Communication method, device and system

By applying a security protection method between terminal devices that is no less secure than the discovery process, the security issue in the V2X PC5 establishment process is resolved, the security level of communications is improved, and message tampering and attacks are prevented.

CN115836539BActive Publication Date: 2025-09-12HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202080103118.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-08-14
Publication Date
2025-09-12
Estimated Expiration
2040-08-14

AI Technical Summary

Technical Problem

The existing V2X PC5 establishment process has insufficient security issues in device-to-device communication, especially control plane signaling is vulnerable to middle attackers, resulting in a reduced security level.

Method used

By determining and applying a security protection method between terminal devices with a security level no lower than the security level determined during the discovery process, the security of the PC5 connection is ensured not to be degraded, and when necessary, critical messages are integrity protected to prevent tampering and attacks.

Benefits of technology

The security level of the V2X PC5 establishment process is improved, preventing attackers from tampering with and attacking messages, and ensuring the security and integrity of communications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115836539B_ABST
    Figure CN115836539B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a communication method, apparatus, and system for improving the security of the V2X PC5 establishment process. The method includes: a first terminal device obtaining a first security protection method, where the first security protection method is determined during a discovery process between the first and second terminal devices; and the first terminal device determining a second security protection method based on the first security protection method, where the second security protection method is the security protection method for the PC5 connection between the first and second terminal devices. Exemplarily, the security level of the second security protection method is no less than that of the first security protection method. This communication method is applicable to the field of V2X communications.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technologies, and in particular to communication methods, devices, and systems. Background Art

[0002] In traditional mobile networks, the signaling and data communication paths between user equipment (UE) need to pass through network-side equipment (such as base stations / serving gateways (SGW) / packet data network gateways (PGW)). Different UEs cannot communicate directly. Even between two UEs that are very close to each other, taking UE1 and UE2 as an example, when transmitting data, UE1 needs to first send the data to the connected base station 1, and then the data is transmitted through the network side to the base station 2 connected to UE2 (at this time, base station 1 and base station 2 can be the same base station or different base stations), and finally base station 2 sends the data to UE2. This will place a large demand on the network transmission bandwidth and have low transmission efficiency.

[0003] Proximity-based services (ProSe) were proposed to address the need for short-range direct communication for device-to-device (D2D) communications. ProSe requires UEs to exchange data directly, or only through base stations without going through core network equipment (such as SGW / PGW), thereby improving communication efficiency between UEs that are close to each other. In fifth-generation (5G) communication technology, short-range direct communication services are used in vehicle-to-everything (V2X).

[0004] Currently, before ProSe technology establishes data exchange between two UEs, it is necessary to execute the ProSe discovery process and the PC5 establishment process in sequence. Among them, the ProSe discovery process is used to realize mutual discovery between the two UEs, and the PC5 establishment process is used to establish a signaling connection and data connection between the two UEs for direct communication through the PC5 interface. However, the security protection mechanism in the existing V2X PC5 establishment process (for details, please refer to the third generation partnership project (3GPP) technical standards (TS) 23.303) is not perfect, and the control plane signaling in the V2X PC5 establishment process is easily attacked by middle attackers, which may cause the security level to be downgraded. Therefore, how to improve the security of the V2XPC5 establishment process is an urgent problem to be solved. Summary of the Invention

[0005] The embodiments of the present application provide a communication method, apparatus, and system for improving the security of the V2X PC5 establishment process.

[0006] To achieve the above objectives, the embodiments of the present application adopt the following technical solutions:

[0007] In a first aspect, a communication method is provided, which includes: a first terminal device obtains a first security protection method, where the first security protection method is a security protection method determined in a discovery process between the first terminal device and the second terminal device; the first terminal device determines a second security protection method based on the first security protection method, where the second security protection method is a security protection method for a PC5 connection between the first terminal device and the second terminal device. Since the embodiment of the present application can refer to the first security protection method determined in the discovery process when determining the second security protection method, the security level of the determined second security protection method can be made not lower than the security level of the first security protection method. In other words, the security level of the first security protection method is the lowest security level of the PC5 connection in the PC5 establishment process, so that the purpose of no security degradation can be achieved.

[0008] In one possible implementation, the communication method further includes: the first terminal device receives a first message from the second terminal device, the first message being the first message in the PC5 establishment process between the first terminal device and the second terminal device; and the first terminal device decrypts the first message according to the first security protection method. That is, in the embodiment of the present application, the first message is protected using the first security protection method. Thus, when the first security protection method includes integrity protection being enabled, since the first terminal device can use the first security protection method to protect the first message, the problem of a reduced security level caused by an attacker attacking or tampering with the first message in the PC5 establishment process can be avoided, thereby improving the security level of the PC5 establishment process.

[0009] In a second aspect, a communication method is provided, the method comprising: a first terminal device obtains a first security protection method, the first security protection method being a security protection method determined in a discovery process between the first terminal device and the second terminal device; the first terminal device uses the first security protection method to perform security protection on at least one message in a PC5 establishment process between the first terminal device and the second terminal device, and then sends the at least one message after security protection to the second terminal device. Based on the communication method provided in the embodiment of the present application, on the one hand, when the first security protection method includes integrity protection being turned on, since the first terminal device can use the first security protection method to perform security protection on at least one message in a PC5 establishment process between the first terminal device and the second terminal device, the problem of a reduced security level caused by an attacker attacking or tampering with a message in the PC5 establishment process can be avoided, thereby improving the security level of the PC5 establishment process. On the other hand, when the security level of the first security protection method is higher than or equal to the security level of the security protection method used by the control plane of the PC5 connection between the first terminal device and the second terminal device, since the first terminal device can use the first security protection method to perform security protection on at least one message in the PC5 establishment process between the first terminal device and the second terminal device, the problem of reduced security level caused by the security level of the security protection method used by the control plane of the PC5 connection being lower than the security level of the first security protection method can be avoided, thereby improving the security level of the PC5 establishment process.

[0010] In one possible implementation, the at least one message includes a first message, which is the first message in the PC5 establishment process. That is, in this embodiment of the present application, the first message is protected using the first security protection method. Thus, if the first security protection method includes integrity protection enabled, the first terminal device can use the first security protection method to protect the first message. This prevents the security level of the first message in the PC5 establishment process from being compromised by an attacker or tampered with, thereby improving the security level of the PC5 establishment process.

[0011] In one possible implementation, at least one message further includes a third message, which is a message sent by the first terminal device during the PC5 establishment process to negotiate a security protection method to be used on the user plane of the PC5 connection between the first terminal device and the second terminal device; the first terminal device uses the first security protection method to perform security protection on at least one message during the PC5 establishment process, including: the first terminal device uses the first security protection method to perform security protection on the first message; and when the security level of the security protection method used on the control plane of the PC5 connection is lower than the security level of the first security protection method, the first terminal device uses the first security protection method to perform security protection on the third message. On the one hand, when the first security protection method includes integrity protection enabled, since the first terminal device can use the first security protection method to perform security protection on the first message during the PC5 establishment process between the first terminal device and the second terminal device, the problem of a reduced security level caused by the first message during the PC5 establishment process being attacked or tampered with by an attacker can be avoided, thereby improving the security level of the PC5 establishment process. On the other hand, when the security level of the security protection method used by the control plane of the PC5 connection is lower than the security level of the first security protection method, since the first terminal device can use the first security protection method to perform security protection on the third message in the PC5 establishment process between the first terminal device and the second terminal device, the problem of reduced security level caused by the security level of the security protection method used by the control plane of the PC5 connection being lower than the security level of the first security protection method can be avoided, thereby improving the security level of the PC5 establishment process.

[0012] In one possible implementation, the communication method may further include: the first terminal device receiving a second message from the second terminal device, the second message including a security algorithm for the control plane connected to PC5 selected by the second terminal device; and the first terminal device determining, based on the security algorithm for the control plane connected to PC5, that the security level of the security protection method used by the control plane connected to PC5 is lower than the security level of the first security protection method. Based on this solution, the first terminal device can learn that the security level of the security protection method used by the control plane connected to PC5 is lower than the security level of the first security protection method.

[0013] In one possible implementation, at least one message includes a fourth message, which is a message sent by the first terminal device during the PC5 establishment process to negotiate a security protection method to be used for the user plane of the PC5 connection between the first terminal device and the second terminal device; the first terminal device uses the first security protection method to perform security protection on at least one message during the PC5 establishment process, including: the first terminal device determines that the security level of the security protection method used by the control plane of the PC5 connection is lower than the security level of the first security protection method; and the first terminal device uses the first security protection method to perform security protection on the fourth message. In this solution, if the security level of the security protection method used by the control plane of the PC5 connection is lower than the security level of the first security protection method, since the first terminal device can use the first security protection method to perform security protection on the fourth message during the PC5 establishment process between the first terminal device and the second terminal device, the problem of a reduced security level caused by the security level of the security protection method used by the control plane of the PC5 connection being lower than the security level of the first security protection method can be avoided, thereby improving the security level of the PC5 establishment process.

[0014] In one possible implementation, the communication method provided by the embodiment of the present application further includes: the first terminal device determines a second security protection method based on the first security protection method, and the second security protection method is the security protection method for the PC5 connection between the first terminal device and the second terminal device. Since the embodiment of the present application can refer to the first security protection method determined in the discovery process when determining the second security protection method, the security level of the determined second security protection method can be made no lower than the security level of the first security protection method. In other words, the security level of the first security protection method is the lowest security level of the PC5 connection in the PC5 establishment process, so that the purpose of no security degradation can be achieved.

[0015] In combination with the first or second aspect above, in one possible implementation, the first terminal device determines the second security protection method based on the first security protection method, including: the first terminal device determines the first security protection method as the second security protection method. That is, in an embodiment of the present application, the first terminal device can directly activate the security of the PC5 connection between the first terminal device and the second terminal device based on the first security protection method. In this solution, since the first terminal device does not need to negotiate the second security protection method with the second terminal device, but directly determines the first security protection method as the second security protection method, it not only simplifies the processing logic of the first terminal device, but also saves the signaling overhead of the PC5 establishment process.

[0016] In conjunction with the first or second aspect above, in one possible implementation, a first terminal device determines a second security protection method based on a first security protection method, including: the first terminal device receives a second security policy from a second terminal device, where the second security policy is the security policy of the second terminal device in the connection with PC 5; and the first terminal device determines the second security protection method based on the second security policy and the first security protection method. In this solution, because the first terminal device also refers to the second security policy of the second terminal device when determining the second security protection method, the second security protection method determined by the first terminal device can be used by the second terminal device to the greatest extent possible.

[0017] In conjunction with the first or second aspect above, in one possible implementation, the first terminal device determines the second security protection method based on the second security policy and the first security protection method, including: determining the first security protection method as the second security protection method when the first security protection method satisfies the second security policy. Because this solution determines the first security protection method as the second security protection method when the first security protection method satisfies the second security policy, not only can the second security protection method determined by the first terminal device also be used by the second terminal device, but it also ensures that the security level of the first security protection method is the minimum security level of the PC5 connection in the PC5 establishment process, thereby achieving the goal of not degrading security.

[0018] In combination with the first or second aspect above, in one possible implementation, the first terminal device determines the second security protection method based on the second security policy and the first security protection method, including: when the first security protection method satisfies the second security policy, selecting a security protection method with a security level not lower than that of the first security protection method according to the second security policy as the first security protection method. Because this solution selects a security protection method with a security level not lower than that of the first security protection method according to the second security policy as the first security protection method when the first security protection method satisfies the second security policy, not only can the second security protection method determined by the first terminal device also be used by the second terminal device, but it also ensures that the security level of the first security protection method is the lowest security level for the PC5 connection in the PC5 establishment process, thereby achieving the goal of no security degradation.

[0019] In conjunction with the first or second aspect above, in one possible implementation, the first terminal device determines the second security protection method based on the second security policy and the first security protection method, including: if the first security protection method does not satisfy the second security policy, selecting a security protection method that satisfies the second security policy as the second security protection method based on the second security policy. Because this solution selects a security protection method that satisfies the second security policy as the second security protection method based on the second security policy when the first security protection method does not satisfy the second security policy, not only can the second security protection method determined by the first terminal device be used by the second terminal device, but it also ensures that the security level of the first security protection method is the lowest security level of the PC5 connection in the PC5 establishment process, thereby achieving the goal of no security degradation.

[0020] In conjunction with the first or second aspect above, in one possible implementation, the second security policy includes a second control plane security policy and / or a second user plane security policy; wherein the second control plane security policy is the control plane security policy of the second terminal device in the PC5 connection, and the second user plane security policy is the user plane security policy of the second terminal device in the PC5 connection. In this embodiment of the present application, the second control plane security policy can be used to determine the security protection method used by the control plane of the PC5 connection, and the second user plane security policy can be used to determine the security protection method used by the user plane of the PC5 connection.

[0021] In combination with the first aspect or the second aspect above, in one possible implementation, the second security protection method is used to perform security protection on some or all parameters transmitted in the control plane signaling of the PC5 connection; and / or, the second security protection method is used to perform security protection on some or all user plane data of the PC5 connection. In other words, the second security protection method in the embodiment of the present application includes the security protection method used by the control plane of the PC5 connection, and / or, the security protection method used by the user plane of the PC5 connection. Among them, the security protection method used by the control plane of the PC5 connection is used to perform security protection on some or all parameters transmitted in the control plane signaling of the PC5 connection, and the security protection method used by the user plane of the PC5 connection is used to perform security protection on some or all user plane data of the PC5 connection.

[0022] In combination with the first or second aspect above, in one possible implementation, the first terminal device obtains the first security protection method, including: the first terminal device sends first information and 3GPP identity information of the first terminal device to a first direct communication discovery name management function network element, where the first information includes identity information for a ProSe service or information used to determine identity information for a ProSe service; and the first terminal device receives the first security protection method from the first direct communication discovery name management function network element. Based on this solution, the first terminal device can obtain the first security protection method during the discovery process between the first terminal device and the second terminal device.

[0023] According to a third aspect, a communication method is provided, comprising: a first direct communication discovery name management function network element receives first information from a first terminal device and 3GPP identity information of the first terminal device, wherein the first information includes identity information for a ProSe service or information for determining identity information for a ProSe service; the first direct communication discovery name management function network element determines, based on the first information and the 3GPP identity information of the first terminal device, a security protection method required when the first terminal device uses the ProSe service; and the first direct communication discovery name management function network element sends, to the first terminal device, the security protection method required when the first terminal device uses the ProSe service. Based on the communication method provided in an embodiment of the present application, the first terminal device can obtain the security protection method required when the first terminal device uses the ProSe service in the discovery process between the first terminal device and the second terminal device.

[0024] In one possible implementation, the first direct communication discovery name management function network element determines the security protection method required by the first terminal device when using the ProSe service based on the first information and the 3GPP identity information of the first terminal device, including: the first direct communication discovery name management function network element determines a plurality of optional security protection methods corresponding to the first terminal device when using the ProSe service based on the first information and the 3GPP identity information of the first terminal device; the first direct communication discovery name management function network element determines the security protection method required by the first terminal device when using the ProSe service based on the plurality of optional security protection methods. That is, in the embodiment of the present application, the security protection method required by the first terminal device when using the ProSe service is determined from the plurality of optional security protection methods corresponding to the first terminal device when using the ProSe service.

[0025] In a possible implementation, the communication method provided by the embodiment of the present application also includes: the first direct communication discovery name management function network element obtains the security protection method required by the second terminal device when using the ProSe service from the second direct communication discovery name management function network element; the first direct communication discovery name management function network element determines the security protection method required by the first terminal device when using the ProSe service based on the multiple optional security protection methods, including: the first direct communication discovery name management function network element determines whether the multiple optional security protection methods include the security protection method required by the second terminal device when using the ProSe service; when the multiple optional security protection methods include the security protection method required by the second terminal device when using the ProSe service, the first direct communication discovery name management function network element determines the security protection method required by the second terminal device when using the ProSe service as the security protection method required by the first terminal device when using the ProSe service. Based on this solution, the first terminal device and the second terminal device can obtain the same security protection method in the discovery process between the first terminal device and the second terminal device.

[0026] In a possible implementation, the communication method provided by the embodiment of the present application also includes: the first direct communication discovery name management function network element obtains the security protection method required by the second terminal device when using the ProSe service from the second direct communication discovery name management function network element; the first direct communication discovery name management function network element determines the security protection method required by the first terminal device when using the ProSe service based on the multiple optional security protection methods, including: the first direct communication discovery name management function network element determines whether the multiple optional security protection methods include the security protection method required by the second terminal device when using the ProSe service; when the multiple optional security protection methods do not include the security protection method required by the second terminal device when using the ProSe service, the first direct communication discovery name management function network element determines the security protection method required by the first terminal device when using the ProSe service from the multiple optional security protection methods. Based on this solution, the first terminal device can obtain the security protection method required by the first terminal device when using the ProSe service in the discovery process between the first terminal device and the second terminal device.

[0027] In one possible implementation, the security protection method required for using the ProSe service is used to protect a fifth message, which is the first PC5 broadcast message in the discovery process between the first terminal device and the second terminal device. Based on this solution, security protection can be achieved for the fifth message, thereby preventing the fifth message from being attacked or tampered with by an attacker.

[0028] In one possible implementation, the security protection method required when using the ProSe service is used to determine the security protection method for the PC5 connection between the first terminal device and the second terminal device. Since the embodiment of the present application can refer to the security protection method determined in the discovery process when determining the security protection method for the PC5 connection between the first terminal device and the second terminal device, the security level of the security protection method for the PC5 connection determined between the first terminal device and the second terminal device can be made not lower than the security level of the security protection method determined in the discovery process. In other words, the security level of the security protection method determined in the discovery process is the lowest security level of the PC5 connection in the PC5 establishment process, so that the purpose of no security degradation can be achieved.

[0029] In one possible implementation, the security protection method for the PC5 connection is used to securely protect some or all of the parameters transmitted in the control plane signaling of the PC5 connection; and / or, the security protection method for the PC5 connection is used to securely protect some or all of the user plane data of the PC5 connection. In other words, in an embodiment of the present application, the security protection method for the PC5 connection includes the security protection method used by the control plane of the PC5 connection, and / or, the security protection method used by the user plane of the PC5 connection. Among them, the security protection method used by the control plane of the PC5 connection is used to securely protect some or all of the parameters transmitted in the control plane signaling of the PC5 connection, and the security protection method used by the user plane of the PC5 connection is used to securely protect some or all of the user plane data of the PC5 connection.

[0030] In one possible implementation, the security protection method required when using the ProSe service is used to securely protect at least one message in the PC5 establishment procedure between the first terminal device and the second terminal device. On one hand, when the security protection method required when using the ProSe service includes integrity protection enabled, since the security protection method required when using the ProSe service is used to securely protect at least one message in the PC5 establishment procedure between the first terminal device and the second terminal device, the problem of a security level being compromised due to attacks or tampering with messages in the PC5 establishment procedure can be avoided, thereby improving the security level of the PC5 establishment procedure. On the other hand, when the security level of the security protection method required when using the ProSe service is higher than or equal to the security level of the security protection method used by the control plane of the PC5 connection between the first terminal device and the second terminal device, since the security protection method required when using the ProSe service is used to securely protect at least one message in the PC5 establishment procedure between the first terminal device and the second terminal device, the problem of a security level being compromised due to the security level of the security protection method used by the control plane of the PC5 connection being lower than the security level of the security protection method required for using the ProSe service determined in the discovery process can be avoided, thereby improving the security level of the PC5 establishment procedure.

[0031] In one possible implementation, the at least one message includes a first message, which is the first message in the PC5 establishment process. That is, in this embodiment of the present application, the first message is protected using the first security protection method. Thus, if the first security protection method includes integrity protection enabled, the first terminal device can use the first security protection method to protect the first message. This prevents the security level of the first message in the PC5 establishment process from being compromised by an attacker or tampered with, thereby improving the security level of the PC5 establishment process.

[0032] In a fourth aspect, a communication device is provided for implementing the above method. The communication device can be the first terminal device in the above first aspect or second aspect, or a device including the above first terminal device; or, the communication device can be the first direct communication discovery name management function network element in the above third aspect, or a device including the above first direct communication discovery name management function network element. The communication device includes a module, unit, or means corresponding to the above method, and the module, unit, or means can be implemented by hardware, software, or by executing the corresponding software implementation by hardware. The hardware or software includes one or more modules or units corresponding to the above functions.

[0033] In a fifth aspect, a communication device is provided, comprising: a processor and a memory; the memory is configured to store computer instructions, and when the processor executes the instructions, the communication device performs the method described in any of the above aspects. The communication device may be the first terminal device described in the first or second aspect, or a device including the first terminal device; or the communication device may be the first direct communication discovery name management function network element described in the third aspect, or a device including the first direct communication discovery name management function network element.

[0034] In a sixth aspect, a communication device is provided, comprising: a processor; the processor being coupled to a memory and, after reading instructions from the memory, executing the method according to any of the above aspects in accordance with the instructions. The communication device may be the first terminal device described in the first or second aspect, or a device including the first terminal device; or the communication device may be the first direct communication discovery name management function network element described in the third aspect, or a device including the first direct communication discovery name management function network element.

[0035] In a seventh aspect, a communication device is provided, comprising: a processor and an interface circuit; the interface circuit is configured to receive a computer program or instruction and transmit it to the processor; the processor is configured to execute the computer program or instruction so that the communication device performs the method described in any of the above aspects. The communication device may be the first terminal device described in the first or second aspect, or a device including the first terminal device; or the communication device may be the first direct communication discovery name management function network element described in the third aspect, or a device including the first direct communication discovery name management function network element.

[0036] In an eighth aspect, a computer-readable storage medium is provided, wherein instructions are stored in the computer-readable storage medium. When the computer-readable storage medium is run on a computer, the computer can execute the method described in any one of the above aspects.

[0037] In a ninth aspect, a computer program product comprising instructions is provided, which, when executed on a computer, enables the computer to execute the method described in any one of the above aspects.

[0038] In a tenth aspect, a communication device (for example, the communication device may be a chip or a chip system) is provided, wherein the communication device includes a processor for implementing the functions involved in any of the above aspects. In one possible implementation, the communication device also includes a memory for storing necessary program instructions and data. When the communication device is a chip system, it can be composed of a chip or include a chip and other discrete devices.

[0039] Among them, the technical effects brought about by any possible implementation method in the fourth to tenth aspects can be referred to the technical effects brought about by different design methods in the above-mentioned first, second or third aspects, and will not be repeated here.

[0040] In the eleventh aspect, a communication system is provided, comprising a first terminal device and a second terminal device. The first terminal device is configured to obtain a first security protection method, which is a security protection method determined in a discovery process between the first and second terminal devices. The first terminal device is further configured to use the first security protection method to securely protect at least one message in a PC5 establishment process between the first and second terminal devices, and then send the at least one secured message to the second terminal device. The second terminal device is configured to receive the at least one secured message and de-secure the at least one message using the first security protection method. The technical effects of the eleventh aspect can be referenced to the second aspect above and will not be elaborated upon here.

[0041] In one possible implementation, the first terminal device or the second terminal device is further configured to determine a second security protection method based on the first security protection method, where the second security protection method is the security protection method for the PC5 connection between the first terminal device and the second terminal device. The technical effects of this solution can be referenced with respect to the first aspect described above and are not further elaborated here.

[0042] In a possible implementation, the communication system also includes a first direct communication discovery name management function network element and a second direct communication discovery name management function network element. The first terminal device is used to obtain the first security protection method, including: the first terminal device is used to receive the security protection method required by the first terminal device when using the ProSe service from the first direct communication discovery name management function network element. Similarly, the second terminal device is also used to receive the security protection method required by the second terminal device when using the ProSe service from the second direct communication discovery name management function network element. The security protection method required by the first terminal device when using the ProSe service and the security protection method required by the second terminal device when using the ProSe service are both the above-mentioned first security protection method. Based on this solution, the first terminal device or the second terminal device can obtain the security protection method required when using the ProSe service in the discovery process between the first terminal device and the second terminal device.

[0043] In the twelfth aspect, a communication system is provided, which includes a first direct communication discovery name management function network element and a second direct communication discovery name management function network element; wherein, the first direct communication discovery name management function network element is used to obtain the security protection method required by the second terminal device when using the ProSe service from the second direct communication discovery name management function network element; and the first direct communication discovery name management function network element is also used to determine a plurality of optional security protection methods corresponding to when the first terminal device uses the ProSe service, and after determining the security protection method required by the first terminal device when using the ProSe service based on the plurality of optional security protection methods and the security protection method required by the second terminal device when using the ProSe service, send the security protection method required by the first terminal device when using the ProSe service to the first terminal device. Among them, the technical effect of the twelfth aspect can refer to the above-mentioned third aspect and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] Figure 1a A schematic diagram of the structure of a communication system provided in an embodiment of the present application;

[0045] Figure 1b A schematic diagram of the structure of a communication system provided in an embodiment of the present application;

[0046] Figure 2 A schematic diagram of a ProSe control plane architecture in a 5G network provided in an embodiment of the present application;

[0047] Figure 3 A schematic diagram of the structure of a communication device provided in an embodiment of the present application;

[0048] Figure 4 An interactive diagram of a communication method provided in an embodiment of the present application;

[0049] Figure 5 An interactive diagram of another communication method provided in an embodiment of the present application;

[0050] Figure 6 An interactive diagram of another communication method provided in an embodiment of the present application;

[0051] Figure 7 An interactive diagram of another communication method provided in an embodiment of the present application;

[0052] Figure 8 A flow chart of a communication method provided in an embodiment of the present application;

[0053] Figure 9 A flowchart of another communication method provided in an embodiment of the present application;

[0054] Figure 10 A flow chart of another communication method provided in an embodiment of the present application;

[0055] Figure 11 A schematic diagram of the structure of a communication device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0056] In order to facilitate understanding of the technical solutions of the embodiments of the present application, a brief introduction to the relevant technologies of the present application is first given as follows.

[0057] First, the discovery type:

[0058] In the embodiment of the present application, the discovery type includes open discovery or restricted discovery. The relevant description of open discovery and restricted discovery can refer to the existing third generation partnership project (3GPP) technical standards (TS) 23.303, v15.1.0, which will not be repeated here. For example, if a terminal device plays a game by itself and has no clear gaming partner, it can initiate an open discovery and "randomly" find a gaming partner. If the terminal device has a clear partner for playing the game, it can "designate" a partner through restricted discovery, and only the partner it designates can access the game, and others cannot. Therefore, open discovery is like a shake application, which can be shaken at will to another user who has opened the shake application. Restricted discovery is like creating a group face to face, and only users who know the group number can access it.

[0059] Second, discovery mode:

[0060] The existing 4G ProSe standard (3GPP TS 23.303, v15.1.0) defines Mode A (Model A) and Mode B (Model B). The difference between Model A and Model B lies in the different ways of initiating discovery. Model A means "I am here." In the Model A discovery process, the terminal devices at both ends are divided into the announcing user equipment (UE) (announcing UE) and the monitoring UE (monitoring UE). The announcing UE broadcasts "I am here". After receiving the message broadcast by the announcing UE, the monitoring UE determines whether to establish a connection for neighboring services with the announcing UE based on whether it meets its own service requirements. Model B means "Who's there? / Where are you?" In the Model B discovery process, the terminal devices at both ends are divided into discoveree UE and discoverer UE. The discoverer UE initiates a specific service request, which includes specific information, asking "Who's there? / Where are you?" After receiving the service request initiated by the discoverer UE, the discoveree UE determines whether to reply to the request message based on whether it can provide the service. If it replies with a response message, it means "I'm here." Among them, the embodiments of this application are described by taking the open discovery scenario applicable to model A discovery model and the restricted discovery scenario applicable to model A and model B discovery models as examples. They are described uniformly here and will not be repeated below.

[0061] Third, the discovery command:

[0062] In this embodiment of the present application, the discovery command is used to inform the network side whether the two terminal devices communicating with each other are announcing UEs or monitoring UEs; whether they are responding terminal devices (response UEs) or requesting terminal devices (query UEs). Among them, the announcing UE and the monitoring UE are the terminal devices at the two ends in the above-mentioned Model A discovery process, and the response UE and the query UE correspond to the discoveree UE and the discoverer UE in the above-mentioned Model B discovery process, respectively. They are described here uniformly and will not be repeated below.

[0063] Fourth, user identity information for ProSe services:

[0064] The identity information used for the ProSe service may be, for example, an application-level user identity. For example, the identity information used for the ProSe service may be a proximity service application identifier (ProSe application ID), a restricted proximity service application user identifier (restricted ProSe application user ID, RPAUID), or a proximity discovery UE identifier (ProSe discovery UE ID, PDUID). In this embodiment of the present application, the ProSe application ID is used for an open discovery scenario, and the PDUID or RPAUID is used for a restricted discovery scenario as an example for explanation. The unified explanation is given here and will not be repeated below.

[0065] Fifth, PC5 connection and PC5 connection establishment process:

[0066] The PC5 connection in the embodiment of the present application refers to a communication connection between terminal devices based on the PC5 interface.

[0067] The PC5 connection establishment process in the embodiment of the present application is used to establish a communication connection between at least two terminal devices that support the PC5 interface. Among them, after the PC5 connection is established, at least two terminal devices can use the PC5 connection to perform control plane signaling negotiation and / or user plane data transmission. The PC5 connection establishment process in the embodiment of the present application may include a PC5 unicast connection establishment (one-to-one communication) process and a PC5 multicast connection establishment (one-to-manycommunication) process. The PC5 unicast connection establishment process is used to establish a communication connection between two terminal devices that support the PC5 interface, and the PC5 multicast connection establishment process is used to establish a communication connection between more than two terminal devices that support the PC5 interface. The following embodiments of the present application are all illustrative and are explained by taking the establishment of a communication connection between two terminal devices as an example, that is, the following embodiments of the present application are all illustrative and are explained by taking the PC5 unicast connection establishment process as an example. The method for establishing a communication connection between any two terminal devices in the PC5 multicast connection establishment process can refer to the process for establishing a communication connection between two terminal devices in the PC5 unicast connection establishment process, which is explained uniformly here and will not be repeated below.

[0068] Sixth, security strategy:

[0069] A security policy is a policy used to describe whether to enable security protection and can be used to determine the security protection method. In the embodiments of the present application, the security policies used in different scenarios include at least one of the following:

[0070] Control plane confidentiality protection policy in PC5 connections;

[0071] Control plane integrity protection strategy in PC5 connections;

[0072] User plane confidentiality protection policy in PC5 connections;

[0073] Alternatively, the user plane integrity protection policy in the PC5 connection.

[0074] Among them, control plane confidentiality protection is to protect the confidentiality of signaling during transmission; control plane integrity protection is to protect the integrity of signaling during transmission; user plane confidentiality protection is to protect the confidentiality of user plane data during transmission; user plane integrity protection is to protect the integrity of user plane data during transmission. In the embodiment of the present application, integrity means that the acquired signaling or data is consistent with the original signaling or data and has not been modified. Therefore, integrity protection is to prevent attackers from "attacking". Confidentiality means that the real content cannot be directly seen, so confidentiality protection is to prevent attackers from "not being able to read". In addition, confidentiality protection in the embodiment of the present application can also be called encryption protection, which is uniformly explained here and will not be repeated below.

[0075] In the embodiment of the present application, the control plane confidentiality protection policy in the PC5 connection and the control plane integrity protection policy in the PC5 connection belong to the control plane security policy in the PC5 connection; the user plane confidentiality protection policy in the PC5 connection and the user plane integrity protection policy in the PC5 connection belong to the user plane security policy in the PC5 connection, which are uniformly explained here and will not be repeated below.

[0076] In the embodiments of this application, the protection policies are divided into three categories: REQUIRED, NOT NEEDED, and PREFERRED. REQUIRED means security is required, NOT NEEDED means security is not required, and PREFERRED means it is preferred or optional, meaning security can be enabled or not. These are described here and will not be further elaborated below.

[0077] For example, taking the control plane confidentiality protection policy in a PC5 connection as an example, the control plane confidentiality protection policy in the PC5 connection includes: control plane confidentiality protection in the PC5 connection is enabled (REQUIRED), control plane confidentiality protection in the PC5 connection is not enabled (NOT NEEDED), or control plane confidentiality protection in the PC5 connection is optional (PREFERRED). For examples of the control plane confidentiality protection policy in the PC5 connection, the user plane confidentiality protection policy in the PC5 connection, or the user plane integrity protection policy in the PC5 connection, refer to the example of the control plane confidentiality protection policy in the PC5 connection and are not further described here.

[0078] It should be noted that in the embodiments of the present application, when a security policy is sent, generally only one of the three types (REQUIRED, NOT NEEDED, and PREFERRED) is selected for transmission. In some special scenarios, at least two types may be selected, and one of them is PREFERRED. For example, when NOT NEEDED and PREFERRED are sent, it indicates that security protection is not enabled; when REQUIRED and PREFERRED are sent, it indicates that security protection is enabled.

[0079] It should be noted that in the embodiment of the present application, the control plane confidentiality protection policy in the PC5 connection, the control plane integrity protection policy in the PC5 connection, and the user plane confidentiality protection policy in the PC5 connection; or, multiple protection policies in the user plane integrity protection policy in the PC5 connection can be the same, and the embodiment of the present application does not make specific limitations on this.

[0080] Seventh, security capabilities:

[0081] The security capabilities in the embodiments of the present application include at least one of the following:

[0082] One or more control plane confidentiality protection algorithms supported in the PC5 connection;

[0083] One or more control plane integrity protection algorithms supported in the PC5 connection;

[0084] One or more user plane confidentiality protection algorithms supported in PC5 connections;

[0085] Alternatively, one or more user plane integrity protection algorithms supported in the PC5 connection.

[0086] Among them, the control plane confidentiality protection algorithm refers to a confidentiality protection algorithm used to protect the control plane. The control plane integrity protection algorithm refers to an integrity protection algorithm used to protect the control plane. The user plane confidentiality protection algorithm refers to a confidentiality protection algorithm used to protect the user plane. The user plane integrity protection algorithm refers to a user plane protection algorithm used to protect the control plane. Among them, one or more control plane confidentiality protection algorithms supported in the PC5 connection and one or more control plane integrity protection algorithms supported in the PC5 connection belong to the control plane security capability in the PC5 connection; one or more user plane confidentiality protection algorithms supported in the PC5 connection and one or more user plane integrity protection algorithms supported in the PC5 connection belong to the user plane security capability in the PC5 connection. They are explained here uniformly and will not be repeated below.

[0087] It should be noted that in the embodiment of the present application, one or more control plane confidentiality protection algorithms supported in the PC5 connection, one or more control plane integrity protection algorithms supported in the PC5 connection, one or more user plane confidentiality protection algorithms supported in the PC5 connection, or multiple protection algorithms in the one or more user plane integrity protection algorithms supported in the PC5 connection may be the same or have common items, and the embodiment of the present application does not make specific limitations on this.

[0088] Eighth, security protection and de-security protection:

[0089] Security protection in the embodiments of the present application refers to protecting user plane data / control plane signaling using a security protection method; de-security protection in the embodiments of the present application refers to restoring user plane data / control plane signaling according to the security protection method. The security protection method herein includes whether confidentiality protection and / or integrity protection are enabled, which are described here uniformly and will not be further elaborated below.

[0090] Specifically, when confidentiality protection is enabled, encryption keys and encryption algorithms can be used to encrypt and protect user plane data / control plane signaling; when integrity protection is enabled, integrity protection keys and integrity protection algorithms can be used to protect the integrity of user plane data / control plane signaling. In addition, it should be noted that when encryption protection and integrity protection are required for user plane data / control plane signaling, encryption protection can be performed on the user plane data / control plane signaling first, and then integrity protection can be performed; or integrity protection can be performed on the user plane data / control plane signaling first, and then encryption protection can be performed. The embodiments of this application do not limit the execution order of encryption protection and integrity protection, and they are described uniformly here and will not be repeated below.

[0091] Specifically, when confidentiality protection is enabled, the encryption key and encryption algorithm can be used to decrypt the user plane data / control plane signaling; when integrity protection is enabled, the integrity protection key and integrity protection algorithm can be used to perform integrity protection verification on the user plane data / control plane signaling. In addition, it is understood that when both encryption protection and integrity protection are performed on the user plane data / control plane signaling, if the user plane data / control plane signaling is first encrypted and then integrity protected, the order of decrypting the confidentiality protection is to first perform integrity protection verification and then decrypt the encrypted user plane data / control plane signaling; if the user plane data / control plane signaling is first integrity protected and then encrypted, the order of decrypting the confidentiality protection is to first decrypt the encrypted user plane data / control plane signaling and then perform integrity protection verification. This is explained here uniformly and will not be repeated below.

[0092] For example, the security protection methods in the embodiments of the present application are divided into the following three categories:

[0093] 1. The security protection method used by the first PC5 broadcast message in the ProSe discovery process is used to protect all or some of the parameters transmitted in the first PC5 broadcast message in the ProSe discovery process. The security protection method used by the first PC5 broadcast message may, for example, include whether confidentiality protection and / or integrity protection are enabled for the first PC5 broadcast message. For example, "00" may indicate that confidentiality protection is disabled and integrity protection is disabled; "01" may indicate that confidentiality protection is disabled and integrity protection is enabled; "10" may indicate that confidentiality protection is enabled and integrity protection is disabled; and "11" may indicate that confidentiality protection is enabled and integrity protection is enabled. It should be noted that this example uses the high bit to represent confidentiality protection and the low bit to represent integrity protection as an example. Of course, the low bit may also represent confidentiality protection and the high bit may represent integrity protection, and this is not specifically limited in this embodiment of the present application. Furthermore, this example uses "0" to represent disabled and "1" to represent enabled as an example. Of course, "1" may also represent disabled and "0" to represent enabled, and this is not specifically limited in this embodiment of the present application.

[0094] In the embodiments of the present application, the first PC5 broadcast message corresponding to different discovery modes is different. For example, in the model A discovery mode, the first PC5 broadcast message is sent by the announcing UE and may be an announcing message. In the model B discovery mode, the first PC5 broadcast message is sent by the discoverer UE and may be a Send Query Code message. This is explained here uniformly and will not be repeated below.

[0095] 2. The security protection method used by the control plane of the PC5 connection is used to protect all or some parameters transmitted in the control plane signaling of the PC5 connection. The security protection method used by the control plane of the PC5 connection may, for example, include whether confidentiality protection and / or integrity protection of the control plane of the PC5 connection is enabled. For related examples, refer to the example of the security protection method used in the first PC5 broadcast message and will not be repeated here.

[0096] 3. The security protection method used by the user plane of the PC5 connection is used to protect some or all user plane data of the PC5 connection. The security protection method used by the user plane of the PC5 connection may, for example, include whether confidentiality protection and / or integrity protection of the user plane of the PC5 connection is enabled. For related examples, refer to the example of the security protection method used in the first PC5 broadcast message and will not be repeated here.

[0097] It should be noted that, in the embodiment of the present application, the security protection method used by the control plane of the PC5 connection can also be referred to as the security protection method used by the control plane signaling of the PC5 connection; the security protection method used by the user plane of the PC5 connection can also be referred to as the security protection method used by the user plane data of the PC5 connection. These are uniformly explained here and will not be repeated below.

[0098] Ninth, MIC and expected MIC:

[0099] Take terminal device 1 sending message 1 to terminal device 2 as an example:

[0100] The MIC in the embodiment of the present application is a parameter generated after integrity protection is performed on all or part of the parameters transmitted in the message 1 sent by the terminal device 1 using the integrity protection key of the terminal device 1, and is included in the message 1. The expected MIC in the embodiment of the present application is a parameter generated by using the integrity protection key of the terminal device 2 (the same as the integrity protection key of the terminal device 1) to perform integrity verification on all or part of the parameters transmitted in the message 1 received by the terminal device 2, and is used to compare with the MIC in the message 1 received by the terminal device 2, and then verify whether the message 1 received by the terminal device 2 has been tampered with. Among them, the relevant examples of MIC and expected MIC will be elaborated in detail in conjunction with the subsequent method embodiments and will not be repeated here.

[0101] It should be noted that, in the embodiment of the present application, the integrity protection key of the terminal device 1 can be understood as a key for performing integrity protection on the message 1 sent by the terminal device 1, and can be used by the device that generates the MIC. Among them, the device that generates the MIC may, for example, include the terminal device 1 or other devices (such as the direct communication discovery name management function network element corresponding to the terminal device 1), and the embodiment of the present application does not make specific limitations on this. Of course, when the terminal device 1 acts as a device for receiving messages, taking the example of the terminal device 1 receiving the message 2 from the terminal device 2, the integrity protection key of the terminal device 1 can be understood as a key for performing integrity verification on the message 2 received by the terminal device 1, and can be used by the device that generates the expected MIC. Among them, the device that generates the expected MIC may, for example, include the terminal device 1 or other devices (such as the direct communication discovery name management function network element corresponding to the terminal device 1), and the embodiment of the present application does not make specific limitations on this.

[0102] It should be noted that, in the embodiment of the present application, the integrity protection key of the terminal device 2 can be understood as a key for performing integrity verification on the message 1 received by the terminal device 2, and can be used by the device that generates the expected MIC. Among them, the device that generates the expected MIC may, for example, include the terminal device 2 or other devices (such as the direct communication discovery name management function network element corresponding to the terminal device 2), and the embodiment of the present application does not make specific limitations on this. Of course, when the terminal device 2 acts as a device for sending messages, taking the example of the terminal device 2 sending message 2 to the terminal device 1, the integrity protection key of the terminal device 2 can be understood as a key for performing integrity protection on the message 2 sent by the terminal device 2, and can be used by the device that generates the MIC. Among them, the device that generates the MIC may, for example, include the terminal device 2 or other devices (such as the direct communication discovery name management function network element corresponding to the terminal device 2), and the embodiment of the present application does not make specific limitations on this.

[0103] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application. Among them, in the description of the present application, unless otherwise specified, " / " indicates that the objects associated before and after are in an "or" relationship. For example, A / B can represent A or B; "and / or" in the present application is only a description of the association relationship of the associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. In addition, in the description of the present application, unless otherwise specified, "multiple" refers to two or more than two. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can represent: a, b, c, ab, ac, bc, or abc, where a, b, c can be single or multiple. In addition, in order to facilitate the clear description of the technical solutions of the embodiments of the present application, in the embodiments of the present application, words such as "first" and "second" are used to distinguish between identical or similar items with substantially the same functions and effects. Those skilled in the art will understand that words such as "first" and "second" do not limit the quantity and execution order, and words such as "first" and "second" do not necessarily limit differences. At the same time, in the embodiments of the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or explanations. Any embodiment or design described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as being more preferred or more advantageous than other embodiments or design schemes. Specifically, the use of words such as "exemplary" or "for example" is intended to present related concepts in a concrete way for easy understanding.

[0104] In addition, the network architecture and business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. Ordinary technicians in this field can know that with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.

[0105] Taking the V2X PC5 establishment process between UE1 and UE2 as an example, in the existing V2X PC5 establishment process (for details, please refer to 3GPP TS 23.303), the first message, the direct communication request, needs to carry UE1's control plane security policy (signaling security policy) in the PC5 connection to assist UE2 in negotiating the control plane security policy of the PC5 connection. This message has no security protection. In this way, when the security policies configured by UE1 and UE2 themselves are both optional (PREFERRED), an intermediary attacker can tamper with the signaling security policy in the direct communication request to not enabled (NOT NEEDED) after receiving the direct communication request sent by UE1. UE2 then discovers that UE1 requires that security protection be disabled for the control plane of the PC5 connection, so it determines that the control plane security protection method for the PC5 connection is to disable security protection for the control plane, and sends a direct security mode command (direct security mode command) to UE1. Since the control plane does not have security protection enabled, the attacker can then tamper with the signaling security policy in the direct connection security mode command back to the content sent by UE1 in the direct connection communication request. The control plane security of the subsequent PC5 connection will be forcibly disabled due to the interference of the intermediate attacker. In the PC5 establishment process, the control plane security policies of UE1 and UE2 are both optional (PREFERRED) and can be enabled without tampering by the intermediate attacker. The attacker forcibly shuts down the control plane security protection between UE1 and UE2 in the above manner, which will cause the security level to be downgraded. In the subsequent negotiation of the user plane security policy for the PC5 connection, the attacker will also be further attacked due to the lack of control plane security protection.

[0106] To solve this problem, the present application provides a communication system 10. Figure 1aAs shown, the communication system 10 includes a first terminal device 101 with a ProSe application function and a second terminal device 102 with a ProSe application function. The first terminal device 101 obtains a first security protection method, which is a security protection method determined in the discovery process between the first terminal device 101 and the second terminal device 102. Furthermore, the first terminal device 101 uses the first security protection method to securely protect at least one message in the PC5 establishment process between the first terminal device 101 and the second terminal device 102, and then sends the at least one secured message to the second terminal device 102. The specific implementation of this solution will be described in detail in subsequent method embodiments and will not be repeated here. Based on the communication system provided in the embodiment of the present application, on the one hand, when the first security protection method includes integrity protection being enabled, since the first terminal device can use the first security protection method to securely protect at least one message in the PC5 establishment process between the first terminal device and the second terminal device, the problem of reduced security level caused by attacks or tampering of messages in the PC5 establishment process by attackers can be avoided, thereby improving the security level of the PC5 establishment process. On the other hand, when the security level of the first security protection method is higher than or equal to the security level of the security protection method used by the control plane of the PC5 connection between the first terminal device and the second terminal device, since the first terminal device can use the first security protection method to perform security protection on at least one message in the PC5 establishment process between the first terminal device and the second terminal device, the problem of reduced security level caused by the security level of the security protection method used by the control plane of the PC5 connection being lower than the security level of the first security protection method can be avoided, thereby improving the security level of the PC5 establishment process.

[0107] Optionally, in an embodiment of the present application, the first terminal device 101 or the second terminal device 102 may further determine a second security protection method based on the first security protection method, where the second security protection method is the security protection method for the PC5 connection between the first terminal device 101 and the second terminal device 102. Since the embodiment of the present application can refer to the first security protection method determined in the discovery process when determining the second security protection method, the security level of the determined second security protection method can be made no lower than the security level of the first security protection method. In other words, the security level of the first security protection method is the lowest security level of the PC5 connection in the PC5 establishment process, thereby achieving the goal of no security degradation.

[0108] Optional, such as Figure 1aAs shown, the communication system 10 may further include a first direct communication discovery name management function network element 103 and a second direct communication discovery name management function network element 104. The first terminal device 101 obtains the first security protection method, including: the first terminal device 101 receives the security protection method required by the first terminal device 101 when using the ProSe service from the first direct communication discovery name management function network element 103. Similarly, the second terminal device 102 may receive the security protection method required by the second terminal device 102 when using the ProSe service from the second direct communication discovery name management function network element 104. The security protection method required by the first terminal device 101 when using the ProSe service and the security protection method required by the second terminal device 102 when using the ProSe service are both the above-mentioned first security protection method. Based on this solution, the first terminal device or the second terminal device can obtain the security protection method required when using the ProSe service in the discovery process between the first terminal device and the second terminal device.

[0109] like Figure 1b As shown, another communication system 20 provided in an embodiment of the present application is shown. The communication system 20 includes a first direct communication discovery name management function network element 201 and a second direct communication discovery name management function network element 202. The first direct communication discovery name management function network element 201 and the second direct communication discovery name management function network element 202 can communicate directly with each other or through forwarding by other devices, which is not specifically limited in this embodiment of the present application.

[0110] Among them, the first direct communication discovery name management function network element 201 obtains the security protection method required by the second terminal device when using the ProSe service from the second direct communication discovery name management function network element 202; and the first direct communication discovery name management function network element 201 determines the multiple optional security protection methods corresponding to the first terminal device when using the ProSe service. Furthermore, after the first direct communication discovery name management function network element 201 determines the security protection method required by the first terminal device when using the ProSe service based on the multiple optional security protection methods and the security protection method required by the second terminal device when using the ProSe service, it sends the security protection method required by the first terminal device when using the ProSe service to the first terminal device. The specific implementation of this solution will be described in detail in the subsequent method embodiments and will not be repeated here. Based on the communication system provided in the embodiment of the present application, the first terminal device can obtain the security protection method required by the first terminal device when using the ProSe service in the discovery process between the first terminal device and the second terminal device.

[0111] Optional, Figure 1a The communication system 10 shown or Figure 1bThe communication system 20 shown can be applicable to the 5G network currently under discussion, and can also be applicable to other networks in the future, etc., and the embodiments of the present application do not make specific limitations on this.

[0112] For example, Figure 1a The communication system 10 shown or Figure 1b The communication system 20 shown is applicable to the 5G network currently under discussion as an example, then the direct communication discovery name management function network element in the embodiment of the present application (including Figure 1b The network element or entity corresponding to the first direct communication discovery name management function network element 201 and the second direct communication discovery name management function network element 202 in the 5G network can be a direct communication discovery name management function (DDNMF) network element in the 5G network. The terminal device (including Figure 1a The network element or entity corresponding to the first terminal device 101 and the second terminal device 102) can be a terminal device with ProSe application function in the 5G network.

[0113] like Figure 2 As shown, a schematic diagram of a ProSe control plane architecture in a 5G network provided by an embodiment of the present application includes one or more terminal devices ( Figure 2 Taking terminal device 1, terminal device 2, terminal device 3 and terminal device 4 as an example), next generation radio access network (NG-RAN) equipment, unified data storage (UDR) network element, unified data management (UDM) network element, session management function (SMF) network element, access and mobility management function (AMF) network element, network exposure function (NEF) network element, policy control function (PCF) network element, user plane function (UPF) network element, 5G DDNMF network element and data network (DN).

[0114] Among them, compared with traditional cellular network communications, terminal devices that can be used for Prose communications need to have proximity service application (ProSe application) functions, and terminal devices with ProSe application functions communicate with each other through PC5 ports. Corresponding to the ProSe application is the ProSe application server. The ProSe application server can be an application function (AF) network element in the DN. The AF with the ProSe application server function has all the functions of the AF defined in version 23.501R-15, as well as related functions for Prose services. That is to say, in the ProSe control plane architecture in the 5G network, the ProSe application server and the terminal device communicate with the user plane through the path of terminal device-NG-RAN device-UPF network element-AF network element. In addition, the ProSe application server can also communicate with other network functions (NF) in the 5G core network (5G core network, 5GC) through NEF, such as communicating with the PCF network element through the NEF network element.

[0115] In this embodiment of the present application, the DDNMF network element allocates and processes the mapping between the ProSe application ID and the code used for ProSe discovery for open ProSe direct discovery. In restricted ProSe direct discovery, the DDNMF network element communicates with the ProSe application server via the PC2 interface to process the authorization of the discovery request.

[0116] In addition, the relevant descriptions of AMF network elements, UDR network elements, SMF network elements, UPF network elements, UDM network elements, NEF network elements or PCF network elements can refer to the existing 3GPP 5G standards and will not be repeated here.

[0117] Optionally, the terminal device in the embodiments of the present application may be a device for implementing wireless communication functions, such as a terminal or a chip that can be used in a terminal, etc., which can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; it can also be deployed on the water surface (such as a ship, etc.); it can also be deployed in the air (such as an airplane, a balloon, and a satellite, etc.). Among them, the terminal can be a UE, an access terminal, a terminal unit, a terminal station, a mobile station, a mobile station, a remote station, a remote terminal, a mobile device, a wireless communication device, a terminal agent, or a terminal device in a 5G network or a future evolved public land mobile network (PLMN). An access terminal may be a cellular phone, a cordless phone, a Session Initiation Protocol (SIP) phone, a wireless local loop (WLL) station, a personal digital assistant (PDA), a handheld device with wireless communication capabilities, a computing device or other processing device connected to a wireless modem, an in-vehicle device or wearable device, an unmanned aerial vehicle (UAV) and a UAV controller (UAVC), a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical care, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, a wireless terminal in a smart home, etc. The terminal may be mobile or fixed.

[0118] Optionally, the RAN device in the embodiment of the present application is a device that provides wireless communication functions for terminal devices. Access network equipment includes, for example, but is not limited to: next-generation base stations (gnodeB, gNB) in 5G, evolved node B (eNB), radio network controller (RNC), node B (NB), base station controller (BSC), base transceiver station (BTS), home base station (for example, home evolved nodeB, or home node B, HNB), baseband unit (BBU), transmission point (TRP), transmitting point (TP), mobile switching center, etc.

[0119] Optionally, the first terminal device, the second terminal device, the first direct communication discovery name management function network element and the second direct communication discovery name management function network element in the embodiment of the present application can also be referred to as communication devices, which can be a general device or a special device. The embodiment of the present application does not make specific limitations on this.

[0120] Optionally, the related functions of the first terminal device, the second terminal device, the first direct communication discovery name management function network element and the second direct communication discovery name management function network element in the embodiment of the present application can be implemented by one device, or can be implemented by multiple devices together, or can be implemented by one or more functional modules within a device, and the embodiment of the present application does not make specific limitations on this. It can be understood that the above functions can be network elements in hardware devices, software functions running on dedicated hardware, or a combination of hardware and software, or virtualization functions instantiated on a platform (for example, a cloud platform).

[0121] For example, the first terminal device, the second terminal device, the first direct communication discovery name management function network element and the second direct communication discovery name management function network element in the embodiment of the present application can be Figure 3 This is achieved by the communication device 300 in FIG. Figure 3 FIG2 is a schematic diagram of the structure of a communication device 300 provided in an embodiment of the present application. The communication device 300 includes one or more processors 301, a communication line 302, and at least one communication interface ( Figure 3 The example in which the communication interface 304 and a processor 301 are included is merely exemplary, and a memory 303 may be optionally included.

[0122] The processor 301 may be a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits for controlling the execution of the program of the present application.

[0123] The communication line 302 may include a path for connecting different components.

[0124] The communication interface 304 can be a transceiver module for communicating with other devices or communication networks, such as Ethernet, RAN, and wireless local area networks (WLAN). For example, the transceiver module can be a device such as a transceiver or a transceiver. Alternatively, the communication interface 304 can be a transceiver circuit located within the processor 301, which is used to implement signal input and output to the processor.

[0125] The memory 303 may be a device having a storage function. For example, it may be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory may exist independently and be connected to the processor via the communication line 302. The memory may also be integrated with the processor.

[0126] The memory 303 is used to store computer-executable instructions for executing the solution of the present application, and the execution is controlled by the processor 301. The processor 301 is used to execute the computer-executable instructions stored in the memory 303, thereby implementing the communication method provided in the embodiment of the present application.

[0127] Alternatively, optionally, in an embodiment of the present application, the processor 301 may also perform processing-related functions in the communication method provided in the following embodiments of the present application, and the communication interface 304 is responsible for communicating with other devices or communication networks, which is not specifically limited in the embodiments of the present application.

[0128] Optionally, the computer-executable instructions in the embodiments of the present application may also be referred to as application code, which is not specifically limited in the embodiments of the present application.

[0129] In a specific implementation, as an embodiment, the processor 301 may include one or more CPUs, such as Figure 3 CPU0 and CPU1 in.

[0130] In a specific implementation, as an embodiment, the communication device 300 may include multiple processors, such as Figure 3 301 and processor 308 in the embodiment. Each of these processors can be a single-core processor or a multi-core processor. The processors herein can include, but are not limited to, at least one of the following: a central processing unit (CPU), a microprocessor, a digital signal processor (DSP), a microcontroller unit (MCU), or an artificial intelligence processor, and other types of computing devices that run software. Each computing device may include one or more cores for executing software instructions to perform calculations or processing.

[0131] In a specific implementation, as an embodiment, the communication device 300 may further include an output device 305 and an input device 306. The output device 305 communicates with the processor 301 and can display information in a variety of ways. For example, the output device 305 can be a liquid crystal display (LCD), a light emitting diode (LED) display device, a cathode ray tube (CRT) display device, or a projector. The input device 306 communicates with the processor 301 and can receive user input in a variety of ways. For example, the input device 306 can be a mouse, a keyboard, a touch screen device, or a sensor device.

[0132] The communication device 300 may also be referred to as a communication apparatus, which may be a general purpose device or a dedicated device. For example, the communication device 300 may be a desktop computer, a portable computer, a network server, a personal digital assistant (PDA), a mobile phone, a tablet computer, a wireless terminal device, an embedded device, the terminal device, the network device, or a Figure 3 The embodiment of the present application does not limit the type of the communication device 300.

[0133] The communication method provided in the embodiments of the present application will be exemplarily described below with reference to the accompanying drawings.

[0134] It should be noted that the message names between network elements or the names of parameters in the messages in the following embodiments of the present application are only examples, and other names may be used in specific implementations. The embodiments of the present application do not specifically limit this.

[0135] It should be noted that, in the embodiment of the present application, "security protection of the message" can be understood as security protection of all or part of the parameters transmitted in the message. This is explained uniformly here and will not be repeated below.

[0136] An embodiment of the present application provides a communication method that uses the security protection method determined in the ProSe discovery process to protect one or more messages in the PC5 establishment process, thereby improving the security level of the PC5 establishment process. Optionally, the embodiment of the present application can determine the security protection method used by the control plane of the PC5 connection and / or the security protection method used by the user plane of the PC5 connection based on the security protection method determined in the ProSe discovery process, wherein the security level of the security protection method used by the control plane of the PC5 connection and / or the security protection method used by the user plane of the PC5 connection is not lower than the security protection method determined in the ProSe discovery process. In other words, the security protection method determined in the ProSe discovery process is the minimum security requirement for the PC5 connection in the PC5 establishment process. In this way, the purpose of not degrading security can be achieved.

[0137] The communication method will be described in detail below with reference to several examples.

[0138] In one possible implementation, taking the interaction between UE1 and UE2 as an example, an embodiment of the present application provides a communication method, which uses the security protection method determined in the ProSe discovery process to perform integrity protection on one or more messages in the PC5 establishment process between UE1 and UE2. At the same time, in the PC5 establishment process, the security protection method used by the control plane of the PC5 connection between UE1 and UE2 (for convenience, the PC5 connection between UE1 and UE2 will be referred to as the PC5 connection) and the security protection method used by the user plane of the first PC5 connection are negotiated. For example, Figure 4 As shown, the communication method provided in the embodiment of the present application includes the following steps:

[0139] S401, UE1 determines that the first security protection method includes integrity protection on. The first security protection method is the security protection method obtained in the ProSe discovery process between UE1 and UE2. The embodiment of the present application does not limit the method for determining the security protection method in the ProSe discovery process. In a possible implementation method, the method for determining the security protection method in the ProSe discovery process can be referred to in the subsequent Figure 7 The embodiment shown.

[0140] Exemplarily, the UE1 in the embodiment of the present application may be an announcing UE in a model A discovery mode, or the UE1 may be a discoverer UE in a model B discovery mode.

[0141] Optionally, the first security protection method in the embodiment of the present application can be used to protect the first PC5 broadcast message in the ProSe discovery process between UE1 and UE2. The description of the first PC5 broadcast message and the security protection method can be found in the preamble of the specific implementation method and will not be repeated here.

[0142] Optionally, the first security protection method in the embodiment of the present application may also include enabling confidentiality protection, which is not specifically limited in the embodiment of the present application.

[0143] S402: UE1 sends a direct communication request to UE2. In response, UE2 receives the direct communication request from UE1. The direct communication request includes UE1's control plane security policy for the PC5 connection, UE1's control plane security capabilities for the PC5 connection, and MIC1. For a description of the control plane security policy and control plane security capabilities for the PC5 connection, please refer to the preface of the specific implementation method and will not be repeated here.

[0144] Of course, in the embodiment of the present application, the direct communication request may also include part or all of the discovery parameters of UE1. For the description of the discovery parameters, please refer to Figure 7 Table 1, Table 2, Table 3 or Table 4 in the illustrated embodiment will not be described in detail here.

[0145] In the embodiment of the present application, all or part of the parameters transmitted in the direct communication request are protected using the first security protection method. For example, the first security protection method can be used to protect at least one of the control plane security policy of UE1 in the PC5 connection or the control plane security capability of UE1 in the PC5 connection.

[0146] In the embodiment of the present application, MIC1 is a parameter generated by integrity-protecting all or part of the parameters transmitted in the direct communication request using the integrity protection key of UE1. The integrity protection key of UE1 may be generated by UE1 or issued by the network, and this embodiment of the present application does not specifically limit this.

[0147] Optionally, in an embodiment of the present application, the control plane security policy of UE1 in the PC5 connection and / or the control plane security capability of UE1 in the PC5 connection can be used as input parameters for generating MIC1. In one possible implementation, MIC1 = KDF (parameter one, parameter two, other parameters). Among them, parameter one can be the control plane security policy in the PC5 connection, parameter two can be the control plane security capability in the PC5 connection, and the key derivation function (KDF) is a function for calculating MIC1. Exemplarily, KDF can be a hash function. Exemplarily, other parameters can include the integrity protection key of UE1.

[0148] Optionally, in the embodiment of the present application, MIC1 may be generated by UE1 itself, or it may be generated by the DDNMF network element corresponding to UE1 (which may be referred to as DDNMF1 network element), and the embodiment of the present application does not specifically limit this. Among them, if MIC1 is generated by the DDNMF1 network element, then before UE1 sends a direct communication request to UE2, UE1 receives MIC1 from the DDNMF1 network element. Optionally, if the input parameters for generating MIC1 include the control plane security policy of UE1 in the PC5 connection and / or the control plane security capability of UE1 in the PC5 connection, then in a possible implementation method, the control plane security policy of UE1 in the PC5 connection and / or the control plane security capability of UE1 in the PC5 connection required by the DDNMF1 network element to generate MIC1 are sent by UE1 to the DDNMF1 network element.

[0149] S403. UE2 verifies MIC1.

[0150] In the embodiment of the present application, the process of verifying MIC1 is the process of comparing the MIC1 in the received direct communication request with the expected MIC of MIC1. Among them, the expected MIC of MIC1 is a parameter generated by using the integrity protection key of UE2 (the same as the integrity protection key of UE1) to perform integrity verification on all or part of the parameters transmitted in the direct communication request received by UE2, which is used to compare with the MIC1 in the direct communication request received by UE2, and then verify whether the direct communication request received by UE2 has been tampered with. Specifically, when the expected MIC of MIC1 is the same as the MIC1 in the direct communication request received by UE2, it can be determined that the MIC1 verification has passed, that is, UE2 can determine that the received direct communication request has not been tampered with; or, when the expected MIC of MIC1 is different from the MIC1 in the direct communication request received by UE2, it can be determined that the MIC1 verification has failed, that is, UE2 can determine that the received direct communication request has been tampered with. Among them, the formula for generating the expected MIC of MIC1 is the same as the formula for generating MIC1. For details, please refer to the formula for generating MIC1, which will not be repeated here.

[0151] Optionally, in the embodiment of the present application, UE2 can verify MIC1 by itself, or verify MIC1 through a match report process, which is not specifically limited in the embodiment of the present application. The match report can refer to the existing 3GPP TS 33.303 standard, which is not described in detail in the embodiment of the present application.

[0152] In one possible implementation, if UE2 can verify MIC1 by itself, then UE2 generates the expected MIC of MIC1 based on the integrity protection key of UE2 (the same as the integrity protection key of UE1). Optionally, the integrity protection key of UE2 may be obtained by UE2 from the network side, for example, UE2 obtains it from the DDNMF network element corresponding to UE1 (which may be referred to as DDNMF1 network element) in the discovery parameter acquisition process. Or, optionally, the integrity protection key of UE2 may be generated by UE2 based on the generation material of the integrity protection key issued by the network side. The embodiment of the present application does not specifically limit the generation material of the integrity protection key. Exemplarily, the generation material of the integrity protection key may include a root key, and may also include other key generation parameters, etc., which are uniformly explained here and will not be repeated below.

[0153] In another possible implementation, if UE2 wants to verify MIC1 through the match report process, the DDNMF network element corresponding to UE2 (which may be referred to as DDNMF2 network element) may generate the expected MIC of MIC1 based on the integrity protection key of UE2 (the same as the integrity protection key of UE1). Optionally, the integrity protection key of UE2 may be obtained by the DDNMF2 network element from the network side, or may be generated by the DDNMF2 network element based on the generation material of the integrity protection key issued by the network side. This embodiment of the present application does not specifically limit this. Optionally, if the input parameters for generating the expected MIC of MIC1 include the control plane security policy of UE1 in the PC5 connection and / or the control plane security capability of UE1 in the PC5 connection, then in a possible implementation, the control plane security policy of UE1 in the PC5 connection and / or the control plane security capability of UE1 in the PC5 connection required for the DDNMF2 network element to generate the expected MIC of MIC1 are sent by UE2 to the DDNMF2 network element. Furthermore, in this solution, the DDNMF2 network element can send UE2's integrity protection key to UE2 during the match report process; or the DDNMF2 network element can send the integrity protection key generation material to UE2 during the match report process, and UE2 generates UE2's integrity protection key based on the integrity protection key generation material. After obtaining UE2's integrity protection key, UE2 saves UE2's integrity protection key for subsequent use.

[0154] In another possible implementation, if UE2 wants to verify MIC1 through the match report process, the DDNMF network element corresponding to UE1 (which may be referred to as DDNMF1 network element) may generate the expected MIC of MIC1 based on the integrity protection key of UE2 (the same as the integrity protection key of UE1). Optionally, the integrity protection key of UE2 may be obtained by the DDNMF1 network element from the network side, or may be generated by the DDNMF1 network element based on the generation material of the integrity protection key issued by the network side. This embodiment of the present application does not specifically limit this. Optionally, if the input parameters for generating the expected MIC of MIC1 include the control plane security policy of UE1 in the PC5 connection and / or the control plane security capability of UE1 in the PC5 connection, then in a possible implementation, the control plane security policy of UE1 in the PC5 connection and / or the control plane security capability of UE1 in the PC5 connection required for the DDNMF1 network element to generate the expected MIC of MIC1 are sent by UE2 to the DDNMF1 network element through the DDNMF2 network element. Furthermore, in this solution, the DDNMF1 network element can send UE2's integrity protection key to UE2 through the DDNMF2 network element in the match report process, or the DDNMF1 network element can send the integrity protection key generation material to UE2 through the DDNMF2 network element in the match report process, and UE2 generates UE2's integrity protection key based on the integrity protection key generation material. After obtaining UE2's integrity protection key, UE2 saves UE1's integrity protection key for subsequent use.

[0155] In the embodiment of the present application, if the MIC1 verification is successful, it can be said that all or part of the parameters transmitted in the direct communication request in step S402 are protected intact and have not been attacked by external attackers, and then the following step S404 can be continued.

[0156] In step S404, UE2 determines a security protection method for the control plane of the PC5 connection between UE1 and UE2 based on the control plane security policy of UE1 in the PC5 connection and the control plane security policy of UE2 in the PC5 connection. Furthermore, UE2 determines a security algorithm for the control plane of the PC5 connection between UE1 and UE2 based on the control plane security capability of UE1 in the PC5 connection and the control plane security capability of UE2 in the PC5 connection. The implementation of step S404 can refer to existing technologies and is not described in detail here. A description of the security protection method for the control plane of the PC5 connection can be found in the preamble of the specific implementation method and is not described in detail here.

[0157] In the embodiment of the present application, the security algorithms used by the control plane connected to PC5 include one or more confidentiality protection algorithms and one or more integrity protection algorithms.

[0158] In the embodiments of this application, the selection of security algorithms follows the following principles:

[0159] First, when the control plane integrity protection is not enabled, the corresponding selected integrity and confidentiality protection algorithms are both null algorithms.

[0160] Second, when the control plane integrity protection is turned on, the corresponding selected control plane integrity protection algorithm needs to be a non-null algorithm (non-null) to indicate that the control plane integrity protection is turned on; if the control plane confidentiality protection is turned on at this time, the corresponding selected control plane confidentiality protection algorithm needs to be a non-null algorithm (non-null) to indicate that the control plane confidentiality protection is turned on; if the control plane confidentiality protection is not turned on at this time, the corresponding selected control plane confidentiality protection algorithm needs to be a null algorithm (null) to indicate that the control plane confidentiality protection is not turned on.

[0161] S405: UE2 sends a direct security mode command to UE1. Correspondingly, UE1 receives the direct security mode command from UE2. The direct security mode command includes the security algorithm selected by UE2 for the control plane of the PC5 connection.

[0162] Optionally, in an embodiment of the present application, the direct connection security mode command may further include the control plane security policy of UE1 in the PC5 connection and / or the control plane security capability of UE1 in the PC5 connection. Furthermore, after UE1 receives the direct connection security mode command from UE2, when UE1 determines that the security protection method used by the control plane of the final PC5 connection includes that the control plane integrity protection is not enabled, UE1 needs to determine whether the control plane security policy in the PC5 connection included in the direct connection security mode command is the control plane security policy in the PC5 connection sent by itself, and whether the security capability in the PC5 connection is the security capability in the PC5 connection sent by itself. If the verification is successful, the subsequent process can be continued, otherwise the current process is terminated. This can prevent a bidding down attack.

[0163] In one possible implementation, in an embodiment of the present application, if UE2 determines that the security protection method used by the control plane of the PC5 connection between UE1 and UE2 includes integrity protection being enabled, then the embodiment of the present application can use the security algorithm used by the control plane of the PC5 connection selected by UE2 to perform integrity protection on all or part of the parameters passed in the direct connection security mode command. The specific integrity protection method can refer to the existing technology and will not be repeated here.

[0164] In another possible implementation, in an embodiment of the present application, if UE2 determines that the security level of the security protection method used by the control plane of the PC5 connection between UE1 and UE2 is lower than the security level of the first security protection method (for example, the security protection method used by the control plane of the PC5 connection between UE1 and UE2 includes integrity protection not being enabled, and the first security protection method includes integrity protection being enabled), then the direct connection security mode command in the embodiment of the present application also includes MIC2. MIC2 is a parameter generated after integrity protection is performed on all or part of the parameters passed in the direct connection security mode command using the integrity protection key of UE2. Exemplarily, the partial parameters that are integrity protected using the integrity protection key of UE2 may, for example, include at least one of the security algorithm used by the control plane of the PC5 connection selected by UE2 (the selected null algorithm), the control plane security policy of UE1 in the PC5 connection, and the control plane security capability of UE1 in the PC5 connection. In the case where UE2 determines that the security level of the security protection method used in the control plane of the PC5 connection between UE1 and UE2 is lower than the security level of the first security protection method, since this solution can use UE2's integrity protection key to perform integrity protection on all or part of the parameters passed in the direct security mode command, it can ensure that the information in the direct security mode command can be trusted by UE1. Furthermore, after UE1 receives the direct security mode command from UE2, it also needs to verify MIC2. The way UE1 verifies MIC2 is similar to the way UE2 verifies MIC1 mentioned above, and will not be repeated here. If the MIC2 verification is successful, it can be said that all or part of the parameters passed in the direct security mode command are protected intact and have not been attacked by external attackers, and then the following step S406 can be continued.

[0165] Optionally, in the embodiment of the present application, the integrity protection key of UE2 may be generated by UE2 or issued by the network side, and the embodiment of the present application does not make any specific limitation on this.

[0166] It should be noted that, in the embodiment of the present application, the integrity protection key used by each generated MIC or expected MIC is the same. For example, the integrity protection key used to generate MIC2 is the same as the integrity protection key used to generate MIC1 or the expected MIC of MIC1. The integrity protection key used to generate MIC3, the expected MIC of MIC3, MIC4, or the expected MIC of MIC4 is also the same as the integrity protection key used to generate MIC1 or the expected MIC of MIC1. This is explained uniformly here and will not be repeated below.

[0167] S406 : UE1 determines a final security protection method used by the control plane of the PC5 connection according to the security algorithm used by the control plane of the PC5 connection selected by UE2.

[0168] Optionally, in the embodiment of the present application, UE1 determines the final security protection method used by the control plane of the PC5 connection according to the security algorithm used by the control plane of the PC5 connection selected by UE2, including:

[0169] If the integrity protection algorithm in the control plane security algorithm used for a PC5 connection is null, the final security protection method used for the control plane of the PC5 connection is: neither integrity protection nor confidentiality protection is enabled for the control plane of the PC5 connection. In other words, subsequent control plane signaling in the PC5 connection does not require integrity protection or confidentiality protection.

[0170] If the integrity protection algorithm in the control plane security algorithm for a PC5 connection is non-null, and the confidentiality protection algorithm in the control plane security algorithm for the PC5 connection is non-null, the final control plane security method used for the PC5 connection is: integrity protection is enabled for the PC5 connection, and confidentiality is enabled for the control plane. In other words, all subsequent control plane signaling in the PC5 connection requires both integrity and confidentiality protection.

[0171] If the integrity protection algorithm in the control plane security algorithm for a PC5 connection is non-null and the confidentiality protection algorithm in the control plane security algorithm for the PC5 connection is null, the final control plane security method for the PC5 connection is: integrity protection is enabled for the PC5 connection, but confidentiality is disabled. In other words, subsequent control plane signaling in the PC5 connection requires integrity protection, but not confidentiality protection.

[0172] It should be noted that, in the embodiment of the present application, the security protection method used by the control plane of the PC5 connection determined by UE1 can be used to protect the messages of the security protection method used by the user plane of the PC5 connection subsequently negotiated between UE1 and UE2, such as the security protection of the direct connection security mode completion message in step S407 and the security protection of the direct connection communication acceptance message in step S409. In addition, the security protection method used by the control plane of the PC5 connection determined by UE1 can also be used to Figure 4 The security protection of the control plane signaling after the PC5 establishment process shown is explained here uniformly and will not be repeated below.

[0173] S407: UE1 sends a direct security mode complete message to UE2. Correspondingly, UE2 receives the direct security mode complete message from UE1, wherein the direct security mode complete message includes the user plane security policy of UE1 in the connection with PC5.

[0174] Optionally, in the embodiment of the present application, when the user plane security capability in the PC5 connection is different from the control plane security capability in the PC5 connection, the direct connection security mode completion message may also include the user plane security capability of UE1 in the PC5 connection.

[0175] It should be noted that in the embodiment of the present application, assuming that the standard stipulates that the user plane security capabilities of UE1 in the PC5 connection are the same as the control plane security capabilities of UE1 in the PC5 connection, or that the security capabilities do not distinguish between the user plane and the control plane, then the direct connection security mode completion message does not need to carry the user plane security capabilities of UE1 in the PC5 connection. In this scenario, the user plane security capabilities of UE1 in the PC5 connection described below are the control plane security capabilities of UE1 in the PC5 connection (which can also be referred to as the security capabilities of UE1 in the PC5 connection), which are uniformly explained here and will not be repeated below.

[0176] Among them, the relevant descriptions of the user plane security policy in the PC5 connection and the user plane security capability in the PC5 connection can be referred to the preamble of the specific implementation method, which will not be repeated here.

[0177] In one possible implementation, in an embodiment of the present application, if UE1 determines that the security protection method used by the control plane of the final PC5 connection includes integrity protection enabled, then the embodiment of the present application can use the security algorithm used by the control plane of the PC5 connection selected by UE2 to perform integrity protection on all or part of the parameters transmitted in the direct connection security mode completion message. The specific integrity protection method can refer to the existing technology and will not be repeated here.

[0178] In another possible implementation, in an embodiment of the present application, if UE1 determines that the security level of the security protection method used by the control plane of the final PC5 connection is lower than the security level of the first security protection method (for example, the security protection method used by the control plane of the final PC5 connection includes integrity protection disabled, while the first security protection method includes integrity protection enabled), then the direct connection security mode complete message in this embodiment of the present application also includes MIC3. MIC3 is a parameter generated by integrity-protecting all or part of the parameters transmitted in the direct connection security mode complete message using UE1's integrity protection key. Exemplarily, the partial parameters integrity-protected using UE1's integrity protection key may include, for example, UE1's user plane security policy in the PC5 connection and UE1's user plane security capabilities in the PC5 connection (optional). If UE1 determines that the security level of the security protection method used by the control plane of the final PC5 connection is lower than the security level of the first security protection method, since this solution can use UE1's integrity protection key to integrity-protect all or part of the parameters transmitted in the direct connection security mode complete message, it can ensure that the information in the direct connection security mode complete message can be trusted by UE2. Furthermore, after receiving the Direct Connection Security Mode Complete message from UE1, UE2 needs to verify MIC3. The method for UE2 to verify MIC3 is similar to the method for UE2 to verify MIC1 described above and will not be repeated here. If MIC3 verification is successful, it indicates that all or part of the parameters transmitted in the Direct Connection Security Mode Complete message are intact and have not been compromised by external attackers. The process then proceeds to step S408.

[0179] Optionally, in the embodiment of the present application, the user plane security policy of UE1 in the PC5 connection and the user plane security capability of UE1 in the PC5 connection (optional) can be used as input parameters for generating MIC3. Specifically, the calculation method of MIC3 can refer to the calculation method of MIC1 above and will not be repeated here.

[0180] Optionally, in the embodiment of the present application, MIC3 may be generated by UE1 itself, or it may be generated by the DDNMF network element corresponding to UE1 (which may be referred to as DDNMF1 network element), and the embodiment of the present application does not specifically limit this. Among them, if MIC3 is generated by the DDNMF1 network element, then before UE1 sends the direct connection security mode completion message to UE2, UE1 receives MIC3 from the DDNMF1 network element. Optionally, if the input parameters for generating MIC1 include the user plane security policy of UE1 in the PC5 connection and the user plane security capability of UE1 in the PC5 connection (optional), then in a possible implementation method, the user plane security policy of UE1 in the PC5 connection and the user plane security capability of UE1 in the PC5 connection (optional) required for the DDNMF1 network element to generate MIC3 are sent by UE1 to the DDNMF1 network element.

[0181] Optionally, in an embodiment of the present application, if UE1 determines that the security protection method used by the control plane of the final PC5 connection includes confidentiality protection being enabled, then all or part of the parameters transmitted in the direct connection security mode completion message also need to be protected for confidentiality. The specific protection method can be referred to the existing technology and will not be elaborated here.

[0182] S408: UE2 determines a security protection method for the user plane of the PC5 connection between UE1 and UE2 based on the user plane security policy of UE1 in the PC5 connection and the user plane security policy of UE2 in the PC5 connection. The specific implementation of step S408 can be referenced in the prior art and is not described in detail here. A description of the security protection method for the user plane of the PC5 connection can be found in the preamble of the specific implementation method and is not described in detail here.

[0183] Optionally, in an embodiment of the present application, if the security algorithm used by the control plane of the PC5 connection is different from the security algorithm used by the user plane of the PC5 connection, UE2 also needs to determine the security algorithm used by the user plane of the PC5 connection between UE1 and UE2 based on the user plane security capabilities of UE1 in the PC5 connection and the user plane security capabilities of UE2 in the PC5 connection. This embodiment of the present application does not specifically limit this. The security algorithm used by the user plane of the PC5 connection includes one or more confidentiality protection algorithms and one or more integrity protection algorithms. The principles followed in selecting the security algorithm can be referred to in step S404 and will not be repeated here.

[0184] S409: UE2 sends a direct communication accept message to UE1. Correspondingly, UE1 receives the direct communication accept message from UE2. The direct communication accept message includes the security protection method used by the user plane connected to PC5.

[0185] Optionally, in an embodiment of the present application, the direct communication acceptance message may also include the user plane security policy of UE1 in the PC5 connection and the user plane security capability of UE1 in the PC5 connection (optional). Furthermore, after UE1 receives the direct communication acceptance message from UE2, when UE1 determines that the security protection method used by the control plane of the final PC5 connection includes that the control plane integrity protection is not enabled, UE1 needs to determine whether the user plane security policy in the PC5 connection included in the direct communication acceptance message is the user plane security policy in the PC5 connection sent by itself, and whether the security capability in the PC5 connection is the security capability in the PC5 connection sent by itself. If the verification is passed, the subsequent process can be continued, otherwise the current process is terminated. This can prevent degradation attacks.

[0186] Optionally, in the embodiment of the present application, if UE2 determines the security algorithm used by the user plane connected to PC5, the direct communication acceptance message also includes the security algorithm used by the user plane connected to PC5.

[0187] In one possible implementation, in an embodiment of the present application, if UE2 determines in step S404 that the security protection method used by the control plane of the PC5 connection includes control plane integrity protection, then the embodiment of the present application can use the security algorithm used by the control plane of the PC5 connection selected by UE2 to perform integrity protection on all or part of the parameters transmitted in the direct communication acceptance message. The specific integrity protection method can refer to the existing technology and will not be repeated here.

[0188] In another possible implementation, in an embodiment of the present application, if the direct connection security mode completion message in step S407 includes MIC3, then the direct connection communication acceptance message in step S409 also includes MIC4. MIC4 is a parameter generated by integrity-protecting all or part of the parameters transmitted in the direct connection communication acceptance message using UE2's integrity protection key. Exemplarily, the partial parameters integrity-protected using UE2's integrity protection key may include, for example, the security protection method used by the user plane of the PC5 connection and the security algorithm used by the user plane of the PC5 connection (optional). If the security level of the security protection method used by the control plane of the PC5 connection between UE1 and UE2 is lower than the security level of the first security protection method (for example, the security protection method used by the control plane of the PC5 connection between UE1 and UE2 includes integrity protection disabled, while the first security protection method includes integrity protection enabled), since this solution can use UE2's integrity protection key to integrity-protect all or part of the parameters transmitted in the direct connection communication acceptance message, it can ensure that the information in the direct connection communication acceptance message can be trusted by UE1. Furthermore, after receiving the direct connection communication acceptance message from UE2, UE1 needs to verify MIC4. If MIC4 verification is successful, it means that all or part of the parameters transmitted in the direct communication acceptance message are intact and not attacked by external attackers, and the subsequent process can be continued.

[0189] Based on the communication method provided in the embodiment of the present application, since UE1 determines that the first security protection method includes integrity protection being turned on, in the PC5 establishment process between UE1 and UE2, UE1 and UE2 can use the first security protection method to perform integrity protection on the messages in the PC5 establishment process. Therefore, the problem of reduced security level caused by the messages in the PC5 establishment process being attacked or tampered with by attackers can be avoided, thereby improving the security level of the PC5 establishment process.

[0190] The actions of UE1 or UE2 in the above steps S401 to S409 can be Figure 3 The processor 301 in the communication device 300 shown calls the application code stored in the memory 303 to instruct the UE1 or UE2 to execute, and this embodiment does not impose any limitation on this.

[0191] In another possible implementation, taking the interaction between UE1 and UE2 as an example, an embodiment of the present application provides a communication method, which uses the security protection method determined in the ProSe discovery process to perform security protection on one or more messages in the PC5 establishment process between UE1 and UE2. At the same time, in the PC5 establishment process, the security protection method used by the control plane of the PC5 connection between UE1 and UE2 (for convenience, the PC5 connection between UE1 and UE2 will be referred to as the PC5 connection) and the security protection method used by the user plane of the PC5 connection are determined according to the security protection method determined in the ProSe discovery process. For example, Figure 5 As shown, the communication method provided in the embodiment of the present application includes the following steps:

[0192] S501: UE1 sends a direct communication request to UE2. In response, UE2 receives the direct communication request from UE1. The direct communication request includes UE1's control plane security capabilities for the PC5 connection. For a description of the control plane security capabilities for the PC5 connection, refer to the preamble of the specific implementation method and are not repeated here.

[0193] Of course, in the embodiment of the present application, the direct communication request may also include part or all of the discovery parameters of UE1. For details, please refer to the existing 3GPP TS23.303, v15.1.0 standard, which will not be repeated here.

[0194] Optionally, in an embodiment of the present application, all or part of the parameters transmitted in the direct communication request are protected by the first security protection method. For example, the first security protection method can be used to protect the control plane security capability of UE1 in the PC5 connection. The first security protection method is the security protection method obtained in the ProSe discovery process between UE1 and UE2. The embodiment of the present application does not limit the method for determining the security protection method in the ProSe discovery process. In a possible implementation method, the method for determining the security protection method in the ProSe discovery process can be referred to in the subsequent Figure 7 The embodiment shown.

[0195] Optionally, in an embodiment of the present application, the direct communication request may further include a control plane security policy for UE1 in the PC5 connection. The control plane security policy for UE1 in the PC5 connection may be used to subsequently determine a security protection method to be used for the control plane of the PC5 connection between UE1 and UE2. The control plane security policy for UE1 in the PC5 connection may employ the first security protection method for security protection. For a description of the control plane security policy in the PC5 connection, please refer to the preamble of the specific implementation method and will not be repeated here.

[0196] Optionally, in the embodiment of the present application, when UE1 determines that the first security protection method includes integrity protection on, the direct communication request may further include MIC1. The relevant description of MIC1 may refer to Figure 4 The embodiment shown is not described here in detail. Further, after UE2 receives the direct communication request from UE1, it can verify MIC1. The verification method of MIC1 can refer to Figure 4 If the MIC1 verification is successful, it can be said that all or part of the parameters transmitted in the direct communication request in step S501 are protected intact and not attacked by external attackers, and then the following step S502 can be executed.

[0197] S502. UE2 determines the security protection method used by the control plane of the PC5 connection based on the first security protection method; and UE2 determines the security algorithm used by the control plane of the PC5 connection between UE1 and UE2 based on the control plane security capability of UE1 in the PC5 connection and the control plane security capability of UE2 in the PC5 connection.

[0198] Two specific implementations of the security protection method used by UE2 to determine the control plane connected to PC5 are given below.

[0199] In one possible implementation, UE2 can directly determine the first security protection method as the security protection method used by the control plane of the PC5 connection, that is, UE2 directly activates the control plane security of the PC5 connection according to the first security protection method. For example, if the first security protection method is confidentiality protection enabled, UE2 determines to activate control plane confidentiality protection; if the first security protection method is confidentiality protection disabled, UE2 determines not to activate control plane confidentiality protection; if the first security protection method is integrity protection enabled, UE2 determines to activate control plane control integrity protection; if the first security protection method is integrity protection disabled, UE2 determines not to activate control plane integrity protection. In this solution, since UE2 does not need to negotiate with UE1 on the security protection method used by the control plane of the PC5 connection, but directly determines the first security protection method as the security protection method used by the control plane of the PC5 connection, this not only simplifies UE2's processing logic, but also saves signaling overhead in the PC5 establishment process.

[0200] In another possible implementation, when determining the security protection method used by the control plane of the PC5 connection, UE2 also refers to the control plane security policy of UE1 in the PC5 connection.

[0201] Among them, when the first security protection method satisfies the control plane security policy of UE1 in the PC5 connection sent by UE1 in the direct communication request (it can also be understood that the first security protection method can be supported by the control plane security policy of UE1 in the PC5 connection sent by UE1 in the direct communication request), UE2 can determine the first security protection method as the security protection method used by the control plane of the PC5 connection, that is, UE2 activates the control plane security of the PC5 connection according to the first security protection method. For example, if the first security protection method is confidentiality protection is not enabled and integrity protection is enabled, and the control plane security policy of UE1 in the PC5 connection is confidentiality protection optional and integrity protection optional, then UE2 can determine that the security protection method used by the control plane of the PC5 connection is confidentiality protection is not enabled and integrity protection is enabled. Since this solution determines the first security protection method as the security protection method used by the control plane of the PC5 connection when the first security protection method meets the control plane security policy of UE1 in the PC5 connection, it not only ensures that the security protection method used by the control plane of the PC5 connection determined by UE2 can be supported by UE1, but also ensures that the security level of the first security protection method is the lowest security level of the PC5 connection in the PC5 establishment process, thereby achieving the purpose of no security degradation.

[0202] In the case where the first security protection method does not satisfy the control plane security policy of UE1 in the PC5 connection sent by UE1 in the direct communication request (it can also be understood that the first security protection method cannot be supported by the control plane security policy of UE1 in the PC5 connection sent by UE1 in the direct communication request), UE2 can select a security protection method that satisfies the control plane security policy of UE1 in the PC5 connection sent by UE1 in the direct communication request as the security protection method used by the control plane of the PC5 connection, so that UE2 activates the control plane security of the PC5 connection according to the selected security protection method. For example, if the first security protection method is confidentiality protection not enabled and integrity protection enabled, and the control plane security policy of UE1 in the PC5 connection is confidentiality protection enabled and integrity protection is optional, then UE2 can determine that the security protection method used by the control plane of the PC5 connection is confidentiality protection enabled and integrity protection enabled. Of course, in the embodiment of the present application, in the case where the first security protection method does not satisfy the control plane security policy of UE1 in the PC5 connection sent by UE1 in the direct communication request, UE2 can also refuse UE1 to join, and the embodiment of the present application does not make specific limitations on this. Because in this solution, when the first security protection method does not meet the control plane security policy of UE1 in the PC5 connection, UE2 selects a security protection method that meets the control plane security policy of UE1 in the PC5 connection as the security protection method used for the control plane of the PC5 connection based on the control plane security policy of UE1 in the PC5 connection. Therefore, not only can the security protection method used for the control plane of the PC5 connection determined by UE2 be supported by UE1, but it also ensures that the security level of the first security protection method is the lowest security level of the PC5 connection in the PC5 establishment process, thereby achieving the purpose of no security degradation.

[0203] When the first security protection method satisfies the control plane security policy of UE1 in the PC5 connection sent by UE1 in the direct communication request (it can also be understood that the first security protection method can be supported by the control plane security policy of UE1 in the PC5 connection sent by UE1 in the direct communication request), UE2 can also select a security protection method with a security level not lower than the first security protection method as the security protection method used for the control plane of the PC5 connection based on the control plane security policy of UE1 in the PC5 connection sent by UE1 in the direct communication request, so that UE2 activates the control plane security of the PC5 connection according to the selected security protection method. For example, if the first security protection method is confidentiality protection not enabled and integrity protection not enabled, and the control plane security policy of UE1 in the PC5 connection is confidentiality protection optional and integrity protection optional, then UE2 can determine that the security protection method used for the control plane of the PC5 connection is confidentiality protection enabled and integrity protection enabled. Since in this solution, when the first security protection method satisfies the control plane security policy of UE1 in the PC5 connection, UE2 selects a security protection method with a security level not lower than the first security protection method as the security protection method used for the control plane of the PC5 connection based on the control plane security policy of UE1 in the PC5 connection. Therefore, not only can the security protection method used for the control plane of the PC5 connection determined by UE2 also be used by UE1, but it also ensures that the security level of the first security protection method is the lowest security level of the PC5 connection in the PC5 establishment process, thereby achieving the purpose of no security degradation.

[0204] In another possible implementation, when determining the security protection method used for the control plane of the PC5 connection, UE2 also refers to the control plane security policy of UE1 in the PC5 connection and the control plane security policy of UE2 in the PC5 connection.

[0205] In which case, if the first security protection method can simultaneously satisfy the control plane security policy of UE1 in the PC5 connection sent by UE1 in the direct communication request and the control plane security policy of UE2 in the PC5 connection stored locally by UE2 or obtained from other network elements (it can also be understood that the first security protection method can be simultaneously supported by the control plane security policy of UE1 in the PC5 connection sent by UE1 in the direct communication request and the control plane security policy of UE2 in the PC5 connection stored locally by UE2 or obtained from other network elements), UE2 can determine the first security protection method as the security protection method used by the control plane of the PC5 connection, that is, UE2 activates control plane security of the PC5 connection according to the first security protection method. For example, if the first security protection method is confidentiality protection disabled and integrity protection enabled, and the control plane security policy of UE1 in the PC5 connection is confidentiality protection optional and integrity protection optional, and the control plane security policy of UE2 in the PC5 connection is confidentiality disabled and integrity protection optional, then UE2 can determine that the security protection method used by the control plane of the PC5 connection is confidentiality protection disabled and integrity protection enabled. Since this solution determines the first security protection method as the security protection method used by the control plane of the PC5 connection when the first security protection method can simultaneously meet the control plane security policy of UE1 in the PC5 connection and the control plane security policy of UE2 in the PC5 connection, it can not only ensure that the security protection method used by the control plane of the PC5 connection determined by UE2 can be supported by both UE1 and UE2, but also ensure that the security level of the first security protection method is the lowest security level of the PC5 connection in the PC5 establishment process, so as to achieve the purpose of no security degradation.

[0206] When the first security protection method does not satisfy the control plane security policy of UE1 in the PC5 connection sent by UE1 in the direct communication request or the control plane security policy of UE2 in the PC5 connection stored locally by UE2 or obtained from other network elements (it can also be understood that the first security protection method cannot be supported by both the control plane security policy of UE1 in the PC5 connection sent by UE1 in the direct communication request and the control plane security policy of UE2 in the PC5 connection stored locally by UE2 or obtained from other network elements), UE2 can select a security protection method that satisfies the control plane security policy of UE1 in the PC5 connection sent by UE1 in the direct communication request and satisfies the control plane security policy of UE2 in the PC5 connection stored locally by UE2 or obtained from other network elements as the security protection method used for the control plane of the PC5 connection, so that UE2 activates the control plane security of the PC5 connection according to the selected security protection method. For example, if the first security protection method is confidentiality protection not enabled and integrity protection enabled, and the control plane security policy of UE1 in the PC5 connection is confidentiality protection enabled and integrity protection optional, and the control plane security policy of UE2 in the PC5 connection is confidentiality protection enabled and integrity protection optional, then UE2 can determine that the security protection method used by the control plane of the PC5 connection is confidentiality protection enabled and integrity protection enabled. Of course, in the embodiment of the present application, if the first security protection method does not satisfy the control plane security policy of UE1 in the PC5 connection sent by UE1 in the direct communication request or the control plane security policy of UE2 in the PC5 connection stored locally by UE2 or obtained from other network elements, UE2 can also reject UE1's joining. The embodiment of the present application does not specifically limit this. Since this solution selects a security protection method that satisfies both the control plane security policy of UE1 in the PC5 connection and the control plane security policy of UE2 in the PC5 connection as the security protection method used for the control plane of the PC5 connection when the first security protection method does not satisfy the control plane security policy of UE1 in the PC5 connection or the control plane security policy of UE2 in the PC5 connection, based on the control plane security policy of UE1 in the PC5 connection and the control plane security policy of UE2 in the PC5 connection. Therefore, not only can the security protection method used for the control plane of the PC5 connection determined by UE2 be supported by both UE1 and UE2 at the same time, but it also ensures that the security level of the first security protection method is the lowest security level of the PC5 connection in the PC5 establishment process, thereby achieving the purpose of no security degradation.

[0207] When the first security protection method can simultaneously satisfy the control plane security policy of UE1 in the PC5 connection sent by UE1 in the direct communication request and the control plane security policy of UE2 in the PC5 connection stored locally by UE2 or obtained from other network elements (it can also be understood that the first security protection method can be simultaneously supported by the control plane security policy of UE1 in the PC5 connection sent by UE1 in the direct communication request and the control plane security policy of UE2 in the PC5 connection stored locally by UE2 or obtained from other network elements), UE2 can also select a security protection method with a security level not lower than the first security protection method as the security protection method used for the control plane of the PC5 connection based on the control plane security policy of UE1 in the PC5 connection sent by UE1 in the direct communication request and the control plane security policy of UE2 in the PC5 connection stored locally by UE2 or obtained from other network elements, so that UE2 activates the control plane security of the PC5 connection according to the selected security protection method. For example, if the first security protection method is confidentiality protection enabled and integrity protection disabled, and the control plane security policy for UE1 in the PC5 connection is confidentiality protection optional and integrity protection optional, and the control plane security policy for UE2 in the PC5 connection is confidentiality protection disabled, then UE2 can determine that the security protection method used for the control plane of the PC5 connection is confidentiality protection enabled and integrity protection enabled. Because in this solution, when the first security protection method satisfies both the control plane security policy for UE1 in the PC5 connection and the control plane security policy for UE2 in the PC5 connection, UE2 selects a security protection method with a security level no lower than the first security protection method as the security protection method used for the control plane of the PC5 connection based on the control plane security policy for UE1 in the PC5 connection and the control plane security policy for UE2 in the PC5 connection. Therefore, not only can the security protection method used for the control plane of the PC5 connection determined by UE2 be supported by both UE1 and UE2, but it also ensures that the security level of the first security protection method is the lowest security level for the PC5 connection in the PC5 establishment process, thereby achieving the goal of no security degradation.

[0208] In summary, in this embodiment of the present application, the security level of the security protection method used by the control plane connected to PC5, as determined by UE2, is no lower than the security level of the first security protection method. In other words, the security level of the first security protection method is the minimum security level requirement for control plane signaling interactions, thus achieving the goal of no security degradation.

[0209] Furthermore, in an embodiment of the present application, after UE2 determines the security protection method used for the control plane of the PC5 connection, UE2 may determine the security algorithm used for the control plane of the PC5 connection between UE1 and UE2 based on the control plane security capabilities of UE1 and UE2 in the PC5 connection, combined with the security protection method used for the control plane of the PC5 connection determined by UE2. The security algorithms used for the control plane of the PC5 connection include one or more confidentiality protection algorithms and one or more integrity protection algorithms. The principles for selecting the security algorithm can be found in step S404 and are not further described here.

[0210] S503: UE2 sends a direct security mode command to UE1. Correspondingly, UE1 receives the direct security mode command from UE2. The direct security mode command includes the security algorithm selected by UE2 for the control plane of the PC5 connection.

[0211] Optionally, in an embodiment of the present application, the direct connection security mode command may further include the control plane security policy of UE1 in the PC5 connection and / or the control plane security capability of UE1 in the PC5 connection. Furthermore, after UE1 receives the direct connection security mode command from UE2, when UE1 determines that the security protection method used by the control plane of the final PC5 connection includes that the control plane integrity protection is not enabled, UE1 needs to determine whether the control plane security policy in the PC5 connection included in the direct connection security mode command is the control plane security policy in the PC5 connection sent by itself, and whether the security capability in the PC5 connection is the security capability in the PC5 connection sent by itself. If the verification is successful, the subsequent process can be continued, otherwise the current process is terminated. This can prevent a bidding down attack.

[0212] In an embodiment of the present application, all or part of the parameters transmitted in the direct connection security mode command are protected by the security protection method used by the control plane of the PC5 connection determined by UE2. For example, if UE2 determines the first security protection method as the security protection method used by the control plane of the PC5 connection, all or part of the parameters transmitted in the direct connection security mode command are protected by the first security protection method. Among them, the method for performing security protection on all or part of the parameters transmitted in the direct connection security mode command can refer to the existing technology and will not be described in detail here. Exemplarily, the part of the parameters that are protected in the direct connection security mode command may include, for example, at least one of the security algorithm used by the control plane of the PC5 connection selected by UE2, the control plane security policy of UE1 in the PC5 connection, and the control plane security capability of UE1 in the PC5 connection.

[0213] S504 : UE1 determines a final security protection method used by the control plane of the PC5 connection according to the security algorithm used by the control plane of the PC5 connection selected by UE2.

[0214] The description of step S504 can be found in Figure 4 Step S406 of the embodiment shown is not described again in detail.

[0215] It should be noted that, in the embodiment of the present application, the security protection method used by the control plane of the PC5 connection determined by UE1 can be used to protect the messages of the security protection method used by the user plane of the PC5 connection between UE1 and UE2 in the subsequent negotiation, such as the security protection of the direct connection security mode completion message in step S505 and the security protection of the direct connection communication acceptance message in step S507. In addition, the security protection method used by the control plane of the PC5 connection determined by UE1 can also be used to protect the security protection method used by the user plane of the PC5 connection between UE1 and UE2. Figure 5 The security protection of the control plane signaling after the PC5 establishment process shown is explained here uniformly and will not be repeated below.

[0216] S505: UE1 sends a direct security mode complete message to UE2. Correspondingly, UE2 receives the direct security mode complete message from UE1.

[0217] Optionally, in an embodiment of the present application, the direct connection security mode completion message may include the user plane security policy of UE1 in the PC5 connection. The user plane security policy of UE1 in the PC5 connection may be used to subsequently determine the security protection method to be used for the user plane of the PC5 connection between UE1 and UE2. For a description of the user plane security policy in the PC5 connection, please refer to the preamble of the specific implementation method and will not be repeated here.

[0218] Optionally, in the embodiment of the present application, when the user plane security capability in the PC5 connection is different from the control plane security capability in the PC5 connection, the direct connection security mode completion message may also include the user plane security capability of UE1 in the PC5 connection.

[0219] It should be noted that in the embodiment of the present application, assuming that the standard stipulates that the user plane security capabilities of UE1 in the PC5 connection are the same as the control plane security capabilities of UE1 in the PC5 connection, or that the security capabilities do not distinguish between the user plane and the control plane, the direct connection security mode completion message does not need to carry the user plane security capabilities of UE1 in the PC5 connection. In this scenario, the user plane security capabilities of UE1 in the PC5 connection described below are the control plane security capabilities of UE1 in the PC5 connection, which are uniformly described here and will not be repeated below.

[0220] In an embodiment of the present application, all or part of the parameters transmitted in the direct connection security mode completion message are protected by the security protection method used by the control plane of the PC5 connection determined by UE1. For example, if UE2 determines the first security protection method as the security protection method used by the control plane of the PC5 connection, all or part of the parameters transmitted in the direct connection security mode completion message are protected by the first security protection method. Among them, the method for protecting all or part of the parameters transmitted in the direct connection security mode completion message can refer to the existing technology and will not be described in detail here. Exemplarily, the part of the parameters that are protected in the direct connection security mode completion message can be, for example, at least one of the user plane security policy of UE1 in the PC5 connection or the user plane security capability of UE1 in the PC5 connection.

[0221] S506. UE2 determines the security protection method used by the user plane connected to PC5 according to the first security protection method.

[0222] In an embodiment of the present application, the implementation manner in which UE2 determines the security protection method used by the user plane of the PC5 connection according to the first security protection method is similar to the implementation manner in which UE2 determines the security protection method used by the control plane of the PC5 connection according to the first security protection method in the above step S502. The differences are, for example: 1. The control plane in step S502 is replaced by the user plane in step S506; 2. The user plane security policy of UE1 in the PC5 connection in step S506 comes from the direct connection security mode completion message sent by UE1 to UE2. The rest of the related descriptions can refer to the above step S502 and will not be repeated here.

[0223] That is, in this embodiment of the present application, the security level of the security protection method used by the user plane connected to PC5 determined by UE2 is not lower than the security level of the first security protection method. In other words, the security level of the first security protection method is the minimum security requirement for user plane data interaction, so that the purpose of non-degradation of security can be achieved.

[0224] Optionally, in an embodiment of the present application, if the security algorithm used by the control plane of the PC5 connection is different from the security algorithm used by the user plane of the PC5 connection, then after UE2 determines the security protection method used by the user plane of the PC5 connection, UE2 also needs to determine the security algorithm used by the user plane of the PC5 connection between UE1 and UE2 based on the user plane security capabilities of UE1 in the PC5 connection and the user plane security capabilities of UE2 in the PC5 connection, combined with UE2's determination of the security protection method used by the user plane of the PC5 connection. This embodiment of the present application does not specifically limit this. Among them, the security algorithm used by the user plane of the PC5 connection includes one or more confidentiality protection algorithms and one or more integrity protection algorithms. The principles followed in the selection of the security algorithm can be referred to step S404 and will not be repeated here.

[0225] S507: UE2 sends a direct communication accept message to UE1. Correspondingly, UE1 receives the direct communication accept message from UE2. The direct communication accept message includes the security protection method used by the user plane connected to PC5.

[0226] Optionally, in an embodiment of the present application, the direct communication acceptance message may also include the user plane security policy of UE1 in the PC5 connection and the user plane security capability of UE1 in the PC5 connection (optional). Furthermore, after UE1 receives the direct communication acceptance message from UE2, when UE1 determines that the security protection method used by the control plane of the final PC5 connection includes that the control plane integrity protection is not enabled, UE1 needs to determine whether the user plane security policy in the PC5 connection included in the direct communication acceptance message is the user plane security policy in the PC5 connection sent by itself, and whether the security capability in the PC5 connection is the security capability in the PC5 connection sent by itself. If the verification is passed, the subsequent process can be continued, otherwise the current process is terminated. This can prevent degradation attacks.

[0227] Optionally, in the embodiment of the present application, if UE2 determines the security algorithm used by the user plane connected to PC5, the direct communication acceptance message also includes the security algorithm used by the user plane connected to PC5.

[0228] In an embodiment of the present application, all or part of the parameters transmitted in the direct communication acceptance message are protected by the security protection method used by the control plane of the PC5 connection determined by UE2. For example, if UE2 determines the first security protection method as the security protection method used by the control plane of the PC5 connection, all or part of the parameters transmitted in the direct communication acceptance message are protected by the first security protection method. Among them, the method for performing security protection on all or part of the parameters transmitted in the direct communication acceptance message can refer to the existing technology and will not be described in detail here. Exemplarily, the part of the parameters that are protected in the direct communication acceptance message may include, for example, the security protection method used by the user plane of the PC5 connection, the user plane security policy of UE1 in the PC5 connection and the user plane security capability of UE1 in the PC5 connection, or at least one of the security algorithms used by the user plane of the PC5 connection.

[0229] Based on the communication method provided by the embodiment of the present application, on the one hand, since the embodiment of the present application can determine the security protection method used by the control plane of the PC5 connection and the security protection method used by the user plane of the PC5 connection according to the first security protection method in the PC5 establishment process, wherein the security level of the security protection method used by the control plane of the PC5 connection and the security protection method used by the user plane of the PC5 connection are not lower than the security level of the first security protection method. In other words, the security level of the first security protection method is the minimum security level requirement for the PC5 connection in the PC5 establishment process, which can achieve the purpose of no security degradation. On the other hand, the embodiment of the present application can use the first security protection method to protect the first message in the PC5 establishment process. When the first security protection method includes integrity protection turned on, UE1 and UE2 can use the first security protection method determined in the ProSe discovery process to perform integrity protection on the first message in the PC5 establishment process. Therefore, the problem of security level reduction caused by the message in the PC5 establishment process being attacked or tampered with by an attacker can be avoided, thereby improving the security level of the PC5 establishment process.

[0230] The actions of UE1 or UE2 in the above steps S501 to S507 can be Figure 3 The processor 301 in the communication device 300 shown calls the application code stored in the memory 303 to instruct the UE1 or UE2 to execute, and this embodiment does not impose any limitation on this.

[0231] It should be noted that Figure 5The embodiment shown is described by taking the security protection method used by the control plane connected to PC5 and the security protection method used by the user plane connected to PC5 as an example. Optionally, in the embodiment of the present application, the security protection method used by the control plane connected to PC5 can also be determined according to the first security protection method. Figure 4 In the embodiment shown, the security protection method used by the user plane connected to PC5 is negotiated in the manner of steps S407-S409; alternatively, in the embodiment of the present application, the security protection method used by the user plane connected to PC5 can also be determined according to the first security protection method, by similar Figure 4 In the illustrated embodiment, steps S402 to S406 are used to negotiate the security protection method used by the control plane connected to PC5, which is not specifically limited in the embodiment of the present application.

[0232] In another possible implementation, taking the interaction between UE1 and UE2 as an example, an embodiment of the present application provides a communication method, which uses the security protection method determined in the ProSe discovery process to perform security protection on one or more messages in the PC5 establishment process between UE1 and UE2. At the same time, in the PC5 establishment process, the security protection method used by the control plane of the PC5 connection between UE1 and UE2 (for convenience, the PC5 connection between UE1 and UE2 will be referred to as the PC5 connection) is determined according to the security protection method determined in the ProSe discovery process, and the security protection method used by the user plane of the PC5 connection is negotiated. For example, Figure 6 As shown, the communication method provided in the embodiment of the present application includes the following steps:

[0233] S601: UE1 sends a direct communication request to UE2. In response, UE2 receives the direct communication request from UE1. The direct communication request includes UE1's user plane security policy for the PC5 connection and UE1's control plane security capabilities for the PC5 connection. For a description of the user plane security policy and control plane security capabilities for the PC5 connection, please refer to the preamble of the specific implementation method and will not be repeated here.

[0234] Of course, in the embodiment of the present application, the direct communication request may also include part or all of the discovery parameters of UE1. For details, please refer to the existing 3GPP TS23.303, v15.1.0 standard, which will not be repeated here.

[0235] It should be noted that, assuming that the standard stipulates that the control plane security capability of UE1 in the PC5 connection is the same as the user plane security capability of UE1 in the PC5 connection, or the security capability does not distinguish between the user plane and the control plane, then in the embodiment of the present application, the control plane security capability in the PC5 connection can also be referred to as the security capability in the PC5 connection. This is explained uniformly here and will not be repeated below.

[0236] Optionally, in an embodiment of the present application, all or part of the parameters transmitted in the direct communication request are protected by the first security protection method. For example, the user plane security policy of UE1 in the PC5 connection and / or the control plane security capability of UE1 in the PC5 connection can be protected by the first security protection method. Among them, the first security protection method is the security protection method obtained in the ProSe discovery process between UE1 and UE2. The embodiment of the present application does not limit the method for determining the security protection method in the ProSe discovery process. In a possible implementation method, the method for determining the security protection method in the ProSe discovery process can be referred to in the subsequent Figure 7 The embodiment shown.

[0237] Optionally, in an embodiment of the present application, the direct communication request may further include a control plane security policy for UE1 in the PC5 connection. The control plane security policy for UE1 in the PC5 connection may be used to subsequently determine a security protection method to be used for the control plane of the PC5 connection between UE1 and UE2. The control plane security policy for UE1 in the PC5 connection may employ the first security protection method for security protection. For a description of the control plane security policy in the PC5 connection, please refer to the preamble of the specific implementation method and will not be repeated here.

[0238] Optionally, in the embodiment of the present application, when the user plane security capability in the PC5 connection is different from the control plane security capability in the PC5 connection, the direct communication request may further include the user plane security capability of UE1 in the PC5 connection.

[0239] Optionally, in the embodiment of the present application, when UE1 determines that the first security protection method includes integrity protection on, the direct communication request may further include MIC3. The relevant description of MIC3 may refer to Figure 4 The embodiment shown is not described here in detail. Further, after UE2 receives the direct communication request from UE1, it can verify MIC3. The verification method of MIC3 can be referred to Figure 4 If the MIC3 verification is successful, it can be said that all or part of the parameters transmitted in the direct communication request in step S601 are protected intact and not attacked by external attackers, and then the following step S602 can be executed.

[0240] S602. UE2 determines the security protection method used by the control plane of the PC5 connection based on the first security protection method; and, UE2 determines the security algorithm used by the control plane of the PC5 connection between UE1 and UE2 based on the control plane security capability of UE1 in the PC5 connection and the control plane security capability of UE2 in the PC5 connection.

[0241] The description of step S602 can be found in Figure 5 Step S502 in the illustrated embodiment will not be described in detail here.

[0242] S603 : UE2 determines a security protection method for the user plane of the PC5 connection between UE1 and UE2 according to the user plane security policy of UE1 in the PC5 connection and the user plane security policy of UE2 in the PC5 connection.

[0243] The relevant description of step S603 can be found in Figure 4 Step S408 in the illustrated embodiment will not be described in detail here.

[0244] S604: UE2 sends a direct security mode command to UE1. Accordingly, UE1 receives the direct security mode command from UE2. The direct security mode command includes the security protection method used by the user plane of the PC5 connection and the security algorithm used by the control plane of the PC5 connection selected by UE2.

[0245] Optionally, in an embodiment of the present application, the direct connection security mode command may also include the user plane security policy of UE1 in the PC5 connection, the control plane security capability of UE1 in the PC5 connection (optional), the user plane security capability of UE1 in the PC5 connection (optional), and the control plane security policy of UE1 in the PC5 connection (optional). Furthermore, after UE1 receives the direct connection security mode command from UE2, if UE1 determines that the security protection method used by the control plane of the final PC5 connection includes not enabling control plane integrity protection, UE1 needs to determine whether the user plane security policy of the PC5 connection included in the direct connection security mode command is the user plane security policy of the PC5 connection sent by UE1, whether the control plane security capability of the PC5 connection is the control plane security capability of the PC5 connection sent by UE1, whether the user plane security capability of the PC5 connection is the user plane security capability of the PC5 connection sent by UE1, and whether the control plane security policy of the PC5 connection is the control plane security policy of the PC5 connection sent by UE1. If the verification is successful, the subsequent process can be continued; otherwise, the current process is terminated. This can prevent degradation attacks.

[0246] Optionally, in the embodiment of the present application, if UE2 determines the security algorithm used by the user plane connected to PC5, the direct connection security mode command also includes the security algorithm used by the user plane connected to PC5.

[0247] In an embodiment of the present application, all or part of the parameters passed in the direct connection security mode command are protected by the security protection method used by the control plane of the PC5 connection determined by UE2. For example, if UE2 determines the first security protection method as the security protection method used by the control plane of the PC5 connection, all or part of the parameters passed in the direct connection security mode command are protected by the first security protection method determined in the ProSe discovery process. Among them, the method for protecting all or part of the parameters passed in the direct connection security mode command can refer to the existing technology and will not be described in detail here. Exemplarily, the part of the parameters that are protected in the direct connection security mode command may include, for example, the security algorithm used by the control plane of the PC5 connection selected by UE2, the security protection method used by the user plane of the PC5 connection, the user plane security policy of UE1 in the PC5 connection, the user plane security capability of UE1 in the PC5 connection, the control plane security capability of UE1 in the PC5 connection, the control plane security policy of UE1 in the PC5 connection, and at least one of the security algorithm used by the user plane of the PC5 connection.

[0248] S605 : UE1 determines a final security protection method used by the control plane of the PC5 connection according to the security algorithm used by the control plane of the PC5 connection selected by UE2.

[0249] The description of step S605 can be found in Figure 4 Step S406 of the embodiment shown is not described again in detail.

[0250] At this point, both UE1 and UE2 can learn the security protection method used by the control plane connected to PC5 and the security protection method used by the user plane connected to PC5.

[0251] It should be noted that in the embodiment of the present application, the security protection method used by the control plane of the PC5 connection determined by UE1 can be used Figure 6 The security protection of the control plane signaling after the PC5 establishment process shown is explained here uniformly and will not be repeated below.

[0252] Optionally, the direct connection communication request in step S601 of the embodiment of the present application may be replaced by a direct connection security mode completion message, and the direct connection security mode command in step S604 may be replaced by a direct connection communication acceptance message. That is, the negotiation of the security protection method used by the user plane of the PC5 connection is performed through messages of the existing negotiation process for the security protection method used by the user plane of the PC5 connection, which is not specifically limited in the embodiment of the present application.

[0253] Based on the communication method provided by the embodiment of the present application, on the one hand, since the embodiment of the present application can determine the security protection method used by the control plane of the PC5 connection according to the first security protection method in the PC5 establishment process, wherein the security level of the security protection method used by the control plane of the PC5 connection is not lower than the security level of the first security protection method. In other words, the security level of the first security protection method is the minimum security level requirement for the control plane signaling interaction, so that the purpose of no security degradation can be achieved. On the other hand, the embodiment of the present application can use the first security protection method to protect the first message in the PC5 establishment process. Then, when the first security protection method includes integrity protection turned on, UE1 and UE2 can use the first security protection method to perform integrity protection on the first message in the PC5 establishment process. Therefore, the problem of reduced security level caused by the message in the PC5 establishment process being attacked or tampered by an attacker can be avoided, thereby improving the security level of the PC5 establishment process.

[0254] It should be noted that Figure 6 The embodiment shown is explained by taking the example of determining the security protection method used by the control plane of the PC5 connection according to the first security protection method in the PC5 establishment process, and negotiating the security protection method used by the user plane of the PC5 connection. Optionally, the embodiment of the present application can also provide a communication method, which uses the first security protection method to perform security protection on one or more messages in the PC5 establishment process. At the same time, in the PC5 establishment process, the security protection method used by the user plane of the PC5 connection is determined according to the first security protection method, and the security protection method used by the control plane of the PC5 connection is negotiated. The specific implementation of this method can be referred to. Figure 6 The embodiments shown are not described in detail here.

[0255] The actions of UE1 or UE2 in the above steps S601 to S605 can be Figure 3 The processor 301 in the communication device 300 shown calls the application code stored in the memory 303 to instruct the UE1 or UE2 to execute, and this embodiment does not impose any limitation on this.

[0256] It should be noted that Figure 5 or Figure 6The illustrated embodiment is described by taking the example of determining the security protection method used by the control plane of the PC5 connection and / or the security protection method used by the user plane of the PC5 connection according to the first security protection method. Of course, the embodiment of the present application can also obtain the security protection method used by the control plane of the PC5 connection and / or the security protection method used by the user plane of the PC5 connection in the ProSe discovery process, so that the PC5 establishment process does not need to negotiate the security protection method used by the control plane of the PC5 connection, nor does it need to negotiate the security protection method used by the user plane of the PC5 connection, thereby saving the signaling overhead of the PC5 establishment process. Furthermore, when the security protection method used by the control plane of the PC5 connection obtained in the ProSe discovery process includes the control plane integrity protection being turned on, since all messages in the PC5 establishment process can be integrity protected, the problem of reduced security level caused by the messages in the PC5 establishment process being attacked or tampered with by attackers can be avoided, thereby improving the security level of the PC5 establishment process.

[0257] The present application also provides a communication method for obtaining Figures 4 to 6 The first security protection method in any embodiment. Optionally, the security protection method used by the control plane connected to PC5 and / or the security protection method used by the user plane connected to PC5 can also be obtained through this communication method. For example, Figure 7 As shown, the communication method includes the following steps:

[0258] S701: Terminal device 1 sends a discovery request to DDNMF1 network element. Correspondingly, DDNMF1 network element receives the discovery request from terminal device 1.

[0259] The discovery request includes one or more of the 3GPP identity information of the terminal device 1, identity information for the ProSe service, discovery mode, discovery command, discovery type, and application ID. For a description of the discovery type, discovery mode, discovery command, or identity information for the ProSe service, please refer to the introduction to the specific implementation method and will not be repeated here.

[0260] For example, the terminal device 1 in the embodiment of the present application may be the announcing UE (announcing UE) in the model A discovery mode, and the terminal device 2 described below may be the monitoring UE (monitoring UE) in the model A discovery mode; or, the terminal device 1 in the embodiment of the present application may be the discoveree UE (discoveree UE) in the model B discovery mode, and the terminal device 2 described below may be the discoverer UE (discoverer UE) in the model B discovery mode. These are described uniformly here and will not be repeated below.

[0261] In one possible implementation, in an embodiment of the present application, the terminal device 1 may send a discovery request to the DDNMF1 network element through a non-access stratum (NAS) message of the control plane, that is, the discovery request itself is a NAS message, or a parameter for implementing the function of the discovery request carried by the NAS message; in another possible implementation, the terminal device 1 may send it to the DDNMF1 network element through the user, that is, the discovery request is carried by the Internet Protocol (IP) or non-IP at this time. The embodiment of the present application does not specifically limit the sending method of the discovery request.

[0262] Optionally, in an embodiment of the present application, the 3GPP identity information of the terminal device 1 can be, for example, one of a subscription concealed identifier (SUCI), a 5G-global unique temporary identifier (GUTI), a generic public subscription identifier (GPSI), and a permanent equipment identifier (PEI). If the terminal device 1 accesses the DDNMF1 network element through the control plane process, identity information such as SUCI or 5G-GUTI can be used as the 3GPP identity information of the terminal device 1; if the terminal device 1 accesses the DDNMF1 network element through the user plane process, identity information such as GPSI or PEI can be used as the 3GPP identity information of the terminal device 1. This is a unified explanation here and will not be repeated below.

[0263] Optionally, the application identifier in the embodiment of the present application is used to represent a specific application. The application identifier may be pre-configured on the terminal device 1. In a possible implementation, in the embodiment of the present application, the DDNMF1 network element may determine the corresponding identity information for the ProSe service based on the application identifier. Exemplarily, assuming that the discovery type corresponding to an application identifier is fixed, that is, an application identifier corresponds to a discovery type (such as open discovery or restricted discovery), then since the discovery type can correspond to the user identity for the ProSe service (such as ProSe application ID for open discovery scenarios; PDUID or RPAUID for restricted discovery scenarios), the corresponding identity information for the ProSe service can be indirectly determined based on the application identifier.

[0264] Optionally, the discovery request in the embodiment of the present application may further include a service type. The service type is a finer granularity under the application identifier, that is, one application identifier can correspond to different service types. The service type is used to assist the application identifier in determining the corresponding identity information for the ProSe service. That is, in the embodiment of the present application, the DDNMF1 network element can determine the corresponding identity information for the ProSe service based on the application identifier and service type.

[0265] Optionally, the service type in the embodiments of the present application can be used to characterize the specific business requirements of the application identified by the application identifier. For example, the service type is used to indicate whether an application is a paid service or a free service. In particular, the embodiments of the present application can enhance the flexibility of application usage by introducing service types.

[0266] Optionally, the content of the service type in the embodiment of the present application can have different storage or transmission methods according to the different information represented. For example, 0 or 1 is used to represent whether it is a paid or free service, and the embodiment of the present application does not make specific restrictions on this.

[0267] Optionally, the service type in the embodiment of the present application can be configured on the terminal device 1 when the application identified by the application identifier is installed, or it can be sent to the terminal device 1 by the network side. The embodiment of the present application does not make specific limitations on this.

[0268] It should be noted that, in the embodiment of the present application, when the discovery request is transmitted between the terminal device 1 and the DDNMF1 network element, it may be forwarded and processed by other network elements. That is to say, when the discovery request is transmitted between the terminal device 1 and the DDNMF1 network element, the content of the message can be appropriately deformed. The embodiment of the present application only describes the message from the functional aspect, which is explained here uniformly and will not be repeated below. For example, in the process of the terminal device 1 sending a discovery request to the DDNMF1 network element through the control surface, the 3GPP identity information of the terminal device 1 needs to be "translated" by the AMF network element or other network elements into the subscription permanent identifier (SUPI) of the terminal device 1. Alternatively, in the process of the terminal device 1 sending a discovery request to the DDNMF1 network element through the user surface, the 3GPP identity information of the terminal device 1 may be "translated" by the NEF network element or other network elements into the SUPI of the terminal device 1. Of course, if the 3GPP identity information of terminal device 1 obtained by the DDNMF1 network element does not include SUPI, the DDNMF1 network element can also obtain the SUPI of terminal device 1 through interaction with the UDM network element (or other network elements). Exemplarily, the DDNMF1 network element sends a UE ID request message to the UDM network element, where the UE ID request message includes the 3GPP identity information (such as GPSI or PEI) of terminal device 1. The UDM network element receives the UE ID request message from the DDNMF1 network element, determines the SUPI of terminal device 1 based on the 3GPP identity information of terminal device 1, and then sends the SUPI of terminal device 1 to the DDNMF1 network element.

[0269] S702 . The DDNMF1 network element performs a ProSe service discovery authorization check on the terminal device 1 according to the identity information and application identifier used for the ProSe service.

[0270] Optionally, in this embodiment of the present application, the DDNMF1 network element may determine the corresponding proximity service application server (ProSe app server) based on the application identifier, and the ProSe app server completes the authorization check and notifies the DDNMF1 network element. In this embodiment of the present application, the ProSe app server authorization check is used to verify whether the terminal device 1 can legally use the ProSe service. This is explained here uniformly and will not be repeated below.

[0271] Optionally, in an embodiment of the present application, if the terminal device 1 carries multiple identity information for ProSe services, then according to the above description, the DDNMF1 network element shall perform ProSe service discovery authorization checks on the terminal device 1 separately according to each identity information used for the ProSe service. The above multiple authorizations can be performed separately in independent processes or in a unified process. They are explained here in a unified manner and will not be repeated below.

[0272] S703. The DDNMF1 network element obtains the discovery parameters and security information corresponding to when the terminal device 1 uses the ProSe service.

[0273] In the embodiment of the present application, the DDNMF1 network element may obtain, based on the 3GPP identity information of the terminal device 1 and the identity information used for the ProSe service, the discovery parameters and security information corresponding to when the terminal device 1 uses the ProSe service. The manner in which the DDNMF network element obtains the discovery parameters and security information corresponding to when the terminal device 1 uses the ProSe service includes: both the discovery parameters and the security information are obtained locally from the DDNMF1 network element; or, part of the discovery parameters and the security information are obtained locally from the DDNMF1 network element, and part of the discovery parameters and the security information are obtained from the authentication response (authentication request) replied by the ProSe app server in the ProSe service discovery authorization check process; or, both the discovery parameters and the security information are obtained from the authentication response replied by the ProSe app server in the ProSe service discovery authorization check process, which is not specifically limited in the embodiment of the present application.

[0274] In the embodiment of the present application, in the restricted discovery scenario, the discovery parameters of the terminal device 1 may be as shown in Table 1, for example:

[0275] Table 1

[0276]

[0277] In Model A, Code-Send-SecParams contains discovery parameters used to protect the Prose Restricted Code during the discovery process on the PC5 interface. In Model B, Code-Send-SecParams is used to protect the ProSe Response Code during the discovery process on the PC5 interface, and Code-Rcv-SecParams contains discovery parameters used to obtain the ProSe discovery code sent by the peer during the discovery process on the PC5 interface. For descriptions of the discovery parameters in Table 1, refer to the existing 3GPP TS 23.303, v15.1.0 and 3GPP TS 33.303, v15.0.0 standards and are not detailed here.

[0278] In the embodiment of the present application, in the discovery scenario of open discovery, the discovery parameters of the terminal device 1 may be as shown in Table 2, for example:

[0279] Model A ProSe discovers the code used ProSe Application Code Discovery Parameters Discovery Key Discovery time limit parameters CURRENT_TIME, MAX_OFFSET

[0280] The Discovery Key contains discovery parameters used to protect the ProSe Application Code during the discovery process. Specifically, these discovery parameters are used to protect the ProSe discovery code on the PC5 interface. The description of the discovery parameters in Table 2 can be found in the existing 3GPP TS 23.303, v15.1.0, and 3GPP TS 33.303, v15.0.0 standards and are not detailed here.

[0281] Optionally, in an embodiment of the present application, the security information corresponding to the terminal device 1 using the ProSe service includes the security protection method required when the terminal device 1 uses the ProSe service, or multiple optional security protection methods corresponding to the terminal device 1 using the ProSe service.

[0282] Among them, in an embodiment of the present application, the security protection method required by the terminal device 1 when using the ProSe service is a fixed security protection method. Optionally, the security protection method can be used to perform security protection on the subsequent first PC5 broadcast message; and / or, the security protection method can be used to perform security protection on one or more messages in the PC5 establishment process; and / or, the security protection method can be used to determine the security protection method for the PC5 connection between the terminal device 1 and the terminal device 2. Among them, the security protection method for the PC5 connection is used to perform security protection on some or all parameters transmitted in the control plane signaling of the PC5 connection; and / or, the security protection method for the PC5 connection is used to perform security protection on some or all user plane data of the PC5 connection. Exemplarily, the security protection method is used to perform security protection on one or more messages in the PC5 establishment process; and / or, the security protection method is used to determine the example of the security protection method for the PC5 connection between the terminal device 1 and the terminal device 2. Figures 4 to 6 The description of the first PC5 broadcast message can be found in the preface of the specific implementation method, and will not be repeated here.

[0283] Optionally, in an embodiment of the present application, the security protection method required by terminal device 1 when using the ProSe service may be multiple security protection methods. For example, one security protection method is the security protection method used by the first PC5 broadcast message; one security protection method is the security protection method used by the control plane connected to PC5; and one security protection method is the security protection method used by the user plane connected to PC5. The security protection method used by the first PC5 broadcast message, the security protection method used by the control plane connected to PC5, and the security protection method used by the user plane connected to PC5 may be the same or different, and this embodiment of the present application does not specifically limit this.

[0284] For example, in an embodiment of the present application, the security protection method required by terminal device 1 when using the ProSe service may include any one of the following: confidentiality protection enabled + integrity protection enabled, confidentiality protection enabled + integrity protection disabled, confidentiality protection disabled + integrity protection enabled, or confidentiality protection disabled + integrity protection disabled. It is assumed that the security protection method to be used can be used to provide security protection for at least the first subsequent PC5 broadcast message.

[0285] Alternatively, illustratively, in an embodiment of the present application, the security protection method required when the terminal device 1 uses the ProSe service may include:

[0286] The security protection method used by the first PC5 broadcast message is: confidentiality protection disabled + integrity protection enabled; the security protection method used by the control plane connected to PC5 is: confidentiality protection enabled + integrity protection enabled; and the security protection method used by the user plane connected to PC5 is: confidentiality protection enabled + integrity protection enabled. The security protection methods used by the first PC5 broadcast message, the control plane connected to PC5, and the user plane connected to PC5 are all different.

[0287] Alternatively, illustratively, in an embodiment of the present application, the security protection method required when the terminal device 1 uses the ProSe service may include:

[0288] The security protection method used by the first PC5 broadcast message and the security protection method used by the control plane connected to PC5 are: confidentiality protection is disabled + integrity protection is enabled; the security protection method used by the user plane connected to PC5 is: confidentiality protection is enabled + integrity protection is enabled.

[0289] Alternatively, illustratively, in an embodiment of the present application, the security protection method required when the terminal device 1 uses the ProSe service may include:

[0290] The security protection method used by the first PC5 broadcast message is: confidentiality protection disabled + integrity protection enabled; and the security protection method used by the control plane connected to PC5 is: confidentiality protection enabled + integrity protection enabled.

[0291] Alternatively, illustratively, in an embodiment of the present application, the security protection method required when the terminal device 1 uses the ProSe service may include:

[0292] The security protection method used by the first PC5 broadcast message is: confidentiality protection is disabled + integrity protection is enabled; and the security protection method used by the user plane connected to PC5 is: confidentiality protection is enabled + integrity protection is enabled.

[0293] In the embodiment of the present application, the multiple optional security protection methods may be, for example, security protection methods corresponding to the security policy recommended by the ProSe appserver. Furthermore, the multiple optional security protection methods may be prioritized.

[0294] For example, a prioritized list of available security protection methods may include: confidentiality protection disabled + integrity protection enabled > confidentiality protection enabled + integrity protection enabled > confidentiality protection disabled + integrity protection disabled. The ">" here can be understood as meaning "security level higher than" and is not further described below.

[0295] Optionally, in an embodiment of the present application, for different discovery modes, such as the above-mentioned Model A or Model B, different security information can be used respectively, or the same security information can be used. The embodiment of the present application does not make specific limitations on this.

[0296] Optionally, the security information in the embodiment of the present application may also be associated with the code used for ProSe discovery in Table 1 or Table 2, that is, different codes used for ProSe discovery may correspond to different security information, or the same security information may be used. The embodiment of the present application does not specifically limit this.

[0297] It should be noted that the security information in the embodiments of the present application may be included in the discovery parameters, and the embodiments of the present application do not make specific limitations on this.

[0298] Furthermore, when the security information corresponding to the terminal device 1 in the embodiment of the present application uses the ProSe service includes multiple optional security protection methods corresponding to the terminal device 1 using the ProSe service, it is necessary to continue to execute the following step S704 and then execute step S705; when the security information corresponding to the terminal device 1 in the embodiment of the present application uses the ProSe service includes the security protection method required when the terminal device 1 uses the ProSe service, step S705 is directly executed without the need to execute step S704.

[0299] S704. The DDNMF1 network element determines the security protection method required by the terminal device 1 when using the ProSe service based on multiple optional security protection methods.

[0300] Optionally, in an embodiment of the present application, the DDNMF1 network element can select the security protection method required for the terminal device 1 when using the ProSe service from multiple optional security protection methods based on parameters such as the status of the terminal device 1, the type of the terminal device 1, and the quality of service (QoS) requirements of the current service.

[0301] For example, if it is a low-latency service, the DDNMF1 network element may determine the security protection method with the lowest security level as the security protection method required when the terminal device 1 uses the ProSe service. Alternatively, for example, if it is a high-reliability service, the DDNMF1 network element may determine the security protection method with the highest security level as the security protection method required when the terminal device 1 uses the ProSe service.

[0302] Of course, in an embodiment of the present application, the DDNMF1 network element may also directly determine the security protection method with the highest security level among multiple optional security protection methods as the security protection method required when the terminal device 1 uses the ProSe service. This embodiment of the present application does not make specific limitations on this.

[0303] S705: The DDNMF1 network element sends a discovery response to the terminal device 1. Accordingly, the terminal device 1 receives the discovery response from the DDNMF1 network element. The discovery response includes the discovery parameters and the required security protection method when the terminal device 1 uses the ProSe service.

[0304] It should be noted that in the embodiment of the present application, the security protection method required when the terminal device 1 uses the ProSe service may be included in the discovery parameters, and the embodiment of the present application does not make specific limitations on this.

[0305] In summary, through steps S701-S705, the terminal device 1 can obtain the corresponding discovery parameters and the required security protection method when the terminal device 1 uses the ProSe service.

[0306] S706: Terminal device 2 sends a discovery request to DDNMF2 network element. Correspondingly, DDNMF2 network element receives the discovery request from terminal device 2.

[0307] S707 . The DDNMF2 network element performs a ProSe service discovery authorization check on the terminal device 2 according to the identity information and application identifier used for the ProSe service.

[0308] S708. The DDNMF2 network element obtains the corresponding discovery parameters and security information when the terminal device 2 uses the ProSe service.

[0309] Furthermore, when the security information corresponding to the terminal device 2 in the embodiment of the present application uses the ProSe service includes multiple optional security protection methods corresponding to the terminal device 2 using the ProSe service, it is necessary to continue to execute the following step S709 and then execute step S710; when the security information corresponding to the terminal device 2 in the embodiment of the present application uses the ProSe service includes the security protection method required for the terminal device 2 to use the ProSe service, then directly execute step S710 without executing step S709.

[0310] S709. The DDNMF2 network element determines the security protection method required by the terminal device 2 when using the ProSe service based on multiple optional security protection methods.

[0311] S710: The DDNMF2 network element sends a discovery response to the terminal device 2. Accordingly, the terminal device 2 receives the discovery response from the DDNMF2 network element. The discovery response includes the discovery parameters and the required security protection method corresponding to the use of the ProSe service by the terminal device 2.

[0312] In the embodiment of the present application, in the restricted discovery scenario, the discovery parameters of the terminal device 2 may be as shown in Table 3:

[0313] Table 3

[0314]

[0315] Among them, in Model A mode, Code-Rcv-SecParams contains discovery parameters used to protect the Prose Restricted Code in the discovery process on the PC5 interface; in Model B mode, Code-Send-SecParams contains discovery parameters used to protect the ProSe Query Code in the discovery process on the PC5 interface, and Code-Rcv-SecParams contains discovery parameters used to obtain the ProSe discovery code sent by the other end in the discovery process on the PC5 interface. In other words, the above discovery parameters are used to protect the ProSe discovery code on the PC5 interface. The relevant description of the discovery parameters in Table 3 can be referred to the existing 3GPP TS 23.303, v15.1.0 and 3GPP TS 33.303, v15.0.0 standards and will not be repeated here.

[0316] In the embodiment of the present application, in the discovery scenario of open discovery, the discovery parameters of the terminal device 2 may be as shown in Table 4, for example:

[0317] Model A ProSe discovers the code used ProSe Application Code Discovery time limit parameters CURRENT_TIME, MAX_OFFSET

[0318] It should be noted that in the open discovery scenario, terminal device 2 does not require a corresponding discovery key; decryption relies on the match report process. In other words, terminal device 2 does not have corresponding discovery parameters at this time. For related descriptions, please refer to the existing 3GPP TS 23.303, v15.1.0 and 3GPP TS 33.303, v15.0.0 standards and will not be repeated here.

[0319] Among them, the specific implementation of the above steps S706-S710 can refer to the above steps S701-S705, and the differences are, for example: replacing the terminal device 1 in steps S701-S705 with the terminal device 2 in steps S706-S710; replacing the DDNMF1 network element in steps S701-S705 with the DDNMF2 network element in steps S706-S710, etc. The rest of the related descriptions can refer to the above steps S701-S705 and will not be repeated here.

[0320] In summary, through steps S706-S710, terminal device 2 can obtain the corresponding discovery parameters and required security protection methods when terminal device 2 uses the ProSe service.

[0321] It should be noted that steps S706-S710 are described using the example of the DDNMF2 network element determining the security protection method required when using the ProSe service. Optionally, in this embodiment of the present application, the DDNMF2 network element may also determine the security protection method required when using the ProSe service through negotiation with the DDNMF1 network element.

[0322] In one possible implementation, the DDNMF2 network element obtains the security protection method required by the terminal device 1 when using the ProSe service from the DDNMF1 network element; further, the DDNMF2 network element determines the security protection method required by the terminal device 2 when using the ProSe service based on multiple optional security protection methods corresponding to the terminal device 2 using the ProSe service and the security protection method required by the terminal device 1 when using the ProSe service. For example, the DDNMF2 network element determines whether the multiple optional security protection methods corresponding to the terminal device 2 using the ProSe service include the security protection method required by the terminal device 1 when using the ProSe service; when the multiple optional security protection methods corresponding to the terminal device 2 using the ProSe service include the security protection method required by the terminal device 1 when using the ProSe service, the DDNMF2 network element determines the security protection method required by the terminal device 1 when using the ProSe service as the security protection method required by the terminal device 2 when using the ProSe service. For another example, when the multiple optional security protection methods corresponding to when terminal device 2 uses the ProSe service do not include the security protection method required by terminal device 1 when using the ProSe service, the DDNMF2 network element determines the security protection method required by terminal device 2 when using the ProSe service from the multiple optional security protection methods corresponding to when terminal device 2 uses the ProSe service. For example, the multiple optional security protection methods corresponding to when terminal device 2 uses the ProSe service obtained by the DDNMF2 network element include integrity protection on + confidentiality protection not on, integrity protection on + confidentiality protection on, that is, as long as integrity protection is on, confidentiality protection can be on or not. Assuming that the security protection method required by terminal device 1 when using the ProSe service includes integrity protection on + confidentiality protection not on, or the security protection method required by terminal device 1 when using the ProSe service includes integrity protection on + confidentiality protection on, the DDNMF2 network element can determine that the security protection method required by terminal device 1 when using the ProSe service is the security protection method required by terminal device 2 when using the ProSe service.

[0323] In another possible implementation, the DDNMF2 network element obtains the security protection method required by the terminal device 1 when using the ProSe service from the DDNMF1 network element; further, after the DDNMF2 network element determines the security protection method required by the terminal device 2 when using the ProSe service, it can further determine whether the security protection method required by the terminal device 1 when using the ProSe service is the same as the security protection method required by the terminal device 2 when using the ProSe service. If they are the same, the DDNMF network element can continue to execute step S710; if they are not the same, the DDNMF2 network element can determine the security protection method required by the terminal device 1 when using the ProSe service as the security protection method required by the final terminal device 2 when using the ProSe service, and carry the security protection method required by the terminal device 2 when using the ProSe service in step S710. The embodiment of the present application does not specifically limit this.

[0324] It should be noted that when terminal device 1 or terminal device 2 needs to obtain security protection methods corresponding to multiple ProSe discovery codes, after the DDNMF2 network element obtains the security protection method required by terminal device 1 when using the ProSe service from the DDNMF1 network element, if the security protection method required by terminal device 1 when using the ProSe service includes security protection methods corresponding to multiple ProSe discovery codes, the DDNMF2 network element determines whether there is a security protection method corresponding to a certain ProSe discovery code in the multiple optional security protection methods corresponding to the terminal device 2 when using the ProSe service, and the security protection method corresponding to the ProSe discovery code is the same as the security protection method required by the terminal device 1 when using the ProSe service. If so, the DDNMF2 network element can further execute step S710 and carry the security protection method corresponding to the ProSe discovery code in step S710. This is explained uniformly here and will not be repeated below.

[0325] Optionally, in an embodiment of the present application, the DDNMF2 network element obtains the security protection method required by the terminal device 1 when using the ProSe service from the DDNMF1 network element, which may include: the DDNMF2 network element sends a request message to the DDNMF1 network element, where the request message is used to request the terminal device 1 to use the security protection method required for the ProSe service. The request message includes identity information for the ProSe service sent by the terminal device 2, or information that can be associated with the identity information for the ProSe service sent by the terminal device 1, or information that can be associated with the target application. Furthermore, the DDNMF2 network element receives the security protection method required by the terminal device 1 when using the ProSe service from the DDNMF1 network element.

[0326] Optionally, in an embodiment of the present application, the DDNMF2 network element may use existing technology to determine whether to obtain the security protection method required by the terminal device 1 when using the ProSe service from the DDNMF1 network element. This embodiment of the present application does not specifically limit this.

[0327] It should be noted that the embodiment of the present application is explained by taking the identity information for the ProSe service sent by terminal device 1 and the identity information for the ProSe service sent by terminal device 2 as the same as the example. This is explained uniformly here and will not be repeated below. Of course, in the embodiment of the present application, the identity information for the ProSe service sent by terminal device 1 and the identity information for the ProSe service sent by terminal device 2 may also be different. At this time, the DDNMF1 network element / DDNMF2 network element can determine the security protection method to be used based on the identity information for the ProSe service sent by terminal device 2 and the identity information for the ProSe service sent by terminal device 1. For example, the DDNMF1 network element / DDNMF2 network element can associate the identity information for the ProSe service sent by terminal device 2 and the identity information for the ProSe service sent by terminal device 1. For example, association can be performed through application ID, and the embodiment of the present application does not specifically limit this.

[0328] Optionally, the communication method provided in the embodiment of the present application also includes the following discovery broadcast process.

[0329] Taking the Model A discovery scenario as an example, the communication method provided in the embodiment of the present application may further include the following steps S711-S712:

[0330] S711: Terminal device 1 sends a broadcast (announcing) message to terminal device 2. Correspondingly, terminal device 2 receives the broadcast message from terminal device 1. The broadcast message is protected using the security protection method required by terminal device 1 for using the ProSe service obtained in step S705.

[0331] Optionally, in an embodiment of the present application, the broadcast message may include a security protection method for protecting the broadcast message, so that terminal devices 2 using this security protection method can receive the broadcast message. The security protection method for protecting the broadcast message may be implicitly or explicitly included in the broadcast message, and this embodiment of the present application does not specifically limit this.

[0332] For example, different ProSe discovery codes represent different security protection methods. That is, the DDNMF1 network element can send multiple ProSe discovery codes to the announcing UE, with different ProSe discovery codes corresponding to different security protection methods. Furthermore, after receiving the broadcast message, the terminal device 2 can determine the corresponding security protection method based on the ProSe discovery code.

[0333] Alternatively, illustratively, the display method is such as carrying security indication information in the broadcast message, and the security indication information is used to indicate the security protection method used by the broadcast message. For example, the security indication information is 2 bits, 0 represents that security is not enabled, and 1 represents that security is enabled. For example, 00 represents that confidentiality protection is not enabled and integrity protection is not enabled, 10 represents that confidentiality protection is enabled, but integrity protection is not enabled, 01 represents that confidentiality protection is not enabled, but integrity protection is not enabled, and 11 represents that confidentiality protection is not enabled and integrity protection is not enabled. Furthermore, after receiving the broadcast message, the terminal device 2 can determine the corresponding security protection method according to the security indication information.

[0334] S712. Terminal device 2 verifies the broadcast message.

[0335] Step S712 may refer to existing implementations and will not be described in detail here.

[0336] For example, assuming that the security protection method required for Terminal Device 2 to use the ProSe service, sent by the DDNMF2 network element, is: confidentiality protection enabled + integrity protection disabled, but the broadcast message received by Terminal Device 2 indicates that the security protection method used by the broadcast message is: confidentiality protection enabled + integrity protection enabled, then even if Terminal Device 2 and Terminal Device 1 are interested in the same application, a subsequent PC5 connection cannot be established. In other words, the PC5 connection cannot be established between Terminal Device 1 and Terminal Device 2 simply because of mismatched security requirements.

[0337] Or, for example, assuming that the broadcast message received by terminal device 2 indicates that the security protection method used by the broadcast message is: confidentiality protection on + integrity protection on, and the security protection method required for terminal device 2 to use the ProSe service sent by the DDNMF2 network element received by terminal device 2 includes: confidentiality protection on + integrity protection on, then terminal device 2 can determine to establish a PC5 connection to the application of terminal device 1.

[0338] Optionally, taking the Model B discovery scenario as an example, the communication method provided in the embodiment of the present application may further include the following steps S713-S716:

[0339] S713: Terminal device 2 sends a query code (Send Query Code) message to terminal device 1. Correspondingly, terminal device 1 receives the query code message from terminal device 2.

[0340] The request code message is protected by the security protection method required by the terminal device 2 when using the ProSe service obtained in step S710.

[0341] Optionally, in an embodiment of the present application, the request code message may include a security protection method for protecting the request code message, so that the terminal device 1 using this security protection method can receive the request code message. The security protection method for protecting the request code message may be implicitly carried in the request code message or may be explicitly carried in the request code message, and this embodiment of the present application does not specifically limit this.

[0342] For example, different ProSe discovery codes represent different security protection methods. That is, the DDNMF2 network element can send multiple ProSe discovery codes to the discoverer UE, with different ProSe discovery codes corresponding to different security protection methods. Furthermore, after receiving the request code message, the terminal device 1 can determine the corresponding security protection method based on the ProSe discovery code.

[0343] Alternatively, illustratively, the display method is such as carrying security indication information in the request code message, and the security indication information is used to indicate the security protection method used by the request code message. For example, the security indication information is 2 bits, 0 represents that security is not enabled, and 1 represents that security is enabled. For example, 00 represents that confidentiality protection is not enabled and integrity protection is not enabled, 10 represents that confidentiality protection is enabled, but integrity protection is not enabled, 01 represents that confidentiality protection is not enabled, but integrity protection is not enabled, and 11 represents that confidentiality protection is not enabled and integrity protection is not enabled. Furthermore, after receiving the request code message, the terminal device 1 can determine the corresponding security protection method according to the security indication information.

[0344] S714. Terminal device 1 verifies and sends the request code message.

[0345] Step S417 may refer to existing implementation methods and will not be described in detail here.

[0346] For example, assuming that the security protection method required for Terminal Device 1 to use the ProSe service, sent by the DDNMF1 network element, is: confidentiality protection enabled + integrity protection disabled, but the request code message received by Terminal Device 1 indicates that the security protection method used by the request code message is: confidentiality protection enabled + integrity protection enabled, then even if Terminal Device 2 and Terminal Device 1 are interested in the same application, a subsequent PC5 connection cannot be established. In other words, the PC5 connection cannot be established between Terminal Device 1 and Terminal Device 2 simply because of mismatched security requirements.

[0347] Optionally, in an embodiment of the present application, after the terminal device 1 verifies that the request code message sent is accurate, it may continue to execute the following step S715.

[0348] S715 : Terminal device 1 sends a response code (Send response Code) message to terminal device 2 . Correspondingly, terminal device 2 receives the send response code message from terminal device 1 .

[0349] S716. Terminal device 2 verifies and sends a response code message.

[0350] Optionally, in an embodiment of the present application, after the above process of Model A or Model B is completed, a match report process may also be included. For details, please refer to the existing 3GPP TS 23.303, v15.1.0 and 3GPPTS 33.303, v15.0.0 standards, which will not be described in detail here.

[0351] Based on the communication method provided in the embodiments of the present application, the security protection method required by the terminal device when using ProSe services can be obtained during the ProSe discovery process. Optionally, the security protection method used by the control plane connected to PC5 and / or the security protection method used by the user plane connected to PC5 can also be obtained through this communication method.

[0352] The actions of the DDNMF1 network element, the DDNMF2 network element, the terminal device 1 or the terminal device 2 in the above steps S701 to S716 can be performed by Figure 3 The processor 301 in the communication device 300 shown calls the application code stored in the memory 303 to instruct the DDNMF1 network element, the DDNMF2 network element, the terminal device 1 or the terminal device 2 to execute, and this embodiment does not impose any limitation on this.

[0353] It should be noted that the embodiments of this application Figures 4 to 6 The PC5 setup process shown above can be used Figure 7The security protection method required by the terminal device when using the ProSe service obtained in the embodiment shown is Figures 4 to 6 The first security protection method in the PC5 establishment process shown can be Figure 7 In the embodiment shown, the terminal device 1 or the terminal device 2 obtains the security protection method required for using the ProSe service. Figures 4 to 6 The PC5 establishment process shown may use the security protection method obtained in the ProSe discovery process by other means, and the embodiments of the present application do not specifically limit this.

[0354] Optionally, in the embodiment of the present application, if Figure 7 The security protection method required for using the ProSe service obtained by the terminal device 1 and the terminal device 2 shown includes integrity protection being turned on, which can be achieved through Figure 7 In the embodiment shown, the first PC5 broadcast message carries Figure 4 or Figure 5 or Figure 6 In the embodiment shown, the parameters of the direct communication request transmission are such that the step of UE1 sending a direct communication request to UE2 (eg, Figure 4 Step S402 in Figure 5 Step S501 in or Figure 6 Step S601 in the flowchart can further save signaling overhead, which is described here uniformly and will not be repeated below.

[0355] like Figure 8 As shown, a communication method provided in an embodiment of the present application includes the following steps:

[0356] S801. The first terminal device obtains a first security protection method, where the first security protection method is a security protection method determined in a discovery process between the first terminal device and the second terminal device.

[0357] The specific implementation of step S801 can be found in Figure 7 The embodiments shown are not described in detail here.

[0358] It should be noted that the first terminal device in the embodiment of the present application can be Figure 7 In the embodiment shown, the terminal device 1, the second terminal device can be Figure 7 The terminal device 2 in the embodiment shown; or, the first terminal device in the embodiment of the present application can be Figure 7 In the embodiment shown, the terminal device 2, the second terminal device may be Figure 7 The terminal device 1 in the illustrated embodiment is described here in a unified manner and will not be described in detail below.

[0359] S802: The first terminal device determines a second security protection method based on the first security protection method, where the second security protection method is a security protection method for the PC5 connection between the first terminal device and the second terminal device.

[0360] The specific implementation of step S802 can be found in Figure 5 In the embodiment shown in FIG. 5 , steps S502 and S506 are shown; or, for the specific implementation of step S802, reference may be made to FIG. Figure 6 Step S602 in the illustrated embodiment will not be described in detail here.

[0361] It should be noted that, in the embodiment of the present application, the first terminal device may be Figure 5 or Figure 6 In the embodiment shown, the second terminal device may be UE2. Figure 5 or Figure 6 The UE1 in the illustrated embodiment is described here uniformly and will not be described in detail below.

[0362] Because the embodiment of the present application can refer to the first security protection method determined during the discovery process when determining the second security protection method, the security level of the second security protection method can be no lower than the security level of the first security protection method. In other words, the security level of the first security protection method is the lowest security level of the PC5 connection during the PC5 establishment process, thus achieving the goal of no security degradation.

[0363] The actions of the first terminal device in steps S801 to S802 can be performed by Figure 3 The processor 301 in the communication device 300 shown calls the application code stored in the memory 303 to instruct the first terminal device to execute it, and this embodiment does not impose any limitation on this.

[0364] like Figure 9 As shown, a communication method provided in an embodiment of the present application includes the following steps:

[0365] S901. The first terminal device obtains a first security protection method, where the first security protection method is a security protection method determined in a discovery process between the first terminal device and the second terminal device.

[0366] The specific implementation of step S801 can be found in Figure 7 The embodiments shown are not described in detail here.

[0367] It should be noted that the first terminal device in the embodiment of the present application can be Figure 7 In the embodiment shown, the terminal device 1, the second terminal device can be Figure 7 The terminal device 2 in the embodiment shown; or, the first terminal device in the embodiment of the present application can be Figure 7 In the embodiment shown, the terminal device 2, the second terminal device may be Figure 7 The terminal device 1 in the illustrated embodiment is described here in a unified manner and will not be described in detail below.

[0368] S902: The first terminal device uses a first security protection method to perform security protection on at least one message in the PC5 establishment process between the first terminal device and the second terminal device, and sends the at least one protected message to the second terminal device.

[0369] The specific implementation of step S902 can be found in Figure 4 In the embodiment shown, steps S402, S405, S407 and S409 are shown; or, the specific implementation of step S902 can refer to Figure 5 In the embodiment shown, steps S501, S503, S505 and S507 are shown; or, the specific implementation of step S902 can refer to Figure 6 Step S601 and step S604 in the illustrated embodiment are not described in detail here.

[0370] It should be noted that, in the embodiment of the present application, the first terminal device may be Figure 4 or Figure 5 or Figure 6 In the embodiment shown, the second terminal device may be UE2. Figure 4 or Figure 5 or Figure 6 UE1 in the embodiment shown; or, in the embodiment of the present application, the first terminal device may be Figure 4 or Figure 5 or Figure 6 In the embodiment shown, the second terminal device may be UE1. Figure 4 or Figure 5 or Figure 6 The UE2 in the illustrated embodiment is described here in a unified manner and will not be described in detail below.

[0371] Based on the communication system provided by the embodiment of the present application, on the one hand, when the first security protection method includes integrity protection being turned on, since the first terminal device can use the first security protection method to perform security protection on at least one message in the PC5 establishment process between the first terminal device and the second terminal device, the problem of a reduced security level caused by an attacker attacking or tampering with the message in the PC5 establishment process can be avoided, thereby improving the security level of the PC5 establishment process. On the other hand, when the security level of the first security protection method is higher than or equal to the security level of the security protection method used by the control plane of the PC5 connection between the first terminal device and the second terminal device, since the first terminal device can use the first security protection method to perform security protection on at least one message in the PC5 establishment process between the first terminal device and the second terminal device, the problem of a reduced security level caused by a security level lower than the security level of the security protection method used by the control plane of the PC5 connection can be avoided, thereby improving the security level of the PC5 establishment process.

[0372] The actions of the first terminal device in steps S901 to S902 can be performed by Figure 3 The processor 301 in the communication device 300 shown calls the application code stored in the memory 303 to instruct the first terminal device to execute it, and this embodiment does not impose any limitation on this.

[0373] like Figure 10 As shown, a communication method provided in an embodiment of the present application includes the following steps:

[0374] S1001. A first direct communication discovery name management function network element receives first information from a first terminal device and 3GPP identity information of the first terminal device, wherein the first information includes identity information for a ProSe service or information for determining identity information for a ProSe service.

[0375] S1002. The first direct communication discovery name management function network element determines the security protection method required for the first terminal device to use the ProSe service based on the first information and the 3GPP identity information of the first terminal device.

[0376] S1003. The first direct communication discovery name management function network element sends the security protection method required by the first terminal device when using the ProSe service to the first terminal device.

[0377] in, Figure 10 The specific implementation of the embodiment shown can be referred to Figure 7 The embodiments shown are not described in detail here.

[0378] It should be noted that, in the embodiment of the present application, the first direct communication discovery name management function network element may be, for example, Figure 7 The DDNMF1 network element in the first terminal device may be, for example, Figure 7 The terminal device 1 in the second direct communication discovery name management function network element can be, for example, Figure 7 The DDNMF2 network element in the second terminal device can be, for example, Figure 4 or, in the embodiment of the present application, the first direct communication discovery name management function network element may be, for example, Figure 7 The DDNMF2 network element in the first terminal device may be, for example, Figure 7 The terminal device 2 in the second direct communication discovery name management function network element can be, for example, Figure 7 The DDNMF1 network element in the second terminal device can be, for example, Figure 7 The terminal device 1 in the figure is described here as a whole and will not be described in detail below.

[0379] Based on the communication method provided in the embodiment of the present application, the first terminal device can obtain the security protection method required by the first terminal device when using the ProSe service in the discovery process between the first terminal device and the second terminal device.

[0380] Among them, the action of the first direct communication discovery name management function network element in the above steps S1001 to S1003 can be performed by Figure 3 The processor 301 in the communication device 300 shown calls the application code stored in the memory 303 to instruct the first direct communication discovery name management function network element of the first terminal device to execute, and this embodiment does not impose any limitation on this.

[0381] It is understandable that Figures 4 to 10 In the embodiment shown, the first terminal device (such as Figures 4 to 6 UE1 or UE2 in the embodiment shown, or Figure 7 The terminal device 1 or terminal device 2 in the embodiment shown, or Figure 8 or Figure 9 The method and / or steps implemented by the first terminal device in the embodiment shown in the figure may also be implemented by a component (such as a chip or circuit) that can be used for the first terminal device; the first direct communication discovery name management function network element (such as Figure 7 The DDNMF1 network element or DDNMF network element in the embodiment shown, or Figure 10 The method and / or steps implemented by the first direct communication discovery name management function network element in the illustrated embodiment may also be implemented by components (eg, chips or circuits) that may be used in the first direct communication discovery name management function network element.

[0382] The above mainly introduces the solutions provided by the embodiments of the present application from the perspective of interaction between various network elements. Accordingly, the embodiments of the present application also provide a communication device, which can be the first terminal device in the above method embodiment, or a device including the above first terminal device, or a component that can be used for the first terminal device; or, the communication device can be the first direct communication discovery name management function network element in the above method embodiment, or a device including the above first direct communication discovery name management function network element, or a component that can be used for the first direct communication discovery name management function network element. It is understandable that, in order to implement the above functions, the communication device includes hardware structures and / or software modules corresponding to executing each function. Those skilled in the art should readily appreciate that, in combination with the various exemplary units and algorithm steps described in the embodiments disclosed herein, the present application can be implemented in hardware or a combination of hardware and computer software. Whether a function is implemented in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0383] Figure 11 1 shows a schematic structural diagram of a communication device 110. The communication device 110 includes a transceiver module 1101 and a processing module 1102. The transceiver module 1101, also called a transceiver unit, is used to implement transceiver functions, and can be, for example, a transceiver circuit, a transceiver, a transceiver, or a communication interface.

[0384] Taking the communication device 110 as the first terminal device in the above method embodiment or a chip or other component provided in the first terminal device as an example, in a possible implementation manner:

[0385] Processing module 1102 is configured to obtain a first security protection method, where the first security protection method is the security protection method determined during the discovery process between the first terminal device and the second terminal device. Processing module 1102 is further configured to determine a second security protection method based on the first security protection method, where the second security protection method is the security protection method for the PC5 connection between the first terminal device and the second terminal device.

[0386] Optionally, the security level of the second security protection method is not lower than the security level of the first security protection method.

[0387] Optionally, the processing module 1102 is configured to determine a second security protection method based on the first security protection method, including: determining the first security protection method as the second security protection method.

[0388] Optionally, the processing module 1102 is used to determine the second security protection method based on the first security protection method, including: receiving a second security policy from the second terminal device through the transceiver module 1101, the second security policy being the security policy of the second terminal device in the PC5 connection; determining the second security protection method based on the second security policy and the first security protection method.

[0389] Optionally, the processing module 1102 is used to determine the second security protection method based on the second security policy and the first security protection method, including: when the first security protection method satisfies the second security policy, determining the first security protection method as the second security protection method; or, when the first security protection method satisfies the second security policy, selecting a security protection method with a security level not lower than the first security protection method as the first security protection method according to the second security policy; or, when the first security protection method does not satisfy the second security policy, selecting a security protection method that satisfies the second security policy as the second security protection method according to the second security policy.

[0390] Optionally, the second security policy includes a second control plane security policy and / or a second user plane security policy; wherein, the second control plane security policy is the control plane security policy of the second terminal device in the PC5 connection, and the second user plane security policy is the user plane security policy of the second terminal device in the PC5 connection.

[0391] Optionally, the second security protection method is used to perform security protection on part or all of the parameters transmitted in the control plane signaling of the PC5 connection; and / or, the second security protection method is used to perform security protection on part or all of the user plane data of the PC5 connection.

[0392] Optionally, the transceiver module 1101 is also used to receive a first message from the second terminal device, where the first message is the first message in the PC5 establishment process between the first terminal device and the second terminal device; the processing module 1102 is also used to decrypt the first message using the first security protection method.

[0393] Optionally, the processing module 1102 is configured to obtain a first security protection method, including: sending, through the transceiver module 1101, first information and 3GPP identity information of the first terminal device to a first direct communication discovery name management function network element, where the first information includes identity information for a ProSe service or information used to determine identity information for a ProSe service;

[0394] The first security protection method is received from the first direct communication discovery name management function network element through the transceiver module 1101.

[0395] Alternatively, taking the communication device 110 as the first terminal device in the above method embodiment or a chip or other component provided in the first terminal device as an example, in another possible implementation manner:

[0396] Processing module 1102 is configured to obtain a first security protection method, where the first security protection method is a security protection method determined during the discovery process between the first terminal device and the second terminal device. Processing module 1102 is further configured to use the first security protection method to perform security protection on at least one message during the PC5 establishment process between the first terminal device and the second terminal device. Transceiver module 1101 is configured to send the at least one message after security protection to the second terminal device.

[0397] Optionally, the at least one message includes a first message, and the first message is the first message in the PC5 establishment process.

[0398] Optionally, the at least one message further includes a third message, where the third message is a message sent by the first terminal device in the PC5 establishment process for negotiating a security protection method to be used for a user plane of a PC5 connection between the first terminal device and the second terminal device. The processing module 1102 is configured to perform security protection on the at least one message in the PC5 establishment process using the first security protection method, including: performing security protection on the first message using the first security protection method; and, if the security level of the security protection method used for the control plane of the PC5 connection is lower than the security level of the first security protection method, performing security protection on the third message using the first security protection method.

[0399] Optionally, before the processing module 1102 uses the first security protection method to perform security protection on the third message, the transceiver module 1101 is also used to receive a second message from the second terminal device, where the second message includes the security algorithm of the control plane of the PC5 connection selected by the second terminal device; the processing module 1102 is also used to determine, based on the security algorithm of the control plane of the PC5 connection, that the security level of the security protection method used by the control plane of the PC5 connection is lower than the security level of the first security protection method.

[0400] Optionally, at least one message includes a fourth message, which is a message sent by the first terminal device in the PC5 establishment process for negotiating the security protection method used by the user plane of the PC5 connection between the first terminal device and the second terminal device; the processing module 1102 is used to use the first security protection method to perform security protection on at least one message in the PC5 establishment process, including: after determining that the security level of the security protection method used by the control plane of the PC5 connection is lower than the security level of the first security protection method, use the first security protection method to perform security protection on the fourth message.

[0401] Optionally, the processing module 1102 is further configured to determine a second security protection method based on the first security protection method, where the second security protection method is a security protection method for the PC5 connection between the first terminal device and the second terminal device.

[0402] Optionally, the security level of the second security protection method is not lower than the security level of the first security protection method.

[0403] Optionally, the processing module 1102 is used to determine the second security protection method based on the first security protection method, including: receiving a second security policy from the second terminal device through the transceiver module 1101, the second security policy being the security policy of the second terminal device in the PC5 connection; determining the second security protection method based on the second security policy and the first security protection method.

[0404] Optionally, the processing module 1102 is used to determine the second security protection method based on the second security policy and the first security protection method, including: when the first security protection method satisfies the second security policy, determining the first security protection method as the second security protection method; or, when the first security protection method satisfies the second security policy, selecting a security protection method with a security level not lower than the first security protection method as the first security protection method according to the second security policy; or, when the first security protection method does not satisfy the second security policy, selecting a security protection method that satisfies the second security policy as the second security protection method according to the second security policy.

[0405] Optionally, the processing module 1102 is used to obtain a first security protection method, including: sending first information and 3GPP identity information of a first terminal device to a first direct communication discovery name management function network element through the transceiver module 1101, the first information including identity information for the ProSe service or information for determining the identity information for the ProSe service; receiving the first security protection method from the first direct communication discovery name management function network element through the transceiver module 1101.

[0406] Alternatively, taking the communication device 110 as the first direct communication discovery name management function network element in the above method embodiment or a chip or other component provided in the first direct communication discovery name management function network element as an example, in a possible implementation manner:

[0407] The transceiver module 1101 is configured to receive first information from a first terminal device and 3GPP identity information of the first terminal device, wherein the first information includes identity information for a ProSe service or information used to determine identity information for a ProSe service. The processing module 1102 is configured to determine, based on the first information and the 3GPP identity information of the first terminal device, a security protection method required for the first terminal device to use the ProSe service. The transceiver module 1101 is further configured to send, to the first terminal device, the security protection method required for the first terminal device to use the ProSe service.

[0408] Optionally, the processing module 1102 is used to determine the security protection method required for the first terminal device when using the ProSe service based on the first information and the 3GPP identity information of the first terminal device, including: determining a plurality of optional security protection methods corresponding to when the first terminal device uses the ProSe service based on the first information and the 3GPP identity information of the first terminal device; and determining the security protection method required for the first terminal device when using the ProSe service based on the plurality of optional security protection methods.

[0409] Optionally, the processing module 1102 is further used to obtain the security protection method required by the second terminal device when using the ProSe service from the second direct communication discovery name management function network element; the processing module 1102 is used to determine the security protection method required by the first terminal device when using the ProSe service based on multiple optional security protection methods, including: determining whether the multiple optional security protection methods include the security protection method required by the second terminal device when using the ProSe service; when the multiple optional security protection methods include the security protection method required by the second terminal device when using the ProSe service, determining the security protection method required by the second terminal device when using the ProSe service as the security protection method required by the first terminal device when using the ProSe service; or, when the multiple optional security protection methods do not include the security protection method required by the second terminal device when using the ProSe service, determining the security protection method required by the first terminal device when using the ProSe service from the multiple optional security protection methods.

[0410] Optionally, the security protection method required when using the ProSe service is used to perform security protection on the fifth message, where the fifth message is the first PC5 broadcast message in the discovery process between the first terminal device and the second terminal device.

[0411] Optionally, the security protection method required when using the ProSe service is used to determine the security protection method of the PC5 connection between the first terminal device and the second terminal device.

[0412] Optionally, the security protection method for the PC5 connection is used to securely protect part or all of the parameters transmitted in the control plane signaling of the PC5 connection; and / or, the security protection method for the PC5 connection is used to securely protect part or all of the user plane data of the PC5 connection.

[0413] Optionally, the security protection method required when using the ProSe service is used to securely protect at least one message in the PC5 establishment process between the first terminal device and the second terminal device.

[0414] Optionally, the at least one message includes a first message, and the first message is the first message in the PC5 establishment process.

[0415] Among them, all relevant contents of each step involved in the above method embodiment can be referred to the functional description of the corresponding functional module and will not be repeated here.

[0416] In this embodiment, the communication device 110 is presented in the form of various functional modules divided in an integrated manner. Here, "module" may refer to a specific ASIC, circuit, processor and memory that executes one or more software or firmware programs, integrated logic circuit, and / or other devices that can provide the above functions. In a simple embodiment, those skilled in the art can imagine that the communication device 110 can be used. Figure 3 The form of the communication device 300 is shown.

[0417] for example, Figure 3 The processor 301 in the communication device 300 shown can call the computer-executable instructions stored in the memory 303 to enable the communication device 300 to execute the communication method in the above method embodiment.

[0418] Specifically, Figure 11 The functions / implementation processes of the transceiver module 1101 and the processing module 1102 can be realized by Figure 3 The processor 301 in the communication device 300 shown calls the computer execution instructions stored in the memory 303 to implement. Or, Figure 11 The function / implementation process of the processing module 1102 can be achieved by Figure 3 The processor 301 in the communication device 300 shown calls the computer execution instructions stored in the memory 303 to implement, Figure 11 The function / implementation process of the transceiver module 1101 can be achieved by Figure 3 The communication interface 304 in the communication device 300 shown in FIG.

[0419] Since the communication device 110 provided in this embodiment can execute the above communication method, the technical effects that can be obtained can refer to the above method embodiments and will not be repeated here.

[0420] It should be noted that one or more of the above modules or units can be implemented by software, hardware, or a combination of the two. When any of the above modules or units is implemented by software, the software exists in the form of computer program instructions and is stored in a memory, and a processor can be used to execute the program instructions and implement the above method flow. The processor can be built into an SoC (system on chip) or an ASIC, or it can be an independent semiconductor chip. In addition to the core used to execute software instructions to perform calculations or processing within the processor, it can further include necessary hardware accelerators, such as a field programmable gate array (FPGA), a PLD (programmable logic device), or a logic circuit that implements dedicated logic operations.

[0421] When the above modules or units are implemented in hardware, the hardware can be any one or any combination of a CPU, a microprocessor, a digital signal processing (DSP) chip, a microcontroller unit (MCU), an artificial intelligence processor, an ASIC, a SoC, an FPGA, a PLD, a dedicated digital circuit, a hardware accelerator or a non-integrated discrete device, which can run the necessary software or not rely on the software to execute the above method flow.

[0422] Optionally, an embodiment of the present application further provides a communication device (for example, the communication device may be a chip or a chip system), which includes a processor for implementing the method in any of the above method embodiments. In one possible implementation, the communication device also includes a memory. The memory is used to store necessary program instructions and data, and the processor can call the program code stored in the memory to instruct the communication device to execute the method in any of the above method embodiments. Of course, the memory may not be in the communication device. When the communication device is a chip system, it may be composed of a chip, or it may include a chip and other discrete devices, which is not specifically limited in the embodiment of the present application.

[0423] In the above embodiments, all or part of the embodiments may be implemented by software, hardware, firmware, or any combination thereof. When implemented using a software program, all or part of the embodiments may be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present application are generated. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium may be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more media integrated therein. The available medium may be a magnetic medium (eg, a floppy disk, a hard disk, a magnetic tape), an optical medium (eg, a DVD), or a semiconductor medium (eg, a solid state disk (SSD)).

[0424] Although the present application is described herein in conjunction with various embodiments, in the process of implementing the claimed application, those skilled in the art can understand and implement other changes to the disclosed embodiments by reviewing the drawings, the disclosure, and the appended claims. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "an" does not exclude multiple situations. A single processor or other unit can implement several functions listed in the claims. Certain measures are recorded in different dependent claims, but this does not mean that these measures cannot be combined to produce good results.

[0425] Although the present application has been described with reference to specific features and embodiments thereof, it is apparent that various modifications and combinations may be made thereto without departing from the spirit and scope of the present application. Accordingly, this specification and the drawings are merely illustrative of the present application as defined by the appended claims and are deemed to cover any and all modifications, variations, combinations or equivalents within the scope of the present application. Obviously, those skilled in the art may make various modifications and variations to the present application without departing from the spirit and scope of the present application. Thus, the present application is intended to include such modifications and variations as fall within the scope of the claims of the present application and their equivalents.

Claims

1. A communication method, characterized in that: The method comprises: The first terminal device obtains a first security protection method, where the first security protection method is a security protection method determined in a discovery process between the first terminal device and the second terminal device; The first terminal device uses the first security protection method to perform security protection on at least one message in the PC5 establishment process between the first terminal device and the second terminal device; The first terminal device sends at least one security-protected message to the second terminal device.

2. The method according to claim 1, characterized in that The at least one message includes a first message, and the first message is the first message in the PC5 establishment process.

3. The method according to claim 2, characterized in that The at least one message further includes a third message, where the third message is a message sent by the first terminal device in the PC5 establishment process and is used to negotiate a security protection method used for a user plane of a PC5 connection between the first terminal device and the second terminal device; The first terminal device uses the first security protection method to perform security protection on at least one message in the PC5 establishment process, including: The first terminal device performs security protection on the first message using the first security protection method; as well as, In a case where the security level of the security protection method used by the control plane to which the PC 5 is connected is lower than the security level of the first security protection method, the first terminal device uses the first security protection method to perform security protection on the third message.

4. The method according to claim 3, characterized in that The method further comprises: The first terminal device receives a second message from the second terminal device, where the second message includes a security algorithm of the control plane connected to the PC5 selected by the second terminal device; The first terminal device determines, based on a security algorithm of the control plane connected to the PC5, that a security level of a security protection method used by the control plane connected to the PC5 is lower than a security level of the first security protection method.

5. The method according to claim 1, characterized in that The at least one message includes a fourth message, where the fourth message is a message sent by the first terminal device in the PC5 establishment process and is used to negotiate a security protection method used for a user plane of a PC5 connection between the first terminal device and the second terminal device; The first terminal device uses the first security protection method to perform security protection on at least one message in the PC5 establishment process, including: The first terminal device determines that the security level of the security protection method used by the control plane connected to the PC5 is lower than the security level of the first security protection method; The first terminal device uses the first security protection method to perform security protection on the fourth message.

6. The method according to claim 1 or 2, characterized in that The method further comprises: The first terminal device determines a second security protection method according to the first security protection method, where the second security protection method is a security protection method for a PC5 connection between the first terminal device and the second terminal device.

7. The method according to claim 6, characterized in that The security level of the second security protection method is not lower than the security level of the first security protection method.

8. The method according to claim 6, characterized in that The first terminal device determines a second security protection method according to the first security protection method, including: The first terminal device receives a second security policy from the second terminal device, where the second security policy is a security policy of the second terminal device in the connection with the PC5; The first terminal device determines the second security protection method according to the second security policy and the first security protection method.

9. The method according to claim 7, characterized in that The first terminal device determines a second security protection method according to the first security protection method, including: The first terminal device receives a second security policy from the second terminal device, where the second security policy is a security policy of the second terminal device in the connection with the PC5; The first terminal device determines the second security protection method according to the second security policy and the first security protection method.

10. The method according to claim 8 or 9, characterized in that The first terminal device determines the second security protection method according to the second security policy and the first security protection method, including: In the case where the first security protection method satisfies the second security policy, determining the first security protection method as the second security protection method; or, In the case where the first security protection method satisfies the second security policy, selecting a security protection method with a security level not lower than that of the first security protection method as the first security protection method according to the second security policy; or In the case that the first security protection method does not satisfy the second security policy, a security protection method that satisfies the second security policy is selected as the second security protection method according to the second security policy.

11. The method according to any one of claims 1-5 or 7-9, characterized in that: The first terminal device obtains a first security protection method, including: The first terminal device sends first information and Third Generation Partnership Project 3GPP identity information of the first terminal device to a first direct communication discovery name management function network element, where the first information includes identity information for a ProSe service or information used to determine the identity information for the ProSe service; The first terminal device receives the first security protection method from a first direct communication discovery name management function network element.

12. The method according to claim 6, characterized in that The first terminal device obtains a first security protection method, including: The first terminal device sends first information and Third Generation Partnership Project 3GPP identity information of the first terminal device to a first direct communication discovery name management function network element, where the first information includes identity information for a ProSe service or information used to determine the identity information for the ProSe service; The first terminal device receives the first security protection method from a first direct communication discovery name management function network element.

13. The method according to any one of claims 1-5 or 7-9, characterized in that: The first terminal device is a user equipment UE or a chip in the UE.

14. A terminal device, characterized in that: The method comprises modules for executing the method according to any one of claims 1 to 13.

15. The terminal device according to claim 14, characterized in that The terminal device is a user equipment UE or a chip in the UE.

16. A terminal device, characterized in that: The terminal device includes: a processor and an interface circuit; The interface circuit is used to receive computer programs or instructions and transmit them to the processor; The processor is configured to execute the computer program or instruction to enable the communication device to perform the method according to any one of claims 1 to 13.

17. A computer-readable storage medium, characterized in that The method comprises instructions, which, when executed on a communication device, enable the communication device to perform the method according to any one of claims 1 to 13.

18. A computer program product comprising instructions, characterized in that When the method is executed on a computer, the computer is enabled to execute the method according to any one of claims 1 to 13.