A secure communication method, device and system
By cooperating with the security policies of the relay and the first terminal device in the device-to-device communication, the second terminal device coordinates to ensure that the user-plane security protection methods of the two links at the relay are consistent, the problem of inconsistent link security protection is solved, and communication security is improved.
Patent Information
- Application Number
- CN202080105677.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-10-01
- Publication Date
- 2025-08-08
- Estimated Expiration
- 2040-10-01
AI Technical Summary
In device-to-device communication, especially when the terminal device is outside the coverage range of the communication network or the communication quality is poor, how to realize the security protection coordinated processing of the links at both ends of the relay for user plane data, and avoid the problem of inconsistent link security protection methods in the case of segmentation.
The second terminal device receives and processes security policy information from the relay and the first terminal device, determines and sends the user plane security protection method indicating the relay and the second PC5 link, so that it is consistent with the user plane security protection method of the first PC5 link, and ensures consistency of the link security protection without segmentation when the secure activation is not secured.
The consistency of the user-plane security protection method of the two-end links is achieved, reducing the probability of errors caused by inconsistent security activation, and improving communication security.
Smart Images

Figure CN116325845B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology, and in particular to a secure communication method, device, and system. Background Art
[0002] Currently, device-to-device (D2D) communication allows user equipment (UE) to communicate directly with each other.
[0003] When a terminal device (such as a remote UE) is outside the coverage of the communication network, or when the communication quality with the access network device in the communication network is poor, it can establish indirect communication with the communication network through a relay (such as a relay UE) based on D2D communication. The relay can establish a protocol data unit (PDU) session for transmitting the remote device, transmit the data received from the remote UE to the data network through the PDU session, or send the data obtained from the data network through the PDU session to the remote UE.
[0004] In this scenario where terminal devices communicate through relays, how to achieve coordinated processing of security protection for user-plane data on the links at both ends of the relay is a problem that needs to be solved. Summary of the Invention
[0005] The present application provides a secure communication method, device and system for realizing collaborative processing of security protection of user plane data on links at both ends of a relay.
[0006] In a first aspect, a first secure communication method is provided. The method can be performed by a communication device. The communication device can be a second terminal device or a communication device that can support the second terminal device to implement the functions required by the method. Of course, it can also be other communication devices, such as a chip system. In the first aspect, the communication device is taken as an example of a second terminal device. The method includes:
[0007] The second terminal device receives a first request message about the first terminal device from the relay; the first request message includes the PC5 user plane security policy of the first terminal device and the PC5 user plane security policy of the relay; determines first information according to the PC5 user plane security policy of the second terminal device, the PC5 user plane security policy of the first terminal device, and the PC5 user plane security policy of the relay; sends the first information to the relay, the first information being used to indicate a user plane security protection method of the first PC5 link and a user plane security protection method of the second PC5 link; wherein the user plane security protection method of the first PC5 link is the same as the user plane security protection method of the second PC5 link;
[0008] The first PC5 link is a PC5 link between the relay and the first terminal device; the second PC5 link is a PC5 link between the relay and the second terminal device.
[0009] By executing the method provided in the embodiments of the present application, collaborative processing of user plane security protection can be achieved among various devices. For example, each device can either activate the integrity protection method of user plane data or not activate the integrity protection method of user plane data, so that each device maintains consistency in the processing method.
[0010] In one possible implementation, the first information is used to indicate the user plane security protection method of the second PC5 link. Because the embodiment of the present application is to avoid inconsistent user plane security protection methods of two links when security activation occurs in segments, the first information is used to indicate the user plane security protection method of the second PC5 link. It can also be understood that the first information is used to indicate the user plane security protection method of the first PC5 link and the user plane security protection method of the second PC5 link, including:
[0011] The first information is used to indicate: the user plane integrity protection of the first PC5 link and / or the user plane integrity protection of the second PC5 link are both enabled or not enabled, and / or the user plane confidentiality protection of the first PC5 link and / or the user plane confidentiality protection of the second PC5 link are both enabled or not enabled.
[0012] In the embodiment of the present application, it can be ensured that the user plane security protection method of the first PC5 link is the same as the user plane security protection method of the second PC5 link.
[0013] In one possible implementation, the method further includes:
[0014] receiving a second request message about the first terminal device from the relay, where the second request message includes the PC5 control plane security policy of the first terminal device and the PC5 control plane security policy of the relay;
[0015] Determining a control plane security algorithm for the second PC5 link according to the PC5 control plane security policy of the second terminal device, the PC5 control plane security policy of the first terminal device, and the PC5 control plane security policy of the relay;
[0016] The second terminal device sends a control plane security algorithm of the second PC5 link to the relay, where the control plane security algorithm is used to indicate a control plane security protection method of the second PC5 link and a control plane security protection method of the first PC5 link, wherein the control plane security protection method of the first PC5 link is the same as the control plane security protection method activated on the second PC5 link.
[0017] In the embodiment of the present application, since the control plane security protection method of the first PC5 link is the same as the control plane security protection method of the second PC5 link, it is possible to avoid inconsistency in the control plane security of the two links when security activation occurs in segments (such as when the security endpoint policy of UE-1 adopts hop-to-hop security).
[0018] It should be noted that, when security activation does not occur in segments, the control plane security protection methods of the two links may be inconsistent.
[0019] In a possible implementation, the second request message further includes an indication of a security endpoint policy, where the indication of the security endpoint policy is used to indicate that the security endpoint is located on the relay.
[0020] In the embodiment of the present application, it can be ensured that when security activation occurs in segments, the user plane security protection method of the first PC5 link and the user plane security protection method of the second PC5 link are the same.
[0021] In a possible implementation, the control plane security algorithm is used to indicate the control plane security protection method of the second PC5 link and the control plane security protection method of the first PC5 link, including:
[0022] The control plane security algorithm is used to indicate: whether the control plane integrity protection of the first PC5 link and the control plane integrity protection of the second PC5 link are both enabled or not enabled, and / or whether the control plane confidentiality protection of the first PC5 link and the control plane confidentiality protection of the second PC5 link are both enabled or not enabled.
[0023] In the embodiment of the present application, it can be ensured that the control plane security protection method of the first PC5 link is the same as the control plane security protection method activated on the second PC5 link, thereby improving the security of the link.
[0024] In one possible implementation, determining the first information according to the PC5 user plane security policy of the second terminal device, the PC5 user plane security policy of the first terminal device, and the PC5 user plane security policy of the relay includes:
[0025] Determining the first information according to the PC5 user plane security policy of the second terminal device, the PC5 user plane security policy of the first terminal device, the PC5 user plane security policy of the relay, and the control plane security algorithm of the second PC5 link;
[0026] The security level of the user plane security of the second PC5 link is not higher than the security level of the control plane security of the second PC5 link, and the security level of the user plane security of the first PC5 link is not higher than the security level of the control plane security of the first PC5 link.
[0027] In the embodiment of the present application, the current requirement that the security level of the user plane security is not higher than the security level of the control plane security can be met.
[0028] In a possible implementation, the user plane security of the second PC5 link is not higher than the control plane security of the second PC5 link, and the user plane security of the first PC5 link is not higher than the control plane security of the first PC5 link, including:
[0029] When the control plane confidentiality protection of the third PC5 link is enabled, the user plane confidentiality protection of the third PC5 link is enabled or disabled;
[0030] When the control plane confidentiality protection of the third PC5 link is not enabled, the user plane confidentiality protection of the third PC5 link is not enabled;
[0031] When the control plane integrity protection of the third PC5 link is enabled, the user plane integrity protection of the third PC5 link is enabled or disabled;
[0032] When the control plane integrity protection of the third PC5 link is not enabled, the user plane integrity protection of the third PC5 link is not enabled;
[0033] The third PC5 link is the second PC5 link or the first PC5 link.
[0034] In the embodiment of the present application, the current requirement that the security level of the user plane security is not higher than the security level of the control plane security can be met.
[0035] In a second aspect, a first secure communication method is provided. The method can be performed by a communication device. The communication device can be a second terminal device or a communication device that can support the second terminal device to implement the functions required by the method. Of course, it can also be other communication devices, such as a chip system. In the first aspect, taking the communication device as the second terminal device as an example, the method includes:
[0036] The second terminal device receives a direct communication request from the first terminal device through at least one relay; the direct communication request includes an indication of a secure endpoint policy, and the indication of the secure endpoint policy is used to indicate that the secure endpoint is located on the relay;
[0037] The second terminal device receives the PC5 control plane security protection method of the first PC5 link and the PC5 control plane security protection method of the second PC5 link determined from the at least one relay;
[0038] The second terminal device determines the target relay according to the PC5 control plane security policy of the second terminal device and the PC5 control plane security protection method of the first PC5 link determined by the at least one relay;
[0039] The second terminal device receives the PC5 user plane security protection method of the first PC5 link determined by the target relay;
[0040] The second terminal device determines the first information according to the PC5 user plane security protection method of the first PC5 link from the target relay and the PC user plane security policy of the second terminal device;
[0041] The second terminal device sends the first information to the relay, where the first information is used to indicate a user plane security protection method of the first PC5 link and a user plane security protection method of the second PC5 link; wherein the user plane security protection method of the first PC5 link and the user plane security protection method of the second PC5 link are the same;
[0042] The first PC5 link is a PC5 link between the relay and the first terminal device; the second PC5 link is a PC5 link between the relay and the second terminal device.
[0043] In an embodiment of the present application, the relay can determine whether to activate the second PC5 link and the user plane security protection method of the second PC5 link, so that by executing the method provided in the embodiment of the present application, collaborative processing of the integrity protection of the user plane data can be achieved between the devices. For example, each device can either activate the user plane security protection method or not activate the integrity protection method of the user plane data, so that each device can maintain consistency in the processing method and reduce the probability of error.
[0044] In a possible implementation, the first information is used to indicate a user plane security protection method of the first PC5 link and a user plane security protection method of the second PC5 link, including:
[0045] The first information is used to indicate: whether the user plane integrity protection of the first PC5 link and the user plane integrity protection of the second PC5 link are both enabled or not enabled, and / or whether the user plane confidentiality protection of the first PC5 link and the user plane confidentiality protection of the second PC5 link are both enabled or not enabled.
[0046] In one possible implementation, the second terminal device determines a control plane security algorithm for the second PC5 link according to the PC5 user plane security protection method of the first PC5 link determined by the target relay;
[0047] The second terminal device sends a control plane security algorithm of a second PC5 link to the relay, where the control plane security algorithm of the second PC5 link is used to indicate a control plane security protection method of the second PC5 link and a control plane security protection method of the first PC5 link.
[0048] In an embodiment of the present application, the relay can determine whether to activate the second PC5 link and the control plane security protection method of the second PC5 link, so that by executing the method provided in the embodiment of the present application, collaborative processing of control plane data security protection can be achieved among various devices. For example, each device can either activate the integrity protection method of the user plane data or not activate the integrity protection method of the user plane data, so that each device can maintain consistency in the processing method and reduce the probability of error.
[0049] In a possible implementation, the control plane security algorithm of the second PC5 link is used to indicate a control plane security protection method of the second PC5 link and a control plane security protection method of the first PC5 link, including:
[0050] The control plane security algorithm of the second PC5 link is used to indicate: whether the control plane integrity protection of the first PC5 link and the control plane integrity protection of the second PC5 link are both enabled or not enabled, and / or whether the control plane confidentiality protection of the first PC5 link and the control plane confidentiality protection of the second PC5 link are both enabled or not enabled.
[0051] In a possible implementation, the second terminal device determines the first information according to the PC5 user plane security protection method of the first PC5 link from the target relay and the PC user plane security policy of the second terminal device, including:
[0052] The second terminal device determines the first information according to the PC5 user plane security policy of the first PC5 link from the target relay, the PC user plane security policy of the second terminal device, and the control plane security algorithm of the second PC5 link;
[0053] Among them, the security level of the user plane security protection method of the second PC5 link is not higher than the security level of the control plane security protection method of the second PC5 link, and the security level of the user plane security protection method of the first PC5 link is not higher than the security level of the control plane security protection method of the first PC5 link.
[0054] In a possible implementation, the user plane security protection method of the second PC5 link is not higher than the control plane security protection method of the second PC5 link, and the user plane security protection method of the first PC5 link is not higher than the control plane security protection method of the first PC5 link, including:
[0055] When the control plane confidentiality protection of the third PC5 link is enabled, the user plane confidentiality protection of the third PC5 link is enabled or disabled;
[0056] When the control plane confidentiality protection of the third PC5 link is not enabled, the user plane confidentiality protection of the third PC5 link is not enabled;
[0057] When the control plane integrity protection of the third PC5 link is enabled, the user plane integrity protection of the third PC5 link is enabled or disabled;
[0058] When the control plane integrity protection of the third PC5 link is not enabled, the user plane integrity protection of the third PC5 link is not enabled;
[0059] The third PC5 link is the second PC5 link or the first PC5 link.
[0060] Some of the beneficial effects achieved in this aspect can be found in the first aspect and will not be repeated here.
[0061] In a third aspect, a first secure communication method is provided. The method can be performed by a communication device. The communication device can be a second terminal device or a communication device that can support the second terminal device to implement the functions required by the method. Of course, it can also be other communication devices, such as a chip system. In the first aspect, the communication device is taken as an example of a second terminal device. The method includes:
[0062] The second terminal device receives a direct communication request from the first terminal device through at least one relay;
[0063] The second terminal device determines a target relay from the at least one relay according to the security policy auxiliary information;
[0064] The second terminal device communicates with the first terminal device through the target relay;
[0065] In the embodiment of the present application, according to this method, a relay that can ensure the establishment of a PC5 link can be selected from multiple relays, so as to successfully establish a PC5 connection.
[0066] In a possible implementation, the second terminal device determines the target relay from the at least one relay according to the security policy auxiliary information, including:
[0067] The second terminal device selects a target relay including an optional PC5 control plane security policy from the at least one relay.
[0068] In the embodiment of the present application, since the control plane security policy of the target relay includes the optional PC5 control plane security policy, it can support the establishment of a PC5 connection.
[0069] In a possible implementation, the security policy auxiliary information includes a PC control plane security policy of the at least one relay and a PC5 control plane security policy of the second terminal device;
[0070] The second terminal device determines a target relay from the at least one relay according to the security policy auxiliary information, including:
[0071] A target relay is selected from the at least one relay, wherein the PC control plane security policy of the relay does not conflict with the PC5 control plane security policy of the second terminal device.
[0072] In the embodiment of the present application, since the control plane security policy of the target relay does not conflict with the PC5 control plane security policy of the second terminal device, it is possible to support the establishment of a PC5 connection.
[0073] In a possible implementation, the security policy auxiliary information includes a PC control plane security policy of the at least one relay and a PC5 control plane security policy of the second terminal device;
[0074] The second terminal device determines a target relay from the at least one relay according to the security policy auxiliary information, including:
[0075] The second terminal device selects a target relay from the at least one relay based on the security policy auxiliary information, wherein the security level of the PC user plane security protection method of the relay is not higher than the security level of the PC control plane security protection method of the second terminal device.
[0076] In the embodiment of the present application, the security level of the target relay PC control plane security protection method is lower than the security level of the relay PC user plane security protection method.
[0077] In a possible implementation, the security policy auxiliary information is pre-configured by a policy control function network element. The policy control function network element may preferentially configure a security policy in an optional state for the target relay.
[0078] In a fourth aspect, a first secure communication method is provided. The method can be performed by a communication device. The communication device can be a relay or a communication device that can support a relay to implement the functions required by the method. Of course, it can also be other communication devices, such as a chip system. In the first aspect, the communication device is taken as an example of a relay. The method includes:
[0079] The relay sends a first request message about the first terminal device to the second terminal device; the first request message includes the PC5 user plane security policy of the first terminal device and the PC5 user plane security policy of the relay;
[0080] The relay receives first information from the second terminal device, where the first information is used to indicate a user plane security protection method of the first PC5 link and a user plane security protection method of the second PC5 link; wherein the user plane security protection method of the first PC5 link is the same as the user plane security protection method of the second PC5 link;
[0081] The relay activates the user plane security protection method of the second PC5 link and the user plane security protection method of the first PC5 link according to the first information;
[0082] The first PC5 link is a PC5 link between the relay and the first terminal device, and the second PC5 link is a PC5 link between the relay and the second terminal device.
[0083] In the embodiment of the present application, because the user plane security protection method of the first PC5 link is the same as the user plane security protection method of the second PC5 link, it is possible to avoid inconsistencies in the user plane security of the two links when security activation occurs in segments (such as when the security endpoint policy of UE-1 adopts hop-to-hop security). By executing the method provided in the embodiment of the present application, collaborative processing of user plane security protection can be achieved between various devices. For example, each device can either activate the integrity protection method of the user plane data or not activate the integrity protection method of the user plane data, thereby maintaining consistency in the processing methods of each device and reducing the probability of errors.
[0084] In one possible design, the method further includes:
[0085] The relay sends the control plane security policy of the first terminal device and the control plane security policy of the relay to the second terminal device, where the control plane security policy of the first terminal device and the control plane security policy of the relay are used to determine the control plane security algorithm of the second PC5 link;
[0086] The relay receives a control plane security algorithm of the second PC5 link from the second terminal device, where the control plane security algorithm is used to indicate control plane security of the second PC5 link and control plane security of the first PC5 link;
[0087] The relay activates the control plane security of the second PC5 link and the control plane security of the first PC5 link according to the control plane security algorithm of the second PC5 link, wherein the control plane security of the first PC5 link is the same as the control plane security activated on the second PC5 link.
[0088] In an embodiment of the present application, by executing the method provided in the embodiment of the present application, collaborative processing of control plane security protection can be achieved among various devices. For example, each device can either activate the integrity protection method of the control plane data or not activate the integrity protection method of the control plane data, so that each device can maintain consistency in the processing method and reduce the probability of error.
[0089] In a possible implementation, the security level of the PC5 control plane security protection method of the relay is not higher than the security level of the PC5 user plane security protection method of the second link.
[0090] In a possible embodiment, the security level of the user plane security protection method of the first PC5 link is not higher than the security level of the control plane security protection method of the first PC5 link; the security level of the user plane security protection method of the second PC5 link is not higher than the security level of the control plane security protection method of the second PC5 link.
[0091] The beneficial effects partially achieved in the fourth aspect can be found in the first aspect and will not be repeated here.
[0092] In a fifth aspect, a first secure communication method is provided. The method can be performed by a communication device. The communication device can be a relay or a communication device that can support a relay to implement the functions required by the method. Of course, it can also be other communication devices, such as a chip system. In the first aspect, the communication device is taken as an example of a relay. The method includes:
[0093] The relay sends a direct communication request from the first terminal device to the second terminal device; the direct communication request includes an indication of a secure endpoint policy, and the indication of the secure endpoint policy is used to indicate that the secure endpoint is located on the relay;
[0094] The relay determines a PC5 user plane security protection method for the first PC5 link according to the PC5 user plane security policy of the relay and the PC user plane security policy of the first terminal device;
[0095] The relay sends the PC5 user plane security protection method of the first PC5 link to the second terminal device;
[0096] The relay receives first information from the second terminal device, where the first information is used to indicate a user plane security protection method of the first PC5 link and a user plane security protection method of the second PC5 link;
[0097] The relay activates the user plane security protection method of the second PC5 link and the user plane security protection method of the first PC5 link according to the first information; the user plane security protection method of the second PC5 link is the same as the user plane security protection method of the first PC5 link;
[0098] The first PC5 link is a PC5 link between the relay and the first terminal device; the second PC5 link is a PC5 link between the relay and the second terminal device.
[0099] In an embodiment of the present application, the relay can determine whether to activate the second PC5 link and the user plane security protection method of the second PC5 link, so that by executing the method provided in the embodiment of the present application, collaborative processing of the integrity protection of the user plane data can be achieved between the devices. For example, each device can either activate the user plane security protection method or not activate the integrity protection method of the user plane data, so that each device can maintain consistency in the processing method and reduce the probability of error.
[0100] In a possible implementation, the first information is used to indicate a user plane security protection method of the first PC5 link and a user plane security protection method of the second PC5 link, including:
[0101] The first information is used to indicate: whether the user plane integrity protection of the first PC5 link and the user plane integrity protection of the second PC5 link are both enabled or not enabled, and / or whether the user plane confidentiality protection of the first PC5 link and the user plane confidentiality protection of the second PC5 link are both enabled or not enabled.
[0102] In a possible implementation, the relay receives a second request message from the first terminal device, where the second request message includes the PC5 control plane security policy of the first terminal device and the PC5 control plane security policy of the relay.
[0103] In one possible implementation, the relay determines a PC5 control plane security protection method for the first PC5 link and a PC5 control plane security protection method for the second PC5 link according to a PC5 control plane security policy of the relay and a PC5 control plane security policy of the first terminal device;
[0104] The relay sends the PC5 control plane security protection method of the first PC5 link and the PC5 control plane security protection method of the second PC5 link to the second terminal device;
[0105] The relay receives a control plane security algorithm for the second PC5 link from the second terminal device, where the control plane security algorithm is used to indicate control plane security of the second PC5 link and control plane security of the first PC5 link, and the control plane security algorithm is determined according to a PC5 control plane security protection method for the first PC5 link and a PC5 control plane security protection method for the second PC5 link;
[0106] The relay activates the control plane security of the second PC5 link and the control plane security of the first PC5 link according to the control plane security algorithm of the second PC5 link.
[0107] In a possible implementation, the control plane security algorithm is used to indicate a control plane security protection method for the second PC5 link and a control plane security protection method for the first PC5 link, including:
[0108] The control plane security algorithm is used to indicate: whether the control plane integrity protection of the first PC5 link and the control plane integrity protection of the second PC5 link are both enabled or not enabled, and / or whether the control plane confidentiality protection of the first PC5 link and the control plane confidentiality protection of the second PC5 link are both enabled or not enabled.
[0109] In a possible implementation, the security level of the user plane security protection method of the second PC5 link is not higher than the security level of the control plane security protection method of the second PC5 link, and the security level of the user plane security protection method of the first PC5 link is not higher than the security level of the control plane security protection method of the first PC5 link.
[0110] Some of the beneficial effects achieved in this aspect can be found in the first aspect and will not be repeated here.
[0111] In a sixth aspect, the present application provides a communication device. The device has the functions of implementing the embodiments of the first to third aspects above. The functions can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions.
[0112] In one possible design, the device includes: a transceiver unit, and optionally, a processing unit. The processing unit may be, for example, a processor, the receiving unit may be, for example, a receiver, the sending unit may be, for example, a transmitter, and the receiver and transmitter include radio frequency circuits. Optionally, the device also includes a storage unit, which may be, for example, a memory. When the device includes a storage unit, the storage unit stores computer-executable instructions, the processing unit is connected to the storage unit, and the processing unit executes the computer-executable instructions stored in the storage unit, so that the device performs the method of any one of the first to third aspects above.
[0113] In another possible design, the device is a chip. The chip includes: a receiving unit and a sending unit, and optionally, a processing unit. The processing unit may be, for example, a processing circuit, the receiving unit may be, for example, an input interface, a pin or a circuit, and the sending unit may be, for example, an output interface, a pin or a circuit. The processing unit may execute the computer-executable instructions stored in the storage unit so that the sending method of any one of the first to third aspects above is executed. Optionally, the storage unit is a storage unit within the chip, such as a register, a cache, etc. The storage unit may also be a storage unit within the terminal located outside the chip, such as a read-only memory (ROM), other types of static storage devices that can store static information and instructions, a random access memory (RAM), etc.
[0114] Among them, the processor mentioned in any of the above places can be a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits used to control the execution of the program of the methods of the first to third aspects mentioned above.
[0115] In a seventh aspect, the present application provides a communication device. The device has the functions of implementing the embodiments of the fourth or fifth aspects above. The functions can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions.
[0116] In one possible design, the apparatus includes: a transceiver unit, and optionally, a processing unit. The processing unit may be, for example, a processor, the receiving unit may be, for example, a receiver, the sending unit may be, for example, a transmitter, and the receiver and transmitter include radio frequency circuits. Optionally, the apparatus further includes a storage unit, which may be, for example, a memory. When the apparatus includes a storage unit, the storage unit stores computer-executable instructions, the processing unit is connected to the storage unit, and the processing unit executes the computer-executable instructions stored in the storage unit, so that the access and mobility management function network element performs the method of any one of the fourth or fifth aspects above.
[0117] In another possible design, the device is a chip. The chip includes: a receiving unit and a sending unit, and optionally, a processing unit. The processing unit may be, for example, a processing circuit, the receiving unit may be, for example, an input interface, a pin or a circuit, and the sending unit may be, for example, an output interface, a pin or a circuit. The processing unit may execute the computer-executable instructions stored in the storage unit so that the sending method of any one of the fourth or fifth aspects above is executed. Optionally, the storage unit is a storage unit within the chip, such as a register, a cache, etc. The storage unit may also be a storage unit within the terminal located outside the chip, such as a read-only memory (ROM), other types of static storage devices that can store static information and instructions, a random access memory (RAM), etc.
[0118] Among them, the processor mentioned in any of the above places can be a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits used to control the execution of the program of the method of the fourth aspect or the fifth aspect mentioned above.
[0119] In an eighth aspect, an embodiment of the present application provides a chip system, comprising a processor and further comprising a memory, for implementing the method performed by the first communication device in any of the design examples of the first, second, or third aspects. The chip system may be composed of a chip alone, or may include a chip and other discrete components.
[0120] In a ninth aspect, an embodiment of the present application provides a chip system, which includes a processor and may also include a memory, for implementing the method performed by the second communication device in any of the design examples in the fourth or fifth aspects above. The chip system may be composed of a chip or may include a chip and other discrete devices.
[0121] In a tenth aspect, the present application provides a communication system, comprising the communication device in any one of the design examples in the sixth aspect and the communication device in any one of the design examples in the seventh aspect. Optionally, the communication system further comprises a network data analytics function (NWDAF) network element.
[0122] In the tenth aspect, an embodiment of the present application also provides a computer-readable storage medium, in which a computer program or instruction is stored. When the computer program or instruction is executed, the method in any one of the design examples of the first aspect, second aspect or third aspect mentioned above can be implemented.
[0123] In the eleventh aspect, an embodiment of the present application also provides a computer-readable storage medium, in which a computer program or instruction is stored. When the computer program or instruction is executed, the method in any one of the design examples of the fourth or fifth aspect mentioned above can be implemented.
[0124] In the twelfth aspect, an embodiment of the present application also provides a computer program product, including instructions, which, when run on a computer, enables the computer to execute the method executed by the first communication device in any design example of the first aspect, second aspect or third aspect above.
[0125] In the thirteenth aspect, an embodiment of the present application also provides a computer program product, including instructions, which, when run on a computer, enables the computer to execute the method executed by the second communication device in any design example of the fourth or fifth aspect above.
[0126] In addition, the technical effects brought about by any design method in the sixth to thirteenth aspects can refer to the technical effects brought about by different design methods in the first to fifth aspects, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0127] Figure 1A and Figure 1B An architectural diagram of a system provided in an embodiment of the present application;
[0128] Figure 2A and Figure 2B A schematic diagram of a communication scenario provided in an embodiment of the present application;
[0129] Figure 3 A schematic diagram of a security policy acquisition method provided in an embodiment of the present application;
[0130] Figure 4 A schematic diagram of a secure communication method provided in an embodiment of the present application;
[0131] Figure 5 A schematic diagram of another secure communication method provided in an embodiment of the present application;
[0132] Figure 6 A schematic diagram of another secure communication method provided in an embodiment of the present application;
[0133] Figures 7 and 8 A schematic structural diagram of a communication device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0134] In order to make the purpose, technical solutions and advantages of the embodiments of the present application clearer, the embodiments of the present application will be further described in detail below with reference to the accompanying drawings.
[0135] The following is an introduction to the definitions of terms involved in this application.
[0136] 1. PC5 connection and PC5 connection establishment process:
[0137] The PC5 connection in the embodiment of the present application refers to a communication connection between terminal devices based on the PC5 interface.
[0138] The PC5 connection establishment process in the embodiment of the present application is used to establish a communication connection between at least two terminal devices that support the PC5 interface. Among them, after the PC5 connection is established, at least two terminal devices can use the PC5 connection to perform control plane signaling negotiation and / or user plane data transmission. The PC5 connection establishment process in the embodiment of the present application may include a PC5 unicast connection establishment (one-to-one communication) process and a PC5 multicast connection establishment (one-to-manycommunication) process. The PC5 unicast connection establishment process is used to establish a communication connection between two terminal devices that support the PC5 interface, and the PC5 multicast connection establishment process is used to establish a communication connection between more than two terminal devices that support the PC5 interface. The following embodiments of the present application are all illustrative and are explained by taking the establishment of a communication connection between two terminal devices as an example, that is, the following embodiments of the present application are all illustrative and are explained by taking the PC5 unicast connection establishment process as an example. The method for establishing a communication connection between any two terminal devices in the PC5 multicast connection establishment process can refer to the process for establishing a communication connection between two terminal devices in the PC5 unicast connection establishment process, which is explained uniformly here and will not be repeated below.
[0139] 2. Security Policy
[0140] A security policy is a policy used to describe whether security protection is enabled and can be used to determine the security protection method. In the embodiments of the present application, the security policies used in different scenarios include at least one of a PC5 user plane security policy and a PC5 control plane security policy. The PC5 user plane security policy includes at least one of a user plane confidentiality protection policy and a user plane integrity protection policy in a PC5 connection; the PC5 control plane security policy includes at least one of a control plane confidentiality protection policy and a control plane integrity protection policy in a PC5 connection. In other words, the security policy includes at least one of the following:
[0141] Control plane confidentiality protection policy in PC5 connections;
[0142] Control plane integrity protection strategy in PC5 connections;
[0143] User plane confidentiality protection policy in PC5 connections;
[0144] Alternatively, the user plane integrity protection policy in the PC5 connection.
[0145] Among them, control plane confidentiality protection is to protect the confidentiality of signaling during transmission; control plane integrity protection is to protect the integrity of signaling during transmission; user plane confidentiality protection is to protect the confidentiality of user plane data during transmission; user plane integrity protection is to protect the integrity of user plane data during transmission. In the embodiment of the present application, integrity means that the acquired signaling or data is consistent with the original signaling or data and has not been modified. Therefore, integrity protection is to prevent attackers from "attacking". Confidentiality means that the real content cannot be directly seen, so confidentiality protection is to prevent attackers from "not being able to read it". In addition, confidentiality protection in the embodiment of the present application can also be called encryption protection, which is uniformly explained here and will not be repeated below.
[0146] In the embodiment of the present application, the control plane confidentiality protection policy in the PC5 connection and the control plane integrity protection policy in the PC5 connection belong to the PC5 control plane security policy in the PC5 connection; the user plane confidentiality protection policy in the PC5 connection and the user plane integrity protection policy in the PC5 connection belong to the PC5 user plane security policy in the PC5 connection. They are explained here uniformly and will not be repeated below.
[0147] In the embodiments of the present application, the security policy is divided into three types: REQUIRED, NOT NEEDED, and PREFERRED. Alternatively, REQUIRED means security needs to be enabled, NOT NEEDED means security does not need to be enabled, and PREFERRED means preferred or optional, meaning security can be enabled or not. These are described here for clarity and will not be further elaborated below.
[0148] For example, taking the control plane confidentiality protection policy in a PC5 connection as an example, the control plane confidentiality protection policy in the PC5 connection includes: control plane confidentiality protection in the PC5 connection is enabled (REQUIRED), control plane confidentiality protection in the PC5 connection is not enabled (NOT NEEDED), or control plane confidentiality protection in the PC5 connection is optional (PREFERRED). For examples of the control plane confidentiality protection policy in the PC5 connection, the user plane confidentiality protection policy in the PC5 connection, or the user plane integrity protection policy in the PC5 connection, refer to the example of the control plane confidentiality protection policy in the PC5 connection and are not further described here.
[0149] It should be noted that in the embodiments of the present application, when a security policy is sent, generally only one of the three policies (REQUIRED, NOT NEEDED, and PREFERRED) will be selected for transmission. In some special scenarios, at least two policies may be selected, and one of them may be PREFERRED. For example, when NOT NEEDED and PREFERRED are sent, it indicates that security protection is not intended to be enabled; when REQUIRED and PREFERRED are sent, it indicates that security protection is intended to be enabled.
[0150] It should be noted that in the embodiment of the present application, the control plane confidentiality protection policy in the PC5 connection, the control plane integrity protection policy in the PC5 connection, and the user plane confidentiality protection policy in the PC5 connection; or, multiple protection policies in the user plane integrity protection policy in the PC5 connection can be the same, and the embodiment of the present application does not make specific limitations on this.
[0151] 3. Security capabilities:
[0152] The security capabilities in the embodiments of the present application include at least one of the following:
[0153] One or more control plane confidentiality protection algorithms supported in PC5 connections;
[0154] One or more control plane integrity protection algorithms supported in the PC5 connection;
[0155] One or more user plane confidentiality protection algorithms supported in PC5 connections;
[0156] Alternatively, one or more user plane integrity protection algorithms supported in the PC5 connection.
[0157] Among them, the control plane confidentiality protection algorithm refers to a confidentiality protection algorithm used to protect the control plane. The control plane integrity protection algorithm refers to an integrity protection algorithm used to protect the control plane. The user plane confidentiality protection algorithm refers to a confidentiality protection algorithm used to protect the user plane. The user plane integrity protection algorithm refers to a user plane protection algorithm used to protect the control plane. Among them, one or more control plane confidentiality protection algorithms supported in the PC5 connection and one or more control plane integrity protection algorithms supported in the PC5 connection belong to the control plane security capability in the PC5 connection; one or more user plane confidentiality protection algorithms supported in the PC5 connection and one or more user plane integrity protection algorithms supported in the PC5 connection belong to the user plane security capability in the PC5 connection. They are explained here uniformly and will not be repeated below.
[0158] It should be noted that in the embodiment of the present application, one or more control plane confidentiality protection algorithms supported in the PC5 connection, one or more control plane integrity protection algorithms supported in the PC5 connection, one or more user plane confidentiality protection algorithms supported in the PC5 connection, or multiple protection algorithms in the one or more user plane integrity protection algorithms supported in the PC5 connection may be the same or have common items, and the embodiment of the present application does not make specific limitations on this.
[0159] 4. Security algorithms may include user plane security algorithms (i.e., security algorithms used on the user plane) and signaling plane security algorithms (i.e., security algorithms used on the signaling plane). User plane security algorithms are used to protect user plane data and may include user plane encryption algorithms and user plane integrity algorithms. Signaling plane security algorithms are used to protect signaling and may include signaling plane encryption algorithms and signaling plane integrity algorithms.
[0160] 5. Security keys may include user plane security keys and signaling plane security keys. User plane security keys are used to protect user plane data and may include user plane encryption keys and user plane integrity protection keys. Signaling plane security keys are used to protect signaling and may, for example, be keys for protecting radio resource control (RRC) signaling, i.e., RRC keys. RRC keys may include RRC encryption keys and RRC integrity protection keys.
[0161] 6. Activating user plane / signaling plane security means that, once the user plane / signaling plane security protection method is determined, the user plane / signaling plane security algorithm and user plane / signaling plane security keys can be used to activate the user plane / signaling plane security. This means that the user plane / signaling plane security algorithm, user plane / signaling plane security algorithm, and user plane / signaling plane security keys can be used to securely protect the user plane data / signaling to be transmitted. For example, if the determined user plane security protection method is to enable user plane confidentiality protection and disable user plane integrity protection, the user plane encryption algorithm is encryption algorithm A, and the user plane encryption key is key K, then encryption algorithm A and key K will be used to protect the user plane confidentiality of the user plane data to be transmitted. Activating the user plane security protection method can result in the node performing the user plane security activation being able to begin both protecting and de-protecting the user plane data. It should be understood that the protection and de-protection actions may be activated separately. For example, after the base station sends a security activation message, the base station activates the security protection; after the base station receives a security activation confirmation message, the base station activates the security protection.
[0162] 7. Security protection and de-security protection:
[0163] Security protection in the embodiments of the present application refers to protecting user plane data / control plane signaling using a security protection method; de-security protection in the embodiments of the present application refers to restoring user plane data / control plane signaling according to the security protection method. The security protection method herein includes whether confidentiality protection and / or integrity protection are enabled, which are described here uniformly and will not be further elaborated below.
[0164] Specifically, when confidentiality protection is turned on, encryption keys and encryption algorithms can be used to encrypt and protect user plane data / control plane signaling; when integrity protection is turned on, integrity protection keys and integrity protection algorithms can be used to protect the integrity of user plane data / control plane signaling. Of course, in the embodiment of the present application, when integrity protection is not turned on, a message integrity check code (MIC) can also be used to protect the integrity of user plane data / control plane signaling, and the embodiment of the present application does not specifically limit this. Among them, the relevant description of MIC refers to the subsequent embodiments and will not be repeated here. In addition, it should be noted that when encryption protection and integrity protection are required for user plane data / control plane signaling, encryption protection can be performed on the user plane data / control plane signaling first, and then integrity protection can be performed; or integrity protection can be performed on the user plane data / control plane signaling first, and then encryption protection can be performed. The embodiment of the present application does not limit the execution order of encryption protection and integrity protection, and they are explained here uniformly, and will not be repeated below.
[0165] Specifically, when confidentiality protection is enabled, the encryption key and encryption algorithm can be used to decrypt the user plane data / control plane signaling; when integrity protection is enabled, the integrity protection key and integrity protection algorithm can be used to perform integrity protection verification on the user plane data / control plane signaling. Of course, in the embodiment of the present application, when integrity protection is not enabled, if MIC is used to perform integrity protection on the user plane data / control plane signaling, then correspondingly, the expected MIC can be used to perform integrity protection verification on the user plane data / control plane signaling, and this embodiment of the present application does not specifically limit this. Among them, the relevant description of the expected MIC refers to the subsequent embodiments and will not be repeated here. In addition, it can be understood that when confidentiality protection and integrity protection are performed on user plane data / control plane signaling at the same time, if the user plane data / control plane signaling is first confidentiality protected and then integrity protected, the order of decrypting the security protection is to first perform integrity protection verification and then decrypt the encrypted user plane data / control plane signaling; if the user plane data / control plane signaling is first integrity protected and then encrypted, the order of decrypting the security protection is to first decrypt the encrypted user plane data / control plane signaling and then perform integrity protection verification. This is explained here uniformly and will not be repeated below.
[0166] The security protection method used by the control plane of the PC5 connection is used to protect all or part of the parameters transmitted in the control plane signaling of the PC5 connection. The security protection method used by the control plane of the PC5 connection may include, for example, whether confidentiality protection and / or integrity protection of the control plane of the PC5 connection is enabled.
[0167] The security protection method used by the user plane of the PC5 connection is used to protect part or all of the user plane data of the PC5 connection. The security protection method used by the user plane of the PC5 connection may include, for example, whether confidentiality protection and / or integrity protection of the user plane of the PC5 connection is enabled.
[0168] It should be noted that, in the embodiment of the present application, the security protection method used by the control plane of the PC5 connection can also be referred to as the security protection method used by the control plane signaling of the PC5 connection; the security protection method used by the user plane of the PC5 connection can also be referred to as the security protection method used by the user plane data of the PC5 connection. These are uniformly explained here and will not be repeated below.
[0169] See Figure 1A As shown in FIG, a schematic diagram of a specific control plane system architecture applicable to the present application. The network elements in the system architecture include terminal equipment (UE), Figure 1AFour UEs are drawn as an example, namely UE A, UE B, UE C, and UE D. The system architecture also includes a radio access network (RAN), an access and mobility management function (AMF) network element, a session management function (SMF) network element, a user plane function (UPF) network element, a unified data management (UDM) network element, a unified data repository (UDR) network element, an application function (AF) network element, a data network (DN), a network exposure function (NEF) network element, a 5G direct discovery name management function (5GDDNMF) network element, a policy control function (PCF) network element, a ProSe application server, etc. Among them, AMF network elements, SMF network elements, UDM network elements, NEF network elements, PCF network elements and other network elements belong to the core network elements in the fifth generation mobile communication technology (5th generation mobile networks, 5G) network architecture. Only some core network network elements are shown here as examples. Other core network elements can also be included in the system architecture.
[0170] A terminal device is a device with wireless transceiver capabilities that can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; it can also be deployed on water (such as ships, etc.); it can also be deployed in the air (such as airplanes, balloons, and satellites, etc.). The terminal device can be a mobile phone, a tablet computer, a computer with wireless transceiver capabilities, a virtual reality (VR) terminal, an augmented reality (AR) terminal, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, etc. The terminal device in the embodiment of the present application can be a terminal device capable of communicating in a proximity service (ProSe) scenario. The terminal device has a proximity service application (ProSe application) function, and terminal devices with ProSe application functions can communicate through PC5 port.
[0171] The embodiments of the present application involve three types of terminal devices, namely a first terminal device, a relay device, and a second terminal device. The first terminal device can request other terminal devices (including the second terminal device) to provide proximity services for the first terminal device. When the second terminal device is able to provide proximity services for the first terminal device, it provides proximity services for the first terminal device. The second terminal device and the first terminal device can communicate directly or through a relay device.
[0172] In different discovery scenarios, the names of the second terminal device providing the proximity service and the first terminal device requiring the proximity service are different. Here we introduce two discovery scenarios, namely the open proximity service discovery (open ProSe discovery) scenario and the restricted proximity service discovery (restricted ProSe discovery) scenario. The relevant descriptions of the open proximity service discovery scenario and the restricted proximity service discovery scenario can be referred to the existing technology and will not be repeated here.
[0173] For example, if user A is playing a game on device A and doesn't have a specific gaming partner, they can simply "randomly" find a gaming partner. This scenario is an open proximity service scenario. If user A has a specific gaming partner on device A, they can "designate" a partner through device A. Only the designated partner can access the game, and others cannot. This scenario is a restricted proximity service discovery scenario.
[0174] Optionally, in an embodiment of the present application, the discovery mode in the discovery scenario includes model A or model B. The difference between model A and model B is that the terminal device initiates discovery in a different manner in the discovery scenario.
[0175] Model A means "I am here". The terminal devices involved in model A are divided into announcing UE and monitoring UE. The announcing UE broadcasts "I am here". After receiving the message broadcast by the announcing UE, the monitoring UE determines whether to establish a connection with the announcing UE based on whether it meets its own business needs.
[0176] Model B means "Who is there? / Where are you?". The terminal devices involved in model B are divided into discoveree UE and discoverer UE. The discoverer UE initiates a request, which includes specific information, such as "Who is there? / Where are you?" After receiving the request initiated by the discoverer UE, the discoveree UE determines whether to reply to the request based on whether it can provide business services. If it replies, it means "I am here". In this embodiment of the present application, the open proximity service discovery scenario is only applicable to the model A discovery mode, while the restricted proximity service discovery scenario is applicable to both model A and model B discovery modes.
[0177] In an embodiment of the present application, the network side (such as a core network element or a 5G DDNMF element) can determine the type of the first terminal device or the second terminal device based on the neighboring service information reported by the first terminal device or the second terminal device to the network side. For example, the discovery command included in the neighboring service information reported by the first terminal device or the second terminal device to the network side can indicate whether the first terminal device or the second terminal device is an announcing UE or a monitoring UE; a responding terminal device (response UE) or a requesting terminal device (queryUE). Among them, the announcing UE and the monitoring UE are the terminal devices at both ends in the above-mentioned model A, and the Response UE and the QueryUE correspond to the discoveree UE and the discoverer UE in the above-mentioned model B, respectively.
[0178] In the application embodiment, before the second terminal device provides proximity services to the first terminal device, it needs to first verify the identity of the first terminal device to determine whether the second terminal device is a terminal device that really needs proximity services. Specifically, the second terminal device can report the message completion code obtained from the first terminal device to the core network network element or the 5G DDNMF network element, wherein the message completion code is generated based on the discovery key of the first terminal device, and the discovery key of the first terminal device is generated using the key generation parameters obtained from the core network network element or the 5G DDNMF network element. The core network network element or the 5G DDNMF network element verifies based on the message completion code reported by the second terminal device and the expected message completion code calculated by the 5G DDNMF network element according to the discovery key of the first terminal device. The second terminal device can also obtain the discovery key with the first terminal device from the core network network element or the 5G DDNMF network element, and the second terminal device calculates the expected message completion code for verification.
[0179] Similarly, before accepting the proximity service provided by the second terminal device, the first terminal device may also verify the identity of the second terminal device to determine whether the second terminal device is a terminal device that can truly provide the proximity service. The specific method is similar to the method used by the second terminal device to verify the identity of the first terminal device.
[0180] The primary function of the RAN is to control user access to the mobile communications network via radio. The RAN is part of a mobile communications system. It implements a radio access technology. Conceptually, it resides between a device (such as a mobile phone, a computer, or any remote control) and provides connectivity to its core network.
[0181] The AMF network element is responsible for terminal access management and mobility management. In actual applications, it includes the mobility management function in the MME in the LTE network framework and adds access management functions.
[0182] Optionally, the AMF network element can also use Kamf to generate a discovery key for the terminal device and send the discovery key of the terminal device to the 5GDDNMF network element or other network elements (such as the ProSe application server).
[0183] Among them, Kamf is a root key of the terminal device, which is allocated to the terminal device by the network side (such as the AMF network element) when the terminal device registers to the network, and is stored in the terminal device and the AMF side respectively.
[0184] The SMF network element is responsible for session management, such as user session establishment.
[0185] The PCF network element is a control plane function provided by the operator and is used to provide session policies to the SMF network element. Policies may include charging-related policies, QoS-related policies, and authorization-related policies.
[0186] The UPF network element is a functional network element of the user plane, which is mainly responsible for connecting to the external network. It includes the relevant functions of the LTE serving gateway (SGW) and public data network gateway (PDN-GW).
[0187] DN is responsible for providing a network service for terminals. For example, some DNs provide Internet access for terminals, while others provide SMS functions for terminals.
[0188] The UDM network element can store the user's subscription information, which is similar to the HSS in 4G. In the embodiment of the present application, the UDM can determine the UE's user permanent identifier (SUPI) based on the UE's anonymous identifier or temporary identifier.
[0189] The UDR network element is mainly used to store user contract information, policy data, open structured data, and application data.
[0190] The AF network element can be a third-party application control platform or the operator's own equipment. The AF network element can provide services for multiple application servers.
[0191] NEF network elements open the capabilities and events of other network elements to third-party partners or AF network elements. It provides a secure way for AF network elements to provide information to the 3rd Generation Partnership Project (3GPP) network. NEF network elements can verify and authorize AF network elements and assist in restricting AF network elements. In addition, NEF network elements can also convert information exchanged between AF network elements and information exchanged between core network function network elements.
[0192] The ProSe application server stores user identities for ProSe services and can also authenticate terminal devices in discovery scenarios. It can also store keys pre-configured for terminal devices, which are keys related to ProSe services.
[0193] In practical applications, the ProSe application server can be an AF network element (NEE), that is, an AF network element that also functions as a ProSe application server. This allows the ProSe application server and the UE to communicate in the user plane via the UE-RAN-UPF-AF path. The ProSe application server can also communicate with other core network elements via the NEF network element, for example, with the PCF network element.
[0194] In the open proximity service discovery scenario, the 5GDDNMF network element can allocate a proximity service application identifier (ProSe application ID) and a proximity service application code (ProSe application code), as well as process the mapping between the proximity service application identifier (ProSe application ID) and the proximity service application code (ProSe application code). In the restricted proximity service discovery scenario, the 5GDDNMF network element can communicate with the ProSe application server through the PC2 port to process the authorization of the discovery request (discovery request), allocate a restricted proximity service application identifier (ProSe discovery UE ID) and a restricted proximity service code (ProSe restricted code), and process the mapping between the proximity service application identifier (ProSe discovery UE ID) and the restricted proximity service code (ProSe restricted code). Among them, the proximity service application code (ProSe application code) and the restricted proximity service code (ProSe restricted code) can both be used as the proximity service temporary identifier mentioned in the embodiment of the present application.
[0195] In the embodiments of the present application, the 5GDDNMF network element adds a security function that can verify the identity of terminal devices (such as the first terminal device and the second terminal device). For example, after receiving the message completion code reported by the second terminal device from the first terminal device, the 5GDDNMF network element can use the discovery key of the first terminal device to generate an expected message completion code. After determining that the message completion code is consistent with the expected message completion code, it notifies the second terminal device that the authentication of the first terminal device is successful.
[0196] It should be noted that this is only an example of adding security functions to the 5GDDNMF network element. This security function can also be added to other network elements, such as core network elements or ProSe application servers, and other network elements interact with terminal devices to verify the identities of other terminal devices.
[0197] Although not shown, the core network network elements also include an authentication service function (AUSF) network element, an authentication and key management for applications (AKMA) anchor function (AAnF) network element, a bootstrapping server function (BSF), etc. The AUSF network element has an authentication service function. In the embodiment of the present application, the AUSF network element can use the Kausf of the terminal device to generate a discovery key for the terminal device, and send the discovery key of the terminal device to the 5GDDNMF network element. Similarly, the AAnF network element can use Kakma to generate a discovery key for the terminal device, and send the discovery key of the terminal device to the 5GDDNMF network element. The bootstrapping server function (BSF) network element can use Ks to generate a discovery key for the terminal device, and send the discovery key of the terminal device to the 5GDDNMF network element.
[0198] Among them, Kausf, Kakma, or Ks is also used as the root key to generate the discovery key of the terminal device. These keys are allocated to the terminal device by the network side when the terminal device registers to the network and are stored on the network side. The key is the same as the key generated by the terminal device itself and stored on the terminal device side.
[0199] Figure 1B This is a schematic diagram of the specific user plane system architecture applicable to this application. The introduction of the functions of the network elements can be referred to Figure 1A The user plane architecture mainly refers to the interaction between the UEA and the 5G DDNMF through the user plane. That is, the UE first accesses the 5GC to complete the user plane establishment, and then the UEA and the 5G DDNMF interact through the user plane.
[0200] Figure 1B and Figure 1A The main difference is that the way UE A connects to 5G DDNMF is different. The control plane architecture mainly refers to the interaction between UE and 5G DDNMF through the control plane. That is, UE first finds AMF through NAS message, and then AMF forwards the NAS message to 5G DDNMF.
[0201] Figure 2AThis is the UE-to-Network Relay system architecture, which shows that a UE can access the network in two ways and three paths. The two ways are direct connection between the UE and the network (path #1 shown in the figure) and UE accessing the network through a relay (paths #2 and #3 shown in the figure).
[0202] in addition, Figure 2B The following figure shows an architecture where UE-1 and UE-2 communicate via a relay. In this case, the relay acts as a medium for communication between UE-1 and UE-2. Through the relay, UE-1 and UE-2 can communicate.
[0203] Currently, for Figure 2B The scenario shown is that UE-1 and UE-2 communicate through a relay. Since the links at both ends of the relay are not defined (such as Figure 2B The relationship between the activation results of the security protection method between the first PC5 link and the second PC5 link, or the first PC5 link and the Uu link, is shown. When security activation occurs in a segmented manner (e.g., UE-1's security endpoint policy uses hop-to-hop security), inconsistent security protection may occur between the two links. For example, assume that the security protection of the links at both ends of the relay is as follows: the first PC5 link between UE-1 and the relay has user plane confidentiality protection enabled and user plane integrity protection enabled; however, the second PC5 link between the relay and UE-2 does not have user plane confidentiality protection enabled, but does have user plane integrity protection enabled. This results in user plane data being confidentiality-protected only on the first PC5 link. This means that an attacker can illegally obtain user plane data from the link between the relay and UE-2. Therefore, the confidentiality protection of the first PC5 link between UE-1 and the relay is meaningless, and the processing performance of UE1 and the relay is wasted. It can be seen that the current communication method of the UE-to-Network Relay system still has insufficient security issues.
[0204] To this end, an embodiment of the present application provides a secure communication method, comprising: a relay device determining a user plane protection method for a first PC5 link between the relay device and a first terminal device based on the user plane protection method for a second PC5 link between the relay device and a second terminal device, thereby ensuring consistency in user plane security protection results for the two links. This avoids user plane security protection failures caused by inconsistencies in the user plane security protection methods used on the two PC5 links.
[0205] Next, the technical solutions provided by the embodiments of the present application are introduced with reference to the accompanying drawings.
[0206] In various embodiments of this application, the identifiers that may be involved include but are not limited to at least one of the following:
[0207] 1. Terminal identification.
[0208] The terminal identification may include at least one of an international mobile subscriber identification number (IMSI), a permanent equipment identifier (PEI), a subscriber permanent identifier (SUPI), a subscriber concealed identifier (SUCI), a temporary mobile subscriber identity (TMSI), an IP multimedia public identity (IMPU), a media access control (MAC) address, an IP address, a mobile phone number, or a globally unique temporary UE identity (GUTI). For example, the terminal identification includes only IMSI, or only PEI and SUPI, or only PEI, TMSI, and IMPU, or includes IMSI, PEI, SUPI, SUCI, TMSI, IMPU, MAC address, IP address, mobile phone number, and GUTI, etc., without limitation here. In subsequent embodiments, UEID is uniformly used to represent the terminal identification.
[0209] Among them, PEI is the fixed identifier of the terminal device; IMSI is the unique permanent identifier of the user in the LTE system; SUPI is the permanent identifier of the user in the 5G system; SUCI is the user identifier obtained by encrypting SUPI.
[0210] The following describes a secure communication method provided by an embodiment of the present application in conjunction with the accompanying drawings. The secure communication method provided by an embodiment of the present application includes two parts: the first part: a security policy configuration method; the second part: a user plane security protection method and a control plane security protection method for determining the PC5 link by a relay device or a second terminal device. The two parts are described below:
[0211] Part 1:
[0212] See also Figure 3 , a security policy configuration method provided in an embodiment of the present application is described, the method comprising:
[0213] In step 301, the terminal device sends a NAS message to the AMF, which is used to trigger the AMF to provide preset data to the terminal device. The preset data is used for establishing a PC5 link in a subsequent short-range communication (prose) scenario.
[0214] Specifically, the terminal device can send the NAS message to the AMF through the RAN.
[0215] Exemplarily, the NAS message may be a UE policy provisioning request message for a terminal device. The message may include a terminal identifier (such as a 5G-GUTI) of the terminal device and short-range communication role indication information (such as a remote indication and / or a relay indication) of the terminal device.
[0216] The terminal identifier is used by the network device to determine which terminal device initiated the request. For example, the network device can determine the UE's SUPI through the 5G-GUTI and obtain the UE's network data based on the UE's SUPI, such as the contract data in the Prose communication scenario.
[0217] The short-range communication role indication information is used by the network-side device to determine what type of UE the UE can access the network as in the Prose scenario. For example, whether the UE accesses the network as a normal UE; or can it access the network as a relay serving other UEs to facilitate forwarding data between other UEs and the access network (or forwarding data between other UEs and another UE); or can it access the network as a remote UE. A remote UE refers to a UE that needs to be relayed to connect to another UE (or network) and exchange data. In other words, a remote UE cannot connect to the network (or to another UE) without the assistance of a relay UE.
[0218] For example, there are several possible implementations of the indication method of the short-range communication role indication information.
[0219] The first possible implementation method: Setting the short-range communication role indication information to "0" indicates that it does not need to act as a relay. At this time, "0" can be understood in two ways on the network side: (1) The UE can act as a remote UE, but not as a relay UE. At this time, it can be understood that all UEs can act as remote UEs; (2) The UE can neither act as a remote UE nor as a relay. This embodiment does not limit the specific understanding method. Setting it to "1" indicates that it can act as a relay. At this time, "1" can be understood in two ways on the network side: (1) The UE can only act as a relay; (2) The UE can act as both a remote UE and a relay. This embodiment does not limit the specific understanding method.
[0220] The second possible implementation method: setting the short-range communication role indication information to "00" indicates that it does not need to be a remote UE or a relay; setting it to "01" indicates that it cannot be a remote UE, but can be a relay; setting it to "10" indicates that it can be a remote UE, but cannot be a relay; setting it to "11" indicates that it can be both a remote UE and a relay.
[0221] A third possible implementation method: The short-range communication role indication information can also be a character string, such as "remote", "relay", "remote & Relay". This embodiment does not limit the number of character strings that can appear at the same time. That is to say, when only two character strings, "remote" and "relay", can be used, these two character strings can be transmitted at the same time, indicating that the UE can act as two roles at the same time. If only one appears, it means that it can only act as one role. When all three character strings are supported, "remote" means that the UE can only act as a remote UE, "relay" means that the UE can only act as a relay UE, and "remote & Relay" means that the UE can act as both a remote UE and a relay UE.
[0222] Step 302: AMF checks the authorization information of the terminal device.
[0223] Specifically, AMF needs to check whether the identity indication information transmitted by the terminal device is legal, that is, whether it can be a remote UE (Remote UE), or AMF needs to check whether the terminal device can be used as a relay, or when the short-range communication role indication information indicates that the terminal device can be used as both a remote UE and a relay, AMF needs to perform the above two identity checks at the same time.
[0224] Specifically, one implementation method for checking authorization may be: the AMF interacts with the UDM to obtain the contract data of the terminal device in the Prose communication scenario from the UDM. The AMF determines whether the terminal device can serve as a relay and / or remote UE based on the contract data. Of course, the AMF can also obtain the contract data of the terminal device from the PCF, or obtain the contract data of the terminal device from the Prose application server through the capability exposure network element, which is not limited in this embodiment.
[0225] Another way to check authorization is for the AMF to obtain the results of the terminal device's authorization information check from the PCF. Specifically, the PCF interacts with the UDM to obtain the terminal device's subscription data for the Prose scenario from the UDM. Based on the subscription data, the PCF determines whether the terminal device can function as a relay and / or remote UE, and then sends the check results to the AMF. Of course, the PCF can also obtain the terminal device's subscription data from a Prose application server or other device via a capability exposure network element, but this embodiment does not limit this.
[0226] Step 303: When the AMF successfully checks the authorization of the terminal device, the AMF sends a request message to the PCF, which is used to request the security policy preset data of the terminal device.
[0227] Exemplarily, the AMF sends a (pcf_UEPolicyControl_Update) message to the PCF, which includes the terminal device's short-range communication role indication information (such as remote UE indication / relay UE indication). Optionally, the message also carries the terminal device's short-range (Prose) communication-related information (such as the UE's Prose identity information: Prose User ID, Prose application information, Prose APP ID, etc.).
[0228] Step 304: The PCF determines the security policy of the terminal device.
[0229] Specifically, based on the short-range communication role indication information of the terminal device, when it is determined that the terminal device can serve as a relay, the PCF determines the security policy used by the terminal device as a relay (relay identity); when it is determined that the terminal device can serve as a remote UE, the PCF determines the security policy used by the terminal device as a remote UE (remote identity). When it is determined that the terminal device is an ordinary UE, the PCF determines the security policy used by the terminal device as an ordinary UE. Among them, the security policy may include PC5 control plane security policy and / or PC5 user plane security policy. When it is determined that the terminal device can serve as both a relay and a remote UE, the PCF can respectively determine the security policy used by the terminal device as a relay and the security policy used by the terminal device as a remote UE.
[0230] In a possible embodiment, the PCF may further interact with other network elements (such as the 5G DDNMF) to obtain more Prose-related information of the terminal device, such as the Prose APP Code, which is used for discovery between UEs.
[0231] Step 305: The PCF sends a response message to the AMF, which includes the security policy of the terminal device.
[0232] Specifically, the PCF replies to the AMF with a Nafm_Communication_N1N2MessageTransfer message, which includes at least one type of security policy for a common identity and a security policy for a non-common identity, such as a relay identity or a remote identity.
[0233] In one possible case, if the message carries only one security policy, it means that the security policy can be used not only for common access, but also for remote identity and / or relay identity access (if the UE supports these identities).
[0234] In another possible case, if the message carries two security policies, one represents a security policy used by a common identity, and the other represents a security policy used by a non-common identity.
[0235] In another possible case, if the message carries three security policies, they represent the security policy used by the common identity, the security policy used by the remote identity, and the security policy used by the relay identity.
[0236] In the embodiment of the present application, if all UEs can be used as remote identities, then the remote identity can also be a common identity. In this case, the non-common identity only includes the relay identity. If not all UEs can use the remote identity, then the non-common identity includes the relay identity and the remote identity.
[0237] Step 306: AMF forwards the security policy of the terminal device to the UE.
[0238] Step 307: The terminal device receives the security policy and saves it to the local device.
[0239] It should be noted that the above-mentioned PCF can also be other network elements that can provide security. The so-called network element that provides security policy is the network element or functional entity that allocates policy on the network side, such as PCF in 5G, policy and charging rules function unit (PCRF) in 4G, and network elements that inherit related functions in future networks.
[0240] In one possible embodiment, in step 304, the security policy of the terminal device determined by the PCF may have multiple granularities. For example, it may be PCF granularity, that is, all terminal devices requesting the PCF correspond to the same security policy; another example may be UE granularity, that is, different terminal devices may correspond to different security policies; another example may be APP granularity, that is, terminal devices corresponding to different APP IDs may correspond to different security policies; another example may be UE+APP granularity, that is, different terminal devices may correspond to different security policies based on different UE+APP binding relationships.
[0241] It should be noted that although security policies can be divided into security policies for common identities and security policies for non-common identities, the security policies for terminal devices with different identities can be the same or different. For example, the security policies corresponding to terminal devices with two identities, remote UE and relay UE, can be the same or different.
[0242] Alternatively, security policies can be stored after being bound to the remote or relay identity, i.e., storing the security policies for both identities. For example, UE1's security policy includes the security policy for the remote identity and the security policy for the relay identity. For example, the security policy for a standard identity includes control plane confidentiality protection set to PREFERRED, control plane integrity protection set to REQUIRED, user plane confidentiality protection set to NOT NEEDED, and user plane integrity protection set to REQUIRED; while the security policy for a non-standard identity includes control plane confidentiality protection set to PREFERRED, control plane integrity protection set to PREFERRED, user plane confidentiality protection set to PREFERRED, and user plane integrity protection set to PREFERRED. Of course, if the security policies for different identities of UE1 are the same, only the security policy for one identity can be stored. For example, control plane confidentiality protection set to PREFERRED, control plane integrity protection set to PREFERRED, user plane confidentiality protection set to PREFERRED, and user plane integrity protection set to PREFERRED. This embodiment does not limit the storage method; in specific implementations, only one implementation method can be used, or multiple implementation methods can coexist.
[0243] In one possible embodiment, a method for ensuring link establishment is: in the configuration of the security policy, the security policy used by the ordinary identity (similar to the security policy used in the one-to-one communication process in V2X) can include two states: enabled and disabled. For example, the control plane confidentiality protection is enabled, the control plane integrity protection is optional, the user plane integrity protection is disabled, and the user plane confidentiality protection is optional. The security policy used by the non-ordinary identity only includes optional security policies, that is, only includes the "PREFERRED" state, and does not include the "REQUIRED" state and the "NOT NEEDED" state.
[0244] The advantage of this is that it ensures that the message link can be established in the communication scenario with relay. Figure 2B If the security policies of any two of the relays shown, UE-1, UE-2, and the relay, are in opposite states (e.g., UE-1's control plane confidentiality policy is REQUIRED and UE-2's control plane confidentiality policy is NOT NEEDED), UE-2 or the relay will release the connection, preventing the link from being established. Therefore, if the relay's security policy includes both "disabled" and "optional" states, a message link in the relay scenario may fail to be established due to the relay's explicit security policy.
[0245] Another way to ensure link establishment is to assign the same security policy, but without the "PREFERRED" status, to UEs with common attributes. Common attributes refer to the same service granularity or other attribute information, which can be used to group UEs together. This ensures that only those UEs within the relay range will use the relay to establish services, ensuring that link establishment is not disrupted due to the relay.
[0246] In addition, in a possible embodiment, the PCF also stores at least one of a security endpoint policy and a security algorithm policy. The security policy of the terminal device determined by the PCF may also include at least one of a security endpoint policy and a security algorithm policy of the terminal device.
[0247] 1) The secure endpoint policy specifies whether the secure endpoint should or prefers to be placed on a relay, or whether it should or prefers not to be placed on a relay. "Should" is a mandatory requirement, meaning it must be met. "Tends" is a preference, meaning it may not be met.
[0248] For example, when the bit information is only one bit and its value is 0, it indicates that the secure endpoint should or prefers to be placed on a relay, while a value of 1 indicates that the secure endpoint should not or does not prefer to be placed on a relay. For another example, when the bit information is at least two bits, 00 indicates that the secure endpoint must be placed on a relay, 01 indicates that the secure endpoint prefers to be placed on a relay, 10 indicates that the secure endpoint prefers not to be placed on a relay, and 11 indicates that the secure endpoint must not be placed on a relay. For another example, the strings "end," "hop," and "prefer" can be used to indicate that the secure endpoint must not be placed on a relay, must be placed on a relay, and prefers to be placed on a relay, respectively.
[0249] 2) The security algorithm policy refers to whether a 128-bit algorithm or a 256-bit algorithm should or should be used. This can be represented by bit indication information or a string.
[0250] For example, when the bit information is only one, 0 indicates that a 128-bit algorithm should or prefers to be used, and 1 indicates that a 256-bit algorithm should or prefers to be used. For another example, when the bit information is at least two, 00 indicates that a 128-bit algorithm must be used, 01 indicates that a 128-bit algorithm is preferred, 10 indicates that a 256-bit algorithm is preferred, and 11 indicates that a 256-bit algorithm must be used. For another example, the strings 128, 256, and prefer can be used to indicate that a 128-bit algorithm must be used, a 256-bit algorithm must be used, or both are acceptable.
[0251] The above-mentioned secure endpoint policy and secure algorithm policy may use the same granularity information as the security policy, that is, these policies have the same granularity as the security policy; or they may use different granularity information than the security policy, that is, these policies have different granularity than the security policy. This embodiment does not specify this.
[0252] Among them, the granularity information of the security policy refers to the scope within which the security policy can be applied. For example, when the security policy is at the APPID granularity, it means that the security policy corresponding to a certain APP ID cannot be used on other APP IDs. For another example, when the security policy is at the UE granularity, it means that all services of this UE use the same security policy. The present invention does not limit the PCF to storing a single security policy for the UE, that is, the PCF can only store UE-granular security policies for certain UEs. It is also possible to store only APP ID-granular security policies for the UE. Security policies of different granularities can also be stored for the UE. For example, if the security policy corresponding to a certain APP ID and the corresponding security policies other than this APP ID are stored for a UE, the corresponding security policies other than this APP ID can be understood as UE-granular.
[0253] Optionally, in step 305, the response message may also carry granular security policy information. For example, each Prose APP ID has a corresponding security policy. When the security policy and granular information are combined, the following possible representation methods emerge. The following representation methods can be used for storage in the UE and PCF, and for the representation method of the transmitted information in the step 305 message. The present embodiment does not limit its use scenario.
[0254] 1) {Security policy for common identity, security policy for non-common identity = (security policy for Prose APP ID-1, security policy for Prose APP ID-2, default security policy)}; This method means that there is a security policy for a common identity. This security policy is used when the UE is not a remote UE or a relay UE. When all UEs can be used as remote UEs, this security policy is the security policy used only when the UE is not a relay UE. It also includes a security policy for a non-common identity with Prose APP ID 1, a security policy for a non-common identity with Prose APP ID 2, and a default security policy for a non-common identity. When the non-common identity includes both a remote identity and a relay identity, the security policy for Prose APP ID-1 can include the security policy for at least one non-common identity. For example, for Prose APP ID-1, it can include only the security policy for the relay identity corresponding to Prose APP ID-1, or it can include both the security policy for the relay identity corresponding to Prose APP ID-1 and the security policy for the remote identity of Prose APP ID-1. It's important to note that in this method, the Prose APP ID represents the granularity of the security policy. Therefore, if the PC5 security granularity doesn't match the Prose APP ID, the Prose APP ID can be replaced with the granularity corresponding to the security policy. For example, if the granularity is UE, the Prose APP ID can be changed to SUPI.
[0255] If the security policy of Prose APP ID-1 contains only one security policy, it can be understood that the security policy can be used by two identities.
[0256] If further expressed as: {security policy of common identity, security policy of non-common identity = (security policy of relay identity of Prose APP ID-1, security policy of remote identity of Prose APP ID-2, default security policy)}, it can be understood as including the security policy of relay identity of Prose APP ID-1, the security policy of remote identity of Prose APP ID-2, and the default security policy of non-common identities other than Prose APP ID-1 and Prose APP ID-2. At this time, if the UE can use the remote identity under Prose APP ID-1, the security policy of the remote identity is the default security policy of the non-common identity. Similarly, if Prose APP ID-2 can use the relay identity, the security policy of its relay identity is the default security policy of the non-common identity.
[0257] 2), or {Prose APP ID-1 = (security policy for common identity, security policy for non-common identity), {Prose APP ID-2 = (security policy for common identity, security policy for non-common identity), default security policy}; In this representation method, Prose APP ID-1 and Prose APP ID-2 represent granular information. This method indicates the security policy for common identity and non-common identity that can be used by Prose APP ID-1, and the security policy for common identity and non-common identity that can be used by Prose APP ID-2. And the default security policy that can be used by any identity of other APPs. For detailed description, please refer to the description in method 1).
[0258] 3) or {Prose APP ID-2 = (security policy for common identity, security policy for non-common identity), default security policy for non-common identity, default security policy for common identity}. This method indicates the common identity security policy and non-common identity security policy that can be used by Prose APP ID-2, as well as the default security policy that can be used by common identity and non-common identity in other Prose APPs. For detailed description, please refer to the description of method 1).
[0259] 4) {Security policy for normal identity, security policy for non-normal identity}: This method specifies the security policy used for the UE's normal identity and the security policy used for the non-normal identity at the UE level. The security policy for the non-normal identity can include at least one of the remote identity's security policy and the relay identity's security policy. Which security policy is carried is determined by the identity indication information carried during the UE request. If both identities are carried, the security policies for both non-normal identities must be carried.
[0260] 5) {Security policy for normal identity, security policy for relay identity}: This representation shows the security policy for the normal identity and the security policy for the relay identity at the UE level. This representation is applicable when all UEs have a remote identity, and the remote identity is a type of normal identity. In other words, the security policy of the normal identity can be reused.
[0261] 6) {Security policy}: This representation method indicates that at the UE granularity, the security policy of the UE's common identity, remote identity, and relay identity use the same security policy.
[0262] The security policy of the non-ordinary identity includes at least one of a security policy of a relay identity and a security policy of a remote identity.
[0263] In the embodiments of the present application, in scenarios where terminal devices communicate via relays, the PCF configures security policies for the terminal devices. For example, the relay's security policy is configured as the PREFERRED security policy, which ensures the establishment of the relay PC5 link. Furthermore, the security policy can include granularity information to ensure the scope of the security policy. It should be noted that the binding relationship between security policy and granularity varies, and the embodiments of the present application only provide some reference examples. The embodiments of the present application do not limit the use of security policy and granularity.
[0264] Part II:
[0265] In conjunction with the first part, the embodiment of this application provides a secure communication method, see Figure 4 , which is the flow chart of this method. In the following introduction, this method is applied to Figure 2A or Figure 2B In addition, the method can be performed by a first communication device, which can be a terminal device, or a communication device that can support the terminal device to implement the functions required by the method, such as a component included in the terminal device, or a chip system in the terminal device.
[0266] For ease of introduction, the cell selection method provided in the embodiment of the present application is described in detail below, taking the method executed by a terminal device as an example.
[0267] Figure 4 A flow chart of a secure communication method provided in an embodiment of the present application, the method may include the following steps.
[0268] Step 401: A first terminal device broadcasts a first direct communication request (DCR) message.
[0269] The first DCR message carries the PC5 control plane security policy of the first terminal device.
[0270] In one possible embodiment, the first DCR message may also carry the first terminal device's secure endpoint policy, which is used to determine whether the secure endpoint is on the relay. For example, if the first DCR message carries a "hop-by-hop" secure endpoint policy, the secure endpoint is on the relay; if the first DCR message carries an "end-to-end" secure endpoint policy, the secure endpoint is not on the relay. Optionally, in one possible embodiment, the first DCR message may also carry a security algorithm policy.
[0271] The PC5 control plane security policy of the first terminal device carried in the first DCR message is the PC5 control plane security policy of the remote identity. When the first terminal only obtains one PC5 control plane security policy from the network side, the PC5 control plane security policy of the first terminal device carried in the first DCR message is based on the remote identity. Figure 3 The embodiment obtains the PC5 control plane security policy from the network side.
[0272] In a possible embodiment, the first DCR message may also carry granular information (such as APP ID) of the PC5 control plane security policy of the first terminal device. The granular information is used for the scope of the PC5 control plane security policy of the first terminal device.
[0273] The first DCR message is a broadcast message and will be received by different relays. The PC5 control plane security policy may include at least one of a common identity PC5 control plane security policy and a non-common identity PC5 control plane security policy.
[0274] In a possible embodiment, the message may further carry a PC5 control plane security algorithm supported by the first terminal device, so that the second terminal device can determine the PC5 control plane security algorithm of the second PC5 link.
[0275] Step 402: After receiving the first DCR message, at least one relay sends a second DCR message to the second terminal device. The second DCR message is generated and sent by at least one relay.
[0276] In one implementation, the second DCR message may be directly the first DCR message, that is, at least one relay directly forwards the first DCR message to the second terminal device.
[0277] In another implementation, the second DCR message may also include information related to the relay and information related to the first terminal device. The information related to the first terminal device comes from the first DCR message. The information related to the first terminal device may be the entire first DCR message or a portion of the first DCR message. The information related to the relay may include the relay's PC5 control plane security policy, the relay's PC5 control plane security algorithm, etc.
[0278] In one possible embodiment, before forwarding the second DCR message to the second terminal device, the relay needs to first determine whether it can serve the first terminal device. It should be noted that this determination process can occur before or after step 401. For example, before the first terminal device sends the second DCR message, the relay can determine whether it can serve the first terminal device through a discovery process. If it can, the relay will receive the first DCR message and generate a second DCR message. If not, the relay will directly reject the first DCR message. For another example, without a discovery process, after receiving the first DCR message, the relay will first determine whether it can serve the first terminal device based on the information in the message. If it can, the relay will receive the first DCR message and generate a second DCR message. If not, the relay will directly reject the first DCR message. For example, this determination can be made based on the application layer ID information carried in the message. This embodiment is not limited to this, and the number of at least one relay can be one or more than two.
[0279] In one possible embodiment, at least one relay determines whether it can support the control plane security policy of the first terminal device. If so, a second DCR message is generated and sent to the second terminal device. If not, there is no need to generate a second DCR message for the first terminal device. Specifically, at least one relay determines whether the relay's PC5 control plane confidentiality protection policy and PC5 control plane integrity protection policy conflict with the first terminal device's PC5 control plane confidentiality security policy. For example, assuming the first terminal device's PC5 control plane security policy is PC5 control plane confidentiality protection is NOT NEEDED and the first terminal device's PC5 control plane integrity protection is REQUIRED, the first terminal device cannot select a relay whose PC5 control plane confidentiality protection is REQUIRED or whose PC5 control plane integrity protection is NOT NEEDED. Here, NOT NEEDED and REQUIRED conflict.
[0280] In one possible embodiment, the relay may also send at least one of the relay's PC5 control plane security policy, security endpoint policy, and security algorithm policy to the second terminal device. It should be noted that the manner in which the relay-related security policies and other information are carried varies depending on the format of the second DCR message. For example, when the second DCR message sent by the relay directly forwards the DCR message sent by the first terminal device, the relay-related security policies may be carried in the DCR message forwarded by the relay to the second terminal device. Alternatively, when the first DCR message or a portion of the first DCR message serves as a container (content), an IE, or several IEs in the second DCR message, the relay-related security policies may be carried in IEs unrelated to the first DCR message. This is not a limitation in this embodiment. It should be noted that the second DCR message may also carry the control plane security algorithms supported by the first terminal device and / or the control plane security algorithms supported by the relay. For specific carrying methods, please refer to the above description of the security policy carrying method.
[0281] Step 403: The second terminal device determines a relay for serving the first terminal from at least one relay.
[0282] It should be noted that in this embodiment, step 403 is optional. In one possible scenario, if only one relay forwards the DCR message to the second terminal device, step 403 may not be performed. In this case, the second terminal device only needs to determine whether the relay supports the service. If so, it determines that the relay is a relay that can serve the first terminal. For example, the second terminal device may make this determination based on whether it is interested in the application information carried in the message.
[0283] In another possible case, when there are more than two relays forwarding the DCR message to the second terminal device, the second terminal device determines the relay serving the first terminal from at least two relays based on at least one of the received PC5 control plane security policy of the first terminal device, the PC5 control plane security policies of at least two relays, the PC5 control plane security policy of the second terminal device, the security endpoint policy of the first terminal device, the security endpoint policy of at least two relays, the security endpoint policy of the second terminal device, the security algorithm policy of the first terminal device, the security algorithm policy of at least two relays, and the security algorithm policy of the second terminal device.
[0284] It should be noted that in one possible implementation, because different relays forward DCR messages to the second terminal device in varying order, the second terminal device can determine, from at least two relays, a relay serving the first terminal based on the order in which forwarded messages are received from different relays. For example, assuming the second terminal device first receives the second DCR message from the first relay, the second terminal device can determine whether the first relay is available for establishing a PC5 link based on at least one of the following: the PC5 control plane security policy of the first terminal device, the PC5 control plane security policy of the first relay, the PC5 control plane security policy of the second terminal device, the security endpoint policy of the first terminal device, the security endpoint policy of the first relay, the security endpoint policy of the second terminal device, the security algorithm policy of the first terminal device, the security algorithm policy of the first relay, and the security algorithm policy of the second terminal device. If so, the first relay is determined to be the target relay and can be used to establish the PC5 link. If not, the above determination is repeated for the remaining relays based on the order in which they were received.
[0285] In another possible implementation, the second terminal device may randomly select a second DCR message sent by a relay for judgment. And so on, until a target relay that meets the conditions is determined. The embodiment of the present application does not limit the specific order of selecting relays for judgment.
[0286] Specifically, the second terminal device may determine the target relay in at least one of the following ways.
[0287] Method 1: The second terminal device determines the target relay based on the security endpoint of the second terminal device.
[0288] For example, if the security endpoint policy pre-configured on the second terminal device or obtained from the network side is hop-by-hop, then the second terminal device can only select a target relay that supports the "hop-by-hop" or PREFERRED security policy from at least two relays. For another example, if the security endpoint policy pre-configured on the second terminal device or obtained from the network side is end-to-end, then the second terminal device can only select a target relay that supports the end-to-end or PREFERRED security policy from at least two relays.
[0289] In the second method, the second terminal device determines the relay according to the PC5 control plane security policy of each terminal device in each combination.
[0290] Here, assuming that there are two relays (a first relay and a second relay) sending a second DCR message to the second terminal device, there are two combinations. The first combination includes the first terminal device, the first relay, and the second terminal device; the second combination includes the first terminal device, the second relay, and the second terminal device.
[0291] Exemplarily, if the PC5 control plane security policy pre-configured by the second terminal device includes a disabled PC5 control plane security policy (meaning that at least one of the control plane confidentiality protection and the control plane integrity protection is NOT NEEDED), then the second terminal device cannot select a relay that conflicts with the PC5 control plane security policy pre-configured by the second terminal device (meaning that at least one of the corresponding control plane confidentiality protection and control plane integrity protection is REQUIRED). For example, assuming that the PC5 control plane security policy of the second terminal device is PC5 control plane confidentiality protection is NOT NEEDED and PC5 control plane integrity protection is REQUIRED, then the second terminal device cannot select a relay that PC5 control plane confidentiality protection is REQUIRED or PC5 control plane integrity protection is NOT NEEDED. Here, NOT NEEDED and REQUIRED are in conflict. Further, optionally, if the second terminal device first determines that the security endpoint is hop-by-hop, then selects the relay according to the above steps. Conversely, if the second terminal device's pre-configured secure endpoint is end-to-end secure, the relay's PC5 control plane security policy does not need to be referenced when selecting the relay. In this case, the control plane security protection method with the first terminal device can be determined according to section 5.3.3.1.4.3 of 3GPP standard TS 33.536.
[0292] Mode three: The second terminal device determines the relay according to the PC5 control plane security policy of each device in each combination, the PC5 user plane security policy of the second terminal device, and the PC5 user plane security policy of the second terminal device.
[0293] In other words, if the user plane security protection cannot be higher than the control plane security protection, in order to ensure the establishment of the PC5 connection, the second terminal device can refer to the PC5 user plane security policy of the second terminal device when selecting the relay. Among them, the specific meaning of user plane security protection cannot be higher than control plane security protection includes the following aspects: 1) If the control plane confidentiality protection is activated, then the user plane confidentiality protection can be activated or not. 2) If the control plane integrity protection is activated, then the user plane integrity protection can be activated or not. 3) If the control plane confidentiality protection is not activated, then the user plane confidentiality protection is not activated. 4) If the control plane integrity protection is not activated, then the user plane integrity protection is not activated.
[0294] Specifically, Principle 1: If the PC5 user plane security policy of the second terminal device has a "REQUIRED" status, then the PC5 control plane security policy of the relay selected by the corresponding second terminal device should also be in the "REQUIRED" status. For example, if the user plane confidentiality protection and / or user plane integrity protection of the PC5 of the second terminal device is in the "REQUIRED" status, then the second terminal device can only select a relay whose control plane confidentiality protection and / or control plane integrity protection of the PC5 is "REQUIRED". Principle 2: If the PC5 user plane security of the second terminal device has a "NOT NEEDED" status, then the PC5 control plane security policy of the relay selected by the corresponding second terminal device cannot be "REQUIRED". For example. If the user plane confidentiality protection and / or user plane integrity protection of the PC5 is in the "NOT NEEDED" status, then the second terminal device can only select a relay whose control plane confidentiality protection and / or control plane integrity protection of the PC5 is not "REQUIRED".
[0295] Method 4: The second terminal device determines the relay according to the security algorithm policy of the relay and the security algorithm policy of the second terminal device.
[0296] Specifically, according to principle one, when the second terminal device only supports the 128-bit algorithm, the second terminal device cannot select a relay that only supports the 256-bit algorithm; according to principle two, when the second terminal device only supports the 256-bit algorithm, the second terminal device cannot select a relay that only supports the 128-bit algorithm.
[0297] It should be noted that the embodiment of the present application does not limit the execution order of the three policies, namely the PC5 user plane security policy, the PC5 control plane security policy and the security endpoint policy. At the same time, because some security policies are optional, they can be not executed. The embodiment of the present application does not limit the combination and use method of the three security policies.
[0298] It should be noted that if the secure endpoint policy is specified by the standard, that is, the standard stipulates that only hop-by-hop or end-to-end can be used, then the secure endpoint policy is not required, and when executing other steps, the relevant regulations must be followed by default.
[0299] Assuming that the first DCR message sent by the first terminal device includes a security endpoint policy of the first terminal device as a "hop-by-hop" security policy, and the target relay is the first relay, the following description assumes that the security endpoint is located on the target relay.
[0300] Step 404: After the second terminal device determines the first relay, it initiates an authentication process with the first relay.
[0301] It should be noted that, in this embodiment, step 404 is an optional step of this embodiment.
[0302] The purpose of this authentication process is to establish mutual trust between the second terminal device and the first relay, and to generate a root key for protecting the control plane and user plane keys. For a detailed description, please refer to section 5.3.3.1.4.3 of standard TS33.536.
[0303] Exemplarily, the second terminal device sends a direct communication key authentication (Direct Auth and Key Establishment) message to the first relay, triggering an authentication process between the second terminal device and the first relay.
[0304] Optionally, the first relay can determine that the Direct Auth and Key Establishment message is sent to itself, and upon receiving the message, the first relay will initiate an authentication and key generation process with the second terminal device. Specifically, the first relay can determine this in at least two ways. One way is: the Direct Auth and Key Establishment message includes indication information, or the indication information is sent to the second terminal device along with the Direct Auth and Key Establishment message (in this case, it can be understood that the indication information is outside the Direct Auth and Key Establishment message). This indication information is used to indicate whether authentication and key distribution are performed between the second terminal device and the first relay. For example, a bit is used to indicate whether the message is sent to the first relay or the first terminal device. Specifically, when the bit indication information is "0", it indicates that it is sent to the first relay, and when it is "1", it indicates that it is sent to the first terminal device. Another way is: the first relay determines whether authentication and key distribution are performed between the second terminal device and the first relay based on the format of the Direct Auth and Key Establishment message. For example, if a Direct Auth and Key Establishment message is sent to the first relay as part of a container, the first relay will forward the Direct Auth and Key Establishment message within the container to the first terminal device. At this point, the first relay may not be aware of the contents of the container, specifically, that it is a Direct Auth and Key Establishment message. In other words, the first relay simply forwards the message based on the container. For another example, if a Direct Auth and Key Establishment message is sent directly to the first relay, the first relay will automatically determine that the message is intended for it, not the first terminal device.
[0305] It should be noted that: if the security endpoint policy is specified by the standard, that is, the standard stipulates that only hop-by-hop or end-to-end can be used, then the first relay does not need to determine whether the Direct Auth and Key Establishment message is sent to itself or to the first terminal device. That is, in the case where the standard stipulates hop-by-hop, the first relay will know that the Direct Auth and Key Establishment message is sent to itself, and in the end-to-end case, the first relay will know that the Direct Auth and Key Establishment message is sent to the first terminal device. The method of knowing is not limited. The embodiments of the present application are not limited. It should be noted that when the PC5 control plane security policy of the second terminal device is in the "NOT NEEDED" state, and when the PC5 control plane security policy of the first relay, the PC5 control plane security policy of the first terminal device, and the PC5 control plane security policy of the second terminal device conflict, the above step 404 will not be initiated, and the second terminal device will reply with a failure message to at least one relay to reject the establishment of the DCR process.
[0306] Step 405 : The second terminal device determines a PC5 control plane security protection method for the second PC5 link, and selects a PC5 control plane security algorithm for the second PC5 link.
[0307] This step may occur after step 403 and before step 404 .
[0308] Specifically, the second terminal device may determine the PC5 control plane security protection method of the second PC5 link in at least one of the following ways:
[0309] Method 1: The second terminal device determines the PC5 control plane security protection method of the second PC5 link based on the PC5 control plane security policy of the first relay and the PC5 control plane security policy of the second terminal device. For the specific determination method, please refer to the description in section 5.3.3.1.4.3 of standard TS33.536.
[0310] Exemplarily, the PC5 control plane integrity protection of the first relay is optional, the PC5 control plane confidentiality protection of the first relay is turned on, the PC5 control plane integrity protection of the second terminal device is turned on, and the PC5 control plane confidentiality protection of the second terminal device is turned on. Then the second terminal device determines that the PC5 control plane integrity protection of the second PC5 link is turned on, and the PC5 control plane confidentiality protection of the second PC5 link is turned on.
[0311] In the second approach, the second terminal device determines the PC5 control plane security protection method for the second PC5 link based on the PC5 control plane security policy of the first relay and the second terminal device, in addition to the PC5 control plane security policy of the first terminal device. In this way, the PC5 control plane security protection method between the first relay and the second terminal device can be the same as the PC5 control plane security protection method between the first relay and the first terminal device.
[0312] Specifically, when one of the control plane integrity protections is REQUIRED, the control plane integrity protection is determined to need to be activated. When one of the control plane confidentiality protections is REQUIRED, the control plane confidentiality protection is determined to need to be activated. When one of the control plane integrity protections is NOT NEEDED, the control plane integrity protection is determined to not need to be activated. When one of the control plane confidentiality protections is NOT NEEDED, the control plane confidentiality protection is determined to not need to be activated. When all of the control plane integrity protections are PREFERRED, the control plane integrity protection is determined to be either activated or not activated. When one of the control plane confidentiality protections is PREFERRED, the control plane confidentiality protection is determined to be either activated or not activated.
[0313] Method three: the second terminal device determines the PC5 control plane security protection method based on the PC5 control plane security policy of the first relay and the PC5 control plane security policy of the second terminal device, and can also combine the PC5 user plane security policy of the second terminal device.
[0314] For example, if the second terminal device determines that the PC5 user plane security policy of the second terminal device has a "REQUIRED" status, and at the same time, the PC5 control plane security policy of the first relay can support REQUIRED (such as PREFEER or REQUIRED), and the PC5 control plane security policy of the second terminal device can support REQUIRED (such as PREFEER or REQUIRED), then the PC5 control plane security policy of the second PC5 link is determined to be in the enabled state. Specifically, if the PC5 user plane integrity protection set by the second terminal is REQUIRED, the second terminal device determines the control plane integrity protection to be enabled. If the user plane integrity protection set by the second terminal is PREFERRED, the method for determining the control plane integrity protection also needs to refer to the user plane confidentiality protection of the second terminal device. That is, if the user plane confidentiality protection of the second terminal device is REQUIRED at this time, the first control plane integrity protection method is determined to be enabled, and the control plane confidentiality protection is REQUIRED; if the user plane confidentiality protection of the second terminal device is PREFERRED or NOT NEEDED at this time, the second terminal device can determine the control plane integrity protection to be enabled or disabled, and the control plane confidentiality protection can be determined to be enabled or disabled. If the user plane integrity protection set by the second terminal is NOT NEEDED, the method for determining the control plane integrity protection also needs to refer to the user plane confidentiality protection of the second terminal device. That is, if the user plane confidentiality protection of the second terminal device is REQUIRED at this time, the connection establishment is rejected; if the user plane confidentiality protection of the second terminal device is PREFERRED or NOTE NEEDED at this time, the second terminal device can determine the control plane integrity protection to be enabled or disabled, and determine the control plane confidentiality protection to be enabled or disabled.
[0315] After determining whether to activate the PC5 control plane security protection method for the second PC5 link, the second terminal device can select a security algorithm for the PC5 control plane. The security algorithm includes a confidentiality protection algorithm and / or an integrity protection algorithm. If it is determined that the PC5 control plane integrity protection of the second PC5 link needs to be activated, it is necessary to select a non-empty PC5 control plane integrity security algorithm; if it is determined that the PC5 control plane integrity protection of the second PC5 link is activated and it is determined that the PC5 control plane confidentiality protection of the second PC5 link needs to be activated, it is necessary to select a non-empty PC5 control plane confidentiality protection algorithm and a non-empty PC5 control plane integrity protection algorithm; if it is determined that the PC5 control plane integrity protection of the second PC5 link is not activated, it is not necessary to select a PC5 control plane integrity wave protection algorithm. Optionally, if there is a security algorithm policy, the second terminal device selects a 128-bit algorithm or a 256-bit algorithm according to the security algorithm policy. For the specific selection method, please refer to the description in section 5.3.3.1.4.3 of standard TS33.536.
[0316] Step 406: The second terminal device sends the PC5 control plane security algorithm of the second PC5 link to the first relay.
[0317] Before executing step 406, the second terminal device activates the security protection method determined in step 405. Specifically, if PC5 control plane integrity protection is enabled, the PC5 control plane integrity protection algorithm and PC5 control plane integrity protection key are used to perform integrity protection on the message in step 406. If PC5 control plane confidentiality protection is determined to be enabled, the selected PC5 control plane confidentiality protection algorithm and PC5 control plane confidentiality key are used to prepare to deconfidentialize the received message. Among them, the PC5 control plane algorithm and PC5 control plane key can refer to the relevant control plane algorithm and control plane key mentioned in section 5.3.3.1.4.3 of standard TS 33.536.
[0318] The method for determining the PC5 control plane security algorithm is: the second terminal device stores a control plane integrity protection algorithm priority list, and the second terminal device can select a control plane security algorithm with the highest priority and supported by the first terminal device and / or the first relay carried in step 402. For example, if the first terminal device supports NIA0 (Next Generation Integrity Algorithm, next generation integrity protection algorithm), NIA1, NIA2, NIA3, and the first relay supports NIA0, NIA2, NIA3, the priority list of the second terminal device is NIA1, NIA3, NIA2. When only the first terminal device and the second terminal device are considered, the selected control plane integrity protection algorithm is NIA1. When only the first relay and the second terminal device are considered, the selected control plane integrity protection algorithm is NIA3. When the first relay, the first terminal device, and the second terminal device are considered, the selected control plane integrity protection algorithm is NIA2. For another example, if the first terminal device supports NEA0 (Next Generation Encryption Algorithm), NEA1, NEA2, and NEA3, and the first relay supports NEA0, NEA2, and NEA3, the priority list for the second terminal device is NEA1, NEA3, and NEA2. When only the first terminal device and the second terminal device are considered, the selected control plane integrity protection algorithm is NEA1. When only the first relay and the second terminal device are considered, the selected control plane integrity protection algorithm is NEA3. When the first relay, the first terminal device, and the second terminal device are considered, the selected control plane integrity protection algorithm is NEA2.
[0319] For example, the second terminal device sends a direct security mode command (DSMC) message to the first relay, which carries the control plane security algorithm of the second PC5 link determined by the second terminal device. For specific carrying methods, please refer to the description of section 5.3.3.1.4.3 of standard TS33.536.
[0320] In step 407, the first relay activates control plane security for the second PC5 link based on the received control plane security algorithm for the second PC5 link. Specifically, the first relay activates control plane security for the second PC5 link based on the PC5 control plane algorithm carried in step 406. For specific activation methods, refer to section 5.3.3.1.4.3 of TS 33.536.
[0321] For example, if the control plane security algorithm for the second PC5 link includes a non-null integrity protection algorithm and a null confidentiality protection algorithm, the first relay enables control plane integrity protection for the second PC5 link and disables control plane confidentiality protection for the second PC5 link. For specific activation methods, refer to section 5.3.3.1.4.3 of TS 33.536.
[0322] In step 408, the first relay performs an authentication process with the first terminal device. For example, the first relay sends a Direct Auth and Key Establishment message to the first terminal device to initiate the authentication and key generation process. For details, please refer to the description in step 404 and will not be repeated here.
[0323] In one possible embodiment, optionally, before step 408, the first relay needs to determine whether the control plane security policy of the first terminal device can be conflicted by the first relay. If it is not conflicting, the first relay performs the following steps. Otherwise, the connection is released. If the first relay has already made this determination in step 402, this determination process does not need to be repeated.
[0324] Step 409 : The first relay determines a PC5 control plane security algorithm for the first PC5 link, and activates control plane security for the first PC5 link.
[0325] The first PC5 link refers to a PC5 link between the first terminal device and the first relay.
[0326] In one possible embodiment, the first relay may use the control plane security protection method between the first relay and the second terminal device as the PC5 control plane security protection method for the first PC5 link. Specifically, the first relay may use the decision result of step 407 on the first PC5 link.
[0327] In another possible embodiment, the first relay can determine the control plane security protection method between the first terminal device and the first relay as the PC5 control plane security protection method for the first PC5 link. This security protection method may be the same as or different from the control plane security protection method between the first relay and the second terminal device. In other words, the first link and the second link are independent of each other.
[0328] Further, optionally, before determining whether to activate the control plane security protection method of the first PC5 link, the first relay verifies whether the control plane security protection method conflicts with the PC5 control plane security policy of the first terminal device. If so, the connection is released; if not, the control plane security protection method between the first relay and the second terminal device is determined as the PC5 control plane security protection method of the first PC5 link.
[0329] After the PC5 control plane security protection method is determined, the first relay further selects the PC5 control plane security algorithm of the first PC5 link and activates the control plane security of the first PC5 link. In the first method, the first relay can determine whether the control plane security algorithm selected by the second terminal device can be used directly. If it can be used directly, the second terminal device will be used as the PC5 control plane security algorithm of the first PC5 link. If not, the algorithm selection will be performed again. The further determination method mainly depends on whether the algorithm selected by the second terminal device is the one with the highest priority supported by the first relay. If so, it is determined that it can be used. If not, the first relay will select the security algorithm (a confidentiality protection algorithm and / or an integrity protection algorithm) supported by UE-1 and with the highest priority of the first relay. In the second method, the first relay determines the security algorithm of the first PC5 link as described in step 406.
[0330] Step 410: The first relay sends the control plane security algorithm of the first PC5 link to the first terminal device.
[0331] Before step 410 , the first relay activates control plane security protection between the first terminal device and the first relay. For details on the activation method, refer to step 406 .
[0332] Exemplarily, the first relay sends a Direct Security Mode Command message to the first terminal device, where the message carries the control plane security algorithm of the first PC5 link.
[0333] Step 411: The first terminal device activates PC5 control plane security of the first PC5 link according to the received control plane security algorithm.
[0334] In the embodiment of the present application, steps 401 to 411 are the process of determining the control plane security protection method for the PC5 link between terminal devices. This method ensures consistency in control plane security between the first and second PC5 links, and enables coordinated processing of control plane security protection on both sides of the relay. This method enables the links on both sides of the relay to either activate the control plane integrity protection method or not, and / or enables the links on both sides of the relay to either activate the control plane confidentiality protection method or not, thereby maintaining consistency in security protection processing between the links on both sides of the relay. This avoids the problem of control plane security protection failure on the first PC5 link due to a higher priority for the control plane security protection used by the second PC5 link, or avoids the problem of control plane security protection failure on the second PC5 link due to a higher priority for the control plane security protection used by the first PC5 link.
[0335] The following steps 412 to 419 are a process for determining a user plane security protection method for a PC5 link between terminal devices.
[0336] Step 412: The first terminal device sends a DSMP message of the first PC5 link to the first relay.
[0337] Exemplarily, the first terminal device replies with a direct security mode command (DSMC) message to the first relay. The DSMC message is used to respond to the Direct Security Mode Command message, and the message may carry the PC5 user plane security policy of the first terminal device.
[0338] Step 413: The first relay sends a DSMP message of the second PC5 link to the second terminal device.
[0339] Optionally, the DSMP message of the second PC5 link may further carry the PC5 user plane security policy of the first relay, or the first relay may further send the PC5 user plane security policy of the first relay to the second terminal device. In other words, the DSMP message of the second PC5 link carries both the PC5 user plane security policy of the first terminal and the PC5 user plane security policy of the first relay.
[0340] The second PC5 link DSMP message may also be a new DSMP message sent by the first relay, and the new DSMP message carries the PC5 user plane security policy of the first relay.
[0341] It should be noted that one possible implementation method is: the first relay replaces the PC5 user plane security policy of the first terminal device in the DSMP message of the first PC5 link with the PC5 user plane security policy of the first relay.
[0342] In step 414 , the second terminal device determines a PC5 user plane security protection method for the second PC5 link and determines a PC5 user plane security algorithm for the second PC5 link according to the PC5 user plane security policy from the first relay and the PC5 user plane security policy of the second terminal device.
[0343] Specifically, the second terminal device may determine whether to activate the PC5 user plane security protection method of the second PC5 link in at least one of the following ways:
[0344] In mode A, the second terminal device determines whether to activate the PC5 user plane security protection method for the second PC5 link based on the PC5 user plane security policy of the first relay and the PC5 user plane security policy of the second terminal device. For specific implementation methods, please refer to the description in section 5.3.3.1.4.2 of standard TS33.536.
[0345] In mode B, in addition to determining whether to activate the PC5 user plane security protection method of the second PC5 link based on the PC5 user plane security policy of the first relay and the PC5 user plane security policy of the second terminal device, the second terminal device also determines based on the PC5 user plane security policy of the first terminal device. In this way, the PC5 user plane security protection method between the first relay and the second terminal device is the same as the PC5 user plane security protection method between the first relay and the first terminal device. Specifically, if any two user plane confidentiality protection policies and / or user plane integrity protection policies conflict (one is NOT NEEDED and the other is REQUIRED), the connection needs to be rejected. For example, assuming that the user plane confidentiality policy of the first terminal device is NOT NEEDED, but the user plane confidentiality protection policy of the second terminal device is REQUIRED, the second terminal device releases the connection. When there is no conflict between any two user plane confidentiality protection policies and / or user plane integrity protection policies, if one is REQUIRED, the security corresponding to REQUIRED is enabled. For example, if the user plane confidentiality policy of the first terminal device is REQUIRED, or the user plane confidentiality protection policy of the second terminal device is REQUIRED, the second terminal device enables user plane confidentiality protection. If the user plane confidentiality protection policy of the first terminal device, the user plane confidentiality protection policy of the second terminal device, and the user plane security policy of the first relay are all PREFERRED, the second terminal device can decide to enable user plane confidentiality protection, or decide not to enable user plane confidentiality protection. When there is no conflict between any two user plane confidentiality protection policies and / or user plane integrity protection policies, if there is NOT NEEDED, the corresponding security is not enabled. For example, if the user plane confidentiality policy of the first terminal device is NOT NEEDED, or the user plane confidentiality protection policy of the second terminal device is NOT NEEDED, the second terminal device does not enable user plane confidentiality protection. Furthermore, after activating the control plane security of the second PC5 link, optionally, the user plane security enabling method should refer to the activated second PC5 link control plane security protection method. Specifically, if control plane confidentiality protection is enabled, user plane confidentiality protection may or may not be enabled. If control plane confidentiality protection is disabled, user plane confidentiality protection is disabled. If control plane integrity protection is enabled, user plane integrity protection may or may not be enabled. If control plane integrity protection is disabled, user plane integrity protection is disabled.
[0346] After determining the PC5 user plane security protection method for the second PC5 link, the second terminal device can determine the PC5 user plane security algorithm. One possible implementation is to reuse the selected PC5 control plane security algorithm as the PC5 user plane security algorithm. Another implementation is to reselect the PC5 user plane security algorithm. This security algorithm may include a confidentiality protection algorithm and / or an integrity protection algorithm. Optionally, if a security algorithm policy is in place, the second terminal device may select a 128-bit algorithm or a 256-bit algorithm based on the security algorithm policy.
[0347] Step 415: The second terminal device sends the first information to the first relay.
[0348] The first information is used to indicate a user plane security protection method for the second PC5 link. Exemplarily, the first information is a user plane security activation indication for the second PC5 link.
[0349] Specifically, the second terminal device sends a direct communication accept message to the first relay. The message carries a user plane security activation indication of the second PC5 link. The definition of the user plane security activation indication can be referred to the description in section 5.3.3.1.4.2 of standard TS33.536.
[0350] Exemplarily, if the user plane security protection method of the second PC5 link determined by the second terminal device is that the user plane confidentiality protection of the second PC5 link is not enabled, and the user plane integrity protection of the second PC5 link is enabled, then the user plane security activation indication is used to indicate the activation of the user plane integrity protection of the second PC5 link and the deactivation of the user plane confidentiality protection of the second PC5 link.
[0351] Step 416: The first relay activates user plane security protection of the second PC5 link according to the first information.
[0352] Continuing with the above example, after the first relay receives the user plane security activation indication, it activates the user plane integrity protection of the second PC5 link according to the username security activation indication, and does not activate the user plane confidentiality protection of the second PC5 link.
[0353] Step 417: The first relay sends the second information to the first terminal device.
[0354] Exemplarily, the second information is used to indicate a user plane security protection method of the first PC5 link.
[0355] In one possible case, the second information is the first information, that is, the first relay forwards the first information to the first terminal device.
[0356] In another possible case, the first relay determines the PC5 user plane security protection method of the first PC5 link according to the user plane security protection method of the second PC5 link, and generates second information, where the second information is the same as the first information.
[0357] Continuing with the above example, the first relay determines that the PC5 user plane security protection method for the first PC5 link is also to enable user plane integrity protection but not to enable user plane confidentiality protection.
[0358] Step 418: The first terminal device activates user plane security of the first PC5 link according to the second information.
[0359] Continuing with the above example, if the user plane security activation indication of the first PC5 link indicates that the user plane integrity protection of the first PC5 link is enabled, the first terminal device activates the user plane integrity protection of the first PC5 link, and the user plane confidentiality protection of the first PC5 link is not enabled.
[0360] It should be noted that the control plane security protection determination process shown in steps 401 to 411 and the user plane security protection determination process shown in steps 412 to 419 can be decoupled, that is, they can be executed separately.
[0361] When the above two processes are executed separately, it is possible that the first relay does not follow the PC5 control plane security protection method of the first PC5 link determined by the second terminal device when activating the PC5 control plane security protection method of the first PC5 link. At this time, the first relay needs to determine whether it can support the user plane security protection method of the second PC5 link determined by the second terminal device before determining the user plane security protection method of the first PC5 link. If it cannot be supported, the requirement for consistency of the user plane security protection method is not met, then the first relay needs to release the connection, and the direct communication link fails to be established.
[0362] Figure 5 A flowchart of a secure communication method provided in an embodiment of the present application is provided. The method is still executed by the first communication device and may include the following steps.
[0363] Step 501: A first terminal device broadcasts a first direct communication request (DCR) message.
[0364] For details, please refer to the above step 401.
[0365] Step 502: After receiving the first DCR message, at least one relay sends a second DCR message to the second terminal device.
[0366] For details, please refer to the above step 402.
[0367] Step 503: The second terminal device determines a first relay for establishing a second PC5 link from at least one relay.
[0368] For details, please refer to the above step 403.
[0369] In an embodiment of the present application, the first DCR message includes that the security endpoint policy of the first terminal device is "end-to-end" security. In the following of this embodiment, the discussion is based on the second terminal device determining that the security endpoint is located in the first terminal device.
[0370] Step 504a: After the second terminal device determines the first relay, it initiates an authentication process with the first relay.
[0371] In this step, the message sent by the second terminal includes indication information, and the indication information is used to indicate that authentication and key distribution are performed between the second terminal device and the first terminal device. For details, please refer to the above step 404.
[0372] Step 504b: The first relay initiates an authentication process to the first terminal device.
[0373] In this embodiment, after the first terminal device and the first relay determine that the security endpoint policy used by the second terminal device is End-to-End security, in the subsequent steps, after the first relay receives the message from the second terminal device, it no longer parses it, but sends it directly to the first terminal device. The advantage of this is that it can reduce communication delay.
[0374] The method for the first relay to identify the End-to-End may refer to the relevant description of step 404 .
[0375] Step 505 : The second terminal device determines a PC5 control plane security protection method for the PC5 link between the first terminal device and the second terminal device, and selects a PC5 control plane security algorithm for the PC5 link between the first terminal device and the second terminal device.
[0376] Specifically, the second terminal device determines a PC5 control plane security protection method for the PC5 link between the first terminal device and the second terminal device based on the control plane security policy of the first terminal device and the control plane security policy of the second terminal device. For example, if the PC5 control plane integrity protection for the first terminal device is REQUIRED, the PC5 control plane confidentiality protection for the first terminal device is REQUIRED, the PC5 control plane integrity protection for the second terminal device is REQUIRED, and the PC5 control plane confidentiality protection for the second terminal device is NOT NEEDED, then the second terminal device determines to enable PC5 control plane security integrity protection for the PC5 link between the first terminal device and the second terminal device, and not enable PC5 control plane security confidentiality protection for the PC5 link between the first terminal device and the second terminal device.
[0377] In a possible embodiment, the second terminal device can also determine the PC5 control plane security algorithm of the PC5 link between the first terminal device and the first terminal device based on the user plane security policy of the first terminal device and the user plane security policy of the second terminal device, as well as the control plane security algorithm of the first terminal device and the control plane security algorithm of the second terminal device.
[0378] Step 506: The second terminal device sends the selected PC5 control plane security algorithm to the first terminal device.
[0379] The PC5 control plane security algorithm is used by the first terminal device and the second terminal device to protect a PC5 link between the first terminal device and the second terminal device.
[0380] Exemplarily, the second terminal device sends a direct security mode command (DSMC) message to the first terminal device, where the message carries a control plane security algorithm for the second PC5 link determined by the second terminal device.
[0381] Step 507: The first terminal device activates PC5 control plane security of the PC5 link between the first terminal device and the second terminal device according to the received control plane security algorithm of the PC5 link.
[0382] In an embodiment of the present application, the above steps 501 to 508 are the process of determining the control plane security protection method of the PC5 link between terminal devices. According to the above method, the control plane security protection method of the PC5 link between the first terminal device and the second terminal device can be determined, which can achieve consistency in the processing method of the control plane security protection of each device.
[0383] The following steps 508 to 511 are a process for determining a user plane security protection method for a PC5 link between terminal devices.
[0384] Step 508: The first terminal device sends a first DSMP message to the second terminal device.
[0385] Exemplarily, the first terminal device sends a first direct security mode complete (DSMP) message to the second terminal device. The first DSMP message is used to respond to the Direct Security Mode Command message. The message may carry the PC5 user plane security policy of the first terminal device.
[0386] For details, please refer to the above step 412.
[0387] Step 509 : The second terminal device determines a PC5 user plane security protection method for the PC5 link between the first terminal device and the second terminal device based on the PC5 user plane security policy from the first terminal device and the PC5 user plane security policy of the second terminal device.
[0388] Specifically, the second terminal device determines a PC5 user plane security protection method for the PC5 link between the first terminal device and the second terminal device based on the user plane security policy of the first terminal device and the user plane security policy of the second terminal device. For example, if the PC5 user plane integrity protection of the first terminal device is REQUIRED, the PC5 user plane confidentiality protection of the first terminal device is REQUIRED, the PC5 user plane integrity protection of the second terminal device is REQUIRED-, and the PC5 user plane confidentiality protection of the second terminal device is NOT NEEDED, then the second terminal device determines to enable PC5 user plane security integrity protection for the PC5 link between the first terminal device and the second terminal device, and not enable PC5 user plane security confidentiality protection for the PC5 link between the first terminal device and the second terminal device.
[0389] After determining the PC5 user plane security protection method for the second PC5 link, the second terminal device may select a security algorithm for the PC5 user plane. This security algorithm may include a confidentiality protection algorithm and / or an integrity protection algorithm. Optionally, if a security algorithm policy exists, the second terminal device may select a 128-bit algorithm or a 256-bit algorithm based on the security algorithm policy.
[0390] Step 510: The second terminal device sends third information to the first terminal device.
[0391] Exemplarily, the third information includes user plane security activation indication information of the PC5 link between the first terminal device and the second terminal device. The user plane security activation indication information is used to indicate a user plane security protection method of the PC5 link between the first terminal device and the second terminal device.
[0392] Exemplarily, the second terminal device sends a direct communication accept message to the first terminal device, where the message carries the user plane security activation indication.
[0393] In step 511 , the first terminal device determines a user plane security protection method for a PC5 link between the first terminal device and a second terminal device, and activates user plane security for the PC5 link between the first terminal device and the second terminal device.
[0394] In an embodiment of the present application, the above steps 509 to 512 are the process of determining the user plane security protection method of the PC5 link between terminal devices. According to the above method, the user plane security protection method of the PC5 link between the first terminal device and the second terminal device can be determined, which can achieve consistency in the processing method of user plane security protection of each device.
[0395] Figure 6 A flow chart of a secure communication method provided in an embodiment of the present application is provided, and the method may include the following steps.
[0396] Step 601: The first terminal device broadcasts a direct communication request (DCR).
[0397] For details, please refer to the above step 401.
[0398] It should be noted that this embodiment adopts hop-by-hop security, so the location of the security endpoint is located at the relay. This embodiment is discussed below based on the situation where the security endpoint is located at the relay.
[0399] In step 602a, each relay receiving the DCR message determines a PC5 control plane security protection method for the first PC5 link according to the PC5 control plane security policy of the first terminal device and the PC5 control plane security policy of the relay itself.
[0400] Specifically, if the PC5 control plane integrity protection of the first terminal device and the relay is REQUIRED, it is determined that the PC5 control plane integrity protection is enabled. If the PC5 control plane integrity protection of the first terminal device and the relay is NOT NEEDED, it is determined that the PC5 control integrity protection is not enabled. If the PC5 control plane confidentiality protection of the first terminal device and the relay is REQUIRED, it is determined that the PC5 control plane confidentiality protection is enabled. If the PC5 control plane confidentiality protection of the first terminal device and the relay is NOT NEEDED, it is determined that the PC5 control plane confidentiality protection is not enabled. If the PC5 control plane integrity protection of the first terminal device and the relay is both PREFERRED, it is determined that the PC5 control plane integrity protection is enabled, or it is determined that the control plane integrity protection is not enabled. If the PC5 control plane confidentiality protection of the first terminal device and the relay is both PREFERRED, it is determined that the PC5 control plane confidentiality protection is enabled, or it is determined that the control plane confidentiality protection is not enabled.
[0401] For specific methods, please refer to the description of standard TS33.5365.3.3.1.4.3.
[0402] Specifically, each relay may determine the security protection method of the first PC5 link PC5 control plane according to the above step 406 .
[0403] Step 602b: Each relay that receives the first DCR message sends a second DCR message to the second terminal device, wherein the second DCR message includes the first PC5 link PC5 control plane security protection method determined by itself.
[0404] In one possible embodiment, the PC5 control plane security protection method for the first PC5 link determined by each relay can be formatted as a security policy. Each relay can then use the PC5 control plane security protection method determined by itself for the first PC5 link to replace the PC5 control plane security policy of the first terminal device in the DCR message. Specifically, if control plane integrity protection is determined to be enabled, the PC5 control plane security policy with control plane integrity protection set to REQUIRED is transmitted; if control plane integrity protection is not enabled, the PC5 control plane security policy with control plane integrity protection set to NOT NEEDED is transmitted. If control plane confidentiality protection is determined to be enabled, the PC5 control plane security policy with control plane confidentiality protection set to REQUIRED is transmitted; if control plane confidentiality protection is not enabled, the PC5 control plane security policy with control plane confidentiality protection set to NOT NEEDED is transmitted. For example, the first terminal device carries in the first DCR message the "PREFERRED" state for PC5 control plane confidentiality protection and the "PREFERRED" state for PC5 control plane integrity protection. The first relay determines, based on the PC5 control plane security policy of the first relay and the PC5 control plane security policy of the first terminal device, that the control plane integrity protection of the second PC5 link is in the "REQUIRED" state and the control plane confidentiality protection is in the "REQUIRED" state. The first relay can then replace the PC5 control plane security policy of the first terminal device in the second DCR message with the control plane confidentiality protection in the "REQUIRED" state and the control plane integrity protection in the "REQUIRED" state.
[0405] In another possible embodiment, the DCR message sent by each relay also includes an indication message, where the indication information is used to indicate that the location of the security endpoint is located in the relay.
[0406] In one possible embodiment, the PC5 control plane security protection method for the first PC5 link determined by each relay itself can be assigned an indication information format or a string format. For example, "00" indicates that control plane confidentiality protection is disabled and control plane integrity protection is disabled, "01" indicates that control plane confidentiality protection is disabled and control plane integrity protection is enabled; or "enabled, enabled" indication information can be used. For example, transmitting "enabled, disabled" means that control plane integrity protection is enabled and control plane confidentiality protection is disabled. The second terminal device can then determine the PC5 control plane security policy selected by the relay or that the second terminal device itself can use based on the received DCR message.
[0407] In an optional manner, the second DCR message may carry at least one PC5 security algorithm policy as in step 402 while carrying the PC5 control plane security protection method of the first PC5 link determined by the second DCR message.
[0408] Step 603: The second terminal device selects a relay serving the first terminal from at least one relay.
[0409] It should be noted that in this embodiment, step 403 is optional. In one possible scenario, if only one relay forwards the DCR message to the second terminal device, step 403 may not be performed. In this case, the second terminal device only needs to determine whether the relay supports the service. If so, it determines that the relay is the relay serving the first terminal. For example, the second terminal device may make this determination based on whether it is interested in the application information carried in the message.
[0410] In another possible case, when there are more than two relays sending the second DCR message to the second terminal device, the second terminal device determines which relay the second terminal device supports based on the received PC5 control plane security protection method of the first PC5 link. The second terminal device selects one relay as the target relay, for example, selects the first relay as the target relay.
[0411] Among them, steps 604 to 611 are the same as steps 404 to 411 above, and will not be repeated here.
[0412] It should be noted that in step 605, the second terminal device determines the PC5 control plane security protection method for the second PC5 link based on the PC5 control plane security protection method for the first PC5 link determined by the relay itself in step 602b and the PC5 control plane security protection policy of the second terminal device. Specifically, if the information is transmitted in the form of a security policy, the second terminal device determines the PC5 control plane security protection method for the second PC5 link based on the security policy carried in the second DCR message. If the information is transmitted in the form of an indication, the second terminal device determines the PC5 control plane security policy for the second PC5 link based on the indication.
[0413] After the second terminal device determines the security policy of the second PC5 link, before sending step 606, the PC5 control plane security of the second PC5 link is activated.
[0414] In the embodiment of the present application, steps 601 to 611 are the process of determining the control plane security protection method for the PC5 link between terminal devices. This method ensures consistency in control plane security between the first and second PC5 links, enables coordinated processing of control plane security protection on both sides of the relay, and enables either both or both of the links on both sides of the relay to activate the control plane integrity protection method, and / or enables either both or both of the links on both sides of the relay to activate the control plane confidentiality protection method, thereby maintaining consistency in security protection processing between the links on both sides of the relay. This avoids the problem of control plane security protection failure on the first PC5 link due to a higher priority for the control plane security protection used by the second PC5 link, or avoids the problem of control plane security protection failure on the second PC5 link due to a higher priority for the control plane security protection used by the first PC5 link.
[0415] The following steps 612 to 618 are a process for determining the user plane security of the PC5 link between terminal devices.
[0416] Step 612: The first terminal device sends a DSMP message of the first PC5 link to the first relay.
[0417] Exemplarily, the first terminal device replies with a direct security mode complete (DSMP) message to the first relay. The DSMP message is used to respond to the Direct Security Mode Command message. The message may carry the PC5 user plane security policy of the first terminal device.
[0418] Step 613: The first relay determines a PC5 user plane security protection method for the first PC5 link according to the PC5 user plane security policy of the first terminal device and the PC5 user plane security policy of the first relay itself.
[0419] Step 614: The first relay sends a DSMP message for the second PC5 link, which includes the PC5 user plane security protection method for the first PC5 link determined by the first relay. Specifically, the method for transmitting the user plane security protection method can refer to the description of step 602b.
[0420] Step 615: The second terminal device determines a PC5 user plane security protection method for the second PC5 link.
[0421] The second terminal device determines the PC5 user plane security protection method for the second PC5 link based on the PC5 user plane security protection method for the first PC5 link determined by the relay itself and the PC5 user plane security policy of the second terminal device. Specifically, if the relay is transmitted in the form of a security policy, the second terminal device determines the PC5 user plane security protection method for the second PC5 link based on the security policy carried in the second DCR message. If the relay is transmitted in the form of indication information, the second terminal device determines the PC5 user plane security protection method for the second PC5 link based on the indication information.
[0422] Steps 617 to 619 are the same as steps 417 to 419 above, and will not be repeated here.
[0423] It can be seen that in the embodiment of the present application, the control plane security and user plane security of the PC5 link between the first terminal device and the second terminal device are determined by the relay. According to the above method, the consistency of the control plane / user plane security of the PC5 link between the first terminal device and the second terminal device can be guaranteed, and the coordinated processing of the control plane / user plane security protection on both sides of the relay can be achieved. The links on both sides of the relay can either activate the control plane / user plane integrity protection method or not activate the control plane / user plane integrity protection method, and / or, the links on both sides of the relay can either activate the control plane / user plane confidentiality protection method or not activate the control plane / user plane confidentiality protection method, so that the links on both sides of the relay remain consistent in the security protection processing method.
[0424] The above embodiments may be implemented separately in different scenarios, or may be implemented in combination in the same scenario, or different solutions involved in different embodiments may be implemented in combination, without specific limitation.
[0425] The step numbers of the various flowcharts described in the embodiments of the present application are only an example of the execution process and do not constitute a limitation on the order of execution of the steps. In the embodiments of the present application, there is no strict execution order between the steps that have no time dependency on each other.
[0426] In the embodiments provided above, the secure communication method provided in the embodiments of the present application is described from the perspective of the terminal as the execution subject. In order to implement the various functions in the secure communication method provided in the embodiments of the present application, the terminal may include a hardware structure and / or a software module, and implement the above functions in the form of a hardware structure, a software module, or a hardware structure plus a software module. Whether a function of the above functions is executed in the form of a hardware structure, a software module, or a hardware structure plus a software module depends on the specific application and design constraints of the technical solution.
[0427] Similar to the concept of the above embodiment, the embodiment of the present application also provides a communication device 700, which is used to implement the functions of the first terminal device, the second terminal device and the relay in the above method. For example, the first communication device 700 can be a first terminal device, or a device in the first terminal device. The device can be a chip system. In the embodiment of the present application, the chip system can be composed of chips, or it can include chips and other discrete devices. In one example, Figure 7 As shown, the communication device 700 includes a processing unit 701 and a transceiver unit 702 .
[0428] Regarding the above Figure 4 The invention concept shown, the communication device 700 is used to implement the functions of the second terminal device in the above method:
[0429] The transceiver unit 702 is used to receive a first request message about a first terminal device from a relay; the first request message includes the PC5 user plane security policy of the first terminal device and the PC5 user plane security policy of the relay.
[0430] A processing unit 701 is configured to determine first information according to a PC5 user plane security policy of the second terminal device, a PC5 user plane security policy of the first terminal device, and a PC5 user plane security policy of the relay;
[0431] The transceiver unit 702 is further configured to send the first information to the relay, where the first information is used to indicate a user plane security protection method of the first PC5 link and a user plane security protection method of the second PC5 link; wherein the user plane security protection method of the first PC5 link is the same as the user plane security protection method of the second PC5 link;
[0432] The first PC5 link is a PC5 link between the relay and the first terminal device; the second PC5 link is a PC5 link between the relay and the second terminal device.
[0433] In one embodiment, the first information is used to indicate a user plane security protection method of the first PC5 link and a user plane security protection method of the second PC5 link, including:
[0434] The first information is used to indicate: whether the user plane integrity protection of the first PC5 link and the user plane integrity protection of the second PC5 link are both enabled or not enabled, and / or whether the user plane confidentiality protection of the first PC5 link and the user plane confidentiality protection of the second PC5 link are both enabled or not enabled.
[0435] In one embodiment, the transceiver unit 702 is further configured to receive a second request message about the first terminal device from the relay, the second request message including the PC5 control plane security policy of the first terminal device and the PC5 control plane security policy of the relay;
[0436] The processing unit 701 is further configured to determine a control plane security algorithm for the second PC5 link according to the PC5 control plane security policy of the second terminal device, the PC5 control plane security policy of the first terminal device, and the PC5 control plane security policy of the relay;
[0437] The transceiver unit 702 is further configured to send a control plane security algorithm for the second PC5 link to the relay, where the control plane security algorithm is used to indicate the control plane security of the second PC5 link and the control plane security of the first PC5 link, wherein the control plane security protection method of the first PC5 link is the same as the control plane security protection method activated on the second PC5 link.
[0438] In some embodiments, the second request message further includes an indication of a secure endpoint policy, where the indication of the secure endpoint policy is used to indicate that a secure endpoint is located on the relay.
[0439] In some embodiments, the control plane security algorithm is used to indicate the control plane security protection method of the second PC5 link and the control plane security protection method of the first PC5 link, including:
[0440] The control plane security algorithm is used to indicate: whether the control plane integrity protection of the first PC5 link and the control plane integrity protection of the second PC5 link are both enabled or not enabled, and / or whether the control plane confidentiality protection of the first PC5 link and the control plane confidentiality protection of the second PC5 link are both enabled or not enabled.
[0441] In some embodiments, the processing unit 701 determines the first information based on the PC5 user plane security policy of the second terminal device, the PC5 user plane security policy of the first terminal device, and the PC5 user plane security policy of the relay, specifically for:
[0442] Determining the first information according to the PC5 user plane security policy of the second terminal device, the PC5 user plane security policy of the first terminal device, the PC5 user plane security policy of the relay, and the control plane security algorithm of the second PC5 link;
[0443] Among them, the security level of the user plane security protection method of the second PC5 link is not higher than the security level of the control plane security protection method of the second PC5 link, and the security level of the user plane security protection method of the first PC5 link is not higher than the security level of the control plane security protection method of the first PC5 link.
[0444] In some embodiments, the user plane security protection method of the second PC5 link is not higher than the control plane security protection method of the second PC5 link, and the security level of the user plane security protection method of the first PC5 link is not higher than the control plane security protection method of the first PC5 link, including:
[0445] When the control plane confidentiality protection of the third PC5 link is enabled, the user plane confidentiality protection of the third PC5 link is enabled or disabled;
[0446] When the control plane confidentiality protection of the third PC5 link is not enabled, the user plane confidentiality protection of the third PC5 link is not enabled;
[0447] When the control plane integrity protection of the third PC5 link is enabled, the user plane integrity protection of the third PC5 link is enabled or disabled;
[0448] When the control plane integrity protection of the third PC5 link is not enabled, the user plane integrity protection of the third PC5 link is not enabled;
[0449] The third PC5 link is the second PC5 link or the first PC5 link.
[0450] For the specific execution process and beneficial effects of the processing unit 701 and the transceiver unit 702, please refer to the above Figure 4 The method shown is described in the embodiment.
[0451] Regarding the above Figure 6 The invention concept shown, the communication device 700 is used to implement the functions of the second terminal device in the above method:
[0452] The transceiver unit 702 is used to request an indication including a security endpoint policy, where the indication of the security endpoint policy is used to indicate that the security endpoint is located on the relay;
[0453] The transceiver unit 702 is configured to receive the PC5 control plane security protection method of the first PC5 link and the PC5 control plane security protection method of the second PC5 link determined by the at least one relay;
[0454] The processing unit 701 is configured to determine a target relay according to the PC5 control plane security policy of the second terminal device and the PC5 control plane security protection method of the first PC5 link and the PC5 control plane security protection method of the second PC5 link determined by the at least one relay;
[0455] The transceiver unit 702 is further configured to receive the PC5 user plane security protection method of the first PC5 link and the PC5 user plane security protection method of the second PC5 link determined by the target relay;
[0456] The processing unit 701 is further configured to determine first information based on the PC5 user plane security protection iteration of the first PC5 link from the target relay and the PC user plane security protection method of the second terminal device;
[0457] The transceiver unit 702 is further configured for the second terminal device to send the first information to the relay, where the first information is used to indicate a user plane security protection method of the first PC5 link and a user plane security protection method of the second PC5 link; wherein the user plane security protection method of the first PC5 link is the same as the user plane security protection method of the second PC5 link;
[0458] The first PC5 link is a PC5 link between the relay and the first terminal device; the second PC5 link is a PC5 link between the relay and the second terminal device.
[0459] In some embodiments, the first information is used to indicate a user plane security protection method of the first PC5 link and a user plane security protection method of the second PC5 link, including:
[0460] The first information is used to indicate: whether the user plane integrity protection of the first PC5 link and the user plane integrity protection of the second PC5 link are both enabled or not enabled, and / or whether the user plane confidentiality protection of the first PC5 link and the user plane confidentiality protection of the second PC5 link are both enabled or not enabled.
[0461] In some embodiments, the processing unit is further configured to determine a control plane security algorithm for the second PC5 link based on the PC5 user plane security protection method of the first PC5 link and the PC5 user plane security protection method of the second PC5 link determined from the target relay;
[0462] The transceiver unit 702 is further configured to send a control plane security algorithm of a second PC5 link to the relay, where the control plane security algorithm of the second PC5 link is used to indicate control plane security of the second PC5 link and control plane security of the first PC5 link.
[0463] In some embodiments, the control plane security algorithm of the second PC5 link is used to indicate the control plane security of the second PC5 link and the control plane security of the first PC5 link, including:
[0464] The control plane security algorithm of the second PC5 link is used to indicate: whether the control plane integrity protection of the first PC5 link and the control plane integrity protection of the second PC5 link are both enabled or not enabled, and / or whether the control plane confidentiality protection of the first PC5 link and the control plane confidentiality protection of the second PC5 link are both enabled or not enabled.
[0465] In some embodiments, the processing unit 701 determines the first information based on the PC5 user plane security protection method of the first PC5 link from the target relay and the PC user plane security policy of the second terminal device, specifically for:
[0466] Determining the first information according to a PC5 user plane security protection method of a first PC5 link from the target relay and a control plane security algorithm of the second PC5 link;
[0467] Among them, the security level of the user plane security protection method of the second PC5 link is not higher than the security level of the control plane security protection method of the second PC5 link, and the security level of the user plane security protection method of the first PC5 link is not higher than the security level of the control plane security protection method of the first PC5 link.
[0468] In some embodiments, the user plane security protection method of the second PC5 link is not higher than the control plane security of the second PC5 link, and the user plane security protection method of the first PC5 link is not higher than the control plane security protection method of the first PC5 link, including:
[0469] When the control plane confidentiality protection of the third PC5 link is enabled, the user plane confidentiality protection of the third PC5 link is enabled or disabled;
[0470] When the control plane confidentiality protection of the third PC5 link is not enabled, the user plane confidentiality protection of the third PC5 link is not enabled;
[0471] When the control plane integrity protection of the third PC5 link is enabled, the user plane integrity protection of the third PC5 link is enabled or disabled;
[0472] When the control plane integrity protection of the third PC5 link is not enabled, the user plane integrity protection of the third PC5 link is not enabled;
[0473] The third PC5 link is the second PC5 link or the first PC5 link.
[0474] For the specific execution process and beneficial effects of the processing unit 701 and the transceiver unit 702, please refer to the above Figure 6 The method shown is described in the embodiment.
[0475] Regarding the above Figures 4 to 6 The invention concept shown, the communication device 700 is used to implement the functions of the second terminal device in the above method:
[0476] The transceiver unit 702 is configured to receive a direct communication request from a first terminal device via at least one relay;
[0477] The processing unit 701 is configured to determine a target relay from the at least one relay according to the security policy auxiliary information;
[0478] The transceiver unit 702 is used to communicate with the first terminal device through the target relay.
[0479] In some embodiments, the security policy auxiliary information includes a PC control plane security policy of the at least one relay;
[0480] The processing unit 701 is configured to determine a target relay from the at least one relay according to the security policy auxiliary information, and is specifically configured to:
[0481] A target relay including an optional PC5 control plane security policy is selected from the at least one relay.
[0482] In some embodiments, the security policy auxiliary information includes a PC control plane security policy of the at least one relay and a PC5 control plane security policy of the second terminal device;
[0483] The second terminal device determines a target relay from the at least one relay according to the security policy auxiliary information, including:
[0484] The processing unit 701 is specifically configured to select, from the at least one relay, a target relay whose PC control plane security policy does not conflict with the PC5 control plane security policy of the second terminal device.
[0485] In some embodiments, the security policy auxiliary information includes a PC control plane security policy of the at least one relay and a PC5 control plane security policy of the second terminal device;
[0486] The processing unit 701 is specifically used for the second terminal device to select a target relay from the at least one relay based on the security policy auxiliary information, wherein the security level of the PC user plane security protection method of the relay is not higher than the security level of the PC control plane security protection method of the second terminal device.
[0487] In some embodiments, the security policy auxiliary information is pre-configured by a policy control function network element.
[0488] For the specific execution process and beneficial effects of the processing unit 701 and the transceiver unit 702, please refer to the above Figure 6 The method shown is described in the embodiment.
[0489] Regarding the above Figure 4 The invention concept shown, the communication device 700 is used to implement the relay function in the above method:
[0490] The transceiver unit 702 is configured to send a first request message about the first terminal device to the second terminal device; the first request message includes the PC5 user plane security policy of the first terminal device and the PC5 user plane security policy of the relay;
[0491] The transceiver unit 702 is configured to receive first information from a second terminal device, where the first information is used to indicate a user plane security protection method of a first PC5 link and a user plane security protection method of a second PC5 link; wherein the user plane security protection method of the first PC5 link is the same as the user plane security protection method of the second PC5 link;
[0492] The processing unit 701 is configured to activate the user plane security protection method of the second PC5 link and the user plane security protection method of the first PC5 link according to the first information;
[0493] The first PC5 link is a PC5 link between the relay and the first terminal device, and the second PC5 link is a PC5 link between the relay and the second terminal device.
[0494] In some embodiments, the transceiver unit 702 is further configured to send the control plane security policy of the first terminal device and the control plane security policy of the relay to the second terminal device, where the control plane security policy of the first terminal device and the control plane security policy of the relay are used to determine a control plane security algorithm for the second PC5 link;
[0495] The transceiver unit 702 is further configured to receive a control plane security algorithm for the second PC5 link from a second terminal device, where the control plane security algorithm is used to indicate a control plane security protection method for the second PC5 link and a control plane security protection method for the first PC5 link;
[0496] The processing unit 701 is further configured to activate a control plane security protection method for the second PC5 link and a control plane security protection method for the first PC5 link according to a control plane security algorithm for the second PC5 link, wherein the control plane security protection method for the first PC5 link is the same as the control plane security protection method activated on the second PC5 link.
[0497] In some embodiments, the security level of the PC5 control plane security protection method of the relay is not higher than the security level of the PC5 user plane security protection method of the second link.
[0498] In some embodiments, the security level of the user plane security protection method of the first PC5 link is not higher than the security level of the control plane security protection method of the first PC5 link; the security level of the user plane security protection method of the second PC5 link is not higher than the security level of the control plane security protection method of the second PC5 link.
[0499] Regarding the above Figure 6 The invention concept shown, the communication device 700 is used to implement the relay function in the above method:
[0500] The transceiver unit 702 is configured to send a direct communication request from the first terminal device to the second terminal device; the direct communication request includes an indication of a secure endpoint policy, where the indication of the secure endpoint policy is used to indicate that the secure endpoint is located on a relay;
[0501] The processing unit 701 is configured to determine a PC5 user plane security protection method for the first PC5 link according to the PC5 user plane security policy of the relay and the PC user plane security policy of the first terminal device;
[0502] The transceiver unit 702 is further configured to send the PC5 user plane security protection method of the first PC5 link to the second terminal device;
[0503] The transceiver unit 702 is further configured to receive first information from the second terminal device, where the first information is used to indicate a user plane security protection method for the first PC5 link and a user plane security protection method for the second PC5 link;
[0504] The processing unit 701 is further configured to activate, according to the first information, a user plane security protection method for the second PC5 link and a user plane security protection method for the first PC5 link; the user plane security protection method for the second PC5 link is the same as the user plane security protection method for the first PC5 link;
[0505] The first PC5 link is a PC5 link between the relay and the first terminal device; the second PC5 link is a PC5 link between the relay and the second terminal device.
[0506] In some embodiments, the first information is used to indicate a user plane security protection method of the first PC5 link and a user plane security protection method of the second PC5 link, including:
[0507] The first information is used to indicate: whether the user plane integrity protection of the first PC5 link and the user plane integrity protection of the second PC5 link are both enabled or not enabled, and / or whether the user plane confidentiality protection of the first PC5 link and the user plane confidentiality protection of the second PC5 link are both enabled or not enabled.
[0508] In some embodiments, the transceiver unit 702 is further configured to receive a second request message from the first terminal device, where the second request message includes the PC5 control plane security policy of the first terminal device and the relayed PC5 control plane security policy;
[0509] The processing unit 701 is further configured to determine a PC5 control plane security protection method for the first PC5 link and a PC5 control plane security protection method for the second PC5 link according to the PC5 control plane security policy of the relay and the PC5 control plane security policy of the first terminal device;
[0510] The transceiver unit 702 is further configured to send the PC5 control plane security protection method of the first PC5 link and the PC5 control plane security protection method of the second PC5 link to the second terminal device;
[0511] The transceiver unit 702 is further configured to receive a control plane security algorithm for the second PC5 link from the second terminal device, where the control plane security algorithm is used to indicate control plane security of the second PC5 link and control plane security of the first PC5 link, and the control plane security algorithm is determined based on a PC5 control plane security protection method for the first PC5 link and a PC5 control plane security protection method for the second PC5 link;
[0512] The processing unit 701 is further configured to activate a control plane security protection method for the second PC5 link and a control plane security protection method for the first PC5 link according to a control plane security algorithm for the second PC5 link.
[0513] In some embodiments, the control plane security algorithm is used to indicate the control plane security of the second PC5 link and the control plane security protection method of the first PC5 link, including:
[0514] The control plane security algorithm is used to indicate: whether the control plane integrity protection of the first PC5 link and the control plane integrity protection of the second PC5 link are both enabled or not enabled, and / or whether the control plane confidentiality protection of the first PC5 link and the control plane confidentiality protection of the second PC5 link are both enabled or not enabled.
[0515] In some embodiments, the security level of the user plane security protection method of the second PC5 link is not higher than the security level of the control plane security protection method of the second PC5 link, and the security level of the user plane security protection method of the first PC5 link is not higher than the security level of the control plane security protection method of the first PC5 link.
[0516] The division of modules in the embodiments of the present application is illustrative and is merely a logical functional division. In actual implementation, other division methods may be used. Furthermore, the functional modules in the various embodiments of the present application may be integrated into a single processor, or may exist physically separately, or two or more modules may be integrated into a single module. The aforementioned integrated modules may be implemented in the form of hardware or software functional modules.
[0517] In another example, Figure 8 As shown, the communication device 800 includes at least one processor 810 and a memory 820. A computer program is stored in the memory 820. The memory 820 is coupled to the processor 810. The coupling in the embodiment of the present application is an interval coupling or communication connection between devices, units or modules, which can be electrical, mechanical or other forms, and is used for information exchange between devices, units or modules. As another implementation, the memory 820 can also be located outside the communication device 800. The processor 810 can operate in conjunction with the memory 820. The processor 810 can call the computer program stored in the memory 820. At least one of the at least one memory may be included in the processor.
[0518] In some embodiments, the communication device 800 may further include a communication interface 830 for communicating with other devices via a transmission medium, thereby enabling the devices in the communication device 800 to communicate with the other devices. Exemplarily, the communication interface 830 may be a transceiver, circuit, bus, module, or other type of communication interface, and the other device may be another terminal. The processor 810 utilizes the communication interface 830 to send and receive information and implement the methods of the above embodiments. Exemplarily, the communication interface 830 is used to receive resource indication information. Furthermore, exemplary, the communication interface 830 is used to send data.
[0519] In the embodiments of the present application, the processor may be a general-purpose processor, a digital signal processor, an application-specific integrated circuit, a field programmable gate array or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component, and may implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of the present application. A general-purpose processor may be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of the present application may be directly implemented as being executed by a hardware processor, or may be executed by a combination of hardware and software modules in the processor.
[0520] In an embodiment of the present application, the memory may be a non-volatile memory, such as a hard disk drive (HDD) or a solid-state drive (SSD), or a volatile memory (volatile memory), such as a random-access memory (RAM). The memory is any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory in an embodiment of the present application may also be a circuit or any other device that can implement a storage function, for storing computer programs and / or data.
[0521] The methods provided in the embodiments of the present application can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, they can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program is loaded and executed on a computer, the process or function described in the embodiment of the present invention is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more integrated media. The medium may be a magnetic medium (eg, a floppy disk, a hard disk, a magnetic tape), an optical medium (eg, a digital video disc (DVD)), or a semiconductor medium (eg, an SSD).
[0522] Obviously, those skilled in the art may make various changes and modifications to the present application without departing from the scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application is intended to include these modifications and variations.
Claims
1. A secure communication method, characterized in that: A chip applied to a second terminal device or in the second terminal device includes: Receiving a first request message about a first terminal device from a relay; the first request message includes a PC5 user plane security policy of the first terminal device and a PC5 user plane security policy of the relay; Determine the first information according to the PC5 user plane security policy of the second terminal device, the PC5 user plane security policy of the first terminal device, and the PC5 user plane security policy of the relay; Sending the first information to the relay, where the first information is used to indicate a user plane security protection method of the first PC5 link and a user plane security protection method of the second PC5 link; wherein the user plane security protection method of the first PC5 link is the same as the user plane security protection method of the second PC5 link; The first PC5 link is a PC5 link between the relay and the first terminal device; the second PC5 link is a PC5 link between the relay and the second terminal device.
2. The method according to claim 1, characterized in that The first information is used to indicate the user plane security protection method of the first PC5 link and the user plane security protection method of the second PC5 link, including: The first information is used to indicate: whether the user plane integrity protection of the first PC5 link and the user plane integrity protection of the second PC5 link are both enabled or not enabled, and / or whether the user plane confidentiality protection of the first PC5 link and the user plane confidentiality protection of the second PC5 link are both enabled or not enabled.
3. The method according to claim 1 or 2, characterized in that The method further comprises: receiving a second request message about the first terminal device from the relay, where the second request message includes a PC5 control plane security policy of the first terminal device and a PC5 control plane security policy of the relay; Determining a control plane security algorithm for the second PC5 link according to the PC5 control plane security policy of the second terminal device, the PC5 control plane security policy of the first terminal device, and the PC5 control plane security policy of the relay; The second terminal device sends a control plane security algorithm of the second PC5 link to the relay, where the control plane security algorithm is used to indicate a control plane security protection method of the second PC5 link and a control plane security protection method of the first PC5 link, wherein the control plane security protection method of the first PC5 link is the same as the control plane security protection method activated on the second PC5 link.
4. The method according to claim 3, characterized in that The second request message also includes an indication of a secure endpoint policy, where the indication of the secure endpoint policy is used to indicate that a secure endpoint is located on the relay.
5. The method according to claim 3, characterized in that The control plane security algorithm is used to indicate a control plane security protection method for the second PC5 link and a control plane security protection method for the first PC5 link, including: The control plane security algorithm is used to indicate: whether the control plane integrity protection of the first PC5 link and the control plane integrity protection of the second PC5 link are both enabled or not enabled, and / or whether the control plane confidentiality protection of the first PC5 link and the control plane confidentiality protection of the second PC5 link are both enabled or not enabled.
6. The method according to claim 3, characterized in that include: Determining first information according to the PC5 user plane security policy of the second terminal device, the PC5 user plane security policy of the first terminal device, and the PC5 user plane security policy of the relay includes: Determining the first information according to the PC5 user plane security policy of the second terminal device, the PC5 user plane security policy of the first terminal device, the PC5 user plane security policy of the relay, and the control plane security algorithm of the second PC5 link; Among them, the security level of the user plane security protection method of the second PC5 link is not higher than the security level of the control plane security protection method of the second PC5 link, and the security level of the user plane security protection method of the first PC5 link is not higher than the security level of the control plane security protection method of the first PC5 link.
7. The method according to claim 6, characterized in that The user plane security protection method of the second PC5 link is not higher than the control plane security protection method of the second PC5 link, and the security level of the user plane security protection method of the first PC5 link is not higher than the control plane security protection method of the first PC5 link, including: When the control plane confidentiality protection of the third PC5 link is enabled, the user plane confidentiality protection of the third PC5 link is enabled or disabled; When the control plane confidentiality protection of the third PC5 link is not enabled, the user plane confidentiality protection of the third PC5 link is not enabled; When the control plane integrity protection of the third PC5 link is enabled, the user plane integrity protection of the third PC5 link is enabled or disabled; When the control plane integrity protection of the third PC5 link is not enabled, the user plane integrity protection of the third PC5 link is not enabled; The third PC5 link is the second PC5 link or the first PC5 link.
8. A communication device, characterized in that: The communication device is a second terminal device or a chip in the second terminal device, including: a transceiver unit configured to receive a first request message about a first terminal device from a relay; the first request message includes a PC5 user plane security policy of the first terminal device and a PC5 user plane security policy of the relay; a processing unit, configured to determine first information according to a PC5 user plane security policy of the second terminal device, a PC5 user plane security policy of the first terminal device, and a PC5 user plane security policy of the relay; The transceiver unit is further configured to send the first information to the relay, where the first information is used to indicate a user plane security protection method of the first PC5 link and a user plane security protection method of the second PC5 link; wherein the user plane security protection method of the first PC5 link is the same as the user plane security protection method of the second PC5 link; The first PC5 link is a PC5 link between the relay and the first terminal device; the second PC5 link is a PC5 link between the relay and the second terminal device.
9. The device according to claim 8, characterized in that The first information is used to indicate the user plane security protection method of the first PC5 link and the user plane security protection method of the second PC5 link, including: The first information is used to indicate: whether the user plane integrity protection of the first PC5 link and the user plane integrity protection of the second PC5 link are both enabled or not enabled, and / or whether the user plane confidentiality protection of the first PC5 link and the user plane confidentiality protection of the second PC5 link are both enabled or not enabled.
10. The device according to claim 8 or 9, characterized in that The transceiver unit is further configured to receive a second request message about the first terminal device from the relay, where the second request message includes a PC5 control plane security policy of the first terminal device and a PC5 control plane security policy of the relay; The processing unit is further configured to determine a control plane security algorithm for the second PC5 link based on the PC5 control plane security policy of the second terminal device, the PC5 control plane security policy of the first terminal device, and the PC5 control plane security policy of the relay; The transceiver unit is further configured to send a control plane security algorithm of the second PC5 link to the relay, where the control plane security algorithm is used to indicate a control plane security protection method of the second PC5 link and a control plane security protection method of the first PC5 link, wherein the control plane security protection method of the first PC5 link is the same as the control plane security protection method activated on the second PC5 link.
11. The device according to claim 10, characterized in that The second request message also includes an indication of a secure endpoint policy, where the indication of the secure endpoint policy is used to indicate that a secure endpoint is located on the relay.
12. The device according to claim 10, characterized in that The control plane security algorithm is used to indicate the control plane security protection method of the second PC5 link and the control plane security protection method of the first PC5 link, including The control plane security algorithm is used to indicate: whether the control plane integrity protection of the first PC5 link and the control plane integrity protection of the second PC5 link are both enabled or not enabled, and / or whether the control plane confidentiality protection of the first PC5 link and the control plane confidentiality protection of the second PC5 link are both enabled or not enabled.
13. The device according to claim 10, characterized in that The processing unit determines the first information according to the PC5 user plane security policy of the second terminal device, the PC5 user plane security policy of the first terminal device, and the PC5 user plane security policy of the relay, specifically for: Determining the first information according to the PC5 user plane security policy of the second terminal device, the PC5 user plane security policy of the first terminal device, the PC5 user plane security policy of the relay, and the control plane security algorithm of the second PC5 link; Among them, the security level of the user plane security protection method of the second PC5 link is not higher than the security level of the control plane security protection method of the second PC5 link, and the security level of the user plane security protection method of the first PC5 link is not higher than the security level of the control plane security protection method of the first PC5 link.
14. The device according to claim 13, characterized in that The user plane security protection method of the second PC5 link is not higher than the control plane security protection method of the second PC5 link, and the security level of the user plane security protection method of the first PC5 link is not higher than the control plane security protection method of the first PC5 link, including: When the control plane confidentiality protection of the third PC5 link is enabled, the user plane confidentiality protection of the third PC5 link is enabled or disabled; When the control plane confidentiality protection of the third PC5 link is not enabled, the user plane confidentiality protection of the third PC5 link is not enabled; When the control plane integrity protection of the third PC5 link is enabled, the user plane integrity protection of the third PC5 link is enabled or disabled; When the control plane integrity protection of the third PC5 link is not enabled, the user plane integrity protection of the third PC5 link is not enabled; The third PC5 link is the second PC5 link or the first PC5 link.
15. A communication device, characterized in that: The communication device comprises means for performing the method according to any one of claims 1 to 7.
16. A communication device, characterized in that: include: A processor is coupled to a memory, wherein the memory is used to store a program or an instruction, and when the program or the instruction is executed by the processor, the communication device executes the method according to any one of claims 1 to 7.
17. A chip system, characterized in that: include: A processing unit and a communication unit coupled to the processing unit, wherein the processing unit is configured to run a computer program or instructions so as to enable the processing unit to perform the method according to any one of claims 1 to 7.
18. A computer-readable storage medium, characterized in that The storage medium stores a computer program or instruction. When the computer program or instruction is executed by the communication device, the method according to any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
User plane integrity protection method and device, and equipment
CN110831007A