Network switching method, terminal, and network side device
By adding a randomness parameter to determine the key during network handover, the communication security problem caused by the source network device knowing the key is solved, one-hop forward security is achieved, and the communication security between the target network device and the terminal is improved.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- VIVO MOBILE COMM CO LTD
- Filing Date
- 2025-11-07
- Publication Date
- 2026-05-15
AI Technical Summary
In existing technologies, when switching networks, the source network device knows the key of the target network device, which allows attackers to obtain the communication content between the target network device and the terminal, affecting communication security.
During network handover, an additional first parameter is added to determine the key between the second network device and the terminal after the handover. This ensures that even if the first network device is compromised, attackers cannot obtain the second key. By adding randomness parameters such as RAPID, TA index value, and uplink authorization to the key derivation process on the terminal or network device side, communication security is improved.
It achieves one-hop forward security, enhances the communication security between target network devices and terminals, and prevents communication content from being exposed.
Smart Images

Figure CN2025133226_15052026_PF_FP_ABST
Abstract
Description
Network handover methods, terminals, and network-side equipment
[0001] Cross-reference to related applications
[0002] This application claims priority to Chinese Patent Application No. 202411593790.9, filed on November 8, 2024, entitled "Method, Terminal and Network Side Device for Network Switching", the entire contents of which are incorporated herein by reference. Technical Field
[0003] This application belongs to the field of communication technology, and specifically relates to a network switching method, terminal, and network-side equipment. Background Technology
[0004] In network handover (such as Xn handover) schemes provided in related technologies, the source network device (such as a base station) usually derives the key to be used after the handover for the target network device, that is, the source network device knows the key of the target network device.
[0005] In this situation, since the source network device knows the key used by the target network device, once the source network device is compromised, the attacker can obtain the key used by the target network device, thereby exposing the communication content between the target network device and the terminal and affecting the communication security between the target network device and the terminal. Summary of the Invention
[0006] This application provides a method, terminal, and network-side device for network switching, which can improve the communication security between the target network device and the terminal after switching in network switching scenarios and prevent the communication content between the target network device and the terminal from being exposed.
[0007] In a first aspect, a network switching method is provided, applied to a scenario where a terminal switches from a first network device to a second network device. The method includes: the terminal receiving a first key derivation instruction from the first network device; the terminal determining a first key based on the first key derivation instruction; and the terminal determining a second key based on the first key and a first parameter, wherein the second key is used for communication between the terminal and the second network device.
[0008] Secondly, a network switching method is provided, applied to a scenario where a terminal switches from a first network device to a second network device. The method includes: the second network device receiving a switching request message from the first network device, the switching request message including a first key; the second network device determining a second key based on the first key and a first parameter, the second key being used for communication between the terminal and the second network device.
[0009] Thirdly, a network handover method is provided, applicable to a scenario where a terminal switches from a first network device to a second network device. The method includes: before the terminal switches to the second network device, the second network device sends a first request message to a core network device, the first request message being used to request key parameters; the second network device receives a first response message from the core network device, the first response message including the key parameters; the second network device determines a first key based on the key parameters, the first key being used for communication between the terminal and the second network device.
[0010] Fourthly, a network handover method is provided, applied to a scenario where a terminal switches from a first network device to a second network device. The method includes: the first network device sending a handover request message to the second network device, the handover request message including a first key deduction indication, wherein the first key deduction indication is determined based on a second key deduction indication currently stored by the first network device; the first network device receiving a handover response message from the second network device; wherein the handover response message corresponds to the handover request message and includes the first key deduction indication.
[0011] Fifthly, a network switching apparatus is provided, applied to a scenario where a terminal switches from a first network device to a second network device. The apparatus includes: a transmission module for receiving a first key derivation instruction from the first network device; and a processing module for determining a first key based on the first key derivation instruction, and determining a second key based on the first key and a first parameter, wherein the second key is used for communication between the terminal and the second network device.
[0012] In a sixth aspect, a network switching apparatus is provided, applied to a scenario where a terminal switches from a first network device to a second network device. The apparatus includes: a transmission module for receiving a switching request message from the first network device, the switching request message including a first key; and a processing module for determining a second key based on the first key and a first parameter, the second key being used for communication between the terminal and the second network device.
[0013] In a seventh aspect, a network switching apparatus is provided, applied to a scenario where a terminal switches from a first network device to a second network device. The apparatus includes: a transmission module, configured to send a first request message to a core network device before the terminal switches to the second network device, the first request message being used to request key parameters; the transmission module is further configured to receive a first response message from the core network device, the first response message including the key parameters; and a processing module, configured to determine a first key based on the key parameters, the first key being used for communication between the terminal and the second network device.
[0014] Eighthly, a network handover apparatus is provided, applied to a scenario where a terminal switches from a first network device to a second network device. The apparatus includes: a sending module, configured to send a handover request message to the second network device, the handover request message including a first key deduction indication, wherein the first key deduction indication is determined based on a second key deduction indication currently stored in the first network device; and a receiving module, further configured to receive a handover response message from the second network device; wherein the handover response message corresponds to the handover request message and includes the first key deduction indication.
[0015] A ninth aspect provides a network switching apparatus configured to perform the steps of the method described in the first aspect, or implement the steps of the method described in the second aspect, or implement the steps of the method described in the third aspect, or implement the steps of the method described in the fourth aspect.
[0016] In a tenth aspect, a terminal is provided, the terminal including a processor and a memory, the memory storing a program or instructions executable on the processor, the program or instructions, when executed by the processor, implementing the steps of the method as described in the first aspect.
[0017] Eleventhly, a terminal is provided, including a processor and a communication interface, wherein the communication interface is used to receive a first key derivation instruction from a first network device, the processor is used to determine a first key according to the first key derivation instruction, and to determine a second key according to the first key and a first parameter, the second key being used for communication between the terminal and the second network device.
[0018] In a twelfth aspect, a network-side device is provided, the network-side device including a processor and a memory, the memory storing a program or instructions executable on the processor, the program or instructions, when executed by the processor, implementing the steps of the method as described in the second aspect, or implementing the steps of the method as described in the third aspect, or implementing the steps of the method as described in the fourth aspect.
[0019] In a thirteenth aspect, a network-side device is provided, including a processor and a communication interface, wherein the communication interface is used to receive a handover request message from a first network device, the handover request message including a first key; the processor is used to determine a second key based on the first key and a first parameter, the second key being used for communication between the terminal and the second network device.
[0020] In a fourteenth aspect, a network-side device is provided, including a processor and a communication interface, wherein the communication interface is configured to send a first request message to a core network device before the terminal switches to the second network device, the first request message being used to request key parameters; the communication interface is further configured to receive a first response message from the core network device, the first response message including the key parameters; the processor is further configured to determine a first key based on the key parameters, the first key being used for communication between the terminal and the second network device.
[0021] In a fifteenth aspect, a network-side device is provided, including a processor and a communication interface, wherein the communication interface is configured to send a handover request message to a second network device, the handover request message including a first key deduction indication, wherein the first key deduction indication is determined based on a second key deduction indication currently stored by the first network device; the communication interface is further configured to receive a handover response message from the second network device; wherein the handover response message corresponds to the handover request message and includes the first key deduction indication.
[0022] In a sixteenth aspect, a readable storage medium is provided, on which a program or instructions are stored, which, when executed by a processor, implement the steps of the method described in the first aspect, or the steps of the method described in the second aspect, or the steps of the method described in the third aspect, or the steps of the method described in the fourth aspect.
[0023] In a seventeenth aspect, a wireless communication system is provided, comprising: a terminal, a first network device, and a second network device, wherein the terminal is configured to perform the steps of the method described in the first aspect, and the second network device is configured to perform the steps of the method described in the second aspect.
[0024] Eighteenth aspect, a wireless communication system is provided, comprising: a terminal, a first network device, and a second network device, wherein the second network device is configured to perform the steps of the method described in the third aspect, and the first network device is configured to perform the steps of the method described in the fourth aspect.
[0025] In a nineteenth aspect, a chip is provided, the chip including a processor and a communication interface coupled to the processor, the processor being configured to run a program or instructions to implement the steps of the method as described in the first aspect, or the steps of the method as described in the second aspect, or the steps of the method as described in the third aspect, or the steps of the method as described in the fourth aspect.
[0026] In a twentieth aspect, a computer program / program product is provided, the computer program / program product being stored in a storage medium, the computer program / program product being executed by at least one processor to implement the steps of the method as described in the first aspect, or the steps of the method as described in the second aspect, or the steps of the method as described in the third aspect, or the steps of the method as described in the fourth aspect.
[0027] In this embodiment of the application, when determining (or deducing) the key (i.e., the second key) used for communication between the second network device (i.e., the target network device) and the terminal after the switch, an additional first parameter is added. This ensures that even if the first network device is compromised, the attacker will not be able to obtain the key (i.e., the second key) used for communication between the target network device and the terminal because the first network device is unaware of the first parameter. This effectively strengthens forward security, such as achieving one-hop forward security, and improves the communication security between the second network device and the terminal.
[0028] Alternatively, in this embodiment, when determining (or deducing) the key used by the second network device (i.e., the target network device) to communicate with the terminal after the handover, the second network device can request a key parameter unknown to the first network device from the core network device before the terminal switches to the second network device. This is done to determine the first key, so that even if the first network device is compromised, the attacker cannot obtain the key used for communication between the target base station and the terminal (i.e., the first key) because the first network device is unaware of the key parameter. This effectively strengthens forward security, achieves one-hop forward security, and improves the communication security between the second network device and the terminal. Attached Figure Description
[0029] Figure 1 is a schematic diagram of the structure of a wireless communication system provided in an exemplary embodiment of this application.
[0030] Figure 2 is a flowchart illustrating one of the network switching methods provided in an exemplary embodiment of this application.
[0031] Figure 3 is one of the interactive flow diagrams of a network switching method provided in an exemplary embodiment of this application.
[0032] Figure 4 is a second flowchart illustrating a network switching method provided in an exemplary embodiment of this application.
[0033] Figure 5 is a flowchart of a network switching method provided in an exemplary embodiment of this application.
[0034] Figure 6 is a second schematic diagram of the interaction flow of the network switching method provided in an exemplary embodiment of this application.
[0035] Figure 7 is a fourth flowchart illustrating a network switching method provided in an exemplary embodiment of this application.
[0036] Figure 8 is a schematic diagram of the structure of a network switching device provided in an exemplary embodiment of this application.
[0037] Figure 9 is a second schematic diagram of the network switching device provided in an exemplary embodiment of this application.
[0038] Figure 10 is a third schematic diagram of the network switching device provided in an exemplary embodiment of this application.
[0039] Figure 11 is a fourth schematic diagram of the network switching apparatus provided in an exemplary embodiment of this application.
[0040] Figure 12 is a schematic diagram of the structure of a communication device provided in an exemplary embodiment of this application.
[0041] Figure 13 is a schematic diagram of the structure of a terminal provided in an exemplary embodiment of this application.
[0042] Figure 14 is a schematic diagram of the structure of a network-side device provided in an exemplary embodiment of this application. Detailed Implementation
[0043] The technical solutions of the embodiments of this application will be clearly described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application are within the scope of protection of this application.
[0044] The terms "first," "second," etc., used in this application are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such terms can be used interchangeably where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first" and "second" are generally of the same class, not limited in number; for example, the first object can be one or more. Furthermore, "or" in this application indicates at least one of the connected objects. For example, the scope of protection for "A or B" covers at least three scenarios: Scenario 1: including A but not B; Scenario 2: including B but not A; Scenario 3: including both A and B. In addition, the terms "A and / or B," "at least one of A and B," and "at least one of A or B" also cover at least the above three scenarios. The character " / " generally indicates that the preceding and following objects are in an "or" relationship.
[0045] The term "instruction" in this application can be either a direct instruction (or explicit instruction) or an indirect instruction (or implicit instruction). A direct instruction can be understood as one in which the sender explicitly informs the receiver of specific information, the operation to be performed, or the requested result, etc., in the instruction sent. An indirect instruction can be understood as one in which the receiver determines the corresponding information based on the instruction sent by the sender, or makes a judgment and determines the operation to be performed or the requested result, etc., based on the judgment result.
[0046] It is worth noting that the technologies described in this application are not limited to Long Term Evolution (LTE) / LTE-Advanced (LTE-A) systems, but can also be used in other wireless communication systems, such as Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single-carrier Frequency-Division Multiple Access (SC-FDMA), or other systems. The terms "system" and "network" in this application are often used interchangeably, and the described technologies can be used in the systems and radio technologies mentioned above, as well as in other systems and radio technologies. The following description describes New Radio (NR) systems for illustrative purposes, and the term NR is used in most of the following description; however, these technologies can also be applied to systems other than NR systems, such as 6th Generation (6G) communication systems.
[0047] Figure 1 shows a block diagram of a wireless communication system applicable to an embodiment of this application. The wireless communication system includes a terminal 11 and a network-side device 12. The terminal 11 can be a mobile phone, tablet computer, laptop computer, notebook computer, personal digital assistant (PDA), handheld computer, netbook, ultra-mobile personal computer (UMPC), mobile internet device (MID), augmented reality (AR), virtual reality (VR) device, robot, wearable device, flight vehicle, vehicle user equipment (VUE), shipboard equipment, pedestrian user equipment (PUE), smart home (home devices with wireless communication capabilities, such as refrigerators, televisions, washing machines, or furniture), game console, personal computer (PC), ATM, or self-service machine, etc. Wearable devices include: smartwatches, smart bracelets, smart headphones, smart glasses, smart jewelry (smart bracelets, smart chains, smart rings, smart necklaces, smart anklets, smart anklets, etc.), smart wristbands, smart clothing, etc. Among these, in-vehicle devices can also be referred to as in-vehicle terminals, in-vehicle controllers, in-vehicle modules, in-vehicle components, in-vehicle chips, or in-vehicle units, etc. It should be noted that the specific type of terminal 11 is not limited in this application embodiment. Network-side equipment 12 may include access network equipment or core network equipment, wherein access network equipment may also be referred to as Radio Access Network (RAN) equipment, radio access network function, or radio access network unit. Access network equipment may include base stations, Wireless Local Area Network (WLAN) access points (AS), or Wireless Fidelity (WiFi) nodes, etc.The term "base station" can be referred to as Node B (NB), Evolved Node B (eNB), Next Generation Node B (gNB), New Radio Node B (NR Node B), Access Point, Relay Base Station (RBS), Serving Base Station (SBS), Base Transceiver Station (BTS), Radio Base Station, Radio Transceiver, Basic Service Set (BSS), Extended Service Set (ESS), Home Node B (HNB), Home Evolved Node B, Transmit / Receive Point (TRP), or any other suitable term in the relevant field, as long as the same technical effect is achieved. The term "base station" is not limited to any specific technical terminology. It should be noted that this application embodiment only uses a base station in an NR system as an example for description and does not limit the specific type of base station.
[0048] Core network equipment, also known as core network nodes, core network functions, or core network elements, includes, but is not limited to, at least one of the following: Mobility Management Entity (MME), Access and Mobility Management Function (AMF), Session Management Function (SMF), User Plane Function (UPF), Policy Control Function (PCF), Policy and Charging Rules Function (PCRF), Edge Application Server Discovery Function (EASDF), Unified Data Management (UDM), Unified Data Repository (UDR), Home Subscriber Server (HSS), Centralized network configuration (CNC), Network Repository Function (NRF), Network Exposure Function (NEF), Local NEF (or L-NEF), and Binding Support. The core network functions include: BSF (Block Network Function), Application Function (AF), Location Management Function (LMF), Gateway Mobile Location Centre (GMLC), and Network Data Analytics Function (NWDAF). It should be noted that this application embodiment only uses core network equipment in the NR system as an example and does not limit the specific type of core network equipment. If the name of the core network equipment mentioned in this application embodiment changes in subsequent protocol versions (e.g., 6G), it will still be within the scope of protection of this application.
[0049] Optionally, the core network equipment can be implemented by one or more functional modules in a single device, or by multiple devices working together; this application does not specifically limit this. It is understood that the aforementioned functional modules can be network elements in hardware devices, software functional modules running on dedicated hardware, or virtualized functional modules instantiated on a platform (e.g., a cloud platform).
[0050] In network handover schemes (such as Xn handover) provided in related technologies, the source network device (such as the source base station) typically deduces the key used after the handover for the target network device (such as the target base station), meaning the source network device knows the key of the target network device. Simultaneously, the target network device after the handover can obtain parameters unknown to the source network device from core network equipment (such as the AMF), which can be used to deduce the key used by the target network device in the next network handover. In other words, the source network device in the current handover does not know the key used by the target network device in the next handover. That is, the network handover schemes provided in related technologies achieve 2-hop forward security, meaning that after two network handovers, the source network device in the first handover does not know the key used by the target network device in the second handover.
[0051] However, for each network switch, since the source network device knows the key used by the target network device, once the source network device is compromised, the attacker can obtain the key used by the target network device, thereby exposing the communication content between the target network device and the terminal and affecting the communication security between the target network device and the terminal.
[0052] To address this, this application provides a network switching scheme to further enhance forward security and improve communication security between the target network device (i.e., the second network device mentioned below) and the terminal. The technical solution provided by this application will be described in detail below with reference to the accompanying drawings and through some embodiments and application scenarios.
[0053] Figure 2 shows a flowchart of a network handover method 200 provided in an exemplary embodiment of this application. This method 200 can be executed by, but is not limited to, a terminal, specifically by hardware and / or software installed in the terminal. In this embodiment, the method 200 may include at least the following steps. It is understood that the method 200 provided in this embodiment is applied to a scenario where a terminal switches from a first network device (i.e., the source network device) to a second network device (i.e., the target network device). The first network device and the second network device can be referred to in the aforementioned description of the network-side device 12.
[0054] S210, the terminal receives a first key derivation instruction from the first network device.
[0055] The first key derivation indication may include, but is not limited to, the Next Hop Chaining Counter (NCC).
[0056] Optionally, the terminal receives a Radio Resource Control (RRC) reconfiguration message from the first network device, which may include the first key derivation indication. The RRC reconfiguration message is used to instruct the terminal to switch from the first network device to the second network device.
[0057] S220, the terminal determines the first key according to the first key derivation instruction.
[0058] In one possible implementation, the process by which the terminal determines the first key based on the first key derivation indication may include, but is not limited to: when the first key derivation indication is NCC, the terminal may determine the first key based on the NCC, the Physical Cell Identifier (PCI) of the second network device, and the Absolute Radio Frequency Channel Number (ARFCN) of the second network device.
[0059] For example, if the NCC currently used by the terminal is different from the NCC indicated by the first key derivation, the terminal first derives the next NH based on the difference between the two NCCs, such as N, and then based on the key Kamf and NH, and repeats the derivation N times to obtain a new NH. Finally, the terminal determines the first key based on the new NH, PCI, and ARFCN-DL. If the NCC currently used by the terminal is the same as the NCC indicated by the first key derivation, the terminal derives the first key based on the key (e.g., KgNB), PCI, and ARFCN-DL stored in the configuration information of the second network device.
[0060] S230, the terminal determines a second key based on the first key and the first parameter. The second key is used for communication between the terminal and the second network device, such as using the second key for subsequent RRC message protection.
[0061] For example, the implementation of "the second key is used for communication between the terminal and the second network device" may include, but is not limited to, one or more of the following methods 1-4.
[0062] Method 1: The terminal derives the RRC encryption key KRRC-enc based on the second key, and uses the RRC encryption key to encrypt the RRC messages between the terminal and the second network device.
[0063] Method 2: The terminal derives the RRC integrity protection key KRRC-int based on the second key, and uses the RRC integrity key to protect the integrity of the RRC messages between the terminal and the second network device.
[0064] Method 3: The terminal derives the user plane encryption key KUP-enc based on the second key, and uses the user plane encryption key to encrypt user plane messages between the terminal and the second network device.
[0065] Method 4: The terminal derives the user plane integrity protection key KUP-int based on the second key, and uses the user plane integrity key to protect the integrity of user plane messages between the terminal and the second network device.
[0066] In this embodiment, the first parameter can be a parameter that is not transmitted through the first network device. It should be understood that the first parameter can also be a parameter that the first network device is unaware of or has not saved, or a parameter that the first network device cannot obtain or deduce. Therefore, even if the first network device is compromised, the attacker cannot obtain the first parameter based on the first network device.
[0067] In other words, compared to the problem in related technologies where, once the source network device is compromised, an attacker can obtain the key used by the target network device to communicate with the terminal, thus exposing the communication content between the target network device and the terminal, this embodiment adds a first parameter when determining (or deducing) the key used by the second network device (i.e., the target network device) to communicate with the terminal after the switch (i.e., the second key). This ensures that even if the first network device is compromised, the attacker cannot obtain the key used by the target network device to communicate with the terminal (i.e., the second key) because the first network device is unaware of the first parameter. This effectively strengthens forward security, achieving one-hop forward security and improving the communication security between the second network device and the terminal.
[0068] In some embodiments, the process by which the terminal derives the second key based on the first key and the first parameters as described in S230 may include, but is not limited to: the terminal using the first key and the first parameters as input to a Key Derivation Function (KDF) and ultimately outputting the second key. The KDF may be, but is not limited to, HMAC-SHA256, etc.
[0069] In some embodiments, the first parameter described above may include, but is not limited to, at least one of the following 11)-19).
[0070] 11) Random Access Preamble Identifier (RAPID), used to identify the transmitted random access preamble.
[0071] In this context, considering that the RAPID has 6 bits and can be used to identify different preambles, meaning that the RAPID has a certain degree of randomness, using the RAPID as the first parameter or a part of the first parameter makes the first parameter also have a certain degree of randomness. This effectively increases the difficulty for attackers to obtain the first parameter, reduces the risk of the first parameter being obtained, and improves the communication security between the second network device and the terminal.
[0072] 12) Timing advanced (TA) index value. Optionally, the TA index value can be indicated by a TA command.
[0073] In this context, considering that the index value of the TA changes with the location of the terminal and the channel state, i.e., the index value of the TA has a certain degree of randomness, using the index value of the TA as the first parameter or a part of the first parameter makes the first parameter also have a certain degree of randomness. This can increase the difficulty for attackers to obtain the first parameter, reduce the risk of the first parameter being obtained, and improve the communication security between the second network device and the terminal.
[0074] 13) Uplink Grant (UL Grant) is used to indicate the resources required for uplink communication.
[0075] In this regard, considering that the uplink authorization usually uses random values to identify resources or terminal identities and has a certain degree of randomness, when the uplink authorization is used as the first parameter or a part of the first parameter, the first parameter also has a certain degree of randomness, thereby increasing the difficulty for attackers to obtain the first parameter, reducing the risk of the first parameter being obtained, and improving the communication security between the second network device and the terminal.
[0076] 14) Cell Radio Network Temporary Identifier (C-RNTI) is used to indicate the temporary identity used by a MAC entity during random access.
[0077] Similar to 13), considering that C-RNTI usually uses random values to identify resources or terminal identities and has a certain degree of randomness, when the C-RNTI is used as the first parameter or a part of the first parameter, the first parameter also has a certain degree of randomness, thereby increasing the difficulty for attackers to obtain the first parameter, reducing the risk of the first parameter being obtained, and improving the communication security between the second network device and the terminal.
[0078] 15) Scrambling identifier, used to indicate the scrambling ID.
[0079] Similar to 13), considering that scrambling identifiers usually use random values to identify resources or terminal identities and have a certain degree of randomness, when the scrambling identifier is used as the first parameter or a part of the first parameter, the first parameter also has a certain degree of randomness, thereby increasing the difficulty for attackers to obtain the first parameter, reducing the risk of the first parameter being obtained, and improving the communication security between the second network device and the terminal.
[0080] 16) Terminal location information, wherein the terminal location information may include, but is not limited to, one or more of the following: SSB ID, PRACH resource ID, relative position between the terminal and the second network device.
[0081] In this context, considering that the terminal location information changes with the location of the terminal, meaning that the terminal location information value has a certain degree of randomness, using the terminal location information as the first parameter or a part of the first parameter makes the first parameter also have a certain degree of randomness. This increases the difficulty for attackers to obtain the first parameter, reduces the risk of the first parameter being obtained, and improves the communication security between the second network device and the terminal.
[0082] 17) Power status information. The power status information may include, but is not limited to, one or more of the following: path loss level, received power level (Rx), etc.
[0083] In this context, considering that the energy state information changes with the location or channel state of the terminal, i.e., the energy state information has a certain degree of randomness, using the energy state information as the first parameter or a part of the first parameter makes the first parameter also have a certain degree of randomness. This increases the difficulty for attackers to obtain the first parameter, reduces the risk of the first parameter being obtained, and improves the communication security between the second network device and the terminal.
[0084] 18) Second parameter. The second parameter is determined based on the random access preamble, or the second parameter may include the random access preamble.
[0085] In the case where the second parameter is determined based on a random access preamble, the symbols in the random access preamble can be transformed into a bit stream and then used as the second parameter.
[0086] In cases where the second parameter may include the random access preamble, symbols in the random access preamble may be used as the second parameter.
[0087] In this case, considering that the second parameter is generated and sent by the terminal during the random access process, and the preamble is a symbol obtained based on computation, that is, the second parameter has a certain degree of randomness, then when the second parameter is used as the first parameter or a part of the first parameter, the first parameter also has a certain degree of randomness, thereby increasing the difficulty for attackers to obtain the first parameter, reducing the risk of the first parameter being obtained, and improving the communication security between the second network device and the terminal.
[0088] 19) A first random number or a second random number, wherein the first random number is determined by the terminal and the second random number is determined by the second network device.
[0089] In this regard, considering that the first random number or the second random number has a certain degree of randomness, when the second parameter is used as the first parameter or a part of the first parameter, the first parameter also has a certain degree of randomness, thereby increasing the difficulty for attackers to obtain the first parameter, reducing the risk of the first parameter being obtained, and improving the communication security between the second network device and the terminal.
[0090] In some embodiments, the first parameter may include which of the parameters in 11)-19) above, which may be implemented by protocol agreement, higher-level configuration or network-side device configuration, etc., and there is no limitation here.
[0091] In some embodiments, for the second network device to which the handover target is located, the second network device may first receive a handover request message from the first network device, the handover request message including a first key; then, the second network device determines a second key based on the first key and a first parameter, the second key being used for communication between the terminal and the second network device. The first parameter can be referred to the foregoing description and will not be repeated here.
[0092] In other words, similar to the aforementioned terminal-side security, this embodiment addresses the problem in related technologies where, once the source network device is compromised, an attacker can obtain the key used by the target network device to communicate with the terminal, thus exposing the communication content between the target network device and the terminal. In this embodiment, when determining (or deducing) the key used for communication between the second network device and the terminal after the switch (i.e., the second key), an additional first parameter is added. This ensures that even if the first network device is compromised, the attacker cannot obtain the key used for communication between the target network device and the terminal (i.e., the second key) because the first network device is unaware of the first parameter. This effectively strengthens forward security (e.g., achieving one-hop forward security) and improves the communication security between the second network device and the terminal.
[0093] In some embodiments, for the aforementioned first parameter, in order to ensure that the second network device and the terminal have a consistent understanding of the first parameter, and thus ensure that the second key determined by the second network device and the terminal is consistent.
[0094] In this embodiment, the terminal may send a third parameter to the second network device. The third parameter may include at least one of the following: the second parameter, or the first random number.
[0095] The third parameter is determined by the terminal and can be synchronized by the terminal to the second network-side device. For example, the terminal can send the third parameter to the second network device, meaning the second network device receives the third parameter from the terminal. It is understood that the third parameter is a subset of the aforementioned first parameter, and the description of the first parameter is similar and will not be repeated here.
[0096] In this embodiment, the terminal can receive a fourth parameter from the second network device. The fourth parameter includes at least one of the following: the random access preamble identifier, the index value of the TA, the uplink grant, the C-RNTI, the scrambling identifier, the terminal location information, the energy state information, and the second random number.
[0097] The fourth parameter, determined by the second network device, can be synchronized to the terminal by the second network device. For example, the second network device can send the fourth parameter to the terminal, and correspondingly, the terminal can receive the fourth parameter from the second network device. It is understood that the fourth parameter is a subset of the aforementioned first parameter, and the description of the first parameter is provided above; it will not be repeated here.
[0098] In some embodiments, the third parameter may be transmitted via a random access message, and / or the fourth parameter may be transmitted via a random access response message.
[0099] In this way, transmitting the third parameter through the random access message or the fourth parameter through the random access response message can be done without modifying the random access message and the random access response message, thus reducing the difficulty of introducing the first parameter.
[0100] For example, assuming the first parameter includes a random access preamble, meaning that during network handover, a second key needs to be determined based on the random access preamble and the first key; then, the terminal can first send a random access message to the second network device, wherein the random access message includes a random access preamble. Then, the second network device determines the second key based on the random access preamble and the first key in the received random access message, and the terminal determines the second key based on the random access preamble and the first key. Finally, the terminal uses the second key to protect the RRC reconfiguration complete message and sends the RRC reconfiguration complete message to the second network device, which decrypts or verifies the RRC reconfiguration complete message based on the second key.
[0101] For example, assuming the first parameter includes the C-RNTI, meaning that during network handover, a second key needs to be determined based on the C-RNTI and the first key, then the terminal can first send a random access message to the second network device. Then, the second network device sends a random access response message to the terminal, which contains the terminal's C-RNTI. Next, the second network device determines the second key based on the C-RNTI and the first key, and the terminal also determines the second key based on the C-RNTI and the first key. Finally, the terminal uses the second key to protect the RRC reconfiguration complete message and sends the RRC reconfiguration complete message to the second network device. The second network device decrypts or verifies the RRC reconfiguration complete message based on the second key.
[0102] For example, assuming the first parameter includes a first random number and a C-RNTI, meaning that during network handover, a second key needs to be determined based on the first random number, C-RNTI, and a first key, then the terminal can first send a random access message to the second network device, wherein the random access message includes the first random number. Then, the second network device sends a random access response message to the terminal, which contains the terminal's C-RNTI. Next, the second network device can determine the second key based on the first random number, C-RNTI, and the first key; the terminal determines the second key based on the first random number, C-RNTI, and the first key. Finally, the terminal uses the second key to protect the RRC reconfiguration complete message and sends the RRC reconfiguration complete message to the second network device, which decrypts or verifies the RRC reconfiguration complete message using the second key.
[0103] Based on the description of the network handover method provided in the aforementioned method embodiment 200, for ease of understanding, the implementation process of the network handover scheme provided in this application embodiment is illustrated below with reference to Example 1 and Figure 3. It is assumed that the first key derivation indicator is NCC.
[0104] Example 1
[0105] S311, The terminal and the first network device (i.e., the source network device) are currently using KgNB1 for communication protection. Here, it is assumed that KgNB1 is derived based on the next hop (NH)1 corresponding to NCC1, and the first network device has an unused NH2 and a corresponding NCC2 (corresponding to the first key derivation indication).
[0106] S312, the first network device sends a handover request message to the second network device (i.e., the target network device). The handover request message may include the terminal's identifier, NCC2, and a first key (such as KgNB2).
[0107] The terminal identifier is used to identify the terminal's context. Optionally, the terminal identifier can be, but is not limited to, the source next-generation radio access network (NG-RAN) node terminal Xn Application Protocol (XnAP) ID.
[0108] For the first key, assuming the first key is KgNB2, if the first network device has an unused NH2, then KgNB2 is derived based on the unused NH2, PCI1, and ARFCN-DL1; otherwise, the first network device derives KgNB2 using KgNB1, PCI1, and ARFCN-DL1. Here, PCI1 and ARFCN-DL1 indicate the physical cell identifier and downlink absolute radio frequency channel number of the second network device, respectively.
[0109] S313, the second network device sends a handover response message to the first network device, wherein the handover response message includes configuration information of the second network device, and the configuration information may include a first key derivation indication, such as NCC2.
[0110] S314, the first network device sends an RRC reconfiguration message to the terminal. The RRC reconfiguration message contains the configuration information of the second network device. The configuration information may include a first key derivation instruction, such as NCC2.
[0111] S315, the terminal determines or derives a first key, such as KgNB2, based on NCC2.
[0112] If the NCC currently used by the terminal (i.e., the NCC1 used to derive the key used by the first network device) is different from the NCC2 in the configuration information of the second network device, the terminal performs NCC2-NCC1 key derivation based on the current key Kamf and NH to derive a new NH, and derives KgNB2, i.e., the first key, based on the new NH, PCI1, and ARFCN-DL1.
[0113] If the NCC currently used by the terminal is the same as NCC2 in the configuration information of the second network device, the terminal deduces KgNB2, i.e., the first key, based on KgNB1, PCI1, and ARFCN-DL1 stored in the configuration information of the second network device.
[0114] In this step, since the NCC1 currently used by the terminal is different from the NCC2 in the configuration information of the second network device, the terminal derives NH2 once from Kamf and NH1 based on the difference between NCC2 and NCC1 (assuming it is 1), and derives KgNB2, i.e., the first key, from NH2, PCI1, and ARFCN-DL1.
[0115] S316, the terminal initiates a random access message to the second network device, the random access message including a PRACH Preamble, to perform random access.
[0116] Optionally, the random access message may include the third parameter, which can be referred to the relevant description in the aforementioned method embodiment 200, and will not be repeated here.
[0117] S317, the second network device sends a random access response message to the terminal to complete random access.
[0118] Optionally, the random access response message may include the fourth parameter, which can be referred to the relevant description in the aforementioned method embodiment 200, and will not be repeated here.
[0119] S318, the second network device determines the second key based on the first key and the first parameter.
[0120] The first parameter is determined based on the third parameter and / or the fourth parameter. The description of the first parameter can be found in the aforementioned method embodiment 200, and will not be repeated here.
[0121] Optionally, in addition to sending the fourth parameter via S317 and determining the second key via S318 as described above, this Example 1 can also determine the second key first and then send the fourth parameter, etc. This Example 1 does not restrict this.
[0122] S319, the terminal determines the second key based on the first key and the first parameter.
[0123] Optionally, the first parameter is determined based on the third parameter and / or the fourth parameter. The relevant description of the first parameter can be found in the aforementioned method embodiment 200, and will not be repeated here.
[0124] S320, the terminal sends an RRC reconfiguration complete message to the second network device to indicate that the RRC configuration is complete, that is, the network handover is completed.
[0125] The terminal uses the second key to protect the RRC reconfiguration completion message, and the second network device decrypts or verifies the RRC reconfiguration completion message according to the second key.
[0126] S321, the second network device sends a path switching message to the AMF to switch the user plane.
[0127] S322, AMF sends a path handover confirmation message to the second network device, which includes NH3 and NCC3. AMF calculates NH3 based on Kamf and the current NH2, and increments the current NCC2 by 1 to obtain NCC3. The second network device 1 stores NH3 and NCC3, using NH3 as the KgNB derivation parameter for the next Xn handover.
[0128] In Example 1, after the second network device obtains the first key (e.g., KgNB2) from the first network device and the terminal derives the first key (KgNB2) according to the first key derivation instruction, it does not directly use the first key known to the first network device. Instead, it uses the first key and a first parameter known to the terminal and the second network device but unknown to the first network device to derive the second key. This ensures that even if the first network device is compromised, it cannot directly obtain the second key used by the second network device when communicating with the terminal, thereby strengthening forward security, such as achieving one-hop forward security, and improving the communication security between the second network device and the terminal.
[0129] It is understood that the network switching scheme provided in Example 1 may include, but is not limited to, the aforementioned S311-S322, and may include more or fewer steps than the aforementioned S311-S322. Furthermore, the implementation process of each step in the aforementioned S311-S322 can refer to the relevant description in the aforementioned method embodiment 200, and achieve the same or corresponding technical effects. To avoid repetition, it will not be described again here.
[0130] Figure 4 shows a flowchart of a network handover method 400 provided in an exemplary embodiment of this application. This method 400 can be executed by, but is not limited to, a second network device, specifically by hardware and / or software installed in the second network device. In this embodiment, the method 400 may include at least the following steps. It is understood that the method 400 provided in this embodiment is applied to scenarios where a terminal hands over data from a first network device to a second network device.
[0131] S410, the second network device receives a handover request message from the first network device, the handover request message including a first key.
[0132] S420, the second network device determines a second key based on the first key and the first parameter, and the second key is used for communication between the terminal and the second network device.
[0133] In some embodiments, the first parameter is a parameter that is not transmitted through the first network device.
[0134] In some embodiments, the first parameter includes at least one of the following: a random access preamble identifier; an index value for a timed advance TA; an uplink grant; a cell radio network temporary identifier (C-RNTI); a scrambling identifier; terminal location information; energy status information; a second parameter, the second parameter being determined based on the random access preamble, or the second parameter including the random access preamble; a first random number or a second random number, wherein the first random number is determined by the terminal, and the second random number is determined by the second network device.
[0135] In some embodiments, the method further includes: the second network device receiving a third parameter from the terminal; wherein the third parameter includes at least one of the following: the second parameter; the first random number.
[0136] In some embodiments, the method further includes: the second network device sending a fourth parameter to the terminal; wherein the fourth parameter includes at least one of the following: the random access preamble identifier; the index value of the TA; the uplink grant; the C-RNTI; the scrambling identifier; the terminal location information; the energy state information; and the second random number.
[0137] In some embodiments, the third parameter is transmitted via a random access message, and / or the fourth parameter is transmitted via a random access response message.
[0138] It is understood that each implementation in this method embodiment 400 has the same or corresponding technical features as the aforementioned method embodiment 200. Therefore, the implementation of each implementation in this method embodiment 400 can be referred to the relevant description in the aforementioned method embodiment 200 to achieve the same or corresponding technical effects. To avoid repetition, it will not be described again here.
[0139] Figure 5 shows a flowchart of a network handover method 500 provided in an exemplary embodiment of this application. This method 500 can be executed by, but is not limited to, a second network device, specifically by hardware and / or software installed in the second network device. In this embodiment, the method 500 may include at least the following steps. It is understood that the method 500 provided in this embodiment is applied to scenarios where a terminal switches from a first network device (i.e., the source network device) to a second network device (i.e., the target network device). The first network device and the second network device can be referred to in the aforementioned description of the network-side device 12.
[0140] S510, before the terminal switches to the second network device, the second network device sends a first request message to the core network device.
[0141] The first request message is used to request key parameters. These key parameters may include, but are not limited to, NH.
[0142] Optionally, the core network equipment may be, but is not limited to, AMF, etc.
[0143] Optionally, before the terminal switches to the second network device, the process includes: before the second network device receives the RRC reconfiguration complete message sent by the terminal.
[0144] The phrase "before the second network device receives the RRC reconfiguration complete message sent by the terminal" can also be understood as the process during which the terminal switches from the first network device to the second network device.
[0145] S520, the second network device receives a first response message from the core network device.
[0146] The first response message includes the key parameters, such as NH. It is worth noting that the key parameters are obtained by the second network device from the core network device. Therefore, the key parameters are not transmitted through the first network device, or the first network device may not know or have not stored the key parameters, or the key parameters may be derived from key parameters that the first network device cannot obtain. Therefore, even if the first network device is compromised, the attacker cannot obtain the key parameters based on the first network device.
[0147] S530, the second network device determines the first key according to the key parameters.
[0148] The first key is used for communication between the terminal and the second network device, such as for protecting subsequent RRC messages.
[0149] For example, the method of "the first key is used for communication between the terminal and the second network device" may include, but is not limited to, one or more of the following methods 1-4.
[0150] Method 1: The terminal derives the RRC encryption key KRRC-enc based on the first key, and uses the RRC encryption key to encrypt the RRC messages between the terminal and the second network device.
[0151] Method 2: The terminal derives the RRC integrity protection key KRRC-int based on the first key, and uses the RRC integrity key to protect the integrity of RRC messages between the terminal and the second network device.
[0152] Method 3: The terminal derives the user plane encryption key KUP-enc based on the first key, and uses the user plane encryption key to encrypt user plane messages between the terminal and the second network device.
[0153] Method 4: The terminal derives the user plane integrity protection key KUP-int based on the first key, and uses the user plane integrity key to protect the integrity of user plane messages between the terminal and the second network device.
[0154] Understandably, compared to related technologies where, once the source network device is compromised, an attacker can obtain the key used by the target network device to communicate with the terminal, thus exposing the communication content between the target network device and the terminal. In this embodiment, when determining (or deducing) the key used by the second network device (target network device) to communicate with the terminal after the handover, the second network device can request a key parameter unknown to the first network device from the core network device before the terminal switches to the second network device. This is done to determine the first key, ensuring that even if the first network device is compromised, the attacker cannot obtain the key used for communication between the target base station and the terminal (i.e., the first key) because the first network device is unaware of the key parameter. This effectively strengthens forward security, achieves one-hop forward security, and improves the communication security between the second network device and the terminal.
[0155] In some embodiments, the process by which the second network device determines the first key based on the key parameters in S530 may include: the second network device determining the first key based on the key parameters, the PCI of the second network device, and the downlink absolute radio frequency channel number of the second network device.
[0156] In some embodiments, the first request message in S510 may be sent by the second network device after receiving the handover request message sent by the first network device. That is, when the second network device determines to perform a network handover, it requests key parameters from the core network device to ensure the efficiency of subsequent determination of the first key.
[0157] In this embodiment, the method further includes:
[0158] The second network device receives a handover request message from the first network device;
[0159] The second network device sends a handover response message to the first network device, wherein the handover response message corresponds to the handover request message and includes a first key derivation indication related to or corresponding to the first key.
[0160] For example, a handover request message can be a Handover Request message, and a handover response message can be a Handover Request ACK message.
[0161] Optionally, upon receiving a first request response from the core network device, the second network device may send a handover response message to the first network device in response to the handover request message sent by the first network device. The handover response message corresponds to the handover request message and includes a first key deduction indication related to or corresponding to the first key. This allows the first network device to send the first key deduction indication to the terminal after receiving the handover response message, enabling the terminal to determine the first key based on the first key deduction indication for communication between the terminal and the second network device.
[0162] In some embodiments, the determination of the first key derivation indication carried in the switching response message may include any one of the following methods 1-3.
[0163] Method 1: The switching request message includes the first key derivation indication.
[0164] If the handover request message includes the first key derivation indication, then the first key derivation indication carried in the handover response message can be directly obtained from the handover request message.
[0165] The first key deduction indication included in the handover request message is determined by the first network device based on the sum of the currently stored second key deduction indication and a predetermined value. The predetermined value may be, but is not limited to, 1.
[0166] For example, assuming the second key derivation indicator is NCC1 and NCC1 = 2, then the first key derivation indicator can be NCC1 + 1, which can be denoted as NCC2, and in this case, NCC2 = 3.
[0167] Method 2: The first response message includes the first key derivation indication.
[0168] Method 3, the handover request message includes a second key deduction indication, and the first key deduction indication is determined by the second network device based on the second key deduction indication.
[0169] If the handover request message includes a second key deduction indication, then the first key deduction indication carried in the handover response message may be determined by the second network device based on the second key deduction indication.
[0170] Optionally, the first key derivation indication is determined by the second network device based on the second key derivation indication, including: when the first key derivation indication and the second key derivation indication are NCC, the first key derivation indication is determined by the second network device based on the sum of the second key derivation indication and a predetermined value.
[0171] The predetermined value can be, but is not limited to, 1.
[0172] For example, assuming the second key derivation indicator is NCC1 and NCC1 = 2, then the first key derivation indicator can be NCC1 + 1, which can be denoted as NCC2, and in this case, NCC2 = 3.
[0173] In some embodiments, since the method for determining the key derivation indication (such as NCC) is fixed, the first network device or the second network device can predict the value of the first key derivation indication received from the core network device, i.e., NCC2. Furthermore, the first network device only needs to notify the terminal of the first key derivation indication, without requiring key parameters. Therefore, the first network device can generate the first key derivation indication in advance and send it to the terminal, enabling the terminal to determine the first key based on the first key derivation indication. That is, the first network device can send a handover response message carrying the first key derivation indication before receiving the first response message, allowing the first network device to send the first key derivation indication to the terminal based on the received handover response message. This effectively improves network handover efficiency.
[0174] Based on the description of the network switching method provided in the aforementioned method embodiment 500, for ease of understanding, the implementation process of the method embodiment 500 of this application will be exemplarily introduced below with reference to Example 2 and Figure 6, the content of which is as follows.
[0175] Example 2
[0176] S611, The terminal and the first network device are currently using KgNB1 for communication protection.
[0177] Here, it is assumed that KgNB1 is derived from NH1 corresponding to NCC1.
[0178] S612, the first network device sends a handover request message to the second network device.
[0179] The switch request message may include the identifier of the terminal. Optionally, the identifier of the terminal may be, but is not limited to, the Source NG-RAN node terminal XnAP ID, used to identify the context of the terminal.
[0180] Optionally, the switching request message may include a first key derivation indication (such as NCC2) or a second key derivation indication (such as NCC1).
[0181] The second key derivation indication is the key derivation indication currently stored by the first network device, such as NCC1.
[0182] The first key derivation indication is determined by the first network device based on the sum of the currently stored second key derivation indication and a predetermined value. For example, assuming the second key derivation indication is NCC1 and NCC1 = 2, then the first key derivation indication can be NCC1 + 1, which can be denoted as NCC2, and at this time NCC2 = 3.
[0183] Optionally, the handover request message may further include KgNB2. KgNB2 is derived by the first network device using KgNB1, PCI1, and ARFCN-DL1. PCI1 and ARFCN-DL1 respectively indicate the physical cell identifier and downlink absolute radio frequency channel number of the second network device.
[0184] S613, the second network device sends a first request message to the AMF to request key parameters, such as NH2.
[0185] S614, the AMF sends a first response message to the second network device, wherein the first response message includes the key parameters. The key parameters may be determined by the AMF based on the Kamf and the current NH1, such as NH2.
[0186] Optionally, the first response message may further include a first key derivation indication, such as NCC2. The first key parameter corresponds to the key parameter; for example, the first key derivation indication is obtained by the AMF from NCC1 plus 1 to obtain NCC2.
[0187] S615, the second network device determines the first key based on the key parameters.
[0188] For example, the second network device determines the first key based on the key parameters (such as NH2), the PCI of the second network device, and the downlink absolute radio frequency channel number of the second network device.
[0189] S616, the second network device sends a handover response message to the first network device, wherein the handover response message includes configuration information of the second network device, and the configuration information may include a first key derivation indication, such as NCC2.
[0190] Optionally, the first key derivation indication in the handover response message can be directly obtained from the handover request message, that is, the handover request message includes the first key derivation indication.
[0191] Alternatively, the first key deduction indication in the handover response message can be determined based on the second key deduction indication included in the handover request message.
[0192] The first key derivation indication is determined by the second network device based on the sum of the second key derivation indication included in the handover request message and a predetermined value. For example, assuming the second key derivation indication is NCC1 and NCC1 = 2, then the first key derivation indication can be NCC1 + 1, which can be denoted as NCC2, and at this time NCC2 = 3.
[0193] It should be understood that in the two acquisition methods described above, the second network device can execute S616 before S613 or S614 to generate the first key derivation instruction in advance and send it to the terminal, without waiting for step S613 or S614 to be completed, thereby improving the handover efficiency.
[0194] Alternatively, the first key derivation indication in the switching response message can be directly obtained from the first response message, that is, the first response message includes the first key derivation indication.
[0195] S617, the first network device sends an RRC reconfiguration message to the terminal. The RRC reconfiguration message contains the configuration information of the second network device, including a first key derivation instruction, such as NCC2.
[0196] S618, the terminal initiates a random access message to the second network device, the random access message including a PRACH Preamble, to perform random access.
[0197] S619, the second network device sends a random access response message to the terminal to complete random access.
[0198] S620, the terminal determines the first key, such as KgNB2, based on the key parameters.
[0199] If the terminal's current NCC (i.e., the NCC1 used to deduce the key used by the first network device) is different from the NCC2 in the configuration information of the second network device, the terminal performs NCC2-NCC1 key deduction based on the current Kamf and NH1, and finally deduces the new NH2, and deduces KgNB2 based on the new NH2, PCI1, and ARFCN-DL1.
[0200] If the NCC currently used by the terminal is the same as NCC2 in the configuration information of the second network device, the terminal deduces KgNB2 based on KgNB1, PCI1, and ARFCN-DL1 stored in the configuration information of the second network device.
[0201] In this step, since the NCC1 currently used by the terminal is different from the NCC2 in the configuration information of the second network device, the terminal derives NH2 once from Kamf and NH1 based on the difference between NCC2 and NCC1 (assuming it is 1), and derives KgNB2 based on NH2, PCI1, and ARFCN-DL1.
[0202] S621, the terminal sends an RRC reconfiguration complete message to the second network device to indicate that the RRC configuration is complete, that is, the network handover is completed.
[0203] S622, the second network device sends a path switching message to the AMF to switch the user plane.
[0204] S623, AMF sends a path switching confirmation message to the second network device.
[0205] In Example 2, when deducing or determining the key used by the second network device after the switch, the second network device can request a key parameter unknown to the first network device from the AMF before the terminal switches to the second network device, so as to determine the first key. This ensures that even if the first network device is compromised, the attacker will not be able to obtain the key (i.e., the first key) for communication between the second network device and the terminal because the first network device does not know the key parameter. This effectively strengthens forward security, such as achieving one-hop forward security, and improves the communication security between the second network device and the terminal.
[0206] Furthermore, since the NCC increment method is fixed, the first network device or the second network device can predict the NCC value received from the AMF, i.e., NCC2. The first network device only needs to notify the terminal of NCC2, and does not need NH2. Therefore, the first network device can generate NCC2 in advance and send it to the terminal, so that S617 can be executed before receiving S613-S616, thereby improving network handover efficiency.
[0207] It is understood that the network switching scheme provided in Example 2 may include, but is not limited to, the aforementioned S611-S623, and may include more or fewer steps than the aforementioned S611-S623. Furthermore, the implementation process of each step in the aforementioned S611-S623 can refer to the relevant description in the aforementioned method embodiment 500, and achieve the same or corresponding technical effects. To avoid repetition, it will not be described again here.
[0208] Figure 7 shows a flowchart of a network handover method 700 provided in an exemplary embodiment of this application. This method 700 can be executed by, but is not limited to, a first network device, specifically by hardware and / or software installed in the first network device. In this embodiment, the method 700 may include at least the following steps. It is understood that the method 700 provided in this embodiment is applied to scenarios where a terminal hands over data from a first network device to a second network device.
[0209] S710, the first network device sends a handover request message to the second network device. The handover request message includes a first key deduction indication, wherein the first key deduction indication is determined based on a second key deduction indication currently stored by the first network device.
[0210] S720, the first network device receives a handover response message from the second network device;
[0211] The handover response message corresponds to the handover request message, and the handover response message includes a first key derivation indication.
[0212] In some embodiments, the first key derivation indication is determined based on a second key derivation indication currently stored by the first network device, including: when the first key derivation indication and the second key derivation indication are a next-hop link counter (NCC), the first key derivation indication is determined based on the sum of the second key derivation indication and a predetermined value.
[0213] It is understood that each implementation in this method embodiment 700 has the same or corresponding technical features as the aforementioned method embodiment 500. Therefore, the implementation of each implementation in this method embodiment 700 can be referred to the relevant description in the aforementioned method embodiment 500 to achieve the same or corresponding technical effects. To avoid repetition, it will not be described again here.
[0214] The network handover method provided in this application can be applied to X2 and Xn handover of LTE, 5G, etc., and can also be applied to scenarios such as handover between 6G base stations.
[0215] The network handover method provided in this application can be executed by a network handover device. This application uses a network handover device executing the network handover method as an example to illustrate the network handover device provided in this application.
[0216] This application provides a network switching apparatus. As an example, the network switching apparatus may be a communication device or a component within a communication device, such as a chip. The communication device may be a terminal, a network-side device, or a server, etc. Exemplarily, the terminal may include, but is not limited to, the type of terminal 11 listed above, and the network-side device may include, but is not limited to, the type of network-side device 12 listed above. This application does not impose specific limitations.
[0217] The network switching device includes a transmission module (such as a receiving module and a transmitting module) and a processing module. These modules can be implemented in software or hardware. When implemented in hardware, the processing module can be implemented by a processor. For example, the processor can include general-purpose processors, special-purpose processors, such as a Central Processing Unit (CPU), microprocessor, Digital Signal Processor (DSP), Artificial Intelligence (AI) processor, Graphics Processing Unit (GPU), Application Specific Integrated Circuit (ASIC), Network Processor (NP), Field Programmable Gate Array (FPGA), or other programmable logic devices, gate circuits, transistors, discrete hardware components, etc. The receiving and transmitting modules can be implemented by a communication interface, which can include one or more of the following: transceiver, pins, circuits, bus, radio frequency unit, etc.
[0218] Specifically, referring to Figure 8, when the network switching device is a terminal or a component in the terminal, the network switching device 800 includes a transmission module 810 for receiving a first key derivation instruction from the first network device; and a processing module 820 for determining a first key based on the first key derivation instruction, and determining a second key based on the first key and a first parameter, wherein the second key is used for communication between the terminal and the second network device.
[0219] In some embodiments, the first parameter is a parameter that is not transmitted through the first network device.
[0220] In some embodiments, the first parameter includes at least one of the following: a random access preamble identifier; an index value for a timed advance TA; an uplink grant; a cell radio network temporary identifier (C-RNTI); a scrambling identifier; terminal location information; energy status information; a second parameter, the second parameter being determined based on the random access preamble, or the second parameter including the random access preamble; a first random number or a second random number, wherein the first random number is determined by the terminal, and the second random number is determined by the second network device.
[0221] In some embodiments, the transmission module 810 is further configured to: send a third parameter to the second network device; wherein the third parameter includes at least one of the following: the second parameter; the first random number.
[0222] In some embodiments, the transmission module 810 is further configured to: receive a fourth parameter from the second network device; wherein the fourth parameter includes at least one of the following: the random access preamble identifier; the index value of the TA; the uplink grant; the C-RNTI; the scrambling identifier; the terminal location information; the energy state information; and the second random number.
[0223] In some embodiments, the third parameter is transmitted via a random access message, and / or the fourth parameter is transmitted via a random access response message.
[0224] In some embodiments, determining the first key based on the first key derivation indication includes: when the first key derivation indication is a next-hop link counter (NCC), determining the first key based on the NCC, the physical cell identifier (PCI) of the second network device, and the downlink absolute radio frequency channel number of the second network device.
[0225] The network switching device 800 provided in this application embodiment can implement the various processes implemented in the method embodiment of FIG2 and achieve the same technical effect. To avoid repetition, it will not be described again here.
[0226] Referring to Figure 9, when the network switching device is a network-side device or a component of a network-side device, the network switching device 900 includes a transmission module 910 for receiving a switching request message from the first network device, the switching request message including a first key; and a processing module 920 for determining a second key based on the first key and a first parameter, the second key being used for communication between the terminal and the second network device.
[0227] In some embodiments, the first parameter is a parameter that is not transmitted through the first network device.
[0228] In some embodiments, the first parameter includes at least one of the following: a random access preamble identifier; an index value for a timed advance TA; an uplink grant; a cell radio network temporary identifier (C-RNTI); a scrambling identifier; terminal location information; energy status information; a second parameter, the second parameter being determined based on the random access preamble, or the second parameter including the random access preamble; a first random number or a second random number, wherein the first random number is determined by the terminal, and the second random number is determined by the second network device.
[0229] In some embodiments, the transmission module 910 is further configured to: receive a third parameter from the terminal; wherein the third parameter includes at least one of the following: the second parameter; the first random number.
[0230] In some embodiments, the apparatus further includes: the transmission module 910 is further configured to: send a fourth parameter to the terminal; wherein the fourth parameter includes at least one of the following: the random access preamble identifier; the index value of the TA; the uplink grant; the C-RNTI; the scrambling identifier; the terminal location information; and the energy state information;
[0231] The second random number.
[0232] In some embodiments, the third parameter is transmitted via a random access message, and / or the fourth parameter is transmitted via a random access response message.
[0233] The network switching device 900 provided in this application embodiment can implement the various processes implemented in the method embodiment of FIG4 and achieve the same technical effect. To avoid repetition, it will not be described again here.
[0234] Referring to Figure 10, when the network switching device is a network-side device or a component within a network-side device, the network switching device 1000 includes a transmission module 1010, configured to send a first request message to a core network device before the terminal switches to the second network device. The first request message is used to request key parameters. The transmission module 1010 is also configured to receive a first response message from the core network device, the first response message including the key parameters. A processing module 1020 is configured to determine a first key based on the key parameters. The first key is used for communication between the terminal and the second network device.
[0235] In some embodiments, determining the first key based on the key parameters includes: determining the first key based on the key parameters, the physical cell identifier of the second network device, and the downlink absolute radio frequency channel number of the second network device.
[0236] In some embodiments, the key parameter includes the next hop NH.
[0237] In some embodiments, before the terminal switches to the second network device, the process includes: before the second network device receives the RRC reconfiguration complete message sent by the terminal.
[0238] In some embodiments, the transmission module 1010 is further configured to receive a handover request message from the first network device; the transmission module 1010 sends a handover response message from the second network device to the first network device, wherein the handover response message corresponds to the handover request message and includes a first key derivation indication related to or corresponding to the first key.
[0239] In some embodiments, the switching request message includes the first key deduction indication; or, the first response message includes the first key deduction indication.
[0240] In some embodiments, the handover request message includes a second key deduction indication, wherein the first key deduction indication is determined by the second network device based on the second key deduction indication.
[0241] In some embodiments, the first key derivation indication is determined by the second network device based on the second key derivation indication, including: when the first key derivation indication and the second key derivation indication are next-hop link counters (NCCs), the first key derivation indication is determined by the second network device based on the sum of the second key derivation indication and a predetermined value.
[0242] The network switching device 1000 provided in this application embodiment can implement the various processes implemented in the method embodiment of FIG5 and achieve the same technical effect. To avoid repetition, it will not be described again here.
[0243] Referring to Figure 11, when the network handover device is a network-side device or a component within a network-side device, the network handover device 1100 includes a sending module 1110, configured to send a handover request message to the second network device. The handover request message includes a first key deduction indication, wherein the first key deduction indication is determined based on a second key deduction indication currently stored by the first network device. The receiving module 1120 is further configured to receive a handover response message from the second network device. The handover response message corresponds to the handover request message and includes the first key deduction indication.
[0244] In some embodiments, the first key derivation indication is determined based on a second key derivation indication currently stored by the first network device, including: when the first key derivation indication and the second key derivation indication are a next-hop link counter (NCC), the first key derivation indication is determined based on the sum of the second key derivation indication and a predetermined value.
[0245] The network switching device 1100 provided in this application embodiment can implement the various processes implemented in the method embodiment of FIG7 and achieve the same technical effect. To avoid repetition, it will not be described again here.
[0246] As shown in Figure 12, this application embodiment also provides a communication device 1200, including a processor 1201 and a memory 1202. The memory 1202 stores programs or instructions that can run on the processor 1201. For example, when the communication device 1200 is a terminal, the program or instructions executed by the processor 1201 implement the various steps of the network switching method embodiment 200 described above, and achieve the same technical effect. When the communication device 1200 is a network-side device, the program or instructions executed by the processor 1201 implement the various steps of the network switching method embodiments 400, 500, or 700 described above, and achieve the same technical effect. To avoid repetition, these will not be described again here.
[0247] This application also provides a terminal, including a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the steps in the method embodiment shown in FIG2. This terminal embodiment corresponds to the above-described terminal-side method embodiment, and all implementation processes and methods of the above-described method embodiments can be applied to this terminal embodiment and can achieve the same technical effect. The terminal can be the network switching device 800 shown in FIG8. Specifically, FIG13 is a schematic diagram of the hardware structure of a terminal implementing an embodiment of this application.
[0248] The terminal 1300 includes, but is not limited to, at least some of the following components: radio frequency unit 1301, network module 1302, audio output unit 1303, input unit 1304, sensor 1305, display unit 1306, user input unit 1307, interface unit 1308, memory 1309, and processor 1310.
[0249] Those skilled in the art will understand that terminal 1300 may also include a power supply (such as a battery) for powering various components. The power supply can be logically connected to processor 1310 through a power management system, thereby enabling functions such as charging, discharging, and power consumption management through the power management system. The terminal structure shown in Figure 13 does not constitute a limitation on the terminal. The terminal may include more or fewer components than shown, or combine certain components, or have different component arrangements, which will not be elaborated here.
[0250] It should be understood that, in this embodiment, the input unit 1304 may include a graphics processor 13041 and a microphone 13042. The graphics processor 13041 processes image data of still images or videos obtained by an image capture device (such as a camera) in video capture mode or image capture mode. The display unit 1306 may include a display panel 13061, which may be configured in the form of a liquid crystal display, an organic light-emitting diode, or the like. The user input unit 1307 includes a touch panel 13071 and at least one of other input devices 13072. The touch panel 13071 is also called a touch screen. The touch panel 13071 may include a touch detection device and a touch controller. Other input devices 13072 may include, but are not limited to, physical keyboards, function keys (such as volume control buttons, power buttons, etc.), trackballs, mice, and joysticks, which will not be described in detail here.
[0251] In this embodiment, after receiving downlink data from the network-side device, the radio frequency unit 1301 can transmit it to the processor 1310 for processing; in addition, the radio frequency unit 1301 can send uplink data to the network-side device. Typically, the radio frequency unit 1301 includes, but is not limited to, antennas, amplifiers, transceivers, couplers, low-noise amplifiers, duplexers, etc.
[0252] The memory 1309 can be used to store software programs or instructions, as well as various data. The memory 1309 may primarily include a first storage area for storing programs or instructions and a second storage area for storing data. The first storage area may store the operating system, application programs or instructions required for at least one function (such as sound playback, image playback, etc.). Furthermore, the memory 1309 may include volatile memory or non-volatile memory. The non-volatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory can be random access memory (RAM), static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct memory bus RAM (DRRAM). The memory 1309 in this embodiment includes, but is not limited to, these and any other suitable types of memory.
[0253] Processor 1310 may include one or more processing units; optionally, processor 1310 integrates an application processor and a modem processor, wherein the application processor mainly handles operations involving the operating system, user interface, and applications, and the modem processor mainly handles wireless communication signals, such as a baseband processor. It is understood that the aforementioned modem processor may also not be integrated into processor 1310.
[0254] The radio frequency unit 1301 is used to receive a first key derivation instruction from the first network device; the processor 1310 is used to determine a first key according to the first key derivation instruction, and to determine a second key according to the first key and a first parameter, wherein the second key is used for communication between the terminal and the second network device.
[0255] In some embodiments, the first parameter is a parameter that is not transmitted through the first network device.
[0256] In some embodiments, the first parameter includes at least one of the following: a random access preamble identifier; an index value for a timed advance TA; an uplink grant; a cell radio network temporary identifier (C-RNTI); a scrambling identifier; terminal location information; energy status information; a second parameter, the second parameter being determined based on the random access preamble, or the second parameter including the random access preamble; a first random number or a second random number, wherein the first random number is determined by the terminal, and the second random number is determined by the second network device.
[0257] In some embodiments, the radio frequency unit 1301 is further configured to: send a third parameter to the second network device; wherein the third parameter includes at least one of the following: the second parameter; the first random number.
[0258] In some embodiments, the radio frequency unit 1301 is further configured to: receive a fourth parameter from the second network device; wherein the fourth parameter includes at least one of the following: the random access preamble identifier; the index value of the TA; the uplink grant; the C-RNTI; the scrambling identifier; the terminal location information; the energy state information; and the second random number.
[0259] In some embodiments, the third parameter is transmitted via a random access message, and / or the fourth parameter is transmitted via a random access response message.
[0260] In some embodiments, determining the first key based on the first key derivation indication includes: when the first key derivation indication is a next-hop link counter (NCC), determining the first key based on the NCC, the physical cell identifier (PCI) of the second network device, and the downlink absolute radio frequency channel number of the second network device. ...
[0261] It is understood that the implementation process of each implementation method mentioned in this embodiment can refer to the relevant description of method embodiment 200 and achieve the same or corresponding technical effects. To avoid repetition, it will not be described again here.
[0262] This application also provides a network-side device, including a processor and a communication interface. The communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the steps of the method embodiment shown in FIG4, FIG5, or FIG7. This network-side device embodiment corresponds to the above-described network-side device method embodiment. All implementation processes and methods of the above-described method embodiments can be applied to this network-side device embodiment and can achieve the same technical effect.
[0263] Specifically, this application embodiment also provides a network-side device, which can be the network switching device 900 shown in FIG. 9, the network switching device 1000 shown in FIG. 10, or the network switching device 1100 shown in FIG. 11. As shown in FIG. 14, the network-side device 1400 includes: an antenna 1401, a radio frequency device 1402, a baseband device 1403, a processor 1404, and a memory 1405. The antenna 1401 is connected to the radio frequency device 1402. In the uplink direction, the radio frequency device 1402 receives information through the antenna 1401 and sends the received information to the baseband device 1403 for processing. In the downlink direction, the baseband device 1403 processes the information to be transmitted and sends it to the radio frequency device 1402. The radio frequency device 1402 processes the received information and transmits it through the antenna 1401.
[0264] The method executed by the network-side device 1400 in the above embodiments can be implemented in the baseband device 1403, which includes a baseband processor.
[0265] The baseband device 1403 may include at least one baseband board, on which multiple chips are disposed, as shown in FIG14. One of the chips is, for example, a baseband processor, which is connected to the memory 1405 via a bus interface to call the program in the memory 1405 and execute the network device operation shown in the above method embodiment.
[0266] The network-side device 1400 may also include a network interface 1406, such as a Common Public Radio Interface (CPRI).
[0267] In this embodiment, the network-side device 1400 is used as an example of the second network device. The radio frequency device 1402 is configured to: receive a handover request message from the first network device, the handover request message including a first key; the processor 1404 is configured to: determine a second key based on the first key and a first parameter, the second key being used for communication between the terminal and the second network device.
[0268] Alternatively, the radio frequency device 1402 is configured to: send a first request message to the core network device, the first request message being used to request key parameters; the second network device receives a first response message from the core network device, the first response message including the key parameters; and the processor 1404 is configured to: determine a first key based on the key parameters, the first key being used for communication between the terminal and the second network device.
[0269] In this embodiment, the network-side device 1400 described above is used as an example of the first network device. The radio frequency device 1402 is configured to: send a handover request message to the second network device, the handover request message including a first key deduction indication, wherein the first key deduction indication is determined based on a second key deduction indication currently stored by the first network device; the radio frequency device 1402 is further configured to: receive a handover response message from the second network device; wherein the handover response message corresponds to the handover request message and includes the first key deduction indication.
[0270] Specifically, the network-side device 1400 in this application embodiment further includes: instructions or programs stored in memory 1405 and executable on processor 1404. The processor 1404 calls the instructions or programs in memory 1405 to execute the methods executed by the modules shown in FIG4, FIG5 or FIG7, and achieve the same technical effect. To avoid repetition, it will not be described in detail here.
[0271] This application also provides a readable storage medium storing a program or instructions that, when executed by a processor, implement the various processes of the above-described network switching method embodiments and achieve the same technical effect. To avoid repetition, these will not be described again here.
[0272] The processor mentioned above is the processor in the terminal described in the above embodiments. The readable storage medium includes computer-readable storage media, such as computer read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk. In some examples, the readable storage medium may be a non-transient readable storage medium.
[0273] This application embodiment also provides a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor. The processor is used to run programs or instructions to implement the various processes of the above-described network switching method embodiment and can achieve the same technical effect. To avoid repetition, it will not be described again here.
[0274] It should be understood that the chip mentioned in the embodiments of this application may also be referred to as a system-on-a-chip, system chip, chip system, or system-on-a-chip, etc.
[0275] This application also provides a computer program / program product, which is stored in a storage medium and executed by at least one processor to implement the various processes of the above-described network switching method embodiments, and can achieve the same technical effect. To avoid repetition, it will not be described again here.
[0276] This application also provides a wireless communication system, including: a terminal, a first network device, and a second network device. The terminal can be used to implement various processes of the above-described network switching method embodiment 200, and the second network device can be used to implement various processes of the above-described network switching method embodiment 400, and can achieve the same technical effect. To avoid repetition, it will not be described again here.
[0277] This application also provides a wireless communication system, including: a terminal, a first network device, and a second network device. The second network device can be used to implement various processes of the above-described network switching method embodiment 500. The first network device can be used to implement various processes of the above-described network switching method embodiment 700, and can achieve the same technical effect. To avoid repetition, it will not be described again here.
[0278] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element. Furthermore, it should be noted that the scope of the methods and apparatuses in the embodiments of this application is not limited to performing functions in the order shown or discussed, but may also include performing functions substantially simultaneously or in the reverse order, depending on the functions involved. For example, the described methods may be performed in a different order than described, and various steps may be added, omitted, or combined. Additionally, features described with reference to certain examples may be combined in other examples.
[0279] From the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of computer software products plus necessary general-purpose hardware platforms, and of course, they can also be implemented by hardware. The computer software product is stored in a storage medium (such as ROM, RAM, magnetic disk, optical disk, etc.) and includes several instructions to cause the terminal or network-side device to execute the methods described in the various embodiments of this application.
[0280] The embodiments of this application have been described above with reference to the accompanying drawings. However, this application is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other implementations under the guidance of this application without departing from the spirit and scope of the claims. All of these implementations are within the protection scope of this application.
Claims
1. A network handover method, applied to a scenario where a terminal switches from a first network device to a second network device, the method comprising: The terminal receives a first key derivation instruction from the first network device; The terminal determines the first key based on the first key derivation instruction; The terminal determines a second key based on the first key and the first parameter, and the second key is used for communication between the terminal and the second network device.
2. The method as described in claim 1, wherein, The first parameter is a parameter that is not transmitted through the first network device.
3. The method as described in claim 1 or 2, wherein, The first parameter includes at least one of the following: Random access preamble identifier; Pre-set the index value of TA periodically; Upward authorization; Temporary Identifier for Cellular Wireless Network (C-RNTI) Scrambling indicator; Terminal location information; Energy state information; The second parameter is determined based on the random access preamble, or the second parameter includes the random access preamble; A first random number or a second random number, wherein the first random number is determined by the terminal and the second random number is determined by the second network device.
4. The method of claim 3, wherein, The method further includes: The terminal sends a third parameter to the second network device; The third parameter includes at least one of the following: The second parameter; The first random number.
5. The method of claim 3, wherein, The method further includes: The terminal receives a fourth parameter from the second network device; The fourth parameter includes at least one of the following: The random access preamble identifier; The index value of the TA; The uplink authorization; The C-RNTI; The scrambling identifier; The terminal location information; The energy state information; The second random number.
6. The method as described in claim 4 or 5, wherein, The third parameter is transmitted via a random access message, and / or the fourth parameter is transmitted via a random access response message.
7. The method according to any one of claims 1-6, wherein, The terminal determines the first key based on the first key derivation instruction, including: When the first key derivation indicator is the next-hop link counter (NCC), the terminal determines the first key based on the NCC, the physical cell identifier (PCI) of the second network device, and the downlink absolute radio frequency channel number of the second network device.
8. A network handover method, applied to a scenario where a terminal switches from a first network device to a second network device, the method comprising: The second network device receives a handover request message from the first network device, the handover request message including a first key; The second network device determines a second key based on the first key and the first parameter, and the second key is used for communication between the terminal and the second network device.
9. The method of claim 8, wherein, The first parameter is a parameter that is not transmitted through the first network device.
10. The method of claim 8 or 9, wherein, The first parameter includes at least one of the following: Random access preamble identifier; Pre-set the index value of TA periodically; Upward authorization; Temporary Identifier for Cellular Wireless Network (C-RNTI) Scrambling indicator; Terminal location information; Energy state information; The second parameter is determined based on the random access preamble, or the second parameter includes the random access preamble; A first random number or a second random number, wherein the first random number is determined by the terminal and the second random number is determined by the second network device.
11. The method of claim 10, wherein, The method further includes: The second network device receives a third parameter from the terminal; The third parameter includes at least one of the following: The second parameter; The first random number.
12. The method of claim 10, wherein, The method further includes: The second network device sends a fourth parameter to the terminal; The fourth parameter includes at least one of the following: The random access preamble identifier; The index value of the TA; The uplink authorization; The C-RNTI; The scrambling identifier; The terminal location information; The energy state information; The second random number.
13. The method of claim 11 or 12, wherein, The third parameter is transmitted via a random access message, and / or the fourth parameter is transmitted via a random access response message.
14. A network handover method, applied to a scenario where a terminal switches from a first network device to a second network device, the method comprising: Before the terminal switches to the second network device, the second network device sends a first request message to the core network device, the first request message being used to request key parameters; The second network device receives a first response message from the core network device, the first response message including the key parameters; The second network device determines a first key based on the key parameters, and the first key is used for communication between the terminal and the second network device.
15. The method of claim 14, wherein, The second network device determines the first key based on the key parameters, including: The second network device determines the first key based on the key parameters, the physical cell identifier of the second network device, and the downlink absolute radio frequency channel number of the second network device.
16. The method of claim 14 or 15, wherein, The key parameters include the next hop NH.
17. The method of any one of claims 14-16, wherein, Before the terminal switches to the second network device, this includes: before the second network device receives the RRC reconfiguration complete message sent by the terminal.
18. The method according to any one of claims 14-17, wherein, The method further includes: The second network device receives a handover request message from the first network device; The second network device sends a handover response message to the first network device, wherein the handover response message corresponds to the handover request message and includes a first key derivation indication related to or corresponding to the first key.
19. The method of claim 18, wherein, The switching request message includes the first key deduction indication; or, the first response message includes the first key deduction indication.
20. The method of claim 18, wherein, The handover request message includes a second key deduction indication, and the first key deduction indication is determined by the second network device based on the second key deduction indication.
21. The method of claim 20, wherein, The first key derivation indication is determined by the second network device based on the second key derivation indication, including: When the first key derivation indication and the second key derivation indication are both the next-hop link counter (NCC), the first key derivation indication is determined by the second network device based on the sum of the second key derivation indication and a predetermined value.
22. A network handover method, applied to a scenario where a terminal switches from a first network device to a second network device, the method comprising: The first network device sends a handover request message to the second network device. The handover request message includes a first key deduction indication, wherein the first key deduction indication is determined based on a second key deduction indication currently stored by the first network device. The first network device receives a handover response message from the second network device; The handover response message corresponds to the handover request message, and the handover response message includes a first key derivation indication.
23. The method of claim 22, wherein, The first key derivation indication is determined based on the second key derivation indication currently stored in the first network device, including: When the first key derivation indication and the second key derivation indication are both the next-hop link counter (NCC), the first key derivation indication is determined based on the sum of the second key derivation indication and a predetermined value.
24. A network switching apparatus, applied in a scenario where a terminal switches from a first network device to a second network device, the apparatus comprising: The transmission module is configured to receive a first key derivation instruction from the first network device; The processing module is configured to determine a first key based on the first key derivation instruction, and to determine a second key based on the first key and a first parameter, wherein the second key is used for communication between the terminal and the second network device.
25. The apparatus of claim 24, wherein, The first parameter is a parameter that is not transmitted through the first network device.
26. The apparatus of claim 24 or 25, wherein, The first parameter includes at least one of the following: Random access preamble identifier; Pre-set the index value of TA periodically; Upward authorization; Temporary Identifier for Cellular Wireless Network (C-RNTI) Scrambling indicator; Terminal location information; Energy state information; The second parameter is determined based on the random access preamble, or the second parameter includes the random access preamble; A first random number or a second random number, wherein the first random number is determined by the terminal and the second random number is determined by the second network device.
27. A network switching apparatus, applied to a scenario where a terminal switches from a first network device to a second network device, the apparatus comprising: The transmission module is configured to receive a handover request message from the first network device, wherein the handover request message includes a first key; The processing module is configured to determine a second key based on the first key and the first parameter, wherein the second key is used for communication between the terminal and the second network device.
28. The apparatus of claim 27, wherein, The first parameter is a parameter that is not transmitted through the first network device.
29. The apparatus of claim 27 or 28, wherein, The first parameter includes at least one of the following: Random access preamble identifier; Pre-set the index value of TA periodically; Upward authorization; Temporary Identifier for Cellular Wireless Network (C-RNTI) Scrambling indicator; Terminal location information; Energy state information; The second parameter is determined based on the random access preamble, or the second parameter includes the random access preamble; A first random number or a second random number, wherein the first random number is determined by the terminal and the second random number is determined by the second network device.
30. A network switching apparatus, applied to a scenario where a terminal switches from a first network device to a second network device, the apparatus comprising: The transmission module is configured to send a first request message to the core network device before the terminal switches to the second network device, wherein the first request message is used to request key parameters; The transmission module is further configured to receive a first response message from the core network device, wherein the first response message includes the key parameters; The processing module is used to determine a first key based on the key parameters, the first key being used for communication between the terminal and the second network device.
31. The apparatus of claim 30, wherein, Determining the first key based on the key parameters includes: The first key is determined based on the key parameters, the physical cell identifier of the second network device, and the downlink absolute radio frequency channel number of the second network device.
32. A network switching apparatus, applied to a scenario where a terminal switches from a first network device to a second network device, the apparatus comprising: The sending module is configured to send a handover request message to the second network device. The handover request message includes a first key deduction indication, wherein the first key deduction indication is determined based on a second key deduction indication currently stored by the first network device. The receiving module is also configured to receive a handover response message from the second network device; The handover response message corresponds to the handover request message, and the handover response message includes a first key derivation indication.
33. The apparatus of claim 32, wherein, The first key derivation indication is determined based on the second key derivation indication currently stored in the first network device, including: When the first key derivation indication and the second key derivation indication are both the next-hop link counter (NCC), the first key derivation indication is determined based on the sum of the second key derivation indication and a predetermined value.
34. A terminal comprising a processor and a memory, the memory storing a program or instructions executable on the processor, the program or instructions, when executed by the processor, implementing the steps of the method as claimed in any one of claims 1 to 7.
35. A network-side device, comprising a processor and a memory, the memory storing a program or instructions executable on the processor, the program or instructions, when executed by the processor, implementing the steps of the method as claimed in any one of claims 8 to 23, or implementing the steps of the method as claimed in any one of claims 14 to 21, or implementing the steps of the method as claimed in any one of claims 22 to 23.
36. A readable storage medium storing a program or instructions that, when executed by a processor, implement the steps of the method as claimed in any one of claims 1 to 7, or the steps of the method as claimed in any one of claims 8 to 13, or the steps of the method as claimed in any one of claims 14 to 21, or the steps of the method as claimed in any one of claims 22 to 23.