Method and apparatus for processing communication data, terminal device, network device and medium

By determining the communication technology between terminal devices and using the corresponding key pairs for secure processing, the security risks caused by the decryption and re-encryption of PRAS and eRG devices are resolved, and secure communication between terminal devices is achieved.

CN115706978BActive Publication Date: 2026-02-13SPREADTRUM SEMICON (NANJING) CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202110895745.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-08-05
Publication Date
2026-02-13
Estimated Expiration
2041-08-05

AI Technical Summary

Technical Problem

In existing technologies, PRAS and eRG devices decrypt and reencrypt data without any security processing during communication, which poses a security risk and may lead to the leakage of communication data.

Method used

By determining whether the first terminal device and the second terminal device use the same communication technology, if they do, end-to-end security processing is performed using the key pair between the two parties; otherwise, security processing is performed using the key pair of the network device, and an indication message is generated to instruct the network device not to perform security processing.

Benefits of technology

When communication technologies are the same, ensure the security of communication data at the access layer to prevent intermediate network devices from obtaining data that has not been securely processed, and thus ensure communication security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115706978B_ABST
    Figure CN115706978B_ABST
Patent Text Reader

Abstract

The application discloses a communication data processing method and device, a terminal device, a network device and a medium. The communication data processing method comprises the following steps: a first terminal device acquires a communication technology used by a second terminal device; if the communication technology used by the first terminal device is the same as the communication technology used by the second terminal device, the first terminal device uses a key between the first terminal device and the second terminal device to perform security processing on target communication data between the first terminal device and the second terminal device, so that an intermediate network device between the first terminal device and the second terminal device cannot acquire any security-processed communication data, the security of the communication data is ensured, and the security communication between the first terminal device and the second terminal device is realized at an access layer.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of communication technology, in particular to a communication data processing method and device, terminal equipment, network equipment and medium. BACKGROUND

[0002] Mobile communication operators have been trying to achieve coverage of indoor mobile communication network by deploying equipment indoors to provide indoor Internet service for users, and shift from using Wi-Fi and fixed broadband to using mobile communication network, so as to seize the indoor traffic market.

[0003] Currently, there is a Residential 5G topic in the 3GPP (3rd Generation Partnership Project, third generation partnership project) standard, in which the equipment deployed indoors may include PRAS (Premises Radio Access Station, Premises Radio Access Station) and eRG (Evolved Residential Gateway, evolved residential / gateway), and PRAS and eRG may be purchased by users themselves or deployed by mobile operators. The network structure diagram is as shown in Figure 1

[0004] PRAS is actually a device similar to the base station of the current mobile communication network, mainly providing network access based on Uu interface; eRG provides broadband access (to 5G core network or Internet) in the north direction, and in the south direction, in addition to providing interface with PRAS, it can also directly provide Wi-Fi network access to traditional Wi-Fi devices. Whether it is a Uu interface communication protocol or a Wi-Fi communication protocol, since protocol conversion is involved, in the process of communication between two terminal devices, the data passing through PRAS or eRG will be decrypted and re-encrypted, so that PRAS or eRG can obtain communication data without any security processing, which poses a security risk. SUMMARY

[0005] The technical problem to be solved by the present application is to overcome the above-mentioned defects in the prior art, and to provide a communication data processing method and device, terminal equipment, network equipment and medium.

[0006] The present application solves the above technical problems by the following technical solutions:

[0007] The first aspect of the present application provides a communication data processing method applied to a first terminal device, comprising the following steps:

[0008] Obtaining the communication technology used by a second terminal device; ​

[0009] If the communication technology used by the first terminal device is the same as the communication technology used by the second terminal device, the target communication data between the first terminal device and the second terminal device is securely processed using a key pair between the first terminal device and the second terminal device.

[0010] Optionally, the method further comprises the following steps:

[0011] If the communication technology used by the first terminal device is the same as the communication technology used by the second terminal device, first indication information is generated;

[0012] The first indication information is used to indicate that the first network device does not securely process the target communication data, and the first network device is a network device required for communication between the first terminal device and the second terminal device.

[0013] The second aspect of the application provides a method for processing communication data, applied to a first terminal device, comprising the following steps:

[0014] The communication technology used by a second terminal device is obtained;

[0015] If the communication technology used by the first terminal device is the same as the communication technology used by the second terminal device, first indication information is generated;

[0016] The first indication information is used to indicate that the first network device does not securely process the target communication data between the first terminal device and the second terminal device, and the first network device is a network device required for communication between the first terminal device and the second terminal device.

[0017] Optionally, the step of obtaining the communication technology used by the second terminal device specifically comprises:

[0018] Second indication information sent by the second terminal device is received, and the second indication information is used to indicate the communication technology used by the second terminal device.

[0019] Optionally, the step of obtaining the communication technology used by the second terminal device specifically comprises:

[0020] Third indication information sent by the first network device is received, and the third indication information is used to indicate the communication technology used by the second terminal device.

[0021] Optionally, the target communication data comprises all data packets of a target bearer between the first terminal device and the second terminal device.

[0022] The first indication information comprises identification information of the target bearer.

[0023] Optionally, the target communication data comprises target data packets of a target bearer between the first terminal device and the second terminal device, and the target data packets comprise the first indication information.

[0024] Optionally, the first indication information is specifically used for indicating that the communication technology used by the first terminal device and the second terminal device is the same.

[0025] The step of performing security processing on the target communication data between the first terminal device and the second terminal device using the key between the first terminal device and the second terminal device specifically comprises:

[0026] The fourth indication information generated by the first network device is acquired, wherein the fourth indication information is used for indicating the target communication data.

[0027] The target communication data is processed using the key between the first terminal device and the second terminal device.

[0028] Optionally, the step of acquiring the fourth indication information generated by the first network device specifically comprises:

[0029] The identification information of a target bearer between the first terminal device and the second terminal device is acquired, wherein the identification information of the target bearer comprises fourth indication information, and the target communication data comprises all data packets of the target bearer.

[0030] Optionally, the method for processing communication data further comprises the following steps:

[0031] If the communication technology used by the first terminal device is different from the communication technology used by the second terminal device, a key between the first terminal device and a first network device is used to perform security processing on the target communication data between the first terminal device and the second terminal device, wherein the first network device is a network device required for communication between the first terminal device and the second terminal device.

[0032] A third aspect of the present application provides a processing device for communication data, which is applied to a first terminal device, and the processing device comprises a first acquisition module and a first processing module:

[0033] The first acquisition module is used for acquiring the communication technology used by a second terminal device.

[0034] The first processing module is used for performing security processing on the target communication data between the first terminal device and the second terminal device using a key between the first terminal device and the second terminal device, if the communication technology used by the first terminal device is the same as the communication technology used by the second terminal device.

[0035] The fourth aspect of the present application provides a communication data processing apparatus applied to a first terminal device, the communication data processing apparatus comprising:

[0036] a second obtaining module, configured to obtain a communication technology used by a second terminal device;

[0037] a first generating module, configured to generate first indication information in a case where the communication technology used by the first terminal device is the same as the communication technology used by the second terminal device;

[0038] The first indication information is used to instruct a first network device not to perform security processing on target communication data between the first terminal device and the second terminal device, and the first network device is a network device required for communication between the first terminal device and the second terminal device.

[0039] The fifth aspect of the present application provides a communication data processing method, comprising the following steps:

[0040] obtaining first indication information generated by a first terminal device; wherein the first indication information is used to instruct not to perform security processing on target communication data between the first terminal device and a second terminal device;

[0041] determining not to perform security processing on the target communication data.

[0042] Optionally, the step of obtaining the first indication information generated by the first terminal device specifically comprises:

[0043] obtaining identification information of a target bearer between the first terminal device and the second terminal device, wherein the identification information of the target bearer comprises the first indication information, and the target communication data comprises all data packets of the target bearer.

[0044] Optionally, the step of obtaining the first indication information generated by the first terminal device specifically comprises:

[0045] obtaining a target data packet of a target bearer between the first terminal device and the second terminal device, wherein the target data packet comprises the first indication information, and the target communication data comprises the target data packet.

[0046] Optionally, the step of obtaining the first indication information generated by the first terminal device specifically comprises: receiving first indication information sent by the first terminal device; wherein the first indication information is used to instruct that the communication technology used by the first terminal device is the same as the communication technology used by the second terminal device.

[0047] The processing method of the communication data further includes the following steps: generating fourth indication information; wherein the fourth indication information is used to indicate the target communication data.

[0048] Optionally, the target communication data includes all data packets of a target bearer between the first terminal device and the second terminal device.

[0049] Optionally, the step of determining not to perform security processing on the target communication data specifically includes: determining not to perform security processing on the target communication data at a MAC layer or a PDCP layer.

[0050] The sixth aspect of the present application provides a processing device of communication data, comprising:

[0051] at least one processor;

[0052] a memory in communication connection with the at least one processor; and

[0053] a transceiver for communicating with other devices;

[0054] wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the processing device to perform the processing method of communication data of the fifth aspect.

[0055] The seventh aspect of the present application provides a processing method of communication data, applied to a first terminal device, comprising the following steps:

[0056] obtaining fifth indication information generated by a first network device; wherein the fifth indication information is used to indicate the first terminal device to perform security processing on target communication data between the first terminal device and a second terminal device using a key between the first terminal device and the second terminal device;

[0057] performing security processing on the target communication data between the first terminal device and the second terminal device using the key between the first terminal device and the second terminal device;

[0058] wherein the first network device is a network device required for communication between the first terminal device and the second terminal device.

[0059] Optionally, the step of obtaining the fifth indication information generated by the first network device specifically includes:

[0060] receiving the fifth indication information sent by the first network device.

[0061] Optionally, the target communication data includes target data packets of a target bearer between the first terminal device and the second terminal device.

[0062] The step of receiving the fifth indication information sent by the first network device further comprises the following steps:

[0063] The sixth indication information is generated, wherein the sixth indication information is used to indicate that the first network device does not perform security processing on the target data packet.

[0064] Optionally, the target communication data comprises all data packets of a target bearer between the first terminal device and the second terminal device.

[0065] The step of receiving the fifth indication information sent by the first network device further comprises the following steps:

[0066] The seventh indication information is generated, wherein the seventh indication information is used to indicate that the first network device does not perform security processing on all data packets of the target bearer.

[0067] Optionally, the step of obtaining the fifth indication information generated by the first network device specifically comprises:

[0068] The identification information of the target bearer between the first terminal device and the second terminal device is obtained, wherein the identification information of the target bearer comprises the fifth indication information, and the target communication data comprises all data packets of the target bearer.

[0069] An eighth aspect of the present application provides a processing device for communication data, which is applied to a first terminal device, and the processing device comprises a third obtaining module and a second processing module.

[0070] The third obtaining module is used to obtain the fifth indication information generated by the first network device, wherein the fifth indication information is used to indicate that the second processing module uses a key between the first terminal device and a second terminal device to perform security processing on target communication data between the first terminal device and the second terminal device.

[0071] The second processing module is used to use the key between the first terminal device and the second terminal device to perform security processing on the target communication data between the first terminal device and the second terminal device.

[0072] The first network device is a network device required for communication between the first terminal device and the second terminal device.

[0073] A ninth aspect of the present application provides a processing method for communication data, which comprises the following steps:

[0074] If the communication technology used by the first terminal device is the same as the communication technology used by the second terminal device, the target communication data between the first terminal device and the second terminal device is not processed.

[0075] Optionally, the method further comprises the following steps.

[0076] generating fifth indication information;

[0077] The fifth indication information is used to instruct the first terminal device to use a key between the first terminal device and the second terminal device to perform security processing on target communication data between the first terminal device and the second terminal device.

[0078] Optionally, the method further comprises the following steps.

[0079] sending the fifth indication information to the first terminal device.

[0080] Optionally, the step of not performing security processing on the target communication data between the first terminal device and the second terminal device comprises the following steps.

[0081] receiving a target data packet of a target bearer between the first terminal device and the second terminal device;

[0082] If the target data packet includes sixth indication information, the target data packet is not processed in a secure manner; the sixth indication information is used to instruct not to perform security processing on the target data packet.

[0083] Optionally, the step of not performing security processing on the target communication data between the first terminal device and the second terminal device comprises the following steps.

[0084] If identification information of a target bearer between the first terminal device and the second terminal device includes seventh indication information, all data packets of the target bearer are not processed in a secure manner; the seventh indication information is used to instruct not to perform security processing on all data packets of the target bearer.

[0085] Optionally, the target communication data includes all data packets of a target bearer between the first terminal device and the second terminal device.

[0086] The fifth indication information includes identification information of the target bearer.

[0087] Optionally, the method further comprises the following steps.

[0088] If the communication technology used by the first terminal device is different from the communication technology used by the second terminal device, the target communication data between the first terminal device and the second terminal device is processed in a secure manner.

[0089] The tenth aspect of the present application provides a communication data processing device, comprising:

[0090] at least one processor;

[0091] a memory communicatively connected with the at least one processor; and

[0092] a transceiver configured to communicate with other devices;

[0093] wherein the memory stores instructions executable by the at least one processor, and the instructions, when executed by the at least one processor, cause the processing device to perform the method for processing communication data according to the ninth aspect.

[0094] An eleventh aspect of the present disclosure provides a terminal device, comprising:

[0095] at least one processor;

[0096] a memory communicatively connected with the at least one processor; and

[0097] a transceiver configured to communicate with other devices;

[0098] wherein the memory stores instructions executable by the at least one processor, and the instructions, when executed by the at least one processor, cause the terminal device to perform the method for processing communication data according to the first aspect, the second aspect, or the seventh aspect.

[0099] A twelfth aspect of the present disclosure provides a network device, comprising:

[0100] at least one processor;

[0101] a memory communicatively connected with the at least one processor; and

[0102] a transceiver configured to communicate with other devices;

[0103] wherein the memory stores instructions executable by the at least one processor, and the instructions, when executed by the at least one processor, cause the network device to perform the method for processing communication data according to the fifth aspect or the ninth aspect.

[0104] A thirteenth aspect of the present disclosure provides a non-transitory computer readable storage medium storing computer instructions for causing a computer to perform the method for processing communication data according to any one of the first aspect, the second aspect, the fifth aspect, the seventh aspect, and the ninth aspect.

[0105] The positive progress effect of the present application is that when the communication technology used by the first terminal device is the same as the communication technology used by the second terminal device, the first terminal device uses the key between the first terminal device and the second terminal device to securely process the communication data between the first terminal device and the second terminal device, so that the intermediate network device between the first terminal device and the second terminal device cannot obtain the communication data without any security processing, ensuring the security of the communication data, thereby realizing the secure communication between the first terminal device and the second terminal device at the access layer. BRIEF DESCRIPTION OF DRAWINGS

[0106] Figure 1 It is a schematic diagram of an indoor 5G network structure.

[0107] Figure 2 It is a flowchart of a communication data processing method provided by the embodiment 1 of the present application.

[0108] Figure 3 It is a flowchart of an end-to-end key negotiation mechanism provided by the embodiment 1 of the present application.

[0109] Figure 4 It is a flowchart of a communication data processing method provided by the embodiment 2 of the present application.

[0110] Figure 5 It is a flowchart of a communication data processing method provided by the embodiment 3 of the present application.

[0111] Figure 6 It is a schematic diagram of a terminal device provided by the embodiment 4 of the present application.

[0112] Figure 7 It is a flowchart of a communication data processing method provided by the embodiment 5 of the present application.

[0113] Figure 8 It is a flowchart of a communication data processing method provided by the embodiment 6 of the present application. DETAILED DESCRIPTION

[0114] The present application will be further described by way of examples below, but the present application is not limited in the scope of the examples.

[0115] It should be noted that the terminal device provided in this embodiment is an entity for receiving or transmitting signals on the user side, which can be referred to as a terminal, a user equipment (UE), a mobile station (MS), a mobile terminal (MT), or the like. The terminal device can be a mobile phone, a wearable device, a tablet computer, a computer with wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote surgery, a wireless terminal in smart power grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, or the like. Embodiments of the present application do not limit the specific technology and specific device form of the terminal device.

[0116] The network device is an entity for transmitting or receiving signals on the network side, which can be a PRAS, an eRG, or an access point (AP) in a wireless local area network (WLAN), or the like. Embodiments of the present application do not limit the specific technology and specific device form of the network device.

[0117] Embodiment 1

[0118] Figure 2 A flowchart of a communication data processing method provided in this embodiment. The communication data processing method provided in this embodiment can be executed by a communication data processing apparatus, which can be implemented in software and / or hardware, and can include part or all of the terminal device.

[0119] The communication data processing method will be described below with the first terminal device as the execution subject. As shown in FIG. 1, the communication data processing method provided in this embodiment can include the following steps S101-S104: Figure 2

[0120] Step S101, obtaining a communication technology used by a second terminal device.

[0121] In some examples, the communication technology used by the terminal device can also be referred to as a radio access technology (RAT).

[0122] ​In an embodiment of step S101, the first terminal device receives second indication information sent by the second terminal device. The second indication information is used to indicate the communication technology used by the second terminal device. In this embodiment, the first terminal device interacts with the second terminal device to obtain the communication technology used by the second terminal device.

[0123] In another embodiment of step S101, the first terminal device receives third indication information sent by the first network device. The third indication information is used to indicate the communication technology used by the second terminal device. It should be noted that the first network device is a network device required for communication between the first terminal device and the second terminal device, and the number of the first network device can be one, two or more. In this embodiment, the first terminal device interacts with the first network device to obtain the communication technology used by the second terminal device.

[0124] Step S102: Determine whether the communication technology used by the first terminal device is the same as the communication technology used by the second terminal device. If yes, execute step S103; if no, execute step S104.

[0125] In an embodiment of step S102, if the communication technology used by the first terminal device and the communication technology used by the second terminal device both support the Uu interface protocol, it is determined that the communication technology used by the first terminal device is the same as the communication technology used by the second terminal device.

[0126] In another embodiment of step S102, if the communication technology used by the first terminal device and the communication technology used by the second terminal device both support the Wi-Fi protocol, it is determined that the communication technology used by the first terminal device is the same as the communication technology used by the second terminal device.

[0127] Step S103: Perform security processing on target communication data between the first terminal device and the second terminal device using a key between the first terminal device and the second terminal device.

[0128] In an embodiment of step S103, the first terminal device performs security processing on target communication data between the first terminal device and the second terminal device using a key between the first terminal device and the second terminal device, which can also be referred to as end-to-end security processing. Only the two parties of the communication, i.e. the first terminal device and the second terminal device, can perform security processing on the target communication data. Specifically, for the first terminal device, it performs security processing on the target communication data using a key between the first terminal device and the second terminal device; for the second terminal device, it performs security processing on the target communication data using a key between the first terminal device and the second terminal device.

[0129] The security processing in the embodiment can include encryption, decryption, verification, integrity protection, and the like. In a specific example, the first terminal device uses a key with the second terminal device to encrypt the target communication data, and the second terminal device uses a key with the first terminal device to decrypt the target communication data.

[0130] Figure 3 A flow chart for illustrating an end-to-end key agreement mechanism. The first terminal device and the second terminal device in the embodiment can use the DH algorithm (Diffie-Hellman) to agree on a key between them. The following describes the DH algorithm in detail. Figure 3 The DH algorithm is described in detail as follows:

[0131] The first terminal device UE1 and the second terminal device UE2 each have a private key known only to itself, and generate a public key A under a specific rule (g, a, p).

[0132] The UE1 sends its public key A, together with g and p, to the UE2.

[0133] After receiving the public key A, g, and p sent by the UE1, the UE2 first generates its own public key B using the same rule (g, a, p), and then calculates a shared key K using the public key A of the UE1.

[0134] The UE2 sends its public key B to the UE1. The UE1 already has g and p, and therefore does not need to send g and p to the UE1.

[0135] After receiving the public key B of the UE2, the UE1 calculates a shared key K using the same rule.

[0136] At this point, the UE1 and the UE2 both have the shared key K. At this time, since the private keys a and b are not spread over the Internet, the network devices between the UE1 and the UE2 cannot crack a, b, and K in a short time through the public A / B / g / p. Therefore, the DH algorithm can agree on a key over an insecure network, and a secure encryption channel can be built based on this.

[0137] In step S104, the target communication data between the first terminal device and the second terminal device is processed using the key between the first terminal device and the first network device. In a specific implementation, the first terminal device processes the target communication data using the key between the first terminal device and the first network device, and the first network device processes the target communication data using the key between the first terminal device and the first network device. In a specific example, the first terminal device encrypts the target communication data using the key between the first terminal device and the first network device, and the first network device decrypts the target communication data using the key between the first terminal device and the first network device.

[0138] In an optional implementation, the method further includes step S105: if the communication technology used by the first terminal device is the same as the communication technology used by the second terminal device, generating first indication information. The first indication information is used to indicate that the first network device does not process the target communication data, and the first network device is a network device required for communication between the first terminal device and the second terminal device.

[0139] In this embodiment, the first terminal device generates the first indication information, so that the first network device does not process the target communication data between the first terminal device and the second terminal device, thereby improving the communication efficiency between the first terminal device and the second terminal device while ensuring the communication security between the first terminal device and the second terminal device.

[0140] In an example of an indoor 5G scenario, if the communication technology used by the first terminal device and the second terminal device both supports the Uu interface protocol, for the first network device PRAS or eRG, it is determined according to the first indication information that the target communication data between the first terminal device and the second terminal device is not processed at the PDCP layer.

[0141] In another example of an indoor 5G scenario, if the communication technology used by the first terminal device and the second terminal device both supports the Wi-Fi protocol, for the first network device eRG, it is determined according to the first indication information that the target communication data between the first terminal device and the second terminal device is not processed at the MAC layer.

[0142] In an optional implementation, the target communication data includes all data packets of a target bearer between the first terminal device and the second terminal device, and the first indication information includes identification information of the target bearer.

[0143] The number of target bearers can be one or multiple, which can be determined by negotiation between the first terminal device and the second terminal device, or determined by the first terminal device.

[0144] In this embodiment, the first terminal device uses the key between the first terminal device and the second terminal device to perform security processing on all data packets of the target bearer.

[0145] In another optional embodiment, the target communication data includes target data packets of a target bearer between the first terminal device and the second terminal device, and the target data packets include the first indication information.

[0146] The number of target data packets can be one or multiple, which can be determined by negotiation between the first terminal device and the second terminal device, or determined by the first terminal device itself. In some examples, the target data packets can be PDCP packets.

[0147] In this embodiment, the first terminal device uses the key between the first terminal device and the second terminal device to perform security processing on the target data packets of the target bearer.

[0148] In an optional embodiment, the first indication information specifically indicates that the communication technology used by the first terminal device and the second terminal device is the same. In a specific implementation, the step S105 can further include: the first terminal device sends the generated first indication information to the first network device. In this embodiment, the step S103 specifically includes:

[0149] In step S103a, the first terminal device acquires fourth indication information generated by the first network device. The fourth indication information is used to indicate the target communication data.

[0150] In step S103b, the first terminal device uses the key between the first terminal device and the second terminal device to perform security processing on the target communication data.

[0151] In this embodiment, the first network device configures, through the fourth indication information, the first terminal device to use the key between the first terminal device and the second terminal device to perform security processing on which communication data, i.e., the first network device configures, through the fourth indication information, the security processing method of the target communication data.

[0152] In an optional embodiment of step S103a, the identification information of the target bearer between the first terminal device and the second terminal device is acquired. The identification information of the target bearer includes the fourth indication information, and the target communication data includes all data packets of the target bearer.

[0153] In this embodiment, the first network device configures the first terminal device to use a key between the first terminal device and the second terminal device to perform security processing on all data packets of the target bearer. In a specific implementation, the fourth indication information is included in the identification information of the target bearer, so that the first terminal device obtains the fourth indication information by obtaining the identification information of the target bearer, and further determines to use the key between the first terminal device and the second terminal device to perform security processing on all data packets of the target bearer.

[0154] The embodiment also provides a communication data processing apparatus applied to a first terminal device, and the communication data processing apparatus comprises a first obtaining module and a first processing module.

[0155] The first obtaining module is configured to obtain a communication technology used by a second terminal device.

[0156] In an optional implementation, the first obtaining module is specifically configured to receive second indication information sent by the second terminal device. The second indication information is used to indicate the communication technology used by the second terminal device.

[0157] In another optional implementation, the first obtaining module is specifically configured to receive third indication information sent by the first network device. The third indication information is used to indicate the communication technology used by the second terminal device.

[0158] The first processing module is configured to, in a case where the communication technology used by the first terminal device is the same as the communication technology used by the second terminal device, use a key between the first terminal device and the second terminal device to perform security processing on target communication data between the first terminal device and the second terminal device.

[0159] In an optional implementation, the communication data processing apparatus further comprises a first generating module configured to generate first indication information. The first determining module is further configured to, in a case where it is determined that the communication technology used by the first terminal device is the same as the communication technology used by the second terminal device, invoke the first generating module.

[0160] The first indication information is used to indicate that the first network device does not perform security processing on the target communication data. The first network device is a network device required for communication between the first terminal device and the second terminal device.

[0161] In an optional implementation, the first indication information is specifically used to indicate that the communication technology used by the first terminal device is the same as the communication technology used by the second terminal device.

[0162] In this embodiment, the first processing module specifically includes an obtaining unit and a processing unit. The obtaining unit is configured to obtain fourth indication information generated by the first network device. The fourth indication information is used to indicate a security processing method of the target communication data. The processing unit is configured to perform security processing on the target communication data using a key between the second terminal device.

[0163] In an optional implementation, the obtaining unit is specifically configured to obtain identification information of a target bearer between the first terminal device and the second terminal device. The identification information of the target bearer includes the fourth indication information, and the target communication data includes all data packets of the target bearer.

[0164] It should be noted that the communication data processing apparatus in this embodiment can be a separate chip, a chip module or a terminal device, or can be a chip or a chip module integrated in a terminal device.

[0165] The various modules / units included in the communication data processing apparatus described in this embodiment can be software modules / units, hardware modules / units, or part software modules / units and part hardware modules / units.

[0166] Embodiment 2

[0167] Figure 4 A flowchart of a communication data processing method provided in this embodiment is shown. The communication data processing method provided in this embodiment can be executed by a communication data processing apparatus, which can be implemented in software and / or hardware, and can include part or all of a terminal device.

[0168] The communication data processing method will be described below with the first terminal device as the execution subject. As shown in Figure 4 The communication data processing method provided in this embodiment can include the following steps S201-S203.

[0169] In step S201, the communication technology used by the second terminal device is obtained. The specific implementation of step S201 can refer to step S101 in Embodiment 1.

[0170] In step S202, it is determined whether the communication technology used by the first terminal device is the same as the communication technology used by the second terminal device. If yes, step S203 is performed; if no, the flow ends. The specific implementation of step S202 can refer to step S102 in Embodiment 1.

[0171] In step S203, first indication information is generated. The specific implementation of step S203 can refer to step S105 in Embodiment 1.

[0172] The first indication information is used to instruct the first network device not to perform security processing on the target communication data between the first terminal device and the second terminal device. The first network device is a network device required for communication between the first terminal device and the second terminal device.

[0173] The present embodiment provides a communication data processing apparatus, which is applied to a first terminal device and includes a second obtaining module and a second generating module.

[0174] The second obtaining module is configured to obtain a communication technology used by a second terminal device.

[0175] The second generating module is configured to generate first indication information in a case where the communication technology used by the first terminal device is the same as the communication technology used by the second terminal device.

[0176] The first indication information is used to instruct the first network device not to perform security processing on the target communication data between the first terminal device and the second terminal device. The first network device is a network device required for communication between the first terminal device and the second terminal device.

[0177] It should be noted that the communication data processing apparatus in the present embodiment can be a separate chip, a chip module or a terminal device, or can be a chip or a chip module integrated in a terminal device.

[0178] The modules / units included in the communication data processing apparatus described in the present embodiment can be software modules / units, hardware modules / units, or part software modules / units and part hardware modules / units.

[0179] Embodiment 3

[0180] Figure 5 A flowchart of a communication data processing method provided in the present embodiment is shown. The communication data processing method provided in the present embodiment can be executed by a communication data processing apparatus, which can be implemented in software and / or hardware, and can include part or all of a terminal device.

[0181] The communication data processing method will be described below with the first terminal device as the execution subject. As shown in FIG. 3, the communication data processing method provided in the present embodiment can include the following steps S301-S302. Figure 5 ​

[0182] Step S301: Obtain fifth indication information generated by a first network device. The fifth indication information is used to instruct a first terminal device to use a key between the first terminal device and a second terminal device to perform security processing on target communication data between the first terminal device and the second terminal device. The first network device is a network device required for communication between the first terminal device and the second terminal device.

[0183] In a specific implementation, the first network device can generate the fifth indication information in a case where it is determined that a communication technology used by the first terminal device is the same as a communication technology used by the second terminal device. In some examples, the communication technology used by the terminal device can also be referred to as a radio access technology.

[0184] In one example of a specific implementation, if the communication technology used by the first terminal device and the communication technology used by the second terminal device both support a Uu interface protocol, it is considered that the communication technology used by the first terminal device and the communication technology used by the second terminal device are the same.

[0185] In another example of a specific implementation, if the communication technology used by the first terminal device and the communication technology used by the second terminal device both support a Wi-Fi protocol, it is considered that the communication technology used by the first terminal device and the communication technology used by the second terminal device are the same.

[0186] In an optional implementation of step S301, the first terminal device receives the fifth indication information sent by the first network device. In a specific implementation, the first network device can send the fifth indication information to the first terminal device in a case where it is determined that the communication technology used by the first terminal device is the same as the communication technology used by the second terminal device.

[0187] In another optional implementation of step S301, obtain identification information of a target bearer between the first terminal device and the second terminal device. The identification information of the target bearer includes the fifth indication information, and the target communication data includes all data packets of the target bearer.

[0188] In a specific implementation, the first network device can include the fifth indication information in the identification information of the target bearer between the first terminal device and the second terminal device. The first terminal device obtains the fifth indication information by obtaining the identification information of the target bearer, and uses the key between the first terminal device and the second terminal device to perform security processing on all data packets of the target bearer according to the fifth indication information.

[0189] Step S302: Use the key between the second terminal device to perform security processing on target communication data between the first terminal device and the second terminal device.

[0190] In the implementation of step S302, the first terminal device uses the key between the first terminal device and the second terminal device to perform security processing on the target communication data between the first terminal device and the second terminal device, which can also be referred to as end-to-end security processing. Only the two terminals, i.e., the first terminal device and the second terminal device, can perform security processing on the target communication data. Specifically, for the first terminal device, the first terminal device uses the key between the first terminal device and the second terminal device to perform security processing on the target communication data. For the second terminal device, the second terminal device uses the key between the first terminal device and the second terminal device to perform security processing on the target communication data.

[0191] In the implementation, the security processing can include encryption, decryption, verification, integrity protection, and the like. In one specific example, the first terminal device uses the key between the first terminal device and the second terminal device to perform encryption processing on the target communication data, and the second terminal device uses the key between the first terminal device and the second terminal device to perform decryption processing on the target communication data.

[0192] In the implementation, the first terminal device and the second terminal device can use the DH algorithm to negotiate the key between the first terminal device and the second terminal device.

[0193] In an optional implementation, the target communication data includes target data packets of a target bearer between the first terminal device and the second terminal device. In the implementation, after step S201, the first terminal device further generates sixth indication information. The sixth indication information is used to indicate that the first network device does not perform security processing on the target data packets.

[0194] The number of target data packets can be one or multiple, which can be determined by negotiation between the first terminal device and the second terminal device, or determined by the first terminal device. In some examples, the target data packets can be PDCP packets.

[0195] In the implementation, the first terminal device uses the key between the first terminal device and the second terminal device to perform security processing on the target data packets of the target bearer, and the first terminal device generates the sixth indication information to make the first network device not perform security processing on the target data packets. In this way, the communication security of the target data packets is ensured, and the communication efficiency of the target data packets is improved.

[0196] In another optional implementation, the target communication data includes all data packets of a target bearer between the first terminal device and the second terminal device. In the implementation, after step S301, the first terminal device further generates seventh indication information. The seventh indication information is used to indicate that the first network device does not perform security processing on all data packets of the target bearer.

[0197] The number of target bearers can be one or multiple, which can be determined by negotiation between the first terminal device and the second terminal device, or determined by the first terminal device.

[0198] In this embodiment, the first terminal device uses the key between the first terminal device and the second terminal device to process all data packets of the target bearer, and the first terminal device generates the seventh indication information to make the first network device not process all data packets of the target bearer, thereby ensuring the communication security of all data packets of the target bearer and improving the communication efficiency of all data packets of the target bearer.

[0199] The embodiment also provides a processing apparatus for communication data, which is applied to a first terminal device and includes a third acquisition module and a second processing module.

[0200] The third acquisition module is configured to acquire fifth indication information generated by a first network device. The fifth indication information is used to instruct the second processing module to use a key between the first terminal device and a second terminal device to process target communication data between the first terminal device and the second terminal device. The first network device is a network device required for communication between the first terminal device and the second terminal device.

[0201] The second processing module is configured to use the key between the first terminal device and the second terminal device to process the target communication data between the first terminal device and the second terminal device.

[0202] In an optional embodiment of the third acquisition module, the third acquisition module is specifically configured to receive the fifth indication information sent by the first network device.

[0203] In an optional embodiment, the target communication data includes target data packets of a target bearer between the first terminal device and the second terminal device.

[0204] In this embodiment, the processing apparatus for communication data further includes a third generation module configured to generate sixth indication information. The sixth indication information is used to instruct the first network device not to process the target data packets.

[0205] In another optional embodiment, the target communication data includes all data packets of a target bearer between the first terminal device and the second terminal device.

[0206] In this embodiment, the processing apparatus for communication data further comprises a fourth generating module configured to generate seventh indication information. The seventh indication information is used to indicate that the first network device does not perform security processing on all data packets of the target bearer.

[0207] In another optional implementation of the second obtaining module, the identification information of the target bearer between the first terminal device and the second terminal device is obtained. The identification information of the target bearer comprises fifth indication information, and the target communication data comprises all data packets of the target bearer.

[0208] It should be noted that the processing apparatus for communication data in this embodiment can be a single chip, a chip module or a terminal device, or a chip or a chip module integrated in a terminal device.

[0209] As to each module / unit included in the processing apparatus for communication data described in this embodiment, it can be a software module / unit, or a hardware module / unit, or part of it is a software module / unit and part of it is a hardware module / unit.

[0210] Embodiment 4

[0211] Figure 6 A structure schematic diagram of a terminal device is provided in this embodiment. The terminal device comprises at least one processor, a memory in communication connection with the at least one processor, and a transceiver for communication with other devices. The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the communication data processing method in embodiments 1, 2 or 3. Figure 6 The terminal device 3 shown is only an example and should not bring any limitation to the function and use range of the embodiments of the present application.

[0212] The components of the terminal device 3 can include, but are not limited to, a transceiver, the at least one processor 4, the at least one memory 5, and a bus 6 connecting different system components including the memory 5 and the processor 4.

[0213] The bus 6 includes a data bus, an address bus and a control bus.

[0214] The memory 5 can include volatile memory, such as a random access memory (RAM) 51 and / or a cache memory 52, and can further include a read-only memory (ROM) 53.

[0215] The memory 5 may also include a program / utility 55 having a set (at least one) of program modules 54, including but not limited to: an operating system, one or more application programs, other program modules, and program data, each or some combination of these examples may include an implementation of a network environment.

[0216] The processor 4 executes various functional applications and data processing by running computer programs stored in the memory 5, such as the communication data processing method in embodiments 1, 2 or 3 of the present invention.

[0217] Terminal device 3 can also communicate with one or more external devices 7 (e.g., keyboard, pointing device, etc.). This communication can be performed through input / output (I / O) interface 8. Furthermore, terminal device 3 can also communicate with one or more networks (e.g., local area network (LAN), wide area network (WAN), and / or public networks, such as the Internet) via network adapter 9. Figure 6 As shown, network adapter 9 communicates with other modules of terminal device 3 via bus 6. It should be understood that, although... Figure 6 As not shown in the diagram, other hardware and / or software modules can be used in conjunction with terminal device 3, including but not limited to: microcode, device drivers, redundant processors, external disk drive arrays, RAID (disk array) systems, tape drives, and data backup storage systems.

[0218] It should be noted that although several units / modules or sub-units / modules of the terminal device are mentioned in the detailed description above, this division is merely exemplary and not mandatory. In fact, according to embodiments of the present invention, the features and functions of two or more units / modules described above can be embodied in one unit / module. Conversely, the features and functions of one unit / module described above can be further divided and embodied by multiple units / modules.

[0219] Example 5

[0220] Figure 7 This is a flowchart illustrating a communication data processing method provided in this embodiment. The communication data processing method provided in this embodiment can be executed by a communication data processing device, which can be implemented through software and / or hardware, and may include part or all of a network device.

[0221] Based on Examples 1 and 2, the following description focuses on the method of processing communication data using a network device as the executing entity. For example... Figure 7 As shown, the communication data processing method provided in this embodiment may include the following steps S401 to S402:

[0222] In step S401, first indication information generated by the first terminal device is acquired. The first indication information is used to indicate that the target communication data between the first terminal device and the second terminal device is not subjected to security processing.

[0223] In an optional embodiment of step S401, identification information of a target bearer between the first terminal device and the second terminal device is acquired. The identification information of the target bearer includes the first indication information, and the target communication data includes all data packets of the target bearer.

[0224] In another optional embodiment of step S401, a target data packet of a target bearer between the first terminal device and the second terminal device is acquired. The target data packet includes the first indication information, and the target communication data includes the target data packet.

[0225] In yet another optional embodiment of step S401, the first indication information sent by the first terminal device is received. The first indication information is used to indicate that the communication technology used by the first terminal device and the second terminal device is the same.

[0226] In the embodiment, the method for processing the communication data further includes the following step: generating fourth indication information. The fourth indication information is used to indicate the target communication data.

[0227] In an optional embodiment, the target communication data includes all data packets of a target bearer between the first terminal device and the second terminal device.

[0228] In step S402, it is determined that the target communication data is not subjected to security processing.

[0229] In a specific implementation of step S402, it is determined that the target communication data is not subjected to security processing at the MAC layer or the PDCP layer.

[0230] In one example of the indoor 5G scenario, if the communication technology used by the first terminal device and the second terminal device both supports the Uu interface protocol, for the first network device PRAS or eRG, it is determined according to the first indication information that the target communication data between the first terminal device and the second terminal device is not subjected to security processing at the PDCP layer.

[0231] In another example of the indoor 5G scenario, if the communication technology used by the first terminal device and the second terminal device both supports the Wi-Fi protocol, for the first network device eRG, it is determined according to the first indication information that the target communication data between the first terminal device and the second terminal device is not subjected to security processing at the MAC layer.

[0232] The embodiment also provides a processing apparatus for communication data, comprising at least one processor, a memory connected with the at least one processor in communication, and a transceiver for communicating with other devices.

[0233] The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the processing apparatus to perform the processing method for communication data.

[0234] It should be noted that the processing apparatus for communication data in the embodiment can be a separate chip, a chip module or a network device, or can be a chip or a chip module integrated in a network device.

[0235] The various modules / units included in the processing apparatus for communication data described in the embodiment can be software modules / units, hardware modules / units, or part software modules / units and part hardware modules / units.

[0236] Embodiment 6

[0237] Figure 8 A flowchart of a processing method for communication data is provided in the embodiment. The processing method for communication data provided in the embodiment can be performed by a processing apparatus for communication data, which can be implemented in software and / or hardware, and can include part or all of a network device.

[0238] Based on the embodiment 3, the processing method for communication data will be described below with the network device as the execution subject. As shown in Figure 8 The processing method for communication data provided in the embodiment can comprise the following steps S501-S503.

[0239] In step S501, it is determined whether the communication technologies used by the first terminal device and the second terminal device are the same. If yes, step S502 is performed, otherwise step S503 is performed.

[0240] In one example of the implementation of step S501, if the communication technologies used by the first terminal device and the second terminal device both support Uu interface protocol, it is determined that the communication technologies used by the first terminal device and the second terminal device are the same.

[0241] In another example of the implementation of step S501, if the communication technologies used by the first terminal device and the second terminal device both support Wi-Fi protocol, it is determined that the communication technologies used by the first terminal device and the second terminal device are the same.

[0242] Step S502: not performing security processing on the target communication data between the first terminal device and the second terminal device.

[0243] In a specific implementation of step S502, it is determined that no security processing is performed on the target communication data at the MAC layer or the PDCP layer.

[0244] In one example of the indoor 5G scenario, if the communication technologies used by the first terminal device and the second terminal device both support the Uu interface protocol, for the first network device PRAS or eRG, it is determined according to the first indication information that no security processing is performed on the target communication data between the first terminal device and the second terminal device at the PDCP layer.

[0245] In another example of the indoor 5G scenario, if the communication technologies used by the first terminal device and the second terminal device both support the Wi-Fi protocol, for the first network device eRG, it is determined according to the first indication information that no security processing is performed on the target communication data between the first terminal device and the second terminal device at the MAC layer.

[0246] Step S503: performing security processing on the target communication data between the first terminal device and the second terminal device. In one example of the implementation of step S503, the first network device uses the key between the first terminal device to perform security processing on the target communication data between the second terminal device. In another example of the implementation of step S503, the first network device uses the key between the second terminal device to perform security processing on the target communication data between the second terminal device. In yet another example of the implementation of step S503, the first network device uses the key between the first network device to perform security processing on the target communication data between the second terminal device.

[0247] In an optional implementation, the method for processing communication data further includes step S504: generating fifth indication information. The fifth indication information is used to instruct the first terminal device to use the key between the second terminal device to perform security processing on the target communication data between the second terminal device.

[0248] In an optional implementation, step S504 further includes: sending the fifth indication information to the first terminal device.

[0249] In an optional implementation of step S502, a target packet of a target bearer between the first terminal device and the second terminal device is received; if the target packet includes sixth indication information, no security processing is performed on the target packet. The sixth indication information is used to instruct not to perform security processing on the target packet.

[0250] In another optional implementation of step S502, if the identification information of the target bearer between the first terminal device and the second terminal device includes seventh indication information, all data packets of the target bearer are not subjected to security processing. The seventh indication information is used to indicate that all data packets of the target bearer are not subjected to security processing.

[0251] In an optional implementation, the target communication data includes all data packets of a target bearer between the first terminal device and the second terminal device. The fifth indication information includes identification information of the target bearer.

[0252] The embodiment also provides a processing apparatus for communication data, including at least one processor, a memory connected with the at least one processor in communication, and a transceiver for communicating with other devices.

[0253] The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the processing apparatus to perform the processing method of communication data described in the embodiment.

[0254] It should be noted that the processing apparatus for communication data in the embodiment can be a separate chip, a chip module or a network device, or can be a chip or a chip module integrated in a network device.

[0255] As to each module / unit contained in the processing apparatus for communication data described in the embodiment, it can be a software module / unit, or a hardware module / unit, or part of a software module / unit and part of a hardware module / unit.

[0256] Embodiment 7

[0257] The embodiment provides a network device, including at least one processor, a memory connected with the at least one processor in communication, and a transceiver for communicating with other devices. The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the processing method of communication data in Embodiment 5 or 6.

[0258] Embodiment 8

[0259] The embodiment provides a non-transitory computer-readable storage medium storing computer instructions for causing a computer to perform the processing method of communication data in Embodiment 1, 2, 3, 5 or 6.

[0260] More specifically, the readable storage medium can include, but is not limited to, a portable disc, a hard disk, a random access memory, a read-only memory, an erasable programmable read-only memory, an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0261] In possible implementation manners, the present application can also be implemented in the form of a program product, which includes program codes for causing a terminal device to perform the processing method of communication data in embodiments 1, 2 or 3 when the program product is run on the terminal device, and for causing a network device to perform the processing method of communication data in embodiments 5 or 6 when the program product is run on the network device.

[0262] The program codes for executing the present application can be written in any combination of one or more programming languages, and can be executed entirely on a terminal device, partially on a terminal device, as a separate software package, partially on a terminal device and partially on a remote device, or entirely on a remote device.

[0263] Although the above describes specific embodiments of the present application, those skilled in the art should understand that this is only an example, and the protection scope of the present application is defined by the appended claims. Those skilled in the art can make various changes or modifications to these embodiments without departing from the principles and essence of the present application, and these changes and modifications all fall within the protection scope of the present application.

Claims

1. A method for processing communication data, characterized in that, When applied to a first terminal device, the following steps are included: Obtain the communication technology used by the second terminal device; If the communication technology used by the first terminal device is the same as that used by the second terminal device, then a first indication message is generated, and the target communication data between the first terminal device and the second terminal device is securely processed using the key between the first terminal device and the second terminal device. The first indication information is used to instruct the first network device not to perform security processing on the target communication data between the first terminal device and the second terminal device. The first network device is the network device required for communication between the first terminal device and the second terminal device.

2. The method for processing communication data as described in claim 1, characterized in that, The step of obtaining the communication technology used by the second terminal device specifically includes: Receive second indication information sent by the second terminal device; wherein the second indication information is used to indicate the communication technology used by the second terminal device.

3. The method for processing communication data as described in claim 1, characterized in that, The step of obtaining the communication technology used by the second terminal device specifically includes: The third indication information sent by the first network device is received; wherein the third indication information is used to indicate the communication technology used by the second terminal device.

4. The method for processing communication data as described in claim 1, characterized in that, The target communication data includes all data packets carried by the target between the first terminal device and the second terminal device; The first indication information includes the identification information carried by the target.

5. The method for processing communication data as described in claim 1, characterized in that, The target communication data includes the target data packet carried between the first terminal device and the second terminal device, and the target data packet includes the first indication information.

6. The method for processing communication data as described in claim 1, characterized in that, The first indication information is specifically used to indicate that the first terminal device and the second terminal device use the same communication technology; The step of using the key between the second terminal device and the target communication data between the second terminal device to perform secure processing specifically includes: Obtain fourth indication information generated by the first network device; wherein the fourth indication information is used to indicate the target communication data; The target communication data is securely processed using a key exchanged with the second terminal device.

7. The method for processing communication data as described in claim 6, characterized in that, The step of obtaining the fourth indication information generated by the first network device specifically includes: Obtain the identification information of the target bearer between the first terminal device and the second terminal device; wherein the identification information of the target bearer includes fourth indication information, and the target communication data includes all data packets of the target bearer.

8. The method for processing communication data as described in claim 1, characterized in that, The method for processing the communication data further includes the following steps: If the communication technology used by the first terminal device is different from that used by the second terminal device, then the target communication data between the first terminal device and the second terminal device is securely processed using the key between the first network device and the second terminal device. The first network device is the network device required for communication between the first terminal device and the second terminal device.

9. A communication data processing apparatus, characterized in that, The communication data processing device, used in a first terminal device, includes: The second acquisition module is used to acquire the communication technology used by the second terminal device; The second generation module is used to generate first indication information and to perform secure processing on target communication data between the first terminal device and the second terminal device using a key between the first terminal device and the second terminal device, when the communication technology used by the first terminal device is the same as that used by the second terminal device. The first indication information is used to instruct the first network device not to perform security processing on the target communication data between the first terminal device and the second terminal device. The first network device is the network device required for communication between the first terminal device and the second terminal device.

10. A method for processing communication data, characterized in that, Applied to a first network device, which is a network device required for communication between a first terminal device and a second terminal device, the method for processing the communication data includes the following steps: Obtain first indication information generated by the first terminal device; wherein, the first indication information is used to indicate that no security processing shall be performed on the target communication data between the first terminal device and the second terminal device; It is determined that the target communication data will not be subject to security processing.

11. The method for processing communication data as described in claim 10, characterized in that, The step of obtaining the first indication information generated by the first terminal device specifically includes: Obtain the identification information of the target bearer between the first terminal device and the second terminal device, wherein the identification information of the target bearer includes first indication information, and the target communication data includes all data packets of the target bearer.

12. The method for processing communication data as described in claim 10, characterized in that, The step of obtaining the first indication information generated by the first terminal device specifically includes: Obtain the target data packet carried by the target between the first terminal device and the second terminal device, wherein the target data packet includes the first indication information and the target communication data includes the target data packet.

13. The method for processing communication data as described in claim 10, characterized in that, The step of obtaining the first indication information generated by the first terminal device specifically includes: receiving the first indication information sent by the first terminal device; wherein, the first indication information is used to indicate that the first terminal device and the second terminal device use the same communication technology; The method for processing the communication data further includes the following step: generating fourth indication information; wherein the fourth indication information is used to indicate the target communication data.

14. The method for processing communication data as described in claim 13, characterized in that, The target communication data includes all data packets carried by the target between the first terminal device and the second terminal device.

15. The method for processing communication data as described in any one of claims 10-14, characterized in that, The step of determining not to perform security processing on the target communication data specifically includes: determining not to perform security processing on the target communication data at the MAC layer or PDCP layer.

16. A communication data processing apparatus, characterized in that, include: At least one processor; A memory that is communicatively connected to the at least one processor; as well as A transceiver is used to communicate with other devices; The memory stores instructions executable by the at least one processor, which, when executed by the at least one processor, enable the processing device to perform the method for processing communication data according to any one of claims 10-15.

17. A method for processing communication data, characterized in that, When applied to a first terminal device, the following steps are included: Obtain fifth indication information generated by the first network device; wherein, the fifth indication information is used to instruct the first terminal device to use the key between itself and the second terminal device to perform secure processing on the target communication data between itself and the second terminal device; The target communication data between the first terminal device and the second terminal device is securely processed using the key between the second terminal device; The first network device is the network device required for communication between the first terminal device and the second terminal device.

18. The method for processing communication data as described in claim 17, characterized in that, The step of obtaining the fifth indication information generated by the first network device specifically includes: Receive the fifth instruction information sent by the first network device.

19. The method for processing communication data as described in claim 18, characterized in that, The target communication data includes the target data packets carried between the first terminal device and the second terminal device. Following the step of receiving the fifth indication information sent by the first network device, the following steps are also included: A sixth indication message is generated; wherein the sixth indication message is used to instruct the first network device not to perform security processing on the target data packet.

20. The method for processing communication data as described in claim 18, characterized in that, The target communication data includes all data packets carried by the target between the first terminal device and the second terminal device; Following the step of receiving the fifth indication information sent by the first network device, the following steps are also included: Generate a seventh indication message; wherein the seventh indication message is used to instruct the first network device not to perform security processing on all data packets carried by the target.

21. The method for processing communication data as described in claim 17, characterized in that, The step of obtaining the fifth indication information generated by the first network device specifically includes: Obtain the identification information of the target bearer between the first terminal device and the second terminal device, wherein the identification information of the target bearer includes fifth indication information, and the target communication data includes all data packets of the target bearer.

22. A communication data processing apparatus, characterized in that, Applied in a first terminal device, the processing device includes a third acquisition module and a second processing module; The third acquisition module is used to acquire the fifth indication information generated by the first network device; wherein, the fifth indication information is used to instruct the second processing module to use the key between the second terminal device and the target communication data between the second terminal device to perform secure processing. The second processing module is used to perform secure processing on the target communication data between the first terminal device and the second terminal device using a key between the second terminal device and the first terminal device; The first network device is the network device required for communication between the first terminal device and the second terminal device.

23. A method for processing communication data, characterized in that, Applied to a first network device, wherein the first network device is a network device required for communication between a first terminal device and a second terminal device, the method includes the following steps: If the communication technology used by the first terminal device is the same as that used by the second terminal device, then no security processing is performed on the target communication data between the first terminal device and the second terminal device.

24. The method for processing communication data as described in claim 23, characterized in that, The method for processing the communication data further includes the following steps: Generate the fifth instruction message; The fifth instruction information is used to instruct the first terminal device to use the key between itself and the second terminal device to perform secure processing on the target communication data between itself and the second terminal device.

25. The method for processing communication data as described in claim 24, characterized in that, The method for processing the communication data further includes the following steps: The fifth instruction information is sent to the first terminal device.

26. The method for processing communication data as described in claim 25, characterized in that, The step of not performing security processing on the target communication data between the first terminal device and the second terminal device specifically includes: Receive the target data packet carried by the target between the first terminal device and the second terminal device; If the target data packet includes a sixth indication, then no security processing is performed on the target data packet; wherein, the sixth indication is used to indicate that no security processing is performed on the target data packet.

27. The method for processing communication data as described in claim 25, characterized in that, The step of not performing security processing on the target communication data between the first terminal device and the second terminal device specifically includes: If the identification information of the target bearer between the first terminal device and the second terminal device includes the seventh indication information, then no security processing will be performed on all data packets of the target bearer; wherein, the seventh indication information is used to indicate that no security processing will be performed on all data packets of the target bearer.

28. The method for processing communication data as described in claim 24, characterized in that, The target communication data includes all data packets carried by the target between the first terminal device and the second terminal device; The fifth indication information includes the identification information carried by the target.

29. The method for processing communication data as described in any one of claims 23-28, characterized in that, The method for processing the communication data further includes the following steps; If the communication technology used by the first terminal device is different from that used by the second terminal device, then the target communication data between the first terminal device and the second terminal device shall be processed securely.

30. A communication data processing apparatus, characterized in that, include: At least one processor; A memory that is communicatively connected to the at least one processor; as well as A transceiver is used to communicate with other devices; The memory stores instructions executable by the at least one processor, which, when executed by the at least one processor, enable the processing device to perform the method for processing communication data according to any one of claims 23-29.

31. A terminal device, characterized in that, include: At least one processor; A memory that is communicatively connected to the at least one processor; as well as A transceiver is used to communicate with other devices; The memory stores instructions that can be executed by the at least one processor, which, when executed by the at least one processor, enable the terminal device to perform the communication data processing method according to any one of claims 1-8 or 17-21.

32. A network device, characterized in that, include: At least one processor; A memory that is communicatively connected to the at least one processor; as well as A transceiver is used to communicate with other devices; The memory stores instructions executable by the at least one processor, which, when executed by the at least one processor, enable the network device to perform the communication data processing method according to any one of claims 10-15 or 23-29.

33. A non-transitory computer-readable storage medium storing computer instructions, characterized in that, The computer instructions are used to cause the computer to perform a method for processing communication data as described in any one of claims 1-8, 10-15, and 17-21 or 23-29.

Citation Information

Patent Citations

  • Method, device, equipment and system for carrying out user login through cross-terminal equipment

    CN104158883A