A direct connection communication method and device, user equipment and storage medium

By configuring security policies corresponding to ProSe services for user equipment, the security issues of direct communication between user equipment in ProSe services are resolved, thereby enhancing the security of information transmission.

CN115885533BActive Publication Date: 2026-02-06BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202180002265.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-07-28
Publication Date
2026-02-06
Estimated Expiration
2041-07-28

AI Technical Summary

Technical Problem

In 5G communication systems, how can we ensure the security of direct communication between user devices in Prose services and avoid security risks in information transmission?

Method used

Configure security policies corresponding to ProSe services for user equipment, including signaling integrity protection, signaling encryption protection, UP integrity protection, and UP encryption protection. Establish direct communication security by acquiring and negotiating security policies.

Benefits of technology

It improves the security of direct communication between user devices in the ProSe service and enhances the security of information transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115885533B_ABST
    Figure CN115885533B_ABST
Patent Text Reader

Abstract

The disclosure provides a direct connection communication method and device, user equipment and storage medium, and belongs to the technical field of communication. The method comprises the following steps: receiving that a ProSe UE can obtain a security policy corresponding to a ProSe service, and establishing direct connection communication security with an initiating ProSe UE based on the obtained security policy. Thus, the security of direct connection communication between UEs in the ProSe service is ensured, and the security of information transmission is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of communication technology, and in particular to a direct communication method, apparatus, user equipment, and storage medium. Background Technology

[0002] In 5G communication systems, Prose (Proximity Based Service) is introduced to enable direct communication between UEs (User Equipment).

[0003] However, ensuring secure direct communication between UEs within the Prose service is a problem that urgently needs to be solved. Summary of the Invention

[0004] The direct communication method, apparatus, user equipment, and storage medium disclosed herein are designed to ensure secure direct communication between UEs in Prose services.

[0005] The direct communication method proposed in one embodiment of this disclosure, applied to receiving ProSe UE, includes:

[0006] Obtain the security policy corresponding to ProSe services;

[0007] Based on the aforementioned security policy, a direct communication security connection is established with the ProSe UE.

[0008] The direct communication method proposed in another embodiment of this disclosure, applied to a ProSe UE, includes:

[0009] Obtain the security policy corresponding to ProSe services;

[0010] Secure direct communication is established between the security policy and the receiving ProSe UE.

[0011] Another embodiment of this disclosure provides a direct communication device, including:

[0012] The acquisition module is used to acquire the security policies corresponding to ProSe services.

[0013] The communication module is used to establish direct communication security with the ProSe UE based on security policies.

[0014] Another embodiment of this disclosure provides a direct communication device, including:

[0015] The acquisition module is used to acquire the security policies corresponding to ProSe services.

[0016] The communication module is configured to establish a direct communication security with the receiving ProSe UE based on the security policy.

[0017] The user equipment provided by the further aspect of the present disclosure comprises: a transceiver; a memory; and a processor connected with the transceiver and the memory respectively, configured to control the wireless signal transceiving of the transceiver by executing the computer executable instructions on the memory, and realize the method provided by the further aspect of the present disclosure.

[0018] The computer storage medium provided by the further aspect of the present disclosure stores computer executable instructions; and the computer executable instructions are executed by the processor to realize the method provided by the present disclosure.

[0019] In the direct communication method, the apparatus, the user equipment and the storage medium provided by the embodiments of the present disclosure, the receiving ProSe UE can obtain the security policy corresponding to the ProSe service, and establish the direct communication security with the initiating ProSe UE based on the obtained security policy. Thus, in the embodiments of the present disclosure, the security policy corresponding to the ProSe service can be configured for the UE, so that the receiving ProSe UE and the initiating ProSe UE can establish the direct communication security based on the security policy. Therefore, the direct communication security between the UEs in the ProSe service is ensured, and the security of information transmission is improved.

[0020] The additional aspects and advantages of the present disclosure will be partially given in the following description, partially become obvious from the following description, or be understood through the practice of the present disclosure. BRIEF DESCRIPTION OF DRAWINGS

[0021] The above and / or additional aspects and advantages of the present disclosure will become apparent and more readily understood from the following description, taken in conjunction with the accompanying drawings, in which:

[0022] Figure 1 Flowchart of the direct communication method provided by an embodiment of the present disclosure;

[0023] Figure 2 Flowchart of the direct communication method provided by another embodiment of the present disclosure;

[0024] Figure 3 Flowchart of the direct communication method provided by another embodiment of the present disclosure;

[0025] Figure 4 Flowchart of the direct communication method provided by another embodiment of the present disclosure;

[0026] Figure 5 Flowchart of the direct communication method provided by another embodiment of the present disclosure;

[0027] Figure 6 A flowchart of a direct communication method according to yet another embodiment of the present disclosure;

[0028] Figure 7 A flowchart of a direct communication method according to yet another embodiment of the present disclosure;

[0029] Figure 8 A flowchart of a direct communication method according to yet another embodiment of the present disclosure;

[0030] Figure 9 A flowchart of a direct communication method according to yet another embodiment of the present disclosure;

[0031] Figure 10 A flowchart of a direct communication method according to yet another embodiment of the present disclosure;

[0032] Figure 11 A flowchart of a direct communication method according to yet another embodiment of the present disclosure;

[0033] Figure 12 A flowchart of a direct communication method according to yet another embodiment of the present disclosure;

[0034] Figure 13 A flowchart of a direct communication method according to yet another embodiment of the present disclosure;

[0035] Figure 14 A flowchart of a direct communication method according to yet another embodiment of the present disclosure;

[0036] Figure 15 A flowchart of a direct communication method according to yet another embodiment of the present disclosure;

[0037] Figure 16 A flowchart of a direct communication method according to yet another embodiment of the present disclosure;

[0038] Figure 17 A flowchart of a direct communication method according to yet another embodiment of the present disclosure;

[0039] Figure 18 A flowchart of a direct communication method according to yet another embodiment of the present disclosure;

[0040] Figure 19 A flowchart of a direct communication method according to yet another embodiment of the present disclosure;

[0041] Figure 20 A flowchart of a direct communication method according to yet another embodiment of the present disclosure;

[0042] Figure 21 A structure diagram of a direct communication device according to an embodiment of the present disclosure is shown in FIG. 1.

[0043] Figure 22 A structure diagram of a direct communication device according to another embodiment of the present disclosure is shown in FIG. 2.

[0044] Figure 23 A block diagram of a user equipment according to an embodiment of the present disclosure is shown in FIG. 3. DETAILED DESCRIPTION

[0045] The exemplary embodiments will be described in detail herein with reference to the attached drawings. The following description is made with reference to the accompanying drawings in which like reference numerals refer to like elements, and redundant description is omitted. The following exemplary embodiments described in the following description do not represent all of the aspects of the present disclosure. Rather, they are merely examples of apparatus and methods in accordance with aspects of the present disclosure as detailed in the appended claims.

[0046] The terminology used in the present disclosure is for the purpose of describing particular embodiments only and is not intended to be limiting of the present disclosure. As used in the description of the present disclosure and the appended claims, the singular forms "a," "an," and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It also will be understood that the term "and / or" as used herein refers to and encompasses any and all possible combinations of one or more of the associated listed items.

[0047] It is to be understood that the singular forms "a," "an," and "the" include plural referents unless the context clearly dictates otherwise. It is to be understood that the term "and / or" as used herein refers to and encompasses any and all possible combinations of one or more of the associated listed items.

[0048] Embodiments of the present disclosure are described in detail below with reference to the attached drawing figures, wherein the same or like reference numerals and characters are used to denote like functionality shared throughout the figures and no further repeated description is provided. The embodiments described below are merely examples in accordance with the present disclosure and are not intended to limit the scope of the present disclosure. Rather, they are intended to provide illustrative examples to persons skilled in the art in light of which many modifications are possible without departing from the scope of the present disclosure.

[0049] In the direct communication method provided by the embodiments of the present disclosure, the receiving ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct communication security with the initiating ProSe UE based on the obtained security policy. Thus, in the embodiments of the present disclosure, the security policy corresponding to the ProSe service can be configured for the UE, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Thus, the safety of direct communication between UEs in the ProSe service is ensured, and the safety of information transmission is improved.

[0050] The direct communication method, apparatus, user equipment and storage medium provided by the present disclosure will be described in detail below with reference to the accompanying drawings.

[0051] Figure 1 A flowchart of a direct communication method provided by an embodiment of the present disclosure is applied to a receiving ProSe UE. As shown in the figure, the direct communication method can include the following steps: Figure 1

[0052] Step 101: Obtain the security policy corresponding to the ProSe service.

[0053] It should be noted that the indication method of the embodiments of the present disclosure can be applied in any UE. The UE can be a device that provides voice and / or data connectivity for a user. The UE can communicate with one or more core networks through a RAN (Radio Access Network). The UE can be an Internet of Things terminal, such as a sensor device, a mobile phone (or called "cellular" phone) and a computer with an Internet of Things terminal, for example, which can be a fixed, portable, pocket-sized, handheld, built-in computer or vehicle-mounted device. For example, a station (Station, STA), a subscriber unit, a subscriber station, a mobile station, a mobile, a remote station, an access point, a remote terminal, an access terminal, a user device or a user agent. Alternatively, the UE can also be a device of an unmanned aerial vehicle. Alternatively, the UE can also be a vehicle-mounted device, for example, it can be a vehicle-mounted computer with wireless communication function or a wireless terminal connected to the vehicle-mounted computer. Alternatively, the UE can also be a roadside device, for example, it can be a street lamp, a signal lamp or other roadside devices with wireless communication function, etc.

[0054] ​In one embodiment of the present disclosure, a security policy corresponding to a ProSe service can be configured in advance for each ProSe UE, so that the PC5 interface of the ProSe UE can be protected based on the security policy.

[0055] In one embodiment of the present disclosure, the security policy corresponding to the ProSe service can include at least one of the following:

[0056] In one embodiment of the present disclosure, the security policy can include at least one of the following:

[0057] A signaling integrity protection policy;

[0058] A signaling encryption protection policy;

[0059] A UP integrity protection policy;

[0060] A UP encryption protection policy.

[0061] In one embodiment of the present disclosure, the security policy can be any one of the above policies. In another embodiment of the present disclosure, the security policy can be any combination of the above policies.

[0062] In one embodiment of the present disclosure, the signaling integrity protection policy and the signaling encryption protection policy belong to a signaling security policy, and the UP integrity protection policy and the UP encryption protection policy belong to a UP security policy.

[0063] Further, in one embodiment of the present disclosure, the security policy can include REQUIRED, NOT NEEDED, and PREFERRED.

[0064] In one embodiment of the present disclosure, the signaling integrity protection policy can include REQUIRED, NOT NEEDED, or PREFERRED.

[0065] In one embodiment of the present disclosure, the signaling encryption protection policy can include REQUIRED, NOT NEEDED, or PREFERRED.

[0066] In one embodiment of the present disclosure, the UP integrity protection policy can include REQUIRED, NOT NEEDED, or PREFERRED.

[0067] In an embodiment of the present disclosure, the policy of UP encryption protection can include REQUIRED, or NOT NEEDED, or PREFERRED.

[0068] It should be noted that, in an embodiment of the present disclosure, REQUIRED can indicate that the ProSe UE needs security protection. In an embodiment of the present disclosure, when the security policy corresponding to the ProSe UE is REQUIRED, the ProSe UE can only establish a connection with a ProSe UE whose security policy is also REQUIRED. Further, when the security policy corresponding to the ProSe UE is REQUIRED, the ProSe UE can only establish a connection with a ProSe UE using a non-NULL confidentiality algorithm or integrity algorithm.

[0069] In an embodiment of the present disclosure, NOT NEEDED can indicate that the ProSe UE does not need security protection. In an embodiment of the present disclosure, when the security policy corresponding to the ProSe UE is NOT NEEDED, the ProSe UE can only establish a connection without security with a ProSe UE whose security policy is also NOT NEEDED.

[0070] In an embodiment of the present disclosure, PREFERRED indicates that the ProSe UE can be protected by security or can not be protected by security. In an embodiment of the present disclosure, when the security policy corresponding to the ProSe UE is PREFERRED, the ProSe UE can establish a connection with a ProSe UE whose security policy is REQUIRED, or can establish a connection without security with a ProSe UE whose security policy is NOT NEEDED.

[0071] It should be noted that, in an embodiment of the present disclosure, there is a security policy conflict between a ProSe UE whose security policy is REQUIRED and a ProSe UE whose security policy is NOT NEEDED, so that the two ProSe UEs do not have a direct connection qualification.

[0072] Further, in an embodiment of the present disclosure, the method for the ProSe UE to obtain the security policy corresponding to the ProSe service can include: obtaining the ProSe service to be protected and the security policy corresponding to the ProSe service to be protected sent by a PCF (Policy Control Function).

[0073] In another embodiment of the present disclosure, the method for the ProSe UE to obtain the security policy corresponding to the ProSe service can include: obtaining the ProSe service to be protected and the security policy corresponding to the ProSe service to be protected sent by the ProSe application server. In one embodiment of the present disclosure, the ProSe application server can send the security policy corresponding to the ProSe service to the ProSe UE through the PCF. In another embodiment of the present disclosure, the ProSe application server can send the security policy corresponding to the ProSe service to the ProSe UE through the PC1 interface.

[0074] In another embodiment of the present disclosure, the method for the ProSe UE to obtain the security policy corresponding to the ProSe service can include: obtaining the ProSe service to be protected and the security policy corresponding to the ProSe service to be protected configured on the UICC (Universal Integrated Circuit Card).

[0075] It should be noted that in one embodiment of the present disclosure, when the ProSe UE obtains the security policy corresponding to the ProSe service, the security policy can be protected through NAS (Non Access Stratum) signaling security. In one embodiment of the present disclosure, the NAS security can be established after the ProSe UE registers the ProSe service.

[0076] Step 102: establishing direct communication with the initiating ProSe UE based on the security policy.

[0077] In one embodiment of the present disclosure, the method for the ProSe UE to obtain the security policy corresponding to the ProSe service can include: obtaining the ProSe service to be protected and the security policy corresponding to the ProSe service to be protected sent by the ProSe application server.

[0078] In one embodiment of the present disclosure, the method for the ProSe UE to obtain the security policy corresponding to the ProSe service can include: obtaining the ProSe service to be protected and the security policy corresponding to the ProSe service to be protected sent by the ProSe application server.

[0079] Figure 2 In another embodiment of the present disclosure, a flowchart of a direct communication method is provided, which is applied to a receiving ProSe UE, as shown in FIG. 6. Figure 2As shown, the direct connection method can include the following steps:

[0080] Step 201, obtaining a security policy corresponding to a ProSe service.

[0081] Details about step 201 can be referred to the related description in the above embodiments, and the present disclosure embodiments will not be described here.

[0082] Step 202, obtaining a Direct Communication Request message sent by the initiating ProSe UE, wherein the Direct Communication Request message contains a signaling security policy of the initiating ProSe UE.

[0083] Step 203, determining whether the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE meet a first preset condition.

[0084] In one embodiment of the present disclosure, the first preset condition can include at least one of the following:

[0085] The signaling integrity protection policy of the initiating ProSe UE is NOT NEEDED, and the signaling integrity protection policy of the receiving ProSe UE is REQUIRED;

[0086] The signaling encryption protection policy of the initiating ProSe UE is NOT NEEDED, and the signaling encryption protection policy of the receiving ProSe UE is REQUIRED;

[0087] The signaling integrity protection policy of the initiating ProSe UE is REQUIRED, and the signaling integrity protection policy of the receiving ProSe UE is NOT NEEDED;

[0088] The signaling encryption protection policy of the initiating ProSe UE is REQUIRED, and the signaling encryption protection policy of the receiving ProSe UE is NOT NEEDED.

[0089] It should be noted that, in one embodiment of the disclosure, the first preset condition can be only one of the above-mentioned preset conditions. In another embodiment of the disclosure, the first preset condition can be any combination of the above-mentioned preset conditions. In one embodiment of the disclosure, when the first preset condition includes two or more of the above-mentioned preset conditions, if the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE satisfy any one of the first preset conditions, it is determined that the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE satisfy the first preset condition, otherwise it is determined that the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE do not satisfy the first preset condition.

[0090] In one embodiment of the disclosure, if it is determined that the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE satisfy the first preset condition, it means that there is a security policy conflict between the initiating ProSe UE and the receiving ProSe UE, and both of them do not have the qualification for direct connection, and step 204 is continued to be executed.

[0091] Step 204, sending a first rejection message to the initiating ProSe UE, the first rejection message being used to reject the Direct Communication Request message sent by the initiating ProSe UE.

[0092] In summary, in the direct communication method provided by the embodiments of the disclosure, the receiving ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct communication security with the initiating ProSe UE based on the obtained security policy. Therefore, in the embodiments of the disclosure, the UE can be configured with the security policy corresponding to the ProSe service, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Thus, the safety of direct communication between UEs in ProSe service is ensured, and the safety of information transmission is improved.

[0093] Figure 3 A flowchart of a direct communication method provided by another embodiment of the disclosure is applied to a receiving ProSe UE, as shown in Figure 3 The direct communication method can include the following steps:

[0094] Step 301, obtaining the security policy corresponding to the ProSe service.

[0095] At step 302, a Direct Communication Request message sent by the initiating ProSe UE is acquired, wherein the Direct Communication Request message contains the signaling security policy of the initiating ProSe UE.

[0096] At step 303, it is determined whether the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE satisfy a first preset condition.

[0097] Details about steps 301-303 can be referred to the related descriptions in the above embodiments, and will not be repeated here.

[0098] In one embodiment of the present disclosure, if it is determined that the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE do not satisfy the first preset condition, it indicates that there is no security policy conflict between the initiating ProSe UE and the receiving ProSe UE, and both of them have the qualification of direct connection, and step 304 is continued to be executed.

[0099] At step 304, a negotiation result of the signaling security policy is determined based on the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE.

[0100] In one embodiment of the present disclosure, the negotiation result of the signaling security policy can include at least one of the following:

[0101] a negotiation result of a signaling integrity protection policy;

[0102] a negotiation result of a signaling encryption protection policy.

[0103] In one embodiment of the present disclosure, determining the negotiation result of the signaling security policy based on the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE includes:

[0104] If the signaling integrity protection policy of the initiating ProSe UE is NOT NEEDED and / or the signaling integrity protection policy of the receiving ProSe UE is NOT NEEDED, it is determined that the negotiation result of the signaling integrity protection policy is NOT NEEDED. That is, in the case that there is no security policy conflict between the receiving ProSe UE and the initiating ProSe UE, when the signaling integrity protection policy of one of the initiating ProSe UE and the receiving ProSe UE is NOT NEEDED, it is determined that the negotiation result of the signaling integrity protection policy is NOT NEEDED.

[0105] If the policy of signaling integrity protection of the initiating ProSe UE is REQUIRED, and / or the policy of signaling integrity protection of the receiving ProSe UE is REQUIRED, the negotiation result of the policy of signaling integrity protection is determined as REQUIRED. That is, in the case that there is no security policy conflict between the receiving ProSe UE and the initiating ProSe UE, when there is one ProSe UE whose policy of signaling integrity protection is REQUIRED between the initiating ProSe UE and the receiving ProSe UE, the negotiation result of the policy of signaling integrity protection is determined as REQUIRED.

[0106] If the policy of signaling integrity protection of the initiating ProSe UE is PREFERRED, and the policy of signaling integrity protection of the receiving ProSe UE is PREFERRED, the negotiation result of the policy of signaling integrity protection is determined as REQUIRED or NOT NEEDED.

[0107] If the policy of signaling encryption protection of the initiating ProSe UE is NOT NEEDED, and / or the policy of signaling encryption protection of the receiving ProSe UE is NOT NEEDED, the negotiation result of the policy of signaling encryption protection is determined as NOT NEEDED. That is, in the case that there is no security policy conflict between the receiving ProSe UE and the initiating ProSe UE, when there is one ProSe UE whose policy of signaling encryption protection is NOT NEEDED between the initiating ProSe UE and the receiving ProSe UE, the negotiation result of the policy of signaling encryption protection is determined as NOT NEEDED.

[0108] If the policy of signaling encryption protection of the initiating ProSe UE is REQUIRED, and / or the policy of signaling encryption protection of the receiving ProSe UE is REQUIRED, the negotiation result of the policy of signaling encryption protection is determined as REQUIRED. That is, in the case that there is no security policy conflict between the receiving ProSe UE and the initiating ProSe UE, when there is one ProSe UE whose policy of signaling encryption protection is REQUIRED between the initiating ProSe UE and the receiving ProSe UE, the negotiation result of the policy of signaling encryption protection is determined as REQUIRED.

[0109] If the policy of signaling encryption protection of the initiating ProSe UE is PREFERRED, and the policy of signaling encryption protection of the receiving ProSe UE is PREFERRED, the negotiation result of the policy of signaling encryption protection is determined as REQUIRED or NOT NEEDED.

[0110] Step 305, sending a Direct Security Mode Command message to the initiating ProSe UE, wherein the Direct Security Mode Command message includes the negotiation result of the signaling security policy.

[0111] In an embodiment of the present disclosure, the negotiation result of the signaling security policy included in the Direct Security Mode Command message can be the negotiation result determined in step 304.

[0112] In summary, in the direct communication method provided by the embodiments of the present disclosure, the receiving ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct communication security with the initiating ProSe UE based on the obtained security policy. Thus, in the embodiments of the present disclosure, the UE can be configured with the security policy corresponding to the ProSe service, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Therefore, the safety of direct communication between UEs in ProSe service is ensured, and the safety of information transmission is improved.

[0113] Figure 4 For another embodiment of the present disclosure, a flowchart of a direct communication method is provided, which is applied to a receiving ProSe UE. As shown in the figure, the direct communication method can include the following steps: Figure 4

[0114] Step 401, obtaining the security policy corresponding to the ProSe service.

[0115] Step 402, obtaining the Direct Communication Request message sent by the initiating ProSe UE, wherein the Direct Communication Request message includes the signaling security policy of the initiating ProSe UE.

[0116] Step 403, determining whether the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE meet the first preset condition.

[0117] In an embodiment of the present disclosure, if it is determined that the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE do not meet the first preset condition, it means that there is no security policy conflict between the initiating ProSe UE and the receiving ProSe UE, and both of them have the qualification of direct connection, and step 404 is continued to be executed.

[0118] ​Step 404, determining the negotiation result of the signaling security policy based on the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE.

[0119] Step 405, sending a Direct Security Mode Command message to the initiating ProSe UE, wherein the Direct Security Mode Command message includes the negotiation result of the signaling security policy.

[0120] Details about steps 401-405 can refer to the related descriptions in the above embodiments, and will not be repeated here.

[0121] Step 406, receiving a second rejection message sent by the initiating ProSe UE, wherein the second rejection message is used to reject the Direct Security Mode Command message sent by the receiving ProSe UE.

[0122] In one embodiment of the present disclosure, when the initiating ProSe UE receives the Direct Security Mode Command message sent by the receiving ProSe UE, it judges whether the security algorithm corresponding to the negotiation result of the signaling security policy included in the Direct Security Mode Command message is consistent with the security algorithm corresponding to the signaling security policy of the initiating ProSe UE. In one embodiment of the present disclosure, when the initiating ProSe UE judges that the security algorithm corresponding to the negotiation result of the signaling security policy included in the Direct Security Mode Command message is not consistent with the security algorithm corresponding to the signaling security policy of the initiating ProSe UE, it means that the receiving ProSe UE and the sending ProSe UE do not have the qualification of protecting direct connection, and then the initiating ProSe UE sends a second rejection message to the receiving ProSe UE to reject the Direct Security Mode Command message sent by the receiving ProSe UE.

[0123] In summary, in the direct connection communication method provided in the embodiments of the present disclosure, the receiving ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct connection communication security with the initiating ProSe UE based on the obtained security policy. Therefore, in the embodiments of the present disclosure, the UE can be configured with the security policy corresponding to the ProSe service, so that the receiving ProSe UE and the initiating ProSe UE can establish direct connection communication security based on the security policy. Thus, the safety of direct connection communication between UEs in ProSe service is ensured, and the safety of information transmission is improved.

[0124] Figure 5 A flowchart of a direct communication method provided by yet another embodiment of the present disclosure is provided, which is applied to a receiving ProSe UE, as shown in the figure, the direct communication method can include the following steps: Figure 5

[0125] Step 501, obtaining a security policy corresponding to a ProSe service.

[0126] Step 502, obtaining a Direct Communication Request message sent by an initiating ProSe UE, wherein the Direct Communication Request message contains a signaling security policy of the initiating ProSe UE.

[0127] Step 503, determining whether the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE meet a first preset condition.

[0128] In an embodiment of the present disclosure, if it is determined that the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE do not meet the first preset condition, it means that there is no security policy conflict between the initiating ProSe UE and the receiving ProSe UE, and both of them have the qualification of direct connection, and step 504 is continued to be executed.

[0129] Step 504, determining a negotiation result of the signaling security policy based on the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE.

[0130] Step 505, sending a Direct Security Mode Command message to the initiating ProSe UE, wherein the Direct Security Mode Command message includes the negotiation result of the signaling security policy.

[0131] The detailed description of steps 501-505 can refer to the related description in the above embodiments, and the present embodiment of the present disclosure will not be described here.

[0132] Step 506, determining whether the negotiation result of the signaling security policy is NOT NEEDED.

[0133] In an embodiment of the present disclosure, when the negotiation result of the signaling security policy is NOT NEEDED, step 507 is continued to be executed.

[0134] ​Step 507, change the UP security policy of the receiving ProSe UE to NOT NEEDED.

[0135] In one embodiment of the present disclosure, when the negotiation result of the signaling encryption protection policy is NOT NEEDED, it indicates that the signaling between the initiating ProSe UE and the receiving ProSe UE does not need security protection and the negotiated encryption algorithm is NULL algorithm, at this time, the UP encryption protection policy of the receiving ProSe UE can also be changed to NOT NEEDED.

[0136] In summary, in the direct communication method provided by the embodiments of the present disclosure, the receiving ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct communication security with the initiating ProSe UE based on the obtained security policy. Therefore, in the embodiments of the present disclosure, the UE can be configured with the security policy corresponding to the ProSe service, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Thus, the safety of direct communication between UEs in ProSe service is ensured, and the safety of information transmission is improved.

[0137] Figure 6 For another embodiment of the present disclosure, a flowchart of a direct communication method is provided, which is applied to a receiving ProSe UE. As shown in the figure, the direct communication method can include the following steps: Figure 6

[0138] Step 601, obtaining the security policy corresponding to the ProSe service.

[0139] Step 602, obtaining the Direct Communication Request message sent by the initiating ProSe UE, wherein the Direct Communication Request message contains the signaling security policy of the initiating ProSe UE.

[0140] Step 603, determining whether the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE meet the first preset condition.

[0141] In one embodiment of the present disclosure, if it is determined that the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE do not meet the first preset condition, it indicates that there is no security policy conflict between the initiating ProSe UE and the receiving ProSe UE, and both of them have the qualification of direct connection, and step 604 is continued to be executed.

[0142] ​Step 604, determining the negotiation result of the signaling security policy based on the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE.

[0143] Step 605, sending a Direct Security Mode Command message to the initiating ProSe UE, wherein the Direct Security Mode Command message comprises the negotiation result of the signaling security policy.

[0144] The detailed description of steps 601-605 can refer to the related description in the above embodiments, and will not be repeated here.

[0145] In one embodiment of the present disclosure, the signaling security policy negotiation between the receiving ProSe UE and the initiating ProSe UE is completed by step 605, and then subsequent steps can be executed to negotiate the UP security policy between the receiving ProSe UE and the initiating ProSe UE.

[0146] It should be further noted that in one embodiment of the present disclosure, if the negotiation result of the signaling security policy determined in step 604 is REQUIRED, it is considered that the signaling security protection is established between the receiving ProSe UE and the initiating ProSe UE, and in the subsequent process, when the receiving ProSe UE and the initiating ProSe UE interact, the messages exchanged will be protected by the signaling security, ensuring the security of the signaling transmission.

[0147] Step 606, receiving the Direct Security Mode Complete message sent by the initiating ProSe UE, wherein the Direct Security Mode Complete message comprises the UP security policy of the initiating ProSe UE.

[0148] Step 607, determining whether the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE meet a second preset condition.

[0149] In one embodiment of the present disclosure, the second preset condition can include at least one of the following:

[0150] the policy of the UP integrity protection of the initiating ProSe UE is NOT NEEDED, and the policy of the UP integrity protection of the receiving ProSe UE is REQUIRED;

[0151] The policy of initiating the UP encryption protection of the ProSe UE is NOT NEEDED, and the policy of receiving the UP encryption protection of the ProSe UE is REQUIRED;

[0152] The policy of initiating the UP integrity protection of the ProSe UE is REQUIRED, and the policy of receiving the UP integrity protection of the ProSe UE is NOT NEEDED;

[0153] The policy of initiating the UP encryption protection of the ProSe UE is REQUIRED, and the policy of receiving the UP encryption protection of the ProSe UE is NOT NEEDED.

[0154] In addition, it should be noted that in one embodiment of the disclosure, the second preset condition can be only one of the above preset conditions. In another embodiment of the disclosure, the second preset condition can be any combination of the above preset conditions. In one embodiment of the disclosure, when the second preset condition contains two or more of the above preset conditions, if the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE satisfy any one of the second preset conditions, it is determined that the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE satisfy the second preset condition, otherwise it is determined that the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE do not satisfy the second preset condition.

[0155] Further, in one embodiment of the disclosure, if it is determined that the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE satisfy the second preset condition, it indicates that there is a security policy conflict between the initiating ProSe UE and the receiving ProSe UE, and both do not have the qualification for direct connection, and step 608 is continued to be executed.

[0156] In addition, it should be noted that in one embodiment of the disclosure, before determining whether the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE satisfy the second preset condition in step 607, the receiving ProSe UE will first determine whether the negotiation result of the signaling security policy determined in step 605 is NOT NEEDED, and when it is NOT NEEDED, the UP security policy of the receiving ProSe UE will also be changed to NOT NEEDED. And then, when determining whether the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE satisfy the second preset condition, it is specifically determined whether the UP security policy of the initiating ProSe UE and the changed UP security policy of the receiving ProSe UE satisfy the second preset condition.

[0157] Step 608, sending a third rejection message to the initiating ProSe UE, wherein the third rejection message is used to reject the Direct Security Mode Complete message sent by the initiating ProSe UE.

[0158] To sum up, in the direct communication method provided by the embodiments of the present disclosure, the receiving ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct communication security with the initiating ProSe UE based on the obtained security policy. Therefore, in the embodiments of the present disclosure, the UE can be configured with the security policy corresponding to the ProSe service, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Thus, the safety of direct communication between UEs in ProSe service is ensured, and the safety of information transmission is improved.

[0159] Figure 7 For another embodiment of the present disclosure, a flowchart of a direct communication method is provided, which is applied to a receiving ProSe UE. As shown in the figure, the direct communication method can include the following steps: Figure 7

[0160] Step 701, obtaining the security policy corresponding to the ProSe service.

[0161] Step 702, obtaining the Direct Communication Request message sent by the initiating ProSe UE, wherein the Direct Communication Request message contains the signaling security policy of the initiating ProSe UE.

[0162] Step 703, determining whether the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE meet the first preset condition.

[0163] In one embodiment of the present disclosure, if it is determined that the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE do not meet the first preset condition, it means that there is no security policy conflict between the initiating ProSe UE and the receiving ProSe UE, and both of them have the qualification of direct connection, and step 704 is continued to be executed.

[0164] Step 704, determining the negotiation result of the signaling security policy based on the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE.

[0165] ​Step 705, sending a Direct Security Mode Command message to the initiating ProSe UE, wherein the Direct Security Mode Command message comprises the negotiation result of the signaling security policy.

[0166] Step 706, receiving a Direct Security Mode Complete message sent by the initiating ProSe UE, wherein the Direct Security Mode Complete message comprises the UP security policy of the initiating ProSe UE.

[0167] Step 707, determining whether the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE satisfy a second preset condition.

[0168] Details of steps 701-707 can be referred to the related descriptions in the above embodiments, which will not be repeated here.

[0169] In addition, in an embodiment of the present disclosure, if it is determined that the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE do not satisfy the second preset condition, it indicates that there is no security policy conflict between the initiating ProSe UE and the receiving ProSe UE, and both of them have the qualification of direct connection, and step 708 is continued to be executed.

[0170] In addition, it should be noted that, in an embodiment of the present disclosure, before determining whether the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE satisfy the second preset condition in step 707, the receiving ProSe UE will first determine whether the negotiation result of the signaling security policy determined in step 705 is NOT NEEDED, and when it is NOT NEEDED, the UP security policy of the receiving ProSe UE will also be changed to NOT NEEDED. Then, when determining whether the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE satisfy the second preset condition, the UP security policy of the initiating ProSe UE and the changed UP security policy of the receiving ProSe UE are determined whether they satisfy the second preset condition.

[0171] Step 708, determining the negotiation result of the UP security policy based on the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE.

[0172] In an embodiment of the present disclosure, the negotiation result of the UP security policy can comprise at least one of the following:

[0173] a negotiation result of a policy of UP integrity protection;

[0174] a negotiation result of a policy of UP encryption protection.

[0175] In an embodiment of the present disclosure, the negotiation result of the UP security policy is determined based on the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE, comprising:

[0176] If the policy of UP integrity protection of the initiating ProSe UE is NOT NEEDED, and / or the policy of UP integrity protection of the receiving ProSe UE is NOT NEEDED, the negotiation result of the policy of UP integrity protection is determined as NOT NEEDED. That is, in the case that there is no security policy conflict between the receiving ProSe UE and the initiating ProSe UE, when there is one ProSe UE whose policy of UP integrity protection is NOT NEEDED between the initiating ProSe UE and the receiving ProSe UE, the negotiation result of the policy of UP integrity protection is determined as NOT NEEDED.

[0177] If the policy of UP integrity protection of the initiating ProSe UE is REQUIRED, and / or the policy of UP integrity protection of the receiving ProSe UE is REQUIRED, the negotiation result of the policy of UP integrity protection is determined as REQUIRED. That is, in the case that there is no security policy conflict between the receiving ProSe UE and the initiating ProSe UE, when there is one ProSe UE whose policy of UP integrity protection is REQUIRED between the initiating ProSe UE and the receiving ProSe UE, the negotiation result of the policy of UP integrity protection is determined as REQUIRED.

[0178] If the policy of UP integrity protection of the initiating ProSe UE is PREFERRED, and the policy of UP integrity protection of the receiving ProSe UE is PREFERRED, the negotiation result of the policy of UP integrity protection is determined as REQUIRED or NOT NEEDED.

[0179] If the policy of UP encryption protection of the initiating ProSe UE is NOT NEEDED, and / or the policy of UP encryption protection of the receiving ProSe UE is NOT NEEDED, it is determined that the negotiation result of the policy of UP encryption protection is NOT NEEDED. That is, in the case that there is no security policy conflict between the receiving ProSe UE and the initiating ProSe UE, when the policy of UP encryption protection of one of the ProSe UEs is NOT NEEDED, it is determined that the negotiation result of the policy of UP encryption protection is NOT NEEDED.

[0180] If the policy of UP encryption protection of the initiating ProSe UE is REQUIRED, and / or the policy of UP encryption protection of the receiving ProSe UE is REQUIRED, it is determined that the negotiation result of the policy of UP encryption protection is REQUIRED. That is, in the case that there is no security policy conflict between the receiving ProSe UE and the initiating ProSe UE, when the policy of UP encryption protection of one of the ProSe UEs is REQUIRED, it is determined that the negotiation result of the policy of UP encryption protection is REQUIRED.

[0181] If the policy of UP encryption protection of the initiating ProSe UE is PREFERRED, and the policy of UP encryption protection of the receiving ProSe UE is PREFERRED, it is determined that the negotiation result of the policy of UP encryption protection is REQUIRED or NOT NEEDED.

[0182] Step 709, sending a Direct Communication Accept message to the initiating ProSe UE, wherein the Direct Communication Accept message includes the negotiation result of the UP security policy.

[0183] In an embodiment of the present disclosure, the negotiation result of the UP security policy included in the Direct Communication Accept message can be the negotiation result determined in step 708.

[0184] In summary, in the direct communication method provided by the embodiments of the present disclosure, the receiving ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct communication security with the initiating ProSe UE based on the obtained security policy. Thus, in the embodiments of the present disclosure, the security policy corresponding to the ProSe service can be configured for the UE, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Thus, the safety of direct communication between UEs in the ProSe service is ensured, and the safety of information transmission is improved.

[0185] Figure 8 For another embodiment of the present disclosure, a flowchart of a direct communication method is provided, which is applied to a receiving ProSe UE. As shown in the figure, the direct communication method can include the following steps: Figure 8

[0186] Step 801: Obtain the security policy corresponding to the ProSe service.

[0187] Step 802: Obtain the Direct Communication Request message sent by the initiating ProSe UE, wherein the Direct Communication Request message contains the signaling security policy of the initiating ProSe UE.

[0188] Step 803: Determine whether the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE meet the first preset condition.

[0189] In an embodiment of the present disclosure, if it is determined that the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE do not meet the first preset condition, it means that there is no security policy conflict between the initiating ProSe UE and the receiving ProSe UE, and both of them have the qualification of direct connection, and step 804 is continued to be executed.

[0190] Step 804: Determine the negotiation result of the signaling security policy based on the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE.

[0191] Step 805: Send the Direct Security Mode Command message to the initiating ProSe UE, wherein the Direct Security Mode Command message includes the negotiation result of the signaling security policy.

[0192] ​Step 806, receiving a Direct Security Mode Complete message initiated by the ProSe UE, wherein the Direct Security Mode Complete message contains the UP security policy of the initiating ProSe UE.

[0193] Step 807, determining whether the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE meet the second preset condition.

[0194] In one embodiment of the present disclosure, if it is determined that the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE do not meet the second preset condition, it means that there is no security policy conflict between the initiating ProSe UE and the receiving ProSe UE, and both of them are qualified for direct connection, and step 808 is continued to be executed.

[0195] In addition, it should be noted that, in one embodiment of the present disclosure, before determining whether the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE meet the second preset condition in step 807, the receiving ProSe UE first determines whether the negotiation result of the signaling security policy determined in step 804 is NOT NEEDED, and when it is NOT NEEDED, the UP security policy of the receiving ProSe UE is also changed to NOT NEEDED. Then, when determining whether the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE meet the second preset condition, the UP security policy of the initiating ProSe UE and the changed UP security policy of the receiving ProSe UE are specifically determined whether they meet the second preset condition.

[0196] Step 808, determining the negotiation result of the UP security policy based on the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE.

[0197] Step 809, sending a Direct Communication Accept message to the initiating ProSe UE, wherein the Direct Communication Accept message includes the negotiation result of the UP security policy.

[0198] The details of steps 801-809 can be referred to the related description in the above embodiments, and the present embodiment of the present disclosure will not be repeated here.

[0199] Step 810, performing direct connection communication with the initiating ProSe UE based on the negotiation result of the signaling security policy and the negotiation result of the UP security policy.

[0200] In summary, in the direct communication method provided by the embodiments of the present disclosure, the receiving ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct communication security with the initiating ProSe UE based on the obtained security policy. Thus, in the embodiments of the present disclosure, the security policy corresponding to the ProSe service can be configured for the UE, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Therefore, the safety of direct communication between UEs in the ProSe service is ensured, and the safety of information transmission is improved.

[0201] Figure 9 For another embodiment of the present disclosure, a flowchart of a direct communication method is provided, which is applied to an initiating ProSe UE. As shown in Figure 9 The direct communication method can include the following steps:

[0202] Step 901, obtaining a security policy corresponding to a ProSe service.

[0203] Step 902, establishing direct communication with a receiving ProSe UE based on the security policy.

[0204] For details of steps 901-902, reference can be made to the related descriptions in the above embodiments, which will not be repeated here.

[0205] In summary, in the direct communication method provided by the embodiments of the present disclosure, the receiving ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct communication security with the initiating ProSe UE based on the obtained security policy. Thus, in the embodiments of the present disclosure, the security policy corresponding to the ProSe service can be configured for the UE, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Therefore, the safety of direct communication between UEs in the ProSe service is ensured, and the safety of information transmission is improved.

[0206] Figure 10 For another embodiment of the present disclosure, a flowchart of a direct communication method is provided, which is applied to an initiating ProSe UE. As shown in Figure 10 The direct communication method can include the following steps:

[0207] Step 1001, obtaining a security policy corresponding to a ProSe service.

[0208] For details of step 1001, reference can be made to the related descriptions in the above embodiments, which will not be repeated here.

[0209] Step 1002, sending a Direct Communication Request message to the receiving ProSe UE, wherein the Direct Communication Request message contains the signaling security policy of the initiating ProSe UE.

[0210] Step 1003, obtaining a first rejection message sent by the receiving ProSe UE, the first rejection message being used to reject the Direct Communication Request message sent by the initiating ProSe UE.

[0211] In one embodiment of the present disclosure, after the receiving ProSe UE obtains the Direct Communication Request message sent by the initiating ProSe UE, the receiving ProSe UE determines whether the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE satisfy a first preset condition. In one embodiment of the present disclosure, if it is determined that the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE satisfy the first preset condition, it indicates that there is a security policy conflict between the initiating ProSe UE and the receiving ProSe UE, and the two do not have the qualification for direct connection. The receiving ProSe UE sends a first rejection message to the initiating ProSe UE.

[0212] In summary, in the direct connection communication method provided by the embodiments of the present disclosure, the initiating ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct connection communication security with the receiving ProSe UE based on the obtained security policy. Thus, in the embodiments of the present disclosure, the security policy corresponding to the ProSe service can be configured for the UE, so that the receiving ProSe UE and the initiating ProSe UE can establish direct connection communication security based on the security policy. Thus, the direct connection communication security between the UEs in the ProSe service is ensured, and the security of information transmission is improved.

[0213] Figure 11 FIG. 1 1 1 1 is a flowchart of a direct connection communication method provided by another embodiment of the present disclosure, applied to an initiating ProSe UE. As shown in the figure, the direct connection communication method can include the following steps: Figure 11

[0214] Step 1 101, obtaining a security policy corresponding to a ProSe service.

[0215] ​Step 1102, sending a Direct Communication Request message to the receiving ProSe UE, wherein the Direct Communication Request message contains the signaling security policy of the initiating ProSe UE.

[0216] Details about steps 1101-1102 can be referred to the relevant description in the above embodiments, which will not be repeated here.

[0217] Step 1103, obtaining the Direct Security Mode Command message sent by the receiving ProSe UE, wherein the Direct Security Mode Command includes the negotiation result of the signaling security policy.

[0218] In one embodiment of the present disclosure, after the receiving ProSe UE obtains the Direct Communication Request message sent by the initiating ProSe UE, it determines whether the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE meet the first preset condition.

[0219] In one embodiment of the present disclosure, if it is determined that the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE do not meet the first preset condition, it means that there is no security policy conflict between the initiating ProSe UE and the receiving ProSe UE, and both of them have the qualification for direct connection. The receiving ProSe UE determines the negotiation result of the signaling security policy based on the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE. Then, it sends a Direct Security Mode Command message to the initiating ProSe UE, wherein the Direct Security Mode Command message includes the negotiation result of the signaling security policy.

[0220] In summary, in the direct communication method provided by the embodiments of the present disclosure, the initiating ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct communication security with the receiving ProSe UE based on the obtained security policy. Therefore, in the embodiments of the present disclosure, the UE can be configured with the security policy corresponding to the ProSe service, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Thus, the direct communication security between UEs in the ProSe service is ensured, and the security of information transmission is improved.

[0221] Figure 12This is a flowchart illustrating a direct communication method provided in yet another embodiment of the present disclosure, applied to initiating a ProSe UE, such as... Figure 12 As shown, the direct communication method may include the following steps:

[0222] Step 1201: Obtain the security policy corresponding to the ProSe service.

[0223] Step 1202: Send a Direct Communication Request message to the receiving ProSe UE. The Direct Communication Request message contains the signaling security policy of the initiating ProSe UE.

[0224] Step 1203: Obtain the Direct Security Mode Command message sent by the ProSe UE. The Direct Security Mode Command includes the negotiation result of the signaling security policy.

[0225] For a detailed description of steps 1201 to 1203, please refer to the relevant descriptions in the above embodiments. This disclosure will not repeat them here.

[0226] Step 1204: Determine whether the security algorithm corresponding to the signaling security policy of the receiving ProSe UE is consistent with the security algorithm corresponding to the signaling security policy of the initiating ProSe UE.

[0227] In one embodiment of this disclosure, each signaling security policy has a corresponding security algorithm. Also, in one embodiment of this disclosure, the security algorithm corresponding to the signaling security policy of the receiving ProSe UE can be the same as the security algorithm corresponding to the signaling security policy of the initiating ProSe UE. Furthermore, in one embodiment of this disclosure, the security algorithm corresponding to the signaling security policy of the receiving ProSe UE can be different from the security algorithm corresponding to the signaling security policy of the initiating ProSe UE.

[0228] Specifically, in one embodiment of this disclosure, when the initiating ProSe UE determines that the security algorithm corresponding to the signaling security policy of the receiving ProSe UE is inconsistent with the security algorithm corresponding to its own signaling security policy, it indicates that the receiving ProSe UE and the sending ProSe UE do not have the qualification for protected direct connection, and step 1205 is continued.

[0229] Step 1205: Send a second rejection message to the receiving ProSe UE. The second rejection message is used to refuse to receive the Direct Security Mode Command message sent by the ProSe UE.

[0230] To sum up, in the direct communication method provided by the embodiment of the present disclosure, the initiating ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct communication security with the receiving ProSe UE based on the obtained security policy. Thus, in the embodiment of the present disclosure, the security policy corresponding to the ProSe service can be configured for the UE, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Thus, the safety of direct communication between UEs in the ProSe service is ensured, and the safety of information transmission is improved.

[0231] Figure 13 For another embodiment of the present disclosure, a flowchart of a direct communication method is provided, which is applied to an initiating ProSe UE. As shown in the figure, the direct communication method can include the following steps: Figure 13

[0232] Step 1301: Obtain the security policy corresponding to the ProSe service.

[0233] Step 1302: Send a Direct Communication Request message to the receiving ProSe UE, wherein the Direct Communication Request message contains the signaling security policy of the initiating ProSe UE.

[0234] Step 1303: Obtain the Direct Security Mode Command message sent by the receiving ProSe UE, wherein the Direct Security Mode Command includes the negotiation result of the signaling security policy.

[0235] For detailed description of steps 1301-1303, reference can be made to the related description in the above embodiments, which will not be repeated here.

[0236] Step 1304: Determine whether the negotiation result of the signaling security policy is NOT NEEDED.

[0237] In one embodiment of the present disclosure, when the negotiation result of the signaling security policy is NOT NEEDED, step 1305 is continued.

[0238] Step 1305: Change the UP security policy of the sending ProSe UE to NOT NEEDED.

[0239] ​In another embodiment of the present disclosure, when the negotiation result of the signaling encryption protection policy is NOT NEEDED, it indicates that the signaling between the initiating ProSe UE and the receiving ProSe UE does not need security protection and the negotiated encryption algorithm is the NULL algorithm, at this time, the UP encryption protection policy of the initiating ProSe UE can also be changed to NOT NEEDED.

[0240] In summary, in the direct communication method provided by the embodiments of the present disclosure, the initiating ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct communication security with the receiving ProSe UE based on the obtained security policy. Therefore, in the embodiments of the present disclosure, the UE can be configured with the security policy corresponding to the ProSe service, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Thus, the safety of direct communication between UEs in ProSe service is ensured, and the safety of information transmission is improved.

[0241] Figure 14 For a flowchart of a direct communication method provided by another embodiment of the present disclosure, applied to an initiating ProSe UE, as shown in the figure, the direct communication method can include the following steps: Figure 14

[0242] Step 1401, obtaining a security policy corresponding to a ProSe service.

[0243] Step 1402, sending a Direct Communication Request message to a receiving ProSe UE, wherein the Direct Communication Request message includes a signaling security policy of the initiating ProSe UE.

[0244] Step 1403, obtaining a Direct Security Mode Command message sent by the receiving ProSe UE, wherein the Direct Security Mode Command includes a negotiation result of the signaling security policy.

[0245] For detailed descriptions of steps 1401-1403, please refer to the related descriptions in the above embodiments, which will not be repeated here.

[0246] Step 1404, judging whether the security algorithm corresponding to the signaling security policy of the receiving ProSe UE is consistent with the security algorithm corresponding to the signaling security policy of the initiating ProSe UE.

[0247] ​In one embodiment of the present disclosure, when the initiating ProSe UE determines that the security algorithm corresponding to the signaling security policy of the receiving ProSe UE is consistent with the security algorithm corresponding to the signaling security policy of the initiating ProSe UE, it means that the receiving ProSe UE and the initiating ProSe UE have the qualification of protection of direct connection, and the step 1405 is continued.

[0248] The step 1405 is to send a Direct Security Mode Complete message to the receiving ProSe UE, wherein the Direct Security Mode Complete message contains the UP security policy of the initiating ProSe UE.

[0249] It should be noted that in one embodiment of the present disclosure, before the step 1405, the initiating ProSe UE will first determine whether the negotiation result of the signaling security policy received in the step 1403 is NOT NEEDED, and when it is NOT NEEDED, the UP security policy of the initiating ProSe UE will also be changed to NOT NEEDED. Then, when the Direct Security Mode Complete message is sent to the receiving ProSe UE, the Direct Security Mode Complete message actually contains the changed UP security policy of the initiating ProSe UE.

[0250] The step 1406 is to obtain a third rejection message sent by the receiving ProSe UE, wherein the third rejection message is used to reject the Direct Security Mode Complete message sent by the initiating ProSe UE.

[0251] In one embodiment of the present disclosure, after the receiving ProSe UE obtains the Direct Security Mode Complete message sent by the initiating ProSe UE, it will determine whether the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE meet a second preset condition. In one embodiment of the present disclosure, if it is determined that the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE meet the second preset condition, it means that there is a security policy conflict between the initiating ProSe UE and the receiving ProSe UE, and the two do not have the qualification of direct connection, and the receiving ProSe UE will send a third rejection message to the initiating ProSe UE.

[0252] In summary, in the direct communication method provided by the embodiments of the present disclosure, the initiating ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct communication security with the receiving ProSe UE based on the obtained security policy. Thus, in the embodiments of the present disclosure, the security policy corresponding to the ProSe service can be configured for the UE, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Thus, the safety of direct communication between UEs in the ProSe service is ensured, and the safety of information transmission is improved.

[0253] Figure 15 For another embodiment of the present disclosure, a flowchart of a direct communication method is provided, which is applied to an initiating ProSe UE. As shown in the figure, the direct communication method can include the following steps: Figure 15

[0254] Step 1501: Obtain the security policy corresponding to the ProSe service.

[0255] Step 1502: Send a Direct Communication Request message to the receiving ProSe UE, wherein the Direct Communication Request message contains the signaling security policy of the initiating ProSe UE.

[0256] Step 1503: Obtain the Direct Security Mode Command message sent by the receiving ProSe UE, wherein the Direct Security Mode Command includes the negotiation result of the signaling security policy.

[0257] Step 1504: Determine whether the security algorithm corresponding to the signaling security policy of the receiving ProSe UE is consistent with the security algorithm corresponding to the signaling security policy of the initiating ProSe UE.

[0258] In one embodiment of the present disclosure, when the initiating ProSe UE determines that the security algorithm corresponding to the signaling security policy of the receiving ProSe UE is consistent with the security algorithm corresponding to the signaling security policy of the initiating ProSe UE, it means that the receiving ProSe UE and the sending ProSe UE have the qualification to protect the direct connection, and step 1505 is continued.

[0259] Step 1505: Send a Direct Security Mode Complete message to the receiving ProSe UE, wherein the Direct Security Mode Complete message contains the UP security policy of the initiating ProSe UE.

[0260] ​The detailed description of steps 1501-1505 can refer to the related description in the above embodiments, and the detailed description is not repeated here.

[0261] It should be noted that in an embodiment of the present disclosure, before the step 1405 of sending the Direct Security Mode Complete message to the receiving ProSe UE, the initiating ProSe UE determines whether the negotiation result of the signaling security policy received in the step 1403 is NOT NEEDED, and when the negotiation result is NOT NEEDED, the UP security policy of the initiating ProSe UE is also changed to NOT NEEDED. Then, when the Direct Security Mode Complete message is sent to the receiving ProSe UE, the Direct Security Mode Complete message actually contains the changed UP security policy of the initiating ProSe UE.

[0262] The step 1506 is to obtain the Direct Communication Accept message sent by the receiving ProSe UE, and the Direct Communication Accept message includes the negotiation result of the UP security policy.

[0263] In an embodiment of the present disclosure, after the receiving ProSe UE obtains the Direct Security Mode Complete message sent by the initiating ProSe UE, the receiving ProSe UE determines whether the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE meet the second preset condition.

[0264] In an embodiment of the present disclosure, if it is determined that the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE do not meet the second preset condition, it means that there is no security policy conflict between the initiating ProSe UE and the receiving ProSe UE, and both of them have the qualification to protect the direct connection. The receiving ProSe UE determines the negotiation result of the UP security policy based on the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE. Then, the Direct Communication Accept message is sent to the initiating ProSe UE, and the Direct Communication Accept message includes the negotiation result of the UP security policy.

[0265] In summary, in the direct communication method provided by the embodiments of the present disclosure, the initiating ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct communication security with the receiving ProSe UE based on the obtained security policy. Thus, in the embodiments of the present disclosure, the security policy corresponding to the ProSe service can be configured for the UE, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Thus, the safety of direct communication between UEs in the ProSe service is ensured, and the safety of information transmission is improved.

[0266] Figure 16 For another embodiment of the present disclosure, a flowchart of a direct communication method is provided, which is applied to an initiating ProSe UE. As shown in the figure, the direct communication method can include the following steps: Figure 16

[0267] Step 1601: Obtain the security policy corresponding to the ProSe service.

[0268] Step 1602: Send a Direct Communication Request message to the receiving ProSe UE, wherein the Direct Communication Request message contains the signaling security policy of the initiating ProSe UE.

[0269] Step 1603: Obtain the Direct Security Mode Command message sent by the receiving ProSe UE, wherein the Direct Security Mode Command includes the negotiation result of the signaling security policy.

[0270] Step 1604: Determine whether the security algorithm corresponding to the signaling security policy of the receiving ProSe UE is consistent with the security algorithm corresponding to the signaling security policy of the initiating ProSe UE.

[0271] In one embodiment of the present disclosure, when the initiating ProSe UE determines that the security algorithm corresponding to the signaling security policy of the receiving ProSe UE is consistent with the security algorithm corresponding to the signaling security policy of the initiating ProSe UE, it means that the receiving ProSe UE and the sending ProSe UE have the qualification to protect the direct connection, and step 1605 is continued.

[0272] Step 1605: Send a Direct Security Mode Complete message to the receiving ProSe UE, wherein the Direct Security Mode Complete message contains the UP security policy of the initiating ProSe UE.

[0273] ​It should be noted that, in one embodiment of this disclosure, before sending the Direct Security Mode Complete message to the receiving ProSe UE in step 1605, the initiating ProSe UE first determines whether the negotiation result of the signaling security policy received in step 1603 is NOT NEEDED. If it is NOT NEEDED, the initiating ProSe UE's UP security policy will also be changed to NOT NEEDED. Furthermore, when the Direct Security Mode Complete message is subsequently sent to the receiving ProSe UE, the Direct Security Mode Complete message specifically contains the modified UP security policy of the initiating ProSe UE.

[0274] Step 1606: Obtain the Direct Communication Accept message sent by the ProSe UE. The Direct Communication Accept message includes the negotiation result of the UP security policy.

[0275] For a detailed description of steps 1601 to 1606, please refer to the relevant descriptions in the above embodiments. This disclosure will not repeat them here.

[0276] Step 1607: Based on the negotiation results of the signaling security policy and the UP security policy, establish direct communication with the ProSe UE.

[0277] In summary, in the direct communication method provided in this disclosure, the ProSe initiating UE can obtain the security policy corresponding to the ProSe service and establish a secure direct communication connection with the receiving ProSe UE based on the obtained security policy. Therefore, in this disclosure, a security policy corresponding to the ProSe service can be configured for the UE, enabling the receiving ProSe UE and the initiating ProSe UE to establish a secure direct communication connection based on the security policy. This ensures the security of direct communication between UEs in the ProSe service and improves the security of information transmission.

[0278] Figure 17 This is a flowchart illustrating a direct communication method provided in another embodiment of the present disclosure, applied to receiving a ProSe UE, such as... Figure 17 As shown, the direct communication method may include the following steps:

[0279] Step 1701: Obtain the security policy corresponding to the ProSe service.

[0280] Step 1702, receiving a Direct Security Mode Complete message initiated by the ProSe UE, wherein the UP security policy of the initiating ProSe UE is contained in the Direct Security Mode Complete message.

[0281] Step 1703, determining whether the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE meet a second preset condition, and if the second preset condition is met, performing step 1704.

[0282] In an embodiment of the present disclosure, if it is determined that the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE meet the second preset condition, it indicates that there is a security policy conflict between the initiating ProSe UE and the receiving ProSe UE, and both of them do not have the qualification to protect the direct connection, and step 1704 is continued to be performed.

[0283] Step 1704, sending a third rejection message to the initiating ProSe UE, wherein the third rejection message is used to reject the Direct Security Mode Complete message initiated by the initiating ProSe UE.

[0284] For details of steps 1701-1704, reference can be made to the related description in the above embodiments, and the present disclosure will not be described here.

[0285] In summary, in the direct communication method provided by the embodiments of the present disclosure, the receiving ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct communication security with the initiating ProSe UE based on the obtained security policy. Therefore, in the embodiments of the present disclosure, the UE can be configured with the security policy corresponding to the ProSe service, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Thus, the direct communication security between UEs in the ProSe service is ensured, and the security of information transmission is improved.

[0286] Figure 18 A flowchart of a direct communication method provided by another embodiment of the present disclosure is applied to a receiving ProSe UE, as shown in Figure 18 The direct communication method can include the following steps:

[0287] Step 1801, obtaining a security policy corresponding to a ProSe service.

[0288] Step 1802, receiving a Direct Security Mode Complete message initiated by the ProSe UE, wherein the UP security policy of the initiating ProSe UE is contained in the Direct Security Mode Complete message.

[0289] Step 1803, determining whether the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE meet the second preset condition, and if not, performing step 1804.

[0290] In an embodiment of the present disclosure, if it is determined that the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE do not meet the second preset condition, it means that there is no security policy conflict between the initiating ProSe UE and the receiving ProSe UE, and both of them have the qualification to protect the direct connection, and step 1804 is continued to be performed.

[0291] Step 1804, determining the negotiation result of the UP security policy based on the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE.

[0292] Step 1805, sending a Direct Communication Accept message to the initiating ProSe UE, wherein the Direct Communication Accept message includes the negotiation result of the UP security policy.

[0293] For details of steps 1801-1805, reference can be made to the related description in the above embodiments, which will not be repeated here.

[0294] In summary, in the direct communication method provided by the embodiments of the present disclosure, the receiving ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct communication security with the initiating ProSe UE based on the obtained security policy. Therefore, in the embodiments of the present disclosure, the UE can be configured with the security policy corresponding to the ProSe service, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Thus, the direct communication security between UEs in the ProSe service is ensured, and the security of information transmission is improved.

[0295] Figure 19 A flowchart of a direct communication method provided by another embodiment of the present disclosure is applied to an initiating ProSe UE, as shown in Figure 19 The direct communication method can include the following steps:

[0296] Step 1901, obtaining a security policy corresponding to the ProSe service.

[0297] Step 1902, sending a Direct Security Mode Complete message to the receiving ProSe UE, wherein the Direct Security Mode Complete message contains the UP security policy of the initiating ProSe UE.

[0298] Step 1903, obtaining a third rejection message sent by the receiving ProSe UE, the third rejection message being used to reject the Direct Security Mode Complete message sent by the initiating ProSe UE.

[0299] Wherein, the detailed introduction about steps 1901-1903 can refer to the related introduction in the above embodiments, and the present disclosure embodiments will not be repeated here.

[0300] In summary, in the direct communication method provided by the embodiments of the present disclosure, the initiating ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct communication security with the receiving ProSe UE based on the obtained security policy. Therefore, in the embodiments of the present disclosure, the UE can be configured with the security policy corresponding to the ProSe service, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Thus, the direct communication security between UEs in the ProSe service is ensured, and the security of information transmission is improved.

[0301] Figure 20 For another embodiment of the present disclosure, a flowchart of a direct communication method is provided, which is applied to an initiating ProSe UE, as shown in Figure 20 The direct communication method can include the following steps:

[0302] Step 2001, obtaining a security policy corresponding to the ProSe service.

[0303] Step 2002, sending a Direct Security Mode Complete message to the receiving ProSe UE, wherein the Direct Security Mode Complete message contains the UP security policy of the initiating ProSe UE.

[0304] Step 2003, obtaining a Direct Communication Accept message sent by the receiving ProSe UE, the Direct Communication Accept message including the negotiation result of the UP security policy.

[0305] The detailed description of steps 2001-2003 can refer to the related description in the above embodiments, and the disclosure embodiments will not be described here.

[0306] In summary, in the direct communication method provided by the embodiments of the disclosure, the initiating ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct communication security with the receiving ProSe UE based on the obtained security policy. Therefore, in the embodiments of the disclosure, the security policy corresponding to the ProSe service can be configured for the UE, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Thus, the safety of direct communication between UEs in the ProSe service is ensured, and the safety of information transmission is improved.

[0307] Figure 21 The structure diagram of a direct communication device provided by an embodiment of the disclosure is shown in FIG. 2. As shown in FIG. 2, the device 2100 can include: Figure 21

[0308] The obtaining module 2101 is configured to obtain the security policy corresponding to the ProSe service.

[0309] The communication module 2102 is configured to establish direct communication security with the initiating ProSe UE based on the security policy.

[0310] In summary, in the direct communication device provided by the embodiments of the disclosure, the receiving ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct communication security with the initiating ProSe UE based on the obtained security policy. Therefore, in the embodiments of the disclosure, the security policy corresponding to the ProSe service can be configured for the UE, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Thus, the safety of direct communication between UEs in the ProSe service is ensured, and the safety of information transmission is improved.

[0311] In an embodiment of the disclosure, the security policy includes at least one of the following:

[0312] a signaling security policy;

[0313] a user plane (UP) security policy.

[0314] Further, in another embodiment of the disclosure, the security policy includes at least one of the following:

[0315] a signaling integrity protection policy;

[0316] a signaling encryption protection policy;

[0317] ​A policy of UP integrity protection

[0318] A policy of UP encryption protection

[0319] Further, in another embodiment of the present disclosure, the security policy includes: REQUIRED; NOT NEEDED; PREFERRED.

[0320] Further, in another embodiment of the present disclosure, the obtaining module is further configured to:

[0321] obtain the ProSe service to be protected and the security policy corresponding to the ProSe service to be protected sent by the PCF.

[0322] Further, in another embodiment of the present disclosure, the obtaining module is further configured to:

[0323] obtain the ProSe service to be protected and the security policy corresponding to the ProSe service to be protected sent by the ProSe application server.

[0324] Further, in another embodiment of the present disclosure, the obtaining module is further configured to:

[0325] obtain the ProSe service to be protected and the security policy corresponding to the ProSe service to be protected configured on the UICC.

[0326] Further, in another embodiment of the present disclosure, the communication module 2102 is further configured to:

[0327] obtain the direct communication request Direct Communication Request message sent by the initiating ProSe UE, and the Direct Communication Request message includes the signaling security policy of the initiating ProSe UE;

[0328] determine whether the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE meet a first preset condition;

[0329] The first preset condition includes at least one of the following:

[0330] the policy of the signaling integrity protection of the initiating ProSe UE is NOT NEEDED, and the policy of the signaling integrity protection of the receiving ProSe UE is REQUIRED;

[0331] the policy of the signaling encryption protection of the initiating ProSe UE is NOT NEEDED, and the policy of the signaling encryption protection of the receiving ProSe UE is REQUIRED;

[0332] the policy of the signaling integrity protection of the receiving ProSe UE is NOT NEEDED;

[0333] the policy of the signaling encryption protection of the receiving ProSe UE is NOT NEEDED;

[0334] when the first preset condition is met, a first rejection message is sent to the initiating ProSe UE, and the first rejection message is used to reject the Direct Communication Request message sent by the initiating ProSe UE.

[0335] Further, in another embodiment of the present disclosure, the communication module 2102 is further used for:

[0336] obtaining the Direct Communication Request message sent by the initiating ProSe UE, and the Direct Communication Request message contains the signaling security policy of the initiating ProSe UE;

[0337] determining whether the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE meet a first preset condition;

[0338] the first preset condition includes at least one of the following:

[0339] the policy of the signaling integrity protection of the initiating ProSe UE is NOT NEEDED, and the policy of the signaling integrity protection of the receiving ProSe UE is REQUIRED;

[0340] the policy of the signaling encryption protection of the initiating ProSe UE is NOT NEEDED, and the policy of the signaling encryption protection of the receiving ProSe UE is REQUIRED;

[0341] the policy of the signaling integrity protection of the initiating ProSe UE is REQUIRED, and the policy of the signaling integrity protection of the receiving ProSe UE is NOT NEEDED;

[0342] the policy of the signaling encryption protection of the initiating ProSe UE is REQUIRED, and the policy of the signaling encryption protection of the receiving ProSe UE is NOT NEEDED;

[0343] determining the negotiation result of the signaling security policy based on the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE when the first preset condition is not met;

[0344] sending a Direct Security Mode Command message to the initiating ProSe UE, the Direct Security Mode Command message including the negotiation result of the signaling security policy.

[0345] Further, in another embodiment of the present disclosure, the negotiation result of the signaling security policy includes at least one of the following:

[0346] the negotiation result of the signaling integrity protection policy;

[0347] the negotiation result of the signaling encryption protection policy;

[0348] Further, in an embodiment of the present disclosure, the communication module 2102 is further configured to:

[0349] if the signaling integrity protection policy of the initiating ProSe UE is NOT NEEDED and / or the signaling integrity protection policy of the receiving ProSe UE is NOT NEEDED, determining the negotiation result of the signaling integrity protection policy as NOT NEEDED;

[0350] if the signaling integrity protection policy of the initiating ProSe UE is REQUIRED and / or the signaling integrity protection policy of the receiving ProSe UE is REQUIRED, determining the negotiation result of the signaling integrity protection policy as REQUIRED;

[0351] if the signaling integrity protection policy of the initiating ProSe UE is PREFERRED and the signaling integrity protection policy of the receiving ProSe UE is PREFERRED, determining the negotiation result of the signaling integrity protection policy as REQUIRED or NOT NEEDED;

[0352] if the signaling encryption protection policy of the initiating ProSe UE is NOT NEEDED and / or the signaling encryption protection policy of the receiving ProSe UE is NOT NEEDED, determining the negotiation result of the signaling encryption protection policy as NOT NEEDED;

[0353] If the policy of signaling encryption protection of the initiating ProSe UE is REQUIRED, and / or the policy of signaling encryption protection of the receiving ProSe UE is REQUIRED, it is determined that the negotiation result of the policy of signaling encryption protection is REQUIRED.

[0354] If the policy of signaling encryption protection of the initiating ProSe UE is PREFERRED, and the policy of signaling encryption protection of the receiving ProSe UE is PREFERRED, it is determined that the negotiation result of the policy of signaling encryption protection is REQUIRED or NOT NEEDED.

[0355] Further, in another embodiment of the present disclosure, the apparatus is further configured to:

[0356] receive a second rejection message sent by the initiating ProSe UE, the second rejection message being used to reject the Direct Security Mode Command message sent by the receiving ProSe UE.

[0357] Further, in another embodiment of the present disclosure, the apparatus is further configured to:

[0358] When the negotiation result of the policy of signaling encryption protection is NOT NEEDED, the policy of UP encryption protection of the receiving ProSe UE is changed to NOT NEEDED.

[0359] Further, in another embodiment of the present disclosure, the apparatus is further configured to:

[0360] receive a Direct Security Mode Complete message sent by the initiating ProSe UE, the Direct Security Mode Complete message comprising the UP security policy of the initiating ProSe UE;

[0361] determine whether the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE satisfy a second preset condition;

[0362] The second preset condition comprises at least one of the following:

[0363] the policy of UP integrity protection of the initiating ProSe UE is NOT NEEDED, and the policy of UP integrity protection of the receiving ProSe UE is REQUIRED;

[0364] the policy of UP encryption protection of the initiating ProSe UE is NOT NEEDED, and the policy of UP encryption protection of the receiving ProSe UE is REQUIRED;

[0365] the policy of UP integrity protection of the initiating ProSe UE is NOT NEEDED, and the policy of UP integrity protection of the receiving ProSe UE is REQUIRED;

[0366] the policy of UP encryption protection of the initiating ProSe UE is NOT NEEDED, and the policy of UP encryption protection of the receiving ProSe UE is REQUIRED;

[0367] when the second preset condition is met, sending a third rejection message to the initiating ProSe UE, the third rejection message being used to reject a Direct Security Mode Complete message sent by the initiating ProSe UE.

[0368] Further, in another embodiment of the present disclosure, the apparatus is further used for:

[0369] receiving a Direct Security Mode Complete message sent by the initiating ProSe UE, the Direct Security Mode Complete message containing a UP security policy of the initiating ProSe UE;

[0370] determining whether the UP security policy of the initiating ProSe UE and a UP security policy of the receiving ProSe UE meet a second preset condition;

[0371] the second preset condition comprises at least one of the following:

[0372] the policy of UP integrity protection of the initiating ProSe UE is NOT NEEDED, and the policy of UP integrity protection of the receiving ProSe UE is REQUIRED;

[0373] the policy of UP encryption protection of the initiating ProSe UE is NOT NEEDED, and the policy of UP encryption protection of the receiving ProSe UE is REQUIRED;

[0374] the policy of UP integrity protection of the initiating ProSe UE is NOT NEEDED, and the policy of UP integrity protection of the receiving ProSe UE is REQUIRED;

[0375] the policy of UP encryption protection of the initiating ProSe UE is NOT NEEDED, and the policy of UP encryption protection of the receiving ProSe UE is REQUIRED;

[0376] determining the negotiation result of the UP security policy based on the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE when the second preset condition is not met;

[0377] sending a Direct Communication Accept message to the initiating ProSe UE, the Direct Communication Accept message including the negotiation result of the UP security policy.

[0378] Further, in another embodiment of the present disclosure, the negotiation result of the UP security policy includes at least one of the following: a negotiation result of a UP integrity protection policy; a negotiation result of a UP encryption protection policy.

[0379] Further, in another embodiment of the present disclosure, the apparatus is further configured to:

[0380] if the UP integrity protection policy of the initiating ProSe UE is NOT NEEDED and / or the UP integrity protection policy of the receiving ProSe UE is NOT NEEDED, determining that the negotiation result of the UP integrity protection policy is NOT NEEDED;

[0381] if the UP integrity protection policy of the initiating ProSe UE is REQUIRED and / or the UP integrity protection policy of the receiving ProSe UE is REQUIRED, determining that the negotiation result of the UP integrity protection policy is REQUIRED;

[0382] if the UP integrity protection policy of the initiating ProSe UE is PREFERRED and the UP integrity protection policy of the receiving ProSe UE is PREFERRED, determining that the negotiation result of the UP integrity protection policy is REQUIRED or NOT NEEDED;

[0383] if the UP encryption protection policy of the initiating ProSe UE is NOT NEEDED and / or the UP encryption protection policy of the receiving ProSe UE is NOT NEEDED, determining that the negotiation result of the UP encryption protection policy is NOT NEEDED;

[0384] if the UP encryption protection policy of the initiating ProSe UE is REQUIRED and / or the UP encryption protection policy of the receiving ProSe UE is REQUIRED, determining that the negotiation result of the UP encryption protection policy is REQUIRED;

[0385] If the policy of UP encryption protection of the initiating ProSe UE is PREFERRED, and the policy of UP encryption protection of the receiving ProSe UE is PREFERRED, the negotiation result of the policy of UP encryption protection is determined as REQUIRED or NOT NEEDED.

[0386] Further, in another embodiment of the present disclosure, the apparatus is further used for:

[0387] Based on the negotiation result of the signaling security policy and the negotiation result of the UP security policy, the direct communication with the initiating ProSe UE is established.

[0388] Figure 22 A structure diagram of the direct communication according to another embodiment of the present disclosure is shown in FIG. 2. As shown in FIG. 2, the apparatus 2200 can include: Figure 22

[0389] The obtaining module 2201 is configured to obtain the security policy corresponding to the ProSe service.

[0390] The communication module 2202 is configured to establish the direct communication security with the receiving ProSe UE based on the security policy.

[0391] In summary, in the direct communication apparatus provided by the embodiments of the present disclosure, the receiving ProSe UE can obtain the security policy corresponding to the ProSe service, and establish the direct communication security with the initiating ProSe UE based on the obtained security policy. Thus, in the embodiments of the present disclosure, the security policy corresponding to the ProSe service can be configured for the UE, so that the receiving ProSe UE and the initiating ProSe UE can establish the direct communication security based on the security policy. Therefore, the direct communication security between the UEs in the ProSe service is ensured, and the security of information transmission is improved.

[0392] In one embodiment of the present disclosure, the security policy includes at least one of the following:

[0393] The signaling security policy;

[0394] The UP security policy.

[0395] Further, in another embodiment of the present disclosure, the security policy includes at least one of the following:

[0396] The policy of signaling integrity protection;

[0397] The policy of signaling encryption protection;

[0398] The policy of UP integrity protection;

[0399] The policy of UP encryption protection. ​

[0400] Further, in another embodiment of the present disclosure, the security policy includes: REQUIRED; NOTNEEDED; PREFERRED.

[0401] Further, in another embodiment of the present disclosure, the obtaining module is further configured to:

[0402] obtain the protected ProSe service and the security policy corresponding to the protected ProSe service sent by the PCF.

[0403] Further, in another embodiment of the present disclosure, the obtaining module is further configured to:

[0404] obtain the protected ProSe service and the security policy corresponding to the protected ProSe service sent by the ProSe application server.

[0405] Further, in another embodiment of the present disclosure, the obtaining module is further configured to:

[0406] obtain the protected ProSe service and the security policy corresponding to the protected ProSe service configured on the UICC.

[0407] Further, in another embodiment of the present disclosure, the communication module 2202 is further configured to:

[0408] send a Direct Communication Request message to the receiving ProSe UE, wherein the Direct Communication Request message includes the signaling security policy of the initiating ProSe UE;

[0409] obtain a first rejection message sent by the receiving ProSe UE, wherein the first rejection message is used to reject the Direct Communication Request message sent by the initiating ProSe UE.

[0410] Further, in another embodiment of the present disclosure, the communication module 2202 is further configured to:

[0411] send a Direct Communication Request message to the receiving ProSe UE, wherein the Direct Communication Request message includes the signaling security policy of the initiating ProSe UE;

[0412] obtain a Direct Security Mode Command message sent by the receiving ProSe UE, wherein the Direct Security Mode Command includes the negotiation result of the signaling security policy.

[0413] Further, in another embodiment of the present disclosure, the communication module 2202 is further configured to:

[0414] determine whether the security algorithm corresponding to the signaling security policy of the receiving ProSe UE is consistent with the security algorithm corresponding to the signaling security policy of the initiating ProSe UE;

[0415] when inconsistent, send a second rejection message to the receiving ProSe UE, the second rejection message being used to reject the Direct Security Mode Command message sent by the receiving ProSe UE.

[0416] Further, in another embodiment of the present disclosure, the negotiation result of the signaling security policy includes at least one of the following:

[0417] the negotiation result of the signaling integrity protection policy;

[0418] the negotiation result of the signaling encryption protection policy.

[0419] Further, in another embodiment of the present disclosure, the apparatus is further configured to:

[0420] when the negotiation result of the signaling encryption protection policy is NOT NEEDED, change the UP encryption protection policy of the initiating ProSe UE to NOT NEEDED.

[0421] Further, in another embodiment of the present disclosure, the apparatus is further configured to:

[0422] send a Direct Security Mode Complete message to the receiving ProSe UE, the Direct Security Mode Complete message containing the UP security policy of the initiating ProSe UE;

[0423] obtain a third rejection message sent by the receiving ProSe UE, the third rejection message being used to reject the Direct Security Mode Complete message sent by the initiating ProSe UE.

[0424] Further, in another embodiment of the present disclosure, the apparatus is further configured to:

[0425] send a Direct Security Mode Complete message to the receiving ProSe UE, the Direct Security Mode Complete message containing the UP security policy of the initiating ProSe UE;

[0426] obtain a Direct Communication Accept message sent by the ProSe UE, the Direct Communication Accept message including a negotiation result of the UP security policy.

[0427] Further, in another embodiment of the present disclosure, the apparatus is further used for:

[0428] performing direct communication with the ProSe UE based on the negotiation result of the signaling security policy and the negotiation result of the UP security policy.

[0429] The computer storage medium provided by the embodiments of the present disclosure stores an executable program; the executable program is executed by a processor to implement the method shown in any of Figures 1 to 8 , Figures 17 to 18 or Figures 9 to 16 , Figures 19 to 20 .

[0430] To achieve the above-mentioned embodiments, the present disclosure further proposes a computer program product comprising a computer program, which, when executed by a processor, implements the method shown in any of Figures 1 to 8 , Figures 17 to 18 or Figures 9 to 16 , Figures 19 to 20 .

[0431] In addition, to achieve the above-mentioned embodiments, the present disclosure further proposes a computer program, which, when executed by a processor, implements the method shown in any of Figures 1 to 8 , Figures 17 to 18 or Figures 9 to 16 , Figures 19 to 20 .

[0432] Figure 19 is a block diagram of a user equipment UE 1900 provided by an embodiment of the present disclosure. For example, the UE 1900 can be a mobile phone, a computer, a digital broadcast terminal device, a messaging device, a game console, a tablet device, a medical device, a fitness device, a personal digital assistant, etc.

[0433] Referring to Figure 23 , the UE 2300 can include at least one of the following components: a processing component 2302, a memory 2304, a power supply component 2306, a multimedia component 2308, an audio component 2310, an input / output (I / O) interface 2312, a sensor component 2313, and a communication component 2316.

[0434] The processing component 2302 generally controls the overall operations of the UE 2300, such as operations associated with display, telephony, data communication, camera, and recording operations. The processing component 2302 can include one or more processors 2320 to execute instructions delivered from a memory 2304 to complete all or part of the steps of the methods described above. In addition, the processing component 2302 can include at least one module to facilitate interaction between the processing component 2302 and other components. For example, the processing component 2302 can include a multimedia module to facilitate the interaction between the multimedia component 2308 and the processing component 2302.

[0435] The memory 2304 is configured to store various types of data to support operations of the UE 2300. Examples of these data include instructions for any application or method operating on the UE 2300, contact data, phonebook data, messages, pictures, videos, and so on. The memory 2304 can be implemented by any type of volatile or non-volatile storage devices or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk, or optical disk.

[0436] The power supply component 2306 supplies electrical power for the various components of the UE 2300. The power supply component 2306 can include a power supply management system, at least one power supply, and other components associated with generating, managing, and delivering electrical power for the UE 2300.

[0437] The multimedia component 2308 includes a screen providing an output interface between the UE 2300 and a user. In some embodiments, the screen can include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen can be implemented as a touch screen to receive an input signal from a user. The touch panel includes at least one touch sensor to sense a touch, slide, and gesture on the touch panel. The touch sensor can not only sense a boundary of a touching or sliding action, but also detect a pressure by a duration and a pressure associated with the touching or sliding action. In some embodiments, the multimedia component 2308 includes a front camera and / or a rear camera. The front and / or rear camera can receive external multimedia data when the UE 2300 is in an operation mode, such as a shooting mode or a video mode. Each of the front and rear camera can be a fixed optical lens system or have a focal length and optical zoom capability.

[0438] The audio component 2310 is configured to output and / or input audio signals. For example, the audio component 2310 includes a microphone (MIC) that is configured to receive an external audio signal when the UE 2300 is in an operation mode, such as a calling mode, a recording mode, and a voice recognition mode. The received audio signal can be further stored in the memory 2304 or transmitted via the communication component 2316. In some embodiments, the audio component 2310 also includes a speaker for outputting an audio signal.

[0439] The I / O interface 2312 provides an interface between the processing component 2302 and peripheral interface modules, which can be a keypad, a click wheel, buttons, and so on. The buttons can include, but are not limited to, a home button, a volume button, a start button, and a lock button.

[0440] The sensor component 2313 includes at least one sensor for providing status assessments of various aspects of the UE 2300. For example, the sensor component 2313 can detect an open / closed position of the device 2300, relative positioning of components, such as a display and a keypad of the UE 2300, a change of location of the UE 2300 or a component of the UE 2300, the presence or absence of user contact with the UE 2300, an orientation or acceleration / deceleration / g-force and a temperature change of the UE 2300. The sensor component 2313 can include a proximity sensor configured to detect presence of an object in a proximity without any physical touch. The sensor component 2313 can further include a light sensor, such as a CMOS or CCD image sensor, for use in imaging applications. In some embodiments, the sensor component 2313 can also include an acceleration sensor, a gyroscope sensor, a magnetic sensor, a pressure sensor, or a temperature sensor.

[0441] The communication component 2316 is configured to facilitate wired or wireless communication between the UE 2300 and another device. The UE 2300 can access a wireless network based on a communication standard, such as WiFi, 2G, or 3G, or a combination thereof. In an example embodiment, the communication component 2316 receives broadcast signals or broadcasting-related information from an external broadcasting management system via a broadcasting channel. In an example embodiment, the communication component 2316 further includes a Near Field Communication (NFC) module to facilitate short-range communication. For example, the NFC module can be implemented based on Radio Frequency Identification (RFID) technology, infrared data association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology, and other technology.

[0442] In an example embodiment, the UE 2300 can be implemented with at least one application-specific integrated circuit (ASIC), digital signal processor (DSP), digital signal processing device (DSPD), programmable logic device (PLD), field programmable gate array (FPGA), controller, microcontroller, microprocessor or other electronic component, for performing the above methods.

[0443] Other embodiments of the application will be apparent to those skilled in the art from consideration of the specification and practice of the application disclosed herein. It is intended that the specification and examples be considered as exemplary only, with a true scope and spirit of the application being indicated by the following claims.

[0444] It is to be understood that the application is not limited to the precise construction described in the specification and shown in the drawings, and that various modifications and changes can be made by those skilled in the art without departing from the scope of the application. The scope of the application is limited only by the claims that follow.

Claims

1. A direct connection communication method characterized by comprising: A method applied to a receiving Proximity-based Service, ProSe, User Equipment, UE, comprises: obtaining a security policy corresponding to a ProSe service; and establishing a direct communication security with an initiating ProSe UE based on the security policy; wherein the security policy comprises at least one of: a signaling security policy; a User Plane, UP, security policy; wherein the signaling security policy comprises: a signaling integrity protection policy; wherein the UP security policy comprises at least one of: a UP integrity protection policy; a UP encryption protection policy; wherein the security policy comprises: REQUIRED; NOT NEEDED; or PREFERRED; wherein the establishing the direct communication security with the initiating ProSe UE based on the security policy comprises: obtaining a Direct Communication Request message sent by the initiating ProSe UE, the Direct Communication Request message comprising a signaling security policy of the initiating ProSe UE; determining a negotiation result of the signaling security policy based on the signaling security policy of the initiating ProSe UE and a signaling security policy of the receiving ProSe UE when a first preset condition is not met; sending a Direct Security Mode Command message to the initiating ProSe UE, the Direct Security Mode Command message comprising the negotiation result of the signaling security policy; wherein the first preset condition comprises at least one of: the signaling integrity protection policy of the initiating ProSe UE is NOT NEEDED and the signaling integrity protection policy of the receiving ProSe UE is REQUIRED; the signaling integrity protection policy of the initiating ProSe UE is REQUIRED and the signaling integrity protection policy of the receiving ProSe UE is NOT NEEDED; wherein the method further comprises: when the negotiation result of the signaling encryption protection policy is NOT NEEDED, changing a UP encryption protection policy of the receiving ProSe UE to NOT NEEDED.

2. The method of claim 1, wherein, The signaling security policy further comprises a signaling encryption protection policy.

3. The method of claim 1 or 2, wherein, The obtaining the security policy corresponding to the ProSe service comprises: obtaining a ProSe service to be protected and a security policy corresponding to the ProSe service to be protected sent by a Policy Control Function, PCF.

4. The method of claim 1 or 2, wherein, The obtaining the security policy corresponding to the ProSe service comprises: obtaining a ProSe service to be protected and a security policy corresponding to the ProSe service to be protected sent by a ProSe Application Server.

5. The method of claim 1 or 2, wherein, The obtaining the security policy corresponding to the ProSe service comprises: Obtaining a ProSe service configured on an embedded Universal Integrated Circuit Card (UICC) and a security policy corresponding to the ProSe service.

6. The method of claim 1, wherein, The establishing of the direct communication security between the initiating ProSe UE and the receiving ProSe UE based on the security policy comprises: determining whether the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE satisfy a first preset condition; The first preset condition comprises at least one of the following: the signaling integrity protection policy of the initiating ProSe UE is NOT NEEDED, and the signaling integrity protection policy of the receiving ProSe UE is REQUIRED; the signaling encryption protection policy of the initiating ProSe UE is NOT NEEDED, and the signaling encryption protection policy of the receiving ProSe UE is REQUIRED; the signaling integrity protection policy of the initiating ProSe UE is REQUIRED, and the signaling integrity protection policy of the receiving ProSe UE is NOT NEEDED; the signaling encryption protection policy of the initiating ProSe UE is REQUIRED, and the signaling encryption protection policy of the receiving ProSe UE is NOT NEEDED; when the first preset condition is satisfied, sending a first rejection message to the initiating ProSe UE, the first rejection message being used to reject a Direct Communication Request message sent by the initiating ProSe UE.

7. The method of claim 1, wherein, The method further comprises: determining whether the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE satisfy a first preset condition; The first preset condition further comprises at least one of the following: the signaling encryption protection policy of the initiating ProSe UE is NOT NEEDED, and the signaling encryption protection policy of the receiving ProSe UE is REQUIRED; the signaling encryption protection policy of the initiating ProSe UE is REQUIRED, and the signaling encryption protection policy of the receiving ProSe UE is NOT NEEDED.

8. The method of claim 7, wherein, The negotiation result of the signaling security policy comprises at least one of the following: a negotiation result of the signaling integrity protection policy; a negotiation result of the signaling encryption protection policy. The determining of the negotiation result of the signaling security policy based on the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE comprises: when the signaling integrity protection policy of the initiating ProSe UE is NOT NEEDED, and / or the signaling integrity protection policy of the receiving ProSe UE is NOT NEEDED, determining that the negotiation result of the signaling integrity protection policy is NOT NEEDED; determining that the negotiation result of the signaling integrity protection policy is REQUIRED when the signaling integrity protection policy of the initiating ProSe UE is REQUIRED and / or the signaling integrity protection policy of the receiving ProSe UE is REQUIRED; determining that the negotiation result of the signaling integrity protection policy is REQUIRED or NOT NEEDED when the signaling integrity protection policy of the initiating ProSe UE is PREFERRED and the signaling integrity protection policy of the receiving ProSe UE is PREFERRED; determining that the negotiation result of the signaling encryption protection policy is NOT NEEDED when the signaling encryption protection policy of the initiating ProSe UE is NOT NEEDED and / or the signaling encryption protection policy of the receiving ProSe UE is NOT NEEDED; determining that the negotiation result of the signaling encryption protection policy is REQUIRED when the signaling encryption protection policy of the initiating ProSe UE is REQUIRED and / or the signaling encryption protection policy of the receiving ProSe UE is REQUIRED; determining that the negotiation result of the signaling encryption protection policy is REQUIRED or NOT NEEDED when the signaling encryption protection policy of the initiating ProSe UE is PREFERRED and the signaling encryption protection policy of the receiving ProSe UE is PREFERRED.

9. The method of claim 8, wherein, The method further comprises: receiving a second rejection message sent by the initiating ProSe UE, the second rejection message being used to reject the Direct Security Mode Command message sent by the receiving ProSe UE.

10. The method of claim 8, wherein, The method further comprises: changing the signaling integrity protection policy of the receiving ProSe UE to NOT NEEDED when the negotiation result of the signaling integrity protection policy is NOT NEEDED.

11. The method of claim 10, wherein, The method further comprises: receiving a Direct Security Mode Complete message sent by the initiating ProSe UE, the Direct Security Mode Complete message containing the UP security policy of the initiating ProSe UE; and determining whether the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE meet a second preset condition; wherein the second preset condition comprises at least one of the following: the UP integrity protection policy of the initiating ProSe UE is NOT NEEDED and the UP integrity protection policy of the receiving ProSe UE is REQUIRED; the policy of UP encryption protection of the initiating ProSe UE is REQUIRED, and the policy of UP encryption protection of the receiving ProSe UE is NOT NEEDED; the policy of UP integrity protection of the initiating ProSe UE is REQUIRED, and the policy of UP integrity protection of the receiving ProSe UE is NOT NEEDED; the policy of UP encryption protection of the initiating ProSe UE is REQUIRED, and the policy of UP encryption protection of the receiving ProSe UE is NOT NEEDED; when the second preset condition is met, sending a third rejection message to the initiating ProSe UE, the third rejection message being used for rejecting the Direct Security Mode Complete message sent by the initiating ProSe UE.

12. The method of claim 10, wherein, The method further comprises: receiving the Direct Security Mode Complete message sent by the initiating ProSe UE, the Direct Security Mode Complete message containing the UP security policy of the initiating ProSe UE; and determining whether the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE meet a second preset condition; the second preset condition comprises at least one of the following: the policy of UP integrity protection of the initiating ProSe UE is NOT NEEDED, and the policy of UP integrity protection of the receiving ProSe UE is REQUIRED; the policy of UP encryption protection of the initiating ProSe UE is NOT NEEDED, and the policy of UP encryption protection of the receiving ProSe UE is REQUIRED; the policy of UP integrity protection of the initiating ProSe UE is REQUIRED, and the policy of UP integrity protection of the receiving ProSe UE is NOT NEEDED; the policy of UP encryption protection of the initiating ProSe UE is REQUIRED, and the policy of UP encryption protection of the receiving ProSe UE is NOT NEEDED; when the second preset condition is not met, determining a negotiation result of the UP security policy based on the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE; sending a Direct Communication Accept message to the initiating ProSe UE, the Direct Communication Accept message comprising the negotiation result of the UP security policy.

13. The method of claim 12, wherein, the negotiation result of the UP security policy comprises at least one of the following: a negotiation result of the policy of UP integrity protection; a negotiation result of the policy of UP encryption protection; The method further comprises: determining a negotiation result of the UP security policy based on the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE, comprising: when the policy of the UP integrity protection of the initiating ProSe UE is NOT NEEDED, and / or the policy of the UP integrity protection of the receiving ProSe UE is NOT NEEDED, determining that the negotiation result of the policy of the UP integrity protection is NOT NEEDED; when the policy of the UP integrity protection of the initiating ProSe UE is REQUIRED, and / or the policy of the UP integrity protection of the receiving ProSe UE is REQUIRED, determining that the negotiation result of the policy of the UP integrity protection is REQUIRED; when the policy of the UP integrity protection of the initiating ProSe UE is PREFERRED, and the policy of the UP integrity protection of the receiving ProSe UE is PREFERRED, determining that the negotiation result of the policy of the UP integrity protection is REQUIRED or NOT NEEDED; when the policy of the UP encryption protection of the initiating ProSe UE is NOT NEEDED, and / or the policy of the UP encryption protection of the receiving ProSe UE is NOT NEEDED, determining that the negotiation result of the policy of the UP encryption protection is NOT NEEDED; when the policy of the UP encryption protection of the initiating ProSe UE is REQUIRED, and / or the policy of the UP encryption protection of the receiving ProSe UE is REQUIRED, determining that the negotiation result of the policy of the UP encryption protection is REQUIRED; 14. The method of claim 12, wherein, when the policy of the UP encryption protection of the initiating ProSe UE is PREFERRED, and the policy of the UP encryption protection of the receiving ProSe UE is PREFERRED, determining that the negotiation result of the policy of the UP encryption protection is REQUIRED or NOT NEEDED. The method further comprises:

15. A direct connection communication method characterized by comprising: protecting the direct connection communication with the initiating ProSe UE based on the negotiation result of the signaling security policy and the negotiation result of the UP security policy. The method is applied to an initiating ProSe UE, comprising: obtaining a security policy corresponding to a ProSe service; establishing a direct connection communication security with a receiving ProSe UE based on the security policy; wherein the security policy comprises at least one of the following: a signaling security policy; a user plane (UP) security policy; wherein the signaling security policy comprises: a policy of signaling integrity protection; wherein the UP security policy comprises at least one of the following: a policy of UP integrity protection; a policy of UP encryption protection; wherein the security policy comprises: REQUIRED; NOT NEEDED; PREFERRED; wherein the establishing of the direct connection communication security with the receiving ProSe UE based on the security policy comprises: sending, to the receiving ProSe UE, a Direct Communication Request message, the Direct Communication Request message including a signaling security policy of the initiating ProSe UE; obtaining a Direct Security Mode Command message sent by the receiving ProSe UE, the Direct Security Mode Command including a negotiation result of the signaling security policy; The method further includes: when the negotiation result of the signaling integrity protection policy is NOT NEEDED, changing a UP integrity protection policy of the initiating ProSe UE to NOT NEEDED.

16. The method of claim 15, wherein, The signaling security policy further includes a signaling encryption protection policy.

17. The method of claim 15 or 16, wherein, The obtaining of the security policy corresponding to the ProSe service includes: obtaining a ProSe service to be protected and a security policy corresponding to the ProSe service from a PCF.

18. The method of claim 15 or 16, wherein, The obtaining of the security policy corresponding to the ProSe service includes: obtaining a ProSe service to be protected and a security policy corresponding to the ProSe service from a ProSe application server.

19. The method of claim 15 or 16, wherein, The obtaining of the security policy corresponding to the ProSe service includes: obtaining a ProSe service to be protected and a security policy corresponding to the ProSe service from a UICC.

20. The method of claim 16, wherein, The establishing of the direct communication security based on the security policy and the receiving ProSe UE includes: sending, to the receiving ProSe UE, a Direct Communication Request message, the Direct Communication Request message including a signaling security policy of the initiating ProSe UE; obtaining a first rejection message sent by the receiving ProSe UE, the first rejection message being used to reject the Direct Communication Request message sent by the initiating ProSe UE.

21. The method of claim 15, wherein, The method further includes: judging whether a security algorithm corresponding to a signaling security policy of the receiving ProSe UE is consistent with a security algorithm corresponding to a signaling security policy of the initiating ProSe UE; when the security algorithms are not consistent, sending, to the receiving ProSe UE, a second rejection message, the second rejection message being used to reject the Direct Security Mode Command message sent by the receiving ProSe UE.

22. The method of claim 15, wherein, The negotiation result of the signaling security policy includes at least one of the following: a negotiation result of a signaling integrity protection policy; a negotiation result of a signaling encryption protection policy. The method further includes: when the negotiation result of the signaling integrity protection policy is NOT NEEDED, changing a UP integrity protection policy of the initiating ProSe UE to NOT NEEDED.

23. The method of claim 22, wherein, The method further includes: sending a Direct Security Mode Complete message to the receiving ProSe UE, the Direct Security Mode Complete message containing a UP security policy of the initiating ProSe UE; obtaining a third rejection message sent by the receiving ProSe UE, the third rejection message being used to reject the Direct Security Mode Complete message sent by the initiating ProSe UE.

24. The method of claim 22, wherein, The method further comprises: sending a Direct Security Mode Complete message to the receiving ProSe UE, the Direct Security Mode Complete message containing a UP security policy of the initiating ProSe UE; obtaining a Direct Communication Accept message sent by the receiving ProSe UE, the Direct Communication Accept message including a negotiation result of the UP security policy.

25. The method of claim 24, wherein, The method further comprises: performing direct communication with the receiving ProSe UE based on the negotiation result of the signaling security policy and the negotiation result of the UP security policy.

26. A device for direct communication, characterized in that The apparatus is applied to a receiving ProSe UE and comprises: an obtaining module, configured to obtain a security policy corresponding to a ProSe service; a communication module, configured to establish direct communication security with an initiating ProSe UE based on the security policy. The security policy comprises at least one of the following: a signaling security policy; a user plane (UP) security policy. The signaling security policy comprises: a policy of signaling integrity protection. The UP security policy comprises at least one of the following: a policy of UP integrity protection; a policy of UP encryption protection. The security policy comprises: REQUIRED, NOT NEEDED, and PREFERRED. The establishing of the direct communication security based on the security policy comprises: obtaining a Direct Communication Request message sent by the initiating ProSe UE, the Direct Communication Request message containing a signaling security policy of the initiating ProSe UE; when a first preset condition is not met, determining a negotiation result of the signaling security policy based on the signaling security policy of the initiating ProSe UE and a signaling security policy of the receiving ProSe UE; sending a Direct Security Mode Command message to the initiating ProSe UE, the Direct Security Mode Command message including the negotiation result of the signaling security policy. The first preset condition comprises at least one of the following: The signaling integrity protection policy of the initiating ProSe UE is NOT NEEDED, and the signaling integrity protection policy of the receiving ProSe UE is REQUIRED; The signaling integrity protection policy of the initiating ProSe UE is REQUIRED, and the signaling integrity protection policy of the receiving ProSe UE is NOT NEEDED; The apparatus is further configured to: When the negotiation result of the signaling encryption protection policy is NOT NEEDED, the UP encryption protection policy of the receiving ProSe UE is changed to NOT NEEDED.

27. A device for direct communication, characterized in that The apparatus is applied to an initiating ProSe UE, and comprises: an obtaining module, configured to obtain a security policy corresponding to a ProSe service; a communication module, configured to establish a direct connection communication security with a receiving ProSe UE based on the security policy; The security policy comprises at least one of the following: a signaling security policy; a user plane (UP) security policy; The signaling security policy comprises: a signaling integrity protection policy; The UP security policy comprises at least one of the following: a UP integrity protection policy; a UP encryption protection policy; The security policy comprises: REQUIRED; NOT NEEDED; and PREFERRED; The establishment of the direct connection communication security based on the security policy comprises: sending, to the receiving ProSe UE, a Direct Communication Request message, wherein the Direct Communication Request message comprises a signaling security policy of the initiating ProSe UE; obtaining a Direct Security Mode Command message sent by the receiving ProSe UE, wherein the Direct Security Mode Command comprises a negotiation result of the signaling security policy; The apparatus is further configured to: When the negotiation result of the signaling encryption protection policy is NOT NEEDED, the UP encryption protection policy of the initiating ProSe UE is changed to NOT NEEDED.

28. A user equipment, comprising: comprise: a transceiver; a memory; a processor, connected with the transceiver and the memory respectively, configured to control wireless signal transceiving of the transceiver by executing computer executable instructions on the memory, and capable of implementing the method in any one of claims 1 to 25.

29. A computer storage medium, wherein, The computer storage medium stores computer executable instructions; the computer executable instructions are executed by the processor, and capable of implementing the method in any one of claims 1 to 14 or 15 to 25.