Communication method and related apparatus
By generating keys using MAC layer messages and NCC instructions during LTM handover, the security protection of terminal equipment and secondary access network equipment is directly activated, solving the problem of low activation efficiency of security protection during LTM handover and achieving efficient and secure data transmission.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- HUAWEI TECH CO LTD
- Filing Date
- 2026-01-13
- Publication Date
- 2026-07-30
AI Technical Summary
In LTM handover scenarios, how to effectively activate the security protection between the terminal device and the secondary access network device in dual connectivity, especially how to ensure efficient activation and resource conservation of security protection during the handover of the primary access network device.
By utilizing MAC layer messages carrying information and next-hop link counter (NCC) indications during LTM handover, a first key is generated between the terminal device and the secondary access network device, directly activating security protection and avoiding additional information interaction and resource waste.
It improves the efficiency of security protection activation, reduces the processing latency and resource consumption of terminal equipment and secondary access network equipment, and ensures the security of uplink and downlink data transmission.
Smart Images

Figure CN2026072224_30072026_PF_FP_ABST
Abstract
Description
Communication methods and related devices
[0001] This application claims priority to Chinese Patent Application No. 202510127790.8, filed on January 27, 2025, entitled "Communication Method and Related Apparatus", the entire contents of which are incorporated herein by reference. Technical Field
[0002] This application relates to the field of communication technology, and in particular to communication methods and related devices. Background Technology
[0003] Handover is a process that occurs when a terminal device is in a connected state, involving signaling interaction between the terminal device and the access network device. For example, if an access network device senses that the signal strength of the terminal device in its own cell is gradually weakening, it can switch the terminal device to the cell of an access network device with a stronger signal (e.g., a neighboring access network device).
[0004] To reduce handover latency, L1 / L2 triggered mobility (LTM) handover has been introduced, which can be triggered by L1 / L2 signaling.
[0005] However, for LTM handover scenarios, how to activate the security protection between the terminal device and the secondary access network device in the dual connectivity when the primary access network device in the dual connectivity of the terminal device is switched still needs further research. Summary of the Invention
[0006] This application discloses a communication method and related apparatus, which can be used to activate security protection between a terminal device and a secondary access network device in a dual-connectivity scenario during LTM handover.
[0007] The first aspect discloses a communication method that can be applied to a terminal device, a module (e.g., a processor or chip) within the terminal device, or a logic module or software capable of implementing all or part of the terminal device's functions. The following description, using an application to a terminal device as an example, includes: receiving first information from a first access network device, the first information being used to switch the primary access network device in a dual-connection configuration of the terminal device from the first access network device to a third access network device; and activating security protection between the terminal device and a second access network device, the second access network device being a secondary access network device corresponding to the third access network device, based on the first information.
[0008] In this embodiment, the terminal device can receive first information from the first access network device (serving primary access network device). Then, the terminal device can activate security protection between itself and the second access network device (secondary access network device) based on the first information, thereby ensuring the security of uplink and downlink transmissions between the terminal device and the second access network device. It is understood that in the above method, after receiving the first information from the first access network device, the terminal device can activate security protection between itself and the second access network device based on the first information, without needing subsequent information / interactions to trigger the activation of security protection between the terminal device and the second access network device (e.g., without needing to receive a radio resource control (RRC) reconfiguration message carrying the secondary access network device counter (e.g., secondary node counter, SN counter) from the third access network device, and trigger the activation of security protection between the terminal device and the second access network device through this RRC reconfiguration message). This method can improve the efficiency of security protection activation on the terminal device side and save resources.
[0009] For example, the primary access network device can also be called the master node (MN) or the primary base station, and the secondary access network device can also be called the secondary node (SN) or the secondary base station.
[0010] In conjunction with the first aspect, in one possible implementation, the method further includes: receiving information for indicating a next-hop link counter (NCC); generating a first key between the terminal device and the second access network device based on the NCC, the first key being used for security protection between the terminal device and the second access network device and being a shared key between the terminal device and the second access network device.
[0011] In this embodiment of the application, the terminal device can also receive information for instructing the NCC, thereby accurately determining the first key between the terminal device and the second access network device based on the NCC indicated by the information, and thus realizing security protection between the terminal device and the second access network device.
[0012] For example, the first key is obtained based on the key corresponding to the third access network device (such as the KgNB between the third access network device and the terminal device). The first key can be used for security protection between the terminal device and the second access network device when the third access network device is the primary access network device in a dual connection of the terminal device. The first key is used to securely protect the connection between the terminal device and the second access network device, such as to securely protect control plane signaling and / or user plane data transmitted through the connection.
[0013] For example, the first key can be a secondary access network device key (denoted as Ksn) between the terminal device and the second access network device (secondary access network device). Ksn can be used to generate an RRC key and / or a user plane (UP) key between the terminal device and the second access network device. The RRC key can be used for the security protection of control plane signaling between the terminal device and the second access network device, and the UP key can be used for the security protection of user plane data between the terminal device and the second access network device.
[0014] In conjunction with the first aspect, in one possible implementation, the first information and the information for instructing the NCC may be carried in the same message or in different messages.
[0015] In conjunction with the first aspect, in one possible implementation, the first information and / or the information for instructing the NCC is carried in a first Media Access Control (MAC) layer message.
[0016] In this embodiment of the application, since MAC layer messages are low-level messages in the communication protocol stack (below the RRC layer), they require less processing. Therefore, carrying the first information and / or the information used to indicate NCC through MAC layer messages can further improve the efficiency of security protection activation on the terminal device side and save processing resources.
[0017] In conjunction with the first aspect, in one possible implementation, the first information includes one or more of the following: the identifier of the third access network device, the index of the configuration of the third access network device, the identifier of the candidate cell in the cell served by the third access network device, and the index of the configuration of the candidate cell in the cell served by the third access network device.
[0018] In conjunction with the first aspect, in one possible implementation, the method further includes: receiving second information of each of a plurality of candidate primary access network devices, the plurality of candidate access network devices including the third access network device; and accessing the third access network device in response to the first information based on the second information of the third access network device.
[0019] In this embodiment, the terminal device can first obtain the second information of each of the multiple candidate primary access network devices. If the terminal device subsequently needs to switch to a third access network device among the multiple candidate primary access network devices, the first access network device sends first information to the terminal device. Correspondingly, the terminal device receives this first information and can use the previously received second information of the third access network device to access the third access network device. This eliminates the need to obtain relevant information from the third access network device again during the handover, reducing the latency of the terminal device switching to the third access network device. For example, the terminal device can obtain the second information of each of the multiple candidate primary access network devices during the LTM handover preparation phase, and then, during the LTM handover execution phase, access the third access network device based on the second information of the third access network device obtained during the LTM handover preparation phase.
[0020] For example, the second information for each candidate primary access network device may include parameters for the terminal device to switch to each candidate primary access network device.
[0021] Accessing the third access network device based on the second information of the third access network device can be achieved by: switching the primary access network device from the first access network device to the third access network device based on the second information of the third access network device.
[0022] In conjunction with the first aspect, in one possible implementation, the method further includes: receiving third information from the second access network device; and, in response to the first information, accessing the second access network device based on the third information.
[0023] In this embodiment, the terminal device can first obtain the third information of the second access network device (secondary access network device). If the terminal device subsequently needs to switch to the third access network device among multiple candidate access network devices, the first access network device sends first information to the terminal device. The terminal device receives this first information and can use the previously received third information of the second access network device to access the second access network device. This eliminates the need to obtain relevant information from the second access network device again during the handover, reducing the latency of the terminal device accessing the second access network device. For example, the terminal device can obtain the third information of the secondary access network device corresponding to each candidate primary access network device during the LTM handover preparation phase. Then, during the LTM handover execution phase, it accesses the second access network device based on the second information of the secondary access network device (i.e., the second access network device) corresponding to the third access network device obtained during the LTM handover preparation phase.
[0024] For example, the third information of the second access network device includes parameters for the terminal device to access the second access network device.
[0025] In conjunction with the first aspect, in one possible implementation, the method further includes: receiving second information of each of a plurality of candidate primary access network devices, the plurality of candidate primary access network devices including the third access network device, the second information of the third access network device including third information of the second access network device; in response to the first information, accessing the third access network device according to the second information of the third access network device; and in response to the first information, accessing the second access network device according to the third information of the second access network device.
[0026] In this embodiment, the terminal device can first obtain the second information of each of the multiple candidate primary access network devices. If the terminal device subsequently needs to switch to a third access network device among the multiple candidate primary access network devices, the first access network device sends first information to the terminal device. Correspondingly, the terminal device receives this first information and can use the previously received second information of the third access network device to access the third access network device, and can also use the third information of the second access network device included in the previously received second information of the third access network device to access the second access network device. This eliminates the need to obtain relevant information from the third and second access network devices again during the switch, thereby reducing the latency of switching to the third access network device and reducing the latency of accessing the second access network device.
[0027] For example, the second information of each candidate primary access network device may include parameters for the terminal device to switch to each candidate primary access network device. The second information of each candidate primary access network device may also include third information of the secondary access network device corresponding to each candidate primary access network device, and the third information of the secondary access network device corresponding to each candidate primary access network device includes parameters for the terminal device to access the secondary access network device corresponding to each candidate primary access network device.
[0028] The second aspect discloses a communication method, which can be applied to a second access network device, a module (e.g., a processor or chip) within the second access network device, or a logic module or software capable of implementing all or part of the functions of the second access network device. The following description uses an application to a second access network device as an example. The communication method may include: receiving uplink data from a terminal device, the uplink data being securely protected based on a first key between the terminal device and the second access network device; caching the uplink data if the first key is not present in the second access network device; receiving the first key from a third access network device, the third access network device being the primary access network device in a dual-connection configuration of the terminal device, and the second access device being the secondary access network device corresponding to the third access network device; and performing secure processing on the cached uplink data based on the first key.
[0029] In existing technologies, if a second access network device receives secure uplink data from a terminal device but lacks the shared first key, it cannot perform secure processing on the uplink data and will discard it, resulting in data loss. In this case, the terminal device may need to retransmit the uplink data, leading to wasted data transmission resources. In this embodiment, when the second access network device receives uplink data from the terminal device, if it does not possess the first key, it can cache the uplink data. Later, after receiving the first key from the third access network device, it can then perform secure processing on the previously cached uplink data based on the first key. This achieves secure data transmission while preventing uplink data loss and avoiding wasted data transmission resources.
[0030] For example, "the first key does not exist in the second access network device" can also be replaced with the following: the second access network device does not store the first key locally, or the keys stored locally by the second access network device do not include the first key, or the second access network device has not received the first key.
[0031] Furthermore, in the above method, after the second access network device receives the first key from the third access network device, it can activate the security protection between the terminal device and the second access network device. Based on the first key, it can perform secure processing on the cached uplink data. There is no need to trigger the second access network device to activate the security protection between the terminal device and the second access network device through other information / interactions (such as not needing to receive the SN configuration completion message from the third access network device to indicate that the terminal device has completed configuration, and trigger the terminal device to activate the security protection between the terminal device and the second access network device through the SN configuration completion message). This method can improve the efficiency of security protection activation on the second access network device side and save resources.
[0032] In conjunction with the second aspect, in one possible implementation, the method further includes: sending third information of the second access network device, the third information being used to configure resources for sending uplink data; and caching the uplink data including: if the resources used for sending the uplink data match the resources configured in the third information, caching the uplink data.
[0033] In this embodiment, the second access network device can configure parameters and / or resources for transmitting uplink data for the terminal device during the LTM handover preparation phase. Then, if the second access network device does not have the first key, it can cache the corresponding uplink data if the received uplink data was sent using the parameters and / or resources configured during the LTM handover preparation phase. If the received uplink data was not sent using the parameters and / or resources configured during the LTM handover preparation phase, it does not need to cache the corresponding uplink data. In this way, while caching the necessary uplink data, the storage space of the second access network device can be saved, and the caching pressure of the second access network device can be reduced.
[0034] In conjunction with the second aspect, in one possible implementation, the third access network device is the primary access network device after the terminal device is switched over, and the first access network device is the primary access network device before the terminal device is switched over. Before receiving uplink data from the terminal device, the method further includes: receiving a second message from the first access network device, the second message indicating the release of the connection between the terminal device and the second access network device, the connection being established when the first access network device is the primary access network device in a dual connection of the terminal device; and in response to the second message, deleting a second key between the terminal device and the second access network device, the second key being used for security protection between the terminal device and the second access network device.
[0035] For example, the second key is obtained based on the key corresponding to the first access network device (such as the KgNB between the first access network device and the terminal device). The second key can be used for security protection between the terminal device and the second access network device when the first access network device is the primary access network device in a dual connection of the terminal device. The second key is used for security protection of this connection (such as the connection between the terminal device and the second access network device in a dual connection), and is used to protect the signaling and / or data transmitted through this connection.
[0036] In conjunction with the second aspect, in one possible implementation, the method further includes: activating security protection between the second access network device and the terminal device based on the first key.
[0037] In this embodiment of the application, after receiving the first key, the second access network device can activate the security protection between the terminal device and the second access network device (secondary access network device) based on the first key, thereby ensuring the security of uplink and downlink transmission between the terminal device and the second access network device.
[0038] In conjunction with the second aspect, in one possible implementation, the method further includes: performing security protection on the downlink data of the terminal device according to the first key to obtain the security-protected downlink data; and sending the security-protected downlink data to the terminal device.
[0039] The third aspect discloses a communication method that can be applied to a terminal device, a module (e.g., a processor or chip) within the terminal device, or a logic module or software capable of implementing all or part of the terminal device's functions. The following description, using an application to a terminal device as an example, includes: receiving first information from a first access network device, the first information being used to switch the primary access network device in a dual-connection configuration of the terminal device from the first access network device to a third access network device; receiving fourth information, the fourth information being used to instruct the activation of security protection between the terminal device and a second access network device, the second access network device being a secondary access network device corresponding to the third access network device; activating security protection between the terminal device and the second access network device in response to the fourth information; or receiving downlink data from the second access network device, the second access network device being a secondary access network device corresponding to the third access network device; activating uplink security protection between the terminal device and the second access network device in response to the downlink data.
[0040] In this embodiment, the terminal device can receive first information from a first access network device (serving primary access network device). After receiving the first information, in response to received fourth information or downlink data from a second access network device, the terminal device can activate security protection between the terminal device and the second access network device (secondary access network device), thereby ensuring the security of uplink and downlink transmission between the terminal device and the second access network device. It is understood that in the above method, after the terminal device receives the fourth information from the first access network device, it can activate the security protection between the terminal device and the second access network device, without needing subsequent activation of the security protection through other information / interactions. This method can improve the efficiency of security protection activation on the terminal device side and save resources.
[0041] In conjunction with the third aspect, in one possible implementation, the method further includes: receiving information for indicating a next-hop link counter (NCC); and generating a first key between the terminal device and the second access network device based on the NCC, the first key being used for security protection between the terminal device and the second access network device.
[0042] For example, the first key is obtained based on the key corresponding to the third access network device (such as the KgNB between the third access network device and the terminal device). The first key can be used for security protection between the terminal device and the second access network device when the third access network device is the primary access network device in a dual connection of the terminal device. The first key is used to securely protect the connection between the terminal device and the second access network device, such as to securely protect control plane signaling and / or user plane data transmitted through the connection.
[0043] In conjunction with the third aspect, in one possible implementation, the fourth information comes from the second access network device or the third access network device.
[0044] In this embodiment, the sender of the fourth information is flexible and can be either a second access network device or a third access network device. For example, the second access network device can send the fourth information to the terminal device after receiving the first key between the terminal device and the second access network device, or it can send the fourth information to the terminal device after receiving the first key and activating the security protection between itself and the terminal device. Similarly, the third access network device can send the fourth information to the terminal device after sending the key to the second access network device.
[0045] Normally, after the terminal device activates security protection with the second access network device, it will securely protect the uplink data sent to the second access network device according to the first key. If the second access network device receives the securely protected uplink data but does not have the first key to securely process it, it will discard the uplink data, resulting in uplink data loss. The aforementioned fourth piece of information ensures that the terminal device activates security protection no earlier than the second access network device receives the first key. Thus, when the second access network device receives the securely protected uplink data from the terminal device, it has the first key for securely processing the uplink data, thereby preventing uplink data loss.
[0046] In conjunction with the third aspect, in one possible implementation, the downlink data is data that has been securely protected based on a first key between the terminal device and the second access network device. After receiving the downlink data from the second access network device, the method further includes: performing secure processing on the downlink data based on the first key.
[0047] In conjunction with the third aspect, in one possible implementation, the security protection includes integrity protection, the security processing includes integrity verification, and the activation of uplink security protection between the terminal device and the second access network device in response to the downlink data includes: activating uplink security protection between the terminal device and the second access network device if the integrity verification for the downlink data passes.
[0048] In this embodiment of the application, if the terminal device passes the integrity verification of the downlink data, it indicates that the second access network device has activated the security protection between itself and the terminal device. If the terminal device receives the secure uplink data, it can perform secure processing. Therefore, the terminal device can activate the uplink security protection between itself and the second access network device to protect the uplink data, ensuring the secure transmission of the uplink data while preventing uplink data loss.
[0049] In conjunction with the third aspect, in one possible implementation, the fourth information used to indicate the activation of security protection between the terminal device and the second access network device includes: the fourth information used to indicate the activation of uplink security protection between the terminal device and the second access network device; the activation of security protection between the terminal device and the second access network device in response to the fourth information includes: activating uplink security protection between the terminal device and the second access network device in response to the fourth information; the method further includes: activating downlink security protection between the terminal device and the second access network device according to the first key in response to the first information.
[0050] In this embodiment of the application, the terminal device can respond to the first information and activate the downlink security protection between the terminal device and the second access network device to ensure the security of downlink transmission between the terminal device and the second access network device more quickly.
[0051] In conjunction with the third aspect, in one possible implementation, the fourth information is information that has been securely protected based on the first key. After receiving the fourth information, the method further includes: performing secure processing on the fourth information based on the first key.
[0052] In this embodiment of the application, the fourth information is protected by the first key, which can ensure the security of the security protection activation between the terminal device and the second access network device.
[0053] In conjunction with the third aspect, in one possible implementation, after receiving the first information from the first access network device and before receiving the fourth information or the downlink data, the method further includes: caching uplink data; activating security protection between the terminal device and the second access network device, including: performing security protection on the cached uplink data according to a first key between the terminal device and the second access network device; and sending the security-protected uplink data to the second access network device.
[0054] In this embodiment of the application, after receiving the first information from the first access network device and before receiving the fourth information or the downlink data, the terminal device may first cache the uplink data to be sent to the second access network device, and then send the uplink data after security protection is activated, so as to ensure the security of uplink transmission with the second access network device.
[0055] In conjunction with the third aspect, in one possible implementation, the first information and the information used to instruct the NCC can be carried in the same message or in different messages.
[0056] In conjunction with the third aspect, in one possible implementation, the first information and / or the information for instructing the NCC is carried in a first MAC layer message.
[0057] In conjunction with the third aspect, in one possible implementation, the first information includes one or more of the following: the identifier of the third access network device, the index of the configuration of the third access network device, the identifier of the candidate cell in the cell served by the third access network device, and the index of the configuration of the candidate cell in the cell served by the third access network device.
[0058] In conjunction with the third aspect, in one possible implementation, the method further includes: receiving second information of each of a plurality of candidate primary access network devices, the plurality of candidate access network devices including the third access network device; and accessing the third access network device in response to the first information based on the second information of the third access network device.
[0059] For example, the second information of each candidate primary access network device may include parameters for the terminal device to switch to each candidate primary access network device. Accessing the third access network device based on the second information of the third access network device can be: switching the primary access network device from the first access network device to the third access network device based on the second information of the third access network device.
[0060] In conjunction with the third aspect, in one possible implementation, the method further includes: receiving third information from the second access network device; and, in response to the first information, accessing the second access network device based on the third information.
[0061] For example, the third information of the second access network device includes parameters for the terminal device to access the second access network device.
[0062] In conjunction with the third aspect, in one possible implementation, the method further includes: receiving second information of each of a plurality of candidate primary access network devices, the plurality of candidate primary access network devices including the third access network device, the second information of the third access network device including third information of the second access network device; in response to the first information, accessing the third access network device according to the second information of the third access network device; and in response to the first information, accessing the second access network device according to the third information of the second access network device.
[0063] For example, the second information of each candidate primary access network device may include parameters for the terminal device to switch to each candidate primary access network device. The second information of each candidate primary access network device may also include third information of the secondary access network device corresponding to each candidate primary access network device, and the third information of the secondary access network device corresponding to each candidate primary access network device includes parameters for the terminal device to access the secondary access network device corresponding to each candidate primary access network device.
[0064] The fourth aspect discloses a communication method that can be applied to a second access network device, a module (e.g., a processor or chip) within the second access network device, or a logic module or software capable of implementing all or part of the functions of the second access network device. The following description uses an application to a second access network device as an example. The communication method may include: after receiving a first key between a terminal device and the second access network device from a third access network device, sending fourth information to the terminal device. This fourth information is used to indicate the activation of security protection between the terminal device and the second access network device. The third access network device is the primary access network device in a dual-connection configuration of the terminal device, and the second access network device is the secondary access network device corresponding to the third access network device. The first key is used for security protection between the terminal device and the second access network device.
[0065] Normally, after the terminal device activates the security protection between itself and the second access network device, it will protect the uplink data sent to the second access network device according to the first key. If the second access network device receives the protected uplink data but does not have the first key to securely process it, it will discard the uplink data, resulting in uplink data loss. In this embodiment, after receiving the first key from the third access network device, the second access network device sends fourth information to the terminal device, triggering the terminal device to activate the security protection between itself and the second access network device. This ensures that the terminal device activates the security protection no earlier than the second access network device receives the first key. Thus, when the second access network device receives the protected uplink data from the terminal device, it has the first key for securely processing the uplink data, preventing uplink data loss.
[0066] In conjunction with the fourth aspect, in one possible implementation, the method further includes: activating security protection between the second access network device and the terminal device based on the first key.
[0067] In this embodiment, after receiving the first key, the second access network device can activate the security protection between the terminal device and the second access network device based on the first key. There is no need to trigger the second access network device to activate the security protection between the terminal device and the second access network device through other information / interactions (such as not needing to receive the SN configuration completion message from the third access network device to indicate that the terminal device has completed configuration, and trigger the terminal device to activate the security protection between the terminal device and the second access network device through the SN configuration completion message). This method can improve the efficiency of security protection activation on the second access network device side and save resources.
[0068] In addition, after activating the security protection between the second access network device and the terminal device, the second access network device can send a fourth message to the terminal device to trigger the terminal device to activate the security protection between the terminal device and the second access network device. In this way, the security protection of the terminal device can be activated after the security protection of the second access network device is activated, thereby avoiding the loss of uplink data due to the second access network device's inability to process correctly.
[0069] In conjunction with the fourth aspect, in one possible implementation, sending the fourth information to the terminal device includes: sending the fourth information to the terminal device when there is no downlink data to be sent to the terminal device.
[0070] In this embodiment, after activating the security protection between the terminal device and the second access network device, if there is downlink data to be sent to the terminal device, the second access network device can perform security protection on the downlink data according to the first key, and then send the security-protected downlink data to the terminal device. This security-protected downlink data can be used to trigger the terminal device to activate the security protection between itself and the second access network device according to the first key. If there is no downlink data to be sent to the terminal device, the second access network device can send a fourth message to the terminal device to trigger the terminal device to activate the security protection between itself and the second access network device according to the first key. This saves transmission resources.
[0071] The fifth aspect discloses a communication method that can be applied to a third access network device, a module (e.g., a processor or chip) within the third access network device, or a logic module or software capable of implementing all or part of the functions of the third access network device. The following description uses an application to a third access network device as an example. The communication method may include: receiving a first message from a first access network device, the first message indicating a switch in dual-connection of a terminal device from the first access network device to the third access network device; sending a first key between the terminal device and the second access network device to the second access network device, the second access network device being a secondary access network device corresponding to the third access network device, the first key being used for security protection between the terminal device and the second access network device; and after sending the first key to the second access network device, sending fourth information to the terminal device, the fourth information indicating activation of security protection between the terminal device and the second access network device.
[0072] Normally, after the terminal device activates the security protection between itself and the second access network device, it will protect the uplink data sent to the second access network device according to the first key. If the second access network device receives the protected uplink data but does not have the first key to securely process it, it will discard the uplink data, resulting in uplink data loss. In this embodiment, after the third access network device sends the first key to the second access network device, it sends fourth information to the terminal device to trigger the terminal device to activate the security protection between itself and the second access network device. This ensures that the terminal device activates the security protection no earlier than the second access network device receives the first key. Thus, when the second access network device receives the protected uplink data from the terminal device, it has the first key for securely processing the uplink data, preventing uplink data loss.
[0073] In conjunction with the fifth aspect, in one possible implementation, the first message includes a key between the terminal device and the third access network device; the method further includes: determining the first key based on the key between the terminal device and the third access network device.
[0074] It should be noted that the technical solutions of the first, second, third, fourth and fifth aspects of this application correspond to each other, and the relevant beneficial effects can be referred to each other.
[0075] The sixth aspect discloses a communication device for performing the methods described in the first or third aspect and any possible implementation of the first or third aspect. For example, the communication device includes a module or unit for performing the methods described in the first aspect or any possible implementation of the first aspect, or the communication device includes a module or unit for performing the methods described in the third aspect or any possible implementation of the third aspect. The module or unit can be implemented by software, by hardware, or by a combination of software and hardware.
[0076] For example, the communication device disclosed in the sixth aspect above may be a terminal device or a chip in a terminal device.
[0077] The seventh aspect discloses a communication device for performing the methods described in the second or fourth aspect and any possible implementation of the second or fourth aspect. For example, the communication device includes a module or unit for performing the methods described in the second aspect or any possible implementation of the second aspect, or the communication device includes a module or unit for performing the methods described in the fourth aspect or any possible implementation of the fourth aspect. The module or unit can be implemented by software, by hardware, or by a combination of software and hardware.
[0078] For example, the communication device disclosed in the seventh aspect above may be a second access network device or a chip in the second access network device.
[0079] The eighth aspect discloses a communication device for performing the methods of the fifth aspect and any possible implementation of the fifth aspect. For example, the communication device includes a module or unit for performing the methods of the fifth aspect or any possible implementation of the fifth aspect. The module or unit can be implemented by software, by hardware, or by a combination of software and hardware.
[0080] For example, the communication device disclosed in the eighth aspect above may be a third access network device or a chip in a third access network device.
[0081] The ninth aspect discloses a communication system comprising a terminal device and a second access network device, the terminal device being configured to implement the methods provided in the first aspect and any possible embodiments thereof, and the second access network device being configured to implement the methods provided in the second aspect and any possible embodiments thereof.
[0082] The tenth aspect discloses a communication system comprising a terminal device and a second access network device, the terminal device being configured to implement the methods provided in the third aspect and any possible embodiments thereof, and the second access network device being configured to implement the methods provided in the fourth aspect and any possible embodiments thereof.
[0083] The eleventh aspect discloses a communication system comprising a terminal device and a third access network device, the terminal device being configured to implement the methods provided in the third aspect and any possible embodiments thereof, and the third access network device being configured to implement the methods provided in the fifth aspect and any possible embodiments thereof.
[0084] The twelfth aspect discloses a communication device, including a processor and a communication interface; the communication interface is used to receive and / or transmit data; the processor invokes a computer program or computer instructions stored in a memory to implement the methods provided in the first aspect and any possible embodiments thereof, or to implement the methods provided in the second aspect and any possible embodiments thereof, or to implement the methods provided in the third aspect and any possible embodiments thereof, or to implement the methods provided in the fourth aspect and any possible embodiments thereof, or to implement the methods provided in the fifth aspect and any possible embodiments thereof.
[0085] As one possible implementation, the communication device disclosed in the twelfth aspect above may include one or more processors.
[0086] Optionally, the communication device disclosed in the eleventh aspect above may further include one or more memories.
[0087] The thirteenth aspect discloses a computer-readable storage medium storing a computer program or computer instructions that, when executed, implement the methods provided in the first aspect and any possible embodiments thereof, or implement the methods provided in the second aspect and any possible embodiments thereof, or implement the methods provided in the third aspect and any possible embodiments thereof, or implement the methods provided in the fourth aspect and any possible embodiments thereof, or implement the methods provided in the fifth aspect and any possible embodiments thereof.
[0088] The fourteenth aspect discloses a chip including a processor for executing a program stored in a memory, wherein when the program is executed, the chip performs the methods provided in the first aspect and any possible embodiments thereof, or performs the methods provided in the second aspect and any possible embodiments thereof, or performs the methods provided in the third aspect and any possible embodiments thereof, or performs the methods provided in the fourth aspect and any possible embodiments thereof, or performs the methods provided in the fifth aspect and any possible embodiments thereof.
[0089] As one possible implementation, the memory is located outside the chip.
[0090] The fifteenth aspect discloses a computer program product comprising computer program code that, when executed, causes the methods provided in the first aspect and any possible embodiments thereof to be performed, or causes the methods provided in the second aspect and any possible embodiments thereof to be performed, or causes the methods provided in the third aspect and any possible embodiments thereof to be performed, or causes the methods provided in the fourth aspect and any possible embodiments thereof to be performed, or causes the methods provided in the fifth aspect and any possible embodiments thereof to be performed.
[0091] It should be understood that the implementation and beneficial effects of the above-mentioned aspects or any possible implementation methods of this application can be referred to each other. Attached Figure Description
[0092] The accompanying drawings are provided to more clearly illustrate the technical solutions of the embodiments of this application. The drawings used in the following description of the embodiments will be briefly introduced. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0093] Figure 1 is a schematic diagram of a service-oriented architecture of a network disclosed in an embodiment of this application;
[0094] Figure 2 is a schematic diagram of the process of key deduction performed by an access network device and a terminal device according to an embodiment of this application;
[0095] Figure 3 is a schematic diagram of an LTM cross-site handover process disclosed in an embodiment of this application;
[0096] Figure 4 is a schematic diagram of the security protection activation process between a terminal device and an SN disclosed in an embodiment of this application;
[0097] Figure 5 is a flowchart illustrating a communication method disclosed in an embodiment of this application;
[0098] Figure 6 is a flowchart illustrating another communication method disclosed in an embodiment of this application;
[0099] Figure 7 is a flowchart illustrating another communication method disclosed in an embodiment of this application;
[0100] Figure 8 is a flowchart illustrating another communication method disclosed in an embodiment of this application;
[0101] Figure 9 is a flowchart illustrating another communication method disclosed in an embodiment of this application;
[0102] Figure 10 is a flowchart illustrating another communication method disclosed in an embodiment of this application;
[0103] Figure 11 is a flowchart illustrating another communication method disclosed in an embodiment of this application;
[0104] Figure 12 is a flowchart illustrating another communication method disclosed in an embodiment of this application;
[0105] Figure 13 is a flowchart illustrating another communication method disclosed in an embodiment of this application;
[0106] Figure 14 is a schematic diagram of the structure of a communication device disclosed in an embodiment of this application;
[0107] Figure 15 is a schematic diagram of the hardware structure of a communication device disclosed in an embodiment of this application. Detailed Implementation
[0108] This application discloses a communication method and related apparatus, which can be used to activate security protection between terminal equipment and secondary access network equipment in LTM handover scenarios. The technical solutions in this application will be clearly and completely described below with reference to the accompanying drawings.
[0109] The technical solutions provided in this application can be applied to various communication systems, such as 5th generation (5G) or new radio (NR) systems, long term evolution (LTE) systems, LTE frequency division duplex (FDD) systems, and LTE time division duplex (TDD) systems. The technical solutions provided in this application can also be applied to future communication systems, as well as Internet of Things (IoT) communication systems or other communication systems.
[0110] Please refer to Figure 1, which is a schematic diagram of a service-oriented architecture for a network disclosed in an embodiment of this application. The service-oriented architecture in Figure 1 can be a service-oriented architecture for a 5G network; however, it should be understood that the 5G network described herein is merely an example and should not constitute any limitation on this application. As shown in Figure 1, the network architecture may include, but is not limited to, the following network elements (or functional network elements, functional entities, nodes, devices, etc.): (radio)access network (R)AN), access and mobility management function (AMF) network elements, session management function (SMF) network elements, user plane function (UPF) network elements, policy control function (PCF) network elements, unified data management (UDM) network elements, application function (AF) network elements, data network (DN), authentication server function (AUSF) network elements, network slice selection function (NSSF) network elements, network exposure function (NEF) network elements, network repository function (NRF) network elements, unified data repository (UDR), service communication proxy (SCP), etc.
[0111] The following is a brief introduction to each network element shown in Figure 1:
[0112] Terminal equipment, also known as user equipment (UE), terminal, mobile station (MS), mobile terminal (MT), customer premise equipment (CPE), etc., is a device with wireless communication capabilities that can provide users with voice and / or data connectivity services. Terminal devices can include handheld terminals, laptops, RSUs (roadside units), subscriber units, cellular phones, smartphones, wireless data cards, personal digital assistant (PDA) computers, tablet computers, tags, wireless modems, other processing devices connected to wireless modems, handheld devices, laptop computers, cordless phones or wireless local loop (WLL) stations, machine-type communication (MTC) terminals, wearable devices (such as smartwatches, smart bracelets, pedometers, etc.), in-vehicle equipment (such as cars, bicycles, electric vehicles, airplanes, ships, trains, high-speed trains, etc.), virtual reality (VR) devices, augmented reality (AR) devices, wireless terminals in industrial control, smart home devices (such as refrigerators, televisions, air conditioners, electricity meters, etc.), intelligent robots, workshop equipment, wireless terminals in self-driving vehicles, and remote medical devices. Wireless terminals can be used in various applications, including smart grids, transportation safety, smart cities, smart homes, flying devices (such as intelligent robots, hot air balloons, drones, and airplanes), or other network-connected devices. Terminal devices can be fixed or mobile, deployed on land (indoors or outdoors, handheld, wearable, or vehicle-mounted), on water (such as ships), or in the air (e.g., on airplanes, balloons, and satellites).
[0113] It should be understood that a terminal device can be any device capable of accessing a network. Terminal devices and access network devices can communicate with each other using some form of air interface technology.
[0114] In this embodiment of the application, the terminal device may refer to a module or unit in the terminal device, such as a chip in the terminal device.
[0115] A Radio Access Network (RAN) can be a network composed of multiple RAN nodes, used to implement functions such as radio resource management, quality of service (QoS) management, data compression, and encryption on the air interface side. The RAN can connect to the User Plane Interface (N3) and the UPF to transmit data from terminal devices. The RAN can also establish control plane signaling connections with the Access and AMF via the Control Plane Interface (N2) to implement functions such as radio access bearer control. It should be understood that RAN nodes are also access network devices, primarily providing access for terminal devices. Access network devices can include radio access network (RAN) devices and access node (AN) devices. RAN devices are mainly wireless network devices in the 3rd Generation Partnership Project (3GPP) network, while AN devices can be access network devices not defined by 3GPP. RAN devices can include various types of base stations, such as macro base stations, micro base stations (also known as small cells), relay stations, access points, and balloon stations. For example, RAN equipment can be a next-generation NodeB (gNB) or ng-eNB (a 4G base station accessing the 5G core network) in a 5th generation (5G) mobile communication system. Radio access network equipment can also be a radio controller in a cloud radio access network (CRAN) scenario, base station equipment in future networks, radio access network equipment in a future evolved public land mobile network (PLMN) network, wearable devices, vehicle-mounted equipment, transmission and reception points (TRPs), radio network controllers (RNCs), home base stations (e.g., home evolved NodeBs or home Node Bs, HNBs), base band units (BBUs), and access points (APs) in wireless fidelity (WiFi) systems.
[0116] In some deployments, such as open RAN (O-RAN) or ORAN systems, access network equipment (e.g., gNB) may include centralized units (CUs) and distributed units (DUs). Access network equipment may also include radio units (RUs). Access network equipment can communicate with the core network (CN) via a backhaul link and with the user equipment (UE) via an air interface (e.g., Uu interface). For example, the baseband unit (BBU) in the access network equipment can communicate with the core network via a backhaul link, and the radio unit can communicate with the UE via an air interface. Furthermore, the BBU can communicate with the RU via a fronthaul link; the BBU and RU may or may not be co-located. The BBU may include at least one centralized unit (CU) and at least one distributed unit (DU), and the CU and DU can communicate via a midhaul link. The CU can implement some of the functions of the access network equipment, the DU can implement some of the functions of the access network equipment, and the CU can be used to control the operation of one or more DUs. For example, the CU can implement the functions of the radio resource control (RRC) and packet data convergence protocol (PDCP) layers, as well as the service data adaptation protocol (SDAP) layer. The DU can implement the functions of the radio link control (RLC) and media access control (MAC) layers, and can also implement some or all physical layer (PHY) layer functions (such as the higher physical layer). The RU can be used to implement some physical layer functions (such as the lower physical layer) and radio frequency functions. For descriptions of the above protocol layers, please refer to the relevant technical specifications of the 3rd Generation Partnership Project (3GPP).
[0117] In some examples, the CU can be split into the CU-control plane (CU-CP) and the CU-user plane (CU-UP). It should be understood that the above configuration of CU and DU is merely an example, and the functions of CU and DU can be configured as needed. This application embodiment does not limit this.
[0118] In some possible implementations, the O-RAN system may also include a RAN intelligent controller (RIC). RICs can be divided into near-real-time RICs (near-RT RICs / nRT RICs) and non-real-time RICs (non-RT RICs / NRT RICs). Near-real-time RICs refer to the near-real-time portion, primarily used for near-real-time intelligent management of the RAN. Near-real-time RICs can achieve near-real-time control and optimization of O-RAN modules and resources through data collection and related operations. Non-real-time RICs refer to the non-real-time portion, primarily used for non-real-time intelligent management of RAN functions. Non-real-time RICs can implement AI / machine learning (ML) workflows, including model training and model updates. More detailed information about open radio access networks (such as interfaces) can be found in the relevant standards and will not be elaborated upon here.
[0119] It is understood that in some possible implementations, the access network device may be a CU, DU, CU-CP, CU-UP, RU, etc., or may be a device including at least one of CU, DU, CU-CP, CU-UP, RU, etc.
[0120] AMF is primarily responsible for mobility management in mobile networks, such as user location updates, user network registration, and user handover.
[0121] In some possible implementations, the aforementioned AMF, SMF, UPF, UDM, AF, AUSF, NSSF, PCF, NEF, etc., can be collectively referred to as core network elements. The core network can include a user plane (UP) and a control plane (CP). The user plane can include UPF, and the control plane can include AMF, SMF, PCF, UDM, NEF, etc.
[0122] In the network architecture shown in Figure 1, network elements can communicate with each other through the interfaces shown in the figure. For the specific meanings of the service interfaces such as Nnssf, Nausf, Nnef, Namf, Npcf, Nsmf, Nudm, and Naf, as well as related interfaces such as N1, N2, N3, N4, and N6 in Figure 1, please refer to the relevant content in the 3GPP standard protocols; no further restrictions are imposed here.
[0123] It should be understood that the architecture shown in Figure 1 is merely an illustrative example, and other devices / network elements may also be included in the architecture shown in Figure 1. This application embodiment does not limit this.
[0124] It should also be understood that the aforementioned terminal devices, network elements, or functions can be implemented in the form of hardware, computer software, or a combination of hardware and computer software. For example, the aforementioned terminal devices, network elements, or functions can be implemented by a single device, by multiple devices working together, or by a functional module within a single device; this application does not limit this.
[0125] Furthermore, the aforementioned "network element" can also be referred to as an entity, device, or module, etc., and this application does not limit it in this way. Also, for ease of description, the term "network element" is omitted in some of the following descriptions. For example, a NEF network element may be abbreviated as NEF. In this case, "NEF" should be understood as either a NEF network element or a NEF entity. A similar understanding should be applied to other network elements or functions. That is to say, function, functional network element, and functional entity can be equivalent, such as UDM, UDM network element, and UDM entity.
[0126] Some scenarios in this application embodiment are illustrated using 5G communication network scenarios as examples. However, it should be understood that the solutions in this application embodiment can also be applied to other communication networks, such as future communication networks, and the corresponding device / network element names can also be replaced by the names of corresponding functions / devices in other communication networks.
[0127] In the embodiments of this application, the term "wireless communication" can also be abbreviated as "communication", and the term "communication" can also be described as "data transmission", "information transmission" or "transmission".
[0128] It should be noted that the system architecture, network architecture, and business scenarios (or application scenarios) described in the embodiments of this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided in the embodiments of this application. As those skilled in the art will know, with the evolution of communication network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.
[0129] To better understand the embodiments of this application, the relevant content, terms, or nouns involved in this application are described by way of example below. It is understood that all / part of the terms given below are used as examples of the current NR system, but it should be understood that the following terms may have other names in other communication systems (such as future communication systems), and this application does not limit them.
[0130] I. Key Deduction
[0131] To ensure secure data transmission between the terminal device and the network side, both typically need to perform the same key derivation to ensure they use the same key. The "network side" can include access network equipment (such as a gNB). The term "derivation" can also be replaced with "derived," "computed," or other descriptions; this application does not limit the specific terminology used.
[0132] The parameters related to the derivation of the primary access network device key (or master node key) may include the next hop parameter (NH) and the next hop chaining counter (NCC).
[0133] NH: Typically, whenever a security context (such as an access stratum (AS) security context) needs to be established between a terminal device and an access network device, the mobility management element (such as an AMF element) and the terminal device can derive the KgNB and NH. The NH can be obtained by the terminal device and the AMF element through chained derivation; that is, the NH generated in this step will be used to generate the next NH, enabling the NH to be provided to the gNB from the AMF element in a forward-secure manner.
[0134] NCC: Typically issued by AMF network elements, it is associated with each KgNB and NH. It is used to count the number of NH key chain derivations and to synchronize the key chains between terminal devices and access network devices, determining whether the next KNG-RAN* is derived from the current KgNB or a new NH. Each KgNB is associated with the NCC corresponding to its NH value. During initial access, KgNBs can be directly derived from KAMF, and can be considered associated with a virtual NH where NCC=0. During initial access, the derived NH is associated with NCC=1.
[0135] KNG-RAN* is the intermediate key used by the terminal equipment and access network equipment during horizontal or vertical key derivation. After handover, KNG-RAN* is used as the KgNB. KNG-RAN* can be derived from either the currently active KgNB or the NH. If KNG-RAN* is derived from the currently active KgNB, it is called horizontal key derivation, and the access network equipment can instruct the terminal equipment not to add an NCC (e.g., send the NCC corresponding to the derived KgNB to the terminal equipment). If KNG-RAN* is derived from the NH, it is called vertical key derivation, and the access network equipment can instruct the terminal equipment to add an NCC (e.g., send the NCC corresponding to the derived NH to the terminal equipment). Generally, if there are unused {NH, NCC} pairs in the current access network equipment, vertical key derivation can be used. If there are no unused {NH, NCC} pairs in the current access network equipment, horizontal key derivation can be used. For example, during initial access, since the AMF network element does not send an NH to the access network equipment at this time, the next handover can only use horizontal key derivation.
[0136] The following example illustrates the key deduction process using the network side as an example. The terminal device side can refer to this for understanding, and will not be elaborated further.
[0137] Figure 2 is a schematic diagram of the key deduction process performed by access network equipment and terminal equipment.
[0138] Horizontal deduction:
[0139] During initial access, the gNB can deduce the initial key KgNB based on the key KAMF and the NAS uplink count value, and then deduce KgNB1 based on the initial key KgNB. Subsequently, if horizontal derivation is to be performed, the gNB can deduce the key KgNB2 based on KgNB1, the physical cell identifier (PCI) of the target cell, and the carrier frequency, such as the downlink carrier frequency (DL frequency). If horizontal derivation continues, the gNB can deduce the key KgNB3 based on the key KgNB2, the PCI of the target cell, and the carrier frequency. This process continues iteratively, updating the key KgNB to ensure communication security.
[0140] Vertical extrapolation:
[0141] AMF network elements can update NCC (for example, when path migration or handover occurs during handover, AMF network elements can update NCC). If NCC1 is updated to NCC2, then AMF network elements can deduce NH2 based on the keys KAMF and NH1. NH2 and NCC2 are associated as a new pair {NH2,NCC2}. AMF network elements can send {NH2,NCC2} to gNB. Then, after receiving {NH2,NCC2}, gNB can perform vertical deduction when it needs to deduce KNG-RAN*, that is, deduce the key KgNB4 based on NH2, the PCI of the target cell and the carrier frequency, and so on.
[0142] As shown in Figure 2, the number of vertical deductions can be determined by the difference between the NCC value before and after the update. For example, if the NCC value is updated from NCC0 to NCC1, one vertical deduction can be performed based on NH0 associated with NCC0 to obtain NH1 associated with NCC1. If the NCC value is updated from NCC0 to NCC2, two vertical deductions can be performed based on NH0 associated with NCC0 to obtain NH2 associated with NCC2. If the NCC value is updated from NCC2 to NCC3, one vertical deduction can be performed based on NH2 associated with NCC2 to obtain NH3 associated with NCC3.
[0143] It is understood that the above key deduction is a key deduction between the terminal device and the main access network device. That is, the KgNB can be the key between the terminal device and the main access network device, and can be used to generate the RRC key and user plane (UP) key between the terminal device and the main access network device. In this embodiment, the same keys maintained or possessed by the terminal device and the access network device (such as KgNB, Ksn, RRC key, UP key) can be referred to as shared keys.
[0144] It should be noted that the primary access network device can also deduce the key Ksn between the terminal device and the secondary access network device (secondary node, SN) based on the KgNB, and provide it to the secondary access network device. The input parameters for deducing Ksn can include the KgNB and the secondary base station counter / secondary access network device counter (SN counter). Ksn can be used to generate the RRC key and / or UP key between the terminal device and the secondary access network device.
[0145] II. Handover
[0146] Handover generally refers to a process initiated by the network side in the RRC connected state of a terminal device, involving signaling interaction between the terminal device and the access network device. For example, when an access network device detects that the signal strength of the terminal device within its own cell is gradually weakening, it can switch the terminal device to the cell of an access network device with a stronger signal (e.g., a neighboring access network device). It can be understood that handover can occur between cells of different access network devices (inter-site handover), such as the terminal device switching from the cell of access network device 1 to the cell of access network device 2. Alternatively, handover can also occur between cells of the same access network device, such as the terminal device switching from cell 1 of access network device 1 to cell 2 of access network device 1. This application embodiment will describe an inter-site handover scenario as an example.
[0147] Generally, a handover process triggered by Layer 3 signaling can be called a Layer 3 handover or a normal handover. Layer 3 can refer to the RRC layer. In a Layer 3 handover (normal handover) process, when the source access network device determines that the terminal device needs to handover, it can select a target access network device. Then, it needs to obtain a container (containing NCC and handover parameters) constructed by the target access network device. Afterward, the source access network device instructs the terminal device to handover to the target access network device via an RRC reconfiguration message (carrying the container constructed by the target access network device). Once the terminal device has switched to the target access network device, the handover ends. In subsequent handovers, the same handover process will be performed, and the terminal device will receive a new RRC reconfiguration message. In other words, each handover triggers an RRC reconfiguration process.
[0148] To reduce handover latency and enhance mobility robustness, LTM handover, also known as Layer 1 / Layer 2 handover, is introduced. Unlike Layer 3 handover, LTM handover can be triggered by Layer 1 / Layer 2 signaling. Layer 1 can refer to the physical layer, and Layer 2 can refer to the MAC layer. Since Layer 1 and Layer 2 are located at lower levels in the protocol stack than the RRC layer (Layer 3), they facilitate lower handover latency. LTM handover mainly consists of two phases: LTM preparation and LTM execution. The LTM preparation phase is primarily used for pre-handover preparations, such as negotiating relevant resources and handover parameters, so that in the subsequent LTM execution phase, the terminal device can directly use the relevant handover parameters to perform the handover, thus reducing handover latency.
[0149] To facilitate understanding of the embodiments of this application, the following example illustrates a possible LTM cross-site handover process.
[0150] Figure 3 is a schematic diagram of an LTM cross-site handover process disclosed in an embodiment of this application. As shown in Figure 3, the process includes:
[0151] 301, The terminal device is in RRC connected state (RRC_CONNECTED).
[0152] For example, a terminal device can access access network device 0 through an initial access procedure, a normal handover procedure, a re-establishment procedure, or a cell reselection procedure, and then access the 5G core network (5GC) through access network device 0. After that, the terminal device can be in RRC connected state (RRC_CONNECTED). Access network device 0 can also be called the serving access network device.
[0153] 302, Access Network Device 0 determines multiple candidate access network devices for LTM handover.
[0154] For example, access network device 0 can decide to perform LTM handover and start preparation of candidate access network devices, that is, to interact with multiple candidate access network devices to obtain parameters for subsequent handover.
[0155] As one possible implementation, the terminal device can measure multiple neighboring cells and send a measurement report to the access network device 0. The measurement report includes the measurement results of multiple neighboring cells. Accordingly, the access network device 0 can select multiple candidate cells from the multiple neighboring cells based on the measurement report. For example, it can select multiple cells with better signal quality from the multiple neighboring cells as candidate cells. The access network devices to which the selected multiple candidate cells belong are the candidate access network devices for LTM handover.
[0156] This process is described using the example of LTM handover candidate access network devices including access network device 1 and access network device 2. However, it should be understood that the number of candidate access network devices is not limited in this embodiment. Multiple candidate cells may include one or more cells from access network device 1 and one or more cells from access network device 2.
[0157] 303, Access network device 0 sends a handover request message 1 to access network device 1.
[0158] Accordingly, access network device 1 receives a handover request / handover required message 1 from access network device 0. The handover request message 1 may include relevant parameters for the terminal device to hand over to access network device 1, such as the security capabilities of the terminal device and the identifier of the terminal device. These parameters can be used by access network device 1 to select a security algorithm for the terminal device so that it can be used when the terminal device hands over to access network device 1 later.
[0159] In some possible implementations, the source access network device (access network device 0) may also configure the candidate cell list of the candidate access network device (such as access network device 1 and access network device 2) to the candidate access network device. That is, in subsequent LTM handover, when the candidate access network device becomes the source access network device, the set of candidate cells that can be handed over. The configuration method of the candidate cell list is not limited in the embodiments of this application.
[0160] In some possible implementations, the handover request message may include the identifier of the candidate cell. For example, for each candidate cell of a candidate access network device, access network device 0 may send a handover request (handover required) message to the corresponding access network device, which may carry the identifier of the corresponding candidate cell.
[0161] Optionally, the handover request message 1 (and the handover request message 2 below) may include a list of candidate access network devices, i.e., the identifiers of multiple candidate access network devices for LTM handover. The list of candidate access network devices is used to select a target access network device for handover in subsequent LTM handovers. For example, if access network device 1 becomes the primary access network device of the terminal device later, access network device 1 can select the target access network device from the list of candidate access network devices, triggering the terminal device to handover to the target access network device. Alternatively, the handover request message 1 (and the handover request message 2 below) may include a list of candidate cells, i.e., the identifiers of multiple candidate cells for LTM handover. The list of candidate cells is used to select a target cell for handover in subsequent LTM handovers. For example, if access network device 1 becomes the primary access network device of the terminal device later, access network device 1 can select the target cell from the list of candidate cells, triggering the terminal device to handover to the target cell. Alternatively, the handover request message 1 (and the handover request message 2 below) may include the identifiers of multiple candidate access network devices for LTM handover, and the identifier of the candidate cell corresponding to each candidate access network device.
[0162] 304. Access network device 1 sends a handover request ACK / handover required ACK message 1 to access network device 0. The handover request ACK message 1 includes configuration information for handing over to access network device 1.
[0163] Accordingly, access network device 0 receives a handover request confirmation message 1 from access network device 1.
[0164] If access network device 1 permits the terminal device to perform LTM handover, access network device 1 can prepare for LTM handover configuration and send a handover request confirmation message 1 to access network device 0. The handover request confirmation message 1 may carry configuration information for handover to access network device 1, which can be used by the terminal device during subsequent LTM handover. This configuration information may include parameters for the terminal device to handover to access network device 1, such as the synchronization signal block (SSB) frequency and beam information of access network device 1. The handover request confirmation message 1 may also include the identifier of access network device 1.
[0165] Furthermore, the permission granted by access network device 1 for the terminal device to perform LTM handover can be as follows: access network device 1 allows the terminal device to perform LTM handover in a candidate cell of access network device 1. Accordingly, the handover request confirmation message 1 may include the identifier of the corresponding candidate cell and configuration information for handover to the corresponding candidate cell, which includes parameters for the terminal device to handover to the corresponding candidate cell.
[0166] In this embodiment, the configuration information (or simply configuration) used for handover to each candidate access network device can be associated with a corresponding index. This index can be configured by access network device 0, or it can be configured separately by each candidate access network device. For example, access network device 0 can allocate the configuration index of each candidate access network device / the configuration index of each candidate cell in the handover request message sent to each candidate access network device. Subsequent handover request confirmation messages sent by each candidate access network device can include the corresponding configuration index of the candidate access network device / candidate cell. For instance, handover request confirmation message 1 can include the configuration index corresponding to access network device 1, which can be used to determine the configuration information for handover to access network device 1. As another example, each candidate access network device can be allocated a corresponding configuration index of the candidate access network device / candidate cell, and the corresponding configuration index of the candidate access network device / candidate cell can be included in the sent handover request confirmation message. In one possible implementation, the configuration index of the candidate access network device can be the identifier of the candidate access network device, and the configuration index of the candidate cell can be the identifier of the candidate cell.
[0167] 305, Access network device 0 sends a handover request message 2 to access network device 2.
[0168] Accordingly, access network device 2 receives handover request message 2 from access network device 0.
[0169] 306. Access network device 2 sends a handover request confirmation message 2 to access network device 0. The handover request confirmation message 2 includes configuration information for handing over to access network device 2.
[0170] Accordingly, access network device 0 receives a handover request confirmation message 2 from access network device 1.
[0171] If access network device 2 allows the terminal device to perform LTM handover, it can send a handover request confirmation message 2 to access network device 0. The handover request confirmation message 2 may carry configuration information for handover to access network device 2, including parameters for the terminal device to handover to access network device 2, such as the SSB frequency and beam information of access network device 2.
[0172] Furthermore, the permission granted by access network device 2 for the terminal device to perform LTM handover can be as follows: access network device 2 allows the terminal device to perform LTM handover in a candidate cell of access network device 2. Accordingly, the handover request confirmation message 2 may include the identifier of the corresponding candidate cell and configuration information for handover to the corresponding candidate cell, which includes parameters for the terminal device to handover to the corresponding candidate cell.
[0173] 307. Access network device 0 sends an RRC reconfiguration message to the terminal device. The RRC reconfiguration message carries configuration information for switching to access network device 1 and configuration information for switching to access network device 2.
[0174] Accordingly, the terminal device receives an RRC reconfiguration message from access network device 0.
[0175] The terminal device can obtain and save the configuration information for switching to access network device 1 and the configuration information for switching to access network device 2 from the RRC reconfiguration message. For example, the terminal device can save the configuration information for switching to each candidate access network device / candidate cell, as well as the corresponding index, such as saving the configuration information for switching to access network device 1, and the index corresponding to that configuration information (such as the identifier of access network device 1).
[0176] 308, The terminal device sends an RRC reconfiguration complete message to access network device 0.
[0177] Accordingly, access network device 0 receives an RRC reconfiguration complete message from the terminal device.
[0178] It is understood that steps 302-308 above can be considered as the LTM handover preparation process (or LTM handover preparation phase).
[0179] 309. Access network device 0 determines that the terminal device needs to perform LTM cross-site handover, and the target access network device for handover is access network device 1.
[0180] In the LTM handover process (or LTM handover phase, or LTM handover execution process), there are multiple ways for the source access network device (such as access network device 0) to determine the target access network device, and this application embodiment does not limit this. For example, the terminal device can perform measurements (such as Layer 1 measurements) on multiple configured candidate cells and report the measurement reports to the source access network device. The source access network device can select one cell from the multiple candidate cells as the target cell to be handed over based on the measurement reports reported by the terminal device, and the access network device to which the target cell belongs is the target access network device. In step 309, the target cell selected by access network device 0 can be a candidate cell in access network device 1, and the target access network device is access network device 1.
[0181] For example, the measurement configuration and measurement reporting configuration of the terminal device can be configured by the source access network device (such as access network device 0).
[0182] 310, Access network device 0 sends a handover command message to the terminal device.
[0183] Accordingly, the terminal device receives a handover command message from access network device 0. This handover command message can also be called a cell handover command (LTM cellswitchcommand) message.
[0184] The handover command message can be a MAC layer message, such as a MAC control element (CE). The handover command message can include the configuration ID of the target access network device, i.e., the configuration ID of access network device 1. The configuration ID of the target access network device can be used to determine the configuration information used for handing over to the target access device.
[0185] Furthermore, the configuration index corresponding to the target access network device in the handover command message can be the configuration index of the target cell within the target access network device. Accordingly, the configuration index of the target cell can be used to determine the configuration information used for handover to the target cell.
[0186] Optionally, if the handover request message 1 does not include the identifiers of multiple candidate access network devices and / or multiple candidate cells for LTM handover, then after determining that the terminal device needs to hand over to access network device 1, access network device 0 can send the identifiers of multiple candidate access network devices and / or multiple candidate cells for LTM handover to access network device 1 through the Xn message.
[0187] 311, Access network device 0 sends a handover notification message to access network device 1.
[0188] Accordingly, access network device 1 receives a cell switch notification message from access network device 0. The cell switch notification message is used to indicate that a cell switch command message has been sent to the terminal device, that is, to indicate that a cell switch command message to access network device 1 has been sent to the terminal device, and in other words, to indicate that access network device 0 has sent a cell switch command message to access network device 1 to the terminal device.
[0189] Optionally, the handover notification message may carry a key that can be used for the security protection of data between the terminal device and access network device 1. This key may be a KgNB between the terminal device and access network device 1.
[0190] 312, A random access process is performed between the terminal device and the access network device 1.
[0191] After receiving the handover command message from access network device 0, the terminal device can determine the configuration of the target access device (access network device 1) / the configuration of the target cell based on the index of the configuration corresponding to the target access network device in the handover command message.
[0192] In some possible implementations, after receiving a handover command message from access network device 0, the terminal device can attach to access network device 0 and access / handover to access network device 1 or a target cell within access network device 1. It should be understood that the terminal device can use the configuration information received in step 307 for handover to access network device 1 / for handover to a target cell within access network device 1 to handover to access network device 1 or a target cell within access network device 1.
[0193] Step 312 is optional and exemplary. If access / handover requires a random access procedure, and the terminal device does not have a valid timing advance (TA), the terminal device can initiate a random access procedure to the target access network device. As one possible implementation, the terminal device can initiate a random access procedure to access network device 1 based on the configuration information used for handover to access network device 1.
[0194] After the target access network device determines that the terminal device has completed the handover (e.g., after determining that the terminal device has completed the random access procedure, or after receiving a handover completion message from the terminal device), the target access network device can send a handover success message to the source access network device. This handover success message can be used to indicate that the terminal device has successfully accessed or handed over to the target access network device or the target cell within the target access network device. For example, after access network device 1 determines that the terminal device has completed the handover, access network device 1 can send a handover success message to access network device 0. This handover success message can be used to indicate that the terminal device has successfully accessed or handed over to access network device 1 or the target cell within access network device 1.
[0195] 313, The terminal device sends a handover completion message to access network device 1.
[0196] Accordingly, access network device 1 receives a handover completion message from the terminal device. Optionally, the terminal device may send a handover completion message to access network device 1 after accessing / handing over to access network device 1.
[0197] For example, the switchover completion message can be an RRC reconfiguration completion message.
[0198] 314. Access network device 1 sends a path switching request message to the AMF network element.
[0199] Access network device 1 sends a path switch request message to the AMF network element to trigger the core network to migrate the downlink data path to access network device 1 and establish a control plane interface between the AMF and access network device 1. Correspondingly, the AMF network element receives the path switch request message from access network device 1.
[0200] 315. The AMF network element sends a path switching response message to access network device 1.
[0201] Accordingly, access network device 1 can receive a path handover response message from an AMF network element, thereby completing the path handover. For example, the path handover response message can carry a new {NH, NCC}.
[0202] Here, path switching can refer to the terminal device's data transmission path changing from "UPF network element - access network device 0 - terminal device" to "UPF network element - access network device 1 - terminal device".
[0203] Optionally, access network device 1 can send an Xn message to other candidate access network devices, carrying a key and its corresponding NCC (such as {NH,NCC} sent by the AMF network element in step 315, or KgNB and NCC calculated based on the NH). This key can be used for the security protection of data between the terminal device and the candidate access network device in the future, such as the security protection of data between the terminal device and the target access network device after the next LTM handover.
[0204] Optionally, access network device 1 can send an RRC reconfiguration message to the terminal device, carrying an NCC (such as the NCC from the AMF network element in step 315) to synchronize the security protection key between the terminal device and the candidate access network device, such as the key used after the next LTM handover. This step can also be omitted, and the NCC can be carried in the handover command message used to trigger the terminal device to switch to the target access network device in the next LTM handover.
[0205] It should be noted that the Xn message and the RRC reconfiguration message can be sent at any time after the handover is completed, outside of the current handover process (during the handover to access network device 1), and will not affect the latency and performance of this handover.
[0206] It is understandable that steps 309-315 above can be considered the LTM handover execution process. It is also understandable that the terminal device can subsequently switch from access network device 1 to access network device 2. If the candidate access network device for LTM handover also includes access network device 3, the terminal device can also switch from access network device 2 to access network device 3. The implementation of this can be referenced in the description of the terminal device switching from access network device 0 to access network device 1.
[0207] During LTM cross-site handover, the source access network device (such as access network device 0) can identify multiple candidate access network devices for LTM handover, obtain containers constructed by multiple candidate access network devices, and send the containers constructed by multiple candidate access network devices to the terminal device. After that, the source access network device can instruct the terminal device to switch to the target access network device through MAC CE. Each LTM handover can be performed without triggering the RRC reconfiguration process.
[0208] To facilitate understanding of the embodiments of this application, the following example illustrates a possible security protection activation process between a terminal device and a secondary access network device.
[0209] Figure 4 is a schematic diagram of the security protection activation process between a terminal device and a secondary access network device disclosed in an embodiment of this application. As shown in Figure 4, the process includes:
[0210] 401. The terminal device and the main access network device establish an RRC connection.
[0211] 402, the primary access network device sends a secondary access network device add / modify request message to the secondary access network device.
[0212] For example, the primary access network device can send a secondary access network device addition / modification request (SN) message to the secondary access network device via the Xn-C interface to negotiate the available resources, configuration, and algorithms of the secondary access network device. If a new key is required, the primary access network device can calculate the KSN and send the calculated KSN to the secondary access network device. The secondary access network device addition / modification request message may also include the terminal device's security capabilities and / or user plane security policy.
[0213] It should be understood that the connection of terminal equipment to both primary access network equipment and secondary access network equipment is also called dual connectivity, and the relevant content in the standard can be referred to for details.
[0214] 403, the secondary access network device performs capability negotiation and selects a security algorithm.
[0215] After receiving a secondary access network device add / modify request message from the primary access network device, the secondary access network device can allocate necessary resources and select the highest priority encryption and integrity algorithms from its configured list that are present in the terminal security capabilities. If a new Ksn is sent to the secondary access network device, the secondary access network device can calculate the required RRC key and / or UP key based on the Ksn. The RRC key may include K RRCint and / or K RRCenc K RRCint It can be used for integrity protection of RRC signaling between terminal equipment and secondary access network equipment, K RRCenc It can be used for encryption protection of RRC signaling between terminal equipment and secondary access network equipment. The UP key can include K. UPint and / or K UPenc K UPint It can be used for integrity protection of user plane traffic / data between terminal devices and secondary access network devices, K UPenc It can be used for encrypted protection of user plane traffic / data between terminal devices and secondary access network devices.
[0216] 404 indicates that the secondary access network device sends a confirmation message to the primary access network device to request the addition / modification of the secondary access network device.
[0217] For example, the secondary access network device can send a secondary access network device addition / modification acknowledgement message to the primary access network device via the Xn-C interface. This message indicates at least one of the following: resources allocated by the secondary access network device to the terminal device, the security protection algorithm selected by the secondary access network device (such as an algorithm identifier), and (user plane) integrity protection and encryption indications. These integrity protection and encryption indications can be determined based on the terminal device's user plane security policy. They can also be used to indicate whether integrity protection and / or confidentiality protection are activated.
[0218] 405, the primary access network device sends an RRC connection reconfiguration message to the terminal device.
[0219] After receiving the secondary access network device's add / modify request confirmation message from the secondary access network device, the primary access network device can send an RRC connection reconfiguration message to the terminal device. This message may include an SN counter, which indicates the need for a new Ksn, and the terminal device should use the SN counter to calculate the Ksn. The primary access network device can also forward UE configuration parameters (including the algorithm identifier received from the secondary access network device in step 4), integrity protection, and encryption instructions (received from the secondary access network device in step 4) to the terminal device.
[0220] After receiving the RRC connection reconfiguration message, if the message includes an SN counter, the terminal device should calculate the Ksn of the secondary access network device. The terminal device should also calculate the required RRC key and / or UP key based on the Ksn, and perform user plane security protection according to the received integrity protection and encryption instructions.
[0221] 406. The terminal device sends an RRC connection reconfiguration complete message to the primary access network device.
[0222] It is understandable that after sending the RRC connection reconfiguration complete message, the terminal device can activate security protection with the secondary access network device, including security protection for the control plane and the user plane.
[0223] 407, the primary access network device sends a secondary access network device reconfiguration complete message to the secondary access network device.
[0224] For example, the primary access network device can send a secondary access network device reconfiguration complete message (SN reconfiguration complete) to the secondary access network device via Xn-C to notify the secondary access network device of the configuration result. Correspondingly, the secondary access network device can receive the secondary access network device reconfiguration complete message from the primary access network device. Upon receiving this message, the secondary access network device can activate security protections with the terminal device, including control plane and user plane security protections.
[0225] It should be noted that if the secondary access network device does not activate the security protection between itself and the terminal device during this stage, the secondary access network device can activate the security protection between itself and the terminal device after receiving a random access request from the terminal device.
[0226] To clarify, "activating security protection between the terminal device and the access network device" can be understood as: using a confidentiality key (or encryption key) and a selected confidentiality protection algorithm (or encryption algorithm) to protect the confidentiality between the terminal device and the access network device, and / or using an integrity protection key and a selected integrity protection algorithm to protect the integrity between the terminal device and the access network device. Further, confidentiality and / or integrity protection is performed on sent messages / data, and decryption and / or integrity protection verification (or integrity verification) are performed on received messages / data. Even further, in this embodiment, security protection between the terminal device and the access network device may include control plane (or signaling plane, RRC protection) security protection and / or user plane (or data plane) security protection. Signaling plane security protection may include RRC signaling security protection. Furthermore, control plane security protection and user plane security protection may respectively include confidentiality protection (or encryption protection) and / or integrity protection.
[0227] When the primary access network device of the terminal device is the source primary access network device, the terminal device and the corresponding secondary access network device will establish a connection, generate a key for security protection between the terminal device and the secondary access network device, and activate the security protection. When the primary access network device of the terminal device switches from the source primary access network device to the target primary access network device, the connection between the terminal device and the corresponding secondary access network device will be released, and the key used for security protection will be deleted. Further, the terminal device needs to establish a connection with the corresponding secondary access network device of the target primary access network device and activate the security protection between the terminal device and the secondary access network device. However, currently, for LTM handover scenarios, there is no specific solution for activating the security protection between the terminal device and the corresponding secondary access network device when the primary access network device of the terminal device switches. Therefore, in this embodiment, we will conduct relevant research on the security protection activation process between the terminal device and the secondary access network device when the primary access network device of the terminal device switches in an LTM handover scenario.
[0228] First, please refer to Figure 5, which is a flowchart illustrating a communication method disclosed in an embodiment of this application. It should be understood that some steps in Figure 5 are the same as / similar to the steps in Figure 3 or Figure 4 above, and the descriptions corresponding to the relevant steps in Figure 3 or Figure 4 can be referenced. As shown in Figure 5, the method may include, but is not limited to, the following steps:
[0229] 501, The terminal device is in RRC connected state and has established a dual connection.
[0230] For example, a terminal device can access the network through access network device 0 and can be in RRC connected state (RRC_CONNECTED). Furthermore, the terminal device can establish dual connections, including a connection between the terminal device and access network device 0 and a connection between the terminal device and a secondary access network device.
[0231] Step 501 is similar to step 301, and you can also refer to the relevant description in step 301 above.
[0232] 502, Access Network Device 0 determines multiple candidate access network devices for LTM handover.
[0233] 503, Access network device 0 sends a handover request message 1 to access network device 1.
[0234] Steps 502 and 503 are similar to steps 302 and 303 above, and you can refer to the relevant descriptions in steps 302 and 303 above.
[0235] 504, Access Network Device 1 sends a Secondary Access Network Device Add Request message to the Secondary Access Network Device.
[0236] Access network device 1 sends a secondary access network device add request message to the secondary access network device to obtain parameters for accessing the secondary access network device, such as frequency information, beam information, DRB and / or SRB configuration. DRB and / or SRB configuration may include, but is not limited to, resource configuration. The secondary access network device add request message may include the terminal device's security capabilities and / or user plane security policies.
[0237] 505, the secondary access network device sends a secondary access network device addition request confirmation message to access network device 1.
[0238] The secondary access network device addition request confirmation message may include at least one of the following: parameters for accessing the secondary access network device, the security protection algorithm selected by the secondary access network device, user plane integrity protection, and encryption indication. This message can be used during subsequent LTM handover when the terminal device switches to access network device 1, allowing the terminal device to re-access the secondary access network device. The user plane integrity protection and encryption indication are used to indicate whether user plane integrity protection and / or confidentiality protection are activated.
[0239] 506, Access network device 1 sends a handover request confirmation message 1 to access network device 0.
[0240] Accordingly, access network device 0 receives a handover request confirmation message 1 from access network device 1.
[0241] The handover request confirmation message 1 may include at least one of the parameters received from the secondary access network device for accessing the secondary access network device, the security protection algorithm selected by the secondary access network device, integrity protection and encryption indication, etc., and may also include configuration information for handing over to access network device 1. The configuration information includes parameters for the terminal device to hand over to access network device 1, such as the synchronization signal block (SSB) frequency point and beam information of access network device 1.
[0242] As one possible implementation, access network device 1 can construct an RRC container, which may include at least one of the parameters received from the secondary access network device for accessing the secondary access network device, the security protection algorithm selected by the secondary access network device, integrity protection and encryption indication, etc., and configuration information for switching to access network device 1.
[0243] Step 506 is similar to step 304, except that the handover request confirmation message 1 in step 506 may also include information from the secondary access network device. For more information about step 506 and the handover request confirmation message 1, please refer to the relevant description in step 304 above.
[0244] 507, Access network device 0 sends a handover request message 2 to access network device 2.
[0245] Accordingly, access network device 2 receives handover request message 2 from access network device 0.
[0246] 508, Access network device 2 sends a secondary access network device add request message to the secondary access network device.
[0247] Access network device 2 sends a secondary access network device add request message to the secondary access network device to obtain parameters for accessing the secondary access network device, such as frequency information, beam information, DRB and / or SRB configuration.
[0248] 509. The secondary access network device sends a secondary access network device addition request confirmation message to access network device 2.
[0249] The secondary access network device addition request confirmation message may include at least one of the following: parameters for accessing the secondary access network device, security protection algorithm selected by the secondary access network device, user plane integrity protection, and encryption indication. It can be used during subsequent LTM handover when the terminal device switches to access network device 2, so that the terminal device can re-access the secondary access network device.
[0250] For example, the secondary access network device add request message in steps 504 and 508 can also be a secondary access network device modify request message, or other request messages; this embodiment does not limit this. Correspondingly, the secondary access network device add request confirmation message in steps 505 and 509 can also be a secondary access network device modify request confirmation message, or other confirmation messages; this embodiment does not limit this.
[0251] 510, Access network device 2 sends a handover request confirmation message 2 to access network device 0.
[0252] Accordingly, access network device 0 receives a handover request confirmation message 2 from access network device 2.
[0253] The handover request confirmation message 2 may include at least one of the parameters received from the secondary access network device for accessing the secondary access network device, the security protection algorithm selected by the secondary access network device, integrity protection and encryption indication, etc., and may also include configuration information for handing over to access network device 2. The configuration information includes parameters for the terminal device to hand over to access network device 2, such as the synchronization signal block (SSB) frequency point and beam information of access network device 2.
[0254] As one possible implementation, access network device 2 can construct an RRC container, which may include at least one of the parameters received from the secondary access network device for accessing the secondary access network device, the security protection algorithm selected by the secondary access network device, integrity protection and encryption indication, etc., as well as configuration information for switching to access network device 2.
[0255] Step 510 is similar to step 306, except that the handover request confirmation message 2 in step 510 may also include information from the secondary access network device. For more information about step 510 and handover request confirmation message 2, please refer to the relevant description in step 306 above.
[0256] 511, Access network device 0 sends an RRC reconfiguration message to the terminal device.
[0257] Accordingly, the terminal device receives an RRC reconfiguration message from access network device 0.
[0258] The RRC reconfiguration message may include parameters for switching to each candidate access network device, and may also include at least one of the following when reconnecting to the secondary access network device during the switch: the security protection algorithm selected by the secondary access network device, integrity protection, and encryption indication. For example, the RRC reconfiguration message may include a container constructed by access network device 1 and a container constructed by access network device 2.
[0259] The terminal device can save at least one of the parameters obtained from the RRC reconfiguration message for switching to each candidate access network device, as well as the parameters for reconnecting to the secondary access network device when switching to each candidate access network device, the security protection algorithm selected by the secondary access network device, integrity protection and encryption indication, etc., such as saving the container constructed by access network device 1 and the container constructed by access network device 2.
[0260] It should be noted that the above process is exemplified by each candidate access network device interacting with the secondary access network device (sending a secondary access network device add request message / receiving a secondary access network device add request confirmation message) (such as steps 504-505, steps 508-509), but this embodiment of the application does not limit this. In some possible implementations, after access network device 0 determines multiple candidate access network devices, it can interact with the secondary access network device to obtain at least one of the parameters of the secondary access network device corresponding to each candidate access network device configured by the secondary access network device for the terminal device, the security protection algorithm selected by the secondary access network device, integrity protection, and encryption indication, etc. In this case, steps 504-505, steps 508-509, etc., may not be included. For example, access network device 0 can send a request message (such as a secondary access network device add request message) to the secondary access network device to request configuration information / configuration parameters. Accordingly, the secondary access network device can send a request confirmation message to access network device 0 based on the request message (the secondary access network device adds a request confirmation message). The request confirmation message may include at least one of the parameters of the secondary access network device corresponding to each candidate access network device configured by the secondary access network device for the terminal device, the security protection algorithm selected by the secondary access network device, integrity protection and encryption indication, etc.
[0261] For example, the parameters of the secondary access network device may be different for different candidate access network devices, such as at least one of the following: the parameters configured for the secondary access network device, the security protection algorithm selected by the secondary access network device, integrity protection, and encryption indication.
[0262] Step 511 is similar to step 307, except that the RRC reconfiguration message in step 511 may also include information from the secondary access network device. For more information about step 511 and the RRC reconfiguration message, please refer to the relevant description in step 307 above.
[0263] 512, The terminal device sends an RRC reconfiguration complete message to access network device 0.
[0264] Accordingly, access network device 0 receives an RRC reconfiguration complete message from the terminal device.
[0265] It is understandable that steps 502-512 above can be considered as the LTM switching preparation stage.
[0266] 513, Access network device 0 determines that the terminal device needs to perform LTM cross-site handover, and the target access network device for handover is access network device 1.
[0267] 514, Access network device 0 sends a handover command message to the terminal device.
[0268] Accordingly, the terminal device receives a handover command message from access network device 0. The handover command message can be a MAC layer message, such as a MAC CE. The handover command message may include the configuration index corresponding to the target access network device, i.e., the configuration index corresponding to access network device 1. The configuration index corresponding to the target access network device can be used to determine the configuration of the target access network device, such as a saved container of the target access network device or parameters used for switching to the target access network device. The configuration index corresponding to the target access network device can also be used to determine the parameters corresponding to the target access network device for accessing the secondary access network device.
[0269] After receiving the handover command message from access network device 0, the terminal device can also delete the currently stored RRC key and / or UP key used for communication with the secondary access network device.
[0270] 515, Access network device 0 sends a handover notification message to access network device 1.
[0271] Accordingly, access network device 1 receives a handover notification message from access network device 0. The handover notification message is used to indicate that a handover command message has been sent to the terminal device.
[0272] It is understandable that access network device 0 can also send relevant information to secondary access network device to trigger the secondary access network device release (SNrelease) process, so that the secondary access network device can release relevant resources, such as deleting the currently stored RRC key and / or UP key used for communication with the terminal device.
[0273] 516, A random access process is performed between the terminal device and access network device 1.
[0274] Step 516 is optional.
[0275] 517, The terminal device sends a handover completion message to access network device 1.
[0276] Accordingly, access network device 1 receives a handover completion message from the terminal device.
[0277] For example, the switchover completion message can be an RRC reconfiguration completion message.
[0278] Steps 513-517 are similar to steps 309-313, and you can also refer to the relevant descriptions in steps 309-313 above.
[0279] 518, Access network device 1 sends a secondary access network device add request message to the secondary access network device, including Ksn.
[0280] For example, after receiving a handover notification message from access network device 0, access network device 1 can send a secondary access network device add request message to the secondary access network device. Accordingly, the secondary access network device can receive the secondary access network device add request message from access network device 1, which may include Ksn.
[0281] As one possible implementation, access network device 1 can deduce Ksn based on the SN counter and the KgNB carried in the handover notification message of step 515.
[0282] It should be noted that the secondary access network device add request message in step 518 can also be a secondary access network device modify request message, or other request messages; this embodiment does not limit this. Correspondingly, the secondary access network device add request confirmation message in step 519 can also be a secondary access network device modify request confirmation message, or other confirmation messages; this embodiment does not limit this.
[0283] 519, the secondary access network device sends a secondary access network device addition request confirmation message to access network device 1.
[0284] 520, Access network device 1 sends an RRC connection reconfiguration message to the terminal device, including the SN counter.
[0285] Accordingly, the terminal device can receive an RRC connection reconfiguration message from access network device 1. The terminal device can calculate Ksn based on the KgNB (the KgNB between the terminal device and access network device 1) and the SN counter in the RRC connection reconfiguration message. The terminal device can also calculate the RRC key and / or UP key based on Ksn, and perform user plane security protection according to the received integrity protection and encryption instructions. It should be understood that the SN counter used by the terminal device to calculate Ksn is the same as the SN counter used by access network device 1 to calculate Ksn in step 518.
[0286] It is understood that, in order to quickly activate the security protection between the terminal device and the secondary access network device, access network device 1 can immediately send the secondary access network device add request message in step 518 after receiving the handover notification message in step 515, and can immediately send the RRC connection reconfiguration message in step 520 after receiving the secondary access network device add confirmation message in step 519, and can immediately send the SN reconfiguration completion message in step 522 after receiving the RRC connection reconfiguration completion message in step 521. It should be understood that "immediately" in this embodiment can be understood as a duration less than a certain small threshold, such as 20ms.
[0287] 521, The terminal device sends an RRC connection reconfiguration complete message to access network device 1.
[0288] It is understandable that after sending the RRC reconfiguration completion message, the terminal device can activate security protection with the secondary access network device, including security protection for the control plane and the user plane.
[0289] In some possible implementations, the terminal device may also activate security protection with the secondary access network device after receiving an RRC connection reconfiguration message from access network device 1.
[0290] 522, Access network device 1 sends a secondary access network device reconfiguration complete message to the secondary access network device.
[0291] For example, access network device 1 can send a secondary access network device reconfiguration completion message to the secondary access network device via Xn-C to notify the secondary access network device of the configuration result, which is the configuration result corresponding to the RRC connection reconfiguration message in step 520. Accordingly, the secondary access network device can receive the secondary access network device reconfiguration completion message from access network device 1. After receiving the message, the secondary access network device can activate the security protection of the control plane and user plane with the terminal device.
[0292] It should be noted that if the secondary access network device does not activate the security protection between itself and the terminal device during this stage, the secondary access network device can activate the security protection between itself and the terminal device after receiving a random access request from the terminal device.
[0293] It should be understood that access network device 1 can also trigger a path switching process to switch the data transmission path of the terminal device from "UPF network element - access network device 0 - terminal device" to "UPF network element - access network device 1 - terminal device".
[0294] Steps 518-522 are similar to steps 402 and 404-407, and you can refer to the relevant descriptions in steps 402 and 404-407 above.
[0295] 523, the random access process between terminal equipment and secondary access network equipment.
[0296] For example, if the handover requires a random access procedure between the terminal device and the secondary access network device, and the terminal device does not have a valid TA (Translation Address Translation), the terminal device can initiate a random access procedure to the secondary access network device. As one possible implementation, the terminal device can initiate a random access procedure to the secondary access network device based on the access parameters received in step 512.
[0297] It is understandable that the random access between the terminal device and the access network device 1 (step 516) has no prior or subsequent constraint relationship with the random access between the terminal device and the secondary base station (step 523).
[0298] It is understandable that the terminal device can subsequently switch from access network device 1 to access network device 2, the implementation of which can refer to the description of the terminal device switching from access network device 0 to access network device 1, that is, the relevant descriptions in steps 513-523. It is also understandable that if the candidate access network device for LTM handover also includes access network device 3, then the terminal device can subsequently switch from access network device 2 to access network device 3, the implementation of which can also refer to the relevant description of the terminal device switching from access network device 0 to access network device 1.
[0299] In the above LTM cross-site handover process, for each LTM handover, in order to activate the security protection between the terminal device and the secondary access network device, it is necessary to trigger the RRC connection reconfiguration process between the terminal device and the target access network device (access network device 1), which will result in low efficiency of security protection activation and high overall latency.
[0300] To improve the efficiency of security protection activation between terminal devices and secondary access network devices in LTM cross-site handover scenarios, this application provides several additional schemes for security protection activation between terminal devices and secondary access network devices in LTM cross-site handover scenarios.
[0301] Specifically, for the secondary access network device, after receiving the Ksn from the target access network device (such as a third access network device), the secondary access network device can calculate the communication key (such as an RRC key and / or an UP key) with the terminal device based on the Ksn, and then activate the security protection with the terminal device.
[0302] From the perspective of the terminal device, in one possible implementation, the terminal device can receive first information and information indicating NCC from the source access network device (such as a first access network device). The first information can be used by the terminal device to switch the primary access network device from the source access network device to the target access network device (such as a third access network device), and the information indicating NCC can be used by the terminal device to determine a first key with the secondary access network device. In response to the first information, the terminal device can activate security protection with the secondary access network device. In another possible implementation, the terminal device can first receive the first information and information indicating NCC from the source access network device, and then the terminal device can also receive information from the target access network device or the secondary access network device indicating the activation of security protection between the terminal device and the secondary access network device (for example, the target access network device can send this information to the terminal device after sending the Ksn to the secondary access network device, or the secondary access network device can send this information to the terminal device after activating security protection with the terminal device). In response to this information, the terminal device can activate security protection with the secondary access network device.
[0303] Furthermore, in this embodiment, since the activation of security protection for terminal devices and secondary access network devices may have a certain time delay (as in the first possible implementation described above), in order to avoid the loss of uplink and downlink data, a caching mechanism for uplink and / or downlink data can be set, and the activation of uplink security protection and downlink security protection can be decoupled and activated at different stages. For related details, please refer to the description in the following method embodiments.
[0304] It is understood that the above content is only intended to make the embodiments of this application easier to understand and should not be construed as limiting the embodiments of this application.
[0305] The overall scheme of the embodiments of this application will be described below.
[0306] Please refer to Figure 6, which is a flowchart illustrating another communication method disclosed in this application. In Figure 6, LTM cross-site handover may include the primary access network device in the dual connectivity of the terminal device switching from a first access network device to a third access network device. That is, the first access network device is the primary access network device before the handover, which can be referred to as the source access network device, and the third access network device is the primary access network device after the handover, which can be referred to as the target access network device. The second access network device is the secondary access network device of the terminal device, and further, the second access network device is the secondary access network device corresponding to the third access network device. It should be noted that the switch from the first access network device to the third access network device can be any LTM handover after the LTM handover preparation is completed. That is, the first access network device can be the source access network device in any LTM handover after the LTM handover preparation is completed, and the third access network device can be the target access network device in that LTM handover. As shown in Figure 6, the method may include, but is not limited to, the following steps:
[0307] 601. The terminal device obtains the second information of each of the multiple candidate primary access network devices, wherein the second information of each candidate primary access network device includes parameters (or configurations) for the terminal device to switch to that candidate primary access network device.
[0308] For example, during the LTM handover preparation phase, the terminal device can be in RRC connected state and have established dual connections (such as establishing a connection between the terminal device and the first access network device and a connection between the terminal device and access network device x). Access network device x and the second access network device can be the same or different.
[0309] During the LTM handover preparation phase, the serving access network device / source access network device of the terminal device is the first access network device, which is the primary access network device currently connected to by the terminal device. The first access network device can be the access network device that the terminal device accesses through an LTM handover procedure, initial access procedure, normal handover procedure, re-establishment procedure, or cell reselection procedure. The first access network device and the terminal device can store the same KgNB and the same NCC (such as the first NCC). This KgNB is the KgNB between the terminal device and the first access network device, and it can be used to generate the key used for communication between the first access network device and the terminal device, such as the RRC key and / or UP key. This KgNB can also be used to generate the Ksn between the current terminal device's secondary access network device (the secondary access network device corresponding to the first access network device) and the terminal device. This Ksn can be used to further generate the key used for communication between the secondary access network device corresponding to the first access network device and the terminal device. In this embodiment, the secondary access network device can also be called a secondary base station, secondary access network device, etc., and the primary access network device can also be called a primary base station, primary node, etc., without limitation.
[0310] As one possible implementation, during the LTM handover preparation phase, the terminal device can receive second information from each of the multiple candidate primary access network devices among the multiple candidate primary access network devices from the source access network device. Taking the source access network device as the first access network device as an example, the terminal device can receive the second information from each of the multiple candidate primary access network devices from the first access network device. For example, the first access network device can send an RRC reconfiguration message to the terminal device, which includes the second information of each of the multiple candidate primary access network devices. Accordingly, the terminal device can receive the RRC reconfiguration message from the first access network device to obtain the second information of each of the multiple candidate primary access network devices. Furthermore, the terminal device can save the second information of each of the multiple candidate primary access network devices for use during subsequent LTM handover execution. In this embodiment, the candidate primary access network device can also be simply referred to as the candidate access network device, without limitation.
[0311] For example, the first access network device can identify multiple candidate primary access network devices for LTM handover and can send handover request messages to each candidate primary access network device to request second information from the multiple candidate primary access network devices. Accordingly, each candidate primary access network device can receive the handover request message from the first access network device and then send its own second information to the first access network device based on the handover request message.
[0312] The second information for each of the multiple candidate primary access network devices includes parameters for the terminal device to switch to that candidate primary access network device. For example, the multiple candidate primary access network devices may include a third access network device and a fourth access network device. The second information for the third access network device includes parameters for the terminal device to switch to the third access network device (such as SSB frequency information or beam information), and the second information for the fourth access network device includes parameters for the terminal device to switch to the fourth access network device (such as SSB frequency information or beam information), as described in steps 302-306 or 502-510.
[0313] Optionally, the second information for each candidate primary access network device may also include a serial number (SN) counter corresponding to each candidate primary access network device; this embodiment of the application does not limit this. For example, the SN counter corresponding to the third access network device may be a first SN counter, and the SN counter corresponding to the fourth access network device may be a second SN counter.
[0314] In this embodiment, the second information of each candidate primary access network device may further include a corresponding configured index, which can be used to determine the second information of the corresponding candidate primary access network device. This can be configured by the first access network device, or it can be configured separately by each candidate primary access network device. For example, the second information of the third access network device may further include the configured index of the third access network device, and / or the configured index of the candidate cells in the cell served by the third access network device.
[0315] The configuration information used for switching to access network device 1 and the configuration information used for switching to access network device 2 in Figure 5 above can be regarded as the second information of the candidate primary access network device. Therefore, the second information of the candidate primary access network device can also refer to the relevant descriptions of the configuration information used for switching to access network device 1 and the configuration information used for switching to access network device 2 in Figure 5 above.
[0316] 602, The terminal device obtains third information from the second access network device, including parameters (or configurations) used by the terminal device to access the second access network device.
[0317] As one possible implementation, during the LTM handover preparation phase, the terminal device can receive third information from the second access network device, which is the source access network device. Taking the first access network device as the source access network device as an example, the terminal device can receive third information from the second access network device, which is the source access network device. For instance, the first access network device can send an RRC reconfiguration message to the terminal device, which includes the third information of the second access network device. Accordingly, the terminal device can receive the RRC reconfiguration message from the first access network device and obtain the third information of the second access network device. Furthermore, the terminal device can save the third information of the second access network device for use during subsequent LTM handover execution.
[0318] It should be noted that, in one possible scenario, for multiple candidate primary access network devices, these devices can share the same third information of the second access network device. That is, during subsequent LTM handover, when the terminal device needs to switch to any of the multiple candidate primary access network devices, it can use the same third information of the second access network device to re-access to that device. In another possible scenario, for multiple candidate primary access network devices, each device can have its own corresponding third information of the second access network device. That is, during subsequent LTM handover, when the terminal device needs to switch to a specific access network device among the multiple candidate primary access network devices, it can use the third information of the second access network device corresponding to that specific access network device to re-access to that device. In the second scenario, the third information of the second access network devices corresponding to different candidate primary access network devices can be different.
[0319] Based on the above, it should be understood that the third information received by the terminal device from the second access network device may include the third information of the second access network device corresponding to (or associated with) each of the multiple candidate primary access network devices. Specifically, the third information of the second access network device corresponding to each of the multiple candidate primary access network devices includes parameters used by the terminal device to re-access the second access network device when it needs to switch to that candidate primary access network device. For example, the third information of the second access network device corresponding to the third access network device includes parameters (such as DRB and / or SRB configurations) used by the terminal to re-access the second access network device when it switches to the third access network device; similarly, the third information of the second access network device corresponding to the fourth access network device includes parameters (such as DRB and / or SRB configurations) used by the terminal to re-access the second access network device when it switches to the fourth access network device.
[0320] The third information of the second access network device may also include at least one of the following: security algorithm (such as algorithm identifier), integrity protection, and encryption indication selected by the second access network device. This application embodiment does not limit this.
[0321] For example, the source access network device can send handover request messages to multiple candidate primary access network devices to request the second information of the multiple candidate primary access network devices and the third information of the corresponding second access network devices. After receiving the handover request message from the source access network device, each candidate primary access network device can obtain the corresponding third information from the second access network device, as described in steps 502-510.
[0322] For another example, the source access network device can directly obtain the third information of the second access network devices corresponding to multiple candidate primary access network devices from the second access network device. For instance, the source access network device can send a SN add / modify request message to the second access network device, and then receive a SN add / modify request confirmation message from the second access network device. This SN add / modify request confirmation message includes the third information of the second access network device, which is shared by multiple candidate primary access network devices. As another example, the source access network device can send a SN add / modify request message to the second access network device, and this SN add / modify request message includes the identifiers of multiple candidate access network devices. After receiving this SN add / modify request message, the second access network device can send a SN add / modify request confirmation message to the source access network device, and this SN add / modify request confirmation message includes the third information of the second access network devices corresponding to each of the multiple candidate access network devices.
[0323] In some possible implementations, the source access network device may send the second information of each of the multiple candidate primary access network devices and the third information of the corresponding second access network device in the same message (such as an RRC reconfiguration message) to the terminal device. For example, each candidate primary access network device may construct a container and send it to the source access network device. The container constructed by each candidate primary access network device may include the second information of that candidate primary access network device and the third information of the corresponding second access network device. The source access network device may send an RRC reconfiguration message to the terminal device, which may include the containers constructed by each candidate primary access network device.
[0324] As one possible implementation, the second information of each candidate primary access network device may include parameters for the terminal device to switch to the candidate primary access network device, and the third information of the secondary access network device corresponding to the candidate primary access network device, wherein the third information of the secondary access network device corresponding to the candidate primary access network device includes parameters for the terminal device to access the secondary access network device corresponding to the candidate primary access network device.
[0325] Optionally, after receiving the RRC reconfiguration message from the source access network device, the terminal device may send an RRC reconfiguration completion message to the source access network device.
[0326] It should be noted that the description of step 602 above can be understood as assuming that the secondary access network devices corresponding to different candidate primary access network devices are the same (all are second access network devices), or it can be understood as assuming that the secondary access network device of the terminal device remains unchanged (all are second access network devices) during the LTM handover preparation phase and the LTM handover process. However, in some other possible embodiments of this application, the secondary access network devices corresponding to different candidate primary access network devices may be different, or the secondary access network device of the terminal device may change during the LTM handover preparation phase and the LTM handover process. For example, during the LTM handover preparation phase, the secondary access network device of the terminal device can be secondary access network device 1, while during the subsequent LTM handover process, when the terminal device switches to the third access network device through LTM handover, the secondary access network device of the terminal device can be changed to the second access network device; when the terminal device switches to the fourth access network device through LTM handover, the secondary access network device of the terminal device can be changed to the fifth access network device, and so on. That is to say, when the terminal device switches the primary access network device to a different access network device through LTM handover, the secondary access network device of the terminal device can be different. In this embodiment of the application, for ease of description, when a terminal device switches to a candidate primary access network device via LTM handover, the secondary access network device that the terminal device needs to access can be referred to as the secondary access network device corresponding to the candidate primary access network device. Alternatively, when a terminal device accesses a candidate primary access network device, the secondary access network device that the terminal device needs to access can be referred to as the secondary access network device corresponding to the candidate primary access network device. For example, the second access network device can be referred to as the secondary access network device corresponding to the third access network device, and the fifth access network device can be referred to as the secondary access network device corresponding to the fourth access network device.
[0327] Furthermore, the secondary access network device corresponding to each candidate primary access network device can be determined by the candidate primary access network device itself, or it can be determined by the source access network device. This application does not limit the method for determining the secondary access network device corresponding to the candidate primary access network device; for example, it can be determined based on the location of the terminal device, the location of the candidate primary access network device, etc.
[0328] Understandably, during the LTM handover preparation phase, the terminal device can receive the third information (such as the third information of the second access network device, the third information of the fifth access network device, etc.) of the secondary access network device corresponding to each candidate primary access network device. This is so that during the subsequent LTM handover process, when the terminal device switches from the primary access network device to the corresponding candidate primary access network device, it can use the third information of the secondary access network device corresponding to that candidate primary access network device to access the secondary access network device. The method by which the terminal device receives the third information of the secondary access network device corresponding to each candidate primary access network device can be referenced in the above description under the condition that the secondary access network device remains unchanged. However, each candidate primary access network device or the source access network device in the LTM handover phase needs to obtain the corresponding second information from the secondary access network device corresponding to each candidate primary access network device separately, rather than obtaining the corresponding second information from the same secondary access network device (such as the second access network device).
[0329] In some possible implementations, the terminal device can store the association between the second information of each candidate primary access network device and the third information of the corresponding secondary access network device, such as storing the association between the third information of the second access network device and the second information of the third access network device. This facilitates access to the corresponding secondary access network device when the terminal device needs to switch to a candidate primary access network device during subsequent LTM handover, by retrieving the stored third information of the corresponding secondary access network device. It should be noted that the method of storing the association between the second information of each candidate primary access network device and the third information of the corresponding secondary access network device is not limited in this embodiment. For example, the second information of each candidate primary access network device and the third information of the corresponding secondary access network device can be stored in a table, with each pair stored in the same row. Alternatively, the association between the identifier of each candidate primary access network device and the identifier of the corresponding secondary access network device can be stored.
[0330] Steps 601 and 602 above can be understood as the LTM handover preparation phase. In some possible cases, steps 601 and 602 are optional.
[0331] 603, The first access network device determines that the terminal device needs to switch to the third access network device among multiple candidate primary access network devices.
[0332] There are several ways for the first access network device to determine that the terminal device needs to switch to the third access network device. For example, the terminal device can perform measurements (such as Layer 1 measurements) on multiple configured candidate cells and report the measurement reports to the first access network device. The first access network device can then select one cell from the multiple candidate cells as the target cell (or target cell) to be switched over, based on the measurement reports reported by the terminal device. In step 603, the target cell selected by the first access network device can be a candidate cell from the third access network device.
[0333] 604. The first access network device sends first information and information for instructing the NCC (hereinafter referred to as the first NCC for easy distinction) to the terminal device. The first information is used by the terminal device to switch the primary access network device from the first access network device to the third access network device.
[0334] Accordingly, the terminal device can receive first information from the first access network device and information for instructing the NCC. For example, the first information used by the terminal device to switch the primary access network device from the first access network device to the third access network device can be: the first information used to switch the primary access network device in the dual-connection of the terminal device from the first access network device to the third access network device.
[0335] For example, the first information may include one or more of the following: the identifier of the third access network device, the index of the configuration of the third access network device, the identifier of the candidate cell in the cell served by the third access network device, and the index of the configuration of the candidate cell in the cell served by the third access network device. This application embodiment does not limit this. In some possible implementations, the first information may also be understood as being used to trigger the terminal device to switch the primary access network device from the first access network device to the third access network device, and to determine the second information of the third access network device, that is, to determine the configuration used by the terminal device to switch to the third access network device.
[0336] For example, the information used to indicate the NCC may include at least one of the following: the NCC, the index of the NCC, and the encrypted ciphertext of the NCC. The information used to indicate the NCC in step 607 may include at least one of the following: a first NCC, the index of the first NCC, and the encrypted ciphertext of the first NCC. The first NCC may be an NCC stored in the first access network device (such as the RRC layer of the first access network device) and may be associated with the communication key used between the current first access network device and the terminal device.
[0337] It is understood that the first information and the information used to indicate NCC can be carried in the same message or in different messages. For example, the first information and the information used to indicate NCC can be carried in the first MAC layer message (such as a handover command message), that is, carried within the first MAC layer message. As another example, the first information and the information used to indicate NCC can be carried in different MAC layer messages. Since the MAC layer is at a lower layer of the protocol stack (below the RRC layer), its processing speed is faster. Therefore, the handover latency of the terminal device can be shorter, and subsequent activation of security protection with the second access network device can be faster.
[0338] It should be understood that once the first access network device determines that the terminal needs to switch to the third access network device, it can send the first information and information for instructing the NCC to the terminal device.
[0339] In some possible implementations, the information used to indicate the NCC can also be replaced with other information that can be used by the terminal device to determine the first key, or other information that can be used by the terminal device to determine the key between the terminal device and the third access network device (such as KgNB1). This application embodiment does not limit this. The information used to indicate the NCC carried in step 604 is optional.
[0340] In some possible implementations, after receiving the first information from the first access network device, the terminal device may delete the currently stored RRC key, UP key, and Ksn used to generate the RRC key and / or UP key for communication between the secondary access network device corresponding to the first access network device.
[0341] 605, the first access network device sends a first message to the third access network device, the first message being used to instruct the terminal device to switch its primary access network device from the first access network device to the third access network device.
[0342] Accordingly, the third access network device can receive the first message from the first access network device.
[0343] For example, the first message could be a switching notification message (Xn message).
[0344] In some possible implementations, the first message may include a key (e.g., KgNB1) between the terminal device and the third access network device, which can be used to determine a first key between the terminal device and the second access network device. For example, the first access network device can deduce the key (e.g., KgNB1) between the terminal device and the third access network device based on the key between the terminal device and the first access network device (e.g., KgNB0) and a first input parameter. The first input parameter may include the PCI and carrier frequency of the target cell in the third access network device. Optionally, the first message may also include an NCC (e.g., a first NCC) associated with the key between the terminal device and the third access network device.
[0345] It is understood that the first message may also include more information, such as the identifier of the terminal device, the identifier of the target cell, etc., and this application embodiment does not limit this.
[0346] It should be noted that the phrase "the first message is used to indicate the switch of the terminal device's primary access network device from the first access network device to the third access network device" can be understood as the first message itself (such as a handover notification message) or all or part of the information carried in the first message indicating the switch of the terminal device's primary access network device from the first access network device to the third access network device. Furthermore, "used to indicate the switch of the terminal device's primary access network device from the first access network device to the third access network device" can also be understood as indicating that the first information has been sent to the terminal device.
[0347] In some possible implementations, the first access network device can also send relevant information to the secondary access network device corresponding to the first access network device to trigger a secondary access network device release (SNrelease) procedure, so that the secondary access network device corresponding to the first access network device can release relevant resources, such as deleting the currently stored RRC key, UP key, and Ksn used to generate the RRC key and / or UP key for communication with the terminal device, and can also release the DRB and SRB between the terminal device and the terminal device. For example, the first access network device can send a second message to the secondary access network device corresponding to the first access network device, the second message indicating the release of the connection between the terminal device and the secondary access network device corresponding to the first access network device, which was established when the first access network device is the primary access network device in a dual connection of the terminal device. Accordingly, the secondary access network device corresponding to the first access network device can receive the second message from the first access network device, and in response to the second message, the secondary access network device corresponding to the first access network device can delete the second key between the terminal device and the secondary access network device corresponding to the first access network device, the second key being used for security protection between the terminal device and the secondary access network device corresponding to the first access network device. The second key may include the RRC key, UP key, and Ksn used to generate the RRC key and / or UP key, currently stored in the secondary access network device corresponding to the first access network device for communication with the terminal device. The secondary access network device corresponding to the first access network device may be the same as or different from the second access network device.
[0348] In the above process, steps 604 (sending information to the terminal device to indicate the NCC) and 605 (sending a first message to the third access network device, the first message carrying the key between the terminal device and the third access network device) enable the terminal device and the third access network device to maintain / possess the same key, i.e., the key between the third access network device and the terminal device (such as KgNB1). However, in some other possible implementations, the terminal device and the third access network device can maintain / possess the same key in other ways. For example, as a possible implementation, during the LTM handover preparation phase, after the source access network device determines multiple candidate primary access network devices, it can determine the keys of each candidate primary access network device and send them to the corresponding candidate primary access network devices through a handover request message. Taking the source access network device as the first access network device, and multiple candidate primary access network devices including a third access network device as examples, the first access network device can deduce the key between the terminal device and the third access network device (e.g., KgNB0) based on the key between itself and the terminal device (e.g., KgNB0) and the first input parameter. It can then send the key between the terminal device and the third access network device to the third access network device via a handover request message. The third access network device can store the key between itself and the terminal device. In this case, the first message in step 605 does not need to carry the key between the terminal device and the third access network device. Optionally, the second information of the third access network device may include the NCC associated with the key between the terminal device and the third access network device (e.g., the first NCC). In this case, step 604 does not need to carry information indicating the NCC. The terminal device can obtain the NCC from the second information of the third access network device. Furthermore, in some possible cases, the terminal device can calculate the first key in advance, such as calculating the first key before step 604, or it can further obtain the corresponding RRC key and / or UP key based on the first key. For example, as another possible implementation, during the LTM handover preparation phase, after each candidate primary access network device receives a handover request message from the source access network device, it can obtain a new {NH, NCC} from the AMF and calculate the key between itself and the terminal device based on the obtained NH. Taking the source access network device as the first access network device, and taking multiple candidate primary access network devices including a third access network device as an example, after the third access network device receives a handover request message from the first access network device, it can obtain a new {NH, NCC} from the AMF and deduce the key between the terminal device and the third access network device (such as KgNB1) based on the obtained NH and the first input parameters. It can also save the deduced key between the terminal device and the third access network device. In this case, the first message in step 605 above does not need to carry the key between the terminal device and the third access network device.Optionally, the second information of the third access network device may include the NCC (such as the first NCC) obtained by the third access device from the AMF, that is, the NCC of the key association between the terminal device and the third access network device. In this case, the information for indicating the NCC does not need to be carried in the above step 604. The terminal device can obtain the corresponding NCC from the second information of the third access network device. In some possible cases, the terminal device can calculate the first key in advance, such as calculating the first key before step 604, or it can further obtain the corresponding RRC key and / or UP key based on the first key.
[0349] It should be noted that the execution order of steps 604 and 605 is not limited in this embodiment. For example, steps 604 and 605 can be executed simultaneously. As another example, step 605 can be executed after step 604.
[0350] 606. The terminal device accesses the second access network device based on the third information of the second access network device.
[0351] For example, a terminal device may access the second access network device based on the parameters for accessing the second access network device included in the third information of the second access network device.
[0352] As one possible implementation, in response to the first information, the terminal device can access the second access network device based on the third information of the second access network device. For example, based on the first information, the terminal device can determine that it needs to switch to the third access network device, and then, based on the association between the third access network device and the second access network device (such as the association between the stored identifiers of the third access network device and the second access network device), it can determine that it needs to access the auxiliary access network device (the second access network device) corresponding to the third access network device, and can access the second access network device based on the third information of the second access network device.
[0353] For example, if a random access procedure needs to be performed between the terminal device and the second access network device, the terminal device can initiate a random access procedure to the second access network device. For instance, the terminal device can initiate a random access procedure to the second access network device based on the parameters for accessing the second access network device included in the third information of the second access network device, in order to access the second access network device.
[0354] In some possible implementations, the terminal device accessing the second access network device based on the third information of the second access network device may include: the terminal device performing relevant processing based on the third information of the second access network device, such as establishing a DRB and / or SRB with the second access network device.
[0355] In some possible cases, after the terminal device connects to the second access network device, it can send an RRC connection reconfiguration complete message to the second access network device.
[0356] 607. The terminal device determines a first key (such as Ksn1) between the terminal device and the second access network device based on the information used to instruct the NCC.
[0357] For example, after receiving the first information and the information indicating the NCC from the first access network device, the terminal device can obtain the corresponding NCC (such as the first NCC) based on the information indicating the NCC. Furthermore, the terminal device can determine the first key (such as Ksn1) between the terminal device and the second access network device based on the obtained NCC.
[0358] As one possible implementation, in response to the first information, or in response to the first information and the information used to indicate the NCC, the terminal device can determine the first key between the terminal device and the second access network device according to the corresponding NCC. This can be understood as the first information, or the first information and the information used to indicate the NCC, triggering the terminal device to determine the first key between the terminal device and the second access network device according to the corresponding NCC.
[0359] There are several ways for the terminal device to determine the first key based on the first NCC. For example, the terminal device can deduce the key between itself and the third access network device (e.g., KgNB1) based on the first NCC, and then deduce the first key based on the key between itself and the third access network device. For instance, the terminal device can compare the first NCC with the NCC stored locally on the terminal device. If they are the same, the terminal device can deduce the key between itself and the third access network device (e.g., KgNB0) based on the key between itself and the first access network device (e.g., KgNB0) or unused NH, and the first input parameter. If they are different, the terminal device can first calculate NH, and then deduce the key between itself and the third access network device (e.g., KgNB1) based on the calculated NH and the first input parameter. Afterwards, the terminal device can deduce the first key between itself and the second access network device (e.g., Ksn1) based on the key between itself and the third access network device (e.g., KgNB1) and the second input parameter. The first input parameter may include the PCI and carrier frequency of the cell of the third access network device, and the second input parameter may include the first SN counter. The first SN counter can be a preset value / default value (such as all 0), or it can be received in step 601 or step 602, that is, configured in the LTM handover preparation stage.
[0360] It is understandable that the terminal device can also deduce the RRC key and / or UP key between the terminal device and the second access network device based on the first key (such as Ksn1). The terminal device can also deduce the RRC key and / or UP key between the terminal device and the third access network device based on the key between the terminal device and the third access network device (such as KgNB1).
[0361] For example, the first key is obtained based on the key corresponding to the third access network device (such as KgNB1). The first key can be used for security protection between the terminal device and the second access network device when the third access network device is the primary access network device in a dual-connection scenario for the terminal device. The first key is used for security protection of this connection (such as the connection between the terminal device and the second access network device in a dual-connection scenario), and for security protection of signaling and / or data transmitted through this connection. The first key is used to securely protect the connection between the terminal device and the second access network device, such as for security protection of control plane signaling and / or user plane data transmitted through this connection. The first key can be the secondary access network device key (Ksn1) between the terminal device and the second access network device (secondary access network device). Ksn1 can be used to generate an RRC key and / or a UP key between the terminal device and the second access network device. The RRC key can be used for security protection of control plane signaling between the terminal device and the second access network device, and the UP key can be used for security protection of user plane data between the terminal device and the second access network device.
[0362] 608. The terminal device activates the security protection between the terminal device and the second access network device based on the first information.
[0363] For example, the terminal device activating the security protection between the terminal device and the second access network device based on the first information can be as follows: in response to the first information, the terminal device activates the security protection between the terminal device and the second access network device.
[0364] It should be noted that in the embodiments of this application, the terminal device's execution of the target operation in "responding to the first information" can be either a direct response to the first information or an indirect response to the first information. A direct response to the first information can be understood as the terminal device directly executing the target operation in response to the first information; that is, the first information can be a triggering condition for the terminal device to execute the target operation. An indirect response to the first information can be understood as the terminal device first performing other operations (such as operations that need to be performed before executing the target operation), and then executing the target operation after the other operations are completed (such as executing the target operation based on the execution result of the other operations). Furthermore, responding to the first information can also be a response to a message carrying the first information, such as the aforementioned first MAC layer message (switching command message).
[0365] For example, in some possible implementations, in response to the first information, the terminal device activating security protection between the terminal device and the second access network device (based on the first key) can be as follows: In response to the first information, the terminal device triggers the deduction of the first key. After obtaining the first key through deduction, the security protection between the terminal device and the second access network device can be activated, and the signaling and / or data between the terminal device and the second access network device can be securely protected according to the first key. Alternatively, it can be as follows: In response to the first MAC layer message (handover command message), the terminal device activates security protection between the terminal device and the second access network device, and the signaling and / or data between the terminal device and the second access network device can be securely protected according to the first key. Alternatively, it can be as follows: In response to the first MAC layer message, the terminal device triggers the deduction of the first key. After obtaining the first key through deduction, the security protection between the terminal device and the second access network device can be activated, and the signaling and / or data between the terminal device and the second access network device can be securely protected according to the first key. Alternatively, in response to the first information, the terminal device accesses the second access network device based on the third information of the second access network device. After accessing the second access network device, it can activate the security protection between the terminal device and the second access network device and perform security protection on the signaling and / or data between the terminal device and the second access network device based on the first key. Alternatively, in response to the first information, the terminal device accesses the second access network device based on the third information of the second access network device. After accessing the second access network device, the terminal device deduces the first key and activates the security protection between the terminal device and the second access network device.
[0366] In this embodiment of the application, accessing the second access network device can also be understood as establishing a connection with the second access network device, and activating the security protection between the terminal device and the second access network device is also activating the security protection for the connection.
[0367] For example, "activating security protection between the terminal device and the second access network device according to the first key" can be understood as: activating security protection between the terminal device and the second access network device, and providing security protection for signaling and / or data between the terminal device and the second access network device according to the first key.
[0368] It should be noted that the security protection activated by the terminal device can include uplink security protection and downlink security protection between the second access network device and the terminal device.
[0369] The key used for security protection between the terminal device and the second access network device can be a key derived from / derived from the first key, such as the RRC key and / or UP key between the terminal device and the second access network device. For example, the terminal device can perform security protection on the signaling and / or data between the terminal device and the second access network device based on the first key by using the RRC key and / or UP key derived from the first key.
[0370] After the terminal device activates the security protection between itself and the second access network device, for uplink data between the terminal device and the second access network device, the terminal device can perform security protection based on the RRC key and / or UP key between itself and the second access network device, which is encryption and / or integrity protection. For downlink data between the terminal device and the second access network device, the terminal device can perform security processing (or security protection processing) based on the RRC key and / or UP key between itself and the second access network device, which is decryption and / or integrity verification.
[0371] 609. The terminal device switches to the third access network device based on the second information of the third access network device.
[0372] For example, a terminal device may switch to a third access network device based on parameters included in the second information of the third access network device for switching the terminal device to the third access network device.
[0373] As one possible implementation, in response to the first information, the terminal device can switch the primary access network device from the first access network device to the third access network device based on the second information of the third access network device. For example, the terminal device can determine based on the first information that it needs to switch the primary access network device from the first access network device to the third access network device, and accordingly, the terminal device can switch the primary access network device from the first access network device to the third access network device based on the second information of the third access network device.
[0374] For example, if a random access procedure needs to be performed between the terminal device and the third access network device, and the terminal device does not have a valid TA (Transfer Address Translation), the terminal device can initiate a random access procedure to the third access network device. For instance, the terminal device can initiate a random access procedure to access the third access network device based on the parameters for accessing the third access network device included in the second information of the third access network device.
[0375] Optionally, the terminal device may send a handover completion message to the third access network device. For example, after accessing the third access network device, the terminal device may send a handover completion message to the third access network device. As another example, after the terminal device completes its second information configuration based on the third access network device, it may send a handover completion message to the third access network device. The handover completion message may be an RRC reconfiguration completion message.
[0376] It is understandable that the handover of a terminal device to a third access network device may include: initiating random access to the third access network device, and / or sending a handover completion message (RRC reconfiguration completion message) to the third access network.
[0377] For example, the terminal device can use the RRC key between itself and the second access network device to send a handover completion message to the second access network device.
[0378] It should be noted that the execution order of steps 606, 607-608, and 609 is not limited in this embodiment. For example, steps 606, 607, and 609 can be executed simultaneously. Another example is that step 609 can be executed simultaneously with step 606, and step 607 can be executed after step 606. That is, after the terminal device accesses the second access network device, the terminal device then deduces the first key and activates the security protection with the second access network device. Yet another example is that steps 609, 606, and 607 can be executed simultaneously, and step 608 can be executed after steps 606 and 607 are completed. That is, after the terminal device deduces the first key and accesses the second access network device, the terminal device then activates the security protection with the second access network device.
[0379] 610, The third access network device sends the first key between the terminal device and the second access network device to the second access network device.
[0380] After receiving the first message from the first access network device, the third access network device can send the first key (such as Ksn1) between the terminal device and the second access network device to the second access network device. Correspondingly, the second access network device can receive the first key between the terminal device and the second access network device from the third access network device.
[0381] For example, a third access network device may send an SN add / modify request message to a second access network device. This SN add / modify request message may include a first key (such as Ksn1) between the terminal device and the second access network device. Correspondingly, the second access network device may receive the SN add / modify request message from the third access network device. Optionally, after receiving the SN add / modify request message, the second access network device may send an SN add / modify request confirmation message to the third access network device. Correspondingly, the third access network device may receive the SN add / modify request confirmation message from the second access network device. Optionally, after receiving the SN add / modify request confirmation message from the second access network device, the third access network device may also directly send an SN reconfiguration complete message to the second access network device.
[0382] It should be noted that in this embodiment, the terminal device can be activated to activate the security protection between itself and the second access network device through step 604. The third access network device does not need to send an RRC connection reconfiguration message to the terminal device to activate the security protection between itself and the second access network device (refer to Figure 5), which can improve the efficiency of security protection activation.
[0383] In some possible implementations, the third access network device can determine the first key (such as Ksn1) between the terminal device and the second access network device based on the key between the third access network device and the terminal device.
[0384] For example, if the first message includes a key between the third access network device and the terminal device, the third access network device can determine the first key based on that key. As one possible implementation, in response to the first message, the third access network device can determine the first key based on the key between the third access network device and the terminal device, and can send the first key to the second access network device.
[0385] There are several ways to implement the third access network device's determination of the first key between the terminal device and the second access network device based on the key between the third access network device and the terminal device. For example, the third access network device can deduce the first key between the terminal device and the second access network device based on the key between the terminal device and the third access network device (such as KgNB1) and a second input parameter. The second input parameter may include a first SN counter, which is the same first SN counter used by the terminal device to deduce the first key. This first SN counter can be maintained by the third access network device or can be a preset value / default value (such as all zeros).
[0386] It should be noted that the execution order of step 610 is not limited in this embodiment. For example, the third access network device may calculate the first key immediately after step 605 and then execute step 610, or the third access network device may execute step 610 at other times after step 605, such as after the terminal device accesses the third access network device.
[0387] 611. The second access network device activates the security protection between the second access network device and the terminal device according to the first key.
[0388] After receiving the first key between the terminal device and the second access network device from the third access network device, the second access network device can activate security protection between the second access network device and the terminal device, and perform security protection on the signaling and / or data between the terminal device and the second access network device based on the first key. It should be noted that the security protection activated by the second access network device can include uplink security protection and downlink security protection between the second access network device and the terminal device.
[0389] It is understandable that the second access network device can also deduce the RRC key and / or UP key between the terminal device and the second access network device based on the first key (Ksn1).
[0390] For example, the second access network device can perform security protection on the signaling and / or data between the terminal device and the second access network device based on the first key as follows: the second access network device performs security protection on the signaling and / or data between the terminal device and the second access network device based on the RRC key and / or UP key between the terminal device and the second access network device derived from the first key.
[0391] After the second access network device activates security protection between itself and the terminal device, for downlink data between the terminal device and the second access network device, the second access network device can perform security protection based on the RRC key and / or UP key between itself and the terminal device, which is encryption and / or integrity protection. For uplink data between the terminal device and the second access network device, the second access network device can perform security processing (or security protection processing) based on the RRC key and / or UP key between itself and the terminal device, which is decryption and / or integrity verification.
[0392] The above process is illustrated by taking the activation of security protection between the second access network device and the terminal device after the second access network device receives the first key from the third access network device as an example. However, in some possible implementations, the second access network device can activate the security protection between the second access network device and the terminal device based on the first key after the terminal device has completed random access. In still other possible implementations, the second access network device can activate the security protection between the second access network device and the terminal device based on the first key after sending a SN add / modify request confirmation message to the third access network device. In yet another possible implementation, the second access network device can activate the security protection between the second access network device and the terminal device based on the first key after receiving a SN reconfiguration completion message from the third access network device.
[0393] Optionally, after the terminal device switches from the first access network device to the third access network device, the above method may further include:
[0394] 612, the third access network device obtains the second NCC from the AMF network element.
[0395] Optionally, the third access network device can also receive the NH corresponding to the second NCC from the AMF network element. The third access network device can store the second NCC and the NH corresponding to the second NCC.
[0396] For example, the third access network device can send a path handover request message to the AMF network element. Correspondingly, after receiving the path handover request message, the AMF network element can update and increment its locally stored NCC value (e.g., the first NCC) to obtain an updated NCC (e.g., the second NCC). It then performs key deduction based on the updated NCC to obtain the NH corresponding to the second NCC and can send a path handover response message to the third access network device. The path handover response message includes the second NCC and the NH corresponding to the second NCC. In one possible implementation, the third access network device can send a path handover request message to the AMF network element in response to a handover completion message sent by the terminal device.
[0397] In some possible implementations, after the third access network device obtains the second NCC and the NH corresponding to the second NCC from the AMF network element, it can calculate a new key between the terminal device and the third access network device (including the new RRC key and / or UP key between the new terminal device and the third access network device) based on the NH corresponding to the second NCC, or it can calculate a new key between the terminal device and the second access network device based on the NH corresponding to the second NCC, and then save the new key. For example, the third access network device can deduce the new key between the terminal device and the third access network device based on the NH corresponding to the second NCC and the first input parameters, or it can deduce the new key between the terminal device and the second access network device based on the new key between the terminal device and the third access network device and the second input parameters. Furthermore, the third access network device can also send the new key (Ksn) between the terminal device and the second access network device to the second access network device so that the second access network device can calculate the new RRC key and / or UP key between the terminal device and the second access network device. The third access network device can also send information to the terminal device to instruct the second NCC, triggering the terminal device to calculate a new key between the terminal device and the third access network device (including calculating the new RRC key and / or UP key between the terminal device and the third access network device), and a key between the terminal device and the second access network device (including calculating the new RRC key and / or UP key between the terminal device and the second access network device). Optionally, the third access network device can calculate the new key between the terminal device and the third access network device, and the new key between the terminal device and the second access network device, based on the NH corresponding to the second NCC. Then, it can save the new key and delete the old key, updating the old key to the new key. Similarly, after calculating the new key between the terminal device and the third access network device, and the new key between the terminal device and the second access network device, based on the NH corresponding to the second NCC, the third access network device can save the new key and delete the old key, updating the old key to the new key. Similarly, after the second access device calculates the new RRC key and / or UP key between the terminal device and the second access network device, it can delete the old RRC key and / or UP key.
[0398] In this embodiment of the application, during each LTM handover process, the corresponding source access network device sends information to the terminal device to indicate the relevant NCC obtained from the AMF, which facilitates secure communication between the second access network device and the terminal device using the updated key.
[0399] It is understandable that the key between the terminal device and the access network device can be stored in the access stratum (AS) security context, and both the terminal device and the access network device can maintain the AS security context corresponding to the terminal device.
[0400] It should be noted that the execution order of steps 612 and 609 / 610 is not limited in this embodiment. For example, the third access network device can execute step 612 at any time after the terminal device accesses the third access network device.
[0401] It is hereby clarified that, in the embodiments of this application, for steps that are not related, the execution order of these steps is not limited and they can be executed in parallel or in a certain order (such as between steps 606, 607, and 609). For steps that are related (such as between steps 605, 610, and 611, or between steps 604 and 606, or between steps 604 and 607, or between steps 604 and 609), these steps can be executed in the corresponding order. Furthermore, to improve handover efficiency and / or security protection activation efficiency, these steps can be executed immediately after the completion of one step. For example, after receiving the first message from the first access network device (step 605), the third access network device can immediately calculate the first key and send the first key to the second access network device (step 610). After receiving the first key from the third access network device, the second access network device can immediately activate the security protection between itself and the terminal device based on the first key (step 611).
[0402] The above process only describes the implementation of the terminal device switching from the first access network device to the third access network device. The terminal device can subsequently perform one or more LTM handovers, such as switching from the third access network device to the fourth access network device, and from the fourth access network device to the sixth access network device. The implementation of "the terminal device switching from the third access network device to the fourth access network device" and "the terminal device switching from the fourth access network device to the sixth access network device" can be referred to the description of "the terminal device switching from the first access network device to the third access network device," and will not be repeated here.
[0403] It is understandable that in the above process, during the LTM handover, the terminal device can be triggered to activate the security protection between itself and the second access network device through step 604. This eliminates the need for the third access network device to send an RRC reconfiguration message carrying the SN counter for activation, thereby reducing the time required to activate the security protection and improving the efficiency of security protection activation.
[0404] Figure 7 shows a possible implementation example of the method shown in Figure 6. In Figure 7, access network device 0 can be the source access network device in the LTM handover preparation phase. Access network device 0 and access network device 1 can be the source access network device and target access network device in the first LTM handover process, respectively. Access network device 1 and access network device 2 can be the source access network device and target access network device in the second LTM handover process, respectively. Therefore, the relevant descriptions of access network device 0, access network device 1, and access network device 2 can refer to the relevant descriptions of the first or second access network device in Figure 6. In Figure 7, taking the example that the secondary access network device remains unchanged in the LTM handover preparation and LTM handover phases, that is, the secondary access network device in Figure 7 can be the secondary access network device corresponding to access network device 1 and the secondary access network device corresponding to access network device 2. As shown in Figure 7, the process may include, but is not limited to, the following steps:
[0405] Steps 701-712 are the same as steps 501-512 above, and you can refer to the relevant descriptions in steps 501-512 above.
[0406] 713, Access network device 0 determines that the terminal device needs to perform LTM cross-site handover, and the target access network device for handover is access network device 1.
[0407] 714, Access network device 0 sends a handover command message to the terminal device.
[0408] Accordingly, the terminal device receives a handover command message from access network device 0. The handover command message can be a MAC layer message, such as a MAC CE.
[0409] The handover command message may include first information and an NCC (Non-Command Control). The first information is used by the terminal device to switch the primary access network device from access network device 0 to access network device 1. The NCC can be used to determine the KgNB between the terminal device and access network device 1, and the Ksn between the terminal device and the secondary access network device. The first information can be referred to the relevant description in step 604 above, and will not be repeated here.
[0410] As one possible implementation, the switching command message can be a dedicated message for LTM switching.
[0411] 715, Access network device 0 sends a handover notification message to access network device 1.
[0412] Accordingly, access network device 1 receives a handover notification message from access network device 0. The handover notification message is used to indicate that a handover command message has been sent to the terminal device.
[0413] As one possible implementation, the handover notification message can be a dedicated message for LTM handover. The handover notification message may include the identifier of the terminal device requiring LTM handover.
[0414] It is understandable that access network device 0 can also send relevant information to secondary access network device to trigger the secondary access network device release (SNrelease) process, so that the secondary access network device can release relevant resources, such as deleting the currently stored RRC key and / or UP key used for communication with the terminal device.
[0415] 716. The terminal device calculates the key between itself and the secondary access network device based on the NCC in the handover command message.
[0416] For example, the terminal device can calculate the Ksn between the terminal device and the secondary access network device based on the KgNB corresponding to the NCC in the handover command message and the SN counter. Furthermore, the terminal device can also calculate the RRC key and / or UP key between the terminal device and the secondary access network device based on the Ksn between them.
[0417] Optionally, the SN counter used to calculate the Ksn between the terminal device and the secondary access network device can be a preset value, or it can be carried in the handover command message, or it can be configured to the terminal device during the LTM handover preparation phase.
[0418] 717, in response to the first information in the handover command message, the terminal device activates security protection between the terminal device and the secondary access network device.
[0419] For example, in response to the first information in the handover command message, the terminal device can activate security protection with the secondary access network device based on the calculated key between the terminal device and the secondary access network device.
[0420] 718, Access Network Device 1 sends a Secondary Access Network Device Add Request message to the Secondary Access Network Device, including Ksn.
[0421] For example, after receiving a handover notification message from access network device 0, access network device 1 can send a secondary access network device add request message to the secondary access network device. Accordingly, the secondary access network device can receive the secondary access network device add request message from access network device 1, which may include a Ksn, that is, the key between the terminal device and the secondary access network device.
[0422] As one possible implementation, access network device 1 can deduce Ksn based on the corresponding SN counter and KgNB carried in the handover notification message of step 715.
[0423] 719, the secondary access network device sends a secondary access network device addition request confirmation message to access network device 1.
[0424] 720, Access network device 1 sends an SN reconfiguration complete message to the secondary access network device.
[0425] Steps 719 and 720 are optional.
[0426] 721, Security protection between secondary access network equipment activation and terminal equipment.
[0427] For example, after receiving a secondary access network device add request message from access network device 1, the secondary access network device can activate the key between the terminal device and the secondary access network device and implement security protection between the terminal devices. As another example, after sending a secondary access network device add request confirmation message to access network device 1, the secondary access network device can activate the key between the terminal device and the secondary access network device and implement security protection between the terminal devices. As yet another example, after receiving an SN reconfiguration complete message from access network device 1, the secondary access network device can activate the key between the terminal device and the secondary access network device and implement security protection between the terminal devices.
[0428] 722, the random access process between the terminal equipment and the secondary access network equipment.
[0429] For example, if a random access procedure between the terminal device and the SN needs to be performed, the terminal device can initiate a random access procedure to the SN. As one possible implementation, the terminal device can initiate a random access procedure to the SN based on the access parameters received in step 712.
[0430] It should be understood that access network device 1 can also trigger a path switching process to switch the data transmission path of the terminal device from "UPF network element - access network device 0 - terminal device" to "UPF network element - access network device 1 - terminal device".
[0431] It is understandable that the terminal device can subsequently switch from access network device 1 to access network device 2, the implementation of which can refer to the description of the terminal device switching from access network device 0 to access network device 1, that is, the relevant descriptions in steps 713-722. It is also understandable that if the candidate primary access network device for LTM handover also includes access network device 3, then the terminal device can subsequently switch from access network device 2 to access network device 3, the implementation of which can also refer to the relevant description of the terminal device switching from access network device 0 to access network device 1.
[0432] It is understandable that the random access between the terminal device and access network device 1 has no prior or subsequent constraints on the random access between the terminal device and the secondary base station.
[0433] Furthermore, the flow shown in Figure 7 corresponds to the flow shown in Figure 6, and the steps of the two can be referred to each other. For example, steps 601 and 602 can refer to steps 702-712, step 603 can refer to step 713, step 604 can refer to step 714, step 605 can refer to step 715, step 606 can refer to step 722, steps 607 and 608 can refer to steps 716 and 717, step 610 can refer to step 718, and step 611 can refer to step 721.
[0434] It should be understood that Figure 7 above is merely an example and does not constitute a limitation. For example, Figure 7 may also include steps such as the terminal device switching to access network device 1.
[0435] In the above process, the terminal device can activate the security protection between the terminal device and the access network device by switching command messages, and the secondary access network device can activate the security protection between the terminal device and the terminal device by adding request messages carrying Ksn. There is no need for RRC reconfiguration messages (refer to Figure 5). Furthermore, the interaction process can be reduced, thereby improving the activation efficiency of security protection between the terminal device and the secondary access network device.
[0436] Using the scheme shown in Figure 6, there may be a time interval between the terminal device activating security protection with the second access network device and the second access network device activating security protection with the terminal device. For example, in some cases, the terminal device may have already connected to the second access network device and activated security protection with it, but the second access network device may not have activated security protection with the terminal device yet (e.g., it has not yet received the first key from the third access network device). In this situation, if the terminal device sends uplink data secured by the first key to the second access network device, the second access network device may not be able to process / parse it properly because it does not have the corresponding key, and thus will discard the uplink data.
[0437] Please refer to Figure 8, which is a flowchart illustrating another communication method disclosed in this application. Similar to Figure 6, the relevant steps in Figure 8 can be found in Figure 6. In Figure 8, to prevent the loss of uplink data between the terminal device and the second access network device, the second access network device can set up a corresponding caching mechanism. If the second access network device has not yet activated security protection with the terminal device based on the first key, but the terminal device has already sent uplink data to the second access network device after security protection based on the first key, the second access network device can cache this uplink data. As shown in Figure 8, this method may include, but is not limited to, the following steps:
[0438] Steps 801-809 are the same as steps 601-609 above, and you can refer to the relevant descriptions in steps 601-609 above.
[0439] 810. The terminal device sends uplink data to the second access network device. This uplink data is securely protected based on the first key.
[0440] Accordingly, the second access network device can receive the uplink data from the terminal device.
[0441] For example, after the terminal device activates security protection between itself and the second access network device, for uplink data between the terminal device and the second access network device, the terminal device can perform security protection (integrity protection and / or encryption) on the uplink data to be sent based on the communication key (RRC key and / or UP key) generated by the first key, and then send the securely protected uplink data to the second access network device. Accordingly, the second access network device can receive the securely protected uplink data from the terminal device.
[0442] In some possible implementations, the terminal device can send uplink data to the second access network device using parameters / resources configured during the LTM preparation phase, that is, by sending uplink data to the second access network device using parameters / resources included in the third information of the second access network device. In other words, the third information of the second access network device may include parameters and / or resources (such as DRB parameters and / or resources, and / or SRB parameters and / or resources) used by the terminal device to send uplink data during subsequent LTM handover. Similarly, the third information of the second access network device may include parameters and / or resources (such as DRB parameters and / or resources, and / or SRB parameters and / or resources) used by the terminal device to receive downlink data during subsequent LTM handover.
[0443] 811. If the first key does not exist, the second access network device caches the uplink data.
[0444] For example, when the second access network device receives uplink data protected by the first key from the terminal device, if the first key does not exist, the second access network device cannot process it and can first cache the uplink data protected by the first key. Here, "the first key does not exist" can also be understood as the first key being unavailable, or it could mean that the first key does not exist in the second access network device, or that the first key is not stored locally in the second access network device, or that the first key is not included in the keys stored locally in the second access network device, or that the second access network device has not yet received the first key from the third access network device, or that the second access network device has not yet activated the security protection between the terminal device and the second access network device based on the first key, or that the second access network device has not yet deduced the communication key (RRC key and / or UP key) between itself and the terminal device based on the first key, etc.
[0445] In some possible implementations, from the perspective of the second access network device, the second access network device can maintain the key between itself and the terminal device, determine the current key status between itself and the terminal device, and thus determine whether a key exists between itself and the terminal device. If no key (such as an RRC key, UP key, KSN, etc.) exists between itself and the terminal device, the second access network device can buffer the received uplink data from the terminal device and process it after receiving the first key from the third access network device. If a key (such as an RRC key, UP key, KSN, etc.) exists between itself and the terminal device, the second access network device can perform secure processing on the uplink data from the terminal device based on the corresponding key. For example, the second access network device can maintain the AS security context of the terminal device. If the AS security context of the terminal device includes a key between itself and the terminal device, the second access network device can determine that a key exists between itself and the terminal device; otherwise, the second access network device can determine that a key does not exist between itself and the terminal device.
[0446] For example, the second access network device can allocate resources to the terminal device, such as allocating resources to the terminal device during the LTM preparation phase. Therefore, the second access network device can determine which terminal device the uplink data comes from based on the resources of the received uplink data.
[0447] To enable the second access network device to more effectively cache relevant uplink data, in some possible implementations, relevant trigger conditions (or caching conditions) for caching uplink data can be set for the second access network device. For example, the trigger conditions for caching uplink data may include one or more of the following conditions:
[0448] Condition 1: Random access is completed between the terminal device and the second access network device, and the first key does not exist. The parameters and / or resources used for this random access are configured during the LTM handover preparation phase, such as those configured by the second access network device during the LTM handover preparation phase. Condition 1 can be understood as follows: After the terminal device completes random access with the second access network device using the parameters and / or resources configured during the LTM handover preparation phase, and before the first key exists (e.g., before receiving the first key from the third access network device, or before activating security protection with the terminal device based on the first key), if the second access network device receives uplink data from the terminal device, the second access network device can cache the corresponding uplink data.
[0449] Condition 2: Uplink data is received using parameters and / or resources configured during the LTM handover preparation phase (e.g., parameters and / or resources configured by the second access network device during the LTM handover preparation phase), and the first key does not exist. Condition 2 can be understood as follows: Before the first key exists, if the second access network device receives uplink data using parameters and / or resources configured during the LTM handover preparation phase—that is, if the parameters and / or resources used in the uplink data received by the second access network device match the parameters and / or resources configured during the LTM handover preparation phase—the second access network device can cache the corresponding uplink data. For example, the parameters and / or resources configured by the second access network device during the LTM handover preparation phase can be carried in the third information of the second access network device, such as the parameters and / or resources configured for sending uplink data.
[0450] Condition 3: A secondary base station release message is received from the first access network device, and the first key does not exist. This secondary base station release message is used to release the connection established between the terminal device and the second access network device when the first access network device is the primary access network device for the terminal device. Alternatively, it can be understood as releasing the connection that exists between the terminal device and the second access network device when the first access network device is the primary access network device for the terminal device; that is, the SRB and / or DRB that need to be released when the primary access network device switches from the first access network device to the third access network device. Condition 3 can be understood as follows: After receiving the secondary base station release message from the first access network device, and before the first key exists, if the second access network device receives uplink data from the terminal device, the second access network device can cache the corresponding uplink data. In some possible implementations, condition 3 applies when the secondary access network device corresponding to the first access network device is also the second access network device.
[0451] Furthermore, in some cases, the corresponding upstream data can be cached if any one of one or more conditions is met. For example, the corresponding upstream data can be cached if any one of conditions 1, 2, and 3 is met. Similarly, the corresponding upstream data can be cached if any one of conditions 1 and 2 is met. In other cases, the corresponding upstream data can also be cached if multiple conditions are met simultaneously. For example, the corresponding upstream data can be cached if conditions 1 and 2 (condition 1 + condition 2), or conditions 1 and 3 (condition 1 + condition 3), or conditions 2 and 3 (condition 2 + condition 3) are met. For example, the corresponding upstream data can be cached if conditions 1 and 2 are met. Taking condition 1+2 as an example, condition 1+2 can be understood as follows: after the terminal device completes random access with the second access network device using the parameters and / or resources configured in the LTM handover preparation phase, and before the first key exists, if the second access network device receives uplink data sent using the parameters and / or resources configured in the LTM handover preparation phase, the second access network device can cache the corresponding uplink data.
[0452] 812, the third access network device sends the first key between the terminal device and the second access network device to the second access network device.
[0453] 813. The second access network device activates the security protection between the second access network device and the terminal device according to the first key.
[0454] In this embodiment, the activation of security protection between the second access network device and the terminal device based on the first key by the second access network device can mean that the second access network device can perform security protection or security processing based on the first key for subsequent uplink and downlink data between the terminal device and the second access network device. Similarly, the activation of downlink security protection between the second access network device and the terminal device based on the first key by the terminal device can mean that the terminal device can perform security protection or security processing based on the first key for subsequent uplink and downlink data between the terminal device and the second access network device. Other cases can be understood similarly and will not be elaborated further here.
[0455] Based on the above description, it can be seen that the activation of security protection between the second access network device and the terminal device by the second access network device according to the first key can be considered a state change of the second access network device. Similarly, the activation of security protection between the terminal device and the second access network device by the terminal device according to the first key can be considered a state change of the terminal device. In other words, the operation of activating security protection between the second access network device and the terminal device according to the first key may not necessarily occur; it may simply indicate a state change between the terminal device and the second access network device.
[0456] 814. The second access network device performs secure processing on the cached uplink data based on the first key.
[0457] After the second access network device obtains the first key (or activates security protection between the terminal device and the second access network device based on the first key, or derives the communication key between the terminal device and the terminal device based on the first key), the second access network device can perform secure processing on the cached uplink data based on the first key.
[0458] Understandably, the second access network device can also perform security protection on the downlink data of the terminal device based on the first key, obtain the security-protected downlink data, and then send the security-protected downlink data to the terminal device. Correspondingly, the terminal device can receive the security-protected downlink data from the second access network device, and then perform security processing (integrity verification and / or decryption) on the security-protected downlink data based on the first key.
[0459] For example, when the second access network device needs to send downlink data to the terminal device, if the first key does not exist, the second access network device can first cache the downlink data to be sent.
[0460] In some possible implementations, from the perspective of the second access network device, the second access network device can maintain the key between itself and the terminal device, determine the current key status between itself and the terminal device, and thus determine whether a key exists between itself and the terminal device. If no key exists between itself and the terminal device (such as an RRC key, UP key, Ksn, etc.), the second access network device can buffer the downlink data to be sent and process it after receiving the first key from the third access network device. If a key exists between itself and the terminal device (such as an RRC key, UP key, Ksn, etc.), the second access network device can provide security protection for the downlink data to be sent to the terminal device based on the corresponding key.
[0461] To enable the second access network device to more effectively cache relevant downlink data, in some possible implementations, trigger conditions (or caching conditions) for caching downlink data can be set for the second access network device. For example, the trigger conditions for caching downlink data may include one or more of the following conditions:
[0462] Condition 1: Random access is completed between the terminal device and the second access network device, and the first key does not exist. The parameters and / or resources used for this random access are configured during the LTM handover preparation phase. Condition 1 can be understood as follows: After the terminal device completes random access with the second access network device using the parameters and / or resources configured during the LTM handover preparation phase, and before the first key exists, if the second access network device has downlink data that needs to be sent to the terminal device, the terminal device can cache the corresponding downlink data.
[0463] Condition 2: A release message from the secondary base station is received from the first access network device, and the first key does not exist. Condition 2 can be understood as follows: After the second access network device receives the release message from the secondary base station of the first access network device, and before the first key exists, if the second access network device has downlink data that needs to be sent to the terminal device, the terminal device can cache the corresponding downlink data.
[0464] Furthermore, in some cases, the corresponding downlink data can be cached if any one of one or more conditions is met. For example, the corresponding downlink data can be cached if either condition 1 or condition 2 is met. As another example, the corresponding downlink data can be cached if condition 1 is met. In other cases, the corresponding downlink data can also be cached if multiple conditions are met simultaneously. For example, the corresponding downlink data can be cached if both condition 1 and condition 2 (condition 1 + condition 2) are met.
[0465] After the second access network device obtains the first key (or activates security protection between the terminal device and the second access network device based on the first key, or derives the communication key between the terminal device and the terminal device based on the first key), the second access network device can perform security processing on the cached downlink data based on the first key to obtain the secure downlink data, and then send the secure downlink data to the terminal device.
[0466] Optionally, after the terminal device switches from the first access network device to the third access network device, the above method may further include step 612 in FIG6.
[0467] The above process only describes the implementation of the terminal device switching from the first access network device to the third access network device. The terminal device can subsequently perform one or more LTM handovers, such as switching from the third access network device to the fourth access network device, and from the fourth access network device to the sixth access network device. The implementation of "the terminal device switching from the third access network device to the fourth access network device" and "the terminal device switching from the fourth access network device to the sixth access network device" can be referred to the description of "the terminal device switching from the first access network device to the third access network device," and will not be repeated here.
[0468] It is understandable that, using the scheme shown in Figure 8, when the second access network device receives uplink data from the terminal device, if the first key is not present in the second access network device, it can first cache the uplink data. After receiving the first key from the third access network device, it can then perform secure processing on the previously cached uplink data based on the first key. In this way, secure data transmission can be achieved while avoiding uplink data loss and preventing waste of data transmission resources.
[0469] Figure 9 shows a possible implementation example of the method shown in Figure 8. It should be understood that the steps in Figure 9 can also be referenced to the relevant descriptions in Figures 8, 7, etc. As shown in Figure 9, the process may include, but is not limited to, the following steps:
[0470] Steps 901-917 are the same as steps 701-717 above, and you can refer to the relevant descriptions in steps 701-717 above.
[0471] 918, the terminal device sends uplink data to the secondary access network device, and this uplink data is securely protected based on the first key (the key between the terminal device and the secondary access network device).
[0472] Correspondingly, the secondary access network equipment can receive uplink data from the terminal equipment, which is securely protected based on the first key.
[0473] 919. If the first key does not exist, the secondary access network device caches the uplink data.
[0474] The implementation of steps 918 and 919 can refer to steps 810 and 811 above, and will not be repeated here.
[0475] 920, Access Network Device 1 sends a Secondary Access Network Device Add Request message to the Secondary Access Network Device, including Ksn.
[0476] 921, the secondary access network device sends a secondary access network device addition request confirmation message to access network device 1.
[0477] 922, Access network device 1 sends an SN reconfiguration complete message to the secondary access network device.
[0478] Steps 921 and 922 are optional.
[0479] 923, Security protection between secondary access network equipment activation and terminal equipment.
[0480] 924. The secondary access network device performs secure processing on the cached uplink data based on the first key.
[0481] Step 924 can be referred to step 814 above, and will not be repeated here.
[0482] 925, the random access process between the terminal equipment and the secondary access network equipment.
[0483] It is understandable that the terminal device can subsequently switch from access network device 1 to access network device 2, the implementation of which can refer to the description of the terminal device switching from access network device 0 to access network device 1, that is, the relevant descriptions in steps 913-925. It is also understandable that if the candidate primary access network device for LTM handover also includes access network device 3, then the terminal device can subsequently switch from access network device 2 to access network device 3, the implementation of which can also refer to the relevant description of the terminal device switching from access network device 0 to access network device 1.
[0484] It should be understood that Figure 9 above is merely an example and does not constitute a limitation. For example, Figure 9 may also include steps such as the terminal device switching to access network device 1 and path switching.
[0485] In the above process, by setting up a mechanism for the secondary access network device to cache uplink data, it is possible to avoid the situation where uplink data is lost because the secondary access network device cannot process the uplink data sent by the terminal device after security protection based on the first key before the security protection between the secondary access network device and the terminal device is activated.
[0486] Please refer to Figure 10, which is a flowchart illustrating another communication method disclosed in this application. It should be understood that the steps in Figure 10 can also be referenced to the relevant descriptions in Figures 6 and 8. In Figure 10, to avoid the loss of uplink data between the terminal device and the second access network device, the terminal device can decouple the activation of downlink security protection and uplink security protection with the second access network device. For example, the terminal device can first activate downlink protection with the second access network device, and then activate uplink security protection upon receiving fourth information or downlink data from the second access network device. The terminal device can also set a corresponding caching mechanism. If the terminal device has not yet activated uplink security protection with the second access network device, but the terminal device needs to send uplink data to the second access network device, the second access network device can cache this uplink data. After activating uplink security protection with the second access network device, the cached uplink data will be protected, and the protected uplink data will be sent. As shown in Figure 10, this method may include, but is not limited to, the following steps:
[0487] Steps 1001-1007 are the same as steps 601-607 above, and you can refer to the relevant descriptions in steps 601-607 above.
[0488] 1008, The terminal device switches to the third access network device based on the second information of the third access network device.
[0489] Step 1008 is similar to step 609, and you can refer to the relevant description in step 609.
[0490] 1009, The third access network device sends the first key between the terminal device and the second access network device to the second access network device.
[0491] 1010, The second access network device activates the security protection between the second access network device and the terminal device according to the first key.
[0492] Steps 1009 and 1010 are similar to steps 610 and 611, respectively, and can be referred to the relevant descriptions in steps 610 and 611.
[0493] 1011, the second access network device sends fourth information or downlink data to the terminal device. The fourth information is used to indicate the activation of security protection between the terminal device and the second access network device. The downlink data is downlink data based on the first key security protection.
[0494] Accordingly, the terminal device can receive fourth information or downlink data from the second access network device.
[0495] As one possible implementation, after activating security protection between the second access network device and the terminal device according to the first key, the second access network device can send fourth information to the terminal device. This fourth information can be used to trigger the terminal device to activate security protection (such as uplink security protection and downlink security protection) between the terminal device and the second access network device. For example, the fourth information can be a dedicated message (such as a dedicated notification message), or carried within such a dedicated message, or it can be indication information carried in an existing message. This dedicated message or existing message can be an RRC message or a MAC layer message. If the dedicated message or existing message is an RRC message, the second access network device can perform security protection on the dedicated message or existing message based on the first key. Correspondingly, the terminal device can perform secure processing on the protected dedicated message or existing message based on the first key.
[0496] As another possible implementation, after activating the security protection between the second access network device and the terminal device according to the first key, the second access network device can send downlink data secured by the first key to the terminal device. This downlink data secured by the first key can be used to trigger the terminal device to activate the security protection between the terminal device and the second access network device (such as uplink security protection and downlink security protection). Essentially, this downlink data secured by the first key has the function of the aforementioned fourth information. For example, in some possible cases, after activating the security protection between the second access network device and the terminal device according to the first key, the second access device can also send downlink data not secured by the first key to the terminal device. This downlink data not secured by the first key can be used to trigger the terminal device to activate the security protection between the terminal device and the second access network device (such as uplink security protection and downlink security protection). It should be understood that either the fourth information triggering the terminal device to activate the security protection between the terminal device and the second access network device, or the downlink data triggering the terminal device to activate the security protection between the terminal device and the second access network device, can be used alone or in combination.
[0497] In some possible implementations, after the second access network device activates the security protection between itself and the terminal device based on the first key, the second access network device can check whether there is downlink data from the terminal device to be transmitted. If there is no downlink data to be transmitted, the second access network device can send a fourth message to the terminal device to trigger the activation of the security protection between the terminal device and the second access network device. If there is downlink data to be transmitted, the second access network device does not need to send the fourth message. It can perform security protection on the downlink data based on the first key and then send the protected downlink data to the terminal device to trigger the activation of the security protection between the terminal device and the second access network device. It should be understood that compared to triggering the activation of the security protection between the terminal device and the second access network device through the fourth message, triggering the activation of the security protection through the protected downlink data based on the first key reduces the transmission of downlink signaling, thereby saving transmission resources.
[0498] In some possible implementations, after the second access network device activates the security protection between itself and the terminal device based on the first key, the second access network device can check whether there is downlink data from the terminal device to be transmitted. If there is, the second access network device can perform security protection on the downlink data based on the first key, and then send the securely protected downlink data to the terminal device. This triggers the terminal device to activate the security protection between itself and the second access network device through the securely protected downlink data based on the first key. If there is no downlink data to be transmitted, the second access network device can start a timer (e.g., 100ms). Before the timer expires, if there is downlink data to be transmitted, the second access network device can perform security protection on the downlink data based on the first key, and then send the securely protected downlink data to the terminal device. This triggers the terminal device to activate the security protection between itself and the second access network device through the securely protected downlink data based on the first key. The timer can then be terminated. When the counter ends, if there is still no downlink data to be sent from the terminal device, the second access network device can send a fourth message to the terminal device to trigger the terminal device to activate the security protection between the terminal device and the second access network device.
[0499] Understandably, after the second access network device obtains the first key (or activates security protection between the terminal device and the second access network device based on the first key, or derives the communication key between the terminal device and the terminal device based on the first key), the second access network device can perform security protection on the downlink data of the terminal device according to the first key, obtain the secure downlink data, and then send the secure downlink data to the terminal device. Correspondingly, the terminal device can receive the secure downlink data from the second access network device and can perform security processing (integrity verification and / or decryption) on the secure downlink data based on the first key.
[0500] For example, when the second access network device needs to send downlink data to the terminal device, if the first key does not exist, the second access network device cannot process it and can first cache the downlink data to be sent.
[0501] In some possible implementations, from the perspective of the second access network device, the second access network device can maintain the key between itself and the terminal device, determine the current key status between itself and the terminal device, and thus determine whether a key exists between itself and the terminal device. If no key exists between itself and the terminal device (such as an RRC key, UP key, Ksn, etc.), the second access network device can buffer the downlink data to be sent and process it after receiving the first key from the third access network device. If a key exists between itself and the terminal device (such as an RRC key, UP key, Ksn, etc.), the second access network device can provide security protection for the downlink data to be sent to the terminal device based on the corresponding key.
[0502] To enable the second access network device to cache relevant downlink data more effectively, in some possible implementations, relevant trigger conditions (or caching conditions) for caching downlink data can be set for the second access network device. The relevant description of the trigger conditions for caching downlink data can be found in step 814 above, and will not be repeated here.
[0503] After the second access network device obtains the first key (or activates security protection between the terminal device and the second access network device based on the first key, or derives the communication key between the terminal device and the terminal device based on the first key), the second access network device can perform security processing on the cached downlink data based on the first key to obtain the secure downlink data, and then send the secure downlink data to the terminal device.
[0504] 1012, In response to the fourth information / downlink data, the terminal device activates the security protection between the terminal device and the second access network device.
[0505] For example, in response to the fourth information or downlink data in step 1011, the terminal device can activate the security protection between the terminal device and the second access network device based on the first key. The above description assumes that the first key can be determined after receiving the information for instructing the NCC in step 1004. However, in some possible cases, the terminal device can also determine the first key based on the information for instructing the NCC after responding to the fourth information / downlink data (or after receiving the fourth information / downlink data from the second access network device). This application embodiment does not limit this. It should be noted that in this application embodiment, the timing of the derivation of the first key is not limited. The terminal device can deduce the first key when it is necessary to activate the security protection between the terminal device and the second access network device based on the first key, or it can complete the derivation of the first key before it is necessary to activate the security protection between the terminal device and the second access network device based on the first key.
[0506] As one possible implementation, in response to downlink data, the terminal device activating the security protection between the terminal device and the second access network device according to the first key may include: if the integrity verification of the downlink data passes according to the first key, the terminal device activating the security protection between the terminal device and the second access network device according to the first key.
[0507] In the above process, the security protection between the terminal device and the second access network device activated by the terminal device in response to the fourth information / downlink data, based on the first key, may include uplink security protection and downlink security protection between the terminal device and the second access network device. However, in some other possible implementations, the terminal device may activate downlink security protection between the terminal device and the second access network device in response to the first information, and the fourth information / downlink data may only be used to instruct / trigger the terminal device to activate uplink security protection between the terminal device and the second access network device. Regarding the implementation of the terminal device activating downlink security protection between the terminal device and the second access network device in response to the first information, refer to step 808 above, which describes the implementation of the security protection between the terminal device and the second access network device in response to the first information.
[0508] Understandably, after the terminal device obtains the first key (or activates security protection between the terminal device and the second access network device based on the first key, or derives the communication key between the terminal device and the second access network device based on the first key), the terminal device can perform security protection on its uplink data according to the first key, obtain the securely protected uplink data, and then send the securely protected uplink data to the second access network device. Correspondingly, the second access network device can receive the securely protected uplink data from the terminal device, and then perform security processing (integrity verification and / or decryption) on the securely protected uplink data based on the first key.
[0509] For example, when a terminal device needs to send uplink data to a second access network device, if the first key does not exist (or the uplink security protection between the terminal device and the second access network device is not activated based on the first key), the terminal device cannot process the data and can first cache the uplink data to be sent. In this embodiment, "the first key does not exist" on the terminal device side can also mean that the first key is unavailable, or that the first key is not stored locally, or that the first key is not included in the locally stored keys, or that the first key has not yet been received from the first access network device, or that the security protection between the terminal device and the second access network device has not yet been activated based on the first key, or that the fourth information (from the second access network device) used to activate the security protection between the terminal device and the second access network device (refer to step 1011) has not yet been received, or that the downlink data (from the second access network device) used to activate the security protection between the terminal device and the second access network device (refer to step 1011) has not yet been received, or that the communication key (RRC key and / or UP key) between the terminal device and the terminal device has not yet been deduced based on the first key, etc.
[0510] In some possible implementations, from the perspective of the terminal device, the terminal device can maintain the key with the second access network device, determine the current key status with the second access network device, and thus determine whether a key exists with the second access network device. If no key (such as RRC key, UP key, Ksn, etc.) exists with the second access network device, the terminal device can cache the uplink data to be sent and process it after the first key is derived. If a key (such as RRC key, UP key, Ksn, etc.) exists with the second access network device and uplink security protection with the second access network device has been activated, the terminal device can perform security protection on the uplink data to be sent to the second access network device based on the corresponding key.
[0511] To enable terminal devices to cache relevant uplink data more effectively, in some possible implementations, trigger conditions (or caching conditions) for caching uplink data can be set for the terminal device. For example, the trigger conditions for caching uplink data may include one or more of the following conditions:
[0512] Condition 1: Random access is completed between the terminal device and the second access network device, and the first key does not exist. The parameters and / or resources used for this random access are configured during the LTM handover preparation phase. Condition 1 can be understood as follows: After the terminal device completes random access with the second access network device using the parameters and / or resources configured during the LTM handover preparation phase, and before the first key exists, if the terminal device has uplink data that needs to be sent to the second access network device, the terminal device can cache the corresponding uplink data.
[0513] Condition 2: The terminal device receives the first information (or the first MAC layer message) from the first access network device, and the first key does not exist. Condition 2 can be understood as follows: After the terminal device receives the first information (or the first MAC layer message) from the first access network device, and before the first key exists (e.g., before the security protection between the terminal device and the second access network device is activated according to the first key, or before the fourth information and downlink data in step 1011 are received), if the terminal device has uplink data that needs to be sent to the second access network device, the terminal device can cache the corresponding uplink data.
[0514] Furthermore, in some cases, the upstream data can be cached if any one of one or more conditions is met. For example, the upstream data can be cached if either condition 1 or condition 2 is met. As another example, the upstream data can be cached if condition 1 is met. In other cases, the upstream data can also be cached if multiple conditions are met simultaneously. For example, the upstream data can be cached if both condition 1 and condition 2 (condition 1 + condition 2) are met.
[0515] It should be understood that after the terminal device obtains the first key (or activates uplink security protection between the terminal device and the second access network device based on the first key), the terminal device can perform security processing on the cached uplink data based on the first key to obtain the secure uplink data, and then send the secure uplink data to the terminal device.
[0516] Optionally, after the terminal device switches from the first access network device to the third access network device, the above method may further include step 612 in FIG6.
[0517] The above process only describes the implementation of the terminal device switching from the first access network device to the third access network device. The terminal device can subsequently perform one or more LTM handovers, such as switching from the third access network device to the fourth access network device, and from the fourth access network device to the sixth access network device. The implementation of "the terminal device switching from the third access network device to the fourth access network device" and "the terminal device switching from the fourth access network device to the sixth access network device" can be referred to the description of "the terminal device switching from the first access network device to the third access network device," and will not be repeated here.
[0518] It is understandable that, by adopting the scheme shown in Figure 10, after the second access network device activates the security protection between the second access network device and the terminal device according to the first key, it can send the fourth information or downlink data to the terminal device to trigger the terminal device to activate the security protection (or uplink security protection) between the terminal device and the second access network device. This can avoid the situation where uplink data is lost due to the asynchronous activation of security protection between the terminal device and the second access network device.
[0519] Figure 11 shows a possible implementation example of the method shown in Figure 10. It should be understood that the steps in Figure 11 can also be referenced to the relevant descriptions in Figures 10, 7, etc. As shown in Figure 11, the process may include, but is not limited to, the following steps:
[0520] Steps 1101-1116 are the same as steps 701-716 above, and you can refer to the relevant descriptions in steps 701-716 above.
[0521] 1117, Access network device 1 sends a secondary access network device add request message to the secondary access network device, including Ksn.
[0522] 1118, the secondary access network device sends a secondary access network device addition request confirmation message to access network device 1.
[0523] 1119, Access network device 1 sends an SN reconfiguration complete message to the secondary access network device.
[0524] Steps 1118 and 1119 are optional.
[0525] 1120, Security protection between secondary access network equipment activation and terminal equipment.
[0526] 1121, The random access process between the terminal equipment and the secondary access network equipment.
[0527] Steps 1117-1121 can also refer to the description of the relevant steps in Figure 7 above.
[0528] 1122, the secondary access network device sends a fourth message or downlink data to the terminal device. The fourth message is used to indicate the activation of security protection between the terminal device and the secondary access network device. The downlink data is downlink data after security protection based on the first key (such as the Ksn received in step 1117).
[0529] The implementation of step 1122 can refer to step 1011 above, and will not be repeated here.
[0530] 1123, in response to the fourth information / downlink data, the terminal device activates security protection between the terminal device and the secondary access network device.
[0531] The implementation of step 1123 can refer to step 1012 above, and will not be repeated here.
[0532] It is understandable that the terminal device can subsequently switch from access network device 1 to access network device 2. The implementation can refer to the description of the terminal device switching from access network device 0 to access network device 1, that is, the relevant description of steps 1113-1123.
[0533] It should be understood that Figure 11 above is merely an example and does not constitute a limitation. For example, Figure 11 may also include steps such as the terminal device switching to access network device 1 and path switching.
[0534] In the above process, after the secondary access network device activates the security protection between the terminal device and the terminal device, it sends the fourth information or downlink data to the terminal device to trigger the terminal device to activate the security protection between the terminal device and the secondary access network device. This can make the security protection activation of the terminal device and the secondary access network device synchronized, thus avoiding the problem of data loss.
[0535] Please refer to Figure 12, which is a flowchart illustrating another communication method disclosed in an embodiment of this application. It should be understood that the steps in Figure 12 can also be referenced to the relevant descriptions in Figures 6, 8, and 10. In Figure 12, to prevent the loss of uplink data between the terminal device and the second access network device, the third access network device can trigger the activation of security protection between the terminal device and the second access network device. As shown in Figure 12, this method may include, but is not limited to, the following steps:
[0536] Steps 1201-1207 are the same as steps 601-607 above, and you can refer to the relevant descriptions in steps 601-607 above.
[0537] 1208, The terminal device switches to the third access network device based on the second information of the third access network device.
[0538] Optionally, the terminal device may send a handover completion message to the third access network device.
[0539] Step 1208 is similar to step 609, and you can refer to the relevant description in step 609.
[0540] 1209, The third access network device sends the first key between the terminal device and the second access network device to the second access network device.
[0541] 1210, The second access network device activates the security protection between the second access network device and the terminal device according to the first key.
[0542] Steps 1209 and 1210 are similar to steps 610 and 611, respectively, and can be referred to the relevant descriptions in steps 610 and 611.
[0543] Understandably, after the second access network device obtains the first key (or activates security protection between the terminal device and the second access network device based on the first key, or derives the communication key between the terminal device and the terminal device based on the first key), the second access network device can perform security protection on the downlink data of the terminal device according to the first key, obtain the secure downlink data, and then send the secure downlink data to the terminal device. Correspondingly, the terminal device can receive the secure downlink data from the second access network device and can perform security processing (integrity verification and / or decryption) on the secure downlink data based on the first key.
[0544] For example, when the second access network device needs to send downlink data to the terminal device, if the first key does not exist, the second access network device cannot process the data and can first cache the downlink data to be sent. For a description of caching downlink data, please refer to the relevant descriptions in steps 814 and 1011 above, which will not be repeated here.
[0545] 1211. After sending the first key to the second access network device, the third access network device sends the fourth information to the terminal device. The fourth information is used to indicate the activation of security protection between the terminal device and the second access network device.
[0546] Accordingly, the terminal device can receive fourth information from the third access network device.
[0547] As one possible implementation, after receiving the first key from the third access network device, the second access network device can activate security protection with the terminal device based on the first key. Based on this, the third access network device can send a fourth message to the terminal device after sending the first key to the second access network device, thereby triggering the terminal device to also activate security protection with the second access network device. In this case, the activation of security protection between the terminal device and the second access device can be considered synchronous.
[0548] The fourth piece of information can be a dedicated message (such as a dedicated notification message), carried within the dedicated message, or it can be indication information carried in an existing message. This dedicated message or existing message can be an RRC message or a MAC layer message. If the dedicated message or existing message is an RRC message, it can be securely protected based on the key between the terminal device and the third access network device.
[0549] The above process is illustrated by taking the activation of security protection between the second access network device and the terminal device after the second access network device receives the first key from the third access network device as an example. However, in some possible implementations, the second access network device can activate the security protection between the second access network device and the terminal device based on the first key after the terminal device has completed random access. In still other possible implementations, the second access network device can activate the security protection between the second access network device and the terminal device based on the first key after sending a SN add / modify request confirmation message to the third access network device. In yet another possible implementation, the second access network device can activate the security protection between the second access network device and the terminal device based on the first key after receiving a SN reconfiguration completion message from the third access network device.
[0550] The above process is illustrated by the example where the third access network device sends the fourth information to the terminal device after sending the first key to the second access network device. However, in other possible implementations, the third access network device may send the fourth information to the terminal device after receiving a confirmation message for an SN addition / modification request from the second access network device. Alternatively, the third access network device may send the fourth information to the terminal device after sending an SN reconfiguration complete message to the second access network device.
[0551] The timing of the second access network device activating security protection with the terminal device, and / or the timing of the third access network device sending the fourth information to the terminal device, can be specified by the protocol. By specifying the timing of the second access network device activating security protection with the terminal device, and / or the timing of the third access network device sending the fourth information to the terminal device, the time interval between the activation of security protection by the terminal device and the second access network device can be shortened.
[0552] It should be noted that the third access network device can send the fourth information to the terminal device without relying on the terminal device completing the handover or receiving a handover completion message from the terminal device. This application embodiment does not limit this. For example, the third access network device can send the fourth information to the terminal device after sending the first key to the second access network device and before receiving the handover completion message from the terminal device, or it can send the fourth information to the terminal device after sending the first key to the second access network device and after receiving the handover completion message from the terminal device.
[0553] 1212, in response to the fourth information, the terminal device activates the security protection between the terminal device and the second access network device according to the first key.
[0554] The above description is based on the example that the first key can be determined after receiving the information for indicating the NCC in step 1204. However, in some possible cases, the terminal device may also respond to the fourth information (or after receiving the fourth information from the second access network device) and then determine the first key based on the information for indicating the NCC. This application embodiment does not limit the timing of the terminal device deduce the first key (or deduce the RRC key and / or UP key between the terminal device and the second access network device).
[0555] In the above process, the terminal device responds to the fourth information, and the security protection between the terminal device and the second access network device activated according to the first key may include uplink security protection and downlink security protection between the terminal device and the second access network device. However, in some possible implementations, the terminal device may respond to the first information and activate downlink security protection between the terminal device and the second access network device, and the fourth information may only be used to instruct / trigger the terminal device to activate uplink security protection between the terminal device and the second access network device. Regarding the implementation of the terminal device activating downlink security protection between the terminal device and the second access network device in response to the first information, refer to step 808 above, which describes the implementation of the security protection between the terminal device and the second access network device in response to the first information.
[0556] Understandably, after the terminal device obtains the first key (or activates security protection between the terminal device and the second access network device based on the first key, or derives the communication key between the terminal device and the second access network device based on the first key), it can perform security protection on the uplink data of the terminal device according to the first key, obtain the secure uplink data, and then send the secure uplink data to the second access network device. Correspondingly, the second access network device can receive the secure uplink data from the terminal device, and then perform security processing (integrity verification and / or decryption) on the secure uplink data based on the first key.
[0557] For example, when a terminal device needs to send uplink data to a second access network device, if the first key is missing (or uplink security protection between the terminal device and the second access network device is not activated based on the first key), the terminal device cannot process the data and can first cache the uplink data to be sent. For a description of caching uplink data, please refer to the relevant descriptions in steps 1012 above, etc., which will not be repeated here.
[0558] It should be noted that if the terminal device needs to initiate a random access procedure to the second access network device, the random access procedure can be initiated before the terminal device activates the security protection between the terminal device and the second access network device, or it can be initiated after the terminal device activates the security protection between the terminal device and the second access network device. This application embodiment does not limit this.
[0559] Optionally, after the terminal device switches from the first access network device to the third access network device, the above method may further include step 612 in FIG6.
[0560] The above process only describes the implementation of the terminal device switching from the first access network device to the third access network device. The terminal device can subsequently perform one or more LTM handovers, such as switching from the third access network device to the fourth access network device, and from the fourth access network device to the sixth access network device. The implementation of "the terminal device switching from the third access network device to the fourth access network device" and "the terminal device switching from the fourth access network device to the sixth access network device" can be referred to the description of "the terminal device switching from the first access network device to the third access network device," and will not be repeated here.
[0561] It is understandable that by adopting the scheme shown in Figure 12, the second access network device can activate the security protection between the second access network device and the terminal device according to the first key, and the terminal device can activate the security protection (or uplink security protection) between the terminal device and the second access network device according to the first key in a synchronous manner. This can avoid the situation where uplink data is lost due to the asynchronous activation of security protection between the terminal device and the second access network device.
[0562] Figure 13 shows a possible implementation example of the method shown in Figure 12. It should be understood that the steps in Figure 13 can also be referenced to the relevant descriptions in Figures 12, 7, etc. As shown in Figure 13, the process may include, but is not limited to, the following steps:
[0563] Steps 1301-1316 are the same as steps 701-716 above, and you can refer to the relevant descriptions in steps 701-716 above.
[0564] 1317, Access network device 1 sends a secondary access network device add request message to the secondary access network device, including Ksn.
[0565] 1318, the secondary access network device sends a secondary access network device addition request confirmation message to access network device 1.
[0566] 1319, Access network device 1 sends an SN reconfiguration complete message to the secondary access network device.
[0567] Steps 1318 and 1319 are optional.
[0568] 1320, Security protection between secondary access network equipment activation and terminal equipment.
[0569] 1321, The random access process between the terminal equipment and the secondary access network equipment.
[0570] Steps 1317-1321 can also refer to the description of the relevant steps in Figure 7 above.
[0571] 1322. After sending a secondary access network device add request message to the secondary access network device, access network device 1 sends fourth information to the terminal device. The fourth information is used to indicate the activation of security protection between the terminal device and the secondary access network device.
[0572] The implementation of step 1322 can refer to step 1211 above, and will not be repeated here.
[0573] 1323, in response to the fourth information, activates security protection between the terminal device and the secondary access network device.
[0574] The implementation of step 1323 can refer to step 1212 above, and will not be repeated here.
[0575] It is understandable that the terminal device can subsequently switch from access network device 1 to access network device 2. The implementation can refer to the description of the terminal device switching from access network device 0 to access network device 1, that is, the relevant description of steps 1313-1323.
[0576] It should be understood that Figure 13 above is merely an example and does not constitute a limitation. For example, Figure 13 may also include steps such as the terminal device switching to access network device 1 and path switching.
[0577] It is understood that the technical solutions provided in this application can be used in the architecture of an open access network. The operations performed by the aforementioned access network devices (such as the first access network device, the second access network device, the third access network device, etc.) can be performed by one or more nodes such as CU, DU, CU-CP, CU-UP, and RIC (such as near-RT RIC, Non-RT RIC). Information sent by the terminal device to the access network device can be sent to nodes such as CU, DU, CU-CP, CU-UP, or RIC (such as near-RT RIC, Non-RT RIC), and this application does not limit this. For example, the access network device can send relevant information to the terminal device through CU, DU, CU-CP, CU-UP, or RIC, such as the aforementioned first information, fourth information, etc.
[0578] It should be noted that the relevant information and descriptions in the different embodiments described above can be referenced interchangeably. For example, the explanations or adaptations in the method embodiments shown in Figures 6-13 can be referenced interchangeably. Furthermore, the technical features in different method embodiments can be combined to form new embodiments based on their inherent logical relationships. In addition, different implementations or examples within the same method embodiment can also be referenced or referenced interchangeably.
[0579] It should be understood that Figures 7, 9, 11, and 13 above primarily illustrate the above processing flow using terminal devices and access network devices as the execution entities for the interactive illustration. However, this application does not limit the execution entities of this interactive illustration. For example, the terminal device in Figures 6-13 could also be a chip, chip system, or processor that supports the implementation of this method on the terminal device, or it could be a logic module or software that can implement all or part of the terminal device's functions. Similarly, the access network device in Figures 6-13 could also be a chip, chip system, or processor that supports the implementation of this method on the access network device, or it could be a logic module or software that can implement all or part of the access network device's functions.
[0580] The foregoing mainly describes the communication method provided in the embodiments of this application. It is understood that, in order to achieve the corresponding functions, the aforementioned terminal device and access network device may include hardware structures and / or software modules corresponding to the execution of each function. Based on the units and steps of the various examples described in the embodiments disclosed herein, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed by hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the embodiments of this application.
[0581] This application embodiment can divide terminal devices and access network devices into functional modules according to the above method examples. For example, each function can be divided into its own functional module, or two or more functions can be integrated into one module. The integrated module can be implemented in hardware or as a software functional module. It should be noted that the module division in this application embodiment is illustrative and only represents one logical functional division; other division methods may be used in actual implementation.
[0582] Figure 14 shows a possible structural diagram of the communication device 1400, where each functional module is divided according to its corresponding function. The communication device 1400 includes a communication unit 1401 and a processing unit 1402. The communication device 1400 may also include a storage unit 1403. Optionally, the communication unit 1401 may also be referred to as a transceiver unit, an output unit, or an interface unit, etc. In one possible implementation, the communication unit 1401 includes at least one of a transmitting unit or a receiving unit. The transmitting unit and the receiving unit may be integrated together, or they may be two independent units, etc. In one possible design, the communication device 1400 may be the aforementioned terminal device, or it may be a component within the terminal device (e.g., a processor, chip, chip system, circuit, or functional module), or it may be a processing system within the terminal device, etc.
[0583] When the communication device 1400 is used for the functions of the terminal device in the embodiment shown in FIG6 above, for example:
[0584] The communication unit 1401 is used to receive first information from the first access network device, the first information being used to switch the primary access network device in the dual connection of the terminal device from the first access network device to the third access network device.
[0585] The processing unit 1402 is used to activate the security protection between the terminal device and the second access network device according to the first information, wherein the second access network device is the auxiliary access network device corresponding to the third access network device.
[0586] In one possible implementation, the communication unit 1401 is further configured to receive information for indicating the next-hop link counter (NCC); the processing unit 1402 is further configured to generate a first key between the terminal device and the second access network device based on the NCC, the first key being used for security protection between the terminal device and the second access network device.
[0587] In one possible implementation, the first information and / or the information used to instruct the NCC is carried in a first Media Access Control (MAC) layer message.
[0588] In one possible implementation, the first information includes one or more of the following: the identifier of the third access network device, the index of the configuration of the third access network device, the identifier of the candidate cell in the cell served by the third access network device, and the index of the configuration of the candidate cell in the cell served by the third access network device.
[0589] In one possible implementation, the communication unit 1401 is further configured to receive second information of each of a plurality of candidate primary access network devices, the plurality of candidate primary access network devices including the third access network device; the processing unit 1402 is further configured to, in response to the first information, access the third access network device according to the second information of the third access network device.
[0590] In one possible implementation, the communication unit 1401 is further configured to receive third information from the second access network device; the processing unit 1402 is further configured to, in response to the first information, access the second access network device according to the third information of the second access network device.
[0591] In one possible implementation, the communication unit 1401 is further configured to receive second information of each of a plurality of candidate primary access network devices, the plurality of candidate primary access network devices including the third access network device, and the second information of the third access network device including the third information of the second access network device; the processing unit 1402 is further configured to, in response to the first information, access the third access network device according to the second information of the third access network device; the processing unit 1402 is further configured to, in response to the first information, access the second access network device according to the third information of the second access network device.
[0592] The operation of each unit in the above-mentioned communication device 1400 can be referred to the description of the terminal device in the embodiment shown in Figure 6 above, and will not be repeated here.
[0593] When the communication device 1400 is used for the functions of the terminal device in the embodiments shown in FIG10 or FIG12, for example:
[0594] Communication unit 1401 is used to receive first information from a first access network device, the first information being used to switch the primary access network device in the dual connection of the terminal device from the first access network device to the third access network device 7;
[0595] The communication unit 1401 is also used to receive fourth information, which is used to indicate the activation of security protection between the terminal device and the second access network device, wherein the second access network device is the auxiliary access network device corresponding to the third access network device;
[0596] Processing unit 1402 is configured to, in response to the fourth information, activate the security protection between the terminal device and the second access network device; or,
[0597] The communication unit 1401 is also used to receive downlink data from a second access network device, which is an auxiliary access network device corresponding to the third access network device.
[0598] The processing unit 1402 is also configured to activate the security protection between the terminal device and the second access network device in response to the downlink data.
[0599] In one possible implementation, the communication unit 1401 is further configured to receive information for indicating the next-hop link counter (NCC); the processing unit 1402 is further configured to determine a first key between the terminal device and the second access network device based on the NCC, the first key being used for security protection between the terminal device and the second access network device.
[0600] In one possible implementation, the fourth information comes from the second access network device or the third access network device.
[0601] In one possible implementation, the downlink data is data that has been securely protected based on a first key between the terminal device and the second access network device. After receiving the downlink data from the second access network device, the processing unit 1402 is further configured to perform secure processing on the downlink data based on the first key.
[0602] In one possible implementation, the security protection includes integrity protection, the security processing includes integrity verification, and the processing unit 1402, in response to the downlink data, activates the security protection between the terminal device and the second access network device, including: activating uplink security protection between the terminal device and the second access network device if the integrity verification of the downlink data passes. In another possible implementation, the fourth information is used to indicate the activation of uplink security protection between the terminal device and the second access network device; the processing unit 1402, in response to the fourth information, activates the security protection between the terminal device and the second access network device, including: activating uplink security protection between the terminal device and the second access network device in response to the fourth information; the processing unit 1402 is further configured to activate downlink security protection between the terminal device and the second access network device in response to the first information.
[0603] In one possible implementation, the fourth information is information that has been securely protected based on the first key. After receiving the fourth information, the processing unit 1402 is further configured to perform secure processing on the fourth information based on the first key.
[0604] In one possible implementation, after receiving the first information from the first access network device and before receiving the fourth information or the downlink data, the storage unit 1403 is used to cache the uplink data; the processing unit 1402 is also used to perform security protection on the cached uplink data according to the first key between the terminal device and the second access network device; and the communication unit 1401 is also used to send the securely protected uplink data to the second access network device.
[0605] In one possible implementation, the first information and / or the information used to instruct the NCC is carried in a first Media Access Control (MAC) layer message.
[0606] In one possible implementation, the first information includes one or more of the following: the identifier of the third access network device, the index of the configuration of the third access network device, the identifier of the candidate cell in the cell served by the third access network device, and the index of the configuration of the candidate cell in the cell served by the third access network device.
[0607] In one possible implementation, the communication unit 1401 is further configured to receive second information of each of a plurality of candidate primary access network devices, the plurality of candidate primary access network devices including the third access network device; the processing unit 1402 is further configured to, in response to the first information, access the third access network device according to the second information of the third access network device.
[0608] In one possible implementation, the communication unit 1401 is further configured to receive third information from the second access network device; the processing unit 1402 is further configured to, in response to the first information, access the second access network device according to the third information of the second access network device.
[0609] In one possible implementation, the communication unit 1401 is further configured to receive second information of each of a plurality of candidate primary access network devices, the plurality of candidate primary access network devices including the third access network device, and the second information of the third access network device including the third information of the second access network device; the processing unit 1402 is further configured to, in response to the first information, access the third access network device according to the second information of the third access network device; the processing unit 1402 is further configured to, in response to the first information, access the second access network device according to the third information of the second access network device.
[0610] The operation of each unit in the above-mentioned communication device 1400 can be referred to the description of the terminal device in the embodiments shown in Figures 10 and 12 above, and will not be repeated here.
[0611] In another possible design, the communication device 1400 may be the aforementioned second access network device, or it may be a component (e.g., a processor, chip, chip system, circuit or functional module) in the second access network device, or it may be a processing system in the second access network device, etc.
[0612] When the communication device 1400 is used for the function of the second access network device in the embodiment shown in FIG8 above, for example:
[0613] The communication unit 1401 is used to receive uplink data from the terminal device, the uplink data being securely protected based on a first key between the terminal device and the second access network device;
[0614] Storage unit 1403 is used to cache the uplink data when the first key is not present in the second access network device;
[0615] The communication unit 1401 is also used to receive the first key from a third access network device, wherein the third access network device is the primary access network device in the dual connection of the terminal device, and the second access network device is the secondary access network device corresponding to the third access network device;
[0616] Processing unit 1402 is used to perform secure processing on the cached uplink data based on the first key.
[0617] In one possible implementation, the communication unit 1401 is further configured to send third information of the second access network device, the third information being used to configure resources for sending uplink data; and the storage unit 1403 is configured to cache the uplink data if the resources used for sending the uplink data match the resources configured in the third information.
[0618] In one possible implementation, the third access network device is the primary access network device after the terminal device is switched over, and the first access network device is the primary access network device before the terminal device is switched over. Before receiving uplink data from the terminal device, the communication unit 1401 is further configured to receive a second message from the first access network device, the second message indicating the release of the connection between the terminal device and the second access network device, the connection being established when the first access network device is the primary access network device in the dual connection of the terminal device; the processing unit 1402 is further configured to, in response to the second message, delete the second key between the terminal device and the second access network device, the second key being used for security protection between the terminal device and the second access network device.
[0619] In one possible implementation, the processing unit 1402 is further configured to activate security protection between the second access network device and the terminal device based on the first key.
[0620] In one possible implementation, the processing unit 1402 is further configured to perform security protection on the downlink data of the terminal device according to the first key, and obtain the secure downlink data; the communication unit 1401 is further configured to send the secure downlink data to the terminal device.
[0621] The operation of each unit in the above-mentioned communication device 1400 can be referred to the description of the second access network device in the embodiment shown in Figure 8 above, and will not be repeated here.
[0622] When the communication device 1400 is used for the function of the second access network device in the embodiment shown in FIG10 above, for example:
[0623] The communication unit 1401 is configured to send fourth information to the terminal device after receiving a first key between the terminal device and the second access network device from the third access network device. The fourth information is used to indicate the activation of security protection between the terminal device and the second access network device. The third access network device is the primary access network device in the dual connection of the terminal device, and the second access network device is the secondary access network device corresponding to the third access network device. The first key is used for security protection between the terminal device and the second access network device.
[0624] In one possible implementation, the processing unit 1402 is used to activate the security protection between the second access network device and the terminal device according to the first key.
[0625] In one possible implementation, the communication unit 1401 is configured to send the fourth information to the terminal device when there is no downlink data to be sent to the terminal device.
[0626] The operation of each unit in the above-mentioned communication device 1400 can be referred to the description of the second access network device in the embodiment shown in Figure 10 above, and will not be repeated here.
[0627] In another possible design, the communication device 1400 may be the aforementioned third access network device, or it may be a component (e.g., processor, chip, chip system, circuit or functional module) in the third access network device, or it may be a processing system in the third access network device, etc.
[0628] When the communication device 1400 is used for the function of the third access network device in the embodiment shown in FIG12 above, for example:
[0629] Communication unit 1401 is configured to receive a first message from a first access network device, the first message being configured to instruct the primary access network device in the dual connection of the terminal device to be switched from the first access network device to the third access network device;
[0630] The communication unit 1401 is also used to send a first key between the terminal device and the second access network device to the second access network device, wherein the second access network device is an auxiliary access network device corresponding to the third access network device, and the first key is used for security protection between the terminal device and the second access network device;
[0631] The communication unit 1401 is further configured to send fourth information to the terminal device after sending the first key to the second access network device, the fourth information being used to indicate the activation of security protection between the terminal device and the second access network device.
[0632] In one possible implementation, the first message includes a key between the terminal device and the third access network device; the processing unit 1402 is configured to determine the first key based on the key between the terminal device and the third access network device.
[0633] The operation of each unit in the above-mentioned communication device 1400 can be referred to the description of the third access network device in the embodiment shown in Figure 12 above, and will not be repeated here.
[0634] It should be noted that the communication device 1400 shown in Figure 14 is only one implementation of the embodiment of this application. In actual applications, the communication device 1400 may include more or fewer units / modules, and the connection method between the various units / modules is not limited, and is not restricted here.
[0635] Figure 15 shows a possible hardware structure diagram of the communication device 1500 provided in an embodiment of this application. The communication device 1500 may include a communication interface 1504 and at least one processor 1502. Optionally, it may also include a bus 1503. Further optionally, it may also include at least one memory 1501, wherein the memory 1501, the processor 1502 and the communication interface 1504 can be connected through the bus 1503.
[0636] The memory 1501 provides storage space, which can store data such as the operating system and computer programs. The memory 1501 can be one or a combination of several of the following: random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), or compact disc read-only memory (CD-ROM).
[0637] Processor 1502 is a module that performs arithmetic and / or logical operations. For example, it may be one or a combination of processing modules such as a central processing unit (CPU), graphics processing unit (GPU), microprocessor unit (MPU), application-specific integrated circuit (ASIC), field-programmable gate array (FPGA), complex programmable logic device (CPLD), coprocessor (assisting the CPU in completing corresponding processing and applications), and microcontroller unit (MCU). For instance, processor 1502 can be used to process communication protocols and communication data.
[0638] The communication interface 1504 is used to receive and / or transmit data to external sources. Optionally, the communication interface 1504 may also include a transmitter (such as an RF transmitter, antenna, etc.) and / or a receiver coupled to the interface. For example, the communication interface 1504 may include a control circuit and an antenna. The control circuit is mainly used for converting baseband signals to RF signals and processing RF signals. The antenna is mainly used for transmitting and receiving RF signals in the form of electromagnetic waves. When data needs to be transmitted wirelessly, the processor 1502 performs baseband processing on the data to be transmitted and outputs a baseband signal to the control circuit. The control circuit then performs RF processing on the baseband signal and transmits the RF signal outward in the form of electromagnetic waves through the antenna. When data is sent to the communication device, the control circuit receives the RF signal through the antenna, converts the RF signal into a baseband signal, and outputs the baseband signal to the processor 1502. The processor 1502 converts the baseband signal back into data and processes the data.
[0639] In one possible implementation, the control circuitry and antenna can be set up independently of the processor performing baseband processing. For example, in a distributed scenario, the control circuitry and antenna can be arranged in a remote manner, independent of the communication device.
[0640] In one design, the communication device 1500 can be used to perform the functions of the terminal device in the embodiments shown in Figures 6-13 above. Refer to the relevant description of the terminal device in Figures 6-13 above, which will not be repeated in detail here.
[0641] In another design, the communication device 1500 can be used to perform the functions of the first access network device in the embodiments shown in Figures 6-13 above. Refer to the relevant description of the first access network device in Figures 6-13 above, which will not be repeated in detail here.
[0642] In another design, the communication device 1500 can be used to perform the functions of the second access network device in the embodiments shown in Figures 6-13 above. Refer to the relevant description of the second access network device in Figures 6-13 above, which will not be repeated in detail here.
[0643] In another design, the communication device 1500 can be used to perform the functions of the third access network device in the embodiments shown in Figures 6-13 above. Refer to the relevant description of the third access network device in Figures 6-13 above, which will not be repeated in detail here.
[0644] In one possible design, the memory 1501 may store instructions, which may be computer programs that run on the processor 1502, causing the communication device 1500 to perform operations performed by the terminal device in any of the above method embodiments, or operations performed by the first access network device, or operations performed by the second access network device, or operations performed by the third access network device. For details, please refer to the relevant descriptions in Figures 6-13 above, whi...
Claims
1. A communication method, characterized in that, The method includes: Receive first information from a first access network device, the first information being used to switch the primary access network device in the dual connection of the terminal device from the first access network device to a third access network device; Based on the first information, the security protection between the terminal device and the second access network device is activated, whereby the second access network device is the auxiliary access network device corresponding to the third access network device.
2. The method according to claim 1, characterized in that, The method further includes: Receive information used to indicate the next-hop link counter; A first key is generated between the terminal device and the second access network device based on the next-hop link counter. The first key is used for security protection between the terminal device and the second access network device.
3. The method according to claim 2, characterized in that, The first information and / or the information used to indicate the next-hop link counter are carried in a first media access control layer message.
4. The method according to any one of claims 1-3, characterized in that, The first information includes one or more of the following: the identifier of the third access network device, the configuration index of the third access network device, the identifier of the candidate cell in the cell served by the third access network device, and the configuration index of the candidate cell in the cell served by the third access network device.
5. The method according to any one of claims 1-4, characterized in that, The method further includes: Receive second information for each of a plurality of candidate primary access network devices, wherein the plurality of candidate primary access network devices includes the third access network device; In response to the first information, access is made to the third access network device according to the second information of the third access network device.
6. The method according to claim 5, characterized in that, The method further includes: Receive third information from the second access network device; In response to the first information, access is made to the second access network device according to the third information of the second access network device.
7. The method according to any one of claims 1-4, characterized in that, The method further includes: Receive second information for each of a plurality of candidate primary access network devices, wherein the plurality of candidate primary access network devices includes the third access network device, and the second information of the third access network device includes the third information of the second access network device; In response to the first information, access is made to the third access network device according to the second information of the third access network device; In response to the first information, access is made to the second access network device according to the third information of the second access network device.
8. A communication method, characterized in that, A chip applied to a second access network device or a second access network device, the method comprising: Receive uplink data from a terminal device, wherein the uplink data is securely protected based on a first key between the terminal device and the second access network device; If the first key is not present in the second access network device, the uplink data is cached; The terminal device receives the first key from a third access network device, wherein the third access network device is the primary access network device in the dual connection of the terminal device, and the second access network device is the secondary access network device corresponding to the third access network device. The cached uplink data is securely processed based on the first key.
9. The method according to claim 8, characterized in that, The method further includes: Send third information from the second access network device, the third information being used to configure resources for sending uplink data; The cached uplink data includes: If the resources used to send the uplink data match the resources configured in the third information, the uplink data is cached.
10. The method according to claim 8 or 9, characterized in that, The third access network device is the primary access network device after the terminal device switches over, and the first access network device is the primary access network device before the terminal device switches over. Before receiving uplink data from the terminal device, the method further includes: Receive a second message from the first access network device, the second message indicating the release of the connection between the terminal device and the second access network device, the connection being established when the first access network device is the primary access network device in a dual connection of the terminal device; In response to the second message, the second key between the terminal device and the second access network device is deleted. The second key is used for security protection between the terminal device and the second access network device.
11. The method according to any one of claims 8-10, characterized in that, The method further includes: The security protection between the second access network device and the terminal device is activated based on the first key.
12. The method according to any one of claims 8-11, characterized in that, The method further includes: The downlink data of the terminal device is protected by the first key to obtain the protected downlink data. Send the protected downlink data to the terminal device.
13. A communication method, characterized in that, The method includes: Receive first information from a first access network device, the first information being used to switch the primary access network device in the dual connection of the terminal device from the first access network device to a third access network device; Receive fourth information, the fourth information being used to instruct the activation of security protection between the terminal device and the second access network device, the second access network device being the auxiliary access network device corresponding to the third access network device; In response to the fourth information, activate the security protection between the terminal device and the second access network device; or, Receive downlink data from a second access network device, which is a secondary access network device corresponding to the third access network device; In response to the downlink data, the security protection between the terminal device and the second access network device is activated.
14. The method according to claim 13, characterized in that, The method further includes: Receive information used to indicate the next-hop link counter; The first key between the terminal device and the second access network device is determined based on the next-hop link counter. The first key is used for security protection between the terminal device and the second access network device.
15. The method according to claim 13 or 14, characterized in that, The fourth piece of information comes from the second access network device or the third access network device.
16. The method according to any one of claims 13-15, characterized in that, The downlink data is data that has been securely protected based on a first key between the terminal device and the second access network device. After receiving the downlink data from the second access network device, the method further includes: The downlink data is processed securely based on the first key.
17. The method according to claim 16, characterized in that, The security protection includes integrity protection, the security processing includes integrity verification, and the activation of security protection between the terminal device and the second access network device in response to the downlink data includes: If the integrity verification of the downlink data passes, the uplink security protection between the terminal device and the second access network device is activated.
18. The method according to any one of claims 13-17, characterized in that, The fourth information used to indicate the activation of security protection between the terminal device and the second access network device includes: the fourth information used to indicate the activation of uplink security protection between the terminal device and the second access network device; The activation of security protection between the terminal device and the second access network device in response to the fourth information includes: In response to the fourth information, the uplink security protection between the terminal device and the second access network device is activated; The method further includes: In response to the first information, downlink security protection between the terminal device and the second access network device is activated.
19. The method according to claim 18, characterized in that, The fourth information is information secured based on the first key. After receiving the fourth information, the method further includes: The fourth information is processed securely based on the first key.
20. The method according to any one of claims 13-19, characterized in that, After receiving the first information from the first access network device and before receiving the fourth information or the downlink data, the method further includes: buffering uplink data; The activation of security protection between the terminal device and the second access network device includes: The cached uplink data is securely protected according to the first key between the terminal device and the second access network device. The uplink data after security protection is sent to the second access network device.
21. The method according to any one of claims 14-20, characterized in that, The first information and / or the information used to indicate the next-hop link counter are carried in a first media access control layer message.
22. The method according to any one of claims 13-21, characterized in that, The first information includes one or more of the following: the identifier of the third access network device, the configuration index of the third access network device, the identifier of the candidate cell in the cell served by the third access network device, and the configuration index of the candidate cell in the cell served by the third access network device.
23. The method according to any one of claims 13-22, characterized in that, The method further includes: Receive second information for each of a plurality of candidate primary access network devices, wherein the plurality of candidate primary access network devices includes the third access network device; In response to the first information, access is made to the third access network device according to the second information of the third access network device.
24. The method according to claim 23, characterized in that, The method further includes: Receive third information from the second access network device; In response to the first information, access is made to the second access network device according to the third information of the second access network device.
25. The method according to any one of claims 13-22, characterized in that, The method further includes: Receive second information for each of a plurality of candidate primary access network devices, wherein the plurality of candidate primary access network devices includes the third access network device, and the second information of the third access network device includes the third information of the second access network device; In response to the first information, access is made to the third access network device according to the second information of the third access network device; In response to the first information, access is made to the second access network device according to the third information of the second access network device.
26. A communication method, characterized in that, The method includes: After receiving the first key between the terminal device and the second access network device from the third access network device, the terminal device sends a fourth message to the terminal device, the fourth message being used to indicate the activation of security protection between the terminal device and the second access network device; The third access network device is the primary access network device in the dual connection of the terminal device, the second access network device is the secondary access network device corresponding to the third access network device, and the first key is used for security protection between the terminal device and the second access network device.
27. The method according to claim 26, characterized in that, The method further includes: The security protection between the second access network device and the terminal device is activated based on the first key.
28. The method according to claim 26 or 27, characterized in that, Sending the fourth information to the terminal device includes: In the absence of downlink data to be sent to the terminal device, a fourth message is sent to the terminal device.
29. A communication method, characterized in that, The method includes: Receive a first message from a first access network device, the first message being used to instruct the primary access network device in the dual connectivity of the terminal device to be switched from the first access network device to a third access network device; Send a first key between the terminal device and the second access network device to the second access network device, wherein the second access network device is an auxiliary access network device corresponding to the third access network device, and the first key is used for security protection between the terminal device and the second access network device; After sending the first key to the second access network device, a fourth message is sent to the terminal device, the fourth message being used to indicate the activation of security protection between the terminal device and the second access network device.
30. The method according to claim 29, characterized in that, The first message includes a key between the terminal device and the third access network device; the method further includes: The first key is determined based on the key between the terminal device and the third access network device.
31. A communication device, characterized in that, Includes modules for implementing the method as described in any one of claims 1-30.
32. A communication device, characterized in that, The device includes a processor and a transceiver, the transceiver being used to send and receive information, and the processor being used to enable the communication device to implement the method as described in any one of claims 1-30.
33. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program or computer instructions that are executed by a processor to implement the method as described in any one of claims 1-30.
34. A computer program product, characterized in that, The computer program product includes computer program code or computer instructions, which, when executed, implement the method described in any one of claims 1-30.