Information processing method and apparatus, communication device, and storage medium
By introducing a default PC5 security policy in the 5G ProSe service, the problem of communication failure caused by not obtaining a specific PC5 security policy was solved, and PC5 connection security protection under the default policy was achieved, ensuring smooth communication.
Patent Information
- Application Number
- CN202180003631.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-10-29
- Publication Date
- 2025-12-30
- Estimated Expiration
- 2041-10-29
AI Technical Summary
In 5G ProSe services, if the specific PC5 security policy of the target ProSe service is not obtained, existing technologies cannot establish PC5 connections and conduct communication, resulting in communication failure.
A default PC5 security policy is introduced to protect PC5 connections when a specific PC5 security policy is not available. By configuring the default PC5 security policy, the security of PC5 communication is ensured.
Without obtaining a specific PC5 security policy, it is able to establish a PC5 connection and conduct secure communication, solving the communication interruption problem caused by the lack of a specific policy and realizing security protection under the default policy.
Smart Images

Figure CN116368834B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to, but is not limited to, the field of wireless communication technology, and particularly to an information processing method and apparatus, communication equipment and storage medium. Background Technology
[0002] In the current version of 3GPP TR33.847 for 5G Proximity Service (ProSe) security, protection for PC5 direct communication is ensured through PC5 security policies provided to the ProSe UE by the PCF or ProSe application server. These security policies are included in the list of ProSe services requiring security protection. Each ProSe service is assigned its own corresponding PC5 security policy.
[0003] The PC5 security policy configuration for 5G ProSe services can reuse the PC5 security policy configuration mechanism for eV2X services defined in 3GPP TS 33.536. The negotiation and implementation of the PC5 security policy can also reuse the procedures defined in 3GPP TS 33.536, where the PC5 security policy needs to be carried in the relevant process messages. Summary of the Invention
[0004] This disclosure provides an information processing method and apparatus, a communication device and a storage medium.
[0005] A first aspect of this disclosure provides an information processing method, wherein the method is executed by a first user equipment (UE), the method comprising:
[0006] Obtain a default PC5 security policy, wherein the default PC5 security policy is used to protect the PC5 connection of the target ProSe service when a specific PC5 security policy based on the target ProSe service is not obtained.
[0007] A second aspect of this disclosure provides an information processing method, wherein the method is executed by a PCF, the method comprising:
[0008] Configure a default PC5 security policy, wherein the default PC5 security policy is used to protect the PC5 connection of the target ProSe service when the specific PC5 security policy of the target based on proximity service is not obtained.
[0009] A third aspect of this disclosure provides an information processing apparatus, wherein the apparatus includes:
[0010] The acquisition module is configured to acquire a default PC5 security policy, wherein the default PC5 security policy is used to protect the PC5 connection of the target ProSe service when a specific PC5 security policy based on the target ProSe service is not acquired.
[0011] A fourth aspect of this disclosure provides an information processing apparatus, the apparatus comprising:
[0012] The first configuration module is configured to configure a default PC5 security policy, wherein the default PC5 security policy is used to protect the PC5 connection of the target ProSe service when the specific PC5 security policy of the target ProSe service based on proximity is not obtained.
[0013] A fifth aspect of this disclosure provides a communication device, including a processor, a transceiver, a memory, and an executable program stored in the memory and executable by the processor, wherein the processor executes the information processing method as provided in the first or second aspect above when running the executable program.
[0014] A sixth aspect of this disclosure provides a computer storage medium storing an executable program; the executable program, when executed by a processor, can implement the information processing method provided in the first or second aspect described above.
[0015] The technical solution provided in this disclosure, when performing PC5 communication based on the PC5 interface, can determine the protection of the PC5 connection between two UEs based on the default PC5 security policy even when the specific PC5 security policy of the target ProSe service is not obtained. This enables the successful establishment of a secure PC5 connection based on the default PC5 security policy and protects the PC5 communication of the target ProSe service even when the specific PC5 security policy of the target ProSe service is not obtained.
[0016] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit the embodiments of this disclosure. Attached Figure Description
[0017] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments of the invention and, together with the description, serve to explain the principles of the embodiments of the invention.
[0018] Figure 1 This is a schematic diagram illustrating the structure of a wireless communication system according to an exemplary embodiment;
[0019] Figure 2 This is a flowchart illustrating an information processing method according to an exemplary embodiment;
[0020] Figure 3 This is a flowchart illustrating an information processing method according to an exemplary embodiment;
[0021] Figure 4 This is a flowchart illustrating an information processing method according to an exemplary embodiment;
[0022] Figure 5 This is a flowchart illustrating an information processing method according to an exemplary embodiment;
[0023] Figure 6 This is a schematic diagram of the structure of an information processing apparatus according to an exemplary embodiment;
[0024] Figure 7 This is a schematic diagram of the structure of an information processing apparatus according to an exemplary embodiment;
[0025] Figure 8 This is a schematic diagram of the structure of a UE according to an exemplary embodiment;
[0026] Figure 9 This is a schematic diagram of the structure of a communication device according to an exemplary embodiment. Detailed Implementation
[0027] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numerals in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with those of the present invention. Rather, they are merely examples of apparatuses and methods consistent with some aspects of the embodiments of the present invention as detailed in the appended claims.
[0028] The terminology used in this disclosure is for the purpose of describing particular embodiments only and is not intended to be limiting of the present disclosure. The singular forms “a,” “an,” and “the” as used in this disclosure and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to and includes any and all possible combinations of one or more of the associated listed items.
[0029] It should be understood that although the terms first, second, third, etc., may be used to describe various information in embodiments of this disclosure, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, first information may also be referred to as second information without departing from the scope of embodiments of this disclosure, and similarly, second information may also be referred to as first information. Depending on the context, the word "if" as used herein may be interpreted as "when," "when," or "in response to a determination."
[0030] Please refer to Figure 1 This illustration shows a schematic diagram of the structure of a wireless communication system provided in an embodiment of this disclosure. Figure 1 As shown, the wireless communication system is a communication system based on cellular mobile communication technology. The wireless communication system may include: several UEs 11 and several access devices 12.
[0031] UE11 can be a device that provides voice and / or data connectivity to a user. UE11 can communicate with one or more core networks via a Radio Access Network (RAN). UE11 can be an IoT UE, such as a sensor device, a mobile phone (or "cellular" phone), and a computer with an IoT UE. For example, it can be a fixed, portable, pocket-sized, handheld, computer-embedded, or vehicle-mounted device. Examples include a station (STA), subscriber unit, subscriber station, mobile station, mobile station, remote station, access point, remote terminal, access terminal, user terminal, user agent, user device, or user equipment (UE). Alternatively, UE11 can be a device in an unmanned aerial vehicle (UAV). Alternatively, UE11 can be a vehicle-mounted device, such as a vehicle computer with wireless communication capabilities, or a wireless communication device connected to an external vehicle computer. Alternatively, UE11 can also be a roadside device, such as a street light, traffic light, or other roadside device with wireless communication capabilities.
[0032] Access device 12 can be a network-side device in a wireless communication system. This wireless communication system can be a 4G system (also known as Long Term Evolution, LTE); or it can be a 5G system (also known as a New Radio, NR, or 5G NR system). Alternatively, it can be the next generation after 5G. In this case, the access network in the 5G system can be called NG-RAN (New Generation-Radio Access Network). Alternatively, it can be an MTC system.
[0033] The access device 12 can be an evolved NB (eNB) used in a 4G system. Alternatively, the access device 12 can also be a gNB (gNB) using a centralized-distributed architecture in a 5G system. When the access device 12 adopts a centralized-distributed architecture, it typically includes a central unit (CU) and at least two distributed units (DUs). The central unit is equipped with a protocol stack of the Packet Data Convergence Protocol (PDCP) layer, the Radio Link Control (RLC) layer, and the Media Access Control (MAC) layer; the distributed units are equipped with a physical (PHY) layer protocol stack. This disclosure does not limit the specific implementation of the access device 12.
[0034] Access device 12 and UE11 can establish a wireless connection via a wireless air interface. In different implementations, the wireless air interface is a wireless air interface based on the fourth-generation mobile communication network technology (4G) standard; or, the wireless air interface is a wireless air interface based on the fifth-generation mobile communication network technology (5G) standard, such as a new air interface; or, the wireless air interface can also be a wireless air interface based on a next-generation mobile communication network technology standard based on 5G.
[0035] In some embodiments, UE11 can also establish E2E (End to End) connections. Examples include V2V (vehicle to vehicle), V2I (vehicle to Infrastructure), and V2P (vehicle to pedestrian) communication scenarios in vehicle-to-everything (V2X) communication.
[0036] In some embodiments, the wireless communication system described above may further include a network management device 13.
[0037] Several access devices 12 are connected to network management device 13. Network management device 13 can be a core network device in a wireless communication system, such as a Mobility Management Entity (MME) in an Evolved Packet Core (EPC). Alternatively, it can be other core network devices, such as a Serving Gateway (SGW), a Public Data Network Gateway (PGW), a Policy and Charging Rules Function (PCRF), or a Home Subscriber Server (HSS). The implementation of network management device 13 is not limited in this embodiment.
[0038] like Figure 2 As shown, this disclosure provides an information processing method, which is executed by a first user equipment (UE). The method includes:
[0039] S110: Obtain the default PC5 security policy, wherein the default PC5 security policy is used to protect the PC5 connection of the target ProSe service when a specific PC5 security policy based on the target ProSe service is not obtained.
[0040] The information processing method provided in this embodiment can be applied to a UE, which can be a first UE. The UE communicating with the first UE via PC5 communication is a second UE. The first UE can be any UE that needs to establish a PC5 connection with the second UE and conduct PC5 communication based on that connection. The second UE can be any UE different from the first UE. The first UE can be either the initiator or the receiver of the PC5 communication.
[0041] The default PC5 security policy here is one type of PC5 security policy. It is used to provide security for PC5 connections when a specific PC5 security policy for the target ProSe service is not available.
[0042] For example, the default PC5 security policy can be a security policy configured by a telecommunications operator and can be applied to all ProSe services of the telecommunications network. For instance, the default PC5 security policy can indicate at least one of the following:
[0043] It is required that PC5 communication signaling and / or data based on PC5 connection be encrypted and / or protected for integrity, that is, when PC5 communication is based on PC5 connection, integrity protection and / or encryption of communication signaling and / or data are required;
[0044] Optionally, it indicates that PC5-based PC5 communication signaling and / or data may be encrypted or unencrypted and / or may or may not be protected by integrity.
[0045] No, indicating that PC5 communication signaling and / or data based on PC5 connection does not require encryption and / or integrity protection, that is, when PC5 communication is based on PC5 connection, there is no need for integrity protection and / or encryption of communication signaling and / or data.
[0046] In some embodiments, the default PC5 security policy can be configured with different security protection requirements for different types of ProSe services; and / or different PC5 security protection requirements can be configured according to different PC5 communication environments and / or different PC5 communication UEs.
[0047] In this way, even based on the default PC5 security policy, it is possible to select the appropriate PC5 security protection requirements for the current communication situation to conduct secure PC5 communication, depending on different ProSe services, communication environments and / or communication UEs.
[0048] Of course, the above is just an example of the default PC5 security policy, and specific implementations are not limited to this example.
[0049] In this embodiment of the disclosure, the default PC5 security policy can be a public PC5 security policy, that is, a PC5 policy provided by various ProSe services. A specific PC5 security policy, however, is only applicable to its designated ProSe service.
[0050] By introducing a default PC5 security policy, the UE can still protect the establishment of PC5 connections and conduct PC5 communication based on PC5 connections even when it has not obtained a specific PC5 security policy for the target ProSe service. This reduces the problems of PC5 connection failure and PC5 communication failure caused by not obtaining a specific PC5 security policy for the target ProSe service.
[0051] In some embodiments, such as Figure 3 As shown, this disclosure provides an information processing method that may include:
[0052] S120: When the specific PC5 security policy of the target ProSe service is obtained, protect the PC5 connection based on the target ProSe service according to the specific PC5 security policy.
[0053] In this embodiment of the disclosure, if a specific PC5 security policy for the target ProSe service is obtained, the specific PC5 security policy shall be used as the basis for protecting the PC5 connection established for the target ProSe.
[0054] That is, if both the default PC5 security policy and a specific PC5 security policy are obtained at the same time, the specific PC5 security policy will be used first.
[0055] This specific PC5 security policy can be specifically formulated by the service provider or telecommunications operator of the target ProSe service for the target ProSe. Therefore, the specific PC5 security policy for the target ProSe service is specifically formulated for the security needs of the target ProSe service, thus possessing the characteristics of the service. Prioritizing the provision of PC5 connection security protection according to the specific PC5 security policy for the target ProSe service can meet the specific security needs of the target ProSe service.
[0056] In some embodiments, such as Figure 4 As shown, the method includes:
[0057] S100: Receive the specific PC5 security policy of the target ProSe service from the Policy Control Function (PCF); or, receive the specific PC5 security policy of the target ProSe service from the ProSe application server.
[0058] Before performing PC5 communication (or direct communication, or sidelink (SL) communication) for the target ProSe service, the UE can request the specific PC5 security policy from the PCF or the ProSe application server of the target ProSe.
[0059] For example, before requesting the specific PC5 security policy from the PCF, the UE can query whether the specific PC5 security policy for the target ProSe service is stored locally. If the UE has it stored locally and it is determined to be the latest version of the specific PC5 security policy, then there is no need to request it again from the PCF or the ProSe application server.
[0060] For example, the specific PC5 security policy that the UE receives from the PCF and / or ProSe application server for the target ProSe service may include:
[0061] Send a request message to the PCF or ProSe application server, wherein the request message includes: the service identifier of the target ProSe service;
[0062] Receive response messages from the PCF or ProSe application server.
[0063] In one embodiment, the response message includes at least one of the following:
[0064] The policy identifier of the specific PC5 security policy;
[0065] The policy entries of the specific PC5 security policy;
[0066] The denial feedback indicates that there is no specific PC5 security policy for the target ProSe service.
[0067] When the UE does not request a specific PC5 security policy for the target ProSe service from the PCF or ProSe application server, or when the response message indicates that the field carrying the specific PC5 security policy is empty, it can be assumed that the corresponding specific PC5 security policy has not been obtained. In this case, the PC5 connection of the target ProSe service will be protected according to the default PC5 security policy.
[0068] Of course, the above is just one way to obtain a specific PC5 security policy from the PCF or ProSe application server. In the actual implementation process, when the UE requests PC5 communication, the PCF or ProSe application server on the network side can send the relevant information of the specific PC5 security policy to the UE in the response message of requesting ProSe communication. If the UE does not find the relevant information of the specific PC5 security policy in the response message of requesting ProSe communication, it can be considered that the specific PC5 security policy of the target ProSe service has not been obtained.
[0069] In some embodiments, the specific PC5 security policy differs for different ProSe services.
[0070] For example, the specific PC5 security policies for different ProSe services may have different policy content and / or policy identifiers to meet the security requirements of different ProSe services.
[0071] In some embodiments, the specific PC5 security policy of the target ProSe service is determined based on the security requirements of the target ProSe service.
[0072] In some embodiments, the default PC5 security policy may be pre-configured within the first UE;
[0073] or,
[0074] The default PC5 security policy is received from PCF.
[0075] For example, the default PC5 security policy can be specified in the communication standard and pre-written into the UE based on the communication standard. In this way, any UE is aware of the default PC5 security policy in advance, so that even if the specific PC5 security policy of the target ProSe service is not obtained, communication of the target ProSe service can be carried out based on the default PC5 security policy.
[0076] In some embodiments, the method further includes:
[0077] Based on the default PC5 security policy or a specific PC5 security policy, negotiate with the second UE the security parameters for protecting the PC5 connection of the target ProSe service.
[0078] This security parameter includes, but is not limited to, at least one of the following:
[0079] The first parameter indicating whether PC5 signaling is encrypted;
[0080] A second parameter indicating whether PC5 data is encrypted;
[0081] A third parameter indicating whether PC5 signaling requires integrity protection;
[0082] The fourth parameter indicates whether PC5 data requires integrity protection;
[0083] The fifth parameter indicates the encryption and integrity protection algorithm (the same algorithm);
[0084] Of course, the above are just examples, and the actual implementation is not limited to the examples above.
[0085] In this embodiment of the disclosure, the first UE negotiates security parameters before establishing PC5 communication with the second UE. Specifically, the negotiation of security parameters is based on either a default PC5 security policy or a specific PC5 security policy.
[0086] For example, when a specific PC5 security policy for the target ProSe service is obtained, the security parameters for protecting the PC5 connection of the target ProSe service will be negotiated with the second UE according to the specific PC5 security policy. When a specific PC5 security policy for the target ProSe service is not obtained, the security parameters for protecting the PC5 connection of the target ProSe service will be negotiated with the second UE according to the default PC5 security policy.
[0087] In some embodiments, the default PC5 security policy includes:
[0088] Default security protection requirements for any ProSe service.
[0089] Since the default PC5 security policy is the default security protection requirement for any ProSe service, PC5 connection protection can be performed for any ProSe service according to the default PC5 security policy even if a specific PC5 security protection policy is not obtained.
[0090] In some embodiments, the specific PC5 security policy has a higher priority than the default PC5 security policy.
[0091] The default PC5 security policy is equivalent to a backup security policy for the specific PC5 security policy of each ProSe service. When the specific PC5 security policy is not configured or is not obtained due to an anomaly, the PC5 connection of the target ProSe service can be protected based on the default PC5 security policy.
[0092] like Figure 5 As shown, this disclosure provides an information processing method, wherein the method is executed by the PCF, and the method includes:
[0093] S210: Configure the default PC5 security policy, wherein the default PC5 security policy is used to protect the PC5 connection of the target ProSe service when the specific PC5 security policy of the target ProSe service based on proximity is not obtained.
[0094] PCF can store the default PC5 security policy, which can be configured into PCF by the network management device.
[0095] In some embodiments, S210 may include at least one of the following:
[0096] Initial configuration defaults to the PC5 security policy;
[0097] Update the default PC5 security policy regularly or irregularly.
[0098] The default PC5 security policy is updated periodically, including updates when new ProSe services or new types of ProSe services are introduced.
[0099] Of course, the above are just examples, and the actual implementation is not limited to any of the examples mentioned above.
[0100] In some embodiments, the method further includes:
[0101] Send the default PC5 security policy to the UE.
[0102] If the PCF is configured with a default PC5 security policy, it will actively push or send the PC5 security policy to the UE based on the UE's request, so that the UE can store the default PC5 security policy.
[0103] In some embodiments, the method further includes:
[0104] Configure the specific PC5 security policy for the target ProSe service.
[0105] PCF can also configure specific PC5 security policies for target ProSe services based on instructions from the ProSe application server.
[0106] If the PCF is configured with a specific PC5 security policy, it can also send that specific PC5 security policy to the UE so that the UE can protect the PC5 connection of the target ProSe service when communicating with the target ProSe service.
[0107] In some embodiments, the specific PC5 security policy has a higher priority than the default PC5 security policy.
[0108] In some embodiments, the default PC5 security policy includes:
[0109] Default security protection requirements for any ProSe service.
[0110] The default PC5 security policy includes default security protection requirements for any ProSe service. Thus, if the specific PC5 security policy for any ProSe service is not obtained, the PC5 connection of the corresponding ProSe service can be protected based on the default PC5 security policy.
[0111] PC5 direct communication (PC5 communication for short) can be secured by PC5 security policies provided to ProSeUE by the PCF or ProSe application server. These PC5 security policies are included in the list of ProSe services that require security protection. Each ProSe service can be assigned its own corresponding PC5 security policy.
[0112] The PC5 security policy configuration for ProSe services can utilize the PC5 security policy configuration mechanism for eV2X services. The negotiation and implementation of the PC5 security policy can also employ procedures defined in relevant technologies, where the PC5 security policy can be carried in relevant process messages.
[0113] However, in actual deployments, some ProSe service providers may not have assigned corresponding security policies to the specific ProSe services they provide, resulting in the UE lacking a PC5 security policy. If a ProSe terminal does not configure a PC5 security policy when establishing direct communication for a specific 5G ProSe service, it cannot negotiate and implement the PC5 security policy with the peer terminal, thus failing to establish direct communication between terminals.
[0114] 5G ProSe services can be highly diversified and offered by various ProSe service providers, some of whom may not be able to effectively assign PC5 security policies to the specific services they offer.
[0115] In the embodiments of this application,
[0116] Define different types of PC5 security policies;
[0117] Configure the default PC5 security policy (also known as the default PC5 security policy) to protect ProSe services through the PC5 interface.
[0118] Securely distribute the configured default PC5 security policy to the UE.
[0119] When multiple PC5 security policies are configured on the UE, such as a default PC5 security policy and a specific PC5 security policy, it is necessary to select which PC5 security policy to use.
[0120] Specific PC5 security policies are tied to specific ProSe services.
[0121] The default PC5 security policy is not specifically bound to any particular ProSe service. This security policy is used when the ProSe service provider does not provide a PC5 security policy for a specific ProSe service.
[0122] The configuration of a specific PC5 security policy is based on the actual security requirements of a specific ProSe service. Depending on the specific PC5 security policy, there are options for encryption and integrity protection, namely "REQUIRED", "PREFERRED", and "NOT NEEDED".
[0123] The default PC5 security policy configuration is not based on the actual security requirements of specific ProSe services and can be determined by the operator supporting ProSe services. The default PC5 security policy can also provide "REQUIRED", "PREFERRED", and "NOT NEEDED" options for encryption and integrity protection, respectively.
[0124] The PCF or ProSe application server can provide specific PC5 security policies for the terminal. Policy delivery is protected by Non-Access Stratum (NAS) security. If the ProSe service provider does not offer this type of PC5 security policy, then this specific PC5 security policy may not be provided to the UE.
[0125] The default PC5 security policy can be pre-configured on the UE or distributed to the terminal by the PCF. The distributed policy is protected by NAS security. This type of PC5 security policy can be configured by the operator and provided to the UE by the PCF.
[0126] Because of the introduction of different types of PC5 security policies, a ProSe UE may be configured with different types of PC5 security policies simultaneously before establishing a PC5 connection with other UEs. The UE needs to determine the security policy to use when communicating directly with the peer UE based on the priority of the different PC5 security policy types.
[0127] Specific PC5 security policies have a higher priority than the default PC5 security policy.
[0128] If only the default PC5 security policy is configured on the UE, the default PC5 security policy will be used when the UE establishes a PC5 connection.
[0129] If both the PC5 security policy and the default PC5 security policy are configured on the UE, the specific PC5 security policy will be used.
[0130] like Figure 6 As shown, this disclosure provides an information processing apparatus, wherein the apparatus includes:
[0131] The acquisition module 110 is configured to acquire a default PC5 security policy, wherein the default PC5 security policy is used to protect the PC5 connection of the target ProSe service when a specific PC5 security policy based on the target ProSe service is not acquired.
[0132] The information processing device may be included in the first UE.
[0133] In one embodiment, the acquisition module 110 includes, but is not limited to, a program module; after being executed by the processor, the program module can realize the functions of the above-mentioned modules.
[0134] In some embodiments, the acquisition module 110 may be a hardware-software hybrid module; the hardware-software hybrid module includes, but is not limited to, a programmable array; the programmable array includes, but is not limited to, field-programmable arrays and / or complex programmable arrays.
[0135] In some embodiments, the acquisition module 110 may be a pure hardware module; the pure hardware module includes, but is not limited to, an application-specific integrated circuit.
[0136] In some embodiments, the apparatus further includes:
[0137] The protection module is configured to protect the PC5 connection based on the target ProSe service according to the specific PC5 security policy when the specific PC5 security policy of the target ProSe service is obtained.
[0138] In some embodiments, the device includes:
[0139] The receiving module is configured to receive a specific PC5 security policy for the target ProSe service from the Policy Control Function (PCF); or, to receive a specific PC5 security policy for the target ProSe service from the ProSe application server.
[0140] In some embodiments, the specific PC5 security policy differs for different ProSe services.
[0141] In some embodiments, the specific PC5 security policy of the target ProSe service is determined based on the security requirements of the target ProSe service.
[0142] In some embodiments, the default PC5 security policy is pre-configured within the first UE;
[0143] or,
[0144] The default PC5 security policy is received from PCF.
[0145] In some embodiments, the apparatus further includes:
[0146] The negotiation module is configured to negotiate with the second UE, based on the default PC5 security policy or a specific PC5 security policy, the security parameters for protecting the PC5 connection of the target ProSe service.
[0147] In some embodiments, the default PC5 security policy includes:
[0148] Default security protection requirements for any ProSe service.
[0149] In some embodiments, the specific PC5 security policy has a higher priority than the default PC5 security policy.
[0150] like Figure 7 As shown, this disclosure provides an information processing apparatus, wherein the apparatus includes:
[0151] The first configuration module 210 is configured to configure a default PC5 security policy, wherein the default PC5 security policy is used to protect the PC5 connection of the target ProSe service when the specific PC5 security policy of the target ProSe service based on proximity is not obtained.
[0152] The information processing device may be included in the PCF.
[0153] In one embodiment, the first configuration module 210 includes, but is not limited to, a program module; after being executed by the processor, the program module can realize the functions of the above-mentioned modules.
[0154] In some embodiments, the first configuration module 210 may be a hardware-software hybrid module; the hardware-software hybrid module includes, but is not limited to, a programmable array; the programmable array includes, but is not limited to, field-programmable arrays and / or complex programmable arrays.
[0155] In some embodiments, the first configuration module 210 may be a pure hardware module; the pure hardware module includes, but is not limited to, an application-specific integrated circuit.
[0156] In some embodiments, the apparatus further includes:
[0157] The second sending module is configured to send the default PC5 security policy to the UE.
[0158] In some embodiments, the apparatus further includes:
[0159] The second configuration module is configured to configure the specific PC5 security policy for the target ProSe service.
[0160] In some embodiments, the specific PC5 security policy has a higher priority than the default PC5 security policy.
[0161] In some embodiments, the default PC5 security policy includes:
[0162] Default security protection requirements for any ProSe service.
[0163] This disclosure provides a communication device, including:
[0164] Memory used to store processor-executable instructions;
[0165] The processor is connected to the memory separately;
[0166] The processor is configured to execute the information processing method provided by any of the aforementioned technical solutions.
[0167] The processor may include various types of storage media, which are non-transitory computer storage media that can continue to store information after the communication device loses power.
[0168] Here, the communication equipment includes: UE or core network equipment. The core network equipment includes, but is not limited to, cables.
[0169] The processor can be connected to the memory via a bus or similar means to read executable programs stored in the memory, for example, such as... Figures 2 to 5 At least one of the methods shown.
[0170] Figure 8 This is a block diagram illustrating a UE800 according to an exemplary embodiment. For example, the UE800 may be a mobile phone, computer, digital broadcast user equipment, messaging transceiver, game console, tablet device, medical device, fitness equipment, personal digital assistant, etc.
[0171] Reference Figure 8 UE800 may include one or more of the following components: processing component 802, memory 804, power supply component 806, multimedia component 808, audio component 810, input / output (I / O) interface 812, sensor component 814, and communication component 816.
[0172] Processing component 802 typically controls the overall operation of UE 800, such as operations associated with display, telephone calls, data communication, camera operation, and recording. Processing component 802 may include one or more processors 820 to execute instructions to complete all or part of the steps of the methods described above. Furthermore, processing component 802 may include one or more modules to facilitate interaction between processing component 802 and other components. For example, processing component 802 may include a multimedia module to facilitate interaction between multimedia component 808 and processing component 802.
[0173] Memory 804 is configured to store various types of data to support operation on UE 800. Examples of this data include instructions for any application or method operating on UE 800, contact data, phonebook data, messages, pictures, videos, etc. Memory 804 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk.
[0174] Power supply component 806 provides power to various components of UE800. Power supply component 806 may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power to UE800.
[0175] The multimedia component 808 includes a screen that provides an output interface between the UE 800 and the user. In some embodiments, the screen may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen may be implemented as a touchscreen to receive input signals from the user. The touch panel includes one or more touch sensors to sense touches, swipes, and gestures on the touch panel. The touch sensors may sense not only the boundaries of the touch or swipe action but also the duration and pressure associated with the touch or swipe operation. In some embodiments, the multimedia component 808 includes a front-facing camera and / or a rear-facing camera. When the UE 800 is in an operating mode, such as a shooting mode or a video mode, the front-facing camera and / or the rear-facing camera may receive external multimedia data. Each front-facing camera and rear-facing camera may be a fixed optical lens system or have focal length and optical zoom capabilities.
[0176] Audio component 810 is configured to output and / or input audio signals. For example, audio component 810 includes a microphone (MIC) configured to receive external audio signals when UE 800 is in an operating mode, such as call mode, recording mode, and voice recognition mode. The received audio signals may be further stored in memory 804 or transmitted via communication component 816. In some embodiments, audio component 810 also includes a speaker for outputting audio signals.
[0177] I / O interface 812 provides an interface between processing component 802 and peripheral interface modules, such as keyboards, click wheels, buttons, etc. These buttons may include, but are not limited to, home buttons, volume buttons, power buttons, and lock buttons.
[0178] Sensor assembly 814 includes one or more sensors for providing status assessments of various aspects of UE 800. For example, sensor assembly 814 can detect the on / off state of UE 800, the relative positioning of components such as the display and keypad of UE 800, changes in the position of UE 800 or one of its components, the presence or absence of user contact with UE 800, the orientation or acceleration / deceleration of UE 800, and temperature changes of UE 800. Sensor assembly 814 may include a proximity sensor configured to detect the presence of nearby objects without any physical contact. Sensor assembly 814 may also include a light sensor, such as a CMOS or CCD image sensor, for use in imaging applications. In some embodiments, sensor assembly 814 may also include an accelerometer, a gyroscope, a magnetometer, a pressure sensor, or a temperature sensor.
[0179] Communication component 816 is configured to facilitate wired or wireless communication between UE 800 and other devices. UE 800 can access wireless networks based on communication standards, such as WiFi, 2G, or 3G, or combinations thereof. In one exemplary embodiment, communication component 816 receives broadcast signals or broadcast-related information from an external broadcast management system via a broadcast channel. In one exemplary embodiment, communication component 816 also includes a near-field communication (NFC) module to facilitate short-range communication. For example, the NFC module may be implemented based on radio frequency identification (RFID) technology, Infrared Data Association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology, and other technologies.
[0180] In an exemplary embodiment, UE800 may be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components to perform the methods described above.
[0181] In an exemplary embodiment, a non-transitory computer-readable storage medium including instructions is also provided, such as a memory 804 including instructions, which can be executed by the processor 820 of the UE 800 to perform the above-described method. For example, the non-transitory computer-readable storage medium may be a ROM, random access memory (RAM), CD-ROM, magnetic tape, floppy disk, and optical data storage device, etc.
[0182] like Figure 9As shown in the illustration, one embodiment of this disclosure illustrates the structure of an access device. For example, the communication device 900 can be provided as a network-side device. This communication device can be the aforementioned core network device. The core network device includes, but is not limited to, the PCF.
[0183] Reference Figure 9 The communication device 900 includes a processing component 922, which further includes one or more processors, and memory resources represented by a memory 932 for storing instructions executable by the processing component 922, such as application programs. The application programs stored in the memory 932 may include one or more modules, each corresponding to a set of instructions. Furthermore, the processing component 922 is configured to execute instructions to perform any of the aforementioned methods applied to the access device, such as... Figures 2 to 5 The method shown.
[0184] The communication device 900 may further include: a power supply component 1926 configured to perform power management of the communication device 900; a wired or wireless network interface 950 configured to connect the communication device 900 to a network; and an input / output (I / O) interface 958. The communication device 900 can operate an operating system stored in memory 932, such as Windows Server™, Mac OS X™, Unix™, Linux™, FreeBSD™, or similar.
[0185] Other embodiments of the invention will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of the invention that follow the general principles of the invention and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of the invention are indicated by the following claims.
[0186] It should be understood that the present invention is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of the invention is limited only by the appended claims.
Claims
1. An information processing method, wherein, A method performed by a first user equipment, UE, the method comprising: obtaining a default PC5 security policy, wherein the default PC5 security policy is used to protect a PC5 connection for a target proximity-based services, ProSe, service when a specific PC5 security policy for the target ProSe service is not obtained; receiving a specific PC5 security policy for the target ProSe service from a ProSe application server; protecting a PC5 connection for the target ProSe service according to the specific PC5 security policy when the specific PC5 security policy for the target ProSe service is obtained; negotiating, with a second UE, security parameters for protecting the PC5 connection for the target ProSe service according to the default PC5 security policy or the specific PC5 security policy; wherein the security parameters comprise at least one of: a first parameter indicating whether PC5 signaling is encrypted; a second parameter indicating whether PC5 data is encrypted; a third parameter indicating whether PC5 signaling needs integrity protection; a fourth parameter indicating whether PC5 data needs integrity protection.
2. The method of claim 1, wherein, The specific PC5 security policy for different ProSe services is different.
3. The method of claim 1, wherein, The specific PC5 security policy for the target ProSe service is determined according to security requirements of the target ProSe service.
4. The method of claim 1, wherein, The default PC5 security policy is pre-configured in the first UE. Alternatively, The default PC5 security policy is received from a PCF.
5. The method of claim 1, wherein, The default PC5 security policy comprises: a default security protection requirement for any ProSe service.
6. The method according to any one of claims 1 to 5, wherein, The specific PC5 security policy has a higher priority than the default PC5 security policy.
7. An information processing method, wherein, A method performed by a PCF, the method comprising: configuring a default PC5 security policy, wherein the default PC5 security policy is used to protect a PC5 connection for a target proximity-based services, ProSe, service when a specific PC5 security policy for the target ProSe service is not obtained by a first user equipment, UE; wherein the specific PC5 security policy for the target ProSe service is received by the first UE from a ProSe application server; wherein the default PC5 security policy or the specific PC5 security policy is used for the first UE to negotiate security parameters for protecting the PC5 connection for the target ProSe service with a second UE; wherein the security parameters comprise at least one of: a first parameter indicating whether PC5 signaling is encrypted; a second parameter indicating whether PC5 data is encrypted; a third parameter indicating whether PC5 signaling needs integrity protection; a fourth parameter indicating whether PC5 data needs integrity protection.
8. The method of claim 7, wherein, The method further comprises: sending the default PC5 security policy to the UE.
9. The method of claim 7, wherein, The method further comprises: configuring the specific PC5 security policy for the target ProSe service.
10. The method of claim 7, wherein, The specific PC5 security policy has a higher priority than the default PC5 security policy.
11. The method according to any one of claims 7 to 10, wherein, The default PC5 security policy comprises: a default security protection requirement for any ProSe service.
12. An information processing apparatus, comprising: The apparatus comprises: obtaining a default PC5 security policy, wherein the default PC5 security policy is used to protect a PC5 connection of a target ProSe service when a specific PC5 security policy for the target ProSe service is not obtained; receiving the specific PC5 security policy for the target ProSe service from a ProSe application server; protecting the PC5 connection of the target ProSe service according to the specific PC5 security policy when the specific PC5 security policy for the target ProSe service is obtained; negotiating, with a second UE, a security parameter for protecting the PC5 connection of the target ProSe service according to the default PC5 security policy or the specific PC5 security policy; wherein the security parameter comprises at least one of: a first parameter indicating whether PC5 signaling is encrypted; a second parameter indicating whether PC5 data is encrypted; a third parameter indicating whether PC5 signaling needs integrity protection; a fourth parameter indicating whether PC5 data needs integrity protection.
13. The apparatus of claim 12, wherein, The specific PC5 security policy for different ProSe services is different.
14. The apparatus of claim 12, wherein, The specific PC5 security policy for the target ProSe service is determined according to a security requirement of the target ProSe service.
15. The apparatus of claim 12, wherein, The default PC5 security policy is pre-configured in the first UE. Alternatively, The default PC5 security policy is received from a PCF.
16. The apparatus of claim 12, wherein, The default PC5 security policy comprises: a default security protection requirement for any ProSe service.
17. The apparatus of any one of claims 12 to 16, wherein, The priority of the specific PC5 security policy is higher than that of the default PC5 security policy.
18. An information processing apparatus, comprising: The apparatus comprises: a first configuration module configured to configure a default PC5 security policy, wherein the default PC5 security policy is used to protect a PC5 connection of a target ProSe service when a specific PC5 security policy for the target ProSe service is not obtained by a first user equipment (UE); wherein the specific PC5 security policy for the target ProSe service is received by the first UE from a ProSe application server; wherein the specific PC5 security policy for the target ProSe service is received by the first UE from a ProSe application server; wherein the default PC5 security policy or the specific PC5 security policy is used for the first UE to negotiate, with a second UE, a security parameter for protecting the PC5 connection of the target ProSe service; wherein the security parameter comprises at least one of: a first parameter indicating whether PC5 signaling is encrypted; a second parameter indicating whether PC5 data is encrypted; a third parameter indicating whether PC5 signaling needs integrity protection; a fourth parameter indicating whether PC5 data needs integrity protection.
19. The apparatus of claim 18, wherein, The apparatus further comprises: a second sending module configured to send the default PC5 security policy to a UE.
20. The apparatus of claim 18, wherein, The apparatus further comprises: a second configuration module configured to configure the specific PC5 security policy for the target ProSe service.
21. The apparatus of claim 18, wherein, The priority of the specific PC5 security policy is higher than the default PC5 security policy.
22. The apparatus of any one of claims 18 to 21, wherein, The default PC5 security policy comprises: A default security protection requirement for any ProSe service.
23. A communication device comprising a processor, a transceiver, a memory, and an executable program stored on the memory and executable by the processor, wherein, The processor, when running the executable program, performs the method of any one of claims 1 to 6 or 7 to 11. 24.A computer storage medium, storing an executable program;The executable program, when executed by a processor, can implement the method of any one of claims 1 to 6 or 7 to 11.
Citation Information
Patent Citations
Method and apparatus for handling security policies in v2x communication system
US20210258793A1