Security parameter processing method, communication device, and storage medium

By negotiating security parameters in advance during the LTM process, the problem of security context transmission delay is solved, and a more efficient security parameter negotiation and node change process is achieved.

WO2026065649A1PCT designated stage Publication Date: 2026-04-02BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-10-31
Publication Date
2026-04-02

AI Technical Summary

Technical Problem

During the L1/L2 Triggered Mobility (LTM) process, existing technologies struggle to effectively reduce the latency of security context transmission during the change of master or slave nodes.

Method used

The first node sends security context information of the user equipment (UE) to the second node in advance, negotiates security parameters, and reduces the transmission delay of security context during handover.

Benefits of technology

It reduces the latency of security context transmission during LTM and improves the efficiency of security parameter negotiation for communication devices during node changes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024129078_02042026_PF_FP_ABST
    Figure CN2024129078_02042026_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure provide a security parameter processing method, a communication device, and a storage medium. The security parameter processing method is performed by a first node and may comprise: sending a first message to a second node, the first message comprising information related to a security context for Layer 1 / Layer 2 triggered mobility (LTM) of a user equipment (UE); receiving a second message sent by the second node, the second message comprising security parameters determined on the basis of the first message; and, on the basis of the second message, sending a third message to the UE, the third message being used by the UE to determine security parameters for communication with the second node. In this way, advance negotiation of security parameters related to the second node can be achieved on the basis of message interactions between the first node and the UE.
Need to check novelty before this filing date? Find Prior Art

Description

Security parameter processing method, communication device, and storage medium

[0001] This application claims priority to PCT application No. PCT / CN2024 / 123059, filed on September 30, 2024. TECHNICAL FIELD

[0002] The present disclosure relates to the field of communication technology, and in particular, to a security parameter processing method, a communication device, and a storage medium. BACKGROUND

[0003] Layer 1 / layer 2 triggered mobility (L1 / L2 Triggered Mobility, LTM) refers to a process of changing a primary cell (PCell) or a primary secondary cell (PSCell) node triggered by a media access control (MAC) control element (CE) based on a layer 1 (Layer 1, L1) measurement result. In the process of changing the primary cell or the primary secondary cell, the master cell group (MCG) or the secondary cell group (SCG) can be changed.

[0004] SUMMARY

[0005] The present disclosure provides a security parameter processing method, a communication device, and a storage medium.

[0006] According to a first aspect of an embodiment of the present disclosure, a security parameter processing method is provided, wherein the method is performed by a first node, and the method comprises: sending a first message to a second node, the first message comprising information related to a security context of layer 1 / layer 2 triggered mobility (LTM) of a user equipment (UE); receiving a second message sent by the second node, the second message comprising a security parameter determined based on the first message; and sending a third message to the UE according to the second message, the third message comprising the security parameter, the security parameter being used to protect communication between the UE and the second node.

[0007] According to a second aspect of the embodiments of the present disclosure, a security parameter processing method is provided, wherein the method is performed by a second node, and the method comprises the following steps: receiving a first message sent by a first node, wherein the first message comprises information related to a security context of Layer 1 / Layer 2 triggered mobility (LTM) of a user equipment (UE); sending a second message to the first node, wherein the second message comprises security parameters determined based on the first message; the security parameters are used for the first node to send a third message to the UE, wherein the third message comprises the security parameters; and the security parameters are used for protecting communication between the UE and the second node.

[0008] According to a third aspect of the embodiments of the present disclosure, a security parameter processing method is provided, wherein the method is performed by a user equipment (UE), and the method comprises the following steps: receiving a third message sent by a first node; the third message is used for the UE to determine security parameters for communication with a second node.

[0009] According to a fourth aspect of the embodiments of the present disclosure, a first node is provided, wherein the first node comprises: a sending module configured to send a first message to a second node, wherein the first message comprises information related to a security context of Layer 1 / Layer 2 triggered mobility (LTM) of a user equipment (UE); a receiving module configured to receive a second message sent by the second node, wherein the second message comprises security parameters determined based on the first message; and a sending module configured to send a third message to the UE according to the second message, wherein the third message is used for the UE to determine security parameters for communication with a second node.

[0010] According to a fifth aspect of the embodiments of the present disclosure, a second node is provided, wherein the second node comprises: a receiving module configured to receive a first message sent by a first node, wherein the first message comprises information related to a security context of Layer 1 / Layer 2 triggered mobility (LTM) of a user equipment (UE); and a sending module configured to send a second message to the second node, wherein the second message comprises security parameters determined based on the first message; and the security parameters are used for the first node to send a third message to the UE, wherein the third message is used for the UE to determine security parameters for communication with a second node.

[0011] According to a sixth aspect of the embodiments of the present disclosure, a user equipment (UE) is provided, wherein the UE comprises: a receiving module configured to receive a third message sent by a first node, wherein the third message comprises first information of M second nodes; the first information of an mth second node is used to indicate a first security algorithm and a first UP security activation state; the first security algorithm is selected by the mth second node according to the first capability information; the first UP security activation state is determined by the mth second node according to the first UP security policy; and m is a positive integer less than or equal to M.

[0012] According to a seventh aspect of the embodiments of the present disclosure, a communication system is provided, wherein the communication system comprises: a first node configured to perform the security parameter processing method provided in any of the technical solutions of the first aspect; a second node configured to perform the security parameter processing method provided in any of the technical solutions of the second aspect; and a UE configured to perform the security parameter processing method provided in any of the technical solutions of the third aspect.

[0013] According to an eighth aspect of the embodiments of the present disclosure, a communication device is provided, wherein the communication device comprises: one or more processors; and wherein the processor is configured to invoke instructions to cause the communication device to perform the security parameter processing method provided in any of the technical solutions of the first aspect, the second aspect and / or the third aspect.

[0014] According to a ninth aspect of the embodiments of the present disclosure, a storage medium is provided, wherein the storage medium stores instructions, and when the instructions are executed on a communication device, the communication device is caused to perform the security parameter processing method provided in any of the technical solutions of the first aspect, the second aspect and / or the third aspect.

[0015] According to a tenth aspect of the embodiments of the present disclosure, a program product is provided, wherein the program product comprises a computer program, and when the computer program is executed on a communication device, the communication device is caused to implement the security parameter processing method provided in any of the technical solutions of the first aspect, the second aspect and / or the third aspect.

[0016] The technical solution provided in the embodiments of the present disclosure is that the first node sends the information related to the security context of the UE to the second node in advance, which can reduce the delay when the security context is needed, compared with temporarily transmitting the information related to the security context.

[0017] It should be understood that the foregoing general description and the following detailed description are only exemplary and explanatory, and are not limiting on the embodiments of the present disclosure. BRIEF DESCRIPTION OF DRAWINGS

[0018] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present disclosure and serve to explain the principles of the present disclosure together with the specification.

[0019] FIG. 1A is a schematic diagram of an architecture of a communication system according to an example embodiment;

[0020] FIG. 1B is a flowchart of an LTM according to an example embodiment;

[0021] FIG. 1C is a flowchart of a key derivation according to an example embodiment;

[0022] FIG. 2A is a flow diagram illustrating a security parameter processing method according to an example embodiment;

[0023] FIG. 2B is a flow diagram illustrating a security parameter processing method according to an example embodiment;

[0024] FIG. 2C is a flow diagram illustrating a security parameter processing method according to an example embodiment;

[0025] FIG. 2D is a flow diagram illustrating a security parameter processing method according to an example embodiment;

[0026] FIG. 3A is a flow diagram illustrating a security parameter processing method according to an example embodiment;

[0027] FIG. 3B is a flow diagram illustrating a security parameter processing method according to an example embodiment;

[0028] FIG. 4 is a structural diagram of a communication system according to an example embodiment;

[0029] FIG. 5A is a structural diagram of a communication device according to an example embodiment;

[0030] FIG. 5B is a structural diagram of a chip according to an example embodiment. DETAILED DESCRIPTION

[0031] The embodiments of the present disclosure provide a security parameter processing method, a communication device, a communication system and a storage medium.

[0032] The first aspect provides a security parameter processing method, wherein the method is performed by a first node, and the method comprises:

[0033] sending a first message to a second node, wherein the first message comprises information related to a security context of a Layer 1 / Layer 2 Triggered Mobility (LTM) of a User Equipment (UE);

[0034] receiving a second message sent by the second node, wherein the second message comprises security parameters determined based on the first message;

[0035] sending a third message to the UE according to the second message, wherein the third message comprises the security parameters, and the security parameters are used to protect communication between the UE and the second node.

[0036] According to the above scheme, the first node sends the information related to the security context of the UE to the second node in advance, which can reduce the delay caused by the transmission of the security context during the handover process, compared with the transmission of the information related to the security context during the handover process.

[0037] In some embodiments of the first aspect, the first node is an initial base station of an LTM of the UE, and the second node is a candidate base station of the UE LTM; the first message comprises at least one of first capability information of the UE and a first user plane (UP) security policy; the first capability information of the UE is used by the at least one second node to determine a first security algorithm supported by the UE; and the first UP security policy is used to protect a first session currently activated by the UE.

[0038] Based on the above scheme, when the initial base station configures the candidate node of the LTM, the first capability information of the UE and the first UP security policy are informed to the candidate node, so as to realize early negotiation of the first security algorithm and early intercommunication of the first UP security policy.

[0039] In some embodiments of the first aspect, the second message comprises first information of the mth second node; the first information is used to indicate the first security algorithm and a first UP security activation state; the first security algorithm is selected by the mth second node according to the first capability information; the first UP security activation state is determined by the mth second node according to the first UP security policy; m is a positive integer less than or equal to M; and M is the total number of the second nodes.

[0040] Based on the above scheme, the first node assists the candidate node and the UE to realize negotiation of the security algorithm between the two by receiving the second message sent by the mth second node when configuring the candidate node for the UE.

[0041] In some embodiments of the first aspect, the third message comprises the first information; and the first information is used by the UE to determine a security parameter for communication with the second node.

[0042] The first node assists the candidate node and the UE to realize negotiation of the security algorithm between the two by sending the third message when configuring the candidate node for the UE.

[0043] In some embodiments of the first aspect, the first node is a serving base station of the UE, and the second node is a candidate base station or an initial base station for LTM switching of the UE.

[0044] In some embodiments of the first aspect, the first node is a source base station for LTM switching of the UE, and the second node is a target base station for LTM switching of the UE.

[0045] In some embodiments of the first aspect, sending the first message to the second node comprises: obtaining a second user plane (UP) security policy of a second session of the UE, and sending the first message to the second node, the first message comprising the second UP security policy of the second session; the second UP security policy is used by the second node to determine an activation mode for protecting the second session; and the second session is a newly established active session of the UE.

[0046] In some embodiments of the first aspect, the second message comprises second information of the mth second node; the second information of the mth node is used to indicate a second UP security activation state determined by the mth second node, and the second UP security activation state is determined according to the second UP security policy.

[0047] Based on the above scheme, the first node sends the second message, and the second node will have pre-set the second UP security state of the second session, so that the second session can be quickly performed when the second session is transferred to the second node, thereby reducing the delay of establishing and starting the second session at the second node.

[0048] In some embodiments of the first aspect, the third message comprises second information; the second information is used at least for the UE to determine a security parameter for the second session with the second node.

[0049] Based on the above scheme, the UE will obtain the second information in advance through the sending of the third message, so that when the second session is transferred to the second node, the delay of the UE preparing work for the second session based on the second node can be reduced.

[0050] Based on the above scheme, the first message is sent to the second node after the second UP security policy of the second session is obtained, so that the first message is sent to the second node in the case of obtaining a new session of the UE, and the second UP security policy of the second session is synchronized to the second node in the first time.

[0051] In some embodiments of the first aspect, sending the first message to the second node comprises at least one of the following: sending the second UP security policy to the second node after obtaining the second UP security policy of the second session and successfully activating the second session; and sending the second UP security policy to the second node before deciding to switch the UE to the second node.

[0052] The above scheme limits the second UP security policy of the second session and sends the second UP security policy to the second node after the second session is successfully activated.

[0053] In some embodiments of the first aspect, sending the UP security policy to the second node comprises: sending a switching request to the second node, and the switching request comprises the second UP security policy.

[0054] Based on the above scheme, the second UP security policy is sent through the switching request instead of using a dedicated message, and the compatibility with related technologies is strong.

[0055] The second aspect provides a security parameter processing method, wherein the method is performed by a second node and comprises:

[0056] receiving a first message sent by a first node, the first message comprising information related to a security context of a layer 1 / layer 2 triggered mobility (LTM) of a user equipment (UE);

[0057] sending a second message to a second node, the second message comprising security parameters determined based on the first message; the security parameters are used by the first node to send a third message to the UE, the third message comprising the security parameters; the security parameters are used to protect communications between the UE and the second node.

[0058] In some embodiments of the second aspect, the first node is an initial base station of the LTM of the UE, the second node is a candidate node for LTM handover of the UE, and the first message comprises at least one of first capability information of the UE and a first user plane (UP) security policy; the first capability information of the UE is used by the at least one second node to determine a first security algorithm supported by the UE; and the first UP security policy is used by the second node to determine an activation manner for protecting a first session, the first session being a currently active session of the UE.

[0059] In some embodiments of the second aspect, the method further comprises:

[0060] selecting, according to the first capability information of the UE, a first security algorithm for communication with the UE; and determining, according to the first UP security policy, a first UP security activation state for communication with the UE.

[0061] the second message comprises first information; the first information is used to determine at least one of the first security algorithm selected by the second node and the first UP security activation state.

[0062] In some embodiments of the second aspect, the first node is a serving base station of the UE or a source base station of the LTM handover, and the first message comprises a second UP security policy of a second session of the UE.

[0063] In some embodiments of the second aspect, the second message comprises second information; the second information is used to indicate the second UP security activation state, the second UP security activation state being determined according to a second UP security policy.

[0064] In some embodiments of the second aspect, the method further comprises: receiving second capability information sent by a third node, the third node being a core network node; in a case where the second capability information is different from the first capability information, selecting a second security algorithm according to the second capability information; and sending, to the UE, a fourth message according to the second security algorithm, the fourth message being used by the UE to determine the second security algorithm.

[0065] Based on the above scheme, in a case that the second capability information saved by the core network device for the UE is different from the first capability information, a second security algorithm is selected in priority according to the second capability information, and a fourth message is sent to the UE in order to keep consistent with the UE, so as to realize re-negotiation of the security algorithm between the UE and the second node.

[0066] In some embodiments of the second aspect, the method further includes:

[0067] receiving a third UP security policy sent by a fourth node, the fourth node being a core network node;

[0068] receiving a third UP security policy sent by a fourth node, the fourth node being a core network node;

[0069] in a case that the third UP security policy is different from the first UP security policy, determining a third UP security activation state according to the third UP security policy;

[0070] sending a fifth message to the UE according to the third UP security activation state, the fifth message being used for the UE to determine the third UP security activation state.

[0071] Based on the above scheme, in a case that the third UP security policy determined by the core network device for the UE is different from the first UP security policy, a third UP security activation state is selected in priority according to the third UP security policy, and a fifth message is sent to the UE in order to keep consistent with the UE, so as to realize re-negotiation of the UP security activation state between the UE and the second node.

[0072] In some embodiments of the second aspect, the method further includes:

[0073] receiving a fourth UP security policy associated with the second session sent by a fourth node, the fourth node being a core network node;

[0074] in a case that the fourth UP security policy is different from the second UP security policy, determining a fourth UP security activation state according to the fourth UP security policy; the second UP security policy being received by the second node from the first node;

[0075] sending a sixth message to the UE according to the fourth UP security activation state, the sixth message being used for the UE to determine the fourth UP security activation state.

[0076] Based on the above scheme, in a case that the fourth UP security policy determined by the core network device for the UE is different from the second UP security policy, a fourth UP security activation state is selected in priority according to the fourth UP security policy, and a sixth message is sent to the UE in order to keep consistent with the UE, so as to realize re-negotiation of the UP security activation state between the UE and the second node.

[0077] The third aspect provides a security parameter processing method, wherein the method is performed by a user equipment (UE), and the method comprises the following steps:

[0078] receiving a third message sent by the first node, wherein the third message is used for the UE to determine the security parameter for the communication with the second node.

[0079] In some embodiments of the third aspect, the third message comprises first information of M second nodes, wherein the first information of the mth second node is used to indicate at least one of a first security algorithm and a first user plane (UP) security activation state, the first security algorithm is a first security algorithm selected by the mth second node based on first capability information of the UE, and the first UP security activation state is determined by the mth second node according to a first UP security policy, m is a positive integer less than or equal to M.

[0080] In some embodiments of the third aspect, the third message comprises second information of M second nodes, wherein the second information of the mth node is used to indicate a second UP security activation state determined by the mth second node, and the second UP security activation state is determined according to a second UP security policy, m is a positive integer less than or equal to M.

[0081] In some embodiments of the third aspect, the method further comprises: receiving a fourth message sent by the mth second node, wherein the fourth message is used for the UE to determine a second security algorithm.

[0082] In some embodiments of the third aspect, the method further comprises: receiving a fifth message sent by the mth second node, wherein the fifth message is used for the UE to determine a third UP security activation state, and the third UP security activation state is a UP security activation state of the first session.

[0083] In some embodiments of the third aspect, the method further comprises:

[0084] receiving a sixth message sent by the mth second node, wherein the sixth message is used for the UE to determine a fourth UP security activation state, and the fourth UP security activation state is a UP security activation state of the second session.

[0085] The fourth aspect provides a first node, wherein the first node comprises:

[0086] a sending module configured to send a first message to a second node, wherein the first message comprises information related to a layer 1 / layer 2 trigger mobility (LTM) security context of a user equipment (UE);

[0087] a receiving module configured to receive a second message sent by the second node, wherein the second message comprises a security parameter determined based on the first message;

[0088] The sending module is configured to send, according to the second message, a third message to the UE; the third message comprises a security parameter; and the security parameter is used to protect communication between the UE and the second node.

[0089] The fifth aspect provides a second node, and the second node comprises:

[0090] The receiving module is configured to receive a first message sent by the first node, and the first message comprises information related to a layer 1 / layer 2 trigger mobility (LTM) security context of a user equipment (UE).

[0091] The sending module is configured to send, to the second node, a second message comprising a security parameter determined based on the first message; the security parameter is used for the first node to send, to the UE, a third message comprising the security parameter; and the security parameter is used to protect communication between the UE and the second node.

[0092] The sixth aspect provides a user equipment (UE), and the UE comprises a receiving module configured to receive a third message sent by the first node; the third message comprises a security parameter; and the security parameter is used to protect communication between the UE and the second node.

[0093] The seventh aspect provides a communication device, and the communication device comprises one or more processors.

[0094] The processor is configured to invoke instructions to enable the communication device to perform the method of any one of the technical solutions in the first aspect, the second aspect and / or the third aspect.

[0095] The eighth aspect provides a communication system, and the communication system comprises a first node, a second node and a user equipment (UE).

[0096] The first node is configured to perform the method of any one of the technical solutions in the first aspect.

[0097] The second node is configured to perform the method of any one of the technical solutions in the second aspect.

[0098] The UE is configured to perform the method of any one of the technical solutions in the third aspect.

[0099] In the ninth aspect, the embodiments of the present disclosure provide a program product, and the program product comprises a computer program; when the computer program is executed by a communication device, the computer program enables the communication device to implement a security parameter processing method described in the optional implementation manners of the first aspect to the third aspect.

[0100] In the tenth aspect, the embodiments of the present disclosure provide a computer program, and when the computer program is executed by a computer, the computer program enables the computer to perform a security parameter processing method described in the optional implementation manners of the first aspect to the third aspect.

[0101] It can be understood that the first node, the second node, the UE, the network device, and the communication system, the program product, and the computer program are used to execute the method provided by the embodiments of the present disclosure. Therefore, the beneficial effects achieved thereby can refer to the beneficial effects in the corresponding method, which will not be described here.

[0102] The embodiments of the present disclosure provide a security parameter processing method, a communication device, a communication system and a storage medium. The embodiments of the present disclosure are not exhaustive, but only illustrate some embodiments, and are not specific limitations on the protection scope of the present disclosure. In the case of no contradiction, each step in an embodiment can be implemented as an independent embodiment, and the steps can be combined arbitrarily, for example, the mode after removing some steps in an embodiment can also be implemented as an independent embodiment, and the order of the steps in an embodiment can be exchanged arbitrarily, in addition, the optional implementation modes in an embodiment can be combined arbitrarily; in addition, the embodiments can be combined arbitrarily, for example, some or all steps of different embodiments can be combined arbitrarily, an embodiment can be combined with the optional implementation modes of other embodiments.

[0103] In the embodiments of the present disclosure, the terms and / or descriptions of the embodiments are consistent and can be referred to each other if there is no special description and logical conflict, and the technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationship.

[0104] The terms used in the embodiments of the present disclosure are only for the purpose of describing specific embodiments, and not as a limitation on the present disclosure.

[0105] In the embodiments of the present disclosure, unless otherwise stated, elements expressed in singular form, such as "one", "a", "the", "above", "preceding", "this", etc., can represent "one and only one", or "one or more", "at least one", etc. For example, in the case of using articles such as "a", "an", "the" in English, the noun after the article can be understood as singular expression, or as plural expression.

[0106] In the embodiments of the present disclosure, "a plurality of" means two or more.

[0107] In some embodiments, the terms "at least one of", "one or more", "a plurality of", "multiple", and the like can be replaced with each other.

[0108] In some embodiments, the description of "at least one of A, B", "A and / or B", "A or B in an instance", "A in one instance and B in another instance", and the like, can include the following technical manners according to the situation: A in some embodiments (A is executed regardless of B); B in some embodiments (B is executed regardless of A); A and B are selectively executed in some embodiments (A and B are selected from A and B); A and B are executed in some embodiments (A and B are executed). When there are more branches such as A, B, C, and the like, the above description is similar.

[0109] In some embodiments, the description of "A or B" and the like can include the following technical manners according to the situation: A in some embodiments (A is executed regardless of B); B in some embodiments (B is executed regardless of A); A and B are selectively executed in some embodiments (A and B are selected from A and B). When there are more branches such as A, B, C, and the like, the above description is similar.

[0110] The prefix words "first", "second", and the like in the embodiments of the present disclosure are only used to distinguish different description objects, and do not constitute a limitation on the position, order, priority, quantity, or content of the description objects. The description of the description objects should refer to the description in the context of the claims or embodiments, and should not constitute an additional limitation because of the use of the prefix words. For example, the description object is "field", and the ordinal words before "field" in "first field" and "second field" do not limit the position or order between "fields", and "first" and "second" do not limit whether the "fields" modified thereby are in the same message or not, nor do they limit the order of "first field" and "second field". For another example, the description object is "level", and the ordinal words before "level" in "first level" and "second level" do not limit the priority between "levels". For another example, the quantity of the description object is not limited by the ordinal words, and can be one or more. For example, "first device", wherein the quantity of "device" can be one or more. In addition, the objects modified by different prefix words can be the same or different, for example, the description object is "device", and "first device" and "second device" can be the same device or different devices, and their types can be the same or different; for another example, the description object is "information", and "first type of information" and "second type of information" can be the same information or different information, and their contents can be the same or different.

[0111] In some embodiments, "including A", "containing A", "for indicating A", "carrying A", can be interpreted as directly carrying A, or indirectly indicating A.

[0112] In some embodiments, the terms "…", "determining …", "in the case of …", "when …", "when …", "if …", and the like can be replaced with each other.

[0113] In some embodiments, the terms "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not lower than", "above", and the like can be replaced with each other, and the terms "less than", "less than or equal to", "not greater than", "fewer than", "fewer than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", "below", and the like can be replaced with each other.

[0114] In some embodiments, an apparatus and the like can be interpreted as an entity, and can also be interpreted as virtual, and the name thereof is not limited to the name described in the embodiments. The terms "apparatus", "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", "subject", and the like can be replaced with each other.

[0115] In some embodiments, "network" can be interpreted as including network-side devices or network functions such as access network devices, core network devices, and the like in the network.

[0116] In some embodiments, the terms "access network device (AN device)", "radio access network device (RAN device)", "base station (BS)", "radio base station", "fixed station", "node", "access point", "transmission point (TP)", "reception point (RP)", "transmission / reception point (TRP)", "panel", "antenna panel", "antenna array", "node (cell)", "macro node", "small node", "femto node", "pico node", "sector", "cell group", "serving node", "node (carrier)", "component node", "bandwidth part (BWP)", and the like can be replaced with each other.

[0117] In some embodiments, the terms "UE (terminal)", "UE device (terminal device)", "user equipment (UE)", "user terminal", "mobile station (MS)", "mobile terminal (MT)", "subscriber station", "mobile unit", "subscriber unit", "wireless unit", "remote unit", "mobile device", "wireless device", "wireless communication device", "remote device", "mobile subscriber station", "access terminal", "mobile terminal", "wireless terminal", "remote terminal", "handset", "user agent", "mobile client", "client", and the like can be replaced with each other.

[0118] In some embodiments, the access network device, the core network device, or the network device can be replaced with the UE. For example, the structure in which the communication between the access network device, the core network device, or the network device and the UE is replaced with the communication between a plurality of UEs (e.g., device-to-device (D2D), vehicle-to-everything (V2X), and the like) can also apply the embodiments of the present disclosure. In this case, it can also be configured such that the UE has all or part of the functions that the access network device has. In addition, the terms "uplink", "downlink", and the like can also be replaced with terms corresponding to the inter-UE communication (e.g., "side"). For example, the uplink channel, the downlink channel, and the like can be replaced with the side channel, and the uplink, the downlink, and the like can be replaced with the sidelink.

[0119] In some embodiments, the UE can be replaced with the access network device, the core network device, or the network device. In this case, it can also be configured such that the access network device, the core network device, or the network device has all or part of the functions that the UE has.

[0120] In some embodiments, the acquisition of data, information, and the like can comply with the laws and regulations of the country where the location is.

[0121] In some embodiments, data, information, etc. can be acquired after obtaining user consent.

[0122] In addition, each element, each row, or each column in the table of the embodiments of the present disclosure can be implemented as an independent embodiment, and any combination of any element, any row, or any column can also be implemented as an independent embodiment.

[0123] FIG. 1A is a schematic diagram of an architecture of a communication system according to an embodiment of the present disclosure.

[0124] As shown in FIG. 1A, the communication system 100 includes a terminal 101 and a network device 102. The network device 102 can include an access network device and / or a core network device. The terminal is also referred to as a UE.

[0125] In some embodiments, the terminal 101 includes at least one of a mobile phone, a wearable device, an Internet of Things device, a car with communication function, a smart car, a Pad, a computer with wireless transceiver function, a virtual reality (VR) UE device, an augmented reality (AR) UE device, a wireless UE device in industrial control, a wireless UE device in self-driving, a wireless UE device in remote medical surgery, a wireless UE device in smart grid, a wireless UE device in transportation safety, a wireless UE device in smart city, a wireless UE device in smart home, etc., but is not limited thereto.

[0126] In some embodiments, the UE is also referred to as a User Equipment (UE).

[0127] In some embodiments, the access network device may, for example, be at least one of a node or a device that accesses a UE to a wireless network, and the access network device may, for example, include at least one of an evolved NodeB (eNB), a next generation eNB (ng-eNB), a next generation NodeB (gNB), a node B (NB), a home node B (HNB), a home evolved node B (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an Open RAN, a Cloud RAN, a base station in other communication systems, an access node in a Wi-Fi system, but is not limited thereto.

[0128] In some embodiments, the technical means of the present disclosure can be applicable to an Open RAN architecture, at which time the interfaces between or within the access network devices involved in the embodiments of the present disclosure can become internal interfaces of the Open RAN, and the processes and information interactions between these internal interfaces can be implemented through software or programs.

[0129] In some embodiments, the access network device can be composed of a central unit (CU) and a distributed unit (DU), where the CU can also be referred to as a control unit. The CU-DU structure can split the protocol layers of the access network device, and some of the protocol layers can be controlled by the CU, and the rest or all of the protocol layers can be distributed in the DU and controlled by the CU, but is not limited thereto.

[0130] In some embodiments, the core network device can be one device including the first network element, or can be multiple devices or device groups, each including the first network element. The network element can be virtual or physical. The core network may, for example, include at least one of an evolved packet core (EPC), a 5G core network (5GCN), and a next generation core (NGC).

[0131] It can be understood that the communication system described in the embodiments of the present disclosure is for more clearly illustrating the technical means of the embodiments of the present disclosure, and does not constitute a limitation on the technical means provided by the embodiments of the present disclosure. It can be known by those skilled in the art that, as the system architecture evolves and new service scenarios appear, the technical means provided by the embodiments of the present disclosure are also applicable to similar technical problems.

[0132] The following embodiments of the present disclosure can be applied to the communication system 100 shown in FIG. 1A or part of the subject, but are not limited thereto. The subjects shown in FIG. 1A are illustrative, and the communication system can include all or part of the subjects in FIG. 1A, or other subjects other than those in FIG. 1A. The number and form of each subject is arbitrary, and the connection relationship between the subjects is illustrative. The subjects can be connected or not connected, and the connection can be in any manner, can be direct connection or indirect connection, and can be wired connection or wireless connection.

[0133] Embodiments of the present disclosure can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New radio access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (Bluetooth (registered trademark)), Public Land Mobile Network (PLMN) network, Device-to-Device (D2D) system, Machine to Machine (M2M) system, Internet of Things (IoT) system, Vehicle-to-Everything (V2X), system using other resources, next-generation system extended based on them, and the like. In addition, a plurality of systems can be combined (for example, LTE and NR can be combined).

[0134] LTM supports intra-frequency and inter-frequency mobility, including migration to inter-frequency cells other than the current cell. In some techniques, only intra-DU LTM and intra-DU LTM are supported. In other embodiments, NR mobility enhancements are extended to LTM across CUs, which can include, but is not limited to, at least one of the following scenarios:

[0135] Example 1: CU acts as MN when no DU is configured;

[0136] Example 2: CU acts as SN when NR-DC is configured, and MCG remains unchanged;

[0137] Example 3: CU acts as MN when NR-DC is configured, and SCG remains unchanged or is released.

[0138] In the process of primary cell or primary secondary cell change, the change of Master Cell Group (MCG) or Secondary Cell Group (SCG) can be accompanied. In LTM, the next generation NodeB (gNB) receives the L1 measurement report from the User Equipment (UE), and based on this, the gNB changes the serving cell of the UE through the cell switch command (cell switch command) issued by the MAC CE. The cell switch command (cell switch command) indicates the LTM candidate cell configuration provided by the gNB to the UE in advance through the Radio Resource Control (RRC) signaling. The UE accesses the target cell indicated in the received cell switch command (cell switch command) according to the received cell switch command (cell switch command). LTM can be used to reduce the mobility delay. The LTM candidate cell configuration can only be added, modified and released by the network through RRC signaling. LTM supports subsequent LTM, which refers to the LTM performed based on the candidate cell without RRC reconfiguration between the network device and the UE. That is, after the mobility operation is performed, the UE does not autonomously delete the configuration information of the LTM, and the configuration information of the LTM can continue to be used even if there is no RRC reconfiguration and update, for triggering the subsequent LTM (Subsequent LTM). For example, the configuration information of the LTM can include the information of the candidate cell.

[0139] LTM supports intra-frequency or inter-frequency cell change. In some scenarios, only Distributed Unit (DU) intra-DU LTM and DU intra-DU LTM are supported. In some scenarios, New Radio (NR) mobility enhancement is extended to inter-CU, inter-node or inter-gNB (inter-CU, inter-node, inter-gNB) LTM. Exemplarily, the inter-CU, inter-node or inter-gNB LTM supports the following scenarios:

[0140] Example 1: CU acts as MN when no DU is configured;

[0141] Example 2: Configure NR-DC, CU acts as SN and MCG is unchanged.

[0142] Example 3: CU acts as MN and SCG is unchanged or SCG is released when configuring NR-DC. For inter-CU LTM, multiple candidate gNB-CUs will participate in the migration flow.

[0143] The signaling flow of LTM can be shown in FIG. IB, including the following three stages:

[0144] Stage 1: Stage 1 is also the LTM preparation stage, in which the initial gNB decides candidate cells and initiates cross-node interaction for LTM preparation across CUs based on L3 RRC measurement report. After the interaction, the initial gNB provides LTM configuration to the UE according to the RRC configuration of multiple candidate cells.

[0145] The initial gNB decides candidate cells and initiates inter-node interaction for inter-CU LTM preparation. After the interaction, the initial gNB provides LTM configuration to the UE with RRC configuration of multiple candidate cells.

[0146] Stage 2: Stage 2 is also the LTM initialization node, in which the UE sends L1 measurement report to the initial gNB. After receiving the cell switch command MAC CE, the UE switches to a candidate cell. In order to support RACH-less LTM, the UE can be synchronized with the candidate cell in advance, specifically, before receiving the cell switch command, the UE performs DL and UL synchronization with the candidate cell.

[0147] Stage 3: Subsequent LTM stage, in which steps similar to steps 8-14 are performed. The subsequent LTM is triggered by the current serving gNB, which itself also belongs to one of the candidate gNBs of the candidate LTM.

[0148] The key update synchronization between the UE and the gNB in the non-LTM scenario switching process can be as follows: During the switching of the inter-CU mobility process, the synchronization of the AS security key between the UE and the target gNB is achieved by using the NCC value of the source gNB, which is then forwarded to the target gNB and the UE in the RRC reconfiguration signaling. When it is necessary to establish an initial AS security context between the UE and the gNB, the AMF and the UE will derive K gNB and the Next Hop, NH) parameter (NCC(NH chain Counter) is associated with each K gNB and the NH parameter. Each K gNB is associated with a NCC corresponding to the NH value.

[0149] During Xn switching, if the source gNB has an unused {NH, NCC} pair, vertical key derivation should be performed. The source gNB should first derivation from the currently active K. gNB (If it's a horizontal key derivation) or calculate K from NH (if it's a vertical key derivation) NG-RAN* Then, the source gNB will {K NG-RAN* The NCC forwards the data to the target gNB. The target gNB should directly forward the received K... NG-RAN* K as used with UE gNB The target gNB should receive the NCC value from the source gNB and match it with the K value. gNB Related. The target gNB includes the received NCC in a prepared Handover (HO) command message, which is sent to the source gNB using a transparent container, and then forwarded to the UE by the source gNB.

[0150] Regardless of whether a handover is performed within the gNB-CU, an Xn handover, or an N2 handover, the UE's behavior is the same. The only difference is that during an intra-gNB-CU handover, the UE may retain the same key according to the gNB's instructions. The UE's behavior is also the same under conditional handover scenarios; for example, if the UE should use K... NG-RAN* The parameters of the target cell selected in the derivation. Figure 1C is a schematic diagram of a key level derivation.

[0151] If the NCC value in the HO command message received by the UE from the target gNB via the source gNB is equal to the currently active K gNB The associated NCC value then the UE is from the currently active K gNB Derivation of K from the target PCI and its frequency (ARFCN-DL or EARFCN-DL) NG-RAN* .

[0152] If the NCC value received by the UE is different from the NCC value associated with the currently activated gNB, the UE should first calculate the iteratively synchronized locally saved NH parameter and increase the NCC value until it matches the NCC value received from the source gNB through the HO command message. When the NCC value matches, the UE uses the synchronized NH parameter and the target physical cell identity (Physical Cell Identity, PCI) PCI and its frequency Absolute Radio-Frequency Channel Number Downlink (ARFCN-DL) or ((Universal Mobile Telecommunications System, UMTS) Terrestrial Radio Access Network, E-UTRAN) Absolute Radio Frequency Channel Number Downlink (EARFCN-DL) to calculate K NG-RAN* .

[0153] The UE should use K NG-RAN* as K gNB .

[0154] In the current cross-gNB handover process, the security-related configurations (such as NCC, K NG-RAN* ) are first synchronized between the source gNB and the target gNB, and then sent to the UE by the source gNB in the RRC reconfiguration of each handover. NCC is used for the key synchronization of the UE with the target gNB as above. However, with the mobility enhancement process designed for cross-gNB LTM, the RRC reconfiguration is no longer sent by the source gNB in each handover. Then, how to update the NCC value and send it to the UE for key synchronization in each handover becomes an open question. In addition to the key synchronization problem based on the NCC value, there are other security-related configurations, including the AS security algorithms that need to be negotiated between the UE and the candidate gNB, and the UP security policy that needs to be applied to the PDU session established by the connected UE. The parameters required for AS key refresh, AS security algorithms, and UP security policy are all part of the AS security context in the UE and gNB, which need to be synchronized in the handover process. Therefore, it is necessary to study how the UE and the candidate gNB negotiate the AS security algorithm, and how to correctly apply the UP security policy to the PDU session during the LTM handover between the candidate gNBs.

[0155] The embodiments of the present disclosure provide a security parameter processing method, which is executed by a communication system shown in FIG. 1A. As shown in FIG. 2A, the method can include:

[0156] S2101: A first node sends a first message to at least one second node.

[0157] In some embodiments, the first node and the second node can both be access network nodes.

[0158] In some embodiments, the first node can be an initial base station for a UE's LTM handover. The second node can be a candidate base station for the UE's LTM handover.

[0159] In some embodiments, the first node can be a current serving base station for a UE. The second node can be a base station that will provide service to the UE later.

[0160] In some embodiments, the first node sends the first message to the at least one second node in an LTM preparation phase.

[0161] In some embodiments, the first node can send the first message to the at least one second node through an X2 interface, an Xn interface, or a backhaul link.

[0162] In some embodiments, the first message includes information related to a security context of a Layer 1 / Layer 2 triggered mobility (LTM) of a user equipment (UE).

[0163] In some embodiments, the first message can include information related to a security context of the UE's LTM and / or a security capability of the UE.

[0164] In some embodiments, the first message includes at least one of the following:

[0165] a UE identity, used to identify the UE;

[0166] first capability information of the UE, used to at least indicate a security capability of the UE;

[0167] a first UP security policy, used to protect a first session currently activated by the UE.

[0168] In some embodiments, the UE identity can be various types of UE identities, for example, the UE's identity can be but not limited to at least one of the following:

[0169] a cell radio network temporary identifier (C-RNTI);

[0170] an international mobile equipment identity (IMEI);

[0171] International Mobile Subscriber Identity (IMSI);

[0172] Globally Unique Temporary Identifier (GPSI).

[0173] Temporary Mobile Subscriber Identity (TMSI).

[0174] In some embodiments, the first capability information of the UE can comprise a first security algorithm or an identification of the first security algorithm supported by the UE.

[0175] In some embodiments, the first UP security policy can be used to indicate whether the UP of the first session needs to be protected by integrity protection and / or confidentiality protection.

[0176] In some embodiments, the first capability information of the UE is used by the at least one second node to determine the first security algorithm supported by the UE.

[0177] In some other embodiments, the first UP security policy is used to protect the first session currently activated by the UE.

[0178] In some embodiments, the first message can be a handover request sent to one or more second nodes in a LTM candidate preparation stage. The handover request directly carries the identification of the UE and the first capability information of the UE. In some embodiments, the handover request also carries the first UP security policy of one or more first sessions currently activated between the UE and the first node.

[0179] In some embodiments, the first message comprises: a session identification of each first session and a first UP security policy of the corresponding first session.

[0180] In some embodiments, the first message can be a handover request message, which is used as the first message, but does not mean that the UE needs to handover to the second node at this time.

[0181] S2102: The second node selects a first security algorithm and / or determines a first UP security activation state.

[0182] In some embodiments, the second node selects a first security algorithm supported by both the UE and the second node according to the first capability information of the UE provided by the first node.

[0183] Exemplarily, the second node can select, according to the first capability information of the first node, a first security algorithm for integrity protection supported by both the UE and the second node. Exemplarily, the second node can select, according to the capability information of the first node, a first security algorithm for confidentiality protection supported by both the UE and the second node.

[0184] In some embodiments, the first UP security activation status is determined by the second node according to the first UP security policy.

[0185] In some embodiments, the first UP security activation status can be used to determine whether and / or how to protect the communication between the UE and the second node.

[0186] Exemplarily, the first UP security activation status can include, but is not limited to, at least one of the following:

[0187] a first status in which no protection is needed;

[0188] a second status in which no integrity protection and no confidentiality protection are needed;

[0189] a third status in which integrity protection is needed but no confidentiality protection is needed;

[0190] a fourth status in which confidentiality protection is needed but no integrity protection is needed;

[0191] a fifth status in which both confidentiality protection and integrity protection are needed.

[0192] S2103: The second node sends a second message to the first node.

[0193] In some embodiments, the second message includes security parameters determined by the second node based on the first message. Exemplarily, the second message includes first information. The first information of the mth second node is used to indicate a first security algorithm and a first UP security activation status; the first security algorithm is selected by the mth second node according to the first capability information; and the first UP security activation status is determined by the mth second node according to the first UP security policy. Exemplarily, the first information can be the first security algorithm selected by the mth second node or an algorithm identifier of the first security algorithm selected by the mth second node.

[0194] It is worth noting that the security parameters contained in the second message are not limited to the security parameters determined based on the first message.

[0195] In some embodiments, the second message of the mth second node can include at least one of the following:

[0196] a node identifier of the mth second node.

[0197] a node configuration of the mth second node;

[0198] a first security algorithm selected by the mth second node;

[0199] an algorithm identity of the first security algorithm selected by the mth second node;

[0200] third indication information, used for indicating a first UP security activation status.

[0201] In some embodiments, if the first message is a handover request message, the second message can be a handover request acknowledge message. Although the first node and the second node interact with the handover request message and the handover request acknowledge message, it does not mean that the UE needs to perform handover.

[0202] S2104: The first node sends a third message to the UE.

[0203] In some embodiments, the third message can include a security parameter determined by the second node based on the first message. The security parameter can be used to protect the communication between the UE and the second node. Exemplarily, the third message includes the first information. In some embodiments, the third message includes the node configuration of each second node, and the first information belongs to part of the node configuration of the second node.

[0204] In some embodiments, the first node encapsulates the second message of each second node in the third message in an RRC container and sends it to the UE.

[0205] In some embodiments, the third message can be an RRC configuration message. In an example, the RRC configuration message can be an RRC reconfiguration message.

[0206] In some embodiments, the third message can further include a first parameter. In some embodiments, the first parameter is used by the UE to generate a security key for communication with the first node.

[0207] In some embodiments, the first information can include, but is not limited to, at least one of the following: the first security algorithm selected by the second node itself, an algorithm identity of the first security algorithm, a third parameter. Exemplarily, the third parameter can be a value of a next hop chaining counter (NCC). The value of the NCC can be used by the UE to determine a parameter of a security key for communication with the first node.

[0208] In some embodiments, the first information comprises at least part of security parameters related to the first session, e.g., the first information can comprise parameters required for generating security keys when the second node participates in the second session, etc. However, the first information is not limited to the first session between the UE and the second node, but can also be used for other control plane signaling interaction and / or user plane data communication other than the first session.

[0209] S2105: The third node sends second capability information to the second node.

[0210] In some embodiments, the third node can be a core network node. Exemplarily, the third node can be a mobile management entity (MME) or an access management function (AMF).

[0211] The second capability information is used to indicate the capability of the UE. Exemplarily, the second capability information is used to indicate at least the security capability of the UE. Further exemplarily, the second capability information is used to indicate at least the security algorithm supported by the UE.

[0212] Correspondingly, the second node will receive the second capability information.

[0213] In some cases, if the UE performs cell handover or cell reselection across AMFs, the AMF will send the second capability information to the second node, e.g., the target node of the cell handover or cell reselection. In some other cases, the third node successfully acquires the second capability information of the UE, and the third node sends the second capability information to the second node. There are many scenarios for the third node to send the second capability information to the second node, and the implementation is not limited to the example.

[0214] S2106: The second node sends a fourth message to the UE.

[0215] In some embodiments, the second capability information is different from the first capability information, and the second node sends the fourth message to the UE. Exemplarily, the second capability information and the first capability information indicate different security algorithms supported by the UE, and the second node sends the fourth message to the UE. Alternatively, the second capability information and the first capability information indicate different security algorithms supported by the UE and the first security algorithm is not indicated by the second capability information, and the second node sends the fourth message to the UE. Alternatively, the second capability information indicates that the UE does not support the first security algorithm, and the second node sends the fourth message to the UE. Alternatively, the second capability information indicates that the UE supports a second security algorithm and the first capability information indicates that the UE does not support the second security algorithm, and the second node sends the fourth message to the UE. It is worth noting that the second security algorithm can be any security algorithm supported by the UE and the second node according to the second capability information, and it is not required to have better performance than the first security algorithm.

[0216] In some embodiments, S2106 is an optional step to save unnecessary signaling overhead if the second capability information is the same as the first capability information, or the second security algorithm selected according to the second capability information is the same as the first security algorithm selected according to the first capability information.

[0217] In some embodiments, the fourth message can be any message sent by the second node to the UE for establishing an RRC connection. In some embodiments, the fourth message can be any RRC message sent by the second node to the UE after the RRC connection establishment is completed.

[0218] S2107: The fourth node sends a third UP security policy to the second node.

[0219] In some embodiments, the fourth node can be a core network node. Exemplarily, the fourth node can include, but is not limited to, a Session Management Function (SMF) and / or a Policy Control Function (PCF).

[0220] The third UP security policy is used to determine the UP security activation state when the UE communicates with the second node. Exemplarily, the UP security activation state indicated by the third UP security policy can be any one of the first to fifth states. In some cases, the UP security activation state can also include a state corresponding to other security algorithms, such as a scrambling algorithm, etc.

[0221] Correspondingly, the second node will receive the third UP security policy.

[0222] In some embodiments, the fourth node can send the third UP security policy to the second node when performing session update or other operations on the UE. However, the fourth node is not limited to sending the third UP security policy to the second node only when performing session update.

[0223] Exemplarily, the third UP security policy and the first UP security policy are both security policies for the first session.

[0224] S2108: The second node sends a fifth message to the UE.

[0225] In some embodiments, the second node sends the fifth message to the UE in the case that the third UP security policy is different from the first UP security policy. Exemplarily, the second node sends the fifth message to the UE in the case that the UP security activation state indicated by the third UP security policy is different from the first UP security policy.

[0226] Exemplarily, the fifth message is used for the UE to determine the third UP security activation state.

[0227] In some embodiments, the fifth message can be any message that the second node sends to the UE to establish an RRC connection with the UE. In some embodiments, the fifth message can be any RRC message that the second node sends to the UE after the second node and the UE complete the establishment of the RRC connection.

[0228] In some embodiments, the fifth message and the fourth message can be the same message. In other embodiments, the fifth message and the fourth message are different messages.

[0229] In the above embodiments, any one of S2101 to S2108 can be implemented alone. For example, the first node can send the first message to the second node. After receiving the first message, the second node can temporarily store the first message. When the second node needs to be switched to the serving node of the UE, the second node does not need to temporarily obtain the first message from the first node, at this time, S2101 can be implemented alone. Illustratively, after receiving the first message, the second node can determine the first information by itself, but it does not necessarily send the second message to the first node to prepare to negotiate the first security algorithm in advance, and it can only be that the first node completes the selection of the first security algorithm in advance. In some embodiments, S2101 and S2102 can be combined to be implemented. S2101 to S2103 can be combined to be implemented, and the second node not only completes the selection of the first security algorithm, but also returns the first security algorithm to the first node or informs the first node through the second message that the second node has completed the selection of the first security algorithm. That is, the first information is also an optional content of the second message. In some embodiments, S2101 to S2104 can be combined to be implemented. Thus, when the UE is connected to the initial base station, not only the acquisition of the related parameters of the security context between the first node is completed, but also the security parameters for the UE to communicate with the second node are acquired.

[0230] It is worth noting that any one or more of S2105 to S2108 can be optional steps and need not be performed. For example, if the third node and / or the fourth node does not send the second capability information and / or the third UP security policy to the second node, then it is clear that S2105 and S2107 need not be performed. Whether S2106 is performed depends on whether the first capability information and the second capability information are the same, or whether the first security algorithm and the second security algorithm are the same. Whether S2108 is performed depends on whether the first UP security policy and the third UP security policy are the same, or whether the UP security activation state determined according to the first UP security policy and the third UP security policy is the same. Exemplarily, S2101 to S2106 can be combined embodiments. S2101 to S2104, S2107 to S2108 can be combined embodiments. It is worth noting that the execution order of S2101 to S2108 can be as shown in FIG. 2A, but is not limited to that shown in FIG. 2A. For example, S2105 and S2107 can be performed simultaneously, or S2107 can be performed first and then S2105 can be performed. For another example, S2106 and S2108 also do not have a certain order.

[0231] In some embodiments, the term “information” can be mutually replaced with the terms “message”, “signal”, “signaling”, “report”, “configuration”, “indication”, “instruction”, “command”, “channel”, “parameter”, “field”, “data”, and the like.

[0232] In some embodiments, “acquire”, “obtain”, “get”, “receive”, “transmit”, “bidirectional transmission”, “send and / or receive” can be mutually replaced, which can be interpreted as receiving from other subjects, acquiring from a protocol, acquiring from a higher layer, obtaining by self-processing, autonomously implementing, and the like. The protocol includes at least one of a 3GPP protocol, a Wi-Fi protocol, an audio and / or video protocol, and the like. In some embodiments, the term “send” can be mutually replaced with the terms “transmit”, “report”, “transmit”, and the like.

[0233] In some embodiments, each step in the present embodiments S2101 to S2104 can be independently implemented, or can be combined and implemented in any order without contradiction. Exemplarily, after the second node receives the first message, the second node is also deleted from the candidate node of the UE, then the second node can not perform S2102, and then there is naturally no subsequent steps S2103 to S2104.

[0234] The embodiment of the disclosure provides a security parameter processing method, which is executed by a communication system shown in FIG. 1A. As shown in FIG. 2B, the method can include the following steps.

[0235] S2201: The first node sends a first message to at least one second node.

[0236] In some embodiments, the first node and the second node can both be access network nodes.

[0237] In some embodiments, the first node can be an initial base station of LTM switching of the UE. The second node can be a candidate base station of LTM switching of the UE.

[0238] In some embodiments, the first node can be a current serving base station of the UE, and the second node can be a neighboring node of the first node.

[0239] In some embodiments, the first node can be a source base station of LTM switching of the UE, and the second node can be a target base station of LTM switching of the UE.

[0240] In some embodiments, the first node sends the first message to the at least one second node in an LTM preparation phase.

[0241] In some embodiments, the first node can send the first message to the at least one second node through an X2 interface, an Xn interface, or a backhaul link.

[0242] In some embodiments, the first message includes information related to a security context of layer 1 / layer 2 triggered mobility (LTM) of a user equipment (UE).

[0243] In some embodiments, the first message includes at least one of the following:

[0244] UE identification, used to identify the UE; the identification information of the UE can refer to any one of the preceding embodiments, and specific examples are not given here;

[0245] A second UP security policy used to protect a second session currently activated by the UE;

[0246] A session identification of the second session.

[0247] In some embodiments, the second session can be any one of the sessions currently activated by the UE. The second session can be one or more. The second UP security policies of different second sessions can be the same or different.

[0248] In some embodiments, the first node obtains a second user plane (UP) security policy of a second session of the UE, sends the first message to the second node, and the first message includes the second UP security policy of the second session; the second UP security policy is used to protect the second session currently activated by the UE.

[0249] Exemplarily, the first node sends a first message to the second node, requesting a second UP security policy for a second session from the core network node. Further, the first node sends the second UP security policy to the second node after obtaining the second UP security policy for the second session and successfully activating the second session.

[0250] Exemplarily, the first node determines the second node to which the UE is to be handed over based on a layer 3 measurement report of the UE, and sends the first message to the second node before the UE is handed over to the second node. Further, the first node sends the second UP security policy to the second node in a preparation phase of the UE being handed over to the second node.

[0251] In some embodiments, the second UP security policy is used to protect a second session currently activated by the UE. Exemplarily, the second session can be a newly established session of the UE. Exemplarily, the second session is different from the first session.

[0252] In some embodiments, if the first node is an initial base station of the UE, the first node can further send the second UP security policy to the second node in a candidate base station configuration procedure of performing LTM of the UE.

[0253] In some embodiments, the first message is a handover request message.

[0254] S2202: The second node stores the second UP security policy.

[0255] In some embodiments, the second UP security policy is used by the second node to determine an activation manner of protecting a second session, which is a newly established activated session of the UE.

[0256] In some embodiments, after the second node stores the second UP security policy, the UE is handed over to the second node, the second node can directly protect the second session of the UE based on the locally stored second UP security policy, so that the second node does not need to request the second UP security policy from the core network or temporarily request the second UP security policy from the first node.

[0257] In some embodiments, the second node can determine a second UP security activation state according to the second UP security policy. The optional states of the second UP security activation state can be the same as the first UP security activation state, for example, both can be any one of the first state value and the fifth state.

[0258] S2203: The second node sends a second message.

[0259] In some embodiments, the second message includes a security parameter determined by the second node based on the first message. Exemplarily, the second message includes the second information. However, it is worth noting that the content of the second message is not limited to the security parameter determined by the second node based on the first message.

[0260] In some embodiments, if the first message is a handover request message, the second message can be a handover request acknowledgement message.

[0261] In some embodiments, sending the second message can be an optional step, for example, if the first message is a notification message, the second node does not need to reply to the first node.

[0262] In some embodiments, the second message includes second information of the mth second node; the second information of the mth node is used to indicate a second UP security activation state determined by the mth second node, and the second UP security activation state is determined according to a second UP security policy.

[0263] In some embodiments, the second message can be used to indicate the second UP security activation state selected by the second node.

[0264] Correspondingly, the first node will receive the second message sent by the second node.

[0265] S2204: The first node sends a third message to the UE.

[0266] In some embodiments, the third message includes a security parameter determined by the second node based on the first message. The security parameter can be used to protect the communication between the UE and the second node. Illustratively, the third message includes second information; the second information is used at least for the UE to determine the security parameter for the second session with the second node. Illustratively, the security parameter can include a parameter for generating a key, etc.

[0267] It is worth noting that this step is an optional step, and the second UP security activation state can also be sent to the UE in the process of establishing an RRC connection with the UE by the second node.

[0268] S2205: The third node sends second capability information to the second node.

[0269] In some embodiments, the third node can be a core network node. Illustratively, the third node can be a mobile management entity (MME) or an access management function (AMF).

[0270] The second capability information is used to indicate the capability of the UE. Illustratively, the second capability information is used at least to indicate the security capability of the UE. Illustratively, the second capability information is used at least to indicate the security algorithm supported by the UE.

[0271] Correspondingly, the second node will receive the second capability information.

[0272] In some cases, the AMF sends the second capability information to a second node, e.g., a target node of the cell handover or cell reselection, if the UE performs a cell handover or cell reselection across AMFs. In some other cases, the third node successfully acquires the second capability information of the UE, and the third node sends the second capability information to the second node. There are many scenarios in which the third node sends the second capability information to the second node, and the specific implementation is not limited to this example.

[0273] S2206: The second node sends a fourth message to the UE.

[0274] In some embodiments, the second capability information and the first capability information are different, and the second node sends the fourth message to the UE. Illustratively, the second capability information and the first capability information indicate that the UE supports different security algorithms, and the second node sends the fourth message to the UE. Alternatively, the second capability information and the first capability information indicate that the UE supports different security algorithms and the first security algorithm is not a security algorithm that the UE supports according to the second capability information, and the second node sends the fourth message to the UE. Alternatively, the second capability information indicates that the UE does not support the first security algorithm, and the second node sends the fourth message to the UE. Alternatively, the second capability information indicates that the UE supports a second security algorithm and the first capability information indicates that the UE does not support the second security algorithm, and the second node sends the fourth message to the UE. It is worth noting that the second security algorithm can be any security algorithm that the UE and the second node both support according to the second capability information, and it is not required to necessarily have better performance than the first security algorithm.

[0275] In some embodiments, if the second capability information and the first capability information are the same, or the second security algorithm selected according to the second capability information and the first security algorithm selected according to the first capability information are the same, S2106 is an optional step to save unnecessary signaling overhead.

[0276] In some embodiments, the fourth message can be any message in which the second node establishes an RRC connection with the UE. In some embodiments, the fourth message can be any RRC message that the second node sends to the UE after the RRC connection establishment is completed.

[0277] S2207: The fourth node sends a fourth UP security policy to the second node.

[0278] In some embodiments, the fourth node can be a core network node. Illustratively, the fourth node can include, but is not limited to, a session management function (SMF) and / or a policy control function (PCF).

[0279] The fourth UP security policy is used to determine the UP security activation state when the UE communicates with the second node. Illustratively, the UP security activation state indicated by the fourth UP security policy can be any one of the first to fifth states described above. In some cases, the UP security activation state can also include a state corresponding to other security algorithms, e.g., a ciphering algorithm, etc.

[0280] Correspondingly, the second node will receive the fourth UP security policy.

[0281] In some embodiments, the fourth node can send the fourth UP security policy to the second node when performing session update of the UE, etc. However, the fourth node is not limited to sending the fourth UP security policy to the second node only when performing session update.

[0282] Illustratively, the fourth UP security policy and the second UP security policy are both security policies for the first session.

[0283] The second UP security policy and the fourth UP security policy are associated with the same session, illustratively, the second session.

[0284] S2208: The second node sends a sixth message to the UE.

[0285] In some embodiments, the second node sends the fifth message to the UE in the case that the fourth UP security policy is different from the second UP security policy. Illustratively, the second node sends the sixth message to the UE in the case that the third UP security policy and the second UP security policy indicate different UP security activation states.

[0286] Illustratively, the sixth message is used for the UE to determine the third UP security activation state.

[0287] In some embodiments, the sixth message can be any message sent by the second node to the UE to establish an RRC connection. In some embodiments, the sixth message can be any RRC message sent by the second node to the UE after the RRC connection establishment is completed.

[0288] In some embodiments, the sixth message and the fourth message can be the same message. In other embodiments, the sixth message and the fourth message are different messages.

[0289] In the above embodiments, any one of S2201 to S2208 can be implemented alone. For example, the first node can send the first message to the second node. The second node can temporarily store the first message after receiving the first message, and the second node does not need to temporarily obtain the first message from the first node when the second node needs to be switched to the serving node of the UE, at this time, S2201 can be implemented alone. Illustratively, the second node can determine the second information by itself after receiving the first message, but does not necessarily send the second message to the first node to prepare in advance the negotiation of the first security algorithm, and can only be that the first node completes the selection of the first security algorithm in advance. In some embodiments, S2201 and S2202 can be combined and implemented. S2201 to S2203 can be combined and implemented, and the second node not only completes the selection of the first security algorithm, but also returns the first security algorithm to the first node or informs the first node through the second message that the second node has completed the selection of the first security algorithm. That is, the second information is also an optional content of the second message. In some embodiments, S2201 to S2204 can be combined and implemented. Thus, when the UE is connected to the initial base station, not only the acquisition of the related parameters of the security context between the first node is completed, but also the security parameters for the UE to communicate with the second node are acquired.

[0290] It is worth noting that any one or more of S2205 to S2208 can be optional steps and do not necessarily need to be executed. For example, the third node and / or the fourth node does not send the second capability information and / or the third UP security policy to the second node, and obviously S2205 and S2207 do not need to be executed. Whether S2206 is executed depends on whether the first capability information and the second capability information are the same, or whether the first security algorithm and the second security algorithm are the same. Whether S2208 is executed depends on whether the first UP security policy and the third UP security policy are the same, or whether the UP security activation state determined according to the first UP security policy and the third UP security policy is the same. Illustratively, S2201 to S2206 can be combined and implemented. S2201 to S2204, S2207 to S2208 can be combined and implemented.

[0291] It is worth noting that the execution order of S2201 to S2208 can be as shown in FIG. 2B, but is not limited to that shown in FIG. 2B. For example, S2205 and S2207 can be executed at the same time, or S2207 can be executed first and then S2205 can be executed. For another example, S2206 and S2208 also do not have a certain order.

[0292] In some embodiments, the term "information" can be mutually interchangeable with the terms "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "field", "data", and the like.

[0293] In some embodiments, "acquire", "obtain", "get", "receive", "transmit", "bidirectional transmission", "send and / or receive" can be mutually interchangeable, which can be interpreted as receiving from other subjects, acquiring from protocols, acquiring from higher layers, obtaining by self-processing, autonomously implementing, and the like. The protocols include at least one of 3GPP protocols, Wi-Fi protocols, audio and / or video protocols, and the like. In some embodiments, the term "send" can be mutually interchangeable with the terms "transmit", "report", "transmit", and the like. In some embodiments, each step in the embodiments S2201 to S2203 can be independently implemented, or can be arbitrarily exchanged in order and combined for implementation under non-contradictory conditions. In some embodiments, S2203 is an optional step. For example, the first node can default that the second node receives the first message without the second node specifically replying to the second message for confirmation.

[0294] It is worth noting that in the embodiments of the present disclosure, both the first session and the second session belong to the current active session of the UE. The embodiment corresponding to FIG. 2A can be a special case of the embodiment corresponding to FIG. 2B. In some embodiments, the embodiment corresponding to FIG. 2B can also be a subsequent execution flow of the embodiment corresponding to FIG. 2A.

[0295] The embodiments of the present disclosure provide a security parameter processing method, which is executed by the communication system shown in FIG. 1A. As shown in FIG. 2C, the method can include:

[0296] S2301: The first node sends a first message to at least one second node.

[0297] In some embodiments, the first node and the second node can both be access network nodes.

[0298] In some embodiments, the first node can be an initial base station of LTM switching of the UE. The second node can be a candidate base station of LTM switching of the UE.

[0299] In some embodiments, the first node can be a current serving base station of the UE. The second node can be a base station that provides service to the UE subsequently.

[0300] In some embodiments, the first node sends the first message to the at least one second node in an LTM preparation phase.

[0301] In some embodiments, the first node can send the first message to the at least one second node over an X2 interface, an Xn interface, or a backhaul link.

[0302] In some embodiments, the first message comprises information related to a security context of Layer 1 / Layer 2 triggered mobility (LTM) of a user equipment (UE).

[0303] In some embodiments, the first message can comprise information related to the security context of the LTM of the UE and / or the security capability of the UE.

[0304] In some embodiments, the first message comprises at least one of:

[0305] a UE identity, used to identify the UE;

[0306] first capability information of the UE, used to at least indicate a security capability of the UE;

[0307] a first UP security policy, used to protect a first session currently activated by the UE.

[0308] The specific content contained in the first message and the related description of each content, and the specific message corresponding to the first message can be referred to the corresponding embodiments of FIG. 2A, which will not be repeated here.

[0309] S2302: The second node selects a first security algorithm and / or determines a first UP security activation state.

[0310] In some embodiments, the second node selects, according to the first capability information of the UE provided by the first node, a first security algorithm supported by both the UE and the second node.

[0311] For example, the second node can select, according to the first capability information of the first node, a first security algorithm for integrity protection supported by both the UE and the second node. For another example, the second node can select, according to the capability information of the first node, a first security algorithm for confidentiality protection supported by both the UE and the second node.

[0312] In some embodiments, the first UP security activation state is determined by the second node according to the first UP security policy.

[0313] In some embodiments, the first UP security activation state can be used to determine whether the communication between the UE and the second node needs to be protected and / or how to protect.

[0314] In some embodiments, the first UP security activation state, the first UP security policy, the second node, and the first capability information can be referred to the corresponding embodiments of FIG. 2A, which will not be repeated here.

[0315] S2303: The second node sends a second message to the first node.

[0316] In some embodiments, the second message includes the security parameters determined by the second node based on the first message. For example, the second message includes the first information. The first information of the mth second node is used to indicate the first security algorithm and the first UP security activation state; the first security algorithm is selected by the mth second node according to the first capability information; and the first UP security activation state is determined by the mth second node according to the first UP security policy. For example, the first information can be the first security algorithm selected by the mth second node or the algorithm identifier of the first security algorithm selected by the mth second node.

[0317] It is worth noting that the security parameters contained in the second message are not limited to the security parameters determined based on the first message.

[0318] In some embodiments, the second message of the mth second node can include at least one of the following:

[0319] The node identifier of the mth second node;

[0320] The node configuration of the mth second node;

[0321] The first security algorithm selected by the mth second node;

[0322] The algorithm identifier of the first security algorithm selected by the mth second node;

[0323] Third indication information used to indicate the first UP security activation state.

[0324] In some embodiments, if the first message is a handover request message, the second message can be a handover request acknowledgement message. Although the first node and the second node interact with the handover request message and the handover request acknowledgement message, it does not mean that the UE needs to be handed over.

[0325] S2304: The first node sends a third message to the UE.

[0326] In some embodiments, the third message can include the security parameters determined by the second node based on the first message. The security parameters can be used to protect the communication between the UE and the second node. For example, the third message includes the first information. In some embodiments, the third message includes the node configuration of each second node, and the first information belongs to part of the node configuration of the second node.

[0327] In some embodiments, the first node sends the second message of each second node to the UE in a third message encapsulating the second message in an RRC container.

[0328] In some embodiments, the third message can be an RRC configuration message. In an example, the RRC configuration message can be an RRC reconfiguration message.

[0329] In some embodiments, the third message can further comprise a first parameter. In some embodiments, the first parameter is used by the UE to generate a security key for communication with the first node.

[0330] In some embodiments, the first information can comprise, but is not limited to, at least one of: the first security algorithm selected by the second node itself, an algorithm identity of the first security algorithm, a third parameter. Exemplarily, the third parameter can be a value of a next hop chaining counter (NCC). The value of the NCC can be used by the UE to determine a parameter of the security key for communication with the first node.

[0331] In some embodiments, the first information comprises at least part of the security parameters related to the first session, e.g., the first information can comprise parameters required by the second node to generate a security key when participating in the second session. However, the first information is not limited to be used for the first session between the UE and the second node, but can also be used for other control plane signaling interactions and / or user plane data communications other than the first session.

[0332] Embodiments of the present disclosure provide a security parameter processing method, which is performed by the communication system shown in FIG. 1A. As shown in FIG. 2D, the method can comprise:

[0333] S2401: The first node sends a first message to at least one second node.

[0334] In some embodiments, the first node and the second node can both be access network nodes.

[0335] In some embodiments, the first node can be an initial base station for LTM handover of the UE. The second node can be a candidate base station for LTM handover of the UE.

[0336] In some embodiments, the first node can be a current serving base station of the UE, and the second node can be a neighboring node of the first node.

[0337] In some embodiments, the first node can be a source base station for LTM handover of the UE, and the second node can be a target base station for LTM handover of the UE.

[0338] In some embodiments, the first node sends the first message to the at least one second node in an LTM preparation phase.

[0339] In some embodiments, the first node can send the first message to the at least one second node through an X2 interface, an Xn interface, or a backhaul link.

[0340] In some embodiments, the first message comprises information related to a security context of a Layer 1 / Layer 2 triggered mobility (LTM) of a user equipment (UE).

[0341] In some embodiments, the first message comprises at least one of:

[0342] an identifier of the UE, which can refer to the identifier of the UE in any of the preceding embodiments and will not be repeated here;

[0343] a second UP security policy for protecting a second session currently activated by the UE;

[0344] a session identifier of the second session.

[0345] In some embodiments, the second session can be any one of the sessions currently activated by the UE. There can be one or more second sessions. The second UP security policies of different second sessions can be the same or different.

[0346] In some embodiments, the first node obtains a second UP security policy of a second session of the UE, and sends the first message to the second node, wherein the first message comprises the second UP security policy of the second session; and the second UP security policy is used for protecting the second session currently activated by the UE.

[0347] For example, the first node requests the second UP security policy of the second session from a core network node, and sends the first message to the second node. Further, after obtaining the second UP security policy of the second session and successfully activating the second session, the first node sends the second UP security policy to the second node.

[0348] For another example, the first node determines the second node to which the UE is to be handed over based on a Layer 3 measurement report of the UE, and sends the first message to the second node before the UE is handed over to the second node. Further, in a preparation stage of the UE being handed over to the second node, the first node sends the second UP security policy to the second node.

[0349] In some embodiments, the second UP security policy is used for protecting a second session currently activated by the UE. For example, the second session can be a newly established session of the UE. For example, the second session is different from the first session.

[0350] In some embodiments, if the first node is an initial base station of the UE, the first node can further send the second UP security policy to the second node in a candidate base station configuration process of the LTM of the UE.

[0351] In some embodiments, the first message is a handover request message.

[0352] S2402: The second node stores the second UP security policy.

[0353] In some embodiments, the second UP security policy is used by the second node to determine an activation manner of protecting a second session, the second session being an active session newly established by the UE.

[0354] In some embodiments, after the second node stores the second UP security policy, the UE switches to the second node, the second node can directly protect the second session of the UE based on the locally stored second UP security policy, so that the second node does not need to request the second UP security policy from the core network or temporarily request the second UP security policy from the first node.

[0355] In some embodiments, the second node can determine a second UP security activation state according to the second UP security policy. The optional states of the second UP security activation state can be the same as the first UP security activation state, for example, both can be any one of the first state value and the fifth state.

[0356] S2403: The second node sends a second message.

[0357] In some embodiments, the second message includes the security parameters determined by the second node based on the first message. Exemplarily, the second message includes the second information. However, it is worth noting that the content of the second message is not limited to the security parameters determined by the second node based on the first message.

[0358] In some embodiments, if the first message is a handover request message, the second message can be a handover request acknowledgement message.

[0359] In some embodiments, sending the second message can be an optional step, for example, if the first message is a notification message, the second node does not need to respond to the first node.

[0360] In some embodiments, the second message includes second information of the mth second node; the second information of the mth node is used to indicate a second UP security activation state determined by the mth second node, the second UP security activation state being determined according to the second UP security policy.

[0361] In some embodiments, the second message can be used to indicate the second UP security activation state selected by the second node.

[0362] Correspondingly, the first node will receive the second message sent by the second node.

[0363] S2404: The first node sends a third message to the UE.

[0364] In some embodiments, the third message includes a security parameter determined by the second node based on the first message. The security parameter can be used to protect the communication between the UE and the second node. Illustratively, the third message includes second information; the second information is used by the UE to determine a security parameter for the second session with the second node. Illustratively, the security parameter can include a parameter for generating a key, etc.

[0365] It is worth noting that this step is an optional step, and the second UP security activation state can also be sent to the UE by the second node in the process of establishing an RRC connection with the UE.

[0366] Embodiments of the present disclosure provide a security parameter processing method, which can be used to implement complete security context synchronization when the UE performs LTM switching. Illustratively, the security context synchronization can include negotiated AS security algorithms and UP security policies applied to the current PDU session.

[0367] In some embodiments, as shown in FIG. 3A, in order to implement the enhancement of inter-gNB LTM, the RRC configuration of the candidate gNB can be pre-configured by the initial gNB and delivered to the UE in the LTM preparation phase.

[0368] In the LTM preparation phase, the UE security capabilities are sent by the initial gNB to the candidate gNBs. Each candidate gNB selects AS security algorithms for the AS security of the UE based on the UE security capabilities and the security capabilities of the candidate gNB. Then, each candidate gNB includes the selected AS security algorithms in the LTM configuration sent to the UE via the initial gNB.

[0369] In addition, during the LTM preparation, there can be an active PDU session running between the UE and the initial gNB, for which the UP security is activated based on the UP security policy received from the core network in the initial gNB. The present disclosure proposes that the UP security policy related to a specific active PDU session is also sent by the initial gNB to the candidate gNBs in the LTM preparation phase. If the PDU session remains unchanged during the LTM switching, the target gNB (one of the candidate gNBs) applies the UP security policy received in the LTM preparation phase to the PDU session. If the PDU session has changed, i.e., the old PDU session is released and a new PDU session is established, it is necessary to configure the UP security policy of the new PDU session again on the candidate gNBs through the LTM preparation.

[0370] As shown in FIG. 3B, the security algorithm negotiation and UP security policy in inter-gNB LTM can include:

[0371] 1. The connected UE sends an RRC measurement report to the serving / source gNB.

[0372] 2. The serving / source gNB decides to prepare LTM for candidate gNBs.

[0373] 3. The serving / source gNB sends a handover request to each candidate gNB, which includes the UE security capabilities and the UP security policy associated with the current active PDU session (e.g. session 1) of the UE. The UP security policy is received from the core network (SMF) during PDU session establishment and stored in the serving / source gNB. Exemplarily, step 3 can include step 3a and step 3b. Step 3a: gNB0 sends a handover request to gNB1. Step 3b: gNB0 sends a handover request to gNB2. At this time, the handover request sent by gNB0 both includes the capability information of the UE, which is the aforementioned first capability information.

[0374] 4. Each candidate gNB selects AS security algorithms for the UE’s AS security based on the received UE security capabilities and the candidate gNB’s own security capabilities, as well as the algorithm priority list configured in the candidate gNB. Then, the candidate gNB stores the selected AS security algorithms in the LTM configuration to send to the UE. Exemplarily, step 4 can include step 4a and step 4b. Step 4a: gNB1 performs access control, selects AS algorithms and stores the UP security policy of session 1. Step 4b: gNB2 performs access control, selects AS algorithms and stores the UP security policy of session 1.

[0375] Each candidate gNB also stores the received UP security policy associated with the current active PDU session (e.g. session 1).

[0376] 5. Each candidate gNB returns the LTM configuration to the serving / source UE through a handover request acknowledgement. Exemplarily, step 5 can include step 5a and step 5b. Step 5a: gNB1 sends a handover request acknowledgement to gNB0, which can include: gNB1 configuration. The configuration can include the AS algorithms selected by gNB1. Exemplarily, the AS algorithm in the embodiment of the present disclosure is one of the aforementioned security algorithms, which can be used to protect the AS layer communication. Step 5b: gNB2 sends a handover request acknowledgement to gNB0, which can include: gNB2 configuration. The configuration can include the AS algorithms selected by gNB2. Exemplarily, the AS algorithm in the embodiment of the present disclosure is one of the aforementioned security algorithms, which can be used to protect the AS layer communication.

[0377] 6. The serving / source gNB sends its own and the candidate gNB’s LTM configuration to the UE. The serving / source gNB includes NCC1 in the RRC reconfiguration message. If the serving / source gNB has unused NHs, the configured NCC value NCC1 = 1. If the serving / source gNB does not have any unused NHs, the configured NCC value NCC1 = 0.

[0378] 7-11. Perform LTM handover with AS security key update and handover the UE to gNB1.

[0379] 7. The UE sends a layer 1 measurement report to the serving or source base station (e.g., gNB0);

[0380] 8. After selecting the target gNB (candidate gNB1), the serving / source gNB determines whether to trigger the LTM procedure. If the serving / source gNB does not have any unused NH, the serving / source gNB performs horizontal key derivation, i.e., derives K gNB0 from K NB-RAN *according to K NG-RAN *← KDF(K gNB0 , Cell Identity). If the serving / source gNB has an unused NH (associated with NCC1), the serving / source gNB performs vertical key derivation, i.e., derives K NB-RAN from the unused NH, i.e., K NG-RAN *← KDF(NH1, Cell Identity).

[0381] 9. The serving / source gNB sends the derived K NB-RAN *to the candidate gNB1 and the NCC value (i.e., NCC1) used for K NB-RAN *derivation. The gNB1 uses K NB-RAN *as K gNB1 and returns the NCC value (NCC1) to the serving / source gNB. Exemplarily, step 9 can include step 9a, step 9b, and step 9c. Step 9a: gNB1 sends a key request to gNB0 for requesting a key or security parameters for generating a key, e.g., KgNB1, KNG-RAN*, NCC1. Step 9b: generate KNG-RAN* based on KNG-RAN*. Step 9c: a key confirmation request including NCC1.

[0382] 10. The serving / source gNB sends a MAC CE message to the UE indicating the target gNB (candidate gNB1). In some embodiments, the MAC CE can include an indication of the key update type (i.e., first indication information).

[0383] 11. Upon receiving the MAC CE from the serving / source gNB, the following steps can be performed. In one example, the UE first determines the key update type based on the preconfigured cell identity of the target gNB or based on the indication of the key update type received through the MAC CE message. If the indication indicates K AMF update, the UE performs derivation, i.e., K gNB = KDF(Uplink NAS COUNT, K AMF ). In another example, if the indication indicates K AMF update, the UE performs derivation, i.e., K gNB = KDF(Uplink NAS COUNT, K AMF ). In another example, if the indication indicates K AMF update, the UE performs derivation, i.e., K gNB = KDF(Uplink NAS COUNT, K AMF ). In another example, if the indication indicates K AMF update, the UE performs derivation, i.e., K gNB = KDF(Uplink NAS COUNT, K AMF ). In another example, if the indication indicates KgNB Update is performed, the UE performs horizontal key derivation (i.e., K NG-RAN *← KDF(K gNB0 , Cell Identity)); if update by NH is indicated, the UE selects to perform vertical key derivation by NCC1 pre-configured by the serving / source gNB in the LTM preparation phase, i.e., derive NH and K NG-RAN * (i.e., NH1 = KDF(NH, K AMF ), K NG-RAN *← KDF(NH1, Cell Identity)). In some embodiments, the UE leaves from the serving / source gNB and applies the configuration of the target gNB (candidate gNB1) which includes using K NG-RAN * as K gNB1 to be used for gNB1.

[0384] 12-14. After the path switching procedure is completed with the AMF, the LTM switching is completed. The AMF generates a new pair of NH and NCC (NH2, NCC2) and passes them to gNB1, where the new NCC value (NCC2) is sent to the UE through RRC reconfiguration.

[0385] 12. The UE sends an RRC reconfiguration complete message to gNB1.

[0386] 13a. The target gNB (gNB1) sends an N2 path switch request to the AMF, which includes an LTM switching indication (i.e., second indication information).

[0387] 13b. Upon receiving the N2 path switch request, the AMF updates the NH (e.g., from NH1 to NH2) and increments the corresponding NCC value (e.g., from NCC1 to NCC2).

[0388] 13c. The AMF returns the new NH and NCC (i.e., NH2 and NCC2) to gNB1 in an N2 path switch response message.

[0389] 14. Upon receiving the LTM switching indication, gNB1 forwards or transmits the new NCC value (NCC2) from the AMF through NAS signaling, so that the UE receives the updated NCC value. The NCC value is the value of the aforementioned first parameter.

[0390] 15. User data of PDU session 1 is switched from gNB0 to gNB1, and gNB1 applies the UP security policy received from gNB0 in the LTM preparation phase to protect the user data.

[0391] 16. While connected with gNB1, the UE releases PDU session 1 and establishes a new PDU session (e.g. session 2) through gNB1, gNB1 receives a new UP security policy associated with PDU session 2 from the core network (e.g. SMF).

[0392] 17. After the new UP security is activated, gNB1 decides to perform LTM candidate preparation.

[0393] 18. gNB1 sends a handover request to the candidate gNB (gNB2) including the UP security policy associated with the UE’s current active PDU session 2.

[0394] 19. gNB2 stores the received UP security policy associated with the current active PDU session 2.

[0395] 20. gNB2 returns the LTM configuration to gNB1 through the handover request acknowledgement.

[0396] 21-25. The LTM handover is performed together with the AS security’s synchronized key update, the UE hands over to gNB2.

[0397] 21. During the UE’s mobility, the UE sends an L1 measurement report to the serving / source gNB (gNB1).

[0398] 22. After selecting the target gNB (candidate gNB2), the serving / source gNB (gNB1) determines whether it needs to trigger the LTM procedure. Since the serving / source gNB has an unused NH (NH2 associated with NCC2), the serving / source gNB performs vertical key derivation, i.e. derives K NB-RAN *from the unused NH (i.e. K NG-RAN *← KDF(NH2, cell identity)).

[0399] In some embodiments, in case of intra-CU handover is triggered later, the serving / source gNB does not have any unused NH, then the serving / source gNB performs horizontal key derivation, i.e. derives K gNB1 from K NB-RAN * (i.e. K NG-RAN *← KDF(K gNB1 , cell identity)).

[0400] 23a. The serving / source gNB (gNB1) sends the derived K NB-RAN *to the candidate gNB2 along with the NCC value (i.e. NCC2) used for K NB-RAN *derivation.

[0401] 23b. gNB2 uses K NB-RAN *as K gNB2 ;

[0402] 23c. Return the NCC value (NCC2) to the serving / source gNB.

[0403] 24. The gNB1 sends a MAC CE message to the UE, which indicates the target gNB (candidate gNB2). In some embodiments, the MAC CE can include an indication of the key update type (i.e., first indication information).

[0404] 25. The UE first determines the handover key update type based on the preconfigured cell identity of the target gNB or based on the indication of the key update type received through the MAC CE message. If the indication is updated by K AMF , the UE derives K gNB = KDF (uplink NAS COUNT, K AMF ). If the indication is updated by K gNB , the UE performs horizontal key derivation (i.e., K NG-RAN * <- KDF (K gNB1 , cell identity)); if the indication is updated by NH, the UE selects NCC2 for vertical key derivation, i.e., derives NH and K NG-RAN * (i.e., NH2 = KDF (NH1, K AMF ), K NG-RAN * <- KDF (NH2, cell identity)). The UE leaves from the serving / source gNB and applies the configuration of the target gNB (candidate gNB2), which includes using K NG-RAN * as K gNB2 to be used for gNB2.

[0405] 26-28. After completing the path switching procedure with the AMF, the LTM handover is completed. The AMF generates a new pair of NH and NCC (NH3, NCC3) and passes them to gNB2, where the new NCC value (NCC3) is sent to the UE through RRC reconfiguration.

[0406] 26. The UE sends an RRC reconfiguration complete message to the target gNB.

[0407] 27a. The target gNB (gNB2) sends an N2 path switch request to the AMF, which includes an LTM handover indication (i.e., second indication information) in the request.

[0408] 27b. Upon receiving the N2 path switch request, the AMF updates the NH (e.g., from NH2 to NH3) and increments the corresponding NCC value (e.g., from NCC2 to NCC3).

[0409] 27c. The AMF returns the new NH and NCC (i.e., NH3 and NCC3) to the gNB2 in an N2 path switch response message.

[0410] 28. Received LTM handover indication, target base station forwards or transmits new NCC value (NCC3) sent by AMF through NAS signaling to UE.

[0411] 29. User data of PDU session 2 is handed over from gNB1 to gNB2, gNB2 applies UP security policy received from gNB2 to protect user data in LTM preparation phase.

[0412] In some embodiments, gNB should be able to send UE security capabilities and UP security policy related to active PDU session to multiple candidate gNBs in LTM preparation phase.

[0413] gNB should be able to include selected AS security algorithm in LTM configuration sent to UE.

[0414] gNB should be able to store received UP security policy of UE's PDU session that is not handed over to itself.

[0415] gNB should be able to initiate LTM candidate configuration when UP security policy applied by itself changes.

[0416] In some embodiments, 5G security capabilities of UE and UE's UP security policy are configured by serving gNB to candidate gNBs in LTM candidate preparation phase.

[0417] Selected AS security algorithm and UE's UP security activation status are stored in LTM candidate configuration of each candidate gNB and sent by serving gNB to UE through RRC reconfiguration message.

[0418] If gNB receives 5G security capabilities related information of UE from AMF in Path-Switch Acknowledge message, once gNB reselected security algorithm is different from selected security algorithm stored in gNB's LTM candidate configuration, gNB will initiate an intra-cell handover procedure which can include RRC connection reconfiguration procedure indicating selected security algorithm change.

[0419] Once gNB receives 5G security capabilities of UE in Path-Switch Acknowledge message from AMF, it can decide to perform LTM candidate preparation procedure to update 5G security capabilities of UE to all candidate gNBs.

[0420] If the gNB receives the UP security policy of the UE with activated PDU session from the SMF in the Path-Switch Acknowledge message, once the UP security activation status of the UE with activated PDU session stored in the LTM candidate configuration by the gNB does not match the UP security policy received from the SMF, the gNB will initiate the intra-cell handover procedure including the RRC connection reconfiguration procedure to activate or deactivate the UP security according to the UP security policy received from the SMF.

[0421] Once the gNB receives the UP security policy of the UE with activated PDU session from the SMF in the Path-Switch Acknowledge message, it can decide to perform the LTM candidate preparation procedure to update the UP security policy of the UE with activated PDU session to all candidate gNBs.

[0422] Any one of the above embodiments can be combined with each other without contradiction and conflict.

[0423] The embodiments of the present disclosure further provide a device for implementing any one of the above methods, for example, a device is provided, which includes units or modules for implementing each step performed by the UE in any one of the above methods. For another example, another device is provided, which includes units or modules for implementing each step performed by the network device (for example, an access network device, or a core network device, etc.) in any one of the above methods.

[0424] It should be understood that the division of each unit or module in the above apparatus is only a logical function division, and all or part of them can be integrated into a physical entity or physically separated in actual implementation. In addition, the units or modules in the apparatus can be implemented in the form of processor calling software: for example, the apparatus includes a processor connected with a memory, the memory stores instructions, and the processor calls the instructions stored in the memory to implement any of the above methods or realize the functions of each unit or module of the above apparatus, wherein the processor is, for example, a general processor such as a central processing unit (CPU) or a microprocessor, and the memory is a memory in the apparatus or a memory outside the apparatus. Alternatively, the units or modules in the apparatus can be implemented in the form of hardware circuit, and the functions of part or all of the units or modules can be realized by the design of hardware circuit. The above hardware circuit can be understood as one or more processors; for example, in one implementation, the above hardware circuit is an application-specific integrated circuit (ASIC), and the functions of part or all of the above units or modules are realized by the design of the logical relationship of elements in the circuit; for example, in another implementation, the above hardware circuit is a programmable logic device (PLD), and a field programmable gate array (FPGA) is taken as an example, which can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by a configuration file, so as to realize the functions of part or all of the above units or modules. All units or modules of the above apparatus can be implemented in the form of processor calling software, or all units or modules can be implemented in the form of hardware circuit, or part of the units or modules are implemented in the form of processor calling software, and the remaining part is implemented in the form of hardware circuit.

[0425] In the embodiments of the present disclosure, the processor is a circuit with signal processing capability. In one implementation, the processor can be a circuit with instruction reading and running capability, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), a digital signal processor (DSP), and the like. In another implementation, the processor can implement certain functions through a logical relationship of a hardware circuit, and the logical relationship of the hardware circuit is fixed or reconfigurable. For example, the processor is a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In the reconfigurable hardware circuit, the processor loads a configuration document to implement the configuration of the hardware circuit. It can be understood that the processor loads an instruction to implement the functions of the above part or all units or modules. In addition, the hardware circuit can also be designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), and the like.

[0426] As shown in FIG. 4, the embodiments of the present disclosure provide a communication system, including a first node 4101, M second nodes 4102, and a UE 4103.

[0427] In some embodiments, the first node 4101 is configured to send a first message to the first node.

[0428] Exemplarily, the first message includes information related to a security context of a layer 1 / layer 2 triggered mobility (LTM) of a user equipment (UE).

[0429] In one scenario, the first node is an initial base station of LTM of the UE, and the second node is a candidate base station of LTM of the UE; the first message includes at least one of first capability information of the UE and a first user plane (UP) security policy; the first capability information of the UE is used for at least one second node to select a first security algorithm supported by the UE; and the first UP security policy is used for the second node to determine an activation manner for protecting a first session, and the first session is a current active session of the UE.

[0430] In some embodiments, the second node 4102 is configured to send a second message to the first node.

[0431] In one scenario, the second message comprises first information of an m th< second node; the first information of the m th< second node is used to indicate a first security algorithm and a first UP security activation state; the first security algorithm is selected by the m th< second node according to the first capability information; the first UP security activation state is determined by the m th< second node according to the first UP security policy; m is a positive integer less than or equal to M; M is the total number of the second nodes.

[0432] In some embodiments, the first node 4101 is configured to send a third message to the terminal.

[0433] In some embodiments, the third message comprises first information; the first information is used by the UE to determine a security parameter for communication with the second node.

[0434] In another scenario, the first node is a serving base station of the UE, and the second node is a candidate base station or an initial base station for LTM switching of the UE; or, the first node is a source base station for LTM switching of the UE, and the second node is a target base station for LTM switching of the UE.

[0435] In some embodiments, the first node 4101 is configured to obtain a second user plane UP security policy of a second session of the UE, and send a first message to the second node, the first message comprising the second UP security policy of the second session; the second UP security policy is used by the second node to determine an activation mode for protection of the second session, and the second session is an activated session newly established by the UE.

[0436] In some embodiments, the second message comprises second information of an m th< second node; the second information of the m th< second node is used to indicate a second UP security activation state determined by the m th< second node, and the second UP security activation state is determined according to a second UP security policy.

[0437] In some embodiments, the third message comprises second information; the second information is used by the UE to determine a security parameter for the second session with the second node.

[0438] In still another scenario, the second node 4102 is further configured to receive second capability information sent by a third node, the third node being a core network node; in a case where the second capability information is different from the first capability information, select a second security algorithm according to the second capability information; and send a fourth message to the UE according to the second security algorithm, the fourth message being used by the UE to determine the second security algorithm.

[0439] In some embodiments, the second node 4102 is further configured to receive a third UP security policy associated with the first session and sent by a fourth node, the fourth node being a core network node; determine a third UP security activation state according to the third UP security policy, in a case that the third UP security policy is different from the first UP security policy; receive the first UP security policy by the second node from the first node; and send a fifth message to the UE according to the third UP security activation state, the fifth message being used for the UE to determine the third UP security activation state.

[0440] In some embodiments, the second node 4102 is further configured to receive a fourth UP security policy associated with the second session and sent by a fourth node, the fourth node being a core network node; determine a fourth UP security activation state according to the fourth UP security policy, in a case that the fourth UP security policy is different from the second UP security policy; receive the second UP security policy by the second node from the first node; and send a sixth message to the UE according to the fourth UP security activation state, the sixth message being used for the UE to determine the fourth UP security activation state.

[0441] In some embodiments, the UE 4103 is further configured to receive a fifth message sent by an mth second node, the fifth message being used for the UE to determine a third UP security activation state; the third UP security activation state being a UP security activation state of the first session; or, receive a sixth message sent by the mth second node, the sixth message being used for the UE to determine a fourth UP security activation state, the fourth UP security activation state being a UP security activation state of the second session.

[0442] The embodiments of the present disclosure further provide a communication device, which can include one or more processors; wherein the processor is configured to invoke instructions to cause the communication device to perform the security parameter processing method implemented by any one of the preceding embodiments.

[0443] In some embodiments, as shown in FIG. 5A and / or FIG. 5B, the communication device 8100 further includes one or more memories 8102 for storing instructions. Alternatively, all or part of the memory 8102 can also be outside the communication device 8100.

[0444] The communication device can be the UE and the network device as described above. In some embodiments, the network device can be the master node and / or the secondary node.

[0445] In some embodiments, the communication device 8100 further includes one or more transceivers 8103. When the communication device 8100 includes one or more transceivers 8103, the communication steps such as sending and receiving in the above method are performed by the transceiver 8103, and the other steps are performed by the processor 8101.

[0446] In some embodiments, the transceiver can include a receiver and a transmitter, which can be separate or integrated together. Optionally, the terms transceiver, transceiving unit, transceiver, transceiving circuit, etc. can be replaced by each other, the terms transmitter, transmitting unit, transmitter, transmitting circuit, etc. can be replaced by each other, and the terms receiver, receiving unit, receiver, receiving circuit, etc. can be replaced by each other.

[0447] Optionally, the communication device 8100 further includes one or more interface circuits 8104 connected with the memory 8102, which can be used to receive signals from the memory 8102 or other devices, and can be used to send signals to the memory 8102 or other devices. For example, the interface circuit 8104 can read the instructions stored in the memory 8102 and send the instructions to the processor 8101.

[0448] The communication device 8100 described in the above embodiments can be a network device or a UE, but the scope of the communication device 8100 described in the present disclosure is not limited to this, and the structure of the communication device 8100 can not be limited by Figure 5A. The communication device can be a standalone device or can be part of a larger device. For example, the communication device can be: (1) a standalone integrated circuit (IC), or a chip, or a chip system or subsystem; (2) a set of one or more ICs, which can optionally also include storage components for storing data, programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, UE device, smart UE device, cellular phone, wireless device, handset, mobile unit, vehicle-mounted device, network device, cloud device, artificial intelligence device, etc.; (6) other, etc.

[0449] Figure 5B is a structural schematic diagram of a chip 8200 according to an embodiment of the present disclosure. For the case where the communication device 8100 is a chip or a chip system, the structural schematic diagram of the chip 8200 shown in Figure 5B can be referred to, but is not limited thereto.

[0450] The chip 8200 includes one or more processors 8201 for invoking instructions to cause the chip 8200 to perform any of the above security parameter processing methods.

[0451] In some embodiments, chip 8200 further includes one or more interface circuits 8202 that are wired to memory 8203, which can be used to receive signals from or send signals to memory 8203 or other devices. For example, interface circuit 8202 can read instructions stored in memory 8203 and send those instructions to processor 8201. Alternately, the terms interface circuit, interface, transceiver pin, transceiver, and the like can be used interchangeably.

[0452] In some embodiments, chip 8200 further includes one or more memories 8203 for storing instructions. Alternately, all or part of memory 8203 can be external to chip 8200.

[0453] The present disclosure also provides a storage medium having stored thereon instructions which, when executed by a communication device 8100, cause the communication device 8100 to perform any of the above methods. Alternately, the storage medium is an electronic storage medium. Alternately, the storage medium is a computer-readable storage medium, but can also be a storage medium readable by other devices. Alternately, the storage medium can be a non-transitory storage medium, but can also be a transitory storage medium.

[0454] The present disclosure also provides a program product which, when executed by a communication device 8100, causes the communication device 8100 to perform any of the above security parameter processing methods. Alternately, the program product is a computer program product.

[0455] The present disclosure also provides a computer program which, when executed on a computer, causes the computer to perform any of the above security parameter processing methods.

[0456] Other embodiments of the present disclosure will be apparent to those skilled in the art from consideration of the specification and practice of the features disclosed herein. The present disclosure is intended to cover any variations, uses or adaptations of the present disclosure following, in general, the principles of the present disclosure and including such features to the present disclosure as come within the true spirit and scope of the present disclosure. Specification and examples are to be construed as merely illustrative of preferred embodiments of the present disclosure and not limitative in any way of the scope of the present disclosure. As used in this specification and the appended claims, the singular forms "a," "an" and "the" include plural referents unless the content clearly dictates otherwise. Thus, for example, reference to "a component" or "the component" can include a plurality of components.

[0457] It should be understood that the present disclosure is not limited to the precise structures herein described and illustrated in the drawings and that various modifications and changes can be made therein without departing from the scope thereof. The scope of the present disclosure is indicated by the appended claims rather than by the specification and embodiments.

Claims

1. A security parameter processing method, wherein, The method is performed by a first node, and the method comprises: sending, to a second node, a first message comprising information related to a security context of a Layer 1 / Layer 2 triggered mobility (LTM) of a user equipment (UE); receiving a second message sent by the second node, the second message comprising security parameters determined based on the first message; sending, to the UE, a third message according to the second message, the third message comprising the security parameters, the security parameters being used to protect communications between the UE and the second node.

2. The method of claim 1, wherein, The first node is an initial base station of the LTM of the UE, and the second node is a candidate base station of the LTM of the UE; the first message comprises at least one of first capability information of the UE and a first user plane (UP) security policy; the first capability information of the UE is used for the at least one second node to select a first security algorithm supported by the UE; The first UP security policy is used for the second node to determine an activation mode for protecting a first session, the first session being a currently activated session of the UE.

3. The method of claim 2, wherein, The second message comprises first information of an mth second node; the first information of the mth second node is used to indicate a first security algorithm and a first UP security activation state; The first security algorithm is selected by the mth second node according to the first capability information; The first UP security activation state is determined by the mth second node according to the first UP security policy; m is a positive integer less than or equal to M; M is a total number of the second nodes.

4. The method of claim 2 or 3, wherein, The third message comprises the first information; the first information is used for the UE to determine security parameters for communicating with the second node.

5. The method of claim 1, wherein, The first node is a serving base station of the UE, and the second node is a candidate base station or an initial base station for LTM handover of the UE; or, The first node is a source base station for LTM handover of the UE, and the second node is a target base station for LTM handover of the UE.

6. The method of claim 5, wherein, The sending, to the second node, of the first message comprises: obtaining a second user plane (UP) security policy of a second session of the UE, and sending, to the second node, the first message comprising the second UP security policy of the second session; the second UP security policy is used for the second node to determine an activation mode for protecting the second session, the second session being a newly established activated session of the UE.

7. The method of claim 6, wherein, The second message comprises second information of an mth second node; the second information of the mth node is used to indicate a second UP security activation state determined by the mth second node, the second UP security activation state being determined according to the second UP security policy.

8. The method of claim 7, wherein, The third message comprises the second information; the second information is used at least for the UE to determine security parameters for the second session with the second node.

9. The method of claim 6, wherein, The sending, to the second node, of the first message comprises at least one of the following: after obtaining the second UP security policy of the second session and successfully activating the second session, sending, to the second node, the second UP security policy; Before the UE switches to the second node, the second UP security policy is sent to the second node.

10. The method according to any one of claims 6 to 9, wherein, The sending of the second UP security policy to the second node comprises: sending a handover request to the second node, the handover request comprising the second UP security policy.

11. A security parameter processing method, wherein, The method is performed by the second node, and the method comprises: receiving a first message sent by a first node, the first message comprising information related to a security context of a Layer 1 / Layer 2 triggered mobility (LTM) of a user equipment (UE); sending a second message to the first node, the second message comprising security parameters determined based on the first message; the security parameters are used by the first node to send a third message to the UE, the third message comprising the security parameters; the security parameters are used to protect communication between the UE and a second node.

12. The method of claim 11, wherein, The first node is an initial base station of the LTM of the UE, the second node is a candidate node to which the UE performs LTM handover, and the first message comprises at least one of first capability information of the UE and a first user plane (UP) security policy; the first capability information of the UE is used by the at least one second node to select a first security algorithm supported by the UE; The first UP security policy is used by the second node to determine an activation mode for protecting a first session, the first session being a currently activated session of the UE.

13. The method of claim 11 or 12, wherein, The method further comprises: selecting a first security algorithm for communication with the UE according to the first capability information of the UE; and determining a first UP security activation state for communication with the UE according to the first UP security policy; The second message comprises first information; the first information is used to determine at least one of the first security algorithm selected by the second node and the first UP security activation state.

14. The method of claim 13, wherein, The first node is a serving base station of the UE or a source base station of LTM handover, and the first message comprises a second UP security policy of a second session of the UE.

15. The method of claim 14, wherein, The second message comprises second information; the second information is used to indicate a second UP security activation state, the second UP security activation state being determined according to the second UP security policy.

16. The method according to any one of claims 11 to 15, wherein, The method further comprises: receiving second capability information sent by a third node, the third node being a core network node; selecting a second security algorithm according to the second capability information in a case where the second capability information is different from the first capability information; sending a fourth message to the UE according to the second security algorithm, the fourth message being used by the UE to determine the second security algorithm.

17. The method of any one of claims 11 to 16, wherein, The method further comprises: receiving a third UP security policy associated with the first session sent by a fourth node, the fourth node being a core network node; determining a third UP security activation state according to the third UP security policy in a case where the third UP security policy is different from a first UP security policy; the first UP security policy is received by the second node from the first node; sending a fifth message to the UE according to the third UP security activation state, the fifth message being used by the UE to determine the third UP security activation state.

18. The method of any one of claims 11 to 17, wherein, The method further includes: receiving a fourth UP security policy associated with the second session sent by a fourth node, the fourth node being a core network node; in a case that the fourth UP security policy is different from the second UP security policy, determining a fourth UP security activation state according to the fourth UP security policy, the second UP security policy being received by the second node from the first node; sending a sixth message to the UE according to the fourth UP security activation state, the sixth message being used for the UE to determine the fourth UP security activation state.

19. A security parameter processing method, wherein, The method is performed by a user equipment (UE) and includes: receiving a third message sent by a first node, the third message including security parameters, the security parameters being used for protecting communications between the UE and a second node.

20. The method of claim 19, wherein the third message includes first information of M second nodes, the first information of an mth second node being used to indicate at least one of a first security algorithm and a first user plane (UP) security activation state, the first security algorithm being a first security algorithm selected by the mth second node based on first capability information of the UE; the first UP security activation state being determined by the mth second node according to a first UP security policy, m being a positive integer less than or equal to M.

21. The method of claim 19, wherein, the third message includes second information of the M second nodes, the second information of the mth node being used to indicate a second UP security activation state determined by the mth second node, the second UP security activation state being determined according to a second UP security policy; m being a positive integer less than or equal to M.

22. The method of any one of claims 19 to 21, wherein, The method further includes: receiving a fourth message sent by the mth second node, the fourth message being used for the UE to determine the second security algorithm; or, receiving a fifth message sent by the mth second node, the fifth message being used for the UE to determine a third UP security activation state, the third UP security activation state being a UP security activation state of a first session; or, receiving a sixth message sent by the mth second node, the sixth message being used for the UE to determine a fourth UP security activation state, the fourth UP security activation state being a UP security activation state of a second session.

23. A communications device, characterized by The communication device is configured to perform the communication method of any of claims 1-10, 11-18, or 19-22.

24. A communication system, wherein, The communication system includes a first node, a second node, and a user equipment (UE); the first node is configured to perform the method of any of claims 1-10; the second node is configured to perform the method of any of claims 11-18; the UE is configured to perform the method of any of claims 19-22.

25. A program product, wherein, The program product includes a computer program, which, when executed by a communication device, enables the communication device to implement the security parameter processing method of any of claims 1-10, 11-18, or 19-22.

Citation Information

Patent Citations

  • Communication method, device and system, and computer related product

    CN117998489A

  • Security update for subsequent ltm

    WO2024146138A1

  • Method and apparatus for efficiently transmitting configuration information of candidate cells for l1 / l2-based mobility support in next-generation mobile communication system

    WO2024167378A1

  • Method and apparatus for an LTM considering split NG-ran architecture in a wireless network system

    WO2024172287A1