WO2020052362A1 - 处理方法和设备 - Google Patents

处理方法和设备 Download PDF

Info

Publication number
WO2020052362A1
WO2020052362A1 PCT/CN2019/098811 CN2019098811W WO2020052362A1 WO 2020052362 A1 WO2020052362 A1 WO 2020052362A1 CN 2019098811 W CN2019098811 W CN 2019098811W WO 2020052362 A1 WO2020052362 A1 WO 2020052362A1
Authority
WO
WIPO (PCT)
Prior art keywords
security key
target node
connection configuration
terminal
configuration information
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2019/098811
Other languages
English (en)
French (fr)
Inventor
郑倩
吴昱民
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Vivo Mobile Communication Co Ltd
Original Assignee
Vivo Mobile Communication Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Vivo Mobile Communication Co Ltd filed Critical Vivo Mobile Communication Co Ltd
Publication of WO2020052362A1 publication Critical patent/WO2020052362A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/04Key management, e.g. using generic bootstrapping architecture [GBA]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W76/00Connection management
    • H04W76/10Connection setup
    • H04W76/15Setup of multiple wireless link connections

Definitions

  • Embodiments of the present disclosure relate to the field of communications technologies, and in particular, to a processing method and device.
  • a data transmission method is to adopt a DC architecture.
  • MN Master Node
  • SN Secondary Node
  • MCG Master Serving Cell Group
  • SCG Secondary Serving Cell Group
  • the base station key (Key of SN, K SN ) used by the terminal to communicate with the SN is assigned by the MN, and each update of the K SN is associated with a corresponding SN counter value (SN Counter) .
  • the terminal will initiate a Random Access Channel (RACH) process to the SN based on the newly obtained K SN , and the SN confirms that the SN security parameter is activated by receiving a random access request from the terminal.
  • RACH Random Access Channel
  • the security key for communication between the terminal and the target node (for example: SN) is allocated by the source node (for example: MN), and the activation of the security parameters of the target node is confirmed through the RACH process. .
  • Connection configuration 1 is used for the terminal to establish a connection with the source node and the target node at the same time during the mobility process
  • connection configuration 2 is used for the mobile After the sexual process, the terminal establishes a connection with the target node.
  • the security mechanism in the related art can only solve the security update method when the connection configuration 1 exists, and there is no solution on how to allocate the security key used by the target node when the network has two connection configurations.
  • An object of the embodiments of the present disclosure is to provide a processing method and device, which solve the problem of how to allocate a security key used by a target node when there are two sets of connection configurations in a network using a dual connection mobility management process.
  • an embodiment of the present disclosure provides a processing method applied to a terminal, where the method includes:
  • the first security key is a security key used to connect the target node with the dual connection configuration information and the single connection configuration information, respectively;
  • the three security keys are security keys used in connection with the target node by applying single connection configuration information.
  • an embodiment of the present disclosure further provides a processing method, which is applied to a target node.
  • the method includes:
  • the terminal's encryption and / or integrity protection function is activated.
  • an embodiment of the present disclosure further provides a processing method, which is applied to a source node, and the method includes:
  • the first parameter is used to calculate a first security key
  • the first security key is a security key used to connect the target node with the dual connection configuration information and the single connection configuration information, respectively;
  • the second parameter is used to calculate a second security key, and the second security key is a security key used to connect to the target node by applying the dual connection configuration information;
  • the third parameter is used to calculate a third security key, and the third security key is a security key used to connect to the target node by applying single connection configuration information.
  • an embodiment of the present disclosure further provides a processing method, which is applied to a target node.
  • the method includes:
  • the first parameter is used to calculate a first security key
  • the first security key is a security key used to connect the target node with the dual connection configuration information and the single connection configuration information, respectively;
  • the third parameter is used to calculate a third security key, and the third security key is a security key used to connect to the target node by applying single connection configuration information.
  • an embodiment of the present disclosure further provides a terminal, including:
  • a first determining module configured to determine a first security key configured by a target node, where the first security key is a security key used to connect the target node with dual connection configuration information and single connection configuration information; or ,
  • a second determining module configured to determine a second security key configured by the source node and a third security key configured by the target node, wherein the second security key is used by the dual-connection configuration information to connect to the target node;
  • a security key; the third security key is a security key used when the single connection configuration information is used to connect with the target node.
  • an embodiment of the present disclosure further provides a target node, including:
  • a first confirmation module configured to confirm activation of an encryption and / or integrity protection function of the terminal according to one or more of a dual connection configuration completion message, a random access request message, and a single connection configuration completion message; or,
  • the second confirmation module is configured to confirm activation of the encryption and / or integrity protection function of the terminal according to the MAC-I or the truncated MAC-I carried in any one of the dual connection configuration completion message and the random access request message.
  • an embodiment of the present disclosure further provides a source node, including:
  • a fifth sending module configured to send a first parameter configured by the target node to the terminal, or send a second parameter configured by the source node and a third parameter configured by the target node;
  • the first parameter is used to calculate a first security key
  • the first security key is a security key used to connect the target node with the dual connection configuration information and the single connection configuration information, respectively;
  • the second parameter is used to calculate a second security key, and the second security key is a security key used to connect to the target node by applying the dual connection configuration information;
  • the third parameter is used to calculate a third security key, and the third security key is a security key used to connect to the target node by applying single connection configuration information.
  • an embodiment of the present disclosure further provides a target node, including:
  • a seventh sending module configured to send a first parameter configured by the target node or a third parameter configured by the target node to a source node;
  • the first parameter is used to calculate a first security key
  • the first security key is a security key used to connect the target node with the dual connection configuration information and the single connection configuration information, respectively;
  • the third parameter is used to calculate a third security key, and the third security key is a security key used to connect to the target node by applying single connection configuration information.
  • an embodiment of the present disclosure further provides a terminal, including: a processor, a memory, and a program stored on the memory and executable on the processor.
  • a terminal including: a processor, a memory, and a program stored on the memory and executable on the processor.
  • the program When the program is executed by the processor, Realizing the steps of the processing method according to the first aspect.
  • an embodiment of the present disclosure further provides a network device, including: a processor, a memory, and a program stored on the memory and executable on the processor, where the program is executed by the processor Steps of implementing the processing method according to the second aspect, the third aspect, or the fourth aspect.
  • an embodiment of the present disclosure further provides a computer-readable storage medium.
  • the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the implementation is implemented as in the first aspect and the second aspect. Aspect, the third aspect, or the step of the processing method described in the fourth aspect.
  • the security key used by the target node can be determined, and the security key update of the mobility management in the dual connection architecture can be realized to ensure the reliability of communication.
  • FIG. 1 is a flowchart of a dual-connection security mechanism in related technologies
  • FIG. 2 is a schematic structural diagram of a wireless communication system according to an embodiment of the present disclosure
  • FIG. 3 is a first flowchart of a processing method according to an embodiment of the present disclosure
  • FIG. 4 is a second flowchart of a processing method according to an embodiment of the present disclosure.
  • FIG. 5 is a third flowchart of a processing method according to an embodiment of the present disclosure.
  • FIG. 6 is a fourth flowchart of a processing method according to an embodiment of the present disclosure.
  • FIG. 7 is a fifth flowchart of a processing method according to an embodiment of the present disclosure.
  • FIG. 8 is a sixth flowchart of a processing method according to an embodiment of the present disclosure.
  • FIG. 9 is a seventh flowchart of a processing method according to an embodiment of the present disclosure.
  • FIG. 10 is a flowchart of a processing method according to an embodiment of the present disclosure.
  • FIG. 11 is a structural diagram of a terminal according to an embodiment of the present disclosure.
  • FIG. 12 is one of the structural diagrams of a target node according to an embodiment of the present disclosure.
  • FIG. 13 is a structural diagram of a source node according to an embodiment of the present disclosure.
  • FIG. 14 is a second structural diagram of a target node according to an embodiment of the present disclosure.
  • 15 is a second structural diagram of a terminal according to an embodiment of the present disclosure.
  • FIG. 16 is a structural diagram of a network device according to an embodiment of the present disclosure.
  • words such as “exemplary” or “for example” are used as examples, illustrations or illustrations. Any embodiment or design described as “exemplary” or “for example” in the embodiments of the present disclosure should not be construed as more preferred or advantageous over other embodiments or designs. Rather, the use of the words “exemplary” or “for example” is intended to present the relevant concept in a concrete manner.
  • the wireless communication system may be a 5G system, an evolved long term evolution (evolved long term evolution, eLTE) system, or a subsequent evolved communication system.
  • eLTE evolved long term evolution
  • FIG. 2 a schematic architecture diagram of a wireless communication system according to an embodiment of the present disclosure is shown.
  • the wireless communication system may include a first network device 20, a second network device 21, and a user equipment (UE).
  • UE user equipment
  • the user equipment is referred to as UE22
  • UE22 may communicate with the first network device 20 Communicate with the second network device 21 (transmit signaling or transmit data).
  • the connection between the foregoing devices may be a wireless connection.
  • a solid line is used in FIG. 2 for illustration.
  • the above communication system may include multiple UEs 22, and the first network device 20 and the second network device 22 may communicate with multiple UEs 22.
  • the first network device 20 and the second network device 21 provided in the embodiment of the present disclosure may be a base station.
  • the base station may be a commonly used base station, an evolved base station (eNB), or a 5G system.
  • Network equipment for example, next generation base station (gNB) or transmission and reception point (TRP) and other equipment.
  • gNB next generation base station
  • TRP transmission and reception point
  • the user equipment provided in the embodiments of the present disclosure may be a mobile phone, a tablet computer, a notebook computer, an Ultra-Mobile Personal Computer (UMPC), a netbook, or a Personal Digital Assistant (PDA).
  • UMPC Ultra-Mobile Personal Computer
  • PDA Personal Digital Assistant
  • an embodiment of the present disclosure provides a processing method, and an execution body of the method may be a terminal.
  • the specific steps are as follows:
  • Step 301 Determine a first security key configured by the target node, where the first security key is a security key used to connect the target node with the dual connection configuration information and the single connection configuration information; or
  • the three security keys are security keys used in connection with the target node by applying single connection configuration information.
  • the first security key can be called Key
  • the second security key can be called Key_1
  • the third security key can be called Key_2.
  • determining the first security key configured by the target node includes:
  • the first parameter may be an input parameter for deriving a first security key (Key), for example, a counter value.
  • Key for example, a first security key
  • determining the second security key configured by the source node and the third security key configured by the target node includes:
  • the second parameter may be an input parameter for deriving a second security key (Key_1), for example, a counter value (Counter_1).
  • the third parameter may be an input parameter for deriving a third security key (Key_2), for example, a counter value (Counter_2).
  • Key_2 a third security key
  • Counter_2 a counter value
  • the first parameter is carried in a Radio Resource Control (RRC) reconfiguration message sent by the source node, or the second parameter and the third parameter are carried by the source node.
  • RRC Radio Resource Control
  • the RRC reconfiguration message further carries one or more of the following:
  • Dual-connection configuration information for establishing a connection with the source node and the target node
  • the RRC reconfiguration message carries part of the mobility management configuration information of the terminal, and the part of the terminal's mobility management configuration information includes: used to communicate with the source node and the target Dual connection configuration information for a node establishing a connection; single connection configuration information for establishing a connection with the target node; a first parameter.
  • the RRC reconfiguration message carries part of the terminal's mobility management configuration information
  • the part of the terminal's mobility management configuration information includes: a dual device used to establish a connection with the source node and the target node; Connection configuration information; single connection configuration information for establishing a connection with the target node; third parameter.
  • the configuration information of the terminal's mobility management is configured by the target node.
  • the method further includes:
  • the RRC reconfiguration completion message may carry integrity-protected Message Authentication Code-Integrity (MAC-I) or truncated MAC-I, or it may not carry MAC-I or Truncated MAC-I.
  • MAC-I Message Authentication Code-Integrity
  • the RRC reconfiguration completion message includes: MAC-I or truncated MAC-I.
  • the method further includes:
  • the random access request message may carry the MAC-I or the truncated MAC-I, or may not carry the MAC-I or the truncated MAC-I.
  • the MAC-I is obtained at least by calculation of the first security key (Key) or the third security key (Key_2).
  • the MAC-I uses the first security key (Key), the physical cell ID (PCI) of the source node, and the source node assigning the terminal to the terminal.
  • Key the first security key
  • PCI physical cell ID
  • ID the cell identifier
  • the MAC-I uses one of the third security key (Key_2), the PCI of the source node, the C-RNTI allocated by the source node to the terminal, and the cell ID of the target node. Term or multiple calculations.
  • the method further includes:
  • the single connection configuration complete message is encrypted and / or integrity protected by the first security key; or the single connection configuration complete message is encrypted and / or integrity protected by the third security key. .
  • the embodiments of the present disclosure are applicable to a security key update for mobility management using a dual connectivity architecture, improving communication reliability, and further supporting encryption and / or integrity protection functions for communication between a terminal and a target node.
  • an embodiment of the present disclosure further provides a processing method, and an execution body of the method may be a target node.
  • the specific steps are as follows:
  • Step 401 confirm the activation of the encryption and / or integrity protection function of the terminal according to one or more of the dual connection configuration completion message, the random access request message, and the single connection configuration completion message; or,
  • the terminal's encryption and / or integrity protection function is activated.
  • the one or more of the dual connection configuration completion message, the random access request message, and the single connection configuration completion message are used to confirm the encryption and / or integrity protection function of the terminal. Activation, including any of the following:
  • the dual connection configuration completion message When the dual connection configuration completion message is received from the source node, the activation of the encryption and / or integrity protection function of the terminal is confirmed, and the dual connection configuration completion message is encrypted by a first security key and / Or integrity protection;
  • the single connection configuration completion message When the single connection configuration completion message is received from the terminal, the activation of the terminal's encryption and / or integrity protection function is confirmed, and the single connection configuration completion message is encrypted by the first security key and / Or integrity protection;
  • the first security key is a security key used to connect the target node with the dual connection configuration information and the single connection configuration information.
  • the one or more of the dual connection configuration completion message, the random access request message, and the single connection configuration completion message are used to confirm the encryption and / or integrity protection function of the terminal. Activation, including:
  • the dual connection configuration complete message is received from the source node or the random access request message is received from the terminal, the activation of the encryption and / or integrity protection function based on the second security key is confirmed , The dual connection configuration complete message is encrypted and / or integrity protected by the second security key;
  • the single connection configuration completion message When the single connection configuration completion message is received from the terminal, the activation of the encryption and / or integrity protection function based on the third security key is confirmed, and the single connection configuration completion message passes the third security Encryption and / or integrity protection of keys;
  • the second security key is a security key used to connect the target node with the dual connection configuration information; and the third security key is a security key used to connect the target node with the single connection configuration information.
  • the MAC-I or truncated MAC-I carried in any one of the dual connection configuration complete message and the random access request message is used to confirm the encryption and / or integrity of the terminal.
  • Activation of protection functions including any of the following:
  • the MAC-I or truncated MAC-I carried in the dual-connection configuration completion message passes the verification of the first security key, confirm the encryption of the terminal and / Or activation of integrity protection functions;
  • the first security key is a security key used to connect the target node with dual connection configuration information and single connection configuration information
  • the third security key is a connection to the target node using single connection configuration information. The security key used.
  • the embodiments of the present disclosure are applicable to a security key update for mobility management using a dual connectivity architecture, improving communication reliability, and further supporting encryption and / or integrity protection functions for communication between a terminal and a target node.
  • an embodiment of the present disclosure further provides a processing method, and an execution body of the method may be a source node.
  • the specific steps are as follows:
  • Step 501 Send a first parameter configured by the target node to the terminal, or send a second parameter configured by the source node and a third parameter configured by the target node;
  • the first parameter is used to calculate a first security key
  • the first security key is a security key used to connect the target node with the dual connection configuration information and the single connection configuration information, respectively;
  • the second parameter is used to calculate a second security key, and the second security key is a security key used to connect to the target node by applying the dual connection configuration information;
  • the third parameter is used to calculate a third security key, and the third security key is a security key used to connect to the target node by applying single connection configuration information.
  • sending the first parameter configured by the target node to the terminal, or sending the second parameter configured by the source node and the third parameter configured by the target node includes:
  • the RRC reconfiguration message includes: configuration information of the terminal's mobility management, and configuration information of the terminal's mobility management includes at least: a first parameter configured by the target node Or the configuration information of the terminal's mobility management includes at least: a second parameter configured by the source node and a third parameter configured by the target node.
  • the method further includes:
  • a MAC-I or a truncated MAC-I is obtained from the RRC reconfiguration completion message; and a dual connection configuration completion message is sent to the target node, where the dual connection configuration completion message is Including: the MAC-I or truncated MAC-I;
  • the MAC-I is obtained through calculation of the first security key or the third security key.
  • the MAC-I uses the first security key (Key), the physical cell ID (PCI) of the source node, and the source node assigning the terminal to the terminal.
  • Key the first security key
  • PCI physical cell ID
  • ID the cell identifier
  • the MAC-I uses one of the third security key (Key_2), the PCI of the source node, the C-RNTI allocated by the source node to the terminal, and the cell ID of the target node. Term or multiple calculations.
  • the method further includes:
  • the configuration information of the terminal's mobility management further includes one or more of the following:
  • Dual-connection configuration information for establishing a connection with the source node and the target node
  • the first security key is the first security key
  • the embodiments of the present disclosure are applicable to a security key update for mobility management using a dual connectivity architecture, improving communication reliability, and further supporting encryption and / or integrity protection functions for communication between a terminal and a target node.
  • an embodiment of the present disclosure further provides a processing method, and an execution body of the method may be a target node.
  • the specific steps are as follows:
  • Step 601 Send a first parameter configured by the target node or a third parameter configured by the target node to a source node;
  • the first parameter is used to calculate a first security key
  • the first security key is a security key used to connect the target node with the dual connection configuration information and the single connection configuration information, respectively;
  • the third parameter is used to calculate a third security key, and the third security key is a security key used to connect to the target node by applying single connection configuration information.
  • the sending the first parameter configured by the target node or the third parameter configured by the target node to the source node includes:
  • the configuration information of mobility management of the terminal includes: a first parameter configured by the target node or a third parameter configured by the target node.
  • the configuration information of the terminal's mobility management further includes one or more of the following:
  • Dual-connection configuration information for establishing a connection with the source node and the target node
  • the first security key is the first security key
  • the method further includes:
  • the terminal's encryption and / or integrity protection function is activated.
  • the one or more of the dual connection configuration completion message, the random access request message, and the single connection configuration completion message are used to confirm the encryption and / or integrity protection function of the terminal. Activation, including any of the following:
  • the dual connection configuration completion message When the dual connection configuration completion message is received from the source node, the activation of the encryption and / or integrity protection function of the terminal is confirmed, and the dual connection configuration completion message is encrypted by a first security key and / Or integrity protection;
  • the single connection configuration completion message When the single connection configuration completion message is received from the terminal, the activation of the terminal's encryption and / or integrity protection function is confirmed, and the single connection configuration completion message is encrypted by the first security key and / Or integrity protection;
  • the first security key is a security key used to connect the target node with the dual connection configuration information and the single connection configuration information.
  • the one or more of the dual connection configuration completion message, the random access request message, and the single connection configuration completion message are used to confirm the encryption and / or integrity protection function of the terminal. Activation, including:
  • the dual connection configuration complete message is received from the source node or the random access request message is received from the terminal, the activation of the encryption and / or integrity protection function based on the second security key is confirmed , The dual connection configuration complete message is encrypted and / or integrity protected by the second security key;
  • the single connection configuration completion message When the single connection configuration completion message is received from the terminal, the activation of the encryption and / or integrity protection function based on the third security key is confirmed, and the single connection configuration completion message passes the third security Encryption and / or integrity protection of keys;
  • the second security key is a security key used to connect the target node with the dual connection configuration information; and the third security key is a security key used to connect the target node with the single connection configuration information.
  • the MAC-I or truncated MAC-I carried in any one of the dual connection configuration complete message and the random access request message is used to confirm the encryption and / or integrity of the terminal.
  • Activation of protection functions including any of the following:
  • the MAC-I or truncated MAC-I carried in the dual-connection configuration completion message passes the verification of the first security key, confirm the encryption of the terminal and / Or activation of integrity protection functions;
  • the first security key is a security key used to connect the target node with dual connection configuration information and single connection configuration information
  • the third security key is a connection to the target node using single connection configuration information. The security key used.
  • the embodiments of the present disclosure are applicable to a security key update for mobility management using a dual connectivity architecture, improving communication reliability, and further supporting encryption and / or integrity protection functions for communication between a terminal and a target node.
  • Example 1 two sets of configuration information are used to connect the security key (Key) used by the target node to be assigned by the target node.
  • the target node uses any of the dual connection configuration complete message, random access request, and single connection configuration complete message. A confirmation that the terminal's encryption function and / or integrity protection function is activated.
  • the two sets of configuration information include: dual connection configuration (dcConfig) information and single connection configuration (targetConfig) information. See Figure 7 for specific steps:
  • Step 1 The source node sends a mobility management request message to the target node.
  • the mobility management request information may be a handover request, and the mobility management request information includes: the security capability information of the terminal, where the security capability information of the terminal may be one or more of the following: a supported user plane (User Plane, UP ) Encryption algorithm, UP integrity protection algorithm, supported control plane radio resource control (Radio Resource Control, RRC) encryption algorithm, RRC integrity protection algorithm.
  • UP User Plane
  • RRC Radio Resource Control
  • Step 2 According to the mobility management request information in step 1, the target node generates configuration information for mobility management of the terminal, and sends the configuration information for mobility management of the terminal to the source node.
  • the configuration information of the terminal's mobility management may be a handover command, where the configuration information of the terminal's mobility management includes:
  • Dual connection configuration (dcConfig) information for maintaining the connection between the source node and the target node at the same time. It can be understood that the dual-connection configuration information is only temporarily used for the terminal to maintain the connection between the source node and the target node at the same time during the mobility process.
  • TargetConfig Single connection configuration
  • Step 3 The source node sends the configuration information of the mobility management of some terminals to the terminal in step 2, for example, the configuration information of the mobility management of some terminals is sent to the terminal through an RRC reconfiguration message.
  • step 2 the content other than "(3) applying the dual connection configuration information and the single connection configuration information to the security node (Key) used to connect with the target node" is sent to the terminal.
  • the security key (Key) cannot be sent in the air interface, and the terminal can derive the security key (Key) through the counter (Counter).
  • the terminal After receiving the RRC reconfiguration message, the terminal can perform one or more of the following actions:
  • Step 4 The terminal sends an RRC reconfiguration complete message to the source node.
  • Step 5 After the completion of step 4, the source node sends a dual connection configuration completion message to the target node. If the target node successfully receives the dual connection configuration completion message, the target node confirms the activation of the encryption function and / or integrity protection function of the terminal. .
  • Step 6 After completion of step 4, the terminal initiates a random access request to the target node. If the target node successfully receives the terminal's random access request message, the target node confirms the activation of the terminal's encryption and / or integrity protection function .
  • Step 7 After step 6 is completed, the terminal performs the following actions:
  • TargetConfig single connection configuration
  • a single connection configuration (targetConfig) completion message is generated, and the single connection configuration (targetConfig) completion message is encrypted and / or integrity protected with a security key (Key).
  • a single connection configuration (targetConfig) completion message is sent to the target node. If the target node successfully receives the single connection configuration (targetConfig) completion message, the target node confirms the activation of the terminal's encryption and / or integrity protection function.
  • the target node confirms activation of the encryption function and / or integrity protection function of the terminal in step 5, step 6, and step 7 is satisfied, the target node confirms the encryption of the terminal and / Or activation of the integrity protection function.
  • Example 2 the security key (hereinafter referred to as Key_1) used to connect to the target node using the dual connection configuration (dcConfig) information is assigned by the source node, and the security key used to connect to the target node using the single connection configuration (targetConfig) information (Hereinafter referred to as Key_2) is assigned by the target node, and the target node confirms the activation of the encryption function and / or the integrity protection function of the terminal through any one of the dual connection configuration complete message, random access request, and single connection configuration complete message. See Figure 8 for specific steps:
  • Step 1 The source node sends a mobility management request message to the target node.
  • the mobility management request information may be a handover request, and the mobility management request information includes: the security capability information of the terminal and Key_1 used by the application to connect to the target node by using dual connection configuration (dcConfig) information.
  • dcConfig dual connection configuration
  • the security capability information of the terminal may be one or more of the following: a supported UP encryption algorithm, a UP integrity protection algorithm, a supported control plane RRC encryption algorithm, and an RRC integrity protection algorithm.
  • Step 2 According to the mobility management request information in step 1, the target node generates configuration information for mobility management of the terminal, and sends the configuration information for mobility management of the terminal to the source node.
  • the configuration information of the terminal's mobility management may be a handover command, where the configuration information of the terminal's mobility management includes:
  • Dual connection configuration (dcConfig) information for maintaining the connection between the source node and the target node at the same time. It can be understood that the dual-connection configuration information is only temporarily used for the terminal to maintain the connection between the source node and the target node at the same time during the mobility process.
  • TargetConfig Single connection configuration
  • Step 3 The source node sends the configuration information of the mobility management of the terminal in Step 2 and the input parameters derived from Key_1 (for example, the counter value (Counter_1)) to the terminal.
  • the configuration information and Counter_1 are sent to the terminal.
  • step 2 other than "(3) Key_2 for applying single connection configuration (targetConfig) information to connect with the target node" is sent to the terminal.
  • Key_2 cannot be sent in the air interface, and the terminal can derive Key2 through input parameters (Counter_2).
  • Key_1 is assigned by the source node
  • the input parameters for example, counter value (Counter_1)
  • Counter_1 the input parameters derived from the corresponding Key_1 are also configured by the source node, so it does not need to be reflected in step 2, but is completed in step Then, the part is sent to the terminal along with a part of the "configuration information of the terminal's mobility management" obtained in step 2.
  • the terminal may perform one or more of the following actions:
  • Step 4 The terminal sends an RRC reconfiguration complete message to the source node.
  • Step 5 After the completion of step 4, the source node sends a dual connection configuration (dcConfig) completion message to the target node. If the target node successfully receives the dual connection configuration (dcConfig) completion message, the target node confirms Key_1-based encryption and / or integrity Sexual protection is activated.
  • dcConfig dual connection configuration
  • Step 6 After completion of step 4, the terminal initiates a random access request to the target node. If the target node successfully receives the terminal's random access request message, the target node confirms that Key_1-based encryption and / or integrity protection functions are activated.
  • Step 7 After step 6 is completed, the terminal performs the following actions:
  • TargetConfig single connection configuration
  • TargetConfig Send the single connection configuration (targetConfig) completion message to the target node. If the target node successfully receives the single connection configuration (targetConfig) completion message, the target node confirms that the encryption and / or integrity protection function based on Key_2 is activated.
  • the target node confirms that the encryption and / or integrity protection function of the terminal is activation.
  • the target node verifies the encryption function and / or integrity of the terminal based on the MAC-I or truncated MAC-I verification carried in any one of the dual connection configuration complete message and random access request message. Activation of protective functions. See Figure 9 for specific steps:
  • Step 1 The source node sends a mobility management request message to the target node.
  • Step 2 According to the mobility management request information in step 1, the target node generates configuration information for mobility management of the terminal, and sends the configuration information for mobility management of the terminal to the source node.
  • Step 3 The source node sends the configuration information of the mobility management of some terminals to the terminal in step 2, for example, the configuration information of the mobility management of some terminals is sent to the terminal through an RRC reconfiguration message.
  • Step 4 The terminal sends an RRC reconfiguration completion message to the source node, and the RRC reconfiguration completion message includes the MAC-I or the truncated MAC-I.
  • MAC-I uses the key, the physical cell identifier (PCI) of the source node, the cell wireless network temporary identifier (C-RNTI) assigned by the source node to the terminal, and the target node's cell identifier. (Identification, ID) obtained by one or more calculations, the truncated MAC-I is a truncated form of MAC-I.
  • Step 5 The source node forwards the MAC-I or truncated MAC-I in step 4 to the target node through the dual connection configuration (dcConfig) completion message. If the target node uses the Key to pair the MAC-I or truncated MAC, -I pass, the target node confirms the activation of the terminal's encryption and / or integrity protection function.
  • dcConfig dual connection configuration
  • Step 6 After the completion of step 4, the terminal sends a random access request message to the target node, and the random access request message includes MAC-I or truncated MAC-I. If the target node uses the Key to MAC- I or truncated MAC-I integrity verification passes, and the target node confirms the activation of the terminal's encryption and / or integrity protection function.
  • the target node confirms activation of the encryption function and / or integrity protection function of the terminal in step 5, step 6, and step 7 is satisfied, the target node confirms the encryption of the terminal and / Or activation of the integrity protection function.
  • the target node confirms the encryption function and / or integrity of the terminal by using the MAC-I or truncated MAC-I carried by one of the dual connection configuration complete message and the random access request message. Activation of protective functions. See Figure 10 for specific steps:
  • Step 1 The source node sends a mobility management request message to the target node.
  • Step 2 According to the mobility management request information in step 1, the target node generates configuration information for mobility management of the terminal, and sends the configuration information for mobility management of the terminal to the source node.
  • Step 3 The source node sends the configuration information of the mobility management of some terminals in Step 2 and the input parameters (for example, the counter value (Counter_1)) derived from Key_1 to the terminal.
  • the input parameters for example, the counter value (Counter_1)
  • Step 4 The terminal sends an RRC reconfiguration completion message to the source node.
  • the RRC reconfiguration completion message includes: MAC-I or truncated MAC-I.
  • the MAC-I is obtained by one or more of Key_2, the PCI of the source node, the C-RNTI allocated by the source node to the terminal, and the cell ID of the target node.
  • the truncated MAC-I is a truncated form of MAC-I.
  • Step 5 The source node forwards the MAC-I or truncated MAC-I in step 4 to the target node through the dual connection configuration (dcConfig) completion message. If the target node successfully receives the dual connection configuration (dcConfig) completion message, and The target node passes the MAC-I or truncated MAC-I verification with the Key_2, and the target node confirms that the encryption and / or integrity protection function of the terminal is activated.
  • dcConfig dual connection configuration
  • Step 6 After step 4 is completed, the terminal initiates a random access request to the target node, and the random access request message includes a MAC-I or a truncated MAC-I. If the target node successfully receives the random access of the terminal, Incoming request message, and the target node passes MAC-I or truncated MAC-I integrity verification with the Key_2, the target node confirms that the terminal's encryption and / or integrity protection function is activated.
  • Examples 1 to 4 describe the scenario of switching based on the DC architecture. It can be understood that the embodiments of the present disclosure are not only applicable to the scenario of switching based on the DC architecture, but also applicable to SCG change, SCG deletion, and SCG addition of the DC architecture. Scenes.
  • the embodiment of the present disclosure also provides a terminal. Since the principle of the terminal to solve the problem is similar to the processing method in the embodiment of the present disclosure, the implementation of the terminal can refer to the implementation of the method, and the duplicated details will not be described again.
  • the terminal 1100 includes:
  • a first determining module 1101, configured to determine a first security key configured by a target node, where the first security key is a security key for applying dual connection configuration information and single connection configuration information to a target node; or,
  • the second determining module 1102 is configured to determine a second security key configured by the source node and a third security key configured by the target node, where the second security key is used for connection with the target node by applying the dual connection configuration information.
  • the third security key is a security key used by the single connection configuration information to connect to the target node.
  • the first determining module is further configured to receive a first parameter configured by the target node from the source node, where the first parameter is used to calculate the first security key. Key; calculating the first security key according to the first parameter.
  • the second determining module is further configured to receive, from the source node, a second parameter configured by the source node and a third parameter configured by the target node, wherein The second parameter is used to calculate the second security key, the third parameter is used to calculate the third security key; the second security key is calculated according to the second parameter; The third parameter is described, and the third security key is calculated.
  • the first parameter is carried in an RRC reconfiguration message sent by the source node, or the second parameter and the third parameter are carried in a message sent by the source node.
  • RRC reconfiguration message optionally, the first parameter is carried in an RRC reconfiguration message sent by the source node, or the second parameter and the third parameter are carried in a message sent by the source node.
  • the RRC reconfiguration message further carries one or more of the following:
  • Dual-connection configuration information for establishing a connection with the source node and the target node
  • the terminal further includes:
  • a first connection module configured to establish a connection with the target node and the source node according to the dual-connection configuration information
  • a first sending module is configured to send an RRC reconfiguration completion message to the source node in response to an RRC reconfiguration message or an RRC reconfiguration message.
  • the terminal further includes:
  • the second sending module is configured to send a random access request message to the target node after sending an RRC reconfiguration completion message to the source node in response to the RRC reconfiguration message or the RRC reconfiguration message.
  • the RRC reconfiguration completion message or the random access request message includes: integrity protection message authentication code MAC-I or truncated MAC-I;
  • the MAC-I is obtained at least through calculation of the first security key or the third security key.
  • a second connection module is configured to establish a connection with the target node according to the single connection configuration and generate a single connection after a random access process initiated to the target node is completed.
  • a third sending module configured to send the single connection configuration complete message to the target node
  • the single connection configuration complete message is encrypted and / or integrity protected by the first security key; or,
  • the single connection configuration complete message is encrypted and / or integrity protected by the third security key.
  • the terminal provided by the embodiment of the present disclosure can execute the foregoing method embodiments, and its implementation principles and technical effects are similar. This embodiment will not repeat them here.
  • the embodiment of the present disclosure also provides a target node. Since the principle of the problem solving method of the target node is similar to the processing method in the embodiment of the present disclosure, the implementation of the target node can refer to the implementation of the method, and the details are not described again.
  • the target node 1200 includes:
  • a first confirmation module 1201 configured to confirm activation of an encryption and / or integrity protection function of a terminal according to one or more of a dual connection configuration completion message, a random access request message, and a single connection configuration completion message; or,
  • the second confirmation module 1202 is configured to confirm activation of the encryption and / or integrity protection function of the terminal according to the MAC-I or the truncated MAC-I carried in any one of the dual connection configuration completion message and the random access request message. .
  • the first confirmation module is further configured to execute any one of the following:
  • the dual connection configuration completion message When the dual connection configuration completion message is received from the source node, the activation of the encryption and / or integrity protection function of the terminal is confirmed, and the dual connection configuration completion message is encrypted by a first security key and / Or integrity protection;
  • the single connection configuration completion message When the single connection configuration completion message is received from the terminal, the activation of the terminal's encryption and / or integrity protection function is confirmed, and the single connection configuration completion message is encrypted by the first security key and / Or integrity protection;
  • the first security key is a security key used to connect the target node with the dual connection configuration information and the single connection configuration information.
  • the first confirmation module is further configured to:
  • the dual connection configuration complete message is received from the source node or the random access request message is received from the terminal, the activation of the encryption and / or integrity protection function based on the second security key is confirmed , The dual connection configuration complete message is encrypted and / or integrity protected by the second security key;
  • the single connection configuration completion message When the single connection configuration completion message is received from the terminal, the activation of the encryption and / or integrity protection function based on the third security key is confirmed, and the single connection configuration completion message passes the third security Encryption and / or integrity protection of keys;
  • the second security key is a security key used to connect the target node with the dual connection configuration information; and the third security key is a security key used to connect the target node with the single connection configuration information.
  • the second confirmation module is further configured to execute any one of the following:
  • the MAC-I or truncated MAC-I carried in the dual-connection configuration completion message passes the verification of the first security key, confirm the encryption of the terminal and / Or activation of integrity protection functions;
  • the first security key is a security key used to connect the target node with the dual connection configuration information and the single connection configuration information
  • the third security key is used to connect the target node with the single connection configuration.
  • the target node provided by the embodiment of the present disclosure can execute the foregoing method embodiments, and its implementation principles and technical effects are similar, which will not be repeated here in this embodiment.
  • a source node is also provided in the embodiment of the present disclosure. Since the principle of the source node to solve the problem is similar to the processing method in the embodiment of the present disclosure, the implementation of the source node can refer to the implementation of the method, and the duplicates are not described again.
  • the source node 1300 includes:
  • a fifth sending module 1301, configured to send a first parameter configured by the target node to the terminal, or send a second parameter configured by the source node and a third parameter configured by the target node;
  • the first parameter is used to calculate a first security key
  • the first security key is a security key used to connect the target node with the dual connection configuration information and the single connection configuration information, respectively;
  • the second parameter is used to calculate a second security key, and the second security key is a security key used to connect to the target node by applying the dual connection configuration information;
  • the third parameter is used to calculate a third security key, and the third security key is a security key used to connect to the target node by applying single connection configuration information.
  • the fifth sending module 1301 is further configured to send an RRC reconfiguration message to the terminal, where the RRC reconfiguration message includes: configuration information of mobility management of the terminal, and the terminal
  • the configuration information of mobility management includes at least: a first parameter configured by a target node; or the configuration information of mobility management of the terminal includes at least: a second parameter configured by the source node and a configuration by the target node
  • the source node further includes:
  • a sixth sending module is configured to send a dual connection configuration completion message to the target node after receiving an RRC reconfiguration completion message in response to the RRC reconfiguration message.
  • the sixth sending module is further configured to: obtain a MAC-I or a truncated MAC-I from the RRC reconfiguration completion message; and send a dual connection configuration completion to the target node Message, the dual connection configuration completion message includes: the MAC-I or truncated MAC-I;
  • the MAC-I is obtained at least by calculation of the first security key or the third security key.
  • the source node further includes: a third receiving module, configured to receive configuration information of mobility management of the terminal from the target node.
  • the configuration information of the terminal's mobility management further includes one or more of the following:
  • Dual-connection configuration information for establishing a connection with the source node and the target node
  • the first security key is the first security key
  • the source node provided in the embodiment of the present disclosure can execute the foregoing method embodiments, and its implementation principles and technical effects are similar. This embodiment will not repeat them here.
  • the embodiment of the present disclosure also provides a target node. Since the principle of the problem solving method of the target node is similar to the processing method in the embodiment of the present disclosure, the implementation of the target node can refer to the implementation of the method, and the details are not described again.
  • the target node 1400 includes:
  • a seventh sending module 1401 is configured to send a first parameter configured by the target node or a third parameter configured by the target node to a source node;
  • the first parameter is used to calculate a first security key
  • the first security key is a security key used to connect the target node with the dual connection configuration information and the single connection configuration information, respectively;
  • the third parameter is used to calculate a third security key, and the third security key is a security key used to connect to the target node by applying single connection configuration information.
  • the sending the first parameter configured by the target node or the third parameter configured by the target node to the source node includes:
  • the configuration information of mobility management of the terminal includes: a first parameter configured by the target node or a third parameter configured by the target node.
  • the configuration information of the terminal's mobility management further includes one or more of the following:
  • Dual-connection configuration information for establishing a connection with the source node and the target node
  • the first security key is the first security key
  • the target node further includes:
  • a third confirmation module configured to confirm activation of an encryption and / or integrity protection function of the terminal according to one or more of a dual connection configuration completion message, a random access request message, and a single connection configuration completion message; or,
  • a fourth confirmation module is configured to confirm activation of the encryption and / or integrity protection function of the terminal according to the MAC-I or the truncated MAC-I carried in any of the dual connectivity configuration completion message and the random access request message.
  • the target node provided by the embodiment of the present disclosure can execute the foregoing method embodiments, and its implementation principles and technical effects are similar, which will not be repeated here in this embodiment.
  • the terminal 1500 shown in FIG. 15 includes: at least one processor 1501, a memory 1502, at least one network interface 1504, and a user interface 1503.
  • the various components in the terminal 1500 are coupled together through a bus system 1505.
  • the bus system 1505 is used to implement connection and communication between these components.
  • the bus system 1505 includes a power bus, a control bus, and a status signal bus in addition to the data bus.
  • various buses are marked as the bus system 1505 in FIG. 15.
  • the user interface 1503 may include a display, a keyboard, or a pointing device (for example, a mouse, a trackball, a touch pad, or a touch screen).
  • a pointing device for example, a mouse, a trackball, a touch pad, or a touch screen.
  • the memory 1502 in the embodiment of the present disclosure may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memory.
  • the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), and an electronic memory. Erase programmable read-only memory (EPROM, EEPROM) or flash memory.
  • the volatile memory may be Random Access Memory (RAM), which is used as an external cache.
  • RAM Static Random Access Memory
  • DRAM Dynamic Random Access Memory
  • Synchronous Dynamic Random Access Memory Synchronous Dynamic Random Access Memory
  • SDRAM double data rate synchronous dynamic random access memory
  • Double SDRAM, DDRSDRAM enhanced synchronous dynamic random access memory
  • Enhanced SDRAM, ESDRAM synchronous connection dynamic random access memory
  • Synchronous DRAM synchronous dynamic random access memory
  • Synchlink RAM SLDRAM
  • Direct RAMbus RAM Direct RAMbus RAM, DRRAM
  • the memory 1502 of the systems and methods described in embodiments of the present disclosure is intended to include, but is not limited to, these and any other suitable types of memory.
  • the memory 1502 stores the following elements, executable modules or data structures, or their subsets, or their extended sets: an operating system 15021 and an application program 15022.
  • the operating system 15021 includes various system programs, such as a framework layer, a core library layer, and a driver layer, etc., for implementing various basic services and processing hardware-based tasks.
  • the application program 15022 includes various application programs, such as a media player (Player), a browser (Browser), and the like, and is used to implement various application services.
  • a program for implementing the method of the embodiment of the present disclosure may be included in the application program 15022.
  • the program or instruction stored in the application 15022 can be implemented, and the following steps are implemented when executed: determining the first security password configured by the target node Key, where the first security key is a security key used to connect the target node with the dual connection configuration information and the single connection configuration information, respectively; or determining a second security key configured by the source node and a security key configured by the target node A third security key, wherein the second security key is a security key used to connect to the target node by applying the dual connection configuration information; and the third security key is used to connect to the target node by applying the single connection configuration information.
  • Security key determining the first security password configured by the target node Key, where the first security key is a security key used to connect the target node with the dual connection configuration information and the single connection configuration information, respectively; or determining a second security key configured by the source node and a security key configured by the target node A third security key, wherein the second security key is a security key used to connect to the target node by applying the dual connection configuration information
  • the terminal provided by the embodiment of the present disclosure can execute the foregoing method embodiments, and its implementation principles and technical effects are similar. This embodiment will not repeat them here.
  • FIG. 16 is a structural diagram of a network device applied in an embodiment of the present disclosure.
  • the network device 1600 includes a processor 1601, a transceiver 1602, a memory 1603, and a bus interface, where:
  • the network device 1600 further includes a program stored in the memory 1603 and executable on the processor 1601.
  • the program When the program is executed by the processor 1601, the following steps are implemented: a message is completed according to the dual connection configuration, One or more of an access request message and a single connection configuration complete message to confirm activation of the terminal's encryption and / or integrity protection function; or, based on any of the dual connection configuration complete message and random access request message
  • the carried MAC-I or truncated MAC-I confirms the activation of the terminal's encryption and / or integrity protection function.
  • the network device 1600 further includes a program stored in the memory 1603 and executable on the processor 1601.
  • the program executes by the processor 1601 to implement the following steps: sending to the terminal the configuration by the target node Or a second parameter configured by the source node and a third parameter configured by the target node; wherein the first parameter is used to calculate a first security key, and the first security
  • the key is a security key used to apply the dual connection configuration information and the single connection configuration information to the target node respectively; the second parameter is used to calculate a second security key, and the second security key is to apply the dual connection configuration
  • the third parameter is used to calculate a third security key, and the third security key is a security key used to connect to the target node by applying single connection configuration information.
  • the network device 1600 further includes: a program stored in the memory 1603 and executable on the processor 1601.
  • the program executes the processor 1601 to implement the following steps: sending to the source node the The first parameter configured by the target node or the third parameter configured by the target node; wherein the first parameter is used to calculate a first security key, and the first security key is the application of dual connection configuration information and
  • the single connection configuration information is a security key used to connect with the target node; the third parameter is used to calculate a third security key, and the third security key is the security used by the single connection configuration information to connect to the target node Key.
  • the bus architecture may include any number of interconnected buses and bridges, and one or more processors specifically represented by the processor 1601 and various circuits of the memory represented by the memory 1603 are linked together.
  • the bus architecture can also link various other circuits such as peripherals, voltage regulators, and power management circuits, which are well known in the art, so they are not described further herein.
  • the bus interface provides an interface.
  • the transceiver 1602 may be multiple elements, including a transmitter and a receiver, providing a unit for communicating with various other devices over a transmission medium.
  • the processor 1601 is responsible for managing the bus architecture and general processing, and the memory 1603 can store data used by the processor 1601 when performing operations.
  • the network device provided by the embodiment of the present disclosure can execute the foregoing method embodiments, and the implementation principles and technical effects thereof are similar. This embodiment is not described herein again.
  • the steps of the method or algorithm described in connection with the present disclosure may be implemented in a hardware manner, or may be implemented in a manner that a processor executes software instructions.
  • the software instructions may be composed of corresponding software modules, and the software modules may be stored in RAM, flash memory, ROM, EPROM, EEPROM, registers, hard disk, mobile hard disk, read-only optical disk, or any other form of storage medium known in the art.
  • An exemplary storage medium is coupled to the processor such that the processor can read information from, and write information to, the storage medium.
  • the storage medium may also be an integral part of the processor.
  • the processor and the storage medium may reside in an ASIC.
  • the ASIC can be located in a core network interface device.
  • the processor and the storage medium can also exist as discrete components in the core network interface device.
  • the functions described in this disclosure may be implemented in hardware, software, firmware, or any combination thereof.
  • the functions may be stored on a computer-readable medium or transmitted as one or more instructions or code on a computer-readable medium.
  • Computer-readable media includes computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another.
  • a storage media may be any available media that can be accessed by a general purpose or special purpose computer.
  • the embodiments of the present disclosure may be provided as a method, a system, or a computer program product. Therefore, the embodiments of the present disclosure may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the embodiments of the present disclosure may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
  • computer-usable storage media including but not limited to disk storage, CD-ROM, optical storage, etc.
  • Embodiments of the present disclosure are described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present disclosure. It should be understood that each process and / or block in the flowcharts and / or block diagrams, and combinations of processes and / or blocks in the flowcharts and / or block diagrams can be implemented by computer program instructions.
  • These computer program instructions may be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing device to produce a machine, so that the instructions generated by the processor of the computer or other programmable data processing device are used to generate instructions Means for implementing the functions specified in one or more flowcharts and / or one or more blocks of the block diagrams.
  • These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to work in a particular manner such that the instructions stored in the computer-readable memory produce a manufactured article including an instruction device, the instructions
  • the device implements the functions specified in one or more flowcharts and / or one or more blocks of the block diagram.
  • These computer program instructions can also be loaded on a computer or other programmable data processing device, so that a series of steps can be performed on the computer or other programmable device to produce a computer-implemented process, which can be executed on the computer or other programmable device.
  • the instructions provide steps for implementing the functions specified in one or more flowcharts and / or one or more blocks of the block diagrams.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本公开实施例提供一种处理方法和设备。所述方法包括:确定由目标节点配置的第一安全密钥,其中所述第一安全密钥为分别应用双连接配置信息和单连接配置信息与目标节点连接使用的安全密钥;或者确定由源节点配置的第二安全密钥和由目标节点配置的第三安全密钥,其中所述第二安全密钥为应用双连接配置信息与目标节点连接使用的安全密钥;所述第三安全密钥为应用单连接配置信息与所述目标节点连接使用的安全密钥。

Description

处理方法和设备
相关申请的交叉引用
本申请主张在2018年9月12日在中国提交的中国专利申请No.201811064727.0的优先权,其全部内容通过引用包含于此。
技术领域
本公开实施例涉及通信技术领域,具体涉及一种处理方法和设备。
背景技术
为了提高通信服务质量,引入了以下通信技术:
(1)基于双连接(Dual Connectivity,DC)的移动性:
在第五代移动通信技术(Fifth-generation,5G)系统中,由于要满足0ms的移动性过程的中断延时,因此需要终端在移动的过程中同时在源节点和目标节点有连接进行数据的收发。要在源节点和目标节点同时保持数据连接,一种数据传输方式是采用DC的架构。
双连接终端的服务基站中有一个为主基站(Master Node,MN),一个为辅基站(Secondary Node,SN)。MN的所有服务小区统称为主服务小区群组(Master Cell Group,MCG),SN的所有服务小区统称为辅服务小区群组(Secondary Cell Group,SCG)。
(2)DC安全机制简介:
在相关技术中的DC机制中,终端与SN通信所使用的基站密钥(Key of SN,简写为K SN)由MN分配,每一次K SN的更新关联一个对应的SN计数值(SN Counter)。如图1所示,终端将基于最新获得的K SN发起到SN的随机接入信道(Random Access Channel,RACH)过程,SN通过接收终端的随机接入请求确认SN安全参数激活。
根据相关技术中的安全机制,当终端采用DC连接时,终端与目标节点(例如:SN)通信的安全密钥由源节点(例如:MN)分配,并且通过RACH过程确认目标节点安全参数的激活。
在采用DC的移动性管理的方式时,网络侧会给终端配置两套连接配置,连接配置1用于在移动性过程中终端同时与源节点和目标节点建立连接,连接配置2用于在移动性过程后终端与目标节点建立连接。
然而,相关技术中的安全机制仅能解决存在连接配置1时的安全更新方法,当网络存在两套连接配置如何分配目标节点使用的安全性秘钥尚没有解决方案。
发明内容
本公开实施例的一个目的在于提供一种处理方法和设备,解决在采用双连接的移动性管理过程中,当网络存在两套连接配置时,如何分配目标节点使用的安全秘钥的问题。
第一方面,本公开实施例提供一种处理方法,应用于终端,所述方法包括:
确定由目标节点配置的第一安全密钥,其中所述第一安全密钥为分别应用双连接配置信息和单连接配置信息与目标节点连接使用的安全密钥;或者
确定由源节点配置的第二安全密钥和由目标节点配置的第三安全密钥,其中所述第二安全密钥为应用双连接配置信息与目标节点连接使用的安全密钥;所述第三安全密钥为应用单连接配置信息与所述目标节点连接使用的安全密钥。
第二方面,本公开实施例还提供一种处理方法,应用于目标节点,所述方法包括:
根据双连接配置完成消息、随机接入请求消息、单连接配置完成消息中的一项或多项,确认终端的加密和/或完整性保护功能的激活;或者,
根据双连接配置完成消息和随机接入请求消息中任一项携带的MAC-I或截短的MAC-I,确认终端的加密和/或完整性保护功能的激活。
第三方面,本公开实施例还提供了一种处理方法,应用于源节点,所述方法包括:
向终端发送由目标节点配置的第一参数,或者发送由所述源节点配置的第二参数和由所述目标节点配置的第三参数;
其中,所述第一参数用于计算第一安全密钥,所述第一安全密钥为分别应用双连接配置信息和单连接配置信息与目标节点连接使用的安全密钥;
所述第二参数用于计算第二安全密钥,所述第二安全密钥为应用双连接配置信息与目标节点连接使用的安全密钥;
所述第三参数用于计算第三安全密钥,所述第三安全密钥为应用单连接配置信息与所述目标节点连接使用的安全密钥。
第四方面,本公开实施例还提供了一种处理方法,应用于目标节点,所述方法包括:
向源节点发送由所述目标节点配置的第一参数或者由所述目标节点配置的第三参数;
其中,所述第一参数用于计算第一安全密钥,所述第一安全密钥为分别应用双连接配置信息和单连接配置信息与目标节点连接使用的安全密钥;
所述第三参数用于计算第三安全密钥,所述第三安全密钥为应用单连接配置信息与所述目标节点连接使用的安全密钥。
第五方面,本公开实施例还提供了一种终端,包括:
第一确定模块,用于确定由目标节点配置的第一安全密钥,其中所述第一安全密钥为分别应用双连接配置信息和单连接配置信息与目标节点连接使用的安全密钥;或者,
第二确定模块,用于确定由源节点配置的第二安全密钥和由目标节点配置的第三安全密钥,其中所述第二安全密钥为应用双连接配置信息与目标节点连接使用的安全密钥;所述第三安全密钥为应用单连接配置信息与所述目标节点连接使用的安全密钥。
第六方面,本公开实施例还提供了一种目标节点,包括:
第一确认模块,用于根据双连接配置完成消息、随机接入请求消息、单连接配置完成消息中的一项或多项,确认终端的加密和/或完整性保护功能的激活;或者,
第二确认模块,用于根据双连接配置完成消息和随机接入请求消息中任一项携带的MAC-I或截短的MAC-I,确认终端的加密和/或完整性保护功能的激活。
第七方面,本公开实施例还提供了一种源节点,包括:
第五发送模块,用于向终端发送由目标节点配置的第一参数,或者发送由所述源节点配置的第二参数和由所述目标节点配置的第三参数;
其中,所述第一参数用于计算第一安全密钥,所述第一安全密钥为分别应用双连接配置信息和单连接配置信息与目标节点连接使用的安全密钥;
所述第二参数用于计算第二安全密钥,所述第二安全密钥为应用双连接配置信息与目标节点连接使用的安全密钥;
所述第三参数用于计算第三安全密钥,所述第三安全密钥为应用单连接配置信息与所述目标节点连接使用的安全密钥。
第八方面,本公开实施例还提供了一种目标节点,包括:
第七发送模块,用于向源节点发送由所述目标节点配置的第一参数或者由所述目标节点配置的第三参数;
其中,所述第一参数用于计算第一安全密钥,所述第一安全密钥为分别应用双连接配置信息和单连接配置信息与目标节点连接使用的安全密钥;
所述第三参数用于计算第三安全密钥,所述第三安全密钥为应用单连接配置信息与所述目标节点连接使用的安全密钥。
第九方面,本公开实施例还提供了一种终端,包括:处理器、存储器及存储在所述存储器上并可在所述处理器上运行的程序,所述程序被所述处理器执行时实现如第一方面所述的处理方法的步骤。
第十方面,本公开实施例还提供了一种网络设备,包括:处理器、存储器及存储在所述存储器上并可在所述处理器上运行的程序,所述程序被所述处理器执行时实现如第二方面、第三方面或第四方面所述的处理方法的步骤。
第十一方面,本公开实施例还提供了一种计算机可读存储介质,所述计算机可读存储介质上存储有计算机程序,所述计算机程序被处理器执行时实现如第一方面、第二方面、第三方面或第四方面所述的处理方法的步骤。
在本公开实施例中,当网络存在两套连接配置时,可以确定目标节点使用的安全秘钥,实现在双连接架构中进行移动性管理的安全密钥更新,确保通信的可靠性。
附图说明
通过阅读下文优选实施方式的详细描述,各种其他的优点和益处对于本领域普通技术人员将变得清楚明了。附图仅用于示出优选实施方式的目的,而并不认为是对本公开的限制。而且在整个附图中,用相同的参考符号表示相同的部件。在附图中:
图1为相关技术中的双连接安全机制流程;
图2为本公开实施例的无线通信系统的架构示意图;
图3为本公开实施例的处理方法的流程图之一;
图4为本公开实施例的处理方法的流程图之二;
图5为本公开实施例的处理方法的流程图之三;
图6为本公开实施例的处理方法的流程图之四;
图7为本公开实施例的处理方法的流程图之五;
图8为本公开实施例的处理方法的流程图之六;
图9为本公开实施例的处理方法的流程图之七;
图10为本公开实施例的处理方法的流程图之八;
图11为本公开实施例的终端的结构图之一;
图12为本公开实施例的目标节点的结构图之一;
图13为本公开实施例的源节点的结构图;
图14为本公开实施例的目标节点的结构图之二;
图15为本公开实施例的终端的结构图之二;
图16为本公开实施例的网络设备的结构图。
具体实施方式
下面将结合本公开实施例中的附图,对本公开实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例是本公开一部分实施例,而不是全部的实施例。基于本公开中的实施例,本领域普通技术人员在没有作出创造性劳动前提下所获得的所有其他实施例,都属于本公开保护的范围。
本申请的说明书和权利要求书中的术语“包括”以及它的任何变形,意图在于覆盖不排他的包含,例如,包含了一系列步骤或单元的过程、方法、系 统、产品或设备不必限于清楚地列出的那些步骤或单元,而是可包括没有清楚地列出的或对于这些过程、方法、产品或设备固有的其它步骤或单元。此外,说明书以及权利要求中使用“和/或”表示所连接对象的至少其中之一,例如A和/或B,表示包含单独A,单独B,以及A和B都存在三种情况。
在本公开实施例中,“示例性的”或者“例如”等词用于表示作例子、例证或说明。本公开实施例中被描述为“示例性的”或者“例如”的任何实施例或设计方案不应被解释为比其它实施例或设计方案更优选或更具优势。确切而言,使用“示例性的”或者“例如”等词旨在以具体方式呈现相关概念。
下面结合附图介绍本公开的实施例。本公开实施例提供的处理方法和设备可以应用于无线通信系统中。该无线通信系统可以为采用5G系统,或者演进型长期演进(Evolved Long Term Evolution,eLTE)系统,或者后续演进通信系统。参考图2,为本公开实施例提供的一种无线通信系统的架构示意图。如图2所示,该无线通信系统可以包括:第一网络设备20、第二网络设备21和用户设备(User Equipment,UE),例如,用户设备记做UE22,UE22可以与第一网络设备20和第二网络设备21通信(传输信令或传输数据)。在实际应用中上述各个设备之间的连接可以为无线连接,为了方便直观地表示各个设备之间的连接关系,图2中采用实线示意。
需要说明的是,上述通信系统可以包括多个UE22,第一网络设备20和第二网络设备22可以与多个UE22通信。
本公开实施例提供的第一网络设备20、第二网络设备21可以为基站,该基站可以为通常所用的基站,也可以为演进型基站(evolved Node Base station,eNB),还可以为5G系统中的网络设备(例如,下一代基站(next generation Node Base station,gNB)或发送和接收点(Transmission and Reception Point,TRP))等设备。
本公开实施例提供的用户设备可以为手机、平板电脑、笔记本电脑、超级移动个人计算机(Ultra-Mobile Personal Computer,UMPC)、上网本或者个人数字助理(Personal Digital Assistant,PDA)等。
参见图3,本公开实施例提供一种处理方法,该方法的执行主体可以为终端,具体步骤如下:
步骤301:确定由目标节点配置的第一安全密钥,其中所述第一安全密钥为分别应用双连接配置信息和单连接配置信息与目标节点连接使用的安全密钥;或者,
确定由源节点配置的第二安全密钥和由目标节点配置的第三安全密钥,其中所述第二安全密钥为应用双连接配置信息与目标节点连接使用的安全密钥;所述第三安全密钥为应用单连接配置信息与所述目标节点连接使用的安全密钥。
其中,第一安全密钥可以称为Key,第二安全密钥可以称为Key_1,第三安全密钥可以称为Key_2。
本公开实施例中,可选地,确定由目标节点配置的第一安全密钥,包括:
从源节点接收由所述目标节点配置的第一参数,所述第一参数用于计算所述第一安全密钥;根据所述第一参数,计算所述第一安全密钥。
其中,第一参数可以是用于导出第一安全密钥(Key)的输入参数,例如:计数值(Counter)。
本公开实施例中,可选地,确定由源节点配置的第二安全密钥和目标节点配置的第三安全密钥,包括:
从所述源节点接收由源节点配置的第二参数和由所述目标节点配置的第三参数,其中,所述第二参数用于计算所述第二安全密钥,所述第三参数用于计算所述第三安全密钥;根据所述第二参数,计算所述第二安全密钥,以及根据所述第三参数,计算所述第三安全密钥。
其中,第二参数可以是用于导出第二安全密钥(Key_1)的输入参数,例如:计数值(Counter_1)。
其中,第三参数可以是用于导出第三安全密钥(Key_2)的输入参数,例如:计数值(Counter_2)。
本公开实施例中,可选地,第一参数携带在由源节点发送的无线资源控制(Radio Resource Control,RRC)重配置消息中,或者第二参数和所述第三参数携带在由源节点发送的RRC重配置消息中。
本公开实施例中,可选地,所述RRC重配置消息中还携带有以下一项或多项:
用于与所述源节点和所述目标节点建立连接的双连接配置信息;
用于与所述目标节点建立连接的单连接配置信息。
进一步地,可选地,所述RRC重配置消息中携带部分的终端的移动性管理的配置信息,该部分的终端的移动性管理的配置信息包括:用于与所述源节点和所述目标节点建立连接的双连接配置信息;用于与所述目标节点建立连接的单连接配置信息;第一参数。
或者,所述RRC重配置消息中携带部分的终端的移动性管理的配置信息,该部分的终端的移动性管理的配置信息包括:用于与所述源节点和所述目标节点建立连接的双连接配置信息;用于与所述目标节点建立连接的单连接配置信息;第三参数。
其中,终端的移动性管理的配置信息是由目标节点配置的。
本公开实施例中,可选地,在所述接收到RRC重配置消息之后,所述方法还包括:
根据所述双连接配置信息建立与所述目标节点和所述源节点的连接;
向所述源节点发送用于响应所述RRC重配置消息的RRC重配置完成消息。
可以理解的是,RRC重配置完成消息中可以携带完整性保护的消息认证码(Message Authentication Code-Integrity,MAC-I)或截短(short)的MAC-I,也可以不携带MAC-I或截短的MAC-I。
本公开实施例中,可选地,RRC重配置完成消息包括:MAC-I或截短的MAC-I。
本公开实施例中,可选地,所述方法还包括:
在向所述源节点发送用于响应所述RRC重配置消息的RRC重配置完成消息之后,向所述目标节点发送随机接入请求消息;
可以理解的是,随机接入请求消息中可以携带MAC-I或截短的MAC-I,也可以不携带MAC-I或截短的MAC-I。
其中,所述MAC-I至少通过所述第一安全密钥(Key)或所述第三安全密钥(Key_2)计算获得。
进一步地,可选地,所述MAC-I通过所述第一安全密钥(Key)、所述源节点的物理小区标识(Physical Cell ID,PCI)、所述源节点给所述终端分配的小区无线网络临时标识(Cell Radio Network Temporary Identifier,C-RNTI)、所述目标节点的小区标识(ID)中的一项或多项计算获得;
或者,所述MAC-I通过所述第三安全密钥(Key_2)、所述源节点的PCI、所述源节点给所述终端分配的C-RNTI、所述目标节点的小区ID中的一项或多项计算获得。
本公开实施例中,可选地,在向所述目标节点发起的随机接入过程完成之后,所述方法还包括:
根据所述单连接配置建立与所述目标节点的连接,并生成单连接配置完成消息;
向所述目标节点发送所述单连接配置完成消息;
其中所述单连接配置完成消息通过所述第一安全密钥进行加密和/或完整性保护;或者,所述单连接配置完成消息通过所述第三安全密钥进行加密和/或完整性保护。
本公开实施例适用于采用双连接架构进行移动性管理的安全密钥更新,提高通信的可靠性,进一步地,支持终端与目标节点通信的加密和/或完整性保护功能。
参见图4,本公开实施例还提供一种处理方法,该方法的执行主体可以为目标节点,具体步骤如下:
步骤401:根据双连接配置完成消息、随机接入请求消息、单连接配置完成消息中的一项或多项,确认终端的加密和/或完整性保护功能的激活;或者,
根据双连接配置完成消息和随机接入请求消息中任一项携带的MAC-I或截短的MAC-I,确认终端的加密和/或完整性保护功能的激活。
本公开实施例中,可选地,所述根据双连接配置完成消息、随机接入请求消息、单连接配置完成消息中的一项或多项,确认终端的加密和/或完整性保护功能的激活,包括以下任意一项:
当从所述源节点接收到所述双连接配置完成消息时,确认所述终端的加密和/或完整性保护功能的激活,所述双连接配置完成消息通过第一安全密钥进行加密和/或完整性保护;
当从所述终端接收到所述随机接入请求消息时,确认所述终端的加密和/或完整性保护功能的激活;
当从所述终端接收到所述单连接配置完成消息时,确认所述终端的加密和/或完整性保护功能的激活,所述单连接配置完成消息通过所述第一安全密钥进行加密和/或完整性保护;
其中,所述第一安全密钥为分别应用双连接配置信息和单连接配置信息与目标节点连接使用的安全密钥。
本公开实施例中,可选地,所述根据双连接配置完成消息、随机接入请求消息、单连接配置完成消息中的一项或多项,确认终端的加密和/或完整性保护功能的激活,包括:
当从所述源节点接收到所述双连接配置完成消息,或者从所述终端接收到所述随机接入请求消息时,确认基于第二安全密钥的加密和/或完整性保护功能的激活,所述双连接配置完成消息通过所述第二安全密钥进行加密和/或完整性保护;
当从所述终端接收到所述单连接配置完成消息时,确认基于所述第三安全密钥的加密和/或完整性保护功能的激活,所述单连接配置完成消息通过所述第三安全密钥进行加密和/或完整性保护;
当确认基于所述第二安全密钥的加密和/或完整性保护功能的激活,以及确认基于所述第三安全密钥的加密和/或完整性保护功能的激活时,确认所述终端的加密和/或完整性保护功能的激活;
其中,所述第二安全密钥为应用双连接配置信息与目标节点连接使用的安全密钥;所述第三安全密钥为应用单连接配置信息与所述目标节点连接使用的安全密钥。
本公开实施例中,可选地,所述根据双连接配置完成消息和随机接入请求消息中任一项携带的MAC-I或截短的MAC-I,确认终端的加密和/或完整性保护功能的激活,包括以下任意一项:
当从所述源节点接收双连接配置完成消息,且所述双连接配置完成消息中携带的MAC-I或截短的MAC-I通过第一安全密钥的验证时,确认终端的加密和/或完整性保护功能的激活;
当从所述终端接收随机接入请求消息,且所述随机接入请求消息中携带的MAC-I或截短的MAC-I通过第一安全密钥验证时,确认终端的加密和/或完整性保护功能的激活;
当从所述源节点接收双连接配置完成消息,且所述双连接配置完成消息中携带的MAC-I或截短的MAC-I通过第三安全密钥的验证时,确认终端的加密和/或完整性保护功能的激活;
当从所述终端接收随机接入请求消息,且所述随机接入请求消息中携带的MAC-I或截短的MAC-I通过第三安全密钥验证时,确认终端的加密和/或完整性保护功能的激活;
其中,所述第一安全密钥为分别应用双连接配置信息和单连接配置信息与目标节点连接使用的安全密钥;所述第三安全密钥为应用单连接配置信息与所述目标节点连接使用的安全密钥。
本公开实施例适用于采用双连接架构进行移动性管理的安全密钥更新,提高通信的可靠性,进一步地,支持终端与目标节点通信的加密和/或完整性保护功能。
参见图5,本公开实施例还提供一种处理方法,该方法的执行主体可以为源节点,具体步骤如下:
步骤501:向终端发送由目标节点配置的第一参数,或者发送由所述源节点配置的第二参数和由所述目标节点配置的第三参数;
其中,所述第一参数用于计算第一安全密钥,所述第一安全密钥为分别应用双连接配置信息和单连接配置信息与目标节点连接使用的安全密钥;
所述第二参数用于计算第二安全密钥,所述第二安全密钥为应用双连接配置信息与目标节点连接使用的安全密钥;
所述第三参数用于计算第三安全密钥,所述第三安全密钥为应用单连接配置信息与所述目标节点连接使用的安全密钥。
本公开实施例中,可选地,所述向终端发送由目标节点配置的第一参数,或者发送由所述源节点配置的第二参数和由所述目标节点配置的第三参数,包括:
向终端发送RRC重配置消息,其中,所述RRC重配置消息包括:所述终端的移动性管理的配置信息,所述终端的移动性管理的配置信息至少包括:由目标节点配置的第一参数;或者所述终端的移动性管理的配置信息至少包括:由所述源节点配置的第二参数和由所述目标节点配置的第三参数。
本公开实施例中,可选地,所述方法还包括:
在接收到用于响应所述RRC重配置消息的RRC重配置完成消息之后,向所述目标节点发送双连接配置完成消息。
本公开实施例中,可选地,从所述RRC重配置完成消息中获取MAC-I或截短的MAC-I;向所述目标节点发送双连接配置完成消息,所述双连接配置完成消息包括:所述MAC-I或截短的MAC-I;
其中,所述MAC-I通过所述第一安全密钥或第三安全密钥计算获得。
进一步地,可选地,所述MAC-I通过所述第一安全密钥(Key)、所述源节点的物理小区标识(Physical Cell ID,PCI)、所述源节点给所述终端分配的小区无线网络临时标识(Cell Radio Network Temporary Identifier,C-RNTI)、所述目标节点的小区标识(ID)中的一项或多项计算获得;
或者,所述MAC-I通过所述第三安全密钥(Key_2)、所述源节点的PCI、所述源节点给所述终端分配的C-RNTI、所述目标节点的小区ID中的一项或多项计算获得。
本公开实施例中,可选地,在所述向终端发送RRC重配置消息之前,所述方法还包括:
从所述目标节点接收所述终端的移动性管理的配置信息。
本公开实施例中,可选地,所述终端的移动性管理的配置信息还包括以下一项或多项:
用于与所述源节点和所述目标节点建立连接的双连接配置信息;
用于与所述目标节点建立连接的单连接配置信息;
所述第一安全密钥;
所述第三安全密钥。
本公开实施例适用于采用双连接架构进行移动性管理的安全密钥更新,提高通信的可靠性,进一步地,支持终端与目标节点通信的加密和/或完整性保护功能。
参见图6,本公开实施例还提供一种处理方法,该方法的执行主体可以为目标节点,具体步骤如下:
步骤601:向源节点发送由所述目标节点配置的第一参数或者由所述目标节点配置的第三参数;
其中,所述第一参数用于计算第一安全密钥,所述第一安全密钥为分别应用双连接配置信息和单连接配置信息与目标节点连接使用的安全密钥;
所述第三参数用于计算第三安全密钥,所述第三安全密钥为应用单连接配置信息与所述目标节点连接使用的安全密钥。
本公开实施例,可选地,所述向源节点发送由所述目标节点配置的第一参数或者由所述目标节点配置的第三参数,包括:
向源节点发送终端的移动性管理的配置信息,所述终端的移动性管理的配置信息包括:由所述目标节点配置的第一参数或者由所述目标节点配置的第三参数。
本公开实施例,可选地,所述终端的移动性管理的配置信息还包括以下一项或多项:
用于与所述源节点和所述目标节点建立连接的双连接配置信息;
用于与所述目标节点建立连接的单连接配置信息;
所述第一安全密钥;
所述第三安全密钥。
本公开实施例,可选地,所述方法还包括:
根据双连接配置完成消息、随机接入请求消息、单连接配置完成消息中的一项或多项,确认终端的加密和/或完整性保护功能的激活;或者,
根据双连接配置完成消息和随机接入请求消息中任一项携带的MAC-I或截短的MAC-I,确认终端的加密和/或完整性保护功能的激活。
本公开实施例中,可选地,所述根据双连接配置完成消息、随机接入请求消息、单连接配置完成消息中的一项或多项,确认终端的加密和/或完整性保护功能的激活,包括以下任意一项:
当从所述源节点接收到所述双连接配置完成消息时,确认所述终端的加密和/或完整性保护功能的激活,所述双连接配置完成消息通过第一安全密钥进行加密和/或完整性保护;
当从所述终端接收到所述随机接入请求消息时,确认所述终端的加密和/或完整性保护功能的激活;
当从所述终端接收到所述单连接配置完成消息时,确认所述终端的加密和/或完整性保护功能的激活,所述单连接配置完成消息通过所述第一安全密钥进行加密和/或完整性保护;
其中,所述第一安全密钥为分别应用双连接配置信息和单连接配置信息与目标节点连接使用的安全密钥。
本公开实施例中,可选地,所述根据双连接配置完成消息、随机接入请求消息、单连接配置完成消息中的一项或多项,确认终端的加密和/或完整性保护功能的激活,包括:
当从所述源节点接收到所述双连接配置完成消息,或者从所述终端接收到所述随机接入请求消息时,确认基于第二安全密钥的加密和/或完整性保护功能的激活,所述双连接配置完成消息通过所述第二安全密钥进行加密和/或完整性保护;
当从所述终端接收到所述单连接配置完成消息时,确认基于所述第三安全密钥的加密和/或完整性保护功能的激活,所述单连接配置完成消息通过所述第三安全密钥进行加密和/或完整性保护;
当确认基于所述第二安全密钥的加密和/或完整性保护功能的激活,以及确认基于所述第三安全密钥的加密和/或完整性保护功能的激活时,确认所述终端的加密和/或完整性保护功能的激活;
其中,所述第二安全密钥为应用双连接配置信息与目标节点连接使用的安全密钥;所述第三安全密钥为应用单连接配置信息与所述目标节点连接使用的安全密钥。
本公开实施例中,可选地,所述根据双连接配置完成消息和随机接入请求消息中任一项携带的MAC-I或截短的MAC-I,确认终端的加密和/或完整性保护功能的激活,包括以下任意一项:
当从所述源节点接收双连接配置完成消息,且所述双连接配置完成消息中携带的MAC-I或截短的MAC-I通过第一安全密钥的验证时,确认终端的加密和/或完整性保护功能的激活;
当从所述终端接收随机接入请求消息,且所述随机接入请求消息中携带的MAC-I或截短的MAC-I通过第一安全密钥验证时,确认终端的加密和/或完整性保护功能的激活;
当从所述源节点接收双连接配置完成消息,且所述双连接配置完成消息中携带的MAC-I或截短的MAC-I通过第三安全密钥的验证时,确认终端的加密和/或完整性保护功能的激活;
当从所述终端接收随机接入请求消息,且所述随机接入请求消息中携带的MAC-I或截短的MAC-I通过第三安全密钥验证时,确认终端的加密和/或完整性保护功能的激活;
其中,所述第一安全密钥为分别应用双连接配置信息和单连接配置信息与目标节点连接使用的安全密钥;所述第三安全密钥为应用单连接配置信息与所述目标节点连接使用的安全密钥。
本公开实施例适用于采用双连接架构进行移动性管理的安全密钥更新,提高通信的可靠性,进一步地,支持终端与目标节点通信的加密和/或完整性保护功能。
示例1:
在示例1中,分别应用两套配置信息与目标节点连接使用的安全密钥(Key)由目标节点分配,目标节点通过双连接配置完成消息、随机接入请求、单连接配置完成消息中的任意一项确认终端的加密功能和/或完整性保护功能的激活。
其中,两套配置信息包括:双连接配置(dcConfig)信息和单连接配置(targetConfig)信息。参见图7,具体步骤如下:
步骤1:源节点发送移动性管理请求信息给目标节点。
例如:移动性管理请求信息可以为切换请求,该移动性管理请求信息包括:终端的安全能力信息,其中终端的安全能力信息可以是以下一项或多项:支持的用户面(User Plane,UP)加密算法、UP完整性保护算法、支持的控制面无线资源控制(Radio Resource Control,RRC)加密算法、RRC完整性保护算法。
步骤2:根据步骤1中的移动性管理请求信息,目标节点生成终端的移动性管理的配置信息,并将该终端的移动性管理的配置信息发送给源节点。
例如:终端的移动性管理的配置信息可以为切换命令,其中,该终端的移动性管理的配置信息包括:
(1)用于同时保持源节点和目标节点连接的双连接配置(dcConfig)信息。可以理解的是,该双连接配置信息仅临时用于移动性过程中终端同时保持源节点和目标节点的连接。
(2)用于目标节点连接的单连接配置(targetConfig)信息。可以理解的是,该单连接配置信息用于移动性过程结束后终端和目标节点的连接。
(3)应用双连接配置信息和单连接配置信息与目标节点连接使用的安全密钥(Key)。
(4)安全密钥(Key)导出的输入参数,例如:计数值(Counter)。
步骤3:源节点将步骤2中部分终端的移动性管理的配置信息下发给终端,例如:通过RRC重配置消息将部分终端的移动性管理的配置信息发送给终端。
可以理解的是,将步骤2中除了“(3)应用双连接配置信息和单连接配置信息与目标节点连接使用的安全密钥(Key)”之外的内容下发给终端。安全密钥(Key)不能在空口中发送,终端可以通过计数值(Counter)导出安全密钥(Key)。
终端接收到RRC重配置消息后,可以执行以下一项或多项动作:
(1)根据计数值(Counter)导出终端使用的安全密钥(Key);
(2)应用双连接配置(dcConfig)信息同时建立与源节点和目标节点的连接。
步骤4:终端向源节点发送RRC重配置完成消息。
步骤5:在步骤4完成后,源节点发送双连接配置完成消息给目标节点,若目标节点成功接收到双连接配置完成消息,目标节点确认该终端的加密功能和/或完整性保护功能的激活。
步骤6:在步骤4完成后,终端向目标节点发起随机接入请求,若目标节点成功接收到该终端的随机接入请求消息,目标节点确认该终端的加密和/或完整性保护功能的激活。
步骤7:在步骤6完成后,终端执行如下动作:
(1)应用单连接配置(targetConfig)信息仅建立与目标节点的连接。
(2)生成单连接配置(targetConfig)完成消息,所述单连接配置(targetConfig)完成消息用安全密钥(Key)进行加密和/或完整性保护。
(3)向目标节点发送单连接配置(targetConfig)完成消息,若目标节点成功接收到单连接配置(targetConfig)完成消息,目标节点确认该终端的加密和/或完整性保护功能的激活。
可以理解的是,步骤5、步骤6和步骤7中“目标节点确认该终端的加密功能和/或完整性保护功能的激活”的条件任一项满足时,目标节点确认该终端的加密和/或完整性保护功能的激活。
示例2:
在示例2中,应用双连接配置(dcConfig)信息与目标节点连接使用的安全密钥(以下简称为Key_1)由源节点分配,应用单连接配置(targetConfig)信息与目标节点连接使用的安全密钥(以下简称为Key_2)由目标节点分配,目标节点通过双连接配置完成消息、随机接入请求、单连接配置完成消息中的任意一项确认终端的加密功能和/或完整性保护功能的激活。参见图8,具体步骤如下:
步骤1:源节点发送移动性管理请求信息给目标节点。
例如:移动性管理请求信息可以为切换请求,该移动性管理请求信息包括:终端的安全能力信息和应用双连接配置(dcConfig)信息与目标节点连接使用的Key_1。
其中,终端的安全能力信息可以是以下一项或多项:支持的UP加密算法、UP完整性保护算法、支持的控制面RRC加密算法和RRC完整性保护算 法。
步骤2:根据步骤1中的移动性管理请求信息,目标节点生成终端的移动性管理的配置信息,并将该终端的移动性管理的配置信息发送给源节点。
例如:终端的移动性管理的配置信息可以为切换命令,其中,该终端的移动性管理的配置信息包括:
(1)用于同时保持源节点和目标节点连接的双连接配置(dcConfig)信息。可以理解的是,该双连接配置信息仅临时用于移动性过程中终端同时保持源节点和目标节点的连接。
(2)用于目标节点连接的单连接配置(targetConfig)信息,可以理解的是,该单连接配置信息用于移动性过程结束后终端和目标节点的连接。
(3)应用单连接配置(targetConfig)信息与目标节点连接使用的Key_2。
(4)Key_2导出的输入参数,例如:计数值(Counter_2)。
步骤3:源节点将步骤2中终端的移动性管理的配置信息和Key_1导出的输入参数(例如:计数值(Counter_1))下发给终端,例如:通过RRC重配置消息将终端的移动性管理的配置信息和Counter_1发送给终端。
可以理解的是,将步骤2中除了“(3)应用单连接配置(targetConfig)信息与目标节点连接使用的Key_2”之外的内容下发给终端。Key_2不能在空口中发送,终端可以通过输入参数(计数值(Counter_2))导出Key2。
需要说明的是,由于Key_1是源节点分配,因此对应的Key_1导出的输入参数(例如:计数值(Counter_1))也由源节点配置,因此不需要体现在步骤2中,而是在步骤2完成后,跟随步骤2获得的部分“终端的移动性管理的配置信息”一起下发给终端。
可选地,终端接收到RRC重配置消息后,可以执行以下一项或多项动作:
(1)根据计数值(Counter_1)导出终端使用的安全密钥Key_1;
(2)根据计数值(Counter_2)导出终端使用的安全密钥Key_2;
(3)应用双连接配置(dcConfig)信息同时建立与源节点和目标节点的连接。
步骤4:终端向源节点发送RRC重配置完成消息。
步骤5:在步骤4完成后,源节点发送双连接配置(dcConfig)完成消息 给目标节点,若目标节点成功接收到双连接配置(dcConfig)完成消息,目标节点确认基于Key_1的加密和/或完整性保护功能激活。
步骤6:在步骤4完成后,终端向目标节点发起随机接入请求,若目标节点成功接收到终端的随机接入请求消息,目标节点确认基于Key_1的加密和/或完整性保护功能激活。
步骤7:在步骤6完成后,终端执行如下动作:
(1)应用单连接配置(targetConfig)信息仅建立与目标节点的连接;
(2)生成单连接配置(targetConfig)完成消息,所述单连接配置(targetConfig)完成消息用所述Key_2进行加密和/或完整性保护;
(3)向目标节点发送所述单连接配置(targetConfig)完成消息,若目标节点成功接收到单连接配置(targetConfig)完成消息,目标节点确认基于Key_2的加密和/或完整性保护功能激活。
可以理解的是,当确认基于Key_1的加密和/或完整性保护功能激活,以及基于Key_2的加密和/或完整性保护功能激活时,目标节点确认该终端的加密和/或完整性保护功能的激活。
示例3:
在示例1的基础上,目标节点基于双连接配置完成消息、随机接入请求消息其中任意一项所携带的MAC-I或截短的MAC-I验证,确认终端的加密功能和/或完整性保护功能的激活。参见图9,具体步骤如下:
步骤1:源节点发送移动性管理请求信息给目标节点。
步骤2:根据步骤1中的移动性管理请求信息,目标节点生成终端的移动性管理的配置信息,并将该终端的移动性管理的配置信息发送给源节点。
步骤3:源节点将步骤2中部分终端的移动性管理的配置信息下发给终端,例如:通过RRC重配置消息将部分终端的移动性管理的配置信息发送给终端。
需要说明的是,示例3中的步骤1~步骤3的内容与示例1中的步骤1~步骤3的内容相同。
步骤4:终端向源节点发送RRC重配置完成消息,RRC重配置完成消息包含MAC-I或截短的MAC-I。
其中,MAC-I通过Key、源节点的物理小区标识(Physical Cell Identifier,PCI),源节点给终端分配的小区无线网络临时标识(Cell Radio Network Temporary Identifier,C-RNTI),目标节点的小区标识(Identification,ID)中的一项或多项计算获得,所述截短的MAC-I是MAC-I的截短形式。
步骤5:源节点将步骤4中的MAC-I或截短的MAC-I通过双连接配置(dcConfig)完成消息转发给目标节点,若目标节点用所述Key对MAC-I或截短的MAC-I验证通过,目标节点确认该终端的加密和/或完整性保护功能的激活。
步骤6:在步骤4完成后,终端向目标节点发送随机接入请求消息,且在随机接入请求消息中包含MAC-I或截短的MAC-I,若目标节点用所述Key对MAC-I或截短的MAC-I完整性验证通过,目标节点确认该终端的加密和/或完整性保护功能的激活。
可以理解的是,步骤5、步骤6和步骤7中“目标节点确认该终端的加密功能和/或完整性保护功能的激活”的条件任一项满足时,目标节点确认该终端的加密和/或完整性保护功能的激活。
示例4:
在示例2的基础上,目标节点通过基于双连接配置完成消息、随机接入请求消息的其中一项所携带的MAC-I或截短的MAC-I,确认终端的加密功能和/或完整性保护功能的激活。参见图10,具体步骤如下:
步骤1:源节点发送移动性管理请求信息给目标节点。
步骤2:根据步骤1中的移动性管理请求信息,目标节点生成终端的移动性管理的配置信息,并将该终端的移动性管理的配置信息发送给源节点。
步骤3:源节点将步骤2中部分终端的移动性管理的配置信息和Key_1导出的输入参数(例如:计数值(Counter_1))下发给终端。
需要说明的是,示例3中的步骤1~步骤3的内容与示例1中的步骤1~步骤3的内容相同。
步骤4:终端向源节点发送RRC重配置完成消息,所述RRC重配置完成消息包含:MAC-I或截短的MAC-I。
其中,MAC-I通过Key_2、源节点的PCI、源节点给终端分配的C-RNTI、 目标节点的小区ID中的一项或多项计算获得。所述截短的MAC-I是MAC-I的截短形式。
步骤5:源节点将步骤4中的MAC-I或截短的MAC-I通过双连接配置(dcConfig)完成消息转发给目标节点,若目标节点成功接收到双连接配置(dcConfig)完成消息,并且目标节点用所述Key_2对MAC-I或截短的MAC-I验证通过,目标节点确认该终端的加密和/或完整性保护功能激活。
步骤6:在步骤4完成后,终端向目标节点发起随机接入请求,所述随机接入请求消息中包含MAC-I或截短的MAC-I,若目标节点成功接收到该终端的随机接入请求消息,并且目标节点用所述Key_2对MAC-I或截短的MAC-I完整性验证通过,目标节点确认该终端的加密和/或完整性保护功能激活。
示例1至示例4描述了基于DC架构进行切换的场景,可以理解的是,本公开实施例不仅适用于基于DC架构进行切换的场景,还可以适用于DC架构的SCG变更、SCG删除和SCG添加场景。
本公开实施例中还提供了一种终端,由于终端解决问题的原理与本公开实施例中处理方法相似,因此该终端的实施可以参见方法的实施,重复之处不再敷述。
参见图11,本公开实施例还提供一种终端,该终端1100包括:
第一确定模块1101,用于确定由目标节点配置的第一安全密钥,其中所述第一安全密钥为分别应用双连接配置信息和单连接配置信息与目标节点连接使用的安全密钥;或者,
第二确定模块1102,用于确定由源节点配置的第二安全密钥和由目标节点配置的第三安全密钥,其中所述第二安全密钥为应用双连接配置信息与目标节点连接使用的安全密钥;所述第三安全密钥为应用单连接配置信息与所述目标节点连接使用的安全密钥。
本公开实施例,可选地,所述第一确定模块进一步用于:从所述源节点接收由所述目标节点配置的第一参数,所述第一参数用于计算所述第一安全密钥;根据所述第一参数,计算所述第一安全密钥。
本公开实施例,可选地,所述第二确定模块进一步用于:从所述源节点接收由所述源节点配置的第二参数和由所述目标节点配置的第三参数,其中,所述第二参数用于计算所述第二安全密钥,所述第三参数用于计算所述第三安全密钥;根据所述第二参数,计算所述第二安全密钥,以及根据所述第三参数,计算所述第三安全密钥。
本公开实施例,可选地,所述第一参数携带在由所述源节点发送的RRC重配置消息中,或者所述第二参数和所述第三参数携带在由所述源节点发送的RRC重配置消息中。
本公开实施例,可选地,所述RRC重配置消息中还携带有以下一项或多项:
用于与所述源节点和所述目标节点建立连接的双连接配置信息;
用于与所述目标节点建立连接的单连接配置信息;
本公开实施例,可选地,所述终端还包括:
第一连接模块,用于根据所述双连接配置信息建立与所述目标节点和所述源节点的连接;
第一发送模块,用于向所述源节点发送用于响应RRC重配置消息或RRC重配置消息的RRC重配置完成消息。
本公开实施例,可选地,所述终端还包括:
第二发送模块,用于在向所述源节点发送用于响应所述RRC重配置消息或RRC重配置消息的RRC重配置完成消息之后,向所述目标节点发送随机接入请求消息。
本公开实施例,可选地,所述RRC重配置完成消息或所述随机接入请求消息包括:完整性保护的消息认证码MAC-I或截短的MAC-I;
其中,所述MAC-I至少通过所述第一安全密钥或所述第三安全密钥计算获得。
本公开实施例,可选地,第二连接模块,用于在向所述目标节点发起的随机接入过程完成之后,根据所述单连接配置建立与所述目标节点的连接,并生成单连接配置完成消息;
第三发送模块,用于向所述目标节点发送所述单连接配置完成消息;
其中,所述单连接配置完成消息通过所述第一安全密钥进行加密和/或完整性保护;或者,
所述单连接配置完成消息通过所述第三安全密钥进行加密和/或完整性保护。
本公开实施例提供的终端,可以执行上述方法实施例,其实现原理和技术效果类似,本实施例此处不再赘述。
本公开实施例中还提供了一种目标节点,由于目标节点解决问题的原理与本公开实施例中处理方法相似,因此该目标节点的实施可以参见方法的实施,重复之处不再敷述。
参见图12,本公开实施例还提供一种目标节点,该目标节点1200包括:
第一确认模块1201,用于根据双连接配置完成消息、随机接入请求消息、单连接配置完成消息中的一项或多项,确认终端的加密和/或完整性保护功能的激活;或者,
第二确认模块1202,用于根据双连接配置完成消息和随机接入请求消息中任一项携带的MAC-I或截短的MAC-I,确认终端的加密和/或完整性保护功能的激活。
本公开实施例,可选地,所述第一确认模块进一步用于执行以下任意一项:
当从所述源节点接收到所述双连接配置完成消息时,确认所述终端的加密和/或完整性保护功能的激活,所述双连接配置完成消息通过第一安全密钥进行加密和/或完整性保护;
当从所述终端接收到所述随机接入请求消息时,确认所述终端的加密和/或完整性保护功能的激活;
当从所述终端接收到所述单连接配置完成消息时,确认所述终端的加密和/或完整性保护功能的激活,所述单连接配置完成消息通过所述第一安全密钥进行加密和/或完整性保护;
其中,所述第一安全密钥为分别应用双连接配置信息和单连接配置信息与目标节点连接使用的安全密钥。
本公开实施例,可选地,所述第一确认模块进一步用于:
当从所述源节点接收到所述双连接配置完成消息,或者从所述终端接收到所述随机接入请求消息时,确认基于第二安全密钥的加密和/或完整性保护功能的激活,所述双连接配置完成消息通过所述第二安全密钥进行加密和/或完整性保护;
当从所述终端接收到所述单连接配置完成消息时,确认基于所述第三安全密钥的加密和/或完整性保护功能的激活,所述单连接配置完成消息通过所述第三安全密钥进行加密和/或完整性保护;
当确认基于所述第二安全密钥的加密和/或完整性保护功能的激活,以及确认基于所述第三安全密钥的加密和/或完整性保护功能的激活时,确认所述终端的加密和/或完整性保护功能的激活;
其中,所述第二安全密钥为应用双连接配置信息与目标节点连接使用的安全密钥;所述第三安全密钥为应用单连接配置信息与所述目标节点连接使用的安全密钥。
本公开实施例,可选地,所述第二确认模块进一步用于执行以下任意一项:
当从所述源节点接收双连接配置完成消息,且所述双连接配置完成消息中携带的MAC-I或截短的MAC-I通过第一安全密钥的验证时,确认终端的加密和/或完整性保护功能的激活;
当从所述终端接收随机接入请求消息,且所述随机接入请求消息中携带的MAC-I或截短的MAC-I通过第一安全密钥验证时,确认终端的加密和/或完整性保护功能的激活;
当从所述源节点接收双连接配置完成消息,且所述双连接配置完成消息中携带的MAC-I或截短的MAC-I通过第三安全密钥的验证时,确认终端的加密和/或完整性保护功能的激活;
当从所述终端接收随机接入请求消息,且所述随机接入请求消息中携带的MAC-I或截短的MAC-I通过第三安全密钥验证时,确认终端的加密和/或完整性保护功能的激活;
其中,所述第一安全密钥为分别应用双连接配置信息和单连接配置信息与目标节点连接使用的安全密钥;所述第三安全密钥为应用单连接配置与所述目标节点连接使用的安全密钥。
本公开实施例提供的目标节点,可以执行上述方法实施例,其实现原理和技术效果类似,本实施例此处不再赘述。
本公开实施例中还提供了一种源节点,由于源节点解决问题的原理与本公开实施例中处理方法相似,因此该源节点的实施可以参见方法的实施,重复之处不再敷述。
参见图13,本公开实施例还提供一种源节点,该源节点1300包括:
第五发送模块1301,用于向终端发送由目标节点配置的第一参数,或者发送由所述源节点配置的第二参数和由所述目标节点配置的第三参数;
其中,所述第一参数用于计算第一安全密钥,所述第一安全密钥为分别应用双连接配置信息和单连接配置信息与目标节点连接使用的安全密钥;
所述第二参数用于计算第二安全密钥,所述第二安全密钥为应用双连接配置信息与目标节点连接使用的安全密钥;
所述第三参数用于计算第三安全密钥,所述第三安全密钥为应用单连接配置信息与所述目标节点连接使用的安全密钥。
本公开实施例,可选地,第五发送模块1301进一步用于:向终端发送RRC重配置消息,其中,所述RRC重配置消息包括:所述终端的移动性管理的配置信息,所述终端的移动性管理的配置信息至少包括:由目标节点配置的第一参数;或者所述终端的移动性管理的配置信息至少包括:由所述源节点配置的第二参数和由所述目标节点配置的第三参数
本公开实施例,可选地,所述源节点还包括:
第六发送模块,用于在接收到用于响应所述RRC重配置消息的RRC重配置完成消息之后,向所述目标节点发送双连接配置完成消息。
本公开实施例,可选地,所述第六发送模块进一步用于:从所述RRC重配置完成消息中获取MAC-I或截短的MAC-I;向所述目标节点发送双连接配置完成消息,所述双连接配置完成消息包括:所述MAC-I或截短的MAC-I;
其中,所述MAC-I至少通过所述第一安全密钥或第三安全密钥计算获得。
本公开实施例,可选地,所述源节点还包括:第三接收模块,用于从所述目标节点接收所述终端的移动性管理的配置信息。
本公开实施例,可选地,所述终端的移动性管理的配置信息还包括以下一项或多项:
用于与所述源节点和所述目标节点建立连接的双连接配置信息;
用于与所述目标节点建立连接的单连接配置信息;
所述第一安全密钥;
所述第三安全密钥。
本公开实施例提供的源节点,可以执行上述方法实施例,其实现原理和技术效果类似,本实施例此处不再赘述。
本公开实施例中还提供了一种目标节点,由于目标节点解决问题的原理与本公开实施例中处理方法相似,因此该目标节点的实施可以参见方法的实施,重复之处不再敷述。
参见图14,本公开实施例还提供一种目标节点,该目标节点1400包括:
第七发送模块1401,用于向源节点发送由所述目标节点配置的第一参数或者由所述目标节点配置的第三参数;
其中,所述第一参数用于计算第一安全密钥,所述第一安全密钥为分别应用双连接配置信息和单连接配置信息与目标节点连接使用的安全密钥;
所述第三参数用于计算第三安全密钥,所述第三安全密钥为应用单连接配置信息与所述目标节点连接使用的安全密钥。
本公开实施例,可选地,所述向源节点发送由所述目标节点配置的第一参数或者由所述目标节点配置的第三参数,包括:
向源节点发送终端的移动性管理的配置信息,所述终端的移动性管理的配置信息包括:由所述目标节点配置的第一参数或者由所述目标节点配置的第三参数。
本公开实施例,可选地,所述终端的移动性管理的配置信息还包括以下一项或多项:
用于与所述源节点和所述目标节点建立连接的双连接配置信息;
用于与所述目标节点建立连接的单连接配置信息;
所述第一安全密钥;
所述第三安全密钥。
本公开实施例,可选地,所述目标节点还包括:
第三确认模块,用于根据双连接配置完成消息、随机接入请求消息、单连接配置完成消息中的一项或多项,确认终端的加密和/或完整性保护功能的激活;或者,
第四确认模块,用于根据双连接配置完成消息和随机接入请求消息中任一项携带的MAC-I或截短的MAC-I,确认终端的加密和/或完整性保护功能的激活。
本公开实施例提供的目标节点,可以执行上述方法实施例,其实现原理和技术效果类似,本实施例此处不再赘述。
如图15所示,图15所示的终端1500包括:至少一个处理器1501、存储器1502、至少一个网络接口1504和用户接口1503。终端1500中的各个组件通过总线系统1505耦合在一起。可理解,总线系统1505用于实现这些组件之间的连接通信。总线系统1505除包括数据总线之外,还包括电源总线、控制总线和状态信号总线。但是为了清楚说明起见,在图15中将各种总线都标为总线系统1505。
其中,用户接口1503可以包括显示器、键盘或者点击设备(例如,鼠标,轨迹球(trackball)、触感板或者触摸屏等。
可以理解,本公开实施例中的存储器1502可以是易失性存储器或非易失性存储器,或可包括易失性和非易失性存储器两者。其中,非易失性存储器可以是只读存储器(Read-Only Memory,ROM)、可编程只读存储器(Programmable ROM,PROM)、可擦除可编程只读存储器(Erasable PROM,EPROM)、电可擦除可编程只读存储器(Electrically EPROM,EEPROM)或闪存。易失性存储器可以是随机存取存储器(Random Access Memory,RAM),其用作外部高速缓存。通过示例性但不是限制性说明,许多形式的RAM可用,例如静态随机存取存储器(Static RAM,SRAM)、动态随机存取存储器(Dynamic RAM,DRAM)、同步动态随机存取存储器(Synchronous DRAM,SDRAM)、双倍数据速率同步动态随机存取存储器(Double Data rate  SDRAM,DDRSDRAM)、增强型同步动态随机存取存储器(Enhanced SDRAM,ESDRAM)、同步连接动态随机存取存储器(Synchlink DRAM,SLDRAM)和直接内存总线随机存取存储器(Direct Rambus RAM,DRRAM)。本公开实施例描述的系统和方法的存储器1502旨在包括但不限于这些和任意其它适合类型的存储器。
在一些实施方式中,存储器1502保存了如下的元素,可执行模块或者数据结构,或者他们的子集,或者他们的扩展集:操作系统15021和应用程序15022。
其中,操作系统15021,包含各种系统程序,例如框架层、核心库层、驱动层等,用于实现各种基础业务以及处理基于硬件的任务。应用程序15022,包含各种应用程序,例如媒体播放器(Media Player)、浏览器(Browser)等,用于实现各种应用业务。实现本公开实施例方法的程序可以包含在应用程序15022中。
在本公开的一个实施例中,通过调用存储器1502保存的程序或指令,具体的,可以是应用程序15022中保存的程序或指令,执行时实现以下步骤:确定由目标节点配置的第一安全密钥,其中所述第一安全密钥为分别应用双连接配置信息和单连接配置信息与目标节点连接使用的安全密钥;或者确定由源节点配置的第二安全密钥和由目标节点配置的第三安全密钥,其中所述第二安全密钥为应用双连接配置信息与目标节点连接使用的安全密钥;所述第三安全密钥为应用单连接配置信息与所述目标节点连接使用的安全密钥。
本公开实施例提供的终端,可以执行上述方法实施例,其实现原理和技术效果类似,本实施例此处不再赘述。
请参阅图16,图16是本公开实施例应用的网络设备的结构图,如图16所示,网络设备1600包括:处理器1601、收发机1602、存储器1603和总线接口,其中:
在本公开的一个实施例中,网络设备1600还包括:存储在存储器上1603并可在处理器1601上运行的程序,程序被处理器1601执行时实现如下步骤:根据双连接配置完成消息、随机接入请求消息、单连接配置完成消息中的一项或多项,确认终端的加密和/或完整性保护功能的激活;或者,根据双连接 配置完成消息和随机接入请求消息中任一项携带的MAC-I或截短的MAC-I,确认终端的加密和/或完整性保护功能的激活。
在本公开的另一个实施例中,网络设备1600还包括:存储在存储器上1603并可在处理器1601上运行的程序,程序被处理器1601执行时实现如下步骤:向终端发送由目标节点配置的第一参数,或者发送由所述源节点配置的第二参数和由所述目标节点配置的第三参数;其中,所述第一参数用于计算第一安全密钥,所述第一安全密钥为分别应用双连接配置信息和单连接配置信息与目标节点连接使用的安全密钥;所述第二参数用于计算第二安全密钥,所述第二安全密钥为应用双连接配置信息与目标节点连接使用的安全密钥;所述第三参数用于计算第三安全密钥,所述第三安全密钥为应用单连接配置信息与所述目标节点连接使用的安全密钥。
在本公开的又一个实施例中,网络设备1600还包括:存储在存储器上1603并可在处理器1601上运行的程序,程序被处理器1601执行时实现如下步骤:向源节点发送由所述目标节点配置的第一参数或者由所述目标节点配置的第三参数;其中,所述第一参数用于计算第一安全密钥,所述第一安全密钥为分别应用双连接配置信息和单连接配置信息与目标节点连接使用的安全密钥;所述第三参数用于计算第三安全密钥,所述第三安全密钥为应用单连接配置信息与所述目标节点连接使用的安全密钥。
在图16中,总线架构可以包括任意数量的互联的总线和桥,具体由处理器1601代表的一个或多个处理器和存储器1603代表的存储器的各种电路链接在一起。总线架构还可以将诸如外围设备、稳压器和功率管理电路等之类的各种其他电路链接在一起,这些都是本领域所公知的,因此,本文不再对其进行进一步描述。总线接口提供接口。收发机1602可以是多个元件,即包括发送机和接收机,提供用于在传输介质上与各种其他装置通信的单元。
处理器1601负责管理总线架构和通常的处理,存储器1603可以存储处理器1601在执行操作时所使用的数据。
本公开实施例提供的网络设备,可以执行上述方法实施例,其实现原理和技术效果类似,本实施例此处不再赘述。
结合本公开公开内容所描述的方法或者算法的步骤可以硬件的方式来实 现,也可以是由处理器执行软件指令的方式来实现。软件指令可以由相应的软件模块组成,软件模块可以被存放于RAM、闪存、ROM、EPROM、EEPROM、寄存器、硬盘、移动硬盘、只读光盘或者本领域熟知的任何其它形式的存储介质中。一种示例性的存储介质耦合至处理器,从而使处理器能够从该存储介质读取信息,且可向该存储介质写入信息。当然,存储介质也可以是处理器的组成部分。处理器和存储介质可以位于ASIC中。另外,该ASIC可以位于核心网接口设备中。当然,处理器和存储介质也可以作为分立组件存在于核心网接口设备中。
本领域技术人员应该可以意识到,在上述一个或多个示例中,本公开所描述的功能可以用硬件、软件、固件或它们的任意组合来实现。当使用软件实现时,可以将这些功能存储在计算机可读介质中或者作为计算机可读介质上的一个或多个指令或代码进行传输。计算机可读介质包括计算机存储介质和通信介质,其中通信介质包括便于从一个地方向另一个地方传送计算机程序的任何介质。存储介质可以是通用或专用计算机能够存取的任何可用介质。
以上所述的具体实施方式,对本公开的目的、技术方案和有益效果进行了进一步详细说明,所应理解的是,以上所述仅为本公开的具体实施方式而已,并不用于限定本公开的保护范围,凡在本公开的技术方案的基础之上,所做的任何修改、等同替换、改进等,均应包括在本公开的保护范围之内。
本领域内的技术人员应明白,本公开实施例可提供为方法、系统、或计算机程序产品。因此,本公开实施例可采用完全硬件实施例、完全软件实施例、或结合软件和硬件方面的实施例的形式。而且,本公开实施例可采用在一个或多个其中包含有计算机可用程序代码的计算机可用存储介质(包括但不限于磁盘存储器、CD-ROM、光学存储器等)上实施的计算机程序产品的形式。
本公开实施例是参照根据本公开实施例的方法、设备(系统)、和计算机程序产品的流程图和/或方框图来描述的。应理解可由计算机程序指令实现流程图和/或方框图中的每一流程和/或方框、以及流程图和/或方框图中的流程和/或方框的结合。可提供这些计算机程序指令到通用计算机、专用计算机、嵌入式处理机或其他可编程数据处理设备的处理器以产生一个机 器,使得通过计算机或其他可编程数据处理设备的处理器执行的指令产生用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的装置。
这些计算机程序指令也可存储在能引导计算机或其他可编程数据处理设备以特定方式工作的计算机可读存储器中,使得存储在该计算机可读存储器中的指令产生包括指令装置的制造品,该指令装置实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能。
这些计算机程序指令也可装载到计算机或其他可编程数据处理设备上,使得在计算机或其他可编程设备上执行一系列操作步骤以产生计算机实现的处理,从而在计算机或其他可编程设备上执行的指令提供用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的步骤。
显然,本领域的技术人员可以对本公开实施例进行各种改动和变型而不脱离本公开的精神和范围。这样,倘若本公开实施例的这些修改和变型属于本公开权利要求及其等同技术的范围之内,则本公开也意图包含这些改动和变型在内。

Claims (29)

  1. 一种处理方法,应用于终端,其中,所述方法包括:
    确定由目标节点配置的第一安全密钥,其中所述第一安全密钥为分别应用双连接配置信息和单连接配置信息与目标节点连接使用的安全密钥;或者
    确定由源节点配置的第二安全密钥和由目标节点配置的第三安全密钥,其中所述第二安全密钥为应用双连接配置信息与目标节点连接使用的安全密钥;所述第三安全密钥为应用单连接配置信息与所述目标节点连接使用的安全密钥。
  2. 根据权利要求1所述的方法,其中,所述确定由目标节点配置的第一安全密钥,包括:
    从所述源节点接收由所述目标节点配置的第一参数,所述第一参数用于计算所述第一安全密钥;
    根据所述第一参数,计算所述第一安全密钥。
  3. 根据权利要求1所述的方法,其中,所述确定由源节点配置的第二安全密钥和目标节点配置的第三安全密钥,包括:
    从所述源节点接收由所述源节点配置的第二参数和由所述目标节点配置的第三参数,其中,所述第二参数用于计算所述第二安全密钥,所述第三参数用于计算所述第三安全密钥;
    根据所述第二参数,计算所述第二安全密钥,以及根据所述第三参数,计算所述第三安全密钥。
  4. 根据权利要求2或3所述的方法,其中,所述第一参数携带在由所述源节点发送的RRC重配置消息中,或者所述第二参数和所述第三参数携带在由所述源节点发送的RRC重配置消息中。
  5. 根据权利要求4所述的方法,其中,所述RRC重配置消息中还携带有以下一项或多项:
    用于与所述源节点和所述目标节点建立连接的双连接配置信息;
    用于与所述目标节点建立连接的单连接配置信息;
    所述方法还包括:
    根据所述双连接配置信息建立与所述目标节点和所述源节点的连接;
    向所述源节点发送用于响应所述RRC重配置消息的RRC重配置完成消息。
  6. 根据权利要求5所述的方法,还包括:
    在向所述源节点发送用于响应所述RRC重配置消息的RRC重配置完成消息之后,向所述目标节点发送随机接入请求消息。
  7. 根据权利要求5或6所述的方法,还包括:
    所述RRC重配置完成消息或所述随机接入请求消息包括:完整性保护的消息认证码MAC-I或截短的MAC-I;
    其中,所述MAC-I至少通过所述第一安全密钥或所述第三安全密钥计算获得。
  8. 根据权利要求6所述的方法,其中,在向所述目标节点发起的随机接入过程完成之后,所述方法还包括:
    根据所述单连接配置建立与所述目标节点的连接,并生成单连接配置完成消息;向所述目标节点发送所述单连接配置完成消息;
    其中,所述单连接配置完成消息通过所述第一安全密钥进行加密和/或完整性保护;或者,所述单连接配置完成消息通过所述第三安全密钥进行加密和/或完整性保护。
  9. 一种处理方法,应用于目标节点,其中,所述方法包括:
    根据双连接配置完成消息、随机接入请求消息、单连接配置完成消息中的一项或多项,确认终端的加密和/或完整性保护功能的激活;或者,
    根据双连接配置完成消息和随机接入请求消息中任一项携带的MAC-I或截短的MAC-I,确认终端的加密和/或完整性保护功能的激活。
  10. 根据权利要求9所述的方法,其中,所述根据双连接配置完成消息、随机接入请求消息、单连接配置完成消息中的一项或多项,确认终端的加密和/或完整性保护功能的激活,包括以下任意一项:
    当从源节点接收到所述双连接配置完成消息时,确认所述终端的加密和/或完整性保护功能的激活,所述双连接配置完成消息通过第一安全密钥进行加密和/或完整性保护;
    当从所述终端接收到所述随机接入请求消息时,确认所述终端的加密和/或完整性保护功能的激活;
    当从所述终端接收到所述单连接配置完成消息时,确认所述终端的加密和/或完整性保护功能的激活,所述单连接配置完成消息通过所述第一安全密钥进行加密和/或完整性保护;
    其中,所述第一安全密钥为分别应用双连接配置信息和单连接配置信息与目标节点连接使用的安全密钥。
  11. 根据权利要求9所述的方法,其中,所述根据双连接配置完成消息、随机接入请求消息、单连接配置完成消息中的一项或多项,确认终端的加密和/或完整性保护功能的激活,包括:
    当从源节点接收到所述双连接配置完成消息,或者从所述终端接收到所述随机接入请求消息时,确认基于第二安全密钥的加密和/或完整性保护功能的激活,所述双连接配置完成消息通过所述第二安全密钥进行加密和/或完整性保护;
    当从所述终端接收到所述单连接配置完成消息时,确认基于第三安全密钥的加密和/或完整性保护功能的激活,所述单连接配置完成消息通过所述第三安全密钥进行加密和/或完整性保护;
    当确认基于所述第二安全密钥的加密和/或完整性保护功能的激活,以及确认基于所述第三安全密钥的加密和/或完整性保护功能的激活时,确认所述终端的加密和/或完整性保护功能的激活;
    其中,所述第二安全密钥为应用双连接配置信息与目标节点连接使用的安全密钥;所述第三安全密钥为应用单连接配置信息与所述目标节点连接使用的安全密钥。
  12. 根据权利要求9所述的方法,其中,所述根据双连接配置完成消息和随机接入请求消息中任一项携带的MAC-I或截短的MAC-I,确认终端的加密和/或完整性保护功能的激活,包括以下任意一项:
    当从源节点接收双连接配置完成消息,且所述双连接配置完成消息中携带的MAC-I或截短的MAC-I通过第一安全密钥的验证时,确认终端的加密和/或完整性保护功能的激活;
    当从所述终端接收随机接入请求消息,且所述随机接入请求消息中携带的MAC-I或截短的MAC-I通过第一安全密钥验证时,确认终端的加密和/或完整性保护功能的激活;
    当从所述源节点接收双连接配置完成消息,且所述双连接配置完成消息中携带的MAC-I或截短的MAC-I通过第三安全密钥的验证时,确认终端的加密和/或完整性保护功能的激活;
    当从所述终端接收随机接入请求消息,且所述随机接入请求消息中携带的MAC-I或截短的MAC-I通过第三安全密钥验证时,确认终端的加密和/或完整性保护功能的激活;
    其中,所述第一安全密钥为分别应用双连接配置信息和单连接配置信息与目标节点连接使用的安全密钥;所述第三安全密钥为应用单连接配置信息与所述目标节点连接使用的安全密钥。
  13. 一种处理方法,应用于源节点,其中,所述方法包括:
    向终端发送由目标节点配置的第一参数,或者发送由所述源节点配置的第二参数和由所述目标节点配置的第三参数;
    其中,所述第一参数用于计算第一安全密钥,所述第一安全密钥为分别应用双连接配置信息和单连接配置信息与目标节点连接使用的安全密钥;
    所述第二参数用于计算第二安全密钥,所述第二安全密钥为应用双连接配置信息与目标节点连接使用的安全密钥;
    所述第三参数用于计算第三安全密钥,所述第三安全密钥为应用单连接配置信息与所述目标节点连接使用的安全密钥。
  14. 根据权利要求13所述的方法,其中,
    所述向终端发送由目标节点配置的第一参数,或者发送由所述源节点配置的第二参数和由所述目标节点配置的第三参数,包括:
    向终端发送RRC重配置消息,其中,所述RRC重配置消息包括:所述终端的移动性管理的配置信息,所述终端的移动性管理的配置信息至少包括:由目标节点配置的第一参数;或者所述终端的移动性管理的配置信息至少包括:由所述源节点配置的第二参数和由所述目标节点配置的第三参数。
  15. 根据权利要求14所述的方法,还包括:
    在接收到用于响应所述RRC重配置消息的RRC重配置完成消息之后,向所述目标节点发送双连接配置完成消息。
  16. 根据权利要求15所述的方法,其中,所述在接收到用于响应所述RRC重配置消息的RRC重配置完成消息之后,向所述目标节点发送双连接配置完成消息,包括:
    从所述RRC重配置完成消息中获取MAC-I或截短的MAC-I;
    向所述目标节点发送双连接配置完成消息,所述双连接配置完成消息包括:所述MAC-I或截短的MAC-I;
    其中,所述MAC-I至少通过所述第一安全密钥或第三安全密钥计算获得。
  17. 根据权利要求14所述的方法,其中,在所述向终端发送RRC重配置消息之前,所述方法还包括:
    从所述目标节点接收所述终端的移动性管理的配置信息。
  18. 根据权利要求13至17任一项所述的方法,其中,
    所述终端的移动性管理的配置信息还包括以下一项或多项:
    用于与所述源节点和所述目标节点建立连接的双连接配置信息;
    用于与所述目标节点建立连接的单连接配置信息;
    所述第一安全密钥;
    所述第三安全密钥。
  19. 一种处理方法,应用于目标节点,其中,所述方法包括:
    向源节点发送由所述目标节点配置的第一参数或者由所述目标节点配置的第三参数;
    其中,所述第一参数用于计算第一安全密钥,所述第一安全密钥为分别应用双连接配置信息和单连接配置信息与目标节点连接使用的安全密钥;
    所述第三参数用于计算第三安全密钥,所述第三安全密钥为应用单连接配置信息与所述目标节点连接使用的安全密钥。
  20. 根据权利要求19所述的方法,其中,所述向源节点发送由所述目标节点配置的第一参数或者由所述目标节点配置的第三参数,包括:
    向源节点发送终端的移动性管理的配置信息,所述终端的移动性管理的配置信息包括:由所述目标节点配置的第一参数或者由所述目标节点配置的第三参数。
  21. 根据权利要求20所述的方法,其中,所述终端的移动性管理的配置信息还包括以下一项或多项:
    用于与所述源节点和所述目标节点建立连接的双连接配置信息;
    用于与所述目标节点建立连接的单连接配置信息;
    所述第一安全密钥;
    所述第三安全密钥。
  22. 根据权利要求19所述的方法,还包括:
    根据双连接配置完成消息、随机接入请求消息、单连接配置完成消息中的一项或多项,确认终端的加密和/或完整性保护功能的激活;或者,
    根据双连接配置完成消息和随机接入请求消息中任一项携带的MAC-I或截短的MAC-I,确认终端的加密和/或完整性保护功能的激活。
  23. 一种终端,包括:
    第一确定模块,用于确定由目标节点配置的第一安全密钥,其中所述第一安全密钥为分别应用双连接配置信息和单连接配置信息与目标节点连接使用的安全密钥;或者,
    第二确定模块,用于确定由源节点配置的第二安全密钥和由目标节点配置的第三安全密钥,其中所述第二安全密钥为应用双连接配置信息与目标节点连接使用的安全密钥;所述第三安全密钥为应用单连接配置信息与所述目标节点连接使用的安全密钥。
  24. 一种目标节点,包括:
    第一确认模块,用于根据双连接配置完成消息、随机接入请求消息、单连接配置完成消息中的一项或多项,确认终端的加密和/或完整性保护功能的激活;或者,
    第二确认模块,用于根据双连接配置完成消息和随机接入请求消息中任一项携带的MAC-I或截短的MAC-I,确认终端的加密和/或完整性保护功能的激活。
  25. 一种源节点,包括:
    第五发送模块,用于向终端发送由目标节点配置的第一参数,或者发送由所述源节点配置的第二参数和由所述目标节点配置的第三参数;
    其中,所述第一参数用于计算第一安全密钥,所述第一安全密钥为分别应用双连接配置信息和单连接配置信息与目标节点连接使用的安全密钥;
    所述第二参数用于计算第二安全密钥,所述第二安全密钥为应用双连接配置信息与目标节点连接使用的安全密钥;
    所述第三参数用于计算第三安全密钥,所述第三安全密钥为应用单连接配置信息与所述目标节点连接使用的安全密钥。
  26. 一种目标节点,包括:
    第七发送模块,用于向源节点发送由所述目标节点配置的第一参数或者由所述目标节点配置的第三参数;
    其中,所述第一参数用于计算第一安全密钥,所述第一安全密钥为分别应用双连接配置信息和单连接配置信息与目标节点连接使用的安全密钥;
    所述第三参数用于计算第三安全密钥,所述第三安全密钥为应用单连接配置信息与所述目标节点连接使用的安全密钥。
  27. 一种终端,包括:处理器、存储器及存储在所述存储器上并可在所述处理器上运行的程序,所述程序被所述处理器执行时实现如权利要求1至8中任一项所述的处理方法的步骤。
  28. 一种网络设备,包括:处理器、存储器及存储在所述存储器上并可在所述处理器上运行的程序,所述程序被所述处理器执行时实现如权利要求9至12中任一项所述的处理方法的步骤;或者,实现如权利要求13至18中任一项所述的处理方法的步骤;或者,实现如权利要求19至22中任一项所述的处理方法的步骤。
  29. 一种计算机可读存储介质,所述计算机可读存储介质上存储有计算机程序,所述计算机程序被处理器执行时实现如权利要求1至8中任一项所述的处理方法的步骤;或者实现如权利要求9至12中任一项所述的处理方法的步骤;或者,实现如权利要求13至18中任一项所述的处理方法的步骤;或者,实现如权利要求19至22中任一项所述的处理方法的步骤。
PCT/CN2019/098811 2018-09-12 2019-08-01 处理方法和设备 Ceased WO2020052362A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201811064727.0 2018-09-12
CN201811064727.0A CN110896539B (zh) 2018-09-12 2018-09-12 处理方法和设备

Publications (1)

Publication Number Publication Date
WO2020052362A1 true WO2020052362A1 (zh) 2020-03-19

Family

ID=69776717

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2019/098811 Ceased WO2020052362A1 (zh) 2018-09-12 2019-08-01 处理方法和设备

Country Status (2)

Country Link
CN (2) CN110896539B (zh)
WO (1) WO2020052362A1 (zh)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2024145891A1 (en) * 2023-01-06 2024-07-11 Zte Corporation Method, device, and system for scg security in wireless networks

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104918242A (zh) * 2014-03-14 2015-09-16 中兴通讯股份有限公司 从基站密钥更新方法、从基站、终端及通信系统
WO2016042766A1 (en) * 2014-09-19 2016-03-24 Nec Corporation Apparatus for dual connectivity
CN105453672A (zh) * 2013-08-07 2016-03-30 交互数字专利控股公司 用于设备对设备通信的分布式调度

Family Cites Families (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2015006980A1 (zh) * 2013-07-19 2015-01-22 华为技术有限公司 加密参数处理方法和装置
EP3057349A1 (en) * 2013-11-01 2016-08-17 Huawei Technologies Co., Ltd. Dual connection mode key processing method and device
US9497673B2 (en) * 2013-11-01 2016-11-15 Blackberry Limited Method and apparatus to enable multiple wireless connections
CN104936174B (zh) * 2014-03-21 2019-04-19 上海诺基亚贝尔股份有限公司 在基于用户平面1a架构的双连接情形下更新密钥的方法
CN104219722B (zh) * 2014-05-23 2019-07-23 中兴通讯股份有限公司 双连接无线承载的迁移处理、迁移方法及装置
WO2016087588A1 (en) * 2014-12-05 2016-06-09 Nokia Solutions And Networks Oy Update of a mobility parameter in a system configured for dual connectivity
CN105848222B (zh) * 2015-01-16 2021-05-28 北京三星通信技术研究有限公司 用于切换的方法和基站设备

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105453672A (zh) * 2013-08-07 2016-03-30 交互数字专利控股公司 用于设备对设备通信的分布式调度
CN104918242A (zh) * 2014-03-14 2015-09-16 中兴通讯股份有限公司 从基站密钥更新方法、从基站、终端及通信系统
WO2016042766A1 (en) * 2014-09-19 2016-03-24 Nec Corporation Apparatus for dual connectivity

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
AT &T: "Key requirements for MR-DC and NR-NR DC", R2-1812408, 24 August 2018 (2018-08-24), XP051522008 *

Also Published As

Publication number Publication date
CN110896539A (zh) 2020-03-20
CN110896539B (zh) 2021-03-19
CN113038466B (zh) 2023-02-21
CN113038466A (zh) 2021-06-25

Similar Documents

Publication Publication Date Title
US20220353059A1 (en) Key processing method in dual connectivity mode and device
US20250392618A1 (en) Mobile communication method, apparatus, and device
US9713001B2 (en) Method and system for generating an identifier of a key
WO2022170994A1 (zh) Pc5根密钥处理方法、装置、ausf及远程终端
US20150269028A1 (en) Methods, apparatuses and computer program products enabling to improve handover security in mobile communication networks
US20240365112A1 (en) Method and apparatus for security context handling during inter-system change
JP2024538790A (ja) 内因性サービスの伝送方法、装置及び記憶媒体
CN109819439B (zh) 密钥更新的方法及相关实体
WO2020011223A1 (zh) 信号处理方法和设备
US20200067702A1 (en) Key generation method and related device
TWI670985B (zh) 處理雙連結的裝置及方法
WO2020052362A1 (zh) 处理方法和设备
CN107708113A (zh) 一种无线资源控制rrc连接重建立方法及装置
US8412159B2 (en) Method, apparatus and computer program product for security configuration coordination during a cell update procedure
CN110636520B (zh) 自动邻区关系协调方法、设备和计算机可读存储介质
CN109842484B (zh) 一种下一跳链计数器更新方法、装置及设备
WO2019154361A1 (zh) 连接控制方法和设备
US9485670B2 (en) Method, apparatus and computer program product for security configuration coordination during a cell update procedure
CN119856522A (zh) 无线电接入网络(ran)分解架构中的用户设备无线电资源控制非活动状态处理
CN110324868B (zh) 获取用户设备上下文信息的方法和网络侧设备
JP6393185B2 (ja) セル更新手続中におけるセキュリティ構成を一致させる方法,装置,およびコンピュータプログラム
CN110769481B (zh) 服务节点更新方法和设备
CN113676995B (zh) 终呼处理方法及装置、终端设备和网络设备
CN120836173A (zh) 用于在无线电资源控制状态改变期间将用户设备的上下文存储在数据库中的方法和装置
CN110012535A (zh) 跟踪区更新周期确定方法、用户设备和网络侧设备

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 19859882

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 19859882

Country of ref document: EP

Kind code of ref document: A1