A data security transmission method for cloud computing

By implementing the data secure transmission method of cloud computing in relay UEs, the problem of secure data transmission of multiple remote UEs under virtualization technology in 5G network is solved, and the secure data transmission service for multiple virtualized remote UEs is realized, which improves data security and flexibility.

CN118200930BActive Publication Date: 2025-06-24JIANGXI DIGITAL NETWORK INFORMATION SECURITY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410340998.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-03-25
Publication Date
2025-06-24
Estimated Expiration
2044-03-25

AI Technical Summary

Technical Problem

After deploying virtualization technology in 5G networks, how to provide secure data transmission services to multiple virtualized remote UEs is a hot topic of research.

Method used

By implementing a cloud-computed data security transmission method in the relay UE, the relay UE determines whether the remote UE is the target remote UE in the group, and establishes or shares a corresponding security mechanism based on the determination result to realize secure data transmission.

Benefits of technology

This method realizes that the relay UE can provide secure data transmission services to multiple virtualized remote UEs at the same time, improving data security and flexibility in cloud computing scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118200930B_ABST
    Figure CN118200930B_ABST
Patent Text Reader

Abstract

The present application provides a data security transmission method for cloud computing. In this method, multiple virtualized remote UEs in a group are divided into target remote UEs and non-target remote UEs. For a target remote UE, such as the first remote UE, the target remote UE can establish a security mechanism for the PC5 connection between the target remote UE and the relay UE, such as the first security mechanism, and this first security mechanism can also be shared by the PC5 connection between the non-target remote UE and the relay UE in the group. In this way, the relay UE can use one security mechanism, that is, the first security mechanism, to perform secure data transmission based on the PC5 connection with each remote UE in the group, that is, to achieve data security transmission in the cloud computing scenario.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of cloud computing technology, and in particular, to a method for secure data transmission in cloud computing. Background Art

[0002] Release 17 of the 3rd generation partnership project (3GPP) defines the PC5 connection to ensure end-to-end communication. For example, a remote UE can establish a PC5 connection with a relay UE. At this time, the communication between the remote UE and the relay UE can be protected by the security mechanism of the PC5 connection, such as integrity, confidentiality, and replay protection, so as to ensure that the remote UE can securely access the network through the relay UE.

[0003] In Release 18 or Release 19 to be discussed in the future, the 5G network may be integrated with cloud computing. For example, virtualization technology is deployed in the 5G network, so that network services are not restricted by physical devices and can be more flexible. For example, multiple virtual remote UEs are implemented in a virtualized manner on the same physical device. In this case, how to provide services for these multiple remote UEs is a hot research issue currently. Summary of the Invention

[0004] An embodiment of this application provides a method for secure data transmission in cloud computing, which is used to enable a relay UE to simultaneously provide secure data transmission services for multiple virtualized remote UEs.

[0005] To achieve the above objective, this application adopts the following technical solutions:

[0006] In a first aspect, a method for secure data transmission in cloud computing is provided. The method includes: when a first remote UE requests to establish a PC5 connection with a relay UE, the relay UE determines whether the first remote UE is a target remote UE in a group; where the group includes multiple remote UEs, and the multiple remote UEs are multiple virtual devices instantiated from one physical device, and the target remote UE can establish the security mechanism of the PC5 connection between the target remote UE and the relay UE, and the security mechanism is shared by the PC5 connections between non-target remote UEs in the group and the relay UE; when the first remote UE is the target remote UE, the relay UE establishes a first security mechanism with the first remote UE; where the first security mechanism is the security mechanism of the first PC5 connection, and the first PC5 connection is the PC5 connection between the relay UE and the first remote UE; the relay UE uses the first security mechanism to perform secure data transmission based on the first PC5 connection.

[0007] In a possible design, the relay UE determines whether the first remote UE is the target remote UE in the group, including: The relay UE receives a first direct communication request from the first remote UE, where the first direct communication request carries the identifier of the group and the identifier of the first remote UE; The relay UE determines whether there is data of the group locally according to the identifier of the group; When there is data of the group locally in the relay UE, the relay UE determines whether the identifier of the first remote UE is the same as the identifier of the target remote UE in the data of the group, where the same identifier of the first remote UE and the target remote UE means that the first remote UE is the target remote UE.

[0008] Optionally, the method further includes: During the process of the relay UE requesting to register to the network, the relay UE obtains the data of the group from the network; Wherein, the data of the group includes the identifier of the group and the identifier of each member in the group.

[0009] For example, during the process of the relay UE requesting to register to the network, the relay UE obtains the data of the group from the network, including: The relay UE sends a registration request to the AMF network element in the network, where the registration request is used for the relay UE to request to register to the network; The relay UE executes the primary authentication process; When the primary authentication is passed, the relay UE receives a registration acceptance from the network, where the registration acceptance carries the data of the group when indicating that the relay UE has successfully registered to the network.

[0010] In a possible design, the method further includes: The relay UE sends a first direct communication acceptance to the second remote UE through a second PC5 connection, where the first direct communication acceptance includes a security mechanism sharing indication, the second PC5 connection is a PC5 connection between the second remote UE and the relay UE established before the first PC5 connection, and the security mechanism sharing indication is used to indicate that the security mechanism of the PC5 connection between the first remote UE and the relay UE needs to be used.

[0011] In a possible design, the method further includes: When a third remote UE requests to establish a PC5 connection with the relay UE, the relay UE determines whether the third remote UE is the target remote UE; When the third remote UE is not the target remote UE, the relay UE sends a security mechanism sharing indication to the third remote UE, where the security mechanism sharing indication is used to indicate that the security mechanism of the PC5 connection between the first remote UE and the relay UE needs to be used.

[0012] Optionally, the relay UE determines whether the first remote UE is the target remote UE in the group, including: the relay UE receives a second direct communication request from a third remote UE, where the second direct communication request carries the identifier of the group and the identifier of the third remote UE; the relay UE determines whether there is data of the group locally according to the identifier of the group; when there is data of the group locally at the relay UE, the relay UE determines whether the identifier of the third remote UE is the same as the identifier of the target remote UE in the group data, where the same identifier of the third remote UE and the target remote UE indicates that the third remote UE is the target remote UE.

[0013] Optionally, the relay UE sends a security mechanism sharing indication to the third remote UE, including: the relay UE sends a second direct communication acceptance to the third remote UE, where the second direct communication acceptance includes the security mechanism sharing indication.

[0014] In a second aspect, a data security transmission method for cloud computing is provided. The method includes: the AMF network element receives a registration request from a first UE, where the registration request is for the first UE to request registration to the network where the AMF network element is located; the AMF network element obtains the subscription data of the first UE from the UDM network element according to the registration request; when the subscription data is used to indicate that the first UE can establish a PC5 connection with a group as a relay UE, if the first UE successfully registers to the network, the AMF network element sends a registration acceptance to the first UE, where the registration acceptance carries the data of the group when indicating that the first UE successfully registers to the network. The group includes multiple remote UEs, and the multiple remote UEs are multiple virtual devices obtained by instantiating an entity device. The target remote UE in the group can establish a security mechanism for the PC5 connection between the target remote UE and the relay UE, and the security mechanism is shared by the PC5 connections between the non-target remote UEs and the relay UE in the group; the group data includes the identifier of the group and the identifier of each member in the group.

[0015] In a possible design, the subscription data is pre-updated by the AF to the UDM network element. The subscription data includes the capability information of the first UE, where the capability information is used to indicate that the first UE has relay capability, and the subscription data further includes the group data and the group type. The group type is used to indicate that the group is a virtual group, and a virtual group means that the multiple remote UEs in the group are multiple virtual devices obtained by instantiating an entity device.

[0016] Optionally, the method further includes: the AMF network element requests the NWDAF network element to perform reliability analysis on the group; the AMF network element receives the reliability result of the group from the NWDAF network element, where the reliability result is used to indicate the reliability of each member of the group; if the member with the highest reliability is the first remote UE, the AMF network element designates the first remote UE as the target remote UE, and determines the other remote UEs in the group except the first remote UE as target remote UEs.

[0017] In a third aspect, a data security transmission device for cloud computing is provided. The device is applied to a relay UE and is configured to: when a first remote UE requests to establish a PC5 connection with the relay UE, the relay UE determines whether the first remote UE is the target remote UE in the group; where the group includes multiple remote UEs, and the multiple remote UEs are multiple virtual devices instantiated from an entity device, and the target remote UE can establish a security mechanism for the PC5 connection between the target remote UE and the relay UE, and the security mechanism is shared by the PC5 connections between the non-target remote UEs in the group and the relay UE; when the first remote UE is the target remote UE, the relay UE establishes a first security mechanism with the first remote UE; where the first security mechanism is the security mechanism for the first PC5 connection, and the first PC5 connection is the PC5 connection between the relay UE and the first remote UE; the relay UE uses the first security mechanism to perform secure data transmission based on the first PC5 connection.

[0018] In a possible design, the device is configured to: the relay UE receives a first direct communication request from the first remote UE, where the first direct communication request carries the identifier of the group and the identifier of the first remote UE; the relay UE determines whether there is data of the group locally based on the identifier of the group; when there is data of the group locally at the relay UE, the relay UE determines whether the identifier of the first remote UE is the same as the identifier of the target remote UE in the data of the group, where the same identifier of the first remote UE and the target remote UE indicates that the first remote UE is the target remote UE.

[0019] Optionally, the device is configured to: during the process of the relay UE requesting to register to the network, obtain the data of the group from the network; where the data of the group includes the identifier of the group and the identifiers of each member in the group.

[0020] For example, the device is configured to: the relay UE sends a registration request to the AMF network element in the network, where the registration request is used for the relay UE to request to register to the network; the relay UE performs the primary authentication process; when the primary authentication is passed, the relay UE receives a registration acceptance from the network, where the registration acceptance carries the data of the group when indicating that the relay UE has successfully registered to the network.

[0021] In a possible design, the device is configured such that: the relay UE sends a first direct communication acceptance to the second remote UE via a second PC5 connection, where the first direct communication acceptance includes a security mechanism sharing indication, the second PC5 connection is a PC5 connection between the second remote UE and the relay UE established before the first PC5 connection, and the security mechanism sharing indication is used to indicate that the security mechanism of the PC5 connection between the first remote UE and the relay UE needs to be used.

[0022] In a possible design, the device is configured such that: in the case where a third remote UE requests to establish a PC5 connection with the relay UE, the relay UE determines whether the third remote UE is a target remote UE; in the case where the third remote UE is not a target remote UE, the relay UE sends a security mechanism sharing indication to the third remote UE, where the security mechanism sharing indication is used to indicate that the security mechanism of the PC5 connection between the first remote UE and the relay UE needs to be used.

[0023] Optionally, the device is configured such that: the relay UE receives a second direct communication request from the third remote UE, where the second direct communication request carries an identifier of a group and an identifier of the third remote UE; the relay UE determines whether there is data of the group locally based on the identifier of the group; in the case where there is data of the group locally at the relay UE, the relay UE determines whether the identifier of the third remote UE is the same as the identifier of the target remote UE in the data of the group, where the same identifier of the third remote UE and the target remote UE indicates that the third remote UE is the target remote UE.

[0024] Optionally, the device is configured such that: the relay UE sends a second direct communication acceptance to the third remote UE, where the second direct communication acceptance includes a security mechanism sharing indication.

[0025] In a third aspect, a data security transmission device for cloud computing is provided. The device is applied to the AMF and is configured as follows: The AMF network element receives a registration request from a first UE. The registration request is used for the first UE to request registration to the network where the AMF network element is located. The AMF network element obtains the subscription data of the first UE from the UDM network element according to the registration request. When the subscription data is used to indicate that the first UE can establish a PC5 connection with a group as a relay UE, if the first UE successfully registers to the network, the AMF network element sends a registration acceptance to the first UE. The registration acceptance carries the data of the group when indicating that the first UE has successfully registered to the network. The group includes multiple remote UEs, and the multiple remote UEs are multiple virtual devices obtained by instantiating an entity device. The target remote UE in the group can establish a security mechanism for the PC5 connection between the target remote UE and the relay UE, and the security mechanism is shared by the PC5 connections between the non-target remote UEs and the relay UE in the group. The data of the group includes the identifier of the group and the identifiers of each member in the group.

[0026] In a possible design, the subscription data is pre-updated by the AF to the UDM network element. The subscription data includes the capability information of the first UE, which is used to indicate that the first UE has relay capability, and the subscription data further includes the data of the group and the type of the group. The type of the group is used to indicate that the group is a virtual group, and a virtual group means that the multiple remote UEs in the group are multiple virtual devices obtained by instantiating an entity device.

[0027] Optionally, the device is configured as follows: The AMF network element requests the NWDAF network element to perform a reliability analysis on the group. The AMF network element receives the reliability result of the group from the NWDAF network element. The reliability result is used to indicate the reliability of each member of the group. If the member with the highest reliability is the first remote UE, the AMF network element designates the first remote UE as the target remote UE and determines the other remote UEs in the group except the first remote UE as non-target remote UEs.

[0028] In a fifth aspect, a communication device is provided, including: a processor and a memory; the memory is used to store a computer program. When the processor executes the computer program, the communication device is caused to execute the method described in the first aspect or the second aspect.

[0029] In a possible design, the communication device may further include a transceiver. The transceiver may be a transceiver circuit or an interface circuit. The transceiver may be used for the communication device to communicate with other communication devices.

[0030] In the embodiments of the present application, the communication device may be the terminal described in the first aspect or the second aspect, or a chip (system) or other components or assemblies that can be disposed in the terminal, or a device including the terminal.

[0031] In a sixth aspect, a computer-readable storage medium is provided, including: a computer program or instruction; when the computer program or instruction runs on a computer, the computer is caused to execute the method described in the first aspect or the second aspect.

[0032] In summary, based on the above methods and apparatuses, it can be known that:

[0033] By dividing multiple virtualized remote UEs in a group into target remote UEs and non-target remote UEs, for a target remote UE, such as a first remote UE, the target remote UE can establish a security mechanism for the PC5 connection between the target remote UE and the relay UE, such as a first security mechanism, and this first security mechanism can also be shared by the PC5 connection between the non-target remote UE and the relay UE in the group. In this way, the relay UE can use one security mechanism, that is, the first security mechanism, to perform secure data transmission based on the PC5 connection with each remote UE in the group, that is, to achieve secure data transmission in the cloud computing scenario. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] Figure 1 It is a schematic diagram of the architecture of a 5G system;

[0035] Figure 2 It is a schematic diagram of the architecture of the communication system provided by an embodiment of the present application;

[0036] Figure 3 It is a schematic flowchart of the method for secure data transmission in cloud computing provided by an embodiment of the present application;

[0037] Figure 4 It is a schematic diagram of the structure of the electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0038] For easy understanding, the technical terms involved in the embodiments of the present application are introduced first below.

[0039] 1. Fifth-generation (5G) mobile communication system (abbreviated as 5G system (5GS)):

[0040] Figure 1 It is a schematic diagram of the non-roaming architecture of 5GS. As Figure 1 shown, 5GS includes: an access network (AN) and a core network (CN), and may also include: a terminal.

[0041] The above terminal can be a terminal with transceiver functions, or a chip or chip system that can be set in the terminal. The terminal can also be referred to as a user equipment (UE), access terminal, subscriber unit, user station, mobile station (MS), mobile platform, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent or user equipment. The terminal in the embodiments of the present application can be a mobile phone, cellular phone, smart phone, tablet computer (Pad), wireless data card, personal digital assistant (PDA), wireless modem, handset, laptop computer, machine type communication (MTC) terminal, computer with wireless transceiver functions, virtual reality (VR) terminal, augmented reality (AR) terminal, wireless terminal in industrial control, wireless terminal in self-driving, wireless terminal in remote medical, wireless terminal in smart grid, wireless terminal in transportation safety, wireless terminal in smart city, wireless terminal in smart home, in-vehicle terminal, roadside unit (RSU) with terminal functions, etc. The terminal in the present application can also be an in-vehicle module, in-vehicle component, in-vehicle chip or in-vehicle unit built in a vehicle as one or more components or units.

[0042] The above AN is used to implement access-related functions, can provide network access functions for authorized users in a specific area, and can determine transmission links of different qualities to transmit user data according to user levels, service requirements, etc. The AN forwards control signals and user data between the terminal and the CN. The AN may include: access network devices, which may also be referred to as radio access network (RAN) devices. The CN is mainly responsible for maintaining the subscription data of the mobile network and providing functions such as session management, mobility management, policy management, and security authentication for the terminal. The CN mainly includes the following network elements: user plane function (UPF) network element, authentication server function (AUSF) network element, access and mobility management function (AMF) network element, session management function (SMF) network element, network slice selection function (NSSF) network element, network exposure function (NEF) network element, network function repository function (NRF) network element, policy control function (PCF) network element, unified data management (UDM) network element, unified data repository (UDR), and application function (AF).

[0043] The UE accesses the 5G network through the RAN device. The UE communicates with the AMF network element through the N1 interface (abbreviated as N1); the RAN network element communicates with the AMF network element through the N2 interface (abbreviated as N2); the RAN network element communicates with the UPF network element through the N3 interface (abbreviated as N3); the SMF communicates with the UPF network element through the N4 interface (abbreviated as N4), and the UPF network element accesses the data network (DN) through the N6 interface (abbreviated as N6). In addition, Figure 1The control plane functions such as the AUSF network element, AMF network element, SMF network element, NSSF network element, NEF network element, NRF network element, PCF network element, UDM network element, UDR network element, or AF shown in the figure interact using service-based interfaces. For example, the service-based interface provided by the AUSF network element externally is Nausf; the service-based interface provided by the AMF network element externally is Namf; the service-based interface provided by the SMF network element externally is Nsmf; the service-based interface provided by the NSSF externally is Nnssf; the service-based interface provided by the NEF network element externally is Nnef; the service-based interface provided by the NRF network element externally is Nnrf; the service-based interface provided by the PCF network element externally is Npcf; the service-based interface provided by the UDM network element externally is Nudm; the service-based interface provided by the UDR network element externally is Nudr; the service-based interface provided by the AF externally is Naf.

[0044] The RAN device can be a device that provides access for the terminal. For example, the RAN device can include: the next-generation mobile communication system, such as the access network device of 6G, such as a 6G base station, or in the next-generation mobile communication system, this network device can also have other naming methods, all of which are covered by the protection scope of the embodiments of this application, and this application makes no limitation in this regard. Or, the RAN device can also include 5G, such as the gNB in the new radio (NR) system, or one or a group (including multiple antenna panels) of antenna panels of the base station in 5G, or, it can also be a network node that constitutes the gNB, transmission and reception point (TRP or transmission point, TP), or transmission measurement function (TMF), such as the building base band unit (BBU), or, the centralized unit (CU) or distributed unit (DU), the RSU with base station functions, or the wired access gateway, or the core network element of 5G. Or, the RAN device can also include the access point (AP) in the wireless fidelity (WiFi) system, wireless relay nodes, wireless backhaul nodes, various forms of macro base stations, micro base stations (also called small stations), relay stations, access points, wearable devices, in-vehicle devices, and so on.

[0045] The UPF network element is mainly responsible for user data processing (such as forwarding, receiving, charging, etc.). For example, the UPF network element can receive user data from the data network (DN) and forward the user data to the terminal through the access network device. The UPF network element can also receive user data from the terminal through the access network device and forward the user data to the DN. The DN network element refers to the operator network that provides data transmission services for users. For example, Internet Protocol (IP) Multimedia Service (IMS), Internet, etc. The DN can be an external network of the operator or a network controlled by the operator, and is used to provide service to the terminal device.

[0046] The AUSF network element is mainly used to perform security authentication of the terminal.

[0047] The AMF network element is mainly used for mobility management in the mobile network. For example, user location update, user registration to the network, user handover, etc.

[0048] The SMF network element is mainly used for session management in the mobile network. For example, session establishment, modification, release. Specific functions include, for example, allocating Internet Protocol (IP) addresses for users, selecting the UPF network element that provides packet forwarding functions, etc.

[0049] The PCF network element mainly supports providing a unified policy framework to control network behavior, providing policy rules to the control layer network functions, and is also responsible for obtaining user subscription information related to policy decisions. The PCF network element can provide policies to the AMF network element and the SMF network element, such as Quality of Service (QoS) policies, slice selection policies, etc.

[0050] The NSSF network element is mainly used to select network slices for the terminal.

[0051] The NEF network element is mainly used to support the opening of capabilities and events.

[0052] The UDM network element is mainly used to store user data, such as subscription data, authentication / authorization data, etc.

[0053] The UDR network element is mainly used to store structured data, including subscription data and policy data, externally exposed structured data, and application-related data.

[0054] The AF mainly supports interacting with the CN to provide services, such as influencing data routing decisions, policy control functions, or providing some third-party services to the network side.

[0055] The technical solutions of the embodiments of this application can be applied to various communication systems, such as wireless network (Wi-Fi) systems, vehicle-to-everything (V2X) communication systems, device-to-device (D2D) communication systems, vehicle networking communication systems, fourth-generation (4G) mobile communication systems, such as long-term evolution (LTE) systems, worldwide interoperability for microwave access (WiMAX) communication systems, fifth-generation (5G), such as new radio (NR) systems, and future communication systems, etc.

[0056] In the embodiments of this application, "indication" can include direct indication and indirect indication, and can also include explicit indication and implicit indication. If the information indicated by a certain piece of information is called the information to be indicated, then in the specific implementation process, there are many ways to indicate the information to be indicated. For example, but not limited to, the information to be indicated can be directly indicated, such as the information to be indicated itself or the index of the information to be indicated, etc. It is also possible to indirectly indicate the information to be indicated by indicating other information, where there is an association relationship between the other information and the information to be indicated. It is also possible to only indicate a part of the information to be indicated, while the other parts of the information to be indicated are known or pre-agreed. For example, it is also possible to use the arrangement order of each piece of information pre-agreed (such as stipulated in the protocol) to achieve the indication of specific information, thereby reducing the indication overhead to a certain extent. At the same time, it is also possible to identify the common part of each piece of information and indicate it uniformly to reduce the indication overhead caused by indicating the same information separately.

[0057] In addition, the specific indication method can also be various existing indication methods, such as, but not limited to, the above indication methods and their various combinations, etc. The specific details of various indication methods can refer to the prior art and will not be elaborated herein. As can be seen from the above, for example, when it is necessary to indicate multiple pieces of information of the same type, there may be a situation where the indication methods of different pieces of information are different. In the specific implementation process, the required indication method can be selected according to specific needs. The embodiments of this application do not limit the selected indication method. In this way, the indication methods involved in the embodiments of this application should be understood to cover various methods that can enable the party to be indicated to obtain the information to be indicated.

[0058] It should be understood that the information to be indicated can be sent as a whole or divided into multiple sub-information and sent separately, and the sending periods and / or sending timings of these sub-information can be the same or different. The specific sending method is not limited in the embodiments of the present application. Among them, the sending periods and / or sending timings of these sub-information can be predefined, for example, predefined according to a protocol, or can be configured by the sending device by sending configuration information to the receiving device.

[0059] "Predefined" or "preconfigured" can be implemented by pre-saving corresponding codes, tables or other ways that can be used to indicate relevant information in the device, and the embodiments of the present application do not limit its specific implementation manner. Among them, "saving" can mean saving in one or more memories. The one or more memories can be separately provided, or integrated in an encoder, a decoder, a processor, or a communication device. The one or more memories can also be partly separately provided and partly integrated in a decoder, a processor, or a communication device. The type of the memory can be any form of storage medium, which is not limited in the embodiments of the present application.

[0060] The "protocol" involved in the embodiments of the present application can refer to a protocol family in the communication field, a standard protocol with a frame structure similar to that of a protocol family, or a relevant protocol applied to a future communication system. The embodiments of the present application do not make specific limitations on this.

[0061] In the embodiments of the present application, descriptions such as "when...", "in the case of...", "if", and "if" all refer to that the device will perform corresponding processing under a certain objective situation, not limited to time, and it is not required that the device must have a judgment action when implemented, nor does it mean that there are other limitations.

[0062] In the description of the embodiments of the present application, unless otherwise specified, " / " indicates that the objects associated before and after are in an "or" relationship. For example, A / B may represent A or B. The "and / or" in the embodiments of the present application is merely a description of the association relationship of the associated objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. Here, A and B may be singular or plural. Also, in the description of the embodiments of the present application, unless otherwise specified, "a plurality of" means two or more than two. "At least one (item)" or its similar expression refers to any combination of these items, including any combination of single item (item) or plural items (items). For example, at least one (item) of a, b, or c may represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c may be single or multiple. Additionally, for the convenience of clearly describing the technical solutions of the embodiments of the present application, in the embodiments of the present application, terms such as "first" and "second" are used to distinguish the same items or similar items with basically the same functions and roles. Those skilled in the art can understand that the terms "first", "second", etc. do not limit the quantity and execution order, and the terms "first", "second", etc. do not necessarily limit to being different. At the same time, in the embodiments of the present application, words such as "exemplary" or "for example" are used to represent examples, illustrations, or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the embodiments of the present application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Exactly, using words such as "exemplary" or "for example" aims to present relevant concepts in a specific way for easy understanding.

[0063] The network architecture and service scenarios described in the embodiments of the present application are for more clearly illustrating the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those of ordinary skill in the art know that with the evolution of the network architecture and the emergence of new service scenarios, the technical solutions provided by the embodiments of the present application are equally applicable to similar technical problems.

[0064] To facilitate the understanding of the embodiments of the present application, first, take the Figure 2 communication system shown as an example to detail the communication system applicable to the embodiments of the present application. Exemplarily, Figure 2 is a schematic diagram of the architecture of a communication system applicable to the data security transmission method of cloud computing provided by the embodiments of the present application.

[0065] As Figure 2 shown, this communication system can be applicable to the above 5GS, including: a relay UE and multiple remote UEs.

[0066] Among them, the relay UE can be an entity device, that is, a terminal in the conventional sense, such as the terminals in various device forms in the above introduction of the terminal. For specific details, reference can be made to the above relevant introduction and will not be elaborated here. Multiple remote UEs can be multiple virtual devices instantiated from an entity device, or can be virtual machines (VMs). In the embodiments of the present application, each virtual machine can be used to implement the functions of the remote UE, so it can also be called a remote UE in terms of naming. In addition, since these multiple remote UEs rely on the same entity device to be implemented, these multiple remote UEs can form a group. Different remote UEs implemented by different entity devices belong to different groups respectively. The communication of multiple remote UEs physically depends on the same entity device to be implemented, that is, physically, it is always this entity device that communicates with other devices, such as the relay UE. Logically at a higher level, it is considered that different multiple remote UEs respectively communicate with this relay UE.

[0067] In this communication system, by dividing multiple virtualized remote UEs in a group into target remote UEs and non-target remote UEs, for a target remote UE, such as the first remote UE, the target remote UE can establish a security mechanism for the PC5 connection between the target remote UE and the relay UE, such as the first security mechanism, and this first security mechanism can also be shared by the PC5 connection between the non-target remote UE and the relay UE in the group. In this way, the relay UE can use one security mechanism, that is, the first security mechanism, to perform secure data transmission based on the PC5 connection with each remote UE in the group, that is, to achieve secure data transmission in the cloud computing scenario.

[0068] The following will be combined with Figure 3 , and the interaction process between each network element / device in the above communication system will be specifically introduced through method embodiments. The data security transmission method for cloud computing provided by the embodiments of the present application can be applied to the above communication system and specifically applied to various scenarios mentioned in the above communication system. The following is a specific introduction.

[0069] Figure 3 It is a schematic flowchart of the method provided by the embodiments of the present application. This data security transmission method for cloud computing is applied to the above communication system and involves the interaction between the remote UE and the relay UE. The specific process is as follows:

[0070] S301, when the first remote UE requests to establish a PC5 connection with the relay UE, the relay UE determines whether the first remote UE is a target remote UE in the group.

[0071] The target remote UE can establish a security mechanism for the PC5 connection between the target remote UE and the relay UE, and the security mechanism is shared by the PC5 connection between the non-target remote UE and the relay UE in the group.

[0072] For example, the relay UE receives a first direct communication request from the first remote UE.

[0073] The first direct communication request carries the identifier of the group and the identifier of the first remote UE. The relay UE can determine whether there is group data locally based on the identifier of the group. The group data may include the identifier of the group and the identifiers of each member in the group, and the group data may also include information indicating whether each member in the group is a target remote UE or a non-target remote UE. Optionally, a group may have one target remote UE, and the rest are all non-target remote UEs. Alternatively, a group may also have multiple target remote UEs, and different non-target remote UEs may belong to different target remote UEs. For example, non-target remote UE #1 and non-target remote UE #2 belong to target remote UE #1, and non-target remote UE #3 and non-target remote UE #4 belong to target remote UE #2, indicating that the security mechanism of the PC5 connection of target remote UE #1 can be shared by the PC5 connections of non-target remote UE #1 and non-target remote UE #2, and cannot be shared by the PC5 connections of non-target remote UE #3 and non-target remote UE #4. Similarly, the security mechanism of the PC5 connection of target remote UE #2 can be shared by the PC5 connections of non-target remote UE #3 and non-target remote UE #4, and cannot be shared by the PC5 connections of non-target remote UE #1 and non-target remote UE #2.

[0074] When there is group data locally in the relay UE, the relay UE determines whether the identifier of the first remote UE is the same as the identifier of the target remote UE in the group data. If the identifier of the first remote UE is the same as the identifier of the target remote UE, it means that the first remote UE is a target remote UE; otherwise, it means that the first remote UE is not a target remote UE.

[0075] Optionally, the relay UE can obtain the group data from the network. For example, the relay UE obtains the group data from the network (such as the AMF network element) during the process of requesting registration to the network. The following will be introduced from the perspectives of the relay UE and the AMF network element respectively.

[0076] The relay UE sends a registration request to the AMF network element in the network. The registration request is used for the relay UE to request registration to the network; the relay UE performs the primary authentication process; in the case of successful primary authentication, the relay UE receives a registration acceptance from the network, and the registration acceptance carries the group data when indicating that the relay UE has successfully registered to the network.

[0077] The AMF network element receives a registration request from the first UE (such as a relay UE). Among them, the registration request is used for the first UE to request registration to the network where the AMF network element is located. The AMF network element can obtain the subscription data of the first UE from the UDM network element according to the registration request (such as the identifier of the first UE in the registration request, such as the SUPI). The subscription data is pre-updated (such as through a configuration update process) to the UDM network element by the AF. The subscription data can be used to indicate that the first UE can establish a PC5 connection with a group as a relay UE. For example, the subscription data can achieve the above indication by including the following information: the capability information of the first UE, which can be used to indicate that the first UE has the relay capability, that is, it can be used as a relay UE, and the subscription data also includes the data of the group and the type of the group. The type of the group can be used to indicate that the group is a virtual group. A virtual group means that multiple remote UEs in the group are multiple virtual devices obtained by instantiating an entity device.

[0078] Therefore, in the case where the subscription data is used to indicate that the first UE can establish a PC5 connection with a group as a relay UE, if the first UE successfully registers to the network, the AMF network element sends a registration acceptance to the first UE. Among them, the registration acceptance carries the data of the group in the case of indicating that the first UE has successfully registered to the network.

[0079] Optionally, the AMF network element may determine which one or which members in the group are the target remote UEs, and which members are the non-target remote UEs corresponding to the target remote UEs. For example, the AMF network element requests the Network Data Analytics Function (NWDAF) network element to perform a reliability analysis on the group (such as sending the data of the group to the NWDAF network element). The NWDAF network element may collect information about each member in the group from the network according to the data of the group, such as the historical communication anomaly data of each member in the network, so as to determine the reliability of each member according to the number of anomaly situations indicated by the historical communication anomaly data. The fewer the anomaly situations, the higher the reliability. Then, the NWDAF returns the reliability result of the group to the AMF, where the reliability result is used to indicate the reliability of each member of the group. Correspondingly, the AMF network element receives the reliability result of the group from the NWDAF network element. Optionally, if the member with the highest reliability is the first remote UE, the AMF network element designates the first remote UE as the target remote UE, and determines the other remote UEs in the group except the first remote UE as non-target remote UEs. Alternatively, optionally, the AMF may also perform reliability grading, dividing the members with the highest and lowest reliability into the same sharing level, dividing the members with the second highest and second lowest reliability into the same sharing level, and so on. That is, the above-mentioned target remote UE#1 is the remote UE with the highest reliability, the target remote UE#2 is the remote UE with the second highest reliability, the non-target remote UE#1 and the non-target remote UE#2 are the two remote UEs with the lowest reliability, and the non-target remote UE#3 and the non-target remote UE#4 are the two remote UEs with the second lowest reliability. At this time, the non-target remote UE#1, the non-target remote UE#2, and the target remote UE#1 form a subset, and the non-target remote UE#1 and the non-target remote UE#2 both belong to the target remote UE#1. The non-target remote UE#3, the non-target remote UE#4, and the target remote UE#2 form a subset, and the non-target remote UE#3 and the non-target remote UE#4 both belong to the target remote UE#2. The advantage of this is that the grading is more flexible, and the security of the remote UE with the lowest reliability can also be guaranteed.

[0080] S302. When the first remote UE is the target remote UE, the relay UE establishes a first security mechanism with the first remote UE.

[0081] Among them, the first security mechanism is the security mechanism of the first PC5 connection. The first PC5 connection is the PC5 connection between the relay UE and the first remote UE. That is, the first security mechanism can be used to establish a security context for integrity, confidentiality, and replay protection. For the specific principle, please refer to the relevant introduction in 3GPP TS33.536 Re17 V2X, which will not be elaborated here.

[0082] It should be noted that, for security considerations, 3GPP defines different security contexts for different PC5 connections. For example, each responder establishes a different security context with UE-1 (unknown to other UEs), that is, UE-2b and UE-2c do not know the security context used between UE-1 and UE-2a. However, the solution of the embodiment of the present application is different in that since different UEs are virtualized multiple UEs obtained by a virtualization technology of the same entity device, there is no security risk between different UEs. Therefore, the security context can be shared among these multiple UEs.

[0083] S303, the relay UE uses the first security mechanism to perform secure data transmission based on the first PC5 connection.

[0084] That is to say, the relay UE can use the first security mechanism to perform integrity, confidentiality, and replay protection verification on the data received through the first PC5 connection, and / or the relay UE can use the first security mechanism to perform integrity, confidentiality, and replay protection on the data sent through the first PC5 connection.

[0085] In summary, by dividing multiple virtualized remote UEs in a group into target remote UEs and non-target remote UEs, for a target remote UE, such as the first remote UE, the target remote UE can establish a security mechanism for the PC5 connection between the target remote UE and the relay UE, such as the first security mechanism, and this first security mechanism can also be shared by the PC5 connections between the non-target remote UEs and the relay UE in the group. In this way, the relay UE can use one security mechanism, that is, the first security mechanism, to perform secure data transmission based on the PC5 connection with each remote UE in the group, that is, to achieve secure data transmission in a cloud computing scenario.

[0086] In a possible design solution, the method further includes: the relay UE sends a first Direct Communication Accept to the second remote UE through a second PC5 connection. Wherein, the second PC5 connection is a PC5 connection established between the second remote UE and the relay UE before the first PC5 connection. The first Direct Communication Accept includes a security mechanism sharing indication, such as including the identifier of the first remote UE, to indicate that the security mechanism of the PC5 connection between the first remote UE and the relay UE needs to be used. That is to say, for the non-target remote UE that first establishes the second PC5 connection, the non-target remote UE can first use the security mechanism of the second PC5 connection negotiated with the relay UE by itself, such as the second security mechanism. After that, when the target remote UE establishes the first PC5 connection, the relay UE can reuse the direct communication acceptance again to update the security mechanism of the second PC5 connection. At this time, since the second remote UE and the first remote UE are both deployed as virtual machines on the same physical device, that is, it can be considered that the communication between them is secure. Therefore, the second remote UE can obtain the first security mechanism from the first remote UE according to the identifier of the first remote UE, and update the second security mechanism used by its own PC5 connection to the first security mechanism.

[0087] In a possible design solution, the method further includes: when the third remote UE requests to establish a PC5 connection with the relay UE, the relay UE determines whether the third remote UE is the target remote UE. For example, the relay UE can receive a second direct communication request from the third remote UE. Wherein, the second direct communication request carries the identifier of the group and the identifier of the third remote UE; the relay UE determines whether there is data of the group locally according to the identifier of the group; when there is data of the group locally in the relay UE, the relay UE determines whether the identifier of the third remote UE is the same as the identifier of the target remote UE in the data of the group, wherein, the same identifier of the third remote UE and the target remote UE indicates that the third remote UE is the target remote UE.

[0088] When the third remote UE is not the target remote UE, the relay UE sends a security mechanism sharing indication to the third remote UE, wherein the security mechanism sharing indication can include the identifier of the first remote UE, to indicate that the security mechanism of the PC5 connection between the first remote UE and the relay UE needs to be used. For example, the relay UE sends a second Direct Communication Accept to the third remote UE, wherein the second Direct Communication Accept includes a security mechanism sharing indication. At this time, since the third remote UE and the first remote UE are both deployed as virtual machines on the same physical device, that is, it can be considered that the communication between them is secure. Therefore, the third remote UE can obtain and use the first security mechanism from the third remote UE according to the identifier of the first remote UE.

[0089] In combination with the above Figure 3 The data security transmission method for cloud computing provided in the embodiments of the present application has been described in detail above. The following describes the apparatus for executing the data security transmission for cloud computing provided in the embodiments of the present application.

[0090] The apparatus is applied to a relay UE, and the apparatus is configured to: when a first remote UE requests to establish a PC5 connection with the relay UE, the relay UE determines whether the first remote UE is a target remote UE in a group; wherein, the group includes multiple remote UEs, and the multiple remote UEs are multiple virtual devices instantiated from an entity device, and the target remote UE can establish a security mechanism for the PC5 connection between the target remote UE and the relay UE, and the security mechanism is shared by the PC5 connections between non-target remote UEs in the group and the relay UE; when the first remote UE is the target remote UE, the relay UE establishes a first security mechanism with the first remote UE; wherein, the first security mechanism is the security mechanism of the first PC5 connection, and the first PC5 connection is the PC5 connection between the relay UE and the first remote UE; the relay UE uses the first security mechanism to perform secure data transmission based on the first PC5 connection.

[0091] In a possible design solution, the apparatus is configured to: the relay UE receives a first direct communication request from the first remote UE, wherein the first direct communication request carries the identifier of the group and the identifier of the first remote UE; the relay UE determines whether there is data of the group locally according to the identifier of the group; when there is data of the group locally in the relay UE, the relay UE determines whether the identifier of the first remote UE is the same as the identifier of the target remote UE in the data of the group, wherein the same identifier of the first remote UE and the target remote UE indicates that the first remote UE is the target remote UE.

[0092] Optionally, the apparatus is configured to: during the process of the relay UE requesting to register to the network, the relay UE obtains the data of the group from the network; wherein, the data of the group includes the identifier of the group and the identifiers of each member in the group.

[0093] For example, the apparatus is configured to: the relay UE sends a registration request to the AMF network element in the network, wherein the registration request is used for the relay UE to request to register to the network; the relay UE executes the main authentication process; when the main authentication is passed, the relay UE receives a registration acceptance from the network, and when the registration acceptance indicates that the relay UE has successfully registered to the network, it carries the data of the group.

[0094] In a possible design solution, the device is configured such that: the relay UE sends a first direct communication acceptance to the second remote UE via a second PC5 connection, where the first direct communication acceptance includes a security mechanism sharing indication, the second PC5 connection is a PC5 connection between the second remote UE and the relay UE established before the first PC5 connection, and the security mechanism sharing indication is used to indicate that the security mechanism of the PC5 connection between the first remote UE and the relay UE needs to be used.

[0095] In a possible design solution, the device is configured such that: when the third remote UE requests to establish a PC5 connection with the relay UE, the relay UE determines whether the third remote UE is the target remote UE; when the third remote UE is not the target remote UE, the relay UE sends a security mechanism sharing indication to the third remote UE, where the security mechanism sharing indication is used to indicate that the security mechanism of the PC5 connection between the first remote UE and the relay UE needs to be used.

[0096] Optionally, the device is configured such that: the relay UE receives a second direct communication request from the third remote UE, where the second direct communication request carries the identifier of the group and the identifier of the third remote UE; the relay UE determines whether there is data of the group locally according to the identifier of the group; when there is data of the group locally at the relay UE, the relay UE determines whether the identifier of the third remote UE is the same as the identifier of the target remote UE in the data of the group, where the same identifier of the third remote UE and the target remote UE indicates that the third remote UE is the target remote UE.

[0097] Optionally, the device is configured such that: the relay UE sends a second direct communication acceptance to the third remote UE, where the second direct communication acceptance includes a security mechanism sharing indication.

[0098] Alternatively, the device is applied to the AMF, and the device is configured such that: the AMF network element receives a registration request from the first UE, where the registration request is for the first UE to request registration to the network where the AMF network element is located; the AMF network element obtains the subscription data of the first UE from the UDM network element according to the registration request; when the subscription data is used to indicate that the first UE can act as a relay UE to establish a PC5 connection with the group, if the first UE successfully registers to the network, the AMF network element sends a registration acceptance to the first UE, where the registration acceptance carries the data of the group when indicating that the first UE successfully registers to the network, the group includes multiple remote UEs, the multiple remote UEs are multiple virtual devices obtained by instantiating an entity device, the target remote UE in the group can establish the security mechanism of the PC5 connection between the target remote UE and the relay UE, and the security mechanism is shared by the PC5 connections between the non-target remote UEs and the relay UE in the group; the data of the group includes the identifier of the group and the identifier of each member in the group.

[0099] In a possible design solution, the subscription data is pre-updated by the AF to the UDM network element. The subscription data includes the capability information of the first UE, where the capability information is used to indicate that the first UE has relay capability, and the subscription data further includes the data of the group and the type of the group. The type of the group is used to indicate that the group is a virtual group, and a virtual group means that multiple remote UEs in the group are multiple virtual devices obtained by instantiating an entity device.

[0100] Optionally, the device is configured to: the AMF network element requests the NWDAF network element to perform a reliability analysis on the group; the AMF network element receives the reliability result of the group from the NWDAF network element, where the reliability result is used to indicate the reliability of each member of the group; if the member with the highest reliability is the first remote UE, the AMF network element sets the first remote UE as the target remote UE and determines the other remote UEs in the group except the first remote UE as the target remote UEs.

[0101] Figure 4 This is a schematic structural diagram of the communication device provided in the embodiments of the present application. Exemplarily, the communication device may be a terminal, or a chip (system) or other components or assemblies that can be set in the terminal. As Figure 4 shown, the communication device 600 may include a processor 601. Optionally, the communication device 600 may further include a memory 602 and / or a transceiver 603. Among them, the processor 601 is coupled to the memory 602 and the transceiver 603, such as being connected through a communication bus.

[0102] Next, in combination with Figure 4 a specific introduction to each component of the communication device 600 will be given:

[0103] Among them, the processor 601 is the control center of the communication device 600, which may be a single processor or a collective term for multiple processing elements. For example, the processor 601 is one or more central processing units (CPUs), or may be an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application, such as: one or more digital signal processors (DSPs), or one or more field programmable gate arrays (FPGAs).

[0104] Optionally, the processor 601 can execute various functions of the communication device 600 by running or executing software programs stored in the memory 602 and calling data stored in the memory 602. For example, it can execute the data security transmission method of cloud computing as described above Figure 4 shown in the figure.

[0105] In a specific implementation, as an example, the processor 601 can include one or more CPUs, such as Figure 4 the CPU0 and CPU1 shown in the figure.

[0106] In a specific implementation, as an example, the communication device 600 can also include multiple processors. Each of these processors can be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). Here, the processor can refer to one or more devices, circuits, and / or processing cores for processing data (such as computer program instructions).

[0107] The memory 602 is used to store software programs for implementing the solution of this application and is controlled by the processor 601 for execution. The specific implementation method can refer to the above method embodiments and will not be elaborated here.

[0108] Optionally, the memory 602 can be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM), or other optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), a magnetic storage medium such as a disk storage, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 602 can be integrated with the processor 601 or exist independently and be coupled to the processor 601 through the interface circuit ( Figure 4 not shown in the figure) of the communication device 600. The embodiments of this application do not make specific limitations on this.

[0109] A transceiver 603 is used for communication with other communication devices. For example, if the communication device 600 is a terminal, the transceiver 603 can be used to communicate with a network device or another terminal device. Another example is that if the communication device 600 is a network device, the transceiver 603 can be used to communicate with a terminal or another network device.

[0110] Optionally, the transceiver 603 may include a receiver and a transmitter ( Figure 4 not shown separately in []). The receiver is used to implement the receiving function, and the transmitter is used to implement the transmitting function.

[0111] Optionally, the transceiver 603 may be integrated with the processor 601 or exist independently and be coupled to the processor 601 through an interface circuit ( Figure 4 not shown in []) of the communication device 600. The embodiments of the present application do not make specific limitations on this.

[0112] It can be understood that Figure 4 the structure of the communication device 600 shown in [] does not constitute a limitation on the communication device. An actual communication device may include more or fewer components than shown in the figure, or combine some components, or have a different component layout.

[0113] In addition, the technical effects of the communication device 600 can refer to the technical effects of the method described in the above method embodiments and will not be elaborated here.

[0114] It should be understood that the processor in the embodiments of the present application may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0115] It should also be understood that the memory in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable ROM (PROM), an erasable programmable ROM (EPROM), an electrically erasable programmable ROM (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of random access memory (RAM) are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM).

[0116] The above embodiments can be implemented in whole or in part by software, hardware (such as circuits), firmware, or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wired (such as infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or a data center that contains one or more collections of available media. The available medium can be a magnetic medium (such as a floppy disk, a hard disk, or a magnetic tape), an optical medium (such as a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state drive.

[0117] It should be understood that the term "and / or" in this document is merely a description of the association relationship between associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. Here, A and B can be singular or plural. Additionally, the character " / " in this document generally represents an "or" relationship between the associated objects before and after, but it may also represent an "and / or" relationship, which can be specifically understood with reference to the context before and after.

[0118] In the present application, "at least one" means one or more, and "a plurality" means two or more. "At least one of the following" or its similar expressions refer to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c can represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c can be single or multiple.

[0119] It should be understood that in various embodiments of the present application, the magnitudes of the sequence numbers of the above processes do not mean the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.

[0120] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. A professional technician can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of this application.

[0121] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0122] In several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of the devices or units can be electrical, mechanical, or other forms.

[0123] The units described as separate components may or may not be physically separated. The components shown as units may or may not be physical units, that is, they can be located in one place, or they can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0124] In addition, the functional units in each embodiment of this application can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit.

[0125] When the above-mentioned functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art or a part of this technical solution can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The foregoing storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs.

[0126] As described above, the above are only specific implementation manners of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed by this application can easily think of changes or substitutions, which should all be covered by the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.

Claims

1. A method for secure data transmission in cloud computing, characterized in that: The method comprises: In the case where a first remote UE requests to establish a PC5 connection with a relay UE, the relay UE determines whether the first remote UE is a target remote UE in a group; wherein the group includes a plurality of remote UEs, the plurality of remote UEs are a plurality of virtual devices obtained by instantiating a physical device, the target remote UE can establish a security mechanism for a PC5 connection between the target remote UE and the relay UE, and the security mechanism is shared by a PC5 connection between a non-target remote UE in the group and the relay UE; In the case where the first remote UE is the target remote UE, the relay UE establishes a first security mechanism with the first remote UE; wherein the first security mechanism is a security mechanism of a first PC5 connection, and the first PC5 connection is a PC5 connection between the relay UE and the first remote UE; The relay UE uses the first security mechanism to perform secure data transmission based on the first PC5 connection; The security mechanism is a security context for integrity, confidentiality and anti-replay protection.

2. The method according to claim 1, characterized in that The relay UE determines whether the first remote UE is a target remote UE in the group, including: The relay UE receives a first direct communication request from the first remote UE, wherein the first direct communication request carries an identifier of the group and an identifier of the first remote UE; The relay UE determines, according to the identifier of the group, whether the relay UE has data of the group locally; In the case that the relay UE has the data of the group locally, the relay UE determines whether the identifier of the first remote UE is the same as the identifier of the target remote UE in the data of the group, wherein the identifier of the first remote UE is the same as the identifier of the target remote UE, indicating that the first remote UE is the target remote UE.

3. The method according to claim 2, characterized in that The method further comprises: The relay UE obtains the group data from the network during the process of requesting to register with the network; wherein the group data includes the identifier of the group and the identifier of each member in the group.

4. The method according to claim 1, characterized in that: The method further comprises: The relay UE sends a first direct communication acceptance to the second remote UE through a second PC5 connection, wherein the first direct communication acceptance includes a security mechanism sharing indication, the second PC5 connection is a PC5 connection between the second remote UE and the relay UE established before the first PC5 connection, and the security mechanism sharing indication is used to indicate the need to use the security mechanism of the PC5 connection between the first remote UE and the relay UE.

5. The method according to claim 1, characterized in that The method further comprises: In the case where the third remote UE requests to establish a PC5 connection with the relay UE, the relay UE determines whether the third remote UE is the target remote UE; In the case that the third remote UE is not the target remote UE, the relay UE sends a security mechanism sharing indication to the third remote UE, wherein the security mechanism sharing indication is used to indicate that the security mechanism of the PC5 connection between the first remote UE and the relay UE needs to be used.

6. The method according to claim 5, characterized in that The relay UE determines whether the third remote UE is a target remote UE in the group, including: The relay UE receives a second direct communication request from the third remote UE, wherein the second direct communication request carries an identifier of the group and an identifier of the third remote UE; The relay UE determines, according to the identifier of the group, whether the relay UE has data of the group locally; In the case that the relay UE has the data of the group locally, the relay UE determines whether the identifier of the third remote UE is the same as the identifier of the target remote UE in the data of the group, wherein the identifier of the third remote UE is the same as the identifier of the target remote UE, indicating that the third remote UE is the target remote UE.

7. The method according to claim 6, characterized in that The relay UE sends a security mechanism sharing indication to the third remote UE, including: The relay UE sends a second direct communication acceptance to the third remote UE, wherein the second direct communication acceptance includes the security mechanism sharing indication.

8. A method for secure data transmission in cloud computing, characterized in that: The method comprises: The AMF network element receives a registration request from the first UE, wherein the registration request is used by the first UE to request registration to the network where the AMF network element is located; The AMF network element obtains the subscription data of the first UE from the UDM network element according to the registration request; In a case where the subscription data is used to indicate that the first UE can establish a PC5 connection with a group as a relay UE, if the first UE successfully registers with the network, the AMF network element sends a registration acceptance to the first UE, wherein the registration acceptance carries the data of the group when indicating that the first UE successfully registers with the network, the group includes a plurality of remote UEs, the plurality of remote UEs are a plurality of virtual devices obtained by instantiating a physical device, the target remote UE in the group can establish a security mechanism for a PC5 connection between the target remote UE and the relay UE, and the security mechanism is shared by a PC5 connection between a non-target remote UE in the group and the relay UE; the data of the group includes an identifier of the group and an identifier of each member of the group; The security mechanism is a security context for integrity, confidentiality and anti-replay protection.

9. The method according to claim 8, characterized in that The subscription data is pre-updated by AF to the UDM network element, the subscription data includes capability information of the first UE, the capability information is used to indicate that the first UE has relay capability, and the subscription data also includes data of the group and the type of the group, the type of the group is used to indicate that the group is a virtual group, and the virtual group means that the multiple remote UEs in the group are multiple virtual devices obtained by instantiating a physical device.

10. The method according to claim 9, characterized in that The method further comprises: The AMF network element requests the NWDAF network element to perform reliability analysis on the group; The AMF network element receives a reliability result of the NWDAF network element for the group, wherein the reliability result is used to indicate the reliability of each member of the group; If the member with the highest reliability is the first remote UE, the AMF network element determines the first remote UE as the target remote UE, and determines other remote UEs in the group except the first remote UE as the non-target remote UEs.

Citation Information

Patent Citations

  • Terminal security method and device for edge network

    CN116723507A

  • Registration in wireless communication network

    CN116868606A