A user plane central unit security processing method and related apparatus
By sending security policies and protection methods during CU-UP handover via CU-CP, the problem of inconsistent security protection methods during CU-UP handover is solved, thereby improving the security and stability of communication.
Patent Information
- Application Number
- CN202010745071.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-07-29
- Publication Date
- 2026-01-09
- Estimated Expiration
- 2040-07-29
AI Technical Summary
During the handover process of the User Plane Central Unit (CU-UP), how to determine the security protection method between the terminal equipment and the target CU-UP to ensure communication security?
The management plane centralized unit CU-CP sends the security policy to the source CU-UP and receives the security protection method determined by it. It then determines whether the security protection method is consistent with that of the target CU-UP. If they are inconsistent, it notifies the terminal equipment and core network equipment to update the security protection method.
This ensures the security and stability of communication for terminal devices during CU-UP handover, avoiding conflicts and inconsistencies in security protection methods.
Smart Images

Figure CN114095917B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of communication technology, and in particular to a user plane centralized unit security processing method and related apparatus. BACKGROUND
[0002] In a wireless communication system, a terminal device, also referred to as a user equipment (UE), and an access network device transmit various data over radio bearers (RBs) on uplink and downlink according to various protocol layers formulated by the 3rd Generation Partnership Project (3GPP), such as transmitting control signaling over a signaling radio bearer or transmitting service data over a data radio bearer. The protocol layers include a physical (PHY) layer, a media access control (MAC) layer, a radio link control (RLC) layer, a packet data convergence protocol (PDCP) layer, and a radio resource control (RRC) layer, etc. The access network device (e.g., a gNB) can be further divided into a centralized unit (CU) and a distributed unit (DU) according to an architecture, and the CU and the DU include a control plane connection and a user plane connection (also referred to as a user plane tunnel (UP tunnel)). A user plane tunnel is determined by an uplink tunnel endpoint on the CU and a downlink tunnel endpoint on the DU. The CU is used to implement the functions of the PDCP layer and the functions of the RRC layer, and the DU is used to implement the functions of the PHY layer, the functions of the MAC layer, and the functions of the RLC layer.
[0003] The CU can be further split into a control plane central unit (CU-CP) and a user plane central unit (CU-UP) two logical functions. The user equipment (UE), also known as terminal equipment, performs protection of the PDCP with the CU-UP. After the Session Management Function (SMF) determines the security policy, the security policy is sent to the access network device through the Access and Mobility Management Function (AMF). The CU-UP (and the UE) determines the corresponding security protection mode according to the security policy.
[0004] With the evolution of communication technology, in the scenario of CU-UP and CU-CP, a new handover mechanism is introduced. The CU-UP changes while the CU-CP does not change, that is, the user plane processing node is switched from the source CU-UP to the target CU-UP. Then, how to determine the security protection mode between the UE and the target CU-UP during the handover process is a problem that needs to be solved urgently. SUMMARY
[0005] Embodiments of the present application provide a user plane central unit security processing method to improve the security of communication in the scenario of switching of a terminal device from a first user plane central unit (CU-UP) to a second CU-UP.
[0006] In a first aspect, embodiments of the present application provide a user plane central unit security processing method applied to a management plane central unit (CU-CP), comprising:
[0007] The management plane central unit (CU-CP) sends a first security policy to a first user plane central unit (CU-UP);
[0008] The CU-CP receives a first security protection mode sent by the first CU-UP, and the first security protection mode is a security protection mode determined by the first CU-UP;
[0009] The CU-CP determines whether the first security protection mode is consistent with a second security protection mode, wherein the second security protection mode is a security protection mode used by a terminal device and a second CU-UP for data protection;
[0010] When the CU-CP determines that the first security protection mode is not consistent with the second security protection mode,
[0011] The CU-CP sends the first security protection mode to the terminal device, where the first security protection mode is a security protection mode used by the terminal device for data protection with the first CU-UP.
[0012] Specifically, the UE initiates an access request to an access network device, where the access network device includes a distributed unit (DU) and a centralized unit (CU). Specifically, the UE sends a radio resource control reconnection (RRC Setup Request) message to the DU. Based on the RRC reconnection message, the UE and the network device (including the access network device and the core network device) complete the related procedures of accessing the network, the UE establishes a connection of a control plane with the CU-CP, and establishes a connection of a user plane with the second CU-UP.
[0013] Specifically, the UE initiates an access request to an access network device, where the access network device includes a distributed unit (DU) and a centralized unit (CU). Specifically, the UE sends a radio resource control reconnection (RRC Setup Request) message to the DU. Based on the RRC reconnection message, the UE and the network device (including the access network device and the core network device) complete the related procedures of accessing the network, the UE establishes a connection of a control plane with the CU-CP, and establishes a connection of a user plane with the second CU-UP.
[0014] When the CU-CP determines that the switching of the CU-UP needs to be initiated, the management plane centralized unit (CU-CP) sends a first security policy to the first user plane centralized unit (CU-UP). Specifically, the CU-CP sends the first security policy to the first CU-UP through a bearer context setup request (BEARER CONTEXT SETUP REQUEST) message. Optionally, the bearer context setup request message can also carry an identifier of the first session and / or the second security protection mode.
[0015] After the CU-UP receives the first security policy from the CU-CP, the CU-UP determines a first security protection mode selected by itself according to the first security policy and its own capability. When the first CU-UP determines the first security protection mode, the first CU-UP sends the first security protection mode to the CU-CP. In a possible implementation manner, the first CU-UP sends the first security protection mode to the CU-CP through a bearer context setup response (BEARER CONTEXT SETUP Response) message, and the bearer context setup response message can also carry an identifier of the first session. Optionally, the first CU-UP also allocates an identifier of a corresponding bearer to the identifier of the first session, and sends the identifier of the corresponding bearer to the CU-CP.
[0016] The CU-CP determines whether the first security protection manner is consistent with the second security protection manner. For example, when the first security protection manner is to perform confidentiality protection and the second security protection manner is not to perform confidentiality protection, the CU-CP determines that the first security protection manner is inconsistent with the second security protection manner. When the first security protection manner is not to perform confidentiality protection and the second security protection manner is to perform confidentiality protection, the CU-CP determines that the first security protection manner is inconsistent with the second security protection manner. Similarly, when the first security protection manner is to perform integrity protection and the second security protection manner is not to perform integrity protection, the CU-CP determines that the first security protection manner is inconsistent with the second security protection manner. When the first security protection manner is not to perform integrity protection and the second security protection manner is to perform integrity protection, the CU-CP determines that the first security protection manner is inconsistent with the second security protection manner.
[0017] When the CU-CP determines that the first security protection manner is inconsistent with the second security protection manner, the CU-CP sends the first security protection manner to the UE. The purpose is to inform the UE to perform the first security protection manner. In an optional implementation, the CU-CP sends user plane measurement change indication information to the terminal device, and the user plane measurement change indication information includes the first security protection manner. Optionally, the user plane measurement change indication information also carries an identifier of the first session. Specifically, the CU-CP sends the user plane measurement change indication information to the UE through an RRC reconfiguration message.
[0018] In the embodiments of the present application, when the security protection manner of the UE and the first CU-UP is inconsistent, the CU-CP can inform the UE of the first security protection manner performed by the first CU-UP, so that the UE performs the first security protection manner performed by the first CU-UP. This ensures that subsequent data between the UE and the first CU-UP can be normally interacted under the protection of the first security protection manner, thereby improving the security of communication.
[0019] With reference to the first aspect, in a possible implementation of the first aspect, after the CU-CP receives the first security protection manner sent by the first CU-UP, the CU-CP further includes:
[0020] If the first security protection manner and the second security protection manner are different, the CU-CP informs a session management function (SMF) that the first CU-UP uses the first security protection manner.
[0021] Alternatively,
[0022] If the first security protection mode and the second security protection mode are different, the CU-CP informs the SMF that protection of the first session cannot be performed, the first session being a session of the terminal device and the second CU-UP using the second security protection mode for data protection.
[0023] Specifically, when the CU-CP determines that the first security protection mode and the second security protection mode are inconsistent, the CU-CP can inform the SMF that the first session uses the first security protection mode.
[0024] In an optional implementation, the CU-CP can send a path switch message to the SMF to inform the SMF that the first session uses the first security protection mode. The CU-CP can also send the path switch message to the AMF, and the AMF forwards the path switch message to the SMF, so that the SMF learns that the first session uses the first security protection mode.
[0025] In another optional implementation, the CU-CP can send a path update message to the SMF to inform the SMF that the first session uses the first security protection mode. The CU-CP can also send the path update message to the AMF, and the AMF forwards the path update message to the SMF, so that the SMF learns that the first session uses the first security protection mode.
[0026] Alternatively, when the CU-CP determines that the first security protection mode and the second security protection mode are inconsistent. Since the second security protection mode is the security protection mode of the first session, the first CU-UP does not support the second security protection mode, the first CU-UP cannot perform protection of the first session. Therefore, the CU-CP can inform the SMF that protection of the first session cannot be performed.
[0027] In the embodiments of the present application, when the first CU-UP determines that the first security protection mode is inconsistent with the second security protection mode corresponding to the first session. The CU-CP can inform the core network device (such as the SMF) that the first CU-UP uses the first security protection mode, or inform the core network device (such as the SMF) that protection of the first session cannot be performed. In order for the core network device to update the state of the first session or the state of the first CU-UP in time. Optionally, the core network device allocates a new CU-UP for the first session.
[0028] In combination with the first aspect, in a possible implementation of the first aspect, the first security policy comprises:
[0029] a confidentiality protection requirement and / or an integrity protection requirement. The confidentiality protection requirement includes a requirement for performing confidentiality protection, a preference for performing confidentiality protection, or no requirement for confidentiality protection. The integrity protection requirement includes a requirement for performing integrity protection, a preference for performing integrity protection, or no requirement for integrity protection.
[0030] With reference to the first aspect, in a possible implementation form of the first aspect, the first security protection manner or the second security protection manner includes:
[0031] whether to perform user plane confidentiality protection, and whether to perform user plane integrity protection.
[0032] specifically, performing confidentiality protection or not performing confidentiality protection, and / or performing integrity protection or not performing integrity protection.
[0033] With reference to the first aspect, in a possible implementation form of the first aspect, before the CU-CP sends the first security policy to the first CU-UP, the method further includes:
[0034] the CU-CP determines, according to the test report, that it is required to switch from the second CU-UP to the first CU-UP;
[0035] or, the CU-CP determines, according to a local policy, that it is required to switch from the second CU-UP to the first CU-UP.
[0036] Specifically, the CU-CP can determine whether to initiate the switching process of the CU-UP through various implementation forms. In an optional implementation form, the CU-CP determines whether the CU-UP serving the UE needs to be switched according to a test report reported by the UE. The test report can be reported to the network device (specifically, to the CU-CP) through a signal flow of the UE.
[0037] In another optional implementation form, the CU-CP initiatively initiates a measurement process to obtain the test report of the UE.
[0038] In another optional implementation form, the CU-CP determines that the CU-UP serving the UE needs to be switched according to a local process.
[0039] In the embodiments of the present application, the CU-CP can determine that the CU-CP serving the UE needs to be switched through various manners, thereby improving the implementation flexibility of the method.
[0040] In a second aspect, the embodiments of the present application provide a user plane centralized unit security processing method, applied to a scenario in which a terminal device switches from a first user plane centralized unit (CU-UP) to a second CU-UP. The method comprises the following steps.
[0041] The terminal device receives user plane policy change indication information sent by a control plane centralized unit (CU-CP), wherein the user plane policy change indication information comprises a first security protection mode.
[0042] The terminal device activates security protection between the terminal device and the second CU-UP according to the first security protection mode.
[0043] Specifically, when the CU-CP determines that the first security protection mode is inconsistent with the second security protection mode, the CU-CP sends the first security protection mode to the UE. The purpose is to inform the UE to execute the first security protection mode.
[0044] In an optional implementation, the CU-CP sends user plane measurement change indication information to the terminal device, wherein the user plane measurement change indication information comprises the first security protection mode. Optionally, the user plane measurement change indication information also carries an identifier of the first session.
[0045] Specifically, the CU-CP sends the user plane measurement change indication information to the UE through an RRC reconfiguration message. The RRC reconfiguration message (specifically, the user plane measurement change indication information) comprises a special field or bit, which is used to indicate that the RRC reconfiguration message is the user plane measurement change indication information. The user plane measurement change indication information can also comprise an identifier of the first session, and can also comprise an identifier of a bearer allocated by the first CU-UP. For example, when the first 2 bits of the RRC reconfiguration message are “00”, it indicates that the RRC reconfiguration message carries the user plane policy change indication information.
[0046] Optionally, the CU-CP sends the first security protection mode to the UE, which can be sent to the UE through a DU.
[0047] In the embodiments of the present application, in the scenario in which the terminal device switches from the first CU-UP to the second CU-UP, after the terminal device receives the user plane measurement change indication information sent by the CU-CP, the terminal device activates the security protection between the terminal device and the second CU-UP according to the first security protection mode included in the user plane measurement change indication information. This ensures the stability of the communication between the terminal device and the second CU-UP, and improves the security of the communication between the terminal device and the second CU-UP.
[0048] With reference to the second aspect, in a possible implementation manner of the second aspect, before the terminal device activates the security protection between the terminal device and the second CU-UP according to the first security protection manner, the terminal device further includes:
[0049] The terminal device deletes a second security protection manner, which is a security protection manner between the terminal device and the first CU-UP.
[0050] In the embodiment, before the terminal device activates the security protection between the terminal device and the second CU-UP according to the first security protection manner, the terminal device can further delete the second security protection manner, so as to save the storage space in the terminal device. In addition, the conflict between the second security protection manner and the first security protection manner is avoided, so as to improve the security of communication.
[0051] In a third aspect, an embodiment of the present application provides a communication apparatus, including:
[0052] The transceiver is configured to send a first security policy to a first user plane centralized unit (CU-UP).
[0053] The transceiver is further configured to receive a first security protection manner sent by the first CU-UP, where the first security protection manner is a security protection manner determined by the first CU-UP.
[0054] The processing module is configured to determine whether the first security protection manner is consistent with a second security protection manner, where the second security protection manner is a security protection manner used by a terminal device and a second CU-UP for data protection.
[0055] The transceiver is further configured to send the first security protection manner to the terminal device when the processing module determines that the first security protection manner is not consistent with the second security protection manner.
[0056] The transceiver is further configured to send the first security protection manner to the terminal device when the processing module determines that the first security protection manner is not consistent with the second security protection manner.
[0057] With reference to the third aspect, in a possible implementation manner of the third aspect, the transceiver is further configured to notify a session management function (SMF) that the first CU-UP uses the first security protection manner if the first security protection manner is different from the second security protection manner.
[0058] Alternatively,
[0059] The transceiving module is further configured to, if the first security protection mode and the second security protection mode are different, notify the SMF that protection of a first session cannot be performed, the first session being a session in which the terminal device and the second CU-UP use the second security protection mode for data protection.
[0060] With reference to the third aspect, in a possible implementation form of the third aspect, the first security policy comprises:
[0061] confidentiality protection is required, or the confidentiality protection is preferred, or the confidentiality protection is not required;
[0062] integrity protection is required, or the integrity protection is preferred, or the confidentiality protection is not required.
[0063] With reference to the third aspect, in a possible implementation form of the third aspect, the first security protection mode or the second security protection mode comprises:
[0064] whether to perform user plane confidentiality protection; whether to perform user plane integrity protection.
[0065] With reference to the third aspect, in a possible implementation form of the third aspect, the processing module is further configured to determine, according to the test report, that switching from the second CU-UP to the first CU-UP is required.
[0066] or,
[0067] The processing module is further configured to determine, according to a local policy, that switching from the second CU-UP to the first CU-UP is required.
[0068] In a fourth aspect, an embodiment of the present application provides a communication apparatus, comprising:
[0069] a transceiving module configured to receive user plane policy change indication information sent by a management plane centralized unit (CU-CP), the user plane policy change indication information comprising a first security protection mode;
[0070] a processing module configured to activate security protection between a terminal device and a second CU-UP according to the first security protection mode.
[0071] With reference to the fourth aspect, in a possible implementation form of the fourth aspect, the processing module is further configured to delete a second security protection mode, the second security protection mode being a security protection mode between the terminal device and the first CU-UP.
[0072] With reference to the fourth aspect, in a possible implementation form of the fourth aspect, the first security protection mode or the second security protection mode comprises:
[0073] whether to perform user plane confidentiality protection; whether to perform user plane integrity protection.
[0074] In some optional embodiments of the present application, the user plane policy change indication information carries a bit or a field.
[0075] In a fifth aspect, embodiments of the present application provide a communication apparatus, comprising:
[0076] a transceiver configured to send a first security policy to a first user plane centralized unit (CU-UP);
[0077] The transceiver is further configured to receive a first security protection mode sent by the first CU-UP, the first security protection mode being a security protection mode determined by the first CU-UP;
[0078] a processor configured to determine whether the first security protection mode is consistent with a second security protection mode, wherein the second security protection mode is a security protection mode used by a terminal device and a second CU-UP for data protection;
[0079] The transceiver is further configured to, when the processor determines that the first security protection mode is not consistent with the second security protection mode,
[0080] The transceiver is further configured to send the first security protection mode to the terminal device, wherein the first security protection mode is a security protection mode used by the terminal device and the first CU-UP for data protection.
[0081] With reference to the fifth aspect, in a possible implementation manner of the fifth aspect, the transceiver is further configured to, if the first security protection mode and the second security protection mode are different, notify a session management function (SMF) that the first CU-UP uses the first security protection mode;
[0082] or,
[0083] The transceiver is further configured to, if the first security protection mode and the second security protection mode are different, notify the SMF that protection of a first session cannot be performed, the first session being a session in which the terminal device and the second CU-UP use the second security protection mode for data protection.
[0084] With reference to the fifth aspect, in a possible implementation manner of the fifth aspect, confidentiality protection needs to be performed, or confidentiality protection is inclined to be performed, or confidentiality protection does not need to be performed;
[0085] Integrity protection needs to be performed, or integrity protection is inclined to be performed, or confidentiality protection does not need to be performed.
[0086] With reference to the fifth aspect, in a possible implementation manner of the fifth aspect, the first security protection manner or the second security protection manner includes:
[0087] whether to perform user plane confidentiality protection; whether to perform user plane integrity protection.
[0088] With reference to the fifth aspect, in a possible implementation manner of the fifth aspect, the processor is further configured to determine, according to the test report, that switching from the second CU-UP to the first CU-UP is needed.
[0089] or,
[0090] The processor is further configured to determine, according to a local policy, that switching from the second CU-UP to the first CU-UP is needed.
[0091] The sixth aspect, the embodiments of the present application provide a communication device, comprising:
[0092] The transceiver is configured to receive user plane policy change indication information sent by a management plane centralized unit (CU-CP), wherein the user plane policy change indication information includes a first security protection manner.
[0093] The processor is configured to activate security protection between the terminal device and the second CU-UP according to the first security protection manner.
[0094] With reference to the sixth aspect, in a possible implementation manner of the sixth aspect, the processor is further configured to delete a second security protection manner, and the second security protection manner is a security protection manner between the terminal device and the first CU-UP.
[0095] With reference to the sixth aspect, in a possible implementation manner of the sixth aspect, the first security protection manner or the second security protection manner includes:
[0096] whether to perform user plane confidentiality protection; whether to perform user plane integrity protection.
[0097] With reference to the sixth aspect, in a possible implementation manner of the sixth aspect, the user plane policy change indication information carries a bit or a field.
[0098] In a seventh aspect, an embodiment of the present application provides a communication apparatus, which can implement the functions performed by the CU-CP or the terminal device in the method of the first or second aspect. The communication apparatus includes a processor, a memory, a receiver connected to the processor, and a transmitter connected to the processor. The memory is configured to store program codes and transmit the program codes to the processor. The processor is configured to drive the receiver and the transmitter to perform the method of the first or second aspect according to the instructions in the program codes. The receiver and the transmitter are respectively connected to the processor to perform the operations of the CU-CP or the terminal device in the method of the first or second aspect. Specifically, the transmitter can perform the operation of transmitting, and the receiver can perform the operation of receiving. Optionally, the receiver and the transmitter can be a radio frequency circuit that receives and transmits messages through an antenna. The receiver and the transmitter can also be a communication interface. The processor is connected to the communication interface through a bus. The processor receives or transmits messages through the communication interface.
[0099] In an eighth aspect, an embodiment of the present application provides a communication apparatus, which can include a network device or a chip, and the communication apparatus includes a processor and a memory. The memory is configured to store instructions. The processor is configured to execute the instructions in the memory, so that the communication apparatus performs the method of any one of the first aspect or the second aspect.
[0100] In a ninth aspect, an embodiment of the present application provides a computer readable storage medium storing one or more computer-executable instructions that, when executed by a processor, cause the processor to perform any one of the possible implementation manners of the first aspect or the second aspect.
[0101] In a tenth aspect, an embodiment of the present application provides a computer program product (or computer program) storing one or more computer-executable instructions that, when executed by a processor, cause the processor to perform any one of the possible implementation manners of the first aspect or the second aspect.
[0102] In an eleventh aspect, an embodiment of the present application provides a chip system, which includes a processor configured to support a computer device to implement the functions involved in the above aspects. In a possible design, the chip system further includes a memory configured to store necessary program instructions and data of the computer device. The chip system can be composed of a chip, or can include the chip and other discrete devices.
[0103] In a twelfth aspect, an embodiment of the present application provides a communication system, which includes the communication apparatus of the third aspect or the fourth aspect. Specifically, the communication system includes a CU-CP, a first CU-UP, a second CU-UP, and a terminal device.
[0104] The CU-CP is configured to send a first security policy to the first CU-UP.
[0105] The CU-UP is configured to receive the first security policy sent by the CU-CP.
[0106] The first CU-UP is further configured to determine a first security protection mode according to the first security policy.
[0107] The first CU-UP is further configured to send the first security protection mode to the first CU-CP.
[0108] The CU-CP is further configured to receive the first security protection mode sent by the first CU-UP, the first security protection mode being the security protection mode determined by the first CU-UP.
[0109] The CU-CP is further configured to determine whether the first security protection mode is consistent with a second security protection mode, the second security protection mode being a security protection mode used by the terminal device and the second CU-UP for data protection.
[0110] The CU-CP is further configured to send the first security protection mode to the terminal device when the CU-CP determines that the first security protection mode is not consistent with the second security protection mode, the first security protection mode being a security protection mode used by the terminal device and the first CU-UP for data protection.
[0111] The terminal device is configured to receive user plane policy change indication information sent by the CU-CP, the user plane policy change indication information including a first security protection mode.
[0112] The terminal device is further configured to activate security protection between the terminal device and the second CU-UP according to the first security protection mode.
[0113] With reference to the twelfth aspect, in a possible implementation manner of the twelfth aspect, the system further includes a session management function (SMF), and after receiving the first security protection mode sent by the first CU-UP, the CU-CP is further configured to:
[0114] If the first security protection mode and the second security protection mode are different, the SMF is notified that the first CU-UP uses the first security protection mode; or if the first security protection mode and the second security protection mode are different, the SMF is notified that protection of a first session cannot be performed, the first session being a session in which the terminal device and the second CU-UP use the second security protection mode for data protection.
[0115] With reference to the twelfth aspect, in a possible implementation of the twelfth aspect, the first security policy comprises:
[0116] receiving a requirement of performing confidentiality protection, or being inclined to perform confidentiality protection, or not requiring to perform confidentiality protection;
[0117] receiving a requirement of performing integrity protection, or being inclined to perform integrity protection, or not requiring to perform confidentiality protection.
[0118] With reference to the twelfth aspect, in a possible implementation of the twelfth aspect, the first security protection mode or the second security protection mode comprises:
[0119] whether to perform user plane confidentiality protection;
[0120] whether to perform user plane integrity protection.
[0121] With reference to the twelfth aspect, in a possible implementation of the twelfth aspect, before the CU-CP sends the first security policy to the first CU-UP, the CU-CP further performs:
[0122] determining, according to a test report, that it is required to switch from the second CU-UP to the first CU-UP;
[0123] or, determining, according to a local policy, that it is required to switch from the second CU-UP to the first CU-UP.
[0124] It should be noted that the specific implementation manners of the twelfth aspect and any one of the communication systems in the twelfth aspect and the beneficial effects brought by the specific implementation manners can refer to the descriptions in any one of the possible implementation manners of the first aspect and the second aspect, which will not be repeated here. BRIEF DESCRIPTION OF DRAWINGS
[0125] Figure 1a is a schematic diagram of a network architecture of a communication system;
[0126] Figure 1b is a schematic diagram of an architecture using CU-DU in a communication system;
[0127] Figure 1c is a schematic diagram of an architecture of a CU;
[0128] Figure 2 is a schematic diagram of a hardware structure of a communication device in an embodiment of the present application;
[0129] Figure 3 is a schematic diagram of an embodiment of a user plane centralized unit security processing method proposed in an embodiment of the present application;
[0130] Figure 4Another embodiment of a user plane centralized unit security processing method proposed in the embodiments of the present application is shown in the figure;
[0131] Figure 5 Another embodiment of a user plane centralized unit security processing method proposed in the embodiments of the present application is shown in the figure;
[0132] Figure 6 Another embodiment of a user plane centralized unit security processing method proposed in the embodiments of the present application is shown in the figure;
[0133] Figure 7 Another embodiment of a user plane centralized unit security processing method proposed in the embodiments of the present application is shown in the figure;
[0134] Figure 8 Another embodiment of a user plane centralized unit security processing method proposed in the embodiments of the present application is shown in the figure;
[0135] Figure 9 Another embodiment of a user plane centralized unit security processing method proposed in the embodiments of the present application is shown in the figure;
[0136] Figure 10 An embodiment of a communication device in the embodiments of the present application is shown in the figure;
[0137] Figure 11 An embodiment of a communication device in the embodiments of the present application is shown in the figure;
[0138] Figure 12 Another embodiment of a communication device in the embodiments of the present application is shown in the figure;
[0139] Figure 13 Another embodiment of a communication device in the embodiments of the present application is shown in the figure;
[0140] Figure 14 A processing device proposed in the embodiments of the present application is shown in the figure. DETAILED DESCRIPTION
[0141] The embodiments of the present application propose a user plane centralized unit security processing method, aiming to improve the security of communication in the scenario of terminal device switching from a first user plane centralized unit CU-UP to a second CU-UP.
[0142] The terms "first", "second", and the like in the description and in the claims of the present application and above drawings are used for distinguishing between similar objects and not necessarily for describing a specific sequential or chronological order. It is to be understood that the terms so used are interchangeable under appropriate circumstances and are merely employed in the description of embodiments of the present application for clarity. Additionally, the term "including" and "comprising" as well as any of their derivatives, are intended to cover a non-exclusive inclusion. For example, a process, method, article, or apparatus that comprises a list of elements is not necessarily limited to those elements but can include other elements not expressly listed or inherent to such process, method, article, or apparatus.
[0143] The technical solutions in the embodiments of the present application will be clearly described below with reference to the drawings in the embodiments of the present application. In the description of the present application, unless otherwise specified, " / " means or, for example, A / B can mean A or B; "and / or" in the present application is only a description of the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B can mean that A exists alone, A and B exist together, and B exists alone. In addition, in the description of the present application, "at least one" means one or more, and "more" means two or more. "At least one of the following" or similar expressions means any combination of these items, including any combination of single item or multiple items. For example, at least one of a, b, or c can mean a, b, c, a-b, a-c, b-c, or a-b-c, where a, b, and c can be single or multiple.
[0144] The embodiments of the present application will be described below with reference to the drawings.
[0145] Figure 1a It is a schematic diagram of a network architecture of a communication system. The communication system includes an access network and a core network. The access network can be a next generation radio access network (NG-RAN), and the core network can be a 5G core network (5GC). The access network can include access network devices (for example, gNBs), and the gNBs are connected through an interface (for example, an Xn interface). The gNBs and the 5GC are connected through an interface (for example, an Ng interface). The core network can include an access and mobility management function (AMF). The core network can also include a session management function (SMF) or a user plane function (UPF), etc.
[0146] Figure 1b This is a schematic diagram of the architecture of a communication system using a CU-DU. Figure 1b As shown, access network equipment can include Centralized Units (CUs) and Distributed Units (DUs). The functions of the access network equipment are split, with some functions deployed in a CU and others in a DU. There can be one or more DUs. Multiple DUs can share a single CU to save costs and facilitate network expansion. CUs and DUs are connected via an interface (e.g., an F1 interface). The CU, representing the access network equipment, connects to the core network via an interface (e.g., an Ng interface). The functional division between CUs and DUs can be based on the protocol stack. One possible approach is to deploy Radio Resource Control (RRC), the Packet Data Convergence Protocol (PDCP) layer, and the Service Data Adaptation Protocol (SDAP) layer in the CU. Radio Link Control (RLC), Media Access Control (MAC), and the Physical Layer (PHY) are deployed in the DU. Accordingly, the CU has the processing capabilities for RRC, PDCP, and SDAP. The DU has RLC, MAC, and PHY processing capabilities. It is worth noting that the above functional division is only one example; other division methods are possible. For example, the CU includes RRC, PDCP, RLC, and SDAP processing capabilities, while the DU has MAC and PHY processing capabilities. Another example is that the CU includes RRC, PDCP, RLC, SDAP, and partial MAC processing capabilities (e.g., adding MAC headers), while the DU has PHY and partial MAC processing capabilities (e.g., scheduling). The names of CU and DU may change; any access network node that can implement the above functions can be considered as the CU or DU in this patent application.
[0147] Figure 1c This is a schematic diagram of a CU architecture. Figure 1cAs shown, the CU includes a control plane CU (CU-CP) and a user plane CU (CU-UP). The CU-CP and the CU-UP can be on different physical devices. The CU-CP and the CU-UP can also be on the same physical device. The CU-CP and the CU-UP are connected through an interface (for example, an E1 interface). The CU-CP is connected to the core network through an interface (for example, an Ng interface) by the access network device. The CU-CP is connected to the DU through an interface (for example, an F1-C interface), and the CU-UP is connected to the DU through an interface (for example, an F1-U interface). The number of CU-CPs can be one, and the number of CU-UPs can be one or more. Multiple CU-UPs can share one CU-CP. The CU-CP mainly has a control plane function. The CU-UP mainly has a user plane function. One possible implementation is that, for the access network device of 5G, the RRC layer can be deployed in the CU-CP, and the SDAP layer is not deployed in the CU-CP. The CU-CP can also have a control plane part function of the PDCP layer, for example, can perform processing of a signaling radio bearer (SRB). The SDAP layer can be deployed in the CU-UP, but the RRC layer is not deployed in the CU-UP. The CU-UP can also have a user plane part function of the PDCP layer, for example, perform processing of a data radio bearer (DRB). The division of the specific protocol stack between the CU-UP and the DU is not limited. In this application, the processing of PDCP-U is considered as the logical function of the CU-UP.
[0148] The network elements described above can be network elements implemented on special hardware, software instances running on special hardware, or instances of virtualized functions on appropriate platforms. For example, the virtualization platform described above can be a cloud platform.
[0149] In addition, the embodiments of the present application can also be applicable to other communication technologies facing the future, such as 6G and the like. The network architecture and service scenarios described in the present application are for more clearly illustrating the technical solutions of the present application, and do not constitute a limitation on the technical solutions provided by the present application. Those skilled in the art can know that, with the evolution of network architecture and the appearance of new service scenarios, the technical solutions provided by the present application are also applicable to similar technical problems.
[0150] Figure 2 A hardware structure diagram of a communication device in the embodiments of the present application. The communication device can be a possible implementation of the CU-CP or the CU-UP in the embodiments of the present application. As shown in FIG. 6, the communication device includes a processor 601, a memory 602, a transceiver 603, and an antenna 604. The processor 601, the memory 602, the transceiver 603, and the antenna 604 are connected through a bus. The processor 601 is configured to implement the functions of the CU-CP or the CU-UP in the embodiments of the present application. The memory 602 is configured to store program codes and data of the communication device. The transceiver 603 is configured to implement the functions of the transceiver in the communication device. The antenna 604 is configured to implement the functions of the antenna in the communication device. Figure 2As shown, the communication apparatus at least includes a processor 201, a memory 203, and a transceiver 202. The memory 203 is further configured to store instructions 2031 and data 2032. Optionally, the communication apparatus can further include an antenna 206, an I / O (Input / Output) interface 210, and a bus 212. The transceiver 202 further includes a transmitter 2021 and a receiver 2022. In addition, the processor 201, the transceiver 202, the memory 203, and the I / O interface 210 are communicatively connected with each other through the bus 212, and the antenna 206 is connected with the transceiver 202.
[0151] The processor 201 can be a general processor, such as but not limited to a Central Processing Unit (CPU), or a special purpose processor, such as but not limited to a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field Programmable Gate Array (FPGA), or the like. In addition, the processor 201 can also be a combination of multiple processors. In particular, in the technical solutions provided by the embodiments of the present application, the processor 201 can be used to execute the related steps of the communication method in the subsequent method embodiments. The processor 201 can be a processor specially designed to execute the above steps and / or operations, or a processor that executes the above steps and / or operations by reading and executing the instructions 2031 stored in the memory 203. The processor 201 can need to use the data 2032 in the process of executing the above steps and / or operations.
[0152] The transceiver 202 includes the transmitter 2021 and the receiver 2022. In an optional implementation manner, the transmitter 2021 is configured to transmit signals through the antenna 206. The receiver 2022 is configured to receive signals through at least one of the antennas 206. In particular, in the technical solutions provided by the embodiments of the present application, the transmitter 2021 can be specifically configured to execute, for example, the operations performed by the receiving module or the transmitting module in the CU-CP or the CU-UP when the communication method in the subsequent method embodiments is applied to the CU-CP or the CU-UP.
[0153] In the embodiments of the present application, the transceiver 202 is configured to support the communication apparatus to execute the receiving function and the transmitting function described above. The processor with processing function is regarded as the processor 201. The receiver 2022 can also be referred to as a receiver, an input port, a receiving circuit, or the like, and the transmitter 2021 can be referred to as a transmitter, a transmitter, or a transmitting circuit, or the like.
[0154] The processor 201 can be configured to execute the instructions stored in the memory 203 to control the transceiver 202 to receive and / or send messages, and complete the functions of the communication device in the method embodiments of the present application. As an implementation manner, the functions of the transceiver 202 can be implemented by a transceiver circuit or a dedicated chip. In the embodiments of the present application, the message received by the transceiver 202 can be understood as the message input by the transceiver 202, and the message sent by the transceiver 202 can be understood as the message output by the transceiver 202.
[0155] The memory 203 can be various types of storage media, such as random access memory (RAM), read only memory (ROM), non-volatile RAM (NVRAM), programmable ROM (PROM), erasable PROM (EPROM), electrically erasable PROM (EEPROM), flash memory, optical storage, and registers, etc. The memory 203 is specifically configured to store instructions 2031 and data 2032. The processor 201 can execute the instructions 2031 stored in the memory 203 to perform the steps and / or operations described in the method embodiments of the present application. The data 2032 can be used in the process of performing the operations and / or steps in the method embodiments of the present application.
[0156] Optionally, the communication device can further include an I / O interface 210, which is configured to receive instructions and / or data from a peripheral device, and output instructions and / or data to the peripheral device.
[0157] The method part of the embodiments of the present application will be introduced below. Please refer to Figure 3 , Figure 3 An embodiment of a user plane centralized unit security processing method proposed in the embodiments of the present application is shown in the following schematic diagram, which includes the following steps:
[0158] 301, the UE accesses the network.
[0159] In this embodiment, the UE initiates an access request to an access network device, where the access network device includes a distributed unit (DU) and a centralized unit (CU). Specifically, the UE sends a radio resource control reconnection (RRC reconnection) message to the DU. Based on the RRC reconnection message, the UE and the network device (including the access network device and the core network device) complete the related procedures of accessing the network, the UE and the CU-CP establish a connection of a control plane, and the UE and the second CU-UP establish a connection of a user plane. For example, the UE and the second CU-UP establish a PDCP connection. The session established between the UE and the second CU-UP is referred to as a first session, and the first session can be a protocol data unit (PDU) session. In this embodiment, the security protection mode of the second CU-UP and the UE for protecting the first session is referred to as a second security protection mode. The UE and the second CU-UP respectively save: an identifier (ID) of the first session, an identifier of a bearer corresponding to the identifier of the first session, and the second security protection mode. The indication content of the second security protection mode specifically includes: whether encryption (or referred to as confidentiality protection) needs to be performed, and whether integrity protection needs to be performed. Optionally, the identifier of the first session can correspond to identifiers of multiple bearers, and the protection modes of the multiple bearers in the first session can be consistent.
[0160] It should be noted that the first session refers to one or more sessions, and the identifier of the first session refers to the identifier of one or more sessions, which is not limited here.
[0161] First, the security policy and the security protection mode are introduced.
[0162] A. The security policy includes: confidentiality protection requirement, and / or, integrity protection requirement. Wherein, the confidentiality protection requirement includes: required to perform confidentiality protection, preferred to perform confidentiality protection, or not required to perform confidentiality protection; the integrity protection requirement includes: required to perform integrity protection, preferred to perform integrity protection, or not required to perform integrity protection.
[0163] B. The security protection mode includes: performing confidentiality protection, or not performing confidentiality protection; and / or, performing integrity protection, or not performing integrity protection.
[0164] 302. The CU-CP determines that the switching of the CU-UP needs to be initiated.
[0165] In this embodiment, the CU-CP can determine whether to initiate the switching procedure of the CU-UP through various implementation manners.
[0166] In an optional implementation manner, the CU-CP determines whether the CU-UP serving the UE needs to be switched according to a test report reported by the UE. The test report can be reported to the network device (specifically, to the CU-CP) through a signal procedure of the UE.
[0167] In another optional implementation manner, the CU-CP initiatively initiates a measurement procedure to obtain the test report of the UE.
[0168] In another optional implementation manner, the CU-CP determines that the CU-UP serving the UE needs to be switched according to a local process.
[0169] 303. The CU-CP sends the first security policy to the first CU-UP.
[0170] In this embodiment, the CU-CP sends the first security policy to the first CU-UP. Specifically, the CU-CP sends the first security policy to the first CU-UP through a BEARER CONTEXT SETUP REQUEST message. Optionally, the BEARER CONTEXT SETUP REQUEST message can also carry the identifier of the first session and / or the second security protection manner.
[0171] It should be noted that the first CU-UP can be referred to as a target CU-UP, and the second CU-UP can be referred to as a source CU-UP. In an optional implementation manner, the CU-CP determines the procedure of the first CU-UP, which is consistent with the procedure of determining the target CU-UP in the prior art. In another optional implementation manner, the CU-CP can also randomly select any CU-UP managed by itself as the first CU-UP, which is not limited herein.
[0172] Optionally, when the first security policy indicates that confidentiality protection needs to be performed and / or integrity protection needs to be performed, or when the second security protection manner indicates that confidentiality protection needs to be performed and / or integrity protection needs to be performed, the first CU-UP cannot be a CU-UP deployed in a low security domain. The first CU-UP being a CU-UP deployed in a low security domain can also be referred to as the first CU-UP belonging to a low security domain, which is not limited herein.
[0173] In the communication network, the firewalls are used to protect the boundaries of different security domains according to the security domains. The low security domain refers to a region with low security protection performance or a region with high risk level, which is not limited herein.
[0174] In an optional implementation, according to the deployment location of the CU-UP, it is determined whether the CU-UP belongs to the CU-UP deployed in the low-security domain. For example, it is determined that the CU-UP deployed in the DU belongs to the CU-UP deployed in the high-security domain; the CU-UP deployed in the distance (physical distance) close to the DU is determined to belong to the CU-UP deployed in the high-security domain; and the CU-UP deployed in the distance far from the DU is determined to belong to the CU-UP deployed in the low-security domain.
[0175] In another optional implementation, according to the data stored in the CU-UP, it is determined whether the CU-UP belongs to the CU-UP deployed in the low-security domain. For example, according to the Internet Protocol (IP) address or the MAC address of the CU-UP stored in the CU-UP, it can be determined that the deployment location of the CU-UP, and then it is determined whether the CU-UP is the low-security domain CU-UP.
[0176] In another optional implementation, according to the security protection mode supported by the CU-UP, it is determined whether the CU-UP belongs to the CU-UP deployed in the low-security domain. For example, when the CU-UP supports confidentiality protection and / or integrity protection, the CU-UP belongs to the CU-UP deployed in the high-security domain; and when the CU-UP does not support confidentiality protection and / or integrity protection, the CU-UP belongs to the CU-UP deployed in the low-security domain.
[0177] In another optional implementation, the CU-CP determines whether the CU-UP belongs to the low-security domain according to the local configuration or the current policy.
[0178] 304, the first CU-UP determines the first security protection mode.
[0179] In this embodiment, after the CU-UP receives the first security policy from the CU-CP, the CU-UP determines the first security protection mode selected by itself according to the first security policy and the capability of the CU-UP.
[0180] Specifically, when the first security policy indicates that the confidentiality protection needs to be performed, and the first CU-UP determines to perform the confidentiality protection, the first security protection mode is to perform the confidentiality protection.
[0181] When the first security protection policy indicates that the confidentiality protection needs to be performed, and the first CU-UP determines that the confidentiality protection cannot be performed, the first CU-UP sends an indication that the protection cannot be performed to the CU-CP. The indication is used to inform the CU-CP that the confidentiality protection corresponding to the session cannot be performed, and the session is refused to be transmitted in the first CU-UP. For example, the session is the first session.
[0182] When the first security protection policy indicates that confidentiality protection is preferred to be performed, the first CU-UP decides whether to perform the confidentiality protection: if the first CU-UP determines to perform the protection, it is determined that the first security protection manner is to perform the confidentiality protection; if the first CU-UP determines not to perform the protection, it is determined that the first security protection manner is not to perform the confidentiality protection. The first CU-UP sends an indication of whether to perform the confidentiality protection to the CU-CP, where the indication of whether to perform the confidentiality protection is used to indicate the result of whether to perform the confidentiality protection determined by the first CU-UP.
[0183] When the first security protection policy indicates that the confidentiality protection is not to be performed, the first CU-UP does not perform the confidentiality protection.
[0184] The integrity protection is similar to the confidentiality protection, and details are as follows:
[0185] When the first security policy indicates that the integrity protection needs to be performed, and the first CU-UP determines to perform the integrity protection, the first security protection manner is to perform the integrity protection.
[0186] When the first security protection policy indicates that the integrity protection needs to be performed, and the first CU-UP determines that the integrity protection cannot be performed, the first CU-UP sends an indication of not being able to perform the protection to the CU-CP, where the indication is used to inform the CU-CP that the integrity protection corresponding to the session cannot be performed, and the session is refused to be transmitted at the first CU-UP. For example, the session is the first session.
[0187] When the first security protection policy indicates that the integrity protection is preferred to be performed, the first CU-UP decides whether to perform the confidentiality protection: if the first CU-UP determines to perform the protection, it is determined that the first security protection manner is to perform the integrity protection; if the first CU-UP determines not to perform the protection, it is determined that the first security protection manner is not to perform the integrity protection. The first CU-UP sends an indication of whether to perform the integrity protection to the CU-CP, where the indication of whether to perform the integrity protection is used to indicate the result of whether to perform the integrity protection determined by the first CU-UP.
[0188] When the first security protection policy indicates that the integrity protection is not to be performed, the first CU-UP does not perform the integrity protection.
[0189] 305、The first CU-UP sends the first security protection manner to the CU-CP.
[0190] In this embodiment, after the first CU-UP determines the first security protection manner, the first CU-UP sends the first security protection manner to the CU-CP. Specifically, different possible cases of the first security protection manner are as shown in Table 1:
[0191]
[0192] Table 1
[0193] In a possible implementation, the first CU-UP sends the first security protection mode to the CU-CP through a Bearer Context Setup Response message, and the Bearer Context Setup Response message can also carry the identifier of the first session.
[0194] Optionally, the first CU-UP also allocates an identifier of a corresponding bearer to the identifier of the first session, and sends the identifier of the corresponding bearer to the CU-CP.
[0195] Optionally, when the first security protection policy indicates that confidentiality protection needs to be performed, and the first CU-UP cannot perform the confidentiality protection, an indication that protection cannot be performed is sent to the first CU-CP. Specifically, the indication that protection cannot be performed can be an indication that confidentiality protection cannot be performed.
[0196] Optionally, when the first security protection policy indicates that integrity protection needs to be performed, and the first CU-UP cannot perform the integrity protection, an indication that protection cannot be performed is sent to the first CU-CP. Specifically, the indication that protection cannot be performed can be an indication that integrity protection cannot be performed.
[0197] 306. The CU-CP determines whether the first security protection mode is consistent with the second security protection mode.
[0198] In this embodiment, the CU-CP determines whether the first security protection mode is consistent with the second security protection mode. For example, when the first security protection mode is to perform confidentiality protection, and the second security protection mode is not to perform confidentiality protection, the CU-CP determines that the first security protection mode is not consistent with the second security protection mode; when the first security protection mode is not to perform confidentiality protection, and the second security protection mode is to perform confidentiality protection, the CU-CP determines that the first security protection mode is not consistent with the second security protection mode. Integrity protection is similar to confidentiality protection, when the first security protection mode is to perform integrity protection, and the second security protection mode is not to perform integrity protection, the CU-CP determines that the first security protection mode is not consistent with the second security protection mode; when the first security protection mode is not to perform integrity protection, and the second security protection mode is to perform integrity protection, the CU-CP determines that the first security protection mode is not consistent with the second security protection mode.
[0199] In an optional implementation, first, the CU-CP determines the second security protection mode according to the received identifier of the first session. Second, the CU-CP determines whether the first security protection corresponding to the identifier of the first session is consistent with the second security protection mode.
[0200] Optionally, if the CU-CP receives an indication from the first CU-UP that it cannot perform the protection (or cannot perform the confidentiality protection; or cannot perform the integrity protection), it means that the first CU-UP cannot perform the requirement of the first security policy. At this time, the CU-CP needs to reselect the CU-UP, or finally reject the data connection of this session, etc., without limitation.
[0201] When the first security protection mode and the second security protection mode are consistent in whether to perform the confidentiality protection, and are consistent in whether to perform the integrity protection, the CU-CP determines that the first security protection mode and the second security protection mode are consistent.
[0202] 307、The CU-CP sends the first security protection mode to the UE.
[0203] In this embodiment, when the CU-CP determines that the first security protection mode and the second security protection mode are inconsistent, the CU-CP sends the first security protection mode to the UE. The purpose is to inform the UE to perform the first security protection mode.
[0204] In an optional implementation, the CU-CP sends user plane measurement change indication information to the terminal device, and the user plane measurement change indication information includes the first security protection mode.
[0205] Optionally, the user plane measurement change indication information also carries an identifier of the first session.
[0206] Specifically, the CU-CP sends the user plane measurement change indication information to the UE through an RRC reconfiguration message. The RRC reconfiguration message (specifically, the user plane measurement change indication information) includes a special field or bit, which is used to indicate that the RRC reconfiguration message is the user plane measurement change indication information. The user plane measurement change indication information can also include an identifier of the first session, and can also include an identifier of the bearer allocated by the first CU-UP.
[0207] Optionally, the CU-CP sends the first security protection mode to the UE, which can be sent to the UE through the DU.
[0208] In an optional implementation, the CU-CP can send the first security protection mode to the UE by modifying the existing bearer information. For example, the bearer information that needs to be modified can include: an identifier of the existing bearer, an identifier of the bearer allocated by the first CU-UP, and the first security protection mode.
[0209] 308、The UE performs the first security protection mode.
[0210] In this embodiment, after receiving the first security protection manner, the UE performs the first security protection manner. Specifically, the UE activates the security protection between the UE and the second CU-CP according to the first security protection manner. Further, the security protection corresponding to the identity of the bearer between the UE and the second CU-CP is activated.
[0211] Optionally, the UE modifies the local existing bearer information, determines the identity of the bearer allocated by the first CU-UP, and determines to perform the first security protection manner.
[0212] For example, when the first security protection manner indicates to perform the confidentiality protection and the integrity protection, the UE performs the confidentiality protection and the integrity protection.
[0213] In an optional implementation, when the UE does not support the confidentiality protection and / or the integrity protection indicated by the first security protection manner, the UE notifies the CU-CP that the first security protection manner cannot be performed. Optionally, the UE can also request the CU-CP to replace other CU-UP as the first CU-UP. Specifically, steps 303-307 are repeated until the UE can perform the first security protection manner.
[0214] Optionally, after the UE performs the first security protection manner, the UE sends an RRC reconfiguration response (RRC reconfiguration complete) message to the CU-CP. The purpose is to notify the CU-CP that the UE has performed the first security protection manner.
[0215] Optionally, the UE can also delete the second security protection manner.
[0216] 309、The CU-CP notifies the SMF that the first session uses the first security protection manner.
[0217] In this embodiment, after step 306, when the CU-CP determines that the first security protection manner is inconsistent with the second security protection manner, the CU-CP can notify the SMF that the first session uses the first security protection manner.
[0218] In an optional implementation, the CU-CP can send a path switch message to the SMF to notify the SMF that the first session uses the first security protection manner. The CU-CP can also send the path switch message to the AMF, and the AMF forwards the path switch message to the SMF, so that the SMF knows that the first session uses the first security protection manner.
[0219] In another optional implementation, the CU-CP can send a path update message to the SMF to inform the SMF that the first session uses the first security protection mode. The CU-CP can also send a path update message to the AMF, and the AMF forwards the path update message to the SMF, so that the SMF knows that the first session uses the first security protection mode.
[0220] It should be noted that step 309 can be performed at any time after step 306, which is not limited here.
[0221] 310、The SMF replies to the CU-CP with an acknowledgement message.
[0222] In this embodiment, after step 309, the SMF can reply to the CU-CP with an acknowledgement (ACK) message. The purpose is to inform the CU-CP that the SMF has learned that the first session uses the first security protection mode.
[0223] Optionally, after the SMF records the first security protection mode, the SMF replies to the CU-CP with an acknowledgement message.
[0224] It should be noted that steps 309-310 are optional steps.
[0225] In the embodiments of the present application, when the security protection mode of the UE and the first CU-UP is inconsistent, the CU-CP can inform the UE of the first security protection mode performed by the first CU-UP, so that the UE performs the first security protection mode performed by the first CU-UP. To ensure that subsequent data between the UE and the first CU-UP can be normally interacted under the protection of the first security protection mode. To improve the security of communication.
[0226] In Figure 3 the embodiments shown in the drawings, please refer to Figure 4 , Figure 4 Another embodiment of a user plane centralized unit security processing method proposed in the embodiments of the present application is shown in the figure, which includes:
[0227] 401、The UE accesses the network.
[0228] 402、The CU-CP determines that it needs to initiate the switching of the CU-UP.
[0229] Steps 401-402 are the same as the aforementioned steps 301-302, and can refer to steps 301-302, which will not be repeated here.
[0230] 403、The CU-CP sends the second security protection mode to the first CU-UP.
[0231] In this embodiment, the CU-CP sends the second security protection mode to the first CU-UP. Specifically, the CU-CP sends the second security protection mode to the first CU-UP through a BEARER CONTEXT SETUP REQUEST message. Optionally, the BEARER CONTEXT SETUP REQUEST message can also carry the identifier of the first session.
[0232] In an optional implementation, the CU-CP determines the first CU-UP in the same way as the target CU-UP is determined in the prior art. In another optional implementation, the CU-CP can also randomly select any CU-UP managed by itself as the first CU-UP, which is not limited here.
[0233] Optionally, when the second security protection mode indicates that confidentiality protection needs to be performed and / or integrity protection needs to be performed, the first CU-UP cannot be a CU-UP deployed in a low-security domain. In a communication network, different security domains are isolated according to security domains, and a firewall is used to protect the boundary between different security domains. The low-security domain refers to a region with low security protection performance or a region with high risk level, which is not limited here.
[0234] In another optional implementation, the CU-CP sends the security protection mode to the first CU-UP in the format of a security policy. Specifically, the CU-CP generates a second security policy according to the second security protection mode and sends the second security policy to the first CU-UP. For example, if the second security protection mode indicates that confidentiality protection needs to be performed, the confidentiality protection of the second security policy is set to required; if the second security protection mode indicates that confidentiality protection does not need to be performed, the confidentiality protection of the second security policy is set to not needed. If the second security protection mode indicates that integrity protection needs to be performed, the integrity protection of the second security policy is set to required; if the second security protection mode indicates that integrity protection does not need to be performed, the integrity protection of the second security policy is set to not needed.
[0235] 404. The first CU-UP determines the first security protection mode.
[0236] In this embodiment, after the CU-UP receives the second security protection mode from the CU-CP, the CU-UP determines the first security protection mode selected by itself according to the second security protection mode and the capability of the CU-UP.
[0237] Specifically, when the second security protection mode is to perform confidentiality protection and to perform integrity protection, the first CU-UP determines whether the first CU-UP itself supports performing confidentiality protection and whether the first CU-UP itself supports performing integrity protection. When the first CU-UP itself supports performing confidentiality protection and supports performing integrity protection, the first CU-UP determines that the first security protection mode is to perform confidentiality protection and to perform integrity protection. When the first CU-UP itself does not support performing confidentiality protection and / or does not support performing integrity protection, the first CU-UP needs to reject the session (for example, the first session).
[0238] When the second security protection mode is not to perform confidentiality protection and to perform integrity protection, the first CU-UP determines whether the first CU-UP itself supports performing integrity protection. When the first CU-UP itself supports performing integrity protection, the first CU-UP determines that the first security protection mode is not to perform confidentiality protection and to perform integrity protection. When the first CU-UP itself does not support performing integrity protection, the first CU-UP needs to reject the session (for example, the first session).
[0239] When the second security protection mode is to perform confidentiality protection and not to perform integrity protection, the first CU-UP determines whether the first CU-UP itself supports performing confidentiality protection. When the first CU-UP itself supports performing confidentiality protection, the first CU-UP determines that the first security protection mode is to perform confidentiality protection and not to perform integrity protection. When the first CU-UP itself does not support performing confidentiality protection, the first CU-UP needs to reject the session (for example, the first session).
[0240] When the second security protection mode is not to perform confidentiality protection and not to perform integrity protection, the first CU-UP determines that the first security protection mode is not to perform confidentiality protection and not to perform integrity protection.
[0241] 405. The first CU-UP determines whether the first security protection mode is consistent with the second security protection mode.
[0242] Step 405 is the same as the foregoing step 306, and can refer to step 306, which will not be described here again.
[0243] In another optional implementation, the first CU-UP determines whether to perform the second security protection mode corresponding to the identifier of the first session according to the identifier of the first session.
[0244] 406. When the first security protection mode is not consistent with the second security protection mode, the first CU-UP sends a failure indication to the CU-CP.
[0245] In this embodiment, when the first security protection manner is inconsistent with the second security protection manner, the first CU-UP sends a failure indication to the CU-CP, and the failure indication is used to indicate that the first CU-UP cannot perform (or activate) the second security protection manner.
[0246] Optionally, the first CU-UP can also send, to the CU-CP, an identifier of a first session corresponding to the failure indication.
[0247] In another optional implementation, the first CU-UP determines, according to the identifier of the first session, whether to perform the second security protection manner corresponding to the identifier of the first session. If the second security protection manner indicates to perform confidentiality protection or integrity protection, and the first CU-UP cannot perform (or is not capable of) the confidentiality protection or the integrity protection, the first CU-UP needs to send a failure indication to the CU-CP, and the failure indication can also be referred to as a rejection indication. Optionally, the first CU-UP can also send, to the CU-CP, an identifier of a first session corresponding to the second security protection manner.
[0248] Optionally, if the CU-CP does not receive the failure indication (or the rejection indication) of the first CU-UP, it is considered that the first CU-UP does not reject the second security protection manner, and the first CU-UP performs the same protection mechanism as the first security protection manner.
[0249] 407. The CU-CP reselects the CU-UP.
[0250] In this embodiment, the CU-CP reselects the CU-UP according to the failure indication sent by the first CU-UP in step 406. Specifically, the CU-CP selects any one of the remaining CU-UPs managed by itself as the first CU-UP, and repeatedly performs the related operations of steps 403-405 until the selected first CU-UP can perform the second security protection manner. Then, the first CU-UP and the UE perform data protection using the second security protection manner, and specifically, the first CU-UP and the UE protect the related data of the first session using the second security protection manner.
[0251] In an optional implementation, when there is no CU-UP supporting the second security protection manner in the CU-UPs managed by the CU-CP (except for the second CU-UP), the CU-CP instructs the second CU-UP to continue to provide services for the UE. Specifically, the second CU-UP and the UE perform data protection on the first session using the second security protection manner.
[0252] It should be noted that step 407 is an optional step.
[0253] 408. When the inconsistency exists, the CU-CP does not carry the identifier of the first session in a reconfiguration message sent to the UE.
[0254] In the embodiment, when the step 406 is performed, when the first security protection mode is inconsistent with the second security protection mode, the CU-CP can further send an RRC reconfiguration message to the UE, and the RRC reconfiguration message does not carry the identifier of the first session. The RRC reconfiguration message is used to remove the data of the first session that is not supported.
[0255] Optionally, the step 408 can further comprise that the CU-CP notifies the UE by sending the identifier of the first session and / or the identifier of the bearer corresponding to the first session, so as to notify the UE to release the first session corresponding to the identifier of the first session, or release the bearer corresponding to the identifier of the first session. In an optional implementation, the CU-CP can notify the UE by releasing the session or the bearer.
[0256] The first CU-UP cannot support the second security protection mode corresponding to the first session. Optionally, the UE needs to transfer the data carried in the first session to other sessions. The UE and the CU-CP re-negotiate the security protection mode of the other session. For example, the CU-CP sends the first security protection mode supported by the first CU-UP to the UE, and the first CU-UP and the CU-CP use the first security protection mode to protect the data of the other session. The specific negotiation manner is the same as that of the foregoing embodiment, and details are not described herein. Figure 3
[0257] It should be noted that the step 408 is an optional step, and the step 408 can be executed after the step 406: when the CU-CP determines that the first security protection mode is inconsistent with the second security protection mode, the step 408 is executed (i.e., the step 407 is not executed). The step 408 can also be executed after the step 407: when the CU-CP reselects the CU-UP and the number of repetitions of the steps 403-405 reaches the first threshold value, and the CU-CP does not find the first CU-UP supporting the first security protection mode, the step 408 is executed. The first threshold value can be adjusted according to actual needs, for example, 5 or 8, etc. The first threshold value can also be represented as a ratio of the number of repetitions to the total number of CU-UPs managed by the CU-CP, for example, 30%, which means that when the number of repetitions of the CU-CP reaches 30% of the total number of CU-UPs managed by the CU-CP, the step 408 is executed.
[0258] 409. The CU-CP notifies the SMF that the data protection of the first session cannot be performed.
[0259] In this embodiment, similar to step 408, after step 406, when the first security protection manner is inconsistent with the second security protection manner, the CU-CP can also notify the SMF that the CU-UPs managed by the current CU-CP (except for the second CU-UP) cannot perform data protection of the first session using the second security protection manner.
[0260] In an optional implementation, the CU-CP can send a path switch message to the SMF to notify the SMF that data protection of the first session cannot be performed. The CU-CP can also send the path switch message to the AMF, and the AMF forwards the path switch message to the SMF, so that the SMF learns that data protection of the first session cannot be performed.
[0261] In another optional implementation, the CU-CP can send a path update message to the SMF to notify the SMF that data protection of the first session cannot be performed. The CU-CP can also send the path update message to the AMF, and the AMF forwards the path update message to the SMF, so that the SMF learns that data protection of the first session cannot be performed.
[0262] It should be noted that step 409 is an optional step, and step 409 can be executed after step 406: when the CU-CP determines that the first security protection manner is inconsistent with the second security protection manner, step 409 is executed (i.e., step 407 is not executed).
[0263] Step 409 can also be executed after step 407: when the CU-CP reselects the CU-UP and the number of repetitions of steps 403-405 reaches a first threshold, and the CU-CP does not find the first CU-UP supporting the first security protection manner, step 409 is executed. The first threshold can be adjusted according to actual needs, for example: 5 or 8, etc.; the first threshold can also be represented as a ratio of the number of repetitions to the total number of CU-UPs managed by the CU-CP, for example: 30%, which means that when the number of repetitions of the CU-CP reaches 30% of the total number of CU-UPs managed by the CU-CP, step 409 is executed.
[0264] 410、The SMF replies to the CU-CP with an acknowledgement message.
[0265] In this embodiment, after step 409, the SMF can reply to the CU-CP with an acknowledgement (ACK) message. The purpose is to notify the CU-CP that the SMF has learned that data protection of the first session cannot be performed.
[0266] Optionally, after recording the first security protection manner, the SMF replies to the CU-CP with an acknowledgement message.
[0267] It should be noted that steps 409-410 are optional steps.
[0268] In the embodiment of the application, when the security protection mode of the UE and the first CU-UP is inconsistent, the CU-CP can reselect the first CU-UP, and finally determine that the first CU-UP supports the second security protection mode. This is to ensure that the data between the UE and the first CU-UP in the future can be normally interacted under the protection of the second security protection mode, so as to improve the security of communication.
[0269] Please refer to Figure 5 , Figure 5 Another embodiment of a user plane centralized unit security processing method proposed in the embodiment of the application is shown in a schematic diagram, which comprises:
[0270] 501. The UE accesses the network.
[0271] 502. The CU-CP determines that the switching of the CU-UP needs to be initiated.
[0272] Steps 501-502 are the same as the aforementioned steps 301-302, and can refer to steps 301-302, which will not be described here again.
[0273] 503. The CU-CP determines the CU-UP supporting the second security protection mode.
[0274] In the embodiment, after step 502, when the CU-CP determines that the switching of the CU-UP needs to be initiated, the CU-CP determines which CU-UPs managed by the current CU-CP support the second security protection mode. Specifically, the CU-CP can determine the CU-UP supporting the second security protection mode in multiple ways, which will be described as follows:
[0275] A. Determine the CU-UP according to the second security protection mode.
[0276] When the second security protection mode is: performing integrity protection, and / or, performing confidentiality protection, the CU-UP supporting the second security protection mode is the CU-UP deployed in the high-security domain.
[0277] When the second security protection mode is: not performing integrity protection, and / or, not performing confidentiality protection, the CU-UP supporting the second security protection mode can be the CU-UP deployed in the high-security domain, or the CU-UP deployed in the low-security domain.
[0278] B. Determine the CU-UP according to whether the first session requires performing integrity protection, and / or, requires performing confidentiality protection.
[0279] When the first session requires integrity protection to be performed, and / or requires confidentiality protection to be performed, the CU-UP supporting the second security protection mode is determined to be the CU-UP deployed in the high-security domain.
[0280] When the first session requires integrity protection not to be performed, and / or requires confidentiality protection not to be performed, the CU-UP supporting the second security protection mode can be the CU-UP deployed in the high-security domain, or the CU-UP deployed in the low-security domain.
[0281] C. Determine the CU-UP according to the capability of the CU-UP.
[0282] When the second security protection mode is: integrity protection is performed, and / or confidentiality protection is performed, the CU-UP is screened and determined according to the capability of each CU-UP. The determined CU-UP supports integrity protection, and / or supports confidentiality protection.
[0283] When the second security protection mode is: integrity protection is not performed, and / or confidentiality protection is not performed, the CU-UP is screened and determined according to the capability of each CU-UP. The determined CU-UP can support integrity protection, and / or supports confidentiality protection; or can not support integrity protection, and / or not support confidentiality protection.
[0284] When the first session requires integrity protection to be performed, and / or requires confidentiality protection to be performed, the determined CU-UP supports integrity protection, and / or supports confidentiality protection.
[0285] When the first session requires integrity protection not to be performed, and / or requires confidentiality protection not to be performed, the determined CU-UP can support integrity protection, and / or supports confidentiality protection; or can not support integrity protection, and / or not support confidentiality protection.
[0286] In the embodiment, the determined CU-UP is referred to as the first CU-UP. In an optional implementation, when the CU-CP cannot determine the first CU-UP from the CU-UPs managed by the current CU-CP (or referred to as the CU-UPs associated with the current CU-CP), the foregoing steps 408, and / or steps 409 and 410 can be performed, which are not limited herein.
[0287] 504. The CU-CP sends the second security protection mode to the first CU-UP.
[0288] In the embodiment, the step 504 is the same as the foregoing step 403, and can refer to the step 403, which is not described herein again.
[0289] In an optional implementation, the CU-CP can send, to the first CU-UP, indication information of the second security protection mode, the indication information of the second security protection mode being used to inform the first CU-UP to perform the second security protection mode.
[0290] 505. The first CU-UP performs the second security protection mode.
[0291] In this embodiment, since it is determined in step 503 that the first CU-UP supports the second security protection mode. Therefore, after the first CU-UP receives the second security protection mode (or the indication information of the second security protection mode) from the CU-CP, the first CU-UP performs the second security protection mode. Specifically, the first CU-UP uses the second security protection mode to protect the first session between the first CU-UP and the UE.
[0292] 506. The first CU-UP sends, to the CU-CP, a BEARER CONTEXT SETUP Response message.
[0293] In this embodiment, the first CU-UP sends, to the CU-CP, a BEARER CONTEXT SETUP Response message, the BEARER CONTEXT SETUP Response message being used to inform the CU-CP that the first CU-UP performs the second security protection mode.
[0294] 507. When there is no CU-UP supporting the second security protection mode among the CU-UPs managed by the CU-CP, the CU-CP does not carry the identifier of the first session in the reconfiguration message sent to the UE.
[0295] In this embodiment, after step 503, when there is no CU-UP supporting the second security protection mode among the CU-UPs managed by the CU-CP, the CU-CP does not carry the identifier of the first session in the reconfiguration message sent to the UE.
[0296] Specifically, step 507 is the same as the aforementioned step 408, and can refer to step 408, which will not be described here.
[0297] 508. The CU-CP informs the SMF to update the transport network layer address information of the downlink.
[0298] In this embodiment, the CU-CP informs the SMF that the first session between the first CU-UP and the UE is protected by the second security protection mode. After receiving the notification, the SMF updates the transport network layer address information of the downlink, and the updated transport network layer address information of the downlink includes the address information of the first CU-UP.
[0299] In an optional implementation, the CU-CP can send a path switch message to the SMF to inform the SMF to update the transport network layer address information of the downlink. The CU-CP can also send the path switch message to the AMF, and the AMF forwards the path switch message to the SMF, so that the SMF updates the transport network layer address information of the downlink.
[0300] In another optional implementation, the CU-CP can send a path update message to the SMF to inform the SMF to update the transport network layer address information of the downlink. The CU-CP can also send the path update message to the AMF, and the AMF forwards the path update message to the SMF, so that the SMF updates the transport network layer address information of the downlink.
[0301] 509、The SMF replies an acknowledgement message to the CU-CP.
[0302] In this embodiment, after step 508, the SMF can reply an acknowledgement (ACK) message to the CU-CP. The purpose is to inform the CU-CP that the SMF has updated the transport network layer address information of the downlink.
[0303] It should be noted that steps 507-509 are optional steps.
[0304] In the embodiment of the application, the second CU-UP and the UE use the second security protection mode to perform data protection on the first session. The CU-CP determines a CU-UP supporting the second security protection mode from the CU-UPs managed by the CU-CP, and the CU-UP is referred to as the first CU-UP. Finally, the first CU-UP and the UE use the second security protection mode to perform data protection on the first session. This ensures that the data between the UE and the first CU-UP can be normally interacted under the protection of the second security protection mode, thereby improving the security of communication. Moreover, under the premise of ensuring the security of communication, the signaling interaction process between the UE and the network device is simplified, and the power consumption of the UE is reduced.
[0305] Please refer to Figure 6 , Figure 6 Another embodiment of a user plane centralized unit security processing method is provided in the embodiment of the application, and a schematic diagram of the method is shown in FIG. 6.
[0306] 601、The UE accesses the network.
[0307] 602、The CU-CP determines that the switching of the CU-UP needs to be initiated.
[0308] 603、The CU-CP sends a first security policy to the first CU-UP.
[0309] 604、The first CU-UP determines the first security protection mode.
[0310] 605、The first CU-UP sends the first security protection mode to the CU-CP.
[0311] 606、The CU-CP determines whether the first security protection mode is consistent with the second security protection mode.
[0312] Steps 601-606 are the same as the aforementioned steps 301-306, and can refer to steps 301-306, which will not be repeated here.
[0313] 607、The CU-CP reselects the CU-UP.
[0314] In this embodiment, when the CU-CP determines that the first security protection mode is inconsistent with the second security protection mode, the CU-CP reselects the CU-UP.
[0315] Specifically, the CU-CP selects any one of the remaining CU-UPs managed by itself as the first CU-UP, and repeatedly performs the related operations of steps 603-606 until the first security protection mode performed by the selected first CU-UP is consistent with the second security protection mode. Then, the first CU-UP and the UE perform data protection using the first security protection mode (at this time, the first security protection mode is equal to the second security protection mode).
[0316] In an optional implementation, when there is no CU-UP supporting the second security protection mode among the CU-UPs managed by the CU-CP (except for the second CU-UP), the CU-CP instructs the second CU-UP to continue to provide services for the UE. Specifically, the second CU-UP and the UE perform data protection on the first session using the second security protection mode.
[0317] 608、When inconsistent, the CU-CP does not carry the identifier of the first session in the reconfiguration message sent to the UE.
[0318] 609、The CU-CP notifies the SMF that the data protection of the first session cannot be performed.
[0319] 610、The SMF replies to the CU-CP with an acknowledgement message.
[0320] Steps 608-610 are the same as the aforementioned steps 408-410, and can refer to steps 408-410, which will not be repeated here.
[0321] It should be noted that steps 607-610 are optional steps.
[0322] In the embodiment of the application, the CU-CP can send a first security policy to the first CU-UP, and the first CU-UP sends a second security protection mode to the CU-CP according to the first security policy. When the security protection mode of the UE and the first CU-UP is inconsistent, the CU-CP can reselect the first CU-UP, and finally determine that the first CU-UP supports the second security protection mode. In this way, the data between the UE and the first CU-UP can be normally interacted under the protection of the second security protection mode, so as to improve the security of communication.
[0323] In Figures 3-6 On the basis of the embodiment shown in the figure, when the CU-CP determines that the first CU-UP is deployed in a low security domain, a new key can be derived to ensure the security of data. For details, please refer to Figure 7 , Figure 7 Another embodiment of a user plane centralized unit security processing method is provided in the embodiment of the application, and the method comprises the following steps of:
[0324] 701. The UE accesses the network.
[0325] 702. The CU-CP determines that the handover of the CU-UP needs to be initiated.
[0326] Steps 701 to 702 are the same as steps 301 to 302 described above, and can refer to steps 301 to 302, which will not be described here again.
[0327] 703. When the first CU-UP is deployed in a low security domain, or is determined to belong to the low security domain according to a local policy, the CU-CP determines that the key needs to be derived.
[0328] In the embodiment, when the first CU-UP determined by the CU-CP is deployed in a low security domain, or the local policy of the CU-CP indicates that the key needs to be derived when the CU-UP is switched, or the first CU-UP is determined to belong to the low security domain according to the local policy or the current policy, the local policy is configured to the CU-CP by other network functions or is preconfigured in the CU-CP.
[0329] Specifically, the process of deriving the key by the CU-CP is as follows:
[0330] In an optional implementation, the CU-CP generates an encryption key K1 and / or an integrity protection key K2 using a derivation parameter and an intermediate key KgNB. Optionally, the derivation parameter is associated with the first CU-UP, and the encryption key K1 and / or the integrity protection key K2 are referred to as derived keys.
[0331] Optionally, the derivation parameters can comprise a fresh parameter (e.g., RRC counter, random number, etc.), an identity of the first CU-UP for binding the first CU-UP, routing information of the first CU-UP, e.g., IP address, media access control (MAC) address, etc., a cell ID or a cell group ID for binding the derived key, a cell corresponding to the cell ID or a cell group corresponding to the cell group ID, spectrum information of a primary cell (Pcell), e.g., Absolute Radio Frequency Channel Number (ARFCN) or ARFCN-DL, for binding the spectrum information, an encryption algorithm identity or an integrity protection algorithm identity, an encryption algorithm type or an integrity protection algorithm type.
[0332] In another optional implementation, the CU-CP generates the first encryption key K1a and / or the first integrity protection key K2a using the intermediate key KgNB and the derivation parameters;
[0333] The CU-CP generates the encryption key K1 and / or the integrity protection key K2 using the derivation parameters and the first encryption key K1a.
[0334] The CU-CP generates the encryption key K1 and / or the integrity protection key K2 using the derivation parameters and the first encryption key K1a.
[0335] The encryption key K1 and / or the integrity protection key K2 are referred to as the derived key.
[0336] Optionally, the derivation parameters can comprise a fresh parameter (e.g., RRC counter, random number, etc.), an identity of the first CU-UP for binding the first CU-UP, routing information of the first CU-UP, e.g., IP address, media access control (MAC) address, etc., a cell ID or a cell group ID for binding the derived key, a cell corresponding to the cell ID or a cell group corresponding to the cell group ID, spectrum information of a primary cell (Pcell), e.g., Absolute Radio Frequency Channel Number (ARFCN) or ARFCN-DL, for binding the spectrum information.
[0337] In another optional implementation, the CU-CP generates the encryption key K1 and / or the integrity protection key K2 using the intermediate key KgNB and the derivation parameters;
[0338] The CU-CP generates a second encryption key K1b using the encryption key K1;
[0339] The CU-CP generates a second integrity protection key K2b using the integrity protection key K2.
[0340] The second encryption key K1b and / or the second integrity protection key K2b is referred to as a derived key.
[0341] 704. The CU-CP sends the derived key and / or the derivation parameter to the first CU-UP.
[0342] In this embodiment, the CU-CP sends the derived key and / or the derivation parameter to the first CU-UP.
[0343] Optionally, the CU-CP sends the derived key to the first CU-UP through a bearer context setup response message.
[0344] Optionally, the CU-CP can also send the first encryption key K1a and / or the first integrity protection key K2a to the first CU-UP, so that the first CU-UP continues to derive the key using the first encryption key K1a and / or the first integrity protection key K2a, and finally generates the second encryption key K1b and / or the second integrity protection key K2b.
[0345] Optionally, the derivation parameter can include a freshness parameter (for example, an RRC counter, a random number, etc.), an identifier of the first CU-UP for binding the first CU-UP, routing information of the first CU-UP, such as an IP address, a media access control (MAC) address, etc., a cell ID or a cell group ID for binding the derived key to a cell corresponding to the cell ID or a cell group corresponding to the cell group ID, and spectrum information of a primary cell (Pcell), such as an Absolute Radio Frequency Channel Number (ARFCN) or an ARFCN-DL, for binding the spectrum information.
[0346] In another optional implementation, the CU-CP sends a derivation indication to the first CU-UP, where the derivation indication is used to instruct the first CU-UP to derive a new key, for example: the CU-CP generates an encryption key K1 and / or an integrity protection key K2 using an intermediate key KgNB and a derivation parameter; the CU-UP generates a second encryption key K1b using the encryption key K1; and the CU-UP generates a second integrity protection key K2b using the integrity protection key K2.
[0347] 705、The first CU-UP performs protection using the derived key.
[0348] In an optional implementation, when the first CU-UP receives the derived key, the first CU-UP performs protection using the derived key.
[0349] In another optional implementation, when the first CU-UP receives the encryption key K1, and / or, the integrity protection key K2. The first CU-UP continues to derive the key using the received derivation parameters. Finally, the first CU-UP derives the first encryption key K1a, and / or, the first integrity protection key K2a. The first CU-UP performs protection using the first encryption key K1a, and / or, the first integrity protection key K2a.
[0350] In another optional implementation, when the first CU-UP receives the first encryption key K1a, and / or, the first integrity protection key K2a. The first CU-UP continues to derive the key using the received derivation parameters. Finally, the first CU-UP derives the second encryption key K1b, and / or, the second integrity protection key K2b. The first CU-UP performs protection using the second encryption key K1b, and / or, the second integrity protection key K2b.
[0351] 706、The first CU-UP sends the derivation parameters to the CU-CP.
[0352] In this embodiment, the first CU-UP sends the derivation parameters to the CU-CP, if needed, so that the CU-CP sends the derivation parameters to the UE.
[0353] It should be noted that step 706 is an optional step.
[0354] 707、The CU-CP sends the derivation indication and / or the derivation parameters to the UE.
[0355] In this embodiment, the CU-CP sends the derivation indication, and / or, the derivation parameters to the UE. The derivation indication is used to instruct the UE to derive the related key using the derivation parameters.
[0356] Optionally, the CU-CP sends the derivation indication, and / or, the derivation parameters to the UE through an RRC reconfiguration message.
[0357] Optionally, the derivation parameter can comprise a fresh parameter (e.g., RRC counter, random number, etc.), an identity of the first CU-UP, a routing information of the first CU-UP, e.g., IP address, media access control (MAC) address, etc., a cell ID or a cell group ID, a spectrum information of a primary cell (Pcell), e.g., Absolute Radio Frequency Channel Number (ARFCN) or ARFCN-DL.
[0358] In another optional implementation, if the UE has one or more of the derivation parameters or can obtain one or more of the derivation parameters by itself, the CU-CP can not send the one or more of the derivation parameters.
[0359] 708、The UE derives the key using the derivation parameter.
[0360] In an optional implementation, the UE generates an encryption key K1 and / or an integrity protection key K2 using the derivation parameter and the intermediate key KgNB, the derivation parameter being associated with the first CU-UP, the encryption key K1 and / or the integrity protection key K2 being referred to as a derived key.
[0361] In another optional implementation, the UE generates a first encryption key K1a and / or a first integrity protection key K2a using the intermediate key KgNB;
[0362] The UE generates the encryption key K1 using the derivation parameter and the first encryption key K1a.
[0363] The UE generates the integrity protection key K2 using the derivation parameter and the first integrity protection key K2a.
[0364] The encryption key K1 and / or the integrity protection key K2 are referred to as a derived key.
[0365] In another optional implementation, the UE generates the encryption key K1 and / or the integrity protection key K2 using the intermediate key KgNB and the derivation parameter;
[0366] The UE generates a second encryption key K1b using the encryption key K1.
[0367] The UE generates a second integrity protection key K2b using the integrity protection key K2.
[0368] The second encryption key K1b and / or the second integrity protection key K2b is referred to as a derived key.
[0369] 709、The UE sends a response message to the CU-CP.
[0370] In this embodiment, the UE sends a response message to the CU-CP. Optionally, the UE sends a response message to the CU-CP through an RRC reconfiguration complete message, and the response message is used to inform the CU-CP that the UE has completed the key derivation process.
[0371] In the case of switching the CU-UP, the second CU-UP and the UE can update the key in the embodiment of the application, so as to ensure that the original CU-UP (the first CU-UP) cannot read the encrypted data between the second CU-UP and the UE, improve the security of the data, and meet the backward security.
[0372] In the case of switching the CU-UP, the second CU-UP and the UE can update the key in the embodiment of the application, so as to ensure that the original CU-UP (the first CU-UP) cannot read the encrypted data between the second CU-UP and the UE, improve the security of the data, and meet the backward security. Figures 3-7 On the basis of the embodiment shown in the figure, the first CU-UP can also derive the intermediate key KgNB to improve the security of the data. For details, please refer to Figure 8 , Figure 8 Another embodiment of a user plane centralized unit security processing method proposed in the embodiment of the application is shown in the figure, which includes the following steps:
[0373] 801、The UE accesses the network.
[0374] 802、The CU-CP determines that the switching of the CU-UP needs to be initiated.
[0375] Steps 801-802 are the same as steps 301-302 described above, and reference can be made to steps 301-302, which will not be described here again.
[0376] 803、When the first CU-UP is deployed in a low-security domain, or the CU-CP determines that the first CU-UP belongs to a low-security domain according to a local policy or a current policy, the CU-CP determines that the intermediate key KgNB needs to be derived.
[0377] In this embodiment, when the first CU-UP is deployed in a low-security domain, the CU-CP triggers the key derivation process. Specifically, the CU-CP derives the intermediate key KgNB to obtain a derived intermediate key KgNB. The CU-CP derives the encryption key and / or the integrity protection key according to the newly derived intermediate key KgNB.
[0378] It should be noted that the specific method for the CU-CP to determine whether the first CU-UP is deployed in a low-security domain is the same as the method described in step 303 described above, which will not be described here again.
[0379] 804. The CU-CP sends the encryption key and / or the integrity protection key to the first CU-UP.
[0380] In this embodiment, the CU-CP sends the encryption key and / or the integrity protection key to the first CU-UP through a BEARER CONTEXT SETUP REQUEST message.
[0381] 805. The first CU-UP sends a response message to the CU-CP.
[0382] In this embodiment, the first CU-UP sends the response message to the CU-CP after receiving the encryption key and the integrity protection key from the CU-CP. Optionally, the first CU-UP sends the response message through a BEARER CONTEXT SETUP RESPONSE message.
[0383] 806. The CU-CP sends an indication of deriving KgNB to the UE.
[0384] In this embodiment, the CU-CP sends the indication of deriving KgNB to the UE through an RRC reconfiguration message or an Access Stratum (AS) security mode command message.
[0385] 807. The UE derives the intermediate key KgNB according to the indication of deriving KgNB.
[0386] It should be noted that the above steps 803-807 can be performed in the scenario of switching the UE from the first CU-UP to the second CU-UP, for example, the above steps 803-807 are synchronously performed in the process of switching the UE from the first CU-UP to the second CU-UP.
[0387] The above steps 803-807 can also be performed in the scenario of switching the UE from the first CU-UP to the second CU-UP, at any time after the UE has been switched to the second CU-UP.
[0388] In the embodiments of the present application, when the CU-UP switching scenario occurs, the intermediate key KgNB can be updated to ensure that the second CU-UP cannot read the encrypted data between the first CU-UP and the UE, thereby improving the security of the data and meeting the forward security.
[0389] In addition, in addition to triggering the KgNB update in the handover process, it is also possible to trigger the KgNB update after the completion of the handover, when the first CU-UP selected in the handover process is deployed in a low-security domain, or the CU-CP determines that the first CU-UP belongs to a low-security domain according to a local policy or according to a current policy, the CU-CP determines that the intermediate key KgNB needs to be derived, and then performs the above-mentioned pushing action to complete the update of the AS security context. The advantage here is that it can also ensure that the second CU-UP cannot read the encrypted data between the first CU-UP and the UE, improving the security of the data and meeting the forward security. The KgNB update triggered in the handover process and the KgNB update triggered after the completion of the handover are two independent mechanisms. They can be deployed separately or executed in one process.
[0390] In Figures 3-8 On the basis of the embodiment shown in the figure, please refer to Figure 9 , Figure 9 Another embodiment of a user plane centralized unit security processing method proposed by the embodiment is shown in the figure, which includes the following steps:
[0391] 901, the UE accesses the network.
[0392] In this embodiment, the UE accesses the network. In an optional implementation, the specific access process is as follows:
[0393] A1, the UE sends an RRC setup request (RRCSetupRequest) message to the DU;
[0394] A2, the DU sends an initial uplink RRC message transmission (INITIAL UL RRC MESSAGE TRANSFER) message to the CU-CP;
[0395] A3, the CU-CP sends a downlink RRC message transmission (DL RRC MESSAGE TRANSFER) message to the DU;
[0396] A4, the DU sends an RRC setup (RRCSetup) message to the UE;
[0397] A5, the UE sends an RRC setup complete (RRCSetupComplete) message to the DU;
[0398] A6, the DU sends an uplink RRC message transmission (UL RRC MESSAGE TRANSFER) message to the CU-CP;
[0399] A7, the CU-CP sends an initial terminal context (INITIAL UE MESSAGE) message to the AMF;
[0400] The A8, AMF sends an initial context setup request (INITIAL CONTEXT SETUP REQUEST) message to the CU-CP.
[0401] 902、Initialize to select the CU-UP.
[0402] In an optional implementation manner in the embodiment, the CU-CP determines the CU-UP according to the security policy of the second session and the security domain corresponding to each CU-UP managed by the CU-CP. The first session is a session between the CU-UP and the UE that needs data protection.
[0403] In another optional implementation manner, the CU-CP determines the CU-UP according to the capability of each CU-UP managed by the CU-CP.
[0404] Specifically as follows:
[0405] A, determine the CU-UP according to the security policy of the first session.
[0406] The security protection manner used by the CU-UP and the UE is the third security protection manner. Specifically, the CU-UP and the UE use the third security protection manner to protect the data of the second session.
[0407] When the security policy of the second session is to perform integrity protection and / or to perform confidentiality protection, the determined CU-UP is the CU-UP deployed in the high-security domain.
[0408] When the security policy of the second session is not to perform integrity protection and / or not to perform confidentiality protection, the determined CU-UP can be the CU-UP deployed in the high-security domain or the CU-UP deployed in the low-security domain.
[0409] When the security policy of the second session is to preferentially perform integrity protection and / or to preferentially not perform confidentiality protection, the CU-CP can determine the CU-UP according to the local policy, for example, the CU-UP determined by the CU-CP can be the CU-UP deployed in the high-security domain or the CU-UP deployed in the low-security domain.
[0410] B, determine the CU-UP according to the capability of the CU-UP.
[0411] When the third security protection manner is to perform integrity protection and / or to perform confidentiality protection, the CU-UP is screened and determined according to the capability of each CU-UP. The determined CU-UP supports integrity protection and / or supports confidentiality protection.
[0412] When the third security protection mode is: integrity protection is not performed, and / or, confidentiality protection is not performed. Then, according to the capability of each CU-UP, the CU-UP is screened and determined. The determined CU-UP can support integrity protection, and / or, support confidentiality protection; or can not support integrity protection, and / or, not support confidentiality protection.
[0413] When the second session requires integrity protection to be performed, and / or, requires confidentiality protection to be performed. Then, the determined CU-UP supports integrity protection, and / or, supports confidentiality protection.
[0414] When the second session requires integrity protection not to be performed, and / or, requires confidentiality protection not to be performed. Then, the determined CU-UP can support integrity protection, and / or, supports confidentiality protection; or can not support integrity protection, and / or, not support confidentiality protection.
[0415] 903、When the CU-UP is a CU-UP deployed in a low security domain, the CU-CP derives a key.
[0416] 904、The CU-CP sends the derived key to the CU-UP.
[0417] 905、The CU-UP uses the derived key for data protection.
[0418] 906、The CU-CP sends the derived key to the UE.
[0419] 907、The UE uses the derived key for data protection.
[0420] It should be noted that steps 903-907 are the same as the aforementioned steps 703-709, and can refer to steps 703-709, which will not be described here.
[0421] 908、The UE continues to complete the access network procedure.
[0422] In this embodiment, the UE continues to complete the access network procedure. It should be noted that step 908 can be performed at any time after step 902.
[0423] Optionally, the access network procedure in step 908 includes:
[0424] A9、The CU-UP sends a BEARER CONTEXT SETUP RESPONSE message to the CU-CP;
[0425] A10、The CU-CP sends a UE CONTEXT SETUP REQUEST message to the DU;
[0426] A11, the DU sends a SecurityModeCommand message to the UE;
[0427] A12, the DU sends a UE CONTEXT SETUP RESPONSE message to the CU-CP;
[0428] A13, the CU-CP sends a BEARER CONTEXT MODIFICATION REQUES message to the CU-UP;
[0429] A14, the CU-UP sends a BEARER CONTEXT MODIFICATION RESPONSE message to the CU-CP;
[0430] A15, the UE sends a SecurityModeComplete message to the DU;
[0431] A16, the DU sends a UL RRC MESSAGE TRANSFER message to the CU-CP;
[0432] A17, the CU-CP sends a DL RRC MESSAGE TRANSFER message to the DU;
[0433] A18, the DU sends a RRCReconfiguration message to the UE;
[0434] A19, the UE sends a RRCReconfigurationComplete message to the DU;
[0435] A20, the DU sends a UL RRC MESSAGE TRANSFER message to the CU-CP;
[0436] A21, the DU sends an INITIAL CONTEXT SETUP RESPONSE message to the CU-CP.
[0437] In the embodiments of the present application, in the scenario of UE accessing the network, the CU-CP can select the CU-UP deployed in different security domains to provide services for the UE according to the requirements, so as to meet different business requirements.
[0438] The above mainly introduces the scheme provided by the embodiments of the present application from the perspective of method. It can be understood that the communication device includes hardware structure and / or software module corresponding to the execution of each function in order to realize the above functions. Those skilled in the art should easily realize that the modules and algorithm steps of each example described in combination with the embodiments disclosed in the present application can be realized in the form of hardware or combination of hardware and computer software. Whether a certain function is realized in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. The skilled person can use different methods to realize the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0439] The embodiments of the present application can divide the function modules of the communication device according to the above method examples. For example, each function module can be divided corresponding to each function, or two or more functions can be integrated in one processing module. The integrated module can be realized in the form of hardware or software function module. It should be noted that the division of modules in the embodiments of the present application is illustrative, and is only a logical function division. Actual implementation can have another division manner.
[0440] The communication device in the present application will be described in detail below. Please refer to Figure 10 , Figure 10 FIG. 1 is a schematic diagram of an embodiment of the communication device in the present application. The communication device can be deployed in a network device, and the communication device includes:
[0441] The transceiver module 1001 is configured to send a first security policy to a first user plane centralized unit CU-UP.
[0442] The transceiver module 1001 is further configured to receive a first security protection mode sent by the first CU-UP, and the first security protection mode is a security protection mode determined by the first CU-UP.
[0443] The processing module 1002 is configured to determine whether the first security protection mode is consistent with a second security protection mode, wherein the second security protection mode is a security protection mode used by the terminal device and the second CU-UP for data protection.
[0444] The transceiver module 1001 is further configured to, when the processing module 1002 determines that the first security protection mode is not consistent with the second security protection mode,
[0445] The transceiver module 1001 is further configured to send the first security protection mode to the terminal device, wherein the first security protection mode is a security protection mode used by the terminal device and the first CU-UP for data protection.
[0446] In some optional embodiments of the present application,
[0447] The transceiver 1001 is further configured to, if the first security protection manner and the second security protection manner are different, notify the session management function SMF that the first CU-UP uses the first security protection manner.
[0448] Alternatively,
[0449] The transceiver 1001 is further configured to, if the first security protection manner and the second security protection manner are different, notify the SMF that protection of the first session cannot be performed, and the first session is a session in which the terminal device and the second CU-UP perform data protection using the second security protection manner.
[0450] In some optional embodiments of the present application, the first security policy comprises:
[0451] Confidentiality protection needs to be performed, or is inclined to be performed, or does not need to be performed;
[0452] Integrity protection needs to be performed, or is inclined to be performed, or does not need to be performed.
[0453] In some optional embodiments of the present application, the first security protection manner or the second security protection manner comprises:
[0454] Whether to perform user plane confidentiality protection; whether to perform user plane integrity protection.
[0455] In some optional embodiments of the present application,
[0456] The processing module 1002 is further configured to determine, according to the test report, that switching from the second CU-UP to the first CU-UP is needed.
[0457] Alternatively,
[0458] The processing module 1002 is further configured to determine, according to the local policy, that switching from the second CU-UP to the first CU-UP is needed.
[0459] Please refer to Figure 11 , Figure 11 is a schematic diagram of an embodiment of a communication apparatus in the embodiments of the present application. The communication apparatus comprises:
[0460] The transceiver 1101 is configured to receive user plane policy change indication information sent by a centralized unit CU-CP in a management plane, and the user plane policy change indication information comprises a first security protection manner;
[0461] The processing module 1102 is configured to activate security protection between the terminal device and the second CU-UP according to the first security protection manner.
[0462] In some optional embodiments of the present application,
[0463] The processing module 1102 is further configured to delete the second security protection mode, the second security protection mode being a security protection mode between the terminal device and the first CU-UP.
[0464] In some optional embodiments of the present application, the first security protection mode or the second security protection mode comprises:
[0465] Whether to perform user plane confidentiality protection; whether to perform user plane integrity protection.
[0466] In some optional embodiments of the present application, the user plane policy change indication information carries a bit or a field.
[0467] The communication apparatus in the above embodiments can be a network device, or a chip or other combination device or component applied in the network device and capable of implementing the functions of the network device. When the communication apparatus is the network device, the receiving module and the sending module can be a transceiver, which can include an antenna and a radio frequency circuit, and the processing module can be a processor, such as a baseband chip. When the communication apparatus is a component with the functions of the network device, the receiving module and the sending module can be a radio frequency unit, and the processing module can be a processor. When the communication apparatus is a chip system, the receiving module can be an input port of the chip system, the sending module can be an output interface of the chip system, and the processing module can be a processor of the chip system, such as a central processing unit (CPU).
[0468] The communication apparatus in the above embodiments can be a terminal device, or a chip or other combination device or component applied in the terminal device and capable of implementing the functions of the terminal device. When the terminal device is the terminal device, the receiving module and the sending module can be a transceiver, which can include an antenna and a radio frequency circuit. When the terminal device is a component with the functions of the terminal device, the receiving module and the sending module can be a radio frequency unit.
[0469] In the embodiments of the present application, the memory included in the network device or the terminal device is mainly used for storing software programs and data, for example, storing the first security policy, the first security protection mode or the second security protection mode described in the above embodiments.
[0470] Please refer to Figure 12 , Figure 12 This is another embodiment of the communication apparatus in the embodiments of the present application. The communication apparatus can be deployed in a network device, and the communication apparatus further has the following functions:
[0471] The transceiver 1201 is configured to send a first security policy to a first user plane centralized unit (CU-UP).
[0472] The transceiver 1201 is further configured to receive a first security protection mode sent by the first CU-UP, where the first security protection mode is a security protection mode determined by the first CU-UP.
[0473] The processor 1202 is configured to determine whether the first security protection mode is consistent with a second security protection mode, where the second security protection mode is a security protection mode used by the terminal device for data protection with a second CU-UP.
[0474] The transceiver 1201 is further configured to, when the processor 1202 determines that the first security protection mode is not consistent with the second security protection mode,
[0475] The transceiver 1201 is further configured to send the first security protection mode to the terminal device, where the first security protection mode is a security protection mode used by the terminal device for data protection with the first CU-UP.
[0476] In some optional embodiments of the present application,
[0477] The transceiver 1201 is further configured to, if the first security protection mode and the second security protection mode are different, notify a session management function (SMF) that the first CU-UP uses the first security protection mode.
[0478] Alternatively,
[0479] The transceiver 1201 is further configured to, if the first security protection mode and the second security protection mode are different, notify the SMF that protection of a first session cannot be performed, where the first session is a session in which the terminal device uses the second security protection mode for data protection with the second CU-UP.
[0480] In some optional embodiments of the present application, the first security policy includes:
[0481] Confidentiality protection needs to be performed, or confidentiality protection tends to be performed, or confidentiality protection does not need to be performed;
[0482] Integrity protection needs to be performed, or integrity protection tends to be performed, or confidentiality protection does not need to be performed.
[0483] In some optional embodiments of the present application, the first security protection mode or the second security protection mode includes:
[0484] Whether to perform user plane confidentiality protection; whether to perform user plane integrity protection.
[0485] In some optional embodiments of the present application,
[0486] The processor 1202 is further configured to determine, according to the test report, that the second CU-UP needs to be switched to the first CU-UP.
[0487] Or,
[0488] The processor 1202 is further configured to determine, according to the local policy, that the second CU-UP needs to be switched to the first CU-UP.
[0489] Please refer to Figure 13 , Figure 13 This is a schematic diagram of another embodiment of a communication device in the embodiments of the present application. The communication device can be deployed in a terminal device, and the communication device also has the following functions:
[0490] The transceiver 1301 is configured to receive user plane policy change indication information sent by a centralized unit CU-CP in a management plane, and the user plane policy change indication information includes a first security protection mode.
[0491] The processor 1302 is configured to activate security protection between the terminal device and a second CU-UP according to the first security protection mode.
[0492] In some optional embodiments of the present application,
[0493] The processor 1302 is further configured to delete a second security protection mode, which is a security protection mode between the terminal device and the first CU-UP.
[0494] In some optional embodiments of the present application, the first security protection mode or the second security protection mode includes:
[0495] Whether to perform user plane confidentiality protection; whether to perform user plane integrity protection.
[0496] In some optional embodiments of the present application, the user plane policy change indication information carries a bit or a field.
[0497] It should be noted that the information interaction, execution process, and the like between the modules and / or components of the communication device are the same as those of the communication device in the embodiments of the present application. Figures 3-9 The corresponding method embodiments are based on the same concept, and specific contents can be referred to the descriptions of the method embodiments in the foregoing embodiments of the present application, which will not be described here.
[0498] The embodiments of the present application also provide a processing device, please refer to Figure 14 , Figure 14 This is a schematic diagram of a processing device according to the embodiments of the present application. The processing device includes an interface 1401 and a processor 1402; the processor 1402 is configured to execute the user plane centralized unit security processing method of any of the method embodiments.
[0499] It should be understood that the above processing device can be a chip, and the processor can be implemented by hardware or software. When implemented by hardware, the processor can be a logic circuit, an integrated circuit, etc. When implemented by software, the processor can be a general-purpose processor, which realizes by reading software codes stored in a memory. The memory can be integrated in the processor or exist independently outside the processor.
[0500] The "implemented by hardware" means that the functions of the above modules or units are implemented by a hardware processing circuit without program instruction processing function. The hardware processing circuit can be composed of discrete hardware components or integrated circuits. In order to reduce power consumption and size, the integrated circuit is usually used to implement. The hardware processing circuit can include ASIC (application-specific integrated circuit) or PLD (programmable logic device). The PLD can include FPGA (field programmable gate array), CPLD (complex programmable logic device) and the like. The hardware processing circuit can be a semiconductor chip packaged separately (such as an ASIC); or can be packaged together with other circuits (such as CPU, DSP) to form a semiconductor chip, for example, a plurality of hardware circuits and CPU can be formed on a silicon base and packaged into a chip. Such a chip is also called SoC, or the circuit for realizing the function of FPGA and CPU can be formed on the silicon base and packaged into a chip. Such a chip is also called SoPC (system on a programmable chip).
[0501] The application also provides a communication system, including a terminal device and a network device.
[0502] The application also provides a computer readable storage medium, including instructions, when running on a computer, causing the computer to control the network device (CU-CP) to perform:
[0503] Step A: the CU-CP is configured to send a first security policy to a first user plane centralized unit CU-UP;
[0504] Step B: the CU-CP is further configured to receive a first security protection mode sent by the first CU-UP, wherein the first security protection mode is a security protection mode determined by the first CU-UP;
[0505] Step C: The CU-CP is configured to determine whether the first security protection manner is consistent with a second security protection manner, wherein the second security protection manner is a security protection manner used by the terminal device and the second CU-UP for data protection;
[0506] Step D: The CU-CP is further configured to send the first security protection manner to the terminal device when the CU-CP determines that the first security protection manner is inconsistent with the second security protection manner, wherein the first security protection manner is a security protection manner used by the terminal device and the first CU-UP for data protection.
[0507] Step E: The CU-CP is further configured to notify a session management function (SMF) that the first CU-UP uses the first security protection manner if the first security protection manner and the second security protection manner are different.
[0508] Alternatively,
[0509] Step F: The CU-CP is further configured to notify the SMF that protection of a first session cannot be performed if the first security protection manner and the second security protection manner are different, wherein the first session is a session in which the terminal device and the second CU-UP use the second security protection manner for data protection.
[0510] In some optional embodiments of the present application, the first security policy comprises:
[0511] Confidentiality protection needs to be performed, or is inclined to be performed, or does not need to be performed;
[0512] Integrity protection needs to be performed, or is inclined to be performed, or does not need to be performed.
[0513] In some optional embodiments of the present application, the first security protection manner or the second security protection manner comprises:
[0514] Whether to perform user plane confidentiality protection; whether to perform user plane integrity protection.
[0515] Step G: The CU-CP is further configured to determine that switching from the second CU-UP to the first CU-UP is needed according to a test report.
[0516] Alternatively,
[0517] Step H: The CU-CP is further configured to determine that switching from the second CU-UP to the first CU-UP is needed according to a local policy.
[0518] The embodiment of the present application also provides a computer readable storage medium, comprising instructions, when the instructions are executed on a computer, the computer controls a terminal device to execute the following steps:
[0519] Step I: the terminal device is configured to receive user plane policy change indication information sent by a CU-CP in a management plane centralized unit, wherein the user plane policy change indication information comprises a first security protection mode;
[0520] Step J: the terminal device is configured to activate security protection between the terminal device and the second CU-UP according to the first security protection mode.
[0521] Step K: the terminal device is further configured to delete a second security protection mode, wherein the second security protection mode is a security protection mode between the terminal device and the first CU-UP.
[0522] In some optional embodiments of the present application, the first security protection mode or the second security protection mode comprises:
[0523] whether to perform user plane confidentiality protection; whether to perform user plane integrity protection.
[0524] In some optional embodiments of the present application, the user plane policy change indication information carries a bit or a field.
[0525] The embodiment of the present application also provides a computer program product, the computer program product comprises computer program code, when the computer program code is executed on a computer, the computer executes the above steps A-D, and / or, steps E-F, and / or, steps G-H, and / or, steps I-K.
[0526] The embodiment of the present application also provides a chip, comprising a memory and a processor, the memory is configured to store a computer program, and the processor is configured to call and run the computer program from the memory, so that the chip executes the above steps A-D, and / or, steps E-F, and / or, steps G-H, and / or, steps I-K.
[0527] The embodiment of the present application also provides a chip, comprising a processor, the processor is configured to call and run a computer program, so that the chip executes steps A-D, and / or, steps E-F, and / or, steps G-H, and / or, steps I-K.
[0528] It should be noted that the apparatus embodiments described above are merely illustrative, and the units described as separate units can or can not be physically separate, and the units displayed as units can or can not be physical units, i.e., can be located in one place, or can be distributed to multiple network units. Part or all of the modules can be selected according to actual needs to achieve the purpose of the embodiment. In addition, the connection relationship between the modules in the apparatus embodiment provided in the present application indicates that there is a communication connection between them, which can be implemented as one or more communication buses or signal lines.
[0529] Through the description of the above embodiments, those skilled in the art can clearly understand that the present application can be realized by means of software and the necessary general hardware, and of course can also be realized by special hardware including special integrated circuits, special CPUs, special memories, special components, etc. Generally, functions completed by computer programs can be easily realized by corresponding hardware, and the specific hardware structure for realizing the same function can also be various, such as analog circuit, digital circuit or special circuit, etc. However, for the present application, software program implementation is a better embodiment. Based on such understanding, the technical solutions of the present application can be embodied in the form of software products, and the computer software product is stored in a readable storage medium, such as a computer floppy disk, U disk, mobile hard disk, ROM, RAM, magnetic disk or optical disk, etc., including a plurality of instructions to make a computer device execute the method described in each embodiment of the present application.
[0530] In the above embodiments, all or part can be realized by software, hardware, firmware or any combination thereof. When realized by software, it can be realized in the form of a computer program product in whole or in part.
[0531] The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on the computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another, for example, the computer instructions can be transmitted from one website, computer, communication device, computing device or data center to another website, computer, communication device, computing device or data center through wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.) mode. The computer-readable storage medium can be any available medium that the computer can store or be integrated into a communication device, data center, etc. data storage device including one or more available media. The available media can be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a DVD), or a semiconductor medium (for example, a solid state disk (SSD)), etc.
[0532] It should be understood that the "one embodiment" or "an embodiment" mentioned throughout the specification means that the specific features, structures or characteristics related to the embodiment are included in at least one embodiment of the present application. Therefore, "in one embodiment" or "in an embodiment" appearing throughout the specification does not necessarily refer to the same embodiment. In addition, these specific features, structures or characteristics can be combined in one or more embodiments in any suitable manner. It should be understood that the size of the sequence number of each process described above does not mean the order of execution, and the execution order of each process should be determined according to its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0533] Those of ordinary skill in the art can realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be realized in electronic hardware, computer software or a combination of both. In order to clearly illustrate the interchangeability of hardware and software, the components and steps of each example have been described in the above description in general terms. Whether the functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0534] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the system, device and unit described above can refer to the corresponding process in the foregoing method embodiments, which will not be described here.
[0535] In several embodiments provided in the present application, it should be understood that the disclosed system, device and method can be implemented in other manners. For example, the division of the above-described device embodiment is merely an example, and there can be other division manners. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections between different units, or the among different units, can be indirect couplings or communication connections through some interfaces, devices or units, and can be in electric, mechanical or other forms.
[0536] The unit described as a separate component can or can not be physically separate, and the component shown as a unit can or can not be a physical unit, i.e., can be located in one place, or can be distributed on multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the embodiment.
[0537] In addition, each functional unit in the various embodiments of the present application can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware, or in the form of a software functional unit.
[0538] When the integrated unit is realized in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer readable storage medium. Based on such an understanding, the technical solutions of the present application essentially or the part that makes a contribution to the prior art, or all or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in the various embodiments of the present application.
[0539] In summary, the above descriptions are merely preferred embodiments of the technical solutions of the present application, but are not intended to limit the protection scope of the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principles of the present application shall be included in the protection scope of the present application.
Claims
1. A method for security processing of a user plane function (UPF) central unit (CU), the method comprising: The method is applied to a scenario in which a terminal device switches from a second user plane centralized unit (CU-UP) to a first CU-UP, and the method comprises the following steps: a management plane centralized unit (CU-CP) sends a first security policy to a first user plane centralized unit (CU-UP), wherein the first security policy is used to indicate a confidentiality protection requirement and / or an integrity protection requirement, the confidentiality protection requirement comprises no need to perform confidentiality protection, and the integrity protection requirement comprises no need to perform integrity protection; the CU-CP receives a first security protection mode sent by the first CU-UP, wherein the first security protection mode is a security protection mode determined by the first CU-UP according to the first security policy; the CU-CP determines whether the first security protection mode is consistent with a second security protection mode, wherein the second security protection mode is a security protection mode used by a terminal device and a second CU-UP for data protection; when the CU-CP determines that the first security protection mode is not consistent with the second security protection mode, the CU-CP sends the first security protection mode to the terminal device, so that the terminal device performs the first security protection mode, wherein the first security protection mode is a security protection mode used by the terminal device and the first CU-UP for data protection.
2. The method of claim 1, wherein, After the CU-CP receives the first security protection mode sent by the first CU-UP, the method further comprises the following steps: if the first security protection mode and the second security protection mode are different, the CU-CP informs a session management function (SMF) that the first CU-UP uses the first security protection mode; or, if the first security protection mode and the second security protection mode are different, the CU-CP informs the SMF that protection of a first session cannot be performed, wherein the first session is a session in which the terminal device and the second CU-UP use the second security protection mode for data protection.
3. The method of claim 1, wherein, The first security policy comprises: a need to perform confidentiality protection, a tendency to perform confidentiality protection, or no need to perform confidentiality protection; a need to perform integrity protection, a tendency to perform integrity protection, or no need to perform integrity protection.
4. The method of claim 1, wherein, The first security protection mode or the second security protection mode comprises: whether to perform user plane confidentiality protection; whether to perform user plane integrity protection.
5. The method according to any one of claims 1-4, characterized in that, Before the CU-CP sends the first security policy to the first CU-UP, the method further comprises the following steps: the CU-CP determines, according to a test report, that it is necessary to switch from the second CU-UP to the first CU-UP; or, the CU-CP determines, according to a local policy, that it is necessary to switch from the second CU-UP to the first CU-UP. 6.A method for security processing of a user plane function (UPF) central unit (CU), comprising: The method is applied to a scenario in which a terminal device switches from a second user plane centralized unit (CU-UP) to a first CU-UP, and the method comprises the following steps: The terminal device receives user plane policy change indication information sent by a management plane centralized unit (CU-CP), wherein the user plane policy change indication information includes a first security protection mode, so that the terminal device executes the first security protection mode, and the user plane policy change indication information is sent when the CU-CP determines that the first security protection mode is inconsistent with a second security protection mode, the first security protection mode is a security protection mode determined by a first CU-UP according to a first security policy, the second security protection mode is a security protection mode used by the terminal device and the second CU-UP for data protection, the first security policy is used to indicate a confidentiality protection requirement and / or an integrity protection requirement, the confidentiality protection requirement includes no need to perform confidentiality protection, and the integrity protection requirement includes no need to perform integrity protection; The terminal device activates security protection between the terminal device and the first CU-UP according to the first security protection mode.
7. The method of claim 6, wherein, Before the terminal device activates security protection between the terminal device and the first CU-UP according to the first security protection mode, the method further includes: The terminal device deletes a second security protection mode, which is a security protection mode between the terminal device and the second CU-UP.
8. The method of claim 7, wherein, The first security protection mode or the second security protection mode includes: Whether to perform user plane confidentiality protection; Whether to perform user plane integrity protection.
9. The method according to any one of claims 6-8, characterized in that, The user plane policy change indication information carries a bit or a field.
10. A communication system, characterized by It includes: A management plane centralized unit (CU-CP), a first user plane centralized unit (CU-UP), a second CU-UP, and a terminal device; The CU-CP is configured to send a first security policy to the first CU-UP, wherein the first security policy is used to indicate a confidentiality protection requirement and / or an integrity protection requirement, the confidentiality protection requirement includes no need to perform confidentiality protection, and the integrity protection requirement includes no need to perform integrity protection; The first CU-UP is configured to receive the first security policy sent by the CU-CP; The first CU-UP is further configured to determine a first security protection mode according to the first security policy; The first CU-UP is further configured to send the first security protection mode to the CU-CP; The CU-CP is further configured to receive the first security protection mode sent by the first CU-UP, wherein the first security protection mode is a security protection mode determined by the first CU-UP; The CU-CP is further configured to determine whether the first security protection mode is consistent with a second security protection mode, wherein the second security protection mode is a security protection mode used by the terminal device and the second CU-UP for data protection; The CU-CP is further configured to send the first security protection mode to the terminal device when the CU-CP determines that the first security protection mode is inconsistent with the second security protection mode, so that the terminal device performs the first security protection mode, wherein the first security protection mode is a security protection mode used by the terminal device and the first CU-UP for data protection. The terminal device is configured to receive user plane policy change indication information sent by the CU-CP, wherein the user plane policy change indication information comprises a first security protection mode. The terminal device is further configured to activate security protection between the terminal device and the first CU-UP according to the first security protection mode.
11. The system of claim 10, wherein, The system further comprises a session management function (SMF), and after receiving the first security protection mode sent by the first CU-UP, the CU-CP is further configured to: If the first security protection mode is different from the second security protection mode, inform the SMF that the first CU-UP uses the first security protection mode; Or, If the first security protection mode is different from the second security protection mode, inform the SMF that protection of a first session cannot be performed, wherein the first session is a session in which the terminal device and the second CU-UP perform data protection using the second security protection mode.
12. The system of claim 10, wherein, The first security policy comprises: Confidentiality protection needs to be performed, or is inclined to be performed, or does not need to be performed; Integrity protection needs to be performed, or is inclined to be performed, or does not need to be performed.
13. The system of claim 10, wherein, The first security protection mode or the second security protection mode comprises: Whether to perform user plane confidentiality protection; Whether to perform user plane integrity protection.
14. The system of any of claims 10-13, wherein, Before the CU-CP sends the first security policy to the first CU-UP, the CU-CP is further configured to: Determine that switching from the second CU-UP to the first CU-UP is needed according to a test report; Or, determine that switching from the second CU-UP to the first CU-UP is needed according to a local policy.
15. A communications device, characterized by Comprise: A transceiver configured to send a first security policy to a first user plane centralized unit (CU-UP), wherein the first security policy is used to indicate a confidentiality protection requirement and / or an integrity protection requirement, the confidentiality protection requirement comprises that confidentiality protection does not need to be performed, and the integrity protection requirement comprises that integrity protection does not need to be performed; The transceiver is further configured to receive a first security protection mode sent by the first CU-UP, wherein the first security protection mode is a security protection mode determined by the first CU-UP according to the first security policy; A processor configured to determine whether the first security protection mode is consistent with a second security protection mode, wherein the second security protection mode is a security protection mode used by a terminal device and a second CU-UP for data protection; The transceiver is further configured to, when the processor determines that the first security protection mode is inconsistent with the second security protection mode, The transceiver is further configured to send the first security protection mode to the terminal device, so that the terminal device performs the first security protection mode, wherein the first security protection mode is a security protection mode used by the terminal device for data protection with the first CU-UP.
16. The communication apparatus according to claim 15, wherein, The transceiver is further configured to notify a session management function (SMF) that the first CU-UP uses the first security protection mode if the first security protection mode is different from the second security protection mode. Or, The transceiver is further configured to notify the SMF that protection of a first session cannot be performed if the first security protection mode is different from the second security protection mode, wherein the first session is a session in which the terminal device performs data protection with the second CU-UP using the second security protection mode.
17. The communication apparatus according to claim 15, wherein The first security policy comprises: Confidentiality protection needs to be performed, or is inclined to be performed, or does not need to be performed; Integrity protection needs to be performed, or is inclined to be performed, or does not need to be performed.
18. The communication apparatus according to claim 15, wherein The first security protection mode or the second security protection mode comprises: Whether to perform user plane confidentiality protection; Whether to perform user plane integrity protection.
19. The communication apparatus according to any one of claims 15-18, wherein, The processor is further configured to determine that switching from the second CU-UP to the first CU-UP is needed according to a test report. Or, The processor is further configured to determine that switching from the second CU-UP to the first CU-UP is needed according to a local policy.
20. A communications device, characterized by Comprise: A transceiver configured to receive user plane policy change indication information sent by a centralized unit (CU) -CP, wherein the user plane policy change indication information comprises a first security protection mode, so that a terminal device performs the first security protection mode, the user plane policy change indication information is sent when the CU-CP determines that the first security protection mode is inconsistent with a second security protection mode, the first security protection mode is a security protection mode determined by a first CU-UP according to a first security policy, the second security protection mode is a security protection mode used by the terminal device for data protection with a second CU-UP, the first security policy is used to indicate a confidentiality protection requirement and / or an integrity protection requirement, the confidentiality protection requirement comprises not needing to perform confidentiality protection, and the integrity protection requirement comprises not needing to perform integrity protection; A processor configured to activate security protection between the terminal device and the first CU-UP according to the first security protection mode.
21. The communication apparatus according to claim 20, wherein, The processor is further configured to delete a second security protection mode, wherein the second security protection mode is a security protection mode between the terminal device and the second CU-UP.
22. The communication apparatus according to claim 21, wherein, The first security protection mode or the second security protection mode comprises: Whether to perform user plane confidentiality protection; Whether to perform user plane integrity protection.
23. The communication apparatus according to any one of claims 20-22, wherein, The user plane policy change indication information carries a bit or a field.
24. A computer-readable storage medium, characterized in that, The computer readable storage medium has program instructions which, when executed directly or indirectly, cause the method of any of claims 1-5 or 6-9 to be implemented.
25. A chip system, characterized by The chip system includes at least one processor, and when program instructions are executed in the at least one processor, the method of any of claims 1-5 or 6-9 is implemented.
26. A communication system, characterized by The communication system includes the communication device of any of claims 15-19 or 20-23.
Citation Information
Patent Citations
Security negotiation method and device
CN110121168A
Key generation method and related device
CN110365470A