A method, device and system for determining user plane security execution information

By obtaining relay-type session information and security policies through the session management network element and determining user plane security execution information, the problem of remote device data security in D2D communication is solved and secure data transmission under the relay device is realized.

CN113810902BActive Publication Date: 2025-09-09HUAWEI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202010480965.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-05-30
Publication Date
2025-09-09
Estimated Expiration
2040-05-30

AI Technical Summary

Technical Problem

In D2D communication, existing technologies cannot effectively guarantee the data security of remote devices when they are outside the coverage of the communication network or when the communication quality is poor. In particular, when relay devices are used, the determination of user-plane security policies is insufficient to meet the security needs of remote devices.

Method used

The session management network element receives requests from terminal devices, obtains relay type session information, determines the user plane security policy, and sends user plane security execution information to the access network device to ensure the security activation status between the relay device and the access network device, including obtaining the user plane security policy and reference service quality requirements signed by the terminal device.

Benefits of technology

It effectively meets the security needs of remote devices, ensures the security of data transmission, avoids the risk of data leakage caused by insufficient security policies, and improves the data transmission reliability of relay devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113810902B_ABST
    Figure CN113810902B_ABST
Patent Text Reader

Abstract

A method, device, and system for determining user plane security execution information, used to ensure the security requirements of data transmitted by a remote device. In the present application, a session management network element can receive a first request, the first request being used to request the creation of a relay-type session of a first terminal device, the first request including first information, the first information being used to indicate that the type of the session is a relay type; thereafter, the session management network element determines the first user plane security execution information of the session based on the first information; and then sends the first user plane security execution information of the session to the access network device, the first user plane execution information of the session being used to determine the first user plane security activation status of the session between the first terminal device and the access network device. The first user plane security execution information determined by the session management network element can better meet the security requirements of the remote device and ensure the security of the data of the remote device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technology, and in particular to a method, device, and system for determining user plane security execution information. Background Art

[0002] Currently, device-to-device (D2D) communication allows user equipment (UE) to communicate directly with each other.

[0003] When a remote device (remote UE) is out of the coverage of the communication network, or when the communication quality between it and the access network device in the communication network is poor, it can establish indirect communication with the communication network through a relay device (relayUE) based on D2D communication. The relay device can establish a protocol data unit (PDU) session for transmitting the remote device, transmit the data received from the remote device to the data network through the PDU session, or send the data obtained from the data network through the PDU session to the remote device.

[0004] During the process of establishing a PDU session, the session management network element obtains the identifier of the relay device and uses the identifier of the relay device to obtain the user plane security policy of the session from the unified data management network element or locally. The session management network element further determines the user plane security execution information of the session based on the user plane security policy. The user plane security execution information is used by the access network device to configure the security activation status between the relay device and the access network device. During the process of determining the user plane security policy of the PDU session, the session management network element determines the user plane security execution information of the established PDU session based on the subscription information or pre-configured information of the relay device. Since the established PDU session can be a PDU session for transmitting services between a remote device and a data network, the user plane security protection method that only uses the subscription information or pre-configured information of the relay device to determine the security requirements of the remote device for transmitting data may not meet the security requirements of the remote device for transmitting data. Summary of the Invention

[0005] The present application provides a method, apparatus, and system for determining user plane security execution information to ensure the security requirements of data transmitted by a remote device.

[0006] In a first aspect, an embodiment of the present application provides a method for determining user plane security execution information, the method comprising: first, a session management network element may receive a first request from a mobile access management network element, the first request being used to request creation of a relay type session of a first terminal device, the first request including first information, the first information being used to indicate that the type of the session is a relay type; thereafter, the session management network element determines the first user plane security execution information of the session based on the first information; and then sends the first user plane security execution information of the session to the access network device, the first user plane execution information of the session being used to determine the first user plane security activation status of the session between the first terminal device and the access network device.

[0007] Through the above method, the session management network element can obtain the user plane security policy of the relay type session through the first information. Afterwards, the determined first user plane security execution information can better meet the security requirements of the remote device and ensure the security of the data of the remote device.

[0008] In one possible design, the first request may include an N1 SM container, which includes the first information. In this case, the first request may be a session establishment request. The first request may also include the first information and the N1 SM container. In this case, the first request includes the session establishment request and the first information. The N1 SM container comes from the first terminal device.

[0009] Through the above method, the first terminal device can send the N1SMcontainer including the first information to the session management network element through the mobile access management network element, and the first information can also be sent by the mobile access management network element to the session management network element, that is, the first request has multiple composition forms and is suitable for different application scenarios.

[0010] In one possible design, when the session management network element determines the first user plane security execution information of the session based on the first information, the session management network element can first obtain the first user plane security policy based on the first information; thereafter, the first user plane security policy can be directly used as the first user plane security execution information of the session, or further analysis can be performed in combination with other judgment information (such as service quality requirements) to determine the first user plane security execution information of the session based on the first user plane security policy.

[0011] Through the above method, after the session management network element obtains the first user plane security policy, it can use multiple methods to determine the first user plane security execution information.

[0012] In one possible design, the session management network element obtains the first user plane security policy based on the first information, including: the session management network element sends a first contract information acquisition request to the unified data management network element, where the first contract information acquisition request can request the user plane security policy subscribed to by the first terminal device; the user plane security policy subscribed to by the first terminal device indicates the user plane security policy of the relay type session of the first terminal device and the user plane security policy of the non-relay type session; thereafter, the session management network element receives a first contract information acquisition response from the unified data management network element, where the first contract information acquisition response includes the user plane security policy subscribed to by the first terminal device; the session management network element determines the first user plane security policy from the user plane security policy subscribed to by the first terminal device based on the first information, and determines the user plane security policy of the relay type session of the first terminal device as the first user plane security policy.

[0013] Through the above method, after the session management network element obtains the user plane security policy signed by the first terminal device from the unified data management network element, it can select the first user plane security policy from the user plane security policy signed by the first terminal device based on the first information, so that the user plane security execution information suitable for the relay session can be finally determined.

[0014] In one possible design, when the session management network element obtains the first user plane security policy according to the first information:

[0015] The session management network element may send a first contract information acquisition request to the unified data management network element; the first contract information acquisition request includes a relay indication; the relay indication is used to request a user plane security policy for a relay-type session of the first terminal device; the relay indication may be the first information (this method can be referred to in the aforementioned content), or the relay indication may be determined based on the first information. Subsequently, the session management network element receives a first contract information acquisition response from the unified data management network element, the first contract information acquisition response including the user plane security policy subscribed to by the first terminal device; the user plane security policy subscribed to by the first terminal device includes the first user plane security policy.

[0016] Through the above method, after the session management network element obtains the user plane security policy subscribed to by the first terminal device from the unified data management network element, it can, based on the relay indication, for example, when the first information is the identifier of the second terminal device, the relay indication can be an explicit indication. This facilitates the unified data management network element to more quickly determine the user plane security policy subscribed to by the first terminal device without having to identify the identifier of the second terminal device.

[0017] In one possible design, when the first information implicitly indicates that the session type is a relay type, for example, the first information may be a temporary identifier or an anonymous identifier of the second terminal device, and when the session management network element obtains the first user plane security policy according to the first request, it may first obtain the SUPI of the second terminal device based on the temporary identifier or anonymized identifier of the second terminal device. For example, the session management network element may obtain the SUPI of the second terminal device from the unified data management network element. Thereafter, the session management network element may send a first contract information acquisition request to the unified data management network element, where the first contract information acquisition request includes the SUPI of the second terminal device; thereafter, the session management network element receives a first contract information acquisition response from the unified data management network element, where the information carried in the first contract information acquisition response may be any of the following:

[0018] The first type is that the first signing information acquisition response includes the first user plane security policy.

[0019] The second type is that the first contract information acquisition response includes the user plane security policy of the first terminal device relay type session; then, the session management network element determines the first user plane security policy based on the user plane security policy of the first terminal device relay type session.

[0020] The third type is that the first contract information acquisition response includes the user plane security policy subscribed by the second terminal device, and then the session management network element determines the first user plane security policy according to the user plane security policy subscribed by the second terminal device.

[0021] Through the above method, the session management network element can obtain the first user plane security policy from the unified data management network element in a variety of different ways.

[0022] In one possible design, when the session management network element obtains the first user plane security policy based on the first request, the session management network element may send a first contract information acquisition request to the unified data management network element, where the first contract information acquisition request includes the first information; the session management network element receives a first contract information acquisition response from the unified data management network element, where the first contract information acquisition response includes the first user plane security policy.

[0023] Through the above method, the session management network element can directly obtain the first user plane security policy from the unified data management network element. This approach is simpler and more efficient.

[0024] In one possible design, there are many ways for the first information to indicate that the session type is a relay type. For example, the first information may be an explicit indication, such as the first information may be a pre-agreed field or character. For another example, the first information may be an implicit indication, such as the first information is an identifier of the second terminal device, and the identifier of the second terminal device includes some or all of the following:

[0025] A temporary identifier of the second terminal device, an anonymous identifier of the second terminal device, or a user permanent identifier SUPI of the second terminal device.

[0026] Through the above method, the first information can flexibly indicate that the type of the session is a relay type in different ways.

[0027] In one possible design, the first user plane security policy indicates that integrity protection is preferred. When determining the first user plane security execution information for the session based on the first user plane security policy, the session management network element may further refer to the maximum data rate for integrity protection of the first terminal device. For example, if the session management network element determines that the maximum data rate for integrity protection of the first terminal device is less than the data rate required for the session, the session management network element may determine that integrity protection of the session is not required, that is, the integrity protection of the session in the first user plane security execution information is not required.

[0028] Through the above method, the first user plane security execution information determined by the session management network element can not only ensure the security requirements of the second terminal device, but also ensure that the first terminal device can effectively transmit the data of the second terminal device through the session.

[0029] In one possible design, if the first user plane security policy indicates that integrity protection is required, the session management network element may send a session establishment rejection response to the first terminal device to indicate the rejection of session establishment when determining that the maximum data rate for integrity protection of the first terminal device is less than the data rate required for the session.

[0030] Through the above method, the session management network element can refuse to establish the session when it determines that the first terminal device cannot support the data transmission of the second terminal device with integrity protection enabled, thereby ensuring the security of the data of the second terminal device.

[0031] In one possible design, the session management network element may also receive a third request, which may be used to instruct a third terminal device to use the session. The third request includes an identifier of the third terminal device. The third request may be a session modification request or another request. The session management network element determines, based on the identifier of the third terminal device, that the third terminal device uses the session. Thereafter, the session management network element may determine second user plane security execution information for the session and send the second user plane security execution information for the session to the access network device. The second user plane security execution information for the session is used to determine the second user plane security activation status of the session between the first terminal device and the access network device.

[0032] Through the above method, the session management network element can update the user plane security execution information of the session to adapt to the security requirements of the third terminal device.

[0033] In one possible design, when the session management network element determines the second user plane security execution information of the session based on the identifier of the third terminal device, it can determine the second user plane security policy based on the identifier of the third terminal device; thereafter, the second user plane security policy can be directly used as the second user plane security execution information of the session, or it can be combined with other judgment information (such as service quality requirements) to determine the first user plane security execution information of the session based on the second user plane security policy.

[0034] Through the above method, after the session management network element obtains the second user plane security policy, it can use multiple methods to determine the second user plane security execution information.

[0035] In one possible design, the identifier of the third terminal device includes part or all of the following:

[0036] A temporary identifier of the third terminal device, an anonymous identifier of the third terminal device, or a SUPI of the third terminal device.

[0037] Through the above method, different identifiers indicate the third terminal device, which is applicable to various scenarios.

[0038] In one possible design, the session management network element may adopt any of the following methods when determining the second user plane security execution information of the session according to the second user plane security policy:

[0039] Method 1: The session management network element determines the second user plane security execution information of the session according to the second user plane security policy and the first user plane security execution information of the session.

[0040] Method 2: The session management network element determines the second user plane security execution information of the session according to the second user plane security policy and the first user plane security policy.

[0041] Method three: The session management network element determines the second user plane security execution information of the session only according to the second user plane security policy.

[0042] Through the above method, the session management network element can determine the second user plane security execution information in a variety of different ways, which are suitable for different application scenarios.

[0043] In one possible design, when the session management network element obtains the second user plane security policy based on the identifier of the third terminal device, it is similar to obtaining the first user plane security policy.

[0044] For example, the session management network element sends a second contract information acquisition request to the unified data management network element, and the second contract information acquisition request includes the identifier of the third terminal device; the session management network element receives a second contract information acquisition response from the unified data management network element, and the second contract information acquisition response includes the second user plane security policy.

[0045] For another example, the session management network element may also determine the second user plane security policy from the user plane security policy subscribed by the first terminal device according to the identifier of the third terminal device.

[0046] For another example, the session management network element sends a second contract information acquisition request to the unified data management network element, and the second contract information acquisition request includes the identifier of the third terminal device; the session management network element receives a second contract information acquisition response from the unified data management network element, and the second contract information acquisition response includes the user plane security policy of the relay type session of the first terminal device. The session management network element determines the second user plane security policy based on the user plane security policy of the relay type session of the first terminal device.

[0047] For another example, the session management network element sends a second contract information acquisition request to the unified data management network element, and the second contract information acquisition request includes the identifier of the third terminal device; the session management network element receives a second contract information acquisition response from the unified data management network element, and the second contract information acquisition response includes the user plane security policy subscribed to by the third terminal device. The session management network element determines the second user plane security policy based on the user plane security policy subscribed to by the third terminal device.

[0048] Through the above method, the session management network element can obtain the second user plane security policy more flexibly, effectively expanding the application scenarios.

[0049] In one possible design, after the session management network element determines that the first user plane security enforcement information of the session is different from the second user plane security enforcement information of the session, the session management network element may send the second user plane security enforcement information of the session to the access network device. After the session management network element determines that the first user plane security enforcement information of the session is the same as the second user plane security enforcement information of the session, the session management network element may not send the second user plane security enforcement information of the session to the access network device.

[0050] Through the above method, by comparing the first user plane security execution information of the session with the second user plane security execution information of the session, when determining whether to send the second user plane security execution information of the session, the information interaction between the session management network element and the access network device can be better reduced.

[0051] In one possible design, the second user plane security policy indicates that integrity protection of the session is preferred. The session management network element determines second user plane security execution information for the session based on the second user plane security policy, and may also refer to the maximum data rate for integrity protection of the first terminal device. For example, after determining that the maximum data rate for integrity protection of the first terminal device is less than the data rate required for the session, the session management network element determines to disable integrity protection for the session, i.e., determines that integrity protection of the session in the second user plane security execution information is not required.

[0052] Through the above method, the second user plane security execution information determined by the session management network element can not only ensure the security requirements of the third terminal device, but also ensure that the first terminal device can effectively transmit the data of the third terminal device through the session.

[0053] In a second aspect, an embodiment of the present application provides a method for determining user plane security execution information, the method comprising: first, a first terminal device may send a second request to a mobile access management network element, the second request being used to request the creation of a relay-type session, the second request including second information indicating that the type of the session is a relay type; thereafter, the first terminal device may receive first indication information from an access network device, the first indication information being used to indicate a first user plane security activation state of a session between the first terminal device and the access network device. The first terminal device configures the first user plane security activation state according to the first indication information.

[0054] Through the above method, the first terminal device can simultaneously indicate the session type of the session when initiating the session creation process, so that the session management network element can determine the user plane security execution information of the session.

[0055] In one possible design, a first terminal device may receive a first direct communication request sent by a second terminal device, where the first direct communication request is used to establish communication with the first terminal device. The first terminal device may determine that a relay-type session needs to be established and send a second request. The first terminal device may pre-establish the relay-type session, that is, the first terminal device may send the second request before receiving the first direct communication request from the second terminal device.

[0056] Through the above method, the first terminal device can determine the need to create a relay-type session in different scenarios and send a second request.

[0057] In one possible design, the second request may include an N1 SM container, which includes the second information. In this case, the first request may be a session establishment request. The second request may also include the second information and the N1 SM container. In this case, the second request includes the session establishment request (i.e., the N1 SM container) and the second information.

[0058] Through the above method, the second request has multiple composition forms, which are suitable for different application scenarios.

[0059] In one possible design, there are many ways for the second information to indicate that the session type is a relay type. For example, the second information may be explicitly indicated, such as by a pre-agreed field or character. Another example is that the second information may be implicitly indicated, such as by the second information being an identifier of the second terminal device, where the identifier of the second terminal device is one of the following: a temporary identifier of the second terminal device, an anonymized identifier of the second terminal device, or a user permanent identifier (SUPI) of the second terminal device. In this case, the session is used to transmit data from the second terminal device.

[0060] Through the above method, the second information can flexibly indicate that the type of the session is a relay type in different ways.

[0061] In one possible design, the first terminal device may further receive a second direct communication request from a third terminal device, the second direct communication request being used to establish communication with the first terminal device. Based on the second direct communication request, the first terminal device determines that the third terminal device should use a session. Thereafter, the first terminal device sends a third request, the third request being used to instruct the third terminal device to use the session and including an identifier of the third terminal device. This third request may be a session modification request or another request.

[0062] Through the above method, when the third terminal device wants to reuse the session, the first terminal device can inform the session management network element that the third terminal device wants to reuse the session by sending a third request, so that the session management network element can re-determine the user plane security execution information.

[0063] In a possible design, the identifier of the third terminal device includes part or all of the following: a temporary identifier of the third terminal device, an anonymous identifier of the third terminal device, or a SUPI of the third terminal device.

[0064] Through the above method, the identifier of the third terminal device can be different types of identifiers, suitable for different application scenarios.

[0065] In one possible design, after receiving the first indication information indicating the security activation status of the first user plane from the access network device, the first terminal device can determine the security activation status of the first terminal device and the second terminal device based on the first user plane security activation status.

[0066] Through the above method, the first terminal device can configure the security activation state of the PC5 port (the communication interface between the first terminal device and the second terminal device) to ensure the data security of the second terminal device.

[0067] In one possible design, if integrity protection is required in the security activation state of the first user plane, the first terminal device may also refer to the integrity protection maximum data rate or QoS control information of the second terminal device when configuring the security activation state of the first terminal device and the second terminal device according to the first user plane security activation state, that is, determine whether to enable integrity protection between the first terminal device and the second terminal device according to the integrity protection maximum data rate or QoS control information of the second terminal device.

[0068] Through the above method, the user plane security activation status of the first terminal device and the second terminal device can not only ensure the data security of the second terminal device, but also ensure that the second terminal device can effectively transmit data to the first terminal device.

[0069] In one possible design, if integrity protection is not required in the first user plane security activation state, the first terminal device sends a direct communication rejection message to the second terminal device when it determines that the user plane security policy of the second terminal device indicates that integrity protection is required (this information can be carried in the first direct communication request).

[0070] Through the above method, the first terminal device can refuse to establish direct communication when it determines that the second terminal device cannot support data transmission with integrity protection enabled, thereby ensuring the security of the data of the second terminal device.

[0071] In one possible design, the first terminal device may further receive second indication information from the access network device, where the second indication information is used to indicate a second user plane security activation state for the session between the first terminal device and the access network device; and then update the first user plane security activation state based on the second indication information. That is, the first user plane security activation state is updated to the second user plane security activation state based on the second indication information.

[0072] Through the above method, the first terminal device can update the user plane security activation status between the first terminal device and the access network device to ensure the data security of the third terminal device.

[0073] In one possible design, after the first terminal device receives the second indication information sent by the access network device, it can also update the user plane security activation status of the first terminal device and the second terminal device based on whether the second user plane security activation status is.

[0074] Through the above method, the first terminal device can update the security activation status of the PC5 port (the communication interface between the first terminal device and the third terminal device) to ensure the data security of the third terminal device.

[0075] In one possible design, integrity protection is required in the security activation state of the second user plane. When the first terminal device updates the security activation state of the first terminal device and the second terminal device according to the security activation state of the second user plane, the integrity protection maximum data rate or QoS control information of the third terminal device can be considered, and whether to enable integrity protection between the first terminal device and the second terminal device can be determined according to the integrity protection maximum data rate or service quality QoS control information of the third terminal device.

[0076] Through the above method, the user plane security activation status of the first terminal device and the third terminal device can not only ensure the data security of the third terminal device, but also ensure that the third terminal device can effectively transmit data to the first terminal device.

[0077] In a third aspect, an embodiment of the present application provides a method for determining user plane security execution information, the method comprising: first, a mobile access management network element receives a second request sent by a first terminal device, the second request including second information, the second request being used to request the creation of a relay type session of the first terminal device, and the second information being used to indicate that the type of the session is a relay type; thereafter, the mobile access management network element sends a first request to the session management network element according to the second request, the first request including first information, the first information being used to indicate that the type of the session is a relay type, and the first request being used to request the creation of a relay type session of the first terminal device.

[0078] Through the above method, after receiving the second request including the second information, the mobile access management network element promptly sends the first request including the first information to the session management network element, so that the session management network element can determine the user plane security execution information of the session based on the first information.

[0079] In one possible design, the second information is identical to the first information. The first request and the second request include an N1 SM container, and the N1 SM container includes the second information. In this case, the first request and the second request may be session establishment requests. That is, the first request and the second request are identical, and the mobile access management network element may transmit the first request directly to the session management network element.

[0080] In one possible design, the second request includes the second information and an N1 SM container; the first request includes the first information and an N1 SM container.

[0081] Through the above method, since the second information is located outside the N1 SM container, the mobility access management network element can identify the second information and further determine the first information that needs to be carried in the first request.

[0082] In one possible design, when the mobile access management network element sends a first request to the session management network element based on the second information, it can first determine whether the first terminal device is authorized to establish a session based on the second information. If it is determined that the first terminal device is authorized to establish a session, the first request is sent to the session management network element; otherwise, the establishment of the session can be directly refused.

[0083] Through the above method, the mobile access management network element can perform an authorization check on the first terminal device according to the second information in advance to ensure that the session can be established more efficiently later.

[0084] In one possible design, the second information is a temporary identifier or an anonymous identifier of the second terminal device. The mobile access management network element can determine the SUPI of the second terminal device based on the second information, and the SUPI of the second terminal device can be used as the first information.

[0085] Through the above method, the mobile access management network element can determine the SUPI of the second terminal device, and the first terminal device does not need to transmit the SUPI of the second terminal device, thereby ensuring the security of the SUPI of the second terminal device.

[0086] In one possible design, there are many ways for the second information to indicate that the session type is a relay type. For example, the second information may be explicitly indicated, such as by a pre-agreed field or character. In another example, the second information may be implicitly indicated, such as by an identifier of the second terminal device, where the identifier of the second terminal device is one of the following: a temporary identifier of the second terminal device, an anonymized identifier of the second terminal device, or a user permanent identifier (SUPI) of the second terminal device.

[0087] Through the above method, the second information can flexibly indicate that the type of the session is a relay type in different ways.

[0088] In one possible design, there are many ways for the first information to indicate that the session type is a relay type. For example, the first information may be an explicit indication, such as the first information may be a pre-agreed field or character. For another example, the first information may be an implicit indication, such as the first information is an identifier of the second terminal device, and the identifier of the second terminal device includes some or all of the following:

[0089] A temporary identifier of the second terminal device, an anonymous identifier of the second terminal device, or a user permanent identifier SUPI of the second terminal device.

[0090] Through the above method, the first information can flexibly indicate that the type of the session is a relay type in different ways.

[0091] In one possible design, before the mobile access management network element sends the first request to the session management network element according to the second request, the mobile access management network element may also determine, based on the second information, that the first terminal device is authorized to establish a session for the second terminal device.

[0092] Through the above method, the mobile access management network element can perform an authorization check on the second terminal device according to the second information in advance to ensure that the first terminal device can transmit the data of the second terminal device.

[0093] In a fourth aspect, an embodiment of the present application provides a method for determining user plane security execution information, the method comprising: a unified data management network element may provide a first user plane security policy to a session management network element, and two methods are provided below:

[0094] Method 1: The unified data management network element can receive a first contract information acquisition request from the session management network element, where the first contract information acquisition request includes first information, and the first information is used to indicate that the type of the session is a relay type; the unified data management network element determines a first user plane security policy based on the first information; thereafter, the unified data management network element sends a first contract information acquisition response to the session management network element, where the first contract information acquisition response includes the first user plane security policy.

[0095] In the above manner, the unified data management network element can directly determine the first user plane security policy and feed it back to the session management network element.

[0096] Method 2: The unified data management network element receives a first contract information acquisition request from the session management network element, where the first contract information acquisition request is used to request the user plane security policy signed by the first terminal device, where the user plane security policy signed by the first terminal device indicates the user plane security policy of the relay type session and the user plane security policy of the non-relay type session of the first terminal device; the unified data management network element sends a first contract information acquisition response to the session management network element, where the first contract information acquisition response includes the user plane security policy signed by the first terminal device, and the user plane security policy signed by the first terminal device includes the first user plane security policy.

[0097] In the above manner, the unified data management network element may only need to feed back the user plane security policy subscribed by the first terminal device to the session management network element, and then the session management network element may determine the first user plane security policy on its own.

[0098] In one possible design, when the unified data management network element determines the first user plane security policy based on the first information, the unified data management network element may determine the first user plane security policy based on the first information and the user plane security policy subscribed by the first terminal device, where the user plane security policy subscribed by the first terminal device indicates a user plane security policy for a relay type and a non-relay type session of the first terminal device;

[0099] Through the above method, the unified data management network element can determine the relay type of the session according to the first information, and further determine the first user plane security policy.

[0100] In one possible design, the first information is the identifier of the second terminal device. When the unified data management network element determines the first user plane security policy based on the first information, the unified data management network element determines the first user plane security policy from the user plane security policy signed by the second terminal device based on the identifier of the second terminal device.

[0101] Through the above method, the first user plane security policy determined according to the user plane security policy subscribed by the second terminal device can ensure the security requirements of the second terminal device.

[0102] In one possible design, the unified data management network element receives a second contract information acquisition request from the session management network element, where the second contract information acquisition request includes an identifier of a third terminal device; then, the unified data management network element determines a second user plane security policy based on the identifier of the third terminal device; then, the unified data management network element sends a second contract information acquisition response to the session management network element, where the second contract information acquisition response includes a second user plane security policy.

[0103] Through the above method, the unified data management network element can determine the relay type of the session according to the second information, and further determine the second user plane security policy.

[0104] In a fifth aspect, an embodiment of the present application further provides a communication device, which is applied to a session management network element. The beneficial effects can be found in the description of the first aspect and will not be repeated here. The device has the function of implementing the behavior in the method example of the first aspect above. The function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions. In one possible design, the structure of the device includes a receiving unit, a processing unit, and a sending unit, which can perform the corresponding functions in the method example of the first aspect above. For details, please refer to the detailed description in the method example, which will not be repeated here.

[0105] In the sixth aspect, an embodiment of the present application further provides a communication device, which is applied to a first terminal device. The beneficial effects can be found in the description of the second aspect and will not be repeated here. The device has the function of implementing the behavior in the method example of the second aspect above. The function can be implemented by hardware, or by hardware executing corresponding software implementation. The hardware or software includes one or more modules corresponding to the above functions. In one possible design, the structure of the device includes a receiving unit and a sending unit, and optionally, a processing unit. These units can perform the corresponding functions in the method example of the second aspect above. Please refer to the detailed description in the method example for details, which will not be repeated here.

[0106] In the seventh aspect, an embodiment of the present application further provides a communication device, which is applied to a mobile access management network element. The beneficial effects can be found in the description of the third aspect and will not be repeated here. The device has the function of implementing the behavior in the method example of the third aspect mentioned above. The function can be implemented by hardware, or by hardware executing corresponding software implementation. The hardware or software includes one or more modules corresponding to the above functions. In one possible design, the structure of the device includes a receiving unit and a sending unit, and optionally, a processing unit. These units can perform the corresponding functions in the method example of the third aspect mentioned above. Please refer to the detailed description in the method example for details, which will not be repeated here.

[0107] In the eighth aspect, an embodiment of the present application further provides a communication device, which is applied to a unified data management network element. The beneficial effects can be found in the description of the fourth aspect and will not be repeated here. The device has the function of implementing the behavior in the method example of the fourth aspect. The function can be implemented by hardware, or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions. In one possible design, the structure of the device includes a receiving unit and a sending unit, and optionally, a processing unit. These units can perform the corresponding functions in the method example of the fourth aspect. Please refer to the detailed description in the method example for details, which will not be repeated here.

[0108] In a ninth aspect, an embodiment of the present application further provides a communication device, which is applied to a session management network element. The beneficial effects can be found in the description of the first aspect and are not further described here. The communication device includes a processor and a memory, wherein the processor is configured to support the session management network element in performing the corresponding functions of the method of the first aspect. The memory is coupled to the processor and stores the necessary program instructions and data for the communication device. The communication device also includes a communication interface for communicating with other devices.

[0109] In a tenth aspect, an embodiment of the present application further provides a communication device, which is applied to a first terminal device. The beneficial effects can be found in the description of the second aspect and are not repeated here. The structure of the communication device includes a processor and a memory, and the processor is configured to support the first terminal device to perform the corresponding functions of the method of the second aspect. The memory is coupled to the processor and stores the necessary program instructions and data for the communication device. The structure of the communication device also includes a transceiver for communicating with other devices.

[0110] In an eleventh aspect, an embodiment of the present application further provides a communication device, which is applied to a mobile access management network element. The beneficial effects can be found in the description of the third aspect and are not repeated here. The structure of the communication device includes a processor and a memory, and the processor is configured to support the mobile access management network element in performing the corresponding functions of the method of the third aspect. The memory is coupled to the processor and stores the necessary program instructions and data for the communication device. The structure of the communication device also includes a communication interface for communicating with other devices.

[0111] In a twelfth aspect, an embodiment of the present application further provides a communication device, which is applied to a unified data management network element. The beneficial effects can be found in the description of the fourth aspect and will not be repeated here. The structure of the communication device includes a processor and a memory, and the processor is configured to support the unified data management network element to perform the corresponding functions in the above-mentioned fourth aspect method. The memory is coupled to the processor, which stores the necessary program instructions and data for the communication device. The structure of the communication device also includes a communication interface for communicating with other devices.

[0112] In a thirteenth aspect, an embodiment of the present application further provides a communication system. The beneficial effects can be found in the description of the above aspects and will not be repeated here. The communication system includes a session management network element and a unified data management network element.

[0113] a session management network element, configured to send a first subscription information acquisition request to a unified data management network element, where the first subscription information acquisition request includes a relay indication, where the relay indication is used to request a user plane security policy for a relay-type session of the first terminal device;

[0114] The unified data management network element is configured to receive a first subscription information acquisition request, determine a first user plane security policy from user plane security policies subscribed to by the first terminal device based on the first information, the user plane security policy subscribed to by the first terminal device including user plane security policies for relay type and non-relay type sessions of the first terminal device; and send a first subscription information acquisition response to the session management network element, the first subscription information acquisition response including the first user plane security policy;

[0115] The session management network element is also used to receive a first signing information acquisition response.

[0116] In one possible design, the system further includes a mobility management network element:

[0117] A mobile access management network element is configured to send a first request to a session management network element, where the first request is used to request establishment of a relay-type session for a first terminal device, and the first request includes first information, where the first information is used to indicate that the type of the session is a relay type;

[0118] The session management network element is configured to receive a first request, wherein the relay indication is first information or is determined based on the first information.

[0119] In one possible design, the session is used to transmit data of the second terminal device. The first information is an identifier of the second terminal device. The identifier of the second terminal device includes some or all of the following:

[0120] The temporary identifier of the second terminal device, the anonymous identifier of the second terminal device, or the SUPI of the second terminal device.

[0121] In one possible design, the system also includes access network equipment.

[0122] The session management network element is further configured to send the first user plane security execution information of the session to the access network device after determining the first user plane security execution information of the session according to the first user plane security policy.

[0123] The access network device is used to receive the first user plane security execution information of the session, and activate the first user plane security activation state of the session between the first terminal device and the access network device according to the first user plane security execution information of the session.

[0124] In one possible design, the system further includes a first terminal device;

[0125] The access network device is also used to send a first indication message to the first terminal device, where the first indication message is used to indicate the first user plane security activation status of the session between the first terminal device and the access network device.

[0126] The first terminal device is used to receive a first indication message, activate the first user plane security activation state with the access network device according to the first indication information; and configure the security activation state of the first terminal device and the second terminal device according to the first user plane security activation state.

[0127] In one possible design, the first terminal device is further configured to, after determining that the third terminal device uses the session, send a second request to the session management network element, where the second request is used to request modification of the session and includes an identifier of the third terminal device;

[0128] The session management network element is also used to obtain the second user plane security policy based on the identifier of the third terminal device; and after determining the second user plane security execution information of the session based on the second user plane security policy, send the second user plane security execution information of the session to the access network device.

[0129] The access network device is further used to receive the second user plane security execution information of the session, update the first user plane security activation state according to the second user plane security execution information of the session, and update the first user plane security activation state to the second user plane security activation state.

[0130] In one possible design, the identifier of the third terminal device includes part or all of the following:

[0131] A temporary identifier of the third terminal device, an anonymous identifier of the third terminal device, or a SUPI of the third terminal device.

[0132] In one possible design, the access network device is further used to send a second indication message to the first terminal device, where the second indication message is used to indicate the second user plane security activation status of the session between the first terminal device and the access network device.

[0133] The first terminal device is used to receive the second indication message, update the first user plane security activation status according to the second indication information, and update the first user plane security activation status to the second user plane security activation status; and update the security activation status of the first terminal device and the second terminal device according to the second user plane security activation status.

[0134] In one possible design, the first user plane security policy indicates that integrity protection is preferred, and the session management network element determines first user plane security execution information for the session based on the first user plane security policy, specifically for:

[0135] After determining that the maximum data rate for integrity protection of the first terminal device is less than the data rate required for the session, it is determined to close the integrity protection of the session.

[0136] In one possible design, if the first user plane security policy indicates that integrity protection is required, the session management network element is also used to send a session establishment rejection response to the first terminal device after determining that the maximum data rate for integrity protection of the first terminal device is lower than the data rate required for the session, to indicate the rejection of session establishment.

[0137] In one possible design, the session management network element determines the second user plane security execution information of the session according to the second user plane security policy, specifically for:

[0138] Determine second user plane security enforcement information for the session according to the second user plane security policy and the first user plane security enforcement information for the session; or

[0139] Second user plane security enforcement information for the session is determined according to the second user plane security policy and the first user plane security policy.

[0140] In one possible design, the session management network element obtains the second user plane security policy according to the identifier of the third terminal device, specifically for:

[0141] Sending a second contract information acquisition request to the unified data management network element, where the second contract information acquisition request includes an identifier of the third terminal device;

[0142] The unified data management network element is configured to receive the second subscription information acquisition request, determine the second user plane security policy according to the identifier of the third terminal device, and send the second user plane security policy to the session management network element;

[0143] The session management network element further receives the second user plane security policy from the unified data management network element.

[0144] In one possible design, before the session management network element sends the second user plane security execution information of the session to the access network device, it is further configured to:

[0145] It is determined that the first user plane security enforcement information of the session is different from the second user plane security enforcement information of the session.

[0146] In one possible design, the second user plane security policy indicates that integrity protection of the session is preferred, and the session management network element determines the second user plane security execution information of the session according to the second user plane security policy, specifically for:

[0147] After determining that the maximum data rate for integrity protection of the first terminal device is less than the data rate required for the session, it is determined to close the integrity protection of the session.

[0148] In a fourteenth aspect, the present application further provides a computer-readable storage medium, wherein the computer-readable storage medium stores instructions, which, when executed on a computer, enable the computer to execute the methods described in the above aspects.

[0149] In a fifteenth aspect, the present application also provides a computer program product comprising instructions, which, when executed on a computer, enables the computer to execute the methods described in the above aspects.

[0150] In a sixteenth aspect, the present application further provides a computer chip, which is connected to a memory, and is used to read and execute the software program stored in the memory to execute the methods described in the above aspects. BRIEF DESCRIPTION OF THE DRAWINGS

[0151] Figure 1 An architectural diagram of a system provided in an embodiment of the present application;

[0152] Figure 2 A schematic diagram of a method for determining user plane security execution information provided in an embodiment of the present application;

[0153] Figure 3 A schematic diagram of a method for determining user plane security execution information provided in an embodiment of the present application;

[0154] Figure 4 A schematic diagram of a method for determining user plane security execution information provided in an embodiment of the present application;

[0155] Figure 5 A schematic diagram of a method for determining user plane security execution information provided in an embodiment of the present application;

[0156] Figure 6 A schematic diagram of a method for determining user plane security execution information provided in an embodiment of the present application;

[0157] Figures 7 to 13 A schematic structural diagram of a communication device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0158] See Figure 1 As shown, a specific network architecture diagram applicable to the present application is shown. The network architecture is the network architecture of a 5G system. The network elements in the 5G architecture include terminal equipment (UE). The network architecture also includes a radio access network (RAN), an access and mobility management function (AMF) network element, a session management function (SMF) network element, a user plane function (UPF) network element, a unified data management (UDM) network element, an application function (AF) network element, a data network (DN), etc.

[0159] A terminal device is a device with wireless transceiver capabilities that can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; it can also be deployed on water (such as ships, etc.); it can also be deployed in the air (such as airplanes, balloons, and satellites, etc.). The terminal device can be a mobile phone, a tablet computer, a computer with wireless transceiver capabilities, a virtual reality (VR) terminal, an augmented reality (AR) terminal, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, etc. In the embodiment of the present application, the terminal devices can be divided into two types, namely, remote UE (such as the second terminal device, the third terminal device) and relay UE (such as the first terminal device). The remote UE refers to a UE that needs to communicate with the data network with the help of a relay UE, and the relay UE is a UE that can communicate directly with the data network.

[0160] In an embodiment of the present application, the remote UE can send a direct communication request (such as a first direct communication request and a second direct communication request) to the relay UE to establish a communication connection of the PC5 port with the relay UE, and the relay UE can initiate a session establishment process to the SMF network element to establish a session for transmitting data between the remote UE and the DN (the session is essentially a session established by the relay UE with the network through the access network, which is used to transmit data that needs to be transmitted between the remote UE and the data network, and can also be called a relay session). When the relay UE initiates the session establishment process, it can directly send the remote UE's identifier or indication information indicating that the established session is a relay session to the SMF network element. When the relay UE initiates the session establishment process, it can also send the remote UE's identifier or indication information to the SMF network element through the AMF network element.

[0161] The primary function of the RAN is to control wireless access of terminal devices to the mobile communications network. The RAN is part of a mobile communications system. It implements a radio access technology. Conceptually, it resides between a device (such as a mobile phone, a computer, or any remote control) and provides connectivity to its core network.

[0162] The AMF network element is responsible for terminal access management and mobility management. In actual applications, it includes the mobility management function in the MME in the LTE network framework and adds access management functions.

[0163] The SMF network element is responsible for session management, such as establishing, modifying or deleting a user's session. In an embodiment of the present application, the SMF network element can determine that the session created by the relay UE is a relay session based on the identification or indication information of the remote UE, obtain the user plane security policy of the relay session from the UDM network element, and determine the user plane security execution information of the session required by the RAN based on the user plane security policy of the relay session.

[0164] The UPF network element is a functional network element of the user plane, which is mainly responsible for connecting to the external network. It includes the relevant functions of the LTE serving gateway (SGW) and public data network gateway (PDN-GW).

[0165] DN is responsible for providing a network service for terminals. For example, some DNs provide Internet access for terminals, while others provide SMS functions for terminals.

[0166] The UDM network element can store the user's subscription information, implementing an implementation similar to the HSS in 4G. In an embodiment of the present application, the UDM can determine the user's permanent identification (SUPI) of the terminal device based on the anonymous identification or temporary identification of the remote UE. The UDM network element also stores the subscription user plane security policy of the relay UE, and the subscription user plane security policy of the relay UE includes the user plane security policy of the relay session. After the UDM network element receives the subscription information acquisition request from the SMF network element, it feeds back the user plane security policy of the relay session to the SMF network element.

[0167] The AF network element can be a third-party application server or a device deployed by the operator itself, such as a proxy-call session control function (P-CSCF). The AF network element can provide services for multiple application servers.

[0168] Although not shown, the core network network elements also include a unified data repository (UDR) network element and a subscription identifier de-concealing function (SIDF) network element. The UDR network element is mainly used to store user-related subscription data, policy data (such as the user plane security policy subscribed by the UE), structured data for openness, and application data. SIDF network element. In an embodiment of the present application, the SIDF network element can parse the UE's anonymized identifier (SUCI) and obtain the SUPI. The SIDF network element can be deployed independently or co-deployed with other network elements. For example, the SIDF network element can be co-deployed with the UDM network element.

[0169] In an embodiment of the present application, when the relay UE determines that a relay session needs to be created, it can initiate a session establishment process to the session management network element to establish a relay-type session, and in the session establishment process, send first information indicating that the type of the session is a relay type to the session management network element. The session management network element determines the first user plane security policy based on the first information, and determines the first user plane security execution information of the session based on the first user plane security policy, and sends the first user plane security execution information of the session to the access network device. The access network device can use the first user plane security execution information of the session to determine the first user plane security activation state. The first user plane security activation state is used to indicate whether the integrity protection of the user plane between the relay UE and the access network device is turned on or off, and whether the encryption protection is turned on or off. In an embodiment of the present application, by receiving the first information, the session management network element can obtain the user plane security policy of the relay-type session, thereby determining the user plane security execution information of the session, so that the security activation state determined by the access network based on the user plane security execution information of the session can meet the security requirements of the remote UE.

[0170] The following describes the method for determining the user plane security policy provided by the embodiment of the present application in conjunction with the accompanying drawings. In the embodiment of the present application, there are two methods for determining the user plane security activation status. One method is to determine the user plane security of the session based on the identification or indication information of the second terminal device without the participation of the mobile access management network element. The other method is to involve the mobile access management network element. The mobile access management network element needs to perform further processing based on the information sent by the first terminal device, and then determine, obtain, or generate indication information and send it to the session management network element. The session management network element then determines the user plane security policy of the session based on the information. The two methods are described below respectively:

[0171] Method 1: See Figure 2 , a method for determining user plane security execution information provided in an embodiment of the present application, the method comprising:

[0172] Step 201: A second terminal device sends a first direct communication request to a first terminal device, requesting to establish a communication connection with the first terminal device. The first direct communication request may include an identifier of the second terminal device.

[0173] The identifier of the second terminal device includes but is not limited to: a temporary identifier of the second terminal device, an anonymous identifier, and a user permanent identifier (SUPI).

[0174] Among them, the temporary identifier is an identifier pre-assigned to the second terminal device, and the anonymous identifier can be a permanent identifier that hides the terminal device. Only a specific network element can obtain the permanent identifier of the terminal device hidden in the anonymous identifier through the anonymous identifier. For example, the anonymous identifier can be a user hidden identifier (subscription concealed identifier, SUCI), and SUCI is a privacy protection identifier including SUPI.

[0175] Step 202: After receiving the first direct communication request, the first terminal device determines that a session needs to be established for transmitting data to the second terminal device, that is, a relay-type session for the first terminal device needs to be established. The first terminal device then sends a session establishment request to the session management network element. The session establishment request is used to request the establishment of a relay-type session for the first terminal device. The session establishment request may include a session identifier. In this embodiment of the present application, the session established may be a PDU session.

[0176] It should be noted that in the embodiment of the present application, a relay-type session may also be referred to as a relay session. A relay session is a session established by the first terminal device as a relay UE to support data transmission between a remote UE and a data network. Accordingly, in addition to the relay-type session of the first terminal device, there is also a non-relay-type session of the first terminal device. In the embodiment of the present application, a non-relay-type session may also be referred to as a non-relay session. A non-relay session is a session established by the first terminal device for itself to support data transmission between the first terminal device and the data network.

[0177] In order to inform the session management network element that the session requested to be created by the first terminal device is a relay session, the first terminal device may carry first information in the session establishment request, where the first information indicates that the type of the session is a relay type.

[0178] The embodiments of the present application do not limit the manner in which the first information indicates that the session type is a relay type. For example, the first information may be an explicit indication, such as a pre-agreed field or character. In another example, the first information may be an implicit indication, such as an identifier of the second terminal device.

[0179] When the first terminal device sends a session establishment request to the session management network element, it may first send the session establishment request to the mobile access management network element. After receiving the session establishment request, the mobile access management network element forwards the session establishment request to the session management network element.

[0180] Furthermore, the first terminal device sends a session establishment request to the mobile access management network element by including it in a NAS message, and the NAS message also includes a data network name (DNN) and / or single-network slice selection assistance information (S-NSSAI). In other words, the session establishment request is included in the N1 SM container.

[0181] Step 203: After receiving the session establishment request, the session management network element determines the first user plane security policy according to the first information.

[0182] Step 204: After obtaining the first user plane security policy, the session management network element can determine the first user plane security execution information of the relay session based on the first user plane security policy, wherein the first user plane security execution information of the relay session can be used to determine the first user plane security activation status of the session between the first terminal device and the access network device.

[0183] It should be noted that the first user plane security activation state of the session between the first terminal device and the access network device is actually the first user plane security activation state of the communication interface between the first terminal device and the access network device. For the sake of convenience, the communication interface between the first terminal device and the access network device is referred to as the first interface.

[0184] Step 205: After determining the first user plane security execution information of the relay session, the session management network element may send the first user plane security execution information of the relay session to the access network device.

[0185] The embodiment of the present application does not limit the manner in which the session management network element determines the first user plane security policy based on the first information. Four manners are listed below:

[0186] (1) The session management network element obtains the contract information of the first terminal device. The contract information of the first terminal device includes relay identification information and the user plane security policy signed by the first terminal device. The relay identification information is used to indicate whether the first terminal device is authorized to establish a relay type session, that is, whether it is allowed to act as a relay device.

[0187] The user plane security policy signed by the first terminal device includes the user plane security policy when the first terminal device is allowed to act as a relay device. The user plane security policy when the first terminal device is allowed to act as a relay device includes the user plane security policy of the relay session of the first terminal device. Optionally, the user plane security policy when the first terminal device is allowed to act as a relay device also includes the user plane security policy of the non-relay session when the first terminal device is allowed to act as a relay device, that is, the user plane security policy of the non-relay session of the first terminal device.

[0188] Optionally, the user plane security policy subscribed to by the first terminal device may also include a user plane security policy when the first terminal device does not serve as a relay device.

[0189] The user plane security policy of the non-relay session when the first terminal device is allowed to act as a relay device and the user plane security policy when the first terminal device is not used as a relay device both belong to the user plane security policy of the non-relay session of the first terminal device. The difference lies in whether the first terminal device is allowed to act as a relay device.

[0190] There are many ways to identify the user plane security policy signed by the first terminal device, the user plane security policy when the first terminal device is allowed to act as a relay device, and the user plane security policy when the first terminal device is not allowed to act as a relay device. For example, it can be explicitly identified by relay identification information, or the user plane security policy can be identified by using relay sessions and non-relay sessions. In the method of using relay sessions and non-relay sessions to identify the user plane security policy, since relay sessions and non-relay sessions are distinguished, it means that the first terminal device is allowed to act as a relay device.

[0191] The following lists several user plane security policies subscribed by the first terminal device, see Table 1 and Table 2.

[0192] Table 1

[0193]

[0194] Among them, user plane security policy 1 is a user plane security policy identified by relay identification information, and is the user plane security policy when the first terminal device acts as a relay device. User plane security policy 2 is the user plane security policy when the first terminal device does not act as a relay device. User plane security policy 1 can be used as the user plane security policy for the relay session of the first terminal device, and user plane security policy 2 can be used as the user plane security policy for the non-relay session of the first terminal device. It should be noted here that since user plane security policy 1 does not distinguish between relay sessions and non-relay sessions, that is, when the data network of the non-relay session of the first terminal device is data network 1, user plane security policy 1 can also be selected as the user plane security policy.

[0195] Table 2

[0196]

[0197] Among them, user plane security policy 1 and user plane security policy 2 are user plane security policies identified by relay identification information, and user plane security policy 5 is the user plane security policy when the first terminal device is not acting as a relay device. Although user plane security policy 3 and user plane security policy 4 do not carry relay identification information, they have distinguished between relay sessions and non-relay sessions. In other words, the first terminal device can act as a relay device. This is an implicit indication that the first terminal device is allowed to act as a relay UE. In essence, it is the user plane security policy when the first terminal device acts as a relay device.

[0198] User plane security policy 1 and user plane security policy 3 are user plane security policies for the relay session of the first terminal device, and user plane security policy 2, user plane security policy 4 and user plane security policy 5 are user plane security policies for the non-relay session of the first terminal device.

[0199] It should be noted that the user plane security policy signed by the first terminal device can also distinguish between the user plane security policy when the first terminal device is allowed to act as a relay device and the user plane security policy when the first terminal device does not act as a relay device. Only the relay identification information is added to the contract information to indicate that the first terminal device is authorized to establish a relay-type session, that is, it can act as a relay device. The session management network element can select the corresponding user plane security policy based on the DNN and / or S-NSSAI corresponding to the session.

[0200] (2) The session management network element obtains the contract information of the first terminal device (including the user plane security policy signed by the first terminal device), and the session management network element determines the first user plane security policy based on the first information and the user plane security policy signed by the first terminal device.

[0201] The user plane security policy signed by the first terminal device is the signed user plane security policy pre-configured by the operator network for the first terminal device. The user plane security policy signed by the first terminal device may include the user plane security policy of the relay type session of the first terminal device, and may also include the user plane security policy of the non-relay type session.

[0202] In an embodiment of the present application, the user plane security policy subscribed to by the first terminal device includes the first user plane security policy and / or the second user plane security policy, and may also include the user plane security policy of the non-relay session.

[0203] For example, the information included in the user plane security policy subscribed by the first terminal device is shown in Table 3:

[0204] Table 3

[0205]

[0206] Optionally, the user plane security policy subscribed by the first terminal device may further include an identifier of the second terminal device. The identifier of the second terminal device is used to indicate the terminal device to which the data to be transmitted in the relay session belongs.

[0207] As can be seen from Table 1, the user plane security policy subscribed by the first terminal device includes the user plane security policy of the session when the session established with one or more data networks is a relay session and a non-relay session. The data network can be indicated by the DNN of the data network. Optionally, the user plane security policy subscribed by the first terminal device may also include single-network slice selection assistance information (S-NSSAI), which is used to identify or indicate the network slice.

[0208] The information included in the user plane security policy is explained here. The user plane security policy indicates whether encryption protection and integrity protection are enabled. Specifically, the user plane security policy includes a user plane encryption protection policy (indicating whether encryption protection is enabled) and a user plane integrity protection policy (indicating whether integrity protection is enabled). There are three possible values ​​for the user plane encryption protection policy, namely not needed, preferred, and required. There are three possible values ​​for the user plane integrity protection policy, namely not needed, preferred, and required. Among them, notneeded means that it does not need to be enabled, preferred means that it can be enabled or not, and required means that it must be enabled. The above three possible values ​​can be indicated by 2 bits, for example, 00 indicates that it does not need to be enabled, 01 indicates that it can be enabled or not, and 11 indicates that it must be enabled. The specific way in which the user plane encryption protection policy and the user plane integrity protection policy indicate the three possible values ​​is not limited in the embodiments of the present application.

[0209] User plane encryption protection protects the confidentiality of data during transmission (hence, it is also called user plane confidentiality protection). Confidentiality means that the true content of the transmitted data cannot be directly revealed. User plane integrity protection protects the integrity of data during user plane transmission. Integrity means that the data is original and has not been tampered with.

[0210] In an embodiment of the present application, the user plane security policy signed by the first terminal device can be locally stored by the session management network element, or obtained by the session management network element from the unified data management network element. For example, after receiving the session establishment request, the session management network element can obtain the user plane security policy signed by the first terminal device from the unified data management network element.

[0211] Exemplarily, the session management network element may send a first contract information acquisition request to the unified data management network element. The first contract information acquisition request may carry a relay indication, where the relay indication is used to request a user plane security policy for a relay-type session of the first terminal device; the relay indication may be the first information or may be determined based on the first information.

[0212] For example, when the first information is the identifier of the second terminal device, the relay indication can use an explicit indication method to indicate that the type of session is a relay type, so as to request the user plane security policy of the relay type session of the first terminal device. After receiving the first contract information acquisition request, the unified data management network element can directly determine the user plane security policy of the relay type session of the first terminal device that needs to be fed back according to the relay indication.

[0213] Afterwards, the unified data management network element sends a first subscription information acquisition response to the session management network element, where the first subscription information acquisition response includes the user plane security policy subscribed to by the first terminal device. The session management network element receives the first subscription information acquisition response from the unified data management network element.

[0214] The session management network element selects a corresponding user plane security policy from the user plane security policies subscribed to by the first terminal device as the first user plane security policy based on the first information carried in the session establishment request, that is, selects the user plane security policy of the relay type session as the first user plane security policy.

[0215] When the session management network element obtains the user plane security policy signed by the first terminal device from the unified data management network element, it can also only obtain part of the user plane security policy signed by the first terminal device, for example, only obtain the user plane security policy of the relay session of the first terminal device.

[0216] Still taking the example of the session management network element sending a first contract information acquisition request to the unified data management network element, the session management network element sends a first contract information acquisition request to the unified data management network element, and the first contract information acquisition request is used to request the user plane security policy signed by the first terminal device, wherein the first contract information acquisition request includes the first information (which can also be a relay indication).

[0217] After receiving the first contract information acquisition request, the unified data management network element can determine the user plane security policy of the relay session of the first terminal device from the user plane security policy subscribed by the first terminal device based on the first information.

[0218] The unified data management network element sends a first contract information acquisition response to the session management network element, where the first contract information acquisition response includes a user plane security policy for the first terminal device relay session.

[0219] The session management network element determines whether the session is a relay session based on the first information carried in the session establishment request. If the session is a relay session, the user plane security policy can be selected from the user plane security policy of the relay session of the first terminal device as the first user plane security policy.

[0220] Optionally, the session management network element may also determine whether the session is a relay session based on the first information carried in the session establishment request. If the session is a relay session, the session management network element may directly request the first user plane security policy from the unified data management network element. In other words, the session management network element may send a request message to the unified data management network element for requesting a user plane security policy for a relay-type session. After receiving the request message, the unified data management network element determines the first user plane security policy from the user plane security policies for the relay session and feeds the first user plane security policy back to the session management network element.

[0221] In the above description, the session management network element obtains the user plane security policy subscribed to by a first terminal device from the unified data management network element. In reality, the session management network element can also obtain the user plane security policy subscribed to by a second terminal device from the unified data management network element via the first information. Specifically, after receiving the first subscription acquisition request including the first information, if the first information is the identifier of the second terminal device, the unified data management network element determines the user plane security policy subscribed to by the second terminal device based on the first information and includes the user plane security policy subscribed to by the second terminal device in the first subscription information acquisition request. The session management network element then determines the first user plane security policy based on the user plane security policy subscribed to by the second terminal device.

[0222] As a possible implementation method, the session management network element can locally store user plane security policy information at the DNN and / or S-NSSAI granularity, where the user plane security policy at the DNN and / or S-NSSAI granularity includes the user plane security policy of the relay session and / or the user plane security policy of the non-relay session corresponding to the DNN and / or S-NSSAI. The session management network element can select the corresponding user plane security policy based on the DNN and / or S-NSSAI corresponding to the session.

[0223] (3) The first information is an anonymous identifier or temporary identifier of the second terminal device. The session management network element first determines the user permanent identifier of the second terminal device, then obtains the user plane security policy of the relay type session of the first terminal device from the unified data management network element, and then determines the first user plane security policy based on the first information.

[0224] The session management network element may first obtain the user permanent identifier of the second terminal device from the unified data management network element according to the first information.

[0225] Exemplarily, the session management network element may send a request message carrying first information to the unified data management network element, requesting to obtain the user permanent identifier of the second terminal device. After receiving the request message, the unified data management network element may obtain the user permanent identifier of the second terminal device based on the first message, and then feedback a response message carrying the user permanent identifier of the second terminal device to the session management network element. The request message may be a newly added message, or it may be a message that the session management network element needs to send to the unified data management network element in an existing interaction process.

[0226] The embodiments of the present application do not limit the manner in which the unified data management network element obtains the user permanent identification of the second terminal device based on the first message. For example, the unified data management network element may store the correspondence between the temporary identification of the second terminal device and the user permanent identification, or the correspondence between the anonymous identification of the second terminal device and the user permanent identification. After obtaining the first information, the unified management network element may determine the user permanent identification of the second terminal device based on the first information based on the stored correspondence. For another example, the unified data management network element may also have an identification resolution capability, and may resolve the anonymous identification of the second terminal device into the user permanent identification of the second terminal device. For another example, the unified data management network element may also obtain the user permanent identification of the second terminal device by interacting with an identification resolution network element (such as a SIDF network element). For example, the unified data management network element sends the anonymous identification of the second terminal device to the identification resolution network element, and obtains the user permanent identification of the second terminal device from the identification resolution network element.

[0227] After obtaining the permanent user identifier of the second terminal device, the session management network element can obtain the user plane security policy of the relay type session of the first terminal device from the unified data management network element according to the permanent user identifier of the second terminal device.

[0228] For example, the session management network element may send a first contract information acquisition request carrying the user permanent identifier of the second terminal device to the unified data management network element, requesting to obtain the user plane security policy of the relay type session of the first terminal device. Optionally, the first contract information acquisition request may also include DNN and / or S-NSSAI. After receiving the first contract information acquisition request, the unified data management network element determines that the session is a relay session based on the user permanent identifier of the second terminal device, and then determines the user plane security policy of the relay type session of the first terminal device from the user plane security policy signed by the first terminal device. The unified data management network element then feeds back a first contract information acquisition response carrying the user plane security policy of the relay type session of the first terminal device to the session management network element. The session management network element receives the user plane security policy of the relay type session of the first terminal device from the unified data management network element.

[0229] As a possible implementation method, after the unified data management network element receives the first contract information acquisition request carrying the user permanent identifier of the second terminal device, it can also determine the user plane security policy signed by the second terminal device based on the user permanent identifier of the second terminal device, and use the user plane security policy signed by the second terminal device as the first user plane security policy. If the user plane security policy signed by the second terminal device includes multiple user plane security policies, the unified data management network element can select one of the user plane security policies as the first user plane security policy. Exemplarily, the unified data management network element can determine the first user plane security policy from multiple user plane security policies based on DNN and / or S-NSSAI, and then feed back the first user plane security policy to the session management network element. Among them, the user plane security policy signed by the second terminal device is the signed user plane security policy pre-configured by the operator network for the second terminal device.

[0230] It should be noted that the information indicated by the user plane security policy signed by the second terminal device may be similar to the information indicated by the user plane security policy signed by the first terminal device, that is, the user plane security policy signed by the second terminal device may indicate the user plane security policy of the relay session when the second terminal device accesses the network as a remote UE through a relay UE, and may also indicate the user plane security policy of the non-relay session when the second terminal device directly creates a session. When determining the first user plane security policy, the unified data management network element may determine the first user plane security policy based on the user plane security policy of the relay session when the second terminal device accesses the network as a remote UE through a relay UE.

[0231] (4) The session management network element directly obtains the first user plane security policy from the unified data management network element.

[0232] The session management network element can directly send a first contract information acquisition request carrying the first information to the unified data management network element, requesting to obtain the first user plane security policy. Optionally, the first contract information acquisition request can also include DNN and / or S-NSSAI, which is used by the unified data management network element to obtain the contract information corresponding to the DNN and / or S-NSSAI, and the contract information includes the corresponding user plane security policy.

[0233] Here, taking the example of carrying the first information in the first contract information acquisition request, in actual applications, the session management network element may also determine the relay indication information based on the first information. The relay indication information may indicate that the type of the session is a relay type. That is, the session management network element generates a relay indication based on the first information and carries the relay indication in the first contract information acquisition request. The first information and the relay indication may indicate that the type of the session is a relay type in different ways. As a possible implementation method, the relay indication may also be the same as the first information, that is, the session management network element carries the first information in the first contract information acquisition request.

[0234] After the unified data management network element receives the first subscription information acquisition request, the unified data management network element may determine that the subscription information of the relay type session needs to be acquired based on the first information, that is, determine the first user plane security policy.

[0235] When determining the first user plane security policy, the unified data management network element may obtain the first user plane security policy from the user plane security policy subscribed to by the first terminal device.

[0236] If the first information is the identifier of the second terminal device, the unified data management network element may also provide the user plane security policy subscribed by the second terminal device to the session management network element, and the session management network element uses the user plane security policy subscribed by the second terminal device as the first user plane security policy. Furthermore, if the subscription information of the second terminal device may include the user plane security policy of the relay session when the second terminal device accesses the network as a remote UE through a relay UE, the unified data network element may provide the user plane security policy as the first user plane security policy to the session management network element.

[0237] Exemplarily, the first information is a temporary identifier or an anonymous identifier of the second terminal device. The unified data management network element can determine the user permanent identifier of the second terminal device based on the temporary identifier or anonymized identifier of the second terminal device. Afterwards, the unified data management network element obtains the user plane security policy signed by the second terminal device based on the user permanent identifier of the second terminal device and provides it to the session management network element. The session management network element uses the user plane security policy signed by the second terminal device as the first user plane security policy.

[0238] After determining the first user plane security policy, the unified data management network element feeds back a first subscription information acquisition response carrying the first user plane security policy to the session management network element. The session management network element receives the first user plane security policy from the unified data management network element.

[0239] It should be noted that in the above-mentioned possible implementation methods, the information interacted between the session management network element and the unified data management network element is uniformly named as the first contract information acquisition request and the first contract information acquisition response, but in different implementation methods, the information carried in the first contract information acquisition request and the first contract information acquisition response may be different.

[0240] The first user plane security execution information of the relay session determined in step 204 is similar to the first user plane security policy, and can indicate whether encryption protection and integrity protection are enabled between the first terminal device and the access network device in the relay session, wherein the values ​​of encryption protection and integrity protection are similar to the values ​​of the user plane encryption protection policy and the user plane integrity protection policy in the aforementioned description. For details, please refer to the aforementioned content and will not be repeated here. When executing step 204, the session management network element can directly use the first user plane security policy as the first user plane security execution information of the relay session. For example, the first user plane security policy indicates that the user plane encryption protection policy is required and the user plane integrity protection policy is not required, then the first user plane security execution information of the relay session indicates that encryption protection of the first interface is required and integrity protection is not required. The session management network element may also analyze information of the first terminal device, including but not limited to the maximum data rate for integrity protection of the first terminal device and quality of service (QoS) control information of the first terminal device (such as the data rate required for the relay session of the first terminal device). After analyzing the information of the first terminal device, the session management network element may determine to use the first user plane security policy as the first user plane security execution information for the relay session. The session management network element may also modify the first user plane security policy after analyzing the information of the first terminal device to determine the first user plane security execution information for the relay session.

[0241] For example, the first user plane security policy indicates that the user plane encryption protection policy is preferred. The session management network element needs to further determine whether encryption protection of the first interface is enabled, and then determine the first user plane security execution information of the relay session.

[0242] For another example, the first user plane security policy indicates that both the user plane encryption protection policy and the user plane integrity protection policy are preferred, and the session management network element needs to further determine whether to enable encryption protection and integrity protection of the first interface.

[0243] There are many ways for the session management network element to further determine the first user plane security execution information of the relay session, which is not limited in the embodiments of the present application. For example, the session management network element can determine the first user plane security execution information of the relay session based on the maximum data rate of the integrity protection of the first terminal device.

[0244] The maximum data rate for integrity protection of the first terminal device is used to indicate the data transmission rate supported by the first terminal device after integrity protection is enabled. If the first user plane security policy indicates that the user plane integrity protection policy is preferred, the session management network element determines whether the data transmission rate supported by the first terminal device after integrity protection is enabled can meet the data rate required by the relay session. The data rate required by the relay session is determined by the session management network element based on the DNN and / or S-NSSAI of the session and / or other parameters used to determine the data rate. The data rate required by the relay session can be obtained by the session management network element from a unified data management network element or a policy control network element (such as a PCF network element), or can be obtained based on local configuration.

[0245] If the data transmission rate supported by the first terminal device after integrity protection is enabled is lower than the data rate required by the relay session, the session management network element can determine that integrity protection in the user plane security execution information is not required, that is, turn off integrity protection of the first interface.

[0246] If the data transmission rate supported by the first terminal device after integrity protection is enabled is not less than the data rate required by the relay session, the session management network element can determine that integrity protection in the user plane security execution information is required, that is, enable integrity protection of the first interface.

[0247] After determining the first user plane security execution information of the relay session, the session management network element may create the relay session and execute step 205 .

[0248] It should be noted that the session management network element may also refuse to establish the relay session based on the first terminal device's maximum integrity protection data rate. For example, if the first user plane security policy indicates that the user plane integrity protection policy is enabled, and the first terminal device's maximum integrity protection data rate is lower than the data rate required for the relay session, that is, after integrity protection is enabled, the first terminal device cannot transmit data at the required data rate for the relay session. The session management network element may refuse to establish the relay session and send a session establishment rejection response to the first terminal device.

[0249] After receiving the first user plane security execution information of the relay session, the access network device can configure the first user plane security activation status of the first interface, which indicates whether encryption protection and integrity protection are enabled between the first terminal device and the access network device in the relay session, and send indication information indicating the first user plane security activation status of the first interface to the first terminal device, informing the first terminal device whether encryption protection and integrity protection are enabled for the first interface.

[0250] It is worth noting that in the first user plane security activation state, encryption protection has only two states: one is enabled and the other is disabled. In the first user plane security activation state, integrity protection also has only two states: one is enabled and the other is disabled. The first user plane security activation state is the final user plane security activation state of the first interface.

[0251] After receiving indication information indicating the security activation status of the first user plane of the first interface, the first terminal device can determine the security activation status of the first terminal device and the second terminal device based on the security activation status of the first user plane of the first interface. The security activation status of the first terminal device and the second terminal device is used to indicate whether encryption protection and integrity protection are enabled when the first terminal device and the second terminal device perform data transmission.

[0252] It should be noted that the security activation status of the first and second terminal devices is essentially the security activation status of the communication interface between the first and second terminal devices. Within this security activation status, encryption protection has only two states: enabled and disabled. Integrity protection also has only two states: enabled and disabled. This security activation status is the final security activation status of the communication interface between the first and second terminal devices. For ease of explanation, the communication interface between the first and second terminal devices will be referred to as the second interface.

[0253] For example, the first terminal device may set the security activation state of the second interface to be consistent with the first user plane security activation state of the first interface.

[0254] For another example, the first terminal device may determine the security activation status of the second interface after analyzing the first user plane security activation status of the first interface. If the first user plane security activation status of the first interface indicates that integrity protection of the first interface is enabled, the first terminal device may further determine whether integrity protection is enabled for the second interface.

[0255] There are many ways for the first terminal device to determine the security activation status of the second interface, which is not limited in the embodiment of the present application.

[0256] Exemplarily, the first terminal device may determine the security activation state of the second interface based on the integrity protection maximum data rate or quality of service (QoS) control information of the second terminal device. The integrity protection maximum data rate or QoS control information of the second terminal device may be carried in the first direct communication request.

[0257] The first terminal device can determine the security activation status of the second interface based on the maximum data rate of integrity protection of the second terminal device in the same way as the session management network element determines the first user plane security execution information of the session based on the maximum data rate of integrity protection of the first terminal device, which will not be repeated here.

[0258] The QoS control information of the second terminal device is used to indicate the requirements of the second terminal device when performing data transmission, such as the required bandwidth, data transmission rate, delay, packet loss rate, etc.

[0259] The first terminal device can determine whether the second terminal device can support the activation of integrity protection based on the QoS control information of the second terminal device.

[0260] For example, the QoS control information of the second terminal device indicates that the second terminal device must transmit data, but the bandwidth required by the second terminal device to transmit data is 100 megabits, and the bandwidth that can be supported after integrity protection is enabled is 50 megabits. The first terminal device can determine not to enable integrity protection.

[0261] Through steps 201 to 205 , the user plane security policy of the relay session created by the first terminal device is based on the first information. The first terminal device can transmit data of the second terminal device through the relay session to ensure the security of the transmitted data.

[0262] In actual applications, the first terminal device can also establish communication with other terminal devices, and these other terminal devices can exchange data with the data network through the session with the first terminal device. In other words, the first terminal device can also use the established relay session to transmit data from other terminal devices. In this case, the relay session is reused by other terminal devices, and the user plane security policy for the relay session may need to be redefined. The following describes how to redefined the user plane security policy for a relay session, using a third terminal device as an example.

[0263] The third terminal device may send a second direct communication request to the first terminal device, where the second direct communication request is used to request to establish communication with the first terminal device. The second direct communication request may include an identifier of the third terminal device.

[0264] The identifier of the third terminal device includes but is not limited to: a temporary identifier, an anonymous identifier, and a SUPI of the third terminal device.

[0265] After receiving the second direct communication request, the first terminal device determines that the established session still needs to transmit data from a third terminal device, meaning that the third terminal device needs to use the relay session. The first terminal device sends a session modification request to the session management network element, requesting modification of the relay session. The session modification request may also be another session management message or a newly defined session management message.

[0266] The session modification request may include the identifier of the third terminal device and may also carry the identifier of the relay session, so as to indicate the relay session to be modified.

[0267] After receiving the session modification request, the session management network element may determine, based on the identifier of the third terminal device, that the third terminal device uses the relay session. The session management network element may then determine a second user plane security policy. The manner in which the session management network element determines the second user plane security policy is similar to that described in step 203. For details, see the preceding content and will not be further described here. Furthermore, the session management network element determines, based on the second user plane security policy, whether to update the user plane security enforcement information for the relay session.

[0268] After the session management network element determines the second user plane security policy, it can determine second user plane security execution information for the relay session based on the second user plane security policy. The second user plane security execution information for the relay session can be used to determine the second user plane security activation status of the session between the first terminal device and the access network device.

[0269] There are many ways for the session management network element to determine the second user plane security execution information of the relay session according to the second user plane security policy. Three of them are listed below:

[0270] The first method is that the session management network element only determines the second user plane security execution information of the relay session based on the second user plane security policy. This method is similar to step 204, and the details can be found in the above content and will not be repeated here.

[0271] The session management network element may compare the second user plane security execution information of the relay session with the first user plane security execution information of the relay session. If the second user plane security execution information of the relay session is consistent with the first user plane security execution information of the relay session, it indicates that the first user plane security activation state of the first interface can be maintained unchanged, and the session management network element may no longer notify the access network device of the second user plane security execution information. If they are inconsistent, the session management network element may need to notify the access network device of the second user plane security execution information so that the access network device can configure the second user plane security activation state of the first interface, and send indication information indicating the second user plane security activation state of the first interface to the first terminal device, informing the first terminal device whether encryption protection and integrity protection are enabled for the first interface.

[0272] After receiving the indication information indicating the second user plane security activation status of the first interface, the first terminal device can update the security activation status of the second interface according to the second user plane security activation status of the first interface. The way in which the first terminal device updates the security activation status of the second interface according to the second user plane security activation status of the first interface is similar to the way in which the first terminal device determines the security activation status of the second interface according to the first user plane security activation status of the first interface. For details, please refer to the above description and will not be repeated here.

[0273] Second, the session management network element determines the second user plane security execution information of the relay session according to the second user plane security policy and the first user plane security policy.

[0274] The session management network element determines whether encryption protection and integrity protection are enabled on the first interface according to the second user plane security policy and the first user plane security policy.

[0275] For example, if the first user plane security policy indicates that the user plane encryption protection policy is preferred and the user plane integrity protection policy is not required, and the second user plane security policy indicates that the user plane encryption protection policy is required and the user plane integrity protection policy is required, the session management network element may determine that encryption protection of the first interface is required and user plane integrity protection is required. For another example, if the first user plane security policy indicates that the user plane encryption protection policy is required and the user plane integrity protection policy is not required, and the second user plane security policy indicates that the user plane encryption protection policy is required and user plane integrity protection is required, the session management network element may determine that encryption protection of the first interface is required and integrity protection is required.

[0276] The session management network element can retain the consistent user plane encryption protection policy or user plane integrity protection policy in the second user plane security policy and the first user plane security policy, and use the retained user plane encryption protection policy or user plane integrity protection policy as the corresponding encryption protection or integrity protection in the second user plane security execution information of the first interface.

[0277] For inconsistent user plane integrity protection policies or user plane encryption protection policies, the session management network element may give priority to the user plane integrity protection policy or user plane encryption protection policy that can improve security. For example, if the user plane integrity protection policy is selected as required or the user plane encryption protection policy is selected as required, the preferred user plane integrity protection policy or user plane encryption protection policy will be used as the corresponding integrity protection or encryption protection in the second user plane security execution information of the first interface.

[0278] After determining the second user plane security execution information of the first interface, the session management network element can compare the second user plane security execution information of the relay session with the first user plane security execution information of the relay session. The operations performed by the session management network element after comparison and the operations performed by the first terminal device can be found in the description of the first method and will not be repeated here.

[0279] A third method is that the session management network element determines the second user plane security execution information of the relay session according to the second user plane security policy and the first user plane security execution information of the relay session.

[0280] The way in which the session management network element determines the second user plane security execution information of the relay session based on the second user plane security policy and the first user plane security execution information of the relay session is similar to the second way. The session management network element can retain the consistent encryption protection or integrity protection in the second user plane security policy and the first user plane security execution information of the relay session, and use the retained encryption protection or integrity protection as the corresponding encryption protection or integrity protection in the second user plane security execution information of the first interface.

[0281] For inconsistent integrity protection or encryption protection, the session management network element may give priority to the integrity protection or encryption protection that can improve security, such as selecting encryption protection to be enabled and integrity protection to be enabled.

[0282] After determining the second user plane security execution information of the first interface, the session management network element can compare the second user plane security execution information of the relay session with the first user plane security execution information of the relay session. The operations performed by the session management network element after comparison and the operations performed by the first terminal device can be found in the description of the first method.

[0283] It should be noted that when the session management network element determines the second user plane security execution information of the relay session based on the second user plane security policy, it may also consider the QoS control information and / or the maximum data rate for integrity protection of the first terminal device. The way in which the session management network element determines the second user plane security execution information of the relay session in combination with the QoS control information and / or the maximum data rate for integrity protection of the first terminal device is similar to the way in which the session management network element determines the first user plane security execution information of the relay session in combination with the QoS control information and / or the maximum data rate for integrity protection of the first terminal device. For details, please refer to the above content and will not be repeated here.

[0284] Method 2: See Figure 3 , another method for determining user plane security execution information provided by an embodiment of the present application, the method comprising:

[0285] Step 301: The same as step 201. For details, please refer to the relevant description of step 201, which will not be repeated here.

[0286] Step 302: After receiving the first direct communication request, the first terminal device determines that a session for transmitting the second terminal device, i.e., a relay session, needs to be established. The first terminal device then sends a session establishment request and second information to the mobile access management network element. The session establishment request is used to request the establishment of a relay-type session for the first terminal device, and the second information is used to indicate that the session type is relay-type. The manner in which the second information indicates that the session type is relay-type is similar to the manner in which the first information indicates that the session type is relay-type. For details, please refer to the previous description and will not be repeated here.

[0287] The first terminal device may send an N1 message to the mobile access management network element, wherein the N1 message includes the second information and a session establishment request. The session establishment request is included in an N1 SM container. Optionally, the session establishment request may also carry the integrity protection maximum data rate of the first terminal device.

[0288] Step 303: The mobile access management network element determines the first information according to the second information.

[0289] For different second information, the first information determined by the mobile access management network element according to the second information is also different, which are described below respectively:

[0290] 1. The second information is an anonymous identifier or temporary identifier of the second terminal device, and the first information is a permanent identifier of the user of the second terminal device or an explicit indication that the session type is a relay type.

[0291] The method in which the mobile access management network element determines the user permanent identification of the second terminal device according to the anonymous identification or temporary identification of the second terminal device is similar to the method in which the mobile access management network element determines the user permanent identification of the second terminal device according to the anonymous identification or temporary identification of the second terminal device Figure 2 In the embodiment shown, the manner in which the session management network element determines the user permanent identification of the second terminal device based on the anonymous identification or temporary identification of the second terminal device is similar. The mobile access management network element can obtain the user permanent identification of the second terminal device from the unified data management network element based on the anonymous identification or temporary identification of the second terminal device. For details, please refer to the above content and will not be repeated here.

[0292] Optionally, the second information may also be a permanent user identifier of the second terminal device, and the first information may also be a permanent user identifier of the second terminal device, or may explicitly indicate that the session type is a relay type.

[0293] The mobile access management network element can determine that the established session is a relay session based on the second information, perform an authorization check on the first terminal device, and determine whether the first terminal device has the authority to create a relay session. The mobile access management network element can obtain the contract information of the first terminal device from the unified data management network element or other network elements (network elements that support storing contract information), and determine whether the first terminal device is authorized to establish a relay session based on the contract information. The contract information is used to indicate whether the first terminal device is allowed to act as a relay device and / or whether it is authorized to establish a relay session corresponding to the requested DNN and / or S-NSSAI (as mentioned above, the relay identification information can be used to explicitly indicate that the first terminal device is allowed to act as a relay device, or the user plane security policy that distinguishes between relay sessions and non-relay sessions can be used to implicitly indicate that the first terminal device is allowed to act as a relay device. The indication of whether the establishment of the relay session corresponding to the requested DNN and / or S-NSSAI is authorized can be determined by whether the user plane security policy corresponding to the DNN and / or S-NSSAI carries relay identification information or whether it is distinguished by relay sessions or non-relay sessions). The mobile access management network element can check whether the first terminal device can establish a specific type of relay session. Such as relay sessions corresponding to specific DNN and / or S-NSSAI.

[0294] Optionally, the mobile access management network element may determine, based on the second information, to initiate an authorization check process to other network elements, so that the authorization check network element determines whether the first terminal device is authorized to establish a relay session and / or determines whether the first terminal can serve as a relay device for the second terminal. The mobile access management network element determines, based on the result sent by the authorization check network element, whether the first terminal is authorized to establish a relay session and / or determines whether the first terminal can serve as a relay device for the second terminal.

[0295] Optionally, the mobility management network element may also determine, based on the second information, whether the first terminal can serve as a relay device for the second terminal.

[0296] Optionally, the mobile access management network element may also perform an authorization check on the second terminal device based on the second information to determine whether the second terminal device can perform data transmission through the relay UE. The mobile access management network element may obtain the contract information of the second terminal device from the unified data management network element or other network element, and determine whether the second terminal device is authorized to use the relay session based on the contract information. The contract information is used to indicate whether the second terminal device can perform data transmission through the relay UE.

[0297] If the mobile access management network element passes the authorization check on the first terminal device, the mobile access management network element may send the first information to the session management network element. Otherwise, the mobile access management network element may reject the session establishment request of the first terminal device.

[0298] 2. The first information explicitly indicates that the session type is a relay type.

[0299] After receiving the second information, the mobile access management network element may determine that the session that the first terminal device needs to create is a relay session, that is, the session needs to transmit data of the second terminal device subsequently.

[0300] The mobile access management network element can perform an authorization check on the first terminal device based on the second information to determine whether the first terminal device has the authority to create a relay session. The mobile access management network element can obtain the contract information of the first terminal device from the unified data management network element or other network elements (network elements that support storage of contract information), and determine whether the first terminal device is authorized to establish a relay session based on the contract information. The contract information is used to indicate whether the first terminal device is authorized to act as a relay UE and / or whether it is authorized to establish a relay session corresponding to the requested DNN and / or S-NSSAI. The mobile access management network element can check whether the first terminal device can establish a specific type of relay session. Such as a relay session corresponding to a specific DNN and / or S-NSSAI.

[0301] Optionally, the mobile access management network element may determine to initiate an authorization check process to other network elements based on the second information, so that the authorization check network element determines whether the first terminal device is authorized to create a relay session.

[0302] Optionally, the mobile access management network element may also perform an authorization check on the second terminal device based on the second information to determine whether the second terminal device can transmit data through the relay UE. The mobile access management network element may obtain the contract information of the second terminal device from the unified data management network element or other network element, and determine whether the second terminal device is authorized to use the relay session based on the contract information. The contract information is used to indicate whether the second terminal device can transmit data through the relay UE.

[0303] If the mobile access management network element passes the authorization check on the first terminal device, the mobile access management network element may send the first information to the session management network element. Otherwise, the mobile access management network element may reject the session establishment request of the first terminal device.

[0304] 3. The first information is the same as the second information.

[0305] Similar to the previous case, the mobile access management network element can perform an authorization check on the first terminal device based on the second information. If the mobile access management network element passes the authorization check on the first terminal device, it can send the first information to the session management network element. In other words, the first information sent by the mobile access management network element to the session management network element is the same as the second information sent by the first terminal device to the mobile access management network element. Otherwise, the mobile access management network element can reject the session establishment request of the first terminal device.

[0306] Step 304: The mobile access management network element sends a session establishment request and first information to the session management network element.

[0307] Step 305: The same as step 203. For details, please refer to the relevant description of step 203, which will not be repeated here.

[0308] Step 306: The same as step 204. For details, please refer to the relevant description of step 204, which will not be repeated here.

[0309] Step 307: The same as step 205. For details, please refer to the relevant description of step 205, which will not be repeated here.

[0310] Through steps 301 to 307 , the user plane security policy of the relay session created by the first terminal device is determined based on the first information. The first terminal device can transmit data of the second terminal device through the relay session to ensure the security of the transmitted data.

[0311] In actual applications, the first terminal device can also establish communication with other terminal devices, and other terminal devices can exchange data with the data network through the session of the first terminal device. In other words, the first terminal device can also use the established relay session to transmit data of other terminal devices. In this case, the relay session is reused by other terminal devices, and the user plane security policy of the relay session may need to be determined again. The method of re-determining the user plane security policy of the relay session when the third terminal device reuses the relay session can be found in Figure 2 The relevant instructions in are not repeated here.

[0312] It should be noted that when the third terminal device reuses the relay session, the first terminal device can also use the same Figure 3 The temporary identifier or anonymous identifier of the third terminal device is sent to the mobile access management network element in the manner shown. The mobile access management network element can also use a similar method to determine the user permanent identifier of the third terminal device, and then send a session modification request (the session modification request does not carry the identifier of the third terminal device) and the user permanent identifier of the third terminal device to the session management network element.

[0313] It is worth noting that in Figures 2-3 The illustrated embodiments all use the example of a first terminal device requesting to establish a relay session after a second terminal device initiates a first direct communication request. In actual applications, the first terminal device may also pre-establish a relay session before the second terminal device initiates the first direct communication request, that is, send a session establishment request to the session management network element. In this case, the first information may explicitly indicate that the session type is a relay session.

[0314] The following is based on Figure 1 The network architecture shown in the figure takes the unified data management network element as the UDM network element, the session management network element as the SMF network element, the mobile access management network element as the AMF network element, the first terminal device as the relay UE, and the second terminal device as the remote UE as an example. Figure 2 The method for determining user plane security execution information shown in FIG is further introduced. Figure 4 As shown, a method for determining user plane security execution information provided by an embodiment of the present application includes:

[0315] Step 401: The user plane security policy subscribed to by the relay UE is configured on the UDM network element, including the user plane security policy for the relay session. The user plane security policy subscribed to by the relay UE may be as shown in Tables 1 to 3. Tables are merely one way of presenting data, and the embodiments of this application do not limit the presentation method of the user plane security policy subscribed to by the relay UE. For example, the user plane security policy subscribed to by the relay UE may also be presented using a data mapping method.

[0316] Step 402: The relay UE sends a session establishment request to the SMF network element to request the creation of a relay type session of the relay UE. The session establishment request includes first information, and the first information is used to indicate that the type of the session is a relay type.

[0317] Step 403: The SMF network element sends a first contract information acquisition request to the UDM network element. The first contract information acquisition request includes first information. The first contract information acquisition request is used to request the contract information of the first terminal device, and the contract information includes the user plane security policy subscribed by the relay UE.

[0318] Step 404: After receiving the first subscription information acquisition request, the UDM network element determines the user plane security policy subscribed to by the relay UE.

[0319] Step 405: The UDM network element sends a first contract information acquisition response to the SMF network element. The first contract information acquisition response includes the user plane security policy of the relay UE's contract.

[0320] It should be noted that the first contract information acquisition request sent by the SMF network element to the UDM network element can be used to request all contract information of the first terminal device, including the user plane security policy of the relay session of the first terminal device (the user plane security policy of the relay session includes the first user plane security policy and other user plane security policies of the relay session) and the user plane security policy of the non-relay session. The first contract information acquisition response sent by the UDM network element to the SMF network element includes all contract information of the first terminal device. The SMF network element can determine the first user plane security policy from all the contract information of the first terminal device. Furthermore, the first contract information acquisition request sent by the SMF network element to the UDM network element can be used to request all contract information corresponding to the DNN / S-NSSAI of the relay session of the first terminal device. Furthermore, the SMF network element determines the first user plane security policy from all the contract information.

[0321] As another possible implementation, the first contract information acquisition request sent by the SMF network element to the UDM network element can also be used to request partial contract information of the first terminal device, such as the contract information of the first terminal device as a relay UE. The contract information of the first terminal device as a relay UE includes the user plane security policy of the relay session of the first terminal device (the user plane security policy of the relay session includes the first user plane security policy and other user plane security policies of the relay session). The first contract information acquisition response sent by the UDM network element to the SMF network element may include all contract information of the first terminal device as a relay UE, such as the first user plane security policy and other user plane security policies of the relay session; it may also include only partial contract information of the first terminal device as a relay UE, such as only the user plane security policy of the relay session of the first terminal device. After receiving the user plane security policy of the relay session of the first terminal device, the SMF network element determines the first user plane security policy from the user plane security policy of the relay session of the first terminal device.

[0322] Step 406: The SMF network element determines first user plane security execution information of the relay session according to the first user plane security policy. The first user plane security execution information indicates the first user plane security activation state of the first interface, which may also be called a UU interface.

[0323] Step 407: The SMF network element sends the first user plane security execution information of the relay session to the RAN. The RAN configures the first user plane security activation state of the first interface according to the first user plane security execution information of the relay session and activates the user plane security activation state of the relay session.

[0324] Step 408: The RAN sends first indication information to the relay UE, where the first indication information is used to indicate a first user plane security activation state of the first interface.

[0325] Step 409: The remote UE sends a first direct communication request to the relay UE, where the first direct communication request includes the remote UE's identifier and optionally the remote UE's maximum data rate for integrity protection.

[0326] Step 410: After receiving the first direct communication request, the relay UE determines that a relay session needs to be established to transmit data of the second terminal device, and determines the security activation status information of the PC5 air interface based on the first user plane security activation status of the first interface. The PC5 air interface is the communication interface between the relay UE and the remote UE.

[0327] For example, the relay UE can set the first user plane security activation status of the first interface to the security activation status of the PC5 port. For example, if encryption protection of the first interface is required and integrity protection is not required, the encryption protection of the PC5 port is also turned on and integrity protection is turned off.

[0328] For another example, if the integrity protection of the first interface is enabled, the relay UE may determine whether to activate the integrity protection according to the UE integrity protection maximum data rate and / or QoS control information of the remote UE.

[0329] Step 411: The relay UE sends a first direct security mode command to the remote UE. The first direct security mode command includes an encryption protection indication and an integrity protection indication, which respectively indicate whether data encryption and integrity protection are enabled.

[0330] Step 412: After receiving the first direct security mode command, the remote UE configures encryption protection and integrity protection of the PC5 port according to the first direct security mode command, and sends a first direct security mode completion message to the relay UE.

[0331] Step 413: The relay UE sends a first direct communication response to the remote UE.

[0332] It should be noted that in the above description, the relay session creation process (steps 402 to 408) is performed before the second terminal device initiates the direct communication process (step 409). In actual applications, the relay session creation process can also be performed after step 409. That is, after the relay UE receives the first direct communication request from the remote UE, if the relay session is not established or the established relay session is not reusable, the relay UE can initiate a process for creating a new relay session. In this case, the identifier of the remote UE can be used as the first information in the session establishment request.

[0333] The following is based on Figure 1The network architecture shown in the figure takes the unified data management network element as the UDM network element, the session management network element as the SMF network element, the mobile access management network element as the AMF network element, the first terminal device as the relay UE, and the second terminal device as the remote UE as an example. Figure 3 The method for determining user plane security execution information shown in FIG is further introduced. Figure 5 As shown, a method for determining a user plane security policy provided by an embodiment of the present application includes:

[0334] Step 501: Same as step 409. For details, please refer to the relevant description of step 409 and will not be repeated here.

[0335] Step 502: After receiving the first direct communication request, the relay UE determines that a relay session needs to be established. The relay UE sends a first N1 message to the AMF network element. The first N1 message includes the identifier of the remote UE and the first N1 SM container. The first N1 SM container contains the session establishment request. The first N1 SM container contains the maximum data rate for integrity protection of the relay UE.

[0336] Step 503: After the AMF network element receives the first N1 message, the AMF network element can determine that the session that the relay UE needs to create is a relay session based on the identifier of the remote UE. The AMF network element performs an authorization check on the relay UE to determine that the relay UE has the authority to create a relay session.

[0337] Optionally, if the remote UE identifier is a temporary identifier or an anonymous identifier, the AMF network element may obtain the remote UE's SUPI from the UDM network element based on the remote UE identifier. The AMF network element performs an authorization check on the remote UE based on the remote UE's SUPI to determine whether the remote UE can transmit data through the relay UE.

[0338] Step 504: After the AMF network element passes the authorization check on the relay UE, it sends a first Nsmf service message to the SMF network element. The first Nsmf service message includes the SUPI of the remote UE and the first N1 SM container.

[0339] Step 505: After receiving the first NSMF network element service message, the SMF network element sends a first subscription information acquisition request carrying the SUPI of the remote UE to the UDM network element. The first subscription information acquisition request also includes the DNN and S-NSSAI of the relay session.

[0340] Step 506: The UDM network element determines a first user plane security policy based on the SUPI of the remote UE and the user plane security policy subscribed to by the relay UE, and then sends a first subscription information acquisition response to the SMF network element, where the first subscription information acquisition response includes the first user plane security policy.

[0341] Step 507: Same as step 406. For details, please refer to the relevant description of step 406 and will not be repeated here.

[0342] Step 508: Same as step 407. For details, please refer to the relevant description of step 407 and will not be repeated here.

[0343] Step 509: Same as step 408. For details, please refer to the relevant description of step 406 and will not be repeated here.

[0344] Step 510: Same as step 410. For details, please refer to the relevant description of step 410 and will not be repeated here.

[0345] Step 511: Same as step 411. For details, please refer to the relevant description of step 411 and will not be repeated here.

[0346] Step 512: Same as step 412. For details, please refer to the relevant description of step 412 and will not be repeated here.

[0347] Step 513: Same as step 413. For details, please refer to the relevant description of step 413 and will not be repeated here.

[0348] The following is based on Figure 1 The network architecture shown in the figure takes the unified data management network element as the UDM network element, the session management network element as the SMF network element, the mobile access management network element as the AMF network element, the first terminal device as the relay UE, the second terminal device as the remote UE1, and the third terminal device as the remote UE2 as an example. Figure 2 and Figure 3 The method for determining the user plane security policy shown in the third terminal device reuses the relay session and updates the user plane security policy of the relay session to further introduce. Figure 6 As shown, a method for determining user plane security execution information provided by an embodiment of the present application includes:

[0349] Step 601: The relay UE transmits data of the remote UE1 via the relay session. The establishment method of the relay session can be referred to as Figures 2 to 5 The embodiment shown.

[0350] Step 602: The remote UE2 sends a second direct communication request to the relay UE. The second direct communication request carries the integrity protection maximum data rate of the remote UE2.

[0351] Step 603: After receiving the second direct communication request, the relay UE determines that the remote UE2 reuses the established relay session.

[0352] Step 604: The relay UE sends a second N1 message to the AMF network element. The second N1 message includes the identifier of the remote UE2 and a second N1 SM container. The second N1 SM container includes a session modification request.

[0353] It should be noted that if the encryption protection of the relay session is encryption and the integrity protection is enabled, the session modification process may not be initiated, that is, step 604 and subsequent steps do not need to be executed.

[0354] Step 604: After receiving the second N1 message, the AMF network element may send a second Nsmf service message to the SMF network element. The second Nsmf service message includes the identifier of the remote UE2 and the second N1 SM container.

[0355] Step 605: After the SMF network element receives the second NSMF network element service message, if the identifier of the remote UE2 is a temporary identifier or an anonymous identifier, the SMF network element can first obtain the SUPI of the remote UE2 from the UDM network element according to the identifier of the remote UE2.

[0356] Step 607: The SMF network element sends a second subscription information acquisition request carrying the SUPI of the remote UE2 to the UDM network element. The second subscription information acquisition request also includes the DNN and S-NSSAI of the relay session.

[0357] Step 608: The UDM network element sends a second contract information acquisition response to the SMF network element, where the second contract information acquisition response includes a second user plane security policy.

[0358] Step 609: The SMF network element determines the second user plane security execution information of the relay session according to the second user plane security policy.

[0359] For example, the SMF network element determines the second user plane security execution information of the relay session based on the first user plane security policy and the second user plane security policy. The SMF network element then compares the first user plane security execution information of the relay session with the second user plane security execution information of the relay session, and executes step 609 if they are different.

[0360] Among them, if the second user plane security policy and the first user plane security policy indicate that the integrity protection of the relay session is turned on or preferably turned on, the SMF network element can determine the second user plane security execution information of the relay session based on the maximum data rate of the integrity protection of the relay UE.

[0361] For another example, the SMF network element determines the second user plane security execution information of the relay session based on the second user plane security policy and the first user plane security execution information. The SMF network element then compares the first user plane security execution information of the relay session with the second user plane security execution information of the relay session. If they are different, step 609 is executed.

[0362] Among them, if the second user plane security policy and the first user plane security execution information indicate that integrity protection is turned on or preferably turned on, the SMF network element can determine the second user plane security execution information of the relay session based on the maximum data rate of integrity protection of the relay UE.

[0363] For another example, the SMF network element determines the second user plane security execution information of the relay session according to the second user plane security policy. The SMF network element then compares the first user plane security execution information of the relay session with the second user plane security execution information of the relay session, and executes step 609 if they are different.

[0364] Step 610: The SMF network element sends the second user plane security execution information of the relay session to the RAN. The RAN configures the second user plane security activation state of the first interface according to the second user plane security execution information of the relay session and activates the user plane security activation state of the relay session.

[0365] The RAN sends second indication information to the relay UE, where the second indication information is used to indicate a second user plane security activation state of the first interface.

[0366] Step 612: The relay UE updates the security activation status of the PC5 air interface according to the second user plane security activation status of the first interface.

[0367] Step 613: The relay UE sends a second direct security mode command to the remote UE2. The second direct security mode command includes an encryption protection indication and an integrity protection indication, indicating whether encryption protection is enabled and integrity protection is enabled respectively.

[0368] Step 614: After receiving the second direct security mode command, the remote UE configures encryption protection and integrity protection of the PC5 port according to the second direct security mode command, and sends a second direct security mode completion message to the relay UE.

[0369] Step 615: The relay UE sends a second direct communication response to the remote UE.

[0370] Based on the same inventive concept as the method embodiment, the embodiment of the present application further provides a communication device for executing the method executed by the session management network element or SMF network element in the above method embodiment. The relevant features can be found in the above method embodiment and will not be repeated here. Figure 7As shown, the device includes a receiving unit 701, a processing unit 702 and a sending unit 703:

[0371] A receiving unit 701 is configured to receive a first request, where the first request is used to request creation of a relay-type session of a first terminal device, and the first request includes first information, where the first information is used to indicate that the type of the session is a relay type;

[0372] A processing unit 702 is configured to determine first user plane security execution information of the session according to the first information;

[0373] The sending unit 703 is used to send the first user plane security execution information of the session to the access network device, where the first user plane execution information of the session is used to determine the first user plane security activation state of the session between the first terminal device and the access network device.

[0374] In a possible implementation manner, the first request includes an N1 SM container, and the N1 SM container includes the first information; the first request includes the first information and the N1 SM container.

[0375] In a possible implementation, when the processing unit 702 determines the first user plane security execution information of the session based on the first information, it can obtain the first user plane security policy based on the first information; thereafter, the first user plane security policy can be directly used as the first user plane security execution information of the session, or the first user plane security policy can be analyzed and the first user plane security execution information of the session can be determined based on the first user plane security policy.

[0376] In a possible implementation, when the processing unit 702 obtains the first user plane security policy based on the first information, the sending unit 703 may send a first contract information acquisition request to the unified data management network element; the user plane security policy subscribed to by the first terminal device indicates the user plane security policy of the relay type session of the first terminal device and the user plane security policy of the non-relay type session; thereafter, the receiving unit 701 receives a first contract information acquisition response from the unified data management network element, and the first contract information acquisition response includes the user plane security policy subscribed to by the first terminal device; the processing unit 702 then determines the user plane security policy of the relay type session of the first terminal device as the first user plane security policy based on the first information.

[0377] In a possible implementation, when the processing unit 702 obtains the first user plane security policy based on the first information, the sending unit 703 may send a first contract information acquisition request to the unified data management network element, and the first contract information acquisition request includes a relay indication; the relay indication is used to request the user plane security policy of the relay type session of the first terminal device; thereafter, the receiving unit 701 receives a first contract information acquisition response from the unified data management network element, and the first contract information acquisition response includes the user plane security policy signed by the first terminal device (including the first user plane security policy); the processing unit 702 then determines the first user plane security policy according to the user plane security policy signed by the first terminal device based on the first information.

[0378] In one possible implementation, the first information is a temporary identifier or an anonymous identifier of the second terminal device. When the processing unit 702 obtains the first user plane security policy based on the first information, the processing unit 702 may obtain the SUPI of the second terminal device based on the temporary identifier or the anonymous identifier of the second terminal device; thereafter, the sending unit 703 may send a first contract information acquisition request to the unified data management network element, where the first contract information acquisition request includes the SUPI of the second terminal device; the receiving unit 701 may receive a first contract information acquisition response from the unified data management network element, where the information carried in the first contract information acquisition response may be any of the following:

[0379] The first type is that the first signing information acquisition response includes the first user plane security policy.

[0380] Second, the first subscription information acquisition response includes the user plane security policy of the relay-type session of the first terminal device; thereafter, the processing unit 702 determines the first user plane security policy according to the user plane security policy of the relay-type session of the first terminal device.

[0381] The third type is that the first subscription information acquisition response includes the user plane security policy subscribed by the second terminal device, and then the processing unit 702 determines the first user plane security policy according to the user plane security policy subscribed by the second terminal device.

[0382] In a possible implementation, when the processing unit 702 obtains the first user plane security policy based on the first information, the sending unit 703 may send a first contract information acquisition request to the unified data management network element, and the first contract information acquisition request includes the first information; thereafter, the receiving unit 701 receives a first contract information acquisition response from the unified data management network element, and the first contract information acquisition response includes the first user plane security policy.

[0383] In a possible implementation, the first information is an identifier of the second terminal device, and the identifier of the second terminal device includes one or more of the following:

[0384] A temporary identifier of the second terminal device, an anonymous identifier of the second terminal device, or a user permanent identifier SUPI of the second terminal device.

[0385] In one possible embodiment, the first user plane security policy indicates that integrity protection is preferred. When the processing unit 702 determines the first user plane security execution information of the session according to the first user plane security policy, it can determine that integrity protection of the session is not required after determining that the maximum data rate of integrity protection of the first terminal device is less than the data rate required for the session.

[0386] In one possible implementation, if the first user plane security policy indicates that integrity protection is required, the processing unit 702 can determine whether the maximum data rate for integrity protection of the first terminal device is less than the data rate required for the session. After the processing unit 702 determines that the maximum data rate for integrity protection of the first terminal device is less than the data rate required for the session, the sending unit 703 sends a session establishment rejection response to the first terminal device to indicate the rejection of session establishment.

[0387] In a possible implementation, the receiving unit 701 may also receive a third request, where the third request is used to instruct a third terminal device to use the session, and the third request includes an identifier of the third terminal device; the processing unit 702 may determine the second user plane security execution information of the session based on the identifier of the third terminal device; the sending unit 703 may send the second user plane security execution information of the session to the access network device, where the second user plane security execution information of the session is used to determine the second user plane security activation status of the session between the first terminal device and the access network device.

[0388] In one possible implementation, when the processing unit 702 determines the second user plane security execution information of the session based on the identifier of the third terminal device, it can determine the second user plane security policy based on the identifier of the third terminal device; thereafter, it determines the second user plane security execution information of the session based on the second user plane security policy.

[0389] In a possible implementation, the identifier of the third terminal device includes one or more of the following:

[0390] A temporary identifier of the third terminal device, an anonymous identifier of the third terminal device, or a user permanent identifier SUPI of the third terminal device.

[0391] In one possible implementation, when the processing unit 702 determines the second user plane security execution information of the session based on the second user plane security policy, it may determine the second user plane security execution information of the session based on the second user plane security policy and the first user plane security execution information of the session; it may also determine the second user plane security execution information of the session based on the second user plane security policy and the first user plane security policy, or it may determine the second user plane security execution information of the session only based on the second user plane security policy.

[0392] In a possible implementation, when the processing unit 702 obtains the second user plane security policy based on the identifier of the third terminal device, the sending unit 703 can send a second contract information acquisition request to the unified data management network element, and the second contract information acquisition request includes the identifier of the third terminal device; the receiving unit 701 can receive a second contract information acquisition response from the unified data management network element, and the second contract information acquisition response includes the second user plane security policy.

[0393] In a possible implementation, when the processing unit 702 obtains the second user plane security policy based on the identifier of the third terminal device, the processing unit 702 may determine the second user plane security policy based on the identifier of the third terminal device and the user plane security policy subscribed to by the first terminal device.

[0394] In one possible implementation, when the processing unit 702 obtains the second user plane security policy based on the identifier of the third terminal device, the sending unit 703 sends a second contract information acquisition request to the unified data management network element, and the second contract information acquisition request includes the identifier of the third terminal device; the receiving unit 701 receives a second contract information acquisition response from the unified data management network element, and the second contract information acquisition response includes the user plane security policy of the relay type session of the first terminal device. The processing unit 702 determines the second user plane security policy based on the user plane security policy of the relay type session of the first terminal device.

[0395] In one possible implementation, when the processing unit 702 obtains the second user plane security policy based on the identifier of the third terminal device, the sending unit 703 sends a second contract information acquisition request to the unified data management network element, and the second contract information acquisition request includes the identifier of the third terminal device; the receiving unit 701 receives a second contract information acquisition response from the unified data management network element, and the second contract information acquisition response includes the user plane security policy signed by the third terminal device. The processing unit 702 determines the second user plane security policy based on the user plane security policy signed by the third terminal device.

[0396] In a possible implementation, before the sending unit 703 sends the second user plane security execution information of the session to the access network device, the processing unit 702 may determine that the first user plane security execution information of the session is different from the second user plane security execution information of the session.

[0397] In one possible embodiment, the second user plane security policy indicates that integrity protection of the session is preferred. When the processing unit 702 determines the second user plane security execution information of the session according to the second user plane security policy, after determining that the maximum data rate of integrity protection of the first terminal device is less than the data rate required by the session, it determines to turn off the integrity protection of the session.

[0398] Based on the same inventive concept as the method embodiment, the embodiment of the present application further provides a communication device for executing the method executed by the first terminal device or the relay UE in the above method embodiment. The relevant features can be found in the above method embodiment and will not be repeated here. Figure 8 As shown, the device includes a sending unit 801 and a receiving unit 802:

[0399] A sending unit 801 is configured to send a second request to a mobile access management network element, where the second request is used to request creation of a relay-type session, and the second request includes second information indicating that the type of the session is a relay type;

[0400] The receiving unit 802 is used to receive first indication information sent by the access network device, where the first indication information is used to indicate the first user plane security activation status of the session between the first terminal device and the access network device.

[0401] In a possible implementation, before the sending unit 801 sends the second request, the receiving unit 802 may receive a first direct communication request sent by the second terminal device, where the first direct communication request is used to establish communication with the first terminal device.

[0402] In a possible implementation manner, the second request includes an N1 SM container, and the N1 SM container includes the second information; or the second request includes the second information and the N1 SM container.

[0403] In a possible implementation, the session is used to transmit data of the second terminal device, and the second information includes one or more of the following:

[0404] The temporary identifier of the second terminal device, the anonymous identifier of the second terminal device, or the SUPI of the second terminal device.

[0405] In a possible implementation, the device further includes a processing unit 803:

[0406] The receiving unit 802 can receive a second direct communication request sent by a third terminal device, and the second direct communication request is used to establish communication with the first terminal device; thereafter, the processing unit 803 can determine whether the third terminal device uses a session based on the second direct communication request; the sending unit 801 can send a third request to the mobile access management network element, and the third request is used to instruct the third terminal device to use a session, and the third request includes an identifier of the third terminal device.

[0407] In a possible implementation, the identifier of the third terminal device includes one or more of the following:

[0408] A temporary identifier of the third terminal device, an anonymous identifier of the third terminal device, or a SUPI of the third terminal device.

[0409] In a possible implementation, after the receiving unit 802 receives the first indication information indicating the security activation status of the first user plane from the access network device, the processing unit 803 can determine the security activation status of the first terminal device and the second terminal device based on the first user plane security activation status of the access network device.

[0410] In one possible implementation, if integrity protection is required in the security activation state of the first user plane, when the processing unit 803 configures the security activation state of the first terminal device and the second terminal device according to the security activation state of the first user plane, it can determine whether to enable integrity protection between the first terminal device and the second terminal device based on the integrity protection maximum data rate or QoS control information of the second terminal device.

[0411] In a possible implementation, if integrity protection is not required in the first user plane security activation state, the sending unit 801 may send a direct communication rejection message to the second terminal device if the user plane security policy of the second terminal device indicates that integrity protection is required.

[0412] In a possible implementation manner, the receiving unit 802 may further receive second indication information sent by the access network device, where the second indication information is used for a second user plane security activation state of the session between the first terminal device and the access network device;

[0413] The processing unit 803 may update the first user plane security activation state to the second user plane security activation state according to the second indication information.

[0414] In a possible implementation, after the receiving unit 802 receives the second indication information from the access network device, the processing unit 803 may update the security activation status of the first terminal device and the second terminal device according to the second user plane security activation status.

[0415] In one possible embodiment, integrity protection is required in the second user plane security activation state. When the processing unit 803 updates the security activation state of the first terminal device and the second terminal device according to the second user plane security activation state, it can determine whether to enable integrity protection between the first terminal device and the second terminal device based on the integrity protection maximum data rate or QoS control information of the third terminal device.

[0416] Based on the same inventive concept as the method embodiment, the embodiment of the present application also provides a communication device for executing the method executed by the mobile access management network element or the AMF network element in the above method embodiment. The relevant features can be found in the above method embodiment and will not be repeated here. Figure 9 As shown, the device includes a receiving unit 901 and a sending unit 902:

[0417] A receiving unit 901 is configured to receive a second request sent by a first terminal device, where the second request includes second information, the second request is used to request creation of a relay-type session of the first terminal device, and the second information is used to indicate that the type of the session is a relay type;

[0418] The sending unit 902 is used to send a first request to the session management network element according to the second request. The first request includes first information. The first information is used to indicate that the type of the session is a relay type. The first request is used to request the creation of a relay type session of the first terminal device.

[0419] In a possible implementation manner, the second information is the same as the first information, the first request and the second request include an N1 SM container, and the N1 SM container includes the second information.

[0420] In a possible implementation manner, the second request includes the second information and an N1 SM container; the first request includes the first information and an N1 SM container.

[0421] In one possible implementation, the apparatus includes a processing unit 903, which can determine, based on the second information, that the first terminal device is authorized to establish a session. After the processing unit 903 determines, based on the second information, that the first terminal device is authorized to establish a session, the sending unit 902 sends a first request to the session management network element.

[0422] In a possible implementation, the second information is a temporary identifier or an anonymous identifier of the second terminal device, and the first information is the SUPI of the second terminal device.

[0423] In one possible implementation, the second information includes one or more of the following:

[0424] The temporary identifier of the second terminal device, the anonymized identifier of the second terminal device, and the SUPI of the second terminal device.

[0425] In a possible implementation, before the sending unit 902 sends the first request to the session management network element according to the second request, the processing unit 903 may determine, according to the second information, that the first terminal device authorizes establishing a session for the second terminal device.

[0426] Based on the same inventive concept as the method embodiment, the embodiment of the present application further provides a communication device for executing the method executed by the unified data management network element or UDM network element in the above method embodiment. The relevant features can be found in the above method embodiment and will not be repeated here. Figure 10 As shown, the device includes a receiving unit 1001, a processing unit 1002 and a sending unit 1003:

[0427] A receiving unit 1001 is configured to receive a first subscription information acquisition request from a session management network element, where the first subscription information acquisition request is used to request a user plane security policy subscribed to by a first terminal device, and the first subscription information acquisition request includes first information, where the first information is used to indicate that the type of the session is a relay type;

[0428] The processing unit 1002 is configured to determine a first user plane security policy according to the first information;

[0429] The sending unit 1003 is configured to send a first subscription information acquisition response to the session management network element, where the first subscription information acquisition response includes a first user plane security policy.

[0430] In a possible implementation, when the processing unit 1002 determines the first user plane security policy based on the first information, the first user plane security policy may be determined based on the first information and the user plane security policy subscribed by the first terminal device, where the user plane security policy subscribed by the first terminal device indicates a user plane security policy for a relay type and a non-relay type session of the first terminal device;

[0431] In one possible implementation, the first information is an identifier of the second terminal device. When the processing unit 1002 determines the first user plane security policy based on the first information, the processing unit 1002 determines the first user plane security policy from the user plane security policy subscribed to by the second terminal device based on the identifier of the second terminal device.

[0432] In a possible implementation, the receiving unit 1001 may receive a second subscription information acquisition request from a session management network element, where the second subscription information acquisition request includes an identifier of the third terminal device.

[0433] The processing unit 1002 may determine the second user plane security policy according to the identifier of the third terminal device.

[0434] The sending unit 1003 can send a second subscription information acquisition response to the session management network element, where the second subscription information acquisition response includes a second user plane security policy.

[0435] In a possible implementation, the identifier of the third terminal device includes one or more of the following:

[0436] A temporary identifier of the third terminal device, an anonymous identifier of the third terminal device, or a user permanent identifier SUPI of the third terminal device.

[0437] Based on the same inventive concept as the method embodiment, the embodiment of the present application further provides a communication device for executing the method executed by the unified data management network element or UDM network element in the above method embodiment. The relevant features can be found in the above method embodiment and will not be repeated here. Figure 11 As shown, the device includes a receiving unit 1101 or a sending unit 1102:

[0438] A receiving unit 1101 is configured to receive a first subscription information acquisition request from a session management network element, where the first subscription information acquisition request is used to request a user plane security policy subscribed to by a first terminal device, where the user plane security policy subscribed to by the first terminal device indicates a user plane security policy for a relay-type session of the first terminal device and a user plane security policy for a non-relay-type session of the first terminal device;

[0439] The sending unit 1102 is used to send a first contract information acquisition response to the session management network element, where the first contract information acquisition response includes the user plane security policy subscribed to by the first terminal device.

[0440] In a possible implementation, the apparatus further includes a processing unit 1103:

[0441] The receiving unit 1101 may receive a second subscription information acquisition request from a session management network element, where the second subscription information acquisition request includes an identifier of a third terminal device, and the processing unit 1103 may determine a second user plane security policy based on the identifier of the third terminal device.

[0442] The sending unit 1102 can send a second subscription information acquisition response to the session management network element, where the second subscription information acquisition response includes a second user plane security policy.

[0443] The division of units in the embodiments of the present application is illustrative and is merely a logical functional division. In actual implementation, other division methods may be used. Furthermore, the functional units in the various embodiments of the present application may be integrated into a single processor, or may exist physically separately, or two or more units may be integrated into a single module. The aforementioned integrated units may be implemented in the form of hardware or software functional modules.

[0444] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium, including a number of instructions for enabling a terminal device (which can be a personal computer, mobile phone, or network device, etc.) or a processor to execute all or part of the steps of the method of each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), magnetic disk or optical disk, etc., various media that can store program code.

[0445] In the embodiments of the present application, the unified data management network element, the session management network element, the mobile access management network element, and the first terminal device can all be integrated and presented in the form of functional modules. "Module" herein can refer to a specific ASIC, circuit, processor and memory executing one or more software or firmware programs, integrated logic circuit, and / or other device capable of providing the aforementioned functions.

[0446] In a simple embodiment, those skilled in the art can imagine that the unified data management network element, the session management network element and the mobile access management network element can all adopt Figure 12 The form shown.

[0447] like Figure 12 The communication device 1200 shown includes at least one processor 1201 , a memory 1202 , and optionally, a communication interface 1203 .

[0448] The memory 1202 may be a volatile memory, such as a random access memory (RAM); a non-volatile memory, such as a read-only memory (ROM), a flash memory, a hard disk drive (HDD), or a solid-state drive (SSD); or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but is not limited thereto. The memory 1202 may be a combination of the aforementioned memories.

[0449] The specific connection medium between the processor 1201 and the memory 1202 is not limited in the embodiment of the present application. In the figure, the memory 1202 and the processor 1201 are connected via a bus 1204. The bus 1204 is represented by a thick line in the figure. The connection between other components is only for schematic illustration and is not limited. The bus 1204 can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 12 Only one thick line is used in the diagram, but this does not mean that there is only one bus or one type of bus.

[0450] The processor 1201 may have a data transceiver function and may communicate with other devices. Figure 12 An independent data transceiver module, such as a communication interface 1203 , may also be provided in the device for transmitting and receiving data. When the processor 1201 communicates with other devices, data may be transmitted through the communication interface 1203 .

[0451] When the session management network element adopts Figure 12 When the form shown is Figure 12 The processor 1201 in the embodiment can call the computer execution instructions stored in the memory 1202, so that the session management network element can execute the method executed by the session management network element or SMF network element in any of the above method embodiments.

[0452] Specifically, Figure 7 The functions / implementation processes of the sending unit, receiving unit and processing unit can be achieved through Figure 12 The processor 1201 in the embodiment calls the computer execution instruction stored in the memory 1202 to implement. Or, Figure 7 The function / implementation process of the processing unit in Figure 12 The processor 1201 in the memory 1202 calls the computer execution instruction stored in the memory 1202 to implement, Figure 7 The functions / implementation process of the sending unit and the receiving unit in Figure 12 It is implemented by the communication interface 1203 in.

[0453] When the mobile access management network element adopts Figure 12 When the form shown is Figure 12 The processor 1201 in the memory 1202 can call the computer execution instructions stored in the memory 1202, so that the mobile access management network element can execute the method executed by the mobile access management network element or the AMF network element in any of the above method embodiments.

[0454] Specifically, Figure 9 The functions / implementation processes of the receiving unit, sending unit and processing unit can be achieved through Figure 12The processor 1201 in the embodiment calls the computer execution instruction stored in the memory 1202 to implement. Or, Figure 9 The function / implementation process of the processing unit in Figure 12 The processor 1201 in the memory 1202 calls the computer execution instruction stored in the memory 1202 to implement, Figure 9 The functions / implementation process of the receiving unit and the sending unit can be achieved through Figure 12 It is implemented by the communication interface 1203 in.

[0455] When the unified data management network element adopts Figure 12 When the form shown is Figure 12 The processor 1201 in the embodiment can call the computer execution instructions stored in the memory 1202, so that the unified data management network element can execute the method executed by the unified data management network element or UDM network element in any of the above method embodiments.

[0456] Specifically, Figure 10 The functions / implementation processes of the sending unit, receiving unit and processing unit in 11 can be realized by Figure 12 The processor 1201 in the embodiment calls the computer execution instruction stored in the memory 1202 to implement. Or, Figure 10 Or the function / implementation process of the processing unit in 11 can be achieved by Figure 12 The processor 1201 in the memory 1202 calls the computer execution instruction stored in the memory 1202 to implement, Figure 10 Or the functions / implementation process of the sending unit and the receiving unit in 11 can be achieved by Figure 12 It is implemented by the communication interface 1203 in.

[0457] In a simple embodiment, those skilled in the art can imagine that the first terminal device can use Figure 13 The form shown.

[0458] like Figure 13 The communication device 1300 shown includes at least one processor 1301 , a memory 1302 , and optionally, a transceiver 1303 .

[0459] The processor 1301 and the memory 1302 are similar to the processor 1201 and the memory 1202 . For details, please refer to the above content and will not be repeated here.

[0460] The specific connection medium between the processor 1301 and the memory 1302 is not limited in the embodiment of the present application. In the figure, the memory 1302 and the processor 1301 are connected via a bus 1304. The bus 1304 is represented by a thick line in the figure. The connection between other components is only for schematic illustration and is not limited. The bus 1304 can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 13 Only one thick line is used in the diagram, but this does not mean that there is only one bus or one type of bus.

[0461] The processor 1301 may have a data transceiver function and may communicate with other devices. Figure 13 An independent data transceiver module, such as a transceiver 1303 , may also be provided in the device for transmitting and receiving data. When the processor 1301 communicates with other devices, data may be transmitted via the transceiver 1303 .

[0462] When the first terminal device adopts Figure 13 When the form shown is Figure 13 The processor 1301 in the memory 1302 can call the computer execution instructions stored in the memory 1302, so that the first terminal device can execute the method executed by the first terminal device or relay UE in any of the above method embodiments.

[0463] Specifically, Figure 8 The functions / implementation processes of the sending unit, receiving unit and processing unit can be achieved through Figure 13 The processor 1301 in the embodiment calls the computer execution instruction stored in the memory 1302 to implement. Or, Figure 8 The function / implementation process of the processing unit in Figure 13 The processor 1301 in the embodiment calls the computer execution instruction stored in the memory 1302 to implement the above. Figure 8 The functions / implementation process of the sending unit and the receiving unit in Figure 13 This is achieved by the transceiver 1303 in .

[0464] In this method: It will be understood by those skilled in the art that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0465] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0466] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0467] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0468] Obviously, those skilled in the art may make various changes and modifications to the present application without departing from the scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application is intended to include such modifications and variations.

Claims

1. A method for determining user plane security execution information, characterized in that: The method comprises: The session management network element receives a first request, where the first request is used to request creation of a relay-type session of a first terminal device, and the first request includes first information, where the first information is used to indicate that the type of the session is a relay type; The session management network element determines first user plane security execution information of the session according to the first information; The session management network element sends the first user plane security execution information of the session to the access network device, and the first user plane execution information of the session is used to determine the first user plane security activation status of the session between the first terminal device and the access network device.

2. The method according to claim 1, wherein The first request includes an N1 SM container, and the N1 SM container includes the first information; or The first request includes first information and an N1 SM container.

3. The method according to claim 1 or 2, wherein: The session management network element determines, according to the first information, first user plane security execution information of the session, including: The session management network element obtains a first user plane security policy according to the first information; The session management network element determines first user plane security execution information of the session according to the first user plane security policy.

4. The method according to claim 3, wherein The session management network element obtains a first user plane security policy according to the first information, including: The session management network element sends a first contract information acquisition request to the unified data management network element; The session management network element receives a first subscription information acquisition response from the unified data management network element, where the first subscription information acquisition response includes a user plane security policy subscribed to by the first terminal device; the user plane security policy subscribed to by the first terminal device includes: a user plane security policy for a relay-type session of the first terminal device and a user plane security policy for a non-relay-type session of the first terminal device; The session management network element determines the user plane security policy of the session of the first terminal device relay type as the first user plane security policy based on the first information.

5. The method according to claim 3, wherein The session management network element obtains a first user plane security policy according to the first information, including: The session management network element sends a first subscription information acquisition request to the unified data management network element; the first subscription information acquisition request includes a relay indication; the relay indication is used to request a user plane security policy for a relay-type session of the first terminal device; The session management network element receives a first subscription information acquisition response from the unified data management network element, where the first subscription information acquisition response includes the user plane security policy subscribed to by the first terminal device; the user plane security policy subscribed to by the first terminal device includes the first user plane security policy.

6. The method according to any one of claims 1, 2, 4 and 5, wherein: The first information is an identifier of the second terminal device, and the identifier of the second terminal device includes one or more of the following: The temporary identifier of the second terminal device, the anonymous identifier of the second terminal device, or the user permanent identifier SUPI of the second terminal device.

7. The method according to any one of claims 1, 2, 4 and 5, wherein: The method further comprises: The session management network element receives a third request, where the third request is used to instruct a third terminal device to use the session, and the third request includes an identifier of the third terminal device; The session management network element determines the second user plane security execution information of the session according to the identifier of the third terminal device; The session management network element sends the second user plane security execution information of the session to the access network device, and the second user plane security execution information of the session is used to determine the second user plane security activation status of the session between the first terminal device and the access network device.

8. The method according to claim 7, wherein Before the session management network element sends the second user plane security execution information of the session to the access network device, the method further includes: The session management network element determines that the first user plane security execution information of the session is different from the second user plane security execution information of the session.

9. A method for determining user plane security execution information, characterized in that: The method is applied to a first terminal device or a chip located in the first terminal device, and the method includes: Sending a second request to a mobile access management network element, where the second request is used to request creation of a relay-type session, and the second request includes second information, where the second information indicates that the type of the session is a relay type; Receive first indication information from an access network device, where the first indication information is used to indicate a first user plane security activation status of the session between the first terminal device and the access network device, where the first user plane security activation status is the user plane security activation status of the session when the first terminal device is allowed to act as a relay device.

10. The method according to claim 9, wherein The second request includes an N1 SM container, and the N1 SM container includes the second information; or the second request includes the second information and the N1 SM container.

11. The method according to claim 9 or 10, wherein: The method further comprises: The session is used to transmit data of the second terminal device, and the second information includes one or more of the following: The temporary identifier of the second terminal device, the anonymous identifier of the second terminal device, or the user permanent identifier SUPI of the second terminal device.

12. The method according to any one of claims 9 to 10, wherein: The method comprises: receiving a second direct communication request sent by a third terminal device, where the second direct communication request is used to establish communication with the first terminal device; determining, according to the second direct communication request, that the third terminal device use the session; A third request is sent to the mobile access management network element, where the third request is used to instruct the third terminal device to use the session, and the third request includes an identifier of the third terminal device.

13. The method according to claim 12, wherein: The identifier of the third terminal device includes one or more of the following: The temporary identifier of the third terminal device, the anonymous identifier of the third terminal device, or the user permanent identifier SUPI of the third terminal device.

14. The method according to any one of claims 9 to 10 and 13, wherein: After receiving the first indication information from the access network device, the method further includes: The security activation status of the first terminal device and the second terminal device is determined according to the security activation status of the first user plane.

15. The method according to any one of claims 9 to 10 and 13, wherein: The method further comprises: Receiving second indication information sent by an access network device, where the second indication information is used to indicate a second user plane security activation state of the session between the first terminal device and the access network device; The first user plane security activation state is updated to a second user plane security activation state according to the second indication information.

16. A method for determining user plane security execution information, characterized in that: The method comprises: The mobile access management network element receives a second request sent by the first terminal device, where the second request includes second information, where the second request is used to request creation of a relay-type session of the first terminal device, and the second information is used to indicate that the type of the session is a relay type; After the authorization check of the first terminal device is passed, the mobile access management network element sends a first request to the session management network element according to the second request, and the first request includes first information, and the first information is used to indicate that the type of the session is a relay type, and the first request is used to request the creation of a relay type session of the first terminal device.

17. The method according to claim 16, wherein The second information is the same as the first information. The first request and the second request include an N1 SM container, and the N1 SM container includes the second information.

18. The method according to claim 16, wherein The second request includes the second information and the N1 SM container; the first request includes the first information and the N1 SM container.

19. The method according to any one of claims 16 to 18, wherein: The mobile access management network element sends a first request to the session management network element according to the second information, including: After determining, based on the second information, that the first terminal device authorizes establishment of the session, the mobile access management network element sends the first request to the session management network element.

20. The method according to any one of claims 16 to 18, wherein: The second information includes one or more of the following: The temporary identifier of the second terminal device, the anonymized identifier of the second terminal device, and the user permanent identifier SUPI of the second terminal device.

21. A communication system, characterized in that: The communication system includes a session management network element and a unified data management network element; The session management network element is configured to send a first subscription information acquisition request to the unified data management network element; the first subscription information acquisition request includes a relay indication, and the relay indication is used to request a user plane security policy for a session of a relay type of the first terminal device; The unified data management network element is configured to receive the first contract information acquisition request, determine a first user plane security policy from user plane security policies subscribed to by the first terminal device according to the first contract information acquisition request, the user plane security policy subscribed to by the first terminal device including user plane security policies for relay type and non-relay type sessions of the first terminal device; and send a first contract information acquisition response to the session management network element, the first contract information acquisition response including the first user plane security policy; The session management network element is also used to receive the first signing information acquisition response.

22. The system of claim 21, wherein: The system further includes a mobile access management network element: The mobile access management network element is configured to send a first request to the session management network element, where the first request is used to request establishment of a relay-type session for the first terminal device, and the first request includes first information, where the first information is used to indicate that the type of the session is a relay type; The session management network element is configured to receive the first request, and the relay indication is the first information or is determined based on the first information.

23. The system of claim 22, wherein: The session is used to transmit data of the second terminal device, and the first information is an identifier of the second terminal device. The identifier of the second terminal device includes one or more of the following: The temporary identifier of the second terminal device, the anonymous identifier of the second terminal device, or the user permanent identifier SUPI of the second terminal device.

24. The system according to any one of claims 21 to 23, wherein: The system further includes an access network device, The session management network element is further configured to, after determining the first user plane security execution information of the session according to the first user plane security policy, send the first user plane security execution information of the session to the access network device; The access network device is used to receive the first user plane security execution information of the session, and activate the first user plane security activation state of the session between the first terminal device and the access network device according to the first user plane security execution information of the session.

25. The system of claim 24, wherein: The system further includes a first terminal device; The access network device is further used to send a first indication message to the first terminal device, where the first indication message is used to indicate a first user plane security activation state of the session between the first terminal device and the access network device in the session; The first terminal device is configured to receive the first indication message and configure the first user plane security activation state according to the first indication message; And configure the security activation status of the first terminal device and the second terminal device according to the security activation status of the first user plane.

26. The system according to any one of claims 21 to 23, wherein: The first terminal device is further configured to, after determining that a third terminal device uses the session, send a second request to the session management network element, where the second request instructs the third terminal device to use the session, and the second request includes an identifier of the third terminal device; The session management network element is further configured to obtain a second user plane security policy according to the identifier of the third terminal device; and after determining the second user plane security execution information of the session according to the second user plane security policy, sending the second user plane security execution information of the session to the access network device; The access network device is further configured to receive second user plane security execution information of the session, and update the first user plane security activation state of the session to a second user plane security activation state according to the second user plane security execution information of the session.

27. The system of claim 25, wherein: The first terminal device is further configured to, after determining that a third terminal device uses the session, send a second request to the session management network element, where the second request instructs the third terminal device to use the session, and the second request includes an identifier of the third terminal device; The session management network element is further configured to obtain a second user plane security policy according to the identifier of the third terminal device; and after determining the second user plane security execution information of the session according to the second user plane security policy, sending the second user plane security execution information of the session to the access network device; The access network device is further configured to receive second user plane security execution information of the session, and update the first user plane security activation state to a second user plane security activation state according to the second user plane security execution information of the session.

28. The system of claim 26, wherein: The access network device is further used to send a second indication message to the first terminal device, where the second indication message is used to indicate a second user plane security activation state of the session between the first terminal device and the access network device in the session; The first terminal device is configured to receive the second indication message, and update the first user plane security activation state with the access network device according to the second indication message; And update the security activation status of the first terminal device and the second terminal device according to the security activation status of the second user plane.

29. The system of claim 25, wherein: Before the session management network element sends the second user plane security execution information of the session to the access network device, the session management network element is further configured to: It is determined that the first user plane security enforcement information of the session is different from the second user plane security enforcement information of the session.

30. A communication device, characterized in that: The communication device comprises: A receiving unit, configured to receive a first request, where the first request is used to request creation of a relay-type session of a first terminal device, the first request including first information, where the first information is used to indicate that the type of the session is a relay type; a processing unit, configured to determine first user plane security execution information of the session based on the first information; A sending unit is used to send the first user plane security execution information of the session to the access network device, where the first user plane execution information of the session is used to determine the first user plane security activation status of the session between the first terminal device and the access network device.

31. The device according to claim 30, wherein The first request includes an N1 SM container, and the N1 SM container includes the first information; or The first request includes first information and an N1 SM container.

32. The device according to claim 30 or 31, characterized in that The processing unit is configured to: Acquire a first user plane security policy according to the first information; Determine first user plane security execution information for the session according to the first user plane security policy.

33. The device according to claim 32, wherein The sending unit is further configured to send a first contract information acquisition request to the unified data management network element; The receiving unit is further configured to receive a first subscription information acquisition response from the unified data management network element, where the first subscription information acquisition response includes a user plane security policy subscribed to by the first terminal device; The user plane security policy subscribed by the first terminal device includes: a user plane security policy for a relay-type session of the first terminal device and a user plane security policy for a non-relay-type session; The processing unit is configured to determine, based on the first information, a user plane security policy for a session of the relay type of the first terminal device as the first user plane security policy.

34. The device according to claim 32, wherein The sending unit is further used to send a first subscription information acquisition request to the unified data management network element; the first subscription information acquisition request includes a relay indication; the relay indication is used to request a user plane security policy for a session of the relay type of the first terminal device; The receiving unit is further used to receive a first contract information acquisition response from the unified data management network element, wherein the first contract information acquisition response includes the user plane security policy subscribed by the first terminal device; the user plane security policy subscribed by the first terminal device includes the first user plane security policy.

35. The device according to any one of claims 30, 31, 33 and 34, characterized in that: The first information is an identifier of the second terminal device, and the identifier of the second terminal device includes one or more of the following: The temporary identifier of the second terminal device, the anonymous identifier of the second terminal device, or the user permanent identifier SUPI of the second terminal device.

36. The device according to any one of claims 30, 31, 33 and 34, characterized in that The receiving unit is further configured to receive a third request, where the third request is used to instruct a third terminal device to use the session, and the third request includes an identifier of the third terminal device; The processing unit is further configured to determine the second user plane security execution information of the session according to the identifier of the third terminal device; The sending unit is also used to send the second user plane security execution information of the session to the access network device, and the second user plane security execution information of the session is used to determine the second user plane security activation status of the session between the first terminal device and the access network device.

37. The device according to claim 36, wherein The processing unit is further configured to: before the sending unit sends the second user plane security execution information of the session to the access network device: It is determined that the first user plane security enforcement information of the session is different from the second user plane security enforcement information of the session.

38. A communication device, characterized in that: The device comprises: a sending unit, configured to send a second request to a mobile access management network element, where the second request is used to request creation of a relay-type session, the second request including second information, where the second information indicates that the type of the session is a relay type; A receiving unit is used to receive first indication information from an access network device, where the first indication information is used to indicate a first user plane security activation status of the session between a first terminal device and the access network device, where the first user plane security activation status is the user plane security activation status of the session when the first terminal device is allowed to act as a relay device.

39. The device according to claim 38, wherein The second request includes an N1 SM container, and the N1 SM container includes the second information; or the second request includes the second information and the N1 SM container.

40. The device according to claim 38 or 39, characterized in that The session is used to transmit data of the second terminal device, and the second information includes one or more of the following: The temporary identifier of the second terminal device, the anonymous identifier of the second terminal device, or the user permanent identifier SUPI of the second terminal device.

41. The device according to any one of claims 38 to 39, wherein: The device further comprises a processing unit; The receiving unit is further configured to receive a second direct communication request sent by a third terminal device, where the second direct communication request is used to establish communication with the first terminal device; The processing unit in the apparatus is configured to determine, based on the second direct communication request, that the third terminal device use the session; The sending unit is further used to send a third request to the mobile access management network element, where the third request is used to instruct the third terminal device to use the session, and the third request includes an identifier of the third terminal device.

42. The device according to claim 41, wherein The identifier of the third terminal device includes one or more of the following: The temporary identifier of the third terminal device, the anonymous identifier of the third terminal device, or the user permanent identifier SUPI of the third terminal device.

43. The device according to any one of claims 38 to 39 and 42, wherein: The processing unit in the apparatus is further configured to: after the receiving unit receives the first use indication information from the access network device, The security activation status of the first terminal device and the second terminal device is determined according to the security activation status of the first user plane.

44. The device according to any one of claims 38 to 39 and 42, wherein: The receiving unit is further configured to receive second indication information sent by an access network device, where the second indication information is used to indicate a second user plane security activation state of the session between the first terminal device and the access network device; The processing unit in the device is further configured to update the first user plane security activation state to a second user plane security activation state according to the second indication information.

45. A communication device, characterized in that The device comprises: A receiving unit, configured to receive a second request sent by a first terminal device, where the second request includes second information, where the second request is used to request creation of a relay-type session of the first terminal device, and the second information is used to indicate that the type of the session is a relay type; A sending unit is used to send a first request to the session management network element according to the second request, the first request includes first information, the first information is used to indicate that the type of the session is a relay type, and the first request is used to request the creation of a relay type session of the first terminal device.

46. ​​The device according to claim 45, wherein The second information is the same as the first information. The first request and the second request include an N1 SM container, and the N1 SM container includes the second information.

47. The device according to claim 45, wherein The second request includes the second information and the N1 SM container; the first request includes the first information and the N1 SM container.

48. The device according to any one of claims 45 to 47, wherein: The communication device further includes a processing unit, wherein the processing unit is configured to: Determine, based on the second information, that the first terminal device authorizes the establishment of the session A sending unit is used to: after the processing unit determines that the first terminal device authorizes to establish the session based on the second information, send the first request to the session management network element.

49. The device according to any one of claims 45 to 47, wherein: The second information includes one or more of the following: The temporary identifier of the second terminal device, the anonymized identifier of the second terminal device, and the user permanent identifier SUPI of the second terminal device.

50. A communication device, characterized in that The device comprises a processor and a memory, wherein the memory stores instructions, and when the processor executes the instructions, the device executes the method according to any one of claims 1 to 8.

51. A communication device, characterized in that The device comprises a processor and a memory, wherein the memory stores instructions, and when the processor executes the instructions, the device executes the method according to any one of claims 9 to 15.

52. A communication device, characterized in that The device comprises a processor and a memory, wherein the memory stores instructions, and when the processor executes the instructions, the device executes the method according to any one of claims 16 to 20.

Citation Information

Patent Citations

  • Session connection establishment method, apparatus and system

    CN104521211A

  • Management system, transmission system, management method, and computer-readable recording medium

    US20160156684A1