and achieve the same technical effect. To avoid repetition, it will not be described again here.
[0350] Referring to Figure 12, when the information transmission device is a core network device or a component within a core network device, the information transmission device 1200 includes:
[0351] The third receiving module 1201 is used to receive a first message sent by the source access network device. The first message is used to request the core network device to configure the LTM configuration of the terminal. The first message includes second indication information.
[0352] The third processing module 1202 is used to complete the context synchronization with the terminal in advance if the security context is not synchronized according to the second indication information.
[0353] Optionally, the second indication information is used to indicate whether the terminal triggers a mobility LTM handover for Layer 1 or Layer 2.
[0354] Optionally, the security context is not synchronized, including:
[0355] It has been determined that a new non-access stratum key has been generated and the access stratum key has not been updated; or,
[0356] It has been determined that the non-access stratum sequence number is about to be flipped.
[0357] Optionally, the third processing module 1202 is used for:
[0358] A terminal context change procedure is triggered on the source access network device, the terminal context change procedure being used to update the access layer key of the terminal.
[0359] Optionally, the device further includes:
[0360] The eighth processing module is used to pause configuring the LTM configuration for the terminal before the terminal context change process is completed.
[0361] The information transmission device provided in this application embodiment can implement the various processes implemented in the method embodiment of FIG7 and achieve the same technical effect. To avoid repetition, it will not be described again here.
[0362] Referring to Figure 13, when the information transmission device is a terminal or a component within a terminal, the information transmission device 1300 includes:
[0363] The fourth receiving module 1301 is used to receive LTM configuration information sent from the source access network device;
[0364] The fifth receiving module 1302 is used to receive a handover instruction sent from the source access network device;
[0365] The fourth processing module 1303 is used to switch to the target access network device via LTM according to the handover instruction;
[0366] The sixth receiving module 1304 is configured to receive a second RRC reconfiguration message sent from the target access network device. The second RRC reconfiguration message includes configuration information of the first access network device. The first access network device includes at least one of the other access network devices besides the target access network device among the access network devices configured for LTM for the terminal.
[0367] The fifth processing module 1305 is used to deduce the access layer key based on the second RRC reconfiguration message.
[0368] Optionally, the configuration information of the first access network device includes key deduction indication information, or the second RRC reconfiguration message also includes key deduction indication information; the key deduction indication information is used to indicate that a key update is required.
[0369] The fifth processing module 1305 is used for:
[0370] The access layer key is deduced based on the key deduction indication information.
[0371] Optionally, if the configuration information of the first access network device includes key deduction indication information, the second RRC reconfiguration message further includes third indication information, and the device further includes:
[0372] The ninth processing module is used to enable the configuration information of the first access network device according to the third indication information in the second RRC reconfiguration message.
[0373] Optionally, the device further includes:
[0374] The tenth processing module is used to save the access layer key into the configuration information of the first access network device.
[0375] The information transmission device provided in this application embodiment can implement the various processes implemented in the method embodiment of FIG9 and achieve the same technical effect. To avoid repetition, it will not be described again here.
[0376] Optionally, as shown in FIG14, this application embodiment also provides a communication device 1400, including a processor 1401 and a memory 1402. The memory 1402 stores a program or instructions that can run on the processor 1401. For example, when the communication device 1400 is a target access network device, the program or instructions executed by the processor 1401 implement the various steps of the above-described information transmission method embodiment and achieve the same technical effect. When the communication device 1400 is a core network device, the program or instructions executed by the processor 1401 implement the various steps of the above-described information transmission method embodiment and achieve the same technical effect. When the communication device 1400 is a terminal, the program or instructions executed by the processor 1401 implement the various steps of the above-described information transmission method embodiment and achieve the same technical effect. To avoid repetition, further details are omitted here.
[0377] Specifically, this application embodiment also provides an access network device, which is a target access network device, and can be the information transmission device shown in FIG10. As shown in FIG15, the access network device 1500 includes: an antenna 1501, a radio frequency device 1502, a baseband device 1503, a processor 1504, and a memory 1505. The antenna 1501 is connected to the radio frequency device 1502. In the uplink direction, the radio frequency device 1502 receives information through the antenna 1501 and sends the received information to the baseband device 1503 for processing. In the downlink direction, the baseband device 1503 processes the information to be transmitted and sends it to the radio frequency device 1502, which processes the received information and then transmits it through the antenna 1501.
[0378] The method executed by the network-side device in the above embodiments can be implemented in the baseband device 1503, which includes a baseband processor.
[0379] The baseband device 1503 may include at least one baseband board, on which multiple chips are disposed, as shown in FIG15. One of the chips is, for example, a baseband processor, which is connected to the memory 1505 via a bus interface to call the program in the memory 1505 and execute the network device operation shown in the above method embodiment.
[0380] The communication device may also include a network interface 1506, such as a common public radio interface (CPRI).
[0381] Specifically, the access network device 1500 in this application embodiment further includes: instructions or programs stored in memory 1505 and executable on processor 1504. Processor 1504 calls the instructions or programs in memory 1505 to execute the methods executed by each module shown in FIG8 and achieve the same technical effect. To avoid repetition, it will not be described in detail here.
[0382] This application embodiment also provides a communication device, which is a target access network device, including a processor and a communication interface. The communication interface is used to receive a path switching message sent by a terminal to the core network device through a Layer 1 or Layer 2 triggered mobility LTM handover access. The path switching message is used to establish a signaling connection between the terminal and the core network device.
[0383] Receive a path switching confirmation message from the core network device, the path switching confirmation message containing a first security parameter;
[0384] The processor is configured to perform at least one of the following if, in the event that a security context out of sync is determined based on the first security parameter:
[0385] Interrupt the LTM process of the terminal;
[0386] The security parameters of the terminal of the first access network device are updated. The first access network device includes at least one of the other access network devices, excluding the target access network device, among the access network devices configured for LTM for the terminal.
[0387] Optionally, the first security parameter includes at least one of the following:
[0388] The first security capability of the terminal is used to indicate the security algorithms supported by the terminal;
[0389] The first user plane security policy is used to indicate whether user plane encryption protection or integrity protection of the terminal is enabled.
[0390] Key synchronization indication information, which is used to indicate that a key update is required.
[0391] Optionally, the processor is configured to implement at least one of the following:
[0392] If the first security algorithm determined based on the terminal's first security capability is inconsistent with the target security algorithm, the security context is determined to be out of sync.
[0393] If the security activation state of the first user plane determined according to the first user plane security policy is inconsistent with the security activation state of the target user plane, the security context is determined to be out of sync.
[0394] If the first security parameter includes key synchronization indication information, it is determined that the security context has lost synchronization.
[0395] Optionally, the communication interface is used for:
[0396] A terminal context release message is sent to the first access network device, the terminal context release message being used to release the context of the terminal.
[0397] Optionally, before the processor interrupts the LTM process of the terminal, the communication interface is further used for:
[0398] A first Radio Resource Control (RRC) reconfiguration message is sent to the terminal. The first RRC reconfiguration message is used to reconfigure the RRC configuration of the terminal in the target access network device.
[0399] Optionally, the communication interface is used for:
[0400] A terminal context update message is sent to the first access network device. The terminal context update message is used to update the context of the terminal. The terminal context update message includes a second security parameter, which includes at least one of the following: the second security capability of the terminal, a second user plane security policy, and a key used by the first access network device.
[0401] Optionally, the communication interface is further used for:
[0402] A second RRC reconfiguration message is sent to the terminal. The second RRC reconfiguration message is used to reconfigure the RRC configuration of the terminal in the first access network device. The second RRC reconfiguration message includes the configuration information of the first access network device.
[0403] Optionally, if the first security parameter carries key synchronization indication information, the second RRC reconfiguration message may further include key deduction indication information; or
[0404] The second RRC reconfiguration message also includes third indication information, and the configuration information of the first access network device includes key deduction indication information. The third indication information is used to instruct the terminal to enable the configuration information of the first access network device.
[0405] The key derivation indication information is determined based on the key synchronization indication information in the first security parameter, and the key derivation indication information is used to indicate that a key update is required.
[0406] Optionally, the second RRC reconfiguration message is used to instruct the terminal to perform an intra-cell handover.
[0407] Optionally, if the first security parameter carries key synchronization indication information, the communication interface is further used for:
[0408] A third RRC reconfiguration message is sent to the terminal, which instructs the terminal to update the access layer key.
[0409] Optionally, the third RRC reconfiguration message is used to instruct the terminal to perform an intra-cell handover.
[0410] Optionally, the processor is further configured to:
[0411] The first access network device is obtained based on the context of the terminal.
[0412] Specifically, this application embodiment also provides a core network device, which may be the information transmission device shown in FIG11. As shown in FIG16, the core network device 1600 includes: a processor 1601, a network interface 1602, and a memory 1603. The network interface 1602 is, for example, a common public radio interface (CPRI).
[0413] Specifically, the core network device 1600 in this application embodiment further includes: instructions or programs stored in memory 1603 and executable on processor 1601. Processor 1601 calls the instructions or programs in memory 1603 to execute the methods executed by each module shown in FIG11 and achieve the same technical effect. To avoid repetition, it will not be described in detail here.
[0414] This application embodiment also provides a communication device, which is a core network device, including a processor and a communication interface. The communication interface is used to receive a first path switching message sent by a target access network device. The first path switching message is used to establish a signaling connection between a terminal and the core network device. The first path switching message includes first indication information.
[0415] The processor is configured to delay context synchronization with the terminal if it determines, based on the first indication information, that the security context is not synchronized.
[0416] Optionally, the first indication information is used to indicate whether the terminal triggers a mobility LTM handover for Layer 1 or Layer 2.
[0417] Optionally, the security context is not synchronized, including:
[0418] It has been determined that a new non-access stratum key has been generated and the access stratum key has not been updated; or,
[0419] It has been determined that the non-access stratum sequence number is about to be flipped.
[0420] Optionally, the processor is configured to:
[0421] A first path switching confirmation message is sent to the target access network device. The first path switching confirmation message does not contain key synchronization indication information, which is used to indicate that a key update is required.
[0422] Optionally, after the communication interface sends a first path handover confirmation message to the target access network device, the communication interface is further configured to:
[0423] Receive a second path switching message from the target access network device;
[0424] If the second path switching message does not include the first indication information, a second path switching confirmation message is sent to the target access network device, and the second path switching confirmation message includes the key synchronization indication information.
[0425] Optionally, after the communication interface sends a first path handover confirmation message to the target access network device, the processor is further configured to:
[0426] A terminal context change procedure is triggered on the target access network device, the terminal context change procedure being used to update the access layer key of the terminal.
[0427] Specifically, this application also provides a communication device, which is a core network device. The core network device can be the information transmission device shown in Figure 12. The structure of the core network device is shown in Figure 16, and will not be described again here.
[0428] This application embodiment also provides a communication device, which is a core network device, including a processor and a communication interface. The communication interface is used to receive a first message sent by a source access network device. The first message is used to request the core network device to configure the LTM configuration of the terminal. The first message includes second indication information.
[0429] The processor is used to perform context synchronization with the terminal in advance if it determines that the security context is not synchronized based on the second indication information.
[0430] Optionally, the second indication information is used to indicate whether the terminal triggers a mobility LTM handover for Layer 1 or Layer 2.
[0431] Optionally, the security context is not synchronized, including:
[0432] It has been determined that a new non-access stratum key has been generated and the access stratum key has not been updated; or,
[0433] It has been determined that the non-access stratum sequence number is about to be flipped.
[0434] Optionally, the processor is used to:
[0435] A terminal context change procedure is triggered on the source access network device, the terminal context change procedure being used to update the access layer key of the terminal.
[0436] Optionally, the processor is further configured to:
[0437] Before the terminal context change process is completed, the configuration of the LTM configuration for the terminal is paused.
[0438] Preferably, embodiments of this application also provide a terminal, including a processor, a memory, and a program or instructions stored in the memory and executable on the processor. When the program or instructions are executed by the processor, they implement the various processes of the above-described communication processing method embodiments and achieve the same technical effects. This terminal may be the information transmission device shown in FIG. 7. Specifically, FIG. 17 is a schematic diagram of the hardware structure of a terminal implementing an embodiment of this application.
[0439] The terminal 1700 includes, but is not limited to, at least some of the following components: radio frequency unit 1701, network module 1702, audio output unit 1703, input unit 1704, sensor 1705, display unit 1706, user input unit 1707, interface unit 1708, memory 1709, and processor 1710.
[0440] Those skilled in the art will understand that terminal 1700 may also include a power supply (such as a battery) for powering various components. The power supply can be logically connected to processor 1710 through a power management system, thereby enabling functions such as charging, discharging, and power consumption management through the power management system. The terminal structure shown in Figure 17 does not constitute a limitation on the terminal. The terminal may include more or fewer components than shown, or combine certain components, or have different component arrangements, which will not be elaborated here.
[0441] It should be understood that, in this embodiment, the input unit 1704 may include a graphics processor 17041 and a microphone 17042. The graphics processor 17041 processes image data of still images or videos obtained by an image capture device (such as a camera) in video capture mode or image capture mode. The display unit 1706 may include a display panel 17061, which may be configured in the form of a liquid crystal display, an organic light-emitting diode, or the like. The user input unit 1707 includes at least one of a touch panel 17071 and other input devices 17072. The touch panel 17071 is also called a touch screen. The touch panel 17071 may include a touch detection device and a touch controller. Other input devices 17072 may include, but are not limited to, physical keyboards, function keys (such as volume control buttons, power buttons, etc.), trackballs, mice, and joysticks, which will not be described in detail here.
[0442] In this embodiment, after receiving downlink data from the access network device, the radio frequency unit 1701 can transmit it to the processor 1710 for processing; in addition, the radio frequency unit 1701 can send uplink data to the network-side device. Typically, the radio frequency unit 1701 includes, but is not limited to, antennas, amplifiers, transceivers, couplers, low-noise amplifiers, duplexers, etc.
[0443] The memory 1709 can be used to store software programs or instructions, as well as various data. The memory 1709 may primarily include a first storage area for storing programs or instructions and a second storage area for storing data. The first storage area may store the operating system, application programs or instructions required for at least one function (such as sound playback, image playback, etc.). Furthermore, the memory 1709 may include volatile memory or non-volatile memory, or both. The non-volatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory can be random access memory (RAM), static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct memory bus RAM (DRRAM). The memory 1709 in this embodiment includes, but is not limited to, these and any other suitable types of memory.
[0444] Processor 1710 may include one or more processing units; optionally, processor 1710 integrates an application processor and a modem processor, wherein the application processor mainly handles operations involving the operating system, user interface, and applications, and the modem processor mainly handles wireless communication signals, such as a baseband processor. It is understood that the aforementioned modem processor may also not be integrated into processor 1710.
[0445] The radio frequency unit 1701 is used for:
[0446] Receive LTM configuration information sent from the source access network device;
[0447] Receive a handover instruction sent from the source access network device;
[0448] The processor 1710 is configured to: switch to the target access network device via LTM according to the handover instruction;
[0449] The radio frequency unit 1701 is used for:
[0450] The terminal receives a second RRC reconfiguration message from the target access network device. The second RRC reconfiguration message includes configuration information of a first access network device, which includes at least one of the other access network devices besides the target access network device among the access network devices configured for LTM for the terminal.
[0451] The processor 1710 is used to deduce the access layer key based on the second RRC reconfiguration message.
[0452] Optionally, the configuration information of the first access network device includes key deduction indication information, or the second RRC reconfiguration message also includes key deduction indication information; the key deduction indication information is used to indicate that a key update is required.
[0453] The processor 1710 is used for:
[0454] The access layer key is deduced based on the key deduction indication information.
[0455] Optionally, if the configuration information of the first access network device includes key deduction indication information, the second RRC reconfiguration message further includes third indication information, and the processor 1710 is further configured to:
[0456] The terminal enables the configuration information of the first access network device according to the third indication information in the second RRC reconfiguration message.
[0457] Optionally, the processor 1710 is further configured to:
[0458] The access layer key is saved to the configuration information of the first access network device.
[0459] This application embodiment also provides a communication device, which is a terminal, including a processor and a communication interface, wherein the communication interface is used for:
[0460] Receive LTM configuration information sent from the source access network device;
[0461] Receive a handover instruction sent from the source access network device;
[0462] The processor is configured to: switch to the target access network device via LTM according to the handover instruction;
[0463] The communication interface is used for:
[0464] The terminal receives a second RRC reconfiguration message from the target access network device. The second RRC reconfiguration message includes configuration information of a first access network device, which includes at least one of the other access network devices besides the target access network device among the access network devices configured for LTM for the terminal.
[0465] The processor is used to deduce the access layer key based on the second RRC reconfiguration message.
[0466] Optionally, the configuration information of the first access network device includes key deduction indication information, or the second RRC reconfiguration message also includes key deduction indication information; the key deduction indication information is used to indicate that a key update is required.
[0467] The processor is used for:
[0468] The access layer key is deduced based on the key deduction indication information.
[0469] Optionally, if the configuration information of the first access network device includes key deduction indication information, the second RRC reconfiguration message further includes third indication information, and the processor 1710 is further configured to:
[0470] The terminal enables the configuration information of the first access network device according to the third indication information in the second RRC reconfiguration message.
[0471] Optionally, the processor is further configured to:
[0472] The access layer key is saved to the configuration information of the first access network device.
[0473] This application also provides a readable storage medium storing a program or instructions. When the program or instructions are executed by a processor, they implement the various processes of the above-described information transmission method embodiments and achieve the same technical effects. To avoid repetition, they will not be described again here.
[0474] The processor mentioned above is the processor in the terminal or network-side device described in the above embodiments. The readable storage medium can be non-volatile or non-transient. The readable storage medium can include computer-readable storage media, such as computer read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk.
[0475] This application embodiment also provides a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor. The processor is used to run programs or instructions to implement the various processes of the above-described information transmission method embodiments and can achieve the same technical effect. To avoid repetition, it will not be described again here.
[0476] It should be understood that the chip mentioned in the embodiments of this application may also be referred to as a system-on-a-chip, system chip, chip system, or system-on-a-chip, etc.
[0477] This application also provides a computer program / program product, which is stored in a storage medium and executed by at least one processor to implement the various processes of the above-described information transmission method embodiments, and can achieve the same technical effect. To avoid repetition, it will not be described again here.
[0478] This application also provides a communication system, including: a target access network device and a terminal, wherein the target access network device can be used to perform the steps of the above-described information transmission method, and the terminal can be used to perform the steps of the above-described information transmission method.
[0479] This application also provides a communication system, including: a target access network device, a source access network device, and a core network device, wherein the core network device can be used to perform the steps of the above-described information transmission method.
[0480] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element. Furthermore, it should be noted that the scope of the methods and apparatuses in the embodiments of this application is not limited to performing functions in the order shown or discussed, but may also include performing functions substantially simultaneously or in the reverse order, depending on the functions involved. For example, the described methods may be performed in a different order than described, and various steps may be added, omitted, or combined. Additionally, features described with reference to certain examples may be combined in other examples.
[0481] From the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of computer software products plus necessary general-purpose hardware platforms, and of course, they can also be implemented by hardware. The computer software product is stored in a storage medium (such as ROM, RAM, magnetic disk, optical disk, etc.) and includes several instructions to cause the terminal or network-side device to execute the methods described in the various embodiments of this application.
[0482] The embodiments of this application have been described above with reference to the accompanying drawings. However, this application is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other implementations under the guidance of this application without departing from the spirit and scope of the claims. All of these implementations are within the protection scope of this application.
Claims
1. A method for information transmission, comprising: accepting, by a target access network device, a terminal to perform a layer one or layer two triggered mobility (LTM) handover, and sending, by the target access network device, a path switch message to a core network device, the path switch message being used to establish a signaling connection between the terminal and the core network device; receiving, by the target access network device, a path switch acknowledgement message from the core network device, the path switch acknowledgement message comprising a first security parameter; in a case where it is determined that a security context is out of synchronization according to the first security parameter, performing, by the target access network device, at least one of the following: interrupting an LTM procedure of the terminal; updating a security parameter of the terminal for a first access network device, the first access network device comprising at least one of other access network devices for the terminal configured for LTM except the target access network device.
2. The method of claim 1, wherein, the first security parameter comprising at least one of the following: a first security capability of the terminal, the first security capability of the terminal being used to indicate a security algorithm supported by the terminal; a first user plane security policy, the first user plane security policy being used to indicate whether user plane encryption protection or integrity protection of the terminal is enabled; key synchronization indication information, the key synchronization indication information being used to indicate that key update is needed.
3. The method of claim 2, wherein, the determining that the security context is out of synchronization according to the first security parameter comprising at least one of the following: determining that the security context is out of synchronization if a first security algorithm determined according to the first security capability of the terminal is inconsistent with a target security algorithm; determining that the security context is out of synchronization if a first user plane security activation state determined according to the first user plane security policy is inconsistent with a target user plane security activation state; determining that the security context is out of synchronization if the key synchronization indication information is included in the first security parameter.
4. The method according to any one of claims 1 to 3, wherein, the interrupting the LTM procedure of the terminal comprising: sending, by the target access network device, a terminal context release message to the first access network device, the terminal context release message being used to release a context of the terminal.
5. The method of claim 4, wherein, before the interrupting the LTM procedure of the terminal, the method further comprising: sending, by the target access network device, a first radio resource control (RRC) reconfiguration message to the terminal, the first RRC reconfiguration message being used to reconfigure an RRC configuration of the terminal at the target access network device.
6. The method of any one of claims 1-3, wherein, the updating the security parameter of the terminal for the first access network device comprising: sending, by the target access network device, a terminal context update message to the first access network device, the terminal context update message being used to update a context of the terminal, the terminal context update message comprising a second security parameter, the second security parameter comprising at least one of the following: a second security capability of the terminal, a second user plane security policy, and a key used by the first access network device.
7. The method of claim 6, wherein, the updating the security parameter of the terminal for the first access network device further comprising: The target access network device sends a second RRC reconfiguration message to the terminal, the second RRC reconfiguration message being used for reconfiguring the RRC configuration of the terminal at the first access network device, and the second RRC reconfiguration message comprising the configuration information of the first access network device.
8. The method of claim 7, wherein, In the case that the first security parameter carries the key synchronization indication information, the second RRC reconfiguration message further comprises key derivation indication information; or The second RRC reconfiguration message further comprises third indication information, the configuration information of the first access network device comprises key derivation indication information, and the third indication information is used for instructing the terminal to enable the configuration information of the first access network device. The key derivation indication information is determined according to the key synchronization indication information in the first security parameter, and the key derivation indication information is used for instructing that key update is needed.
9. The method of claim 7, wherein, The second RRC reconfiguration message is used for instructing the terminal to perform intra-cell handover.
10. The method of claim 7, wherein, In the case that the first security parameter carries the key synchronization indication information, the method further comprises: The target access network device sends a third RRC reconfiguration message to the terminal, the third RRC reconfiguration message being used for instructing the terminal to update the access layer key.
11. The method of claim 10, wherein, The third RRC reconfiguration message is used for instructing the terminal to perform intra-cell handover.
12. The method according to any one of claims 1-11, further comprising: The target access network device acquires the first access network device according to the context of the terminal.
13. An information transmission method, comprising: A core network device receives a first path switching message sent by a target access network device, the first path switching message being used for establishing a signaling connection between a terminal and the core network device, and the first path switching message comprising first indication information; In the case that the core network device determines that the security context is not synchronized according to the first indication information, the core network device delays the context synchronization with the terminal.
14. The method of claim 13, wherein, The first indication information is used for instructing that the terminal is layer one or layer two triggered mobility (LTM) handover.
15. The method of claim 13, wherein, The security context is not synchronized, including: The core network device determines that a new non-access layer key has been generated and the access layer key has not been updated; or The core network device determines that the non-access layer sequence number is about to be rolled over.
16. The method of any one of claims 13-15, wherein, The delay of the context synchronization with the terminal comprises: The core network device sends a first path switching confirmation message to the target access network device, and the first path switching confirmation message does not comprise key synchronization indication information, the key synchronization indication information being used for instructing that key update is needed.
17. The method of claim 16, wherein, After the core network device sends the first path switching confirmation message to the target access network device, the method further comprises: The core network device receives a second path switching message from the target access network device; In the case that the second path switching message does not comprise the first indication information, the core network device sends a second path switching confirmation message to the target access network device, and the second path switching confirmation message comprises the key synchronization indication information.
18. The method of claim 16, wherein, After the core network device sends the first path switching confirmation message to the target access network device, the method further includes: The core network device triggers a terminal context change procedure to the target access network device, and the terminal context change procedure is used to update an access layer key of the terminal.
19. An information transmission method, comprising: A core network device receives a first message sent by a source access network device, and the first message is used to request the core network device to configure an LTM configuration of a terminal, and second indication information is included in the first message; The core network device determines that the security context is not synchronized, and completes the context synchronization with the terminal in advance.
20. The method of claim 19, wherein, The second indication information is used to indicate that the terminal triggers a layer one or layer two mobility LTM switching.
21. The method of claim 19, wherein, The security context is not synchronized, including: The core network device determines that a new non-access layer key has been generated, and an access layer key has not been updated; or The core network device determines that a non-access layer sequence number is about to be rolled over.
22. The method of any one of claims 19-21, wherein, The core network device triggers a terminal context change procedure to the source access network device, and the terminal context change procedure is used to update an access layer key of the terminal.
23. The method of claim 22, further comprising: Before the terminal context change procedure is completed, the core network device suspends the configuration of the LTM configuration for the terminal.
24. An information transmission method, comprising: A terminal receives LTM configuration information sent by a source access network device; The terminal receives a switching indication sent by the source access network device; The terminal switches to a target access network device through LTM according to the switching indication; The terminal receives a second RRC reconfiguration message sent by the target access network device, and configuration information of a first access network device is included in the second RRC reconfiguration message, the first access network device including at least one of other access network devices for LTM configured for the terminal except the target access network device; The terminal derives an access layer key according to the second RRC reconfiguration message. The configuration information of the first access network device includes key derivation indication information, or the second RRC reconfiguration message further includes key derivation indication information; 25. The method of claim 24, wherein, The key derivation indication information is used to indicate that key update is required; The terminal derives an access layer key according to the second RRC reconfiguration message, including: The terminal derives an access layer key according to the key derivation indication information. In the case that the configuration information of the first access network device includes key derivation indication information, the second RRC reconfiguration message further includes third indication information, and the method further includes:
26. The method of claim 25, wherein, The terminal enables the configuration information of the first access network device according to the third indication information in the second RRC reconfiguration message.
27. The method of claim 25 or 26, further comprising: The terminal saves the access layer key to the configuration information of the first access network device. 28.An information transmission apparatus applied to a target access network device, the apparatus comprising: a first sending module configured to accept a terminal to access through layer one or layer two triggered mobility (LTM) switching, and send a path switching message to a core network device, the path switching message being used to establish a signaling connection between the terminal and the core network device; a first receiving module configured to receive a path switching confirmation message from the core network device, the path switching confirmation message containing first security parameters; a first processing module configured to, in a case where it is determined that security context is out of synchronization according to the first security parameters, perform at least one of the following: interrupt the LTM procedure of the terminal; update security parameters of the terminal of a first access network device, the first access network device comprising at least one of other access network devices for LTM configured for the terminal except the target access network device. 29.A communication device, which is a target access network device, comprising a processor and a memory, the memory storing programs or instructions executable on the processor, the programs or instructions being executed by the processor to implement steps of the information transmission method according to any one of claims 1 to 12. 30.An information transmission apparatus applied to a core network device, the apparatus comprising: a second receiving module configured to receive a first path switching message sent by a target access network device, the first path switching message being used to establish a signaling connection between a terminal and the core network device, the first path switching message containing first indication information; a second processing module configured to, in a case where it is determined that security context is out of synchronization according to the first indication information, delay context synchronization with the terminal. 31.An information transmission apparatus applied to a core network device, the apparatus comprising: a third receiving module configured to receive a first message sent by a source access network device, the first message being used to request the core network device to configure LTM configuration of a terminal, the first message containing second indication information; a third processing module configured to, in a case where it is determined that security context is out of synchronization according to the second indication information, complete context synchronization with the terminal in advance. 32.A communication device, which is a core network device, comprising a processor and a memory, the memory storing programs or instructions executable on the processor, the programs or instructions being executed by the processor to implement steps of the information transmission method according to any one of claims 13 to 23. 33.An information transmission apparatus applied to a terminal, the apparatus comprising: a fourth receiving module configured to receive LTM configuration information sent by a source access network device; a fifth receiving module configured to receive a switching indication sent by the source access network device; a fourth processing module configured to switch to a target access network device through LTM according to the switching indication. a sixth receiving module, configured to receive a second RRC reconfiguration message sent by the target access network device, wherein the second RRC reconfiguration message comprises configuration information of the first access network device, and the first access network device comprises at least one of the access network devices other than the target access network device, which are configured for the terminal to perform LTM; a fifth processing module, configured to derive an access layer key according to the second RRC reconfiguration message. 34.A communication device, which is a terminal, comprising a processor and a memory, wherein the memory stores programs or instructions executable by the processor, and the programs or instructions, when executed by the processor, implement the steps of the information transmission method according to any one of claims 24 to 27. 35.A readable storage medium, which stores programs or instructions, and the programs or instructions, when executed by a processor, implement the steps of the information transmission method according to any one of claims 1 to 27. 36.A computer program product comprising computer instructions, which, when executed by a processor, implement the steps of the method according to any one of claims 1 to 27.
Citation Information
Patent Citations
Information recording method and device, information receiving method and device, terminal, network equipment and storage medium
CN118077250A
Layer 1 / layer 2 based mobility enhancement
WO2024064333A1