Information transmission method and apparatus, computer device, and storage medium

WO2026199778A1PCT designated stage Publication Date: 2026-10-01CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/109841
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-03-28
Filing Date
2025-07-22
Publication Date
2026-10-01

Smart Images

  • Figure CN2025109841_01102026_PF_FP_ABST
    Figure CN2025109841_01102026_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to an information transmission method and apparatus, a computer device, and a storage medium. The method comprises: a first base station control-plane entity sending a second radio resource control (RRC) message to a terminal by means of a first base station split entity; sending an intra-station interface request message to a first base station user-plane entity, wherein the intra-station interface request message comprises at least one of a user-plane security policy and security activation information, and the security activation information is used for indicating whether encryption and / or integrity protection is activated or not activated for at least one protocol data unit (PDU) session or data radio bearer (DRB); and receiving an intra-station interface response message fed back by the first base station user-plane entity.
Need to check novelty before this filing date? Find Prior Art

Description

Information transmission methods, devices, computer equipment and storage media

[0001] Related applications

[0002] This application claims priority to Chinese patent application filed on March 28, 2025, with application number 202510385114.0 and entitled "Information transmission method, apparatus, computer equipment and storage medium", the entire contents of which are incorporated herein by reference. Technical Field

[0003] This application relates to the field of wireless communication technology, and in particular to an information transmission method, apparatus, computer equipment, and storage medium. Background Technology

[0004] 5G refers to the fifth generation of mobile communication technology. Compared with previous generations of mobile communication technology, it supports high speed, low latency, massive connectivity, high reliability, network slicing and other functions. These features make 5G an important infrastructure to promote digital transformation and will profoundly affect many fields such as industry, transportation, healthcare, and entertainment.

[0005] The 5G security key management system is based on hierarchical derivation of key K, ensuring minimal key exposure. Encryption and integrity protection algorithms employ three main methods: AES, SNOW 3G, and ZUC, ensuring security requirements across different global markets.

[0006] However, different base stations use different encryption or integrity protection algorithms. In particular, the current main encryption and integrity protection algorithm is 128-bit. After upgrading to 256-bit encryption and integrity protection algorithm, the currently accessing cell cannot confirm the encryption or integrity algorithm used by the source cell. This may cause the information stored on the terminal or the signaling received from the accessing cell to fail the security check, resulting in abnormal call drops. Summary of the Invention

[0007] Therefore, it is necessary to provide a signal transmission method, apparatus, computer equipment, and storage medium that can meet the needs of network deployment and optimization, addressing the aforementioned technical problems.

[0008] This application provides an information transmission method in a first aspect, applied to a first base station control plane entity, the method comprising: sending a second Radio Resource Control (RRC) message to a terminal through a first base station separation entity; sending an intra-station interface request message to a first base station user plane entity; the intra-station interface request message including at least one of a user plane security policy and security activation information; the security activation information being used to instruct at least one Protocol Data Unit (PDU) session or Data Radio Bearer (DRB) to activate or deactivate encryption and / or integrity protection; and receiving an intra-station interface response message fed back by the first base station user plane entity.

[0009] In one embodiment, the method further includes: receiving an intra-station message sent by a first base station separation entity, the intra-station message including a first RRC message and / or uplink data sent by a terminal; wherein the first RRC message carries user identification and security verification information.

[0010] In one embodiment, the method further includes: sending a first interface request message to a second base station; wherein the first interface request message carries the user identifier and the security verification information; the second base station is used to send a third RRC message to the terminal to trigger the terminal to enter an inactive state.

[0011] In one embodiment, the method further includes: receiving a first interface response message sent by the second base station; wherein the first interface response message carries at least one of a user plane security policy, a security algorithm used by the terminal at the second base station, and a user plane security activation state; the security algorithm includes an encryption and / or integrity protection algorithm; the user plane security activation state includes an activation state of encryption and / or integrity protection; the user plane security policy includes at least one of an integrity protection indication, a confidentiality protection indication, and a maximum integrity protection rate, wherein the integrity protection indication is used to indicate whether user plane integrity is applied for PDU session resources, and includes at least three configurations: required, preferred, and not needed; the confidentiality protection indication is used to indicate whether user plane encryption is applied for PDU session resources, and includes at least three configurations: required, preferred, and not needed.

[0012] In one embodiment, sending the second RRC message to the terminal via the first base station separation entity includes: sending the second RRC message to the terminal via the first base station separation entity according to the security algorithm or the user plane security activation state; the second RRC message is carried by a signaling radio bearer (SRB0) or a signaling radio bearer (SRB1).

[0013] In one embodiment, the security verification information is determined by an integrity protection algorithm and a security key negotiated between the second base station and the terminal; the integrity protection algorithm is configured by a fourth RRC message from the second base station; the fourth RRC message includes encryption configuration and / or integrity protection configuration, which includes at least one of the following: a wireless side key, NCC, an encryption or integrity algorithm, disabling encryption, and disabling integrity protection.

[0014] In one embodiment, the first RRC message and the uplink data use the same or different logical channels during transmission; the logical channel used by the uplink data is configured by the second base station through the third RRC message.

[0015] In one embodiment, the uplink data is encrypted or protected with the encryption key or integrity protection algorithm configured by the second base station; the first RRC message is encrypted with the integrity protection algorithm configured by the second base station; the key length of the encryption key and the integrity protection algorithm is 128 bits or 256 bits.

[0016] In one embodiment, the first RRC message may be an RRC recovery request message in a 5G system or an RRC recovery request message in a 6G system, used to request the network to restore the terminal's RRC connection.

[0017] In one embodiment, the wireless access technologies used by the first base station separation entity and the second base station may be the same or different; wherein the wireless access technology is 5G wireless access technology or 6G wireless access technology.

[0018] In one embodiment, the core networks connected to the first base station separation entity and the second base station may be the same or different; wherein, the core network is a 5G core network or a 6G core network.

[0019] In one embodiment, the first interface request message further includes a user context retrieval request message between base stations in a 5G system, or a user context retrieval request message between base stations in a 6G system; the first interface response message further includes a user context retrieval response message between base stations in a 5G system, or a user context retrieval response message between base stations in a 6G system.

[0020] In one embodiment, the first interface request message further includes a data transmission indication; the data transmission indication is used to inform the second base station that the terminal has data to be transmitted, so that the second base station can report back to the first base station separation entity the security algorithm and user plane security activation status used when the terminal is stationed at the second base station.

[0021] In one embodiment, the first interface response message further includes at least one of the following: user security context, user plane security policy, user plane security activation status, PDU session establishment resources, key information, and the security capabilities of the terminal; the protocol data unit (PDU) session establishment resources include at least one PDU session information; the PDU session information includes a PDU identifier and at least one Quality of Service (QoS) flow information; the QoS flow information includes a QoS flow identifier, at least one DRB identifier, and QoS configuration information; the key information includes at least one of a new radio key and a next-hop chain count (NCC); the security capabilities of the terminal include at least one of the following: at least one 4G encryption algorithm, at least one 4G integrity protection algorithm, at least one 5G encryption algorithm, at least one 5G integrity protection algorithm, at least one 6G encryption algorithm, and at least one 6G integrity protection algorithm supported by the terminal.

[0022] In one embodiment, according to the security algorithm or the user plane security activation state, a second RRC message carried on SRB0 is sent to the terminal through a first base station separation entity, including: if the first base station separation entity does not support the security algorithm or does not use the security algorithm, and / or does not support the user plane security activation state, then the second RRC message carried on SRB0 is sent to the terminal; wherein the second RRC message is a Radio Resource Control Setting RRC Establishment Message in a 5G system, or an RRC Establishment Message in a 6G system.

[0023] In one embodiment, according to the security algorithm or the user plane security activation state, a second RRC message carried on SRB1 is sent to the terminal through a first base station separation entity, including: if the first base station separation entity supports the security algorithm and supports the user plane security activation state, then the second RRC message is sent to the terminal; wherein the second RRC message is an RRC recovery message in a 5G system or an RRC recovery message in a 6G system.

[0024] In one embodiment, the method further includes: updating the key based on the security algorithm to obtain a target key; activating the target key after resetting the sequence count (COUNT) value of the terminal packet data convergence protocol (PDCP) to 0; and sending a second RRC message to the terminal after successfully activating the target key.

[0025] In one embodiment, sending the second RRC message to the terminal includes: sending the second RRC message to the terminal via a signaling radio bearer (SRB1); wherein the signaling carried by the SRB1 is encrypted and / or protected for integrity according to network configuration.

[0026] In one embodiment, sending the second RRC message to the terminal includes: sending the second RRC message to the terminal via SRB0; wherein the RRC signaling carried by SRB0 does not have encryption and integrity protection enabled.

[0027] In one embodiment, the user identifier is configured by the second base station via a third RRC message; wherein the third RRC message is an RRC release message sent by the terminal to the second base station when the terminal is camped there; the RRC release message includes at least one of the user identifier and logical channel configuration.

[0028] In one embodiment, the in-station interface request message includes at least one of the user identifier, a small data transfer (SDT) transmission resumption indication, a security activation indication, and a user plane security policy. The security activation indication is used to activate or deactivate security for at least one PDU session or data radio bearer (DRB) configuration; the security includes encryption and / or integrity protection.

[0029] In one embodiment, the in-station interface request message is a bearer context establishment request message or a bearer context modification request message in a 5G system, or a bearer context establishment request message or a bearer context modification request message in a 6G system, used to request the base station user plane entity to establish or modify the context configuration information of at least one bearer; the in-station interface response message is a bearer context establishment response message in a 5G system, or a bearer context establishment response message in a 6G system.

[0030] This application provides a second aspect of an information transmission method applied to a first base station user plane entity. The method includes: receiving an intra-station interface request message sent by a first base station control plane entity in the first base station; the intra-station interface request message includes at least one of a user plane security policy and security activation information; the security activation information is used to instruct at least one PDU session or data radio bearer (DRB) to activate or deactivate encryption and / or integrity protection; and feeding back an intra-station interface response message to the first base station control plane; wherein the intra-station interface response message is sent by the first base station user plane entity after completing security activation.

[0031] In one embodiment, the step of activating the security of a PDU session or DRB configuration according to the intra-site interface request message includes: selecting a target PDU session to be processed from candidate PDU sessions, or selecting a target DRB configuration to be processed from candidate DRB configurations, according to the security activation instruction; and activating the security of the target PDU session or target DRB configuration according to the instruction content of the security activation instruction.

[0032] In one embodiment, the method further includes enabling user plane data integrity protection or encryption protection for the PDU session if the user plane security policy exists in the resource list of the PDU session to be established and the integrity protection indication or confidentiality protection indication is set to required.

[0033] In one embodiment, the method further includes: if user plane data integrity protection or encryption protection cannot be enabled for the PDU session through the first base station, then the establishment of the PDU session resource is refused, and the core network is notified through an error reason value.

[0034] In one embodiment, the method further includes: if the first base station is a next-generation LTE base station ng-eNB, then rejecting PDU sessions where the integrity protection indication is set to required.

[0035] In one embodiment, the method further includes: if the security indication information element in the PDU session resource list to be established contains the maximum integrity protection data rate, then by storing the rate parameter through the first base station, and when integrity protection is enabled for the PDU session, enforcing a rate limit for the PDU session and the associated terminal.

[0036] In one embodiment, the method further includes: if the security indication information element exists in the resource list of the PDU session to be established, and the integrity protection indication or confidentiality protection indication is set to not needed, then user plane integrity protection or encryption protection is not enabled for the PDU session.

[0037] In one embodiment, if each PDU session that includes a security activation status information element in the PDU session resource creation list information element supports the relevant function, then user plane integrity protection or encryption operations are performed based on the security activation status.

[0038] This application provides an information transmission method in a third aspect, applied to a first base station, the method comprising: receiving a first RRC message and / or uplink data sent by a terminal; wherein the first RRC message carries a user identifier and security verification information; and sending a first interface request message to a second base station; wherein the first interface request message carries the user identifier and the security verification information; the second base station is used to send a third RRC message to the terminal to trigger the terminal to enter an inactive state.

[0039] In one embodiment, the method further includes: receiving a first interface response message sent by the second base station; wherein the first interface response message carries at least one of a user plane security policy, a security algorithm used by the terminal at the second base station, and a user plane security activation state; the security algorithm includes an encryption and / or integrity protection algorithm; the user plane security activation state includes an activation state of encryption and / or integrity protection; the user plane security policy includes at least one of an integrity protection indication, a confidentiality protection indication, and a maximum integrity protection rate, wherein the integrity protection indication is used to indicate whether user plane integrity is applied for PDU session resources, and includes at least three configurations: required, preferred, and not needed; the confidentiality protection indication is used to indicate whether user plane encryption is applied for PDU session resources, and includes at least three configurations: required, preferred, and not needed.

[0040] In one embodiment, the method further includes: sending a second RRC message to the terminal via a first base station according to the security algorithm or the user plane security activation state; the second RRC message is carried by SRB0 or ​​SRB1.

[0041] In one embodiment, the security verification information is determined by an integrity protection algorithm and a security key negotiated between the second base station and the terminal; the integrity protection algorithm is configured by a fourth RRC message from the second base station; the fourth RRC message includes encryption configuration and / or integrity protection configuration, which includes at least one of the following: a wireless side key, NCC, an encryption or integrity algorithm, disabling encryption, and disabling integrity protection.

[0042] In one embodiment, the first RRC message and the uplink data use the same or different logical channels during transmission; the logical channel used by the uplink data is configured by the second base station through the third RRC message.

[0043] In one embodiment, the uplink data is encrypted or protected with the encryption key or integrity protection algorithm configured by the second base station; the first RRC message is encrypted with the integrity protection algorithm configured by the second base station; the key length of the encryption key and the integrity protection algorithm is 128 bits or 256 bits.

[0044] In one embodiment, the first RRC message may be an RRC recovery request message in a 5G system or an RRC recovery request message in a 6G system, used to request the network to restore the terminal's RRC connection.

[0045] In one embodiment, the first base station and the second base station may use the same or different wireless access technologies; wherein the wireless access technology is 5G wireless access technology or 6G wireless access technology.

[0046] In one embodiment, the core networks connected to the first base station and the second base station may be the same or different; wherein, the core network is a 5G core network or a 6G core network.

[0047] In one embodiment, according to the security algorithm or the user plane security activation state, a second RRC message carried on SRB0 is sent to the terminal through a first base station, including: if the first base station does not support the security algorithm or does not use the security algorithm, and / or does not support the user plane security activation state, then the second RRC message carried on SRB0 is sent to the terminal; wherein the second RRC message is a Radio Resource Control Setting RRC Establishment Message in a 5G system, or an RRC Establishment Message in a 6G system.

[0048] In one embodiment, according to the security algorithm or the user plane security activation state, a second RRC message carried on SRB1 is sent to the terminal through the first base station, including: if the first base station supports the security algorithm and supports the user plane security activation state, then the second RRC message is sent to the terminal; wherein the second RRC message is an RRC recovery message in a 5G system or an RRC recovery message in a 6G system.

[0049] In one embodiment, the method further includes: updating the key based on the security algorithm to obtain a target key; activating the target key after resetting the sequence COUNT value of the terminal packet data convergence protocol (PDCP) to 0; and sending a second RRC message to the terminal after successfully activating the target key.

[0050] In one embodiment, sending the second RRC message to the terminal includes: sending the second RRC message to the terminal via SRB1; wherein the signaling carried by SRB1 is encrypted and / or protected for integrity according to network configuration.

[0051] In one embodiment, sending the second RRC message to the terminal includes: sending the second RRC message to the terminal via SRB0; wherein the RRC signaling carried by SRB0 does not have encryption and integrity protection enabled.

[0052] In one embodiment, the first interface request message further includes a user context retrieval request message between base stations in a 5G system, or a user context retrieval request message between base stations in a 6G system; the first interface response message further includes a user context retrieval response message between base stations in a 5G system, or a user context retrieval response message between base stations in a 6G system.

[0053] In one embodiment, the first interface response message further includes at least one of the following: user security context, user plane security policy, user plane security activation status, protocol data unit (PDU) session establishment resources, key information, and the security capabilities of the terminal.

[0054] In one embodiment, the first interface request message further includes a data transmission indication; the data transmission indication is used to inform the second base station that the terminal has data to be transmitted, so that the second base station can report back to the first base station the security algorithm and user plane security activation status used when the terminal is stationed at the second base station.

[0055] In one embodiment, the user identifier is configured by the second base station via a third RRC message; wherein the third RRC message is an RRC release message sent by the terminal to the second base station when the terminal is camped there; the RRC release message includes at least one of the user identifier and logical channel configuration.

[0056] This application provides a fourth aspect of an information transmission method applied to a terminal, the method comprising: sending a first RRC message and / or uplink data to a network entity; wherein the first RRC message carries a user identifier and security verification information, the security verification information being determined by an integrity protection algorithm negotiated between a second base station and the terminal, and the logical channel used by the uplink data being configured by the second base station through a third RRC message; and receiving a second RRC message sent by the network entity; wherein the second RRC message is carried in SRB0 or ​​SRB1.

[0057] In one embodiment, the network entity includes at least one of a first base station, a first base station centralized entity, and a first base station decentralized entity.

[0058] In one embodiment, the method further includes: after receiving the second RRC message, resetting the COUNT value in the PDCP entity to 0.

[0059] In one embodiment, receiving the second RRC message sent by the network entity includes: receiving the second RRC message sent by the network entity via SRB1, wherein the RRC message transmitted on SRB1 is protected by encryption and / or integrity; the encryption and / or integrity protection configuration is configured by the second base station via a fourth RRC message.

[0060] In one embodiment, the second RRC message carried on SRB1 is an RRC recovery message in a 5G system or an RRC recovery message in a 6G system.

[0061] In one embodiment, the second RRC message carried on SRB0 is an RRC establishment message in a 5G system or an RRC establishment message in a 6G system.

[0062] In one embodiment, receiving the second RRC message sent by the network entity includes: receiving the second RRC message sent by the network entity via SRB0; wherein the RRC message transmitted on SRB0 does not have encryption and / or integrity protection enabled.

[0063] In one embodiment, the logical channel used for transmission of the first RRC message and the uplink data may be the same or different. The logical channel used for the uplink data is configured by the second base station through a third RRC message.

[0064] In one embodiment, the uplink data is encrypted or protected with the encryption key or integrity protection algorithm configured by the second base station; the first RRC message is encrypted with the integrity protection algorithm configured by the second base station; the key length of the encryption key and the integrity protection algorithm is 128 bits or 256 bits.

[0065] In one embodiment, the security verification information is determined using an integrity protection algorithm and a security key negotiated between the second base station and the terminal.

[0066] In one embodiment, the first RRC message may be an RRC recovery request message in a 5G system or an RRC recovery request message in a 6G system.

[0067] In one embodiment, the wireless access technologies that can be used when the terminal is respectively camped on the network entity and the second base station may be the same or different; wherein, the wireless access technologies include 5G wireless access technology and 6G wireless access technology.

[0068] In one embodiment, the user identifier is configured by the second base station via a third RRC message to trigger the terminal to enter an inactive state; wherein, the third RRC message is an RRC release message sent by the terminal to the second base station when the terminal is camped there; the RRC release message includes at least one of the user identifier and logical channel configuration.

[0069] In one embodiment, the integrity protection algorithm is configured by a fourth RRC message sent by the second base station; the fourth RRC message includes encryption configuration and / or integrity protection configuration, which includes at least one of: a radio side key, NCC, an encryption or integrity algorithm, disabling encryption, and disabling integrity protection. The fourth RRC message may be an RRC reconfiguration message.

[0070] This application also provides an information transmission device in a fifth aspect, configured in a first base station control plane entity. The device includes: a first transmitting module for transmitting a second RRC message to the terminal through a first base station separation entity; a second transmitting module for transmitting an intra-station interface request message to a first base station user plane entity; the intra-station interface request message includes at least one of a user plane security policy and security activation information; the security activation information is used to instruct at least one PDU session or data radio bearer DRB to activate or deactivate encryption and / or integrity protection; and a receiving module for receiving an intra-station interface response message fed back by the first base station user plane entity.

[0071] This application also provides an information transmission device in a sixth aspect, configured in a first base station user plane entity, the device comprising: a first receiving module, configured to receive an intra-station interface request message sent by a first base station control plane entity in the first base station; the intra-station interface request message includes at least one of a user plane security policy and security activation information; the security activation information is used to instruct at least one PDU session or data radio bearer (DRB) to activate or deactivate encryption and / or integrity protection; and a feedback module, configured to feed back an intra-station interface response message to the first base station control plane; wherein the intra-station interface response message is sent by the first base station user plane entity after completing security activation.

[0072] This application also provides an information transmission device in a seventh aspect, configured at a first base station, the device comprising: a second receiving module for receiving a first RRC message and / or uplink data sent by a terminal; wherein the first RRC message carries a user identifier and security verification information; and a third sending module for sending a first interface request message to a second base station; wherein the first interface request message carries the user identifier and the security verification information; the second base station is configured to send a third RRC message to the terminal to trigger the terminal to enter an inactive state.

[0073] This application also provides an information transmission device in an eighth aspect, configured in a terminal, the device comprising: a fourth transmitting module, configured to transmit a first RRC message and / or uplink data to a network entity; wherein the first RRC message carries a user identifier and security verification information, the security verification information being determined by an integrity protection algorithm negotiated between a second base station and the terminal, and the logical channel used by the uplink data being configured by the second base station through a third RRC message; and a third receiving module, configured to receive a second RRC message transmitted by the network entity; wherein the second RRC message is carried in SRB0 or ​​SRB1.

[0074] This application also provides a computer device in a ninth aspect. The computer device includes a memory and a processor. The memory stores a computer program, and the processor, when executing the computer program, performs the following steps: sending a second RRC message to the terminal via a first base station separation entity; sending an intra-station interface request message to a first base station user plane entity; the intra-station interface request message including at least one of a user plane security policy and security activation information; the security activation information being used to instruct at least one PDU session or data radio bearer DRB to activate or deactivate encryption and / or integrity protection; and receiving an intra-station interface response message from the first base station user plane entity.

[0075] This application also provides a computer device in a tenth aspect. The computer device includes a memory and a processor. The memory stores a computer program, and the processor, when executing the computer program, performs the following steps: receiving an intra-site interface request message sent by a first base station control plane entity in a first base station; the intra-site interface request message includes at least one of a user plane security policy and security activation information; the security activation information is used to instruct at least one PDU session or data radio bearer (DRB) to activate or deactivate encryption and / or integrity protection; and feeding back an intra-site interface response message to the first base station control plane; wherein the intra-site interface response message is sent by the first base station user plane entity after completing security activation.

[0076] In its eleventh aspect, this application also provides a computer device. The computer device includes a memory and a processor. The memory stores a computer program, and the processor, when executing the computer program, performs the following steps: receiving a first RRC message and / or uplink data sent by a terminal; wherein the first RRC message carries a user identifier and security verification information; and sending a first interface request message to a second base station; wherein the first interface request message carries the user identifier and the security verification information; the second base station is used to send a third RRC message to the terminal to trigger the terminal to enter an inactive state.

[0077] This application also provides a computer device in its twelfth aspect. The computer device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program performing the following steps: sending a first RRC message and / or uplink data to a first base station; wherein the first RRC message carries a user identifier and security verification information; and receiving a second RRC message sent by the first base station; wherein the second RRC message is carried in SRB0 or ​​SRB1.

[0078] In its thirteenth aspect, this application also provides a non-volatile computer-readable storage medium storing a computer program thereon, which, when executed by a processor, causes the processor to perform the following steps: sending a second RRC message to the terminal via a first base station separation entity; sending an intra-station interface request message to a first base station user plane entity; the intra-station interface request message including at least one of a user plane security policy and security activation information; the security activation information being used to instruct at least one PDU session or data radio bearer (DRB) to activate or deactivate encryption and / or integrity protection; and receiving an intra-station interface response message from the first base station user plane entity.

[0079] In its fourteenth aspect, this application also provides a non-volatile computer-readable storage medium storing a computer program thereon, which, when executed by a processor, causes the processor to perform the following steps: receiving an intra-site interface request message sent by a first base station control plane entity in a first base station; the intra-site interface request message including at least one of a user plane security policy and security activation information; the security activation information being used to instruct at least one PDU session or data radio bearer (DRB) to activate or deactivate encryption and / or integrity protection; and feeding back an intra-site interface response message to the first base station control plane; wherein the intra-site interface response message is sent by the first base station user plane entity after completing security activation.

[0080] In its fifteenth aspect, this application also provides a non-volatile computer-readable storage medium storing a computer program thereon, which, when executed by a processor, causes the processor to perform the following steps: receiving a first RRC message and / or uplink data sent by a terminal; wherein the first RRC message carries a user identifier and security verification information; and sending a first interface request message to a second base station; wherein the first interface request message carries the user identifier and the security verification information; the second base station is used to send a third RRC message to the terminal to trigger the terminal to enter an inactive state.

[0081] In its sixteenth aspect, this application also provides a non-volatile computer-readable storage medium storing a computer program thereon, which, when executed by a processor, causes the processor to perform the following steps: sending a first RRC message and / or uplink data to a first base station; wherein the first RRC message carries a user identifier and security verification information; and receiving a second RRC message sent by the first base station; wherein the second RRC message is carried in SRB0 or ​​SRB1.

[0082] This application also provides a computer program product in its seventeenth aspect, including a computer program that, when executed by a processor, causes the processor to perform the following steps: sending a second RRC message to the terminal via a first base station separation entity; sending an intra-station interface request message to a first base station user plane entity; the intra-station interface request message including at least one of a user plane security policy and security activation information; the security activation information being used to instruct at least one PDU session or data radio bearer DRB to activate or deactivate encryption and / or integrity protection; and receiving an intra-station interface response message from the first base station user plane entity.

[0083] This application also provides a computer program product in its eighteenth aspect, including a computer program that, when executed by a processor, causes the processor to perform the following steps: receiving an intra-site interface request message sent by a first base station control plane entity in a first base station; the intra-site interface request message including at least one of a user plane security policy and security activation information; the security activation information being used to instruct at least one PDU session or data radio bearer (DRB) to activate or deactivate encryption and / or integrity protection; and feeding back an intra-site interface response message to the first base station control plane; wherein the intra-site interface response message is sent by the first base station user plane entity after completing security activation.

[0084] This application also provides a computer program product in its nineteenth aspect, including a computer program that, when executed by a processor, causes the processor to perform the following steps: receiving a first RRC message and / or uplink data sent by a terminal; wherein the first RRC message carries a user identifier and security verification information; and sending a first interface request message to a second base station; wherein the first interface request message carries the user identifier and the security verification information; the second base station is used to send a third RRC message to the terminal to trigger the terminal to enter an inactive state.

[0085] In its twentieth aspect, this application also provides a computer program product, including a computer program that, when executed by a processor, causes the processor to perform the following steps: sending a first RRC message and / or uplink data to a first base station; wherein the first RRC message carries a user identifier and security verification information; and receiving a second RRC message sent by the first base station; wherein the second RRC message is carried in SRB0 or ​​SRB1.

[0086] The aforementioned information transmission method, apparatus, computer equipment, and storage medium involve the first base station control plane entity sending a second RRC message to the terminal through the first base station separation entity, and sending an intra-base station interface request message to the first base station user plane entity. The intra-base station interface request message includes at least one of a user plane security policy and security activation information. The security activation information is used to instruct at least one PDU session or data radio bearer (DRB) to activate or deactivate encryption and / or integrity protection. The system also receives an intra-base station interface response message from the first base station user plane entity. This application, by sending the intra-base station interface request message, implements the transmission of security algorithms for at least one of the user plane security policies and security activation information. This enables the transmission of algorithms supported by the source base station or security algorithms configured for the terminal to the target base station that actually requires them. This supports the target base station in deriving keys based on the security algorithms, providing reasonable assistance for the mobility and resource allocation of specific user equipment. This solves the problem of abnormal call drops caused by different base stations supporting different security algorithms and having different selection capabilities, thereby achieving support for the transmission of 256-bit encryption and integrity protection algorithms and related keys. Furthermore, this application does not involve any impact on the terminal and can be adjusted only through network-side solutions, thus exhibiting good forward compatibility and facilitating network deployment and implementation. Attached Figure Description

[0087] To more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the accompanying drawings used in the description of the embodiments of this application or related technologies will be briefly introduced below. Obviously, the drawings described below are merely some embodiments of this application. For those skilled in the art, other related drawings can be obtained based on these drawings without any creative effort.

[0088] Figure 1 is a 5G network architecture diagram provided in an embodiment of this application.

[0089] Figure 2 is a schematic diagram of the CU / DU architecture separation provided in an embodiment of this application.

[0090] Figure 3 is a signaling diagram of terminal recovery and release provided in an embodiment of this application.

[0091] Figure 4 is a flowchart illustrating a first information transmission method provided in an embodiment of this application.

[0092] Figure 5 is an interactive signaling diagram of the first information transmission method provided in an embodiment of this application.

[0093] Figure 6 is an interactive signaling diagram of a second information transmission method provided in an embodiment of this application.

[0094] Figure 7 is a flowchart illustrating a second information transmission method provided in an embodiment of this application.

[0095] Figure 8 is a flowchart illustrating a third information transmission method provided in an embodiment of this application.

[0096] Figure 9 is a flowchart illustrating a fourth information transmission method provided in an embodiment of this application.

[0097] Figure 10 is a structural block diagram of a first information transmission device provided in an embodiment of this application.

[0098] Figure 11 is a structural block diagram of a second information transmission device provided in an embodiment of this application.

[0099] Figure 12 is a structural block diagram of a third information transmission device provided in an embodiment of this application.

[0100] Figure 13 is a structural block diagram of a fourth information transmission device provided in an embodiment of this application.

[0101] Figure 14 is an internal structural diagram of a computer device according to an embodiment of this application. Detailed Implementation

[0102] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0103] 5G is the fifth generation of mobile communication technology. Compared to previous generations, it supports high speed, low latency, massive connectivity, high reliability, and network slicing. These characteristics make 5G a crucial infrastructure for driving digital transformation and will profoundly impact various fields such as industry, transportation, healthcare, and entertainment. 5G radio nodes (NG-RAN nodes) can be one of the following two types:

[0104] (1) gNB: User equipment functions that provide new radio (NR) user plane and control plane protocols for user equipment (UE);

[0105] (2) ng-eNB: User equipment functions that provide Enhanced Universal Terrestrial Radio Access (E-UTRA) user plane and control plane protocols for user equipment (UE).

[0106] gNB and ng-eNB are interconnected via the Xn interface. A gNB includes gNB-CU-CP and gNB-CU-UP. Figure 1 shows the 5G network architecture, and Figure 2 shows the CU / DU architecture separation diagram. Furthermore, gNB and ng-eNB are connected to the 5G core network (5GC) via the NG interface. Specifically:

[0107] (1) Connect to the Access and Mobility Management Function (AMF) via the NG-C interface;

[0108] (2) Connect to the User Plane Function (UPF) via the NG-U interface.

[0109] RRC_INACTIVE (Connection State between User Equipment (UE) and Radio Access Network (RAN)) is a state in which the UE remains in Connection Management Mode (CM-CONNECTED) and can move within the NG-RAN configured area (RNA) without notifying the NG-RAN. In the RRC_INACTIVE state, the last serving gNB retains the UE context and the NG connection associated with the UE in the serving AMF and UPF. If the last serving gNB receives downlink data from the UPF or downlink UE-associated signaling from the AMF (excluding UE context release command messages) while the UE is in the RRC_INACTIVE state, it will page the cell corresponding to the RNA, and if the RNA contains cells of neighboring gNBs, it may send XnAP RAN paging to those neighboring gNBs. When the last serving gNB receives a UE context release command message while the UE is in the RRC_INACTIVE state, it may page the cell corresponding to the RNA, and if the RNA contains cells of neighboring gNBs, it may send XnAP RAN paging to those neighboring gNBs to explicitly release the UE. When the last serving gNB receives an NG RESET message while the UE is in the RRC_INACTIVE state, it may page the relevant UE in the cell corresponding to the RNA, and if the RNA contains the cell of the neighboring gNB, it may send an XnAP RAN paging to the neighboring gNB to explicitly release the relevant UE.

[0110] When the cell the terminal recovers and the cell that was released are not the same cell, the signaling procedure is as shown in the error message. According to the TS38.423 protocol, the RETRIEVE UE CONTEXT RESPONSE section covers the following content:

[0111] The UE Context Information–Retrieve UE Context Response contains security-related information:

[0112] The UE Security Capabilities define the security algorithms supported by the terminal, as follows:

[0113] Wireless access layer security information (AS Security Information) mainly includes key-related information:

[0114] 5G's secure key management system is based on hierarchical derivation of key K, ensuring minimal key exposure. Encryption and integrity protection algorithms employ three main methods: AES, SNOW 3G, and ZUC, ensuring security requirements across different global markets. Compared to 4G, 5G offers higher security, providing stronger protection for user identity, data transmission, and signaling security. 5G supports a range of encryption and integrity protection algorithms, primarily defined by 3GPP (3rd Generation Partnership Project):

[0115] (1) Encryption Algorithms

[0116] Used to protect data confidentiality and prevent eavesdropping:

[0117] 128-NEA0: Unencrypted, suitable for certain special cases (such as emergency services).

[0118] 128-NEA1: Based on the SNOW 3G stream encryption algorithm, similar to the 4G EIA1.

[0119] 128-NEA2: Based on the Advanced Encryption Standard (AES) algorithm, providing stronger security.

[0120] 128-NEA3: Based on the stream encryption algorithm (ZUC) proposed in China, for the Chinese market or other specific needs.

[0121] (2) Integrity Protection Algorithms

[0122] Used to ensure data has not been tampered with and to prevent man-in-the-middle attacks:

[0123] 128-NIA0: No integrity protection; only suitable for special scenarios.

[0124] 128-NIA1: Integrity protection algorithm based on SNOW 3G.

[0125] 128-NIA2: Based on AES-CMAC (AES-based message verification code), it provides a high level of security.

[0126] 128-NIA3: Integrity protection based on the ZUC algorithm, suitable for the Chinese market or specific applications.

[0127] During PDU session establishment, the SMF should provide the ng eNB / gNB with the user plane security policy for the PDU session. The user plane security policy should indicate whether user plane confidentiality and / or user plane integrity protection should be activated for all DRBs belonging to the PDU session. The user plane security policy applies to activating user plane confidentiality and / or user plane integrity protection for all DRBs belonging to the PDU session.

[0128] AS user plane integrity protection and encryption activation should be performed as part of the DRB addition procedure using the RRC connection reconfiguration procedure, as follows:

[0129] 1a) The RRC connection reconfiguration procedure for adding DRBs can only be executed after RRC security has been activated as part of the AS security mode command procedure.

[0130] 1b) The gNB / ng-eNB shall send an RRC connection reconfiguration message to the UE for UP security activation, which includes an indication to activate UP integrity protection and encryption for each DRB according to the security policy.

[0131] 1c) If, as shown in the RRC connection reconfiguration message, UP integrity protection for the DRB is activated, and if the gNB / ng-eNB does not have a KUPint, then the gNB / ng-eNB should generate a KUPint, and UL integrity protection for such DRBs should begin from the gNB / ng-eNB. Similarly, if, as shown in the RRC connection reconfiguration message, UP encryption is activated for the DRB, and if the gNB / ng-eNB...

[0132] Because different base stations use different encryption or integrity protection algorithms, especially since the current main method is 128-bit encryption and integrity protection, the following problems will arise after upgrading to 256-bit encryption and integrity protection algorithms:

[0133] (1) The current access cell cannot confirm the encryption algorithm or integrity algorithm used by the source cell, which may cause the information stored on the terminal side or the signaling received from the access cell to fail the security check, resulting in abnormal call drops at the terminal.

[0134] (2) Unable to support 256-bit encryption and integrity protection algorithms and related key transmission process: The current standard already supports 256-bit encryption and integrity protection algorithms, and 256-bit encryption and integrity protection algorithms may also be used in 6G. However, the current process lacks support for 256 bits.

[0135] (3) Lack of user plane security activation status: It is impossible to determine whether the relevant user plane security is enabled or disabled at the source base station, so it is impossible to generate a security key for the user equipment; At present, there is only information exchange of security policies on the E1 interface, and there is no security activation indication. According to the requirements in the standard, the security policy may not be executed, so there needs to be a clear security activation indication.

[0136] Based on the above analysis of needs and reasons, the current 3GPP protocols still lack the ability to handle the recovery process from inactive states. Therefore, new standardization methods are needed to enhance functionality in order to meet the needs of network deployment and optimization.

[0137] In one embodiment, as shown in FIG4, an information transmission method is provided, applied to a first base station control plane entity, including the following steps S401 to S403.

[0138] S401: The first base station separates the entity and sends a second RRC message to the terminal.

[0139] It should be noted that when sending the second RRC message to the terminal through the first base station separation entity, the following steps may be included: sending the second RRC message to the terminal through the first base station separation entity according to the security algorithm or the user plane security activation state; the second RRC message is carried by the signaling radio bearer SRB0 or ​​SRB1.

[0140] In some embodiments of this application, when a security algorithm or user plane security activation state is sent to a terminal via a second RRC message carried on SRB1 through a first base station separation entity, the following may be included: if the first base station separation entity does not support the security algorithm or does not use the security algorithm, and / or does not support the user plane security activation state, then a second RRC message carried on SRB0 is sent to the terminal; wherein, the second RRC message is a Radio Resource Control Setting RRC Establishment Message in a 5G system, or an RRC Establishment Message in a 6G system.

[0141] In some embodiments of this application, if a security algorithm or user plane security activation state is used to send a second RRC message carried on SRB1 to a terminal through a first base station separation entity, the following steps may be included: if the first base station separation entity supports a security algorithm and supports user plane security activation state, then a second RRC message is sent to the terminal; wherein, the second RRC message is a radio resource control recovery RRC recovery message in a 5G system or an RRC recovery message in a 6G system.

[0142] S402: Send an intra-base station interface request message to the user plane entity of the first base station.

[0143] Specifically, the internal interface request message includes at least one of the following: user plane security policy and security activation information. The security activation information is used to instruct at least one PDU session or data radio bearer (DRB) to activate or deactivate encryption and / or integrity protection.

[0144] It should be noted that the in-station interface request message is the Bearer CONTEXT SETUP REQUEST message or the Bearer CONTEXT MODIFICATION REQUEST message in the 5G system, or the Bearer CONTEXT SETUP REQUEST message or the Bearer CONTEXT MODIFICATION REQUEST message in the 6G system, used to request the base station user plane entity to establish or modify the context configuration information of at least one bearer.

[0145] In some embodiments of this application, the intra-site interface request message includes at least one of a user identifier, an indication to resume SDT transmission, a security activation indication, and a user plane security policy. The security activation indication is used to activate or deactivate security for at least one PDU session or data radio bearer (DRB) configuration. Security includes encryption and / or integrity protection.

[0146] Specifically, the user identifier is configured by the second base station via a third RRC message. This third RRC message is an RRC release message sent by the terminal to the second base station when it is camped there; the RRC release message contains at least one of the following: the user identifier and the logical channel configuration.

[0147] S403: Receive the site interface response message from the user plane entity of the first base station.

[0148] It should be noted that the on-site interface response message is the Bearer CONTEXT SETUP RESPONSE message in the 5G system, or the Bearer CONTEXT SETUP RESPONSE message in the 6G system.

[0149] In some embodiments of this application, the signaling diagram for the information transmission method of the first base station control plane entity is shown in Figure 5. The first base station control plane entity sends a second RRC message to the terminal through the first base station separation entity; after the second RRC message is sent, the first base station control plane entity sends an intra-station interface request message to the first base station user plane entity; the first base station control plane entity receives the intra-station interface response message fed back by the first base station user plane entity.

[0150] The aforementioned information transmission method involves the first base station control plane entity sending a second RRC message to the terminal through the first base station separation entity, and sending an intra-base station interface request message to the first base station user plane entity. The intra-base station interface request message includes at least one of a user plane security policy and security activation information. The security activation information is used to instruct at least one PDU session or data radio bearer (DRB) to activate or deactivate encryption and / or integrity protection. The first base station control plane entity receives an intra-base station interface response message from the first base station user plane entity. This application, by sending the intra-base station interface request message, implements the transmission of security algorithms for at least one of the user plane security policies and security activation information. This enables the transmission of algorithms supported by the source base station or security algorithms configured for the terminal to the target base station that actually requires them. This supports the target base station in deriving keys based on security algorithms and provides reasonable assistance for the mobility and resource allocation of specific user equipment. This solves the problem of abnormal call drops caused by different base stations supporting different security algorithms and having different selection capabilities, and achieves support for the transmission of 256-bit encryption and integrity protection algorithms and related keys. Furthermore, this application does not involve any impact on the terminal. This application can be adjusted only through network-side solutions, has good forward compatibility, and is easy to deploy and implement in the network.

[0151] In some embodiments, the above information transmission method may further include the following steps:

[0152] The terminal receives an intra-station message sent by the first base station separation entity. The intra-station message includes a first Radio Resource Control (RRC) message and / or uplink data sent by the terminal. The first RRC message carries user identification and security verification information.

[0153] The first RRC message and the uplink data may use the same or different logical channels during transmission; the logical channel used by the uplink data is configured by the second base station through the third RRC message.

[0154] Specifically, the uplink data is encrypted or protected with the encryption key or integrity protection algorithm configured by the second base station; the first RRC message is encrypted with the integrity protection algorithm configured by the second base station; the key length of the encryption key and the integrity protection algorithm is 128 bits or 256 bits.

[0155] The first RRC message can be an RRC recovery request (RRCResumeRequest) in a 5G system or an RRC recovery request message in a 6G system, used to request the network to restore the terminal's RRC connection.

[0156] The first base station separation entity and the second base station may use the same or different wireless access technologies; the wireless access technologies may be 5G or 6G wireless access technologies. Furthermore, the core networks connected to the first base station separation entity and the second base station may be the same or different; the core networks may be 5G or 6G core networks.

[0157] The above-described information transmission method, by receiving the intra-station message separately sent by the first base station, enables the acquisition of the first Radio Resource Control (RRC) message and / or uplink data sent by the terminal, providing a basic guarantee for subsequent secure information transmission.

[0158] In some embodiments, the above information transmission method may further include the following steps:

[0159] The first interface request message is sent to the second base station; wherein the first interface request message carries user identifier and security verification information; the second base station is used to send a third RRC message to the terminal to trigger the terminal to enter an inactive state.

[0160] The security verification information is determined by the integrity protection algorithm and security key negotiated between the second base station and the terminal. The integrity protection algorithm is configured by the fourth RRC message of the second base station. The fourth RRC message includes encryption configuration and / or integrity protection configuration, which includes at least one of the following: wireless side key, next-hop chain count (NCC), encryption or integrity algorithm, disabling encryption, and disabling integrity protection.

[0161] In some embodiments of this application, the first interface request message further includes a data transmission indication; the data transmission indication is used to inform the second base station terminal that there is data to be transmitted, so that the second base station can provide feedback to the first base station separation entity on the security algorithm and user plane security activation status used when the terminal is stationed at the second base station.

[0162] To further explain, after the first base station control plane entity sends a first interface request message to the second base station, it may include the following: receiving a first interface response message sent by the second base station.

[0163] The first interface response message carries at least one of the following: user plane security policy, security algorithm used by the terminal at the second base station, and user plane security activation state; the security algorithm includes encryption and / or integrity protection algorithm; the user plane security activation state includes the activation state of encryption and / or integrity protection; the user plane security policy includes at least one of integrity protection indication, confidentiality protection indication, and maximum integrity protection rate; the integrity protection indication is used to indicate whether user plane integrity is applied for PDU session resources, and includes at least three configurations: required, preferred, and not needed; the confidentiality protection indication is used to indicate whether user plane encryption is applied for PDU session resources, and includes at least three configurations: required, preferred, and not needed.

[0164] In some embodiments of this application, the first interface request message further includes a user text message retrieval request message between base stations in a 5G system, or a user text message retrieval request message between base stations in a 6G system; correspondingly, the first interface response message further includes a user text message retrieval response message between base stations in a 5G system, or a user text message retrieval response message between base stations in a 6G system.

[0165] In other embodiments of this application, the first interface response message further includes at least one of the following: user security context, user plane security policy, user plane security activation state, protocol data unit (PDU) session establishment resources, key information, and terminal security capabilities. The protocol data unit (PDU) session establishment resources include at least one PDU session information. The PDU session information includes a PDU identifier and at least one Quality of Service (QoS) flow information. The QoS flow information includes a QoS flow identifier, at least one DRB identifier, and QoS configuration information. The key information includes at least one of a new radio key and an NCC (Network Control Center). The terminal's security capabilities include at least one of the following: at least one 4G encryption algorithm, at least one 4G integrity protection algorithm, at least one 5G encryption algorithm, at least one 5G integrity protection algorithm, at least one 6G encryption algorithm, and at least one 6G integrity protection algorithm supported by the terminal.

[0166] In summary, an interactive signaling diagram for the information transmission method can be obtained, as shown in Figure 6. The first base station control plane receives the intra-station message sent by the first base station separation entity. The first base station control plane entity sends a first interface request message to the second base station, and the second base station sends a first interface response message to the first base station control plane entity.

[0167] The above information transmission method, by sending a first interface request message to the second base station and receiving a first interface response message sent by the second base station, realizes the transmission operation of security algorithms for at least one of user plane security policies and security activation information, providing reasonable assistance for the mobility and resource allocation of specific user equipment, thereby solving the problem of abnormal call drops caused by different base stations supporting different security algorithms and selection capabilities.

[0168] In some embodiments of this application, the information transmission method may further include the following steps:

[0169] The target key is obtained by updating the key based on the security algorithm; after resetting the sequence count COUNT value of the terminal packet data aggregation protocol PDCP to 0, the target key is activated; after successfully activating the target key, a second RRC message is sent to the terminal.

[0170] By resetting the COUNT value of the terminal PDCP to 0, the PDCP layer will restart counting, and the previous sequence number will no longer be valid.

[0171] In some embodiments of this application, when sending a second RRC message to a terminal, the above method may include the following steps: sending a second RRC message to the terminal via a signaling radio bearer SRB1; wherein the signaling carried by SRB1 is encrypted and / or protected for integrity according to network configuration.

[0172] In some other embodiments of this application, when sending the second RRC message to the terminal, the above method may further include the following: sending the second RRC message to the terminal via the signaling radio bearer SRB0; wherein the RRC signaling carried by SRB0 does not have encryption and integrity protection enabled.

[0173] The aforementioned information transmission method uses a security algorithm to update the key, obtain the target key, and sends a second RRC message to the terminal after successfully activating the target key. This effectively solves the problem of inconsistent security algorithm support and selection capabilities between the two base stations, particularly the issue arising from the introduction of the 256-bit security algorithm.

[0174] In one embodiment, as shown in FIG7, an information transmission method is provided, applied to a first base station user plane entity, the method including the following steps S701 to S702.

[0175] S701: Receive the intra-station interface request message sent by the control plane entity of the first base station in the first base station.

[0176] The internal interface request message includes at least one of the following: user plane security policy and security activation information. The security activation information is used to instruct at least one PDU session or data radio bearer (DRB) to activate or deactivate encryption and / or integrity protection.

[0177] It should be noted that, when performing security activation on a PDU session or DRB configuration based on an internal interface request message, the following steps may be included: selecting a target PDU session to be processed from candidate PDU sessions, or selecting a target DRB configuration to be processed from candidate DRB configurations, according to the security activation instruction; and performing security activation on the target PDU session or target DRB configuration according to the instruction content of the security activation instruction.

[0178] S702: Feedback of the station interface response message to the control plane of the first base station.

[0179] Among them, the in-station interface response message is sent by the first base station user plane entity after completing security activation.

[0180] In some embodiments of this application, when the first base station user plane entity executes the information transmission method, the method may further include the following steps:

[0181] If the user plane security policy exists in the resource list of the PDU session to be established and the integrity protection indicator or confidentiality protection indicator is set to required, then user plane data integrity protection or encryption protection is enabled for the PDU session.

[0182] If user plane data integrity protection or encryption protection cannot be enabled for the PDU session through the first base station, the PDU session resource will be refused to be established, and the core network will be notified through the error reason value.

[0183] If the first base station is a next-generation LTE base station ng-eNB, then PDU sessions with the integrity protection indicator set to required are rejected.

[0184] If the security indication information element in the resource list of the PDU session to be established contains the maximum integrity protection data rate, then the rate parameter is stored through the first base station, and when integrity protection is enabled for the PDU session, rate limiting is enforced for the PDU session and the associated terminal.

[0185] If the security indication information element exists in the resource list of the PDU session to be established, and the integrity protection indication or confidentiality protection indication is set to "not needed", then user plane integrity protection or encryption protection will not be enabled for the PDU session.

[0186] If each PDU session that includes a security activation status information element in its PDU session resource creation list supports the relevant functions, then user plane integrity protection or encryption operations are performed based on the security activation status.

[0187] The aforementioned information transmission method involves the first base station user plane entity receiving an intra-station interface request message sent by the first base station control plane entity within the first base station. The intra-station interface request message includes at least one of a user plane security policy and security activation information. The first base station user plane entity then sends an intra-station interface response message back to the first base station control plane. This intra-station interface response message is sent by the first base station user plane entity after completing security activation. This application enables the transmission of algorithms supported by the source base station or security algorithms configured for the terminal to the target base station that actually requires them. This allows the target base station to derive keys based on security algorithms, providing reasonable assistance for the mobility and resource allocation of specific user equipment. This solves the problem of abnormal call drops caused by different security algorithms and selection capabilities supported by different base stations, thereby achieving support for the transmission of 256-bit encryption and integrity protection algorithms and related keys. Furthermore, this application does not involve any impact on the terminal; it can be adjusted only through network-side solutions, thus exhibiting good forward compatibility and facilitating network deployment and implementation.

[0188] In one embodiment, as shown in FIG8, an information transmission method is provided and applied to a first base station. The method includes the following steps S801 to S802.

[0189] S801: Receive the first RRC message and / or uplink data sent by the receiving terminal.

[0190] The first RRC message carries the user identifier and security verification information.

[0191] It should be noted that the security verification information is determined using the integrity protection algorithm and security key negotiated between the second base station and the terminal. The integrity protection algorithm is configured by the fourth RRC message of the second base station. The fourth RRC message includes encryption configuration and / or integrity protection configuration. The encryption configuration and / or integrity protection configuration includes at least one of the following: radio side key, NCC, encryption or integrity algorithm, disabling encryption, and disabling integrity protection.

[0192] To further clarify, the first RRC message and the uplink data may use the same or different logical channels during transmission; the logical channel used by the uplink data is configured by the second base station through the third RRC message.

[0193] Furthermore, uplink data is encrypted or protected against corruption using either the encryption key or integrity protection algorithm configured by the second base station. The first RRC message is encrypted using the integrity protection algorithm configured by the second base station. The key length for both the encryption key and the integrity protection algorithm is 128 bits or 256 bits. The first RRC message can be an RRC recovery request message (RRCResumeRequest) in a 5G system or an RRC recovery request message in a 6G system, used to request the network to restore the terminal's RRC connection.

[0194] S802: Send a first interface request message to the second base station.

[0195] Specifically, the first interface request message also includes a data transmission indication. The data transmission indication is used to inform the second base station terminal that there is data to be transmitted, so that the second base station can report back to the first base station the security algorithm and user plane security activation status used when the terminal is camped on the second base station.

[0196] The first interface request message carries the user identifier and security verification information. The second base station is used to send a third RRC message to the terminal to trigger the terminal to enter an inactive state.

[0197] Furthermore, the user identifier is configured by the second base station via a third RRC message. This third RRC message is an RRC release message sent by the terminal to the second base station when it is camped there. The RRC release message contains at least one of the following: the user identifier and the logical channel configuration.

[0198] Furthermore, after sending the first interface request message to the second base station, the above method may further include the following steps: receiving a first interface response message sent by the second base station; wherein the first interface response message carries at least one of the following: user plane security policy, security algorithm used by the terminal when at the second base station, and user plane security activation state; the security algorithm includes encryption and / or integrity protection algorithm; the user plane security activation state includes the activation state of encryption and / or integrity protection; the user plane security policy includes at least one of integrity protection indication, confidentiality protection indication, and maximum integrity protection rate, the integrity protection indication is used to indicate whether user plane integrity is applied for PDU session resources, and includes at least three configurations: required, preferred, and not needed; the confidentiality protection indication is used to indicate whether user plane encryption is applied for PDU session resources, and includes at least three configurations: required, preferred, and not needed.

[0199] It should be noted that when it is necessary to send a first interface request message to the second base station, the above method may include the following steps: according to the security algorithm or the user plane security activation state, send a second RRC message to the terminal through the first base station; wherein the second RRC message is carried by SRB0 or ​​SRB1.

[0200] Furthermore, the first base station and the second base station may use the same or different wireless access technologies; the wireless access technologies may be 5G or 6G wireless access technologies. In addition, the core networks connected to the first base station and the second base station may be the same or different; the core networks may be 5G or 6G core networks.

[0201] In some embodiments of this application, when it is necessary to send a second RRC message to the terminal, the second RRC message carried on SRB0 can also be sent to the terminal through the first base station according to the security algorithm or the user plane security activation state. Specifically, if the first base station does not support the security algorithm or does not use the security algorithm, and / or does not support the user plane security activation state, then the second RRC message carried on SRB0 is sent to the terminal. The second RRC message is a Radio Resource Control Setting RRC Establishment Message in a 5G system, or an RRC Establishment Message in a 6G system.

[0202] In some other embodiments of this application, when it is necessary to send a second RRC message to the terminal, the second RRC message carried on SRB1 can also be sent to the terminal through the first base station according to the security algorithm or the user plane security activation state. Specifically, if the first base station supports the security algorithm and supports the user plane security activation state, the second RRC message is sent to the terminal; wherein, the second RRC message is a radio resource control recovery RRC recovery message in the 5G system or an RRC recovery message in the 6G system.

[0203] As an example, when the first base station performs the information transmission method, the above method may further include the following steps: updating the key based on a security algorithm to obtain the target key; activating the target key after resetting the sequence COUNT value of the terminal packet data aggregation protocol PDCP to 0; and sending a second RRC message to the terminal after successfully activating the target key.

[0204] In some embodiments of this application, when sending a second RRC message to a terminal, the second RRC message can be sent to the terminal via SRB1; wherein the signaling carried by SRB1 is encrypted and / or protected for integrity according to the network configuration.

[0205] In some other embodiments of this application, when sending a second RRC message to the terminal, a second RRC message can also be sent to the terminal via SRB0; wherein the RRC signaling carried by SRB0 does not have encryption and integrity protection enabled.

[0206] It should be noted that the first interface request message also includes a user text message retrieval request message between base stations in a 5G system, or a user text message retrieval request message between base stations in a 6G system; correspondingly, the first interface response message also includes a user text message retrieval response message between base stations in a 5G system, or a user text message retrieval response message between base stations in a 6G system.

[0207] To further explain, the first interface response message also includes at least one of the following: user security context, user plane security policy, user plane security activation status, protocol data unit (PDU) session establishment resources, key information, and terminal security capabilities.

[0208] In the aforementioned information transmission method, the first base station receives a first RRC message and / or uplink data sent by the terminal; wherein the first RRC message carries user identifier and security verification information; the first base station sends a first interface request message to the second base station; wherein the first interface request message carries user identifier and security verification information; the second base station sends a third RRC message to the terminal to trigger the terminal to enter an inactive state. This application enables the transmission of algorithms supported by the source base station or security algorithms configured for the terminal to the target base station that actually requires them, thereby supporting the target base station in deriving keys based on security algorithms, providing reasonable assistance for the mobility and resource allocation of specific user equipment. This solves the problem of abnormal call drops caused by different security algorithms and selection capabilities supported by different base stations, thus achieving support for the transmission of 256-bit encryption and integrity protection algorithms and related keys. Furthermore, this application does not involve any impact on the terminal; this application can be adjusted only through network-side solutions, therefore it has good forward compatibility and is easy to deploy and implement in the network.

[0209] In one embodiment, as shown in FIG9, an information transmission method is provided, applied to a terminal, the method including the following steps S901 to S902.

[0210] S901: Send the first RRC message and / or uplink data to the first base station.

[0211] The first RRC message carries the user identifier and security verification information.

[0212] It should be noted that the user identifier is configured by the second base station through the third RRC message; the third RRC message is the RRC release message sent by the terminal to the second base station when it is camped there; the RRC release message contains at least one of the user identifier and logical channel configuration.

[0213] S902: Receive the second RRC message sent by the network entity.

[0214] The second RRC message is carried in either SRB0 or ​​SRB1. The network entity may include at least one of the following: the first base station, the first base station centralized entity, and the first base station separate entity. In the following embodiments, the example of a network entity including the first base station is used for illustration.

[0215] It should be noted that after receiving the second RRC message, the terminal resets the COUNT value in the PDCP entity to 0.

[0216] In some embodiments of this application, the terminal receiving the second RRC message sent by the first base station may include the following steps: receiving the second RRC message sent by the first base station via SRB1, wherein the RRC message transmitted on SRB1 is protected by encryption and / or integrity, and the encryption and / or integrity protection configuration is configured by the second base station via a fourth RRC message.

[0217] The second RRC message carried on SRB1 is either an RRC recovery message in a 5G system or an RRC recovery message in a 6G system.

[0218] In some other embodiments of this application, the terminal receiving the second RRC message sent by the first base station may include the following steps: receiving the second RRC message sent by the first base station via SRB0; wherein the RRC message transmitted on SRB0 does not have encryption and / or integrity protection enabled.

[0219] The second RRC message carried on SRB0 is either an RRC establishment message in a 5G system or an RRC establishment message in a 6G system.

[0220] To further clarify, the logical channel used for transmission of the first RRC message and the uplink data may be the same or different. The logical channel used for the uplink data is configured by the second base station through the third RRC message. The uplink data is encrypted or protected with integrity using either the encryption key or the integrity protection algorithm configured by the second base station; the first RRC message is encrypted with integrity protection using the integrity protection algorithm configured by the second base station; the key length of the encryption key and the integrity protection algorithm is 128 bits or 256 bits.

[0221] The security verification information is determined using the integrity protection algorithm and security key negotiated between the second base station and the terminal.

[0222] The first RRC message can be an RRC recovery request (RRCResumeRequest) message in a 5G system or an RRC recovery request message in a 6G system.

[0223] Furthermore, when the terminal camps on the first base station and the second base station respectively, the wireless access technologies that can be used may be the same or different; among them, the wireless access technologies include 5G wireless access technology and 6G wireless access technology.

[0224] In the aforementioned information transmission method, the terminal sends a first RRC message and / or uplink data to the first base station, wherein the first RRC message carries user identification and security verification information; and the terminal receives a second RRC message sent by the first base station, wherein the second RRC message is carried in SRB0 or ​​SRB1. This application enables the transmission of algorithms supported by the source base station or security algorithms configured for the terminal to the target base station that actually requires them, thereby supporting the target base station in deriving keys based on security algorithms, providing reasonable assistance for the mobility and resource allocation of specific user equipment. This solves the problem of abnormal call drops caused by different base stations supporting different security algorithms and having different selection capabilities, thus achieving support for the transmission of 256-bit encryption and integrity protection algorithms and related keys. Furthermore, this application does not involve any impact on the terminal; it can be adjusted only through network-side solutions, therefore it has good forward compatibility and is easy to deploy and implement in the network.

[0225] In some embodiments of this application, (1) the terminal sends an RRCresumeRequest to gNB1; wherein the RRCresumeRequest includes a user identifier resumeIdentity and security verification information resumeMAC-I, and the specific signaling includes:

[0226] (3) gNB1 obtains the user identifier resumeIdentity and security verification information resumeMAC-I from the RRRCResumeRequest message, and determines that it is not assigned by gNB1 based on resumeIdentity;

[0227] (4) gNB1 sends a RETRIEVE UE CONTEXT REQUEST message to gNB2, as shown in the table below:

[0228] (5) After receiving the RETRIEVE UE CONTEXT REQUEST message, gNB2 determines that the allocation was made by gNB2 based on the UE Context ID and resumeMAC-I, and sends back a RETRIEVE UE CONTEXT RESPONSE message. The information of the RETRIEVE UE CONTEXT RESPONSE message is shown in the table below:

[0229] The information in UE Context Information – Retrieve UE Context Response is shown in the table below:

[0230] The gNB security information is shown below:

[0231] The PDU Session Resources To Be Setup List contains the following information, as shown in the table below:

[0232] The UP activation status includes the following, as shown in the table below:

[0233] It should be understood that although the steps in the flowcharts of the above embodiments are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the above embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.

[0234] Based on the same inventive concept, this application also provides an information transmission device for implementing the above-described information transmission method. The solution provided by this device is similar to the solution described in the above-described method; therefore, the specific limitations in one or more information transmission device embodiments provided below can be found in the limitations of the information transmission method described above, and will not be repeated here.

[0235] In one embodiment, as shown in FIG10, an information transmission device is provided, configured in a first base station control plane entity, including: a first transmitting module 10, a second transmitting module 20, and a receiving module 30. Wherein:

[0236] The first sending module 10 is used to send a second RRC message to the terminal through the first base station separation entity;

[0237] The second sending module 20 is used to send an intra-station interface request message to the user plane entity of the first base station; the intra-station interface request message includes at least one of user plane security policy and security activation information; the security activation information is used to instruct at least one PDU session or data radio bearer DRB to activate or deactivate encryption and / or integrity protection.

[0238] The receiving module 30 is used to receive the site interface response message fed back by the user plane entity of the first base station.

[0239] In some embodiments, the receiving module 30 is further configured to receive an intra-station message separately transmitted by the first base station, the intra-station message including a first radio resource control (RRC) message and / or uplink data transmitted by the terminal; wherein the first RRC message carries a user identifier and security verification information.

[0240] In some embodiments, the first sending module 10 is further configured to send a first interface request message to the second base station; wherein the first interface request message carries a user identifier and security verification information; the second base station is configured to send a third RRC message to the terminal to trigger the terminal to enter an inactive state.

[0241] In some embodiments, the receiving module 30 is further configured to receive a first interface response message sent by the second base station; wherein the first interface response message carries at least one of the following: user plane security policy, security algorithm used by the terminal when at the second base station, and user plane security activation state; the security algorithm includes encryption and / or integrity protection algorithm; the user plane security activation state includes the activation state of encryption and / or integrity protection; the user plane security policy includes at least one of integrity protection indication, confidentiality protection indication, and maximum integrity protection rate; the integrity protection indication is used to indicate whether user plane integrity is applied for PDU session resources, and includes at least three configurations: required, preferred, and not needed; the confidentiality protection indication is used to indicate whether user plane encryption is applied for PDU session resources, and includes at least three configurations: required, preferred, and not needed.

[0242] In some embodiments, the first sending module 10 is further configured to send a second RRC message to the terminal through the first base station separation entity according to a security algorithm or user plane security activation status; the second RRC message is carried by SRB0 or ​​SRB1.

[0243] In some embodiments, the security verification information is determined by the integrity protection algorithm and security key negotiated between the second base station and the terminal; the integrity protection algorithm is configured by the fourth RRC message of the second base station; the fourth RRC message includes encryption configuration and / or integrity protection configuration, which includes at least one of the following: wireless side key, NCC, encryption or integrity algorithm, disabling encryption, and disabling integrity protection.

[0244] In some embodiments, the first RRC message and the uplink data may use the same or different logical channels during transmission; the logical channel used by the uplink data is configured by the second base station through the third RRC message.

[0245] In some embodiments, the uplink data is encrypted or protected with the encryption key or integrity protection algorithm configured by the second base station; the first RRC message is encrypted with the integrity protection algorithm configured by the second base station; the key length of the encryption key and the integrity protection algorithm is 128 bits or 256 bits.

[0246] In some embodiments, the first RRC message may be an RRC recovery request message in a 5G system or an RRC recovery request message in a 6G system, used to request the network to restore the terminal's RRC connection.

[0247] In some embodiments, the wireless access technologies used by the first base station separation entity and the second base station may be the same or different; wherein, the wireless access technology is 5G wireless access technology or 6G wireless access technology.

[0248] In some embodiments, the core networks connected to the first base station separation entity and the second base station may be the same or different; wherein, the core network is a 5G core network or a 6G core network.

[0249] In some embodiments, the first interface request message may further include a user-to-text message retrieval request message between base stations in a 5G system, or a user-to-text message retrieval request message between base stations in a 6G system.

[0250] The first interface response message also includes user-to-user message retrieval response messages between base stations in a 5G system, or user-to-user message retrieval response messages between base stations in a 6G system.

[0251] In some embodiments, the first interface request message further includes a data transmission indication; the data transmission indication is used to inform the second base station terminal that there is data to be transmitted, so that the second base station can provide feedback to the first base station separation entity on the security algorithm and user plane security activation status used when the terminal is stationed at the second base station.

[0252] In some embodiments, the first interface response message further includes at least one of the following: user security context, user plane security policy, user plane security activation state, protocol data unit (PDU) session establishment resources, key information, and terminal security capabilities; the protocol data unit (PDU) session establishment resources include at least one PDU session information; the PDU session information includes a PDU identifier and at least one QoS FLOW information; the QoS FLOW information includes a QoS FLOW identifier, at least one DRB identifier, and QoS configuration information; the key information includes at least one of a new radio key and NCC; the terminal security capabilities include at least one of the following: at least one 4G encryption algorithm, at least one 4G integrity protection algorithm, at least one 5G encryption algorithm, at least one 5G integrity protection algorithm, at least one 6G encryption algorithm, and at least one 6G integrity protection algorithm supported by the terminal.

[0253] In some embodiments, the first sending module 10 is further configured to: if the first base station separation entity does not support the security algorithm or does not use the security algorithm, and / or does not support the user plane security activation state, then send a second RRC message carried on SRB0 to the terminal; wherein the second RRC message is a Radio Resource Control Setting RRC Establishment Message in a 5G system, or an RRC Establishment Message in a 6G system.

[0254] In some embodiments, the first sending module 10 is further configured to: if the first base station separation entity supports a security algorithm and supports user plane security activation state, then send a second RRC message to the terminal; wherein the second RRC message is a radio resource control recovery RRC recovery message in a 5G system or an RRC recovery message in a 6G system.

[0255] In some embodiments, the first sending module 10 is further configured to: perform key update based on a security algorithm to obtain a target key;

[0256] After resetting the sequence COUNT value of the Terminal Packet Data Convergence Protocol (PDCP) to 0, the target key is activated;

[0257] After successfully activating the target key, a second RRC message is sent to the terminal.

[0258] In some embodiments, the first sending module 10 is further configured to: send a second RRC message to the terminal via a signaling radio bearer SRB1; wherein the signaling carried by SRB1 is encrypted and / or protected for integrity according to network configuration.

[0259] In some embodiments, the first sending module 10 is further configured to: send a second RRC message to the terminal via SRB0; wherein the RRC signaling carried by SRB0 does not have encryption and integrity protection enabled.

[0260] In some embodiments, the user identifier is configured by the second base station via a third RRC message; wherein the third RRC message is an RRC release message sent by the terminal to the second base station when the terminal is camped there; the RRC release message includes at least one of the user identifier and logical channel configuration.

[0261] In some embodiments, the in-site interface request message includes at least one of the following: user identifier, indication of whether to resume small data transmission (SDT) transmission, security activation indication, and user plane security policy; the security activation indication is used to activate or deactivate the security configuration of at least one PDU session or data radio bearer DRB; security includes encryption and / or integrity protection.

[0262] In some embodiments, the in-station interface request message is a Bearer CONTEXT SETUP REQUEST or Bearer CONTEXT MODIFICATION REQUEST message in a 5G system, or a Bearer CONTEXT SETUP REQUEST or Bearer CONTEXT MODIFICATION REQUEST message in a 6G system, used to request the base station user plane entity to establish or modify the context configuration information of at least one bearer.

[0263] The on-site interface response message is either the Bearer CONTEXT SETUP RESPONSE message in the 5G system, or the Bearer CONTEXT SETUP RESPONSE message in the 6G system.

[0264] In one embodiment, as shown in FIG11, an information transmission device is provided, configured in a first base station user plane entity, including: a first receiving module 40 and a feedback module 50. Wherein:

[0265] The first receiving module 40 is used to receive an intra-station interface request message sent by the control plane entity of the first base station in the first base station; the intra-station interface request message includes at least one of user plane security policy and security activation information; the security activation information is used to instruct at least one PDU session or data radio bearer DRB to activate or deactivate encryption and / or integrity protection.

[0266] The feedback module 50 is used to feed back the internal interface response message to the control plane of the first base station; wherein, the internal interface response message is sent by the user plane entity of the first base station after completing the security activation.

[0267] In some embodiments, the first receiving module 40 is further configured to: select a target PDU session to be processed from candidate PDU sessions according to a security activation indication, or select a target DRB configuration to be processed from candidate DRB configurations;

[0268] Perform security activation on the target PDU session or target DRB configuration according to the instructions in the security activation instruction.

[0269] In some embodiments, the feedback module 50 is further configured to: enable user plane data integrity protection or encryption protection for the PDU session if the user plane security policy exists in the resource list of the PDU session to be established and the integrity protection indication or confidentiality protection indication is set to required.

[0270] In some embodiments, the feedback module 50 is further configured to: refuse to establish PDU session resources if user plane data integrity protection or encryption protection cannot be enabled for the PDU session through the first base station, and notify the core network through an error reason value.

[0271] In some embodiments, the feedback module 50 is further configured to reject PDU sessions where the integrity protection indication is set to required if the first base station is a next-generation LTE base station ng-eNB.

[0272] In some embodiments, the feedback module 50 is further configured to: if the security indication information element in the PDU session resource list to be established contains the maximum integrity protection data rate, then store the rate parameter through the first base station, and enforce rate limiting for the PDU session and associated terminal when integrity protection is enabled for the PDU session.

[0273] In some embodiments, the feedback module 50 is further configured to: if the security indication information element exists in the resource list of the PDU session to be established, and the integrity protection indication or confidentiality protection indication is set to not needed, then not enable user plane integrity protection or encryption protection for the PDU session.

[0274] In some embodiments, the feedback module 50 is further configured to: if each PDU session that includes a security activation status information element in the PDU session resource establishment list information element supports the relevant function, then perform user plane integrity protection or encryption operations based on the security activation status.

[0275] In one embodiment, as shown in FIG12, an information transmission device is provided, configured in a first base station, including: a second receiving module 60 and a third transmitting module 70. Wherein:

[0276] The second receiving module 60 is used to receive a first RRC message and / or uplink data sent by the terminal; wherein the first RRC message carries user identification and security verification information;

[0277] The third sending module 70 is used to send a first interface request message to the second base station; wherein the first interface request message carries user identifier and security verification information; the second base station is used to send a third RRC message to the terminal to trigger the terminal to enter an inactive state.

[0278] In some embodiments, the second receiving module 60 is further configured to: receive a first interface response message sent by the second base station; wherein the first interface response message carries at least one of the following: a user plane security policy, a security algorithm used by the terminal when it is at the second base station, and a user plane security activation state; the security algorithm includes an encryption and / or integrity protection algorithm; the user plane security activation state includes an activation state of encryption and / or integrity protection; the user plane security policy includes at least one of an integrity protection indication, a confidentiality protection indication, and a maximum integrity protection rate; the integrity protection indication is used to indicate whether user plane integrity is applied for PDU session resources, and includes at least three configurations: required, preferred, and not needed; the confidentiality protection indication is used to indicate whether user plane encryption is applied for PDU session resources, and includes at least three configurations: required, preferred, and not needed.

[0279] In some embodiments, the third sending module 70 is further configured to: send a second RRC message SRB to the terminal via the first base station according to the security algorithm or the user plane security activation state; the second RRC message is carried by SRB0 or ​​SRB1.

[0280] In some embodiments, the security verification information is determined by the integrity protection algorithm and security key negotiated between the second base station and the terminal; the integrity protection algorithm is configured by the fourth RRC message of the second base station; the fourth RRC message includes encryption configuration and / or integrity protection configuration, which includes at least one of the following: wireless side key, NCC, encryption or integrity algorithm, disabling encryption, and disabling integrity protection.

[0281] In some embodiments, the first RRC message and the uplink data may use the same or different logical channels during transmission; the logical channel used by the uplink data is configured by the second base station through the third RRC message.

[0282] In some embodiments, the uplink data is encrypted or protected with the encryption key or integrity protection algorithm configured by the second base station; the first RRC message is encrypted with the integrity protection algorithm configured by the second base station; the key length of the encryption key and the integrity protection algorithm is 128 bits or 256 bits.

[0283] In some embodiments, the first RRC message may be an RRC recovery request message in a 5G system or an RRC recovery request message in a 6G system, used to request the network to restore the terminal's RRC connection.

[0284] In some embodiments, the first base station and the second base station may use the same or different wireless access technologies; wherein, the wireless access technology is 5G wireless access technology or 6G wireless access technology.

[0285] In some embodiments, the core networks connected to the first base station and the second base station may be the same or different; wherein, the core network is a 5G core network or a 6G core network.

[0286] In some embodiments, if the first base station does not support a security algorithm or does not employ a security algorithm, and / or does not support a user plane security activation state, a second RRC message carried on SRB0 is sent to the terminal; wherein the second RRC message is a Radio Resource Control Setting RRC Establishment Message in a 5G system, or an RRC Establishment Message in a 6G system.

[0287] In some embodiments, the third sending module 70 is further configured to: if the first base station supports a security algorithm and supports user plane security activation state, send a second RRC message to the terminal; wherein the second RRC message is a radio resource control recovery RRC recovery message in a 5G system or an RRC recovery message in a 6G system.

[0288] In some embodiments, the third sending module 70 is further configured to: perform key update based on a security algorithm to obtain a target key;

[0289] After resetting the sequence COUNT value of the Terminal Packet Data Convergence Protocol (PDCP) to 0, the target key is activated;

[0290] After successfully activating the target key, a second RRC message is sent to the terminal.

[0291] In some embodiments, the third sending module 70 is further configured to: send a second RRC message to the terminal via the signaling radio bearer SRB1; wherein the signaling carried by SRB1 is encrypted and / or protected for integrity according to the network configuration.

[0292] In some embodiments, the third sending module 70 is further configured to: send a second RRC message to the terminal via SRB0; wherein the RRC signaling carried by SRB0 does not have encryption and integrity protection enabled.

[0293] In some embodiments, the first interface request message may further include a user-to-text message retrieval request message between base stations in a 5G system, or a user-to-text message retrieval request message between base stations in a 6G system.

[0294] The first interface response message also includes user-to-user message retrieval response messages between base stations in a 5G system, or user-to-user message retrieval response messages between base stations in a 6G system.

[0295] In some embodiments, the first interface response message may further include at least one of the following: user security context, user plane security policy, user plane security activation status, protocol data unit (PDU) session establishment resources, key information, and terminal security capabilities.

[0296] In some embodiments, the first interface request message further includes a data transmission indication; the data transmission indication is used to inform the second base station terminal that there is data to be transmitted, so that the second base station can report back to the first base station the security algorithm and user plane security activation status used when the terminal is camped on the second base station.

[0297] In some embodiments, the user identifier is configured by the second base station via a third RRC message; wherein the third RRC message is an RRC release message sent by the terminal to the second base station when the terminal is camped there; the RRC release message includes at least one of the user identifier and logical channel configuration.

[0298] In one embodiment, as shown in FIG13, an information transmission device is provided, configured in a terminal, including: a fourth transmitting module 80 and a third receiving module 90. Wherein:

[0299] The fourth sending module 80 is used to send a first RRC message and / or uplink data to the network entity; wherein, the first RRC message carries a user identifier and security verification information, the security verification information is determined by the integrity protection algorithm negotiated by the second base station and the terminal, and the logical channel used by the uplink data is configured by the second base station through the third RRC message;

[0300] The third receiving module 90 is used to receive the second RRC message sent by the network entity; wherein the second RRC message is carried in SRB0 or ​​SRB1.

[0301] In some embodiments, the network entity includes at least one of a first base station, a first base station centralized entity, and a first base station separate entity.

[0302] In the following embodiments, the network entity including the first base station is used as an example for illustration.

[0303] In some embodiments, the third receiving module 90 is further configured to: after receiving the second RRC message, reset the COUNT value in the PDCP entity to 0.

[0304] In some embodiments, the third receiving module 90 is further configured to: receive a second RRC message sent by the first base station via SRB1, wherein the RRC message transmitted on SRB1 is protected by encryption and / or integrity; the encryption and / or integrity protection configuration is configured by the second base station via a fourth RRC message.

[0305] In some embodiments, the second RRC message carried on SRB1 is an RRC recovery message in a 5G system or an RRC recovery message in a 6G system.

[0306] In some embodiments, the second RRC message carried on SRB0 is an RRC establishment message in a 5G system or an RRC establishment message in a 6G system.

[0307] In some embodiments, the third receiving module 90 is further configured to: receive a second RRC message sent by the first base station via SRB0; wherein the RRC message transmitted on SRB0 does not have encryption and / or integrity protection enabled.

[0308] In some embodiments, the logical channel used for transmission of the first RRC message and the uplink data may be the same or different. The logical channel used for the uplink data is configured by the second base station through the third RRC message.

[0309] In some embodiments, the uplink data is encrypted or protected with the encryption key or integrity protection algorithm configured by the second base station; the first RRC message is encrypted with the integrity protection algorithm configured by the second base station; the key length of the encryption key and the integrity protection algorithm is 128 bits or 256 bits.

[0310] In some embodiments, the security verification information is determined using an integrity protection algorithm and a security key negotiated between the second base station and the terminal.

[0311] In some embodiments, the first RRC message may be an RRC recovery request message in a 5G system or an RRC recovery request message in a 6G system.

[0312] In some embodiments, when a terminal camps on a first base station and a second base station, the wireless access technologies that can be used may be the same or different; wherein, the wireless access technologies include 5G wireless access technology and 6G wireless access technology.

[0313] In some embodiments, the user identifier is configured by the second base station via a third RRC message; wherein the third RRC message is an RRC release message sent by the terminal to the second base station when the terminal is camped there; the RRC release message includes at least one of the user identifier and logical channel configuration.

[0314] The aforementioned information transmission method, apparatus, computer equipment, and storage medium involve the first base station control plane entity sending a second RRC message to the terminal through the first base station separation entity, and sending an intra-base station interface request message to the first base station user plane entity. The intra-base station interface request message includes at least one of a user plane security policy and security activation information. The security activation information is used to instruct at least one PDU session or data radio bearer (DRB) to activate or deactivate encryption and / or integrity protection. The system also receives an intra-base station interface response message from the first base station user plane entity. This application, by sending the intra-base station interface request message, implements the transmission of security algorithms for at least one of the user plane security policies and security activation information. This enables the transmission of algorithms supported by the source base station or security algorithms configured for the terminal to the target base station that actually requires them. This supports the target base station in deriving keys based on the security algorithms, providing reasonable assistance for the mobility and resource allocation of specific user equipment. This solves the problem of abnormal call drops caused by different base stations supporting different security algorithms and having different selection capabilities, thereby achieving support for the transmission of 256-bit encryption and integrity protection algorithms and related keys. Furthermore, this application does not involve any impact on the terminal and can be adjusted only through network-side solutions, thus exhibiting good forward compatibility and facilitating network deployment and implementation.

[0315] Each module in the aforementioned information transmission device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the memory of a computer device as software, so that the processor can call and execute the operations corresponding to each module.

[0316] In one embodiment, a computer device is provided, which may be a terminal, and its internal structure diagram is shown in Figure 14. The computer device includes a processor, memory, input / output interface, communication interface, display unit, and input device. The processor, memory, and input / output interface are connected via a system bus, and the communication interface, display unit, and input device are also connected to the system bus via the input / output interface. The processor of the computer device provides computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The input / output interface of the computer device is used for exchanging information between the processor and external devices. The communication interface of the computer device is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, mobile cellular networks, NFC (Near Field Communication), or other technologies. When the computer program is executed by the processor, it implements an information transmission method. The display unit of the computer device is used to form a visually visible image and may be a display screen, a projection device, or a virtual reality imaging device. The display screen can be an LCD screen or an e-ink screen. The input device of the computer device can be a touch layer covering the display screen, or buttons, trackballs, or touchpads set on the casing of the computer device, or external keyboards, touchpads, or mice, etc.

[0317] Those skilled in the art will understand that the structure shown in Figure 14 is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or may combine certain components, or may have different component arrangements.

[0318] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of the relevant data shall comply with the relevant laws, regulations and standards of the relevant countries and regions.

[0319] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.

[0320] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0321] The above embodiments are merely illustrative of several implementation methods of this application, and their descriptions are relatively specific and detailed. However, they should not be construed as limiting the scope of this application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.

Claims

An information transmission method, applied to a first base station control plane entity, the method comprising: The first base station separates the entity from the terminal and sends a second Radio Resource Control (RRC) message. Send an intra-base station interface request message to the user plane entity of the first base station; The in-site interface request message includes at least one of the following: user plane security policy and security activation information; The security activation information is used to instruct at least one Protocol Data Unit (PDU) session or Data Radio Bearer (DRB) to activate or deactivate encryption and / or integrity protection; as well as Receive the site interface response message fed back by the user plane entity of the first base station. The method according to claim 1, further comprising: The terminal receives an intra-station message sent by the first base station separation entity. The intra-station message includes a first RRC message and / or uplink data sent by the terminal. The first RRC message carries user identification and security verification information. The method according to claim 2, further comprising: The first interface request message is sent to the second base station; wherein the first interface request message carries the user identifier and the security verification information; the second base station is used to send a third RRC message to the terminal to trigger the terminal to enter an inactive state. The method according to claim 1, further comprising: The terminal receives a first interface response message sent by the second base station; wherein the first interface response message carries at least one of the following: a user plane security policy, a security algorithm used by the terminal at the second base station, and a user plane security activation state; the security algorithm includes an encryption and / or integrity protection algorithm; the user plane security activation state includes an activation state of encryption and / or integrity protection; the user plane security policy includes at least one of an integrity protection indication, a confidentiality protection indication, and a maximum integrity protection rate; the integrity protection indication is used to indicate whether user plane integrity is applied for PDU session resources, and includes at least three configurations: required, preferred, and not needed; the confidentiality protection indication is used to indicate whether user plane encryption is applied for PDU session resources, and includes at least three configurations: required, preferred, and not needed. According to the method of claim 1, the step of sending a second RRC message to the terminal via a first base station separation entity includes: Based on the security algorithm or the user plane security activation status, a second RRC message is sent to the terminal through the first base station separation entity; The second RRC message is carried using either a signaling radio bearer (SRB0) or a signaling radio bearer (SRB1). The method according to claim 2, wherein the security check information is determined by an integrity protection algorithm and a security key negotiated between the second base station and the terminal; the integrity protection algorithm is configured by a fourth RRC message of the second base station; the fourth RRC message comprises encryption configuration and / or integrity protection configuration, and the encryption configuration and / or integrity protection configuration comprises: At least one of the following: wireless side key, NCC, encryption or integrity algorithm, disabling encryption, and disabling integrity protection. According to the method of claim 2, the first RRC message and the uplink data use the same or different logical channels during transmission; the logical channel used by the uplink data is configured by the second base station through the third RRC message. According to the method of claim 2, the uplink data is encrypted or protected with the encryption key or integrity protection algorithm configured by the second base station; the first RRC message is encrypted with the integrity protection algorithm configured by the second base station; and the key length of the encryption key and the integrity protection algorithm is 128 bits or 256 bits. According to the method of claim 2, the first RRC message may be an RRC recovery request message in a 5G system or an RRC recovery request message in a 6G system, used to request the network to restore the RRC connection of the terminal. The method of claim 3, wherein the radio access technologies employed by the first base station separation entity and the second base station, respectively, can or can not be the same; and wherein, The wireless access technology is either 5G or 6G wireless access technology. The method according to claim 3, wherein the core networks to which the first base station separation entity and the second base station are respectively connected can be the same or different; and The core network is either a 5G core network or a 6G core network. According to the method of claim 3, the first interface request message further includes a user context retrieval request message between base stations in a 5G system, or a user context retrieval request message between base stations in a 6G system. The first interface response message also includes a user-to-user message retrieval response message between base stations in a 5G system, or a user-to-user message retrieval response message between base stations in a 6G system. According to the method of claim 3, the first interface request message further includes a data transmission indication; the data transmission indication is used to inform the second base station that the terminal has data to be transmitted, so that the second base station can feed back to the first base station separation entity the security algorithm and user plane security activation status used when the terminal is stationed at the second base station. According to the method of claim 4, the first interface response message further includes at least one of user security context, user plane security policy, user plane security activation state, PDU session establishment resources, key information, and the security capabilities of the terminal; the PDU session establishment resources include at least one PDU session information; the PDU session information includes a PDU identifier and at least one Quality of Service Flow (QOS FLOW) information; the QOS FLOW information includes a QOS FLOW identifier, at least one DRB identifier, and QOS configuration information; the key information includes at least one of a new radio key and a next-hop chain count (NCC); the security capabilities of the terminal include at least one of at least one 4G encryption algorithm, at least one 4G integrity protection algorithm, at least one 5G encryption algorithm, at least one 5G integrity protection algorithm, at least one 6G encryption algorithm, and at least one 6G integrity protection algorithm supported by the terminal. According to the method of claim 5, wherein sending a second RRC message carried on SRB0 to the terminal via a first base station separation entity based on the security algorithm or the user plane security activation state includes: If the first base station separation entity does not support the security algorithm or does not use the security algorithm, and / or does not support the user plane security activation state, then a second RRC message carried on SRB0 is sent to the terminal; wherein the second RRC message is a Radio Resource Control Setting RRC Establishment Message in a 5G system, or an RRC Establishment Message in a 6G system. According to the method of claim 5, wherein sending a second RRC message carried on SRB1 to the terminal via a first base station separation entity based on the security algorithm or the user plane security activation state includes: If the first base station separation entity supports the security algorithm and the user plane security activation state, then a second RRC message is sent to the terminal; wherein the second RRC message is an RRC recovery message in a 5G system or an RRC recovery message in a 6G system. The method according to claim 1, further comprising: The target key is obtained by updating the key based on the security algorithm described above. The target key is activated after the sequence count (COUNT) value of the terminal packet data convergence protocol (PDCP) is reset to 0; After successfully activating the target key, a second RRC message is sent to the terminal. The method according to claim 17, wherein sending a second RRC message to the terminal includes: A second RRC message is sent to the terminal via Signaling Radio Bearer (SRB1); wherein the signaling carried by SRB1 enables encryption and / or integrity protection according to the network configuration. The method according to claim 16, wherein sending a second RRC message to the terminal includes: A second RRC message is sent to the terminal via SRB0; wherein the RRC signaling carried by SRB0 does not have encryption and integrity protection enabled. The method of claim 2, wherein the user identity is configured by the second base station through a third RRC message; wherein, The third RRC message is an RRC release message sent by the terminal to the second base station when the terminal is camped there; the RRC release message contains at least one of the following: user identifier and logical channel configuration. According to the method of claim 1, the in-station interface request message includes at least one of the user identifier, whether to resume small data transmission (SDT) transmission, security activation indication, and user plane security policy; the security activation indication is used to activate or deactivate the security configuration of at least one PDU session or data radio bearer DRB; the security includes encryption and / or integrity protection. According to the method of claim 1, the in-station interface request message is a bearer context establishment request message or a bearer context modification request message in a 5G system, or a bearer context establishment request message or a bearer context modification request message in a 6G system, used to request the base station user plane entity to establish or modify the context configuration information of at least one bearer. The in-station interface response message is either a bearer context establishment response message in a 5G system or a bearer context establishment response message in a 6G system. An information transmission method, applied to a first base station user plane entity, the method comprising: Receive the intra-station interface request message sent by the control plane entity of the first base station in the first base station; The in-site interface request message includes at least one of the following: user plane security policy and security activation information; The security activation information is used to instruct at least one PDU session or data radio bearer DRB to activate or deactivate encryption and / or integrity protection. as well as The system feeds back an internal interface response message to the control plane of the first base station; wherein the internal interface response message is sent by the user plane entity of the first base station after completing security activation. According to the method of claim 23, the security activation of the PDU session or DRB configuration based on the intra-site interface request message includes: The target PDU session to be processed is selected from the candidate PDU sessions according to the security activation indication, or the target DRB configuration to be processed is selected from the candidate DRB configurations. The security activation is performed on the target PDU session or target DRB configuration according to the instructions of the security activation instruction. The method according to claim 23, further comprising: If the user plane security policy exists in the resource list of the PDU session to be established and the integrity protection indicator or confidentiality protection indicator is set to required, then user plane data integrity protection or encryption protection is enabled for the PDU session. The method according to claim 23, further comprising: If user plane data integrity protection or encryption protection cannot be enabled for the PDU session through the first base station, the establishment of the PDU session resource will be refused, and the core network will be notified through an error reason value. The method according to claim 23, further comprising: If the first base station is a next-generation LTE base station ng-eNB, then PDU sessions with the integrity protection indicator set to required are rejected. The method according to claim 23, further comprising: If the security indication information element in the resource list of the PDU session to be established contains the maximum integrity protection data rate, then the rate parameter is stored through the first base station, and when integrity protection is enabled for the PDU session, rate limiting is enforced for the PDU session and the associated terminal. The method according to claim 23, further comprising: If the security indication information element exists in the resource list of the PDU session to be established, and the integrity protection indication or confidentiality protection indication is set to not needed, then user plane integrity protection or encryption protection will not be enabled for the PDU session. According to the method of claim 23, if each PDU session that includes a security activation status information element in the PDU session resource establishment list information element supports the relevant function, then user plane integrity protection or encryption operation is performed based on the security activation status. An information transmission method, applied to a first base station, the method comprising: The receiving terminal sends a first RRC message and / or uplink data; wherein the first RRC message carries a user identifier and security verification information; and The first interface request message is sent to the second base station; wherein the first interface request message carries the user identifier and the security verification information; the second base station is used to send a third RRC message to the terminal to trigger the terminal to enter an inactive state. The method according to claim 31, further comprising: The terminal receives a first interface response message sent by the second base station; wherein the first interface response message carries at least one of the following: a user plane security policy, a security algorithm used by the terminal at the second base station, and a user plane security activation state; the security algorithm includes an encryption and / or integrity protection algorithm; the user plane security activation state includes an activation state of encryption and / or integrity protection; the user plane security policy includes at least one of an integrity protection indication, a confidentiality protection indication, and a maximum integrity protection rate; the integrity protection indication is used to indicate whether user plane integrity is applied for PDU session resources, and includes at least three configurations: required, preferred, and not needed; the confidentiality protection indication is used to indicate whether user plane encryption is applied for PDU session resources, and includes at least three configurations: required, preferred, and not needed. The method according to claim 31, further comprising: Based on the security algorithm or the user plane security activation status, a second RRC message is sent to the terminal through the first base station; The second RRC message is carried by either SRB0 or ​​SRB1. The method of claim 31, wherein the security check information is determined by an integrity protection algorithm and a security key negotiated between the second base station and the terminal; the integrity protection algorithm is configured by a fourth RRC message of the second base station; the fourth RRC message includes an encryption configuration and / or an integrity protection configuration, and the encryption configuration and / or the integrity protection configuration includes: At least one of the following: wireless side key, NCC, encryption or integrity algorithm, disabling encryption, and disabling integrity protection. According to the method of claim 31, the first RRC message and the uplink data use the same or different logical channels during transmission; the logical channel used by the uplink data is configured by the second base station through the third RRC message. According to the method of claim 33, the uplink data is encrypted or protected with the encryption key or integrity protection algorithm configured by the second base station; the first RRC message is encrypted with the integrity protection algorithm configured by the second base station; and the key length of the encryption key and the integrity protection algorithm is 128 bits or 256 bits. According to the method of claim 31, the first RRC message may be an RRC recovery request message in a 5G system or an RRC recovery request message in a 6G system, used to request the network to restore the terminal's RRC connection. The method of claim 31, wherein the radio access technologies employed by the first base station and the second base station, respectively, can or can not be the same; wherein, The wireless access technology is either 5G or 6G wireless access technology. The method of claim 31, wherein the core networks to which the first base station and the second base station are connected respectively can be the same or different; and The core network is either a 5G core network or a 6G core network. According to the method of claim 31, sending a second RRC message carried on SRB0 to the terminal via the first base station according to the security algorithm or the user plane security activation state includes: If the first base station does not support the security algorithm or does not use the security algorithm, and / or does not support the user plane security activation state, then it sends a second RRC message carried on SRB0 to the terminal; wherein the second RRC message is a Radio Resource Control Setting RRC Establishment Message in a 5G system, or an RRC Establishment Message in a 6G system. According to the method of claim 31, wherein sending a second RRC message carried on SRB1 to the terminal via the first base station according to the security algorithm or the user plane security activation state includes: If the first base station supports the security algorithm and the user plane security activation state, it sends a second RRC message to the terminal; wherein the second RRC message is an RRC recovery message in a 5G system or an RRC recovery message in a 6G system. The method according to claim 31, further comprising: The target key is obtained by updating the key based on the security algorithm described above. After resetting the sequence COUNT value of the Terminal Packet Data Convergence Protocol (PDCP) to 0, the target key is activated; After successfully activating the target key, a second RRC message is sent to the terminal. The method according to claim 42, wherein sending the second RRC message to the terminal includes: The second RRC message is sent to the terminal via SRB1; wherein the signaling carried by SRB1 is encrypted and / or protected for integrity according to the network configuration. The method according to claim 42, wherein sending the second RRC message to the terminal includes: A second RRC message is sent to the terminal via SRB0; wherein the RRC signaling carried by SRB0 does not have encryption and integrity protection enabled. According to the method of claim 31, the first interface request message further includes a user context retrieval request message between base stations in a 5G system, or a user context retrieval request message between base stations in a 6G system. The first interface response message also includes a user-to-user message retrieval response message between base stations in a 5G system, or a user-to-user message retrieval response message between base stations in a 6G system. According to the method of claim 31, the first interface response message further includes at least one of user security context, user plane security policy, user plane security activation state, protocol data unit (PDU) session establishment resources, key information, and the security capabilities of the terminal. According to the method of claim 31, the first interface request message further includes a data transmission indication; the data transmission indication is used to inform the second base station that the terminal has data to be transmitted, so that the second base station can feed back to the first base station the security algorithm and user plane security activation status used when the terminal is camped on the second base station. The method of claim 31, wherein the user identity is configured by the second base station through a third RRC message; wherein, The third RRC message is an RRC release message sent by the terminal to the second base station when the terminal is camped there; the RRC release message contains at least one of the following: user identifier and logical channel configuration. An information transmission method, applied to a terminal, the method comprising: Sending a first RRC message and / or uplink data to a network entity; wherein the first RRC message carries a user identifier and security verification information, the security verification information being determined using an integrity protection algorithm negotiated between the second base station and the terminal, and the logical channel used by the uplink data being configured by the second base station through a third RRC message; and Receive a second RRC message sent by the network entity; wherein the second RRC message is carried in SRB0 or ​​SRB1. The method according to claim 49, wherein The network entity includes at least one of the following: a first base station, a first base station centralized entity, and a first base station separate entity. The method according to claim 49, further comprising: Upon receiving the second RRC message, reset the COUNT value in the PDCP entity to 0. The method according to any one of claims 49 to 51, wherein receiving the second RRC message sent by the network entity comprises: The second base station receives a second RRC message sent by the network entity via SRB1, wherein the RRC message transmitted on SRB1 is protected by encryption and / or integrity; the encryption and / or integrity protection configuration is configured by the second base station via a fourth RRC message. According to the method of claim 49, the second RRC message carried on SRB1 is an RRC recovery message in a 5G system or an RRC recovery message in a 6G system. According to the method of claim 49, the second RRC message carried on SRB0 is an RRC establishment message in a 5G system or an RRC establishment message in a 6G system. The method of claim 49, wherein receiving the second RRC message sent by the network entity includes: The network entity sends a second RRC message via SRB0; wherein the RRC message transmitted on SRB0 does not have encryption and / or integrity protection enabled. According to the method of claim 49, the first RRC message and the logical channel used during the transmission of the uplink data may be the same or different; the logical channel used by the uplink data is configured by the second base station through the third RRC message. According to the method of claim 49, the uplink data is encrypted or protected with integrity using the encryption key or integrity protection algorithm configured by the second base station; the first RRC message is encrypted with integrity protection algorithm configured by the second base station; and the key length of the encryption key and integrity protection algorithm is 128 bits or 256 bits. According to the method of claim 49, the security verification information is determined by an integrity protection algorithm and a security key negotiated between the second base station and the terminal. According to the method of claim 49, the first RRC message may be an RRC recovery request message in a 5G system or an RRC recovery request message in a 6G system. The method of claim 49, wherein the radio access technologies that can be employed when the terminal camps on the network entity and the second base station, respectively, can or can not be the same; wherein, The wireless access technologies include 5G wireless access technology and 6G wireless access technology. The method of claim 49, wherein the user identification is configured by the second base station through a third RRC message to trigger a terminal to enter an inactive state; wherein, The third RRC message is an RRC release message sent by the terminal to the second base station when the terminal is camped there; the RRC release message contains at least one of the following: user identifier and logical channel configuration. The method according to claim 49, wherein The integrity protection algorithm is configured by a fourth RRC message sent by the second base station; the fourth RRC message includes an encryption configuration and / or an integrity protection configuration, and the encryption configuration and / or the integrity protection configuration include: The wireless side key, NCC, encryption or integrity algorithm, disabling encryption, and disabling integrity protection are at least one of the following. The fourth RRC message may be an RRC reconfiguration message. An information transmission device is configured on the control plane entity of a first base station, the device comprising: The first sending module is used to send a second RRC message to the terminal through the first base station separation entity; The second sending module is used to send an intra-station interface request message to the user plane entity of the first base station. The in-site interface request message includes at least one of the following: user plane security policy and security activation information; The security activation information is used to instruct at least one PDU session or data radio bearer DRB to activate or deactivate encryption and / or integrity protection. as well as The receiving module is used to receive the site interface response message fed back by the user plane entity of the first base station. An information transmission device is configured on the user plane entity of a first base station, the device comprising: The first receiving module is used to receive the intra-station interface request message sent by the first base station control plane entity in the first base station; The in-site interface request message includes at least one of the following: user plane security policy and security activation information; The security activation information is used to instruct at least one PDU session or data radio bearer (DRB) to activate or deactivate encryption and / or integrity protection; as well as The feedback module is used to feed back the internal interface response message to the control plane of the first base station; wherein the internal interface response message is sent by the user plane entity of the first base station after completing security activation. An information transmission device is configured at a first base station, the device comprising: The second receiving module is used to receive a first RRC message and / or uplink data sent by the terminal; wherein the first RRC message carries user identification and security verification information; and The third sending module is used to send a first interface request message to the second base station; wherein the first interface request message carries the user identifier and the security verification information; the second base station is used to send a third RRC message to the terminal to trigger the terminal to enter an inactive state. An information transmission device, configured on a terminal, the device comprising: The fourth sending module is used to send a first RRC message and / or uplink data to a network entity; wherein the first RRC message carries a user identifier and security verification information, the security verification information being determined using an integrity protection algorithm negotiated between the second base station and the terminal, and the logical channel used by the uplink data being configured by the second base station through a third RRC message; and The third receiving module is used to receive the second RRC message sent by the network entity; wherein the second RRC message is carried in SRB0 or ​​SRB1. A computer device comprising a memory and a processor, the memory storing a computer program, wherein the processor implements the method of any one of claims 1 to 62 when executing the computer program. A non-volatile computer readable storage medium having stored thereon a computer program, wherein the computer program, when executed by a processor, causes the processor to implement the method of any one of claims 1 to 62. A computer program product comprising a computer program, wherein the computer program, when executed by a processor, causes the processor to implement the method of any one of claims 1 to 62.