Information processing method and apparatus, communication device, and storage medium
By verifying the security of relay and remote UEs through interaction between relay UE and network equipment, the security issues in 5G proximity service relay communication are resolved, and communication security is improved.
Patent Information
- Application Number
- CN202280003145.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-12
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2042-08-12
AI Technical Summary
In 5G proximity services, UEs may not use the correct security method for discovery and communication protection according to the network configuration in the user equipment to network relay communication, resulting in trust risks, security degradation and resource waste.
The relay UE receives a direct communication request message from the remote UE and sends a relay key request message to the network device to verify whether a pre-configured security method is used. The network device performs the verification and responds with a relay key response message to ensure the communication security between the relay UE and the remote UE.
By verifying whether the relay UE and the remote UE use the pre-configured security method, security vulnerabilities caused by not using the correct security method are reduced, and the security of relay communication is improved.
Smart Images

Figure CN117882414B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of wireless communication, and more particularly to an information processing method and device, a communication device, and a storage medium. BACKGROUND
[0002] For the security of user equipment to network relay communication of the 5th Generation (5G) proximity services (ProSe), there are two optional ways, which are the schemes of user equipment control plane (CP) and user plane (UP) based on PC5 discovery and communication between a remote user equipment (UE) and a user equipment to network (U2N) relay for a specific relay service indicated by a relay service code (RSC).
[0003] In the related art, it is disclosed that the UE can select whether to perform CP-based and / or UP-based security protection. For example, if a specific relay service indicated by a relay service code (RSC) in the U2N relay discovery parameter is configured with a CP security indication, the relay service is protected based on the CP. If a specific relay service indicated by a relay service code (RSC) in the U2N relay discovery parameter is not configured with a CP security indication, the relay service is protected by default based on the UP.
[0004] However, in some scenarios, the network has configured the UE with U2N relay discovery parameters, in which a specific RSC indicates a relay service that is configured or not configured with a CP security indication, and the UE may not use the correct security mode to perform the protection of the mutual discovery and communication between UEs according to the network configuration, which poses a certain risk of trust, security degradation, or waste of network resources for the mutual discovery and communication between UEs. SUMMARY
[0005] Embodiments of the present disclosure provide an information processing method and device, a communication device, and a storage medium.
[0006] The first aspect of the embodiments of the present disclosure provides an information processing method, executed by a relay UE, comprising:
[0007] receiving a direct communication request message sent by a remote UE;
[0008] sending a relay key request message to a first network device according to the direct communication request message, wherein the relay key request message comprises: a verification of whether the relay UE and / or the remote UE establish a relay connection in a pre-configured security mode;
[0009] receiving the relay key response message sent by the first network device.
[0010] A second aspect of the embodiments of the present disclosure provides an information processing method, executed by a first network device, and the method comprises:
[0011] receiving a relay key request message sent by a relay UE;
[0012] According to the relay key request message, verifying whether a security mode adopted by the relay UE when communicating with a remote UE is a pre-configured security mode, to obtain a verification result;
[0013] According to the verification result, sending a relay key response message to the relay UE.
[0014] A third aspect of the embodiments of the present disclosure provides an information processing method, executed by a second network device, and the method comprises:
[0015] receiving a verification request message sent by a first network device;
[0016] According to the verification request message, determining whether a security mode adopted by a relay UE when communicating with a remote UE is a pre-configured security mode, to obtain a verification result;
[0017] According to the verification result, sending a verification response message to the first network device.
[0018] A fourth aspect of the embodiments of the present disclosure provides an information processing method, executed by a third network device, and the method comprises:
[0019] receiving a proximity communication authentication request message sent by a first network device;
[0020] According to the proximity communication authentication request message, verifying whether a security mode adopted by a remote UE when communicating with the relay UE is a pre-configured security mode, and obtaining a verification result;
[0021] According to the verification result, sending a proximity communication authentication response message to the first network device.
[0022] A fifth aspect of the embodiments of the present disclosure provides an information processing method, executed by a fourth network device, and the method comprises:
[0023] receiving a verification request message sent by a third network device;
[0024] According to the verification request message, determining whether a security mode adopted by a remote UE when communicating with a relay UE is a pre-configured security mode, to obtain a verification result;
[0025] According to the verification result, a verification response message is sent to the third network device.
[0026] A sixth aspect of the embodiments of the present disclosure provides an information processing device, which comprises:
[0027] The first receiving module is configured to receive a direct communication request message sent by a remote UE.
[0028] The first sending module is configured to send a relay key request message to a first network device according to the direct communication request message, wherein the relay key request message comprises: information used to verify whether the relay UE and / or the remote UE establish a relay connection in a pre-configured security mode.
[0029] The first receiving module is configured to receive a relay key response message sent by the first network device.
[0030] A seventh aspect of the embodiments of the present disclosure provides an information processing device, which comprises:
[0031] The second receiving module is configured to receive a relay key request message sent by a relay UE.
[0032] The first verification module is configured to verify, according to the relay key request message, whether a security mode used by the relay UE when communicating with a remote UE is a pre-configured security mode, to obtain a verification result.
[0033] The second sending module is configured to send a relay key response message to the relay UE according to the verification result.
[0034] An eighth aspect of the embodiments of the present disclosure provides an information processing device, which comprises:
[0035] The third receiving module is configured to receive a verification request message sent by a first network device.
[0036] The second verification module is configured to determine, according to the verification request message, whether a security mode used by a relay UE when communicating with a remote UE is a pre-configured security mode, to obtain a verification result.
[0037] The third sending module is configured to send a verification response message to the first network device according to the verification result.
[0038] A ninth aspect of the embodiments of the present disclosure provides an information processing device, which comprises:
[0039] The fourth receiving module is configured to receive a proximity communication authentication request message sent by a first network device.
[0040] a third verification module, configured to verify, according to the proximity communication authentication request message, whether a security mode adopted by the remote UE when communicating with the relay UE is a preconfigured security mode, and obtain a verification result;
[0041] a fourth sending module, configured to send, according to the verification result, a proximity communication authentication response message to the first network device.
[0042] In an eleventh aspect, the present disclosure provides a communication device, comprising a processor, a transceiver, a memory, and an executable program stored in the memory and capable of being executed by the processor, wherein the processor executes the executable program to perform the information processing method according to the first aspect, the second aspect, the third aspect, the fourth aspect, or the fifth aspect.
[0043] a fifth receiving module, configured to receive a verification request message sent by a third network device;
[0044] a fourth verification module, configured to determine, according to the verification request message, whether a security mode adopted by the remote UE when communicating with the relay UE is a preconfigured security mode, and obtain a verification result;
[0045] a fifth sending module, configured to send, according to the verification result, a verification response message to the third network device.
[0046] In an eleventh aspect, the present disclosure provides a communication device, comprising a processor, a transceiver, a memory, and an executable program stored in the memory and capable of being executed by the processor, wherein the processor executes the executable program to perform the information processing method according to the first aspect, the second aspect, the third aspect, the fourth aspect, or the fifth aspect.
[0047] In a twelfth aspect, the present disclosure provides a computer storage medium, which stores an executable program; the executable program is executed by a processor to implement the information processing method according to the first aspect, the second aspect, the third aspect, the fourth aspect, or the fifth aspect.
[0048] In a thirteenth aspect, the present disclosure provides a communication system, comprising a remote UE, a relay UE, and a first network device.
[0049] The remote UE is configured to send a direct communication request message to the relay UE;
[0050] The relay UE is configured to receive the direct communication request message of the remote UE, and send a relay key request message to the first network device according to the direct communication request message; wherein the relay key request message comprises: a verification of whether the relay UE and / or the remote UE adopts a preconfigured security mode to establish a relay connection; and receiving a relay key response message sent by the first network device.
[0051] The first network device is configured to receive the relay key request message, verify whether a security mode adopted by the relay UE when communicating with the remote UE is a preconfigured security mode according to the relay key request message, and obtain a verification result; and send a relay key response message to the relay UE according to the verification result.
[0052] The technical solution provided by the embodiments of the present disclosure is that, when receiving a direct communication request message sent by a remote UE, a relay UE needs to interact with a network device to verify whether the relay UE and / or the remote UE adopts a security mode preconfigured by a network side for relay communication (or direct communication), so as to reduce security problems caused by the fact that any one of the relay UE and / or the remote UE does not use the preconfigured security mode, thereby improving the communication security between the relay UE and the remote UE.
[0053] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the embodiments of the present disclosure. BRIEF DESCRIPTION OF DRAWINGS
[0054] The accompanying drawings, which are incorporated into and form part of the specification, illustrate an embodiment consistent with the present disclosure and, together with the specification, serve to explain the principles of the embodiments of the present disclosure.
[0055] Figure 1 is a structural schematic diagram of a wireless communication system according to an exemplary embodiment;
[0056] Figure 2A is a flowchart of an information processing method according to an exemplary embodiment;
[0057] Figure 2B is a flowchart of an information processing method according to an exemplary embodiment;
[0058] Figure 2C is a flowchart of an information processing method according to an exemplary embodiment;
[0059] Figure 2D is a flowchart of an information processing method according to an exemplary embodiment;
[0060] Figure 2E is a flowchart of an information processing method according to an exemplary embodiment;
[0061] Figure 3A is a flowchart of an information processing method according to an exemplary embodiment;
[0062] Figure 3Bis a flowchart of an information processing method according to an example embodiment;
[0063] Figure 4 is a flowchart of an information processing method according to an example embodiment;
[0064] Figure 5A is a flowchart of an information processing method according to an example embodiment;
[0065] Figure 5B is a flowchart of an information processing method according to an example embodiment;
[0066] Figure 5C is a flowchart of an information processing method according to an example embodiment;
[0067] Figure 5D is a flowchart of an information processing method according to an example embodiment;
[0068] Figure 6 is a flowchart of an information processing method according to an example embodiment;
[0069] Figure 7 is a flowchart of an information processing method according to an example embodiment;
[0070] Figure 8 is a structural diagram of an information processing apparatus according to an example embodiment;
[0071] Figure 9 is a structural diagram of an information processing apparatus according to an example embodiment;
[0072] Figure 10 is a structural diagram of an information processing apparatus according to an example embodiment;
[0073] Figure 11 is a structural diagram of an information processing apparatus according to an example embodiment;
[0074] Figure 12 is a structural diagram of an information processing apparatus according to an example embodiment;
[0075] Figure 13 is a structural diagram of a UE according to an example embodiment;
[0076] Figure 14 is a structural diagram of a network device according to an example embodiment. DETAILED DESCRIPTION
[0077] The exemplary embodiments will be described in detail herein with reference to the attached drawings. The following description is made with reference to the accompanying drawings in which like reference numerals refer to like elements, unless the context clearly shows otherwise. The following description of exemplary embodiments is not representative of all possible embodiments consistent with the present embodiments. Rather, they are merely examples of apparatuses and methods consistent with some aspects of the present embodiments.
[0078] The terminology used in the present disclosure is solely for the purpose of describing particular embodiments and is not intended to limit the present embodiments. As used in the present disclosure, the singular forms "a," "an," and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms "comprises" and / or "comprising," when used in this specification, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.
[0079] It should be understood that although the terms first, second, third, etc. can be used herein to describe various information, the information should not be limited to these terms. These terms are only used to differentiate one piece of information from another piece of information. For example, a first information can also be called a second information, and similarly, a second information can also be called a first information without departing from the scope of the present embodiments. Depending on the context, the word "if" as used herein can be interpreted as meaning "when" or "upon" or "in response to determining."
[0080] Reference is made to Figure 1 which shows a structure diagram of a wireless communication system provided by the present embodiments. As shown in Figure 1 , the wireless communication system is a communication system based on cellular mobile communication technology, and the wireless communication system can include a plurality of UEs 11 and a plurality of access devices 12.
[0081] The UE 11 can be a device that provides voice and / or data connectivity to a user. The UE 11 can be a machine-to-machine UE, such as a sensor device, a mobile phone (also known as a cellular telephone or handset), and a computer with a machine-to-machine UE, e.g., a fixed, portable, pocket, handheld, computer-embedded, or car-mounted device. For example, the UE 11 can be a Station (STA), a subscriber unit, a subscriber station, a mobile station, a mobile, a remote station, an access point, a remote terminal, an access terminal, a user terminal, a user agent, a user device, or a user equipment (UE). Alternatively, the UE 11 can be a device of an unmanned aerial vehicle. Alternatively, the UE 11 can be a vehicle-mounted device, e.g., a car-mounted device with wireless communication function, or a wireless communication device externally connected to a car-mounted device. Alternatively, the UE 11 can be a roadside device, e.g., a street lamp, a signal lamp, or other roadside device with wireless communication function.
[0082] The access device 12 can be a network-side device in a wireless communication system. The wireless communication system can be a 4th generation mobile communication (4G) system, also known as a Long Term Evolution (LTE) system. Alternatively, the wireless communication system can be a 5G system, also known as a new radio (NR) system or a 5G NR system. Alternatively, the wireless communication system can be a further next generation system of the 5G system. In the 5G system, the access network can be referred to as a New Generation-Radio Access Network (NG-RAN). Alternatively, the wireless communication system can be an MTC system.
[0083] The access device 12 can be an evolved access device (eNB) used in a 4G system. Alternatively, the access device 12 can also be an access device (gNB) using a centralized and distributed architecture in a 5G system. When the access device 12 uses a centralized and distributed architecture, it usually includes a central unit (CU) and at least two distributed units (DUs). The central unit is provided with a protocol stack of a packet data convergence protocol (PDCP) layer, a radio link control (RLC) layer, and a media access control (MAC) layer; the distributed unit is provided with a physical (PHY) layer protocol stack, and the specific implementation of the access device 12 is not limited in the embodiments of the present disclosure.
[0084] The access device 12 and the UE 11 can establish a wireless connection through a wireless air interface. In different embodiments, the wireless air interface is a wireless air interface based on a fourth generation mobile communication network technology (4G) standard; or the wireless air interface is a wireless air interface based on a fifth generation mobile communication network technology (5G) standard, such as a new radio (NR); or the wireless air interface can also be a wireless air interface based on a more next generation mobile communication network technology standard of 5G.
[0085] As shown in FIG. 1, the embodiments of the present disclosure provide an information processing method, which is executed by a relay UE, and the method comprises the following steps: Figure 2A
[0086] S1110: receiving a direct communication request message sent by a remote UE;
[0087] S1120: sending a relay key request message to a first network device according to the direct communication request message; wherein the relay key request message comprises: information used to verify whether the relay UE and / or the remote UE establish a relay connection in a pre-configured security mode;
[0088] S1130: receiving a relay key response message sent by the first network device.
[0089] The relay UE is a relay device between the remote UE and the network device. The relay UE can also be referred to as a user equipment to network (U2N) relay.
[0090] After receiving the sidelink communication request message sent by the remote UE, the relay UE sends a relay key request message to a network device according to the received sidelink communication request message. For example, the relay UE sends the sidelink communication request message to a core network device of a control plane or a user plane of the relay UE. For example, the relay UE sends the sidelink communication request message to an access management function (AMF) of the relay UE, or to a proximity service key management function (PKMF) or a direct discovery name management function (DDNMF) of the relay UE.
[0091] In an embodiment, the relay UE can determine to send the relay key request message to a network device of a control plane or a network device of a user plane according to a security mode to be adopted by the relay UE. For example, the relay UE selects to use a control plane-based security mode, and the relay UE sends the relay key request message to a network device of the control plane. For example, the relay UE selects to use a user plane-based security mode, and the relay UE sends the relay key request message to a network device of the user plane.
[0092] After receiving the relay key request message, the network device verifies whether a preconfigured security mode is used for mutual discovery and / or communication between the relay UE and / or the remote UE based on a PC5 interface.
[0093] The relay UE and the remote UE establish a relay connection in at least two ways:
[0094] One way is a user plane (UP)-based security mode.
[0095] The other way is a control plane (CP)-based security mode.
[0096] The network devices involved in the two ways are different, and / or the security parameters for generating a session key can be different. The session key includes, but is not limited to, a confidentiality protection key and / or an integrity protection key. The confidentiality protection key can be used for message encryption and decryption in relay connection establishment. The integrity protection key can be used for message integrity protection in relay connection establishment.
[0097] For example, the sidelink communication request message can include one or more parameters for determining the security mode actually adopted by the remote UE.
[0098] For example, the one or more parameters can include at least one of the following:
[0099] a security mode indication parameter, which can be dedicated for the remote UE to indicate the security mode adopted by itself;
[0100] a negotiation parameter, which is used for negotiating a session key.
[0101] Different security modes have different negotiation parameters for negotiating a session key, so the actual security mode adopted by the remote UE can be implicitly indicated according to the type of the negotiation parameter, the bit overhead of the direct communication request message can be reduced, and the reuse of the negotiation parameter can be realized.
[0102] The relay key request message can be a message in which the relay UE requests a security parameter from the network device, which can be used to verify whether the relay UE and / or the remote UE adopts a security mode pre-configured by the network device.
[0103] Exemplarily, the relay key request message can be generated according to a direct communication request message sent by the remote UE, and the relay key request message can include information content carried by the direct communication request message and information of the relay UE.
[0104] The information content carried by the direct communication request message includes but is not limited to at least one of the following:
[0105] an identifier of the remote UE;
[0106] a relay service code (RSC) of a relay service requested by the remote UE;
[0107] a negotiation parameter for negotiating a session key;
[0108] a security mode indication parameter.
[0109] The information of the relay UE can include but is not limited to an identifier of the relay UE, etc.
[0110] The identifier of the remote UE and the identifier of the relay UE can each include but is not limited to a subscription concealed identifier (SUCI) or an application layer identifier of the corresponding UE.
[0111] The relay key response message can indicate whether the relay UE and / or the remote UE establishes a relay connection using a pre-configured security mode. The relay connection can be used for the relay UE to transmit uplink transmission of the remote UE to the network device and / or to forward downlink transmission sent by the network device to the remote UE.
[0112] The remote UE can be a UE located at the edge of a network or outside the coverage range of the network. The network here includes but is not limited to a 3Gpp network.
[0113] The pre-configured security mode here may be: a security mode pre-configured by a network device, and / or a security mode pre-configured by a communication protocol.
[0114] By sending the direct communication request message and receiving the relay key response message, the relay UE can verify whether the establishment of the direct connection between itself and the remote UE uses a pre-configured security method, thereby reducing security vulnerabilities caused by not using the pre-configured security method and improving the security of the relay connection establishment between the remote UE and the relay UE.
[0115] It is worth noting that: in the embodiment of the present disclosure, the information interaction between the relay UE and the network device on the network side can forward or transparently transmit the direct communication request message sent by the relay UE to the first network device through one or more intermediate network devices, and then forward or transparently transmit the relay key response message of the first network device to the relay UE through one or more intermediate network devices.
[0116] The one or more relay network devices herein may include at least a base station that relays UEs, etc.
[0117] like Figure 2B As shown, an embodiment of the present disclosure provides an information processing method, which is performed by a relay UE, and the method includes:
[0118] S1210: Receive a direct communication request message sent by a remote UE;
[0119] S1220: Sending a relay key request message to the first network device according to the direct communication request message; wherein the relay key request message includes: a method for verifying whether the relay UE and / or the remote UE establishes a relay connection in a pre-configured security manner;
[0120] S1230: Receive a relay key response message sent by the first network device;
[0121] S1240: In response to the relay key response message indicating successful verification, sending a direct connection security mode command to the remote UE.
[0122] In one embodiment, if the relay key response message indicates successful authentication, it can be assumed that both the relay UE and the remote UE are using a pre-configured security method, and therefore a secure relay connection can be established. Upon receiving the relay key response message, the relay UE can respond to the direct communication request message and send a direct connection security mode command to the remote UE to continue the subsequent steps of establishing the relay connection.
[0123] Exemplarily, if the relay UE is a trusted UE or in some specific scenarios, only if the remote UE uses the pre-configured security mode to establish the relay connection with the relay UE, the relay key response message indicates that the remote UE uses the pre-configured security mode, and then the direct connection security mode command can be sent to the remote UE to continue the establishment of the direct connection between the remote UE and the relay UE.
[0124] In some other embodiments, if the relay key response message indicates the verification failure, the relay UE can not return any message to the remote UE, and thus the remote UE can consider that the current relay connection establishment fails if the remote UE does not receive the direct connection security mode command of the relay UE within a period of time after sending the direct connection communication request message.
[0125] As shown in Figure 2C The embodiments of the present disclosure provide an information processing method, which is performed by a relay UE, and the method comprises the following steps:
[0126] S1310: receiving a direct connection communication request message sent by a remote UE;
[0127] S1320: sending a relay key request message to a first network device according to the direct connection communication request message, wherein the relay key request message comprises: verification of whether the relay UE and / or the remote UE uses a pre-configured security mode to establish a relay connection;
[0128] S1330: receiving a relay key response message sent by the first network device;
[0129] S1340: sending a direct connection communication rejection message to the remote UE in response to the relay key response message indicating the verification failure.
[0130] In some other embodiments, if the relay key response message indicates the verification failure, a direct connection communication rejection message can be sent to the remote UE, and the direct connection communication rejection message can indicate rejection of the direct connection communication request message of the remote UE, i.e., rejection of the direct connection communication between the remote UE and the relay UE. Thus, after receiving the direct connection communication rejection message, the remote UE can know that the current direct connection establishment between the remote UE and the relay UE fails.
[0131] In some embodiments, the direct connection communication rejection message can further comprise: a failure cause. Exemplarily, the failure cause can be indicated by a cause code. Thus, after receiving the direct connection communication rejection message, the remote UE can know the cause of the failure of the current relay connection establishment between the remote UE and the relay UE. The failure cause can comprise: the relay UE does not use the pre-configured security mode, the remote UE does not use the pre-configured security mode, or neither the relay UE nor the remote UE uses the pre-configured security mode.
[0132] If the failure reason is that the remote UE does not use the preconfigured security mode and the remote UE wants to continue to establish a relay connection with the relay UE, the security mode can be changed and the direct communication request message can be initiated again.
[0133] As shown in Figure 2D The embodiments of the present disclosure provide an information processing method, executed by a relay UE, comprising:
[0134] S1410: receiving service authorization and configuration information;
[0135] S1420: receiving a direct communication request message sent by a remote UE;
[0136] S1430: in response to receiving the direct communication request message, determining whether a security mode used by the remote UE is a security mode indicated by the service authorization and configuration information;
[0137] S1440: in response to the security mode used by the remote UE being the security mode indicated by the service authorization and configuration information, sending a relay key request message to a first network device according to the direct communication request message.
[0138] In some embodiments, in order to reduce unnecessary interaction between the relay UE and the network device, the relay UE first locally verifies whether the remote UE uses a preconfigured security mode, and after the relay UE locally verifies that the remote UE uses the preconfigured security mode, the relay UE sends the relay key request message to the network device.
[0139] The service authorization and configuration information can be pre-sent by the network device to the relay UE.
[0140] Exemplarily, when the relay UE registers with the network device, the relay UE can receive the service authorization and configuration information sent by the network device and locally store the service authorization and configuration information.
[0141] Exemplarily, different relay UEs have different relay service codes (RSCs), and the RSC is included in the direct communication request message sent by the remote UE. After receiving the direct communication request message, the relay UE locally queries the service authorization and configuration information corresponding to the RSC according to the RSC carried in the direct communication request message, and determines the security mode preconfigured by the network side device when establishing a relay connection based on the RSC according to the service authorization and configuration information.
[0142] If the relay UE does not locally query the service authorization and configuration information corresponding to the RSC, it can be indicated that the relay UE does not have the permission to provide the relay corresponding to the RSC, and can send a direct communication rejection message to the remote UE, or it can be indicated that the relay UE has not temporarily requested the corresponding service authorization and configuration information from the network device, and at this time, the relay UE can first request the network device for the service authorization and configuration information corresponding to the RSC based on the RSC.
[0143] In some embodiments, when the network device configures the security mode, the network device can configure one security mode for one RSC, that is, one-to-one correspondence between the RSC and the security mode can be configured in advance. The one-to-one correspondence can be provided by the service authorization and configuration information sent by the network device.
[0144] Exemplarily, the service authorization and configuration information can include the RSC and a security indicator, and the security indicator can indicate the pre-configured security mode.
[0145] In some embodiments, if the relay UE does not perform the local verification of whether the remote UE uses the pre-configured security mode, the relay UE can determine to send the relay key request message to the network device of the user plane or the network device of the control plane according to the security mode indication parameter and / or the negotiation parameter carried in the direct connection request message.
[0146] In some embodiments, if the relay UE performs the local verification of whether the remote UE uses the pre-configured security mode or locally stores the service authorization and configuration information, it is determined to send the relay key request message to the network device of the user plane or the network device of the control plane according to the security mode indicated by the service authorization and configuration information.
[0147] Of course, the above is only an example of the specific way in which the relay UE determines to receive the network device of the relay key request message, and the specific implementation is not limited to the above example.
[0148] As shown in FIG. 13, the method provided by the embodiment of the present disclosure includes the following steps. Figure 2E
[0149] S1510: receiving service authorization and configuration information;
[0150] S1520: receiving a direct connection request message sent by a remote UE;
[0151] S1530: in response to receiving the direct connection request message, determining whether the security mode used by the remote UE is the security mode indicated by the service authorization and configuration information;
[0152] S1540: In response to the security mode adopted by the remote UE not being the security mode indicated by the service authorization and configuration information, sending a direct communication rejection message to the remote UE.
[0153] If the relay UE locally verifies that the remote UE does not use the pre-configured security mode, the relay UE can directly send a direct communication rejection message to the remote UE to inform the remote UE that the relay connection establishment fails.
[0154] Alternatively, in some other embodiments, the relay UE can directly ignore the direct communication request message, so that the remote UE will not receive the direct communication response message or the direct communication rejection message sent by the relay UE, and the remote UE will also default that the relay connection establishment fails.
[0155] The embodiments of the present disclosure provide an information processing method, executed by a relay UE, comprising:
[0156] receiving service authorization and configuration information;
[0157] receiving a direct communication request message sent by a remote UE;
[0158] In response to receiving a relay service indicated by an RSC in the direct communication request message and the direct communication request message comprising a root key identifier and a random number of the remote UE, determining that the remote UE uses a control plane (CP) based security mode;
[0159] In response to the service authorization and configuration information indicating a CP based security mode, determining that the security mode adopted by the remote UE is the security mode indicated by the service authorization and configuration information.
[0160] The embodiments of the present disclosure provide an information processing method, executed by a relay UE, comprising:
[0161] receiving a direct communication request message sent by a remote UE;
[0162] receiving service authorization and configuration information;
[0163] In response to receiving a relay service indicated by an RSC in the direct communication request message and the direct communication request message comprising a root key identifier and a random number of the remote UE, determining that the remote UE uses a control plane (CP) based security mode;
[0164] In response to the service authorization and configuration information indicating a user plane (UP) based security mode, determining that the security mode adopted by the remote UE is not the security mode indicated by the service authorization and configuration information.
[0165] When the session key negotiation is performed based on the CP-based security mode, the root key identifier and the random number generated by the remote UE are used. The root key identifier can be carried by the long-term credential issued by the network device and for the RSC.
[0166] The root key identifier and the random number can be used for the session key negotiation when the relay connection is established between the remote UE and the relay UE.
[0167] Therefore, if the service authorization and configuration information indicates the UP-based security mode, it indicates that the local verification remote UE does not use the security mode pre-configured by the network device. If the service authorization and configuration information indicates the CP-based security mode, it indicates that the local verification UE uses the security mode pre-configured by the network device.
[0168] In the embodiments of the present disclosure, the security mode used by the remote UE is implicitly indicated by the root key identifier and the random number, which has the characteristics of simple implementation.
[0169] An information processing method is provided in the embodiments of the present disclosure, which is performed by a relay UE and includes the following steps.
[0170] Receiving service authorization and configuration information;
[0171] Receiving a direct communication request message sent by a remote UE;
[0172] In response to receiving a relay service indicated by an RSC in the direct communication request message and the direct communication request message including a root key identifier and a freshness parameter of a root key sent by the remote UE, it is determined that the remote UE uses the UP-based security mode.
[0173] In response to the service authorization and configuration information indicating the UP-based security mode, it is determined that the security mode used by the remote UE is the security mode indicated by the service authorization and configuration information.
[0174] An information processing method is provided in the embodiments of the present disclosure, which is performed by a relay UE and includes the following steps.
[0175] Receiving service authorization and configuration information;
[0176] Receiving a direct communication request message sent by a remote UE;
[0177] In response to receiving a relay service indicated by an RSC in the direct communication request message and the direct communication request message including a root key identifier and a freshness parameter of a root key sent by the remote UE, it is determined that the remote UE uses the UP-based security mode.
[0178] In response to the service authorization and configuration information indicating the CP-based security mode, it is determined that the security mode used by the remote UE is not the security mode indicated by the service authorization and configuration information.
[0179] If the direct communication request message carries a root key identifier and a freshness parameter of a root key. The freshness parameter can be used to verify whether the remote UE is attacked. In the embodiment of the present disclosure, the freshness parameter of the root key can also be used to indicate that the remote UE currently selects to use the UP-based security mode.
[0180] The root key identifier can be used for session key negotiation when the freshness parameter of the root key parameter indicates that the remote UE is not attacked.
[0181] If the network device preconfigured security mode indicated by the service authorization and configuration information is the CP-based security mode, it can be considered that the remote UE does not use the network device preconfigured security mode. If the network device preconfigured security mode indicated by the service authorization and configuration information is the UP-based security mode, it can be considered that the remote UE uses the network device preconfigured security mode.
[0182] As shown in Figure 3A The embodiment of the present disclosure provides an information processing method, executed by a first network device, the method comprising:
[0183] S2110: receiving a relay key request message sent by a relay UE;
[0184] S2120: verifying, according to the relay key request message, whether the security mode used by the relay UE when communicating with the remote UE is a preconfigured security mode, to obtain a verification result;
[0185] S2130: sending a relay key response message to the relay UE according to the verification result.
[0186] Here, the first network device can be any core network device serving the relay UE. Exemplarily, the first network device can be an AMF or a PKMF serving the relay UE.
[0187] If the first network device receiving the relay key request message is a network device of CP, it can be determined that the relay UE currently uses a CP-based security mode by default. If the first network device is through the AMF of the relay UE, that is, the AMF is the serving AMF of the relay UE. The AMF of the relay UE can interact with the policy control function (PCF) of the relay UE to determine whether the security mode pre-configured by the PCF is a CP-based security mode. If the security mode pre-configured by the PCF is not the CP-based security mode, it indicates that the relay UE does not use the pre-configured security mode, otherwise it can be considered that the relay UE uses the pre-configured security mode of the network device.
[0188] If the first network device receiving the relay key request message is a network device of UP, it can be determined that the relay UE currently uses a UP-based security mode by default. If the first network device is through the PKMF of the relay UE. The AMF of the relay UE can interact with the policy control function (PCF) of the relay UE to determine whether the security mode pre-configured by the PCF is a UP-based security mode. If the security mode pre-configured by the PCF is not the UP-based security mode, it indicates that the relay UE does not use the pre-configured security mode, otherwise it indicates that the relay UE uses the pre-configured security mode of the network device.
[0189] Exemplarily, the relay key request message can be generated according to a direct communication request message sent by a remote UE, and the relay key request message can include information content carried by the direct communication request message and information of the relay UE.
[0190] The information content carried by the direct communication request message includes but is not limited to at least one of the following:
[0191] An identifier of the remote UE;
[0192] A relay service code (RSC) of a relay service requested by the remote UE;
[0193] Negotiation parameters for negotiating a session key;
[0194] A security mode indication parameter.
[0195] The information of the relay UE can include but is not limited to an identifier of the relay UE, etc.
[0196] In this way, the first network device can verify whether the remote UE uses the pre-configured security mode of the network device through interaction between the core network device serving the remote UE.
[0197] In one embodiment, the first network device can return a relay key response message to the relay UE in time in a case where at least one UE verification does not use the pre-configured security mode according to a verification result of whether the relay UE and / or the remote UE adopts the pre-configured security mode, and the relay key response message indicates a verification failure.
[0198] In another embodiment, the first network device can return a response relay key response message to the relay UE only after obtaining two verification results of the relay UE and the remote UE, so that the relay key response message can specifically indicate a verification success or a verification failure and a failure cause of which UE causes the verification failure, etc.
[0199] As Figure 3B shown, the embodiments of the present disclosure provide an information processing method, which is executed by a first network device, and the method comprises:
[0200] S2210: receiving a relay key request message sent by a relay UE;
[0201] S2220: sending a verification request message to a second network device according to the relay key request message;
[0202] S2230: receiving a verification response message returned by the second network device;
[0203] S2240: determining the verification result according to the verification response message;
[0204] S2250: sending a relay key response message to the relay UE according to the verification result.
[0205] Exemplarily, the second network device can be a PCF of the relay UE.
[0206] The first network device can send a verification request message to the second network device according to the relay key request message, and the verification request message can be verified by the PCF whether the relay UE has the pre-configured security mode.
[0207] Exemplarily, the verification response message can at least include an identifier and an RSC of the relay UE.
[0208] The second network device, such as the PCF, receives the verification request message, determines the security mode configured by the PCF for the relay UE according to the identifier of the relay UE and the RSC, and determines that the relay UE uses the preconfigured security mode if the first network device is a CP network device and the PCF preconfigures the CP-based security mode for the relay UE, or determines that the relay UE does not use the preconfigured security mode if the first network device is a UP network device and the PCF preconfigures the CP-based security mode for the relay UE.
[0209] In some embodiments, the step of verifying whether the security mode used by the relay UE in the communication between the relay UE and the remote UE is the preconfigured security mode according to the relay key request message, and obtaining a verification result, includes:
[0210] According to the relay key request message,
[0211] When the security mode used by the relay UE is not the preconfigured security mode of the second network device, the relay key response message indicating a verification failure is sent to the relay UE.
[0212] When the security mode used by the relay UE is the preconfigured security mode of the second network device, a proximity communication authentication request message is sent to a third network device.
[0213] In this embodiment, when it is determined that the relay UE does not use the preconfigured security mode of the second network device, a relay key response message indicating an identifier verification failure is directly returned to the relay UE, which is equivalent to directly notifying the relay UE that the establishment of the relay connection with the remote UE can be terminated.
[0214] When the security mode used by the relay UE is the preconfigured security mode of the second network device, the remote UE is further verified in this embodiment of the present disclosure whether to use the preconfigured security mode. In this embodiment, the second network device sends the proximity communication authentication request message to the third network device, which can be used to request the third network device to perform network-side verification on whether the remote UE uses the preconfigured security mode.
[0215] Exemplarily, the proximity communication authentication request message can be sent according to the received relay key request message. Exemplarily, the proximity communication authentication request message can comprise at least the information of the remote UE, the RSC, and a parameter indicating the security mode currently actually adopted by the remote UE. Here, the parameter indicating the security mode currently actually adopted by the remote UE can comprise but not limited to the security mode indication parameter provided in any of the foregoing embodiments, and / or the negotiation parameter used for generating the session key between the remote UE and the relay UE.
[0216] The information of the remote UE can comprise at least the identification of the remote UE, which can be used by the network device to uniquely identify the remote UE. Exemplarily, the information of the remote UE can comprise but not limited to the application layer identification of the remote UE.
[0217] In some embodiments, the method further comprises:
[0218] receiving the proximity communication authentication response message sent by the third network device;
[0219] sending a relay key response message to the relay UE according to the proximity communication authentication request message.
[0220] Exemplarily, when the proximity communication authentication request message indicates that the remote UE uses the security mode pre-configured by the network device, the relay key response message indicating the verification success is sent to the relay UE.
[0221] When the proximity communication authentication request message indicates that the remote UE does not use the security mode pre-configured by the network device, the relay key response message indicating the verification failure is sent to the relay UE.
[0222] Exemplarily, the relay key response message indicating the verification failure can comprise a failure cause, so that after the relay UE receives the relay key response message comprising the failure cause, it can be considered that at least one of the relay UE and the remote UE does not use the pre-configured security mode, and thus the relay UE can no longer continue to establish the relay connection with the remote UE.
[0223] Exemplarily, the relay key response message indicating the verification success can comprise a success indication, so that after the relay UE receives the relay key response message comprising the failure cause, it can be considered that both the relay UE and the remote UE use the pre-configured security mode, and thus the relay UE can continue to establish the relay connection with the remote UE.
[0224] Exemplarily, the relay key response message indicating that the verification succeeds can include parameters such as a root key and a random number provided by the network device to derive a session key, so that after the relay UE receives the relay key response message containing the root key and the random number, it can be considered that the relay UE and the remote UE both use the preconfigured security mode, and thus the relay connection with the remote UE can be continued.
[0225] As shown in Figure 4 The embodiments of the present disclosure provide an information processing method, wherein the method is performed by a second network device, and the method comprises:
[0226] S3110: receiving a verification request message sent by a first network device;
[0227] S3120: determining, according to the verification request message, whether a security mode used by a relay UE when communicating with a remote UE is a preconfigured security mode, to obtain a verification result;
[0228] S3130: sending a verification response message to the first network device according to the verification result.
[0229] The verification request message can be a message requesting verification of whether the relay UE uses the preconfigured security mode.
[0230] The second network device can be a PCF of the relay UE, which can verify whether the relay UE uses the preconfigured security mode to establish a relay connection with the remote UE, and obtain the verification result.
[0231] The verification response message is sent to the first network device according to the verification result.
[0232] If the verification result indicates that the verification fails, the verification response message indicates that the verification fails; if the verification result indicates that the verification succeeds, the verification response message indicates that the verification succeeds.
[0233] Exemplarily, the determining, according to the relay service indicated by the RSC in the verification request message, whether the security mode used by the relay UE when communicating with the remote UE is a security mode preconfigured for the relay service, to obtain the verification result, comprises:
[0234] When the verification request message is received and the security mode preconfigured for the relay service indicated by the RSC in the verification request message is a user plane (UP) based security mode, it is determined that the security mode used by the relay UE when communicating with the remote UE is not the preconfigured security mode;
[0235] Or,
[0236] When the verification request message is received and the second network device is pre-configured with a security mode indicated by the RSC in the verification request message for relay service as a control plane (CP) based security mode, it is determined that the security mode adopted by the relay UE when communicating with the remote UE is the pre-configured security mode.
[0237] In some embodiments, the second network device stores policy information configured for the relay UE, and according to the policy information, it can be verified whether the relay UE adopts the security mode indicated by the policy information (or configuration information).
[0238] If the verification request message is from the control plane network device of the relay UE, it is considered that the security mode currently actually adopted by the relay UE can be a CP based security mode; if the verification request message is from the UP network device of the relay UE, it is considered that the security mode actually adopted by the relay UE is a UP based security mode.
[0239] The second network device verifies whether the relay UE adopts the pre-configured security mode in multiple ways, and the specific implementation is not limited to the above examples.
[0240] As shown in Figure 5A The embodiments of the present disclosure provide an information processing method, executed by a third network device, and the method comprises:
[0241] S4110: receiving a proximity communication authentication request message sent by a first network device;
[0242] S4120: verifying, according to the proximity communication authentication request message, whether a security mode adopted by a remote UE when communicating with a relay UE is a pre-configured security mode, and obtaining a verification result;
[0243] S4130: sending, to the first network device, a proximity communication authentication response message according to the verification result.
[0244] In the embodiments of the present disclosure, the third network device can be an authentication server function (AUSF) of the remote UE.
[0245] After receiving the proximity communication authentication request message sent by the first network device, the third network device verifies whether the security mode adopted by the remote UE when communicating with the relay UE is the pre-configured security mode, and further obtains the verification result.
[0246] The proximity communication authentication request message can include: an identifier of the remote UE and an RSC corresponding to the relay communication between the remote UE and the relay UE. In some embodiments, the proximity communication authentication request message can further include: information of a security mode that can be used by the remote UE when communicating with the relay UE.
[0247] The AUSF can further verify whether the remote UE uses the pre-configured security mode according to the identifier of the remote UE in the proximity communication authentication request message and the RSC.
[0248] For example, the third network device such as the AUSF can request the policy information or the configuration information from the PCF of the remote UE according to the historical time, and locally verify whether the remote UE uses the pre-configured security mode.
[0249] For another example, the third network device such as the AUSF can interact with the PCF of the remote UE, and verify whether the remote UE uses the pre-configured security mode according to the interaction information.
[0250] In summary, the third network device such as the AUSF verifies whether the remote UE uses the pre-configured security mode in multiple ways, and the specific implementation is not limited thereto.
[0251] Meanwhile, the AUSF can further verify whether the remote UE supports the relay service of the RSC according to the RSC and the identifier of the remote UE, and when the remote UE supports the relay service corresponding to the RSC, the AUSF can further provide a key parameter required for generating a session key when the remote UE and the relay UE communicate in the future. The key parameter includes but is not limited to: a root key identifier and / or a random number generated by the AUSF.
[0252] The verification result includes: verifying that the remote UE uses the pre-configured security mode, and verifying that the remote UE does not use the pre-configured security mode.
[0253] The third network device can return a proximity communication authentication response message indicating that the verification is successful or the verification fails to the first network device according to the authentication result.
[0254] In some embodiments, the verification of whether the security mode used by the remote UE when communicating with the relay UE is the pre-configured security mode according to the proximity communication authentication request message and obtaining the verification result include:
[0255] sending a verification request message to a fourth network device according to the proximity communication authentication request message;
[0256] receiving a verification response message returned by the fourth network device;
[0257] According to the verification response message, the verification result is determined.
[0258] The fourth network device can be a PCF of the remote UE. The PCF of the remote UE stores policy information and / or configuration information of the remote UE, and / or information that can determine the security mode pre-configured for the remote UE.
[0259] In this way, the third network device such as the AUSF can obtain the verification result through communication with the fourth network device.
[0260] That is, as shown in Figure 5B The embodiment of the disclosure provides an information processing method, executed by a third network device, and the method comprises the following steps:
[0261] S4210: receiving a proximity communication authentication request message sent by a first network device;
[0262] S4220: sending a verification request message to a fourth network device according to the proximity communication authentication request message;
[0263] S4230: receiving a verification response message returned by the fourth network device;
[0264] S4240: determining the verification result according to the verification response message.
[0265] S4250: sending a proximity communication authentication response message to the first network device according to the verification result.
[0266] In the embodiment of the disclosure, the verification request message is sent according to the proximity communication authentication request message, and the verification request message can include the content covered by the proximity communication authentication request message, for example, the identifier of the remote UE and the RSC, and / or information used to determine the security mode adopted by the remote UE for relay communication with the relay UE.
[0267] For example, the proximity communication authentication request message can be sent to the fourth network device by being contained in the verification request message, or the content contained in the proximity communication authentication request message is extracted, and then the verification request message is generated according to the extracted content.
[0268] As shown in Figure 5C The embodiment of the disclosure provides an information processing method, executed by a third network device, and the method comprises the following steps:
[0269] S4310: receiving a proximity communication authentication request message sent by a first network device;
[0270] S4320: Verify, according to the proximity communication authentication request message, whether a security mode adopted by the remote UE when the remote UE communicates with the relay UE is a preconfigured security mode, and obtain a verification result.
[0271] S4330: When the security mode adopted by the remote UE is not the preconfigured security mode of the fourth network device, send, to the first network device, the proximity communication authentication response message indicating a verification failure.
[0272] As shown in Figure 5D The embodiments of the present disclosure provide an information processing method, executed by a third network device, comprising:
[0273] S4410: Receive a proximity communication authentication request message sent by a first network device;
[0274] S4420: Verify, according to the proximity communication authentication request message, whether a security mode adopted by the remote UE when the remote UE communicates with the relay UE is a preconfigured security mode, and obtain a verification result.
[0275] S4430: When the security mode adopted by the remote UE is the preconfigured security mode of the fourth network device, send, to the first network device, the proximity communication authentication response message indicating a verification success.
[0276] In some embodiments, the proximity communication authentication response message indicating a verification failure comprises a failure cause; and / or, the proximity communication authentication response message indicating a verification success comprises an intermediate key used for relay transmission between the relay UE and the remote UE.
[0277] Specifically, the failure cause can be carried by a failure cause code, and different failure cause codes can represent different failure causes. For example, the remote UE does not support the network preconfigured security mode, the remote UE does not use the network device preconfigured security mode, or the remote UE does not support the relay service indicated by the RSC.
[0278] In some embodiments, the proximity communication authentication response message can comprise a proximity communication authentication rejection message and a proximity communication authentication confirmation message; the message formats of the proximity communication authentication rejection message and the proximity communication authentication confirmation message are different, and the proximity communication authentication rejection message can indicate a verification failure. The proximity communication authentication confirmation message can indicate a verification success.
[0279] As shown in Figure 6 The embodiments of the present disclosure provide an information processing method, executed by a fourth network device, comprising:
[0280] S5110: receiving a verification request message sent by the third network device;
[0281] S5120: determining, according to the verification request message, whether a security mode adopted by the remote UE when communicating with the relay UE is a preconfigured security mode, to obtain a verification result;
[0282] S5130: sending, to the third network device, a verification response message according to the verification result.
[0283] The fourth network device can be a core network device such as a PCF of the remote UE.
[0284] The fourth network device can receive a verification request message provided by the third network device, and the verification request message can include an identifier of the remote UE and / or an RSC, etc.
[0285] The fourth network device verifies whether the remote UE adopts a preconfigured security mode of the fourth network device, and the process is the same as that of the second network device verifying whether the relay UE adopts a preconfigured security mode of the second network device.
[0286] In summary, the fourth network device can complete verification of whether the remote UE has a preconfigured security mode according to policy information and / or configuration information stored by itself, and return the verification result to the third network device. After receiving the verification result through the verification response message, the third network device returns a corresponding verification result to the first network device of the relay UE, and finally returns the verification result to the relay UE, for the relay UE to determine whether to continue to establish a relay connection with the remote UE and perform subsequent relay communication.
[0287] Exemplarily, the determining, according to the relay service indicated by the RSC in the verification request message, whether the security mode adopted by the remote UE when communicating with the relay UE is a preconfigured security mode to obtain a verification result includes:
[0288] When the fourth network device preconfigures a user plane UP-based security mode for the relay service indicated by the RSC in the verification request message, it is determined that the security mode adopted by the remote UE when communicating with the relay UE is not the preconfigured security mode;
[0289] Or,
[0290] When the fourth network device preconfigures a user plane CP-based security mode for the relay service indicated by the RSC in the verification request message, it is determined that the security mode adopted by the remote UE when communicating with the relay UE is the preconfigured security mode.
[0291] A PC5 link is established between a Remote UE and a Relay UE in a 5G ProSe service, which can be one of the aforementioned relay links. Exemplarily, the relay link can be established based on a PC5 interface or a SR interface.
[0292] In the embodiments of the present disclosure, the U2N relay and the AMF of the U2N relay perform an authentication process on the Remote UE, and synchronously verify whether the Remote UE and / or the Relay UE use the security mode pre-configured by the network to establish and verify the relay link. As shown in the following table, the information processing method provided by the embodiments of the present disclosure can include: Figure 7
[0293] 0 (including 0a and 0b). The Remote UE and the U2N relay (i.e., the Relay UE) are registered with the network respectively. The U2N relay must be authenticated and authorized by the network to provide the U2N relay service. The Remote UE needs to be authenticated and authorized to be determined to have the right to accept the U2N relay service. In the service authorization and configuration information issuance process, the UE needs to obtain the service authorization and configuration information of the U2N relay service. The service authorization and configuration information can at least include the RSC, and exemplarily, the service authorization and configuration information can also include: a control plane security indicator, which can be used to indicate the use of CP-based security mode. It is worth noting that the control plane security indicator is an optional parameter of the service authorization and configuration information, and if the service authorization and configuration information does not have the control plane security indicator, the UP-based security mode is used by default. The Relay UE can subsequently not verify whether the Remote UE uses the security mode pre-configured by the network side, but directly request the network side whether the Remote UE uses the security mode pre-configured by the network side through a relay key request message.
[0294] 1. The U2N relay starts the discovery process between the UEs of the relay service indicated by the aforementioned RSC using mode A, or the Remote UE starts the discovery process between the UEs of the relay service indicated by the aforementioned RSC using mode B.
[0295] 2. After the discovery between the Remote UE and the Relay UE is completed, the Remote UE sends a direct communication request (DCR) message to the U2N relay, the direct communication request message includes the RSC, and the direct communication request is used to request the establishment of a secure PC5 unicast link between the Relay UE and the Remote UE.
[0296] 3. The U2N relay decides whether to use the CP-based or UP-based security procedure for the relay communication according to the received RSC and the parameters provided by its own PCF.
[0297] If the received DCR contains the 5G proximity service relay user key identification (5GPRUK ID) and Nonce_1, it means that the remote UE initiates the DCR using CP-based security procedure. If the U2N relay is configured with the security indicator of the CP associated with the received request RSC, the U2N relay determines that the actual behavior of the remote UE matches the network configuration. Then the U2N relay proceeds to step #4a.
[0298] If the received DCR contains the PRUK ID and / or K NRP freshness parameter, it means that the remote UE initiates the DCR using UP-based security procedure. If the U2N relay is configured with the security indicator of the CP associated with the received request RSC, the U2N relay will determine that there is no match between the network configuration and the actual security way adopted by the remote UE. Then the U2N relay will perform step #4b.
[0299] 4a. If step 3 verification is successful, the U2N relay sends a Relay Key Request to the AMF of the U2N relay, the request content includes: SUCI or 5G PRUK ID, RSC and Nonce_1 received in the DCR message.
[0300] 4b. If step 3 verification is not successful, the U2N relay sends a Direct Communication Reject message to the remote UE.
[0301] 5. The AMF of the U2N relay verifies whether the U2N relay is authorized to provide relay service.
[0302] 6. The AMF of the U2N relay verifies whether the U2N relay correctly uses the security way configured by the network for the requested RSC, according to the RSC in the received Relay Key Request message, together with the PCF of the U2N relay.
[0303] 7a. If the PCF verification is successful, the AMF of the U2N relay selects the AUSF of the remote UE according to the SUCI or 5G PRUK ID, and forwards the parameters received in the Relay Key Request to the AUSF of the remote UE, and then proceeds to step #8a.
[0304] 7b. If the PCF verification is not successful, the AMF of the U2N relay sends a Relay Key Response message to the relay terminal and gives the failure reason. Then the U2N relay will perform step #8b.
[0305] 8. The AUSF of the Remote UE verifies with the PCF of the Remote UE whether the security mode being employed is the one assigned by the network based on the RSC in the Nausf_UEAuthentication_ProseAuthenticateRequest message received from the AMF of the U2N Relay.
[0306] If the verification is successful, the AUSF of the Remote UE proceeds to step 9. If the verification is not successful, the AUSF of the Remote UE proceeds to step #1 lb.
[0307] 8b. The U2N Relay sends a Direct Communication Reject message to the Remote UE after receiving the Relay Key Response message from the AMF.
[0308] 9. Perform 5G ProSe authentication between the Remote UE and the network.
[0309] 10. The AUSF of the Remote UE generates a random number 2 (Nonce_2), derives K NR_ProSe key using the 5G PRU K, random number 1 (Nonce_1) and random number 2 (Nonce_2).
[0310] 11a. The AUSF of the Remote UE sends a Nausf_UEAuthentication_ProseAuthenticate Response message containing K NR_ProSe , Nonce_2, etc. to the AMF of the U2N Relay, the U2N Relay proceeds to step #12a. The Nausf_UEAuthentication_ProseAuthenticate Response message is one of the aforementioned Proximity Communication Authentication Response messages, which can include a success flag, which can be an optional parameter. That is, in some embodiments, if the Proximity Communication Authentication Response message includes K NR_ProSe and Nonce_2 provided by the AUSF, it means that the verification is successful. The success flag can be denoted as: EAP Success.
[0311] 11b. The AUSF of the Remote UE sends a Nausf_UEAuthentication_ProseAuthenticate Response message containing a failure cause to the AMF of the U2N Relay, the U2N Relay proceeds to step #12b.
[0312] 12a. The AMF of the U2N Relay sends a Relay Key Response message containing K NR_ProSe , Nonce_2, etc. to the U2N Relay, the U2N Relay proceeds to step #13a.
[0313] 12b. The U2N relay's AMF sends a Relay Key Response message containing a failure cause to the U2N relay, which continues to perform step 13b.
[0314] 13a. The U2N relay derives a relay key K relay-sess for PC5 from KNR_ProSe and generates a confidentiality protection key K relay-enc and / or an integrity key K relay-int based on the intermediate key, and then sends a Direct Security Mode Command message including Nonce_2 to the remote UE and will continue to perform step #14.
[0315] 13b. The U2N relay sends a Direct Communication Reject message to the remote UE. After receiving the Direct Communication Reject message, the remote UE stops performing the following steps.
[0316] 14. The remote UE generates a key K NR_ProSe for remote access through the U2N relay. The remote UE also derives PC5 session keys K NR_ProSe , a confidentiality key, and an integrity key in the same way as defined in step #13a. relay-sess .
[0317] 15. The remote UE sends a Direct Security Mode Complete message to the U2N relay, which is protected by Krelay-int or / and Krelay-enc derived from Krelay-sess.
[0318] 16. Direct Communication Accept message transmission, for example, after the Direct Security Mode Complete message is verified successfully, the U2N relay responds to the remote UE with a Direct Communication Accept message, completes the PC5 connection establishment process, and stores the security context associated with the PC5 link to the remote UE.
[0319] It is worth noting that: Figure 7 PAnF in the above formula is the English abbreviation of ProSe Anchor Function.
[0320] As shown in Figure 8 , the embodiment of the disclosure provides an information processing device, which comprises:
[0321] A first receiving module 110 is configured to receive a direct communication request message sent by a remote UE;
[0322] A first sending module 120 is configured to send a relay key request message to a first network device according to the direct communication request message; wherein the relay key request message comprises: a message used to verify whether the relay UE and / or the remote UE establishes a relay connection in a pre-configured security mode.
[0323] The first receiving module 110 is configured to receive a relay key response message sent by the first network device.
[0324] In some embodiments, the information processing device can be included in a relay UE.
[0325] In some embodiments, the first receiving module 110 and the first sending module 120 can be program modules; after the program modules are executed by a processor, the above operations can be implemented.
[0326] In some other embodiments, the first receiving module 110 and the first sending module 120 can be soft and hard combined modules; the soft and hard combined modules include but are not limited to programmable arrays; the programmable arrays include but are not limited to field programmable arrays and / or complex programmable arrays.
[0327] In still some other embodiments, the first receiving module 110 and the first sending module 120 can be pure hardware modules; the pure hardware modules include but are not limited to application specific integrated circuits.
[0328] In some embodiments, the first sending module 120 is further configured to, in response to the relay key response message indicating that the verification is successful, send a direct connection security mode command to the remote UE.
[0329] In some embodiments, the first sending module 120 is configured to, in response to the relay key response message indicating that the verification fails, send a direct connection communication rejection message to the remote UE.
[0330] In some embodiments, the first receiving module 110 is further configured to receive service authorization and configuration information;
[0331] The apparatus further includes:
[0332] A determining module is configured to, in response to receiving the direct connection communication request message, determine whether a security mode adopted by the remote UE is a security mode indicated by the service authorization and configuration information.
[0333] The first sending module 120 is configured to, in response to the security mode adopted by the remote UE being the security mode indicated by the service authorization and configuration information, send a relay key request message to the first network device according to the direct connection communication request message.
[0334] In some embodiments, the first sending module 120 is further configured to, in response to the security mode adopted by the remote UE not being the security mode indicated by the service authorization and configuration information, send a direct connection communication rejection message to the remote UE.
[0335] In some embodiments, the determining module is configured to determine, in response to receiving the relay service indicated by the RSC in the direct communication request message and the direct communication request message including the root key identification and the freshness parameter of the root key sent by the remote UE, that the remote UE uses a control plane (CP) based security mode; determine, in response to the service authorization and configuration information indicating a CP based security mode, that the security mode used by the remote UE is the security mode indicated by the service authorization and configuration information; or determine, in response to the service authorization and configuration information indicating a user plane (UP) based security mode, that the security mode used by the remote UE is not the security mode indicated by the service authorization and configuration information.
[0336] In some embodiments, the determining module is configured to determine, in response to receiving the relay service indicated by the RSC in the direct communication request message and the direct communication request message including the root key identification and the freshness parameter of the root key sent by the remote UE, that the remote UE uses a user plane (UP) based security mode; determine, in response to the service authorization and configuration information indicating a UP based security mode, that the security mode used by the remote UE is the security mode indicated by the service authorization and configuration information; or determine, in response to the service authorization and configuration information indicating a control plane (CP) based security mode, that the security mode used by the remote UE is not the security mode indicated by the service authorization and configuration information.
[0337] As shown in Figure 9 The information processing apparatus provided by the embodiments of the present disclosure includes:
[0338] The second receiving module 210 is configured to receive a relay key request message sent by a relay UE.
[0339] The first verifying module 220 is configured to verify, according to the relay key request message, whether a security mode used by the relay UE when communicating with a remote UE is a preconfigured security mode, to obtain a verification result.
[0340] The second sending module 230 is configured to send a relay key response message to the relay UE according to the verification result.
[0341] The information processing apparatus can be the first network device described above.
[0342] In some embodiments, the second receiving module 210, the first verifying module 220 and the second sending module 230 can be program modules; after the program modules are executed by a processor, the above operations can be implemented.
[0343] In other embodiments, the second receiving module 210, the first verification module 220 and the second sending module 230 may be pure hardware modules; the pure hardware modules include but are not limited to: application-specific integrated circuits.
[0344] In some other embodiments, the second receiving module 210 , the first verification module 220 and the second sending module 230 may also be a software-hard combination module; the software-hard combination module includes but is not limited to a programmable array.
[0345] In some embodiments, the second sending module 230 is further configured to send a verification request message to the second network device according to the relay key request message;
[0346] The second receiving module 210 is further configured to receive a verification response message returned by the second network device;
[0347] The first verification module 220 is configured to determine the verification result according to the verification response message.
[0348] In some embodiments, the first verification module 220 is configured to, based on the relay key request message, send the relay key response message indicating verification failure to the relay UE when the relay key request message determines that the security method adopted by the relay UE is not the security method pre-configured by the second network device; and send a proximity communication authentication request message to the third network device when it is determined that the security method adopted by the relay UE is the security method pre-configured by the second network device based on the relay key request message.
[0349] like Figure 10 As shown, an embodiment of the present disclosure provides an information processing device, wherein the device includes:
[0350] The third receiving module 310 is configured to receive a verification request message sent by the first network device;
[0351] The second verification module 320 is configured to determine, based on the verification request message, whether the security mode adopted by the relay UE during communication between the relay UE and the remote UE is a pre-configured security mode, and obtain a verification result;
[0352] The third sending module 330 is configured to send a verification response message to the first network device according to the verification result.
[0353] The information processing apparatus may be a second network device, and the second network device may include a PCF.
[0354] In some embodiments, the third receiving module 310, the second verifying module 320 and the third sending module 330 can be pure software modules; the pure software modules include but are not limited to program modules; the program modules can perform the above operations after being executed by a processor.
[0355] In still some embodiments, the third receiving module 310, the second verifying module 320 and the third sending module 330 can also be soft and hard combined modules; the soft and hard combined modules include but are not limited to various programmable arrays; the programmable arrays include but are not limited to field programmable arrays and / or complex programmable arrays.
[0356] In still some embodiments, the third receiving module 310, the second verifying module 320 and the third sending module 330 can also include pure hardware modules; the pure hardware modules include but are not limited to application specific integrated circuits.
[0357] In some embodiments, the second verifying module 320 is configured to, when receiving the verification request message and the second network device is pre-configured for the relay service indicated by the RSC in the verification request message as a security mode based on a user plane UP, determine that a security mode adopted by the relay UE in communication between the relay UE and the remote UE is not the pre-configured security mode.
[0358] Or,
[0359] When receiving the verification request message and the second network device is pre-configured for the relay service indicated by the RSC in the verification request message as a security mode based on a user plane CP, it is determined that the security mode adopted by the relay UE in communication between the relay UE and the remote UE is the pre-configured security mode.
[0360] As Figure 11 shown, the embodiments of the present disclosure provide an information processing apparatus, the apparatus comprising:
[0361] A fourth receiving module 410 is configured to receive a proximity communication authentication request message sent by a first network device;
[0362] A third verifying module 420 is configured to verify, according to the proximity communication authentication request message, whether a security mode adopted by a remote UE in communication between the remote UE and the relay UE is a pre-configured security mode, and obtain a verification result;
[0363] A fourth sending module 430 is configured to send, according to the verification result, a proximity communication authentication response message to the first network device.
[0364] The information processing apparatus can be a second network device, i.e., a PCF of a relay UE.
[0365] In some embodiments, the fourth receiving module 410, the third verification module 420 and the fourth sending module 430 may be pure software modules; the pure software modules include but are not limited to program modules; the program modules can perform the above operations after being executed by the processor.
[0366] In some other embodiments, the fourth receiving module 410, the third verification module 420 and the fourth sending module 430 may also be a combination of soft and hard modules; the soft and hard modules include but are not limited to various programmable arrays; the programmable arrays include but are not limited to: field programmable arrays and / or complex programmable arrays.
[0367] In some other embodiments, the fourth receiving module 410, the third verification module 420 and the fourth sending module 430 further include pure hardware modules; the pure hardware modules include but are not limited to application-specific integrated circuits.
[0368] In some embodiments, the third verification module 420 is configured to send a verification request message to a fourth network device according to the proximity communication authentication request message; receive a verification response message returned by the fourth network device; and determine the verification result according to the verification response message.
[0369] In some embodiments, the third verification module 420 is configured to send the proximity communication authentication response message indicating verification failure to the first network device when the security method adopted by the remote UE is not the security method pre-configured by the fourth network device; and to send the proximity communication authentication response message indicating verification success to the first network device when the security method adopted by the remote UE is the security method pre-configured by the fourth network device.
[0370] In some embodiments, the proximity communication authentication response message indicating verification failure includes: a failure reason;
[0371] and / or,
[0372] The proximity communication authentication response message indicating successful verification includes: an intermediate key relayed between the relay UE and the remote UE.
[0373] like Figure 12 As shown, an embodiment of the present disclosure provides an information processing device, the device comprising:
[0374] The fifth receiving module 510 is configured to receive a verification request message sent by a third network device;
[0375] The fourth verification module 520 is configured to determine, according to the verification request message, whether a security mode adopted by the remote UE when communicating with the relay UE is a preconfigured security mode, to obtain a verification result.
[0376] The fifth sending module 530 is configured to send a verification response message to the third network device according to the verification result.
[0377] The information processing apparatus can be a PCF of the relay UE.
[0378] In some embodiments, the fifth receiving module 510, the fourth verification module 520, and the fifth sending module 530 can be pure software modules; the pure software modules include but are not limited to program modules; the program modules can perform the above operations after being executed by a processor.
[0379] In still other embodiments, the fifth receiving module 510, the fourth verification module 520, and the fifth sending module 530 can also be soft and hard combined modules; the soft and hard combined modules include but are not limited to various programmable arrays; the programmable arrays include but are not limited to field programmable arrays and / or complex programmable arrays.
[0380] In still other embodiments, the fifth receiving module 510, the fourth verification module 520, and the fifth sending module 530 can also include pure hardware modules; the pure hardware modules include but are not limited to application specific integrated circuits.
[0381] In some embodiments, the fourth verification module 520 is configured to determine that the security mode adopted by the remote UE when communicating with the relay UE is not the preconfigured security mode when the verification request message is received and the fourth network device preconfigures a user plane UP-based security mode for relay service indicated by the RSC in the verification request message; or determine that the security mode adopted by the remote UE when communicating with the relay UE is the preconfigured security mode when the verification request message is received and the fourth network device preconfigures a user plane CP-based security mode for relay service indicated by the RSC in the verification request message.
[0382] Embodiments of the present disclosure provide a communication system, wherein the communication system includes a remote UE, a relay UE, and a first network device.
[0383] The remote UE is configured to send a direct communication request message to the relay UE.
[0384] The relay UE is configured to receive the direct connection request message of the remote UE, and send a relay key request message to the first network device according to the direct connection request message; wherein the relay key request message comprises: a verification of whether the relay UE and / or the remote UE establish a relay connection in a pre-configured security mode; receiving a relay key response message sent by the first network device;
[0385] The first network device is configured to receive the relay key request message, verify whether the security mode used by the relay UE in communication between the relay UE and the remote UE is a pre-configured security mode according to the relay key request message, and obtain a verification result; and send a relay key response message to the relay UE according to the verification result.
[0386] The relay UE can be a U2N relay, and relays the communication between the remote UE and the network device.
[0387] The communication request message, the relay key request message, and the relay key response message and the like described herein can refer to any one of the preceding embodiments.
[0388] The first network device can be an AMF or the like core network device of the relay UE.
[0389] In some embodiments, the communication system further comprises a second network device;
[0390] The first network device is configured to send a verification request message to the second network device according to the relay key request message, receive a verification response message returned by the second network device, and determine the verification result according to the verification response message.
[0391] The second network device is configured to receive the verification request message sent by the first network device, determine whether the security mode used by the relay UE in communication between the relay UE and the remote UE is a pre-configured security mode according to the verification request message, obtain a verification result, and send a verification response message to the first network device according to the verification result.
[0392] The second network device can be a PCF or the like core network device of the relay UE.
[0393] The relay key request message, the verification request message, and the verification response message and the like described herein can refer to any one of the preceding embodiments.
[0394] In some embodiments, the communication system further comprises a third network device;
[0395] The first network device is configured to send a proximity communication authentication request message to a third network device, and receive a proximity communication authentication response message returned by the third network device.
[0396] The third network device is configured to receive the proximity communication authentication request message sent by the first network device, verify whether a security mode adopted by a remote UE when communicating with the relay UE is a preconfigured security mode according to the proximity communication authentication request message, and obtain a verification result, and send a proximity communication authentication response message to the first network device according to the verification result.
[0397] Exemplarily, the third network device includes, but is not limited to, an AUSF of the remote UE.
[0398] The proximity communication authentication request message, the proximity communication authentication response message, and the like described herein can refer to the foregoing any one embodiment.
[0399] In some embodiments, the communication system further includes a fourth network device.
[0400] The third network device is configured to send a verification request message to the fourth network device according to the proximity communication authentication request message, receive a verification response message returned by the fourth network device, and determine the verification result according to the verification response message.
[0401] The fourth network device is configured to receive the verification request message sent by the third network device, determine whether a security mode adopted by a remote UE when communicating with a relay UE is a preconfigured security mode according to the verification request message, obtain a verification result, and send a verification response message to the third network device according to the verification result.
[0402] The fourth network device includes, but is not limited to, a PCF or the like core network device of the remote UE.
[0403] The proximity communication authentication request message, the verification request message, and the verification response message described herein can refer to the foregoing any one embodiment.
[0404] The embodiment of the present disclosure provides a communication device, including:
[0405] A memory for storing processor-executable instructions;
[0406] A processor connected to the memory respectively;
[0407] The processor is configured to execute the information processing method provided in the foregoing any technical solution.
[0408] The processor can include various types of storage media that are non-transitory computer storage media that continue to store information even after a power failure.
[0409] Here, the communication device includes a relay UE or a network device, which can be any one of the first network device to the fourth network device.
[0410] The processor can be connected with the memory through a bus or the like, for reading an executable program stored on the memory, for example, at least one of the methods shown in FIGS. Figures 2A to 2E , Figures 3A to 3B , Figure 4 , Figures 5A to 5D , Figures 6 to 7
[0411] Figure 13 is a block diagram of a UE 800 according to an exemplary embodiment. The UE 800 can be, for example, a mobile phone, a computer, a digital broadcast user device, a messaging device, a game console, a tablet device, a medical device, a fitness device, a personal digital assistant, and the like.
[0412] Referring to Figure 13 , the UE 800 can include one or more of the following components: a processing component 802, a memory component 804, a power supply component 806, a multimedia component 808, an audio component 810, an input / output (I / O) interface 812, a sensor component 814, and a communication component 816.
[0413] The processing component 802 usually controls the overall operations of the UE 800, such as operations associated with displaying, making phone calls, data communications, camera operations, and recording operations. The processing component 802 can include one or more processors 820 to execute instructions to generate all or part of the steps of the above-described methods. In addition, the processing component 802 can include one or more modules to facilitate the interaction between the processing component 802 and other components. For example, the processing component 802 can include a multimedia module to facilitate the interaction between the multimedia component 808 and the processing component 802.
[0414] The memory 804 is configured to store various types of data to support the operation of the UE 800. Examples of such data include instructions for any application or method operating on the UE 800, contact data, phonebook data, messages, pictures, videos, and so on. The memory 804 can be implemented by any type of volatile or nonvolatile storage devices or a combination thereof such as static random access memory (SRAM), electrically erasable programmable read only memory (EEPROM), erasable programmable read only memory (EPROM), programmable read only memory (PROM), read only memory (ROM), magnetic memory, flash memory, magnetic disc or optical disc.
[0415] The power component 806 supplies electrical power for the various components of the UE 800. The power component 806 can include a power supply management system, one or more power supplies, and other components associated with generating, managing, and distributing electrical power for the UE 800.
[0416] The multimedia component 808 includes a screen providing an output interface between the UE 800 and a user. In some embodiments, the screen can include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen can be implemented as a touch screen to receive input signals from a user. The touch panel includes one or more touch sensors to sense touch, swiping, and gestures on the touch panel. The touch sensors can not only sense a boundary of a touching or swiping action, but also detect duration and pressure related to the touching or swiping action. In some embodiments, the multimedia component 808 includes a front camera and / or a rear camera. The front and / or rear camera can receive external multimedia data when the UE 800 is in an operating mode, such as a shooting mode or a video mode. Each of the front and rear camera can be a fixed optical lens system or have a focal length and optical zoom capability.
[0417] The audio component 810 is configured to output and / or input audio signals. For example, the audio component 810 includes a microphone (MIC) configured to receive external audio signals when the UE 800 is in an operating mode, such as a call mode, a recording mode, and a voice recognition mode. The received audio signals can be further stored in the memory 804 or transmitted via the communication component 816. In some embodiments, the audio component 810 also includes a speaker for outputting audio signals.
[0418] The I / O interface 812 provides an interface between the processing component 802 and peripheral interface modules, which can be a keyboard, a click wheel, a button, and so on. The buttons can include, but are not limited to, a home button, a volume button, a start button, and a lock button.
[0419] The sensor component 814 includes one or more sensors to provide the UE 800 with state assessment of various aspects. For example, the sensor component 814 can detect the open / closed position of the UE 800, relative positioning of components, such as a display and keypad of the UE 800, changes in position of the UE 800 or a component of the UE 800, the presence or absence of user contact with the UE 800, the orientation or acceleration / deceleration of the UE 800, and temperature changes of the UE 800. The sensor component 814 can include a proximity sensor configured to detect the presence of nearby objects without any physical touch. The sensor component 814 can also include a light sensor, such as a CMOS or CCD image sensor, for use in imaging applications. In some embodiments, the sensor component 814 can also include an accelerometer, a gyroscope, a magnetometer, a pressure sensor or a temperature sensor.
[0420] The communication component 816 is configured to facilitate wired or wireless communication between the UE 800 and another device. The UE 800 can access a wireless network based on a communication standard, such as WiFi, 2G, or 3G, or a combination thereof. In an example embodiment, the communication component 816 receives a broadcast signal or broadcast related information from an external broadcast management system via a broadcast channel. In an example embodiment, the communication component 816 further includes a Near Field Communication (NFC) module to facilitate short-range communication. For example, the NFC module can be implemented based on Radio Frequency Identification (RFID) techniques, infrared data association (IrDA) techniques, ultra-wideband (UWB) techniques, Bluetooth (BT) techniques, and other techniques.
[0421] In an example embodiment, the UE 800 can be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, micro-controllers, microprocessors, or other electronic elements for performing the above-described methods.
[0422] In an example embodiment, a non-transitory computer-readable storage medium including instructions, such as the memory 804 including instructions, is also provided, which can be executed by the processor 820 of the UE 800 to generate the above-described methods. For example, the non-transitory computer-readable storage medium can be a ROM, a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disc, and an optical data storage device, etc.
[0423] As Figure 14As shown, an embodiment of the present disclosure shows a structure of a network device. For example, the network device 900 can be provided as a network-side device. The network device can be any one of the first network device to the fourth network device as described above.
[0424] Referring to Figure 14 The network device 900 includes a processing component 922, which is further composed of one or more processors, and a memory resource represented by a memory 932 for storing instructions, such as an application program, executable by the processing component 922. The application program stored in the memory 932 can include one or more than one module each corresponding to a set of instructions. In addition, the processing component 922 is configured to execute the instructions to perform any method described above, such as the method described above in the application of the access device, for example, as shown in any one of the methods described above. Figures 2A to 2E 、 Figures 3A to 3B 、 Figure 4 、 Figures 5A to 5D 、 Figures 6 to 7 any one of the methods described above.
[0425] The network device 900 can also include a power supply component 926 configured to perform power management of the network device 900, a wired or wireless network interface 950 configured to connect the network device 900 to a network, and an input / output (I / O) interface 958. The network device 900 can operate based on an operating system stored in the memory 932, such as Windows Server™, Mac OS X™, Unix™, Linux™, FreeBSD™ or the like.
[0426] Other embodiments of the application will be apparent to those skilled in the art from consideration of the specification and practice of the application disclosed herein. It is intended that the present disclosure cover any and all variations of the present application which come within the scope of the claims and their equivalents. It is intended that the specification and examples be considered exemplary only, with the true scope and spirit of the application being indicated by the following claims.
[0427] It is to be understood that the application is not limited to the precise details of construction and the arrangement of components described above and illustrated in the drawings, and that various modifications and changes can be made without departing from the scope thereof. The scope of the application is limited only by the claims that follow.
Claims
1. An information processing method, performed by a relay UE, comprising: Receive business authorization and configuration information; Receiving a direct communication request message sent by a remote UE; determining, according to the direct communication request message, whether the security mode adopted by the remote UE is the security mode indicated by the service authorization and configuration information; The method further comprises at least one of the following: When the security mode adopted by the remote UE is the security mode indicated by the service authorization and configuration information, sending a relay key request message to the first network device, and receiving a relay key response message sent by the first network device; In a case where the security mode adopted by the remote UE is not the security mode indicated by the service authorization and configuration information, a direct communication rejection message is sent to the remote UE.
2. The method according to claim 1, wherein The method further comprises at least one of the following: If the relay key response message indicates that the verification is successful, sending a direct connection security mode command to the remote UE; In a case where the relay key response message indicates that the verification fails, a direct communication rejection message is sent to the remote UE.
3. The method according to claim 1 or 2, wherein: The determining, according to the direct communication request message, whether the security mode adopted by the remote UE is the security mode indicated by the service authorization and configuration information includes at least one of the following: Upon receiving the relay service indicated by the relay service code RSC in the direct communication request message and the direct communication request message including the root key identifier and the random number sent by the remote UE, determining that the remote UE uses a security method based on the control plane CP; When the service authorization and configuration information indicates a CP-based security mode, determining that the security mode adopted by the remote UE is the security mode indicated by the service authorization and configuration information; When the service authorization and configuration information indicates a security mode based on the user plane UP, determining that the security mode adopted by the remote UE is not the security mode indicated by the service authorization and configuration information; Upon receiving the relay service indicated by the relay service code RSC in the direct communication request message and the direct communication request message including the root key identifier and the fresh parameter of the root key sent by the remote UE, determining that the remote UE uses a security mode based on the user plane UP; When the service authorization and configuration information indicates a UP-based security mode, determining that the security mode adopted by the remote UE is the security mode indicated by the service authorization and configuration information; In a case where the service authorization and configuration information indicates a CP-based security mode, it is determined that the security mode adopted by the remote UE is not the security mode indicated by the service authorization and configuration information.
4. An information processing method, performed by a first network device, the method comprising: Receive a relay key request message sent by the relay UE; The relay key request message is sent by the relay UE when it receives the direct communication request message sent by the remote UE and determines that the security method adopted by the remote UE is the security method indicated by the service authorization and configuration information; Verifying, according to the relay key request message, whether a security mode adopted by the relay UE during communication between the relay UE and the remote UE is a pre-configured security mode, and obtaining a verification result; Send a relay key response message to the relay UE according to the verification result.
5. The method according to claim 4, wherein The verifying, according to the relay key request message, whether a security mode adopted by the relay UE during communication between the relay UE and the remote UE is a pre-configured security mode, and obtaining a verification result, includes: Sending a verification request message to the second network device according to the relay key request message; and receiving a verification response message returned by the second network device; The verification result is determined according to the verification response message.
6. The method according to claim 5, wherein: The verifying, according to the relay key request message, whether a security mode adopted by the relay UE during communication between the relay UE and the remote UE is a pre-configured security mode, and obtaining a verification result, including at least one of the following: When it is determined according to the relay key request message that the security mode adopted by the relay UE is not the security mode pre-configured by the second network device, sending the relay key response message indicating a verification failure to the relay UE; If it is determined according to the relay key request message that the security mode adopted by the relay UE is the security mode pre-configured by the second network device, a proximity communication authentication request message is sent to the third network device.
7. An information processing method, wherein: Executed by the second network device, the method includes: Receiving a verification request message sent by a first network device; the verification request message is sent by the first network device based on a relay key request message sent by a relay UE, and the relay key request message is sent by the relay UE after receiving a direct communication request message sent by a remote UE and determining that the security mode used by the remote UE is the security mode indicated by the service authorization and configuration information; determining, according to the verification request message, whether a security mode adopted by the relay UE during communication between the relay UE and the remote UE is a pre-configured security mode, and obtaining a verification result; According to the verification result, a verification response message is sent to the first network device.
8. The method according to claim 7, wherein: The determining, according to the verification request message, whether a security mode adopted by the relay UE during communication between the relay UE and the remote UE is a pre-configured security mode, and obtaining a verification result, includes at least one of the following: Upon receiving the verification request message and the second network device pre-configuring a user plane UP-based security mode for the relay service indicated by the RSC in the verification request message, determining that the security mode adopted by the relay UE during communication between the relay UE and the remote UE is not the pre-configured security mode; When the verification request message is received and the second network device pre-configures the relay service indicated by the RSC in the verification request message as a control plane CP-based security method, it is determined that the security method adopted by the relay UE during communication between the relay UE and the remote UE is the pre-configured security method.
9. An information processing method, performed by a third network device, the method comprising: receiving a proximity communication authentication request message sent by the first network device; The proximity communication authentication request message is sent by the first network device when the first network device determines, based on the relay key request message sent by the relay UE, that the security mode adopted by the relay UE is the security mode pre-configured by the second network device; the relay key request message is sent by the relay UE when it receives the direct communication request message sent by the remote UE and determines that the security mode adopted by the remote UE is the security mode indicated by the service authorization and configuration information; Verifying, according to the proximity communication authentication request message, whether a security mode adopted by the remote UE when communicating with the relay UE is a pre-configured security mode, and obtaining a verification result; According to the verification result, a proximity communication authentication response message is sent to the first network device.
10. The method according to claim 9, wherein: The verifying, according to the proximity communication authentication request message, whether a security mode adopted by the remote UE when communicating with the relay UE is a pre-configured security mode, and obtaining a verification result, includes: Sending a verification request message to a fourth network device according to the proximity communication authentication request message; receiving a verification response message returned by the fourth network device; The verification result is determined according to the verification response message.
11. The method according to claim 10, wherein: The verifying, according to the proximity communication authentication request message, whether a security mode adopted by the remote UE when communicating with the relay UE is a pre-configured security mode, and obtaining a verification result, includes at least one of the following: When the security mode adopted by the remote UE is not the security mode pre-configured by the fourth network device, sending the proximity communication authentication response message indicating verification failure to the first network device; In a case where the security mode adopted by the remote UE is the security mode pre-configured by the fourth network device, the proximity communication authentication response message indicating successful authentication is sent to the first network device.
12. The method according to claim 11, wherein The proximity communication authentication response message indicating verification failure includes: a failure reason; and / or, The proximity communication authentication response message indicating successful verification includes: an intermediate key relayed between the relay UE and the remote UE.
13. An information processing method, performed by a fourth network device, the method comprising: receiving a verification request message sent by a third network device; The verification request message is sent by the third network device based on the proximity communication authentication request message sent by the first network device, and the proximity communication authentication request message is sent by the first network device when it is determined, based on the relay key request message sent by the relay UE, that the security mode adopted by the relay UE is the security mode pre-configured by the second network device; the relay key request message is sent by the relay UE when it receives the direct communication request message sent by the remote UE and determines that the security mode adopted by the remote UE is the security mode indicated by the service authorization and configuration information; Determining, according to the verification request message, whether a security mode adopted by the remote UE during communication between the relay UE and the remote UE is a pre-configured security mode, and obtaining a verification result; According to the verification result, a verification response message is sent to the third network device.
14. The method according to claim 13, wherein The determining, according to the verification request message, whether a security mode adopted by the remote UE during communication between the relay UE and the remote UE is a pre-configured security mode, and obtaining a verification result, includes one of the following: Upon receiving the verification request message and the fourth network device pre-configuring a security mode based on the user plane UP for the relay service indicated by the RSC in the verification request message, determining that the security mode adopted by the remote UE during communication between the relay UE and the remote UE is not the pre-configured security mode; When the verification request message is received and the fourth network device pre-configures a security method based on the control plane CP for the relay service indicated by the RSC in the verification request message, it is determined that the security method adopted by the remote UE during communication between the relay UE and the remote UE is the pre-configured security method.
15. An information processing device, wherein: The device comprises: The first receiving module is configured to receive service authorization and configuration information; receive a direct communication request message sent by a remote UE; a determination module configured to determine, based on the direct communication request message, whether the security mode adopted by the remote UE is the security mode indicated by the service authorization and configuration information; The first sending module is configured to perform at least one of the following: When the security mode adopted by the remote UE is the security mode indicated by the service authorization and configuration information, sending a relay key request message to the first network device; If the security mode adopted by the remote UE is not the security mode indicated by the service authorization and configuration information, sending a direct communication rejection message to the remote UE; The first receiving module is configured to receive a relay key response message sent by the first network device.
16. The device according to claim 15, wherein The first sending module is further configured to perform at least one of the following: If the relay key response message indicates that the verification is successful, sending a direct connection security mode command to the remote UE; In a case where the relay key response message indicates that the verification fails, a direct communication rejection message is sent to the remote UE.
17. The device according to claim 15 or 16, wherein The determining module is configured to perform at least one of the following: Upon receiving the relay service indicated by the relay service code RSC in the direct communication request message and the direct communication request message including the root key identifier and the random number sent by the remote UE, determining that the remote UE uses a security method based on the control plane CP; When the service authorization and configuration information indicates a CP-based security mode, determining that the security mode adopted by the remote UE is the security mode indicated by the service authorization and configuration information; When the service authorization and configuration information indicates a security mode based on the user plane UP, determining that the security mode adopted by the remote UE is not the security mode indicated by the service authorization and configuration information; Upon receiving the relay service indicated by the relay service code RSC in the direct communication request message and the direct communication request message including the root key identifier and the fresh parameter of the root key sent by the remote UE, determining that the remote UE uses a security mode based on the user plane UP; When the service authorization and configuration information indicates a UP-based security mode, determining that the security mode adopted by the remote UE is the security mode indicated by the service authorization and configuration information; In a case where the service authorization and configuration information indicates a CP-based security mode, it is determined that the security mode adopted by the remote UE is not the security mode indicated by the service authorization and configuration information.
18. An information processing device, wherein: The device comprises: a second receiving module configured to receive a relay key request message sent by the relay UE; the relay key request message is sent by the relay UE when it receives a direct communication request message sent by the remote UE and determines that the security method used by the remote UE is the security method indicated by the service authorization and configuration information; A first verification module is configured to verify, according to the relay key request message, whether a security mode adopted by the relay UE during communication between the relay UE and the remote UE is a pre-configured security mode, and obtain a verification result; The second sending module is configured to send a relay key response message to the relay UE according to the verification result.
19. The device according to claim 18, wherein The second sending module is further configured to send a verification request message to the second network device according to the relay key request message; The second receiving module is further configured to receive a verification response message returned by the second network device; The first verification module is configured to determine the verification result according to the verification response message.
20. The device according to claim 19, wherein The first verification module is configured to perform at least one of the following: If the relay key request message determines that the security mode adopted by the relay UE is not the security mode pre-configured by the second network device, sending the relay key response message indicating verification failure to the relay UE; If it is determined according to the relay key request message that the security mode adopted by the relay UE is the security mode pre-configured by the second network device, a proximity communication authentication request message is sent to the third network device.
21. An information processing device, wherein: The device comprises: a third receiving module, configured to receive a verification request message sent by the first network device; the verification request message is sent by the first network device according to the relay key request message sent by the relay UE, and the relay key request message is sent by the relay UE after receiving the direct communication request message sent by the remote UE and determining that the security mode adopted by the remote UE is the security mode indicated by the service authorization and configuration information; A second verification module is configured to determine, based on the verification request message, whether a security mode adopted by the relay UE during communication between the relay UE and the remote UE is a pre-configured security mode, and obtain a verification result; The third sending module is configured to send a verification response message to the first network device according to the verification result.
22. The device according to claim 21, wherein The second verification module is configured as at least one of the following: Upon receiving the verification request message and the second network device pre-configuring a user plane UP-based security mode for the relay service indicated by the RSC in the verification request message, determining that the security mode adopted by the relay UE during communication between the relay UE and the remote UE is not the pre-configured security mode; When the verification request message is received and the second network device pre-configures the relay service indicated by the RSC in the verification request message as a control plane CP-based security method, it is determined that the security method adopted by the relay UE during communication between the relay UE and the remote UE is the pre-configured security method.
23. An information processing device, wherein: The device comprises: a fourth receiving module, configured to receive a proximity communication authentication request message sent by the first network device; the proximity communication authentication request message is sent by the first network device when it determines, based on the relay key request message sent by the relay UE, that the security method adopted by the relay UE is a security method pre-configured by the second network device; the relay key request message is sent by the relay UE when it receives a direct communication request message sent by the remote UE and determines that the security method adopted by the remote UE is the security method indicated by the service authorization and configuration information; A third verification module is configured to verify, according to the proximity communication authentication request message, whether a security mode adopted by the remote UE when communicating with the relay UE is a pre-configured security mode, and obtain a verification result; The fourth sending module is configured to send a proximity communication authentication response message to the first network device according to the verification result.
24. The device according to claim 23, wherein The third verification module is configured to send a verification request message to a fourth network device according to the proximity communication authentication request message; receive a verification response message returned by the fourth network device; and determine the verification result according to the verification response message.
25. The apparatus according to claim 24, wherein The third verification module is configured to perform at least one of the following: When the security mode adopted by the remote UE is not the security mode pre-configured by the fourth network device, sending the proximity communication authentication response message indicating verification failure to the first network device; In a case where the security mode adopted by the remote UE is the security mode pre-configured by the fourth network device, the proximity communication authentication response message indicating successful verification is sent to the first network device.
26. An information processing device, wherein: The device comprises: a fifth receiving module, configured to receive a verification request message sent by a third network device; the verification request message is sent by the third network device based on the proximity communication authentication request message sent by the first network device, the proximity communication authentication request message is sent by the first network device when determining, based on the relay key request message sent by the relay UE, that the security method adopted by the relay UE is a security method pre-configured by the second network device; the relay key request message is sent by the relay UE when receiving a direct communication request message sent by a remote UE and determining that the security method adopted by the remote UE is the security method indicated by the service authorization and configuration information; a fourth verification module configured to determine, based on the verification request message, whether a security mode adopted by the remote UE during communication between the relay UE and the remote UE is a pre-configured security mode, and obtain a verification result; The fifth sending module is configured to send a verification response message to the third network device according to the verification result.
27. The apparatus according to claim 26, wherein The fourth verification module is configured to perform one of the following: Upon receiving the verification request message and the fourth network device pre-configuring a security mode based on the user plane UP for the relay service indicated by the RSC in the verification request message, determining that the security mode adopted by the remote UE during communication between the relay UE and the remote UE is not the pre-configured security mode; When the verification request message is received and the fourth network device pre-configures a security method based on the control plane CP for the relay service indicated by the RSC in the verification request message, it is determined that the security method adopted by the remote UE during communication between the relay UE and the remote UE is the pre-configured security method.
28. A communication system, wherein: The communication system includes: a remote UE, a relay UE and a first network device; The remote UE is configured to send a direct communication request message to the relay UE; The relay UE is configured to receive service authorization and configuration information; receive a direct communication request message sent by the remote UE, and determine, based on the direct communication request message, whether the security method used by the remote UE is the security method indicated by the service authorization and configuration information; The relay UE is further configured to perform at least one of the following: When the security mode adopted by the remote UE is the security mode indicated by the service authorization and configuration information, sending a relay key request message to the first network device; and receiving a relay key response message sent by the first network device; If the security mode adopted by the remote UE is not the security mode indicated by the service authorization and configuration information, sending a direct communication rejection message to the remote UE; The first network device is configured to receive the relay key request message; verify, based on the relay key request message, whether the security method adopted by the relay UE when communicating with the remote UE is a pre-configured security method, and obtain a verification result; and send a relay key response message to the relay UE based on the verification result.
29. The system of claim 28, wherein: The relay UE is further configured to perform at least one of the following: If the relay key response message indicates that the verification is successful, sending a direct connection security mode command to the remote UE; In a case where the relay key response message indicates that the verification fails, a direct communication rejection message is sent to the remote UE.
30. The system of claim 28 or 29, wherein: The relay UE is further configured to perform at least one of the following: Upon receiving the relay service indicated by the relay service code RSC in the direct communication request message and the direct communication request message including the root key identifier and the random number sent by the remote UE, determining that the remote UE uses a security method based on the control plane CP; When the service authorization and configuration information indicates a CP-based security mode, determining that the security mode adopted by the remote UE is the security mode indicated by the service authorization and configuration information; When the service authorization and configuration information indicates a security mode based on the user plane UP, determining that the security mode adopted by the remote UE is not the security mode indicated by the service authorization and configuration information; Upon receiving the relay service indicated by the relay service code RSC in the direct communication request message and the direct communication request message including the root key identifier and the fresh parameter of the root key sent by the remote UE, determining that the remote UE uses a security mode based on the user plane UP; When the service authorization and configuration information indicates a UP-based security mode, determining that the security mode adopted by the remote UE is the security mode indicated by the service authorization and configuration information; In a case where the service authorization and configuration information indicates a CP-based security mode, it is determined that the security mode adopted by the remote UE is not the security mode indicated by the service authorization and configuration information.
31. The system of claim 30, wherein: The communication system further includes: a second network device; The first network device is configured to send a verification request message to the second network device according to the relay key request message; receive a verification response message returned by the second network device; and determine the verification result according to the verification response message; The second network device is configured to receive a verification request message sent by the first network device; determine, based on the verification request message, whether the security method adopted by the relay UE when communicating with the remote UE is a pre-configured security method, and obtain a verification result; and send a verification response message to the first network device based on the verification result.
32. The system of claim 31, wherein: The communication system further includes: a third network device; The first network device is configured to perform at least one of the following: if it is determined according to the relay key request message that the security mode adopted by the relay UE is not the security mode pre-configured by the second network device, sending the relay key response message indicating a verification failure to the relay UE; if it is determined according to the relay key request message that the security mode adopted by the relay UE is the security mode pre-configured by the second network device, sending a proximity communication authentication request message to a third network device; and receiving a proximity communication authentication response message returned by the third network device; The third network device is configured to receive a proximity communication authentication request message sent by the first network device; verify, based on the proximity communication authentication request message, whether the security method adopted by the remote UE when communicating with the relay UE is a pre-configured security method, and obtain a verification result; and send a proximity communication authentication response message to the first network device based on the verification result.
33. The system of claim 32, wherein: The communication system further includes: a fourth network device; The third network device is configured to send a verification request message to a fourth network device according to the proximity communication authentication request message; receive a verification response message returned by the fourth network device; and determine the verification result according to the verification response message; The fourth network device is configured to receive a verification request message sent by the third network device; determine, based on the verification request message, whether the security method adopted by the remote UE during communication between the relay UE and the remote UE is a pre-configured security method, and obtain a verification result; and send a verification response message to the third network device based on the verification result.
34. The system of claim 33, wherein: The third network device is configured to perform at least one of the following: When the security mode adopted by the remote UE is not the security mode pre-configured by the fourth network device, sending the proximity communication authentication response message indicating verification failure to the first network device; In a case where the security mode adopted by the remote UE is the security mode pre-configured by the fourth network device, the proximity communication authentication response message indicating successful authentication is sent to the first network device.
35. A communication device comprising a processor, a transceiver, a memory, and an executable program stored in the memory and capable of being run by the processor, wherein: When the processor runs the executable program, the method provided in any one of claims 1 to 3 is performed.
36. A communication device comprising a processor, a transceiver, a memory, and an executable program stored in the memory and capable of being run by the processor, wherein: When the processor runs the executable program, the method provided in any one of claims 4 to 6 is executed.
37. A communication device comprising a processor, a transceiver, a memory, and an executable program stored in the memory and capable of being run by the processor, wherein: When the processor runs the executable program, the method provided in claim 7 or 8 is executed.
38. A communication device comprising a processor, a transceiver, a memory, and an executable program stored in the memory and capable of being run by the processor, wherein: When the processor runs the executable program, the method provided in any one of claims 9 to 12 is executed.
39. A communication device comprising a processor, a transceiver, a memory, and an executable program stored in the memory and capable of being run by the processor, wherein: When the processor runs the executable program, the method provided in claim 13 or 14 is executed.
40. A computer storage medium storing an executable program; after the executable program is executed by a processor, it can implement the method provided in any one of claims 1 to 3.
41. A computer storage medium storing an executable program; after the executable program is executed by a processor, it can implement the method provided in any one of claims 4 to 6.
42. A computer storage medium storing an executable program; after the executable program is executed by a processor, it can implement the method provided in claim 7 or 8.
43. A computer storage medium storing an executable program; after the executable program is executed by a processor, it can implement the method provided in any one of claims 9 to 12.
44. A computer storage medium storing an executable program; after the executable program is executed by a processor, it can implement the method provided in any one of claims 13 or 14.
Citation Information
Patent Citations
Method, system and device for determining security protection
CN113676898A
Relay sidelink communications for secure link establishment
US20210345104A1