Communication method, device and equipment

Through the autonomous configuration of access network devices and verification of terminal devices, the security risks of SNPN credentials caused by policy neglect in ONN are resolved, and effective protection of SNPN credentials is achieved.

CN115843438BActive Publication Date: 2025-09-09BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202180002206.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-07-19
Publication Date
2025-09-09
Estimated Expiration
2041-07-19

AI Technical Summary

Technical Problem

How to protect the credentials of terminal devices when logging into a standalone non-public network (SNPN), especially in an access network (ONN), to avoid the risk of credential leakage caused by disguised or faulty access network devices ignoring security policies.

Method used

The access network device autonomously configures the user plane security policy on the Uu interface as 'required', indicating user plane encryption and/or integrity protection of the data radio bearer (DRB). The terminal device verifies whether the indication information meets the security requirements and rejects requests that do not meet the requirements.

Benefits of technology

It effectively protects the security of SNPN credentials, prevents the risk of leakage caused by policy neglect in access network devices, and ensures the security of credential transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115843438B_ABST
    Figure CN115843438B_ABST
Patent Text Reader

Abstract

The present disclosure provides a communication method, apparatus and device. The communication method can be applied to a communication system, such as an on-line network (ONN) system. The method may include: an access network device receives a registration request message from a terminal device, and the establishment reason information carried in the registration request message is a login to a standalone non-public network (SNPN); the access network device configures the user plane security policy of the terminal device as a first security policy based on the establishment reason information, so as to indicate the activation of user plane encryption protection and / or user plane integrity protection for the DRB belonging to the PDU session. In the present disclosure, the access network device autonomously configures the UP security policy on the Uu interface to indicate the activation of user plane encryption protection and / or user plane integrity protection for the DRB belonging to the PDU session used to transmit the SNPN credentials, thereby protecting the SNPN credentials.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of wireless communication technologies, and in particular to a communication method, apparatus, and device. Background Art

[0002] With the continuous development of wireless communication technology, a standalone non-public network (SNPN) is a network in the fifth generation (5G) communication system that is different from the public network and provides services for specific users or organizations.

[0003] Currently, a terminal device needs to provide SNPN credentials to log in (onboarding) SNPN. Previously, the terminal device could obtain SNPN credentials by accessing an onboarding network (ONN).

[0004] So, how to protect SNPN credentials is an urgent problem to be solved. Summary of the Invention

[0005] The present disclosure provides a communication method, apparatus, and device to protect SNPN credentials through user plane security policies.

[0006] In a first aspect, the present disclosure provides a communication method that can be applied to an open network (ONN), where the ONN is used to transmit SNPN credentials. The method may include: an access network device receiving a registration request message from a terminal device, the registration request message carrying establishment reason information, where the establishment reason information is logging into the SNPN; and the access network device configuring, based on the establishment reason information, a user plane security policy of the terminal device to a first security policy, where the first security policy is used to indicate activation of user plane encryption protection and / or user plane integrity protection for a data radio bearer (DRB) belonging to a protocol data unit (PDU) session.

[0007] In the present disclosure, the above-mentioned PDU session is used to transmit SNPN credentials.

[0008] In some possible implementations, the first security policy includes a first field; the first field is used to indicate that user plane encryption protection and / or user plane integrity protection must be activated (“required”).

[0009] In some possible implementations, after the access network device receives the registration request message from the terminal device, the method further includes: the access network device associates and stores identification information (such as C-RNTI) allocated to the terminal device with the establishment cause information.

[0010] In some possible implementations, after the access network device configures the user plane security policy of the terminal device as the first security policy based on the establishment reason information, the above method also includes: the access network device receives a PDU session establishment acceptance message from the first core network device belonging to the ONN, the PDU session establishment acceptance message requests to establish a PDU session for transmitting SNPN credentials, and the PDU session establishment acceptance message carries the identification information of the terminal device; the access network device determines that the user plane security policy of the terminal device is configured as the first security policy based on the identification information of the terminal device; the access network device starts the first security policy for the terminal device.

[0011] In some possible implementations, after the access network device determines that the user plane security policy of the terminal device is configured as the first security policy based on the identification information of the terminal device, the above method also includes: the access network device sends a first indication information to the terminal device, and the first indication information is used to indicate the activation of user plane encryption protection and / or user plane integrity protection for DRB.

[0012] In some possible implementations, the above method further includes: the access network device receiving the user plane security policy of the terminal device indicated by the second core network device belonging to the ONN; the access network device ignoring (overruling) the user plane security policy of the terminal device indicated by the second core network device.

[0013] In a second aspect, the present disclosure provides a communication method that can be applied to an open network (ONN), where the ONN is used to transmit an SNPN credential. The method may include: a terminal device receiving second indication information from an access network device, the second indication information being used to indicate whether user plane encryption protection and / or user plane integrity protection are activated for a data radio bearer (DRB) belonging to a protocol data unit (PDU) session; the terminal device verifying whether the second indication information meets security requirements for protecting the SNPN credential; and the terminal device determining whether user plane encryption protection and / or user plane integrity protection are activated for the DRB based on the verification result.

[0014] In the present disclosure, the above-mentioned PDU session is used to transmit SNPN credentials.

[0015] In some possible implementations, the terminal device determines whether to start user plane encryption protection and / or user plane integrity protection for the DRB based on the verification result, including: when the verification result shows that the second indication information does not meet the security requirements, the terminal device rejects the radio resource control RRC connection reconfiguration request from the access network device; or when the verification result shows that the second indication information meets the security requirements, the terminal device starts user plane encryption protection and / or user plane integrity protection for the DRB.

[0016] In some possible implementations, the terminal device verifies whether the second indication information meets the security requirements for protecting independent non-public network credentials, including: the terminal device verifies whether the second indication information indicates whether user plane encryption protection and / or user plane integrity protection is activated for the DRB; wherein, when the second indication information indicates deactivation of user plane encryption protection and / or user plane integrity protection for the DRB on the terminal device side, it indicates that the second indication information does not meet the security requirements; when the second indication information indicates activation of user plane encryption protection and user plane integrity protection for the DRB on the terminal device side, it indicates that the second indication information meets the security requirements.

[0017] In some possible implementations, the second indication information is carried in an RRC connection reconfiguration message (RRC Connection Reconfiguration) sent by the access network device.

[0018] In a third aspect, the present disclosure provides a communication device, which may be an access network device (such as a gNB) in the above-mentioned communication system or a chip or system on chip in the access network device, or a functional module in the access network device for implementing the methods described in the above-mentioned various aspects. The communication device can implement the functions performed by the access network device in the above-mentioned various aspects, and these functions can be implemented by hardware executing corresponding software. These hardware or software include one or more modules corresponding to the above-mentioned functions. The communication device includes: a first receiving module for receiving a registration request message from a terminal device, the registration request message carrying establishment reason information, and the establishment reason information is logging into an independent non-public network; a first processing module for configuring the user plane security policy of the terminal device to a first security policy based on the establishment reason information, the first security policy being used to indicate activation of user plane encryption protection and / or user plane integrity protection for a data radio bearer DRB belonging to a protocol data unit PDU session.

[0019] In some possible implementations, the first security policy includes a first field; the first field is used to indicate that user plane encryption protection and / or user plane integrity protection must be activated (“required”).

[0020] In some possible implementations, the first processing module is further configured to associate and store identification information (such as C-RNTI) allocated to the terminal device with the establishment cause information after the first receiving module receives the registration request message from the terminal device.

[0021] In some possible implementations, the first receiving module is further used for the first processing module to receive a PDU session establishment acceptance message from a first core network device belonging to the ONN after configuring the user plane security policy of the terminal device as the first security policy according to the establishment reason information, the PDU session establishment acceptance message requests establishment of a PDU session for transmitting SNPN credentials, and the PDU session establishment acceptance message carries identification information of the terminal device; the first processing module is further used to determine, based on the identification information of the terminal device, that the user plane security policy of the terminal device is configured as the first security policy; and start the first security policy for the terminal device.

[0022] In some possible implementations, the communication device further includes a first sending module configured to send first indication information to the terminal device after the first processing module determines, based on identification information of the terminal device, that the user plane security policy of the terminal device is configured as the first security policy, the first indication information being used to indicate activation of user plane encryption protection and / or user plane integrity protection for the DRB.

[0023] In some possible implementations, the first receiving module is further configured to receive a user plane security policy of the terminal device indicated by a second core network device belonging to the ONN; the first processing module is further configured to overrule the user plane security policy of the terminal device indicated by the second core network device.

[0024] In a fourth aspect, the present disclosure provides a communication device, which may be a terminal device (such as UE) in the above-mentioned communication system or a chip or system on chip in the terminal device, or a functional module in the terminal device for implementing the methods described in the above-mentioned various aspects. The communication device can implement the functions performed by the terminal device in the above-mentioned various aspects, and these functions can be implemented by hardware executing corresponding software. These hardware or software include one or more modules corresponding to the above-mentioned functions. The communication device includes: a second receiving module for receiving second indication information from an access network device, wherein the second indication information is used to indicate whether user plane encryption protection and / or user plane integrity protection is activated for a data radio bearer DRB belonging to a protocol data unit PDU session; a second processing module for the terminal device to verify whether the second indication information meets the security requirements for protecting independent non-public network credentials; and determine whether to start user plane encryption protection and / or user plane integrity protection for the DRB based on the verification result.

[0025] In some possible embodiments, the second processing module is used to reject the radio resource control RRC connection reconfiguration request from the access network device when the verification result shows that the second indication information does not meet the security requirements; or to start user plane encryption protection and / or user plane integrity protection of the DRB when the verification result shows that the second indication information meets the security requirements.

[0026] In some possible embodiments, the second processing module is used to verify whether the second indication information indicates whether user plane encryption protection and / or user plane integrity protection is activated for the DRB; wherein, when the second indication information indicates deactivation of user plane encryption protection and / or user plane integrity protection for the DRB on the terminal device side, it indicates that the second indication information does not meet the security requirements; when the second indication information indicates activation of user plane encryption protection and user plane integrity protection for the DRB on the terminal device side, it indicates that the second indication information meets the security requirements.

[0027] In some possible implementations, the second indication information is carried in an RRC connection reconfiguration message (RRC Connection Reconfiguration) sent by the access network device.

[0028] In a fifth aspect, the present disclosure provides an access network device, comprising: a memory; a processor, connected to the memory, and configured to execute computer-executable instructions stored on the memory to implement a communication method as described in any one of the first aspect, the second aspect and possible implementations thereof.

[0029] In a sixth aspect, the present disclosure provides a terminal device, comprising: a memory; and a processor, connected to the memory, configured to execute computer-executable instructions stored on the memory to implement a communication method as described in any one of the first aspect, the second aspect, and possible implementations thereof.

[0030] In the seventh aspect, the present disclosure provides a computer storage medium and a processing module, which are used for storing computer-executable instructions on the computer storage medium, characterized in that after the computer-executable instructions are executed by the processor, they can implement the communication method as described in any one of the first aspect, the second aspect and their possible implementation methods.

[0031] In the present disclosure, the access network device can autonomously configure the UP security policy on the Uu interface, and configure the security policy of the PDU session used to transmit the SNPN certificate as "required" to indicate the activation of the user plane encryption protection and / or user plane integrity protection of the DRB of the PDU session, thereby protecting the SNPN certificate. Furthermore, the terminal device can verify whether the security activation instruction issued by the access network device meets the security requirements for protecting the SNPN certificate. When the security activation instruction issued by the access network device does not meet the security requirements for protecting the SNPN certificate, the terminal device can reject the request of the access network device to avoid the security risks of the SNPN certificate and protect the SNPN certificate.

[0032] It should be understood that the third to seventh aspects of the present disclosure are consistent with the technical solutions of the first to second aspects of the present disclosure, and the beneficial effects achieved by each aspect and the corresponding feasible implementation methods are similar, which will not be repeated. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] Figure 1 is a schematic structural diagram of a communication system in an embodiment of the present disclosure;

[0034] Figure 2 Schematic diagram of an architecture represented by reference points in a non-roaming 5G network in an embodiment of the present disclosure;

[0035] Figure 3 Schematic diagram of an architecture based on a service-based interface in a non-roaming 5G network according to an embodiment of the present disclosure;

[0036] Figure 4 Schematic diagram of an implementation flow of a communication method in an embodiment of the present disclosure;

[0037] Figure 5 is a flow chart of another communication method in an embodiment of the present disclosure;

[0038] Figure 6 Schematic diagram of an implementation flow of another communication method in an embodiment of the present disclosure;

[0039] Figure 7 Schematic diagram of the structure of a communication device in an embodiment of the present disclosure;

[0040] Figure 8 is a structural diagram of another communication device in an embodiment of the present disclosure;

[0041] Figure 9 is a schematic structural diagram of a communication device in an embodiment of the present disclosure;

[0042] Figure 10 is a schematic structural diagram of a terminal device in an embodiment of the present disclosure;

[0043] Figure 11 A schematic diagram of the structure of an access network device in an embodiment of the present disclosure. DETAILED DESCRIPTION

[0044] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements, unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all possible implementations consistent with the present disclosure. Rather, they are merely examples of apparatuses and methods consistent with certain aspects of the present disclosure, as detailed in the appended claims.

[0045] The terms used in the embodiments of the present disclosure are for the purpose of describing specific embodiments only and are not intended to limit the embodiments of the present disclosure. The singular forms "a," "an," and "the" used in the embodiments of the present disclosure and the appended claims are also intended to include plural forms unless the context clearly indicates otherwise. It should also be understood that the term "and / or" as used herein refers to and includes any or all possible combinations of one or more associated listed items.

[0046] It should be understood that although the terms "first," "second," "third," etc. may be used to describe various information in the embodiments of the present disclosure, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from each other. For example, without departing from the scope of the embodiments of the present disclosure, "first information" may also be referred to as "second information," and similarly, "second information" may also be referred to as "first information." Depending on the context, the word "if" as used herein may be interpreted as "at the time of" or "when" or "in response to determining."

[0047] Furthermore, in the description of the embodiments of the present disclosure, "and / or" is merely a description of the association relationship between associated objects, indicating that three relationships can exist. For example, "A and / or B" can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone. Furthermore, in the description of the embodiments of the present disclosure, "plurality" can refer to two or more than two.

[0048] With the development of wireless communication technology, 5GS (i.e., 5G system) can support SNPN. To enhance support for terminal devices to log in to SNPN, the terminal device needs to provide SNPN credentials (and / or other information) for authentication, and then log in to the SNPN required by the terminal device. Therefore, before this, the terminal device should be allowed to access ONN to obtain SNPN credentials.

[0049] An embodiment of the present disclosure provides a communication system, which can be applied to the above-mentioned ONN. Figure 1This is a schematic diagram of the structure of the communication system in the embodiment of the present disclosure, see Figure 1 As shown, the communication system 100 may include a 5G access network (AN) and a 5G core network (5GC). The 5G access network may include a next generation radio access network (NG RAN) 101, which communicates with a terminal device 102 via a Uu interface. The 5G core network 103 may include an access and mobility management function (AMF) 1031, a user plane function (UPF) 1032, a session management function (SMF) 1033, a policy control function (PCF) 1034, and a unified data management (UDM) 1035.

[0050] In the embodiment of the present disclosure, the above-mentioned communication system may further include other network elements, which is not specifically limited in the embodiment of the present disclosure.

[0051] In the above communication system, the terminal device can access the 5G core network through the 3rd Generation Partnership Project (3GPP) technology. Specifically, the terminal device can access the 5G core network through the 3GPP access network device.

[0052] In the above communication system, UDM has the function of unified data management, mainly responsible for managing contract data, user access authorization and other functions.

[0053] The PCF has a policy control function and is mainly responsible for policy decisions related to charging policies for sessions and business flows, quality of service (QoS), bandwidth guarantees, and policies. In this architecture, the PCF connected to the AMF and SMF can correspond to the AM PCF (PCF for access and mobility control) and SM PCF (PCF for session management), respectively. In actual deployment scenarios, the AM PCF and SM PCF may not be the same PCF entity.

[0054] SMF has session management functions, mainly performing session management, execution of control policies issued by PCF, selection of UPF, and allocation of Internet Protocol (IP) addresses to UEs.

[0055] The AMF has access and mobility management functions, mainly performing mobility management, access authentication / authorization, etc. In addition, it is also responsible for transmitting user policies between the UE and the PCF.

[0056] UPF is a user plane functional entity that serves as an interface with the data network and performs functions such as user plane (UP) data forwarding, session / flow-level billing statistics, and bandwidth limitation.

[0057] The functions of each interface are described as follows:

[0058] N7: The interface between PCF and SMF, used to deliver control policies for packet data unit (PDU) session granularity and service data flow granularity.

[0059] N3: Communication interface between UPF and NG-RAN.

[0060] N15: Interface between PCF and AMF, used to deliver UE policies and access control related policies.

[0061] N4: Interface between SMF and UPF, used to transmit information between the control plane and UP, including controlling the delivery of forwarding rules, QoS control rules, traffic statistics rules, etc. for UP, and reporting UP information.

[0062] N11: The interface between SMF and AMF, used to transfer PDU session tunnel information between RAN and UPF, transfer control messages sent to UE, transfer radio resource control information sent to RAN, etc.

[0063] N2: The interface between AMF and NG-RAN, used to transmit radio bearer control information from the core network side to NG-RAN.

[0064] N1: The interface between AMF and UE, which is not related to access and is used to deliver QoS control rules to UE.

[0065] N8: Interface between AMF and UDM, used by AMF to obtain access and mobility management related subscription data and authentication data from UDM, and AMF to register UE current mobility management related information with UDM.

[0066] N10: Interface between SMF and UDM, used by SMF to obtain session management-related subscription data from UDM, and for SMF to register UE current session-related information with UDM.

[0067] The terminal device may be a terminal device with wireless communication capabilities, and may also be referred to as user equipment (UE). The terminal device may be deployed on land, including indoors or outdoors, handheld, wearable, or vehicle-mounted; it may also be deployed on water (such as ships); it may also be deployed in the air (such as airplanes, balloons, and satellites). The terminal device may be a mobile phone, a tablet computer, a computer with wireless transceiver capabilities, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical care, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, a wireless terminal in a smart home, and the like. The terminal device may also be a handheld device with wireless communication capabilities, a vehicle-mounted device, a wearable device, a computing device, or other processing device connected to a wireless modem. Optionally, the terminal device may be called different names in different networks, such as: terminal device, access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent or user device, cellular phone, cordless phone, session initiation protocol (SIP) phone, wireless local loop (WLL) station, personal digital assistant (PDA), terminal device in 5G network or future evolution network, etc.

[0068] The access network device may be a device on the access network side used to support terminal access to a wireless communication system. For example, it may be a next generation nodeB (gNB), a transmission reception point (TRP), a relay node, an access point (AP), etc. in a 5G access technology communication system.

[0069] It should be noted that in Figure 1 In the communication system shown, the functions and interfaces of each device are only exemplary. Not all functions of each device are necessary when applied in the embodiments of the present disclosure. All or part of the core network devices can be physical entities or virtualized devices, which is not limited here. Of course, the communication system in the embodiments of the present disclosure can also include Figure 1 Other devices shown in are not limited here.

[0070] In some possible implementations, the ONN may be a public land mobile network (PLMN).

[0071] Exemplarily, the ONN may be, but is not limited to, a 5G network with the following architecture.

[0072] The first one, Figure 2 This is a schematic diagram of the architecture using reference points in a non-roaming 5G network according to an embodiment of the present disclosure. Figure 2As shown in the figure, in the core network of the non-roaming 5G network, in addition to the above-mentioned AMF, SMF, PCF and UDM, the 5G core network can also include: user plane function (UPF), data network (DN), application function (AF), authentication server function (AUSF), network slice selection function (NSSF), network slice-specific and SNPN authentication and authorization function (NSSAAF), network slice admission control function (NSACF), etc. The functions of each interface are described as follows: N7 is the communication interface between SMF and PCF; N5 is the communication interface between PCF and AF; N6 is the communication interface between UPF and DN; N9 is the communication interface between any two UPFs; N12 is the communication interface between AMF and AUSF; N22 is the communication interface between AMF and NSSF; N14 is the communication interface between any two AMFs; N58 is the communication interface between AMF and NSSAAF; N59 is the communication interface between NSSAAF and UDM; N80 is the communication interface between NSACF and AMF; N81 is the communication interface between NSACF and SMF; N13 is the communication interface between AUSF and UDM. PCF communicates with UDR.

[0073] The second type, Figure 3 This is a schematic diagram of the architecture based on the service-oriented interface in the non-roaming 5G network in the embodiment of the present disclosure, see Figure 3As shown, in the core network of a non-roaming 5G network, each network element interacts with each other using a service-based interface. For example, NSSAAF, AUSF, AMF, SMF, NSACF, NSSF, network exposure function (NEF), network repository function (NRF), PCF, UDM or AF interact with each other using a service-based interface. Among them, the service-based interface provided by NSSAAF to the outside world may be Nnssaaf, the service-based interface provided by ASUF to the outside world may be Nausf, the service-based interface provided by AMF to the outside world may be Namf, the service-based interface provided by SMF to the outside world may be Nsmf, and the service-based interface provided by NSACF to the outside world may be Nnsacf. The service-based interface provided by NSSF to the outside world may be Nnssf, the service-based interface provided by NEF to the outside world may be Nnef, the service-based interface provided by NRF to the outside world may be Nnrf, the service-based interface provided by PCF to the outside world may be Npcf, the service-based interface provided by UDM to the outside world may be Nudm, and the service-based interface provided by AF to the outside world may be Naf.

[0074] Optional, see also Figure 3 As shown in FIG, a service communication proxy (SCP) can also be deployed in the 5G core network, which can be used for indirect communication between network functions (NF) and network function services (NF services).

[0075] It should be understood that Figure 2 and Figure 3 For the description of the names of various service-oriented interfaces, please refer to the 5G system architecture diagram in the 3GPP TS23.501 standard, which will not be repeated here.

[0076] In some possible implementations, a terminal device (such as a UE) obtains an SNPN credential (i.e., an independent non-public network credential) issued by a specific data network (DN) by logging in to the ONN. The UE can then log in to the SNPN based on the SNPN credential. However, based on existing protocols, if the ONN selected by the UE is not the UE's home network, the UDM of the ONN does not contain the UE's subscription information. In this way, the UP security policy on the Uu interface can be locally configured by the SMF. However, it is currently not defined how the SMF determines the configuration of the security policy to protect the SNPN credential.

[0077] Furthermore, since the SMF and access network equipment are network elements in the ONN, the SNPN and the UE may not trust the SMF and access network equipment in the ONN to correctly implement the configuration of the security policy for protecting the SNPN credentials. In particular, in the presence of a disguised access network device or a faulty access network device, the access network device may ignore the UP security policy received from the SMF and disable the UP security protection of the Uu interface, making the SNPN credentials unable to be protected.

[0078] Furthermore, since the UE is only allowed to implement UP security protection by following the security activation indication information sent by the access network device, and cannot distinguish whether the received security activation indication information matches the security requirements of the requested PDU session, the SNPN certificate poses a security risk.

[0079] It can be seen that how to protect SNPN credentials is an urgent problem to be solved.

[0080] To address the above issues, embodiments of the present disclosure provide a communication method that can be applied to the above communication system. For example, the terminal device is a UE, the access network device can be a gNB in ​​an ONN, the first core network device can be an AMF in the ONN, and the second core network device can be an SMF in the ONN.

[0081] Figure 4 This is a schematic diagram of an implementation flow of a communication method in an embodiment of the present disclosure, see Figure 4 As shown, the method may include:

[0082] S401: The UE sends a registration request message to the gNB.

[0083] The registration request message may be non-access stratum (NSA) signaling, such as a registration request message. Furthermore, the registration request message may carry establishment cause information (such as an establishment cause field) to indicate the purpose of the UE initiating this registration request.

[0084] It is understandable that before logging into the SNPN, the UE needs to log into the ONN to obtain the SNPN credentials. In S401, the UE can first send a registration request message to the gNB in ​​the ONN, where the establishment cause information carried can be logging into the SNPN, such as establishment cause = SNPN onboarding.

[0085] S402: The gNB configures the UE's UP security policy to security policy A (i.e., the first security policy) based on the establishment cause information.

[0086] Among them, the UP security policy can be an indication of whether to activate user plane encryption (UP confidentiality) protection and / or user plane integrity (UP integrity) protection for the data radio bearer (DRB) belonging to a PDU session (here, it can also be understood as: "The UP security policy shall indicate whether UP confidentiality and / or UP integrity protection shall be activated or not for all DRBs belonging to that PDU session"). Among them, security policy A indicates to activate (activate) user plane encryption protection and / or user plane integrity protection for DRBs belonging to the PDU session; security policy B indicates to deactivate (deactivate) user plane encryption protection and / or user plane integrity protection for DRBs belonging to the PDU session.

[0087] In some possible implementations, the gNB may indicate security activation to the UE based on the UP security policy provided by the SMF. If the policy indicates "required" (i.e., user plane encryption protection and / or user plane integrity protection must be activated for DRBs belonging to a PDU session), the gNB indicates activation of UP security protection for each DRB (here, UP security protection for each DRB can be understood as enabling user plane encryption protection and / or user plane integrity protection for each DRB). If the policy indicates "not needed" (i.e., user plane encryption protection and / or user plane integrity protection is not required for DRBs belonging to a PDU session), the gNB indicates deactivation of UP security protection for each DRB, so that the PDU session is established without protection. Therefore, the above-mentioned security policy A can also be understood as configuring the UP security policy as "required," and the above-mentioned security policy B can also be understood as configuring the UP security policy as "not needed."

[0088] Optionally, the UP security policy may include an indication field (i.e., the first field). Different values ​​of the indication field indicate the specific configuration of the UP security policy. For example, if the indication field is set to "Required," the UP security policy is configured as Security Policy A; if the indication field is set to "Not Required," the UP security policy is configured as Security Policy B.

[0089] As can be appreciated, in S402, after receiving the Registration Request message from the UE, the gNB may obtain the establishment cause information carried in the Registration Request message. When the establishment cause information is SNPN Registration, the gNB configures the UE's UP security policy to Security Policy A, indicating activation of user plane encryption protection and / or user plane integrity protection for DRBs belonging to the PDU session.

[0090] In one embodiment, after S401, the gNB may further associate and store the UE's identification information with the establishment cause information sent in S401, so that the gNB can configure a UP security policy for the UE. Optionally, the UE's identification information may be a temporary identifier assigned to the UE by the gNB, such as a cell-radio network temporary identifier (C-RNTI).

[0091] In one possible implementation, see Figure 4 As shown, after S401, the method further includes:

[0092] S403: The gNB selects an AMF.

[0093] S404: The gNB forwards the registration request message to the AMF.

[0094] It can be understood that in S403 and S404, the gNB selects an AMF in the ONN according to the registration request message sent by the UE, and after selecting the AMF, sends the registration request message to the AMF to trigger the subsequent registration process.

[0095] At this point, the UE registration process in the ONN is completed.

[0096] In some possible implementations, when the UE successfully logs in to the ONN and wishes to receive the SNPN credentials through the ONN, the UE may initiate a PDU session establishment process. The specific PDU session establishment process is as follows: Figure 5 As shown in the embodiment.

[0097] It should be noted that triggering the UE to initiate a PDU session establishment process for obtaining SNPN credentials may depend on the implementation on the UE side, such as user input.

[0098] Figure 5 This is a flow chart of another communication method in the embodiment of the present disclosure, see Figure 5 As shown, after S401 to S404, the communication method may further include:

[0099] S501, UE sends a PDU session establishment request message to AMF.

[0100] Among them, the PDU session establishment request message can be NSA signaling, such as a PDU session establishment request message. In one embodiment, the PDU session establishment request message is encapsulated in the N1 SM container in the uplink non-access layer transport message (i.e., UL NAS transport), and carries DNN, PDU session ID (PDUsession ID), single-network slice selection assistance information (single-network slice selection assistance information, S-NSSAI) and other information and is sent to the AMF. Of course, other information can also be included in the UL NAS transport, and the embodiment of the present disclosure does not specifically limit this.

[0101] In one embodiment, the aforementioned DNN (which may also be understood as the DNN requested by the UE (i.e., the requested DNN)) may be pre-configured by the UE, and a provisioning server (PVS) may be deployed in the target DN corresponding to the DNN (i.e., the aforementioned specific DN). The PVS may be an entity that provides network credentials and other information for the UE to initiate SNPN access. In another embodiment, the aforementioned DNN may be provided to the UE by the ONN during the login process.

[0102] S502: AMF selects an appropriate SMF to serve the DNN and S-NSSAI requested by the UE.

[0103] In some possible implementations, the AMF compares the DNN requested by the UE with the DNN in the AMF onboarding configuration data to see if it matches; if so, proceeds to S502; if not, the AMF rejects the PDU session establishment request message. The reason for the AMF rejection may be that the UE is limited to requesting only one PDU session for providing SNPN credentials.

[0104] S503, AMF sends a session management context creation request message (such as Nsmf_PDUSession_CreateSMContext request) to SMF.

[0105] Among them, the Nsmf_PDUSession_CreateSMContext request can carry PDU session establishment request, user permanent identifier (SUPI), DNN, PDU Session ID, AMF ID, user location information (user location information), etc.

[0106] S504, SMF sends a session management context creation response message (such as Nsmf_PDUSession_CreateSMContextresponse) to AMF.

[0107] It can be understood that after receiving the session management context creation request message sent by AMF, SMF responds to it and sends back the response result, i.e., the session management context creation response message, to AMF, where the field "created" indicates that the creation is successful.

[0108] S505: The AMF sends a PDU session establishment accept message to the gNB.

[0109] Here, the PDU session establishment acceptance message corresponds to the PDU session.

[0110] In one embodiment, a PDU session establishment acceptance message (such as PDU session establishment accept) can be carried in a PDU session resource request message (such as N2 PDU session request). The N2 message can also carry UE identification information (such as AMF UE NGAP ID and RAN UE NGAP ID). Among them, AMF UE NGAP ID is the next generation application protocol (NGAP) ID of the UE in the AMF, and RAN UE NGAPID is the NGAP ID of the UE on the RAN side. Furthermore, the N2 message can also carry PDU session ID, network slice information, etc. It should be noted that the PDU session ID in the N2 message is consistent with the PDU session ID in S501.

[0111] S506: The gNB determines, based on the UE's identification information, that the UE's UP security policy is configured as security policy A.

[0112] In one embodiment, the gNB identifies the UE based on the AMF UE NGAP ID and RAN UE NGAP ID received from the AMF and determines that the UE's UP security policy is configured as security policy A (i.e., the security policy indicates "required").

[0113] S507: The gNB initiates security policy A for the UE.

[0114] It can be understood that after determining that the UE's UP security policy is configured as security policy A, the gNB starts applying security policy A to the UE. In other words, the gNB performs user plane encryption protection and / or user plane integrity protection on the DRB belonging to the PDU used to transmit the SNPN credentials.

[0115] In some possible implementations, the SMF may also provide the gNB with a UP security policy on the Uu interface. After executing S506, the gNB may override the UP security policy provided by the SMF. In this way, regardless of the UP security policy provided by the SMF, the DRBs belonging to the PDUs used to transmit the SNPN credentials are protected by user plane encryption and / or user plane integrity, thereby protecting the SNPN credentials.

[0116] S508: The gNB sends security activation indication information A (i.e., first indication information) to the UE.

[0117] Among them, the security activation indication information A is used to indicate the activation of user plane encryption protection and / or user plane integrity protection for the above-mentioned DRB.

[0118] In one implementation, the gNB may also issue an access network specific signaling exchange (AN) to the UE related to the information received from the SMF. For example, when the UE establishes necessary access network resources, an RRC connection reconfiguration may occur. In this case, in S508, the gNB sends the security activation indication information A to the UE in an RRC connection reconfiguration message (e.g., RRC Connection Reconfiguration).

[0119] It should be noted that there are unrepeated steps in the PDU session establishment process described in S501 to S508 above. These unrepeated steps can be found in the UE-requested PDU session establishment process in the 3GPP TS 23.502 standard and will not be described in detail here.

[0120] At this point, the process of the UE requesting to establish a PDU session in the ONN is completed.

[0121] In the disclosed embodiment, the gNB is capable of autonomously configuring the UP security policy on the Uu interface, and configuring the security policy for the PDU session used to transmit the SNPN credentials as "required" to indicate activation of user plane encryption protection and / or user plane integrity protection of the DRB of the PDU session, thereby protecting the SNPN credentials.

[0122] Based on the same inventive concept, to address the aforementioned issues, the present disclosure also provides another communication method applicable to the aforementioned communication system. For example, the terminal device is a UE, the access network device is a gNB in ​​an ONN, the first core network device is an AMF in the ONN, and the second core network device is an SMF in the ONN.

[0123] Here, it should be noted that during the UE's request to establish a PDU session in the ONN, the SMF can provide UP security policy for the PDU session. The gNB can instruct the UE whether to activate user plane encryption protection and / or user plane integrity protection for each DRB based on the received UP security policy. And the UE must follow the instructions of the gNB. If the UE implements UP security protection according to the instructions of the gNB, the SNPN credentials carried by these DRBs may have security risks. Therefore, in order to protect the SNPN credentials, the following can be performed during the UE's request to establish a PDU session in the ONN: Figure 6 communication method.

[0124] Figure 6 This is a schematic diagram of an implementation flow of another communication method in the embodiment of the present disclosure, see Figure 6 As shown, the method may include:

[0125] S601: The gNB sends security activation indication information B (i.e., second indication information) to the UE.

[0126] The security activation indication information B is used to indicate whether to activate user plane encryption protection and / or user plane integrity protection for the DRB belonging to the PDU used to transmit the SNPN certificate.

[0127] Optionally, the security activation indication information B may be carried in an RRC connection reconfiguration message (e.g., RRCConnection Reconfiguration) sent by the gNB to the UE.

[0128] In one embodiment, before S601, the gNB activates an access stratum (AS) security mode, such as RRC security, to ensure that RRC messages between the UE and the gNB are securely transmitted using AS security keys. Therefore, after S601 and before S602, the UE may also verify the received RRC Connection Reconfiguration based on the AS security mode to ensure that the RRC Connection Reconfiguration is secure.

[0129] In some possible implementations, after S601, the gNB may also generate K UPint and K UPenc , perform user plane encryption protection and / or user plane integrity protection for the DRB carrying the SNPN certificate.

[0130] S602: The UE verifies whether the security activation indication information B meets the security requirements for protecting the SNPN credentials. If so, S603 is executed; if not, S605 is executed.

[0131] In some possible implementations, in S602, the UE may instruct, through the gNB, whether to activate user plane encryption protection and / or user plane integrity protection for the DRB belonging to the PDU used to transmit the SNPN credentials, and verify whether the security activation indication information B meets the security requirements for protecting the SNPN credentials. When the security activation indication information B indicates that user plane encryption protection and user plane integrity protection are activated on the UE side for the DRB belonging to the PDU used to transmit the SNPN credentials, it indicates that the security activation indication information B meets the security requirements for protecting the SNPN credentials; when the security activation indication information B indicates that user plane encryption protection and / or user plane integrity protection are deactivated on the UE side for the DRB belonging to the PDU used to transmit the SNPN credentials, it indicates that the security activation indication information B does not meet the security requirements for protecting the SNPN credentials.

[0132] S603: The UE starts user plane encryption protection and / or user plane integrity protection for the DRB belonging to the PDU used to transmit the SNPN certificate.

[0133] In one embodiment, in S603, the UE generates a user plane transmission key, such as K UPint and K UPenc The UE uses the user plane transport key to perform user plane encryption protection and / or user plane integrity protection on the DRB carrying the SNPN credentials. UPint K is the user plane integrity protection key UPenc Encryption key for user plane.

[0134] Further, after S603, the UE executes S604, and the UE sends a protected RRC connection reconfiguration complete message (e.g., RRC Connection Reconfiguration Complete) to the gNB.

[0135] S605: The UE rejects the RRC connection reconfiguration request (e.g., RRC Connection Reconfiguration request) from the gNB.

[0136] It should be noted that there are some undescribed steps in the PDU session establishment process described in S601 to S605 above. These undescribed steps can be found in the UE-requested PDU session establishment process in the 3GPP TS 23.502 standard and will not be described in detail here.

[0137] In the disclosed embodiments, the UE can verify whether the security activation indication issued by the gNB meets the security requirements for protecting the SNPN credentials. If the security activation indication issued by the gNB does not meet the security requirements for protecting the SNPN credentials, the UE rejects the gNB's request to avoid security risks to the SNPN credentials and protect the SNPN credentials.

[0138] Based on the same inventive concept, embodiments of the present disclosure also provide a communications device. This communications device can be an access network device (such as a gNB) in the aforementioned communications system, or a chip or system-on-chip in the access network device. It can also be a functional module in the access network device used to implement the methods described in the aforementioned embodiments. This communications device can implement the functions performed by the access network device in the aforementioned embodiments. These functions can be implemented by hardware executing corresponding software. This hardware or software includes one or more modules corresponding to the aforementioned functions. Figure 7 This is a schematic diagram of the structure of a communication device in an embodiment of the present disclosure, see Figure 7 As shown by the solid line, the communication device 700 may include: a first receiving module 701, used to receive a registration request message from a terminal device, the registration request message carries establishment reason information, and the establishment reason information is logging into an independent non-public network; a first processing module 702, used to configure the user plane security policy of the terminal device to a first security policy according to the establishment reason information, and the first security policy is used to indicate the activation of user plane encryption protection and / or user plane integrity protection for a data radio bearer DRB belonging to a protocol data unit PDU session.

[0139] In some possible implementations, the first security policy includes a first field; the first field is used to indicate that user plane encryption protection and / or user plane integrity protection must be activated (“required”).

[0140] In some possible implementations, the first processing module 702 is further configured to associate and store identification information (such as C-RNTI) allocated to the terminal device with establishment cause information after the first receiving module 701 receives the registration request message from the terminal device.

[0141] In some possible implementations, the first receiving module 701 is further used for the first processing module 702 to receive a PDU session establishment acceptance message from a first core network device belonging to the ONN after configuring the user plane security policy of the terminal device as the first security policy according to the establishment cause information, the PDU session establishment acceptance message requesting establishment of a PDU session for transmitting the NPN certificate, and the PDU session establishment acceptance message carrying identification information of the terminal device; the first processing module 702 is further used to determine, based on the identification information of the terminal device, that the user plane security policy of the terminal device is configured as the first security policy; and start the first security policy for the terminal device.

[0142] In some possible implementations, see Figure 7 As shown by the middle dotted line, the above-mentioned communication device 700 also includes a first sending module 703; the first sending module 703 is used to send a first indication information to the terminal device after the first processing module 702 determines that the user plane security policy of the terminal device is configured as the first security policy based on the identification information of the terminal device, and the first indication information is used to indicate the activation of user plane encryption protection and / or user plane integrity protection for DRB.

[0143] In some possible implementations, the first receiving module 701 is further configured to receive a user plane security policy of a terminal device indicated by a second core network device belonging to the ONN; and the first processing module 702 is further configured to overrule the user plane security policy of the terminal device indicated by the second core network device.

[0144] It should be noted that the specific implementation process of the first receiving module 701, the first processing module 702 and the first sending module 703 can be referred to Figures 4 and 5 For the sake of brevity, the detailed description of the embodiments will not be repeated here.

[0145] The first receiving module 701 mentioned in the embodiment of the present disclosure can be a receiving interface, a receiving circuit or a receiver, etc.; the first sending module 703 can be a sending interface, a sending circuit or a transmitter, etc.; the first processing module 702 can be one or more processors.

[0146] Based on the same inventive concept, an embodiment of the present disclosure provides a communication device, which can be a terminal device (such as a UE) in the above-mentioned communication system or a chip or system-on-chip in the terminal device, or a functional module in the terminal device for implementing the methods described in the above-mentioned various aspects. The communication device can implement the functions performed by the terminal device in the above-mentioned various aspects, and these functions can be implemented by hardware executing corresponding software. These hardware or software include one or more modules corresponding to the above-mentioned functions. Figure 8 This is a schematic diagram of the structure of another communication device in the embodiment of the present disclosure, see Figure 8 As shown in , the communication device 800 may include: a second receiving module 801, used to receive second indication information from the access network device, wherein the second indication information is used to indicate whether user plane encryption protection and / or user plane integrity protection is activated for the data radio bearer DRB belonging to a protocol data unit PDU session; a second processing module 802, used for the terminal device to verify whether the second indication information meets the security requirements for protecting independent non-public network credentials; and determine whether to start user plane encryption protection and / or user plane integrity protection for the DRB based on the verification result.

[0147] In some possible implementations, the second processing module 802 is used to reject the radio resource control RRC connection reconfiguration request from the access network device when the verification result shows that the second indication information does not meet the security requirements; or to start user plane encryption protection and / or user plane integrity protection of the DRB when the verification result shows that the second indication information meets the security requirements.

[0148] In some possible embodiments, the second processing module 802 is used to verify whether the second indication information indicates whether user plane encryption protection and / or user plane integrity protection is activated for DRB; wherein, when the second indication information indicates deactivation of user plane encryption protection and / or user plane integrity protection for DRB on the terminal device side, it indicates that the second indication information does not meet the security requirements; when the second indication information indicates activation of user plane encryption protection and user plane integrity protection for DRB on the terminal device side, it indicates that the second indication information meets the security requirements.

[0149] In some possible implementations, the second indication information is carried in an RRC connection reconfiguration message (RRC Connection Reconfiguration) sent by the access network device.

[0150] It should be noted that the specific implementation process of the second receiving module 801 and the second processing module 802 can be referred to Figure 6 For the sake of brevity, the detailed description of the embodiments will not be repeated here.

[0151] The second receiving module 801 mentioned in the embodiment of the present disclosure may be a receiving interface, a receiving circuit, a receiver, etc.; the second processing module 802 may be one or more processors.

[0152] Based on the same inventive concept, an embodiment of the present disclosure provides a communication device, which may be the terminal device or access network device described in one or more of the above embodiments. Figure 9 This is a schematic diagram of the structure of a communication device in an embodiment of the present disclosure, see Figure 9 As shown, the communication device 900 adopts general computer hardware, including a processor 901 , a memory 902 , a bus 903 , an input device 904 and an output device 905 .

[0153] In some possible implementations, the memory 902 may include computer storage media in the form of volatile and / or non-volatile memory, such as read-only memory and / or random access memory. The memory 902 may store an operating system, application programs, other program modules, executable code, program data, user data, and the like.

[0154] Input devices 904 can be used to input commands and information to the communication device, such as a keyboard or pointing device, such as a mouse, trackball, touchpad, microphone, joystick, game pad, satellite TV antenna, scanner, or similar device. These input devices can be connected to the processor 901 via bus 903.

[0155] The output device 905 can be used to output information to the communication device. In addition to the monitor, the output device 905 can also be other peripheral output devices, such as speakers and / or printing devices. These output devices can also be connected to the processor 901 through the bus 903.

[0156] The communication device 900 can be connected to a network, such as a local area network (LAN), via the antenna 906. In a networked environment, the computer-executable instructions stored in the control device can be stored in a remote storage device, rather than being limited to local storage.

[0157] When the processor 901 in the communication device 900 executes the executable code or application stored in the memory 902, the communication device executes the communication method on the terminal device side or the access network device side in the above embodiments. The specific execution process refers to the above embodiments and will not be repeated here.

[0158] In addition, the memory 902 stores the data for implementing Figure 7 The computer executes instructions for the functions of the first receiving module 701, the first processing module 702 and the first sending module 703. Figure 7The functions / implementation processes of the first receiving module 701, the first processing module 702 and the first sending module 703 can be realized by Figure 9 The processor 901 in the memory 902 calls the computer execution instructions stored in the memory 902 to implement the above-mentioned specific implementation process and functions.

[0159] Alternatively, the memory 902 stores the information for implementing Figure 8 The computer executes instructions for the functions of the second receiving module 801 and the second processing module 802. Figure 8 The functions / implementation processes of the second receiving module 801 and the second processing module 802 can be achieved by Figure 9 The processor 901 in the memory 902 calls the computer execution instructions stored in the memory 902 to implement the above-mentioned specific implementation process and functions.

[0160] Based on the same inventive concept, an embodiment of the present disclosure provides a terminal device that is consistent with the terminal device in one or more of the above embodiments. Optionally, the terminal device can be a mobile phone, a computer, a digital broadcast terminal, a messaging device, a game console, a tablet device, a medical device, a fitness device, a personal digital assistant, etc.

[0161] Figure 10 This is a schematic diagram of the structure of a terminal device in an embodiment of the present disclosure, see Figure 10 As shown, the terminal device 1000 may include one or more of the following components: a processing component 1001, a memory 1002, a power component 1003, a multimedia component 1004, an audio component 1005, an input / output (I / O) interface 1006, a sensor component 1007, and a communication component 1008.

[0162] The processing component 1001 generally controls the overall operation of the terminal device 1000, such as operations associated with display, phone calls, data communications, camera operation, and recording operations. The processing component 1001 may include one or more processors 1310 to execute instructions to complete all or part of the steps of the above-described method. In addition, the processing component 1001 may include one or more modules to facilitate interaction between the processing component 1001 and other components. For example, the processing component 1001 may include a multimedia module to facilitate interaction between the multimedia component 1004 and the processing component 1001.

[0163] The memory 1002 is configured to store various types of data to support operations on the terminal device 1000. Examples of such data include instructions for any application or method operating on the terminal device 1000, contact data, phone book data, messages, pictures, videos, etc. The memory 1002 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk, or optical disk.

[0164] The power supply component 1003 provides power to various components of the terminal device 1000. The power supply component 1003 may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power to the terminal device 1000.

[0165] The multimedia component 1004 includes a screen that provides an output interface between the terminal device 1000 and the user. In some embodiments, the screen may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen may be implemented as a touch screen to receive input signals from the user. The touch panel includes one or more touch sensors to sense touches, slides, and gestures on the touch panel. The touch sensor can not only sense the boundaries of a touch or slide action, but also detect the duration and pressure associated with the touch or slide operation. In some embodiments, the multimedia component 1004 includes a front camera and / or a rear camera. When the terminal device 1000 is in an operating mode, such as a shooting mode or a video mode, the front camera and / or the rear camera can receive external multimedia data. Each front camera and rear camera can be a fixed optical lens system or have a focal length and optical zoom capability.

[0166] The audio component 1005 is configured to output and / or input audio signals. For example, the audio component 1005 includes a microphone (MIC), which is configured to receive external audio signals when the terminal device 1000 is in an operating mode, such as a call mode, a recording mode, and a voice recognition mode. The received audio signal can be further stored in the memory 1002 or transmitted via the communication component 1008. In some embodiments, the audio component 1005 also includes a speaker for outputting audio signals.

[0167] I / O interface 1006 provides an interface between processing component 1001 and peripheral interface modules, such as a keyboard, click wheel, buttons, etc. These buttons may include but are not limited to: a home button, volume buttons, a start button, and a lock button.

[0168] The sensor component 1007 includes one or more sensors for providing various aspects of status assessment for the terminal device 1000. For example, the sensor component 1007 can detect the open / closed state of the terminal device 1000, the relative positioning of components, such as the display and keypad of the terminal device 1000. The sensor component 1007 can also detect changes in the position of the terminal device 1000 or a component of the terminal device 1000, the presence or absence of user contact with the terminal device 1000, the orientation or acceleration / deceleration of the terminal device 1000, and temperature changes of the terminal device 1000. The sensor component 1007 can include a proximity sensor configured to detect the presence of nearby objects without any physical contact. The sensor component 1007 can also include an optical sensor, such as a CMOS or CCD image sensor, for use in imaging applications. In some embodiments, the sensor component 1007 can also include an accelerometer, a gyroscope, a magnetic sensor, a pressure sensor, or a temperature sensor.

[0169] The communication component 1008 is configured to facilitate wired or wireless communication between the terminal device 1000 and other devices. The terminal device 1000 can access a wireless network based on a communication standard, such as Wi-Fi, 2G or 3G, or a combination thereof. In an exemplary embodiment, the communication component 1008 receives a broadcast signal or broadcast-related information from an external broadcast management system via a broadcast channel. In an exemplary embodiment, the communication component 1008 also includes a near field communication (NFC) module to facilitate short-range communication. For example, the NFC module can be implemented based on radio frequency identification (RFID) technology, infrared data association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology and other technologies.

[0170] In an exemplary embodiment, the terminal device 1000 can be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components to perform the above method.

[0171] Based on the same inventive concept, an embodiment of the present disclosure provides an access network device, which is consistent with the access network device in one or more of the above embodiments.

[0172] Figure 11 This is a schematic diagram of the structure of an access network device in an embodiment of the present disclosure, see Figure 11As shown, access network device 1100 may include a processing component 1101, which further includes one or more processors, and memory resources represented by memory 1102 for storing instructions executable by processing component 1101, such as applications. The applications stored in memory 1102 may include one or more modules, each corresponding to a set of instructions. Furthermore, processing component 1101 is configured to execute the instructions to perform any of the aforementioned methods applied to access network device A.

[0173] The access network device 1100 may further include a power supply component 1103 configured to perform power management of the access network device 1100, a wired or wireless network interface 1104 configured to connect the access network device 1100 to a network, and an input / output (I / O) interface 1105. The access network device 1100 may operate based on an operating system stored in the memory 1102, such as Windows Server™, Mac OS X™, Unix™, Linux™, FreeBSD™, or the like.

[0174] Based on the same inventive concept, an embodiment of the present disclosure also provides a computer-readable storage medium, which stores instructions; when the instructions are run on a computer, they are used to execute the communication method on the terminal device side or the access network device A side in one or more of the above embodiments.

[0175] Based on the same inventive concept, the embodiments of the present disclosure also provide a computer program or computer program product. When the computer program product is executed on a computer, it enables the computer to implement the communication method on the terminal device side or the access network device A side in one or more of the above embodiments.

[0176] Other embodiments of the present invention will readily occur to those skilled in the art after considering the specification and practicing the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of the invention that follow from the general principles of the invention and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, with the true scope and spirit of the invention being indicated by the following claims.

[0177] It should be understood that the present invention is not limited to the exact construction described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present invention is limited only by the appended claims.

Claims

1. A communication method, characterized in that: include: The access network device receives a registration request message from the terminal device, wherein the registration request message carries establishment reason information, and the establishment reason information is logging into an independent non-public network; The access network device configures the user plane security policy of the terminal device as a first security policy based on the establishment reason information, and the first security policy is used to indicate the activation of user plane encryption protection and / or user plane integrity protection for the data radio bearer DRB belonging to the protocol data unit PDU session for transmitting an independent non-public network.

2. The method according to claim 1, characterized in that The first security policy includes a first field; the first field is used to indicate that the user plane encryption protection and / or the user plane integrity protection must be activated.

3. The method according to claim 1 or 2, characterized in that After the access network device receives the registration request message from the terminal device, the method further includes: The access network device associates and stores the identification information of the terminal device with the establishment reason information, where the identification information of the terminal device is allocated to the terminal device by the access network device.

4. The method according to claim 1, wherein After the access network device configures the user plane security policy of the terminal device as the first security policy according to the establishment reason information, the method further includes: The access network device receives a PDU session establishment acceptance message from a first core network device, where the PDU session establishment acceptance message corresponds to the PDU session and carries identification information of the terminal device. The first core network device belongs to an ONN, and the ONN is used to transmit independent non-public network credentials. The access network device determines, according to the identification information of the terminal device, that the user plane security policy of the terminal device is configured as the first security policy; The access network device executes the first security policy on the terminal device.

5. The method according to claim 4, characterized in that After the access network device determines, based on the identification information of the terminal device, that the user plane security policy of the terminal device is configured as the first security policy, the method further includes: The access network device sends first indication information to the terminal device, where the first indication information is used to indicate the activation of the user plane encryption protection and / or the user plane integrity protection for the DRB.

6. The method according to claim 4, characterized in that The method further comprises: The access network device receives a user plane security policy of the terminal device indicated by a second core network device, where the second core network device belongs to the ONN; The access network device ignores the user plane security policy of the terminal device indicated by the second core network device.

7. A communication method, characterized in that: include: The terminal device receives second indication information from the access network device, wherein the second indication information is used to indicate whether to activate user plane encryption protection and / or user plane integrity protection for a data radio bearer DRB belonging to a protocol data unit PDU session for transmitting an independent non-public network; The terminal device verifies whether the second indication information meets the security requirements for protecting independent non-public network credentials; The terminal device determines whether to perform the user plane encryption protection and / or the user plane integrity protection on the DRB based on the verification result.

8. The method according to claim 7, characterized in that The terminal device determines, according to the verification result, whether to perform the user plane encryption protection and / or the user plane integrity protection on the DRB, including: When the verification result indicates that the second indication information does not meet the security requirement, the terminal device rejects the radio resource control RRC connection reconfiguration request from the access network device; or When the verification result indicates that the second indication information meets the security requirement, the terminal device starts the user plane encryption protection and / or the user plane integrity protection of the DRB.

9. The method according to claim 7, characterized in that The terminal device verifies whether the second indication information meets the security requirements for protecting independent non-public network credentials, including: The terminal device verifies, by the second indication information, whether the user plane encryption protection and / or the user plane integrity protection is activated for the DRB; Among them, when the second indication information indicates that the user plane encryption protection and / or the user plane integrity protection are deactivated for the DRB on the terminal device side, it indicates that the second indication information does not meet the security requirements; when the second indication information indicates that the user plane encryption protection and the user plane integrity protection are activated for the DRB on the terminal device side, it indicates that the second indication information meets the security requirements.

10. The method according to claim 7, characterized in that The second indication information is carried in the RRC connection reconfiguration message sent by the access network device.

11. A communication device, characterized in that: include: A first receiving module is configured to receive a registration request message from a terminal device, wherein the registration request message carries establishment reason information, and the establishment reason information is logging into an independent non-public network; The first processing module is used to configure the user plane security policy of the terminal device to a first security policy based on the establishment reason information, and the first security policy is used to indicate the activation of user plane encryption protection and / or user plane integrity protection for the data radio bearer DRB belonging to the protocol data unit PDU session for transmitting an independent non-public network.

12. The device according to claim 11, characterized in that The first security policy includes a first field; the first field is used to indicate that the user plane encryption protection and / or the user plane integrity protection must be activated.

13. The device according to claim 11 or 12, characterized in that The first processing module is used to associate and save the identification information of the terminal device with the establishment reason information after the first receiving module receives the registration request message, where the identification information of the terminal device is allocated to the terminal device by the access network device.

14. The device according to claim 11, characterized in that The first receiving module is further configured to receive a PDU session establishment accept message from a first core network device after the first processing module configures the user plane security policy of the terminal device as the first security policy, wherein the PDU session establishment accept message corresponds to the PDU session, and the PDU session establishment accept message carries identification information of the terminal device, and the first core network device belongs to a login network ONN, and the ONN is used to transmit independent non-public network credentials; The first processing module is further configured to determine, based on the identification information of the terminal device, that the user plane security policy of the terminal device is configured as the first security policy; and execute the first security policy on the terminal device.

15. The device according to claim 14, characterized in that The device also includes: a first sending module, used to send first indication information to the terminal device after the first processing module determines that the user plane security policy of the terminal device is configured as the first security policy, and the first indication information is used to indicate the activation of the user plane encryption protection and / or the user plane integrity protection for the DRB.

16. The device according to claim 14, characterized in that The first receiving module is further used to receive the user plane security policy of the terminal device indicated by the second core network device, and the second core network device belongs to the ONN; the first processing module is further used to ignore the user plane security policy of the terminal device indicated by the second core network device.

17. A communication device, characterized in that: include: A second receiving module is configured to receive second indication information from an access network device, wherein the second indication information is used to indicate whether to activate user plane encryption protection and / or user plane integrity protection for a data radio bearer DRB belonging to a protocol data unit PDU session for transmitting an independent non-public network; The second processing module is used to verify whether the second indication information meets the security requirements for protecting independent non-public network credentials; based on the verification result, determine whether to perform the user plane encryption protection and / or the user plane integrity protection on the DRB.

18. The device according to claim 17, characterized in that The second processing module is used to reject the radio resource control RRC connection reconfiguration request from the access network device when the verification result shows that the second indication information does not meet the security requirements; or to start the user plane encryption protection and / or the user plane integrity protection of the DRB when the verification result shows that the second indication information meets the security requirements.

19. The device according to claim 17, characterized in that The second processing module is used to verify whether the second indication information indicates whether the user plane encryption protection and / or the user plane integrity protection is activated for the DRB; wherein, when the second indication information indicates that the user plane encryption protection and / or the user plane integrity protection is deactivated for the DRB on the terminal device side, it indicates that the second indication information does not meet the security requirements; when the second indication information indicates that the user plane encryption protection and the user plane integrity protection are activated for the DRB on the terminal device side, it indicates that the second indication information meets the security requirements.

20. The device according to claim 17, wherein The second indication information is carried in the RRC connection reconfiguration message sent by the access network device.

21. An access network device, characterized in that: include: Memory; A processor is connected to the memory and is configured to execute computer-executable instructions stored in the memory to implement the communication method according to any one of claims 1 to 6.

22. A terminal device, characterized in that: include: Memory; A processor is connected to the memory and is configured to execute computer-executable instructions stored in the memory to implement the communication method according to any one of claims 7 to 10.

23. A computer storage medium, a processing module, wherein the computer storage medium stores computer executable instructions, characterized in that: After being executed by a processor, the computer executable instructions can implement the communication method according to any one of claims 1 to 6 or claims 7 to 10.

Citation Information

Patent Citations

  • Communication Method and Related Apparatus

    US20190246282A1