Security information processing method, communication device, and storage medium
By sending the UE's security context and capability information to candidate nodes in advance during the LTM process, the problem of difficulty in security algorithm negotiation and UP security policy synchronization in the prior art is solved, and efficient negotiation and fast handover of security information processing are achieved.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-09-30
- Publication Date
- 2026-04-02
AI Technical Summary
During the L1/L2 Triggered Mobility (LTM) process, existing technologies struggle to effectively negotiate security algorithms and synchronize user plane (UP) security policies for user equipment (UE), leading to increased latency during handover.
By sending the UE's security context and capability information to the second node in advance from the first node, the security algorithm negotiation between the candidate node and the UE is assisted, including the UE's capability information and UP security policy, thereby reducing latency during the handover process.
It enables advance negotiation of safety algorithms and synchronization of UP safety policies during the LTM process, reducing latency during handover and improving system efficiency and reliability.
Smart Images

Figure CN2024123059_02042026_PF_FP_ABST
Abstract
Description
Security information processing method, communication device, and storage medium TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of communication, and particularly relates to a security information processing method, a communication device, and a storage medium. BACKGROUND
[0002] Layer 1 / layer 2 triggered mobility (L1 / L2 Triggered Mobility, LTM) refers to a process of triggering a primary cell (PCell) or a primary secondary cell (PSCell) node change (cell switch) by a network based on a layer 1 (Layer 1, L1) measurement result through a media access control (Media Access Control, MAC) control element (Control Element, CE). In the process of primary node or primary secondary node change, the change of a master cell group (Master Cell Group, MCG) or a secondary cell group (Sencodary Cell Group, SCG) can be accompanied.
[0003] SUMMARY
[0004] The embodiments of the present disclosure provide a security information processing method, a communication device, and a storage medium.
[0005] According to a first aspect of the embodiments of the present disclosure, a security information processing method is provided, wherein the method is performed by a first node, and the method comprises: sending, to a second node, a first message, wherein the first message comprises information related to a security context of layer 1 / layer 2 triggered mobility (L1 / L2 Triggered Mobility, LTM) of a user equipment (User Equipment, UE).
[0006] According to a second aspect of the embodiments of the present disclosure, a security information processing method is provided, wherein the method is performed by a second node, and the method comprises: receiving a first message sent by a first node, wherein the first message comprises information related to a security context of layer 1 / layer 2 triggered mobility (L1 / L2 Triggered Mobility, LTM) of a user equipment (User Equipment, UE).
[0007] According to a third aspect of the embodiments of the present disclosure, a security information processing method is provided, wherein the method is performed by a user equipment (User Equipment, UE), and the method comprises: receiving a third message sent by a first node; the third message comprises first information of M second nodes; the first information of the mth second node is used to indicate a security algorithm selected by the mth second node based on capability information of the UE; and the m is a positive integer less than or equal to M.
[0008] According to a fourth aspect of the embodiments of the present disclosure, a first node is provided, and the first node comprises a sending module configured to send a first message to a second node, wherein the first message comprises information related to a security context of Layer 1 / Layer 2 triggered mobility (LTM) of a user equipment (UE).
[0009] According to a fifth aspect of the embodiments of the present disclosure, a second node is provided, and the second node comprises a receiving module configured to receive a first message sent by a first node, wherein the first message comprises information related to a security context of Layer 1 / Layer 2 triggered mobility (LTM) of a user equipment (UE).
[0010] According to a sixth aspect of the embodiments of the present disclosure, a user equipment (UE) is provided, and the UE comprises: receiving a third message sent by a first node, wherein the third message comprises first information of M second nodes, and the first information of an mth second node is used to indicate a security algorithm selected by the mth second node based on capability information of the UE, wherein m is a positive integer less than or equal to M.
[0011] According to a seventh aspect of the embodiments of the present disclosure, a communication system is provided, and the communication system comprises: a first node configured to perform the security information processing method provided in any of the technical solutions of the first aspect; a second node configured to perform the security information processing method provided in any of the technical solutions of the second aspect; and a UE configured to perform the security information processing method provided in any of the technical solutions of the third aspect.
[0012] According to an eighth aspect of the embodiments of the present disclosure, a communication device is provided, and the communication device comprises: one or more processors; and wherein the processors are used to invoke instructions to cause the communication device to perform the security information processing method provided in any of the technical solutions of the first aspect, the second aspect and / or the third aspect.
[0013] According to a ninth aspect of the embodiments of the present disclosure, a storage medium is provided, and the storage medium stores instructions, and when the instructions are run on a communication device, the communication device is caused to perform the security information processing method provided in any of the technical solutions of the first aspect, the second aspect and / or the third aspect.
[0014] According to a tenth aspect of the embodiments of the present disclosure, a program product is provided, and the program product comprises a computer program, and when the computer program is executed by a communication device, the communication device is enabled to implement the security information processing method provided in any of the technical solutions of the first aspect, the second aspect and / or the third aspect.
[0015] According to the technical solutions provided by the embodiments of the present disclosure, the first node sends the information related to the security context of the UE to the second node in advance, and compared with temporarily transmitting the information related to the security context, the delay when the security context is needed can be reduced.
[0016] It should be understood that the general description above and the detailed description below are only exemplary and explanatory and are not restrictive of the present disclosure. BRIEF DESCRIPTION OF DRAWINGS
[0017] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate implementations consistent with the present disclosure and serve to explain the principles of the present disclosure.
[0018] FIG. 1A is a schematic diagram of an architecture of a communication system according to an example embodiment;
[0019] FIG. 1B is a flow diagram of an LTM according to an example embodiment;
[0020] FIG. 1C is a flow diagram of a key derivation according to an example embodiment;
[0021] FIG. 2A is a flow diagram of a secure information processing method according to an example embodiment;
[0022] FIG. 2B is a flow diagram of a secure information processing method according to an example embodiment;
[0023] FIG. 3A is a flow diagram of a secure information processing method according to an example embodiment;
[0024] FIG. 3B is a flow diagram of a secure information processing method according to an example embodiment;
[0025] FIG. 4A is a flow diagram of a secure information processing method according to an example embodiment;
[0026] FIG. 4B is a flow diagram of a secure information processing method according to an example embodiment;
[0027] FIG. 5 is a flow diagram of a secure information processing method according to an example embodiment;
[0028] FIG. 6A is a flow diagram of a secure information processing method according to an example embodiment;
[0029] FIG. 6B is a flow diagram of a secure information processing method according to an example embodiment;
[0030] FIG. 7A is a schematic diagram of a structure of a second node according to an example embodiment;
[0031] FIG. 7B is a schematic diagram of a structure of a second node according to an example embodiment;
[0032] FIG. 7C is a schematic diagram of a structure of a user equipment according to an example embodiment;
[0033] FIG. 8A is a schematic diagram of a structure of a communication device according to an example embodiment;
[0034] FIG. 8B is a schematic diagram of a structure of a chip according to an example embodiment. DETAILED DESCRIPTION
[0035] Embodiments of the present disclosure provide a security information processing method, a communication device, a communication system and a storage medium.
[0036] The first aspect provides a security information processing method, wherein the method is performed by a first node, and the method comprises: sending, to a second node, a first message, the first message comprising information related to a security context of Layer 1 / Layer 2 triggered mobility (LTM) of a user equipment (UE).
[0037] According to the above scheme, the first node sends the information related to the security context of the UE to the second node in advance, which can reduce the delay caused by the transmission of the security context during the handover process, compared with the transmission of the information related to the security context during the handover process. In some embodiments of the first aspect, the first node is an initial base station of LTM of the UE, and the second node is a candidate base station of LTM of the UE; the first message comprises at least one of capability information of the UE and a first user plane (UP) security policy; the capability information of the UE is used for the at least one second node to determine a security algorithm supported by the UE; and the first UP security policy is used to protect a first session currently activated by the UE.
[0038] According to the above scheme, the initial base station informs the candidate node of the capability information of the UE and the first UP security policy when configuring the candidate node for LTM, so as to realize the early negotiation of the security algorithm and the early intercommunication of the first UP security policy.
[0039] In some embodiments of the first aspect, the method further comprises:
[0040] receiving a second message sent by the mth second node, the second message comprising first information of the mth second node; the first information is used to indicate a security algorithm selected by the mth second node based on the capability information of the UE, m is a positive integer less than or equal to M, and M is the total number of the second nodes.
[0041] According to the above scheme, the first node receives the second message sent by the mth second node, so as to assist the candidate node and the UE to realize the negotiation of the security algorithm between the two nodes while configuring the candidate node for the UE.
[0042] In some embodiments of the first aspect, the method further comprises: sending, to the UE, a third message, the third message comprising the first information.
[0043] The first node sends the third message, thus assisting the candidate node and the UE to implement negotiation of the security algorithm between the two while configuring the candidate node for the UE.
[0044] In some embodiments of the first aspect, the first node is a serving base station of the UE, and the second node is a candidate base station or an initial base station of the UE LTM.
[0045] In some embodiments of the first aspect, the first node is a source base station of the UE for LTM switching, and the second node is a target base station of the UE for LTM switching.
[0046] In some embodiments of the first aspect, the sending, to the second node, of the first message comprises: obtaining a second user plane (UP) security policy of a second session of the UE, and sending, to the second node, the first message comprising the second UP security policy of the second session; the second UP security policy is used to protect a second session currently activated by the UE.
[0047] Based on the above manner, the second UP security policy of the second session is obtained and then the first message is sent to the second node, so that the second UP security policy of the second session is synchronized to the second node in the first time after a new session of the UE is obtained.
[0048] In some embodiments of the first aspect, the sending, to the second node, of the first message comprises at least one of: sending, to the second node, the second UP security policy of the second session after the second UP security policy of the second session is obtained and the second session is successfully activated; and sending, to the second node, the second UP security policy of the second session before the decision to switch the UE to the second node.
[0049] The above scheme defines the second UP security policy of the second session and sends the second UP security policy to the second node after the second session is successfully activated.
[0050] In some embodiments of the first aspect, the sending, to the second node, of the UP security policy comprises: sending, to the second node, a switching request, the switching request comprising the second UP security policy.
[0051] Based on the above scheme, the second UP security policy is sent through the switching request instead of using a dedicated message, and thus the compatibility with related technologies is strong.
[0052] The second aspect provides a security information processing method, wherein the method is performed by a second node, and the method comprises:
[0053] receiving a first message sent by a first node, wherein the first message comprises information related to a security context of Layer 1 / Layer 2 triggered mobility (LTM) of a user equipment (UE).
[0054] In some embodiments of the second aspect, the first node is an initial base station of LTM of the UE, the second node is a candidate node to which the UE performs LTM switching, and the first message comprises at least one of capability information of the UE and a first user plane (UP) security policy; the capability information of the UE is used for the at least one second node to determine a security algorithm supported by the UE; and the first UP security policy is used to protect a first session currently activated by the UE.
[0055] In some embodiments of the second aspect, the method further comprises:
[0056] selecting, according to the capability information of the UE, a security algorithm for communication with the UE;
[0057] sending, to the first node, a second message comprising the security algorithm selected by the second node.
[0058] In some embodiments of the second aspect, the first node is a serving base station or a source base station of LTM switching of the UE, and the first message comprises a second UP security policy of a second session of the UE.
[0059] The third aspect provides a security information processing method, wherein the method is performed by a user equipment (UE), and the method comprises:
[0060] receiving a third message sent by a first node, wherein the third message comprises first information of M second nodes; the first information of an mth second node is used to indicate a security algorithm selected by the mth second node based on capability information of the UE; and m is a positive integer less than or equal to M.
[0061] The fourth aspect provides a first node, wherein the first node comprises:
[0062] a sending module configured to send, to a second node, a first message comprising information related to a security context of Layer 1 / Layer 2 triggered mobility (LTM) of a user equipment (UE).
[0063] The fifth aspect provides a second node, wherein the second node comprises:
[0064] The receiving module is configured to receive a first message sent by the first node, the first message comprising information related to a security context of Layer 1 / Layer 2 Triggered Mobility (LTM) of a User Equipment (UE).
[0065] The sixth aspect provides a User Equipment (UE), wherein the UE comprises:
[0066] receiving a third message sent by the first node, the third message comprising first information of M second nodes, the first information of an mth second node being used to indicate a security algorithm selected by the mth second node based on the capability information of the UE, and the m being a positive integer less than or equal to M.
[0067] The seventh aspect provides a communication device, wherein the communication device comprises one or more processors.
[0068] The processor is configured to invoke instructions to enable the communication device to perform the method provided in any one of the technical solutions of the first aspect, the second aspect and / or the third aspect.
[0069] The eighth aspect provides a communication system, wherein the communication system comprises a first node, a second node and a User Equipment (UE).
[0070] The first node is configured to perform the method provided in any one of the technical solutions of the first aspect.
[0071] The second node is configured to perform the method provided in any one of the technical solutions of the second aspect.
[0072] The UE is configured to perform the method provided in any one of the technical solutions of the third aspect.
[0073] In the ninth aspect, the embodiments of the present disclosure provide a program product, wherein the program product comprises a computer program, and the computer program, when executed by a communication device, enables the communication device to implement a security information processing method described in the optional implementation manners of the first aspect to the third aspect.
[0074] In the tenth aspect, the embodiments of the present disclosure provide a computer program, which, when executed on a computer, enables the computer to perform a security information processing method described in the optional implementation manners of the first aspect to the third aspect.
[0075] It can be understood that the above-mentioned first node, second node, UE, network device and communication system, program product and computer program are all used to perform the method provided in the embodiments of the present disclosure. Therefore, the beneficial effects that can be achieved thereby can refer to the beneficial effects in the corresponding method, which will not be described herein again.
[0076] The embodiments of the present disclosure provide a security information processing method, a communication device, a communication system and a storage medium. The embodiments of the present disclosure are not exhaustive, but only illustrate some embodiments, and are not specific limitations on the protection scope of the present disclosure. In the case of no contradiction, each step in an embodiment can be implemented as an independent embodiment, and the steps can be combined arbitrarily, for example, the mode after removing some steps in an embodiment can also be implemented as an independent embodiment, and the order of the steps in an embodiment can be exchanged arbitrarily, in addition, the optional implementation mode in an embodiment can be combined arbitrarily; in addition, the embodiments can be combined arbitrarily, for example, the steps of different embodiments can be combined arbitrarily, an embodiment can be combined with the optional implementation mode of other embodiments.
[0077] In the embodiments of the present disclosure, the terms and / or descriptions between the embodiments are consistent and can be referred to each other if there is no special description and logical conflict, and the technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationship.
[0078] The terms used in the embodiments of the present disclosure are only for the purpose of describing the specific embodiments, and not as a limitation on the present disclosure.
[0079] In the embodiments of the present disclosure, unless otherwise specified, the elements expressed in singular form, such as "one", "a", "the", "above", "preceding", "this", etc., can represent "one and only one", or "one or more", "at least one", etc. For example, in the case of using articles such as "a", "an", "the" in English, the noun after the article can be understood as singular expression, or as plural expression.
[0080] In the embodiments of the present disclosure, "plurality" means two or more.
[0081] In some embodiments, the terms "at least one of", "one or more", "a plurality of", "multiple", and the like can be replaced with each other.
[0082] In some embodiments, the description of "at least one of A, B", "A and / or B", "one of A or B", "one of A or B", etc. can include the following technical manners according to the situation: in some embodiments, A is executed (A is executed regardless of B); in some embodiments, B is executed (B is executed regardless of A); in some embodiments, A and B are selectively executed (A and B are selectively executed); in some embodiments, A and B are executed (A and B are executed). When there are more branches such as A, B, C, etc., the above description is similar.
[0083] In some embodiments, the description of "A or B" and the like can include the following technical manners according to the situation: in some embodiments, A is executed (A is executed regardless of B); in some embodiments, B is executed (B is executed regardless of A); in some embodiments, A and B are selectively executed (A and B are selectively executed). When there are more branches such as A, B, C, etc., the above description is similar.
[0084] The prefix words "first", "second" and the like in the embodiments of the present disclosure are only used to distinguish different description objects, and do not constitute limitation on the position, order, priority, quantity or content of the description objects. The description of the description objects should refer to the description in the context of the claims or embodiments, and should not constitute redundant limitation because of the use of the prefix words. For example, the description objects are "fields", and the ordinal words before "fields" in "first field" and "second field" do not limit the position or order between "fields". "First" and "second" do not limit whether the "fields" modified thereby are in the same message, nor do they limit the order of "first field" and "second field". For another example, the description objects are "levels", and the ordinal words before "levels" in "first level" and "second level" do not limit the priority between "levels". For another example, the quantity of the description objects is not limited by the ordinal words, and can be one or more. For example, "first device", wherein the quantity of "devices" can be one or more. In addition, the objects modified by different prefix words can be the same or different, for example, the description objects are "devices", and "first device" and "second device" can be the same device or different devices, and their types can be the same or different. For another example, the description objects are "information", and "first type of information" and "second type of information" can be the same information or different information, and their contents can be the same or different.
[0085] In some embodiments, "including A", "containing A", "for indicating A", "carrying A" can be interpreted as directly carrying A, or indirectly indicating A.
[0086] In some embodiments, the terms "…", "determining …", "in the case of …", "when …", "when …", "if …", "if …" and the like can be replaced with each other.
[0087] In some embodiments, the terms “greater than”, “greater than or equal to”, “not less than”, “more than”, “more than or equal to”, “not less than”, “higher than”, “higher than or equal to”, “not lower than”, “above”, and the like can be replaced with each other, and the terms “less than”, “less than or equal to”, “not greater than”, “fewer than”, “fewer than or equal to”, “not more than”, “lower than”, “lower than or equal to”, “not higher than”, “below”, and the like can be replaced with each other.
[0088] In some embodiments, an apparatus and the like can be interpreted as an entity, and can also be interpreted as virtual, and the name thereof is not limited to the name described in the embodiments. The terms “apparatus”, “equipment”, “device”, “circuit”, “network element”, “node”, “function”, “unit”, “section”, “system”, “network”, “chip”, “chip system”, “entity”, “subject”, and the like can be replaced with each other.
[0089] In some embodiments, “network” can be interpreted as including network-side devices or network functions in the network, such as access network devices, core network devices, and the like.
[0090] In some embodiments, the terms “access network device (AN device)”, “radio access network device (RAN device)”, “base station (BS)”, “radio base station”, “fixed station”, “node”, “access point”, “transmission point (TP)”, “reception point (RP)”, “transmission / reception point (TRP)”, “panel”, “antenna panel”, “antenna array”, “node (cell)”, “macro node”, “small node”, “femto node”, “pico node”, “sector”, “cell group”, “serving node”, “node (carrier)”, “component node”, “bandwidth part (BWP)”, and the like can be replaced with each other.
[0091] In some embodiments, the terms "UE (terminal)", "UE device (terminal device)", "user equipment (UE)", "user terminal", "mobile station (MS)", "mobile terminal (MT)", "subscriber station", "mobile unit", "subscriber unit", "wireless unit", "remote unit", "mobile device", "wireless device", "wireless communication device", "remote device", "mobile subscriber station", "access terminal", "mobile terminal", "wireless terminal", "remote terminal", "handset", "user agent", "mobile client", "client", and the like can be replaced with each other.
[0092] In some embodiments, the access network device, the core network device, or the network device can be replaced with the UE. For example, the structure in which the communication between the access network device, the core network device, or the network device and the UE is replaced with the communication between a plurality of UEs (e.g., device-to-device (D2D), vehicle-to-everything (V2X), and the like) can also apply the embodiments of the present disclosure. In this case, it can also be configured as a structure in which the UE has all or part of the functions that the access network device has. In addition, the terms "uplink", "downlink", and the like can also be replaced with terms corresponding to the inter-UE communication (e.g., "side"). For example, the uplink channel, the downlink channel, and the like can be replaced with the side channel, and the uplink, the downlink, and the like can be replaced with the sidelink.
[0093] In some embodiments, the UE can be replaced with the access network device, the core network device, or the network device. In this case, it can also be configured as a structure in which the access network device, the core network device, or the network device has all or part of the functions that the UE has.
[0094] In some embodiments, the acquisition of data, information, and the like can comply with the laws and regulations of the country where the location is.
[0095] In some embodiments, data, information, etc. can be acquired after obtaining user consent.
[0096] In addition, each element, each row, or each column in the table of the embodiments of the present disclosure can be implemented as an independent embodiment, and any combination of any element, any row, or any column can also be implemented as an independent embodiment.
[0097] FIG. 1A is a schematic diagram of an architecture of a communication system according to an embodiment of the present disclosure.
[0098] As shown in FIG. 1A, the communication system 100 includes a terminal 101 and a network device 102. The network device 102 can include an access network device and / or a core network device. The terminal is also referred to as a UE.
[0099] In some embodiments, the terminal 101 includes at least one of a mobile phone, a wearable device, an Internet of Things device, a car with communication function, a smart car, a Pad, a computer with wireless transceiver function, a virtual reality (VR) UE device, an augmented reality (AR) UE device, a wireless UE device in industrial control, a wireless UE device in self-driving, a wireless UE device in remote medical surgery, a wireless UE device in smart grid, a wireless UE device in transportation safety, a wireless UE device in smart city, a wireless UE device in smart home, etc., but is not limited thereto.
[0100] In some embodiments, the UE is also referred to as a User Equipment (UE).
[0101] In some embodiments, the access network device may, for example, be at least one of a node or a device that accesses a UE to a wireless network, and the access network device may, for example, include at least one of an evolved NodeB (eNB) in a 5G communication system, a next generation eNB (ng-eNB), a next generation NodeB (gNB), a node B (NB), a home node B (HNB), a home evolved node B (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an Open RAN, a Cloud RAN, a base station in other communication systems, an access node in a Wi-Fi system, but is not limited thereto.
[0102] In some embodiments, the technical means of the present disclosure can be applicable to an Open RAN architecture, in which case the interfaces between or within the access network devices involved in the embodiments of the present disclosure can become internal interfaces of the Open RAN, and the processes and information interactions between these internal interfaces can be implemented through software or programs.
[0103] In some embodiments, the access network device can be composed of a central unit (CU) and a distributed unit (DU), where the CU can also be referred to as a control unit. The CU-DU structure can split the protocol layers of the access network device, and some of the protocol layers can be controlled by the CU, while the rest or all of the protocol layers can be distributed in the DU and controlled by the CU, but is not limited thereto.
[0104] In some embodiments, the core network device can be one device including the first network element, or a plurality of devices or device groups each including the first network element. The network element can be virtual or physical. The core network may, for example, include at least one of an evolved packet core (EPC), a 5G core network (5GCN), and a next generation core (NGC).
[0105] It can be understood that the communication system described in the embodiments of the present disclosure is for more clearly illustrating the technical means of the embodiments of the present disclosure, and does not constitute a limitation on the technical means provided by the embodiments of the present disclosure. It can be known by those skilled in the art that, as the system architecture evolves and new service scenarios appear, the technical means provided by the embodiments of the present disclosure are also applicable to similar technical problems.
[0106] The following embodiments of the present disclosure can be applied to the communication system 100 shown in FIG. 1A or part of the subjects, but are not limited thereto. The subjects shown in FIG. 1A are exemplary, and the communication system can include all or part of the subjects in FIG. 1A, or other subjects other than FIG. 1A. The number and form of each subject is arbitrary, and the connection relationship between the subjects is exemplary. The subjects can be connected or not connected, and the connection can be in any way, can be direct connection or indirect connection, can be wired connection or wireless connection.
[0107] Embodiments of the present disclosure can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New radio access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (Bluetooth (registered trademark)), Public Land Mobile Network (PLMN) network, Device-to-Device (D2D) system, Machine to Machine (M2M) system, Internet of Things (IoT) system, Vehicle-to-Everything (V2X), system using other resources, next-generation system extended based on them, and the like. In addition, a plurality of systems can be combined (for example, LTE and NR can be combined).
[0108] LTM supports intra-frequency and inter-frequency mobility, including migration to inter-frequency cells other than the current cell. In some techniques, only intra-DU LTM and intra-DU LTM are supported. In other embodiments, NR mobility enhancements are extended to LTM across CUs, which can include, but is not limited to, at least one of the following scenarios:
[0109] Example 1: CU acts as MN when no DU is configured;
[0110] Example 2: CU acts as SN when NR-DC is configured, and MCG remains unchanged;
[0111] Example 3: CU acts as MN when NR-DC is configured, and SCG remains unchanged or is released.
[0112] In the process of primary cell or primary secondary cell change, the change of Master Cell Group (MCG) or Secondary Cell Group (SCG) can be accompanied. In LTM, the next generation NodeB (gNB) receives L1 measurement report from User Equipment (UE), and based on this, the gNB changes the serving cell of the UE through the cell switch command issued by the MAC CE. The cell switch command indicates the LTM candidate cell configuration provided by the gNB to the UE in advance through Radio Resource Control (RRC) signaling. The UE accesses the target cell indicated in the received cell switch command. LTM can be used to reduce mobility delay. LTM candidate cell configuration can only be added, modified and released by the network through RRC signaling. LTM supports subsequent LTM, which refers to LTM based on candidate cells without RRC reconfiguration between network devices and UE. That is, after the mobility operation is performed, the UE does not autonomously delete the configuration information of LTM, and the configuration information of LTM can continue to be used even without RRC reconfiguration and update, for triggering subsequent LTM (Subsequent LTM). For example, the configuration information of LTM can include the information of candidate cells.
[0113] LTM supports intra-frequency or inter-frequency cell change. In some scenarios, only Distributed Unit (DU) internal LTM and DU internal LTM are supported. In some scenarios, New Radio (NR) mobility enhancement is extended to inter-CU or inter-node or inter-gNB (inter-CU, inter-node, inter-gNB) LTM. Exemplarily, the inter-CU or inter-node or inter-gNB LTM supports the following scenarios:
[0114] Example 1: CU acts as MN when no DU is configured;
[0115] Example 2: Configure NR-DC, CU acts as SN and MCG is unchanged.
[0116] Example 3: CU acts as MN and SCG is unchanged or SCG is released when configuring NR-DC. For inter-CU LTM, multiple candidate gNB-CUs will participate in the migration flow.
[0117] The signaling flow of LTM can be shown in FIG. IB, including the following three stages:
[0118] Stage 1: Stage 1 is also the LTM preparation stage, in which the initial gNB decides candidate cells and initiates cross-node interaction for LTM preparation across CUs based on L3 RRC measurement report. After the interaction, the initial gNB provides LTM configuration to the UE according to the RRC configuration of multiple candidate cells.
[0119] The initial gNB decides candidate cells and initiates inter-node interaction for inter-CU LTM preparation. After the interaction, the initial gNB provides LTM configuration to the UE with RRC configuration of multiple candidate cells.
[0120] Stage 2: Stage 2 is also the LTM initialization node, in which the UE sends L1 measurement report to the initial gNB. After receiving the cell switch command MAC CE, the UE switches to a candidate cell. In order to support RACH-less LTM, the UE can be synchronized with the candidate cell in advance, specifically, before receiving the cell switch command, the UE performs DL and UL synchronization with the candidate cell.
[0121] Stage 3: Subsequent LTM stage, in which steps similar to steps 8-14 are performed. The subsequent LTM is triggered by the current serving gNB, which itself also belongs to one of the candidate gNBs of the candidate LTM.
[0122] The key update synchronization between the UE and the gNB in the non-LTM scenario switching process can be as follows: During the switching of the inter-CU mobility process, the synchronization of the AS security key between the UE and the target gNB is achieved by using the NCC value of the source gNB, which is then forwarded to the target gNB and the UE in the RRC reconfiguration signaling. When it is necessary to establish an initial AS security context between the UE and the gNB, the AMF and the UE will derive K gNB and the Next Hop, NH) parameter (NCC(NH chain Counter) is associated with each K gNB and the NH parameter. Each K gNB is associated with a NCC corresponding to the NH value.
[0123] During Xn switching, if the source gNB has an unused {NH, NCC} pair, vertical key derivation should be performed. The source gNB should first derivation from the currently active K. gNB (If it's a horizontal key derivation) or calculate K from NH (if it's a vertical key derivation) NG-RAN* Then, the source gNB will {K NG-RAN* The NCC forwards the data to the target gNB. The target gNB should directly forward the received K... NG-RAN* K as used with UE gNB The target gNB should receive the NCC value from the source gNB and match it with the K value. gNB Related. The target gNB includes the received NCC in a prepared Handover (HO) command message, which is sent to the source gNB using a transparent container, and then forwarded to the UE by the source gNB.
[0124] Regardless of whether a handover is performed within the gNB-CU, an Xn handover, or an N2 handover, the UE's behavior is the same. The only difference is that during an intra-gNB-CU handover, the UE may retain the same key according to the gNB's instructions. The UE's behavior is also the same under conditional handover scenarios; for example, if the UE should use K... NG-RAN* The parameters of the target cell selected in the derivation. Figure 1C is a schematic diagram of a key level derivation.
[0125] If the NCC value in the HO command message received by the UE from the target gNB via the source gNB is equal to the currently active K gNB The associated NCC value then the UE is from the currently active K gNB Derivation of K from the target PCI and its frequency (ARFCN-DL or EARFCN-DL) NG-RAN* .
[0126] If the NCC value received by the UE is different from the NCC value associated with the currently activated gNB, the UE should first calculate the iteratively synchronized locally saved NH parameter and increase the NCC value until it matches the NCC value received from the source gNB through the HO command message. When the NCC value matches, the UE uses the synchronized NH parameter and the target physical cell identity (Physical Cell Identity, PCI) PCI and its frequency Absolute Radio-Frequency Channel Number Downlink (ARFCN-DL) or ((Universal Mobile Telecommunications System, UMTS) Terrestrial Radio Access Network, E-UTRAN) Absolute Radio Frequency Channel Number Downlink (EARFCN-DL) to calculate K NG-RAN* .
[0127] The UE should use K NG-RAN* as K gNB .
[0128] In the current cross-gNB handover process, the security-related configurations (such as NCC, K NG-RAN* ) are first synchronized between the source gNB and the target gNB, and then sent to the UE by the source gNB in the RRC reconfiguration of each handover. NCC is used for key synchronization between the UE and the target gNB as described above. However, with the mobility enhancement process designed for cross-gNB LTM, the RRC reconfiguration is no longer sent by the source gNB in each handover. Then, how to update the NCC value and send it to the UE for key synchronization in each handover becomes an open question. In addition to the key synchronization problem based on the NCC value, there are other security-related configurations, including the AS security algorithms that need to be negotiated between the UE and the candidate gNB, and the UP security policy that needs to be applied to the PDU session established by the connected UE. The parameters required for AS key refresh, AS security algorithms, and UP security policy are all part of the AS security context in the UE and gNB, which need to be synchronized during the handover process. Therefore, it is necessary to study how the UE and the candidate gNB negotiate the AS security algorithm, and how to correctly apply the UP security policy to the PDU session during the LTM handover between the candidate gNBs.
[0129] As shown in FIG. 2A, the embodiments of the present disclosure provide a security information processing method, which is executed by the communication system shown in FIG. 1A. The method can include:
[0130] S2101: A first node sends a first message to at least one second node.
[0131] In some embodiments, the first node and the second node can both be access network nodes.
[0132] In some embodiments, the first node can be an initial base station for a UE’s LTM handover. The second node can be a candidate base station for the UE’s LTM handover.
[0133] In some embodiments, the first node can be a current serving base station for a UE. The second node can be a base station that will provide service to the UE later.
[0134] In some embodiments, the first node sends the first message to the at least one second node in an LTM preparation phase.
[0135] In some embodiments, the first node can send the first message to the at least one second node over an X2 interface, an Xn interface, or a backhaul link.
[0136] In some embodiments, the first message includes information related to a security context for a Layer 1 / Layer 2 triggered mobility (LTM) of a user equipment (UE).
[0137] In some embodiments, the first message can include information related to a security context for the UE’s LTM and / or a security capability of the UE.
[0138] In some embodiments, the first message includes at least one of the following:
[0139] a UE identity, used to identify the UE;
[0140] capability information of the UE, used to indicate at least a security capability of the UE;
[0141] a first UP security policy, used to protect a first session currently activated by the UE.
[0142] In some embodiments, the UE identity can be various types of UE identities, for example, the UE’s identity can be but not limited to at least one of the following:
[0143] a cell radio network temporary identifier (C-RNTI)
[0144] an international mobile equipment identity (IMEI);
[0145] International Mobile Subscriber Identity (IMSI);
[0146] Globally Unique Temporary Identifier (GPSI).
[0147] Temporary Mobile Subscriber Identity (TMSI).
[0148] In some embodiments, the capability information of the UE can comprise an identification of a security algorithm or security algorithms supported by the UE.
[0149] In some embodiments, the first UE security policy can be used to indicate whether the UP of the first session needs to be integrity protected and / or confidentiality protected.
[0150] In some embodiments, the capability information of the UE is used by the at least one second node to determine a security algorithm supported by the UE.
[0151] In some other embodiments, the first UP security policy is used to protect a first session currently activated by the UE.
[0152] In some embodiments, the first message can be a handover request sent to one or more second nodes in a LTM candidate preparation stage. The handover request directly carries an identification of the UE and the capability information of the UE. In some embodiments, the handover request also carries a first UP security policy of one or more first sessions currently activated between the UE and the first node.
[0153] In some embodiments, the first message comprises a session identification of each first session and a first UP security policy of the corresponding first session.
[0154] In some embodiments, the first message can be a handover request message, which is used as the first message but does not mean that the UE needs to handover to the second node at this time.
[0155] S2102: The second node selects a security algorithm.
[0156] In some embodiments, the second node selects a security algorithm supported by both the UE and the second node according to the capability information of the UE provided by the first node.
[0157] Exemplarily, the second node can select, according to the capability information of the first node, a security algorithm for integrity protection supported by both the UE and the second node. Exemplarily, the second node can select, according to the capability information of the first node, a security algorithm for confidentiality protection supported by both the UE and the second node.
[0158] S2103: The second node sends a second message to the first node.
[0159] In some embodiments, the second message comprises first information. The first information is used to indicate a security algorithm selected by the mth second node based on the capability information of the UE. Exemplarily, the first information can be the security algorithm selected by the mth second node or an algorithm identifier of the security algorithm selected by the mth second node.
[0160] In some embodiments, the second message of the mth second node can comprise at least one of the following:
[0161] a node identifier of the mth second node;
[0162] a node configuration of the mth second node;
[0163] a security algorithm selected by the mth second node;
[0164] an algorithm identifier of the security algorithm selected by the mth second node.
[0165] In some embodiments, if the first message is a handover request message, the second message can be a handover request acknowledge message. Although the first node and the second node interact with the handover request message and the handover request acknowledge message, it does not mean that the UE needs to perform handover.
[0166] S2104: The first node sends a third message to the UE.
[0167] In some embodiments, the third message comprises the first information. In some embodiments, the third message comprises a node configuration of each second node, and the first information belongs to part of the node configuration of the second node.
[0168] In some embodiments, the first node encapsulates the second message of each second node in the third message in an RRC container and sends it to the UE.
[0169] In some embodiments, the third message can be an RRC configuration message. In an example, the RRC configuration message can be an RRC reconfiguration message.
[0170] In some embodiments, the third message can further comprise a first parameter. In some embodiments, the first parameter is used by the UE to generate a security key for communication with the first node.
[0171] In some embodiments, the third parameter can be a value of a next hop chaining counter (NCC). The value of the NCC can be used by the UE to determine a parameter of a security key for communicating with the first node.
[0172] In some embodiments, the term "information" can be mutually replaceable with the terms "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "field", "data", and the like.
[0173] In some embodiments, "acquire", "obtain", "get", "receive", "transmit", "bidirectional transmission", "send and / or receive" can be mutually replaceable, which can be interpreted as receiving from other subjects, acquiring from protocols, acquiring from higher layers, obtaining by self-processing, autonomously implementing, and the like. The protocols include at least one of 3GPP protocols, Wi-Fi protocols, audio and / or video protocols, and the like. In some embodiments, the term "send" can be mutually replaceable with the terms "transmit", "report", "transmit", and the like.
[0174] In some embodiments, the steps in the present embodiments S2101 to S2104 can be independently implemented, or can be combined and implemented in any order without contradiction. For example, after the second node receives the first message, the second node is also deleted from the candidate nodes of the UE, then the second node can not perform S2102, and then there is naturally no subsequent steps S2103 to S2104.
[0175] As shown in FIG. 2B, the present disclosure provides a security information processing method, which is executed by the communication system shown in FIG. 1A. The method can include:
[0176] S2201: The first node sends a first message to at least one second node.
[0177] In some embodiments, the first node and the second node can both be access network nodes.
[0178] In some embodiments, the first node can be an initial base station of LTM switching of the UE, and the second node can be a candidate base station of LTM switching of the UE.
[0179] In some embodiments, the first node can be a current serving base station of the UE, and the second node can be a neighboring node of the first node.
[0180] In some embodiments, the first node can be a source base station for the UE to perform LTM handover, and the second node can be a target base station for the UE to perform LTM handover.
[0181] In some embodiments, the first node sends the first message to the at least one second node in an LTM preparation phase.
[0182] In some embodiments, the first node can send the first message to the at least one second node through an X2 interface, an Xn interface, or a backhaul link.
[0183] In some embodiments, the first message comprises information related to a security context of Layer 1 / Layer 2 triggered mobility (LTM) of a user equipment (UE).
[0184] In some embodiments, the first message comprises at least one of the following:
[0185] an identifier of the UE, which can refer to the identifier of the UE in any of the preceding embodiments and will not be repeated here;
[0186] a second UP security policy for protecting a second session currently activated by the UE;
[0187] a session identifier of the second session.
[0188] In some embodiments, the second session can be any one of the sessions currently activated by the UE. There can be one or more second sessions. The second UP security policies of different second sessions can be the same or different.
[0189] In some embodiments, the first node obtains a second UP security policy of a second session of the UE, and sends the first message to the second node, wherein the first message comprises the second UP security policy of the second session; the second UP security policy is used to protect the second session currently activated by the UE.
[0190] For example, the first node requests the second UP security policy of the second session from a core network node, and sends the first message to the second node. Further, after obtaining the second UP security policy of the second session and successfully activating the second session, the first node sends the second UP security policy to the second node.
[0191] For another example, the first node determines the second node to which the UE is to be handed over based on a Layer 3 measurement report of the UE, and sends the first message to the second node before the UE is handed over to the second node. Further, in a preparation phase of the UE being handed over to the second node, the first node sends the second UP security policy to the second node.
[0192] In some embodiments, the second UP security policy is used to protect a second session currently activated by the UE.
[0193] In some embodiments, if the first node is an initial base station of the UE, the first node can further send the second UP security policy to the second node in a candidate base station configuration procedure for LTM of the UE.
[0194] In some embodiments, the first message is a handover request message.
[0195] S2202: The second node stores the second UP security policy.
[0196] In some embodiments, after the second node stores the second UP security policy, the UE switches to the second node, the second node can directly protect a second session of the UE based on the locally stored second UP security policy, so that the second node does not need to request the second UP security policy from the core network or temporarily request the second UP security policy from the first node.
[0197] S2203: The second node sends a second message.
[0198] In some embodiments, if the first message is a handover request message, the second message can be a handover request acknowledgement message.
[0199] In some embodiments, sending the second message can be an optional step, for example, if the first message is a notification message, the second node does not need to respond to the first node.
[0200] In some embodiments, the term "information" can be mutually replaced with the terms "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "field", "data", and the like.
[0201] In some embodiments, "obtain", "get", "receive", "transmit", "bidirectional transmission", "send and / or receive" can be mutually replaced, which can be interpreted as receiving from other subjects, obtaining from protocols, obtaining from higher layers, obtaining by self-processing, autonomous implementation, and the like. The protocol, for example, includes at least one of 3GPP protocol, Wi-Fi protocol, audio and / or video protocol. In some embodiments, the term "send" can be mutually replaced with the terms "transmit", "report", "transmit", and the like.
[0202] In some embodiments, the steps in the embodiments S2201 to S2203 can be implemented independently, or can be combined and implemented in any order without contradiction. In some embodiments, S2203 is an optional step. For example, the first node can default that the second node receives the first message without the second node specifically replying to the second message for confirmation.
[0203] It is worth noting that in the embodiments of the present disclosure, both the first session and the second session belong to the current active session of the UE. The embodiment of FIG. 2A can be a special case of the embodiment of FIG. 2B.
[0204] As shown in FIG. 3A, the embodiments of the present disclosure provide a security information processing method, wherein the method is performed by a first node. The method can include:
[0205] S3101: sending a first message.
[0206] In some embodiments, the first node sends the first message to at least one second node.
[0207] In some embodiments, the first node is an initial base station of an LTM of the UE, and the second node is a candidate base station of the LTM of the UE.
[0208] In some embodiments, the first message includes at least one of capability information of the UE and a first user plane (UP) security policy; the capability information of the UE is used for the at least one second node to determine a security algorithm supported by the UE; and the first UP security policy is used for protecting a first session currently activated by the UE.
[0209] For example, the message content of the first message can be as in the embodiment of FIG. 2A, which is not repeated here. For another example, the optional implementation of the first node sending the first message can refer to any one of the optional implementations of S2101 in FIG. 2A.
[0210] In some embodiments, the related descriptions of the UE, the network device, the first signal, and the like can refer to the embodiments of FIG. 2A, which are not repeated here.
[0211] S3102: receiving a second message.
[0212] In some embodiments, the first node receives the second message sent by at least one or more second nodes.
[0213] In some embodiments, the first node receives a second message sent by the mth second node. The second message includes first information of the mth second node. The first information is used to indicate a security algorithm selected by the mth second node based on the capability information of the UE, m is a positive integer less than or equal to M, and M is the total number of the second nodes.
[0214] Exemplarily, the message content of the second message can be as in the corresponding embodiment of FIG. 2A, which will not be repeated here.
[0215] S3103: sending a third message.
[0216] In some embodiments, the third message is sent to the UE.
[0217] In some embodiments, an RRC message is sent to the UE, and the RRC message can include node configurations of the respective candidate nodes. Exemplarily, the node configuration can include a node identifier of the candidate node and / or a security context associated with the candidate node. Here, the security context associated with the candidate node can include a security algorithm or an algorithm identifier selected by the candidate node.
[0218] In some embodiments, the message content of the third message and the optional implementation of sending the third message by the first node can refer to the corresponding embodiment of FIG. 2A, which will not be repeated here.
[0219] It is worth noting that both S3102 and S3103 are optional steps. For example, after receiving the first message, the second node is no longer a candidate node of the UE, and the first node will not receive the second message, and thus will not send the third message.
[0220] As shown in FIG. 3B, the embodiments of the present disclosure provide a security information processing method, wherein the method is performed by a first node. The method can include:
[0221] S3201: sending a first message.
[0222] In some embodiments, the first node sends the first message to at least one second node.
[0223] In some embodiments, the first node is an initial base station of an LTM of the UE, and the second node is a candidate base station of the LTM of the UE.
[0224] In some embodiments, the first node is a current serving base station of the UE, and the second node is a candidate base station of the LTM of the UE.
[0225] In some embodiments, the first node is a source base station of the UE for LTM switching, and the second node is a target base station of the UE for LTM switching.
[0226] In some embodiments, the first message comprises a second UP security policy and / or a session ID of a second session. For example, the related information of the second UP security policy related information can refer to the related description of the corresponding embodiment of FIG. 2B, which is not repeated here.
[0227] For example, the optional implementation of the first node sending the first message can refer to any one of the optional implementations of S2201 of FIG. 2B.
[0228] S3202: receiving a second message.
[0229] In some embodiments, the first node receives the second message sent by the second node. For example, the first node receives the second message sent by one node.
[0230] In some embodiments, the related content of the second message can refer to the corresponding embodiment of FIG. 2B, which is not repeated here.
[0231] It is worth noting that S3202 can be an optional step, for example, after the first node sends the first message, it can be assumed that the second node can successfully receive the first message, and the second message will not be sent specially.
[0232] As shown in FIG. 4A, the embodiments of the present disclosure provide a security information processing method, which is executed by a second node, and the method can comprise:
[0233] S4101: receiving a first message.
[0234] In some embodiments, the second node receives the first message sent by the first node.
[0235] In some embodiments, the first node is an initial base station of an LTM of the UE, and the second node is a candidate base station of the UE LTM; the first message comprises at least one of capability information of the UE and a first user plane UP security policy; the capability information of the UE is used for the at least one second node to determine a security algorithm supported by the UE; and the first UP security policy is used for protecting a first session currently activated by the UE.
[0236] S4102: selecting a security algorithm.
[0237] In some embodiments, the security algorithm is selected according to the capability information of the UE.
[0238] In some embodiments, the operation of the second node selecting the security algorithm can refer to the related description of the corresponding embodiment of FIG. 2A, which is not repeated here.
[0239] S4103: sending a second message.
[0240] In some embodiments, the second node sends a second message to the first node.
[0241] In some embodiments, the message content of the second message and / or optional implementation of sending the second message can refer to the corresponding S2103 of FIG. 2A, which will not be repeated here.
[0242] As shown in FIG. 4B, the embodiments of the present disclosure provide a security information processing method, which is performed by a second node. The method can include:
[0243] S4201: receiving a first message.
[0244] In some embodiments, the second node receives the first message sent by the first node.
[0245] In some embodiments, the first node is an initial base station of an LTM of the UE, and the second node is a candidate base station of the UE LTM.
[0246] In some embodiments, the first node is a serving base station of the UE or a source base station of LTM switching, and the first message includes a second user plane (UP) security policy of a second session.
[0247] In some embodiments, the first session and the second session can be collectively referred to as a session of the UE or an active session of the UE.
[0248] S4202: sending a second message.
[0249] In some embodiments, the message content of the second message and / or optional implementation of sending the second message can refer to the corresponding embodiments of FIG. 2B. In some embodiments, the sending of the second message is an optional step. For example, the first node and the second node both belong to network nodes, and it is considered that they are trustworthy and / or stable to each other. Therefore, the first node can default that the second node receives the first message, and the second node does not need to specially return the second message.
[0250] As shown in FIG. 5, the embodiments of the present disclosure provide a security information processing method, which is performed by a user equipment (UE). The method can include:
[0251] S5101: receiving a third message.
[0252] In some embodiments, the third message can include configuration information and / or a first parameter of each candidate node.
[0253] In some embodiments, the content description of the third message can refer to the corresponding embodiments of FIG. 2A.
[0254] The embodiments of the present disclosure provide a security information processing method, which can be used to implement complete security context synchronization when the UE performs LTM switching. Exemplarily, the security context synchronization can include negotiated AS security algorithms and UP security policy applied to the current PDU session.
[0255] In some embodiments, as shown in FIG. 6A, in order to implement the enhancement of inter-gNB LTM, the RRC configuration of the candidate gNB can be pre-configured by the initial gNB and delivered to the UE in the LTM preparation phase.
[0256] In the LTM preparation phase, the UE security capability is sent by the initial gNB to the candidate gNB. Each candidate gNB selects AS security algorithms for the AS security of the UE based on the UE security capability and the security capability of the candidate gNB. Then, each candidate gNB includes the selected AS security algorithms in the LTM configuration sent to the UE via the initial gNB.
[0257] In addition, during the LTM preparation, there can be an active PDU session running between the UE and the initial gNB, for which the UP security is activated based on the UP security policy received from the core network in the initial gNB. The present disclosure proposes that the UP security policy related to the specific active PDU session is also sent by the initial gNB to the candidate gNB in the LTM preparation phase. If the PDU session remains unchanged during the LTM switching, the target gNB (one of the candidate gNBs) applies the UP security policy received in the LTM preparation phase to the PDU session. If the PDU session has changed, i.e., the old PDU session is released and a new PDU session is established, it is necessary to configure the UP security policy of the new PDU session again on the candidate gNB through the LTM preparation.
[0258] As shown in FIG. 6B, the security algorithm negotiation and UP security policy in inter-gNB LTM can include:
[0259] 1. The connected UE sends an RRC measurement report to the serving / source gNB.
[0260] 2. The serving / source gNB decides to prepare LTM for candidate gNBs.
[0261] 3. The serving / source gNB sends a handover request to each candidate gNB, which includes the UE security capability and the UP security policy associated with the current active PDU session (e.g., session 1) of the UE. The UP security policy is received from the core network (SMF) during the PDU session establishment and stored in the serving / source gNB.
[0262] 4. Each candidate gNB selects the AS security algorithms for the UE's AS security based on the received UE security capabilities and the candidate gNB's own security capabilities, and the list of algorithm priorities configured in the candidate gNB. The candidate gNB then stores the selected AS security algorithms in the LTM configuration to send to the UE.
[0263] Each candidate gNB also stores the received UP security policy associated with the currently active PDU session (e.g. session 1).
[0264] 5. Each candidate gNB returns the LTM configuration to the serving / source UE through the handover request acknowledgement.
[0265] 6. The serving / source gNB sends its own and the candidate gNBs' LTM configurations to the UE. The serving / source gNB includes NCC1 in the RRC reconfiguration message. If the serving / source gNB has unused NHs, the configured NCC value NCC1 = 1. If the serving / source gNB does not have any unused NHs, the configured NCC value NCC1 = 0.
[0266] 7-11. The LTM handover is performed with the synchronization key update of the AS security and the UE is handed over to gNB1.
[0267] 7. The UE sends a layer 1 measurement report to the serving or source base station (e.g. gNB0);
[0268] 8. After selecting the target gNB (candidate gNB1), the serving / source gNB determines whether it needs to trigger the LTM procedure. If the serving / source gNB does not have any unused NHs, the serving / source gNB performs the horizontal key derivation, i.e. derives K gNB0 derives K NB-RAN * (i.e. K NG-RAN * = KDF(K gNB0 , cell identity)). If the serving / source gNB has unused NHs (associated with NCC1), the serving / source gNB performs the vertical key derivation, i.e. derives K NB-RAN * (i.e. K NG-RAN * = KDF(NH1, cell identity)).
[0269] 9. The serving / source gNB sends the derived K NB-RAN * to candidate gNB1 and the NCC value (i.e. NCC1) used for the derivation of K NB-RAN *. gNB1 uses K NB-RAN * as K gNB1 and returns the NCC value (NCC1) to the serving / source gNB.
[0270] 10. The serving / source gNB sends a MAC CE message to the UE, which indicates the target gNB (candidate gNB1). In some embodiments, the MAC CE can include an indication of the key update type (i.e., first indication information).
[0271] 11. Upon receiving the MAC CE from the serving / source gNB, the subsequent steps can be performed. In one example, the UE first determines the key update type based on the pre-configured cell identity of the target gNB or based on the indication of the key update type received through the MAC CE message. If the indication is by K AMF update, the UE performs a derivation, i.e., K gNB = KDF (uplink NAS COUNT, K AMF ). In another embodiment, if the indication is by K gNB update, the UE performs a horizontal key derivation (i.e., K NG-RAN * <- KDF (K gNB0 , cell identity)); if the indication is by NH update, the UE selects the NCC1 pre-configured by the serving / source gNB in the LTM preparation phase to perform a vertical key derivation, i.e., to derive NH and K NG-RAN * (i.e., NH1 = KDF (NH, K AMF ), K NG-RAN * <- KDF (NH1, cell identity)). In some embodiments, the UE leaves from the serving / source gNB and applies the configuration of the target gNB (candidate gNB1), which includes using K NG-RAN * as K gNB1 to be used for gNB1.
[0272] 12-14. After completing the path switching procedure with the AMF, the LTM switching is completed. The AMF generates a new pair of NH and NCC (NH2, NCC2) and passes them to gNB1, where the new NCC value (NCC2) is sent to the UE through RRC reconfiguration.
[0273] 12. The UE sends an RRC reconfiguration complete message to gNB1.
[0274] 13a. The target gNB (gNB1) sends an N2 path switch request to the AMF, which includes an LTM switching indication (i.e., second indication information) in the request.
[0275] 13b. Upon receiving the N2 path switch request, the AMF updates the NH (e.g., from NH1 to NH2) and increments the corresponding NCC value (e.g., from NCC1 to NCC2).
[0276] 13c. The AMF returns the new NH and NCC (i.e. NH2 and NCC2) to gNB1 in the N2 path switch response message.
[0277] 14. The received LTM handover indication, gNB1 forwards or transmits the new NCC value (NCC2) by NAS signaling from the AMF, so that the UE receives the updated NCC value. The NCC value is the value of the first parameter mentioned above.
[0278] 15. The user data of PDU session 1 is switched from gNB0 to gNB1, and gNB1 applies the UP security policy received from gNB0 in the LTM preparation phase to protect the user data.
[0279] 16. When connected to gNB1, the UE releases PDU session 1 and establishes a new PDU session (e.g. session 2) through gNB1, and gNB1 receives a new UP security policy associated with PDU session 2 from the core network (e.g. SMF).
[0280] 17. After the activation of the new UP security, gNB1 decides to perform LTM candidate preparation.
[0281] 18. gNB1 sends a handover request to the candidate gNB (gNB2), which includes the UP security policy associated with the current active PDU session 2 of the UE.
[0282] 19. gNB2 stores the received UP security policy associated with the current active PDU session 2.
[0283] 20. gNB2 returns the LTM configuration to gNB1 through the handover request acknowledgement.
[0284] 21-25. LTM handover is performed together with the synchronization key update of AS security, and the UE switches to gNB2.
[0285] 21. During the process of UE keeping moving, the UE sends an L1 measurement report to the serving / source gNB (gNB1).
[0286] 22. After selecting the target gNB (candidate gNB2), the serving / source gNB (gNB1) determines whether to trigger the LTM process. Since the serving / source gNB has an unused NH (NH2 associated with NCC2), the serving / source gNB performs vertical key derivation, i.e. derives K NB-RAN * (i.e. K NG-RAN * from the unused NH.
[0287] In some embodiments, in case of intra-CU handover is triggered later, the serving / source gNB does not have any unused NH, then the serving / source gNB performs horizontal key derivation, i.e. K gNB1 is derived from K NB-RAN *(i.e. K NG-RAN *← KDF(K gNB1 , cell identity)).
[0288] 23a. The serving / source gNB (gNB1) sends the derived K NB-RAN *to the candidate gNB2 along with the NCC value (i.e. NCC2) used for K NB-RAN *derivation.
[0289] 23b. The gNB2 uses K NB-RAN *as K gNB2 ;
[0290] 23c. The NCC value (NCC2) is returned to the serving / source gNB.
[0291] 24. The gNB1 sends a MAC CE message to the UE indicating the target gNB (candidate gNB2). In some embodiments, the MAC CE can include an indication of the key update type (i.e. first indication information).
[0292] 25. The UE determines first the handover key update type based on the preconfigured cell identity of the target gNB or based on the indication of the key update type received through the MAC CE message. If the indication is updated by K AMF , the UE derives K gNB = KDF (uplink NAS COUNT, K AMF ). If the indication is updated by K gNB , the UE performs horizontal key derivation (i.e. K NG-RAN *← KDF(K gNB1 , cell identity)); if the indication is updated by NH, the UE selects NCC2 for vertical key derivation, i.e. NH and K NG-RAN are derived (i.e. NH2 = KDF(NH1, K AMF ), K NG-RAN *← KDF(NH2, cell identity)). The UE leaves from the serving / source gNB and applies the configuration of the target gNB (candidate gNB2), which includes using K NG-RAN *as K gNB2 to be used for gNB2.
[0293] 26-28. After completing the path switching procedure with the AMF, the LTM switching is completed. The AMF generates a new pair of NH and NCC (NH3, NCC3) and passes them to gNB2, where the new NCC value (NCC3) is sent to the UE through RRC reconfiguration.
[0294] 26. The UE sends an RRC Reconfiguration Complete message to the target gNB.
[0295] 27a. The target gNB (gNB2) sends an N2 Path Switch Request to the AMF, which includes an LTM switching indication (i.e., second indication information).
[0296] 27b. Upon receiving the N2 Path Switch Request, the AMF updates the NH (e.g., from NH2 to NH3) and increments the corresponding NCC value (e.g., from NCC2 to NCC3).
[0297] 27c. The AMF returns the new NH and NCC (i.e., NH3 and NCC3) to gNB2 in the N2 Path Switch Response message.
[0298] 28. The received LTM switching indication, the target base station forwards or transmits the new NCC value (NCC3) sent by the AMF through NAS signaling to the UE.
[0299] 29. The user data of PDU Session 2 is switched from gNB1 to gNB2, and gNB2 applies the UP security policy received from gNB2 in the LTM preparation phase to protect the user data.
[0300] In some embodiments, the gNB should be able to send the UE security capabilities and UP security policy related to the active PDU session to multiple candidate gNBs in the LTM preparation phase.
[0301] The gNB should be able to include the selection of AS security algorithms in the LTM configuration sent to the UE.
[0302] The gNB should be able to store the received UP security policy of the PDU session of the UE that is not switched to itself.
[0303] The gNB should be able to initiate LTM candidate configuration when the UP security policy applied by itself changes.
[0304] Any one of the above embodiments can be combined with each other without contradiction and conflict.
[0305] The embodiments of the present disclosure further provide a device for implementing any of the above methods, for example, a device is provided, and the device includes units or modules for implementing the steps performed by the UE in any of the above methods. For another example, another device is provided, and the device includes units or modules for implementing the steps performed by the network device (for example, an access network device, or a core network device, etc.) in any of the above methods.
[0306] It should be understood that the division of each unit or module in the above device is only a logical function division, and all or part of the units or modules can be integrated into one physical entity, or can be physically separated. In addition, the units or modules in the device can be implemented in the form of processor calling software: for example, the device includes a processor, the processor is connected with a memory, the memory stores instructions, and the processor calls the instructions stored in the memory to implement any of the above methods or to implement the functions of the units or modules of the device, wherein the processor is a general processor, for example, a central processing unit (CPU) or a microprocessor, and the memory is a memory in the device or a memory outside the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuit, and the functions of part or all of the units or modules can be implemented by the design of the hardware circuit, and the hardware circuit can be understood as one or more processors; for example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC), and the functions of part or all of the units or modules are implemented by the design of the logical relationship between the elements in the circuit; for another example, in another implementation, the hardware circuit is a programmable logic device (PLD), and taking a field programmable gate array (FPGA) as an example, it can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by a configuration file, so as to implement the functions of part or all of the units or modules. All units or modules of the above device can be implemented in the form of processor calling software, or all units or modules can be implemented in the form of hardware circuit, or part of the units or modules are implemented in the form of processor calling software, and the remaining part is implemented in the form of hardware circuit.
[0307] In the embodiments of the present disclosure, the processor is a circuit with signal processing capability. In one implementation, the processor can be a circuit with instruction reading and running capability, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), a digital signal processor (DSP), and the like. In another implementation, the processor can implement certain functions through a logical relationship of a hardware circuit, and the logical relationship of the hardware circuit is fixed or reconfigurable. For example, the processor is a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In the reconfigurable hardware circuit, the processor loads a configuration document to implement the configuration of the hardware circuit. It can be understood that the processor loads an instruction to implement the functions of the above part or all units or modules. In addition, the hardware circuit can also be designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), and the like.
[0308] As shown in FIG. 7A, the embodiments of the present disclosure provide a first node, wherein the first node comprises:
[0309] The sending module 7101 is configured to send a first message to a second node, wherein the first message comprises information related to a security context of a layer 1 / layer 2 triggered mobility (LTM) of a user equipment (UE).
[0310] In some embodiments, the first node further comprises a receiving module and / or a processing module.
[0311] In some embodiments, the sending module and / or the receiving module can correspond to a network interface and / or a transceiving antenna of the first node.
[0312] In some embodiments, the processing module can be used by the first node to perform steps related to information processing in any one of the security information processing methods.
[0313] In some embodiments, the sending module can be used by the first node to perform steps related to information sending in any one of the security information processing methods.
[0314] In some embodiments, the receiving module can be configured to cause the first node to perform the steps related to information sending in any one of the security information processing methods.
[0315] In some embodiments of the first aspect, the first node is a serving base station of the UE, and the second node is a candidate base station or an initial base station of the UE LTM.
[0316] In some embodiments of the first aspect, the first node is a source base station of the UE for LTM switching, and the second node is a target base station of the UE for LTM switching.
[0317] In some embodiments, the first message includes at least one of capability information of the UE and a first user plane (UP) security policy; the capability information of the UE is used for the at least one second node to determine a security algorithm supported by the UE; and the first UP security policy is used for protecting a first session currently activated by the UE.
[0318] In some embodiments, the receiving module is configured to receive a second message sent by an mth second node, the second message including first information of the mth second node; the first information is used for indicating a security algorithm selected by the mth second node based on the capability information of the UE, m is a positive integer less than or equal to M, and M is the total number of the second nodes.
[0319] In some embodiments, the sending module is configured to send, to the UE, a third message including the first information.
[0320] In some embodiments, the third message further includes a first parameter; and the first parameter is used for the UE to generate a security key for communication with the first node.
[0321] In some embodiments, the sending module is configured to obtain a second user plane (UP) security policy of a second session of the UE, and send, to the second node, the first message including the second UP security policy of the second session; and the second UP security policy is used for protecting a second session currently activated by the UE.
[0322] In some embodiments, the sending module is configured to perform at least one of the following: sending, to the second node, the second UP security policy after obtaining the second UP security policy of the second session and successfully activating the second session; and sending, to the second node, the second UP security policy before the UE switches to the second node.
[0323] In some embodiments, the sending module is configured to perform at least one of the following: sending, to the second node, the second UP security policy after obtaining the second UP security policy of the second session and successfully activating the second session; and sending, to the second node, the second UP security policy before the UE switches to the second node.
[0324] In some embodiments, the sending module is configured to send a handover request to the second node, the handover request comprising the second UP security policy.
[0325] As shown in FIG. 7B, the embodiments of the present disclosure provide a second node, wherein the second node comprises:
[0326] The receiving module 7201 is configured to receive a first message sent by a first node, the first message comprising information related to a security context of a Layer 1 / Layer 2 triggered mobility (LTM) of a user equipment (UE).
[0327] In some embodiments, the second node can further comprise a receiving module and / or a processing module. In some embodiments, the sending module and / or the receiving module can correspond to a network interface and / or a transceiving antenna of the second node. In some embodiments, the processing module can be used by the second node to perform steps related to information processing in any one of the security information processing methods. In some embodiments, the sending module can be used by the second node to perform steps related to information sending in any one of the security information processing methods. In some embodiments, the receiving module can be used by the second node to perform steps related to information sending in any one of the security information processing methods.
[0328] In some embodiments, the first node is an initial base station of an LTM of the UE, the second node is a candidate node to which the UE performs LTM handover, and the first message comprises at least one of capability information of the UE and a first user plane (UP) security policy; the capability information of the UE is used by the at least one second node to determine a security algorithm supported by the UE; and the first UP security policy is used to protect a first session currently activated by the UE.
[0329] In some embodiments, the processing module is configured to select a security algorithm for communication with the UE according to the capability information of the UE; and the sending module is configured to send a second message to the first node, the second message comprising the security algorithm selected by the second node.
[0330] In some embodiments, the first node is a serving base station or a source base station of LTM handover of the UE, and the first message comprises a second UP security policy of a second session of the UE.
[0331] As shown in FIG. 7C, the embodiments of the present disclosure provide a UE, wherein the UE comprises:
[0332] The receiving module 7301 is configured to receive a third message sent by the first node; the third message comprises first information of M second nodes; the first information of the mth second node is used to indicate a security algorithm selected by the mth second node based on the capability information of the UE; the m is a positive integer less than or equal to M.
[0333] In some embodiments, the UE can further include a receiving module and / or a processing module. In some embodiments, the sending module and / or the receiving module can correspond to a network interface and / or a transceiving antenna of the UE. In some embodiments, the processing module can be used for the UE to perform steps related to information processing in any one of the security information processing methods. In some embodiments, the sending module can be used for the second node to perform steps related to information sending in any one of the security information processing methods. In some embodiments, the receiving module can be used for the UE to perform steps related to information sending in any one of the security information processing methods.
[0334] The embodiments of the present disclosure further provide a communication device, which can include one or more processors; wherein the processor is configured to invoke instructions to cause the communication device to perform the security information processing method implemented by any one of the preceding embodiments.
[0335] In some embodiments, as shown in FIG. 8A and / or FIG. 8B, the communication device 8100 further includes one or more memories 8102 for storing instructions. Alternatively, all or part of the memory 8102 can also be outside the communication device 8100.
[0336] The communication device can be the UE and the network device mentioned above. In some embodiments, the network device can be the master node and / or the secondary node.
[0337] In some embodiments, the communication device 8100 further includes one or more transceivers 8103. When the communication device 8100 includes one or more transceivers 8103, the communication steps such as sending and receiving in the above methods are performed by the transceiver 8103, and the other steps are performed by the processor 8101.
[0338] In some embodiments, the transceiver can include a receiver and a transmitter, which can be separate or integrated together. Alternatively, the terms of transceiver, transceiving unit, transceiver, transceiving circuit, etc. can be replaced by each other, the terms of transmitter, transmitting unit, transmitter, transmitting circuit, etc. can be replaced by each other, and the terms of receiver, receiving unit, receiver, receiving circuit, etc. can be replaced by each other.
[0339] Optionally, the communication device 8100 further includes one or more interface circuits 8104 connected with the memory 8102, which can be used to receive signals from the memory 8102 or other devices, and can be used to send signals to the memory 8102 or other devices. For example, the interface circuit 8104 can read instructions stored in the memory 8102 and send the instructions to the processor 8101.
[0340] The communication device 8100 in the above embodiment description can be a network device or a UE, but the scope of the communication device 8100 described in the present disclosure is not limited to this, and the structure of the communication device 8100 can not be limited by Figure 8A. The communication device can be a standalone device or can be part of a larger device. For example, the communication device can be: (1) a standalone integrated circuit (IC), or a chip, or a chip system or subsystem; (2) a set of one or more ICs, which can optionally also include storage components for storing data, programs; (3) an ASIC, such as a Modem; (4) a module that can be embedded in other devices; (5) a receiver, a UE device, a smart UE device, a cellular phone, a wireless device, a handset, a mobile unit, a car-mounted device, a network device, a cloud device, an artificial intelligence device, etc.; (6) other, etc.
[0341] Figure 8B is a structural schematic diagram of a chip 8200 according to an embodiment of the present disclosure. For the case where the communication device 8100 can be a chip or a chip system, reference can be made to the structural schematic diagram of the chip 8200 shown in Figure 8B, but not limited thereto.
[0342] The chip 8200 includes one or more processors 8201 for invoking instructions to cause the chip 8200 to perform any of the above security information processing methods.
[0343] In some embodiments, the chip 8200 further includes one or more interface circuits 8202 connected with the memory 8203, which can be used to receive signals from the memory 8203 or other devices, and can be used to send signals to the memory 8203 or other devices. For example, the interface circuit 8202 can read instructions stored in the memory 8203 and send the instructions to the processor 8201. Optionally, the terms interface circuit, interface, transceiver pin, and transceiver can be replaced with each other.
[0344] In some embodiments, the chip 8200 further includes one or more memories 8203 for storing instructions. Optionally, all or part of the memory 8203 can be outside the chip 8200.
[0345] The present disclosure also provides a storage medium having stored thereon instructions which, when executed on a communication device 8100, cause the communication device 8100 to perform any of the above methods. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer-readable storage medium, but can also be a storage medium readable by other apparatuses. Optionally, the storage medium can be a non-transitory storage medium, but can also be a transitory storage medium.
[0346] The present disclosure also provides a program product which, when executed by a communication device 8100, causes the communication device 8100 to perform any of the above methods of processing security information. Optionally, the program product is a computer program product.
[0347] The present disclosure also provides a computer program which, when executed on a computer, causes the computer to perform any of the above methods of processing security information.
[0348] Other embodiments of the present disclosure will be apparent to those skilled in the art from consideration of the specification and practice of the features disclosed herein. The present disclosure is intended to cover any variations, uses or adaptations of the present disclosure embodiments following, in general, the principles of the present disclosure and including such features to the present disclosure as come within the true spirit and scope of the present disclosure. Specification and examples are to be regarded only as illustrative, and the true scope and spirit of the present disclosure are indicated by the following claims.
[0349] It should be understood that the present embodiments are not limited to the precise structures as herein described and illustrated and that various modifications and changes can be made by those skilled in the art without departing from the scope of the present embodiments. The scope of the present embodiments should only be limited by the appended claims.
Claims
1. A security information processing method in which, The method is performed by a first node, and the method comprises: sending, to a second node, a first message comprising information related to a security context of a Layer 1 / Layer 2 triggered mobility (LTM) of a user equipment (UE).
2. The method of claim 1, wherein, The first node is an initial base station of the LTM of the UE, and the second node is a candidate base station of the LTM of the UE; the first message comprises at least one of capability information of the UE and a first user plane (UP) security policy; the capability information of the UE is used for the at least one second node to determine a security algorithm supported by the UE; The first UP security policy is used for protecting a first session currently activated by the UE.
3. The method of claim 2, wherein, The method further comprises: receiving a second message sent by an mth second node, the second message comprising first information of the mth second node; the first information is used for indicating a security algorithm selected by the mth second node based on the capability information of the UE, m is a positive integer less than or equal to M; and the M is a total number of the second nodes.
4. The method of claim 2 or 3, wherein, The method further comprises: sending, to the UE, a third message comprising the first information; The third message further comprises a first parameter; and the first parameter is used for the UE to generate a security key used for communication with the first node.
5. The method of claim 1, wherein, The first node is a serving base station of the UE, and the second node is a candidate base station or an initial base station of the LTM of the UE.
6. The method of claim 1, wherein, The first node is a source base station of the UE performing LTM switching, and the second node is a target base station of the UE performing LTM switching.
7. The method of claim 5 or 6, wherein, The sending, to the second node, of the first message comprises: obtaining a second user plane (UP) security policy of a second session of the UE, and sending, to the second node, the first message comprising the second UP security policy of the second session; the second UP security policy is used for protecting the second session currently activated by the UE.
8. The method of claim 7, wherein, The sending, to the second node, of the first message comprises at least one of: sending, to the second node, the second UP security policy after obtaining the second UP security policy and successfully activating the second session; sending, to the second node, the second UP security policy before the UE switches to the second node.
9. The method of claim 7 or 8, wherein, The sending, to the second node, of the second UP security policy comprises: sending, to the second node, a handover request comprising the second UP security policy.
10. A security information processing method in which, The method is performed by a second node, and the method comprises: receiving a first message sent by a first node, the first message comprising information related to a security context of a Layer 1 / Layer 2 triggered mobility (LTM) of a user equipment (UE).
11. The method of claim 10, wherein, The first node is an initial base station of the LTM of the UE, and the second node is a candidate base station of the LTM of the UE; the first message comprises at least one of capability information of the UE and a first user plane (UP) security policy; the capability information of the UE is used for the at least one second node to determine a security algorithm supported by the UE; The first UP security policy is used for protecting a first session currently activated by the UE.
12. The method of claim 10 or 11, wherein, The method further comprises: selecting, according to capability information of the UE, a security algorithm for communicating with the UE; sending, to the first node, a second message including the security algorithm selected by the second node.
13. The method of claim 10, wherein, The first node is a serving base station of the UE or a source base station of LTM switching, and the first message includes a second UP security policy of a second session of the UE.
14. A security information processing method, wherein, The method is performed by a user equipment (UE), and the method comprises: receiving a third message sent by a first node; the third message includes first information of M second nodes; the first information of an mth second node is used to indicate a security algorithm selected by the mth second node based on capability information of the UE; m is a positive integer less than or equal to M.
15. A first node, wherein, The first node comprises: a sending module configured to send, to a second node, a first message including information related to a security context of layer 1 / layer 2 triggered mobility (LTM) of a user equipment (UE).
16. A second node, wherein, The second node comprises: a receiving module configured to receive a first message sent by a first node, the first message including information related to a security context of layer 1 / layer 2 triggered mobility (LTM) of a user equipment (UE). The UE comprises:
17. A user equipment (UE), wherein, receiving a third message sent by a first node; the third message includes first information of M second nodes; the first information of an mth second node is used to indicate a security algorithm selected by the mth second node based on capability information of the UE; m is a positive integer less than or equal to M. The communication device comprises:
18. A communication device, wherein, one or more processors; The processor is configured to invoke instructions to cause the communication device to perform the security information processing method of any one of claims 1 to 9, 10, or 13 or 14. The storage medium stores instructions that, when executed on the communication device, cause the communication device to perform the security information processing method of any one of claims 1 to 9, 10, or 13 or 14.
19. A storage medium, wherein, The communication system comprises a first node, a second node, and a user equipment (UE); 20. A communication system, wherein, The first node is configured to perform the method of any one of claims 1 to 9; The second node is configured to perform the method of any one of claims 10 to 13; The UE is configured to perform the method of claim 14. The program product comprises a computer program that, when executed on a communication device, enables the communication device to implement the security information processing method of any one of claims 1 to 9, 10, or 13 or 14.
21. A program product, wherein,
Citation Information
Patent Citations
Method, apparatus and system for security protection
CN109600804A
Methods for cancelling or update of conditional mobility procedures
CN113170366A
Safety protection method, device and system
CN117979378A