A communication method, apparatus, user equipment, base station, core network device, and storage medium

By aligning the UP security policies across the Uu and PC5 links in 5G ProSe L3 U2N relay communication, the method ensures robust end-to-end security for remote UE communication by activating the PC5 link based on the Uu link's security state, addressing the independent protection issue in existing systems.

CN115885572BActive Publication Date: 2025-07-15BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202180002271.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-07-28
Publication Date
2025-07-15
Estimated Expiration
2041-07-28

AI Technical Summary

Technical Problem

In the communication system, the Uu link protection between the relay UE and the base station and the PC5 link protection between the remote UE and the relay UE are relatively independent, and it is impossible to ensure that the communication protection between the remote UE and the network meets the service security needs.

Method used

By determining the activation state of the UP security policy of the first link between the relay UE and the base station, and activating the UP security of the second link between the relay UE and the remote UE based on the state, ensuring that the security policy of the two links is performed in aligned manner.

Benefits of technology

The end-to-end security of remote UE communication with base stations is improved, the security policy alignment of communication is ensured, and the overall security of communication is enhanced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115885572B_ABST
    Figure CN115885572B_ABST
Patent Text Reader

Abstract

The present disclosure provides a communication method, apparatus, user equipment, base station, and storage medium, belonging to the field of communication technologies. Among them, the method includes: a relay UE can determine the activation state of the UP security policy of the first link between itself and the base station, and activate the UP security of the second link between the relay UE and the remote UE based on the activation state of the UP security policy of the first link. The method provided by the present disclosure ensures the end-to-end security of the communication between the remote UE and the base station, and improves the communication security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of communication technologies, and in particular, to a communication method, apparatus, user equipment, base station, core network equipment, and storage medium. Background Art

[0002] In a communication system, indirect communication between a remote UE and a base station is achieved through L3 U2N (Layer 3 UE (User Equipment) to Network) relay based on 5G Prose (Proximity based Service). Moreover, when the remote UE and the base station perform indirect communication through the L3 U2N relay, it includes two links: the Uu link between the relay UE and the base station and the PC5 link between the remote UE and the relay UE. Among them, in order to ensure the end-to-end security of the communication between the remote UE and the base station, it is usually necessary to ensure that both the Uu link and the PC5 link are protected, and ensure that the security policies of the Uu link and the PC5 link are aligned and executed.

[0003] However, in the related art, the protection of the Uu link between the relay UE and the base station and the protection of the PC5 link between the remote UE and the relay UE are relatively independent, so that the communication protection between the remote UE and the network cannot meet the security requirements of the service. Summary of the Invention

[0004] The communication method, apparatus, user equipment, base station, core network equipment, and storage medium proposed by the present disclosure are used to solve the technical problem that the communication protection in the related art cannot meet the service security.

[0005] The communication method proposed in an embodiment of one aspect of the present disclosure is applied to a relay UE and includes:

[0006] Determine the activation status of the user plane UP security policy of the first link between the relay UE and the base station;

[0007] Activate the UP security of the second link between the relay UE and the remote UE based on the activation status of the UP security policy of the first link.

[0008] The communication method proposed in an embodiment of another aspect of the present disclosure is applied to a remote UE and includes:

[0009] Obtain a second UP security activation instruction sent by the relay UE, where the second UP security activation instruction is used to indicate whether to activate the UP security of the remote UE;

[0010] When the second UP security activation instruction indicates to activate the UP security, activate the UP security of the remote UE based on the second UP security activation instruction.

[0011] The communication method proposed in another aspect of the present disclosure, which is applied to a core network device, includes:

[0012] Obtain a PDU session establishment request sent by a relay UE through a base station;

[0013] Set a UP security policy;

[0014] Send a PDU session request message to the base station, where the PDU session request message includes the UP security policy.

[0015] The communication method proposed in another aspect of the present disclosure, which is applied to a base station, includes:

[0016] Obtain a PDU session establishment request sent by a relay UE, and send the PDU session establishment request to a core network device;

[0017] Receive a PDU session request message sent by the core network device, where the PDU session request message includes a UP security policy;

[0018] Activate the UP security of the first link between the relay UE and the base station based on the UP security policy sent by the core network device.

[0019] The communication device proposed in another aspect of the present disclosure includes:

[0020] A determination module, configured to determine the activation status of the user plane (UP) security policy of the first link between the relay UE and the base station;

[0021] An activation module, configured to activate the UP security of the second link between the relay UE and a remote UE based on the activation status of the UP security policy of the first link.

[0022] The communication device proposed in another aspect of the present disclosure includes:

[0023] An acquisition module, configured to acquire a second UP security activation instruction sent by a relay UE, where the second UP security activation instruction is used to indicate whether to activate the UP security of the remote UE;

[0024] An activation module, configured to activate the UP security of the remote UE based on the second UP security activation instruction when the second UP security activation instruction indicates to activate the UP security.

[0025] The communication device proposed in another aspect of the present disclosure includes:

[0026] An acquisition module, configured to acquire a PDU session establishment request sent by a relay UE through a base station;

[0027] A setting module, configured to set a UP security policy;

[0028] A sending module, configured to send a PDU session request message to the base station, where the PDU session request message includes the UP security policy.

[0029] A communication device according to an embodiment of another aspect of the present disclosure includes:

[0030] An obtaining module, configured to obtain a PDU session establishment request sent by a relay UE and send the PDU session establishment request to a core network device;

[0031] A receiving module, configured to receive a PDU session request message sent by the core network device, where the PDU session request message includes a UP security policy;

[0032] An activation module, configured to activate the UP security of a first link between the relay UE and the base station based on the UP security policy sent by the core network device.

[0033] A user equipment according to an embodiment of another aspect of the present disclosure includes: a transceiver; a memory; and a processor, which are respectively connected to the transceiver and the memory, and are configured to control the wireless signal transceiver of the transceiver by executing computer-executable instructions on the memory, and can implement the method proposed in the above-mentioned embodiment of another aspect.

[0034] A base station according to an embodiment of another aspect of the present disclosure includes: a transceiver; a memory; and a processor, which are respectively connected to the transceiver and the memory, and are configured to control the wireless signal transceiver of the transceiver by executing computer-executable instructions on the memory, and can implement the method proposed in the above-mentioned embodiment of another aspect.

[0035] A core network device according to an embodiment of another aspect of the present disclosure includes: a transceiver; a memory; and a processor, which are respectively connected to the transceiver and the memory, and are configured to control the wireless signal transceiver of the transceiver by executing computer-executable instructions on the memory, and can implement the method proposed in the above-mentioned embodiment of another aspect.

[0036] A computer storage medium according to an embodiment of another aspect of the present disclosure stores computer-executable instructions; after the computer-executable instructions are executed by a processor, the method described above can be implemented.

[0037] In summary, among the communication method, apparatus, user equipment, and storage medium provided in the embodiments of the present disclosure, the relay UE can determine the activation state of the UP security policy of the first link between itself and the base station, and activate the UP security of the second link between the relay UE and the remote UE based on the activation state of the UP security policy of the first link. That is, in the method of the embodiments of the present disclosure, the UP security policy of the second link between the relay UE and the remote UE is determined based on the UP security policy of the first link between the relay UE and the base station. Thus, while ensuring that both the first link and the second link are protected, it is also possible to ensure that the security policies of the first link and the second link are aligned and executed, thereby ensuring the end-to-end security of the communication between the remote UE and the base station and improving the communication security.

[0038] Additional aspects and advantages of the present disclosure will be given in part in the following description, become apparent in part from the following description, or be learned through the practice of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] The above and / or additional aspects and advantages of the present disclosure will become apparent and be readily understood from the following description of the embodiments in conjunction with the accompanying drawings, where:

[0040] Figure 1 is a schematic flowchart of a communication method provided by an embodiment of the present disclosure;

[0041] Figure 2 is a schematic flowchart of a communication method provided by another embodiment of the present disclosure;

[0042] Figure 3 is a schematic flowchart of a communication method provided by still another embodiment of the present disclosure;

[0043] Figure 4 is a schematic flowchart of a communication method provided by yet another embodiment of the present disclosure;

[0044] Figure 5 is a schematic flowchart of a communication method provided by yet another embodiment of the present disclosure;

[0045] Figure 6 is a schematic flowchart of a communication method provided by yet another embodiment of the present disclosure;

[0046] Figure 7 is a schematic flowchart of a communication method provided by yet another embodiment of the present disclosure;

[0047] Figure 8 is a schematic flowchart of a communication method provided by yet another embodiment of the present disclosure;

[0048] Figure 9 is a schematic flowchart of a communication method provided by yet another embodiment of the present disclosure;

[0049] Figure 10 Schematic flowchart of a communication method provided by another embodiment of the present disclosure;

[0050] Figure 11 Schematic flowchart of a communication method provided by another embodiment of the present disclosure;

[0051] Figure 12 Schematic flowchart of a communication method provided by another embodiment of the present disclosure;

[0052] Figure 13 Schematic flowchart of a communication method provided by another embodiment of the present disclosure;

[0053] Figure 14 Schematic flowchart of a communication interaction provided by an embodiment of the present disclosure;

[0054] Figure 15 Schematic structural diagram of a communication device provided by an embodiment of the present disclosure;

[0055] Figure 16 Schematic structural diagram of a communication device provided by another embodiment of the present disclosure;

[0056] Figure 17 Schematic structural diagram of a communication device provided by another embodiment of the present disclosure;

[0057] Figure 18 Schematic structural diagram of a communication device provided by another embodiment of the present disclosure;

[0058] Figure 19 Block diagram of a user equipment provided by an embodiment of the present disclosure;

[0059] Figure 20 Block diagram of a base station provided by an embodiment of the present disclosure. Detailed implementation manners

[0060] Here, exemplary embodiments will be described in detail, and examples thereof are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementation manners described in the following exemplary embodiments do not represent all implementation manners consistent with the embodiments of the present disclosure. On the contrary, they are merely examples of devices and methods consistent with some aspects of the embodiments of the present disclosure as detailed in the appended claims.

[0061] The terms used in the embodiments of the present disclosure are for the purpose of describing specific embodiments only and are not intended to limit the embodiments of the present disclosure. The singular forms "a" and "the" used in the embodiments of the present disclosure and the appended claims are also intended to include the plural forms unless the context clearly dictates otherwise. It should also be understood that the term "and / or" as used herein refers to and encompasses any and all possible combinations of one or more of the associated listed items.

[0062] It should be understood that although the terms first, second, third, etc. may be used in the embodiments of the present disclosure to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from each other. For example, without departing from the scope of the embodiments of the present disclosure, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, the words "if" and "when" as used herein may be interpreted as "when" or "while" or "in response to determining".

[0063] Embodiments of the present disclosure will be described in detail below. Examples of the embodiments are shown in the accompanying drawings, in which the same or similar reference numerals denote the same or similar elements throughout. The embodiments described below with reference to the accompanying drawings are exemplary and are intended to explain the present disclosure and should not be construed as limiting the present disclosure.

[0064] Among the communication method, device, user equipment, and storage medium provided in the embodiments of the present disclosure, the relay UE can determine the activation state of the UP security policy of the first link between itself and the base station, and activate the UP security of the second link between the relay UE and the remote UE based on the activation state of the UP security policy of the first link. That is, in the method of the embodiments of the present disclosure, the UP security policy of the second link between the relay UE and the remote UE is determined based on the UP security policy of the first link between the relay UE and the base station. Thus, while ensuring that both the first link and the second link are protected, it is also possible to ensure that the security policies of the first link and the second link are aligned and executed, thereby ensuring the end-to-end security of the communication between the remote UE and the base station and improving the communication security.

[0065] The communication method, device, user equipment, base station, core network equipment, and storage medium provided by the present disclosure will be described in detail below with reference to the accompanying drawings.

[0066] Figure 1 A schematic flowchart of a communication method provided for the embodiments of the present disclosure, which is applied to a relay UE, as Figure 1 shown, the communication method may include the following steps:

[0067] Step 101: Determine the activation status of the UP (User Plane) security policy for the first link between the relay UE and the base station.

[0068] It should be noted that the indication method in the embodiments of the present disclosure can be applied to any UE. A UE can be a device that provides voice and / or data connectivity to a user. A UE can communicate with one or more core networks via a RAN (Radio Access Network). A UE can be an Internet of Things (IoT) terminal, such as a sensor device, a mobile phone (or "cellular" phone), and a computer with an IoT terminal. For example, it can be a fixed, portable, pocket-sized, handheld, computer-integrated, or vehicle-mounted device. For example, a Station (STA), a subscriber unit, a subscriber station, a mobile station, a mobile, a remote station, an access point, a remote terminal, an access terminal, a user terminal, or a user agent. Alternatively, a UE can also be a device of an unmanned aerial vehicle. Alternatively, a UE can also be a vehicle-mounted device, such as a vehicle computer with wireless communication capabilities or a wireless terminal external to the vehicle computer. Alternatively, a UE can also be a roadside device, such as a street lamp, a traffic signal, or other roadside devices with wireless communication capabilities.

[0069] Among them, in an embodiment of the present disclosure, the communication method in the embodiments of the present disclosure is applied to the 5G ProSe L3 U2N relay scenario.

[0070] In addition, in an embodiment of the present disclosure, the first link can include a Uu link.

[0071] Furthermore, in an embodiment of the present disclosure, the UP security policy can include at least one of the following: a policy for UP integrity protection; a policy for UP encryption protection.

[0072] Based on this, in an embodiment of the present disclosure, the activation status of the UP security policy for the first link between the relay UE and the base station can include at least one of the following: whether the policy for UP integrity protection is activated; whether the policy for UP encryption protection is activated.

[0073] Step 102: Activate the UP security of the second link between the relay UE and the remote UE based on the activation status of the UP security policy for the first link.

[0074] Among them, in an embodiment of the present disclosure, the second link may include a PC5 link.

[0075] In addition, in an embodiment of the present disclosure, the method for activating the UP security of the second link between the relay UE and the remote UE based on the activation status of the UP security policy of the first link may include: making the activation status of the UP security policy of the second link consistent with the activation status of the UP security policy of the first link, and ensuring that the activation status of the UP security policy of the second link is aligned with the activation status of the UP security policy of the first link.

[0076] In summary, in the communication method provided by the embodiment of the present disclosure, the relay UE may determine the activation status of the UP security policy of the first link between itself and the base station, and activate the UP security of the second link between the relay UE and the remote UE based on the activation status of the UP security policy of the first link. That is, in the method of the embodiment of the present disclosure, the UP security policy of the second link between the relay UE and the remote UE is determined based on the UP security policy of the first link between the relay UE and the base station. Thus, while ensuring that both the first link and the second link are protected, it is also possible to ensure that the security policies of the first link and the second link are aligned and executed, thereby ensuring the end-to-end security of the communication between the remote UE and the base station and improving the communication security.

[0077] Figure 2 The flowchart of a communication method provided by another embodiment of the present disclosure is applied to a relay UE, as Figure 2 shown, the communication method may include the following steps:

[0078] Step 201, establish signaling security on the second link.

[0079] Among them, in an embodiment of the present disclosure, the second link may include the PC5 link between the relay UE and the remote UE.

[0080] In addition, in an embodiment of the present disclosure, the method for establishing signaling security on the second link may include the following steps:

[0081] Step a, obtain a Direct Communication Request message sent by the remote UE.

[0082] Step b, send a Relay Key Request message to the core network device based on the Direct Communication Request message, where the Relay Key Request message may include a Relay Service Code.

[0083] Among them, in an embodiment of the present disclosure, the relay UE specifically sends a Relay Key Request message to the 5G PKMF in the core network device.

[0084] In addition, in an embodiment of the present disclosure, after receiving the Relay Key Request message, the 5G PKMF authenticates the remote UE and the relay UE based on the Relay Service Code in the Relay Key Request message, and determines whether to authorize the remote UE and the relay UE based on the authentication result. When authorization is determined, an authorization message is sent to the relay UE.

[0085] In addition, in an embodiment of the present disclosure, after receiving the Relay Key Request message sent by the relay UE, the 5G PKMF also determines the 5G PRUK, and determines the 5G PRUK ID and 5G PRUK_Info corresponding to the 5G PRUK; and determines the 5G_K NRP Freshness Parameter (5G_K NRP refresh parameter), and generates 5G_K NRP based on the 5G PRUK, 5G_K NRP . After that, the 5G PKMF uses 5G_K NRP as the intermediate key parameter, and uses 5G_K NRP Freshness Parameter and 5G PRUK_Info as the intermediate key related parameters, and sends them to the relay UE, so that the relay UE can subsequently establish the signaling security of the second link based on the intermediate key parameter.

[0086] Step c: Obtain the authorization message, intermediate key parameter, and intermediate key related parameters sent by the core network device.

[0087] In an embodiment of the present disclosure, the relay UE specifically obtains the authorization message, intermediate key parameter, and intermediate key related parameters sent by the 5G PKMF in the core network device.

[0088] Among them, in an embodiment of the present disclosure, the interaction between the core network device and the relay UE is implemented through a base station or other devices. For the sake of convenience of description, in the embodiments of the present disclosure, the core network device sending to the UE through a base station or other devices is referred to as the core network device sending to the UE. Similarly, the UE sending to the core network device through a base station or other devices is referred to as the UE sending to the core network device.

[0089] Step d: Determine a session key based on the intermediate key parameters, where the session key is used to protect the signaling security of the second link.

[0090] Step e: Send a Direct Security Mode Command message to the remote UE.

[0091] Among them, the Direct Security Mode Command message is protected by the session key, and the Direct Security Mode Command message may include the above-mentioned intermediate key-related parameters: 5G_K NRP Freshness Parameter and 5GPRUK_Info.

[0092] Exemplarily, in an embodiment of the present disclosure, the relay UE may send 5G_K NRP Freshness and 5GPRUK_Info to the remote UE through the Direct Security Mode Command message, so that the remote UE can determine 5GPRUK based on 5GPRUK_Info, and further determine 5GPRUK_ID, and at the same time combine 5G_K NRP Freshness to generate 5G_K NRP and the session key for protecting the signaling security of the second link.

[0093] Step f: Receive a Direct Security Mode Complete message sent by the remote UE, where the Direct Security Mode Complete message is protected by the session key.

[0094] Then, when step 201 is executed, the signaling security has been successfully established on the second link between the relay UE and the remote UE. Then, when the relay UE and the remote UE interact through the second link subsequently, the interacted signaling will be protected by security, ensuring the security of signaling transmission.

[0095] Step 202: Determine the activation status of the UP security policy of the first link between the relay UE and the base station.

[0096] Step 203: Activate the UP security of the second link between the relay UE and the remote UE based on the activation status of the UP security policy of the first link.

[0097] Among them, for the detailed introduction of steps 202-203, reference can be made to the relevant introduction in the above embodiment, and the embodiments of the present disclosure will not be elaborated here.

[0098] In summary, in the communication method provided by the embodiments of the present disclosure, the relay UE can determine the activation state of the UP security policy of the first link between itself and the base station, and activate the UP security of the second link between the relay UE and the remote UE based on the activation state of the UP security policy of the first link. That is to say, in the method of the embodiments of the present disclosure, the UP security policy of the second link between the relay UE and the remote UE is determined based on the UP security policy of the first link between the relay UE and the base station. Thus, while ensuring that both the first link and the second link are protected, it is also possible to ensure that the security policies of the first link and the second link are aligned and executed, thereby ensuring the end-to-end security of the communication between the remote UE and the base station and improving the communication security.

[0099] Figure 3 The flowchart of a communication method provided by another embodiment of the present disclosure is applied to a relay UE, as Figure 3 shown, the communication method may include the following steps:

[0100] Step 301, establish signaling security on the second link.

[0101] For the detailed introduction of step 301, reference can be made to the relevant introduction in the above embodiments, and the embodiments of the present disclosure will not elaborate here.

[0102] Step 302, determine whether a new PDU session needs to be established between the relay UE and the base station. When a new PDU session does not need to be established, execute step 303.

[0103] It should be noted that, in an embodiment of the present disclosure, during the process of the relay UE establishing a PDU session, the core network device configures the UP security policy of the PDU session for the base station. That is to say, when the relay UE establishes a PDU session, its UP security policy is synchronously activated. Thus, when it is determined in step 302 that a new PDU session does not need to be established between the relay UE and the base station, it means that a PDU session for relay has been established between the relay UE and the base station. In other words, the UP security policy of the first link between the relay UE and the base station has been activated, and then step 303 can be continued.

[0104] Step 303, determine the activation state of the UP security policy of the first interface corresponding to the first link in the relay UE as the activation state of the UP security policy of the first link.

[0105] In an embodiment of the present disclosure, the first interface may include the Uu interface.

[0106] In addition, in an embodiment of the present disclosure, the UP security policy may include at least one of the following:

[0107] The policy of UP integrity protection;

[0108] UP encryption protection policy.

[0109] In one embodiment of the present disclosure, the activation state of the UP security policy may include at least one of the following:

[0110] Whether the UP integrity protection policy is activated;

[0111] Whether the UP encryption protection policy is activated.

[0112] Step 304: Map the UP security policy of the first interface to the second interface corresponding to the second link in the relay UE.

[0113] Among them, in one embodiment of the present disclosure, the second interface may include a PC5-U interface.

[0114] And, in one embodiment of the present disclosure, the method of mapping the UP security activation state of the first interface to the second interface corresponding to the second link in the relay UE may include: The relay UE maps the UP security activation state corresponding to the PDCP (Packet Data Convergence Protocol) layer of its first interface to the PDCP layer of the second interface, so that the activation state of the UP security policy of the second interface of the relay UE is consistent with the activation state of the UP security policy of the first interface.

[0115] Exemplarily, in one embodiment of the present disclosure, if the UP security policy activation state of the first interface of the relay UE is: the UP integrity protection policy is activated, and the UP encryption protection policy is activated; then the relay UE may map the "UP integrity protection policy is activated, and the UP encryption protection policy is activated" of the first interface to the second interface, so that the activation state of the UP security policy of the second interface is also: the UP integrity protection policy is activated, and the UP encryption protection policy is activated.

[0116] Step 305: Determine a second UP security activation instruction based on the activation state of the security policy of the second interface, and the second UP security activation instruction is used to indicate whether to activate the UP security of the remote UE.

[0117] Among them, in one embodiment of the present disclosure, the second UP security activation instruction is specifically determined based on the activation state of the security policy of the second interface of the relay UE to ensure that the activation state of the UP security policy of the remote UE is aligned with the activation state of the UP security policy of the relay UE.

[0118] Specifically, in an embodiment of the present disclosure, when the activation status of the security policy of the second interface of the relay UE is "UP integrity protection policy is activated, UP encryption protection policy is activated", the second UP security activation instruction may be: activate UP integrity protection and activate UP encryption protection.

[0119] Step 306: Send the second UP security activation instruction to the remote UE through a Direct Communication Accept message.

[0120] Among them, in an embodiment of the present disclosure, after the remote UE obtains the second UP security activation instruction sent by the relay UE, it may activate the UP security of the remote UE according to the second UP security activation instruction.

[0121] Up to step 306, the UP security policy in the second link between the relay UE and the remote UE is successfully established. Then, when the relay UE and the remote UE interact subsequently, the data transmission will be protected by the UP security policy, ensuring the security of data transmission.

[0122] In summary, in the communication method provided by the embodiment of the present disclosure, the relay UE can determine the activation status of the UP security policy of the first link between itself and the base station, and activate the UP security of the second link between the relay UE and the remote UE based on the activation status of the UP security policy of the first link. That is, in the method of the embodiment of the present disclosure, the UP security policy of the second link between the relay UE and the remote UE is determined based on the UP security policy of the first link between the relay UE and the base station. Thus, while ensuring that both the first link and the second link are protected, it can also ensure that the security policies of the first link and the second link are aligned and executed, thereby ensuring the end-to-end security of the communication between the remote UE and the base station and improving the communication security.

[0123] Figure 4 It is a schematic flowchart of a communication method provided by another embodiment of the present disclosure, which is applied to a relay UE. As Figure 4 shown, the communication method may include the following steps:

[0124] Step 401: Establish signaling security in the second link.

[0125] Among them, for the detailed introduction of step 401, reference may be made to the relevant introduction in the above embodiment, and the embodiment of the present disclosure will not elaborate here.

[0126] Step 402: Determine whether a new PDU session needs to be established between the relay UE and the base station. When a new PDU session needs to be established, execute step 403.

[0127] Among them, in an embodiment of the present disclosure, when the relay UE determines that a new PDU session needs to be established, it indicates that a PDU session for relay has not been established between the relay UE and the base station. In other words, the core network device has not yet configured the UP security policy for the relay UE and the base station. Therefore, step 403 needs to be continued.

[0128] Step 403: Send a PDU session establishment request to the core network device through the base station.

[0129] Among them, in an embodiment of the present disclosure, after receiving the PDU session establishment request, the core network device sets the UP security policy according to the PDU session establishment request and sends a PDU session establishment response message to the base station. The PDU session establishment response message includes the UP security policy. In addition, after receiving the UP security policy, the base station activates the UP security policy of the base station based on the UP security policy and sends a first UP security activation instruction to the relay UE based on the UP security policy. The first UP security activation instruction is used to indicate whether to activate the UP security of the first interface corresponding to the first link in the relay UE.

[0130] It should be noted that, in an embodiment of the present disclosure, the first UP security activation instruction is specifically determined based on the UP security policy configured by the core network device to ensure that the activation state of the UP security policy of the base station is aligned with the activation state of the UP security policy of the relay UE.

[0131] Exemplarily, in an embodiment of the present disclosure, if the UP security policy configured by the core network device for the Uu interface of the base station is: activate UP integrity protection and activate UP encryption protection. Then the first UP security activation instruction may include: activate UP integrity protection and activate UP encryption protection.

[0132] In addition, in an embodiment of the present disclosure, the method for the base station to send the first UP security activation instruction to the relay UE may include: using the RRC (Radio Resource Control) connection reconfiguration process to send the first UP security activation instruction to the relay UE according to 3GPP TS 33.501[4].

[0133] Step 404: Obtain the first UP security activation instruction sent by the base station.

[0134] Step 405: Activate the UP security of the first interface based on the first UP security activation instruction, and determine the activation state of the UP security policy of the first interface as the activation state of the UP security policy of the first link.

[0135] At this step 405, the UP security policy in the first link between the relay UE and the base station is successfully established. Subsequently, when the relay UE interacts with the base station, data transmission will be protected by the UP security policy, ensuring the security of data transmission.

[0136] Step 406: Map the UP security policy of the first interface to the second interface corresponding to the second link in the relay UE.

[0137] Step 407: Determine a second UP security activation instruction based on the activation status of the security policy of the second interface. The second UP security activation instruction is used to indicate whether to activate the UP security of the remote UE.

[0138] Step 408: Send the second UP security activation instruction to the remote UE through a Direct Communication Accept message.

[0139] At this step 406, the UP security policy in the second link between the relay UE and the remote UE is successfully established. Subsequently, when the relay UE interacts with the remote UE, data transmission will be protected by the UP security policy, ensuring the security of data transmission.

[0140] For the detailed introduction of steps 406 to 408, reference can be made to the relevant introduction in the above embodiments, and the embodiments of the present disclosure will not be elaborated here.

[0141] In summary, in the communication method provided by the embodiments of the present disclosure, the relay UE can determine the activation status of the UP security policy of the first link between itself and the base station, and activate the UP security of the second link between the relay UE and the remote UE based on the activation status of the UP security policy of the first link. That is, in the method of the embodiments of the present disclosure, the UP security policy of the second link between the relay UE and the remote UE is determined based on the UP security policy of the first link between the relay UE and the base station. Thus, while ensuring that both the first link and the second link are protected, it can also ensure that the security policies of the first link and the second link are aligned and executed, thereby ensuring the end-to-end security of the communication between the remote UE and the base station and improving the communication security.

[0142] Figure 5 As shown in the flowchart of a communication method provided by another embodiment of the present disclosure, which is applied to a relay UE, as Figure 5 shown, the communication method may include the following steps:

[0143] Step 501: Establish signaling security in the second link.

[0144] Step 502: Determine the activation status of the UP security policy of the first link between the relay UE and the base station.

[0145] Step 503: Activate the UP security of the second link between the relay UE and the remote UE based on the activation status of the UP security policy of the first link.

[0146] Step 504: Communicate with the base station based on the UP security policy of the first link.

[0147] Step 505: Communicate with the remote UE based on the UP security policy of the second link.

[0148] In summary, in the communication method provided by the embodiments of the present disclosure, the relay UE can determine the activation status of the UP security policy of the first link between itself and the base station, and activate the UP security of the second link between the relay UE and the remote UE based on the activation status of the UP security policy of the first link. That is to say, in the method of the embodiments of the present disclosure, the UP security policy of the second link between the relay UE and the remote UE is determined based on the UP security policy of the first link between the relay UE and the base station. Thus, while ensuring that both the first link and the second link are protected, it can also ensure that the security policies of the first link and the second link are aligned and executed, thereby ensuring the end-to-end security of the communication between the remote UE and the base station and improving the communication security.

[0149] Figure 6 As shown in the flowchart of a communication method provided by another embodiment of the present disclosure, which is applied to a remote UE, Figure 6 The communication method may include the following steps:

[0150] Step 601: Obtain a second UP security activation instruction sent by the relay UE, where the second UP security activation instruction is used to indicate whether to activate the UP security of the remote UE.

[0151] Among them, in an embodiment of the present disclosure, the method for the remote UE to obtain the second UP security activation instruction sent by the relay UE may include: obtaining the second UP security activation instruction sent by the relay UE through a Direct Communication Accept message.

[0152] In addition, for a detailed introduction to the second UP security activation instruction, reference may be made to the relevant introduction in the above embodiments, and the embodiments of the present disclosure will not elaborate herein.

[0153] Step 602: When the second UP security activation instruction indicates to activate the UP security, activate the UP security of the remote UE based on the second UP security activation instruction.

[0154] In summary, among the communication methods provided in the embodiments of the present disclosure, the remote UE can obtain the second UP security activation instruction sent by the relay UE, where the second UP security activation instruction is used to indicate whether to activate the UP security of the remote UE. When the second UP security activation instruction indicates to activate the UP security, the remote UE activates the UP security of the remote UE based on the second UP security activation instruction. That is, in the method of the embodiments of the present disclosure, the UP security policy of the second link between the relay UE and the remote UE is determined based on the UP security policy of the first link between the relay UE and the base station. Thus, while ensuring that both the first link and the second link are protected, it can also ensure that the security policies of the first link and the second link are aligned and executed, thereby ensuring the end-to-end security of the communication between the remote UE and the base station and improving the communication security.

[0155] Figure 7 A schematic flow chart of a communication method provided by another embodiment of the present disclosure, which is applied to a remote UE, as Figure 7 shown, the communication method may include the following steps:

[0156] Step 701, establish signaling security on the second link.

[0157] Among them, in an embodiment of the present disclosure, the method for establishing signaling security on the second link may include the following steps:

[0158] Step a, send a Direct Communication Request message to the relay UE.

[0159] Step b, obtain the Direct Security Mode Command message sent by the relay UE. Among them, the Direct Security Mode Command message is protected by the session key; and, the Direct Security Mode Command message may include intermediate key related parameters: 5G_K NRP Freshness and 5GPRUK_Info.

[0160] Step c, determine the session key based on the intermediate key related parameters.

[0161] Among them, in an embodiment of the present disclosure, the method for the remote UE to determine the session key based on the intermediate key related parameters may include: first determine the intermediate key based on the intermediate key related parameters, and then determine the session key based on the intermediate key.

[0162] Exemplarily, in an embodiment of the present disclosure, the remote UE can obtain 5G_K by obtaining the Direct Security Mode Command message sent by the relay UENRP For the Freshness and 5GPRUK_Info parameters, afterwards, the remote UE can determine the 5GPRUK based on the 5GPRUK_Info, and further determine the 5GPRUK_ID for storage. At the same time, in combination with 5G_K NRP generate 5G_K with Freshness NRP and the session key for protecting the signaling security of the second link.

[0163] Then, when step 701 is completed, the signaling security has been successfully established on the second link between the remote UE and the relay UE. Subsequently, when the remote UE and the relay UE interact through the second link, the signaling exchanged will be protected by security, ensuring the security of signaling transmission.

[0164] Step 702: Obtain the second UP security activation instruction sent by the relay UE, where the second UP security activation instruction is used to indicate whether to activate the UP security of the remote UE.

[0165] Step 703: When the second UP security activation instruction indicates to activate the UP security, activate the UP security of the remote UE based on the second UP security activation instruction.

[0166] For the detailed introduction of steps 702 to 703, reference can be made to the relevant introduction in the above embodiments, and the embodiments of the present disclosure will not be elaborated here.

[0167] In summary, in the communication method provided by the embodiments of the present disclosure, the remote UE can obtain the second UP security activation instruction sent by the relay UE, where the second UP security activation instruction is used to indicate whether to activate the UP security of the remote UE. When the second UP security activation instruction indicates to activate the UP security, the remote UE activates the UP security of the remote UE based on the second UP security activation instruction. That is, in the method of the embodiments of the present disclosure, the UP security policy of the second link between the relay UE and the remote UE is determined based on the UP security policy of the first link between the relay UE and the base station. Thus, while ensuring that both the first link and the second link are protected, it can also ensure that the security policies of the first link and the second link are aligned and executed, thereby ensuring the end-to-end security of the communication between the remote UE and the base station and improving the communication security.

[0168] Figure 8 It is a schematic flowchart of a communication method provided by another embodiment of the present disclosure, which is applied to a remote UE, as Figure 8 shown. The communication method may include the following steps:

[0169] Step 801: Establish signaling security on the second link.

[0170] Step 802: Obtain a second UP security activation instruction sent by the relay UE, where the second UP security activation instruction is used to indicate whether to activate the UP security of the remote UE.

[0171] Step 803: When the second UP security activation instruction indicates to activate the UP security, activate the UP security of the remote UE based on the second UP security activation instruction.

[0172] For the detailed introduction of steps 801 to 803, reference can be made to the relevant introduction in the above embodiments, and the embodiments of the present disclosure will not be elaborated herein.

[0173] Step 804: Communicate with the relay UE based on the UP security policy of the second link.

[0174] In summary, in the communication method provided by the embodiments of the present disclosure, the remote UE can obtain a second UP security activation instruction sent by the relay UE, where the second UP security activation instruction is used to indicate whether to activate the UP security of the remote UE. When the second UP security activation instruction indicates to activate the UP security, the remote UE activates the UP security of the remote UE based on the second UP security activation instruction. That is, in the method of the embodiments of the present disclosure, the UP security policy of the second link between the relay UE and the remote UE is determined based on the UP security policy of the first link between the relay UE and the base station. Thus, while ensuring that both the first link and the second link are protected, it is also possible to ensure that the security policies of the first link and the second link are aligned and executed, thereby ensuring the end-to-end security of the communication between the remote UE and the base station and improving the communication security.

[0175] Figure 9 It is a schematic flowchart of a communication method provided by another embodiment of the present disclosure, which is applied to a core network device, such as Figure 9 As shown, the communication method may include the following steps:

[0176] Step 901: Obtain a PDU session establishment request sent by the relay UE through the base station.

[0177] Step 902: Set the UP security policy.

[0178] Among them, in an embodiment of the present disclosure, the core network device may set the UP security policy for the PDU session used for relaying according to 3GPP TS 33.501 [4] and / or TS 23.502 [5].

[0179] Step 903: Send a PDU session request message to the base station, where the PDU session request message includes the UP security policy.

[0180] In summary, in the communication method provided by the embodiments of the present disclosure, the core network device can obtain a PDU session establishment request sent by the relay UE through the base station, set the UP security policy, and then send a PDU session establishment response message to the base station, where the PDU session establishment response message includes the UP security policy. That is to say, in the method of the embodiments of the present disclosure, the UP security policy of the second link between the relay UE and the remote UE is determined based on the UP security policy of the first link between the relay UE and the base station. Thus, while ensuring that both the first link and the second link are protected, it is also possible to ensure that the security policies of the first link and the second link are aligned and executed, thereby ensuring the end-to-end security of the communication between the remote UE and the base station and improving the communication security.

[0181] Figure 10 It is a schematic flowchart of a communication method provided by another embodiment of the present disclosure, which is applied to a core network device. As Figure 10 shown, the communication method may include the following steps:

[0182] Step 1001: Obtain a Relay Key Request message sent by the relay UE. The Relay Key Request message includes a Relay Service Code.

[0183] Among them, in an embodiment of the present disclosure, specifically, the 5GPKMF in the core network device obtains the Relay Key Request message sent by the relay UE.

[0184] Step 1002: Send an authorization message to the relay UE based on the Relay Service Code.

[0185] Among them, in an embodiment of the present disclosure, after receiving the Relay Key Request message, the 5GPKMF authenticates the remote UE and the relay UE based on the Relay Service Code in the Relay Key Request message, and determines whether to authorize the remote UE and the relay UE based on the authentication result. When it is determined to authorize, an authorization message is sent to the relay UE.

[0186] Step 1003: Send intermediate key parameters and intermediate key-related parameters for determining the session key to the relay UE.

[0187] Among them, in an embodiment of the present disclosure, the intermediate key parameters may include 5G_K NRP and the intermediate key-related parameters may include 5G_K NRP Freshness and 5GPRUK_Info.

[0188] Also, in an embodiment of the present disclosure, after receiving the Relay KeyRequest message sent by the relay UE, 5GPKMF determines 5GPRUK, and determines the 5GPRUK_ID and 5GPRUK_Info corresponding to 5GPRUK; and determines 5G_K NRP Freshness Parameter(5G_K NRP refresh parameter), and generates 5G_K NRP based on 5GPRUK, 5G_K NRP FreshnessParameter, Nonce_1, and Relay Service Code. After that, 5GPKMF determines 5G_K NRP as the intermediate key parameter, and uses 5G_K NRP Freshness Parameter and 5GPRUK_Info as intermediate key-related parameters, and sends them to the relay UE, so that the relay UE and the remote UE can subsequently establish signaling security for the second link based on the intermediate key parameter and the intermediate key-related parameters.

[0189] Step 1004: Obtain the PDU session establishment request sent by the relay UE through the base station.

[0190] Step 1005: Set the UP security policy.

[0191] Step 1006: Send a PDU session request message to the base station, where the PDU session request message includes the UP security policy.

[0192] Among them, for the detailed introduction of steps 1004 to 1006, reference can be made to the relevant introduction in the above embodiments, and the embodiments of the present disclosure will not be elaborated here.

[0193] In summary, in the communication method provided by the embodiments of the present disclosure, the core network device can obtain the PDU session establishment request sent by the relay UE through the base station, set the UP security policy, and then send a PDU session establishment response message to the base station, where the PDU session establishment response message includes the UP security policy. That is, in the method of the embodiments of the present disclosure, the UP security policy for the second link between the relay UE and the remote UE is determined based on the UP security policy of the first link between the relay UE and the base station. Thus, while ensuring that both the first link and the second link are protected, it can also ensure that the security policies of the first link and the second link are aligned and executed, thereby ensuring the end-to-end security of the communication between the remote UE and the base station and improving the communication security.

[0194] Figure 11 It is a schematic flowchart of a communication method provided by another embodiment of the present disclosure, applied to a base station, asFigure 11 As shown, the communication method may include the following steps:

[0195] Step 1101: Obtain a PDU session establishment request sent by a relay UE, and send the PDU session establishment request to a core network device.

[0196] Step 1102: Receive a PDU session request message sent by the core network device, where the PDU session request message includes a UP security policy.

[0197] For a detailed introduction to the UP security policy, reference may be made to the relevant introduction in the foregoing embodiments, and details are not described herein again in the embodiments of the present disclosure.

[0198] Step 1103: Activate the UP security of the first link between the relay UE and the base station based on the UP security policy sent by the core network device.

[0199] For a detailed introduction to the first link, reference may be made to the relevant introduction in the foregoing embodiments, and details are not described herein again in the embodiments of the present disclosure.

[0200] In summary, in the communication method provided in the embodiments of the present disclosure, the base station may obtain a PDU session establishment request sent by the relay UE, and send the PDU session establishment request to the core network device. Then, the base station may receive a PDU session establishment response message sent by the core network device, where the PDU session establishment response message includes a UP security policy, and activate the UP security of the first link between the relay UE and the base station based on the UP security policy sent by the core network device. That is, in the method of the embodiments of the present disclosure, the UP security policy of the second link between the relay UE and the remote UE is determined based on the UP security policy of the first link between the relay UE and the base station. Thus, while ensuring that both the first link and the second link are protected, it is also possible to ensure that the security policies of the first link and the second link are aligned and executed, thereby ensuring the end-to-end security of the communication between the remote UE and the base station and improving the communication security.

[0201] Figure 12 It is a schematic flowchart of a communication method provided by another embodiment of the present disclosure, which is applied to a base station. As Figure 12 shown, the communication method may include the following steps:

[0202] Step 1201: Obtain a PDU session establishment request sent by a relay UE, and send the PDU session establishment request to a core network device.

[0203] Step 1202: Receive a PDU session request message sent by the core network device, where the PDU session request message includes a UP security policy.

[0204] Among them, for the detailed introduction of steps 1201-1202, reference can be made to the relevant introduction in the above embodiments, and the embodiments of the present disclosure will not repeat it here.

[0205] Step 1203: Activate the UP security of the base station based on the UP security policy sent by the core network device.

[0206] Step 1204: Send a first UP security activation instruction to the relay UE based on the UP security policy sent by the core network device, where the first UP security activation instruction is used to indicate whether to activate the UP security of the first interface corresponding to the first link in the relay UE.

[0207] Among them, for the detailed introduction of the first link, reference can be made to the relevant introduction in the above embodiments, and the embodiments of the present disclosure will not repeat it here.

[0208] In summary, in the communication method provided by the embodiments of the present disclosure, the base station can obtain a PDU session establishment request sent by the relay UE, and send the PDU session establishment request to the core network device. Then, the base station can receive a PDU session establishment response message sent by the core network device, where the PDU session establishment response message includes a UP security policy, and activate the UP security of the first link between the relay UE and the base station based on the UP security policy sent by the core network device. That is to say, in the method of the embodiments of the present disclosure, the UP security policy of the second link between the relay UE and the remote UE will be determined based on the UP security policy of the first link between the relay UE and the base station. Thus, while ensuring that both the first link and the second link are protected, it is also possible to ensure that the security policies of the first link and the second link are aligned and executed, thereby ensuring the end-to-end security of the communication between the remote UE and the base station and improving the communication security.

[0209] Figure 13 It is a schematic flowchart of a communication method provided by another embodiment of the present disclosure, which is applied to a base station. As Figure 13 shown, the communication method may include the following steps:

[0210] Step 1301: Obtain a PDU session establishment request sent by the relay UE, and send the PDU session establishment request to the core network device.

[0211] Step 1302: Receive a PDU session request message sent by the core network device, where the PDU session request message includes a UP security policy.

[0212] Step 1303: Activate the UP security of the first link between the relay UE and the base station based on the UP security policy sent by the core network device.

[0213] Among them, for the detailed introduction of steps 1301 to 1303, reference can be made to the relevant introduction in the above embodiments, and the embodiments of the present disclosure will not elaborate herein.

[0214] Step 1304: Communicate with the relay UE based on the UP security policy of the first link.

[0215] In summary, in the communication method provided by the embodiments of the present disclosure, the base station can obtain the PDU session establishment request sent by the relay UE and send the PDU session establishment request to the core network device. Then, the base station can receive the PDU session establishment response message sent by the core network device, where the PDU session establishment response message includes the UP security policy, and activate the UP security of the first link between the relay UE and the base station based on the UP security policy sent by the core network device. That is, in the method of the embodiments of the present disclosure, the UP security policy of the second link between the relay UE and the remote UE is determined based on the UP security policy of the first link between the relay UE and the base station. Thus, while ensuring that both the first link and the second link are protected, it is also possible to ensure that the security strategies of the first link and the second link are aligned and executed, thereby ensuring the end-to-end security of the communication between the remote UE and the base station and improving the communication security.

[0216] Based on the above description, Figure 14 A communication method among a core network device (for example, the core network device can be an AMF (Authentication Management Function), 5GPKMF, and an SMF (Session Management Function)), a base station, a relay UE, and a remote UE provided by an embodiment of the present disclosure is as follows Figure 14 As shown, the interaction method may include the following steps:

[0217] 1401: The remote UE sends a Direct Communication Request message to the relay UE.

[0218] 1402: The relay UE sends a Relay Key Request message to the 5GPKMF based on the Direct Communication Request message, where the Relay Key Request message includes a Relay Service Code.

[0219] Among them, in an embodiment of the present disclosure, the interaction between the core network device and the relay UE is implemented through a base station or other devices. For the convenience of description, in the embodiments of the present disclosure, the core network device sending to the UE through the base station or other devices is referred to as the core network device sending to the UE. Similarly, the UE sending to the core network device through the base station or other devices is referred to as the UE sending to the core network device.

[0220] 1403. The 5G PKMF sends an authorization message, intermediate key parameters for determining the session key, and intermediate key-related parameters to the relay UE.

[0221] 1404. The relay UE determines the session key (not shown in the figure) based on the intermediate key parameters, and sends a Direct Security Mode Command message to the remote UE, where the Direct Security Mode Command message is protected by the session key, and the Direct Security Mode Command message includes intermediate key-related parameters: 5G_K NRP Freshness and 5G PRUK_Info.

[0222] 1405. The remote UE generates intermediate key parameters based on 5G PRUK_Info and determines the session key based on the intermediate key parameters.

[0223] 1406. The remote UE sends a Direct Security Mode Complete message to the relay UE, where the Direct Security Mode Complete message is protected by the session key.

[0224] 1407. The relay UE sends a PDU session establishment request to the AMF through the base station.

[0225] 1408. The AMF sends an Nsmf_PDUSession_CreateSMContext Request message to the SMF.

[0226] 1409. The SMF sets the UP security policy.

[0227] It should be noted that the SMF can set the UP security policy for the PDU session used for relaying according to 3GPP TS 33.501 [4] and / or TS 23.502 [5].

[0228] 1410. The SMF sends an Nsmf_PDUSession_CreateSMContext ReSponse message to the AMF.

[0229] 1411. The AMF sends a PDU session request message to the base station, where the PDU session request message includes an UP security policy.

[0230] 1412. The base station activates the UP security of the Uu link.

[0231] 1413. The base station sends a first UP security activation instruction to the relay UE based on the UP security policy, where the first UP security activation instruction is used to indicate whether to activate the UP security of the first interface corresponding to the first link in the relay UE.

[0232] 1414. The base station sends a PDU session response message to the AMF.

[0233] 1415. The relay UE activates the UP security of the Uu link based on the first UP security activation instruction.

[0234] 1416. The relay UE activates the UP security of the PC5 link based on the activation status of the UP security policy of the Uu link, and determines a second UP security activation instruction based on the activation status of the security policy of the PC5 link, where the second UP security activation instruction is used to indicate whether to activate the UP security of the remote UE.

[0235] 1417. The relay UE sends the second UP security activation instruction to the remote UE through the Direct CommunicationAccept message of the direct communication acceptance.

[0236] 1418. The relay UE sends the ID (Identity Document, serial number) of the remote UE and the information of the remote UE to the SMF.

[0237] 1419. The remote UE activates the UP security of the remote UE based on the second UP security activation instruction.

[0238] In summary, among the interaction methods provided in the embodiments of the present disclosure, the relay UE can determine the activation status of the UP security policy of the first link between itself and the base station, and activate the UP security of the second link between the relay UE and the remote UE based on the activation status of the UP security policy of the first link. That is, in the method of the embodiments of the present disclosure, the UP security policy of the second link between the relay UE and the remote UE is determined based on the UP security policy of the first link between the relay UE and the base station. Thus, while ensuring that both the first link and the second link are protected, it is also possible to ensure that the security policies of the first link and the second link are aligned and executed, thereby ensuring the end-to-end security of the communication between the remote UE and the base station and improving the communication security.

[0239] Figure 15 The structural schematic diagram of a communication device provided by an embodiment of the present disclosure is asFigure 15 As shown, the apparatus 1500 may include:

[0240] A determination module 1501, configured to determine the activation status of the user plane (UP) security policy of the first link between the relay UE and the base station;

[0241] An activation module 1502, configured to activate the UP security of the second link between the relay UE and the remote UE based on the activation status of the UP security policy of the first link.

[0242] In summary, among the communication apparatuses provided in the embodiments of the present disclosure, the relay UE may determine the activation status of the UP security policy of the first link between itself and the base station, and activate the UP security of the second link between the relay UE and the remote UE based on the activation status of the UP security policy of the first link. That is, in the method of the embodiments of the present disclosure, the UP security policy of the second link between the relay UE and the remote UE is determined based on the UP security policy of the first link between the relay UE and the base station. Thus, while ensuring that both the first link and the second link are protected, it is also possible to ensure that the security policies of the first link and the second link are aligned and executed, thereby ensuring the end-to-end security of the communication between the remote UE and the base station and improving the communication security.

[0243] In an embodiment of the present disclosure, the first link includes a Uu link.

[0244] Further, in another embodiment of the present disclosure, the second link includes a PC5 link.

[0245] Further, in another embodiment of the present disclosure, the above-mentioned apparatus is further configured to:

[0246] Establish signaling security on the second link.

[0247] Further, in another embodiment of the present disclosure, the above-mentioned apparatus is further configured to:

[0248] Obtain a Direct Communication Request message sent by the remote UE;

[0249] Send a Relay Key Request message to the core network device based on the Direct Communication Request message, where the Relay Key Request message includes a Relay Service Code;

[0250] Obtain an authorization message, intermediate key parameters, and intermediate key-related parameters sent by the core network device, where the intermediate key parameters include 5G_K NRP and the intermediate key-related parameters include 5G_KNRP Freshness Parameter(5G_K NRP Refresh parameter) and 5GPRUK_Info;

[0251] Determine a session key based on the intermediate key parameter, where the session key is used to protect the signaling security of the second link;

[0252] Send a Direct Security Mode Command message of the direct security mode command to the remote UE; the Direct Security Mode Command is protected by the session key; the Direct Security Mode Command message includes the intermediate key related parameters;

[0253] Receive a Direct Security Mode Complete message sent by the remote UE, where the Direct Security Mode Complete message is protected by the session key.

[0254] Furthermore, in another embodiment of the present disclosure, the above determination module 1501 is further configured to:

[0255] Determine whether a new packet data unit PDU session needs to be established between the relay UE and the base station;

[0256] When it is determined that a new PDU session does not need to be established, determine the activation state of the UP security policy of the first interface corresponding to the first link in the relay UE as the activation state of the UP security policy of the first link.

[0257] Furthermore, in another embodiment of the present disclosure, the above determination module 1501 is further configured to:

[0258] Determine whether a new PDU session needs to be established between the relay UE and the base station;

[0259] When it is determined that a new PDU session needs to be established, send a PDU session establishment request to the core network device through the base station;

[0260] Obtain a first UP security activation instruction sent by the base station, where the first UP security activation instruction is used to indicate whether to activate the UP security of the first interface corresponding to the first link in the relay UE;

[0261] Activate the UP security of the first interface based on the first UP security activation instruction, and determine the activation state of the UP security policy of the first interface as the activation state of the UP security policy of the first link.

[0262] Furthermore, in another embodiment of the present disclosure, the first interface includes the Uu interface.

[0263] Further, in another embodiment of the present disclosure, the activation module 1502 is further configured to:

[0264] Map the UP security policy of the first interface to the second interface corresponding to the second link in the relay UE;

[0265] Determine a second UP security activation instruction based on the activation status of the security policy of the second interface, where the second UP security activation instruction is used to indicate whether to activate the UP security of the remote UE;

[0266] Send the second UP security activation instruction to the remote UE through the Direct Communication Accept message received by direct communication.

[0267] Further, in another embodiment of the present disclosure, the second interface includes a PC5-U interface.

[0268] Further, in another embodiment of the present disclosure, the above device is further configured to:

[0269] Communicate with the base station based on the UP security policy of the first link;

[0270] Communicate with the remote UE based on the UP security policy of the second link.

[0271] Further, in an embodiment of the present disclosure, the UP security policy includes at least one of the following:

[0272] UP integrity protection policy;

[0273] UP encryption protection policy.

[0274] Further, in another embodiment of the present disclosure, the first UP security activation instruction is used to indicate at least one of the following:

[0275] Whether to activate UP integrity protection;

[0276] Whether to activate UP encryption protection.

[0277] Further, in another embodiment of the present disclosure, the second UP security activation instruction is used to indicate at least one of the following:

[0278] Whether to activate UP integrity protection;

[0279] Whether to activate UP encryption protection.

[0280] Figure 16 The structural schematic diagram of a communication device provided by another embodiment of the present disclosure is as Figure 16 shown, and the device 1600 may include:

[0281] An acquisition module 1601, configured to acquire a second UP security activation instruction sent by a relay UE, where the second UP security activation instruction is used to indicate whether to activate the UP security of a remote UE;

[0282] An activation module 1602, configured to, when the second UP security activation instruction indicates to activate the UP security, activate the UP security of the remote UE based on the second UP security activation instruction.

[0283] In summary, among the communication devices provided in the embodiments of the present disclosure, the remote UE can acquire a second UP security activation instruction sent by the relay UE, where the second UP security activation instruction is used to indicate whether to activate the UP security of the remote UE. When the second UP security activation instruction indicates to activate the UP security, the remote UE activates the UP security of the remote UE based on the second UP security activation instruction. That is, in the method of the embodiments of the present disclosure, the UP security policy of the second link between the relay UE and the remote UE is determined based on the UP security policy of the first link between the relay UE and the base station. Thus, while ensuring that both the first link and the second link are protected, it can also ensure that the security policies of the first link and the second link are aligned and executed, thereby ensuring the end-to-end security of the communication between the remote UE and the base station and improving the communication security.

[0284] In an embodiment of the present disclosure, the second link includes a PC5 link.

[0285] Further, in another embodiment of the present disclosure, the above-mentioned device is further configured to:

[0286] Establish signaling security on the second link.

[0287] Further, in another embodiment of the present disclosure, the above-mentioned device is further configured to:

[0288] Send a Direct Communication Request message to the relay UE;

[0289] Acquire a Direct Security Mode Command message sent by the relay UE; the Direct Security Mode Command message is protected by a session key; the Direct Security Mode Command message includes intermediate key-related parameters: 5G_K NRP Freshness Parameter; 5GPRUK_Info;

[0290] Determine a session key based on the intermediate key-related parameters;

[0291] Send a Direct Security Mode Complete message to the relay UE, and the Direct Security Mode Complete message is protected by the session key.

[0292] Further, in another embodiment of the present disclosure, the above-mentioned obtaining module 1601 is further configured to:

[0293] Obtain a second UP security activation instruction sent by the relay UE through the Direct Communication Accept message.

[0294] Further, in another embodiment of the present disclosure, the above-mentioned device is further configured to:

[0295] Communicate with the relay UE based on the UP security policy of the second link.

[0296] Further, in another embodiment of the present disclosure, the UP security policy includes at least one of the following:

[0297] The policy of UP integrity protection;

[0298] The policy of UP encryption protection.

[0299] Further, in another embodiment of the present disclosure, the second UP security activation instruction is used to indicate at least one of the following:

[0300] Whether to activate UP integrity protection;

[0301] Whether to activate UP encryption protection.

[0302] Figure 17 The structural schematic diagram of a communication device provided by another embodiment of the present disclosure is as Figure 17 shown. The device 1700 may include:

[0303] An obtaining module 1701, configured to obtain a PDU session establishment request sent by the relay UE through the base station;

[0304] A setting module 1702, configured to set the UP security policy;

[0305] A sending module 1703, configured to send a PDU session request message to the base station, and the PDU session request message includes the UP security policy.

[0306] In summary, among the communication devices provided in the embodiments of the present disclosure, the core network device can obtain a PDU session establishment request sent by the relay UE through the base station, set the UP security policy, and then send a PDU session establishment response message to the base station, where the PDU session establishment response message includes the UP security policy. That is, in the method of the embodiments of the present disclosure, the UP security policy of the second link between the relay UE and the remote UE is determined based on the UP security policy of the first link between the relay UE and the base station. Thus, while ensuring that both the first link and the second link are protected, it is also possible to ensure that the security policies of the first link and the second link are aligned and executed, thereby ensuring the end-to-end security of the communication between the remote UE and the base station and improving the communication security.

[0307] In one embodiment of the present disclosure, the above device is further configured to:

[0308] Obtain a Relay Key Request message sent by the relay UE, where the Relay Key Request message includes a RelayService Code;

[0309] Send an authorization message to the relay UE based on the Relay Service Code;

[0310] Send an intermediate key parameter and an intermediate key related parameter for determining the session key to the relay UE, where the intermediate key parameter includes 5G_K NRP and the intermediate key related parameter includes 5G_K NRP Freshness and 5GPRUK_Info.

[0311] Furthermore, in another embodiment of the present disclosure, the above device is further configured to:

[0312] Determine 5GPRUK, and determine the 5GPRUK_ID and 5GPRUK_Info corresponding to 5GPRUK;

[0313] Determine 5G_K NRP Freshness Parameter, and generate 5G_K NRP based on 5GPRUK, 5G_K NRP ;

[0314] Send the intermediate key parameter and the intermediate key related parameter to the relay UE.

[0315] Figure 18 The structural schematic diagram of a communication device provided in yet another embodiment of the present disclosure is as Figure 18As shown, the apparatus 1800 may include:

[0316] An obtaining module 1801, configured to obtain a PDU session establishment request sent by a relay UE and send the PDU session establishment request to a core network device;

[0317] A receiving module 1802, configured to receive a PDU session request message sent by the core network device, where the PDU session request message includes a UP security policy;

[0318] An activation module 1803, configured to activate the UP security of a first link between the relay UE and the base station based on the UP security policy sent by the core network device.

[0319] In summary, among the communication apparatuses provided in the embodiments of the present disclosure, the base station may obtain a PDU session establishment request sent by the relay UE and send the PDU session establishment request to the core network device, and then the base station may receive a PDU session establishment response message sent by the core network device, where the PDU session establishment response message includes a UP security policy, and activate the UP security of the first link between the relay UE and the base station based on the UP security policy sent by the core network device. That is, in the method of the embodiments of the present disclosure, the UP security policy of the second link between the relay UE and the remote UE is determined based on the UP security policy of the first link between the relay UE and the base station. Thus, while ensuring that both the first link and the second link are protected, it is also possible to ensure that the security policies of the first link and the second link are aligned and executed, thereby ensuring the end-to-end security of the communication between the remote UE and the base station and improving the communication security.

[0320] In an embodiment of the present disclosure, the first link includes a Uu link.

[0321] Further, in another embodiment of the present disclosure, the activation apparatus 1803 is further configured to:

[0322] Activate the UP security of the base station based on the UP security policy;

[0323] Send a first UP security activation instruction to the relay UE based on the UP security policy, where the first UP security activation instruction is used to indicate whether to activate the UP security of a first interface corresponding to the first link in the relay UE.

[0324] Further, in another embodiment of the present disclosure, the first interface includes a Uu interface.

[0325] Further, in another embodiment of the present disclosure, the above apparatus is further configured to:

[0326] Communicate with the relay UE based on the UP security policy of the first link.

[0327] Further, in another embodiment of the present disclosure, the UP security policy includes at least one of the following:

[0328] The policy of UP integrity protection;

[0329] The policy of UP encryption protection.

[0330] Further, in another embodiment of the present disclosure, the first UP security activation instruction is used to indicate at least one of the following:

[0331] Whether to activate UP integrity protection;

[0332] Whether to activate UP encryption protection.

[0333] The computer storage medium provided by the embodiment of the present disclosure stores an executable program; after the executable program is executed by a processor, it can implement as Figures 1 to 5 or Figures 6 to 8 or Figures 9 to 10 or Figures 11 to 14 any one of the methods shown.

[0334] In order to implement the above embodiments, the present disclosure also proposes a computer program product, including a computer program, and the computer program implements as Figures 1 to 5 or Figures 6 to 8 or Figures 9 to 10 or Figures 11 to 14 any one of the methods shown when executed by a processor.

[0335] In addition, in order to implement the above embodiments, the present disclosure also proposes a computer program, which, when executed by a processor, implements as Figures 1 to 5 or Figures 6 to 8 or Figures 9 to 10 or Figures 11 to 14 any one of the methods shown.

[0336] In order to implement the above embodiments, the present disclosure also provides a core network device, including: a transceiver; a memory; a processor, which are respectively connected to the transceiver and the memory, and are configured to control the wireless signal transceiver of the transceiver by executing computer-executable instructions on the memory, and can implement Figures 9 to 10 the method described above.

[0337] Figure 19 It is a block diagram of a user equipment UE1900 provided by an embodiment of the present disclosure. For example, UE1900 may be a mobile phone, a computer, a digital broadcast terminal device, a messaging device, a game console, a tablet device, a medical device, a fitness device, a personal digital assistant, etc.

[0338] Refer to Figure 19, UE1900 may include at least one of the following components: a processing component 1902, a memory 1904, a power supply component 1906, a multimedia component 1908, an audio component 1910, an input / output (I / O) interface 1912, a sensor component 1913, and a communication component 1916.

[0339] The processing component 1902 generally controls the overall operation of UE1900, such as operations associated with display, telephone calls, data communication, camera operations, and recording operations. The processing component 1902 may include at least one processor 1920 to execute instructions to complete all or part of the steps of the above methods. In addition, the processing component 1902 may include at least one module to facilitate the interaction between the processing component 1902 and other components. For example, the processing component 1902 may include a multimedia module to facilitate the interaction between the multimedia component 1908 and the processing component 1902.

[0340] The memory 1904 is configured to store various types of data to support the operation of UE1900. Examples of such data include instructions for any application or method operating on UE1900, contact data, phone book data, messages, pictures, videos, etc. The memory 1904 may be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, a magnetic disk, or an optical disk.

[0341] The power supply component 1906 provides power to various components of UE1900. The power supply component 1906 may include a power management system, at least one power supply, and other components associated with generating, managing, and distributing power for UE1900.

[0342] The multimedia component 1908 includes a screen that provides an output interface between the UE 1900 and the user. In some embodiments, the screen may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen can be implemented as a touch screen to receive input signals from the user. The touch panel includes at least one touch sensor to sense touches, swipes, and gestures on the touch panel. The touch sensor can sense not only the boundaries of a touch or swipe action, but also detect the wake-up time and pressure associated with the touch or swipe operation. In some embodiments, the multimedia component 1908 includes a front camera and / or a rear camera. When the UE 1900 is in an operating mode, such as a shooting mode or a video mode, the front camera and / or the rear camera can receive external multimedia data. Each of the front camera and the rear camera can be a fixed optical lens system or have a focal length and optical zoom capabilities.

[0343] The audio component 1910 is configured to output and / or input audio signals. For example, the audio component 1910 includes a microphone (MIC) that is configured to receive external audio signals when the UE 1900 is in an operating mode, such as a call mode, a recording mode, and a voice recognition mode. The received audio signals can be further stored in the memory 1904 or transmitted via the communication component 1916. In some embodiments, the audio component 1910 further includes a speaker for outputting audio signals.

[0344] The I / O interface 1912 provides an interface between the processing component 1902 and a peripheral interface module, which can be a keyboard, a click wheel, buttons, etc. These buttons can include, but are not limited to: a home button, a volume button, a power button, and a lock button.

[0345] The sensor component 1913 includes at least one sensor for providing an assessment of the various aspects of the UE 1900. For example, the sensor component 1913 can detect the on / off state of the device 1900, the relative positioning of components, such as the display and the keypad of the UE 1900. The sensor component 1913 can also detect a change in the position of the UE 1900 or a component of the UE 1900, the presence or absence of user contact with the UE 1900, the orientation or acceleration / deceleration of the UE 1900, and the temperature change of the UE 1900. The sensor component 1913 can include a proximity sensor configured to detect the presence of nearby objects without any physical contact. The sensor component 1913 can also include a light sensor, such as a CMOS or a CCD image sensor, for use in imaging applications. In some embodiments, the sensor component 1913 can further include an acceleration sensor, a gyro sensor, a magnetic sensor, a pressure sensor, or a temperature sensor.

[0346] The communication component 1916 is configured to facilitate communication between the UE 1900 and other devices in a wired or wireless manner. The UE 1900 can access a wireless network based on a communication standard, such as WiFi, 2G, or 3G, or a combination thereof. In an exemplary embodiment, the communication component 1916 receives a broadcast signal or broadcast-related information from an external broadcast management system via a broadcast channel. In an exemplary embodiment, the communication component 1916 further includes a Near Field Communication (NFC) module to facilitate short-range communication. For example, the NFC module can be implemented based on Radio Frequency Identification (RFID) technology, Infrared Data Association (IrDA) technology, Ultra Wideband (UWB) technology, Bluetooth (BT) technology, and other technologies.

[0347] In an exemplary embodiment, the UE 1900 can be implemented by at least one Application Specific Integrated Circuit (ASIC), Digital Signal Processor (DSP), Digital Signal Processing Device (DSPD), Programmable Logic Device (PLD), Field Programmable Gate Array (FPGA), controller, microcontroller, microprocessor, or other electronic components for performing the above method.

[0348] Figure 20 It is a block diagram of a base station 2000 provided by an embodiment of the present application. For example, the base station 2000 can be provided as a base station. Referring to Figure 20 , the base station 2000 includes a processing component 2011, which further includes at least one processor, and memory resources represented by a memory 2032 for storing instructions executable by the processing component 2022, such as application programs. The application programs stored in the memory 2032 can include one or more modules each corresponding to a set of instructions. In addition, the processing component 2015 is configured to execute instructions to perform any of the above methods for the foregoing applications in the base station, for example, the method shown in Figure 1 .

[0349] The base station 2000 may further include a power component 2026 configured to perform power management of the base station 2000, a wired or wireless network interface 2050 configured to connect the base station 2000 to a network, and an input / output (I / O) interface 2058. The base station 2000 can operate based on an operating system stored in the memory 2032, such as Windows Server TM, MacOS XTM, Unix TM, Linux TM, Free BSDTM, or the like.

[0350] Other embodiments of the present invention will be readily apparent to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of the invention following the general principles of the invention and including known or customary techniques in the art not disclosed herein. The specification and examples are only to be considered as exemplary, and the true scope and spirit of the disclosure are pointed out by the following claims.

[0351] It should be understood that the present disclosure is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present disclosure is only limited by the appended claims.

Claims

1. A communication method, characterized in that, Applied to a relay user equipment (UE), including: Determine the activation status of the user plane (UP) security policy of the first link between the relay UE and the base station; Obtain the first UP security activation instruction sent by the base station; Determine that the UP security of the first interface has been activated; Determine the second UP security activation instruction; Send the second UP security activation instruction to the remote UE through a Direct Communication Accept message in direct communication; Send the ID of the remote UE and the information of the remote UE to the session management function (SMF); Obtain a Direct Communication Request message sent by the remote UE; Send a RelayKey Request message to the core network device based on the Direct Communication Request message; Obtain the intermediate key parameters and intermediate key related parameters sent by the core network device, wherein the intermediate key parameters include 5G_K NRP The intermediate key related parameters include 5G_K NRP Freshness Parameter(5G_K NRP Refresh parameters) and 5GPRUK_Info; Determine a session key based on the intermediate key parameters, where the session key is used to protect the signaling security of the second link; Send a Direct Security Mode Command message to the remote UE; the Direct Security Mode Command message is protected by the session key; the Direct Security Mode Command message includes the intermediate key related parameters; Receive a Direct Security Mode Complete message sent by the remote UE, where the Direct Security Mode Complete message is protected by the session key.

2. The method according to claim 1, wherein The first link includes a Uu link; the second link includes a PC5 link.

3. The method according to claim 2, wherein The determining the activation status of the UP security policy of the first link between the relay UE and the base station includes: Determine whether a new packet data unit (PDU) session needs to be established between the relay UE and the base station; When it is determined that a new PDU session does not need to be established, determine the activation status of the UP security policy of the first interface corresponding to the first link in the relay UE as the activation status of the UP security policy of the first link.

4. The method according to claim 2, wherein The first UP security activation instruction is used to indicate whether to activate the UP security of the first interface corresponding to the first link in the relay UE; The determining the activation status of the UP security policy of the first link between the relay UE and the base station includes: Determine whether a new PDU session needs to be established between the relay UE and the base station; When it is determined that a new PDU session needs to be established, send a PDU session establishment request to the core network device through the base station; Activate the UP security of the first interface based on the first UP security activation instruction, and determine the activation status of the UP security policy of the first interface as the activation status of the UP security policy of the first link.

5. The method according to claim 3 or 4, characterized in that, The first interface includes a Uu interface.

6. The method according to claim 3 or 4, characterized in that, The determining the second UP security activation instruction includes: Map the UP security policy of the first interface to the second interface corresponding to the second link in the relay UE; Determine a second UP security activation instruction based on the activation status of the security policy of the second interface, where the second UP security activation instruction is used to indicate whether to activate the UP security of the remote UE.

7. The method according to claim 6, characterized in that The second interface includes a PC5-U interface.

8. The method according to claim 6, characterized in that, The method further includes: Communicate with the base station based on the UP security policy of the first link; Communicate with the remote UE based on the UP security policy of the second link.

9. The method according to claim 6, wherein The UP security policy includes at least one of the following: A policy for UP integrity protection; A policy for UP encryption protection.

10. The method according to claim 9, characterized in that, The first UP security activation instruction is used to indicate at least one of the following: Whether to activate UP integrity protection; Whether to activate UP encryption protection.

11. The method according to claim 9, wherein The second UP security activation instruction is used to indicate at least one of the following: Whether to activate UP integrity protection; Whether to activate UP encryption protection.

12. A communication method, characterized in that, Applied to a remote UE, it includes: Obtain a second UP security activation instruction sent by the relay UE through direct communication to accept a message, where the second UP security activation instruction is used to indicate whether to activate the UP security of the remote UE; When the second UP security activation instruction indicates to activate UP security, activate the UP security of the remote UE based on the second UP security activation instruction; A Direct Communication Request message sent to the relay UE; Obtain the Direct Security Mode Command message sent by the relay UE; the Direct Security Mode Command message is protected by a session key; the Direct Security Mode Command message includes intermediate key-related parameters: 5G_K NRP Freshness Parameter; 5GPRUK_Info; Determine the session key based on the intermediate key-related parameters, where the session key is used to protect the signaling security of the second link; Send a Direct Security Mode Complete message to the relay UE, and the Direct Security Mode Complete message is protected by the session key.

13. The method according to claim 12, characterized in that, The second link includes a PC5 link.

14. The method according to claim 12, wherein The method further includes: Communicate with the relay UE based on the UP security policy of the second link.

15. The method according to claim 14, wherein The UP security policy includes at least one of the following: A policy for UP integrity protection; A policy for UP encryption protection.

16. The method according to claim 12, wherein The second UP security activation instruction is used to indicate at least one of the following: Whether to activate UP integrity protection; Whether to activate UP encryption protection.

17. A communication method, characterized in that, Applied to a core network device, it includes: Obtain a PDU session establishment request sent by the relay UE through the base station; Set the UP security policy; Send a PDU session request message to the base station, where the PDU session request message includes the UP security policy; Obtain a Relay Key Request message sent by the relay UE, where the Relay Key Request message includes a Relay Service Code; Send an authorization message to the relay UE based on the Relay Service Code; Send intermediate key parameters and intermediate key-related parameters for determining a session key to the relay UE, where the intermediate key parameters include 5G_K NRP , and the intermediate key-related parameters include 5G_K NRP Freshness and 5GPRUK_Info; Wherein, the sending to the relay UE the intermediate key parameter and the intermediate key-related parameter for determining the session key includes: Determine 5G PRUK, and determine the 5G PRUK ID and 5G PRUK_Info corresponding to the 5G PRUK; Determine 5G_K NRP Freshness Parameter, and generate 5G_K based on 5GPRUK, 5G_K NRP Freshness Parameter, Nonce_1, Relay Service Code NRP ; Send the intermediate key parameter and the intermediate key related parameter to the relay UE; Receive the ID of the remote UE and the information of the remote UE sent by the relay UE.

18. A communication method, characterized in that, Applied to the base station, including: Obtain the PDU session establishment request sent by the relay UE, and send the PDU session establishment request to the core network device; Receive the PDU session request message sent by the core network device, and the PDU session request message includes the UP security policy; Send a first UP security activation instruction to the relay UE; Wherein, the first UP security activation instruction is used for the relay UE to determine that the UP security of the first interface has been activated, and determine the second UP security activation instruction, and send the second UP security activation instruction to the remote UE through the direct communication accept message of the direct communication; Wherein, the relay UE also sends the ID of the remote UE and the information of the remote UE to the session management function SMF; Among them, the relay UE also obtains the Direct Communication Request message sent by the remote UE; sends a Relay Key Request message to the core network device based on the Direct Communication Request message; obtains the intermediate key parameter and the intermediate key related parameter sent by the core network device, where the intermediate key parameter includes 5G_K NRP , and the intermediate key related parameter includes 5G_K NRP FreshnessParameter(5G_K NRP refresh parameter) and 5GPRUK_Info; determines a session key based on the intermediate key parameter, where the session key is used to protect the signaling security of the second link; sends a Direct Security Mode Command message to the remote UE; the Direct Security Mode Command message is protected by the session key; the Direct Security Mode Command message includes the intermediate key related parameter; receives the Direct Security Mode Complete message sent by the remote UE, and the Direct Security Mode Complete message is protected by the session key.

19. The method according to claim 18, wherein The first link between the relay UE and the base station includes the Uu link.

20. The method according to claim 19, characterized in that, The sending the first UP security activation instruction to the relay UE includes: Activate the UP security of the base station based on the UP security policy; Send a first UP security activation instruction to the relay UE based on the UP security policy, and the first UP security activation instruction is used to indicate whether to activate the UP security of the first interface corresponding to the first link in the relay UE.

21. The method according to claim 20, characterized in that, The first interface includes the Uu interface.

22. The method according to claim 19, wherein The method further includes: Communicate with the relay UE based on the UP security policy of the first link.

23. The method according to claim 18, wherein The UP security policy includes at least one of the following: The policy of UP integrity protection; The policy of UP encryption protection.

24. The method according to claim 18, wherein The first UP security activation instruction is used to indicate at least one of the following: Whether to activate UP integrity protection; Whether to activate UP encryption protection.

25. A communication device, characterized in that, Including: A determination module, configured to determine the activation state of the user plane UP security policy of the first link between the relay UE and the base station; The communication device is further configured to: Obtain the first UP security activation instruction sent by the base station; Determine that the UP security of the first interface has been activated; Determine the second UP security activation instruction; Send the second UP security activation instruction to the remote UE through the direct communication accept message of the direct communication; Send the ID of the remote UE and the information of the remote UE to the session management function SMF; The communication device is further configured to: Obtain the direct communication request message sent by the remote UE; Send a relay key request message to the core network device based on the direct communication request message; Obtain the intermediate key parameter and the intermediate key related parameter sent by the core network device, where the intermediate key parameter includes 5G_K NRP , and the intermediate key related parameter includes 5G_K NRP Freshness Parameter(5G_K NRP refresh parameter) and 5GPRUK_Info; Determine a session key based on the intermediate key parameter, and the session key is used to protect the signaling security of the second link; Send a Direct Security Mode Command message to the remote UE; The Direct Security Mode Command message is protected by the session key; the Direct Security Mode Command message includes the intermediate key related parameters; Receive a Direct Security Mode Complete message sent by the remote UE, and the Direct Security Mode Complete message is protected by the session key.

26. A communication device, characterized in that, Comprising: An obtaining module, configured to obtain a second UP security activation instruction sent by the relay UE through a direct communication acceptance message, where the second UP security activation instruction is used to indicate whether to activate the UP security of the remote UE; An activation module, configured to activate the UP security of the remote UE based on the second UP security activation instruction when the second UP security activation instruction indicates to activate the UP security; The communication device is further configured to: Send a Direct Communication Request message to the relay UE; Obtain the Direct Security Mode Command message sent by the relay UE; the Direct Security Mode Command message is protected by a session key; the Direct Security Mode Command message includes intermediate key-related parameters: 5G_K NRP Freshness Parameter; 5GPRUK_Info; Determine the session key based on the intermediate key related parameters, where the session key is used to protect the signaling security of the second link; Send a Direct Security Mode Complete message to the relay UE, and the Direct Security Mode Complete message is protected by the session key.

27. A communication device, characterized in that, Comprising: An obtaining module, configured to obtain a PDU session establishment request sent by the relay UE through a base station; A setting module, configured to set a UP security policy; A sending module, configured to send a PDU session request message to the base station, where the PDU session request message includes the UP security policy; The communication device is further configured to: Obtain a Relay Key Request message sent by the relay UE, where the Relay Key Request message includes a Relay Service Code; Send an authorization message to the relay UE based on the Relay Service Code; Send an intermediate key parameter and an intermediate key related parameter for determining a session key to the relay UE, where the intermediate key parameter includes 5G_K NRP , and the intermediate key related parameter includes 5G_K NRP Freshness and 5GPRUK_Info; Wherein, sending the intermediate key parameter and the intermediate key related parameter for determining the session key to the relay UE includes: Determine 5G PRUK, and determine the 5G PRUK ID and 5G PRUK_Info corresponding to the 5G PRUK; Determine 5G_K NRP Freshness Parameter, and generate 5G_K based on 5GPRUK, 5G_K NRP Freshness Parameter, Nonce_1, Relay Service Code NRP ; Send the intermediate key parameter and the intermediate key related parameter to the relay UE; The communication device is further configured to: Receive the ID of the remote UE and the information of the remote UE sent by the relay UE.

28. A communication device, characterized in that, Comprising: An obtaining module, configured to obtain a PDU session establishment request sent by the relay UE and send the PDU session establishment request to a core network device; A receiving module, configured to receive a PDU session request message sent by the core network device, where the PDU session request message includes a UP security policy; An activation module, configured to activate the UP security of the first link between the relay UE and the base station based on the UP security policy sent by the core network device; A sending module, configured to send a first UP security activation instruction to the relay UE; Wherein, the first UP security activation instruction is used for the relay UE to determine that the UP security of the first interface has been activated, and determine a second UP security activation instruction, and send the second UP security activation instruction to the remote UE through a DirectCommunication Accept message of direct communication; Wherein, the relay UE also sends the ID of the remote UE and the information of the remote UE to the Session Management Function (SMF); Among them, the relay UE also obtains the Direct CommunicationRequest message sent by the remote UE; sends a Relay Key Request message to the core network device based on the Direct Communication Request message; obtains the intermediate key parameter and the intermediate key-related parameter sent by the core network device, where the intermediate key parameter includes 5G_K NRP , and the intermediate key-related parameter includes 5G_K NRP FreshnessParameter(5G_K NRP refresh parameter) and 5GPRUK_Info; determines a session key based on the intermediate key parameter, where the session key is used to protect the signaling security of the second link; sends a Direct Security Mode Command message to the remote UE; the Direct Security Mode Command message is protected by the session key; the Direct Security Mode Command message includes the intermediate key-related parameter; receives a Direct Security Mode Complete message sent by the remote UE, and the Direct Security Mode Complete message is protected by the session key.

29. A user equipment, characterized in that, Comprising: A transceiver; A memory; A processor, respectively connected to the transceiver and the memory, configured to control the wireless signal transceiver of the transceiver by executing computer-executable instructions on the memory, and be capable of implementing the method according to any one of claims 1 to 11 or 12 to 16.

30. A core network device, wherein, Comprising: A transceiver; A memory; A processor, respectively connected to the transceiver and the memory, configured to control the wireless signal transceiver of the transceiver by executing computer-executable instructions on the memory, and be capable of implementing the method according to claim 17.

31. A base station, characterized in that, Comprising: A transceiver; A memory; A processor, respectively connected to the transceiver and the memory, configured to control the wireless signal transceiver of the transceiver by executing computer-executable instructions on the memory, and be capable of implementing the method according to any one of claims 18 to 24.

32. A computer storage medium, wherein, The computer storage medium stores computer-executable instructions; after being executed by the processor, the computer-executable instructions are capable of implementing the method according to any one of claims 1 to 11 or 12 to 16 or 17 or 18 to 24.

Citation Information

Patent Citations

  • Safety protection mode determining method and device

    CN112351431A

  • Method and apparatus for determining security protection mode

    WO2021027435A1