Wireless communication method and related equipment
By negotiating the application of security only on the UE to relay link or the UE to UE link in 5G proximity service, the problem of waste of communication resources of UE and UE to UE relay nodes in the existing system is solved, and efficient and secure communication is achieved.
Patent Information
- Application Number
- CN202380074345.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-10-25
- Filing Date
- 2023-10-24
- Publication Date
- 2025-06-17
AI Technical Summary
In 5G proximity services, communication between UE and UE to UE relay nodes in existing systems is double protected, resulting in waste of resources and inefficiency, especially in power-constrained deployment scenarios.
Efficient secure communication is achieved through negotiation between the UE and the UE to the UE relay node, security is applied only on the UE to the relay link (hop-by-hop) or only on the UE to the UE to the UE link (end to end).
This method enables the UE and UE to UE relay nodes to manage resource usage more efficiently while maintaining security of communication between two UEs through UE to UE relay.
Smart Images

Figure CN120167128A_ABST
Abstract
Description
[0001] Cross - Reference to Related Applications
[0002] This application claims the priority benefit of U.S. Provisional Application No. 63 / 419,266, filed on October 25, 2022, the entire content of which is incorporated herein by reference. Technical Field
[0003] This application relates to wireless communication, and in particular, to a wireless communication method and related devices. Background Art
[0004] Communication systems and networks have evolved towards broadband mobile systems. For cellular wireless communication systems, the Third Generation Partnership Project (3GPP) has developed the Long Term Evolution (LTE) system, namely the Evolved Universal Mobile Telecommunication System Territorial Radio Access Network (E - UTRAN). The 5G or New Radio (NR) system has evolved from LTE, where the base station for supporting one or more cells is called a gNB. In 5G NR, the User Equipment (UE) connects to the Radio Access Network (RAN) via a wireless link. The RAN includes a set of Base Stations (BSs), which provide wireless links to UEs located in the cells covered by the base stations, and the set of base stations provides an interface to the Core Network (CN), and the core network provides overall network control. The RAN and the CN each implement corresponding functions related to the entire network.
[0005] In 5G Proximity Services, two user equipments not within the network coverage can be connected via UE - to - UE relay (also referred to as "UE - to - UE relay node" in this article). Before UEs can establish a secure connection with each other via UE - to - UE relay, each UE can separately establish a secure sidelink (or PC5) connection with the UE - to - UE relay. A secure connection generally means that security measures (such as confidentiality protection, integrity protection, or replay protection) are enabled on the communication link between two entities (e.g., UEs).
[0006] The 4G or 5G cellular network can be used in various ways to facilitate secure communication between two entities (e.g., UEs). For example, UEs can use services such as Facebook TMor WhatsApp TM Upper layer applications such as communicate with each other, where the upper layer applications use end-to-end encryption at the application layer. Here, the UE also uses a lower layer security of the Packet Data Convergence Protocol (PDCP) layer to connect to the cellular network, which facilitates encryption between the UE and the base station. Figure 1 FIG. shows UE-to-UE communication protected at different layers. As Figure 1 shown, link #1 and link #2 between the UE and the network are protected at a lower layer (e.g., the PDCP layer), and link #3 between UE #1 and UE #2 is protected at a higher layer (e.g., the application layer). In addition, link #4 can be protected at the application layer or the transport layer.
[0007] However, neither the UE nor the network knows that the UE uses a high-layer application to communicate with other UEs. This means that encryption is performed between two UEs through the upper layer application, while encryption is performed separately between each UE and the network through the lower layer security. Since there is no negotiation between the security applied to different layers on the network side or the UE side, the communication between the UE and other UEs and the communication between the UE and the UE-to-UE relay are doubly protected.
[0008] Since the double protection (e.g., double encryption) occurs in different layers and different security domains, and since each layer does not know what is happening in other layers, the double protection is inevitable. In addition, compared with the UE-to-UE relay node, the network node is not power-limited. Therefore, in the existing system, there is no need to prioritize the efficient use of resources such as power to provide additional (e.g., unnecessary) security. However, the UE-to-UE relay node (by definition, the UE-to-UE relay node provides connection services to two or more UEs that communicate with each other and may be outside the network coverage area) and the UE (the UE may be outside the network coverage area) are power-limited, so it is necessary to more efficiently manage the use of their resources. SUMMARY OF THE INVENTION
[0009] In a first aspect, some embodiments of the present application provide a wireless communication method for a first user equipment (UE), including: at least one processor executes a first security process to establish a first secure communication with a UE-to-UE relay node for communicating with a second UE; a communication interface sends a direct communication request to the second UE through the UE-to-UE relay node; the at least one processor executes a direct security operation to establish a second secure communication between the first UE and the second UE; the at least one processor disables the first secure communication with the UE-to-UE relay node during or after establishing the second secure communication with the second UE.
[0010] In a second aspect, some embodiments of the present application provide a first user equipment (UE), including: at least one processor, configured to execute a first security process to establish a first secure communication with a UE-to-UE relay node for communicating with a second UE; a communication interface, coupled to the at least one processor, configured to send a direct communication request to the second UE via the UE-to-UE relay node, wherein the at least one processor is further configured to: execute a direct security operation to establish a second secure communication between the first UE and the second UE; and disable the first secure communication with the UE-to-UE relay node during or after establishing the second secure communication with the second UE.
[0011] In a third aspect, some embodiments of the present application provide a wireless communication method for a first user equipment (UE), including: at least one processor determines to use hop-by-hop security for communicating with a second UE via a UE-to-UE relay node; the at least one processor executes a hop-by-hop security process to establish a first secure communication with the UE-to-UE relay node for communicating with the second UE; a communication interface sends a direct communication request to the second UE via the UE-to-UE relay node; the communication interface receives a direct communication response from the second UE via the UE-to-UE relay node; and the communication interface communicates with the second UE using the hop-by-hop security via the UE-to-UE relay node.
[0012] In a fourth aspect, some embodiments of the present application provide a first user equipment (UE), including at least one processor and a communication interface coupled to the at least one processor, wherein the at least one processor and the communication interface are configured to cooperate with each other to execute the above method. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] To more clearly illustrate the embodiments of the present application or related technologies, the following drawings briefly introduced will be described in the embodiments. Obviously, the drawings are only some embodiments of the present application, and those of ordinary skill in the art can obtain other drawings based on these drawings without creative efforts.
[0014] Figure 1 is a schematic diagram showing UE-to-UE communication protected at different layers.
[0015] Figure 2 is a block diagram showing a communication system including a relay.
[0016] Figure 3 is a block diagram showing a possible relay architecture applicable to the present application.
[0017] Figure 4It is a schematic diagram showing the use of hop-by-hop protection for UE-to-UE communication provided by some embodiments of the present application.
[0018] Figure 5 It is a schematic diagram showing the use of end-to-end protection for UE-to-UE communication provided by some embodiments of the present application.
[0019] Figure 6 It is a flowchart of a wireless communication method provided by the first embodiment of the present application.
[0020] Figure 7 It is a schematic diagram showing the call flow of end-to-end secure communication provided by some embodiments of the present application.
[0021] Figure 8 It is a flowchart of a wireless communication method provided by the second embodiment of the present application.
[0022] Figure 9 It is a schematic diagram showing the call flow of hop-by-hop secure communication provided by some embodiments of the present application. Detailed implementation manners
[0023] Next, with reference to the accompanying drawings, the embodiments of the present disclosure will be described in detail from the aspects of technical problems, structural features, implementation objectives, and effects. Specifically, the terms in the embodiments of the present application are only used for the purpose of describing specific embodiments, rather than limiting the present disclosure.
[0024] In this document, combinations such as "at least one of A, B, or C", "one or more of A, B, or C", "at least one of A, B, and C", "one or more of A, B, and C", "A, B, and / or C" can be only A, only B, only C, A and B, A and C, B and C, or A and B and C, where any combination can include one or more of A, B, or C.
[0025] For example, in 5G Proximity Services, two UEs outside the network coverage can be connected through UE-to-UE relay. Before the UEs can establish a secure connection with each other through UE-to-UE relay, each UE and the UE-to-UE relay will need to establish a secure sidelink (or PC5) connection respectively. A secure connection generally means that security measures (such as confidentiality protection, integrity protection, or replay protection) are enabled on the communication link between two communicating entities (e.g., between UEs, or between a UE and a UE-to-UE relay).
[0026] Once each UE has established a secure connection with the UE-to-UE relay and the two UEs have established secure connections with each other via the UE-to-UE relay, it is wasteful and inefficient for both the UE-to-relay link and the UE-to-UE link to turn on security measures (e.g., double encryption) in terms of the resources of the UE and the resources of the relay. The resources of the UE and the UE-to-UE relay are important considerations, especially considering that many deployment scenarios of UE-to-UE relay communication are in disaster-stricken areas where resources (such as network, power, etc.) are limited in the long term.
[0027] The present application provides the following mechanism: through negotiation between the UE and the UE-to-UE relay, to have security only on the UE-to-relay link (e.g., hop by hop) or only on the UE-to-UE link (e.g., end to end), so as to enable efficient secure communication between two UEs via the UE-to-UE relay.
[0028] Therefore, the present application enables the UE and the UE-to-UE relay node to more efficiently manage the use of their resources, while providing (and maintaining) the security of communication between two UEs via the UE-to-UE relay.
[0029] Further details of the present application are provided below.
[0030] Figure 2 FIG. is a block diagram showing a communication system including a relay (e.g., UE-to-UE relay or UE-to-network relay). The communication system includes a relay 10, a base station (e.g., gNB) 20, and at least one user equipment 30. The relay 10 communicates with the base station 20 and communicates with at least one user equipment 30. The relay 10 serves as an intermediate device that facilitates signal transmission between the base station and the user equipment in the downlink and uplink directions, especially in scenarios where direct communication is difficult. A user equipment with relay capabilities can be used as the relay 10. The relay 10 can improve coverage, capacity, reliability, and energy efficiency, while being cost-effective and flexible for various deployment scenarios.
[0031] Figure 3FIG. 0 is a block diagram showing a possible relay architecture to which the present application is applicable. Relay 10 may be a UE-to-UE relay that can facilitate communication between two UEs 30, 30' even when a base station is unavailable and can establish a secure connection for the two UEs 30, 30'. The UE-to-UE relay 10 and the two UEs 30, 30' are capable of performing embodiments of the methods provided by the present application. The UE-to-UE relay 10 includes a communication interface 12 and a processor 14 that are electrically connected to each other. The UE 30 includes a communication interface 32 and a processor 34 that are electrically connected to each other. The UE 30' includes a communication interface 32' and a processor 34' that are electrically connected to each other. The communication interfaces 12, 32, 32' are used to transmit and / or receive signals. The processors 14, 34, 34' are used to process signals and any other control flow or perform some calculations. The processors 14, 34, 34' and the communication interfaces 12, 32, 32' may be configured to implement the functions, processes, and / or methods described in this specification. Each layer of the radio interface protocol may be implemented in the processors 14, 34, 34'. The UE-to-UE relay 10 and the two UEs 30, 30' may each include a memory that operably stores various programs and information to operate the processors connected thereto. The communication interfaces 12, 32, 32' are operably coupled to the connected processors to transmit and / or receive wireless signals.
[0032] Each of the processors 14, 34, 34' may include a general-purpose central processing unit (CPU), an application-specific integrated circuit (ASIC), other chip sets, logic circuits, and / or data processing devices. The memory may include a read-only memory (ROM), a random access memory (RAM), a flash memory, a memory card, a storage medium, other storage devices, and / or any combination of a memory and a storage device. Each of the communication interfaces 12, 32, 32' may include a baseband circuit and a radio frequency (RF) circuit for processing radio frequency signals. When embodiments are implemented by software, the techniques described herein may be implemented by modules, processes, functions, entities, etc. that perform the functions described herein. The modules may be stored in the memory and executed by the processors. The memory may be implemented inside or outside the processors, and the memory may be communicatively coupled to the processors by various means known in the art.
[0033] The present application may provide a secure relay service in a 5G communication system, for example, when two communicating UEs are not within the network coverage.
[0034] When UEs are outside the network coverage, they can communicate directly with each other using sidelink or communicate with each other indirectly through relays. When UEs communicate through UE-to-UE relay, this application enables secure communication between two UEs connected via UE-to-UE relay to be achieved through end-to-end security or hop-by-hop security.
[0035] Figure 4 FIG. is a schematic diagram showing the use of hop-by-hop protection for UE-to-UE communication provided by some embodiments of this application. Figure 5 FIG. is a schematic diagram showing the use of end-to-end protection for UE-to-UE communication provided by some embodiments of this application. As Figure 4 and Figure 5 shown, secure communication can be achieved through hop-by-hop or end-to-end security applied on the communication link. For Figure 4 the hop-by-hop security shown, a first protected link is established between UE1 and the UE-to-UE relay, and a second protected link is established between UE2 and the UE-to-UE relay. For Figure 5 the end-to-end security shown, a protected link is established between UE1 and UE2. Efficiency can be achieved by not applying security measures twice on the same communication link.
[0036] In this application, after end-to-end communication is established between UE1 and UE2, in order to maintain the same security level and achieve a high efficiency level, hop-by-hop security will not be used (or will be turned off), or end-to-end security will not be used (or will be turned off). That is to say, the communication between UE1 and UE2 can have security only on the UE-to-relay link (e.g., hop-by-hop) or only on the UE-to-UE link (e.g., end-to-end). The link security that will not be used (or will be turned off) can be based on the implementation or on the negotiation between UE1, UE2 and the UE-to-UE relay.
[0037] For example, the operator can configure UE1 / UE2 and the UE-to-UE relay to always use a security policy of hop-by-hop security. The communication between the UE-to-UE relay and the UEs can be such that the links between UE1 and the UE-to-UE relay and between UE2 and the UE-to-UE relay are always protected. During the process of establishing UE-to-UE communication, UE1 / UE2 can be notified that end-to-end security is not allowed or disabled or turned off, or after UE-to-UE communication is established, UE1 / UE2 can be notified by dedicated signaling that end-to-end security is not allowed or disabled or turned off.
[0038] Similarly, if the security policy indicates that end-to-end security is always used, hop-by-hop security will not be used, or hop-by-hop security will be turned off after end-to-end security is established. The communication between the UE-to-UE relay and the UE can be such that once the UE-to-UE communication is established, the links between UE1 and the UE-to-UE relay and between UE2 and the UE-to-UE relay will not be protected. During the process of establishing UE-to-UE communication, the UE can be notified that hop-by-hop security is not allowed or disabled or turned off, or after the UE-to-UE communication is established, the UE can be notified by dedicated signaling that hop-by-hop security is not allowed or disabled or turned off.
[0039] The security policies received by UE1, UE2, and the UE-to-UE relay may be different or conflicting. For example, the security policy of UE1 may use hop-by-hop security, while the security policy of UE2 uses end-to-end security. In the case of a conflict between the security policies of UE1 and UE2, the UE-to-UE relay can decide to use its own security policy. Generally, since the UE-to-UE relay is the party providing the relay service, its security policy should supersede the security policy of either UE1 or UE2. In the case where UE1 and UE2 are not configured with a security policy, the UE-to-UE relay can also decide whether to use hop-by-hop security or end-to-end security, and notify UE1 and UE2 of this decision during or after the establishment of end-to-end communication between UE1 and UE2.
[0040] UE1, UE2, and the UE-to-UE relay can also negotiate with each other to determine whether to use hop-by-hop security or end-to-end security when UE1 and UE2 have established communication through the relay. For example, the negotiation can be based on the capabilities (e.g., security capabilities) or security policies of one or more of UE1, UE2, and the UE-to-UE relay.
[0041] Figure 6 is a flowchart of a wireless communication method 100 provided by the first embodiment of the present application. The wireless communication method 100 is applied to a first user equipment (denoted here as UE1). The exemplary structure of UE1 can refer to Figure 3 the user equipment 30 shown. The wireless communication method 100 can be implemented by using Figure 3 the communication interface 32 and the processor 34. The method 100 includes the following steps.
[0042] Step 110: At least one processor executes a first security process to establish a first secure communication with a UE-to-UE relay node for communicating with a second UE;
[0043] In this step, the first UE establishes a first secure communication (e.g., a secure PC5 connection) with the UE-to-UE relay node. More specifically, the processor of the first UE executes a first security procedure to establish the first secure communication. Security parameters required for establishing the first secure communication can be used in the first security procedure. Before the first security procedure, discovery and selection of the UE-to-UE relay node can be performed. To communicate with a second UE (denoted as UE2) via the UE-to-UE relay node, the selected relay will be the UE-to-UE relay node that can provide better or the best communication quality for the first UE and the second UE.
[0044] The second UE can also execute a security procedure similar to the security procedure applied by the first UE to establish a secure communication with the UE-to-UE relay node. That is, secure communications are established both between the UE-to-UE relay node and the first UE and between the UE-to-UE relay node and the second UE. To establish communication between the first UE and the second UE, it may be necessary to negotiate some information through the link between the UE-to-UE relay node and the first UE and the link between the UE-to-UE relay node and the second UE.
[0045] In some embodiments, the UE-to-UE relay node can negotiate with the first UE and the second UE a security policy (e.g., end-to-end security or hop-by-hop security) to be used in the communication (i.e., end-to-end communication) between the first UE and the second UE. The determined security policy can be sent through the link between the UE-to-UE relay node and the first UE (for carrying the first secure communication) and the link between the UE-to-UE relay node and the second UE. In this way, the UE-to-UE relay node, the first UE, and the second UE can know which security policy will be used in the end-to-end communication.
[0046] In some embodiments, for example, when the first UE and the second UE are not configured with a security policy, the UE-to-UE relay node notifies the first UE and the second UE respectively of the specific security policy to be used (e.g., end-to-end security). In other embodiments, the first UE and the second UE notify the UE-to-UE relay node of the specific security policy used (e.g., end-to-end security).
[0047] In some embodiments, there is a conflict between the security policies of the first UE and the second UE, or the first UE and the second UE are not configured with a security policy. In these cases, the UE-to-UE relay node can decide the security policy for the first UE and the second UE (e.g., by negotiating with the first UE and the second UE, or by using a preset security policy in the UE-to-UE relay node, or based on specific information).
[0048] Step 120: The communication interface sends a direct communication request to the second UE via the UE-to-UE relay node;
[0049] In this step, since the links between the UE-to-UE relay node and the first UE and between the UE-to-UE relay node and the second UE have been established, in order to establish end-to-end communication with the second UE, the first UE uses the communication interface to send a direct communication request to the second UE through the UE-to-UE relay node.
[0050] In some embodiments, when end-to-end security will be used, the direct communication request may carry the necessary information for securely establishing end-to-end secure communication between the first UE and the second UE. If the second UE accepts the direct communication with the first UE, the first UE may receive a direct communication acceptance message sent by the second UE in response to the direct communication request. The first UE may also receive the direct communication acceptance message when end-to-end secure communication is established between the first UE and the second UE.
[0051] Step 130: At least one processor performs a direct security operation to establish second secure communication between the first UE and the second UE;
[0052] In this step, when end-to-end security will be used, the first UE uses the processor to perform a direct security operation to establish end-to-end secure communication (i.e., second secure communication between the first UE and the second UE). Details regarding the direct security operation can refer to the relevant operations specified in the current standard. The direct security operation may include, but is not limited to: establishing security credentials necessary for starting end-to-end secure communication for the two UEs, determining security algorithms (e.g., cryptographic algorithms and / or integrity protection algorithms), such as Advanced Encryption Standard (AES) or Rivest-Shamir-Adleman (RSA), etc.
[0053] Step 140: At least one processor disables the first secure communication with the UE-to-UE relay node during or after establishing the second secure communication with the second UE.
[0054] In this step, once the second secure communication with the second UE (e.g., with end-to-end security) is established, the first UE uses the processor to disable or turn off (or prohibit) the first secure communication with the UE-to-UE relay node (e.g., with hop-by-hop security). That is, for the secure communication between the first UE and the second UE, only one security policy (i.e., end-to-end security) is applied. Therefore, this can efficiently facilitate secure communication between the two UEs through the UE-to-UE relay node.
[0055] In some embodiments, during the process of establishing UE-to-UE communication, it is possible to notify between UEs that the first secure communication (e.g., with hop-by-hop security) is not allowed or disabled or turned off. That is, the disabling operation can be performed during the establishment of UE-to-UE communication (i.e., during the establishment of the second secure communication with the second UE). In other embodiments, after the UE-to-UE communication is established, the first secure communication (e.g., with hop-by-hop security) can be made not allowed or disabled or turned off through dedicated signaling. That is, the disabling operation can be performed after the UE-to-UE communication is established (i.e., after the establishment of the second secure communication with the second UE). The dedicated signaling is the signaling sent after the communication is established between the first UE and the second UE.
[0056] This application provides the wireless communication method 100 as described above. In this method, the first UE performs a first security process to establish a first secure communication with a UE-to-UE relay node for communicating with the second UE, sends a direct communication request to the second UE through the UE-to-UE relay node, performs a direct security operation to establish a second secure communication between the first UE and the second UE, and disables the first secure communication with the UE-to-UE relay node during or after the establishment of the second secure communication with the second UE. Since only one security policy (i.e., end-to-end security) is applied to the secure communication between the first UE and the second UE, this method enables the UE and the UE-to-UE relay node to more efficiently manage the use of their resources while providing (and maintaining) the communication security between the two UEs communicating through the UE-to-UE relay node.
[0057] Figure 7 is a schematic diagram showing the call flow of end-to-end secure communication provided in some embodiments of this application. As Figure 7 shown, the end-to-end secure communication establishment process includes the following operations:
[0058] Operation 1: Provide authorization and policy information. In this operation, the authorization and policy information of UE1 (e.g., security parameters, security policies, and other parameters necessary for the two UEs to establish communication) can be passed to UE2 through the network (not shown) or through the UE-to-UE relay, and vice versa. The authorization information can facilitate the establishment of the communication link. The policy information will be used by UE1 and UE2 to determine the security policy (e.g., end-to-end security or hop-by-hop security).
[0059] Operation 2: UE1 and UE2 discover UE-to-UE relay. If there are multiple UE-to-UE relays in the area, UE1 and UE2 select a relay that can provide relay services for them. The selected relay will be the UE-to-UE relay that can provide better or the best communication quality (e.g., Reference Signal Received Power (RSRP) or Quality of Service (QoS)) for both UE1 and UE2.
[0060] Operations 3a and 3b: UE1 and UE2 respectively establish connections (e.g., PC5 connections) with the UE-to-UE relay. During the establishment of the PC5 connection, the UE-to-UE relay respectively notifies UE1 and UE2 that end-to-end security will be used, or UE1 and UE2 notify the UE-to-UE relay that end-to-end security has been used. In the case of a security policy conflict between UE1 and UE2 or when UE1 and UE2 are not configured with security policies, the UE-to-UE relay can also decide which security policy will be used for UE1 and UE2. In this call flow, the UE-to-UE relay determines end-to-end security.
[0061] Operations 4 to Operation 9: UE1 and UE2 establish communication and establish the security credentials necessary to initiate end-to-end secure communication for both UEs. The security credential establishment process may include exchanging parameters necessary for UE1 and UE2 to establish key material (e.g., the security capabilities of the UEs, security policies, Nonce (one-time random number), authentication codes, etc.), where the key material can subsequently be used to protect the communication (e.g., end-to-end communication). Specifically, UE1 can send a direct communication request to UE2 in Operation 4, where the direct communication request can carry the necessary information for establishing security. UE2 can reply with a direct communication acceptance message in Operation 9 after establishing end-to-end secure communication between UE1 and UE2. UE1 and UE2 can perform direct authentication and key establishment in Operation 5. In Operations 6 and 7, protection algorithms such as Advanced Encryption Standard (AES) or Rivest-Shamir-Adleman (RSA) can be determined. Once the protection algorithm is determined, UE2 can start ciphering protection in Operation 8.
[0062] Operations 10a and 10b: The UE-to-UE relay disables or turns off the security measures between UE1 and the UE-to-UE relay and between UE2 and the UE-to-UE relay. It should be noted that if hop-by-hop security is used in addition to end-to-end security, the UE can be notified during the establishment of UE-to-UE communication that hop-by-hop security is not allowed or disabled or turned off, or the UE can be notified by dedicated signaling after the establishment of UE-to-UE communication that hop-by-hop security is not allowed or disabled or turned off. It should also be noted that turning off hop-by-hop security is considered more beneficial for saving resources of the UE-to-UE relay because hop-by-hop security requires the UE-to-UE relay to perform decryption and encryption for each communication exchange between UE1 and UE2 (i.e., the UE-to-UE relay uses the security key with UE1 to decrypt the communication sent from UE1 to UE2, and then uses the security key with UE2 to encrypt the communication sent from UE1 to UE2).
[0063] Operation 11: End-to-end secure communication continues between UE1 and UE2 through the UE-to-UE relay.
[0064] Figure 8 It is a flowchart of a wireless communication method 200 provided by the second embodiment of the present application. The wireless communication method 200 is applied to a first user equipment (denoted here as UE1). The exemplary structure of UE1 can refer to Figure 3 the user equipment 30' shown. The wireless communication method 200 can be implemented by using Figure 3 the communication interface 32' and the processor 34'. The method 200 includes the following steps.
[0065] Step 210: At least one processor determines that hop-by-hop security will be used for communicating with a second UE through a UE-to-UE relay node;
[0066] In this step, the first UE uses the processor to determine that hop-by-hop security will be used for communicating with a second UE (denoted as UE2) through a UE-to-UE relay node. The hop-by-hop security determined by the first UE can be a security policy determined by the UE-to-UE relay node through negotiation with the first UE and the second UE, or can be a security policy decided by the first UE and agreed by the UE-to-UE relay node.
[0067] In some embodiments, a UE-to-UE relay node may negotiate with a first UE and a second UE a security policy (e.g., end-to-end security or hop-by-hop security) to be used in the communication (i.e., end-to-end communication) between the first UE and the second UE. In this case, the determined security policy is hop-by-hop security, and the determined hop-by-hop security may be conveyed through the link between the UE-to-UE relay node and the first UE and the link between the UE-to-UE relay node and the second UE. In this way, the UE-to-UE relay node, the first UE, and the second UE are aware that hop-by-hop security will be used in the end-to-end communication.
[0068] In some embodiments, for example, in the case where the first UE and the second UE are not configured with a security policy, the UE-to-UE relay node notifies the first UE and the second UE respectively that hop-by-hop security will be used. In other embodiments, the first UE and the second UE notify the UE-to-UE relay node that hop-by-hop security is being used.
[0069] In some embodiments, there is a conflict in the security policies of the first UE and the second UE, or the first UE and the second UE are not configured with a security policy. In these cases, the UE-to-UE relay node may (e.g., by negotiating with the first UE and the second UE, or by using a pre-set security policy in the UE-to-UE relay node (in this case, hop-by-hop security is the pre-set or default security policy), or based on certain information) decide to use hop-by-hop security as the security policy to be used for the first UE and the second UE.
[0070] Step 220: At least one processor executes a hop-by-hop security process to establish a first secure communication with the UE-to-UE relay node for communicating with the second UE;
[0071] In this step, the first UE establishes a first secure communication (e.g., a secure PC5 connection) with the UE-to-UE relay node. More specifically, the processor of the first UE executes a hop-by-hop security process to establish the first secure communication. The security parameters required for establishing the first secure communication may be used in the hop-by-hop security process. Before this process, discovery and selection of the UE-to-UE relay node may be performed. To communicate with the second UE through the UE-to-UE relay node, the selected relay will be the UE-to-UE relay node that can provide better or the best communication quality for both the first UE and the second UE.
[0072] The second UE may also perform a hop-by-hop security process similar to the hop-by-hop security process applied in the first UE to establish secure communication with the UE-to-UE relay node. That is, establish secure communication between the UE-to-UE relay node and the first UE and between the UE-to-UE relay node and the second UE. To establish UE-to-UE communication, it may be necessary to negotiate some information through the link between the UE-to-UE relay node and the first UE and the link between the UE-to-UE relay node and the second UE.
[0073] Step 230: The communication interface sends a direct communication request to the second UE through the UE-to-UE relay node;
[0074] In this step, since the link between the UE-to-UE relay node and the first UE and the link between the UE-to-UE relay node and the second UE have been established, in order to establish end-to-end communication with the second UE, the first UE uses the communication interface to send a direct communication request to the second UE through the UE-to-UE relay node.
[0075] Step 240: The communication interface receives a direct communication response from the second UE through the UE-to-UE relay node; and
[0076] In this step, the first UE receives the direct communication response sent from the second UE through the communication interface. If the direct communication response is "accepted", this indicates that the second UE agrees to establish end-to-end communication with the first UE. If the direct communication response is "not accepted", this indicates that the second UE does not agree to establish end-to-end communication with the first UE.
[0077] In some embodiments, the first UE may not need to establish end-to-end secure communication with the second UE (e.g., having end-to-end security). That is, the first UE and the second UE do not communicate using end-to-end security. Therefore, only one security policy (i.e., hop-by-hop security) is applied to the secure communication between the first UE and the second UE. However, in other embodiments, establishing end-to-end secure communication with end-to-end security is allowed. In subsequent processes, it may be possible to perform not allowing or disabling or closing end-to-end secure communication. For example, after establishing UE-to-UE communication, disabling end-to-end secure communication can be achieved through dedicated signaling.
[0078] Step 250: The communication interface communicates with the second UE using hop-by-hop security through the UE-to-UE relay node.
[0079] In the step, the communication interface of the first UE is used to communicate with the second UE using hop-by-hop security. Since hop-by-hop security is used, the link between the first UE and the UE-to-UE relay node and the link between the UE-to-UE relay node and the second UE are secure. Using hop-by-hop security enables end-to-end secure communication between the first UE and the second UE. Since only one security policy (i.e., hop-by-hop security) is involved in the end-to-end communication, this can efficiently facilitate secure communication between the two UEs through the UE-to-UE relay node.
[0080] This application provides the wireless communication method 200 as described above. In this method, the first UE determines to use hop-by-hop security for communicating with the second UE through the UE-to-UE relay node, executes a hop-by-hop security process to establish a first secure communication with the UE-to-UE relay node for communicating with the second UE, sends a direct communication request to the second UE through the UE-to-UE relay node, receives a direct communication response from the second UE through the UE-to-UE relay node, and communicates with the second UE using hop-by-hop security through the UE-to-UE relay node. Since only one security policy (i.e., hop-by-hop security) is applied to the secure communication between the first UE and the second UE, this method enables the UE and the UE-to-UE relay node to more efficiently manage the use of their resources while providing (and maintaining) communication security between the two UEs communicating through the UE-to-UE relay node.
[0081] Figure 9 is a schematic diagram showing the call flow of hop-by-hop secure communication provided by some embodiments of this application. As Figure 7 shown, the hop-by-hop secure communication establishment process includes the following operations:
[0082] Operation 1: Provide authorization and policy information. In this operation, the authorization and policy information of UE1 (e.g., security parameters, security policies, and other parameters required for the two UEs to establish communication) can be passed to UE2 through the network (not shown) or through the UE-to-UE relay, and vice versa. The authorization information can facilitate the establishment of the communication link. The policy information will be used by UE1 and UE2 to determine the security policy (e.g., end-to-end security or hop-by-hop security).
[0083] Operation 2: UE1 and UE2 discover the UE-to-UE relay. If there are multiple UE-to-UE relays in the area, UE1 and UE2 select a relay that can provide relay services for them. The selected relay will be the UE-to-UE relay that can provide better or the best communication quality (e.g., reference signal received power (RSRP) or quality of service (QoS)) for both UE1 and UE2.
[0084] Operations 3a and 3b: UE1 and UE2 respectively establish a secure connection (e.g., PC5 connection) with the UE-to-UE relay. During the establishment of the PC5 connection, the UE-to-UE relay respectively notifies UE1 and UE2 that hop-by-hop security will be used, or UE1 and UE2 notify the UE-to-UE relay to use hop-by-hop security. During the establishment of the PC5 link, security is established between UE1 and the UE-to-UE relay and between UE2 and the UE-to-UE relay. In the case of a security policy conflict between UE1 and UE2 or when UE1 and UE2 are not configured with a security policy, the UE-to-UE relay can also decide which security policy will be used for UE1 and UE2. In this call flow, the hop-by-hop security is determined by the UE-to-UE relay.
[0085] Operations 4 to 5: UE1 and UE2 establish communication between them through the UE-to-UE relay. Since UE1 and UE2 are aware that hop-by-hop security will be used, there is no need to exchange the parameters required to establish security between UE1 and UE2. Specifically, UE1 can send a direct communication request to UE2 in operation 4, and UE2 can reply with a direct communication acceptance message in operation 9 to establish insecure end-to-end communication between UE1 and UE2.
[0086] Operations 6, 6a and 6b: UE1 and UE2 start communicating with each other. Since hop-by-hop security is used, the link between UE1 and the UE-to-UE relay and the link between the UE-to-UE relay and UE2 are secure. In this case, UE1 encrypts the data sent to UE2 using the security parameters established between UE1 and the UE-to-UE relay. UE1 sends the encrypted data to the UE-to-UE relay. The UE-to-UE relay decrypts the data received from UE1. The UE-to-UE relay encrypts the data using the security parameters established between the UE-to-UE relay and UE2. The UE-to-UE relay sends the encrypted data to UE2 (i.e., relays the encrypted data to UE2). It should be noted that if end-to-end security is also used in addition to hop-by-hop security, it is possible to notify UE1 / UE2 during the establishment of UE-to-UE communication that end-to-end security is not allowed or disabled or turned off, or it is possible to notify UE1 / UE2 through dedicated signaling after the establishment of UE-to-UE communication that end-to-end security is not allowed or disabled or turned off.
[0087] Since the communication security between UEs and the efficiency of UEs and the UE-to-UE relay are both important, this application provides the mechanism described above to efficiently and securely protect the communication between two UEs when they communicate with each other through the UE-to-UE relay. This mechanism also ensures that UEs communicating through the UE-to-UE relay use the same protection scheme, whether the protection scheme is end-to-end or hop-by-hop.
[0088] An alternative is to use static configuration or static security policies, such as always using hop-by-hop or end-to-end security. However, the inflexibility of static configuration may mean lower efficiency. For example, if UE-to-UE relay and UE are always configured to use security measures, UE1 and UE2 may end up in a sub-optimal situation where both hop-by-hop security and end-to-end security are used.
[0089] An embodiment of the present application also provides a first user equipment, including at least one processor and a communication interface coupled to the at least one processor, wherein the at least one processor and the communication interface are used to cooperate with each other to execute any one of the above methods. For the sake of brevity, it will not be elaborated here.
[0090] An embodiment of the present application also provides a second user equipment, including at least one processor and a communication interface coupled to the at least one processor, wherein the at least one processor and the communication interface are used to cooperate with each other to execute any one of the above methods. For the sake of brevity, it will not be elaborated here.
[0091] An embodiment of the present application also provides a UE-to-UE relay node, including at least one processor and a communication interface coupled to the at least one processor, wherein the at least one processor and the communication interface are used to cooperate with each other to execute any one of the above methods. For the sake of brevity, it will not be elaborated here.
[0092] An embodiment of the present application also provides a computer-readable storage medium for storing a computer program. The computer-readable storage medium enables a computer to execute the corresponding processes implemented in the methods of the embodiments of the present application. For the sake of brevity, it will not be elaborated here.
[0093] An embodiment of the present application also provides a computer program product including computer program instructions. The computer program product enables a computer to execute the corresponding processes implemented in the methods of the embodiments of the present application. For the sake of brevity, it will not be elaborated here.
[0094] An embodiment of the present application also provides a computer program. The computer program enables a computer to execute the corresponding processes implemented in the methods of the embodiments of the present application. For the sake of brevity, it will not be elaborated here.
[0095] Those skilled in the art can understand that any one of various different technologies can be used to represent information and signals. For example, data, instructions, commands, information, signals, bits, symbols, and chips that may be mentioned in the above description can be represented by voltage, current, electromagnetic waves, magnetic fields or magnetic particles, optical fields or optical particles, or any combination thereof.
[0096] Furthermore, those skilled in the art can understand that the various illustrative logical blocks, modules, circuits, and algorithmic steps described in connection with the embodiments disclosed herein can be implemented as electronic hardware, computer software, or a combination of both. To clearly illustrate this interchangeability of hardware and software, the various illustrative components, blocks, modules, circuits, and steps have been described generally above in terms of their functionality. Whether such functionality is implemented as hardware or software depends upon the particular application and design constraints imposed on the overall system. Those skilled in the art can implement the described functionality in different ways for each particular application, but such implementation decisions should not be construed as causing a departure from the scope of the present invention.
[0097] The methods, sequences, and / or algorithms described in connection with the embodiments disclosed herein can be embodied directly in hardware, in software modules executed by a processor, or in a combination of both. The software modules can be located in RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor such that the processor can read information from, and write information to, the storage medium. Alternatively, the storage medium can be integrated with the processor.
[0098] It should be understood that any embodiment disclosed herein as "non-transitory" does not exclude any physical storage medium, but only excludes an interpretation that might regard the medium as a transitory propagated signal.
[0099] The elements and components of the embodiments of the present invention can be physically, functionally, and logically implemented in any suitable manner. In fact, the functionality can be implemented in a single unit, multiple units, or as part of other functional units. Although the present invention has been described in connection with some embodiments, it is not intended to limit the present invention to the specific forms set forth herein. On the contrary, the scope of the present invention is defined only by the appended claims. Furthermore, although the description of a certain feature may seem to be related to a particular embodiment, those skilled in the art will recognize that the various features described in connection with the embodiments can be combined. In the claims, the term "comprising" does not exclude the presence of other elements or steps.
[0100] In addition, although multiple devices, elements, or method steps are listed separately, they can be implemented by, for example, a single unit or processor. Moreover, although the various features can be included in different claims, these features can be advantageously combined, and the inclusion in different claims does not mean that the combination of features is infeasible and / or disadvantageous. Additionally, including a feature in only one class of claims does not mean it is limited to that class, but rather that the feature is equally applicable to other claim classes as appropriate.
[0101] Furthermore, the order of features in the claims does not mean that these features must be performed in any specific order, especially the order of the individual steps in a method claim does not mean that the steps must be performed in that order. On the contrary, the steps can be performed in any suitable order. In addition, a singular reference does not exclude a plurality. Thus, references to "a", "an", "first", "second", etc. do not exclude a plurality.
[0102] In summary, although the preferred embodiments of the present application have been described in detail, various modifications and changes can be made by those of ordinary skill in the art. Therefore, the embodiments of the present application are described in an illustrative rather than a restrictive sense. The present application should not be limited to the specific forms shown, and all modifications and changes within the spirit and scope of the present application are within the scope defined by the appended claims.
Claims
1. A wireless communication method for a first user equipment (UE), characterized in that, Comprising: At least one processor executes a first security process to establish a first secure communication with a UE-to-UE relay node for communicating with a second UE; A communication interface sends a direct communication request to the second UE via the UE-to-UE relay node; The at least one processor executes a direct security operation to establish a second secure communication between the first UE and the second UE; And The at least one processor disables the first secure communication with the UE-to-UE relay node during or after establishing the second secure communication with the second UE.
2. The method according to claim 1, characterized in that, Once the first secure communication is established, a determined security policy is sent via the first secure communication, and the determined security policy includes end-to-end security.
3. The method according to claim 2, characterized in that, In the case where there is a conflict in the security policies of the first UE and the second UE, or in the case where the first UE and the second UE are not configured with security policies, the determined security policy is provided.
4. The method according to claim 1, characterized in that, Further comprising: The communication interface sends, via the first secure communication, the security policy used by the first UE to the UE-to-UE relay node.
5. The method according to claim 1, characterized in that, The direct communication request carries necessary information for establishing the second secure communication between the first UE and the second UE.
6. The method according to claim 1, characterized in that, During the process of establishing UE-to-UE communication, the disabling of the first secure communication is notified between the first UE and the second UE.
7. The method according to claim 1, characterized in that, After establishing UE-to-UE communication, the first secure communication is disabled by dedicated signaling.
8. A first user equipment (UE), characterized in that, Comprising: At least one processor for executing a first security process to establish a first secure communication with a UE-to-UE relay node for communicating with a second UE; And A communication interface, coupled to the at least one processor, for sending a direct communication request to the second UE via the UE-to-UE relay node, wherein the at least one processor is further configured to: Execute a direct security operation to establish a second secure communication between the first UE and the second UE; and Disable the first secure communication with the UE-to-UE relay node during or after establishing the second secure communication with the second UE.
9. The first UE according to claim 8, characterized in that, Once the first secure communication is established, a determined security policy is sent via the first secure communication, and the determined security policy includes end-to-end security.
10. The first UE according to claim 9, characterized in that, In the case where there is a conflict in the security policies of the first UE and the second UE, or in the case where the first UE and the second UE are not configured with security policies, the determined security policy is provided.
11. The first UE according to claim 8, characterized in that, The communication interface is further configured to: Send, via the first secure communication, the security policy used by the first UE to the UE-to-UE relay node.
12. The first UE according to claim 8, characterized in that, The direct communication request carries necessary information for establishing the second secure communication between the first UE and the second UE.
13. The first UE according to claim 8, characterized in that, During the process of establishing UE-to-UE communication, the disabling of the first secure communication is notified between the first UE and the second UE.
14. The first UE according to claim 8, characterized in that, After establishing UE-to-UE communication, the first secure communication is disabled by dedicated signaling.
15. A wireless communication method for a first user equipment (UE), characterized in that, Comprising: At least one processor determines to use hop-by-hop security for communicating with a second UE via a UE-to-UE relay node; The at least one processor performs a hop-by-hop security process to establish a first secure communication with the UE-to-UE relay node for communicating with the second UE; A communication interface sends a direct communication request to the second UE via the UE-to-UE relay node; The communication interface receives a direct communication response from the second UE via the UE-to-UE relay node; and The communication interface communicates with the second UE using the hop-by-hop security via the UE-to-UE relay node.
16. The method according to claim 15, characterized in that, Once the first secure communication is established, the determined hop-by-hop security is sent via the first secure communication.
17. The method according to claim 16, characterized in that, In the case of a conflict in the security policies of the first UE and the second UE, or based on a preset security policy in the UE-to-UE relay node, the determined hop-by-hop security is provided.
18. The method according to claim 15, characterized in that, The first UE and the second UE do not communicate using end-to-end security.
19. A first user equipment (UE), characterized in that, Comprising at least one processor and a communication interface coupled to the at least one processor, wherein the at least one processor and the communication interface are configured to cooperate with each other to perform the method according to claim 1.