A communication method and apparatus

By determining whether to enable user-plane integrity protection based on the required rate, residual rate and user-plane security policy of the terminal device in the 5G network, the problems of data transmission security and communication service requirements of the UE and network side are solved, and efficient and secure data transmission is achieved.

CN113660665BActive Publication Date: 2025-06-17HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202010368371.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-04-30
Publication Date
2025-06-17
Estimated Expiration
2040-04-30

AI Technical Summary

Technical Problem

The prior art is difficult to effectively ensure the data transmission security of user terminal equipment (UE) and network side in 5G networks, while taking into account the communication service needs of UE, especially when the maximum integrity protection rate is 64Kbps or the full data rate, there are problems of insufficient security or abnormal performance.

Method used

By obtaining the required rate, residual rate and user plane security policy of the terminal device, determine whether to enable user plane integrity protection of user plane resources to ensure the accuracy and adaptability of protection, so as to improve the security and timeliness of data transmission without affecting the performance of the terminal device.

Benefits of technology

It realizes the security and timeliness of data transmission without affecting the performance of the terminal equipment, and avoids insufficient security when the maximum integrity protection rate is 64Kbps or abnormal performance problems when the maximum data rate is full.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113660665B_ABST
    Figure CN113660665B_ABST
Patent Text Reader

Abstract

A communication method and apparatus, which are used to solve the problem that the UE and the network side cannot balance timeliness and security when transmitting data in the prior art. The method includes obtaining the required rate of the first user plane resource requested to be established by the UE, the remaining rate of the UE, and the user plane security policy of the first user plane resource requested to be established; determining whether to enable the user plane integrity protection of the first user plane resource according to the required rate, the remaining rate, and the user plane security policy; the remaining rate is determined according to the used rate of the second user plane resource already established by the UE and the maximum integrity protection rate after the UE enables the user plane integrity protection, and the user plane security policy includes enabling, optionally enabling or disabling the user plane integrity protection. Therefore, the condition for enabling the user plane integrity protection of the first user plane resource can be determined more accurately, so as to ensure the timeliness and security of UE data transmission as much as possible.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technologies, and in particular, to a communication method and apparatus. Background Art

[0002] With the development of communication technologies, security issues in communication networks have received increasing attention. For example, communication content may be intercepted, tampered with, or forged. To address these security issues, communication networks provide protection mechanisms such as confidentiality and integrity. In the 5th-Generation (5G) network, to meet security requirements, a security feature of user plane integrity protection is introduced.

[0003] Currently, the radio access network (RAN) determines whether to enable user plane integrity protection based on the maximum integrity protection rate reported by the user equipment (UE). Currently, only two values are defined for the maximum integrity protection rate reported by the UE, namely 64 kilobits per second (kbps) and full-data-rate. When the maximum integrity protection rate reported by the UE is 64 Kbps, since this rate is relatively low, it means that user plane integrity protection can basically not be enabled for data transmission between the UE and the RAN, resulting in the security of the transmitted data not being guaranteed. When the maximum integrity protection rate of the UE is full-data-rate, it may cause user plane integrity protection to always be enabled for data transmission between the UE and the network side. Enabling user plane integrity protection without restraint may cause abnormal performance of the UE, resulting in the timeliness of data transmission not meeting the requirements.

[0004] In summary, how to ensure the security of data transmitted between the UE and the network side while also taking into account the communication service requirements of the UE is a technical problem that urgently needs to be solved. Summary of the Invention

[0005] This application provides a communication method and apparatus for ensuring the security of data transmitted between the UE and the network side while also taking into account the communication service requirements of the UE.

[0006] In a first aspect, the present application provides a communication method, which includes obtaining the required rate, remaining rate, and user plane security policy of a first terminal device; determining whether to enable user plane integrity protection for a first user plane resource according to the required rate, remaining rate, and user plane security policy; where the required rate is used to indicate the rate required for the first user plane resource requested to be established by the first terminal device, the remaining rate is determined according to the used rate of the first terminal device and the maximum integrity protection rate of the first terminal device, the used rate is used to indicate the rate used by the second user plane resource already established by the first terminal device, and the maximum integrity protection rate is used to indicate the maximum rate after the first terminal device enables user plane integrity protection; the user plane security policy includes user plane integrity protection enabled, user plane integrity protection optionally enabled, or user plane integrity protection disabled.

[0007] Based on this solution, it is determined whether to enable user plane integrity protection for the first user plane resource according to the required rate, remaining rate, and maximum integrity protection rate of the first user plane resource to be established, so that the conditions for enabling user plane integrity protection for the first user plane resource can be determined more accurately. To ensure the timeliness and security of the transmitted data of the terminal device as much as possible. That is, the user plane integrity protection of the terminal device and the network side can be enabled on demand according to the capabilities of the UE, which helps to avoid the situation where when the maximum integrity protection rate of the terminal device is 64 Kbps, the user plane integrity protection between the terminal device and the network side is always disabled, resulting in the security of the transmitted data not being guaranteed, or when the maximum integrity protection rate of the terminal device is the full data rate, the user plane integrity protection between the terminal device and the network side is always enabled, resulting in abnormal performance of the terminal device.

[0008] In a possible implementation, the second user plane resource includes the user plane resources with enabled user plane integrity protection among the user plane resources already established by the first terminal device.

[0009] By determining the usage rate of the second user plane resource with enabled user plane integrity protection among the already established user plane resources, the remaining rate of the first terminal device can be accurately determined.

[0010] In a possible implementation, the used rate of the first terminal device can be determined according to a rate parameter; the rate parameter includes any one or any combination of the following: (a) the maximum bit rate of the protocol data unit (PDU) session aggregation of the second user plane resource; (b) the maximum aggregated bit rate of the terminal device of the first terminal device; (c) the maximum flow bit rate of the quality of service (QoS) QoS flow with the guaranteed bit rate (GBR) of the second user plane resource; (d) the guaranteed bit rate of the QoS flow with the GBR of the second user plane resource; (e) the real-time rate of the second user plane resource.

[0011] As follows, four possible implementations of determining the used rate are exemplarily shown.

[0012] Implementation Mode 1, the maximum value of the used rate.

[0013] In a possible implementation, the sum of the maximum bit rate of all PDU session aggregations and the maximum flow bit rate of all QoS flows with GBR is determined as the used rate; alternatively, the sum of the maximum aggregated bit rate of the terminal device and the maximum flow bit rate of all QoS flows with GBR is determined as the used rate.

[0014] Through the above Implementation Mode 1, the used rate is obtained based on the assumption that the second user plane resource transmits data at the maximum bit rate. In this way, the remaining rate represents the data transmission capacity that the terminal still has in the extreme case. Therefore, the timeliness of data transmission of the first terminal device can be guaranteed as much as possible. That is to say, this implementation mode starts from the perspective of the service availability of the first terminal device to determine whether to enable the user plane integrity protection of the first user plane resource.

[0015] Implementation Mode 2, the minimum value of the used rate.

[0016] In a possible implementation, the sum of the guaranteed bit rates of all QoS flows with GBR is determined as the used rate.

[0017] Through the above Implementation Mode 2, the used rate is obtained based on the assumption that the second user plane resource transmits data at the minimum bit rate. In this way, the security of data transmission of the first terminal device can be guaranteed as much as possible. That is to say, this implementation mode starts from the perspective of the security of data transmission of the first terminal device to determine whether to enable the user plane integrity protection of the first user plane resource.

[0018] Implementation Mode 3, the used rate is between the maximum value determined by the above Implementation Mode 1 and the minimum value determined by the above Implementation Mode 2.

[0019] In a possible implementation, the maximum bit rate obtained by aggregating all PDU sessions and the sum of the guaranteed bit rates of all QoS flows of GBR are determined as the used rate.

[0020] Through the above implementation method 3, the used rate is obtained based on the assumption of transmitting data at a moderate rate adjusted according to the second user plane resource usage. In this way, the remaining rate represents the comprehensive rate of the first terminal device, thus ensuring the availability of the communication services of the first terminal device as much as possible and ensuring the security of the data transmitted between the first terminal device and the network as much as possible.

[0021] Implementation method 4: Real-time monitor the real-time rate of the second user plane resource.

[0022] In a possible implementation, the sum of the real-time rates of all the monitored second user plane resources is determined as the used rate of the first terminal device.

[0023] Through the above implementation method 4, the used rate is obtained based on the assumption of transmitting data at the real-time rate of the second user plane resource usage. In this way, the remaining rate represents the accurate rate of the terminal. That is, the basis for the decision on whether to enable the user plane integrity protection is the most accurate data. Therefore, the availability or timeliness of the data transmitted by the first terminal device can be ensured as much as possible, and the security of the data transmitted by the first terminal device can be ensured as much as possible.

[0024] In a possible implementation, when the user plane security policy includes the enabling or optional enabling of the user plane integrity protection, if the remaining rate is greater than or equal to the required rate, a first indication message is sent to the first terminal device. The first indication message is used to indicate the enabling of the user plane integrity protection of the first user plane resource.

[0025] Through this communication method, the security of the data transmitted by the first terminal device can be ensured, and the timely transmission of the data of the communication service can be ensured.

[0026] In a possible implementation, when the user plane security policy includes the enabling of the user plane integrity protection, if the remaining rate is less than the required rate, a third user plane resource is obtained. The user plane security policy of the third user plane resource is the optional enabling of the user plane integrity protection, and the user plane integrity protection of the third user plane resource has been enabled, and the used rate of the third user plane resource is greater than or equal to the difference between the required rate and the remaining rate. A second indication message is sent to the first terminal device. The second indication message is used to indicate the enabling of the user plane integrity protection of the first user plane resource and is used to indicate the disabling of the user plane integrity protection of the third user plane resource.

[0027] Through this communication method, the security of the data corresponding to the first user plane resource for which the user plane integrity protection must be enabled can be ensured, that is, the security of the data transmitted by the first terminal device can be protected as much as possible, and the timely transmission of the data of the communication service can be guaranteed.

[0028] In a possible implementation manner, when the user plane security policy includes the optional enabling of user plane integrity protection, if the remaining rate is less than the required rate, the third indication information is sent to the first terminal, and the third indication is used to indicate not to enable the user plane integrity protection of the first user plane resource.

[0029] Through this communication method, the timely transmission of the data of the communication service of the first terminal device can be guaranteed as much as possible.

[0030] In a possible implementation manner, the method can be applied to a radio access network device; the radio access network device can receive the required rate, the maximum integrity protection rate, and the user plane security policy of the first terminal device from the session management function network element; the session management function network element obtains the required rate of the first terminal device from the policy control function network element, obtains the maximum integrity protection rate from the first terminal device; obtains the used rate from the context of the first terminal device; and determines the remaining rate according to the maximum integrity protection rate and the used rate.

[0031] In a possible implementation manner, the method can be applied to the master node of dual connectivity; the master node can obtain the required rate of the first terminal device from the policy control function network element, obtain the maximum integrity protection rate of the first terminal device from the session management function network element, and obtain the used rate from the context of the first terminal device; and determine the remaining rate according to the maximum integrity protection rate and the used rate.

[0032] Furthermore, the master node sends the fourth indication information to the secondary node of dual connectivity, and the fourth indication information is used for the secondary node to determine whether to enable the user plane integrity protection.

[0033] Through this communication method, the secondary node can also accurately determine whether to enable the user plane integrity protection of the first user plane resource.

[0034] In a possible implementation manner, the method can be applied to a radio access network device during a handover process; the radio access network device during the handover process can obtain a handover request message from the source radio access network device, and the handover request message includes the required rate, the user plane security policy, the maximum integrity protection rate, and the used rate of the first terminal device; and determine the remaining rate according to the maximum integrity protection rate and the used rate.

[0035] In a possible implementation, the method can be applied to a radio access network device during a radio resource control (RRC) connection restoration process; the radio access network device during the RRC connection restoration process can obtain a context response message of a first terminal device from a target radio access network device, where the context response message of the first terminal device includes the required rate of the first terminal device, a user plane security policy, a maximum integrity protection rate, and a used rate; and determine a remaining rate according to the maximum integrity protection rate and the used rate.

[0036] In a possible implementation, the method can be applied to a secondary node of a dual connection; the secondary node can receive the required rate, the maximum integrity protection rate, the used rate, and a user plane security policy sent by a master node of the dual connection; and determine a remaining rate according to the maximum integrity protection rate and the used rate.

[0037] Through this communication method, the secondary node can also accurately determine whether to enable user plane integrity protection for a first user plane resource.

[0038] In a possible implementation, the difference between the maximum integrity protection rate and the used rate can be determined as the remaining rate.

[0039] In a possible implementation, the method can be applied to a secondary node of a dual connection; the secondary node receives the required rate, the remaining rate, and a user plane security policy from the master node.

[0040] When the method is applied to a secondary node of a dual connection, the secondary node can also send the rate used for enabling user plane integrity protection for a first user plane resource to the master node of the dual connection.

[0041] Through this communication method, it is convenient for the master node to obtain and record the rate used for user plane integrity protection of this first user plane resource. When a new user plane resource is created next time, the rate used for user plane integrity protection of this first user plane resource is a second user plane resource. Thus, it is convenient to determine the used rate of the first terminal device.

[0042] In a possible implementation, the method can be applied to a second terminal device, and the second terminal device can receive the remaining rate and a user plane security policy from the first terminal device and obtain the required rate from the context of the first terminal device.

[0043] Second aspect, the present application provides a communication method, which can be executed by the master node of dual connection. The method includes obtaining the used rate, required rate, maximum integrity protection rate, and user plane security policy of a first terminal device; the required rate is used to indicate the rate required for the first user plane resource requested to be established by the first terminal device, the used rate is used to indicate the rate used by the second user plane resource already established by the first terminal device, the maximum integrity protection rate is used to indicate the maximum rate after the user plane integrity protection is enabled for the first terminal device, and the user plane security policy includes user plane integrity protection enabled, user plane integrity protection optionally enabled, or user plane integrity protection disabled; determining the remaining rate according to the maximum integrity protection rate and the used rate; and sending the remaining rate, required rate, and user plane security policy to the secondary node of the dual connection.

[0044] In a possible implementation, the rate used for enabling the user plane integrity protection of the first user plane resource from the secondary node may also be obtained and recorded.

[0045] Through this communication method, it is convenient for the master node to obtain and record the rate used for the user plane integrity protection of the first user plane resource. When a new user plane resource is created next time, the rate used for the user plane integrity protection of the first user plane resource is the second user plane resource. Thus, it is convenient to determine the used rate of the first terminal device.

[0046] Third aspect, the present application provides a communication method, which can be executed by the first terminal device. The method includes obtaining the used rate, maximum integrity protection rate, and user plane security policy of the first terminal device; determining the remaining rate according to the maximum integrity protection rate and the used rate; and sending the remaining rate and user plane security policy to the second terminal device. The used rate is used to indicate the rate used by the second user plane resource already established by the first terminal device, the maximum integrity protection rate is used to indicate the maximum rate after the user plane integrity protection is enabled for the first terminal device, and the user plane security policy includes user plane integrity protection enabled, user plane integrity protection optionally enabled, or user plane integrity protection disabled.

[0047] Fourth aspect, the present application provides a communication device, which has the function of implementing the above-mentioned first aspect or any one of the first aspect, or is used to implement the function of the above-mentioned second aspect or any one of the second aspect. This function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more units or modules corresponding to the above functions.

[0048] In a possible implementation, the communication device may include: a transceiver and a processor. The processor may be configured to support the communication device in performing the corresponding functions of the first aspect or the second aspect shown above, and the transceiver is used to support the communication device in communicating with a radio access network device, a terminal device, etc. Among them, the transceiver may be an independent receiver, an independent transmitter, a transceiver integrating transceiver functions, or an interface circuit. Optionally, the communication device may further include a memory, which may be coupled to the processor and stores necessary program instructions and data of the communication device.

[0049] Among them, the transceiver cooperates with the processor to obtain the required rate, remaining rate, and user plane security policy of the first terminal device. The required rate is used to indicate the rate required for the first user plane resource requested to be established by the first terminal device. The remaining rate is determined according to the used rate of the first terminal device and the maximum integrity protection rate of the first terminal device. The used rate is used to indicate the rate used by the second user plane resource already established by the first terminal device. The maximum integrity protection rate is used to indicate the maximum rate after the first terminal device enables user plane integrity protection; the user plane security policy includes user plane integrity protection enabled, user plane integrity protection optionally enabled, or user plane integrity protection disabled; the processor is used to determine whether to enable user plane integrity protection for the first user plane resource according to the required rate, remaining rate, and user plane security policy.

[0050] In a possible implementation, the second user plane resource includes the user plane resources with user plane integrity protection enabled among the user plane resources already established by the first terminal device.

[0051] In a possible implementation, the processor is further used to determine the used rate of the first terminal device according to the rate parameter; where the rate parameter includes any one or any combination of the following: the maximum bit rate of the protocol data unit (PDU) session aggregation of the second user plane resource; the maximum aggregated bit rate of the terminal device of the first terminal device; the maximum flow bit rate of the QoS flow of the GBR of the second user plane resource; the guaranteed bit rate of the QoS flow of the GBR of the second user plane resource; and, the real-time rate of the second user plane resource.

[0052] In a possible implementation, the processor is specifically used to determine the sum of the maximum bit rate of all PDU session aggregations and the maximum flow bit rate of all QoS flows of the GBR as the used rate; or, determine the sum of the maximum aggregated bit rate of the terminal device and the maximum flow bit rate of all QoS flows of the GBR as the used rate.

[0053] In a possible implementation, the processor is specifically used to: determine the sum of the guaranteed bit rates of all QoS flows of the GBR as the used rate.

[0054] In a possible implementation, the processor is specifically configured to: determine the sum of the maximum bit rate of all aggregated PDU sessions and the guaranteed bit rate of all QoS flows of GBR as the used rate.

[0055] In a possible implementation, when the user plane security policy includes enabling or optionally enabling user plane integrity protection, the processor is specifically configured to: if the remaining rate is greater than or equal to the required rate, send a first indication message to the first terminal device, where the first indication message is used to indicate enabling user plane integrity protection for the first user plane resource.

[0056] In a possible implementation, when the user plane security policy includes enabling user plane integrity protection, the processor is specifically configured to: if the remaining rate is less than the required rate, obtain a third user plane resource, where the user plane security policy of the third user plane resource is optionally enabling user plane integrity protection, and the user plane integrity protection of the third user plane resource has been enabled, and the used rate of the third user plane resource is greater than or equal to the difference between the required rate and the remaining rate, send a second indication message to the first terminal device, where the second indication message is used to indicate enabling user plane integrity protection for the first user plane resource and is used to indicate disabling user plane integrity protection for the third user plane resource.

[0057] In a possible implementation, when the user plane security policy includes optionally enabling user plane integrity protection, the processor is specifically configured to: if the remaining rate is less than the required rate, send a third indication message to the first terminal, where the third indication is used to indicate disabling user plane integrity protection for the first user plane resource.

[0058] In a possible implementation, the communication device is applied to a radio access network device; the transceiver is specifically configured to: receive the required rate, the maximum integrity protection rate, and the user plane security policy of the first terminal device from the session management function network element; the session management function network element obtains the required rate of the first terminal device from the policy control function network element and obtains the maximum integrity protection rate from the first terminal device; obtain the used rate from the context of the first terminal device; the processor is specifically configured to determine the remaining rate according to the maximum integrity protection rate and the used rate.

[0059] In a possible implementation, the communication device is applied to the master node of a dual connection; the transceiver is further configured to: send a fourth indication message to the secondary node of the dual connection, where the fourth indication message is used for the secondary node to determine whether to enable user plane integrity protection.

[0060] In a possible implementation, the communication device is applied to a radio access network device during a handover process; the transceiver is specifically configured to: obtain a handover request message from a source radio access network device, where the handover request message includes the required rate, user plane security policy, maximum integrity protection rate, and used rate of a first terminal device; the processor is specifically configured to: determine the remaining rate according to the maximum integrity protection rate and the used rate.

[0061] In a possible implementation, the communication device is applied to a radio access network device during an RRC connection restoration process; the transceiver is specifically configured to: obtain a context response message of a first terminal device from a target radio access network device, where the context response message of the first terminal device includes the required rate, user plane security policy, maximum integrity protection rate, and used rate of the first terminal device; the processor is specifically configured to: determine the remaining rate according to the maximum integrity protection rate and the used rate.

[0062] In a possible implementation, the communication device is applied to a secondary node of a dual connection; the transceiver is specifically configured to: receive the required rate, maximum integrity protection rate, used rate, and user plane security policy sent by a primary node of the dual connection; the processor is specifically configured to: determine the remaining rate according to the maximum integrity protection rate and the used rate.

[0063] In a possible implementation, the processor is specifically configured to: determine the difference between the maximum integrity protection rate and the used rate as the remaining rate.

[0064] In a possible implementation, the communication device is applied to a secondary node of a dual connection; the transceiver is specifically configured to: the secondary node receives the required rate, remaining rate, and user plane security policy from the primary node.

[0065] In a possible implementation, the transceiver is further configured to: send the rate used for enabling user plane integrity protection of a first user plane resource to the primary node of the dual connection.

[0066] In a possible implementation, the communication device is applied to a second terminal device; the transceiver is specifically configured to: receive the remaining rate and user plane security policy from a first terminal device; obtain the required rate from the context of the first terminal device.

[0067] In a fifth aspect, the present application provides a communication device for implementing the above first aspect or any method in the first aspect, or for implementing the above second aspect or any method in the second aspect, including corresponding functional modules respectively used to implement the steps in the above methods. The functions can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions.

[0068] In a possible implementation, the communication device may include a processing module and a transceiver module. Among them, the transceiver module cooperates with the processing module to obtain the required rate, remaining rate, and user plane security policy of the first terminal device. The required rate is used to indicate the rate required for the first user plane resource that the first terminal device requests to establish. The remaining rate is determined according to the used rate of the first terminal device and the maximum integrity protection rate of the first terminal device. The used rate is used to indicate the rate used by the second user plane resource that the first terminal device has established. The maximum integrity protection rate is used to indicate the maximum rate of the first terminal device after enabling user plane integrity protection. The user plane security policy includes enabling user plane integrity protection, optionally enabling user plane integrity protection, or disabling user plane integrity protection. The processing module is used to determine whether to enable user plane integrity protection for the first user plane resource according to the required rate, remaining rate, and user plane security policy.

[0069] In a possible implementation, the second user plane resource includes the user plane resources with user plane integrity protection enabled among the user plane resources established by the first terminal device.

[0070] In a possible implementation, the processing module is further used to determine the used rate of the first terminal device according to the rate parameter. Wherein, the rate parameter includes any one or any combination of the following: the maximum bit rate of the protocol data unit (PDU) session aggregation of the second user plane resource; the maximum aggregated bit rate of the first terminal device; the maximum flow bit rate of the quality of service (QoS) flow with guaranteed bit rate (GBR); the guaranteed bit rate of the QoS flow with guaranteed bit rate (GBR); and, the real-time rate of the second user plane resource.

[0071] In a possible implementation, the processing module is specifically used to determine the sum of the maximum bit rate of all PDU session aggregations and the maximum flow bit rate of all QoS flows with GBR as the used rate; or, determine the sum of the maximum aggregated bit rate of the terminal device and the maximum flow bit rate of all QoS flows with GBR as the used rate.

[0072] In a possible implementation, the processing module is specifically used to: determine the sum of the guaranteed bit rates of all QoS flows with GBR as the used rate.

[0073] In a possible implementation, the processing module is specifically used to: determine the sum of the maximum bit rate of all PDU session aggregations and the sum of the guaranteed bit rates of all QoS flows with GBR as the used rate.

[0074] In a possible implementation, when the user plane security policy includes enabling or optionally enabling user plane integrity protection, the processing module is specifically configured to: if the remaining rate is greater than or equal to the required rate, send a first indication message to the first terminal device, where the first indication message is used to indicate enabling the user plane integrity protection of the first user plane resource.

[0075] In a possible implementation, when the user plane security policy includes enabling user plane integrity protection, the processing module is specifically configured to: if the remaining rate is less than the required rate, obtain a third user plane resource, where the user plane security policy of the third user plane resource is optionally enabling user plane integrity protection, and the user plane integrity protection of the third user plane resource has been enabled, and the used rate of the third user plane resource is greater than or equal to the difference between the required rate and the remaining rate, send a second indication message to the first terminal device, where the second indication message is used to indicate enabling the user plane integrity protection of the first user plane resource and is used to indicate not enabling the user plane integrity protection of the third user plane resource.

[0076] In a possible implementation, when the user plane security policy includes optionally enabling user plane integrity protection, the processing module is specifically configured to: if the remaining rate is less than the required rate, send a third indication message to the first terminal, where the third indication is used to indicate not enabling the user plane integrity protection of the first user plane resource.

[0077] In a possible implementation, the communication device is applied to a radio access network device; the transceiver module is specifically configured to: receive the required rate, the maximum integrity protection rate, and the user plane security policy of the first terminal device from the session management function network element; the session management function network element obtains the required rate of the first terminal device from the policy control function network element and obtains the maximum integrity protection rate from the first terminal device; obtain the used rate from the context of the first terminal device; the processing module is specifically configured to: determine the remaining rate according to the maximum integrity protection rate and the used rate.

[0078] In a possible implementation, the communication device is applied to the master node of a dual connection; the transceiver module is further configured to: send a fourth indication message to the secondary node of the dual connection, where the fourth indication message is used for the secondary node to determine whether to enable user plane integrity protection.

[0079] In a possible implementation, the communication device is applied to a radio access network device during a handover process; the transceiver module is specifically configured to: obtain a handover request message from the source radio access network device, where the handover request message includes the required rate, the user plane security policy, the maximum integrity protection rate, and the used rate of the first terminal device; the processing module is specifically configured to: determine the remaining rate according to the maximum integrity protection rate and the used rate.

[0080] In a possible implementation, the communication device is applied to a radio access network device in an RRC connection restoration process; the transceiver module is specifically configured to: obtain a context response message of a first terminal device from a target radio access network device, where the context response message of the first terminal device includes the required rate, user plane security policy, maximum integrity protection rate, and used rate of the first terminal device; the processing module is specifically configured to: determine the remaining rate according to the maximum integrity protection rate and the used rate.

[0081] In a possible implementation, the communication device is applied to a secondary node of a dual connection; the transceiver module is specifically configured to: receive the required rate, maximum integrity protection rate, used rate, and user plane security policy sent by a master node of the dual connection; the processing module is specifically configured to: determine the remaining rate according to the maximum integrity protection rate and the used rate.

[0082] In a possible implementation, the processing module is specifically configured to: determine the difference between the maximum integrity protection rate and the used rate as the remaining rate.

[0083] In a possible implementation, the communication device is applied to a secondary node of a dual connection; the transceiver module is specifically configured to: the secondary node receives the required rate, remaining rate, and user plane security policy from the master node.

[0084] In a possible implementation, the transceiver module is further configured to: send the rate used for enabling user plane integrity protection of a first user plane resource to the master node of the dual connection.

[0085] In a possible implementation, the communication device is applied to a second terminal device; the transceiver module is specifically configured to: receive the remaining rate and user plane security policy from a first terminal device; obtain the required rate from the context of the first terminal device.

[0086] In a sixth aspect, the present application provides a computer-readable storage medium, in which a computer program or instruction is stored. When the computer program or instruction is executed by a communication device, the communication device is caused to execute the method in the first aspect or any possible implementation manner of the first aspect, or the communication device is caused to execute the method in the second aspect or any possible implementation manner of the second aspect.

[0087] In a seventh aspect, the present application provides a computer program product, which includes a computer program or instruction. When the computer program or instruction is executed by a communication device, the method in the first aspect or any possible implementation manner of the first aspect is implemented, or the method in the second aspect or any possible implementation manner of the second aspect is implemented.

[0088] The technical effects achievable by any one of the above fourth aspect and fifth aspect can be referred to the description of the beneficial effects in the above first aspect, and will not be repeated here. Brief Description of the Drawings

[0089] Figure 1a A schematic diagram of a communication system architecture provided by the present application;

[0090] Figure 1b A schematic diagram of a communication system architecture provided by the present application;

[0091] Figure 2 A schematic diagram of a communication system architecture provided by the present application;

[0092] Figure 3 A schematic diagram of the method flow of a communication method provided by the present application;

[0093] Figure 4 A schematic diagram of the method flow of a communication method applied to a radio access network device provided by the present application;

[0094] Figure 5 A schematic diagram of the method flow of a communication method applied to a radio access network device during a handover process provided by the present application;

[0095] Figure 6 A schematic diagram of the method flow of a communication method applied to a radio access network device during an RRC connection restoration process provided by the present application;

[0096] Figure 7 A schematic diagram of the method flow of a communication method applied to a secondary node in a dual connection provided by the present application;

[0097] Figure 8 A schematic diagram of the method flow of another communication method applied to a secondary node in a dual connection provided by the present application;

[0098] Figure 9 A schematic diagram of the method flow of a communication method applied to a master node in a dual connection provided by the present application;

[0099] Figure 10 A schematic diagram of the method flow of yet another communication method applied to a radio access network device provided by the present application;

[0100] Figure 11 A schematic diagram of the method flow of a communication method applied to a second terminal device provided by the present application;

[0101] Figure 12 A schematic diagram of the structure of a communication device provided by the present application;

[0102] Figure 13Schematic diagram of a communication device provided by this application.

[0103] Figure 14 Schematic diagram of a terminal device provided by this application;

[0104] Figure 15 Schematic diagram of a radio access network device provided by this application. Detailed implementation manners

[0105] The embodiments of this application will be described in detail below in conjunction with the accompanying drawings.

[0106] Some terms in this application are explained below to facilitate understanding by those skilled in the art.

[0107] I. Maximum integrity protection rate

[0108] The maximum integrity protection rate is used to represent the maximum rate after the terminal device enables user plane integrity protection. The maximum integrity protection rate includes the uplink maximum integrity protection rate and the downlink maximum integrity protection rate. The uplink maximum integrity protection rate represents the maximum uplink rate after the terminal device enables user plane integrity protection. The downlink maximum integrity protection rate represents the maximum downlink rate after the terminal device enables user plane integrity protection. For example, when the uplink maximum integrity protection rate is 64 kilobits per second, it means that after the terminal device enables user plane integrity protection, the maximum rate at which data can be sent to the radio access network device is 64 kilobits per second. When the downlink maximum integrity protection rate is 64 kilobits per second, it means that after the terminal device enables user plane integrity protection, the maximum rate at which data can be received from the radio access network device is 64 kilobits per second. For another example, when the downlink maximum integrity protection rate is the full data rate, it means that after the terminal device enables user plane integrity protection, there is no limit to the rate of receiving data from the radio access network device. Exemplarily, the current uplink maximum integrity protection rate values include two values: 64 kilobits per second (kbps) and the full data rate (full-data-rate). The current downlink maximum integrity protection rate values include two values: 64 kilobits per second (kbps) and the full data rate (full-data-rate). To solve the problem that the user plane integrity protection between the UE and the access network device is always turned off when the maximum integrity protection rate value currently includes 64 kilobits per second (kbps), and the performance of the UE may be overloaded when the maximum integrity protection rate value is the full data rate (full-data-rate), in the embodiments of this application, the uplink or downlink maximum integrity protection rate can include more values, such as 1 gigabit per second (Gbps), 2 Gbps, etc. The uplink maximum integrity protection rate and the downlink maximum integrity protection rate can be equal or not equal, and this application does not make any limitations in this regard.

[0109] II. Required Rate

[0110] The required rate is used to represent the rate required for the terminal device to newly establish user plane resources with the radio access network device. The required rate includes the uplink required rate and the downlink required rate. Specifically, the uplink required rate may include the maximum rate, minimum rate, or average rate at which the terminal device sends data to the radio access network device (such as a base station) on the user plane resources, and the downlink required rate includes the maximum rate, minimum rate, or average rate at which the radio access network device sends data to the terminal device on the user plane resources. Among them, the user plane resources include one or more data resource bearers (DRBs), and the DRB defines the processing method for packets on the radio interface (Uu).

[0111] In the 5G system, when the terminal device requests to establish or modify a protocol data unit (PDU) session, it simultaneously requests to establish one or more QoS flows. The radio access network device can establish a new DRB or multiplex it onto an existing DRB to transmit the QoS flows.

[0112] For non-guaranteed bit rate (Non-GBR) QoS flows, the required rate can be the maximum bit rate aggregated by the PDU session, i.e., the PDU session Aggregate Maximum Bit Rate, which is used to limit the aggregated bit rate of all Non-GBR QoS flows of a specific PDU session. The uplink required rate can be the maximum uplink bit rate aggregated by the PDU session, and the downlink required rate can be the maximum downlink bit rate aggregated by the PDU session. The required rate can also be the aggregated maximum bit rate of the terminal device, i.e., the UE Aggregate Maximum Bit Rate, which is used to limit the aggregated bit rate that all Non-GBR QoS flows of a terminal device can provide. The uplink required rate can be the aggregated maximum uplink bit rate of the terminal device, and the downlink required rate can be the aggregated maximum downlink bit rate of the terminal device.

[0113] For a QoS flow with guaranteed bit rate (GBR), the required rate can be the maximum flow bit rate, i.e., Maximum Flow Bit Rate, which is used to limit the highest flow bit rate expected for the QoS flow. The uplink required rate can be the uplink maximum flow bit rate, and the downlink required rate can be the downlink maximum flow bit rate. The required rate can also be the guaranteed flow bit rate, i.e., Guaranteed Flow Bit Rate, which is used to represent the flow bit rate that the network guarantees to provide for the QoS flow within an average time window. The uplink required rate can be the uplink guaranteed flow bit rate, and the downlink required rate can be the downlink guaranteed flow bit rate.

[0114] In a 4G system, when a terminal device requests to establish or modify an evolved packet system (EPS) bearer, a new DRB is simultaneously requested to be established.

[0115] For a Non-GBR EPS bearer, the required rate can be the per access point network (APN) aggregate maximum bit rate, i.e., per APN Aggregate Maximum Bit Rate, which is used to limit the aggregate bit rate that all Non-GBR EPS bearers of all PDN connections with the same APN can provide. The uplink required rate can be the per APN aggregate uplink maximum bit rate, and the downlink required rate can be the per APN aggregate downlink maximum bit rate. The required rate can also be the per UE aggregate maximum bit rate, i.e., per UE Aggregate Maximum Bit Rate, which is used to limit the aggregate bit rate that all Non-GBR EPS bearers of a UE can provide. The uplink required rate can be the per UE aggregate uplink maximum bit rate, and the downlink required rate can be the per UE aggregate downlink maximum bit rate.

[0116] For a GBR EPS bearer, the required rate can be the maximum flow bit rate, i.e., Maximum Flow Bit Rate, which is used to limit the highest flow bit rate expected for the EPS bearer. The uplink required rate can be the uplink maximum flow bit rate, and the downlink required rate can be the downlink maximum flow bit rate. The required rate can be the guaranteed flow bit rate, i.e., Guaranteed Flow Bit Rate, which is used to represent the flow bit rate that the network guarantees to provide for the EPS bearer within an average time window. The uplink required rate can be the uplink guaranteed flow bit rate, and the downlink required rate can be the downlink guaranteed flow bit rate.

[0117] III. Used Rate

[0118] The used rate is used to represent the rate at which the user plane resources established by the terminal device are used. The used rate can be the real-time rate at which the user plane resources established by the terminal device are used. At the same time, since the real-time rate often changes and it is impossible to stably evaluate the usage rate of the terminal at a certain moment, therefore, the used rate can also be the estimated rate at which the user plane resources established by the terminal device are used. The estimated rate can be obtained according to the required rate for establishing the user plane resources. The maximum integrity protection rate is used to represent the maximum rate after the user plane integrity protection of the terminal device is enabled, and is an indicator for characterizing the UE performance, while the used rate can be used to characterize the performance that the UE has used at the integrity protection rate.

[0119] It should be understood that the used rate includes the uplink used rate and the downlink used rate.

[0120] Taking the user plane resource as the DRB as an example, exemplarily, the terminal device has established DRB1, DRB2, and DRB3. The uplink rate used by DRB1 is A1, the downlink rate is B1, the uplink rate used by DRB2 is A2, the downlink rate is B2, and the uplink rate used by DRB3 is A3, and the downlink rate is B3. Then the uplink used rate of the terminal device is A1 + A2 + A3, and the downlink used rate is B1 + B2 + B3.

[0121] IV. User plane security policy

[0122] The user plane security policy includes user plane encryption protection and user plane integrity protection. The user plane encryption protection can be indicated by three possible values, namely not needed, preferred, and required; the user plane integrity protection can also be indicated by three possible values, namely not needed, preferred, and required. Among them, not needed means that it is not necessary to enable; preferred means that it is optional to enable, or is called recommended to enable, that is, it can be enabled or not; required means that it must be enabled. The above three possible values can be indicated by 2 bits (bit). For example, 00 indicates that it is not necessary to enable, 01 indicates that it can be enabled or not, and 11 indicates that it must be enabled. In the embodiments of the present application, there is no limitation on the specific manner in which the user plane encryption protection indication information and the user plane integrity protection indication information indicate the three possible values. Since the user plane encryption protection does not affect the communication rate, the implementation of the user plane encryption protection in the present application is not limited.

[0123] Based on the above content, Figure 1a is a schematic diagram of the architecture of a communication system applicable to the present application. As Figure 1aAs shown, the communication system may include a data management network element, an authentication service network element, a mobility management network element, a session management network element, a policy control network element, a user plane network element, an access network device, and a terminal device. Figure 1a Taking the data management network element as the unified data management (UDM), the authentication service network element as the authentication server function (AUSF), the mobility management network element as the access and mobility management function (AMF), the session management network element as the session management function (SMF), the policy control network element as the policy control function (PCF), the user plane network element as the user plane function (UPF), and the terminal device as the UE as an example.

[0124] The data management network element is mainly used to manage and store user data, such as subscription information, authentication / authorization information. In 5G, the data management network element can be a UDM network element or a unified data repository (UDR) network element. In future communications such as the 6th generation (6G), the data management network element can still be a UDM network element or a UDR network element, or have other names, which are not limited in this application.

[0125] The authentication service network element is mainly used to use the extensible authentication protocol (EAP) authentication service function and store keys to implement user authentication and authorization. In 5G, the authentication server network element can be an AUSF network element. In future communications such as 6G, the authentication server network element can still be an AUSF network element, or have other names, which are not limited in this application.

[0126] The mobility management network element is mainly used for the registration of terminal devices in the mobile network, mobility management, and tracking area update process. The mobility management network element terminates non-access stratum (NAS) messages, completes registration management, connection management, reachability management, allocates a track area list (TA list), and performs mobility management, etc., and transparently routes session management (SM) messages to the session management network element. In 5G communication, the mobility management network element can be the AMF network element. In future communications such as 6G, the mobility management network element can still be the AMF network element, or have other names, which are not limited in this application.

[0127] The session management network element is mainly used for session management in the mobile network and the selection and control of user plane network elements. Among them, session management includes session creation, modification, and release. Specific functions include, for example, allocating Internet Protocol (IP) addresses for users, selecting user plane network elements that provide packet forwarding functions, etc. In 5G, the session management network element can be the SMF network element. In future communications such as 6G, the session management network element can still be the SMF network element, or have other names, which are not limited in this application. The messages for the terminal device to communicate with the SMF are encapsulated in the SM container of the NAS message, and the AMF extracts the SM container content from the NAS message and then sends it to the SMF.

[0128] The policy control network element is mainly used for the management of user subscription data, charging policy control, quality of service (QoS) control, etc. In 5G, the policy control network element can be the PCF network element. In future communications such as 6G, the policy control network element can still be the PCF network element, or have other names, which are not limited in this application.

[0129] The user plane network element is mainly used for the processing of user plane services, such as packet routing and transmission, packet detection, service usage reporting, quality of service (QoS) processing, lawful interception, uplink packet detection, downlink packet storage, etc. In 5G, the user plane network element can be the UPF network element. In future communications such as 6G, the user plane network element can still be the UPF network element, or have other names, which are not limited in this application.

[0130] An access network device (also known as a radio access network (RAN) device) is an access device through which a terminal device accesses the communication system wirelessly. It can be a base station, an evolved NodeB (eNB), a transmission reception point (TRP), a next generation NodeB (gNB) in a 5G communication system, a next generation-evolved NodeB (ng-eNB), a Node B (NB), a base station controller (BSC), a base transceiver station (BTS), a home base station (e.g., home evolved nodeB, or home node B, HNB), a base station in a future communication system, or an access node in a wireless-fidelity (WiFi) system, etc. It can also be a module or unit that completes some functions of the base station. For example, it can be a central unit (CU) or a distributed unit (DU). Embodiments of this application do not limit the specific technologies and specific device forms adopted by the access network device.

[0131] A terminal device can also be referred to as a terminal, a user equipment (UE), a mobile station, a mobile terminal, etc. The terminal device can be a mobile phone, a tablet computer, a computer with wireless transceiver function, a virtual reality terminal device, an augmented reality terminal device, a wireless terminal in industrial control, a wireless terminal in unmanned driving, a wireless terminal in remote surgery, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, etc. This application does not limit the specific technologies and specific device forms adopted by the terminal device.

[0132] This application can also be applied to a 4th generation (4G) communication system. As Figure 1b shown, it is a schematic diagram of the architecture of another communication system to which this application can be applied. Figure 1bThis is exemplified by taking the data management network element as the Home Subscriber Server (HSS), part of the functions of the mobility management network element as the Mobility Management Entity (MME), part of the functions of the session management network element as the MME and part of the functions of the Serving Gateway (SGW), the policy control network element as the Policy and Charging Rules Function (PCRF), part of the functions of the user plane network element as the Packet Data Gateway (PGW), and the terminal device as the UE.

[0133] The core network elements in this communication system are all core network elements in the LTE network. Among them, the interface between the MME and the E-UTRAN is the S1-MME interface, that is, the interface between the eNodeB and the MME, which is used to transmit user data and corresponding user plane control frames. The interface between the PGW and the SGW is the S5 / S8 interface. The S5 interface is the interface between the SGW and the PGW inside the network. This interface should be able to provide the function of SGW relocation during the user's movement in the case where the SGW and the PGW are separately set up. The S8 is the interface between the SGW and the PGW across the Public Land Mobile Network (PLMN), and has the functions of the S5 interface in the case of roaming. The interface between the SGW and the E-UTRAN is the S1-U interface, that is, the interface between the eNodeB and the SGW, which is used to carry the user plane tunnel and the path exchange between eNodeBs during handover. The interface between the SGW and the MME is the S11 interface, which is used to transmit information such as bearer control and session control. The interface between the HSS and the MME is the S6a interface. The S6a interface is mainly used for functions such as user access authentication, inserting user subscription data, authorizing the user to access the PDN, and authenticating the user's mobility management messages when interconnected with non-3GPP systems.

[0134] This application can also be applied to a dual-connectivity network architecture. As Figure 2 shown, it is another communication system architecture to which this application can be applied. This communication system architecture can include a Master Node (MN), a Secondary Node (SN), a Core Network (CN), and a terminal device. In a dual-connectivity communication system, the node that initiates the dual-connectivity is called the master node, and can also be called the primary network node or the primary base station, etc. Another node selected by the master node to cooperate in serving the terminal device is called the secondary node, and can also be called the secondary network node or the secondary base station.

[0135] The following exemplarily shows five dual-connection network architectures.

[0136] For Network Architecture 1, MN is an eNB, SN is an eNB, and CN is an MME. Among them, MN communicates with SN through the X2 interface, and MN communicates with CN through the S1 interface, that is, MN is connected to the MME in the 4G core network through the S1 interface.

[0137] For Network Architecture 2, MN is an eNB, SN is a gNB, and CN is an MME. Among them, MN communicates with SN through the X2 interface, and MN communicates with CN through the S1 interface, that is, MN can be connected to the MME in the 4G core network through the S1 interface. This Network Architecture 2 can also be called the E-UTRA-NR dual connectivity (EN-DC) network architecture.

[0138] For Network Architecture 3, MN is a gNB, SN is an ng-eNB, and CN is an AMF. Among them, MN communicates with SN through the Xn interface, and MN communicates with CN through the N2 interface, that is, MN can be connected to the AMF in the 5G core network through the N2 interface.

[0139] For Network Architecture 4, MN is an ng-eNB, SN is a gNB, and CN is an AMF. Among them, MN communicates with SN through the Xn interface, and MN communicates with CN through the N2 interface, that is, MN can be connected to the AMF in the 5G core network through the N2 interface.

[0140] For Network Architecture 5, MN is a gNB, SN is a gNB, and CN is an AMF. Among them, MN communicates with SN through the Xn interface, and MN communicates with CN through the N2 interface, that is, MN can be connected to the AMF in the 5G core network through the N2 interface.

[0141] In the above five dual-connection network architectures, the terminal device can communicate with MN or SN respectively through the Uu interface. For the specific possible forms, please refer to the introduction of the terminal device above Figure 1a and will not be repeated here.

[0142] It should be understood that the above Figure 1a , Figure 1b and Figure 2 are only schematic diagrams, Figure 1a and Figure 1b the shown communication systems may also include other radio access network devices, such as wireless relay devices and wireless backhaul devices, which are not drawn in Figure 1a and Figure 1b . This application does not limit the number of core network devices, access network devices, and terminal devices included in the communication system.

[0143] It should be noted that the system architecture and application scenarios described in this application are for more clearly explaining the technical solution of this application, and do not constitute a limitation to the technical solution provided by this application. As is known to those of ordinary skill in the art, with the evolution of the system architecture and the emergence of new business scenarios, the technical solution provided by this application is equally applicable to similar technical problems.

[0144] Currently, when the RAN determines whether to enable the integrity protection of the PDU session, it is based on the two values of the maximum integrity protection rate of the UE, which are 64 Kbps and the full data rate, and the user plane security policy of the PDU session. Specifically, if the maximum integrity protection rate of the UE is 64 Kbps and the user plane integrity protection policy of this PDU session is preferred, then the RAN determines that the user plane integrity protection of this DRB is not enabled; if the maximum integrity protection rate of the UE is the full data rate and the user plane integrity protection policy of this PDU session is preferred, then the RAN determines whether to enable the user plane integrity protection of this PDU session according to its own situation (for example, if its own resources are sufficient, it is enabled; otherwise, it is not enabled). If the user plane integrity protection policy is not needed, then the RAN directly does not enable the user plane integrity protection. If the maximum integrity protection rate of the UE is 64 Kbps and the user plane integrity protection policy of this PDU session is required, the SMF rejects the establishment or modification of the PDU session and does not need to allocate a DRB from the RAN side.

[0145] However, currently in the standard, there are only two values for the maximum integrity protection rate, which are 64 Kbps and the full data rate. These are two extreme values, one is infinitely small and the other is infinitely large. When the maximum integrity protection rate of the UE is 64 Kbps (this value is very small), it means that the user plane integrity protection cannot be enabled most of the time during the data transmission between the UE and the network side, so the security of user data is not guaranteed. When the maximum integrity protection rate of the UE is the full data rate (this value is infinite), it means that whether to enable the user plane integrity protection during the data transmission between the UE and the network side is completely determined by the RAN. In the case where the user plane integrity protection policy is preferred and the RAN resources are sufficient, all data transmissions between the UE and the network side may enable the user plane integrity protection. Since enabling the user plane integrity protection will have a greater impact on the performance of the UE, the services on the UE may be abnormal. For example, due to the inability of the UE performance to keep up, the timeliness of data transmission cannot meet the requirements.

[0146] In view of this, the present application proposes a communication method. When determining whether to enable the integrity protection of the first user plane resource, this communication method fully considers the maximum integrity protection rate of the terminal device and the used rate of the user plane resources on the terminal device for which integrity protection has been enabled, so as to ensure the timeliness and security of the transmission data of the terminal device as much as possible. For example, the maximum integrity protection rate of the terminal device is 1000 Mbps, and the total used rate of the user plane resources corresponding to the user plane integrity protection enabled on the terminal device is 400 Mbps. At this time, if the rate corresponding to the first user plane resource requested to be established by the terminal device is less than 600 Mbps, the terminal device can still enable the user plane integrity protection of the first user plane resource. That is, the user plane integrity protection of the terminal device and the network side can be enabled on demand according to the capabilities of the UE, which helps to avoid the situation where when the maximum integrity protection rate of the terminal device is 64 Kbps, the user plane integrity protection between the terminal device and the network side is always disabled, resulting in the security of the transmitted data not being guaranteed, or when the maximum integrity protection rate of the terminal device is the full data rate, the user plane integrity protection between the terminal device and the network side is always enabled, resulting in abnormal performance of the terminal device.

[0147] The following refers to Figure 3 , which is a schematic diagram of the method flow of a communication method provided by the present application. The method includes the following steps:

[0148] Step 301, the first communication device obtains the required rate, remaining rate, and user plane security policy of the first terminal device.

[0149] Among them, the user plane security policy includes user plane integrity protection enabled, user plane integrity protection optionally enabled, or user plane integrity protection disabled. The required rate is used to indicate the rate required for the first user plane resource requested to be established by the first terminal device. Among them, the first user plane resource is the user plane resource to be established between the first terminal device and the first communication device. The first user plane resource may include one or more data bearers, such as DRB, sidelink radio bearer (SLRB). The remaining rate is determined according to the used rate of the first terminal device and the maximum integrity protection rate of the first terminal device. The maximum integrity protection rate is used to indicate the maximum rate after the first terminal device enables user plane integrity protection. It should be understood that this user plane security policy is used to determine whether to enable the integrity protection of the first user plane resource. That is to say, this user plane security policy is the user plane security policy corresponding to the first user plane resource to be established by the first terminal device. In addition, the first user plane resource may include one or more DRBs, and the user plane security policies of these one or more DRBs included in the first user plane resource are the same.

[0150] Here, the used rate is used to indicate the rate used by the second user plane resource established between the first terminal device and the first communication device. Optionally, the second user plane resource includes all the user plane resources established by the first terminal device. Optionally, the second user plane resource includes the user plane resources with user plane integrity protection enabled among the user plane resources established by the first terminal device. Further, if the second user plane resources established by the first terminal device include one, the used rate of the first terminal device is equal to the rate used by this second user plane resource; if the second user plane resources established by the first terminal device include multiple ones, the used rate of the first terminal device is equal to the sum of the rates used by each of these multiple established second user plane resources.

[0151] Exemplarily, taking the DRB as the user plane resource, the user plane resources established by the first terminal device include DRB11, DRB12, DRB13, and DRB14. Among them, user plane integrity protection has been enabled for DRB11, DRB12, and DRB13, and user plane integrity protection has not been enabled for DRB14. Then, the second user plane resource includes DRB11, DRB12, and DRB13. Further, the used rate is equal to the sum of the rates used by DRB11, the rate used by DRB12, and the rate used by DRB13.

[0152] In a possible implementation manner, the difference between the maximum integrity protection rate and the used rate can be determined as the remaining rate. Further, the maximum integrity protection rate includes the uplink maximum integrity protection rate and the downlink maximum integrity protection rate, the required rate includes the uplink required rate and the downlink required rate, and the remaining rate includes the uplink remaining rate and the downlink rate; the uplink remaining rate is equal to the difference between the uplink maximum integrity protection rate and the uplink required rate, and the downlink remaining rate is equal to the difference between the downlink maximum integrity protection rate and the downlink required rate.

[0153] In a possible implementation manner, the first communication device may be a radio access network device. The process by which the radio access network device obtains the required rate, the remaining rate, and the user plane security policy of the first terminal device can be seen in the following Figure 4 or the introduction in item 10; or, the first communication device may be a radio access network device during the handover process. The process by which the radio access network device during the handover process obtains the required rate, the remaining rate, and the user plane security policy of the first terminal device can be seen in the following Figure 5 introduction of the target radio access network in the following; or, the first communication device may be a radio access network device during the RRC connection restoration process. The process by which the radio access network device during the RRC connection restoration process obtains the required rate, the remaining rate, and the user plane security policy of the first terminal device can be seen in the following Figure 6Introduction; alternatively, the first communication device may be a secondary node in dual connectivity. For the process of the secondary node obtaining the required rate, remaining rate, and user plane security policy of the first terminal device, refer to the following Figure 7 or Figure 8 Introduction; alternatively, the first communication device may be a master node in dual connectivity. For the process of the master node obtaining the required rate, remaining rate, and user plane security policy of the first terminal device, refer to the following Figure 9 Introduction; alternatively, the first communication device may be a second terminal device. For the process of the second terminal device obtaining the required rate, remaining rate, and user plane security policy of the first terminal device, refer to the following Figure 11 Introduction; details are not repeated here.

[0154] Step 302, the first communication device may determine whether to enable the user plane integrity protection of the first user plane resource according to the required rate, remaining rate, and user plane security policy.

[0155] Here, based on the user plane security policy, three possible implementation manners for determining whether to enable the user plane integrity protection of the first user plane resource are exemplarily shown in different scenarios.

[0156] Scenario 1, the user plane security policy includes enabling (required) user plane integrity protection.

[0157] Based on Scenario 1, if the remaining rate is greater than or equal to the required rate, send a first indication message to the first terminal device, where the first indication message is used to indicate enabling the user plane integrity protection of the first user plane resource. Correspondingly, the first terminal device receives the first indication message and enables the user plane integrity protection of the first user plane resource according to the first indication message. It should be understood that if the remaining rate is greater than or equal to the required rate, it means that enabling the user plane integrity protection of the first user plane resource will not affect the normal communication service of the first terminal device.

[0158] Based on Scenario 1, if the remaining rate is less than the required rate, obtain a third user plane resource and send a second indication message to the first terminal device, where the second indication message is used to indicate enabling the user plane integrity protection of the first user plane resource and is used to indicate disabling (i.e., closing) the user plane integrity protection of the third user plane resource. Here, the user plane security policy of the third user plane resource is optional enabling of user plane integrity protection, and the user plane integrity protection of the third user plane resource has been enabled, and the used rate of the third user plane resource is greater than or equal to the difference between the required rate and the remaining rate. Correspondingly, the first terminal device receives the second indication message, enables the user plane integrity protection of the first user plane resource according to the second indication message, and closes the user plane integrity protection of the third user plane resource.

[0159] It should be noted that the third user plane resource may be one or multiple. That is to say, for the user plane security policy in the first terminal device, the user plane resources with optional and enabled user plane integrity protection may be multiple. One user plane resource whose used rate is greater than or equal to the difference between the required rate and the remaining rate can be selected from these multiple user plane resources, and the selected user plane resource is the third user plane resource; alternatively, multiple user plane resources can also be selected from these multiple user plane resources, and the sum of the used rates of these multiple user plane resources is greater than or equal to the difference between the required rate and the remaining rate, and the selected multiple user plane resources are the third user plane resources.

[0160] Exemplarily, the user plane resources with optional user plane integrity protection in the first terminal device include: user plane resource 1, user plane resource 2, user plane resource 3, user plane resource 4, and user plane resource 5; among them, user plane resource 1, user plane resource 2, and user plane resource 3 have enabled user plane integrity protection, and user plane resource 4 and user plane resource 5 have not enabled user plane integrity protection; the third user plane resource can be selected from user plane resource 1, user plane resource 2, and user plane resource 3. For example, if the used rate of user plane resource 1 is greater than or equal to the difference between the required rate and the remaining rate, then user plane resource 1 is the third user plane resource. Of course, user plane resource 1, user plane resource 2, and user plane resource 3 can also be used as the third user plane resource; or user plane resource 1 and user plane resource 2 can also be used as the third user plane resource. For another example, if the used rates of user plane resource 1, user plane resource 2, and user plane resource 3 are all less than the difference between the required rate and the remaining rate, and the sum of the used rates of user plane resource 1 and user plane resource 2 is greater than or equal to the difference between the required rate and the remaining rate, then user plane resource 1 and user plane resource 2 are the third user plane resources; user plane resource 1, user plane resource 2, and user plane resource 3 can also be used as the third user plane resource. No further examples will be listed here.

[0161] It should be noted that if the sum of the used rates of all user plane resources with optional and enabled user plane integrity protection in the first terminal device is less than the difference between the required rate and the remaining rate, at this time, the request of the first terminal device to establish the first user plane resource is rejected.

[0162] In a possible implementation, if the remaining rate is less than the required rate, the request of the first terminal device to establish the first user plane resource may be rejected. For example, a first message is sent to the first terminal device, and the first message is used to reject the first terminal device's request to establish the first user plane resource. Alternatively, a rejection request is sent to other radio access network devices to trigger the other radio access network devices to send a second message to the first terminal device, and the second message is used to reject the first terminal device's request to establish the first user plane resource. That is, based on the remaining rate and the required rate, it can be determined whether to accept or reject the establishment of the first user plane resource. Further, after the first user plane resource is established, it is determined whether to enable the user plane integrity protection of the first user plane resource.

[0163] Case 2: The user plane security policy includes that the user plane integrity protection can be optionally enabled (prefered).

[0164] In this Case 2, if the remaining rate is greater than or equal to the required rate, a first indication message is sent to the first terminal device, and the first indication message is used to indicate enabling the user plane integrity protection of the first user plane resource. Correspondingly, the first terminal device receives the first indication message and enables the user plane integrity protection of the first user plane resource according to the first indication message.

[0165] In this Case 2, if the remaining rate is less than the required rate, a third indication message is sent to the first terminal, and the third indication is used to indicate not enabling the user plane integrity protection of the first user plane resource. Correspondingly, the first terminal device receives the third indication message and does not enable the user plane integrity protection of the first user plane resource.

[0166] Case 3: The user plane security policy includes that the user plane integrity protection is not enabled (not needed).

[0167] Based on this Case 3, it is determined not to enable the user plane integrity protection of the first user plane resource, and a third indication message is sent to the first terminal device, and the third indication is used to indicate not enabling the user plane integrity protection of the first user plane resource. Correspondingly, the first terminal device receives the third indication message and does not enable the user plane integrity protection of the first user plane resource.

[0168] It should be noted that the above remaining rate being greater than or equal to the required rate means that: the uplink remaining rate is greater than or equal to the uplink required rate and / or the downlink remaining rate is greater than or equal to the downlink required rate. The remaining rate being less than the required rate means that: the uplink remaining rate is less than the uplink required rate and / or the downlink remaining rate is less than the downlink required rate.

[0169] In the above step 301, the used rate of the first terminal device can be determined by any one or any combination of the following rate parameters (a), (b), (c), (d), (e), and (f). The rate parameters may include the real-time rate, the highest rate, the lowest rate, the average rate, etc. at which the first communication device sends data on the user plane resources.

[0170] In a possible implementation, the rate parameter (a) is the maximum bit rate of the PDU session aggregation of the second user plane resource, that is, the PDU session Aggregate Maximum Bit Rate. Further, the maximum bit rate of the PDU session aggregation includes the maximum bit rate of the PDU session aggregation for downlink / uplink, that is, the PDU session Aggregate Maximum Bit Rate includes the PDU session Aggregate Maximum Bit Rate Downlink / Uplink. This rate parameter (a) can be stored in the PDU session-related policy information of the PCF. The rate parameter (b) is the maximum bit rate of the APN aggregation of the second user plane resource, that is, the per APN Aggregate Maximum Bit Rate. The maximum bit rate of the APN aggregation includes the maximum bit rate of the APN aggregation for downlink / uplink, that is, the per UE Aggregate Maximum Bit Rate Downlink / Uplink. This rate parameter (b) can be stored in the APN-related policy information of the PCRF. The rate parameter (c) is the aggregate maximum bit rate of the first terminal device, that is, the UE Aggregate Maximum Bit Rate. Further, the aggregate maximum bit rate of the terminal device includes the aggregate maximum bit rate of the terminal device for downlink / uplink, that is, the UE Aggregate Maximum Bit Rate includes the UE Aggregate Maximum Bit Rate Downlink / Uplink. This rate parameter (c) can be stored in the access and mobility-related policy control information of the PCF, or can also be stored in the UE subscription information of the HSS / UDM. The rate parameter (d) is the maximum flow bit rate of the QoS flow of the GBR of the second user plane resource, that is, the Maximum Flow BitRate. Further, the maximum flow bit rate of the QoS flow of the GBR includes the maximum flow bit rate of the QoS flow of the GBR for downlink / uplink. That is, the Maximum Flow Bit Rate includes the Maximum Flow Bit Rate Downlink / Uplink. This rate parameter (d) can be stored in the policy control and charging (PCC) rules of the PCF or the PCRF. The rate parameter (e) is the guaranteed flow bit rate of the QoS flow of the GBR of the second user plane resource, that is, the Guaranteed Flow BitRate.Furthermore, the guaranteed flow bit rate of the QoS flow of GBR includes the downlink / uplink guaranteed flow bit rate of the QoS flow of GBR, that is, Guaranteed Flow Bit Rate includes Guaranteed Flow Bit Rate Downlink / Uplink. This rate parameter (e) can be stored in the PCC of the PCF or PCRF. The rate parameter (f) is the real-time rate of the second user plane resource. Furthermore, the real-time rate also includes the uplink real-time rate and the downlink real-time rate.

[0171] Exemplarily, the second user plane resources in the terminal device include DRB11, DRB12, and DRB13. The QoS flow of DRB11 is non-GBR, and the QoS flows of DRB12 and DRB13 are both GBR. Then the rate parameter (a) is the maximum bit rate of the PDU session aggregation of the PDU session corresponding to DRB11. The rate parameter (b) is the maximum bit rate of the APN session aggregation of the APN corresponding to DRB11. The rate parameter (c) is the maximum bit rate of the aggregation of the terminal device. The rate parameter (d) is the maximum flow bit rate of the QoS flows included in DRB12 and DRB13. The rate parameter (e) is the guaranteed flow bit rate of the QoS flows included in DRB12 and DRB13.

[0172] As follows, four possible implementation manners for determining the used rate are exemplarily shown.

[0173] Implementation manner 1, the maximum value of the used rate.

[0174] In a possible implementation manner, the sum of the maximum bit rate of the aggregation of all PDU sessions and the maximum flow bit rate of all QoS flows of GBR is determined as the used rate; or the sum of the maximum bit rate of the aggregation of the terminal device and the maximum flow bit rate of all QoS flows of GBR is determined as the used rate.

[0175] Exemplarily, the second user plane resources can all be non-GBR, or part of them can be non-GBR. The sum of the maximum bit rate of the PDU session aggregation of all non-GBR QoS flows of the first terminal device and the maximum flow bit rate of all GBR QoS flows of the first terminal device can be determined as the used rate; or the sum of the maximum bit rate of the aggregation of all UEs of the first terminal device and the maximum flow bit rate of all GBR QoS flows of the first terminal device can be determined as the used rate.

[0176] Further, the used rate includes the uplink used rate and the downlink used rate. The sum of the downlink maximum bit rate obtained by aggregating the PDU sessions of all non-GBR QoS flows of the first terminal device or the aggregated downlink maximum bit rate of the UE of the first terminal device, and the downlink maximum bit rates of all GBR QoS flows of the first terminal device is determined as the downlink used rate of the first terminal device; the sum of the uplink maximum bit rate obtained by aggregating the PDU sessions of all non-GBR QoS flows of the first terminal device or the aggregated uplink maximum bit rate of the UE of the first terminal device, and the uplink maximum bit rates of all GBR QoS flows of the first terminal device is determined as the uplink used rate of the first terminal device.

[0177] In another possible implementation, the sum of the maximum bit rates obtained by aggregating the PDU sessions of all non-GBR QoS flows with user plane integrity protection enabled on the first terminal device and the maximum flow bit rates of all GBR QoS flows with user plane integrity protection enabled on the first terminal device is determined as the used rate.

[0178] Further, the used rate includes the uplink used rate and the downlink used rate. The sum of the downlink maximum bit rates obtained by aggregating the PDU sessions of all non-GBR QoS flows with user plane integrity protection enabled on the first terminal device and the downlink maximum bit rates of all GBR QoS flows with user plane integrity protection enabled on the first terminal device is determined as the downlink used rate of the first terminal device; the sum of the uplink maximum bit rates obtained by aggregating the PDU sessions of all non-GBR QoS flows with user plane integrity protection enabled on the first terminal device and the uplink maximum bit rates of all GBR QoS flows with user plane integrity protection enabled on the first terminal device is determined as the uplink used rate of the first terminal device.

[0179] Through the above implementation method 1, the used rate is obtained based on the assumption that the second user plane resources all transmit data at the maximum bit rate. In this way, the remaining rate represents the transmission capacity that the terminal still has under extreme conditions. Therefore, the communication services of the first terminal device can be guaranteed as much as possible. That is to say, this implementation method 1 determines whether to enable the user plane integrity protection of the first user plane resources from the perspective of the service availability of the first terminal device.

[0180] Implementation method 2, the minimum value of the used rate.

[0181] In a possible implementation, the sum of the guaranteed bit rates of all GBR QoS flows of the first terminal device is determined as the used rate.

[0182] Further, the used rate includes an uplink used rate and a downlink used rate; the sum of the guaranteed downlink bit rates of all QoS flows of all GBRs of the first terminal device is determined as the downlink used rate of the first terminal device; the sum of the guaranteed uplink bit rates of all QoS flows of all GBRs of the first terminal device is determined as the uplink used rate of the first terminal device.

[0183] In another possible implementation, the sum of the guaranteed bit rates of all QoS flows of all GBRs with user plane integrity protection enabled for the first terminal device is determined as the used rate.

[0184] Further, the used rate includes an uplink used rate and a downlink used rate; the sum of the guaranteed downlink bit rates of all QoS flows of all GBRs with user plane integrity protection enabled for the first terminal device is determined as the downlink used rate of the first terminal device; the sum of the guaranteed uplink bit rates of all QoS flows of all GBRs with user plane integrity protection enabled for the first terminal device is determined as the uplink used rate of the first terminal device.

[0185] Through the above implementation method 2, the used rate is obtained based on the assumption that the second user plane resources all transmit data at the minimum bit rate. In this way, the security of data transmission of the first terminal device can be guaranteed as much as possible. That is to say, this implementation method 2 determines whether to enable the user plane integrity protection of the first user plane resources from the perspective of the security of data transmission of the first terminal device.

[0186] Implementation method 3, the used rate is between the maximum value determined by the above implementation method 1 and the minimum value determined by the above implementation method 2.

[0187] In a possible implementation, the sum of the maximum bit rate aggregated by all PDU sessions and the sum of the guaranteed bit rates of all QoS flows of all GBRs is determined as the used rate.

[0188] Exemplarily, the adjusted value of the maximum bit rate aggregated by the PDU sessions of all non-GBR QoS flows of the first terminal device or the adjusted value of the maximum bit rate aggregated by the UE of the first terminal device, and the sum of the guaranteed bit rates of all QoS flows of all GBRs are determined as the used rate.

[0189] The adjusted value can be obtained by reducing the maximum bit rate aggregated by the PDU session or the maximum bit rate aggregated by the UE. For example, the adjusted value can be obtained according to the transmission statistical characteristics of non-GBR QoS flows.

[0190] Further, the used rate includes the uplink used rate and the downlink used rate; the sum of the downlink maximum bit rate obtained by aggregating the PDU sessions of all non-GBR QoS flows of the first terminal device and the guaranteed downlink bit rate of all GBR QoS flows is determined as the downlink used rate; the sum of the uplink maximum bit rate obtained by aggregating the PDU sessions of all non-GBR QoS flows of the first terminal device and the guaranteed uplink bit rate of all GBR QoS flows is determined as the uplink used rate.

[0191] In another possible implementation, the sum of the maximum bit rate obtained by aggregating the PDU sessions of all non-GBR QoS flows with user plane integrity protection enabled on the first terminal device or the adjusted value of the aggregated maximum bit rate of the UE of the first terminal device, and the guaranteed bit rate of all GBR QoS flows with user plane integrity protection enabled, is determined as the used rate.

[0192] Further, the used rate includes the uplink used rate and the downlink used rate; the sum of the downlink maximum bit rate obtained by aggregating the PDU sessions of all non-GBR QoS flows with user plane integrity protection enabled on the first terminal device and the guaranteed downlink bit rate of all GBR QoS flows with user plane integrity protection enabled is determined as the downlink used rate; the sum of the uplink maximum bit rate obtained by aggregating the PDU sessions of all non-GBR QoS flows with user plane integrity protection enabled on the first terminal device and the guaranteed uplink bit rate of all GBR QoS flows with user plane integrity protection enabled is determined as the uplink used rate.

[0193] Through the above implementation method 3, the used rate is obtained based on the assumption of transmitting data at a moderate rate adjusted according to the second user plane resource usage. In this way, the remaining rate represents the comprehensive rate of the terminal, which can both ensure the availability of the communication services of the first terminal device as much as possible and ensure the security of the data transmitted by the first terminal device as much as possible.

[0194] Implementation method 4: Real-time monitor the real-time rate of the second user plane resource.

[0195] In a possible implementation, the sum of the real-time rates of all monitored second user plane resources is determined as the used rate of the first terminal device.

[0196] Further, the used rate includes the uplink used rate and the downlink used rate; the sum of the uplink real-time rates of the monitored second user plane resources is determined as the uplink used rate, and the sum of the downlink real-time rates of the monitored second user plane resources is determined as the downlink used rate.

[0197] Exemplarily, the sum of the real-time rates of all the second user plane resources for which the user plane integrity protection has been enabled and monitored is determined as the used rate of the first terminal device.

[0198] Furthermore, the used rate includes an uplink used rate and a downlink used rate; the sum of the uplink real-time rates of the second user plane resources for which the user plane integrity protection has been enabled and monitored is determined as the uplink used rate, and the sum of the downlink real-time rates of the second user plane resources for which the user plane integrity protection has been enabled and monitored is determined as the downlink used rate.

[0199] Through the above implementation method 4, the used rate is obtained based on the assumption of transmitting data at the real-time rate of the second user plane resources. In this way, the remaining rate represents the most accurate rate of the first terminal device, thus ensuring that the basis for decision-making is the most accurate data, which can both ensure the availability of the communication service of the first terminal device as much as possible and ensure the security of the data transmitted by the first terminal device as much as possible.

[0200] As follows, in combination with possible application scenarios, the communication method provided in this application will be described.

[0201] Scenario 1 can be applied to the PDU session establishment process, the PDU session modification process, or the EPS bearer establishment process.

[0202] Please refer to Figure 4 , a communication method applied to a radio access network device provided in this application. In this method, the radio access network device is the first communication device in the above Figure 3 . The session management network element can be the SMF in the above Figure 1a or the MME in the above Figure 1b ; the data management network element can be the UDM in the above Figure 1a or the HSS in the above Figure 1b ; the policy control network element can be the PCF in the above Figure 1a or the PCRF in the above Figure 1b . This method includes the following steps:

[0203] Step 401, the first terminal device sends a first request message to the session management network element. Correspondingly, the session management network element receives the first request message from the first terminal device.

[0204] Here, the first request message is used to request PDU session establishment, PDU session modification, or request for bearer resource change. The first request message includes the maximum integrity protection rate of the first terminal device. That is, the session management network element can obtain the maximum integrity protection rate of the first terminal device from the first terminal device. Further, there can be multiple values for the maximum integrity protection rate of the first terminal device reported by the first terminal device to the session management network element, such as 1 Gbps (i.e., 1000 Mbps) and 2 Gbps, etc. The specific values can be set according to the performance of the first terminal device. Exemplarily, if the performance of the first terminal device is high, the value can be larger; if the performance of the first terminal device is low, the value can be smaller. Compared with the prior art where there are only two values, 64 Kbps and full data rate, for the maximum integrity protection rate of the terminal device, in this application, the maximum integrity protection rate of the first terminal device reported by the first terminal device can take more values and can reflect the performance of the first terminal device.

[0205] It should be noted that during the PDU session establishment, PDU session modification, or bearer resource change process, the first terminal device will ultimately establish the first user plane resource with the radio access network device, and the first user plane resource can be one or more DRBs.

[0206] Step 402, the session management network element obtains the user plane security policy of the first user plane resource according to the first request message.

[0207] Here, the session management network element can obtain the identifier of the first terminal device, such as the subscriber permanent identifier (SUPI), from the context of the terminal device according to the first request message.

[0208] In a possible implementation manner, the session management network element sends a subscription acquisition request message to the data management network element. Correspondingly, the data management network element receives the subscription acquisition request message from the session management network element. Here, the subscription acquisition request message is used to request to obtain the user plane security policy of the first terminal device. The subscription acquisition request message can include the identifier of the first terminal device, the data network name (DNN), and / or the identifier of the network slice (single network slice selection assistance information, NSSAI). The data management network element can obtain the subscription information of the first terminal device according to the SUPI, and then obtain the user plane security policy of the first terminal device according to the DNN and / or NSSAI.

[0209] In another possible implementation, the session management network element may also obtain the user plane security policy of the first terminal device according to the local configuration. For example, when the DNN and / or NSSAI are included in the first request message, the session management network element may determine the user plane security policy of the first terminal device from the local configuration according to the DNN and / or NSSAI.

[0210] It should be noted that the user plane security policy of the first terminal device obtained by the session management function will be used as the basis for the radio access network device to determine whether to enable integrity protection for the first user plane resource in the future. Therefore, it can also be called the user plane security policy of the first user plane resource.

[0211] Step 403, the session management network element obtains the required rate for establishing the first user plane resource according to the first request message.

[0212] In a possible implementation, the session management network element sends a policy control creation message to the policy control network element. The policy control creation message is used to request the required rate for establishing the first user plane resource. When the policy control creation message includes the SUPI, DNN, and / or NSSAI, the policy control network element may obtain the policy information of the first terminal device according to the SUPI, and then obtain the required rate for establishing the first user plane resource from the policy information according to the DNN and / or NSSAI. At this time, the required rate may be the maximum bit rate of PDU session aggregation or the maximum bit rate of APN session aggregation.

[0213] In another possible implementation, when the policy control creation message includes the SUPI, DNN, and / or NSSAI and a flow template, the policy control network element may obtain the policy information of the first terminal device according to the SUPI, and then obtain the required rate for establishing the first user plane resource from the policy information according to the DNN and / or NSSAI and the flow template. The flow template is used to indicate the QoS flow. At this time, the required rate may be the maximum flow bit rate or the guaranteed flow bit rate.

[0214] It should be noted that the required rate of the first terminal device obtained by the session management function will be used as a reference for the radio access network device to establish the first user plane resource for the first terminal device in the future. Therefore, it can also be called the required rate of the first user plane resource.

[0215] It should also be noted that there is no sequence between step 402 and step 403. Step 402 may be executed first and then step 403; step 403 may also be executed first and then step 403; step 402 and step 403 may also be executed simultaneously; this application does not make any restrictions on this.

[0216] Step 404, the session management network element sends a first response message to the radio access network device. Correspondingly, the radio access network device receives the first response message from the session management network element.

[0217] Here, the first response message includes the user plane security policy of the first user plane resource, the maximum integrity protection rate of the first terminal device, and the required rate for establishing the first user plane resource.

[0218] Step 405, the radio access network device obtains the used rate of the first terminal device from the context of the terminal device saved locally.

[0219] Among them, the required rate, the maximum integrity protection rate, and the used rate can refer to the relevant introductions in step 301 above respectively, and will not be repeated here.

[0220] Step 406, the radio access network device determines the remaining rate of the first terminal device according to the maximum integrity protection rate of the first terminal device and the used rate of the first terminal device.

[0221] This step 406 can refer to the way of determining the remaining rate in step 301 above, and will not be repeated here.

[0222] Step 407, the radio access network device determines whether to enable the user plane integrity protection of the first user plane resource according to the required rate for establishing the first user plane resource, the remaining rate of the first terminal device, and the user plane security policy of the first user plane resource.

[0223] For example, the maximum integrity protection rate of the first terminal device is 1000 Mbps, and the rate used by the second user plane resource already established on the first terminal device is 400 Mbps, that is, the used rate of the first terminal device is 400 Mbps. Then, if the required rate for establishing the first user plane resource is less than or equal to 600 Mbps, it means that the first terminal device has the ability to enable the user plane integrity protection of the first user plane resource. Further, if the user plane security policy of the first user plane resource is that the user plane integrity protection is enabled, it can be determined to enable the user plane integrity protection of the first user plane resource. If the user plane security policy of the first user plane resource is that the user plane integrity protection is optionally enabled, it can also be determined to enable the user plane integrity protection of the first user plane resource.

[0224] This step 407 can refer to the introduction in step 302 above, and will not be repeated here.

[0225] Step 408, the radio access network device sends an RRC reconfiguration message to the first terminal device. Correspondingly, the first terminal device receives the RRC reconfiguration message from the radio access network device.

[0226] In a possible implementation, the RRC reconfiguration message includes security indication information. The security indication information is used to indicate whether to enable or disable the user plane integrity protection for the first user plane resource. Further, the security indication information may be the above-mentioned first indication information, or the second indication information, or the third indication information. If the security indication information is the above-mentioned third indication information, the security indication information is further used to indicate disabling the user plane integrity protection for the third user plane resource. For the descriptions of the first indication information, or the second indication information, or the third indication information, reference may be made to the introduction in step 302 above, which will not be repeated here.

[0227] Step 409, the first terminal device sends an RRC reconfiguration complete message to the radio access network device.

[0228] The RRC reconfiguration complete message is used to indicate whether the first terminal device has enabled or disabled the user plane integrity protection for the first user plane resource.

[0229] Through the above steps 401 to 409, the radio access network device can accurately determine whether to enable the user plane integrity protection for the first user plane resource based on the maximum integrity protection rate, the used rate, the required rate, and the user plane security policy, so as to ensure the timeliness and security of data transmission of the first terminal device as much as possible. That is, the user plane integrity protection of the terminal device and the network side can be enabled on demand according to the capabilities of the terminal device, which helps to avoid the problem that when the maximum integrity protection rate of the terminal device is 64 Kbps, the user plane integrity protection of the terminal device and the network side is always disabled, resulting in the security of the transmitted data not being guaranteed, or when the maximum integrity protection rate of the terminal device is the full data rate, the user plane integrity protection of the terminal device and the network side is always enabled, resulting in abnormal performance of the terminal device.

[0230] Scenario 2, applied to the handover process of the terminal device between different radio access network devices.

[0231] Refer to Figure 5 , a communication method applied to the handover process of the terminal device between radio access network devices provided in this application. In this method, the target radio access network device is the first communication device mentioned above Figure 3 , and the source radio access network device is the radio access network device to which the first terminal device is currently connected. The method includes the following steps:

[0232] Step 500, the first terminal device sends a measurement report to the source radio access network device. Correspondingly, the source radio access network device receives the measurement report from the first terminal device.

[0233] In a possible implementation, the source radio access network device may determine whether to perform a handover based on the measurement report reported by the first terminal device. If a handover is to be performed, the source radio access network device performs the following step 501, that is, sending a handover request message to the target radio access network device. For example, if the measurement report shows that the signal strength between the first terminal device and the target radio access network device is good, and the signal strength between the first terminal device and the source radio access network device is poor, the source radio access network device sends a handover request message to the target radio access network device.

[0234] Step 501, the source radio access network device sends a handover request message to the target radio access network device. Correspondingly, the target radio access network device receives the handover request message from the source radio access network device.

[0235] The handover request message includes the required rate of the first user plane resource, the user plane security policy of the first user plane resource, and the maximum integrity protection rate of the first terminal device. Among them, the required rate of the first user plane resource, the user plane security policy of the first user plane resource, and the maximum integrity protection rate of the first terminal device are obtained by the source radio access network device from the context of the first terminal device.

[0236] In particular, since the handover process migrates all the context information of the first terminal device from the source radio access network device to the target radio access network device, for the target radio access network device, the required rate of the first terminal device includes the required rate of the user plane resources already established between the source radio access network device and the first terminal device. Or it can be understood that for the target radio access network device, the required rate of the first user plane resource includes the required rate of the user plane resources already established in the source radio access network device.

[0237] For example, if the source radio access network device has already established DRB11, DRB12, and DRB13 with the first terminal device, the required rate of the first user plane resource may include the required rate for establishing DRB11, the required rate for establishing DRB12, and the required rate for establishing DRB13.

[0238] In particular, the user plane security policy may be different or the same for different user plane resources. The user plane security policy includes the user plane security policies of the user plane resources already established between the source radio access network device and the first terminal device.

[0239] Step 502, the target radio access network device determines the remaining rate of the first terminal device according to the maximum integrity protection rate of the first terminal device and the used rate of the first terminal device.

[0240] Specifically, since the target radio access network device has not yet established a user plane resource with the first terminal device when receiving the handover request message, initially, the used rate is 0. At this time, the remaining rate is the maximum integrity protection rate. After the target radio access network device determines to continuously enable the integrity protection of the user plane resource, the used rate gradually increases and the remaining rate continuously decreases.

[0241] This step 502 can refer to the method of determining the remaining rate in the above step 301, and will not be repeated here.

[0242] Step 503, the target radio access network device determines whether to enable the user plane integrity protection of the first user plane resource according to the required rate of the first user plane resource, the remaining rate of the first terminal device, and the user plane security policy of the first user plane resource.

[0243] Among them, the first user plane resource includes the user plane resource already established between the source radio access network device and the first terminal device.

[0244] Optionally, the target radio access network device first determines whether to enable the user plane integrity protection of the user plane resource whose user plane security policy is enabled (required) for user plane integrity protection, and then determines whether to enable the user plane integrity protection of the user plane resource whose user plane security policy is optionally enabled (preferred) for user plane integrity protection.

[0245] Optionally, after the target radio access network device determines whether to enable the user plane integrity protection of the user plane resource, repeat step 503 until the determination of whether to enable the user plane integrity protection of all user plane resources included in the first user plane resource is completed.

[0246] For example, if the first user plane resource includes DRB11, DRB12, DRB13, the user plane security policy of DRB11 indicates that the user plane integrity protection is enabled, the user plane security policy of DRB12 indicates that the user plane integrity protection is optionally enabled, and the user plane security policy of DRB13 indicates that the user plane integrity protection is not enabled, then the target radio access network device first determines whether it can enable the user plane integrity protection of DRB11 according to the required rate of DRB11 and the remaining rate (which is the maximum integrity protection rate at this time). The target radio access network device then determines whether it can enable the user plane integrity protection of DRB12 according to the required rate of DRB12 and the remaining rate. The target radio access network device does not enable the user plane integrity protection of DRB13.

[0247] This step 503 can refer to the introduction in the above step 302, and will not be repeated here.

[0248] Step 504: The target radio access network device sends a handover response message to the source radio access network device.

[0249] This handover response message includes security indication information. For the introduction of the security indication information, please refer to the description in step 408 above, and it will not be elaborated here.

[0250] Step 505: The source radio access network device sends an RRC reconfiguration message to the first terminal device. Correspondingly, the first terminal device receives the RRC reconfiguration message from the source radio access network device.

[0251] For the description of this step 505, please refer to the introduction in step 408 above, and it will not be repeated here.

[0252] Step 506: The first terminal device sends an RRC reconfiguration complete message to the target radio access network device.

[0253] For the RRC reconfiguration complete message in this step 506, please refer to the introduction in step 409 above, and it will not be repeated here.

[0254] Scenario 3: Applied to the RRC connection restoration process.

[0255] Please refer to Figure 6 , a communication method applied to the RRC connection restoration process provided by this application. In this method, the target radio access network device is the first communication device in the above Figure 3 . This method includes the following steps:

[0256] Step 601: The first terminal device sends an RRC restoration request message to the target radio access network device. Correspondingly, the target access network device receives the RRC restoration request message from the first terminal device.

[0257] In a possible implementation, the RRC restoration request message is used to request the restoration of the RRC connection, and the RRC restoration request message may include the identifier of the first terminal device.

[0258] Step 602: The target radio access network device sends a UE context request message to the source radio access network device according to the RRC restoration request message. Correspondingly, the source access network device receives the UE context request message of the terminal device from the target radio access network device.

[0259] In a possible implementation, the UE context request message is used to request the context of the first terminal device, and the UE context request message includes the identifier of the first terminal device.

[0260] Step 603: The source radio access network device determines the context of the first terminal device according to the context request message of the terminal device.

[0261] Here, the source radio access network device may determine the context of the terminal device according to the identifier of the first terminal device in the context request message of the terminal device. The context of the terminal device includes the required rate of the first terminal device, the user plane security policy, and the maximum integrity protection rate.

[0262] Step 604: The source radio access network device sends a UE Context Response message of the terminal device to the target radio access network device. Correspondingly, the target radio access network device receives the UE Context Response message of the terminal device from the source radio access network device.

[0263] The UE Context Response message of the terminal device includes the required rate of the first terminal device, the user plane security policy, and the maximum integrity protection rate.

[0264] For the introduction of this Step 604, please refer to the introduction of Step 501.

[0265] Step 605: The target radio access network device determines the remaining rate of the first terminal device according to the maximum integrity protection rate and the used rate of the first terminal device.

[0266] For the introduction of this Step 605, please refer to the introduction of the above Step 502, and details will not be repeated here.

[0267] Step 606: The target radio access network device determines whether to enable the user plane integrity protection of the first user plane resource according to the required rate and the user plane security policy in the UE Context Response message of the terminal device, and the determined remaining rate.

[0268] For the introduction of this Step 606, please refer to the introduction of the above Step 504, and details will not be repeated here.

[0269] Step 607: The target radio access network device sends an RRC Reconfiguration message to the first terminal device. Correspondingly, the first terminal device receives the RRC Reconfiguration message from the target radio access network device.

[0270] For the introduction of this Step 607, please refer to the introduction of the above Step 408, and details will not be repeated here.

[0271] Step 608: The first terminal device sends an RRC Reconfiguration Complete message to the target radio access network device.

[0272] For the introduction of this Step 608, please refer to the introduction of the above Step 409, and details will not be repeated here.

[0273] Scenario 4, applied to the bearer addition process or bearer modification process in a dual-connection system.

[0274] As Figure 7 shown, a communication method for a secondary node applied to dual-connection provided by this application. In this method, the secondary node is the first communication device in the above Figure 3 . The method includes the following steps:

[0275] Step 701, the master node obtains the required rate, maximum integrity protection rate, used rate, and user plane security policy of the first terminal device.

[0276] In a possible implementation, the master node determines to load the established first user plane resource to the secondary node, that is, the master node determines to unload the first user plane resource and requests the secondary node to establish the first user plane resource for the first terminal. The master node can obtain the required rate, maximum integrity protection rate, used rate, and user plane security policy of the first terminal device from the context of the terminal device saved locally.

[0277] At this time, the used rate is used to indicate the rate not used by the first user plane resource in the second user plane resource established between the first terminal device and the master node. Optionally, the second user plane resource includes all the established user plane resources of the first terminal device except the first user plane resource. Optionally, if the first user plane resource has enabled user plane integrity protection, the second user plane resource includes the user plane resources with user plane integrity protection among the established user plane resources of the first terminal device.

[0278] Exemplarily, taking the user plane resource as DRB, the user plane resources established between the first terminal device and the master node include DRB11, DRB12, DRB13, and DRB14. Among them, DRB11, DRB12, and DRB13 have all enabled user plane integrity protection, and DRB14 has not enabled user plane integrity protection. The master node is going to load DRB11 to the secondary node, then the second user plane resource includes DRB12 and DRB13.

[0279] In another possible implementation, when the master node determines to request the secondary node to establish the first user plane resource for the first terminal, that is, when the master node does not unload the existing user plane resources, the master node can obtain the required rate, maximum integrity protection rate, used rate, and user plane security policy of the first terminal device from the context obtained from the terminal device saved locally. At this time, the way to obtain the used rate can refer to the way to determine the used rate in step 301 above Figure 3 , which will not be repeated here.

[0280] Step 702: The master node sends an SN Addition Request message or an SN Modification Request message of the first terminal device to the secondary node. Correspondingly, the secondary node receives the SN Addition Request message or the SN Modification Request message from the master node.

[0281] Here, the required rate, the maximum integrity protection rate, the used rate, and the user plane security policy of the first terminal device are carried in the SN Addition Request message or the SN Modification Request message.

[0282] Step 703: The secondary node determines the remaining rate according to the maximum integrity protection rate and the used rate.

[0283] For this step 703, reference can be made to the method of determining the remaining rate in the above step 301, which will not be repeated here.

[0284] Step 704: The secondary node determines whether to enable the user plane integrity protection of the first user plane resource according to the required rate, the remaining rate, and the user plane security policy.

[0285] For this step 704, reference can be made to the introduction in the above step 302, which will not be repeated here.

[0286] Step 705: The secondary node sends an SN Addition Request ACK message or an SN Modification Request ACK message to the master node.

[0287] Here, the security indication information is included in the SN Addition Request ACK message or the SN Modification Request ACK message. The security indication information is used to indicate whether to enable the user plane integrity protection of the first user plane resource for the first terminal device.

[0288] Optionally, the rate used to enable the user plane integrity protection of the first user plane resource is included in the SN Addition Request ACK message or the SN Modification Request ACK message. The used rate is used to indicate the usage rate after enabling the user plane integrity protection of the first user plane resource. The secondary node can send it to the master node after determining to enable the user plane integrity protection of the first user plane resource.

[0289] Step 706: The master node obtains and records the rate used to enable the user plane integrity protection of the first user plane resource from the secondary node.

[0290] In a possible implementation, the master node may record the rate used for user plane integrity protection of the first user plane resource in the context of the first terminal device. When a new user plane resource is created next time, the rate used for enabling user plane integrity protection of the first user plane resource is used as the second user plane resource, which becomes the input for obtaining the used rate.

[0291] Step 707: The master node sends an RRC reconfiguration message to the first terminal device. Correspondingly, the first terminal device receives the RRC reconfiguration message from the master node.

[0292] This step 707 is an optional step. For details, refer to the introduction of step 408 above, and will not be repeated here.

[0293] Step 708: The first terminal device sends an RRC reconfiguration complete message to the master node.

[0294] This step 708 can be referred to the introduction of step 409 above, and will not be repeated here.

[0295] Through the above steps 701 to 708, the master node sends the determined maximum integrity protection rate, used rate, required rate, and user plane security policy of the first terminal device to the secondary node. The secondary node can accurately determine whether to enable user plane integrity protection for the first user plane resource based on the maximum integrity protection rate, used rate, required rate, and user plane security policy, so as to ensure the timeliness and security of the transmission data of the terminal device as much as possible.

[0296] Scenario Five: Applied to the bearer addition process or bearer modification process in a dual-connection system.

[0297] Refer to Figure 8 , a communication method for a secondary node applied to dual connection provided by this application. In the method, the secondary node is the first communication device mentioned above Figure 3 . The method includes the following steps:

[0298] Step 801: The master node obtains the used rate, required rate, maximum integrity protection rate, and user plane security policy of the first terminal device.

[0299] This step 801 can be referred to the description of step 701 above, and will not be repeated here.

[0300] Step 802: The master node determines the remaining rate according to the maximum integrity protection rate and the used rate.

[0301] This step 802 can be referred to the way of determining the remaining rate in step 301 above, and will not be repeated here.

[0302] Step 803: The master node sends an SN Addition Request message or an SN Modification Request message to the secondary node. Correspondingly, the secondary node receives the SN Addition Request message or the SN Modification Request message from the master node.

[0303] Here, the required rate, remaining rate, and user plane security policy of the first terminal device are carried in the SN Addition Request message or the SN Modification Request message.

[0304] Step 804: The secondary node determines whether to enable the user plane integrity protection of the first user plane resource according to the required rate, remaining rate, and user plane security policy.

[0305] For the introduction of this step 804, please refer to the above step 302 and will not be repeated here.

[0306] Step 805: The secondary node sends an SN Addition Request ACK message or an SN Modification Request ACK message to the master node.

[0307] Here, the security indication information is included in the SN Addition Request ACK message or the SN Modification Request ACK message. The security indication information is used to indicate whether to enable the user plane integrity protection of the first user plane resource for the first terminal device.

[0308] Optionally, the rate used to enable the user plane integrity protection of the first user plane resource is included in the SN Addition Request ACK message or the SN Modification Request ACK message. The used rate is used to indicate the usage rate after enabling the user plane integrity protection of the first user plane resource. The secondary node can send it to the master node after determining to enable the user plane integrity protection of the first user plane resource.

[0309] Step 806: The master node obtains and records the rate used to enable the user plane integrity protection of the first user plane resource from the secondary node.

[0310] For the introduction of this step 806, please refer to the above step 706 and will not be repeated here.

[0311] Step 807: The master node sends an RRC reconfiguration message to the first terminal device. Correspondingly, the first terminal device receives the RRC reconfiguration message from the master node.

[0312] This step 807 is an optional step. For details, please refer to the introduction of step 408 above and will not be repeated here.

[0313] Step 808: The first terminal device sends an RRC reconfiguration complete message to the master node.

[0314] Through the above steps 801 to 808, the master node sends the remaining rate, required rate, and user plane security policy of the first terminal device to the secondary node. Based on the remaining rate, required rate, and user plane security policy of the first terminal device, the secondary node can accurately determine whether to enable the user plane integrity protection of the first user plane resource, so as to ensure the timeliness and security of the transmission data of the terminal device as much as possible.

[0315] The above Figure 8 and the above Figure 7 The difference lies in that Figure 7 in, the remaining rate is determined by the secondary node; Figure 8 in, the remaining rate is determined by the master node.

[0316] Scenario six: applied to the bearer addition process or bearer modification process in a dual-connectivity system.

[0317] Refer to Figure 9 , a communication method for a master node applied to dual connectivity provided by this application. In this method, the master node is the first communication device in the above Figure 3 . This method includes the following steps:

[0318] Step 901: The master node obtains the required rate, maximum integrity protection rate, used rate, and user plane security policy of the first terminal device.

[0319] In a possible implementation, when the master node determines to establish the first user plane resource for the first terminal device, the master node may trigger the acquisition of the required rate, maximum integrity protection rate, used rate, and user plane security policy of the first terminal device.

[0320] Step 902: The master node determines the remaining rate according to the maximum integrity protection rate and the used rate.

[0321] This step 902 can refer to the method for determining the remaining rate in step 301 above and will not be repeated here.

[0322] Step 903: The master node determines whether to enable the user plane integrity protection of the first user plane resource according to the required rate, remaining rate, and user plane security policy.

[0323] This step 903 can refer to the introduction of step 302 above and will not be repeated here.

[0324] Step 904: The master node sends the fourth indication information to the secondary node.

[0325] Here, the fourth indication information is used to instruct the secondary node to determine whether to enable user plane integrity protection. It can also be understood that the fourth indication information is used to instruct whether the master node enables user plane integrity protection for the first user plane resource, that is, the fourth indication information is used to notify the secondary node whether the master node enables user plane integrity protection for the first user plane resource. The fourth indication information can also be referred to as user plane security decision information.

[0326] This step 904 is an optional step. In a possible implementation, the master node sends an SN Addition Request message or an SN Modification Request message to the secondary node, and the fourth indication information is carried in the SN Addition Request message or the SN Modification Request message.

[0327] Step 905: The master node sends an RRC reconfiguration message to the first terminal device. Correspondingly, the first terminal device receives the RRC reconfiguration message from the master node.

[0328] For the introduction of this step 905, reference can be made to the above step 408, and details will not be repeated here.

[0329] Step 906: The first terminal device sends an RRC reconfiguration complete message to the master node.

[0330] For the introduction of this step 906, reference can be made to the above step 409, and details will not be repeated here.

[0331] It can be seen from the above steps 901 to 906 that after the master node in the dual connection accurately determines whether to enable user plane integrity protection for the first user plane resource, it notifies the secondary node of the judgment result, so that the secondary node can also accurately determine whether to enable user plane integrity protection for the first user plane resource, so as to ensure the timeliness and security of the transmission data of the terminal device as much as possible.

[0332] Scenario 7: Applied to the PDU session establishment process, the PDU session modification process, or the EPS bearer establishment process.

[0333] Please refer to Figure 10 , another communication method for a radio access network device provided by this application. In this method, the radio access network device is the first communication device in the above Figure 3 . This method may include the following steps:

[0334] Step 1001, the first terminal device obtains the used rate and the maximum integrity protection rate of the first terminal device.

[0335] In a possible implementation, when the first terminal device determines to request PDU session establishment, PDU session modification, or EPS bearer establishment, it may trigger the acquisition of the used rate and the maximum integrity protection rate of the first terminal device.

[0336] In a possible implementation, the first terminal device may determine the used rate of the first terminal device according to the second user plane resources in the first terminal device; and may determine the maximum integrity protection rate of the first terminal device according to the performance of the first terminal device. Exemplarily, if the performance of the first terminal device is high, the maximum integrity protection rate can take a larger value; if the performance of the first terminal device is low, the value of the maximum integrity protection rate can be smaller.

[0337] Step 1002, the first terminal device determines the remaining rate according to the maximum integrity protection rate and the used rate.

[0338] For this step 1002, reference can be made to the method of determining the remaining rate in step 301 above, and details will not be repeated here.

[0339] Step 1003, the first terminal device sends a second request message to the session management network element.

[0340] Here, the second request message is used to request PDU session establishment, PDU session modification, or request bearer resource change. The second request message includes the remaining rate of the first terminal device.

[0341] Step 1004, the session management network element sends a second response message to the radio access network device. Correspondingly, the radio access network device receives the second response message from the session management network element.

[0342] The second response message includes the remaining rate of the first terminal device.

[0343] Step 1005, the radio access network device obtains the required rate for establishing the first user plane resource and the user plane security policy.

[0344] In a possible implementation, the radio access network device may obtain the user plane security policy and the required rate of the first user plane resource from the context information of the terminal device.

[0345] Step 1006, the radio access network device determines whether to enable the user plane integrity protection of the first user plane resource according to the required rate for establishing the first user plane resource, the remaining rate of the first terminal device, and the user plane security policy of the first user plane resource.

[0346] Step 1006 can be referred to the introduction of step 302 above, and will not be repeated here.

[0347] Step 1007, the radio access network device sends an RRC reconfiguration message to the first terminal device. Correspondingly, the first terminal device receives the RRC reconfiguration message from the radio access network device.

[0348] This step 1007 is an optional step, which can be referred to the introduction of step 408 above, and will not be repeated here.

[0349] Step 1008, the first terminal device sends an RRC reconfiguration complete message to the radio access network device.

[0350] Through the above steps 1001 to 1008, the first terminal device determines the remaining rate according to the maximum integrity protection rate and the used rate, and sends the remaining rate to the radio access network device. The radio access network device accurately judges whether the first user plane resource needs to enable the user plane integrity protection according to the required rate and the remaining rate of the first terminal device, so as to ensure the timeliness and security of the transmission data of the terminal device as much as possible.

[0351] Scenario eight, applied to the vehicle to everything (V2X) scenario.

[0352] Please refer to Figure 11 , a communication method applied to a second terminal device provided by this application. In this method, the second terminal device is the first communication device in the above Figure 3 . This method may include the following steps:

[0353] Step 1101, the first terminal device obtains the used rate, the maximum integrity protection rate, and the user plane security policy of the first terminal device.

[0354] Here, the first terminal device obtains the used rate and the maximum integrity protection rate of the first terminal device, which can be referred to the introduction of step 1001 above, and will not be repeated here.

[0355] In a possible implementation, when the first terminal device pre-communicates with the second terminal device, the first terminal device may trigger to obtain the used rate and the maximum integrity protection rate of the first terminal device.

[0356] Step 1102, the first terminal device determines the remaining rate of the first terminal device according to the maximum integrity protection rate and the used rate of the first terminal device.

[0357] This step 1102 can be referred to the way of determining the remaining rate in step 301 above, and will not be repeated here.

[0358] Step 1103: The first terminal device sends a direct communication request message or a direct security mode command message to the second terminal device. Correspondingly, the second terminal device receives the direct communication request message or the direct security mode command message from the first terminal device.

[0359] In a possible implementation, the remaining rate of the first terminal device and the user plane security policy are carried in the direct communication request message or the direct security mode command message.

[0360] Step 1104: The second terminal device obtains the required rate of the first user plane resource.

[0361] In a possible implementation, the second terminal device obtains the remaining rate of the first terminal device and the user plane security policy for establishing the first user plane resource from the first terminal device. Further, the second terminal device obtains the required rate for establishing the first user plane resource from the context of the second terminal device.

[0362] Step 1105: The second terminal device determines whether to enable the user plane integrity protection of the first user plane resource according to the required rate for establishing the first user plane resource, the remaining rate of the first terminal device, and the user plane security policy of the first user plane resource.

[0363] This step 1106 is an optional step. For details, please refer to the introduction of step 302 above and will not be repeated here.

[0364] Step 1106: The second terminal device sends a direct communication response message or a direct security mode response message to the first terminal device. Correspondingly, the first terminal device receives the security indication message from the second terminal device.

[0365] Here, the direct communication response message or the direct security mode response message may include a security indication message. The security indication message is used to indicate whether to enable the user plane integrity protection of the first user plane resource.

[0366] Step 1107: The first terminal device sends a security indication completion message to the second terminal device.

[0367] Through the above steps 1101 to 1107, the first terminal device determines the remaining rate according to the maximum integrity protection rate and the used rate, and sends the remaining rate to the second terminal device. The second terminal device accurately judges whether the first terminal device needs to enable the user plane integrity protection of the first user plane resource according to the required rate and the remaining rate of the first terminal device, so as to ensure the timeliness and security of the transmission data of the terminal device as much as possible.

[0368] It should be noted that the above Figures 4 to 11The first user plane resource in may be a DRB, and the above Figure 11 The first user plane resource in may be an SLBR. Among them, the first user plane resource refers to the user plane resource that the first terminal device is about to establish; the second user plane resource refers to the user plane resource that the first terminal device has established.

[0369] It can be understood that, in order to implement the functions in the above embodiments, the communication device may include the corresponding hardware structures and / or software modules for executing each function. Those skilled in the art should easily realize that, in combination with the modules and method steps of each example described in the embodiments disclosed in the present application, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in the way of hardware or computer software driving hardware depends on the specific application scenario and design constraints of the technical solution.

[0370] Based on the above content and the same concept, Figure 12 and Figure 13 are schematic structural diagrams of possible communication devices provided by the present application. These communication devices can be used to implement the functions of the radio access network device or the master node in the dual connection or the secondary node in the dual connection or the second terminal device or the radio access network device in the handover process or the radio access network device in the RRC connection recovery process in the above method embodiments, and thus can also achieve the beneficial effects possessed by the above method embodiments. In the present application, the communication device may be an access network device as shown in Figure 1a or a terminal device as shown in Figure 1a or the access network device in the above Figure 1b or the terminal device in Figure 1b or the master node in Figure 2 or the secondary node in Figure 2 or a module (such as a chip) applied to the terminal device or the access network device or the master node or the secondary node.

[0371] As Figure 12 shown, the communication device 1200 includes a processing module 1201 and a transceiver module 1202. The communication device 1200 is used to implement the functions of the radio access network device or the master node in the dual connection or the secondary node in the dual connection or the second terminal device or the radio access network device in the handover process or the radio access network device in the RRC connection recovery process in the method embodiments shown in the above Figures 3 to 10 .

[0372] When the communication device 1200 is used to implement Figure 3When implementing the functions of the method embodiments shown: The transceiver module 1202 cooperates with the processing module 1201 to obtain the required rate, remaining rate, and user plane security policy of the first terminal device. The required rate is used to indicate the rate required for the first user plane resource requested to be established by the first terminal device. The remaining rate is determined according to the used rate of the first terminal device and the maximum integrity protection rate of the first terminal device. The used rate is used to indicate the rate used by the second user plane resource already established by the first terminal device. The maximum integrity protection rate is used to indicate the maximum rate after the first terminal device enables user plane integrity protection. The user plane security policy includes user plane integrity protection enabled, user plane integrity protection optionally enabled, or user plane integrity protection disabled. The processing module 1201 is used to determine whether to enable user plane integrity protection for the first user plane resource according to the required rate, the remaining rate, and the user plane security policy.

[0373] For a more detailed description of the above processing module 1201 and transceiver module 1202, reference can be made to Figure 3 the relevant descriptions in the method embodiments shown, and details will not be repeated here one by one.

[0374] It should be understood that the processing module 1201 in the embodiments of the present application may be implemented by a processor or processor-related circuit components, and the transceiver module 1202 may be implemented by a transceiver or transceiver-related circuit components.

[0375] Based on the above content and the same concept, as Figure 13 shown, the present application further provides a communication device 1300. The communication device 1300 may include a processor 1301 and a transceiver 1302. The processor 1301 and the transceiver 1302 are coupled to each other. It can be understood that the transceiver 1302 may be an interface circuit or an input / output interface. Optionally, the communication device 1300 may further include a memory 1303 for storing instructions executed by the processor 1301 or storing input data required for the processor 1301 to run instructions or storing data generated after the processor 1301 runs instructions.

[0376] When the communication device 1300 is used to implement Figure 3 the method shown, the processor 1301 is used to execute the functions of the above processing module 1201, and the transceiver 1302 is used to execute the functions of the above transceiver module 1202.

[0377] When the communication device is a terminal device, Figure 14 shows a schematic structural diagram of a simplified terminal device. For ease of understanding and convenient illustration, Figure 14 in this case, the terminal device is taken as a mobile phone. As Figure 14As shown in the figure, the terminal device 1400 includes a processor, a memory, a radio frequency circuit, an antenna, and an input / output device. The processor is mainly used to process communication protocols and communication data, and to control the entire terminal device, execute software programs, and process the data of software programs. For example, it is used to support the terminal device 1400 to execute the methods performed by the terminal device in any of the above embodiments. The memory is mainly used to store software programs and data. The radio frequency circuit is mainly used for the conversion between baseband signals and radio frequency signals and the processing of radio frequency signals. The antenna is mainly used to transmit and receive radio frequency signals in the form of electromagnetic waves. The input / output device, such as a touch screen, a display screen, a keyboard, etc., is mainly used to receive data input by the user and output data to the user. It should be noted that some types of terminal devices may not have an input / output device.

[0378] After the terminal device is powered on, the processor can read the software program in the memory, interpret and execute the instructions of the software program, and process the data of the software program. When data needs to be sent, after the processor performs baseband processing on the data to be sent, it outputs a baseband signal to the radio frequency circuit. The radio frequency circuit performs radio frequency processing on the baseband signal and then sends the radio frequency signal out in the form of electromagnetic waves through the antenna. When data is sent to the terminal device 1400, the radio frequency circuit receives the radio frequency signal through the antenna, converts the radio frequency signal into a baseband signal, and outputs the baseband signal to the processor. The processor converts the baseband signal into data and processes the data.

[0379] In an alternative implementation, the processor may include a baseband processor and a central processor. The baseband processor is mainly used to process communication protocols and communication data, and the central processor is mainly used to control the entire terminal device 1400, execute software programs, and process the data of software programs. Figure 14 The processor in [description] integrates the functions of the baseband processor and the central processor. It should be noted that the baseband processor and the central processor may also be separate processors, interconnected through technologies such as a bus. In addition, the terminal device may include multiple baseband processors to adapt to different network modes, the terminal device 1400 may include multiple central processors to enhance its processing capabilities, and the various components of the terminal device 1400 may be connected through various buses. The baseband processor may also be referred to as a baseband processing circuit or a baseband processing chip. The central processor may also be referred to as a central processing circuit or a central processing chip. The function of processing communication protocols and communication data may be built into the processor or stored in a storage module in the form of a software program, and the processor executes the software program to implement the baseband processing function.

[0380] In this application, the antenna and the radio frequency circuit with transceiver functions can be regarded as the transceiver module of the terminal device, and the processor with processing functions can be regarded as the processing module of the terminal device. As Figure 14As shown in the figure, the terminal device includes a processing module 1401 and a transceiver module 1402. The transceiver module may also be referred to as a transceiver, a transceiver unit, a transceiver device, etc. The processing module may also be referred to as a processor, a processing board, a processing unit, a processing device, etc. Optionally, the devices in the transceiver module for implementing the receiving function may be regarded as a receiving module, and the devices in the transceiver module for implementing the transmitting function may be regarded as a transmitting module, that is, the transceiver module includes a receiving module and a transmitting module. Exemplarily, the receiving module may also be referred to as a receiver, a receiving circuit, etc., and the transmitting module may be referred to as a transmitter, a transmitting device, or a transmitting circuit, etc.

[0381] On the downlink, the downlink signal (including data and / or control information) sent by the network device is received through the antenna. On the uplink, the uplink signal (including data and / or control information) is sent to the network device or other terminal devices through the antenna. In the processor, the service data and signaling messages are processed. These modules are processed according to the radio access technology adopted by the radio access network (for example, the access technologies of LTE, NR, and other evolved systems). The processor is also used to control and manage the actions of the terminal device and is used to execute the processing performed by the terminal device in the above embodiments. The processor is also used to support the terminal device to execute Figure 3 the execution methods related to the terminal device in

[0382] It should be noted that Figure 14 only one memory, one processor, and one antenna are shown. In an actual terminal device, the terminal device may include any number of antennas, memories, processors, etc. Among them, the memory may also be referred to as a storage medium or a storage device, etc. In addition, the memory may be set independently of the processor or integrated with the processor. The embodiments of the present application do not limit this.

[0383] It should be understood that the transceiver module 1402 is used to execute the sending operation and receiving operation on the terminal device side in the method embodiments shown above Figure 3 The processing module 1401 is used to execute other operations on the terminal device side except the sending and receiving operations in the method embodiments shown above Figure 3 For example, the transceiver module 1402 is used to execute Figure 3 the sending and receiving steps on the terminal device side in the embodiments shown above, such as step 301. The processing module 1401 is used to execute Figure 3 other operations on the terminal device side except the sending and receiving operations in the embodiments shown above, such as step 302.

[0384] When the communication device is a chip - type device or a circuit, the communication device may include a transceiver module and a processing module. Among them, the transceiver module may be an input - output circuit and / or an interface circuit; the processing module may be a processor, a microprocessor, or an integrated circuit integrated on the chip.

[0385] When the communication device is a radio access network device, Figure 15 An exemplary structural schematic diagram of a radio access network device provided by the present application is shown. As Figure 15 shown, the radio access network device 1500 may include one or more radio frequency units, such as a remote radio unit (RRU) 1502 and one or more baseband units (BBU) 1501. The RRU 1502 can be referred to as a transceiver module, a transceiver, a transceiver circuit, or a transceiver, etc. It may include at least one antenna 15021 and a radio frequency unit 15022. The RRU 1502 part is mainly used for the transceiver of radio frequency signals and the conversion between radio frequency signals and baseband signals. The BBU 1501 part can be referred to as a processing module, a processor, etc., and is mainly used for baseband processing, such as channel coding, multiplexing, modulation, spreading, etc., and is also used for controlling the radio access network device. The RRU 1502 and the BBU 1501 can be physically set together; they can also be physically separated, that is, a distributed radio access network device.

[0386] The BBU 1501 is the control center of the base station and can also be called a processing module. It can correspond to Figure 12 the processing module 1201 therein, and is mainly used to complete baseband processing functions, such as channel coding, multiplexing, modulation, spreading, etc. For example, the BBU (processing module) can be used to control the base station to execute the operation process of the radio access network device in the above - mentioned method embodiments. For example, to determine whether to enable the user - plane integrity protection of the first user - plane resource, etc.

[0387] As an alternative implementation, the BBU 1501 may be composed of one or more single boards. Multiple single boards may jointly support a radio access network of a single access mode (such as an LTE network), or may separately support radio access networks of different access modes (such as an LTE network, a 5G network, or other networks). The BBU 1501 further includes a memory 15012 and a processor 15011. The memory 15012 is used to store necessary instructions and data. The processor 15011 is used to control the radio access network device to perform necessary operations, for example, to control the radio access network device to execute the method performed by the radio access network device in any of the above embodiments. The memory 15012 and the processor 15011 may serve one or more single boards. That is to say, a memory and a processor may be separately provided on each single board. It is also possible that multiple single boards share the same memory and processor. In addition, necessary circuits are provided on each single board.

[0388] On the uplink, an uplink signal (including data, etc.) sent by the terminal device is received through the antenna 15021. On the downlink, a downlink signal (including data and / or control information) is sent to the terminal device through the antenna 15021. In the processor 15011, service data and signaling messages are processed, and these modules are processed according to the radio access technology adopted by the radio access network (for example, access technologies of LTE, NR, and other evolved systems). The processor 15011 is further used to control and manage the operations of the radio access network device, and is used to execute the processing performed by the radio access network device in the above embodiments. The processor 15011 is further used to support the radio access network device to execute Figure 3 the method performed by the radio access network device in

[0389] It should be noted that Figure 15 only a simplified design of the radio access network device is shown. In practical applications, the radio access network device may include any number of antennas, memories, processors, radio frequency units, RRUs, BBUs, etc., and all radio access network devices that can implement the present application are within the protection scope of the present application.

[0390] It should be understood that the transceiver module 1502 is used to perform the sending operation and the receiving operation in the method embodiments shown above Figure 3 and the processing module 1501 is used to perform other operations except the sending and receiving operations in the method embodiments shown above Figure 3 For example, step 301. The processing module 1501 is used to perform Figure 3 other operations except the sending and receiving operations in the embodiments shown above, such as step 302.

[0391] Based on the above content and the same concept, the present application provides a communication system. The communication system may include one or more of the foregoing terminal devices, and one or more radio access network devices. The terminal device may execute any method on the terminal device side, and the radio access network device may execute any method on the radio access network device side. The possible implementation manners of the radio access network device and the terminal device may refer to the above introduction, which will not be elaborated herein.

[0392] It can be understood that the processor in the embodiments of the present application may be a central processing unit (CPU), or may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.

[0393] The method steps in the embodiments of the present application may be implemented in a hardware manner, or may be implemented by a processor executing software instructions. The software instructions may be composed of corresponding software modules, and the software modules may be stored in a random access memory (RAM), flash memory, read-only memory (ROM), programmable ROM (PROM), erasable PROM (EPROM), electrically erasable PROM (EEPROM), register, hard disk, removable hard disk, CD-ROM, or any other form of storage medium well-known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium may also be a component of the processor. The processor and the storage medium may be located in the ASIC. In addition, the ASIC may be located in a network device or a terminal device. Of course, the processor and the storage medium may also exist as discrete components in the network device or the terminal device.

[0394] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are executed in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device, or other programmable devices. The computer program or instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer program or instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired or wireless manner. The computer-readable storage medium can be any available medium that can be accessed by a computer, or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium, such as a floppy disk, a hard disk, or a magnetic tape; it can also be an optical medium, such as a digital video disc (DVD); it can also be a semiconductor medium, such as a solid state drive (SSD).

[0395] In various embodiments of the present application, if there is no special description and logical conflict, the terms and / or descriptions between different embodiments are consistent and can be referenced to each other. The technical features in different embodiments can be combined to form new embodiments according to their internal logical relationships.

[0396] In the present application, "at least one" means one or more, and "a plurality" means two or more. "At least one of the following (items)" or similar expressions refer to any combination of these items, including any combination of single (item) or plural (items). For example, at least one of a, b, or c can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple. "And / or" describes the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone, where A and B can be singular or plural. In the text description of the present application, the character " / " generally represents an "or" relationship between the associated objects before and after; in the formula of the present application, the character " / " represents a "division" relationship between the associated objects before and after.

[0397] It is understood that the various numerical numbers involved in the embodiments of the present application are only for the convenience of description and are not used to limit the scope of the embodiments of the present application. The magnitudes of the serial numbers of the above processes do not mean the sequence of execution, and the execution sequence of each process should be determined by its function and internal logic. Terms such as "first" and "second" are used to distinguish similar objects and do not necessarily describe a specific order or sequence. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a series of steps or modules are included. A method, system, product or device is not necessarily limited to those steps or modules clearly listed, but may include other steps or modules not clearly listed or inherent to these processes, methods, products or devices.

[0398] Obviously, those skilled in the art can make various modifications and variations to the present application without departing from the scope of protection of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these modifications and variations.

Claims

1. A communication method, characterized in that, Including: Obtain the required rate, remaining rate, and user plane security policy of the first terminal device. The required rate is used to indicate the rate required for the first user plane resource that the first terminal device requests to establish. The remaining rate is determined according to the used rate of the first terminal device and the maximum integrity protection rate of the first terminal device. The used rate is used to indicate the rate used by the second user plane resource established by the first terminal device. The maximum integrity protection rate is used to indicate the maximum rate after the first terminal device enables user plane integrity protection. The user plane security policy includes user plane integrity protection enabled, user plane integrity protection optionally enabled, or user plane integrity protection disabled. The user plane security policy corresponds to the first user plane resource. Determine whether to enable user plane integrity protection for the first user plane resource according to the required rate, the remaining rate, and the user plane security policy.

2. The method according to claim 1, characterized in that, The second user plane resource includes the user plane resources with user plane integrity protection enabled among the user plane resources established by the first terminal device.

3. The method according to claim 1, characterized in that, The method further includes: Determine the used rate of the first terminal device according to rate parameters. Wherein, the rate parameters include any one or any combination of the following: The maximum bit rate of the protocol data unit (PDU) session aggregation of the second user plane resource; The maximum aggregated bit rate of the first terminal device; The maximum flow bit rate of the quality of service (QoS) flow with guaranteed bit rate (GBR) of the second user plane resource; The guaranteed bit rate of the QoS flow with GBR of the second user plane resource; and The real-time rate of the second user plane resource.

4. The method according to claim 3, characterized in that, The determining the used rate of the first terminal device according to rate parameters includes: Determine the sum of the maximum bit rates of all PDU session aggregations and the maximum flow bit rates of all QoS flows with GBR as the used rate; or Determine the sum of the maximum aggregated bit rate of the terminal device and the maximum flow bit rates of all QoS flows with GBR as the used rate.

5. The method according to claim 3, characterized in that, The determining the used rate of the first terminal device according to rate parameters includes: Determine the sum of the guaranteed bit rates of all QoS flows with GBR as the used rate.

6. The method according to claim 3, characterized in that, The determining the used rate of the first terminal device according to rate parameters includes: Determine the sum of the maximum bit rates of all PDU session aggregations and the guaranteed bit rates of all QoS flows with GBR as the used rate.

7. The method according to any one of claims 1 to 6, characterized in that, When the user plane security policy includes user plane integrity protection enabled or optionally enabled, the determining whether to enable user plane integrity protection for the first user plane resource according to the required rate, the remaining rate, and the user plane security policy includes: If the remaining rate is greater than or equal to the required rate, send a first indication message to the first terminal device. The first indication message is used to indicate enabling user plane integrity protection for the first user plane resource.

8. The method according to any one of claims 1 to 6, characterized in that, When the user plane security policy includes enabling user plane integrity protection, determining whether to enable user plane integrity protection according to the required rate, the remaining rate, and the user plane security policy includes: If the remaining rate is less than the required rate, obtain a third user plane resource, where the user plane security policy of the third user plane resource is optional enabling of user plane integrity protection, and the user plane integrity protection of the third user plane resource has been enabled, and the used rate of the third user plane resource is greater than or equal to the difference between the required rate and the remaining rate, and send a second indication message to the first terminal device, where the second indication message is used to indicate enabling the user plane integrity protection of the first user plane resource and is used to indicate not enabling the user plane integrity protection of the third user plane resource.

9. The method according to any one of claims 1 to 6, characterized in that, When the user plane security policy includes optional enabling of user plane integrity protection, determining whether to enable user plane integrity protection according to the required rate, the remaining rate, and the user plane security policy includes: If the remaining rate is less than the required rate, send a third indication message to the first terminal, where the third indication message is used to indicate not enabling the user plane integrity protection of the first user plane resource.

10. The method according to claim 1, characterized in that, The method is applied to a radio access network device; The obtaining the required rate, the remaining rate, and the user plane security policy of the first terminal device includes: Receiving the required rate, the maximum integrity protection rate, and the user plane security policy of the first terminal device from a session management function network element; the session management function network element obtains the required rate of the first terminal device from a policy control function network element and obtains the maximum integrity protection rate from the first terminal device; Obtaining the used rate from the context of the first terminal device; Determining the remaining rate according to the maximum integrity protection rate and the used rate.

11. The method according to claim 10, characterized in that, The method is applied to a master node of a dual connection; The method further includes: Sending a fourth indication message to the secondary node of the dual connection, where the fourth indication message is used for the secondary node to determine whether to enable user plane integrity protection.

12. The method according to claim 1, wherein, The method is applied to a radio access network device during a handover process; The obtaining the required rate, the remaining rate, and the user plane security policy of the first terminal device includes: Receiving a handover request message from a source radio access network device, where the handover request message includes the required rate, the user plane security policy, the maximum integrity protection rate, and the used rate of the first terminal device; Determining the remaining rate according to the maximum integrity protection rate and the used rate.

13. The method according to claim 1, wherein, The method is applied to a radio access network device during a radio resource control (RRC) connection restoration process; The obtaining the required rate, the remaining rate, and the user plane security policy of the first terminal device includes: Obtain the context response message of the first terminal device from the target radio access network device, where the context response message of the first terminal device includes the required rate of the first terminal device, the user plane security policy, the maximum integrity protection rate, and the used rate; Determine the remaining rate according to the maximum integrity protection rate and the used rate.

14. The method according to claim 1, wherein, The method is applied to the secondary node of dual connectivity; The obtaining the required rate, remaining rate, and user plane security policy of the first terminal device includes: Receive the required rate, the maximum integrity protection rate, the used rate, and the user plane security policy sent by the master node of the dual connectivity; Determine the remaining rate according to the maximum integrity protection rate and the used rate.

15. The method according to any one of claims 10, 12, 13, and 14, wherein, The determining the remaining rate according to the maximum integrity protection rate and the used rate includes: Determine the difference between the maximum integrity protection rate and the used rate as the remaining rate.

16. The method according to claim 1, wherein, The method is applied to the secondary node of dual connectivity; The obtaining the required rate, remaining rate, and user plane security policy of the first terminal device includes: Receive the required rate, the remaining rate, and the user plane security policy from the master node.

17. The method according to claim 14 or 16, wherein, The method further includes: Send to the master node of the dual connectivity the rate used for enabling user plane integrity protection of the first user plane resource.

18. The method according to claim 1, wherein, The method is applied to a second terminal device; The obtaining the required rate, remaining rate, and user plane security policy of the first terminal device includes: Receive the remaining rate and the user plane security policy from the first terminal device; Obtain the required rate from the context of the first terminal device.

19. A communication device, wherein, Includes a module for performing the method according to any one of claims 1 to 18.

20. A communication device, wherein, Includes a processor and a transceiver, where the transceiver is configured to receive signals from other communication devices outside the communication device and transmit them to the processor, or send signals from the processor to other communication devices outside the communication device, and the processor is configured to perform the method according to any one of claims 1 to 18 through logic circuits or by executing code instructions.