A communication method and related apparatus

By using the session management function network element to determine differentiated user plane security strategies based on the characteristic information of service data streams, the problem of decreased user plane security protection performance in existing technologies is solved, and differentiated security protection of service data streams in mobile communication systems is realized, thereby improving security performance and service quality.

CN119584113BActive Publication Date: 2026-02-06HUAWEI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311156906.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-09-07
Publication Date
2026-02-06
Estimated Expiration
2043-09-07

AI Technical Summary

Technical Problem

In mobile communication systems, access network equipment and terminal equipment use the same user plane security policy to protect all service data carried by the same session, which leads to a decrease in user plane security protection performance.

Method used

Based on the characteristics of the service data flow, the session management function network element determines differentiated user plane security policies and achieves differentiated user plane security protection for the service data flow through the collaborative work of the session management function network element and the access network equipment.

Benefits of technology

It improves user plane security protection performance, meets user plane security requirements in different business scenarios, and ensures the security and service quality of business data flow.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119584113B_ABST
    Figure CN119584113B_ABST
Patent Text Reader

Abstract

The application provides a communication method and related device, which can improve the user plane security protection performance. In the method, a session management function network element receives a session establishment request message from a terminal device and obtains a first user plane security policy corresponding to the session. The first user plane security policy and an identifier indicating the session are sent to an access network device. Then, feature information of a service data flow of the terminal device is obtained, and a second user plane security policy corresponding to the service data flow is determined. In the case that the first user plane security policy and the second user plane security policy are inconsistent, the second user plane security policy and a quality of service (QoS) flow identifier of a first QoS flow are sent to the access network device.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of communication, and in particular to a communication method and related apparatus. BACKGROUND

[0002] In a mobile communication system, in order to ensure the security of service data transmission, an access network device performs user plane security protection, such as confidentiality protection and / or integrity protection, on downlink service data of a terminal device, and then sends the downlink service data subjected to user plane security protection to the terminal device through an air interface between the access network device and the terminal device. Similarly, the terminal device performs user plane security protection on uplink service data, and sends the uplink service data subjected to user plane security protection to the access network device through the air interface.

[0003] In the prior art, the access network device and the terminal device use the same user plane security policy to perform user plane security protection on all service data of a same session bearer. However, the service data of the session bearer is different, and using the same user plane security policy may result in a decline in user plane security protection performance. SUMMARY

[0004] The present application provides a communication method and related apparatus to improve user plane security protection performance.

[0005] In a first aspect, an embodiment of the present application provides a communication method, which is applied to a session management function network element, and the session management function network element can also be referred to as a session management function. The method comprises the following steps.

[0006] Receiving a session establishment request message from a terminal device, the session establishment request message being used to request establishment of a session;

[0007] In response to the session establishment request message, obtaining a first user plane security policy corresponding to the session, the first user plane security policy being used to indicate whether to activate user plane security protection corresponding to the session;

[0008] Sending the first user plane security policy and an identifier used to indicate the session to an access network device;

[0009] Obtaining characteristic information of a service data flow of the terminal device, the service data flow being carried in the session and being used to transmit service data of the terminal device;

[0010] Determining a second user plane security policy corresponding to the service data flow according to the characteristic information of the service data flow, the second user plane security policy being used to indicate whether to activate user plane security protection corresponding to the service data flow;

[0011] in a case that the first user plane security policy is inconsistent with the second user plane security policy, sending, to the access network device, the second user plane security policy and a quality of service (QoS) flow identifier of a first QoS flow, the QoS flow identifier of the first QoS flow being used to indicate the first QoS flow in the session for carrying the service data flow.

[0012] In an embodiment of the present application, the service data flow (SDF) of the terminal device refers to a service data flow transmitted in the terminal device, and the service data flow is used to transmit service data of the terminal device. The service data flow can be transmitted by using various protocols, including but not limited to a user datagram protocol (UDP) or a transmission control protocol (TCP). A session includes one or more QoS flows. A session management function network element allocates a QoS flow to a service data flow. An access network device maps a QoS flow to a data radio bearer (DRB). The service data flow is carried in the DRB.

[0013] In an embodiment of the present application, user plane security protection includes user plane integrity protection and / or user plane encryption protection, and the user plane encryption protection can also be referred to as user plane encryption. User plane security protection corresponding to a session is for all data radio bearers included in the session. User plane security protection corresponding to a service data flow is for a DRB carrying the service data flow.

[0014] By using the above method, the session management function network element implements differentiated user plane security protection for service data carried by a session, and improves the user plane security protection performance.

[0015] In a possible implementation manner, the session management function network element obtains the characteristic information of the service data flow of the terminal device, including that the session management function network element receives a session modification request message from the terminal device, and the session modification request message includes the characteristic information of the service data flow of the terminal device. In a scenario where the terminal device initiates session modification, the session management function network element can obtain the characteristic information of the service data flow of the terminal device from the session modification request message from the terminal device, enriches the obtaining manner of the session management function network element for the characteristic information of the service data flow, improves the implementation flexibility of the scheme, improves the user plane security protection performance, and meets the user plane security demand in different service scenarios.

[0016] In a possible implementation, before the session management function network element receives the session modification request message from the terminal device, the terminal device determines whether the session can carry the service data flow according to the characteristic information of the service data flow and the related information of the session. The terminal device obtains a data network (data network, DN) corresponding to the service data flow or network slice selection assistance information (network slice selection assistance information, NSSAI) corresponding to the service data flow. The terminal device obtains a DN corresponding to the session or NSSAI corresponding to the session. If the DN of the service data flow is the same as the DN of the session, or the NSSAI of the service data flow is the same as the NSSAI of the session, the session can carry the service data flow, and the terminal device can trigger modification of a QoS flow used to transmit the service data flow. After the terminal device triggers modification of the QoS flow used to transmit the service data flow, the terminal device sends a session modification request message to the access network device, where the session modification request message includes the characteristic information of the service data flow.

[0017] In a possible implementation, the session modification request message includes a packet filter of the service data flow, and the packet filter of the service data flow is used to indicate the characteristic information of the service data flow. The packet filter of the service data flow is used to filter an internet protocol (internet protocol, IP) data flow, to implement classification processing of the service data flow. The packet filter can be used to determine which type of service, application, or scenario the classified service data flow belongs to.

[0018] In a possible implementation, the session management function network element obtains the characteristic information of the service data flow of the terminal device, including: receiving a message for requesting to update policy information of the session from a policy control function network element, where the message for requesting to update the policy information of the session includes the characteristic information of the service data flow. The policy control function network element can also be referred to as a policy control function. The session management function network element obtains the characteristic information of the service data flow of the terminal device in a policy control function (policy control function, PCF) network element and a PCF session management policy association modification process of the session management function network element.

[0019] Further, the characteristic information of the service data flow is included in a policy and charging control (policy and charging control, PCC) rule. The PCC rule includes a template of the service data flow, and the template of the service data flow includes the characteristic information of the service data flow. The PCC rule is sent by the policy control function network element to the session management function network element.

[0020] In a scenario where the policy control function network element triggers session modification, the session management function network element can obtain the characteristic information of the service data flow from the policy control function network element, thereby enriching the obtaining manner of the session management function network element for the characteristic information of the service data flow, improving the implementation flexibility of the scheme, improving the user plane security protection performance, and meeting the user plane security requirements in different service scenarios.

[0021] In a possible implementation, the session management function network element obtains the characteristic information of the service data flow of the terminal device, including: the session management function network element obtains the subscription data of the terminal device from a unified data management network element, and the subscription data includes the characteristic information of the service data flow of the terminal device. The unified data management network element can also be referred to as unified data management. For example, after the relevant data of the terminal device included in the subscription data is changed, the unified data management network element sends the updated subscription data to the session management function network element. Alternatively, the session management function network element actively obtains the subscription data from the unified data management network element, for example, the session management function network element periodically sends the identification information of the UE to the unified data management network element, and the unified data management network element sends the subscription data to the session management function network element in response to the identification information of the UE. In a scenario where the unified data management network element triggers session modification, the session management function network element can obtain the characteristic information of the service data flow from the unified data management network element, thereby enriching the obtaining manner of the session management function network element for the characteristic information of the service data flow, improving the implementation flexibility of the scheme, improving the user plane security protection performance, and meeting the user plane security requirements in different service scenarios.

[0022] In a possible implementation, after the session management function network element obtains the characteristic information of the service data flow of the terminal device, the session management function network element determines whether the service data flow is carried in the session; and in a case where the session management function network element determines that the service data flow is carried in the session, a first user plane security policy is obtained. In a case where it is determined that the service data flow is carried in the session, the session management function network element obtains the first user plane security policy corresponding to the session, and then detects whether the second user plane security policy corresponding to the service data flow is consistent with the first user plane security policy.

[0023] In a possible implementation, the session management function network element sends a message for requesting to obtain subscription data of the terminal device to the unified data management network element; the session management function network element receives the subscription data of the terminal device from the unified data management network element, and the subscription data includes a correspondence between characteristic information of a service data flow and a user plane security policy; and the session management function network element determines a second user plane security policy corresponding to the service data flow according to the subscription data. Exemplarily, the message for requesting to obtain the subscription data of the terminal device sent by the session management function network element to the unified data management network element carries identification information of the terminal device, the unified data management network element determines corresponding subscription data according to the identification information of the terminal device, and then the unified data management network element sends the subscription data to the session management function network element. The subscription data includes the correspondence between the characteristic information of the service data flow and the user plane security policy. The session management function network element determines, according to the characteristic information of the service data flow, that the user plane security policy of the service data flow is the second user plane security policy from the subscription data. The session management function network element can obtain the subscription data of the terminal device from the unified data management network element, and then determine the second user plane security policy corresponding to the service data flow from the subscription data. The method enriches the way in which the session management function network element determines the user plane security policy of the service data flow, improves the implementation flexibility of the scheme, improves the user plane security protection performance, and meets the user plane security requirements in different service scenarios. In a possible implementation, the session management function network element determines the second user plane security policy corresponding to the service data flow according to the characteristic information of the service data flow, including: the session management function network element sends a message for requesting a user plane security policy corresponding to the characteristic information of the service data flow to the unified data management network element; and the session management function network element receives the second user plane security policy from the unified data management network element. Exemplarily, the message for requesting the user plane security policy corresponding to the characteristic information of the service data flow sent by the session management function network element to the unified data management network element carries the characteristic information of the service data flow, the unified data management network element determines the second user plane security policy corresponding to the characteristic information of the service data flow according to the characteristic information of the service data flow carried in the message. The unified data management network element feeds back to the session management function network element that the user plane security policy of the service data flow is the second user plane security policy. The session management function network element can obtain the second user plane security policy corresponding to the service data flow from the unified data management network element. The method enriches the way in which the session management function network element determines the user plane security policy of the service data flow, improves the implementation flexibility of the scheme, improves the user plane security protection performance, and meets the user plane security requirements in different service scenarios.

[0024] In a possible implementation, the session management function network element receives a policy and charging control rule from a policy control function network element, the policy and charging control rule including a correspondence between characteristic information of a service data flow and a user plane security policy; and the session management function network element determines the second user plane security policy corresponding to the characteristic information of the service data flow according to the policy and charging control rule. For example, the session management function network element determines the second user plane security policy corresponding to the service data flow from the policy and charging control rule according to the characteristic information of the service data flow. The policy and charging control rule is a dynamic rule, and the session management function network element can dynamically obtain the policy and charging control rule. The modification of the policy and charging control rule can be triggered by an application function (AF). The implementation flexibility of the scheme is improved, and the session management function network element can determine the user plane security policy corresponding to the service data flow as the second user plane security policy in multiple ways, thereby meeting the security requirements of different services.

[0025] In a possible implementation, the session management function network element determines the second user plane security policy corresponding to the characteristic information of the service data flow according to a locally configured policy. The session management function network element obtains a locally configured policy, and the locally configured policy includes a correspondence between the service data flow and a corresponding user plane security policy. For the session management function network element, the locally configured policy can also be referred to as a configuration policy of the session management function network element. The session management function network element determines the second user plane security policy corresponding to the service data flow from the configuration policy according to the characteristic information of the service data flow. The configuration policy can be a session granularity configuration policy, a QoS flow granularity configuration policy, or a service data flow granularity configuration policy. The implementation flexibility of the scheme is improved, and the session management function network element can determine the user plane security policy corresponding to the service data flow as the second user plane security policy in multiple ways, thereby meeting the security requirements of different services.

[0026] In a possible implementation, before the session management function network element sends the second user plane security policy and the QoS flow identifier of the first QoS flow to the access network device, the session management function network element further includes: creating, by the session management function network element, the first QoS flow, and determining, by the session management function network element, a quality of service parameter of the first QoS flow according to a quality of service requirement of the service data flow; and sending, by the session management function network element, the second user plane security policy and the QoS flow identifier of the first QoS flow to the access network device, including: sending, by the session management function network element, the second user plane security policy, the QoS flow identifier of the first QoS flow, and the quality of service parameter of the first QoS flow to the access network device.

[0027] Different QoS flows have different QoS parameters. The session management function network element provides the access network device with the QoS parameters corresponding to each QoS flow, and the access network device completes the configuration of the DRB and the mapping of the QoS flow and the DRB according to the QoS parameters. For example, multiple QoS flows with the same QoS parameters or similar QoS parameters are mapped to the same DRB. One or more QoS flows mapped to the DRB are transmitted through the DRB.

[0028] The session management function network element sends the service quality parameters of the first QoS flow to the access network device, so that the service quality requirements of the service data flow are met when the service data flow is carried in the first QoS flow for transmission. The session management function network element explicitly informs the RAN access network device that the user plane security policy of the first QoS flow is the second user plane security policy, which improves the implementation flexibility of the scheme. The session management function network element creates a new first QoS flow, and then sends the QoS flow identifier of the first QoS flow and the second user plane security policy to the access network device. The session management function network element configures the first QoS flow to use the second user plane security policy, and then allocates the first QoS flow to the service data flow, and the user plane security policy of the service data flow is the second user plane security policy. Avoid the problem that the QoS flow carries service data flows with different user plane security policies, and the user plane security policy of the QoS flow is inconsistent with the security requirements of the service data flow.

[0029] In a possible implementation, the session management function network element determines a QoS flow that satisfies a first condition from one or more QoS flows of a session as a first QoS flow, and the first condition includes: the service quality parameters of the QoS flow match the service quality requirements of the service data flow, and the user plane security policy corresponding to the service data flow carried by the QoS flow is consistent with the second user plane security policy. Through the above method, the problem that the QoS flow carries service data flows with different user plane security policies, and the user plane security policy of the QoS flow is inconsistent with the security requirements of the service data flow is avoided.

[0030] The session management function network element can obtain the service quality requirement of the service data flow in multiple ways. For example, the session management function network element can obtain the service quality requirement of the service data flow from the terminal device. For example, the session management function network element receives a session modification request message from the terminal device, and the session modification request message includes the service quality requirement of the service data flow. The session management function network element determines whether the service quality parameter of the QoS flow meets the service quality requirement of the service data flow according to the obtained service quality requirement of the service data flow. For example, the session management function network element can obtain the service quality requirement of the service data flow from the policy control function network element. For example, the session management function network element receives a policy and charging control rule from the policy control function network element, and the policy and charging control rule includes a parameter for determining whether the policy and charging control rule is bound to the QoS flow. The policy and charging control rule can be determined by the policy control function network element according to the service quality requirement of the service data flow sent by the application function. The session management function network element determines whether the parameter of the QoS flow is the same as the parameter in the policy and charging control rule. Please refer to clause 6.1.3.2.4 of the 3rd generation partnership project (3GPP) standard TS 23.502, which is not repeated here.

[0031] In a possible implementation, the characteristic information of the service data flow includes indication information, which is used to indicate the application layer security activation state of the service data flow. The application layer security activation state of the service data flow includes that the application layer of the service data flow is encrypted and / or integrity protected, or the application layer of the service data flow is not encrypted and / or integrity protected. For example, the indication information can be an application identifier. The session management function network element determines the application layer security activation state corresponding to the service data flow according to the application identifier.

[0032] In a case where the indication information indicates that the service data flow is encrypted at the application layer, and the first user plane security policy includes user plane encryption activation, the second user plane security policy includes user plane encryption not to be started. And / or, in a case where the indication information indicates that the application layer of the service data flow is integrity protected, the second user plane security policy includes user plane integrity protection not to be started. The user plane encryption not to be started can also be referred to as not requiring user plane encryption protection. The user plane integrity protection not to be started can also be referred to as not requiring user plane integrity protection.

[0033] In a possible implementation, the characteristic information of the service data flow includes a protocol used by the terminal device to transmit the service data flow. When the protocol used by the terminal device to transmit the service data flow is a quick user datagram protocol internet connection (QUIC) protocol or a multipath QUIC (MPQUIC) protocol, and the first user plane security policy includes a case in which user plane encryption needs to be enabled, the second user plane security policy includes a case in which user plane encryption does not need to be enabled.

[0034] In a possible implementation, the session management function network element sends first indication information to the access network device, where the first indication information is used to indicate that the user plane security policy of the first QoS flow is the second user plane security policy. The first indication information is carried in control information of the first QoS flow, and the user plane security policy of the first QoS flow is indicated to be the second user plane security policy implicitly through the control information of the first QoS flow. A network function or device receiving the control information of the first QoS flow determines, according to the control information of the first QoS flow, that the user plane security policy of the QoS flow is the second user plane security policy.

[0035] In a possible implementation, the first indication information is carried in a QoS flow identifier (QFI) of the first QoS flow. A first indication bit is added in the QFI, and the first indication bit is used to indicate that the user plane security policy of the first QoS flow is the second user plane security policy. For example, when the first indication bit is "1", it is indicated that the user plane security policy of the first QoS flow is the second user plane security policy. For another example, when the first indication bit is "0", it is indicated that the first QoS flow uses the user plane security policy of a session to which the first QoS flow belongs.

[0036] Alternatively, the first indication information is carried in a QoS profile corresponding to the first QoS flow. First indication information is added in the QoS profile of the first QoS flow, and the first indication information is used to indicate that the user plane security policy of the first QoS flow is the second user plane security policy. For example, when the first indication information is "1", it is indicated that the user plane security policy of the first QoS flow is the second user plane security policy. For another example, when the first indication information is "0", it is indicated that the first QoS flow uses the user plane security policy of a session to which the first QoS flow belongs.

[0037] Alternatively, the first indication information is carried in description information of the first QoS flow.

[0038] In a possible implementation, the session management function network element sends, to the terminal device, an access traffic steering, switching, splitting (ATSSS) rule including a correspondence between the second user plane security policy and the first QoS flow. The session management function network element adds the correspondence between the first QoS flow and the second user plane security policy in the ATSSS rule, so that the UE receiving the ATSSS rule can determine that the first QoS flow corresponds to the second user plane security policy according to the ATSSS rule.

[0039] In a second aspect, an embodiment of the present application provides a communication method, the method being applied to an access network device, and the method includes the following steps.

[0040] In a process of establishing a session of a terminal device, a first user plane security policy corresponding to the session and an identifier used for indicating the session are received from a session management function network element, the first user plane security policy being used for indicating whether user plane security protection corresponding to the session is activated;

[0041] According to the first user plane security policy, it is determined whether user plane security protection of a data radio bearer (DRB) belonging to the session is activated;

[0042] A second user plane security policy and a QoS flow identifier of a first QoS flow are received from the session management function network element, the second user plane security policy being used for indicating whether user plane security protection corresponding to a service data flow is activated, and the QoS flow identifier of the first QoS flow being used for indicating the first QoS flow in the session used for carrying the service data flow;

[0043] According to the second user plane security policy and the QoS flow identifier of the first QoS flow, it is determined that a first DRB corresponding to the first QoS flow in the session and a user plane security activation state of the first DRB.

[0044] Through the above method, the access network device allocates a first DRB for the first QoS flow according to the indication of the session management function network element, and the user plane security activation state of the first DRB is determined according to the second user plane security policy, in other words, the user plane security policy of the first DRB is the second user plane security policy, or the first DRB adopts the second user plane security policy. In this way, it is ensured that the first DRB adopting the second user plane security policy can carry service data of the first QoS flow. Through the above method, the access network device implements differentiated user plane security protection for service data carried by the session, and improves the user plane security protection performance.

[0045] In a possible implementation, the determining, according to the second user plane security policy and the QoS flow identifier of the first QoS flow, of the first DRB corresponding to the first QoS flow in the session and the user plane security activation state of the first DRB includes:

[0046] determining, according to the QoS flow identifier of the first QoS flow, that the first QoS flow is newly established;

[0047] creating the first DRB and determining, according to the second user plane security policy, the user plane security activation state of the first DRB; or determining, from the one or more DRBs of the session, a DRB that satisfies a second condition as the first DRB, the second condition including that the user plane security activation state of the DRB is determined according to the second user plane security policy.

[0048] After the access network device receives the QoS flow identifier of the first QoS flow from the session management function network element, the access network device determines, according to the QoS flow identifier of the first QoS flow, that the first QoS flow is a newly established QoS flow. Then the access network device creates the first DRB and determines, according to the second user plane security policy, the user plane security activation state of the first DRB, or the access network device determines, from the one or more DRBs of the session, a DRB that satisfies a second condition as the first DRB, the one or more DRBs of the session being the already created DRBs. The second condition includes that the user plane security activation state of the DRB is determined according to the second user plane security policy. In other words, the access network device determines, from the one or more DRBs of the session that adopt the second user plane security policy, the first DRB. Then the access network device allocates the first DRB to the first QoS flow, so as to ensure that the first DRB that adopts the second user plane security policy can bear the service data of the first QoS flow.

[0049] In a possible implementation, the determining, according to the second user plane security policy and the QoS flow identifier of the first QoS flow, of the first DRB corresponding to the first QoS flow in the session and the user plane security activation state of the first DRB includes:

[0050] determining, according to the QoS flow identifier of the first QoS flow, that the first QoS flow satisfies the following condition: 1) the first QoS flow is already created before the access network device receives the second user plane security policy and the QoS flow identifier of the first QoS flow from the session management function network element, and 2) the first QoS flow corresponds to a second DRB, and the number of QoS flows corresponding to the second DRB is greater than 1;

[0051] creating the first DRB and determining, according to the second user plane security policy, the user plane security activation state of the first DRB; or

[0052] determining, from the one or more DRBs of the session, a DRB satisfying a second condition as the first DRB, the second condition comprising: a user plane security activation status of the DRB being determined according to the second user plane security policy.

[0053] After the access network device receives the QoS flow identifier of the first QoS flow from the session management function network element, the access network device determines that the first QoS flow satisfies the following conditions according to the QoS flow identifier of the first QoS flow: 1) the first QoS flow is a QoS flow that has been created, and the first QoS flow has been created before the access network device receives the second user plane security policy and the QoS flow identifier of the first QoS flow from the session management function network element. 2) the first QoS flow has been allocated a second DRB, and the second DRB corresponds to more than one QoS flow, in other words, the second DRB corresponds to other QoS flows in addition to the first QoS flow. Then the access network device creates the first DRB, or the access network device determines the first DRB from one or more DRBs of the session that adopt the second user plane security policy. Then the access network device allocates the first DRB to the first QoS flow, so as to ensure that the first QoS flow can be borne by the first DRB that adopts the second user plane security policy.

[0054] In a possible implementation, the determining the first DRB corresponding to the first QoS flow in the session and the user plane security activation status of the first DRB according to the second user plane security policy and the QoS flow identifier of the first QoS flow comprises:

[0055] determining, according to the QoS flow identifier of the first QoS flow, that the following conditions are satisfied: 1) the first QoS flow is created before the access network device receives the second user plane security policy and the QoS flow identifier of the first QoS flow from the session management function network element, 2) the first QoS flow corresponds to the first DRB, and the number of QoS flows corresponding to the first DRB is equal to 1;

[0056] updating the user plane security activation status of the first DRB according to the second user plane security policy.

[0057] After the access network device receives the QoS flow identifier of the first QoS flow from the session management function network element, the access network device determines that the first QoS flow satisfies the following conditions according to the QoS flow identifier of the first QoS flow: 1) the first QoS flow is a QoS flow that has been created, and the first QoS flow has been created before the access network device receives the second user plane security policy and the QoS flow identifier of the first QoS flow from the session management function network element; and 2) the first QoS flow has been allocated a first DRB, and the first DRB corresponds to only one QoS flow, that is, the first DRB corresponds to only the first QoS flow. Then, the access network device updates the user plane security activation state of the first DRB according to the second user plane security policy, that is, the access network device modifies the user plane security policy of the first DRB, and the user plane security policy of the first DRB after the modification is the second user plane security policy, so as to ensure that the first DRB that can use the second user plane security policy carries traffic data of the first QoS flow.

[0058] In a possible implementation, the method further includes:

[0059] The access network device sends, to the terminal device, user plane security indication information corresponding to the first DRB, where the user plane security indication information is used to indicate whether to activate user plane security protection of the first DRB, and the user plane security indication information is determined according to the second user plane security policy.

[0060] The user plane security indication information corresponding to the first DRB is used to notify the terminal device that the user plane security policy of the first QoS flow is the second user plane security policy. In a possible implementation, the user plane security indication information corresponding to the first DRB can be carried in a radio resource control (RRC) reconfiguration message. Optionally, the RRC reconfiguration message further includes a mapping relationship between the first QoS flow and the first DRB. Through the mapping relationship between the first QoS flow and the first DRB, it is indicated that the user plane security policy of the first DRB is the second user plane security policy.

[0061] In a possible implementation, the indication of the session management function network element includes the QoS flow identifier of the first QoS flow and the second user plane security policy. After the access network device receives the QoS flow identifier of the first QoS flow and the second user plane security policy from the session management function network element, the access network device determines that the user plane security policy of the first QoS flow is the second user plane security policy according to the QoS flow identifier of the first QoS flow and the second user plane security policy. The access network device determines that the user plane security policy of the first QoS flow is the second user plane security policy according to the explicit indication of the session management function network element.

[0062] In another possible implementation, the access network device receives first indication information from the session management function network element, the first indication information being used to indicate that the user plane security policy of the first QoS flow is the second user plane security policy. Then, the access network device determines, according to the first indication information, that the user plane security policy of the first QoS flow is the second user plane security policy, and the first indication information is an implicit indication of the session management function network element. The access network device determines, according to the first indication information, that the user plane security policy of the first QoS flow is the second user plane security policy.

[0063] In a possible implementation, in response to the indication of the session management function network element, the access network device determines that the user plane security policy of the service quality first QoS flow is the second user plane security policy, including: the access network device receives first indication information from the session management function network element, the first indication information being used to indicate that the user plane security policy of the first QoS flow is the second user plane security policy; and the access network device determines, according to the first indication information, that the user plane security policy of the first QoS flow is the second user plane security policy. The first indication information is carried in control information of the first QoS flow, and the user plane security policy of the first QoS flow is implicitly indicated as the second user plane security policy through the control information of the first QoS flow. A network function or device receiving the control information of the first QoS flow determines, according to the control information of the first QoS flow, that the user plane security policy of the first QoS flow is the second user plane security policy.

[0064] In a possible implementation, the first indication information is carried in a QoS flow identifier QFI of the first QoS flow. A first indication bit is added in the QFI, and the first indication bit is used to indicate that the user plane security policy of the first QoS flow is the second user plane security policy. For example, when the first indication bit is “1”, it indicates that the user plane security policy of the first QoS flow is the second user plane security policy. For another example, when the first indication bit is “0”, it indicates that the first QoS flow adopts the user plane security policy of the session to which the first QoS flow belongs.

[0065] Alternatively, the first indication information is carried in a QoS profile corresponding to the first QoS flow. The first indication information is added in the QoS profile of the first QoS flow, and the first indication information is used to indicate that the user plane security policy of the first QoS flow is the second user plane security policy. For example, when the first indication information is “1”, it indicates that the user plane security policy of the first QoS flow is the second user plane security policy. For another example, when the first indication information is “0”, it indicates that the first QoS flow adopts the user plane security policy of the session to which the first QoS flow belongs.

[0066] Alternatively, the first indication information is carried in description information of the first QoS flow. The QoS flow description (QoS flow description) of the first QoS flow includes the first indication information.

[0067] In a possible implementation, the access network device determines that the user plane security policy of the first QoS flow is the second user plane security policy, including: the access network device acquires a configuration policy of the access network device, the configuration policy of the access network device including a correspondence between the first QoS flow and the second user plane security policy; and the access network device determines, according to the configuration policy of the access network device and the first indication information, that the first QoS flow adopts the second user plane security policy. The configuration policy can be a session granularity configuration policy, or the configuration policy can be a service data flow granularity configuration policy, which is not limited here.

[0068] In a third aspect, an embodiment of the present application provides a communication method, including:

[0069] The session management function network element acquires a network state;

[0070] The session management function network element determines a second user plane security policy corresponding to the network state according to the network state;

[0071] In a case where the second user plane security policy is inconsistent with a user plane security policy of a session of the terminal device, the session management function network element instructs an access network device to perform user plane security protection on a first QoS flow according to the second user plane security policy, the first QoS flow carrying the service data flow.

[0072] In the embodiment of the present application, after the session management function network element acquires the network state, the session management function network element determines the second user plane security policy corresponding to the network state. In a case where the second user plane security policy is inconsistent with a user plane security policy of a session of the terminal device carrying the service data flow, the session management function network element instructs an access network device to perform user plane security protection on a first QoS flow according to the second user plane security policy, the first QoS flow carrying the service data flow. By using the method provided in the above embodiment, the session management function network element modifies the user plane security policy of the first QoS flow, so that the QoS flow can execute different user plane security policies, and security protection based on the QoS flow is realized under different security requirements, and different user plane security policies of service data flows are met. In addition, when the user plane security policy of the session is different from the user plane security policy of the first QoS flow, the SMF can also instruct each network function or the terminal device to modify the user plane security policy of the first QoS flow, so as to ensure that the core network, the access network, and the terminal adopt the same security policy for the same first QoS flow.

[0073] In a possible implementation, the session management function network element acquires the network state, including:

[0074] The session management function network element acquires notification information, and the notification information is from any one or more of the following network functions or devices: an access and mobility management function, an access network device, a policy control function network element, a network manager, or a terminal device.

[0075] The session management function network element determines the network state according to the notification information.

[0076] In a possible implementation, the network state includes a network security capability, and the session management function network element determines the second user plane security policy corresponding to the network state according to the network state, including:

[0077] The session management function network element determines that the network security capability is improved according to the network state.

[0078] In response to the network security capability being improved, the session management function network element determines the second user plane security policy, and the security protection capability of the second user plane security policy is higher than that of a first user plane security policy, which is a user plane security policy used by the first QoS flow before the network state changes.

[0079] In a possible implementation, the network state includes that the network returns to normal, and the network returning to normal includes that congestion of the network returns to normal, service resources provided by the network are improved, and / or network functions in the network return to normal.

[0080] In a possible implementation, the network state includes a network security capability, and the session management function network element determines the second user plane security policy corresponding to the network state according to the network state, including:

[0081] The session management function network element determines that the network security capability is reduced according to the network state.

[0082] In response to the network security capability being reduced, the session management function network element determines the second user plane security policy, and the security protection capability of the second user plane security policy is lower than that of a first user plane security policy, which is a user plane security policy used by the first QoS flow before the network state changes.

[0083] In a possible implementation, the network state includes: a network abnormality, and the network abnormality includes: network congestion, a natural disaster in a region where the network is deployed, reduced service resources provided by the network, and / or a network function failure in the network.

[0084] In a possible implementation, the session management function network element determines the second user plane security policy corresponding to the network state according to the network state, including:

[0085] The session management function network element obtains the subscription data of a unified data management network element.

[0086] The session management function network element determines, according to the subscription data and the network state, that the user plane security policy corresponding to the network state is the second user plane security policy.

[0087] In a possible implementation, the session management function network element determines the second user plane security policy corresponding to the network state according to the network state, including:

[0088] The session management function network element obtains a policy and charging control (PCC) rule from a policy control function network element.

[0089] The session management function network element determines, according to the network state, that the user plane security policy corresponding to the network state is the second user plane security policy from the PCC rule.

[0090] In a possible implementation, the session management function network element determines the second user plane security policy corresponding to the network state according to the network state, including:

[0091] The session management function network element obtains a local configuration policy, and the local configuration policy includes a correspondence between the network state and the second user plane security policy.

[0092] The session management function network element determines, according to the network state, that the user plane security policy corresponding to the network state is the second user plane security policy from the configuration policy.

[0093] In a possible implementation, the session management function network element instructs the access network device to perform user plane security protection on the first QoS flow according to the second user plane security policy, including:

[0094] The session management function network element sends, to the access network device, a QoS flow identifier of the first QoS flow and the second user plane security policy.

[0095] In a possible implementation, the session management function network element instructs the access network device to perform user plane security protection on the first QoS flow according to the second user plane security policy, including:

[0096] The session management function network element sends first indication information to the access network device, where the first indication information is used to indicate that the user plane security policy of the first QoS flow is the second user plane security policy.

[0097] In a possible implementation, the first indication information is carried in a QoS flow identifier of the first QoS flow.

[0098] Alternatively, the first indication information is carried in a QoS profile corresponding to the first QoS flow.

[0099] Alternatively, the first indication information is carried in description information of the first QoS flow.

[0100] In a possible implementation, the session management function network element sends an access traffic steering, switching, splitting, ATSSS, rule to the terminal device, where the ATSSS rule includes a correspondence between the second user plane security policy and the first QoS flow.

[0101] In a fourth aspect, an embodiment of the present application provides a communication method, including:

[0102] A session management function network element receives a session establishment request from a terminal device, where the session establishment request includes a first session identifier and a second session identifier.

[0103] The session management function network element determines, according to the session establishment request, that a quality of service, QoS, flow corresponding to a user plane security policy is a first user plane security policy, where the QoS flow carries data of the terminal device.

[0104] The session management function network element creates a first session and a second session according to the session establishment request, where the first session corresponds to the first session identifier, the second session identifier corresponds to the second session identifier, the first session carries the QoS flow, and a user plane security policy of the first session is the first user plane security policy.

[0105] In the embodiments of the present application, after determining that the user plane security policy corresponding to the QoS flow is the first user plane security policy, the session management function network element establishes two protocol data units (PDUs) sessions respectively, and the two PDU sessions respectively carry the traffic corresponding to the first user plane security policy and other traffic. The PDU session carrying the traffic corresponding to the first user plane security policy is protected by the first user plane security policy. Thus, the user plane security policy of the QoS flow granularity is realized.

[0106] In a possible implementation, the method further includes:

[0107] The session management function network element sends the first session identifier and the first user plane security policy to the access network device;

[0108] The session management function network element sends the second session identifier and the user plane security policy of the second session to the access network device.

[0109] The fifth aspect of the present application provides a communication apparatus, which can implement the method in the first aspect or any possible implementation manner of the first aspect. The apparatus includes corresponding units or modules for performing the method. The units or modules included in the apparatus can be implemented by software and / or hardware. For example, the apparatus can be a session management function network element, or the apparatus can be a component (for example, a processor, a chip or a chip system, etc.) in the session management function network element, or the apparatus can also be a logical module or software capable of implementing all or part of the session management function network element. The communication apparatus includes one or more functional modules for executing the method in the first aspect or any possible implementation manner of the first aspect. Exemplarily, the communication apparatus includes a transceiver module and a processing module.

[0110] The sixth aspect of the present application provides a communication apparatus, which can implement the method in the second aspect or any possible implementation manner of the second aspect. The apparatus includes corresponding units or modules for performing the method. The units or modules included in the apparatus can be implemented by software and / or hardware. For example, the apparatus can be an access network device, or the apparatus can be a component (for example, a processor, a chip or a chip system, etc.) in the access network device, or the apparatus can also be a logical module or software capable of implementing all or part of the access network device. The communication apparatus includes one or more functional modules for executing the method in the second aspect or any possible implementation manner of the second aspect. Exemplarily, the communication apparatus includes a transceiver module and a processing module.

[0111] The seventh aspect of the present application provides a communication device which can implement the method in the third aspect or any possible implementation manner of the third aspect. The device comprises corresponding units or modules for performing the method. The units or modules included in the device can be implemented in a software and / or hardware manner. For example, the device can be a session management function network element, or the device can be a component (for example, a processor, a chip or a chip system, etc.) in the session management function network element, or the device can also be a logical module or software capable of implementing all or part of the session management function network element. The communication device comprises one or more functional modules for performing the method in the third aspect or any possible implementation manner of the third aspect. Exemplarily, the communication device comprises a transceiver module and a processing module.

[0112] The eighth aspect of the present application provides a communication device which can implement the method in the fourth aspect or any possible implementation manner of the fourth aspect. The device comprises corresponding units or modules for performing the method. The units or modules included in the device can be implemented in a software and / or hardware manner. For example, the device can be a session management function network element, or the device can be a component (for example, a processor, a chip or a chip system, etc.) in the session management function network element, or the device can also be a logical module or software capable of implementing all or part of the session management function network element. The communication device comprises one or more functional modules for performing the method in the fourth aspect or any possible implementation manner of the fourth aspect. Exemplarily, the communication device comprises a transceiver module and a processing module.

[0113] The ninth aspect of the embodiments of the present application provides a communication device, comprising at least one processor coupled with a memory; the memory is used to store programs or instructions; the at least one processor is used to execute the programs or instructions, so that the device implements the method in any possible implementation manner of the first aspect to the fourth aspect.

[0114] The tenth aspect of the embodiments of the present application provides a communication device, comprising a communication interface for inputting and / or outputting signaling or data; a processor for executing a computer executable program, so that the device implements the method in any possible implementation manner of the first aspect to the fourth aspect.

[0115] The eleventh aspect of the embodiments of the present application provides a communication device, comprising at least one logic circuit and an input / output interface; the input / output interface is used to input or output information; the logic circuit is used to execute the method in any possible implementation manner of the first aspect to the fourth aspect.

[0116] The twelfth aspect of the embodiments of the present application provides a computer program product, which comprises a computer program, and when the computer program is run on a computer, the computer program causes the computer to execute the method in the first aspect to the fourth aspect and any possible implementation manner.

[0117] The thirteenth aspect of the embodiments of the present application provides a chip system, which comprises at least one processor, and is configured to support the communication device to implement the method in the first aspect to the fourth aspect and any possible implementation manner.

[0118] In a possible design, the chip system can further comprise a memory, which is configured to store necessary program instructions and data of the communication device. The chip system can be composed of a chip, or can comprise the chip and other discrete devices. Optionally, the chip system further comprises an interface circuit, which provides program instructions and / or data for the at least one processor.

[0119] The fourteenth aspect of the embodiments of the present application provides a communication system, which comprises the communication device in the fifth aspect, the communication device in the sixth aspect, the communication device in the seventh aspect, or the communication device in the eighth aspect.

[0120] The technical effects brought by the fifth aspect to the fourteenth aspect can be referred to the technical effects brought by the different implementation manners of the first aspect to the third aspect, and details are not described herein.

[0121] It should be understood that, for the components in the device, the above-mentioned “sending” can be referred to as “output”, and “receiving” can be referred to as “input”. BRIEF DESCRIPTION OF DRAWINGS

[0122] Figure 1 FIG. 1 is a schematic diagram of a communication system in the embodiments of the present application;

[0123] Figure 2a FIG. 2 is a schematic diagram of a PDU session;

[0124] Figure 2b FIG. 3 is a schematic diagram of an architecture for access traffic steering, switching, splitting;

[0125] Figure 2c FIG. 4 is another schematic diagram of an architecture for access traffic steering, switching, splitting;

[0126] Figure 3 FIG. 5 is a schematic diagram of an embodiment of a communication method in the embodiments of the present application;

[0127] Figure 4 FIG. 6 is a schematic diagram of a structure of a QFI in the embodiments of the present application;

[0128] Figure 5 A structure diagram for QoS flow description in embodiments of the present application;

[0129] Figure 6 Another embodiment flow diagram of a communication method proposed in embodiments of the present application;

[0130] Figure 7 Another embodiment flow diagram of a communication method proposed in embodiments of the present application;

[0131] Figure 8 An application scenario diagram in embodiments of the present application;

[0132] Figure 9 An application scenario diagram in embodiments of the present application;

[0133] Figure 10 An application scenario diagram in embodiments of the present application;

[0134] Figure 11 A schematic diagram of a communication device provided by the present application;

[0135] Figure 12 Another schematic diagram of a communication device provided by the present application;

[0136] Figure 13 Another schematic diagram of a communication device provided by the present application;

[0137] Figure 14 Another schematic diagram of a communication device provided by the present application. DETAILED DESCRIPTION

[0138] The technical solutions in embodiments of the present application will be clearly and completely described below with reference to the drawings in embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, not all the embodiments. The terms "first", "second" and corresponding terms of reference in the specification and claims of the present application and the above drawings are used to distinguish similar objects, and do not necessarily describe a specific order or sequence. It should be understood that the terms used in this way can be interchanged under appropriate circumstances, which is only a distinguishing way used in the description of the embodiments of the present application to describe the objects with the same attributes. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, so that the process, method, system, product or equipment including a series of units does not necessarily limit to those units, but can include other units not clearly listed or inherent to these processes, methods, products or equipment.

[0139] In the description of the present application, unless otherwise specified, " / " means or, for example, A / B can mean A or B; "and / or" in the present application is only a description of the relationship between the associated objects, which means that there can be three relationships, for example, A and / or B can mean that A exists alone, A and B exist together, and B exists alone. In addition, in the description of the present application, "at least one" means one or more, and "more" means two or more. "At least one" or similar expressions refer to any combination of these items, including any combination of single or multiple items. For example, at least one of a, b, or c can mean a, b, c, a-b, a-c, b-c, or a-b-c, where a, b, and c can be single or multiple.

[0140] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as: long term evolution (LTE) system, LTE frequency division duplex (FDD) system, LTE time division duplex (TDD), universal mobile telecommunication system (UMTS), worldwide interoperability for microwave access (WiMAX) communication system, 5th generation (5G) system, new generation (NR) communication system or future 6th generation communication system, etc.

[0141] Part of the communication system operated by the operator can be referred to as an operator network. The operator network can also be referred to as a public land mobile network (PLMN) network, which is a network established and operated by a government or a government-approved operator for the purpose of providing land mobile communication services to the public, mainly a public network in which a mobile network operator (MNO) provides mobile broadband access services for users. The operator network or PLMN network described in the embodiments of the present application can be a network that meets the requirements of the 3rd generation partnership project (3GPP) standard, referred to as a 3GPP network. Generally, the 3GPP network is operated by an operator, including but not limited to a fifth-generation mobile communication network, a fourth-generation mobile communication network, or a third-generation mobile communication technology network. It also includes future sixth-generation mobile communication networks. For the convenience of description, the embodiments of the present application will be described taking the operator network as an example.

[0142] The terminal device in this application embodiment can refer to user equipment (UE). As a device with wireless transceiver capabilities, the terminal device involved in this application embodiment can communicate with one or more core networks (CNs) via access network devices in a radio access network (RAN). The terminal device can also be referred to as an access terminal, terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, wireless network device, user agent, or user device, etc. The terminal device can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; it can also be deployed on water (such as on ships); and it can also be deployed in the air (e.g., on airplanes, balloons, and satellites). Terminal devices can be cellular phones, cordless phones, session initiation protocol (SIP) phones, smartphones, mobile phones, wireless local loop (WLL) stations, personal digital assistants (PDAs), handheld devices with wireless communication capabilities, computing devices or other devices connected to a wireless modem, in-vehicle devices, wearable devices, drone devices or IoT devices, terminals in vehicle networks, terminals in any form in 5G networks and future networks, relay user equipment, or terminals in future evolved PLMNs, etc. Among them, relay user equipment can be, for example, a 5G residential gateway (RG). For example, terminal devices can be virtual reality (VR) terminals, augmented reality (AR) terminals, wireless terminals in industrial control, self-driving, remote medical care, smart grids, transportation safety, smart cities, and smart homes. Furthermore, a user interface (UE) can also be a terminal device in an Internet of Things (IoT) system. IoT is an important component of future information technology development, its main technical characteristic being the connection of objects to networks through communication technologies, thereby achieving intelligent networks that enable human-machine interconnection and machine-to-machine interconnection.IoT technology can achieve massive connection, deep coverage and terminal power saving through, for example, narrow band (NB) technology. In addition, the UE can also include smart printers, train detectors, gas station sensors, and the like, and the main functions include collecting data (part of terminal devices), receiving control information and downlink data of network devices, and sending electromagnetic waves to transmit uplink data to network devices. It should be understood that the UE can be any device that can access the network. The UE and the access network device can communicate with each other using a certain air interface technology, and the embodiments of the present application are not limited thereto.

[0143] Please refer to Figure 1 , Figure 1 is a schematic diagram of a communication system in an embodiment of the present application. As shown in Figure 1 , the network includes an access and mobility management function (AMF) network element, a unified data management (UDM) network element, a radio access network (RAN), a policy control function network element, a terminal device, a user plane function (UPF) network element, a data network, and the like.

[0144] It should be understood that Figure 1 only as a schematic description of the diagram, the number and type of network elements (or devices, or network functions) actually deployed in the network are not limited by the embodiments of the present application.

[0145] Among them, Figure 1 The main function of each device shown in the description is as follows:

[0146] The radio access network includes one or more access network devices. The access network device in the present application includes but is not limited to: a next generation base station (gnodeB, gNB) in 5G, an evolved node B (eNB), a radio network controller (RNC), a node B (NB), a base station controller (BSC), a base transceiver station (BTS), a home base station (for example, a home evolved nodeB, or a home node B, HNB), a baseband unit (BBU), a transmitting and receiving point (TRP), a transmitting point (TP), a mobile switching center, etc.

[0147] The unified data management network element (also referred to as unified data management, unified data management network element entity, data management device, unified data management network element device) is a kind of core network device, mainly used for processing terminal device identification, access authentication, registration and mobility management, etc. The unified data management network element is a control plane device.

[0148] The policy control function network element (also referred to as policy control network element, policy control function, policy control device, policy control function network element entity, etc.): mainly responsible for charging, quality of service bandwidth guarantee and mobility management, terminal device policy decision and other policy control functions for session, service flow level.

[0149] The session management function (SMF) network element (also referred to as session management function): mainly for session management, execution of control policy issued by PCF, selection of UPF, terminal device internet protocol address allocation and other functions.

[0150] The access and mobility management function network element (also referred to as access and mobility management function entity, access and mobility management device, access and mobility management function, access management device, mobility management device) is a kind of core network device, mainly used for mobility management and access management, etc. It can be used to realize other functions in the mobility management entity (MME) function except session management, for example, lawful interception, or access authorization (or authentication), user equipment registration, mobility management, tracking area update process, reachability detection, session management network element selection, mobile state conversion management and other functions.

[0151] User plane function network element (may also be referred to as a user plane device, a user plane function network element, a user plane network element, a user plane function entity): mainly includes the following functions: data packet routing and transmission, packet detection, service usage reporting, QoS processing, lawful interception, uplink packet detection, downlink data packet storage, and other user plane related functions.

[0152] Application Function (AF), the AF is similar to an application server, which interacts with other 5G core control plane NFs and provides service services. The AF can exist for different application services and can be owned by an operator or a trusted third party. For example, the main function of this network element is to tell the PCF the latest business requirements of a third-party enterprise for a certain application. The PCF will generate corresponding quality of service QoS rules according to the requirements to ensure that the services provided by the network meet the requirements proposed by the third party.

[0153] Network Exposure Function (network exposure function, NEF), not shown in the figure. The NEF can also be referred to as a network exposure device, a network exposure function entity, a network exposure function network element, a network capability exposure function entity, a network capability exposure function device, a network capability exposure function network element, or a network capability exposure device. The NEF is mainly used to support the exposure of capabilities and events, such as safely exposing services and capabilities provided by 3GPP network functions to the outside.

[0154] It should be understood that the RAN, SMF, PCF or AF in the embodiments of the present application can also be referred to as a communication device or a communication device, which can be a general-purpose device or a special-purpose device, and the present application does not specifically limit it.

[0155] It should also be understood that the above naming is only used to distinguish different functions and does not mean that these devices are independent physical devices. The present application does not limit the specific form of the above devices, for example, they can be integrated in the same physical device or can be different physical devices. In actual deployment, network functions (or simply functions), network elements or devices can be combined. For example, the access and mobility management function network element can be combined with the session management function network element; the session management function network element can be combined with the user plane function network element. When two functions are combined, the interaction between the two functions provided by the embodiments of the present application becomes an internal operation of the combined function or can be omitted.

[0156] It can be understood that the above functions can be network elements in hardware devices, software functions running on special hardware, or a combination of hardware and software, or virtualized functions instantiated on a platform (for example, a cloud platform).

[0157] It should be noted that Figure 1 The naming of each device (such as PCF, AMF, etc.) is only a name, and the name does not limit the function of the device itself. In the 5G network and future other networks, the above-mentioned devices can also be other names, and the present application does not specifically limit this. For example, in the 6G network, part or all of the above-mentioned network elements can use the terms in 5G, or other names, etc., which are uniformly described herein and will not be described below.

[0158] It should be noted that the examples mentioned in the present application do not represent the best; the first, second, etc. mentioned in the present application are only used to distinguish different information, messages or other objects, and do not represent a sequential relationship; in addition, the embodiments in the present application can be mutually referenced and learned from each other, and the same or similar steps or terms are not described one by one.

[0159] In order to better describe the technical solutions of the embodiments of the present application, the technical terms related to the technical solutions of the embodiments of the present application will be described below.

[0160] 1. Session, quality of service flow (QoS flow) and data radio bearer (DRB).

[0161] The terminal device and the core network can transmit the service data of the terminal device through the session. One session can include one or more QoS flows. The QoS flow can be identified by a (QoS flow identifier, QFI). The session management function network element allocates the QoS flow to the service data flow, in other words, the QoS flow is used to carry the service data flow.

[0162] The core network provides the access network device with QoS parameters corresponding to each QoS flow, and the access network device completes the configuration of the data radio bearer and the mapping of the QoS flow and the DRB according to the QoS parameters. For example, multiple QoS flows with the same QoS parameters or similar QoS parameters are mapped to the same DRB, and one or more QoS flows mapped to the DRB are transmitted through the DRB.

[0163] Exemplarily, please refer to Figure 2a , Figure 2a is a schematic diagram of a PDU session in the fifth generation mobile communication technology. The PDU session between the core network and the UE includes QoS flows 1-7 (Flow 1-Flow 7), a total of 7 QoS flows, wherein QoS flows 1-2 are carried on DRB1, QoS flows 3-4 are carried on DRB2, and QoS flows 5-7 are carried on DRB3.

[0164] 2. User plane security policy.

[0165] The terminal device and the access network device perform security protection on the session according to the user plane security policy. The user plane security policy can include: user plane integrity protection, and / or, user plane encryption protection. The user plane security policy of the session is determined in the session establishment process, and is applied to the entire life of the session.

[0166] 2.1, the user plane integrity protection in the user plane security policy can have 3 values:

[0167] 1) required: the user plane integrity protection shall be used for all traffic on the session;

[0168] 2) preferred: the user plane integrity protection should be used for all traffic on the session;

[0169] 3) not needed: no user plane integrity protection is performed on the session.

[0170] 2.2, the user plane encryption protection in the user plane security policy can have 3 values:

[0171] 1) required: the user plane encryption protection shall be used for all traffic on the session;

[0172] 2) preferred: the user plane encryption protection should be used for all traffic on the session;

[0173] 3) not needed: no user plane encryption protection is performed on the session.

[0174] The current user plane security policy is usually session granularity, that is, one or more QoS flows contained in the session use the same user plane security policy, but the service data carried by different QoS flows is different, and the use of the same user plane security policy may cause the performance of user plane security protection to decline.

[0175] For example, in a traffic steering, switching, splitting (ATSSS) scenario, if the service data in the QoS flow is transmitted by using a multipath quick UDP internet connection (MPQUIC) protocol, since the MPQUIC protocol adopts a mandatory encryption security mechanism, that is, the MPQUIC protocol stipulates that a terminal device and a UPF perform encryption protection and integrity protection on a data flow, if a user plane security policy corresponding to the session of the QoS flow is required to perform user plane integrity protection and required to perform user plane encryption protection, the QoS flow has a redundant encryption problem.

[0176] In the following, the communication method proposed by the embodiments of the present application is introduced in combination with the drawings. First, refer to Figure 3 , Figure 3 FIG. 1 is a flowchart of an embodiment of the communication method in the embodiments of the present application. The communication method proposed by the embodiments of the present application includes the following steps.

[0177] S1, a session management function network element receives a session establishment request message from a terminal device, the session establishment request message being used to request to establish a session.

[0178] In step S1, exemplarily, the session is a PDU session, and the session establishment request message is a “PDU Session Establishment Request” message.

[0179] S2, the session management function network element acquires a first user plane security policy in response to the session establishment request message.

[0180] In step S2, the session management function network element acquires a user plane security policy of a session requested to be established by the session establishment request message according to the session establishment request message. In order to facilitate description, the user plane security policy of the session is referred to as a first user plane security policy. The first user plane security policy is used to indicate whether to activate user plane security protection corresponding to the session.

[0181] Exemplarily, the session management function network element can acquire the first user plane security policy in multiple ways. For example, the session management function network element determines the first user plane security policy according to subscription data of the terminal device from a unified data management network element. For another example, the session management function network element determines the first user plane security policy according to a local configuration policy of the session management function network element. For another example, the session management function network element determines the first user plane security policy according to a maximum data rate of user plane integrity protection supported by the terminal device for a DRB.

[0182] S3, the session management function network element sends the first user plane security policy and an identifier indicating the session to the access network device.

[0183] In step S3, the session management function network element sends the first user plane security policy and an identifier indicating the session to the access network device, and the access network device is informed that the user plane security policy corresponding to the session is the first user plane security policy through the identifier indicating the session and the first user plane security policy. Correspondingly, the access network device receives the first user plane security policy corresponding to the session and the identifier indicating the session from the session management function network element in the process of establishing the session of the terminal device, and the first user plane security policy is used to indicate whether to activate the user plane security protection corresponding to the session. For example, the first user plane security policy is used to indicate to activate the user plane security protection corresponding to the session, or the first user plane security policy is used to indicate not to activate the user plane security protection corresponding to the session. The access network device determines whether to activate the user plane security protection of the data radio bearer (DRB) belonging to the session according to the first user plane security policy, for example, if the first user plane security policy includes that the session needs user plane integrity protection and the session needs user plane encryption protection, the access network device determines that the DRB belonging to the session needs user plane integrity protection and needs user plane encryption protection according to the first user plane security policy.

[0184] After the session management function network element sends the first user plane security policy and the identifier indicating the session to the access network device, step S4 is entered.

[0185] S4, the session management function network element obtains the characteristic information of the service data flow of the terminal device.

[0186] In step S4, the service data flow of the terminal device refers to the service data flow transmitted between the terminal device and the service server. The service data flow involved in the embodiments of the present application can be a service data flow transmitted using UDP, a transmission control protocol or other protocols. For example, the service data flow of the terminal device can be: a UDP service data flow in a PDU session established between the terminal device and a 5G core network (5G core, 5GC); or a UDP service data flow in a packet data network (packet data network, PDN) connection established between the terminal device and an evolved packet core network (evolved packet core network, EPC) network.

[0187] The characteristic information of the service data flow described in the embodiments of the present application includes any one or more of the following information: a service type of the service data flow, a network transmission protocol of the service data flow, an Internet protocol (Internet Protocol, IP) five-tuple of the service data flow, or an application layer security activation state of the service data flow.

[0188] Exemplarily, the service type of the service data flow includes, but is not limited to, instant messaging service, video service, webpage browsing service, audio service, extended reality (XR) service, or virtual reality (VR) service, and the like.

[0189] Exemplarily, the network transmission protocol of the service data flow includes, but is not limited to, TCP protocol, UDP protocol, QUIC protocol, MPTCP protocol, or MPQUIC protocol.

[0190] The QUIC protocol is a transmission protocol based on the UDP transmission layer protocol, and can realize multiplexing and secure transmission between a client and a server. Exemplarily, the client can be a terminal device, and the server can be a service server providing services for the client.

[0191] The QUIC connection uses the transport layer security (TLS) protocol to establish and maintain a secure connection and end-to-end encryption, and all data sent through the QUIC connection is encrypted by default, which helps to prevent data from being eavesdropped and other forms of attacks.

[0192] The MPQUIC protocol is an extension of the QUIC protocol, and the MPQUIC protocol allows data to be transmitted through multiple paths. The security mechanism of the MPQUIC protocol is similar to that of the QUIC protocol, and therefore the data sent through the MPQUIC protocol is also encrypted by default.

[0193] Exemplarily, the Internet protocol IP five-tuple of the service data flow includes: a source IP address, a destination IP address, a source port number, a destination port number, and a network transmission protocol type.

[0194] Exemplarily, the application layer security activation state of the service data flow includes: the application layer of the service data flow is encrypted and / or integrity protected, or the application layer of the service data flow is not encrypted and / or integrity protected.

[0195] In an implementation manner, the feature information of the service data flow includes any one or more of the following information: flow identification information of the service data flow, service data flow description information, application identifier of the service data flow, identifier of a session carrying the service data flow, and identifier of a terminal device transmitting the service data flow. The application identifier of the service data flow is specifically an identifier of an application program corresponding to the service data flow. Exemplarily, the identifier of the session carrying the service data flow can be an identifier of a PDU session carrying the service data flow.

[0196] In yet another possible implementation, the characteristic information of the service data flow is indicated by a packet filter of the service data flow, in other words, the packet filter of the service data flow includes the characteristic information of the service data flow. The packet filter of the service data flow can be carried in various messages, for example, a PDU session modification request message. Illustratively, the session management function network element determines the characteristic information of the service data flow from the packet filter of the service data flow included in the PDU session modification request message.

[0197] The following describes how the session management function network element obtains the characteristic information of the service data flow of the terminal device. Illustratively, the session management function network element obtains the characteristic information of the service data flow of the terminal device in any one or more of the following ways 1-3.

[0198] Way 1: The session management function network element receives the characteristic information of the service data flow of the terminal device sent by the terminal device.

[0199] For example, the terminal device sends a message for requesting to modify a session to the session management function network element, and correspondingly, the session management function network element receives the message for requesting to modify the session sent by the terminal device, and the message for requesting to modify the session includes the characteristic information of the service data flow of the terminal device. Illustratively, the message for requesting to modify the session is a session modification request message.

[0200] Way 2: The session management function network element receives the characteristic information of the service data flow of the terminal device sent by a policy control function network element PCF.

[0201] For example, the policy control function network element sends a message for requesting to update policy information of the session to the session management function network element, and the message for requesting to update the policy information of the session includes the characteristic information of the service data flow. Illustratively, the message for requesting to update the policy information of the session can be a “Npcf_SMPolicyControl_UpdateNotify request” message.

[0202] Illustratively, the session management function network element obtains the characteristic information of the service data flow in a session management (SM) policy association modification procedure initiated by the policy control function network element.

[0203] Regarding the PCF session management policy association modification procedure, the AF can trigger the PCF session management policy association modification procedure. In the above PCF session management policy association modification procedure, the AF sends the characteristic information of the service data flow to the PCF through the NEF. For example, the PCF obtains the characteristic information of the service data flow from the "Npcf_PolicyAuthorization_Create" message or the "Npcf_PolicyAuthorization_Update" message.

[0204] Regarding the AF triggering the PCF session management policy association modification procedure, the following is described in detail:

[0205] (1) The AF can initiate a QoS flow creation procedure.

[0206] First, the AF sends an "Nnef_AFsessionWithQoS_Create" request message to the NEF, and the request message is used to request to establish an AF session (AF session). The request message includes one or more of the following information: address information of the UE, identification information of the AF, flow description information, external application identifier, QoS reference or individual QoS parameters, PDU set QoS parameters, protocol description, or alternative service requirements. The characteristic information of the service data flow is included in one or more of the above information.

[0207] Secondly, the NEF responds to the "Nnef_AFsessionWithQoS_Create" request message and performs an authorization check. Then, the NEF discovers the PCF and forwards the information carried in the "Nnef_AFsessionWithQoS_Create" request message to the PCF. The NEF sends the "Npcf_PolicyAuthorization_Create" request message to the PCF, and the request message carries one or more of the above information. If the AF is considered to be trusted by the operator, the AF directly sends the "Npcf_PolicyAuthorization_Create" request message to the PCF, and the request message carries one or more of the above information. The AF requests to reserve resources for the related session of the AF through the "Npcf_PolicyAuthorization_Create" request message.

[0208] Secondly, after receiving the "Npcf_PolicyAuthorization_Create" request message, the PCF judges whether the request message is authorized. If the request message is authorized, the PCF derives the QoS parameters required by the PCC rule according to the information carried in the request message. The PCF judges whether the QoS flow is allowed according to the configuration of the PCF and notifies the NEF of the judgment result. If the NEF subscribes to the QoS monitoring event, the PCF generates the QoS monitoring policy of the service data flow according to the information provided by the NEF. If the AF is considered to be trusted by the operator, the PCF directly sends the "Npcf_PolicyAuthorization_Create" response message to the AF.

[0209] (2) The AF can initiate a QoS flow modification process.

[0210] For an established AF session, the AF can send the "Nnef_AFsessionWithQoS_Update" request message to the NEF, which is used to update the reserved resources of the AF session to the NEF. The message includes one or more of the following information: AF identifier, transaction reference ID, flow description information, QoS reference or single QoS parameter, PDU Set QoS parameter, protocol description, or alternative service requirement. The above one or more information includes the characteristic information of the service data flow.

[0211] The AF can also provide one or more of the following parameters to describe the traffic characteristics: flow direction, burst arrival time of UE (uplink) or UPF (downlink), periodicity, time domain, survival time, or cycle range, etc.

[0212] Optionally, the NEF interacts with the PCF by triggering a “Npcf_PolicyAuthorization_Update” request message, and the NEF forwards the received information or parameters to the PCF.

[0213] Optionally, if the AF is considered as operator trusted, the AF interacts with the PCF directly using a “Npcf_PolicyAuthorization_Update” request message, and the AF sends the information or parameters to the PCF and updates the reserved resources of the AF session.

[0214] The PCF updates the PCC rules according to the “Npcf_PolicyAuthorization_Update” request message.

[0215] Option 3: The session management function network element receives subscription data sent by the unified data management network element, and the subscription data includes characteristic information of a service data flow of the terminal device.

[0216] For example, the unified data management network element sends subscription data of the terminal device to the session management function network element, and the subscription data of the terminal device includes characteristic information of a service data flow. Illustratively, the session management function network element obtains the subscription data from the unified data management network element through a “Nudm_SDM_Notification” message, and details are described in 3GPP standard TS23.502 clause 4.3.3.2 “The UDM updates the subscription data of SMF by Nudm_SDM_Notification (SUPI, Session Management Subscription Data)”, which is not described herein.

[0217] In an example, after the subscription data of the terminal device is changed, the unified data management network element sends the updated subscription data to the session management function network element. Alternatively, the session management function network element actively obtains the subscription data of the terminal device from the unified data management network element, for example, the session management function network element sends a message for requesting the subscription data of the terminal device to the unified data management network element, and the message can include an identifier of the terminal device. In response to the message, the unified data management network element sends the subscription data of the terminal device to the session management function network element. Optionally, the session management function network element can periodically send a message for requesting the subscription data of the terminal device to the unified data management network element, so as to obtain the latest subscription data of the terminal device.

[0218] S5, the session management function network element determines a second user plane security policy corresponding to the service data flow according to the characteristic information of the service data flow.

[0219] In step S5, after obtaining the characteristic information of the service data flow, the session management function network element can determine the second user plane security policy corresponding to the service data flow in multiple ways.

[0220] Next, how the session management function network element determines the second user plane security policy corresponding to the service data flow is described. By way of example, the session management function network element determines the second user plane security policy corresponding to the service data flow in any one or more of the following ways 1-4.

[0221] Way 1: The session management function network element sends a message for requesting to obtain the subscription data of the terminal device to the unified data management network element. Correspondingly, the session management function network element receives the subscription data of the terminal device from the unified data management network element, which includes the correspondence between the characteristic information of the service data flow and the user plane security policy. Finally, the session management function network element determines the second user plane security policy corresponding to the characteristic information of the service data flow according to the subscription data.

[0222] By way of example, the session management function network element sends a message for requesting the subscription data of the terminal device to the unified data management network element, which optionally includes the identification information of the terminal device. In response to the message for requesting the subscription data of the terminal device, the unified data management network element sends the subscription data to the session management function network element, for example, the unified data management network element determines the subscription data corresponding to the identification information of the terminal device according to the identification information of the terminal device in the message, and sends the subscription data to the session management function network element. The subscription data includes the second user plane security policy. After receiving the subscription data of the terminal device sent by the unified data management network element, the session management function network element determines from the subscription data that the user plane security policy corresponding to the characteristic information of the service data flow is the second user plane security policy.

[0223] Way 2: The session management function network element sends a message for requesting the user plane security policy corresponding to the characteristic information of the service data flow to the unified data management network element; the session management function network element receives the second user plane security policy from the unified data management network element.

[0224] By way of example, the message for requesting the user plane security policy corresponding to the characteristic information of the service data flow includes the characteristic information of the service data flow. The unified data management network element determines the corresponding second user plane security policy in the subscription data according to the characteristic information of the service data flow carried by the message for requesting the user plane security policy corresponding to the characteristic information of the service data flow, and then sends the second user plane security policy to the session management function network element.

[0225] Manner 3: The session management function network element receives a policy and charging control rule from the policy control function network element, the policy and charging control rule including a correspondence between characteristic information of a service data flow and a user plane security policy; the session management function network element determines a second user plane security policy corresponding to the characteristic information of the service data flow according to the policy and charging control rule.

[0226] Exemplarily, the session management function network element obtains a policy and charging control (PCC) rule from a policy control function (PCF). Then, the session management function network element determines a second user plane security policy corresponding to a service data flow according to characteristic information of the service data flow from the PCC rule. The PCC rule is a dynamic rule, and the session management function network element can dynamically obtain the PCC rule. Modification of the PCC rule can be triggered by an AF.

[0227] The ATSSS described in the embodiments of the application can also be referred to as splitting, switching, and separating of accessed services, and the embodiments of the application do not make specific limitations thereon. A terminal device or UPF supporting an ATSSS function can select a transmission link for a data packet based on a splitting mode and a link state.

[0228] Specifically, a terminal device supporting an ATSSS function supports one or more of the following functions: a multipath transmission control protocol (MPTCP) function, an MPQUIC protocol function, and an ATSSS low layer (ATSSS-LL) function.

[0229] Each steering, switching, and splitting function in the UE allows service traffic to be diverted, switched, and / or split to 3GPP access and non-3GPP access according to an ATSSS rule provided by the network, or allows service traffic to be diverted, switched, and / or split to 3GPP access, or allows service traffic to be diverted, switched, and / or split to non-3GPP access. For example Figure 2b and Figure 2c As shown in Figure 2b is a schematic diagram of an architecture for steering, switching, and splitting of access traffic, Figure 2c is a schematic diagram of an architecture for steering, switching, and splitting of access traffic. Figure 2b As shown, a non-roaming scenario and a roaming with local breakout scenario using ATSSS are shown, Figure 2b In the non-roaming scenario and the roaming with local breakout scenario using ATSSS, the UE and the UPF support an MPTCP function, an MPQUIC function, and an ATSSS-LL function. Figure 2c As shown, a home-routed roaming scenario using ATSSS is shown, Figure 2cThe UE and the home UPF (H-UPF) support MPTCP function, MPQUIC function and ATSSS-LL function.

[0230] For an Ethernet type multi-access protocol data unit (MAPDU) session (or multi-access PDU session), the ATSSS-LL function is required in the UE. In the same MA PDU session in the UE, the MPTCP function can be used to guide the TCP corresponding traffic data flow, the MPQUIC function can be used to guide the UDP corresponding traffic data flow, and the ATSSS-LL function can be used to guide other traffic data flow (ATSSS-LL can also guide TCP and UDP traffic).

[0231] Further optionally, the SMF can also include a second user plane security policy in the ATSSS rule derived according to the PCC rule. For example, the ATSSS rule is shown in Table 1, and the ATSSS rule can include any one or more information in Table 1. It can be understood that the ATSSS rule can also include other information, which is not described here.

[0232] Table 1

[0233]

[0234] Option 4: The session management function network element determines the second user plane security policy corresponding to the characteristic information of the traffic data flow according to a local configuration policy. Specifically, the session management function network element obtains a local configuration policy, and the local configuration policy includes a corresponding relationship between the traffic data flow and the corresponding user plane security policy. For the session management function network element, the local configuration policy can also be referred to as the configuration policy of the session management function network element.

[0235] Specifically, the session management function network element determines the second user plane security policy according to the local configuration policy. For example, the local configuration policy includes a corresponding relationship between the traffic data flow and the second user plane security policy, and the session management function network element determines the second user plane security policy corresponding to the traffic data flow according to the characteristic information of the traffic data flow. The configuration policy can be a session granularity configuration policy, the configuration policy can also be a QoS flow granularity configuration policy, or the configuration policy can be a traffic data flow granularity configuration policy. For example, the configuration policy is shown in Tables 2-5.

[0236] Exemplarily, the configuration policy is shown in Table 2. When the steering function used by the service data flow is the MPQUIC function, the second user plane security policy is the user plane security policy #1. When the steering function used by the service data flow is the MPTCP function, the second user plane security policy is the user plane security policy #2. When the steering function used by the service data flow is the ATSSS-LL function, the second user plane security policy is the user plane security policy #3. Exemplarily, the session management function network element determines the steering function used by the service data flow according to the characteristic information of the service data flow, for example, the session management function network element determines the steering function used by the service data flow from the ATSSS rule according to the characteristic information of the service data flow.

[0237] Table 2

[0238]

[0239] Exemplarily, the configuration policy is shown in Table 3.

[0240] Table 3

[0241]

[0242] Exemplarily, the configuration policy is shown in Table 3. When the service type of the service data flow is the service data flow of the XR service, the second user plane security policy is the user plane security policy #1. When the service type of the service data flow is the service data flow of the VR service, the second user plane security policy is the user plane security policy #2. When the service type of the service data flow is the service data flow of other services, the second user plane security policy is the user plane security policy #3.

[0243] Exemplarily, the configuration policy is shown in Table 4.

[0244] Table 4

[0245]

[0246] Exemplarily, the configuration policy is shown in Table 4. When the application layer security activation state of the service data flow is that the application layer of the service data flow is encrypted, the second user plane security policy is the user plane security policy #1. When the application layer security activation state of the service data flow is that the application layer of the service data flow is not encrypted, the second user plane security policy is the user plane security policy #2. Exemplarily, the user plane security policy corresponding to the service data flow in the session can also be determined according to the network transmission protocol of the service data flow, that is, according to the network transmission protocol of the service data flow, the user plane security policy used by the service data flow related to the network transmission protocol in the session is determined. For example, the configuration policy is shown in Table 5.

[0247] Table 5

[0248]

[0249] Regarding Table 5, it is illustrated that: when the network transmission protocol of the service data stream is the QUIC protocol, the service data stream in this session adopts user plane security policy #1; when the network transmission protocol of the service data stream is the TCP protocol, the service data stream in this session adopts user plane security policy #2; when the network transmission protocol of the service data stream is both the TCP protocol and the TLS protocol, the service data stream in this session adopts user plane security policy #3.

[0250] Furthermore, the characteristic information of the service data flow includes indication information, which indicates the application layer security activation status of the service data flow. The application layer security activation status of the service data flow includes: the application layer of the service data flow is encrypted and / or protected for integrity, or the application layer of the service data flow is not encrypted and / or not protected for integrity. For example, this indication information may be an application identifier. The session management function network element determines the application layer security activation status corresponding to the service data flow based on the application identifier.

[0251] If the indication information indicates that the business data flow is encrypted at the application layer, and the first user plane security policy includes user plane encryption requiring activation, then the second user plane security policy includes user plane encryption not requiring activation. And / or, if the indication information indicates that the application layer of the business data flow has integrity protection, then the second user plane security policy includes user plane integrity protection not requiring activation. User plane encryption not requiring activation can also be referred to as not requiring user plane encryption protection. User plane integrity protection not requiring activation can also be referred to as not requiring user plane integrity protection.

[0252] S6. If the second user plane security policy is inconsistent with the first user plane security policy, the session management function network element sends the second user plane security policy and the QoS flow identifier of the first QoS flow of the quality of service to the access network device. The QoS flow identifier of the first QoS flow is used to indicate the first QoS flow used to carry service data flow in the session.

[0253] In step S6, the session management function network element determines whether the second user plane security policy is consistent with the first user plane security policy. If they are inconsistent, the session management function network element instructs the access network device to perform user plane security protection on the first QoS flow carrying the service data flow according to the second user plane security policy. If the session management function network element determines that the second user plane security policy is consistent with the first user plane security policy, the session management function network element instructs the access network device to perform user plane security protection on the first QoS flow carrying the service data flow according to the first user plane security policy; or, the session management function network element sends the first user plane security policy and the QoS flow identifier of the first QoS flow to the access network device.

[0254] Regarding the second user plane security policy, including but not limited to: a, the first QoS flow needs user plane integrity protection;

[0255] b, the first QoS flow recommends user plane integrity protection;

[0256] c, the first QoS flow does not need user plane integrity protection;

[0257] d, the first QoS flow needs user plane encryption protection;

[0258] e, the first QoS flow recommends user plane encryption protection;

[0259] f, the first QoS flow does not need user plane encryption protection;

[0260] g, the first QoS flow needs user plane integrity protection, and the first QoS flow needs user plane encryption protection;

[0261] h, the first QoS flow needs user plane integrity protection, and the first QoS flow recommends user plane encryption protection;

[0262] i, the first QoS flow needs user plane integrity protection, and the first QoS flow does not need user plane encryption protection;

[0263] j, the first QoS flow recommends user plane integrity protection, and the first QoS flow needs user plane encryption protection;

[0264] k, the first QoS flow recommends user plane integrity protection, and the first QoS flow recommends user plane encryption protection;

[0265] l, the first QoS flow recommends user plane integrity protection, and the first QoS flow does not need user plane encryption protection;

[0266] m, the first QoS flow does not need user plane integrity protection, and the first QoS flow needs user plane encryption protection;

[0267] n, the first QoS flow does not need user plane integrity protection, and the first QoS flow recommends user plane encryption protection;

[0268] o, the first QoS flow does not need user plane integrity protection, and the first QoS flow does not need user plane encryption protection.

[0269] Regarding the session management function network element instructing the access network equipment to perform user plane security protection on the first QoS flow carrying the service data flow according to the second user plane security policy, specific ways include the following:

[0270] In a possible implementation, the session management function network element sends the second user plane security policy and the QoS flow identifier of the first QoS flow to the access network device. The QoS flow identifier of the first QoS flow includes but is not limited to the QoS flow identifier of the first QoS flow, a 5G QoS indicator, or an allocation and retention priority. Optionally, the session management function network element sends the second user plane security policy and the QoS flow identifier of the first QoS flow to the access network device through the access and mobility management function.

[0271] For example, the session management function network element carries the second user plane security policy and the identifier of the QoS flow in a “Namf_Communication_N1N2MessageTransfer” message sent to the access and mobility management function, and carries the second user plane security policy and the identifier of the QoS flow in a “N2_PDU_Session Request (NAS msg)” message sent to the access network device.

[0272] In another possible implementation, the session management function network element sends first indication information to the access network device, where the first indication information is used to indicate that the user plane security policy of the first QoS flow is the second user plane security policy.

[0273] The first indication information is carried in control information of the first QoS flow, and the user plane security policy of the first QoS flow is implicitly indicated as the second user plane security policy through the control information of the first QoS flow. A network function or device receiving the control information of the first QoS flow determines, according to the control information of the first QoS flow, that the user plane security policy of the first QoS flow is the second user plane security policy.

[0274] The control information of the first QoS flow is described below, which includes but is not limited to the QFI of the first QoS flow, a QoS profile of the first QoS flow, a QoS flow description of the first QoS flow, or other related information of the QoS flow.

[0275] (1) The QFI of the first QoS flow includes the first indication information. A first indication bit is added in the QFI, and the first indication bit is used to indicate that the user plane security policy of the first QoS flow is the second user plane security policy. For example, when the first indication bit is “1”, it indicates that the user plane security policy of the first QoS flow is the second user plane security policy. For another example, when the first indication bit is “0”, it indicates that the first QoS flow adopts the user plane security policy of the session to which the first QoS flow belongs.

[0276] For example, refer to Figure 4 ,Figure 4 A structure diagram of QFI in an embodiment of the present application. The length of current QFI is 6 bits. In the embodiment of the present application, the QFI is expanded, and the expanded QFI includes the original 6-bit field and a first indication bit. For example, when the length of the first indication bit is 1 bit, the length of the expanded QFI is 7 bits.

[0277] It should be noted that the QFI carrying the first indication bit can be carried in any message sent by the SMF to any network function or device, and the embodiments of the present application do not limit this.

[0278] It should be noted that the first indication bit can also be carried by other QoS flow identification information of the first QoS flow, which includes but is not limited to: the QoS classification identification code of the first QoS flow, the 5G QoS indication of the first QoS flow, or the allocation and retention priority of the first QoS flow.

[0279] (2) The QoS profile of the first QoS flow includes first indication information. The first indication information is added in the QoS profile of the first QoS flow, and the first indication information is used to indicate that the user plane security policy of the first QoS flow is the second user plane security policy. For example, when the first indication information is “1”, it indicates that the user plane security policy of the first QoS flow is the second user plane security policy. For another example, when the first indication information is “0”, it indicates that the first QoS flow uses the user plane security policy of the session to which the first QoS flow belongs.

[0280] For example, the above-mentioned QoS profile of the first QoS flow can be carried in an N2 message, which is sent by a session management function network element to an access network device through an access and mobility management function.

[0281] (3) The QoS flow description of the first QoS flow includes the first indication information. As for the QoS flow description, it means that the network can also provide the terminal device with one or more QoS flow descriptions associated with a PDU session at the PDU session establishment or at the PDU session modification. The QoS flow description of the first QoS flow includes the first indication information. In the QoS flow description of the first QoS flow, a second indication bit is added, which is used to indicate that the user plane security policy of the first QoS flow is the second user plane security policy. For example, when the second indication bit is “1”, it indicates that the user plane security policy of the first QoS flow is the second user plane security policy. For another example, when the second indication bit is “0”, it indicates that the first QoS flow adopts the user plane security policy of the session to which the first QoS flow belongs, and the user plane security policy of the session is the first user plane security policy, that is, the user plane security policy of the first QoS flow is not modified. For ease of understanding, please refer to Figure 5 , Figure 5 A structure diagram of the QoS flow description in the embodiment of the application.

[0282] (4) The other related information of the first QoS includes the first indication information. In the other related information of the first QoS, a first information element (IE) is added, which is used to indicate that the user plane security policy of the first QoS flow is the second user plane security policy. The other related information of the first QoS can be authorized QoS flow descriptions, which can be carried in the “PDU SESSION ESTABLISHMENT ACCEPT” message sent by the session management function network element to the terminal device, or the “PDU SESSION MODIFICATION COMMAND” message sent by the session management function network element to the terminal device.

[0283] In another possible implementation, the session management function network element creates a first QoS flow, then allocates the first QoS flow to the service data flow, and determines the quality of service of the first QoS flow according to the quality of service requirement of the service data flow. The user plane security policy of the first QoS flow is the second user plane security policy. The specific method is as follows:

[0284] Step D1, the session management function network element creates a first QoS flow.

[0285] Step D2, the session management function network element determines the QoS parameter of the first QoS flow according to the quality of service requirement of the service data flow. The QoS parameter includes but is not limited to: guaranteed flow bit rate (GFBR), maximum flow bit rate (MFBR), notification control, reflective QoS attribute (RQA), and maximum packet loss rate-up link and down link, etc. By determining the QoS parameter of the first QoS flow, the quality of service of the first QoS flow meets the quality of service requirement of the service data flow.

[0286] Step D3, the session management function network element indicates that the user plane security policy of the first QoS flow is the second user plane security policy to the access network device. The session management function network element sends the second user plane security policy and the QoS flow identifier of the first QoS flow to the access network device. Alternatively, the session management function network element sends first indication information to the access network device, the first indication information being used to indicate that the user plane security policy of the first QoS flow is the second user plane security policy. The specific method is similar to the method described in the foregoing embodiments, and details are not described herein.

[0287] Step D4, the session management function network element notifies the terminal device that the first QoS flow is used to carry the service data flow through the access network device.

[0288] The session management function network element sends the second user plane security policy, the QoS flow identifier of the first QoS flow, and the quality of service parameter of the first QoS flow to the access network device. The session management function network element sends the quality of service parameter of the first QoS flow to the access network device, so that the quality of service requirement of the service data flow is met when the service data flow is carried in the first QoS flow for transmission. The second user plane security policy is carried in the newly created first QoS flow, and then the first QoS flow is allocated to the service data flow. The problem that the user plane security policy of the first QoS flow is inconsistent with the security requirement of the service data flow due to the fact that the service data flow adopting different user plane security policies is carried in the first QoS flow is avoided.

[0289] In another possible implementation, the session management function network element determines, from one or more QoS flows in a session, a QoS flow satisfying a first condition as the first QoS flow. The first condition includes that the quality of service parameter of the QoS flow matches the quality of service requirement of the service data flow, and the user plane security policy corresponding to the service data flow carried by the QoS flow is consistent with the second user plane security policy. Then, the session management function network element allocates the first QoS flow to the service data flow. The specific method is as follows:

[0290] Step F1, the session management function network element determines, from one or more QoS flows in a session, the first QoS flow, the quality of service of the first QoS flow satisfying the quality of service requirement of the service data flow, and the user plane security policy corresponding to the service data flow carried by the first QoS flow being consistent with the second user plane security policy.

[0291] Step F2, the session management function network element indicates, to the access network device, that the user plane security policy of the first QoS flow is the second user plane security policy. The specific method is similar to the method described in the foregoing embodiments, and details are not described herein.

[0292] Step F3, the session management function network element notifies, through the access network device, the terminal device that the first QoS flow is used to carry the service data flow.

[0293] By determining, from one or more QoS flows in a session, the first QoS flow, the quality of service of the first QoS flow satisfying the quality of service requirement of the service data flow, and the user plane security policy of the first QoS flow being the second user plane security policy, the problem that the user plane security policy of the first QoS flow is inconsistent with the security requirement of the service data flow due to the fact that the service data flow adopting different user plane security policies is carried in the first QoS flow is avoided.

[0294] S7, the access network device receives the second user plane security policy and the QoS flow identifier of the first QoS flow from the session management function network element, and determines the first DRB corresponding to the first QoS flow in the session and the user plane security activation state of the first DRB according to the second user plane security policy and the QoS flow identifier of the first QoS flow.

[0295] For example, after the access network device receives the QoS flow identifier of the first QoS flow and the second user plane security policy from the session management function network element, the access network device determines that the user plane security policy of the first QoS flow is the second user plane security policy according to the QoS flow identifier of the first QoS flow and the second user plane security policy. According to the explicit indication of the session management function network element, the access network device can directly and accurately determine that the user plane security policy of the first QoS flow is the second user plane security policy.

[0296] For another example, the access network device receives first indication information from the session management function network element, the first indication information being used to indicate that the user plane security policy of the first QoS flow is the second user plane security policy. Then, the access network device determines that the user plane security policy of the first QoS flow is the second user plane security policy according to the first indication information. In this way, the access network device determines the user plane security policy of the first QoS flow as the second user plane security policy according to the indication of the session management function network element, without the need for the session management function network element to send the specific content of the second user plane security policy, which can reduce the signaling overhead.

[0297] Optionally, the access network device determines that the user plane security policy of the first QoS flow is the second user plane security policy according to the local configuration policy and the first indication information, and the configuration policy is similar to the configuration policy shown in Tables 2-5, which will not be described herein. The configuration policy of the access network device includes the correspondence between the first QoS flow and the second user plane security policy. Alternatively, the configuration policy of the access network device includes the correspondence between the characteristic information of the service data flow and the second user plane security policy. Then, the access network device determines that the user plane security policy of the first QoS flow is the second user plane security policy according to the configuration policy of the access network device and the first indication information.

[0298] For the indication of the session management function network element, please refer to the description of step S6, which will not be described herein.

[0299] Secondly, how the access network device determines the first DRB corresponding to the first QoS flow in the session and the user plane security activation state of the first DRB according to the second user plane security policy and the QoS flow identifier of the first QoS flow will be introduced, and the first DRB uses the second user plane security policy.

[0300] In a possible implementation, the access network device determines, according to the QoS flow identifier of the first QoS flow, that the first QoS flow is a newly established one; the access network device creates the first DRB and determines, according to the second user plane security policy, the user plane security activation state of the first DRB; or determines, from the one or more DRBs of the session, that the DRB satisfying the second condition is the first DRB, and the second condition includes that the user plane security activation state of the DRB is determined according to the second user plane security policy.

[0301] After the access network device receives the QoS flow identifier of the first QoS flow from the session management function network element, the access network device determines, according to the QoS flow identifier of the first QoS flow, that the first QoS flow is a newly established QoS flow. For example, the access network device locally stores the correspondence between a PDU session, a QoS flow and a DRB, which can be “an identifier of a PDU session-an identifier of a QoS flow-an identifier of a DRB”. After the access network device receives the QoS flow identifier of the first QoS flow from the session management function network element, the access network device detects whether the corresponding QoS flow identifier exists in the correspondence stored locally by the access network device. If the access network device determines that the QoS flow identifier of the first QoS flow does not exist in the correspondence stored locally by the access network device, the access network device determines that the first QoS flow is a newly established QoS flow. After the access network device determines that the first QoS flow is a newly established QoS flow, the access network device creates the first DRB and determines, according to the second user plane security policy, the user plane security activation state of the first DRB.

[0302] For example, the second user plane security policy is that the first QoS flow needs user plane integrity protection, and the first QoS flow needs user plane encryption protection. The access network device determines, according to the second user plane security policy, that the user plane security activation state of the first DRB is that the user plane integrity protection of the first DRB is activated (or the user plane integrity protection of the first DRB is turned on), and the user plane encryption protection of the first DRB is activated (or the user plane encryption protection of the first DRB is turned on).

[0303] For another example, the second user plane security policy is: the first QoS flow is recommended to be protected by user plane integrity protection, and the first QoS flow is recommended to be protected by user plane encryption. The access network device determines the user plane security activation state of the first DRB according to the second user plane security policy and a local policy of the access network device. According to the local policy of the access network device, the user plane security activation state of the first DRB can be: the user plane integrity protection of the first DRB is activated (or the user plane integrity protection of the first DRB is turned on) and the user plane encryption protection of the first DRB is activated (or the user plane encryption protection of the first DRB is turned on); the user plane security activation state of the first DRB can also be: the user plane integrity protection of the first DRB is not activated (or the user plane integrity protection of the first DRB is turned off) and the user plane encryption protection of the first DRB is not activated (or the user plane encryption protection of the first DRB is turned off); the user plane security activation state of the first DRB can also be: the user plane integrity protection of the first DRB is not activated (or the user plane integrity protection of the first DRB is turned off) and the user plane encryption protection of the first DRB is activated (or the user plane encryption protection of the first DRB is turned on); the user plane security activation state of the first DRB can also be: the user plane integrity protection of the first DRB is activated (or the user plane integrity protection of the first DRB is turned on) and the user plane encryption protection of the first DRB is not activated (or the user plane encryption protection of the first DRB is turned off).

[0304] For another example, the second user plane security policy is: the first QoS flow does not need to be protected by user plane integrity protection, and the first QoS flow does not need to be protected by user plane encryption. The access network device determines the user plane security activation state of the first DRB according to the second user plane security policy as: the user plane integrity protection of the first DRB is not activated (or the user plane integrity protection of the first DRB is turned off), and the user plane encryption protection of the first DRB is not activated (or the user plane encryption protection of the first DRB is turned off).

[0305] Alternatively, the access network device determines a DRB satisfying a second condition from one or more DRBs of the session as the first DRB, the one or more DRBs of the session being the created DRBs. The second condition comprises that the user plane security activation state of the DRB is determined according to the second user plane security policy. In other words, the access network device determines the first DRB from one or more DRBs of the session adopting the second user plane security policy. Then the access network device allocates the first DRB to the first QoS flow, so as to ensure that the first DRB adopting the second user plane security policy can carry the service data of the first QoS flow.

[0306] In a possible implementation, the access network device determines, according to the QoS flow identifier of the first QoS flow, that the following conditions are met: 1) the first QoS flow is created before the second user plane security policy and the QoS flow identifier of the first QoS flow are received from the session management function network element, 2) the first QoS flow corresponds to the second DRB, and the number of QoS flows corresponding to the second DRB is greater than 1.

[0307] The access network device creates the first DRB, and determines the user plane security activation state of the first DRB according to the second user plane security policy; or determines, from one or more DRBs of the session, that a DRB satisfying a second condition is the first DRB, and the second condition includes that the user plane security activation state of the DRB is determined according to the second user plane security policy.

[0308] The access network device receives the QoS flow identifier of the first QoS flow from the session management function network element, and determines, according to the QoS flow identifier of the first QoS flow, that the first QoS flow meets the following conditions: 1) the first QoS flow is a created QoS flow, and the first QoS flow is created before the access network device receives the second user plane security policy and the QoS flow identifier of the first QoS flow from the session management function network element; 2) the first QoS flow is allocated to the second DRB, and the number of QoS flows corresponding to the second DRB is greater than 1, in other words, the second DRB corresponds to other QoS flows in addition to the first QoS flow. Then the access network device creates the first DRB, or determines, from one or more DRBs of the session that use the second user plane security policy, the first DRB. Then the access network device allocates the first DRB to the first QoS flow, to ensure that the first DRB that uses the second user plane security policy can carry service data of the first QoS flow.

[0309] In a possible implementation, the access network device determines, according to the QoS flow identifier of the first QoS flow, that the following conditions are met: 1) the first QoS flow is created before the second user plane security policy and the QoS flow identifier of the first QoS flow are received from the session management function network element, 2) the first QoS flow corresponds to the first DRB, and the number of QoS flows corresponding to the first DRB is equal to 1; and the access network device updates the user plane security activation state of the first DRB according to the second user plane security policy.

[0310] After the access network device receives the QoS flow identifier of the first QoS flow from the session management function network element, the access network device determines that the first QoS flow satisfies the following conditions according to the QoS flow identifier of the first QoS flow: 1) the first QoS flow is a QoS flow that has been created, and the first QoS flow has been created before the access network device receives the second user plane security policy and the QoS flow identifier of the first QoS flow from the session management function network element; and 2) the first QoS flow has been allocated the first DRB, and the first DRB corresponds to only one QoS flow, in other words, the first DRB corresponds to only the first QoS flow. Then, the access network device updates the user plane security activation state of the first DRB according to the second user plane security policy, in other words, the access network device modifies the user plane security policy of the first DRB, and the user plane security policy of the first DRB after the modification is the second user plane security policy, so as to ensure that the first DRB that can use the second user plane security policy carries the service data of the first QoS flow.

[0311] Through the above method, the access network device allocates the first DRB for the first QoS flow according to the indication of the session management function network element, and the first DRB uses the second user plane security policy. This ensures that after the user plane security policy of the QoS flow is modified, the DRB that can use the corresponding security policy carries the traffic of the QoS flow.

[0312] S8. The access network device sends user plane security indication information corresponding to the first DRB to the terminal device.

[0313] Step S8 is an optional step. After receiving the indication of the session management function network element, the access network device sends the user plane security indication information corresponding to the first DRB to the terminal device. The user plane security indication information is used to indicate whether to activate the user plane security protection of the first DRB, and the user plane security indication information is determined according to the second user plane security policy.

[0314] For example, the second user plane security policy is that the first QoS flow needs user plane integrity protection, and / or the first QoS flow needs user plane encryption protection. The user plane security indication information corresponding to the first DRB includes an indication to activate the user plane integrity protection of the first DRB, and / or an indication to activate the user plane encryption protection of the first DRB.

[0315] For another example, the second user plane security policy is that the first QoS flow recommends user plane integrity protection, and / or, the first QoS flow recommends user plane encryption protection. The access network device determines the user plane security activation state of the first DRB according to the second user plane security policy and a local policy of the access network device. Further, the access network device determines the user plane security indication information corresponding to the first DRB according to the user plane security activation state of the first DRB. The user plane security indication information corresponding to the first DRB can be: indicating activating user plane integrity protection of the first DRB and / or indicating activating user plane encryption protection of the first DRB; the user plane security indication information corresponding to the first DRB can also be: indicating not activating user plane integrity protection of the first DRB and / or indicating not activating user plane encryption protection of the first DRB; the user plane security indication information corresponding to the first DRB can also be: indicating not activating user plane integrity protection of the first DRB and / or indicating activating user plane encryption protection of the first DRB; the user plane security indication information corresponding to the first DRB can also be: indicating activating user plane integrity protection of the first DRB and / or indicating not activating user plane encryption protection of the first DRB.

[0316] For another example, the second user plane security policy is that the first QoS flow does not need user plane integrity protection, and / or, the first QoS flow does not need user plane encryption protection. The user plane security indication information corresponding to the first DRB can also be: indicating not activating user plane integrity protection of the first DRB and / or indicating not activating user plane encryption protection of the first DRB.

[0317] In a possible implementation manner, the user plane security indication information corresponding to the first DRB can be carried in a radio resource control (RRC) reconfiguration message. The RRC reconfiguration message includes the DRB and the user plane security indication information corresponding to the DRB.

[0318] In the embodiments of the present application, after the session management function network element obtains the characteristic information of the service data flow of the terminal device, the second user plane security policy corresponding to the service data flow is determined according to the characteristic information of the service data flow. In the case where the second user plane security policy is inconsistent with the first user plane security policy corresponding to the session, the session management function network element instructs the access network device to perform user plane security protection on the first QoS flow according to the second user plane security policy, and the first QoS flow carries the service data flow. By using the method provided in the above embodiments, the differentiated user plane security protection is realized for the service data carried by the session, the user plane security protection performance is improved, and the security requirements of different services are met. In addition, when the user plane security policy of the session is different from the user plane security policy of the QoS flow, the SMF can also instruct each network function or the terminal device to modify the user plane security policy of the QoS flow, so as to ensure that the core network, the access network and the terminal adopt the same user plane security policy for the same QoS flow.

[0319] In combination with the foregoing embodiments, the present application also provides other implementation schemes. In yet another example, the subscription data further includes a user plane security policy corresponding to a data network accessed by the terminal device. Alternatively, in yet another example, the subscription data includes a user plane security policy corresponding to a slice providing communication services for the terminal device. Illustratively, the terminal device carries an identifier of a data network requested by the terminal device or an identifier of a slice requested by the terminal device in a session establishment request message sent to the session management function network element. The terminal device requests to access the data network through the session establishment request message, or the terminal device requests the slice to provide communication services for the terminal device through the session establishment request message. The session management function network element determines the data network accessed by the terminal device or the slice providing communication services for the terminal device according to the session establishment request message. Further, the session management function network element determines the user plane security policy of the terminal device in the data network or the user plane security policy of the terminal device in the slice according to the subscription data. The session management function network element uses the user plane security policy to perform corresponding user plane security protection on the QoS flow corresponding to all service data flows in the terminal device.

[0320] Or, in another example, the subscription data includes a user plane security policy corresponding to a terminal device level. Illustratively, the terminal device level refers to the user plane security protection level of the terminal device, and the terminal device level includes: level 1, level 2, and level 3, etc. Each terminal device level corresponds to a user plane security policy. As the terminal device level of the terminal device changes, the user plane security policy of all service data flows of the terminal device also needs to change. For example, when the terminal device level is level 1, the corresponding user plane security policy includes: no user plane encryption protection and no user plane integrity protection; when the terminal device level is level 2, the corresponding user plane security policy includes: recommended user plane encryption protection and recommended user plane integrity protection; when the terminal device level is level 3, the corresponding user plane security policy includes: user plane encryption protection and user plane integrity protection are required. When the terminal device level changes, the unified data management network element sends the subscription data corresponding to the terminal device to the session management function network element and notifies the session management function network element that the terminal device level of the terminal device has changed, for example, the terminal device level of the terminal device changes from level 1 to level 2. The session management function network element determines that the level of the terminal device changes from level 1 to level 2 according to the notification from the unified data management function network element. The session management function network element determines the user plane security policy corresponding to the level 2 of the terminal device from the subscription data of the terminal device from the unified data management network element according to the level of the terminal device. Then the session management function network element instructs the access network device to perform corresponding user plane security protection on all QoS flows corresponding to the terminal device according to the user plane security policy corresponding to the level 2.

[0321] Or, in another example, the subscription data includes a user plane security policy corresponding to a service level. Illustratively, the service level refers to the user plane security protection level of the service, and the service level includes: level 1, level 2, and level 3. Each service level corresponds to a user plane security policy. As the service level of the service in the terminal device changes, the user plane security policy of the service data flow corresponding to the service also needs to change. For example, the service level is level 1, and the corresponding user plane security policy includes: no user plane encryption protection and no user plane integrity protection; the service level is level 2, and the corresponding user plane security policy includes: recommended user plane encryption protection and recommended user plane integrity protection; the service level is level 3, and the corresponding user plane security policy includes: user plane encryption protection and user plane integrity protection are required. After the service level changes, the unified data management network element sends the subscription data corresponding to the terminal device to the session management function network element, and the unified data management network element notifies the session management function network element that the service level of the service of the terminal device has changed; the session management function network element determines that the service level of the service in the terminal device has changed, such as the service level of service #1 of the terminal device changes from level 1 to level 2, according to the notification of the unified data management network element. The session management function network element determines the user plane security policy corresponding to the service level of level 2 from the subscription data of the terminal device from the unified data management network element. Then the session management function network element instructs the access network device to perform user plane security protection on all QoS flows of the service data flow corresponding to service #1 in the terminal device according to the user plane security policy corresponding to level 2.

[0322] In combination with the foregoing embodiments, the present application also proposes other implementation solutions. For ease of understanding, please refer to Figure 6 , Figure 6 Another embodiment flow diagram of a communication method proposed by the embodiments of the present application. The communication method proposed by the embodiments of the present application includes:

[0323] G1, the session management function network element acquires the current network state.

[0324] In step G1, the session management function network element acquires notification information, which comes from any one or more of the following network functions or devices, including but not limited to: access and mobility management function AMF, access network device RAN, policy control function network element PCF, network manager, or terminal device, the network manager is used to manage the above network functions. Then, the session management function network element determines the current network state according to the notification information.

[0325] The network state includes but is not limited to: the network returns to normal, or the network occurs abnormally. Further, the network state is the network security capability, and the network state includes: the network security capability is improved or the network security capability is reduced.

[0326] The network returns to normal includes, but is not limited to, that the network congestion is recovered, the service resource provided by the network is improved, and / or the network function in the network returns to normal. Exemplarily, the service resource provided by the network can be a security protection function provided by the network, and the service resource provided by the network is improved can be that the network increases the network function related to the security protection function. The network function in the network returns to normal can be that the network function related to the security protection function in the network is recovered from an abnormal state to a normal state.

[0327] The network is abnormal includes, but is not limited to, that the network is congested, a natural disaster occurs in the region where the network is deployed, the service resource provided by the network is reduced, and / or the network function in the network is faulty. Exemplarily, the service resource provided by the network is reduced can be that the network closes part of the network function related to the security protection function, or the network function related to the security protection function in the network is offline. The network function in the network is faulty can be that the network function related to the security protection function in the network changes from a normal state to a faulty state.

[0328] G2, the session management function network element determines the second user plane security policy corresponding to the network state according to the network state.

[0329] In step G2, one possible implementation manner is that the session management function network element determines that the network security capability is improved according to the network state. In response to the network security capability being improved, the session management function network element determines the second user plane security policy. The security protection capability of the second user plane security policy is higher than that of the first user plane security policy, and the first user plane security policy is the user plane security policy adopted by the QoS flow before the network state changes. For example, the network function related to the security protection function is newly online in the network, and then the network security capability is improved. Then, the session management function network element determines the corresponding second user plane security policy according to the network state in response to the network security capability being improved.

[0330] Another possible implementation manner is that the session management function network element determines that the network security capability is reduced according to the network state. In response to the network security capability being reduced, the session management function network element determines the second user plane security policy. The security protection capability of the second user plane security policy is lower than that of the first user plane security policy, and the first user plane security policy is the user plane security policy adopted by the QoS flow before the network state changes. For example, part of the network function related to the security protection function is offline in the network, and then the network security capability is reduced. Then, the session management function network element determines the corresponding second user plane security policy according to the network state in response to the network security capability being reduced.

[0331] Further, the session management function network element determines the second user plane security policy corresponding to the network state according to the network state, including multiple implementation manners. Specifically as follows:

[0332] (1) The subscription data includes the correspondence between the network state and the user plane security policy. The session management function network element determines the user plane security policy corresponding to the network state from the subscription data as the second user plane security policy according to the network state.

[0333] (2) The PCC rule includes the correspondence between the network state and the user plane security policy. The session management function network element determines the user plane security policy corresponding to the network state from the PCC rule as the second user plane security policy according to the network state.

[0334] (3) The local configuration policy includes the correspondence between the network state and the user plane security policy. The session management function network element determines the user plane security policy corresponding to the network state from the local configuration policy as the second user plane security policy according to the network state.

[0335] Next, taking the session management function network element determining the user plane security policy corresponding to the network state from the local configuration policy as an example for description.

[0336] In an example, the local configuration policy includes the correspondence between the network security capability and the user plane security policy, for example: the network security capability X1 corresponds to the user plane security policy Y1; the network security capability X2 corresponds to the user plane security policy Y2; the network security capability X3 corresponds to the user plane security policy Y3. The notification information indicates the network security capability, and the session management function network element determines the user plane security policy corresponding to the current network security capability according to the network security capability indicated by the notification information and the configuration policy. Further, the session management function network element adopts the user plane security policy corresponding to the current network security capability to perform the user plane integrity protection and / or the user plane encryption protection on the QoS flow. For example, when the notification information indicates that the network security capability is X1, the QoS flow adopts the user plane security policy Y1; when the notification information indicates that the network security capability is X2, the QoS flow adopts the user plane security policy Y2; when the notification information indicates that the network security capability is X3, the QoS flow adopts the user plane security policy Y3.

[0337] In another example, after the network function or device in the network perceives that the network security capability changes, the network function or device sends a notification information to the session management function network element to notify the session management function network element that the current network security capability changes, and the session management function network element needs to adjust the user plane security policy of the QoS flow. The notification information indicates the degree of change of the user plane security policy of the first QoS flow. For example, the PCF perceives that the current network security capability changes from X1 to X2, and the PCF sends a notification information to the session management function network element, which indicates that the user plane security policy of the first QoS flow needs to be changed from the user plane security policy Y1 to the user plane security policy Y2. In another example, the PCF perceives that the current network security capability changes from X1 to X2, and the PCF sends a notification information to the session management function network element, which indicates that the user plane security policy of the first QoS flow is the user plane security policy Y2.

[0338] Exemplarily, the level of the network security capability X1 is higher than the level of the network security capability X2, the level of the network security capability X2 is higher than the level of the network security capability X3, the security of the user plane security policy Y1 is higher than the security of the user plane security policy Y2, and the security of the user plane security policy Y2 is higher than the security of the user plane security policy Y3. For example, the user plane security policy Y1 is that the QoS flow needs to be protected by the user plane integrity and the QoS flow needs to be protected by the user plane encryption, the user plane security policy Y2 is that the QoS flow is recommended to be protected by the user plane integrity and the QoS flow is recommended to be protected by the user plane encryption, and the user plane security policy Y3 is that the QoS flow does not need to be protected by the user plane integrity and the QoS flow does not need to be protected by the user plane encryption.

[0339] G3, if the second user plane security policy is inconsistent with the first user plane security policy, the session management function network element instructs the access network device to protect the first QoS flow by the second user plane security policy, the first QoS flow carrying the service data flow.

[0340] G4, the access network device receives the second user plane security policy and the QoS flow identifier of the first QoS flow from the session management function network element, and determines the first DRB corresponding to the first QoS flow in the session and the user plane security activation state of the first DRB according to the second user plane security policy and the QoS flow identifier of the first QoS flow.

[0341] G5, the access network device notifies the terminal device that the user plane security policy of the first DRB is the second user plane security policy.

[0342] Steps G3 to G5 are similar to steps S6 to S8 in the foregoing embodiments, and will not be described here.

[0343] In the embodiments of the present application, after the session management function network element obtains the network state, the second user plane security policy corresponding to the network state is determined. In the case that the second user plane security policy is inconsistent with the user plane security policy of the session of the terminal device carrying the service data flow, the session management function network element instructs the access network device to perform user plane security protection on the first QoS flow according to the second user plane security policy, and the first QoS flow carries the service data flow. By adopting the method provided in the above embodiments, differentiated user plane security protection is realized for the service data carried by the session, and differentiated user plane security policy is adopted for the service data flow corresponding to the service data to perform user plane security protection, thereby improving the user plane security protection performance and meeting the security requirements of different services. In addition, when the user plane security policy of the session is different from the user plane security policy of the QoS flow, the SMF can also instruct each network function or the terminal device to modify the user plane security policy of the QoS flow, so as to ensure that the core network, the access network and the terminal adopt the same user plane security policy for the same QoS flow.

[0344] In combination with the foregoing embodiments, the present application also provides other implementation solutions. For ease of understanding, please refer to the following Figure 7 , Figure 7 Another embodiment flow diagram of a communication method provided by the present application is provided. The communication method provided by the present application comprises:

[0345] H1, the UE sends a session establishment request to the AMF, the session establishment request is used to request to establish a first session, and the session establishment request comprises a first session identifier and a second session identifier.

[0346] In step H1, the UE sends a session establishment request to the AMF, the session establishment request is used to request to establish a first session, and the session establishment request comprises a first session identifier and a second session identifier, and the first session identifier is inconsistent with the second session identifier. The first session corresponds to the first session identifier.

[0347] Optionally, in the case that the UE supports the MPQUIC capability, the UE includes the first session identifier and the second session identifier in the session establishment request sent to the AMF.

[0348] Exemplarily, the session establishment request is a "PDU Session Establishment Request" message.

[0349] H2, the SMF selects and sends a session management context creation / update request.

[0350] In step H2, the AMF triggers selection of a suitable SMF in response to the session establishment request. The AMF then sends a session management context creation / update request to the selected SMF for requesting establishment of a first session (corresponding to the first session identity) and a second session (corresponding to the second session identity). That is, the AMF sends an "Nsmf_PDUSession_CreateSMContextRequest" message to the SMF.

[0351] H3, obtaining session management subscription data from the UDM, checking the legality of the request.

[0352] Step H3 is an optional step. In step H3, the SMF obtains session management subscription data from the UDM, the session management subscription data including: subscription retrieval / subscription for updates information. By querying the session management subscription data, it is determined whether the MAPDU session (e.g., the first session is a MAPDU session) can be created according to the query result.

[0353] The SMF is also configured to query SMF query subscription data and PCC rules, and determine whether the MAPDU session can be created according to the query result. The subscription data includes the relevant data of the UE, and the relevant data of the UE in the subscription data can also be referred to as the subscription data of the UE.

[0354] H4, the SMF obtains the PCC rules and generates ATSSS rules and / or N4 rules according to the PCC rules, and distributes the ATSSS rules and / or N4 rules to the RAN, the UE and the UPF. After the SMF receives the PCC rules, it derives from the received PCC rules (a) ATSSS rules, which will be sent to the UE for controlling traffic layering, switching and splitting in the uplink direction; (b) N4 rules, which will be sent to the UPF for controlling traffic layering, switching and splitting in the downlink direction. After the SMF derives the N4 rules for the session (MAPDU session), the N4 rules are sent to the UPF.

[0355] Step H4 is an optional step.

[0356] H5, the SMF obtains the user plane security policy of the QoS flow.

[0357] In step H5, the SMF determines the QoS flow corresponding to the session establishment request according to the session establishment request. Then the SMF determines the user plane security policy of the QoS flow. For example, the SMF determines that the user plane security policy of the first QoS flow is the first user plane security policy. For another example, the SMF determines that the PDU session corresponding to the session establishment request includes multiple QoS flows, and the user plane security policies of the multiple QoS flows are the first user plane security policy and the second user plane security policy, and the second user plane security policy is inconsistent with the first user plane security policy.

[0358] As to how the SMF determines the user plane security policy of the first QoS flow, it is similar to the foregoing steps S4-S5, or similar to the foregoing steps G1-G2, which will not be described herein.

[0359] In step H5, if it is determined that the multiple QoS flows adopt the first user plane security policy and the second user plane security policy, step H6 is entered, and the SMF creates a first session and a second session. The first session carries the QoS flow adopting the first user plane security policy, and the first session adopts the first user plane security policy. The QoS flow adopting the second user plane security policy is carried in the second session, and the second session adopts the second user plane security policy. Or the first session carries the QoS flow adopting the second user plane security policy, and the first session adopts the second user plane security policy. The QoS flow adopting the second user plane security policy is carried in the first session, and the second session adopts the first user plane security policy. If it is determined that the user plane security policies of the multiple QoS flows are all the first user plane security policy, the SMF only needs to create the first session, and the first session carries the QoS flow.

[0360] H6, the SMF creates a first session and a second session, the first session corresponds to a first session identifier, and the second session corresponds to a second session identifier. The first session carries the QoS flow adopting the first user plane security policy, and the user plane security policy of the first session is the first user plane security policy.

[0361] In step H6, if the first session is a MA PDU session, the SMF creates the first session and the second session in response to the session establishment request in step H1. The first session corresponds to a first session identifier, and the second session corresponds to a second session identifier. The first session uses the first user plane security policy, and the second session adopts the second user plane security policy. The first session carries the QoS flow adopting the first user plane security policy.

[0362] Exemplarily, the first session carries MPQUIC data packets, and the second session carries MPTCP data packets and ATSSS data packets.

[0363] For another example, the first session carries an application data stream of XR / VR service, and the second session carries an application data stream of a video application.

[0364] H7. The SMF sends the session and the user plane security policy for the session to the RAN and the UPF.

[0365] In step H7, the SMF sends the first session and the first user plane security policy for the first session, the second session and the second user plane security policy for the second session to the RAN and the UPF respectively.

[0366] In a possible implementation, the SMF can send by, for example: message #1 includes the first session identifier and the first user plane security policy for the first session; message #2 includes the second session identifier and the second user plane security policy for the second session. Correspondingly, the RAN receives the message #1 and the message #2, and the UPF receives the message #1 and the message #2.

[0367] In another possible implementation, the SMF can send by, for example: message #1 includes the first session identifier and the first user plane security policy for the first session, and the second session identifier and the second user plane security policy for the second session. Correspondingly, the RAN receives the message #1, and the UPF receives the message #1.

[0368] H8. The RAN allocates DRBs for the QoS flows in the session according to the session and the security policy for the session.

[0369] In step H8, in response to step H7, the RAN allocates DRBs for the QoS flows in the first session, and the DRBs use the first user plane security policy; the RAN allocates DRBs for the QoS flows in the second session, and the DRBs use the second user plane security policy.

[0370] H9. The RAN sends the session and the security policy for the session to the UE.

[0371] In step H9, the RAN sends the first session and the first user plane security policy for the first session, the second session and the second user plane security policy for the second session to the UE.

[0372] In a possible implementation, the RAN can send by, for example: message #1 includes the first session identifier and the first user plane security policy for the first session; message #2 includes the second session identifier and the second user plane security policy for the second session. Correspondingly, the UE receives the message #1 and the message #2.

[0373] In another possible implementation, the RAN can send, for example, by the following way: the message #1 includes a first session identity and a first user plane security policy used by the first session, and a second session identity and a second user plane security policy used by the second session. Correspondingly, the UE receives the message #1.

[0374] It can be understood that the RAN can also implement the user plane security activation in other ways. For example, the RAN sends the corresponding user plane security policy to the UE for the DRB corresponding to the session.

[0375] H10, the UE executes the security policy of the PDU session.

[0376] In step H10, the UE executes the first user plane security policy for the first session and executes the second user plane security policy for the second session.

[0377] In the embodiments of the present application, after determining that the user plane security policy corresponding to the QoS flow is the first user plane security policy, the SMF establishes two PDU sessions respectively, and the two PDU sessions respectively carry the traffic corresponding to the first user plane security policy and other traffic. The PDU session carrying the traffic corresponding to the first user plane security policy uses the first user plane security policy for user plane security protection. Thus, the user plane security policy of the QoS flow granularity is realized.

[0378] In combination with the foregoing embodiments, the following introduces various application scenarios proposed by the embodiments of the present application, specifically including:

[0379] I. The terminal device triggers a session modification request, and the SMF modifies the user plane security policy corresponding to the QoS flow.

[0380] Exemplarily, please refer to Figure 8 , Figure 8 The following is a schematic diagram of one application scenario in the embodiments of the present application. The application scenario proposed by the embodiments of the present application includes:

[0381] J1, the UE sends a session modification request, and the session modification request carries feature information of a service data flow.

[0382] In step J1, the UE sends a session modification request to the SMF, and the session modification request carries feature information of a service data flow. For details, please refer to the foregoing step S4, which will not be repeated here.

[0383] J2, the session management function network element determines a second user plane security policy corresponding to the service data flow according to the feature information of the service data flow.

[0384] J3, if the second user plane security policy is inconsistent with the first user plane security policy, the session management function network element instructs the access network device to perform user plane security protection on the first QoS flow according to the second user plane security policy, the first QoS flow carrying the service data flow.

[0385] J4, the access network device receives the second user plane security policy and the QoS flow identifier of the first QoS flow from the session management function network element, and determines the first DRB corresponding to the first QoS flow in the session and the user plane security activation state of the first DRB according to the second user plane security policy and the QoS flow identifier of the first QoS flow.

[0386] J5, the access network device notifies the terminal device that the user plane security policy of the first DRB is the second user plane security policy.

[0387] Steps J2 to J5 are similar to the aforementioned steps S5 to S8, which will not be repeated here.

[0388] II. PCF triggers session modification request, SMF modifies QoS flow corresponding user plane security policy.

[0389] Exemplarily, please refer to Figure 9 , Figure 9 for a schematic diagram of an application scenario in the embodiments of the present application. The application scenario proposed in the embodiments of the present application includes:

[0390] K1, PCF session management policy association modification process, in which the PCF sends the characteristic information of the service data flow to the SMF.

[0391] In step K1, in the PCF session management policy association modification process "PCF initated SM Policy Association Modification", the SMF obtains the characteristic information of the service data flow sent by the PCF, or the PCF sends the characteristic information of the service data flow to the SMF. Optionally, the above-mentioned PCF session management policy association modification process can be triggered by the AF. For details, please refer to the aforementioned step S4, which will not be repeated here.

[0392] K2, the session management function network element determines the second user plane security policy corresponding to the service data flow according to the characteristic information of the service data flow.

[0393] K3, if the second user plane security policy is inconsistent with the first user plane security policy, the session management function network element instructs the access network device to perform user plane security protection on the first QoS flow according to the second user plane security policy, the first QoS flow carrying the service data flow.

[0394] K4, the access network device receives the second user plane security policy and the QoS flow identifier of the first QoS flow from the session management function network element, and determines the first DRB corresponding to the first QoS flow in the session and the user plane security activation state of the first DRB according to the second user plane security policy and the QoS flow identifier of the first QoS flow.

[0395] K5, the access network device notifies the terminal device that the user plane security policy of the first DRB is the second user plane security policy.

[0396] Steps K2 to K5 are similar to the foregoing steps S5 to S8, and are not described here.

[0397] III. The UDM triggers a session modification request, and the SMF modifies the user plane security policy corresponding to the QoS flow.

[0398] Exemplarily, refer to Figure 10 , Figure 10 An application scenario is shown in the embodiment of the present application. The application scenario proposed in the embodiment of the present application includes:

[0399] Option (1):

[0400] L1-1, send subscription data including feature information of a service data flow.

[0401] In step L1-1, the subscription data changes, and the UDM sends the subscription data to the SMF, the subscription data including the feature information of the service data flow. Exemplarily, the subscription data includes UE-related data, and the UE-related data includes the feature information of the service data flow of the UE. After the terminal device-related data included in the subscription data changes, the UDM sends the updated subscription data to the session management function network element. Alternatively, the session management function network element actively acquires the subscription data from the UDM, for example, the session management function network element periodically sends the identification information of the UE to the UDM, and the UDM sends the subscription data to the session management function network element in response to the identification information of the UE.

[0402] For details, refer to the foregoing step S4, which is not described here.

[0403] L2-1, the session management function network element determines the second user plane security policy corresponding to the service data flow according to the feature information of the service data flow.

[0404] For details, refer to the foregoing step S5, which is not described here. Step L3 is performed after step L2-1.

[0405] Option (2):

[0406] L1-2, send subscription data including a user plane security policy.

[0407] The subscription data changes, and the UDM sends the subscription data to the SMF, the subscription data including a user plane security policy.

[0408] For details, please refer to the foregoing step S4, which will not be repeated here.

[0409] L2-2, the session management function network element determines a second user plane security policy according to the user plane security policy included in the subscription data.

[0410] For details, please refer to the foregoing step S5, which will not be repeated here. Step L3 is performed after step L2-2.

[0411] L3, if the second user plane security policy is inconsistent with the first user plane security policy, the session management function network element instructs the access network device to perform user plane security protection on the first QoS flow according to the second user plane security policy, the first QoS flow carrying the service data flow.

[0412] L4, the access network device receives the second user plane security policy and the QoS flow identifier of the first QoS flow from the session management function network element, and determines the first DRB corresponding to the first QoS flow in the session and the user plane security activation state of the first DRB according to the second user plane security policy and the QoS flow identifier of the first QoS flow.

[0413] L5, the access network device notifies the terminal device that the user plane security policy of the first DRB is the second user plane security policy.

[0414] Steps L3 to L5 are similar to the foregoing steps S6 to S8, which will not be repeated here.

[0415] The above describes the present application from the perspective of a method, and the following further describes other embodiments provided by the present application.

[0416] Please refer to Figure 11 An implementation schematic diagram of a communication device provided by the present application is shown in the figure, which includes a processing module 1101 and a transceiver module 1102. The communication device 1100 can realize the functions of the communication device (including the session management function network element and the access network device, etc.) in the above-mentioned method embodiments, and thus can also realize the beneficial effects possessed by the above-mentioned method embodiments. In the embodiments of the present application, the communication device 1100 can be a session management function network element, or an integrated circuit or element inside the session management function network element, such as a chip. The following embodiments take the communication device 1100 as a session management function network element for example.

[0417] In one possible example,

[0418] The transceiver module 1102 is configured to receive a session establishment request message from a terminal device, the session establishment request message being used to request establishment of a session; the transceiver module 1102 is also configured to, in response to the session establishment request message, acquire a first user plane security policy corresponding to the session, the first user plane security policy being used to indicate whether to activate user plane security protection corresponding to the session; the transceiver module 1102 is also configured to send the first user plane security policy and an identifier used to indicate the session to an access network device; the transceiver module 1102 is also configured to acquire feature information of a service data flow of the terminal device, the service data flow being carried in the session and being used to transmit service data of the terminal device; the processing module 1101 is configured to determine a second user plane security policy corresponding to the service data flow according to the feature information of the service data flow, the second user plane security policy being used to indicate whether to activate user plane security protection corresponding to the service data flow; and the transceiver module 1102 is also configured to, in a case where the first user plane security policy and the second user plane security policy are inconsistent, send the second user plane security policy and a QoS flow identifier of a first QoS flow to the access network device, the QoS flow identifier of the first QoS flow being used to indicate the first QoS flow in the session that is used to carry the service data flow.

[0419] Optionally, the transceiver module 1102 is also configured to receive a session modification request message from the terminal device, the session modification request message being used to request modification of the session, and the session modification request message including the feature information of the service data flow.

[0420] Optionally, the transceiver module 1102 is also configured to receive a message used to request update of policy information of the session from a policy control function network element, and the message used to request update of the policy information of the session including the feature information of the service data flow.

[0421] Optionally, the transceiver module 1102 is also configured to receive subscription data of the terminal device from a unified data management network element, and the subscription data including the feature information of the service data flow.

[0422] Optionally, the processing module 1101 is also configured to determine whether the service data flow is carried in the session; and the transceiver module 1102 is also configured to, in a case where it is determined that the service data flow is carried in the session, acquire the first user plane security policy.

[0423] Optionally, the transceiver 1102 is further configured to send, to a unified data management network element, a message for requesting subscription data of the terminal device; the transceiver 1102 is further configured to receive, from the unified data management network element, the subscription data of the terminal device, the subscription data comprising a correspondence between characteristic information of a service data flow and a user plane security policy; and the processor 1101 is further configured to determine, according to the subscription data, the second user plane security policy corresponding to the characteristic information of the service data flow.

[0424] Optionally, the transceiver 1102 is further configured to send, to a unified data management network element, a message for requesting a user plane security policy corresponding to characteristic information of a service data flow; and the transceiver 1102 is further configured to receive, from the unified data management network element, the second user plane security policy.

[0425] Optionally, the transceiver 1102 is further configured to receive, from a policy control function network element, a policy and charging control rule comprising a correspondence between characteristic information of a service data flow and a user plane security policy; and the processor 1101 is further configured to determine, according to the policy and charging control rule, the second user plane security policy corresponding to the characteristic information of the service data flow.

[0426] Optionally, the processor 1101 is further configured to determine, according to a locally configured policy, the second user plane security policy corresponding to characteristic information of a service data flow.

[0427] Optionally, the processor 1101 is further configured to create the first QoS flow, and determine a quality of service parameter of the first QoS flow according to a quality of service requirement of the service data flow; and the transceiver 1102 is further configured to send, to the access network device, the second user plane security policy, a QoS flow identifier of the first QoS flow, and the quality of service parameter of the first QoS flow.

[0428] Optionally, the processor 1101 is further configured to determine, from one or more QoS flows in the session, a QoS flow satisfying a first condition as the first QoS flow, the first condition comprising: a quality of service parameter of the QoS flow matching a quality of service requirement of the service data flow, and a user plane security policy corresponding to a service data flow carried by the QoS flow being consistent with the second user plane security policy.

[0429] Optionally, the characteristic information of the service data flow includes indication information used for indicating an application layer security activation state of the service data flow; in a case where the indication information indicates that the service data flow has been encrypted at an application layer and the first user plane security policy includes that user plane encryption needs to be activated, the second user plane security policy includes that user plane encryption does not need to be started; and / or in a case where the indication information indicates that the service data flow has been integrity protected at an application layer and the first user plane security policy includes that user plane integrity protection needs to be activated, the second user plane security policy includes that user plane integrity protection does not need to be started.

[0430] Optionally, the characteristic information of the service data flow includes a protocol used by the terminal device to transmit the service data flow; in a case where the protocol is a quick user datagram protocol internet connection (QUIC) protocol or a multi-path QUIC protocol and the first user plane security policy includes that user plane encryption needs to be started, the second user plane security policy includes that user plane encryption does not need to be started.

[0431] In another possible implementation, the transceiver 1102 is further configured to receive, from a session management function network element, a first user plane security policy corresponding to a session of a terminal device and an identifier used for indicating the session, the first user plane security policy being used for indicating whether user plane security protection corresponding to the session is activated; and the processor 1101 is further configured to determine, according to the first user plane security policy, whether user plane security protection of a data radio bearer (DRB) belonging to the session is activated.

[0432] The transceiver 1102 is further configured to receive, from the session management function network element, a second user plane security policy and a QoS flow identifier of a first QoS flow, the second user plane security policy being used for indicating whether user plane security protection corresponding to the service data flow is activated, and the QoS flow identifier of the first QoS flow being used for indicating the first QoS flow in the session used for carrying the service data flow; and the processor 1101 is further configured to determine, according to the second user plane security policy and the QoS flow identifier of the first QoS flow, a first DRB corresponding to the first QoS flow in the session and a user plane security activation state of the first DRB.

[0433] Optionally, the processing module 1101 is further configured to determine, according to the QoS flow identifier of the first QoS flow, that the first QoS flow is newly established; the processing module 1101 is further configured to create the first DRB, and determine the user plane security activation state of the first DRB according to the second user plane security policy; or determine, from the one or more DRBs of the session, that a DRB satisfying a second condition is the first DRB, the second condition comprising that the user plane security activation state of the DRB is determined according to the second user plane security policy.

[0434] Optionally, the processing module 1101 is further configured to determine, according to the QoS flow identifier of the first QoS flow, that the first QoS flow satisfies the following conditions: 1) the first QoS flow is established before the reception of the second user plane security policy and the QoS flow identifier of the first QoS flow from the session management function network element, and 2) the first QoS flow corresponds to a second DRB, and the number of QoS flows corresponding to the second DRB is greater than 1; the processing module 1101 is further configured to create the first DRB, and determine the user plane security activation state of the first DRB according to the second user plane security policy; or the processing module 1101 is further configured to determine, from the one or more DRBs of the session, that a DRB satisfying a second condition is the first DRB, the second condition comprising that the user plane security activation state of the DRB is determined according to the second user plane security policy.

[0435] Optionally, the processing module 1101 is further configured to determine, according to the QoS flow identifier of the first QoS flow, that the first QoS flow satisfies the following conditions: 1) the first QoS flow is established before the reception of the second user plane security policy and the QoS flow identifier of the first QoS flow from the session management function network element, and 2) the first QoS flow corresponds to the first DRB, and the number of QoS flows corresponding to the first DRB is equal to 1; the processing module 1101 is further configured to update the user plane security activation state of the first DRB according to the second user plane security policy.

[0436] Optionally, the transceiver 1102 is further configured to send, to the terminal device, user plane security indication information corresponding to the first DRB, the user plane security indication information being used to indicate whether to activate user plane security protection of the first DRB, and the user plane security indication information being determined according to the second user plane security policy.

[0437] Please refer to Figure 12 Another schematic structural diagram of the communication apparatus 1200 provided in the present application is shown, and the communication apparatus 1200 at least includes an input / output interface 1202. The communication apparatus 1200 can be a chip or an integrated circuit.

[0438] Optionally, the communication apparatus further includes a logic circuit 1201.

[0439] wherein, Figure 11 The transceiver module 1102 shown can be a communication interface, which can be Figure 12 The input and output interface 1202 can include an input interface and an output interface. Alternatively, the communication interface can also be a transceiver circuit, which can include an input interface circuit and an output interface circuit.

[0440] Optionally, in the case of the session management function network element (or components in the session management function network element) in the foregoing embodiments, the input and output interface 1202 is configured to input and output information, and the logic circuit 1201 is configured to perform the method performed by the session management function network element in the foregoing Figures 3-10 and related embodiments.

[0441] Optionally, in the case of the access network device (or components in the access network device) in the foregoing embodiments, the input and output interface 1202 is configured to input and output information, and the logic circuit 1201 is configured to perform the method performed by the access network device in the foregoing Figures 3-10 and related embodiments.

[0442] The logic circuit 1201 and the input and output interface 1202 can also perform other steps performed by the communication apparatus in any embodiment and achieve corresponding beneficial effects, which will not be described here.

[0443] In a possible implementation manner, Figure 11 The processing module 1101 shown can be a logic circuit 1201 in the Figure 12

[0444] Optionally, the logic circuit 1201 can be a processing apparatus, and the functions of the processing apparatus can be partially or entirely implemented through software. The functions of the processing apparatus can be partially or entirely implemented through software.

[0445] Optionally, the processing apparatus can include a memory and a processor, where the memory is configured to store a computer program, and the processor is configured to read and execute the computer program stored in the memory to perform the corresponding processing and / or steps in any one of the method embodiments.

[0446] Optionally, the processing apparatus can only include the processor. The memory for storing the computer program is located outside the processing apparatus, and the processor is connected with the memory through a circuit / wire to read and execute the computer program stored in the memory. The memory and the processor can be integrated together or can be physically independent of each other.

[0447] ​Optionally, the processing device can be one or more chips, or one or more integrated circuits. For example, the processing device can be one or more field-programmable gate arrays (FPGA), application specific integrated circuits (ASIC), system on chips (SoC), central processor units (CPU), network processors (NP), digital signal processors (DSP), microcontroller units (MCU), programmable logic devices (PLD), or other integrated circuits, or any combination of the above chips or processors, etc.

[0448] Referring to Figure 13 The communication device 1300 involved in the above embodiments provided for the embodiments of the present application, and the communication device 1300 can be specifically the communication device in the above embodiments as a session management function network element.

[0449] A possible logical structure diagram of the communication device 1300 can include but is not limited to at least one processor 1301 and a communication port 1302.

[0450] Further optionally, the device can further include at least one of a memory 1303 and a bus 1304. In the embodiments of the present application, the at least one processor 1301 is configured to control and process the actions of the communication device 1300.

[0451] In addition, the processor 1301 can be a central processor unit, a general processor, a digital signal processor, an application specific integrated circuit, a field-programmable gate array, or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It can implement or execute various exemplary logical blocks, modules and circuits described in combination with the disclosure of the present application. The processor can also be a combination of computing functions, such as one or more microprocessor combinations, combinations of digital signal processors and microprocessors, etc. Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described system, device and unit can refer to the corresponding processes in the foregoing method embodiments, which will not be described here.

[0452] It should be noted that, Figure 13The communication apparatus 1300 shown can be specifically used to implement the steps implemented by the session management function network element in the foregoing method embodiments, and achieve the technical effects corresponding to the session management function network element. Figure 13 The specific implementation of the communication apparatus can be referred to the description in the foregoing method embodiments, which will not be repeated here.

[0453] Please refer to Figure 14 The foregoing structure of the communication apparatus 1400 involved in the embodiments of the present application is shown in the structure diagram of the communication apparatus 1400, which can be specifically the communication apparatus as the access network device in the foregoing embodiments. The structure of the communication apparatus can be referred to the structure shown in the foregoing embodiments. Figure 14 The structure shown.

[0454] The communication apparatus 1400 includes at least one processor 1401 and at least one network interface 1404. Further optionally, the communication apparatus further includes at least one memory 1402, at least one transceiver 1403 and one or more antennas 1405. The processor 1401, the memory 1402, the transceiver 1403 and the network interface 1404 are connected, for example, through a bus, which in the embodiments of the present application can include various types of interfaces, transmission lines or buses, etc., which are not limited in the embodiments. The antenna 1405 is connected to the transceiver 1403. The network interface 1404 is used for the communication apparatus to communicate with other communication devices through a communication link. For example, the network interface 1404 can include the network interface between the communication apparatus and the core network device, such as the S4 interface, and the network interface can include the network interface between the communication apparatus and other communication apparatuses (such as other access network devices or core network devices), such as the X2 or Xn interface.

[0455] The processor 1401 is mainly used for processing communication protocols and communication data, and controlling the whole communication apparatus, executing software programs, processing data of software programs, such as for supporting the communication apparatus to perform the actions described in the embodiments. The communication apparatus can include a baseband processor and a central processor, the baseband processor is mainly used for processing communication protocols and communication data, and the central processor is mainly used for controlling the whole terminal device, executing software programs, and processing data of software programs. Figure 14The processor 1401 in the terminal device can integrate the functions of a baseband processor and a central processor. Those skilled in the art can understand that the baseband processor and the central processor can also be independent processors, and are interconnected through a bus or the like. Those skilled in the art can understand that the terminal device can include multiple baseband processors to accommodate different network systems, and the terminal device can include multiple central processors to enhance the processing capability. The various components of the terminal device can be connected through various buses. The baseband processor can also be referred to as a baseband processing circuit or a baseband processing chip. The central processor can also be referred to as a central processing circuit or a central processing chip. The functions of processing communication protocols and communication data can be built into the processor, or the functions can be stored in the memory in the form of software programs, and the processor executes the software programs to implement the baseband processing functions.

[0456] The memory is mainly used for storing software programs and data. The memory 1402 can exist independently and be connected with the processor 1401. Alternatively, the memory 1402 can be integrated with the processor 1401, for example, in a chip. The memory 1402 can store program codes for executing the technical solutions of the embodiments of the present application, and the processor 1401 controls the execution. The executed computer programs of various types can also be regarded as a driver of the processor 1401.

[0457] Figure 14 Only one memory and one processor are shown. In an actual terminal device, multiple processors and multiple memories can exist. The memory can also be referred to as a storage medium or a storage device, etc. The memory can be a storage element on the same chip as the processor, that is, an on-chip storage element, or an independent storage element, and the embodiments of the present application do not limit this.

[0458] The transceiver 1403 can be configured to support the receiving or transmitting of radio frequency signals between the communication device and a terminal. The transceiver 1403 can be connected to the antenna 1405. The transceiver 1403 includes a transmitter Tx and a receiver Rx. Specifically, one or more antennas 1405 can receive radio frequency signals, the receiver Rx of the transceiver 1403 is configured to receive the radio frequency signals from the antenna and convert the radio frequency signals into digital baseband signals or digital intermediate frequency signals, and provide the digital baseband signals or digital intermediate frequency signals to the processor 1401 for further processing, such as demodulation processing and decoding processing, by the processor 1401. In addition, the transmitter Tx in the transceiver 1403 is also configured to receive modulated digital baseband signals or digital intermediate frequency signals from the processor 1401, and convert the modulated digital baseband signals or digital intermediate frequency signals into radio frequency signals, and transmit the radio frequency signals through one or more antennas 1405. Specifically, the receiver Rx can selectively perform one or more levels of down-mixing and analog-to-digital conversion to obtain digital baseband signals or digital intermediate frequency signals, and the order of the down-mixing and analog-to-digital conversion can be adjustable. The transmitter Tx can selectively perform one or more levels of up-mixing and digital-to-analog conversion to obtain radio frequency signals, and the order of the up-mixing and digital-to-analog conversion can be adjustable. The digital baseband signals and the digital intermediate frequency signals can be collectively referred to as digital signals.

[0459] The transceiver 1403 can also be referred to as a transceiver module, a transceiver, a transceiver device, etc. Optionally, the devices in the transceiver module for implementing the receiving function can be regarded as a receiving unit, and the devices in the transceiver module for implementing the transmitting function can be regarded as a transmitting unit, that is, the transceiver module includes a receiving unit and a transmitting unit. The receiving unit can also be referred to as a receiver, an input port, a receiving circuit, etc., and the transmitting unit can be referred to as a transmitter, a transmitter, or a transmitting circuit, etc.

[0460] It should be noted that, Figure 14 The communication device 1400 shown can be specifically configured to implement the steps implemented by the access network device in the foregoing method embodiments, and achieve the corresponding technical effects of the access network device, Figure 14 The specific implementation of the communication device 1400 shown can be referred to the description in the foregoing method embodiments, which will not be repeated here.

[0461] The embodiments of the present application also provide a computer readable storage medium storing one or more computer execution instructions, when the computer execution instructions are executed by a processor, the processor executes the method of the possible implementation manners of the session management function network element or the access network device in the foregoing embodiments.

[0462] The embodiments of the present application further provide a computer program product (or computer program) storing one or more computers, when the computer program product is executed by the processor, the processor executes the method of the possible implementation manners of the session management function network element or the access network device.

[0463] The embodiments of the present application further provide a chip system, which comprises at least one processor for supporting the communication device to implement the functions involved in the possible implementation manners of the communication device. Optionally, the chip system further comprises an interface circuit for providing the at least one processor with program instructions and / or data. In a possible design, the chip system can further comprise a memory for storing the necessary program instructions and data of the communication device. The chip system can be composed of a chip, or can comprise a chip and other discrete devices, and the communication device can be specifically the session management function network element or the access network device in the foregoing method embodiments.

[0464] The embodiments of the present application further provide a communication system, which comprises the session management function network element and the access network device in any of the foregoing embodiments.

[0465] In several embodiments provided in the present application, it should be understood that the disclosed system, device and method can be implemented in other manners. For example, the device embodiments described above are only schematic; the division of the units is only a logical function division; there can be another division manner for the actual implementation, for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections between the units can be indirect couplings or communication connections through some interfaces, devices or units, and can be electrical, mechanical or in other forms.

[0466] The units described as separated components can or can not be physically separated, and the components displayed as units can or can not be physical units, i.e., can be located in one place, or can be distributed on multiple network units. According to actual needs, some or all of the units can be selected to implement the purposes of the embodiments of the present application.

[0467] In addition, each of the functional units in the various embodiments of the present application can be integrated in one processing module, or each unit can exist physically, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit. When the integrated unit is realized in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application, essentially or in the form of a contribution, or all or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, and includes several instructions for causing a computer device (which can be a personal computer, a server, or an access network device, etc.) to execute all or part of the steps of the methods according to the various embodiments of the present application. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various media that can store program codes.

Claims

1. A communication method characterized by comprising: Applied to a session management function network element, comprising: receiving a session establishment request message from a terminal device, the session establishment request message being used to request to establish a session; in response to the session establishment request message, obtaining a first user plane security policy corresponding to the session, the first user plane security policy being used to indicate whether to activate user plane security protection corresponding to the session; sending the first user plane security policy and an identifier indicating the session to an access network device; obtaining characteristic information of a service data flow of the terminal device, the service data flow being carried in the session and being used to transmit service data of the terminal device; determining a second user plane security policy corresponding to the service data flow according to the characteristic information of the service data flow, the second user plane security policy being used to indicate whether to activate user plane security protection corresponding to the service data flow; in a case where the first user plane security policy and the second user plane security policy are inconsistent, sending the second user plane security policy and a quality of service, QoS, flow identifier of a first QoS flow to the access network device, the QoS flow identifier of the first QoS flow being used to indicate the first QoS flow in the session used to carry the service data flow.

2. The method of claim 1, wherein, The obtaining of the characteristic information of the service data flow of the terminal device comprises: receiving a session modification request message from the terminal device, the session modification request message being used to request to modify the session, and the session modification request message comprising the characteristic information of the service data flow.

3. The method of claim 1, wherein, The obtaining of the characteristic information of the service data flow of the terminal device comprises: receiving a message for requesting to update policy information of the session from a policy control function network element, the message for requesting to update the policy information of the session comprising the characteristic information of the service data flow.

4. The method of claim 1, wherein, The obtaining of the characteristic information of the service data flow of the terminal device comprises: receiving subscription data of the terminal device from a unified data management network element, the subscription data comprising the characteristic information of the service data flow.

5. The method of claim 1, wherein, After the obtaining of the characteristic information of the service data flow of the terminal device, the method further comprises: determining whether the service data flow is carried in the session; in a case where it is determined that the service data flow is carried in the session, obtaining the first user plane security policy.

6. The method of claim 1, wherein, The determining of the second user plane security policy corresponding to the service data flow according to the characteristic information of the service data flow comprises: sending a message for requesting to obtain subscription data of the terminal device to a unified data management network element; receiving subscription data of the terminal device from the unified data management network element, the subscription data comprising a corresponding relationship between characteristic information of a service data flow and a user plane security policy; determining the second user plane security policy corresponding to the characteristic information of the service data flow according to the subscription data.

7. The method of claim 1, wherein, The determining of the second user plane security policy corresponding to the service data flow according to the characteristic information of the service data flow comprises: sending a message for requesting a user plane security policy corresponding to the characteristic information of the service data flow to a unified data management network element; receiving the second user plane security policy from the unified data management network element.

8. The method of claim 1, wherein, The determining the second user plane security policy corresponding to the service data flow according to the characteristic information of the service data flow comprises: receiving a policy and charging control rule from a policy control function network element, the policy and charging control rule comprising a corresponding relationship between characteristic information of a service data flow and a user plane security policy; determining the second user plane security policy corresponding to the characteristic information of the service data flow according to the policy and charging control rule.

9. The method of claim 1, wherein, The determining the second user plane security policy corresponding to the service data flow according to the characteristic information of the service data flow comprises: determining the second user plane security policy corresponding to the characteristic information of the service data flow according to a locally configured policy.

10. The method of claim 1, wherein, Before the sending the second user plane security policy and a QoS flow identifier of a first QoS flow to the access network device, the method further comprises: creating the first QoS flow, and determining a quality of service parameter of the first QoS flow according to a quality of service requirement of the service data flow; The sending the second user plane security policy and a QoS flow identifier of a first QoS flow to the access network device comprises: sending the second user plane security policy, the QoS flow identifier of the first QoS flow, and the quality of service parameter of the first QoS flow to the access network device.

11. The method of claim 1, wherein, Before the sending the second user plane security policy and a QoS flow identifier of a first QoS flow to the access network device, the method further comprises: determining, from one or more QoS flows in the session, a QoS flow satisfying a first condition as the first QoS flow, the first condition comprising: a quality of service parameter of the QoS flow matching a quality of service requirement of the service data flow, and a user plane security policy corresponding to a service data flow carried by the QoS flow being consistent with the second user plane security policy.

12. The method according to any one of claims 1 to 11, characterized in that, The characteristic information of the service data flow comprises indication information, the indication information being used to indicate an application layer security activation state of the service data flow; in a case where the indication information indicates that the service data flow has been encrypted at an application layer and the first user plane security policy comprises user plane encryption needing to be activated, the second user plane security policy comprises user plane encryption not needing to be started; and / or, in a case where the indication information indicates that the service data flow has been integrity protected at an application layer and the first user plane security policy comprises user plane integrity protection needing to be activated, the second user plane security policy comprises user plane integrity protection not needing to be started.

13. The method according to any one of claims 1 to 11, characterized in that, The characteristic information of the service data flow comprises a protocol used by the terminal device to transmit the service data flow; in a case where the protocol is a quick user datagram protocol internet connection (QUIC) protocol or a multi-path QUIC protocol and the first user plane security policy comprises user plane encryption needing to be started, the second user plane security policy comprises user plane encryption not needing to be started.

14. A communication method, comprising: applied to an access network device, comprising: In a process of establishing a session of a terminal device, a first user plane security policy corresponding to the session and an identifier indicating the session are received from a session management function network element, the first user plane security policy being used to indicate whether user plane security protection corresponding to the session is activated; It is determined whether user plane security protection of a data radio bearer (DRB) belonging to the session is activated according to the first user plane security policy; A second user plane security policy and a quality of service (QoS) flow identifier of a first QoS flow are received from the session management function network element, the second user plane security policy being used to indicate whether user plane security protection corresponding to a service data flow is activated, and the QoS flow identifier of the first QoS flow being used to indicate the first QoS flow in the session used to carry the service data flow; A first DRB corresponding to the first QoS flow in the session and a user plane security activation state of the first DRB are determined according to the second user plane security policy and the QoS flow identifier of the first QoS flow.

15. The method of claim 14, wherein, The determining a first DRB corresponding to the first QoS flow in the session and a user plane security activation state of the first DRB according to the second user plane security policy and the QoS flow identifier of the first QoS flow comprises: It is determined that the first QoS flow is newly established according to the QoS flow identifier of the first QoS flow; The first DRB is created, and the user plane security activation state of the first DRB is determined according to the second user plane security policy; or A DRB satisfying a second condition is determined as the first DRB from one or more DRBs of the session, the second condition comprising that the user plane security activation state of the DRB is determined according to the second user plane security policy.

16. The method of claim 14, wherein, The determining a first DRB corresponding to the first QoS flow in the session and a user plane security activation state of the first DRB according to the second user plane security policy and the QoS flow identifier of the first QoS flow comprises: It is determined that the first QoS flow satisfies the following condition according to the QoS flow identifier of the first QoS flow: 1) the first QoS flow has been created before the receiving the second user plane security policy and the QoS flow identifier of the first QoS flow from the session management function network element, 2) the first QoS flow corresponds to a second DRB, and a quantity of QoS flows corresponding to the second DRB is greater than 1; The first DRB is created, and the user plane security activation state of the first DRB is determined according to the second user plane security policy; or A DRB satisfying a second condition is determined as the first DRB from one or more DRBs of the session, the second condition comprising that the user plane security activation state of the DRB is determined according to the second user plane security policy.

17. The method of claim 14, wherein, The determining a first DRB corresponding to the first QoS flow in the session and a user plane security activation state of the first DRB according to the second user plane security policy and the QoS flow identifier of the first QoS flow comprises: determining, according to the QoS flow identity of the first QoS flow, that the following conditions are satisfied: 1) the first QoS flow is created before the receiving of the second user plane security policy and the QoS flow identity of the first QoS flow from the session management function network element, 2) the first QoS flow corresponds to the first DRB, and the number of QoS flows corresponding to the first DRB is equal to 1; updating, according to the second user plane security policy, the user plane security activation state of the first DRB.

18. The method according to any one of claims 14-17, characterized by, The method further comprises: sending, to the terminal device, user plane security indication information corresponding to the first DRB, the user plane security indication information being used to indicate whether to activate user plane security protection of the first DRB, the user plane security indication information being determined according to the second user plane security policy.

19. A communications device, characterized by comprising one or more functional modules for performing the method of any one of claims 1-13, or for performing the method of any one of claims 14-18.

20. A communications device, characterized by comprising a communication interface and a processor: the communication interface is configured to input and / or output signaling or data; the processor is configured to execute a computer executable program, so that the method of any one of claims 1-13 is performed, or the method of any one of claims 14-18 is performed.

21. A communications device, characterized by comprising a processor and a memory, the memory is configured to store a computer program or instructions; the processor is configured to execute the computer program or instructions in the memory, so that the method of any one of claims 1-13 is performed, or the method of any one of claims 14-18 is performed.

22. A computer-readable storage medium comprising instructions, wherein: when the instructions are executed by the processor, the method of any one of claims 1-13 is implemented, or the method of any one of claims 14-18 is implemented.

23. A computer program product comprising a program, characterized in that when the program is executed by the processor, the method of any one of claims 1-13 is implemented, or the method of any one of claims 14-18 is implemented.

24. A chip system, characterized by the chip system comprises at least one processor, when program instructions are executed in the at least one processor, so that the method of any one of claims 1-13 is implemented, or the method of any one of claims 14-18 is implemented.

25. A communication system, characterized by comprising a communication device for performing the method of any one of claims 1-13, and a communication device for performing the method of any one of claims 14-18.

Citation Information

Patent Citations

  • Communication method, device and system

    CN109600339A

  • Communication method, device and system

    CN114500008A