Data transmission method and communication device
Patent Information
- Application Number
- CN202280100731.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-31
- Publication Date
- 2025-05-09
AI Technical Summary
Access network equipment can decrypt user plane data during data transmission, which risks leakage and modification, affecting data security.
By deploying a protocol layer with encryption/decryption and integrity protection functions between terminal equipment and core network elements, access network equipment is prevented from decrypting user plane data and the security of data during transmission is ensured.
It improves data security, reduces operating costs, and supports flexible protocol stack deployment to adapt to different scenarios.
Smart Images

Figure CN119968824A_ABST
Abstract
Description
Data transmission method and communication device Technical Field
[0001] The present application relates to the field of communication technology, and in particular to a data transmission method and a communication device. Background Art
[0002] Access network equipment connects user devices (also known as terminal devices) to wireless networks, enabling them to exchange data with other devices. To ensure the security of user data during this exchange, terminal devices typically encrypt the user data using the Packet Data Convergence Protocol (PDCP) layer.
[0003] However, the communication between the access network equipment and the terminal equipment follows the same protocol layer structure, that is, the access network equipment side can decrypt the encrypted data of the terminal device at the PDCP layer, and the access network equipment side can see the plaintext user plane data (that is, unencrypted user data). Therefore, the access network equipment is often suspected of leaking or modifying the user plane data.
[0004] Summary of the Invention
[0005] The present application provides a data transmission method and a communication device to prevent access network equipment from encrypting / decrypting and performing integrity protection / verification on user plane data, thereby improving data security.
[0006] In a first aspect, the present application provides a data transmission method, comprising: a first device (data transmitter) performing integrity protection and encryption processing on first data through a first protocol layer to obtain second data; the first device transparently transmits the second data to a second device (data receiver) through an access network device; wherein both the first device and the second device are deployed with a first protocol layer, and the first protocol layer has the function of encrypting / decrypting data and the function of performing integrity protection / verification on data. Furthermore, when the first device is a terminal device, the second device is a first core network element; when the first device is a first core network element, the second device is a terminal device.
[0007] Based on the method described in the first aspect, during the data transmission process, the first core network element and the terminal device encrypt / decrypt and perform integrity protection / verification on the user plane data through the deployed first protocol layer, thereby preventing the access network device from decrypting the user plane data during the transmission process, thereby preventing the access network from knowing the plaintext user plane data, and improving the security of the data. In addition, after the user plane data is encrypted and integrity protected from the terminal device to the core network element, the link between the access network device and the core network element may not be encrypted. Compared with the transmission method that requires two encryptions (i.e., encryption between the terminal device and the access network device, and encryption of the link between the access network device and the core network element), the operating cost is reduced.
[0008] In one possible implementation, the protocol stack deployed on the terminal device consists of the first protocol layer, the Service Data Adaptation Protocol (SDAP) layer, the second protocol layer, the Radio Link Control (RLC) layer, the Media Access Control (MAC) layer, and the first physical layer. The second protocol layer includes packet sorting and packet replication functions. The protocol layers deployed on the first core network element consist of the first protocol layer, the user plane portion of the General Packet Radio Tunneling Protocol (GTP-U), the User Datagram Protocol (UDP), the Internet Protocol (IP), the data link layer protocol, and the second physical layer protocol. The protocol stack deployed on the access network device consists of the SDAP layer, the second protocol layer, the RLC layer, the MAC layer, and the first physical layer. The access network device also deploys GTP-U, UDP, IP, the data link layer protocol, and the second physical layer protocol. By implementing this possible implementation, the protocol stack supports flexible deployment, adapting to different scenarios.
[0009] In one possible implementation, the protocol stack deployed on the terminal device consists of the SDAP layer, the first protocol layer, the second protocol layer, the RLC layer, the MAC layer, and the first physical layer, in order. The second protocol layer has packet sorting, traffic diversion, and packet replication functions. The protocol layers deployed on the first core network element consist of the first protocol layer, GTP-U, UDP, IP, the data link layer protocol, and the second physical layer protocol, in order. The protocol stack deployed on the access network device consists of the SDAP layer, the second protocol layer, the RLC layer, the MAC layer, and the first physical layer, in order. The access network device also deploys GTP-U, UDP, IP, the data link layer protocol, and the second physical layer protocol, in order. By implementing this possible implementation, the protocol stack supports flexible deployment, adapting to different scenarios.
[0010] In one possible implementation, the protocol stack deployed on a terminal device consists of, in order, the first protocol layer, the third protocol layer, the RLC layer, the MAC layer, and the first physical layer. The first protocol layer also includes IP header compression and packet sorting, while the third protocol layer includes the SDAP layer's functions and packet replication. The protocol layers deployed on the first core network element consist of, in order, the first protocol layer, GTP-U, UDP, IP, a data link layer protocol, and a second physical layer protocol. The protocol stack deployed on the access network device consists of, in order, the third protocol layer, the RLC layer, the MAC layer, and the first physical layer. The access network device also includes, in order, GTP-U, UDP, IP, a data link layer protocol, and a second physical layer protocol. This possible implementation allows for flexible deployment of the protocol stack, adapting to diverse scenarios. Furthermore, IP header compression is performed on both the terminal device and the core network element, reducing the load on the GTP-U link compared to a scenario where IP header compression is performed on both the terminal device and the access network device.
[0011] In one possible implementation, when the first device is a terminal device, the first device sends a Protocol Data Unit (PDU) session establishment request message to a second core network element. The PDU session establishment request message is used to request the establishment of a PDU session for transmitting first data. The first device receives a PDU session establishment response message from the second core network element. The PDU session establishment response message includes a target encryption integrity policy. The target encryption integrity policy is determined based on one or more of the following policies: the encryption integrity policy of the terminal device, the encryption integrity policy of the session management function (SMF), the encryption integrity policy of the application function (AF), or the encryption integrity policy of the policy control function (PCF). Furthermore, the first device generates a first key and a second key based on the target encryption integrity policy. The first key is used to perform integrity protection / verification on the first data, and the second key is used to encrypt / decrypt the first data. By implementing this possible embodiment, the terminal device generates a key based on the target encryption integrity policy issued by the second core network element, ensuring that the terminal device and the first core network element have the same encryption integrity policy, thereby ensuring the normal encryption / decryption and integrity protection / verification of data.
[0012] In one possible implementation, the PDU session establishment request message includes the terminal device's encryption and security policy. By implementing this possible implementation, the terminal device carries the terminal device's encryption and security policy in the PDU session establishment request message, eliminating the need for additional signaling to transmit the terminal device's encryption and security policy, thereby saving communication resources. Furthermore, the second core network element can determine a target encryption and security policy based on the terminal device's encryption and security policy, making the target encryption and security policy more tailored to user needs.
[0013] In one possible implementation, when the first device is a first core network element, the first device receives a target encryption integrity policy from a second core network element; wherein the target encryption integrity policy is determined based on one or more of the following policies: the encryption integrity policy of the terminal device, the encryption integrity policy of the SMF, the encryption integrity policy of the AF, or the encryption integrity policy of the PCF; the first device receives a first key and a second key from the second core network element; wherein the first key is used to perform integrity protection / verification processing on the first data, and the second key is used to perform encryption / decryption processing on the first data; the first key and the second key are generated based on the target encryption integrity policy. By implementing this possible implementation method, the first core network element performs data encryption / decryption and integrity protection / verification through the target encryption integrity policy and key (including the first key and the second key) issued by the second core network element, ensuring that the terminal device and the first core network element correspond to the same encryption integrity policy, so as to ensure the normal encryption / decryption and integrity protection / verification of the data.
[0014] In one possible implementation, at the first protocol layer, the first device performs integrity protection processing on the first data according to the target encryption integrity policy and the first key; the first device performs encryption processing on the first data according to the target encryption integrity policy and the second key.
[0015] In one possible implementation, the encryption integrity policy includes a granularity for encrypting / decrypting or integrity protecting / verifying the first data, where the granularity is one of a PDU session, a Quality of Service flow, or a data flow. By implementing this possible implementation method, the efficiency and accuracy of encryption / decryption or integrity protection / verification of the data can be selected by controlling the granularity of encryption / decryption or integrity protection / verification of the data, thereby improving the flexibility of encryption integrity in the data transmission method of the present application.
[0016] In one possible implementation, the first device performs integrity protection processing on the first data based on the first key and the granularity identifier; the first device performs encryption processing on the first data based on the second key and the granularity identifier; wherein the granularity identifier is one of the QoS Flow identifier, the PDU session identifier, or the data flow identifier.
[0017] In one possible implementation, the encryption integrity policy is further used to instruct the terminal device to perform encryption / decryption processing or integrity protection / verification processing with the first core network element; or further used to instruct the terminal device to perform encryption / decryption processing or integrity protection / verification processing with the access network device. By implementing this possible implementation, the diversity of devices that encrypt and secure data can be increased, thereby improving the compatibility of the data transmission method provided in this application.
[0018] In a second aspect, the present application provides a data transmission method, which includes: a second device receives second data transmitted from a first device through an access network device; the second device decrypts and performs integrity verification on the second data through a first protocol layer to obtain first data; wherein, both the first device and the second device are deployed with a first protocol layer, and the first protocol layer has the function of encrypting / decrypting data and the function of performing integrity protection / verification on data; the first device is a terminal device, and the second device is a first core network network element; or, the first device is a first core network network element, and the second device is a terminal device.
[0019] The beneficial effects of the method provided in the second aspect can be found in the description of the beneficial effects of the method in the first aspect, which will not be repeated here.
[0020] In one possible implementation, the protocol stack deployed on the terminal device is, in order, the first protocol layer, the service data adaptation protocol (SDAP) layer, the second protocol layer, the radio link control (RLC) layer, the media access control (MAC) layer, and the first physical layer; wherein the second protocol layer has packet sorting and packet replication functions;
[0021] The protocol layers deployed by the first core network element are, in order, the first protocol layer, the user plane General Packet Radio Tunneling Protocol GTP-U, the User Datagram Protocol UDP, the Internet Protocol IP, the data link layer protocol and the second physical layer protocol;
[0022] The protocol stack deployed by the access network equipment includes the SDAP layer, the second protocol layer, the RLC layer, the MAC layer and the first physical layer in sequence. The access network equipment also deploys GTP-U, UDP, IP, the data link layer protocol and the second physical layer protocol in sequence.
[0023] In one possible implementation, the protocol stack deployed on the terminal device is, in order, the SDAP layer, the first protocol layer, the second protocol layer, the RLC layer, the MAC layer, and the first physical layer; wherein the second protocol layer has packet sorting, diversion, and packet replication functions;
[0024] The protocol layers deployed by the first core network element are the first protocol layer, GTP-U, UDP, IP, data link layer protocol and the second physical layer protocol.
[0025] The protocol stack deployed by the access network equipment includes the SDAP layer, the second protocol layer, the RLC layer, the MAC layer and the first physical layer in sequence. The access network equipment also deploys GTP-U, UDP, IP, the data link layer protocol and the second physical layer protocol in sequence.
[0026] In one possible implementation, the protocol stack deployed on the terminal device is, in order, the first protocol layer, the third protocol layer, the RLC layer, the MAC layer, and the first physical layer; wherein the first protocol layer also has the functions of IP header compression and data packet sorting, and the third protocol layer has the functions of the SDAP layer and a data packet replication function;
[0027] The protocol layers deployed by the first core network element are the first protocol layer, GTP-U, UDP, IP, data link layer protocol and the second physical layer protocol.
[0028] The protocol stack deployed by the access network equipment includes the third protocol layer, RLC layer, MAC layer and the first physical layer in sequence. The access network equipment also deploys GTP-U, UDP, IP, data link layer protocol and the second physical layer protocol in sequence.
[0029] In one possible implementation, when the second device is a terminal device, the second device sends a protocol data unit PDU session establishment request message to the second core network network element; the PDU session establishment request message is used to request the establishment of a PDU session for transmitting the second data; the second device receives a PDU session establishment response message from the second core network network element, and the PDU session establishment response message includes a target encryption integrity policy; wherein, the target encryption integrity policy is determined based on one or more of the following policies: the encryption integrity policy of the terminal device, the encryption integrity policy of the session management function SMF, the encryption integrity policy of the application function AF, or the encryption integrity policy of the policy control function PCF; the second device generates a first key and a second key according to the target encryption integrity policy; wherein, the first key is used to perform integrity protection / verification processing on the second data, and the second key is used to perform encryption / decryption processing on the second data.
[0030] In a possible implementation, the PDU session establishment request message includes the encryption security policy of the terminal device.
[0031] In one possible implementation, when the second device is the first core network network element, the second device receives a target encryption integrity policy from the second core network network element; wherein the target encryption integrity policy is determined based on one or more of the following policies: the encryption integrity policy of the terminal device, the encryption integrity policy of the SMF, the encryption integrity policy of the AF, or the encryption integrity policy of the PCF; the second device receives a first key and a second key from the second core network network element; wherein the first key is used to perform integrity protection / verification processing on the second data, and the second key is used to perform encryption / decryption processing on the second data; the first key and the second key are generated based on the target encryption integrity policy.
[0032] In one possible implementation, at the first protocol layer, the second device decrypts the second data according to the target encryption security policy and the second key; the second device performs integrity verification on the second data according to the target encryption security policy and the first key.
[0033] In a possible implementation, the encryption integrity policy includes a granularity of encryption / decryption or integrity protection / verification of the second data, where the granularity is one of a PDU session, a quality of service flow QoS Flow, or a data flow.
[0034] In one possible implementation, the second device decrypts the second data based on the second key and the granularity identifier; the second device performs integrity verification on the second data based on the first key and the granularity identifier; wherein the granularity identifier is one of the QoS Flow identifier, the PDU session identifier, or the data flow identifier.
[0035] In one possible implementation, the encryption integrity policy is also used to instruct the terminal device to perform encryption / decryption processing or integrity protection / verification processing with the first core network network element; or, it is also used to instruct the terminal device to perform encryption / decryption processing or integrity protection / verification processing with the access network device.
[0036] In the third aspect, the present application provides a method for determining an encryption integrity policy, the method comprising: the second core network network element determines a target encryption integrity policy for target data; the target encryption integrity policy is determined based on one or more of the following policies: the encryption integrity policy of the terminal device, the encryption integrity policy of the session management function SMF, the encryption integrity policy of the application function AF, or the encryption integrity policy of the policy control function PCF; the second core network network element sends the target encryption integrity policy to the terminal device, the access network device corresponding to the terminal device, and the first core network network element.
[0037] Based on the method described in the third aspect, after the second core network network element determines the target encryption and security policy, it sends the target encryption and security policy to the terminal device, access network device and the first core network network element, so that during the transmission of the target data, each transmission node (i.e., including the terminal device, access network device and the first core network network element) reaches a consensus on the encryption and security policy of the target data, which is conducive to improving the transmission efficiency and security of the target data.
[0038] In one possible implementation, a second core network element receives a protocol data unit (PDU) session establishment request message from a terminal device; the PDU session establishment request message is used to request the establishment of a PDU session for transmitting target data; and the second core network element sends a PDU session establishment response message to the terminal device, where the PDU session establishment response message includes a target encryption integrity policy. By implementing this possible implementation, the second core network element includes the target encryption integrity policy in the PDU session establishment response message, eliminating the need for additional signaling to transmit the target encryption integrity policy, thereby saving communication resources.
[0039] In one possible implementation, the PDU session establishment request message includes the terminal device's encryption and security policy. By implementing this possible implementation, the second core network element can determine a target encryption and security policy based on the terminal device's encryption and security policy, so that the target encryption and security policy can better meet user needs. Furthermore, the terminal device carries the terminal device's encryption and security policy in the PDU session establishment request message, eliminating the need for additional signaling to transmit the terminal device's encryption and security policy, thereby saving communication resources.
[0040] In one possible implementation, the second core network element generates a first key and a second key based on the target encryption integrity policy; wherein the first key is used to perform integrity protection / verification processing on the target data, and the second key is used to perform encryption / decryption processing on the target data; the second core network element sends the first key and the second key to the first core network element.
[0041] In one possible implementation, the encryption integrity policy includes the granularity of encryption / decryption or integrity protection / verification of the target data, where the granularity is one of a PDU session, a Quality of Service flow, or a data flow. By implementing this possible implementation method, the efficiency and accuracy of encryption / decryption or integrity protection / verification of the data can be selected by controlling the granularity of encryption / decryption or integrity protection / verification of the data, thereby improving the flexibility of encryption integrity in the data transmission method of the present application.
[0042] In one possible implementation, the encryption integrity policy is further used to instruct the terminal device to perform encryption / decryption processing or integrity protection / verification processing with the first core network element; or further used to instruct the terminal device to perform encryption / decryption processing or integrity protection / verification processing with the access network device. By implementing this possible implementation, the diversity of devices that encrypt and secure data can be increased, thereby improving the compatibility of the data transmission method provided in this application.
[0043] In a fourth aspect, the present application provides a communication device, which may be a first device, a device in the first device, or a device that can be used in combination with the first device; wherein, the communication device may also be a chip system, and the communication device may execute the method performed by the first device in the first to third aspects. The functions of the communication device may be implemented by hardware, or by hardware executing corresponding software implementations. The hardware or software includes one or more units corresponding to the above functions. The unit may be software and / or hardware. The operations and beneficial effects performed by the communication device can refer to the methods and beneficial effects described in the first to third aspects above, and the repeated parts will not be repeated.
[0044] In a fifth aspect, the present application provides a communication device, which may be a second device, or a device in the second device, or a device that can be used in combination with the second device; wherein, the communication device may also be a chip system, and the communication device may execute the method executed by the second device in the first to third aspects, or the communication device may execute the method executed by the second device in the first to third aspects. The functions of the communication device may be implemented by hardware, or by hardware executing corresponding software implementations. The hardware or software includes one or more units corresponding to the above functions. The unit may be software and / or hardware. The operations and beneficial effects performed by the communication device may refer to the methods and beneficial effects described in the first to third aspects above, and the repeated parts will not be repeated.
[0045] In a sixth aspect, the present application provides a communications device, which may be a second core network element, a device within the second core network element, or a device capable of being used in conjunction with the second core network element. The communications device may also be a system-on-chip (SoC) capable of executing the methods performed by the second core network element in aspects 1 through 3, or alternatively, the communications device capable of executing the methods performed by the second core network element in aspects 1 through 3. The functions of the communications device may be implemented in hardware or by hardware executing corresponding software. The hardware or software includes one or more units corresponding to the aforementioned functions. The units may be software and / or hardware. The operations and beneficial effects performed by the communications device may refer to the methods and beneficial effects described in aspects 1 through 3 above, and any repetitions will not be repeated.
[0046] In the seventh aspect, the present application provides a communication device, which includes a processor. When the processor calls a computer program in the memory, the method executed by the first device, the second device or the second core network element in the methods described in the first aspect to the third aspect is executed.
[0047] In an eighth aspect, the present application provides a communication device, comprising a processor and a memory, wherein the memory is used to store computer execution instructions; the processor is used to execute the computer execution instructions stored in the memory, so that the communication device executes the method executed by the first device, the second device or the second core network element in the methods described in the first aspect to the third aspect.
[0048] In the ninth aspect, the present application provides a communication device, which includes a processor, a memory and a transceiver, wherein the transceiver is used to receive or send signals; the memory is used to store a computer program; and the processor is used to call the computer program from the memory to execute the method executed by the first device, the second device or the second core network element in the methods described in the first to third aspects.
[0049] In the tenth aspect, the present application provides a communication device, which includes a processor and an interface circuit, wherein the interface circuit is used to receive computer execution instructions and transmit them to the processor; the processor runs the computer execution instructions to execute the method executed by the first device, the second device or the second core network element in the methods described in the first aspect to the third aspect.
[0050] In the eleventh aspect, the present application provides a computer-readable storage medium, which is used to store computer execution instructions. When the computer execution instructions are executed, the first device, the second device or the second core network element in the methods described in the first aspect to the third aspect executes the method.
[0051] In a twelfth aspect, the present application provides a communication device, which includes a function or unit for executing the method described in any one of the first to third aspects.
[0052] In a thirteenth aspect, the present application provides a computer program product comprising a computer program, which, when executed, enables the method executed by the first device, the second device or the second core network element in the methods described in the first to third aspects to be implemented.
[0053] In the fourteenth aspect, the present application provides a communication system, which includes a first device, a second device and a second core network element; wherein the first device is used to execute the method described in the first aspect, the second device is used to indicate the method of the second aspect, and the second core network element is used to execute the method described in the third aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0054] FIG1 is a schematic diagram of a network system architecture provided in an embodiment of the present application;
[0055] FIG2 is a schematic diagram of a core network architecture provided in an embodiment of the present application;
[0056] FIG3 is a schematic diagram of downlink data transmission between protocol layers according to an embodiment of the present application;
[0057] FIG4a is a schematic diagram of a protocol stack structure provided in an embodiment of the present application;
[0058] FIG4 b is a schematic diagram of another protocol stack structure provided in an embodiment of the present application;
[0059] FIG4c is a schematic diagram of another protocol stack structure provided in an embodiment of the present application;
[0060] FIG5 is a flow chart of a data transmission method provided in an embodiment of the present application;
[0061] FIG6 is a schematic diagram of a data flow of integrity protection and encryption processing provided by an embodiment of the present application;
[0062] FIG7 is a data flow diagram of a decryption process and integrity check process provided by an embodiment of the present application;
[0063] FIG8a is a flow chart of a method for determining target encryption integrity provided by an embodiment of the present application;
[0064] FIG8 b is a schematic diagram of a flow chart of a key generation method provided in an embodiment of the present application;
[0065] FIG9 is a schematic structural diagram of a communication device provided in an embodiment of the present application;
[0066] FIG10 is a schematic structural diagram of another communication device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0067] In order to make the purpose, technical solutions and advantages of this application clearer, this application will be further described in detail below with reference to the accompanying drawings.
[0068] The terms "first" and "second" and the like in the specification, claims, and drawings of this application are used to distinguish between different objects, not to describe a particular order. Furthermore, the terms "including" and "having," and any variations thereof, are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or apparatus comprising a series of operations or units is not limited to the listed operations or units, but may optionally include operations or units not listed, or may optionally include other operations or units inherent to the process, method, product, or apparatus.
[0069] References herein to "embodiments" mean that a particular feature, structure, or characteristic described in connection with the embodiments may be included in at least one embodiment of the present application. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor does it constitute an independent or alternative embodiment that is mutually exclusive of other embodiments. It is understood, both explicitly and implicitly, by those skilled in the art that the embodiments described herein may be combined with other embodiments.
[0070] In the present application, "at least one (item)" refers to one or more, "more than one" refers to two or more, "at least two (items)" refers to two or three and more than three, and "and / or" is used to describe the corresponding relationship of corresponding objects, indicating that there can be three relationships. For example, "A and / or B" can mean: only A exists, only B exists, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally indicates that the corresponding objects before and after are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.
[0071] To better understand the embodiments of the present application, the following first introduces the system architecture involved in the embodiments of the present application:
[0072] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as: long term evolution (LTE) system, LTE frequency division duplex (FDD) system, LTE time division duplex (TDD), new radio (NR), the 3rd generation partner project (3GPP) service-based network architecture (SBA), and other fifth generation (5G) communication systems or sixth generation (6G) communication systems and other communication systems evolved after 5G.
[0073] Please refer to Figure 1, which is a schematic diagram of a network system architecture provided by an embodiment of the present application. As shown in Figure 1, a terminal device can access a wireless network to obtain services of an external network (such as a data network (DN)) through the wireless network, or communicate with other devices through the wireless network, such as communicating with other terminal devices. The wireless network includes a (radio) access network ((R)AN) and a core network (CN), wherein the (R)AN (hereinafter described as RAN) is used to access the terminal device to the wireless network, and the CN is used to manage the terminal device and provide a gateway for communicating with the DN. The terminal device, RAN, CN and DN involved in the system architecture in Figure 1 are described in detail below.
[0074] 1. Terminal Equipment
[0075] Terminal devices include devices that provide voice and / or data connectivity to users. For example, a terminal device is a device with wireless transceiver capabilities that can be deployed on land, including indoors or outdoors, handheld, wearable, or vehicle-mounted; it can also be deployed on the water (such as ships, etc.); it can also be deployed in the air (such as airplanes, balloons, and satellites, etc.). The terminal device can be a mobile phone, a tablet computer, a computer with wireless transceiver capabilities, a virtual reality (VR) terminal, an augmented reality (AR) terminal, a wireless terminal in industrial control, a vehicle-mounted terminal, a wireless terminal in self-driving, a wireless terminal in remote medical care, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, a wireless terminal in a smart home, a wearable terminal, etc. The embodiments of the present application do not limit the application scenarios. Terminal equipment may sometimes also be referred to as terminal, user equipment (UE), access terminal, vehicle-mounted terminal, industrial control terminal, UE unit, UE station, mobile station, mobile station, remote station, remote terminal, mobile device, UE terminal, wireless communication equipment, UE agent or UE device, etc. The terminal may also be fixed or mobile. It will be understood that all or part of the functions of the terminal in this application may also be implemented by software functions running on hardware, or by virtualization functions instantiated on a platform (such as a cloud platform). The terminal device in this application may be a terminal for 5G or a terminal for 6G, and this application does not limit this.
[0076] 2. RAN
[0077] The RAN may include one or more RAN devices (or access network devices). The interface between the access network device and the terminal device may be a Uu interface (or air interface). Of course, in communications evolved after 5G, the names of these interfaces may remain unchanged or may be replaced by other names, and this application does not limit this.
[0078] Access network equipment is a node or device that connects a terminal device to a wireless network. Examples of access network equipment include, but are not limited to, next generation node B (gNB), evolved node B (eNB), next generation eNB (ng-eNB), wireless backhaul equipment, radio network controller (RNC), node B (NB), home evolved node B (HeNB) or home node B (HNB), baseband unit (BBU), transmitting and receiving point (TRP), transmitting point (TP), mobile switching center, and equipment that performs base station functions in device-to-device (D2D), vehicle-to-everything (V2X), and machine-to-machine (M2M) communications in 5G communication systems. It may also include centralized units (C-RAN) in cloud radio access network (C-RAN) systems. The RAN in this application may be a 5G RAN or a 6G RAN, and this application does not limit this.
[0079] 3. CN
[0080] The CN may include one or more CN devices (which may be understood as network element devices or network functions (NFs)). In the following text, the CN devices are collectively referred to as core network elements (eg, the first core network element and the second core network element in the following text).
[0081] Please refer to Figure 2, which is a structural diagram of a CN provided by this application. The CN in Figure 2 is a schematic diagram of the CN in the 5G network architecture. The CN shown in Figure 2 includes multiple CN devices: network slice selection function (NSSF), network exposure function (NEF), network function repository function (NRF), policy control function (PCF), unified data management (UDM), application function (AF), network control function (NCF), network slice specific authentication and authorization function (NSSAAF), authentication server function (AUSF), access and mobility management function (AMF), session management function (SMF), user plane function (UPF), service communication proxy (SCP), network slice admission control function (NSACF). Among them:
[0082] The AMF is a control plane function provided by the operator network, responsible for access control and mobility management of terminal devices accessing the operator network, such as mobility status management, allocating temporary user identities, and authenticating and authorizing users.
[0083] SMF is a control plane function provided by the operator network, responsible for managing the protocol data unit (PDU) sessions of terminal devices. A PDU session is a channel for transmitting PDUs. Terminal devices need to transmit PDUs to and from the DN through PDU sessions. The SMF is responsible for establishing, maintaining, and deleting PDU sessions. SMF includes session management (such as session establishment, modification, and release, including tunnel maintenance between the UPF and RAN), UPF selection and control, service and session continuity (SSC) mode selection, roaming, and other session-related functions.
[0084] The PCF is a control plane function provided by the operator, including user subscription data management, policy control, charging policy control, and Quality of Service (QoS) control. It is mainly used to provide PDU session policies to the SMF. Among them, the policies may include charging-related policies, QoS-related policies, and authorization-related policies.
[0085] The UPF is a gateway provided by the operator, serving as the gateway for communication between the operator's network and the DN. The UPF includes user-plane-related functions such as packet routing and transmission, packet inspection, quality of service (QoS) processing, uplink packet inspection, and downlink packet storage.
[0086] The UDM is primarily used to manage user subscription and authentication data, as well as perform authentication credit processing, user identity processing, access authorization, registration / mobility management, subscription management, and short message management. In some embodiments, the UDM may also include a unified data repository (UDR). Alternatively, in other embodiments, the 3GPP SBA of the 5G system may also include a UDR. The UDR is used to provide storage and retrieval for PCF policies, storage and retrieval of open structured data, and storage of user information requested by application functions.
[0087] It should be noted that the above-mentioned CN devices may also be referred to as network elements or functional network elements. In a 5G communication system, each functional network element may be the name of each functional network element shown in Figure 2. In a communication system evolved after 5G (such as a 6G communication system), each functional network element may still be the name of each functional network element shown in Figure 2, or may have other names. For example, in a 5G communication system, the user plane function may be a UPF. In a communication system evolved after 5G (such as a 6G communication system), the user plane function may still be a UPF, or may have other names, which is not limited in this application.
[0088] It should also be noted that in the 5G communication system, the functions implemented by each functional network element can be independent as shown in Figure 2. In the communication system evolved after 5G (such as the 6G communication system), each functional network element can still be in an independent state as shown in Figure 2, or the functions of multiple functional network elements in Figure 2 can be implemented by an integrated functional network element. For example, in the 5G communication system, the user plane related functions are implemented by the UPF, and the access and mobility management related functions are implemented by the AMF. In the communication system evolved after 5G (such as the 6G communication system), the user plane related functions can still be implemented by the UPF, and the access and mobility management related functions can still be implemented by the AMF, or the user plane related functions and the access and mobility management related functions can be implemented by an integrated functional network element at the same time, which is not limited in this application.
[0089] In Figure 2, Npcf, Nudm, Naf, Namf, Nsmf, N1, N2, N3, N4, and N6 are interface serial numbers. The meanings of these interface serial numbers can be found in the definitions of relevant standard protocols and are not limited here.
[0090] 4. DN
[0091] DN, also known as packet data network (PDN), is a network located outside the operator network. The operator network can access multiple DNs. Application servers corresponding to various services can be deployed in the DN to provide a variety of possible services for terminal devices.
[0092] To better understand the solution provided by this application, the following describes the protocol layer structure:
[0093] Communication between terminal devices and access network devices follows a specific protocol layer structure, and communication between access network devices and core network elements (such as UPF) must also follow a specific protocol layer structure. For example, the user plane protocol layer structure between access network devices and terminal devices (which can be understood as the user plane protocol layer structure for air interface transmission) includes: the service data adaptation protocol (SDAP) layer, the PDCP layer, the radio link control (RLC) layer, the media access control (MAC) layer, and the first physical layer (PHY layer); the user plane protocol layer structure between access network devices and core network elements (which can be understood as the user plane protocol structure for wired transmission) includes: the general packet radio service tunneling protocol for the user plane (GTP-U), the user datagram protocol (UDP), the internet protocol (IP), the data link layer (hereinafter collectively referred to as L2), and the second physical layer (hereinafter collectively referred to as L1).
[0094] Taking downlink data transmission as an example, Figure 3 illustrates the transmission of downlink data between protocol layers. Downward arrows in Figure 3 indicate data transmission, and upward arrows indicate data reception. In Figure 3, data on the UPF side undergoes GTP-U processing, UDP processing, IP processing, Layer 2 processing, and Layer 1 processing in sequence. The UPF then transmits this data to the access network device. On the access network device side, the data is first processed using the wired transmission protocol, sequentially undergoing Layer 1 processing, Layer 2 processing, IP processing, UDP processing, and GTP-U processing. The access network device then processes the data using the air interface transmission protocol, sequentially undergoing processing at the SDAP layer, PDCP layer, RLC layer, MAC layer, and PHY layer. Furthermore, the access network device transmits this data over the air interface to the terminal device. On the terminal device side, the data is processed using the air interface transmission protocol, sequentially undergoing processing at the PHY layer, MAC layer, RLC layer, PDCP layer, and SDAP layer. The uplink data transmission process is in the opposite direction to the arrows in Figure 3 and will not be described in detail here.
[0095] The following uses the protocol layer in 5G as an example to introduce the functions of some protocol layers involved in this application:
[0096] (1)SDAP
[0097] The SDAP layer sits above the PDCP layer and directly carries user-plane IP packets. Its functions include, but are not limited to, mapping QoS flows to data radio bearers (DRBs) and adding QoS flow indicators (QFIs) to packets.
[0098] (2)PDCP
[0099] The functions of the PDCP layer include but are not limited to: user IP header compression function (the specific compression algorithm is jointly determined by the terminal device and the access network device); encryption / decryption (for control plane / user plane data); data integrity protection / verification (in 4G, the PDCP layer only performs integrity protection / verification on control plane data; in 5G, the PDCP layer can perform integrity protection / verification on control plane data, and can also perform integrity protection / verification on user plane data (optional)); data packet sorting function; data packet replication function; diversion function, etc.
[0100] (3)RLC
[0101] The RLC layer is located below the PDCP layer. Since RLC entities transmit data in three modes: Transparent Mode (TM), Unacknowledged Mode (UM), and Acknowledged Mode (AM), RLC entities can be classified into TM entities, UM entities, and AM entities. AM data transmission and reception share the same entity, while UM and TM data transmission and reception entities are separate. RLC functions include but are not limited to:
[0102] TM (broadcast message), UM (voice service, with delay requirements), AM (normal service, with high accuracy); segmentation and reassembly (UM / AM, the size of the segmented data packet is determined by the MAC, with larger data packets in a good wireless environment and smaller data packets in a poor wireless environment); error correction (only for AM transmission, automatic repeat-request (ARQ) transmission, and high-accuracy transmission).
[0103] (4)MAC
[0104] The MAC layer in 5G functions similarly to that in 4G, with its primary function being scheduling. The MAC layer in 5G includes, but is not limited to, resource scheduling, mapping between logical and transport channels, multiplexing / demultiplexing, and asynchronous hybrid automatic repeat request (HARQ) for uplink and downlink transmission.
[0105] (5)PHY
[0106] The functions of the 5G physical layer include but are not limited to: error detection, forward error correction (FEC) encryption and decryption, rate matching, physical channel mapping, adjustment and demodulation, frequency synchronization and time synchronization, wireless measurement, and multiple-input multiple-output (MIMO) processing.
[0107] (6)GTP-U
[0108] General Packet Radio Service (GPRS) is a wireless packet switching technology based on the Global System for Mobile Communications (GSM) system, providing end-to-end, wide-area wireless IP connectivity. The GPRS tunneling protocol (GTP) is a set of communication protocols based on the Internet Protocol (IP) used to carry GPRS in GSM networks. These protocols include the control plane protocol (also known as GTP-C) and the user plane protocol (GTP-U). The payload in GTP-U refers to the user's original data packets, such as IP packets or Ethernet packets.
[0109] During data transmission, encryption and decryption are performed at the PDCP layer by the access network device and the terminal device. That is, in the downlink data transmission process shown in Figure 3, user plane data is integrity protected and encrypted at the PDCP layer on the access network device side, and decrypted and integrity-checked at the PDCP layer on the terminal device side. Similarly, during uplink data transmission, user plane data is integrity protected and encrypted at the PDCP layer on the terminal device side, and decrypted and integrity-checked at the PDCP layer on the access network device side. This indicates that the access network device can see unencrypted user plane data, posing security risks such as data leakage.
[0110] The present application provides a data transmission method that can improve the security of data during data transmission. The data transmission method and communication device provided by the present application are further described below with reference to the accompanying drawings:
[0111] For ease of understanding, before introducing the data transmission method provided in this application, the protocol stack structure followed by the terminal device, access network device and first core network network element in this application is first explained.
[0112] In the present application, the terminal device and the first core network element are deployed with a first protocol layer (having the function of encrypting / decrypting data and the function of performing integrity protection / verification on data). Furthermore, the terminal device and the first core network element can perform integrity protection / verification on data, as well as encrypt / decrypt data through the first protocol layer. Specifically, in the present application, any one of the following three protocol stack structures can be followed between the terminal device, the first core network element and the access network device. In one possible implementation, the first protocol layer can be a service data protection protocol (SDPP).
[0113] Structure 1: See Figure 4a.
[0114] The protocol stack deployed on terminal devices (which can be understood as the air interface transmission protocol stack) consists of the first protocol layer, SDAP, the second protocol layer, RLC, MAC, and PHY. The protocol stack deployed on the first core network element (which can be understood as the wired transmission protocol stack) consists of the first protocol layer, GTP-U, UDP, IP, L2, and L1. The air interface transmission protocol stack deployed on access network devices consists of SDAP, the second protocol layer, RLC, MAC, and PHY; the wired transmission protocol stack deployed on access network devices consists of GTP-U, UDP, IP, L2, and L1. The functions of the second protocol layer include packet sorting and packet replication.
[0115] In other words, the PDCP functionality is split into two parts: the first layer, which includes data integrity protection / verification and data encryption / decryption, is deployed as the upper layer of SDAP; the second layer, which includes packet sorting and packet replication, is deployed as the lower layer of SDAP. Access network devices do not implement the first layer and therefore cannot process data packets through it.
[0116] In one possible implementation, the first protocol layer further has an IP header compression function, that is, the IP header compression function in PDCP is placed in the first protocol layer. In another possible implementation, the second protocol layer further has an IP header compression function, that is, the IP header compression function in PDCP is placed in the second protocol layer.
[0117] It should be noted that, in the process of sending data, the protocol layer that processes the data packet first in the protocol stack can be considered as the upper protocol layer of the protocol layer that processes the data packet later; or, in the process of receiving data, the protocol layer that processes the data packet first can be considered as the lower protocol layer of the protocol layer that processes the data packet later. The order of "sequentially" mentioned in this application can be understood as the order in which the data packet is processed in each protocol layer during the data transmission process of the device deploying the protocol stack (that is, in the order from upper layer protocol to lower layer protocol in the protocol stack). The first core network element mentioned in this application is a user plane function that can transmit user plane data. For example, the first core network element is the UPF in the 5G CN shown in Figure 2. The full text is as follows.
[0118] Structure 2: See Figure 4b.
[0119] The protocol stack deployed on terminal devices (which can be understood as the air interface transmission protocol stack) consists of SDAP, Layer 1, Layer 2, RLC, MAC, and PHY. The protocol stack deployed on the first core network element (which can be understood as the wired transmission protocol stack) consists of Layer 1, GTP-U, UDP, IP, Layer 2, and Layer 1. The air interface transmission protocol stack deployed on access network devices consists of SDAP, Layer 2, RLC, MAC, and PHY. The wired transmission protocol stack deployed on access network devices consists of GTP-U, UDP, IP, Layer 2, and Layer 1.
[0120] In other words, in Structure 2, the functions of PDCP are divided into two parts: a part including the functions of integrity protection / verification of data and encryption / decryption of data (i.e., the first protocol layer), and a part including the functions of data packet sorting and data packet replication (i.e., the second protocol layer). The terminal device and the first core network element are deployed with the first protocol layer, while the access network device is not deployed with the first protocol layer. Therefore, the terminal device and the first core network element can process the data packet through the first protocol layer, while the access network device cannot process the data packet through the first protocol layer. For example, after the terminal device processes the first data through the first protocol layer (i.e., encryption processing and integrity protection processing), it obtains the second data; after the access network device receives the second data from the terminal device, it encapsulates the second data in the payload part of GTP-U and sends the second data to the first core network element; after the first core network element receives the second data, it processes the second data through the first protocol layer (i.e., decryption processing and integrity verification processing) to obtain the first data.
[0121] In one possible implementation, the first protocol layer further has an IP header compression function, that is, the IP header compression function in PDCP is placed in the first protocol layer. In another possible implementation, the second protocol layer further has an IP header compression function, that is, the IP header compression function in PDCP is placed in the second protocol layer.
[0122] Structure 3: See Figure 4c.
[0123] The protocol stack deployed on the terminal device (which can be understood as the air interface transmission protocol stack) consists of the first protocol layer, the third protocol layer, RLC, MAC, and PHY. The protocol stack deployed on the first core network element (which can be understood as the wired transmission protocol stack) consists of the first protocol layer, GTP-U, UDP, IP, L2, and L1. The air interface transmission protocol stack deployed on the access network device consists of the third protocol layer, RLC, MAC, and PHY; the wired transmission protocol stack deployed on the access network device consists of GTP-U, UDP, IP, L2, and L1. The third protocol layer has the aforementioned SDAP functionality and the aforementioned PDCP packet replication functionality.
[0124] This means that in Structure 3, the PDCP packet replication function is deployed at the SDAP layer, while the first protocol layer, which performs other functions besides packet replication (such as data encryption / decryption, data integrity protection / verification, and IP header compression), is deployed above the SDAP layer. Access network devices do not have the first protocol layer deployed, so they cannot process data packets at the first protocol layer.
[0125] It should be noted that in Structure 3, the aforementioned PDCP offload function is mainly used in non-standalone (NSA) scenarios. In this application, the first protocol layer may not have the original PDCP offload function.
[0126] The transmission method provided by the present application will be explained in detail below with reference to the accompanying drawings. Please refer to Figure 5, which is a flow chart of a data transmission method provided by an embodiment of the present application. As shown in Figure 5, the data transmission method includes the following S501 to S503. The execution subject of the method shown in Figure 5 can be a first device (sending device), a second device (receiving device), an access network device, and a second core network element, or the execution subject of the method shown in Figure 5 can be a chip of the first device, a chip of the second device, a chip of the access network device, and a chip of the second core network element. Figure 5 takes the first device, the second device, the access network device, and the second core network element as the execution subject of the method as an example for explanation. Among them:
[0127] S501. A first device performs integrity protection and encryption processing on first data through a first protocol layer to obtain second data.
[0128] The first device is deployed with a first protocol layer, which has the functions of encrypting / decrypting data and performing integrity protection / verification on data.
[0129] That is to say, the first device performs integrity protection on the first data at the first protocol layer using a first key (a key used for data integrity protection / verification) to ensure the integrity of the first data during transmission; and encrypts the first data using a second key (a key used for data encryption / decryption) to ensure the security of the first data during transmission.
[0130] Among them, the first key and the second key are generated according to the target encryption security policy, and the target encryption security policy is determined by the second core network element according to one or more of the following policies: the encryption security policy of the terminal device (the first device or the second device in Figure 5), the encryption security policy of the SMF, the encryption security policy of the AF or the encryption security policy of the PCF.
[0131] In one possible implementation, the second core network element obtains one or more of the encryption integrity policy of the terminal device (the first device or the second device in FIG5 ), the encryption integrity policy of the SMF, the encryption integrity policy of the AF, or the encryption integrity policy of the PCF, and then determines the target encryption integrity policy. Furthermore, the second core network element sends the target encryption integrity policy to the first device, the second device, and the access network device, so that the first device, the second device, and the access network device reach a consensus on the encryption / decryption and integrity protection / verification of the first data. It should be noted that the second core network element is an access and mobility management function, for example, the second core network element is the AMF in the 5G CN shown in FIG2 .
[0132] That is to say, after the second core network network element obtains the encryption integrity policy from one or more of the terminal device, SMF, AF or PCF, the second core network network element coordinates according to certain determination rules (such as device priority, encryption / decryption processing efficiency, integrity protection / verification processing efficiency, data security requirement, etc.), determines the target encryption integrity policy, and sends the target encryption integrity policy to the first device, the second device and the access network device.
[0133] The encryption integrity policy includes a granularity for encrypting / decrypting or integrity protecting / checking the first data, where the granularity is one of a packet data unit (PDU) session, a QoS flow (also known as a QoS flow), or a data flow. Furthermore, the encryption integrity policy may also be used to instruct: the terminal device to perform encryption / decryption processing or integrity protection / checking processing with the first core network element; or to instruct the terminal device to perform encryption / decryption processing or integrity protection / checking processing with the access network device.
[0134] It is understandable that a PDU session can include one or more QoS Flows, and a QoS Flow can include one or more data flows. In other words, the granularity of encryption and integrity protection, from largest to smallest, is PDU session granularity, QoS Flow granularity, and data flow granularity. This approach allows the granularity of encryption / decryption or integrity protection / verification to be selected based on business requirements (or data encryption requirements), improving the flexibility of data encryption / decryption or integrity protection / verification.
[0135] For example, the PDU session corresponding to the first data (or understood as being used to transmit the first data) includes three QoS flows: QoS Flow 1, QoS Flow 2, and QoS Flow 3; each QoS Flow includes two data flows, for example, QoS Flow 1 includes data flow 11 and data flow 12. In this case, if the encryption requirement for the first data is to encrypt all data transmitted in the PDU session (i.e., all QoS Flows or all data flows), the granularity of encryption / decryption or integrity protection / verification for the first data can be the PDU session granularity. If the encryption requirement for the first data is to encrypt QoS Flow 1 and QoS Flow 2 but not encrypt QoS Flow 3, the granularity of encryption / decryption or integrity protection / verification for the first data can be the QoS Flow granularity. If the encryption requirement for the first data is to encrypt only data flow 11, the granularity of encryption / decryption or integrity protection / verification for the first data can be the data flow granularity.
[0136] Furthermore, after the first device receives the target encryption integrity policy for the target data (i.e., the first data) from the second core network network element, the first device performs integrity protection processing on the first data at the first protocol layer according to the target encryption integrity policy and the first key; and encrypts the first data at the first protocol layer according to the target encryption integrity policy and the second key.
[0137] Specifically, in one possible implementation, the first device performs integrity protection on the first data based on the first key and the granularity identifier in the target encryption integrity policy; and encrypts the first data based on the second key and the granularity identifier in the target encryption integrity policy. The granularity identifier is one of a QFI (i.e., a QoS Flow identifier), a PDU session identifier, or a data flow identifier. The data flow identifier can be an IP five-tuple or an L2 address, etc.
[0138] For example, as shown in 6a in Figure 6, the first device uses the first key and granularity identifier as input parameters of the integrity algorithm to generate a message authentication code corresponding to the first data, and then appends the message authentication code to the first data to obtain the first data that has undergone integrity protection. Furthermore, as shown in 6b in Figure 6, the first device uses the second key and granularity identifier as input parameters of the encryption algorithm to generate a data keystream block (also known as a keystream block), and uses the data keystream block to encrypt the first data that has undergone integrity protection (i.e., the first data that includes the message authentication code) to obtain the second data.
[0139] S502: The first device transparently transmits the second data to the second device via the access network device. Correspondingly, the second device receives the second data transparently transmitted by the first device via the access network device.
[0140] In other words, the first device sends the second data to the access network device, the access network device does not perform decryption processing and integrity verification processing on the second data, and the access network device sends the second data to the second device.
[0141] Among them, when the first device is a terminal device, the second device is a first core network network element; or, when the first device is a first core network network element, the second device is a terminal device.
[0142] S503: The second device performs decryption processing and integrity verification processing on the second data through the first protocol layer to obtain the first data.
[0143] The second device is deployed with a first protocol layer, which has the functions of encrypting / decrypting data and performing integrity protection / verification on data.
[0144] That is to say, the second device decrypts the second data using the second key (the key used for data encryption / decryption) at the first protocol layer to ensure the security of the first data during transmission; and performs integrity verification on the second data using the first key (the key used for data integrity protection / verification) to ensure the integrity of the first data during transmission.
[0145] It should be noted that the description of the first key, the second key and the target encryption security policy (used to generate the first key and the second key) can be found in the relevant description in the aforementioned S501 and will not be repeated here.
[0146] In one possible implementation, the second device receives a target encryption integrity policy for target data (i.e., second data) from a second core network element. Furthermore, the second device performs integrity verification on the second data at a first protocol layer based on the target encryption integrity policy and a first key, and decrypts the second data at the first protocol layer based on the target encryption integrity policy and a second key.
[0147] Specifically, in one possible implementation, the second device performs integrity verification on the second data based on the first key and the granularity identifier in the target encryption integrity policy; and decrypts the second data based on the second key and the granularity identifier in the target encryption integrity policy. The granularity identifier is one of a QFI, a PDU session identifier, or a data flow identifier. The data flow identifier can be an IP quintuple or an L2 address, for example.
[0148] For example, as shown in 7a of Figure 7 , the second device uses the second key and granularity identifier as input parameters of the encryption algorithm to generate a data keystream block. The data keystream block is then used to decrypt the second data, obtaining first data containing a message authentication code. Furthermore, as shown in 7b of Figure 7 , the second device uses the first key and granularity identifier as input parameters of the integrity algorithm to verify the message authentication code in the first data, obtaining first data that has undergone integrity verification.
[0149] In summary, in the data transmission process described in Figure 5, the devices that perform encryption / decryption and integrity protection / verification on the first data (such as user plane data) are the terminal device and the first core network network element. That is, when the terminal device encrypts the first data and performs data integrity protection, the first core network network element decrypts the first data and performs data integrity verification; when the first core network network element encrypts the first data and performs data integrity protection, the terminal device decrypts the first data and performs data integrity verification. Through such a data transmission method, it is possible to avoid the access network device from decrypting the user plane data during the transmission process, thereby avoiding the access network from knowing the plaintext user plane data, and improving the security of the data.
[0150] According to the foregoing, both the first key used for data integrity protection / verification and the second key used for data encryption / decryption are generated according to the target encryption integrity policy. The following will explain how to determine the target encryption integrity policy in the data transmission process. Please refer to Figure 8a, which is a flow chart of a method for determining an encryption integrity policy. It should be noted that, for ease of understanding, Figure 8a only provides a schematic introduction using the core network element in the 5G CN as an example, and cannot be regarded as a specific limitation of the present application. Among them, when the terminal device in Figure 8a is the first device in Figure 5, the first core network element in Figure 8a is the second device in Figure 5; when the terminal device in Figure 8a is the second device in Figure 5, the first core network element in Figure 8a is the first device in Figure 5.
[0151] As shown in Figure 8a, the key generation method includes the following S801 to S802. The execution subject of the method shown in Figure 8a can be a terminal device, a first core network network element, an access network device, and a second core network network element, or the execution subject of the method shown in Figure 8a can be a chip of the terminal device, a chip of the first core network network element, a chip of the access network device, and a chip of the second core network network element. Figure 8a takes the terminal device, the first core network network element (such as the UPF in Figure 8a), the access network device, and the second core network network element (such as the AMF in Figure 8a) as the execution subject of the method as an example for explanation. Among them:
[0152] S801. AMF determines the target encryption and security policy for the target data; the target encryption and security policy is determined based on one or more of the following policies: the encryption and security policy of the terminal device, the encryption and security policy of the SMF, the encryption and security policy of the AF, or the encryption and security policy of the PCF.
[0153] The target data may be the first data in FIG5 or the second data (i.e., the first data that has been encrypted and integrity protected). For an explanation of the encryption integrity protection strategy, please refer to the description of the encryption integrity protection strategy in S501 above, which will not be described here.
[0154] That is to say, one or more devices among the terminal device, SMF, AF or PCF can send encryption integrity policies to AMF according to their own needs. Then, AMF coordinates the received encryption integrity policies according to certain determination rules (such as device priority, encryption / decryption processing efficiency, integrity protection / verification processing efficiency, data security requirements, etc.) and determines the target encryption integrity policy. Among them, the determination rule can be a rule preset on the network side or a rule determined according to business needs, and can be adaptively adjusted according to specific application scenarios, which is not specifically limited here.
[0155] Exemplarily, the AMF receives the encryption security policy from the terminal device, the encryption security policy of the SMF, the encryption security policy of the AF, and the encryption security policy of the PCF. The priority of the preset devices corresponding to the encryption security policies is SMF, PCF, terminal device, and AF, from high to low. In this case, the AMF may determine the encryption security policy of the SMF as the target encryption security policy.
[0156] S802. AMF sends the target encryption security policy to the terminal device, access network device and UPF.
[0157] After AMF determines the target encryption security policy, it sends the target encryption security policy to the terminal device, access network device, and UPF respectively, so that during the transmission of the target data, each transmission node (i.e., including the terminal device, access network device, and the first core network element) reaches a consensus on the encryption security policy of the target data, which is conducive to improving the transmission efficiency and security of the target data. It should be noted that when UPF receives the target encryption security policy sent by AMF, it can also receive the first key and the second key generated by AMF according to the target encryption security policy. After the terminal device receives the target encryption security policy sent by AMF, the terminal device can generate the first key and the second key according to the target encryption security policy. After the access network device receives the target encryption security policy, it cannot obtain the first key and the second key.
[0158] In one possible implementation, the terminal device sends a PDU session establishment request or a PDU session modification request to the AMF through the access network device. Furthermore, the AMF may send the target encryption integrity policy to the terminal device by sending a PDU session establishment response or a PDU session modification response to the terminal device through the access network device, wherein the PDU session establishment response or the PDU session modification response carries the target encryption integrity policy.
[0159] In a possible implementation, the way in which AMF obtains the encryption and security policy of the terminal device can be: when the terminal device sends a PDU session establishment request or a PDU session modification request to the AMF through the access network device, the PDU session establishment request or the PDU session modification request carries the encryption and security policy of the terminal device.
[0160] In order to more intuitively demonstrate the method for determining the target encryption security strategy described in Figure 8a, Figure 8b takes the example of the terminal device sending a PDU session establishment request to the AMF as an example for exemplary explanation. Please refer to Figure 8b, which is a flow chart of a key generation method. As shown in Figure 8b, the key generation method includes the following S8001 to S8012. The execution subject of the method shown in Figure 8b can be a terminal device, a first core network element, an access network device, and a second core network element, or the execution subject of the method shown in Figure 8b can be a chip of the terminal device, a chip of the first core network element, a chip of the access network device, and a chip of the second core network element. Figure 8b takes the terminal device, the first core network element (such as the UPF in Figure 8b), the access network device, and the second core network element (such as the AMF in Figure 8b) as the execution subject of the method as an example for explanation. Among them:
[0161] (Optionally) S8001. AMF receives the encryption protection policy for the target data from SMF, PCF or AF.
[0162] The target data may be the first data in FIG5 or the second data (i.e., the first data that has been encrypted and integrity protected).
[0163] S8002. AMF sends a security mode command (also known as a security mode command) to the terminal device.
[0164] The security mode command is used to configure security-related information, such as encryption algorithms and integrity protection algorithms.
[0165] S8003. The terminal device sends a security mode configuration completion (also known as security mode complete) message to the AMF.
[0166] S8004. AMF receives a PDU session establishment request (also known as a PDU session establishment request) sent by the terminal device through the access network device.
[0167] The PDU session establishment request is used to request the establishment of a PDU session for transmitting target data.
[0168] In one possible implementation method, the PDU session establishment request carries the encryption and security policy of the terminal device. That is, when the terminal device requests the AMF to establish a PDU session, it sends the encryption and security policy of the terminal device to the AMF.
[0169] S8005. AMF determines the target encryption protection strategy for the target data.
[0170] The AMF determines the target encryption and security policy for the target data based on one or more of the following policies: the encryption and security policy of the terminal device, the encryption and security policy of the SMF, the encryption and security policy of the AF, or the encryption and security policy of the PCF.
[0171] Among them, the method for AMF to determine the target encryption and protection strategy can be found in the description of the second core network element determining the target encryption and protection strategy in S801, which will not be described in detail here.
[0172] S8006. AMF sends a PDU session establishment request to the access network device, where the PDU session establishment request includes the target encryption security policy.
[0173] AMF sends the target encryption integrity policy to the access network device through the PDU session establishment request, so that the access network device knows whether it needs to encrypt the target data. Exemplarily, when the target encryption integrity policy indicates that the terminal device and the first core network network element perform encryption / decryption processing or integrity protection / verification processing, the access network device determines that it does not need to encrypt the target data; when the target encryption integrity policy indicates that the terminal device and the access network device perform encryption / decryption processing or integrity protection / verification processing, the access network device determines that it needs to encrypt the target data. The PDU session establishment request carries information for establishing a PDU session (for example, a PDU session resource establishment request list, for example, the PDU session establishment request is a PDU session establishment request message or an initial context setup request message).
[0174] S8007. The access network device sends a radio resource control (RRC) reconfiguration message (also called RRC Reconfiguration) to the terminal device.
[0175] Among them, the functions of the RRC reconfiguration message include but are not limited to: sending the configuration information of the DRB corresponding to the PDU session or the configuration information of the logical channel to the terminal device.
[0176] S8008. The terminal device sends an RRC reconfiguration completion message (also known as RRC Reconfiguration complete) to the access network device.
[0177] S8009. The access network device sends a PDU session establishment response to the AMF.
[0178] It can be understood that the response in S8009 corresponds to the request in S8006, that is, it is used to reply to the request message in S8006. For example, when the message sent in S8006 is a PDU session setup request message, the PDU session setup response in S8009 is a PDU session setup response message; when the message sent in S8006 is an initial context setup request message, the PDU session setup response in S8009 is an initial context setup response message.
[0179] S8010. The AMF sends a PDU session establishment response (also known as PDU session establishment accept) to the terminal device through the access network device. The PDU session establishment response includes the target encryption security policy.
[0180] That is, the AMF sends the target encryption security policy to the terminal device through the PDU session establishment response. In one possible implementation, when the target encryption security policy indication granularity is PDU session, a new information element (e.g., pdcp-config) is added to the PDU session establishment response to indicate the target encryption security policy; when the target encryption security policy indication granularity is QoS Flow, a new pdcp-config information is added to the information element (e.g., QoS-rule-info) used to indicate the QoS configuration in the PDU session establishment response to indicate the target encryption security policy; when the target encryption security policy indication granularity is data flow, a new pdcp-config information is added to the information used to indicate the data flow configuration in a certain information element (used to indicate QoS configuration) in the PDU session establishment response to indicate the target encryption security policy.
[0181] S8011. The terminal device generates a first key and a second key according to the target encryption security policy.
[0182] The first key and second key generated by the terminal device according to the target encryption and security policy are the same as the first key and second key generated by the AMF according to the target encryption and security policy in S812. Furthermore, the terminal device encrypts / decrypts and performs integrity protection / verification on the data based on the first key and second key and the target encryption and security policy.
[0183] S8012. AMF sends the target encryption security policy and the first key and second key generated according to the target encryption security policy to UPF through SMF.
[0184] That is, after AMF generates the first key and the second key according to the target encryption security policy, AMF sends the target encryption security policy, the first key and the second key to SMF; SMF sends the target encryption security policy, the first key and the second key to UPF, so that UPF encrypts / decrypts the data and performs integrity protection / verification according to the first key and the second key, as well as the target encryption security policy.
[0185] It can be seen that by implementing the key generation method described in Figure 8b of this application, during the transmission of target data, each transmission node (i.e., including terminal equipment, access network equipment and the first core network network element) can reach a consensus on the encryption and security strategy of the target data, which is conducive to improving the transmission efficiency and security of the target data.
[0186] Please refer to Figure 9, which shows a structural diagram of a communication device 900 according to an embodiment of the present application. The communication device shown in Figure 9 can be a first device, or a device in the first device, or a device that can be used in combination with the first device; or the communication device shown in Figure 9 can be a second device, or a device in the second device, or a device that can be used in combination with the second device; the communication device shown in Figure 9 can be a second core network element, or a device in the second core network element, or a device that can be used in combination with the second core network element; the communication device shown in Figure 9 can include a communication unit 901 and a processing unit 902. Specifically, the processing unit 902 is used to process data, and the data can be data received by the communication unit 901, and the processed data can also be sent by the communication unit 901;
[0187] In one embodiment, the communication device 900 is a first device, or may be a device in the first device, or a device that can be used in conjunction with the first device, wherein:
[0188] The processing unit 902 is configured to perform integrity protection processing and encryption processing on the first data through the first protocol layer to obtain second data; the communication unit 901 is configured to transparently transmit the second data to the second device through the access network device;
[0189] Among them, both the first device and the second device are deployed with a first protocol layer, which has the function of encrypting / decrypting data and protecting / verifying the integrity of data; the first device is a terminal device, and the second device is a first core network network element; or, the first device is a first core network network element, and the second device is a terminal device.
[0190] In one possible implementation, the protocol stack deployed on the terminal device is, in sequence, the first protocol layer, the SDAP layer, the second protocol layer, the RLC layer, the MAC layer, and the first physical layer; the second protocol layer has packet sorting and packet replication functions; the protocol layers deployed on the first core network network element are, in sequence, the first protocol layer, GTP-U, UDP, IP, the data link layer, and the second physical layer; the protocol stack deployed on the access network device includes, in sequence, the SDAP layer, the second protocol layer, the RLC layer, the MAC layer, and the first physical layer, and the access network device is also deployed with, in sequence, GTP-U, UDP, IP, the data link layer, and the second physical layer.
[0191] In one possible implementation, the protocol stack deployed on the terminal device is, in sequence, the SDAP layer, the first protocol layer, the second protocol layer, the RLC layer, the MAC layer, and the first physical layer; the second protocol layer has packet sorting, diversion, and packet replication functions; the protocol layers deployed on the first core network network element are, in sequence, the first protocol layer, GTP-U, UDP, IP, data link layer, and the second physical layer; the protocol stack deployed on the access network device includes, in sequence, the SDAP layer, the second protocol layer, the RLC layer, the MAC layer, and the first physical layer, and the access network device is also deployed with GTP-U, UDP, IP, data link layer, and the second physical layer.
[0192] In one possible implementation, the protocol stack deployed on the terminal device is, in sequence, the first protocol layer, the third protocol layer, the RLC layer, the MAC layer, and the first physical layer; wherein, the first protocol layer also has the function of IP header compression and the data packet sorting function, and the third protocol layer has the function of the SDAP layer and the data packet replication function; the protocol layers deployed on the first core network network element are, in sequence, the first protocol layer, GTP-U, UDP, IP, the data link layer, and the second physical layer; the protocol stack deployed on the access network device includes, in sequence, the third protocol layer, the RLC layer, the MAC layer, and the first physical layer, and the access network device is also deployed with GTP-U, UDP, IP, the data link layer, and the second physical layer.
[0193] In one possible implementation, when the first device is a terminal device, the communication unit 901 is also used to send a PDU session establishment request message to the second core network network element; the PDU session establishment request message is used to request the establishment of a PDU session for transmitting the first data; the communication unit 901 is also used to receive a PDU session establishment response message from the second core network network element, and the PDU session establishment response message includes a target encryption integrity policy; wherein the target encryption integrity policy is determined based on one or more of the following policies: the encryption integrity policy of the terminal device, the encryption integrity policy of the SMF, the encryption integrity policy of the AF, or the encryption integrity policy of the PCF; the processing unit 902 is also used to generate a first key and a second key based on the target encryption integrity policy; wherein the first key is used to perform integrity protection / verification processing on the first data, and the second key is used to perform encryption / decryption processing on the first data.
[0194] In a possible implementation, the PDU session establishment request message includes the encryption security policy of the terminal device.
[0195] In one possible implementation, when the first device is a first core network element, the communication unit 901 is further used to receive a target encryption integrity policy from a second core network element; wherein the target encryption integrity policy is determined based on one or more of the following policies: the encryption integrity policy of the terminal device, the encryption integrity policy of the SMF, the encryption integrity policy of the AF, or the encryption integrity policy of the PCF; the communication unit 901 is further used to receive a first key and a second key from the second core network element; wherein the first key is used to perform integrity protection / verification processing on the first data, and the second key is used to perform encryption / decryption processing on the first data; the first key and the second key are generated based on the target encryption integrity policy.
[0196] In a possible implementation, the processing unit 902 is specifically configured to perform integrity protection processing on the first data according to the target encryption integrity policy and the first key; and perform encryption processing on the first data according to the target encryption integrity policy and the second key.
[0197] In one possible implementation, the encryption integrity policy includes a granularity of encryption / decryption or integrity protection / verification of the first data, where the granularity is one of a PDU session, a QoS Flow, or a data flow.
[0198] In one possible implementation, the processing unit 902 is specifically used to perform integrity protection processing on the first data based on the first key and the granularity identifier; and to perform encryption processing on the first data based on the second key and the granularity identifier; wherein the granularity identifier is one of the QoS Flow identifier, the PDU session identifier, or the data flow identifier.
[0199] In one possible implementation, the encryption integrity policy is also used to instruct the terminal device to perform encryption / decryption processing or integrity protection / verification processing with the first core network network element; or, it is also used to instruct the terminal device to perform encryption / decryption processing or integrity protection / verification processing with the access network device.
[0200] In one embodiment, the communication device shown in FIG9 may be a second device, or a device in the second device, or a device that can be used in conjunction with the second device, wherein:
[0201] The communication unit 901 is configured to receive second data transparently transmitted from the first device via the access network device;
[0202] Processing unit 902 is used to decrypt and integrity check the second data through the first protocol layer to obtain the first data; wherein, the first device and the second device are both deployed with a first protocol layer, and the first protocol layer has the function of encrypting / decrypting data and the function of integrity protection / verification of data; the first device is a terminal device, and the second device is a first core network network element; or, the first device is a first core network network element, and the second device is a terminal device.
[0203] In one possible implementation, the protocol stack deployed on the terminal device is, in sequence, the first protocol layer, the SDAP layer, the second protocol layer, the RLC layer, the MAC layer, and the first physical layer; the second protocol layer has packet sorting and packet replication functions; the protocol layers deployed on the first core network network element are, in sequence, the first protocol layer, GTP-U, UDP, Internet Protocol IP, data link layer, and the second physical layer; the protocol stack deployed on the access network device includes, in sequence, the SDAP layer, the second protocol layer, the RLC layer, the MAC layer, and the first physical layer, and the access network device is also deployed with GTP-U, UDP, IP, data link layer, and the second physical layer.
[0204] In one possible implementation, the protocol stack deployed on the terminal device is, in sequence, the SDAP layer, the first protocol layer, the second protocol layer, the RLC layer, the MAC layer, and the first physical layer; the second protocol layer has packet sorting, diversion, and packet replication functions; the protocol layers deployed on the first core network network element are, in sequence, the first protocol layer, GTP-U, UDP, IP, data link layer, and the second physical layer; the protocol stack deployed on the access network device includes, in sequence, the SDAP layer, the second protocol layer, the RLC layer, the MAC layer, and the first physical layer, and the access network device is also deployed with GTP-U, UDP, IP, data link layer, and the second physical layer.
[0205] In one possible implementation, the protocol stack deployed on the terminal device is, in sequence, the first protocol layer, the third protocol layer, the RLC layer, the MAC layer, and the first physical layer; wherein, the first protocol layer also has the function of IP header compression and the data packet sorting function, and the third protocol layer has the function of the SDAP layer and the data packet replication function; the protocol layers deployed on the first core network network element are, in sequence, the first protocol layer, GTP-U, UDP, IP, the data link layer, and the second physical layer; the protocol stack deployed on the access network device includes, in sequence, the third protocol layer, the RLC layer, the MAC layer, and the first physical layer, and the access network device is also deployed with GTP-U, UDP, IP, the data link layer, and the second physical layer.
[0206] In one possible implementation, when the second device is a terminal device, the communication unit 901 is also used to send a protocol data unit PDU session establishment request message to the second core network network element; the PDU session establishment request message is used to request the establishment of a PDU session for transmitting the second data; the communication unit 901 is also used to receive a PDU session establishment response message from the second core network network element, and the PDU session establishment response message includes a target encryption integrity policy; wherein, the target encryption integrity policy is determined according to one or more of the following policies: the encryption integrity policy of the terminal device, the encryption integrity policy of the session management function SMF, the encryption integrity policy of the application function AF or the encryption integrity policy of the policy control function PCF; the processing unit 902 is also used to generate a first key and a second key according to the target encryption integrity policy; wherein, the first key is used to perform integrity protection / verification processing on the second data, and the second key is used to perform encryption / decryption processing on the second data.
[0207] In a possible implementation, the PDU session establishment request message includes the encryption security policy of the terminal device.
[0208] In one possible implementation, when the second device is the first core network network element, the communication unit 901 is also used to receive a target encryption integrity policy from the second core network network element; wherein the target encryption integrity policy is determined based on one or more of the following policies: the encryption integrity policy of the terminal device, the encryption integrity policy of the SMF, the encryption integrity policy of the AF, or the encryption integrity policy of the PCF; the communication unit 901 is also used to receive a first key and a second key from the second core network network element; wherein the first key is used to perform integrity protection / verification processing on the second data, and the second key is used to perform encryption / decryption processing on the second data; the first key and the second key are generated according to the target encryption integrity policy.
[0209] In one possible implementation, the processing unit 902 is specifically configured to decrypt the second data at the first protocol layer according to the target encryption security policy and the second key; and perform integrity verification on the second data according to the target encryption security policy and the first key.
[0210] In one possible implementation, the encryption integrity policy includes a granularity of encryption / decryption or integrity protection / verification of the second data, where the granularity is one of a PDU session, a QoS Flow, or a data flow.
[0211] In one possible implementation, the processing unit 902 is specifically used to decrypt the second data based on the second key and the granularity identifier; and perform integrity verification on the second data based on the first key and the granularity identifier; wherein the granularity identifier is one of the QoS Flow identifier, the PDU session identifier, or the data flow identifier.
[0212] In one possible implementation, the encryption integrity policy is also used to instruct the terminal device to perform encryption / decryption processing or integrity protection / verification processing with the first core network network element; or, it is also used to instruct the terminal device to perform encryption / decryption processing or integrity protection / verification processing with the access network device.
[0213] In one embodiment, the communication device shown in FIG9 may be a second core network element, or a device in the second core network element, or a device that can be used in conjunction with the second core network element, wherein:
[0214] The processing unit 902 is used to determine the target encryption and security policy of the target data; the target encryption and security policy is determined based on one or more of the following policies: the encryption and security policy of the terminal device, the encryption and security policy of the session management function SMF, the encryption and security policy of the application function AF or the encryption and security policy of the policy control function PCF; the communication unit 901 is used to send the target encryption and security policy to the terminal device, the access network device corresponding to the terminal device and the first core network network element.
[0215] In one possible implementation, the communication unit 901 is also used to receive a protocol data unit PDU session establishment request message sent from a terminal device; the PDU session establishment request message is used to request the establishment of a PDU session for transmitting target data; and send a PDU session establishment response message to the terminal device, the PDU session establishment response message including a target encryption security policy.
[0216] In a possible implementation, the PDU session establishment request message includes the encryption security policy of the terminal device.
[0217] In one possible implementation, the processing unit 902 is also used to generate a first key and a second key based on the target encryption integrity policy; wherein the first key is used to perform integrity protection / verification processing on the target data, and the second key is used to perform encryption / decryption processing on the target data; the communication unit 901 is also used to send the first key and the second key to the first core network network element.
[0218] In one possible implementation, the encryption integrity policy includes a granularity for encryption / decryption or integrity protection / verification of target data, where the granularity is one of a PDU session, a quality of service flow QoS flow, or a data flow.
[0219] In one possible implementation, the encryption integrity policy is also used to instruct the terminal device and the first core network network element to perform encryption / decryption processing or integrity protection / verification processing; or, it is also used to instruct the terminal device and the access network device to perform encryption / decryption processing or integrity protection / verification processing.
[0220] As shown in Figure 10, a communication device 1000 provided in an embodiment of the present application is used to implement the functions of the above-mentioned first device, second device or second core network element. The device can be a first device or a device used in a first device; or the device can be a second device or a device used in a second device; or the device can be a second core network element or a device used in a second core network element. The device used in a device (such as a first device, a second device or a second core network element) can be a chip system or a chip in the device. Among them, the chip system can be composed of a chip, or it can include a chip and other discrete devices.
[0221] The communication device 1000 includes at least one processor 1020, which is used to implement the data transmission function of the device (such as the first device, the second device or the second core network element) in the method provided in the embodiment of the present application. The communication device 1000 may also include a communication interface 1010, which is used to implement the transceiver operation of the device (such as the first device, the second device or the second core network element) in the method provided in the embodiment of the present application. In the embodiment of the present application, the communication interface can be a transceiver, a circuit, a bus, a module or other type of communication interface, which is used to communicate with other devices through a transmission medium. For example, the communication interface 1010 is used for the device in the communication device 1000 to communicate with other devices. The processor 1020 uses the communication interface 1010 to send and receive data, and is used to implement the method described in the above method embodiment.
[0222] The communication device 1000 may also include at least one memory 1030 for storing program instructions and / or data. The memory 1030 is coupled to the processor 1020. Coupling in the embodiments of the present application is an indirect coupling or communication connection between devices, units, or modules, which may be electrical, mechanical, or other forms, and is used for information exchange between the devices, units, or modules. The processor 1020 may operate in conjunction with the memory 1030. The processor 1020 may execute program instructions stored in the memory 1030. At least one of the at least one memory may be included in the processor.
[0223] The specific connection medium between the communication interface 1010, processor 1020, and memory 1030 is not limited in the embodiments of the present application. In Figure 10, the embodiment of the present application shows that the memory 1030, processor 1020, and communication interface 1010 are connected via a bus 1040. The bus is represented by a bold line in Figure 10. The connection method between other components is only for schematic illustration and is not intended to be limiting. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, only one bold line is used in Figure 10, but this does not mean that there is only one bus or one type of bus.
[0224] When the communication device 1000 is specifically a device for a device (e.g., a first device, a second device, or a second core network element), for example, when the communication device 1000 is specifically a chip or a chip system, the communication interface 1010 may output or receive a baseband signal. When the communication device 1000 is specifically a device (e.g., a first device, a second device, or a second core network element), the communication interface 1010 may output or receive a radio frequency signal. In an embodiment of the present application, the processor may be a general-purpose processor, a digital signal processor, an application-specific integrated circuit, a field programmable gate array, or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component, and may implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. A general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the method disclosed in conjunction with the embodiments of the present application may be directly embodied as being executed by a hardware processor, or may be executed by a combination of hardware and software modules in the processor.
[0225] An embodiment of the present application also provides a computer-readable storage medium, which stores computer execution instructions. When the computer execution instructions are executed, the method executed by the first device, the second device or the second core network element in the above method embodiment is implemented.
[0226] An embodiment of the present application also provides a computer program product, which includes a computer program. When the computer program is executed, the method executed by the first device, the second device or the second core network element in the above method embodiment is implemented.
[0227] The present application also provides a communication system including a first device, a second device, an access network device, and a second core network element. The first device is configured to execute the method executed by the first device in the above-mentioned method embodiment; the second device is configured to execute the method executed by the second device in the above-mentioned method embodiment; and the second core network element is configured to execute the method executed by the second core network element in the above-mentioned method embodiment.
[0228] It should be noted that for the aforementioned method embodiments, for the sake of simplicity, they are all expressed as a series of action combinations, but those skilled in the art should be aware that this application is not limited by the order of the actions described, because according to this application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily required by this application.
[0229] The descriptions of the various embodiments provided in this application can refer to each other. The descriptions of each embodiment have their own focus. For parts not described in detail in a particular embodiment, please refer to the relevant descriptions of other embodiments. For the convenience and brevity of description, for example, the functions and execution steps of the various devices and equipment provided in the embodiments of this application can refer to the relevant descriptions of the method embodiments of this application. The various method embodiments and the various device embodiments can also refer to, be combined with, or quote each other.
[0230] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some or all of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the scope of the technical solutions of the embodiments of the present application.
Claims
1. A data transmission method, characterized in that: The method comprises: The first device performs integrity protection processing and encryption processing on the first data through the first protocol layer to obtain second data; The first device transparently transmits the second data to the second device through the access network device; The first device and the second device are both deployed with the first protocol layer, and the first protocol layer has the function of encrypting / decrypting data and the function of performing integrity protection / verification on data; The first device is a terminal device, and the second device is a first core network element; or, the first device is a first core network element, and the second device is a terminal device.
2. The method according to claim 1, characterized in that The protocol stack deployed in the terminal device is, in order, a first protocol layer, a service data adaptation protocol (SDAP) layer, a second protocol layer, a radio link control (RLC) layer, a media access control (MAC) layer, and a first physical layer; wherein the second protocol layer has a data packet sorting function and a data packet duplication function; The protocol layers deployed by the first core network network element are, in order, the first protocol layer, the general packet radio service tunneling protocol GTP-U of the user plane part, the user datagram protocol UDP, the Internet protocol IP, the data link layer and the second physical layer; The protocol stack deployed by the access network device includes the SDAP layer, the second protocol layer, the RLC layer, the MAC layer and the first physical layer in sequence. The access network device also deploys GTP-U, UDP, IP, the data link layer and the second physical layer in sequence.
3. The method according to claim 1, characterized in that The protocol stack deployed in the terminal device is, in order, an SDAP layer, a first protocol layer, a second protocol layer, an RLC layer, a MAC layer, and a first physical layer; wherein the second protocol layer has packet sorting, diversion, and packet replication functions; The protocol layers deployed by the first core network network element are the first protocol layer, GTP-U, UDP, IP, data link layer and the second physical layer in sequence; The protocol stack deployed by the access network device includes the SDAP layer, the second protocol layer, the RLC layer, the MAC layer and the first physical layer in sequence. The access network device also deploys GTP-U, UDP, IP, the data link layer and the second physical layer in sequence.
4. The method according to claim 1, characterized in that The protocol stack deployed in the terminal device is, in order, the first protocol layer, the third protocol layer, the RLC layer, the MAC layer, and the first physical layer; wherein the first protocol layer also has the function of IP header compression and data packet sorting, and the third protocol layer has the function of the SDAP layer and the data packet replication function; The protocol layers deployed by the first core network network element are the first protocol layer, GTP-U, UDP, IP, data link layer and the second physical layer in sequence; The protocol stack deployed by the access network device includes the third protocol layer, RLC layer, MAC layer and the first physical layer in sequence. The access network device also deploys GTP-U, UDP, IP, data link layer and the second physical layer in sequence.
5. The method according to any one of claims 1 to 4, characterized in that When the first device is a terminal device, the method further includes: The first device sends a protocol data unit (PDU) session establishment request message to the second core network element; the PDU session establishment request message is used to request establishment of a PDU session for transmitting the first data; The first device receives a PDU session establishment response message from the second core network element, where the PDU session establishment response message includes the target encryption integrity policy; wherein the target encryption integrity policy is determined according to one or more of the following policies: the encryption integrity policy of the terminal device, the encryption integrity policy of the session management function SMF, the encryption integrity policy of the application function AF, or the encryption integrity policy of the policy control function PCF; The first device generates a first key and a second key according to the target encryption integrity policy; wherein the first key is used to perform integrity protection / verification processing on the first data, and the second key is used to encrypt / decrypt the first data.
6. The method according to claim 5, characterized in that The PDU session establishment request message includes the encryption security policy of the terminal device.
7. The method according to any one of claims 1 to 4, characterized in that When the first device is a first core network element, the method further includes: The first device receives a target encryption integrity policy from a second core network element; wherein the target encryption integrity policy is determined according to one or more of the following policies: an encryption integrity policy of the terminal device, an encryption integrity policy of the SMF, an encryption integrity policy of the AF, or an encryption integrity policy of the PCF; The first device receives a first key and a second key from the second core network element; wherein, the first key is used to perform integrity protection / verification processing on the first data, and the second key is used to perform encryption / decryption processing on the first data; the first key and the second key are generated according to the target encryption integrity policy.
8. The method according to any one of claims 5 to 7, characterized in that: The first device performs integrity protection processing and encryption processing on the first data through the first protocol layer, including: At the first protocol layer, the first device performs integrity protection processing on the first data according to the target encryption integrity policy and the first key; The first device encrypts the first data according to the target encryption security policy and the second key.
9. The method according to claim 8, characterized in that The encryption integrity strategy includes the granularity of encryption / decryption or integrity protection / verification of the first data, and the granularity is one of PDU session, quality of service flow QoS Flow or data flow.
10. The method according to claim 9, characterized in that: The first device performs integrity protection processing on the first data according to the target encryption integrity protection policy and the first key, including: The first device performs integrity protection processing on the first data according to the first key and the identifier of the granularity; The first device encrypts the first data according to the target encryption integrity policy and the second key, including: The first device encrypts the first data according to the second key and the granularity identifier; The granularity identifier is one of a QoS Flow identifier, a PDU session identifier, and a data flow identifier.
11. The method according to any one of claims 5 to 10, characterized in that: The encryption integrity policy is also used to instruct the terminal device and the first core network network element to perform encryption / decryption processing or integrity protection / verification processing; or, it is also used to instruct the terminal device and the access network device to perform encryption / decryption processing or integrity protection / verification processing.
12. A data transmission method, characterized in that: The method comprises: The second device receives second data transparently transmitted from the first device through the access network device; The second device performs decryption processing and integrity verification processing on the second data through the first protocol layer to obtain first data; The first device and the second device are both deployed with the first protocol layer, and the first protocol layer has the function of encrypting / decrypting data and the function of performing integrity protection / verification on data; The first device is a terminal device, and the second device is a first core network element; or, the first device is a first core network element, and the second device is a terminal device.
13. The method according to claim 12, characterized in that: The protocol stack deployed in the terminal device is, in order, a first protocol layer, a service data adaptation protocol (SDAP) layer, a second protocol layer, a radio link control (RLC) layer, a media access control (MAC) layer, and a first physical layer; wherein the second protocol layer has a data packet sorting function and a data packet duplication function; The protocol layers deployed by the first core network network element are, in order, the first protocol layer, the general packet radio service tunneling protocol GTP-U of the user plane part, the user datagram protocol UDP, the Internet protocol IP, the data link layer and the second physical layer; The protocol stack deployed by the access network device includes the SDAP layer, the second protocol layer, the RLC layer, the MAC layer and the first physical layer in sequence. The access network device also deploys GTP-U, UDP, IP, the data link layer and the second physical layer in sequence.
14. The method according to claim 12, characterized in that: The protocol stack deployed in the terminal device is, in order, an SDAP layer, a first protocol layer, a second protocol layer, an RLC layer, a MAC layer, and a first physical layer; wherein the second protocol layer has packet sorting, diversion, and packet replication functions; The protocol layers deployed by the first core network network element are the first protocol layer, GTP-U, UDP, IP, data link layer and the second physical layer in sequence; The protocol stack deployed by the access network device includes the SDAP layer, the second protocol layer, the RLC layer, the MAC layer and the first physical layer in sequence. The access network device also deploys GTP-U, UDP, IP, the data link layer and the second physical layer in sequence.
15. The method according to claim 12, characterized in that: The protocol stack deployed in the terminal device is, in order, the first protocol layer, the third protocol layer, the RLC layer, the MAC layer, and the first physical layer; wherein the first protocol layer also has the function of IP header compression and data packet sorting, and the third protocol layer has the function of the SDAP layer and the data packet replication function; The protocol layers deployed by the first core network network element are the first protocol layer, GTP-U, UDP, IP, data link layer and the second physical layer in sequence; The protocol stack deployed by the access network device includes the third protocol layer, RLC layer, MAC layer and the first physical layer in sequence. The access network device also deploys GTP-U, UDP, IP, data link layer and the second physical layer in sequence.
16. The method according to any one of claims 12 to 15, characterized in that: When the second device is a terminal device, the method further includes: The second device sends a protocol data unit (PDU) session establishment request message to a second core network element; the PDU session establishment request message is used to request establishment of a PDU session for transmitting the second data; The second device receives a PDU session establishment response message from the second core network network element, where the PDU session establishment response message includes the target encryption integrity policy; wherein the target encryption integrity policy is determined according to one or more of the following policies: the encryption integrity policy of the terminal device, the encryption integrity policy of the session management function SMF, the encryption integrity policy of the application function AF, or the encryption integrity policy of the policy control function PCF; The second device generates a first key and a second key according to the target encryption integrity policy; wherein the first key is used to perform integrity protection / verification processing on the second data, and the second key is used to encrypt / decrypt the second data.
17. The method according to claim 16, characterized in that: The PDU session establishment request message includes the encryption security policy of the terminal device.
18. The method according to any one of claims 12 to 15, characterized in that: When the second device is a first core network element, the method further includes: The second device receives a target encryption and security policy from a second core network element; wherein the target encryption and security policy is determined according to one or more of the following policies: an encryption and security policy of the terminal device, an encryption and security policy of the SMF, an encryption and security policy of the AF, or an encryption and security policy of the PCF; The second device receives a first key and a second key from the second core network element; wherein, the first key is used to perform integrity protection / verification processing on the second data, and the second key is used to perform encryption / decryption processing on the second data; the first key and the second key are generated according to the target encryption integrity policy.
19. The method according to any one of claims 15 to 18, characterized in that: The second device sequentially performs decryption processing and integrity verification processing on the second data through the first protocol layer, including: At the first protocol layer, the second device decrypts the second data according to the target encryption integrity policy and the second key; The second device performs integrity verification on the second data according to the target encryption integrity policy and the first key.
20. The method according to claim 19, characterized in that The encryption integrity strategy includes the granularity of encryption / decryption or integrity protection / verification of the second data, and the granularity is one of PDU session, quality of service flow QoS Flow or data flow.
21. The method according to claim 20, characterized in that The second device decrypts the second data according to the target encryption security policy and the second key, including: The second device decrypts the second data according to the second key and the granularity identifier; The second device performs integrity verification processing on the second data according to the target encryption integrity policy and the first key, including: The second device performs integrity verification on the second data according to the first key and the granularity identifier; The granularity identifier is one of a QoS Flow identifier, a PDU session identifier, and a data flow identifier.
22. The method according to any one of claims 12 to 21, characterized in that The encryption integrity policy is also used to instruct the terminal device and the first core network network element to perform encryption / decryption processing or integrity protection / verification processing; or, it is also used to instruct the terminal device and the access network device to perform encryption / decryption processing or integrity protection / verification processing.
23. A method for determining an encryption integrity strategy, characterized in that: The method comprises: The second core network element determines a target encryption and security policy for the target data; the target encryption and security policy is determined according to one or more of the following policies: an encryption and security policy of the terminal device, an encryption and security policy of the session management function SMF, an encryption and security policy of the application function AF, or an encryption and security policy of the policy control function PCF; The second core network element sends the target encryption security policy to the terminal device, the access network device corresponding to the terminal device and the first core network element.
24. The method according to claim 23, wherein: The method further comprises: The second core network element receives a protocol data unit (PDU) session establishment request message sent from the terminal device; the PDU session establishment request message is used to request establishment of a PDU session for transmitting the target data; The second core network element sends the target encryption and security policy to the terminal device, including: The second core network element sends a PDU session establishment response message to the terminal device, and the PDU session establishment response message includes the target encryption security policy.
25. The method according to claim 24, characterized in that The PDU session establishment request message includes the encryption security policy of the terminal device.
26. The method according to any one of claims 23 to 25, characterized in that The method further comprises: The second core network element generates a first key and a second key based on the target encryption integrity policy; wherein the first key is used to perform integrity protection / verification processing on the target data, and the second key is used to perform encryption / decryption processing on the target data; The second core network element sends the first key and the second key to the first core network element.
27. The method according to any one of claims 23 to 26, characterized in that The encryption integrity strategy includes the granularity of encryption / decryption or integrity protection / verification of the target data, and the granularity is one of PDU session, quality of service flow QoSFlow or data flow.
28. The method according to any one of claims 23 to 27, characterized in that The encryption integrity policy is also used to instruct the terminal device and the first core network network element to perform encryption / decryption processing or integrity protection / verification processing; or, it is also used to instruct the terminal device and the access network device to perform encryption / decryption processing or integrity protection / verification processing.
29. A communication device, characterized in that: The method comprises a function or a unit for executing the method according to any one of claims 1 to 11, or executing the method according to any one of claims 12 to 22, or executing the method according to any one of claims 23 to 28.
30. A communication device, characterized in that: The method comprises a processor and a memory, wherein the processor and the memory are coupled, and the processor is used to implement the method according to any one of claims 1 to 11, or the processor is used to implement the method according to any one of claims 12 to 22, or the processor is used to implement the method according to any one of claims 23 to 28.
31. A communication device, characterized in that: The method comprises a processor and an interface circuit, wherein the interface circuit is used to receive signals from other communication devices outside the communication device and transmit them to the processor or send signals from the processor to other communication devices outside the communication device, wherein the processor is used to implement the method according to any one of claims 1 to 11 through a logic circuit or by executing code instructions, or the processor is used to implement the method according to any one of claims 12 to 22 through a logic circuit or by executing code instructions, or the processor is used to implement the method according to any one of claims 23 to 28 through a logic circuit or by executing code instructions.
32. A computer-readable storage medium, characterized in that The storage medium stores a computer program or instruction. When the computer program or instruction is executed by the communication device, the method according to any one of claims 1 to 11 is implemented, or the method according to any one of claims 12 to 22 is implemented, or the method according to any one of claims 23 to 28 is implemented.
33. A computer program product, characterized in that When a computer reads and executes the computer program product, the computer is enabled to execute the method according to any one of claims 1 to 11, or the method according to any one of claims 12 to 22, or the method according to any one of claims 23 to 28.
34. A communication system, characterized in that It includes a terminal device, a first core network element and a second core network element; wherein, the terminal device is used to execute the method according to any one of claims 1-11, the first core network element is used to execute the method according to any one of claims 12-22, and the second core network element is used to execute the method according to any one of claims 23-28.