Communication method and apparatus

By using horizontal extrapolation and design without NCC, the key alignment problem in the regenerative satellite architecture was solved, improving the security and reliability of encrypted communication and simplifying the key update process.

WO2026045928A1PCT designated stage Publication Date: 2026-03-05HUAWEI TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/114440
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-08-27
Filing Date
2025-08-13
Publication Date
2026-03-05

AI Technical Summary

Technical Problem

In a regenerative satellite architecture, how can we align the keys used by terminal devices to communicate with different satellites without requiring interactive switching commands, thus ensuring the security of encrypted communication?

Method used

The keys between terminal devices and access network devices are aligned using a horizontal extrapolation approach. By not using NCC and retaining unused NCCs, the core network devices avoid configuring new NCCs. Combined with parameter maintenance on both the terminal device side and the access network device side, the alignment of key updates is ensured.

Benefits of technology

It enhances the security of encrypted communication, simplifies the key update process, reduces the configuration burden on core network equipment, and improves the reliability of communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025114440_05032026_PF_FP_ABST
    Figure CN2025114440_05032026_PF_FP_ABST
Patent Text Reader

Abstract

The present application is applied to a regenerative satellite architecture. Provided are a communication method and apparatus, which can align communication keys between a terminal device and an access network device. The method comprises: receiving first indication information, wherein the first indication information is used for indicating that a first value of next-hop chaining calculation (NCC) corresponding to a first access network device is not used, or the first indication information is used for indicating that the NCC is not configured; and after a terminal device is switched from the first access network device to a second access network device, sending a first message to the second access network device, wherein the first message carries second indication information, and the second indication information is used for indicating the first value of the NCC, or the first message does not carry the configuration of the NCC.
Need to check novelty before this filing date? Find Prior Art

Description

A communication method and apparatus

[0001] Cross-reference to related applications

[0002] This application claims priority to Chinese Patent Application No. 202411193429.7, filed on August 27, 2024, entitled "A Communication Method and Apparatus", the entire contents of which are incorporated herein by reference. Technical Field

[0003] This application relates to the field of communication technology, and in particular to a communication method and apparatus. Background Technology

[0004] Satellite communication boasts advantages such as wide coverage, long communication distance, high reliability, high flexibility, and high throughput. Unaffected by geographical environment, climate conditions, or natural disasters, it has been widely applied in fields such as aviation, maritime, and military communications. Introducing satellites into 5th-Generation (5G) mobile networks can provide communication services to areas difficult to cover by terrestrial networks, such as oceans and forests. This can enhance the reliability of 5G communication, providing more stable and higher-quality communication services for users on trains, airplanes, and other modes of transportation. It can also provide more data transmission resources and support a greater number of connections.

[0005] Regenerated satellites have the functions of access network devices. In the regenerated satellite architecture, a satellite switch with re-sync scenario is introduced. Without interactive switching commands, terminal devices can switch between multiple access network devices. In this scenario, how to align the keys used by the terminal device to communicate with different satellites becomes a problem worth studying. Summary of the Invention

[0006] This application provides a communication method and apparatus that can be used in a regenerative satellite architecture to align the keys used for communication between terminal equipment and access network equipment.

[0007] In a first aspect, this application provides a communication method applicable to the core network device side, comprising: receiving first indication information, wherein the first indication information is used to indicate that a first value of the next-hop chain corresponding to the first access network device for calculating the NCC is not used, or the first indication information is used to indicate that the NCC is not configured; after the terminal device switches from the first access network device to the second access network device, sending a first message to the second access network device, wherein the first message carries second indication information, wherein the second indication information is used to indicate the first value of the NCC; or, the first message does not carry the configuration of the NCC.

[0008] The above design does not use NCC, but adopts horizontal extrapolation to align the keys between terminal devices and access network devices; and the unused NCC is reused in accordance with the design, so that the core network device does not configure a new NCC for the access network device, which facilitates the alignment of subsequent key updates, thereby improving the security of encrypted communication.

[0009] In one possible design, receiving the first indication information includes: receiving a second message from the first access network device before the first access network device initiates a request for the terminal device to switch to the second access network device; wherein the second message includes the first indication information and the identifier of the terminal device.

[0010] In one possible design, receiving the first indication information includes: after the terminal device switches from the first access network device to the second access network device, receiving a third message from the second access network device, the third message including the first indication information and the identifier of the terminal device.

[0011] In one possible design, the first key used for communication between the second access network device and the terminal device is generated based on a second key and the cell information of the second access network device. The second key is the key used for communication between the first access network device and the terminal device. This method of key generation can be understood as horizontal extrapolation.

[0012] Secondly, this application provides a communication method applied to a second access network device, comprising: after a terminal device switches from a first access network device to the second access network device, sending a third message to a core network device, the third message including first indication information and an identifier of the terminal device; wherein the first indication information is used to indicate that a first value of the next-hop chain corresponding to the first access network device for calculating the NCC is not used, or the first indication information is used to indicate that the NCC is not configured; receiving a first message from the core network device, the first message carrying second indication information, the second indication information being used to indicate the first value of the NCC; or, the first message not carrying the configuration of the NCC.

[0013] The above design does not use NCC, but adopts horizontal extrapolation to align the keys between terminal devices and access network devices; and the unused NCC is reused in accordance with the design, so that the core network device does not configure a new NCC for the access network device, which facilitates the alignment of subsequent key updates, thereby improving the security of encrypted communication.

[0014] In one possible design, the method further includes: receiving a fourth message from the first access network device, the fourth message being used to request the terminal device to switch to the second access network device, the fourth message including the first indication information and the identifier of the terminal device.

[0015] In one possible design, the fourth message further includes a first key for communication between the second access network device and the terminal device. This first key is generated based on a second key and cell information of the second access network device. The second key is a key used for communication between the terminal device and the first access network device. This key generation method can be understood as horizontal derivation.

[0016] Thirdly, this application provides a communication method applied to a terminal device, comprising: obtaining a first value of the NCC (Network Control Class) for the next-hop chain corresponding to a first access network device; after m cell handovers, receiving a handover command instructing the terminal device to handover to a third access network device, the handover command including a second value of the NCC; wherein, in the m cell handovers, the nth cell handover instructs the terminal device to handover from the nth access network device to the (n+1)th access network device, m is a positive integer, and n is an integer from 1 to m; when n is 1, the nth access network device is the first access network device; determining a key for communication between the terminal device and the third access network device based on the first value of the NCC, the second value of the NCC, and a first parameter; wherein, the first parameter is determined based on the first value of the NCC, the value of m, and the range of the NCC value.

[0017] In the above design, by maintaining the first parameter on the terminal device side, the number of NCC iterations between the terminal device and the access network device can be aligned, thereby aligning the communication keys used between the terminal device and the access network device, without affecting the normal configuration of NCC by the core network device.

[0018] In one possible design, the value range of the NCC indicates j possible values ​​of the NCC, where j is an integer greater than 1; the method further includes: after performing the nth cell handover, determining the value of the first parameter. Wherein, k indicates the first value of the NCC. This is the floor function. In this design, the first parameter is defined based on the range of NCC values, ensuring that the terminal device can accurately determine the current NCC iteration round number, thereby aligning the keys between the terminal device and the access network device.

[0019] In one possible design, the switching command may also include the first parameter.

[0020] In one possible design, after the terminal device switches to the third access network device, the value of the first parameter is updated to 0.

[0021] In one possible design, the (n+1)th key used for communication between the terminal device and the (n+1)th access network device is determined based on the nth key used when the terminal device communicates with the nth access network device and the cell information of the (n+1)th access network device. This method of key generation can be understood as horizontal derivation.

[0022] Fourthly, this application provides a communication method applied to a second access network device, comprising: receiving a fourth message from a first access network device, the fourth message being used to request a terminal device to switch to the second access network device, the fourth message including a first value of a first parameter and a first value of a second parameter, the values ​​of the first parameter and the second parameter being related to the value range of the next-hop chain's NCC calculation; after the terminal device switches from the first access network device to the second access network device, updating the values ​​of the first parameter and the second parameter; sending a fifth message to a third access network device, the fifth message being used to request the terminal device to switch to the third access network device, the fifth message including a second value of the NCC corresponding to the second access network device and the updated value of the first parameter; wherein, the second value of the NCC and the first parameter are used to determine the key used by the terminal device to communicate with the third access network device.

[0023] In the above design, by maintaining the first and second parameters on the access network device side, the number of NCC iterations between the terminal device and the access network device can be aligned, thereby aligning the communication keys used between the terminal device and the access network device, without affecting the normal configuration of NCC by the core network device.

[0024] In one possible design, if the first value of the second parameter is less than j-1, then the value of the second parameter is updated to the first value of the second parameter plus one, and the value of the first parameter is the first value of the first parameter; if the first value of the second parameter is equal to j-1, then the value of the second parameter is updated to 0, and the value of the first parameter is updated to the first value of the first parameter plus one.

[0025] Fifthly, this application provides a communication method applied to a terminal device, comprising: determining a first value of NCC corresponding to a first access network device; and communicating with the second access network device according to a first key after switching from the first access network device to a second access network device; wherein, if the first value of NCC was not used before switching from the first access network device to the second access network device, the first key is generated based on the first value of NCC and cell information of the second access network device; or, if the first value of NCC was used before switching from the first access network device to the second access network device, the first key is generated based on a second key and cell information of the second access network device, and the second key is used for communication between the terminal device and the first access network device.

[0026] The above design is applied when there is an unused NCC (Network Control Center), and prioritizes vertical derivation to align the keys between the terminal equipment and the access network equipment, which can improve the security of encrypted communication.

[0027] In one possible design, before switching from the first access network device to the second access network device, the method further includes: if switching from the first cell of the first access network device to the second cell of the first access network device, then determining that the first value of the NCC was used before switching from the first access network device to the second access network device; or, if the terminal device does not switch between cells of the first access network device, then determining that the first value of the NCC was not used before switching from the first access network device to the second access network device.

[0028] Sixthly, this application provides a communication method applied to a second access network device, comprising: acquiring time information, the time information being used to indicate the usage time corresponding to each security context in at least one security context of a terminal device; and communicating with the terminal device according to a first security context during a first time period after the terminal device switches from a first access network device to the second access network device; wherein the first security context is a security context used for communication between the first access network device and the terminal device, and the first time period is determined based on the usage time corresponding to the first security context.

[0029] The above design allows terminal devices to switch access network devices without changing the key within a set time period via switch with re-sync, and then change the key after the set time period has expired. This enables the terminal device and the access network device to align the key update time and the updated value, which helps to save the cost of key calculation.

[0030] In one possible design, the method further includes: receiving a fourth message from the first access network device, the fourth message being used to request the terminal device to switch to the second access network device, the fourth message including information for indicating not to update the security context and information for indicating the first security context.

[0031] In one possible design, the method further includes: during the first time period, sending a fifth message to the third access network device, the fifth message being used to request the terminal device to switch to the third access network device; wherein the fifth message includes information indicating that the security context should not be updated and information indicating the first security context. This design supports inter-site handovers without updating the security context during its usage period.

[0032] In one possible design, the method further includes: after the first time period, sending a fifth message to the third access network device, the fifth message being used to request the terminal device to switch to the third access network device; the security context used for communication between the terminal device and the third access network device is different from the first security context. This design supports updating the security context through inter-site handover after the security context's usage time has expired.

[0033] In one possible design, the method further includes: after the first time period, sending a Radio Resource Control (RRC) reconfiguration message to the terminal device. The RRC reconfiguration message includes information indicating a second security context, which is used for communication between the terminal device and the second access network device, and is different from the first security context. This design supports updating the security context via RRC reconfiguration after the security context's usage time has expired.

[0034] In this application, the security context may include a combination of {NH, NCC}, or only NCC, or only NH, or a key used for communication between the terminal device and the access network device, such as an access layer key.

[0035] In a seventh aspect, embodiments of this application provide a communication device, which may be a core network device, a device, module, or chip within the core network device, or a device compatible with the core network device. In one design, the communication device may include modules corresponding to the methods / operations / steps / actions described in the first aspect. These modules may be hardware circuits, software, or a combination of hardware circuits and software. In another design, the communication device may include a processing module and a communication module, the communication module including a transmitting unit and a receiving unit. Optionally, the processing module may also be described as a processing unit.

[0036] The communication module, under the control of the processing module, performs the following operations:

[0037] Receive first indication information, the first indication information being used to indicate that the first value of the next-hop chain corresponding to the first access network device for calculating the NCC is not used, or the first indication information being used to indicate that the NCC is not configured;

[0038] After the terminal device switches from the first access network device to the second access network device, it sends a first message to the second access network device. The first message carries second indication information, which is used to indicate the first value of the NCC; or, the first message does not carry the configuration of the NCC.

[0039] In one possible design, the communication module is specifically configured to receive a second message from the first access network device before the first access network device initiates a request for the terminal device to switch to the second access network device; wherein the second message includes the first indication information and the identifier of the terminal device.

[0040] In one possible design, the communication module is specifically configured to receive a third message from the second access network device after the terminal device switches from the first access network device to the second access network device, the third message including the first indication information and the identifier of the terminal device.

[0041] In one possible design, the first key used for communication between the second access network device and the terminal device is generated based on a second key and the cell information of the second access network device. The second key is the key used for communication between the first access network device and the terminal device. This method of key generation can be understood as horizontal extrapolation.

[0042] Eighthly, embodiments of this application provide a communication device, which may be a second access network device, or a device, module, or chip within the second access network device, or a device compatible with the second access network device. In one design, the communication device may include modules corresponding to the methods / operations / steps / actions described in the second aspect. These modules may be hardware circuits, software, or a combination of hardware circuits and software. In another design, the communication device may include a processing module and a communication module, the communication module including a transmitting unit and a receiving unit. Optionally, the processing module may also be described as a processing unit.

[0043] The communication module, under the control of the processing module, performs the following operations:

[0044] After the terminal device switches from the first access network device to the second access network device, it sends a third message to the core network device. The third message includes first indication information and the identifier of the terminal device. The first indication information is used to indicate that the first value of the NCC calculation for the next hop chain corresponding to the first access network device is not used, or the first indication information is used to indicate that the NCC is not configured.

[0045] Receive a first message from the core network device, the first message carrying second indication information, the second indication information being used to indicate a first value of the NCC; or, the first message not carrying the configuration of the NCC.

[0046] In one possible design, the communication module is further configured to receive a fourth message from the first access network device, the fourth message being used to request the terminal device to switch to the second access network device, the fourth message including the first indication information and the identifier of the terminal device.

[0047] In one possible design, the fourth message further includes a first key for communication between the second access network device and the terminal device. This first key is generated based on a second key and cell information of the second access network device. The second key is a key used for communication between the terminal device and the first access network device. This key generation method can be understood as horizontal derivation.

[0048] Ninthly, embodiments of this application provide a communication device, which may be a terminal device, a device, module, or chip within the terminal device, or a device compatible with the terminal device. In one design, the communication device may include modules corresponding to the methods / operations / steps / actions described in the third aspect. These modules may be hardware circuits, software, or a combination of hardware circuits and software. In another design, the communication device may include a processing module and a communication module, the communication module including a transmitting unit and a receiving unit. Optionally, the processing module may also be described as a processing unit.

[0049] The processing module is used to obtain the first value of the NCC for the next-hop chain corresponding to the first access network device;

[0050] The communication module is configured to receive a handover command instructing the terminal device to handover to a third access network device after m cell handovers, wherein the handover command includes a second value of the NCC; wherein the nth cell handover in the m cell handovers instructs the terminal device to handover from the nth access network device to the (n+1)th access network device, where m is a positive integer and n is an integer from 1 to m; when n is 1, the nth access network device is the first access network device;

[0051] The processing module is further configured to determine a key for communication between the terminal device and the third access network device based on the first value of the NCC, the second value of the NCC, and the first parameter; wherein the first parameter is determined based on the first value of the NCC, the value of m, and the value range of the NCC.

[0052] In one possible design, the value range of the NCC indicates j possible values ​​of the NCC, where j is an integer greater than 1; the method further includes: after performing the nth cell handover, determining the value of the first parameter. Wherein, k indicates the first value of the NCC. This is the floor symbol.

[0053] In one possible design, the switching command may also include the first parameter.

[0054] In one possible design, after the terminal device switches to the third access network device, the value of the first parameter is updated to 0.

[0055] In one possible design, the (n+1)th key used for communication between the terminal device and the (n+1)th access network device is determined based on the nth key used when the terminal device communicates with the nth access network device and the cell information of the (n+1)th access network device. This method of key generation can be understood as horizontal derivation.

[0056] In a tenth aspect, embodiments of this application provide a communication device, which may be a second access network device, or a device, module, or chip within the second access network device, or a device compatible with the second access network device. In one design, the communication device may include modules corresponding to the methods / operations / steps / actions described in the fourth aspect. These modules may be hardware circuits, software, or a combination of hardware circuits and software. In another design, the communication device may include a processing module and a communication module, the communication module including a transmitting unit and a receiving unit. Optionally, the processing module may also be described as a processing unit.

[0057] A communication module is used to receive a fourth message from a first access network device. The fourth message is used to request a terminal device to switch to the second access network device. The fourth message includes a first value of a first parameter and a first value of a second parameter. The values ​​of the first parameter and the second parameter are related to the range of values ​​for calculating the NCC of the next hop link.

[0058] The processing module is configured to update the values ​​of the first parameter and the second parameter after the terminal device switches from the first access network device to the second access network device.

[0059] The communication module is further configured to send a fifth message to a third access network device, the fifth message being used to request the terminal device to switch to the third access network device, the fifth message including a second value of the NCC corresponding to the second access network device and an updated value of the first parameter; wherein, the second value of the NCC and the first parameter are used to determine the key used by the terminal device to communicate with the third access network device.

[0060] In one possible design, the processing module is further configured to: if the first value of the second parameter is less than j-1, then update the value of the second parameter to the first value of the second parameter plus one, and the value of the first parameter to the first value of the first parameter; if the first value of the second parameter is equal to j-1, then update the value of the second parameter to 0, and update the value of the first parameter to the first value of the first parameter plus one.

[0061] Eleventhly, embodiments of this application provide a communication device, which may be a terminal device, a device, module, or chip within the terminal device, or a device compatible with the terminal device. In one design, the communication device may include modules corresponding to the methods / operations / steps / actions described in the fifth aspect. These modules may be hardware circuits, software, or a combination of hardware circuits and software. In another design, the communication device may include a processing module. Optionally, the processing module may also be described as a processing unit.

[0062] The processing module is configured to determine the first value of the NCC (Neural Code Control) for the next-hop chain corresponding to the first access network device; and to communicate with the second access network device according to a first key after switching from the first access network device to the second access network device; wherein, if the first value of the NCC was not used before switching from the first access network device to the second access network device, the first key is generated based on the first value of the NCC and the cell information of the second access network device; or, if the first value of the NCC was used before switching from the first access network device to the second access network device, the first key is generated based on a second key and the cell information of the second access network device, and the second key is used for communication between the terminal device and the first access network device.

[0063] The above design is applied when there is an unused NCC (Network Control Center), and prioritizes vertical derivation to align the keys between the terminal equipment and the access network equipment, which can improve the security of encrypted communication.

[0064] In one possible design, the processing module is further configured to: determine that the first value of the NCC was used before switching from the first access network device to the second access network device if the terminal device switches from the first cell of the first access network device to the second cell of the first access network device; or determine that the first value of the NCC was not used before switching from the first access network device to the second access network device if the terminal device does not switch between cells of the first access network device.

[0065] In a twelfth aspect, this application provides a communication method. The communication device can be a second access network device, or a device, module, or chip within the second access network device, or a device compatible with the second access network device. In one design, the communication device may include modules corresponding to the methods / operations / steps / actions described in the sixth aspect. These modules can be hardware circuits, software, or a combination of hardware circuits and software. In another design, the communication device may include a processing module and a communication module, the communication module including a transmitting unit and a receiving unit. Optionally, the processing module may also be described as a processing unit.

[0066] A communication module is used to acquire time information, the time information being used to indicate the usage time corresponding to each security context in at least one security context of the terminal device;

[0067] The processing module is configured to communicate with the terminal device according to a first security context during a first time period after the terminal device switches from the first access network device to the second access network device; wherein the first security context is a security context used for communication between the first access network device and the terminal device, and the first time period is determined based on the usage time corresponding to the first security context.

[0068] In one possible design, the communication module is further configured to receive a fourth message from the first access network device, the fourth message being used to request the terminal device to switch to the second access network device, the fourth message including information for indicating not to update the security context and information for indicating the first security context.

[0069] In one possible design, the communication module is further configured to send a fifth message to the third access network device during the first time period, the fifth message being used to request the terminal device to switch to the third access network device; wherein the fifth message includes information for indicating not to update the security context and information for indicating the first security context.

[0070] In one possible design, the communication module is further configured to send a fifth message to the third access network device after the first time period, the fifth message being used to request the terminal device to switch to the third access network device; the security context for communication between the terminal device and the third access network device is different from the first security context.

[0071] In one possible design, the communication module is further configured to send a Radio Resource Control (RRC) reconfiguration message to the terminal device after the first time period. The RRC reconfiguration message includes information indicating a second security context, which is used for communication between the terminal device and the second access network device, and is different from the first security context.

[0072] In a thirteenth aspect, this application provides a communication device including at least one processor and a memory; the memory is used to store computer programs or instructions, and when the device is running, the at least one processor executes the computer program or instructions to cause the communication device to perform the methods as described in the first aspect or various designs of the first aspect above, or perform the methods as described in the second aspect or various designs of the second aspect above, or perform the methods as described in the third aspect or various designs of the third aspect above, or perform the methods as described in the fourth aspect or various designs of the fourth aspect above, or perform the methods as described in the fifth aspect or various designs of the fifth aspect above, or perform the methods as described in the sixth aspect or various designs of the sixth aspect above.

[0073] In a fourteenth aspect, this application provides another communication device, comprising: a logic circuit and an input / output interface; wherein the input / output interface can be understood as an interface circuit, and the logic circuit can be used to run code instructions to perform the methods of the first aspect or the various designs of the first aspect described above, or to perform the methods of the second aspect or the various designs of the second aspect described above, or to perform the methods of the third aspect or the various designs of the third aspect described above, or to perform the methods of the fourth aspect or the various designs of the fourth aspect described above, or to perform the methods of the fifth aspect or the various designs of the fifth aspect described above, or to perform the methods of the sixth aspect or the various designs of the sixth aspect described above.

[0074] In a fifteenth aspect, this application also provides a computer-readable storage medium storing computer-readable instructions that, when executed on a computer, cause the computer to perform a method as described in the first aspect or the various designs of the first aspect above, or to perform a method as described in the second aspect or the various designs of the second aspect above, or to perform a method as described in the third aspect or the various designs of the third aspect above, or to perform a method as described in the fourth aspect or the various designs of the fourth aspect above, or to perform a method as described in the fifth aspect or the various designs of the fifth aspect above, or to perform a method as described in the sixth aspect or the various designs of the sixth aspect above.

[0075] In a sixteenth aspect, this application provides a computer program product containing instructions that, when run on a computer, causes the computer to perform the methods described in the first aspect or the various designs of the first aspect, or the methods described in the second aspect or the various designs of the second aspect, or the methods described in the third aspect or the various designs of the third aspect, or the methods described in the fourth aspect or the various designs of the fourth aspect, or the methods described in the fifth aspect or the various designs of the fifth aspect, or the methods described in the sixth aspect or the various designs of the sixth aspect.

[0076] In a seventeenth aspect, this application provides a chip system including a processor and further including a memory for implementing methods as described in the first aspect or various designs of the first aspect above, or methods as described in the second aspect or various designs of the second aspect above, or methods as described in the third aspect or various designs of the third aspect above, or methods as described in the fourth aspect or various designs of the fourth aspect above, or methods as described in the fifth aspect or various designs of the fifth aspect above, or methods as described in the sixth aspect or various designs of the sixth aspect above.

[0077] Eighteenthly, this application provides a communication system, the system including a terminal device, an access network device, and a core network device, the communication system being used to perform the methods as described in the first aspect or the various designs of the first aspect above, or to perform the methods as described in the second aspect or the various designs of the second aspect above, or to perform the methods as described in the third aspect or the various designs of the third aspect above, or to perform the methods as described in the fourth aspect or the various designs of the fourth aspect above, or to perform the methods as described in the fifth aspect or the various designs of the fifth aspect above, or to perform the methods as described in the sixth aspect or the various designs of the sixth aspect above.

[0078] For the technical effects that can be achieved in aspects seven through eighteen above, please refer to the description of the technical effects that can be achieved by the corresponding possible design schemes in aspects one through six above. This application will not repeat these descriptions. Attached Figure Description

[0079] Figures 1a, 1b, 1c, 1d, and 1e are schematic diagrams of the architecture of the communication system provided in this application.

[0080] Figure 2 is a schematic diagram of the architecture of the open wireless access network provided in an embodiment of this application;

[0081] Figure 3 is a schematic diagram of the protocol stack of the Xn interface provided in an embodiment of this application;

[0082] Figure 4 is a schematic diagram of key generation for vertical and horizontal deduction.

[0083] Figures 5 to 11 are schematic flowcharts of the communication method provided in the embodiments of this application;

[0084] Figure 12 is a schematic diagram of one of the communication devices provided in the embodiments of this application;

[0085] Figure 13 is one of the structural schematic diagrams of the communication device provided in the embodiments of this application. Detailed Implementation

[0086] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the embodiments of this application will be further described in detail below with reference to the accompanying drawings.

[0087] The at least one item mentioned in the embodiments of this application refers to one or more items. Multiple items refers to two or more items. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone. The character " / " generally indicates that the preceding and following related objects have an "or" relationship. Furthermore, it should be understood that although the terms "first," "second," etc., may be used to describe objects in the embodiments of this application, these objects should not be limited to these terms. These terms are only used to distinguish the objects from each other.

[0088] The terms "comprising" and "having," and any variations thereof, used in the following description of embodiments of this application are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally include other steps or units not listed, or may optionally include other steps or units inherent to these processes, methods, products, or devices. It should be noted that in embodiments of this application, words such as "exemplary" or "for example" are used to indicate examples, illustrations, or descriptions. Any method or design described as "exemplary" or "for example" in embodiments of this application should not be construed as preferred or advantageous over other methods or designs. Specifically, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner.

[0089] The embodiments of this application can be applied to terrestrial networks (TN) and non-terrestrial networks (NTN), such as satellite networks. As one possible application scenario, satellites can be classified according to their altitude, i.e., their orbital altitude, into highly elliptical orbit (HEO) satellites, geosynchronous orbit (GEO) satellites, medium Earth orbit (MEO) satellites, and low Earth orbit (LEO) satellites.

[0090] The technical solution of this application can be applied to various wireless communication systems, including but not limited to fourth-generation (4G) systems (also known as long-term evolution (LTE) systems), fifth-generation (5G) systems (also known as new radio (NR) systems), or next-generation mobile communication systems, future communication systems, or other similar communication systems, etc., without any specific limitations.

[0091] Furthermore, the embodiments of this application can be applied to device-to-device (D2D) scenarios, such as NR-D2D scenarios, or to vehicle-to-everything (V2X) scenarios, such as NR-V2X scenarios. The embodiments of this application can also be applied to fields such as intelligent driving, assisted driving, intelligent connected vehicles, or factory manufacturing scenarios.

[0092] Figures 1a, 1b, 1c, and 1d are schematic diagrams of the architecture of a communication system applicable to the embodiments of this application. This application uses a satellite network as an example, but it can be extended to other non-terrestrial networks. According to their operating modes, satellites are generally divided into two types:

[0093] One approach is transparent, where the satellite relays the radio frequency signals between the terminal equipment and the ground-based access network equipment. Figure 1a illustrates a transparent satellite architecture (RAN architecture with transparent satellite). Here, RAN refers to the radio access network. The satellite's role is radio frequency filtering, frequency conversion, and amplification; essentially, the satellite primarily acts as a Layer 1 relay, regenerating physical layer signals and not involving any higher protocol layers. The satellite communicates with the ground-based NTN gateway via radio signals, and the gateway is connected to the ground-based access network equipment via a wired connection. The terminal equipment accesses the access network equipment via an air interface. The satellite and the ground-based gateway relay the signals between the terminal equipment and the ground-based access network equipment. The access network equipment connects to the core network, and the core network communicates with the data network (DN). Optionally, the aforementioned gateway can be an NTN gateway, which can also be described as a gateway; the ground-based gateway can also be described as a ground station. In this architecture, the satellite can be understood as a remote radio unit (RRU) of the access network equipment. The satellite can provide simple physical signal coverage, but the function of radio remote transmission needs to go through the gateway station and the microwave link between the satellite and the gateway station to reach the satellite. In this process, no protocol layer processing is involved and no logical interface is established.

[0094] Another type is the regenerative form, where the satellite possesses all or part of the functions of the access network equipment; that is, the access network equipment or some of its functions are deployed on the satellite. As shown in Figure 1b, in a regenerative satellite architecture without an inter-satellite link (ISL), the satellite possesses the functions of the access network equipment, such as all protocol layer processing functions. The satellite transmits data back to the ground gateway station via microwave, and the gateway station is connected to the core network via a wired connection. The link between the satellite and the gateway station is generally referred to as the satellite radio interface (SRI) or feeder link. As shown in Figure 1c, in a regenerative satellite architecture with an inter-satellite link, the satellite possesses the functions of the access network equipment, such as all protocol layer processing functions. This architecture has an inter-satellite link (ISL), supporting Xn interface communication between satellites based on the ISL. Optionally, when a satellite is not visible to the ground gateway station, that satellite can establish Xn interface communication with other satellites via the ISL and transmit its data back to the ground via those other satellites. As shown in Figure 1d, this regenerative satellite architecture features distributed unit (DU) processing capabilities for access network equipment. In this architecture, the access network equipment can be viewed as a separate architecture for the central unit (CU) and DU, with the satellite possessing the DU functionality of the access network equipment. As illustrated in Figure 1e, the aforementioned CU includes a control plane (CP) and a user plane (UP). The CU-CP includes the radio resource control (RRC) layer and the packet data convergence protocol (PDCP)-C layer. The CU-UP includes the service data adaptation protocol (SDAP) layer and the PDCP-U layer. The DU includes the radio link control (RLC) layer, the medium access control (MAC) layer, and the physical (PHY) layer. Furthermore, in one possible implementation, based on the regenerative satellite architecture illustrated in Figure 1d, the satellite, in addition to its DU (Dedicated Unit) function, also possesses mobile termination (MT) functionality. Such a satellite can also be understood as an integrated access and backhaul (IAB) node. The satellite can utilize the air interface between the MT and the ground access network equipment for backhaul, eliminating the need to establish a separate microwave backhaul link between the satellite and the gateway station.

[0095] Terminal equipment accesses the access network equipment via an air interface. The access network equipment is deployed on a satellite and connects to the core network deployed on the ground via a gateway station. The core network communicates with the data network (DN). The gateway station is responsible for forwarding signaling and service data between the satellite access network equipment and the core network. Communication between the access network equipment and the gateway station occurs via an NG interface.

[0096] Figure 2 is a schematic diagram of the architecture of an open radio access network (O-RAN) communication system applicable to the embodiments of this application. In this system, the access network equipment can be viewed as a separate architecture of CU and DU. The regenerating satellite has all the functions of the access network equipment, and the CU and DU communicate with each other through the F1 interface. The RAN intelligent controller (RIC) is used to collect network information and perform network optimization tasks. The RIC communicates with the access network equipment (satellite) through the E2 interface, and the RIC can interface with both the CU and DU. In the O-RAN communication system, the CU can also be called O-CU, and the DU can also be called O-DU.

[0097] The functions of some of these network elements are briefly introduced below.

[0098] A terminal device, also known as user equipment (UE), is a device with wireless transceiver capabilities. It can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; it can also be deployed on water (such as on ships); and it can be deployed in the air (e.g., on airplanes, balloons, and satellites). Terminal devices can be mobile phones, tablets, computers with wireless transceiver capabilities, virtual reality (VR) terminals, augmented reality (AR) terminals, wireless terminals in industrial control, wireless terminals in self-driving vehicles, wireless terminals in remote medical care, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, wireless terminals in smart homes, etc. The embodiments in this application do not limit the specific technologies or device forms used in the terminal devices.

[0099] The access network equipment in this application is a device that provides wireless communication functions for terminal devices. Access network equipment is also referred to as RAN equipment. The RAN equipment in this application includes, but is not limited to: next-generation base stations (g node B, gNB), evolved node B (eNB), radio network controller (RNC), node B (NB), base station controller (BSC), base transceiver station (BTS), home base station (e.g., home evolved node B, or home node B, HNB), baseband unit (BBU), transmitting and receiving point (TRP), transmitting point (TP), mobile switching center, etc. In systems employing different wireless access technologies, the names of devices with base station functions may vary. For example, in 5th generation (5G) systems, they are called RAN or gNB (5G NodeB); in LTE systems, they are called evolved NodeB (eNB or eNodeB); and in 3rd generation (3G) systems, they are called Node B, etc.

[0100] A Data Network (DN) can deploy various services, providing data and / or voice services to terminal devices. For example, a DN might be the private network of a smart factory. Sensors installed in the workshop can act as terminal devices. The DN deploys both sensors and a control server, with the control server providing services to the sensors. Sensors can communicate with the control server, receive instructions, and transmit collected sensor data accordingly. Another example is a DN serving as an internal office network for a company. Employees' mobile phones or computers can act as terminal devices, accessing information and data resources within the company's internal network.

[0101] The core network portion may include one or more of the following network elements:

[0102] The access management network element (also known as the mobility management network element) is a control plane network element provided by the operator's network. It is responsible for access control and mobility management of terminal devices accessing the operator's network, including functions such as mobility state management, allocation of temporary user identities, authentication, and user management. In 5G communication systems, this access management network element can be an access and mobility management function (AMF) network element. In future communication systems, the access management network element can still be an AMF network element, or it can have other names; this application does not limit its scope.

[0103] The session management network element is primarily responsible for session management in mobile networks, such as session establishment, modification, and release. Specific functions include allocating communication addresses to users and selecting user plane network elements that provide packet forwarding capabilities. In 5G communication systems, this session management network element can be a session management function (SMF) network element. In future communication systems, the session management network element may still be an SMF network element, or it may have other names; this application does not impose any limitations on this.

[0104] User plane network elements are responsible for forwarding and receiving user data in terminal devices. They can receive user data from the data network and transmit it to the terminal device through the access network equipment; user plane network elements can also receive user data from the terminal device through the access network equipment and forward it to the data network. The transmission resources and scheduling functions that provide services to the terminal device in the user plane network element are managed and controlled by the SMF network element. In 5G communication systems, this user plane network element can be a user plane function (UPF) network element. In future communication systems, the user plane network element can still be a UPF network element, or it can have other names; this application does not limit this.

[0105] Core network equipment and access network equipment can be independent and different physical devices, or the functions of core network equipment and the logical functions of access network equipment can be integrated into the same physical device, or a single physical device can integrate some of the functions of core network equipment and some of the functions of access network equipment.

[0106] This application relates to Xn interface communication technology between access network devices. Figure 3 illustrates the protocol stack of the control plane (Xn-C, or XnAP) and user plane (Xn-U) of the Xn interface. The control plane of the Xn interface includes the Stream Control Transmission Protocol (SCTP) layer, the Internet Protocol (IP) layer, the Data Link Layer (DL) layer, and the PHY layer. The user plane of the Xn interface includes the GTP-U layer, the User Datagram Protocol (UDP) layer, the IP layer, the Data Link Layer, and the PHY layer; GTP-U is a type of GPRS tunneling protocol (GTP), where GPRS refers to General Packet Radio Service (GPRS). Data packets of the Xn interface are transmitted based on IP. Two access network devices establishing an Xn interface need to know each other's IP address to establish Xn interface communication. The IP address is a TNL address, and the following embodiments of this application use TNL addresses as an example. In terrestrial networks, network management can pre-configure the TNL addresses of nearby access network devices and the device identifiers (such as identity documents, IDs) on the access network device, for the access network device to initiate Xn interface communication; alternatively, access network devices can establish Xn interface communication through an automatic neighbor relation (ANR) mechanism. In a terrestrial network, two access network devices establishing Xn interface communication only need to exchange one TNL address.

[0107] This application relates to the access stratum (AS) layer security mechanism for terminal devices. Taking a 5G communication system as an example, data transmission between the terminal device and the base station requires encryption and integrity protection. Different messages use different keys, such as the radio resource control (RRC) signaling integrity protection key (Krrcint), the RRC signaling encryption key (Krrcenc), and the user plane encryption key (Kupenc). These keys are all derived from the KgNB, and the terminal device and the base station need to align the KgNB values. The following describes how the KgNB is obtained during the initial access of the terminal device and how it is updated during terminal device handover.

[0108] (1) Acquisition of KgNB in ​​the initial access scenario

[0109] During initial access, both the terminal device and the AMF (Active Network Provider) derive a KgNB (Key Generation NodeB) based on the root key KAMF. The terminal device obtains its KgNB by calculating it using the KAMF. The base station obtains its KgNB after establishing an RRC (Regional Relationship Control) connection with the base station. The gNB sends an initial UE message to the core network equipment (such as the AMF). The core network performs user authentication / authorization. If authentication is successful, the AMF derives the KgNB and then informs it via an initial context setup request (INITIAL CONTEXT SETUP REQUEST) message. Further, the gNB instructs the terminal device on the key derivation algorithm through SMC (Security Mode Command) procedures (e.g., sending a Security Mode Command message) to establish a secure connection. Based on the above description, it can be understood that communication between the terminal device and the base station is unencrypted before the SMC procedure, and encrypted communication occurs after the SMC procedure.

[0110] (2) Switch the update of KgNB in ​​the scene.

[0111] Handover between base stations by a terminal device is called inter-site handover. Inter-site handover requires updating the KgNB (Kidney NodeB). After the terminal device switches from the source base station to the target base station, it uses the updated KgNB to conduct encrypted communication with the target base station. Inter-site handover can be understood as divided into Xn handover and NG handover. Xn refers to the interface between base stations, and NG refers to the interface between the base station and the core network. Handover between multiple cells managed by the same base station by a terminal device is called intra-site handover, i.e., a scenario where the accessed cell is changed but the accessed base station is not changed. In 5G communication systems, the KgNB may or may not be updated, while in LTE, the KeNB (Kidney NodeB) must be updated.

[0112] The KgNB update method includes horizontal deduction and vertical deduction. Optionally, deduction can also be described as derivation. The following uses inter-site handover as an example to introduce the key update process.

[0113] As shown in Figure 4, K NG-RAN * indicates the updated KgNB, used to calculate K when the KgNB update method includes horizontal extrapolation. NG-RAN The input parameters for * include: the physical cell ID (PCI) of the target cell, the frequency of the target cell, and the old KgNB; when the KgNB update method includes vertical extrapolation, it is used to calculate K. NG-RANThe input parameters for * include: the PCI of the target cell, the frequency of the target cell, and NH. For Xn handover, the source base station determines the PCI and frequency of the target cell based on the potential target cell selected for the terminal equipment, and then determines the third parameter (i.e., the old KgNB or NH) based on the following principles, thereby calculating K. NG-RAN The principle for determining the third parameter is as follows: if the source base station has unused {NH, NCC}, then NH is used as the third parameter, and the newly generated K is... NG-RAN *This is called vertical extrapolation; if the source base station does not have any unused {NH, NCC} locally, then the third parameter uses the old KgNB, and the generated K... NG-RAN *This is called horizontal deduction. Here, NH refers to the next hop (NH), which can be understood as the starting point value for deducing the new KgNB key. NCC refers to the next hop chaining count (NCC). The relationship between NH and NCC in {NH,NCC} can be understood as follows: NCC is the number of the NH and the number of the KgNB used for subsequent horizontal deduction based on the NH.

[0114] The source station generates K through vertical or horizontal extrapolation. NG-RAN *Afterwards, K will be NG-RAN * The NCC corresponding to the third parameter is included in the handover request and sent to the target base station. This can be understood as: K NG-RAN *This is the key used by the target base station for future communication with the terminal device. Accordingly, the target base station can send a handover command to the terminal device through the source base station to trigger the terminal device to hand over to the target base station. The handover command carries the target cell's PCI, the target cell's frequency, and the NCC corresponding to the aforementioned third parameter. The terminal device can generate a key consistent with the target base station's key based on the parameters carried in the handover command. NG-RAN *

[0115] Specifically, the terminal device will determine whether the NCC carried in the handover command is the same as the NCC currently used locally by the terminal device; if they are the same, the terminal device will generate K using a horizontal extrapolation method. NG-RAN * This means that the terminal device can determine the new KgNB based on the old KgNB, as well as the target cell's PCI and frequency point carried in the handover command. NG-RAN *; If they are different, the terminal device generates K using a vertical deduction method. NG-RANFor example, the terminal device determines the number of hops based on the difference between the NCC currently used locally and the NCC carried in the handover command; then, it vertically extrapolates to the NH corresponding to the current NCC according to the number of hops. For instance, if the terminal device currently uses NCC 0, the NCC carried in the handover command is 2, and the number of hops is 2, the terminal device first calculates the NH corresponding to NCC=1 based on KAMF and the NH corresponding to NCC=0 by running a key extrapolation algorithm; then, it calculates the NH corresponding to NCC=2 based on KAMF and the NH corresponding to NCC=1. Similarly, if the terminal device currently uses NCC 2, the NCC carried in the handover command is 3, and the number of hops is 1, the terminal device calculates the NH corresponding to NCC=3 based on KAMF and the NH corresponding to NCC=2 by running a key extrapolation algorithm. After calculating the new NH, the terminal device can extrapolate the new K based on this NH, as well as the PCI and frequency of the target cell carried in the handover command. NG-RAN * This completes the alignment of the K-line between the target base station and the terminal device. NG-RAN * This means that the target base station and the terminal device use the same K NG-RAN * To communicate.

[0116] After the terminal device switches to the target base station, the target base station will send a path switch request (PATH SWITCH REQUEST) message to the core network equipment (such as AMF) to inform the core network terminal device that it has switched to the target station. The AMF manages (or maintains) the NCC number. If the NCC value previously configured by the AMF for the source base station is 0, the AMF can send a path switch request confirmation (PATH SWITCH REQUEST ACK) message to the target base station. The PATH SWITCH REQUEST ACK will carry "NCC=2" and the corresponding NH. That is, NCC=1 is a special value. The AMF does not configure the NH for NCC=1. If the NCC value previously configured by the AMF for the source base station is not 0, the AMF can increment the previously configured NCC value by one, denoted as "NCC+1", and calculate the NH corresponding to "NCC+1". Then, the AMF sends a PATH SWITCH REQUEST ACK message to the target base station, carrying "NCC+1" and the corresponding NH in the PATH SWITCH REQUEST ACK. For the target base station, it receives its own {NH, NCC}, which it can store locally as unused {NH, NCC}. This unused {NH, NCC} can be used for scenarios where the terminal device switches from the aforementioned target base station to another base station, or for handover scenarios between cells managed by the aforementioned target base station. It is understandable that if unused{NH,NCC} is used in a certain intra-base handover scenario managed by a base station, then in subsequent intra-base handovers of that base station or in scenarios where the terminal device is switched from that base station to another base station, horizontal extrapolation will be used to generate KgNB; if unused{NH,NCC} is not used in an intra-base handover of a base station, then the terminal device can use vertical extrapolation in scenarios where the terminal device is switched from that base station to another base station.

[0117] In regenerative satellite architectures, a satellite switch with re-sync scenario is introduced. This scenario eliminates the need for interactive handover commands to trigger inter-site handover on the terminal device. In other words, the terminal device does not receive a handover command and therefore cannot receive the NCC (Neural Control Code) carried in the handover command by the AS (Autonomous System) layer, thus preventing key updates. To address this scenario, this application provides several solutions to align the keys used for communication between the terminal device and the access network device. The access network device can be a communication device partially or entirely deployed on a satellite, or the access network device can be understood as a satellite itself.

[0118] Option 1

[0119] Figure 5 illustrates a communication method, which mainly includes the following steps.

[0120] S501, the first access network device sends a fourth message to the second access network device.

[0121] In this context, the first access network device can be understood as the source base station, and the second access network device can be understood as the target base station.

[0122] The fourth message is used to request the terminal device to switch to the second access network device. This fourth message carries information indicating the switching type, which is "switch with re-sync". Accordingly, the second access network device determines not to send a switching command to the terminal device based on this switching type. Optionally, the fourth message can be a handover request message, carrying the indication information for "switch with re-sync", or the fourth message can be a newly defined message specifically for "switch with re-sync". This application embodiment does not limit this. Furthermore, it is understood that the fourth message also carries a key used for communication between the second access network device and the terminal device, denoted as the first key.

[0123] In one possible implementation, after the terminal device switches to any access network device, each access network device can obtain a {NH, NCC} from the core network side. The NCC value obtained by different access network devices is different. Taking the terminal device switching to the first access network device as an example, the NCC value obtained by the first access network device can be recorded as the first value. Based on this, before sending the fourth message, the first access network device can determine whether the first value of the NCC has been used. If the first value of the NCC has not been used, the first access network device can use vertical deduction, that is, determine the first key based on the NH corresponding to the first value of the NCC and the cell information (such as PCI and frequency point) of the second access network device. If the first value of the NCC has been used, the first access network device can use horizontal deduction, that is, determine the first key based on the second key and the cell information (such as PCI and frequency point) of the second access network device. Here, the second key is the key used for communication between the first access network device and the terminal device.

[0124] In one possible implementation, if the terminal device does not handover between cells of the first access network device, the first access network device can determine that the first value of the NCC was not used before handover from the first access network device to the second access network device; if handover is made from the first cell of the first access network device to the second cell of the first access network device, it is determined that the first value of the NCC was used before handover from the first access network device to the second access network device. It is understood that the first cell and the second cell described herein are general concepts, meaning that the first cell can be any one of all cells managed by the first access network device, and the second cell can also be one of all cells managed by the first access network device; this application embodiment does not limit this.

[0125] S502, the terminal device determines the first value of the NCC corresponding to the first access network device.

[0126] For example, a terminal device follows a normal handover procedure, switching from a fourth access network device to a first access network device based on a handover command. This handover command originates from the first access network device and carries the third value of the NCC corresponding to the fourth access network device. If the terminal device, knowing from satellite ephemeris that it is about to switch from the first access network device to the second access network device, can automatically calculate the first value of the NCC by adding one to the third value.

[0127] S503, after the terminal device switches from the first access network device to the second access network device, it communicates with the second access network device according to the first key.

[0128] Specifically, the terminal device can determine the cell information (PCI and frequency of the target cell) of the second access network device based on the system broadcast message of the second access network device; and the terminal device and the first access network device use the same deduction method to determine the first key, that is: the terminal device determines whether to use vertical deduction or horizontal deduction to determine the first key based on whether the first value of NCC has been used. If the terminal device determines that the first value of NCC has not been used, vertical deduction is used, that is, the terminal device determines the first key based on the first value of NCC and the cell information of the second access network device. For example, corresponding to the example in S502, the terminal device can calculate the NH corresponding to the first value of NCC based on KAMF and the NH corresponding to the third value of NCC by running the key deduction algorithm; and then determine the first key based on the NH corresponding to the first value of NCC and the cell information of the second access network device. If the terminal device determines that the first value of NCC has been used, horizontal deduction is used, that is, the first key is determined based on the second key and the cell information of the second access network device.

[0129] The implementation method for the terminal device to determine whether the first value of NCC is used can be understood by referring to the description in S501, and will not be repeated in this embodiment.

[0130] In addition, Figure 5 also shows, with dashed lines, the following optional steps S504 and S505.

[0131] S504, the second access network device sends a path switching request message to the core network device.

[0132] S505, the core network equipment sends a path switching request confirmation message to the second access network equipment.

[0133] The core network device can be an AMF. Steps S504 and S505 can be understood by referring to the introduction of the AS layer security mechanism above. This application embodiment will not elaborate on these steps.

[0134] The design of Scheme 1 above is applied when there is an unused NCC. It prioritizes vertical deduction to align the keys between the terminal equipment and the access network equipment, which can improve the security of encrypted communication.

[0135] Option 2

[0136] Example 1, as shown in Figure 6, illustrates a communication method, which mainly includes the following steps.

[0137] S601, after the terminal device switches from the first access network device to the second access network device, the second access network device sends a third message to the core network device.

[0138] The handover type corresponding to the terminal device switching from the first access network device to the second access network device is "switch with re-sync". Optionally, before S601, step S600 is included: the first access network device sends a fourth message to the second access network device, which requests the terminal device to switch to the second access network device. This fourth message carries information indicating the handover type, which is "switch with re-sync". Accordingly, the second access network device determines not to send a handover command to the terminal device based on this handover type. The terminal device executes "switch with re-sync" to switch from the first access network device to the second access network device.

[0139] Optionally, the fourth message may be a HANDOVER REQUEST message, which carries an indication of switch with re-sync, or the fourth message may be a newly defined message specifically for switch with re-sync. This application does not limit this.

[0140] In this method, a horizontal derivation approach is used to generate the first key for communication between the terminal device and the second access network device. For example, the terminal device can determine the cell information (PCI and frequency of the target cell) of the second access network device based on the system broadcast message of the second access network device, and then generate the aforementioned first key based on the second key used for communication between the first access network device and the terminal device, and the cell information (such as PCI and frequency) of the second access network device. The first access network device can generate the aforementioned first key based on the second key used for communication between the first access network device and the terminal device, and the cell information (such as PCI and frequency) of the second access network device; furthermore, the first access network device can carry the first key in a fourth message to inform the second access network device. Based on this, it can be understood that the {NCC, NH} configured by the core network device for the first access network device is not used. Optionally, the first access network device can also carry first indication information in the fourth message, which indicates that the first value of the NCC corresponding to the first access network device is not used, or the first indication information is used to indicate that the NCC is not configured. For example, in a scenario where the core network device configures {NCC, NH} to the access network device through a security context, the first indication message could be "no security context indication," indicating that the core network device does not need to configure a new {NCC, NH}. Furthermore, if the first indication message indicates that the NCC is not configured, the first access network device can also carry the aforementioned first value of the NCC in the fourth message.

[0141] In one possible design, the third message includes the first indication information and the identifier of the terminal device. It is understood that, when S600 is executed and the fourth message carries the first indication information, the second access network device can carry the first indication information in the third message based on the fourth message; or, if the second access network device does not receive the first indication information from the first access network device, the second access network device can also determine the first indication information itself based on the aforementioned design for generating the first key through horizontal deduction. This application embodiment does not limit this aspect.

[0142] Optionally, the core network device can be an AMF, and the third message can be a PATH SWITCH REQUEST message.

[0143] S602, the core network device sends the first message to the second access network device.

[0144] In one possible design, the first message includes second indication information, which indicates a first value for the NCC. Specifically, the core network device indicates the same {NCC, NH} to the second access network device as the first access network device, where the NCC value is the first value. It is understood that the core network device carries the second indication information in the first message in response to the first indication information from the second access network device. Accordingly, the second access device can use the first value of the NCC for subsequent vertical deduction. For example, when a terminal device switches from the second access network device to another access network device, the second access network device can determine the key used for communication between the terminal device and the other access network device based on the NH corresponding to the first value of the NCC and the cell information of the other access network device.

[0145] In another possible design, the first message does not carry the NCC configuration, or it can be described as follows: the core network device does not configure {NCC, NH} in the first message. It is understood that, corresponding to the first indication information in S601 indicating that NCC is not configured, the core network device may not configure {NCC, NH} in the first message.

[0146] Optionally, the core network device can be an AMF, and the first message can be a PATH SWITCH REQUEST ACK message.

[0147] Example 2, as shown in Figure 7, illustrates a communication method that mainly includes the following steps.

[0148] S701, the first access network device sends a second message to the core network device.

[0149] For example, the second message could be a Next Generation Application Protocol (NGAP) message, and the core network device could be an AMF (Advanced Feature Message).

[0150] Specifically, when the first access network device determines to initiate an inter-site handover according to the switch with re-sync method and updates the key using a horizontal deduction approach, the first access network device carries a first indication information and the identifier of the terminal device in the second message. The first indication information indicates that the first value of the NCC corresponding to the first access network device is not used; or the first indication information is used to indicate that the NCC is not configured. For example, in a scenario where the core network device configures {NCC, NH} to the access network device through a security context, the first indication information could be "no sceurity context indication," indicating that the core network device does not need to configure a new {NCC, NH}.

[0151] S702, the first access network device sends a fourth message to the second access network device.

[0152] The fourth message is used to request the terminal device to switch to the second access network device. This fourth message carries information indicating the handover type, which is "switch with re-sync". Accordingly, based on this handover type, the second access network device determines not to send a handover command to the terminal device. The terminal device executes "switch with re-sync", switching from the first access network device to the second access network device.

[0153] Optionally, the fourth message may be a HANDOVER REQUEST message, which carries an indication of switch with re-sync, or the fourth message may be a newly defined message specifically for switch with re-sync. This application does not limit this.

[0154] In this method, a horizontal extrapolation approach is used to generate the first key for communication between the terminal device and the second access network device. For example, the first access network device can use the second key used for communication between the first access network device and the terminal device, and the cell information of the second access network device, to generate the first key.

[0155] The first key (e.g., PCI and frequency point) is generated; subsequently, the first access network device can carry the first key in the fourth message to inform the second access network device. Based on this, it can be understood that the {NCC, NH} configured by the core network device for the first access network device is not used. Optionally, the first access network device can also carry first indication information in the fourth message, indicating that the first value of the NCC corresponding to the first access network device is not used; or the first indication information is used to indicate that the NCC is not configured. For example, in a scenario where the core network device configures {NCC, NH} to the access network device through a security context, the first indication information can be "no sceurity context indication," indicating that the core network device does not need to configure a new {NCC, NH}. Furthermore, if the first indication information indicates that the NCC is not configured, the first access network device can also carry the first value of the aforementioned NCC in the fourth message.

[0156] It is understood that the embodiments of this application do not limit the execution order of S701 and S702, for example, S701 is executed first and then S702 is executed; or, for example, S702 is executed first and then S701 is executed.

[0157] S703, the terminal device determines the first key based on the second key and the cell information of the second access network device.

[0158] For example, a terminal device can determine the cell information (PCI and frequency of the target cell) of the second access network device based on the system broadcast message of the second access network device, and then generate the aforementioned first key based on the second key used by the first access network device to communicate with the terminal device and the cell information (such as PCI and frequency) of the second access network device.

[0159] S704, the second access network device sends a path switching request message to the core network device.

[0160] S705, the core network equipment sends the first message to the second access network equipment.

[0161] The first message may carry second indication information, which indicates a first value of the NCC; or, the first message may not carry the configuration of the NCC. The first message may be a path switching request confirmation message. Step S705 can be specifically implemented with reference to the description in S602, and will not be elaborated upon in this embodiment.

[0162] The design of Scheme 2 above uses horizontal deduction to align the keys between the terminal equipment and the access network equipment during inter-site handover, and the NCC is reused in this design. This can save the computation of NCC and NH and facilitate the alignment of subsequent key updates, thereby improving the security of encrypted communication.

[0163] Option 3

[0164] Example 1, as shown in Figure 8, illustrates a communication method that mainly includes the following steps.

[0165] S801, the terminal device obtains the first value of the NCC corresponding to the first access network device.

[0166] For example, a terminal device follows a normal handover procedure, switching from a fourth access network device to a first access network device based on a handover command. This handover command originates from the first access network device and carries the third value of the NCC corresponding to the fourth access network device. If the terminal device, knowing from satellite ephemeris data that it is about to switch from the first access network device to another device, can calculate the first value of the NCC by adding one to the third value of the NCC.

[0167] S802, the terminal device performs m cell handovers, switching to the (m+1)th access network device.

[0168] Where m is a positive integer, that is, an integer greater than or equal to 1. Taking an integer n from 1 to m as an example, the nth cell handover in the m cell handovers indicates that the terminal device is handovering from the nth access network device to the (n+1)th access network device. It can be understood that when n is 1, the nth access network device is the first access network device, that is, the terminal device starts from the first access network device and performs m cell handovers sequentially. In the design of this method, cell handover can be implemented by horizontal extrapolation to update the key. For example, the (n+1)th key used for communication between the terminal device and the (n+1)th access network device is determined based on the nth key used when the terminal device communicates with the nth access network device and the cell information of the (n+1)th access network device.

[0169] Optionally, each of the m cell handovers is an inter-site handover and a handover between cells with the same PCI.

[0170] For ease of implementation, the handover and key update process for a terminal device from the nth access network device to the (n+1)th access network device is described below, including the following steps:

[0171] S8021, the nth access network device sends a first handover request message to the (n+1)th access network device.

[0172] The first handover request message contains an indication for "switch with re-sync," or it may be a newly defined message specifically for "switch with re-sync." The nth access network device generates the aforementioned n+1th key based on the nth key and the cell information of the (n+1)th access network device. Consequently, the first access network device includes the (n+1)th key generated based on horizontal deduction and the first value of the NCC in the first handover request message.

[0173] S8022, the terminal device switches from the nth access network device to the (n+1)th access network device and generates the (n+1)th key based on horizontal deduction.

[0174] For example, the terminal device can determine the cell information (PCI and frequency of the target cell) of the (n+1)th access network device based on the system broadcast message of the (n+1)th access network device, and then generate the (n+1)th key based on the aforementioned nth key and the cell information of the (n+1)th access network device.

[0175] S8023, the (n+1)th access network device sends a path switching request message to the core network device.

[0176] S8024, the core network device sends a path switching request confirmation message to the (n+1)th access network device.

[0177] The path switching request confirmation message carries the {NCC, NH} configured by the core network device for the (n+1)th access network device. Specifically, if the NCC configured by the core network device for the nth access network device is 0, then the NCC configured by the core network device for the nth access network device is 2; if the NCC configured by the core network device for the nth access network device is not 0, then the NCC configured by the nth access network device is incremented by one to obtain the NCC configured for the (n+1)th access network device. In other words, the value of the NCC corresponding to the (n+1)th access network device is equal to the value of the NCC corresponding to the nth access network device plus one.

[0178] Understandably, based on the horizontal deduction update key, without using the NCC corresponding to the nth access network device, the core network device indicates the new NCC to the (n+1)th access network device according to the traditional AS layer security mechanism. Therefore, given the NCC value range specified in the protocol, the value of the NCC corresponding to the (n+1)th access network device configured in the aforementioned manner may exceed this range. For example, if the NCC value range indicates that the NCC has j values, where j is an integer greater than 1, and n is greater than j, the NCC value corresponding to the (n+1)th access network device will exceed the NCC value range, thus causing a communication error.

[0179] To address this situation, this method defines the number of cell handover rounds and ensures that the number of cell handovers in each round does not exceed the range of NCC values. For example, a first parameter (or denoted as count1) and a second parameter (or denoted as count2) are defined. The first parameter indicates the current round, and the second parameter indicates the difference between the current NCC value and the first value of the NCC. The values ​​of the first and second parameters are updated after each horizontally extrapolated cell handover. Figure 8 illustrates an example of the terminal device maintaining the first and second parameters in step S8025.

[0180] S8025, after the nth cell handover, the terminal device updates the values ​​of the first parameter and the second parameter.

[0181] After the nth cell handover, the terminal device can determine the value of the first parameter. The second parameter takes the value (n+k)mod j; where k indicates the first value of NCC. The floor operator (`\n`) is the floor operator, and the mod operator (`\m`) is the modulo operator. For example, the value range of NCC includes 8 values, from 0 to 7, where j is 8 and k is 3. When n is 1, the first parameter is 0 and the second parameter is 4; when n is 6, the first parameter is 1 and the second parameter is 1.

[0182] It is understandable that the handover process and key update process for each cell handover in m cell handovers can be implemented with reference to S8021 to S8025. Similarly, after m cell handovers, the value of the first parameter is related to the value of m and the range of the NCC value.

[0183] S803, the (m+1)th access network device sends a second handover request message to the third access network device.

[0184] For example, the second handover request message is used to request the terminal device to hand over to the third access network device. The second handover request message can be a HANDOVER REQUEST message. Taking the value of the NCC received by the (m+1)th access network device from the core network device as the second value, the second handover request message carries the (m+1)th key and the second value of the NCC.

[0185] S804, the third access network device sends a handover command to the terminal device.

[0186] The handover command receives instructions to switch the terminal device to a third access network device, such as a Layer 3 handover command (e.g., RRC Reconfiguration). The handover command includes a second value of the NCC.

[0187] It is understandable that S803 and S804 describe one possible implementation, namely inter-site handover. In another possible implementation, if intra-site handover occurs, for example, if the terminal device switches from cell 1 of the (n+1)th access network device to cell 2 of the (n+1)th access network device, in this case, there is no need for a second handover request message between the two sites, and the (n+1)th access network device sends a handover command to the terminal device.

[0188] In one possible design, the handover command includes a second value of the NCC. The terminal device can determine the key used for communication between the terminal device and the third access network device in a manner described in S805. Optionally, the handover command also includes the first parameter.

[0189] S805, the terminal device determines a key for communication between the terminal device and the third access network device based on the first value of the NCC, the second value of the NCC, and the first parameter.

[0190] For example, the terminal device calculates the hop count p according to the following formula: p = second value of NCC + (first parameter × j) - first value of NCC; then, the terminal device calculates the first NH based on KAMF and the NH corresponding to the first value of NCC by running a key deduction algorithm, calculates the second NH based on KAMF and the first NH, and so on, until the p-th NH is calculated based on KAMF and the (p-1)-th NH. After calculating the p-th NH, the terminal device can vertically deduce the key used for communication between the terminal device and the third access network device based on the p-th NH, as well as the PCI and frequency of the target cell carried in the handover command. It can be understood that the first parameter in S805 is the parameter after m cell handovers, i.e., m updates, that is, the first parameter is determined based on the value of m, the value range of NCC, and the first value of NCC.

[0191] Optionally, after the terminal device switches to the third access network device, the value of the first parameter can be updated to 0, and the value of the second parameter can be updated to 0.

[0192] In another possible design, the handover command does not include the second value and the first parameter of NCC. The terminal device calculates the number of hops p based on the latest value of the first parameter and the latest value of the second parameter maintained locally: p = second parameter + (first parameter × j) - first value of NCC; and then determines the key for communication between the terminal device and the third access network device in accordance with the method described in S805.

[0193] In another possible implementation, the handover command does not include the second value and the first parameter of the NCC. After the terminal device can handover from the nth access network device to the (n+1)th access network device, it calculates the NH corresponding to the NCC value of the (n+1)th access network device by running a key deduction algorithm based on KAMF and the NH corresponding to the NCC value of the nth access network device. That is, the terminal device calculates one NH after each cell handover in m cell handovers, and so on, until the NH is calculated after the mth cell handover. The terminal device can vertically deduce the key used for communication between the terminal device and the third access network device based on the NH calculated after the mth cell handover, as well as the PCI and frequency of the target cell carried in the handover command. In this implementation, the first and second parameters do not need to be introduced, and step S8025 can be omitted.

[0194] Example 1 above maintains a first parameter and a second parameter on the terminal device side to align the NCC between the terminal device and the access network device, thereby aligning the communication key. Similarly, Example 2, described below, maintains a first parameter and a second parameter on the access network device side to achieve communication key alignment.

[0195] Example 2, as shown in Figure 9, illustrates a communication method that mainly includes the following steps.

[0196] S901, the first access network device sends a fourth message to the second access network device.

[0197] The fourth message is used to request the terminal device to switch to the second access network device. This fourth message carries information indicating the handover type, which is "switch with re-sync". Accordingly, based on this handover type, the second access network device determines not to send a handover command to the terminal device. The terminal device executes "switch with re-sync", switching from the first access network device to the second access network device.

[0198] Optionally, the fourth message may be a HANDOVER REQUEST message, which carries an indication of switch with re-sync, or the fourth message may be a newly defined message specifically for switch with re-sync. This application does not limit this.

[0199] In one possible implementation, the fourth message includes a first value for the first parameter and a first value for the second parameter. The values ​​of the first and second parameters are related to the range of NCC values, and their specific definitions can be understood from the description in the method shown in Figure 8; this embodiment will not elaborate further. Furthermore, the fourth message also includes: a first key generated based on horizontal deduction, and a first value of the NCC corresponding to the first access network device. The first key is used for communication between the second access network device and the terminal device, and is generated based on the second key and the cell information of the second access network device. The second key is also used for communication between the first access network device and the terminal device.

[0200] In one possible implementation, if the first access network device determines that the terminal device will switch to the second access network device using a switch with re-sync switching method, then step S901 is executed.

[0201] S902, the terminal device switches from the first access network device to the second access network device and generates the first key based on horizontal deduction.

[0202] This step can be implemented with reference to S8022, and will not be described in detail in this embodiment.

[0203] S903, the second access network device sends a path switching request message to the core network device.

[0204] S904, the core network equipment sends a path switching request confirmation message to the second access network equipment.

[0205] The path switching request confirmation message includes the second value of the NCC corresponding to the second access network device. This step can be implemented with reference to S8024, and will not be described in detail in this embodiment.

[0206] S905, the second access network device updates the values ​​of the first parameter and the second parameter.

[0207] For example, the value range of NCC indicates that the value of NCC is an integer less than or equal to j, where j is a positive integer. When the first value of the second parameter is less than j-1, the second access network device can update the value of the second parameter to the first value of the second parameter plus one, and the value of the first parameter is the first value of the first parameter; if the first value of the second parameter is equal to j-1, then the value of the second parameter is updated to 0, and the value of the first parameter is updated to the first value of the first parameter plus one.

[0208] Taking the value range of NCC as 0 to 7, i.e. j is 8, as an example, if the first value of the first parameter is 0 and the first value of the second parameter is 3, then update the value of the second parameter to 4, and the value of the first parameter remains 0; if the first value of the first parameter is 0 and the first value of the second parameter is 6, then update the value of the second parameter to 0, and the value of the first parameter to 1.

[0209] In one possible design, the following steps S906 to S908 are further performed.

[0210] S906, the second access network device sends the fifth message to the third access network device.

[0211] The fifth message includes a second value of the NCC corresponding to the second access network device and an updated value of the first parameter; wherein the second value of the NCC and the first parameter are used to determine the key used by the terminal device to communicate with the third access network device.

[0212] The fifth message can be a HANDOVER REQUEST message. This step can be implemented with reference to S803, and will not be described in detail in this embodiment.

[0213] S907, the third access network device sends a handover command to the terminal device.

[0214] Specifically, the third access network device sends a handover command to the terminal device through the second access network device. This handover command is used to instruct the terminal device to switch to the third access network device. For example, the handover command is a Layer 3 handover command (such as RRC Reconfiguration). The handover command includes the second value of the NCC and the aforementioned first parameter.

[0215] It is understandable that S906 and S907 describe one possible implementation, namely inter-site handover. In another possible implementation, if intra-site handover occurs, for example, when the terminal device switches between cells managed by the second access network device, no inter-site handover request message is needed, and the second access network device sends a handover command to the terminal device.

[0216] S908, the terminal device determines a key for communication between the terminal device and the third access network device based on the first value of the NCC, the second value of the NCC, and the first parameter.

[0217] This step can be implemented with reference to S805, and will not be described in detail in this embodiment.

[0218] Optionally, after the terminal device switches to the third access network device, the third access network device can update the value of the first parameter to 0 and the value of the second parameter to 0.

[0219] In another possible design, inter-station handover based on vertical deduction is not performed on the basis of S901 to S905, that is, steps S906 to S908 are not performed. Instead, inter-station handover or intra-station handover based on horizontal deduction is performed in the manner of S901 to S905. This embodiment of the application will not elaborate on this.

[0220] Example 2 above maintains the first and second parameters on the access network device side to align the NCC between the terminal device and the access network device, thereby aligning the communication keys. Similarly, Example 3, described below, maintains the first and second parameters on the core network device side to achieve communication key alignment.

[0221] Example 3, as shown in Figure 10, illustrates a communication method, which mainly includes the following steps.

[0222] S1001, the first access network device sends a fourth message to the second access network device.

[0223] The fourth message is used to request the terminal device to hand over to the second access network device. The fourth message includes a first key generated based on horizontal deduction and a first value of the NCC corresponding to the first access network device. The first key is used for communication between the second access network device and the terminal device, and is generated based on the second key and the cell information of the second access network device. The second key is used for communication between the first access network device and the terminal device. For example, the fourth message may be a handover request message containing an indication of "switch with re-sync," or it may be a newly defined message specifically for "switch with re-sync." Accordingly, based on the handover type being "switch with re-sync," the second access network device determines not to send a handover command to the terminal device.

[0224] In one possible implementation, if the first access network device determines that the terminal device will switch to the second access network device using a switch with re-sync method, then step S1001 is executed. In step S1002, the terminal device switches from the first access network device to the second access network device, and a first key is generated based on horizontal deduction.

[0225] This step can be implemented with reference to S8022, and will not be described in detail in this embodiment.

[0226] S1003, the second access network device sends a path switching request message to the core network device.

[0227] The path switching request message carries a third indication information, which indicates whether the switching type is switch with re-sync. The third indication information is used to trigger the core network equipment to update the values ​​of the first parameter and the second parameter.

[0228] S1004, the core network equipment updates the values ​​of the first parameter and the second parameter.

[0229] For example, the value range of NCC indicates that the value of NCC is an integer less than or equal to j, where j is a positive integer. When the third indication information indicates that the handover type is switch with re-sync, and the first value of the second parameter is less than j-1, the core network device updates the value of the second parameter to the first value of the second parameter plus one, and the value of the first parameter is the first value of the first parameter; when the third indication information indicates that the handover type is switch with re-sync, and the first value of the second parameter is equal to j-1, the core network device updates the value of the second parameter to 0, and updates the value of the first parameter to the first value of the first parameter plus one.

[0230] Taking the value range of NCC as 0 to 7, i.e. j is 7, if the first value of the first parameter is 0 and the first value of the second parameter is 3, then update the value of the second parameter to 4, and the value of the first parameter remains 0; if the first value of the first parameter is 0 and the first value of the second parameter is 6, then update the value of the second parameter to 0, and the value of the first parameter to 1.

[0231] When the third indication information indicates that the switching type is not switch with re-sync, or when the message in step S1003 does not contain the third indication information, the core network device can update the value of the first parameter to 0 and update the value of the second parameter to 0.

[0232] S1005, the core network device sends a path switching request confirmation message to the second access network device.

[0233] The path switching request confirmation message includes the second value of the NCC corresponding to the second access network device and the updated value of the first parameter. This step can be implemented with reference to S8024, and will not be described in detail in this embodiment.

[0234] In one possible design, the following steps S1006 to S1008 are further performed.

[0235] S1006, the second access network device sends the fifth message to the third access network device.

[0236] The fifth message includes a second value of the NCC corresponding to the second access network device and an updated value of the first parameter; wherein the second value of the NCC and the first parameter are used to determine the key used by the terminal device to communicate with the third access network device.

[0237] The fifth message can be a HANDOVER REQUEST message. This step can be implemented with reference to S803, and will not be described in detail in this embodiment.

[0238] S1007, the third access network device sends a handover command to the terminal device.

[0239] Specifically, the third access network device sends a handover command to the terminal device through the second access network device. This handover command is used to instruct the terminal device to switch to the third access network device. For example, the handover command is a Layer 3 handover command (such as RRC Reconfiguration). The handover command includes the second value of the NCC and the aforementioned first parameter.

[0240] S1008, the terminal device determines a key for communication between the terminal device and the third access network device based on the first value of the NCC, the second value of the NCC, and the first parameter.

[0241] This step can be implemented with reference to S805, and will not be described in detail in this embodiment.

[0242] In another possible design, based on S1001 to S1005, inter-station handover based on vertical inference is not performed, that is, steps S1006 to S1008 are not performed. Instead, inter-station handover or intra-station handover based on horizontal inference is performed in the manner of S1001 to S1005. This application embodiment will not elaborate on this.

[0243] Example 3 above maintains the first and second parameters on the core network equipment side to align the NCC between the terminal equipment and the access network equipment, thereby aligning the communication keys.

[0244] Similarly, applying Example 3 to the O-RAN system, the method of maintaining the first and second parameters on the core network equipment side can be replaced by the RIC maintaining the first and second parameters. For example, steps S1003 to S1005 in Figure 10 can be replaced with steps S1 to S5 as follows, while the remaining steps and execution order of the method shown in Figure 10 remain unchanged.

[0245] S1, the second access network device sends the sixth message to the RIC.

[0246] The sixth message carries a third indication message, which indicates whether the switching type is switch with re-sync. The third indication message is used to trigger the RIC side to update the values ​​of the first parameter and the second parameter.

[0247] Optionally, the sixth message can be an E2 message, where E2 refers to the interface between the access network device and the RIC.

[0248] Example 3, described below, maintains the first and second parameters on the core network equipment side to achieve communication key alignment.

[0249] S2, RIC updates the values ​​of the first and second parameters.

[0250] This step can be implemented with reference to the description in S1004, and will not be described in detail in this embodiment.

[0251] S3, RIC sends the seventh message to the second access network device.

[0252] The seventh message includes the updated value of the first parameter. Optionally, this seventh message can also be an E2 message.

[0253] S4, the second access network device sends a path switching request message to the core network device.

[0254] S5, the core network device sends a path switching request confirmation message to the second access network device.

[0255] The path switching request confirmation message includes the second value of the NCC corresponding to the second access network device. This step can be implemented with reference to S8024, and will not be described in detail in this embodiment.

[0256] Option 4

[0257] Figure 11 illustrates a communication method, which mainly includes the following steps.

[0258] S1101, the core network equipment sends time information to at least one communication device.

[0259] In this method, taking the handover between a terminal device and a first access network device, a second access network device, and a third access network device as an example, the core network device can send time information to one or more communication devices among the terminal device, the first access network device, the second access network device, and the third access network device. The terminal device can switch between access network devices using a switch-with-re-sync handover method. Figure 11 illustrates step S1101, using the core network device sending time information to the terminal device and the second access network device as an example.

[0260] The time information is used to indicate the usage time corresponding to each security context in at least one security context. For example, in one possible design, the time information indicates only one usage time, and the usage time is the same for different security contexts. In another possible design, the time information indicates multiple security contexts and the usage time corresponding to each of the multiple security contexts, and the usage time corresponding to different security contexts may be different.

[0261] Optionally, the usage time corresponding to a security context refers to the maximum duration for which the security context is not updated. For example, a usage time of 100 seconds means that the security context can be used for communication between different access network devices and terminal devices within a maximum of 100 seconds; or the maximum number of handovers corresponding to the security context that is not updated. For example, a handover count of 5 times means that the security context can be used for communication between different access network devices and terminal devices during a maximum of 5 inter-site handover processes.

[0262] Optionally, the security context includes one or more of the following: a key used for communication between the access network device and the terminal device, and {NCC, NH} used to deduce and generate the key.

[0263] It is understandable that the correspondence between security context and usage time in the aforementioned time information can be defined by the protocol or pre-configured on the access network device side. In this way, S1101 can be omitted, that is, S1101 is an optional step, and S1101 is shown as a dashed line in Figure 11.

[0264] S1102, the first access network device sends a fourth message to the second access network device.

[0265] The fourth message is used to request the terminal device to switch to the second access network device. For example, the fourth message is a handover request message, and the handover request message contains indication information for "switch with re-sync", or the handover request message is a newly defined message specifically for "switch with re-sync". Accordingly, the second access network device determines not to send a handover command to the terminal device based on the handover type being "switch with re-sync".

[0266] In one possible implementation, the fourth message includes information indicating that the security context should not be updated and information indicating a first security context. The first security context is the security context used for communication between the first access network device and the terminal device.

[0267] For example, the information used to indicate that the security context should not be updated could be a 1-bit flag bit, where a value of 1 indicates that the second access network device should not update the security context. The information used to indicate the first security context could include the first security context itself, or an identifier of the first security context. For example, if the first security context and its corresponding usage duration are configured in the time information in S1101, the second access network device obtains the first security context from the time information based on the identifier of the first security context. Furthermore, the information used to indicate the first security context could also include the duration or number of times the first security context has been used.

[0268] Optionally, the first access network device also sends an eighth message to the third access network device. Optionally, the eighth message carries hop count indication information (or number of times indication information), indicating the number of handovers required for the terminal device to switch from the first access network device to the third access network device; or the eighth message carries delay indication information, indicating that the third access network device is not the target base station for the current handover, but rather the target base station for a subsequent handover. This design can be used in NTNs where the access network devices are deployed on satellites with fixed satellite trajectories. The first access network device can send a fourth message in advance to the third access network device that will subsequently perform a switch with re-sync handover.

[0269] S1103, during the first time period after the terminal device switches from the first access network device to the second access network device, the second access network device communicates with the terminal device according to the first security context.

[0270] In one possible implementation, corresponding to the time information described in S1101, the first time period is determined based on the usage time corresponding to the first security context. For example, taking the handover from the terminal device to the second access network device as the starting time, the first time period is the usage time corresponding to the first security context, or the number of handovers supported within the first time period is the number of handovers corresponding to the first security context. Alternatively, taking the first use of the first security context as the starting time, the second access network device determines the remaining available time corresponding to the first security context as the first time period based on the duration the first security context has been used and the usage time corresponding to the first security context, as indicated in the fourth message; or, the second access network device determines the remaining available number of handovers corresponding to the first security context based on the number of handovers the first security context has been used and the number of handovers corresponding to the first security context, as indicated in the fourth message.

[0271] In another possible implementation, corresponding to the case where S1101 is not executed, i.e., there is no time information configuration, the second access network device can request the usage time corresponding to the first security context from the core network device. Accordingly, the core network device configures the usage time corresponding to the first security context to the second access network device based on the ephemeris information. The usage time of the security context is described in S1101. Then, the second access network device determines the first time period based on the usage time corresponding to the first security context. Alternatively, the second access network device can request the usage time corresponding to the first security context and the duration that the first security context has been used from the core network device to determine the remaining available time corresponding to the first security context as the first time period.

[0272] Similarly, in the case where S1101 is not executed, i.e., there is no time information configuration, if the first access network device also sends the eighth message to the third access network device, the third access network device can request the usage time corresponding to the first security context from the core network device. Accordingly, the core network device configures the usage time corresponding to the first security context to the third access network device based on the ephemeris information. The usage time of the security context is described in S1101. Then, the third access network device determines the first time period based on the usage time corresponding to the first security context. Alternatively, the third access network device can request the usage time corresponding to the first security context and the duration that the first security context has been used from the core network device to determine the remaining available time corresponding to the first security context as the first time period.

[0273] Furthermore, in the first possible implementation, if inter-site handover occurs within the first time period, there is no need to update the first security context; for example, S1104a is executed after S1103. In the second possible implementation, if no inter-site handover occurs within the first time period, but the usage time corresponding to the first security context is exceeded after the first time period (i.e., the time when the security context needs to be updated), the second access network device can update the security context based on the inter-site handover, such as S1104b is executed after S1103. In the third possible implementation, if no cell handover occurs within the first time period, but the usage time corresponding to the first security context is exceeded after the first time period (i.e., the time when the security context needs to be updated), the second access network device can update the security context based on RRC reconfiguration, such as S1106 is executed after S1103.

[0274] S1104a, during the first time period, the second access network device sends a fifth message to the third access network device.

[0275] The fifth message is used to request the terminal device to switch to the third access network device; the fifth message includes information indicating not to update the security context and information indicating the first security context. For detailed implementation, please refer to the description in S1102; this application embodiment will not elaborate further.

[0276] Accordingly, based on the case of S1104a, after the terminal device switches to the third access network device, the third access network device can determine the duration of communication with the terminal device using the first security context by referring to the description in S1103.

[0277] S1104b, after the first time period, the second access network device sends a handover request message to the third access network device.

[0278] The handover request message is used to request the terminal device to switch to the third access network device.

[0279] In the case where the time information described in S1101 includes at least one security context, the second access network device can select the next security context (denoted as the second security context) after the first security context by querying the security context in the time information; subsequently, the access network device can carry information indicating the second security context in the handover request message. It is understood that the second security context includes a key and / or NCC used for communication between the third access network device and the terminal device.

[0280] In cases where there is no other security context on the second access network device side, the second access network device can request a security context from the core network device, for example, by sending a request message (such as a path switching request message), so that the core network device can carry the key and / or NCC used for communication between the third access network device and the terminal device in the confirmation message (such as a path switching request confirmation message) fed back to the second access network device.

[0281] Based on the above example, it can be understood that the security context used for communication between the terminal device and the third access network device is different from the first security context. The second access network device may carry a key and / or NCC for communication between the third access network device and the terminal device in the handover request message sent to the third access network device.

[0282] In one possible design, the handover request initiated by the second access network device is a normal handover, and the handover request message can be a HANDOVER REQUEST message. In this design, after executing S1104b, the following step S1105 also needs to be executed.

[0283] S1105, the third access network device sends a handover command to the terminal device through the second access network device.

[0284] The handover command can be implemented using an RRC reconfiguration message, which carries the NCC (Neural Code Control). Accordingly, after the time required to update the security context is reached, the terminal device determines whether to generate a key for communication with the third access network device using vertical or horizontal derivation, based on the NCC in the handover command and its local NCC.

[0285] In another possible design, the handover request initiated by the second access network device is a switch with re-sync. The second access network device does not send a handover command to the terminal device; that is, after executing S1104b, S1105 is not executed. In this design, the terminal device needs to maintain at least one security context and its corresponding usage time to ensure that the terminal device and the access network device generate the same key. S1106, after the first time period, the second access network device sends an RRC reconfiguration message to the terminal device.

[0286] Corresponding to the case where the time information described in S1101 includes at least one security context, the second access network device can select the next security context (denoted as the second security context) after the first security context by querying the security context in the time information; subsequently, the second access network device can carry information indicating the second security context in the RRC reconfiguration message, such as carrying an identifier of the second security context. It is understood that the second security context includes a key and / or NCC used for communication between the third access network device and the terminal device.

[0287] In cases where there is no other security context on the second access network device side, the second access network device can request a security context from the core network device, for example, by sending a request message (such as a path switching request message), so that the core network device carries information indicating the second security context in the confirmation message (such as a path switching request confirmation message) fed back to the second access network device. For example, the second security context includes a new key and / or NCC for communication between the second access network device and the terminal device; then the second access network device can carry the new key and / or NCC in the RRC reconfiguration message.

[0288] Optionally, the second access network device can also instruct the terminal device to perform an intra-site handover via an RRC reconfiguration message. For example, the RRC reconfiguration message may carry the identifier of the target cell, instructing the terminal device to hand over to the target cell, and the target cell belongs to the second access network device. It is understood that the second security context used for communication between the terminal device and the target cell is different from the first security context.

[0289] Furthermore, this application embodiment also provides a possible implementation: if no inter-station handover occurs within the first time period, but the usage time corresponding to the first security context is exceeded after the first time period, that is, the time when the security context needs to be updated is reached, and in step S1101, the core network has already configured a new security context for both the terminal device and the second access network device, then the terminal device can communicate with the second access network device synchronously using the new key (denoted as the second security context) at the time when the usage time corresponding to the first security context arrives, and steps 1104a, 1104b, 1105, and 1106 do not need to be executed.

[0290] Scheme 4 allows terminal devices to switch access network devices without changing the key within a set time period via switch with re-sync, and then change the key after the set time period has expired. This enables the terminal device and the access network device to align the key update time and the updated value, which helps to save the cost of key calculation.

[0291] Based on the same concept, referring to Figure 12, this application embodiment provides a communication device 1200, which includes a processing module 1201 and a communication module 1202. The communication device 1200 can be a communication equipment, or a communication device applied to or used in conjunction with a communication equipment to implement a communication method executed on the communication equipment side. The communication equipment can be the terminal device, access network device, or core network device described in the foregoing embodiments.

[0292] The communication module can also be called a transceiver module, transceiver, transceiver unit, or transceiver device. The processing module can also be called a processor, processing board, processing unit, or processing device. Optionally, the communication module is used to perform the sending and receiving operations on the communication device side or the communication device side in the above method. The device in the communication module that implements the receiving function can be regarded as a receiving unit, and the device in the communication module that implements the sending function can be regarded as a sending unit. That is, the communication module includes a receiving unit and a sending unit.

[0293] When the communication device 1200 is applied to a communication device, the processing module 1201 can be used to implement the processing function of the communication device in the embodiments shown in Figures 5 to 11, and the communication module 1202 can be used to implement the sending and receiving function of the communication device in the embodiments shown in Figures 5 to 11.

[0294] Furthermore, it should be noted that the aforementioned communication module and / or processing module can be implemented through virtual modules. For example, the processing module can be implemented through software functional units or virtual devices, and the communication module can be implemented through software functions or virtual devices. Alternatively, the processing module or communication module can also be implemented through physical devices. For example, if the communication device is implemented using a chip / chip circuit, the communication module can be an input / output circuit and / or a communication interface, performing input operations (corresponding to the aforementioned receiving operation) and output operations (corresponding to the aforementioned sending operation); the processing module is an integrated processor, microprocessor, or integrated circuit.

[0295] The module division in this embodiment is illustrative and represents only one logical functional division. In actual implementation, other division methods may be used. Furthermore, the functional modules in each embodiment of this application can be integrated into a single processor, exist as separate physical entities, or be integrated into a single module. The integrated modules described above can be implemented in hardware or as software functional modules.

[0296] Based on the same technical concept, this application also provides a communication device 1300. For example, the communication device 1300 may be a chip or a chip system. Optionally, in this application embodiment, the chip system may be composed of chips, or may include chips and other discrete devices.

[0297] The communication device 1300 can be used to implement the function of any network element in the communication system described in the foregoing embodiments. The communication device 1300 may include at least one processor 1310 coupled to a memory. Optionally, the memory may be located within the communication device, integrated with the processor, or located outside the communication device. For example, the communication device 1300 may also include at least one memory 1320. The memory 1320 stores computer programs, computer programs or instructions, and / or data necessary for implementing any of the above embodiments; the processor 1310 may execute the computer program stored in the memory 1320 to complete the methods in any of the above embodiments.

[0298] The communication device 1300 may also include a communication interface 1330, through which the communication device 1300 can interact with other devices. For example, the communication interface 1330 may be a transceiver, circuit, bus, module, pin, or other type of communication interface. When the communication device 1300 is a chip-based device or circuit, the communication interface 1330 may also be an input / output circuit, capable of inputting information (or receiving information) and outputting information (or sending information). The processor may be an integrated processor, microprocessor, integrated circuit, or logic circuit, and the processor can determine the output information based on the input information.

[0299] The coupling in this embodiment is an indirect coupling or communication connection between devices, units, or modules, which can be electrical, mechanical, or other forms, used for information exchange between devices, units, or modules. The processor 1310 may operate in conjunction with the memory 1320 and the communication interface 1330. This embodiment does not limit the specific connection medium between the processor 1310, the memory 1320, and the communication interface 1330.

[0300] Optionally, referring to Figure 13, the processor 1310, the memory 1320, and the communication interface 1330 are interconnected via a bus 1340. The bus 1340 can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of illustration, only one thick line is used in Figure 13, but this does not indicate that there is only one bus or one type of bus.

[0301] In the embodiments of this application, the processor may be a general-purpose processor, a digital signal processor, an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components, capable of implementing or executing the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this application can be directly manifested as being executed by a hardware processor, or executed by a combination of hardware and software modules within the processor.

[0302] In the embodiments of this application, the memory can be non-volatile memory, such as a hard disk drive (HDD) or a solid-state drive (SSD), or it can be volatile memory, such as random-access memory (RAM). Memory is any other medium capable of carrying or storing desired program code in the form of instructions or data structures, and accessible by a computer, but is not limited thereto. The memory in the embodiments of this application can also be a circuit or any other device capable of implementing storage functions, used to store program instructions and / or data.

[0303] In one possible implementation, the communication device 1300 can be applied to a communication device, such as a terminal device, access network device, or core network device described in the foregoing embodiments. Specifically, the communication device 1300 can be a communication device or an apparatus capable of supporting the communication device and implementing the functions of the communication device in any of the aforementioned embodiments. The memory 1320 stores computer programs (or instructions) and / or data that implement the functions of the communication device in any of the aforementioned embodiments. The processor 1313 can execute the computer program stored in the memory 1320 to complete the methods performed by the communication device in any of the aforementioned embodiments. Applied to a communication device, the communication interface in the communication device 1300 can be used to interact with other communication devices, sending information to or receiving information from other communication devices.

[0304] Since the communication device 1300 provided in this embodiment can be applied to communication equipment to complete the method executed by the above-mentioned communication equipment, the technical effects it can achieve can be referred to the above-mentioned method example, and will not be repeated here.

[0305] Based on the above embodiments, this application provides a communication system including at least two communication devices, wherein the at least two communication devices can implement the methods provided in the embodiments shown in Figures 5 to 11. For example, the communication devices may be terminal devices, access network devices, or core network devices described in the foregoing embodiments.

[0306] The technical solutions provided in this application can be implemented, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented using software, they can be implemented, in whole or in part, in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a communication device, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available media may be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., digital video discs (DVDs)), or semiconductor media, etc.

[0307] In the embodiments of this application, provided there is no logical contradiction, the embodiments may reference each other. For example, the methods and / or terms between method embodiments may reference each other, the functions and / or terms between device embodiments may reference each other, and the functions and / or terms between device embodiments and method embodiments may reference each other.

[0308] Obviously, those skilled in the art can make various modifications and variations to the embodiments of this application without departing from the scope of the embodiments of this application. Therefore, if these modifications and variations to the embodiments of this application fall within the scope of the claims of the embodiments of this application and their equivalents, the embodiments of this application are also intended to include these modifications and variations.

Claims

1. A communication method, characterized in that, include: Receive first indication information, the first indication information being used to indicate that the first value of the next-hop chain corresponding to the first access network device for calculating the NCC is not used, or the first indication information being used to indicate that the NCC is not configured; After the terminal device switches from the first access network device to the second access network device, it sends a first message to the second access network device. The first message carries second indication information, which is used to indicate the first value of the NCC; or, the first message does not carry the configuration of the NCC.

2. The method as described in claim 1, characterized in that, The receiving of the first indication information includes: Before the first access network device initiates a request for the terminal device to switch to the second access network device, a second message is received from the first access network device; wherein the second message includes the first indication information and the identifier of the terminal device.

3. The method as described in claim 1, characterized in that, The receiving of the first indication information includes: After the terminal device switches from the first access network device to the second access network device, it receives a third message from the second access network device, the third message including the first indication information and the identifier of the terminal device.

4. The method according to any one of claims 1-3, characterized in that, The first key used for communication between the second access network device and the terminal device is generated based on the second key and the cell information of the second access network device. The second key is the key used for communication between the first access network device and the terminal device.

5. A communication method, characterized in that, Applied to second access network equipment, including: After the terminal device switches from the first access network device to the second access network device, it sends a third message to the core network device. The third message includes first indication information and the identifier of the terminal device. The first indication information is used to indicate that the first value of the NCC calculation for the next hop chain corresponding to the first access network device is not used, or the first indication information is used to indicate that the NCC is not configured. Receive a first message from the core network device, the first message carrying second indication information, the second indication information being used to indicate a first value of the NCC; or, the first message not carrying the configuration of the NCC.

6. The method as described in claim 5, characterized in that, Also includes: A fourth message is received from the first access network device. The fourth message is used to request the terminal device to switch to the second access network device. The fourth message includes the first indication information and the identifier of the terminal device.

7. The method as described in claim 6, characterized in that, The fourth message also includes a first key for communication between the second access network device and the terminal device. The first key is generated based on the second key and the cell information of the second access network device. The second key is a key for communication between the terminal device and the first access network device.

8. A communication method, characterized in that, Applied to terminal devices, including: Obtain the first value of NCC from the next-hop link corresponding to the first access network device; After m cell handovers, a handover command is received instructing the terminal device to handover to a third access network device. The handover command includes the second value of the NCC. In the m cell handovers, the nth cell handover instructs the terminal device to handover from the nth access network device to the (n+1)th access network device, where m is a positive integer and n is an integer from 1 to m. When n is 1, the nth access network device is the first access network device. A key for communication between the terminal device and the third access network device is determined based on the first value of the NCC, the second value of the NCC, and the first parameter; wherein the first parameter is determined based on the first value of the NCC, the value of m, and the range of values ​​of the NCC.

9. The method as described in claim 8, characterized in that, The range of values ​​for NCC indicates j possible values ​​for NCC, where j is an integer greater than 1; the method further includes: After the nth cell handover, the value of the first parameter is determined. Wherein, k indicates the first value of the NCC. This is the floor symbol.

10. The method as described in claim 9, characterized in that, The switching command also includes the first parameter.

11. The method as described in claim 9 or 10, characterized in that, After the terminal device switches to the third access network device, the value of the first parameter is updated to 0.

12. The method according to any one of claims 8-11, characterized in that, The (n+1)th key used for communication between the terminal device and the (n+1)th access network device is determined based on the nth key used when the terminal device communicates with the nth access network device and the cell information of the (n+1)th access network device.

13. A communication method, characterized in that, Applied to second access network equipment, including: Obtain time information, which is used to indicate the usage time corresponding to each security context in at least one security context of the terminal device; During a first time period after the terminal device switches from the first access network device to the second access network device, communication is conducted with the terminal device based on a first security context; wherein, the first security context is a security context used for communication between the first access network device and the terminal device, and the first time period is determined based on the usage time corresponding to the first security context.

14. The method as described in claim 13, characterized in that, Also includes: A fourth message is received from the first access network device. The fourth message is used to request the terminal device to switch to the second access network device. The fourth message includes information for indicating that the security context should not be updated and information for indicating the first security context.

15. The method as described in claim 13 or 14, characterized in that, Also includes: During the first time period, a fifth message is sent to the third access network device. The fifth message is used to request the terminal device to switch to the third access network device. The fifth message includes information indicating that the security context should not be updated and information indicating the first security context.

16. The method as described in claim 13 or 14, characterized in that, Also includes: After the first time period, a fifth message is sent to the third access network device, the fifth message being used to request the terminal device to switch to the third access network device; The security context used for communication between the terminal device and the third access network device is different from the first security context.

17. The method as described in claim 13 or 14, characterized in that, Also includes: After the first time period, a Radio Resource Control (RRC) reconfiguration message is sent to the terminal device. The RRC reconfiguration message includes information for indicating a second security context. The second security context is used for communication between the terminal device and the second access network device. The second security context is different from the first security context.

18. A communication device, characterized in that, It includes a module for performing the method as described in any one of claims 1-7, or a module for performing the method as described in any one of claims 8-12, or a module for performing the method as described in any one of claims 13-17.

19. A communication device, characterized in that, include: A processor coupled to a memory, the processor being configured to invoke computer program instructions stored in the memory to perform the method as claimed in any one of claims 1-7, or the method as claimed in any one of claims 8-12, or the method as claimed in any one of claims 13-17.

20. A communication system, characterized in that, It includes a communication device for performing the method as described in any one of claims 1-7, or a communication device for performing the method as described in any one of claims 8-12, or a communication device for performing the method as described in any one of claims 13-17.

21. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores instructions that, when executed on a computer, cause the computer to perform the method as described in any one of claims 1-17.

22. A computer program product, characterized in that, Includes computer execution instructions, which, when executed on a computer, cause the computer to perform the method as described in any one of claims 1-17.

Citation Information

Patent Citations

  • Communication method, communication device and computer readable storage medium

    CN111565425A

  • Security information processing method and apparatus during handover process, network device, and terminal

    CN112956236A

  • Switching key determination method, switching method and device

    CN116782211A

  • Cell switching method and device

    CN117793831A

  • Handover method, network device, user equipment and communication system

    EP4175360A1