WO2020164399A1 - 密钥生成方法、切换方法、装置、网络设备和存储介质 - Google Patents
密钥生成方法、切换方法、装置、网络设备和存储介质 Download PDFInfo
- Publication number
- WO2020164399A1 WO2020164399A1 PCT/CN2020/074197 CN2020074197W WO2020164399A1 WO 2020164399 A1 WO2020164399 A1 WO 2020164399A1 CN 2020074197 W CN2020074197 W CN 2020074197W WO 2020164399 A1 WO2020164399 A1 WO 2020164399A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- parameter
- network device
- terminal
- encryption key
- value
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0891—Revocation or update of secret information, e.g. encryption key update or rekeying
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0861—Generation of secret information including derivation or calculation of cryptographic keys or passwords
- H04L9/0866—Generation of secret information including derivation or calculation of cryptographic keys or passwords involving user or device identifiers, e.g. serial number, physical or biometrical information, DNA, hand-signature or measurable physical characteristics
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/04—Key management, e.g. using generic bootstrapping architecture [GBA]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W36/00—Hand-off or reselection arrangements
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W36/00—Hand-off or reselection arrangements
- H04W36/0005—Control or signalling for completing the hand-off
- H04W36/0011—Control or signalling for completing the hand-off for data sessions of end-to-end connection
- H04W36/0033—Control or signalling for completing the hand-off for data sessions of end-to-end connection with transfer of context information
- H04W36/0038—Control or signalling for completing the hand-off for data sessions of end-to-end connection with transfer of context information of security context information
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W36/00—Hand-off or reselection arrangements
- H04W36/08—Reselecting an access point
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/80—Wireless
Definitions
- This application relates to wireless technology, and in particular to a key generation method, switching method, device, network device, and storage medium.
- the encryption key of the Packet Data Convergence Protocol is based on the physical cell identifier (PCI, Physical Cell Identifier) and frequency point generation; here, the frequency point is the downlink evolved absolute radio frequency channel number (EARFCN-DL) of the target cell.
- PCI Physical Cell identifier
- ERFN-DL downlink evolved absolute radio frequency channel number
- the main purpose of the embodiments of the present application is to provide a key generation method, switching method, device, network equipment, and storage medium.
- the embodiment of the present application provides a method for generating a key, the method is applied to a network device or a terminal, and the method includes: configuring an input parameter; the input parameter includes a first parameter and/or a second parameter; The value of a parameter and/or the second parameter is related to the network device; an encryption key is determined based on the input parameter, and the encryption key is used to encrypt and complete the communication between the network device and the terminal Sexual protection.
- the value of the first parameter is the identity of at least part of the network device; the value of the second parameter is the identity of at least part of the network device assigned to the terminal .
- the identifier of the network device is one of the following: the identity (ID) of the network device itself; the ID of the centralized unit (CU, Centralized Unit) of the network device .
- the identity identifier assigned by the network device to the terminal is a unique identity identifier of the terminal within the coverage of the network device.
- the network device configuration input parameter includes: the type of the configuration input parameter and the corresponding value range, and the input is determined based on the type of the input parameter and the corresponding value range The value of the parameter.
- An embodiment of the application provides a handover method, the method includes: when a network device determines that a terminal is handed over from the current cell to another cell within the coverage of the network device, keeping the first parameter and/or the second parameter unchanged The value of the first parameter and/or the second parameter is related to the network device; the first parameter and/or the second parameter is used to determine the encryption and integrity of the communication between the network device and the terminal The first encryption key for sexual protection; the network device communicates with the terminal based on the first encryption key.
- the value of the first parameter is the identity of at least part of the network device; the value of the second parameter is the identity of at least part of the network device assigned to the terminal .
- the method further includes: the network device restarts the update timing
- the update timer is used to time the update period of the first parameter and/or the second parameter; in the case where the update timer expires, the network device updates the second parameter,
- the second encryption key is determined according to the updated second parameter; the network device communicates with the terminal based on the second encryption key.
- the method when the update timer expires, the method further includes: the network device sends connection reconfiguration information to the terminal, where the connection reconfiguration information includes: The second encryption key, the second encryption key is used by the terminal to perform packet data convergence protocol (PDCP, Packet Data Convergence Protocol) reconfiguration.
- PDCP Packet Data Convergence Protocol
- the method further includes: when the network device determines that the terminal switches to the target network device, updating the first parameter and/or the second parameter, and the updated first parameter The value of a parameter and/or the second parameter is related to the target network device; the network device determines a third encryption key according to the updated first parameter and/or second parameter;
- the network device sends handover reconfiguration information to the target network device, where the handover reconfiguration information includes the third encryption key, and the third encryption key is used for the target network device to perform PDCP reconfiguration.
- An embodiment of the application provides a key generation device, the device is applied to a network device or a terminal, and the device includes: a configuration module and a determination module; wherein,
- the configuration module is configured to configure input parameters; the input parameters include a first parameter and/or a second parameter; the value of the first parameter and/or the second parameter is related to a network device;
- the determining module is configured to determine an encryption key based on the input parameter, and the encryption key is used to encrypt and protect the integrity of the communication between the network device and the terminal.
- the value of the first parameter is the identity of at least part of the network device; the value of the second parameter is the identity of at least part of the network device assigned to the terminal .
- the identifier of the network device is one of the following: the ID of the network device itself; the ID of the CU of the network device.
- the identity identifier assigned by the network device to the terminal is a unique identity identifier of the terminal within the scope of the network device.
- the configuration module is configured to configure the type of input parameter and the corresponding value range, and determine the value of the input parameter based on the type of the input parameter and the corresponding value range. value.
- An embodiment of the present application provides a network device, the network device includes: a first processing module and a second processing module; wherein, the first processing module is configured to determine that the terminal is handed over from the current cell to the network device When covering other cells in the coverage area, keep the first parameter and/or the second parameter unchanged; the value of the first parameter and/or the second parameter is related to the network device; the first parameter and/or The second parameter is used to determine the first encryption key used to encrypt and protect the integrity of the communication between the network device and the terminal;
- the second processing module is configured to communicate with the terminal based on the first encryption key.
- the value of the first parameter is the identity of at least part of the network device; the value of the second parameter is the identity of at least part of the network device assigned to the terminal .
- the first processing module is further configured to restart the update timer after determining that the terminal is handed over from the current cell to another cell within the coverage of the network device;
- the update timer is used to time the update period of the first parameter and/or the second parameter; in the case that the update timer expires, the second parameter is updated according to the updated second parameter.
- the parameter determines the second encryption key
- the second processing module is further configured to communicate with the terminal based on the second encryption key.
- the first processing module is further configured to send connection reconfiguration information to the terminal when the update timer expires, where the connection reconfiguration information includes: The second encryption key, so that the terminal performs PDCP reconfiguration based on the second encryption key.
- the first processing module is further configured to update the first parameter and/or the second parameter when it is determined that the terminal is switched to the target network device, and the updated The values of the first parameter and/or the second parameter are related to the target network device; determine a third encryption key according to the updated first parameter and/or second parameter; send to the target network device Handover reconfiguration information, where the handover reconfiguration information includes the third encryption key, and the third encryption key is used for the target network device to perform PDCP reconfiguration.
- An embodiment of the application provides a key generation device, including a memory, a processor, and a computer program stored in the memory and capable of running on the processor.
- the processor implements any of the above items when the program is executed. Steps of the key generation method.
- An embodiment of the present application provides a network device, including a memory, a processor, and a computer program stored in the memory and capable of running on the processor, and the processor implements any of the switching methods described above when the program is executed A step of.
- the embodiment of the present application also provides a computer-readable storage medium on which a computer program is stored, and when the computer program is executed by a processor, the steps of any one of the key generation methods described above are implemented; or, the computer When the program is executed by the processor, the steps of any one of the above switching methods are realized.
- the key generation method includes: configuring input parameters; the input parameters include the first parameter and/or the first parameter Two parameters; the value of the first parameter and/or the second parameter is related to the network device; the encryption key is determined based on the input parameter, and the encryption key is used to communicate between the network device and the terminal Encryption and integrity protection of communications.
- using the above key generation method during handover includes: when the network device determines that the terminal is handed over from the current cell to another cell within the coverage of the network device, keeping the first parameter and/or the second parameter unchanged; The value of a parameter and/or a second parameter is related to the network device; the first parameter and/or the second parameter are used to determine the first parameter for encrypting and integrity protection of the communication between the network device and the terminal An encryption key; communicating with the terminal based on the first encryption key.
- the encryption key KeNB* does not need to be updated in synchronization with the handover, and the PDCP re-establishment process does not occur, reducing PDCP re-establishment frequency.
- FIG. 1 is a schematic flowchart of a key generation method provided by an embodiment of this application.
- FIG. 2 is a schematic flowchart of another key generation method provided by an embodiment of the application.
- FIG. 3 is a schematic flowchart of a handover method provided by an embodiment of this application.
- FIG. 5 is a schematic structural diagram of a key generation device provided by an embodiment of this application.
- FIG. 6 is a schematic structural diagram of a network device provided by an embodiment of this application.
- FIG. 7 is a schematic structural diagram of an electronic device provided by an embodiment of the application.
- the key generation method includes: configuring an input parameter; the input parameter includes a first parameter and/or a second parameter; taking the first parameter and/or the second parameter The value is related to the network device; an encryption key is determined based on the input parameter, and the encryption key is used to encrypt and protect the integrity of the communication between the network device and the terminal.
- the handover method includes: when the network device determines that the terminal is handed over from the current cell to another cell in the current network device, keeping the first parameter and/or the second parameter unchanged; the selection of the first parameter and/or the second parameter The value is related to the network device; the first parameter and/or the second parameter are used to determine the first encryption key that encrypts and protects the integrity of the communication between the network device and the terminal; the network device is based on the The first encryption key communicates with the terminal.
- Figure 1 is a schematic flowchart of a key generation method provided by an embodiment of the application; the method can be applied to a network device or a terminal, where the network device can be an access network device, and the access network device can be various A base station in a mobile communication network, such as an evolutionary base station (eNB, Evolutional Node B), a 5G network base station (gNB), and so on.
- the method includes:
- Step 101 Configure input parameters; the input parameters include a first parameter and/or a second parameter; the values of the first parameter and/or the second parameter are related to a network device.
- the value of the first parameter is the identity of at least part of the network device; the value of the second parameter is the identity of at least part of the network device assigned to the terminal.
- the identifier of the network device is one of the following: the identity of the network device itself; the ID of the CU of the network device.
- the identity identifier assigned by the network device to the terminal is a unique identity identifier of the terminal within the coverage of the network device.
- Step 102 Determine an encryption key (for example, KeNB*) based on the input parameters, where the encryption key is used to encrypt and protect the integrity of the communication between the network device and the terminal.
- an encryption key for example, KeNB*
- determining the encryption key based on the input parameter includes: inputting the input parameter into a prescribed key derivation function (KDF, Key Derivation Function) to determine the encryption key.
- KDF Key Derivation Function
- the input parameters input to the KDF may specifically include:
- L1 the length of the second parameter.
- the configuring input parameters may include: configuring the type of the input parameter and the corresponding value range, and determining the input parameter based on the type of the input parameter and the corresponding value range Value.
- both the terminal and the network device can use the KDF to determine the encryption key.
- the terminal uses the above key generation method to generate the encryption key
- the terminal receives the relevant parameters (for example, the first parameter and/or the second parameter) allocated by the network device, and moves on the terminal.
- the encryption key can be generated according to the received relevant parameters.
- Fig. 2 is a schematic flowchart of another key generation method provided by an embodiment of the application; the method can be applied to a network device or a terminal. As shown in Fig. 2, the method includes:
- Step 201 Configure input parameters.
- the first parameter (denoted as P0) and/or the second parameter (denoted as P1) in the input parameters of the KDF is configured; specifically, P0 and P1 are defined as the cell and frequency point where the terminal is located. Irrelevant and related to the network equipment connected to the terminal.
- the value of P0 may be at least part of the identification of the network device; for example, the ID of the network device itself, the ID of the centralized unit (for example, gNB-CU) of the network device.
- the value of P1 is an identification assigned to the terminal by at least part of the network device.
- the identity identifier assigned by the network device to the terminal is a unique identity identifier of the terminal within the coverage area of the network device, such as: a temporary wireless network identifier (gNB-RNTI, gNB Radio Network Temporary Identifier) within the coverage area of the network device ,
- the gNB-RNTI is the unique ID of the terminal in the coverage of the entire gNB.
- a method for defining gNB-RNTI including: defining an existing common radio network temporary identifier (C-RNTI, Common Radio Network Temporary Identifier) from cell-level parameter adjustment to gNB-level parameters, That is, the C-RNTI is adjusted to a unique ID within the coverage of the gNB (that is, gNB-RNTI).
- C-RNTI Common Radio Network Temporary Identifier
- the C-RNTI of the terminal in the related technology is a cell-level parameter, that is, each C-RNTI has a unique value in a cell, and the C-RNTI in different cells has an independent value.
- adjusting the C-RNTI to a gNB-level parameter means that the C-RNTI allocated by the network device to the terminal is unique and unchanged within a gNB.
- bits of a certain length (denoted as LenP0) can be intercepted as the first parameter The value of P0.
- gNB_CU_ID_Part means to take a part of gNB-CU ID
- L0 LenP0
- LenP0 represents the length of the partial gNB-CU ID taken.
- P1 gNB-RNTI, where the gNB-RNTI represents the dedicated ID allocated by the network equipment to the terminal;
- L1 LenP1
- the LenP1 represents the length of gNB-RNTI.
- Step 202 Determine an encryption key based on the input parameter, where the encryption key is used to encrypt and protect the integrity of the communication between the network device and the terminal.
- step 202 in this embodiment please refer to the description of step 102 in the foregoing embodiment, which will not be repeated here.
- FIG. 3 is a schematic flowchart of a handover method provided by an embodiment of the application; the method is applied to a network device, as shown in FIG. 3, the method includes:
- Step 301 When the network device determines that the terminal is handed over from the current cell to another cell within the coverage of the network device, it keeps the first parameter and/or the second parameter unchanged; the value of the first parameter and/or the second parameter The value is related to the network device; the first parameter and/or the second parameter are used to determine the first encryption key for encrypting and integrity protecting the communication between the network device and the terminal.
- the value of the first parameter is at least part of the identification of the network device.
- the value of the second parameter is an identification assigned to the terminal by at least part of the network device.
- Step 302 The network device communicates with the terminal based on the first encryption key.
- the method may further include: the network device restarts an update timer; the update The timer is used to time the update period of the first parameter and/or the second parameter; in the case that the update timer expires, the network device updates the second parameter according to the updated The second parameter determines a second encryption key; the network device communicates with the terminal based on the second encryption key.
- the method further includes: the network device sends connection reconfiguration information to the terminal, and the connection reconfiguration information includes: the second encryption A key, the second encryption key is used for the terminal to perform PDCP reconfiguration.
- the method may further include: when the network device determines that the terminal is switched to the target network device, updating the first parameter and/or the second parameter, and the updated The values of the first parameter and/or the second parameter are related to the target network device; the network device determines the third encryption key according to the updated first parameter and/or second parameter; the network The device sends handover reconfiguration information to the target network device, where the handover reconfiguration information includes the third encryption key, and the third encryption key is used for the target network device to perform PDCP reconfiguration.
- the terminal needs to perform PDCP reconfiguration based on the second encryption key.
- This process may also involve the terminal generating its own encryption key (KeNB*).
- the terminal can receive the relevant parameters of the target network device sent by the network device (specifically, it can include: the identity of the target network device, the identity of the target network device assigned to the terminal, etc.), and use the above-mentioned figure 1 The method to generate KeNB* will not be repeated here.
- FIG. 4 is a schematic flowchart of another handover method provided by an embodiment of the application; as shown in FIG. 4, the method includes:
- Step 401 The radio resource management (RRM, Radio Resource Management) of the source network device (such as the source gNB) makes a handover decision, and judges whether the handover is a cell handover within the coverage of the source network device or between network devices Handover; when it is determined that this handover is a handover between different cells within the coverage of the source network device, go to step 402; when it is determined to be a handover between network devices, go to step 403.
- the switching between network devices refers to switching from a source network device to a target network device (Target gNB).
- Step 402 The source network device does not change the value of the first parameter (denoted as P0) and/or the second parameter (denoted as P1), and directly switches from the current cell accessed by the terminal to another within the coverage of the source network equipment. Community.
- the method may further include steps 402a to 402b: the source network device restarts the update timer, and when the update timer expires, the source network device Reconfigure the P1, and use the method shown in Figure 1 above to determine a new encryption key based on the reconfigured P1, which is recorded as the first KeNB*; the source network device is based on the determined first KeNB* and the terminal To communicate.
- the value of P1 is an idle gNB-RNTI allocated to the terminal by the source network device.
- the update timer is used to time the update period of P0 and/or P1.
- the update cycle is preset and saved by the developer.
- the method further includes: the source network device sends connection reconfiguration information to the terminal, where the connection reconfiguration information includes : The first KeNB*, so that the terminal performs PDCP reconfiguration based on the determined first KeNB*.
- RRC Radio Resource Control
- RRC Connection Reconfiguration also known as the handover (Handover) process reconfiguration Configure the terminal.
- Step 403 Re-assign P0 and/or P1, generate a new encryption key, record it as the second KeNB*, and initiate a handover reconfiguration process between network devices.
- the step 403 may include: the source network device determines that the terminal switches to the target network device, the source network device updates P0 and/or P1, and the updated The value of P0 and/or P1 is related to the target network device; the source network device generates a second KeNB* according to the updated P0 and/or P1; the source network device sends a handover reconfiguration to the target network device Information, the handover reconfiguration information includes the second KeNB*, so that the target network device performs PDCP reconfiguration based on the second KeNB*.
- the source network device sends handover reconfiguration information to the target network device, which can be implemented through step 403a in the figure: the source network device may send an RRC Connection Reconfiguration message to the target network device.
- the RRC The connection reconfiguration message may carry the second KeNB*.
- FIG. 5 is a schematic structural diagram of a key generation device provided by an embodiment of the application; the device can be applied to a network device or a terminal, as shown in FIG. 5, the device includes: a configuration module 51 and a determination module 52;
- the configuration module 51 is configured to configure input parameters; the input parameters include a first parameter and/or a second parameter; the value of the first parameter and/or the second parameter is related to a network device.
- the determining module 52 is configured to determine an encryption key based on the input parameters, and the encryption key is used to encrypt and protect the integrity of the communication between the network device and the terminal.
- the value of the first parameter is the identity of at least part of the network device; the value of the second parameter is the identity of at least part of the network device assigned to the terminal .
- the identifier of the network device is one of the following: the ID of the network device itself; the ID of the CU of the network device.
- the identity identifier assigned by the network device to the terminal is a unique identity identifier of the terminal within the scope of the network device.
- the configuration module 51 is configured to configure the type of the input parameter and the corresponding value range, and determine the input parameter based on the type of the input parameter and the corresponding value range. Value.
- the key generation device provided in the above embodiment performs key generation
- only the division of the above-mentioned program modules is used as an example.
- the above-mentioned processing can be allocated to different program modules as needed.
- Complete that is, divide the internal structure of the device into different program modules to complete all or part of the processing described above.
- the key generation device provided in the foregoing embodiment and the key generation method embodiment belong to the same concept, and the specific implementation process is detailed in the method embodiment, which will not be repeated here.
- Fig. 6 is a schematic structural diagram of a network device provided by an embodiment of the application; as shown in Fig. 6, the network device includes: a first processing module 61 and a second processing module 62; wherein,
- the first processing module 61 is configured to keep the first parameter and/or the second parameter unchanged when determining that the terminal is handed over from the current cell to another cell within the coverage of the network device; the first parameter and/ Or the value of the second parameter is related to the network device; the first parameter and/or the second parameter are used to determine the first encryption key for encrypting and integrity protecting the communication between the network device and the terminal ;
- the second processing module 62 is configured to communicate with the terminal based on the first encryption key.
- the value of the first parameter is the identity of at least part of the network device; the value of the second parameter is the identity of at least part of the network device assigned to the terminal .
- the first processing module 61 is further configured to restart the update timer after determining that the terminal is handed over from the current cell to another cell within the coverage of the network device;
- the update timer is used to time the update period of the first parameter and/or the second parameter; in the case that the update timer expires, the second parameter is updated according to the updated first parameter
- the second parameter determines the second encryption key
- the second processing module 62 is configured to communicate with the terminal based on the second encryption key.
- the first processing module 61 is further configured to send connection reconfiguration information to the terminal when the update timer expires, where the connection reconfiguration information includes : The second encryption key, which is used for the terminal to perform PDCP reconfiguration.
- the first processing module 61 is further configured to update the first parameter and/or the second parameter when it is determined that the terminal switches to the target network device, and the updated all The value of the first parameter and/or the second parameter is related to the target network device; the third encryption key is determined according to the updated first parameter and/or the second parameter; and the switch is sent to the target network device Reconfiguration information, where the handover reconfiguration information includes the third encryption key, and the third encryption key is used for the target network device to perform PDCP reconfiguration.
- the network device provided in the above embodiment is switched, only the division of the above-mentioned program modules is used as an example for illustration.
- the above-mentioned processing can be allocated by different program modules as needed, that is, the network
- the internal structure of the device is divided into different program modules to complete all or part of the processing described above.
- the network equipment provided in the foregoing embodiment and the handover method embodiment belong to the same concept, and the specific implementation process is detailed in the method embodiment, which will not be repeated here.
- FIG. 7 is a schematic diagram of the hardware composition structure of an electronic device according to an embodiment of the application.
- the electronic device includes a memory 72, a processor 71, and a computer program stored in the memory 72 and running on the processor 71.
- the processor 71 implements the steps of the key generation method or the switching method described in the embodiment of the present application when the program is executed.
- the electronic device further includes a communication interface 73 and a bus system 74.
- the various components in the electronic device can be coupled together through the bus system 74.
- the bus system 74 is used to implement connection and communication between these components.
- the bus system 74 also includes a power bus, a control bus, and a status signal bus.
- various buses are marked as the bus system 74 in FIG. 7.
- the memory 72 may be a volatile memory or a non-volatile memory, and may also include both volatile and non-volatile memory.
- the non-volatile memory can be a read only memory (ROM, Read Only Memory), a programmable read only memory (PROM, Programmable Read-Only Memory), an erasable programmable read only memory (EPROM, Erasable Programmable Read- Only Memory, Electrically Erasable Programmable Read-Only Memory (EEPROM, Electrically Erasable Programmable Read-Only Memory), magnetic random access memory (FRAM, ferromagnetic random access memory), flash memory (Flash Memory), magnetic surface memory , CD-ROM, or CD-ROM (Compact Disc Read-Only Memory); magnetic surface memory can be magnetic disk storage or tape storage.
- the volatile memory may be random access memory (RAM, Random Access Memory), which is used as an external cache.
- RAM random access memory
- SRAM Static Random Access Memory
- SSRAM synchronous static random access memory
- DRAM Dynamic Random Access Memory
- SDRAM Synchronous Dynamic Random Access Memory
- DDRSDRAM Double Data Rate Synchronous Dynamic Random Access Memory
- ESDRAM enhanced -Type synchronous dynamic random access memory
- SLDRAM SyncLink Dynamic Random Access Memory
- direct memory bus random access memory DRRAM, Direct Rambus Random Access Memory
- DRRAM Direct Rambus Random Access Memory
- the memory 72 described in the embodiment of the present application is intended to include, but is not limited to, these and any other suitable types of memory.
- the method disclosed in the above embodiments of the present application may be applied to the processor 71 or implemented by the processor 71.
- the processor 71 may be an integrated circuit chip with signal processing capability. In the implementation process, the steps of the foregoing method can be completed by hardware integrated logic circuits in the processor 71 or instructions in the form of software.
- the aforementioned processor 71 may be a general-purpose processor, a DSP, or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, and the like.
- the processor 71 may implement or execute various methods, steps, and logical block diagrams disclosed in the embodiments of the present application.
- the general-purpose processor may be a microprocessor or any conventional processor.
- the steps of the method disclosed in the embodiments of the present application can be directly embodied as being executed and completed by a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor.
- the software module may be located in a storage medium, and the storage medium is located in the memory 72.
- the processor 71 reads the information in the memory 72 and completes the steps of the foregoing method in combination with its hardware.
- the electronic device may be used by one or more application specific integrated circuits (ASIC, Application Specific Integrated Circuit), DSP, programmable logic device (PLD, Programmable Logic Device), complex A programmable logic device (CPLD, Complex Programmable Logic Device), FPGA, general-purpose processor, controller, MCU, microprocessor (Microprocessor), or other electronic components are implemented to implement the foregoing methods.
- ASIC Application Specific Integrated Circuit
- DSP digital signal processor
- PLD programmable logic device
- CPLD Complex Programmable Logic Device
- FPGA general-purpose processor
- controller MCU
- microprocessor Microprocessor
- the embodiment of the present application also provides a computer storage medium, such as a memory 72 including a computer program, which can be executed by a processor 71 of a terminal or a network device to complete the steps described in the foregoing method.
- the computer storage medium may be FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disk, or CD-ROM, etc.; it may also be various devices including one or any combination of the foregoing memories.
- the computer storage medium provided by the embodiment of the present application has computer instructions stored thereon, and when the computer program is executed by the processor, the steps of the key generation method described in the embodiment of the present application are implemented; or, the computer program is executed by the processor When implementing the steps of the switching method described in the embodiment of the present application.
- the disclosed device and method may be implemented in other ways.
- the device embodiments described above are merely illustrative.
- the division of the units is only a logical function division, and there may be other divisions in actual implementation, such as: multiple units or components can be combined, or It can be integrated into another system, or some features can be ignored or not implemented.
- the coupling, or direct coupling, or communication connection between the components shown or discussed may be indirect coupling or communication connection through some interfaces, devices or units, and may be in electrical, mechanical or other forms. of.
- the units described above as separate components may or may not be physically separate, and the components displayed as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units; Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of the embodiment.
- the functional units in the embodiments of the present application can all be integrated into one processing unit, or each unit can be individually used as a unit, or two or more units can be integrated into one unit;
- the unit can be implemented in the form of hardware, or in the form of hardware plus software functional units.
- the foregoing program can be stored in a computer readable storage medium. When the program is executed, it is executed. Including the steps of the foregoing method embodiment; and the foregoing storage medium includes: various media that can store program codes, such as a mobile storage device, ROM, RAM, magnetic disk, or optical disk.
- the above-mentioned integrated unit of this application is implemented in the form of a software function module and sold or used as an independent product, it can also be stored in a computer readable storage medium.
- the computer software product is stored in a storage medium and includes several instructions for A computer device (which may be a personal computer, a server, or a network device, etc.) executes all or part of the methods described in the various embodiments of the present application.
- the aforementioned storage media include: removable storage devices, ROM, RAM, magnetic disks, or optical disks and other media that can store program codes.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Security & Cryptography (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
本申请实施例公开了一种密钥生成方法,包括:配置输入参数;所述输入参数包括第一参数和/或第二参数;所述第一参数和/或所述第二参数的取值与网络设备相关;基于所述输入参数确定加密密钥,所述加密密钥用于对所述网络设备与终端之间的通信进行加密以及完整性保护。本申请实施例还公开了一种密钥生成装置、切换方法、网络设备和计算机可读存储介质。
Description
相关申请的交叉引用
本申请基于申请号为201910118103.0、申请日为2019年2月15日的中国专利申请提出,并要求该中国专利申请的优先权,该中国专利申请的全部内容在此以引入方式并入本申请。
本申请涉及无线技术,尤其涉及一种密钥生成方法、切换方法、装置、网络设备和存储介质。
在第五代移动通信技术(5G,5th-Generation)中,在进行小区间切换时,分组数据汇聚协议(PDCP,Packet Data Convergence Protocol)加密的密钥根据目标小区的物理小区标识符(PCI,Physical Cell Identifier)和频点生成;这里,所述频点为目标小区的下行链路演进绝对射频信道号(EARFCN-DL)。
基于上述5G中现有的方案,终端在移动切换时,随着小区切换,目标小区的PCI和频点会随之变化,则需更新加密密钥KeNB*,并根据新的KeNB*进行PDCP重建立;从而每次进行小区切换都需发起PDCP重建立过程(Reestablishment)。
发明内容
本申请实施例的主要目的在于提供一种密钥生成方法、切换方法、装置、网络设备和存储介质。
本申请实施例的技术方案是这样实现的:
本申请实施例提供了一种密钥生成方法,所述方法应用于网络设备或终端,所述方法包括:配置输入参数;所述输入参数包括第一参数和/或第二参数;所述第一参数和/或所述第二参数的取值与网络设备相关;基于所述输入参数确定加密密钥,所述加密密钥用于对所述网络设备与终端之间的通信进行加密以及完整性保护。
在本申请的一些可选实施例中,所述第一参数的取值为至少部分所述网络设备的标识;所述第二参数的取值为至少部分所述网络设备为终端分配的身份标识。
在本申请的一些可选实施例中,所述网络设备的标识为以下之一:所述网络设备自身的身份标识(ID);所述网络设备的集中式单元(CU,Centralized Unit)的ID。
在本申请的一些可选实施例中,所述网络设备为终端分配的身份标识为所述终端在所述网络设备的覆盖范围内的唯一身份标识。
在本申请的一些可选实施例中,所述网络设备配置输入参数,包括:配置输入参数的类型以及对应的取值范围,基于所述输入参数的类型以及对应的取值范围确定所述输入参数的取值。
本申请实施例提供了一种切换方法,所述方法包括:网络设备确定终端由当前小区切换到所述网络设备的覆盖范围内的其他小区时,保持第一参数和/或第二参数不变;所述第一参数和/或第二参数的取值与所述网络设备相关;所述第一参数和/或第二参数用以确定对所述网络设备与终端之间通信进行加密以及完整性保护的第一加密密钥;所述网络设备基于所述第一加密密钥与所述终端进行通信。
在本申请的一些可选实施例中,所述第一参数的取值为至少部分所述网络设备的标识;所述第二参数的取值为至少部分所述网络设备为终端分 配的身份标识。
在本申请的一些可选实施例中,所述网络设备确定所述终端由当前小区切换到所述网络设备的覆盖范围内的其他小区后,所述方法还包括:所述网络设备重启更新定时器;所述更新定时器用于对所述第一参数和/或所述第二参数的更新周期进行计时;在所述更新定时器超时的情况下,所述网络设备更新所述第二参数,根据更新的所述第二参数确定第二加密密钥;所述网络设备基于所述第二加密密钥与所述终端进行通信。
在本申请的一些可选实施例中,在所述更新定时器超时的情况下,所述方法还包括:所述网络设备向所述终端发送连接重配置信息,所述连接重配置信息包括:所述第二加密密钥,所述第二加密密钥用于所述终端进行分组数据汇聚协议(PDCP,Packet Data Convergence Protocol)重配置。
在本申请的一些可选实施例中,所述方法还包括:所述网络设备确定所述终端切换到目标网络设备时,更新所述第一参数和/或第二参数,更新的所述第一参数和/或所述第二参数的取值与所述目标网络设备相关;所述网络设备根据更新的所述第一参数和/或第二参数确定第三加密密钥;
所述网络设备向所述目标网络设备发送切换重配置信息,所述切换重配置信息包括所述第三加密密钥,所述第三加密密钥用于所述目标网络设备进行PDCP重配置。
本申请实施例提供了一种密钥生成装置,所述装置应用于网络设备或终端,所述装置包括:配置模块和确定模块;其中,
所述配置模块,配置为配置输入参数;所述输入参数包括第一参数和/或第二参数;所述第一参数和/或所述第二参数的取值与网络设备相关;
所述确定模块,配置为基于所述输入参数确定加密密钥,所述加密密钥用于对所述网络设备与终端之间的通信进行加密以及完整性保护。
在本申请的一些可选实施例中,所述第一参数的取值为至少部分所述 网络设备的标识;所述第二参数的取值为至少部分所述网络设备为终端分配的身份标识。
在本申请的一些可选实施例中,所述网络设备的标识为以下之一:所述网络设备自身的ID;所述网络设备的CU的ID。
在本申请的一些可选实施例中,所述网络设备为终端分配的身份标识为所述终端在所述网络设备的范围内的唯一身份标识。
在本申请的一些可选实施例中,所述配置模块,配置为配置输入参数的类型以及对应的取值范围,基于所述输入参数的类型以及对应的取值范围确定所述输入参数的取值。
本申请实施例提供了一种网络设备,所述网络设备包括:第一处理模块和第二处理模块;其中,所述第一处理模块,配置为确定终端由当前小区切换到所述网络设备的覆盖范围内的其他小区时,保持第一参数和/或第二参数不变;所述第一参数和/或第二参数的取值与所述网络设备相关;所述第一参数和/或第二参数用以确定对所述网络设备与终端之间通信进行加密以及完整性保护的第一加密密钥;
所述第二处理模块,配置为基于所述第一加密密钥与所述终端进行通信。
在本申请的一些可选实施例中,所述第一参数的取值为至少部分所述网络设备的标识;所述第二参数的取值为至少部分所述网络设备为终端分配的身份标识。
在本申请的一些可选实施例中,所述第一处理模块,还配置为在确定所述终端由当前小区切换到所述网络设备的覆盖范围内的其他小区后,重启更新定时器;所述更新定时器用于对所述第一参数和/或所述第二参数的更新周期进行计时;在所述更新定时器超时的情况下,更新所述第二参数,根据更新的所述第二参数确定第二加密密钥;
所述第二处理模块,还配置为基于所述第二加密密钥与所述终端进行通信。
在本申请的一些可选实施例中,所述第一处理模块,还配置为在所述更新定时器超时的情况下,向所述终端发送连接重配置信息,所述连接重配置信息包括:所述第二加密密钥,以使所述终端基于所述第二加密密钥进行PDCP重配置。
在本申请的一些可选实施例中,所述第一处理模块,还配置为在确定所述终端切换到目标网络设备时,更新所述第一参数和/或第二参数,更新的所述第一参数和/或所述第二参数的取值与所述目标网络设备相关;根据更新的所述第一参数和/或第二参数确定第三加密密钥;向所述目标网络设备发送切换重配置信息,所述切换重配置信息包括所述第三加密密钥,所述第三加密密钥用于所述目标网络设备进行PDCP重配置。
本申请实施例提供了一种密钥生成装置,包括存储器、处理器及存储在存储器上并可在处理器上运行的计算机程序,所述处理器执行所述程序时实现以上任一项所述密钥生成方法的步骤。
本申请实施例提供了一种网络设备,包括存储器、处理器及存储在存储器上并可在处理器上运行的计算机程序,所述处理器执行所述程序时实现以上任一项所述切换方法的步骤。
本申请实施例还提供了一种计算机可读存储介质,其上存储有计算机程序,所述计算机程序被处理器执行时实现以上任一项所述密钥生成方法的步骤;或者,所述计算机程序被处理器执行时实现以上任一项所述切换方法的步骤。
本申请实施例所提供的密钥生成方法、切换方法、装置、网络设备和计算机可读存储介质,所述密钥生成方法包括:配置输入参数;所述输入参数包括第一参数和/或第二参数;所述第一参数和/或所述第二参数的取值 与网络设备相关;基于所述输入参数确定加密密钥,所述加密密钥用于对所述网络设备与终端之间的通信进行加密以及完整性保护。另外,切换时运用上述密钥生成方法包括:网络设备确定终端由当前小区切换到所述网络设备的覆盖范围内的其他小区时,保持第一参数和/或第二参数不变;所述第一参数和/或第二参数的取值与所述网络设备相关;所述第一参数和/或第二参数用以确定对所述网络设备与终端之间通信进行加密以及完整性保护的第一加密密钥;基于所述第一加密密钥与所述终端进行通信。采用本申请实施例的技术方案,终端在一定范围内(如在同一网络设备内)进行小区切换时,加密密钥KeNB*无需与切换同步进行更新,PDCP不发生重建立过程,降低PDCP重建立次数。
图1为本申请实施例提供的一种密钥生成方法的流程示意图;
图2为本申请实施例提供的另一种密钥生成方法的流程示意图;
图3为本申请实施例提供的一种切换方法的流程示意图;
图4为本申请实施例提供的另一种切换方法的流程示意图;
图5为本申请实施例提供的一种密钥生成装置的结构示意图;
图6为本申请实施例提供的一种网络设备的结构示意图;
图7为本申请实施例提供的一种电子设备的结构示意图。
在本申请的各种实施例中,密钥生成方法包括:配置输入参数;所述输入参数包括第一参数和/或第二参数;所述第一参数和/或所述第二参数的取值与网络设备相关;基于所述输入参数确定加密密钥,所述加密密钥用于对所述网络设备与终端之间的通信进行加密以及完整性保护。所述切换方法包括:网络设备确定终端由当前小区切换到当前网络设备内的其他小 区时,保持第一参数和/或第二参数不变;所述第一参数和/或第二参数的取值与所述网络设备相关;所述第一参数和/或第二参数用以确定对所述网络设备与终端之间通信进行加密以及完整性保护的第一加密密钥;网络设备基于所述第一加密密钥与所述终端进行通信。
下面结合附图及具体实施例对本申请实施例作进一步详细的说明。
图1为本申请实施例提供的一种密钥生成方法的流程示意图;所述方法可以应用于网络设备或终端,其中,网络设备可以是接入网设备,所述接入网设备可以是各种移动通信网络下的基站,例如演进型基站(eNB,Evolutional Node B)、5G网络基站(gNB)等等。如图1所示,所述方法包括:
步骤101、配置输入参数;所述输入参数包括第一参数和/或第二参数;所述第一参数和/或所述第二参数的取值与网络设备相关。
本实施例中,所述第一参数的取值为至少部分所述网络设备的标识;所述第二参数的取值为至少部分所述网络设备为终端分配的身份标识。
在一些可选实施例中,所述网络设备的标识为以下之一:所述网络设备自身的身份标识ID;所述网络设备的CU的ID。
在一些可选实施例中,所述网络设备为终端分配的身份标识为所述终端在所述网络设备的覆盖范围内的唯一身份标识。
步骤102、基于所述输入参数确定加密密钥(例如KeNB*),所述加密密钥用于对所述网络设备与终端之间的通信进行加密以及完整性保护。
本实施例中,所述基于所述输入参数确定加密密钥,包括:将所述输入参数输入到规定的密钥派生函数(KDF,Key Derivation Function)中,确定加密密钥。
示例性的,输入至所述KDF的输入参数,可以具体包括:
FC=0x13;
P0=所述第一参数;
L0=所述第一参数的长度;
P1=所述第二参数;
L1=所述第二参数的长度。
在一些实施例中,步骤101中,所述配置输入参数,可以包括:配置输入参数的类型以及对应的取值范围,基于所述输入参数的类型以及对应的取值范围确定所述输入参数的取值。
本实施例中,终端和网络设备均可以运用所述KDF确定加密密钥。但需要说明的是,当终端运用上述密钥生成方法生成加密密钥时,所述终端接收网络设备分配的相关参数(例如可包含所述第一参数和/或第二参数),在终端移动切换的过程中,即可根据接收的所述相关参数生成加密密钥。
图2为本申请实施例提供的另一种密钥生成方法的流程示意图;所述方法可以应用于网络设备或终端,如图2所示,所述方法包括:
步骤201、配置输入参数。
这里,所述步骤201中,配置KDF的输入参数中的第一参数(记为P0)和/或第二参数(记为P1);具体将P0和P1定义为与终端所在的小区和频点无关、与终端所连接的网络设备相关。
在一些示例中,所述P0的取值可以为至少部分所述网络设备的标识;如:网络设备自身的ID、所述网络设备的集中式单元(例如gNB-CU)的ID。
所述P1的取值为至少部分所述网络设备为终端分配的身份标识。所述网络设备为终端分配的身份标识为所述终端在所述网络设备的覆盖范围内的唯一身份标识,如:网络设备覆盖范围内无线网络临时标识(gNB-RNTI,gNB Radio Network Temporary Identifier),所述gNB-RNTI为终端在整个gNB覆盖范围内的唯一ID。
本实施例中,具体提供了一种定义gNB-RNTI的方法,包括:将已有的通用无线网络临时标识(C-RNTI,Common Radio Network Temporary Identifier)从小区级参数调整定义为gNB级参数,即将C-RNTI调整为gNB覆盖范围内的唯一ID(即gNB-RNTI)。
需要说明的是,目前,相关技术中的终端的C-RNTI为小区级参数,即每个C-RNTI在一个小区内唯一取值,不同小区内的C-RNTI独立取值。这里,将C-RNTI调整为gNB级参数,即为在一个gNB内,网络设备为终端分配的C-RNTI是唯一的、不改变的。
由于相关技术中的gNB-CU的ID长度为28比特(bits)或34bits,本实施例中,从加解密算法计算的复杂度考虑,可以截取一定长度(记为LenP0)的比特作为第一参数P0的值。
以下为本实施例提供的一种具体地P0和L0的取值,如下:
P0=gNB_CU_ID_Part,所述gNB_CU_ID_Part表示取gNB-CU ID的一部分;
L0=LenP0,所述LenP0表示取的部分gNB-CU ID的长度。
P1=gNB-RNTI,所述gNB-RNTI表示网络设备为终端分配的专用ID;
L1=LenP1,所述LenP1表示gNB-RNTI的长度。
步骤202、基于所述输入参数确定加密密钥,所述加密密钥用于对所述网络设备与终端之间的通信进行加密以及完整性保护。
本实施例中步骤202中的详细阐述具体可参照前述实施例中的步骤102所述,这里不再赘述。
图3为本申请实施例提供的一种切换方法的流程示意图;所述方法应用于网络设备,如图3所示,所述方法包括:
步骤301、网络设备确定终端由当前小区切换到所述网络设备的覆盖范围内的其他小区时,保持第一参数和/或第二参数不变;所述第一参数和/ 或第二参数的取值与所述网络设备相关;所述第一参数和/或第二参数用以确定对所述网络设备与终端之间通信进行加密以及完整性保护的第一加密密钥。
在一些实施例中,所述第一参数的取值为至少部分所述网络设备的标识。所述第二参数的取值为至少部分所述网络设备为终端分配的身份标识。
步骤302、所述网络设备基于所述第一加密密钥与所述终端进行通信。
本实施例中,所述网络设备确定所述终端由当前小区切换到所述网络设备的覆盖范围内的其他小区后,所述方法还可以包括:所述网络设备重启更新定时器;所述更新定时器用于对所述第一参数和/或所述第二参数的更新周期进行计时;在所述更新定时器超时的情况下,所述网络设备更新所述第二参数,根据更新的所述第二参数确定第二加密密钥;所述网络设备基于所述第二加密密钥与所述终端进行通信。
在一些实施例中,在所述更新定时器超时的情况下,所述方法还包括:所述网络设备向所述终端发送连接重配置信息,所述连接重配置信息包括:所述第二加密密钥,所述第二加密密钥用于所述终端进行PDCP重配置。
在本申请的一些可选实施例中,所述方法还可以包括:所述网络设备确定所述终端切换到目标网络设备时,更新所述第一参数和/或第二参数,更新的所述第一参数和/或所述第二参数的取值与所述目标网络设备相关;所述网络设备根据更新的所述第一参数和/或第二参数确定第三加密密钥;所述网络设备向所述目标网络设备发送切换重配置信息,所述切换重配置信息包括所述第三加密密钥,所述第三加密密钥用于所述目标网络设备进行PDCP重配置。
需要说明的是,终端在移动切换的过程中,需基于所述第二加密密钥进行PDCP重配置,该过程也可能涉及到终端需生成自身的加密密钥(KeNB*),当终端需要生成自身的KeNB*时,终端可接收网络设备发送的 目标网络设备的相关参数(具体可以包括:目标网络设备的标识、目标网络设备为终端分配的身份标识等),并采用上述图1所示的方法生成KeNB*,这里不再赘述。
图4为本申请实施例提供的另一种切换方法的流程示意图;如图4所示,所述方法包括:
步骤401、源网络设备(例如源基站(Source gNB))的无线资源管理(RRM,Radio Resource Management)进行切换判决,判断本次切换是源网络设备的覆盖范围内的小区切换还是网络设备间的切换;确定为本次切换是所述源网络设备的覆盖范围内不同小区间的切换时,进入步骤402;确定为网络设备间的切换时,则进入步骤403。其中,所述网络设备间切换指由源网络设备切换到目标网络设备(Target gNB)。
步骤402、源网络设备不改变第一参数(记为P0)和/或第二参数(记为P1)的取值,直接从终端接入的当前小区切换到源网络设备的覆盖范围内的其他小区。
在一些实施例中,所述步骤402之后,所述方法还可以包括步骤402a至步骤402b:所述源网络设备重启更新定时器,在所述更新定时器超时的情况下,所述源网络设备重新配置所述P1,并采用以上图1所示的方法根据重新配置的所述P1确定新的加密密钥,记做第一KeNB*;所述源网络设备基于确定的第一KeNB*与终端进行通信。其中,所述P1取值为源网络设备给终端分配的一个空闲的gNB-RNTI。其中,所述更新定时器用于对P0和/或P1的更新周期进行计时。所述更新周期由开发人员预先设定并保存。
在本申请的一些可选实施例中,在所述更新定时器超时的情况下,所述方法还包括:所述源网络设备向所述终端发送连接重配置信息,所述连接重配置信息包括:第一KeNB*,以使所述终端基于确定的所述第一KeNB*进行PDCP重配置。
需要说明的是,由于终端是进行网络设备内小区的切换,即网络设备没有变化,所以P0和P1可以不变;但更新计时器超时后,为了防止长期不更新加密密钥致密钥泄露风险,可以对其进行更新,这里,可以给终端重新分配一个空闲的gNB-RNTI,并通过无线资源控制(RRC,Radio Resource Control)连接重配置(RRC Connection Reconfiguration)、也称切换(Handover)过程重配置终端。
步骤403、重新赋值P0和/或P1,生成新的加密密钥,记做第二KeNB*,并发起网络设备间的切换重配置过程。
在本申请的一些可选实施例中,所述步骤403,可包括:所述源网络设备确定所述终端切换到目标网络设备,所述源网络设备更新P0和/或P1,更新的所述P0和/或P1的取值与所述目标网络设备相关;所述源网络设备根据更新的所述P0和/或P1生成第二KeNB*;所述源网络设备向目标网络设备发送切换重配置信息,所述切换重配置信息包括所述第二KeNB*,以使所述目标网络设备基于所述第二KeNB*进行PDCP重配置。
示例性的,所述源网络设备向目标网络设备发送切换重配置信息,可通过图中的步骤403a实现:源网络设备可向目标网络设备发送RRC连接重配置(RRC Connection Reconfiguration)消息,该RRC连接重配置消息中可携带所述第二KeNB*。
本实施例中,所述P0的取值为至少部分所述目标网络设备的标识;所述P1的取值为至少部分所述目标网络设备为所述终端分配的身份标识。
图5为本申请实施例提供的一种密钥生成装置的结构示意图;所述装置可以应用于网络设备或终端,如图5所示,所述装置包括:配置模块51和确定模块52;
所述配置模块51,配置为配置输入参数;所述输入参数包括第一参数和/或第二参数;所述第一参数和/或所述第二参数的取值与网络设备相关。
所述确定模块52,配置为基于所述输入参数确定加密密钥,所述加密密钥用于对所述网络设备与终端之间的通信进行加密以及完整性保护。
在本申请的一些可选实施例中,所述第一参数的取值为至少部分所述网络设备的标识;所述第二参数的取值为至少部分所述网络设备为终端分配的身份标识。
在本申请的一些可选实施例中,所述网络设备的标识为以下之一:所述网络设备自身的ID;所述网络设备的CU的ID。
在本申请的一些可选实施例中,所述网络设备为终端分配的身份标识为所述终端在所述网络设备的范围内的唯一身份标识。
在本申请的一些可选实施例中,所述配置模块51,配置为配置输入参数的类型以及对应的取值范围,基于所述输入参数的类型以及对应的取值范围确定所述输入参数的取值。
需要说明的是:上述实施例提供的密钥生成装置在进行密钥生成时,仅以上述各程序模块的划分进行举例说明,实际应用中,可以根据需要而将上述处理分配由不同的程序模块完成,即将装置的内部结构划分成不同的程序模块,以完成以上描述的全部或者部分处理。另外,上述实施例提供的密钥生成装置与密钥生成方法实施例属于同一构思,其具体实现过程详见方法实施例,这里不再赘述。
图6为本申请实施例提供的一种网络设备的结构示意图;如图6所示,所述网络设备包括:第一处理模块61和第二处理模块62;其中,
所述第一处理模块61,配置为确定终端由当前小区切换到所述网络设备的覆盖范围内的其他小区时,保持第一参数和/或第二参数不变;所述第一参数和/或第二参数的取值与所述网络设备相关;所述第一参数和/或第二参数用以确定对所述网络设备与终端之间通信进行加密以及完整性保护的第一加密密钥;
所述第二处理模块62,配置为基于所述第一加密密钥与所述终端进行通信。
在本申请的一些可选实施例中,所述第一参数的取值为至少部分所述网络设备的标识;所述第二参数的取值为至少部分所述网络设备为终端分配的身份标识。
在本申请的一些可选实施例中,所述第一处理模块61,还配置为在确定所述终端由当前小区切换到所述网络设备的覆盖范围内的其他小区后,重启更新定时器;所述更新定时器用于对所述第一参数和/或所述第二参数的更新周期进行计时;在所述更新定时器超时的情况下,更新所述第二参数,根据更新的所述第二参数确定第二加密密钥;
所述第二处理模块62,配置为基于所述第二加密密钥与所述终端进行通信。
在本申请的一些可选实施例中,所述第一处理模块61,还配置为在所述更新定时器超时的情况下,向所述终端发送连接重配置信息,所述连接重配置信息包括:所述第二加密密钥,所述第二加密密钥用于所述终端进行PDCP重配置。
在本申请的一些可选实施例中,所述第一处理模块61,还配置为在确定所述终端切换到目标网络设备时,更新所述第一参数和/或第二参数,更新的所述第一参数和/或所述第二参数的取值与所述目标网络设备相关;根据更新的所述第一参数和/或第二参数确定第三加密密钥;向目标网络设备发送切换重配置信息,所述切换重配置信息包括所述第三加密密钥,所述第三加密密钥用于所述目标网络设备进行PDCP重配置。
需要说明的是:上述实施例提供的网络设备在进行切换时,仅以上述各程序模块的划分进行举例说明,实际应用中,可以根据需要而将上述处理分配由不同的程序模块完成,即将网络设备的内部结构划分成不同的程 序模块,以完成以上描述的全部或者部分处理。另外,上述实施例提供的网络设备与切换方法实施例属于同一构思,其具体实现过程详见方法实施例,这里不再赘述。
本申请实施例还提供了一种电子设备,所述电子设备具体可以是终端或网络设备。图7为本申请实施例的电子设备的硬件组成结构示意图,如图7所示,电子设备包括存储器72、处理器71及存储在存储器72上并可在处理器71上运行的计算机程序,所述处理器71执行所述程序时实现本申请实施例所述密钥生成方法或切换方法的步骤。
可以理解,电子设备(终端或网络设备)还包括通信接口73和总线系统74。电子设备(终端或网络设备)中的各个组件可通过总线系统74耦合在一起。可理解,总线系统74用于实现这些组件之间的连接通信。总线系统74除包括数据总线之外,还包括电源总线、控制总线和状态信号总线。但是为了清楚说明起见,在图7中将各种总线都标为总线系统74。
可以理解,存储器72可以是易失性存储器或非易失性存储器,也可包括易失性和非易失性存储器两者。其中,非易失性存储器可以是只读存储器(ROM,Read Only Memory)、可编程只读存储器(PROM,Programmable Read-Only Memory)、可擦除可编程只读存储器(EPROM,Erasable Programmable Read-Only Memory)、电可擦除可编程只读存储器(EEPROM,Electrically Erasable Programmable Read-Only Memory)、磁性随机存取存储器(FRAM,ferromagnetic random access memory)、快闪存储器(Flash Memory)、磁表面存储器、光盘、或只读光盘(CD-ROM,Compact Disc Read-Only Memory);磁表面存储器可以是磁盘存储器或磁带存储器。易失性存储器可以是随机存取存储器(RAM,Random Access Memory),其用作外部高速缓存。通过示例性但不是限制性说明,许多形式的RAM可用,例如静态随机存取存储器(SRAM,Static Random Access Memory)、同步静 态随机存取存储器(SSRAM,Synchronous Static Random Access Memory)、动态随机存取存储器(DRAM,Dynamic Random Access Memory)、同步动态随机存取存储器(SDRAM,Synchronous Dynamic Random Access Memory)、双倍数据速率同步动态随机存取存储器(DDRSDRAM,Double Data Rate Synchronous Dynamic Random Access Memory)、增强型同步动态随机存取存储器(ESDRAM,Enhanced Synchronous Dynamic Random Access Memory)、同步连接动态随机存取存储器(SLDRAM,SyncLink Dynamic Random Access Memory)、直接内存总线随机存取存储器(DRRAM,Direct Rambus Random Access Memory)。本申请实施例描述的存储器72旨在包括但不限于这些和任意其它适合类型的存储器。
上述本申请实施例揭示的方法可以应用于处理器71中,或者由处理器71实现。处理器71可能是一种集成电路芯片,具有信号的处理能力。在实现过程中,上述方法的各步骤可以通过处理器71中的硬件的集成逻辑电路或者软件形式的指令完成。上述的处理器71可以是通用处理器、DSP,或者其他可编程逻辑器件、分立门或者晶体管逻辑器件、分立硬件组件等。处理器71可以实现或者执行本申请实施例中的公开的各方法、步骤及逻辑框图。通用处理器可以是微处理器或者任何常规的处理器等。结合本申请实施例所公开的方法的步骤,可以直接体现为硬件译码处理器执行完成,或者用译码处理器中的硬件及软件模块组合执行完成。软件模块可以位于存储介质中,该存储介质位于存储器72,处理器71读取存储器72中的信息,结合其硬件完成前述方法的步骤。
在示例性实施例中,电子设备(终端或网络设备)可以被一个或多个应用专用集成电路(ASIC,Application Specific Integrated Circuit)、DSP、可编程逻辑器件(PLD,Programmable Logic Device)、复杂可编程逻辑器件(CPLD,Complex Programmable Logic Device)、FPGA、通用处理器、 控制器、MCU、微处理器(Microprocessor)、或其他电子元件实现,用于执行前述方法。
在示例性实施例中,本申请实施例还提供了一种计算机存储介质,例如包括计算机程序的存储器72,上述计算机程序可由终端或网络设备的处理器71执行,以完成前述方法所述步骤。计算机存储介质可以是FRAM、ROM、PROM、EPROM、EEPROM、Flash Memory、磁表面存储器、光盘、或CD-ROM等存储器;也可以是包括上述存储器之一或任意组合的各种设备。
本申请实施例提供的计算机存储介质,其上存储有计算机指令,所述计算机程序被处理器执行时实现本申请实施例所述密钥生成方法的步骤;或者,所述计算机程序被处理器执行时实现本申请实施例所述切换方法的步骤。
本申请所提供的几个方法实施例中所揭露的方法,在不冲突的情况下可以任意组合,得到新的方法实施例。
本申请所提供的几个产品实施例中所揭露的特征,在不冲突的情况下可以任意组合,得到新的产品实施例。
本申请所提供的几个方法或设备实施例中所揭露的特征,在不冲突的情况下可以任意组合,得到新的方法实施例或设备实施例。
在本申请所提供的几个实施例中,应该理解到,所揭露的设备和方法,可以通过其它的方式实现。以上所描述的设备实施例仅仅是示意性的,例如,所述单元的划分,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式,如:多个单元或组件可以结合,或可以集成到另一个系统,或一些特征可以忽略,或不执行。另外,所显示或讨论的各组成部分相互之间的耦合、或直接耦合、或通信连接可以是通过一些接口,设备或单元的间接耦合或通信连接,可以是电性的、机械的或其它形式的。
上述作为分离部件说明的单元可以是、或也可以不是物理上分开的,作为单元显示的部件可以是、或也可以不是物理单元,即可以位于一个地方,也可以分布到多个网络单元上;可以根据实际的需要选择其中的部分或全部单元来实现本实施例方案的目的。
另外,在本申请各实施例中的各功能单元可以全部集成在一个处理单元中,也可以是各单元分别单独作为一个单元,也可以两个或两个以上单元集成在一个单元中;上述集成的单元既可以采用硬件的形式实现,也可以采用硬件加软件功能单元的形式实现。
本领域普通技术人员可以理解:实现上述方法实施例的全部或部分步骤可以通过程序指令相关的硬件来完成,前述的程序可以存储于一计算机可读取存储介质中,该程序在执行时,执行包括上述方法实施例的步骤;而前述的存储介质包括:移动存储设备、ROM、RAM、磁碟或者光盘等各种可以存储程序代码的介质。
或者,本申请上述集成的单元如果以软件功能模块的形式实现并作为独立的产品销售或使用时,也可以存储在一个计算机可读取存储介质中。基于这样的理解,本申请实施例的技术方案本质上或者说对现有技术做出贡献的部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质中,包括若干指令用以使得一台计算机设备(可以是个人计算机、服务器、或者网络设备等)执行本申请各个实施例所述方法的全部或部分。而前述的存储介质包括:移动存储设备、ROM、RAM、磁碟或者光盘等各种可以存储程序代码的介质。
以上所述,仅为本申请的具体实施方式,但本申请的保护范围并不局限于此,任何熟悉本技术领域的技术人员在本申请揭露的技术范围内,可轻易想到变化或替换,都应涵盖在本申请的保护范围之内。因此,本申请的保护范围应以所述权利要求的保护范围为准。
Claims (23)
- 一种密钥生成方法,所述方法应用于网络设备或终端,所述方法包括:配置输入参数;所述输入参数包括第一参数和/或第二参数;所述第一参数和/或所述第二参数的取值与网络设备相关;基于所述输入参数确定加密密钥,所述加密密钥用于对所述网络设备与终端之间的通信进行加密以及完整性保护。
- 根据权利要求1所述的方法,其中,所述第一参数的取值为至少部分所述网络设备的标识;所述第二参数的取值为至少部分所述网络设备为终端分配的身份标识。
- 根据权利要求2所述的方法,其中,所述网络设备的标识为以下之一:所述网络设备自身的身份标识ID;所述网络设备的集中式单元CU的ID。
- 根据权利要求2所述的方法,其中,所述网络设备为终端分配的身份标识为所述终端在所述网络设备的覆盖范围内的唯一身份标识。
- 根据权利要求1至4任一项所述的方法,其中,所述配置输入参数,包括:配置输入参数的类型以及对应的取值范围,基于所述输入参数的类型以及对应的取值范围确定所述输入参数的取值。
- 一种切换方法,所述方法包括:网络设备确定终端由当前小区切换到所述网络设备的覆盖范围内的其他小区时,保持第一参数和/或第二参数不变;所述第一参数和/或第二参数的取值与所述网络设备相关;所述第一参数和/或第二参数用以确定对所述网络设备与终端之间通信进行加密以及完整性保护的第一加密密钥;所述网络设备基于所述第一加密密钥与所述终端进行通信。
- 根据权利要求6所述的方法,其中,所述第一参数的取值为至少部分所述网络设备的标识;所述第二参数的取值为至少部分所述网络设备为终端分配的身份标识。
- 根据权利要求7所述的方法,其中,所述网络设备确定所述终端由当前小区切换到所述网络设备的覆盖范围内的其他小区后,所述方法还包括:所述网络设备重启更新定时器;所述更新定时器用于对所述第一参数和/或所述第二参数的更新周期进行计时;在所述更新定时器超时的情况下,所述网络设备更新所述第二参数,根据更新的所述第二参数确定第二加密密钥;所述网络设备基于所述第二加密密钥与所述终端进行通信。
- 根据权利要求8所述的方法,其中,在所述更新定时器超的情况下,所述方法还包括:所述网络设备向所述终端发送连接重配置信息,所述连接重配置信息包括:所述第二加密密钥,所述第二加密密钥用于所述终端进行分组数据汇聚协议PDCP重配置。
- 根据权利要求6所述的方法,其中,所述方法还包括:所述网络设备确定所述终端切换到目标网络设备时,更新所述第一参数和/或第二参数,更新的所述第一参数和/或所述第二参数的取值与所述目标网络设备相关;所述网络设备根据更新的所述第一参数和/或第二参数确定第三加密密钥;所述网络设备向所述目标网络设备发送切换重配置信息,所述切换重配置信息包括所述第三加密密钥,所述第三加密密钥用于所述目标网络设 备进行PDCP重配置。
- 一种密钥生成装置,所述装置应用于网络设备或终端,所述装置包括:配置模块和确定模块;其中,所述配置模块,配置为配置输入参数;所述输入参数包括第一参数和/或第二参数;所述第一参数和/或所述第二参数的取值与网络设备相关;所述确定模块,配置为基于所述输入参数确定加密密钥,所述加密密钥用于对所述网络设备与终端之间的通信进行加密以及完整性保护。
- 根据权利要求11所述的装置,其中,所述第一参数的取值为至少部分所述网络设备的标识;所述第二参数的取值为至少部分所述网络设备为终端分配的身份标识。
- 根据权利要求12所述的装置,其中,所述网络设备的标识为以下之一:所述网络设备自身的ID;所述网络设备的CU的ID。
- 根据权利要求12所述的装置,其中,所述网络设备为终端分配的身份标识为所述终端在所述网络设备的覆盖范围内的唯一身份标识。
- 根据权利要求11至14任一项所述的装置,其中,所述配置模块,配置为配置输入参数的类型以及对应的取值范围,基于所述输入参数的类型以及对应的取值范围确定所述输入参数的取值。
- 一种网络设备,所述网络设备包括:第一处理模块和第二处理模块;其中,所述第一处理模块,配置为确定终端由当前小区切换到所述网络设备的覆盖范围内的其他小区时,保持第一参数和/或第二参数不变;所述第一参数和/或第二参数的取值与所述网络设备相关;所述第一参数和/或第二参数用以确定对所述网络设备与终端之间通信进行加密以及完整性保护的第 一加密密钥;所述第二处理模块,配置为基于所述第一加密密钥与所述终端进行通信。
- 根据权利要求16所述的网络设备,其中,所述第一参数的取值为至少部分所述网络设备的标识;所述第二参数的取值为至少部分所述网络设备为终端分配的身份标识。
- 根据权利要求17所述的网络设备,其中,所述第一处理模块,还配置为在确定所述终端由当前小区切换到所述网络设备的覆盖范围内的其他小区后,重启更新定时器;所述更新定时器用于对所述第一参数和/或所述第二参数的更新周期进行计时;在所述更新定时器超时的情况下,更新所述第二参数,根据更新的所述第二参数确定第二加密密钥;所述第二处理模块,还配置为基于所述第二加密密钥与所述终端进行通信。
- 根据权利要求18所述的网络设备,其中,所述第一处理模块,还配置为在所述更新定时器超时的情况下,向所述终端发送连接重配置信息,所述连接重配置信息包括:所述第二加密密钥,所述第二加密密钥用于所述终端进行PDCP重配置。
- 根据权利要求16所述的网络设备,其中,所述第一处理模块,还配置为在确定所述终端切换到目标网络设备时,更新所述第一参数和/或第二参数,更新的所述第一参数和/或所述第二参数的取值与所述目标网络设备相关;根据更新的所述第一参数和/或第二参数确定第三加密密钥;向所述目标网络设备发送切换重配置信息,所述切换重配置信息包括所述第三加密密钥,所述第三加密密钥用于所述目标网络设备进行PDCP重配置。
- 一种密钥生成装置,包括存储器、处理器及存储在存储器上并可在处理器上运行的计算机程序,所述处理器执行所述程序时实现权利要求1 至5任一项所述方法的步骤。
- 一种网络设备,包括存储器、处理器及存储在存储器上并可在处理器上运行的计算机程序,所述处理器执行所述程序时实现权利要求6至10任一项所述方法的步骤。
- 一种计算机可读存储介质,其上存储有计算机程序,所述计算机程序被处理器执行时实现权利要求1至5任一项所述方法的步骤;或者,所述计算机程序被处理器执行时实现权利要求6至10任一项所述方法的步骤。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201910118103.0 | 2019-02-15 | ||
| CN201910118103.0A CN111585746A (zh) | 2019-02-15 | 2019-02-15 | 密钥生成方法、切换方法、装置、网络设备和存储介质 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2020164399A1 true WO2020164399A1 (zh) | 2020-08-20 |
Family
ID=72045494
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2020/074197 Ceased WO2020164399A1 (zh) | 2019-02-15 | 2020-02-03 | 密钥生成方法、切换方法、装置、网络设备和存储介质 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN111585746A (zh) |
| WO (1) | WO2020164399A1 (zh) |
Families Citing this family (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2024229637A1 (zh) * | 2023-05-06 | 2024-11-14 | 北京小米移动软件有限公司 | 通信方法、装置、设备及计算机可读存储介质 |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2010032798A1 (ja) * | 2008-09-22 | 2010-03-25 | 株式会社エヌ・ティ・ティ・ドコモ | 移動通信方法 |
| CN107371155A (zh) * | 2016-05-13 | 2017-11-21 | 华为技术有限公司 | 通信安全的处理方法、装置及系统 |
| CN108924894A (zh) * | 2017-04-11 | 2018-11-30 | 华为技术有限公司 | 一种移动性管理方法、接入网设备和终端设备 |
Family Cites Families (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN102316426A (zh) * | 2010-07-09 | 2012-01-11 | 中国移动通信集团广东有限公司 | 一种重传短信的方法及网络设备 |
| US9817720B2 (en) * | 2012-10-29 | 2017-11-14 | Nokia Solutions And Networks Oy | Methods, apparatuses and computer program products enabling to improve handover security in mobile communication networks |
| CN108738096B (zh) * | 2017-04-18 | 2022-10-14 | 维沃移动通信有限公司 | 一种小区选择和重选的方法、终端、基站及核心网实体 |
-
2019
- 2019-02-15 CN CN201910118103.0A patent/CN111585746A/zh active Pending
-
2020
- 2020-02-03 WO PCT/CN2020/074197 patent/WO2020164399A1/zh not_active Ceased
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2010032798A1 (ja) * | 2008-09-22 | 2010-03-25 | 株式会社エヌ・ティ・ティ・ドコモ | 移動通信方法 |
| CN107371155A (zh) * | 2016-05-13 | 2017-11-21 | 华为技术有限公司 | 通信安全的处理方法、装置及系统 |
| CN108924894A (zh) * | 2017-04-11 | 2018-11-30 | 华为技术有限公司 | 一种移动性管理方法、接入网设备和终端设备 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN111585746A (zh) | 2020-08-25 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| JP6928143B2 (ja) | 暗号化されたクライアントデバイスコンテキストを用いたネットワークアーキテクチャおよびセキュリティ | |
| US12010107B2 (en) | Network security architecture | |
| US11716615B2 (en) | Network architecture and security with simplified mobility procedure | |
| CN107371155B (zh) | 通信安全的处理方法、装置及系统 | |
| KR102040036B1 (ko) | 보안 패스워드 변경 방법, 기지국, 및 사용자 기기 | |
| TWI726890B (zh) | 具有加密的網路可達性上下文的網路架構和安全 | |
| WO2019095206A1 (zh) | 一种切换的方法、设备及计算机存储介质 | |
| CN114642014A (zh) | 一种通信方法、装置及设备 | |
| WO2019178722A1 (zh) | 一种获取密钥的方法及装置、计算机存储介质 | |
| US10708971B2 (en) | Mobility management method, user equipment, storage node, and base station | |
| WO2020164399A1 (zh) | 密钥生成方法、切换方法、装置、网络设备和存储介质 | |
| CN121194176A (zh) | 信息传输方法、装置、相关设备、存储介质及计算器程序产品 | |
| CN121463145A (zh) | 一种通信方法及装置 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 20756136 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 32PN | Ep: public notification in the ep bulletin as address of the adressee cannot be established |
Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 19/01/2022) |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 20756136 Country of ref document: EP Kind code of ref document: A1 |