Communication method, device and system
By obtaining the user plane security protection activation indication through the management device or session management entity, the problem of inconsistent user plane security protection in C2 communication between UAV and UAVC is solved, the unification of security and efficiency is achieved, and the C2 communication security and transmission efficiency between UAV and UAVC are ensured.
Patent Information
- Application Number
- CN202080107200.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-11-18
- Publication Date
- 2025-10-14
- Estimated Expiration
- 2040-11-18
AI Technical Summary
In C2 communication between UAV and UAVC, existing technologies cannot guarantee the consistency of user plane security protection, resulting in security or transmission efficiency issues.
Obtain a user plane security protection activation indication through a management device or session management entity to ensure consistency of user plane security protection for the first and second sessions, including activation or deactivation of confidentiality and integrity protection, and trigger session establishment based on the indication.
The consistency of user plane security protection of C2 communication between UAV and UAVC is achieved, which improves the security and transmission efficiency of communication and avoids the contradiction between security and efficiency.
Smart Images

Figure CN116671235B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technologies, and in particular to communication methods, devices, and systems. Background Art
[0002] In the current discussion of unmanned aerial systems enabled by fifth-generation (5G) wireless communication networks, an unmanned aerial system (UAS) includes an unmanned aerial vehicle (UAV) and a UAV controller (UAVC). The UAV and UAVC establish a command and control (C2) communication process, establishing a first protocol data unit (PDU) session for the UAV to carry C2 communications and a second PDU session for the UAVC to carry C2 communications. The UAS traffic management (UTM) / UAS service provider (USS) associates the first PDU session with the second PDU session to implement C2 communications between the UAV and UAVC. Of course, if either the UAV or UAVC already has a PDU session for carrying non-C2 communications with the UAS, the session management function (SMF) serving it can modify the PDU session for carrying non-C2 communications with the UAS to meet the requirements for C2 communications.
[0003] The current standardization discussions have not yet addressed the security issues surrounding the C2 communication establishment process between UAVs and UAVCs. Therefore, in scenarios where the UAVC controls the flight of the UAV, the user plane security protection activation method for C2 communication on the UAV segment may be inconsistent with the user plane security protection activation method for C2 communication on the UAVC segment. Furthermore, in scenarios where C2 communication requires a certain level of security, an attacker could interfere with the entire C2 communication between the UAV and UAVC through the end that does not have security protection enabled, thereby reducing the security of C2 communication. Alternatively, in scenarios where C2 communication requires transmission efficiency, the end that has security protection enabled could affect the transmission efficiency of the entire C2. In summary, ensuring the consistency of user plane security for C2 communication between UAVs and UAVCs is a pressing issue. Summary of the Invention
[0004] The embodiments of the present application provide a communication method, apparatus, and system for solving the problem that the user plane security consistency of C2 communication between UAV and UAVC cannot be guaranteed at present.
[0005] To achieve the above objectives, the embodiments of the present application adopt the following technical solutions:
[0006] In the first aspect, a communication method is provided, and the communication device that executes the communication method can be a management device or a module applied to the management device, such as a chip or a chip system. The following description is made by taking the execution subject as the management device as an example. The management device obtains a first user plane security protection activation indication, and the first user plane security protection activation indication is used to indicate whether the user plane security protection of the first session is activated; wherein, the first session is a session used by the first terminal device to carry C2 communication, the first terminal device is the initiating end device of the C2 communication, the second terminal device is the opposite end device of the C2 communication, and the C2 communication is the communication between the first terminal device and the second terminal device; the management device triggers the second terminal device to initiate the establishment of a second session, wherein whether the user plane security protection of the second session is activated is determined by the first user plane security protection activation indication, and the second session is a session used by the second terminal device to carry the C2 communication. In this solution, the management device can obtain the first user plane security protection activation indication and trigger the second terminal device to initiate the establishment of the second session. Among them, whether the user plane security protection of the second session is turned on is determined by the first user plane security protection turn-on indication, and the first user plane security protection turn-on indication is used to indicate whether the user plane security protection of the first session is turned on. In other words, whether the user plane security protection of the first session is turned on and whether the user plane security protection of the second session is turned on are both determined by the first user plane security protection turn-on indication. Since the first session is a session used by the first terminal device to carry C2 communication, and the second session is a session used by the second terminal device to carry C2 communication, and the C2 communication is the communication between the first terminal device and the second terminal device, based on this solution, the consistency of the user plane security protection of the C2 communication between the first terminal device and the second terminal device can be guaranteed.
[0007] It should be noted that in the embodiments of the present application, the first user plane security protection activation indication can also be understood as a first user plane security protection activation result indication. The first user plane security protection activation result indication may, for example, include a first user plane confidentiality protection activation result indication and a first user plane integrity protection activation result indication. The first user plane confidentiality protection activation result indication is used to indicate whether user plane confidentiality protection is enabled or disabled; the first user plane integrity protection activation result indication is used to indicate whether user plane integrity protection is enabled or disabled. This description applies to all embodiments of the present application and is therefore uniformly described here and will not be repeated below.
[0008] In combination with the above-mentioned first aspect, in a possible implementation method, the management device triggers the second terminal device to initiate the establishment of the second session, including: the management device sends a first message to the second terminal device, and the first message is used to trigger the second terminal device to initiate the establishment of the second session; and the management device sends the first user plane security protection activation indication to the second unified data management entity, wherein the second unified data management entity is a unified data management entity serving the second terminal device. Based on this scheme, the second unified data management entity serving the second terminal device can obtain the first user plane security protection activation indication from the management device. Furthermore, in the process of establishing the second session, the second session management entity serving the second terminal device can obtain the first user plane security protection activation indication from the second unified data management entity. The first user plane security protection activation indication is used to determine whether the user plane security protection of the second session is activated.
[0009] In conjunction with the first aspect above, in one possible implementation, the management device triggers the second terminal device to initiate establishment of a second session, including: the management device sends a first message to the second terminal device, the first message being used to trigger the second terminal device to initiate establishment of the second session; and the management device receives a second message from a second proxy function entity and sends the first user plane security protection activation indication to the second proxy function entity; wherein the second message includes identification information of the second terminal device, the second message is used to request the first user plane security protection activation indication, the second proxy function entity is used to provide an interface from a second session management entity to the management device, and the second session management entity is a session management entity serving the second terminal device. Based on this solution, the second session management entity serving the second terminal device can obtain the first user plane security protection activation indication from the management device via the second proxy function entity. The first user plane security protection activation indication is used to determine whether user plane security protection for the second session is activated.
[0010] In conjunction with the first aspect above, in one possible implementation, the management device obtaining the first user plane security protection on indication includes: the management device receiving the first user plane security protection on indication from a first session management entity, where the first session management entity is a session management entity serving the first terminal device. That is, the management device may obtain the first user plane security protection on indication via a control plane between the first terminal device and the management device.
[0011] In conjunction with the first aspect above, in one possible implementation, the management device obtaining the first user plane security protection activation indication includes: the management device receiving the first user plane security protection activation indication from the first terminal device. That is, the management device may obtain the first user plane security protection activation indication via the user plane between the first terminal device and the management device.
[0012] In conjunction with the first aspect above, in one possible implementation, the management device obtaining the first user plane security protection enable indication includes: the management device receiving the first user plane security protection enable indication from a first proxy function entity, where the first proxy function entity is configured to provide an interface between the first session management entity and the management device. That is, the management device may obtain the first user plane security protection enable indication from the first proxy function entity that is configured to provide the interface between the first session management entity and the management device.
[0013] In conjunction with the first aspect above, in one possible implementation, the management device obtains the first user plane security protection activation indication, including: the management device determines that pairing authorization between the first terminal device and the second terminal device is successful; the management device sends a third message to a first proxy function entity, the third message including identification information of the first terminal device, and the third message is used to request the first user plane security protection activation indication; wherein the first proxy function entity is used to provide an interface between a first session management entity and the management device, the first session management entity being a session management entity serving the first terminal device; and the management device receives the first user plane security protection activation indication from the first proxy function entity. That is, the management device can obtain the first user plane security protection activation indication via the first proxy function entity used to provide the interface between the first session management entity and the management device based on triggering of the pairing authorization process.
[0014] In a second aspect, a communication method is provided. The communication device executing the communication method can be a first session management entity or a module implemented in the first session management entity, such as a chip or chip system. The following description uses the first session management entity as an example. The first session management entity obtains a first user plane security protection enablement indication, which indicates whether user plane security protection is enabled for a first session. The first session is a session used by a first terminal device to carry C2 communication, the first terminal device is the initiator of the C2 communication, and the second terminal device is the peer device of the C2 communication. The C2 communication is communication between the first terminal device and the second terminal device, and the first session management entity is the session management entity serving the first terminal device. The first session management entity sends the first user plane security protection enablement indication, which is used to determine whether user plane security protection is enabled for a second session, the second session being a session used by the second terminal device to carry the C2 communication. In this solution, the first session management entity obtains the first user plane security protection enablement indication and sends the first user plane security protection enablement indication. Among them, the first user plane security protection on indication is used to determine whether the user plane security protection of the second session is on, and the first user plane security protection on indication is used to indicate whether the user plane security protection of the first session is on. In other words, whether the user plane security protection of the first session is on and whether the user plane security protection of the second session is on are both determined by the first user plane security protection on indication. Since the first session is a session used by the first terminal device to carry C2 communication, the second session is a session used by the second terminal device to carry the C2 communication, and the C2 communication is the communication between the first terminal device and the second terminal device, based on this solution, the consistency of the user plane security protection of the C2 communication between the first terminal device and the second terminal device can be guaranteed.
[0015] In combination with the second aspect above, in a possible implementation manner, the first session management entity sending the first user plane security protection activation indication includes: the first session management entity sending the first user plane security protection activation indication to the management device.
[0016] In combination with the above-mentioned second aspect, in a possible implementation method, the first session management entity sends the first user plane security protection activation indication, including: the first session management entity sends the first user plane security protection activation indication to the first proxy function entity; wherein, the first proxy function entity is used to provide the first session management entity with an interface to the management device.
[0017] In combination with the above-mentioned second aspect, in a possible implementation method, before the first session management entity sends the first user plane security protection activation indication to the first proxy function entity, the method also includes: the first session management entity receives a fourth message from the first proxy function entity, the fourth message including the identification information of the first terminal device, and the fourth message is used to request the first user plane security protection activation indication.
[0018] In conjunction with the second aspect above, in one possible implementation, the first session management entity obtains a first user plane security protection enablement indication, including: the first session management entity obtains a first user plane security protection policy from a first unified data management entity serving the first terminal device; the first session management entity sends the first user plane security protection policy to a first access network device serving the first terminal device; and the first session management entity receives the first user plane security protection enablement indication from the first access network device, wherein the first user plane security protection enablement indication is determined based on the first user plane security protection policy. For example, when the first user plane security protection policy is to enable optional security protection, the first access network device may determine the first user plane security protection enablement indication based on the first user plane security protection policy (which may be combined with other information, such as resource usage on the first access network device or the maximum integrity protection rate supported by the first terminal device) and send the first user plane security protection enablement indication to the first session management entity. A possible embodiment is that the first user plane security protection policy includes user plane confidentiality protection as optional activation (PREFERRED) and user plane integrity protection as optional activation; the first access network device is currently relatively idle and has sufficient resources to provide security protection for the user plane data of the first terminal device, then the first access network device can activate user plane confidentiality protection and user plane integrity protection, and send a first user plane security protection activation indication to the first session management entity, at this time, the first user plane security protection activation indication is used to indicate the activation of user plane confidentiality protection and user plane integrity protection.
[0019] In conjunction with the second aspect, in one possible implementation, a first session management entity obtains a first user plane security protection enablement indication, including: the first session management entity obtains a first user plane security protection policy from a first unified data management entity serving the first terminal device; the first session management entity sends the first user plane security protection policy to a first access network device serving the first terminal device; the first session management entity receives a seventh message from the first access network device, the seventh message being used to indicate that the first access network device has established a first session in accordance with the first user plane security protection policy; and in response to the seventh message, the first session management entity determines the first user plane security protection enablement indication based on the first user plane security protection policy. For example, when the first user plane security protection policy includes user plane confidentiality protection as required / not needed and user plane integrity protection as required / not needed, then when the first session management entity receives the seventh message from the first access network device, it can accurately determine whether user plane confidentiality protection and user plane integrity protection are enabled based on the first user plane security protection policy. For example, if the first user plane security protection policy includes user plane confidentiality protection as mandatory on and user plane integrity protection as mandatory on, then it is determined to enable user plane confidentiality protection and enable user plane integrity protection. For another example, if the first user plane security protection policy includes user plane confidentiality protection as mandatory off and user plane integrity protection as mandatory off, then it is determined not to enable user plane confidentiality protection and not to enable user plane integrity protection. Other situations are similar and will not be described in detail. In other words, when the first user plane security protection policy is a deterministic policy (for example, user plane confidentiality protection is mandatory on / mandatory off and user plane integrity protection is mandatory on / mandatory off), the first access network device does not need to explicitly notify the first session management entity of the user plane security enabling result. When the first session management entity determines that the session has been established, it can determine whether the user plane confidentiality protection and user plane integrity protection are enabled based on the first user plane security protection policy.
[0020] In a third aspect, a communication method is provided. The communication device executing the communication method can be a second session management entity or a module applied to the second session management entity, such as a chip or chip system. The following description takes the execution subject as the second session management entity as an example. The second session management entity obtains a first user plane security protection activation indication, where the first user plane security protection activation indication is used to indicate whether user plane security protection is activated for a first session; wherein the first session is a session used by a first terminal device to carry C2 communication, the first terminal device is the initiator of the C2 communication, the second terminal device is the counterpart device of the C2 communication, the C2 communication is communication between the first terminal device and the second terminal device, and the second session management entity is a session management entity serving the second terminal device; the second session management entity sends the first user plane security protection activation indication to a second access network device serving the second terminal device; wherein the first user plane security protection activation indication is used to determine whether user plane security protection is activated for a second session, where the second session is a session used by the second terminal device to carry the C2 communication. In this solution, the first user plane security protection on indication is used to determine whether the user plane security protection of the second session is on, and at the same time, the first user plane security protection on indication is used to indicate whether the user plane security protection of the first session is on. In other words, whether the user plane security protection of the first session is on and whether the user plane security protection of the second session is on are both determined by the first user plane security protection on indication. Since the first session is a session used by the first terminal device to carry C2 communication, the second session is a session used by the second terminal device to carry the C2 communication, and the C2 communication is the communication between the first terminal device and the second terminal device, based on this solution, the consistency of the user plane security protection of the C2 communication between the first terminal device and the second terminal device can be guaranteed.
[0021] In a fourth aspect, a communication method is provided. The communication device executing the communication method may be a second session management entity or a module implemented in the second session management entity, such as a chip or chip system. The following description will be based on the second session management entity as an example. The second session management entity obtains a first user plane security protection enable indication, where the first user plane security protection enable indication is used to indicate whether user plane security protection is enabled for a first session; wherein the first session is a session used by a first terminal device to carry C2 communication, the first terminal device is an initiator device of the C2 communication, the second terminal device is a peer device of the C2 communication, the C2 communication is communication between the first terminal device and the second terminal device, and the second session management entity is a session management entity serving the second terminal device; the second session management entity determines a third user plane security protection policy based on the first user plane security protection enable indication, where the third user plane security protection policy only includes forcibly enabling security protection or forcibly not enabling security protection; the second session management entity sends the third user plane security protection policy to a second access network device serving the second terminal device; wherein the third user plane security protection policy is used to determine the second user plane security protection enable indication, where the second user plane security protection enable indication is used to determine whether user plane security protection is enabled for a second session, where the second session is a session used by the second terminal device to carry the C2 communication. In this solution, the third user plane security protection policy is used to determine the second user plane security protection activation indication indicating whether the user plane security protection of the second session is activated, and the third user plane security protection policy is determined by the first user plane security protection activation indication indicating whether the user plane security protection of the first session is activated, and the third user plane security protection policy only includes forcibly activating security protection or forcibly not activating security protection. In other words, whether the user plane security protection of the first session is activated and whether the user plane security protection of the second session is activated are both determined by the first user plane security protection activation indication. Since the first session is a session used by the first terminal device to carry C2 communication, and the second session is a session used by the second terminal device to carry the C2 communication, and the C2 communication is the communication between the first terminal device and the second terminal device, based on this solution, the consistency of the user plane security protection of the C2 communication between the first terminal device and the second terminal device can be guaranteed.
[0022] It should be noted that in the embodiments of the present application, the second user plane security protection activation indication can also be understood as a second user plane security protection activation result indication. The second user plane security protection activation result indication may, for example, include a second user plane confidentiality protection activation result indication and a second user plane integrity protection activation result indication. The second user plane confidentiality protection activation result indication is used to indicate whether user plane confidentiality protection is enabled or disabled; the second user plane integrity protection activation result indication is used to indicate whether user plane integrity protection is enabled or disabled. This description applies to all embodiments of the present application and is therefore uniformly described here and will not be repeated below.
[0023] In combination with the above-mentioned fourth aspect, in a possible implementation manner, the second session management entity determines a third user plane security protection policy based on the first user plane security protection activation indication, including: when the first user plane security protection activation indication includes a first user plane confidentiality protection activation result indication and a first user plane integrity protection activation result indication, and the first user plane confidentiality protection activation result indication is used to indicate that user plane confidentiality protection is activated, and the first user plane integrity protection activation result indication is used to indicate that user plane integrity protection is activated, the second session management entity determines that the third user plane security protection policy includes user plane confidentiality protection is forcibly activated and user plane integrity protection is forcibly activated; or when the first user plane security protection activation indication includes a first user plane confidentiality protection activation result indication and a first user plane integrity protection activation result indication, and the first user plane confidentiality protection activation result indication is used to indicate that user plane confidentiality protection is not activated, and the first user plane integrity protection activation result indication is used to indicate that user plane integrity protection is not activated, the second session management entity determines that the third user plane security protection policy includes user plane confidentiality protection is forcibly not activated and user plane integrity protection is forcibly not activated. When the first user plane security protection activation indication includes a first user plane confidentiality protection activation result indication and a first user plane integrity protection activation result indication, and the first user plane confidentiality protection activation result indication is used to indicate that user plane confidentiality protection is not activated, and the first user plane integrity protection activation result indication is used to indicate that user plane integrity protection is activated, the second session management entity determines that the third user plane security protection policy includes that user plane confidentiality protection is forcibly not activated and user plane integrity protection is forcibly activated; or, when the first user plane security protection activation indication includes a first user plane confidentiality protection activation result indication and a first user plane integrity protection activation result indication, and the first user plane confidentiality protection activation result indication is used to indicate that user plane confidentiality protection is activated, and the first user plane integrity protection activation result indication is used to indicate that user plane integrity protection is not activated, the second session management entity determines that the third user plane security protection policy includes that user plane confidentiality protection is forcibly activated and user plane integrity protection is forcibly not activated.
[0024] In a possible implementation manner of the third aspect or the fourth aspect, the second session management entity obtaining the first user plane security protection start indication comprises: the second session management entity sending a fifth message to a second unified data management entity serving the second terminal device, the fifth message comprising identification information of the second terminal device, the fifth message being used for requesting a second user plane security protection policy; and the second session management entity receiving the second user plane security protection policy and the first user plane security protection start indication from the second unified data management entity. That is, the second session management entity can obtain the first user plane security protection start indication from the second unified data management entity serving the second terminal device.
[0025] In a possible implementation manner of the third aspect or the fourth aspect, the second session management entity obtaining the first user plane security protection start indication comprises: the second session management entity sending a sixth message to a second proxy function entity, the sixth message comprising identification information of the second terminal device, the sixth message being used for requesting the first user plane security protection start indication, the second proxy function entity being used for providing an interface of the second session management entity to a management device; and the second session management entity receiving the first user plane security protection start indication from the second proxy function entity. That is, the second session management entity can obtain the first user plane security protection start indication from the management device through the second proxy function entity used for providing the interface of the second session management entity to the management device.
[0026] In a possible implementation manner of the third aspect or the fourth aspect, before the second session management entity sends the sixth message to the second proxy function entity, the method further comprises: the second session management entity receiving indication information from the second terminal device, the indication information indicating that the second terminal device requests the second session to be established for responding to the C2 communication initiated by the first terminal device. That is, the second session management entity can obtain the first user plane security protection start indication from the management device through the second proxy function entity used for providing the interface of the second session management entity to the management device after learning that the second terminal device requests the second session to be established for responding to the C2 communication initiated by the first terminal device.
[0027] In a fifth aspect, a communication device is provided for executing the method in the above-mentioned first aspect or any possible implementation of the first aspect. The communication device can be a management device in the above-mentioned first aspect or any possible implementation of the first aspect, or a module applied to a management device, such as a chip or a chip system. The communication device includes a module, unit, or means corresponding to the above-mentioned method, and the module, unit, or means can be implemented by hardware, software, or by executing the corresponding software implementation by hardware. The hardware or software includes one or more modules or units corresponding to the above-mentioned functions.
[0028] In combination with the above-mentioned fifth aspect, in a possible implementation method, the communication device includes a processing module and a transceiver module; the processing module is used to obtain a first user plane security protection activation indication, and the first user plane security protection activation indication is used to indicate whether the user plane security protection of the first session is activated; wherein, the first session is a session used by the first terminal device to carry C2 communication, the first terminal device is the initiating end device of the C2 communication, the second terminal device is the opposite end device of the C2 communication, and the C2 communication is the communication between the first terminal device and the second terminal device; the transceiver module is used to trigger the second terminal device to initiate the establishment of a second session, wherein whether the user plane security protection of the second session is activated is determined by the first user plane security protection activation indication, and the second session is a session used by the second terminal device to carry the C2 communication.
[0029] In combination with the above-mentioned fifth aspect, in a possible implementation method, the transceiver module is used to trigger the second terminal device to initiate the establishment of the second session, including: sending a first message to the second terminal device, the first message is used to trigger the second terminal device to initiate the establishment of the second session; and sending the first user plane security protection activation indication to the second unified data management entity, wherein the second unified data management entity is a unified data management entity serving the second terminal device.
[0030] In combination with the above-mentioned fifth aspect, in a possible implementation method, the transceiver module is used to trigger the second terminal device to initiate the establishment of a second session, including: sending a first message to the second terminal device, the first message is used to trigger the second terminal device to initiate the establishment of a second session; and, receiving a second message from the second proxy function entity, and sending the first user plane security protection activation indication to the second proxy function entity; wherein the second message includes the identification information of the second terminal device, the second message is used to request the first user plane security protection activation indication, and the second proxy function entity is used to provide an interface from the second session management entity to the management device, and the second session management entity is a session management entity serving the second terminal device.
[0031] In combination with the above-mentioned fifth aspect, in a possible implementation method, the processing module is specifically used to: receive the first user plane security protection activation indication from the first session management entity through the transceiver module, and the first session management entity is a session management entity serving the first terminal device; or, receive the first user plane security protection activation indication from the first terminal device through the transceiver module; or, receive the first user plane security protection activation indication from the first proxy function entity through the transceiver module, and the first proxy function entity is used to provide an interface between the first session management entity and the management device.
[0032] In combination with the above-mentioned fifth aspect, in a possible implementation method, the processing module is specifically used to: determine that the pairing authorization between the first terminal device and the second terminal device is successful; send a third message to the first proxy function entity through the transceiver module, and the third message includes the identification information of the first terminal device, and the third message is used to request the first user plane security protection activation indication; wherein, the first proxy function entity is used to provide an interface from the first session management entity to the management device, and the first session management entity is a session management entity serving the first terminal device; receive the first user plane security protection activation indication from the first proxy function entity through the transceiver module.
[0033] In combination with the above-mentioned fifth aspect, in a possible implementation method, the communication device includes a processor and a transceiver; the processor is used to obtain a first user plane security protection activation indication, and the first user plane security protection activation indication is used to indicate whether the user plane security protection of the first session is activated; wherein, the first session is a session used by the first terminal device to carry C2 communication, the first terminal device is the initiating end device of the C2 communication, the second terminal device is the opposite end device of the C2 communication, and the C2 communication is the communication between the first terminal device and the second terminal device; the transceiver is used to trigger the second terminal device to initiate the establishment of a second session, wherein whether the user plane security protection of the second session is activated is determined by the first user plane security protection activation indication, and the second session is a session used by the second terminal device to carry the C2 communication.
[0034] In combination with the above-mentioned fifth aspect, in a possible implementation method, the transceiver is used to trigger the second terminal device to initiate the establishment of the second session, including: sending a first message to the second terminal device, the first message is used to trigger the second terminal device to initiate the establishment of the second session; and sending the first user plane security protection activation indication to the second unified data management entity, wherein the second unified data management entity is a unified data management entity serving the second terminal device.
[0035] In combination with the above-mentioned fifth aspect, in a possible implementation method, the transceiver is used to trigger the second terminal device to initiate the establishment of a second session, including: sending a first message to the second terminal device, the first message is used to trigger the second terminal device to initiate the establishment of a second session; and, receiving a second message from the second proxy function entity, and sending the first user plane security protection activation indication to the second proxy function entity; wherein the second message includes the identification information of the second terminal device, the second message is used to request the first user plane security protection activation indication, and the second proxy function entity is used to provide an interface from the second session management entity to the management device, and the second session management entity is a session management entity serving the second terminal device.
[0036] In combination with the above-mentioned fifth aspect, in a possible implementation method, the processor is specifically used to: receive the first user plane security protection activation indication from the first session management entity through the transceiver, and the first session management entity is a session management entity serving the first terminal device; or, receive the first user plane security protection activation indication from the first terminal device through the transceiver; or, receive the first user plane security protection activation indication from the first proxy function entity through the transceiver, and the first proxy function entity is used to provide an interface between the first session management entity and the management device.
[0037] In combination with the above-mentioned fifth aspect, in a possible implementation method, the processor is specifically used to: determine that the pairing authorization between the first terminal device and the second terminal device is successful; send a third message to the first proxy function entity through the transceiver, the third message including the identification information of the first terminal device, and the third message is used to request the first user plane security protection activation indication; wherein, the first proxy function entity is used to provide an interface from the first session management entity to the management device, and the first session management entity is a session management entity serving the first terminal device; receive the first user plane security protection activation indication from the first proxy function entity through the transceiver.
[0038] Among them, the technical effects of the above-mentioned fifth aspect or any possible implementation method of the fifth aspect can refer to the above-mentioned first aspect and will not be repeated here.
[0039] In a sixth aspect, a communication device is provided for executing the method in the second aspect or any possible implementation of the second aspect. The communication device may be the first session management entity in the second aspect or any possible implementation of the second aspect, or a module applied to the first session management entity, such as a chip or a chip system. The communication device includes a module, unit, or means corresponding to the above method, and the module, unit, or means may be implemented by hardware, software, or by executing the corresponding software implementation by hardware. The hardware or software includes one or more modules or units corresponding to the above functions.
[0040] In combination with the above-mentioned sixth aspect, in a possible implementation method, the communication device includes a processing module and a transceiver module; the processing module is used to obtain a first user plane security protection activation indication, and the first user plane security protection activation indication is used to indicate whether the user plane security protection of the first session is activated; wherein, the first session is a session used by the first terminal device to carry C2 communication, the first terminal device is the initiating end device of the C2 communication, the second terminal device is the opposite end device of the C2 communication, the C2 communication is the communication between the first terminal device and the second terminal device, and the first session management entity is a session management entity serving the first terminal device; the transceiver module is used to send the first user plane security protection activation indication, and the first user plane security protection activation indication is used to determine whether the user plane security protection of the second session is activated, and the second session is the session used by the second terminal device to carry the C2 communication.
[0041] In combination with the sixth aspect above, in a possible implementation manner, the transceiver module is specifically used to: send the first user plane security protection activation indication to the management device.
[0042] In combination with the above-mentioned sixth aspect, in a possible implementation method, the transceiver module is specifically used to: send the first user plane security protection activation indication to the first proxy function entity; wherein, the first proxy function entity is used to provide the interface between the first session management entity and the management device.
[0043] In combination with the above-mentioned sixth aspect, in a possible implementation method, the transceiver module is also used to receive a fourth message from the first proxy function entity before the first session management entity sends the first user plane security protection activation indication to the first proxy function entity, and the fourth message includes the identification information of the first terminal device, and the fourth message is used to request the first user plane security protection activation indication.
[0044] In combination with the above-mentioned sixth aspect, in a possible implementation method, the processing module is specifically used to: obtain a first user plane security protection policy from a first unified data management entity serving the first terminal device; send the first user plane security protection policy to a first access network device serving the first terminal device through the transceiver module; receive the first user plane security protection activation indication from the first access network device through the transceiver module, wherein the first user plane security protection activation indication is determined based on the first user plane security protection policy.
[0045] In combination with the above-mentioned sixth aspect, in a possible implementation method, the processing module is specifically used to: obtain a first user plane security protection policy from a first unified data management entity serving the first terminal device; send the first user plane security protection policy to a first access network device serving the first terminal device through the transceiver module; after receiving a seventh message from the first access network device through the transceiver module, in response to the seventh message, determine a first user plane security protection activation indication according to the first user plane security protection policy, wherein the seventh message is used to indicate that the first access network device has established a first session according to the first user plane security protection policy.
[0046] In combination with the above-mentioned sixth aspect, in a possible implementation method, the communication device includes a processor and a transceiver; the processor is used to obtain a first user plane security protection activation indication, and the first user plane security protection activation indication is used to indicate whether the user plane security protection of the first session is activated; wherein, the first session is a session used by the first terminal device to carry C2 communication, the first terminal device is the initiating end device of the C2 communication, the second terminal device is the opposite end device of the C2 communication, the C2 communication is the communication between the first terminal device and the second terminal device, and the first session management entity is a session management entity serving the first terminal device; the transceiver is used to send the first user plane security protection activation indication, and the first user plane security protection activation indication is used to determine whether the user plane security protection of the second session is activated, and the second session is the session used by the second terminal device to carry the C2 communication.
[0047] In combination with the sixth aspect above, in a possible implementation manner, the transceiver is specifically used to: send the first user plane security protection activation indication to the management device.
[0048] In combination with the above-mentioned sixth aspect, in a possible implementation method, the transceiver is specifically used to: send the first user plane security protection activation indication to the first proxy function entity; wherein, the first proxy function entity is used to provide the interface between the first session management entity and the management device.
[0049] In combination with the above-mentioned sixth aspect, in a possible implementation method, the transceiver is also used to receive a fourth message from the first proxy function entity before the first session management entity sends the first user plane security protection activation indication to the first proxy function entity, and the fourth message includes the identification information of the first terminal device, and the fourth message is used to request the first user plane security protection activation indication.
[0050] In combination with the above-mentioned sixth aspect, in a possible implementation method, the processor is specifically used to: obtain a first user plane security protection policy from a first unified data management entity serving the first terminal device; send the first user plane security protection policy to a first access network device serving the first terminal device through the transceiver; receive the first user plane security protection activation indication from the first access network device through the transceiver, wherein the first user plane security protection activation indication is determined based on the first user plane security protection policy.
[0051] In combination with the above-mentioned sixth aspect, in a possible implementation method, the processor is specifically used to: obtain a first user plane security protection policy from a first unified data management entity serving the first terminal device; send the first user plane security protection policy to a first access network device serving the first terminal device through the transceiver; after receiving a seventh message from the first access network device through the transceiver, determine a first user plane security protection activation indication according to the first user plane security protection policy in response to the seventh message, wherein the seventh message is used to indicate that the first access network device has established a first session according to the first user plane security protection policy.
[0052] Among them, the technical effects of the above-mentioned sixth aspect or any possible implementation method of the sixth aspect can refer to the above-mentioned second aspect and will not be repeated here.
[0053] In a seventh aspect, a communication device is provided for executing the method in the third aspect or any possible implementation of the third aspect. The communication device may be the second session management entity in the third aspect or any possible implementation of the third aspect, or a module applied to the second session management entity, such as a chip or a chip system. The communication device includes a module, unit, or means corresponding to the above method, and the module, unit, or means may be implemented by hardware, software, or by executing the corresponding software implementation by hardware. The hardware or software includes one or more modules or units corresponding to the above functions.
[0054] In combination with the above-mentioned seventh aspect, in a possible implementation method, the communication device includes a processing module and a transceiver module; the processing module is used to obtain a first user plane security protection activation indication, and the first user plane security protection activation indication is used to indicate whether the user plane security protection of the first session is activated; wherein, the first session is a session used by the first terminal device to carry the C2 communication between the first terminal device and the second terminal device, the first terminal device is the initiating end device of the C2 communication, the second terminal device is the opposite end device of the C2 communication, and the second session management entity is a session management entity serving the second terminal device; the transceiver module is used to send the first user plane security protection activation indication to the second access network device serving the second terminal device; wherein, the first user plane security protection activation indication is used to determine whether the user plane security protection of the second session is activated, and the second session is a session used by the second terminal device to carry the C2 communication.
[0055] In combination with the above-mentioned seventh aspect, in a possible implementation method, the communication device includes a processor and a transceiver; the processor is used to obtain a first user plane security protection activation indication, and the first user plane security protection activation indication is used to indicate whether the user plane security protection of the first session is activated; wherein, the first session is a session used by the first terminal device to carry C2 communication, the first terminal device is the initiating end device of the C2 communication, the second terminal device is the opposite end device of the C2 communication, the C2 communication is the communication between the first terminal device and the second terminal device, and the second session management entity is the session management entity serving the second terminal device; the transceiver is used to send the first user plane security protection activation indication to the second access network device serving the second terminal device; wherein, the first user plane security protection activation indication is used to determine whether the user plane security protection of the second session is activated, and the second session is the session used by the second terminal device to carry the C2 communication.
[0056] In an eighth aspect, a communication device is provided for executing the method in the fourth aspect or any possible implementation of the fourth aspect. The communication device may be the second session management entity in the fourth aspect or any possible implementation of the fourth aspect, or a module applied to the second session management entity, such as a chip or a chip system. The communication device includes a module, unit, or means corresponding to the above method, and the module, unit, or means may be implemented by hardware, software, or by executing the corresponding software implementation by hardware. The hardware or software includes one or more modules or units corresponding to the above functions.
[0057] In combination with the eighth aspect above, in a possible implementation, the communication device includes a processing module and a transceiver module; the processing module is used to obtain a first user plane security protection activation indication, and the first user plane security protection activation indication is used to indicate whether the user plane security protection of the first session is activated; wherein the first session is a session used by the first terminal device to carry C2 communication, the first terminal device is the initiating end device of the C2 communication, the second terminal device is the opposite end device of the C2 communication, the C2 communication is the communication between the first terminal device and the second terminal device, and the second session management entity is a session management entity serving the second terminal device. entity; the processing module is further used to determine a third user plane security protection policy based on the first user plane security protection activation indication, and the third user plane security protection policy only includes forcibly enabling security protection or forcibly not enabling security protection; the transceiver module is used to send the third user plane security protection policy to the second access network device serving the second terminal device; wherein the third user plane security protection policy is used to determine the second user plane security protection activation indication, and the second user plane security protection activation indication is used to determine whether the user plane security protection of the second session is enabled, and the second session is the session used by the second terminal device to carry the C2 communication.
[0058] In combination with the above-mentioned eighth aspect, in a possible implementation method, the processing module is used to determine the third user plane security protection policy based on the first user plane security protection activation indication. The solution can refer to the above-mentioned fourth aspect and will not be repeated here.
[0059] In combination with the above-mentioned eighth aspect, in a possible implementation manner, the communication device includes a processor and a transceiver; the processor is used to obtain a first user plane security protection activation indication, and the first user plane security protection activation indication is used to indicate whether the user plane security protection of the first session is activated; wherein the first session is a session used by the first terminal device to carry C2 communication, the first terminal device is an initiating end device of the C2 communication, the second terminal device is a peer device of the C2 communication, the C2 communication is a communication between the first terminal device and the second terminal device, and the second session management entity is a session management entity serving the second terminal device. The processor is further configured to determine a third user plane security protection policy based on the first user plane security protection activation indication, where the third user plane security protection policy only includes forcibly activating security protection or forcibly not activating security protection; the transceiver is configured to send the third user plane security protection policy to a second access network device serving the second terminal device; wherein the third user plane security protection policy is used to determine a second user plane security protection activation indication, where the second user plane security protection activation indication is used to determine whether user plane security protection for a second session is activated, where the second session is a session used by the second terminal device to carry the C2 communication.
[0060] In combination with the above-mentioned eighth aspect, in a possible implementation method, the processor is used to determine the third user plane security protection policy based on the first user plane security protection activation indication. The solution can refer to the above-mentioned fourth aspect and will not be repeated here.
[0061] In combination with the above-mentioned seventh aspect or eighth aspect, in a possible implementation method, the processing module is used to obtain the first user plane security protection activation indication, including: sending a fifth message to the second unified data management entity serving the second terminal device through the transceiver module, the fifth message including the identification information of the second terminal device, and the fifth message being used to request the second user plane security protection policy; receiving the second user plane security protection policy and the first user plane security protection activation indication from the second unified data management entity through the transceiver module.
[0062] In combination with the above-mentioned seventh aspect or eighth aspect, in a possible implementation method, the processing module is used to obtain the first user plane security protection activation indication, including: sending a sixth message to the second proxy function entity through the transceiver module, the sixth message including the identification information of the second terminal device, the sixth message being used to request the first user plane security protection activation indication, the second proxy function entity being used to provide an interface between the second session management entity and the management device; receiving the first user plane security protection activation indication from the second proxy function entity through the transceiver module.
[0063] In combination with the above-mentioned seventh aspect or eighth aspect, in a possible implementation method, the transceiver module is also used to receive indication information from the second terminal device before sending the sixth message to the second proxy function entity, and the indication information indicates that the second session requested to be established by the second terminal device is used to respond to the C2 communication initiated by the first terminal device.
[0064] In combination with the above-mentioned seventh aspect or eighth aspect, in a possible implementation method, the processor is used to obtain a first user plane security protection activation indication, including: sending a fifth message to a second unified data management entity serving the second terminal device through the transceiver, the fifth message including identification information of the second terminal device, and the fifth message being used to request a second user plane security protection policy; receiving the second user plane security protection policy and the first user plane security protection activation indication from the second unified data management entity through the transceiver.
[0065] In combination with the above-mentioned seventh aspect or eighth aspect, in a possible implementation method, the processor is used to obtain the first user plane security protection activation indication, including: sending a sixth message to the second proxy function entity through the transceiver, the sixth message including the identification information of the second terminal device, the sixth message being used to request the first user plane security protection activation indication, the second proxy function entity being used to provide an interface between the second session management entity and the management device; receiving the first user plane security protection activation indication from the second proxy function entity through the transceiver.
[0066] In combination with the above-mentioned seventh aspect or eighth aspect, in a possible implementation method, the transceiver is also used to receive indication information from the second terminal device before sending the sixth message to the second proxy function entity, and the indication information indicates that the second session requested to be established by the second terminal device is used to respond to the C2 communication initiated by the first terminal device.
[0067] Among them, the technical effects of the above-mentioned seventh aspect or any possible implementation method of the seventh aspect can refer to the above-mentioned third aspect and will not be repeated here.
[0068] Among them, the technical effects of the above-mentioned eighth aspect or any possible implementation method of the eighth aspect can refer to the above-mentioned fourth aspect and will not be repeated here.
[0069] In the ninth aspect, a communication device is provided, comprising: a memory and a processor coupled to the memory, the memory being used to store programs, and the processor being used to execute the programs stored in the memory; when the communication device is running, the processor runs the program, so that the communication device executes the method described in any one of the above aspects.
[0070] In conjunction with the ninth aspect above, in one possible implementation, the communication device may be a chip or a chip system. When the communication device is a chip system, the communication device may be composed of a chip or may include a chip and other discrete devices.
[0071] In combination with the ninth aspect above, in a possible implementation, when the communication device is a chip or a chip system, the processor may also be embodied as a processing circuit or a logic circuit.
[0072] In a tenth aspect, a computer-readable storage medium is provided, wherein instructions are stored in the computer-readable storage medium, and when the computer-readable storage medium is run on the computer, the computer can execute the method described in any one of the above aspects.
[0073] In an eleventh aspect, a computer program product comprising instructions is provided, which, when executed on a computer, enables the computer to execute the method described in any one of the above aspects.
[0074] Among them, the technical effects brought about by any possible implementation method in the ninth to eleventh aspects can be referred to the technical effects brought about by different implementation methods in the above-mentioned first aspect or second aspect or third aspect or fourth aspect, and will not be repeated here.
[0075] In a twelfth aspect, a communication system is provided, which includes the management device described in the first aspect and the second session management entity described in the third aspect or the fourth aspect.
[0076] In combination with the above-mentioned twelfth aspect, in a possible implementation method, a management device is used to obtain a first user plane security protection activation indication, and the first user plane security protection activation indication is used to indicate whether the user plane security protection of the first session is activated; the first session is a session used by the first terminal device to carry C2 communication, and the C2 communication is communication between the first terminal device and the second terminal device; the management device is also used to trigger the second terminal device to initiate the establishment of a second session, and the second session is a session used by the second terminal device to carry the C2 communication; the second session management entity is used to receive the first user plane security protection activation indication obtained by the management device, and send the first user plane security protection activation indication to the second access network device serving the second terminal device; wherein, the first user plane security protection activation indication is used to determine whether the user plane security protection of the second session is activated.
[0077] In combination with the above-mentioned twelfth aspect, in another possible implementation manner, a management device is used to obtain a first user plane security protection activation indication, where the first user plane security protection activation indication is used to indicate whether user plane security protection of a first session is activated; the first session is a session used by the first terminal device to carry C2 communication, where the C2 communication is communication between the first terminal device and the second terminal device; the management device is also used to trigger the second terminal device to initiate establishment of a second session, where the second session is a session used by the second terminal device to carry the C2 communication; a second session management entity is used to receive the first user plane security protection activation indication obtained by the management device, and after determining a third user plane security protection policy based on the first user plane security protection activation indication, send the third user plane security protection policy to a second access network device serving the second terminal device; wherein the third user plane security protection policy only includes forcibly activating security protection or forcibly not activating security protection; the third user plane security protection policy is used to determine a second user plane security protection activation indication, where the second user plane security protection activation indication is used to determine whether user plane security protection of a second session is activated, where the second session is a session used by the second terminal device to carry the C2 communication.
[0078] In combination with the above-mentioned twelfth aspect, in another possible implementation method, the communication system also includes the first session management entity described in the above-mentioned second aspect; wherein, the first session management entity is used to send the first user plane security protection activation indication to the management device; the management device is used to obtain the first user plane security protection activation indication, including: being used to receive the first user plane security protection activation indication from the first session management entity.
[0079] In combination with the above-mentioned twelfth aspect, in another possible implementation method, the communication system also includes the first terminal device; the first terminal device is used to send the first user plane security protection activation indication to the management device; the management device is used to obtain the first user plane security protection activation indication, including: used to receive the first user plane security protection activation indication from the first terminal device.
[0080] Among them, the technical effects of the twelfth aspect can be referred to the technical effects brought about by different implementation methods in the above-mentioned first aspect, second aspect, third aspect or fourth aspect, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0081] Figure 1 A schematic diagram of the architecture of the 5G wireless communication network-enabled UAV system currently under discussion;
[0082] Figure 2a A schematic diagram of the architecture of a communication system provided in an embodiment of the present application;
[0083] Figure 2b A schematic diagram of the architecture of another communication system provided in an embodiment of the present application;
[0084] Figure 2c A schematic diagram of the architecture of another communication system provided in an embodiment of the present application;
[0085] Figure 3 This is a schematic diagram of the architecture of the communication system provided in an embodiment of the present application when applied to a 5G network;
[0086] Figure 4 A schematic diagram of the structure of a communication device provided in an embodiment of the present application;
[0087] Figure 5 A flow chart of a communication method provided in an embodiment of the present application;
[0088] Figure 6 A flowchart of another communication method provided in an embodiment of the present application;
[0089] Figure 7a A flow chart of another communication method provided in an embodiment of the present application;
[0090] Figure 7b A flow chart of another communication method provided in an embodiment of the present application;
[0091] Figure 8 An interactive diagram of a communication method provided in an embodiment of the present application;
[0092] Figure 9 An interactive diagram of another communication method provided in an embodiment of the present application;
[0093] Figure 10 An interactive diagram of another communication method provided in an embodiment of the present application;
[0094] Figure 11 An interactive diagram of another communication method provided in an embodiment of the present application;
[0095] Figure 12 A schematic diagram of the structure of another communication device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0096] In order to facilitate understanding of the technical solutions of the embodiments of the present application, a brief introduction to the relevant technologies of the present application is first given as follows.
[0097] First, C2 communication:
[0098] The 3rd Generation Partnership Project (3GPP) Network Requirements Working Group (SA1) defines C2 communication as: UAVC or UTM / USS uses a user plane connection to transmit command and control signaling to the UAV. Based on different requirements (such as information exchange frequency, traffic volume, end-to-end latency, etc.), UAVC or UTM / USS has four operating modes for the UAV: waypoint steering, direct steering stick control, automatic flight, and approaching an automated navigation facility. Because the present embodiment does not involve specific C2 communication operations, the present embodiment does not elaborate on these four operating modes.
[0099] The 3GPP Network Architecture Working Group (SA2) has added some new details to the definition of C2 communication. C2 communication is defined as: UAVC or UTM / USS using a user plane connection to transmit command and control signaling to a UAV, or the UAV reporting remote sensing information to the UAVC or UTM / USS. In other words, C2 communication currently includes bidirectional communication between the UAVC and the UAV, and bidirectional communication between the UTM / USS and the UAV.
[0100] It should be noted that the C2 communication referred to in the following embodiments of the present application only involves the C2 communication between the UAV and the UAVC, and does not involve the C2 communication between the UAV and the UTM / USS. This is explained here uniformly and will not be repeated below.
[0101] Second, the architecture of 5G network-enabled drone systems:
[0102] Figure 1 The following is a schematic diagram of the architecture of the 5G wireless communication network-enabled drone system currently under discussion. Figure 1 As shown, a UAS includes a UAV and a UAVC. In a 5G network, the UAV is designed to communicate with the peer through the 3GPP network. The peer can be, for example, a UAVC; or, the peer can be, for example, a UTM / USS; or, for example, an authorized third party entity (TPAE). Figure 1 As shown in the figure, the interface between UAV or UAVC and 3GPP network for UAS service authentication, authorization, identification and tracking is UAV1; the interface between TPAE and 3GPP network for remote identification (Remote ID) and tracking is UAV2; the interface between UAV and UAVC for C2 communication through 3GPP network is UAV3, and the interface between UAV and UTM / USS through 3GPP network is UAV9. Figure 1 As shown, a UAV can communicate with TPAE via UAV7, and with other UAVs outside the UAS to which it belongs via U2U. A UAV can communicate with UAVC via UAV8. The interface for C2 communication between a UAV and a UAVC via the Internet is UAV5. UAV5, UAV7, UAV8, and U2U interfaces are not controlled by the 3GPP network and are therefore outside the scope of this application. They are described here as a unified interface and will not be further elaborated below.
[0103] In the embodiments of the present application, both UAVs and UAVCs can be considered terminal devices or user equipment (UE) by the 3GPP network. UTM is responsible for drone communication management, and USS is the provider of drone services. UTM / USS services include authenticating and authorizing the use of drone services by UAVs / UAVCs and authorizing pairing between UAVs and UAVCs. TPAEs are devices held by agencies with regulatory requirements (such as the police), in addition to UAVCs and UTM / USSs.
[0104] In the embodiment of the present application, the UAV communicates with the peer end through the 3GPP network in three ways:
[0105] 1. UAVC or UTM / USS performs C2 communication with UAV to control UAV flight, or to control UAV to send measurement and control data to UAVC or UTM / USS. It should be noted that when UAV and UAVC perform C2 communication, they can be in different public land mobile network (PLMN) connections, for example, Figure 1 The UAV in a certain UAS can be in a 3GPP PLMN-a connection, and the UAVC can be in a 3GPP PLMN-b connection. The unified description is given here and will not be repeated below.
[0106] 2. UTM / USS or TPAE remotely identifies UAVs. The UAV in flight provides its own identification information to UTM / USS or TPAE to assist regulatory agencies (such as UTM or Civil Aviation Administration) to identify the status of drones in a timely manner to fill safety risks.
[0107] 3. The UAV and the UTM / USS perform other UAS services, such as obtaining UAS service parameters from the UTM / USS, or obtaining authentication and authorization to use UAS services.
[0108] Third, user plane security protection policy and user plane security protection activation indication:
[0109] The user plane security protection policy is a policy used to describe whether to enable user plane security protection, and can be used to determine the user plane security protection enable indication. In an embodiment of the present application, the user plane security protection policy includes a user plane confidentiality protection policy and / or a user plane integrity protection policy. The user plane confidentiality protection policy is a policy used to describe whether to enable user plane confidentiality protection, and can be used to determine the user plane confidentiality protection enable indication. The user plane integrity protection policy is a policy used to describe whether to enable user plane integrity protection, and can be used to determine the user plane integrity protection enable indication. The user plane confidentiality protection enable indication is used to indicate the enable result of the user plane confidentiality protection, such as whether the enable result of the user plane confidentiality protection is user plane confidentiality protection enabled (performed) or not enabled (not performed) (for example, when the first value is taken, the enable result of the user plane confidentiality protection is user plane confidentiality protection enabled; when the second value is taken, the enable result of the user plane confidentiality protection is user plane confidentiality protection not enabled). The user plane integrity protection activation indication is used to indicate the activation result of the user plane integrity protection, such as whether the activation result of the user plane integrity protection is user plane integrity protection activated (performed) or not activated (not performed) (for example, when the third value is taken, the activation result of the user plane confidentiality protection is user plane integrity protection activated; when the fourth value is taken, the activation result of the user plane confidentiality protection is user plane integrity protection not activated). In the embodiment of the present application, user plane confidentiality protection is to protect the confidentiality of user plane data during transmission. User plane integrity protection is to protect the integrity of user plane data during transmission. Integrity means that the acquired signaling or data is consistent with the original signaling or data and has not been modified. Therefore, integrity protection is to prevent attackers from "attacking". Confidentiality means that the real content cannot be directly seen. Therefore, confidentiality protection is to prevent attackers from "not being able to read". In addition, confidentiality protection in the embodiment of the present application can also be referred to as encryption protection, which is explained here uniformly and will not be repeated below.
[0110] In the embodiment of the present application, the user plane security protection policy (including the user plane confidentiality protection policy and the user plane integrity protection policy) can have three values: REQUIRED, NOT NEEDED, and PREFERRED. REQUIRED indicates that security protection must be enabled, NOT NEEDED indicates that security protection must not be enabled, and PREFERRED indicates that security protection is preferred or optional, that is, security protection can be enabled or not enabled.
[0111] It should be noted that in the embodiment of the present application, the user plane security protection policy and the user plane security protection activation indication are used to establish a session carrying C2 communication or to establish a session carrying non-C2 communication. They are uniformly explained here and will not be repeated below.
[0112] It should be noted that in the embodiments of the present application, when the user plane confidentiality protection policy or the user plane integrity protection policy is sent, generally only one of the three values (REQUIRED, NOT NEEDED, and PREFERRED) will be selected for transmission. In some special scenarios, at least two values may be selected for transmission, and one of them is PREFERRED. For example, when NOT NEEDED and PREFERRED are sent, it indicates that security protection is not enabled; when REQUIRED and PREFERRED are sent, it indicates that security protection is enabled.
[0113] It should be noted that in the embodiment of the present application, the user plane confidentiality protection policy and the user plane integrity protection policy can be the same, and the user plane confidentiality protection enable indication and the user plane integrity protection enable indication can be the same. The embodiment of the present application does not make specific limitations on this.
[0114] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application. Among them, in the description of the present application, unless otherwise specified, " / " indicates that the objects associated before and after are in an "or" relationship. For example, A / B can represent A or B; "and / or" in the present application is only a description of the association relationship of the associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. In addition, in the description of the present application, unless otherwise specified, "multiple" refers to two or more than two. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can represent: a, b, c, ab, ac, bc, or abc, where a, b, c can be single or multiple. In addition, in order to facilitate the clear description of the technical solutions of the embodiments of the present application, in the embodiments of the present application, words such as "first" and "second" are used to distinguish between identical or similar items with substantially the same functions and effects. Those skilled in the art will understand that words such as "first" and "second" do not limit the quantity and execution order, and words such as "first" and "second" do not necessarily limit differences. At the same time, in the embodiments of the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or explanations. Any embodiment or design described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as being more preferred or more advantageous than other embodiments or design schemes. Specifically, the use of words such as "exemplary" or "for example" is intended to present related concepts in a concrete way for easy understanding.
[0115] In addition, the network architecture and business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. Ordinary technicians in this field can know that with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.
[0116] like Figure 2a As shown, a communication system 20 provided by an embodiment of the present application is provided. The communication system 20 includes a management device 201 and a second session management entity 202 serving a second terminal device. The second terminal device is a peer device of C2 communication, where C2 communication is communication between a first terminal device and a second terminal device, and the first terminal device is an initiating end device of C2 communication. The management device 201 and the second session management entity 202 may communicate directly or through other devices (e.g., Figure 2a The communication is carried out by forwarding the second proxy function entity 203) in the embodiment of the present application. This embodiment does not make any specific limitation on this.
[0117] In one possible implementation, management device 201 is configured to obtain a first user plane security protection enable indication, where the first user plane security protection enable indication is used to indicate whether user plane security protection is enabled for a first session. The first session is a session used by a first terminal device to carry C2 communications. Management device 201 is further configured to trigger a second terminal device to initiate establishment of a second session, where the second session is a session used by the second terminal device to carry C2 communications. A second session management entity 202 is configured to receive the first user plane security protection enable indication obtained by management device 201 and send the first user plane security protection enable indication to a second access network device serving the second terminal device. The first user plane security protection enable indication is used to determine whether user plane security protection is enabled for the second session. The specific implementation of this solution can be found in the subsequent method embodiments and will not be further described here. In the communication system provided in the embodiments of the present application, the first user plane security protection enable indication is used to determine whether user plane security protection is enabled for the second session, and the first user plane security protection enable indication is used to indicate whether user plane security protection is enabled for the first session. In other words, whether user plane security protection is enabled for the first session and whether user plane security protection is enabled for the second session are both determined by the first user plane security protection enable indication. Since the first session is a session used by the first terminal device to carry C2 communications between the first terminal device and the second terminal device, and the second session is a session used by the second terminal device to carry the C2 communications, this solution ensures consistency in user plane security protection for C2 communications between the first terminal device and the second terminal device.
[0118] In another possible implementation, management device 201 is configured to obtain a first user plane security protection enable indication, where the first user plane security protection enable indication indicates whether user plane security protection is enabled for a first session; the first session is a session used by the first terminal device to carry C2 communications. Management device 201 is further configured to trigger a second terminal device to initiate establishment of a second session; the second session is a session used by the second terminal device to carry C2 communications. A second session management entity 202 is configured to receive the first user plane security protection enable indication obtained by management device 201, determine a third user plane security protection policy based on the first user plane security protection enable indication, and then send the third user plane security protection policy to a second access network device serving the second terminal device. The third user plane security protection policy may include only forcibly enabling security protection or forcibly disabling security protection. The third user plane security protection policy is used to determine the second user plane security protection enable indication, where the second user plane security protection enable indication determines whether user plane security protection is enabled for the second session; the second session is a session used by the second terminal device to carry C2 communications. The specific implementation of this solution can be found in the subsequent method embodiments and will not be further described here. In the communication system provided in the embodiment of the present application, the third user plane security protection policy is used to determine the second user plane security protection activation indication indicating whether the user plane security protection of the second session is activated, and the third user plane security protection policy is determined by the first user plane security protection activation indication indicating whether the user plane security protection of the first session is activated, and the third user plane security protection policy only includes forcibly activating security protection or forcibly not activating security protection. In other words, whether the user plane security protection of the first session is activated and whether the user plane security protection of the second session is activated are both determined by the first user plane security protection activation indication. Since the first session is a session used by the first terminal device to carry C2 communication, the second session is a session used by the second terminal device to carry the C2 communication, and the C2 communication is the communication between the first terminal device and the second terminal device, based on this solution, the consistency of the user plane security protection of the C2 communication between the first terminal device and the second terminal device can be guaranteed.
[0119] Optional, such as Figure 2b As shown, the communication system 20 may further include a first session management entity 204 serving the first terminal device. The management device 201 and the first session management entity 204 may communicate directly or through other devices (eg Figure 2b The communication is carried out by forwarding the first proxy function entity 205), which is not specifically limited in this embodiment of the present application.
[0120] The first session management entity 204 is configured to send a first user plane security protection activation instruction to the management device 201. Accordingly, the management device 201 is configured to obtain the first user plane security protection activation instruction, including receiving the first user plane security protection activation instruction from the first session management entity 204. That is, in this embodiment of the present application, the management device may obtain the first user plane security protection activation instruction via a control plane between the first terminal device and the management device.
[0121] Optional, such as Figure 2c As shown, the communication system 20 may further include a first terminal device 206. The management device 201 and the first terminal device 206 may communicate directly or through forwarding by other devices, which is not specifically limited in this embodiment of the present application.
[0122] The first terminal device 206 is configured to send a first user plane security protection activation instruction to the management device 201. Accordingly, the management device 201 is configured to obtain the first user plane security protection activation instruction, including receiving the first user plane security protection activation instruction from the first terminal device 206. That is, in this embodiment of the present application, the management device can obtain the first user plane security protection activation instruction via the user plane between the first terminal device and the management device.
[0123] Optional, Figures 2a to 2c The communication system 20 shown can be applicable to the 5G network currently under discussion, and can also be applicable to other networks in the future, etc., and the embodiments of the present application do not make specific limitations on this.
[0124] For example, Figures 2a to 2c The communication system 20 shown is applied to the 5G network currently under discussion as an example. Figure 3 As shown, Figures 2a to 2c The network element or entity corresponding to the first session management entity or the second session management entity in the communication system 20 shown may be an SMF of a 5G network; Figures 2a to 2c The management device in the illustrated communication system 20 may be, for example, a UTM / USS for a 5G wireless communication network-enabled UAV system; Figures 2a to 2cThe network element or entity corresponding to the first proxy function entity or the second proxy function entity in the communication system 20 shown can be a UAV flight enablement subsystem (UFES) for providing an interface from the 3GPP network to the UTM / USS, which can reduce the impact on the existing 3GPP network. In the embodiment of the present application, the functions of UFES include at least providing UTM / USS selective addressing for the 3GPP network, device mapping of the external UAV ID and 3GPP identifier of the terminal device (including the first terminal device and the second terminal device), and obtaining the contract and policy control information of the terminal device from the 3GPP network instead of the UTM / USS, etc., which are uniformly explained here and will not be repeated below.
[0125] In addition, if Figure 3 As shown, the 5G network may also include radio access network (RAN) equipment, user plane function (UPF), access and mobility management function (AMF), authentication server function (AUSF), network slice selection function (NSSF), network exposure function (NEF), network exposure function repository function (NRF), policy control function (PCF), unified data management (UDM), unified data storage (UDR), application function (AF) or charging function (CHF), etc. Among them, the terminal device accesses the 5G network through the RAN device, and the terminal device communicates with the AMF through the N1 interface (referred to as N1); the RAN device communicates with the AMF through the N2 interface (referred to as N2); the RAN device communicates with the UPF through the N3 interface (referred to as N3); the RAN device can also communicate with the UTM / USS; the SMF communicates with the UP through the N4 interface (referred to as N4), and the UPF accesses the data network through the N6 interface (referred to as N6). In addition, Figure 3The control plane functions shown in the figure, such as AUSF, AMF, SMF, NSSF, NEF, NRF, PCF, UDM, UDR, CHF, UFES or AF, interact using service-based interfaces. For example, the service-based interface provided by AUSF is Nausf; the service-based interface provided by AMF is Namf; the service-based interface provided by SMF is Nsmf; the service-based interface provided by NSSF is Nnssf; the service-based interface provided by NEF is Nnef; the service-based interface provided by NRF is Nnrf; the service-based interface provided by PCF is Npcf; the service-based interface provided by UDM is Nudm; the service-based interface provided by UDR is Nudr; the service-based interface provided by CHF is Nchf; the service-based interface provided by UFES is Nufes; and the service-based interface provided by AF is Naf. For relevant function descriptions and interface descriptions, please refer to the 5G system architecture diagram in the 23501 standard and will not be repeated here.
[0126] It should be noted that in the embodiment of the present application, UFES can be deployed independently of the network element of the 5G network, or it can be deployed on the network element of the 5G network, such as deployed on the NEF. The embodiment of the present application does not make specific limitations on this.
[0127] Optionally, the terminal device in the embodiment of the present application (including the first terminal device or the second terminal device mentioned above) can be a device for implementing wireless communication functions, such as a terminal or a chip that can be used in a terminal, etc., which can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; it can also be deployed on the water surface (such as a ship, etc.); it can also be deployed in the air (such as an airplane, a balloon, and a satellite, etc.). In one possible implementation, the first terminal device mentioned above can be, for example, a UAV of a 5G wireless communication network-enabled unmanned aerial vehicle system or a chip that can be used on a UAV, and the second terminal device mentioned above can be, for example, a UAVC of a 5G wireless communication network-enabled unmanned aerial vehicle system or a chip that can be used on a UAVC. In another possible implementation, the first terminal device mentioned above can be, for example, a UAVC of a 5G wireless communication network-enabled unmanned aerial vehicle system or a chip that can be used on a UAVC, and the second terminal device can be, for example, a UAV of a 5G wireless communication network-enabled unmanned aerial vehicle system or a chip that can be used on a UAV. Of course, the first terminal device and the second terminal device mentioned above can also be other terminal devices that can be used to implement C2 communication or similar C2 communication, such as terminal devices in scenarios such as remote control car driving, remote control industrial machinery, and monitoring backhaul, which are not specifically limited in the embodiment of the present application.
[0128] Optionally, the RAN device in the embodiment of the present application is a device that provides wireless communication functions for terminal devices. Access network equipment includes, for example, but is not limited to: next-generation base stations (gnodeB, gNB) in 5G, evolved node B (eNB), radio network controller (RNC), node B (NB), base station controller (BSC), base transceiver station (BTS), home base station (for example, home evolved nodeB, or home node B, HNB), baseband unit (BBU), transmission point (TRP), transmitting point (TP), mobile switching center, etc.
[0129] Optionally, the management device, the first session management entity or the second session management entity in the embodiment of the present application may also be referred to as a communication device, which may be a general device or a dedicated device, and the embodiment of the present application does not specifically limit this.
[0130] Optionally, the relevant functions of the management device, the first session management entity, or the second session management entity in the embodiments of the present application can be implemented by a single device, or can be implemented jointly by multiple devices, or can be implemented by one or more functional modules within a single device, and the embodiments of the present application do not specifically limit this. It is understood that the above functions can be network elements in a hardware device, software functions running on dedicated hardware, or a combination of hardware and software, or virtualized functions instantiated on a platform (e.g., a cloud platform).
[0131] For example, the relevant functions of the management device, the first session management entity or the second session management entity in the embodiment of the present application can be Figure 4 It is implemented by the communication device 400 in. Figure 4 FIG. 4 is a schematic diagram of the structure of a communication device 400 provided in an embodiment of the present application. The communication device 400 includes one or more processors 401, a communication line 402, and at least one communication interface ( Figure 4 The example in which the communication interface 404 and a processor 401 are included is merely exemplary), and a memory 403 may be optionally included.
[0132] The processor 401 may be a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits for controlling the execution of the program of the present application.
[0133] The communication line 402 may include a path for connecting different components.
[0134] Communication interface 404 can be a transceiver module for communicating with other devices or communication networks, such as Ethernet, RAN, wireless local area networks (WLAN), etc. For example, the transceiver module can be a device such as a transceiver or a transceiver. Optionally, communication interface 404 can also be a transceiver circuit located within processor 401 to implement signal input and output to the processor.
[0135] The memory 403 may be a device having a storage function. For example, it may be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory may exist independently and be connected to the processor via a communication line 402. The memory may also be integrated with the processor.
[0136] The memory 403 is used to store computer-executable instructions for executing the solution of the present application, and the execution is controlled by the processor 401. The processor 401 is used to execute the computer-executable instructions stored in the memory 403, thereby implementing the communication method provided in the embodiment of the present application.
[0137] Alternatively, optionally, in an embodiment of the present application, the processor 401 may also perform processing-related functions in the communication method provided in the following embodiments of the present application, and the communication interface 404 is responsible for communicating with other devices or communication networks, which is not specifically limited in the embodiments of the present application.
[0138] Optionally, the computer-executable instructions in the embodiments of the present application may also be referred to as application code, which is not specifically limited in the embodiments of the present application.
[0139] In a specific implementation, as an embodiment, the processor 401 may include one or more CPUs, such as Figure 4 CPU0 and CPU1 in.
[0140] In a specific implementation, as an embodiment, the communication device 400 may include multiple processors, such as Figure 4 Processor 401 and processor 408 in the embodiment. Each of these processors can be a single-core processor or a multi-core processor. The processor here can include but is not limited to at least one of the following: a central processing unit (CPU), a microprocessor, a digital signal processor (DSP), a microcontroller unit (MCU), or an artificial intelligence processor, etc., and each computing device can include one or more cores for executing software instructions to perform calculations or processing.
[0141] In a specific implementation, as an embodiment, the communication device 400 may further include an output device 405 and an input device 406. The output device 405 communicates with the processor 401 and can display information in a variety of ways. For example, the output device 405 can be a liquid crystal display (LCD), a light emitting diode (LED) display device, a cathode ray tube (CRT) display device, or a projector. The input device 406 communicates with the processor 401 and can receive user input in a variety of ways. For example, the input device 406 can be a mouse, a keyboard, a touch screen device, or a sensor device.
[0142] The communication device 400 may also be referred to as a communication device, which may be a general-purpose device or a dedicated device. For example, the communication device 400 may be a desktop computer, a portable computer, a network server, a personal digital assistant (PDA), a mobile phone, a tablet computer, a wireless terminal device, an embedded device, the above terminal device, the above network device, or a Figure 4 The embodiment of the present application does not limit the type of the communication device 400.
[0143] The communication method provided in the embodiments of the present application will be described below with reference to the accompanying drawings.
[0144] like Figure 5 As shown, a communication method provided in an embodiment of the present application includes the following steps:
[0145] S501. A management device obtains a first user plane security protection enable indication, where the first user plane security protection enable indication is used to indicate whether user plane security protection is enabled for a first session. The first session is a session used by a first terminal device to carry C2 communication, where the first terminal device is an initiating device of the C2 communication, and the second terminal device is a peer device of the C2 communication. The C2 communication is communication between the first terminal device and the second terminal device.
[0146] In the embodiments of the present application and the following embodiments, the relevant description of the first user plane security protection activation indication can be referred to the invention content part and will not be repeated here.
[0147] In a possible implementation, the management device obtains the first user plane security protection start indication, including: the management device receives the first user plane security protection start indication from the first session management entity, the first session management entity is a session management entity serving the first terminal device. The specific implementation of this solution can be referred to Figure 8 or Figure 9 The embodiments shown are not described in detail here.
[0148] In another possible implementation, the management device obtains the first user plane security protection activation instruction, including: the management device receives the first user plane security protection activation instruction from the first terminal device. Figure 9 The embodiments shown are not described in detail here.
[0149] In another possible implementation, the management device obtains the first user plane security protection start indication, including: the management device receives the first user plane security protection start indication from the first proxy function entity, and the first proxy function entity is used to provide an interface from the first session management entity to the management device. The specific implementation of this solution can be referred to Figure 11The embodiments shown are not described in detail here.
[0150] In another possible implementation, the management device obtains the first user plane security protection activation indication, including: the management device determines that the pairing authorization between the first terminal device and the second terminal device is successful; the management device sends a third message to the first proxy function entity, the third message includes the identification information of the first terminal device, and the third message is used to request the first user plane security protection activation indication. The first proxy function entity is used to provide an interface from the first session management entity to the management device, and the first session management entity is a session management entity serving the first terminal device. The management device receives the first user plane security protection activation indication from the first proxy function entity. For the specific implementation of this solution, please refer to Figure 10 or Figure 11 The embodiments shown are not described in detail here.
[0151] S502: The management device triggers the second terminal device to initiate establishment of a second session. Whether user plane security protection of the second session is enabled is determined by the first user plane security protection enabling indication. The second session is a session used by the second terminal device to carry C2 communication.
[0152] In one possible implementation, the management device triggers the second terminal device to initiate the establishment of the second session, including: the management device sends a first message to the second terminal device, the first message is used to trigger the second terminal device to initiate the establishment of the second session; and the management device sends a first user plane security protection start indication to the second unified data management entity, wherein the second unified data management entity is a unified data management entity serving the second terminal device. For specific implementation, please refer to Figure 8 The embodiments shown are not described in detail here.
[0153] In another possible implementation, the management device triggers the second terminal device to initiate the establishment of the second session, including: the management device sends a first message to the second terminal device, the first message is used to trigger the second terminal device to initiate the establishment of the second session; and the management device receives a second message from the second proxy function entity, and sends a first user plane security protection start indication to the second proxy function entity; wherein the second message includes the identification information of the second terminal device, the second message is used to request the first user plane security protection start indication, the second proxy function entity is used to provide an interface from the second session management entity to the management device, and the second session management entity is a session management entity serving the second terminal device. For specific implementation, please refer to Figure 8 The embodiments shown are not described in detail here.
[0154] In the communication method provided in the embodiment of the present application, the management device can obtain the first user plane security protection activation indication and trigger the second terminal device to initiate the establishment of the second session. Among them, whether the user plane security protection of the second session is activated is determined by the first user plane security protection activation indication, and the first user plane security protection activation indication is used to indicate whether the user plane security protection of the first session is activated. In other words, whether the user plane security protection of the first session is activated and whether the user plane security protection of the second session is activated are both determined by the first user plane security protection activation indication. Since the first session is a session used by the first terminal device to carry the C2 communication between the first terminal device and the second terminal device, the second session is a session used by the second terminal device to carry the C2 communication. Therefore, based on this solution, the consistency of the user plane security protection of the C2 communication between the first terminal device and the second terminal device can be guaranteed.
[0155] The actions of managing the device in steps S501 to S502 can be performed by Figure 4 The processor 401 in the communication apparatus 400 shown calls the application code stored in the memory 403 to instruct the management device to execute, and this embodiment does not impose any limitation on this.
[0156] like Figure 6 As shown, a communication method provided in an embodiment of the present application includes the following steps:
[0157] S601. A first session management entity obtains a first user plane security protection enable indication, where the first user plane security protection enable indication is used to indicate whether user plane security protection is enabled for a first session. The first session is a session used by a first terminal device to carry C2 communication, where the first terminal device is an initiating device of the C2 communication, and the second terminal device is a peer device of the C2 communication. The C2 communication is communication between the first terminal device and the second terminal device, and the first session management entity is a session management entity serving the first terminal device.
[0158] In one possible implementation, the first session management entity obtains a first user plane security protection activation indication, including: the first session management entity obtains a first user plane security protection policy from a first unified data management entity serving a first terminal device; the first session management entity sends the first user plane security protection policy to a first access network device serving the first terminal device; the first session management entity receives the first user plane security protection activation indication from the first access network device, wherein the first user plane security protection activation indication is determined based on the first user plane security protection policy.
[0159] In another possible implementation, the first session management entity obtains a first user plane security protection activation indication, including: the first session management entity obtains a first user plane security protection policy from a first unified data management entity serving the first terminal device; the first session management entity sends the first user plane security protection policy to a first access network device serving the first terminal device; the first session management entity receives a seventh message from the first access network device, the seventh message being used to indicate that the first access network device has established a first session according to the first user plane security protection policy; in response to the seventh message, the first session management entity determines the first user plane security protection activation indication according to the first user plane security protection policy.
[0160] The specific implementation of the above solution can be referred to Figure 8 The embodiments shown are not described in detail here.
[0161] S602: The first session management entity sends a first user plane security protection enabling indication. The first user plane security protection enabling indication is used to determine whether user plane security protection for a second session is enabled, where the second session is a session used by a second terminal device to carry C2 communications.
[0162] In a possible implementation, the first session management entity sends the first user plane security protection start indication, including: the first session management entity sends the first user plane security protection start indication to the management device. Figure 8 or Figure 9 The embodiments shown are not described in detail here.
[0163] In another possible implementation, the first session management entity sends the first user plane security protection start indication, including: the first session management entity sends the first user plane security protection start indication to the first proxy function entity; wherein the first proxy function entity is used to provide the first session management entity with an interface to the management device. The specific implementation of this solution can be referred to Figure 10 or Figure 11 The embodiment shown is not described in detail here. Optionally, before the first session management entity sends the first user plane security protection activation instruction to the first proxy function entity, the method further includes: the first session management entity receives a fourth message from the first proxy function entity, the fourth message includes identification information of the first terminal device, and the fourth message is used to request the first user plane security protection activation instruction. The specific implementation of this solution can be referred to Figure 10 The embodiments shown are not described in detail here.
[0164] In the communication method provided in the embodiment of the present application, the first session management entity obtains a first user plane security protection activation indication and sends a first user plane security protection activation indication. The first user plane security protection activation indication is used to determine whether the user plane security protection of the second session is activated, and the first user plane security protection activation indication is used to indicate whether the user plane security protection of the first session is activated. In other words, whether the user plane security protection of the first session is activated and whether the user plane security protection of the second session is activated are both determined by the first user plane security protection activation indication. Since the first session is a session used by the first terminal device to carry the C2 communication between the first terminal device and the second terminal device, the second session is a session used by the second terminal device to carry the C2 communication. Therefore, based on this solution, the consistency of the user plane security protection of the C2 communication between the first terminal device and the second terminal device can be guaranteed.
[0165] The actions of the first session management entity in steps S601 to S602 can be performed by Figure 4 The processor 401 in the communication device 400 shown calls the application code stored in the memory 403 to instruct the first session management entity to execute, and this embodiment does not impose any limitation on this.
[0166] like Figure 7a As shown, a communication method provided in an embodiment of the present application includes the following steps:
[0167] S701a. The second session management entity obtains a first user plane security protection activation indication, where the first user plane security protection activation indication is used to indicate whether user plane security protection for the first session is activated; wherein the first session is a session used by the first terminal device to carry C2 communication, the first terminal device is an initiating device of the C2 communication, the second terminal device is an opposite device of the C2 communication, the C2 communication is communication between the first terminal device and the second terminal device, and the second session management entity is a session management entity serving the second terminal device.
[0168] In one possible implementation, the second session management entity obtains the first user plane security protection activation indication, including: the second session management entity sends a fifth message to the second unified data management entity serving the second terminal device, the fifth message including identification information of the second terminal device, and the fifth message is used to request a second user plane security protection policy; the second session management entity receives the second user plane security protection policy and the first user plane security protection activation indication from the second unified data management entity. The specific implementation of this solution can be referred to Figure 8 The embodiments shown are not described in detail here.
[0169] In another possible implementation, the second session management entity obtains the first user plane security protection activation indication, including: the second session management entity sends a sixth message to the second proxy function entity, the sixth message includes identification information of the second terminal device, the sixth message is used to request the first user plane security protection activation indication, and the second proxy function entity is used to provide an interface from the second session management entity to the management device. The second session management entity receives the first user plane security protection activation indication from the second proxy function entity. Optionally, before the second session management entity sends the sixth message to the second proxy function entity, the method further includes: the second session management entity receives indication information from the second terminal device, the indication information indicates that the second session requested to be established by the second terminal device is used to respond to the C2 communication initiated by the first terminal device. For the specific implementation of this solution, please refer to Figure 8 The embodiments shown are not described in detail here.
[0170] S702a. The second session management entity sends a first user plane security protection activation indication to the second access network device serving the second terminal device; wherein the first user plane security protection activation indication is used to determine whether the user plane security protection of the second session is activated, and the second session is a session used by the second terminal device to carry C2 communication.
[0171] In the communication method provided in the embodiment of the present application, the first user plane security protection on indication is used to determine whether the user plane security protection of the second session is on, and at the same time, the first user plane security protection on indication is used to indicate whether the user plane security protection of the first session is on. In other words, whether the user plane security protection of the first session is on and whether the user plane security protection of the second session is on are both determined by the first user plane security protection on indication. Since the first session is a session used by the first terminal device to carry the C2 communication between the first terminal device and the second terminal device, the second session is a session used by the second terminal device to carry the C2 communication. Therefore, based on this solution, the consistency of the user plane security protection of the C2 communication between the first terminal device and the second terminal device can be guaranteed.
[0172] The actions of the second session management entity in steps S701a to S702a can be performed by Figure 4 The processor 401 in the communication device 400 shown calls the application code stored in the memory 403 to instruct the second session management entity to execute, and this embodiment does not impose any limitation on this.
[0173] like Figure 7b As shown, a communication method provided in an embodiment of the present application includes the following steps:
[0174] S701b, same as step S701a, for related descriptions, please refer to Figure 7a The embodiments shown are not described in detail here.
[0175] S702b: The second session management entity determines a third user plane security protection policy according to the first user plane security protection enabling indication, where the third user plane security protection policy only includes forcibly enabling security protection or forcibly not enabling security protection.
[0176] In a possible implementation manner, in an embodiment of the present application, the solution for the second session management entity to determine the third user plane security protection policy according to the first user plane security protection activation indication can be referred to the aforementioned invention content part and will not be repeated here.
[0177] S703b: The second session management entity sends a third user plane security protection policy to the second access network device serving the second terminal device. The third user plane security protection policy is used to determine a second user plane security protection enable indication, which is used to determine whether user plane security protection is enabled for a second session, where the second session is a session used by the second terminal device to carry C2 communications.
[0178] In the embodiments of the present application and the following embodiments, the relevant description of the second user plane security protection activation indication can be referred to the invention content part and will not be repeated here.
[0179] In the communication method provided in the embodiment of the present application, the third user plane security protection policy is used to determine the second user plane security protection activation indication indicating whether the user plane security protection of the second session is activated, and the third user plane security protection policy is determined by the first user plane security protection activation indication indicating whether the user plane security protection of the first session is activated, and the third user plane security protection policy only includes forcibly activating security protection or forcibly not activating security protection. In other words, whether the user plane security protection of the first session is activated and whether the user plane security protection of the second session is activated are both determined by the first user plane security protection activation indication. Since the first session is a session used by the first terminal device to carry the C2 communication between the first terminal device and the second terminal device, the second session is a session used by the second terminal device to carry the C2 communication. Therefore, based on this solution, the consistency of the user plane security protection of the C2 communication between the first terminal device and the second terminal device can be guaranteed.
[0180] The actions of the second session management entity in steps S701b to S703b can be performed by Figure 4 The processor 401 in the communication device 400 shown calls the application code stored in the memory 403 to instruct the second session management entity to execute, and this embodiment does not impose any limitation on this.
[0181] Below Figures 2a to 2c The communication system is applied to Figure 3In the 5G network shown, the first terminal device is UAV, the second terminal device is UAVC, the management device is UTM / USS, the first access network device serving the first terminal device is RAN device 1, the second access network device serving the second terminal device is RAN device 2, the first session management entity serving the first terminal device is SMF1, the second session management entity serving the second terminal device is SMF2, the first unified data management entity serving the first terminal device is UDM1, the second unified data management entity serving the second terminal device is UDM2, the first proxy function entity serving the first terminal device is UFES1, and the second proxy function entity serving the second terminal device is UFES2. As an example, the communication method provided in the embodiment of the present application is described in detail. Of course, in the embodiment of the present application, the first terminal device may also be UAVC and the second terminal device may be UAV. In this case, it is only necessary to swap the operations of UAV and UAVC in the following embodiments. They are explained here uniformly and will not be repeated below.
[0182] It should be noted that the message names between network elements or the names of parameters in the messages in the following embodiments of the present application are only examples, and other names may be used in specific implementations. The embodiments of the present application do not specifically limit this.
[0183] It should be noted that the following examples of this application are all based on the existence of UFES between the 3GPP network and UTM / USS, and UFES is an independent network element. Of course, UFES can also be a part of the function of an existing 3GPP network element (for example, a part of the function of NEF). In this case, the process of interaction between UFES and 3GPP network or UTM / USS in the following examples can be replaced by the interaction between the 3GPP network element (such as NEF) and 3GPP network or UTM / USS. This is explained uniformly here and will not be repeated below.
[0184] In a possible implementation, the UTM / USS may obtain a first user plane security protection start indication for indicating whether user plane security protection of the first PDU session is enabled during the process of the UAV establishing a first PDU session for carrying C2 communication between the UAV and the UAVC (hereinafter referred to as C2 communication between the UAV and the UAVC). Furthermore, the SMF2 serving the UAVC may obtain the first user plane security protection start indication during the process of the UAVC establishing a second PDU session for carrying C2 communication. For example, Figure 8 As shown, a communication method provided by an embodiment of the present application includes a registration process of a UAV and a UAVC in a 3GPP network, such as the following steps S801a and S801b:
[0185] S801a, the UAV registers to the 3GPP network, and a specific registration process can refer to prior art, which is not described here.
[0186] In the embodiments of the present application, the UAV can obtain a 3GPP device ID (hereinafter referred to as 3GPP UAV ID) allocated by the 3GPP network in the process of registering to the 3GPP network, which is used to uniquely identify the UAV in the 3GPP network where the UAV is registered. For example, the 3GPP UAV ID can be a subscription permanent identifier (SUPI) or a subscription concealed identifier (SUCI).
[0187] S801b, the UAVC registers to the 3GPP network, and a specific registration process can refer to prior art, which is not described here.
[0188] In the embodiments of the present application, the UAVC can obtain a 3GPP device ID (hereinafter referred to as 3GPP UAVC ID) allocated by the 3GPP network in the process of registering to the 3GPP network, which is used to uniquely identify the UAVC in the 3GPP network where the UAVC is registered. For example, the 3GPP UAVC ID can be a SUPI or a SUCI.
[0189] It should be noted that in the embodiments of the present application, the 3GPP network where the UAV is registered and the 3GPP network where the UAVC is registered can be the same 3GPP network or different 3GPP networks, which is not limited in the embodiments of the present application.
[0190] It should be noted that in the embodiments of the present application, in addition to obtaining the respective 3GPP device IDs described above, the UAV and the UAVC are respectively preconfigured with an external UAV ID. The external UAV ID is allocated by a non-3GPP network, for example, a UAV ID allocated by a civil aviation authority (CAA) for the UAV or the UAVC.
[0191] Further, the communication method provided by the embodiments of the present application further includes a process of triggering the UAV to establish a first PDU session, as steps S802-S813 described below:
[0192] S802, the UAV sends a session establishment request 1 to the SMF1 in the 3GPP network. Correspondingly, the SMF1 receives the session establishment request 1 from the UAV. The session establishment request 1 includes the 3GPP UAV ID and indication information 1, which is used to indicate that the first PDU session requested by the UAV to establish is used to carry the C2 communication.
[0193] In a possible implementation, the indication information 1 can be explicit indication. For example, the indication information 1 can be a UAS operation request indication, which is a C2 request, and is used to explicitly indicate that the first PDU session requested by the UAV to establish is used to carry the C2 communication. Optionally, in the embodiment of the present application, the UAS operation request indication can also indicate that the C2 request is a proactive C2 request.
[0194] In another possible implementation, the indication information 1 can be implicit indication. For example, the indication information 1 can be data network name (DNN) information dedicated to C2 communication, or DNN and slice combination information dedicated to C2 communication, etc.
[0195] Of course, if the UAV and the UAVC have been paired offline through a non-3GPP manner (for example, the two devices are paired through Bluetooth) or through other manners before step S802, the UAV can obtain the pairing identifier of the paired UAVC. Further, the pairing identifier of the UAVC can be included in the session establishment request 1, and can be used to implicitly indicate that the first PDU session requested by the UAV to establish is used to carry the C2 communication. For example, the pairing identifier of the UAVC can be a 3GPP UAVC ID or an external UAV ID of the UAVC.
[0196] Optionally, in the embodiment of the present application, when the pairing identifier of the UAVC is the external UAV ID of the UAVC, the external UAV ID of the UAVC can be included in a container of the session establishment request 1. In this way, on the one hand, since the intermediate node transparently transmits the container without tampering the content in the container, the security of the above-mentioned parameters can be ensured; on the other hand, since the intermediate node can not analyze the above-mentioned parameters, the processing resources of the intermediate node can be saved, and the processing efficiency of the intermediate node can be improved.
[0197] S803, after determining that the first PDU session requested by the UAV to establish is used to carry the C2 communication according to the indication information 1, the SMF1 obtains a first user plane security protection policy from the UDM1, which is used to establish the first PDU session.
[0198] In the embodiment of the present application, the relevant description of the first user plane security protection policy can refer to the description of "User Plane Security Protection Policy" in the preamble of the specific implementation method, which will not be repeated here.
[0199] In one possible implementation, after SMF1 determines, based on indication information 1, that the first PDU session requested by the UAV is for C2 communication, it sends a request message to UDM1. The request message includes a 3GPP UAV ID and is used to request a first user plane security protection policy. After receiving the request message, UDM1 determines the first user plane security protection policy based on the 3GPP UAV ID and includes the first user plane security protection policy in a response message sent to SMF1.
[0200] S804: SMF1 sends a first user plane security protection policy to RAN device 1. Correspondingly, RAN device 1 receives the first user plane security protection policy from SMF1.
[0201] S805 . RAN device 1 determines a first user plane security protection enabling indication according to the first user plane security protection policy. The first user plane security protection enabling indication is used to indicate whether user plane security protection for the first PDU session is enabled.
[0202] In an embodiment of the present application, when the RAN device 1 determines the first user plane security protection activation indication based on the first user plane security protection policy, it can be determined in combination with other information (such as the usage of resources on the first access network device or the maximum integrity protection rate that the first terminal device can support).
[0203] For example, when the first user plane security protection policy includes user plane confidentiality protection as optional activation and user plane integrity protection as optional activation; and the RAN device 1 is currently relatively idle and has sufficient resources to provide security protection for the user plane data of the UAV, the RAN device 1 can determine to activate the user plane confidentiality protection and the user plane integrity protection, that is, the first user plane security protection activation indication is used to indicate that the user plane confidentiality protection is activated and the user plane integrity protection is activated. For another example, when the first user plane security protection policy includes user plane confidentiality protection as optional activation and user plane integrity protection as optional activation; and the RAN device 1 does not have sufficient resources to provide security protection for the user plane data of the UAV, the RAN device 1 can determine not to activate the user plane confidentiality protection and the user plane integrity protection, that is, the first user plane security protection activation indication is used to indicate that the user plane confidentiality protection is not activated and the user plane integrity protection is not activated.
[0204] For example, in an embodiment of the present application, when the first user plane security protection policy includes user plane confidentiality protection as mandatory on and user plane integrity protection as mandatory on, and the RAN device 1 is currently relatively idle and has sufficient resources to provide security protection for the user plane data of the UAV, the RAN device 1 can determine to enable user plane confidentiality protection and enable user plane integrity protection, that is, the first user plane security protection enable indication is used to indicate that user plane confidentiality protection is enabled and user plane integrity protection is enabled. For another example, if the first user plane security protection policy includes user plane confidentiality protection as mandatory off and user plane integrity protection as mandatory off, the RAN device 1 can determine not to enable user plane confidentiality protection and not to enable user plane integrity protection, that is, the first user plane security protection enable indication is used to indicate that user plane confidentiality protection is disabled and user plane integrity protection is disabled. Other situations are similar and will not be described in detail.
[0205] Of course, in the embodiment of the present application, when the first user plane security protection policy includes user plane confidentiality protection as mandatory on and user plane integrity protection as mandatory on, but the RAN device 1 currently does not have sufficient resources to provide security protection for the user plane data of the UAV, the RAN device 1 may determine to reject the establishment of the first PDU session, and then the RAN device may send an indication of rejecting the establishment of the first PDU session to SMF1 to terminate the subsequent process. This embodiment of the present application does not specifically elaborate on this situation. This ensures that all nodes on the path carrying C2 communication on the UAV side can support the first user plane security protection on indication, thereby ensuring normal C2 communication between the UAV and the UAVC.
[0206] Furthermore, when the RAN device 1 does not reject the establishment of the first PDU session, the communication method provided in the embodiment of the present application further includes the following step S806:
[0207] S806: RAN device 1 sends a PDU session resource setup response transfer message to SMF 1. Accordingly, SMF 1 receives the PDU session resource setup response transfer message from RAN device 1. The PDU session resource setup response transfer message indicates that RAN device 1 has established the first PDU session according to the first user plane security protection policy.
[0208] It should be noted that, in the embodiment of the present application, the PDU session resource establishment response transmission message sent by the RAN device 1 to the SMF1 is only Figure 6 The embodiment shown is an example of the seventh message. The seventh message may also be other, and the embodiment of the present application does not make specific limitations on this.
[0209] In an embodiment of the present application, when the first user plane security protection policy is to enable security protection optionally, the PDU session resource establishment response transmission message includes a first user plane security protection enable indication. When the PDU session resource establishment response transmission message does not include a first user plane security protection enable indication (i.e., when the first user plane security protection policy is to enable security protection forcibly or not forcibly), the communication method provided in the embodiment of the present application further includes the following step S807:
[0210] S807. In response to the PDU session resource establishment response transmission message, SMF1 determines a first user plane security protection activation indication according to the first user plane security protection policy.
[0211] That is, in the embodiment of the present application, when the first user plane security protection policy is a deterministic policy (for example, the first user plane security protection policy includes user plane confidentiality protection being forced on / forced off and user plane integrity protection being forced on / forced off), the RAN device 1 may not explicitly notify the SMF 1 of the result of enabling the user plane security protection. When the SMF 1 determines that the first session has been established, it may determine whether to enable the user plane confidentiality protection and the user plane integrity protection based on the first user plane security protection policy.
[0212] Based on the above step S806 or step S807, SMF1 can obtain the first user plane security protection start indication. Furthermore, the first PDU session establishment process further includes the following steps:
[0213] S808: SMF1 sends message 1 to UFES1. Correspondingly, UFES1 receives message 1 from SMF1. Message 1 includes the 3GPP UAV ID and a first user plane security protection activation indication.
[0214] S809: UFES1 sends message 2 to UTM / USS. Correspondingly, UTM / USS receives message 2 from UFES1. Message 2 includes the external UAV ID of the UAV and a first user plane security protection enable indication.
[0215] For the above steps S808-S809:
[0216] In one possible implementation, the above-mentioned message 1 and message 2 may be messages for pairing authorization in the session establishment process (such as a C2 pairing request); or the above-mentioned message 1 and message 2 may be messages for secondary authentication in the session establishment process. Optionally, the UAV may use the secondary authentication process to complete USS UAV authentication authorization (USS UAV authorization / authentication, UUAA) and / or pairing authorization; or the above-mentioned message 1 and message 2 may be messages for UUAA in the session establishment process; or the above-mentioned message 1 and message 2 may be other existing messages or newly defined messages in the session establishment process, and the embodiments of the present application do not specifically limit this.
[0217] In another possible implementation, before SMF1 sends message 1 to UFES1, SMF1 sends message a to UFES1. After UFES1 receives message a from SMF1, it determines based on message a that the first PDU session requested by the UAV to be established is used to carry C2 communication, and then requests SMF1 to obtain the first user plane security protection activation indication. Then, SMF1 sends message 1 to UFES1. In this scenario, message a and message 2 can be messages used for pairing authorization in the session establishment process (such as a C2 pairing request); or message a and message 2 can be messages used for secondary authentication in the session establishment process. Optionally, the UAV can complete UUAA and / or pairing authorization with the help of the secondary authentication process; or message a and message 2 can be messages used for UUAA in the session establishment process; or the above-mentioned message a and message 2 can be other messages in the session establishment process, and the embodiments of the present application do not make specific limitations on this.
[0218] In an embodiment of the present application, after UFES1 obtains the 3GPP UAV ID from the 3GPP network, it can "translate" the 3GPP UAV ID into the external UAV ID of the UAV that can be recognized by the UTM / USS based on the mapping relationship between the stored 3GPP UAV ID and the external UAV ID of the UAV, and send the external UAV ID of the UAV to the UTM / USS. This is explained here uniformly and will not be repeated below.
[0219] In the embodiment of the present application, if the session establishment request 1 includes a UAVC pairing identifier, the message 1 and the message 2 also include the UAVC pairing identifier. When the UAVC pairing identifier is a 3GPP UAVC ID, after obtaining the 3GPP UAVC ID from the 3GPP network, the UFES1 can "translate" the 3GPP UAVC ID into an external UAV ID of the UAVC that can be recognized by the UTM / USS based on the stored mapping relationship between the 3GPP UAVC ID and the external UAV ID of the UAVC, and send the external UAV ID of the UAVC to the UTM / USS. This is explained here and will not be repeated below.
[0220] Based on the above step S808 or step S809, the UTM / USS can obtain the first user plane security protection opening indication. Optionally, in the embodiment of the present application, if the C2 pairing authorization is implemented in the first PDU session establishment process, the communication method provided by the embodiment of the present application further includes the following step S810:
[0221] S810. After the UTM / USS determines that the UAVC paired with the UAV is online, it authorizes the C2 pairing request.
[0222] It should be noted that, in the embodiment of the present application, the UAVC on the network may be that the UAVC and the UTM / USS are connected through a 3GPP method, and then the 3GPP access method is used to execute the UUAA process to obtain the authentication authorization of the UTM / USS; or, in the embodiment of the present application, the UAVC on the network may be that the UAVC and the UTM / USS are connected through a non-3GPP method, and then the non-3GPP access method is used to obtain the authentication authorization of the UTM / USS. The embodiment of the present application does not make specific limitations on this.
[0223] In one possible implementation, if before step S802, the UAV and UAVC have been paired offline through a non-3GPP method (for example, the two devices are paired through Bluetooth) or through other methods, the UTM / USS can obtain the external UAV ID of the UAVC from the received message and determine whether the UAVC has obtained the authentication authorization of the UTM / USS based on the external UAV ID of the UAVC. If the UAVC has obtained the authentication authorization of the UTM / USS, the UTM / USS can determine that the UAVC is online. The method in which the UTM / USS obtains the external UAV ID of the UAVC from the received message includes: parsing the container in the received message to obtain the external UAV ID of the UAVC contained in the container; or directly obtaining the external UAV ID of the UAVC from the received message.
[0224] In another possible implementation, the pairing relationship between the UAV and the UAVC can be stored in the UTM / USS (for example, the manufacturers of the UAV and the UAVC pair the UAV and the UAVC when the equipment leaves the factory, and register the pairing relationship in the UTM / USS). The pairing relationship can be represented by the mapping relationship between the external UAV ID of the UAV and the external UAV ID of the UAVC. Furthermore, after the UTM / USS determines the external UAV ID of the UAVC based on the external UAV ID of the received UAV and the pairing relationship between the UAV and the UAVC, it determines whether the UAVC has obtained the authentication authorization of the UTM / USS based on the external UAV ID of the UAVC. If the UAVC has obtained the authentication authorization of the UTM / USS, the UTM / USS can determine that the UAVC is online.
[0225] In the embodiment of the present application, the UTM / USS authorizing the C2 pairing request includes: the UTM / USS determining whether the UAV and the UAVC match based on the obtained external UAV ID of the UAVC and the external UAV ID of the UAV.
[0226] In an embodiment of the present application, after the UTM / USS determines that the C2 pairing authorization between the UAV and the UAVC is successful, the mapping relationship between the external UAV ID of the UAV, the external UAV ID of the UAVC, and the first user plane security protection activation indication can be stored for subsequent use.
[0227] Furthermore, the first PDU session establishment process provided in the embodiment of the present application further includes the following steps:
[0228] S811. For other establishment processes of the first PDU session between the 3GPP network and the UTM / USS, please refer to the existing technology for details and will not be described again here.
[0229] It should be noted that, in an embodiment of the present application, if the above-mentioned step S810 is executed, then in other establishment processes between the 3GPP network and the UTM / USS for the first PDU session, the UTM / USS needs to send an indication message of the successful C2 pairing authorization between the UAV and the UAVC to SMF1 through UFES1, and then SMF1 can know that the C2 pairing authorization between the UAV and the UAVC is successful. Of course, the C2 pairing authorization between the UAV and the UAVC can also be completed in the registration process in steps S801a and S801b. In this scenario, when the C2 pairing authorization between the UAV and the UAVC is successful, SMF1 can also obtain the indication message of the successful C2 pairing authorization between the UAV and the UAVC, so that it can be known that the C2 pairing authorization between the UAV and the UAVC is successful.
[0230] S812: After SMF1 determines that the first PDU session is successfully established, it sends a session establishment acceptance message 1 to RAN device 1. Accordingly, RAN device 1 receives the session establishment acceptance message 1 from SMF1. The session establishment acceptance message 1 includes the N1 session management container (N1 session management container) sent by SMF1 to the UAV and the N2 session management information (N2 Session Management Information) sent by SMF1 to RAN device 1. The N2 session management information includes session identification information for the first PDU session, core network tunnel information (CN Tunnel Info) for configuring the N3 tunnel, and / or a QoS profile. For specific information, please refer to the existing technology and will not be repeated here.
[0231] S813: RAN device 1 sends a Session Establishment Accept message 2 to the UAV. Accordingly, the UAV receives the Session Establishment Accept message 2 from SMF 1. The Session Establishment Accept message 2 includes a first user plane security protection enable indication, an N1 session management container, and session identification information for the first PDU session. Of course, the Session Establishment Accept message 2 may also include other parameters, which are not specifically limited in this embodiment of the present application.
[0232] Since both the UAV and the RAN device 1 can obtain the first user plane security protection activation instruction, when the UAV and the UAVC perform C2 communication subsequently, the UAV and the RAN device 1 can perform user plane security protection on the UAV side according to the first user plane security protection activation instruction.
[0233] Furthermore, the communication method provided in the embodiment of the present application also includes a process in which SMF2 serving the UAVC obtains a first user plane security protection activation indication when establishing a second PDU session, such as method A shown in steps S814-S818 or method B shown in steps S819-S821 below.
[0234] Method A is as follows:
[0235] S814: The UTM / USS sends a message 3 to the UFES2 serving the UAVC. Accordingly, the UFES2 receives the message 3 from the UTM / USS. The message 3 includes the external UAV ID of the UAVC and a first user plane security protection enablement indication.
[0236] S815: UFES2 sends message 4 to UDM2 serving the UAVC. Correspondingly, UDM2 receives message 4 from UFES2. Message 4 includes the 3GPP UAVC ID and a first user plane security protection activation indication.
[0237] Exemplarily, message 3 in the embodiment of the present application may be, for example, a message used by UTM / USS to update UAS service-related parameters in UFES2, and message 4 may be, for example, a message used by UFES2 to update UAS service-related parameters in UDM2.
[0238] Optionally, in an embodiment of the present application, after UDM2 obtains the 3GPP UAVC ID and the first user plane security protection activation indication, it may store the mapping relationship between the 3GPP UAVC ID and the first user plane security protection activation indication for subsequent use. Optionally, in an embodiment of the present application, before UDM2 stores the mapping relationship between the 3GPP UAVC ID and the first user plane security protection activation indication, it may determine, based on the 3GPP UAVC ID, whether the second user plane security protection policy corresponding to the UAVC stored in UDM2 satisfies the first user plane security protection activation indication obtained by UDM2 from the UTM / USS. If UDM2 determines that the second user plane security protection policy satisfies the first user plane security protection activation indication, UDM2 may store the mapping relationship between the 3GPP UAVC ID and the first user plane security protection activation indication. If UDM2 determines that the second user plane security protection policy does not satisfy the first user plane security protection activation indication, UDM2 may send a rejection indication to the UTM / USS via UFES2, where the rejection indication is used to indicate that the UAVC is rejected from establishing a PDU session that carries C2 communication. Of course, if UDM2 determines that the second user plane security protection policy meets the first user plane security protection start indication, UDM2 can also send an indication message to UTM / USS through UFES2 to allow UAVC to establish a PDU session that carries C2 communication. This embodiment of the present application does not specifically limit this. Based on this solution, on the one hand, it can avoid the problem of subsequent C2 communication failure that may be caused by the second user plane security protection policy not meeting the first user plane security protection start indication. On the other hand, when the second user plane security protection policy does not meet the first user plane security protection start indication, the process of UAVC initiating the establishment of the second PDU session can be terminated in time, avoiding excessive signaling waste.
[0239] Exemplarily, assuming that the first user plane security protection on indication indicates that user plane confidentiality protection is on and user plane integrity protection is on, and the second user plane security protection policy includes that user plane confidentiality protection is forcibly on and user plane integrity protection is forcibly on, then UDM2 can determine that the second user plane security protection policy satisfies the first user plane security protection on indication; or, assuming that the first user plane security protection on indication indicates that user plane confidentiality protection is on and user plane integrity protection is on, and the second user plane security protection policy includes that user plane confidentiality protection is forcibly not on and user plane integrity protection is forcibly not on, then UDM2 can determine that the second user plane security protection policy does not satisfy the first user plane security protection on indication; or, assuming that the first user plane security protection on indication indicates that user plane confidentiality protection is on and user plane integrity protection is on, and the second user plane security protection policy includes that user plane confidentiality protection is optionally on and user plane integrity protection is optionally on, then UDM2 can determine that the second user plane security protection policy satisfies the first user plane security protection on indication. Other situations are similar and will not be repeated here.
[0240] S816: The UTM / USS sends a message 5 to the UAVC. Correspondingly, the UAVC receives the message 5 from the UTM / USS. The message 5 is used to trigger the UAVC to initiate a second PDU session establishment process.
[0241] In the embodiment of the present application, message 5 can be sent through the control plane or user plane of the 3GPP network, or through a non-3GPP network, which is not specifically limited in the embodiment of the present application.
[0242] Exemplarily, message 5 in the embodiment of the present application may be, for example, a C2 communication trigger request sent by the UTM / USS through the control plane or user plane of the 3GPP network; or, message 5 in the embodiment of the present application may be, for example, a C2 communication trigger request sent by the UTM / USS through a non-3GPP network, and the C2 communication trigger request is used to request the UAVC to respond to the UAV's C2 communication request through the 3GPP network.
[0243] It should be noted that, in the embodiment of the present application, the message 5 sent by UTM / USS to UAVC is only Figure 5 The embodiment shown is an example of the first message. The first message may also be other, and the embodiment of the present application does not specifically limit this.
[0244] S817: The UAVC sends a session establishment request 2 to SMF2 in the 3GPP network. Accordingly, SMF2 receives the session establishment request 2 from the UAVC. The session establishment request 2 includes the 3GPP UAVC ID and indication information 2, which indicates that the second PDU session requested by the UAVC is to be used to carry C2 communications.
[0245] In one possible implementation, indication information 2 may be a display indication. For example, indication information 2 may be a UAS operation request indication (UAS operation request indication), where the UAS operation request indication is a C2 request, which is used to display an indication that the UAVC requests to establish a second PDU session for carrying C2 communication. Optionally, in this embodiment of the present application, the UAS operation request indication may also indicate that the C2 request is a passive C2 request.
[0246] In another possible implementation, the indication information 2 may be an implicit indication. For example, the indication information 2 may be DNN information dedicated to C2 communication, or DNN and slice combination information dedicated to C2 communication.
[0247] Of course, if the UAV and UAVC have been paired offline through non-3GPP means (for example, the two devices are paired via Bluetooth) or through other means before step S802, the UAVC can obtain the pairing identifier of the UAV with which it is paired. Furthermore, the session establishment request 2 may include the pairing identifier of the UAV, and the pairing identifier of the UAV implicitly indicates that the second PDU session requested by the UAVC is used to carry C2 communication. Exemplarily, the pairing identifier of the UAV can be, for example, a 3GPP UAV ID or an external UAV ID of the UAV.
[0248] S818. After SMF2 determines, based on indication information 2, that the second PDU session established by the UAVC request is used to carry C2 communication, it obtains a first user plane security protection activation indication from UDM2.
[0249] In one possible implementation, after SMF2 determines, based on indication information 2, that the second PDU session established by the UAVC request is used to carry C2 communication, it sends a request message to UDM2. The request message includes a 3GPP UAVC ID, and the request message is used to request the second user plane security protection policy corresponding to the UAVC. After receiving the request message, UDM2 determines the second user plane security protection policy corresponding to the UAVC based on the 3GPP UAVCID, and carries the second user plane security protection policy corresponding to the UAVC in the response message sent to SMF2. In the embodiment of the present application, the relevant description of the second user plane security protection policy can refer to the description of "User Plane Security Protection Policy" in the preamble of the specific implementation method, which will not be repeated here. In addition, in the embodiment of the present application, since the first user plane security protection activation indication is stored in UDM2, the response message may also include the first user plane security protection activation indication.
[0250] It should be noted that, in the embodiment of the present application, the request message sent by SMF2 to UDM2 is only Figure 7aThe embodiment shown is an example of the fifth message. The fifth message may also be other, and the embodiment of the present application does not make specific limitations on this.
[0251] It should be noted that in the embodiment of the present application, if UDM2 determines in step S815 that the second user plane security protection policy corresponding to the UAVC stored in UDM2 satisfies the first user plane security protection activation indication obtained by UDM2 from the UTM / USS based on the 3GPP UAVC ID, then the UTM / USS may send message 5 to the UAVC (execute step S816) after receiving the indication information from UDM2 allowing the UAVC to establish a PDU session carrying C2 communication. Of course, UDM2 may also directly assume that the second user plane security protection policy corresponding to the UAVC satisfies the first user plane security protection activation indication obtained by UDM2 from the UTM / USS. At this time, there is no necessary order for executing steps S814 and S816. Step S814 may be executed first, and then step S816; step S816 may be executed first, and then step S814; or steps S814 and S816 may be executed simultaneously. This embodiment of the present application does not specifically limit this.
[0252] Method B is as follows:
[0253] S819, same as step S816. For related descriptions, please refer to the above step S816 and will not be repeated here.
[0254] S820: The UAVC sends a session establishment request 2 to SMF2 in the 3GPP network. Accordingly, SMF2 receives the session establishment request 2 from the UAVC. The session establishment request 2 includes the 3GPP UAVC ID and indication information 3, which indicates that the UAVC is requesting to establish a second PDU session in response to the C2 communication initiated by the UAV.
[0255] In one possible implementation, indication information 3 may be a display indication. For example, indication information 3 may be a UAS operation request indication (UAS operation request indication), where the UAS operation request indication is a passive C2 request, used to display an indication of the second PDU session established by the UAVC request in response to the C2 communication initiated by the UAV.
[0256] S821. After SMF2 determines, based on indication information 3, that the second PDU session established by the UAVC request is used to respond to the C2 communication initiated by the UAV, it obtains a first user plane security protection activation indication from the UTM / USS through UFES2.
[0257] In one possible implementation, after SMF2 determines, based on indication information 3, that the second PDU session established by the UAVC request is used to respond to the C2 communication initiated by the UAV, it sends a request message to UFES2, where the request message includes the 3GPP UAVC ID, and the request message is used to request a first user plane security protection activation indication. Furthermore, UFES2 sends a request message to the UTM / USS, where the request message includes the external UAV ID of the UAVC, and the request message is used to request a first user plane security protection activation indication. After receiving the request message, the UTM / USS can determine the first user plane security protection activation indication based on the external UAV ID of the UAVC, the external UAV ID of the UAV, the external UAV ID of the UAVC, and the mapping relationship between the first user plane security protection activation indication, and send the first user plane security protection activation indication to SMF2.
[0258] It should be noted that, in the embodiment of the present application, the request message sent by UFES2 to UTM / USS is only Figure 5 The embodiment shown is an example of the second message. The second message may also be other, and the embodiment of the present application does not specifically limit this.
[0259] It should be noted that, in the embodiment of the present application, the request message sent by SMF2 to UFES2 is only Figure 7a The embodiment shown is an example of the sixth message. The sixth message may also be other, and the embodiment of the present application does not specifically limit this.
[0260] In the embodiment of the present application, after UFES2 obtains the 3GPP UAVC ID from the 3GPP network, it can "translate" the 3GPP UAVC ID into an external UAV ID of UAVC that can be recognized by UTM / USS according to the stored mapping relationship between the 3GPP UAVC ID and the external UAV ID of UAVC, and send the external UAV ID of UAVC to UTM / USS. This is explained here uniformly and will not be repeated below.
[0261] Optionally, in an embodiment of the present application, after SMF2 determines, based on indication information 3, that the second PDU session established by the UAVC request is used to respond to the C2 communication initiated by the UAV, it may also obtain the second user plane security protection policy corresponding to the UAVC from UDM2. This embodiment of the present application does not specifically limit this. Among them, when SMF2 obtains the second user plane security protection policy corresponding to the UAVC and the first user plane security protection start indication from UDM2 at the same time, SMF2 can determine whether the second user plane security protection policy satisfies the first user plane security protection start indication. If SMF2 determines whether the second user plane security protection policy satisfies the first user plane security protection start indication, SMF2 continues the second PDU session establishment process; or, if SMF2 determines that the second user plane security protection policy does not satisfy the first user plane security protection start indication, SMF2 rejects the establishment of the second PDU session. The way in which SMF2 determines whether the second user plane security protection policy satisfies the first user plane security protection start indication can refer to the above-mentioned way in which UDM2 determines whether the second user plane security protection policy satisfies the first user plane security protection start indication, and will not be repeated here. Of course, when SMF2 obtains the second user plane security protection policy corresponding to UAVC and the first user plane security protection activation indication from UDM2 at the same time, SMF2 may also use the first user plane security protection activation indication by default and ignore the second user plane security protection policy. This embodiment of the present application does not specifically limit this.
[0262] Furthermore, the communication method provided in the embodiment of the present application may also include other processes for establishing a second PDU session, such as method 1 shown in steps S822-S825 or method 2 shown in steps S826-S827 below.
[0263] Method 1 is as follows:
[0264] S822: SMF2 determines a third user plane security protection policy based on the first user plane security protection activation instruction. The third user plane security protection policy may include only forcibly activating security protection or forcibly disabling security protection. The specific implementation of step S822 can be found in the aforementioned Summary of the Invention section and will not be repeated here.
[0265] S823: SMF2 sends the third user plane security protection policy to RAN device 2. Correspondingly, RAN device 2 receives the third user plane security protection policy from SMF2.
[0266] S824. RAN device 2 determines a second user plane security protection enabling indication according to the third user plane security protection policy. The second user plane security protection enabling indication is used to indicate whether user plane security protection for the second PDU session is enabled.
[0267] In the embodiment of the present application, the relevant example of RAN device 2 determining the second user plane security protection activation indication according to the third user plane security protection policy can refer to the manner in which RAN device 1 determines the first user plane security protection activation indication according to the first user plane security protection policy in step S805, which will not be repeated here.
[0268] Of course, in the embodiment of the present application, when the third user plane security protection policy includes user plane confidentiality protection as mandatory on and user plane integrity protection as mandatory on, but the RAN device 2 currently does not have sufficient resources to provide security protection for the user plane data of the UAVC, the RAN device 2 may determine to reject the establishment of the second PDU session, and then the RAN device may send an indication of rejecting the establishment of the second PDU session to SMF2 to terminate the subsequent process. This embodiment of the present application does not specifically elaborate on this situation. This ensures that all nodes on the path carrying C2 communication on the UAVC side can support the second user plane security protection on indication, thereby ensuring normal C2 communication between the UAV and the UAVC.
[0269] For details of the other processes for establishing the second PDU session in step S825, refer to the prior art and are not further described here. During the other processes for establishing the second PDU session, RAN device 2 may send a second user plane security protection activation instruction to the UAVC. Because both RAN device 2 and the UAVC can obtain the second user plane security protection activation instruction, during subsequent C2 communication between the UAV and the UAVC, user plane security protection on the UAVC side can be performed between the UAVC and RAN device 2 based on the second user plane security protection activation instruction.
[0270] In this method one, since the method for enabling user plane security protection indicated by the second user plane security protection enablement indication is the same as the method for enabling user plane security protection indicated by the third user plane security protection policy, and the method for enabling user plane security protection indicated by the third user plane security protection policy is the same as the method for enabling user plane security protection indicated by the first user plane security protection enablement indication, the method for enabling user plane security protection indicated by the first user plane security protection enablement indication is the same as the method for enabling user plane security protection indicated by the second user plane security protection enablement indication. Since the method for enabling user plane security protection indicated by the first user plane security protection enablement indication is the method for enabling user plane security protection for the first PDU session on the UAV side for carrying C2 communication, and the method for enabling user plane security protection indicated by the second user plane security protection enablement indication is the method for enabling user plane security protection for the second PDU session on the UAVC side for carrying C2 communication, based on this solution, consistency of user plane security protection for C2 communication between the UAV and the UAVC can be guaranteed.
[0271] Method 2 is as follows:
[0272] S826: SMF2 sends a first user plane security protection enabling instruction to RAN device 2. Correspondingly, RAN device 2 receives the first user plane security protection enabling instruction from SMF2.
[0273] For details of the other processes for establishing the second PDU session at step S827, refer to the prior art and are not further described here. During the other processes for establishing the second PDU session, RAN device 2 may send a second user plane security protection activation instruction to the UAVC. Because both RAN device 2 and the UAVC can obtain the second user plane security protection activation instruction, during subsequent C2 communication between the UAV and the UAVC, user plane security protection on the UAVC side can be performed between the UAVC and RAN device 2 based on the second user plane security protection activation instruction.
[0274] In this second approach, since both the user plane security protection activation method for the first PDU session carrying C2 communication on the UAV side and the user plane security protection activation method for the second PDU session carrying C2 communication on the UAVC side are indicated by the first user plane security protection activation indication, this solution ensures consistency in user plane security protection for C2 communication between the UAV and UAVC.
[0275] Optionally, as an alternative, in an embodiment of the present application, after step S815, UDM2 may also update the second user plane security protection policy corresponding to the UAVC stored in UDM2 based on the first user plane security protection activation indication obtained from the UTM / USS. The updated second user plane security protection policy may only include forcibly enabling security protection or forcibly disabling security protection. Specifically, the method by which the UDM determines the updated second user plane security protection policy based on the first user plane security protection activation indication is similar to the example in step S822 where SMF2 determines the third user plane security protection policy based on the first user plane security protection activation indication, and will not be further described here. Furthermore, after SMF2 receives session establishment request 2 from the UAVC and determines, based on indication information 2, that the second PDU session requested by the UAVC is to carry C2 communication, or determines, based on indication information 3, that the second PDU session requested by the UAVC is to respond to C2 communication initiated by the UAV, it may send a request message to UDM2. The request message includes the 3GPP UAVC ID and is used to request the second user plane security protection policy corresponding to the UAVC. After receiving the request message, UDM2 determines the second user plane security protection policy corresponding to the UAVC based on the 3GPP UAVC ID, and carries the second user plane security protection policy corresponding to the UAVC in a response message sent to SMF2. Furthermore, SMF2 can send the second user plane security protection policy to RAN device 2. Accordingly, RAN device 2 receives the second user plane security protection policy from SMF2 and determines a second user plane security protection activation indication based on the second user plane security protection policy. The second user plane security protection activation indication is used to indicate whether user plane security protection for the second PDU session is activated. Based on this solution, since the user plane security protection activation method indicated by the second user plane security protection activation indication is the same as the user plane security protection activation method indicated by the second user plane security protection policy, and the user plane security protection activation method indicated by the second user plane security protection policy is the same as the user plane security protection activation method indicated by the first user plane security protection activation indication, the user plane security protection activation method indicated by the first user plane security protection activation indication is the same as the user plane security protection activation method indicated by the second user plane security protection activation indication. Since the user plane security protection activation method indicated by the first user plane security protection activation indication is the user plane security protection activation method for the first PDU session on the UAV side used to carry C2 communication, and the user plane security protection activation method indicated by the second user plane security protection activation indication is the user plane security protection activation method for the second PDU session on the UAVC side used to carry C2 communication, based on this solution, the consistency of the user plane security protection of the C2 communication between the UAV and the UAVC can be guaranteed.
[0276] Optionally, as an alternative solution, after SMF2 obtains the first user plane security protection activation indication, it can also send the first user plane security protection activation indication to other network elements (such as PCF), and after the other network elements determine the above-mentioned third user plane security protection policy based on the first user plane security protection activation indication, the third user plane security protection policy is sent to SMF2. The embodiment of the present application does not make specific limitations on this.
[0277] Furthermore, the communication method provided in the embodiment of the present application may further include the following step S828:
[0278] S828: After the second PDU session is established, the 3GPP network with which the UAV is registered configures session information with the 3GPP network with which the UAVC is registered. A C2 communication channel is established between the UAV and the UAVC, and subsequent C2 communication processes begin. The configuration of session information includes routing information configuration, PDU session modification, and other processes. For related implementations, reference can be made to existing technologies and will not be further described here.
[0279] Based on the communication method provided in the embodiment of the present application, the UTM / USS can obtain a first user plane security protection activation indication indicating whether user plane security protection for the first PDU session is activated during the process of the UAV establishing a first PDU session for carrying C2 communication, and the SMF2 serving the UAVC can obtain the first user plane security protection activation indication or obtain a second user plane security protection policy corresponding to the UAVC updated according to the first user plane security protection activation indication during the process of the UAVC establishing a second PDU session for carrying C2 communication. Whether user plane security protection for the second PDU session is activated is determined by the first user plane security protection activation indication or the second user plane security protection policy. Therefore, based on this solution, it can be ensured that the user plane security protection activation method for the first PDU session for carrying C2 communication on the UAV side is the same as the user plane security protection activation method for the second PDU session for carrying C2 communication on the UAVC side, thereby ensuring consistency in user plane security protection for C2 communication between the UAV and the UAVC.
[0280] The actions of SMF1, UTM / USS, SMF2, UFES1 or UFES2 in steps S801a to S828 can be performed by Figure 4 The processor 401 in the communication device 400 shown calls the application code stored in the memory 403 to instruct SMF1, UTM / USS, SMF2, UFES1 or UFES2 to execute, and this embodiment does not impose any limitation on this.
[0281] In another possible implementation, the UTM / USS may obtain, through the user plane or control plane, a first user plane security protection enable indication for indicating whether user plane security protection for the first PDU session is enabled after the UAV establishes a first PDU session for carrying C2 communication between the UAV and the UAVC (hereinafter referred to as C2 communication between the UAV and the UAVC). Furthermore, the SMF2 serving the UAVC may obtain the first user plane security protection enable indication or obtain the second user plane security protection policy corresponding to the UAVC updated according to the first user plane security protection enable indication during the process of the UAVC establishing a second PDU session for carrying C2 communication. For example, as Figure 9 As shown, a communication method provided by an embodiment of the present application includes a registration process of a UAV and a UAVC in a 3GPP network, such as the following steps S901a and S901b:
[0282] S901a. The UAV registers with the 3GPP network. The specific registration process can be referred to the existing technology and will not be described in detail here.
[0283] S901b, UAVC registers with the 3GPP network. The specific registration process can be referred to the existing technology and will not be repeated here.
[0284] The specific implementation of step S901a and step S901b can refer to Figure 8 Steps S801a and S801b in the illustrated embodiment are not described in detail here.
[0285] Furthermore, the communication method provided in the embodiment of the present application further includes a process of the UAV triggering establishment of a first PDU session, such as the following step S902:
[0286] S902 , the UAV triggers the process of establishing the first PDU session. For details, please refer to the existing technology and will not be described here.
[0287] After the first PDU session is established, the UAV, RAN device 1, and SMF 1 can all obtain the first user plane security protection activation indication. Furthermore, the communication method provided in the embodiment of the present application also includes a process for the UTM / USS to obtain the first user plane security protection activation indication, such as the method M shown in step S903 or the method N shown in steps S904-S905.
[0288] Method M is as follows:
[0289] S903: The UAV sends the external UAV ID of the UAV and the first user plane security protection start indication to the UTM / USS via the user plane of the established first PDU session. Accordingly, the UTM / USS receives the external UAV ID of the UAV and the first user plane security protection start indication from the UAV.
[0290] Method N is as follows:
[0291] S904: After SMF1 determines that the first PDU session is established, it sends a message 6 to UFES1. Accordingly, UFES1 receives the message 6 from SMF1. The message 6 includes the 3GPP UAV ID and the first user plane security protection start indication.
[0292] S905: UFES1 sends message 7 to UTM / USS. Correspondingly, UTM / USS receives message 7 from UFES1. Message 7 includes the external UAV ID of the UAV and a first user plane security protection enable indication.
[0293] For the above steps S904-S905:
[0294] The above-mentioned messages 6 and 7 may be messages in which SMF1 notifies UTM / USS of the session parameters used for C2 communication on the UAV side (such as the IP address used by UAV for C2 communication) after the session establishment process is completed; or the above-mentioned messages 6 and 7 may be other existing control plane messages or newly defined control plane messages after the session establishment process is completed. The embodiments of the present application do not make specific limitations on this.
[0295] In an embodiment of the present application, after UFES1 obtains the 3GPP UAV ID from the 3GPP network, it can "translate" the 3GPP UAV ID into the external UAV ID of the UAV that can be recognized by the UTM / USS based on the mapping relationship between the stored 3GPP UAV ID and the external UAV ID of the UAV, and send the external UAV ID of the UAV to the UTM / USS. This is explained here uniformly and will not be repeated below.
[0296] Based on the above-mentioned method M or method N, the UTM / USS can obtain the first user plane security protection activation indication. Furthermore, the SMF2 serving the UAVC can obtain the first user plane security protection activation indication or obtain the second user plane security protection policy corresponding to the UAVC updated according to the first user plane security protection activation indication during the process of the UAVC establishing the second PDU session for carrying the C2 communication. Among them, whether the user plane security protection of the second PDU session is activated is determined by the first user plane security protection activation indication or the second user plane security protection policy. For related implementations, please refer to Figure 8Steps S814-S828 in the illustrated embodiment are not described in detail here.
[0297] Based on the communication method provided in the embodiment of the present application, since the UTM / USS can obtain a first user plane security protection activation indication indicating whether user plane security protection of the first PDU session is activated after the process of the UAV establishing the first PDU session for carrying C2 communication is completed, and the SMF2 serving the UAVC can obtain the first user plane security protection activation indication or obtain the second user plane security protection policy corresponding to the UAVC updated according to the first user plane security protection activation indication during the process of the UAVC establishing the second PDU session for carrying C2 communication. Among them, whether the user plane security protection of the second PDU session is activated is determined by the first user plane security protection activation indication or the second user plane security protection policy. Therefore, based on this solution, it can be ensured that the user plane security protection activation method of the first PDU session for carrying C2 communication on the UAV side and the user plane security protection activation method of the second PDU session for carrying C2 communication on the UAVC side are the same, thereby ensuring the consistency of user plane security protection of C2 communication between the UAV and the UAVC.
[0298] The actions of SMF1, UTM / USS, SMF2, UFES1 or UFES2 in steps S901a to S905 can be performed by Figure 4 The processor 401 in the communication device 400 shown calls the application code stored in the memory 403 to instruct SMF1, UTM / USS, SMF2, UFES1 or UFES2 to execute, and this embodiment does not impose any limitation on this.
[0299] In another possible implementation, the UTM / USS may, based on the triggering of the pairing authorization process, obtain, through the UFES1 serving the UAV, a first user plane security protection activation indication for indicating whether the user plane security protection of the first PDU session (i.e., the session used by the UAV to carry the C2 communication between the UAV and the UAVC (hereinafter referred to as C2 communication between the UAV and the UAVC)) is activated. Furthermore, the SMF2 serving the UAVC may obtain the first user plane security protection activation indication during the process of the UAVC establishing a second PDU session for carrying the C2 communication, or obtain the second user plane security protection policy corresponding to the UAVC updated according to the first user plane security protection activation indication. For example, as Figure 10 As shown, a communication method provided by an embodiment of the present application includes a registration process of a UAV and a UAVC in a 3GPP network, such as the following steps S1001a and S1001b:
[0300] S1001a. The UAV registers with the 3GPP network. The specific registration process can be referred to the existing technology and will not be repeated here.
[0301] S1001b. UAVC registers with the 3GPP network. The specific registration process can be referred to the existing technology and will not be described here.
[0302] The specific implementation of step S1001a and step S1001b can refer to Figure 8 Steps S801a and S801b in the illustrated embodiment are not described in detail here.
[0303] Furthermore, the communication method provided in the embodiment of the present application also includes a process in which the UAV triggers the establishment of a PDU session (referred to as a third PDU session) for non-C2 communication, such as the following step S1002:
[0304] S1002, the UAV triggers the process of establishing the third PDU session. For details, please refer to the existing technology and will not be repeated here.
[0305] Furthermore, the communication method provided in the embodiment of the present application also includes a pairing authorization process, as shown in the following steps S1003-S1004:
[0306] S1003: The UAV sends a C2 pairing request 1 to the UTM / USS via the user side of the established third PDU session. Accordingly, the UTM / USS receives the C2 pairing request 1 from the UAV. The C2 pairing request 1 includes the external UAV ID of the UAV.
[0307] Of course, if the UAV and UAVC have been paired offline via a non-3GPP method (e.g., via Bluetooth) or other methods before step S1003, the UAV can obtain the pairing identifier of the UAVC with which it is paired. Furthermore, the C2 pairing request 1 may include the pairing identifier of the UAVC. Exemplarily, the pairing identifier of the UAVC may be, for example, a 3GPP UAVC ID or an external UAV ID of the UAVC.
[0308] Optionally, in an embodiment of the present application, when the UAVC pairing identifier is the UAVC's external UAV ID, the UAVC's external UAV ID can be included in the container of C2 pairing request 1. This ensures the security of the aforementioned parameters because the intermediate node transparently transmits the container without tampering with the container's contents. Furthermore, because the intermediate node does not need to parse the aforementioned parameters, it can conserve its processing resources and improve its processing efficiency.
[0309] S1004: After the UTM / USS determines that the UAVC paired with the UAV is online, it authorizes the C2 pairing request.
[0310] The relevant description of UAVC on the network and UTM / USS authorization of C2 pairing request can be found in Figure 8 Step S810 of the embodiment shown is not described again in detail.
[0311] In one possible implementation, if the C2 pairing request 1 includes the UAVC's external UAV ID, the UTM / USS can determine whether the UAVC has obtained authentication authorization from the UTM / USS based on the UAVC's external UAV ID. If the UAVC has obtained authentication authorization from the UTM / USS, the UTM / USS can determine that the UAVC is online. The UTM / USS obtains the UAVC's external UAV ID from the received C2 pairing request 1 by: parsing the container in the received C2 pairing request 1 to obtain the UAVC's external UAV ID contained in the container; or directly obtaining the UAVC's external UAV ID from the received C2 pairing request 1.
[0312] In another possible implementation, the pairing relationship between the UAV and the UAVC can be stored in the UTM / USS (for example, the manufacturers of the UAV and the UAVC pair the UAV and the UAVC when the equipment leaves the factory, and register the pairing relationship in the UTM / USS). The pairing relationship can be represented by the mapping relationship between the external UAV ID of the UAV and the external UAV ID of the UAVC. Furthermore, after the UTM / USS determines the external UAV ID of the UAVC based on the external UAV ID of the received UAV and the pairing relationship between the UAV and the UAVC, it determines whether the UAVC has obtained the authentication authorization of the UTM / USS based on the external UAV ID of the UAVC. If the UAVC has obtained the authentication authorization of the UTM / USS, the UTM / USS can determine that the UAVC is online.
[0313] If necessary, the embodiments of the present application are described using an example in which a UAV sends a C2 pairing request to a UTM / USS via a user-facing 3GPP access. Optionally, the UAV may also send a C2 pairing request to the UTM / USS via a non-3GPP access, where the C2 pairing request includes the UAV's external UAV ID, which is not specifically limited in the embodiments of the present application.
[0314] Furthermore, the communication method provided in the embodiment of the present application also includes a process in which the UTM / USS obtains a first user plane security protection activation indication for indicating whether user plane security protection of the first PDU session is activated based on the triggering of the pairing authorization process, as shown in the following steps S1005-S1013:
[0315] S1005. After pairing authorization is completed, the UTM / USS sends a request message 1 to UFES1. Accordingly, UFES1 receives the request message 1 from the UTM / USS. The request message 1 includes the external UAV ID of the UAV and is used to request a first user plane security protection enablement indication. The first user plane security protection enablement indication is used to indicate whether user plane security protection for the first PDU session is enabled.
[0316] Among them, the relevant description of the first user plane security protection activation instruction can refer to the description of "user plane security protection activation instruction" in the preamble of the specific implementation method, and will not be repeated here.
[0317] It should be noted that, in the embodiment of the present application, the request message 1 sent by UTM / USS to UFES1 is only Figure 5 The embodiment shown is an example of the third message. The third message may also be other, and the embodiment of the present application does not make specific limitations on this.
[0318] In a possible implementation, in an embodiment of the present application, the request message 1 may include indication information 4, and the indication information 4 is used to indicate that the request message 1 is used to request an indication for enabling security protection of the first user plane.
[0319] In another possible implementation, the request message 1 itself may indicate that the request message 1 is used to request a first user plane security protection activation instruction. For example, the request message 1 may be a user plane security protection activation instruction request message, which is not specifically limited in this embodiment of the present application.
[0320] S1006: UFES1 sends a request message 2 to SMF1. Accordingly, SMF1 receives the request message 2 from UFES1. The request message 2 includes a 3GPP UAV ID and is used to request a first user plane security protection activation indication.
[0321] It should be noted that, in the embodiment of the present application, the request message 2 sent by UFES1 to SMF1 is only Figure 6 The embodiment shown is an example of the fourth message. The fourth message may also be other, and the embodiment of the present application does not make specific limitations on this.
[0322] In an embodiment of the present application, after UFES1 obtains the external UAV ID of the UAV, it can "translate" the external UAV ID of the UAV in the request message 1 into a 3GPP UAV ID that can be recognized by the 3GPP network based on the mapping relationship between the stored 3GPP UAV ID and the external UAV ID of the UAV, and send the 3GPP UAV ID to SMF1 through the request message 2. This is explained here uniformly and will not be repeated below.
[0323] In a possible implementation, in an embodiment of the present application, the request message 2 may include indication information 5, and the indication information 5 is used to indicate that the request message 2 is used to request an indication for enabling security protection of the first user plane.
[0324] In another possible implementation, the request message 2 itself may indicate that the request message 2 is used to request a first user plane security protection activation instruction. For example, the request message 2 may be a user plane security protection activation instruction request message, which is not specifically limited in this embodiment of the present application.
[0325] S1007-S1011, same Figure 8 For the related description of S803-S807 in the embodiment shown, please refer to Figure 8 The embodiments shown are not described in detail here.
[0326] S1012: SMF1 sends a response message 2 to UFES1. Accordingly, UFES1 receives the response message 2 from SMF1. The response message 2 includes the 3GPP UAV ID and a first user plane security protection activation indication.
[0327] S1013: UFES1 sends a response message 1 to the UTM / USS. Accordingly, the UTM / USS receives the response message 1 from the UFES1. The response message 1 includes the external UAV ID of the UAV and a first user plane security protection activation indication.
[0328] In the embodiment of the present application, the external UAV ID of the UAV in the response message 1 is obtained by "translating" the 3GPP UAVID in the response message 2. The conversion method can refer to the above step S809 and will not be repeated here.
[0329] In the embodiment of the present application, after SMF1 receives the first user plane security protection activation instruction, it may further perform the following step S1014:
[0330] S1014, SMF1 triggers the process of establishing the first PDU session. Among them, the first PDU session in the embodiment of the present application can be obtained by modifying the above-mentioned third PDU session, or it can be newly created by SMF triggering UAV. The embodiment of the present application does not make specific limitations on this. The process of modifying the first PDU session based on the third PDU session and the process of creating a new first PDU session can refer to the existing technology and will not be repeated here.
[0331] Based on the above-mentioned solution, UTM / USS can obtain the first user plane security protection activation indication. Furthermore, SMF2 serving UAVC can obtain the first user plane security protection activation indication or obtain the second user plane security protection policy corresponding to UAVC updated according to the first user plane security protection activation indication during the process of UAVC establishing a second PDU session for carrying C2 communication. Among them, whether the user plane security protection of the second PDU session is activated is determined by the first user plane security protection activation indication or the second user plane security protection policy. For related implementation, please refer to Figure 8 Steps S814-S828 in the illustrated embodiment are not described in detail here.
[0332] Based on the communication method provided in the embodiment of the present application, since the UTM / USS can obtain the first user plane security protection activation indication for indicating whether the user plane security protection of the first PDU session carrying C2 communication is activated through the UFES1 serving the UAV based on the triggering of the pairing authorization process, and the SMF2 serving the UAVC can obtain the first user plane security protection activation indication during the process of the UAVC establishing the second PDU session carrying C2 communication or obtain the second user plane security protection policy corresponding to the UAVC updated according to the first user plane security protection activation indication. Among them, whether the user plane security protection of the second PDU session is activated is determined by the first user plane security protection activation indication or the second user plane security protection policy. Therefore, based on this solution, it can be ensured that the activation method of the user plane security protection of the first PDU session carrying C2 communication on the UAV side and the activation method of the user plane security protection of the second PDU session carrying C2 communication on the UAVC side are the same, thereby ensuring the consistency of the user plane security protection of C2 communication between the UAV and the UAVC.
[0333] The actions of SMF1, UTM / USS, SMF2, UFES1 or UFES2 in steps S1001a to S1014 can be performed by Figure 4 The processor 401 in the communication device 400 shown calls the application code stored in the memory 403 to instruct SMF1, UTM / USS, SMF2, UFES1 or UFES2 to execute, and this embodiment does not impose any limitation on this.
[0334] In another possible implementation, the UFES1 serving the UAV may obtain the first user plane security protection on indication for indicating whether the user plane security protection of the first PDU session (i.e., the session used by the UAV to carry the C2 communication between the UAV and the UAVC (hereinafter referred to as C2 communication between the UAV and the UAVC)) is on in the UUAA process or based on the triggering of the UUAA process, and maintain the mapping relationship between the first user plane security protection on indication and the external UAV ID of the UAV. Furthermore, in the pairing authorization process triggered by the UAV, the UFES1 serving the UAV may send the first user plane security protection on indication to the UTM / USS. Furthermore, the SMF2 serving the UAVC may obtain the first user plane security protection on indication or obtain the second user plane security protection policy corresponding to the UAVC updated according to the first user plane security protection on indication during the process of the UAVC establishing the second PDU session for carrying the C2 communication. For example, as Figure 11 As shown, a communication method provided by an embodiment of the present application includes a registration process of a UAV and a UAVC in a 3GPP network, such as the following steps S1101a and S1101b:
[0335] S1101a. The UAV registers with the 3GPP network. The specific registration process can be referred to the existing technology and will not be repeated here.
[0336] S1101b. UAVC registers with the 3GPP network. The specific registration process can be referred to the existing technology and will not be described in detail here.
[0337] The specific implementation of step S1101a and step S1101b can refer to Figure 8 Steps S801a and S801b in the illustrated embodiment are not described in detail here.
[0338] Furthermore, the communication method provided in the embodiment of the present application also includes a process in which the UAV triggers the establishment of a PDU session (referred to as a third PDU session) for non-C2 communication, such as the following steps S1102-S1112:
[0339] S1102: The UAV sends a session establishment request 3 to SMF1 in the 3GPP network. Accordingly, SMF1 receives the session establishment request 3 from the UAV. The session establishment request 3 includes the 3GPP UAV ID and indication information 6, which indicates that the third PDU session requested by the UAV is for non-C2 communication of the UAS.
[0340] In a possible implementation, the indication information 6 can be a display indication. For example, the indication information 6 can be a UAS operation request indication, which is a request other than the C2 request.
[0341] In another possible implementation, the indication information 6 can be an implicit indication. For example, the indication information 6 can be DNN information dedicated to the non-C2 communication of the UAS, or DNN and slice combination information dedicated to the non-C2 communication of the UAS, and the like.
[0342] S1103, the SMF 1 obtains, from the UDM 1, a first user plane security protection policy for establishing the first PDU session and a fourth user plane security protection policy for establishing the third PDU session after determining, according to the indication information 6, that the third PDU session requested by the UAV is used for the non-C2 communication of the UAS.
[0343] In the embodiments of the present application, the related descriptions of the first user plane security protection policy and the fourth user plane security protection policy can refer to the description of the "user plane security protection policy" in the preamble of the specific embodiments, which will not be repeated here.
[0344] In a possible implementation, the SMF 1 sends a request message to the UDM 1, where the request message includes the 3GPP UAV ID, and the request message is used to request the user plane security policy of the third PDU session. After receiving the request message, the UDM 1 determines the subscription information of the UAV according to the 3GPP UAV ID. The subscription information of the UAV includes the first user plane security protection policy and the fourth user plane security protection policy. Then, the UDM 1 can carry the first user plane security protection policy and the fourth user plane security protection policy in a response message sent to the SMF 1.
[0345] In another possible implementation, the SMF 1 can determine that the node requesting to establish the session is the UAV according to the information in the session establishment request 3, and then the SMF 1 sends a request message to the UDM 1, where the request message includes the 3GPP UAV ID, and the request message is used to request the first user plane security protection policy and the fourth user plane security protection policy. After receiving the request message, the UDM 1 obtains the first user plane security protection policy and the fourth user plane security protection policy from the subscription information of the UAV according to the 3GPP UAV ID. Then, the UDM 1 can carry the first user plane security protection policy and the fourth user plane security protection policy in a response message sent to the SMF 1.
[0346] It should be noted that, in the embodiment of the present application, the first user plane security protection policy and the fourth user plane security protection policy may be the same user plane security protection policy, and the embodiment of the present application does not make any specific limitation on this.
[0347] It should be noted that the embodiment of the present application is described by taking UDM2 as an example in which UDM2 stores corresponding user plane security protection policies for different types of PDU sessions. Of course, the user plane security protection policy corresponding to the UAV stored in UDM2 can also be one, and the user plane security protection policy can be used to establish both the first PDU session and the third PDU session. In this case, the user plane security protection policy corresponding to the UAV obtained by SMF1 from UDM1 is also one, and the embodiment of the present application does not specifically limit this.
[0348] S1104: SMF1 sends the first user plane security protection policy and the fourth user plane security protection policy to RAN device 1. Correspondingly, RAN device 1 receives the first user plane security protection policy and the fourth user plane security protection policy from SMF1.
[0349] S1105 . RAN device 1 determines a fourth user plane security protection enabling indication according to the fourth user plane security protection policy. The fourth user plane security protection enabling indication is used to indicate whether user plane security protection for the third PDU session is enabled.
[0350] Among them, the description of the fourth user plane security protection opening instruction can refer to the description of the "user plane security protection opening instruction" in the preamble of the specific implementation method, which will not be repeated here. In addition, the method in which the RAN device 1 determines the fourth user plane security protection opening instruction according to the fourth user plane security protection policy can refer to Figure 8 In the illustrated embodiment, the manner in which the RAN device 1 determines the first user plane security protection activation indication according to the first user plane security protection policy is not described in detail here.
[0351] S1106-S1108, same Figure 8 For the related description of S805-S807 in the embodiment shown, please refer to Figure 8 The embodiments shown are not described in detail here.
[0352] Furthermore, UFES1 can obtain the first user plane security protection activation indication through method P of step S1109 or steps S1110-S1111 in the third PDU session establishment process.
[0353] Method P is as follows:
[0354] S1109: SMF1 sends UUAA request 1 to UFES1. Accordingly, UFES1 receives UUAA request 1 from SMF1. The UUAA request 1 includes a 3GPP UAV ID and a first user plane security protection on indication.
[0355] That is, in the embodiment of the present application, SMF1 relies on UUAA request 1 in the session establishment process to send the 3GPP UAV ID and the first user plane security protection activation indication to UFES1.
[0356] Method Q is as follows:
[0357] S1110: SMF1 sends UUAA Request 2 to UFES1. In response, UFES1 receives UUAA Request 2 from SMF1. UUAA Request 2 includes a 3GPP UAV ID.
[0358] S1111. UFES1 obtains a first user plane security protection activation indication from SMF1.
[0359] In one possible implementation, UFES1 sends a request message to SMF1, the request message including 3GPP UAVID, requesting a first user plane security protection activation indication. After receiving the request message, SMF1 sends a response message to UFES1, the response message including a first user plane security protection activation indication.
[0360] Furthermore, the third PDU session establishment process provided in the embodiment of the present application further includes the following steps:
[0361] S1112: Other processes for establishing the third PDU session, such as UFES1 sending UUAA Request 3 including the UAV's external UAVI ID to the UTM / USS. After receiving UUAA Request 3 from UFES1, the UTM / USS performs UUAA on the UAV based on the UAV's external UAV ID. For related implementation details, please refer to the prior art and will not be repeated here.
[0362] Furthermore, the communication method provided in the embodiment of the present application may further include the following step S511:
[0363] S1113. UFES1 stores the mapping relationship between the external UAV ID of the UAV and the first user plane security protection activation indication.
[0364] In the embodiment of the present application, after UFES1 obtains the 3GPP UAV ID, it can determine the external UAV ID of the UAV corresponding to the 3GPP UAV ID based on the stored mapping relationship between the 3GPP UAV ID and the external UAV ID of the UAV. Then, the mapping relationship between the external UAV ID of the UAV and the first user plane security protection activation indication is stored. Of course, in the embodiment of the present application, UFES1 can store the mapping relationship between the external UAV ID of the UAV, the 3GPP UAV ID, and the first user plane security protection activation indication, and the embodiment of the present application does not specifically limit this.
[0365] Furthermore, the communication method provided in the embodiment of the present application also includes a process in which the UTM / USS obtains a first user plane security protection activation indication through a pairing authorization process, such as method X shown in steps S1114-S1116 below or method Y shown in steps S1117-S1119.
[0366] Method X is as follows:
[0367] S1114: The UAV sends a C2 pairing request 2 to the UFES 1 via the SMF 1. Accordingly, the UFES 1 receives the C2 pairing request 2 from the UAV. The C2 pairing request 2 includes the 3GPP UAV ID.
[0368] Of course, if the UAV and UAVC have been paired offline via a non-3GPP method (e.g., via Bluetooth) or other methods before step S1114, the UAV can obtain the pairing identifier of the UAVC it is paired with. Furthermore, the C2 pairing request 2 may include the UAVC pairing identifier. Exemplarily, the UAVC pairing identifier may be, for example, a 3GPP UAVC ID or an external UAV ID of the UAVC.
[0369] Optionally, in an embodiment of the present application, when the UAVC pairing identifier is the UAVC's external UAV ID, the UAVC's external UAV ID can be included in the container of C2 pairing request 2. This ensures the security of the aforementioned parameters because the intermediate node transparently transmits the container without tampering with the contents within the container. Furthermore, because the intermediate node does not need to parse the aforementioned parameters, it can conserve its processing resources and improve its processing efficiency.
[0370] S1115: UFES1 sends a C2 pairing request 3 to the UTM / USS. Accordingly, the UTM / USS receives the C2 pairing request 3 from UFES1. The C2 pairing request 3 includes the external UAV ID of the UAV and a first user plane security protection on indication.
[0371] In the embodiment of the present application, the external UAV ID of the UAV in the C2 pairing request 3 is obtained by "translating" the 3GPPUAV ID in the C2 pairing request 2. The conversion method can refer to the above step S809 and will not be repeated here.
[0372] In addition, in an embodiment of the present application, after UFES1 obtains the external UAV ID of the UAV, it can determine the first user plane security protection activation indication based on the stored mapping relationship between the external UAV ID of the UAV and the first user plane security protection activation indication, and send it to UTM / USS through the C2 pairing request 3.
[0373] In this embodiment of the present application, if the C2 pairing request 2 includes the UAVC pairing identifier, then the C2 pairing request 3 also includes the UAVC pairing identifier. When the UAVC pairing identifier is a 3GPP UAVC ID, UFES1 also needs to "translate" the 3GPP UAVC ID into an external UAV ID of the UAVC recognizable by the UTM / USS, and send the external UAV ID of the UAVC to the UTM / USS. The conversion method can be referred to in step S809 above and will not be repeated here.
[0374] S1116. After the UTM / USS determines that the UAVC paired with the UAV is online, it authorizes the C2 pairing request.
[0375] The relevant implementation of step S1116 can refer to Figure 10 The description of step S1004 in the embodiment shown is different, for example, in that C2 pairing request 1 in step S1004 is replaced by C2 pairing request 3 in the embodiment of the present application, which will not be repeated here.
[0376] Method Y is as follows:
[0377] S1117: The UAV sends a C2 pairing request 1 to the UTM / USS via the user side of the established third PDU session. Accordingly, the UTM / USS receives the C2 pairing request 1 from the UAV. The C2 pairing request includes the external UAV ID of the UAV.
[0378] The relevant implementation of step S1117 can be referred to Figure 10 The description of step S1003 in the illustrated embodiment will not be repeated here.
[0379] S1118. After the UTM / USS determines that the UAVC paired with the UAV is online, it authorizes the C2 pairing request.
[0380] The specific implementation of step S1118 may refer to the above step S1116, with the difference being that C2 pairing request 3 in step S1116 is replaced by C2 pairing request 1 in step S1118, which will not be repeated here.
[0381] S1119. After pairing authorization is completed, UTM / USS obtains the first user plane security protection activation instruction from UFES1.
[0382] In one possible implementation, the UTM / USS sends a request message to UFES1. The request message includes the external UAV ID of the UAV, and the request message is used to request a first user plane security protection activation indication. After receiving the request message, UFES1 can determine the first user plane security protection activation indication based on a stored mapping relationship between the external UAV ID of the UAV and the first user plane security protection activation indication, and carry the first user plane security protection activation indication in a response message sent to the UTM / USS.
[0383] It should be noted that, in the embodiment of the present application, the request message sent by UTM / USS to UFES1 is only Figure 5 The embodiment shown is an example of the third message. The third message may also be other, and the embodiment of the present application does not make specific limitations on this.
[0384] If necessary, the above-mentioned method X or method Y is described using the example of a UAV sending a C2 pairing request to a UTM / USS via 3GPP access. Optionally, the UAV may also send a C2 pairing request to the UTM / USS via non-3GPP access, where the C2 pairing request includes the UAV's external UAV ID. After receiving the C2 pairing request, the UTM / USS may obtain a first user plane security protection activation indication in accordance with steps S1118-S1119 above, which will not be further described here.
[0385] Based on the above method X or method Y, the UTM / USS can obtain the first user plane security protection activation instruction through the pairing authorization process. Further, the communication method provided in the embodiment of the present application also includes the following steps S1120-S1121:
[0386] S1120: After pairing authorization is completed, UTM / USS sends indication information 7 to SMF1 via UFES1. In response, SMF1 receives indication information 7 from UTM / USS. Indication information 7 is used to indicate that the C2 pairing authorization between the UAV and the UAVC is successful.
[0387] S1121, SMF1 triggers the process of establishing the first PDU session. Among them, the first PDU session in the embodiment of the present application can be obtained by modifying the above-mentioned third PDU session, or it can be newly created by SMF triggering UAV. The embodiment of the present application does not make specific limitations on this. The process of modifying the first PDU session based on the third PDU session and the process of creating a new first PDU session can refer to the existing technology and will not be repeated here.
[0388] Based on the above-mentioned solution, UTM / USS can obtain the first user plane security protection activation indication. Furthermore, SMF2 serving UAVC can obtain the first user plane security protection activation indication or obtain the second user plane security protection policy corresponding to UAVC updated according to the first user plane security protection activation indication during the process of UAVC establishing a second PDU session for carrying C2 communication. Among them, whether the user plane security protection of the second PDU session is activated is determined by the first user plane security protection activation indication or the second user plane security protection policy. For related implementation, please refer to Figure 8 Steps S814-S828 in the illustrated embodiment are not described in detail here.
[0389] Based on the communication method provided in the embodiment of the present application, since the UTM / USS can obtain the first user plane security protection activation indication for indicating whether the user plane security protection of the first PDU session carrying C2 communication is activated through the UFES1 serving the UAV based on the triggering of the pairing authorization process, and the SMF2 serving the UAVC can obtain the first user plane security protection activation indication during the process of the UAVC establishing the second PDU session carrying C2 communication or obtain the second user plane security protection policy corresponding to the UAVC updated according to the first user plane security protection activation indication. Among them, whether the user plane security protection of the second PDU session is activated is determined by the first user plane security protection activation indication or the second user plane security protection policy. Therefore, based on this solution, it can be ensured that the activation method of the user plane security protection of the first PDU session carrying C2 communication on the UAV side and the activation method of the user plane security protection of the second PDU session carrying C2 communication on the UAVC side are the same, thereby ensuring the consistency of the user plane security protection of C2 communication between the UAV and the UAVC.
[0390] The actions of SMF1, UTM / USS, SMF2, UFES1 or UFES2 in steps S1101a to S1121 can be performed by Figure 4 The processor 401 in the communication device 400 shown calls the application code stored in the memory 403 to instruct SMF1, UTM / USS, SMF2, UFES1 or UFES2 to execute, and this embodiment does not impose any limitation on this.
[0391] As an alternative, Figure 11 In the embodiment shown, after UFES1 obtains the first user plane security protection start indication in the process of establishing the third PDU session, it can send the first user plane security protection start indication to UTM / USS in other processes of establishing the third PDU session described in step S1112. For example, UFES1 can send the first user plane security protection start indication to UTM / USS through the above-mentioned UUAA request 3. In this way, after UFES1 receives the UUAA request 3, it can obtain the first user plane security protection start indication without going through Figure 11 In the embodiment shown, the first user plane security protection opening indication is obtained by way of X or way Y. The embodiment of the present application will not elaborate on this scheme in detail. For details, please refer to Figure 11 Related steps in the embodiment shown.
[0392] It can be understood that in the above embodiments, the methods and / or steps implemented by the management device can also be implemented by components (such as chips or circuits) that can be used for the management device; the methods and / or steps implemented by the session management entity (including the first session management entity or the second session management entity) can also be implemented by components (such as chips or circuits) that can be used for the session management entity.
[0393] The above mainly introduces the solutions provided by the embodiments of the present application from the perspective of interaction between various network elements. Accordingly, the embodiments of the present application also provide a communication device, which is used to implement the various methods described above. The communication device can be the management device in the above method embodiments, or a device that includes the above management device, or a component that can be used for the management device; or the communication device can be the session management entity (including the first session management entity or the second session management entity) in the above method embodiments, or a device that includes the above session management entity, or a component that can be used for the session management entity. It is understood that in order to implement the above functions, the communication device includes hardware structures and / or software modules corresponding to performing each function. Those skilled in the art should readily appreciate that, in combination with the various exemplary units and algorithm steps described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is implemented in hardware or in a hardware-driven manner by computer software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0394] In the embodiment of the present application, the functional modules of the communication device can be divided according to the above method embodiment. For example, each functional module can be divided according to each function, or two or more functions can be integrated into one processing module. The above integrated modules can be implemented in the form of hardware or in the form of software functional modules. It should be noted that the division of modules in the embodiment of the present application is schematic and is only a logical functional division. In actual implementation, there may be other division methods.
[0395] Figure 12 1 shows a schematic structural diagram of a communication device 120. The communication device 120 includes a transceiver module 1201 and a processing module 1202. The transceiver module 1201, also called a transceiver unit, is used to implement transceiver functions, and can be, for example, a transceiver circuit, a transceiver, a transceiver, or a communication interface.
[0396] Here, the communication device 120 is taken as the management device in the above method embodiment as an example:
[0397] In one possible implementation, the processing module 1202 is used to obtain a first user plane security protection activation indication, where the first user plane security protection activation indication is used to indicate whether user plane security protection for the first session is activated. The first session is a session in which the first terminal device is used to carry C2 communication, the first terminal device is the initiating device of the C2 communication, the second terminal device is the opposite device of the C2 communication, and C2 communication is the communication between the first terminal device and the second terminal device. The transceiver module 1201 is used to trigger the second terminal device to initiate the establishment of a second session, where whether user plane security protection for the second session is activated is determined by the first user plane security protection activation indication, and the second session is a session in which the second terminal device is used to carry C2 communication.
[0398] In one possible implementation, the transceiver module 1201 is used to trigger the second terminal device to initiate the establishment of a second session, including: sending a first message to the second terminal device, the first message is used to trigger the second terminal device to initiate the establishment of a second session; and sending a first user plane security protection activation indication to the second unified data management entity, wherein the second unified data management entity is a unified data management entity serving the second terminal device.
[0399] In another possible implementation, the transceiver module 1201 is used to trigger the second terminal device to initiate the establishment of a second session, including: sending a first message to the second terminal device, the first message is used to trigger the second terminal device to initiate the establishment of the second session; and, receiving a second message from the second proxy function entity, and sending a first user plane security protection activation indication to the second proxy function entity; wherein the second message includes identification information of the second terminal device, the second message is used to request the first user plane security protection activation indication, the second proxy function entity is used to provide an interface from the second session management entity to the management device, and the second session management entity is a session management entity serving the second terminal device.
[0400] In one possible implementation, the processing module 1202 is specifically used to: receive a first user plane security protection activation indication from a first session management entity through the transceiver module 1201, where the first session management entity is a session management entity serving the first terminal device; or, receive a first user plane security protection activation indication from the first terminal device through the transceiver module 1201; or, receive a first user plane security protection activation indication from a first proxy function entity through the transceiver module 1201, where the first proxy function entity is used to provide an interface from the first session management entity to the management device.
[0401] In another possible implementation, the processing module 1202 is specifically used to: determine that the pairing authorization between the first terminal device and the second terminal device is successful; send a third message to the first proxy function entity through the transceiver module 1201, the third message including the identification information of the first terminal device, and the third message is used to request a first user plane security protection activation indication; wherein the first proxy function entity is used to provide an interface from the first session management entity to the management device, and the first session management entity is a session management entity serving the first terminal device; receive a first user plane security protection activation indication from the first proxy function entity through the transceiver module 1201.
[0402] Take the communication device 120 as the first session management entity in the above method embodiment as an example:
[0403] In a possible implementation, the processing module 1202 is configured to obtain a first user plane security protection start indication, where the first user plane security protection start indication is used to indicate whether user plane security protection of a first session is started. The first session is a session used by a first terminal device to carry C2 communication, the first terminal device is an initiating terminal device of the C2 communication, a second terminal device is a terminal device opposite to the first terminal device in the C2 communication, the C2 communication is communication between the first terminal device and the second terminal device, and the first session management entity is a session management entity serving the first terminal device. The transceiver module 1201 is configured to send the first user plane security protection start indication, where the first user plane security protection start indication is used to determine whether user plane security protection of a second session is started. The second session is a session used by the second terminal device to carry the C2 communication.
[0404] In a possible implementation, the transceiver module 1201 is specifically configured to send the first user plane security protection start indication to a management device.
[0405] In another possible implementation, the transceiver module 1201 is specifically configured to send the first user plane security protection start indication to a first proxy function entity. The first proxy function entity is used to provide an interface between the first session management entity and the management device.
[0406] Optionally, in the embodiment of the application, the transceiver module 1201 is further configured to receive a fourth message from the first proxy function entity before the first session management entity sends the first user plane security protection start indication to the first proxy function entity. The fourth message includes identification information of the first terminal device, and the fourth message is used to request the first user plane security protection start indication.
[0407] In a possible implementation, the processing module 1202 is specifically configured to obtain a first user plane security protection policy from a first unified data management entity serving the first terminal device, send the first user plane security protection policy to a first access network device serving the first terminal device through the transceiver module 1201, and receive a first user plane security protection start indication from the first access network device through the transceiver module 1201. The first user plane security protection start indication is determined according to the first user plane security protection policy.
[0408] In one possible implementation, the processing module 1202 is specifically used to: obtain a first user plane security protection policy from a first unified data management entity serving the first terminal device; send the first user plane security protection policy to a first access network device serving the first terminal device through the transceiver module 1201; receive a seventh message from the first access network device through the transceiver module 1201, the seventh message being used to indicate that the first access network device has established a first session according to the first user plane security protection policy; and determine, in response to the seventh message, the first user plane security protection activation indication according to the first user plane security protection policy.
[0409] Take the communication device 120 as the second session management entity in the above method embodiment as an example:
[0410] In one possible implementation, the processing module 1202 is configured to obtain a first user plane security protection activation indication, where the first user plane security protection activation indication is used to indicate whether user plane security protection for the first session is activated. The first session is a session in which the first terminal device is used to carry C2 communication, the first terminal device is the initiating device of the C2 communication, the second terminal device is the counterpart device of the C2 communication, the C2 communication is the communication between the first terminal device and the second terminal device, and the second session management entity is the session management entity serving the second terminal device. The transceiver module 1201 is configured to send a first user plane security protection activation indication to a second access network device serving the second terminal device; the first user plane security protection activation indication is used to determine whether user plane security protection for the second session is activated, where the second session is a session in which the second terminal device is used to carry C2 communication.
[0411] Take the communication device 120 as the second session management entity in the above method embodiment as an example:
[0412] In one possible implementation, processing module 1202 is configured to obtain a first user plane security protection enable indication, where the first user plane security protection enable indication is used to indicate whether user plane security protection is enabled for a first session. The first session is a session used by a first terminal device to carry C2 communications, the first terminal device is the initiating device of the C2 communications, the second terminal device is the peer device of the C2 communications, C2 communications are communications between the first terminal device and the second terminal device, and the second session management entity is a session management entity serving the second terminal device. Processing module 1202 is further configured to determine a third user plane security protection policy based on the first user plane security protection enable indication, where the third user plane security protection policy only includes forcibly enabling security protection or forcibly disabling security protection. Transceiver module 1201 is configured to send the third user plane security protection policy to a second access network device serving the second terminal device. The third user plane security protection policy is used to determine the second user plane security protection enable indication, where the second user plane security protection enable indication is used to determine whether user plane security protection is enabled for a second session, where the second session is a session used by the second terminal device to carry C2 communications.
[0413] In the embodiment of the present application, the processing module 1202 is used to determine the third user plane security protection policy according to the first user plane security protection activation indication. The solution can be referred to the aforementioned invention content part and will not be repeated here.
[0414] In one possible implementation, the processing module 1202 is used to obtain an indication of enabling security protection of the first user plane, including: sending a fifth message to a second unified data management entity serving the second terminal device through the transceiver module 1201, the fifth message including identification information of the second terminal device, and the fifth message being used to request a second user plane security protection policy; receiving a second user plane security protection policy and an indication of enabling security protection of the first user plane from the second unified data management entity through the transceiver module 1201.
[0415] In another possible implementation, the processing module 1202 is used to obtain the first user plane security protection activation indication, including: sending a sixth message to the second proxy function entity through the transceiver module 1201, the sixth message including the identification information of the second terminal device, the sixth message being used to request the first user plane security protection activation indication, the second proxy function entity being used to provide an interface from the second session management entity to the management device; receiving the first user plane security protection activation indication from the second proxy function entity through the transceiver module 1201.
[0416] Optionally, in an embodiment of the present application, the transceiver module 1201 is further used to receive indication information from the second terminal device before sending the sixth message to the second proxy function entity, where the indication information indicates that the second terminal device requests to establish a second session for responding to the C2 communication initiated by the first terminal device.
[0417] Among them, all relevant contents of each step involved in the above method embodiment can be referred to the functional description of the corresponding functional module and will not be repeated here.
[0418] In this embodiment, the communication device 120 is presented in the form of various functional modules divided in an integrated manner. The "module" here can refer to a specific ASIC, circuit, processor and memory that executes one or more software or firmware programs, integrated logic circuit, and / or other devices that can provide the above functions. In a simple embodiment, those skilled in the art can imagine that the communication device 120 can be used. Figure 4 The form of the communication device 400 is shown.
[0419] for example, Figure 4 The processor 401 in the communication device 400 shown can call the computer-executable instructions stored in the memory 403 to enable the communication device 400 to execute the communication method in the above method embodiment.
[0420] Specifically, Figure 12 The functions / implementation processes of the transceiver module 1201 and the processing module 1202 can be realized by Figure 4 The processor 401 in the communication device 400 shown calls the computer execution instructions stored in the memory 403 to implement. Or, Figure 12 The function / implementation process of the processing module 1202 can be achieved by Figure 4 The processor 401 in the communication device 400 shown calls the computer execution instructions stored in the memory 403 to implement, Figure 12 The function / implementation process of the transceiver module 1201 can be achieved by Figure 4 The communication interface 404 in the communication device 400 shown in FIG.
[0421] Since the communication device 120 provided in this embodiment can execute the above communication method, the technical effects that can be obtained can refer to the above method embodiments and will not be repeated here.
[0422] It should be noted that one or more of the above modules or units can be implemented by software, hardware, or a combination of the two. When any of the above modules or units is implemented by software, the software exists in the form of computer program instructions and is stored in a memory, and a processor can be used to execute the program instructions and implement the above method flow. The processor can be built into an SoC (system on chip) or an ASIC, or it can be an independent semiconductor chip. In addition to the core used to execute software instructions to perform calculations or processing within the processor, it can further include necessary hardware accelerators, such as a field programmable gate array (FPGA), a PLD (programmable logic device), or a logic circuit that implements dedicated logic operations.
[0423] When the above modules or units are implemented in hardware, the hardware can be any one or any combination of a CPU, a microprocessor, a digital signal processing (DSP) chip, a microcontroller unit (MCU), an artificial intelligence processor, an ASIC, a SoC, an FPGA, a PLD, a dedicated digital circuit, a hardware accelerator or a non-integrated discrete device, which can run the necessary software or not rely on the software to execute the above method flow.
[0424] Optionally, an embodiment of the present application further provides a chip system, comprising: at least one processor and an interface, wherein the at least one processor is coupled to a memory via the interface, and when the at least one processor executes a computer program or instruction in the memory, the method in any of the above method embodiments is executed. In one possible implementation, the communication device also includes a memory. Optionally, the chip system can be composed of a chip, or can include a chip and other discrete devices, which is not specifically limited in the embodiment of the present application.
[0425] In the above embodiments, all or part of the embodiments may be implemented by software, hardware, firmware, or any combination thereof. When implemented using a software program, all or part of the embodiments may be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present application are generated. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium may be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more media integrated therein. The available medium may be a magnetic medium (eg, a floppy disk, a hard disk, a magnetic tape), an optical medium (eg, a DVD), or a semiconductor medium (eg, a solid state disk (SSD)).
[0426] Although the present application is described herein in conjunction with various embodiments, in the process of implementing the claimed application, those skilled in the art can understand and implement other changes to the disclosed embodiments by reviewing the drawings, the disclosure, and the appended claims. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "an" does not exclude multiple situations. A single processor or other unit can implement several functions listed in the claims. Certain measures are recorded in different dependent claims, but this does not mean that these measures cannot be combined to produce good results.
[0427] Although the present application has been described with reference to specific features and embodiments thereof, it is apparent that various modifications and combinations may be made thereto without departing from the spirit and scope of the present application. Accordingly, this specification and the drawings are merely illustrative of the present application as defined by the appended claims and are deemed to cover any and all modifications, variations, combinations or equivalents within the scope of the present application. Obviously, those skilled in the art may make various modifications and variations to the present application without departing from the spirit and scope of the present application. Thus, the present application is intended to include such modifications and variations as fall within the scope of the claims of the present application and their equivalents.
Claims
1. A communication method, characterized in that: The method comprises: The management device obtains a first user plane security protection activation indication, where the first user plane security protection activation indication is used to indicate whether user plane security protection for a first session is activated; wherein the first session is a session used by a first terminal device to carry C2 communication, the first terminal device is an initiating end device of the C2 communication, the second terminal device is a peer device of the C2 communication, and the C2 communication is communication between the first terminal device and the second terminal device; The management device triggers the second terminal device to initiate the establishment of a second session, wherein whether the user plane security protection of the second session is enabled is determined by the first user plane security protection enable indication, and the second session is a session used by the second terminal device to carry the C2 communication.
2. The method according to claim 1, characterized in that The management device triggering the second terminal device to initiate establishment of a second session includes: The management device sends a first message to the second terminal device, where the first message is used to trigger the second terminal device to initiate establishment of the second session; Furthermore, the management device sends the first user plane security protection activation indication to a second unified data management entity, wherein the second unified data management entity is a unified data management entity serving the second terminal device.
3. The method according to claim 1, characterized in that The management device triggering the second terminal device to initiate establishment of a second session includes: The management device sends a first message to the second terminal device, where the first message is used to trigger the second terminal device to initiate establishment of a second session; In addition, the management device receives a second message from the second proxy function entity and sends the first user plane security protection activation indication to the second proxy function entity; wherein the second message includes the identification information of the second terminal device, the second message is used to request the first user plane security protection activation indication, and the second proxy function entity is used to provide an interface from the second session management entity to the management device, and the second session management entity is a session management entity serving the second terminal device.
4. The method according to any one of claims 1 to 3, characterized in that The management device obtains a first user plane security protection enabling indication, including: The management device receives the first user plane security protection activation indication from a first session management entity, where the first session management entity is a session management entity serving the first terminal device; Alternatively, the management device receives the first user plane security protection activation instruction from the first terminal device; Alternatively, the management device receives the first user plane security protection activation indication from a first proxy function entity, where the first proxy function entity is used to provide an interface from the first session management entity to the management device.
5. The method according to any one of claims 1 to 3, characterized in that The management device obtains a first user plane security protection enabling indication, including: The management device determines that pairing authorization between the first terminal device and the second terminal device is successful; The management device sends a third message to the first proxy function entity, where the third message includes identification information of the first terminal device, and the third message is used to request the first user plane security protection activation indication; wherein the first proxy function entity is used to provide an interface from a first session management entity to the management device, and the first session management entity is a session management entity serving the first terminal device; The management device receives the first user plane security protection activation instruction from the first proxy function entity.
6. The method according to claim 1, characterized in that The first user plane security protection activation indication includes a first user plane confidentiality protection activation result indication and a first user plane integrity protection activation result indication; the first user plane confidentiality protection activation result indication is used to indicate whether the user plane confidentiality protection is activated or not; the first user plane integrity protection activation result indication is used to indicate whether the user plane integrity protection is activated or not.
7. A communication method, characterized in that: The method comprises: A first session management entity obtains a first user plane security protection enable indication, where the first user plane security protection enable indication is used to indicate whether user plane security protection for a first session is enabled; wherein the first session is a session used by a first terminal device to carry C2 communication, the first terminal device is an initiator device of the C2 communication, the second terminal device is a peer device of the C2 communication, the C2 communication is communication between the first terminal device and the second terminal device, and the first session management entity is a session management entity serving the first terminal device; The first session management entity sends the first user plane security protection activation indication, which is used to determine whether the user plane security protection of the second session is activated, and the second session is a session used by the second terminal device to carry the C2 communication.
8. The method according to claim 7, characterized in that The first session management entity sending the first user plane security protection enabling indication includes: The first session management entity sends the first user plane security protection activation indication to the management device.
9. The method according to claim 7, characterized in that The first session management entity sending the first user plane security protection enabling indication includes: The first session management entity sends the first user plane security protection activation indication to the first proxy function entity; wherein the first proxy function entity is used to provide an interface from the first session management entity to a management device.
10. The method according to claim 9, characterized in that Before the first session management entity sends the first user plane security protection activation instruction to the first proxy function entity, the method further includes: The first session management entity receives a fourth message from the first proxy function entity, where the fourth message includes identification information of the first terminal device, and the fourth message is used to request an indication of enabling security protection of the first user plane.
11. The method according to any one of claims 7 to 10, characterized in that: The first session management entity obtains a first user plane security protection enabling indication, including: The first session management entity obtains a first user plane security protection policy from a first unified data management entity serving the first terminal device; The first session management entity sends the first user plane security protection policy to a first access network device serving the first terminal device; The first session management entity receives the first user plane security protection activation instruction from the first access network device, wherein the first user plane security protection activation instruction is determined according to the first user plane security protection policy.
12. The method according to any one of claims 7 to 10, characterized in that: The first session management entity obtains a first user plane security protection enabling indication, including: The first session management entity obtains a first user plane security protection policy from a first unified data management entity serving the first terminal device; The first session management entity sends the first user plane security protection policy to a first access network device serving the first terminal device; The first session management entity receives a seventh message from the first access network device, where the seventh message is used to indicate that the first access network device has established the first session according to the first user plane security protection policy; In response to the seventh message, the first session management entity determines the first user plane security protection activation indication according to the first user plane security protection policy.
13. The method according to claim 7, characterized in that The first user plane security protection activation indication includes a first user plane confidentiality protection activation result indication and a first user plane integrity protection activation result indication; the first user plane confidentiality protection activation result indication is used to indicate whether the user plane confidentiality protection is activated or not; the first user plane integrity protection activation result indication is used to indicate whether the user plane integrity protection is activated or not.
14. A communication method, characterized in that: The method comprises: The second session management entity obtains a first user plane security protection enable indication, where the first user plane security protection enable indication is used to indicate whether user plane security protection for the first session is enabled; wherein the first session is a session used by a first terminal device to carry C2 communication, the first terminal device is an initiator device of the C2 communication, the second terminal device is a peer device of the C2 communication, the C2 communication is communication between the first terminal device and the second terminal device, and the second session management entity is a session management entity serving the second terminal device; The second session management entity sends the first user plane security protection activation indication to the second access network device serving the second terminal device; wherein the first user plane security protection activation indication is used to determine whether the user plane security protection of the second session is activated, and the second session is a session used by the second terminal device to carry the C2 communication.
15. A communication method, characterized in that: The method comprises: The second session management entity obtains a first user plane security protection enable indication, where the first user plane security protection enable indication is used to indicate whether user plane security protection for the first session is enabled; wherein the first session is a session used by a first terminal device to carry C2 communication, the first terminal device is an initiator device of the C2 communication, the second terminal device is a peer device of the C2 communication, the C2 communication is communication between the first terminal device and the second terminal device, and the second session management entity is a session management entity serving the second terminal device; The second session management entity determines a third user plane security protection policy according to the first user plane security protection activation indication, where the third user plane security protection policy only includes forcibly activating security protection or forcibly not activating security protection; The second session management entity sends the third user plane security protection policy to the second access network device serving the second terminal device; wherein the third user plane security protection policy is used to determine the second user plane security protection activation indication, and the second user plane security protection activation indication is used to determine whether the user plane security protection of the second session is activated, and the second session is a session used by the second terminal device to carry the C2 communication.
16. The method according to claim 15, characterized in that The second session management entity determines, according to the first user plane security protection enabling indication, a third user plane security protection policy, including: When the first user plane security protection enabling indication includes a first user plane confidentiality protection enabling result indication and a first user plane integrity protection enabling result indication, and the first user plane confidentiality protection enabling result indication is used to indicate that user plane confidentiality protection is enabled, and the first user plane integrity protection enabling result indication is used to indicate that user plane integrity protection is enabled, the second session management entity determines that the third user plane security protection policy is user plane confidentiality protection forced enabling and user plane integrity protection forced enabling; Alternatively, when the first user plane security protection activation indication includes a first user plane confidentiality protection activation result indication and a first user plane integrity protection activation result indication, and the first user plane confidentiality protection activation result indication is used to indicate that user plane confidentiality protection is not activated, and the first user plane integrity protection activation result indication is used to indicate that user plane integrity protection is not activated, the second session management entity determines that the third user plane security protection policy is that user plane confidentiality protection is forcibly not activated and user plane integrity protection is forcibly not activated; Alternatively, when the first user plane security protection activation indication includes a first user plane confidentiality protection activation result indication and a first user plane integrity protection activation result indication, and the first user plane confidentiality protection activation result indication is used to indicate that user plane confidentiality protection is not activated, and the first user plane integrity protection activation result indication is used to indicate that user plane integrity protection is activated, the second session management entity determines that the third user plane security protection policy is that user plane confidentiality protection is forcibly not activated and user plane integrity protection is forcibly activated; Alternatively, when the first user plane security protection activation indication includes a first user plane confidentiality protection activation result indication and a first user plane integrity protection activation result indication, and the first user plane confidentiality protection activation result indication is used to indicate that user plane confidentiality protection is activated, and the first user plane integrity protection activation result indication is used to indicate that user plane integrity protection is not activated, the second session management entity determines that the third user plane security protection policy is that user plane confidentiality protection is forcibly activated and user plane integrity protection is forcibly not activated.
17. The method according to any one of claims 14 to 16, characterized in that: The second session management entity obtains the first user plane security protection activation indication, including: The second session management entity sends a fifth message to the second unified data management entity serving the second terminal device, where the fifth message includes identification information of the second terminal device and is used to request a second user plane security protection policy; The second session management entity receives the second user plane security protection policy and the first user plane security protection activation indication from the second unified data management entity.
18. The method according to any one of claims 14 to 16, characterized in that: The second session management entity obtains the first user plane security protection activation indication, including: The second session management entity sends a sixth message to the second proxy function entity, where the sixth message includes identification information of the second terminal device, and the sixth message is used to request an indication of enabling security protection of the first user plane. The second proxy function entity is used to provide an interface from the second session management entity to the management device. The second session management entity receives the first user plane security protection activation indication from the second proxy function entity.
19. The method according to claim 18, characterized in that Before the second session management entity sends the sixth message to the second proxy function entity, the method further includes: The second session management entity receives indication information from the second terminal device, where the indication information indicates that the second session requested to be established by the second terminal device is used to respond to the C2 communication initiated by the first terminal device.
20. A management device, characterized in that: The management device includes: a processing module and a transceiver module; The processing module is configured to obtain a first user plane security protection activation indication, where the first user plane security protection activation indication is used to indicate whether user plane security protection for a first session is activated; wherein the first session is a session used by a first terminal device to carry C2 communication, the first terminal device is an initiating end device of the C2 communication, the second terminal device is a peer device of the C2 communication, and the C2 communication is communication between the first terminal device and the second terminal device; The transceiver module is used to trigger the second terminal device to initiate the establishment of a second session, wherein whether the user plane security protection of the second session is enabled is determined by the first user plane security protection enable indication, and the second session is a session used by the second terminal device to carry the C2 communication.
21. The management device according to claim 20, characterized in that The transceiver module is configured to trigger the second terminal device to initiate establishment of a second session, including: Sending a first message to the second terminal device, where the first message is used to trigger the second terminal device to initiate the establishment of the second session; and sending an indication of enabling the first user plane security protection to the second unified data management entity, wherein the second unified data management entity is a unified data management entity serving the second terminal device.
22. The management device according to claim 20, characterized in that The transceiver module is configured to trigger the second terminal device to initiate establishment of a second session, including: Sending a first message to the second terminal device, where the first message is used to trigger the second terminal device to initiate the establishment of a second session; and receiving a second message from a second proxy function entity, and sending the first user plane security protection activation indication to the second proxy function entity; wherein the second message includes identification information of the second terminal device, the second message is used to request the first user plane security protection activation indication, and the second proxy function entity is used to provide an interface from a second session management entity to the management device, and the second session management entity is a session management entity serving the second terminal device.
23. The management device according to any one of claims 20 to 22, characterized in that: The processing module is specifically used for: receiving, by the transceiver module, a first user plane security protection activation indication from a first session management entity, where the first session management entity is a session management entity serving the first terminal device; Alternatively, receiving, through the transceiver module, the first user plane security protection activation instruction from the first terminal device; Alternatively, the first user plane security protection activation indication is received from a first proxy function entity through the transceiver module, and the first proxy function entity is used to provide an interface from the first session management entity to the management device.
24. The management device according to any one of claims 20 to 22, characterized in that: The processing module is specifically used for: Determine that the pairing authorization between the first terminal device and the second terminal device is successful; send a third message to the first proxy function entity through the transceiver module, the third message including the identification information of the first terminal device, and the third message is used to request the first user plane security protection activation indication; wherein, the first proxy function entity is used to provide an interface from the first session management entity to the management device, and the first session management entity is a session management entity serving the first terminal device; receive the first user plane security protection activation indication from the first proxy function entity through the transceiver module.
25. The management device according to claim 20, characterized in that The first user plane security protection activation indication includes a first user plane confidentiality protection activation result indication and a first user plane integrity protection activation result indication; the first user plane confidentiality protection activation result indication is used to indicate whether the user plane confidentiality protection is activated or not; the first user plane integrity protection activation result indication is used to indicate whether the user plane integrity protection is activated or not.
26. A first session management entity, characterized in that: The first session management entity includes: a processing module and a transceiver module; The processing module is configured to obtain a first user plane security protection activation indication, where the first user plane security protection activation indication is used to indicate whether user plane security protection for a first session is activated; wherein the first session is a session used by a first terminal device to carry C2 communication, the first terminal device is an initiating end device of the C2 communication, the second terminal device is a peer device of the C2 communication, the C2 communication is communication between the first terminal device and the second terminal device, and the first session management entity is a session management entity serving the first terminal device; The transceiver module is used to send the first user plane security protection activation indication, which is used to determine whether the user plane security protection of the second session is activated. The second session is a session used by the second terminal device to carry the C2 communication.
27. The first session management entity according to claim 26, characterized in that The transceiver module is specifically used for: Sending the first user plane security protection activation indication to the management device.
28. The first session management entity according to claim 26, characterized in that The transceiver module is specifically used for: Sending the first user plane security protection activation indication to a first proxy function entity; wherein the first proxy function entity is used to provide an interface from the first session management entity to a management device.
29. The first session management entity according to claim 28, characterized in that The transceiver module is also used to receive a fourth message from the first proxy function entity before the first session management entity sends the first user plane security protection activation indication to the first proxy function entity, wherein the fourth message includes the identification information of the first terminal device, and the fourth message is used to request the first user plane security protection activation indication.
30. The first session management entity according to any one of claims 26 to 29, characterized in that: The processing module is specifically used for: Obtaining a first user plane security protection policy from a first unified data management entity serving the first terminal device; sending the first user plane security protection policy to a first access network device serving the first terminal device through the transceiver module; The first user plane security protection activation instruction is received from the first access network device through the transceiver module, wherein the first user plane security protection activation instruction is determined according to the first user plane security protection policy.
31. The first session management entity according to any one of claims 26 to 29, characterized in that: The processing module is specifically used for: Obtaining a first user plane security protection policy from a first unified data management entity serving the first terminal device; sending the first user plane security protection policy to a first access network device serving the first terminal device through the transceiver module; After receiving the seventh message from the first access network device through the transceiver module, in response to the seventh message, the first user plane security protection activation indication is determined according to the first user plane security protection policy, wherein the seventh message is used to indicate that the first access network device has established the first session according to the first user plane security protection policy.
32. The first session management entity according to claim 26, characterized in that The first user plane security protection activation indication includes a first user plane confidentiality protection activation result indication and a first user plane integrity protection activation result indication; the first user plane confidentiality protection activation result indication is used to indicate whether the user plane confidentiality protection is activated or not; the first user plane integrity protection activation result indication is used to indicate whether the user plane integrity protection is activated or not.
33. A second session management entity, characterized in that: The second session management entity includes: a processing module and a transceiver module; The processing module is configured to obtain a first user plane security protection activation indication, where the first user plane security protection activation indication is used to indicate whether user plane security protection for a first session is activated; wherein the first session is a session used by a first terminal device to carry C2 communication, the first terminal device is an initiating end device of the C2 communication, the second terminal device is a peer device of the C2 communication, the C2 communication is communication between the first terminal device and the second terminal device, and the second session management entity is a session management entity serving the second terminal device; The transceiver module is used to send the first user plane security protection activation indication to the second access network device serving the second terminal device; wherein the first user plane security protection activation indication is used to determine whether the user plane security protection of the second session is activated, and the second session is a session used by the second terminal device to carry the C2 communication.
34. A second session management entity, characterized in that: The second session management entity includes: a processing module and a transceiver module; The processing module is configured to obtain a first user plane security protection activation indication, where the first user plane security protection activation indication is used to indicate whether user plane security protection for a first session is activated; wherein the first session is a session used by a first terminal device to carry C2 communication, the first terminal device is an initiating end device of the C2 communication, the second terminal device is a peer device of the C2 communication, the C2 communication is communication between the first terminal device and the second terminal device, and the second session management entity is a session management entity serving the second terminal device; The processing module is further configured to determine a third user plane security protection policy according to the first user plane security protection enabling indication, wherein the third user plane security protection policy only includes forcibly enabling security protection or forcibly not enabling security protection; The transceiver module is used to send the third user plane security protection policy to the second access network device serving the second terminal device; wherein the third user plane security protection policy is used to determine the second user plane security protection activation indication, and the second user plane security protection activation indication is used to determine whether the user plane security protection of the second session is activated, and the second session is the session used by the second terminal device to carry the C2 communication.
35. The second session management entity according to claim 34, characterized in that: The processing module is configured to determine a third user plane security protection policy according to the first user plane security protection enabling indication, including: When the first user plane security protection activation indication includes a first user plane confidentiality protection activation result indication and a first user plane integrity protection activation result indication, and the first user plane confidentiality protection activation result indication is used to indicate that user plane confidentiality protection is activated, and the first user plane integrity protection activation result indication is used to indicate that user plane integrity protection is activated, determining that the third user plane security protection policy is user plane confidentiality protection forced activation and user plane integrity protection forced activation; Alternatively, when the first user plane security protection activation indication includes a first user plane confidentiality protection activation result indication and a first user plane integrity protection activation result indication, and the first user plane confidentiality protection activation result indication is used to indicate that user plane confidentiality protection is not enabled, and the first user plane integrity protection activation result indication is used to indicate that user plane integrity protection is not enabled, determining that the third user plane security protection policy is that user plane confidentiality protection is forcibly disabled and user plane integrity protection is forcibly disabled; Alternatively, when the first user plane security protection activation indication includes a first user plane confidentiality protection activation result indication and a first user plane integrity protection activation result indication, and the first user plane confidentiality protection activation result indication is used to indicate that user plane confidentiality protection is not activated, and the first user plane integrity protection activation result indication is used to indicate that user plane integrity protection is activated, determining that the third user plane security protection policy is that user plane confidentiality protection is forcibly not activated and user plane integrity protection is forcibly activated; Alternatively, when the first user plane security protection activation indication includes a first user plane confidentiality protection activation result indication and a first user plane integrity protection activation result indication, and the first user plane confidentiality protection activation result indication is used to indicate that the user plane confidentiality protection is activated, and the first user plane integrity protection activation result indication is used to indicate that the user plane integrity protection is not activated, it is determined that the third user plane security protection policy is that the user plane confidentiality protection is forcibly activated and the user plane integrity protection is forcibly not activated.
36. The second session management entity according to any one of claims 33 to 35, characterized in that: The processing module is configured to obtain a first user plane security protection activation indication, including: A fifth message is sent to the second unified data management entity serving the second terminal device through the transceiver module, wherein the fifth message includes identification information of the second terminal device and is used to request a second user plane security protection policy; and the second user plane security protection policy and the first user plane security protection activation indication are received from the second unified data management entity through the transceiver module.
37. The second session management entity according to any one of claims 33 to 35, characterized in that: The processing module is configured to obtain a first user plane security protection activation indication, including: A sixth message is sent to the second proxy function entity through the transceiver module, where the sixth message includes identification information of the second terminal device, and the sixth message is used to request the first user plane security protection activation indication, and the second proxy function entity is used to provide an interface from the second session management entity to the management device; and the first user plane security protection activation indication is received from the second proxy function entity through the transceiver module.
38. The second session management entity according to claim 37, characterized in that The transceiver module is further configured to receive indication information from the second terminal device before sending the sixth message to the second proxy function entity, wherein the indication information indicates that the second session requested to be established by the second terminal device is used to respond to the C2 communication initiated by the first terminal device.
39. A communication device, characterized in that: include: A memory and a processor coupled to the memory, the memory being used to store a program, and the processor being used to execute the program stored in the memory; when the communication device is running, the processor runs the program, so that the communication device executes the method described in any one of claims 1-6 or 7-13 or 14-19 above.
40. The communication device according to claim 39, wherein: The communication device is a chip or a chip system.
41. A computer-readable storage medium, characterized in that A computer program is stored thereon, which, when executed by a computer, causes the computer to execute the method according to any one of claims 1 to 6, 7 to 13, or 14 to 19.
42. A computer program product, characterized in that include: The computer program product comprises instructions, which, when the computer program product is run on a computer, causes the computer to perform the method according to any one of claims 1 to 6 or 7 to 13 or 14 to 19.
43. A communication system, characterized in that The communication system includes a management device and a second session management entity serving a second terminal device, the second terminal device being a peer device of C2 communication, the C2 communication being communication between a first terminal device and the second terminal device, and the first terminal device being an initiator device of the C2 communication; The management device is configured to obtain a first user plane security protection activation indication, where the first user plane security protection activation indication is used to indicate whether user plane security protection for a first session is activated; the first session is a session used by the first terminal device to carry the C2 communication; The management device is further configured to trigger the second terminal device to initiate establishment of a second session, where the second session is a session used by the second terminal device to carry the C2 communication; The second session management entity is used to receive the first user plane security protection activation indication obtained by the management device, and send the first user plane security protection activation indication to the second access network device serving the second terminal device; wherein, the first user plane security protection activation indication is used to determine whether the user plane security protection of the second session is activated.
44. A communication system, characterized in that The communication system includes a management device and a second session management entity serving a second terminal device, the second terminal device being a peer device of C2 communication, the C2 communication being communication between a first terminal device and the second terminal device, and the first terminal device being an initiator device of the C2 communication; The management device is configured to obtain a first user plane security protection activation indication, where the first user plane security protection activation indication is used to indicate whether user plane security protection for a first session is activated; the first session is a session used by the first terminal device to carry the C2 communication; The management device is further configured to trigger the second terminal device to initiate establishment of a second session, where the second session is a session used by the second terminal device to carry the C2 communication; The second session management entity is configured to receive the first user plane security protection activation indication obtained by the management device, determine a third user plane security protection policy according to the first user plane security protection activation indication, and then send the third user plane security protection policy to the second access network device serving the second terminal device; wherein the third user plane security protection policy only includes forcibly enabling security protection or forcibly not enabling security protection; The third user plane security protection policy is used to determine the second user plane security protection activation indication, and the second user plane security protection activation indication is used to determine whether the user plane security protection of the second session is activated, and the second session is the session used by the second terminal device to carry the C2 communication.
45. The communication system according to claim 43 or 44, characterized in that The communication system further includes a first session management entity serving the first terminal device; The first session management entity is configured to send the first user plane security protection activation indication to the management device; The management device is configured to obtain a first user plane security protection activation indication, including: receiving the first user plane security protection activation indication from the first session management entity.
46. The communication system according to claim 43 or 44, characterized in that The communication system further includes the first terminal device; The first terminal device is configured to send the first user plane security protection activation instruction to the management device; The management device is used to obtain the first user plane security protection activation indication, including: receiving the first user plane security protection activation indication from the first terminal device.
Citation Information
Patent Citations
Method, apparatus and system for security protection
CN109600804A
Communication method and device
CN109788480A