WO2025148993A1 - 通信方法、装置、用户设备、基站及存储介质 - Google Patents

通信方法、装置、用户设备、基站及存储介质

Info

Publication number
WO2025148993A1
WO2025148993A1 PCT/CN2025/071569 CN2025071569W WO2025148993A1 WO 2025148993 A1 WO2025148993 A1 WO 2025148993A1 CN 2025071569 W CN2025071569 W CN 2025071569W WO 2025148993 A1 WO2025148993 A1 WO 2025148993A1
Authority
WO
WIPO (PCT)
Prior art keywords
rrc
base station
mac
integrity protection
layer
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
PCT/CN2025/071569
Other languages
English (en)
French (fr)
Inventor
张宏平
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Vivo Mobile Communication Co Ltd
Original Assignee
Vivo Mobile Communication Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Vivo Mobile Communication Co Ltd filed Critical Vivo Mobile Communication Co Ltd
Publication of WO2025148993A1 publication Critical patent/WO2025148993A1/zh
Anticipated expiration legal-status Critical
Pending legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W76/00Connection management
    • H04W76/20Manipulation of established connections
    • H04W76/27Transitions between radio resource control [RRC] states
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/03Protecting confidentiality, e.g. by encryption
    • H04W12/037Protecting confidentiality, e.g. by encryption of the control plane, e.g. signalling traffic
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/04Key management, e.g. using generic bootstrapping architecture [GBA]
    • H04W12/043Key management, e.g. using generic bootstrapping architecture [GBA] using a trusted network node as an anchor
    • H04W12/0433Key management protocols
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W76/00Connection management
    • H04W76/10Connection setup
    • H04W76/19Connection re-establishment

Definitions

  • the present application belongs to the field of communication technology, and specifically relates to a communication method, device, user equipment, base station and storage medium.
  • Embodiments of the present application provide a communication method, apparatus, user equipment, base station, and storage medium, which can improve the security of RRC re-establishment messages.
  • a communication method comprising: a UE sends an RRC re-establishment request message to a base station; a medium access control (MAC) layer of the UE receives a first medium access control element (MAC Control Element, MAC CE) from the base station; wherein the first MAC CE includes an NCC and a first byte stream, the first byte stream includes an encrypted RRC re-establishment message, and the RRC re-establishment message is used to instruct the UE to re-establish an RRC connection.
  • MAC medium access control
  • MAC CE medium access control element
  • a communication method comprising: a base station receives an RRC re-establishment request message from a UE; a MAC layer of the base station sends a first MAC CE to the UE; wherein the first MAC CE comprises an NCC and a first byte stream, the first byte stream comprises an encrypted RRC re-establishment message, and the RRC re-establishment message is used to instruct the UE to re-establish an RRC connection.
  • a communication method comprising: a UE sends an RRC re-establishment request message to a base station; the UE receives a first signaling from the base station, the first signaling being used to request the UE to update a key used by the UE, the first signaling comprising an NCC, and the first signaling being a second MAC CE or a PDCP control PDU; the RRC layer of the UE updates the key used by the UE based on the NCC, and generates a first encryption key and a first integrity protection key based on the updated key; the RRC layer of the UE instructs the Packet Data Convergence Protocol (PDCP) layer of the UE to restore integrity protection and encryption using the first encryption key and the first integrity protection key; after the PDCP layer of the UE restores integrity protection and encryption using the first encryption key and the first integrity protection key, the PDCP layer of the UE processes a second PDCP protocol data unit (PDU)
  • PDU Packet Data Converg
  • a communication method comprising: a base station receives an RRC re-establishment request message from a UE; the base station sends a first signaling to the UE, the first signaling being used to request the UE to update a key used by the UE, the first signaling comprising an NCC, the first signaling being a second MAC CE or a PDCP control PDU; the base station sends a second PDCP PDU to the UE, the second PDCP PDU comprising an integrity-protected and encrypted RRC re-establishment message, the RRC re-establishment message being used to instruct the UE to re-establish the RRC connection.
  • a communication device which is applied to a UE, and the device includes: a sending module and a receiving module.
  • the sending module is used to send an RRC re-establishment request message to a base station.
  • the receiving module is used to receive a first MAC CE from the base station; wherein the first MAC CE includes an NCC and a first byte stream, the first byte stream includes an encrypted RRC re-establishment message, and the RRC re-establishment message is used to instruct the UE to re-establish the RRC connection.
  • a communication device which is applied to a base station, and the device includes: a receiving module and a sending module.
  • the receiving module is used to receive an RRC re-establishment request message from a UE.
  • the sending module is used to send a first MAC CE to the UE; wherein the first MAC CE includes an NCC and a first byte stream, the first byte stream includes an encrypted RRC re-establishment message, and the RRC re-establishment message is used to instruct the UE to re-establish an RRC connection.
  • a communication device which is applied to a UE, and the device includes: a sending module, a receiving module, a processing module, and an indicating module.
  • the sending module is used to send an RRC re-establishment request message to a base station.
  • the receiving module is used to receive a first signaling from the base station, the first signaling is used to request the UE to update the key used by the UE, the first signaling includes an NCC, and the first signaling is a second MAC CE or a PDCP control PDU.
  • the processing module is used to update the key used by the UE based on the NCC, and generate a first encryption key and a first integrity protection key based on the updated key.
  • a communication device comprising: a receiving module and a sending module.
  • the receiving module is used to receive an RRC re-establishment request message from a UE.
  • the sending module is used to send a first signaling to the UE, the first signaling is used to request the UE to update a key used by the UE, the first signaling includes an NCC, and the first signaling is a second MAC CE or a PDCP control PDU; and send a second PDCP PDU to the UE, the second PDCP PDU includes an integrity-protected and encrypted RRC re-establishment message, and the RRC re-establishment message is used to instruct the UE to re-establish the RRC connection.
  • a UE which includes a processor and a memory, wherein the memory stores programs or instructions that can be executed on the processor, and when the program or instructions are executed by the processor, the steps of the method described in the first aspect are implemented.
  • a base station which includes a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the programs or instructions are executed by the processor, the steps of the method described in the second aspect are implemented.
  • a base station comprising a processor and a communication interface, wherein the communication interface is used to receive an RRC re-establishment request message from a UE; and send a first MAC CE to the UE; wherein the first MAC CE includes an NCC and a first byte stream, the first byte stream includes an encrypted RRC re-establishment message, and the RRC re-establishment message is used to instruct the UE to re-establish the RRC connection.
  • a UE which includes a processor and a memory, wherein the memory stores programs or instructions that can be executed on the processor, and when the program or instructions are executed by the processor, the steps of the method described in the third aspect are implemented.
  • a UE comprising a processor and a communication interface, wherein the communication interface is used to send an RRC re-establishment request message to a base station; and receive a first signaling from the base station, the first signaling being used to request the UE to update the key used by the UE, the first signaling comprising an NCC, and the first signaling being a second MAC CE or a PDCP control PDU; the processor being used to update the key used by the UE based on the NCC, and to generate a first encryption key and a first integrity protection key based on the updated key; and instructing the PDCP layer of the UE to use the first encryption key and the first integrity protection key to restore integrity protection and encryption; and after the PDCP layer of the UE uses the first encryption key and the first integrity protection key to restore integrity protection and encryption, processing a second PDCP PDU from the base station, the second PDCP PDU comprising an integrity-protected and encrypted RRC re-est
  • a base station comprising a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the programs or instructions are executed by the processor, the steps of the method described in the fourth aspect are implemented.
  • a base station comprising a processor and a communication interface, wherein the communication interface is used to receive an RRC re-establishment request message from a UE; and send a first signaling to the UE, the first signaling being used to request the UE to update a key used by the UE, the first signaling comprising an NCC, the first signaling being a second MAC CE or a PDCP control PDU; and send a second PDCP PDU to the UE, the second PDCP PDU comprising an integrity-protected and encrypted RRC re-establishment message, the RRC re-establishment message being used to instruct the UE to re-establish the RRC connection.
  • a readable storage medium on which a program or instruction is stored.
  • the steps of the method described in the first aspect are implemented, or the steps of the method described in the second aspect are implemented, or the steps of the method described in the third aspect are implemented, or the steps of the method described in the fourth aspect are implemented.
  • a wireless communication system including: a UE and a base station, the UE can be used to execute the steps of the method described in the first aspect, or execute the steps of the method described in the third aspect, and the base station can be used to execute the steps of the method described in the second aspect, or execute the steps of the method described in the fourth aspect.
  • a chip comprising a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run a program or instructions to implement the method as described in the first aspect, or the method as described in the second aspect, or the method as described in the third aspect, or the method as described in the fourth aspect.
  • a computer program/program product is provided, wherein the computer program/program product is stored in a storage medium, and the program/program product is executed by at least one processor to implement the steps of the communication method as described in the first aspect, or the steps of the communication method as described in the second aspect, or the steps of the communication method as described in the third aspect, or the steps of the communication method as described in the fourth aspect.
  • the UE sends an RRC re-establishment request message to the base station; the UE's medium access control (MAC) layer receives a first media access control element (MAC CE) from the base station; wherein the first MAC CE includes an NCC and a first byte stream, the first byte stream includes an encrypted RRC re-establishment message, and the RRC re-establishment message is used to instruct the UE to re-establish the RRC connection.
  • MAC medium access control
  • MAC CE media access control element
  • the base station can send the first MAC CE including the NCC and the first byte stream to the UE, and the first byte stream includes the encrypted RRC re-establishment message, that is, the base station can carry the NCC outside the encrypted RRC re-establishment message, so while the UE obtains the NCC update key, the security of the RRC re-establishment message is also improved.
  • FIG1 is a schematic diagram of the architecture of a wireless communication system provided in an embodiment of the present application.
  • FIG2 is a flow chart of a communication method according to an embodiment of the present application.
  • FIG3 is a second flow chart of a communication method provided in an embodiment of the present application.
  • FIG4 is one of the structural diagrams of a first MAC CE provided in an embodiment of the present application.
  • Figure 5 is a schematic diagram of the structure of a first PDCP PDU provided in an embodiment of the present application.
  • FIG6 is a second schematic diagram of the structure of a first MAC CE provided in an embodiment of the present application.
  • FIG7 is a third flow chart of a communication method provided in an embodiment of the present application.
  • FIG8 is a schematic diagram of a structure of a communication device provided in an embodiment of the present application.
  • FIG9 is a second schematic diagram of the structure of a communication device provided in an embodiment of the present application.
  • FIG10 is a fourth flow chart of a communication method provided in an embodiment of the present application.
  • FIG11 is a fifth flow chart of a communication method provided in an embodiment of the present application.
  • FIG12 is a schematic diagram of the structure of a PDCP control PDU provided in an embodiment of the present application.
  • FIG13 is a sixth flow chart of a communication method provided in an embodiment of the present application.
  • FIG14 is a flow chart of a communication method according to an embodiment of the present application.
  • FIG15 is a third schematic diagram of the structure of a communication device provided in an embodiment of the present application.
  • FIG16 is a fourth structural diagram of a communication device provided in an embodiment of the present application.
  • FIG17 is a schematic diagram of the hardware structure of a communication device provided in an embodiment of the present application.
  • FIG18 is a schematic diagram of a hardware structure of a UE provided in an embodiment of the present application.
  • FIG19 is a schematic diagram of the hardware structure of a base station provided in an embodiment of the present application.
  • indication in this application can be a direct indication (or explicit indication) or an indirect indication (or implicit indication).
  • a direct indication can be understood as the sender explicitly informing the receiver of specific information, operations to be performed, or request results in the sent indication;
  • an indirect indication can be understood as the receiver determining the corresponding information according to the indication sent by the sender, or making a judgment and determining the operation to be performed or the request result according to the judgment result.
  • the above-mentioned first byte stream corresponds to a first PDCP PDU
  • the first PDCP PDU includes an encrypted first MAC-I
  • the encrypted first MAC-I is generated by the PDCP layer of the base station by performing an integrity protection operation on the RRC re-establishment message
  • the above-mentioned step 207 can be specifically implemented through the following steps 207a to 207c.
  • Step 207b The PDCP layer of the UE performs a decryption operation on the encrypted RRC re-establishment message and the encrypted first MAC-I using the first encryption key to obtain a decrypted RRC re-establishment message and a decrypted first MAC-I.
  • the UE when the PDCP layer of the UE fails to perform an integrity protection verification operation, the UE may enter an idle state.
  • the PDCP layer of the UE when the PDCP layer of the UE passes the integrity protection verification operation, the PDCP layer of the UE can pass the decrypted RRC re-establishment message to the RRC layer of the UE, and the RRC layer of the UE configures the PDCP layer of the UE to use the first encryption key and the first integrity protection key to restore integrity protection and encryption.
  • the PDCP layer of the UE can parse the first PDCP PDU, obtain "PDCP SN", “Data” and “MAC-I”, and use the first encryption key to decrypt the two information elements of "Data” and “MAC-I”, and then use the first integrity protection key and the decrypted "MAC-I” to perform integrity protection verification on the decrypted "Data” information element. If the verification fails, the UE can enter the idle state and the process ends; if the verification passes, the PDCP layer of the UE can return the decrypted "Data” to the RRC layer. Among them, “Data” corresponds to the encrypted RRC re-establishment message, and "MAC-I” corresponds to the encrypted first MAC-I.
  • the value of the downlink direction is 1.
  • Step 208 The PDCP layer of the UE sets the first variable maintained by the PDCP entity corresponding to SRB1 to 1 or increases it by 1.
  • the PDCP entity of SRB1 of the UE considers that the PDCP SDU with a COUNT value of 0 has been successfully received.
  • the RRC layer of the UE configures the PDCP layer of the UE to use the first encryption key and the first integrity protection key to resume integrity protection and encryption.
  • the above-mentioned second parameter or second parameter set includes at least one of the following: all bits of the COUNT value are 1, all bits of the BEARER value are 1, and DIRECTION is the downlink direction.
  • the first MAC CE includes first information, which is a MAC-I generated by performing an integrity protection operation on the RRC re-establishment message; the step 207 can be specifically implemented by the following steps 207d and 207e.
  • the UE when the PDCP layer of the UE fails to perform an integrity protection verification operation, the UE may enter an idle state.
  • the PDCP layer of the UE when the PDCP layer of the UE passes the integrity protection verification operation, the PDCP layer of the UE can pass the decrypted RRC re-establishment message to the RRC layer of the UE, and configure the PDCP layer to use the first encryption key and the first integrity protection key to restore integrity protection and encryption.
  • Step 207g When the PDCP layer of the UE passes the integrity protection verification operation on the NCC and the first byte stream, the PDCP layer of the UE performs a decryption operation on the first byte stream using the first encryption key to obtain a decrypted RRC re-establishment message.
  • the UE when the PDCP layer of the UE fails to perform an integrity protection verification operation, the UE may enter an idle state.
  • the PDCP layer of the UE when the PDCP layer of the UE passes the integrity protection verification operation, the PDCP layer of the UE can pass the decrypted RRC re-establishment message to the RRC layer of the UE, and configure the PDCP layer to use the first encryption key and the first integrity protection key to restore integrity protection and encryption.
  • the parameters used by the PDCP layer of the UE to perform the decryption operation and the integrity protection verification operation in the embodiment of the present application are any of the following: the first parameter, the first parameter set, the second parameter, and the second parameter set, which will not be described in detail in the embodiment of the present application.
  • the parameters used by the UE to perform the integrity protection verification operation and the decryption operation are the same as the parameters used by the base station to perform the integrity protection operation and the encryption operation.
  • the present application embodiment provides a communication method
  • Figure 3 shows a flow chart of a communication method provided by the present application embodiment.
  • the communication method provided by the present application embodiment may include the following steps 401 and 402.
  • Step 402 The MAC layer of the base station sends the first MAC CE to the UE.
  • the base station can send a first MAC CE to the UE, so that the UE can update the key used by the UE based on the NCC in the first MAC CE, and generate a first encryption key and a first integrity protection key based on the updated key, and re-establish the RRC connection based on the first byte stream in the first MAC CE.
  • the first MAC CE corresponds to a dedicated logical channel identification (LCID), that is, an LCID is assigned to the first MAC CE.
  • LCID dedicated logical channel identification
  • the UE After receiving the MAC PDU containing the first MAC CE, the UE can know that it is the first MAC CE through the LCID in the MAC subheader in the MAC PDU.
  • Step 405 The RRC layer of the base station generates an RRC re-establishment message, and requests the PDCP layer of the base station to perform security protection on the RRC re-establishment message.
  • Step 408 The MAC layer of the base station generates a first MAC CE based on the NCC and the first byte stream.
  • Step 406a The PDCP layer of the base station performs an integrity protection operation on the RRC re-establishment message using the first integrity protection key to generate a first MAC-I.
  • Step 406b The PDCP layer of the base station performs encryption operations on the RRC re-establishment message and the first MAC-I using the first encryption key to generate a first PDCP PDU.
  • the PDCP layer of the base station performs security protection on the RRC re-establishment message, and the security protection includes an encryption operation and an integrity protection operation.
  • the PDCP layer of the base station After the PDCP layer of the base station generates the first MAC-I, it also performs an encryption operation on the first MAC-I using the first encryption key, thereby improving security.
  • the above-mentioned first parameter or first parameter set includes at least one of the following: the COUNT value is 0, BEARER is the bearer identifier of the radio signaling bearer SRB1, and DIRECTION is the downlink direction.
  • the value of the downlink direction is 1.
  • the communication method provided by the embodiments of the present application may further include the following step 409.
  • Step 409 The PDCP layer of the base station sets the second variable maintained by the PDCP entity corresponding to SRB1 to 1 or increases it by 1.
  • the above-mentioned second variable is a variable corresponding to the COUNT value of the next PDCP SDU to be sent.
  • the second variable may be understood as a TX_NEXT variable.
  • the PDCP entity of SRB1 assigns a COUNT value (i.e., 0) to the RRC re-establishment message and performs security protection processing. After processing, it is not submitted to the RLC layer but returned to the RRC layer, and the TX_NEXT variable is set to 1 or increased by 1, thereby avoiding the problem of reduced security caused by the use of the same security protection parameters in subsequent RRC messages sent in SRB1.
  • COUNT value i.e., 0
  • the parameters used by the PDCP layer of the above-mentioned base station to perform encryption operations and integrity protection operations are second parameters or a second parameter set.
  • the above-mentioned second parameter or second parameter set includes at least one of the following: all bits of the COUNT value are 1, all bits of the BEARER value are 1, and DIRECTION is the downlink direction.
  • the above step 406 can be specifically implemented through the following steps 406c to 406e.
  • Step 406c The PDCP layer of the base station performs an encryption operation on the RRC re-establishment message using the first encryption key to generate a first byte stream.
  • the first byte stream includes the encrypted RRC re-establishment message.
  • Step 406d The PDCP layer of the base station performs an integrity protection operation on the RRC re-establishment message using the first integrity protection key to generate first information.
  • the PDCP layer of the base station performs security protection on the RRC re-establishment message, and the security protection includes an encryption operation and an integrity protection operation.
  • the MAC-I generated when the PDCP layer of the base station uses the first parameter or the first parameter set to perform an integrity protection operation on the RRC re-establishment message is different from the MAC-I generated when the PDCP layer of the base station uses the second parameter or the second parameter set to perform an integrity protection operation on the RRC re-establishment message.
  • Step 406e The PDCP layer of the base station transmits the first byte stream and the first information to the RRC layer of the base station.
  • the first MAC CE generated by the MAC layer of the above-mentioned base station includes a first byte stream, an NCC and first information, and the first information is transmitted from the RRC layer of the base station to the MAC layer of the base station.
  • the PDCP layer of the base station can return the first byte stream and the first information to the RRC layer of the base station, and then the RRC layer of the base station can pass the first byte stream, NCC and the first information to the MAC layer of the base station, so that the MAC layer of the base station can generate a first MAC CE based on the NCC, the first byte stream and the first information.
  • the PDCP layer of the base station may only perform encryption operations on the RRC re-establishment message.
  • the communication method provided by the embodiment of the present application further includes the following steps 407a and 407b.
  • Step 407a The RRC layer of the base station requests the PDCP layer of the base station to perform integrity protection operations on the NCC and the first byte stream.
  • the RRC layer of a base station when the RRC layer of a base station requests the PDCP layer of the base station to perform security protection on the RRC re-establishment message, and the RRC layer of the base station only receives the first byte stream returned by the PDCP layer of the base station, that is, the PDCP layer of the base station does not perform integrity protection operations on the RRC re-establishment message, the RRC layer of the base station may request the PDCP layer of the base station to perform integrity protection operations on the NCC and the first byte stream.
  • the RRC layer of the base station may transfer the NCC and the first byte stream to the PDCP layer of the base station.
  • Step 407b The PDCP layer of the base station performs an integrity protection operation on the NCC and the first byte stream using the first integrity protection key, generates a second MAC-I, and transmits the second MAC-I to the RRC layer of the base station.
  • the first MAC CE generated by the MAC layer of the above-mentioned base station includes a first byte stream, an NCC, and a second MAC-I, and the second MAC-I is transmitted from the RRC layer of the base station to the MAC layer of the base station.
  • the RRC layer of the base station when the RRC layer of the base station receives the second MAC-I returned by the PDCP layer of the base station, it can pass the first byte stream, NCC and the second MAC-I to the MAC layer of the base station, so that the MAC layer of the base station can generate a first MAC CE based on the NCC, the first byte stream and the second MAC-I.
  • the second MAC-I may be second information.
  • the parameters used by the PDCP layer of the base station when performing integrity protection on the NCC and the first byte stream through the first integrity protection key are the same as the parameters used when performing encryption operations on the RRC re-establishment message through the first encryption key.
  • the communication method provided by the embodiment of the present application further includes the following steps 408a and 408b.
  • Step 408a The MAC layer of the base station requests the PDCP layer of the base station to perform integrity protection operations on the NCC and the first byte stream.
  • the MAC layer of the base station when the MAC layer of the base station only receives the first byte stream and NCC transmitted by the RRC layer of the base station, that is, the PDCP layer of the base station does not perform integrity protection operations on the RRC re-establishment message, the MAC layer of the base station can request the PDCP layer of the base station to perform integrity protection operations on the first byte stream and NCC.
  • the MAC layer of the base station may transfer the NCC and the first byte stream to the PDCP layer of the base station.
  • Step 408b The PDCP layer of the base station performs integrity protection on the NCC and the first byte stream using the first integrity protection key, generates a third MAC-I, and transmits the third MAC-I to the MAC layer of the base station.
  • the first MAC CE generated by the MAC layer of the above-mentioned base station includes a first byte stream, an NCC and a third MAC-I.
  • the MAC layer of the base station when the MAC layer of the base station receives the third MAC-I returned by the PDCP layer of the base station, the MAC layer of the base station can generate a first MAC CE based on the NCC, the first byte stream and the third MAC-I.
  • the third MAC-I may be the second information.
  • the parameters used by the PDCP layer of the base station when performing integrity protection on the NCC and the first byte stream through the first integrity protection key are the same as the parameters used when performing encryption operations on the RRC re-establishment message through the first encryption key.
  • the MAC layer of the base station can request the PDCP layer of the base station to perform integrity protection operation on the NCC and the first byte stream to generate the third MAC-I, and then the MAC layer of the base station can generate the first MAC CE based on the NCC, the first byte stream and the third MAC-I returned by the PDCP layer of the base station, thereby improving the flexibility and reliability of the base station in generating the first MAC CE.
  • the NCC is also integrity protected, thereby improving security.
  • the parameters used by the PDCP layer of the base station to perform encryption operations and integrity protection operations in the embodiment of the present application are any of the following: a first parameter, a first parameter set, a second parameter, and a second parameter set.
  • the RRC re-establishment message is no longer transmitted through SRB1 like a conventional RRC message, but the RRC layer of the base station performs security protection on the message through inter-layer interaction with the PDCP layer, and then the RRC re-establishment message after security protection is delivered to the MAC layer through inter-layer interaction with the MAC layer, and is carried in the MAC CE as a byte stream and sent to the UE, and the MAC CE also carries the NCC for updating the key.
  • the UE first updates the key used by the UE based on the NCC in the MAC CE, and then performs security-related processing on the RRC re-establishment message based on the updated key.
  • the UE sends an RRC re-establishment request message to the base station.
  • the MAC layer of the base station generates the first MAC CE based on the NCC and the first byte stream.
  • the MAC layer of the base station sends the first MAC CE to the UE.
  • the MAC layer of the UE parses the first MAC CE, obtains the NCC and the first byte stream, and passes the NCC and the first byte stream to the RRC layer of the UE.
  • the RRC layer of the UE updates the key used by the UE based on the NCC, generates a first encryption key and a first integrity protection key based on the updated key, and requests the PDCP layer of the UE to process the first byte stream based on the first encryption key and the first integrity protection key.
  • the PDCP layer of the UE processes the first byte stream based on the first encryption key and the first integrity protection key to obtain a decrypted RRC re-establishment message, and passes the decrypted RRC re-establishment message to the RRC layer of the UE.
  • the RRC layer of the UE re-establishes the RRC connection based on the decrypted RRC re-establishment message.
  • the UE sends an RRC re-establishment completion message to the base station.
  • the communication method provided in the embodiment of the present application can be executed by a communication device.
  • the communication device provided in the embodiment of the present application is described by taking the communication device executing the communication method as an example.
  • the communication device provided in the embodiment of the present application also includes: a parsing module, a transmission module, a processing module and a request module.
  • the parsing module is used to parse the first MAC CE after the receiving module 42 receives the first MAC CE from the base station to obtain the NCC and the first byte stream.
  • the transmission module is used to transmit the NCC and the first byte stream parsed by the parsing module to the RRC layer of the UE.
  • the processing module is used to update the key used by the UE based on the NCC transmitted by the transmission module, and generate a first encryption key and a first integrity protection key based on the updated key.
  • the request module is used to request the PDCP layer of the UE to process the first byte stream based on the first encryption key and the first integrity protection key.
  • the processing module is also used to process the first byte stream based on the first encryption key and the first integrity protection key.
  • the first MAC CE includes first information, where the first information is a MAC-I generated by performing an integrity protection operation on an RRC re-establishment message; a processing module is specifically used to perform a decryption operation on a first byte stream using a first encryption key to obtain a decrypted RRC re-establishment message; and perform an integrity protection verification operation on the decrypted RRC re-establishment message using the first integrity protection key and the first information.
  • the first information is a MAC-I generated by performing an integrity protection operation on an RRC re-establishment message
  • a processing module is specifically used to perform a decryption operation on a first byte stream using a first encryption key to obtain a decrypted RRC re-establishment message
  • perform an integrity protection verification operation on the decrypted RRC re-establishment message using the first integrity protection key and the first information.
  • the first MAC CE includes second information, and the second information is a MAC-I generated by performing an integrity protection operation on the NCC and the first byte stream; the processing module is specifically used to perform an integrity protection verification operation on the NCC and the first byte stream using a first integrity protection key and the second information; and when the integrity protection verification operation on the NCC and the first byte stream is passed at the PDCP layer of the UE, a decryption operation is performed on the first byte stream using the first encryption key to obtain a decrypted RRC re-establishment message.
  • the second information is a MAC-I generated by performing an integrity protection operation on the NCC and the first byte stream
  • the processing module is specifically used to perform an integrity protection verification operation on the NCC and the first byte stream using a first integrity protection key and the second information
  • a decryption operation is performed on the first byte stream using the first encryption key to obtain a decrypted RRC re-establishment message.
  • the parameter used by the UE's PDCP layer to perform decryption operations and integrity protection verification operations is a first parameter or a first parameter set; wherein the first parameter or the first parameter set includes at least one of the following: the COUNT value is 0, BEARER is the bearer identifier of the wireless signaling bearer SRB1, and DIRECTION is the downlink direction.
  • the processing module is further used to set a first variable maintained by the PDCP entity corresponding to SRB1 to 1 or increase it by 1, where the first variable is a variable corresponding to the COUNT value of the next PDCP service data unit SDU expected to be received.
  • the parameter used by the UE's PDCP layer to perform decryption operations and integrity protection verification operations is a second parameter or a second parameter set; wherein the second parameter or the second parameter set includes at least one of the following: all bits of the COUNT value are 1, all bits of the BEARER value are 1, and DIRECTION is the downlink direction.
  • the processing module is specifically used to re-establish the RRC connection according to the decrypted RRC re-establishment message when the NCC in the first MAC CE is the same as the NCC in the RRC re-establishment message.
  • the receiving module 51 is used to receive an RRC re-establishment request message from the UE.
  • the sending module 52 is used to send a first MAC CE to the UE; wherein the first MAC CE includes an NCC and a first byte stream, the first byte stream includes an encrypted RRC re-establishment message, and the RRC re-establishment message is used to instruct the UE to re-establish the RRC connection.
  • An embodiment of the present application provides a communication device.
  • the base station After the base station receives the RRC re-establishment request message sent by the UE, it can send a first MAC CE including an NCC and a first byte stream to the UE.
  • the first byte stream includes an encrypted RRC re-establishment message. That is, the base station can send the NCC to the UE alone and does not carry it in the RRC re-establishment message. Therefore, when the UE obtains the NCC update key, the security of the RRC re-establishment message is also improved.
  • the communication device provided by the embodiment of the present application also includes: a processing module and an indication module.
  • the processing module is used to update the key used by the base station after the receiving module 51 receives the RRC re-establishment request message from the UE, and generate a first encryption key and a first integrity protection key based on the updated key.
  • the indication module is used to instruct the PDCP layer of the base station to restore integrity protection and encryption using the first encryption key and the first integrity protection key generated by the processing module.
  • the processing module is also used to generate an RRC re-establishment message and request the PDCP layer of the base station to perform security protection on the RRC re-establishment message.
  • the communication device provided by the embodiment of the present application also includes: a transmission module and a generation module.
  • the processing module is also used to perform security protection on the RRC re-establishment message after generating an RRC re-establishment message and requesting the PDCP layer of the base station to perform security protection on the RRC re-establishment message, generate a first byte stream, and transmit the first byte stream to the RRC layer of the base station.
  • the first byte stream includes the RRC re-establishment message after security protection, and the security protection includes at least one of the following: encryption operation, integrity protection operation.
  • the transmission module is used to transmit the first byte stream and the NCC saved in the UE context of the UE to the MAC layer of the base station.
  • the generation module is used to generate a first MAC CE based on the NCC and the first byte stream.
  • a generation module is specifically used to perform an integrity protection operation on the RRC re-establishment message through a first integrity protection key to generate a first MAC-I; and perform an encryption operation on the RRC re-establishment message and the first MAC-I through a first encryption key to generate a first PDCP PDU, the first PDCP PDU corresponds to a first byte stream, and the first PDCP PDU includes the encrypted RRC re-establishment message and the first MAC-I.
  • the processing module is specifically used to perform an encryption operation on the RRC re-establishment message through a first encryption key to generate a first byte stream; and perform an integrity protection operation on the RRC re-establishment message through a first integrity protection key to generate first information, the first information being a MAC-I generated by performing the integrity protection operation on the RRC re-establishment message; and transmitting the first byte stream and the first information to the RRC layer of the base station; wherein the first MAC CE generated by the MAC layer of the base station includes the first byte stream, NCC and the first information, and the first information is transmitted by the RRC layer of the base station to the MAC layer of the base station.
  • the processing module is also used to perform integrity protection operations on the NCC and the first byte stream through the first integrity protection key, generate a second MAC-I, and pass the second MAC-I to the RRC layer of the base station; wherein the first MAC CE generated by the MAC layer of the base station includes the first byte stream, the NCC and the second MAC-I, and the second MAC-I is transmitted by the RRC layer of the base station to the MAC layer of the base station.
  • the RRC of the UE may parse the first signaling to obtain the above-mentioned NCC.
  • Step 504 The RRC layer of the UE instructs the PDCP layer of the UE to use the first encryption key and the first integrity protection key to resume integrity protection and encryption.
  • Step 505. After the PDCP layer of the UE restores integrity protection and encryption using the first encryption key and the first integrity protection key, the PDCP layer of the UE processes the second PDCP PDU from the base station.
  • the PDCP layer of the UE uses the first encryption key and the first integrity protection key to restore integrity protection and encryption
  • the PDCP entity corresponding to the SRB1 of the UE receives the PDCP PDU, for example: the second PDCP PDU is received first due to the retransmission of the first signaling
  • the PDCP entity corresponding to the SRB1 of the UE will not process the second PDCP PDU first until the first signaling is received and the PDCP layer of the UE uses the first encryption key and the first integrity protection key to restore integrity protection and encryption. Only then can the PDCP layer of the UE process the second PDCP PDU.
  • the above-mentioned second PDCP PDU includes an integrity-protected and encrypted RRC re-establishment message, and the RRC re-establishment message is used to instruct the UE to re-establish the RRC connection.
  • the PDCP layer of the UE processes the second PDCP PDU from the base station after restoring integrity protection and encryption using the first encryption key and the first integrity protection key.
  • An embodiment of the present application provides a communication method.
  • the UE After the UE sends an RRC re-establishment request message to the base station, it can receive a first signaling from the base station for requesting the UE to update the key used by the UE.
  • the first signaling includes an NCC. Therefore, the RRC layer of the UE can update the key used by the UE based on the NCC included in the first signaling, and generate a first encryption key and a first integrity protection key based on the updated key, and instruct the PDCP layer of the UE to use the first encryption key and the first integrity protection key to restore integrity protection and encryption.
  • the PDCP layer of the UE restores integrity protection and encryption using the first encryption key and the first integrity protection key, it can process a second PDCP PDU from the base station.
  • the second PDCP PDU includes an integrity-protected and encrypted RRC re-establishment message.
  • the RRC re-establishment message is used to instruct the UE to re-establish the RRC connection. That is, the PDCP layer of the UE first restores integrity protection and encryption, and then processes the second PDCP PDU from the base station. Therefore, the RRC re-establishment message can be integrity protected and encrypted, thereby improving the security of the RRC re-establishment message.
  • Step 502b The MAC layer of the UE parses the second MAC CE, obtains the NCC, and submits the NCC to the RRC layer of the UE.
  • the MAC layer of the UE can parse the second MAC CE, obtain the above-mentioned NCC, and submit the NCC to the RRC layer of the UE through inter-layer interaction.
  • Step 502c The PDCP layer of the UE receives a PDCP control PDU from the base station.
  • the PDCP layer of the UE may specifically be a PDCP entity corresponding to SRB1.
  • Step 504a The RRC layer of the UE requests the PDCP layer of the UE to perform an integrity protection verification operation on the NCC using the first integrity protection key and the third information.
  • Step 504b The PDCP layer of the UE performs an integrity protection verification operation on the NCC using the first integrity protection key and the third information.
  • the RRC layer of the UE may request the PDCP layer of the UE to perform integrity protection verification operations on the NCC using the first integrity protection key and the MAC-I included in the PDCP control PDU.
  • the above-mentioned second parameter or second parameter set includes at least one of the following: all bits of the COUNT value are 1, all bits of the BEARER value are 1, and DIRECTION is the downlink direction.
  • the RRC layer of the UE can process the decrypted RRC re-establishment message and re-establish the RRC connection according to the RRC re-establishment message.
  • the above-mentioned first signaling is used to request the UE to update the key used by the UE, the first signaling includes NCC, and the first signaling is the second MAC CE or PDCP control PDU.
  • Step 703 The base station sends a second PDCP PDU to the UE.
  • the RRC layer of the base station may instruct the PDCP layer of the base station to use the first encryption key and the first integrity protection key to restore integrity protection and encryption, or, before the PDCP layer of the base station generates a PDCP control PDU, the RRC layer of the base station may instruct the PDCP layer of the base station to use the first encryption key and the first integrity protection key to restore integrity protection and encryption, or, before the base station sends the PDCP control PDU to the UE, the RRC layer of the base station may instruct the PDCP layer of the base station to use the first encryption key and the first integrity protection key to restore integrity protection and encryption.
  • the embodiments of the present application are not limited to this.
  • step 702 can be specifically implemented through the following steps 702a to 702c.
  • the above-mentioned second MAC CE is used to request the UE to update the key used by the UE, and the second MAC CE includes the NCC.
  • the above-mentioned second MAC CE is used to send NCC to the UE.
  • Step 702a1 The RRC layer of the base station requests the PDCP layer of the base station to perform an integrity protection operation on the NCC using a first integrity protection key.
  • Step 702a2 The PDCP layer of the base station performs an integrity protection operation on the NCC using the first integrity protection key, generates a fourth MAC-I, and transmits it to the RRC layer of the base station.
  • Step 702a3 The RRC layer of the base station transfers the NCC and the fourth MAC-I to the MAC layer of the base station.
  • the above-mentioned second MAC CE includes NCC and a fourth MAC-I.
  • the above-mentioned second parameter or second parameter set includes at least one of the following: all bits of the COUNT value are 1, all bits of the BEARER value are 1, and DIRECTION is the downlink direction.
  • step 702b can be specifically implemented through the following steps 702b1 to 702b3.
  • Step 702b1 The MAC layer of the base station requests the PDCP layer of the base station to perform an integrity protection operation on the NCC using a first integrity protection key.
  • the fifth MAC-I may be the third information.
  • the RRC layer of the base station can obtain the NCC stored in the UE context of the UE.
  • the RRC layer of the base station may deliver the NCC to the PDCP layer of the UE through inter-layer interaction.
  • the above-mentioned PDCP control PDU is used to request the UE to update the key used by the UE, and the PDCP control PDU includes the NCC.
  • the PDCP control PDU corresponds to a dedicated PDU Type value, that is, a PDU Type value is assigned to the PDCP control PDU.
  • a PDU Type value is assigned to the PDCP control PDU.
  • Step 702f The base station sends a PDCP control PDU to the UE.
  • step 702e can be specifically implemented through the following steps 702e1 and 702e2.
  • the sixth MAC-I may be the third information.
  • the above-mentioned PDCP control PDU includes a sixth MAC-I.
  • the parameter used by the PDCP layer of the above-mentioned base station to perform integrity protection operation on the NCC is a second parameter or a second parameter set.
  • Step 703a The RRC layer of the base station generates an RRC re-establishment message and transmits it to the PDCP layer of the base station.
  • step 703 can be specifically implemented through the following step 703e.
  • Step 703e After the first signaling is sent, or after the first signaling is successfully sent, or after the base station receives a reception confirmation message of the first signaling, the base station sends a second PDCP PDU to the UE.
  • the communication method provided in the embodiment of the present application may include the following steps B1 to B12.
  • the UE is in connected state and the RRC layer connection needs to be re-established.
  • the base station receives an RRC re-establishment request message from the UE.
  • the MAC layer of the base station generates a second MAC CE including the NCC based on the NCC.
  • the RRC layer of the UE updates the key used by the UE based on the NCC included in the second MAC CE, generates a first encryption key and a first integrity protection key based on the updated key, and instructs the PDCP layer of the UE to restore integrity protection and encryption using the first encryption key and the first integrity protection key.
  • the base station sends the second PDCP PDU to the UE.
  • the PDCP layer of the UE uses the first encryption key and the first integrity protection key to perform decryption operations and integrity protection verification operations on the second PDCP PDU, and submits the decrypted RRC re-establishment message to the RRC layer of the UE.
  • the RRC layer of the UE re-establishes the RRC connection based on the decrypted RRC re-establishment message.
  • the UE sends an RRC re-establishment completion message to the base station.
  • the base station can put the subPDU corresponding to the second MAC CE and the subPDU corresponding to the second PDCP PDU in one MAC PDU and send it to the UE, but the subPDU corresponding to the second MAC CE is placed in front.
  • the PDCP layer of the UE can process the second PDCP PDU.
  • the PDCP entity corresponding to the SRB1 of the UE receives the PDCP PDU, for example: the second PDCP PDU is received first due to the retransmission of the second MAC CE, the PDCP entity corresponding to the SRB1 of the UE will not process the second PDCP PDU first until the second MAC CE is received and the PDCP layer of the UE uses the first encryption key and the first integrity protection key to restore integrity protection and encryption. Only then can the PDCP layer of the UE process the second PDCP PDU.
  • the UE is in connected state and the RRC layer connection needs to be re-established.
  • the base station receives an RRC re-establishment request message from the UE.
  • the base station sends a PDCP control PDU to the UE.
  • the RRC layer of the UE updates the key used by the UE based on the NCC included in the PDCP control PDU, generates a first encryption key and a first integrity protection key based on the updated key, and instructs the PDCP layer of the UE to restore integrity protection and encryption using the first encryption key and the first integrity protection key.
  • the base station sends the second PDCP PDU to the UE.
  • the RRC layer of the UE re-establishes the RRC connection based on the decrypted RRC re-establishment message.
  • FIG15 shows a possible structural diagram of a communication device involved in an embodiment of the present application, which is applied to a UE.
  • a communication device 60 may include: a sending module 61 , a receiving module 62 , a processing module 63 and an indicating module 64 .
  • the instructing module 64 is used to instruct the PDCP layer of the UE to use the first encryption key and the first integrity protection key generated by the processing module 63 to restore integrity protection and encryption.
  • the processing module 63 is also used to process a second PDCP PDU from the base station after the PDCP layer of the UE uses the first encryption key and the first integrity protection key to restore integrity protection and encryption, the second PDCP PDU including an integrity protected and encrypted RRC re-establishment message, and the RRC re-establishment message is used to instruct the UE to re-establish the RRC connection.
  • the PDCP layer of the UE uses the first encryption key and the first integrity protection key to restore integrity protection and encryption, it can process a second PDCP PDU from the base station, the second PDCP PDU including an integrity-protected and encrypted RRC re-establishment message, and the RRC re-establishment message is used to instruct the UE to re-establish the RRC connection. That is, the PDCP layer of the UE first restores integrity protection and encryption, and then processes the second PDCP PDU from the base station. Therefore, the RRC re-establishment message can be integrity protected and encrypted, thereby improving the security of the RRC re-establishment message.
  • the processing module 63 is further configured to enter an idle state when the PDCP layer of the UE fails to perform an integrity protection verification operation on the NCC.
  • the parameter used by the PDCP layer of the UE to perform integrity protection verification operations on the NCC is a second parameter or a second parameter set; wherein the second parameter or the second parameter set includes at least one of the following: all bits of the COUNT value are 1, all bits of the BEARER value are 1, and DIRECTION is the downlink direction.
  • the receiving module 62 is specifically used to receive the second MAC CE from the base station; and parse the second MAC CE to obtain the NCC, and submit the NCC to the RRC layer of the UE.
  • the receiving module 62 is specifically configured to receive a PDCP control PDU from a base station, parse the PDCP control PDU, obtain an NCC, and submit the NCC to the RRC layer of the UE.
  • the communication device provided in the embodiment of the present application can implement each process implemented by the UE in the above method embodiment and achieve the same technical effect. To avoid repetition, it will not be repeated here.
  • the receiving module 71 is configured to receive an RRC re-establishment request message from a UE.
  • the sending module 72 is used to send a first signaling to the UE, where the first signaling is used to request the UE to update the key used by the UE, the first signaling includes an NCC, and the first signaling is a second MAC CE or a PDCP control PDU; and send a second PDCP PDU to the UE, where the second PDCP PDU includes an integrity protected and encrypted RRC re-establishment message, and the RRC re-establishment message is used to instruct the UE to re-establish the RRC connection.
  • a generation module is specifically used to request the PDCP layer of the base station to perform an integrity protection operation on the NCC through a first integrity protection key; and perform an integrity protection operation on the NCC through the first integrity protection key to generate a fifth MAC-I, and pass it to the MAC layer of the base station; and generate a second MAC CE based on the NCC and the fifth MAC-I, the second MAC CE including the NCC and the fifth MAC-I.
  • an embodiment of the present application further provides a communication device 5000, including a processor 5001 and a memory 5002, wherein the memory 5002 stores a program or instruction that can be run on the processor 5001.
  • the communication device 5000 is a UE
  • the program or instruction is executed by the processor 5001 to implement the various steps of the above-mentioned UE side method embodiment, and can achieve the same technical effect.
  • the communication device 5000 is a base station
  • the program or instruction is executed by the processor 5001 to implement the various steps of the above-mentioned base station method embodiment, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.
  • the input unit 104 may include a graphics processing unit (GPU) 1041 and a microphone 1042, and the graphics processor 1041 processes the image data of a static picture or video obtained by an image capture device (such as a camera) in a video capture mode or an image capture mode.
  • the display unit 106 may include a display panel 1061, and the display panel 1061 may be configured in the form of a liquid crystal display, an organic light emitting diode, etc.
  • the user input unit 107 includes a touch panel 1071 and at least one of other input devices 1072.
  • the touch panel 1071 is also called a touch screen.
  • the touch panel 1071 may include two parts: a touch detection device and a touch controller.
  • Other input devices 1072 may include, but are not limited to, a physical keyboard, function keys (such as a volume control key, a switch key, etc.), a trackball, a mouse, and a joystick, which will not be repeated here.
  • the RF unit 101 after receiving downlink data from the network side device, can transmit the data to the processor 110 for processing; in addition, the RF unit 101 can send uplink data to the network side device.
  • the RF unit 101 includes but is not limited to an antenna, an amplifier, a transceiver, a coupler, a low noise amplifier, a duplexer, etc.
  • the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory.
  • the volatile memory may be a random access memory (RAM), a static random access memory (SRAM), a dynamic random access memory (DRAM), a synchronous dynamic random access memory (SDRAM), a double data rate synchronous dynamic random access memory (DDRSDRAM), an enhanced synchronous dynamic random access memory (ESDRAM), a synchronous link dynamic random access memory (SLDRAM) and a direct memory bus random access memory (DRRAM).
  • the memory 109 in the embodiment of the present application includes but is not limited to these and any other suitable types of memory.
  • the processor 110 may include one or more processing units; optionally, the processor 110 integrates an application processor and a modem processor, wherein the application processor mainly processes operations related to an operating system, a user interface, and application programs, and the modem processor mainly processes wireless communication signals, such as a baseband processor. It is understandable that the modem processor may not be integrated into the processor 110.
  • the UE provided in the embodiment of the present application can implement each process implemented by the terminal in the above method embodiment and achieve the same technical effect. To avoid repetition, it will not be repeated here.
  • the embodiment of the present application also provides a base station, including a processor and a communication interface, the communication interface and the processor are coupled, and the processor is used to run a program or instruction to implement the steps of the above method embodiment.
  • the base station embodiment corresponds to the above base station method embodiment, and each implementation process and implementation method of the above method embodiment can be applied to the base station embodiment and can achieve the same technical effect.
  • the method executed by the base station in the above embodiment may be implemented in the baseband device 63, which includes a baseband processor.
  • the base station may also include a network interface 66, which may be, for example, a common public radio interface (CPRI).
  • a network interface 66 which may be, for example, a common public radio interface (CPRI).
  • CPRI common public radio interface
  • An embodiment of the present application further provides a chip, which includes a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the various processes of the above-mentioned method embodiment, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.
  • the chip mentioned in the embodiments of the present application can also be called a system-level chip, a system chip, a chip system or a system-on-chip chip, etc.
  • the embodiments of the present application further provide a computer program/program product, which is stored in a storage medium and is executed by at least one processor to implement the various processes of the above-mentioned method embodiments and can achieve the same technical effect. To avoid repetition, it will not be described here.
  • An embodiment of the present application further provides a communication system, including: a UE and a terminal, wherein the UE can be used to execute the steps of the communication method described above, and the terminal can be used to execute the steps of the communication method described above.
  • the technical solution of the present application can be embodied in the form of a computer software product, which is stored in a storage medium (such as ROM/RAM, magnetic disk, optical disk), and includes a number of instructions for a terminal (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in each embodiment of the present application.
  • a storage medium such as ROM/RAM, magnetic disk, optical disk
  • a terminal which can be a mobile phone, computer, server, air conditioner, or network device, etc.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本申请公开了一种通信方法、装置、用户设备、基站及存储介质,属于通信技术领域,该方法包括:用户设备UE向基站发送无线资源控制RRC重建立请求消息;UE的媒体接入控制MAC层接收来自基站的第一媒体接入控制控制单元MAC CE;其中,第一MAC CE包括下一跳链计数NCC和第一字节流,第一字节流包括加密后的RRC重建立消息,RRC重建立消息用于指示UE重建立RRC连接。

Description

通信方法、装置、用户设备、基站及存储介质
相关申请的交叉引用
本申请主张在2024年01月12日在中国提交的申请号为202410052512.6的中国专利的优先权,其全部内容通过引用包含于此。
技术领域
本申请属于通信技术领域,具体涉及一种通信方法、装置、用户设备、基站及存储介质。
背景技术
目前,用户设备(User Equipment,UE)和基站在无线资源控制(Radio Resource Control,RRC)重建立过程中会更新使用的密钥,具体地,在UE侧,UE可以接收基站发送的RRC重建立消息,该RRC重建立消息中携带下一跳链计数(NextHop Chaining Count,NCC),UE可以根据该RRC重建立消息里携带的NCC,对UE使用的密钥进行更新。由于UE更新密钥需要用到NCC,因此基站发送的RRC重建立消息不能加密,若加密,UE无法获取到NCC,从而无法更新使用的密钥。如此,RRC重建立消息的安全性较低,因此,如何提高RRC重建立消息的安全性是本申请亟待解决的问题。
发明内容
本申请实施例提供一种通信方法、装置、用户设备、基站及存储介质,能够提高RRC重建立消息的安全性。
第一方面,提供了一种通信方法,该方法包括:UE向基站发送RRC重建立请求消息;UE的媒体接入控制(Medium Access Control,MAC)层接收来自基站的第一媒体接入控制单元(MAC Control Element,MAC CE);其中,第一MAC CE包括NCC和第一字节流,第一字节流包括加密后的RRC重建立消息,RRC重建立消息用于指示UE重建立RRC连接。
第二方面,提供了一种通信方法,该方法包括:基站接收来自UE的RRC重建立请求消息;基站的MAC层向UE发送第一MAC CE;其中,第一MAC CE包括NCC和第一字节流,第一字节流包括加密后的RRC重建立消息,RRC重建立消息用于指示UE重建立RRC连接。
第三方面,提供了一种通信方法,该方法包括:UE向基站发送RRC重建立请求消息;UE接收来自基站的第一信令,第一信令用于请求UE更新UE使用的密钥,第一信令包括NCC,第一信令为第二MAC CE或PDCP控制PDU;UE的RRC层基于NCC更新UE使用的密钥,并基于更新后的密钥生成第一加密密钥和第一完整性保护密钥;UE的RRC层指示UE的分组数据汇聚协议(Packet Data Convergence Protocol,PDCP)层使用第一加密密钥和第一完整性保护密钥恢复完整性保护和加密;在UE的PDCP层使用第一加密密钥和第一完整性保护密钥恢复完整性保护和加密之后,UE的PDCP层处理来自基站的第二PDCP协议数据单元(Protocol Data Unit,PDU),第二PDCP PDU中包括被完整性保护和加密的RRC重建立消息,RRC重建立消息用于指示UE重建立RRC连接。
第四方面,提供了一种通信方法,该方法包括:基站接收来自UE的RRC重建立请求消息;基站向UE发送第一信令,第一信令用于请求UE更新UE使用的密钥,第一信令包括NCC,第一信令为第二MAC CE或PDCP控制PDU;基站向UE发送第二PDCP PDU,第二PDCP PDU中包括被完整性保护和加密的RRC重建立消息,RRC重建立消息用于指示UE重建立RRC连接。
第五方面,提供了一种通信装置,应用于UE,该装置包括:发送模块和接收模块。发送模块,用于向基站发送RRC重建立请求消息。接收模块,用于接收来自基站的第一MAC CE;其中,第一MAC CE包括NCC和第一字节流,第一字节流包括加密后的RRC重建立消息,RRC重建立消息用于指示UE重建立RRC连接。
第六方面,提供了一种通信装置,应用于基站,该装置包括:接收模块和发送模块。接收模块,用于接收来自UE的RRC重建立请求消息。发送模块,用于向UE发送第一MAC CE;其中,第一MAC CE包括NCC和第一字节流,第一字节流包括加密后的RRC重建立消息,RRC重建立消息用于指示UE重建立RRC连接。
第七方面,提供了一种通信装置,应用于UE,该装置包括:发送模块、接收模块、处理模块和指示模块。发送模块,用于向基站发送RRC重建立请求消息。接收模块,用于接收来自基站的第一信令,第一信令用于请求UE更新UE使用的密钥,第一信令包括NCC,第一信令为第二MAC CE或PDCP控制PDU。处理模块,用于基于NCC更新UE使用的密钥,并基于更新后的密钥生成第一加密密钥和第一完整性保护密钥。请求模块,用于指示UE的PDCP层使用处理模块生成的第一加密密钥和第一完整性保护密钥恢复完整性保护和加密。处理模块,还用于在UE的PDCP层使用第一加密密钥和第一完整性保护密钥恢复完整性保护和加密之后,处理来自基站的第二PDCP PDU,第二PDCP PDU中包括被完整性保护和加密的RRC重建立消息,RRC重建立消息用于指示UE重建立RRC连接。
第八方面,提供了一种通信装置,该装置包括:接收模块和发送模块。接收模块,用于接收来自UE的RRC重建立请求消息。发送模块,用于向UE发送第一信令,第一信令用于请求UE更新UE使用的密钥,第一信令包括NCC,第一信令为第二MAC CE或PDCP控制PDU;并向UE发送第二PDCP PDU,第二PDCP PDU中包括被完整性保护和加密的RRC重建立消息,RRC重建立消息用于指示UE重建立RRC连接。
第九方面,提供了一种UE,该UE包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如第一方面所述的方法的步骤。
第十方面,提供了一种UE,包括处理器及通信接口,其中,所述通信接口用于向基站发送RRC重建立请求消息;并接收来自基站的第一MAC CE;其中,第一MAC CE包括NCC和第一字节流,第一字节流包括加密后的RRC重建立消息,RRC重建立消息用于指示UE重建立RRC连接。
第十一方面,提供了一种基站,该基站包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如第二方面所述的方法的步骤。
第十二方面,提供了一种基站,包括处理器及通信接口,其中,所述通信接口用于接收来自UE的RRC重建立请求消息;并向UE发送第一MAC CE;其中,第一MAC CE包括NCC和第一字节流,第一字节流包括加密后的RRC重建立消息,RRC重建立消息用于指示UE重建立RRC连接。
第十三方面,提供了一种UE,该UE包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如第三方面所述的方法的步骤。
第十四方面,提供了一种UE,包括处理器及通信接口,其中,所述通信接口用于向基站发送RRC重建立请求消息;并接收来自基站的第一信令,第一信令用于请求UE更新UE使用的密钥,第一信令包括NCC,第一信令为第二MAC CE或PDCP控制PDU;所述处理器用于基于NCC更新UE使用的密钥,并基于更新后的密钥生成第一加密密钥和第一完整性保护密钥;并指示UE的PDCP层使用第一加密密钥和第一完整性保护密钥恢复完整性保护和加密;以及在UE的PDCP层使用第一加密密钥和第一完整性保护密钥恢复完整性保护和加密之后,处理来自基站的第二PDCP PDU,第二PDCP PDU中包括被完整性保护和加密的RRC重建立消息,RRC重建立消息用于指示UE重建立RRC连接。
第十五方面,提供了一种基站,该基站包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如第四方面所述的方法的步骤。
第十六方面,提供了一种基站,包括处理器及通信接口,其中,所述通信接口用于接收来自UE的RRC重建立请求消息;并向UE发送第一信令,第一信令用于请求UE更新UE使用的密钥,第一信令包括NCC,第一信令为第二MAC CE或PDCP控制PDU;以及向UE发送第二PDCP PDU,第二PDCP PDU中包括被完整性保护和加密的RRC重建立消息,RRC重建立消息用于指示UE重建立RRC连接。
第十七方面,提供了一种可读存储介质,所述可读存储介质上存储程序或指令,所述程序或指令被处理器执行时实现如第一方面所述的方法的步骤,或者实现如第二方面所述的方法的步骤,或者实现如第三方面所述的方法的步骤,或者实现如第四方面所述的方法的步骤。
第十八方面,提供了一种无线通信系统,包括:UE及基站,所述UE可用于执行如第一方面所述的方法的步骤,或者执行如第三方面所述的方法的步骤,所述基站可用于执行如第二方面所述的方法的步骤,或者执行如第四方面所述的方法的步骤。
第十九方面,提供了一种芯片,所述芯片包括处理器和通信接口,所述通信接口和所述处理器耦合,所述处理器用于运行程序或指令,实现如第一方面所述的方法,或实现如第二方面所述的方法,或实现如第三方面所述的方法,或实现如第四方面所述的方法。
第二十方面,提供了一种计算机程序/程序产品,所述计算机程序/程序产品被存储在存储介质中,所述程序/程序产品被至少一个处理器执行以实现如第一方面所述的通信方法的步骤,或实现如第二方面所述的通信方法的步骤,或实现如第三方面所述的通信方法的步骤,或实现如第四方面所述的通信方法的步骤。
在本申请实施例中,UE向基站发送RRC重建立请求消息;UE的媒体接入控制(Medium Access Control,MAC)层接收来自基站的第一媒体接入控制单元(MAC Control Element,MAC CE);其中,第一MAC CE包括NCC和第一字节流,第一字节流包括加密后的RRC重建立消息,RRC重建立消息用于指示UE重建立RRC连接。本方案中,由于在UE向基站发送RRC重建立请求消息后,基站可以向UE发送包括NCC和第一字节流的第一MAC CE,第一字节流包括加密后的RRC重建立消息,即基站可以将NCC携带在加密后的RRC重建立消息的外面,因此在UE获取到NCC更新密钥的同时,也提高了RRC重建立消息的安全性。
附图说明
图1是本申请实施例提供的一种无线通信系统的架构示意图;
图2是本申请实施例提供的一种通信方法的流程示意图之一;
图3是本申请实施例提供的一种通信方法的流程示意图之二;
图4是本申请实施例提供的一种第一MAC CE的结构示意图之一;
图5是本申请实施例提供的一种第一PDCP PDU的结构示意图;
图6是本申请实施例提供的一种第一MAC CE的结构示意图之二;
图7是本申请实施例提供的一种通信方法的流程示意图之三;
图8是本申请实施例提供的一种通信装置的结构示意图之一;
图9是本申请实施例提供的一种通信装置的结构示意图之二;
图10是本申请实施例提供的一种通信方法的流程示意图之四;
图11是本申请实施例提供的一种通信方法的流程示意图之五;
图12是本申请实施例提供的一种PDCP控制PDU的结构示意图;
图13是本申请实施例提供的一种通信方法的流程示意图之六;
图14是本申请实施例提供的一种通信方法的流程示意图之七;
图15是本申请实施例提供的一种通信装置的结构示意图之三;
图16是本申请实施例提供的一种通信装置的结构示意图之四;
图17是本申请实施例提供的一种通信设备的硬件结构示意图;
图18是本申请实施例提供的一种UE的硬件结构示意图;
图19是本申请实施例提供的一种基站的硬件结构示意图。
具体实施方式
下面将结合本申请实施例中的附图,对本申请实施例中的技术方案进行清楚描述,显然,所描述的实施例是本申请一部分实施例,而不是全部的实施例。基于本申请中的实施例,本领域普通技术人员所获得的所有其他实施例,都属于本申请保护的范围。
本申请的术语“第一”、“第二”等是用于区别类似的对象,而不用于描述特定的顺序或先后次序。应该理解这样使用的术语在适当情况下可以互换,以便本申请的实施例能够以除了在这里图示或描述的那些以外的顺序实施,且“第一”、“第二”所区别的对象通常为一类,并不限定对象的个数,例如第一对象可以是一个,也可以是多个。此外,本申请中的“或”表示所连接对象的至少其中之一。例如“A或B”涵盖三种方案,即,方案一:包括A且不包括B;方案二:包括B且不包括A;方案三:既包括A又包括B。字符“/”一般表示前后关联对象是一种“或”的关系。
本申请的术语“指示”既可以是一个直接的指示(或者说显式的指示),也可以是一个间接的指示(或者说隐含的指示)。其中,直接的指示可以理解为,发送方在发送的指示中明确告知了接收方具体的信息、需要执行的操作或请求结果等内容;间接的指示可以理解为,接收方根据发送方发送的指示确定对应的信息,或者进行判断并根据判断结果确定需要执行的操作或请求结果等。
本申请的术语“至少一个(项)”、“至少之一”等指其包含对象中的任意一个、任意两个或两个以上的组合。例如,a、b、c中的至少一个(项),可以表示:“a”、“b”、“c”、“a和b”、“a和c”、“b和c”以及“a、b和c”,其中a,b,c可以是单个,也可以是多个。同理,“至少两个(项)”是指两个或两个以上,其表达的含义与“至少一个(项)”类似。
值得指出的是,本申请实施例所描述的技术不限于长期演进型(Long Term Evolution,LTE)/LTE的演进(LTE-Advanced,LTE-A)系统,还可用于其他无线通信系统,诸如码分多址(Code Division Multiple Access,CDMA)、时分多址(Time Division Multiple Access,TDMA)、频分多址(Frequency Division Multiple Access,FDMA)、正交频分多址(Orthogonal Frequency Division Multiple Access,OFDMA)、单载波频分多址(Single-carrier Frequency-Division Multiple Access,SC-FDMA)或其他系统。本申请实施例中的术语“系统”和“网络”常被可互换地使用,所描述的技术既可用于以上提及的系统和无线电技术,也可用于其他系统和无线电技术。以下描述出于示例目的描述了新空口(New Radio,NR)系统,并且在以下大部分描述中使用NR术语,但是这些技术也可应用于NR系统以外的系统,如第6代(6th Generation,6G)通信系统。
图1示出本申请实施例可应用的一种无线通信系统的框图。无线通信系统包括终端11和网络侧设备12。其中,终端11可以是UE、手机、平板电脑(Tablet Personal Computer)、膝上型电脑(Laptop Computer)、笔记本电脑、个人数字助理(Personal Digital Assistant,PDA)、掌上电脑、上网本、超级移动个人计算机(Ultra-mobile Personal Computer,UMPC)、移动上网装置(Mobile Internet Device,MID)、增强现实(Augmented Reality,AR)、虚拟现实(Virtual Reality,VR)设备、机器人、可穿戴式设备(Wearable Device)、飞行器(flight vehicle)、车载设备(Vehicle User Equipment,VUE)、船载设备、行人终端(Pedestrian User Equipment,PUE)、智能家居(具有无线通信功能的家居设备,如冰箱、电视、洗衣机或者家具等)、游戏机、个人计算机(Personal Computer,PC)、柜员机或者自助机等终端侧设备。可穿戴式设备包括:智能手表、智能手环、智能耳机、智能眼镜、智能首饰(智能手镯、智能手链、智能戒指、智能项链、智能脚镯、智能脚链等)、智能腕带、智能服装等。其中,车载设备也可以称为车载终端、车载控制器、车载模块、车载部件、车载芯片或车载单元等。需要说明的是,在本申请实施例并不限定终端11的具体类型。网络侧设备12可以包括接入网设备或核心网设备,其中,接入网设备也可以称为无线接入网(Radio Access Network,RAN)设备、无线接入网功能或无线接入网单元。接入网设备可以包括基站、无线局域网(Wireless Local Area Network,WLAN)接入点(Access Point,AP)或无线保真(Wireless Fidelity,WiFi)节点等。其中,基站可被称为节点B(Node B,NB)、演进节点B(Evolved Node B,eNB)、下一代节点B(the next generation Node B,gNB)、新空口节点B(New Radio Node B,NR Node B)、接入点、中继站(Relay Base Station,RBS)、服务基站(Serving Base Station,SBS)、基收发机站(Base Transceiver Station,BTS)、无线电基站、无线电收发机、基本服务集(Basic Service Set,BSS)、扩展服务集(Extended Service Set,ESS)、家用B节点(home Node B,HNB)、家用演进型B节点(home evolved Node B)、发送接收点(Transmission Reception Point,TRP)或所属领域中其他某个合适的术语,只要达到相同的技术效果,所述基站不限于特定技术词汇,需要说明的是,在本申请实施例中仅以NR系统中的基站为例进行介绍,并不限定基站的具体类型。
下面对本申请实施例提供的通信方法中涉及的一些概念和/或术语做一下解释说明。
1、RRC重建立:在UE处于RRC连接态,但是UE发生了无线链路失败,或完整性检查失败等情况下,UE可以执行小区选择过程以选择一个目标小区发起RRC重建立过程,通过SRB0向目标小区所在的基站发送RRC Reestablishment Request。
2、无线接口控制面协议栈:无线接口控制面协议栈从上到下依次为:RRC层,PDCP层,RLC层,MAC层和PHY层。
3、PDCP层的PDU分为两种类型:Data PDU和Control PDU。其中Data PDU用来传送用户面和控制面的数据以及完整性保护产生的数字签名MAC-I,Control PDU是PDCP层自己生成的,用来传送,比如,PDCP的状态报告和压缩/解压模块产生的解压反馈报文。PDCP层从上层接收到的数据包被称之为PDCP服务数据单元(Service Data Unit,SDU),PDCP层对其进行处理后生成PDCP Data PDU,然后递交给下一层进行处理。
下面结合附图,通过一些实施例及其应用场景对本申请实施例提供的通信方法进行详细地说明。
目前,UE和基站在RRC重建立过程中会更新使用的密钥,具体地,在UE侧,UE可以接收基站发送的RRC重建立消息,该RRC重建立消息中携带NCC,UE可以根据该RRC重建立消息里携带的NCC,对UE使用的密钥进行更新。由于UE更新密钥需要用到NCC,因此基站发送的RRC重建立消息不能加密,若加密,UE无法获取到NCC,从而无法更新使用的密钥。具体地,在基站侧,若当前密钥对应的NCC与该UE的UE上下文中保存的NCC一样,则基于当前密钥进行更新,否则基于该UE的UE上下文中保存的NCC对应的下一跳(Next Hop,NH)更新密钥,并基于更新的密钥生成加密密钥和完整性保护密钥,并配置PDCP层使用新的完整性保护密钥恢复完整性保护。UE上下文中保存的NCC及其对应的NH可能是上次切换过程中核心网发送给基站的,RRC层生成RRC消息RRC Reestablishment。RRC Reestablishment消息里携带NCC,作为PDCP SDU被递交给SRB1对应的PDCP实体,PDCP实体使用新的完整性保护的密钥进行完整性保护,但是不进行加密操作,然后生成PDCP PDU,将生成的PDCP PDU递交给无线链路层控制协议(Radio Link Control,RLC)层以发送给UE。可以看出,RRCReestablishment消息被完整性保护,但是未加密。进一步,基站配置PDCP层使用新的加密密钥恢复加密。在UE侧,UE收到RRCReestablishment消息后,根据该消息里携带的NCC更新密钥,生成新的加密密钥和完整性保护密钥,然后请求PDCP层基于该新的完整性保护密钥验证该消息。如果验证成功,则配置PDCP层使用新的完整性保护密钥和加密密钥恢复完整性保护和加密。由此可以看出,由于UE需要用到NCC更新密钥,因此RRCReestablishment消息只能进行完整性保护,而不能加密,否则UE无法解密RRCReestablishment而获取不到NCC,进一步导致无法更新密钥。如此,RRC重建立消息的安全性较低,因此,如何提高RRC重建立消息的安全性是本申请亟待解决的问题。
在本申请实施例中,由于在UE向基站发送RRC重建立请求消息后,基站可以向UE发送包括NCC和第一字节流的第一MAC CE,第一字节流包括加密后的RRC重建立消息,即基站可以将NCC携带在加密后的RRC重建立消息的外面,因此在UE获取到NCC更新密钥的同时,也提高了RRC重建立消息的安全性。
本申请实施例提供一种通信方法,图2示出了本申请实施例提供的一种通信方法的流程图。如图2所示,本申请实施例提供的通信方法可以包括下述的步骤201和步骤202。
步骤201、UE向基站发送RRC重建立请求消息。
本申请的一些实施例中,在UE处于RRC连接态,但是RRC连接需要重建立,例如:处于连接态的UE发生了无线链路失败,或完整性检查失败等情况下,UE可以执行小区选择过程以选择一个目标小区发起RRC重建立过程,通过SRB0向目标小区所在的基站发送RRC Reestablishment Request,即RRC重建立请求消息。
步骤202、UE的MAC层接收来自基站的第一MAC CE。
本申请的实施例中,上述第一MAC CE包括NCC和第一字节流,第一字节流包括加密后的RRC重建立消息,RRC重建立消息用于指示UE重建立RRC连接。
本申请的一些实施例中,NCC用于指示UE如何更新UE使用的密钥,具体的,可以参考3GPP TS33.501协议里的图6.9.2.1.1-1来进行描述:如果当前密钥(即图中的某一个KgNB)对应的NCC与上述接收到的NCC相同,则基于当前密钥生成新的密钥,即图中的水平衍生;如果当前密钥对应的NCC与上述接收到的NCC不同,则基于上述接收到的NCC对应的NH生成新的密钥,即图中的垂直衍生。进一步的,UE基于更新后的密钥生成第一加密密钥和第一完整性保护密钥。
本申请的一些实施例中,UE可以使用第一加密密钥和第一完整性保护密钥恢复完整性保护和加密。
可以理解,基站接收到UE发送的RRC重建立请求后,可以向UE发送第一MAC CE,使得UE可以基于第一MAC CE中的NCC更新UE使用的密钥,并基于更新后的密钥生成第一加密密钥和第一完整性保护密钥,并基于第一MAC CE中的第一字节流,重建立RRC连接。
本申请实施例提供一种通信方法,由于在UE向基站发送RRC重建立请求消息后,基站可以向UE发送包括NCC和第一字节流的第一MAC CE,第一字节流包括加密后的RRC重建立消息,即基站可以将NCC携带在加密后的RRC重建立消息的外面,因此在UE获取到NCC更新密钥的同时,也提高了RRC重建立消息的安全性。
本申请的一些实施例中,在上述步骤202之后,本申请实施例提供的通信方法还包括下述的步骤203至步骤207。
步骤203、UE的MAC层解析第一MAC CE,得到NCC和第一字节流。
步骤204、UE的MAC层将NCC和第一字节流传递给UE的RRC层。
可以理解,UE的MAC层接收到第一MAC CE后,可以对第一MAC CE进行解析,得到NCC和第一字节流,并通过层间交互将NCC和第一字节流传递给UE的RRC层。
本申请的一些实施例中,若第一MAC CE还携带有第一信息或其他消息完整性鉴权码MAC-I,则UE的MAC层可以一并传递给UE的RRC层。
步骤205、UE的RRC层基于NCC更新UE使用的密钥,并基于更新后的密钥生成第一加密密钥和第一完整性保护密钥。
本申请的一些实施例中,在当前密钥对应的NCC与第一MAC CE里的NCC相同的情况下,UE的RRC层可以基于当前密钥更新UE使用的密钥,否则可以基于第一MAC CE里的NCC对应的NH更新UE使用的密钥。
步骤206、UE的RRC层请求UE的PDCP层基于第一加密密钥和第一完整性保护密钥对第一字节流进行处理。
步骤207、UE的PDCP层基于第一加密密钥和第一完整性保护密钥对第一字节流进行处理。
本申请的一些实施例中,在上述步骤207之后,本申请实施例提供的通信方法还包括下述的步骤301或步骤302。
步骤301、在UE的PDCP层执行完整性保护验证操作失败的情况下,UE进入空闲态。
步骤302、在UE的PDCP层执行完整性保护验证操作通过的情况下,UE的PDCP层将解密后的RRC重建立消息传递给UE的RRC层。
本申请的一些实施例中,在上述步骤302之后,本申请实施例提供的通信方法还包括下述的步骤303和步骤304。
步骤303、UE的RRC层基于解密后的RRC重建立消息重建立RRC连接。
可以理解,UE的RRC层可以对解密后的RRC重建立消息进行处理,并根据RRC重建立消息重建立RRC连接。
本申请的一些实施例中,上述步骤303具体可以通过下述的步骤303a实现。
步骤303a、在第一MAC CE中的NCC与RRC重建立消息中的NCC相同的情况下,UE的RRC层根据解密后的RRC重建立消息重建立RRC连接。
本申请的一些实施例中,在RRC重建立消息包括NCC的情况下,UE的RRC层可以进一步验证第一MAC CE里的NCC与RRC重建立消息里的NCC是否相同,若不同,则验证失败,UE进入空闲态;若相同,则UE的RRC层根据解密后的RRC重建立消息重建立RRC连接。
如此,由于上述RRC重建立消息中包括NCC,因此可以基于该NCC验证第一MAC CE里包括的NCC与RRC重建立消息里包括的NCC是否一致,从而提高安全性。
步骤304、UE向基站发送RRC重建立完成消息。
本申请的实施例中,上述RRC重建立完成消息为UE的PDCP层通过第一加密密钥和第一完整性保护密钥处理后的消息。
可以理解,UE可以向基站发送RRC Reestablishment Complete,即RRC重建立完成消息,该消息被加密和完整性保护并在SRB1上传输。
本申请的一些实施例中,上述第一字节流对应第一PDCP PDU,第一PDCP PDU包括加密后的第一MAC-I,加密后的第一MAC-I为基站的PDCP层通过对RRC重建立消息执行完整性保护操作生成的;上述步骤207具体可以通过下述的步骤207a至步骤207c实现。
步骤207a、UE的PDCP层解析第一PDCP PDU,得到加密后的RRC重建立消息和加密后的第一MAC-I。
步骤207b、UE的PDCP层通过第一加密密钥,对加密后的RRC重建立消息和加密后的第一MAC-I执行解密操作,得到解密后的RRC重建立消息和解密后的第一MAC-I。
步骤207c、UE的PDCP层通过第一完整性保护密钥和解密后的第一MAC-I,对解密后的RRC重建立消息执行完整性保护验证操作。
本申请的一些实施例中,在UE的PDCP层执行完整性保护验证操作失败的情况下,UE可以进入空闲态。
本申请的一些实施例中,在UE的PDCP层执行完整性保护验证操作通过的情况下,UE的PDCP层可以将解密后的RRC重建立消息传递给UE的RRC层,并且UE的RRC层配置UE的PDCP层使用第一加密密钥和第一完整性保护密钥恢复完整性保护和加密。
具体地,UE的PDCP层可以解析第一PDCP PDU,获取到“PDCP SN”、“Data”和“MAC-I”,并使用第一加密密钥对“Data”和“MAC-I”这两个信元进行解密,然后使用第一完整性保护密钥和解密后的“MAC-I”对解密后的“Data”信元进行完整性保护验证,如果验证失败,UE可以进入空闲态,流程结束;如果验证通过,UE的PDCP层可以将解密后的“Data”返回给RRC层。其中,“Data”对应加密后的RRC重建立消息,“MAC-I”对应加密后的第一MAC-I。
本申请的一些实施例中,UE的PDCP层执行解密操作和完整性保护验证操作所使用的参数为第一参数或第一参数集。
本申请的一些实施例中,上述第一参数或第一参数集包括以下至少一项:COUNT值为0,BEARER为无线信令承载SRB1的承载标识,DIRECTION为下行方向。
本申请的一些实施例中,上述下行方向的取值为1。
本申请的一些实施例中,本申请实施例提供的通信方法还可以包括下述的步骤208。
步骤208、UE的PDCP层将SRB1对应的PDCP实体维护的第一变量置为1或增加1。
本申请的实施例中,上述第一变量为对应下一个期望接收的PDCP SDU的COUNT值的变量。
本申请的一些实施例中,上述第一变量可以理解为RX_NEXT变量。
可以理解,UE的SRB1的PDCP实体认为成功收到了COUNT值为0的PDCP SDU。UE的RRC层配置UE的PDCP层使用第一加密密钥和第一完整性保护密钥恢复完整性保护和加密。
本申请的一些实施例中,UE的PDCP层执行解密操作和完整性保护验证操作所使用的参数为第二参数或第二参数集。
本申请的一些实施例中,上述第二参数或第二参数集包括以下至少一项:COUNT值的所有比特为1、BEARER值的所有比特为1、DIRECTION为下行方向。
需要说明的是,UE执行完整性保护验证操作和解密操作使用的参数与基站执行完整性保护操作和加密操作使用的参数相同。
本申请的一些实施例中,上述第一MAC CE包括第一信息,第一信息为通过对RRC重建立消息执行完整性保护操作生成的MAC-I;上述步骤207具体可以通过下述的步骤207d和步骤207e实现。
步骤207d、UE的PDCP层通过第一加密密钥对第一字节流执行解密操作,得到解密后的RRC重建立消息。
步骤207e、UE的PDCP层通过第一完整性保护密钥和第一信息对解密后的RRC重建立消息执行完整性保护验证操作。
本申请的一些实施例中,在UE的PDCP层执行完整性保护验证操作失败的情况下,UE可以进入空闲态。
本申请的一些实施例中,在UE的PDCP层执行完整性保护验证操作通过的情况下,UE的PDCP层可以将解密后的RRC重建立消息传递给UE的RRC层,并配置PDCP层使用第一加密密钥和第一完整性保护密钥恢复完整性保护和加密。
本申请的一些实施例中,上述第一MAC CE包括第二信息,第二信息为通过对NCC和第一字节流执行完整性保护操作生成的MAC-I;上述步骤207具体可以通过下述的步骤207f和步骤207g实现。
步骤207f、UE的PDCP层通过第一完整性保护密钥和第二信息,对NCC和第一字节流执行完整性保护验证操作。
步骤207g、在UE的PDCP层对NCC和第一字节流执行完整性保护验证操作通过的情况下,UE的PDCP层通过第一加密密钥对第一字节流执行解密操作,得到解密后的RRC重建立消息。
本申请的一些实施例中,在UE的PDCP层执行完整性保护验证操作失败的情况下,UE可以进入空闲态。
本申请的一些实施例中,在UE的PDCP层执行完整性保护验证操作通过的情况下,UE的PDCP层可以将解密后的RRC重建立消息传递给UE的RRC层,并配置PDCP层使用第一加密密钥和第一完整性保护密钥恢复完整性保护和加密。
需要说明的是,本申请实施例中UE的PDCP层执行解密操作和完整性保护验证操作所使用的参数为以下任一项:第一参数、第一参数集、第二参数、第二参数集,本申请实施例不再赘述。并且,UE执行完整性保护验证操作和解密操作使用的参数与基站执行完整性保护操作和加密操作使用的参数相同。
本申请实施例提供一种通信方法,图3示出了本申请实施例提供的一种通信方法的流程图。如图3所示,本申请实施例提供的通信方法可以包括下述的步骤401和步骤402。
步骤401、基站接收来自UE的RRC重建立请求消息。
步骤402、基站的MAC层向UE发送第一MAC CE。
本申请的实施例中,上述第一MAC CE包括NCC和第一字节流,第一字节流包括加密后的RRC重建立消息,RRC重建立消息用于指示UE重建立RRC连接。
本申请的一些实施例中,上述第一MAC CE用于向UE发送NCC和加密后的RRC重建立消息。
可以理解,基站接收到UE发送的RRC重建立请求后,可以向UE发送第一MAC CE,使得UE可以基于第一MAC CE中的NCC更新UE使用的密钥,并基于更新后的密钥生成第一加密密钥和第一完整性保护密钥,并基于第一MAC CE中的第一字节流,重建立RRC连接。
本申请的一些实施例中,上述第一MAC CE对应一个专用的逻辑信道标识(Logical Channel Identification,LCID),也就是说,将一个LCID分配给第一MAC CE。使得UE在接收到包含第一MAC CE的MAC PDU后,通过MAC PDU里的MAC subheader里的该LCID能获知是第一MAC CE。
本申请实施例提供一种通信方法,由于基站接收UE发送的RRC重建立请求消息后,可以向UE发送包括NCC和第一字节流的第一MAC CE,第一字节流包括加密后的RRC重建立消息,即基站可以将NCC单独发送给UE,并不携带在RRC重建立消息中,因此在UE获取到NCC更新密钥的同时,也提高了RRC重建立消息的安全性。
本申请的一些实施例中,在上述步骤401之后,本申请实施例提供的通信方法还包括下述的步骤403至步骤405。
步骤403、基站的RRC层更新基站使用的密钥,并基于更新后的密钥生成第一加密密钥和第一完整性保护密钥。
本申请的一些实施例中,基站的RRC层接收到RRC重建立请求消息后,可以获取UE的UE上下文中保存的NCC,并基于NCC更新基站使用的密钥。
步骤404、基站的RRC层指示基站的PDCP层使用第一加密密钥和第一完整性保护密钥恢复完整性保护和加密。
步骤405、基站的RRC层生成RRC重建立消息,并请求基站的PDCP层对RRC重建立消息执行安全保护。
可以理解,在基站的PDCP层使用第一加密密钥和第一完整性保护密钥恢复完整性保护和加密后,基站的RRC层可以生成RRC重建立消息,并请求基站的PDCP层对RRC重建立消息执行安全保护。
本申请的一些实施例中,在上述步骤405之后,本申请实施例提供的通信方法还包括下述的步骤406至步骤408。
步骤406、基站的PDCP层对RRC重建立消息执行安全保护,生成第一字节流,并向基站的RRC层传递第一字节流。
本申请的实施例中,上述第一字节流包括被安全保护后的RRC重建立消息,安全保护包括以下至少一项:加密操作、完整性保护操作。
步骤407、基站的RRC层将第一字节流和UE的UE上下文中保存的NCC传递给基站的MAC层。
步骤408、基站的MAC层基于NCC和第一字节流生成第一MAC CE。
本申请的一些实施例中,上述第一MAC CE用于指示UE重建立RRC连接,或者说用于向UE发送NCC和被安全保护后的RRC重建立消息。
可以理解,在基站的MAC层基于NCC和第一字节流生成第一MAC CE后,基站的MAC层可以向UE发送包括NCC和第一字节流的第一MAC CE。
示例性地,如图4所示,为本申请实施例提供的一种第一MAC CE的结构示意图,第一MAC CE中包括R、NCC和第一字节流,其中,R为保留bits。
本申请的一些实施例中,上述步骤406中的“基站的PDCP层对RRC重建立消息执行安全保护,生成第一字节流”具体可以通过下述的步骤406a和步骤406b实现。
步骤406a、基站的PDCP层通过第一完整性保护密钥对RRC重建立消息执行完整性保护操作,生成第一MAC-I。
步骤406b、基站的PDCP层通过第一加密密钥对RRC重建立消息和第一MAC-I执行加密操作,生成第一PDCP PDU。
本申请的实施例中,上述第一PDCP PDU对应第一字节流,第一PDCP PDU包括加密后的RRC重建立消息和第一MAC-I。
本申请的一些实施例中,上述第一PDCP PDU可以理解为第一字节流,即第一PDCP PDU就是第一字节流。
可以理解,在该实施例中,基站的PDCP层对RRC重建立消息执行安全保护,该安全保护包括加密操作和完整性保护操作。
示例性地,如图5所示,为本申请实施例提供的一种第一PDCP PDU的结构示意图,上述第一PDCP PDU的“PDCP SN”信元为0,“Data”信元对应加密后的RRC重建立消息,“MAC-I”信元对应加密后的第一MAC-I。
如此,由于基站的PDCP层生成第一MAC-I后,还通过第一加密密钥对第一MAC-I执行了加密操作,从而提高了安全性。
本申请的一些实施例中,基站的PDCP层执行加密操作和执行完整性保护操作所使用的参数为第一参数或第一参数集。
本申请的一些实施例中,上述第一参数或第一参数集包括以下至少一项:COUNT值为0,BEARER为无线信令承载SRB1的承载标识,DIRECTION为下行方向。
本申请的一些实施例中,上述下行方向的取值为1。
本申请的一些实施例中,本申请实施例提供的通信方法还可以包括下述的步骤409。
步骤409、基站的PDCP层将SRB1对应的PDCP实体维护的第二变量置为1或增加1。
本申请的实施例中,上述第二变量为对应下一个将发送的PDCP SDU的COUNT值的变量。
本申请的一些实施例中,上述第二变量可以理解为TX_NEXT变量。
可以理解,SRB1的PDCP实体为RRC重建立消息分配一个COUNT值(即0值),并进行安全保护处理,处理后不递交给RLC层,而是返回给RRC层,并且,TX_NEXT变量被置为1或增加1,从而避免了后续在SRB1发送的RRC消息使用相同的安全保护参数而导致的安全性降低的问题。
本申请的一些实施例中,上述基站的PDCP层执行加密操作和执行完整性保护操作所使用的参数为第二参数或第二参数集。
本申请的一些实施例中,上述第二参数或第二参数集包括以下至少一项:COUNT值的所有比特为1、BEARER值的所有比特为1、DIRECTION为下行方向。
本申请的一些实施例中,上述步骤406具体可以通过下述的步骤406c至步骤406e实现。
步骤406c、基站的PDCP层通过第一加密密钥对RRC重建立消息执行加密操作,生成第一字节流。
可以理解,上述第一字节流中包括加密后的RRC重建立消息。
步骤406d、基站的PDCP层通过第一完整性保护密钥对RRC重建立消息执行完整性保护操作,生成第一信息。
本申请的实施例中,上述第一信息为通过对RRC重建立消息执行完整性保护操作生成的MAC-I。
可以理解,在该实施例中,基站的PDCP层对RRC重建立消息执行安全保护,该安全保护包括加密操作和完整性保护操作。
本申请的一些实施例中,基站的PDCP层使用第一参数或第一参数集对RRC重建立消息执行完整性保护操作时生成的MAC-I与基站的PDCP层使用第二参数或第二参数集对RRC重建立消息执行完整性保护操作时生成的MAC-I不同。
步骤406e、基站的PDCP层向基站的RRC层传递第一字节流和第一信息。
本申请的实施例中,上述基站的MAC层生成的第一MAC CE中包括第一字节流、NCC和第一信息,第一信息为基站的RRC层传递给基站的MAC层的。
可以理解,在基站的RRC层请求基站的PDCP层对RRC重建立消息执行安全保护、且基站的PDCP层对RRC重建立消息执行加密操作和完整性保护操作,生成第一字节流和第一信息后,基站的PDCP层可以向基站的RRC层返回第一字节流和第一信息,然后基站的RRC层可以将第一字节流、NCC和第一信息传递给基站的MAC层,使得基站的MAC层可以基于NCC、第一字节流和第一信息生成第一MAC CE。
本申请的一些实施例中,基站的RRC层请求基站的PDCP层对RRC重建立消息执行安全保护的情况下,基站的PDCP层可以只对RRC重建立消息执行加密操作。
本申请的一些实施例中,基站的PDCP层可以只向基站的RRC层传递第一字节流。
本申请的一些实施例中,在上述步骤407之前,本申请实施例提供的通信方法还包括下述的步骤407a和步骤407b。
步骤407a、基站的RRC层请求基站的PDCP层对NCC和第一字节流执行完整性保护操作。
本申请的一些实施例中,在基站的RRC层请求基站的PDCP层对RRC重建立消息执行安全保护、且基站的RRC层只接收到基站的PDCP层返回的第一字节流时,即基站的PDCP层未对RRC重建立消息执行完整性保护操作时,基站的RRC层可以请求基站的PDCP层对NCC和第一字节流执行完整性保护操作。
本申请的一些实施例中,基站的RRC层可以向基站的PDCP层传递NCC和第一字节流。
步骤407b、基站的PDCP层通过第一完整性保护密钥对NCC和第一字节流执行完整性保护操作,生成第二MAC-I,并将第二MAC-I传递给基站的RRC层。
本申请的实施例中,上述基站的MAC层生成的第一MAC CE中包括第一字节流、NCC和第二MAC-I,该第二MAC-I为基站的RRC层传递给基站的MAC层的。
可以理解,基站的RRC层接收到基站的PDCP层返回的第二MAC-I时,可以将第一字节流、NCC和第二MAC-I传递给基站的MAC层,使得基站的MAC层可以基于NCC、第一字节流和第二MAC-I生成第一MAC CE。
本申请的一些实施例中,上述第二MAC-I可以为第二信息。
本申请的一些实施例中,基站的PDCP层通过第一完整性保护密钥对NCC和第一字节流执行完整性保护时所使用的参数与通过第一加密密钥对RRC重建立消息执行加密操作时使用的参数相同。
如此,由于在基站的PDCP层未对RRC重建立消息执行完整性保护操作时,基站的RRC层可以请求基站的PDCP层对NCC和第一字节流执行完整性保护操作,生成第二MAC-I,然后可以将第一字节流、NCC和第二MAC-I传递给基站的MAC层,使得基站的MAC层生成第一MAC CE,因此提高了基站生成第一MAC CE的灵活性和可靠性。
本申请的一些实施例中,在上述步骤408之前,本申请实施例提供的通信方法还包括下述的步骤408a和步骤408b。
步骤408a、基站的MAC层请求基站的PDCP层对NCC和第一字节流执行完整性保护操作。
本申请的一些实施例中,在基站的MAC层只接收到基站的RRC层传递的第一字节流和NCC时,即基站的PDCP层未对RRC重建立消息执行完整性保护操作时,基站的MAC层可以请求基站的PDCP层对第一字节流和NCC执行完整性保护操作。
本申请的一些实施例中,基站的MAC层可以向基站的PDCP层传递NCC和第一字节流。
步骤408b、基站的PDCP层通过第一完整性保护密钥对NCC和第一字节流执行完整性保护,生成第三MAC-I,并将第三MAC-I传递给基站的MAC层。
本申请的实施例中,上述基站的MAC层生成的第一MAC CE中包括第一字节流、NCC和第三MAC-I。
可以理解,基站的MAC层接收到基站的PDCP层返回的第三MAC-I时,基站的MAC层可以基于NCC、第一字节流和第三MAC-I生成第一MAC CE。
本申请的一些实施例中,上述第三MAC-I可以为第二信息。
本申请的一些实施例中,基站的PDCP层通过第一完整性保护密钥对NCC和第一字节流执行完整性保护时所使用的参数与通过第一加密密钥对RRC重建立消息执行加密操作时使用的参数相同。
如此,由于在基站的PDCP层未对RRC重建立消息执行完整性保护操作时,基站的MAC层可以请求基站的PDCP层对NCC和第一字节流执行完整性保护操作,生成第三MAC-I,然后基站的MAC层可以基于NCC、第一字节流和基站的PDCP层返回的第三MAC-I生成第一MAC CE,因此提高了基站生成第一MAC CE的灵活性和可靠性。并且,除了第一字节流外,NCC也被进行了完整性保护,从而提高了安全性。
需要说明的是,本申请实施例中基站的PDCP层执行加密操作和执行完整性保护操作所使用的参数为以下任一项:第一参数、第一参数集、第二参数、第二参数集。
示例性地,如图6所示,为本申请实施例提供的一种第一MAC CE的结构示意图,第一MAC CE中包括R、NCC、第一字节流和MAC-I,其中,R为保留bits。
本申请的一些实施例中,RRC重建立消息不再像常规的RRC消息通过SRB1传输,而是基站的RRC层通过与PDCP层之间的层间交互对该消息进行安全保护,然后将经过安全保护后的RRC重建立消息通过与MAC层之间的层间交互被递交给MAC层,并被携带在MAC CE里作为字节流发送给UE,该MAC CE也携带用于更新密钥的NCC。对应的,UE先基于MAC CE里的NCC更新UE使用的密钥,再基于更新的密钥对RRC重建立消息进行安全相关的处理。
在本申请的一些实施例中,如图7所示,本申请实施例提供的通信方法可以包括下述的步骤A1至步骤A14。
A1、UE处于连接态,RRC层连接需要重建立。
A2、UE向基站发送RRC重建立请求消息。
A3、基站接收来自UE的RRC重建立请求消息。
A4、基站的RRC层更新基站使用的密钥,并基于更新后的密钥生成第一加密密钥和第一完整性保护密钥,并指示基站的PDCP层使用第一加密密钥和第一完整性保护密钥恢复完整性保护和加密。
A5、基站的RRC层生成RRC重建立消息,并请求基站的PDCP层对RRC重建立消息执行安全保护。
A6、基站的PDCP层RRC重建立消息执行安全保护,生成第一字节流,并向基站的RRC层传递第一字节流。
A7、基站的RRC层将第一字节流和UE的UE上下文中保存的NCC传递给基站的MAC层。
A8、基站的MAC层基于NCC和第一字节流生成第一MAC CE。
A9、基站的MAC层向UE发送第一MAC CE。
A10、UE的MAC层解析第一MAC CE,得到NCC和第一字节流,并将NCC和第一字节流传递给UE的RRC层。
A11、UE的RRC层基于NCC更新UE使用的密钥,并基于更新后的密钥生成第一加密密钥和第一完整性保护密钥,以及请求UE的PDCP层基于第一加密密钥和第一完整性保护密钥对第一字节流进行处理。
A12、UE的PDCP层基于第一加密密钥和第一完整性保护密钥对第一字节流进行处理,得到解密后的RRC重建立消息,并将解密后的RRC重建立消息传递给UE的RRC层。
A13、UE的RRC层基于解密后的RRC重建立消息重建立RRC连接。
A14、UE向基站发送RRC重建立完成消息。
需要说明的是,针对上述步骤A1至步骤A14中的相关说明,可以参见上述实施例中的描述,此处不再赘述。
上述各个方法实施例,或者各个方法实施例中的各种可能的实现方式均可以单独执行,也可以任意两个或两个以上相互结合执行,具体可以根据实际使用需求确定,本申请实施例对此不做限制。
本申请实施例提供的通信方法,执行主体可以为通信装置。本申请实施例中以通信装置执行通信方法为例,说明本申请实施例提供的通信装置。
图8示出了本申请实施例中涉及的通信装置的一种可能的结构示意图,应用于UE。如图8所示,通信装置40可以包括:发送模块41和接收模块42。
其中,发送模块41,用于向基站发送RRC重建立请求消息。
接收模块42,用于接收来自基站的第一MAC CE;其中,第一MAC CE包括NCC和第一字节流,第一字节流包括加密后的RRC重建立消息,RRC重建立消息用于指示UE重建立RRC连接。
本申请实施例提供一种通信装置,由于在UE向基站发送RRC重建立请求消息后,基站可以向UE发送包括NCC和第一字节流的第一MAC CE,第一字节流包括加密后的RRC重建立消息,即基站可以将NCC携带在加密后的RRC重建立消息的外面,因此在UE获取到NCC更新密钥的同时,也提高了RRC重建立消息的安全性。
在一种可能的实现方式中,本申请实施例提供的通信装置还包括:解析模块、传递模块、处理模块和请求模块。解析模块,用于在接收模块42接收来自基站的第一MAC CE之后,解析第一MAC CE,得到NCC和第一字节流,传递模块,用于将解析模块解析得到的NCC和第一字节流传递给UE的RRC层。处理模块,用于基于传递模块传递的NCC更新UE使用的密钥,并基于更新后的密钥生成第一加密密钥和第一完整性保护密钥。请求模块,用于请求UE的PDCP层基于第一加密密钥和第一完整性保护密钥对第一字节流进行处理。处理模块,还用于基于第一加密密钥和第一完整性保护密钥对第一字节流进行处理。
在一种可能的实现方式中,第一字节流对应第一PDCP PDU,第一PDCP PDU包括加密后的第一MAC-I,加密后的第一MAC-I为基站的PDCP层通过对RRC重建立消息执行完整性保护操作生成的;处理模块,具体用于解析第一PDCP PDU,得到加密后的RRC重建立消息和加密后的第一MAC-I;并通过第一加密密钥,对加密后的RRC重建立消息和加密后的第一MAC-I执行解密操作,得到解密后的RRC重建立消息和解密后的第一MAC-I;以及通过第一完整性保护密钥和解密后的第一MAC-I,对解密后的RRC重建立消息执行完整性保护验证操作。
在一种可能的实现方式中,第一MAC CE包括第一信息,第一信息为通过对RRC重建立消息执行完整性保护操作生成的MAC-I;处理模块,具体用于通过第一加密密钥对第一字节流执行解密操作,得到解密后的RRC重建立消息;并通过第一完整性保护密钥和第一信息对解密后的RRC重建立消息执行完整性保护验证操作。
在一种可能的实现方式中,第一MAC CE包括第二信息,第二信息为通过对NCC和第一字节流执行完整性保护操作生成的MAC-I;处理模块,具体用于通过第一完整性保护密钥和第二信息,对NCC和第一字节流执行完整性保护验证操作;并在UE的PDCP层对NCC和第一字节流执行完整性保护验证操作通过的情况下,通过第一加密密钥对第一字节流执行解密操作,得到解密后的RRC重建立消息。
在一种可能的实现方式中,UE的PDCP层执行解密操作和完整性保护验证操作所使用的参数为第一参数或第一参数集;其中,第一参数或第一参数集包括以下至少一项:COUNT值为0,BEARER为无线信令承载SRB1的承载标识,DIRECTION为下行方向。
在一种可能的实现方式中,处理模块,还用于将SRB1对应的PDCP实体维护的第一变量置为1或增加1,第一变量为对应下一个期望接收的PDCP业务数据单元SDU的COUNT值的变量。
在一种可能的实现方式中,UE的PDCP层执行解密操作和完整性保护验证操作所使用的参数为第二参数或第二参数集;其中,第二参数或第二参数集包括以下至少一项:COUNT值的所有比特为1、BEARER值的所有比特为1、DIRECTION为下行方向。
在一种可能的实现方式中,处理模块,还用于在基于第一加密密钥和第一完整性保护密钥对第一字节流进行处理之后,在UE的PDCP层执行完整性保护验证操作失败的情况下,进入空闲态;传递模块,还用于在处理模块基于第一加密密钥和第一完整性保护密钥对第一字节流进行处理之后,在UE的PDCP层执行完整性保护验证操作通过的情况下,将解密后的RRC重建立消息传递给UE的RRC层。
在一种可能的实现方式中,处理模块,还用于在传递模块将解密后的RRC重建立消息传递给UE的RRC层之后,基于解密后的RRC重建立消息重建立RRC连接;发送模块41,还用于向基站发送RRC重建立完成消息,RRC重建立完成消息为UE的PDCP层通过第一加密密钥和第一完整性保护密钥处理后的消息。
在一种可能的实现方式中,处理模块,具体用于在第一MAC CE中的NCC与RRC重建立消息中的NCC相同的情况下,根据解密后的RRC重建立消息重建立RRC连接。
本申请实施例提供的通信装置能够实现上述方法实施例中UE实现的各个过程,并达到相同的技术效果,为避免重复,这里不再赘述。
图9示出了本申请实施例中涉及的通信装置的另一种可能的结构示意图,应用于基站。如图9所示,通信装置50可以包括:接收模块51和发送模块52。
其中,接收模块51,用于接收来自UE的RRC重建立请求消息。
发送模块52,用于向UE发送第一MAC CE;其中,第一MAC CE包括NCC和第一字节流,第一字节流包括加密后的RRC重建立消息,RRC重建立消息用于指示UE重建立RRC连接。
本申请实施例提供一种通信装置,由于基站接收UE发送的RRC重建立请求消息后,可以向UE发送包括NCC和第一字节流的第一MAC CE,第一字节流包括加密后的RRC重建立消息,即基站可以将NCC单独发送给UE,并不携带在RRC重建立消息中,因此在UE获取到NCC更新密钥的同时,也提高了RRC重建立消息的安全性。
在一种可能的实现方式中,本申请实施例提供的通信装置还包括:处理模块和指示模块。处理模块,用于在接收模块51接收来自UE的RRC重建立请求消息之后,更新基站使用的密钥,并基于更新后的密钥生成第一加密密钥和第一完整性保护密钥。指示模块,用于指示基站的PDCP层使用处理模块生成的第一加密密钥和第一完整性保护密钥恢复完整性保护和加密。处理模块,还用于生成RRC重建立消息,并请求基站的PDCP层对RRC重建立消息执行安全保护。
在一种可能的实现方式中,本申请实施例提供的通信装置还包括:传递模块和生成模块。处理模块,还用于在生成RRC重建立消息,并请求基站的PDCP层对RRC重建立消息执行安全保护之后,对RRC重建立消息执行安全保护,生成第一字节流,并向基站的RRC层传递第一字节流,第一字节流包括被安全保护后的RRC重建立消息,安全保护包括以下至少一项:加密操作、完整性保护操作。传递模块,用于将第一字节流和UE的UE上下文中保存的NCC传递给基站的MAC层。生成模块,用于基于NCC和第一字节流生成第一MAC CE。
在一种可能的实现方式中,生成模块,具体用于通过第一完整性保护密钥对RRC重建立消息执行完整性保护操作,生成第一MAC-I;并通过第一加密密钥对RRC重建立消息和第一MAC-I执行加密操作,生成第一PDCP PDU,第一PDCP PDU对应第一字节流,第一PDCP PDU包括加密后的RRC重建立消息和第一MAC-I。
在一种可能的实现方式中,处理模块,具体用于通过第一加密密钥对RRC重建立消息执行加密操作,生成第一字节流;并通过第一完整性保护密钥对RRC重建立消息执行完整性保护操作,生成第一信息,第一信息为通过对RRC重建立消息执行完整性保护操作生成的MAC-I;以及向基站的RRC层传递第一字节流和第一信息;其中,基站的MAC层生成的第一MAC CE中包括第一字节流、NCC和第一信息,第一信息为基站的RRC层传递给基站的MAC层的。
在一种可能的实现方式中,本申请实施例提供的通信装置还包括:请求模块。请求模块,用于在传递模块将第一字节流和UE的UE上下文中保存的NCC传递给基站的MAC层之前,请求基站的PDCP层对NCC和第一字节流执行完整性保护操作。处理模块,还用于通过第一完整性保护密钥对NCC和第一字节流执行完整性保护操作,生成第二MAC-I,并将第二MAC-I传递给基站的RRC层;其中,基站的MAC层生成的第一MAC CE中包括第一字节流、NCC和第二MAC-I,第二MAC-I为基站的RRC层传递给基站的MAC层的。
在一种可能的实现方式中,本申请实施例提供的通信装置还包括:请求模块。请求模块,用于在生成模块基于NCC和第一字节流生成第一MAC CE之前,请求基站的PDCP层对NCC和第一字节流执行完整性保护操作。处理模块,用于通过第一完整性保护密钥对NCC和第一字节流执行完整性保护,生成第三MAC-I,并将第三MAC-I传递给基站的MAC层;其中,基站的MAC层生成的第一MAC CE中包括第一字节流、NCC和第三MAC-I。
在一种可能的实现方式中,基站的PDCP层执行加密操作和执行完整性保护操作所使用的参数为第一参数或第一参数集;其中,第一参数或第一参数集包括以下至少一项:COUNT值为0,BEARER为无线信令承载SRB1的承载标识,DIRECTION为下行方向。
在一种可能的实现方式中,处理模块,还用于将SRB1对应的PDCP实体维护的第二变量置为1或增加1,第二变量为对应下一个将发送的PDCP业务数据单元SDU的COUNT值的变量。
在一种可能的实现方式中,基站的PDCP层执行加密操作和执行完整性保护操作所使用的参数为第二参数或第二参数集;
其中,第二参数或第二参数集包括以下至少一项:COUNT值的所有比特为1、BEARER值的所有比特为1、DIRECTION为下行方向。
本申请实施例提供的通信装置能够实现上述方法实施例中基站实现的各个过程,并达到相同的技术效果,为避免重复,这里不再赘述。
本申请实施例提供一种通信方法,图10示出了本申请实施例提供的一种通信方法的流程图。如图10所示,本申请实施例提供的通信方法可以包括下述的步骤501至步骤505。
步骤501、UE向基站发送RRC重建立请求消息。
本申请的一些实施例中,在UE处于RRC连接态,但是RRC连接需要重建立,例如:处于连接态的UE发生了无线链路失败,或完整性检查失败等情况下,UE可以执行小区选择过程以选择一个目标小区发起RRC重建立过程,通过SRB0向目标小区所在的基站发送RRC重建立请求消息。
步骤502、UE接收来自基站的第一信令。
本申请的实施例中,上述第一信令用于请求UE更新UE使用的密钥,第一信令包括NCC,第一信令为第二MAC CE或PDCP控制PDU。
步骤503、UE的RRC层基于NCC更新UE使用的密钥,并基于更新后的密钥生成第一加密密钥和第一完整性保护密钥。
本申请的一些实施例中,UE的RRC接收到第一信令后,可以解析该第一信令,得到上述NCC。
本申请的一些实施例中,在当前密钥对应的NCC与第二MAC CE里的NCC相同的情况下,UE的RRC层可以基于当前密钥更新UE使用的密钥,否则可以基于第二MAC CE里的NCC对应的NH更新UE使用的密钥。
本申请的一些实施例中,在当前密钥对应的NCC与PDCP控制PDU里的NCC相同的情况下,UE的RRC层可以基于当前密钥更新UE使用的密钥,否则可以基于PDCP控制PDU里的NCC对应的NH更新UE使用的密钥。
步骤504、UE的RRC层指示UE的PDCP层使用第一加密密钥和第一完整性保护密钥恢复完整性保护和加密。
步骤505、在UE的PDCP层使用第一加密密钥和第一完整性保护密钥恢复完整性保护和加密之后,UE的PDCP层处理来自基站的第二PDCP PDU。
需要说明的是,在UE的PDCP层使用第一加密密钥和第一完整性保护密钥恢复完整性保护和加密之前,若UE的SRB1对应的PDCP实体接收到了PDCP PDU,例如:由于第一信令的重传导致第二PDCP PDU先被接收到,则UE的SRB1对应的PDCP实体先不对第二PDCP PDU进行处理,直到等待第一信令被收到,UE的PDCP层使用第一加密密钥和第一完整性保护密钥恢复完整性保护和加密之后,UE的PDCP层才能处理第二PDCP PDU。
本申请的实施例中,上述第二PDCP PDU中包括被完整性保护和加密的RRC重建立消息,RRC重建立消息用于指示UE重建立RRC连接。
可以理解,UE的PDCP层在使用第一加密密钥和第一完整性保护密钥恢复完整性保护和加密之后,再处理来自基站的第二PDCP PDU。
本申请实施例提供一种通信方法,由于UE向基站发送RRC重建立请求消息后,可以接收来自基站的用于请求UE更新UE使用的密钥的第一信令,第一信令包括NCC,因此UE的RRC层可以基于第一信令中包括的NCC,更新UE使用的密钥,并基于更新后的密钥生成第一加密密钥和第一完整性保护密钥,以及指示UE的PDCP层使用第一加密密钥和第一完整性保护密钥恢复完整性保护和加密,然后,UE的PDCP层在使用第一加密密钥和第一完整性保护密钥恢复完整性保护和加密之后,可以处理来自基站的第二PDCP PDU,该第二PDCP PDU中包括被完整性保护和加密的RRC重建立消息,该RRC重建立消息用于指示UE重建立RRC连接,也就是说,UE的PDCP层是先恢复完整性保护和加密的,然后再处理来自基站的第二PDCP PDU,因此RRC重建立消息可以被完整性保护和加密,从而提高了RRC重建立消息的安全性。
本申请的一些实施例中,在上述第一信令为第二MAC CE的情况下,上述步骤502具体可以通过下述的步骤502a和步骤502b实现。
步骤502a、UE的MAC层接收来自基站的第二MAC CE。
步骤502b、UE的MAC层解析第二MAC CE,得到NCC,并将NCC递交给UE的RRC层。
可以理解,UE的MAC层接收到第二MAC CE后,可以解析第二MAC CE,得到上述NCC,并通过层间交互将NCC递交给UE的RRC层。
本申请的一些实施例中,若第二MAC CE还携带有其他MAC-I,则UE的MAC层可以一并传递给UE的RRC层。
本申请的一些实施例中,在第一信令为PDCP控制PDU的情况下,上述步骤502具体可以通过下述的步骤502c和步骤502d实现。
步骤502c、UE的PDCP层接收来自基站的PDCP控制PDU。
步骤502d、UE的PDCP层解析PDCP控制PDU,得到NCC,并将NCC递交给UE的RRC层。
可以理解,UE的PDCP层接收到PDCP控制PDU后,可以解析PDCP控制PDU,得到上述NCC,并通过层间交互将NCC递交给UE的RRC层。
本申请的一些实施例中,UE的PDCP层具体可以为SRB1对应的PDCP实体。
本申请的一些实施例中,若PDCP控制PDU还携带有其他MAC-I,则UE的PDCP层可以一并传递给UE的RRC层。
本申请的一些实施例中,上述第一信令包括第三信息,第三信息为对NCC执行完整性保护操作生成的MAC-I;上述步骤504具体可以通过下述的步骤504a至步骤504c实现。
步骤504a、UE的RRC层请求UE的PDCP层使用第一完整性保护密钥和第三信息对NCC执行完整性保护验证操作。
步骤504b、UE的PDCP层通过第一完整性保护密钥和第三信息对NCC执行完整性保护验证操作。
步骤504c、在UE的PDCP层对NCC执行完整性保护验证操作通过的情况下,UE的RRC层指示UE的PDCP层使用第一加密密钥和第一完整性保护密钥恢复完整性保护和加密。
本申请的一些实施例中,在上述第一信令为第二MAC CE的情况下,UE的RRC层可以请求UE的PDCP层使用第一完整性保护密钥和第二MAC CE里包括的MAC-I对NCC执行完整性保护验证操作。
本申请的一些实施例中,在上述第一信令为PDCP控制PDU的情况下,UE的RRC层可以请求UE的PDCP层使用第一完整性保护密钥和PDCP控制PDU里包括的MAC-I对NCC执行完整性保护验证操作。
本申请的一些实施例中,上述UE的PDCP层对NCC执行完整性保护验证操作所使用的参数为第二参数或第二参数集。
本申请的一些实施例中,上述第二参数或第二参数集包括以下至少一项:COUNT值的所有比特为1、BEARER值的所有比特为1、DIRECTION为下行方向。
本申请的一些实施例中,本申请实施例提供的通信方法还可以包括下述的步骤506。
步骤506、在UE的PDCP层对NCC执行完整性保护验证操作失败的情况下,UE进入空闲态。
本申请的一些实施例中,在UE的PDCP层对NCC执行完整性保护验证操作通过的情况下,可以配置UE的PDCP层使用第一加密密钥和第一完整性保护密钥恢复完整性保护和加密。
本申请的一些实施例中,上述步骤505中的“UE的PDCP层处理来自基站的第二PDCP PDU”具体可以通过下述的步骤505a实现。
步骤505a、UE的PDCP层使用第一加密密钥和第一完整性保护密钥对第二PDCP PDU执行解密操作和完整性保护验证操作,并将解密后的RRC重建立消息递交给UE的RRC层。
可以理解,由于UE的PDCP层使用第一加密密钥和第一完整性保护密钥恢复了完整性保护和加密,因此UE的PDCP层可以对接收到的PDCP PDU执行解密操作和完整性保护验证操作,得到解密后的RRC重建立消息,并将解密后的RRC重建立消息递交给UE的RRC层。
本申请的一些实施例中,本申请实施例提供的通信方法还可以包括下述的步骤601和步骤602。
步骤601、UE的RRC层基于解密后的RRC重建立消息重建立RRC连接。
可以理解,UE的RRC层可以对解密后的RRC重建立消息进行处理,并根据RRC重建立消息重建立RRC连接。
步骤602、UE向基站发送RRC重建立完成消息。
本申请的实施例中,上述RRC重建立完成消息为UE的PDCP层通过第一加密密钥和第一完整性保护密钥处理后的消息。
可以理解,UE可以向基站发送RRC重建立完成消息,该消息被加密和完整性保护并在SRB1上传输。
本申请实施例提供一种通信方法,图11示出了本申请实施例提供的一种通信方法的流程图。如图11所示,本申请实施例提供的通信方法可以包括下述的步骤701至步骤703。
步骤701、基站接收来自UE的RRC重建立请求消息。
步骤702、基站向UE发送第一信令。
本申请的实施例中,上述第一信令用于请求UE更新UE使用的密钥,第一信令包括NCC,第一信令为第二MAC CE或PDCP控制PDU。
步骤703、基站向UE发送第二PDCP PDU。
本申请的实施例中,上述第二PDCP PDU中包括被完整性保护和加密的RRC重建立消息,RRC重建立消息用于指示UE重建立RRC连接。
本申请实施例提供一种通信方法,由于基站接收到UE发送的RRC重建立请求消息后,可以向UE发送用于请求UE更新UE使用的密钥的第一信令,第一信令包括NCC,以及向UE发送指示UE重建立RRC连接的第二PDCP PDU,第二PDCP PDU中包括被完整性保护和加密的RRC重建立消息,即NCC和RRC重建立消息是分开的,因此提高了RRC重建立消息的安全性。
本申请的一些实施例中,在上述步骤703之前,本申请实施例提供的通信方法还包括下述的步骤704和步骤705。
步骤704、基站的RRC层更新基站使用的密钥,并基于更新后的密钥生成第一加密密钥和第一完整性保护密钥。
本申请的一些实施例中,基站的RRC层接收到UE发送的RRC重建立请求消息后,可以获取UE的UE上下文里保存的NCC,然后基于NCC更新基站使用的密钥。
步骤705、基站的RRC层指示基站的PDCP层使用第一加密密钥和第一完整性保护密钥恢复完整性保护和加密。
需要说明的是,基站的RRC层可以在生成第一加密密钥和第一完整性保护密钥时,指示基站的PDCP层使用第一加密密钥和第一完整性保护密钥恢复完整性保护和加密,或者,基站的RRC层可以在基站的PDCP层生成PDCP控制PDU之前,指示基站的PDCP层使用第一加密密钥和第一完整性保护密钥恢复完整性保护和加密,或者,基站的RRC层可以在基站向UE发送PDCP控制PDU之前,指示基站的PDCP层使用第一加密密钥和第一完整性保护密钥恢复完整性保护和加密,本申请实施例对此不作限制。
本申请的一些实施例中,上述步骤702具体可以通过下述的步骤702a至步骤702c实现。
步骤702a、基站的RRC层将UE的UE上下文里保存的NCC传递给基站的MAC层。
本申请的一些实施例中,基站的RRC层可以通过层间交互将NCC递交给UE的MAC层。
步骤702b、基站的MAC层基于NCC生成第二MAC CE。
本申请的实施例中,上述第二MAC CE用于请求UE更新UE使用的密钥,第二MAC CE包括NCC。
本申请的一些实施例中,上述第二MAC CE用于向UE发送NCC。
步骤702c、基站向UE发送第二MAC CE。
本申请的一些实施例中,上述第二MAC CE对应一个专用的LCID,也就是说,将一个LCID分配给第二MAC CE。使得UE在接收到包含第二MAC CE的MAC PDU后,通过MAC PDU里的MAC subheader里的该LCID能获知是第二MAC CE。如此,无需占用至少两个bits指示发送的是什么消息,从而节省了信令开销。
本申请的一些实施例中,上述步骤702a具体可以通过下述的步骤702a1至步骤702a3实现。
步骤702a1、基站的RRC层请求基站的PDCP层通过第一完整性保护密钥对NCC执行完整性保护操作。
步骤702a2、基站的PDCP层通过第一完整性保护密钥对NCC执行完整性保护操作,生成第四MAC-I,并传递给基站的RRC层。
本申请的一些实施例中,上述第四MAC-I可以为第三信息。
步骤702a3、基站的RRC层将NCC和第四MAC-I传递给基站的MAC层。
本申请的一些实施例中,上述第二MAC CE包括NCC和第四MAC-I。
可以理解,基站的MAC层可以基于NCC和第四MAC-I,生成第二MAC CE。
本申请的一些实施例中,上述基站的PDCP层对NCC执行完整性保护操作所使用的参数为第二参数或第二参数集。
本申请的一些实施例中,上述第二参数或第二参数集包括以下至少一项:COUNT值的所有比特为1、BEARER值的所有比特为1、DIRECTION为下行方向。
如此,由于NCC被进行了完整性保护,从而提高了安全性。
本申请的一些实施例中,上述步骤702b具体可以通过下述的步骤702b1至步骤702b3实现。
步骤702b1、基站的MAC层请求基站的PDCP层通过第一完整性保护密钥对NCC执行完整性保护操作。
步骤702b2、基站的PDCP层通过第一完整性保护密钥对NCC执行完整性保护操作,生成第五MAC-I,并传递给基站的MAC层。
本申请的一些实施例中,上述第五MAC-I可以为第三信息。
步骤702b3、基站的MAC层基于NCC和第五MAC-I生成第二MAC CE。
本申请的实施例中,上述第二MAC CE包括NCC和第五MAC-I。
本申请的一些实施例中,在基站的RRC层只将UE的UE上下文里保存的NCC传递给基站的MAC层,即NCC未执行完整性保护操作的情况下,基站的MAC层可以请求UE的PDCP层通过第一完整性保护密钥对NCC执行完整性保护操作,或者,对包含该NCC的字节或字节流执行完整性保护操作。
如此,由于NCC被进行了完整性保护,从而提高了安全性。
本申请的一些实施例中,上述步骤702具体可以通过下述的步骤702d至步骤702f实现。
步骤702d、基站的RRC层将UE的UE上下文里保存的NCC传递给基站的PDCP层。
本申请的一些实施例中,基站的RRC层收到RRC重建立消息后,可以获取UE的UE上下文里保存的NCC。
本申请的一些实施例中,基站的RRC层可以基于NCC更新基站使用的密钥,并基于更新的密钥生成第一加密密钥和第一完整性保护密钥。
本申请的一些实施例中,基站的RRC层可以通过层间交互将NCC递交给UE的PDCP层。
步骤702e、基站的PDCP层基于NCC生成PDCP控制PDU。
本申请的实施例中,上述PDCP控制PDU用于请求UE更新UE使用的密钥,PDCP控制PDU包括NCC。
本申请的一些实施例中,上述PDCP控制PDU对应一个专用的PDU Type值,也就是说,将一个PDU Type值分配给PDCP control PDU。使得UE在接收到PDCP control PDU后,且该PDCP control PDU的PDU Type的值为该专用的PDU Type值时,UE能获知是PDCP control PDU。
示例性地,如图12所示,为本申请实施例提供的一种PDCP控制PDU的结构示意图,其中,其中:D/C用于指示是control PDU还是data PDU,PDU Type用于指示control PDU的类型,R是保留比特,NCC是上层递交的NCC。
步骤702f、基站向UE发送PDCP控制PDU。
本申请的一些实施例中,上述PDCP控制PDU用于请求UE更新UE使用的密钥。
本申请的一些实施例中,上述步骤702e具体可以通过下述的步骤702e1和步骤702e2实现。
步骤702e1、基站的PDCP层通过第一完整性保护密钥对NCC执行完整性保护操作,生成第六MAC-I。
本申请的一些实施例中,上述第六MAC-I可以为第三信息。
步骤702e2、基站的PDCP层基于NCC和第六MAC-I生成PDCP控制PDU。
本申请的实施例中,上述PDCP控制PDU包括第六MAC-I。
本申请的一些实施例中,上述基站的PDCP层对NCC执行完整性保护操作所使用的参数为第二参数或第二参数集。
如此,由于NCC被进行了完整性保护,从而提高了安全性。
本申请的一些实施例中,上述步骤703具体可以通过下述的步骤703a至步骤703d实现。
步骤703a、基站的RRC层生成RRC重建立消息,并传递给基站的PDCP层。
本申请的一些实施例中,基站的RRC层生成RRC重建立消息后,可以将RRC重建立消息作为PDCP SDU传递给SRB1对应的PDCP层。
步骤703b、基站的PDCP层通过第一加密密钥和第一完整性保护密钥对RRC重建立消息执行加密操作和完整性保护操作,生成第二PDCP PDU。
步骤703c、基站的PDCP层将第二PDCP PDU传递给基站的RLC层。
步骤703d、基站的RLC层向UE发送第二PDCP PDU。
可以理解,由于基站的PDCP层被配置使用第一加密密钥和第一完整性保护密钥恢复完整性保护和加密,因此,基站的PDCP层可以通过第一加密密钥和第一完整性保护密钥对RRC重建立消息执行加密操作和完整性保护操作,生成第二PDCP PDU,并将第二PDCP PDU传递给基站的RLC层以发送给UE。
本申请的一些实施例中,上述步骤703具体可以通过下述的步骤703e实现。
步骤703e、在第一信令被发送后,或在第一信令被成功发送后,或在基站接收到第一信令的接收确认消息后,基站向UE发送第二PDCP PDU。
在本申请的一些实施例中,如图13所示,本申请实施例提供的通信方法可以包括下述的步骤B1至步骤B12。
B1、UE处于连接态,RRC层连接需要重建立。
B2、UE向基站发送RRC重建立请求消息。
B3、基站接收来自UE的RRC重建立请求消息。
B4、基站的RRC层将UE的UE上下文里保存的NCC传递给基站的MAC层。
B5、基站的MAC层基于NCC生成包括NCC的第二MAC CE。
B6、基站向UE发送第二MAC CE。
B7、UE接收来自基站的第二MAC CE。
B8、UE的RRC层基于第二MAC CE包括的NCC更新UE使用的密钥,并基于更新后的密钥生成第一加密密钥和第一完整性保护密钥,以及指示UE的PDCP层使用第一加密密钥和第一完整性保护密钥恢复完整性保护和加密。
B9、基站向UE发送第二PDCP PDU。
B10、UE的PDCP层使用第一加密密钥和第一完整性保护密钥对第二PDCP PDU执行解密操作和完整性保护验证操作,并将解密后的RRC重建立消息递交给UE的RRC层。
B11、UE的RRC层基于解密后的RRC重建立消息重建立RRC连接。
B12、UE向基站发送RRC重建立完成消息。
需要说明的是,针对上述步骤B1至步骤B12中的相关说明,可以参见上述实施例中的描述,此处不再赘述。
需要说明的是,上述步骤中“基站的RRC层生成RRC重建立消息,并传递给基站的PDCP层,基站的PDCP层通过第一加密密钥和第一完整性保护密钥对RRC重建立消息执行加密操作和完整性保护操作,生成第二PDCP PDU,并将第二PDCP PDU传递给基站的RLC层”与“基站生成第二MAC CE”可以同时执行,但是基站需要先将第二MAC CE发送给UE,再将第二PDCP PDU发送给UE。或者,基站可以将第二MAC CE对应的subPDU和第二PDCP PDU对应的subPDU放在一个MAC PDU里发送给UE,但是第二MAC CE对应的subPDU被放在前面。总之,需要确保UE先处理第二MAC CE,在UE的PDCP层使用第一加密密钥和第一完整性保护密钥恢复完整性保护和加密之后,UE的PDCP层才能处理第二PDCP PDU。
需要说明的是,在UE的PDCP层使用第一加密密钥和第一完整性保护密钥恢复完整性保护和加密之前,若UE的SRB1对应的PDCP实体接收到了PDCP PDU,例如:由于第二MAC CE的重传导致第二PDCP PDU先被接收到,则UE的SRB1对应的PDCP实体先不对第二PDCP PDU进行处理,直到等待第二MAC CE被收到,UE的PDCP层使用第一加密密钥和第一完整性保护密钥恢复完整性保护和加密之后,UE的PDCP层才能处理第二PDCP PDU。
在本申请的一些实施例中,如图14所示,本申请实施例提供的通信方法可以包括下述的步骤C1至步骤C12。
C1、UE处于连接态,RRC层连接需要重建立。
C2、UE向基站发送RRC重建立请求消息。
C3、基站接收来自UE的RRC重建立请求消息。
C4、基站的RRC层将UE的UE上下文里保存的NCC传递给基站的PDCP层。
C5、基站的PDCP层基于NCC生成包括NCC的PDCP控制PDU。
C6、基站向UE发送PDCP控制PDU。
C7、UE接收来自基站的PDCP控制PDU。
C8、UE的RRC层基于PDCP控制PDU包括的NCC更新UE使用的密钥,并基于更新后的密钥生成第一加密密钥和第一完整性保护密钥,以及指示UE的PDCP层使用第一加密密钥和第一完整性保护密钥恢复完整性保护和加密。
C9、基站向UE发送第二PDCP PDU。
C10、UE的PDCP层使用第一加密密钥和第一完整性保护密钥对第二PDCP PDU执行解密操作和完整性保护验证操作,并将解密后的RRC重建立消息递交给UE的RRC层。
C11、UE的RRC层基于解密后的RRC重建立消息重建立RRC连接。
C12、UE向基站发送RRC重建立完成消息。
需要说明的是,针对上述步骤C1至步骤C12中的相关说明,可以参见上述实施例中的描述,此处不再赘述。
上述各个方法实施例,或者各个方法实施例中的各种可能的实现方式均可以单独执行,也可以任意两个或两个以上相互结合执行,具体可以根据实际使用需求确定,本申请实施例对此不做限制。
本申请实施例提供的通信方法,执行主体可以为通信装置。本申请实施例中以通信装置执行通信方法为例,说明本申请实施例提供的通信装置。
图15示出了本申请实施例中涉及的通信装置的一种可能的结构示意图,应用于UE。如图15所示,通信装置60可以包括:发送模块61、接收模块62、处理模块63和指示模块64。
其中,发送模块61,用于向基站发送RRC重建立请求消息。
接收模块62,用于接收来自基站的第一信令,第一信令用于请求UE更新UE使用的密钥,第一信令包括NCC,第一信令为第二MAC CE或PDCP控制PDU。
处理模块63,用于基于NCC更新UE使用的密钥,并基于更新后的密钥生成第一加密密钥和第一完整性保护密钥。
指示模块64,用于指示UE的PDCP层使用处理模块63生成的第一加密密钥和第一完整性保护密钥恢复完整性保护和加密。
处理模块63,还用于在UE的PDCP层使用第一加密密钥和第一完整性保护密钥恢复完整性保护和加密之后,处理来自基站的第二PDCP PDU,第二PDCP PDU中包括被完整性保护和加密的RRC重建立消息,RRC重建立消息用于指示UE重建立RRC连接。
本申请实施例提供一种通信装置,由于UE向基站发送RRC重建立请求消息后,可以接收来自基站的用于请求UE更新UE使用的密钥的第一信令,因此UE的RRC层可以基于第一信令中包括的NCC,更新UE使用的密钥,并基于更新后的密钥生成第一加密密钥和第一完整性保护密钥,以及指示UE的PDCP层使用第一加密密钥和第一完整性保护密钥恢复完整性保护和加密,然后,UE的PDCP层在使用第一加密密钥和第一完整性保护密钥恢复完整性保护和加密之后,可以处理来自基站的第二PDCP PDU,该第二PDCP PDU中包括被完整性保护和加密的RRC重建立消息,该RRC重建立消息用于指示UE重建立RRC连接,也就是说,UE的PDCP层是先恢复完整性保护和加密的,然后再处理来自基站的第二PDCP PDU,因此RRC重建立消息可以被完整性保护和加密,从而提高了RRC重建立消息的安全性。
在一种可能的实现方式中,第一信令包括第三信息,第三信息为对NCC执行完整性保护操作生成的MAC-I;指示模块64,具体用于请求UE的PDCP层使用第一完整性保护密钥和第三信息对NCC执行完整性保护验证操作;并通过第一完整性保护密钥和第三信息对NCC执行完整性保护验证操作;以及在UE的PDCP层对NCC执行完整性保护验证操作通过的情况下,UE的RRC层指示UE的PDCP层使用第一加密密钥和第一完整性保护密钥恢复完整性保护和加密。
在一种可能的实现方式中,处理模块63,还用于在UE的PDCP层对NCC执行完整性保护验证操作失败的情况下,进入空闲态。
在一种可能的实现方式中,UE的PDCP层对NCC执行完整性保护验证操作所使用的参数为第二参数或第二参数集;其中,第二参数或第二参数集包括以下至少一项:COUNT值的所有比特为1、BEARER值的所有比特为1、DIRECTION为下行方向。
在一种可能的实现方式中,在第一信令为第二MAC CE的情况下,接收模块62,具体用于接收来自基站的第二MAC CE;并解析第二MAC CE,得到NCC,并将NCC递交给UE的RRC层。
在一种可能的实现方式中,在第一信令为PDCP控制PDU的情况下,接收模块62,具体用于接收来自基站的PDCP控制PDU;并解析PDCP控制PDU,得到NCC,并将NCC递交给UE的RRC层。
在一种可能的实现方式中,处理模块63,具体用于使用第一加密密钥和第一完整性保护密钥对第二PDCP PDU执行解密操作和完整性保护验证操作,并将解密后的RRC重建立消息递交给UE的RRC层。
在一种可能的实现方式中,处理模块63,还用于基于解密后的RRC重建立消息重建立RRC连接;发送模块61,还用于向基站发送RRC重建立完成消息,RRC重建立完成消息为UE的PDCP层通过第一加密密钥和第一完整性保护密钥处理后的消息。
本申请实施例提供的通信装置能够实现上述方法实施例中UE实现的各个过程,并达到相同的技术效果,为避免重复,这里不再赘述。
图16示出了本申请实施例中涉及的通信装置的另一种可能的结构示意图,应用于基站。如图16所示,通信装置70可以包括:接收模块71和发送模块72。
接收模块71,用于接收来自UE的RRC重建立请求消息。
发送模块72,用于向UE发送第一信令,第一信令用于请求UE更新UE使用的密钥,第一信令包括NCC,第一信令为第二MAC CE或PDCP控制PDU;并向UE发送第二PDCP PDU,第二PDCP PDU中包括被完整性保护和加密的RRC重建立消息,RRC重建立消息用于指示UE重建立RRC连接。
本申请实施例提供一种通信装置,由于基站接收到UE发送的RRC重建立请求消息后,可以向UE发送用于请求UE更新UE使用的密钥的第一信令,第一信令包括NCC,以及向UE发送指示UE重建立RRC连接的第二PDCP PDU,第二PDCP PDU中包括被完整性保护和加密的RRC重建立消息,即NCC和RRC重建立消息是分开的,因此提高了RRC重建立消息的安全性。
在一种可能的实现方式中,本申请实施例提供的通信装置还包括:处理模块和指示模块;处理模块,用于在发送模块72向UE发送第二PDCP PDU之前,更新基站使用的密钥,并基于更新后的密钥生成第一加密密钥和第一完整性保护密钥。指示模块,用于指示基站的PDCP层使用处理模块生成的第一加密密钥和第一完整性保护密钥恢复完整性保护和加密。
在一种可能的实现方式中,本申请实施例提供的通信装置还包括:传递模块和生成模块。传递模块,用于将UE的UE上下文里保存的NCC传递给基站的MAC层。生成模块,用于基于传递模块传递的NCC生成第二MAC CE,第二MAC CE用于请求UE更新UE使用的密钥,第二MAC CE包括NCC。发送模块72,具体用于向UE发送生成模块生成的第二MAC CE。
在一种可能的实现方式中,传递模块,具体用于请求基站的PDCP层通过第一完整性保护密钥对NCC执行完整性保护操作;并通过第一完整性保护密钥对NCC执行完整性保护操作,生成第四MAC-I,并传递给基站的RRC层;以及将NCC和第四MAC-I传递给基站的MAC层;其中,第二MAC CE包括NCC和第四MAC-I。
在一种可能的实现方式中,生成模块,具体用于请求基站的PDCP层通过第一完整性保护密钥对NCC执行完整性保护操作;并通过第一完整性保护密钥对NCC执行完整性保护操作,生成第五MAC-I,并传递给基站的MAC层;以及基于NCC和第五MAC-I生成第二MAC CE,第二MAC CE包括NCC和第五MAC-I。
在一种可能的实现方式中,本申请实施例提供的通信装置还包括:传递模块和生成模块;传递模块,用于将UE的UE上下文里保存的NCC传递给基站的PDCP层。生成模块,用于基于传递模块传递的NCC生成PDCP控制PDU,PDCP控制PDU用于请求UE更新UE使用的密钥,PDCP控制PDU包括NCC。发送模块72,具体用于向UE发送生成模块生成的PDCP控制PDU。
在一种可能的实现方式中,生成模块,具体用于通过第一完整性保护密钥对NCC执行完整性保护操作,生成第六MAC-I;并基于NCC和第六MAC-I生成PDCP控制PDU,PDCP控制PDU包括第六MAC-I。
在一种可能的实现方式中,基站的PDCP层对NCC执行完整性保护操作所使用的参数为第二参数或第二参数集;其中,第二参数或第二参数集包括以下至少一项:COUNT值的所有比特为1、BEARER值的所有比特为1、DIRECTION为下行方向。
在一种可能的实现方式中,发送模块72,具体用于生成RRC重建立消息,并传递给基站的PDCP层;并通过第一加密密钥和第一完整性保护密钥对RRC重建立消息执行加密操作和完整性保护操作,生成第二PDCP PDU;并将第二PDCP PDU传递给基站的无线链路控制RLC层;以及向UE发送第二PDCP PDU。
在一种可能的实现方式中,发送模块72,具体用在第一信令被发送后,或在第一信令被成功发送后,或在基站接收到第一信令的接收确认消息后,向UE发送第二PDCP PDU。
本申请实施例提供的通信装置能够实现上述方法实施例中基站实现的各个过程,并达到相同的技术效果,为避免重复,这里不再赘述。
可选地,如图17所示,本申请实施例还提供一种通信设备5000,包括处理器5001和存储器5002,存储器5002上存储有可在所述处理器5001上运行的程序或指令,例如,该通信设备5000为UE时,该程序或指令被处理器5001执行时实现上述UE侧方法实施例的各个步骤,且能达到相同的技术效果。该通信设备5000为基站时,该程序或指令被处理器5001执行时实现上述基站方法实施例的各个步骤,且能达到相同的技术效果,为避免重复,这里不再赘述。
本申请实施例还提供一种UE,包括处理器和通信接口,所述通信接口和所述处理器耦合,所述处理器用于运行程序或指令,实现如上述方法实施例中的步骤。该UE实施例与上述UE侧方法实施例对应,上述方法实施例的各个实施过程和实现方式均可适用于该UE实施例中,且能达到相同的技术效果。
具体地,图18为实现本申请实施例的一种UE的硬件结构示意图。
该UE100包括但不限于:射频单元101、网络模块102、音频输出单元103、输入单元104、传感器105、显示单元106、用户输入单元107、接口单元108、存储器109以及处理器110等中的至少部分部件。
本领域技术人员可以理解,UE100还可以包括给各个部件供电的电源(比如电池),电源可以通过电源管理系统与处理器110逻辑相连,从而通过电源管理系统实现管理充电、放电、以及功耗管理等功能。图18中示出的UE结构并不构成对UE的限定,UE可以包括比图示更多或更少的部件,或者组合某些部件,或者不同的部件布置,在此不再赘述。
应理解的是,本申请实施例中,输入单元104可以包括图形处理器(Graphics Processing Unit,GPU)1041和麦克风1042,图形处理器1041对在视频捕获模式或图像捕获模式中由图像捕获装置(如摄像头)获得的静态图片或视频的图像数据进行处理。显示单元106可包括显示面板1061,可以采用液晶显示器、有机发光二极管等形式来配置显示面板1061。用户输入单元107包括触控面板1071以及其他输入设备1072中的至少一种。触控面板1071,也称为触摸屏。触控面板1071可包括触摸检测装置和触摸控制器两个部分。其他输入设备1072可以包括但不限于物理键盘、功能键(比如音量控制按键、开关按键等)、轨迹球、鼠标、操作杆,在此不再赘述。
本申请实施例中,射频单元101接收来自网络侧设备的下行数据后,可以传输给处理器110进行处理;另外,射频单元101可以向网络侧设备发送上行数据。通常,射频单元101包括但不限于天线、放大器、收发信机、耦合器、低噪声放大器、双工器等。
存储器109可用于存储软件程序或指令以及各种数据。存储器109可主要包括存储程序或指令的第一存储区和存储数据的第二存储区,其中,第一存储区可存储操作系统、至少一个功能所需的应用程序或指令(比如声音播放功能、图像播放功能等)等。此外,存储器109可以包括易失性存储器或非易失性存储器,或者,存储器109可以包括易失性和非易失性存储器两者。其中,非易失性存储器可以是只读存储器(Read-Only Memory,ROM)、可编程只读存储器(Programmable ROM,PROM)、可擦除可编程只读存储器(Erasable PROM,EPROM)、电可擦除可编程只读存储器(Electrically EPROM,EEPROM)或闪存。易失性存储器可以是随机存取存储器(Random Access Memory,RAM),静态随机存取存储器(Static RAM,SRAM)、动态随机存取存储器(Dynamic RAM,DRAM)、同步动态随机存取存储器(Synchronous DRAM,SDRAM)、双倍数据速率同步动态随机存取存储器(Double Data Rate SDRAM,DDRSDRAM)、增强型同步动态随机存取存储器(Enhanced SDRAM,ESDRAM)、同步连接动态随机存取存储器(Synch link DRAM,SLDRAM)和直接内存总线随机存取存储器(Direct Rambus RAM,DRRAM)。本申请实施例中的存储器109包括但不限于这些和任意其它适合类型的存储器。
处理器110可包括一个或多个处理单元;可选的,处理器110集成应用处理器和调制解调处理器,其中,应用处理器主要处理涉及操作系统、用户界面和应用程序等的操作,调制解调处理器主要处理无线通信信号,如基带处理器。可以理解的是,上述调制解调处理器也可以不集成到处理器110中。
本申请实施例提供的UE能够实现上述方法实施例中终端实现的各个过程,并达到相同的技术效果,为避免重复,这里不再赘述。
本申请实施例还提供一种基站,包括处理器和通信接口,所述通信接口和所述处理器耦合,所述处理器用于运行程序或指令,实现上述方法实施例的步骤。该基站实施例与上述基站方法实施例对应,上述方法实施例的各个实施过程和实现方式均可适用于该基站实施例中,且能达到相同的技术效果。
具体地,本申请实施例还提供了一种基站。如图19所示,该基站600包括:天线61、射频装置62、基带装置63、处理器64和存储器65。天线61与射频装置62连接。在上行方向上,射频装置62通过天线61接收信息,将接收的信息发送给基带装置63进行处理。在下行方向上,基带装置63对要发送的信息进行处理,并发送给射频装置62,射频装置62对收到的信息进行处理后经过天线61发送出去。
以上实施例中基站执行的方法可以在基带装置63中实现,该基带装置63包括基带处理器。
本申请实施例提供的基站能够实现上述方法实施例中基站实现的各个过程,并达到相同的技术效果,为避免重复,这里不再赘述。
基带装置63例如可以包括至少一个基带板,该基带板上设置有多个芯片,如图19所示,其中一个芯片例如为基带处理器,通过总线接口与存储器65连接,以调用存储器65中的程序,执行以上方法实施例中所示的网络设备操作。
该基站还可以包括网络接口66,该接口例如为通用公共无线接口(common public radio interface,CPRI)。
具体地,本申请实施例的基站600还包括:存储在存储器65上并可在处理器64上运行的指令或程序,处理器64调用存储器65中的指令或程序执行图19所示各模块执行的方法,并达到相同的技术效果,为避免重复,故不在此赘述。
本申请实施例还提供一种可读存储介质,所述可读存储介质上存储有程序或指令,该程序或指令被处理器执行时实现上述方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。
其中,所述处理器为上述实施例中所述的通信设备中的处理器。所述可读存储介质,包括计算机可读存储介质,如计算机只读存储器ROM、随机存取存储器RAM、磁碟或者光盘等。
本申请实施例另提供了一种芯片,所述芯片包括处理器和通信接口,所述通信接口和所述处理器耦合,所述处理器用于运行程序或指令,实现上述方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。
应理解,本申请实施例提到的芯片还可以称为系统级芯片,系统芯片,芯片系统或片上系统芯片等。
本申请实施例另提供了一种计算机程序/程序产品,所述计算机程序/程序产品被存储在存储介质中,所述计算机程序/程序产品被至少一个处理器执行以实现上述方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。
本申请实施例还提供了一种通信系统,包括:UE及终端,所述UE可用于执行如上所述的通信方法的步骤,所述终端可用于执行如上所述的通信方法的步骤。
需要说明的是,在本文中,术语“包括”、“包含”或者其任何其他变体意在涵盖非排他性的包含,从而使得包括一系列要素的过程、方法、物品或者装置不仅包括那些要素,而且还包括没有明确列出的其他要素,或者是还包括为这种过程、方法、物品或者装置所固有的要素。在没有更多限制的情况下,由语句“包括一个……”限定的要素,并不排除在包括该要素的过程、方法、物品或者装置中还存在另外的相同要素。此外,需要指出的是,本申请实施方式中的方法和装置的范围不限按示出或讨论的顺序来执行功能,还可包括根据所涉及的功能按基本同时的方式或按相反的顺序来执行功能,例如,可以按不同于所描述的次序来执行所描述的方法,并且还可以添加、省去、或组合各种步骤。另外,参照某些示例所描述的特征可在其他示例中被组合。
通过以上的实施方式的描述,本领域的技术人员可以清楚地了解到上述实施例方法可借助软件加必需的通用硬件平台的方式来实现,当然也可以通过硬件,但很多情况下前者是更佳的实施方式。基于这样的理解,本申请的技术方案本质上或者说对现有技术做出贡献的部分可以以计算机软件产品的形式体现出来,该计算机软件产品存储在一个存储介质(如ROM/RAM、磁碟、光盘)中,包括若干指令用以使得一台终端(可以是手机,计算机,服务器,空调器,或者网络设备等)执行本申请各个实施例所述的方法。
上面结合附图对本申请的实施例进行了描述,但是本申请并不局限于上述的具体实施方式,上述的具体实施方式仅仅是示意性的,而不是限制性的,本领域的普通技术人员在本申请的启示下,在不脱离本申请宗旨和权利要求所保护的范围情况下,还可做出很多形式,均属于本申请的保护之内。

Claims (83)

  1. 一种通信方法,所述方法包括:
    用户设备UE向基站发送无线资源控制RRC重建立请求消息;
    所述UE的媒体接入控制MAC层接收来自所述基站的第一媒体接入控制控制单元MAC CE;
    其中,所述第一MAC CE包括下一跳链计数NCC和第一字节流,所述第一字节流包括加密后的RRC重建立消息,所述RRC重建立消息用于指示所述UE重建立RRC连接。
  2. 根据权利要求1所述的方法,其中,所述UE的MAC层接收来自所述基站的第一MAC CE之后,所述方法还包括:
    所述UE的MAC层解析所述第一MAC CE,得到所述NCC和所述第一字节流;
    所述UE的MAC层将所述NCC和所述第一字节流传递给所述UE的RRC层;
    所述UE的RRC层基于所述NCC更新所述UE使用的密钥,并基于更新后的密钥生成第一加密密钥和第一完整性保护密钥;
    所述UE的RRC层请求所述UE的分组数据汇聚协议PDCP层基于所述第一加密密钥和所述第一完整性保护密钥对所述第一字节流进行处理;
    所述UE的PDCP层基于所述第一加密密钥和所述第一完整性保护密钥对所述第一字节流进行处理。
  3. 根据权利要求2所述的方法,其中,所述第一字节流对应第一PDCP协议数据单元PDU,所述第一PDCP PDU包括加密后的第一消息鉴权码MAC-I,加密后的所述第一MAC-I为所述基站的PDCP层通过对所述RRC重建立消息执行完整性保护操作生成的;
    所述UE的PDCP层基于所述第一加密密钥和所述第一完整性保护密钥对所述第一字节流进行处理,包括:
    所述UE的PDCP层解析所述第一PDCP PDU,得到加密后的所述RRC重建立消息和加密后的所述第一MAC-I;
    所述UE的PDCP层通过所述第一加密密钥,对加密后的所述RRC重建立消息和加密后的所述第一MAC-I执行解密操作,得到解密后的所述RRC重建立消息和解密后的所述第一MAC-I;
    所述UE的PDCP层通过所述第一完整性保护密钥和解密后的所述第一MAC-I,对解密后的所述RRC重建立消息执行完整性保护验证操作。
  4. 根据权利要求2所述的方法,其中,所述第一MAC CE包括第一信息,所述第一信息为通过对所述RRC重建立消息执行完整性保护操作生成的MAC-I;
    所述UE的PDCP层基于所述第一加密密钥和所述第一完整性保护密钥对所述第一字节流进行处理,包括:
    所述UE的PDCP层通过所述第一加密密钥对所述第一字节流执行解密操作,得到解密后的所述RRC重建立消息;
    所述UE的PDCP层通过所述第一完整性保护密钥和所述第一信息对解密后的所述RRC重建立消息执行完整性保护验证操作。
  5. 根据权利要求2所述的方法,其中,所述第一MAC CE包括第二信息,所述第二信息为通过对所述NCC和所述第一字节流执行完整性保护操作生成的MAC-I;
    所述UE的PDCP层基于所述第一加密密钥和所述第一完整性保护密钥对所述第一字节流进行处理,包括:
    所述UE的PDCP层通过所述第一完整性保护密钥和所述第二信息,对所述NCC和所述第一字节流执行完整性保护验证操作;
    在所述UE的PDCP层对所述NCC和所述第一字节流执行完整性保护验证操作通过的情况下,所述UE的PDCP层通过所述第一加密密钥对所述第一字节流执行解密操作,得到解密后的所述RRC重建立消息。
  6. 根据权利要求3至5任一项所述的方法,其中,所述UE的PDCP层执行解密操作和完整性保护验证操作所使用的参数为第一参数或第一参数集;
    其中,所述第一参数或所述第一参数集包括以下至少一项:COUNT值为0,BEARER为无线信令承载SRB1的承载标识,DIRECTION为下行方向。
  7. 根据权利要求6所述的方法,其中,所述方法还包括:
    所述UE的PDCP层将所述SRB1对应的PDCP实体维护的第一变量置为1或增加1,所述第一变量为对应下一个期望接收的PDCP业务数据单元SDU的COUNT值的变量。
  8. 根据权利要求4或5所述的方法,其中,所述UE的PDCP层执行解密操作和完整性保护验证操作所使用的参数为第二参数或第二参数集;
    其中,所述第二参数或所述第二参数集包括以下至少一项:COUNT值的所有比特为1、BEARER值的所有比特为1、DIRECTION为下行方向。
  9. 根据权利要求3至5任一项所述的方法,其中,所述UE的PDCP层基于所述第一加密密钥和所述第一完整性保护密钥对所述第一字节流进行处理之后,所述方法还包括:
    在所述UE的PDCP层执行完整性保护验证操作失败的情况下,所述UE进入空闲态;
    在所述UE的PDCP层执行完整性保护验证操作通过的情况下,所述UE的PDCP层将解密后的所述RRC重建立消息传递给所述UE的RRC层。
  10. 根据权利要求9所述的方法,其中,所述UE的PDCP层将解密后的所述RRC重建立消息传递给所述UE的RRC层之后,所述方法还包括:
    所述UE的RRC层基于解密后的所述RRC重建立消息重建立RRC连接;
    所述UE向所述基站发送RRC重建立完成消息,所述RRC重建立完成消息为所述UE的PDCP层通过所述第一加密密钥和所述第一完整性保护密钥处理后的消息。
  11. 根据权利要求10所述的方法,其中,所述UE的RRC层基于解密后的所述RRC重建立消息重建立RRC连接,包括:
    在所述第一MAC CE中的NCC与所述RRC重建立消息中的NCC相同的情况下,所述UE的RRC层根据解密后的所述RRC重建立消息重建立RRC连接。
  12. 一种通信方法,所述方法包括:
    基站接收来自UE的RRC重建立请求消息;
    所述基站的MAC层向所述UE发送第一MAC CE;
    其中,所述第一MAC CE包括NCC和第一字节流,所述第一字节流包括加密后的RRC重建立消息,所述RRC重建立消息用于指示所述UE重建立RRC连接。
  13. 根据权利要求12所述的方法,其中,所述基站接收来自UE的RRC重建立请求消息之后,所述方法还包括:
    所述基站的RRC层更新所述基站使用的密钥,并基于更新后的密钥生成第一加密密钥和第一完整性保护密钥;
    所述基站的RRC层指示所述基站的PDCP层使用所述第一加密密钥和所述第一完整性保护密钥恢复完整性保护和加密;
    所述基站的RRC层生成所述RRC重建立消息,并请求所述基站的PDCP层对所述RRC重建立消息执行安全保护。
  14. 根据权利要求13所述的方法,其中,所述基站的RRC层生成所述RRC重建立消息,并请求所述基站的PDCP层对所述RRC重建立消息执行安全保护之后,所述方法还包括:
    所述基站的PDCP层对所述RRC重建立消息执行安全保护,生成所述第一字节流,并向所述基站的RRC层传递所述第一字节流,所述第一字节流包括被安全保护后的所述RRC重建立消息,所述安全保护包括以下至少一项:加密操作、完整性保护操作;
    所述基站的RRC层将所述第一字节流和所述UE的UE上下文中保存的NCC传递给所述基站的MAC层;
    所述基站的MAC层基于所述NCC和所述第一字节流生成所述第一MAC CE。
  15. 根据权利要求14所述的方法,其中,所述基站的PDCP层对所述RRC重建立消息执行安全保护,生成所述第一字节流,包括:
    所述基站的PDCP层通过所述第一完整性保护密钥对所述RRC重建立消息执行完整性保护操作,生成第一MAC-I;
    所述基站的PDCP层通过所述第一加密密钥对所述RRC重建立消息和所述第一MAC-I执行加密操作,生成第一PDCP PDU,所述第一PDCP PDU对应所述第一字节流,所述第一PDCP PDU包括加密后的所述RRC重建立消息和所述第一MAC-I。
  16. 根据权利要求14所述的方法,其中,所述基站的PDCP层对所述RRC重建立消息执行安全保护,生成所述第一字节流,并向所述基站的RRC层传递所述第一字节流,包括:
    所述基站的PDCP层通过所述第一加密密钥对所述RRC重建立消息执行加密操作,生成所述第一字节流;
    所述基站的PDCP层通过所述第一完整性保护密钥对所述RRC重建立消息执行完整性保护操作,生成第一信息,所述第一信息为通过对所述RRC重建立消息执行完整性保护操作生成的MAC-I;
    所述基站的PDCP层向所述基站的RRC层传递所述第一字节流和所述第一信息;
    其中,所述基站的MAC层生成的所述第一MAC CE中包括所述第一字节流、所述NCC和所述第一信息,所述第一信息为所述基站的RRC层传递给所述基站的MAC层的。
  17. 根据权利要求14所述的方法,其中,所述基站的RRC层将所述第一字节流和所述UE的UE上下文中保存的NCC传递给所述基站的MAC层之前,所述方法还包括:
    所述基站的RRC层请求所述基站的PDCP层对所述NCC和所述第一字节流执行完整性保护操作;
    所述基站的PDCP层通过所述第一完整性保护密钥对所述NCC和所述第一字节流执行完整性保护操作,生成第二MAC-I,并将所述第二MAC-I传递给所述基站的RRC层;
    其中,所述基站的MAC层生成的所述第一MAC CE中包括所述第一字节流、所述NCC和所述第二MAC-I,所述第二MAC-I为所述基站的RRC层传递给所述基站的MAC层的。
  18. 根据权利要求14所述的方法,其中,所述基站的MAC层基于所述NCC和所述第一字节流生成所述第一MAC CE之前,所述方法还包括:
    所述基站的MAC层请求所述基站的PDCP层对所述NCC和所述第一字节流执行完整性保护操作;
    所述基站的PDCP层通过所述第一完整性保护密钥对所述NCC和所述第一字节流执行完整性保护,生成第三MAC-I,并将所述第三MAC-I传递给所述基站的MAC层;
    其中,所述基站的MAC层生成的所述第一MAC CE中包括所述第一字节流、所述NCC和所述第三MAC-I。
  19. 根据权利要求15至18任一项所述的方法,其中,所述基站的PDCP层执行加密操作和执行完整性保护操作所使用的参数为第一参数或第一参数集;
    其中,所述第一参数或所述第一参数集包括以下至少一项:COUNT值为0,BEARER为无线信令承载SRB1的承载标识,DIRECTION为下行方向。
  20. 根据权利要求19所述的方法,其中,所述方法还包括:
    所述基站的PDCP层将所述SRB1对应的PDCP实体维护的第二变量置为1或增加1,所述第二变量为对应下一个将发送的PDCP业务数据单元SDU的COUNT值的变量。
  21. 根据权利要求16至18任一项所述的方法,其中,所述基站的PDCP层执行加密操作和执行完整性保护操作所使用的参数为第二参数或第二参数集;
    其中,所述第二参数或所述第二参数集包括以下至少一项:COUNT值的所有比特为1、BEARER值的所有比特为1、DIRECTION为下行方向。
  22. 一种通信方法,所述方法包括:
    UE向基站发送RRC重建立请求消息;
    所述UE接收来自所述基站的第一信令,所述第一信令用于请求所述UE更新所述UE使用的密钥,所述第一信令包括NCC,所述第一信令为第二MAC CE或PDCP控制PDU;
    所述UE的RRC层基于所述NCC更新所述UE使用的密钥,并基于更新后的密钥生成第一加密密钥和第一完整性保护密钥;
    所述UE的RRC层指示所述UE的PDCP层使用所述第一加密密钥和所述第一完整性保护密钥恢复完整性保护和加密;
    在所述UE的PDCP层使用所述第一加密密钥和所述第一完整性保护密钥恢复完整性保护和加密之后,所述UE的PDCP层处理来自所述基站的第二PDCP PDU,所述第二PDCP PDU中包括被完整性保护和加密的RRC重建立消息,所述RRC重建立消息用于指示所述UE重建立RRC连接。
  23. 根据权利要求22所述的方法,其中,所述第一信令包括第三信息,所述第三信息为对所述NCC执行完整性保护操作生成的MAC-I;所述UE的RRC层指示所述UE的PDCP层使用所述第一加密密钥和所述第一完整性保护密钥恢复完整性保护和加密,包括:
    所述UE的RRC层请求所述UE的PDCP层使用所述第一完整性保护密钥和所述第三信息对所述NCC执行完整性保护验证操作;
    所述UE的PDCP层通过所述第一完整性保护密钥和所述第三信息对所述NCC执行完整性保护验证操作;
    在所述UE的PDCP层对所述NCC执行完整性保护验证操作通过的情况下,所述UE的RRC层指示所述UE的PDCP层使用所述第一加密密钥和所述第一完整性保护密钥恢复完整性保护和加密。
  24. 根据权利要求23所述的方法,其中,所述方法还包括:
    在所述UE的PDCP层对所述NCC执行完整性保护验证操作失败的情况下,所述UE进入空闲态。
  25. 根据权利要求23所述的方法,其中,所述UE的PDCP层对所述NCC执行完整性保护验证操作所使用的参数为第二参数或第二参数集;
    其中,所述第二参数或所述第二参数集包括以下至少一项:COUNT值的所有比特为1、BEARER值的所有比特为1、DIRECTION为下行方向。
  26. 根据权利要求22所述的方法,其中,在所述第一信令为第二MAC CE的情况下,所述UE接收来自所述基站的第一信令,包括:
    所述UE的MAC层接收来自所述基站的所述第二MAC CE;
    所述UE的MAC层解析所述第二MAC CE,得到所述NCC,并将所述NCC递交给所述UE的RRC层。
  27. 根据权利要求22所述的方法,其中,在所述第一信令为PDCP控制PDU的情况下,所述UE接收来自所述基站的第一信令,包括:
    所述UE的PDCP层接收来自所述基站的PDCP控制PDU;
    所述UE的PDCP层解析所述PDCP控制PDU,得到所述NCC,并将所述NCC递交给所述UE的RRC层。
  28. 根据权利要求22所述的方法,其中,所述UE的PDCP层处理来自所述基站的第二PDCP PDU,包括:
    所述UE的PDCP层使用所述第一加密密钥和所述第一完整性保护密钥对所述第二PDCP PDU执行解密操作和完整性保护验证操作,并将解密后的所述RRC重建立消息递交给所述UE的RRC层。
  29. 根据权利要求28所述的方法,其中,所述方法还包括:
    所述UE的RRC层基于解密后的所述RRC重建立消息重建立RRC连接;
    所述UE向所述基站发送所述RRC重建立完成消息,所述RRC重建立完成消息为所述UE的PDCP层通过所述第一加密密钥和所述第一完整性保护密钥处理后的消息。
  30. 一种通信方法,所述方法包括:
    基站接收来自UE的RRC重建立请求消息;
    所述基站向所述UE发送第一信令,所述第一信令用于请求所述UE更新所述UE使用的密钥,所述第一信令包括NCC,所述第一信令为第二MAC CE或PDCP控制PDU;
    所述基站向所述UE发送第二PDCP PDU,所述第二PDCP PDU中包括被完整性保护和加密的RRC重建立消息,所述RRC重建立消息用于指示所述UE重建立RRC连接。
  31. 根据权利要求30所述的方法,其中,在所述基站向所述UE发送第二PDCP PDU之前,所述方法还包括:
    所述基站的RRC层更新所述基站使用的密钥,并基于更新后的密钥生成第一加密密钥和第一完整性保护密钥;
    所述基站的RRC层指示所述基站的PDCP层使用所述第一加密密钥和所述第一完整性保护密钥恢复完整性保护和加密。
  32. 根据权利要求30所述的方法,其中,所述基站向所述UE发送第一信令,包括:
    所述基站的RRC层将所述UE的UE上下文里保存的NCC传递给所述基站的MAC层;
    所述基站的MAC层基于所述NCC生成所述第二MAC CE,所述第二MAC CE用于请求所述UE更新所述UE使用的密钥,所述第二MAC CE包括所述NCC;
    所述基站向所述UE发送所述第二MAC CE。
  33. 根据权利要求32所述的方法,其中,所述基站的RRC层将所述UE的UE上下文里保存的NCC传递给所述基站的MAC层,包括:
    所述基站的RRC层请求所述基站的PDCP层通过所述第一完整性保护密钥对所述NCC执行完整性保护操作;
    所述基站的PDCP层通过所述第一完整性保护密钥对所述NCC执行完整性保护操作,生成第四MAC-I,并传递给所述基站的RRC层;
    所述基站的RRC层将所述NCC和所述第四MAC-I传递给所述基站的MAC层;
    其中,所述第二MAC CE包括所述NCC和所述第四MAC-I。
  34. 根据权利要求32所述的方法,其中,所述基站的MAC层基于所述NCC生成所述第二MAC CE,包括:
    所述基站的MAC层请求所述基站的PDCP层通过所述第一完整性保护密钥对所述NCC执行完整性保护操作;
    所述基站的PDCP层通过所述第一完整性保护密钥对所述NCC执行完整性保护操作,生成第五MAC-I,并传递给所述基站的MAC层;
    所述基站的MAC层基于所述NCC和所述第五MAC-I生成所述第二MAC CE,所述第二MAC CE包括所述NCC和所述第五MAC-I。
  35. 根据权利要求30所述的方法,其中,所述基站向所述UE发送第一信令,包括:
    所述基站的RRC层将所述UE的UE上下文里保存的NCC传递给所述基站的PDCP层;
    所述基站的PDCP层基于所述NCC生成所述PDCP控制PDU,所述PDCP控制PDU用于请求所述UE更新所述UE使用的密钥,所述PDCP控制PDU包括所述NCC;
    所述基站向所述UE发送所述PDCP控制PDU。
  36. 根据权利要求35所述的方法,其中,所述基站的PDCP层基于所述NCC生成所述PDCP控制PDU,包括:
    所述基站的PDCP层通过所述第一完整性保护密钥对所述NCC执行完整性保护操作,生成第六MAC-I;
    所述基站的PDCP层基于所述NCC和所述第六MAC-I生成所述PDCP控制PDU,所述PDCP控制PDU包括所述第六MAC-I。
  37. 根据权利要求33或34或36所述的方法,其中,所述基站的PDCP层对所述NCC执行完整性保护操作所使用的参数为第二参数或第二参数集;
    其中,所述第二参数或所述第二参数集包括以下至少一项:COUNT值的所有比特为1、BEARER值的所有比特为1、DIRECTION为下行方向。
  38. 根据权利要求31所述的方法,其中,所述基站向所述UE发送第二PDCP PDU,包括:
    所述基站的RRC层生成所述RRC重建立消息,并传递给所述基站的PDCP层;
    所述基站的PDCP层通过所述第一加密密钥和所述第一完整性保护密钥对所述RRC重建立消息执行加密操作和完整性保护操作,生成所述第二PDCP PDU;
    所述基站的PDCP层将所述第二PDCP PDU传递给所述基站的无线链路控制RLC层;
    所述基站的RLC层向所述UE发送所述第二PDCP PDU。
  39. 根据权利要求31至38任一项所述的方法,其中,所述基站向所述UE发送第二PDCP PDU,包括:
    在所述第一信令被发送后,或在所述第一信令被成功发送后,或在所述基站接收到所述第一信令的接收确认消息后,所述基站向所述UE发送所述第二PDCP PDU。
  40. 一种通信装置,所述装置包括:发送模块和接收模块;
    所述发送模块,用于向基站发送RRC重建立请求消息;
    所述接收模块,用于接收来自所述基站的第一MAC CE;
    其中,所述第一MAC CE包括NCC和第一字节流,所述第一字节流包括加密后的RRC重建立消息,所述RRC重建立消息用于指示所述UE重建立RRC连接。
  41. 根据权利要求40所述的装置,其中,所述装置还包括:解析模块、传递模块、处理模块和请求模块;
    所述解析模块,用于在所述接收模块接收来自所述基站的第一MAC CE之后,解析所述第一MAC CE,得到所述NCC和所述第一字节流;
    所述传递模块,用于将所述解析模块解析得到的所述NCC和所述第一字节流传递给所述UE的RRC层;
    所述处理模块,用于基于所述传递模块传递的所述NCC更新所述UE使用的密钥,并基于更新后的密钥生成第一加密密钥和第一完整性保护密钥;
    所述请求模块,用于请求所述UE的PDCP层基于所述第一加密密钥和所述第一完整性保护密钥对所述第一字节流进行处理;
    所述处理模块,还用于基于所述第一加密密钥和所述第一完整性保护密钥对所述第一字节流进行处理。
  42. 根据权利要求41所述的装置,其中,所述第一字节流对应第一PDCP PDU,所述第一PDCP PDU包括加密后的第一MAC-I,加密后的所述第一MAC-I为所述基站的PDCP层通过对所述RRC重建立消息执行完整性保护操作生成的;
    所述处理模块,具体用于解析所述第一PDCP PDU,得到加密后的所述RRC重建立消息和加密后的所述第一MAC-I;并通过所述第一加密密钥,对加密后的所述RRC重建立消息和加密后的所述第一MAC-I执行解密操作,得到解密后的所述RRC重建立消息和解密后的所述第一MAC-I;以及通过所述第一完整性保护密钥和解密后的所述第一MAC-I,对解密后的所述RRC重建立消息执行完整性保护验证操作。
  43. 根据权利要求41所述的装置,其中,所述第一MAC CE包括第一信息,所述第一信息为通过对所述RRC重建立消息执行完整性保护操作生成的MAC-I;
    所述处理模块,具体用于通过所述第一加密密钥对所述第一字节流执行解密操作,得到解密后的所述RRC重建立消息;并通过所述第一完整性保护密钥和所述第一信息对解密后的所述RRC重建立消息执行完整性保护验证操作。
  44. 根据权利要求41所述的装置,其中,所述第一MAC CE包括第二信息,所述第二信息为通过对所述NCC和所述第一字节流执行完整性保护操作生成的MAC-I;
    所述处理模块,具体用于通过所述第一完整性保护密钥和所述第二信息,对所述NCC和所述第一字节流执行完整性保护验证操作;并在所述UE的PDCP层对所述NCC和所述第一字节流执行完整性保护验证操作通过的情况下,通过所述第一加密密钥对所述第一字节流执行解密操作,得到解密后的所述RRC重建立消息。
  45. 根据权利要求42至44任一项所述的装置,其中,所述UE的PDCP层执行解密操作和完整性保护验证操作所使用的参数为第一参数或第一参数集;
    其中,所述第一参数或所述第一参数集包括以下至少一项:COUNT值为0,BEARER为无线信令承载SRB1的承载标识,DIRECTION为下行方向。
  46. 根据权利要求45所述的装置,其中,所述处理模块,还用于将所述SRB1对应的PDCP实体维护的第一变量置为1或增加1,所述第一变量为对应下一个期望接收的PDCP业务数据单元SDU的COUNT值的变量。
  47. 根据权利要求43或44所述的装置,其中,所述UE的PDCP层执行解密操作和完整性保护验证操作所使用的参数为第二参数或第二参数集;
    其中,所述第二参数或所述第二参数集包括以下至少一项:COUNT值的所有比特为1、BEARER值的所有比特为1、DIRECTION为下行方向。
  48. 根据权利要求42至44任一项所述的装置,其中,所述处理模块,还用于在基于所述第一加密密钥和所述第一完整性保护密钥对所述第一字节流进行处理之后,在所述UE的PDCP层执行完整性保护验证操作失败的情况下,进入空闲态;
    所述传递模块,还用于在所述处理模块基于所述第一加密密钥和所述第一完整性保护密钥对所述第一字节流进行处理之后,在所述UE的PDCP层执行完整性保护验证操作通过的情况下,将解密后的所述RRC重建立消息传递给所述UE的RRC层。
  49. 根据权利要求48所述的装置,其中,所述处理模块,还用于在所述传递模块将解密后的所述RRC重建立消息传递给所述UE的RRC层之后,基于解密后的所述RRC重建立消息重建立RRC连接;
    所述发送模块,还用于向所述基站发送RRC重建立完成消息,所述RRC重建立完成消息为所述UE的PDCP层通过所述第一加密密钥和所述第一完整性保护密钥处理后的消息。
  50. 根据权利要求49所述的装置,其中,所述处理模块,具体用于在所述第一MAC CE中的NCC与所述RRC重建立消息中的NCC相同的情况下,根据解密后的所述RRC重建立消息重建立RRC连接。
  51. 一种通信装置,所述装置包括:接收模块和发送模块;
    所述接收模块,用于接收来自UE的RRC重建立请求消息;
    所述发送模块,用于向所述UE发送第一MAC CE;
    其中,所述第一MAC CE包括NCC和第一字节流,所述第一字节流包括加密后的RRC重建立消息,所述RRC重建立消息用于指示所述UE重建立RRC连接。
  52. 根据权利要求51所述的装置,其中,所述装置还包括:处理模块和指示模块;
    所述处理模块,用于在所述接收模块接收来自UE的RRC重建立请求消息之后,更新所述基站使用的密钥,并基于更新后的密钥生成第一加密密钥和第一完整性保护密钥;
    所述指示模块,用于指示所述基站的PDCP层使用所述处理模块生成的所述第一加密密钥和所述第一完整性保护密钥恢复完整性保护和加密;
    所述处理模块,还用于生成所述RRC重建立消息,并请求所述基站的PDCP层对所述RRC重建立消息执行安全保护。
  53. 根据权利要求52所述的装置,其中,所述装置还包括:传递模块和生成模块;
    所述处理模块,还用于在生成所述RRC重建立消息,并请求所述基站的PDCP层对所述RRC重建立消息执行安全保护之后,对所述RRC重建立消息执行安全保护,生成所述第一字节流,并向所述基站的RRC层传递所述第一字节流,所述第一字节流包括被安全保护后的所述RRC重建立消息,所述安全保护包括以下至少一项:加密操作、完整性保护操作;
    所述传递模块,用于将所述第一字节流和所述UE的UE上下文中保存的NCC传递给所述基站的MAC层;
    所述生成模块,用于基于所述NCC和所述第一字节流生成所述第一MAC CE。
  54. 根据权利要求53所述的装置,其中,所述生成模块,具体用于通过所述第一完整性保护密钥对所述RRC重建立消息执行完整性保护操作,生成第一MAC-I;并通过所述第一加密密钥对所述RRC重建立消息和所述第一MAC-I执行加密操作,生成第一PDCP PDU,所述第一PDCP PDU对应所述第一字节流,所述第一PDCP PDU包括加密后的所述RRC重建立消息和所述第一MAC-I。
  55. 根据权利要求53所述的装置,其中,所述处理模块,具体用于通过所述第一加密密钥对所述RRC重建立消息执行加密操作,生成所述第一字节流;并通过所述第一完整性保护密钥对所述RRC重建立消息执行完整性保护操作,生成第一信息,所述第一信息为通过对所述RRC重建立消息执行完整性保护操作生成的MAC-I;以及向所述基站的RRC层传递所述第一字节流和所述第一信息;
    其中,所述基站的MAC层生成的所述第一MAC CE中包括所述第一字节流、所述NCC和所述第一信息,所述第一信息为所述基站的RRC层传递给所述基站的MAC层的。
  56. 根据权利要求53所述的装置,其中,所述装置还包括:请求模块;
    所述请求模块,用于在所述传递模块将所述第一字节流和所述UE的UE上下文中保存的NCC传递给所述基站的MAC层之前,请求所述基站的PDCP层对所述NCC和所述第一字节流执行完整性保护操作;
    所述处理模块,还用于通过所述第一完整性保护密钥对所述NCC和所述第一字节流执行完整性保护操作,生成第二MAC-I,并将所述第二MAC-I传递给所述基站的RRC层;
    其中,所述基站的MAC层生成的所述第一MAC CE中包括所述第一字节流、所述NCC和所述第二MAC-I,所述第二MAC-I为所述基站的RRC层传递给所述基站的MAC层的。
  57. 根据权利要求53所述的装置,其中,所述装置还包括:请求模块;
    所述请求模块,用于在所述生成模块基于所述NCC和所述第一字节流生成所述第一MAC CE之前,请求所述基站的PDCP层对所述NCC和所述第一字节流执行完整性保护操作;
    所述处理模块,用于通过所述第一完整性保护密钥对所述NCC和所述第一字节流执行完整性保护,生成第三MAC-I,并将所述第三MAC-I传递给所述基站的MAC层;
    其中,所述基站的MAC层生成的所述第一MAC CE中包括所述第一字节流、所述NCC和所述第三MAC-I。
  58. 根据权利要求54至57任一项所述的装置,其中,所述基站的PDCP层执行加密操作和执行完整性保护操作所使用的参数为第一参数或第一参数集;
    其中,所述第一参数或所述第一参数集包括以下至少一项:COUNT值为0,BEARER为无线信令承载SRB1的承载标识,DIRECTION为下行方向。
  59. 根据权利要求58所述的装置,其中,所述处理模块,还用于将所述SRB1对应的PDCP实体维护的第二变量置为1或增加1,所述第二变量为对应下一个将发送的PDCP业务数据单元SDU的COUNT值的变量。
  60. 根据权利要求55至57任一项所述的装置,其中,所述基站的PDCP层执行加密操作和执行完整性保护操作所使用的参数为第二参数或第二参数集;
    其中,所述第二参数或所述第二参数集包括以下至少一项:COUNT值的所有比特为1、BEARER值的所有比特为1、DIRECTION为下行方向。
  61. 一种通信装置,所述装置包括:发送模块、接收模块、处理模块和指示模块;
    所述发送模块,用于向基站发送RRC重建立请求消息;
    所述接收模块,用于接收来自所述基站的第一信令,所述第一信令用于请求所述UE更新所述UE使用的密钥,所述第一信令包括NCC,所述第一信令为第二MAC CE或PDCP控制PDU;
    所述处理模块,用于基于所述NCC更新所述UE使用的密钥,并基于更新后的密钥生成第一加密密钥和第一完整性保护密钥;
    所述指示模块,用于指示所述UE的PDCP层使用所述处理模块生成的所述第一加密密钥和所述第一完整性保护密钥恢复完整性保护和加密;
    所述处理模块,还用于在所述UE的PDCP层使用所述第一加密密钥和所述第一完整性保护密钥恢复完整性保护和加密之后,处理来自所述基站的第二PDCP PDU,所述第二PDCP PDU中包括被完整性保护和加密的RRC重建立消息,所述RRC重建立消息用于指示所述UE重建立RRC连接。
  62. 根据权利要求61所述的装置,其中,所述第一信令包括第三信息,所述第三信息为对所述NCC执行完整性保护操作生成的MAC-I;所述指示模块,具体用于请求所述UE的PDCP层使用所述第一完整性保护密钥和所述第三信息对所述NCC执行完整性保护验证操作;并通过所述第一完整性保护密钥和所述第三信息对所述NCC执行完整性保护验证操作;以及在所述UE的PDCP层对所述NCC执行完整性保护验证操作通过的情况下,所述UE的RRC层指示所述UE的PDCP层使用所述第一加密密钥和所述第一完整性保护密钥恢复完整性保护和加密。
  63. 根据权利要求62所述的装置,其中,所述处理模块,还用于在所述UE的PDCP层对所述NCC执行完整性保护验证操作失败的情况下,进入空闲态。
  64. 根据权利要求62所述的装置,其中,所述UE的PDCP层对所述NCC执行完整性保护验证操作所使用的参数为第二参数或第二参数集;
    其中,所述第二参数或所述第二参数集包括以下至少一项:COUNT值的所有比特为1、BEARER值的所有比特为1、DIRECTION为下行方向。
  65. 根据权利要求61所述的装置,其中,在所述第一信令为第二MAC CE的情况下,所述接收模块,具体用于接收来自所述基站的所述第二MAC CE;并解析所述第二MAC CE,得到所述NCC,并将所述NCC递交给所述UE的RRC层。
  66. 根据权利要求61所述的装置,其中,在所述第一信令为PDCP控制PDU的情况下,所述接收模块,具体用于接收来自所述基站的PDCP控制PDU;并解析所述PDCP控制PDU,得到所述NCC,并将所述NCC递交给所述UE的RRC层。
  67. 根据权利要求61所述的装置,其中,所述处理模块,具体用于使用所述第一加密密钥和所述第一完整性保护密钥对所述第二PDCP PDU执行解密操作和完整性保护验证操作,并将解密后的所述RRC重建立消息递交给所述UE的RRC层。
  68. 根据权利要求67所述的装置,其中,所述处理模块,还用于基于解密后的所述RRC重建立消息重建立RRC连接;
    所述发送模块,还用于向所述基站发送所述RRC重建立完成消息,所述RRC重建立完成消息为所述UE的PDCP层通过所述第一加密密钥和所述第一完整性保护密钥处理后的消息。
  69. 一种通信装置,所述装置包括:接收模块和发送模块;
    所述接收模块,用于接收来自UE的RRC重建立请求消息;
    所述发送模块,用于向所述UE发送第一信令,所述第一信令用于请求所述UE更新所述UE使用的密钥,所述第一信令包括NCC,所述第一信令为第二MAC CE或PDCP控制PDU;并向所述UE发送第二PDCP PDU,所述第二PDCP PDU中包括被完整性保护和加密的RRC重建立消息,所述RRC重建立消息用于指示所述UE重建立RRC连接。
  70. 根据权利要求69所述的装置,其中,所述装置还包括:处理模块和指示模块;所述处理模块,用于在所述发送模块向所述UE发送第二PDCP PDU之前,更新所述基站使用的密钥,并基于更新后的密钥生成第一加密密钥和第一完整性保护密钥;
    所述指示模块,用于指示所述基站的PDCP层使用所述处理模块生成的所述第一加密密钥和所述第一完整性保护密钥恢复完整性保护和加密。
  71. 根据权利要求69所述的装置,其中,所述装置还包括:传递模块和生成模块;
    所述传递模块,用于将所述UE的UE上下文里保存的NCC传递给所述基站的MAC层;
    所述生成模块,用于基于所述传递模块传递的所述NCC生成所述第二MAC CE,所述第二MAC CE用于请求所述UE更新所述UE使用的密钥,所述第二MAC CE包括所述NCC;
    所述发送模块,具体用于向所述UE发送所述生成模块生成的所述第二MAC CE。
  72. 根据权利要求71所述的装置,其中,所述传递模块,具体用于请求所述基站的PDCP层通过所述第一完整性保护密钥对所述NCC执行完整性保护操作;并通过所述第一完整性保护密钥对所述NCC执行完整性保护操作,生成第四MAC-I,并传递给所述基站的RRC层;以及将所述NCC和所述第四MAC-I传递给所述基站的MAC层;
    其中,所述第二MAC CE包括所述NCC和所述第四MAC-I。
  73. 根据权利要求71所述的装置,其中,所述生成模块,具体用于请求所述基站的PDCP层通过所述第一完整性保护密钥对所述NCC执行完整性保护操作;并通过所述第一完整性保护密钥对所述NCC执行完整性保护操作,生成第五MAC-I,并传递给所述基站的MAC层;以及基于所述NCC和所述第五MAC-I生成所述第二MAC CE,所述第二MAC CE包括所述NCC和所述第五MAC-I。
  74. 根据权利要求69所述的装置,其中,所述装置还包括:传递模块和生成模块;
    所述传递模块,用于将所述UE的UE上下文里保存的NCC传递给所述基站的PDCP层;
    所述生成模块,用于基于所述传递模块传递的所述NCC生成所述PDCP控制PDU,所述PDCP控制PDU用于请求所述UE更新所述UE使用的密钥,所述PDCP控制PDU包括所述NCC;
    所述发送模块,具体用于向所述UE发送所述生成模块生成的所述PDCP控制PDU。
  75. 根据权利要求74所述的装置,其中,所述生成模块,具体用于通过所述第一完整性保护密钥对所述NCC执行完整性保护操作,生成第六MAC-I;并基于所述NCC和所述第六MAC-I生成所述PDCP控制PDU,所述PDCP控制PDU包括所述第六MAC-I。
  76. 根据权利要求72或73或75所述的装置,其中,所述基站的PDCP层对所述NCC执行完整性保护操作所使用的参数为第二参数或第二参数集;
    其中,所述第二参数或所述第二参数集包括以下至少一项:COUNT值的所有比特为1、BEARER值的所有比特为1、DIRECTION为下行方向。
  77. 根据权利要求70所述的装置,其中,所述发送模块,具体用于生成所述RRC重建立消息,并传递给所述基站的PDCP层;并通过所述第一加密密钥和所述第一完整性保护密钥对所述RRC重建立消息执行加密操作和完整性保护操作,生成所述第二PDCP PDU;并将所述第二PDCP PDU传递给所述基站的无线链路控制RLC层;以及向所述UE发送所述第二PDCP PDU。
  78. 根据权利要求70至77任一项所述的装置,其中,所述发送模块,具体用在所述第一信令被发送后,或在所述第一信令被成功发送后,或在所述基站接收到所述第一信令的接收确认消息后,向所述UE发送所述第二PDCP PDU。
  79. 一种用户设备,包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如权利要求1至11任一项所述的通信方法的步骤。
  80. 一种用户设备,包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如权利要求22至29任一项所述的通信方法的步骤。
  81. 一种基站,包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如权利要求12至21任一项所述的通信方法的步骤。
  82. 一种基站,包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如权利要求30至39任一项所述的通信方法的步骤。
  83. 一种可读存储介质,所述可读存储介质上存储程序或指令,所述程序或指令被处理器执行时实现如权利要求1至11任一项所述的通信方法的步骤,或者实现如权利要求12至21任一项所述的通信方法的步骤,或者实现如权利要求22至29任一项所述的通信方法的步骤,或者实现如权利要求30至39任一项所述的通信方法的步骤。
PCT/CN2025/071569 2024-01-12 2025-01-09 通信方法、装置、用户设备、基站及存储介质 Pending WO2025148993A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202410052512.6 2024-01-12
CN202410052512.6A CN120321812A (zh) 2024-01-12 2024-01-12 通信方法、装置、用户设备、基站及存储介质

Publications (1)

Publication Number Publication Date
WO2025148993A1 true WO2025148993A1 (zh) 2025-07-17

Family

ID=96334275

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2025/071569 Pending WO2025148993A1 (zh) 2024-01-12 2025-01-09 通信方法、装置、用户设备、基站及存储介质

Country Status (2)

Country Link
CN (1) CN120321812A (zh)
WO (1) WO2025148993A1 (zh)

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109802809A (zh) * 2017-11-17 2019-05-24 华为技术有限公司 网络接入的方法、终端设备和网络设备
CN110831255A (zh) * 2018-08-09 2020-02-21 电信科学技术研究院有限公司 重建rrc连接的方法、基站、移动终端及存储介质
CN110830988A (zh) * 2018-08-08 2020-02-21 维沃移动通信有限公司 一种安全更新方法、网络设备及终端

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109802809A (zh) * 2017-11-17 2019-05-24 华为技术有限公司 网络接入的方法、终端设备和网络设备
CN110830988A (zh) * 2018-08-08 2020-02-21 维沃移动通信有限公司 一种安全更新方法、网络设备及终端
CN110831255A (zh) * 2018-08-09 2020-02-21 电信科学技术研究院有限公司 重建rrc连接的方法、基站、移动终端及存储介质

Non-Patent Citations (2)

* Cited by examiner, † Cited by third party
Title
LG ELECTRONICS INC.: "Consideration on security aspect for inactive UEs", 3GPP DRAFT; R2-1711147_CONSIDERATION ON SECURITY ASPECT FOR INACTIVE UES_V2, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, vol. RAN WG2, no. Prague, Czech; 20171009 - 20171013, 29 September 2017 (2017-09-29), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France , XP051355422 *
SAMSUNG [TO BE REPLACED BY RAN2]: "[DRAFT] LS on Xn support for connection re-establishment", 3GPP DRAFT; R2-1810165 LS ON XN SUPPORT FOR REESTABLISHMENT, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, vol. RAN WG2, no. Montreal, Canada; 20180702 - 20180706, 22 June 2018 (2018-06-22), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France , XP051525970 *

Also Published As

Publication number Publication date
CN120321812A (zh) 2025-07-15

Similar Documents

Publication Publication Date Title
US20250016253A1 (en) Data transmission method of communication system, terminal, and network-side device
US20250344065A1 (en) Message transmission method and apparatus, and device
US12538182B2 (en) Method for splitting end-to-end QoS requirement information, terminal, and network side device
US12513770B2 (en) Access procedure processing method based on matching between transmission data and first condition, apparatus and communication device
EP4216625A1 (en) Paging method and apparatus, terminal, network device and readable storage medium
US20240064853A1 (en) Rrc connection maintenance method, related device, and readable storage medium
US20230328532A1 (en) Communication method and apparatus for trusted or untrusted relay, terminal, and network side device
US12425849B2 (en) Method and apparatus for obtaining key, user equipment, and network side device
WO2025148993A1 (zh) 通信方法、装置、用户设备、基站及存储介质
US20230095930A1 (en) Method and apparatus for processing downlink data, and terminal
US20230189061A1 (en) Data transmission processing method and apparatus, and device
US9237441B2 (en) Method and apparatus for configuring signaling radio bearer in a wireless communications system
EP4664958A1 (en) Data processing method and apparatus, network side device and terminal device
US20260081929A1 (en) Communication Method, Communication Apparatus, and Electronic Device
CN115706996B (zh) 安全策略更新系统及方法、存储介质与电子设备
WO2025039905A1 (zh) 传输处理方法、装置、终端及网络侧设备
WO2026077427A1 (zh) 无线通信方法、终端及网络侧设备
WO2024235040A1 (zh) 副链路数据传输方法、设备及可读存储介质
CN121728523A (zh) 数据传输方法、装置、终端、网络侧设备及可读存储介质
WO2025124383A1 (zh) 通信方法、装置、用户设备、基站及存储介质
WO2025167908A1 (zh) 同步状态信息的传输方法、终端及网络侧设备
WO2023030329A1 (zh) 数据传输方法和设备
CN120128917A (zh) 交互方法、装置、系统、终端及网络侧设备
CN113905457A (zh) 消息发送方法、接收方法、装置及通信设备

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 25738521

Country of ref document: EP

Kind code of ref document: A1