WO2026007409A1 - 通信方法、第一网络设备、终端、通信系统和存储介质 - Google Patents

通信方法、第一网络设备、终端、通信系统和存储介质

Info

Publication number
WO2026007409A1
WO2026007409A1 PCT/CN2025/076735 CN2025076735W WO2026007409A1 WO 2026007409 A1 WO2026007409 A1 WO 2026007409A1 CN 2025076735 W CN2025076735 W CN 2025076735W WO 2026007409 A1 WO2026007409 A1 WO 2026007409A1
Authority
WO
WIPO (PCT)
Prior art keywords
information
terminal
network device
indicator
identifier
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
PCT/CN2025/076735
Other languages
English (en)
French (fr)
Inventor
陆伟
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Beijing Xiaomi Mobile Software Co Ltd
Original Assignee
Beijing Xiaomi Mobile Software Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Beijing Xiaomi Mobile Software Co Ltd filed Critical Beijing Xiaomi Mobile Software Co Ltd
Priority to CN202580001453.2A priority Critical patent/CN121220116A/zh
Publication of WO2026007409A1 publication Critical patent/WO2026007409A1/zh
Pending legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W36/00Hand-off or reselection arrangements
    • H04W36/08Reselecting an access point

Definitions

  • This disclosure relates to the field of communication technology, and in particular to a communication method, a first network device, a terminal, a communication system, and a storage medium.
  • the data transmitted through the interface established between the terminal and the base station may be unprotected due to the fact that some protocol layers do not support security-related calculations. This could lead to the data being tampered with and pose security risks.
  • This disclosure provides a communication method, a first network device, a terminal, a communication system, and a storage medium.
  • a communication method is provided, the method being performed by a first network device, the method comprising: sending first information to a terminal; wherein the first information includes: second information and third information; the second information is information confirmed by a second network device; the third information is information generated based on the second information and the fourth information; the third information and the fourth information are used to verify the second information; the fourth information is information associated with a first identifier; the first identifier is an identifier assigned to the terminal; the first network device is a serving network device of the terminal, and the second network device is a candidate network device for the terminal to perform a handover.
  • a communication method comprising: receiving first information sent by a first network device; wherein the first information includes: second information and third information; the second information is information confirmed by a second network device; the third information is information generated based on the second information and fourth information; the third information and fourth information are used to verify the second information; the fourth information is information associated with a first identifier; the first identifier is an identifier assigned to the terminal; the first network device is a serving network device of the terminal, and the second network device is a candidate network device for the terminal to perform a handover.
  • a communication method further comprising: a first network device sending first information to a terminal; wherein the first information includes: second information and third information; the second information is information confirmed by a second network device; the third information is information generated based on the second information and the fourth information; the third information and the fourth information are used to verify the second information; the fourth information is information associated with a first identifier; the first identifier is an identifier assigned to the terminal; the first network device is a serving network device of the terminal, and the second network device is a candidate network device for the terminal to perform a handover.
  • a first network device comprising: a transceiver module configured to: send first information to a terminal; wherein the first information includes: second information and third information; the second information is information confirmed by a second network device; the third information is information generated based on the second information and the fourth information; the third information and the fourth information are used to verify the second information; the fourth information is information associated with a first identifier; the first identifier is an identifier assigned to the terminal; the first network device is a serving network device for the terminal, and the second network device is a candidate network device for the terminal to perform a handover.
  • a terminal comprising: a transceiver module configured to: receive first information sent by a first network device; wherein the first information includes: second information and third information; the second information is information confirmed by a second network device; the third information is information generated based on the second information and the fourth information; the third information and the fourth information are used to verify the second information; the fourth information is information associated with a first identifier; the first identifier is an identifier assigned to the terminal; the first network device is a serving network device of the terminal, and the second network device is a candidate network device for the terminal to perform a handover.
  • a communication system including a first network device and a terminal, wherein the first network device is configured to perform the communication method of the first aspect; and the terminal is configured to perform the communication method of the second aspect.
  • a first network device comprising: one or more processors; wherein the first network device is configured to perform the communication method of the first aspect.
  • a terminal comprising: one or more processors; wherein the terminal is configured to perform the communication method of the second aspect.
  • a storage medium stores instructions that, when executed on a communication device, cause the communication device to perform the communication method provided in the first aspect and/or the second aspect.
  • a communication method is provided, the method being executed by a first network device, the method comprising: sending first information to a terminal; wherein the first information includes: second information and third information; the second information is information related to communication protection between the terminal and a second network device; the third information is used to verify the second information; the first network device is a serving network device of the terminal, and the second network device is a candidate network device for the terminal to perform a handover.
  • a communication method which is executed by a terminal.
  • the method includes: receiving first information sent by a first network device; wherein the first information includes: second information and third information; the second information is information related to communication protection between the terminal and the second network device; the third information is used to verify the second information; the first network device is a serving network device of the terminal, and the second network device is a candidate network device for the terminal to perform a handover.
  • a first network device comprising: a transceiver module configured to: send first information to a terminal; wherein the first information includes: second information and third information; the second information is information related to communication protection between the terminal and a second network device; the third information is used to verify the second information; the first network device is a serving network device of the terminal, and the second network device is a candidate network device for the terminal to perform a handover.
  • a terminal comprising: a transceiver module configured to: receive first information sent by a first network device; wherein the first information includes: second information and third information; the second information is information related to communication protection between the terminal and the second network device; the third information is used to verify the second information; the first network device is a serving network device of the terminal, and the second network device is a candidate network device for the terminal to perform a handover.
  • a communication system including a first network device and a terminal, wherein the first network device is configured to perform the communication method of the tenth aspect, and the terminal is configured to perform the communication method of the eleventh aspect.
  • a first network device comprising: one or more processors; wherein the first network device is configured to perform the communication method of the tenth aspect.
  • a terminal comprising: one or more processors; wherein the terminal is configured to execute the communication method of the eleventh aspect.
  • a storage medium stores instructions that, when executed on a communication device, cause the communication device to perform the communication method provided in the tenth and/or eleventh aspects.
  • a computer program product including a computer program that, when executed by a processor, implements the communication methods of the tenth and/or eleventh aspects.
  • a computer program includes code, which, when executed by a processor, implements the communication methods of the tenth and/or eleventh aspects.
  • a chip or chip system including processing circuitry configured to perform the communication methods as described in the tenth and/or eleventh aspects.
  • the communication mechanism of the technical solution provided in this disclosure can protect the data transmitted between network devices and terminals.
  • Figure 1a is a schematic diagram of the architecture of a communication system according to an exemplary embodiment
  • Figure 1b is a schematic diagram illustrating a communication method according to an exemplary embodiment
  • Figure 1c is a schematic diagram illustrating a security process according to an exemplary embodiment
  • Figure 1d is a schematic diagram illustrating a MAC CE signaling according to an exemplary embodiment
  • Figure 1e is a schematic diagram illustrating a communication method according to an exemplary embodiment
  • Figure 1f is a schematic diagram illustrating a communication method according to an exemplary embodiment
  • Figure 2a is a flowchart illustrating a communication method according to an exemplary embodiment
  • Figure 3a is a flowchart illustrating a communication method according to an exemplary embodiment
  • Figure 3b is a flowchart illustrating a communication method according to an exemplary embodiment
  • Figure 4a is a flowchart illustrating a communication method according to an exemplary embodiment
  • Figure 7a is a schematic diagram of the structure of a first network device according to an exemplary embodiment
  • Figure 7b is a schematic diagram of the structure of a terminal according to an exemplary embodiment
  • Figure 8a is a schematic diagram of the structure of a UE according to an exemplary embodiment
  • Figure 8b is a schematic diagram of the structure of a communication device according to an exemplary embodiment.
  • This disclosure provides a communication method, a first network device, a terminal, a communication system, and a storage medium.
  • embodiments of this disclosure provide a communication method, performed by a first network device, the method comprising: sending first information to a terminal; wherein the first information includes: second information and third information; the second information is information confirmed by a second network device; the third information is information generated based on the second information and the fourth information; the third information and the fourth information are used to verify the second information; the fourth information is information associated with a first identifier; the first identifier is an identifier assigned to the terminal; the first network device is a serving network device of the terminal, and the second network device is a candidate network device for the terminal to perform a handover.
  • the first identifier is a terminal identifier assigned by the initial network device to the serving network device during a mobility LTM process triggered by Layer 1L1 or Layer 2L2.
  • the initial access device during the LTM process can assign a terminal identifier to the first network device.
  • sending first information to the terminal includes: sending a first Media Access Control (MAC) Control Element (CE) message to the terminal; wherein the first MAC CE message contains the first information.
  • MAC Media Access Control
  • CE Control Element
  • first information can be sent to the terminal through the first MAC CE message, and the MAC CE message can be reused to reduce signaling overhead.
  • sending first information to the terminal includes: sending first information to the terminal during the LTM process between the terminal and the first network device.
  • the terminal and the first network device can reuse the LTM process between the base station to send the first information to the terminal.
  • sending first information to the terminal includes at least one of the following: sending first information to the terminal during the initial LTM process between the terminal and the first network device; and sending first information to the terminal during the subsequent LTM process between the terminal and the first network device.
  • the first information can be sent to the terminal during the initial base station LTM process between the terminal and the first network device or during the subsequent base station LTM process between the terminal and the first network device, making the sending method more flexible.
  • the method further includes: determining second information; sending the second information to a second network device; and receiving the confirmed second information sent by the second network device.
  • the second network device after determining the second information, it is sent to the second network device for confirmation, so that the second information is the second information confirmed by the second network device.
  • third information can be generated based on the second information and the fourth information.
  • the terminal after receiving the first information, the terminal can verify the second information based on the third information and the fourth information.
  • the second information is the first next-step counter parameter NCC; generating the third information based on the second information and the fourth information includes: encoding the first NCC using the fourth information to obtain the third information.
  • the first NCC can be encoded based on the fourth information to obtain the encoded third information.
  • the first NCC is encoded using fourth information to obtain third information, including: performing an XOR operation between the fourth information and the first NCC to obtain the third information.
  • the first NCC can be encoded by performing an XOR operation between the fourth information and the first NCC to obtain the encoded third information.
  • the method further includes: performing a hash process on the first identifier to obtain fourth information.
  • the fourth information can be obtained by performing a hash process on the first identifier.
  • the first identifier is at least one of the following: a Cell Radio Network Temporary Identifier (C-RNTI) assigned to the terminal; an LTM-specific identifier assigned to the terminal; or a random number assigned to the terminal.
  • C-RNTI Cell Radio Network Temporary Identifier
  • the selection of the first identifier can be more flexible.
  • embodiments of this disclosure provide a communication method executed by a terminal.
  • the method includes: receiving first information sent by a first network device; wherein the first information includes: second information and third information; the second information is information confirmed by a second network device; the third information is information generated based on the second information and fourth information; the third information and fourth information are used to verify the second information; the fourth information is information associated with a first identifier; the first identifier is an identifier assigned to the terminal; the first network device is a serving network device of the terminal, and the second network device is a candidate network device for the terminal to perform a handover.
  • the first identifier is the terminal identifier assigned by the initial network device to the serving network device during the LTM process.
  • receiving the first information sent by the first network device includes: receiving the first MAC CE message sent by the first network device; wherein the first MAC CE message contains the first information.
  • receiving the first information sent by the first network device includes: receiving the first information sent by the first network device during the LTM process between the terminal and the first network device.
  • receiving first information sent by the first network device during the LTM process between the terminal and the first network device includes: receiving first information sent by the first network device during the initial LTM process between the terminal and the first network device; and receiving first information sent by the first network device during the subsequent LTM process between the terminal and the first network device.
  • the second information is the first next-hop counter parameter NCC
  • the third information is security information obtained by encoding the first NCC using the fourth information.
  • the third information is security information obtained after performing an XOR operation between the first NCC and the fourth information.
  • the fourth information is information obtained by performing a hash process on the first identifier.
  • the first identifier is at least one of the following: a Cell Radio Network Temporary Identifier (C-RNTI) assigned to the terminal; an LTM-specific identifier assigned to the terminal; or a random number assigned to the terminal.
  • C-RNTI Cell Radio Network Temporary Identifier
  • the method further includes: verifying the second information based on the second information, the third information, and the fourth information; wherein the first network device and the terminal share the fourth information.
  • verifying the second information based on the second information, the third information, and the fourth information includes: decoding the third information based on the fourth information to obtain the fifth information; and determining whether the second information passes verification based on the comparison result of the second information and the fifth information.
  • the second information based on the comparison result of the second information and the fifth information, it is determined whether the second information passes the verification, including at least one of the following: determining that the second information is the same as the fifth information, and determining that the second information passes the verification; determining that the second information is different from the fifth information, and determining that the second information fails the verification.
  • verifying the second information based on the second information, the third information, and the fourth information includes: encoding the second information based on the fourth information to obtain the sixth information; and determining whether the second information passes the verification based on the comparison result of the third information and the sixth information.
  • determining whether the second information passes verification based on the comparison result of the third information and the sixth information includes: determining that the second information passes verification if the third information is the same as the sixth information; or determining that the second information fails verification if the third information is different from the sixth information.
  • the method further includes: performing a hash process on the first identifier to obtain third information.
  • embodiments of this disclosure provide a communication method, which further includes: a first network device sending first information to a terminal; wherein the first information includes: second information and third information; the second information is information confirmed by a second network device; the third information is information generated based on the second information and the fourth information; the third information and the fourth information are used to verify the second information; the fourth information is information associated with a first identifier; the first identifier is an identifier assigned to the terminal; the first network device is a serving network device of the terminal, and the second network device is a candidate network device for the terminal to perform a handover.
  • embodiments of this disclosure provide a first network device, the first network device comprising: a transceiver module configured to: send first information to a terminal; wherein the first information includes: second information and third information; the second information is information confirmed by a second network device; the third information is information generated based on the second information and the fourth information; the third information and the fourth information are used to verify the second information; the fourth information is information associated with a first identifier; the first identifier is an identifier assigned to the terminal; the first network device is a serving network device for the terminal, and the second network device is a candidate network device for the terminal to perform a handover.
  • the first information includes: second information and third information
  • the second information is information confirmed by a second network device
  • the third information is information generated based on the second information and the fourth information
  • the third information and the fourth information are used to verify the second information
  • the fourth information is information associated with a first identifier
  • the first identifier is an identifier assigned to the terminal
  • a terminal including: a transceiver module configured to: receive first information sent by a first network device; wherein the first information includes: second information and third information; the second information is information confirmed by a second network device; the third information is information generated based on the second information and the fourth information; the third information and the fourth information are used to verify the second information; the fourth information is information associated with a first identifier; the first identifier is an identifier assigned to the terminal; the first network device is a serving network device of the terminal, and the second network device is a candidate network device for the terminal to perform a handover.
  • the first information includes: second information and third information
  • the second information is information confirmed by a second network device
  • the third information is information generated based on the second information and the fourth information
  • the third information and the fourth information are used to verify the second information
  • the fourth information is information associated with a first identifier
  • the first identifier is an identifier assigned to the terminal
  • the first network device is a serving network device of the terminal
  • embodiments of this disclosure provide a communication system, which includes a first network device and a terminal, wherein the first network device is configured to perform the communication method of the first aspect; and the terminal is configured to perform the communication method of the second aspect.
  • embodiments of this disclosure provide a first network device, the first network device comprising: one or more processors; wherein the first network device is configured to perform the communication method of the first aspect.
  • embodiments of this disclosure provide a terminal, the terminal including: one or more processors; wherein the terminal is used to execute the communication method of the second aspect.
  • embodiments of this disclosure provide a storage medium storing instructions that, when executed on a communication device, cause the communication device to perform the communication method described in the optional implementations of the first and/or second aspects.
  • embodiments of this disclosure provide a program product that, when executed by a communication device, causes the communication device to perform the method as described in the optional implementations of the first and/or second aspects.
  • embodiments of this disclosure provide a computer program that, when run on a computer, causes the computer to perform the methods described in optional implementations of the first and/or second aspects.
  • embodiments of this disclosure provide a chip or chip system.
  • the chip or chip system includes processing circuitry configured to perform the methods described according to optional implementations of the first and/or second aspects above.
  • embodiments of this disclosure provide a communication method executed by a first network device, the method comprising: sending first information to a terminal; wherein the first information includes: second information and third information; the second information is information related to communication protection between the terminal and the second network device; the third information is used to verify the second information; the first network device is a serving network device of the terminal, and the second network device is a candidate network device for the terminal to perform a handover.
  • the third information is information generated at least based on the second information and the fourth information, the fourth information being used to protect the second information, the fourth information being information associated with the first identifier, and the first identifier being an identifier assigned to the terminal.
  • the first identifier is a terminal identifier assigned by the initial network device to the serving network device during a mobility LTM process triggered by layer 1L1 or layer 2L2.
  • the method further includes: determining second information; sending the second information to a second network device; and receiving the confirmed second information sent by the second network device.
  • the first information further includes a first indicator, which is used to indicate to the terminal whether to generate a first key based on the second information, and the first key is used for the terminal to communicate with the second network device.
  • the method further includes one of the following: generating third information based on second information and fourth information; generating third information based on second information, fourth information and a first indicator; generating third information based on second information, fourth information, first indicator and first time information, wherein the first time information is the current time at which the first network device generates the third information; wherein the fourth information is information associated with a first identifier, and the first identifier is an identifier assigned to the terminal.
  • the second information is the first next-step counter parameter NCC; the method further includes one of the following: encoding the first NCC using fourth information to obtain third information; encoding the first indicator and the first NCC using the fourth information to obtain third information; encoding the first indicator and the first NCC using the fourth information and first time information to obtain third information.
  • the method further includes one of the following: performing an XOR operation on the fourth information and the first NCC to obtain the third information; hashing the first XOR value to obtain the third information; the first XOR value is obtained after an XOR operation on the fourth information and the first NCC; performing an XOR operation on the fourth information, the first NCC, and the first indicator to obtain the third information; hashing the second XOR value to obtain the third information; the second XOR value is obtained after an XOR operation on the fourth information, the first indicator, and the first NCC; performing an XOR operation on the fourth information, the first NCC, the first indicator, and the first time information to obtain the third information; hashing the third XOR value to obtain the third information; the third XOR value is obtained after an XOR operation on the fourth information, the first indicator, the first NCC, and the first time information.
  • the fourth information is obtained by the first network device after hashing the first identifier, or the fourth information is the first identifier.
  • sending first information to the terminal includes: sending a first Media Access Control (MAC) Control Element (CE) message to the terminal; wherein the first MAC CE message contains the first information.
  • MAC Media Access Control
  • CE Control Element
  • sending first information to the terminal includes: sending first information to the terminal during the LTM process between the terminal and the first network device.
  • the first information is sent to the terminal, including at least one of the following: during the process of the terminal and the first network device performing initial inter-base station LTM, the first information is sent to the terminal; during the process of the terminal and the first network device performing subsequent inter-base station LTM, the first information is sent to the terminal.
  • the first identifier is at least one of the following: a Cell Radio Network Temporary Identifier (C-RNTI) assigned to the terminal; an LTM-specific identifier assigned to the terminal; or a random number assigned to the terminal.
  • C-RNTI Cell Radio Network Temporary Identifier
  • embodiments of this disclosure provide a communication method executed by a terminal.
  • the method includes: receiving first information sent by a first network device; wherein the first information includes: second information and third information; the second information is information related to communication protection between the terminal and the second network device; the third information is used to verify the second information; the first network device is a serving network device of the terminal, and the second network device is a candidate network device for the terminal to perform a handover.
  • the first identifier is a terminal identifier assigned by the initial network device to the serving network device during the LTM process.
  • the first information further includes a first indicator, which is used to indicate to the terminal whether to generate a first key based on the second information, and the first key is used by the terminal to communicate with the second network device.
  • the third information is generated based on the second information and the fourth information; or, the third information is generated based on the second information, the fourth information and the first indicator; or, the third information is generated based on the second information, the fourth information, the first indicator and the first time information, wherein the first time information is the current time when the first network device generates the third information; wherein, the fourth information is information associated with the first identifier, and the first identifier is an identifier assigned to the terminal.
  • the second information is the first next-step counter parameter NCC
  • the third information is security information obtained by encoding the first NCC using the fourth information, or, the third information is security information obtained by encoding the first indicator and the first NCC using the fourth information; the third information is security information obtained by encoding the first indicator and the first NCC using the fourth information and the first time information.
  • the third information is security information obtained after performing an XOR operation between the first NCC and the fourth information; or, the third information is security information obtained after hashing the first XOR value, where the first XOR value is obtained after performing an XOR operation between the fourth information and the first NCC; or, the third information is security information obtained after performing an XOR operation between the fourth information, the first NCC, and the first indicator; or, the third information is security information obtained after hashing the second XOR value, where the second XOR value is obtained after performing an XOR operation between the fourth information, the first NCC, and the first indicator; or, the third information is security information obtained after performing an XOR operation between the fourth information, the first NCC, the first indicator, and the first time information; or, the third information is security information obtained after hashing the third XOR value, where the third XOR value is obtained after performing an XOR operation between the fourth information, the first NCC, the first indicator,
  • the fourth information is information obtained by the first network device performing a hash process on the first identifier, or the fourth information is the first identifier.
  • the method further includes one of the following: verifying the second information based on the second information, the third information, and the seventh information; verifying the second information based on the second information, the third information, the seventh information, and the first indicator; verifying the second information based on the second information, the third information, the seventh information, the first indicator, and the second time information; wherein the seventh information is associated with the first identifier, and the second time information is the current time when the terminal verifies the second information.
  • the method further includes one of the following: decoding the third information based on the seventh information to obtain the fifth information; decoding the third information based on the seventh information and the first indicator to obtain the fifth information; decoding the third information based on the seventh information, the first indicator, and the second time information to obtain the fifth information; wherein the fifth information is used to verify the second information.
  • the method further includes: determining whether the second information passes verification based on a comparison result between the second information and the fifth information.
  • the second information passes the verification, including at least one of the following: determining that the second information is the same as the fifth information, and determining that the second information passes the verification; determining that the second information is different from the fifth information, and determining that the second information fails the verification.
  • the method further includes one of the following: encoding the second information based on the seventh information to obtain the sixth information; encoding the second information and the first indicator based on the seventh information to obtain the sixth information; encoding the second information and the first indicator based on the seventh information and the second time information to obtain the sixth information; wherein the sixth information is used to verify the second information.
  • the method further includes one of the following: performing an XOR operation on the seventh information and the second information to obtain the sixth information; hashing the fourth XOR value to obtain the sixth information, wherein the fourth XOR value is obtained after the XOR operation on the seventh information and the second information; performing an XOR operation on the seventh information, the second information, and the first indicator to obtain the sixth information; hashing the fifth XOR value to obtain the sixth information, wherein the fifth XOR value is obtained after the XOR operation on the seventh information, the second information, and the first indicator; performing an XOR operation on the seventh information, the second information, the first indicator, and the second time information to obtain the sixth information; hashing the sixth XOR value to obtain the sixth information, wherein the sixth XOR value is obtained after the XOR operation on the seventh information, the second information, the first indicator, and the second time information.
  • the method further includes: determining whether the second information passes verification based on a comparison result between the third information and the sixth information.
  • determining whether the second information passes verification based on the comparison result of the third information and the sixth information includes: determining that the second information passes verification if the third information is the same as the sixth information; or determining that the second information fails verification if the third information is different from the sixth information.
  • the seventh information is obtained by the terminal after hashing the first identifier, or the seventh information is the first identifier.
  • the value of the second time information is equal to the value of the first time information, or the value of the second time information is equal to the value of the first time information plus a first offset value.
  • receiving first information sent by a first network device includes: receiving a first MAC CE message sent by the first network device; wherein the first MAC CE message contains first information.
  • receiving first information sent by the first network device includes: receiving first information sent by the first network device during the LTM process between the terminal and the first network device.
  • receiving first information sent by the first network device includes: receiving first information sent by the first network device during the initial inter-base station LTM process between the terminal and the first network device; and receiving first information sent by the first network device during the subsequent inter-base station LTM process between the terminal and the first network device.
  • the first identifier is at least one of the following: a Cell Radio Network Temporary Identifier (C-RNTI) assigned to the terminal; an LTM-specific identifier assigned to the terminal; or a random number assigned to the terminal.
  • C-RNTI Cell Radio Network Temporary Identifier
  • a communication system including a first network device and a terminal, the first network device being configured to perform the communication method of the thirteenth aspect, and the terminal being configured to perform the communication method of the fourteenth aspect.
  • a first network device comprising: one or more processors; wherein the first network device is configured to perform the communication method of the thirteenth aspect.
  • a terminal comprising: one or more processors; wherein the terminal is used to execute the communication method of the fourteenth aspect.
  • a storage medium stores instructions that, when executed on a communication device, cause the communication device to perform the communication method provided in the thirteenth and/or fourteenth aspects.
  • a computer program product comprising a computer program that, when executed by a processor, implements the communication methods of the thirteenth and/or fourteenth aspects.
  • a computer program which includes code that, when executed by a processor, implements the communication methods of the thirteenth and/or fourteenth aspects.
  • a chip or chip system including processing circuitry configured to perform the communication methods of the thirteenth and/or fourteenth aspects.
  • This disclosure provides a communication method.
  • the terms “communication method” and “information indication method,” “information processing method,” and “information transmission method” can be used interchangeably, as can the terms “communication system” and “information processing system.”
  • each step in a particular embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined.
  • a solution after removing some steps in a particular embodiment can also be implemented as an independent embodiment, and the order of the steps in a particular embodiment can be arbitrarily interchanged.
  • the optional implementation methods in a particular embodiment can be arbitrarily combined; moreover, the embodiments can be arbitrarily combined, for example, some or all steps of different embodiments can be arbitrarily combined, and a particular embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.
  • multiple refers to two or more.
  • the notation "at least one of A and B", “A and/or B", “A in one case, B in another”, “in response to one case A, in response to another case B”, etc. may include the following technical solutions depending on the situation: in some embodiments, A (execute A regardless of B); in some embodiments, B (execute B regardless of A); in some embodiments, execution is selected from A and B (A and B are selectively executed); in some embodiments, A and B (both A and B are executed). The same applies when there are more branches such as A, B, C, etc.
  • the notation "A or B” may include the following technical solutions, depending on the situation: in some embodiments, A (execution of A regardless of B); in some embodiments, B (execution of B regardless of A); in some embodiments, execution is selected from A and B (A and B are selectively executed). The same applies when there are more branches such as A, B, C, etc.
  • the descriptive object is a "field,” the ordinal numbers preceding "field” in “first field” and “second field” do not restrict the position or order of the "fields.” "First” and “second” do not restrict whether the "fields” they modify are in the same message, nor do they restrict the order of "first field” and “second field.”
  • the descriptive object is a "level,” the ordinal numbers preceding "level” in “first level” and “second level” do not restrict the priority between “levels.”
  • the number of descriptive objects is not limited by ordinal numbers and can be one or more. For example, in “first device,” the number of "devices" can be one or more.
  • the objects modified by different prefixes can be the same or different.
  • first device and second device can be the same device or different devices, and their types can be the same or different.
  • first information and second information can be the same information or different information, and their content can be the same or different.
  • “including A,” “containing A,” “for indicating A,” and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.
  • time/frequency and time-frequency domain refer to the time domain and/or frequency domain.
  • the terms “in response to...”, “in response to determining...”, “in the case of...”, “when...”, “if...”, “if...”, etc., can be used interchangeably.
  • the terms “greater than,” “greater than or equal to,” “not less than,” “more than,” “more than or equal to,” “not less than,” “higher than,” “higher than or equal to,” “not lower than,” and “above” can be used interchangeably, as can the terms “less than,” “less than or equal to,” “not greater than,” “less than,” “less than or equal to,” “not more than,” “lower than,” “lower than or equal to,” “not higher than,” and “below”.
  • devices, etc. can be interpreted as physical or virtual, and their names are not limited to the names recorded in the embodiments.
  • Terms such as “device”, “equipment”, “circuit”, “network element”, “node”, “function”, “unit”, “section”, “system”, “network”, “chip”, “chip system”, “entity”, and “subject” can be used interchangeably.
  • network can be interpreted as devices included in a network (e.g., access network devices, core network devices, etc.).
  • the terms “access network device (AN device),” “radio access network device (RAN device),” “base station (BS),” “radio base station,” “fixed station,” “node,” “access point,” “transmission point (TP),” “reception point (RP),” “transmission/reception point (TRP),” “panel,” “antenna panel,” “antenna array,” “cell,” “macro cell,” “small cell,” “femto cell,” “pico cell,” “sector,” “cell group,” “serving cell,” “carrier,” “component carrier,” and “bandwidth part (BWP)” can be used interchangeably.
  • terminal In some embodiments, the terms "terminal”, “terminal device”, “user equipment (UE)”, “user terminal”, “mobile station (MS)”, “mobile terminal (MT)", “subscriber station”, “mobile unit”, “subscriber unit”, “wireless unit”, “remote unit”, “mobile device”, “wireless device”, “wireless communication device”, “remote device”, “mobile subscriber station”, “access terminal”, “mobile terminal”, “wireless terminal”, “remote terminal”, “handset”, “user agent”, “mobile client”, and “client” can be used interchangeably.
  • access network devices, core network devices, or network devices can be replaced by terminals.
  • embodiments of this disclosure can also be applied to structures where communication between access network devices, core network devices, or network devices and terminals is replaced by communication between multiple terminals (e.g., device-to-device (D2D), vehicle-to-everything (V2X), etc.).
  • the structure can also be configured such that the terminal has all or part of the functions of the access network device.
  • terms such as "uplink” and “downlink” can be replaced with terms corresponding to communication between terminals (e.g., "sidelink”).
  • uplink channel, downlink channel, etc. can be replaced with sidelink channel
  • uplink link, downlink, etc. can be replaced with sidelink link.
  • the terminal may be replaced by an access network device, a core network device, or a network device.
  • the access network device, core network device, or network device may also be configured to have all or some of the functions of the terminal.
  • the acquisition of data, information, etc. may comply with the laws and regulations of the country where the location is situated.
  • data, information, etc. may be obtained with the user's consent.
  • each element, each row, or each column in the table of this disclosure can be implemented as an independent embodiment, and any combination of any element, any row, or any column can also be implemented as an independent embodiment.
  • Figure 1a is a schematic diagram of the architecture of a communication system according to an embodiment of the present disclosure.
  • the communication system 100 includes a terminal 101 and a network device 102.
  • network device 102 may be an access network device or a core network device.
  • terminal 101 includes, for example, at least one of the following: mobile phone, wearable device, Internet of Things device, car with communication function, smart car, tablet computer, computer with wireless transceiver function, virtual reality (VR) terminal device, augmented reality (AR) terminal device, wireless terminal device in industrial control, wireless terminal device in self-driving, wireless terminal device in remote medical surgery, wireless terminal device in smart grid, wireless terminal device in transportation safety, wireless terminal device in smart city, and wireless terminal device in smart home, but is not limited thereto.
  • VR virtual reality
  • AR augmented reality
  • the access network device is, for example, a node or device that connects a terminal to a wireless network.
  • the access network device may include, but is not limited to, at least one of the following in a 5G communication system: evolved Node B (eNB), next-generation evolved Node B (ng-eNB), next-generation Node B (gNB), node B (NB), home node B (HNB), home evolved node B (HeNB), radio backhaul device, radio network controller (RNC), base station controller (BSC), base transceiver station (BTS), base band unit (BBU), mobile switching center, base station in a 6G communication system, open RAN, cloud RAN, base station in other communication systems, and access node in a Wi-Fi system.
  • eNB evolved Node B
  • ng-eNB next-generation evolved Node B
  • gNB next-generation Node B
  • gNB next-generation Node B
  • NB node B
  • HNB home node B
  • HeNB home evolved
  • the technical solutions of this disclosure can be applied to the Open RAN architecture.
  • the interfaces between or within access network devices involved in the embodiments of this disclosure can be transformed into internal interfaces of Open RAN.
  • the processes and information interactions between these internal interfaces can be implemented by software or programs.
  • the access network device may be composed of a central unit (CU) and a distributed unit (DU).
  • the CU may also be called a control unit.
  • the CU-DU structure can separate the protocol layer of the access network device. Some protocol layer functions are centrally controlled by the CU, while the remaining part or all of the protocol layer functions are distributed in the DU and centrally controlled by the CU. However, this is not the only possibility.
  • the core network equipment may be a single device, including a first network element, a second network element, etc., or it may be multiple devices or a group of devices, each including all or part of the first network element, the second network element, etc.
  • Network elements may be virtual or physical.
  • the core network may include, for example, at least one of the Evolved Packet Core (EPC), 5G Core Network (5GCN), and Next Generation Core (NGC).
  • EPC Evolved Packet Core
  • 5GCN 5G Core Network
  • NGC Next Generation Core
  • the first network element is, for example, a Mobility Management Entity (MME).
  • MME Mobility Management Entity
  • the first network element is used for signaling processing, and its name is not limited thereto.
  • the second network element is, for example, a Home Subscriber Server (HSS).
  • HSS Home Subscriber Server
  • the second network element is used to store subscribed user information, and the name is not limited thereto.
  • the third network element is, for example, the Policy and Charging Rules Function (PCRF).
  • PCRF Policy and Charging Rules Function
  • the third network element is used for policy provisioning and billing, and its name is not limited thereto.
  • the first network element, the second network element, and/or the third network element may be independent of the core network equipment.
  • the first network element, the second network element, and/or the third network element may be part of the core network equipment.
  • the following embodiments of this disclosure can be applied to the communication system 100 shown in FIG1a, or to some of the main bodies, but are not limited thereto.
  • the main bodies shown in FIG1a are illustrative.
  • the communication system may include all or some of the main bodies in FIG1a, or it may include other main bodies outside of FIG1a.
  • the number and form of each main body are arbitrary.
  • Each main body may be physical or virtual.
  • the connection relationship between the main bodies is illustrative.
  • the main bodies may not be connected or may be connected.
  • the connection may be in any way, such as direct connection or indirect connection, wired connection or wireless connection.
  • LTE Long Term Evolution
  • LTE-A LTE-Advanced
  • LTE-B LTE-Beyond
  • SUPER 3G IMT-Advanced
  • 4G 4th generation mobile communication system
  • 5G 5th generation mobile communication system
  • 5G 5G New Radio
  • F New Radio Access
  • RAT New Radio
  • NX New Radio Access
  • F Future Generation Radio Access
  • GSM Global System for Mobile communications
  • CDMA2000 Global System for Mobile communications
  • UMB Ultra Mobile Broadband
  • IEEE 802.11 Wi-Fi (registered trademark)
  • IEEE 802.16 WiMAX (registered trademark)
  • IEEE 802.20 Ultra-Wideband (UWB)
  • Bluetooth registered trademark
  • PLMN Public Land Mobile Network
  • D2D Device-to-Device
  • M2M Machine-to-Machine
  • IoT Internet of Things
  • V2X Vehicle-to-Everything
  • V2X Vehicle-to-Everything
  • systems utilizing other communication methods and next-generation systems extended from them.
  • next-generation systems extended from them can be combined (e.g., a combination of LTE or LTE-A with 5G).
  • Layer 1 or Layer 2 Triggered Mobility refers to a process in which a primary cell (Pcell) or primary secondary cell (PSCell) is switched by a Media Access Control (MAC) control element based on L1 measurement results. This may be accompanied by a change in the master cell group (MCG) or secondary cell group (SCG).
  • MCG master cell group
  • SCG secondary cell group
  • the gNB receives an L1 measurement report from the UE. Based on this report, the gNB changes the UE's serving cell via a cell switch command issued by the MAC CE.
  • the cell switch command indicates an LTM candidate cell configuration that the gNB has pre-provided to the UE via Radio Resource Control (RRC) signaling.
  • RRC Radio Resource Control
  • the UE accesses the target cell indicated in this cell switch command according to the received cell switch command.
  • LTM can be used to reduce mobility latency.
  • the LTM candidate cell configuration can only be added, modified, and released by the network via RRC signaling.
  • the LTM procedure can be used to reduce mobility delay.
  • LTM supports subsequent LTM, where subsequent LTM refers to a subsequent LTM cell handover process between candidate cells without network RRC reconfiguration. That is, after performing mobility operations, the UE does not voluntarily delete the LTM configuration information; the LTM configuration information can continue to be used to trigger subsequent LTM even without RRC reconfiguration and updates.
  • LTM supports intra-frequency and inter-frequency mobility, including mobility between inter-frequency cells that are not the current serving cell.
  • Rel-18 only supports LTM within a Distributed Unit (DU) and between DUs within a Central Processing Unit (CU).
  • Rel-19 extends NR mobility enhancement to inter-CU (inter-node or gNB) LTM, supporting the following scenarios:
  • Scenario 1 When no DC is configured, the CU acts as the network master node (MN);
  • Scenario 2 When NR-DC is configured and CU acts as a secondary node (SN) in the network and MCG remains unchanged;
  • Scenario 3 When NR-DC is configured, CU acts as MN and SCG remains unchanged or is released.
  • inter-CU LTM for inter-CU LTM, more than one candidate gNB-CU will be involved in the mobility flow.
  • the signaling process of Rel-19 inter-CU LTM is shown in Figure 1b and includes the following three stages:
  • Phase 1 (LTM Preparation): Based on the L3 Radio Resource Management (RRM) measurement report, the initial gNB determines candidate cells and initiates inter-node interaction for inter-CU LTM preparation. After the interaction, the initial gNB provides the UE with an LTM configuration containing multiple candidate cells and their RRC configurations.
  • RRM Radio Resource Management
  • Phase 2 (Initial LTM Execution): As in Rel-18 CU-based LTM, the UE sends an L1 measurement report to the initial gNB. After receiving the Cell Handover Command (MAC CE), the UE hands over to a candidate gNB (e.g., C-gNB1). To support Random Access Channel-less (RACH) LTM, early synchronization of DL and UL with the candidate cell can be performed before receiving the cell handover command.
  • RACH Random Access Channel-less
  • Phase 3 (Subsequent LTM Execution): In the subsequent LTM execution phase, steps similar to those in Phase 2 are performed.
  • the subsequent LTM is triggered by the current serving gNB, which is a candidate gNB (e.g., C-gNB1).
  • the synchronization of the Access Stratum (AS) security key between the UE and the target gNB is achieved via the Next Hop Chaining Counter (NCC) value used by the source gNB, which is then forwarded to the target gNB and the UE in the RRC reconfiguration signaling.
  • NCC Next Hop Chaining Counter
  • the Access and Mobility Management Function (AMF) and the UE should derive the K gNB and Next Hop Parameter (NH).
  • the NCC is associated with each K gNB and NH parameter.
  • Each K gNB is associated with the NCC corresponding to the NH value from which it is derived.
  • the source gNB should perform vertical key derivation. As described in Annex A.11/A.12 of 3GPP TS 33.501[1], the source gNB should first calculate K NG-RAN * from the currently active K gNB in the case of horizontal key derivation, or calculate K NG- RAN * from NH in the case of vertical key derivation.
  • the source gNB should forward the ⁇ K NG-RAN *, NCC ⁇ pair to the target gNB.
  • the target gNB should directly use the received K NG-RAN * as the K gNB to be used with the UE.
  • the target gNB should associate the NCC value received from the source gNB with the K gNB .
  • the target gNB should include the received NCC in a prepared handover (HO) command message, which is sent back to the source gNB in a transparent container and forwarded by the source gNB to the UE.
  • HO prepared handover
  • the UE behaves the same regardless of whether the handover is within the gNB-CU, Xn, or N2, except that the UE may retain the same key based on an indication from the gNB during handover within the gNB-CU.
  • the UE behaves the same in the case of conditional handover, as specified in 3GPP TS 38.300[2], that is, the UE should use the parameters of the selected target cell in the K NG-RAN * derivation.
  • the UE should use the functions defined in Appendices A.11 and A.12 of 3GPP TS 33.501[1] to derive K NG -RAN * from the currently active K gNB and the Physical Cell Identifier (PCI) and its downlink frequency Absolute Radio Frequency Channel Number (ARFCN) or downlink LTE Absolute Radio Frequency Channel Number (EARFCN).
  • PCI Physical Cell Identifier
  • the UE should first synchronize the locally held NH parameters by iteratively calculating the function defined in Appendix A.10 of 3GPP TS 33.501[1] (and incrementing the NCC value until it matches the NCC value received from the source gNB via the HO command message).
  • the UE should use the functions defined in Appendices A.11 and A.12 of 3GPP TS 33.501[1] to calculate K NG-RAN * based on the synchronized NH parameters and the target PCI and its frequency ARFCN-DL or EARFCN-DL.
  • the UE when communicating with a target gNB, the UE should use KNG-RAN * as the KgNB .
  • security-related configurations e.g., NCC, KNG -RAN *
  • the source gNB sends the NCC to the UE in the RRC reconfiguration during each handover.
  • the NCC is used by the UE for key reset synchronization with the target gNB.
  • the source gNB does not send the RRC reconfiguration during each handover. Therefore, how to update the NCC value and send it to the UE for key update synchronization during each handover becomes an open question, and 3GPP has investigated several options for this, one of which is as follows.
  • Option 1 Please refer to Figure 1d. Use the new information in the MAC CE to transmit security information. Whether the UE uses horizontal or vertical key export is derived from this new information in the MAC CE (which is currently neither integrity-protected nor encrypted).
  • Option 1A Include the NCC value used during LTM execution between CUs in the LTM cell handover command MAC CE.
  • option 1A i.e., carrying the NCC value in the LTM cell handover command MAC CE
  • option 1A is considered the option with the least impact in terms of feasibility and signaling overhead.
  • the main problem with this option is that the MAC CE message is unprotected, making the NCC carried in the MAC CE message unprotected.
  • the unprotected NCC is vulnerable to tampering by attackers.
  • the key derived by the UE will differ from the key received and derived by the target gNB from the source gNB. This desynchronization of the key reset between the UE and the target gNB will lead to handover failure.
  • security-related configurations e.g., MasterKeyUpdate, NCC
  • the RRC reconfiguration is sent after AS security is established between the UE and the gNB, therefore the entire RRC reconfiguration message is at least protected by integrity and cannot be tampered with by an attacker.
  • the preparation phase is performed only by the initial gNB and not for each subsequent handover; that is, there is no preparation phase before each handover for inter-CU LTM enhancement.
  • RRC reconfiguration signaling is performed only by the initial gNB during the LTM preparation phase, but is replaced by a MAC CE message at each handover after LTM preparation. Since the MAC CE message is unprotected, the security-related configuration carried in the MAC CE message cannot be protected.
  • AS security established between the UE and gNB is performed at the Packet Data Convergence Protocol (PDCP) layer on the Uu interface.
  • the MAC layer below the PDCP layer does not support security-related calculations. Therefore, there is no existing security mechanism to protect the MAC CE message.
  • PDCP Packet Data Convergence Protocol
  • the serving or source gNB assigns a Cell-Radio Network Temporary Identifier (C-RNTI) to the attached UE.
  • C-RNTI Cell-Radio Network Temporary Identifier
  • the current C-RNTI is known only to the serving or source gNB and the assigned UE, and not to any other party.
  • the serving or source gNB needs to send the current C-RNTI to the target gNB in the handover request, and the target gNB needs to return the current or old C-RNTI assigned by the serving or source gNB and the new C-RNTI assigned by the target gNB in the handover request confirmation to the serving or source gNB, which then forwards it to the UE.
  • both the serving or source and target gNBs know the old and new C-RNTI values; for example, see the last three steps of Figure 1e.
  • all C-RNTI values are allocated by the initial gNB and delivered to the UE during the LTM preparation phase (i.e., see step #5 in Figure 1f). Therefore, it is not necessary to transmit old and new C-RNTI values during the inter-gNB handover process as described above.
  • all candidate gNBs only know the C-RNTI values they use, and no gNB other than the initial or source gNB can know the C-RNTI values used by other gNBs.
  • the C-RNTI value can be considered a key shared between the serving gNB and the UE.
  • the initial or source gNB possessing all the C-RNTI values of candidate gNBs actually possesses information even more critical than the C-RNTI values, making it possible for an attacked initial or source gNB to compromise all LTM executions and subsequent LTM executions. Therefore, the discussion of NCC protection is based on the assumption that the initial or source gNB will never be attacked. Under this assumption, the present invention proposes using the C-RNTI shared between the UE and the serving gNB to protect the integrity of the NCC value contained in the MAC CE message.
  • Figure 2a is an interactive schematic diagram of a communication method according to an embodiment of the present disclosure. As shown in Figure 2a, the present disclosure relates to a communication method for a communication system 100, the method comprising:
  • Step S2101 The first network device sends the first identifier to the terminal.
  • the first network device assigns a first identifier to the terminal.
  • the first network device may be the initial network device.
  • the initial network device may be an initial base station.
  • the initial network device may be the source base station (e.g., source gnb0) in the LTM process.
  • the initial network device sends information containing a first identifier to the terminal.
  • the initial network device may send information containing a first identifier to the terminal.
  • the first identifier is at least one of the following:
  • the temporary cell radio network identifier (C-RNTI) assigned to the terminal is a temporary cell radio network identifier (C-RNTI) assigned to the terminal;
  • the LTM-specific identifier assigned to the terminal
  • a random number assigned to the terminal is A random number assigned to the terminal.
  • the first identifier may include C-RNTI_0, C-RNTI_1, and C-RNTI_2.
  • the initial network device may send information containing a first identifier to the terminal via a Radio Resource Control (RRC) configuration message.
  • RRC Radio Resource Control
  • the first identifier is an identifier assigned to the terminal connected to the first network device.
  • the first identifier is a terminal identifier assigned by the initial network device to the serving network device during the LTM process.
  • Step S2102 The first network device obtains the second information.
  • the second information is information related to communication protection between the terminal and the second network device.
  • the second information may be information confirmed by the second network device. In some embodiments, the second information may not require confirmation by the second network device.
  • the second information is the first security information.
  • the second information is the first NCC.
  • the first network device is an access network device.
  • the first network device is an initial base station, a source base station, and/or a serving base station.
  • the first network device is the serving base station during the subsequent LTM execution phase.
  • the first network device determines the second information.
  • the first network device selects the second information.
  • the first network device sends second information to the second network device.
  • the first network device receives confirmed second information sent by the second network device.
  • the first network device may determine the second information based on protocol specifications or based on preset policies or rules.
  • the first network device selects the second information; the first network device sends the second information to the second network device; the second network device confirms the second information; and the second network device sends the second information back to the first network device.
  • the second network device is a candidate access network device for the terminal to perform handover, such as a candidate base station.
  • Step S2103 The first network device generates third information.
  • the first network device generates the third information based on the second information and the fourth information. In some embodiments, the first network device generates the third information based on the second information, the fourth information, and a first indicator. In some embodiments, the first network device generates the third information based on the second information, the fourth information, the first indicator, and first time information.
  • the third information is the second security information. In some embodiments, the third information is used to verify the second information.
  • the fourth information is information associated with the first identifier. In some embodiments, the first identifier is used to protect the second information. In some embodiments, the first identifier is used to verify the second information. In some embodiments, the fourth information is used to protect the second information. In some embodiments, the fourth information is used to verify the second information.
  • the fourth information is information obtained by hashing the first identifier. In some embodiments, the fourth information is the first identifier.
  • a first indicator (keySetChangeIndicator) is used to indicate to the terminal whether to generate a first key based on the second information, and the first key is used by the terminal to communicate with the second network device.
  • the first indicator is used to indicate how the terminal generates the first key.
  • the first indicator may be used to indicate to the terminal the parameter value for generating the first key.
  • the first indicator is used to indicate the switching type, and the parameter values used to generate the first key are different for different switching types.
  • the first indicator is used to indicate the key update type, and different key update types use different parameter values to generate the second key.
  • the handover type may include different types such as intra-node cell handover, cross-node cell handover, or cross-AMF cell handover. Different types use different parameters to generate the key for communication between the UE and the second cell.
  • the first indicator may include one or more bits, and exemplarily, the first indicator has one or more values.
  • the first indicator may have a first value and a second value.
  • the first indicator has a first value, in which case the first key is generated based on the second information, or in other words, the generation of the first key takes the second information into account.
  • the first indicator When the first indicator has a second value, the first key is not generated based on the second information, or in other words, the generation of the first key does not require consideration of the second information.
  • the first indicator when the first indicator has a second value, it indicates that the second key is generated by the UE based on the K AMF .
  • the K AMF is a key shared by the UE and the AMF, and is an intermediate key used to generate the first key.
  • the first time information is the current time when the first network device generates the third information.
  • the first time information is Coordinated Universal Time (UTC) information. Understandably, by incorporating the first time information during the generation of the third information, the receiver can use the first time information to verify whether the third information has expired, thereby effectively rejecting replay attacks.
  • UTC Coordinated Universal Time
  • the first network device may encode the second information using the fourth information to obtain the third information. In some embodiments, the first network device may encode the first indicator and the second information using the fourth information to obtain the third information. In some embodiments, the first network device may encode the first indicator and the second information using the fourth information and the first time information to obtain the third information.
  • the first network device can perform an XOR operation on the fourth information and the second information to obtain the third information. In some embodiments, the first network device can hash the first XOR value to obtain the third information, where the first XOR value is the result of an XOR operation on the fourth information and the second information. In some embodiments, the first network device can perform an XOR operation on the fourth information, the second information, and the first indicator to obtain the third information. In some embodiments, the first network device can hash the second XOR value to obtain the third information, where the second XOR value is the result of an XOR operation on the fourth information, the first indicator, and the second information.
  • the first network device can perform an XOR operation on the fourth information, the second information, the first indicator, and the first time information to obtain the third information.
  • the first network device can hash the third XOR value to obtain the third information, where the third XOR value is the result of an XOR operation on the fourth information, the first indicator, the second information, and the first time information.
  • the first network device may obtain third information based on one or more of the following operations: AND, OR, NOT, XOR, XNOR, NAND, and NOR.
  • the following example illustrates the generation process of the third information, using the fourth information as the result of hashing the first identifier (e.g., C-RNTI).
  • the first identifier e.g., C-RNTI
  • the second information is the first NCC, which can be represented as NCC1.
  • the third information can be understood as the encoded second information, represented as [NCC1].
  • hash processing can be represented as H().
  • the fourth information can be represented as H(C-RNTI).
  • the XOR operation can be represented as XOR.
  • the first indicator keySetChangeIndicator
  • the first time information can be represented as T1.
  • [NCC1] NCC1 xor Indicator xor H(C-RNTI).
  • [NCC1] NCC1 xor Indicator xor T1 xor H(C-RNTI).
  • [NCC1] H(NCC1 xor Indicator xor T1 xor H(C-RNTI)).
  • any of the second information (i.e., NCC1), the fourth information (i.e., H(C-RNTI)), the first indicator (i.e., Indicator), and the first time information (i.e., T1) can be subjected to one or more operations among AND, OR, NOT, XOR, XNOR, NAND, and NOR.
  • the following example illustrates the process of generating the third information, using the fourth information as the first identifier (e.g., C-RNTI).
  • the fourth information e.g., C-RNTI
  • the second information is the first NCC, which can be represented as NCC1.
  • the third information can be understood as the encoded second information, represented as [NCC1].
  • hash processing can be represented as H().
  • the fourth information can be represented as C-RNTI.
  • the XOR operation can be represented as xor.
  • the first indicator keySetChangeIndicator
  • the first time information can be represented as T1.
  • [NCC1] H(NCC1 xor C-RNTI).
  • [NCC1] H(NCC1 xor Indicator xor T1 xor C-RNTI).
  • any of the second information (i.e., NCC1), the fourth information (C-RNTI), the first indicator (i.e., Indicator), and the first time information (i.e., T1) can be subjected to one or more operations among AND, OR, NOT, XOR, XNOR, NAND, and NOR.
  • the first network device performs a hash operation on the first identifier to obtain the fourth information.
  • the first network device performs a hash operation on the first identifier to obtain the fourth information; the first network device generates the third information based on the second information and the fourth information.
  • the third information and the fourth information are used to verify the second information.
  • the second information is a first NCC (e.g., NCC1); the third information is obtained by encoding the first NCC using the fourth information.
  • NCC1 a first NCC
  • the third information is obtained by encoding the first NCC using the fourth information.
  • the second information is a first NCC
  • the first network device performs a hash process on the first identifier to obtain the fourth information
  • the first NCC is encoded using the fourth information to obtain the third information.
  • Step S2104 The first network device sends the first information to the terminal.
  • the terminal receives first information sent by the first network device.
  • the first information is the third security information.
  • the first information includes second information and third information. In some embodiments, the first information may also include a first indicator.
  • a first Media Access Control (MAC) Control Element (CE) message is sent to the terminal.
  • the first MAC CE message contains first information.
  • first information is sent to the terminal.
  • the inter-base station LTM process includes an initial inter-base station LTM process and a subsequent inter-base station LTM process.
  • sending first information to the terminal includes at least one of the following: sending first information to the terminal during the initial LTM process between the terminal and the first network device; and sending first information to the terminal during the subsequent LTM process between the terminal and the first network device.
  • first information is sent to the terminal; wherein the inter-base station LTM process includes the initial inter-base station LTM process.
  • first information is sent to the terminal; wherein, the base station LTM process includes the subsequent inter-base station LTM process.
  • Step S2105 The terminal verifies the second information.
  • the terminal verifies the second information based on the second information, the third information, and the seventh information. In some embodiments, the terminal verifies the second information based on the second information, the third information, the seventh information, and a first indicator. In some embodiments, the terminal verifies the second information based on the second information, the third information, the seventh information, the first indicator, and second time information.
  • the seventh information is associated with the first identifier. In some embodiments, the seventh information may be the same as or different from the fourth information. In some embodiments, the seventh information is information obtained by the terminal after hashing the first identifier. In some embodiments, the seventh information is the first identifier.
  • the seventh and fourth information are the same. In some embodiments, if the result obtained by the terminal after hashing the first identifier is the same as the result obtained by the first network device after hashing the first identifier, then the seventh and fourth information are the same. In some embodiments, if the result obtained by the terminal after hashing the first identifier is different from the result obtained by the first network device after hashing the first identifier, then the seventh and fourth information are different.
  • the second time information is the current time when the terminal verifies the second information. In some embodiments, the second time information can be the time when the terminal receives the third information. In some embodiments, the second time information is associated with the first time information. In some embodiments, the value of the second time information is equal to the value of the first time information. It can be understood that if the transmission speed between the first network device and the terminal is fast enough, the time when the first network device generates the third information (i.e., the first time information) is equal to the time when the terminal receives the third information (i.e., the second time information).
  • the value of the second time information is equal to the value of the first time information plus a first offset value, where the first offset value is the time when the first network device transmits the third information to the terminal.
  • the first offset value can be understood as the transmission delay between the first network device and the terminal.
  • the terminal can know the transmission delay between itself and the first network device.
  • the terminal decodes the third information based on the seventh information to obtain the fifth information, and verifies the second information based on the fifth information. In some embodiments, the terminal decodes the third information based on the seventh information and the first indicator to obtain the fifth information, and verifies the second information based on the fifth information. In some embodiments, the terminal decodes the third information based on the seventh information, the first indicator, and the second time information to obtain the fifth information, and verifies the second information based on the fifth information.
  • the terminal can perform the inverse operation on the operation that generates the third information by the first network device to obtain the fifth information, and verify the second information based on the fifth information.
  • the terminal can obtain the fifth information based on the inverse AND operation, i.e., a NAND operation.
  • the terminal can obtain the fifth information based on the inverse OR operation, i.e., a NOR operation.
  • the terminal can obtain the fifth information based on the inverse NOT operation, i.e., a NOT operation.
  • the terminal can obtain the fifth information based on the inverse XOR operation, i.e., a XOR operation.
  • the terminal can obtain the fifth information based on the inverse XNOR operation, i.e., a XOR operation.
  • the terminal can obtain the fifth information based on the inverse NAND operation, i.e., an AND operation.
  • the terminal can obtain the fifth information based on the inverse operation of the NOR operation, i.e., an OR operation.
  • the following example illustrates the generation process of the fifth information, using the seventh information as the information obtained by hashing the first identifier (e.g., C-RNTI) and the third information obtained by the first network device based on an XOR operation.
  • the seventh information as the information obtained by hashing the first identifier (e.g., C-RNTI) and the third information obtained by the first network device based on an XOR operation.
  • the fifth piece of information is the second NCC, which can be represented as NCC1'.
  • the third piece of information can be understood as the encoded second piece of information, which can be represented as [NCC1].
  • hash processing can be represented as H().
  • the seventh piece of information can be represented as H(C-RNTI).
  • the XOR operation can be represented as xor.
  • the first indicator keySetChangeIndicator
  • the second time information can be represented as T2.
  • NCC1’ [NCC1]xor H(C-RNTI).
  • NCC1’ [NCC1]xor Indicator xor T2 xor H(C-RNTI).
  • the second information passes verification if the fifth information and the second information are the same. In one example, if NCC1 and NCC1' are the same, then NCC1 passes verification.
  • the second piece of information fails verification.
  • NCC1 and NCC1' differ, then NCC1 fails verification.
  • the terminal encodes the second information based on the seventh information to obtain the sixth information, and verifies the second information based on the sixth information. In some embodiments, the terminal encodes the second information and the first indicator based on the seventh information to obtain the sixth information, and verifies the second information based on the sixth information. In some embodiments, the terminal encodes the second information and the first indicator based on the seventh information and the second time information to obtain the sixth information, and verifies the second information based on the sixth information.
  • the terminal may perform the same operation as the first network device in generating the third information to obtain the sixth information, and verify the second information based on the sixth information.
  • the terminal performs an XOR operation between the seventh information and the second information to obtain the sixth information.
  • the terminal hashes the fourth XOR value to obtain the sixth information; the fourth XOR value is obtained by XORing the seventh information and the second information.
  • the terminal performs an XOR operation between the seventh information, the second information, and the first indicator to obtain the sixth information.
  • the terminal hashes the fifth XOR value to obtain the sixth information; the fifth XOR value is obtained by XORing the seventh information, the second information, and the first indicator.
  • the terminal performs an XOR operation between the seventh information, the second information, the first indicator, and the second time information to obtain the sixth information.
  • the terminal hashes the sixth XOR value to obtain the sixth information; the sixth XOR value is obtained by XORing the seventh information, the second information, the first indicator, and the second time information.
  • the following example illustrates the generation process of the sixth information, using the seventh information as the information obtained by hashing the first identifier (e.g., C-RNTI) and the third information obtained by the first network device based on an XOR operation.
  • the seventh information as the information obtained by hashing the first identifier (e.g., C-RNTI) and the third information obtained by the first network device based on an XOR operation.
  • the second information is the first NCC, which can be represented as NCC1.
  • the sixth information can be represented as [NCC1]'.
  • hash processing can be represented as H().
  • the seventh information can be represented as H(C-RNTI).
  • the XOR operation can be represented as xor.
  • the first indicator keySetChangeIndicator
  • the second time information can be represented as T2.
  • [NCC1]’ NCC1 xor H(C-RNTI).
  • [NCC1]’ H(NCC1 xor H(C-RNTI)).
  • [NCC1]’ NCC1 xor Indicator xor H(C-RNTI).
  • [NCC1]’ H(NCC1 xor Indicator xor H(C-RNTI)).
  • [NCC1]’ NCC1 xor Indicator xor T2 xor H(C-RNTI).
  • [NCC1]’ H(NCC1 xor Indicator xor T2 xor H(C-RNTI)).
  • the following example illustrates the generation process of the sixth information, using the seventh information as the first identifier and the third information obtained by the first network device based on an XOR operation.
  • [NCC1]’ H(NCC1 xor C-RNTI).
  • [NCC1]’ H(NCC1 xor Indicator xor C-RNTI).
  • [NCC1]’ H(NCC1 xor Indicator xor T2 xor C-RNTI).
  • the second information passes verification. In one example, if [NCC1] and [NCC1]' are the same, then NCC1 passes verification. In some embodiments, if the sixth information and the third information are different, then the second information fails verification. In one example, if [NCC1] and [NCC1]' are different, then NCC1 fails verification.
  • the terminal after receiving the first information, the terminal verifies the second information based on the second, third, and fourth information.
  • the first network device and the terminal share fourth information.
  • the terminal decodes the third information based on the fourth information to obtain the fifth information.
  • the terminal determines whether the second information has passed verification based on the comparison result between the second information and the fifth information.
  • the second information and the fifth information may be the same or different.
  • the terminal determines whether the second information passes verification based on the comparison result of the second information and the fifth information, including at least one of the following: the terminal determines that the second information is the same as the fifth information, and the terminal determines that the second information passes verification; the terminal determines that the second information is different from the fifth information, and the terminal determines that the second information fails verification.
  • the terminal determines that the second information is the same as the fifth information, and the terminal determines that the second information has passed verification.
  • the terminal determines that the second information is different from the fifth information, and the terminal determines that the second information has failed verification.
  • the terminal encodes the second information based on the fourth information to obtain the sixth information.
  • the terminal determines whether the second information passes verification based on the comparison result of the third information and the sixth information.
  • the third information and the sixth information may be the same or different.
  • the terminal determines whether the second information passes verification based on the comparison result of the third information and the sixth information, including: if the terminal determines that the third information is the same as the sixth information, the terminal determines that the second information passes verification; if the terminal determines that the third information is different from the sixth information, the terminal determines that the second information fails verification.
  • the terminal determines that the third information is the same as the sixth information, and the terminal determines that the second information has passed verification.
  • the terminal determines that the third information is different from the sixth information, and the terminal determines that the second information has failed verification.
  • the term “information” may be used interchangeably with terms such as “message,” “signal,” “signaling,” “report,” “configuration,” “indication,” “instruction,” “command,” “channel,” “parameter,” “field,” and “data.”
  • the term “send” may be used interchangeably with terms such as “transmit,” “report,” or “transmit.”
  • the communication method involved in the embodiments of this disclosure may include at least one of steps S2101 to S2105.
  • step S2102 can be implemented as an independent embodiment
  • step S2104 can be implemented as an independent embodiment
  • step S2105 can be implemented as an independent embodiment
  • step S2104 combined with step S2105 can be implemented as an independent embodiment
  • step S2103 combined with steps S2104 and S2105 can be implemented as an independent embodiment
  • step S2102 combined with steps S2103, S2104, and S2105 can be implemented as an independent embodiment
  • step S2101 combined with steps S2102, S2103, S2104, and S2105 can be implemented as an independent embodiment, but is not limited thereto.
  • each step can be implemented independently, or, without contradiction, the order can be arbitrarily changed and freely combined for implementation.
  • Figure 3a is a flowchart illustrating a communication method according to an embodiment of the present disclosure. As shown in Figure 3a, the embodiment of the present disclosure relates to a communication method executed by a first network device, the method comprising:
  • Step S3101 Assign a first identifier to the terminal.
  • step S3101 can be found in optional implementations of step S2101 in FIG2a and other related parts in the embodiments involved in FIG2a, which will not be repeated here.
  • Step S3102 Obtain the second information.
  • the first network device receives second information sent by the second network device, but is not limited thereto; it may also receive second information sent by other entities.
  • the first network device obtains second information as defined by a protocol.
  • the first network device obtains the second information from the upper layer(s).
  • the first network device processes the information to obtain the second information.
  • step S3102 is omitted, and the first network device autonomously implements the function indicated by the second information, or the above function is default or default.
  • step S3102 can be found in optional implementations of step S2102 in FIG2a and other related parts in the embodiments involved in FIG2a, which will not be repeated here.
  • Step S3103 Generate third information.
  • step S3103 can be found in optional implementations of step S2103 in FIG2a and other related parts in the embodiments involved in FIG2a, which will not be repeated here.
  • Step S3104 Send the first information to the terminal.
  • the communication method involved in the embodiments of this disclosure may include at least one of steps S3101 to S3104.
  • step S3101 can be implemented as an independent embodiment
  • step S3102 can be implemented as an independent embodiment
  • step S3103 can be implemented as an independent embodiment
  • step S3104 can be implemented as an independent embodiment
  • step S3103 combined with step S3104 can be implemented as an independent embodiment
  • step S3101 combined with steps S3103 and S3104 can be implemented as an independent embodiment
  • step S3101 combined with steps S3102, S3103, and S3104 can be implemented as an independent embodiment, but it is not limited thereto.
  • each step can be implemented independently, or, without contradiction, the order can be arbitrarily changed and the steps can be freely combined for implementation.
  • Figure 3b is a flowchart illustrating a communication method according to an embodiment of the present disclosure. As shown in Figure 3b, the embodiment of the present disclosure relates to a communication method executed by a first network device, the method comprising:
  • Step S3201 Send the first information to the terminal.
  • the first information includes second information and third information; the second information is information related to communication protection between the terminal and the second network device; the third information is used to verify the second information; the first network device is the serving network device of the terminal, and the second network device is a candidate network device for the terminal to perform a handover.
  • the first information includes: second information and third information; the second information is information confirmed by the second network device; the third information is information generated based on the second information and the fourth information; the third information and the fourth information are used to verify the second information; the fourth information is information associated with a first identifier; the first identifier is an identifier assigned to the terminal; the first network device is the serving network device of the terminal, and the second network device is a candidate network device for the terminal to perform a handover.
  • step S3201 can be found in optional implementations of step S2104 in FIG2a and other related parts in the embodiments involved in FIG2a, which will not be repeated here.
  • the first identifier is a terminal identifier assigned by the initial network device to the serving network device during the mobility LTM process triggered by Layer 1L1 or Layer 2L2.
  • sending first information to the terminal includes:
  • the first MAC CE message contains the first information.
  • sending first information to the terminal includes:
  • the first information is sent to the terminal.
  • sending first information to the terminal includes at least one of the following:
  • the first information is sent to the terminal;
  • the first information is sent to the terminal.
  • the method further includes:
  • the method includes:
  • the third information is generated based on the second and fourth information.
  • the second information is the first next-step counter parameter NCC; the third information is generated based on the second and fourth information, including:
  • the third information is obtained by encoding the first NCC using the fourth information.
  • the first NCC is encoded using the fourth information to obtain the third information, including:
  • the method further includes:
  • the first identifier is at least one of the following:
  • the temporary identifier (C-RNTI) of the cell radio network assigned to the terminal is a temporary identifier (C-RNTI) of the cell radio network assigned to the terminal;
  • the LTM-specific identifier assigned to the terminal
  • a random number assigned to the terminal is A random number assigned to the terminal.
  • Figure 4a is a flowchart illustrating a communication method according to an embodiment of the present disclosure. As shown in Figure 4a, the embodiment of the present disclosure relates to a communication method executed by a terminal, the method including:
  • Step S4101 Obtain the first information.
  • the first information includes second information and third information; the second information is information related to communication protection between the terminal and the second network device; the third information is used to verify the second information; the first network device is the serving network device of the terminal, and the second network device is a candidate network device for the terminal to perform a handover.
  • the terminal receives first information sent by a first network device, but is not limited thereto; it may also receive first information sent by other entities.
  • the terminal obtains first information as defined by the protocol.
  • the terminal obtains first information from the upper layer(s).
  • the terminal processes the information to obtain the first information.
  • step S4101 is omitted, and the terminal autonomously implements the function indicated by the second information, or the above function is defaulted or set to default.
  • step S4101 can be found in optional implementations of step S2104 in FIG2a and other related parts in the embodiments involved in FIG2a, which will not be repeated here.
  • Step S4102 Verify the second information.
  • step S4102 can be found in optional implementations of step S2105 in FIG2a and other related parts in the embodiments involved in FIG2a, which will not be repeated here.
  • Figure 4b is a flowchart illustrating a communication method according to an embodiment of the present disclosure. As shown in Figure 4b, the embodiment of the present disclosure relates to a communication method executed by a terminal, the method including:
  • Step S4201 Receive the first information sent by the first network device.
  • the first information includes second information and third information; the second information is information related to communication protection between the terminal and the second network device; the third information is used to verify the second information; the first network device is the serving network device of the terminal, and the second network device is a candidate network device for the terminal to perform a handover.
  • the first information includes: second information and third information; the second information is information confirmed by the second network device; the third information is information generated based on the second information and the fourth information; the third information and the fourth information are used to verify the second information; the fourth information is information associated with a first identifier; the first identifier is an identifier assigned to the terminal; the first network device is the serving network device of the terminal, and the second network device is a candidate network device for the terminal to perform a handover.
  • step S4201 can be found in optional implementations of step S2105 in FIG2a and other related parts in the embodiments involved in FIG2a, which will not be repeated here.
  • the first identifier is the terminal identifier assigned by the initial network device to the serving network device during the LTM process.
  • receiving first information sent by a first network device includes:
  • the first MAC CE message contains the first information.
  • receiving first information sent by a first network device includes:
  • the terminal receives the first information sent by the first network device.
  • receiving first information sent by the first network device includes:
  • the terminal receives the first information sent by the first network device.
  • the terminal receives the first information sent by the first network device.
  • the second information is the first next-hop counter parameter NCC
  • the third information is security information obtained by encoding the first NCC using the fourth information.
  • the third information is security information obtained by performing an XOR operation between the first NCC and the fourth information.
  • the fourth information is information obtained by performing a hash process on the first identifier.
  • the first identifier is at least one of the following:
  • the temporary identifier (C-RNTI) of the cell radio network assigned to the terminal is a temporary identifier (C-RNTI) of the cell radio network assigned to the terminal;
  • the LTM-specific identifier assigned to the terminal
  • a random number assigned to the terminal is A random number assigned to the terminal.
  • the method further includes:
  • the first network device and the terminal share the fourth information.
  • verifying the second information based on the second information, the third information, and the fourth information includes:
  • the third information is decoded to obtain the fifth information
  • determining whether the second information passes verification based on the comparison result of the second information and the fifth information includes at least one of the following:
  • the second piece of information is confirmed to be the same as the fifth piece of information; therefore, the second piece of information has passed verification.
  • the second piece of information is determined to be different from the fifth piece of information; therefore, the second piece of information has failed verification.
  • verifying the second information based on the second information, the third information, and the fourth information includes:
  • the second information is encoded based on the fourth information to obtain the sixth information
  • determining whether the second information passes verification based on the comparison result of the third information and the sixth information includes:
  • the third piece of information is confirmed to be the same as the sixth piece of information; the second piece of information has passed verification.
  • the third piece of information is determined to be different from the sixth piece of information, and the second piece of information has failed verification.
  • the method further includes:
  • Figure 5a is an interactive schematic diagram of a communication method according to an embodiment of the present disclosure. As shown in Figure 5a, the present disclosure relates to a communication method for a communication system, the method including one of the following steps:
  • Step S5101 The first network device sends the first information to the terminal.
  • the first information includes second information and third information; the second information is information related to communication protection between the terminal and the second network device; the third information is used to verify the second information; the first network device is the serving network device of the terminal, and the second network device is a candidate network device for the terminal to perform a handover.
  • the first information includes: second information and third information; the second information is information confirmed by the second network device; the third information is information generated based on the second information and the fourth information; the third information and the fourth information are used to verify the second information; the fourth information is information associated with a first identifier; the first identifier is an identifier assigned to the terminal; the first network device is the serving network device of the terminal, and the second network device is a candidate network device for the terminal to perform a handover.
  • step S5101 can be found in the optional implementation of step S2104 in Figure 2a and other related parts in the embodiment involved in Figure 2a, which will not be repeated here.
  • the above methods may include the methods of the above-described communication system side, terminal side, network device side, etc., which will not be described in detail here.
  • Figure 6a provides a communication method, the communication method including:
  • Step S6101 Assign C-RNTI.
  • the UE is assigned a C-RNTI value (e.g., C-RNTI_0, C-RNTI_1 and/or C-RNTI_2, corresponding to the first identifier in this disclosure) that is used with all candidate gNBs.
  • C-RNTI value e.g., C-RNTI_0, C-RNTI_1 and/or C-RNTI_2, corresponding to the first identifier in this disclosure
  • Step S6102 L1 Measurement Report.
  • the UE when the UE moves, the UE sends an L1 measurement report to the serving or source gNB.
  • Step S6103 Determine NCC1.
  • the serving or source gNB determines whether an LTM procedure needs to be triggered. If the serving or source gNB has no unused NH, then the serving or source gNB derives K NG-RAN *(i.e., K NG-RAN * ⁇ KDF(K gNB0 ,cell ID)). If the serving or source gNB has an unused NH (associated with NCC1), then the serving or source gNB derives K NG-RAN *(i.e., K NG-RAN * ⁇ KDF(NH1,cell ID)) from the unused NH.
  • K NG-RAN * i.e., K NG-RAN * ⁇ KDF(NH1,cell ID)
  • Step S6104 The serving or source gNB sends the exported K NG-RAN * and the NCC value (NCC1) used for exporting K NG-RAN * to candidate gNB1.
  • gNB1 uses K NG-RAN * as K gNB1 and returns the NCC value (NCC1) to the serving or source gNB.
  • Step S6104 includes:
  • Step S6104a Send a handshake request, including NCC1;
  • Step S6104b Obtain K gNB1 ;
  • Step S6104c Send a handshake request response, including NCC1.
  • Step S6105 Encode NCC1.
  • the serving or source gNB when the NCC value (NCC1) returned by candidate gNB1 is received, the serving or source gNB first performs a hash operation on the C-RNTI value (i.e., C-RNTI_0) assigned to the UE, and then encodes NCC1 by XORing it with the result of the C-RNTI operation (i.e., H(C-RNTI_0)).
  • C-RNTI_0 the C-RNTI value assigned to the UE
  • the encoded NCC value [NCC1] NCC1 xor H(C-RNTI_0).
  • the encoded NCC value [NCC1] NCC1 xor H(C-RNTI_0).
  • the encoded NCC value [NCC1] H(NCC1 xor H(C-RNTI_0)).
  • the encoded NCC value [NCC1] NCC1 xor Indicator xor H(C-RNTI_0).
  • the encoded NCC value [NCC1] H(NCC1 xor Indicator xor H(C-RNTI_0)).
  • the encoded NCC value [NCC1] NCC1 xor Indicator xor T1 xor H(C-RNTI_0).
  • the encoded NCC value [NCC1] H(NCC1 xor Indicator xor T1 xor H(C-RNTI_0)).
  • the encoded NCC value [NCC1] H(NCC1 xor C-RNTI_0).
  • the encoded NCC value [NCC1] H(NCC1 xor Indicator xor C-RNTI_0).
  • the encoded NCC value [NCC1] H(NCC1 xor Indicator xor T1 xor C-RNTI_0).
  • Indicator is represented as the first indicator (keySetChangeIndicator), T1 is the first time information, which is the current time when the service or source gNB0 generates [NCC1], H() represents hash operation, and xor represents XOR operation.
  • Step S6106 Send MAC CE.
  • the service or source gNB includes the plaintext of NCC1 and the encoded NCC value [NCC1] in the MAC CE sent to the UE.
  • the structure of the MAC CE is shown in Figure 6b.
  • the service or source gNB may also include a first indicator (keySetChangeIndicator) in the MAC CE sent to the UE to indicate to the terminal whether to generate a first key based on NCC1.
  • a first indicator keySetChangeIndicator
  • Step S6107 Perform verification.
  • authentication is performed when a MAC CE is received from a service or source gNB.
  • NCC1’ [NCC1]xor H(C-RNTI_0).
  • NCC1’ [NCC1]xor Indicator xor H(C-RNTI_0).
  • the UE can compare the calculated NCC1’ with NCC1 to determine the verification result of NCC1.
  • NCC verification can be done by comparing [received NCC1 xor H(C-RNTI_0)] with the received [NCC1].
  • [NCC1]’ NCC1 xor H(C-RNTI_0).
  • [NCC1]’ NCC1 xor Indicator xor H(C-RNTI_0).
  • [NCC1]’ H(NCC1 xor Indicator xor H(C-RNTI_0)).
  • the UE can compare the calculated [NCC1]’ with [NCC1] to determine the verification result of NCC1.
  • Indicator represents the first indicator (keySetChangeIndicator)
  • T2 represents the second time information, which is the current time when the UE verifies NCC1
  • H() represents hash operation
  • xor represents XOR operation.
  • the UE separates from the serving or source gNB and applies the configuration of the target gNB (candidate gNB1), including using K NG-RAN * as K gNB1 with gNB1.
  • Step S6108 The UE sends an RRC reconfiguration complete message to gNB1.
  • Step S6109 N2 path switching.
  • the target gNB (gNB1) sends an N2 path switching request to the AMF, and the AMF returns new NH and NCC (NH2, NCC2) to gNB1.
  • the UE when the UE remains mobile, the UE sends an L1 measurement report to the serving or source gNB (gNB1).
  • gNB serving or source gNB
  • Step S6111 Determine NCC2.
  • the serving gNB determines whether the LTM process needs to be triggered.
  • gNB1 further determines an NCC value (NCC2) for deriving the K NG-RAN from the NH associated with the NCC value.
  • NCC2 an NCC value
  • the service or source gNB since the service or source gNB has unused NH (i.e., NH2 associated with NCC2), the service or source gNB derives K NG-RAN *(ieK NG-RAN * ⁇ KDF(K gNB1 ,cell ID)) from the unused NH.
  • Step S6112 Service gNB1 sends the exported K NG-RAN * and the NCC value (NCC2) used for exporting K NG-RAN * to candidate gNB2.
  • NCC2 the NCC value used for exporting K NG-RAN * to candidate gNB2.
  • gNB2 takes K NG-RAN * as K gNB2 and returns the NCC value (NCC2) to gNB1.
  • Step S6112 includes:
  • Step S6112a Send a handshake request, including NCC2;
  • Step S6112b Obtain K gNB2 ;
  • the encoded NCC value [NCC2] NCC2 xor H(C-RNTI_1).
  • the encoded NCC value [NCC2] H(NCC2 xor H(C-RNTI_1)).
  • the encoded NCC value [NCC2] NCC2 xor Indicator xor T3 xor H(C-RNTI_1).
  • the encoded NCC value [NCC2] H(NCC1 xor Indicator xor C-RNTI_1).
  • the encoded NCC value [NCC2] H(NCC1 xor Indicator xor T3 xor C-RNTI_1).
  • Indicator represents the first indicator (keySetChangeIndicator)
  • T3 represents the third time information, which is the current time when the candidate or target gNB generates [NCC2]
  • H() represents hash operation
  • xor represents XOR operation.
  • Step S6114 Send MAC CE.
  • gNB1 includes the plaintext of NCC2 and the encoded NCC value [NCC2] in the MAC CE sent to the UE.
  • NCC verification can be done by comparing [received NCC2 xor H(C-RNTI_1)] with the received [NCC2].
  • the UE detaches from the serving or source gNB and applies the configuration of the target gNB (candidate gNB2), including using KNG-RAN * as KgNB2 to be used with gNB2.
  • NCC2’ [NCC2]xor H(C-RNTI_1).
  • NCC2’ [NCC2]xor Indicator xor H(C-RNTI_1).
  • NCC2’ [NCC2]xor Indicator xor T4 xor H(C-RNTI_1).
  • the UE can compare the calculated NCC1’ with NCC1 to determine the verification result.
  • [NCC2]’ NCC2 xor H(C-RNTI_1).
  • [NCC2]’ H(NCC2 xor H(C-RNTI_1)).
  • [NCC2]’ NCC2 xor Indicator xor H(C-RNTI_1).
  • [NCC2]’ H(NCC2 xor Indicator xor H(C-RNTI_1)).
  • [NCC2]’ NCC2 xor Indicator xor T4 xor H(C-RNTI_1).
  • [NCC2]’ H(NCC2 xor Indicator xor T4 xor H(C-RNTI_1)).
  • the UE can compare the calculated [NCC1]’ with [NCC1] to determine the verification result of NCC1.
  • Indicator represents the first indicator (keySetChangeIndicator)
  • T4 represents the fourth time information, which is the current time when the UE verifies NCC2
  • H() represents hash operation
  • xor represents XOR operation.
  • Step S6116 The UE sends an RRC reconfiguration complete message to gNB2.
  • Step S6117 N2 path switching.
  • the target gNB (gNB2) sends an N2 path switching request to the AMF, and the AMF returns a new NH and NCC (NH3, NCC3) to gNB2.
  • Step S6118 Execute subsequent procedures.
  • This disclosure also provides an apparatus for implementing any of the above methods.
  • an apparatus is provided that includes units or modules for implementing the steps performed by the terminal in any of the above methods.
  • another apparatus is provided that includes units or modules for implementing the steps performed by a network device (e.g., an access network device, a core network functional node, a core network device, etc.) in any of the above methods.
  • a network device e.g., an access network device, a core network functional node, a core network device, etc.
  • the division of units or modules in the above device is only a logical functional division. In actual implementation, they can be fully or partially integrated into a single physical entity, or they can be physically separated.
  • the units or modules in the device can be implemented by a processor calling software: for example, the device includes a processor connected to a memory containing instructions. The processor calls the instructions stored in the memory to implement any of the above methods or to implement the functions of the units or modules in the above device.
  • the processor can be, for example, a general-purpose processor, such as a Central Processing Unit (CPU) or a microprocessor, and the memory can be internal or external to the device.
  • the units or modules in the device can be implemented in the form of hardware circuits.
  • the functionality of some or all of the units or modules can be achieved through the design of these hardware circuits, which can be understood as one or more processors.
  • the hardware circuit is an application-specific integrated circuit (ASIC).
  • ASIC application-specific integrated circuit
  • the functionality of some or all of the units or modules is achieved through the design of the logical relationships between the components within the circuit.
  • the hardware circuit can be implemented using a programmable logic device (PLD). Taking a field-programmable gate array (FPGA) as an example, it can include a large number of logic gates. The connection relationships between the logic gates are configured through configuration files, thereby achieving the functionality of some or all of the units or modules. All units or modules of the above device can be implemented entirely through processor-called software, entirely through hardware circuits, or partially through processor-called software with the remaining parts implemented through hardware circuits.
  • PLD programmable logic device
  • the processor is a circuit with signal processing capabilities.
  • the processor can be a circuit with instruction read and execute capabilities, such as a Central Processing Unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), or a digital signal processor (DSP).
  • the processor can implement certain functions through the logical relationships of hardware circuits. The logical relationships of the aforementioned hardware circuits are fixed or reconfigurable.
  • the processor is a hardware circuit implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA.
  • ASIC application-specific integrated circuit
  • PLD programmable logic device
  • the process of the processor loading a configuration document and configuring the hardware circuit can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules.
  • it can also be hardware circuits designed for artificial intelligence, which can be understood as ASICs, such as Neural Network Processing Unit (NPU), Tensor Processing Unit (TPU), Deep Learning Processing Unit (DPU), etc.
  • ASICs such as Neural Network Processing Unit (NPU), Tensor Processing Unit (TPU), Deep Learning Processing Unit (DPU), etc.
  • Figure 7a is a schematic diagram of the structure of the first network device 7100 according to an embodiment of this disclosure.
  • the first network device 7100 may include at least one of a transceiver module 7101, a processing module 7102, etc.
  • the transceiver module is used to perform at least one of the communication steps such as sending and/or receiving performed by the first network device 7100 in any of the above methods, which will not be described in detail here.
  • the processing module is used to perform at least one of the other steps performed by the first network device 7100 in any of the above methods, which will not be described in detail here.
  • Figure 7b is a schematic diagram of the structure of the terminal 7200 proposed in an embodiment of this disclosure.
  • the terminal 7200 may include at least one of a transceiver module 7201, a processing module 7202, etc.
  • the transceiver module is used to perform at least one of the communication steps such as sending and/or receiving performed by the terminal 7200 in any of the above methods, which will not be described in detail here.
  • the transceiver module may include a sending module and/or a receiving module, which may be separate or integrated together.
  • the transceiver module may be interchangeable with a transceiver.
  • the processing module is used to perform at least one of the other steps performed by the terminal 7200 in any of the above methods, which will not be described in detail here.
  • the processing module may be a single module or may include multiple sub-modules.
  • the multiple sub-modules may each perform all or part of the steps required by the processing module.
  • the processing module may be interchangeable with a processor.
  • Figure 8a is a schematic diagram of the structure of the communication device 8100 proposed in an embodiment of this disclosure.
  • the communication device 8100 can be a network device (e.g., access network device, core network device, etc.), a terminal (e.g., user equipment, etc.), a chip, chip system, or processor that supports the network device in implementing any of the above methods, or a chip, chip system, or processor that supports the terminal in implementing any of the above methods.
  • the communication device 8100 can be used to implement the methods described in the above method embodiments; for details, please refer to the descriptions in the above method embodiments.
  • the communication device 8100 includes one or more processors 8101.
  • the processor 8101 can be a general-purpose processor or a dedicated processor, such as a baseband processor or a central processing unit (CPU).
  • the baseband processor can be used to process communication protocols and communication data, while the CPU can be used to control communication devices (e.g., base stations, baseband chips, terminal devices, terminal device chips, DUs or CUs, etc.), execute programs, and process program data.
  • the communication device 8100 is used to execute any of the above methods.
  • the communication device 8100 further includes one or more memories 8102 for storing instructions.
  • the memories 8102 may also be located outside the communication device 8100.
  • the communication device 8100 further includes one or more transceivers 8103.
  • the transceivers 8103 perform at least one of the communication steps such as sending and/or receiving in the above method, and the processor 8101 performs at least one of the other steps.
  • a transceiver may include a receiver and/or a transmitter, which may be separate or integrated.
  • the terms transceiver, transceiver unit, transceiver, transceiver circuit, etc. may be used interchangeably; the terms transmitter, transmitting unit, transmitter, transmitting circuit, etc., may be used interchangeably; and the terms receiver, receiving unit, receiver, receiving circuit, etc., may be used interchangeably.
  • the communication device 8100 may include one or more interface circuits 8104.
  • the interface circuit 8104 is connected to the memory 8102, and the interface circuit 8104 can be used to receive signals from the memory 8102 or other devices, and can be used to send signals to the memory 8102 or other devices.
  • the interface circuit 8104 can read instructions stored in the memory 8102 and send the instructions to the processor 8101.
  • the communication device 8100 described in the above embodiments may be a network device or a terminal, but the scope of the communication device 8100 described in this disclosure is not limited thereto, and the structure of the communication device 8100 may not be limited by FIG8a.
  • the communication device may be a standalone device or may be part of a larger device.
  • the communication device may be: (1) a standalone integrated circuit IC, or chip, or chip system or subsystem; (2) a collection of one or more ICs, optionally, the IC collection may also include storage components for storing data and programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, terminal device, smart terminal device, cellular phone, wireless device, handheld device, mobile unit, vehicle device, network device, cloud device, artificial intelligence device, etc.; (6) others, etc.
  • Figure 8b is a schematic diagram of the structure of chip 8200 according to an embodiment of this disclosure.
  • the communication device 8100 can be a chip or a chip system
  • the schematic diagram of chip 8200 shown in Figure 8b can be referenced, but is not limited thereto.
  • Chip 8200 includes one or more processors 8201, which are used to perform any of the above methods.
  • chip 8200 further includes one or more interface circuits 8202.
  • the interface circuit 8202 is connected to memory 8203, and the interface circuit 8202 can be used to receive signals from memory 8203 or other devices, and the interface circuit 8202 can be used to send signals to memory 8203 or other devices.
  • the interface circuit 8202 can read instructions stored in memory 8203 and send the instructions to processor 8201.
  • the interface circuit 8202 performs at least one of the communication steps such as sending and/or receiving in the above method (e.g., step S2101, step S3101, but not limited thereto), and the processor 8201 performs at least one of the other steps.
  • interface circuit In some embodiments, the terms interface circuit, interface, transceiver pin, transceiver, etc., can be used interchangeably.
  • chip 8200 further includes one or more memories 8203 for storing instructions.
  • all or part of the memories 8203 may be located outside of chip 8200.
  • This disclosure also proposes a storage medium storing instructions that, when executed on a communication device 8100, cause the communication device 8100 to perform any of the above methods.
  • the storage medium is an electronic storage medium.
  • the storage medium is a computer-readable storage medium, but not limited thereto; it may also be a storage medium readable by other devices.
  • the storage medium may be a non-transitory storage medium, but not limited thereto; it may also be a temporary storage medium.
  • This disclosure also provides a program product that, when executed by the communication device 8100, causes the communication device 8100 to perform any of the above methods.
  • the program product is a computer program product.
  • This disclosure also proposes a computer program that, when run on a computer, causes the computer to perform any of the above methods.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本公开实施例提供一种通信方法、第一网络设备、终端及存储介质。所述方法由第一网络设备执行,所述方法包括:向终端发送第一信息;其中,所述第一信息包含:第二信息和第三信息;所述第二信息为所述终端与第二网络设备通信保护相关的信息;所述第三信息用于对所述第二信息进行验证;所述第一网络设备为所述终端的服务网络设备,所述第二网络设备为所述终端执行切换的候选网络设备。本公开实施例提供的技术方案的通信机制可以保护网络设备和终端之间传输的数据。

Description

通信方法、第一网络设备、终端、通信系统和存储介质 技术领域
本公开涉及通信技术领域,尤其涉及一种通信方法、第一网络设备、终端、通信系统及存储介质。
背景技术
在通信技术领域中,终端和基站之间建立的接口传输数据,由于某些协议层不支持安全的相关计算,可能使得传输的数据不被受到保护,会导致传输的数据被篡改,带来安全隐患。
发明内容
针对数据不受保护的机制,需要引入安全机制来保护数据。
本公开实施例提供一种通信方法、第一网络设备、终端、通信系统及存储介质。
根据本公开实施例的第一方面,提供一种通信方法,方法由第一网络设备执行,方法包括:向终端发送第一信息;其中,第一信息包含:第二信息和第三信息;第二信息为经第二网络设备确认的信息;第三信息为基于第二信息和第四信息生成的信息;第三信息和第四信息用于对第二信息进行验证;第四信息为与第一标识关联的信息;第一标识为分配给终端的标识;第一网络设备为终端的服务网络设备,第二网络设备为终端执行切换的候选网络设备。
根据本公开实施例的第二方面,提供一种通信方法,方法由终端执行,方法包括:接收第一网络设备发送的第一信息;其中,第一信息包含:第二信息和第三信息;第二信息为经第二网络设备确认的信息;第三信息为基于第二信息和第四信息生成的信息;第三信息和第四信息用于对第二信息进行验证;第四信息为与第一标识关联的信息;第一标识为分配给终端的标识;第一网络设备为终端的服务网络设备,第二网络设备为终端执行切换的候选网络设备。
根据本公开实施例的第三方面,提供一种通信方法,方法还包括:第一网络设备向终端发送第一信息;其中,第一信息包含:第二信息和第三信息;第二信息为经第二网络设备确认的信息;第三信息为基于第二信息和第四信息生成的信息;第三信息和第四信息用于对第二信息进行验证;第四信息为与第一标识关联的信息;第一标识为分配给终端的标识;第一网络设备为终端的服务网络设备,第二网络设备为终端执行切换的候选网络设备。
根据本公开实施例的第四方面,提供一种第一网络设备,第一网络设备包括:收发模块,被配置为:向终端发送第一信息;其中,第一信息包含:第二信息和第三信息;第二信息为经第二网络设备确认的信息;第三信息为基于第二信息和第四信息生成的信息;第三信息和第四信息用于对第二信息进行验证;第四信息为与第一标识关联的信息;第一标识为分配给终端的标识;第一网络设备为终端的服务网络设备,第二网络设备为终端执行切换的候选网络设备。
根据本公开实施例的第五方面,提供一种终端,终端包括:收发模块,被配置为:接收第一网络设备发送的第一信息;其中,第一信息包含:第二信息和第三信息;第二信息为经第二网络设备确认的信息;第三信息为基于第二信息和第四信息生成的信息;第三信息和第四信息用于对第二信息进行验证;第四信息为与第一标识关联的信息;第一标识为分配给终端的标识;第一网络设备为终端的服务网络设备,第二网络设备为终端执行切换的候选网络设备。
根据本公开实施例的第六方面,提供一种通信系统,通信系统包括第一网络设备和终端,其中,第一网络设备被配置为执行第一方面的通信方法;终端被配置为执行第二方面的通信方法。
根据本公开实施例的第七方面,提供一种第一网络设备,第一网络设备包括:一个或多个处理器;其中,第一网络设备用于执行第一方面通信方法。
根据本公开实施例的第八方面,提供一种终端,终端包括:一个或多个处理器;其中,终端用于执行第二方面通信方法。
根据本公开实施例的第九方面,提供一种存储介质,其中,存储介质存储有指令,当指令在通信设备上运行时,使得通信设备执行第一方面和/或第二方面提供的通信方法。
根据本公开实施例的第十方面,提供一种通信方法,该方法由第一网络设备执行,方法包括:向终端发送第一信息;其中,第一信息包含:第二信息和第三信息;第二信息为终端与第二网络设备通信保护相关的信息;第三信息用于对第二信息进行验证;第一网络设备为终端的服务网络设备,第二网络设备为终端执行切换的候选网络设备。
根据本公开实施例的第十一方面,提供一种通信方法,该方法由终端执行,方法包括:接收第一网络设备发送的第一信息;其中,第一信息包含:第二信息和第三信息;第二信息为终端与第二网络设备通信保护相关的信息;第三信息用于对第二信息进行验证;第一网络设备为终端的服务网络设备,第二网络设备为终端执行切换的候选网络设备。
根据本公开实施例的第十二方面,提供一种第一网络设备,包括:收发模块,被配置为:向终端发送第一信息;其中,第一信息包含:第二信息和第三信息;第二信息为终端与第二网络设备通信保护相关的信息;第三信息用于对第二信息进行验证;第一网络设备为终端的服务网络设备,第二网络设备为终端执行切换的候选网络设备。
根据本公开实施例的第十三方面,提供一种终端,包括:收发模块,被配置为:接收第一网络设备发送的第一信息;其中,第一信息包含:第二信息和第三信息;第二信息为终端与第二网络设备通信保护相关的信息;第三信息用于对第二信息进行验证;第一网络设备为终端的服务网络设备,第二网络设备为终端执行切换的候选网络设备。
根据本公开实施例的第十四方面,提供一种通信系统,包括第一网络设备和终端,第一网络设备被配置为执行第十方面的通信方法,终端被配置为执行第十一方面的通信方法。
根据本公开实施例中第十五方面,提供一种第一网络设备,包括:一个或多个处理器;其中,第一网络设备用于执行第十方面通信方法。
根据本公开实施例的第十六方面,提供一种终端,包括:一个或多个处理器;其中,终端用于执行第十一方面通信方法。
根据本公开实施例的第十七方面,提供一种存储介质,其中,存储介质存储有指令,当指令在通信设备上运行时,使得通信设备执行第十方面和/或第十一方面提供的通信方法。
根据本公开实施例的第十八方面,提出了一种计算机程序产品,包括计算机程序,计算机程序被处理器执行时实现第十方面和/或第十一方面的通信方法。
根据本公开实施例的第十九方面,提出了一种计算机程序,该计算机程序包括代码,代码在被处理器执行时实现第十方面和/或第十一方面的通信方法。
根据本公开实施例的第二十方面,提供了一种芯片或芯片系统,该芯片或芯片系统包括处理电路,处理电路被配置为执行如第十方面和/或第十一方面的通信方法。
本公开实施例提供的技术方案的通信机制可以保护网络设备和终端之间传输的数据。
应当理解的是,以上的一般描述和后文的细节描述仅是示例性和解释性的,并不能限制本公开实施例。
附图说明
此处的附图被并入说明书中并构成本说明书的一部分,示出了符合本发明实施例,并与说明书一起用于解释本发明实施例的原理。
图1a是根据一示例性实施例示出的一种通信系统的架构示意图;
图1b是根据一示例性实施例示出的一种通信方法的示意图;
图1c是根据一示例性实施例示出的一种安全处理的示意图;
图1d是根据一示例性实施例示出的一种MAC CE信令的示意图;
图1e是根据一示例性实施例示出的一种通信方法的示意图;
图1f是根据一示例性实施例示出的一种通信方法的示意图;
图2a是根据一示例性实施例示出的一种通信方法的流程示意图;
图3a是根据一示例性实施例示出的一种通信方法的流程示意图;
图3b是根据一示例性实施例示出的一种通信方法的流程示意图;
图4a是根据一示例性实施例示出的一种通信方法的流程示意图;
图4b是根据一示例性实施例示出的一种通信方法的流程示意图;
图5a是根据一示例性实施例示出的一种通信方法的流程示意图;
图6a是根据一示例性实施例示出的一种通信方法的流程示意图;
图6b是根据一示例性实施例示出的一种MAC CE的示意图;
图7a是根据一示例性实施例示出的一种第一网络设备的结构示意图;
图7b是根据一示例性实施例示出的一种终端的结构示意图;
图8a是根据一示例性实施例示出的一种UE的结构示意图;
图8b是根据一示例性实施例示出的一种通信设备的结构示意图。
具体实施方式
本公开实施例提供一种通信方法、第一网络设备、终端、通信系统及存储介质。
第一方面,本公开实施例提供了一种通信方法,方法由第一网络设备执行,方法包括:向终端发送第一信息;其中,第一信息包含:第二信息和第三信息;第二信息为经第二网络设备确认的信息;第三信息为基于第二信息和第四信息生成的信息;第三信息和第四信息用于对第二信息进行验证;第四信息为与第一标识关联的信息;第一标识为分配给终端的标识;第一网络设备为终端的服务网络设备,第二网络设备为终端执行切换的候选网络设备。
在上述实施例中,由于第一信息包含了从第二网络设备获得的经确认的第二信息以及基于第二信息和第四信息生成的第三信息,在向终端发送第一信息后,终端就可以基于第三信息和第四信息对第二信息进行验证,确保接收到的第二信息未被篡改,如此,使得后续基于第二信息的处理会更加安全。
结合第一方面的一些实施例,在一些实施例中,第一标识为层1L1或者层2L2触发的移动性LTM过程中初始网络设备为服务网设备分配的终端标识。
在上述实施例中,LTM过程中初始接入设备能够给第一网络设备分配终端标识。
结合第一方面的一些实施例,在一些实施例中,向终端发送第一信息,包括:向终端发送第一媒体接入控制MAC控制元素CE消息;其中,第一MAC CE消息包含第一信息。
在上述实施例中,可以通过第一MAC CE消息向终端发送第一信息,可以复用MAC CE消息,减少信令开销。
结合第一方面的一些实施例,在一些实施例中,向终端发送第一信息,包括:在终端与第一网络设备执行基站间LTM过程中,向终端发送第一信息。
在上述实施例中,可以复用终端与第一网络设备执行基站间LTM过程向终端发送第一信息。
结合第一方面的一些实施例,在一些实施例中,在终端与第一网络设备执行基站间LTM过程中,向终端发送第一信息,包括以下至少一者:在终端与第一网络设备执行初始基站间LTM过程中,向终端发送第一信息;在终端与第一网络设备执行后续基站间LTM过程中,向终端发送第一信息。
在上述实施例中,可以在终端与第一网络设备执行初始基站间LTM过程中或者在终端与第一网络设备执行后续基站间LTM过程中向终端发送第一信息,发送方式会更加灵活。
结合第一方面的一些实施例,在一些实施例中,方法还包括:确定第二信息;向第二网络设备发送第二信息;接收第二网络设备发送的经确认的第二信息。
在上述实施例中,在确定第二信息后会发送给第二网络设备进行确认,使得第二信息为第二网络设备确认后的第二信息。
结合第一方面的一些实施例,在一些实施例中,方法包括:基于第二信息和第四信息生成第三信息。
在上述实施例中,可以基于第二信息和第四信息生成第三信息,如此,终端在接收到第一信息后,终端就可以基于第三信息和第四信息对第二信息进行验证。
结合第一方面的一些实施例,在一些实施例中,第二信息为第一下一跳变计数器参数NCC;基于第二信息和第四信息生成第三信息,包括:利用第四信息对第一NCC进行编码,得到第三信息。
在上述实施例中,可以基于第四信息对第一NCC进行编码得到编码后的第三信息。
结合第一方面的一些实施例,在一些实施例中,利用第四信息对第一NCC进行编码,得到第三信息,包括:执行第四信息与第一NCC的异或操作,得到第三信息。
在上述实施例中,可以通过执行第四信息与第一NCC的异或操作对第一NCC进行编码得到编码后的第三信息。
结合第一方面的一些实施例,在一些实施例中,方法还包括:执行针对第一标识的哈希hash处理,得到第四信息。
在上述实施例中,可以通过执行针对第一标识的hash处理得到第四信息。
结合第一方面的一些实施例,在一些实施例中,第一标识为以下至少一者:分配给终端的小区无线网络临时标识C-RNTI;分配给终端的LTM专用标识;分配给终端的随机数。
在上述实施例中,第一标识的选取可以更加灵活。
第二方面,本公开实施例提供了一种通信方法,方法由终端执行,方法包括:接收第一网络设备发送的第一信息;其中,第一信息包含:第二信息和第三信息;第二信息为经第二网络设备确认的信息;第三信息为基于第二信息和第四信息生成的信息;第三信息和第四信息用于对第二信息进行验证;第四信息为与第一标识关联的信息;第一标识为分配给终端的标识;第一网络设备为终端的服务网络设备,第二网络设备为终端执行切换的候选网络设备。
结合第二方面的实施例,在一些实施例中,第一标识为LTM过程中初始网络设备为服务网设备分配的终端标识。
结合第二方面的实施例,在一些实施例中,接收第一网络设备发送的第一信息,包括:接收第一网络设备发送的第一MAC CE消息;其中,第一MAC CE消息包含第一信息。
结合第二方面的实施例,在一些实施例中,接收第一网络设备发送的第一信息,包括:在终端与第一网络设备执行基站间LTM过程中,接收第一网络设备发送的第一信息。
结合第二方面的实施例,在一些实施例中,在终端与第一网络设备执行基站间LTM过程中,接收第一网络设备发送的第一信息,包括:在终端与第一网络设备执行初始基站间LTM过程中,接收第一网络设备发送的第一信息;在终端与第一网络设备执行后续基站间LTM过程中,接收第一网络设备发送的第一信息。
结合第二方面的实施例,在一些实施例中,第二信息为第一下一跳变计数器参数NCC,第三信息为利用第四信息对第一NCC进行编码获得的安全信息。
结合第二方面的实施例,在一些实施例中,第三信息为执行第一NCC与第四信息的异或操作后获得的安全信息。
结合第二方面的实施例,在一些实施例中,第四信息为针对第一标识执行哈希hash处理得到的信息。
结合第二方面的实施例,在一些实施例中,第一标识为以下至少一者:分配给终端的小区无线网络临时标识C-RNTI;分配给终端的LTM专用标识;分配给终端的随机数。
结合第二方面的实施例,在一些实施例中,方法还包括:基于第二信息、第三信息和第四信息验证第二信息;其中,第一网络设备和终端共享第四信息。
结合第二方面的实施例,在一些实施例中,基于第二信息、第三信息和第四信息验证第二信息,包括:基于第四信息解码第三信息,得到第五信息;基于第二信息和第五信息的比较结果,确定第二信息是否通过验证。
结合第二方面的实施例,在一些实施例中,基于第二信息和第五信息的比较结果,确定第二信息是否通过验证,包括以下至少之一:确定第二信息与第五信息相同,确定第二信息通过验证;确定第二信息与第五信息不同,确定第二信息未通过验证。
结合第二方面的实施例,在一些实施例中,基于第二信息、第三信息和第四信息验证第二信息,包括:基于第四信息对第二信息进行编码,得到第六信息;基于第三信息和第六信息的比较结果,确定第二信息是否通过验证。
结合第二方面的实施例,在一些实施例中,基于第三信息和第六信息的比较结果,确定第二信息是否通过验证,包括:确定第三信息与第六信息相同,确定第二信息通过验证;确定第三信息与第六信息不同,确定第二信息未通过验证。
结合第二方面的实施例,在一些实施例中,方法还包括:执行针对第一标识的哈希hash处理,得到第三信息。
第三方面,本公开实施例提供了一种通信方法,方法还包括:第一网络设备向终端发送第一信息;其中,第一信息包含:第二信息和第三信息;第二信息为经第二网络设备确认的信息;第三信息为基于第二信息和第四信息生成的信息;第三信息和第四信息用于对第二信息进行验证;第四信息为与第一标识关联的信息;第一标识为分配给终端的标识;第一网络设备为终端的服务网络设备,第二网络设备为终端执行切换的候选网络设备。
第四方面,本公开实施例提供了一种第一网络设备,第一网络设备包括:收发模块,被配置为:向终端发送第一信息;其中,第一信息包含:第二信息和第三信息;第二信息为经第二网络设备确认的信息;第三信息为基于第二信息和第四信息生成的信息;第三信息和第四信息用于对第二信息进行验证;第四信息为与第一标识关联的信息;第一标识为分配给终端的标识;第一网络设备为终端的服务网络设备,第二网络设备为终端执行切换的候选网络设备。
第五方面,本公开实施例提供了一种终端,终端包括:收发模块,被配置为:接收第一网络设备发送的第一信息;其中,第一信息包含:第二信息和第三信息;第二信息为经第二网络设备确认的信息;第三信息为基于第二信息和第四信息生成的信息;第三信息和第四信息用于对第二信息进行验证;第四信息为与第一标识关联的信息;第一标识为分配给终端的标识;第一网络设备为终端的服务网络设备,第二网络设备为终端执行切换的候选网络设备。
第六方面,本公开实施例提供了一种通信系统,通信系统包括第一网络设备和终端,其中,第一网络设备被配置为执行第一方面的通信方法;终端被配置为第二方面的通信方法。
第七方面,本公开实施例提供了一种第一网络设备,第一网络设备包括:一个或多个处理器;其中,第一网络设备用于执行第一方面通信方法。
第八方面,本公开实施例提供一种终端,终端包括:一个或多个处理器;其中,终端用于执行第二方面通信方法。
第九方面,本公开实施例提供了一种存储介质,其中,存储介质存储有指令,当指令在通信设备上运行时,使得通信设备执行第一方面和/或第二方面的可选实现方式所描述的通信方法。
第十方面,本公开实施例提出了程序产品,上述程序产品被通信设备执行时,使得上述通信设备执行如第一方面和/或第二方面的可选实现方式所描述的方法。
第十一方面,本公开实施例提出了计算机程序,当其在计算机上运行时,使得计算机执行如第一方面和/或第二方面的可选实现方式所描述的方法。
第十二方面,本公开实施例提供了一种芯片或芯片系统。该芯片或芯片系统包括处理电路,被配置为执行根据上述第一方面和/或第二方面的可选实现方式所描述的方法。
第十三方面,本公开实施例提供一种通信方法,该方法由第一网络设备执行,方法包括:向终端发送第一信息;其中,第一信息包含:第二信息和第三信息;第二信息为终端与第二网络设备通信保护相关的信息;第三信息用于对第二信息进行验证;第一网络设备为终端的服务网络设备,第二网络设备为终端执行切换的候选网络设备。
结合第十三方面的一些实施例,在一些实施例中,第三信息是至少基于第二信息和第四信息生成的信息,第四信息用于对第二信息进行保护,第四信息为与第一标识关联的信息,第一标识为分配给终端的标识。
结合第十三方面的一些实施例,在一些实施例中,第一标识为层1L1或者层2L2触发的移动性LTM过程中初始网络设备为服务网设备分配的终端标识。
结合第十三方面的一些实施例,在一些实施例中,方法还包括:确定第二信息;向第二网络设备发送第二信息;接收第二网络设备发送的经确认的第二信息。
结合第十三方面的一些实施例,在一些实施例中,第一信息还包括第一指示符,第一指示符用于向终端指示是否基于第二信息生成第一密钥,第一密钥用于终端与第二网络设备通信。
结合第十三方面的一些实施例,在一些实施例中,方法还包括以下之一:基于第二信息和第四信息,生成第三信息;基于第二信息、第四信息和第一指示符,生成第三信息;基于第二信息、第四信息、第一指示符和第一时间信息,生成第三信息,第一时间信息为第一网络设备生成第三信息的当前时间;其中,第四信息为与第一标识关联的信息,第一标识为分配给终端的标识。
结合第十三方面的一些实施例,在一些实施例中,第二信息为第一下一跳变计数器参数NCC;方法还包括以下之一:利用第四信息对第一NCC进行编码,得到第三信息。利用第四信息对第一指示符和第一NCC进行编码,得到第三信息;利用第四信息和第一时间信息对第一指示符和第一NCC进行编码,得到第三信息。
结合第十三方面的一些实施例,在一些实施例中,方法还包括以下之一:执行第四信息与第一NCC的异或操作,得到第三信息;将第一异或值进行哈希处理,得到第三信息;第一异或值为第四信息与第一NCC异或操作后得到的;执行第四信息、第一NCC和第一指示符的异或操作,得到第三信息;将第二异或值进行哈希处理,得到第三信息;第二异或值为第四信息、第一指示符和第一NCC异或操作后得到的;执行第四信息、第一NCC、第一指示符和第一时间信息的异或操作,得到第三信息;将第三异或值进行哈希处理,得到第三信息;第三异或值为第四信息、第一指示符、第一NCC和第一时间信息异或操作后得到的。
结合第十三方面的一些实施例,在一些实施例中,第四信息是第一网络设备通过对第一标识进行哈希处理后得到的,或者,第四信息为第一标识。
结合第十三方面的一些实施例,在一些实施例中,向终端发送第一信息,包括:向终端发送第一媒体接入控制MAC控制元素CE消息;其中,第一MAC CE消息包含第一信息。
结合第十三方面的一些实施例,在一些实施例中,向终端发送第一信息,包括:在终端与第一网络设备执行基站间LTM过程中,向终端发送第一信息。
结合第十三方面的一些实施例,在一些实施例中,在终端与第一网络设备执行基站间LTM的过程中,向终端发送第一信息,包括以下至少一者:在终端与第一网络设备执行初始基站间LTM过程中,向终端发送第一信息;在终端与第一网络设备执行后续基站间LTM过程中,向终端发送第一信息。
结合第十三方面的一些实施例,在一些实施例中,第一标识为以下至少一者:分配给终端的小区无线网络临时标识C-RNTI;分配给终端的LTM专用标识;分配给终端的随机数。
第十四方面,本公开实施例提供一种通信方法,由终端执行,该方法包括:接收第一网络设备发送的第一信息;其中,第一信息包含:第二信息和第三信息;第二信息为终端与第二网络设备通信保护相关的信息;第三信息用于对第二信息进行验证;第一网络设备为终端的服务网络设备,第二网络设备为终端执行切换的候选网络设备。
结合第十四方面的一些实施例,在一些实施例中,第一标识为LTM过程中初始网络设备为服务网设备分配的终端标识。
结合第十四方面的一些实施例,在一些实施例中,第一信息还包括第一指示符,第一指示符用于向终端指示是否基于第二信息生成第一密钥,第一密钥用于终端与第二网络设备通信。
结合第十四方面的一些实施例,在一些实施例中,第三信息是基于第二信息和第四信息生成的;或者,第三信息是基于第二信息、第四信息和第一指示符生成的;或者,第三信息是基于第二信息、第四信息、第一指示符和第一时间信息生成的,第一时间信息为第一网络设备生成第三信息的当前时间;其中,第四信息为与第一标识关联的信息,第一标识为分配给终端的标识。
结合第十四方面的一些实施例,在一些实施例中,第二信息为第一下一跳变计数器参数NCC,第三信息为利用第四信息对第一NCC进行编码获得的安全信息,或者,第三信息为利用第四信息对第一指示符和第一NCC进行编码获得的安全信息;第三信息为利用第四信息和第一时间信息对第一指示符和第一NCC进行编码获得的安全信息。
结合第十四方面的一些实施例,在一些实施例中,第三信息为执行第一NCC与第四信息的异或操作后获得的安全信息;或者,第三信息为将第一异或值进行哈希处理后获得的安全信息,第一异或值为第四信息与第一NCC异或操作后得到的;或者,第三信息为执行第四信息、第一NCC和第一指示符的异或操作后获得的安全信息;或者,第三信息为将第二异或值进行哈希处理后获得的安全信息,第二异或值为第四信息、第一NCC和第一指示符异或操作后得到的;或者,第三信息为执行第四信息、第一NCC、第一指示符和第一时间信息的异或操作后获得的安全信息;或者,第三信息为将第三异或值进行哈希处理后获得的安全信息,第三异或值为第四信息、第一NCC、第一指示符和第一时间信息异或操作后得到的。
结合第十四方面的一些实施例,在一些实施例中,第四信息为第一网络设备针对第一标识执行哈希hash处理得到的信息,或者,第四信息为第一标识。
结合第十四方面的一些实施例,在一些实施例中,方法还包括以下之一:基于第二信息、第三信息和第七信息,验证第二信息;基于第二信息、第三信息、第七信息和第一指示符,验证第二信息;基于第二信息、第三信息、第七信息、第一指示符和第二时间信息,验证第二信息;其中,第七信息与第一标识关联,第二时间信息为终端验证第二信息的当前时间。
结合第十四方面的一些实施例,在一些实施例中,方法还包括以下之一:基于第七信息,对第三信息进行解码,得到第五信息;基于第七信息和第一指示符,对第三信息进行解码,得到第五信息;基于第七信息、第一指示符和第二时间信息,对第三信息进行解码,得到第五信息;其中,第五信息用于验证第二信息。
结合第十四方面的一些实施例,在一些实施例中,方法还包括:基于第二信息和第五信息的比较结果,确定第二信息是否通过验证。
结合第十四方面的一些实施例,在一些实施例中,基于第二信息和第五信息的比较结果,确定第二信息是否通过验证,包括以下至少之一:确定第二信息与第五信息相同,确定第二信息通过验证;确定第二信息与第五信息不同,确定第二信息未通过验证。
结合第十四方面的一些实施例,在一些实施例中,方法还包括以下之一:基于第七信息对第二信息进行编码,得到第六信息;基于第七信息对第二信息和第一指示符进行编码,得到第六信息;基于第七信息和第二时间信息对第二信息和第一指示符进行编码,得到第六信息;其中,第六信息用于验证第二信息。
结合第十四方面的一些实施例,在一些实施例中,方法还包括以下之一:执行第七信息与第二信息的异或操作,得到第六信息;将第四异或值进行哈希处理,得到第六信息,第四异或值为第七信息与第二信息异或操作后得到的;执行第七信息、第二信息和第一指示符的异或操作,得到第六信息;将第五异或值进行哈希处理,得到第六信息,第五异或值为第七信息、第二信息和第一指示符异或操作后得到的;执行第七信息、第二信息、第一指示符和第二时间信息的异或操作,得到第六信息;将第六异或值进行哈希处理,得到第六信息,第六异或值为第七信息、第二信息、第一指示符和第二时间信息异或操作后得到的。
结合第十四方面的一些实施例,在一些实施例中,方法还包括:基于第三信息和第六信息的比较结果,确定第二信息是否通过验证。
结合第十四方面的一些实施例,在一些实施例中,基于第三信息和第六信息的比较结果,确定第二信息是否通过验证,包括:确定第三信息与第六信息相同,确定第二信息通过验证;确定第三信息与第六信息不同,确定第二信息未通过验证。
结合第十四方面的一些实施例,在一些实施例中,第七信息为终端通过对第一标识进行哈希处理后得到的,或者,第七信息为第一标识。
结合第十四方面的一些实施例,在一些实施例中,第二时间信息的值与第一时间信息的值相等,或者,第二时间信息的值等于第一时间信息的值加上第一偏移值。
结合第十四方面的一些实施例,在一些实施例中,接收第一网络设备发送的第一信息,包括:接收第一网络设备发送的第一MAC CE消息;其中,第一MAC CE消息包含第一信息。
结合第十四方面的一些实施例,在一些实施例中,接收第一网络设备发送的第一信息,包括:在终端与第一网络设备执行基站间LTM过程中,接收第一网络设备发送的第一信息。
结合第十四方面的一些实施例,在一些实施例中,在终端与第一网络设备执行基站间LTM的过程中,接收第一网络设备发送的第一信息,包括:在终端与第一网络设备执行初始基站间LTM过程中,接收第一网络设备发送的第一信息;在终端与第一网络设备执行后续基站间LTM过程中,接收第一网络设备发送的第一信息。
结合第十四方面的一些实施例,在一些实施例中,第一标识为以下至少一者:分配给终端的小区无线网络临时标识C-RNTI;分配给终端的LTM专用标识;分配给终端的随机数。
第十五方面,提供一种通信系统,包括第一网络设备和终端,第一网络设备被配置为执行第十三方面的通信方法,终端被配置为执行第十四方面的通信方法。
第十六方面,提供一种第一网络设备,包括:一个或多个处理器;其中,第一网络设备用于执行第十三方面通信方法。
第十七方面,提供一种终端,包括:一个或多个处理器;其中,终端用于执行第十四方面通信方法。
第十八方面,提供一种存储介质,其中,存储介质存储有指令,当指令在通信设备上运行时,使得通信设备执行第十三方面和/或第十四方面提供的通信方法。
第十九方面,提出了一种计算机程序产品,包括计算机程序,计算机程序被处理器执行时实现第十三方面和/或第十四方面的通信方法。
第二十方面,提出了一种计算机程序,该计算机程序包括代码,代码在被处理器执行时实现第十三方面和/或第十四方面的通信方法。
第二十一方面,提供了一种芯片或芯片系统,该芯片或芯片系统包括处理电路,处理电路被配置为执行如第十三方面和/或第十四方面的通信方法。
可以理解地,上述第一网络设备、终端、通信系统及存储介质、程序产品、计算机程序、芯片或芯片系统均用于执行本公开实施例所提出的方法。因此,其所能达到的有益效果可以参考对应方法中的有益效果,此处不再赘述。
本公开实施例提出了一种通信方法。在一些实施例中,通信方法与信息指示方法、信息处理方法、信息传输方法等术语可以相互替换,通信系统、信息处理系统等术语可以相互替换。
本公开实施例并非穷举,仅为部分实施例的示意,不作为对本公开保护范围的具体限制。在不矛盾的情况下,某一实施例中的每个步骤均可以作为独立实施例来实施,且各步骤之间可以任意组合,例如,在某一实施例中去除部分步骤后的方案也可以作为独立实施例来实施,且在某一实施例中各步骤的顺序可以任意交换,另外,某一实施例中的可选实现方式可以任意组合;此外,各实施例之间可以任意组合,例如,不同实施例的部分或全部步骤可以任意组合,某一实施例可以与其他实施例的可选实现方式任意组合。
在各本公开实施例中,如果没有特殊说明以及逻辑冲突,各实施例之间的术语和/或描述具有一致性,且可以互相引用,不同实施例中的技术特征根据其内在的逻辑关系可以组合形成新的实施例。
本公开实施例中所使用的术语只是为了描述特定实施例的目的,而并非作为对本公开的限制。
在本公开实施例中,除非另有说明,以单数形式表示的元素,如“一个”、“一种”、“该”、“上述”、“所述”、“前述”、“这一”等,可以表示“一个且只有一个”,也可以表示“一个或多个”、“至少一个”等。例如,在翻译中使用如英语中的“a”、“an”、“the”等冠词(article)的情况下,冠词之后的名词可以理解为单数表达形式,也可以理解为复数表达形式。
在本公开实施例中,“多个”是指两个或两个以上。
在一些实施例中,“至少一者(至少一项、至少一个)(at least one of)”、“一个或多个(one or more)”、“多个(a plurality of)”、“多个(multiple)等术语可以相互替换。
在一些实施例中,“A、B中的至少一者”、“A和/或B”、“在一情况下A,在另一情况下B”、“响应于一情况A,响应于另一情况B”等记载方式,根据情况可以包括以下技术方案:在一些实施例中A(与B无关地执行A);在一些实施例中B(与A无关地执行B);在一些实施例中从A和B中选择执行(A和B被选择性执行);在一些实施例中A和B(A和B都被执行)。当有A、B、C等更多分支时也类似上述。
在一些实施例中,“A或B”等记载方式,根据情况可以包括以下技术方案:在一些实施例中A(与B无关地执行A);在一些实施例中B(与A无关地执行B);在一些实施例中从A和B中选择执行(A和B被选择性执行)。当有A、B、C等更多分支时也类似上述。
本公开实施例中的“第一”、“第二”等前缀词,仅仅为了区分不同的描述对象,不对描述对象的位置、顺序、优先级、数量或内容等构成限制,对描述对象的陈述参见权利要求或实施例中上下文的描述,不应因为使用前缀词而构成多余的限制。例如,描述对象为“字段”,则“第一字段”和“第二字段”中“字段”之前的序数词并不限制“字段”之间的位置或顺序,“第一”和“第二”并不限制其修饰的“字段”是否在同一个消息中,也不限制“第一字段”和“第二字段”的先后顺序。再如,描述对象为“等级”,则“第一等级”和“第二等级”中“等级”之前的序数词并不限制“等级”之间的优先级。再如,描述对象的数量并不受序数词的限制,可以是一个或者多个,以“第一装置”为例,其中“装置”的数量可以是一个或者多个。此外,不同前缀词修饰的对象可以相同或不同,例如,描述对象为“装置”,则“第一装置”和“第二装置”可以是相同的装置或者不同的装置,其类型可以相同或不同;再如,描述对象为“信息”,则“第一信息”和“第二信息”可以是相同的信息或者不同的信息,其内容可以相同或不同。
在一些实施例中,“包括A”、“包含A”、“用于指示A”、“携带A”,可以解释为直接携带A,也可以解释为间接指示A。
在一些实施例中,“时频(time/frequency)”、“时频域”等术语是指时域和/或频域。
在一些实施例中,“响应于……”、“响应于确定……”、“在……的情况下”、“在……时”、“当……时”、“若……”、“如果……”等术语可以相互替换。
在一些实施例中,“大于”、“大于或等于”、“不小于”、“多于”、“多于或等于”、“不少于”、“高于”、“高于或等于”、“不低于”、“以上”等术语可以相互替换,“小于”、“小于或等于”、“不大于”、“少于”、“少于或等于”、“不多于”、“低于”、“低于或等于”、“不高于”、“以下”等术语可以相互替换。
在一些实施例中,装置等可以解释为实体的、也可以解释为虚拟的,其名称不限定于实施例中所记载的名称,“装置”、“设备(equipment)”、“设备(device)”、“电路”、“网元”、“节点”、“功能”、“单元”、“部件(section)”、“系统”、“网络”、“芯片”、“芯片系统”、“实体”、“主体”等术语可以相互替换。
在一些实施例中,“网络”可以解释为网络中包含的装置(例如,接入网设备、核心网设备等)。
在一些实施例中,“接入网设备(access network device,AN device)”、“无线接入网设备(radio access network device,RAN device)”、“基站(base station,BS)”、“无线基站(radio base station)”、“固定台(fixed station)”、“节点(node)”、“接入点(access point)”、“发送点(transmission point,TP)”、“接收点(reception point,RP)”、“发送和/或接收点(transmission/reception point,TRP)”、“面板(panel)”、“天线面板(antenna panel)”、“天线阵列(antenna array)”、“小区(cell)”、“宏小区(macro cell)”、“小型小区(small cell)”、“毫微微小区(femto cell)”、“微微小区(pico cell)”、“扇区(sector)”、“小区组(cell group)”、“服务小区”、“载波(carrier)”、“分量载波(component carrier)”、“带宽部分(bandwidth part,BWP)”等术语可以相互替换。
在一些实施例中,“终端(terminal)”、“终端设备(terminal device)”、“用户设备(user equipment,UE)”、“用户终端(user terminal)”、“移动台(mobile station,MS)”、“移动终端(mobile terminal,MT)”、订户站(subscriber station)、移动单元(mobile unit)、订户单元(subscriber unit)、无线单元(wireless unit)、远程单元(remote unit)、移动设备(mobile device)、无线设备(wireless device)、无线通信设备(wireless communication device)、远程设备(remote device)、移动订户站(mobile subscriber station)、接入终端(access terminal)、移动终端(mobile terminal)、无线终端(wireless terminal)、远程终端(remote terminal)、手持设备(handset)、用户代理(user agent)、移动客户端(mobile client)、客户端(client)等术语可以相互替换。
在一些实施例中,接入网设备、核心网设备、或网络设备可以被替换为终端。例如,针对将接入网设备、核心网设备、或网络设备以及终端间的通信置换为多个终端间的通信(例如,设备对设备(device-to-device,D2D)、车联网(vehicle-to-everything,V2X)等)的结构,也可以应用本公开的各实施例。在该情况下,也可以设为终端具有接入网设备所具有的全部或部分功能的结构。此外,“上行”、“下行”等术语也可以被替换为与终端间通信对应的术语(例如,“侧行(side)”)。例如,上行信道、下行信道等可以被替换为侧行信道,上行链路、下行链路等可以被替换为侧行链路。
在一些实施例中,终端可以被替换为接入网设备、核心网设备、或网络设备。在该情况下,也可以设为接入网设备、核心网设备、或网络设备具有终端所具有的全部或部分功能的结构。
在一些实施例中,获取数据、信息等可以遵照所在地国家的法律法规。
在一些实施例中,可以在得到用户同意后获取数据、信息等。
此外,本公开实施例的表格中的每一元素、每一行、或每一列均可以作为独立实施例来实施,任意元素、任意行、任意列的组合也可以作为独立实施例来实施。
图1a是根据本公开实施例示出的通信系统的架构示意图。
如图1a所示,通信系统100包括终端101和网络设备102。
在一些实施例中,网络设备102可以是接入网设备或者核心网设备。
在一些实施例中,终端101例如包括手机(mobile phone)、可穿戴设备、物联网设备、具备通信功能的汽车、智能汽车、平板电脑(Pad)、带无线收发功能的电脑、虚拟现实(virtual reality,VR)终端设备、增强现实(augmented reality,AR)终端设备、工业控制(industrial control)中的无线终端设备、无人驾驶(self-driving)中的无线终端设备、远程手术(remote medical surgery)中的无线终端设备、智能电网(smart grid)中的无线终端设备、运输安全(transportation safety)中的无线终端设备、智慧城市(smart city)中的无线终端设备、智慧家庭(smart home)中的无线终端设备中的至少一者,但不限于此。
在一些实施例中,接入网设备例如是将终端接入到无线网络的节点或设备,接入网设备可以包括5G通信系统中的演进节点B(evolved NodeB,eNB)、下一代演进节点B(next generation eNB,ng-eNB)、下一代节点B(next generation NodeB,gNB)、节点B(node B,NB)、家庭节点B(home node B,HNB)、家庭演进节点B(home evolved nodeB,HeNB)、无线回传设备、无线网络控制器(radio network controller,RNC)、基站控制器(base station controller,BSC)、基站收发台(base transceiver station,BTS)、基带单元(base band unit,BBU)、移动交换中心、6G通信系统中的基站、开放型基站(Open RAN)、云基站(Cloud RAN)、其他通信系统中的基站、Wi-Fi系统中的接入节点中的至少一者,但不限于此。
在一些实施例中,本公开的技术方案可适用于Open RAN架构,此时,本公开实施例所涉及的接入网设备间或者接入网设备内的接口可变为Open RAN的内部接口,这些内部接口之间的流程和信息交互可以通过软件或者程序实现。
在一些实施例中,接入网设备可以由集中单元(central unit,CU)与分布式单元(distributed unit,DU)组成的,其中,CU也可以称为控制单元(control unit),采用CU-DU的结构可以将接入网设备的协议层拆分开,部分协议层的功能放在CU集中控制,剩下部分或全部协议层的功能分布在DU中,由CU集中控制DU,但不限于此。
在一些实施例中,核心网设备可以是一个设备,包括第一网元、第二网元等,也可以是多个设备或设备群,分别包括第一网元、第二网元等中的全部或部分。网元可以是虚拟的,也可以是实体的。核心网例如包括演进分组核心(Evolved Packet Core,EPC)、5G核心网络(5GCore Network,5GCN)、下一代核心(Next Generation Core,NGC)中的至少一者。
在一些实施例中,第一网元例如是移动管理实体(MME,Mobility Management Entity)。
在一些实施例中,第一网元用于信令处理,名称不限于此。
在一些实施例中,第二网元例如是归属签约用户服务器(HSS,Home Subscriber Server)。
在一些实施例中,第二网元用于存储签约用户信息,名称不限于此。
在一些实施例中,第三网元例如是策略与计费规则功能(PCRF,Policy and Charging Rules Function)。
在一些实施例中,第三网元用于策略提供和计费,名称不限于此。
在一些实施例中,第一网元、第二网元和/或第三网元可以与核心网设备独立。
在一些实施例中,第一网元、第二网元和/或第三网元可以是核心网设备的一部分。
可以理解的是,本公开实施例描述的通信系统是为了更加清楚的说明本公开实施例的技术方案,并不构成对于本公开实施例提出的技术方案的限定,本领域普通技术人员可知,随着系统架构的演变和新业务场景的出现,本公开实施例提出的技术方案对于类似的技术问题同样适用。
下述本公开实施例可以应用于图1a所示的通信系统100、或部分主体,但不限于此。图1a所示的各主体是例示,通信系统可以包括图1a中的全部或部分主体,也可以包括图1a以外的其他主体,各主体数量和形态为任意,各主体可以是实体的也可以是虚拟的,各主体之间的连接关系是例示,各主体之间可以不连接也可以连接,其连接可以是任意方式,可以是直接连接也可以是间接连接,可以是有线连接也可以是无线连接。
本公开各实施例可以应用于长期演进(Long Term Evolution,LTE)、LTE-Advanced(LTE-A)、LTE-Beyond(LTE-B)、SUPER 3G、IMT-Advanced、第四代移动通信系统(4th generation mobile communication system,4G)、)、第五代移动通信系统(5th generation mobile communication system,5G)、5G新空口(new radio,NR)、未来无线接入(Future Radio Access,FRA)、新无线接入技术(New-Radio Access Technology,RAT)、新无线(New Radio,NR)、新无线接入(New radio access,NX)、未来一代无线接入(Future generation radio access,FX)、Global System for Mobile communications(GSM(注册商标))、CDMA2000、超移动宽带(Ultra Mobile Broadband,UMB)、IEEE 802.11(Wi-Fi(注册商标))、IEEE 802.16(WiMAX(注册商标))、IEEE 802.20、超宽带(Ultra-WideBand,UWB)、蓝牙(Bluetooth(注册商标))、陆上公用移动通信网(Public Land Mobile Network,PLMN)网络、设备到设备(Device-to-Device,D2D)系统、机器到机器(Machine to Machine,M2M)系统、物联网(Internet of Things,IoT)系统、车联网(Vehicle-to-Everything,V2X)、利用其他通信方法的系统、基于它们而扩展的下一代系统等。此外,也可以将多个系统组合(例如,LTE或者LTE-A与5G的组合等)应用。
在一些实施例中,层1或者层2触发的移动性(LTM,L1/L2 Triggered Mobility)是指一种网络基于L1的测量结果通过媒体接入控制(MAC,Media Access Control)控制元素(CE,Control Element)触发的主小区(Pcell,Primary Cell)或者主辅小区(PSCell,Primary Secondary Cell)小区改变(cell switch)的过程,其中可以伴随着主小区组(MCG,Master Cell group)或者辅小区组(SCG,Secondary Cell group)的改变。
在一些实施例中,在LTM中,gNB从UE接收L1测量报告,基于此,gNB通过MAC CE发出的小区改变命令(cell switch command)改变UE的服务小区。Cell switch command中指示了一个gNB预先通过无线资源控制(Radio Resource Control)信令提供给UE的LTM候选小区配置。UE根据接收到的Cell switch command接入到此小区改变命令中指示的目标小区。LTM可用于减少移动性时延。其中,LTM候选小区配置只能由网络通过RRC信令进行添加、修改和释放。LTM过程可用于减少移动延迟。
在一些实施例中,LTM支持后续的(subsequent)LTM,其中Subsequent LTM是指候选小区之间的后续LTM小区切换过程,而其间没有网络的RRC重新配置。也就是说,在执行了移动性操作后,UE不会自主地删除LTM的配置信息,所述LTM的配置信息即使没有进行RRC重配和更新也能继续使用,用于触发后续的LTM(Subsequent LTM)。
在一些实施例中,LTM支持频率内和频率间移动性,包括不是当前服务小区的频率间小区的移动性。Rel-18仅支持分布式单元(DU,Distributed Unit)内和DU间中央单元(CU,Central processing Unit)内LTM。Rel-19将NR移动性增强扩展到CU间(节点间或者gNB)LTM,其支持以下场景:
情况1:未配置DC时,CU充当网络主节点(MN,Master Node);
情况2:当配置了NR-DC并且CU充当网络辅节点(SN,Secondary Node)并且MCG不变时;
情况3:当配置NR-DC时,CU充当MN并且SCG不变或SCG被释放。
在一些实施例中,对于CU间LTM,移动性流中将涉及多于一个候选gNB-CU。基于Rel-18 CU内LTM的总体过程,Rel-19 CU间LTM的信令过程在图1b中示出,并且包括以下三个阶段:
阶段1(LTM准备):基于L3无线资源管理(RRM,Radio Resource Management)测量报告,初始gNB决定候选小区并启动节点间交互以进行CU间LTM准备。在交互之后,初始gNB向UE提供具有多个候选小区的RRC配置的LTM配置。
阶段2(初始LTM执行):如在Rel-18 CU内LTM中,UE向初始gNB发送L1测量报告。在接收到小区切换命令MAC CE之后,UE切换到一个候选gNB(例如,C-gNB1)。为了支持无随机接入信道(RACH,Random Access CHannel)LTM,可以在接收小区切换命令之前执行与候选小区的DL和UL早期同步。
阶段3(后续LTM执行):在后续LTM执行阶段,执行阶段2类似的步骤。并且后续LTM由当前服务gNB触发,当前服务gNB是一个候选gNB(例如,C-gNB1)。
在一些实施例中,请参见图1c,在用于传统CU间移动性过程的切换期间,UE和目标gNB之间的接入层(AS,Access Stratum)安全密钥的同步经由源gNB使用的下一跳变计数器或者NH连锁计数器(NCC,Next hop Chaining Counter)值来实现,该NCC值然后在RRC重新配置信令中被转发给目标gNB和UE。
在一些实施例中,请参见图1c,每当需要在UE和gNB之间建立初始AS安全上下文时,接入和移动性管理功能(AMF,Access and Mobility Management Function)和UE应导出KgNB和下一跳参数(NH,Next Hop Parameter)。NCC与每个KgNB和NH参数相关联。每个KgNB与对应于从中导出它的NH值的NCC相关联。
在一些实施例中,请参见图1c,在Xn切换中,如果源gNB具有未使用的{NH,NCC}对,则源gNB应执行垂直密钥推导。如3GPP TS 33.501[1]的附件A.11/A.12中所述,源gNB应首先在水平密钥导出的情况下从当前激活的KgNB计算KNG-RAN*,或者在垂直密钥导出的情况下从NH计算KNG- RAN*。
在一些实施例中,源gNB应将{KNG-RAN*,NCC}对转发到目标gNB。目标gNB应将接收到的KNG-RAN*直接用作要与UE一起使用的KgNB。目标gNB应将从源gNB接收的NCC值与KgNB相关联。目标gNB应将接收到的NCC包括在准备好的握手(HO,Handover)命令消息中,该消息在透明容器中被发送回源gNB并由源gNB转发给UE。
在一些实施例中,除了在gNB-CU内切换期间,UE可以基于来自gNB的指示保留相同密钥之外,无论切换是gNB-CU内切换、Xn还是N2,UE行为都是相同的。在条件切换的情况下,UE行为也是相同的,如3GPP TS 38.300[2]中所规定的,即,UE应在KNG-RAN*推导中使用所选目标小区的参数。
在一些实施例中,如果UE经由源gNB在HO命令消息中从目标gNB接收的NCC值等于与当前激活的KgNB相关联的NCC值,则UE应使用3GPP TS 33.501[1]的附录A.11和A.12中定义的函数从当前激活的KgNB和物理小区标识(PCI,Physical Cell Identifier)及其下行频率绝对无线频率信道号(ARFCN,Absolute Radio Frequency Channel Number)或者下行长期演进无线接入网络绝对无线电频道号码(EARFCN,E-UTRA Absolute Radio Frequency Channel Number))导出KNG-RAN*。
在一些实施例中,如果UE接收到与当前激活的KgNB相关联的NCC不同的NCC值,则UE应首先通过迭代地计算3GPP TS 33.501[1]的附录A.10中定义的函数(并且增加NCC值直到其与经由HO命令消息从源gNB接收的NCC值匹配)来同步本地保持的NH参数。当NCC值匹配时,UE应使用3GPP TS 33.501[1]的附录A.11和A.12中定义的函数根据同步NH参数和目标PCI及其频率ARFCN-DL或者EARFCN-DL来计算KNG-RAN*。
在一些实施例中,当与目标gNB通信时,UE应使用KNG-RAN*作为KgNB
在一些实施例中,在当前的gNB间切换过程中,首先在源和目标gNB之间同步安全相关配置(例如,NCC、KNG-RAN*),之后在每次切换时由源gNB在RRC重新配置中向UE发送NCC。如上所述,NCC由UE用于与目标gNB进行密钥重置同步。然而,利用针对gNB间LTM定义的移动性增强过程,源gNB不在每次切换时发送RRC重新配置。然后,如何在每次切换时更新NCC值并将其发送到UE以进行密钥更新同步成为一个公开问题,3GPP为此研究了几种选项,其中以下是其中之一。
选项1:请参见图1d,使用MAC CE中的新信息来传递安全信息。UE是使用水平密钥导出还是垂直密钥导出是从MAC CE中的该新信息导出的(其当前既不是完整性保护也不是加密的)。
选项1A:将在CU间LTM执行时使用的NCC值包括在LTM小区切换命令MAC CE中。
在一些实施例中,考虑到选项对现有系统的影响,在可行性和信令开销方面,选项1A(即在LTM小区切换命令MAC CE中携带NCC值)被视为影响最小的选项。然而,该选项的主要问题是MAC CE消息不受保护,使得MAC CE消息中携带的NCC不受保护。未受保护的NCC将面临被攻击者篡改的风险。当由UE接收的NCC值被篡改时,由UE导出的密钥将不同于由目标gNB从源gNB接收和导出的密钥。UE与目标gNB之间的密钥重置的这种去同步将导致切换失败。
在一些实施例中,在当前的gNB间切换过程中,在每个切换的准备阶段,通过Uu接口经由RRC重配置信令将安全相关配置(例如,MasterKeyUpdate,NCC)从源gNB发送到UE。RRC重配置是在UE和gNB之间的AS安全性建立之后发送的,因此整个RRC重配置消息至少受到完整性保护并且不能被攻击者篡改。
在一些实施例中,对于CU间LTM增强,准备阶段仅由初始gNB执行,并且不针对每个后续切换执行,即,在用于CU间LTM增强的每个切换之前不存在准备阶段。基于这种设计,RRC重新配置信令仅由LTM准备阶段的初始gNB执行,但是在LTM准备之后的每次切换时由MAC CE消息代替。由于MAC CE消息不受保护,MAC CE消息中携带的安全相关配置无法得到保护。目前,UE和gNB之间建立的AS安全是在Uu接口上的分组数据汇聚协议(PDCP,Packet Data Convergence Protocol)层上执行的。PDCP层下面的MAC层不支持安全相关计算。因此,没有现有的安全机制来保护MAC CE消息。
因此,如何确保在MAC CE中从gNB发送到UE的安全相关参数(例如,NCC)被保护免受篡改是需要考虑的问题。
在一些实施例中,当UE附着至gNB时,服务或者源gNB将向附着的UE指派小区无线网络临时标识(C-RNTI,Cell-Radio Network Temporary Identifier)。在UE切换到目标gNB之前,当前C-RNTI仅为服务或源gNB和被指派的UE所知,而不为任何其他方所知。在传统gNB间切换期间,服务或源gNB需要在切换请求中向目标gNB发送当前C-RNTI,并且目标gNB需要将由服务或源gNB分配的当前或者旧C-RNTI和由目标gNB在切换请求确认中分配的新C-RNTI返回给服务或者源gNB,后者转发给UE。利用这种切换过程,服务或源和目标gNB都知道旧的和新的C-RNTI值,示例性地,请参见图1e的的最后3个步骤。
在一些实施例中,根据gNB间LTM的增强,C-RNTI值(包括由初始或者源gNB和候选gNB使用的C-RNTI值)全部由初始gNB分配并在LTM准备阶段(即,请参见图1f中的步骤#5)递送给UE。因此,不需要在如上所述的gNB间切换过程期间发送旧的和新的C-RNTI值。这意味着所有候选gNB仅知道其自身使用的C-RNTI值,并且除了初始或者源gNB之外,没有gNB可以知道其他gNB使用的C-RNTI值。
在一些实施例中,C-RNTI值可以被视为在服务gNB和UE之间共享的密钥。拥有候选gNB的所有C-RNTI值的初始或者源gNB实际上拥有甚至比C-RNTI值更关键的信息,使得受攻击的初始或者源gNB将攻击所有LTM执行和后续LTM执行。因此,NCC保护的讨论是基于初始或者源gNB永远不会受到攻击的假设。在这样的假设下,本发明提出使用在UE和服务gNB之间共享的C-RNTI来保护包含在MAC CE消息中的NCC值的完整性。
图2a是根据本公开实施例示出的一种通信方法的交互示意图。如图2a所示,本公开实施例涉及通信方法,用于通信系统100,方法包括:
步骤S2101:第一网络设备向终端发送第一标识。
在一些实施例中,第一网络设备给终端分配第一标识。
在一些实施例中,第一网络设备可以是初始网络设备。
在一些实施例中,初始网络设备可以是初始(initial)基站。
在一些实施例中,初始网络设备可以是LTM过程中的源基站(例如,source gnb0)。
在一些实施例中,初始网络设备向终端发送包含第一标识的信息。
在一些实施例中,可以是在LTM准备(LTM,Preraration)过程中,初始网络设备向终端发送包含第一标识的信息。
在一些实施例中,所述第一标识为以下至少一者:
分配给所述终端的小区无线网络临时标识C-RNTI;
分配给所述终端的LTM专用标识;
分配给所述终端的随机数。
示例性地,第一标识可以包括C-RNTI_0、C-RNTI_1和C-RNTI_2。
在一些实施例中,初始网络设备可以通过无线资源控制(RRC,Radio Resource Control)配置消息向终端发送包含第一标识的信息。
在一些实施例中,所述第一标识为分配给与所述第一网络设备连接的所述终端的标识。
在一些实施例中,所述第一标识为LTM过程中初始网络设备为服务网设备分配的终端标识。
步骤S2102:第一网络设备获取第二信息。
在一些实施例中,第二信息为终端与第二网络设备通信保护相关的信息。
在一些实施例中,第二信息可以为经第二网络设备确认的信息。在一些实施例中,第二信息可以无需经第二网络设备确认。
示例性地,第二信息为第一安全信息。
在一些实施例中,第二信息为第一NCC。
在一些实施例中,第一网络设备为接入网设备。
在一些实施例中,在LTM执行(LTM Execution)阶段,第一网络设备为初始基站、源基站和/或服务基站。
在一些实施例中,在后续LTM执行(Subsequent LTM Execution)阶段,第一网络设备为服务基站。
在一些实施例中,第一网络设备确定第二信息。
在一些实施例中,第一网络设备选择第二信息。
在一些实施例中,第一网络设备向第二网络设备发送第二信息。
在一些实施例中,第一网络设备接收第二网络设备发送的经确认的第二信息。
在一些实施例中,第一网络设备可以基于协议规定确定第二信息,也可以基于预设的策略或规则确定第二信息。
示例性地,第一网络设备选择第二信息;第一网络设备向第二网络设备发送第二信息;第二网络设备确认第二信息;第二网络设备向第一网络设备发送第二信息。
在一些实施例中,第二网络设备为终端执行切换的候选接入网设备,例如,候选基站。
步骤S2103:第一网络设备生成第三信息。
在一些实施例中,第一网络设备基于所述第二信息和第四信息生成所述第三信息。在一些实施例中,第一网络设备基于第二信息、第四信息和第一指示符,生成第三信息。在一些实施例中,第一网络设备基于第二信息、第四信息、第一指示符和第一时间信息,生成第三信息。
在一些实施例中,第三信息为第二安全信息。在一些实施例中,第三信息用于对第二信息进行验证。
在一些实施例中,所述第四信息为与第一标识关联的信息。在一些实施例中,第一标识用于对第二信息进行保护。在一些实施例中,第一标识用于对第二信息进行验证。在一些实施例中,第四信息用于对第二信息进行保护。在一些实施例中,第四信息用于对第二信息进行验证。
在一些实施例中,所述第四信息为针对所述第一标识进行哈希hash处理得到的信息。在一些实施例中,第四信息为第一标识。
在一些实施例中,第一指示符(keySetChangeIndicator)用于向终端指示是否基于第二信息生成第一密钥,第一密钥用于终端与第二网络设备通信。
在一些实施例中,第一指示符用于指示终端生成第一密钥的方式。
在一些实施例中,第一指示符可以用于向终端指示生成第一密钥的参数值。
在一些实施例中,第一指示符用于指示切换类型,不同切换类型时生成第一密钥使用的参数值不同。
在一些实施例中,第一指示符用于指示密钥更新类型,不同密钥更新类型生成第二密钥使用的参数值不同。
在一些实施例中,切换类型可包括节点内部小区更换、跨节点小区更换或者跨AMF的小区切换等不同类型。不同类型生成UE与第二小区通信的密钥使用的参数不同。
在一些实施例中,第一指示符可以包括一个或多个比特,示例性地,第一指示符具有一个或多个取值。例如,第一指示符具有第一取值和第二取值。
在一些实施例中,第一指示符具有第一取值,在此情况下,第一密钥是基于第二信息生成的,或者说,第一密钥的生成需要考虑第二信息。
在第一指示符具有第二取值时,在此情况下,第一密钥不是基于第二信息生成的,或者说,第一密钥的生成不需要考虑第二信息。在一些实施例中,在第一指示符具有第二取值时,说明第二密钥是UE根据KAMF生成。KAMF是UE和AMF共享的密钥,是用于生成第一密钥的中间密钥。
在一些实施例中,第一时间信息为第一网络设备生成第三信息的当前时间。在一些实施例中,第一时间信息为世界标准时间(Coordinated Universal Time,UTC)信息。可以理解地,通过在生成第三信息的过程中加入第一时间信息,接收方可以利用第一时间信息验证第三信息是否过期,从而有效拒绝重放攻击。
在一些实施例中,第一网络设备可以利用第四信息对第二信息进行编码,得到第三信息。在一些实施例中,第一网络设备可以利用第四信息对第一指示符和第二信息进行编码,得到第三信息。在一些实施例中,第一网络设备可以利用第四信息和第一时间信息对第一指示符和第二信息进行编码,得到第三信息。
在一些实施例中,第一网络设备可以执行第四信息和第二信息的异或操作,得到第三信息。在一些实施例中,第一网络设备可以对第一异或值进行哈希处理,得到第三信息,第一异或值为第四信息和第二信息异或操作后得到的。在一些实施例中,第一网络设备可以执行第四信息、第二信息和第一指示符的异或操作,得到第三信息。在一些实施例中,第一网络设备可以将第二异或值进行哈希处理,得到第三信息,第二异或值为第四信息、第一指示符和第二信息异或操作后的得到的。在一些实施例中,第一网络设备欸可以执行第四信息、第二信息、第一指示符和第一时间信息的异或操作,得到第三信息。在一些实施例中,第一网络设备可以将第三异或值进行哈希处理,得到第三信息,第三异或值为第四信息、第一指示符、第二信息和第一时间信息异或操作后得到的。
在一些实施例中,第一网络设备可以基于与运算、或运算、非运算、异或运算、同或运算、与非运算、或非运算中的一个或多个运算得到第三信息。
下面以第四信息为对第一标识(例如,C-RNTI)进行哈希处理后得到的信息为例说明第三信息的生成过程。
在一示例中,第二信息为第一NCC,即可以表示为NCC1。在一示例中,第三信息可以理解为编码后的第二信息,即表示为[NCC1]。在一示例中,哈希hash处理可以表示为H()。在一示例中,第四信息可以表示为H(C-RNTI)。在一示例中,异或操作可以表示为xor。在一示例中,第一指示符(keySetChangeIndicator)可以表示为Indicator。在一示例中,第一时间信息可以表示为T1。
在一示例中,[NCC1]=NCC1 xor H(C-RNTI)。
在一示例中,[NCC1]=H(NCC1 xor H(C-RNTI))。
在一示例中,[NCC1]=NCC1 xor Indicator xor H(C-RNTI)。
在一示例中,[NCC1]=H(NCC1 xor Indicator xor H(C-RNTI))。
在一示例中,[NCC1]=NCC1 xor Indicator xor T1 xor H(C-RNTI)。
在一示例中,[NCC1]=H(NCC1 xor Indicator xor T1 xor H(C-RNTI))。
在一些实施例中,第二信息(即NCC1)、第四信息(即H(C-RNTI))、第一指示符(即Indicator)和第一时间信息(即T1)中任意多个信息之间可以进行与运算、或运算、非运算、异或运算、同或运算、与非运算、或非运算中的一个或多个运算。
下面以第四信息为第一标识(例如,C-RNTI)为例说明第三信息的生成过程。
在一示例中,第二信息为第一NCC,即可以表示为NCC1。在一示例中,第三信息可以理解为编码后的第二信息,即表示为[NCC1]。在一示例中,哈希hash处理可以表示为H()。在一示例中,第四信息可以表示为C-RNTI。在一示例中,异或操作可以表示为xor。在一示例中,第一指示符(keySetChangeIndicator)可以表示为Indicator。在一示例中,第一时间信息可以表示为T1。
在一示例中,[NCC1]=H(NCC1 xor C-RNTI)。
在一示例中,[NCC1]=H(NCC1 xor Indicator xor C-RNTI)。
在一示例中,[NCC1]=H(NCC1 xor Indicator xor T1 xor C-RNTI)。
在一些实施例中,第二信息(即NCC1)、第四信息(C-RNTI)、第一指示符(即Indicator)和第一时间信息(即T1)中任意多个信息之间可以进行与运算、或运算、非运算、异或运算、同或运算、与非运算、或非运算中的一个或多个运算。
在一些实施例中,第一网络设备执行针对所述第一标识的哈希hash处理得到所述第四信息。
示例性地,第一网络设备执行针对所述第一标识的哈希hash处理得到所述第四信息;第一网络设备基于所述第二信息和第四信息生成所述第三信息。
在一些实施例中,所述第三信息和所述第四信息用于对所述第二信息进行验证。
在一些实施例中,所述第二信息为第一NCC(例如,NCC1);利用所述第四信息对所述第一NCC进行编码,得到所述第三信息。
示例性地,所述第二信息为第一NCC;第一网络设备执行针对所述第一标识的哈希hash处理得到所述第四信息;利用所述第四信息对所述第一NCC进行编码,得到所述第三信息。
在一些实施例中,执行所述第四信息与所述第一NCC的异或操作,得到所述第三信息。
步骤S2104:第一网络设备向终端发送第一信息。
在一些实施例中,终端接收第一网络设备发送的第一信息。
示例性地,第一信息为第三安全信息。
在一些实施例中,第一信息包含:第二信息和第三信息。在一些实施例中,第一信息还可以包含第一指示符。
在一些实施例中,向终端发送第一媒体接入控制MAC控制元素CE消息,例如,第一MAC CE消息包含第一信息。
在一些实施例中,在终端与第一网络设备执行基站间LTM过程中,向终端发送第一信息。
在一些实施例中,基站间LTM过程包括初始基站间LTM过程和后续基站间LTM过程。
在一些实施例中,在终端与第一网络设备执行基站间LTM过程中,向终端发送第一信息,包括以下至少一者:在终端与第一网络设备执行初始基站间LTM过程中,向终端发送第一信息;在终端与第一网络设备执行后续基站间LTM过程中,向终端发送第一信息。
在一些实施例中,在终端与第一网络设备执行初始基站间LTM过程中,向终端发送第一信息;其中,基站间LTM过程包括初始基站间LTM过程。
在一些实施例中,在终端与第一网络设备执行后续基站间LTM过程中,向终端发送第一信息;其中,基站件LTM过程包括后续基站间LTM过程。
步骤S2105:终端验证第二信息。
在一些实施例中,终端基于第二信息、第三信息和第七信息,验证第二信息。在一些实施例中,终端基于第二信息、第三信息、第七信息和第一指示符,验证第二信息。在一些实施例中,终端基于第二信息、第三信息、第七信息、第一指示符和第二时间信息,验证第二信息。
在一些实施例中,第七信息与第一标识关联。在一些实施例中,第七信息可以与第四信息相同,也可以与第四信息不同。在一些实施例中,第七信息为终端对第一标识进行哈希处理后得到的信息。在一些实施例中,第七信息为第一标识。
在一些实施例中,在第七信息为第一标识、第四信息为第一标识的情况下,第七信息与第四信息相同。在一些实施例中,若终端对第一标识进行哈希处理后得到的结果与第一网络设备对第一标识进行哈希处理后得到的结果相同,则第七信息与第四信息相同。在一些实施例中,若终端对第一标识进行哈希处理后得到的结果与第一网络设备对第一标识进行哈希处理后得到的结果不同,则第七信息与第四信息不同。
在一些实施例中,第二时间信息为终端验证第二信息的当前时间。在一些实施例中,第二时间信息可以为终端接收到第三信息的时间。在一些实施例中,第二时间信息与第一时间信息关联。在一些实施例中,第二时间信息的值与第一时间信息的值相等。可以理解地,若第一网络设备和终端之间的传输速度足够快,则第一网络设备生成第三信息的时间(即第一时间信息)与终端接收到第三信息的时间(即第二时间信息)相等。在一些实施例中,第二时间信息的值等于第一时间信息的值加上第一偏移值,第一偏移值为第一网络设备向终端传输第三信息的时间。在一些实施例中,第一偏移值可以理解为第一网络设备和终端之间的传输时延。在一些实施例中,终端可以获知自身与第一网络设备之间的传输时延。
在一些实施例中,终端基于第七信息,对第三信息进行解码,得到第五信息,基于第五信息验证第二信息。在一些实施例中,终端基于第七信息和第一指示符,对第三信息进行解码,得到第五信息,基于第五信息验证第二信息。在一些实施例中,终端基于第七信息、第一指示符和第二时间信息,对第三信息进行解码,得到第五信息,基于第五信息验证第二信息。
在一些实施例中,终端可以对第一网络设备生成第三信息的运算进行逆运算,得到第五信息,基于第五信息验证第二信息。在一些实施例中,若第一网络设备基于与运算得到第三信息,则终端可以基于与运算的逆运算,即与非运算,得到第五信息。在一些实施例中,若第一网络设备基于或运算得到第三信息,则终端可以基于或运算的逆运算,即或非运算,得到第五信息。在一些实施例中,若第一网络设备基于非运算得到第三信息,则终端可以基于非运算的逆运算,即非运算,得到第五信息。在一些实施例中,若第一网络设备基于异或运算得到第三信息,则终端可以基于异或运算的逆运算,即异或运算,得到第五信息。在一些实施例中,若第一网络设备基于同或运算得到第三信息,则终端可以基于同或运算的逆运算,即异或运算,得到第五信息。在一些实施例中,若第一网络设备基于与非运算得到第三信息,则终端可以基于与非运算的逆运算,即与运算,得到第五信息。在一些实施例中,若第一网络设备基于或非运算得到第三信息,则终端可以基于或非运算的逆运算,即或运算,得到第五信息。
下面以第七信息为对第一标识(例如,C-RNTI)进行哈希处理后得到的信息、第一网络设备基于异或运算得到第三信息为例,说明第五信息的生成过程。
在一示例中,第五信息为第二NCC,即可以表示为NCC1’。在一示例中,第三信息可以理解为编码后的第二信息,即表示为[NCC1]。在一示例中,哈希hash处理可以表示为H()。在一示例中,第七信息可以表示为H(C-RNTI)。在一示例中,异或操作可以表示为xor。在一示例中,第一指示符(keySetChangeIndicator)可以表示为Indicator。在一示例中,第二时间信息可以表示为T2。
在一示例中,NCC1’=[NCC1]xor H(C-RNTI)。
在一示例中,NCC1’=[NCC1]xor Indicator xor H(C-RNTI)。
在一示例中,NCC1’=[NCC1]xor Indicator xor T2 xor H(C-RNTI)。
在一些实施例中,若第五信息和第二信息相同,则第二信息通过验证。在一示例中,若NCC1和NCC1’相同,则NCC1通过验证。
在一些实施例中,若第五信息和第二信息不同,则第二信息未通过验证。在一示例中,若NCC1和NCC1’不同,则NCC1未通过验证。
在一些实施例中,终端基于第七信息对第二信息进行编码,得到第六信息,基于第六信息验证第二信息。在一些实施例中,终端基于第七信息对第二信息和第一指示符进行编码,得到第六信息,基于第六信息验证第二信息。在一些实施例中,终端基于第七信息和第二时间信息对第二信息和第一指示符进行编码,得到第六信息,基于第六信息验证第二信息。
在一些实施例中,终端可以进行与第一网络设备生成第三信息的运算相同的运算,得到第六信息,基于第六信息验证第二信息。
在一些实施例中,终端执行第七信息与第二信息的异或操作,得到第六信息。在一些实施例中,终端将第四异或值进行哈希处理,得到第六信息,第四异或值为第七信息与第二信息异或操作后得到的。在一些实施例中,终端执行第七信息、第二信息和第一指示符的异或操作,得到第六信息。在一些实施例中,终端将第五异或值进行哈希处理,得到第六信息,第五异或值为第七信息、第二信息和第一指示符异或操作后得到的。在一些实施例中,终端执行第七信息、第二信息、第一指示符和第二时间信息的异或操作,得到第六信息。在一些实施例中,将第六异或值进行哈希处理,得到第六信息,第六异或值为第七信息、第二信息、第一指示符和第二时间信息异或操作后得到的。
下面以第七信息为对第一标识(例如,C-RNTI)进行哈希处理后得到的信息、第一网络设备基于异或运算得到第三信息为例,说明第六信息的生成过程。
在一示例中,第二信息为第一NCC,即可以表示为NCC1。在一示例中,第六信息可以表示为[NCC1]’。在一示例中,哈希hash处理可以表示为H()。在一示例中,第七信息可以表示为H(C-RNTI)。在一示例中,异或操作可以表示为xor。在一示例中,第一指示符(keySetChangeIndicator)可以表示为Indicator。在一示例中,第二时间信息可以表示为T2。
在一示例中,[NCC1]’=NCC1 xor H(C-RNTI)。
在一示例中,[NCC1]’=H(NCC1 xor H(C-RNTI))。
在一示例中,[NCC1]’=NCC1 xor Indicator xor H(C-RNTI)。
在一示例中,[NCC1]’=H(NCC1 xor Indicator xor H(C-RNTI))。
在一示例中,[NCC1]’=NCC1 xor Indicator xor T2 xor H(C-RNTI)。
在一示例中,[NCC1]’=H(NCC1 xor Indicator xor T2 xor H(C-RNTI))。
下面以第七信息为第一标识、第一网络设备基于异或运算得到第三信息为例,说明第六信息的生成过程。
在一示例中,[NCC1]’=H(NCC1 xor C-RNTI)。
在一示例中,[NCC1]’=H(NCC1 xor Indicator xor C-RNTI)。
在一示例中,[NCC1]’=H(NCC1 xor Indicator xor T2 xor C-RNTI)。
在一些实施例中,若第六信息和第三信息相同,则第二信息通过验证。在一示例中,若[NCC1]和[NCC1]’相同,则NCC1通过验证。在一些实施例中,若第六信息和第三信息不同,则第二信息未通过验证。在一示例中,若[NCC1]和[NCC1]’不同,则NCC1未通过验证。
在一些实施例中,终端在接收到第一信息后,终端基于第二信息、第三信息和第四信息验证第二信息。
在一些实施例中,第一网络设备和终端共享第四信息。
在一些实施例中,终端基于第四信息解码第三信息得到第五信息。
在一些实施例中,终端基于第二信息和第五信息的比较结果确定第二信息是否通过验证。
在一些实施例中,第二信息和第五信息可能相同也可能不同。
在一些实施例中,终端基于第二信息和第五信息的比较结果确定第二信息是否通过验证,包括以下至少一者:终端确定第二信息与第五信息相同,终端确定第二信息通过验证;终端确定第二信息与第五信息不同,终端确定第二信息未通过验证。
在一些实施例中,终端确定第二信息与第五信息相同,终端确定第二信息通过验证。
在一些实施例中,终端确定第二信息与第五信息不同,终端确定第二信息未通过验证。
在一些实施例中,终端基于第四信息对第二信息进行编码得到第六信息。
在一些实施例中,终端基于第三信息和第六信息的比较结果,终端确定第二信息是否通过验证。
在一些实施例中,第三信息和第六信息可能相同也可能不同。
在一些实施例中,终端基于第三信息和第六信息的比较结果,终端确定第二信息是否通过验证,包括:终端确定第三信息与第六信息相同,终端确定第二信息通过验证;终端确定第三信息与第六信息不同,终端确定第二信息未通过验证。
在一些实施例中,终端确定第三信息与第六信息相同,终端确定第二信息通过验证。
在一些实施例中,终端确定第三信息与第六信息不同,终端确定第二信息未通过验证。
在一些实施例中,术语“信息”可以与“消息(message)”、“信号(signal)”、“信令(signaling)”、“报告(report)”、“配置(configuration)”、“指示(indication)”、“指令(instruction)”、“命令(command)”、“信道”、“参数(parameter)”、“字段”、“数据(data)”等术语可以相互替换。
在一些实施例中,术语“发送”可以与“发射”、“上报”、“传输”等术语相互替换。
本公开实施例所涉及的通信方法可以包括步骤S2101至步骤S2105中的至少一者。例如,步骤S2102可以作为独立实施例来实施,步骤S2104可以作为独立实施例来实施,步骤S2105可以作为独立实施例来实施。例如,步骤S2104结合步骤S2105可以作为独立实施例来实施,步骤S2103结合步骤S2104、步骤S2105可以作为独立实施例来实施,步骤S2102结合步骤S2103、步骤S2104、步骤S2105可以作为独立实施例来实施,步骤S2101结合步骤S2102、步骤S2103、步骤S2104、步骤S2105可以作为独立实施例来实施,但不限于此。需要说明的是,各个步骤可以独立实施,也可以在不矛盾的情况下,可以任意调换顺序,自由组合起来实施。
图3a是根据本公开实施例示出的一种通信方法的流程示意图。如图3a所示,本公开实施例涉及通信方法,由第一网络设备执行,上述方法包括:
步骤S3101:给终端分配第一标识。
在一些实施例中,步骤S3101的可选实现方式可以参见图2a的步骤S2101的可选实现方式、及图2a所涉及的实施例中其他关联部分,此处不再赘述。
步骤S3102:获取第二信息。
在一些实施例中,第一网络设备接收由第二网络设备发送的第二信息,但不限于此,也可以接收由其他主体发送的第二信息。
在一些实施例中,第一网络设备获取由协议规定的第二信息。
在一些实施例中,第一网络设备从高层(upper layer(s))获取第二信息。
在一些实施例中,第一网络设备进行处理从而得到第二信息。
在一些实施例中,步骤S3102被省略,第一网络设备自主实现第二信息所指示的功能,或上述功能为缺省或默认。
在一些实施例中,步骤S3102的可选实现方式可以参见图2a的步骤S2102的可选实现方式、及图2a所涉及的实施例中其他关联部分,此处不再赘述。
步骤S3103:生成第三信息。
在一些实施例中,步骤S3103的可选实现方式可以参见图2a的步骤S2103的可选实现方式、及图2a所涉及的实施例中其他关联部分,此处不再赘述。
步骤S3104:向终端发送第一信息。
在一些实施例中,第一信息包含第二信息和第三信息;第二信息为终端与第二网络设备通信保护相关的信息;第三信息用于对第二信息进行验证;第一网络设备为终端的服务网络设备,第二网络设备为终端执行切换的候选网络设备。
在一些实施例中,步骤S3104的可选实现方式可以参见图2a的步骤S2104的可选实现方式、及图2a所涉及的实施例中其他关联部分,此处不再赘述。
本公开实施例所涉及的通信方法可以包括步骤S3101至步骤S3104中的至少一者。例如,步骤S3101可以作为独立实施例来实施,步骤S3102可以作为独立实施例来实施,步骤S3103可以作为独立实施例来实施,步骤S3104可以作为独立实施例来实施。例如,步骤S3103结合步骤S3104可以作为独立实施例来实施,步骤S3101结合步骤S3103、步骤S3104可以作为独立实施例来实施,步骤S3101结合步骤S3102、步骤S3103、步骤S3104可以作为独立实施例来实施,但不限于此。需要说明的是,各个步骤可以独立实施,也可以在不矛盾的情况下,可以任意调换顺序,自由组合起来实施。
图3b是根据本公开实施例示出的一种通信方法的流程示意图。如图3b所示,本公开实施例涉及通信方法,由第一网络设备执行,上述方法包括:
步骤S3201:向终端发送第一信息。
在一些实施例中,第一信息包含第二信息和第三信息;第二信息为终端与第二网络设备通信保护相关的信息;第三信息用于对第二信息进行验证;第一网络设备为终端的服务网络设备,第二网络设备为终端执行切换的候选网络设备。
在一些实施例中,第一信息包含:第二信息和第三信息;第二信息为经第二网络设备确认的信息;第三信息为基于第二信息和第四信息生成的信息;第三信息和第四信息用于对第二信息进行验证;第四信息为与第一标识关联的信息;第一标识为分配给终端的标识;第一网络设备为终端的服务网络设备,第二网络设备为终端执行切换的候选网络设备。
在一些实施例中,步骤S3201的可选实现方式可以参见图2a的步骤S2104的可选实现方式、及图2a所涉及的实施例中其他关联部分,此处不再赘述。
在一些实施例中,第一标识为层1L1或者层2L2触发的移动性LTM过程中初始网络设备为服务网设备分配的终端标识。
在一些实施例中,向终端发送第一信息,包括:
向终端发送第一媒体接入控制MAC控制元素CE消息;
其中,第一MAC CE消息包含第一信息。
在一些实施例中,向终端发送第一信息,包括:
在终端与第一网络设备执行基站间LTM过程中,向终端发送第一信息。
在一些实施例中,在终端与第一网络设备执行基站间LTM的过程中,向终端发送第一信息,包括以下至少一者:
在终端与第一网络设备执行初始基站间LTM过程中,向终端发送第一信息;
在终端与第一网络设备执行后续基站间LTM过程中,向终端发送第一信息。
在一些实施例中,方法还包括:
确定第二信息;
向第二网络设备发送第二信息;
接收第二网络设备发送的经确认的第二信息。
在一些实施例中,方法包括:
基于第二信息和第四信息生成第三信息。
在一些实施例中,第二信息为第一下一跳变计数器参数NCC;基于第二信息和第四信息生成第三信息,包括:
利用第四信息对第一NCC进行编码,得到第三信息。
在一些实施例中,利用第四信息对第一NCC进行编码,得到第三信息,包括:
执行第四信息与第一NCC的异或操作,得到第三信息。
在一些实施例中,方法还包括:
执行针对第一标识的哈希hash处理,得到第四信息。
在一些实施例中,第一标识为以下至少一者:
分配给终端的小区无线网络临时标识C-RNTI;
分配给终端的LTM专用标识;
分配给终端的随机数。
图4a是根据本公开实施例示出的一种通信方法的流程示意图。如图4a所示,本公开实施例涉及通信方法,由终端执行,上述方法包括:
步骤S4101:获取第一信息。
在一些实施例中,第一信息包含第二信息和第三信息;第二信息为终端与第二网络设备通信保护相关的信息;第三信息用于对第二信息进行验证;第一网络设备为终端的服务网络设备,第二网络设备为终端执行切换的候选网络设备。
在一些实施例中,终端接收由第一网络设备发送的第一信息,但不限于此,也可以接收由其他主体发送的第一信息。
在一些实施例中,终端获取由协议规定的第一信息。
在一些实施例中,终端从高层(upper layer(s))获取第一信息。
在一些实施例中,终端进行处理从而得到第一信息。
在一些实施例中,步骤S4101被省略,终端自主实现第二信息所指示的功能,或上述功能为缺省或默认。
在一些实施例中,步骤S4101的可选实现方式可以参见图2a的步骤S2104的可选实现方式、及图2a所涉及的实施例中其他关联部分,此处不再赘述。
步骤S4102:验证第二信息。
在一些实施例中,步骤S4102的可选实现方式可以参见图2a的步骤S2105的可选实现方式、及图2a所涉及的实施例中其他关联部分,此处不再赘述。
图4b是根据本公开实施例示出的一种通信方法的流程示意图。如图4b所示,本公开实施例涉及通信方法,由终端执行,上述方法包括:
步骤S4201:接收第一网络设备发送的第一信息。
在一些实施例中,第一信息包含第二信息和第三信息;第二信息为终端与第二网络设备通信保护相关的信息;第三信息用于对第二信息进行验证;第一网络设备为终端的服务网络设备,第二网络设备为终端执行切换的候选网络设备。
在一些实施例中,所述第一信息包含:第二信息和第三信息;第二信息为经第二网络设备确认的信息;第三信息为基于第二信息和第四信息生成的信息;第三信息和第四信息用于对第二信息进行验证;第四信息为与第一标识关联的信息;第一标识为分配给终端的标识;第一网络设备为终端的服务网络设备,第二网络设备为终端执行切换的候选网络设备。
在一些实施例中,步骤S4201的可选实现方式可以参见图2a的步骤S2105的可选实现方式、及图2a所涉及的实施例中其他关联部分,此处不再赘述。
在一些实施例中,第一标识为LTM过程中初始网络设备为服务网设备分配的终端标识。
在一些实施例中,接收第一网络设备发送的第一信息,包括:
接收第一网络设备发送的第一MAC CE消息;
其中,第一MAC CE消息包含第一信息。
在一些实施例中,接收第一网络设备发送的第一信息,包括:
在终端与第一网络设备执行基站间LTM过程中,接收第一网络设备发送的第一信息。
在一些实施例中,在终端与第一网络设备执行基站间LTM的过程中,接收第一网络设备发送的第一信息,包括:
在终端与第一网络设备执行初始基站间LTM过程中,接收第一网络设备发送的第一信息;
在终端与第一网络设备执行后续基站间LTM过程中,接收第一网络设备发送的第一信息。
在一些实施例中,第二信息为第一下一跳变计数器参数NCC,第三信息为利用第四信息对第一NCC进行编码获得的安全信息。
在一些实施例中,第三信息为执行第一NCC与第四信息的异或操作后获得的安全信息。
在一些实施例中,第四信息为针对第一标识执行哈希hash处理得到的信息。
在一些实施例中,第一标识为以下至少一者:
分配给终端的小区无线网络临时标识C-RNTI;
分配给终端的LTM专用标识;
分配给终端的随机数。
在一些实施例中,方法还包括:
基于第二信息、第三信息和第四信息验证第二信息;
其中,第一网络设备和终端共享第四信息。
在一些实施例中,基于第二信息、第三信息和第四信息验证第二信息,包括:
基于第四信息解码第三信息,得到第五信息;
基于第二信息和第五信息的比较结果,确定第二信息是否通过验证。
在一些实施例中,基于第二信息和第五信息的比较结果,确定第二信息是否通过验证,包括以下至少之一:
确定第二信息与第五信息相同,确定第二信息通过验证;
确定第二信息与第五信息不同,确定第二信息未通过验证。
在一些实施例中,基于第二信息、第三信息和第四信息验证第二信息,包括:
基于第四信息对第二信息进行编码,得到第六信息;
基于第三信息和第六信息的比较结果,确定第二信息是否通过验证。
在一些实施例中,基于第三信息和第六信息的比较结果,确定第二信息是否通过验证,包括:
确定第三信息与第六信息相同,确定第二信息通过验证;
确定第三信息与第六信息不同,确定第二信息未通过验证。
在一些实施例中,方法还包括:
执行针对第一标识的哈希hash处理,得到第三信息。
图5a是根据本公开实施例示出的一种通信方法的交互示意图。如图5a所示,本公开实施例涉及通信方法,用于通信系统,方法包括以下步骤之一:
步骤S5101:第一网络设备向终端发送第一信息。
在一些实施例中,第一信息包含第二信息和第三信息;第二信息为终端与第二网络设备通信保护相关的信息;第三信息用于对第二信息进行验证;第一网络设备为终端的服务网络设备,第二网络设备为终端执行切换的候选网络设备。
在一些实施例中,第一信息包含:第二信息和第三信息;第二信息为经第二网络设备确认的信息;第三信息为基于第二信息和第四信息生成的信息;第三信息和第四信息用于对第二信息进行验证;第四信息为与第一标识关联的信息;第一标识为分配给终端的标识;第一网络设备为终端的服务网络设备,第二网络设备为终端执行切换的候选网络设备。
步骤S5101的可选实现方式可以参见图2a的步骤S2104的可选实现方式及图2a所涉及的实施例中其他关联部分,此处不再赘述。
在一些实施例中,上述方法可以包括上述通信系统侧、终端侧、网络设备侧等实施例的方法,此处不再赘述。
为了更好地理解本公开实施例,以下通过一个示例性实施例对本公开技术方案进行进一步说明:
示例1:
请参见图6a,提供一种通信方法,所述通信方法包括:
步骤S6101:分配C-RNTI。
在一些实施例中,在UE与服务或者源gNB(对应本公开中的初始网络设备)之间执行LTM准备期间,UE被分配与所有候选gNB一起使用的C-RNTI值(例如,C-RNTI_0、C-RNTI_1和/或C-RNTI_2,对应本公开中的第一标识)。
步骤S6102:L1测量报告。
在一些实施例中,当UE移动时,UE向服务或者源gNB发送L1测量报告。
步骤S6103:确定NCC1。
在一些实施例中,在选择目标gNB(候选gNB1,对应本公开中的第二网络设备)之后,服务或者源gNB(对应本公开中的第一网络设备)确定是否需要触发LTM过程。如果服务或者源gNB没有任何未使用的NH,则服务或者源gNB从KgNB0导出KNG-RAN*(i.e.KNG-RAN*←KDF(KgNB0,cell ID))。如果服务或者源gNB具有未使用的NH(与NCC1相关联),则服务或者源gNB从未使用的NH导出KNG-RAN*(i.e.KNG-RAN*←KDF(NH1,cell ID))。
步骤S6104:服务或者源gNB将导出的KNG-RAN*和用于KNG-RAN*导出的NCC值(NCC1)发送到候选gNB1。gNB1将KNG-RAN*作为KgNB1。并且将NCC值(NCC1)返回给服务或者源gNB。
步骤S6104包括:
步骤S6104a:发送握手请求,包含NCC1;
步骤S6104b:获取KgNB1
步骤S6104c:发送握手请求响应,包含NCC1。
步骤S6105:对NCC1进行编码。
在一些实施例中,在接收到候选gNB1返回的NCC值(NCC1)时,服务或者源gNB首先对分配给UE的C-RNTI值(即,C-RNTI_0)进行hash运算,然后通过将其与C-RNTI的运算结果值(即,H(C-RNTI_0))进行异或来对NCC1进行编码。
示例性地,编码NCC值[NCC1]=NCC1 xor H(C-RNTI_0)。
示例性地,编码NCC值[NCC1]=NCC1 xor H(C-RNTI_0)。
示例性地,编码NCC值[NCC1]=H(NCC1 xor H(C-RNTI_0))。
示例性地,编码NCC值[NCC1]=NCC1 xor Indicator xor H(C-RNTI_0)。
示例性地,编码NCC值[NCC1]=H(NCC1 xor Indicator xor H(C-RNTI_0))。
示例性地,编码NCC值[NCC1]=NCC1 xor Indicator xor T1 xor H(C-RNTI_0)。
示例性地,编码NCC值[NCC1]=H(NCC1 xor Indicator xor T1 xor H(C-RNTI_0))。
示例性地,编码NCC值[NCC1]=H(NCC1 xor C-RNTI_0)。
示例性地,编码NCC值[NCC1]=H(NCC1 xor Indicator xor C-RNTI_0)。
示例性地,编码NCC值[NCC1]=H(NCC1 xor Indicator xor T1 xor C-RNTI_0)。
上述实施例中,Indicator表示为第一指示符(keySetChangeIndicator),T1为第一时间信息,第一时间信息为服务或源gNB0生成[NCC1]的当前时间,H()表示哈希运算,xor表示异或运算。
步骤S6106:发送MAC CE。
在一些实施例中,服务或者源gNB在发送给UE的MAC CE中包括NCC1的明文和编码的NCC值[NCC1]。MAC CE的机构请参见图6b。
在一些实施例中,服务或者源gNB在发送给UE的MAC CE中还可以包括第一指示符(keySetChangeIndicator),以向终端指示是否基于NCC1生成第一密钥。
步骤S6107:执行验证。
在一些实施例中,在从服务或者源gNB接收到MAC CE时,执行验证。
示例性地,UE首先从MAC CE消息中检索NCC1的明文和编码的NCC值[NCC1],对服务或者源gNB0(C-RNTI_0)分配的C-RNTI值进行hash运算,并且使用C-RNTI_0的运算结果来验证NCC值[NCC1]。
在一示例中,NCC1’=[NCC1]xor H(C-RNTI_0)。
在一示例中,NCC1’=[NCC1]xor Indicator xor H(C-RNTI_0)。
在一示例中,NCC1’=[NCC1]xor Indicator xor T2 xor H(C-RNTI_0)。
在一示例中,UE可以将计算得到的NCC1’与NCC1比较确定NCC1的验证结果。
例如,NCC验证可以为将[接收到的NCC1 xor H(C-RNTI_0)]与接收到的[NCC1]进行比较。
在一示例中,[NCC1]’=NCC1 xor H(C-RNTI_0)。
在一示例中,[NCC1]’=H(NCC1 xor H(C-RNTI_0))。
在一示例中,[NCC1]’=NCC1 xor Indicator xor H(C-RNTI_0)。
在一示例中,[NCC1]’=H(NCC1 xor Indicator xor H(C-RNTI_0))。
在一示例中,[NCC1]’=NCC1 xor Indicator xor T2 xor H(C-RNTI_0)。
在一示例中,[NCC1]’=H(NCC1 xor Indicator xor T2 xor H(C-RNTI_0))。
在一示例中,UE可以将计算得到的[NCC1]’与[NCC1]比较确定NCC1的验证结果。
上述实施例中,Indicator表示为第一指示符(keySetChangeIndicator),T2为第二时间信息,第二时间信息为UE验证NCC1的当前时间,H()表示哈希运算,xor表示异或运算。
在一些实施例中,如果解码的NCC值与当前激活的KgNB0相关联的NCC相同,则UE执行水平密钥推导(i.e.KNG-RAN*←KDF(KgNB0,cell ID))。如果解码的NCC值不同于当前激活的KgNB0相关联的NCC,则UE导出NH,然后导出KNG-RAN*(i.e.NH1=KDF(NH,KAMF),KNG- RAN*←KDF(NH1,cell ID))。
在一些实施例中,UE从服务或者源gNB分离并应用目标gNB(候选gNB1)的配置,包括将KNG-RAN*作为KgNB1与gNB1一起使用。
步骤S6108:UE向gNB1发送RRC重新配置完成消息。
步骤S6109:N2路径切换。
在一些实施例中,目标gNB(gNB1)向AMF发送N2路径切换请求,AMF向gNB1返回新的NH和NCC(NH2,NCC2)。
步骤S6110:L1测量报告。
在一些实施例中,当UE保持移动时,UE向服务或者源gNB(gNB1)发送L1测量报告。
步骤S6111:确定NCC2。
在一些实施例中,在选择目标gNB(候选gNB2)之后,服务gNB(gNB1)确定是否需要触发LTM过程。
在一些实施例中,gNB1进一步确定用于从与NCC值相关联的NH导出KNG-RAN的NCC值(NCC2)。
在一些实施例中,NCC值=NCC1,用于水平密钥导出;NCC值=NCC2,用于垂直密钥导出。
在一些实施例中,由于服务或者源gNB具有未使用的NH(即,与NCC2相关联的NH2),所以服务或者源gNB从不使用的NH导出KNG-RAN*(i.e.KNG-RAN*←KDF(KgNB1,cell ID))。
注意:如果触发了进一步的CU内切换,则服务或者源gNB没有任何未使用的NH,因此从KgNB1导出KNG-RAN*(i.e.KNG-RAN*←KDF(KgNB1,cell ID))。
步骤S6112:服务gNB1将导出的KNG-RAN*和用于KNG-RAN*导出的NCC值(NCC2)发送到候选gNB2。gNB2将KNG-RAN*作为KgNB2,并将NCC值(NCC2)返回给gNB1。
步骤S6112包括:
步骤S6112a:发送握手请求,包含NCC2;
步骤S6112b:获取KgNB2
步骤S6112c:发送握手请求响应,包含NCC2。
步骤S6113:对NCC2进行编码。
在一些实施例中,当接收到gNB2返回的NCC值(NCC2)时,gNB1首先对分配给UE的配置C-RNTI值(即C-RNTI_1)进行hash运算,然后通过将NCC2与C-RNTI的运算结果(即H(C-RNTI_1))进行异或来编码NCC2。
示例性地,编码NCC值[NCC2]=NCC2 xor H(C-RNTI_1)。
示例性地,编码NCC值[NCC2]=NCC2 xor H(C-RNTI_1)。
示例性地,编码NCC值[NCC2]=H(NCC2 xor H(C-RNTI_1))。
示例性地,编码NCC值[NCC2]=NCC2 xor Indicator xor H(C-RNTI_1)。
示例性地,编码NCC值[NCC2]=H(NCC2 xor Indicator xor H(C-RNTI_1))。
示例性地,编码NCC值[NCC2]=NCC2 xor Indicator xor T3 xor H(C-RNTI_1)。
示例性地,编码NCC值[NCC2]=H(NCC2 xor Indicator xor T3 xor H(C-RNTI_1))。
示例性地,编码NCC值[NCC2]=H(NCC2 xor C-RNTI_1)。
示例性地,编码NCC值[NCC2]=H(NCC1 xor Indicator xor C-RNTI_1)。
示例性地,编码NCC值[NCC2]=H(NCC1 xor Indicator xor T3 xor C-RNTI_1)。
上述实施例中,Indicator表示为第一指示符(keySetChangeIndicator),T3为第三时间信息,第三时间信息为候选或目标gNB生成[NCC2]的当前时间,H()表示哈希运算,xor表示异或运算。
步骤S6114:发送MAC CE。
在一些实施例中,gNB1在发送给UE的MAC CE中包括NCC2的明文和编码的NCC值[NCC2]。
步骤S6115:执行验证。
在一些实施例中,在从服务或者源gNB接收到MAC CE时,执行验证。
在一些实施例中,UE首先从MAC CE消息检索NCC2的明文和编码的NCC值[NCC2],对服务或者源gNB1(C-RNTI_1)分配的C-RNTI值进行hash运算,并且使用C-RNTI_1的运算结果值来验证NCC值[NCC2]。
例如,NCC验证可以是将[接收到的NCC2 xor H(C-RNTI_1)]与接收到的[NCC2]进行比较。
在一些实施例中,如果解码的NCC值与当前激活的KgNB1相关联的NCC相同,则UE执行水平密钥导出(即,KNG-RAN*KDF(KgNB1,小区ID))。如果解码的NCC值不同于与当前激活的KgNB1相关联的NCC,则UE通过导出NH然后导出KNG-RAN*(即,NH2=KDF(NH1,KAMF),KNG-RAN*KDF(NH2,小区ID))来执行垂直密钥导出。
在一些实施例中,UE从服务或者源gNB分离并应用目标gNB(候选gNB2)的配置,包括将KNG-RAN*用作与gNB2一起使用的KgNB2
在一示例中,NCC2’=[NCC2]xor H(C-RNTI_1)。
在一示例中,NCC2’=[NCC2]xor Indicator xor H(C-RNTI_1)。
在一示例中,NCC2’=[NCC2]xor Indicator xor T4 xor H(C-RNTI_1)。
在一示例中,UE可以将计算得到的NCC1’与NCC1比较确定验证结果。
在一示例中,[NCC2]’=NCC2 xor H(C-RNTI_1)。
在一示例中,[NCC2]’=H(NCC2 xor H(C-RNTI_1))。
在一示例中,[NCC2]’=NCC2 xor Indicator xor H(C-RNTI_1)。
在一示例中,[NCC2]’=H(NCC2 xor Indicator xor H(C-RNTI_1))。
在一示例中,[NCC2]’=NCC2 xor Indicator xor T4 xor H(C-RNTI_1)。
在一示例中,[NCC2]’=H(NCC2 xor Indicator xor T4 xor H(C-RNTI_1))。
在一示例中,UE可以将计算得到的[NCC1]’与[NCC1]比较确定NCC1的验证结果。
上述实施例中,Indicator表示为第一指示符(keySetChangeIndicator),T4为第四时间信息,第四时间信息为UE验证NCC2的当前时间,H()表示哈希运算,xor表示异或运算。
步骤S6116:UE向gNB2发送RRC重新配置完成消息。
步骤S6117:N2路径切换。
在一些实施例中,目标gNB(gNB2)向AMF发送N2路径切换请求,AMF向gNB2返回新的NH和NCC(NH3,NCC3)。
步骤S6118:执行后续程序。
利用上述过程,即使攻击篡改了经由MAC CE消息发送的NCC值(例如,将NCC1改变为NCCx),攻击者也不能使用仅为UE和服务gNB已知的C-RNTI对NCCx进行编码。然后,由UE执行的对接收到的NCCx的验证将永远不会成功,因为UE没有接收到与C-RNTI异或的正确编码的NCCx值。
本公开实施例还提出用于实现以上任一方法的装置,例如,提出一装置,上述装置包括用以实现以上任一方法中终端所执行的各步骤的单元或模块。再如,还提出另一装置,包括用以实现以上任一方法中网络设备(例如接入网设备、核心网功能节点、核心网设备等)所执行的各步骤的单元或模块。
应理解以上装置中各单元或模块的划分仅是一种逻辑功能的划分,在实际实现时可以全部或部分集成到一个物理实体上,也可以物理上分开。此外,装置中的单元或模块可以以处理器调用软件的形式实现:例如装置包括处理器,处理器与存储器连接,存储器中存储有指令,处理器调用存储器中存储的指令,以实现以上任一方法或实现上述装置各单元或模块的功能,其中处理器例如为通用处理器,例如中央处理单元(Central Processing Unit,CPU)或微处理器,存储器为装置内的存储器或装置外的存储器。或者,装置中的单元或模块可以以硬件电路的形式实现,可以通过对硬件电路的设计实现部分或全部单元或模块的功能,上述硬件电路可以理解为一个或多个处理器;例如,在一种实现中,上述硬件电路为专用集成电路(application-specific integrated circuit,ASIC),通过对电路内元件逻辑关系的设计,实现以上部分或全部单元或模块的功能;再如,在另一种实现中,上述硬件电路为可以通过可编程逻辑器件(programmable logic device,PLD)实现,以现场可编程门阵列(Field Programmable Gate Array,FPGA)为例,其可以包括大量逻辑门电路,通过配置文件来配置逻辑门电路之间的连接关系,从而实现以上部分或全部单元或模块的功能。以上装置的所有单元或模块可以全部通过处理器调用软件的形式实现,或全部通过硬件电路的形式实现,或部分通过处理器调用软件的形式实现,剩余部分通过硬件电路的形式实现。
在本公开实施例中,处理器是具有信号处理能力的电路,在一种实现中,处理器可以是具有指令读取与运行能力的电路,例如中央处理单元(Central Processing Unit,CPU)、微处理器、图形处理器(graphics processing unit,GPU)(可以理解为微处理器)、或数字信号处理器(digital signal processor,DSP)等;在另一种实现中,处理器可以通过硬件电路的逻辑关系实现一定功能,上述硬件电路的逻辑关系是固定的或可以重构的,例如处理器为专用集成电路(application-specific integrated circuit,ASIC)或可编程逻辑器件(programmable logic device,PLD)实现的硬件电路,例如FPGA。在可重构的硬件电路中,处理器加载配置文档,实现硬件电路配置的过程,可以理解为处理器加载指令,以实现以上部分或全部单元或模块的功能的过程。此外,还可以是针对人工智能设计的硬件电路,其可以理解为ASIC,例如神经网络处理单元(Neural Network Processing Unit,NPU)、张量处理单元(Tensor Processing Unit,TPU)、深度学习处理单元(Deep learning Processing Unit,DPU)等。
图7a本公开实施例提出的第一网络设备7100的结构示意图。如图7a所示,第一网络设备7100可以包括:收发模块7101、处理模块7102等中的至少一者。可选地,上述收发模块用于执行以上任一方法中第一网络设备7100执行的发送和/或接收等通信步骤中的至少一者,此处不再赘述。可选地,上述处理模块用于执行以上任一方法中第一网络设备7100执行的其他步骤中的至少一者,此处不再赘述。
图7b是本公开实施例提出的终端7200的结构示意图。如图7b所示,终端7200可以包括:收发模块7201、处理模块7202等中的至少一者。可选地,上述收发模块用于执行以上任一方法中终端7200执行的发送和/或接收等通信步骤中的至少一者,此处不再赘述。在一些实施例中,收发模块可以包括发送模块和/或接收模块,发送模块和接收模块可以是分离的,也可以集成在一起。可选地,收发模块可以与收发器相互替换。可选地,上述处理模块用于执行以上任一方法中终端7200执行的其他步骤中的至少一者,此处不再赘述。
在一些实施例中,处理模块可以是一个模块,也可以包括多个子模块。可选地,上述多个子模块分别执行处理模块所需执行的全部或部分步骤。可选地,处理模块可以与处理器相互替换。
图8a是本公开实施例提出的通信设备8100的结构示意图。通信设备8100可以是网络设备(例如接入网设备、核心网设备等),也可以是终端(例如用户设备等),也可以是支持网络设备实现以上任一方法的芯片、芯片系统、或处理器等,还可以是支持终端实现以上任一方法的芯片、芯片系统、或处理器等。通信设备8100可用于实现上述方法实施例中描述的方法,具体可以参见上述方法实施例中的说明。
如图8a所示,通信设备8100包括一个或多个处理器8101。处理器8101可以是通用处理器或者专用处理器等,例如可以是基带处理器或中央处理器。基带处理器可以用于对通信协议以及通信数据进行处理,中央处理器可以用于对通信装置(如,基站、基带芯片,终端设备、终端设备芯片,DU或CU等)进行控制,执行程序,处理程序的数据。通信设备8100用于执行以上任一方法。
在一些实施例中,通信设备8100还包括用于存储指令的一个或多个存储器8102。可选地,全部或部分存储器8102也可以处于通信设备8100之外。
在一些实施例中,通信设备8100还包括一个或多个收发器8103。在通信设备8100包括一个或多个收发器8103时,收发器8103执行上述方法中的发送和/或接收等通信步骤中的至少一者,处理器8101执行其他步骤中的至少一者。
在一些实施例中,收发器可以包括接收器和/或发送器,接收器和发送器可以是分离的,也可以集成在一起。可选地,收发器、收发单元、收发机、收发电路等术语可以相互替换,发送器、发送单元、发送机、发送电路等术语可以相互替换,接收器、接收单元、接收机、接收电路等术语可以相互替换。
在一些实施例中,通信设备8100可以包括一个或多个接口电路8104。可选地,接口电路8104与存储器8102连接,接口电路8104可用于从存储器8102或其他装置接收信号,可用于向存储器8102或其他装置发送信号。例如,接口电路8104可读取存储器8102中存储的指令,并将该指令发送给处理器8101。
以上实施例描述中的通信设备8100可以是网络设备或者终端,但本公开中描述的通信设备8100的范围并不限于此,通信设备8100的结构可以不受图8a的限制。通信设备可以是独立的设备或者可以是较大设备的一部分。例如所述通信设备可以是:1)独立的集成电路IC,或芯片,或,芯片系统或子系统;(2)具有一个或多个IC的集合,可选地,上述IC集合也可以包括用于存储数据,程序的存储部件;(3)ASIC,例如调制解调器(Modem);(4)可嵌入在其他设备内的模块;(5)接收机、终端设备、智能终端设备、蜂窝电话、无线设备、手持机、移动单元、车载设备、网络设备、云设备、人工智能设备等等;(6)其他等等。
图8b是本公开实施例提出的芯片8200的结构示意图。对于通信设备8100可以是芯片或芯片系统的情况,可以参见图8b所示的芯片8200的结构示意图,但不限于此。
芯片8200包括一个或多个处理器8201,芯片8200用于执行以上任一方法。
在一些实施例中,芯片8200还包括一个或多个接口电路8202。可选地,接口电路8202与存储器8203连接,接口电路8202可以用于从存储器8203或其他装置接收信号,接口电路8202可用于向存储器8203或其他装置发送信号。例如,接口电路8202可读取存储器8203中存储的指令,并将该指令发送给处理器8201。
在一些实施例中,接口电路8202执行上述方法中的发送和/或接收等通信步骤(例如步骤S2101、步骤S3101,但不限于此)中的至少一者,处理器8201执行其他步骤中的至少一者。
在一些实施例中,接口电路、接口、收发管脚、收发器等术语可以相互替换。
在一些实施例中,芯片8200还包括用于存储指令的一个或多个存储器8203。可选地,全部或部分存储器8203可以处于芯片8200之外。
本公开还提出存储介质,上述存储介质上存储有指令,当上述指令在通信设备8100上运行时,使得通信设备8100执行以上任一方法。可选地,上述存储介质是电子存储介质。可选地,上述存储介质是计算机可读存储介质,但不限于此,其也可以是其他装置可读的存储介质。可选地,上述存储介质可以是非暂时性(non-transitory)存储介质,但不限于此,其也可以是暂时性存储介质。
本公开还提出程序产品,上述程序产品被通信设备8100执行时,使得通信设备8100执行以上任一方法。可选地,上述程序产品是计算机程序产品。
本公开还提出计算机程序,当其在计算机上运行时,使得计算机执行以上任一方法。

Claims (40)

  1. 一种通信方法,其特征在于,所述方法由第一网络设备执行,所述方法包括:
    向终端发送第一信息;
    其中,所述第一信息包含:第二信息和第三信息;所述第二信息为所述终端与第二网络设备通信保护相关的信息;所述第三信息用于对所述第二信息进行验证;所述第一网络设备为所述终端的服务网络设备,所述第二网络设备为所述终端执行切换的候选网络设备。
  2. 根据权利要求1所述的方法,其特征在于,所述第三信息是至少基于第二信息和第四信息生成的信息,所述第四信息用于对第二信息进行保护,所述第四信息为与第一标识关联的信息,所述第一标识为分配给所述终端的标识。
  3. 根据权利要求2所述的方法,其特征在于,所述第一标识为层1L1或者层2L2触发的移动性LTM过程中初始网络设备为服务网设备分配的终端标识。
  4. 根据权利要求1或者2所述的方法,其特征在于,所述方法还包括:
    确定所述第二信息;
    向所述第二网络设备发送所述第二信息;
    接收所述第二网络设备发送的经确认的所述第二信息。
  5. 根据权利要求1至4任一项所述的方法,其特征在于,所述第一信息还包括第一指示符,所述第一指示符用于向所述终端指示是否基于第二信息生成第一密钥,所述第一密钥用于所述终端与所述第二网络设备通信。
  6. 根据权利要求1至5中任一项所述的方法,其特征在于,所述方法还包括以下之一:
    基于所述第二信息和第四信息,生成所述第三信息;
    基于所述第二信息、第四信息和第一指示符,生成所述第三信息;
    基于所述第二信息、第四信息、第一指示符和第一时间信息,生成所述第三信息,所述第一时间信息为所述第一网络设备生成所述第三信息的当前时间;
    其中,所述第四信息为与第一标识关联的信息,所述第一标识为分配给所述终端的标识。
  7. 根据权利要求6所述的方法,其特征在于,所述第二信息为第一下一跳变计数器参数NCC;所述方法还包括以下之一:
    利用所述第四信息对所述第一NCC进行编码,得到所述第三信息。
    利用所述第四信息对第一指示符和所述第一NCC进行编码,得到所述第三信息;
    利用所述第四信息和第一时间信息对第一指示符和所述第一NCC进行编码,得到所述第三信息。
  8. 根据权利要求7所述的方法,其特征在于,所述方法还包括以下之一:
    执行所述第四信息与所述第一NCC的异或操作,得到所述第三信息;
    将第一异或值进行哈希处理,得到所述第三信息;所述第一异或值为所述第四信息与所述第一NCC异或操作后得到的;
    执行所述第四信息、所述第一NCC和第一指示符的异或操作,得到所述第三信息;
    将第二异或值进行哈希处理,得到所述第三信息;所述第二异或值为所述第四信息、第一指示符和所述第一NCC异或操作后得到的;
    执行所述第四信息、所述第一NCC、所述第一指示符和第一时间信息的异或操作,得到所述第三信息;
    将第三异或值进行哈希处理,得到所述第三信息;所述第三异或值为所述第四信息、第一指示符、所述第一NCC和第一时间信息异或操作后得到的。
  9. 根据权利要求2至8中任一项所述的方法,其特征在于,所述第四信息是所述第一网络设备通过对所述第一标识进行哈希处理后得到的,或者,所述第四信息为所述第一标识。
  10. 根据权利要求1至9中任一项所述的方法,其特征在于,所述向终端发送第一信息,包括:
    向所述终端发送第一媒体接入控制MAC控制元素CE消息;
    其中,所述第一MAC CE消息包含所述第一信息。
  11. 根据权利要求1至10中任一项所述的方法,其特征在于,所述向终端发送第一信息,包括:
    在终端与所述第一网络设备执行基站间LTM过程中,向所述终端发送所述第一信息。
  12. 根据权利要求11所述的方法,其特征在于,所述在终端与所述第一网络设备执行基站间LTM的过程中,向所述终端发送所述第一信息,包括以下至少一者:
    在终端与所述第一网络设备执行初始基站间LTM过程中,向所述终端发送所述第一信息;
    在终端与所述第一网络设备执行后续基站间LTM过程中,向所述终端发送所述第一信息。
  13. 根据权利要求2至12中任一项所述的方法,其特征在于,所述第一标识为以下至少一者:
    分配给所述终端的小区无线网络临时标识C-RNTI;
    分配给所述终端的LTM专用标识;
    分配给所述终端的随机数。
  14. 一种通信方法,其特征在于,所述方法由终端执行,所述方法包括:
    接收第一网络设备发送的第一信息;
    其中,所述第一信息包含:第二信息和第三信息;所述第二信息为所述终端与第二网络设备通信保护相关的信息;所述第三信息用于对所述第二信息进行验证;所述第一网络设备为所述终端的服务网络设备,所述第二网络设备为所述终端执行切换的候选网络设备。
  15. 根据权利要求14所述的方法,其特征在于,所述第三信息是至少基于第二信息和第四信息生成的信息,所述第四信息用于对第二信息进行保护,所述第四信息为与第一标识关联的信息,所述第一标识为分配给所述终端的标识。
  16. 根据权利要求15所述的方法,其特征在于,所述第一标识为LTM过程中初始网络设备为服务网设备分配的终端标识。
  17. 根据权利要求14至16任一项所述的方法,其特征在于,所述第一信息还包括第一指示符,所述第一指示符用于向所述终端指示是否基于第二信息生成第一密钥,所述第一密钥用于所述终端与所述第二网络设备通信。
  18. 根据权利要求14至17任一项所述的方法,其特征在于,所述第三信息是基于所述第二信息和第四信息生成的;或者,
    所述第三信息是基于所述第二信息、第四信息和第一指示符生成的;或者,
    所述第三信息是基于所述第二信息、第四信息、第一指示符和第一时间信息生成的,所述第一时间信息为所述第一网络设备生成所述第三信息的当前时间;
    其中,所述第四信息为与第一标识关联的信息,所述第一标识为分配给所述终端的标识。
  19. 根据权利要求18所述的方法,其特征在于,所述第二信息为第一下一跳变计数器参数NCC,所述第三信息为利用所述第四信息对所述第一NCC进行编码获得的安全信息,或者,所述第三信息为利用所述第四信息对第一指示符和所述第一NCC进行编码获得的安全信息;所述第三信息为利用所述第四信息和第一时间信息对第一指示符和第一NCC进行编码获得的安全信息。
  20. 根据权利要求19所述的方法,其特征在于,所述第三信息为执行所述第一NCC与所述第四信息的异或操作后获得的安全信息;或者,
    所述第三信息为将第一异或值进行哈希处理后获得的安全信息,所述第一异或值为所述第四信息与所述第一NCC异或操作后得到的;或者,
    所述第三信息为执行所述第四信息、所述第一NCC和第一指示符的异或操作后获得的安全信息;或者,
    所述第三信息为将第二异或值进行哈希处理后获得的安全信息,所述第二异或值为所述第四信息、所述第一NCC和第一指示符异或操作后得到的;或者,
    所述第三信息为执行所述第四信息、所述第一NCC、第一指示符和第一时间信息的异或操作后获得的安全信息;或者,
    所述第三信息为将第三异或值进行哈希处理后获得的安全信息,所述第三异或值为所述第四信息、所述第一NCC、第一指示符和第一时间信息异或操作后得到的。
  21. 根据权利要求14至20中任一项所述的方法,其特征在于,所述第四信息为所述第一网络设备针对所述第一标识执行哈希hash处理得到的信息,或者,所述第四信息为所述第一标识。
  22. 根据权利要求14至21中任一项所述的方法,其特征在于,所述方法还包括以下之一:
    基于所述第二信息、所述第三信息和第七信息,验证所述第二信息;
    基于所述第二信息、所述第三信息、第七信息和所述第一指示符,验证所述第二信息;
    基于所述第二信息、所述第三信息、第七信息、所述第一指示符和第二时间信息,验证所述第二信息,
    其中,所述第七信息与所述第一标识关联,所述第二时间信息为所述终端验证所述第二信息的当前时间。
  23. 根据权利要求22所述的方法,其特征在于,所述方法还包括以下之一:
    基于所述第七信息,对所述第三信息进行解码,得到第五信息;
    基于所述第七信息和第一指示符,对所述第三信息进行解码,得到第五信息;
    基于所述第七信息、第一指示符和所述第二时间信息,对所述第三信息进行解码,得到第五信息;
    其中,所述第五信息用于验证所述第二信息。
  24. 根据权利要求23所述的方法,其特征在于,所述方法还包括:
    基于所述第二信息和所述第五信息的比较结果,确定所述第二信息是否通过验证。
  25. 根据权利要求24所述的方法,其特征在于,所述基于所述第二信息和所述第五信息的比较结果,确定所述第二信息是否通过验证,包括以下至少之一:
    确定所述第二信息与所述第五信息相同,确定所述第二信息通过验证;
    确定所述第二信息与所述第五信息不同,确定所述第二信息未通过验证。
  26. 根据权利要求22所述的方法,其特征在于,所述方法还包括以下之一:
    基于所述第七信息对所述第二信息进行编码,得到第六信息;
    基于所述第七信息对所述第二信息和第一指示符进行编码,得到第六信息;
    基于所述第七信息和第二时间信息对所述第二信息和第一指示符进行编码,得到第六信息;
    其中,所述第六信息用于验证所述第二信息。
  27. 根据权利要求26所述的方法,其特征在于,所述方法还包括以下之一:
    执行所述第七信息与所述第二信息的异或操作,得到所述第六信息;
    将第四异或值进行哈希处理,得到所述第六信息,所述第四异或值为所述第七信息与所述第二信息异或操作后得到的;
    执行所述第七信息、所述第二信息和所述第一指示符的异或操作,得到所述第六信息;
    将第五异或值进行哈希处理,得到所述第六信息,所述第五异或值为所述第七信息、所述第二信息和第一指示符异或操作后得到的;
    执行所述第七信息、所述第二信息、所述第一指示符和所述第二时间信息的异或操作,得到所述第六信息;
    将第六异或值进行哈希处理,得到所述第六信息,所述第六异或值为所述第七信息、所述第二信息、所述第一指示符和所述第二时间信息异或操作后得到的。
  28. 根据权利要求27所述的方法,其特征在于,所述方法还包括:
    基于所述第三信息和所述第六信息的比较结果,确定所述第二信息是否通过验证。
  29. 根据权利要求28所述的方法,其特征在于,所述基于所述第三信息和所述第六信息的比较结果,确定所述第二信息是否通过验证,包括:
    确定所述第三信息与所述第六信息相同,确定所述第二信息通过验证;
    确定所述第三信息与所述第六信息不同,确定所述第二信息未通过验证。
  30. 根据权利要求22至29任一项所述的方法,其特征在于,所述第七信息为所述终端通过对所述第一标识进行哈希处理后得到的,或者,所述第七信息为所述第一标识。
  31. 根据权利要求22至30任一项所述的方法,其中,所述第二时间信息的值与所述第一时间信息的值相等,或者,所述第二时间信息的值等于所述第一时间信息的值加上第一偏移值。
  32. 根据权利要求14至31中任一项所述的方法,其特征在于,所述接收第一网络设备发送的第一信息,包括:
    接收第一网络设备发送的第一MAC CE消息;
    其中,所述第一MAC CE消息包含所述第一信息。
  33. 根据权利要求14至32中任一项所述的方法,其特征在于,所述接收第一网络设备发送的第一信息,包括:
    在终端与所述第一网络设备执行基站间LTM过程中,接收第一网络设备发送的所述第一信息。
  34. 根据权利要求33所述的方法,其特征在于,所述在终端与所述第一网络设备执行基站间LTM的过程中,接收第一网络设备发送的所述第一信息,包括:
    在终端与所述第一网络设备执行初始基站间LTM过程中,接收所述第一网络设备发送的所述第一信息;
    在终端与所述第一网络设备执行后续基站间LTM过程中,接收所述第一网络设备发送的所述第一信息。
  35. 根据权利要求15至34中任一项所述的方法,其特征在于,所述第一标识为以下至少一者:
    分配给所述终端的小区无线网络临时标识C-RNTI;
    分配给所述终端的LTM专用标识;
    分配给所述终端的随机数。
  36. 一种通信方法,用于通信系统,所述通信系统包括第一网络设备和终端,其特征在于,所述方法包括:
    第一网络设备向终端发送第一信息;
    其中,所述第一信息包含:第二信息和第三信息;所述第二信息为所述终端与第二网络设备通信保护相关的信息;所述第三信息用于对所述第二信息进行验证;所述第一网络设备为所述终端的服务网络设备,所述第二网络设备为所述终端执行切换的候选网络设备。
  37. 一种通信设备,其特征在于,所述通信设备用于执行权利要求1至13、14至35任一项所述的通信方法。
  38. 一种通信系统,其特征在于,所述通信系统包括第一网络设备和终端,其中,所述第一网络设备被配置为权利要求1至13中任一项所述的通信方法;所述终端被配置为权利要求14至35中任一项所述的通信方法。
  39. 一种存储介质,所述存储介质存储有指令,其特征在于,当所述指令在通信设备上运行时,使得所述通信设备如权利要求1至13、14至35任一项所述的通信方法。
  40. 一种程序产品,包括程度、指令的至少之一,其特征在于,所述程序、指令的至少之一被通信设备执行时实现权利要求1至13、14至35中任一项所述的通信方法。
PCT/CN2025/076735 2024-07-05 2025-02-10 通信方法、第一网络设备、终端、通信系统和存储介质 Pending WO2026007409A1 (zh)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN202580001453.2A CN121220116A (zh) 2024-07-05 2025-02-10 通信方法、第一网络设备、终端、通信系统和存储介质

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
PCT/CN2024/103771 WO2026007094A1 (zh) 2024-07-05 2024-07-05 通信方法、第一网络设备、终端、通信系统和存储介质
CNPCT/CN2024/103771 2024-07-05

Publications (1)

Publication Number Publication Date
WO2026007409A1 true WO2026007409A1 (zh) 2026-01-08

Family

ID=98317314

Family Applications (2)

Application Number Title Priority Date Filing Date
PCT/CN2024/103771 Pending WO2026007094A1 (zh) 2024-07-05 2024-07-05 通信方法、第一网络设备、终端、通信系统和存储介质
PCT/CN2025/076735 Pending WO2026007409A1 (zh) 2024-07-05 2025-02-10 通信方法、第一网络设备、终端、通信系统和存储介质

Family Applications Before (1)

Application Number Title Priority Date Filing Date
PCT/CN2024/103771 Pending WO2026007094A1 (zh) 2024-07-05 2024-07-05 通信方法、第一网络设备、终端、通信系统和存储介质

Country Status (1)

Country Link
WO (2) WO2026007094A1 (zh)

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20200015074A1 (en) * 2018-07-04 2020-01-09 Lg Electronics Inc. Method and apparatus for supporting security in rrc inactive state in wireless communication system
US20220060888A1 (en) * 2019-04-28 2022-02-24 Huawei Technologies Co., Ltd. Communication Method and Communications Apparatus
US20220174760A1 (en) * 2019-08-16 2022-06-02 Huawei Technologies Co., Ltd. Communication method and apparatus
CN116782211A (zh) * 2023-07-06 2023-09-19 中国电信股份有限公司技术创新中心 切换密钥的确定方法、切换方法及装置
CN117941395A (zh) * 2021-07-08 2024-04-26 瑞典爱立信有限公司 生成认证令牌

Family Cites Families (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2023147767A1 (zh) * 2022-02-07 2023-08-10 华为技术有限公司 网络校验的方法和装置
CN117998495A (zh) * 2022-11-04 2024-05-07 华为技术有限公司 通信方法、装置及系统
CN117136615A (zh) * 2023-07-19 2023-11-28 北京小米移动软件有限公司 信息处理方法、终端、通信系统及存储介质
CN117813855A (zh) * 2023-11-14 2024-04-02 北京小米移动软件有限公司 波束指示方法、设备和存储介质

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20200015074A1 (en) * 2018-07-04 2020-01-09 Lg Electronics Inc. Method and apparatus for supporting security in rrc inactive state in wireless communication system
US20220060888A1 (en) * 2019-04-28 2022-02-24 Huawei Technologies Co., Ltd. Communication Method and Communications Apparatus
US20220174760A1 (en) * 2019-08-16 2022-06-02 Huawei Technologies Co., Ltd. Communication method and apparatus
CN117941395A (zh) * 2021-07-08 2024-04-26 瑞典爱立信有限公司 生成认证令牌
CN116782211A (zh) * 2023-07-06 2023-09-19 中国电信股份有限公司技术创新中心 切换密钥的确定方法、切换方法及装置

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
HUAWEI, HISILICON: "Support of RNA update without context relocation", 3GPP DRAFT; R2-1812507, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, vol. RAN WG2, no. Gothenburg, Sweden; 20180820 - 20180824, 10 August 2018 (2018-08-10), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France , XP051522105 *

Also Published As

Publication number Publication date
WO2026007094A1 (zh) 2026-01-08

Similar Documents

Publication Publication Date Title
US12452757B2 (en) Communication method and communications apparatus for handling detection of secondary cell group failure
WO2025015580A9 (zh) 信息处理方法、终端、通信系统及存储介质
US20220007274A1 (en) Communication Method And Apparatus
CN113727342B (zh) 网络注册的方法和装置
US11889310B2 (en) Communication method and communication apparatus
CN113873520A (zh) 一种通信方法、终端设备和无线接入网设备
WO2025035417A1 (zh) 信息处理方法、装置及存储介质
WO2021169873A1 (zh) 通信方法、通信装置及通信系统
US20230189135A1 (en) Cell access selection method, terminal device, and network device
WO2026007094A1 (zh) 通信方法、第一网络设备、终端、通信系统和存储介质
WO2025043723A1 (zh) 一种信息处理方法及其装置
WO2025030300A1 (zh) 信息指示方法、第一api调用者、第一网络功能和存储介质
CN121220116A (zh) 通信方法、第一网络设备、终端、通信系统和存储介质
WO2026011396A1 (zh) 密钥处理方法、通信设备及存储介质
WO2026065522A1 (zh) 安全信息处理方法、通信设备及存储介质
WO2025010609A1 (zh) 通信处理方法、用户设备
WO2026031234A1 (zh) 通信方法、终端、接入网设备、系统及存储介质
WO2026036328A1 (zh) 信息处理方法、通信设备及存储介质
CN121220075A (zh) 信息传输方法、装置以及存储介质
WO2025213303A1 (zh) 信息处理方法、网络设备、终端、通信系统及存储介质
WO2026016151A1 (zh) 信息处理方法、通信设备及存储介质
WO2026031233A1 (zh) 通信方法、第一mn、第一sn、系统及存储介质
WO2026055945A1 (zh) 数据安全处理方法、通信设备、通信系统、存储介质及程序产品
WO2026085823A1 (zh) 数据安全处理方法、通信设备、通信系统、存储介质及程序产品
CN120677734A (zh) 安全参数处理方法、通信设备及存储介质

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 25831771

Country of ref document: EP

Kind code of ref document: A1