Communication methods and related apparatuses
By reporting the user plane security activation status of the first 3GPP access in the enhanced 5G mobile communication technology system, the security failure problem of different 3GPP accesses in the redundant mode is solved, the consistency of the security protection status of the MA PDU session is achieved, and the security and reliability of the system are improved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- HUAWEI TECH CO LTD
- Filing Date
- 2023-10-08
- Publication Date
- 2026-07-10
AI Technical Summary
In enhanced 5G mobile communication technology systems, when a Multi-Access Protocol Data Unit (MA PDU) session simultaneously supports two 3GPP access paths, if the user plane security activation states of the two 3GPP access paths are different in the redundant mode, the security of the MA PDU session will be low, and the security of the other 3GPP access path will fail.
The RAN or UE of the first 3GPP access through the MA PDU session reports the user plane security activation status, ensuring that the RAN and UE of the second 3GPP access perform user plane security activation according to the status, so that the two 3GPP accesses have the same user plane security activation status, thereby achieving consistency of security protection status.
This achieves consistency in the security protection status of the two 3GPP accesses in the redundant mode of the MA PDU session, thereby improving the security and reliability of the system.
Smart Images

Figure CN119789090B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to a communication method and related apparatus. Background Technology
[0002] In mobile communication systems, to ensure the security of service data transmission, access network nodes provide security protection for downlink service data from user equipment (UE), such as encryption and integrity protection, and then transmit the secure downlink service data to the UE through the air interface between the access network node and the terminal. Correspondingly, the UE provides security protection for uplink service data and transmits the secure uplink service data to the access network node through the air interface. The securely protected service data remains in a protected state during air interface transmission, effectively preventing attackers from eavesdropping or tampering.
[0003] Currently, in scenarios where the 5G system architecture is enhanced to enable Multiple Access Protocol Data Unit (MA PDU) sessions to simultaneously support two 3GPP access paths, when the access traffic steering, switching, and splitting (ATSSS) rules of the MA PDU session created by the user equipment (UE) are in a steering mode (including a redundant mode), if the two 3GPP access paths of the UE-created MA PDU session transmit the same content, and if the user plane security activation states of the two 3GPP access paths of the MA PDU session are different, the 3GPP access path with lower security in the MA PDU session will cause the security of the other 3GPP access path of the MA PDU session to fail. Summary of the Invention
[0004] This application provides a communication method and related apparatus. When a UE creates an MA PDU session supporting dual 3GPP access, if the steering mode in the ATSSS rule corresponding to the MA PDU session includes a redundant mode and the confidentiality protection or integrity protection of the user plane security policy is preferred, then the UE or RAN of the MA PDU session reports the user plane security activation state determined on the first 3GPP access, so that the RAN and UE of the second 3GPP access of the MA PDU session perform user plane security activation according to the user plane security activation state, so that the two 3GPP accesses of the MA PDU session have the same user plane security activation state, thereby achieving the consistency of the security protection state of the two 3GPP accesses of the MA PDU session supporting dual 3GPP access.
[0005] To achieve the above objectives, this application adopts the following technical solution:
[0006] In a first aspect, a communication method is provided, applied to a network device, the method comprising:
[0007] The system receives a first Protocol Data Unit (PDU) session creation request sent by a User Equipment (UE) through a first Radio Access Node (RAN). This PDU session creation request is used to request the creation of a multi-access MA PDU session supporting dual 3GPP access on a first 3GPP access network. The system then determines the access traffic steering, handover, and splitting ATSSS rules and user plane security policies corresponding to the MA PDU session. If the steering mode in the ATSSS rules includes a redundant mode, and the confidentiality protection or integrity protection of the user plane security policy is set to preferred, the system sends a reporting indication request to the first RAN or the UE. This reporting indication request instructs the first RAN or the UE to report the user plane security activation status of the first 3GPP access network. The user plane security activation status includes whether the integrity protection and confidentiality protection of the user plane of the first 3GPP access network are activated. Finally, the system sends the user plane security activation status to the second RAN, so that the second RAN and the UE can perform user plane security activation based on the user plane security activation status. The second RAN is the second RAN corresponding to the second 3GPP access network supporting the dual 3GPP access MA PDU session, and the second RAN is different from the first RAN.
[0008] Thus, when a UE creates an MA PDU session supporting dual 3GPP access, if the steering mode in the ATSSS rule corresponding to the MA PDU session includes a redundant mode and the confidentiality protection or integrity protection of the user plane security policy is preferred, then the first RAN or UE corresponding to the first 3GPP access of the MA PDU session reports the user plane security activation state determined by the UE and the first RAN, and sends the user plane security activation state to the second RAN, so that the second RAN performs user plane security activation according to the user plane security activation state. The two 3GPP accesses of the MA PDU session have the same user plane security activation state, thereby achieving consistency of the security protection state of the two 3GPP accesses of the MA PDU session supporting dual 3GPP access.
[0009] Furthermore, the network equipment can be either AMF or SMF.
[0010] In some embodiments of the first aspect, sending the user plane security activation status to the second RAN includes:
[0011] If the network device is a Session Management Function (SMF), the SMF sends the User Plane Security Activation Status (MPS) to the Access and Mobility Management Function (AMF), so that the AMF sends the MPS to the second RAN.
[0012] If the network device is an AMF, then the AMF sends the user plane security activation status to the second RAN.
[0013] In some embodiments of the first aspect, the AMF sends the user plane security activation status to the second RAN, including:
[0014] Obtain the context information of the UE, determine the second RAN corresponding to the second 3GPP access corresponding to the MA PDU session supporting dual 3GPP access based on the context information of the UE, and send the user plane security activation status to the second RAN.
[0015] Furthermore, if the network device is an SMF, after receiving the second PDU session creation request sent by the UE through the second RAN, the SMF determines the second RAN corresponding to the second 3GPP access of the MA PDU session supporting dual 3GPP access based on the second PDU session creation request. For example, after receiving the second PDU session creation request, the AMF obtains the UE's context information and determines the second RAN corresponding to the second 3GPP access of the MA PDU session supporting dual 3GPP access based on the UE's context information. It can be understood that in other embodiments, the AMF obtains the UE's context information and determines the RAN information of the two 3GPP accesses registered by the UE on the AMF based on the UE's context information, that is, the two RANs corresponding to the two 3GPP accesses (i.e., the two RANs belong to the same PLMN): the first RAN and the second RAN. The AMF can determine the RAN corresponding to the second 3GPP access of the MA PDU session supporting dual 3GPP access based on the first RAN corresponding to the first 3GPP access of the MA PDU session supporting dual 3GPP access. The SMF sends the user plane security activation status to the second RAN through the AMF.
[0016] If the network device is an AMF, after receiving the second PDU session creation request sent by the UE through the second RAN, the AMF determines the second RAN corresponding to the second 3GPP access for the MA PDU session supporting dual 3GPP access based on the second PDU session creation request. For example, after receiving the second PDU session creation request, the AMF obtains the UE's context information and determines the second RAN corresponding to the second 3GPP access for the MA PDU session supporting dual 3GPP access based on the UE's context information. It can be understood that in other embodiments, the AMF obtains the UE's context information and determines the RAN information of the two 3GPP accesses registered by the UE on the AMF based on the UE's context information, that is, the two RANs corresponding to the two 3GPP accesses (i.e., the two RANs belong to the same PLMN): the first RAN and the second RAN. The AMF can determine the RAN corresponding to the second 3GPP access for the MA PDU session supporting dual 3GPP access based on the RAN corresponding to the first 3GPP access for the MA PDU session supporting dual 3GPP access. The AMF sends the user plane security activation status to the second RAN.
[0017] In some embodiments of the first aspect, if the network device sends a reporting indication request to the first RAN, the method further includes, after the network device sends the reporting indication request to the first RAN, the network device receiving a user plane security activation status sent by the first RAN.
[0018] Thus, when a UE creates an MA PDU session supporting dual 3GPP access, if the steering mode in the ATSSS rule corresponding to the MA PDU session includes a redundant mode and the confidentiality protection or integrity protection of the user plane security policy is preferred, then the first RAN corresponding to the first 3GPP access of the MA PDU session reports the user plane security activation state determined by the UE and the first RAN. The first RAN sends the user plane security activation state to the network device to send the user plane security activation state to the second RAN, so that the second RAN performs user plane security activation based on the user plane security activation state. The two 3GPP accesses of the MA PDU session have the same user plane security activation state, thereby achieving consistency of the security protection state of the two 3GPP accesses of the MA PDU session supporting dual 3GPP access.
[0019] Furthermore, after receiving the user plane security activation state sent by the first RAN, the network device can save the user plane security activation state locally, or it can send the user plane security activation state to other network devices after receiving the user plane security activation state sent by the first RAN, so that the other network devices can save the user plane security activation state.
[0020] In some embodiments of the first aspect, if the first SMF sends a reporting indication request to the UE, the second PDU session creation request carries the user plane security activation state. The network device receives the user plane security activation state carried in the second PDU session creation request.
[0021] Furthermore, after receiving the user plane security activation state sent by the first RAN, the network device can save the user plane security activation state locally, or it can send the user plane security activation state to other network devices after receiving the user plane security activation state sent by the first RAN, so that the other network devices can save the user plane security activation state.
[0022] Thus, when a UE creates an MA PDU session supporting dual 3GPP access, if the steering mode in the ATSSS rule corresponding to the MA PDU session includes a redundant mode and the confidentiality protection or integrity protection of the user plane security policy is preferred, then the UE corresponding to the first 3GPP access of the MA PDU session reports the user plane security activation state determined by the UE and the first RAN. The second PDU session creation request carries the user plane security activation state, that is, the user plane security activation state is reported through the second PDU session creation request. The network device sends the user plane security activation state to the second RAN so that the second RAN performs user plane security activation based on the user plane security activation state. The two 3GPP accesses of the MA PDU session have the same user plane security activation state, thereby achieving consistency of the security protection state of the two 3GPP accesses of the MA PDU session supporting dual 3GPP access.
[0023] In some embodiments of the first aspect, the first PDU session creation request carries a PDU session identifier, a request type, and a dual 3GPP access indication. The request type is an MA PDU request, and the dual 3GPP access indication is used to indicate that the MA PDU session requested by the first PDU session creation request supports dual 3GPP access. The second PDU session creation request carries a PDU session identifier and a request type. The request type is an existing PDU session or a dual 3GPP access type.
[0024] Thus, by combining the request type and the dual 3GPP access indication, the first PDU session creation request is used to create a MA PDU session supporting dual 3GPP access on the first 3GPP access; the PDU session identifier and the request type are used to indicate the creation of an existing PDU session.
[0025] The first PDU session creation request and the second PDU session creation request are used to create MA PDU sessions on two 3GPP access points, respectively. The PDU session identifier in the first PDU session creation request is the same as the PDU session identifier in the second PDU session creation request.
[0026] In some embodiments of the first aspect, if the network device is a first SMF, the method further includes: the first SMF receiving a PDU session context creation request sent by a second SMF, the PDU session context creation request carrying a PDU session identifier; the first SMF sending a PDU session context creation response to the second SMF, the PDU session context creation response carrying the user plane security activation state corresponding to the PDU session identifier.
[0027] Thus, if the two 3GPP access RANs corresponding to the MA PDU sessions of dual 3GPP access are located in different PLMNs, the SMFs between the two PLMNs will send PDU session context creation requests to each other to send the user plane security activation state of one PLMN to the SMF of the other PLMN.
[0028] Secondly, a communication method is provided, applied to a user equipment (UE), the method comprising:
[0029] The first radio access node (RAN) sends a first protocol data unit (PDU) session creation request to the network device. The first PDU session creation request is used to request the creation of a multi-access MAPDU session that supports dual 3GPP access on the first 3GPP access.
[0030] The network device receives a reporting instruction request, which instructs the UE to report the user plane security activation status of the first 3GPP access to the network device. The user plane security activation status includes whether the integrity protection and confidentiality protection of the user plane of the first 3GPP access are activated. The reporting instruction request is sent by the network device to the UE when the steering mode in the ATSSS rule includes the redundant mode and the confidentiality protection or integrity protection of the user plane security policy is preferred.
[0031] The second RAN sends a second PDU session creation request to the network device. The second PDU session creation request is used to request the creation of a MA PDU session supporting dual 3GPP access on the second 3GPP access. The second PDU session creation request carries the user plane security activation state, so that the network device sends the user plane security activation state to the second RAN, thereby enabling the second RAN and the UE to perform user plane security activation based on the user plane security activation state.
[0032] In some embodiments of the second aspect, the first PDU session creation request carries a PDU session identifier, a request type, and a dual 3GPP access indication, wherein the request type is an MA PDU request, and the dual 3GPP access indication is used to indicate that the MA PDU session requested by the first PDU session creation request supports dual 3GPP access.
[0033] The second PDU session creation request carries the PDU session identifier and request type, wherein the request type is an existing PDU session or a dual 3GPP access type.
[0034] In some embodiments of the second aspect, the network device is an Access and Mobility Management Function (AMF) or a Session Management Function (SMF).
[0035] A third aspect provides a communication method applied to a network device, the method comprising:
[0036] Receive a first protocol data unit (PDU) session creation request sent by the user equipment (UE) through the first radio access node (RAN). The first PDU session creation request is used to request the creation of a multi-access MA PDU session that supports dual 3GPP access on the first 3GPP access.
[0037] Determine the access traffic routing, switching, splitting ATSSS rules and user plane security policies corresponding to the MA PDU session;
[0038] Send a PDU session creation acceptance to the UE, wherein the PDU session creation acceptance carries the ATSSS rule;
[0039] The UE sends a second PDU session creation request through the second RAN. The second PDU session creation request is used to request the creation of a MA PDU session supporting dual 3GPP access on the second 3GPP access. If the steering mode in the ATSSS rule includes a redundant mode, the second PDU session creation request carries the user plane security activation state determined on the first 3GPP access. The user plane security activation state includes whether the integrity protection and confidentiality protection of the user plane of the first 3GPP access are activated.
[0040] When the confidentiality protection or integrity protection of the user plane security policy is preferred, a user plane security activation state is sent to the second RAN so that the second RAN and the UE can perform user plane security activation according to the user plane security activation state.
[0041] In some embodiments of the third aspect, the first PDU session creation request carries a PDU session identifier, a request type, and a dual 3GPP access indication, wherein the request type is an MA PDU request, and the dual 3GPP access indication is used to indicate that the MA PDU session requested by the first PDU session creation request supports dual 3GPP access.
[0042] The second PDU session creation request carries a PDU session identifier and a request type, wherein the request type is an existing PDU session or a dual 3GPP access session.
[0043] In some embodiments of the third aspect, the network device is an Access and Mobility Management Function (AMF) or a Session Management Function (SMF).
[0044] In some embodiments of the third aspect, if the network device is a first SMF, the method further includes:
[0045] The first SMF receives a PDU session context creation request sent by the second SMF, the PDU session context creation request carrying a PDU session identifier;
[0046] The first SMF sends a PDU session context creation response to the second SMF, the PDU session context creation response carrying the user plane security activation state corresponding to the PDU session identifier.
[0047] Fourthly, a communication method is provided, applied to a user equipment (UE), the method comprising:
[0048] The first RAN sends a first PDU session creation request to the network device. The first PDU session creation request is used to request the creation of an MA PDU session that supports dual 3GPP access on the first 3GPP access.
[0049] Receive the PDU session creation acceptance sent by the network device, wherein the PDU session creation acceptance carries the ATSSS rule;
[0050] The second RAN sends a second PDU session creation request to the first SMF. The second PDU session creation request is used to request the creation of an MA PDU session supporting dual 3GPP access on the second 3GPP access. If the steering mode in the ATSSS rule includes a redundant mode, the second PDU session creation request carries the user plane security activation state determined on the first 3GPP access. This allows the network device to send the user plane security activation state to the second RAN when the confidentiality protection or integrity protection of the user plane security policy corresponding to the MA PDU session is preferred. This enables the second RAN and the UE to perform user plane security activation based on the user plane security activation state.
[0051] In some embodiments of the fourth aspect, the first PDU session creation request carries a PDU session identifier, a request type, and a dual 3GPP access indication, wherein the request type is an MA PDU request, and the dual 3GPP access indication is used to indicate that the MA PDU session requested by the first PDU session creation request supports dual 3GPP access.
[0052] The second PDU session creation request carries a PDU session identifier and a request type, wherein the request type is an existing PDU session or a dual 3GPP access session.
[0053] In some embodiments of the fourth aspect, the network device is an Access and Mobility Management Function (AMF) or a Session Management Function (SMF).
[0054] Fifthly, a communication method is provided for use in the Access and Mobility Management Function (AMF), the method comprising:
[0055] Receive a first protocol data unit (PDU) session creation request sent by the user equipment (UE) through the first radio access node (RAN). The first PDU session creation request is used to request the creation of a multi-access MA PDU session that supports dual 3GPP access on the first 3GPP access.
[0056] Determine the access traffic routing, switching, splitting ATSSS rules and user plane security policies corresponding to the MA PDU session;
[0057] Send a PDU session creation acceptance to the UE;
[0058] The system receives a second PDU session creation request sent by the UE through the second RAN. The second PDU session creation request is used to request the creation of an MA PDU session that supports dual 3GPP access on the second 3GPP access.
[0059] When the steering mode in the ATSSS rule includes the redundant mode and the confidentiality protection or integrity protection of the user plane security policy is preferred, a user plane security activation status transmission indication is sent to the first RAN. The reporting indication request is used to instruct the first RAN to report the user plane security activation status to the second RAN, so that the second RAN and the UE can perform user plane security activation according to the user plane security activation status. The user plane security activation status includes whether the integrity protection and confidentiality protection of the user plane of the first 3GPP access are activated.
[0060] In some embodiments of the fifth aspect, the first PDU session creation request carries a PDU session identifier, a request type, and a dual 3GPP access indication, wherein the request type is an MA PDU request, and the dual 3GPP access indication is used to indicate that the MA PDU session requested by the first PDU session creation request supports dual 3GPP access.
[0061] The second PDU session creation request carries a PDU session identifier and a request type, wherein the request type is an existing PDU session or a dual 3GPP access session.
[0062] Sixthly, a communication method is provided, applied to a first radio access node (RAN), the method comprising:
[0063] The network device receives a reporting instruction request, which instructs the first RAN to send the user plane security activation status of the first 3GPP access to the network device. The user plane security activation status includes whether the integrity protection and confidentiality protection of the user plane of the first 3GPP access are activated. The reporting instruction request is sent by the network device to the first RAN when the steering mode in the ATSSS rule includes the redundant mode and the confidentiality protection or integrity protection of the user plane security policy is preferred.
[0064] Send the user plane security activation status to the network device.
[0065] A seventh aspect provides a communication method applied to a first radio access node (RAN), the method comprising:
[0066] The network device receives a user plane security activation status transmission indication, which is used to instruct the first RAN to send the user plane security activation status of the first 3GPP access to the second RAN. The user plane security activation status includes whether the integrity protection and confidentiality protection of the user plane of the first 3GPP access are activated. The user plane security activation status transmission indication is sent by the network device to the first RAN when the steering mode in the ATSSS rule includes the redundant mode and the confidentiality protection or integrity protection of the user plane security policy is preferred. The user plane security activation status transmission indication carries the identifier of the second RAN.
[0067] Send the user plane security activation status to the second RAN.
[0068] Eighthly, a communication method is provided, applied to a second radio access node (RAN), the method comprising:
[0069] Receive the user plane security activation status sent by the network device;
[0070] User plane security activation with the UE is performed based on the user plane security activation status.
[0071] In some embodiments of the eighth aspect, the step of performing user plane security activation with the UE based on the user plane security activation state includes:
[0072] A Radio Resource Control (RRC) connection reconfiguration message is generated based on the user plane security activation status, and the RRC connection reconfiguration message is sent to the UE.
[0073] Ninthly, a communication method is provided, applied to a second radio access node (RAN), the method comprising:
[0074] Receive the user plane security activation status sent by the first RAN;
[0075] User plane security activation with the UE is performed based on the user plane security activation status.
[0076] In some embodiments of the ninth aspect, the step of performing user plane security activation with the UE based on the user plane security activation state includes:
[0077] An RRC connection reconfiguration message is generated based on the user plane security activation status, and the RRC connection reconfiguration message is sent to the UE.
[0078] A tenth aspect provides a communication apparatus comprising: a processor and a memory, the memory being configured to store computer-executable instructions, and the processor being configured to execute the computer-executable instructions stored in the memory to cause the apparatus to perform the method described in any one of the first to ninth aspects.
[0079] Eleventhly, a chip is provided, the chip including at least one processor and a communication interface, the communication interface being coupled to the at least one processor, the at least one processor being configured to run computer programs or instructions to implement the communication method as described in any one of the first to ninth aspects; the communication interface being configured to communicate with other modules outside the chip.
[0080] In a twelfth aspect, a computer-readable storage medium is provided, wherein instructions are stored therein, which, when executed, implement the communication method described in any one of the first to ninth aspects.
[0081] The beneficial effects of each possible implementation of the communication method provided in the second aspect, the third aspect, the fourth aspect, the fifth aspect, the sixth aspect, the seventh aspect, the eighth aspect, the ninth aspect, the tenth aspect, the eleventh aspect, and the twelfth aspect of the embodiments of this application can be referred to the descriptions of the various possible implementations in the first aspect, and will not be repeated here. Attached Figure Description
[0082] Figure 1 This is a schematic diagram of a network architecture applicable to embodiments of this application;
[0083] Figure 2 This is a schematic diagram of an application architecture for a communication system applicable to embodiments of this application;
[0084] Figure 3 A flowchart illustrating a communication method provided in an embodiment of this application;
[0085] Figure 4 A flowchart illustrating a communication method provided in an embodiment of this application;
[0086] Figure 5 A flowchart illustrating a communication method provided in an embodiment of this application;
[0087] Figure 6 A flowchart illustrating a communication method provided in an embodiment of this application;
[0088] Figure 7 A flowchart illustrating a communication method provided in an embodiment of this application;
[0089] Figure 8 A flowchart illustrating a communication method provided in an embodiment of this application;
[0090] Figure 9 A flowchart illustrating a communication method provided in an embodiment of this application;
[0091] Figure 10 A flowchart illustrating a communication method provided in an embodiment of this application;
[0092] Figure 11 A flowchart illustrating a communication method provided in an embodiment of this application;
[0093] Figure 12 A flowchart illustrating a communication method provided in an embodiment of this application;
[0094] Figure 13A flowchart illustrating a communication method provided in an embodiment of this application;
[0095] Figure 14 A flowchart illustrating a communication method provided in an embodiment of this application;
[0096] Figure 15 A flowchart illustrating a communication method provided in an embodiment of this application;
[0097] Figure 16 A flowchart illustrating a communication method provided in an embodiment of this application;
[0098] Figure 17 A flowchart illustrating a communication method provided in an embodiment of this application;
[0099] Figure 18 This is a schematic diagram of the structure of a communication device provided in an embodiment of this application. Detailed Implementation
[0100] The technical solutions in this application will now be described with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments in this specification, and not all of them.
[0101] First, a system diagram applicable to the communication method provided in this application is illustrated.
[0102] The technical solutions provided in this application can be applied to various communication systems, such as 5th generation (5G) or new radio (NR) systems, long term evolution (LTE) systems, LTE frequency division duplex (FDD) systems, and LTE time division duplex (TDD) systems. The technical solutions provided in this application can also be applied to future communication systems, such as 6th generation mobile communication systems. Furthermore, the technical solutions provided in this application can also be applied to device-to-device (D2D) communication, vehicle-to-everything (V2X) communication, machine-to-machine (M2M) communication, machine-type communication (MTC), and Internet of Things (IoT) communication systems or other communication systems.
[0103] First, let me briefly introduce the network architecture applicable to this application, as follows.
[0104] As an example, Figure 1 A schematic diagram of a network architecture is shown.
[0105] like Figure 1 As shown, this network architecture uses the 5G system (5GS) as an example. This network architecture may include, but is not limited to: network slice selection function (NSSF), authentication server function (AUSF), unified data management (UDM), network exposure function (NEF), network repository function (NRF), policy control function (PCF), application function (AF), access and mobility management function (AMF), session management function (SMF), user equipment (UE), radio access network equipment, user plane function (UPF), and data network (DN).
[0106] Where DN can be the Internet; NSSF, AUSF, UDM, NEF, NRF, PCF, AF, AMF, SMF, and UPF are network elements in the core network, because Figure 1 Taking a 5G system as an example, the core network can be called the 5G core network (5GC or 5GCN).
[0107] The following is about Figure 1 A brief introduction to each network element shown in the diagram is provided.
[0108] 1. UE: can be called user equipment, access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication equipment, user agent, or user device.
[0109] A UE can be a device that provides voice / data to a user, such as a handheld device or vehicle-mounted device with wireless connectivity. Currently, examples of terminals include: mobile phones, tablets, laptops, PDAs, mobile internet devices (MIDs), wearable devices, virtual reality (VR) devices, augmented reality (AR) devices, wireless terminals in industrial control, wireless terminals in self-driving, wireless terminals in remote medical surgery, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, wireless terminals in smart homes, cellular phones, cordless phones, session initiation protocol (SIP) phones, wireless local loop (WLL) stations, personal digital assistants (PDAs), handheld devices with wireless communication capabilities, computing devices or other processing devices connected to a wireless modem, wearable devices, terminal devices in 5G networks, or future public land mobile communication networks. Terminal devices in a network (PLMN), etc., are not limited to this in the embodiments of this application.
[0110] By way of example and not limitation, in this embodiment, the terminal device can also be a wearable device. Wearable devices, also known as wearable smart devices, are a general term for devices that utilize wearable technology to intelligently design and develop everyday wearables, such as glasses, gloves, watches, clothing, and shoes. Wearable devices are portable devices that are worn directly on the body or integrated into the user's clothing or accessories. Wearable devices are not merely hardware devices, but also achieve powerful functions through software support, data interaction, and cloud interaction. Broadly speaking, wearable smart devices include those that are feature-rich, large in size, and can achieve complete or partial functions without relying on a smartphone, such as smartwatches or smart glasses, as well as those that focus on a specific type of application function and require the use of other devices such as smartphones, such as various smart bracelets and smart jewelry for vital sign monitoring.
[0111] Furthermore, in this embodiment, the UE can also be a terminal device in an IoT system. IoT is an important component of the future development of information technology. Its main technical feature is to connect objects to the network through communication technology, thereby realizing an intelligent network of human-machine interconnection and object-to-object interconnection.
[0112] It should be noted that UEs and access network devices can communicate with each other using some air interface technology (such as NR or LTE). UEs can also communicate with each other using some air interface technology (such as NR or LTE).
[0113] In this embodiment, the device for implementing the UE's function can be a terminal device or a device capable of supporting the terminal device in implementing the function, such as a chip system or a chip, which can be installed in the terminal device. In this embodiment, the chip system can be composed of chips or can include chips and other discrete components.
[0114] 2. Radio Access Network (RAN) Equipment: This equipment provides access to a communication network for authorized users in a specific area. Specifically, it can include wireless network equipment in 3GPP (3rd Generation Partnership Project) networks or access points in non-3GPP networks. For ease of description, RAN will be used in the following text.
[0115] RAN can utilize different radio access technologies. Currently, there are two types of radio access technologies: 3GPP access technologies (e.g., those used in 3rd generation (3G), 4th generation (4G), or 5G systems) and non-3GPP access technologies. 3GPP access technologies refer to access technologies that conform to 3GPP standards and specifications. For example, access network equipment in a 5G system is called a next-generation node basestation (gB) or RAN. Non-3GPP access technologies can include air interface technologies such as access points (APs) in Wireless Fidelity (WiFi), Worldwide Interoperability for Microwave Access (WiMAX), and Code Division Multiple Access (CDMA). RAN allows terminal equipment and the 3GPP core network to interconnect using non-3GPP technologies.
[0116] The RAN is responsible for functions such as radio resource management, quality of service (QoS) management, data compression, and encryption on the air interface side. The RAN provides access services to terminal devices, thereby completing the forwarding of control signals and user data between the terminal devices and the core network.
[0117] RAN can include, but is not limited to: macro base stations, micro base stations (also known as small stations), radio network controllers (RNCs), Node Bs (NBs), base station controllers (BSCs), base transceiver stations (BTSs), home base stations (e.g., home-evolved Node Bs, or home Node Bs, HNBs), baseband units (BBUs), access points (APs), wireless relay nodes, wireless backhaul nodes, transmission points (TPs), or transmission and reception points (TRPs) in WiFi systems. It can also be gNBs or transmission points (TRPs or TPs) in 5G (e.g., NR) systems, one or a group of antenna panels (including multiple antenna panels) of a base station in a 5G system, or network nodes constituting gNBs or transmission points, such as distributed units (DUs), or base stations in next-generation 6G communication systems. This application does not limit the specific technologies or equipment forms used in the RAN.
[0118] 3. AMF: Primarily used for access control, mobility management, attach and detach functions.
[0119] 4. SMF: Primarily used for user plane network element selection, user plane network element redirection, Internet Protocol (IP) address allocation for terminal devices, as well as session creation, modification and release, and QoS control.
[0120] 5. UPF: Primarily used for receiving and forwarding user plane data. For example, a UPF can receive user plane data from a DN and send it to the terminal equipment via a RAN. A UPF can also receive user plane data from the terminal equipment via a RAN and forward it to a DN.
[0121] 6. NEF: Primarily used to securely expose services and capabilities provided by 3GPP network functions to the outside world.
[0122] 7. PCF: Primarily used as a unified policy framework to guide network behavior, providing policy rule information to control plane network elements (such as AMF, SMF, etc.).
[0123] 8. AF: Primarily used to provide services to 3GPP networks, such as interacting with PCF for policy control.
[0124] 9. Network slice selection function (NSSF): mainly used for network slice selection.
[0125] 10. UDM: Primarily used for UE subscription data management, including UE identifier storage and management, UE access authorization, etc.
[0126] 11. DN: Primarily used by operators to provide data services to the UE. Examples include the Internet, third-party service networks, and IP Multimedia Service (IMS) networks.
[0127] 12. AUSF: Primarily used for user authentication, etc.
[0128] 13. NRF: Primarily used to store network functional entities and their descriptions of the services they provide.
[0129] exist Figure 1 In the network architecture shown, network elements can communicate with each other via interfaces. For example, the UE connects to the RAN via the radio resource control (RRC) protocol, and the UE and RAN communicate using the Uu interface. The PC5 interface can be used for UE discovery and data and signaling transmission between UEs. Furthermore, in... Figure 1 In this interface, N1 is the interface between the UE and the AMF; N2 is the interface between the (R)AN and the AMF, used for sending NAS messages, etc.; N3 is the interface between the RAN and the UPF, used for transmitting user plane data, etc.; N4 is the interface between the SMF and the UPF, used for transmitting information such as tunnel identification information for the N3 connection, data buffer indication information, and downlink data notification messages, etc.; the N6 interface is the interface between the UPF and the DN, used for transmitting user plane data, etc.; and the N11 interface is the interface between the AMF and the SMF.
[0130] It should be understood that the network architecture shown above is merely an illustrative example, and the network architecture applicable to the embodiments of this application is not limited thereto. Any network architecture capable of realizing the functions of the above-described network elements is applicable to the embodiments of this application.
[0131] It should also be understood that Figure 1The functions or network elements shown, such as AMF, SMF, UPF, PCF, UDM, NSSF, and AUSF, can be understood as network elements used to implement different functions, such as network slices that can be combined as needed. These network elements can be independent devices or integrated into the same device to implement different functions. They can be network components in hardware devices, software functions running on dedicated hardware, or virtualization functions instantiated on a platform (e.g., a cloud platform). This application does not limit the specific form of the above network elements.
[0132] It should also be understood that the above naming is defined only for the convenience of distinguishing different functions and should not constitute any limitation on this application. This application does not exclude the possibility of using other naming in 6G networks and other future networks. For example, in 6G networks, some or all of the above-mentioned network elements may use the terminology from 5G, or may use other names, etc. To facilitate understanding of the embodiments of this application, the terminology involved in this application is briefly explained.
[0133] 1. Protocol Data Unit (PDU) Session: The 5G core network (5GC) supports PDU connection services. A PDU connection service refers to the exchange of PDU data packets between the UE and the DN. PDU connection services are established by the terminal device initiating the establishment of a PDU session. Once a PDU session is established, a data transmission channel between the UE and the DN is established. In other words, the PDU session is at the UE level. Each UE can establish one or more PDU sessions.
[0134] As mentioned earlier, the SMF is primarily responsible for session management in mobile networks. PDU sessions can be established, modified, or released between the UE and the SMF via NAS session management (SM) signaling.
[0135] In this embodiment of the application, a PDU session can be identified by a PDU session identifier (PDU sessionidentifier, PDU session ID).
[0136] Figure 2 This is a schematic diagram of a communication system applicable to embodiments of this application. For example... Figure 2 As shown, this network architecture is... Figure 1 On the infrastructure shown, the 3GPP standard provides a scheme for a UE to create a multiple access (MA) PDU session that supports dual 3GPP access.
[0137] Figure 2Both the UE and the core network support Access Traffic Steering, Switching, Splitting, and ATSSS. UEs supporting ATSSS can create MA PDU sessions. This session is a PDU session that provides PDU connection services and supports multiple access methods, such as... Figure 2 The UE creates a dual 3GPP access MA PDU session through the first RAN on the first 3GPP access, and the UE creates a dual 3GPP access MA PDU session through the second RAN on the second 3GPP access. The data of the MA PDU session can be transmitted on the data transmission channels corresponding to the two 3GPP accesses.
[0138] Specifically, during the MA PDU session creation process, the core network determines the corresponding ATSSS rules for the MA PDU session based on the ATSSS capabilities, relevant subscription information, PCC rules, local policies, and other information reported by the UE. The ATSSS rules include multiple modes, among which the steering mode in ATSSS is used to identify the steering mode and related parameters used for the matching traffic.
[0139] If the steering mode includes a redundant mode, then for matching service data flow (SDF) traffic, it can be copied and transmitted on both 3GPP access points. If the ATSSS rule provides a primary access, the UE and core network (e.g., UPF) should send all SDF packets on the primary access and copy the corresponding packets on the other access. If the ATSSS rule does not provide a primary access, the UE and core network should send all SDF packets on both access points.
[0140] For MA PDU sessions supporting dual 3GPP access, if the steering mode of the ATSSS rule corresponding to the MA PDU includes the redundant mode, then the two 3GPP accesses in the MA PDU session should maintain security consistency. Since the two 3GPP accesses in an MA PDU session transmit the same content, if one 3GPP access has lower security and the other has higher security, the security of the entire MA PDU session is determined by the less secure 3GPP access, thus affecting the overall security of the MA PDU session.
[0141] In 5G networks, to ensure the security of data transmission for each PDU session, a user plane security policy is determined during PDU session creation and distributed to the RAN. The current user plane security policy (whether to perform confidentiality and integrity protection) in 5G networks is based on session granularity. During PDU session creation, the user plane security policy for the current session is determined and distributed to the RAN. The RAN determines, based on the user plane policy and local configuration, whether to activate user plane security for the DRB (Data Radio Bearer) carrying the service data of this session, thereby determining the user plane security activation status between the RAN and the UE.
[0142] First, the user plane security policy is determined by the SMF based on the subscribed user plane security policy and the locally configured user plane security policy when the PDU session is created.
[0143] Secondly, the user plane security policy includes whether user plane integrity protection and confidentiality protection are activated; specifically: the User Plane Security Enforcement information sent by the SMF to the RAN through the AMF carries the user plane security policy, that is, the user plane security policy of the PDU session is provided to the RAN through the User Plane Security Enforcement information.
[0144] Specifically, user security policies include user plane integrity protection and confidentiality protection;
[0145] If integrity protection is required, then all data transmitted in the PDU session is required to use user plane integrity protection.
[0146] If integrity protection is not needed, then all transmitted data in the PDU session will not use user plane integrity protection;
[0147] If integrity protection is preferred, then all transmitted data in the PDU session will use user plane integrity protection according to the preference.
[0148] If confidentiality protection is required, then all data transmitted in the PDU session is required to use user plane confidentiality protection.
[0149] If confidentiality protection is not needed, then all data transmitted in the PDU session will not use user plane confidentiality protection.
[0150] If confidentiality protection is preferred, then all transmitted data in the PDU session will use user plane confidentiality protection according to the preference.
[0151] Furthermore, the user plane security policy only applies to 3GPP access. Once determined when the PDU session is created, the user plane security policy will be applied to the lifetime of the PDU session.
[0152] Finally, the RAN performs user plane security activation with the UE based on the user plane security policy.
[0153] Specifically, the RRC connection reconfiguration message sent by the RAN to the UE carries the user plane security activation status of the corresponding PDU session, such as whether user plane integrity protection or confidentiality protection is performed on the corresponding DRB carrying the service data of this session.
[0154] If the user plane security policy for confidentiality protection or integrity protection is required or not needed, the RAN can perform user plane security activation based on the user security policy. For MA PDU sessions that support dual 3GPP access, since the user plane security policies corresponding to the two 3GPP accesses of the MA PDU session are the same, the user plane security activation status of the two 3GPP accesses of the MA PDU session will be the same after user plane security activation. For example, if confidentiality protection is required, the user plane of both 3GPP accesses of the MA PDU session needs to be protected with confidentiality.
[0155] However, if the user plane security policy for confidentiality or integrity protection includes "preferred," then after user plane security activation according to the user plane security policy, since confidentiality or integrity protection is determined based on the preferences configured locally by the RAN, the user plane security activation states of the two 3GPP accesses (corresponding to two RANs) of the MA PDU session may be different. For example, the user plane of one 3GPP access of the MA PDU session is protected by confidentiality, while the user plane of the other 3GPP access of the MA PDU session is not protected by confidentiality. Since the two 3GPP accesses of the redundant mode MA PDU session transmit the same content, the inconsistent user plane security activation states of the two 3GPP accesses of the MA PDU session affect the overall security of the MA PDU session.
[0156] To address the aforementioned issues, this application provides a communication method. When a UE creates a MAPDU session supporting dual 3GPP access, if the steering mode in the ATSSS rule corresponding to the MAPDU session includes the redundant mode and the confidentiality protection or integrity protection of the user plane security policy is preferred, then the UE or RAN corresponding to the first 3GPP access of the MAPDU session reports the user plane security activation state determined by the UE and RAN, and sends the user plane security activation state to the RAN corresponding to the second 3GPP access of the MAPDU session, so that the RAN corresponding to the second 3GPP access of the MAPDU session performs user plane security activation based on the user plane security activation state, thereby achieving consistency of the security protection states of the two 3GPP accesses in the MAPDU session supporting dual 3GPP access.
[0157] Specifically, when a UE creates a MA PDU session supporting dual 3GPP access, the SMF can obtain the ATSSS rules and user plane security policies of the MA PDU session. Based on these rules, the SMF determines whether the steering mode in the ATSSS rules corresponding to the MA PDU session includes the redundant mode and whether the confidentiality protection or integrity protection of the user plane security policy is preferred. If the steering mode in the ATSSS rules includes the redundant mode and the confidentiality protection or integrity protection of the user plane security policy is preferred, the SMF notifies the UE or RAN corresponding to the first 3GPP access of the MA PDU session to report the user plane security activation status. This allows the RAN corresponding to the second 3GPP access of the MA PDU session to perform user plane security activation based on this status, thereby achieving consistency in the security protection status of the two 3GPP accesses in the MA PDU session supporting dual 3GPP access. The following section combines... Figure 3 Please provide an explanation.
[0158] Please see Figure 3 , Figure 3 This is a flowchart illustrating a communication method provided in an embodiment of this application. Figure 3 As shown, the communication methods include: S301 to S304.
[0159] S301, SMF receives the first PDU session creation request sent by the UE through the first RAN. The first PDU session creation request is used to request the creation of an MA PDU session that supports dual 3GPP access on the first 3GPP access.
[0160] The MA PDU session for dual 3GPP access requested by the UE includes two 3GPP accesses: a first 3GPP access and a second 3GPP access. The first 3GPP access is when the UE accesses the 3GPP network through one of the RANs (e.g., the first RAN); the second 3GPP access is when the UE accesses the 3GPP network through another RAN (e.g., a second RAN different from the first RAN).
[0161] Optionally, the first PDU session creation request carries a PDU session identifier, a request type, and a dual 3GPP access indication. The request type is an MA PDU request, and the dual 3GPP access indication is used to indicate that the MA PDU session requested by the first PDU session creation request supports dual 3GPP access.
[0162] Optionally, after receiving the first PDU session creation request, the SMF determines, based on the MA PDU session request type and the dual 3GPP access indication, that the request is for requesting the establishment of a dual 3GPP access MA PDU session.
[0163] Optionally, after receiving the first PDU session creation request, the SMF determines, based on the dual 3GPP access indication and the carried PDU session identifier, whether the request is intended to create a session on the second 3GPP access corresponding to an existing MA PDU session with the corresponding PDU session identifier. If it is not intended to create a session on the second 3GPP access corresponding to an existing MA PDU session with the corresponding PDU session identifier, the SMF continues to execute S302. Specifically, the SMF uses the PDU session identifier to retrieve the context and, if it does not obtain the context of the MA PDU session corresponding to the PDU session identifier, it determines that the request is not intended to create a PDU session for the second access of the MA PDU session.
[0164] S302, SMF determines the ATSSS rules and user plane security policies corresponding to the MA PDU session.
[0165] Optionally, after determining the subscription data and local policy corresponding to the MA PDU session, the SMF determines whether the corresponding MA PDU session can be created based on the subscription data and local policy. If the SMF determines that the corresponding MA PDU session cannot be created, it sends a rejection message to the UE or ignores and discards the first PDU session creation request. If the SMF determines that the MA PDU session can be created, the SMF selects the PCF and obtains the session policy of the corresponding MA PDU session from the PCF. The SMF determines the ATSSS rules and user plane security policy based on the subscription data corresponding to the MA PDU session, the SMF local policy, and the session policy corresponding to the session, and confirms that the security policy is supported. At the same time, a corresponding session context is created for the UE. Specifically, the session context may include the PDU session identifier, the policy corresponding to the session, etc.
[0166] S303. If the steering mode in the ATSSS rule includes the redundant mode and the confidentiality protection or integrity protection of the user plane security policy is preferred, then the SMF sends a reporting indication request to the first RAN or UE. The reporting indication request is used to instruct the first RAN or UE to send the user plane security activation status to the SMF. The user plane security activation status includes whether the integrity protection and confidentiality protection of the user plane accessed by the first 3GPP are activated.
[0167] Specifically, whether the integrity protection and confidentiality protection of the user plane of the first 3GPP access are activated, that is, whether the integrity protection and confidentiality protection of the user plane between the UE and the first RAN are activated.
[0168] Optionally, after determining the ATSSS rules and user plane security policy for the MA PDU session, the SMF determines whether the steering mode in the ATSSS rules includes the redundant mode, and whether the confidentiality protection or integrity protection in the user plane security policy for the MA PDU session is preferred.
[0169] If the steering mode includes the redundant mode and the confidentiality or integrity protection of the user plane security policy of the MA PDU session is preferred, then the SMF sends a reporting instruction request to the first RAN or UE, sends the user plane security policy to the first RAN, and the reporting instruction is used to instruct the first RAN to report its user plane security activation status to the SMF.
[0170] If the steering mode does not include the redundant mode or the confidentiality or integrity protection of the user plane security policy for the MA PDU session does not include the preferred mode, then the SMF does not need to send a reporting instruction request to the first RAN or the UE, but only sends the user plane security policy to the first RAN.
[0171] Optionally, if the SMF sends a reporting indication request to the first RAN, after receiving the reporting indication request, the first RAN sends the user plane security activation state on the first 3GPP access to the SMF, and the SMF receives and saves the user plane security activation state. Optionally, the user plane security activation state is stored in the context corresponding to the session. If the SMF sends a reporting indication request to the UE, after receiving the reporting indication request sent by the SMF, the UE sends the user plane security activation state on the first 3GPP access to the corresponding SMF on the network side through the second PDU session creation request.
[0172] Optionally, after step S303, the method further includes: the SMF receiving a second PDU session creation request sent by the UE through the second RAN. The second PDU session creation request is used to request the creation of an MA PDU session supporting dual 3GPP access on the second 3GPP access. After receiving the second PDU session creation request sent by the UE through the second RAN, the SMF determines the second RAN corresponding to the second 3GPP access that supports the MA PDU session based on the second PDU session creation request sent by the second RAN. For example, after receiving the second PDU session creation request, the AMF obtains the UE's context information and determines the second RAN corresponding to the second 3GPP access that supports the MA PDU session based on the UE's context information.
[0173] Optionally, the second PDU session creation request carries a PDU session identifier and a request type. The PDU session identifier in the second PDU session creation request is the same as the PDU session identifier in the first PDU session creation request, and the request type is either an existing PDU session or a dual 3GPP access session. Based on the dual 3GPP access indication and the carried PDU session identifier, the SMF determines that the request is used to create a session on the second 3GPP access for an existing MA PDU session corresponding to the PDU session identifier. Specifically, the SMF uses the PDU session identifier to retrieve the context, thereby obtaining the context of the MA PDU session corresponding to the PDU session identifier, and thus determining that the request is used to create a PDU session for the second access of the MA PDU session.
[0174] Optionally, the first RAN and the second RAN belong to the same PLMN, and the first PDU session creation request and the second PDU session creation request are used to create two 3GPP accesses for the MA PDU session, respectively.
[0175] Optionally, if the UE receives the reporting indication request sent by the SMF in step S303, the second PDU session creation request carries the user plane security activation status between the UE and the first RAN.
[0176] Optionally, after the UE accesses the 3GPP network through the first RAN and completes authentication with the network, establishing a NAS security context between the UE and the AMF, it accesses the 3GPP network through the second RAN and completes authentication with the network, establishing a NAS security context between the UE and the corresponding AMF.
[0177] Furthermore, if the first RAN and the second RAN belong to the same PLMN, then the first RAN and the second RAN correspond to the same AMF, which stores the NAS layer security context corresponding to the UE. However, the connections corresponding to the two RANs use different RRC keys and user plane keys. If the first RAN and the second RAN belong to different PLMNs, then the first RAN and the second RAN correspond to different AMFs, and the two AMFs respectively store the NAS layer security context corresponding to the UE. However, the connections corresponding to the two RANs use different NAS keys, different access layer keys, and different user plane keys.
[0178] It is understood that in other embodiments, the AMF obtains the UE's context information and, based on the UE's context information, determines the RAN information of the two 3GPP accesses registered by the UE on the AMF, namely, the two RANs corresponding to the two 3GPP accesses (i.e., the two RANs belong to the same PLMN): the first RAN and the second RAN. The AMF can determine the RAN corresponding to the second 3GPP access of the MA PDU session supporting dual 3GPP access based on the RAN corresponding to the first 3GPP access. The SMF sends the user plane security activation status to the second RAN through the AMF. It is understood that the second RAN corresponding to the second 3GPP access of the MA PDU session supporting dual 3GPP access can also be obtained through other means.
[0179] S304, SMF sends the user plane security activation status to the second RAN, so that the second RAN and UE can perform user plane security activation based on the user plane security activation status.
[0180] Optionally, after receiving the second PDU session creation request, the SMF determines, based on the dual 3GPP access indication and PDU session identifier in the second PDU session creation request, that the second PDU session creation request is used to create a session on the second 3GPP access corresponding to an existing MA PDU session with the corresponding PDU session identifier.
[0181] The SMF obtains the user plane security activation status sent to the second RAN. Specifically, if the SMF sends a reporting instruction to the first RAN in step S303, the SMF uses the PDU session identifier to retrieve the context, and can obtain the context of the MA PDU session corresponding to the PDU session identifier. Further, the SMF can obtain the corresponding user plane security activation status from this context. If the user plane security activation status is carried in the PDU session creation request, the SMF can directly obtain the user plane security activation status from the second PDU session creation request. Optionally, the SMF can send the user plane security activation status to the AMF, and the AMF will then send the user plane security activation status to the second RAN.
[0182] Optionally, the SMF may send the user plane security activation status to the second RAN in the following ways: the SMF sends Namf_Communication_N1N2MessageTransfer to the AMF, and the AMF sends N2 PDU Session Request to the second RAN. That is, both Namf_Communication_N1N2MessageTransfer and N2 PDU Session Request carry the user plane security activation status.
[0183] Optionally, after receiving the user plane security activation state, the second RAN determines an RRC connection reconfiguration message based on the security activation state and sends the RRC connection reconfiguration message to the UE; wherein, the RRC connection reconfiguration message is used to perform user plane security activation between the second RAN and the UE, and the RRC connection reconfiguration message contains an indication of activating user plane integrity protection and confidentiality protection for each DRB of the session according to the security activation state.
[0184] Specifically, after receiving the user plane security activation status sent by the SMF, the second RAN determines whether to activate the confidentiality protection and integrity protection of the user plane based on the user plane security activation status; then it generates an RRC connection reconfiguration message, which carries an indication of whether to activate confidentiality protection and whether to activate integrity protection.
[0185] Optionally, the UE receives the RRC connection reconfiguration message sent by the second RAN, performs user plane security activation according to the corresponding indication in the RRC connection reconfiguration message, and sends an RRC connection reconfiguration complete message to the second RAN.
[0186] Specifically, after receiving the RRC connection reconfiguration message, the UE performs user plane security activation based on the indications in the RRC connection reconfiguration message regarding whether user plane confidentiality protection and integrity protection are activated. If the RRC connection reconfiguration message indicates that integrity protection is activated, the UE checks the integrity of the RRC connection reconfiguration message. If the UE successfully checks the integrity of the RRC connection reconfiguration message, the UE sends an RRC connection reconfiguration message completion message to the second RAN.
[0187] Thus, when a UE creates an MA PDU session supporting dual 3GPP access, if the SMF determines that the steering mode in the ATSSS rule corresponding to the MA PDU session includes the redundant mode and that the confidentiality protection or integrity protection of the user plane security policy is preferred, the SMF notifies the UE or RAN to report the user plane security activation state determined by the UE and RAN. This allows the RAN corresponding to the second 3GPP access of the MA PDU session to perform user plane security activation based on the user plane security activation state, thereby ensuring that the user plane security activation states of the two 3GPP accesses in the MA PDU session supporting dual 3GPP access are the same, and thus achieving consistency in the security protection states of the two 3GPP accesses in the MA PDU session supporting dual 3GPP access.
[0188] The following is through Figure 4 and Figure 5 This paper describes how, when a UE creates an MA PDU session supporting dual 3GPP access, if the steering mode in the ATSSS rule corresponding to the MA PDU session includes the redundant mode and the confidentiality protection or integrity protection of the user plane security policy is preferred, the SMF notifies the RAN to send the user plane security activation state to the SMF. The SMF then sends this user plane security activation state to the RAN corresponding to the other 3GPP access of the MA PDU session, so that the RAN and the UE can perform user plane security activation based on the user plane security activation state. This achieves consistency of the security protection states of the two 3GPP accesses in the MA PDU session supporting dual 3GPP access. Figure 4 The first RAN and the second RAN belong to the same PLMN. Figure 5 The first RAN and the second RAN belong to different PLMNs.
[0189] It is understood that the communication methods in the embodiments of this application are all MA PDU session creation processes. The implementation processes of each embodiment have the same steps. To avoid repetition, the same steps in the MA PDU session creation process are described in detail only in one or two embodiments. For the steps involved in other embodiments, please refer to the detailed description of the embodiments.
[0190] Please see Figure 4 , Figure 4 This is a flowchart illustrating a communication method provided in an embodiment of this application. Figure 4 As shown, the communication methods include: S401 to S408.
[0191] S401, The UE sends a first PDU session creation request to the SMF through the first RAN;
[0192] The first PDU session creation request is used to request the creation of a MA PDU session that supports dual 3GPP access on the first 3GPP access.
[0193] Optionally, the first PDU session creation request carries a request type, a PDU session identifier (PDU Session ID), and a dual 3GPP access indication; the request type is an MA PDU Request, which indicates that the PDU session creation request is used to create an MA PDU session; the dual 3GPP access indication indicates that the PDU session creation request is used to request the creation of an MA PDU session that supports dual 3GPP access.
[0194] In one optional implementation, the UE sends a PDU session establishment request (PDUSession Establishment Request) to the AMF through the first RAN. The PDU session establishment request carries the request type, PDU session ID, and dual 3GPP access indication. After receiving the first PDU session establishment request sent by the UE, the AMF determines that the current MA PDU session is an MA PDU session that supports dual 3GPP access based on the request type and dual 3GPP access in the first PDU session establishment request. Then, the AMF selects the SMF of the MA PDU session that supports dual 3GPP access. Then, the AMF sends a PDU session creation context request (Nsmf_PDUSession_CreateSMContext) to the SMF, wherein the PDU session creation context request carries the request type, PDU session ID, and dual 3GPP access indication.
[0195] Optionally, the UE registers with the network through the first RAN, completes two-way authentication between the UE and the network, and creates a corresponding non-access stratum (NAS) security context; then the UE encapsulates the PDU session creation request in a NAS transport message and sends it to the AMF, and then the AMF forwards the first PDU session creation request to the SMF.
[0196] Optionally, after receiving the first PDU session creation request, the SMF determines, based on the dual 3GPP access indication and the carried PDU session identifier, whether the request is intended to create a session on the second 3GPP access corresponding to an existing MA PDU session with the corresponding PDU session identifier. If it is not intended to create a session on the second 3GPP access corresponding to an existing MA PDU session with the corresponding PDU session identifier, the SMF continues to execute S302. Specifically, the SMF uses the PDU session identifier to retrieve the context and, if it does not obtain the context of the MA PDU session corresponding to the PDU session identifier, it determines that the request is not intended to create a PDU session for the second access of the MA PDU session.
[0197] After receiving the first PDU session creation request, S402 and SMF determine the ATSSS rules and user plane security policies corresponding to the MA PDU session.
[0198] Specifically, the SMF receives a first PDU session creation request forwarded via the AMF (the first PDU session creation request is forwarded via a PDU session creation context request). Based on the MA PDU session request type and dual 3GPP access indication, the SMF determines that the request is for creating an MA PDU session supporting dual 3GPP access. The SMF queries the UDM for the UE's subscription data and obtains the SMF's local policy. Based on the subscription data and local policy, the SMF determines whether the corresponding MA PDU session can be created. If it is determined that the corresponding MA PDU session cannot be created, a rejection message is sent to the UE. If it is determined that the MA PDU session can be created, the SMF selects the PCF and obtains the session policy for the corresponding MA PDU session from the PCF. Based on the session policy, the SMF determines the ATSSS rules, and based on the subscription data, local policy, and session policy, it determines the user plane security policy and confirms the user plane security policy supporting the MA PDU session. If the user plane security policy of the MA PDU session is satisfied, a corresponding context is created for the MA PDU session, which includes the session identifier, session policy, etc.
[0199] S403. If the steering mode in the ATSSS rule includes the redundant mode and the confidentiality protection or integrity protection of the user plane security policy is preferred, then the SMF sends a reporting indication request to the first RAN accessed by the UE.
[0200] The reporting instruction request is used to request the first RAN to send the user plane security activation status of the MA PDU session corresponding to the first 3GPP access to the SMF. The user plane security activation status includes whether the integrity protection and confidentiality protection of the user plane of the first 3GPP access are activated.
[0201] Optionally, the reporting instruction request carries a user plane security policy and a user plane security activation status reporting instruction. The user plane security activation status reporting instruction is used to instruct the first RAN to send the user plane security activation status of the MA PDU session corresponding to the first 3GPP access to the SMF.
[0202] Optionally, SMF determines whether the steering mode in the ATSSS rule includes the redundant mode and whether the confidentiality protection or integrity protection in the user plane security policy of the MA PDU session is preferred:
[0203] If the steering mode includes the redundant mode and the confidentiality or integrity protection of the user plane security policy of the MA PDU session is preferred, then the SMF sends a reporting instruction request to the first RAN, which carries the user plane security policy and the user plane security activation status reporting instruction.
[0204] If the steering mode does not include the redundant mode or the confidentiality and integrity protection of the user plane security policy of the MA PDU session does not include preferred, then the SMF does not need to send a reporting instruction request to the first RAN, or the SMF does not need to instruct the first RAN to send the user plane security activation status to the SMF in the reporting instruction request sent to the first RAN.
[0205] Regardless of whether the above conditions are met, the SMF sends the user plane security policy information for the session to the first RAN.
[0206] Optionally, the SMF may send the user plane security policy and user plane security activation status reporting indication to the first RAN in the following ways: the SMF sends Namf_Communication_N1N2MessageTransfer to the AMF and the AMF sends N2PDU Session Request to the first RAN. That is, both Namf_Communication_N1N2MessageTransfer and N2PDU Session Request carry the user plane security policy and user plane security activation status reporting indication.
[0207] Optionally, after the SMF determines that a corresponding MA PDU session can be created, the SMF also needs to select a UPF for the MA PDU session, determine the corresponding N4 rules for the session according to the session's policy, create an N4 connection (session) between the SMF and the UPF, and send the corresponding N4 rules to the selected UPF.
[0208] S404. The first RAN receives the reporting instruction request sent by the SMF, and sends the user plane security activation state to the SMF according to the reporting instruction request, so that the SMF saves the user plane security activation state in the context of the PDU session.
[0209] The user plane security activation state is determined after the first RAN and UE complete user plane security activation. Specifically, after the first RAN obtains the user plane security policy sent by the SMF, the first RAN generates an RRC connection reconfiguration message according to the security activation policy and sends the RRC connection reconfiguration message to the UE. The RRC connection reconfiguration message is used to perform user plane security activation between the first RAN and the UE. The RRC connection reconfiguration message carries an indication of activating user plane integrity protection and confidentiality protection for each DRB of the PDU session according to the security activation policy. After receiving the RRC connection reconfiguration message sent by the first RAN, the UE performs user plane security activation according to the corresponding indication in the RRC connection reconfiguration message. If the RRC connection reconfiguration message indicates that user plane integrity protection is activated, the UE also needs to verify the integrity of the RRC connection reconfiguration message. If the UE successfully verifies the integrity of the RRC connection reconfiguration message, the UE should send an RRC connection reconfiguration message to the eNB to complete the reconfiguration.
[0210] Furthermore, after the first RAN performs user plane security activation between the first RAN and the UE according to the user plane security policy and the first RAN's local policy, the first RAN sends the user plane security activation status to the SMF through the AMF according to the reporting instruction request. After receiving the user plane security activation status sent by the first RAN, the SMF stores the user plane security activation status in the context of the MA PDU session. The user plane security activation status is used to identify whether confidentiality protection and integrity protection are performed between the first RAN and the UE.
[0211] S405, the UE sends a second PDU session creation request to the SMF through the second RAN.
[0212] The second PDU session creation request is used to create a MAPDU session that supports dual 3GPP access on the second 3GPP access.
[0213] Optionally, the second PDU session creation request carries a request type and a PDU session identifier. The PDU session identifier in the second PDU session creation request is the same as the PDU session identifier in the first PDU session creation request. The request type is either an existing PDU session or a dual 3GPP access session for the MA PDU session currently being created.
[0214] Among them, the dual 3GPP access session is used to instruct the second PDU session creation request to request the creation of an MA PDU session that supports dual 3GPP access.
[0215] Furthermore, after receiving the second PDU session creation request sent by the UE, the SMF determines that the second PDU session creation request is used to request the creation of a session on the second 3GPP access corresponding to an existing MA PDU session with the PDU session identifier based on the session identifier and request type in the second PDU session creation request. The SMF obtains the PDU session context based on the PDU session identifier and the UE identity identifier, and then obtains the user plane security activation status of the PDU session on the first 3GPP access from the PDU session context.
[0216] It is understood that S405 is an optional step. After receiving the second PDU session creation request sent by the UE through the second RAN, the SMF determines the second RAN corresponding to the second 3GPP access that supports the MA PDU session for dual 3GPP access based on the second PDU session creation request sent by the second RAN. For example, after the AMF receives the second PDU session creation request, it obtains the UE's context information and determines the second RAN corresponding to the second 3GPP access that supports the MA PDU session for dual 3GPP access based on the UE's context information. The SMF then sends the user plane security activation status to the second RAN through the AMF. It is understood that in other embodiments, the UE accesses the 3GPP network through the first RAN and the second RAN respectively. The AMF obtains the UE's context information and determines the RAN information of the two 3GPP accesses registered by the UE on the AMF based on the UE's context information, that is, the two RANs corresponding to the two 3GPP accesses (i.e., the two RANs belong to the same PLMN): the first RAN and the second RAN. The AMF can determine the RAN corresponding to the second 3GPP access that supports the MA PDU session of dual 3GPP access based on the RAN corresponding to the first 3GPP access that supports the MA PDU session of dual 3GPP access. The SMF sends the user plane security activation status to the second RAN through the AMF. Then, S406 does not send the user plane security activation status to the second RAN only after receiving the second PDU session creation request sent by the UE through the second RAN. As long as the SMF obtains the user plane security activation status on the first 3GPP access and the second RAN on the second 3GPP access, it can send the user plane security activation status to the second RAN.
[0217] S406, SMF sends the user plane security activation status to the second RAN.
[0218] Optionally, the SMF may send the user plane security activation status to the second RAN in the following ways: the SMF sends Namf_Communication_N1N2MessageTransfer to the AMF, and the AMF sends N2 PDU SessionRequest to the second RAN. That is, both Namf_Communication_N1N2MessageTransfer and N2 PDU Session Request carry the user plane security activation status.
[0219] S407. After receiving the user plane security activation state, the second RAN determines the RRC connection reconfiguration message based on the security activation state and sends the RRC connection reconfiguration message to the UE.
[0220] The RRC Connection Reconfiguration message is used to activate user plane security between the second RAN and the UE. The RRC Connection Reconfiguration message contains an indication to activate user plane integrity protection and confidentiality protection for each DRB of the session according to the security activation status.
[0221] Specifically, after receiving the user plane security activation status sent by the SMF, the second RAN determines whether to activate the confidentiality protection and integrity protection of the user plane based on the user plane security activation status; then it generates an RRC connection reconfiguration message, which carries an indication of whether to activate confidentiality protection and whether to activate integrity protection.
[0222] S408. The UE receives the RRC connection reconfiguration message sent by the second RAN, performs user plane security activation according to the corresponding indication in the RRC connection reconfiguration message, and sends an RRC connection reconfiguration complete message to the second RAN.
[0223] Specifically, after receiving the RRC connection reconfiguration message, the UE performs user plane security activation based on the indications in the RRC connection reconfiguration message regarding whether user plane confidentiality protection and integrity protection are activated. If the RRC connection reconfiguration message indicates that integrity protection is activated, the UE checks the integrity of the RRC connection reconfiguration message. If the UE successfully checks the integrity of the RRC connection reconfiguration message, the UE sends an RRC connection reconfiguration complete message to the second RAN.
[0224] Thus, during the creation of a MA PDU session supporting dual 3GPP access, if the steering mode in the ATSSS rule corresponding to the MA PDU session includes the redundant mode and the confidentiality protection or integrity protection in the user plane security policy of the MA PDU session is preferred, then the SMF notifies the first RAN accessed by the UE to send the user plane security activation status of the MA PDU session on the first 3GPP access to the SMF; during the creation of the MA PDU session on the second 3GPP access by the UE, the SMF sends the user plane security activation status to the second RAN accessed by the UE, so that the second RAN performs user plane security activation of the second 3GPP access of the MA PDU session according to the user plane security activation status. Since the two 3GPP accesses of the MA PDU session have the same user plane security activation status, the consistency of the security protection status of the two 3GPP accesses of the MA PDU session is guaranteed.
[0225] Easy to understand Figure 4 If the two 3GPP accesses of a UE-created MA PDU session correspond to the same PLMN, the UE can select the same AMF and SMF when creating the two 3GPP accesses. If the two 3GPP accesses of a UE-created MA PDU session correspond to different PLMNs, the UE selects different AMFs and SMFs. The first SMF corresponding to the first 3GPP access of the MA PDU session sends the user plane security activation state to the second SMF corresponding to the second 3GPP access of the MA PDU session, and the second SMF then sends it to the corresponding RAN, thus ensuring the consistency of the user plane security protection state of the two 3GPP accesses in the MA PDU session. Please refer to [link to relevant documentation]. Figure 5 , Figure 5 This is a flowchart illustrating a communication method provided in an embodiment of this application.
[0226] as follows Figure 5 As shown, the communication methods include: S501 to S510.
[0227] S501, the UE sends a first PDU session creation request to the first SMF through the first RAN.
[0228] For details, please refer to step S401, which will not be repeated here.
[0229] S502. After receiving the first PDU session creation request, the first SMF determines the ATSSS rules and user plane security policy.
[0230] For details, please refer to step S402, which will not be repeated here.
[0231] S503. If the steering mode in the ATSSS rule includes the redundant mode and the confidentiality protection or integrity protection of the user plane security policy is preferred, then the first SMF sends a reporting indication request to the first RAN accessed by the UE.
[0232] For details, please refer to step S403, which will not be repeated here.
[0233] S504. The first RAN receives the reporting instruction request sent by the first SMF and sends the user plane security activation status to the first SMF according to the reporting instruction request.
[0234] For details, please refer to step S404, which will not be repeated here.
[0235] S505, the UE sends a second PDU session creation request to the second SMF through the second RAN.
[0236] The second PDU session creation request is used to create a MAPDU session that supports dual 3GPP access on the first 3GPP access.
[0237] Optionally, the second PDU session creation request carries a request type and a PDU session identifier. The request type is either an existing PDU session or a dual 3GPP access session, and the PDU session identifier is the same as the PDU session identifier in the first PDU session creation request.
[0238] Among them, the dual 3GPP access session is used to instruct the second PDU session creation request to request the creation of a dual 3GPP access MA PDU session.
[0239] Optionally, since the first RAN and the second RAN belong to different PLMNs, when the UE creates a MA PDU session supporting dual 3GPP access in the second RAN access network, the UE first sends a second PDU session creation request to the second AMF in the PLMN. The second AMF determines that the second PDU session creation request is used to request the creation of a MA PDU session supporting dual 3GPP access on the second 3GPP access. Then, the second AMF queries the UDM of the UE's home network based on the PDU session identifier carried in the second PDU session creation request to see if the MA PDU session already exists. If it exists, the second AMF obtains the first SMF identifier corresponding to the MA PDU session and selects the corresponding second SMF (e.g., the SMF supporting the MA PDU session supporting dual 3GPP access) according to the first SMF. Then, the second AMF forwards the second PDU session creation request to the second SMF.
[0240] Specifically, the second PDU session creation request carries the UE's 5G-GUTI. The UE sends the second PDU session creation request to the network side. After receiving the second PDU session creation request, the second AMF obtains the identifier of the first AMF (Globally Unique AMF Identifier, GUAMI) based on the 5G-GUTI. The second AMF determines the UE's registered PLMN and the corresponding first AMF based on the GUAMI. Since the UE registers and authenticates in this PLMN, it can obtain the UE's Subscription Permanent Identifier (SUPI). Then, it sends a query request (Nudm_SDM_Get) to the corresponding UDM of the UE's PLMN to query the SMF corresponding to the SUPI and the PDU session identifier, i.e., the first SMF. Then, it selects the corresponding second SMF based on the first SMF.
[0241] Among them, <5G-GUTI> = <guami>+<5G-TMSI>, the GUAMI field of 5G-GUTI includes the identifier of the PLMN registered by the UE.
[0242] Optionally, the method for selecting the corresponding second SMF based on the first SMF is as follows: if the DNN (Data Network Name) corresponding to the second SMF is the same as the DNN corresponding to the first SMF, and the second SMF can establish a direct or indirect connection with the first SMF, then the second SMF can be determined to be the required second SMF.
[0243] S506, The second SMF sends a PDU session context creation request to the first SMF.
[0244] Specifically, the second SMF sends a PDU session context creation request to the first SMF to request the user plane security activation status corresponding to the first 3GPP access that supports dual 3GPP access.
[0245] Optionally, the PDU session context creation request carries the PDU session identifier and the request type, which is a MAPDU session request.
[0246] Optionally, after the second AMF determines the second SMF, it sends a second PDU session creation request to the second SMF via Nsmf_PDUSession_CreateSMContextRequest / Nsmf_PDUSession_UpdateSMContext Request, wherein Nsmf_PDUSession_CreateSMContext Request / Nsmf_PDUSession_UpdateSMContext Request carries the first SMF identifier and the PDU session identifier.
[0247] S507. The first SMF sends a PDU session context creation response to the second SMF;
[0248] Optionally, the first SMF obtains the PDU session context based on the received PDU session identifier and UE identity identifier (see S305 for details), and then obtains the user plane security activation status of the PDU session on the first 3GPP access from the PDU session context.
[0249] The PDU session context creation response carries the user plane security activation status of the first 3GPP access.
[0250] Optionally, the PDU session context creation request carries the PDU session identifier, and the PDU session context creation response also carries relevant context information. The first SMF determines the corresponding PDU session context information based on the PDU session identifier, and then sends the corresponding PDU session context information and user plane security activation status to the second SMF.
[0251] Optionally, if the steering mode in the ATSSS rules of the MA PDU session does not include the redundant mode, or if the confidentiality protection of the user plane security policy does not include preferred and the integrity protection does not include preferred, then the PDU session context creation response does not carry the user plane security activation state.
[0252] Optionally, after the first SMF sends a PDU session context creation response to the second SMF, it is not necessary to delete the context information of the PDU session.
[0253] S508, the second SMF sends the user plane security activation status to the second RAN.
[0254] Optionally, after receiving the PDU session context creation response sent by the first SMF, the second SMF obtains the user plane security activation status of the first 3GPP access from the PDU session context creation response.
[0255] For the specific sending process, please refer to step S406.
[0256] S509. After receiving the user plane security activation state, the second RAN generates an RRC connection reconfiguration message based on the user plane security activation state and sends the RRC connection reconfiguration message to the UE.
[0257] S510: The UE receives the RRC connection reconfiguration message sent by the second RAN, performs user plane security activation according to the corresponding indication in the RRC connection reconfiguration message, and sends an RRC connection reconfiguration completion message to the second RAN.
[0258] For the specific activation process, please refer to steps S407-S408.
[0259] Thus, if the two RANs corresponding to the two 3GPP accesses of the MA PDU session supporting 3GPP access created by the UE belong to two different PLMNs, when creating the MA PDU session on the second 3GPP access, the user plane security activation state is transmitted through the SMF corresponding to the two PLMNs, and the user plane security activation state is sent to the second RAN corresponding to the second 3GPP access of the MA PDU session. The second RAN then performs user plane security activation between the UE and the second RAN based on the user plane security activation state, so as to achieve consistency of the security protection state of the two 3GPP accesses of the MA PDU session.
[0260] The following is through Figure 6 and Figure 7 This paper describes how, when a UE creates a MA PDU session supporting dual 3GPP access, if the steering mode in the ATSSS rule corresponding to the MA PDU session includes the redundant mode and the confidentiality protection or integrity protection of the user plane security policy is preferred, the SMF notifies the UE to report the user plane security activation state. Based on this user plane security activation state, the SMF sends the information to the RAN corresponding to the other 3GPP access of the MA PDU session, so that the RAN and the UE can perform user plane security activation according to the user plane security activation state. This achieves consistency in the security protection states of the two 3GPP accesses in the MA PDU session supporting dual 3GPP access. Figure 6 The first RAN and the second RAN belong to the same PLMN. Figure 7 The first RAN and the second RAN belong to different PLMNs.
[0261] Please see Figure 6 , Figure 6 This is a flowchart illustrating a communication method provided in an embodiment of this application. Figure 6 As shown, the communication methods include: S601 to S607.
[0262] S601, The UE sends a first PDU session creation request to the SMF through the first RAN;
[0263] After receiving the first PDU session creation request, S602 and SMF determine the ATSSS rules and user plane security policies corresponding to the MA PDU session.
[0264] S603. If the steering mode in the ATSSS rule includes the redundant mode and the confidentiality protection or integrity protection of the user plane security policy is preferred, then the SMF sends a reporting instruction request to the UE.
[0265] The reporting instruction request is used to instruct the UE to send the user plane security activation status of the MA PDU session on the first 3GPP access to the SMF.
[0266] Optionally, the reporting instruction request carries a user plane security policy and a user plane security activation status reporting instruction. The user plane security activation status reporting instruction is used to instruct the UE to send the user plane security activation status of the first 3GPP access PDU session to the SMF. The user plane security activation status includes whether integrity protection is activated and whether confidentiality protection is activated.
[0267] S604. The UE sends a second PDU session creation request to the SMF through the second RAN. The second PDU session creation request carries the user plane security activation status.
[0268] S605 and SMF send the user plane security activation status to the second RAN.
[0269] S606. After receiving the user plane security activation state, the second RAN generates an RRC connection reconfiguration message based on the user plane security activation state and sends the RRC connection reconfiguration message to the UE.
[0270] S607. The UE receives the RRC connection reconfiguration message sent by the second RAN, performs user plane security activation according to the corresponding indication in the RRC connection reconfiguration message, and sends an RRC connection reconfiguration complete message to the second RAN.
[0271] Thus, during the dual 3GPP access creation process of an MA PDU session supporting dual 3GPP access, if the steering mode in the ATSSS rule corresponding to the MA PDU session includes the redundant mode and the confidentiality protection or integrity protection in the user plane security policy of the MA PDU session is preferred, then the SMF notifies the UE to report the user plane security activation state of the first 3GPP access of the MA PDU session. During the creation of the MA PDU session on the second 3GPP access by the UE, since the second PDU session creation request carries the user plane security activation state, the SMF sends the user plane security activation state to the second RAN accessed by the UE, so that the second RAN performs user plane security activation of the second 3GPP access of the MA PDU session according to the user plane security activation state. Since the two 3GPP accesses of the MA PDU session have the same user plane security activation state, the consistency of the security protection state of the two 3GPP accesses of the MA PDU session is guaranteed.
[0272] Easy to understand Figure 6 If the two 3GPP accesses of the MA PDU session created by the UE correspond to the same PLMN, the UE can select the same AMF and SMF when creating the two 3GPP accesses of the MA PDU session. If the two 3GPP accesses of the MA PDU session created by the UE correspond to different PLMNs, the UE can select different AMF and SMF when creating the two 3GPP accesses of the MA PDU session. The UE reports the user plane security activation state when creating the MA PDU session, and the second SMF sends it to the corresponding RAN so that the RAN and the UE can activate the user plane security state according to the user plane security activation state, thereby ensuring the consistency of the user plane security protection state of the two 3GPP accesses of the MA PDU session.
[0273] Please see Figure 7 The following is a flowchart illustrating a communication method provided in an embodiment of this application. Figure 7 As shown, the communication methods include: S701 to S707.
[0274] S701, The UE sends a first PDU session creation request to the first SMF through the first RAN;
[0275] S702. After receiving the first PDU session creation request, the first SMF determines the ATSSS rules and user plane security policy.
[0276] S703. If the steering mode in the ATSSS rule includes the redundant mode and the confidentiality protection or integrity protection of the user plane security policy is preferred, then the SMF sends a reporting instruction request to the UE.
[0277] The reporting instruction request is used to instruct the UE to send the user plane security activation status of the first 3GPP access PDU session to the SMF.
[0278] Optionally, the reporting instruction request carries a user plane security activation status reporting instruction and an ATSSS rule. The user plane security activation status reporting instruction instructs the UE to send the user plane security activation status of the first 3GPP access PDU session to the SMF.
[0279] S704, the UE sends a second PDU session creation request to the second SMF through the second RAN.
[0280] The second PDU session creation request is used to create a MAPDU session supporting dual 3GPP access on the second 3GPP access, and the second PDU session creation request carries the user plane security activation status on the first 3GPP access.
[0281] S705, the second SMF sends the user plane security activation status to the second RAN.
[0282] S706. After receiving the user plane security activation state, the second RAN generates an RRC connection reconfiguration message based on the user plane security activation state and sends the RRC connection reconfiguration message to the UE.
[0283] S707, the UE receives the RRC connection reconfiguration message sent by the second RAN, performs user plane security activation according to the corresponding indication in the RRC connection reconfiguration message, and sends an RRC connection reconfiguration complete message to the second RAN.
[0284] Thus, if the two RANs corresponding to the two 3GPP accesses of the MA PDU session supporting 3GPP access created by the UE belong to two different PLMNs, when creating the MA PDU session on the first 3GPP access, the user plane security activation state is carried in the second PDU session creation request sent by the UE. The SMF then sends this user plane security activation state to the second RAN corresponding to the second 3GPP access of the MA PDU session, so that the second RAN performs user plane security activation between the UE and the second RAN based on the user plane security activation state, thereby achieving consistency in the security protection state of the two 3GPP accesses of the MA PDU session.
[0285] Specifically, when a UE creates an MA PDU session that supports dual 3GPP access, the AMF can obtain the ATSSS rules and user plane security policies of the MA PDU session. Based on the ATSSS rules and user plane security policies, the AMF makes a judgment. If the steering mode in the ATSSS rules corresponding to the MA PDU session includes the redundant mode and the confidentiality protection or integrity protection of the user plane security policy is preferred, then the AMF notifies the UE or RAN to report the user plane security activation status. This enables the RAN corresponding to the second 3GPP access of the MA PDU session to perform user plane security activation based on the user plane security activation status, thereby achieving consistency in the security protection status of the two 3GPP accesses of the MA PDU session that supports dual 3GPP access.
[0286] Please see Figure 8 , Figure 8 This is a flowchart illustrating a communication method provided in an embodiment of this application. Figure 8 As shown, the communication methods include: S801 to S804.
[0287] S801, AMF receives the first PDU session creation request sent by the UE through the first RAN. The first PDU session creation request is used to request the creation of an MA PDU session that supports dual 3GPP access on the first 3GPP access.
[0288] Optionally, the first PDU session creation request carries a PDU session identifier, a request type, and a dual 3GPP access indication. The request type is a multi-access PDU request, and the dual 3GPP access indication is used to indicate that the MA PDU session to be created supports dual 3GPP access.
[0289] S802, AMF determines the ATSSS rules and user plane security policies corresponding to the MA PDU session.
[0290] Optionally, after receiving the first Protocol Data Unit (PDU) session creation request sent by the UE through the first Radio Access Node (RAN), the AMF forwards it to the SMF. After determining the subscription data and local policy corresponding to the MA PDU session, the SMF determines whether the corresponding MA PDU session can be created based on the subscription data and local policy. If it is determined that the corresponding MA PDU session cannot be created, a rejection message is sent to the UE. If it is determined that the MA PDU session can be created, the PCF is selected, and the session policy of the corresponding MA PDU session is obtained from the PCF. The ATSSS rules and user plane security policies are determined based on the session policy. Then, the SMF sends the ATSSS rules and user plane security policies to the AMF.
[0291] S803. If the steering mode in the ATSSS rule includes the redundant mode and the confidentiality protection or integrity protection of the user plane security policy is preferred, then the AMF sends a reporting instruction request to the first RAN or UE. The reporting instruction request is used to instruct the first RAN or UE to report the user plane security activation status to the AMF. The user plane security activation status includes whether the integrity protection and confidentiality protection of the user plane data transmitted between the first RAN and the UE are activated.
[0292] Optionally, after obtaining the ATSSS rules and user plane security policy for the MA PDU session, the AMF determines whether the steering mode in the ATSSS rules includes the redundant mode and whether the confidentiality protection or integrity protection in the user plane security policy of the MA PDU session is preferred.
[0293] If the steering mode includes the redundant mode and the confidentiality or integrity protection of the user plane security policy of the MA PDU session is preferred, then the AMF sends a reporting indication request to the first RAN or UE, and the reporting indication request carries the user plane security activation status reporting indication.
[0294] If the steering mode does not include the redundant mode or the confidentiality and integrity protection of the user plane security policy for the MA PDU session does not include preferred, then the AMF does not need to send a reporting instruction request to the first RAN or UE.
[0295] Optionally, if the AMF sends a reporting indication request to the first RAN, after receiving the reporting indication request, the first RAN sends the user plane security activation status on the first 3GPP access to the AMF; if the AMF sends a reporting indication request to the UE, after receiving the reporting indication request, the UE sends the user plane security activation status on the first 3GPP access to the corresponding AMF on the network side through the second PDU session creation request.
[0296] Optionally, after S803, the method further includes: the AMF receiving a second PDU session creation request sent by the UE through the second RAN. The second PDU session creation request is used to request the creation of a MA PDU session supporting dual 3GPP access on the second 3GPP access. After receiving the second PDU session creation request sent by the UE through the second RAN, the AMF determines the second RAN corresponding to the second 3GPP access for the MA PDU session supporting dual 3GPP access based on the second PDU session creation request. For example, after receiving the second PDU session creation request, the AMF obtains the UE's context information and determines the second RAN corresponding to the second 3GPP access for the MA PDU session supporting dual 3GPP access based on the UE's context information.
[0297] It is understood that in other embodiments, the AMF obtains the UE's context information and determines the RAN information of the two 3GPP accesses registered by the UE on the AMF based on the UE's context information, that is, the two RANs corresponding to the two 3GPP accesses (i.e., the two RANs belong to the same PLMN): the first RAN and the second RAN. The AMF can determine the RAN corresponding to the second 3GPP access of the MA PDU session that supports dual 3GPP access based on the RAN corresponding to the first 3GPP access of the MA PDU session that supports dual 3GPP access. Then the AMF sends the user plane security activation status to the second RAN.
[0298] S804, AMF sends the user plane security activation status to the second RAN, so that the second RAN and UE can perform user plane security activation based on the user plane security activation status.
[0299] Thus, when a UE creates an MA PDU session supporting dual 3GPP access, if the AMF determines that the steering mode in the ATSSS rule corresponding to the MA PDU session includes the redundant mode and that the confidentiality protection or integrity protection of the user plane security policy is preferred, the AMF notifies the UE or RAN to report the user plane security activation state determined by the UE and RAN. This allows the RAN corresponding to the second 3GPP access of the MA PDU session to perform user plane security activation based on the user plane security activation state, thereby ensuring that the user plane security activation states of the two 3GPP accesses in the MA PDU session supporting dual 3GPP access are the same, and thus achieving consistency in the security protection states of the two 3GPP accesses in the MA PDU session supporting dual 3GPP access.
[0300] The following is combined with Figure 9 and Figure 10 This document describes how, when a UE creates a MA PDU session supporting dual 3GPP access on the first 3GPP access, the AMF obtains the ATSSS rules and user plane security policy corresponding to the MA PDU session. If the steering mode in the ATSSS rules includes the redundant mode and the confidentiality protection or integrity protection in the user plane security policy of the MA PDU session is preferred, the AMF sends a reporting instruction request to the first RAN accessed by the UE. This allows the first RAN to report the user plane security activation status determined by the first RAN and the UE to the AMF after completing user plane security activation with the UE. When the UE creates a MA PDU session supporting dual 3GPP access on the first 3GPP access, the AMF sends the user plane security activation status corresponding to the MA PDU session to the corresponding second RAN. This allows the second RAN and the UE to perform user plane security activation based on the user plane security activation status. Since the two 3GPP accesses of the MA PDU session supporting dual 3GPP access have the same user plane security activation status, the consistency of the two 3GPP accesses in the MA PDU session supporting dual 3GPP access is guaranteed. Figure 9 The first RAN and the second RAN belong to the same PLMN. Figure 10 The first RAN and the second RAN belong to different PLMNs.
[0301] Please see Figure 9 This is a flowchart illustrating a communication method provided in an embodiment of this application. Figure 9 As shown, the communication methods include: S901 to S910.
[0302] S901, the UE sends a first PDU session creation request to the AMF through the first RAN. The first PDU session creation request is used to request the creation of an MA PDU session that supports dual 3GPP access on the first 3GPP access.
[0303] S902. After receiving the first PDU session creation request, the AMF selects the SMF based on the first PDU session creation request and sends a PDU session creation context request to the SMF.
[0304] Optionally, the PDU session creation context request is Nsmf_PDUSession_CreateSMContext.
[0305] S903 and SMF request the ATSSS rules and user plane security policies corresponding to the MA PDU session based on the PDU session creation context request.
[0306] Optionally, after the SMF determines the subscription data and local policy corresponding to the MA PDU session based on the PDU session creation context request, it determines whether the corresponding MA PDU session can be created based on the subscription data and local policy. If it is determined that the corresponding MA PDU session cannot be created, a rejection message is sent to the UE; if it is determined that the MA PDU session can be created, the PCF is selected, and the session policy of the corresponding MA PDU session is obtained from the PCF. The ATSSS rule, N4 rule and user plane security policy are determined based on the session policy.
[0307] S904, SMF sends a transmission message to AMF.
[0308] The transmitted message carries the ATSSS rules and user plane security policies corresponding to the MA PDU session.
[0309] Optionally, the transmission message is Nsmf_Communication_N1N2MessageTransfer.
[0310] After receiving the PDU session creation context response, if the steering mode in the ATSSS rule includes the redundant mode and the confidentiality protection or integrity protection of the user plane security policy is preferred, then the AMF sends a reporting indication request to the first RAN accessed by the UE.
[0311] The reporting instruction request carries the user plane security policy and the user plane security activation status reporting instruction. The reporting instruction request is used to instruct the first RAN to send the user plane security activation status of the first 3GPP access PDU session to the AMF.
[0312] Specifically, after determining the ATSSS rules and user plane security policies corresponding to the MA PDU session, the AMF determines whether the steering mode in the ATSSS rules includes the redundant mode and whether the confidentiality protection or integrity protection in the user plane security policy of the MA PDU session is preferred.
[0313] If the steering mode includes the redundant mode and the confidentiality protection or integrity protection of the user plane security policy of the MA PDU session is preferred, then the AMF sends a reporting instruction request to the first RAN, which carries the user plane security policy and the user plane security activation status reporting instruction.
[0314] If the steering mode does not include the redundant mode or the confidentiality and integrity protection of the user plane security policy for the MA PDU session does not include preferred, then the AMF sends a reporting instruction request to the first RAN, carrying the user plane security policy.
[0315] Optionally, the AMF sends an N2 PDU Session Request to the first RAN, thereby enabling the AMF to send the user plane security policy and user plane security activation status reporting indication to the first RAN.
[0316] S906, The first RAN sends the user plane security activation status to the AMF;
[0317] Specifically, after receiving the reporting instruction request sent by the AMF, the first RAN sends the user plane security activation status on the first 3GPP access to the AMF according to the reporting instruction request.
[0318] In one optional implementation, after receiving the user plane security activation state sent by the first RAN, the AMF stores the user plane security activation state in the AMF; in another optional implementation, after receiving the user plane security activation state sent by the first RAN, the AMF sends the user plane security activation state to the corresponding SMF, and the SMF stores the user plane security activation state in the context of the corresponding PDU session.
[0319] S907, the UE sends a second PDU session creation request to the AMF through the second RAN.
[0320] The second PDU session creation request is used to create a MAPDU session that supports dual 3GPP access on the second 3GPP access.
[0321] The first RAN and the second RAN belong to the same PLMN.
[0322] It is understood that S907 is an optional step. After receiving the second PDU session creation request sent by the UE through the second RAN, the AMF determines the second RAN corresponding to the second 3GPP access that supports the MA PDU session for dual 3GPP access based on the second PDU session creation request sent by the second RAN. For example, after receiving the second PDU session creation request, the AMF obtains the UE's context information and determines the second RAN corresponding to the second 3GPP access that supports the MA PDU session for dual 3GPP access based on the UE's context information. The AMF then sends the user plane security activation status to the second RAN. It is understood that in other embodiments, the UE accesses the 3GPP network through the first RAN and the second RAN respectively. The AMF obtains the UE's context information and determines the RAN information of the two 3GPP accesses registered by the UE on the AMF based on the UE's context information, that is, the two RANs corresponding to the two 3GPP accesses (i.e., the two RANs belong to the same PLMN): the first RAN and the second RAN. The AMF can determine the RAN corresponding to the second 3GPP access that supports the MA PDU session of dual 3GPP access based on the RAN corresponding to the first 3GPP access that supports the MA PDU session of dual 3GPP access. The SMF sends the user plane security activation status to the second RAN through the AMF. Then, S406 does not send the user plane security activation status to the second RAN only after receiving the second PDU session creation request sent by the UE through the second RAN. As long as the AMF obtains the user plane security activation status on the first 3GPP access and the second RAN corresponding to the second 3GPP access, it can send the user plane security activation status to the second RAN.
[0323] S908 and AMF send the user plane security activation status to the second RAN.
[0324] Optionally, after receiving the second PDU session creation request sent by the UE, the AMF determines that the second PDU session creation request is used to create a MA PDU session supporting dual 3GPP access on the second 3GPP access, and then obtains the user plane security activation state corresponding to the first 3GPP access of the MA PDU session according to the PDU session identifier; then sends the user plane security activation state to the second RAN so that the second RAN performs user plane security activation between the UE and the second RAN according to the user plane security activation state.
[0325] S909. After receiving the user plane security activation state, the second RAN generates an RRC connection reconfiguration message based on the user plane security activation state and sends the RRC connection reconfiguration message to the UE.
[0326] S910, the UE receives the RRC connection reconfiguration message sent by the second RAN, performs user plane security activation according to the corresponding indication in the RRC connection reconfiguration message, and sends an RRC connection reconfiguration completion message to the second RAN.
[0327] Thus, during the creation of a MA PDU session supporting dual 3GPP access, if the steering mode in the ATSSS rule corresponding to the MA PDU session includes the redundant mode and the confidentiality protection or integrity protection in the user plane security policy of the MA PDU session is preferred, then the AMF notifies the first RAN accessed by the UE to report the user plane security activation status of the first 3GPP access of the MA PDU session. During the creation of the MA PDU session by the UE, the AMF sends the user plane security activation status to the RAN accessed by the UE, so that the RAN performs user plane security activation of the second 3GPP access according to the user plane security activation status. Since the two 3GPP accesses of the MA PDU session have the same user plane security activation status, the consistency of the security protection status of the two 3GPP accesses of the MA PDU session is guaranteed.
[0328] In one alternative implementation, Figure 9 In addition to S906, the following also include:
[0329] S906a, AMF forwards the user plane security activation state to SMF so that SMF stores the first 3GPP access corresponding user plane security activation state of MA PDU session.
[0330] Accordingly, following S907, the following are included:
[0331] S907a, AMF sends a PDU session creation request to SMF;
[0332] After receiving the forwarded second PDU session creation request, S908a and SMF send a transport message to AMF, which carries the user plane security activation status corresponding to the first 3GPP access of the MA PDU session.
[0333] Thus, when the UE creates the first 3GPP access for a MA PDU session that supports dual 3GPP access, the first RAN sends the user plane security activation status of the first 3GPP access to the AMF, and the AMF sends the user plane security activation status corresponding to the first 3GPP access of the MA PDU session to the second RAN.
[0334] Easy to understand Figure 9 If the two 3GPP accesses of a UE-created MA PDU session correspond to the same PLMN, the UE can select the same AMF when creating the two 3GPP accesses. If the two 3GPP accesses of a UE-created MA PDU session correspond to different PLMNs, the UE selects different AMFs when creating the two 3GPP accesses. The first SMF corresponding to the first 3GPP access of the MA PDU session sends the user activation status to the second SMF corresponding to the second 3GPP access of the MA PDU session, and the second AMF then sends it to the corresponding RAN, thus ensuring the consistency of the user plane security protection status of the two 3GPP accesses in the MA PDU session. Please refer to [link to relevant documentation]. Figure 10 , Figure 10 This is a flowchart illustrating a communication method provided in an embodiment of this application. Figure 10 As shown, the communication method includes: S1001 to S1010.
[0335] S1001, The UE sends a first PDU session creation request to the first AMF through the first RAN;
[0336] The first PDU session creation request is used to request the creation of a MA PDU session that supports dual 3GPP access on the first 3GPP access.
[0337] S1002. After receiving the first PDU session creation request, the first AMF determines the first SMF and sends a PDU session creation context request to the first SMF.
[0338] S1003. The first SMF requests the ATSSS rules and user plane security policies corresponding to the MA PDU session based on the PDU session creation context request.
[0339] S1004, the first SMF sends a transmission message to the first AMF.
[0340] The transmitted message carries the ATSSS rules and user plane security policies corresponding to the MA PDU session.
[0341] S1005. After receiving the PDU session creation context response, if the steering mode in the ATSSS rule includes the redundant mode and the confidentiality protection or integrity protection of the user plane security policy is preferred, then the AMF sends a reporting indication request to the first RAN accessed by the UE.
[0342] S1006, The first RAN sends the user plane security activation status to the first AMF;
[0343] S1007, the UE sends a second PDU session creation request to the second AMF through the second RAN.
[0344] The second PDU session creation request is used to request the creation of a MA PDU session that supports dual 3GPP access on the second 3GPP access.
[0345] Among them, the first RAN and the second RAN belong to different PLMNs.
[0346] S1008, the second AMF obtains the user plane security activation status corresponding to the first 3GPP access of the MA PDU session supporting dual 3GPP access, and sends the user plane security activation status to the second RAN.
[0347] The user plane security activation state is used to enable the second RAN to perform user plane security activation between the UE and the second RAN based on the user plane security activation state.
[0348] Optionally, after receiving the second PDU session creation request sent by the UE, the second AMF can obtain the user plane security activation status corresponding to the first 3GPP access of the MA PDU session supporting dual 3GPP access through the first AMF or through the second SMF.
[0349] S1009. After receiving the user plane security activation state, the second RAN generates an RRC connection reconfiguration message based on the user plane security activation state and sends the RRC connection reconfiguration message to the UE.
[0350] S1010: The UE receives the RRC connection reconfiguration message sent by the second RAN, performs user plane security activation according to the corresponding indication in the RRC connection reconfiguration message, and sends an RRC connection reconfiguration completion message to the second RAN.
[0351] Thus, if the two RANs corresponding to the two 3GPP accesses in the MA PDU session supported by the UE belong to two different PLMNs, then when the MA PDU session is created, the user plane security activation state is transmitted through the AMF corresponding to the two PLMNs, and the user plane security activation state is sent to the RAN corresponding to the second 3GPP access in the MA PDU session. The second RAN then performs user plane security activation between the UE and the second RAN based on the user plane security activation state, so as to achieve consistency of the security protection state of the two 3GPP accesses in the MA PDU session.
[0352] Optionally, after S1006, the method further includes:
[0353] S1006a, AMF forwards the user plane security activation status report to SMF so that SMF stores the user plane security activation status corresponding to the first 3GPP access of the MA PDU session.
[0354] Accordingly, following S1007, the method also includes:
[0355] S1007a, The second AMF sends a PDU session creation context request to the second SMF;
[0356] Specifically, the second PDU session creation request is forwarded to the second SMF through the PDU session creation context request, and the user plane security activation status corresponding to the first 3GPP access of the MA PDU session is obtained through the SMF.
[0357] S1007b: The second SMF sends a PDU session creation context response to the second AMF;
[0358] S1007c, The second SMF sends a PDU session creation context request to the first SMF;
[0359] S1007d, the first SMF sends a PDU session creation context response to the second SMF, carrying the user plane security activation status of the first 3GPP access corresponding to the MA PDU session;
[0360] S1007e, the second SMF sends a transmission message to the second AMF, the transmission message carrying the user plane security activation status corresponding to the first 3GPP access of the MA PDU session.
[0361] Thus, the second AMF requests the user plane security activation state corresponding to the first 3GPP access of the MA PDU session from the first SMF through the second SMF, so as to ensure that the user plane security activation states of the two 3GPP accesses of the MA PDU session supporting dual 3GPP access are consistent, thereby achieving consistency of the security protection states of the two 3GPP accesses.
[0362] The following is through Figure 11 and Figure 12 This document describes how, when a UE creates a MA PDU session supporting dual 3GPP access, if the steering mode in the ATSSS rule corresponding to the MA PDU session includes the redundant mode and the confidentiality protection or integrity protection of the user plane security policy is set to preferred, the AMF notifies the UE to report the user plane security activation state. Based on this user plane security activation state, the AMF sends the information to the RAN corresponding to the other 3GPP access in the MA PDU session. This ensures that the RAN and UE perform user plane security activation based on the user plane security activation state, thereby achieving consistency in the security protection states of the two 3GPP accesses in the MA PDU session supporting dual 3GPP access. Figure 11 The first RAN and the second RAN belong to the same PLMN. Figure 12 The first RAN and the second RAN belong to different PLMNs.
[0363] Please see Figure 11 This is a flowchart illustrating a communication method provided in an embodiment of this application. Figure 11 As shown, the communication methods include: S1101 to S1109.
[0364] S1101, The UE sends a first PDU session creation request to the AMF through the first RAN;
[0365] The first PDU session creation request is used to request the creation of a MA PDU session that supports dual 3GPP access on the first 3GPP access.
[0366] S1102. After receiving the first PDU session creation request, the AMF selects the SMF based on the first PDU session creation request and sends a PDU session creation context request to the SMF.
[0367] Optionally, the PDU session creation context request is Nsmf_PDUSession_CreateSMContext.
[0368] S1103, SMF requests the ATSSS rules and user plane security policies corresponding to the MA PDU session based on the PDU session creation context request.
[0369] Optionally, after the SMF determines the subscription data and local policy corresponding to the MA PDU session based on the PDU session creation context request, it determines whether the corresponding MA PDU session can be created based on the subscription data and local policy. If it is determined that the corresponding MA PDU session cannot be created, a rejection message is sent to the UE; if it is determined that the MA PDU session can be created, the PCF is selected, and the session policy of the corresponding MA PDU session is obtained from the PCF. The ATSSS rule, N4 rule and user plane security policy are determined based on the session policy.
[0370] Optionally, the PDU session creation context request carries the request type, PDU session ID, and dual 3GPP access indication, wherein the request type is MA PDU Request.
[0371] S1104, SMF sends a transmission message to AMF.
[0372] The transmitted message carries the ATSSS rules and user plane security policies corresponding to the MA PDU session.
[0373] Optionally, the transmission message is Nsmf_Communication_N1N2MessageTransfer.
[0374] S1105. After receiving the PDU session creation context response, if the steering mode in the ATSSS rule includes the redundant mode and the confidentiality protection or integrity protection of the user plane security policy is preferred, then the AMF sends a reporting indication request to the UE.
[0375] The reporting instruction request carries the user plane security policy and the user plane security activation status reporting instruction. The reporting instruction request is used to instruct the UE to report the user plane security activation status of the MA PDU session on the first 3GPP access to the AMF.
[0376] Specifically, after determining the ATSSS rules and user plane security policies corresponding to the MA PDU session, the AMF determines whether the steering mode in the ATSSS rules includes the redundant mode and whether the confidentiality protection or integrity protection in the user plane security policy of the MA PDU session is preferred.
[0377] If the steering mode includes the redundant mode and the confidentiality protection or integrity protection of the user plane security policy of the MA PDU session is preferred, then the AMF sends a reporting indication request to the UE. The reporting indication request carries the user plane security policy and the user plane security activation status reporting indication.
[0378] If the steering mode does not include the redundant mode or the confidentiality and integrity protection of the user plane security policy for the MA PDU session does not include preferred, then the AMF does not need to send a reporting indication request to the UE or the reporting indication request does not carry a user plane security activation status reporting indication.
[0379] Optionally, the N2 PDU Session Request carries the user plane security policy and user plane security activation status reporting indication. The AMF sends the user plane security policy and user plane security activation status reporting indication to the first RAN through the N2 PDU Session Request.
[0380] S1106, The UE sends a second PDU session creation request to the AMF through the second RAN.
[0381] The second PDU session creation request is used to create a MAPDU session supporting dual 3GPP access on the second 3GPP access, and the second PDU session creation request carries the user plane security activation status.
[0382] The first RAN and the second RAN belong to the same PLMN.
[0383] S1107, AMF sends the user plane security activation status to the second RAN so that the second RAN and UE can perform user plane security activation based on the user plane security activation status.
[0384] S1108. After receiving the user plane security activation state, the second RAN generates an RRC connection reconfiguration message based on the user plane security activation state and sends the RRC connection reconfiguration message to the UE.
[0385] S1109, the UE receives the RRC connection reconfiguration message sent by the second RAN, performs user plane security activation according to the corresponding indication in the RRC connection reconfiguration message, and sends an RRC connection reconfiguration completion message to the second RAN.
[0386] Thus, during the creation of the first 3GPP access in a MA PDU session supporting dual 3GPP access, if the steering mode in the ATSSS rule corresponding to the MA PDU session includes the redundant mode and the confidentiality protection or integrity protection in the user plane security policy of the MA PDU session is preferred, the AMF notifies the UE to report the user plane security activation status of the first 3GPP access of the MA PDU session. During the creation of the MA PDU session on the second 3GPP access by the UE, the second PDU session creation request carries the user plane security activation status, and the AMF sends the user plane security activation status to the RAN accessed by the UE, so that the RAN performs user plane security activation of the second 3GPP access according to the user plane security activation status. Since the two 3GPP accesses of the MA PDU session have the same user plane security activation status, the consistency of the security protection status of the two 3GPP accesses of the MA PDU session is guaranteed.
[0387] Easy to understand Figure 11 If the two 3GPP access routes corresponding to the two RANs of a MA PDU session created by the UE belong to the same PLMN, then the UE can select the same AMF when creating the two 3GPP access routes of the MA PDU session; if the two 3GPP access routes corresponding to the two RANs of a MA PDU session created by the UE belong to different PLMNs, then the UE can select different AMFs when creating the two 3GPP access routes of the MA PDU session. Please refer to [link to relevant documentation]. Figure 12 , Figure 12 This is a flowchart illustrating a communication method provided in an embodiment of this application.
[0388] like Figure 12 As shown, the communication methods include: S1201 to S1209.
[0389] S1201, The UE sends a first PDU session creation request to the first AMF through the first RAN;
[0390] The first PDU session creation request is used to request the creation of a MA PDU session that supports dual 3GPP access on the first 3GPP access.
[0391] S1202. After receiving the first PDU session creation request, the first AMF determines the first SMF and sends a PDU session creation context request to the first SMF.
[0392] S1203. The first SMF requests the ATSSS rules and user plane security policies corresponding to the MA PDU session based on the PDU session creation context request.
[0393] S1204, The first SMF sends a transmission message to the first AMF.
[0394] The transmitted messages carry ATSSS rules and user plane security policies.
[0395] S1205. After receiving the PDU session creation context response, if the steering mode in the ATSSS rule includes the redundant mode and the confidentiality protection or integrity protection of the user plane security policy is preferred, then the AMF sends a reporting indication request to the UE that the UE is accessing.
[0396] S1206, The UE sends a second PDU session creation request to the second AMF through the second RAN.
[0397] The second PDU session creation request is used to request the creation of a MA PDU session supporting dual 3GPP access on the second 3GPP access. The second PDU session creation request carries the user plane security activation status determined by the UE and the first RAN.
[0398] Among them, the first RAN and the second RAN belong to different PLMNs.
[0399] S1207, the second AMF obtains the user plane security activation status corresponding to the first 3GPP access of the MA PDU session supporting dual 3GPP access, and sends the user plane security activation status to the second RAN.
[0400] The user plane security activation state is used to enable the second RAN to perform user plane security activation between the UE and the second RAN based on the user plane security activation state.
[0401] S1208. After receiving the user plane security activation state, the second RAN generates an RRC connection reconfiguration message based on the user plane security activation state and sends the RRC connection reconfiguration message to the UE.
[0402] S1209, the UE receives the RRC connection reconfiguration message sent by the second RAN, performs user plane security activation according to the corresponding indication in the RRC connection reconfiguration message, and sends an RRC connection reconfiguration completion message to the second RAN.
[0403] Thus, if the two RANs corresponding to the two 3GPP accesses of the MA PDU session supporting 3GPP access created by the UE belong to two different PLMNs, when creating the MA PDU session on the second 3GPP access, the user plane security activation state is carried in the second PDU session creation request, and the user plane security activation state is sent to the second RAN corresponding to the second 3GPP access of the MA PDU session. The second RAN then performs user plane security activation between the UE and the second RAN based on the user plane security activation state, so as to achieve consistency of the security protection state of the two 3GPP accesses of the MA PDU session.
[0404] It is understandable that, in order to ensure the consistency of the security protection states of the two 3GPP accesses in a MA PDU session supporting dual 3GPP access, after the UE creates an MA PDU session on the first 3GPP access, the UE determines the steering mode of the MA PDU session, including the redundant mode, according to the ATSSS rules issued by the network side (e.g., AMF or SMF). When the UE creates an MA PDU session on the second 3GPP access, it reports the user security activation state corresponding to the first 3GPP access of the MA PDU session to the network side. Then, if the network side determines that the confidentiality protection or integrity protection in the user plane security policy of the MA PDU session is preferred, it issues the user plane security activation state to the RAN accessed by the UE, so that the RAN performs user plane security activation between the UE and the RAN according to the user plane security activation state, thereby achieving the consistency of the security protection states of the two 3GPP accesses in the MA PDU session.
[0405] Please see Figure 13 , Figure 13 This is a flowchart illustrating a communication method provided in an embodiment of this application. Figure 13 As shown, the communication methods include: S1301 to S1307.
[0406] S1301, The UE sends a first PDU session creation request to the SMF through the first RAN;
[0407] The first PDU session creation request is used to request the creation of a MA PDU session that supports dual 3GPP access on the first 3GPP access.
[0408] S1302, SMF obtains the ATSSS rules and user plane security policies corresponding to the MA PDU session based on the first PDU session creation request.
[0409] S1303, SMF sends a PDU session creation acceptance to UE.
[0410] Among them, the PDU session creation accepts the ATSSS rules corresponding to the MA PDU session.
[0411] Specifically, the SMF determines that the UE can create an MA PDU session and sends the ATSSS rule corresponding to the MA PDU session to the UE.
[0412] Optionally, PDU session creation acceptance can be PDU session establishment acceptance.
[0413] S1304, the UE sends a second PDU session creation request to the SMF through the second RAN.
[0414] Specifically, the UE obtains the ATSSS rule based on the PDU session creation acceptance, and then determines whether the steering mode of the ATSSS rule includes the redundant mode. If the steering mode in the ATSSS rule includes the redundant mode, the second PDU session creation request carries the user plane security activation status between the UE and the first RAN; if the steering mode in the ATSSS rule does not include the redundant mode, the second PDU session creation request does not carry the user plane security activation status between the UE and the first RAN.
[0415] S1305. If the confidentiality protection or integrity protection in the user plane security policy of the MA PDU session is preferred, the SMF sends the user plane security activation status to the second RAN.
[0416] Specifically, after receiving the second PDU session creation request sent by the UE, the SMF obtains the user plane security policy corresponding to the MA PDU session, and then determines whether the confidentiality protection or integrity protection in the user plane security policy of the MA PDU session is preferred.
[0417] If the confidentiality protection or integrity protection in the user plane security policy of the MA PDU session is preferred, the SMF sends the user plane security activation state to the second RAN accessed by the UE, so that the second RAN can perform user plane security activation between the UE and the second RAN based on the user plane security activation state; if neither the confidentiality protection nor the integrity protection in the user plane security policy of the MA PDU session includes preferred, then the SMF does not need to send the user plane security activation state to the second RAN.
[0418] S1306. After receiving the user plane security activation state, the second RAN generates an RRC connection reconfiguration message based on the user plane security activation state and sends the RRC connection reconfiguration message to the UE.
[0419] S1307, the UE receives the RRC connection reconfiguration message sent by the second RAN, performs user plane security activation according to the corresponding indication in the RRC connection reconfiguration message, and sends an RRC connection reconfiguration complete message to the second RAN.
[0420] Thus, during the dual 3GPP access creation process of an MA PDU session, if the steering mode in the ATSSS rule corresponding to the MA PDU session includes the redundant mode, the UE reports the user plane security activation status to the SMF during the creation of the MA PDU session on the second 3GPP access. The SMF determines whether the confidentiality protection or integrity protection in the user plane security policy of the MA PDU session is preferred. If the steering mode in the ATSSS rule corresponding to the MA PDU session includes the redundant mode and the confidentiality protection or integrity protection in the user plane security policy of the MA PDU session is preferred, the SMF issues the user plane security activation status to the second RAN accessed by the UE, so that the second RAN performs user plane security activation of the second 3GPP access according to the user plane security activation status. Since the two 3GPP accesses of the MA PDU session have the same user plane security activation status, the consistency of the security protection status of the two 3GPP accesses of the MA PDU session is guaranteed.
[0421] Easy to understand Figure 13 If the two 3GPP accesses corresponding to the two RANs of the MA PDU session created by the UE belong to the same PLMN, then the UE can select the same AMF and SMF when creating the two 3GPP accesses of the MA PDU session; if the two 3GPP accesses corresponding to the two RANs of the MA PDU session created by the UE belong to different PLMNs, please refer to [link to relevant documentation]. Figure 14 , Figure 14 This is a flowchart illustrating a communication method provided in an embodiment of this application.
[0422] like Figure 14 As shown, the communication methods include: S1401 to S1407.
[0423] S1401, The UE sends a first PDU session creation request to the SMF through the first RAN;
[0424] The first PDU session creation request is used to request the creation of a MA PDU session that supports dual 3GPP access on the second 3GPP access.
[0425] S1402, SMF obtains the ATSSS rules and user plane security policies corresponding to the MA PDU session based on the first PDU session creation request.
[0426] S1403, SMF sends a PDU session creation acceptance to UE.
[0427] Among them, the PDU session creation accepts the ATSSS rules corresponding to the MA PDU session.
[0428] Specifically, the SMF determines that the UE can create an MA PDU session and sends the ATSSS rule corresponding to the MA PDU session to the UE.
[0429] Optionally, PDU session creation acceptance can be PDU session establishment acceptance.
[0430] S1404, the UE sends a second PDU session creation request to the second SMF through the second RAN.
[0431] Specifically, the UE obtains the ATSSS rule based on the PDU session creation acceptance, and then determines whether the steering mode of the ATSSS rule includes the redundant mode. If the steering mode in the ATSSS rule includes the redundant mode, the second PDU session creation request carries the user plane security activation status between the UE and the first RAN; if the steering mode in the ATSSS rule does not include the redundant mode, the second PDU session creation request does not carry the user plane security activation status between the UE and the first RAN.
[0432] S1405. If the confidentiality protection or integrity protection in the user plane security policy of the MA PDU session is preferred, the second SMF sends the user plane security activation status to the second RAN.
[0433] Specifically, after receiving the second PDU session creation request sent by the UE, the second SMF searches for the user plane security policy of the MA PDU session; then it determines whether the confidentiality protection or integrity protection in the user plane security policy of the MA PDU session is preferred.
[0434] If the steering mode in the ATSSS rule includes the redundant mode and the confidentiality or integrity protection in the user plane security policy of the MA PDU session is preferred, the SMF sends the user plane security activation state to the second RAN accessed by the UE, so that the second RAN can perform user plane security activation between the UE and the second RAN based on the user plane security activation state; if neither the confidentiality nor the integrity protection in the user plane security policy of the MA PDU session includes preferred, then the second SMF does not need to send the user plane security activation state to the second RAN.
[0435] S1406. After receiving the user plane security activation state, the second RAN generates an RRC connection reconfiguration message based on the user plane security activation state and sends the RRC connection reconfiguration message to the UE.
[0436] S1407, the UE receives the RRC connection reconfiguration message sent by the second RAN, performs user plane security activation according to the corresponding indication in the RRC connection reconfiguration message, and sends an RRC connection reconfiguration complete message to the second RAN.
[0437] Thus, for the dual 3GPP access creation process of an MA PDU session, if the steering mode in the ATSSS rule corresponding to the MA PDU session includes the redundant mode; the UE reports the user plane security activation status to the second SMF during the creation of the MA PDU session on the second 3GPP access; if the steering mode in the ATSSS rule corresponding to the MA PDU session includes the redundant mode and the confidentiality protection or integrity protection in the user plane security policy of the MA PDU session is preferred, the second SMF issues the user plane security activation status to the RAN accessed by the UE, so that the RAN performs user plane security activation of the second 3GPP access according to the user plane security activation status. Since the two 3GPP accesses of the MA PDU session have the same user plane security activation status, the consistency of the security protection status of the two 3GPP accesses of the MA PDU session is guaranteed.
[0438] It is easy to understand that when a UE creates a MA PDU session supporting dual 3GPP access on the second 3GPP access, if the steering mode in the ATSSS rule includes the redundant mode, the UE reports the user plane security activation state to the SMF. If the steering mode in the ATSSS rule includes the redundant mode and the confidentiality protection or integrity protection in the user plane security policy of the MA PDU session is preferred, then the AMF sends the user plane security activation state corresponding to the MA PDU session to the corresponding second RAN, so that the second RAN and the UE can activate user plane security according to the user plane security activation state. Since the two 3GPP accesses of the MA PDU session supporting dual 3GPP access have the same user plane security activation state, the consistency of the two 3GPP accesses of the MA PDU session supporting dual 3GPP access is guaranteed.
[0439] Please see Figure 15 This is a flowchart illustrating a communication method provided in an embodiment of this application. Figure 15 As shown, the communication methods include: S1501 to S1509.
[0440] S1501, The UE sends a first PDU session creation request to the AMF through the first RAN;
[0441] The first PDU session creation request is used to request the creation of a MA PDU session that supports dual 3GPP access on the first 3GPP access.
[0442] S1502. After receiving the first PDU session creation request, the AMF determines the SMF and sends a PDU session creation context request to the SMF.
[0443] Optionally, the PDU session creation context request is Nsmf_PDUSession_CreateSMContext.
[0444] S1503, SMF requests the ATSSS rules and user plane security policies corresponding to the MA PDU session based on the PDU session creation context request.
[0445] Optionally, after the SMF determines the subscription data and local policy corresponding to the MA PDU session based on the PDU session creation context request, it determines whether the corresponding MA PDU session can be created based on the subscription data and local policy. If it is determined that the corresponding MA PDU session cannot be created, a rejection message is sent to the UE; if it is determined that the MA PDU session can be created, the PCF is selected, and the session policy of the corresponding MA PDU session is obtained from the PCF. The ATSSS rule, N4 rule and user plane security policy are determined based on the session policy.
[0446] Optionally, the PDU session creation context request carries the request type, PDU session ID, and Dual 3GPP access indication, wherein the request type is MA PDU Request.
[0447] S1504, SMF sends a transmission message to AMF.
[0448] The transmitted messages carry ATSSS rules and user plane security policies.
[0449] Optionally, the transmission message is Nsmf_Communication_N1N2MessageTransfer.
[0450] After receiving the PDU session creation context response, S1505 and AMF send a PDU session creation acceptance to the UE.
[0451] Among them, the PDU session creation accepts the ATSSS rules corresponding to the MA PDU session.
[0452] Specifically, the SMF determines that the UE can create an MA PDU session and sends the ATSSS rule corresponding to the MA PDU session to the UE.
[0453] Optionally, PDU session creation acceptance can be PDU session establishment acceptance.
[0454] S1506, the UE sends a second PDU session creation request to the AMF through the second RAN.
[0455] Specifically, the UE obtains the ATSSS rule based on the PDU session creation request, and then determines whether the ATSSS rule's steering mode includes the redundant mode. If the steering mode in the ATSSS rule includes the redundant mode, the second PDU session creation request carries the user plane security activation status between the UE and the first RAN; if the steering mode in the ATSSS rule does not include the redundant mode, the second PDU session creation request does not carry the user plane security activation status between the UE and the first RAN.
[0456] The first RAN and the second RAN belong to the same PLMN.
[0457] S1507. If the steering mode in the ATSSS rule includes the redundant mode and the confidentiality protection or integrity protection in the user plane security policy of the MA PDU session is preferred, the AMF sends the user plane security activation status to the second RAN.
[0458] Optionally, after receiving the second PDU session creation request from the UE, the AMF looks up the user plane security policy of the MA PDU session; then it determines whether the confidentiality protection or integrity protection in the user plane security policy of the MA PDU session is preferred.
[0459] If the steering mode in the ATSSS rule includes the redundant mode and the confidentiality protection or integrity protection in the user plane security policy of the MA PDU session is preferred, the AMF sends a user plane security activation state to the second RAN accessed by the UE, so that the second RAN can perform user plane security activation between the UE and the second RAN based on the user plane security activation state; if neither the confidentiality protection nor the integrity protection in the user plane security policy of the MA PDU session includes preferred, then the AMF does not need to send a user plane security activation state to the second RAN.
[0460] S1508 After receiving the user plane security activation state, the second RAN generates an RRC connection reconfiguration message based on the user plane security activation state and sends the RRC connection reconfiguration message to the UE.
[0461] S1509, the UE receives the RRC connection reconfiguration message sent by the second RAN, performs user plane security activation according to the corresponding indication in the RRC connection reconfiguration message, and sends an RRC connection reconfiguration complete message to the second RAN.
[0462] Thus, during the creation of an MA PDU session supporting dual 3GPP access, if the steering mode in the ATSSS rule corresponding to the MA PDU session includes the redundant mode and the confidentiality protection or integrity protection in the user plane security policy of the MA PDU session is preferred, then the AMF notifies the first RAN accessed by the UE to report the user plane security activation status of the first 3GPP access of the MA PDU session; during the creation of the MA PDU session on the second 3GPP access by the UE, the AMF sends the user plane security activation status to the RAN accessed by the UE, so that the RAN performs user plane security activation of the second 3GPP access according to the user plane security activation status. Since the two 3GPP accesses of the MA PDU session have the same user plane security activation status, the consistency of the security protection status of the two 3GPP accesses of the MA PDU session is guaranteed.
[0463] Please see Figure 16 This is a flowchart illustrating a communication method provided in an embodiment of this application.
[0464] like Figure 16 As shown, the communication methods include: S1601 to S1609.
[0465] S1601, The UE sends a first PDU session creation request to the first AMF through the first RAN;
[0466] The first PDU session creation request is used to request the creation of a MA PDU session that supports dual 3GPP access on the first 3GPP access.
[0467] S1602. After receiving the first PDU session creation request, the first AMF determines the first SMF and sends a PDU session creation context request to the first SMF.
[0468] S1603. The first SMF requests the ATSSS rules and user plane security policies corresponding to the MA PDU session based on the PDU session creation context request.
[0469] S1604, The first SMF sends a transmission message to the first AMF.
[0470] The transmitted messages carry ATSSS rules and user plane security policies.
[0471] S1605, the first AMF sends a PDU session creation acceptance to the UE.
[0472] Among them, the PDU session creation accepts the ATSSS rules corresponding to the MA PDU session.
[0473] Specifically, the SMF determines that the UE can create an MA PDU session and sends the ATSSS rule corresponding to the MA PDU session to the UE.
[0474] Optionally, PDU session creation acceptance can be PDU session establishment acceptance.
[0475] S1606, the UE sends a second PDU session creation request to the second AMF through the second RAN.
[0476] The second PDU session creation request is used to request the creation of a MA PDU session that supports dual 3GPP access on the second 3GPP access.
[0477] Specifically, the UE obtains the ATSSS rule based on the PDU session creation request, and then determines whether the steering mode of the ATSSS rule includes the redundant mode. If the steering mode in the ATSSS rule includes the redundant mode, the second PDU session creation request carries the user plane security activation status between the UE and the first RAN; if the steering mode in the ATSSS rule does not include the redundant mode, the second PDU session creation request does not carry the user plane security activation status between the UE and the first RAN.
[0478] Among them, the first RAN and the second RAN belong to different PLMNs.
[0479] S1607. If the confidentiality protection or integrity protection in the user plane security policy of the MA PDU session is preferred, the second AMF sends the user plane security activation status to the second RAN.
[0480] Optionally, after receiving the second PDU session creation request sent by the UE, the second AMF selects an SMF based on the second PDU session creation request and queries the SMF for the user plane security policy of the MA PDU session corresponding to the second PDU session creation request; then it determines whether the confidentiality protection or integrity protection in the user plane security policy of the MA PDU session is preferred.
[0481] If the steering mode in the ATSSS rule includes the redundant mode and the confidentiality or integrity protection in the user plane security policy of the MA PDU session is preferred, the second AMF sends the user plane security activation state to the second RAN accessed by the UE, so that the second RAN can perform user plane security activation between the UE and the second RAN based on the user plane security activation state; if neither the confidentiality nor the integrity protection in the user plane security policy of the MA PDU session includes preferred, then the AMF does not need to send the user plane security activation state to the second RAN.
[0482] Optionally, after receiving the second PDU session creation request, the second AMF then determines whether the steering mode in the ATSSS rule corresponding to the MA PDU session includes the redundant mode. If the steering mode in the ATSSS rule corresponding to the MA PDU session does not include the redundant mode, the second AMF ignores the user plane security activation status in the second PDU session creation request.
[0483] S1608. After receiving the user plane security activation state, the second RAN generates an RRC connection reconfiguration message based on the user plane security activation state and sends the RRC connection reconfiguration message to the UE.
[0484] S1609, the UE receives the RRC connection reconfiguration message sent by the second RAN, performs user plane security activation according to the corresponding indication in the RRC connection reconfiguration message, and sends an RRC connection reconfiguration completion message to the second RAN.
[0485] Thus, if the two RANs corresponding to the two 3GPP accesses supporting 3GPP access created by the UE belong to two different PLMNs, when creating the MA PDU session on the first 3GPP access, the UE determines that the steering mode in the ATSSS rule corresponding to the MA PDU session includes the redundant mode. During the creation of the MA PDU session on the second 3GPP access, the UE reports the user plane security activation status to the SMF. After receiving the second PDU session creation request, the AMF determines that the steering mode in the ATSSS rule corresponding to the MA PDU session includes the redundant mode and that the confidentiality protection or integrity protection in the user plane security policy of the MA PDU session is preferred. The second AMF then sends the user plane security activation status to the second RAN accessed by the UE, so that the second RAN performs user plane security activation between the UE and the second RAN based on the user plane security activation status, thereby achieving consistency in the security protection status of the two 3GPP accesses of the MA PDU session.
[0486] Please see Figure 17 This is a flowchart illustrating a communication method provided in an embodiment of this application.
[0487] like Figure 17 As shown, the communication methods include: S1701 to S1710.
[0488] S1701, The UE sends a first PDU session creation request to the AMF through the first RAN;
[0489] The first PDU session creation request is used to request the creation of a MA PDU session that supports dual 3GPP access on the first 3GPP access.
[0490] S1702. After receiving the first PDU session creation request, the AMF determines the SMF and sends a PDU session creation context request to the SMF.
[0491] Optionally, the PDU session creation context request is Nsmf_PDUSession_CreateSMContext.
[0492] S1703, SMF requests the ATSSS rules and user plane security policies corresponding to the MA PDU session based on the PDU session creation context request.
[0493] Optionally, after the SMF determines the subscription data and local policy corresponding to the MA PDU session based on the PDU session creation context request, it determines whether the corresponding MA PDU session can be created based on the subscription data and local policy. If it is determined that the corresponding MA PDU session cannot be created, a rejection message is sent to the UE; if it is determined that the MA PDU session can be created, the PCF is selected, and the session policy of the corresponding MA PDU session is obtained from the PCF. The ATSSS rule, N4 rule and user plane security policy are determined based on the session policy.
[0494] Optionally, the PDU session creation context request carries the request type, PDU session ID, and dual 3GPP access indication, wherein the request type is MA PDU Request.
[0495] S1704, SMF sends a transmission message to AMF.
[0496] The transmitted messages carry ATSSS rules and user plane security policies.
[0497] Optionally, the transmission message is Nsmf_Communication_N1N2MessageTransfer.
[0498] S1705, AMF sends a PDU session creation acceptance to UE.
[0499] Among them, the PDU session creation accepts the ATSSS rules corresponding to the MA PDU session.
[0500] Specifically, the SMF determines that the UE can create an MA PDU session and sends the ATSSS rule corresponding to the MA PDU session to the UE.
[0501] Optionally, PDU session creation acceptance can be PDU session establishment acceptance.
[0502] S1706, The UE sends a second PDU session creation request to the AMF through the second RAN.
[0503] The second PDU session creation request is used to create a MAPDU session that supports dual 3GPP access on the second 3GPP access.
[0504] The first RAN and the second RAN belong to the same PLMN.
[0505] S1707 After receiving the second PDU session creation request, the AMF obtains the ATSSS rules and user plane security policy corresponding to the MA PDU session. If the steering mode in the ATSSS rules includes the redundant mode and the confidentiality protection or integrity protection of the user plane security policy is preferred, the AMF sends a user plane security activation status transmission indication to the first RAN accessed by the UE.
[0506] The user plane security activation status transmission indication carries the user plane security policy, the user plane security activation status reporting indication, and the second RAN identifier. The user plane security activation status transmission indication is used to instruct the first RAN to send the user plane security activation status of the first 3GPP access MA PDU session to the second RAN.
[0507] Specifically, after receiving the second PDU session creation request, the AMF obtains the ATSSS rules and user plane security policy from the SMF based on the request. After obtaining the ATSSS rules and user plane security policy corresponding to the MA PDU session, the AMF determines whether the steering mode in the ATSSS rules includes the redundant mode and whether the confidentiality protection or integrity protection in the user plane security policy of the MA PDU session is preferred.
[0508] If the steering mode includes the redundant mode and the confidentiality protection or integrity protection of the user plane security policy of the MA PDU session is preferred, then the AMF sends a reporting instruction request to the first RAN, which carries the second RAN identifier and the user plane security activation status reporting instruction.
[0509] If the steering mode does not include the redundant mode or the confidentiality and integrity protection of the user plane security policy for the MA PDU session does not include preferred, then the AMF sends a reporting instruction request to the first RAN, carrying the user plane security policy.
[0510] Optionally, the AMF sends an N2 PDU Session Request to the first RAN, thereby enabling the AMF to send the user plane security policy and user plane security activation status reporting indication to the first RAN.
[0511] S1708, The first RAN sends the user plane security activation status to the second RAN;
[0512] Specifically, after receiving the reporting instruction request sent by the AMF, the first RAN sends the user plane security activation status to the second RAN, so that the second RAN and the UE can perform user plane security activation based on the user plane security activation status.
[0513] Optionally, the first RAN reports the user plane security activation status to the second RAN via an SN Addition / Modification Request.
[0514] S1709. After receiving the user plane security activation state, the second RAN generates an RRC connection reconfiguration message based on the user plane security activation state and sends the RRC connection reconfiguration message to the UE.
[0515] S1710, the UE receives the RRC connection reconfiguration message sent by the second RAN, performs user plane security activation according to the corresponding indication in the RRC connection reconfiguration message, and sends an RRC connection reconfiguration complete message to the second RAN.
[0516] Thus, during the creation of an MA PDU session supporting dual 3GPP access, if the steering mode in the ATSSS rule corresponding to the MA PDU session includes the redundant mode and the confidentiality protection or integrity protection in the user plane security policy of the MA PDU session is preferred, then the AMF notifies the first RAN accessed by the UE to send the user plane security activation state to the second RAN; so that the second RAN corresponding to the second 3GPP access process of the MA PDU session performs user plane security activation for the second 3GPP access based on the user plane security activation state. Since the two 3GPP accesses of the MA PDU session have the same user plane security activation state, the consistency of the security protection state of the two 3GPP accesses of the MA PDU session is guaranteed.
[0517] The communication method provided in this application, when a UE creates an MA PDU session supporting dual 3GPP access, if the steering mode in the ATSSS rule corresponding to the MA PDU session includes a redundant mode and the confidentiality protection or integrity protection of the user plane security policy is preferred, then the UE or RAN corresponding to the first 3GPP access of the MA PDU session sends the user plane security activation state determined by the UE and RAN, so that the RAN corresponding to the second 3GPP access of the MA PDU session performs user plane security activation according to the user plane security activation state. The two 3GPP accesses of the MA PDU session have the same user plane security activation state, thereby achieving consistency of the security protection states of the two 3GPP accesses of the MA PDU session supporting dual 3GPP access.
[0518] It should be understood that the above description is merely to help those skilled in the art better understand the embodiments of this application, and is not intended to limit the scope of the embodiments of this application. Based on the examples given above, those skilled in the art can obviously make various equivalent modifications or changes. For example, some steps in the various methods described above may be unnecessary, or new steps may be added. Alternatively, any combination of two or more of the above embodiments may be used. Such modifications, changes, or combinations also fall within the scope of the embodiments of this application.
[0519] It should also be understood that the methods, situations, categories, and classifications of embodiments in this application are for the convenience of description only and should not constitute a special limitation. Various methods, categories, situations, and features in embodiments can be combined without contradiction.
[0520] It should also be understood that the various numerical designations used in the embodiments of this application are merely for descriptive convenience and are not intended to limit the scope of the embodiments of this application. The order of the process numbers described above does not imply the order of execution; the execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0521] It should also be understood that the above description of the embodiments of this application focuses on highlighting the differences between the various embodiments. Any similarities or differences not mentioned can be referred to each other. For the sake of brevity, they will not be repeated here.
[0522] The above combination Figures 1-17 The embodiments of the methods and systems provided in this application have been described. The communication device provided in the embodiments of this application is described below.
[0523] This embodiment can divide the communication device into functional modules according to the above method. For example, it can be divided into functional modules corresponding to each function, or two or more functions can be integrated into one processing module. The integrated modules can be implemented in hardware. It should be noted that the module division in this embodiment is illustrative and only represents one logical functional division; other division methods may be used in actual implementation.
[0524] It should be noted that the relevant content of each step involved in the above method embodiments can be referenced from the functional description of the corresponding functional module, and will not be repeated here.
[0525] The communication device provided in this application embodiment is used to execute the communication method provided in the above method embodiment, and thus can achieve the same effect as the above implementation method.
[0526] In other embodiments, when using integrated units, the communication device may include a processing module, a storage module, and a communication module. The processing module can be used to control and manage the operations of the communication device. For example, it can be used to support the communication device in executing the steps performed by the processing unit. The storage module can be used to store program code and data, etc. The communication module can be used to support communication between the communication device and other devices.
[0527] The processing module can be a processor or a controller. It can implement or execute various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. The processor can also be a combination that implements computational functions, such as a combination of one or more microprocessors, a combination of digital signal processing (DSP) and a microprocessor, etc. The storage module can be a memory. The communication module can specifically be a radio frequency circuit, a Bluetooth chip, a Wi-Fi chip, or other devices that interact with other communication devices.
[0528] See Figure 18 , Figure 18 A schematic diagram of the structure of an exemplary communication device according to this application is shown. Figure 18 The communication device shown can execute the steps of the communication method performed by any of the communication devices (such as AMF, AMF, or UE) provided in the embodiments of this application. The hardware structures of SMF, AMF, and UE in the embodiments of this application can all be referred to as follows: Figure 18 The diagram shows the hardware structure of the communication device.
[0529] The communication device 1800 includes at least one processor 1801, a memory 1803, and at least one network interface 1804.
[0530] The processor 1801 is, for example, a general-purpose CPU, a digital signal processor (DSP), a network processor (NP), a GPU, a neural network processing unit (NPU), a data processing unit (DPU), a microprocessor, or one or more integrated circuits or application-specific integrated circuits (ASICs) used to implement the solutions of this application, a programmable logic device (PLD), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The PLD is, for example, a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof. It can implement or execute the various logic blocks, modules, and circuits described in conjunction with the disclosure of this application. The processor can also be a combination that implements computational functions, such as including one or more microprocessor combinations, a combination of a DSP and a microprocessor, etc.
[0531] Optionally, the communication device 1800 also includes a bus 1802. The bus 1802 is used to transmit information between the components of the communication device 1800. The bus 1802 can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus 1802 can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 18 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.
[0532] Memory 1803 may be, for example, read-only memory (ROM) or other types of storage devices capable of storing static information and instructions; random access memory (RAM) or other types of dynamic storage devices capable of storing information and instructions; electrically erasable programmable read-only memory (EEPROM); compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.); magnetic disk storage media or other magnetic storage devices; or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but not limited thereto. Memory 1803 may exist independently and be connected to processor 1801 via bus 1802. Memory 1803 may also be integrated with processor 1801.
[0533] Network interface 1804 uses any transceiver-like device for communicating with other devices or communication networks, such as Ethernet, radio access network (RAN), or wireless local area network (WLAN). Network interface 1804 can include wired network interfaces and wireless network interfaces. Specifically, network interface 1804 can be an Ethernet interface, such as Fast Ethernet (FE), Gigabit Ethernet (GE), Asynchronous Transfer Mode (ATM), WLAN, cellular network, or combinations thereof. The Ethernet interface can be an optical interface, an electrical interface, or a combination thereof. In some embodiments of this application, network interface 1804 can be used by communication device 1800 to communicate with other devices.
[0534] In specific implementations, as some embodiments, processor 1801 may include one or more CPUs. Each of these processors may be a single-core processor or a multi-core processor. Here, "processor" may refer to one or more devices, circuits, and processing cores for processing data (e.g., computer program instructions).
[0535] In specific implementations, as some embodiments, the communication device 1800 may include multiple processors. Each of these processors may be a single-core processor or a multi-core processor. Here, a processor may refer to one or more devices, circuits, and processing cores for processing data (such as computer program instructions).
[0536] In some embodiments, the memory 1803 is used to store program instructions for executing the present application's solution, and the processor 1801 can execute the program instructions stored in the memory 1803. That is, the communication device 1800 can implement the method provided in the above-described embodiments through the processor 1801 and the program instructions in the memory 1803. The program instructions may include one or more software modules. Optionally, the processor 1801 itself may also store program instructions for executing the present application's solution.
[0537] In specific implementation, the processor 1801 in the communication device 1800 of this application reads instructions from the memory 1803, causing... Figure 18 The communication device 1800 shown is capable of performing all or part of the steps in the communication method performed by the communication device in the above embodiments.
[0538] In the above embodiments, each step of the method described is implemented through integrated logic circuits in the hardware of the processor of the communication device 1800 or through software instructions. The steps of the method embodiments disclosed in this application can be directly implemented by the hardware processor, or implemented by a combination of hardware and software modules in the processor. The software modules can reside in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. Since the storage medium is located in memory, the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method embodiments; to avoid repetition, these will not be described in detail here.
[0539] It should be understood that the aforementioned processor can be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. General-purpose processors can be microprocessors or any conventional processor. It is worth noting that the processor can be a processor supporting the Advanced Reduced Instruction Set Computing (RISC) machine (ARM) architecture.
[0540] Furthermore, in an alternative embodiment, the memory described above may include read-only memory and random access memory, and provide instructions and data to the processor. The memory may also include non-volatile random access memory. For example, the memory may also store device type information.
[0541] The memory can be volatile or non-volatile, or may include both. The non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be random access memory (RAM), which serves as an external cache. Many forms of RAM are available by way of example, but not limitation. Examples include static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous linked dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM).
[0542] This application also provides a communication system, including a communication device, wherein the communication device can execute the steps of the communication method executed by any of the communication devices provided in this application.
[0543] In an exemplary embodiment, this application provides a computer program (product) comprising: computer program code, which, when executed by a computer, causes the computer to perform steps in a communication method that can be executed by any of the communication devices provided in this application.
[0544] This application provides a computer-readable storage medium that stores a program or instructions. When the program or instructions are run on a computer, the communication method executed by any of the communication devices provided in this application is executed.
[0545] This application provides a chip, including a processor, for calling and executing instructions stored in a memory, causing a communication device with the chip installed to execute a communication method performed by any of the communication devices provided in this application.
[0546] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state drive).
[0547] In this application, the terms "first," "second," etc., are used to distinguish identical or similar items that have substantially the same function. It should be understood that there is no logical or temporal dependency between "first," "second," and "nth," nor does it limit the quantity or order of execution. It should also be understood that although the following description uses the terms "first," "second," etc., to describe various elements, these elements should not be limited by the terms. These terms are merely used to distinguish one element from another.
[0548] It should also be understood that, in the various embodiments of this application, the sequence number of each process does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0549] In this application, the term "at least one" means one or more, and the term "multiple" means two or more. For example, multiple second devices means two or more second devices. The terms "system" and "network" are often used interchangeably in this document.
[0550] It should be understood that the terminology used in the description of the various examples herein is for the purpose of describing particular examples only and is not intended to be limiting. As used in the description of the various examples and the appended claims, the singular forms "a" and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise.
[0551] It should also be understood that the term "and" as used herein refers to and covers any and all possible combinations of one or more of the listed items. The term "and" describes an association between related objects, indicating that three relationships can exist; for example, A and B can represent: A alone, A and B simultaneously, or B alone. Additionally, the character " / " in this application generally indicates that the preceding and following related objects are in an "or" relationship.
[0552] It should also be understood that the terms "if" and "if" can be interpreted as meaning "when" or "upon" or "in response to determination" or "in response to detection." Similarly, depending on the context, the phrases "if determination..." or "if detection [the stated condition or event]" can be interpreted as meaning "when determination..." or "in response to determination..." or "when detection [the stated condition or event]" or "in response to detection [the stated condition or event]."
[0553] The above description is merely an embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the principles of this application should be included within the protection scope of this application.< / guami>
Claims
1. A communication method, characterized in that, Applied to network devices, the method includes: Receive a first protocol data unit (PDU) session creation request sent by the user equipment (UE) through the first radio access node (RAN). The first PDU session creation request is used to request the creation of a multi-access MA PDU session that supports dual 3GPP access on the first 3GPP access. Determine the access traffic routing, switching, splitting ATSSS rules and user plane security policies corresponding to the MA PDU session; In the ATSSS rule, the steering mode includes a redundant mode, and when the confidentiality protection or integrity protection of the user plane security policy is preferred, a reporting indication request is sent to the first RAN or the UE. The reporting indication request is used to instruct the first RAN or the UE to send the user plane security activation status of the first 3GPP access. The user plane security activation status includes whether the integrity protection and confidentiality protection of the user plane of the first 3GPP access are activated. Sending a user plane security activation status to the second RAN, so that the second RAN and the UE can perform user plane security activation according to the user plane security activation status, wherein the second RAN is the second RAN corresponding to the second 3GPP access of the MA PDU session supporting dual 3GPP access, and the second RAN is different from the first RAN.
2. The method according to claim 1, characterized in that, Sending the user plane security activation status to the second RAN includes: If the network device is a session management function, the session management function sends a user plane security activation state to the access and mobility management function, so that the access and mobility management function sends the user plane security activation state to the second RAN. If the network device is an access and mobility management function, then the access and mobility management function sends a user plane security activation status to the second RAN.
3. The method according to claim 2, characterized in that, The access and mobility management function sends the user plane security activation status to the second RAN, including: Obtain the context information of the UE, determine the second RAN corresponding to the second 3GPP access corresponding to the MAPDU session supporting dual 3GPP access based on the context information of the UE, and send the user plane security activation status to the second RAN.
4. The method according to claim 1, characterized in that, If the network device sends a reporting indication request to the first RAN, then after the network device sends the reporting indication request to the first RAN, the method further includes: Receive the user plane security activation status sent by the first RAN.
5. The method according to claim 1, characterized in that, If the network device sends a reporting indication request to the UE, the method further includes: receiving a second PDU session creation request sent by the UE through a second RAN, wherein the second PDU session creation request carries the user plane security activation status.
6. The method according to claim 5, characterized in that, The first PDU session creation request carries a PDU session identifier, a request type, and a dual 3GPP access indication. The request type is an MA PDU request, and the dual 3GPP access indication is used to indicate that the MA PDU session requested by the first PDU session creation request supports dual 3GPP access. The second PDU session creation request carries the PDU session identifier and request type, wherein the request type is an existing PDU session or a dual 3GPP access type.
7. The method according to claim 1, characterized in that, If the network device is a first session management function, the method further includes: The first session management function receives a PDU session context creation request sent by the second session management function, wherein the PDU session context creation request carries a PDU session identifier; The first session management function sends a PDU session context creation response to the second session management function. The PDU session context creation response carries the user plane security activation status corresponding to the PDU session identifier.
8. A communication method, characterized in that, An apparatus for implementing the functions of a user equipment (UE), the method comprising: The first radio access node (RAN) sends a first protocol data unit (PDU) session creation request to the network device. The first PDU session creation request is used to request the creation of a multi-access MA PDU session that supports dual 3GPP access on the first 3GPP access. The network device receives a reporting instruction request, which instructs the UE to send a first 3GPP access user plane security activation status to the network device. The user plane security activation status includes whether the integrity protection and confidentiality protection of the first 3GPP access user plane are activated. The reporting instruction request is sent by the network device to the UE when the steering mode in the ATSSS rule includes the redundant mode and the confidentiality protection or integrity protection of the user plane security policy is preferred. The second RAN sends a second PDU session creation request to the network device. The second PDU session creation request is used to request the creation of a MA PDU session supporting dual 3GPP access on the second 3GPP access. The second PDU session creation request carries the user plane security activation state, so that the network device sends the user plane security activation state to the second RAN, thereby enabling the second RAN and the UE to perform user plane security activation based on the user plane security activation state.
9. The method according to claim 8, characterized in that, The first PDU session creation request carries a PDU session identifier, a request type, and a dual 3GPP access indication. The request type is an MA PDU request, and the dual 3GPP access indication is used to indicate that the MA PDU session requested by the first PDU session creation request supports dual 3GPP access. The second PDU session creation request also carries the PDU session identifier and request type, wherein the request type is an existing PDU session or a dual 3GPP access type.
10. The method according to claim 8 or 9, characterized in that, The network device has access and mobility management functions or session management functions.
11. A communication method, characterized in that, Applied to network devices, the method includes: Receive a first protocol data unit (PDU) session creation request sent by the user equipment (UE) through the first radio access node (RAN). The first PDU session creation request is used to request the creation of a multi-access MA PDU session that supports dual 3GPP access on the first 3GPP access. Determine the access traffic routing, switching, splitting ATSSS rules and user plane security policies corresponding to the MA PDU session; Send a PDU session creation acceptance to the UE, wherein the PDU session creation acceptance carries the ATSSS rule; The UE sends a second PDU session creation request through the second RAN. The second PDU session creation request is used to request the creation of a MA PDU session supporting dual 3GPP access on the second 3GPP access. If the steering mode in the ATSSS rule includes a redundant mode, the second PDU session creation request carries the user plane security activation state determined on the first 3GPP access. The user plane security activation state includes whether the integrity protection and confidentiality protection of the user plane of the first 3GPP access are activated. When the confidentiality protection or integrity protection of the user plane security policy is preferred, a user plane security activation state is sent to the second RAN so that the second RAN and the UE can perform user plane security activation according to the user plane security activation state.
12. The method according to claim 11, characterized in that, The first PDU session creation request carries a PDU session identifier, a request type, and a dual 3GPP access indication. The request type is an MA PDU request, and the dual 3GPP access indication is used to indicate that the MA PDU session requested by the first PDU session creation request supports dual 3GPP access. The second PDU session creation request also carries a PDU session identifier and a request type, wherein the request type is an existing PDU session or a dual 3GPP access session.
13. The method according to claim 11 or 12, characterized in that, The network device has access and mobility management functions or session management functions.
14. The method according to claim 13, characterized in that, If the network device is a first session management function, the method further includes: The first session management function receives a PDU session context creation request sent by the second session management function, wherein the PDU session context creation request carries a PDU session identifier; The first session management function sends a PDU session context creation response to the second session management function. The PDU session context creation response carries the user plane security activation status corresponding to the PDU session identifier.
15. A communication method, characterized in that, An apparatus for implementing the functions of a user equipment (UE), the method comprising: The first RAN sends a first PDU session creation request to the network device. The first PDU session creation request is used to request the creation of an MA PDU session that supports dual 3GPP access on the first 3GPP access. Receive PDU session creation acceptance sent by the network device, wherein the PDU session creation acceptance carries ATSSS rules; The second RAN sends a second PDU session creation request to the first session management function. The second PDU session creation request is used to request the creation of an MA PDU session that supports dual 3GPP access on the second 3GPP access. If the steering mode in the ATSSS rule includes a redundant mode, the second PDU session creation request carries the user plane security activation status determined on the first 3GPP access.
16. The method according to claim 15, characterized in that, The first PDU session creation request carries a PDU session identifier, a request type, and a dual 3GPP access indication. The request type is an MA PDU request, and the dual 3GPP access indication is used to indicate that the MA PDU session requested by the first PDU session creation request supports dual 3GPP access. The second PDU session creation request also carries a PDU session identifier and a request type, wherein the request type is an existing PDU session or a dual 3GPP access session.
17. The method according to claim 15 or 16, characterized in that, The network device has access and mobility management functions or session management functions.
18. A communication method, characterized in that, Applied to access and mobility management functions, the method includes: Receive a first protocol data unit (PDU) session creation request sent by the user equipment (UE) through the first radio access node (RAN). The first PDU session creation request is used to request the creation of a multi-access MA PDU session that supports dual 3GPP access on the first 3GPP access. Determine the access traffic routing, switching, splitting ATSSS rules and user plane security policies corresponding to the MA PDU session; Send a PDU session creation acceptance to the UE; The system receives a second PDU session creation request sent by the UE through the second RAN. The second PDU session creation request is used to request the creation of an MA PDU session that supports dual 3GPP access on the second 3GPP access. When the steering mode in the ATSSS rule includes a redundant mode and the confidentiality protection or integrity protection of the user plane security policy is preferred, a user plane security activation status transmission indication is sent to the first RAN. The user plane security activation status transmission indication is used to instruct the first RAN to send the user plane security activation status to the second RAN, so that the second RAN and the UE can perform user plane security activation according to the user plane security activation status. The user plane security activation status includes whether the integrity protection and confidentiality protection of the user plane of the first 3GPP access are activated.
19. The method according to claim 18, characterized in that, The first PDU session creation request carries a PDU session identifier, a request type, and a dual 3GPP access indication. The request type is an MA PDU request, and the dual 3GPP access indication is used to indicate that the MA PDU session requested by the first PDU session creation request supports dual 3GPP access. The second PDU session creation request carries a PDU session identifier and a request type, wherein the request type is an existing PDU session or a dual 3GPP access session.
20. A communication method, characterized in that, Applied to a first radio access node (RAN), the method includes: The network device receives a reporting instruction request, which instructs the first RAN to send the user plane security activation status of the first 3GPP access to the network device. The user plane security activation status includes whether the integrity protection and confidentiality protection of the user plane of the first 3GPP access are activated. The reporting instruction request is sent by the network device to the first RAN when the steering mode in the ATSSS rule includes the redundant mode and the confidentiality protection or integrity protection of the user plane security policy is preferred. Send the user plane security activation status to the network device.
21. A communication method, characterized in that, Applied to a first radio access node (RAN), the method includes: The network device receives a user plane security activation status transmission indication, which is used to instruct the first RAN to send the user plane security activation status of the first 3GPP access to the second RAN. The user plane security activation status includes whether the integrity protection and confidentiality protection of the user plane of the first 3GPP access are activated. The user plane security activation status transmission indication is sent by the network device to the first RAN when the steering mode in the ATSSS rule includes the redundant mode and the confidentiality protection or integrity protection of the user plane security policy is preferred. The user plane security activation status transmission indication carries the identifier of the second RAN. Send the user plane security activation status to the second RAN.
22. A communication system, characterized in that, The communication system includes network equipment and a second wireless access node (RAN). The network device is used to receive a first protocol data unit (PDU) session creation request sent by a user equipment (UE) through a first radio access node (RAN). The first PDU session creation request is used to request the creation of a multi-access MA PDU session that supports dual 3GPP access on a first 3GPP access. The network device is also used to determine the access traffic routing, switching, splitting ATSSS rules and user plane security policies corresponding to the MA PDU session; In the ATSSS rule, the steering mode includes a redundant mode, and when the confidentiality protection or integrity protection of the user plane security policy is preferred, a reporting indication request is sent to the first RAN or the UE. The reporting indication request is used to instruct the first RAN or the UE to send the user plane security activation status of the first 3GPP access. The user plane security activation status includes whether the integrity protection and confidentiality protection of the user plane of the first 3GPP access are activated. The network device is also used to send the user plane security activation status to the second RAN, the second RAN being the second RAN corresponding to the second 3GPP access of the MA PDU session supporting dual 3GPP access, and the second RAN being different from the first RAN; The second RAN is used to receive the user plane security activation status sent by the network device, and to perform user plane security activation with the UE based on the user plane security activation status.
23. The system according to claim 22, characterized in that, The communication system also includes the UE; The UE is used to send the first PDU session creation request to the network device through the first RAN; The UE is also configured to receive the reporting instruction request sent by the network device; The UE is also used to send the second PDU session creation request to the network device through the second RAN.
24. The system according to claim 22, characterized in that, The communication system further includes the first RAN, the first RAN being used for: Receive the reporting instruction request sent by the network device; and send the user plane security activation status to the network device.
25. The system according to any one of claims 22 to 24, characterized in that, If the network device is a session management function, the session management function is used to send the user plane security activation state to the access and mobility management function, so that the access and mobility management function sends the user plane security activation state to the second RAN; If the network device is an access and mobility management function, then the access and mobility management function is used to send the user plane security activation status to the second RAN.
26. The system according to claim 25, characterized in that, The access and mobility management functions are specifically used for: Obtain the context information of the UE, determine the second RAN corresponding to the second 3GPP access corresponding to the MAPDU session supporting dual 3GPP access based on the context information of the UE, and send the user plane security activation status to the second RAN.
27. The system according to any one of claims 22 to 24, characterized in that, If the network device sends a reporting indication request to the first RAN, then after the network device sends the reporting indication request to the first RAN, the network device is further configured to: Receive the user plane security activation status sent by the first RAN.
28. The system according to any one of claims 22 to 24, characterized in that, If the network device sends a reporting indication request to the UE, the network device is further configured to: receive a second PDU session creation request sent by the UE through a second RAN, wherein the second PDU session creation request carries the user plane security activation status.
29. The system according to claim 28, characterized in that, The first PDU session creation request carries a PDU session identifier, a request type, and a dual 3GPP access indication. The request type is an MA PDU request, and the dual 3GPP access indication is used to indicate that the MA PDU session requested by the first PDU session creation request supports dual 3GPP access. The second PDU session creation request carries the PDU session identifier and request type, wherein the request type is an existing PDU session or a dual 3GPP access type.
30. The system according to any one of claims 22 to 24, characterized in that, If the network device is a first session management function, the first session management function is used to receive a PDU session context creation request sent by a second session management function. The PDU session context creation request carries a PDU session identifier and sends a PDU session context creation response to the second session management function. The PDU session context creation response carries the user plane security activation status corresponding to the PDU session identifier.
31. The system according to claim 22, characterized in that, The second RAN is specifically used to: generate a Radio Resource Control (RRC) connection reconfiguration message based on the user plane security activation state, and send the RRC connection reconfiguration message to the UE.
32. A communication system, characterized in that, The communication system includes network equipment and a second wireless access node (RAN). The network device is used to receive a first protocol data unit (PDU) session creation request sent by a user equipment (UE) through a first radio access node (RAN). The first PDU session creation request is used to request the creation of a multi-access MA PDU session that supports dual 3GPP access on a first 3GPP access. The network device is also used to determine the access traffic guidance, handover, splitting ATSSS rules and user plane security policies corresponding to the MA PDU session; and to send a PDU session creation acceptance to the UE, wherein the PDU session creation acceptance carries the ATSSS rules; The network device is further configured to receive a second PDU session creation request sent by the UE through the second RAN. The second PDU session creation request is used to request the creation of a MA PDU session supporting dual 3GPP access on the second 3GPP access. If the steering mode in the ATSSS rule includes a redundant mode, the second PDU session creation request carries the user plane security activation state determined on the first 3GPP access. The user plane security activation state includes whether the integrity protection and confidentiality protection of the user plane of the first 3GPP access are activated. When the confidentiality protection or integrity protection of the user plane security policy is preferred, the network device is also used to send the user plane security activation status to the second RAN; The second RAN is used to receive the user plane security activation state and perform user plane security activation with the UE based on the user plane security activation state.
33. The system according to claim 32, characterized in that, The communication system also includes the UE; The UE is used to send the first PDU session creation request to the network device through the first RAN; The UE is also configured to receive the PDU session creation acceptance sent by the network device; The UE is also used to send a second PDU session creation request to the network device through the second RAN.
34. The system according to claim 32 or 33, characterized in that, The first PDU session creation request carries a PDU session identifier, a request type, and a dual 3GPP access indication. The request type is an MA PDU request, and the dual 3GPP access indication is used to indicate that the MA PDU session requested by the first PDU session creation request supports dual 3GPP access. The second PDU session creation request also carries a PDU session identifier and a request type, wherein the request type is an existing PDU session or a dual 3GPP access session.
35. The system according to claim 32 or 33, characterized in that, The network device has access and mobility management functions or session management functions.
36. The system according to claim 35, characterized in that, If the network device is a first session management function, the first session management function is used to receive a PDU session context creation request sent by a second session management function, and the PDU session context creation request carries a PDU session identifier; The first session management function is also used to send a PDU session context creation response to the second session management function, wherein the PDU session context creation response carries the user plane security activation state corresponding to the PDU session identifier.
37. The system according to claim 32 or 33, characterized in that, The communication system further includes the first RAN, which is used to receive a user plane security activation status transmission indication sent by a network device. The user plane security activation status transmission indication is used to instruct the first RAN to send the first 3GPP access user plane security activation status to the second RAN and to send the user plane security activation status to the second RAN.
38. The system according to claim 32 or 33, characterized in that, The second RAN is specifically used to: generate an RRC connection reconfiguration message based on the user plane security activation state, and send the RRC connection reconfiguration message to the UE.
39. A communication device, characterized in that, The device includes a processor and a memory, the memory being used to store computer execution instructions, and the processor being used to execute the computer execution instructions stored in the memory, so that the device performs the method according to any one of claims 1-21.
40. A chip, characterized in that, The chip includes at least one processor and a communication interface, the communication interface being coupled to the at least one processor, the at least one processor being used to run computer programs or instructions to implement the communication method as described in any one of claims 1-21; The communication interface is used to communicate with other modules besides the chip.
41. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores instructions that, when executed, implement the communication method as described in any one of claims 1-21.