Communication method and device

CN120239955APending Publication Date: 2025-07-01HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202280101489.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2022-11-11
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

The existing security policy negotiation mechanism cannot effectively meet the changing needs of users in different business scenarios, resulting in limitations in communication security performance and the inability to proactively trigger new security policy negotiation processes, resulting in security performance challenges.

Method used

Deploying an independent security function module in the communication system allows communication nodes to generate and negotiate security policies based on their security requirements and capabilities, and dynamically generate and update security policies through information exchange and requests between the first security module and the second security module. To adapt to the needs of different business scenarios.

Benefits of technology

It improves the security performance of the communication system, can dynamically adapt to changes in user security requirements, reduces communication delays, and ensures the timeliness and flexibility of security policies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120239955A_ABST
    Figure CN120239955A_ABST
Patent Text Reader

Abstract

Provided is a communication method, comprising: a first security module generating a security policy based on a trusted demand declaration of a first node and / or a network global trusted policy of the first node and a trusted demand declaration of a second node and / or a network global trusted policy of the second node (S420), the first security module is a security module serving a first node, and the second security module is a security module serving a second node; and the first security module sends a security policy to the second security module (S430), wherein the security policy is used for secure communication between the first node and the second node. According to the invention, security policy negotiation can be performed based on the security requirement of the user to generate the security policy, which is suitable for the security requirements of more service scenes and improves the security performance of communication.
Need to check novelty before this filing date? Find Prior Art

Description

A communication method and device Technical Field

[0001] The present application relates to the field of communications, and more particularly, to a communication method and a communication device. Background Art

[0002] Communication network security technology is an interdisciplinary field that intersects communication networks and security. It is based on security policy negotiation between communicating parties. In existing technologies, security policy negotiation is initiated by the network side, which generates a security policy based on the capability lists of both communicating parties.

[0003] With the advancement of communication technologies, user security needs are constantly evolving. Existing security policy negotiation, which generates security policies based on capability lists, struggles to meet these needs. For example, in different business scenarios, user security needs may change, but the network cannot autonomously detect these changes and continues to use the existing security policy. Another example is when a user's security needs change, the user cannot proactively trigger a new security policy negotiation process and must passively use the existing security policy, presenting significant security challenges.

[0004] Therefore, when conducting security policy negotiation, how to generate a security policy that meets the user's security needs becomes an issue worthy of attention.

[0005] Summary of the Invention

[0006] The present application proposes a communication method and a communication device that can negotiate security policies based on the user's security needs, thereby generating security policies that are applicable to the security needs of more business scenarios and improve the security performance of communications.

[0007] In the first aspect, a communication method is provided, which can be executed by a first security module. The first security module can be a security function unit, module or device, or a chip or circuit in a security function unit, module or device, or a logic module or software that can implement all or part of the security function. This application does not limit this.

[0008] The method includes: a first security module generates a security policy based on first information and second information, the first information includes a trust requirement statement of a first node and / or a network global trust policy of the first node, the second information includes a trust requirement statement of a second node and / or a network global trust policy of the second node, the first security module is a security module serving the first node, and the second security module is a security module serving the second node; the first security module sends the security policy to the second security module, and the security policy is used for secure communication between the first node and the second node.

[0009] According to the above technical solution, an independent security function module (first security module or second security module) is deployed at the communication node (first node or second node), thereby enabling the security policy negotiation process of the communication node based on communication needs in the communication system. The security function module of the communication node generates a security policy according to the security needs and security capabilities of the communication node in the security negotiation process, which is suitable for the security needs of more business scenarios of the node, thereby improving the security performance of communication.

[0010] With reference to the first aspect, in a possible implementation manner, the first security module receives the second information from the second security module.

[0011] In this solution, if the first security module stores the second information that can be directly used, it can directly generate a security policy based on the first and second information, thereby reducing communication latency. However, if the first security module does not have the second information that can be directly used, the second security module can obtain the second information, thus ensuring the timeliness of the security requirements of the second node.

[0012] It should be understood that the first security module may obtain the second information from the second security module directly, or obtain the second information through forwarding by the first node and the second node.

[0013] With reference to the first aspect, in a possible implementation, the first security module receives a first request message from the second security module, where the first request message is used to request the first security module to perform security negotiation, and the first request message includes the second information.

[0014] In this solution, the second security module triggers the security policy negotiation process and carries the second information in the negotiation request message (first request message), thereby saving overhead and reducing delay.

[0015] With reference to the first aspect, in a possible implementation, the first security module sends a second request message to the second security module, where the second request message is used to request the second security module to perform security negotiation.

[0016] In this solution, the first security module triggers the security policy negotiation process, and the second security module sends the second information to the first security module for generating the security policy. This solution is flexible, and any communication node with policy negotiation requirements can trigger the negotiation process.

[0017] In combination with the first aspect, in a possible implementation, the first information further includes a trusted configuration obtained from the management end, and the second information further includes a trusted configuration obtained from the management end.

[0018] On the second aspect, a communication method is provided, which can be executed by a second security module. The second security module can be a security function unit, module or device, or a chip or circuit in a security function unit, module or device, or a logic module or software that can implement all or part of the security function. This application does not limit this.

[0019] The method includes: a second security module determines second information, the second information is used by the first security module to generate a security policy in combination with the first information, the first information includes a trust requirement statement of a first node and / or a network global trust policy of the first node, the second information includes a trust requirement statement of a second node and / or a network global trust policy of the second node, the first security module is a security module serving the first node, and the second security module is a security module serving the second node; the second security module receives the security policy from the first security module, and the security policy is used for secure communication between the first node and the second node.

[0020] According to the above technical solution, an independent security function module is deployed at the communication node (first node or second node), thereby enabling the security policy negotiation process of the communication node based on communication needs in the communication system. The security function module of the communication node generates a security policy according to the security needs and security capabilities of the communication node in the security negotiation process, which is suitable for the security needs of more business scenarios of the node, thereby improving the security performance of communication.

[0021] With reference to the second aspect, in a possible implementation, the second security module sends the second information to the first security module.

[0022] In this solution, if the first security module stores the second information that can be directly used, it can directly generate a security policy based on the first and second information, thereby reducing communication latency. However, if the first security module does not have the second information that can be directly used, the second security module can obtain the second information, thus ensuring the timeliness of the security requirements of the second node.

[0023] With reference to the second aspect, in a possible implementation, the second security module sends a first request message to the first security module, where the first request message is used to request the first security module to perform security negotiation, and the first request message includes the second information.

[0024] In this solution, the second security module triggers the security policy negotiation process and carries the second information in the negotiation request message (first request message), thereby saving overhead and reducing delay.

[0025] With reference to the second aspect, in a possible implementation, the second security module receives a second request message from the first security module, where the second request message is used to request the second security module to perform security negotiation.

[0026] In this solution, the first security module triggers the security policy negotiation process, and the second security module sends the second information to the first security module for generating the security policy. This solution is flexible, and any communication node with policy negotiation requirements can trigger the negotiation process.

[0027] In conjunction with the second aspect, in a possible implementation, the first information further includes a trusted configuration obtained from the management end, and the second information further includes a trusted configuration obtained from the management end.

[0028] On the third aspect, a communication device is provided, which can be a first security module. The first security module can be a security function unit, module or device, or a chip or circuit in a security function unit, module or device, or a logic module or software that can realize all or part of the security function. This application does not limit this.

[0029] The device includes: a processing unit, used to generate a security policy based on first information and second information, the first information includes a trust requirement statement of a first node and / or a network global trust policy of the first node, the second information includes a trust requirement statement of a second node and / or a network global trust policy of the second node, the first security module is a security module serving the first node, and the second security module is a security module serving the second node; a transceiver unit, used to send the security policy to the second security module, and the security policy is used for secure communication between the first node and the second node.

[0030] In conjunction with the third aspect, in a possible implementation manner, the transceiver unit is further configured to receive the second information from the second security module.

[0031] In conjunction with the third aspect, in a possible implementation, the transceiver unit is specifically configured to receive a first request message from the second security module, where the first request message is used to request the first security module to perform security negotiation, and the first request message includes the second information.

[0032] With reference to the third aspect, in a possible implementation, the transceiver unit is specifically configured to send a second request message to the second security module, where the second request message is used to request the second security module to perform security negotiation.

[0033] In conjunction with the third aspect, in a possible implementation, the first information further includes a trusted configuration obtained from the management end, and the second information further includes a trusted configuration obtained from the management end.

[0034] In the fourth aspect, a communication device is provided, which can be a second security module. The second security module can be a security function unit, module or device, or a chip or circuit in a security function unit, module or device, or a logic module or software that can realize all or part of the security function. This application does not limit this.

[0035] The device includes: a processing unit for determining second information, the second information being used by the first security module to generate a security policy in combination with the first information, the first information including a trust requirement statement of a first node and / or a network global trust policy of the first node, the second information including a trust requirement statement of a second node and / or a network global trust policy of the second node, the first security module being a security module serving the first node, and the second security module being a security module serving the second node; and a transceiver unit for receiving the security policy from the first security module, the security policy being used for secure communication between the first node and the second node.

[0036] With reference to the fourth aspect, in a possible implementation manner, the transceiver unit is further configured to send the second information to the first security module.

[0037] In conjunction with the fourth aspect, in a possible implementation, the transceiver unit is specifically configured to send a first request message to the first security module, where the first request message is used to request the first security module to perform security negotiation, and the first request message includes the second information.

[0038] With reference to the fourth aspect, in a possible implementation, the transceiver unit is specifically configured to receive a second request message from the first security module, where the second request message is used to request the second security module to perform security negotiation.

[0039] In conjunction with the fourth aspect, in a possible implementation, the first information further includes a trusted configuration obtained from the management end, and the second information further includes a trusted configuration obtained from the management end.

[0040] In combination with the fourth aspect, in a possible implementation, the processing unit is further configured to save the security policy.

[0041] In a fifth aspect, a communication device is provided, comprising a processor coupled to a memory and configured to execute instructions in the memory to implement the method described above in any one of the first to second aspects, and any possible implementation of the first to second aspects. Optionally, the device further comprises a memory, which may be deployed separately from the processor or may be deployed centrally. Optionally, the device further comprises a communication transceiver, and the processor is coupled to the communication transceiver. In one implementation, the communication transceiver may be a transceiver, or an input / output transceiver.

[0042] When the device is a chip, the communication transceiver can be an input / output transceiver, a transceiver circuit, an output circuit, an input circuit, a pin or related circuits on the chip or chip system, etc. The processor can also be embodied as a processing circuit or a logic circuit.

[0043] Optionally, the transceiver may be a transceiver circuit. Optionally, the input / output transceiver may be an input / output circuit.

[0044] In a specific implementation, the processor may be one or more chips, the input circuit may be an input pin, the output circuit may be an output pin, and the processing circuit may be a transistor, a gate circuit, a trigger, or various logic circuits. The input signal received by the input circuit may be, but is not limited to, received and input by a receiver, and the signal output by the output circuit may be, but is not limited to, output to and transmitted by a transmitter. The input circuit and the output circuit may be the same circuit, which functions as an input circuit and an output circuit at different times. The embodiments of the present application do not limit the specific implementation of the processor and various circuits.

[0045] In a sixth aspect, a communication device is provided, which includes a logic circuit and an input / output transceiver, wherein the logic circuit is used to couple with the input / output transceiver and transmit data through the input / output transceiver to execute any aspect of the above-mentioned first to second aspects, and any possible implementation method of the first to second aspects.

[0046] In a seventh aspect, a communication system is provided, which includes the first module in any possible implementation of the first aspect or the second aspect.

[0047] In an eighth aspect, a computer-readable storage medium is provided, which stores a computer program (also referred to as code, or instructions). When the computer-readable storage medium is run on a computer, the computer executes any one of the above-mentioned first to second aspects, and any possible implementation of the first to second aspects.

[0048] In the ninth aspect, a computer program product is provided, which includes: a computer program (also referred to as code, or instructions), which, when executed, enables a computer to execute any one of the above-mentioned first to second aspects, and any possible implementation of the first to second aspects.

[0049] In the tenth aspect, a circuit system is provided, comprising a memory and a processor, wherein the memory is used to store a computer program, and the processor is used to call and run the computer program from the memory, so that a communication device equipped with the circuit system executes a method in any possible implementation of the first or second aspect above.

[0050] Among them, the circuit system may include an input circuit or transceiver for sending information or data, and an output circuit or transceiver for receiving information or data.

[0051] In an eleventh aspect, a circuit system is provided for executing the method in any possible implementation of the first aspect or the second aspect.

[0052] The beneficial effects brought about by the third to eleventh aspects mentioned above can be referred to the description of the beneficial effects in the first to second aspects, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0053] FIG1 shows a schematic diagram of a wireless communication system 100 applicable to an embodiment of the present application.

[0054] FIG2 shows a schematic diagram of a network architecture 200 applicable to an embodiment of the present application.

[0055] FIG3 shows a schematic diagram of a network architecture 300 applicable to an embodiment of the present application.

[0056] FIG4 shows a schematic interaction diagram applicable to the communication method provided in a specific embodiment of the present application.

[0057] FIG5 shows a schematic flow chart of a communication method applicable to a specific embodiment of the present application.

[0058] FIG6 shows another schematic flow chart of a communication method applicable to a specific embodiment of the present application.

[0059] FIG7 shows a triggering process of a security policy negotiation process applicable to different application scenarios of a specific embodiment of the present application.

[0060] FIG8 shows a security negotiation process triggered by a communication node change applicable to a specific embodiment of the present application.

[0061] FIG9 shows a schematic block diagram of a communication device applicable to an embodiment of the present application.

[0062] FIG10 shows a schematic architecture diagram of a communication device applicable to an embodiment of the present application. DETAILED DESCRIPTION

[0063] The technical solution in this application will be described below with reference to the accompanying drawings.

[0064] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as: Global System of Mobile communication (GSM) system, Code Division Multiple Access (CDMA) system, Wideband Code Division Multiple Access (WCDMA) system, General Packet Radio Service (GPRS), Long Term Evolution (LTE) system, LTE frequency division duplex (FDD) system, LTE time division duplex (TDD) system, Universal Mobile Telecommunications System (UMTS), Worldwide Interoperability for Microwave Access (WiMAX) communication system, Fifth Generation (5G) mobile communication system or new radio (NR), wireless local area network (WLAN) system, wireless fidelity (WiFi) system. Among them, the 5G mobile communication system can be a non-standalone (NSA) or standalone (SA) network.

[0065] The technical solution provided in this application can also be applied to machine type communication (MTC), long term evolution-machine (LTE-M), device-to-device (D2D) network, machine-to-machine (M2M) network, Internet of Things (IoT) network or other networks. Among them, the IoT network can include, for example, the Internet of Vehicles. Among them, the communication mode in the Internet of Vehicles system is collectively referred to as vehicle to other devices (vehicle to X, V2X, X can represent anything), for example, the V2X can include: vehicle to vehicle (V2V) communication, vehicle to infrastructure (V2I) communication, vehicle to pedestrian (V2P) communication or vehicle to network (V2N) communication, etc.

[0066] The technical solution provided in this application may also be applied to future communication systems, such as the sixth generation (6G) mobile communication system, etc. This application does not limit this.

[0067] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0068] Figure 1 is a schematic diagram of a communication system 100 applicable to an embodiment of the present application. As shown in Figure 1, the communication system 100 may include at least one network device, such as the network device 110 shown in Figure 1; the communication system 100 may also include at least one terminal device, such as the terminal device 120 shown in Figure 1. The network device 110 and the terminal device 120 can communicate via a wireless link. Each communication device, such as the network device 110 or the terminal device 120, can be configured with multiple antennas. For each communication device in the communication system, the configured multiple antennas may include at least one transmitting antenna for sending signals and at least one receiving antenna for receiving signals. Therefore, communication between the communication devices in the communication system and between the network device 110 and the terminal device 120 can be achieved through multi-antenna technology.

[0069] It should be understood that FIG1 is only a simplified schematic diagram for ease of understanding, and the communication system may further include other network devices or other terminal devices, which are not shown in FIG1 .

[0070] It should also be understood that the communication system 100 shown in Figure 1 is only an example of an application scenario of an embodiment of the present application. The present application can also be applied to communication between any two devices, for example, communication between terminal devices, and communication between network devices.

[0071] FIG2 is a schematic diagram of a network architecture 200 applicable to the communication system of the present application.

[0072] As shown in Figure 2, the network architecture of the communication system includes but is not limited to the following network elements:

[0073] 1. User Equipment (UE): The user equipment in the embodiments of the present application may also be referred to as user equipment (UE), mobile station (MS), mobile terminal (MT), access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent or user device, etc.

[0074] The user equipment may be a device that provides voice / data connectivity to the user, for example, a handheld device or a vehicle-mounted device with a wireless connection function. At present, some examples of terminals include: mobile phones, tablet computers, laptop computers, PDAs, mobile internet devices (MIDs), wearable devices, virtual reality (VR) devices, augmented reality (AR) devices, wireless terminals in industrial control, wireless terminals in self-driving, wireless terminals in remote medical surgery, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, wireless terminals in smart homes, cellular phones, cordless phones, session initiation protocol (SIP) phones, wireless local loop (WLL) stations, personal digital assistants (PDAs), handheld devices with wireless communication capabilities, computing devices or other processing devices connected to wireless modems, vehicle-mounted devices, wearable devices, user equipment in future 5G networks or future evolved public land mobile communication networks (PLMNs). The embodiment of the present application does not limit this.

[0075] As an example and not a limitation, in the embodiments of the present application, the user device may also be a wearable device. Wearable devices may also be referred to as wearable smart devices, which are a general term for wearable devices that are intelligently designed and developed using wearable technology for everyday wear, such as glasses, gloves, watches, clothing, and shoes. A wearable device is a portable device that is worn directly on the body or integrated into the user's clothes or accessories. Wearable devices are not just hardware devices, but also achieve powerful functions through software support, data interaction, and cloud interaction. Broadly speaking, wearable smart devices include those that are fully functional, large in size, and can achieve complete or partial functions without relying on smartphones, such as smart watches or smart glasses, as well as those that only focus on a certain type of application function and need to be used in conjunction with other devices such as smartphones, such as various smart bracelets and smart jewelry for vital sign monitoring.

[0076] Furthermore, in the embodiments of the present application, the user device may also be a user device in an Internet of Things (IoT) system. The IoT is an important component of future information technology development. Its main technical feature is to connect objects to the network through communication technology, thereby realizing an intelligent network that interconnects humans and machines, and objects and things.

[0077] In the embodiments of the present application, IoT technology can achieve massive connections, deep coverage, and terminal power saving through, for example, narrowband NB technology. For example, an NB can include one resource block (RB), that is, the NB bandwidth is only 180KB. To achieve massive access, it is necessary to require that terminals are discrete in access. According to the communication method of the embodiments of the present application, it can effectively solve the congestion problem of massive IoT terminals when accessing the network through NB.

[0078] In addition, the access device in the embodiment of the present application may be a device for communicating with a user device. The access device may also be referred to as an access network device or a wireless access network device. For example, the access device may be an evolved NodeB (eNB or eNodeB) in an LTE system, or a wireless controller in a cloud radio access network (CRAN) scenario, or the access device may be a relay station, an access point, a vehicle-mounted device, a wearable device, and an access device in a future 5G network or an access device in a future evolved PLMN network, etc. It may be an access point (AP) in a WLAN, or a gNB in ​​a new radio system (NR). The embodiment of the present application is not limited.

[0079] In addition, in the embodiment of the present application, the user equipment may also communicate with user equipment of other communication systems, for example, inter-device communication, etc. For example, the user equipment may also transmit (for example, send and / or receive) time synchronization messages with user equipment of other communication systems.

[0080] 2. Access device (AN / RAN): The access device in the embodiment of the present application may be a device for communicating with a user equipment. The access device may also be referred to as an access network device or a wireless access network device. For example, the access device may be an evolved NodeB (eNB or eNodeB) in an LTE system, or a wireless controller in a cloud radio access network (CRAN) scenario, or the access device may be a relay station, an access point, a vehicle-mounted device, a wearable device, an access device in a 5G network, or an access device in a future evolved PLMN network, etc. It may be an access point (AP) in a WLAN, or a gNB in ​​an NR system. The embodiment of the present application is not limited thereto.

[0081] In addition, in the embodiment of the present application, the access device is a device in the RAN, or in other words, a RAN node that connects the user equipment to the wireless network. For example, as an example and not a limitation, the access device can be listed as: gNB, transmission reception point (TRP), evolved Node B (eNB), radio network controller (RNC), Node B (NB), base station controller (BSC), base transceiver station (BTS), home base station (e.g., home evolved NodeB, or home Node B, HNB), base band unit (BBU), or wireless fidelity (Wifi) access point (AP). In a network structure, the network device may include a centralized unit (CU) node, a distributed unit (DU) node, or a RAN device including a CU node and a DU node, or a RAN device including a control plane CU node (CU-CP node) and a user plane CU node (CU-UP node) and a DU node.

[0082] An access device provides services for a cell, and a user device communicates with the access device through the transmission resources used by the cell (e.g., frequency domain resources, or spectrum resources). The cell may be a cell corresponding to the access device (e.g., a base station). The cell may belong to a macro base station or a base station corresponding to a small cell. Small cells may include: metro cells, micro cells, pico cells, femto cells, etc. These small cells have the characteristics of small coverage and low transmission power, and are suitable for providing high-speed data transmission services.

[0083] In addition, multiple cells can operate simultaneously on the same frequency on a carrier in an LTE or 5G system. In some special scenarios, the concepts of carrier and cell can be considered equivalent. For example, in a carrier aggregation (CA) scenario, when a secondary carrier is configured for a UE, both the carrier index of the secondary carrier and the cell identification (Cell ID) of the secondary cell operating on the secondary carrier are carried. In this case, the concepts of carrier and cell can be considered equivalent, for example, a user equipment accessing a carrier is equivalent to accessing a cell.

[0084] The communication system of the present application can also be applied to vehicle to everything (V2X) technology, that is, the user equipment of the present application can also be a car, for example, a smart car or a self-driving car.

[0085] The "X" in V2X represents different communication goals. V2X can include but is not limited to: vehicle to vehicle (V2V), vehicle to infrastructure (V2I), vehicle to network (V2N), and vehicle to pedestrian (V2P).

[0086] In V2X, access devices can configure "zones" for UEs. These zones can also be called geographic regions. Once configured, the world is divided into multiple zones, defined by reference points, length, and width. When determining a zone identifier (ID), the UE uses the zone's length, width, the number of zones in the length, the number of zones in the width, and the reference points. This information can be configured by the access device.

[0087] V2X services can be provided in two ways: Proximity-based Services Communication 5 (PC5) transceivers and Uu transceivers. PC5 transceivers are defined based on sidelinks and allow direct communication between communication devices (e.g., vehicles). PC5 transceivers can be used both out of coverage (OOC) and in coverage (IC), but only authorized communication devices can use PC5 transceivers for transmission.

[0088] 3. Access and Mobility Management Function (AMF) network element: Mainly used for mobility management and access management, etc., and can be used to implement other functions of the mobility management entity (MME) in the LTE system except session management, such as lawful interception and access authorization / authentication. When the AMF network element provides services for a session in a user equipment, it will provide control plane storage resources for the session to store the session identifier, the SMF network element identifier associated with the session identifier, etc. In the embodiment of the present application, it can be used to implement the functions of the access and mobility management network element.

[0089] 4. Session Management Function (SMF) network element: This element is primarily used for session management, allocating and managing Internet Protocol (IP) addresses for user devices, selecting and managing endpoints for user plane functions, policy control, or charging functions, and downlink data notification. In embodiments of the present application, this element can be used to implement the functions of the session management network element.

[0090] 5. Policy Control Function (PCF) network element: A unified policy framework used to guide network behavior, providing policy rule information and flow-based billing control functions for control plane function network elements (such as AMF, SMF network elements, etc.).

[0091] 6. Unified data management (UDM) network element: Mainly responsible for processing UE subscription data, including the storage and management of user identities, user subscription data, authentication data, etc.

[0092] 7. User Plane Function (UPF) network element: This element can be used for packet routing and forwarding, or for quality of service (QoS) processing of user plane data. User data can be connected to the data network (DN) through this element, and user data can also be received from the data network and transmitted to the user equipment through the access network equipment. The transmission resources and scheduling functions provided to the user equipment in the UPF network element are managed and controlled by the SMF network element. In the embodiments of the present application, this element can be used to implement the functions of the user plane network element.

[0093] 8. Network Exposure Function (NEF) network element: Used to securely expose services and capabilities provided by 3GPP network functions to the outside world, mainly supporting secure interaction between 3GPP networks and third-party applications.

[0094] 9. Application Function (AF) NE: This NE is used to perform application-influenced data routing, access network open function NEs, or interact with the policy framework for policy control, such as influencing data routing decisions, policy control functions, or providing third-party services to the network side.

[0095] 10. Network Slice Selection Function (NSSF) network element: mainly responsible for network slice selection, and determines the network slice instance that the UE is allowed to access based on the UE's slice selection auxiliary information, contract information, etc.

[0096] 11. Authentication Server Function (AUSF) network element: supports 3GPP and non-3GPP access authentication.

[0097] 12. Network Repository Function (NRF) network element: supports registration and discovery of network functions.

[0098] 13. Unified Data Repository (UDR) network element: stores and retrieves contract data used by UDM and PCF.

[0099] In this network architecture, N2 is a reference point between the RAN and AMF entities, used for sending NAS (Non-Access Stratum) messages, etc.; N3 is a reference point between the RAN and UPF network elements, used for transmitting user plane data, etc.; N4 is a reference point between the SMF network element and the UPF network element, used for transmitting information such as tunnel identification information of the N3 connection, data cache indication information, and downlink data notification messages.

[0100] It should be understood that the UE, (R)AN, UPF and DN in Figure 2 are generally referred to as data plane network functions and entities. The user's data traffic can be transmitted through the PDU session established between the UE and the DN, and the transmission will pass through the two network function entities (R)AN and UPF; the other parts are called control plane network functions and entities, which are mainly responsible for functions such as authentication and authorization, registration management, session management, mobility management and policy control, so as to achieve reliable and stable transmission of user layer traffic.

[0101] It should be understood that the above-mentioned network architecture applied to the embodiment of the present application is only an example of the network architecture described from the perspective of traditional point-to-point architecture and service-oriented architecture. The network architecture applicable to the embodiment of the present application is not limited to this. Any network architecture that can realize the functions of the above-mentioned network elements is applicable to the embodiment of the present application.

[0102] It should be understood that the names of the messages sent and received between the various network elements in Figure 2 are only examples. In specific implementations, the names of the messages sent and received may be other names, and this application does not specifically limit this. In addition, the names of the messages (or signaling) transmitted between the various network elements are only examples and do not constitute any limitation on the functions of the messages themselves.

[0103] It should be noted that the above-mentioned "network element" can also be referred to as an entity, device, apparatus or module, etc., and this application does not specifically limit it. Moreover, in this application, for the sake of ease of understanding and explanation, the description of "network element" is omitted in some descriptions. For example, the SMF network element is referred to as SMF. In this case, the "SMF" should be understood as the SMF network element or SMF entity. The description of the same or similar situations will be omitted below.

[0104] It is understandable that the above entities or functions can be network elements in hardware devices, software functions running on dedicated hardware, or virtualized functions instantiated on a platform (e.g., a cloud platform).

[0105] It should be understood that the above-mentioned network architecture applied to the embodiment of the present application illustrates an example of a service-oriented architecture, in which the core network sets up special network elements for different types of communication services, that is, communication-related functions can be provided in the form of services. In the embodiment of the present application, communication-related functions are not limited to the functional network elements listed in Figure 2, and the embodiment of the present application does not limit this.

[0106] It should be understood that in the prior art, security as a function is dispersed in various communication nodes. For example, AUSF supports authentication for 3GPP access and non-3GPP access; SEAF provides authentication function in the service network and can support the initial authentication process based on subscription concealed identifier (SUCI); AMF supports encryption and integrity protection of NAS signaling; NRF supports two-way authentication function with other NFs and supports authorization function for other NFs; NEF supports two-way authentication function with AF and supports encryption, integrity protection and replay protection of messages between NF and NF through transport layer security (TLS); base station supports encryption, integrity protection and replay protection of messages between UE and UE through PDCP protocol, and supports two-way authentication function, encryption, integrity protection and replay protection between CU and DU; UE supports two-way authentication function with core network, supports encryption, integrity protection and replay protection of NAS signaling with core network, and supports radio resource control (RRC) between UE and base station through packet data convergence protocol (PDCP). The 5G-LTE standard supports encryption, integrity protection, and replay protection of 5G LTE control (RRC) messages, privacy protection by converting the subscription permanent identifier (SUPI) to the 5G globally unique temporary UE identifier (5G-GUTI), upper-layer application-visible security features, and user-configurable security features.

[0107] It should be noted that the security policy negotiation of the existing 5G network is mainly triggered by the network and is based on the user's security capabilities. For example, the security policy negotiation between the UE and the CN is mainly carried out in the Security Mode Command phase of the NAS protocol. In the initial registration phase, the UE sends the UE security capabilities IE to the AMF, and the AMF sends a SECURITY MODE COMMAND message, which carries the Selected EPS NAS security algorithms IE, which is used to declare the encryption and integrity protection algorithms provided by the network to the UE. The UE sets the encryption and integrity protection algorithms. The security algorithm obtained by the security policy negotiation is determined by the network based on security capabilities, which is difficult to meet the user's security needs. For example, when the user's business scenario changes, the network side cannot perceive the change in the user's security needs and cannot provide new security policies to meet the new security needs. The security policy negotiation under the existing security function deployment is obviously unable to meet communication needs, resulting in communication security problems.

[0108] Secure transmission is the basic guarantee for communication. The embodiments of the present application can deploy independent security functions, thereby enabling the communication nodes in the communication system to negotiate security policies based on communication needs, which is suitable for the security needs of more business scenarios and improves the security performance of communication.

[0109] The present application provides a security function module, which is not limited to hardware or software. In the following specific embodiments, the first module and the second module can be two different types of security function modules. The first security module and the second security module are two security function modules serving different communication nodes, and are represented by security module #1 and security module #2, respectively, in the specific embodiments.

[0110] Based on the security function module, based on different capability properties, it is specifically divided into two categories: the first module and the second module. Among them, the first module is used to call security algorithms, obtain security parameters or request security services from other security function modules; the second module is used to perform management of security services or management of the first module.

[0111] Exemplarily, the second module performs management of security services, which can be the management, addition, deletion, and granting of new capabilities (data on-chain, downloading, participation in public disclosure mechanisms, smart contracts, etc.) of blockchain nodes in blockchain services.

[0112] For example, the second module uses network behavior data for analysis and security policy development. After collecting behavioral information, the 6G network's own AI capabilities can analyze and output policies. Alternatively, the network can integrate third-party professional service capabilities, de-identifying the behavior data and handing it over to third parties for analysis and policy output. Alternatively, third-party service modules (such as Defense Solutions) can be embedded within the second module, becoming internalized as part of the second module.

[0113] FIG3 is a schematic diagram of a network architecture 300 suitable for use in the present application.

[0114] Taking the existing network architecture as an example, the security function module can be deployed in the existing communication node. For example, the security function module can be deployed on the terminal side, as shown in Figure 3. The first module can be integrated with the UE function, that is, the first module can be deployed inside the UE. For example, the first module can be deployed on the ME and communicate with the UICC function through transceiver communication, or it can be combined with the UICC. The first module can be deployed separately from the UE, that is, the first module can be deployed outside the UE as a functional entity. The security function can be deployed outside the access network device in the form of a functional entity, or it can be deployed inside the access network device in the form of a logical function. For example, when the access network device can include a CU node and a DU node, the first module or the second module can be deployed only on the CU, or it can be deployed on both the CU and the DU. The first module or the second module can be deployed on the core network device, or it can be deployed outside the core network device in the form of a functional entity. For example, the first module in Figure 3 is independently deployed on the bus in the form of a network function of the core network.

[0115] It should be noted that, depending on the needs of different communication nodes, security function modules deployed at different nodes can implement different security functions. The following uses the first security module as an example. This first security module can serve any communication node or third-party requesting node. Any communication node or third-party requesting node is described using the requesting party as an example.

[0116] It should be understood that the above deployment form is only an example. Whether on the network side, terminal side or application side, the security function module can form the basis of multi-party negotiation and trusted communication through unified external transmission and reception.

[0117] The following specific embodiments are used to describe the technical solution of the present application in detail. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described in detail in some embodiments.

[0118] Fig. 4 is a schematic diagram of a communication method 1100 applicable to the present application. The method 400 shown in Fig. 4 can be applicable to the systems or architectures shown in Figs. 1 to 3. The method 400 includes the following steps.

[0119] S420: The first security module generates a security policy based on the first information and the second information.

[0120] In the present application, the first security module performs security policy negotiation based on the first information and the second information to generate a security policy.

[0121] The first information includes the trust requirement statement of the first node and / or the global trust policy of the network; the second information includes the trust requirement statement of the second node and / or the global trust policy of the network.

[0122] It should be understood that the trust requirement statement of a communication node includes the communication node's requirement statement for trust capabilities.

[0123] It should be understood that the network global trust policy obtained by the communication node refers to another trusted function or security module generating a network global trust policy through AI-based full-network situational awareness, such as all communications between nodes must support post-quantum encryption / all nodes must be trusted before communication / all UEs must support blockchain light node capabilities, etc.

[0124] In this application, two different types of security function modules are provided, where the first security module and the second security module are of the first module type, and the other trusted function or security module is of the second module type. That is, the communication node obtains the network global trusted policy from the security module of the second module type.

[0125] Optionally, the first information may also include a trusted configuration obtained from the management terminal. Trusted configuration can be understood as the configuration of trusted functions by the operator, such as time-based or coverage configuration, event-triggered configuration, user-customized opening configuration, and disabling certain trusted capabilities. This embodiment of the present application is not limited to this.

[0126] In this application, a first security module is a security module serving a first node. For example, if the first node is a UE, the first security module is a security module deployed on the UE. A second security module is a security module serving a second node. For example, if the second node is an access network device, the second security module is a security module deployed on the access network device. The second security module and the first security module are security function modules deployed in different communication nodes in a communication system.

[0127] It should be understood that the first node and the second node may be any communication node or application in the communication system, for example, a terminal device, an access network device, a core network element, or a third-party application. This embodiment of the present application does not limit this.

[0128] In one possible implementation, the first security module inputs the first information and the second information into an AI model to intelligently generate a security policy.

[0129] In another possible implementation, the first security module integrates the first information and the second information based on an expert database and / or rules preset by the operator to generate a security policy.

[0130] In one possible implementation, the first information and the second information may be stored by the first security module. For example, the first information and the second information may have an expiration date. During the expiration date, the first security module may directly use the stored first information and the second information. If the expiration date expires, the first security module may obtain updated first information and obtain updated second information from the second security module.

[0131] In another possible implementation, the first information and the second information are acquired by the first security module and the second security module respectively.

[0132] Specifically, the first security module obtains the trust requirement statement from the first node and / or obtains the network global trust policy from the second module to which the first security module belongs, and may also obtain the trust configuration from the management end.

[0133] Specifically, the second security module obtains the trust requirement statement from the second node and / or obtains the network global trust policy from the second module to which the second security module belongs, and may also obtain the trust configuration from the management end.

[0134] The second module to which the first security module belongs can be understood as the first security module belonging to the first module type, and the second module can manage the first security module. For example, in the first module and second module deployed on the RAN side shown in FIG3 , when the first module here is the first security module, the first security module can obtain the network global trusted policy from the second module. The second module to which the second security module belongs is similar and is not further described here.

[0135] In this application, before S420, a security policy negotiation process may also be triggered.

[0136] In one implementation, the second security module may trigger the security policy negotiation process.

[0137] S410a: The second security module sends a first request message to the first security module, where the first request message includes second information.

[0138] The first request message is used to request security negotiation.

[0139] It should be understood that the second security module triggers the security policy negotiation process, which can be understood as the second node sending a security policy request message to the second security module, which includes the ID of the first node. If the second security module does not save the security policy corresponding to the first node ID, or the saved security policy corresponding to the first node ID has expired, then the second security module sends a first request message to the first security module of the first node according to the ID of the first node, requesting security policy negotiation to generate a security policy.

[0140] In another implementation, the first security module triggers the security policy negotiation process.

[0141] S410b: The first security module sends a second request message to the second security module, where the second request message is used to request security negotiation.

[0142] S410c: The second security module sends second information to the first security module.

[0143] It should be understood that the first security module triggers the security policy negotiation process, which can be understood as the first node sending a security policy request message to the first security module, which includes the ID of the second node. If the first security module does not save the security policy corresponding to the second node ID, or the saved security policy corresponding to the second node ID has expired, then the first security module sends a second request message to the second security module of the second node according to the ID of the second node, requesting security policy negotiation to generate a security policy.

[0144] S430: The first security module sends the security policy to the second security module.

[0145] In a possible implementation, when the second security module sends the first request message to the first security module, the first security module sends a first feedback message to the second security module, where the first feedback message includes a security policy.

[0146] In a possible implementation, when the first security module sends the second request message to the second security module, the first security module sends first notification information to the second security module, where the first notification information includes a security policy.

[0147] Correspondingly, the second security module saves the security policy for communication between the first node and the second node. The second security module sends a feedback message to the second node, indicating whether the security policy negotiation succeeds or fails.

[0148] The security policy specifies the specific security algorithms and security parameters to be invoked. For example, authentication between the first and second nodes uses the authentication and key agreement (AKA), trustworthy proof uses the trusted platform module (TPM), and encryption and decryption uses the Advanced Encryption Standard (AES) algorithm. After the security policy is generated, it is associated with the identity and stored in the first and second security modules. For example, the first security module stores the second node identity and the security policies of the first and second nodes, while the second security module stores the first node identity and the security policies of the first and second nodes.

[0149] After receiving the trusted service request message, the first security module locates the security policy previously negotiated with the second security module through the second node identity, and determines the specific security algorithm to be called and the security parameters to be used.

[0150] According to this technical solution, independent security functions are deployed to enable the communication nodes in the communication system to negotiate security policies based on communication needs, which is applicable to the security needs of more business scenarios and improves the security performance of communications.

[0151] Figure 5 is a schematic flow chart of a communication method applicable to the present application. The communication method shown in Figure 5 can be a specific implementation of Figure 4, and the method 500 includes the following steps.

[0152] In this embodiment, the security negotiation process between node #1 and node #2 is taken as an example for description.

[0153] TGF#1 is the security function module of node #1, and TGF#2 is the security function module of node #2. TGF#1 (an example of the first security module) and TGF#1 (an example of the second security module) belong to the first module type. TEF#1 is the security function module responsible for managing TGF#1, and TEF#2 is the security function module responsible for managing TGF#2. TEF#1 and TEF#2 belong to the second module type.

[0154] Node #1 (an example of a first node) and node #2 (an example of a second node) can be any communication node or application in the communication system, for example, a terminal device, an access network device, a core network element, or a third-party application. This embodiment of the present application is not limited to this.

[0155] The following steps S510 to S590 are a security negotiation process between node #1 and node #2.

[0156] S510, node #1 sends a request message #1 to TGF #1.

[0157] The request message #1 is used to request the security policy between node #1 and node #2 from TGF #1.

[0158] The request message #1 includes the ID of the node #2.

[0159] The request message #1 may be a security policy request message.

[0160] S510a, TGF#1 sends a request message #2 to TEF#1.

[0161] The request message #2 is used to request TEF #1 to generate a global network trust policy #1.

[0162] S510b, TEF#1 generates a network global trusted policy #1 and sends a response message #1 to TGF#1.

[0163] Response message #1 includes network global trust policy #1.

[0164] It should be understood that when TGF#1 has pre-stored the network global trust policy #1, steps S510a and S510b may not be performed.

[0165] S520, TGF#1 determines the first information.

[0166] The first information includes at least one of the security requirement statement of node #1 and the network global trust policy #1.

[0167] The first information may also include the trusted configuration obtained by TGF#1 from the management end.

[0168] It should be understood that TGF#1 may store the first information in advance, so the aforementioned steps S510-S520 may be optional steps.

[0169] It should be understood that TGF#1 may have saved the security policies of node#1 and node#2, so the saved security policy can be directly sent to node#2. When the saved security policy expires or no security policy is saved, the following steps are performed.

[0170] TGF#1 requests security policy negotiation from TGF#2. There are two requesting methods: method 1 is the following step S530a, and method 2 is the following step S530b.

[0171] S530a, TGF#1 sends a request message #3 to TGF#2, where the request message #3 includes the first information.

[0172] That is, when TGF#1 and TGF#2 support direct communication, request message #3 does not need to be forwarded by node #1, node #2, and other nodes.

[0173] S530b, TGF#1 sends a request message #3 to TGF#2 through node #1 and node #2, where the request message #3 includes the first information.

[0174] That is, TGF#1 and TGF#2 do not support direct communication, and the request message #3 needs to be forwarded by node #1, node #2, and other nodes.

[0175] S540, TGF#2 determines the second information.

[0176] The second information includes at least one of the security requirement statement of node #2 and the network global trust policy #2.

[0177] The second information may also include the trusted configuration obtained by TGF#2 from the management end.

[0178] S540a, TGF#2 sends a request message #4 to node #2.

[0179] The request message #4 is used to request node #2 for a trusted request of node #2.

[0180] S540b, node #2 generates trusted requirement #2 and sends response message #2 to TGF #2.

[0181] The response message #2 includes the trust requirement of node #2.

[0182] S540c, TGF#2 sends a request message #5 to TEF#2.

[0183] The request message #5 is used to request TEF #2 to generate a network global trusted policy #2.

[0184] S540d, TEF#2 generates a network global trusted policy #2 and sends a response message #3 to TGF#2.

[0185] Response message #3 includes network global trust policy #2.

[0186] It should be understood that when TGF#2 has pre-saved the network global trust policy #2 and security requirement #2, steps S540a-S540d may not be executed.

[0187] It should be understood that TGF#2 may store the second information in advance, so the aforementioned steps S510 - S540d may be optional steps.

[0188] S550, TGF#2 generates a security policy according to the first information and the second information.

[0189] In one possible implementation, TGF#2 inputs the first information and the second information into an AI model to intelligently generate a security policy.

[0190] In another possible implementation, TGF#2 integrates the first information and the second information to generate a security policy based on an expert database and / or rules preset by the operator.

[0191] It should be understood that TGF#2 saves the security policy after generating it.

[0192] Corresponding to the above two ways of TGF#1 requesting security policy negotiation from TGF#2, there are also two response ways. Way 1 is the following step S560a, and Way 2 is the following step S560b.

[0193] S560a, TGF#2 sends a response message #4 to TGF#1, where the response message #4 includes a security policy.

[0194] S560b, TGF#2 sends a response message #4 to TGF#1 through node #2 and node #1. The response message #4 includes the security policy.

[0195] S570, TGF#1 saves the security policy.

[0196] S580, TGF#1 sends the negotiation result to node#1.

[0197] The negotiation result includes an indication of whether TGF#1 obtains the security policy successfully or fails.

[0198] S590, TGF#2 sends the negotiation result to node#2.

[0199] The negotiation result includes an indication of whether TGF#2 obtains the security policy successfully or fails.

[0200] According to this technical solution, TGF#1 requests security policy negotiation from TGF#2 and sends the identity identification and security requirement related information of node #1 to TGF#2. TGF#2 generates a security policy based on the security requirement information of node #1 and the security requirement information of node #2, thereby enabling the security policy negotiation process of communication nodes based on communication requirements in the communication system, which is suitable for the security requirements of more business scenarios and improves the security performance of communication.

[0201] Figure 6 is a schematic flow chart of a communication method applicable to the present application. The communication method shown in Figure 6 may be a specific implementation of Figure 4, and the method 600 includes the following steps.

[0202] In this embodiment, the security negotiation process between node #1 and node #2 is taken as an example for description.

[0203] TGF#1 is the security function module of node #1, and TGF#2 is the security function module of node #2. TGF#1 (an example of the first security module) and TGF#1 (an example of the second security module) belong to the first module type. TEF#1 is the security function module responsible for managing TGF#1, and TEF#2 is the security function module responsible for managing TGF#2. TEF#1 and TEF#2 belong to the second module type.

[0204] Node #1 (an example of a first node) and node #2 (an example of a second node) can be any communication node or application in the communication system, for example, a terminal device, an access network device, a core network element, or a third-party application. This embodiment of the present application is not limited to this.

[0205] The following steps S610 to S690 are a security negotiation process between node #1 and node #2.

[0206] S610, node #1 sends a request message #1 to TGF #1.

[0207] The request message #1 is used to request the security policy between node #1 and node #2 from TGF #1.

[0208] The request message #1 includes the ID of the node #2.

[0209] The request message #1 may be a security policy request message.

[0210] It should be understood that TGF#1 may have saved the security policies of node#1 and node#2, so the saved security policy can be directly sent to node#2. When the saved security policy expires or no security policy is saved, the following steps are performed.

[0211] TGF#1 requests security policy negotiation from TGF#2. There are two requesting methods: method 1 is the following step S620a, and method 2 is the following step S630b.

[0212] S620a, TGF#1 sends a request message #2 to TGF#2, where the request message #2 is used to request second information from node #2.

[0213] That is, when TGF#1 and TGF#2 support direct communication, the request message #2 does not need to be forwarded by node #1, node #2, and other nodes.

[0214] The request message #2 may be a security policy negotiation request message.

[0215] S620b, TGF#1 sends a request message #2 to TGF#2 through node #1 and node #2, where the request message #2 is used to request the second information from node #2.

[0216] That is, TGF#1 and TGF#2 do not support direct communication, and the request message #2 needs to be forwarded by node #1, node #2, and other nodes.

[0217] S630, TGF#2 determines the second information.

[0218] The second information includes at least one of the security requirement statement of node #2 and the network global trust policy #2.

[0219] The second information may also include the trusted configuration obtained by TGF#2 from the management end.

[0220] S630a, TGF#2 sends a request message #3 to node #2.

[0221] The request message #3 is used to request node #2 for a trusted request of node #2.

[0222] S630b, node #2 generates trusted requirement #2 and sends response message #1 to TGF #2.

[0223] The response message #1 includes the trust requirement of node #2.

[0224] S630c, TGF#2 sends a request message #4 to TEF#2.

[0225] The request message #4 is used to request TEF #2 to generate a network global trusted policy #2.

[0226] S630d, TEF#2 generates a network global trusted policy #2 and sends a response message #2 to TGF#2.

[0227] Response message #2 includes network global trust policy #2.

[0228] It should be understood that when TGF#2 has pre-saved the network global trust policy #2 and security requirement #2, steps S630a-S630d may not be executed.

[0229] It should be understood that TGF#2 may store the second information in advance, so the aforementioned steps S610 - S630d may be optional steps.

[0230] Corresponding to the above two ways of STGF#1 requesting security policy negotiation from TGF#2, there are also two response ways. Way 1 is the following step S640a, and Way 2 is the following step S640b.

[0231] S640a, TGF#2 sends a response message #3 to TGF#1, where the response message #3 includes the second information.

[0232] S640b, TGF#2 sends a response message #3 to TGF#1 through node #2 and node #1, where the response message #3 includes the second information.

[0233] When TGF#1 does not have an available network global trusted policy #1, it needs to obtain the network global trusted policy #1 through the following steps S610a-S610b.

[0234] S610a, TGF#1 sends a request message #5 to TEF#1.

[0235] The request message #5 is used to request TEF #1 to generate a network global trusted policy #1.

[0236] S610b, TEF#1 generates a network global trusted policy #1 and sends a response message #4 to TGF#1.

[0237] Response message #4 includes network global trust policy #1.

[0238] It should be understood that when TGF#1 has pre-saved the network global trust policy #1, steps S610a and S610b may not be performed.

[0239] S650, TGF#1 determines the first information.

[0240] The first information includes at least one of the security requirement statement of node #1 and the network global trust policy #1.

[0241] The first information may also include the trusted configuration obtained by TGF#1 from the management end.

[0242] It should be understood that TGF#1 may store the first information in advance, so the aforementioned step S650 may be an optional step.

[0243] S660, TGF#1 generates a security policy based on the first information and the second information.

[0244] In one possible implementation, TGF#1 inputs the first information and the second information into an AI model to intelligently generate a security policy.

[0245] In another possible implementation, TGF#1 integrates the first information and the second information to generate a security policy based on an expert database and / or rules preset by an operator.

[0246] It should be understood that TGF#1 saves the security policy after generating it.

[0247] S670, TGF#1 sends the negotiation result to node#1, including an indication of success or failure of TGF#1 obtaining the security policy.

[0248] Corresponding to the above two methods of STGF#1 requesting security policy negotiation from TGF#2, the negotiation result notification method is also divided into the following steps S680a and S680b.

[0249] S680a, TGF#1 directly sends the negotiation result to TGF#2.

[0250] The negotiation result includes a security policy.

[0251] S680b, TGF#1 sends the negotiation result to TGF#2 through node#1 and node#2.

[0252] The negotiation result includes a security policy.

[0253] S690, TGF#2 saves the security policy.

[0254] According to this technical solution, TGF#1 requests security policy negotiation from TGF#2 and sends the identity of node #1 to TGF#2. TGF#2 sends the identity and security requirement information of node #2 to TGF#1. TGF#1 generates a security policy based on the security requirement information of node #1 and the security requirement information of node #2, thereby enabling the security policy negotiation process of communication nodes based on communication requirements in the communication system, which is suitable for the security requirements of more business scenarios and improves the security performance of communication.

[0255] In this application, the security policy negotiation process between two nodes is applicable to a variety of application scenarios. Figure 7 shows the triggering timing of the security policy negotiation process in different application scenarios.

[0256] It should be understood that in the embodiment of the present application, a node triggers a security policy negotiation request, which is triggered and negotiated by the security function module serving the node.

[0257] As shown in FIG7 (a), the UE and the access network device may perform a security policy negotiation process during the UE access process. There are four triggering methods for performing security policy negotiation during the access process.

[0258] In method 1, the UE sends an RRC setup request message to the access network device, along with a negotiation request message. That is, the UE proactively triggers the security policy negotiation process when requesting to establish a connection.

[0259] Method 2: The UE sends an RRC establishment request message to the access network device; the access network device sends an RRC establishment message to the UE; the UE sends an RRC establishment completion message to the access network device, and carries a negotiation request message, that is, the UE actively triggers the security policy negotiation process when the complete connection is established.

[0260] Method three: The UE sends an RRC establishment request message to the access network device; the access network device sends an RRC establishment message to the UE, and carries a negotiation request message, that is, the access network device actively triggers the security policy negotiation process when establishing a connection.

[0261] In mode 4, the UE sends an RRC establishment completion message to the access network device, and the access network device sends a negotiation request message to the UE. That is, the access network device actively triggers the security policy negotiation process when the complete connection is established.

[0262] After the negotiation process is triggered, the specific negotiation process refers to the method shown in Figure 5 or Figure 6 to obtain a security policy, and execute a specific trusted service based on the negotiated security policy.

[0263] The above four triggering scenarios of policy negotiation are only exemplary and not all triggering scenarios. For example, the UE sends a negotiation request message after sending an RRC establishment request message. This embodiment of the present application does not limit this.

[0264] As shown in FIG7( b ), the UE and the core network may perform a security policy negotiation process during the authentication process. There are two triggering methods for performing security policy negotiation during the authentication process.

[0265] Method 1: The UE sends a registration request message to the core network, and carries a negotiation request message.

[0266] In method 2, the UE sends a registration request message to the core network, and after receiving the registration request message, the core network sends a negotiation request message to the UE.

[0267] It should be understood that the security function module of the UE or the core network may periodically trigger a negotiation request after saving the security policy. For example, the security function module may set a timer to periodically trigger a negotiation request and update the security policy.

[0268] After the negotiation process is triggered, the specific negotiation process refers to the method shown in Figure 5 or Figure 6 to obtain a security policy, and execute a specific trusted service based on the negotiated security policy.

[0269] The triggering scenarios of the above two policy negotiations are only exemplary and not all triggering scenarios, and the embodiments of the present application are not limited to this.

[0270] As shown in Figure 7(c), when the access network equipment is divided into CU and DU, the CU and DU can perform a security policy negotiation process during the establishment of the transmission and reception. There are three triggering methods for performing security policy negotiation during the establishment of the transmission and reception.

[0271] Method 1: The DU sends a transmission and reception establishment request message to the CU, and carries a negotiation request message.

[0272] Method 2: After the CU sends a transmission and reception establishment response message to the DU, the DU sends a negotiation request message to the CU.

[0273] In mode three, the DU sends a transceiver setup request message to the CU, and the CU sends a transceiver setup response message to the DU carrying a negotiation request message.

[0274] Exemplarily, the above-mentioned transceiver may be F1 transceiver.

[0275] After the negotiation process is triggered, the specific negotiation process refers to the method shown in Figure 5 or Figure 6 to obtain a security policy, and execute a specific trusted service based on the negotiated security policy.

[0276] The above three triggering scenarios of policy negotiation are only exemplary and not all triggering scenarios, and the embodiments of the present application are not limited to them.

[0277] As shown in (d) of Figure 7, different access network devices can perform security policy negotiation during the establishment of a transmission and reception process. There are three triggering methods for performing security policy negotiation during the establishment of a transmission and reception process.

[0278] Method 1: Access network device #1 sends a transceiver setup request message to access network device #2, and carries a negotiation request message.

[0279] Method 2: After access network device #2 sends a transceiver establishment response message to access network device #1, access network device #1 sends a negotiation request message to access network device #2.

[0280] In mode three, access network device #1 sends a transceiver setup request message to access network device #2, and access network device #2 sends a transceiver setup response message to access network device #1 carrying a negotiation request message.

[0281] Exemplarily, the above-mentioned transceiver may be Xn transceiver.

[0282] After the negotiation process is triggered, the specific negotiation process refers to the method shown in Figure 5 or Figure 6 to obtain a security policy, and execute a specific trusted service based on the negotiated security policy.

[0283] The above three triggering scenarios of policy negotiation are only exemplary and not all triggering scenarios, and the embodiments of the present application are not limited to them.

[0284] As shown in (e) of Figure 7, the access network device and the core network device can perform a security policy negotiation process during the establishment of the transmission and reception. There are three triggering methods for performing security policy negotiation during the establishment of the transmission and reception.

[0285] Method 1: The access network device sends a transceiver establishment request message to the core network, and carries a negotiation request message.

[0286] Method 2: After the core network sends a transceiver establishment response message to the access network device, the access network device sends a negotiation request message to the core network.

[0287] In method three, the access network device sends a transceiver setup request message to the core network, and the core network sends a transceiver setup response message to the access network device, carrying a negotiation request message.

[0288] Exemplarily, the above-mentioned transceiver may be NG transceiver.

[0289] After the negotiation process is triggered, the specific negotiation process refers to the method shown in Figure 5 or Figure 6 to obtain a security policy, and execute a specific trusted service based on the negotiated security policy.

[0290] The above three triggering scenarios of policy negotiation are only exemplary and not all triggering scenarios, and the embodiments of the present application are not limited to them.

[0291] As shown in (f) of Figure 7, two functional network elements can perform a security policy negotiation process during the service request process. There are three triggering methods for performing security policy negotiation during the establishment of a transmission and reception process.

[0292] In the first method, NF#1 (serving as a service user) sends a service request message to NF#2 (serving as a service producer), and carries a negotiation request message.

[0293] In the second method, NF#1 (as a service user) sends a negotiation request message to NF#2 (as a service producer) and obtains a trusted policy. NF#1 then sends a service request message to NF#2.

[0294] In the third mode, NF#1 (as a service user) sends a service request message to NF#2 (as a service producer), and NF#2 sends a negotiation request message to NF#1.

[0295] After the negotiation process is triggered, the specific negotiation process refers to the method shown in Figure 5 or Figure 6 to obtain a security policy, and execute a specific trusted service based on the negotiated security policy.

[0296] The above three triggering scenarios of policy negotiation are only exemplary and not all triggering scenarios, and the embodiments of the present application are not limited to them.

[0297] In this application, communication nodes can perform security negotiation to obtain security policies through the security negotiation process provided in this embodiment. The above triggering scenarios are only exemplary and do not limit the implementation of the embodiments of this application.

[0298] In this application, when two communication nodes change, a new security negotiation process can also be triggered.

[0299] FIG8 shows a security negotiation process triggered when a communication node changes.

[0300] As shown in Figure 8(a), in the existing standard, the old AMF (AMF#2) and the new AMF (AMF#1) in the roaming scenario come from the same operator. In future networks, UEs may have cross-operator capabilities and access different operator networks. In this case, AMF#2 and AMF#1 come from different operator core networks. In both roaming scenarios, the old security policy #1 can be reused, or security policy #2 can be renegotiated.

[0301] FIG8( a ) shows three ways of determining security policies after a UE switches to different operators.

[0302] Method 1: The UE sends a Registration Request message to AMF#1, and AMF#1 sends a Policy Transfer Request message to AMF#2, that is, requesting the original Security Policy#1 from AMF#2. AMF#2 sends Security Policy#1 to AMF#1, and AMF#1 sends a Registration Response message to the UE carrying Security Policy#1.

[0303] Method 2: The UE sends a registration request message to AMF#1 and carries a negotiation request message. The UE sends a registration request message to AMF#1 and carries a negotiation request message to perform a security negotiation process and obtain security policy #2.

[0304] Method three: The UE sends a registration request message to AMF#1, and AMF#1 sends a negotiation request message to the UE to perform a security negotiation process and obtain security policy #2.

[0305] After the negotiation process is triggered, the specific negotiation process refers to the method shown in Figure 5 or Figure 6 to obtain security policy #2, and execute specific trusted services based on the negotiated security policy #2 or the original security policy #1.

[0306] The above three scenarios are only exemplary descriptions and are not all application scenarios. The embodiments of this application are not limited to them.

[0307] As shown in FIG8( b ), after the UE switches the access network device, it can reuse the old security policy #1 or renegotiate to obtain the security policy #2.

[0308] FIG8( b ) shows three ways of determining security policies after the UE switches to different access network devices.

[0309] Method 1: Access network device #1 (source access network device) sends a switching request message to access network device #2 (target access network device), and carries a policy transfer request message. Access network device #2 sends security policy #1 to access network device #1, and access network device #1 carries security policy #1 when sending RRC reconfiguration information to the UE.

[0310] Method 2: Access network device #1 (source access network device) sends a switching request message to access network device #2 (target access network device). Access network device #2 sends a switching request confirmation message to access network device #1, and carries a negotiation request message. Access network device #1 carries a negotiation request message when sending RRC reconfiguration information to the UE, and executes the security policy negotiation process to obtain security policy #2.

[0311] Method three: Access network device #1 (source access network device) sends a switching request message to access network device #2 (target access network device), access network device #2 sends a switching request confirmation message to access network device #1, access network device #1 sends RRC reconfiguration information to the UE, and the UE sends a negotiation request message to access network device #2. The negotiation request message can also be carried in the RRC reconfiguration message, and the security policy negotiation process is executed to obtain security policy #2.

[0312] The above three scenarios are only exemplary descriptions and are not all application scenarios. The embodiments of this application are not limited to them.

[0313] It should be noted that in this application, security policy generation is based on at least one input parameter from the node's trusted requirement declaration and the network's global trusted security policy, and may also include the management's trusted configuration. Changes in any of these three input parameters can trigger a new security policy negotiation process at the node.

[0314] In one possible implementation, using Node #1 and Node #2 in Figure 5 as an example, the trusted requirements of Node #1 may change. For example, a user may input a new trusted requirement through human-machine communication. Another example is the application scenario changing, and Node #1 may generate a new trusted requirement based on pre-set rules. Another example is the application scenario changing, and Node #1 may generate a new initial trusted requirement based on AI. Another example is the security capability configuration of TGF #1 changing, which in turn generates new trusted requirement parameters. After Node #1's trusted requirements are updated, TGF #1 updates the first information based on the new trusted requirements. In subsequent processes, the updated first information is used to generate a new security policy.

[0315] In one possible implementation, using Node #1 and Node #2 in Figure 5 as an example, the global network trust policy for Node #1 may change. For example, the situational awareness results of TEF #1 on Node #1 may change, resulting in a new global network trust policy. Another example might be a configuration change or a change in the application scenario, resulting in a new global network trust policy. After Node #1's global network trust policy is updated, TGF #1 updates the first information based on the new global network trust policy. Subsequent processes use the updated first information to generate a new security policy.

[0316] In one possible implementation, using Node #1 and Node #2 in Figure 5 as an example, the trusted configuration of Node #1 changes. For example, a carrier administrator changes security settings, or the OAM generates new management-side trusted configuration fields. After the trusted configuration of Node #1 is updated, TGF #1 updates the first information based on the new trusted configuration. In subsequent processes, the updated first information is used to generate a new security policy.

[0317] The above scenarios are only illustrative and not all application scenarios, and the embodiments of this application are not limited to them.

[0318] Figure 9 is a schematic block diagram of a communication device provided in an embodiment of the present application. The communication device 900 shown in Figure 9 includes a transceiver unit 910 and a processing unit 920. The transceiver unit 910 can communicate with the outside world, and the processing unit 920 is used to process data. The transceiver unit 910 can also be referred to as a communication transceiver or a communication unit.

[0319] Optionally, the transceiver unit 910 may include a sending unit and a receiving unit. The sending unit is configured to perform the sending operation in the above method embodiment. The receiving unit is configured to perform the receiving operation in the above method embodiment.

[0320] It should be noted that the communication device 900 may include a sending unit but not a receiving unit. Alternatively, the communication device 900 may include a receiving unit but not a sending unit. The specific implementation depends on whether the above solution executed by the communication device 900 includes a sending action and a receiving action.

[0321] Optionally, the communication device 900 may further include a storage unit, which may be used to store instructions and / or data, and the processing unit 920 may read the instructions and / or data in the storage unit.

[0322] In one design, the communication device 900 may be used to execute the actions performed by the first security module in the above method embodiment.

[0323] Optionally, the communication device 900 can perform the actions performed by the first security module in the above method embodiment. The first security module can be a security function unit, module, or device, or a chip or circuit in a security function unit, module, or device, or a logic module or software that can implement all or part of the functions of the security function unit, module, or device, and this application does not limit this.

[0324] Optionally, the communication device 900 may be a first security module, the transceiver unit 910 is configured to perform the receiving or sending operations of the first security module in the above method embodiment, and the processing unit 920 is configured to perform the operations processed by the first security module in the above method embodiment.

[0325] Optionally, the communication device 900 may be a device that includes a first security module. Alternatively, the communication device 900 may be a component configured within the first security module, such as a chip within the first security module. In this case, the transceiver unit 910 may be a transceiver circuit, a pin, etc. Specifically, the transceiver circuit may include an input circuit and an output circuit, and the processing unit 920 may include a processing circuit.

[0326] In one possible implementation, the processing unit 920 is used to: generate a security policy based on first information and second information, the first information includes the trust requirement statement of the first node and / or the network global trust policy of the first node, the second information includes the trust requirement statement of the second node and / or the network global trust policy of the second node, the first security module is a security module serving the first node, and the second security module is a security module serving the second node; the transceiver unit 910 is used to: send the security policy to the second security module, and the security policy is used for secure communication between the first node and the second node.

[0327] In a possible implementation, the transceiver unit 910 is further configured to receive the second information from the second security module.

[0328] In a possible implementation, the transceiver unit 910 is specifically configured to receive a first request message from the second security module, where the first request message is used to request the first security module to perform security negotiation, and the first request message includes the second information.

[0329] In a possible implementation, the transceiver unit 910 is specifically configured to send a second request message to the second security module, where the second request message is used to request the second security module to perform security negotiation.

[0330] In a possible implementation, the first information further includes a trusted configuration obtained from the management end, and the second information further includes a trusted configuration obtained from the management end.

[0331] Optionally, the communication device 900 can perform the actions performed by the requesting party in the above method embodiment. The requesting party can be a terminal device, a network device, or a security module (a second security module), or a chip or circuit in the terminal device, network device, or security module, or a logic module or software that can implement all or part of the functions of the terminal device, network device, or security module. This application does not limit this.

[0332] Optionally, the communication device 900 may be a requester, the transceiver unit 910 is configured to perform the receiving or sending operations of the requester in the above method embodiment, and the processing unit 920 is configured to perform the internal processing operations of the requester in the above method embodiment.

[0333] Alternatively, the communication device 900 may be a device including a requester. Alternatively, the communication device 900 may be a component configured in the requester, such as a chip in the requester. In this case, the transceiver unit 910 may be a transceiver circuit, a pin, etc. Specifically, the transceiver circuit may include an input circuit and an output circuit, and the processing unit 920 may include a processing circuit.

[0334] In one possible implementation, the transceiver unit 910 is used to: determine second information, the second information is used by the first security module to generate a security policy in combination with the first information, the first information includes the trust requirement statement of the first node and / or the network global trust policy of the first node, the second information includes the trust requirement statement of the second node and / or the network global trust policy of the second node, the first security module is a security module serving the first node, and the second security module is a security module serving the second node; the transceiver unit 910 is also used to: receive the security policy from the first security module, and the security policy is used for secure communication between the first node and the second node.

[0335] In a possible implementation, the transceiver unit 910 is further configured to send the second information to the first security module.

[0336] In a possible implementation, the transceiver unit 910 is specifically configured to send a first request message to the first security module, where the first request message is used to request the first security module to perform security negotiation, and the first request message includes the second information.

[0337] In a possible implementation, the transceiver unit 910 is specifically configured to receive a second request message from the first security module, where the second request message is used to request the second security module to perform security negotiation.

[0338] In a possible implementation, the first information further includes a trusted configuration obtained from the management end, and the second information further includes a trusted configuration obtained from the management end.

[0339] As shown in Figure 10, an embodiment of the present application further provides a communication device 1000. The communication device 1000 includes a processor 1010, which is coupled to a memory 1020. The memory 1020 is used to store computer programs or instructions and / or data. The processor 1010 is used to execute the computer programs or instructions and / or data stored in the memory 1020, so that the method in the above method embodiment is executed.

[0340] Optionally, the communication device 1000 includes one or more processors 1010.

[0341] Optionally, as shown in FIG10 , the communication device 1000 may further include a memory 1020 .

[0342] Optionally, the communication device 1000 may include one or more memories 1020 .

[0343] Optionally, the memory 1020 may be integrated with the processor 1010 or provided separately.

[0344] Optionally, as shown in Figure 10, the communication device 1000 may further include a transceiver 1030 and / or a communication transceiver, which is used to receive and / or send signals. For example, the processor 1010 is used to control the transceiver 1030 and / or the communication transceiver to receive and / or send signals.

[0345] Alternatively, the device implementing the receiving function in transceiver 1030 may be considered a receiving module, and the device implementing the transmitting function in transceiver 1030 may be considered a transmitting module. That is, transceiver 1030 includes a receiver and a transmitter. A transceiver may also be sometimes referred to as a transceiver, a transceiver module, or a transceiver circuit. A receiver may also be sometimes referred to as a receiver, a receiving module, or a receiving circuit. A transmitter may also be sometimes referred to as a transmitter, a transmitter, a transmitting module, or a transmitting circuit.

[0346] As a solution, the communication device 1000 is used to implement the operations performed by the first security module in the above method embodiment. For example, the processor 1010 is used to implement the operations performed by the first security module in the above method embodiment (e.g., the operation in S420), and the transceiver 1030 is used to implement the receiving or sending operations performed by the first security module in the above method embodiment (e.g., the operation in S430).

[0347] As another solution, the communication device 1000 is used to implement the operations performed by the second security module in the above method embodiment. For example, the transceiver 1030 is used to implement the receiving or sending operations (such as the operation in S430) performed by the second security module in the above method embodiment.

[0348] It should be noted that the above-mentioned method embodiments of the present application can be applied to a processor or implemented by a processor. The processor may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above-mentioned method embodiments can be completed by hardware integrated logic circuits in the processor or by software instructions. The above-mentioned processor may be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. The various methods, steps, and logic block diagrams disclosed in the embodiments of the present application can be implemented or executed. The general-purpose processor may be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of the present application can be directly implemented and executed by a hardware decoding processor, or by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium mature in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, etc. The storage medium is located in the memory, and the processor reads the information in the memory and completes the steps of the above method in combination with its hardware.

[0349] It is understood that the memory in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct RAM bus random access memory (DR RAM). It should be noted that the memory of the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.

[0350] It should be understood that the term "and / or" in this document simply describes a relationship between related objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A exists alone, A and B exist simultaneously, or B exists alone. Furthermore, the character " / " in this document generally indicates that the related objects are in an "or" relationship.

[0351] It should be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0352] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0353] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0354] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some transceivers, devices or units, which can be electrical, mechanical or other forms.

[0355] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0356] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0357] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0358] The above are only specific embodiments of the present application, but the scope of protection of this application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

Claims

1. A communication method, characterized in that: include: A first security module generates a security policy based on first information and second information, where the first information includes a trust requirement statement of a first node and / or a global trust policy of the network for the first node, and the second information includes a trust requirement statement of a second node and / or a global trust policy of the network for the second node. The first security module is a security module serving the first node, and the second security module is a security module serving the second node. The first security module sends the security policy to the second security module, where the security policy is used for secure communication between the first node and the second node.

2. The method according to claim 1, characterized in that The method further comprises: The first security module receives the second information from the second security module.

3. The method according to claim 2, characterized in that The first security module receiving the second information from the second security module includes: The first security module receives a first request message from the second security module, where the first request message is used to request the first security module to perform security negotiation, and the first request message includes the second information.

4. The method according to claim 1 or 2, characterized in that The method further comprises: The first security module sends a second request message to the second security module, where the second request message is used to request the second security module to perform security negotiation.

5. The method according to any one of claims 1 to 4, characterized in that The first information also includes a trusted configuration obtained from the management end, and the second information also includes a trusted configuration obtained from the management end.

6. A communication method, characterized in that: include: The second security module determines second information, where the second information is used by the first security module to generate a security policy in combination with the first information, the first information including a trust requirement statement of a first node and / or a global trust policy of the network for the first node, the second information including a trust requirement statement of a second node and / or a global trust policy of the network for the second node, the first security module is a security module serving the first node, and the second security module is a security module serving the second node; The second security module receives the security policy from the first security module, where the security policy is used for secure communication between the first node and the second node.

7. The method according to claim 6, characterized in that The method further comprises: The second security module sends the second information to the first security module.

8. The method according to claim 7, characterized in that The second security module sending the second information to the first security module includes: The second security module sends a first request message to the first security module, where the first request message is used to request the first security module to perform security negotiation, and the first request message includes the second information.

9. The method according to claim 6 or 7, characterized in that The method further comprises: The second security module receives a second request message from the first security module, where the second request message is used to request the second security module to perform security negotiation.

10. The method according to any one of claims 6 to 9, characterized in that The first information also includes a trusted configuration obtained from the management end, and the second information also includes a trusted configuration obtained from the management end.

11. The method according to any one of claims 7 to 10, characterized in that The second security module stores the security policy.

12. A communication device, characterized in that: include: a processing unit, configured to generate a security policy based on first information and second information, wherein the first information includes a trust requirement statement of a first node and / or a network-wide trust policy of the first node, the second information includes a trust requirement statement of a second node and / or a network-wide trust policy of the second node, the first security module is a security module serving the first node, and the second security module is a security module serving the second node; The transceiver unit is configured to send the security policy to the second security module, where the security policy is used for secure communication between the first node and the second node.

13. The communication device according to claim 12, wherein: The transceiver unit is further configured to receive the second information from the second security module.

14. The communication device according to claim 13, wherein: The transceiver unit is specifically configured to receive a first request message from the second security module, where the first request message is used to request the first security module to perform security negotiation, and the first request message includes the second information.

15. The communication device according to claim 12 or 13, characterized in that: The transceiver unit is specifically configured to send a second request message to the second security module, where the second request message is used to request the second security module to perform security negotiation.

16. The communication device according to any one of claims 12 to 15, characterized in that: The first information also includes a trusted configuration obtained from the management end, and the second information also includes a trusted configuration obtained from the management end.

17. A communication device, characterized in that: include: a processing unit, configured to determine second information, the second information being used by the first security module to generate a security policy in combination with the first information, the first information including a trust requirement statement of a first node and / or a global trust policy of the network for the first node, the second information including a trust requirement statement of a second node and / or a global trust policy of the network for the second node, the first security module being a security module serving the first node, and the second security module being a security module serving the second node; The transceiver unit is configured to receive the security policy from the first security module, where the security policy is used for secure communication between the first node and the second node.

18. The communication device according to claim 17, wherein: The transceiver unit is further configured to send the second information to the first security module.

19. The communication device according to claim 18, wherein: The transceiver unit is specifically configured to send a first request message to the first security module, where the first request message is used to request the first security module to perform security negotiation, and the first request message includes the second information.

20. The communication device according to claim 17 or 18, characterized in that The transceiver unit is specifically configured to receive a second request message from the first security module, where the second request message is used to request the second security module to perform security negotiation.

21. The communication device according to any one of claims 17 to 20, characterized in that: The first information also includes a trusted configuration obtained from the management end, and the second information also includes a trusted configuration obtained from the management end.

22. The communication device according to any one of claims 17 to 21, characterized in that: The processing unit is further configured to store the security policy.

23. A communication device, characterized in that: include: A processor, configured to execute a computer program stored in a memory, so that the communication device executes the communication method according to any one of claims 1 to 11.

24. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is run on a computer, the computer is caused to execute the communication method according to any one of claims 1 to 11.

25. A chip system, characterized in that: include: A processor, configured to call and run a computer program from a memory, so that a communication device equipped with the chip system executes the communication method according to any one of claims 1 to 11.