A method of activating security and a communication device
By utilizing the instruction and policy interaction between access network devices in the NSA deployment mode, on-demand protection of user plane security between terminal devices and secondary access network devices is achieved, solving the problem of on-demand protection of user plane security during the transition from 4G to 5G networks and improving security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-08-06
- Publication Date
- 2026-04-07
AI Technical Summary
During the transition from 4G to 5G networks, how can we implement an on-demand user plane security protection mechanism in non-standalone (NSA) deployment mode, especially enabling user plane security protection between terminal devices and dual-connectivity secondary access network devices?
The first access network device sends an instruction message to the second access network device, instructing the terminal device to support user plane security protection, and determines the security activation status according to the user plane security policy, thereby enabling on-demand activation of user plane encryption protection and/or user plane integrity protection.
This effectively avoids the security degradation caused by the secondary access network equipment not supporting user plane security protection, and enables user plane security between the terminal equipment and the second access network equipment to be enabled on demand.
Smart Images

Figure CN115396884B_ABST
Abstract
Description
[0001] Cross Reference to Related Applications
[0002] The present application claims priority to the Chinese Patent Application No. 202110502511.3, filed on May 8, 2021, and entitled “Method for Activating Security and Communication Device”, the content of which is incorporated herein by reference in its entirety; the present application claims priority to the Chinese Patent Application No. 202110506910.7, filed on May 10, 2021, and entitled “Method for Activating Security and Communication Device”, the content of which is incorporated herein by reference in its entirety. TECHNICAL FIELD
[0003] The present application relates to the technical field of wireless communication, and in particular to a method for activating security and a communication device. BACKGROUND
[0004] User plane security on-demand protection mechanism is a security mechanism in 5G network. The user plane security on-demand protection mechanism involves user plane encryption protection and user plane integrity protection, and requires an access network device to determine whether to start user plane encryption protection and user plane integrity protection with a terminal device according to a user plane security policy received from a core network device, thereby providing more flexible user plane security for the terminal device.
[0005] In the prior art, the 4G network does not support the user plane security on-demand protection mechanism. In the 4G network, the user plane security between the access network device and the terminal device is fixed as: the user plane encryption protection is started, and the user plane integrity protection is not started. In the case that the 4G network will not be retired in the short term, the industry has researched to apply the user plane security on-demand protection mechanism to the 4G network through the participation of the access network device and the related core network device (such as the mobility management entity (MME)) in the network.
[0006] In the process of transition from the 4G network to the 5G network, a non-standalone (NSA) deployment mode appears, in which a terminal device connects an evolved packet system (eNB) in the 4G network and a next generation NodeB (gNB) in the 5G network simultaneously through a dual connection mode.
[0007] After introducing the user plane security on-demand protection mechanism in the 4G network, how to implement the user plane security on-demand protection mechanism in the NSA deployment mode is a problem to be solved at present. SUMMARY
[0008] This application provides a method and communication device for activating security, used to enable user plane security between a terminal device and a dual-connectivity secondary access network device in an NSA deployment mode.
[0009] In a first aspect, embodiments of this application provide a method for activating security, which can be executed by a first access network device or by a component (e.g., a chip or circuit) configured in the first access network device.
[0010] The method includes: a first access network device of a first communication standard requesting a second access network device of a second communication standard to allocate resources for dual connectivity of a terminal device and sending a first indication message to the second access network device, the first indication message being used to indicate that the terminal device supports user plane security protection, and the first access network device being the primary access network device in the dual connectivity of the terminal device; the first access network device receiving bearer identification information and security activation status from the second access network device; the first access network device sending the bearer identification information and security activation status to the terminal device, the security activation status being used to indicate whether user plane encryption protection and / or user plane integrity protection of the bearer are enabled.
[0011] The above technical solution enhances the processing logic of the first access network device (primary access network device) and the second access network device (secondary access network device) in the auxiliary station addition process under cross-system dual-connectivity scenarios. The first access network device can send a first indication message to the second access network device, indicating that the terminal device supports user plane security protection, or further, send a user plane security policy. The second access network device determines the security activation status based on the first indication message and the user plane security policy and sends it to the terminal device, thereby enabling user plane security between the terminal device and the second access network device on demand. Simultaneously, the first access network device can also determine whether the second access network device supports user plane security protection based on the user plane integrity protection policy, thus avoiding the problem of the second access network device ignoring the user plane integrity protection policy because it does not support it when the user plane integrity protection policy is indicated as enabled, which would lead to a decrease in security.
[0012] In one possible design of the first aspect, the bearer is used to transmit user plane data between the terminal device and the second access network device.
[0013] In one possible design of the first aspect, the method further includes: the first access network device generating first indication information based on the context of the terminal device.
[0014] In one possible design of the first aspect, the context of the terminal device includes a first security capability of the terminal device, which indicates that the terminal device supports user plane security protection, and the first security capability corresponds to a first communication standard.
[0015] In one possible design of the first aspect, the context of the terminal device includes a first wireless capability of the terminal device, which indicates that the terminal device supports user plane security protection, and the first wireless capability corresponds to a first communication standard.
[0016] In one possible design of the first aspect, if the user plane security policy is mandatory, the type of the first indication information is critical information of rejection; if the user plane security policy is not mandatory, the type of the first indication information is critical information of ignoring.
[0017] In one possible design of the first aspect, the method further includes: a first access network device selecting a second access network device based on the context of the terminal device, the second access network device supporting user plane security protection.
[0018] In one possible design of the first aspect, the context of the terminal device includes a user plane security policy; the first access network device selects a second access network device based on the context of the terminal device, including: if the first access network device determines that the terminal device supports user plane security protection, then selects the second access network device according to the user plane security policy.
[0019] In one possible design of the first aspect, the method further includes: the first access network device sending a user plane security policy from the core network device or pre-configured by the first access network device to the second access network device.
[0020] In one possible design of the first aspect, the method further includes: a first access network device receiving an enable instruction from a terminal device, the enable instruction indicating that the terminal device has enabled user plane security with the second access network device; and the first access network device sending the enable instruction to the second access network device.
[0021] In one possible design of the first aspect, the method further includes: a first access network device receiving a support enable indication from a second access network device, the support enable indication being used to instruct the second access network device to support user plane security protection.
[0022] In one possible design of the first aspect, the first access network device of the first communication standard requests the second access network device of the second communication standard to allocate resources for the dual connectivity of the terminal device and sends first indication information to the second access network device, including: the first access network device sending a secondary station addition request to the second access network device, the secondary station addition request including the first indication information, the secondary station addition request being used to request the allocation of resources for the dual connectivity of the terminal device; the first access network device receiving the bearer identification information and security activation status from the second access network device includes: the first access network device receiving the secondary station addition response from the second access network device, the secondary station addition response including the bearer identification information and security activation status.
[0023] In one possible design of the first aspect, the auxiliary site addition request also includes a user plane security policy.
[0024] In one possible design of the first aspect, the first access network device sending the bearer identification information and security activation status to the terminal device includes: the first access network device sending a reconfiguration message to the terminal device, the reconfiguration message including the bearer identification information and security activation status.
[0025] Secondly, embodiments of this application provide a method for activating security, which can be executed by a second access network device or by a component (e.g., a chip or circuit) configured in the second access network device.
[0026] The method includes: a second access network device of a second communication standard accepting a request from a first access network device of a first communication standard to allocate resources for dual connectivity of a terminal device and receiving first indication information from the first access network device, the first indication information being used to indicate that the terminal device supports user plane security protection; the second access network device determining a security activation state based on the first indication information and a user plane security policy; and the second access network device sending bearer identification information and the security activation state to the terminal device through the first access network device, the security activation state being used to indicate whether user plane encryption protection and / or user plane integrity protection of the bearer are enabled.
[0027] In one possible design of the second aspect, the bearer is used to transmit user plane data between the terminal device and the second access network device.
[0028] In one possible design of the second aspect, the method further includes: the second access network device receiving a user plane security policy from the first access network device; or, the user plane security policy is pre-configured by the second access network device.
[0029] In one possible design of the second aspect, if the user plane security policy is required to be enabled, the type of the first indication information is critical information of rejection; if the user plane security policy is not required to be enabled, the type of the first indication information is critical information of ignoring.
[0030] In one possible design of the second aspect, the method further includes: the second access network device sending a support enable indication to the first access network device, the support enable indication being used to instruct the second access network device to support user plane security protection.
[0031] In one possible design of the second aspect, the method further includes: the second access network device receiving activation indication information from the terminal device through the first access network device, the activation indication information being used to indicate that the terminal device has enabled user plane security with the second access network device.
[0032] In one possible design of the second aspect, the method further includes: the second access network device activating user plane security with the terminal device according to the security activation state.
[0033] In one possible design of the second aspect, the second access network device of the second communication standard accepts a request from the first access network device of the first communication standard to allocate resources for the dual connectivity of the terminal device and receives first indication information from the first access network device, including: the second access network device receiving a secondary station addition request from the first access network device, the secondary station addition request including the first indication information, the secondary station addition request being used to request the allocation of resources for the dual connectivity of the terminal device; the second access network device sending bearer identification information and security activation status to the terminal device through the first access network device, including: the second access network device sending a secondary station addition response to the first access network device, the secondary station addition response including bearer identification information and security activation status.
[0034] In one possible design of the second aspect, the auxiliary site addition request includes a user plane security policy.
[0035] Thirdly, embodiments of this application provide a method for activating security, which can be executed by a first access network device or by a component (e.g., a chip or circuit) configured in the first access network device.
[0036] The method includes: a first access network device of a first communication standard selecting a second access network device of a second communication standard that supports user plane security protection based on the context of the terminal device, wherein the first access network device is the primary access network device in the dual connection of the terminal device; the first access network device requesting the second access network device to allocate resources for the dual connection of the terminal device and sending a user plane security policy to the second access network device; the first access network device receiving the bearer identification information and security activation status from the second access network device; and the first access network device sending the bearer identification information and security activation status to the terminal device, wherein the security activation status is used to indicate whether to enable user plane encryption protection and / or user plane integrity protection of the bearer.
[0037] The above technical solution enhances the processing logic of the first access network device (primary access network device) and the second access network device (secondary access network device) in the auxiliary station addition process under cross-system dual-connectivity scenarios. The first access network device determines whether the terminal device supports user plane security protection. If the terminal device supports user plane security protection, it selects the second access network device that supports user plane security protection according to the user plane security policy and sends the user plane security policy to the second access network device. The second access network device then determines the security activation status according to the user plane security policy and sends it to the terminal device, thereby enabling user plane security between the terminal device and the second access network device on demand.
[0038] In one possible design of the third aspect, the bearer is used to transmit user plane data between the terminal device and the second access network device.
[0039] In one possible design of the third aspect, the context of the terminal device includes a first security capability of the terminal device, which indicates that the terminal device supports user plane security protection, and the first security capability corresponds to a first communication standard.
[0040] In one possible design of the third aspect, the context of the terminal device includes a first wireless capability of the terminal device, which indicates that the terminal device supports user plane security protection, and the first wireless capability corresponds to a first communication standard.
[0041] In one possible design of the third aspect, the user plane security policy is received by the first access network device from the core network device or pre-configured by the first access network device.
[0042] In one possible design of the third aspect, the method further includes: a first access network device receiving an enable indication message from a terminal device, the enable indication message indicating that the terminal device has enabled user plane security with the second access network device; and the first access network device sending the enable indication message to the second access network device.
[0043] Fourthly, embodiments of this application provide a method for activating security, which can be executed by a second access network device or by a component (e.g., a chip or circuit) configured in the second access network device.
[0044] The method includes: a second access network device of a second communication standard accepting a request from a first access network device of a first communication standard to allocate resources for dual connectivity of a terminal device and receiving a user plane security policy from the first access network device; the second access network device determining a security activation state according to the user plane security policy; and the second access network device sending bearer identification information and the security activation state to the terminal device through the first access network device, wherein the security activation state is used to indicate whether user plane encryption protection and / or user plane integrity protection of the bearer are enabled.
[0045] In one possible design of the fourth aspect, the bearer is used to transmit user plane data between the terminal device and the second access network device.
[0046] In one possible design of the fourth aspect, the method further includes: the second access network device receiving an activation indication information from the terminal device through the first access network device, the activation indication information being used to indicate that the terminal device has activated user plane security with the second access network device.
[0047] In one possible design of the fourth aspect, the method further includes: the second access network device, in accordance with the security activation state, enabling user plane security between itself and the terminal device.
[0048] Fifthly, embodiments of this application provide a method for activating security, which can be executed by a second access network device or by a component (e.g., a chip or circuit) configured in the second access network device.
[0049] The method includes: a second access network device using a second communication standard sending a first request message to a terminal device via a first access network device using a first communication standard, the first request message requesting the terminal device to support user plane security, wherein the second access network device is the secondary access network device in the dual-connection of the terminal device, and the first access network device is the primary access network device in the dual-connection of the terminal device; the second access network device receiving a second indication message from the terminal device via the first access network device, the second indication message indicating that the terminal device supports user plane security protection; the second access network device determining a security activation state based on the second indication message and the user plane security policy; and the second access network device sending a bearer identification information and a security activation state to the terminal device via the first access network device, the security activation state indicating whether to enable user plane encryption protection and / or user plane integrity protection for the bearer.
[0050] The above technical solution enhances the processing logic of the first access network device (primary access network device) and the second access network device (secondary access network device) in the auxiliary station addition process under cross-system dual-connectivity scenarios. After receiving a request to allocate resources for dual connectivity of the terminal device, the second access network device can interact with the terminal device through the first access network device to obtain the terminal device's support capability for user plane security. Then, if the terminal device supports user plane security protection, it determines the security activation status according to the user plane security policy and sends it to the terminal device, thereby enabling user plane security between the terminal device and the second access network device on demand.
[0051] In one possible design of the fifth aspect, the bearer is used to transmit user plane data between the terminal device and the second access network device.
[0052] In one possible design of the fifth aspect, the user plane security policy is pre-configured by the second access network device.
[0053] In one possible design of the fifth aspect, the method further includes: the second access network device receiving an activation indication information from the terminal device through the first access network device, the activation indication information being used to indicate that the terminal device has activated user plane security with the second access network device.
[0054] In one possible design of the fifth aspect, the method further includes: the second access network device activating user plane security with the terminal device according to the security activation state.
[0055] In one possible design of the fifth aspect, the method further includes: a second access network device receiving a secondary station addition request from a first access network device, the secondary station addition request being used to request resource allocation for dual connectivity of the terminal device; the second access network device sending bearer identification information and the security activation status to the terminal device through the first access network device of the first communication standard, including: the second access network device sending a secondary station modification response to the first access network device, the secondary station modification response including the bearer identification information and the security activation status.
[0056] Sixthly, embodiments of this application provide a method for activating security, which can be executed by a terminal device or by a component (e.g., a chip or circuit) configured on the terminal device.
[0057] The method includes: a terminal device receiving a first request message from a second access network device of a second communication standard via a first access network device of a first communication standard, the first request message being used to request the terminal device to support user plane security; and the terminal device sending a second indication message to the second access network device via the first access network device, the second indication message being used to instruct the terminal device to support user plane security protection.
[0058] The above technical solution enhances the processing logic of the first access network device (primary access network device) and the second access network device (secondary access network device) in the auxiliary site addition process under a cross-system dual-connectivity scenario. After receiving the auxiliary site addition request, if the second access network device does not receive the first indication information or user plane security policy, it can determine the security activation status according to the pre-configured user plane security policy and send it to the terminal device. If the terminal device supports user plane security protection, it can enable user plane security with the second access network device based on the received security activation status and send an activation indication information. This allows the second access network device to enable user plane security with the terminal device after receiving the activation indication information sent by the terminal device, thereby achieving on-demand activation of user plane security between the terminal device and the second access network device. If the terminal device does not support user plane security protection, it can perform no processing, such as discarding or ignoring the received bearer identification information and security activation status. It can be seen that this technical solution can determine the security activation status and send it to the terminal device based on the pre-configured user plane security policy when it is uncertain whether the terminal device supports user plane security protection. Compared with the technical solution that confirms with the terminal device whether it has the ability to support user plane security protection before determining the security activation status, it can effectively reduce signaling overhead.
[0059] In one possible design of the sixth aspect, the method further includes: the terminal device receiving, via a first access network device, identification information and security activation status of a bearer from a second access network device, the security activation status indicating whether user plane encryption protection and / or user plane integrity protection of the bearer are enabled; and the terminal device enabling user plane security with the second access network device according to the security activation status.
[0060] In one possible design of the sixth aspect, the bearer is used to transmit user plane data between the terminal device and the second access network device.
[0061] In one possible design of the sixth aspect, the method further includes: the terminal device sending an activation indication message to the second access network device through the first access network device, the activation indication message being used to indicate that the terminal device has enabled user plane security with the second access network device.
[0062] In a seventh aspect, embodiments of this application provide a method for activating security, which can be executed by a second access network device or by a component (e.g., a chip or circuit) configured in the second access network device.
[0063] The method includes: a second access network device of a second communication standard determining a security activation state according to a user plane security policy, wherein the second access network device is the secondary access network device in the dual connection of the terminal device; the second access network device sending bearer identification information and a security activation state to the terminal device through a first access network device of a first communication standard, wherein the security activation state is used to indicate whether user plane encryption protection and / or user plane integrity protection of the bearer is enabled, wherein the first access network device is the primary access network device in the dual connection of the terminal device; the second access network device receiving an enable indication information from the terminal device through the first access network device, wherein the enable indication information is used to indicate that the terminal device has enabled user plane security with the second access network device; and the second access network device enabling user plane security with the terminal device according to the enable indication information and the security activation state.
[0064] In one possible design of the seventh aspect, the bearer is used to transmit user plane data between the terminal device and the second access network device.
[0065] In one possible design of the seventh aspect, the user plane security policy is pre-configured by the second access network device.
[0066] In one possible design of the seventh aspect, the method further includes: the second access network device sending an acknowledgment information to the terminal device through the first access network device, the acknowledgment information being used to instruct the terminal device to send an enable instruction information after enabling user plane security with the second access network device.
[0067] In one possible design of the seventh aspect, the method further includes: a second access network device receiving a secondary station addition request from a first access network device, the secondary station addition request being used to request resource allocation for dual connectivity of a terminal device; the second access network device sending bearer identification information and security activation status to the terminal device through the first access network device of the first communication standard, including: the second access network device sending a secondary station addition response to the first access network device, the secondary station addition response including bearer identification information and security activation status.
[0068] In one possible design of the seventh aspect, the auxiliary station addition response includes confirmation indication information.
[0069] In one possible design of the seventh aspect, if the auxiliary station addition request message does not contain the first indication information, the second access network device determines the security activation state according to the user plane security policy; the first indication information is used to indicate that the terminal device supports user plane security protection.
[0070] Eighthly, embodiments of this application provide a method for activating security, which can be executed by a terminal device or by a component (e.g., a chip or circuit) configured on the terminal device.
[0071] The method includes: a terminal device receiving, via a first access network device of a first communication standard, bearer identification information and security activation status from a second access network device of a second communication standard, wherein the security activation status is used to indicate whether user plane encryption protection and / or user plane integrity protection of the bearer is enabled; the terminal device enabling user plane security with the second access network device according to the security activation status; and the terminal device sending enabling indication information to the second access network device via the first access network device, wherein the enabling indication information is used to indicate that the terminal device has enabled user plane security with the second access network device.
[0072] In one possible design of the eighth aspect, the bearer is used to transmit user plane data between the terminal device and the second access network device.
[0073] In one possible design of the eighth aspect, the method further includes: the terminal device receiving confirmation indication information from the second access network device through the first access network device, the confirmation indication information being used to instruct the terminal device to send an enable indication information after enabling user plane security with the second access network device.
[0074] Ninthly, embodiments of this application provide a communication device that performs the functions of a first access network device or a second access network device as described in the above aspects. The communication device can be an access network device or a chip included in an access network device. Optionally, the communication device can also perform the functions of a terminal device as described in the above aspects. The communication device can be a terminal device or a chip included in a terminal device.
[0075] The functions of the aforementioned communication device can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules, units, or means corresponding to the aforementioned functions.
[0076] In one possible design, the communication device includes a processing module and a transceiver module. The processing module is configured to support the device in performing the functions corresponding to the first access network device, the second access network device, or the terminal device as described above. The transceiver module supports communication between the communication device and other communication devices; for example, when the communication device is the first access network device, it can send first instruction information to the first access network device. The communication device may also include a storage module coupled to the processing module, which stores the necessary program instructions and data for the communication device. As an example, the processing module may be a processor, the communication module may be a transceiver, and the storage module may be a memory, which may be integrated with or separated from the processor.
[0077] In another possible design, the communication device includes a processor and may also include a memory. The processor is coupled to the memory and can be used to execute computer program instructions stored in the memory to cause the communication device to perform the methods described above. Optionally, the communication device also includes a communication interface, with the processor coupled to the communication interface. When the communication device is a terminal device or an access network device, the communication interface may be a transceiver or an input / output interface; when the communication device is a chip included in a terminal device or an access network device, the communication interface may be the chip's input / output interface. Optionally, the transceiver may be a transceiver circuit, and the input / output interface may be an input / output circuit.
[0078] In a tenth aspect, embodiments of this application provide a chip system, including: a processor coupled to a memory, the memory being used to store programs or instructions, wherein when the program or instructions are executed by the processor, the chip system implements the methods in the above aspects.
[0079] Optionally, the chip system also includes an interface circuit for exchanging code instructions with the processor.
[0080] Optionally, the chip system may include one or more processors, which can be implemented in hardware or software. When implemented in hardware, the processor may be a logic circuit, integrated circuit, etc. When implemented in software, the processor may be a general-purpose processor that reads software code stored in memory.
[0081] Optionally, the chip system may contain one or more memories. These memories may be integrated with the processor or disposed separately. For example, the memory may be a non-transitory processor, such as a read-only memory (ROM), which may be integrated with the processor on the same chip or disposed on separate chips.
[0082] Eleventhly, embodiments of this application provide a computer-readable storage medium having a computer program or instructions stored thereon, which, when executed, causes a communication device to perform any of the above-described aspects or any possible design methods.
[0083] In a twelfth aspect, embodiments of this application provide a computer program product that, when executed by a communication device, causes the communication device to perform any of the methods in the above-described aspects or any of the possible designs.
[0084] In a thirteenth aspect, embodiments of this application provide a communication system including a first access network device, a second access network device, and a terminal device. Optionally, the communication system may further include core network equipment. Attached Figure Description
[0085] Figure 1 This is a schematic diagram of a network architecture for a communication system applicable to embodiments of this application;
[0086] Figure 2 This is a schematic diagram illustrating an NSA deployment method applicable to an embodiment of this application;
[0087] Figure 3 A flowchart illustrating a method for activating security, provided in an embodiment of this application;
[0088] Figure 4 This application provides a specific example of a method for activating security.
[0089] Figure 5 A flowchart illustrating another method for activating security provided in an embodiment of this application;
[0090] Figure 6 A specific example of another method for activating security provided in the embodiments of this application;
[0091] Figure 7 A flowchart illustrating another method for activating security provided in an embodiment of this application;
[0092] Figure 8 A specific example of yet another method for activating security provided in the embodiments of this application;
[0093] Figure 9A flowchart illustrating another method for activating security provided in an embodiment of this application;
[0094] Figure 10 A specific example of yet another method for activating security provided in the embodiments of this application;
[0095] Figure 11 A flowchart illustrating another method for activating security provided in an embodiment of this application;
[0096] Figure 12 A flowchart illustrating another method for activating security provided in an embodiment of this application;
[0097] Figure 13 A flowchart illustrating another method for activating security provided in an embodiment of this application;
[0098] Figure 14 A flowchart illustrating another method for activating security provided in an embodiment of this application;
[0099] Figure 15 , Figure 16 and Figure 17 This is a schematic diagram of the structure of a communication device provided in an embodiment of this application. Detailed Implementation
[0100] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the embodiments of this application will be further described in detail below with reference to the accompanying drawings.
[0101] The technical solutions of this application can be applied to various communication systems, such as: Global System for Mobile Communications (GSM) system, Code Division Multiple Access (CDMA) system, Wideband Code Division Multiple Access (WCDMA) system, General Packet Radio Service (GPRS), Long Term Evolution (LTE) system, LTE Frequency Division Duplex (FDD) system, LTE Time Division Duplex (TDD) system, Universal Mobile Telecommunication System (UMTS), 5th Generation (5G) communication system, or New Radio (NR) system, or applied to future communication systems or other similar communication systems, etc.
[0102] Please refer to Figure 1 This is a schematic diagram of a network architecture for a communication system applicable to embodiments of this application. The communication system includes a core network device 110, a wireless access network device 120, and at least one terminal device (such as...). Figure 1 (Terminal devices 130 and 140 in the network). The terminal devices are connected to the wireless access network equipment wirelessly, and the wireless access network equipment is connected to the core network equipment wirelessly or via wired connection.
[0103] Core network equipment and radio access network equipment can be independent physical devices, or the functions of core network equipment and the logical functions of radio access network equipment can be integrated into the same physical device, or a single physical device can integrate some of the functions of core network equipment and some of the functions of radio access network equipment. Terminal equipment can be fixed in location or mobile.
[0104] It should be understood that Figure 1 This is just an illustration; the communication system may also include other types of network devices, such as wireless repeaters and wireless backhaul devices. Figure 1 Not shown in the diagram. The embodiments of this application do not limit the number of core network devices, wireless access network devices, and terminal devices included in the communication system.
[0105] The terminal device in this application is a device with wireless transceiver capabilities, which connects wirelessly to a wireless access network device to access the communication system. The terminal device can also be called a terminal, user equipment (UE), mobile station, mobile terminal, etc. Terminal devices can be mobile phones, tablets, computers with wireless transceiver capabilities, virtual reality terminal devices, augmented reality terminal devices, wireless terminals in industrial control, wireless terminals in autonomous driving, wireless terminals in remote surgery, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, wireless terminals in smart homes, etc. This application does not limit the specific technology or device form used in the terminal device. As an example and not a limitation, the terminal device can also be a wearable device. Wearable devices can also be called wearable smart devices or smart wearable devices, etc., and are a general term for devices that apply wearable technology to intelligently design and develop everyday wearables, such as glasses, gloves, watches, clothing, and shoes. Wearable devices are portable devices that are worn directly on the body or integrated into the user's clothing or accessories. Wearable devices are not just hardware devices, but also achieve powerful functions through software support, data interaction, and cloud interaction. Wearable smart devices in a broad sense include those that are feature-rich, large in size, and capable of performing all or part of their functions without relying on a smartphone, such as smartwatches or smart glasses. They also include devices focused on a specific application function that require the use of other devices, such as smart bracelets, smart helmets, and smart jewelry for vital sign monitoring. Terminal devices can also be onboard modules, components, chips, or units integrated into a vehicle as one or more parts or units. The vehicle can implement the methods of this application through these built-in onboard modules, components, chips, or units.
[0106] The wireless access network device in this application is a device used in a network to connect terminal devices to wireless network equipment. The wireless access network device is a node in the wireless access network, also known as a base station or RAN node (or device). In this application, the wireless access network device can be simply referred to as the access network device. Unless otherwise specified, the access network device referred to below refers to the wireless access network device. The wireless access network device can be a base station, an evolved NodeB (eNodeB) in an LTE system or an evolved LTE system (LTE-Advanced, LTE-A), a next-generation NodeB (gNB) in a 5G communication system, a transmission reception point (TRP), a base band unit (BBU), a WiFi access point (AP), a base station in a future mobile communication system, or an access node in a WiFi system, etc. The wireless access network device can also be a module or unit that performs some of the functions of a base station; for example, it can be a central unit (CU) or a distributed unit (DU). The embodiments of this application do not limit the specific technology or device form used in the wireless access network equipment.
[0107] In a separate deployment architecture of radio access network equipment, including CUs and DUs, one CU can connect to one or more DUs, and a control plane interface exists between the CU and the DU. Specifically, the CU is used to support protocols such as radio resource control (RRC), packet data convergence protocol (PDCP), and service data adaptation protocol (SDAP); the DU is used to support radio link control (RLC) layer protocols, medium access control (MAC) layer protocols, and physical layer protocols.
[0108] The wireless access network equipment and terminal equipment in this application embodiment can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; they can also be deployed on water; and they can also be deployed in the air on airplanes, balloons, and artificial satellites. This application embodiment does not limit the application scenarios of the network equipment and terminal equipment.
[0109] Wireless access network (WLAN) devices and terminal devices can communicate using licensed spectrum, unlicensed spectrum, or both simultaneously. They can communicate using spectrum below 6 GHz, spectrum above 6 GHz, or both simultaneously. This application does not limit the spectrum resources used between WLAN devices and terminal devices.
[0110] The embodiments of this application can be applied to NSA deployment. In NSA deployment, a terminal device can simultaneously connect to two access network devices via dual connectivity. The two access network devices use different communication standards but can connect to the same core network. The communication standards may include, for example, 4G networks, 5G networks, etc., and are not limited thereto.
[0111] In this system, one of the two access network devices connected to the terminal device is the primary access network device, and the other is the secondary access network device. The primary access network device can also be called the primary base station, master node (MN), or master anchor, or simply the primary station. The secondary access network device can also be called the secondary base station, secondary node (SN), or secondary anchor, or simply the secondary station.
[0112] Figure 2 This diagram illustrates one NSA deployment method applicable to embodiments of this application. Specifically, this NSA deployment method is a dual connectivity mode when the core network is an evolved packet core (EPC), also known as the evolved universal terrestrial radio access and new air interface dual connectivity (E-UTRA NR dual connectivity, EN-DC) mode.
[0113] For example, such as Figure 2As shown, the primary access network device is the evolved NodeB (eNB) in a 4G network, such as the MeNB in the diagram. The secondary access network device is the next-generation node (gNB) in a 5G network, such as the SgNB in the diagram. Both the MeNB and SgNB are connected to the core network EPC of the 4G network, which provides core network transmission resources for data transmission between the UE and the network. For example, the MeNB can connect to the MME in the EPC, and the SgNB can connect to the serving gateway (SGW) of the EPC. In this scenario, there is an X2 interface between the MeNB and SgNB, which provides at least a control plane connection and may also provide a user plane connection; there is an S1 interface between the MeNB and the EPC, which provides at least a control plane connection and may also provide a user plane connection; there is an S1-U interface between the SgNB and the EPC, which provides only a user plane connection. The MeNB can provide air interface resources to the terminal device through at least one cell, which is called the master cell group (MCG). Similarly, the SgNB can also provide air interface resources to the terminal device through at least one cell, which is called the secondary cell group (SCG).
[0114] The MME is responsible for managing and storing the UE's mobility management context (e.g., UE identifier, mobility management status, and user security parameters), processing non-access stratum (NAS) signaling (e.g., attach request, location update request, service request, and PDN connectivity request), and ensuring the security of NAS signaling.
[0115] In this application embodiment, the terminal device supports user plane security protection in various ways depending on the object and characteristics. The object can be: 1) Evolved Packet Core (EPC); 2) eNB; 3) Long Term Evolution (LTE); 4) E-UTRA with EPC; 5) EPC-based Dual Connectivity of eUTRA and NR RAT. The characteristics can be: 1) User Plane Integrity Protection (UPIP); 2) User Plane Encryption Protection; 3) User Plane On-Demand Protection (i.e., whether to enable user plane encryption protection and / or user plane integrity protection can be determined based on the user plane security policy).
[0116] For example, combining object 1) and feature 1), UE support for UPIP can be described as "UE supports user plane integrity protection with EPC". It should be noted that the object is optional; for example, combining feature 1), UE support for UPIP can be described as "UE supports user plane integrity protection". Subsequent descriptions involving "supporting user plane security protection" can be replaced with combinations of objects 1-5 and features 1-3, or descriptions of features 1-3.
[0117] It should be noted that the terms "system" and "network" in the embodiments of this application can be used interchangeably. "Multiple" refers to two or more; therefore, in the embodiments of this application, "multiple" can also be understood as "at least two." "At least one" can be understood as one or more, such as one, two, or more. For example, including at least one means including one, two, or more, and is not limited to which ones are included. For example, including at least one of A, B, and C, then it can include A, B, C, A and B, A and C, B and C, or A and B and C. Similarly, the understanding of descriptions such as "at least one" is similar. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. Additionally, the character " / ", unless otherwise specified, generally indicates that the preceding and following related objects have an "or" relationship.
[0118] Unless otherwise stated, the ordinal numbers such as "first" and "second" mentioned in the embodiments of this application are used to distinguish multiple objects, and are not used to limit the order, timing, priority or importance of multiple objects, and the description of "first" and "second" does not limit the objects to necessarily being different.
[0119] This application applies to a cross-system dual-connection scenario, where a terminal device can simultaneously connect to a first access network device and a second access network device through dual connection. The first access network device is the primary access network device (also known as the master station) connected to the terminal device, and the second access network device is the secondary access network device (also known as the secondary station) connected to the terminal device. Furthermore, the first access network device and the second access network device use different communication standards.
[0120] In the existing secondary site addition process, due to the different communication standards between the primary and secondary sites, the primary access network device in the dual connection of the terminal device cannot transmit information about whether the terminal device supports user plane security protection to the secondary access network device. This results in the inability to enable user plane security between the terminal device and the secondary access network device. Taking an evolved NodeB (eNB) in a 4G network (MeNB) and a next-generation NodeB (gNB) in a 5G network (SgNB) as an example, the information about whether the terminal device supports user plane security protection is indicated by specific bits of the UE EPS security capability. In the secondary site addition process, if the MeNB has UE NR security capability, it can directly send the UE NR security capability to the SgNB without sending the UE EPS security capability. However, this UE NR security capability cannot indicate whether the terminal device supports user plane security protection, such as whether the terminal device supports UPIP. If the MeNB does not have UE NR security capabilities, the MeNB can map UE EPS security capabilities to UE NR security capabilities. However, during the mapping process, because the mapping ignores specific bits of the UE EPS security capabilities, information related to whether the terminal device supports user plane security protection will also be lost.
[0121] To address the aforementioned issues, this application provides a method for activating security, which enables user plane security between a terminal device and a secondary station in an NSA deployment configuration. This method can have four possible implementations, which, for ease of description, are referred to as Scheme 1 to Scheme 4. Schemes 1 to 4 of the embodiments of this application will be described in detail below.
[0122] Option 1
[0123] Please refer to Figure 3 The above is a flowchart illustrating a method for activating security according to an embodiment of this application. The method includes:
[0124] Step S301: The first access network device of the first communication standard requests the second access network device of the second communication standard to allocate resources for the dual connection of the terminal device and sends a first indication information to the second access network device. The first indication information is used to indicate that the terminal device supports user plane security protection. The first access network device is the primary access network device in the dual connection of the terminal device, and the second access network device is the secondary access network device in the dual connection of the terminal device.
[0125] Accordingly, the second access network device accepts the request from the first access network device to allocate resources for the dual connectivity of the terminal device, and receives the first instruction information from the first access network device.
[0126] The first access network device requests the second access network device to allocate resources for the dual connection of the terminal device, and sends the first indication information to the second access network device. This can be achieved by the first access network device sending a message to the second access network device, such as a secondary station addition request message; or it can be achieved by sending two messages respectively. This application does not limit this.
[0127] For example, the first communication standard can be a 4G network, also referred to as a 4G system or an evolved packet system (EPS). The second communication standard can be a 5G network, also referred to as a 5G system or a new radio (NR) system. Thus, the first access network device can be an evolved NB (eNB) in a 4G network, and the second access network device can be a gNB (gNB) in a 5G network.
[0128] In this embodiment, "terminal device supports user plane security protection" can mean that the terminal device supports user plane encryption protection and / or user plane integrity protection, or that the terminal device supports enabling user plane encryption protection and / or user plane integrity protection. "Terminal device supports user plane security protection" can also be understood as "terminal device supports on-demand user plane security protection," meaning that whether the terminal device enables user plane encryption protection and / or user plane integrity protection is not fixed, but can be determined based on user plane security policies. Optionally, "terminal device supports on-demand user plane security protection" can also be understood as "terminal device supports enabling or disabling user plane encryption protection and / or user plane integrity protection under the instruction of the access network device." Similarly, "terminal device does not support user plane security protection" can mean that the terminal device does not support user plane encryption protection and / or user plane integrity protection, or that the terminal device does not support enabling user plane encryption protection and / or user plane integrity protection.
[0129] The first access network device can generate the aforementioned first indication information based on the context of the terminal device. In one possible implementation, the context of the terminal device includes a first security capability corresponding to the first communication standard. This first security capability is used to indicate one or more security algorithms (e.g., encryption protection algorithms and / or integrity protection algorithms) supported by the terminal device under the first communication standard, and may contain information related to whether the terminal device supports user plane security protection. Therefore, the first access network device can determine whether the terminal device supports user plane security protection based on the first security capability. If it is determined that the terminal device supports user plane security protection, the aforementioned first indication information is generated.
[0130] For example, when the first communication standard is a 4G network, the aforementioned first security capability can be the EPS security capability of the terminal device. This EPS security capability is used to indicate the security algorithms supported by the terminal device in the 4G network. The EPS security capability can consist of EPS encryption algorithms (EEA) 0 to EEA7 and EPS integrity algorithms (EIA) 0 to EIA7, where EIA7 can be used to indicate whether the terminal device supports user plane integrity protection. Thus, the first access network device can determine whether the terminal device supports user plane integrity protection based on the indication of EIA7 in the EPS security capability. If it is determined that the terminal device supports user plane integrity protection, the aforementioned first indication information is generated and sent to the second access network device. It can be understood that when EIA7 in the EPS security capability indicates that the terminal device supports user plane integrity protection, the corresponding first indication information can be used to indicate that the terminal device supports user plane integrity protection. Therefore, the first indication information can also be called user plane integrity protection (UPIP) indication information. Optionally, considering that terminal devices typically support user plane encryption protection by default, when it is determined that the terminal device supports user plane integrity protection according to the EIA7 indication in the EPS security capability of the terminal device, it can also be assumed that the terminal device supports user plane encryption protection at the same time. In this case, the first indication information can be used to indicate that the terminal device supports user plane integrity protection and / or user plane encryption protection.
[0131] In another possible implementation, the context of the terminal device includes a first wireless capability corresponding to the first communication standard. The first wireless capability is used to indicate one or more wireless communication capabilities supported by the terminal device for the first communication standard, and may include information related to whether the terminal device supports user plane security protection. Therefore, the first access network device can determine whether the terminal device supports user plane security protection based on the first security capability. If it is determined that the terminal device supports user plane security protection, the aforementioned first indication information is generated.
[0132] For example, when the first communication standard is a 4G network, the aforementioned first radio capability can be the evolved universal terrestrial radio access network (E-UTRAN) radio capability of the terminal device. This E-UTRAN radio capability is used to indicate the radio access capabilities in the E-URATN network supported by the terminal device. Thus, the first access network device can determine whether the terminal device supports user plane integrity protection based on whether the E-UTRAN radio capability contains an indication that the terminal device supports user plane security protection. If it is determined that the terminal device supports user plane integrity protection, the first indication information is generated and sent to the second access network device. It can be understood that when the E-UTRAN radio capability contains an indication that the terminal device supports user plane security protection, the corresponding first indication information can be used to indicate that the terminal device supports user plane integrity protection. Therefore, the first indication information can also be called user plane integrity protection (UPIP) indication information. For example, when the first communication standard is a 4G network, the aforementioned first radio capability can also be the multi-radio dual connectivity (MR-DC) radio capability of the terminal device. This MR-DC radio capability is used to indicate the radio access capabilities supported by the terminal device in a dual-connectivity network with E-URATN access standard. In particular, the MR-DC radio capability is transparent to the first access network device. Thus, the first access network device can generate the aforementioned first indication information based on the context of the terminal device. This can be understood as the first access network device sending the MR-DC radio capability of the terminal device's context to the second access network device when establishing dual connectivity. At this time, the generated first indication information is the MR-DC radio capability. It can be understood that when the MR-DC radio capability includes an indication that the terminal device supports user plane security protection, the corresponding first indication information can be used to indicate that the terminal device supports user plane integrity protection. Therefore, the first indication information can also be called user plane integrity protection (UPIP) indication information.
[0133] Optionally, in this embodiment, the first access network device may also send a user plane security policy to the second access network device. This user plane security policy may be received by the first access network device from the core network device, or it may be pre-configured in the first access network device; this application is not limited to this. The user plane security policy received by the first access network device from the core network device may be included in the context of the terminal device. The user plane security policy may be sent to the second access network device in the same message as the aforementioned first indication information, or it may be sent to the second access network device through different messages; this application is not limited to either approach.
[0134] The user plane security policy may include a user plane encryption protection policy and / or a user plane integrity protection policy. The user plane encryption protection policy indicates whether user plane encryption protection is enabled, and the user plane integrity protection policy indicates whether user plane integrity protection is enabled. The user plane encryption protection policy has three possible values: not needed, preferred, and required. The user plane integrity protection policy also has three possible values: not needed, preferred, and required. "Not needed" means it is not required, "preferred" means it can be enabled or disabled, and "required" means it must be enabled. These three possible values can be indicated using 2 bits; for example, 00 indicates it is not needed, 01 indicates it can be enabled or disabled, and 11 indicates it must be enabled.
[0135] The first access network device can send user plane security policies to the second access network device in the following two possible ways:
[0136] Method 1: Only send the user plane security policy received from the core network device. If no user plane security policy is received from the core network device, do not send the user plane security policy pre-configured in the first access network device.
[0137] Method 2: If a user plane security policy is received from the core network device, then the user plane security policy received from the core network device is sent. If no user plane security policy is received from the core network device, then the user plane security policy pre-configured in the first access network device is sent.
[0138] Figure 4 An example is shown of one possible implementation of the interaction between a first access network device and a second access network device. For example... Figure 4As shown, in step S401, the first access network device can send a secondary site addition request to the second access network device. This secondary site addition request is used to request resource allocation for the dual connectivity of the terminal device. The secondary site addition request includes the aforementioned first indication information. Optionally, the secondary site addition request may also include the aforementioned user plane security policy, and further, may include the second security capability corresponding to the second communication standard of the terminal device, such as the NR security capability of the terminal device. The secondary site addition request may be, for example, an SgNB addition request message, or other messages; this application is not limited to these.
[0139] The auxiliary station addition request is used to request the allocation of resources for the dual connectivity of the terminal device. It can also be understood as adding the second access network device as the auxiliary access network device in the dual connectivity of the terminal device and allocating resources for the dual connectivity of the terminal device.
[0140] For example, the first indication information may be a new information element in the secondary station addition request. For instance, the secondary station addition request may add an information element indicating the terminal device's EPS security capability, using EIA7 in the EPS security capability to indicate whether the terminal device supports user plane security. Another example is adding an information element indicating the terminal device's E-UTRAN radio capability, using whether the E-UTRAN radio capability includes an indication that the terminal device supports user plane security protection to indicate whether the terminal device supports user plane security. Alternatively, the first indication information may be a newly added 1-bit indication information in the secondary station addition request. When the indication information is 1, it can be used to indicate that the terminal device supports user plane security protection; when the indication information is 0, it can be used to indicate that the terminal device does not support user plane security protection. Alternatively, the first indication information can be encapsulated in the information elements already present in the auxiliary station addition request, such as the NR security capability of the terminal device. The NIA7 in the NR security capability can be used to indicate whether the terminal device supports user plane security protection. The NIA7 in the NR security capability can be mapped by the first access network device according to the EIA7 in the EPS security capability. Another example is the MR-DC radio capability of the terminal device. Whether the terminal device supports user plane security is indicated by whether the MR-DC radio capability contains an indication that the terminal device supports user plane security protection.
[0141] In this embodiment of the application, before the first access network device requests the second access network device to allocate resources for the dual connectivity of the terminal device and sends the first indication information, the first access network device may also select the second access network device, which can serve as the secondary access network device in the dual connectivity of the terminal device, in the following two ways:
[0142] Method 1: The first access network device selects the second access network device according to the existing logic. The first access network device does not need to pre-configure whether the access network devices of each second communication standard support user plane security protection. Therefore, the first access network device may select the second access network device that supports user plane security protection or it may select the second access network device that does not support user plane security protection.
[0143] Optionally, based on Method 1, the first access network device can further determine the user plane integrity protection policy. For example, taking the secondary site addition request as an SgNB Addition Request message, if the user plane integrity protection policy indicates "required," the first access network device can set the newly added information element (such as the first indication information and / or user plane security policy) as critical information of type "reject IE" in the SgNB Addition Request message, so that the second access network device will reject the request if it does not recognize the information element. If the user plane integrity protection policy indicates "not needed" or "preferred," the first access network device can set the newly added information element as critical information of type "ignore IE" in the SgNB Addition Request message, so that the second access network device will ignore the information element if it does not recognize it, but this will not affect subsequent processes.
[0144] Method 2: The first access network device pre-configures whether each access network device of the second communication standard supports user plane security protection, for example, through a network management system. In this way, the first access network device can select a second access network device that supports user plane security protection based on the context of the terminal device. For example, the context of the terminal device includes the terminal device's first security capability and user plane security policy, the first security capability corresponding to the first communication standard. The first access network device can select a second access network device based on the terminal device's first security capability and user plane security policy. Alternatively, the context of the terminal device includes the terminal device's first radio capability and user plane security policy, the first radio capability corresponding to the first communication standard. The first access network device can select a second access network device based on the terminal device's first radio capability and user plane security policy.
[0145] Taking user plane integrity protection as an example, if the terminal device supports user plane integrity protection and the user plane integrity protection policy indicates "required," then the first access network device can select a second access network device that supports user plane integrity protection. If a second access network device that supports user plane integrity protection cannot be selected, the first access network device cannot add / offload the E-UTRAN radio access bearer (E-RAB) corresponding to the user plane integrity protection policy to that second access network device. In other scenarios, such as when the user plane integrity protection policy indicates "preferred" or "not needed," the first access network device can select a second access network device that does not support user plane integrity protection.
[0146] In one example, the first access network device can determine whether the selected second access network device supports user plane security protection based on the terminal device's first security capability (or first radio capability) and user plane security policy. If it does not support user plane security protection, the first access network device will be changed to a second access network device that supports user plane security protection. For example, if the terminal device supports user plane integrity protection and the user plane integrity protection policy indicates "required," and the first access network device determines that the selected second access network device does not support user plane integrity protection, then the first access network device will reselect a second access network device that supports user plane integrity protection.
[0147] Step S302: The second access network device determines the security activation status based on the first instruction information and the user plane security policy.
[0148] In this embodiment, the second access network device can determine that the terminal device supports user plane security protection based on the first indication information, and then determine the security activation state according to the user plane security policy. The security activation state can be the security activation state corresponding to a bearer allocated to the terminal device, the bearer being used to transmit user plane data between the terminal device and the second access network device.
[0149] Corresponding to method 1 of the first access network device sending user plane security policies, if the second access network device receives a user plane security policy from the first access network device, the second access network device can determine the security activation state according to the received user plane security policy, provided that the terminal device supports user plane security protection, based on the first indication information. Otherwise, the second access network device can determine the security activation state according to the user plane security policy pre-configured in the second access network device, provided that the terminal device supports user plane security protection, based on the first indication information.
[0150] Corresponding to the above-mentioned method 2 for the first access network device to send user plane security policies, the second access network device can always receive user plane security policies from the first access network device. Then, according to the first instruction information, the second access network device determines the security activation state based on the received user plane security policies when the terminal device supports user plane security protection.
[0151] In other words, since sending user plane security policies from the first access network device to the second access network device is optional—that is, depending on the different ways the first access network device sends user plane security policies—if the first access network device does not receive user plane security policies from the core network device, it may send a pre-configured user plane security policy or it may not send a pre-configured user plane security policy. Therefore, the user plane security policy used by the second access network device when determining the security activation state can be the one received by the second access network device from the first access network device, or it can be pre-configured in the second access network device; this application does not limit this.
[0152] The security activation state is used to indicate whether user plane encryption protection and / or user plane integrity protection of the bearer are enabled. Specifically, the security activation state may include encryption activation state and integrity protection state. If the user plane encryption protection policy is required, the second access network device can determine that the encryption activation state of its corresponding bearer is enabled. If the user plane encryption protection policy is preferred, the second access network device can determine that the encryption activation state of its corresponding bearer can be enabled or disabled. The second access network device can determine whether to enable the encryption activation state based on local policies (e.g., its own operating status, control policies, regulatory requirements, etc.). If the user plane encryption protection policy is not needed, the second access network device can determine that the encryption activation state of its corresponding bearer is disabled.
[0153] If the user plane integrity protection policy is "required," the second access network device can determine that the integrity protection activation status of its corresponding bearers is enabled. If the user plane integrity protection policy is "preferred," the second access network device can determine that the integrity protection activation status of its corresponding bearers can be enabled or disabled. The second access network device can determine whether to enable the integrity protection activation status based on local policies (e.g., its own operating status, control policies, regulatory requirements, etc.). If the user plane integrity protection policy is "not needed," the second access network device can determine that the integrity protection activation status of its corresponding bearers is disabled.
[0154] Furthermore, the second access network device can also enable user plane security with the terminal device based on the determined security activation state, that is, enable the user plane encryption protection and / or user plane integrity protection carried by the device. The second access network device can enable user plane security with the terminal device immediately after determining the security activation state, or it can enable user plane security with the terminal device after receiving an enable instruction information from the terminal device; this application is not limited to this.
[0155] Alternatively, if the terminal device supports user plane security protection based on the first indication information, the second access network device enables user plane security protection for the bearer according to the user plane security policy. For example, if the terminal device supports user plane integrity protection based on the first indication information, the second access network device enables user plane integrity protection for the data radio bearer (DRB) according to the user plane integrity protection policy, and optionally, enables user plane integrity protection for each DRB.
[0156] The term "enable" can also be understood as "activate". The descriptions of "enable user plane security" mentioned below can be replaced with "activate user plane security".
[0157] Step S303: The second access network device sends the bearer identification information and security activation status to the first access network device.
[0158] Correspondingly, the first access network device receives the identification information and security activation status of the bearer from the second access network device.
[0159] The identification information carried can be the DRB identifier (drb-identity), EPS bearer identifier (EPS-BearerIdentity), etc., without limitation.
[0160] For example, such as Figure 4 As shown, in step S402, the second access network device can determine the security activation state based on the first indication information and the user plane security policy. Optionally, at this time, the second access network device can enable user plane security with the terminal device based on the security activation state. Furthermore, in step S403, the second access network device can send a secondary site addition response to the first access network device, indicating that the second access network device has completed the preparation for adding a secondary site. This secondary site addition response includes the bearer's identification information and the security activation state. This secondary site addition response can be, for example, an SgNB additionrequest ACK message, an SgNB addition response message, or other messages; this application is not limited to these.
[0161] Optionally, the auxiliary station may include an NR RRC reconfiguration message in its response. This NR RRC reconfiguration message is transparent to the first access network device and includes the identification information and security activation status of the aforementioned bearer.
[0162] Optionally, the secondary site add response may carry a support enable indication. This enable indication is used to instruct the second access network device to support user plane security protection or to enable user plane security according to the user plane security policy. The first access network device makes an additional determination based on this support enable indication after receiving the secondary site add response. For example, if the current user plane integrity protection policy indicates "required," but the first access network device has not received a support enable indication, the first access network device may trigger a secondary site release procedure, such as the SgNB Release procedure, to instruct the second access network device to release the resources allocated for the dual connectivity of the terminal device. Optionally, the first access network device may reselect a second access network device. If the current user plane integrity protection policy indicates "required," but the first access network device has received a support enable indication, or if the current user plane integrity protection policy indicates "preferred" or "not needed," the first access network device may continue to execute the following steps.
[0163] Step S304: The first access network device sends the bearer identification information and security activation status to the terminal device.
[0164] Accordingly, the terminal device receives the identification information and security activation status of the bearer from the first access network device.
[0165] For example, such as Figure 4 As shown, in step S404, the first access network device may send an RRC reconfiguration message to the terminal device. This RRC reconfiguration message includes the identification information and security activation status of the aforementioned bearer. Optionally, the RRC reconfiguration message may include an NR RRC reconfiguration message transparently transmitted by the first access network device, which carries the identification information and security activation status of the aforementioned bearer.
[0166] Step S305: The terminal device enables user plane security with the second access network device based on the identification information and security activation status of the bearer, that is, enables user plane encryption protection and / or user plane integrity protection of the bearer.
[0167] Optionally, after enabling user plane security with the second access network device, the terminal device may send an activation indication message to the first access network device, which then sends the activation indication message to the second access network device. This activation indication message indicates that the terminal device has enabled user plane security with the second access network device. Thus, if the second access network device, after determining the security activation state, has not enabled user plane security with the terminal device, the second access network device may, upon receiving the activation indication message, enable user plane security with the terminal device according to the activation indication message.
[0168] For example, such as Figure 4 As shown, in step S405, the terminal device can configure the second access network device as the secondary access network device in the dual-connectivity configuration based on the received RRC reconfiguration message, and enable user plane security with the second access network device according to the bearer's identifier and security activation status. Further, in step S406, the terminal device can send an RRC reconfiguration completion message to the first access network device. This RRC reconfiguration completion message carries an NR RRC response message, which is transparent to the first access network device. Optionally, the NR RRC response message includes activation indication information to indicate that the terminal device has enabled user plane security with the second access network device. In step S407, the first access network device can send an RRC reconfiguration completion message to the second access network device. This RRC reconfiguration completion message includes the NR RRC response message transparently transmitted by the first access network device. After receiving the NR RRC response message, the second access network device can determine that the terminal device has completed the relevant dual-connectivity configuration.
[0169] The above technical solution enhances the processing logic of the first access network device (primary access network device) and the second access network device (secondary access network device) in the auxiliary station addition process under cross-system dual-connectivity scenarios. The first access network device can send a first indication message to the second access network device, indicating that the terminal device supports user plane security protection, or further, send a user plane security policy. The second access network device determines the security activation status based on the first indication message and the user plane security policy and sends it to the terminal device, thereby enabling user plane security between the terminal device and the second access network device on demand. Simultaneously, the first access network device can also determine whether the second access network device supports user plane security protection based on the user plane integrity protection policy, thus avoiding the problem of the second access network device ignoring the user plane integrity protection policy because it does not support it when the user plane integrity protection policy is indicated as enabled, which would lead to a decrease in security.
[0170] Option 2
[0171] Please refer toFigure 5 The above is a flowchart illustrating a method for activating security according to an embodiment of this application. The method includes:
[0172] Step S501: The first access network device of the first communication standard selects a second access network device that supports user plane security protection based on the context of the terminal device.
[0173] The first access network device is the primary access network device in the dual connection of the terminal device, and the second access network device is the secondary access network device in the dual connection of the terminal device.
[0174] In one possible implementation, the context of the terminal device includes a first security capability and a user plane security policy, the first security capability corresponding to a first communication standard. Thus, the first access network device can determine, based on the terminal device's first security capability, that the terminal device supports user plane security protection, and then further select a second access network device based on the user plane integrity protection policy.
[0175] In another possible implementation, the context of the terminal device includes a first radio capability and a user plane security policy, the first radio capability corresponding to a first communication standard. Thus, the first access network device can determine, based on the terminal device's first radio capability, that the terminal device supports user plane security protection, and then further select a second access network device based on the user plane integrity protection policy.
[0176] For example, such as Figure 6 As shown, in step S601, the first access network device can select the second access network device based on whether the terminal device supports user plane security protection and user plane security policies.
[0177] Taking the user plane security policy as a user plane integrity protection policy as an example, if the terminal device supports user plane security protection and the user plane integrity protection policy in the user plane security policy is required, then the first access network device can select a second access network device that supports user plane security protection (for example, the first access network device may have pre-configured the capability of each access network device of the second communication standard to support user plane security protection through the network management system), and send the user plane security policy to the second access network device. If a second access network device that supports user plane security protection cannot be selected, then the first access network device cannot add / offload the E-RAB corresponding to the user plane integrity protection policy to the second access network device.
[0178] If the terminal device supports user plane security protection, and the user plane integrity protection policy in the user plane security policy is preferred / not needed, then the first access network device can preferentially select the second access network device that supports user plane security protection and send the user plane security policy to the second access network device. If a second access network device that supports user plane security protection cannot be selected, the first access network device can also select a second access network device that does not support user plane security protection and add / offload the E-RAB corresponding to the user plane integrity protection policy to the second access network device.
[0179] If the terminal device does not support user plane security protection, and the user plane integrity protection policy in the user plane security policy is preferred / not needed, then the first access network device will select the second access network device according to the existing logic, and will not send the user plane security policy to the second access network device.
[0180] In one example, the first access network device can determine whether the selected second access network device supports user plane security protection based on the terminal device's first security capability (or first radio capability) and user plane security policy. If it does not support user plane security protection, the first access network device will be changed to a second access network device that supports user plane security protection. For example, if the terminal device supports user plane integrity protection and the user plane integrity protection policy indicates "required," and the first access network device determines that the selected second access network device does not support user plane integrity protection, then the first access network device will reselect a second access network device that supports user plane integrity protection.
[0181] Step S502: The first access network device requests the second access network device to allocate resources for the dual connectivity of the terminal device and sends a user plane security policy to the second access network device.
[0182] Accordingly, the second access network device accepts the request from the first access network device to allocate resources for dual connectivity of the terminal device, and receives the user plane security policy from the first access network device.
[0183] The first access network device's request for the second access network device to allocate resources for the dual connectivity of the terminal device, and the sending of user plane security policies to the second access network device, can be achieved by the first access network device sending a message to the second access network device, such as a secondary station addition request message; or by sending two messages respectively, which is not limited in this application.
[0184] The aforementioned user plane security policy can be obtained in two ways. If the first access network device receives the user plane security policy from the core network device, the first access network device can send the user plane security policy received from the core network device. If the first access network device does not receive the user plane security policy from the core network device, but the terminal device supports user plane integrity protection, the first access network device can send a pre-configured user plane security policy.
[0185] For example, such as Figure 6 As shown, in step S602, the first access network device may send a secondary site addition request to the second access network device. This secondary site addition request is used to request resource allocation for the dual connectivity of the terminal device. The secondary site addition request includes a user plane security policy, which may be received by the first access network device from the core network device or pre-configured in the first access network device; it is not limited to this. Furthermore, the secondary site addition request may also include a second security capability corresponding to the second communication standard of the terminal device, such as the NR security capability of the terminal device. The secondary site addition request may be, for example, an SgNB addition request message, or other messages; this application does not limit the scope.
[0186] Step S503: The second access network device determines the security activation status according to the user plane security policy.
[0187] In this embodiment, the second access network device determines a security activation state based on the user plane security policy received from the first access network device. This security activation state may be the security activation state corresponding to a bearer allocated to the terminal device, the bearer being used to transmit user plane data between the terminal device and the second access network device.
[0188] The security activation status indicates whether user plane encryption protection and / or user plane integrity protection are enabled for the bearer. For details, please refer to the relevant description in step S302 above.
[0189] Furthermore, the second access network device can also enable user plane security with the terminal device based on the determined security activation state, that is, enable the user plane encryption protection and / or user plane integrity protection carried by the device. The second access network device can enable user plane security with the terminal device immediately after determining the security activation state, or it can enable user plane security with the terminal device after receiving an enable instruction information from the terminal device; this application is not limited to this.
[0190] Alternatively, the second access network device enables user plane security protection based on the user plane security policy. For example, if the user plane integrity protection policy is required, the second access network device enables user plane integrity protection for the DRB; optionally, it enables user plane integrity protection for each DRB.
[0191] Step S504: The second access network device sends the bearer's identification information and security activation status to the first access network device. The security activation status is used to indicate whether user plane encryption protection and / or user plane integrity protection of the bearer are enabled.
[0192] Correspondingly, the first access network device receives the identification information and security activation status of the bearer from the second access network device.
[0193] The identification information carried can be the DRB identifier (drb-identity), EPS bearer identifier (EPS-BearerIdentity), etc., without limitation.
[0194] For example, such as Figure 6 As shown, in step S603, the second access network device can determine the security activation state based on the user plane security policy received from the first access network device. Optionally, the second access network device can then enable user plane security with the terminal device based on this security activation state. Furthermore, in step S604, the second access network device can send a secondary site addition response to the first access network device, indicating that the second access network device has completed the preparation for adding a secondary site. This secondary site addition response includes the bearer's identification information and the security activation state. This secondary site addition response can be, for example, an SgNB addition request ACK message, an SgNB addition response message, or other messages; this application is not limited to these.
[0195] Optionally, the auxiliary station addition response may include an NR RRC reconfiguration message, which is transparent to the first access network device and carries the identification information and security activation status of the aforementioned bearer.
[0196] Optionally, the secondary site addition response may carry a support enable indication, which the first access network device uses for additional judgment after receiving the secondary site addition response. For example, if the current user plane integrity protection policy indicates "required," but the first access network device has not received a support enable indication, the first access network device may trigger a secondary site release procedure, such as the SgNB Release procedure, to instruct the second access network device to release the resources allocated for the dual connectivity of the terminal device. Optionally, the first access network device may reselect a second access network device. If the current user plane integrity protection policy indicates "required," but the first access network device has received a support enable indication, or if the current user plane integrity protection policy indicates "preferred" or "not needed," the first access network device may continue to execute the following steps.
[0197] Step S505: The first access network device sends the bearer identification information and security activation status to the terminal device.
[0198] Accordingly, the terminal device receives the identification information and security activation status of the bearer from the first access network device.
[0199] For example, such as Figure 6 As shown, in step S605, the first access network device may send an RRC reconfiguration message to the terminal device. This RRC reconfiguration message includes the identification information and security activation status of the aforementioned bearer. Optionally, the RRC reconfiguration message may include an NR RRC reconfiguration message transparently transmitted by the first access network device, which carries the identification information and security activation status of the aforementioned bearer.
[0200] Step S506: The terminal device enables user plane security with the second access network device based on the identification information and security activation status of the bearer, that is, enables user plane encryption protection and / or user plane integrity protection of the bearer.
[0201] Optionally, after enabling user plane security with the second access network device, the terminal device may send an activation indication message to the first access network device, which then sends the activation indication message to the second access network device. This activation indication message indicates that the terminal device has enabled user plane security with the second access network device. Thus, if the second access network device, after determining the security activation state, has not enabled user plane security with the terminal device, the second access network device may, upon receiving the activation indication message, enable user plane security with the terminal device according to the activation indication message.
[0202] For example, such as Figure 6As shown, in step S606, the terminal device can configure the second access network device as the secondary access network device in the dual-connectivity configuration based on the received RRC reconfiguration message, and enable user plane security with the second access network device according to the carried identification information and security activation status. Further, in step S607, the terminal device can send an RRC reconfiguration completion message to the first access network device. This RRC reconfiguration completion message includes an NR RRC response message, which is transparent to the first access network device. Optionally, the NR RRC response message carries activation indication information to indicate that the terminal device has enabled user plane security with the second access network device. In step S608, the first access network device can send an RRC reconfiguration completion message to the second access network device. This RRC reconfiguration completion message includes an NR RRC response message transparently transmitted by the first access network device. After receiving the NR RRC response message, the second access network device can determine that the terminal device has completed the relevant configuration for dual connectivity.
[0203] The above technical solution enhances the processing logic of the first access network device (primary access network device) and the second access network device (secondary access network device) in the auxiliary station addition process under cross-system dual-connectivity scenarios. The first access network device determines whether the terminal device supports user plane security protection. If the terminal device supports user plane security protection, it selects the second access network device that supports user plane security protection according to the user plane security policy and sends the user plane security policy to the second access network device. The second access network device then determines the security activation status according to the user plane security policy and sends it to the terminal device, thereby enabling user plane security between the terminal device and the second access network device on demand.
[0204] Option 3
[0205] Please refer to Figure 7 The above is a flowchart illustrating a method for activating security according to an embodiment of this application. The method includes:
[0206] Step S701: The first access network device of the first communication standard requests the second access network device of the second communication standard to allocate resources for the dual connection of the terminal device. The first access network device is the primary access network device in the dual connection of the terminal device, and the second access network device is the secondary access network device in the dual connection of the terminal device.
[0207] Correspondingly, the second access network device accepts the request from the first access network device to allocate resources for the dual connectivity of the terminal device.
[0208] For example, such as Figure 8As shown, if the processing logic of the first access network device is not enhanced, the first access network device may not support user plane security protection. In this case, even if the first security capability (such as UE EPS security capability) or the first radio capability (such as UE E-UTRAN radio capability) corresponding to the first communication standard indicates that the terminal device supports user plane security protection, the first access network device cannot transmit the first indication information to the second access network device during the secondary site addition procedure, and the user plane security policy may also be lost. In step S801, if the first access network device decides to request the second access network device to allocate resources for a specific E-RAB, the first access network device can initiate a secondary site addition procedure and send a secondary site addition request to the second access network device. This secondary site addition request is used to request the allocation of resources for the dual connectivity of the terminal device. This secondary site addition request may include the second security capability corresponding to the second communication standard of the terminal device, such as the NR security capability of the terminal device. It should be noted that this secondary site addition request does not include the first indication information and user plane security policy mentioned above. The auxiliary station addition process can be an SgNB Addition process, and the auxiliary station addition request can be an SgNB addition request message, or other messages. This application does not limit the specific message.
[0209] Step S702: The second access network device sends a first request message to the terminal device through the first access network device. The first request message is used to request the terminal device to support user plane security.
[0210] Correspondingly, the terminal device receives the first request information from the second access network device through the first access network device.
[0211] For example, such as Figure 8As shown, after the second access network device receives a secondary site addition request from the first access network device, in step S802, if the second access network device supports user plane security protection, but has not received the first indication information and / or user plane security policy, then the second access network device determines to carry the first request information in the secondary site addition response. This first request information is used to request the terminal device's support capability for user plane security. This first request information can also be called a UPIP request indication, used to request whether the terminal device supports user plane security protection. The second access network device can also allocate resources for the requested E-RAB and construct an NR RRC reconfiguration message based on the received secondary site addition request. In step S803, the second access network device can send a secondary site addition response to the first access network device, which includes the first request information. The secondary site addition response can be an SgNB addition request ACK message or an SgNBaddition response message, or other messages; this application is not limited to these. Optionally, the auxiliary station addition response may include an NR RRC reconfiguration message, which is transparent to the first access network device and carries the aforementioned first request information (i.e., a UPIP request indication). In step S804, the first access network device may send an RRC reconfiguration message to the terminal device, which includes the aforementioned first request information (i.e., a UPIP request indication). Optionally, the RRC reconfiguration message may include a transparently transmitted NR RRC reconfiguration message, which carries the aforementioned first request information (i.e., a UPIP request indication).
[0212] Step S703: The terminal device sends a second indication message to the second access network device through the first access network device. The second indication message is used to indicate that the terminal device supports user plane security protection.
[0213] Correspondingly, the second access network device receives the second instruction information from the terminal device through the first access network device.
[0214] For example, such as Figure 8As shown, after receiving the RRC reconfiguration message from the first access network device, if the terminal device supports user plane security protection, it can send second indication information to the second access network device according to the indication of the first request information therein. This second indication information is used to indicate that the terminal device supports user plane security protection, and it can be one bit. Specifically, in step S805, the terminal device can send an RRC reconfiguration completion message to the first access network device, which includes the aforementioned second indication information. Optionally, the RRC reconfiguration completion message includes an NR RRC response message, which is transparent to the first access network device and carries the aforementioned second indication information. Furthermore, in step S806, the first access network device can send another RRC reconfiguration completion message to the second access network device, which includes the aforementioned second indication information. Optionally, the RRC reconfiguration completion message may include a transparently transmitted NR RRC response message, which carries the aforementioned second indication information.
[0215] Step S704: The second access network device determines the security activation status based on the second instruction information and the user plane security policy.
[0216] In this embodiment, the second access network device can determine that the terminal device supports user plane security protection based on the second indication information, and then determine the security activation state according to the user plane security policy. The user plane security policy is pre-configured in the second access network device, or may be referred to as the default user plane security policy. The security activation state may be the security activation state corresponding to a bearer allocated to the terminal device, which is used to transmit user plane data between the terminal device and the second access network device.
[0217] The security activation status indicates whether user plane encryption protection and / or user plane integrity protection are enabled for the bearer. For details, please refer to the relevant description of step S302 above.
[0218] Furthermore, the second access network device can also enable user plane security with the terminal device based on the determined security activation state, that is, enable the user plane encryption protection and / or user plane integrity protection carried by the device. The second access network device can enable user plane security with the terminal device immediately after determining the security activation state, or it can enable user plane security with the terminal device after receiving an enable instruction information from the terminal device; this application is not limited to this.
[0219] Alternatively, if the terminal device supports user plane security protection based on the second indication information, the second access network device enables user plane security protection for the bearer according to the user plane security policy. For example, if the terminal device supports user plane integrity protection based on the second indication information, the second access network device enables user plane integrity protection for the data radio bearer (DRB) according to the user plane integrity protection policy, and optionally, enables user plane integrity protection for each DRB.
[0220] Step S705: The second access network device sends the bearer's identification information and security activation status to the terminal device through the first access network device. The security activation status is used to indicate whether to enable user plane encryption protection and / or user plane integrity protection for the bearer.
[0221] Correspondingly, the terminal device receives the identification information and security activation status carried by the second access network device through the first access network device.
[0222] The identification information of the bearer can be a data radio bearer, the identifier of a DRB (drb-identity), the identifier of an EPS bearer (EPS-BearerIdentity), etc., without limitation.
[0223] For example, such as Figure 8As shown, in step S807, the second access network device determines the security activation state based on the second indication information and the pre-configured user plane security policy. Optionally, the second access network device can enable user plane security with the terminal device based on this security activation state. Since it is necessary to update the security activation state with the UE, in step S808, the second access network device can trigger a secondary site modification procedure (such as an SgNB modification procedure). The second access network device can send a secondary site modification request to the first access network device to request the first access network device to modify the resources allocated by the second access network device for the UE. This secondary site modification request can be an SgNB Modification Required message or other messages, which are not limited in this application. In step S809, the first access network device sends a secondary site modification request to the second access network device to request the second access network device to prepare for modifying the resources allocated for the UE. This secondary site modification request can be an SgNB Modification Request message or other messages, which are not limited in this application. In step S810, the second access network device may send a secondary site modification response to the first access network device to confirm the completion of resource allocation for the UE. This secondary site modification response includes bearer identification information and security activation status. The secondary site modification response can be an SgNB Modification Request ACK message or other messages, and is not limited thereto. Optionally, the secondary site modification response includes an NR RRC reconfiguration message, which is transparent to the first access network device and carries the aforementioned bearer identification information and security activation status. In step S811, the first access network device sends an RRC reconfiguration message to the terminal device. This RRC reconfiguration message includes bearer identification information and security activation status. Optionally, this RRC reconfiguration message includes an NR RRC reconfiguration message transparently transmitted by the first access network device, which carries the aforementioned bearer identification information and security activation status.
[0224] Step S706: The terminal device enables user plane security with the second access network device based on the identification information and security activation status of the bearer, that is, enables user plane encryption protection and / or user plane integrity protection of the bearer.
[0225] Optionally, after enabling user plane security with the second access network device, the terminal device may send an activation indication message to the first access network device, which then sends the activation indication message to the second access network device. This activation indication message indicates that the terminal device has enabled user plane security with the second access network device. Thus, if the second access network device, after determining the security activation state, has not enabled user plane security with the terminal device, the second access network device may, upon receiving the activation indication message, enable user plane security with the terminal device according to the activation indication message.
[0226] For example, such as Figure 8 As shown, in step S812, the terminal device can configure the second access network device as the secondary access network device in dual connectivity according to the received RRC reconfiguration message, and enable user plane security between itself and the second access network device according to the security activation state. In step S813, the terminal device can send an RRC reconfiguration completion message to the first access network device. This RRC reconfiguration completion message includes an NR RRC response message, which is transparent to the first access network device. Optionally, the NR RRC response message includes activation indication information to indicate that the terminal device has enabled user plane security between itself and the second access network device. In step S814, the first access network device sends an RRC reconfiguration completion message to the second access network device. This RRC reconfiguration completion message includes a transparently transmitted NR RRC response message, and the second access network device can determine that the terminal device has completed the relevant configuration for dual connectivity based on the NR RRC response message.
[0227] The above technical solution enhances the processing logic of the first access network device (primary access network device) and the second access network device (secondary access network device) in the auxiliary station addition process under cross-system dual-connectivity scenarios. After receiving a request to allocate resources for dual connectivity of the terminal device, the second access network device can interact with the terminal device through the first access network device to obtain the terminal device's support capability for user plane security. Then, if the terminal device supports user plane security protection, it determines the security activation status according to the user plane security policy and sends it to the terminal device, thereby enabling user plane security between the terminal device and the second access network device on demand.
[0228] Option 4
[0229] Please refer to Figure 9 The above is a flowchart illustrating a method for activating security according to an embodiment of this application. The method includes:
[0230] Step S901: The first access network device of the first communication standard requests the second access network device of the second communication standard to allocate resources for the dual connection of the terminal device. The first access network device is the primary access network device in the dual connection of the terminal device, and the second access network device is the secondary access network device in the dual connection of the terminal device.
[0231] Correspondingly, the second access network device accepts the request from the first access network device to allocate resources for the dual connectivity of the terminal device.
[0232] For example, such as Figure 10 As shown, if the processing logic of the first access network device is not enhanced, the first access network device may not support user plane security protection. In this case, even if the first security capability (such as UE EPS security capability) or the first radio capability (such as UE E-UTRAN radio capability) corresponding to the first communication standard indicates that the terminal device supports user plane security protection, the first access network device cannot add a procedure at the secondary station to transmit the first indication information to the second access network device, and the user plane security policy may also be lost.
[0233] In step S1001, if the first access network device decides to request the second access network device to allocate resources for a specific E-RAB, the first access network device can initiate a secondary site addition procedure, sending a secondary site addition request to the second access network device. This secondary site addition request is used to request resource allocation for the dual connectivity of the terminal device. The secondary site addition request may include the second security capabilities corresponding to the second communication standard of the terminal device, such as the NR security capabilities of the terminal device. It should be noted that this secondary site addition request does not include the first indication information and user plane security policy mentioned above. The secondary site addition procedure can be an SgNBAddition procedure, and the secondary site addition request can be an SgNB addition request message, or other messages; this application is not limited to any of these.
[0234] Step S902: The second access network device determines the security activation status according to the user plane security policy.
[0235] The user plane security policy is pre-configured in the second access network device, or it can be referred to as the default user plane security policy. The security activation state can be the security activation state corresponding to the bearer allocated to the terminal device, which is used to transmit user plane data between the terminal device and the second access network device.
[0236] The security activation status indicates whether user plane encryption protection and / or user plane integrity protection are enabled for the bearer. For details, please refer to the relevant description in step S302.
[0237] It should be noted that in this fourth scheme, since the second access network device does not receive the first indication information to indicate that the terminal device supports user plane security protection, the second access network device does not know whether the terminal device supports user plane security protection. Therefore, it determines the security activation state based on the pre-configured user plane security policy. Thus, in this case, after determining the security activation state, the second access network device may temporarily not enable user plane security with the terminal device, but will only enable user plane security with the terminal device after receiving the activation indication information from the terminal device.
[0238] For example, such as Figure 10 As shown, after the second access network device receives a secondary site addition request from the first access network device, in step S1002, if the second access network device supports user plane security protection, but the second access network device has not received the first indication information and / or user plane security policy, then the second access network device can determine the security activation state according to the pre-configured user plane security policy. The second access network device can also allocate resources for the requested E-RAB and construct an NR RRC reconfiguration message based on the secondary site addition request received from the first access network device.
[0239] Step S903: The second access network device sends the bearer's identification information and security activation status to the terminal device through the first access network device. The security activation status is used to indicate whether to enable user plane encryption protection and / or user plane integrity protection for the bearer.
[0240] Correspondingly, the terminal device receives the identification information and security activation status carried by the second access network device through the first access network device.
[0241] The identification information of the bearer can be a data radio bearer, the identifier of a DRB (drb-identity), the identifier of an EPS bearer (EPS-BearerIdentity), etc., without limitation.
[0242] Optionally, the second access network device can also send an acknowledgment information to the terminal device through the first access network device. This acknowledgment information instructs the terminal device to send an activation indication after enabling user plane security with the second access network device. The acknowledgment information can also be called an activation acknowledgment. This acknowledgment information can be an additional 1-bit indication or can be implicitly indicated using a security activation status. The implicit indication means that if the second access network device sends a security activation status, it indicates the existence of the acknowledgment information; if the second access network device does not send a security activation status, it indicates the absence of the acknowledgment information.
[0243] For example, such as Figure 10As shown, in step S1003, the second access network device may send a secondary site addition response to the first access network device. This response includes the bearer's identification information and security activation status. Optionally, the secondary site addition response may also include acknowledgment information, which is a 1-bit indication information in the response. The secondary site addition response may be an SgNB addition request ACK message or an SgNB addition response message, or other messages; this application is not limited to any particular message. Optionally, the secondary site addition response may include an NR RRC reconfiguration message, which is transparent to the first access network device. This message carries the bearer's identification information and security activation status, and optionally, also includes acknowledgment information. In step S1004, the first access network device may send an RRC reconfiguration message to the terminal device. This message includes the bearer's identification information and security activation status, and optionally, also includes acknowledgment information. Optionally, the RRC reconfiguration message includes a transparent NRRRC reconfiguration message, which carries the identification information and security activation status of the aforementioned bearer. Optionally, it also includes confirmation indication information.
[0244] Step S904: The terminal device enables user plane security with the second access network device based on the identification information and security activation status of the bearer, that is, enables user plane encryption protection and / or user plane integrity protection of the bearer.
[0245] Step S905: The terminal device sends an activation indication message to the second access network device through the first access network device. The activation indication message is used to indicate that the terminal device has enabled user plane security with the second access network device.
[0246] Correspondingly, the second access network device receives the activation instruction information from the terminal device through the first access network device.
[0247] In this embodiment, if the terminal device supports user plane security protection, it can enable user plane security with the second access network device based on the received security activation status, and then send the aforementioned activation instruction information to the second access network device based on the confirmation instruction information or the security activation status. Otherwise, if the terminal device does not support user plane security protection, it may not perform any processing, such as discarding or ignoring the received bearer identification information and security activation status.
[0248] Step S906: The second access network device enables user plane security with the terminal device according to the activation instruction information and security activation status.
[0249] For example, such asFigure 10 As shown, in step S1005, if the terminal device supports user plane security protection, the terminal device can configure the second access network device as the secondary access network device in dual connectivity according to the received RRC reconfiguration message, and enable user plane security with the second access network device according to the security activation state. In step S1006, the terminal device can send an RRC reconfiguration completion message to the first access network device. This RRC reconfiguration completion message includes an NR RRC response message, which is transparent to the first access network device. The NR RRC response message includes activation indication information to indicate whether the terminal device has enabled user plane security with the second access network device. In step S1007, the first access network device sends an RRC reconfiguration completion message to the second access network device. This RRC reconfiguration completion message includes a transparently transmitted NR RRC response message, which includes activation indication information. Furthermore, in step S1008, the second access network device can activate user plane security with the terminal device according to the previously determined security activation state based on the activation indication information in the NR RRC response message. If no activation instruction is received, the second access network device can activate user plane security with the terminal device in the default manner, that is, enable user plane encryption protection but not user plane integrity protection.
[0250] The above technical solution enhances the processing logic of the first access network device (primary access network device) and the second access network device (secondary access network device) in the auxiliary site addition process under a cross-system dual-connectivity scenario. After receiving the auxiliary site addition request, if the second access network device does not receive the first indication information or user plane security policy, it can determine the security activation status according to the pre-configured user plane security policy and send it to the terminal device. If the terminal device supports user plane security protection, it can enable user plane security with the second access network device based on the received security activation status and send an activation indication information. This allows the second access network device to enable user plane security with the terminal device after receiving the activation indication information sent by the terminal device, thereby achieving on-demand activation of user plane security between the terminal device and the second access network device. If the terminal device does not support user plane security protection, it can perform no processing, such as discarding or ignoring the received bearer identification information and security activation status. It can be seen that this technical solution can determine the security activation status and send it to the terminal device based on the pre-configured user plane security policy when it is uncertain whether the terminal device supports user plane security protection. Compared with the technical solution that confirms with the terminal device whether it has the ability to support user plane security protection before determining the security activation status, it can effectively reduce signaling overhead.
[0251] The following section uses MeNB as the first access network device and SgNB as the second access network device as an example to explain in detail the method for activating security in this application.
[0252] Figure 11 This is a flowchart illustrating a method for activating security, as provided in an embodiment of this application. Figure 11 As shown, the method includes:
[0253] Step 1: The MeNB selects the SgNB and carries the second UPIP indication in the SgNB Addition Request message according to the EIA7 indication in the UE EPS security capability or the indication supporting user plane security protection contained in the UE E-UTRAN / MR-DC radio capability (the above three indications are referred to as the first user plane integrity protection UPIP indication in this application).
[0254] There are two ways to select an SgNB for a MeNB:
[0255] Method 1: The MeNB selects the SgNB based on the existing logic. In this case, the MeNB does not need to pre-configure whether the SgNB supports UPIP. Therefore, the MeNB may select an SgNB that supports UPIP or an SgNB that does not support UPIP.
[0256] Method 2: The MeNB pre-configures whether the SgNB supports UPIP (e.g., through the network management system). Based on the user plane integrity protection policy, if the policy indicates "required," the MeNB selects an SgNB that supports UPIP. If an SgNB supporting UPIP cannot be selected, the MeNB cannot add / offload the E-UTRAN radio access bearer (E-RAB) corresponding to that user plane integrity protection policy to the SgNB. In other scenarios, the MeNB can select an SgNB that does not support UPIP. Furthermore, the MeNB can select an SgNB that supports UPIP based on the user plane integrity protection policy and the first UPIP indication. Specifically, if the user plane integrity protection policy indicates "required" and the first UPIP indication indicates that the UE supports UPIP, the MeNB selects an SgNB that supports UPIP.
[0257] Building upon Method 1, MeNB can perform additional checks on the user plane integrity protection policy. For example, if the user plane integrity protection policy indicates "required," MeNB will set the new information element (e.g., the second UPIP indication and / or user plane security policy) to "critical information" of type "reject IE" in the SgNB Addition Request message. This ensures that SgNB will reject the SgNB Addition Request if it does not recognize this information element. If the user plane integrity protection policy indicates "not needed" or "preferred," MeNB will set the new information element to "critical information" of type "ignore IE" in the SgNB Addition Request message. This ensures that SgNB will ignore this information element if it does not recognize it, but this will not affect subsequent processes.
[0258] One possible implementation is that if the MeNB determines that the UE supports UPIP based on the UE's current context, it carries a second UPIP indication in step 2, which indicates that the UE supports UPIP. For example, the MeNB can determine that the UE supports UPIP based on the EIA7 indication in the UE's EPS security capabilities; or, the MeNB can determine that the UE supports UPIP based on the indication that the UE supports user plane security protection contained in the UE's E-UTRAN radio capabilities. The second UPIP indication can be the following: a new information element in the SgNB Addition Request message (e.g., UE EPS security capabilities (containing EIA7), or a new 1 bit) used to indicate that the UE supports UPIP. Alternatively, it can be encapsulated in an existing information element in the SgNB Addition Request message, such as the UENR security capabilities; one approach is for the MeNB to map EIA7 to NIA7.
[0259] Another possible implementation is that the MeNB directly carries a second UPIP indication in step 2 based on the UE's current context. This second UPIP indication is used to indicate that the UE supports UPIP. For example, the MeNB uses the MR-DC radio capability in the UE's current context as the second UPIP indication.
[0260] Step 2: The MeNB sends an SgNB Addition Request message to the SgNB, which carries a second UPIP indication. This message is used to request resource allocation for the UE's dual connectivity.
[0261] MeNB sends user plane security policies in two ways, among which:
[0262] Method 1: Only send the user plane security policy received from the core network. If no user plane security policy is received from the core network, do not send the user plane security policy pre-configured in the MeNB.
[0263] Method 2: If a user plane security policy is received from the core network, then send the user plane security policy received from the core network. If no user plane security policy is received from the core network, then send the user plane security policy pre-configured in the MeNB.
[0264] Based on the two methods of MeNB sending user plane security policies mentioned above, it can be seen that the SgNB Addition Request message can optionally carry user plane security policies.
[0265] User plane security policies include user plane encryption protection policies and / or user plane integrity protection policies. The user plane encryption protection policy indicates whether user plane encryption protection is enabled, and the user plane integrity protection policy indicates whether user plane integrity protection is enabled. Both user plane encryption and integrity protection policies have three possible values: not needed, preferred, and required. "Not needed" means it doesn't need to be enabled, "preferred" means it can be enabled or disabled, and "required" means it must be enabled. These three possible values can be indicated using 2 bits; for example, 00 indicates it doesn't need to be enabled, 01 indicates it can be enabled or disabled, and 11 indicates it must be enabled.
[0266] Step 3: SgNB determines the security activation status based on the second UPIP instruction and the user plane security policy.
[0267] Corresponding to method 1 of MeNB sending user plane security policies described above, if SgNB receives a user plane security policy from MeNB, SgNB can determine the security activation state based on the received user plane security policy, provided the UE supports UPIP, according to the second UPIP instruction. Otherwise, SgNB can determine the security activation state based on the user plane security policy pre-configured on SgNB, provided the UE supports UPIP, according to the second UPIP instruction.
[0268] Corresponding to the above-mentioned method 2 for MeNB to send user plane security policies, SgNB always receives user plane security policies from MeNB. Then, according to the second UPIP instruction, if the UE supports UPIP, SgNB determines the security activation state based on the received user plane security policies.
[0269] The security activation status indicates whether user plane encryption protection and / or user plane integrity protection are enabled. Specifically, the SgNB determines the bearer's user plane security activation status based on the user plane security policy.
[0270] Specifically, if the user plane encryption protection policy is "required," the SgNB determines that the encryption activation status of its corresponding bearer is enabled. If the user plane encryption protection policy is "preferred," the SgNB determines that the encryption activation status of its corresponding bearer can be either enabled or disabled. The SgNB can determine whether to enable encryption activation based on local policies (e.g., its own operational status, control policies, regulatory requirements, etc.). If the user plane encryption protection policy is "not needed," the SgNB determines that the encryption activation status of its corresponding bearer is disabled.
[0271] If the user plane integrity protection policy is "required," the SgNB determines that the integrity protection activation status of its corresponding bearer is enabled. If the user plane integrity protection policy is "preferred," the SgNB determines that the integrity protection activation status of its corresponding bearer can be either enabled or disabled. The SgNB can determine whether to enable integrity protection activation based on local policies (e.g., its own operational status, control policies, regulatory requirements, etc.). If the user plane integrity protection policy is "not needed," the SgNB determines that the integrity protection activation status of its corresponding bearer is disabled.
[0272] Optionally, if the SgNB receives a user plane integrity protection policy from the MeNB and the user plane integrity protection policy indicates required, the SgNB also needs to send a support enable instruction to the MeNB in step 4. The support enable instruction is used to indicate that the SgNB supports UPIP, or that the SgNB can enable user plane integrity protection in accordance with the user plane integrity protection policy, or that the SgNB determines to enable user plane integrity protection.
[0273] Step 4: The SgNB sends an SgNB Addition Request ACK message or an SgNB Addition Response message to the MeNB. This message indicates that preparation for adding the SgNB is complete.
[0274] This message carries an NR RRC reconfiguration message, which is transparent to the MeNB. The NR RRC reconfiguration message carries the bearer's identification information and security activation status.
[0275] The bearer identification information identifies the bearer used to transmit user plane data between the UE and the SgNB. The bearer identification information can be the identifier of the data radio bearer (DRB) (drb-identity) or the identifier of the EPS bearer (EPS-BearerIdentity).
[0276] Optionally, the message also carries a support enable indication. The MeNB further determines whether the current user plane integrity protection policy indicates required, but the MeNB has not received a support enable indication. In this case, the MeNB triggers the SgNB Release procedure to instruct the SgNB to release the resources allocated for the UE's dual connectivity. Optionally, the MeNB reselects an SgNB and re-executes step 1. If the current user plane integrity protection policy indicates required, but the MeNB has received a support enable indication, or if the current user plane integrity protection policy indicates preferred or not needed, the MeNB continues to execute step 5.
[0277] Step 5: The MeNB sends an RRC reconfiguration message to the UE, which carries a transparently transmitted NR RRC reconfiguration message. The NR RRC reconfiguration message carries the bearer identification information and security activation status.
[0278] Step 6: The UE configures the SgNB's configuration information according to the NR RRC reconfiguration message, and enables user plane security according to the security activation status indication. "Enabled" can also be understood as "activated". User plane security includes user plane encryption protection and / or user plane integrity protection.
[0279] Step 7: The UE replies with an RRC reconfiguration complete message, which carries an NR RRC Response message.
[0280] Step 8: The MeNB sends an RRC reconfiguration complete message to the SgNB, which carries an NR RRC Response message. The SgNB determines that the UE has completed the configuration based on the NR RRC Response message.
[0281] The above technical solution enhances the processing logic of the primary MeNB and secondary SgNB in the secondary site addition process under cross-system dual-connectivity scenarios. The primary MeNB can send a second UPIP indication to the secondary SgNB to instruct the UE to support UPIP, or further send a user plane security policy. The secondary SgNB determines the security activation status based on the second UPIP indication and the user plane security policy and sends it to the UE, thereby enabling user plane security between the UE and the secondary SgNB on demand. Simultaneously, the method by which the MeNB determines whether the SgNB supports UPIP based on the user plane integrity protection policy avoids the problem of the SgNB ignoring the user plane integrity protection policy because it does not support UPIP when the policy is not enabled, thus reducing security.
[0282] Figure 12 This is a flowchart illustrating a method for activating security, as provided in an embodiment of this application. Figure 12 As shown, the method includes:
[0283] Step 1: The MeNB selects the SgNB based on whether the UE supports UPIP and the user plane security policy.
[0284] If the UE supports UPIP and the user plane integrity protection policy in the user plane security policy is required, the MeNB selects an SgNB that supports UPIP (the MeNB may have its UPIP support capability pre-configured through the network management system) and carries the user plane security policy in step 3. If an SgNB that supports UPIP cannot be selected, the MeNB cannot add / offload the E-RAB corresponding to the user plane integrity protection policy to the SgNB.
[0285] If the UE supports UPIP and the user plane integrity protection policy in the user plane security policy is preferred / not needed, the MeNB will preferentially select an SgNB that supports UPIP and include the user plane security policy in step 2. If an SgNB that supports UPIP cannot be selected, the MeNB can also select an SgNB that does not support UPIP and add / offload the E-RAB corresponding to the user plane integrity protection policy to the SgNB.
[0286] If the UE does not support UPIP, the MeNB selects the SgNB according to the existing logic and does not carry the user plane security policy in step S302.
[0287] Step 2: The MeNB sends an SgNB Addition Request message to the SgNB, which may carry user plane security policies.
[0288] The aforementioned user plane security policy can be obtained in two ways. If the MeNB receives the user plane security policy from the core network, the MeNB can send the user plane security policy received from the core network. If the MeNB does not receive the user plane security policy from the core network, but the UE supports UPIP, the MeNB can send a pre-configured user plane security policy.
[0289] Step 3: After receiving the user plane security policy, SgNB can determine the security activation status based on the user plane security policy.
[0290] Otherwise, if the SgNB does not receive the user plane security policy, the SgNB does not need to determine the security activation status and will configure the DRB in the existing manner.
[0291] Step 4: The SgNB sends an SgNB Addition Request ACK message or an SgNB Addition Response message to the MeNB. This message carries an NR RRC reconfiguration message, which is transparent to the MeNB. The NR RRC reconfiguration message carries the bearer's identification information and security activation status.
[0292] Step 5: The MeNB sends an RRC reconfiguration message to the UE, which carries a transparently transmitted NR RRC reconfiguration message. The NR RRC reconfiguration message carries the bearer's identification information and security activation status.
[0293] Step 6: The UE configures the SgNB's configuration information according to the NR RRC reconfiguration message, and performs user plane security according to the security activation status indication. "Activated" can also be understood as "enabled".
[0294] Step 7: The UE replies with an RRC reconfiguration complete message, which carries an NR RRC Response message.
[0295] Step 8: The MeNB sends an RRC reconfiguration complete message to the SgNB, which carries an NR RRC Response message. The SgNB determines that the UE has completed the configuration based on the NR RRC Response message.
[0296] The above technical solution enhances the processing logic of the primary MeNB and secondary SgNB in the secondary site addition process under cross-system dual-connectivity scenarios. The primary MeNB determines whether the UE supports UPIP and sends the user plane security policy to the secondary SgNB. The secondary SgNB then determines the security activation status based on the user plane security policy and sends it to the UE, thereby enabling user plane security between the UE and the secondary SgNB on demand.
[0297] Figure 13This is a flowchart illustrating a method for activating security, as provided in an embodiment of this application. Figure 13 As shown, the method includes:
[0298] Step 0: If the MeNB has not been upgraded and therefore does not support UPIP, the MeNB cannot carry the UP policy and / or second UPIP indication in the SgNB AdditionRequest message.
[0299] If the MeNB decides to request the SgNB to allocate resources for a specific E-RAB, the MeNB can initiate the following SgNB Addition procedure.
[0300] Step 1: The MeNB sends an SgNB Addition Request message to the SgNB.
[0301] Step 2: Based on the SgNB Addition Request message, the SgNB allocates resources for the requested E-RAB and constructs an NR RRC reconfiguration message. If the SgNB supports UPIP, since no second UPIP indication and / or user plane security policy has been received, the SgNB carries a UPIP request indication in the NR RRC reconfiguration message. This UPIP request indication is used to request whether the UE supports UPIP.
[0302] Step 3: The SgNB sends an SgNB Addition Request ACK message to the MeNB, which carries an NR RRC reconfiguration message. This message is transparent to the MeNB. The NR RRC reconfiguration message carries a UPIP request indication.
[0303] Step 4: The MeNB sends an RRC reconfiguration message to the UE, which carries a transparently transmitted NR RRC reconfiguration message. The NR RRC reconfiguration message carries a UPIP request indication.
[0304] Step 5: Based on the UPIP request indication in the NR RRC reconfiguration message, if the UE supports UPIP, the UE sends a third UPIP indication to the SgNB. This third UPIP indication can be one bit, used to indicate whether the UE supports UPIP. Specifically, the UE sends an RRC reconfiguration message to the MeNB, which carries an NR RRC Response message. The NR RRC Response message contains the third UPIP indication.
[0305] Step 6: The MeNB sends an SgNB Reconfiguration Complete message to the SgNB, which carries an NRRRC Response message. The NRRRC Response message contains a third UPIP indication.
[0306] Step 7: SgNB determines the security activation status based on the third UPIP instruction and the pre-configured user plane security policy.
[0307] The pre-configured user plane security policy can also be referred to as the default user plane security policy.
[0308] Step 8: Because the SgNB needs to update the security activation status with the UE, it triggers the SgNB initiated SgNBmodification process, that is, the SgNB sends an SgNB Modification Required message to the MeNB.
[0309] Step 9: MeNB sends an SgNB Modification Request message to SgNB.
[0310] Step 10: The SgNB sends an SgNB Modification Request ACK message to the MeNB, which carries an NRRRC reconfiguration message. The NRRRC reconfiguration message carries the bearer's identification information and security activation status.
[0311] Step 11: The MeNB sends an RRC reconfiguration message to the UE, which carries a transparently transmitted NR RRC reconfiguration message. The NR RRC reconfiguration message carries the bearer's identification information and security activation status.
[0312] Step 12: The UE configures the SgNB's configuration information according to the NR RRC reconfiguration message, and enables user plane security with the SgNB based on the security activation status. "Enabled" can also be understood as "activated".
[0313] Step 13: The UE replies with an RRC reconfiguration complete message, which carries an NR RRC Response message.
[0314] Step 14: The MeNB sends an RRC reconfiguration complete message to the SgNB, which carries an NR RRC Response message. The SgNB determines that the UE has completed the configuration based on the NR RRC Response message.
[0315] The above technical solution enhances the processing logic of the UE and the secondary site SgNB in the secondary site addition process under cross-system dual-connectivity scenarios. After receiving the secondary site addition request, the secondary site SgNB interacts with the UE to obtain the UE's UPIP capability. Then, if the UE supports UPIP, it determines the security activation status according to the user plane security policy and sends it to the UE, thereby enabling user plane security between the UP and the secondary site SgNB on demand.
[0316] Figure 14 This is a flowchart illustrating a method for activating security, as provided in an embodiment of this application. Figure 14 As shown, the method includes:
[0317] Step 0: The MeNB has not been upgraded and therefore does not support UPIP. In this case, the MeNB cannot carry the UP policy and / or second UPIP indication in the SgNB Addition Request message.
[0318] If the MeNB decides to request the SgNB to allocate resources for a specific E-RAB, the MeNB can initiate the following SgNB Addition procedure.
[0319] Step 1: The MeNB sends an SgNB Addition Request message to the SgNB, which carries the UE's NR security capabilities.
[0320] Step 2: Based on the SgNB Addition Request message, the SgNB allocates resources for the requested E-RAB and constructs an NR RRC reconfiguration message. If the SgNB upgrade supports UPIP, since no second UPIP instruction and / or user plane security policy has been received, the SgNB can determine the security activation status based on the pre-configured user plane security policy.
[0321] The SgNB carries the security activation status in the NR RRC reconfiguration message. Optionally, the SgNB also carries an activation confirmation indicator in the NR RRC reconfiguration message, which instructs the UE to reply with the activation confirmation indicator after activating UP security according to the security activation status. The activation confirmation indicator can be an additional bit value or an implicit indication of the security activation status.
[0322] Note that SgNB does not activate user plane security with the UE at this time.
[0323] Step 3: The SgNB sends an SgNB Addition Request ACK message to the MeNB, which carries the aforementioned NRRRC reconfiguration message. This message is transparent to the MeNB. The NRRRC reconfiguration message carries the bearer's identification information and security activation status, and optionally, also includes an activation confirmation indication.
[0324] Step 4: The MeNB sends an RRC reconfiguration message to the UE, which carries a transparently transmitted NR RRC reconfiguration message. The NR RRC reconfiguration message carries the bearer's identification information and security activation status, and optionally, also includes an activation confirmation indication.
[0325] Step 5: Based on the security activation status in the NR RRC reconfiguration message, if the UE supports UPIP and receives the security activation status from the SgNB, the UE activates user plane security with the SgNB according to the security activation status. The UE sends an enable indication to the SgNB based on the activation confirmation indication or the security activation status. The enable indication can be a single bit, used to indicate whether the UE has enabled security according to the security activation status. Specifically, the UE sends an RRC reconfiguration message to the MeNB, carrying an NR RRCResponse message. The NR RRC Response message contains the enable indication.
[0326] Step 6: The MeNB sends an SgNB ReconfigurationComplete message to the SgNB, which carries an NRRRC Response message. The NRRRC Response message contains an enable indication.
[0327] Upon receiving an activation instruction, the SgNB can activate user plane security with the UE according to the security activation state determined in step 2. If no activation instruction is received, the SgNB can activate user plane security with the UE in the default manner, i.e., enable user plane encryption protection but not user plane integrity protection.
[0328] The above technical solution enhances the processing logic of the UE and the secondary site SgNB in the secondary site addition process under cross-system dual-connectivity scenarios. After receiving a secondary site addition request, if the secondary site SgNB does not receive a second UPIP instruction or user plane security policy, it can determine the security activation state according to the pre-configured user plane security policy and send it to the UE. If the UE supports UPIP, it can enable user plane security with the SgNB based on the received security activation state and provide an activation instruction. If the UE supports UPIP, it can perform no processing, such as discarding or ignoring the received security activation state. Thus, the SgNB can enable user plane security with the UE after receiving the UE's activation instruction, thereby achieving on-demand activation of user plane security between the UE and the secondary site SgNB. Furthermore, this technical solution can effectively reduce signaling overhead.
[0329] This application also provides a communication device, please refer to... Figure 15This is a schematic diagram of a communication device provided in an embodiment of this application. The communication device 1500 includes a transceiver module 1510 and a processing module 1520. This communication device can be used to implement the functions of access network devices (e.g., a first access network device or a second access network device) involved in any of the above method embodiments. For example, the communication device may be an access network device or a chip or circuit included in the access network device.
[0330] The communication device can also be used to implement the functions of the terminal device involved in any of the above method embodiments. For example, the communication device can be a terminal device, such as a handheld terminal device or a vehicle-mounted terminal device; the communication device can also be a chip or circuit included in the terminal device, or a device including the terminal device, such as various types of vehicles, etc.
[0331] For example, when the communication device performs Figure 3 In the method embodiment shown, when operating or taking steps corresponding to the first access network device, the processing module 1520 is used to request the second access network device of the second communication standard to allocate resources for the dual connection of the terminal device through the transceiver module 1510 and send first indication information to the second access network device. The first indication information is used to indicate that the terminal device supports user plane security protection, and the communication device is the primary access network device in the dual connection of the terminal device. The transceiver module 1510 is used to receive the bearer identification information and security activation status from the second access network device; and to send the bearer identification information and security activation status to the terminal device. The security activation status is used to indicate whether to enable user plane encryption protection and / or user plane integrity protection of the bearer.
[0332] In one possible design, the bearer is used to transmit user plane data between the terminal device and the second access network device.
[0333] In one possible design, the processing module 1520 is also used to generate first instruction information based on the context of the terminal device.
[0334] In one possible design, the context of the terminal device includes a first security capability of the terminal device, which indicates that the terminal device supports user plane security protection, and the first security capability corresponds to a first communication standard.
[0335] In one possible design, the context of the terminal device includes a first wireless capability of the terminal device, which indicates that the terminal device supports user plane security protection, and the first wireless capability corresponds to a first communication standard.
[0336] In one possible design, if the user plane security policy requires it to be enabled, the first indication information is a critical information for rejection; if the user plane security policy does not require it to be enabled, the first indication information is a critical information for ignoring.
[0337] In one possible design, the processing module 1520 is further configured to select a second access network device, which supports user plane security protection, based on the context of the terminal device.
[0338] In one possible design, the context of the terminal device includes a user plane security policy; the processing module 1520 is specifically used to determine that the terminal device supports user plane security protection, and then select a second access network device according to the user plane security policy.
[0339] In one possible design, the transceiver module 1510 is also used to send user plane security policies from the core network device or pre-configured by the first access network device to the second access network device.
[0340] In one possible design, the transceiver module 1510 is further configured to receive an enable instruction from the terminal device, the enable instruction indicating that the terminal device has enabled user plane security with the second access network device; and to send the enable instruction to the second access network device.
[0341] In one possible design, the transceiver module 1510 is further configured to receive a support enable instruction from the second access network device, the support enable instruction being used to instruct the second access network device to support user plane security protection.
[0342] In one possible design, the transceiver module 1510 is specifically configured to: send a secondary site addition request to the second access network device, the secondary site addition request including first indication information, the secondary site addition request being used to request resource allocation for dual connectivity of the terminal device; and receive a secondary site addition response from the second access network device, the secondary site addition response including bearer identification information and security activation status.
[0343] In one possible design, the auxiliary site addition request also includes a user plane security policy.
[0344] In one possible design, the transceiver module 1510 is specifically used to send a reconfiguration message to the terminal device, the reconfiguration message including carried identification information and security activation status.
[0345] When the communication device performs Figure 3In the method embodiment shown, when operating or taking steps corresponding to the second access network device, the transceiver module 1510 is used to accept a request from the first access network device of the first communication standard to allocate resources for dual connectivity of the terminal device and to receive first indication information from the first access network device, which is used to indicate that the terminal device supports user plane security protection; the processing module 1520 is used to determine the security activation state according to the first indication information and the user plane security policy; the transceiver module 1510 is also used to send the bearer identification information and the security activation state to the terminal device through the first access network device, which is used to indicate whether to enable user plane encryption protection and / or user plane integrity protection of the bearer.
[0346] In one possible design, the bearer is used to transmit user plane data between the terminal device and the second access network device.
[0347] In one possible design, the transceiver module 1510 is also used to receive user plane security policies from the first access network device; or, the user plane security policies are pre-configured by the second access network device.
[0348] In one possible design, if the user plane security policy is mandatory, the first indication information is a critical information for rejection; if the user plane security policy is not mandatory, the first indication information is a critical information for ignoring.
[0349] In one possible design, the transceiver module 1510 is further configured to send a support enable instruction to the first access network device, the support enable instruction being used to instruct the second access network device to support user plane security protection.
[0350] In one possible design, the transceiver module 1510 is further configured to receive an enable instruction from the terminal device via the first access network device, the enable instruction being used to indicate that the terminal device has enabled user plane security with the second access network device.
[0351] In one possible design, the processing module 1520 is also configured to enable user plane security with the terminal device according to the security activation state.
[0352] In one possible design, the transceiver module 1510 is specifically configured to: receive a secondary station addition request from a first access network device, the secondary station addition request including first indication information, the secondary station addition request being used to request resource allocation for dual connectivity of the terminal device; and send a secondary station addition response to the first access network device, the secondary station addition response including bearer identification information and security activation status.
[0353] In one possible design, the auxiliary site addition request includes a user plane security policy.
[0354] When the communication device performs Figure 5 In the method embodiment shown, when corresponding to the operation or steps of the first access network device, the processing module 1520 is used to: select a second access network device that supports the second communication standard for user plane security protection according to the context of the terminal device, wherein the first access network device is the primary access network device in the dual connection of the terminal device; and request the second access network device to allocate resources for the dual connection of the terminal device through the transceiver module 1510 and send a user plane security policy to the second access network device; the transceiver module 1510 is used to: receive the identification information and security activation status of the bearer from the second access network device; and send the identification information and security activation status of the bearer to the terminal device, wherein the security activation status is used to indicate whether to enable user plane encryption protection and / or user plane integrity protection of the bearer.
[0355] In one possible design, the bearer is used to transmit user plane data between the terminal device and the second access network device.
[0356] In one possible design, the context of the terminal device includes a first security capability of the terminal device, which indicates that the terminal device supports user plane security protection, and the first security capability corresponds to a first communication standard.
[0357] In one possible design, the context of the terminal device includes a first wireless capability of the terminal device, which indicates that the terminal device supports user plane security protection, and the first wireless capability corresponds to a first communication standard.
[0358] In one possible design, the user plane security policy is received by the first access network device from the core network device or pre-configured by the first access network device.
[0359] In one possible design, the transceiver module 1510 is further configured to: receive an enable instruction from the terminal device, the enable instruction indicating that the terminal device has enabled user plane security with the second access network device; and send the enable instruction to the second access network device.
[0360] When the communication device performs Figure 5In the method embodiment shown, when operating or taking steps corresponding to the second access network device, the transceiver module 1510 is used to accept a request from the first access network device of the first communication standard to allocate resources for dual connectivity of the terminal device and to receive the user plane security policy from the first access network device; the processing module 1520 is used to determine the security activation state according to the user plane security policy; the transceiver module 1510 is also used to send the bearer identification information and security activation state to the terminal device through the first access network device, wherein the security activation state is used to indicate whether to enable user plane encryption protection and / or user plane integrity protection of the bearer.
[0361] In one possible design, the bearer is used to transmit user plane data between the terminal device and the second access network device.
[0362] In one possible design, the transceiver module 1510 is further configured to receive an enable instruction from the terminal device via the first access network device, the enable instruction being used to indicate that the terminal device has enabled user plane security with the second access network device.
[0363] In one possible design, the processing module 1520 is also configured to enable user plane security with the terminal device according to the security activation state.
[0364] When the communication device performs Figure 7 In the method embodiment shown, when operating or taking steps corresponding to the second access network device, the transceiver module 1510 is used to send a first request message to the terminal device through the first access network device of the first communication standard. The first request message is used to request the terminal device to support user plane security. The communication device is the secondary access network device in the dual connection of the terminal device, and the first access network device is the primary access network device in the dual connection of the terminal device. The transceiver module 1510 is also used to receive a second indication message from the terminal device through the first access network device. The second indication message is used to instruct the terminal device to support user plane security protection. The processing module 1520 is used to determine the security activation state according to the second indication message and the user plane security policy. The transceiver module 1510 is also used to send the bearer identification information and the security activation state to the terminal device through the first access network device. The security activation state is used to indicate whether to enable user plane encryption protection and / or user plane integrity protection of the bearer.
[0365] In one possible design, the bearer is used to transmit user plane data between the terminal device and the second access network device.
[0366] In one possible design, the user plane security policy is pre-configured by the second access network device.
[0367] In one possible design, the transceiver module 1510 is further configured to receive an enable instruction from the terminal device via the first access network device, the enable instruction being used to indicate that the terminal device has enabled user plane security with the second access network device.
[0368] In one possible design, the processing module 1520 is also configured to enable user plane security with the terminal device according to the security activation state.
[0369] In one possible design, the transceiver module 1510 is further configured to: receive a secondary station addition request from a first access network device, the secondary station addition request being used to request the allocation of resources for dual connectivity of the terminal device; and send a secondary station modification response to the first access network device, the secondary station modification response including the identification information of the bearer and the security activation status.
[0370] When the communication device performs Figure 7 In the method embodiment shown, when the terminal device operates or takes a certain step, the transceiver module 1510 is used to: receive a first request information from a second access network device of a second communication standard through a first access network device of a first communication standard, the first request information being used to request the terminal device to support user plane security; and send a second indication information to the second access network device through the first access network device, the second indication information being used to instruct the terminal device to support user plane security protection.
[0371] In one possible design, the transceiver module 1510 is further configured to receive, via the first access network device, identification information and security activation status of a bearer from the second access network device, the security activation status indicating whether user plane encryption protection and / or user plane integrity protection of the bearer are enabled; the processing module 1520 is configured to enable user plane security with the second access network device according to the security activation status.
[0372] In one possible design, the bearer is used to transmit user plane data between the terminal device and the second access network device.
[0373] In one possible design, the transceiver module 1510 is further configured to send an enable indication message to the second access network device via the first access network device, the enable indication message being used to indicate that the terminal device has enabled user plane security with the second access network device.
[0374] When the communication device performs Figure 9In the method embodiment shown, when operating or taking steps corresponding to the second access network device, the processing module 1520 is used to determine the security activation state according to the user plane security policy. The communication device is the secondary access network device in the dual connection of the terminal device. The transceiver module 1510 is used to send the bearer identification information and security activation state to the terminal device through the first access network device of the first communication standard. The security activation state is used to indicate whether to enable user plane encryption protection and / or user plane integrity protection of the bearer. The first access network device is the primary access network device in the dual connection of the terminal device. The transceiver module 1510 is also used to receive the activation indication information from the terminal device through the first access network device. The activation indication information is used to indicate that the terminal device has enabled user plane security with the second access network device. The processing module 1520 is also used to enable user plane security with the terminal device according to the activation indication information and the security activation state.
[0375] In one possible design, the bearer is used to transmit user plane data between the terminal device and the second access network device.
[0376] In the first possible design, the user plane security policy is pre-configured by the second access network device.
[0377] In one possible design, the transceiver module 1510 is further configured to send an acknowledgment instruction to the terminal device via the first access network device. The acknowledgment instruction is used to instruct the terminal device to send an enable instruction after enabling user plane security with the second access network device.
[0378] In one possible design, the transceiver module 1510 is further configured to: receive a secondary station addition request from a first access network device, the secondary station addition request being used to request the allocation of resources for dual connectivity of the terminal device; and send a secondary station addition response to the first access network device, the secondary station addition response including bearer identification information and security activation status.
[0379] In one possible design, the auxiliary station add response includes confirmation indication information.
[0380] When the communication device performs Figure 9In the method embodiment shown, when the terminal device operates or takes a certain step, the transceiver module 1510 is used to receive the bearer identification information and security activation status from the second access network device of the second communication standard through the first access network device of the first communication standard. The security activation status is used to indicate whether to enable user plane encryption protection and / or user plane integrity protection of the bearer. The processing module 1520 is used to enable user plane security with the second access network device according to the security activation status. The transceiver module 1510 is also used to send an activation indication information to the second access network device through the first access network device. The activation indication information is used to indicate that the terminal device has enabled user plane security with the second access network device.
[0381] In one possible design, the bearer is used to transmit user plane data between the terminal device and the second access network device.
[0382] In one possible design, the transceiver module 1510 is further configured to receive acknowledgment information from the second access network device via the first access network device. This acknowledgment information is used to instruct the terminal device to send an enable instruction after enabling user plane security with the second access network device.
[0383] The processing module 1520 in this communication device can be implemented by at least one processor or processor-related circuit components, and the transceiver module 1510 can be implemented by at least one transceiver or transceiver-related circuit components or a communication interface. The operation and / or function of each module in this communication device are respectively for the purpose of implementing… Figures 3 to 14 The corresponding flow of the method shown is omitted here for brevity. Optionally, the communication device may also include a storage module for storing data and / or instructions. The transceiver module 1510 and / or processing module 1520 can read the data and / or instructions from the storage module, thereby enabling the communication device to implement the corresponding method. This storage module can be implemented, for example, through at least one memory.
[0384] The aforementioned storage module, processing module, and transceiver module can exist separately, or all or some of the modules can be integrated, such as integrating the storage module and the processing module, or integrating the processing module and the transceiver module, etc.
[0385] Please refer to Figure 16 This is another structural schematic diagram of a communication device provided in an embodiment of this application. The communication device may specifically be an access network device, such as a base station, used to implement the functions of the first or second access network device involved in any of the above method embodiments.
[0386] The access network device 1600 includes one or more DU 1601 and one or more CU 1602. Each DU 1601 may include at least one antenna 16011, at least one radio frequency unit 16012, at least one processor 16013, and at least one memory 16014. The DU 1601 is mainly used for transmitting and receiving radio frequency signals, converting radio frequency signals to baseband signals, and performing some baseband processing.
[0387] The CU 1602 may include at least one processor 16022 and at least one memory 16021. The CU 1602 is mainly used for baseband processing and base station control. The CU 1602 is the control center of the base station and can also be called a processing unit. For example, the CU 1602 can be used to control the base station to perform the aforementioned tasks. Figures 3 to 14 The operation or steps corresponding to the first access network device or the second access network device in the method shown.
[0388] CU 1602 and DU 1601 can communicate via an interface. The control plane (CP) interface can be Fs-C, such as F1-C, and the user plane (UP) interface can be Fs-U, such as F1-U. DU 1601 and CU 1602 can be physically set together or physically separated (i.e., distributed base stations), and there is no limitation on this.
[0389] Specifically, the baseband processing on the CU and DU can be divided according to the protocol layer of the wireless network. For example, the functions of the PDCP layer and above are set in the CU, while the functions of the protocol layers below the PDCP layer (such as the RLC layer and MAC layer) are set in the DU. For another example, the CU implements the functions of the RRC and PDCP layers, while the DU implements the functions of the RLC, MAC, and physical (PHY) layers.
[0390] Optionally, the network device 1600 may include one or more radio frequency units (RU), one or more DUs, and one or more CUs. The DU may include at least one processor 16013 and at least one memory 16014, the RU may include at least one antenna 16011 and at least one radio frequency unit 16012, and the CU may include at least one processor 16022 and at least one memory 16021.
[0391] In one embodiment, the CU 1602 can be composed of one or more single boards. These boards can collectively support a single access-indicating wireless access network (such as a 5G network), or they can each support wireless access networks with different access standards (such as LTE, 5G, or other networks). The memory 16021 and processor 16022 can serve one or more single boards. That is, each single board can have its own memory and processor, or multiple single boards can share the same memory and processor. Furthermore, each single board can also have necessary circuitry.
[0392] The DU 1601 can be composed of one or more single boards. Multiple single boards can collectively support a single access-indicating wireless access network (such as a 5G network), or they can each support wireless access networks with different access standards (such as LTE, 5G, or other networks). The memory 16014 and processor 16013 can serve one or more single boards. That is, each single board can have its own memory and processor, or multiple single boards can share the same memory and processor. Furthermore, each single board can also have necessary circuitry.
[0393] Please refer to Figure 17 This is another structural schematic diagram of a communication device provided in an embodiment of this application. Specifically, this communication device can be a terminal device, which can be used to implement the functions of the terminal device involved in any of the above method embodiments. For ease of understanding and illustration, [the following is a simplified diagram]. Figure 17 In this context, the terminal device is taken as a mobile phone. For example... Figure 17 As shown, the terminal device includes a processor, and may also include memory, radio frequency circuits, antennas, and input / output devices. The processor is mainly used to process communication protocols and data, control the terminal device, execute software programs, and process software program data. The memory is mainly used to store software programs and data. The radio frequency circuit is mainly used for converting baseband signals to radio frequency signals and processing radio frequency signals. The antenna is mainly used for transmitting and receiving radio frequency signals in the form of electromagnetic waves. Input / output devices, such as touchscreens, displays, and keyboards, are mainly used to receive user input data and output data to the user. It should be noted that some types of terminal devices may not have input / output devices.
[0394] When data needs to be sent, the processor performs baseband processing on the data to be sent and outputs the baseband signal to the radio frequency (RF) circuit. The RF circuit then processes the baseband signal and transmits it outward as electromagnetic waves through the antenna. When data is sent to the terminal device, the RF circuit receives the RF signal through the antenna, converts it into a baseband signal, and outputs the baseband signal to the processor. The processor then converts the baseband signal back into data and processes it. For ease of explanation,Figure 17 Only one memory and processor are shown in the illustration. In actual end products, there may be one or more processors and one or more memories. Memory may also be called storage medium or storage device, etc. Memory may be set up independently of the processor or integrated with the processor; this application does not limit this.
[0395] In this embodiment, the antenna and radio frequency circuit with transceiver functions can be considered as the transceiver unit of the terminal device, and the processor with processing functions can be considered as the processing unit of the terminal device. Figure 17 As shown, the terminal device includes a transceiver unit 1710 and a processing unit 1720. The transceiver unit can also be called a transceiver, transceiver machine, transceiver device, etc. The processing unit can also be called a processor, processing board, processing module, processing device, etc. Optionally, the device in the transceiver unit 1710 used to implement the receiving function can be considered as a receiving unit, and the device in the transceiver unit 1710 used to implement the transmitting function can be considered as a transmitting unit; that is, the transceiver unit 1710 includes a receiving unit and a transmitting unit. The transceiver unit can sometimes also be called a transceiver, transceiver, or transceiver circuit, etc. The receiving unit can sometimes be called a receiver, receiver, or receiving circuit, etc. The transmitting unit can sometimes be called a transmitter, transmitter, or transmitting circuit, etc. It should be understood that the transceiver unit 1710 is used to perform the transmitting and receiving operations on the terminal side in the above method embodiments, and the processing unit 1720 is used to perform other operations on the terminal in the above method embodiments besides the transmitting and receiving operations.
[0396] This application also provides a chip system, including: a processor coupled to a memory, the memory being used to store programs or instructions, and when the program or instructions are executed by the processor, the chip system enables the chip system to implement the method of the corresponding terminal device or the method of the corresponding network device in any of the above method embodiments.
[0397] Optionally, the chip system may contain one or more processors. These processors can be implemented in hardware or software. When implemented in hardware, the processor can be a logic circuit, an integrated circuit, etc. When implemented in software, the processor can be a general-purpose processor, implemented by reading software code stored in memory.
[0398] Optionally, the chip system may contain one or more memories. The memory may be integrated with the processor or disposed separately from it; this application does not limit this. For example, the memory may be a non-transient processor, such as a read-only memory (ROM), which may be integrated with the processor on the same chip or disposed separately on different chips. This application does not specifically limit the type of memory or the arrangement of the memory and processor.
[0399] For example, the chip system may be a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on chip (SoC), a central processor unit (CPU), a network processor (NP), a digital signal processor (DSP), a micro controller unit (MCU), a programmable logic device (PLD), or other integrated chips.
[0400] It should be understood that each step in the above method embodiments can be completed by integrated logic circuits in the processor hardware or by instructions in software form. The method steps disclosed in the embodiments of this application can be directly manifested as being executed by a hardware processor, or being executed by a combination of hardware and software modules in the processor.
[0401] This application also provides a computer-readable storage medium storing computer-readable instructions, which, when read and executed by a computer, cause the computer to perform the method in any of the above method embodiments.
[0402] This application also provides a computer program product that, when read and executed by a computer, causes the computer to perform the method in any of the above method embodiments.
[0403] This application also provides a communication system, which includes a first access network device, a second access network device, and a terminal device. Optionally, the communication system may further include core network equipment.
[0404] It should be understood that the processor mentioned in the embodiments of this application can be a CPU, or other general-purpose processors, DSPs, ASICs, FPGAs, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor can be a microprocessor or any conventional processor.
[0405] It should also be understood that the memory mentioned in the embodiments of this application can be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. Non-volatile memory can be read-only memory (ROM), programmable read-only memory, erasable programmable read-only memory, electrically erasable programmable read-only memory, or flash memory. Volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as static random access memory, dynamic random access memory, synchronous dynamic random access memory, double data rate synchronous dynamic random access memory, enhanced synchronous dynamic random access memory, synchronous linked dynamic random access memory, and direct memory bus random access memory.
[0406] It should be noted that when the processor is a general-purpose processor, DSP, ASIC, FPGA, or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component, the memory (storage module) is integrated into the processor.
[0407] It should be noted that the memories described herein are intended to include, but are not limited to, these and any other suitable types of memories.
[0408] It should be understood that the various numerical designations involved in the various embodiments of this application are merely for the convenience of description, and the order of the numbers of the above processes or steps does not imply the order of execution. The execution order of each process or step should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this invention.
[0409] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0410] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0411] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0412] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0413] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0414] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, ROM, RAM, magnetic disks, or optical disks.
[0415] In the various embodiments of this application, unless otherwise specified or in case of logical conflict, the terminology and / or descriptions of different embodiments are consistent and can be referenced by each other. The technical features of different embodiments can be combined to form new embodiments according to their inherent logical relationship.
Claims
1. A method for activating security, characterized in that, The method includes: The first access network device using the first communication standard determines whether the terminal device supports user plane security protection based on the first security capability of the terminal device corresponding to the first communication standard. The first access network device sends a secondary station addition request message to the second access network device using the second communication standard. The secondary station addition request message is used to request the allocation of resources for the dual connection of the terminal device. The first access network device is the primary access network device in the dual connection, and the second access network device is the secondary access network device in the dual connection. When the terminal device supports user plane security protection, the secondary station addition request message includes first indication information. The first access network device receives the bearer's identification information and security activation status from the second access network device. The security activation status is determined based on the first indication information and is used to indicate whether to enable user plane encryption protection and / or user plane integrity protection for the bearer. The first access network device sends the identification information and the security activation status carried by the device to the terminal device.
2. The method according to claim 1, characterized in that, The first security capability is included in the context of the terminal device.
3. The method according to claim 2, characterized in that, The first communication standard is a 4G network, the first security capability is the Evolved Packet System (EPS) security capability of the terminal device, the EPS integrity algorithm (EIA7) in the EPS security capability indicates that the terminal device supports user plane integrity protection, and the terminal device's support for user plane security protection includes the terminal device's support for user plane integrity protection. The first access network device determines whether the terminal device supports user plane security protection based on the first security capability of the terminal device corresponding to the first communication standard, including: The first access network device determines that the terminal device supports user plane integrity protection based on EIA7 in the EPS security capabilities.
4. The method according to any one of claims 1-3, characterized in that, The first indication information is used to indicate that the terminal device supports user plane security protection.
5. The method according to any one of claims 1-3, characterized in that, The method further includes: The first access network device sends the second security capability corresponding to the second communication standard to the second access network device.
6. The method according to claim 5, characterized in that, The second communication standard is a 5G network, and the second security capability is the new wireless NR security capability of the terminal device.
7. The method according to any one of claims 1-3, characterized in that, The method further includes: The second access network device receives the first indication information from the first access network device; The second access network device sends the bearer's identification information and the security activation status to the first access network device.
8. The method according to claim 7, characterized in that, The method further includes: The second access network device determines the security activation status based on the first indication information.
9. A communication device, characterized in that, Includes a module for performing the method as described in any one of claims 1 to 6.
10. A communication device, characterized in that, It includes a processor and a memory, the processor and the memory being coupled, the processor being used to control the device to implement the method as described in any one of claims 1 to 6.
11. A communication device, characterized in that, The device includes a processor and an interface circuit, wherein the interface circuit is used to receive signals from other communication devices besides the communication device and transmit them to the processor, or to send signals from the processor to other communication devices besides the communication device, and the processor is used to implement the method as described in any one of claims 1 to 6 through logic circuits or execution code instructions.
12. A computer-readable storage medium, characterized in that, The storage medium stores a computer program or instructions, which, when executed by a communication device, implement the method as described in any one of claims 1 to 6.
13. A computer program product, characterized in that, The computer program product includes instructions that, when executed by a computer, implement the method as described in any one of claims 1 to 6.
14. A communication system, characterized in that, Including the first access network equipment and the second access network equipment; Wherein, the first access network device is used to perform the method as described in any one of claims 1 to 6, and the second access network device is used to: receive first indication information from the first access network device; and send the carried identification information and security activation status to the first access network device.
15. The communication system according to claim 14, characterized in that, The second access network device is further configured to: determine the security activation state based on the first indication information.
Citation Information
Patent Citations
Security protection method and device and access network equipment
CN110167018A