Communication method and communication apparatus

By interacting with the target access network device and the access and mobility management functions, the system ensures that candidate access network devices obtain consistent security capabilities, thus solving the problem of unclear security algorithm selection in LTM handover and achieving lower latency and more robust mobility handover.

WO2026073508A1PCT designated stage Publication Date: 2026-04-09HUAWEI TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-09-28
Publication Date
2026-04-09

AI Technical Summary

Technical Problem

The lack of clear regulations in the existing technology regarding the selection of safety algorithms for LTM handover leads to increased handover latency.

Method used

The target access network device receives the security capabilities of the source access network device, determines the highest priority security algorithm, and interacts with the access and mobility management functions to ensure that candidate access network devices obtain consistent security capabilities, thereby avoiding increased latency caused by inconsistent capabilities during subsequent handover processes.

Benefits of technology

By establishing a clear security algorithm selection process, LTM handover latency is reduced, the robustness and efficiency of mobility handover are improved, and handover delays caused by inconsistent security capabilities are avoided.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025124926_09042026_PF_FP_ABST
    Figure CN2025124926_09042026_PF_FP_ABST
Patent Text Reader

Abstract

The present application provides a communication method and a communication apparatus. In the method, a security algorithm selection process of LTM switching is provided. After acquiring, on the basis of a path switching response message, a security capability associated with a terminal device that is stored in an access and mobility management function, a target access network device may notify a candidate access network device, which corresponds to subsequent switching of the target access network device, of the acquired security capability, thereby avoiding the problem of an increase in an LTM switching delay caused by inconsistency between a security capability associated with the terminal device that is stored in the candidate access network device and the security capability associated with the terminal device that is stored in the access and mobility management function in a subsequent switching process.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method and communication apparatus

[0001] This application claims priority to the Chinese Patent Application No. 202411403592.1, filed on October 3, 2024, entitled "Communication method and communication apparatus", the content of which is incorporated herein by reference in its entirety. TECHNICAL FIELD

[0002] The present application relates to the field of wireless communication, and more particularly, to a communication method and a communication apparatus. BACKGROUND

[0003] To reduce the handover terminal latency and enhance the mobility robustness, the base station can trigger the terminal to complete the handover based on the signaling and process of the physical layer or the medium access control (MAC) layer, which can be referred to as L1 / L2 triggered mobility (LTM) handover. The LTM handover does not require radio resource control (RRC) messages in the handover process, which can reduce the latency of the user equipment in the process of switching cells, and ensure a smoother user experience. The purpose is to shorten the terminal handover latency and interruption latency, and improve the user experience. However, at present, there is no clear provision for the security algorithm selection problem in the LTM scenario. SUMMARY

[0004] The present application provides a communication method and a communication apparatus, which clarifies the security algorithm selection process for LTM handover.

[0005] In a first aspect, a communication method is provided. The method can be applied to the target access network device side, that is, the method can be executed by the target access network device, or can be executed by the component (such as a chip or a chip system or a circuit or a communication module) of the target access network device, which is not limited in the present application.

[0006] The method can comprise: receiving a first handover request message from a source access network device, the first handover request message comprising a first security capability; determining a second security algorithm of a target access network device, the second security algorithm being a highest priority algorithm selected from a priority list of algorithms configured locally at the target access network device based on the first security capability; using the second security algorithm to secure communications between the target access network device and a terminal device; sending a first path handover request message to an access and mobility management function, the first path handover request message being used to trigger the core network to migrate downlink data of the terminal device to the target access network device, the first path handover request message comprising the first security capability; receiving a first path handover request response message from the access and mobility management function, the first path handover request response message indicating that the core network has successfully completed path handover, the first path handover request response message comprising a second security capability, the second security capability being different from the first security capability; updating the first security capability to the second security capability; and sending a first message to a candidate access network device, the first message comprising the second security capability, the second security capability being used to update a security capability associated with the terminal device saved at the candidate access network device, the candidate access network device being an L1 / L2 triggered mobility, LTM, handover access network device for the terminal device.

[0007] It can be understood that the first security capability is a security capability associated with the terminal device saved at the source access network device, and the second security capability is a security capability associated with the terminal device saved at the access and mobility management function.

[0008] In the above technical solution, the security algorithm selection process of the LTM handover is specified. In this process, after the target access network device obtains the security capability associated with the terminal device saved at the access and mobility management function based on the first path handover response message, the target access network device can inform the candidate access network device corresponding to subsequent handover of the obtained security capability, thereby avoiding the problem of increased LTM handover delay due to the inconsistency between the security capability associated with the terminal device saved at the candidate access network device and the security capability associated with the terminal device saved at the access and mobility management function in the subsequent handover process.

[0009] In some implementations of the first aspect, the method further comprises: determining a third security algorithm of the target access network device, the third security algorithm being a highest priority algorithm selected from a priority list of algorithms configured locally at the target access network device based on the second security capability; in a case where the third security algorithm is different from the second security algorithm, sending a second message to the terminal device, the second message comprising the third security algorithm; and using the third security algorithm to secure communications between the target access network device and the terminal device.

[0010] In some implementations of the first aspect, the first handover request message further comprises a first candidate cell list, the first candidate cell list indicating at least one cell, and the method further comprises determining a candidate access network device based on the first candidate cell list, the candidate access network device being an access network device associated with the at least one cell.

[0011] In some implementations of the first aspect, the first handover request message is used to request the target access network device to prepare resources required for the handover, and the method further comprises sending a first handover request response message to the source access network device, the first handover request response message being used to inform the target access network device of the resources prepared for the handover.

[0012] In some implementations of the first aspect, the first handover request message further comprises a first security algorithm, and in a case where the second security algorithm is different from the first security algorithm, the first handover request response message comprises the second security algorithm.

[0013] In some implementations of the first aspect, the method further comprises receiving a first handover notification message from the source access network device, the first handover notification message being used to inform the source access network device that a handover command has been initiated to the terminal device; and receiving a third message from the terminal device, the third message indicating that the terminal device has completed reconfiguration, wherein the third message is secured by using the second security algorithm.

[0014] In some implementations of the first aspect, the method further comprises receiving a fourth message from the candidate access network device, the fourth message comprising a fourth security algorithm of the candidate access network device, the fourth security algorithm being a highest priority algorithm selected from a local algorithm priority list of the candidate access network device based on the second security capability.

[0015] In the above technical solution, after the target access network device synchronizes the second security capability with the candidate access network device, the target access network device receives the fourth security algorithm selected by the candidate access network device based on the second security capability.

[0016] In some implementations of the first aspect, the method further comprises sending a fifth message to the terminal device, the fifth message comprising the fourth security algorithm, the fourth security algorithm being used to update a security algorithm for securing communication between the candidate access network device and the terminal device; and receiving a sixth message from the terminal device, the sixth message being a response message of the fifth message.

[0017] In the above technical solution, the target access network device sends the fourth security algorithm obtained from the candidate access network device to the terminal device, and subsequently the terminal device can use the fourth security algorithm corresponding to the candidate access network device to secure communication between the candidate access network device and the terminal device.

[0018] Optionally, the target access network device can send the second security capability to the candidate access network device first, and then send the third security algorithm of the target access network device to the terminal device, or the target access network device can send the third security algorithm of the target access network device to the terminal device first, and then send the fifth message to the terminal device, or the target access network device can send the third security algorithm of the target access network device and the fourth security algorithm of the candidate access network device to the terminal device after receiving the fourth security algorithm of the candidate access network device, without limitation.

[0019] In some implementations of the first aspect, the fifth message further includes identification information of the candidate access network device, the identification information of the candidate access network device being associated with the fourth security algorithm, or the fifth message further includes identification information of a cell associated with the candidate access network device, the identification information of the cell associated with the candidate access network device being associated with the fourth security algorithm.

[0020] In some implementations of the first aspect, after receiving the sixth message from the terminal device, the method further includes: sending a second handover command message to the terminal device, the second handover command message instructing the terminal device to hand over to a first access network device, the first access network device being one of the candidate access network devices; and sending a second handover notification message to the first access network device, the second handover notification message being used to inform the first access network device that the target access network device has initiated a handover command to the terminal device.

[0021] It can be understood that the handover of the source access network device to the target access network device can be regarded as a first handover, and the handover of the target access network device to the first access network device can be regarded as a second handover, and the target access network device in the above scheme can be regarded as a source access network device of the second handover, and the first access network device can be regarded as a target access network device of the second handover.

[0022] In the above technical solution, in the execution of the first handover of the source access network device to the target access network device, the target access network device synchronizes the second security capability to its candidate access network devices, thereby avoiding the problem of increased LTM handover delay due to the inconsistency between the security capability associated with the terminal device saved by the first access network device and the security capability associated with the terminal device saved by the access and mobility management function in the subsequent handover process.

[0023] In some implementations of the first aspect, the method further includes: sending a second path handover request message to the access and mobility management function, the second path handover request message being used to trigger the core network to migrate the downlink data of the terminal device to the first access network device, and the second path handover request message including the second security capability; and receiving a second path handover request response message from the access and mobility management function, the second path handover request response message indicating that the core network has successfully completed the path handover.

[0024] In some implementations of the first aspect, the first message is a second handover request message, the first message is used to request resources needed for preparing handover, the fourth message is a second handover request response message, the second handover request response message is used to inform the candidate access network device of the resources prepared for handover, and the fifth message is an RRC reconfiguration message, the RRC reconfiguration message is used to configure the terminal device with the resources prepared for handover by the candidate access network device.

[0025] In the technical solution described above, after determining that the first security capability is different from the second security capability, the target access network device temporarily stops subsequent handover and executes a handover preparation related procedure. In the handover preparation procedure, the target access network device synchronizes the second security capability to its candidate access network device, thereby avoiding the problem of increased LTM handover latency due to the inconsistency between the security capability associated with the terminal device saved by the candidate access network device and the security capability associated with the terminal device saved by the access and mobility management function in the subsequent handover process. In addition, this solution can reuse the messages in the existing handover preparation procedure, and does not need to add new messages, which has little impact on the standard.

[0026] In some implementations of the first aspect, the method further includes: sending a second candidate cell list to the candidate access network device, the second candidate cell list indicating at least one cell, the at least one cell being associated with at least one access network device, and the at least one access network device being a candidate access network device for subsequent handover by the candidate access network device.

[0027] In some implementations of the first aspect, the second candidate cell list sent to the candidate access network device does not include a cell associated with the source access network device.

[0028] In the technical solution described above, the target access network device does not include the source access network device in the second candidate cell list, which can avoid switching to the source access network device that is malfunctioning or captured again.

[0029] In a second aspect, a communication method is provided. The method can be applied to the terminal device side, that is, the method can be executed by the terminal device, or can be executed by a component (such as a chip or a chip system or a circuit or a communication module) of the terminal device, which is not limited in the present application.

[0030] The method can comprise: receiving a first handover command message from a source access network device, the first handover command message indicating that the terminal device is to be handed over to a target access network device; sending a third message to the target access network device, the third message indicating that the terminal device has completed reconfiguration; receiving a fifth message from the target access network device, the fifth message comprising a fourth security algorithm of a candidate access network device of the target access network device, the fourth security algorithm being different from a fifth security algorithm of the candidate access network device, the fifth security algorithm being a security algorithm saved by the terminal device for protecting communication between the candidate access network device and the terminal device, the candidate access network device being an L1 / L2 triggered mobility (LTM) handover access network device candidate for the terminal device; updating the fifth security algorithm to the fourth security algorithm; and sending a sixth message to the target access network device, the sixth message being a response message of the fifth message.

[0031] In the technical solution described above, the terminal device can receive the updated security algorithm of the candidate base station of the target base station sent by the target access network device in advance before the subsequent target access network device is handed over to the candidate access network device, so that problems can be avoided when the subsequent target access network device is handed over to the candidate access network device.

[0032] In some implementations of the second aspect, the fifth message further comprises identification information of the candidate access network device, the identification information of the candidate access network device being associated with the fourth security algorithm, or the fifth message further comprises identification information of a cell associated with the candidate access network device, the identification information of the cell associated with the candidate access network device being associated with the fourth security algorithm.

[0033] In some implementations of the second aspect, after the sixth message is sent to the target access network device, the method further comprises: receiving a second handover command message from the target access network device, the second handover command message indicating that the terminal device is to be handed over to a first access network device, the first access network device being one of the candidate access network devices; and sending an eighth message to the first access network device, the eighth message indicating that the terminal device has completed reconfiguration.

[0034] In some implementations of the second aspect, the fifth message is a radio resource control (RRC) reconfiguration message, the RRC reconfiguration message being used to reconfigure the terminal device with resources prepared by the candidate access network device for handover.

[0035] In some implementations of the second aspect, before the first handover command message is received from the source access network device, the method further comprises: receiving a seventh message from the source access network device, the seventh message being used to configure the terminal device with resources prepared by the target access network device and the candidate access network device for handover.

[0036] In some implementations of the second aspect, the seventh message comprises the fifth security algorithm, and the method further comprises: saving the fifth security algorithm.

[0037] In some implementations of the second aspect, after sending the third message to the first target access network device, the method further includes: receiving a second message from the target access network device, the second message including a third security algorithm of the target access network device, the third security algorithm being different from the second security algorithm, the second security algorithm being saved by the terminal device for security protection of communication between the target access network device and the terminal device.

[0038] In some implementations of the second aspect, the seventh message includes the second security algorithm, and the method further includes: saving the second security algorithm.

[0039] In a third aspect, a communication method is provided. The method can be applied to the target access network device side, that is, the method can be executed by the target access network device, or can be executed by a component (such as a chip or a chip system or a circuit or a communication module) of the target access network device, which is not limited in the present application.

[0040] The method can include: receiving a handover request message from a source access network device, the handover request message including a first security capability of a terminal device; determining a second security capability according to the first security capability, the second security capability being a security capability associated with the terminal device and saved by an access and mobility management function; determining a third security algorithm of the target access network device, the third security algorithm being a highest priority algorithm selected from a local algorithm priority list of the target access network device based on the second security capability;

[0041] sending a handover request response message to the source access network device, the handover request response message being a response message of the handover request message, the handover request response message being used to indicate a security algorithm required to be used by the target access network device for subsequent communication with the terminal device, wherein the required security algorithm is the same as the third security algorithm.

[0042] In the above technical solution, the security algorithm selection process of LTM handover is specified. In this process, after receiving the handover request, the candidate access network device can interact with the access and mobility management function to ensure that the candidate base station obtains the same security capability as the access and mobility management function, thereby avoiding the problem of increased LTM handover delay due to the inconsistency between the security capability associated with the terminal device saved by the candidate access network device and the security capability associated with the terminal device saved by the access and mobility management function in the subsequent handover process. In addition, in this method, each candidate access network device itself interacts with the access and mobility management function for security capability verification, which does not depend on the verification results of other access network devices, and can achieve better security protection.

[0043] In some implementations of the third aspect, the determining the second security capability according to the first security capability comprises: sending a first request message to an access and mobility management function, the first request message comprising the first security capability, the first request message being used to request verification of the first security capability; and receiving a first request response message from the access and mobility management function, wherein the first request response message comprises the second security capability of the terminal device.

[0044] In some implementations of the third aspect, the determining the second security capability according to the first security capability comprises: sending a first request message to an access and mobility management function, the first request message comprising the first security capability, the first request message being used to request verification of the first security capability; and receiving a first request response message from the access and mobility management function, wherein the first request response message does not carry the security capability of the terminal device, and in the case that the first request response message does not carry the security capability of the terminal device, the second security capability is the same as the first security capability.

[0045] A fourth aspect provides a communication method. The method can be applied to a target access network device side, that is, the method can be executed by a target access network device, or can be executed by a component (for example, a chip or a chip system or a circuit or a communication module) of the target access network device, and the present application does not limit this.

[0046] The method comprises: receiving a handover request message from a source access network device, the handover request message comprising identification information of a terminal device; sending a first request message to an access and mobility management function, the first request message being used to request a security capability associated with the terminal device and saved by the access and mobility management function; receiving a first request response message from the access and mobility management function, the first request response message comprising a second security capability of the terminal device; determining a third security algorithm of the target access network device, the third security algorithm being a highest-priority algorithm selected from a locally configured algorithm priority list of the target access network device based on the second security capability; and sending a handover request response message to the source access network device, the handover request response message being a response message of the handover request message, and the handover request response message being used to indicate a security algorithm required to be used by the target access network device for subsequent communication with the terminal device, the required security algorithm being the same as the third security algorithm.

[0047] In the technical solution, the security algorithm selection process of LTM switching is specified. In the process, the candidate access network device can interact with the access and mobility management function after receiving the switching request to ensure that the candidate base station obtains the security capability consistent with the access and mobility management function, thereby avoiding the problem of increasing LTM switching delay due to the inconsistency between the security capability associated with the terminal device saved by the candidate access network device and the security capability associated with the terminal device saved by the access and mobility management function in the subsequent switching process. In addition, in the method, each candidate access network device itself interacts with the access and mobility management function for security capability verification, which does not depend on the verification result of other access network devices, and can achieve better security protection.

[0048] In some implementations of the third aspect or the fourth aspect, before sending the first request message to the access and mobility management function, the method further includes: determining, by the target access network device, that the current switching is LTM switching.

[0049] In some implementations of the third aspect or the fourth aspect, the method further includes: receiving a candidate cell list from the source base station, the candidate cell list indicating at least one cell, the at least one cell being associated with at least one access network device, the at least one access network device being a candidate access network device for subsequent switching of the target access network device; and determining that the current switching is LTM switching, including: determining that the current switching is LTM switching based on the candidate cell list.

[0050] In some implementations of the third aspect or the fourth aspect, the method further includes: receiving a first message indicating that the current switching is LTM switching; and determining that the current switching is LTM switching, including: determining that the current switching is LTM switching based on the candidate cell list.

[0051] In some implementations of the third aspect or the fourth aspect, the switching request message is used to request resources required by the target access network device for switching preparation, and the switching request response message is used to notify the target access network device of the resources prepared for switching.

[0052] In some implementations of the third aspect, the method further includes: determining a third security algorithm of the target access network device, the third security algorithm being a priority highest algorithm selected from a locally configured algorithm priority list of the target access network device based on the second security capability; and using the third security algorithm to perform security protection on the communication between the target access network device and the terminal device.

[0053] In some implementations of the third or fourth aspect, the handover request message further comprises a first security algorithm, and the handover request response message further comprises the third security algorithm in a case that the third security algorithm is different from the first security algorithm; or the handover request response message does not carry the third security algorithm in a case that the third security algorithm is the same as the first security algorithm.

[0054] In some implementations of the third or fourth aspect, the method further comprises: receiving a handover notification message from the source access network device, the handover notification message being used to inform that the source access network device has initiated a handover command to the terminal device; and receiving a first message from the terminal device, the first message indicating that the terminal device has completed reconfiguration.

[0055] In some implementations of the third aspect, the method further comprises: sending a path switch request message to an access and mobility management function, the path switch request message being used to trigger the core network to migrate downlink data of the terminal device to the target access network device, the path switch request message comprising a second security capability; and receiving a path switch request response message from the access and mobility management function, the path switch request response message indicating that the core network has successfully completed path switching.

[0056] In the above technical solution, the target access network device has performed security capability verification before handover is successful, and has obtained the same security capability as the access and mobility management function, which is equivalent to advancing the security capability verification process. Therefore, when verification is performed in the above path switching process, the event of security capability mismatch will not be triggered, thereby avoiding the problem of increased LTM handover delay.

[0057] In a fifth aspect, a communication apparatus is provided, which is configured to execute the method in any of the first to fourth aspects and any possible implementation manner thereof. Specifically, the apparatus can comprise units and / or modules for executing the method in any of the first to fourth aspects and any possible implementation manner thereof, such as a processing unit and / or a communication unit.

[0058] In an implementation manner, the apparatus is a communication device (such as a target access network device, or a terminal device). When the apparatus is a communication device, the communication unit can be a transceiver, or an input / output interface; and the processing unit can be at least one processor. Optionally, the transceiver can be a transceiver circuit. Optionally, the input / output interface can be an input / output circuit.

[0059] In another implementation, the apparatus is a chip, chip system or circuit or communication module for a communication device (e.g., a target access network device, or a terminal device). When the apparatus is a chip, chip system or circuit for a communication device, the communication unit can be an input / output interface, interface circuit, output circuit, input circuit, pin or related circuit on the chip, chip system or circuit, etc.; and the processing unit can be at least one processor, processing circuit or logic circuit, etc.

[0060] In a sixth aspect, a communication apparatus is provided, which comprises at least one processor configured to cause the apparatus to perform the method in any one of the first aspect to the fourth aspect and any possible implementation thereof.

[0061] Optionally, the at least one processor is configured to execute computer programs or instructions to perform the method in any one of the first aspect to the fourth aspect and any possible implementation thereof.

[0062] Optionally, the apparatus further comprises a memory configured to store the computer programs or instructions.

[0063] Optionally, the at least one processor is coupled to the memory configured to store the computer programs or instructions. The memory can be disposed outside the apparatus.

[0064] Optionally, the apparatus further comprises a communication interface through which the processor reads the instructions on the memory. It can be understood that the communication interface is coupled to the processor and can be used to input the computer programs or instructions to the processor, or output the information in the processor.

[0065] For the sending and obtaining / receiving operations involved, if no special description is made, or if it does not contradict the actual role or inherent logic in the related description, it can be understood as output, input, etc. operations, or as sending and receiving operations performed by the radio frequency circuit and the antenna, which are not limited in the present application.

[0066] In an implementation, the apparatus is a communication device (e.g., a target access network device, or a terminal device).

[0067] In another implementation, the apparatus is a chip, chip system or circuit or communication module for a communication device (e.g., a target access network device, or a terminal device). Optionally, the chip is a Modem chip, also known as a baseband chip, or a system on chip (SoC) chip or system in package (SIP) chip containing a modem core.

[0068] In a seventh aspect, a computer-readable storage medium is provided, and the computer-readable medium stores computer programs (for example, program codes) or instructions thereon, which, when run on a communication device, cause the communication device to perform the method in any one of the first aspect to the fourth aspect and any possible implementation manner thereof.

[0069] In an eighth aspect, a computer program product containing instructions is provided, which, when run on a computer, causes the computer to perform the method in any one of the first aspect to the fourth aspect and any possible implementation manner thereof.

[0070] In a ninth aspect, a communication system is provided, and the communication system comprises at least one of the following: a terminal device, a source access network device, a target access network device, and an access and mobility management function. BRIEF DESCRIPTION OF DRAWINGS

[0071] FIG. 1 is a schematic diagram of a network architecture suitable for embodiments of the present application.

[0072] FIG. 2 is a schematic flowchart of a security algorithm selection method based on Xn handover.

[0073] FIG. 3 is a schematic flowchart of LTM cross-base station handover.

[0074] FIG. 4 is a schematic flowchart of a security algorithm selection method based on LTM handover according to the present application.

[0075] FIG. 5 is a schematic diagram of a communication method according to the present application.

[0076] FIGS. 6 and 7 are schematic flowcharts of another security algorithm selection method based on LTM handover according to the present application.

[0077] FIG. 8 is a schematic diagram of another communication method according to the present application.

[0078] FIG. 9 is a schematic flowchart of another security algorithm selection method based on LTM handover according to the present application.

[0079] FIG. 10 is a schematic block diagram of a communication device 1000 according to an embodiment of the present application.

[0080] FIG. 11 is a schematic block diagram of a communication device 1100 according to an embodiment of the present application. DETAILED DESCRIPTION

[0081] The technical solutions in the present application will be described below with reference to the accompanying drawings.

[0082] Before introducing the solutions of the present application, the following points are explained.

[0083] (1) In this application, "indication" can include direct indication, indirect indication, explicit indication, implicit indication, etc. When describing that certain indication information indicates A, it can be understood that the indication information carries A, carries an identifier of A, carries B having an association relationship with A, carries an identifier of B having an association relationship with A, etc. In other words, if the receiving side of certain indication information can determine A according to the indication information, it can be described that the indication information indicates A, and the specific determination is not limited. When it is understood that the indication information carries A, "indication" can be replaced by "includes", at this time, similar to the expression "sending / receiving indication information, the indication information indicates A", it can be replaced by "sending / receiving A".

[0084] In this application, the information indicated by the indication information is referred to as to-be-indicated information. In the specific implementation process, there are many ways to indicate the to-be-indicated information, for example, but not limited to, the to-be-indicated information can be directly indicated, such as the to-be-indicated information itself or an index of the to-be-indicated information. The to-be-indicated information can also be indirectly indicated by indicating other information, wherein the other information has an association relationship with the to-be-indicated information. The to-be-indicated information can also be only indicated a part, and the other part of the to-be-indicated information is known or agreed in advance. For example, the indication of a specific information can also be realized by means of the arrangement order of each information agreed in advance (for example, the protocol stipulates), thereby reducing the indication overhead to a certain extent. In addition, the to-be-indicated information can be sent as a whole, or can be sent separately into multiple sub-information, and the sending period and / or sending time of these sub-information can be the same or different.

[0085] (2) In this application, the expression " / " is used to represent that the objects before and after the association are in an "or" relationship; for example, A / B can represent A or B. The expression "and / or" is used to represent that the objects before and after the association can be in an "and" association relationship or an "or" association relationship; for example, A and / or B can represent the following cases: A exists alone, B exists alone, A and B exist together, wherein A and B can be single or multiple. "At least one of the following" or similar expressions are used to represent any combination of the listed items; for example, at least one of A, B and (or) C can represent the following cases: A exists alone, B exists alone, C exists alone, A and B exist together, B and C exist together, A and C exist together, A, B and C exist together, wherein A, B and C can be single or multiple.

[0086] (3) In this application, "send" and "receive" indicate the direction of signal transmission. For example, "send information to XX" can be understood as the destination of the information being XX, which may include direct transmission via the air interface or indirect transmission by other units or modules via the air interface. "Receive information from YY" can be understood as the source of the information being YY, which may include direct reception from YY via the air interface or indirect reception from YY by other units or modules via the air interface. "Send" can also be understood as the "output" of the chip interface, and "receive" can also be understood as the "input" of the chip interface. In other words, sending and receiving can occur between devices, such as between network devices and terminal devices, or within a device, such as between components, modules, chips, software modules, or hardware modules within the device via a bus, wiring, or interface.

[0087] (4) In the various embodiments of this application, unless otherwise specified or in case of logical conflict, the terms and / or descriptions of different embodiments are consistent and can be referenced by each other. The technical features of different embodiments can be combined to form new embodiments according to their inherent logical relationship.

[0088] (5) In this application, "first," "second," and "#1," "#2," and "#A" are merely for descriptive convenience and are used to distinguish objects, and are not intended to limit the scope of the embodiments of this application. They are not used to describe the order or sequence of features. It should be understood that such described objects can be interchanged where appropriate in order to describe solutions other than those in the embodiments of this application.

[0089] (6) In this application, "predefined" can mean a standard protocol predefined, or it can mean a pre-agreed or pre-negotiated agreement between devices. Here, "protocol" can refer to a standard protocol in the field of communications, for example, it may include fourth-generation (4G) protocols. th Generation 4G network, fifth generation (5G) network th This application does not limit the scope to network protocols such as 5G (generation, 5G), New Radio (NR) protocols, 5.5G network protocols, and related protocols applied in future communication systems.

[0090] (7) In this application, the words "example," "such as," and "for example" are used to mean that an implementation so described is one among many possible implementations. No inference should be drawn that any other implementation is "preferred" or "constitutes all other implementations." The word "example" is used herein to mean one of a number of possible implementations, and not necessarily the preferred or advantageous implementation. In the embodiments of this application, "of", "corresponding" and "corresponding" are sometimes mixed. It should be pointed out that when there is no emphasis on their differences, the meanings expressed are consistent.

[0091] First, introduce the communication system applicable to this application.

[0092] The technical solutions provided in this application can be applied to various communication systems, such as: 5th generation (5G) or new radio (NR) system, long term evolution (LTE) system, LTE frequency division duplex (FDD) system, LTE time division duplex (TDD) system, etc. The technical solutions provided in this application can also be applied to future communication systems. The technical solutions provided in this application can also be applied to device to device (D2D) communication, vehicle-to-everything (V2X) communication, machine to machine (M2M) communication, machine type communication (MTC), and internet of things (IoT) communication system. The technical solutions provided in this application can also be applied to non-terrestrial network (NTN) system such as inter-satellite communication and satellite communication.

[0093] As an example, the satellite communication system includes a satellite base station and a terminal device. The satellite base station provides communication services for the terminal device. The satellite base station can also communicate with the base station. The satellite can act as a base station, and also as a terminal device. Among them, the satellite can refer to unmanned aerial vehicle, hot air balloon, low earth orbit satellite, medium earth orbit satellite, high earth orbit satellite, etc. The satellite can also refer to non-ground base station or non-ground device, etc.

[0094] As an example, the V2X communication can include vehicle-to-vehicle (V2V) communication, vehicle-to-infrastructure (V2I) communication, vehicle-to-pedestrian (V2P) communication, vehicle-to-network (V2N) communication.

[0095] In the communication system, the part operated by the operator can be referred to as a public land mobile network (PLMN), which can also be referred to as an operator network, etc. The PLMN is a network established and operated for the purpose of providing public land mobile communication services to the public, mainly a public network through which a mobile network operator (MNO) provides mobile broadband access services to users. The PLMN described in the embodiments of the present application can be a network conforming to the requirements of the 3rd generation partnership project (3GPP) standard, referred to as a 3GPP network. The 3GPP network generally includes but is not limited to a 5G network, a 4th-generation (4G) network, and other future communication systems.

[0096] One device in the communication system can send a signal to another device or receive a signal from another device. Wherein the signal can include information, signaling or data, etc. Wherein the device can also be replaced by an entity, a network entity, a communication device, a communication module, a node, a communication node, etc. The embodiments of the present application are described by taking the device as an example.

[0097] The network architecture is introduced below.

[0098] FIG. 1 is a schematic diagram of a network architecture suitable for the embodiments of the present application. As shown in FIG. 1, the network architecture takes the 5th generation system (5GS) as an example. As an example, the network architecture includes three parts, which are terminal device part, data network (DN) part and operator network PLMN part respectively. Wherein, the operator network PLMN part can include but is not limited to (radio) access network ((R)AN) and core network (CN) part.

[0099] The network elements of each part are briefly introduced below.

[0100] 1、terminal device part, including user equipment (UE). UE: also known as terminal or terminal device, can be a device or module with corresponding communication function to access the above communication system. UE can include various devices with wireless communication function, which can be used to connect people, things, machines, etc. Terminal device can be widely used in various scenarios, such as: cellular communication, D2D, V2X, peer to peer, M2M, MTC, IoT, virtual reality (VR), augmented reality (AR), industrial control, automatic driving, remote medical treatment, smart power grid, smart furniture, smart office, smart wear, intelligent transportation, smart city unmanned aerial vehicle, robot, remote sensing, passive sensing, positioning, navigation and tracking, autonomous delivery, etc. Terminal device can be a terminal in any of the above scenarios, such as MTC terminal, IoT terminal, etc. Terminal device can be a UE, terminal, fixed device, mobile station device or mobile device, subscriber unit, handheld device, vehicle-mounted device, wearable device, cellular phone, smart phone, session initiation protocol (SIP) phone, wireless data card, personal digital assistant (PDA), computer, tablet computer, notebook computer, wireless modem, handset, laptop computer, computer with wireless transceiver function, smart book, vehicle, satellite, global positioning system (GPS) device, target tracking device, aircraft (such as unmanned aerial vehicle, helicopter, multi-helicopter, four-helicopter or airplane, etc.), ship, remote control device smart home device, industrial device, transport vehicle with wireless communication function, communication module, road side unit (RSU) with terminal function, or device built in the above device (such as communication module, modem or chip in the above device, etc.), or other processing device connected to the wireless modem.

[0101] In addition, the UE can also store a long-term key K and related functions. When two-way authentication is performed, the UE can use K and the related functions to verify the authenticity of the network.

[0102] It should be appreciated that in certain scenarios, a UE can also be used to act as a base station. For example, a UE can act as a scheduling entity that provides sidelink signals between UEs in V2X, D2D, or end-to-end scenarios, etc.

[0103] In the embodiments of the present application, the device for implementing the function of the terminal device, i.e., the terminal device, can be a terminal device or a device capable of supporting the terminal device to implement the function, such as a chip system or a chip or a circuit or a communication module (i.e., a communication module performing a communication function), which can be installed in the terminal device. In the embodiments of the present application, the chip system can be composed of a chip or can include a chip and other discrete devices. In addition, the device can also be configured with program instructions for performing corresponding communication functions.

[0104] 2. Data network part, which can include a DN, for providing a network for transmitting data. For example, a network of an operator service (such as an IP multimedia subsystem (IMS)), an Internet network, a service network of a third party, etc. The DN can also be referred to as a packet data network (PDN), which is usually a network outside the operator network, such as a third-party network.

[0105] 3. (R)AN part, which can include one or more access network elements or access network devices. The access network can provide network access functions for authorized users in a specific area, including radio access network (RAN) devices and AN devices. The RAN device is mainly the wireless network device of the 3GPP network, and the AN device can be an access network device defined by non-3GPP (non-3GPP).

[0106] The access network can be an access network using different access technologies. There are two types of current wireless access technologies: 3GPP access technology (such as the wireless access technology used in 3G, 4G, or 5G systems) and non-3GPP (non-3GPP) access technology.

[0107] Among them, the 3GPP access technology refers to the access technology conforming to the 3GPP standard specification, for example, the access network device in the 5G system is called the next generation NodeB (gNB) or RAN.

[0108] The non-3GPP access technology refers to an access technology that does not conform to the 3GPP standard specification, for example, an air interface technology represented by an access point (AP) in wireless fidelity (WiFi), worldwide interoperability for microwave access (WiMAX), a code division multiple access (CDMA) network, and the like. An access network device (AN device) can allow a terminal device and a 3GPP core network to be interconnected and communicated using a non-3GPP technology.

[0109] The access network device in the embodiments of the present application can be a device or a module with corresponding communication functions. The access network device can be a device for communicating with a terminal device, and the access network device can also be referred to as a network device or a wireless access network device, for example, the access network device can be a base station. The access network device in the embodiments of the present application can refer to a RAN node (or device) for accessing a terminal device to a wireless network. The base station can broadly cover various names in the following or be replaced by the following names, such as: Node B (NodeB), evolved Node B (eNB), gNB, relay station, access point, transmitting and receiving point (TRP), transmission point, primary station, secondary station, motor slide retainer (MSR) node, home base station, network controller, access node, wireless node, access point (AP), transmission node, transceiver node, baseband unit (BBU), remote radio unit (RRU), active antenna unit (AAU), remote radio head (RRH), central unit (CU), distributed unit (DU), positioning node, etc. The base station can be a macro base station, a micro base station, a relay node, a donor node, or the like, or a combination thereof. The base station can also refer to a communication module, modem, or chip for being arranged in the foregoing device or apparatus. The base station can also be a mobile switching center and a device that performs a base station function in D2D, V2X, M2M communication, a device that performs a base station function in a future communication system, etc. The base station can support networks of the same or different access technologies. The embodiments of the present application do not limit the specific technology and specific device form adopted by the network device.

[0110] A base station can be fixed, or mobile. For example, a helicopter or an unmanned aerial vehicle (UAV) can be configured to act as a mobile base station, and one or more cells can move according to the location of the mobile base station. In other examples, a helicopter or an unmanned aerial vehicle can be configured to act as a device that communicates with another base station.

[0111] In some deployments, the access network device mentioned in the embodiments of the present application can be a device including a CU, or a DU, or including a CU and a DU, or a control plane CU node (central unit-control plane (CU-CP)) and a user plane CU node (central unit-user plane (CU-UP)), and a DU node.

[0112] In some deployments, a plurality of RAN nodes cooperate to assist a terminal device to implement wireless access, and different RAN nodes respectively implement part of the functions of a base station. For example, the RAN node can be a CU, a DU, a CU-CP, a CU-UP, or a radio unit (RU), etc. The CU and the DU can be separately arranged, or can also be included in the same network element, such as a BBU. The RU can be included in a radio frequency device or a radio frequency unit, such as an RRU, an AAU, or an RRH.

[0113] In different systems, the CU (or CU-CP and CU-UP), DU, or RU can also have different names, but those skilled in the art can understand their meanings. For example, the wireless access network can also be an open radio access network (O-RAN) architecture, in which the CU can also be referred to as an open CU (O-CU), the DU can also be referred to as an open DU (O-DU), the CU-CP can also be referred to as an open CU-CP (O-CU-CP), the CU-UP can also be referred to as an open CU-UP (O-CU-UP), and the RU can also be referred to as an open RU (O-RU). Any of the CU (or CU-CP, CU-UP), DU, and RU in the present application can be implemented by a software module, a hardware module, or a combination of a software module and a hardware module.

[0114] In the embodiments of the present application, the device for implementing the function of the access network device can be the access network device, or can be a device capable of supporting the access network device to implement the function, such as a chip system or a chip or a circuit or a communication module (i.e., a communication module performing a communication function), which can be installed in the access network device. In the embodiments of the present application, the chip system can be composed of a chip, or can include a chip and other discrete devices. In addition, program instructions for performing corresponding communication functions can also be configured in the device. In the embodiments of the present application, only the device for implementing the function of the access network device is taken as an example to illustrate the access network device, and the scheme of the embodiments of the present application is not limited.

[0115] The access network device and the terminal device can be deployed on land, including indoor or outdoor, handheld or vehicle-mounted; can also be deployed on the water surface; and can also be deployed on airplanes, balloons and satellites in the air. The scenarios in which the access network device and the terminal device are located are not limited in the embodiments of the present application.

[0116] 4. The CN part can include but is not limited to the following network functions (network functions, NFs): network slice selection function (network slice selection function, NSSF), network slice specific authentication and authorization function (network slice specific authentication and authorization function, NSSAAF), authentication server function (authentication server function, AUSF), unified data management (unified data management, UDM), network exposure function (network exposure function, NEF), network storage function (NF repository function, NRF), policy control function (policy control function, PCF), application function (application function, AF), access and mobility management function (access and mobility management function, AMF), session management function (session management function, SMF), user plane function (user plane function, UPF), service control point (signaling control point, SCP). The network elements are briefly introduced below.

[0117] 1) UPF network element: used for packet routing and forwarding, quality of service (QoS) processing of user plane data, etc. User data can access the DN through the network element. In the embodiments of the present application, the function of the user plane function can be implemented.

[0118] 2) AMF network element: mainly used for mobility management and access management, etc., and can be used to implement other functions in the mobility management entity (MME) function except for session management, such as access authorization / authentication functions, etc.

[0119] The AMF network element can include a security anchor function (SEAF) network element, and the SEAF network element is mainly used to initiate an authentication request to the AUSF, and complete the authentication of the UE on the network side in the evolved packet system authentication and key agreement (EPS-AKA) authentication process. It can be understood that the SEAF network element can also be an independent network element, that is, a network element independent of the AMF network element, and no limitation is made in this regard.

[0120] 3) SMF network element: mainly used for session management, IP address allocation and management of terminal devices, selection and management of user plane functions, termination of policy control and charging function interfaces, and downlink data notification, etc.

[0121] 4) PCF network element: a unified policy framework for guiding network behavior, providing policy rule information for network elements (such as AMF, SMF network elements, etc.) or terminal devices, etc.

[0122] In addition, the PCF internally stores QoS rules. In addition, the PCF can generate corresponding QoS rules according to requirements to ensure that the services provided by the network meet the requirements proposed by the third party.

[0123] 5) NRF network element: used to save the description information of network function entities and the services they provide, and support service discovery, network element entity discovery, etc.

[0124] 6) NEF network element: used to enable third parties to use the services provided by the network, support network to open its capabilities, event and data analysis, information conversion from external applications to PLMN security equipment, and interaction between PLMN and outside, etc.

[0125] 7) UDM network element: used for unified data management, 5G user data management, processing user identification, access authentication, registration, or mobility management, etc.

[0126] 8) UDR network element: used for providing functions of saving and obtaining subscription data for UDM, saving and obtaining policy data for PCF, saving and obtaining user NF group ID (group ID) information, etc.

[0127] 9) AF network element: used for providing corresponding services by interacting with other NFs in the PLMN, such as providing roaming UE visited network selection information, guiding data flow routing, accessing NEF, etc.

[0128] 10) AUSF network element: used for primary authentication, i.e., authentication between the UE (subscribed user) and the operator network.

[0129] In addition, the architecture can also include other network elements, such as an authentication repository and processing function (ARPF) network element, which is mainly used for storing a long-term key K; receiving an authentication vector request from the AUSF; calculating an authentication vector using K; and sending the authentication vector to the AUSF.

[0130] In FIG. 1, Nnssf, Nnef, Nnrf, Npcf, Nudm, Nudr, Naf, Nausf, Namf, Nsmf, Neasdf, Nnssaaf, Nnsacf, N1, N2, N3, N4, and N6 are interface sequence numbers. For example, the meanings of the above interface sequence numbers can refer to the meanings defined in the 3GPP standard protocol, and the meanings of the above interface sequence numbers are not limited by the present application. It should be noted that the interface names between the various network functions in FIG. 1 are merely an example, and in a specific implementation, the interface names of the system architecture can also be other names, which are not limited by the present application. In addition, the names of the messages (or signaling) transmitted between the above network elements are also merely an example, and do not constitute any limitation on the functions of the messages themselves.

[0131] It should be noted that in the architecture shown in FIG. 1, the interface between (R)AN and CN can also be referred to as an NG interface (not shown in the figure), and (R)AN and CN are connected through the NG interface. The NG interface can include an NG-C interface and an NG-U interface, wherein the NG-C interface is a control plane interface, and the connection parties are (R)AN and AMF, which are used to transmit control plane data; the NG-U interface is a user plane interface, and the connection parties are (R)AN and UPF, which are used to transmit user plane data.

[0132] The AMF, SMF, UPF, NEF, AUSF, NRF, PCF, UDM, and the like shown in FIG. 1 can be understood as network elements in the core network for implementing different functions, for example, can be combined into a network slice as needed. These core network network elements can be independent devices, or can be integrated into the same device to implement different functions. The specific form of the network elements is not limited in the present application. In addition, the network elements or functions mentioned above can be a physical entity in a hardware device, or a software instance running on a dedicated hardware, or a virtualized function instantiated on a shared platform (for example, a cloud platform). In short, an NF can be implemented by hardware or software.

[0133] In addition, the above naming is only defined for the convenience of distinguishing different functions, and should not constitute any limitation on the present application. The present application does not exclude the possibility of using other names in 5G networks and future other networks. For example, in future communication networks, part or all of the above network elements can use the terms in 5G, or other names, etc.

[0134] Next, for the convenience of understanding, several concepts are introduced.

[0135] 1. Security capability: a set of identifiers corresponding to the confidentiality protection and integrity protection algorithms implemented by the UE. In the present application, the security capability can also be referred to as the UE security capability.

[0136] 2. Xn handover: this handover can also change the serving base station of the UE to enjoy uninterrupted network services. The prerequisite for Xn handover is that the Xn interface between the source base station and the target base station has been established.

[0137] 3. L1 / L2 triggered mobility (LTM) handover: the LTM mechanism aims to reduce the delay of switching cells by the user equipment during movement, and to ensure a smoother user experience. In order to reduce the terminal switching delay and enhance the mobility robustness, the base station can trigger the terminal to complete the handover based on the physical layer or medium access control (MAC) layer signaling and process, that is, the LTM handover does not require RRC messages in the handover process, to meet the requirement of reducing the terminal switching delay.

[0138] 4. Target access network device and candidate access network device: In this application, the target access network device corresponds to the source access network device, that is, for the source access network device, the access network device that can perform handover is called the target access network device. The candidate access network device corresponds to the target access network device. When the candidate access network device of the target access network device becomes the source access network device, the access network device that can perform handover by the target access network device is called the candidate access network device. The target access network device and the candidate access network device can be converted to each other under certain conditions, for example, when the target access network device becomes the source access network device, the candidate access network device of the target access network device is the corresponding target access network device.

[0139] FIG. 2 is a schematic flowchart of a security algorithm selection method based on Xn handover. In the Xn handover shown in FIG. 2, the source base station selects a target base station according to the measurement report of the UE, and triggers the UE to be handed over from the source base station to the target base station, which specifically includes the following steps.

[0140] S201, the UE establishes a connection with the source base station, and the UE is in an RRC connected state. The source base station selects a first security algorithm and sends it to the UE for use.

[0141] It can be understood that the source base station saves a security capability associated with the terminal device, denoted as a first security capability, wherein the first security algorithm is the highest priority algorithm selected from the algorithm priority list locally configured by the source base station based on the first security capability. For example, the algorithm priority list locally configured by the source base station has priorities from high to low as ZUC, AES, and SNOW, and the first security capability is (SNOW, AES), and the selected first security algorithm is AES.

[0142] The first security algorithm is the highest priority algorithm selected from the algorithm priority list locally configured by the source base station based on the first security capability. The first security algorithm is the highest priority security algorithm in the intersection of the algorithm priority list locally configured by the source base station and the first security capability.

[0143] For example, the first security algorithm includes a confidentiality protection algorithm and an integrity protection algorithm. It should be noted that the confidentiality protection algorithm and the integrity protection algorithm in the first security algorithm can be different, such as the selected confidentiality protection algorithm is the ZUC confidentiality protection algorithm, and the selected integrity protection algorithm is the AES integrity protection algorithm. In the following, when referring to the security algorithm, the corresponding confidentiality protection algorithm and integrity protection algorithm are included, and the involved places will not be described one by one.

[0144] In addition, the AMF stores a security capability, denoted as a second security capability. The first security capability and the second security capability can be the same or different. For example, in an initial registration process, the UE sends the security capability to the AMF, and the AMF receives and stores the security capability. For example, the UE carries the security capability in an initial non-access stratum (NAS) message, the AMF selects a NAS security algorithm according to the security capability, and sends the NAS security algorithm and the security capability to the UE in a NAS security mode command message. The UE checks whether the security capability is tampered with, and in the case of no tampering, the UE sends a security-protected NAS security mode command complete message. In the case of successful verification of the NAS security mode command complete message, the AMF sends the security capability to the source base station, and the source base station receives and stores the security capability. At this time, it can be considered that the first security capability and the second security capability are the same. For example, if the source base station fails or is captured later, the security capability stored by the source base station changes, and at this time, it can be considered that the first security capability and the second security capability are different.

[0145] S202, the UE sends a measurement report to the source base station. Correspondingly, the source base station receives the measurement report from the UE.

[0146] The measurement report includes measurement results of a plurality of base stations, and the source base station decides to switch to one of the base stations, denoted as a target base station, based on the measurement results.

[0147] S203, the source base station sends a request message to the target base station, and the request message is used to request resources required for preparing handover. Correspondingly, the target base station receives the request message from the source base station.

[0148] The request message includes necessary parameters for switching to the target base station.

[0149] For example, the necessary parameters for switching to the target base station include the first security capability and access stratum (AS) security information. For example, the AS security information includes a key.

[0150] For example, the request message further includes RRC context information, and the RRC context information includes the first security algorithm.

[0151] For example, the name of the request message can be Handover request or Handover required, which is not limited.

[0152] S204, the target base station sends a request response message to the source base station, the request response message is used to inform the prepared resource of the target base station, and the request response message includes a container of the RRC message for triggering the handover. Correspondingly, the source base station receives the request response message from the target base station.

[0153] In an example, the RRC message includes a second security algorithm, and the second security algorithm is the highest priority algorithm selected by the target base station from a locally configured algorithm priority list based on the first security capability.

[0154] In an example, when the second security algorithm is different from the first security algorithm, the RRC message includes the second security algorithm; and when the second security algorithm is the same as the first security algorithm, the RRC message can not carry the second security algorithm.

[0155] In an example, the RRC message can be a handover command (Handover Command) message.

[0156] In an example, the name of the request response message can be Handover request ACK or Handover required ACK, which is not limited.

[0157] S205, the source base station sends an RRC reconfiguration (RRC Reconfiguration) message to the UE, and the RRC reconfiguration message includes a container of the RRC message described in S204. Correspondingly, the UE receives the RRC reconfiguration message from the source base station.

[0158] S206, the UE sends an RRC reconfiguration complete (RRC Reconfiguration Complete) message to the target base station. Correspondingly, the target base station receives the RRC reconfiguration complete message from the UE.

[0159] It can be understood that when the RRC reconfiguration message carries the second security algorithm, the UE subsequently uses the second security algorithm for the security protection of the message with the target base station; and when the RRC reconfiguration message does not carry the second security algorithm, the UE subsequently continues to use the first security algorithm for the security protection of the message with the target base station.

[0160] S207, the target base station sends a path switching request message to the AMF, and the request message is used to inform the AMF of the target base station of the handover, and trigger the core network to migrate the downlink data path of the UE to the target base station, wherein the path switching request message carries the first security capability. Correspondingly, the AMF receives the path switching request message from the target base station.

[0161] S208, the AMF sends a path switch request response message to the target base station, the path switch request response message indicating that the core network has successfully completed the path. Correspondingly, the target base station receives the path switch request response message from the AMF.

[0162] It can be understood that before replying the response message, the AMF needs to check whether the locally stored second security capability and the received first security capability match, and if not, the second security capability is carried in the response message. In addition, in the case of mismatch, the AMF will also record the event and possibly take additional measures, such as generating an alarm, etc.

[0163] In addition, after receiving the response message, the target base station will select the highest priority security algorithm from the second security capability according to the algorithm priority list configured locally by the target base station, which is recorded as the third security algorithm.

[0164] Optionally, when the third security algorithm is different from the first security algorithm or the second security algorithm, the target base station initiates an intra-cell handover procedure, i.e., performs S209 and S210.

[0165] S209, the target base station sends an RRC reconfiguration message to the UE, the RRC reconfiguration message carrying the third security algorithm. Correspondingly, the UE receives the RRC reconfiguration message from the target base station.

[0166] It can be understood that the UE subsequently uses the third security algorithm to protect subsequent messages with the target base station.

[0167] S210, the UE sends an RRC reconfiguration complete message to the target base station. Correspondingly, the target base station receives the RRC reconfiguration complete message from the UE.

[0168] It can be understood that the RRC reconfiguration message in S209 needs to be protected using the second security algorithm, but the RRC reconfiguration complete message in S210 needs to be protected using the third security algorithm.

[0169] FIG. 3 is a schematic flowchart of LTM cross-base station handover. The method mainly includes the following steps.

[0170] S301, the UE sends a measurement report #1 to the source base station. Correspondingly, the source base station receives the measurement report #1 from the UE.

[0171] For example, the measurement report #1 includes measurement results of at least one base station. The measurement report #1 can also include measurement results of at least one cell associated with the at least one base station.

[0172] The at least one base station is a neighboring base station of the terminal device. The measurement result of the at least one base station in the measurement report #1 includes signal strength and signal quality information of the at least one base station.

[0173] The measurement report #1 includes measurement results of the target base station #1 and the target base station #2 shown in FIG. 3. It can be understood that the measurement report #1 can also include measurement results of other base stations in addition to the target base station #1 and the target base station #2.

[0174] It should be noted that the at least one base station corresponding to the measurement report #1 can not be completely the same as the target base station of the source base station. For example, the at least one base station corresponding to the measurement report #1 includes the base station #1, the base station #2 and the base station #3, but the target base station of the source base station includes the base station #2, the base station #3 and the base station #4.

[0175] S302, the source access network decides to configure LTM switching.

[0176] S303, the source base station sends a switching request message #1 to the target base station, the switching request message #1 is used to request the target base station to prepare resources required for switching, and the switching request message #1 includes necessary parameters for switching to the target base station. Correspondingly, the target base station receives the switching request message #1 from the source base station.

[0177] For example, the at least one base station corresponding to the measurement report #1 includes the target base station #1 and the target base station #2 in FIG. 3, and the source base station sends the switching request message #1a and the switching request message #1b to the target base station #1 and the target base station #2 respectively in S303, as shown in S303a and S303b in FIG. 3.

[0178] For example, the source base station can also configure a first cell list for the target base station through the switching request message #1. Taking the target base station #1 as an example, the first cell list of the target base station #1 indicates at least one cell of the target base station #1, and the first cell list indicates configuration information of the at least one cell, for example, the configuration information includes UE aggregate maximum bit rate, UE associated signalling reference and the like. For example, the first cell list can indicate the corresponding cell through a cell identifier.

[0179] The source base station can also configure a second cell list to the target base station. In this application, the second cell list of the target base station can also be referred to as the candidate cell list of the target base station. Taking the target base station #1 as an example, the second cell list of the target base station #1 indicates the set of candidate cells that can be switched to when the target base station #1 becomes the source base station in the subsequent LTM handover. The set of candidate cells can include the cells of the source base station, and / or the cells of the target base station of the source base station, which is not limited in this application.

[0180] The second cell list can indicate the corresponding cells by cell identifiers. As a possible implementation, the cell identifiers are associated with base station identifiers, and the target base station #1 can determine the corresponding candidate base stations based on the cell identifiers in the second cell list. As another possible implementation, the cell identifiers are not associated with base station identifiers, and the source base station sends the second cell list to the target base station while indicating the base station identifiers corresponding to each cell identifier in the second cell list.

[0181] The source base station can carry the second cell list of the corresponding target base station in the handover request message #1 of this step, or can carry the second cell list of the corresponding target base station in a new message, which is not limited in this application.

[0182] The name of the handover request message #1 can be Handover request or Handover required, which is not limited.

[0183] The target base station sends a handover request response message #1 to the source base station, which is used to inform the source base station of the handover resources prepared by the target base station. Correspondingly, the source base station receives the handover request response message #1 from the target base station.

[0184] Taking the target base station including the target base station #1 and the target base station #2 as an example, the source base station sends the handover request response message #1a and the handover request response message #1b to the target base station #1 and the target base station #2 respectively, as shown in S304a and S304b in FIG. 3.

[0185] Optionally, the handover request response message #1 includes an RRC message container, which includes the information (for example, the information of the resources prepared for handover) that the target base station needs to send to the terminal device. The source base station as an intermediate node does not analyze the RRC message container, and the terminal device receives the RRC message container and analyzes the RRC message container to obtain the corresponding information of the target base station.

[0186] The handover request response message 1 can be named as Handover request ACK or Handover required ACK, for example, without limitation.

[0187] S305, the source base station sends an RRC reconfiguration message to the UE, and the RRC reconfiguration message includes the RRC messages of the target base stations in S304. Correspondingly, the UE receives the RRC reconfiguration message from the source base station.

[0188] The RRC messages in S304 and S305 are carried in containers, the source base station acts as a forwarding node and does not parse the RRC messages of the target base stations, and the UE acts as a receiving node and parses the RRC message containers and saves the configurations of the target base stations, for example.

[0189] S306, the UE saves the configurations of the target base stations and sends an RRC reconfiguration complete message to the source base station. Correspondingly, the source base station receives the RRC reconfiguration complete message from the UE.

[0190] S307, the UE sends a measurement report 2 to the source base station. Correspondingly, the source base station receives the measurement report 2 from the UE.

[0191] The measurement report 2 includes the measurement results of the target base station 1 and the target base station 2, for example. Then, the source base station decides to start LTM handover and switches to the target base station 1.

[0192] S308, the source base station sends a cell switch command message to the UE, and the cell switch command message includes the configuration index of the target base station 1. Correspondingly, the UE receives the cell switch command message from the source base station, and the UE determines the configuration of the target base station 1 according to the configuration index of the target base station 1.

[0193] Generally, one cell corresponds to one configuration index, and the configuration index of the target base station 1 can be understood as the configuration index of one cell of the target base station 1. The one cell can be one of the cells indicated by the first cell list of the target base station 1. Then, the configuration of the target base station 1 can be understood as the configuration of the corresponding cell obtained by parsing the RRC message container in S305.

[0194] The cell switch command message is a MAC control element (CE) message, for example.

[0195] S309, the source base station sends a cell switch notification message to the target base station 1, to inform the target base station 1 that the cell switch command has been initiated to the UE.

[0196] S310, optionally, if the handover needs to perform a random access procedure, the UE performs a random access procedure with the target base station #1.

[0197] S311, the UE sends a reconfiguration complete message to the source base station. Correspondingly, the source base station receives the RRC reconfiguration complete message from the UE.

[0198] It can be understood that the reconfiguration complete message is used to indicate that the UE has successfully switched to the target base station #1. That is, after S311, the UE and the target base station #1 can communicate normally.

[0199] S312, the target base station #1 sends a path switch request message to the AMF, and the path switch request message is used to trigger the core network to migrate the downlink data path to the target base station #1. Correspondingly, the AMF receives the path switch request message from the target base station #1.

[0200] S313, the AMF sends a path switch request response message to the target base station #1, and the path switch request response message indicates that the core network has successfully completed the path switch. Correspondingly, the target base station #1 receives the path switch request response message from the AMF.

[0201] S314, optionally, the target base station #1 sends a message #1 to the candidate base station of the target base station #1, and the message #1 is used for updating the security key for subsequent LTM switching, and the message #1 carries a key and a next hop chaining counter (NCC), wherein the key is used for security protection of subsequent messages between the UE and the target base station, and the NCC is used to determine the derivation manner of the key. Correspondingly, the target base station receives the message #1 from the target base station #1.

[0202] For example, the target base station #1 can determine its corresponding candidate base station based on the second cell list (i.e. the candidate cell list) of the target base station #1 obtained in S303. Taking the candidate base stations of the target base station #1 including the source base station and the target base station #2 as an example, the target base station #1 sends a message #1a and a message #1b to the source base station #1 and the target base station #2 respectively, see S314a and S314b in FIG. 3.

[0203] S315, the target base station #1 sends an RRC reconfiguration message to the UE. Correspondingly, the UE receives the RRC reconfiguration message from the target base station #1.

[0204] It can be understood that the target base station #1 needs to inform the UE of the NCC of the above-mentioned candidate base station, indicating that the UE and the target base station perform key derivation in a consistent manner. Then, for example, the target base station #1 can carry the NCC in the RRC reconfiguration message.

[0205] In addition, the order of S314 and S315 is not limited in the present application.

[0206] S316, the UE sends an RRC reconfiguration complete message to the target base station #1. Correspondingly, the target base station #1 receives the RRC reconfiguration complete message from the UE.

[0207] S317, the UE successfully camps on the target base station #1, and the target base station #1 repeatedly performs S307 to S311.

[0208] It can be understood that after the UE successfully camps, the target base station #1 becomes the source base station. In order to avoid confusion, the names of the base stations in the subsequent steps are not modified.

[0209] It can also be understood that repeatedly performing S307 to S311 means replacing the source base station in S307 to S311 with the target base station #1, and replacing the target base station #1 in S307 to S311 with the target base station #2, taking the target base station #2 as the target base station of the third stage handover (i.e. the handover from the target base station #1 to the target base station #2 in the third stage), which is briefly described here and will not be described again. For specific descriptions of each step, please refer to the above S307 to S311.

[0210] S317-1, the UE sends a measurement report #3 to the target base station #1. Correspondingly, the target base station #1 receives the measurement report #3 from the UE.

[0211] The measurement report #3 includes measurement results of at least one base station, the target base station #1 decides to start LTM handover, and decides to hand over to the target base station #2 based on the measurement report #3.

[0212] S317-2, the target base station #1 sends a cell switch command message to the UE, and the cell switch command message includes the configuration index of the target base station #2. Correspondingly, the UE receives the LTM cell switch command message from the target base station #1.

[0213] For example, the target base station #1 can not carry the NCC in S315, but can carry the NCC in the cell switch command message of this step.

[0214] S317-3, the target base station #1 sends a handover notification message to the target base station #2, to inform the target base station #2 that the cell switch command has been initiated to the UE.

[0215] S317-4, optionally, if the handover needs to perform a random access process, the UE and the target base station #2 perform a random access process.

[0216] S317-5, the UE sends a reconfiguration complete message to the target base station #2. Correspondingly, the target base station #2 receives the RRC reconfiguration complete message from the UE.

[0217] S318, the target base station #2 sends a path switching request message to the AMF, the request message being used to trigger the core network to migrate the downlink data path to the target base station #2. Correspondingly, the AMF receives the path switching request message from the target base station #2.

[0218] S319, the AMF sends a path switching request response message to the target base station #2, the response message indicating that the core network has successfully completed the path switching. Correspondingly, the target base station #2 receives the path switching request response message from the AMF.

[0219] S320, optionally, the target base station #2 sends a message #2 to the target base station of the target base station #2, the message #2 being used for updating the security key for the subsequent LTM switching, the message #2 carrying the key and the NCC, the key being used for the security protection of the subsequent messages between the UE and the target base station.

[0220] Taking the candidate base stations of the target base station #2 as an example, the candidate base stations including the source base station and the target base station #1, the target base station #2 sends a message #2a and a message #2b to the source base station and the target base station #1 respectively, see S320a and S320b in FIG. 3.

[0221] S321, the target base station #2 sends an RRC reconfiguration message to the UE. Correspondingly, the UE receives the RRC reconfiguration message from the target base station #2.

[0222] S322, the UE sends an RRC reconfiguration complete message to the target base station #2. Correspondingly, the target base station #2 receives the RRC reconfiguration complete message from the UE.

[0223] The above describes in detail the flow of the security algorithm selection based on the Xn switching. However, at present, there is no clear provision for the security algorithm selection in the LTM switching. Therefore, the algorithm selection method of the Xn switching is combined with the existing LTM switching flow in the present application, and a security algorithm selection method based on the LTM switching is proposed. The following will be described in detail in combination with FIG. 4.

[0224] FIG. 4 is a schematic flow chart of a security algorithm selection method based on LTM switching. As an example, the LTM switching procedure shown in FIG. 4 can be divided into three stages, i.e., LTM Preparation, LTM Execution and Subsequent LTM after initial LTM execution, which correspond to S401-S406, S407-S416 and S417-S422 respectively. The names of the three stages are not limited in the present application. The steps are described in detail as follows.

[0225] It can be understood that FIG. 4 is based on FIG. 3 and specifies how to implement security algorithm selection in the LTM switching procedure. The description not detailed in FIG. 4 can be referred to the description of the corresponding steps in FIG. 3, and the differences between FIG. 3 and FIG. 4 are described in detail as follows.

[0226] S400, the UE establishes a connection with the source access network device, and the terminal device is in an RRC connected state. The source access network device selects a security algorithm #1 and sends it to the terminal device for use.

[0227] For S400, refer to the description of S210 in FIG. 2, which will not be repeated.

[0228] S401, the terminal device sends a measurement report #1 to the source access network device, wherein the measurement report #1 includes measurement results of at least one access network device. Correspondingly, the source access network device receives the measurement report #1 from the terminal device.

[0229] As an example, the measurement report #1 includes measurement results of at least one access network device. The measurement report #1 can also include measurement results of at least one cell associated with the at least one access network device. The other measurement reports will not be repeated one by one hereinafter.

[0230] As an example, the at least one access network device is a nearby access network device of the terminal device. As an example, the measurement results of the at least one access network device in the measurement report #1 include information such as signal strength and signal quality of the at least one access network device.

[0231] As an example, the measurement report #1 includes measurement results of the target access network device #1 and the target access network device #2 shown in FIG. 4. It can be understood that the measurement report #1 can also include measurement results of other access network devices in addition to the target access network device #1 and the target access network device #2.

[0232] It should be noted that the at least one access network device corresponding to the measurement report #1 can not be completely the same as the target access network device of the source access network device. For example, the at least one access network device corresponding to the measurement report #1 includes the access network device #1, the access network device #2 and the access network device #3, but the target access network device of the source access network device includes the access network device #2, the access network device #3 and the access network device #4.

[0233] S402, the source access network device decides to configure LTM switching.

[0234] S403, the source access network device sends a switching request message #1 to at least one target access network device, the switching request message #1 is used to request the target access network device to prepare the resources required for switching, and the switching request message #1 contains a first security capability, and the first security capability is the security capability associated with the terminal device saved by the source access network device. Correspondingly, the target access network device receives the switching request message #1 from the source access network device.

[0235] Taking the target access network device of the source access network device including the target access network device #1 and the target access network device #2 as an example, the source access network device sends the switching request message #1a and the switching request message #1b to the target access network device #1 and the target access network device #2 respectively in S403, see S403a and S403b in FIG. 4.

[0236] For example, the switching request message #1 includes AS security information.

[0237] For example, the switching request message #1 further includes RRC context information, and the RRC context information includes the security algorithm #1.

[0238] For example, the source access network device can also configure the first cell list for the target access network device through the switching request message #1.

[0239] For example, the source access network device can also configure the second cell list for the target access network device. The second cell list can also be called the candidate cell list. For the first cell list and the second cell list, see the description in FIG. 3, which will not be repeated here.

[0240] For example, the source access network device can carry the second cell list corresponding to the target access network device in the switching request message #1 of this step, or can carry the second cell list corresponding to the target access network device in a new message, which is not limited in the present application.

[0241] S404, the target access network device sends a handover request response message #1 to the source access network device, where the handover request response message #1 is used to inform the source access network device of the handover resource prepared by the target access network device. Correspondingly, the source access network device receives the request response message #1 from the target access network device.

[0242] Taking the target access network device as an example, the source access network device sends a request response message #1a and a request response message #1b to the target access network device #1 and the target access network device #2 respectively, as shown in S404a and S404b in FIG. 4.

[0243] Optionally, when the security algorithm selected by the target access network device from the algorithm priority list locally configured by the target access network device based on the first security capability is different from the security algorithm #1, the request response message #1 can further include the security algorithm selected by the target access network device based on the first security capability. For ease of description, the security algorithm selected by the target access network device #1 based on the first security capability is denoted as security algorithm #2, and the security algorithm selected by the target access network device #2 based on the first security capability is denoted as security algorithm #3.

[0244] Optionally, the handover request response message #1 includes an RRC message container, and the RRC message includes information (for example, information of the resource prepared for the handover and the security algorithm) that needs to be sent to the terminal device by the target access network device. The source access network device does not analyze the RRC message container as an intermediate node, and the terminal device receives the RRC message container and analyzes the RRC message container to obtain the corresponding information of the target access network device. For example, if the first cell list is included in S403, the RRC message includes the related configuration information of the cell indicated by the first cell list. For another example, the RRC message can further carry the security algorithm #2 and the security algorithm #3.

[0245] In one implementation, the RRC message must carry the security algorithm selected by the target access network device based on the first security capability; in another implementation, when the security algorithm selected by the target access network device based on the first security capability is different from the security algorithm #1, the RRC message includes the security algorithm selected by the target access network device based on the first security capability; and when the security algorithm selected by the target access network device based on the first security capability is the same as the security algorithm #1, the RRC message can not carry the security algorithm selected by the target access network device based on the first security capability. Taking the RRC message corresponding to the target access network device #1 as an example, the following describes several ways of carrying the security algorithm #2 based on different granularities.

[0246] Example one, carried in the granularity of cell identification (Cell ID) of target access network device #1. For example, {Cell ID#1, security algorithm #2}, {Cell ID#2, security algorithm #2}, {Cell ID#3, security algorithm #2}. For another example, {{Cell ID#1, Cell ID#2, Cell ID#3}, security algorithm #2}.

[0247] Example two, carried in the granularity of target access network device #1 identification (RAN ID). For example, {RAN ID#1, security algorithm #2}.

[0248] Example three, carried in the granularity of cell set identification (Cell Set ID) of target access network device #1. For example, {Cell Set ID#1, security algorithm #2}. One cell set ID corresponds to multiple cells, and one access network device can correspond to at least one cell set ID, and generally corresponds to one cell set ID.

[0249] S405, the source access network device sends an RRC reconfiguration message to the terminal device, and the RRC reconfiguration message includes the RRC message of each target access network device in S404. Correspondingly, the terminal device receives the RRC reconfiguration message from the source access network device.

[0250] Example, the RRC message in S404 and S405 is carried in a container, the source access network device acts as a forwarding node and does not analyze the RRC message of each target access network device, and the terminal device acts as a receiving node and analyzes the RRC message container and saves the configuration of each target access network device.

[0251] S406, the terminal device sends an RRC reconfiguration completion message to the source access network device. Correspondingly, the source access network device receives the RRC reconfiguration completion message from the terminal device.

[0252] S407, the terminal device sends a measurement report #2 to the source access network device. Correspondingly, the source access network device receives the measurement report #2 from the terminal device.

[0253] Example, the measurement report #2 includes the measurement results of each target access network device (target access network device #1 and target access network device #2). The source access network device decides to start LTM switching and switches to target access network device #1 based on the measurement report #2.

[0254] S408, the source access network device sends a cell switch command message to the terminal device, the cell switch command message comprising the configuration index of the target access network device #1. Correspondingly, the terminal device receives the cell switch command message from the source access network device, and determines the configuration of the target access network device #1 according to the configuration index of the target access network device #1.

[0255] In an example, the cell switch command message is a MAC control element (CE) message.

[0256] S409, the source access network device sends a cell switch notification message to the target access network device #1, to inform the target access network device #1 that the source access network device has initiated the cell switch command to the terminal device.

[0257] S410, optionally, if the switch needs to perform a random access procedure, the terminal device performs a random access procedure with the target access network device #1.

[0258] S411, the terminal device sends a reconfiguration complete message to the target access network device #1. Correspondingly, the target access network device #1 receives the RRC reconfiguration complete message from the terminal device.

[0259] It can be understood that after S411, the terminal device and the target access network device #1 can normally communicate.

[0260] S412, the target access network device #1 sends a path switch request message to the access and mobility management function, the path switch request message being used to trigger the core network to migrate the downlink data path to the target access network device #1, wherein the path switch request message comprises the first security capability. Correspondingly, the access and mobility management function receives the path switch request message from the target access network device #1.

[0261] S413, the access and mobility management function sends a path switch request response message to the target access network device #1, the path switch request response message indicating that the core network has successfully completed the path switch. Correspondingly, the target access network device #1 receives the path switch request response message from the access and mobility management function.

[0262] It can be understood that before replying the response message, the access and mobility management function needs to check whether the locally stored second security capability and the received first security capability match, and if not, the second security capability carried in the response message is the security capability associated with the terminal device saved by the access and mobility management function. In addition, in the case of mismatch, the access and mobility management function will also record the event and may take additional measures, such as generating an alarm.

[0263] For example, if the first security capability does not match, the target access network device #1 receives the path switching request response message, and selects the security algorithm with the highest priority from the second security capability according to the algorithm priority list locally configured by the target access network device #1, which is recorded as security algorithm #4. When the security algorithm #4 is different from the security algorithm #1 or the security algorithm #2, the target access network device #1 initiates an intra-cell handover process, that is, performs S415 and S416.

[0264] S414, optionally, the target access network device #1 sends a message #1 to the candidate access network device of the target access network device #1, the message #1 being used for updating the security key for subsequent LTM switching, the message #1 carrying a key and a next hop chaining counter (NCC), wherein the key is used for security protection of messages between the terminal device and the candidate access network device, and the NCC is used to determine the derivation mode of the key. Correspondingly, the candidate access network device receives the message #1 from the target access network device #1.

[0265] For example, the target access network device #1 can determine the corresponding candidate access network device based on the second cell list (i.e. the candidate cell list) of the target access network device #1 obtained in S403. Taking the candidate access network devices of the target access network device #1 including the source access network device and the target access network device #2 as an example, the source access network device sends a message #1a and a message #1b to the target access network device #1 and the target access network device #2 respectively, as shown in S414a and S414b in FIG. 4.

[0266] S415, the target access network device #1 sends an RRC reconfiguration message to the terminal device, the RRC reconfiguration message carrying the security algorithm #4. Correspondingly, the terminal device receives the RRC reconfiguration message from the target access network device #1.

[0267] It can be understood that the terminal device updates the locally saved security algorithm associated with the target access network device #1, that is, updates to the received security algorithm #4. Subsequently, the terminal device uses the security algorithm #4 to perform security protection of messages with the target access network device #1.

[0268] It can also be understood that the target access network device #1 also needs to inform the terminal device of the NCC of the candidate access network device of the target access network device #1, instructing the terminal device and the candidate access network device to perform key derivation in a consistent manner. Therefore, for example, the target access network device #1 can carry the NCC in the RRC reconfiguration message.

[0269] In addition, the present application does not limit the order of S414 and S415.

[0270] S416, the terminal device sends an RRC reconfiguration complete message to the target access network device #1. Correspondingly, the target access network device #1 receives the RRC reconfiguration complete message from the terminal device.

[0271] It can be understood that the RRC reconfiguration message in S415 needs to be protected by using the security algorithm #2, but the RRC reconfiguration complete message in S416 needs to be protected by using the security algorithm #4.

[0272] It can also be understood that S415 and S416 are used to align the security algorithms required to be used subsequently by the terminal device and the target access network device #1, and therefore the RRC reconfiguration process needs to be completed compulsorily, which will affect the switching delay and performance.

[0273] S417, the terminal device successfully camps on the target access network device #1, and the target access network device #1 repeatedly performs S407 to S411.

[0274] It can be understood that after the terminal device successfully camps, the target access network device #1 becomes the source access network device. In order to avoid confusion, the names of the access network devices in the subsequent steps are not modified.

[0275] It can also be understood that repeatedly performing S407 to S411 means replacing the source access network device in S407 to S411 with the target access network device #1, and replacing the target access network device #1 in S407 to S411 with the target access network device #2, taking the target access network device # as the target access network device of the third stage switching (i.e., switching from the target access network device #1 to the target access network device #2 in the third stage), for example. The processes are briefly described here, and will not be described again. For specific descriptions of the steps, please refer to the above S407 to S411.

[0276] S417-1, the terminal device performs measurement on the candidate access network device and sends a measurement report #3 to the target access network device #1. Correspondingly, the target access network device #1 receives the measurement report #3 from the terminal device.

[0277] The measurement report #3 includes measurement results of each candidate access network device, the target access network device #1 decides to initiate LTM handover, and decides to hand over to the target access network device #2 based on the measurement report #3.

[0278] S417-2, the target access network device #1 sends a cell switch command message to the terminal device, and the cell switch command message includes a configuration index of the target access network device #2. Correspondingly, the terminal device receives the cell switch command message from the target access network device #1, and determines the configuration of the target access network device #2 according to the configuration index of the target access network device #2.

[0279] For example, the target access network device #1 can not carry the NCC in S415, but carry the NCC in the cell switch command message of this step.

[0280] S417-3, the target access network device #1 sends a handover notification message to the target access network device #2, to inform the target access network device #2 that the cell switch command has been initiated to the terminal device.

[0281] S417-4, optionally, if the handover needs to perform a random access procedure, the terminal device and the target access network device #2 perform a random access procedure.

[0282] S417-5, the terminal device sends a reconfiguration complete message to the target access network device #2. Correspondingly, the target access network device #2 receives the RRC reconfiguration complete message from the terminal device.

[0283] It can be understood that after S417-5, the terminal device and the target access network device #2 can normally communicate based on the second security algorithm #2.

[0284] S418, the target access network device #2 sends a path switch request message to the access and mobility management function, and the request message is used to trigger the core network to migrate the downlink data path to the target access network device #2 access and mobility management function, wherein the first security capability is included in the path switch request message. Correspondingly, the access and mobility management function receives the path switch request message from the target access network device #2.

[0285] S419, the access and mobility management function sends a path switch request response message to the target access network device #2, and the response message indicates that the core network has successfully completed the path switch. Correspondingly, the target access network device #2 receives the path switch request response message from the access and mobility management function.

[0286] It can be understood that before replying the response message, the access and mobility management function needs to check whether the locally stored second security capability and the received first security capability match, and if not, the second security capability is carried in the response message. In addition, in the case of mismatch, the access and mobility management function also records the event and can take additional measures, such as generating an alarm, etc.

[0287] In addition, after receiving the response message, the target access network device #1 selects the security algorithm with the highest priority from the second security capability according to the algorithm priority list locally configured by the target access network device #2, and records it as security algorithm #5. When the security algorithm #5 is different from the security algorithm #1 or the security algorithm #3, the target access network device #2 initiates an intra-cell handover procedure, that is, performs S421.

[0288] S420, optionally, the target access network device #2 sends a message #2 to the candidate access network device of the target access network device #2, the message #2 is used for updating the security key for subsequent LTM handover, and the message #2 carries the key and the NCC, the key is used for the security protection of the message between the subsequent terminal device and the candidate access network device.

[0289] Taking the candidate access network device of the target access network device #2 including the source access network device and the target access network device #1 as an example, the target access network device #2 sends a message #2a and a message #2b to the source access network device and the target access network device #1 respectively, see S420a and S420b in FIG. 4.

[0290] S421, the target access network device #2 sends an RRC reconfiguration message to the terminal device, and the RRC reconfiguration message carries the security algorithm #5. Correspondingly, the terminal device receives the RRC reconfiguration message from the target access network device #2.

[0291] It can be understood that after receiving the security algorithm #5, the terminal device uses the security algorithm #5 for the security protection of the message with the target access network device #2 in the subsequent process.

[0292] S422, the terminal device sends an RRC reconfiguration complete message to the target access network device #2. Correspondingly, the target access network device #2 receives the RRC reconfiguration complete message from the terminal device.

[0293] It can be understood that the RRC reconfiguration message in S421 needs to be protected by using the security algorithm #3, but the RRC reconfiguration complete message in S422 needs to be protected by using the security algorithm #5.

[0294] It can also be understood that S421 and S422 are used for the terminal device and the target access network device #2 to align the security algorithm required for subsequent interaction, so the RRC reconfiguration process needs to be forced to complete, which will affect the handover delay and performance.

[0295] The above describes in detail the flow of a possible security algorithm selection method based on LTM handover in combination with FIG. 4. As can be seen, in the security algorithm selection flow in the LTM scenario shown in FIG. 4, each target access network device (for example, target access network device #1 and target access network device #2) first obtains the security capability saved by the source access network device from the source access network device. When the source access network device fails or is captured, the subsequent step of checking the security capability by the AMF will result in a failed security capability check, which means that the security capability saved by the source access network device and the AMF side is inconsistent. Then, each time the LTM handover is performed (the source access network device switches to target access network device #1 in the second stage, and target access network device #1 switches to target access network device #2 in the third stage), the AMF will record the event of inconsistent security capability and may generate an alarm, and finally trigger the intra-cell handover process, thereby increasing the LTM handover delay. In addition, triggering the AMF to record the event of inconsistent security capability multiple times, and possibly generating multiple alarms, will also result in very complex operation and maintenance costs and problem positioning.

[0296] Therefore, the present application further improves the security algorithm selection flow shown in FIG. 4, which can effectively solve the above technical problems. The following will be described in detail in combination with FIGS. 5 to 9.

[0297] FIG. 5 is a schematic diagram of a communication method proposed by the present application. In this method, the target access network device can inform other candidate access network devices of the security capability associated with the terminal device after obtaining the security capability saved by the AMF in the LTM execution stage (i.e., the second stage), thereby avoiding the problem of increased LTM handover delay caused by the unsuccessful UE security capability check. The method mainly includes the following steps.

[0298] S501, the source access network device sends a first handover request message to the target access network device, and the first handover request message includes a first security capability. Correspondingly, the target access network device receives the first handover request message from the source access network device.

[0299] The first security capability is a security capability associated with the terminal device and stored by the source access network device. It can be understood that the source access network device can send the first handover request message to at least one target access network device respectively in this step, and the at least one target access network device is a candidate LTM handover access network device of the terminal device. For example, the at least one target access network device in this embodiment can be the target access network device #1 and the target access network device #2 in FIG. 4.

[0300] It can be understood that the first handover request message is used to request the candidate access network device to prepare the resources required for handover. For example, the resources required for handover include a UE aggregate maximum bit rate, a UE associated signalling reference, and the like.

[0301] For example, the first handover request message includes an RRC context, and the RRC context includes the first security capability.

[0302] For example, the first handover request message further includes a security algorithm #1, and the security algorithm #1 is an algorithm with the highest priority selected by the source access network device from an algorithm priority list configured locally by the source access network device based on the first security capability.

[0303] S502, the target access network device determines a security algorithm #2 of the target access network device, and the security algorithm #2 is an algorithm with the highest priority selected from an algorithm priority list configured locally by the target access network device based on the first security capability.

[0304] Optionally, the method further includes S503 and S504.

[0305] S503, the target access network device sends a first handover request response message to the source access network device. Correspondingly, the source access network device receives the request response message from the target access network device.

[0306] It can be understood that the first handover request response message is used to notify the target access network device of the resources prepared for handover.

[0307] For example, if the first handover request message includes the security algorithm #1, the security algorithm #2 is included in the first handover request response message in the case that the security algorithm #2 is not the same as the security algorithm #1.

[0308] Optionally, the first handover request response message comprises an RRC message container, and the RRC message container comprises information (e.g., information of resources prepared for handover and security algorithm #2, etc.) required to be sent by the target access network device to the terminal device. The source access network device does not analyze the RRC message container as an intermediate node, and the terminal device receives the RRC message container and analyzes the RRC message container to obtain and save corresponding information of the target access network device.

[0309] S504, the source access network device sends a message #1 to the terminal device, and the message #1 is used to notify the target access network device of resources prepared for handover. Correspondingly, the terminal device receives the message #1 from the source access network device.

[0310] Optionally, the message #1 comprises the RRC message container.

[0311] Optionally, the terminal device further sends a response message of the message #1 to the source access network device.

[0312] Optionally, the message #1 and the response message of the message #1 are RRC reconfiguration messages.

[0313] It can be understood that if the message #1 carries the security algorithm #2, after the terminal device and the target access network device synchronize the security algorithm #2, the terminal device and the target access network device can use the security algorithm #2 to perform security protection on communication between the target access network device and the terminal device. For example, the terminal device can use the security algorithm #2 to perform security protection on the message #2 in subsequent S507.

[0314] S505, the source access network device sends a first handover command message to the terminal device, and the first handover command message instructs the terminal device to switch to the target access network device. Correspondingly, the terminal device receives the first handover command message from the source access network device.

[0315] Optionally, before sending the first handover command message, the source access network device can determine a target access network device to switch to based on the received measurement report.

[0316] S506, the source access network device sends a first handover notification message to the target access network device, and the first handover notification message is used to inform the target access network device that the source access network device has initiated a handover command to the terminal device. Correspondingly, the target access network device receives the first handover notification message from the source access network device.

[0317] S507, the terminal device sends a message #2 to the target access network device, and the message #2 indicates that the terminal device has completed reconfiguration.

[0318] For example, the message #2 can be an RRC reconfiguration message. The message #2 indicates that the terminal device has successfully switched to the target access network device.

[0319] S508, the target access network device sends a first path switching request message to the access and mobility management function, the first path switching request message being used to trigger the core network to migrate the downlink data of the terminal device to the target access network device. The first security capability is included in the first path switching request message.

[0320] S509, the target access network device receives a first path switching request response message from the access and mobility management function, the first path switching request response message indicating that the core network has successfully completed the path switching, the first path switching request response message including a second security capability, the second security capability being different from the first security capability, and the second security capability being the security capability associated with the terminal device saved by the access and mobility management function.

[0321] S510, the target access network device updates the saved first security capability to the second security capability.

[0322] The execution sequence of S510 is not limited in the present application.

[0323] S511, the target access network device sends a message #3 to the candidate access network device, the message #3 including the second security capability, the second security capability being used to update the security capability associated with the terminal device saved by the candidate access network device.

[0324] It can be understood that the candidate access network device is a candidate access network device corresponding to the target access network device, i.e., the terminal device can be switched to the candidate access network device by the target access network device in the subsequent LTM switching. For example, the candidate access network device can be determined based on the following manner in this step: the target access network device can receive a candidate cell list (i.e., a second cell list) sent by the source access network before this step, the candidate cell list indicating at least one cell; and the target access network device can determine the candidate access network device based on the candidate cell list, the candidate access network device being an access network device associated with the at least one cell.

[0325] For example, the candidate cell list of the target access network device can be carried in the first switching request message in S501, or can be sent separately, for example, in a separate step after S501, which is not limited.

[0326] The candidate access network device in FIG. 5 is taken as an example. It should be noted that FIG. 5 is only an example, and the candidate access network device of the target access network device can also include other access network devices. For example, the target access network device further includes access network device A and access network device B, and the target access network device sends the second security capability to the access network device A and the access network device B.

[0327] The message #3 further includes the identification information of the terminal device.

[0328] Optionally, the step can be performed at any time after S509, that is, at any time after the second security capability is acquired. For example, the step can be performed before S509.

[0329] S512, the candidate access network device of the target access network device sends a message #4 to the target access network device, and the message #4 includes a security algorithm #3 of the candidate access network device. The security algorithm #3 is the highest priority algorithm selected from the algorithm priority list locally configured by the candidate access network device based on the second security capability. Correspondingly, the target access network device receives the message #4 from the candidate access network device.

[0330] In an implementation manner, the security algorithm #3 must be carried in the message #4. In another implementation manner, if the security algorithm #3 of the candidate access network device is different from the highest priority algorithm selected from the algorithm priority list locally configured by the candidate access network device based on the first security capability, the security algorithm #3 needs to be carried in the message #4, and if the same, the security algorithm #3 is not carried in the message #4.

[0331] For example, the message #3 and the message #4 are Xn messages.

[0332] S513, the target access network device sends a message #5 to the terminal device, and the message #5 includes the security algorithm #3 of the candidate access network device. The message #5 indicates that the security algorithm #3 is used to update the security algorithm for protecting the communication between the candidate access network device and the terminal device. Correspondingly, the terminal device receives the message #5 from the target access network device, and updates the security algorithm for protecting the communication between the terminal device and the candidate access network device saved by the terminal device to the security algorithm #3.

[0333] In an implementation manner, the target access network device carries the security algorithm #3 of all the related candidate access network devices in one message #5.

[0334] In another implementation manner, the target access network device carries the security algorithm #3 of N candidate access network devices in M messages #5, N is an integer greater than 1, and M is less than or equal to N.

[0335] For example, M=3, N=5, the M fifth messages are respectively fifth message #1, fifth message #2 and fifth message #3, and the 5 candidate access network devices are respectively candidate access network device #1, candidate access network device #2, candidate access network device #3, candidate access network device #4 and candidate access network device #5, wherein the fifth message #1 carries the corresponding security algorithm #3 of the candidate access network device #1, candidate access network device #2 and candidate access network device #3, the fifth message #2 carries the corresponding security algorithm #3 of the candidate access network device #4, and the fifth message #3 carries the corresponding security algorithm #3 of the candidate access network device #5.

[0336] For example, if M=N, the M fifth messages correspond to the N candidate access network devices one by one, that is, the security algorithm #3 corresponding to one candidate access network device is carried in the fifth message.

[0337] Optionally, the message #5 also includes the security algorithm #4 of the target access network device, and the security algorithm #4 is the highest priority algorithm selected from the algorithm priority list locally configured by the target access network device based on the second security capability.

[0338] Optionally, the target access network device can also send the security algorithm #4 to the terminal device through a separate message after determining the security algorithm #4.

[0339] The application does not limit the sending occasion of the security algorithm #4. The target access network device can first send the second security capability to the candidate access network device, and then send the security algorithm #4 to the terminal device after receiving the second security capability, or first send the second security capability to the candidate access network device, and then send the security algorithm #4 to the terminal device, or send the security algorithm #4 of the target access network device and the security algorithm #3 of the candidate access network device to the terminal device after receiving the security algorithm #3 of the candidate access network device, without limitation.

[0340] It can be understood that the terminal device saves the corresponding security algorithm after receiving the security algorithm #4 of the target access network device and the security algorithm #3 of the candidate access network device. Subsequently, the terminal device can use the updated security algorithm to securely protect the communication between the candidate access network device / target access network device and the terminal device.

[0341] S514, the terminal device sends a message #6 to the target access network device, and the message #6 is a response message of the message #5. Correspondingly, the target access network device receives the message #6 from the terminal device.

[0342] For example, the message #6 is an RRC reconfiguration complete message.

[0343] The flow corresponding to FIG. 5 is described in detail above. As can be seen, in the scheme shown in FIG. 5, when the target access network device obtains the second security capability in S509, the target access network device can indicate the second security capability to the candidate access network device, and indicate the updated security algorithm to the terminal device, thereby avoiding the problem of increased LTM switching delay due to the inconsistency between the security capability associated with the terminal device saved by the candidate access network device and the security capability associated with the terminal device saved by the access and mobility management function in subsequent switching processes.

[0344] For example, the target access network device can indicate the corresponding information to the candidate access network device and the terminal device at different stages. For example, indication mode one, the target access network device can indicate the above information before the next LTM switching; indication mode two, the target access network device can temporarily stop subsequent switching after receiving the second security capability information, perform LTM switching preparation, and indicate the above information to the candidate access network device and the terminal device in the switching preparation process.

[0345] Corresponding to indication mode one, after receiving the message #6 of the terminal device, the method can further include: the target access network device determines to switch to the first access network device; the target access network device sends a second switching command message to the terminal device, the second switching command message indicating the terminal device to switch to the first access network device; the target access network device sends a second switching notification message to the first access network device, the second switching notification message being used to inform the first access network device that the target access network device has initiated a switching command to the terminal device.

[0346] It can be understood that the switching of the source access network device to the target access network device in the flow shown in FIG. 5 can be regarded as the first switching, and the switching of the target access network device to the first access network device can be regarded as the second switching. Then, in this mode one, the target access network device can be regarded as the source access network device of the second switching, and the first access network device can be regarded as the target access network device of the second switching.

[0347] It can also be understood that after the second switching, the terminal device successfully switches to the first access network device, and this mode one can further include the following steps: the first access network device sends a second path switching request message to the access and mobility management function, the second path switching request message being used to trigger the core network to migrate the downlink data of the terminal device to the first access network device, and the first path switching request message includes the second security capability. Then, the access and mobility management function sends a second path switching request response message to the target access network device, the second path switching request response message indicating that the core network has successfully completed the path switching.

[0348] It can be seen that, based on mode one, in the first handover execution of the source access network device to the target access network device, the target access network device synchronizes the second security capability to its candidate access network device, thereby avoiding the problem of increasing LTM handover delay due to unsuccessful UE security capability verification in the subsequent handover execution of the target access network device to the first access network device.

[0349] Corresponding to the indication mode two, the message #3 is a second handover request message, which is used to request resources needed for handover preparation, the message #4 is a second handover request response message, which is used to notify the candidate access network device of the target access network device of the resources prepared for handover, and the message #5 is an RRC reconfiguration message, which is used to configure the terminal device with the resources prepared for handover by the candidate access network device, and the message #6 is an RRC reconfiguration message.

[0350] For example, in mode two, the target access network device can also send a candidate cell list to its candidate access network device, and the candidate access network device can determine the subsequent switchable access network device based on the candidate cell list sent to itself.

[0351] For example, the target access network device can carry the candidate cell list of the candidate access network device in the second handover request message, or can carry the candidate cell list of the candidate access network device in a new message, which is not limited in the present application.

[0352] It can be seen that, based on mode two, after the target access network device determines that the first security capability is different from the second security capability, it temporarily stops subsequent handover and executes handover preparation related procedures, and in the handover preparation procedure, the target access network device synchronizes the second security capability to its candidate access network device.

[0353] The complete security algorithm selection procedure based on LTM handover is given below based on the above-mentioned mode one and mode two, and the specific procedure is shown in FIG. 6 and FIG. 7. For the convenience of understanding, FIG. 6 and FIG. 7 take the terminal device as UE, the access network device as base station, and the access and mobility management function as AMF as examples for introduction. It can be understood that the procedure described below is only an example for illustration, and the embodiments of the present application are not limited thereto.

[0354] First, the method of selecting a security algorithm based on LTM handover shown in FIG. 6 is introduced. The method includes the following steps.

[0355] The description of S600 to S611 in FIG. 6 is the same as that of S400 to S411 in FIG. 4, which will not be repeated here.

[0356] S612, the target base station #1 sends a path switching request message to the AMF, the path switching request message is used to trigger the core network to migrate the downlink data path to the target base station #1, wherein the first security capability is carried in the path switching request message. Correspondingly, the AMF receives the path switching request message from the target base station #1.

[0357] S613, the AMF sends a path switching request response message to the target base station #1, the path switching request response message indicates that the core network has successfully completed the path switching. Correspondingly, the target base station #1 receives the path switching request response message from the AMF.

[0358] It can be understood that before replying the response message, the AMF will check whether the second security capability stored locally and the first security capability received match, if not, the second security capability is carried in the response message. In addition, in the case of not matching, the AMF will also record the event and may take additional measures, such as generating an alarm, etc.

[0359] In addition, if the second security capability and the first security capability do not match, the target base station #1 needs to synchronize the second security capability to the candidate base station of the target base station #1, that is, S615 is performed.

[0360] S614, optionally, the target base station #1 sends a message A to the candidate base station of the target base station #1, the message A is used to synchronize the security key used in the subsequent LTM switching, the message A carries the key and the NCC, wherein the key is used for security protection of the subsequent messages of the UE and the candidate base station, and the NCC is used to determine the derivation mode of the key. Correspondingly, the candidate base station receives the message A from the target base station #1.

[0361] For example, the target base station #1 can determine the corresponding candidate base station based on the second cell list (i.e. the candidate cell list) of the target base station #1 obtained in S603. As shown in FIG. 6, here the candidate base station of the target base station #1 includes the source base station and the target base station #2, then the target base station #1 sends the message A to the source base station and the target base station #2 respectively, see S614a and 14b in FIG. 6.

[0362] S615, the target base station #1 sends a message B to the candidate base station of the target base station #1, the message B is used to update the UE security capability saved by the candidate base station, and the second security capability is carried in the message B. Correspondingly, the candidate base station receives the message B from the target base station #1.

[0363] Taking the candidate base stations of the target base station #1 including the source base station and the target base station #2 as an example, the target base station #1 sends a message B to the source base station and the target base station #2 respectively, as shown in S615a and S615b in FIG. 6. Then, the candidate base stations store the second security capability, that is, the first security capability stored is updated to the second security capability.

[0364] It can be understood that the trigger condition of S615 is that the target base station #1 receives the second security capability in S613.

[0365] In this application, the order of S614 and S615 is not limited. For example, S615 can be executed before S614, or it can also be executed after S614, or S614 and S615 can be combined, that is, the second security capability is carried in the message A of S614 and sent to the candidate base station, which is not limited.

[0366] S616, the candidate base station of the target base station #1 sends a message C to the target base station #1, and the message C includes the security algorithm #3 of the candidate base station, which is the highest priority algorithm selected from the algorithm priority list configured locally by the candidate base station based on the second security capability. Correspondingly, the target base station #1 receives the message #3 from the candidate base station.

[0367] Taking the candidate base stations of the target base station #1 including the source base station and the target base station #2 as an example, the source base station and the target base station #2 send a message C to the target base station #1 respectively, as shown in S616a and S616b in FIG. 6.

[0368] In one implementation, the security algorithm #3 must be carried in the message C. In another implementation, if the security algorithm #3 of the candidate base station is different from the highest priority algorithm selected from the algorithm priority list configured locally by the candidate base station based on the first security capability, the security algorithm #3 needs to be carried in the message #4, and if they are the same, the security algorithm #3 is not carried in the message #4.

[0369] For example, the message B and the message C are Xn messages.

[0370] Based on S615 and S616, the following beneficial effects can be achieved: As can be seen, when the target base station #1 finds that the first security capability and the second security capability are inconsistent, it will inform its candidate base stations of the second security capability obtained from the AMF, and the candidate base stations can obtain the security capability consistent with the AMF, avoiding abnormal event records and alarms on the AMF in the subsequent LTM switching process of the candidate base stations; and the reselection of the security algorithm corresponding to the base station and the intra-base station switching process in the subsequent LTM switching process are avoided.

[0371] S617, the target base station #1 sends an RRC reconfiguration message to the UE, the RRC reconfiguration message including the security algorithm #3 of the candidate base station and the security algorithm #4 of the target base station, the security algorithm #4 being the highest priority algorithm selected from the algorithm priority list configured locally by the target base station based on the second security capability. Correspondingly, the UE receives the RRC reconfiguration message from the target base station #1 and updates the saved security algorithms of the candidate base station and the target base station, i.e., saves the security algorithm #3 of the candidate base station and the security algorithm #4 of the target base station.

[0372] In an implementation manner, the target base station #1 can send multiple RRC reconfiguration messages, each RRC reconfiguration message indicating the corresponding security algorithm of one base station (the target base station #1 or the candidate base station). For example, the target base station #1 sends an RRC reconfiguration message #1, an RRC reconfiguration message #2 and an RRC reconfiguration message #3 to the UE, wherein the RRC reconfiguration message #1 includes {the identification information of the target base station #1, the security algorithm #4}, the RRC reconfiguration message #2 includes {the identification information of the candidate base station #1, the security algorithm #3 corresponding to the candidate base station #1}, and the RRC reconfiguration message #1 includes {the identification information of the candidate base station #2, the security algorithm #3 corresponding to the candidate base station #2}.

[0373] In another implementation manner, the target base station #1 can send only one RRC reconfiguration message, the RRC reconfiguration message indicating the corresponding security algorithms of the target base station #1 and the candidate base stations of the target base station #1. For example, the RRC reconfiguration message includes {{the identification information of the target base station #1, the security algorithm #4}, {the identification information of the candidate base station #1, the security algorithm #3 corresponding to the candidate base station #1}, {the identification information of the candidate base station #2, the security algorithm #3 corresponding to the candidate base station #2}}. For another example, the RRC reconfiguration message includes {the identification information of the target base station #1, the identification information of the candidate base station #1, the identification information of the candidate base station #2}, {the security algorithm #4, the security algorithm #3 corresponding to the candidate base station #1, the security algorithm #3 corresponding to the candidate base station #2}.

[0374] It can be understood that the target base station #1 also needs to inform the UE of the NCC of the candidate base station in S614. Then, for example, the target base station #1 can carry the NCC in the RRC reconfiguration message in this step.

[0375] S618, the UE sends an RRC reconfiguration complete message to the target base station #1. Correspondingly, the target base station #1 receives the RRC reconfiguration complete message from the UE.

[0376] It can be understood that the RRC reconfiguration message in S617 needs to be protected by using the security algorithm #2 of the target base station, which is the highest priority algorithm selected from the algorithm priority list configured locally by the target base station based on the first security capability, but the RRC reconfiguration completion message in S618 needs to be protected by using the security algorithm #4.

[0377] S619, the UE successfully camps on the target base station #1, and the target base station #1 repeats S607 to S611.

[0378] It can be understood that after the UE successfully camps, the target base station #1 becomes the source base station in the third phase of the LTM handover. In order to avoid confusion, the names of the base stations in the subsequent steps are not modified.

[0379] It can also be understood that repeating S607 to S611 means replacing the source base station in S607 to S611 with the target base station #1, and replacing the target base station #1 in S607 to S611 with the target base station #2, taking the target base station #2 as an example. The target base station for this handover, hereinafter the steps are briefly described, and the specific description of each step is described with reference to S607 to S611 in FIG. 6.

[0380] S619-1, the UE sends a measurement report #3 to the target base station #1. Correspondingly, the target base station #1 receives the measurement report #3 from the UE.

[0381] The measurement report #3 includes the measurement results of each candidate base station, the source base station starts the LTM handover, and decides to hand over to the target base station #2 based on the measurement report #3.

[0382] S619-2, the target base station #1 sends a cell switch command message to the UE, and the cell switch command message includes the configuration index of the target base station #2. Correspondingly, the UE receives the cell switch command message from the target base station #1, and determines the configuration of the target base station #2 according to the configuration index of the target base station #2.

[0383] For example, the target base station #1 can not carry the NCC in S615, but carry the NCC in the LTM cell switch command message in this step.

[0384] S619-3, the target base station #1 sends a handover notification message to the target base station #2, to inform the target base station #2 that the cell switch command has been initiated to the UE.

[0385] S619-4, optionally, if the handover needs to perform a random access process, the UE and the target base station #2 perform a random access process.

[0386] S619-5, the UE sends an RRC reconfiguration complete message to the target base station #2. Correspondingly, the target base station #2 receives the RRC reconfiguration complete message from the UE.

[0387] It can be understood that the RRC reconfiguration complete message indicates that the terminal device successfully switches to the target base station #2.

[0388] S620, the target base station #2 sends a path switching request message to the AMF, and the path switching request message is used to trigger the core network to migrate the downlink data path to the target base station #2, wherein the second security capability is included in the path switching request message. Correspondingly, the AMF receives the path switching request message from the target base station #2.

[0389] S621, the AMF sends a path switching request response message to the target base station #2, and the path switching request response message indicates that the core network has successfully completed the path switching. Correspondingly, the target base station #2 receives the path switching request response message from the AMF.

[0390] It can be understood that before replying to the response message, the AMF needs to check whether the locally stored second security capability and the received UE security capability from the target base station #1 match, and if they do not match, the second security capability is carried in the response message. In addition, in the case of mismatch, the AMF will also record the event and may take additional measures, such as generating an alarm. Since the target base station #2 has obtained the UE security capability consistent with the AMF through the target base station #1 in S615, the check of the UE security capability on the AMF will be successful, thereby avoiding the generation of abnormal event records and alarms on the AMF by the target base station #2 in this LTM switching process, and also avoiding the reselection of the corresponding security algorithm and the intra-base station switching process by the target base station #2 in this LTM switching process.

[0391] S622, optionally, the target base station #2 sends a message D to the candidate base station of the target base station #2, and the message D is used for updating the security key for subsequent LTM switching, and the message D carries the key and the NCC.

[0392] Taking the candidate base station of the target base station #2 as an example, the source base station and the target base station #1 respectively send a message D to the target base station #2, see S622a and S622b in FIG. 6.

[0393] For example, the NCC can be carried by a switching command message in the next switching, or it can also be carried in other RRC reconfiguration messages after the end of this switching, which is not limited.

[0394] Next, the method for selecting a security algorithm based on LTM switching shown in FIG. 7 is introduced. The method includes the following steps.

[0395] The description of S700 to S711 in FIG. 7 is the same as that of S400 to S411 in FIG. 4, and is not repeated here.

[0396] S712, the target base station #1 sends a path switching request message to the AMF, the request message being used to trigger the core network to migrate the downlink data path to the target base station #1, wherein the first security capability is included in the path switching request message. Correspondingly, the AMF receives the path switching request message from the target base station #1.

[0397] S713, the AMF sends a path switching request response message to the target base station #1, the path switching request response message indicating that the core network has successfully completed the path switching. Correspondingly, the target base station #1 receives the path switching request response message from the AMF.

[0398] It can be understood that before replying the response message, the AMF will check whether the second security capability stored locally and the first security capability received match, and if not, the second security capability is included in the response message. In addition, in the case of mismatch, the AMF will also record the event and possibly take additional measures, such as generating an alarm, etc.

[0399] In addition, if the second security capability and the first security capability do not match, the target base station #1 needs to synchronize the second security capability to the candidate base station of the target base station #1, i.e., S715 is performed.

[0400] S714, optionally, the target base station #1 sends a message E to the candidate base station of the target base station #1, the message E being used for updating the security key for subsequent LTM switching, the message E including a key and a next hop chaining counter (NCC), wherein the key is used for security protection of subsequent messages between the UE and the candidate base station, and the NCC is used to determine the derivation manner of the key. Correspondingly, the candidate base station receives the message E from the target base station #1.

[0401] For example, the target base station #1 can determine the corresponding candidate base station based on the second cell list (i.e., the candidate cell list) of the target base station #1 obtained in step 3. Taking an example in which the candidate base stations of the target base station #1 include the target base station #1 and the target base station #2, the source base station sends a message Ea and a message Eb to the target base station #1 and the target base station #2, respectively, see S714a and S714b in FIG. 7.

[0402] S715, the target base station #1 sends an RRC reconfiguration message to the UE, the RRC reconfiguration message carrying a security algorithm #4 of the target base station #1, the security algorithm #4 being the highest priority algorithm selected from the algorithm priority list of the target base station #1 based on the second security capability. Correspondingly, the UE receives the RRC reconfiguration message from the target base station #1.

[0403] It can also be understood that the target base station #1 also needs to inform the UE of the NCC of the candidate base station of the target base station #1, instructing the UE and the candidate base station to perform key derivation in a consistent manner. Therefore, for example, the target base station #1 can carry the NCC in the RRC reconfiguration message.

[0404] In addition, the present application does not limit the order of S714 and S715.

[0405] S716, the UE sends an RRC reconfiguration complete message to the target base station #1. Correspondingly, the target base station #1 receives the RRC reconfiguration complete message from the UE.

[0406] After that, the target base station #1 stops subsequent LTM switching (i.e., the target base station #1 temporarily does not perform LTM switching), and triggers to re-perform LTM switching preparation. The re-performed LTM switching preparation is used to update the resources of the candidate base station.

[0407] It can be understood that the UE successfully camps on the target base station #1, and the current target base station #1 becomes the source base station. In order to avoid confusion, the names of the base stations are not modified in the following steps.

[0408] In this method, when the target base station #1 obtains the second security capability, it temporarily terminates subsequent LTM switching, decides to configure LTM switching, and interacts with the candidate base station of the target base station #1 and the terminal device to re-perform LTM switching preparation. S717 to S720 are the interaction processes included in the LTM switching preparation.

[0409] S717, the target base station #1 sends a handover request message #2 to the candidate base station of the target base station #1, the handover request message #2 being used to request the candidate base station to prepare resources required for switching, the request message containing the second security capability, the second security capability being used to update the security capability associated with the terminal device saved by the candidate base station. Correspondingly, the candidate base station receives the handover request message #2 from the target base station #1.

[0410] It can also be understood that the trigger condition of S717 is that the target base station #1 receives the second security capability in S713.

[0411] Taking the candidate base stations of the target base station #1 including the source base station and the target base station #2 as an example, the target base station #1 sends the request message #2a and the request message #2b to the source base station and the target base station #2 respectively, as shown in S717a and S717b in FIG. 7.

[0412] For example, the handover request message #2 further includes RRC context information, and the RRC context information includes a security algorithm #4 of the target base station #1, which is the highest priority algorithm selected from the algorithm priority list configured locally by the target base station based on the second security capability.

[0413] For example, the handover request message #2 further includes AS security information.

[0414] For example, the handover request message #2 further includes a first cell list of the candidate base stations.

[0415] For example, the target base station #1 can further configure a second cell list for the candidate base stations. As a possible implementation, the second cell list does not include the cell of the source base station due to the abnormality of the source base station.

[0416] For example, the target base station #1 can carry the second cell list of the corresponding candidate base station in the handover request message #2 of this step, or can carry the second cell list of the corresponding candidate base station in a new message, which is not limited in the present application.

[0417] The handover request response message #1 can include an RRC message container for triggering handover.

[0418] For example, the name of the handover request response message #1 can be Handover request ACK or Handover required ACK, which is not limited.

[0419] S718, the candidate base stations of the target base station #1 send the handover request response message #2 to the target base station #1, and the handover request response message #2 is used to inform the target base station #1 of the handover resources prepared by the candidate base stations. Correspondingly, the target base station #1 receives the handover request response message #2 from the candidate base stations.

[0420] Taking the candidate base stations of the target base station #1 including the source base station and the target base station #2 as an example, the source base station and the target base station #2 send the request response message #2a and the request response message #2b to the target base station #1 respectively, as shown in S718a and S718b in FIG. 7.

[0421] Optionally, the handover request response message #1 includes an RRC message container, and the RRC message includes information (for example, information of resources prepared for handover and security algorithms) that the target base station needs to send to the terminal device. The source base station does not analyze the RRC message container as an intermediate node, and the terminal device receives the RRC message container and analyzes the RRC message container to obtain the corresponding information of the target base station. For example, if the first cell list is included in the handover request message #2, the handover request response message #2 includes the related configuration information of the cells indicated by the first cell list. For another example, the RRC message can also carry the security algorithm #3 of the candidate base station, and the security algorithm #3 is selected from the algorithm priority list configured locally by the candidate base station based on the second security capability selection priority.

[0422] In one implementation, the RRC message must carry the security algorithm #3 of the candidate base station; in another implementation, when the security algorithm #3 of the candidate base station is different from the security algorithm #4 of the target base station #1, the RRC message includes the security algorithm #3 of the candidate base station; and when the security algorithm #3 of the candidate base station is the same as the security algorithm #4 of the target base station #1, the RRC message can not carry the security algorithm #3 of the candidate base station.

[0423] S719, the target base station #1 sends an RRC reconfiguration message to the UE, and the RRC reconfiguration message is used to configure the terminal device with resources prepared for handover by the candidate base station. Correspondingly, the UE receives the RRC reconfiguration message from the target base station #1.

[0424] S720, the UE sends an RRC reconfiguration complete message to the target base station #1. Correspondingly, the target base station #1 receives the RRC reconfiguration complete message from the UE.

[0425] Based on S717 to S720, the following beneficial effects can be achieved: after obtaining the UE security capability saved by the AMF, the target base station #1 re-negotiates the LTM configuration with the candidate base station of the target base station #1, and in the negotiation process, the candidate base station of the target base station #1 can obtain the UE security capability consistent with the AMF, avoiding abnormal event records and alarms on the AMF in the subsequent LTM handover process of the candidate base station of the target base station #1; and the re-selection of the corresponding security algorithm of the base station and the intra-base station handover process in the subsequent LTM handover process are avoided.

[0426] FIG. 8 is a schematic diagram of another communication method proposed in the present application. In this method, in the LTM preparation phase (i.e., the first phase), each target access network device initiated by the source access network device interacts with the AMF to ensure that the target access network device obtains the UE security capability consistent with the AMF, thereby avoiding the problem of increased LTM handover delay caused by unsuccessful UE security capability verification. The method mainly includes the following steps.

[0427] S801, the source access network device sends a handover request message to the target access network device, the handover request message comprising the first security capability. Correspondingly, the target access network device receives the handover request message from the source access network device.

[0428] The first security capability is a security capability associated with the terminal device and saved by the source access network device. It can be understood that the source access network device can send a handover request message to at least one target access network device respectively in this step, and the at least one target access network device is a candidate LTM handover access network device of the terminal device. For example, the at least one target access network device in this embodiment can be the target access network device #1 and the target access network device #2 in FIG. 4.

[0429] It can be understood that the handover request message is used to request the candidate access network device to prepare the resources required for handover. For example, the resources required for handover include a UE aggregate maximum bit rate, a UE associated signalling reference, etc.

[0430] For example, the handover request message comprises identification information of the terminal device.

[0431] For example, the handover request message comprises an RRC context, and the RRC context comprises the first security capability.

[0432] For example, the handover request message further comprises a security algorithm #1, and the security algorithm #1 is an algorithm with the highest priority selected by the source access network device from an algorithm priority list configured locally by the source access network device based on the first security capability.

[0433] S802, the target access network device determines a second security capability according to the first security capability, and the second security capability is a security capability associated with the terminal device and saved by an access and mobility management function.

[0434] Two implementation manners of determining the second security capability according to the first security capability are given below.

[0435] In an implementation, the target access network device sends a first request message to the access and mobility management function, the first request message comprising the first security capability, the first request message being used to request verification of the first security capability. Correspondingly, the access and mobility management function receives the first request message from the target access network device. Then, the access and mobility management function sends a first request response message to the target access network device, and the target access network device correspondingly receives the first request response message from the access and mobility management function, wherein the first request response message comprises the second security capability of the terminal device, or the first request response message does not carry the security capability of the terminal device, and in the case that the first request response message does not carry the security capability of the terminal device, the second security capability is the same as the first security capability.

[0436] It can be understood that the verification of the first security capability here refers to verification of whether the first security capability and the second security capability are the same, and the second security capability is the security capability associated with the terminal device saved by the access and mobility management function.

[0437] In another implementation, the target access network device sends a first request message to the access and mobility management function, the first request message comprising the first security capability, the first request message being used to request the security capability associated with the terminal device saved by the access and mobility management function. Then, the access and mobility management function sends a first request response message to the target access network device, wherein the first request response message comprises the second security capability of the terminal device.

[0438] For example, the target access network device can not save the first security capability first, and then save the determined second security capability.

[0439] For example, the target access network device can save the first security capability first after receiving the first security capability, and then determine whether to update the first security capability to the second security capability based on the above description.

[0440] Optionally, in the above S801 and S802, the switching request message of S801 can carry the identification information of the terminal device, but does not carry the first security capability. Then, the target access network device can request the security capability associated with the terminal device saved by the access and mobility management function in the first request message in S802, and then the access and mobility management function sends the corresponding security capability (i.e. the second security capability) to the target access network device, and the target access network device directly saves the second security capability after receiving the second security capability.

[0441] Optionally, before the target access network device sends the first request message to the access and mobility management function, the method further comprises: the target access network device determines that the current switching is LTM switching.

[0442] For example, the method for determining that the current handover is the LTM handover can be: determined based on the received candidate cell list, or determined based on indication information indicating that the current handover is the LTM handover. In a case where the target access network device determines that the current handover is the LTM handover, the target access network device sends a first request message to the access and mobility management function; in a case where the target access network device determines that the current handover is not the LTM handover, the target access network device does not send the first request message.

[0443] S803, the target access network device determines a security algorithm #4 of the target access network device, the security algorithm #4 being the highest priority algorithm selected from the algorithm priority list locally configured by the target access network device based on the second security capability.

[0444] S804, the target access network device sends a handover request response message to the source access network device, the handover request response message being a response message of the handover request message, the handover request response message being used to indicate a security algorithm required by the target access network device for subsequent communication with the terminal device, wherein the security algorithm required by the target access network device for subsequent communication with the terminal device is the same as the third security algorithm. Correspondingly, the source access network device receives the request response message from the target access network device.

[0445] It can be understood that the handover request response message is also used to notify the target access network device of the resources prepared for the handover.

[0446] In a possible implementation manner, the security algorithm #4 must be carried in the handover request response message. In another possible implementation manner, if the security algorithm #4 is different from the security algorithm #1, the security algorithm #4 is included in the handover request response message, and if the security algorithm #4 is the same as the security algorithm #1, the security algorithm #4 can not be carried.

[0447] Optionally, the handover request response message includes an RRC message container, the RRC message including information (for example, information of the resources prepared for the handover and the security algorithm #4) required to be sent to the terminal device. The source access network device does not analyze the RRC message container as an intermediate node, and the terminal device receives the RRC message container and analyzes the RRC message container to obtain corresponding information.

[0448] Optionally, the method further includes S805 to S808.

[0449] S805, the source access network device sends a message #1 to the terminal device, the message #1 being used to notify the target access network device of the resources prepared for the handover. Correspondingly, the terminal device receives the message #1 from the source access network device.

[0450] For example, the message #1 is an RRC reconfiguration message.

[0451] In an example, the message #1 includes the RRC message container described above.

[0452] It can be understood that after the terminal device synchronizes the security algorithm #4 with the target access network device, the terminal device can use the security algorithm #4 to perform security protection on the communication between the target access network device and the terminal device. For example, the terminal device can use the security algorithm #4 to perform security protection on the message #2 in the subsequent S808.

[0453] S806, the source access network device sends a handover command message to the terminal device, and the handover command message instructs the terminal device to switch to the target access network device. Correspondingly, the terminal device receives the handover command message from the source access network device.

[0454] In an example, before sending the handover command message, the source access network device can determine a target access network device to which the terminal device switches based on the received measurement report.

[0455] S807, the source access network device sends a handover notification message to the target access network device, and the handover notification message is used to inform the target access network device that the source access network device has initiated a handover command to the terminal device. Correspondingly, the target access network device receives the handover notification message from the source access network device.

[0456] S808, the terminal device sends a message #2 to the target access network device, and the message #2 indicates that the terminal device has completed reconfiguration.

[0457] In an example, the message #2 can be an RRC reconfiguration message. The message #2 indicates that the terminal device has successfully switched to the target access network device.

[0458] It can also be understood that after the terminal device successfully switches to the target access network device, S809 and S810 can also be performed.

[0459] S809, the target access network device sends a path switching request message to the access and mobility management function, and the path switching request message is used to trigger the core network to migrate the downlink data of the terminal device to the target access network device. The second security capability is included in the path switching request message.

[0460] S810, the target access network device receives a path switching request response message from the access and mobility management function, and the path switching request response message indicates that the core network has successfully completed the path switching.

[0461] It can be seen that in the handover preparation phase, each target access network device synchronizes the security capability with the access and mobility management function, thereby avoiding the problem of increasing LTM handover delay due to unsuccessful security capability verification in subsequent source access network device handover execution to the target access network device. In addition, in the method, each target access network device interacts with the access and mobility management function to perform UE security capability verification, which does not depend on the verification result of other target access network devices, and can achieve better security protection.

[0462] The complete security algorithm selection process based on LTM handover is given below based on the method shown in FIG. 8, and the specific process is shown in FIG. 9. For ease of understanding, in FIG. 9, the terminal device is taken as UE, the access network device is taken as a base station, and the access and mobility management function is taken as AMF for example. It can be understood that the process described below is only an example for illustration, and the embodiments of the present application are not limited thereto. The method includes the following steps.

[0463] The description of S900 to S902 in FIG. 9 is the same as that of S400 to S402 in FIG. 4, which will not be repeated here.

[0464] S903, the source base station sends a handover request message #1 to the target base station of the source base station, the handover request message #1 is used to trigger the core network to migrate the downlink data path to the target base station #1, and the request message #1 includes the first security capability. Correspondingly, the target base station receives the request message #1 from the source base station.

[0465] Taking the target base station of the source base station as an example, the target base station #1 sends a request message #1a and a request message #1b to the source base station and the target base station #2 respectively, as shown in S903a and S903b in FIG. 9.

[0466] In an example, the handover request message #1 further includes RRC context information, and the RRC context information includes a security algorithm #1, which is the highest priority algorithm selected by the source base station from the algorithm priority list configured locally by the source base station based on the first security capability.

[0467] In an example, the handover request message #1 includes AS security information.

[0468] In an example, the source base station can also configure a first cell list for the target base station through the request message #1. In an example, the source base station can also configure a second cell list for the target base station. The description of the first cell list and the second cell list is the same as that in S403 in FIG. 4, which will not be repeated here. The source base station can carry the second cell list in the request message of this step, or can carry the second cell list in a new message, which is not limited by the present application.

[0469] S904, the target base station of the source base station sends a request message #2 to the AMF. Correspondingly, the AMF receives the request message #2 from the source base station.

[0470] Taking the target base station of the source base station including the target base station #1 and the target base station #2 as an example, the target base station #1 and the target base station #2 respectively send a request message #2a and a request message #2b to the AMF, see S904a and S904b in FIG. 9.

[0471] Two implementation manners of the request message #2 are exemplarily given below.

[0472] Implementation manner one: the request message #2 is used to request to determine whether the first security capability on the target base station is consistent with the second security capability on the AMF, and the request message #2 includes the first security capability.

[0473] Implementation manner two: the request message #2 is used to request the security capability saved by the AMF.

[0474] It can be understood that the trigger condition of S904 is S903, that is, the target base station receives the first security capability sent by the source base station.

[0475] S905, the AMF sends a request response message #2 to the target base station of the source base station. Correspondingly, the target base station of the source base station receives the request response message #2 from the AMF.

[0476] Taking the target base station of the source base station including the target base station #1 and the target base station #2 as an example, the AMF respectively sends a request response message #2a and a request response message #2b to the target base station #1 and the target base station #2, see S905a and S905b in FIG. 9.

[0477] Two implementation manners of the request response message #2 are exemplarily given below.

[0478] Corresponding to the implementation manner one: the AMF checks whether the first security capability is consistent with the second security capability, and carries the second security capability in the request response message #2 in the case of inconsistency, or carries ACK in the request response message #2 in the case of consistency, or the request response message #2 is an ACK message, without limitation. If the target base station receives the second security capability, the second security capability is updated and stored.

[0479] Corresponding to the implementation manner two: the AMF carries the second security capability in the request response message #2. The target base station checks whether the first security capability is consistent with the second security capability, and updates the stored second security capability in the case of inconsistency. Alternatively, the target base station does not perform the checking, and directly updates to the second security capability.

[0480] Based on S904 and S905, the following beneficial effects can be brought about: As can be seen, in the method shown in FIG. 4, the security capability verification is performed in the path switching process in the LTM switching execution stage, which is equivalent to post-verification. In this embodiment, the security capability verification is performed in the LTM switching preparation stage, which is equivalent to verifying in advance, thereby ensuring that the target base station can select a suitable security algorithm in the switching preparation stage, for the security protection of subsequent messages between the UE and the base station. In addition, in this method, each target base station interacts with the AMF to perform security capability verification, which does not depend on the verification results of other target base stations, and can achieve better security protection.

[0481] S906, the target base station of the source base station sends a handover request response message #1 to the source base station, and the handover request response message #1 is used to notify the source base station of the handover resources prepared by the target base station. Correspondingly, the source base station receives the request response message #1 from the target base station.

[0482] Taking the target base station including the target base station #1 and the target base station #2 as an example, the target base station #1 and the target base station #2 respectively send a request response message #1a and a request response message #1b to the AMF, as shown in S906a and S906b in FIG. 9.

[0483] For example, the request response message #1 further includes a security algorithm required by each target base station for subsequent information protection with the UE. The following illustrates how to select the security algorithm based on the above-mentioned implementation mode one and implementation mode two.

[0484] Corresponding to the implementation mode one

[0485] If the second security capability is included in the handover request response message #1, each target base station selects a security algorithm with the highest priority from the algorithm priority list configured locally by the target base station based on the second security capability, denoted as security algorithm #4, and if the second security capability is not included, each target base station selects a security algorithm with the highest priority from the first security capability based on the algorithm priority list configured locally by the target base station.

[0486] In one possible implementation mode, the security algorithm #4 must be carried in the handover request response message #1. In another possible implementation mode, if the security algorithm #4 is different from the security algorithm #1, the security algorithm #4 is included in the handover request response message #1, and if the security algorithm #4 is the same as the security algorithm #1, the security algorithm #4 can not be carried.

[0487] Corresponding to the implementation mode two

[0488] If the first security capability is consistent with the second security capability, each target base station selects a security algorithm with the highest priority from an algorithm priority list of the target base station locally configured based on the first security capability, and the security algorithm is recorded as security algorithm #2. It can be understood that the security algorithm #2 is the same as the security algorithm #4 when the first security capability is consistent with the second security capability.

[0489] Optionally, the handover request response message #1 includes an RRC message container, and the RRC message includes information (for example, information of resources prepared for handover and the security algorithm #4) required to be sent to the terminal device. The source base station does not analyze the RRC message container as an intermediate node, and the terminal device receives the RRC message container and analyzes the RRC message container to obtain corresponding information.

[0490] S907, the source base station sends an RRC reconfiguration message to the UE, and the RRC reconfiguration message includes the RRC message container of each target base station in S906. Correspondingly, the UE receives the RRC reconfiguration message from the source base station, analyzes the RRC message container, and saves the configuration of each target base station.

[0491] For example, all target base stations can carry RRC messages through one RRC reconfiguration message, or each target base station can carry an RRC message through multiple RRC reconfiguration messages, which is not limited.

[0492] S908, the UE sends an RRC reconfiguration complete message to the source base station. Correspondingly, the source base station receives the RRC reconfiguration complete message from the UE.

[0493] S909, the UE sends a measurement report #2 to the source base station. Correspondingly, the source base station receives the measurement report #2 from the UE.

[0494] The measurement report #2 includes the measurement result of the target base station of the source base station, the source base station decides to start LTM handover, and determines to hand over to the target base station #1 based on the measurement report #2.

[0495] S910, the source base station sends a cell switch command (LTM Cell Switch Command) message to the UE, and the cell switch command message includes the configuration index of the target base station #1. Correspondingly, the UE receives the cell switch command message from the source base station, and the UE determines the configuration of the target base station #1 according to the configuration index of the target base station #1.

[0496] Here, the configuration of the target base station #1 can be understood as the configuration obtained by analyzing the RRC message container in S907.

[0497] For example, the cell switch command message is a MAC CE message.

[0498] S911, the source base station sends a handover notification message to the target base station #1, for informing the target base station #1 that the cell handover command has been initiated to the UE.

[0499] S912, optionally, if the handover needs to perform a random access procedure, the UE performs a random access procedure with the target base station #1.

[0500] S913, the UE sends a reconfiguration complete message to the target base station #1. Correspondingly, the target base station #1 receives the RRC reconfiguration complete message from the UE.

[0501] It can be understood that after S913, the UE and the target base station #1 can normally communicate based on the security algorithm carried in the RRC message in S906.

[0502] S914, the target base station #1 sends a path switch request message to the AMF, the request message being used to trigger the core network to migrate the downlink data path to the target base station #1, wherein the path switch request message includes the second security capability. Correspondingly, the AMF receives the path switch request message from the target base station #1.

[0503] S915, the AMF sends a path switch request response message to the target base station #1, the path switch request response message indicating that the core network has successfully completed the path switch. Correspondingly, the target base station #1 receives the path switch request response message from the AMF.

[0504] It can be understood that before replying to the response message, the AMF needs to check whether the locally stored second security capability and the received security capability from the target base station #1 match, and if not, the response message carries the second security capability. In addition, in the case of mismatch, the AMF will also record the event and may take additional measures, such as generating an alarm. Since the target base station #1 has obtained the security capability consistent with the AMF in S905, the security capability check on the AMF will be successful, thereby avoiding the generation of abnormal event records and alarms on the AMF in the target base station #1 during the LTM handover process, and also avoiding the reselection of corresponding security algorithms and the intra-base station handover process in the target base station #1 during the LTM handover process.

[0505] S916, optionally, the target base station #1 sends a message F to the candidate base station of the target base station #1, the message F being used for updating the security key for subsequent LTM handover, the message F carrying a key and an NCC, wherein the key is used for security protection of messages between the UE and the candidate base station, and the NCC is used to determine the derivation mode of the key. Correspondingly, the candidate base station receives the message F from the target base station #1.

[0506] For example, the target base station #1 can determine the corresponding candidate base station based on the second cell list (i.e., the candidate cell list) of the target base station #1 acquired in S903. Here, the candidate base station of the target base station #1 includes the source base station and the target base station #2, and the target base station #1 sends a message F to the source base station and the target base station #2 respectively, as shown in S916a and S916b in FIG. 9.

[0507] For example, the message F is an Xn message.

[0508] S917, the UE successfully camps on the target base station #1, and the target base station #1 repeats S909 to S916.

[0509] It can be understood that after the UE successfully camps, the target base station #1 becomes the source base station. In order to avoid confusion, the names of the base stations in the subsequent steps are not modified. The target base station #1 repeats S909 to S916, and the corresponding description is specifically described in S619 to S622 in FIG. 6, which will not be repeated here.

[0510] It can be understood that the above steps in the above figures are only exemplary and are not strictly limited. In addition, the size of the serial number of the above processes does not mean the order of execution, and the execution order of the processes should be determined according to its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0511] It can also be understood that some optional features in the embodiments of the present application can not depend on other features in some scenarios, or can be combined with other features in some scenarios, without limitation.

[0512] It can also be understood that the methods and operations implemented by the communication device (such as the target access network device, and the terminal device) in the above method embodiments can also be implemented by the components of the device, such as chips or circuits, without limitation.

[0513] The above describes the method embodiments provided by the present application in combination with FIG. 1 to FIG. 9, and the device embodiments of the present application will be described in combination with FIG. 10 and FIG. 11. It can be understood that in order to realize the functions in the above embodiments, the device in FIG. 10 and FIG. 11 includes the corresponding hardware structure and / or software module for executing each function. Those skilled in the art should easily realize that the units and method steps described in combination with the embodiments disclosed in the present application can be realized in the form of hardware or hardware and computer software. It can be understood that the technical features described in the above method embodiments are also applicable to the following device embodiments.

[0514] FIG. 10 and FIG. 11 are structural diagrams of possible apparatuses provided by embodiments of the present application. The apparatuses can be used to implement the functions of the target access network device or the terminal device in the above method embodiments, and thus can achieve the beneficial effects of the above method embodiments.

[0515] FIG. 10 is a schematic block diagram of a communication apparatus 1000 provided by an embodiment of the present application. As shown in FIG. 10, the apparatus 1000 can include a communication unit 1010 and a processing unit 1020. The communication unit 1010 can communicate with an external device, and the processing unit 1020 can perform data processing. The communication unit 1010 can also be referred to as a communication interface or a transceiver unit.

[0516] In a possible design, the apparatus 1000 can implement the steps or processes performed by the target access network device in the above method embodiments, where the processing unit 1020 is configured to perform processing-related operations of the target access network device in the above method embodiments, and the communication unit 1010 is configured to perform transmission-related operations of the target access network device in the above method embodiments.

[0517] In another possible design, the apparatus 1000 can implement the steps or processes performed by the terminal device in the above method embodiments, where the communication unit 1010 is configured to perform receiving-related operations of the terminal device in the above method embodiments, and the processing unit 1020 is configured to perform processing-related operations of the terminal device in the above method embodiments.

[0518] It can be understood that the apparatus 1000 is in the form of functional units here. The term “unit” can refer to an application specific integrated circuit (ASIC), an electronic circuit, a processor (shared, dedicated or group) and memory for executing one or more software or firmware programs, a baseband processor or a combination thereof, and other suitable components for performing the functions described. In an optional example, those skilled in the art can understand that the apparatus 1000 can be specifically the target access network device in the above embodiments, and can be used to perform the processes and / or steps corresponding to the target access network device in the above method embodiments. Alternatively, the apparatus 1000 can be specifically the terminal device in the above embodiments, and can be used to perform the processes and / or steps corresponding to the terminal device in the above method embodiments. To avoid repetition, details are not described here.

[0519] The apparatus 1000 of each of the above-mentioned solutions has a function of implementing the corresponding steps performed by the target access network device in the above-mentioned methods, or the apparatus 1000 of each of the above-mentioned solutions has a function of implementing the corresponding steps performed by the terminal device in the above-mentioned methods. The functions can be implemented by hardware, or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above-mentioned functions; for example, the communication unit can be replaced by a transceiver (for example, the sending unit in the communication unit can be replaced by a transmitter, and the receiving unit in the communication unit can be replaced by a receiver), and other units such as the processing unit can be replaced by a processor, which respectively performs the transceiving operations and related processing operations in each method embodiment.

[0520] In addition, the communication unit can also be a transceiving circuit (for example, can include a receiving circuit and a sending circuit), and the processing unit can be a processing circuit. In embodiments of the present application, the apparatus in FIG. 10 can be a terminal device or a target access network device in the foregoing embodiments, or can be a chip or a chip system, for example, a system on chip (SoC). The communication unit can be an input / output circuit, a communication interface; and the processing unit can be a processor or a microprocessor integrated on the chip or an integrated circuit. In this regard, no limitation is made.

[0521] FIG. 11 is a schematic block diagram of a communication apparatus 1100 provided by embodiments of the present application. The apparatus 1100 includes a processor 1110 and a transceiver 1120. The processor 1110 and the transceiver 1120 communicate with each other through an internal connection path. The processor 1110 is configured to execute instructions to control the transceiver 1120 to send and / or receive signals.

[0522] Optionally, the apparatus 1100 can further include a memory 1130, which communicates with the processor 1110 and the transceiver 1120 through an internal connection path. The memory 1130 is configured to store instructions, and the processor 1110 can execute the instructions stored in the memory 1130. In a possible implementation, the apparatus 1100 is configured to implement the corresponding processes and steps of the target access network device in the above-mentioned method embodiments. In another possible implementation, the apparatus 1100 is configured to implement the corresponding processes and steps of the terminal device in the above-mentioned method embodiments.

[0523] Optionally, the memory 1130 can be integrated in the processor 1110.

[0524] In a possible scenario, the apparatus 1100 includes at least one processor integrated with a memory, and other memories in addition to the memory integrated on the processor.

[0525] It can be understood that the apparatus 1100 can be specifically the target access network device or the terminal device in the above embodiments, and can also be a chip or a chip system. Correspondingly, the transceiver 1120 can be a transceiver circuit of the chip, which is not limited here. Specifically, the apparatus 1100 can be used to execute various steps and / or processes in the above method embodiments corresponding to the target access network device or the terminal device.

[0526] Optionally, the memory 1130 can include read-only memory and random access memory, and provide instructions and data for the processor. The memory can include non-volatile random access memory. For example, the memory can also store device type information. The processor 1110 can be used to execute the instructions stored in the memory, and when the processor 1110 executes the instructions stored in the memory, the processor 1110 is used to execute various steps and / or processes of the above method embodiments corresponding to the target access network device or the terminal device.

[0527] In the implementation process, the steps of the above method can be completed by the integrated logic circuit of hardware in the processor or the instructions in the form of software. The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as hardware processor execution completion, or executed by a combination of hardware and software modules in the processor. The software module can be located in a mature storage medium in the field, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, register, etc. The storage medium is located in the memory, and the processor reads the information in the memory, and combines the hardware to complete the steps of the above method. To avoid repetition, it will not be described in detail here.

[0528] It should be noted that the processor in the embodiments of the present application can be an integrated circuit chip with a signal processing capability. In the implementation process, the steps of the above method embodiments can be completed by the integrated logic circuit or the software form of instructions in the processor. The processor mentioned above can be a general purpose processor, a digital signal processor (DSP), an ASIC, a field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. The processor in the embodiments of the present application can implement or execute the disclosed methods, steps and logic block diagrams in the embodiments of the present application. The general purpose processor can be a microprocessor or the processor can also be any conventional processor or the like. The steps of the method disclosed in conjunction with the embodiments of the present application can be directly embodied as a hardware code processor for execution, or be executed by a combination of hardware and software modules in the code processor. The software module can be located in a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register or other mature storage medium in the art. The storage medium is located in the storage, and the processor reads the information in the storage, and combines the hardware to complete the steps of the above method.

[0529] It is to be understood that the memory in the embodiments of the present application can be a volatile memory or a nonvolatile memory, or can include both volatile and nonvolatile memory. Among them, the nonvolatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically EPROM (EEPROM), or a flash memory. The volatile memory can be a random access memory (RAM) used as an external cache. By way of example, and not limitation, many forms of RAM can be used, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous dynamic RAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM). It should be noted that the memory of the system and method described herein is intended to include, but not be limited to, these and any other suitable types of memory.

[0530] Optionally, the memory (e.g. 1130) in the embodiments of the present application can be integrated in the processor (e.g. 1110).

[0531] In addition, the present application also provides a computer readable storage medium, the computer readable storage medium stores computer instructions, when the computer instructions run on the computer, the operations and / or processes performed by the target access network device / first access network device or terminal device in the method embodiments of the present application are executed.

[0532] The present application also provides a computer program product, the computer program product includes computer program code or instructions, when the computer program code or instructions run on the computer, the operations and / or processes performed by the target access network device / first access network device or terminal device in the method embodiments of the present application are executed.

[0533] Further, the present application also provides a chip, which comprises a processor. A memory for storing a computer program is arranged independently of the chip, and the processor is configured to execute the computer program stored in the memory, so that the operations and / or processes performed by the target access network device / first access network device or the terminal device in any one of the method embodiments are performed.

[0534] Further, the chip can further comprise a communication interface. The communication interface can be an input / output interface, an interface circuit or the like. Further, the chip can further comprise a memory.

[0535] Further, the present application also provides a communication system comprising the target access network device / first access network device and the terminal device in the embodiments of the present application.

[0536] It should also be noted that the memory described herein is intended to include, but not limited to, these and any other suitable types of memory.

[0537] Those skilled in the art can appreciate that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be realized in electronic hardware or in a combination of computer software and electronic hardware. Whether the functions are realized in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to realize the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application. Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described system, device and unit can refer to the corresponding processes in the foregoing method embodiments, which will not be described here. In several embodiments provided in the present application, it should be understood that the disclosed system, device and method can be implemented in other ways. For example, the above-described device embodiments are only schematic, for example, the division of the units is only a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some interface, device or unit, and can be electrical, mechanical or other forms. The units described as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, that is, they can be located in one place, or can be distributed on a plurality of network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the embodiment. In addition, each functional unit in the embodiments of the present application can be integrated in one processing unit, or each unit can be physically present, or two or more units can be integrated in one unit.

[0538] If the functions are realized in the form of software function units and sold or used as independent products, they can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application or the essential part of the prior art or the part of the technical solutions can be embodied in the form of a software product, which is stored in a storage medium and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in the embodiments of the present application. The foregoing storage medium includes: U disk, mobile hard disk, ROM, RAM, magnetic disk or optical disk and various program code storage media.

[0539] It is to be understood that the terminology "embodiment", used throughout this specification, means a specific feature, structure, or characteristic including an embodiment to which the application pertains. Therefore, throughout the specification, embodiments can refer to different embodiments. Moreover, these features, structures, or characteristics can be combined in any suitable manner in one or more embodiments.

[0540] It is also to be understood that, in this application, "when", "if", and "provided that" refer to objective conditions under which the network element will make corresponding processing, and are not limited in time, nor do they require the network element to have a judgment action when implemented, nor do they mean that there are other limitations.

[0541] It is also to be understood that, in each embodiment of the application, "A corresponding B" means that B is associated with A, and B can be determined according to A. However, it is also to be understood that determining B according to A does not mean that B is determined only according to A, but B can also be determined according to A and / or other information.

[0542] The above merely illustrates the specific embodiments of the application, but the protection scope of the application is not limited thereto, and any person skilled in the art can easily think of changes or replacements within the technical scope disclosed by the application, which should be covered within the protection scope of the application. Therefore, the protection scope of the application should be subject to the protection scope of the claims.

Claims

1. A communication method, the method being applied to a target access network device, characterized in that, The method comprises: receiving a first handover request message from a source access network device, the first handover request message comprising a first security capability of a terminal device; determining a second security algorithm of the target access network device, the second security algorithm being a highest priority algorithm selected from a locally configured algorithm priority list of the target access network device based on the first security capability; using the second security algorithm to secure communications between the target access network device and the terminal device; sending a first path handover request message to an access and mobility management function, the first path handover request message being used to trigger the core network to migrate downlink data of the terminal device to the target access network device, the first path handover request message comprising the first security capability; receiving a first path handover request response message from the access and mobility management function, the first path handover request response message indicating that the core network has successfully completed path handover, the first path handover request response message comprising a second security capability, the second security capability being different from the first security capability; sending a first message to a candidate access network device, the first message comprising the second security capability, the second security capability being used to update a security capability associated with the terminal device saved by the candidate access network device, the candidate access network device being an L1 / L2 triggered mobility LTM handover access network device candidate for the terminal device.

2. The method of claim 1, wherein, The method further comprises: determining a third security algorithm of the target access network device, the third security algorithm being a highest priority algorithm selected from a locally configured algorithm priority list of the target access network device based on the second security capability; in a case where the third security algorithm is different from the second security algorithm, sending a second message to the terminal device, the second message comprising the third security algorithm; using the third security algorithm to secure communications between the target access network device and the terminal device.

3. The method according to claim 1 or 2, characterized in that, The method further comprises: receiving a first candidate cell list from the source access network device, the first candidate cell list indicating at least one cell; determining the candidate access network device based on the first candidate cell list, the candidate access network device being an access network device associated with the at least one cell.

4. The method according to any one of claims 1 to 3, characterized in that, The first handover request message is used to request resources required by the target access network device for preparation of handover, and the method further comprises: sending a first handover request response message to the source access network device, the first handover request response message being used to inform the target access network device of resources prepared for handover.

5. The method of claim 4, wherein, The first handover request message further comprises a first security algorithm, in a case where the second security algorithm is different from the first security algorithm, the first handover request response message comprises the second security algorithm.

6. The method according to any one of claims 1 to 5, characterized in that, The method further comprises: receiving a first handover notification message from the source access network device, the first handover notification message being used to inform the source access network device that a handover command has been initiated to the terminal device; receiving a third message from the terminal device, the third message indicating that the terminal device has completed reconfiguration, wherein the third message is secured by using the second security algorithm.

7. The method according to any one of claims 1 to 6, characterized in that, The method further includes: receiving a fourth message from the candidate access network device, the fourth message including a fourth security algorithm of the candidate access network device, the fourth security algorithm being a highest priority algorithm selected from a local algorithm priority list of the candidate access network device based on the second security capability.

8. The method of claim 7, wherein, The method further includes: sending a fifth message to the terminal device, the fifth message including the fourth security algorithm, the fourth security algorithm being used to update a security algorithm for securing communication between the candidate access network device and the terminal device; receiving a sixth message from the terminal device, the sixth message being a response message to the fifth message.

9. The method of claim 8, wherein, The fifth message further includes identification information of the candidate access network device, the identification information of the candidate access network device being associated with the fourth security algorithm, or, The fifth message further includes identification information of a cell associated with the candidate access network device, the identification information of the cell associated with the candidate access network device being associated with the fourth security algorithm.

10. The method according to claim 8 or 9, characterized in that, After the receiving the sixth message from the terminal device, the method further includes: sending a second handover command message to the terminal device, the second handover command message instructing the terminal device to hand over to a first access network device, the first access network device being one of the candidate access network devices; sending a second handover notification message to the first access network device, the second handover notification message being used to inform the first access network device that the target access network device has initiated a handover command to the terminal device.

11. The method of claim 10, wherein, The method further includes: sending a second path switch request message to an access and mobility management function, the second path switch request message being used to trigger the core network to migrate downlink data of the terminal device to the first access network device, the second path switch request message including the second security capability; receiving a second path switch request response message from the access and mobility management function, the second path switch request response message indicating that the core network has successfully completed path switching.

12. The method of claim 8 or 9, wherein, The first message is a second handover request message, the first message being used to request resources needed for handover preparation, the fourth message is a second handover request response message, the second handover request response message being used to inform the candidate access network device of resources prepared for handover, and the fifth message is a radio resource control (RRC) reconfiguration message, the RRC reconfiguration message being used to configure the terminal device with resources prepared for handover by the candidate access network device.

13. The method of claim 12, wherein, The method further includes: sending a second candidate cell list to the candidate access network device, the second candidate cell list indicating at least one cell, the at least one cell being associated with at least one access network device, the at least one access network device being a candidate access network device for subsequent handover by the candidate access network device.

14. The method of claim 13, wherein, The cell associated with the source access network device is not included in the second candidate cell list.

15. The method according to any one of claims 1 to 14, characterized in that, The method further includes: updating the first security capability to a second security capability of the terminal device.

16. A communication method, the method being applied to a terminal device, characterized by, comprising: receiving a first handover command message from a source access network device, the first handover command message indicating the terminal device to hand over to a target access network device; sending a third message to the target access network device, the third message indicating that the terminal device has completed reconfiguration; receiving a fifth message from the target access network device, the fifth message including a fourth security algorithm of a candidate access network device of the target access network device, the fourth security algorithm being different from a fifth security algorithm of the candidate access network device, the fifth security algorithm being a security algorithm saved by the terminal device for securing communication between the candidate access network device and the terminal device, the candidate access network device being an L1 / L2 triggered mobility (LTM) handover access network device candidate for the terminal device; updating the fifth security algorithm to the fourth security algorithm; sending a sixth message to the target access network device, the sixth message being a response message of the fifth message.

17. The method of claim 16, wherein: the fifth message further includes identification information of the candidate access network device, the identification information of the candidate access network device being associated with the fourth security algorithm, or, the fifth message further includes identification information of a cell associated with the candidate access network device, the identification information of the cell associated with the candidate access network device being associated with the fourth security algorithm.

18. The method according to claim 16 or 17, characterized in that, After the sending of the sixth message to the target access network device, the method further includes: receiving a second handover command message from the target access network device, the second handover command message indicating the terminal device to hand over to a first access network device, the first access network device being one of the candidate access network devices; sending an eighth message to the first access network device, the eighth message indicating that the terminal device has completed reconfiguration.

19. The method of claim 16 or 17, wherein, The fifth message is a radio resource control (RRC) reconfiguration message, the RRC reconfiguration message being used to reconfigure the terminal device with resources prepared by the candidate access network device for handover.

20. The method of any one of claims 16-19, wherein, Before the receiving of the first handover command message from the source access network device, the method further includes: receiving a seventh message from the source access network device, the seventh message being used to configure the terminal device with resources prepared by the target access network device and the candidate access network device for handover.

21. A communication method, the method being applied to a target access network device, characterized in that, comprising: receiving a handover request message from a source access network device, the handover request message including a first security capability of a terminal device; determining a second security capability according to the first security capability, the second security capability being a security capability associated with the terminal device and saved by an access and mobility management function; determining a third security algorithm of the target access network device, the third security algorithm being a highest priority algorithm selected from a local algorithm priority list of the target access network device based on the second security capability. sending a handover request response message to the source access network device, the handover request response message being a response message of the handover request message, the handover request response message being used to indicate a security algorithm required to be used by the target access network device for subsequent communication with the terminal device, wherein the security algorithm required to be used is the same as the third security algorithm.

22. The method of claim 21, wherein, The method further comprises: sending a first request message to an access and mobility management function, the first request message comprising the first security capability, the first request message being used to request verification of the first security capability; receiving a first request response message from the access and mobility management function, wherein the first request response message comprises a second security capability of the terminal device.

23. The method of claim 21, wherein, The method further comprises: sending a first request message to an access and mobility management function, the first request message comprising the first security capability, the first request message being used to request verification of the first security capability; receiving a first request response message from the access and mobility management function, the first request response message not carrying a security capability of the terminal device, and in the case that the first request response message does not carry the security capability of the terminal device, the second security capability is the same as the first security capability.

24. A communication method, the method being applied to a target access network device, the method comprising: The method further comprises: receiving a handover request message from a source access network device, the handover request message comprising identification information of a terminal device; sending a first request message to an access and mobility management function, the first request message being used to request a security capability associated with the terminal device and saved by the access and mobility management function; receiving a first request response message from the access and mobility management function, the first request response message comprising a second security capability of the terminal device; determining a third security algorithm of the target access network device, the third security algorithm being a highest-priority algorithm selected from a list of algorithm priorities configured locally by the target access network device based on the second security capability; sending a handover request response message to the source access network device, the handover request response message being a response message of the handover request message, the handover request response message being used to indicate a security algorithm required to be used by the target access network device for subsequent communication with the terminal device, the security algorithm required to be used being the same as the third security algorithm.

25. The method of any one of claims 21-24, wherein, Before the method further comprises: determining that the current handover is an LTM handover.

26. The method of claim 25, wherein, The method further comprises: receiving a candidate cell list from the source access network device, the candidate cell list indicating at least one cell, the at least one cell being associated with at least one access network device, the at least one access network device being a candidate access network device for subsequent handover by the target access network device; The method further comprises: determining that the current handover is an LTM handover based on the candidate cell list.

27. The method of claim 25, wherein, The method further comprises: receiving a first message, the first message indicating that the current handover is an LTM handover; the determining that the current handover is an LTM handover comprises: determining that the current handover is an LTM handover based on the candidate cell list.

28. The method of any one of claims 21-27, wherein, The handover request message is used to request the target access network device to prepare the resources required for handover, and the handover request response message is used to inform the target access network device of the resources prepared for handover.

29. The method of any one of claims 21-28, wherein, The handover request message further comprises a first security algorithm, In the case where the third security algorithm is different from the first security algorithm, the handover request response message further comprises the third security algorithm; Or, In the case where the third security algorithm is the same as the first security algorithm, the handover request response message does not carry the third security algorithm.

30. The method of any one of claims 21-29, wherein, The method further comprises: receiving a handover notification message from the source access network device, the handover notification message being used to inform the source access network device that the handover command has been initiated to the terminal device; receiving a second message from the terminal device, the second message indicating that the terminal device has completed reconfiguration.

31. The method of claim 30, wherein, The method further comprises: sending a path handover request message to an access and mobility management function, the path handover request message being used to trigger the core network to migrate the downlink data of the terminal device to the target access network device, and the path handover request message comprising the second security capability; receiving a path handover request response message from the access and mobility management function, the path handover request response message indicating that the core network has successfully completed the path handover.

32. A communications device, characterized by comprise a module or unit for performing the method of any one of claims 1 to 15; or comprise a module or unit for performing the method of any one of claims 16 to 20; or comprise a module or unit for performing the method of any one of claims 21 to 31.

33. A communications device, characterized by comprise a processor configured to cause the communication apparatus to perform the method of any one of claims 1 to 15; or configured to cause the communication apparatus to perform the method of any one of claims 16 to 20; or configured to cause the communication apparatus to perform the method of any one of claims 21 to 31.

34. A computer-readable storage medium, characterized in that, The computer readable storage medium has stored thereon a computer program or instructions, which, when executed on a communication apparatus, cause the communication apparatus to perform the method of any one of claims 1 to 15; or cause the communication apparatus to perform the method of any one of claims 16 to 20; or cause the communication apparatus to perform the method of any one of claims 21 to 31.

35. A computer program product, characterised in that, The computer program product comprises a computer program or instructions, which, when executed on a communication apparatus, cause the communication apparatus to perform the method of any one of claims 1 to 15; or cause the communication apparatus to perform the method of any one of claims 16 to 20; or cause the communication apparatus to perform the method of any one of claims 21 to 31.

Citation Information

Patent Citations

  • Security processing method and device, equipment and storage medium

    CN110167078A

  • Method, user equipment and storage medium for layer 1 / layer 2 triggered mobility

    CN118450453A

  • Communication method and related apparatus

    WO2024120500A1