Secure communication method, device and communication system
By activating the integrity security protection of the session in the communication system, the DoS attack risk when the link between the terminal device and the core network is not connected, and secure data storage and communication guarantees are realized in the scenario of link disconnection.
Patent Information
- Application Number
- CN202410083047.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-19
- Publication Date
- 2025-07-22
AI Technical Summary
In a communication system, especially when the communication link between the terminal device and the base station and the communication link between the base station and the core network are not in a connected state at the same time, there is a risk of a denial of service (DoS) attack, which makes the network security unable to be guaranteed.
During the session establishment process of the terminal device, the network device determines whether to activate the integrity security protection of the session based on the first information, and sends the first integrity security protection indication information to the terminal device to indicate whether to activate the integrity security protection of the session, and maximizes the integrity security protection of the session, so that only the user plane data passing the integrity verification is stored when the communication link is disconnected.
It effectively alleviates the potential risk of denial of service DoS attacks, ensures network communication security, and ensures that only user-side data that has undergone integrity verification is stored in the scenario of link disconnection.
Smart Images

Figure CN120358501A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communications, and more particularly, to a secure communication method, apparatus, and communication system. Background Art
[0002] In a communication system, such as a fifth-generation (5G) communication system or a satellite communication system, a terminal device may communicate with a base station via a new radio (NR), and the base station may communicate with a core network via a terrestrial gateway station.
[0003] The uplink and downlink messages between the terminal device and the core network may be transmitted via the base station and the terrestrial gateway station. At certain moments, the communication link between the terminal device and the base station, and the communication link between the base station and the core network may not be in a connected state simultaneously. For example, when the communication link between the terminal device and the base station is in a connected state and the communication link between the base station and the core network is in a disconnected state, the base station may perform a store and forward operation to store the uplink message from the terminal device, and after the communication link between the base station and the core network is restored, send the stored uplink message to the core network. In this case, if an attacker sends a large amount of malicious data or messages to the base station, it may lead to the inability to guarantee network security, and there is also a risk of the base station being subject to a denial of service (DoS) attack. Therefore, it is urgent to take additional measures to deal with this to reduce potential security risks. Summary of the Invention
[0004] This application provides a secure communication method, apparatus, and communication system, which can reduce potential security risks and improve network communication security.
[0005] In a first aspect, a secure communication method is provided. This method is applied on the network device side. For example, this method may be executed by a network device, or may be executed by a chip or circuit in the network device, or may be executed by a functional module in the network device that can call and execute a program, or may be executed by a centralized unit (CU) or a distributed unit (DU) in the network device, etc. This application does not make any limitations in this regard. For ease of description, the following will take the execution by a network device (such as a base station) as an example for illustration.
[0006] The method includes: during the session establishment process of a terminal device, a network device determines whether to activate the integrity security protection of the session according to first information, where the first information is used to indicate whether the network device supports the store-and-forward operation, and the session is used to transmit data between the terminal device and the core network; the network device sends first integrity security protection indication information to the terminal device, and the first integrity security protection indication information is used to indicate the activation result.
[0007] Exemplarily, the activation result is used to indicate whether to activate the integrity security protection of the session, or in other words, the activation result is used to indicate whether to activate the integrity security protection of one or more data radio bearers (DRBs) corresponding to the session. For example, the activation result includes activating the integrity security protection of the session, or not activating the integrity security protection of the session.
[0008] Exemplarily, the first information can also be used to indicate whether the network device is configured to enable the store-and-forward operation, and / or the first information can also be used to indicate whether the network device is deployed on a satellite.
[0009] It should be understood that the network device being deployed on a satellite can be understood as the network device (such as a base station) being physically deployed on the satellite, or the network device (such as a base station) and the satellite being co-located. At this time, the satellite has the capabilities of the network device, for example, the satellite supports the store-and-forward operation of the network device.
[0010] According to the solution provided in this application, considering the first information, the integrity security protection of the session is maximally enabled or activated, so that the data subsequently received by the network device is as much as possible protected by integrity security, which facilitates the scenario where the communication link (such as a feeder link) between the network device and the core network is disconnected. The network device only stores the user plane data that passes the integrity check, alleviating the potential risk of a denial-of-service (DoS) attack and at the same time ensuring network communication security.
[0011] In some implementation manners, the network device determines whether to activate the integrity security protection of the session according to the first information, including: when the first information indicates that the network device supports the store-and-forward operation, the network device determines to activate the integrity security protection of the session; and / or when the first information indicates that the network device does not support the store-and-forward operation, the network device determines not to activate the integrity security protection of the session.
[0012] That is to say, when the network device supports the store-and-forward operation, the network device activates the integrity security protection of the session; when the network device does not support the store-and-forward operation, the network device does not activate the integrity security protection of the session, or can activate or not activate the integrity security protection of the session according to the user plane integrity security policy.
[0013] In some implementations, before the network device determines whether to activate the integrity security protection for a session based on the first information, it includes: the network device obtains the user plane integrity security policy corresponding to the session, and the user plane integrity security policy is used to indicate whether to activate the integrity security protection for the session; the network device determines whether to activate the integrity security protection for the session based on the first information, including: the network device determines whether to activate the integrity security protection for the session based on the first information and the user plane integrity security policy.
[0014] Based on the above solution, when the network device determines whether to activate the integrity security protection for a session based on the first information, additionally, the user plane integrity security policy can be considered to activate or enable the integrity security protection for the session as much as possible, so that the user plane data received by the network device undergoes integrity security protection to the greatest extent. In the scenario where the feeder link is disconnected, only the user plane data that passes the integrity check is stored, which not only mitigates the potential risk of a denial-of-service (DoS) attack, but also ensures network communication security.
[0015] In some implementations, the network device determines whether to activate the integrity security protection for a session based on the first information and the user plane integrity security policy, including: when the first information indicates that the network device does not support the store-and-forward operation and the user plane integrity security policy indicates that the session activates or optionally activates the integrity security protection, the network device determines to activate the integrity security protection for the session; and / or, when the first information indicates that the network device does not support the store-and-forward operation and the user plane integrity security policy indicates that the session does not activate the integrity security protection, the network device determines not to activate the integrity security protection for the session.
[0016] Based on the above solution, when the network device does not support the store-and-forward operation, the network device determines whether to activate the integrity security protection for a session. It can be based on the user plane integrity security policy, or it can also be based on whether the network device supports the store-and-forward operation, to activate or enable the integrity security protection for the session to the greatest extent, so that the user plane data received by the network device undergoes integrity security protection to the greatest extent. In the scenario where the feeder link is disconnected, only the user plane data that passes the integrity check is stored, which not only mitigates the potential risk of a denial-of-service (DoS) attack, but also ensures network communication security.
[0017] In some implementations, a network device determines whether to activate integrity security protection for a session based on first information and a user plane integrity security policy, including: when the first information indicates that the network device supports store-and-forward operations and the user plane integrity security policy indicates that the session activates or optionally activates integrity security protection, the network device determines to activate integrity security protection for the session; and / or when the first information indicates that the network device supports store-and-forward operations and the user plane integrity security policy indicates that the session does not activate integrity security protection, the network device determines to activate integrity security protection for the session.
[0018] Based on the above solution, when the network device supports store-and-forward operations, regardless of whether the user plane integrity security policy indicates that the session activates or optionally activates or does not activate integrity security protection, the network device determines to activate integrity security protection for the session. That is, the network device determines whether to activate integrity security protection for the session based on the first information, maximally enabling or activating the integrity security protection for the session, so that the user plane data received by the network device passes through integrity security protection to the greatest extent. This facilitates storing only the user plane data that passes integrity verification in the scenario where the feeder link is disconnected, not only mitigating the potential risk of a denial-of-service (DoS) attack but also ensuring network communication security.
[0019] In a second aspect, a secure communication method is provided. This method is applied to the terminal device side. For example, this method can be executed by the terminal device, or it can be executed by a chip or circuit in the terminal device, or it can be executed by a functional module in the terminal device that can call and execute a program. This application does not limit this. For ease of description, the following takes the execution by the terminal device (such as a user equipment (UE)) as an example for illustration.
[0020] The method includes: during the session establishment process of the terminal device, the terminal device receives first integrity security protection indication information from the network device. The first integrity security protection indication information is used to indicate whether to activate integrity security protection for the session. The first integrity security protection indication information is determined based on first information, and the first information is used to indicate whether the network device supports store-and-forward operations; the terminal device performs integrity verification on the first integrity security protection indication information. The session is used to transmit data between the terminal device and the core network; when the integrity verification passes, the terminal device determines whether to activate integrity security protection for the session based on the first integrity security protection indication information.
[0021] Optionally, before the terminal device determines whether to activate the integrity security protection of the session according to the first integrity security protection indication information, the method further includes: the terminal device performs integrity verification on the first integrity security protection indication information. Further, in the case where the integrity verification is passed, the terminal device determines whether to activate the integrity security protection of the session according to the first integrity security protection indication information.
[0022] Optionally, the first integrity security protection indication information is used to indicate whether to activate the integrity security protection of the session. It can be understood that: the first integrity security protection indication information is used to indicate the activation result, and the activation result is used to indicate whether to activate the integrity security protection of the session.
[0023] In some implementation manners, in the case where the first information indicates that the network device supports the store-and-forward operation, the first integrity security protection indication information is used to indicate activating the integrity security protection of the session; and / or, in the case where the first information indicates that the network device does not support the store-and-forward operation, the first integrity security protection indication information is used to indicate not activating the integrity security protection of the session.
[0024] In some implementation manners, the first integrity security protection indication information is determined according to the first information and the user plane integrity security policy, where the user plane integrity security policy is used to indicate whether to activate the integrity security protection of the session.
[0025] In some implementation manners, in the case where the first information indicates that the network device does not support the store-and-forward operation, and the user plane integrity security policy indicates that the session activates or optionally activates the integrity security protection, the first integrity security protection indication information is used to indicate activating the integrity security protection of the session; and / or, in the case where the first information indicates that the network device does not support the store-and-forward operation, and the user plane integrity security policy indicates that the session does not activate the integrity security protection, the first integrity security protection indication information is used to indicate not activating the integrity security protection of the session.
[0026] In some implementation manners, in the case where the first information indicates that the network device supports the store-and-forward operation, and the user plane integrity security policy indicates that the session activates or optionally activates the integrity security protection, the first integrity security protection indication information is used to indicate activating the integrity security protection of the session; and / or, in the case where the first information indicates that the network device supports the store-and-forward operation, and the user plane integrity security policy indicates that the session does not activate the integrity security protection, the first integrity security protection indication information is used to indicate activating the integrity security protection of the session.
[0027] The beneficial effects of the second aspect and some implementation manners above can be correspondingly referred to the description related to the first aspect, and will not be elaborated here.
[0028] In a third aspect, a secure communication method is provided. This method is applied to the network device side. For example, this method can be executed by the network device, or can be executed by a chip or circuit in the network device, etc., or can be executed by a functional module in the network device that can call and execute a program, etc., or can be executed by a CU or DU in the network device, etc. This application does not make any limitations in this regard. For ease of description, the following takes the execution by a network device (such as a base station) as an example for illustration.
[0029] The method includes: during the session establishment process of the terminal device, the network device obtains a user plane integrity security policy corresponding to the session, where the user plane integrity security policy is used to indicate whether integrity security protection is activated for the session, and the session is used to transmit data between the terminal device and the core network; the network device determines first integrity security protection indication information according to the user plane integrity security policy, where the first integrity security protection indication information is used to indicate whether to activate the integrity security protection of the first DRB, the session corresponds to the first DRB, and the first DRB is used to carry data between the terminal device and the network device; activate or deactivate the integrity security protection of the first DRB according to the first integrity security protection indication information; in the case where the first link is disconnected, the network device determines whether to release the first DRB according to whether the integrity security protection of the first DRB is activated, or the network device determines whether to modify the integrity security protection state of the first DRB according to whether the integrity security protection of the first DRB is activated, and the first link is the link between the network device and the core network; the network device sends a first message to the terminal device, and the first message is used to indicate the release result or modification result of the first DRB.
[0030] Exemplarily, in a satellite communication scenario, the first link may be a feeder link.
[0031] Optionally, in the case where the first link is disconnected, the network device may also determine whether to release the first DRB according to the first integrity security protection indication information, or the network device determines whether to modify the integrity security protection state of the first DRB according to the first integrity security protection indication information.
[0032] According to the solution provided by this application, the network device determines whether to release the first DRB or modify the integrity security protection state of the first DRB to the active state based on the user plane integrity security policy, so that the user plane data received by the network device subsequently is all protected by integrity security. It is convenient for the satellite base station to only store the user plane data that passes the integrity check in the scenario where the feeder link is disconnected, which can alleviate the potential DoS risk and ensure network communication security.
[0033] In some implementations, the network device determines whether to release the first DRB based on whether the integrity security protection of the first DRB is activated, including: when the integrity security protection of the first DRB is not activated, the network device determines to release the first DRB.
[0034] In some implementations, the network device determines whether to modify the integrity security protection status of the first DRB based on whether the integrity security protection of the first DRB is activated, including: when the integrity security protection of the first DRB is not activated, the network device determines to modify the integrity security protection status of the first DRB to the activated state.
[0035] In some implementations, the method further includes: when the first link resumes connection, the network device sends a second message to the terminal device, where the second message is used to instruct the terminal device to establish a second DRB, the second message includes second integrity security protection indication information, and the second integrity security protection indication information is used to indicate that the second DRB does not activate integrity security protection, and the second DRB is used to carry data between the terminal device and the network device.
[0036] In some implementations, the second DRB is the first DRB. Before sending the second message to the terminal device, and / or after sending the first message to the terminal device, the method further includes: the network device stores the identifier of the first DRB; and / or the network device records that the integrity security protection status of the first DRB before modification is the non-activated state; where the second message includes the identifier of the first DRB, and / or the second integrity security protection indication information carried in the second message is determined based on the integrity security protection status of the first DRB before modification being the non-activated state.
[0037] Optionally, the second DRB may be a DRB re-established between the terminal device and the network device, or may be the first DRB determined based on the identifier of the first DRB. In addition, this application does not limit the timing of storing the identifier of the first DRB; and / or the network device records that the integrity security protection status of the first DRB before modification is the non-activated state. This implementation is for facilitating subsequent normal communication between the terminal device and the network device.
[0038] That is to say, the network device may determine not to activate or turn on the integrity security protection of the second DRB based on the recorded integrity security protection status of the first DRB before modification being the non-activated state. Optionally, the network device may also determine not to activate or turn on the integrity security protection of the second DRB according to the user plane integrity security policy of the session. This application does not make a limitation on this.
[0039] Based on this implementation manner, after releasing the first DRB or modifying the integrity security protection status of the first DRB to the active state, by recording the identifier of the first DRB, and / or recording that the integrity security protection status of the first DRB before modification is the inactive state, it is convenient to re - establish the first DRB (i.e., an example of the second DRB) based on the recorded identifier of the first DRB after the subsequent restoration of the first link.
[0040] In some implementation manners, the method further includes: the network device receives first data from the terminal device through the first DRB; when the first integrity security protection indication information indicates to activate the integrity security protection of the first DRB, the network device performs integrity verification on the first data; in the case where the integrity verification passes and the first link is disconnected, the network device stores the first data; or, in the case where the integrity verification fails, the network device does not store the first data, or the network device discards the first data.
[0041] In some implementation manners, before storing the first data, the method further includes: in the case where the integrity verification passes, determining whether the first link is disconnected.
[0042] In some implementation manners, before performing integrity verification on the first data, the method further includes: determining whether the first link is disconnected.
[0043] That is to say, this application does not limit the execution order of determining whether the first link is disconnected and determining whether it is necessary to perform integrity verification on the first data. Exemplarily, the network device can determine whether the first link is disconnected by determining whether the communication between the network device and the core network is normal. For example, the network device flies to the side away from the ground gateway station, such that the ground gateway station cannot receive the signal transmitted by the network device; or, the communication condition between the network device and the core network deteriorates, such as encountering bad weather, or the signal quality is lower than a certain threshold, etc.
[0044] In some implementation manners, the method further includes: the network device receives first data from the terminal device through the first DRB; when the first integrity security protection indication information indicates that the first DRB does not activate integrity security protection and the first link is disconnected, the network device does not perform integrity verification on the first data, or the network device discards the first data.
[0045] The beneficial effects of the above - mentioned third aspect and some implementation manners can be correspondingly referred to the description related to the first aspect, and will not be elaborated here.
[0046] Fourthly, a secure communication method is provided. This method is applied to the terminal device side. For example, this method can be executed by the terminal device, or can be executed by a chip or circuit in the terminal device, etc., or can be executed by a functional module in the terminal device that can call and execute programs, etc. This application does not limit this. For ease of description, the following takes the execution by the terminal device (such as UE) as an example for illustration.
[0047] This method includes: when the first link is disconnected, the terminal device receives a first message from the network device, where the first message is used to indicate the release result or modification result of the first DRB. The release result is used to indicate whether to activate the first DRB, and the modification result is used to indicate whether to modify the integrity security protection status of the first DRB. The release result or modification result is determined according to whether the integrity security protection of the first DRB is activated. The first DRB is used to carry data between the terminal device and the network device, and the first link is the link between the network device and the core network; the terminal device determines whether to release the first DRB according to the release result, or the terminal device determines whether to modify the integrity security protection status of the first DRB according to the modification result.
[0048] Exemplarily, whether the integrity security protection of the first DRB is activated is determined according to the user plane integrity security policy.
[0049] Optionally, before the terminal device determines whether to release the first DRB according to the release result, or the terminal device determines whether to modify the integrity security protection status of the first DRB according to the modification result, this method further includes: the terminal device performs an integrity check on the first message. Further, when the integrity check passes, the terminal device determines whether to release the first DRB according to the release result, or the terminal device determines whether to modify the integrity security protection status of the first DRB according to the modification result.
[0050] In some implementation manners, when the first integrity security protection indication information indicates that the first DRB does not activate integrity security protection, the release result indicates to release the first DRB.
[0051] In some implementation manners, when the first integrity security protection indication information indicates that the first DRB does not activate integrity security protection, the modification result indicates to modify the integrity security protection status of the first DRB to the active state.
[0052] In some implementations, the method further includes: when the first link resumes connection, the terminal device receives a second message from the network device, where the second message is used to indicate the establishment of a second DRB. The second message includes second integrity security protection indication information, which is used to indicate that the second DRB deactivates integrity security protection. The second DRB is used to carry data between the terminal device and the network device, and the first link is the link between the network device and the core network.
[0053] The beneficial effects of the fourth aspect and some implementations above can be correspondingly referred to the description related to the first aspect, and will not be elaborated here.
[0054] In a fifth aspect, a secure communication method is provided. This method can be executed by a session management network element, or can be executed by a chip or circuit in the session management network element, or can be executed by a functional module in the session management network element that can call and execute a program, etc. This application does not make a limitation in this regard. For ease of description, the following takes the execution by the session management network element as an example for illustration.
[0055] The method includes: during the session establishment process of the terminal device, the session management network element obtains indication information, where the indication information is used to indicate that the network device is deployed on a satellite; the session management network element determines a user plane integrity security policy corresponding to the session according to the indication information, and the user plane integrity security policy is used to indicate that the session activates or optionally activates integrity security protection; the session management network element sends the user plane integrity security policy to the network device.
[0056] In some implementations, the indication information is further used to indicate that the network device supports store-and-forward operations.
[0057] In some implementations, the method further includes: the session management network element obtains subscription information, where the subscription information is used to indicate whether the terminal device subscribes to the store-and-forward operation service; the session management network element determines the user plane integrity security policy according to the indication information, including: the session management network element determines the user plane integrity security policy according to the indication information and the subscription information.
[0058] Optionally, the session management network element determines the user plane integrity security policy according to the subscription information.
[0059] In some implementations, the session management network element determines the user plane integrity security policy according to the indication information and the subscription information, including: when the subscription information indicates that the terminal device subscribes to the store-and-forward operation service, the session management network element determines that the integrity security policy is used to indicate that the session activates integrity security protection.
[0060] The beneficial effects of the fifth aspect and some implementations above can be correspondingly referred to the description related to the first aspect, and will not be elaborated here.
[0061] In a sixth aspect, a communication device, such as a network device, is provided. The communication device includes: a processing unit configured to determine whether to activate integrity security protection for a session according to first information during a session establishment process of a terminal device, where the first information is used to indicate whether the network device supports a store-and-forward operation; and a transceiver unit configured to send first integrity security protection indication information to the terminal device, where the first integrity security protection indication information is used to indicate an activation result.
[0062] The transceiver unit may perform the receiving and sending processes in the foregoing first aspect, and the processing unit may perform other processes in the foregoing first aspect except for receiving and sending.
[0063] In a seventh aspect, a communication device, such as a terminal device, is provided. The communication device includes: a transceiver unit configured to receive, during a session establishment process of the terminal device, first integrity security protection indication information from a network device, where the first integrity security protection indication information is used to indicate whether to activate integrity security protection for a session, the first integrity security protection indication information is determined according to first information, and the first information is used to indicate whether the network device supports a store-and-forward operation; a processing unit configured to perform an integrity check on the first integrity security protection indication information; and a processing unit further configured to determine whether to activate integrity security protection for the session according to the first integrity security protection indication information when the integrity check passes.
[0064] The transceiver unit may perform the receiving and sending processes in the foregoing second aspect, and the processing unit may perform other processes in the foregoing second aspect except for receiving and sending.
[0065] In an eighth aspect, a communication device, such as a network device, is provided. The communication device includes: a transceiver unit configured to obtain a user plane integrity security policy corresponding to a session during a session establishment process of a terminal device, where the user plane integrity security policy is used to indicate whether to activate integrity security protection for the session; a processing unit configured to determine first integrity security protection indication information according to the user plane integrity security policy, where the first integrity security protection indication information is used to indicate whether to activate integrity security protection for a first data radio bearer (DRB) corresponding to the session; a processing unit further configured to determine whether to release the first DRB according to whether integrity security protection for the first DRB is activated, or determine whether to modify the integrity security protection state of the first DRB according to whether integrity security protection for the first DRB is activated when a first link is disconnected, where the first link is a link between the network device and the core network; and a transceiver unit further configured to send a first message to the terminal device, where the first message is used to indicate a release result or a modification result of the first DRB.
[0066] The transceiver unit can perform the reception and transmission processes in the foregoing third aspect, and the processing unit can perform other processes in the foregoing third aspect except for reception and transmission.
[0067] In a ninth aspect, a communication device, such as a terminal device, is provided. The communication device includes: a transceiver unit, configured to receive, when a first link is disconnected, a first message from a network device, where the first message is used to indicate a release result or a modification result of a first DRB, the first DRB is used to carry data between the terminal device and the network device, the release result is used to indicate whether to activate the first DRB, the modification result is used to indicate whether to modify the integrity security protection status of the first DRB, and the release result or the modification result is determined according to whether the integrity security protection of the first DRB is activated; a processing unit, configured to perform an integrity check on the first message; and the processing unit is further configured to, when the integrity check passes, determine whether to release the first DRB according to the release result, or determine whether to modify the integrity security protection status of the first DRB according to the modification result.
[0068] Exemplarily, whether the integrity security protection of the first DRB is activated is determined according to a user plane integrity security policy.
[0069] The transceiver unit can perform the reception and transmission processes in the foregoing fourth aspect, and the processing unit can perform other processes in the foregoing fourth aspect except for reception and transmission.
[0070] In a tenth aspect, a communication device, such as a session management network element, is provided. The communication device includes: a transceiver unit, configured to receive, during a session establishment process of a terminal device, indication information, where the indication information is used to indicate that the network device is deployed on a satellite; a processing unit, configured to determine a user plane integrity security policy according to the indication information, where the user plane integrity security policy is used to indicate session activation or optional activation of integrity security protection; and the transceiver unit is further configured to send the user plane integrity security policy to the network device.
[0071] The transceiver unit can perform the reception and transmission processes in the foregoing fifth aspect, and the processing unit can perform other processes in the foregoing fifth aspect except for reception and transmission.
[0072] In an eleventh aspect, a communication device is provided. The communication device includes a transceiver, a processor, and a memory. The processor is configured to control the transceiver to transmit and receive signals. The memory is configured to store a computer program. The processor is configured to call and run the computer program from the memory, so that the communication device executes the method in any one of the possible implementation manners of the foregoing first aspect to the fifth aspect.
[0073] Optionally, the processor is one or more, and the memory is one or more.
[0074] Optionally, the memory may be integrated with the processor or may be separately provided from the processor.
[0075] Optionally, the communication device further includes a transmitter and a receiver.
[0076] In a twelfth aspect, a communication system is provided. The communication system includes a network device and a session management network element. Among them, the network device is configured to execute the method in the first aspect or the third aspect and any one of the possible implementation manners thereof above, and the session management network element is configured to execute the method in any one of the possible implementation manners in the fifth aspect above.
[0077] Optionally, the communication system further includes a terminal device. Among them, the terminal device is configured to execute the method in the second aspect or the fourth aspect and any one of the possible implementation manners thereof above.
[0078] In a thirteenth aspect, a computer-readable storage medium is provided. The computer-readable storage medium stores computer program code instructions. When the computer program code or instructions are run, the method in any one of the possible implementation manners from the first aspect to the fifth aspect above is executed.
[0079] In a fourteenth aspect, a chip is provided. The chip includes at least one processor. The at least one processor is coupled to a memory. The memory is configured to store a computer program. The processor is configured to call and run the computer program from the memory, so that a communication device equipped with the chip system executes the method in any one of the possible implementation manners from the first aspect to the fifth aspect above.
[0080] Among them, the chip may include an input circuit or interface for sending information or data, and an output circuit or interface for receiving information or data.
[0081] In a fifteenth aspect, a computer program product is provided. The computer program product includes: computer program code. When the computer program code runs, the method in any one of the possible implementation manners from the first aspect to the fifth aspect above is executed.
[0082] In a sixteenth aspect, a computer program is provided. When the computer program is run, the method in any one of the possible implementation manners from the first aspect to the fifth aspect above is executed.
[0083] Among them, for the technical effects of the technical solutions in the sixth aspect to the sixteenth aspect, reference may be made to the description of the corresponding technical effects in the first aspect to the fifth aspect, and details are not described herein again. BRIEF DESCRIPTION OF THE DRAWINGS
[0084] Figure 1 is a schematic diagram of a communication system applicable to an embodiment of the present application;
[0085] Figure 2 is a schematic diagram of another communication system applicable to the embodiments of the present application;
[0086] Figure 3 is a schematic flowchart of a session establishment method for a terminal device;
[0087] Figure 4 is a schematic flowchart of a communication method provided by the embodiments of the present application;
[0088] Figure 5 is a schematic flowchart of another communication method provided by the embodiments of the present application;
[0089] Figure 6 is a schematic flowchart of yet another communication method provided by the embodiments of the present application;
[0090] Figure 7 is a schematic flowchart of yet another communication method provided by the embodiments of the present application;
[0091] Figure 8 is a schematic flowchart of yet another communication method provided by the embodiments of the present application;
[0092] Figure 9 is a schematic flowchart of yet another communication method provided by the embodiments of the present application;
[0093] Figure 10 is a schematic block diagram of a communication device provided by the embodiments of the present application;
[0094] Figure 11 is a schematic block diagram of another communication device provided by the embodiments of the present application. Detailed implementation manners
[0095] Next, the technical solutions in the present application will be described with reference to the accompanying drawings.
[0096] The technical solutions of the present application can be applied to non-terrestrial network (NTN) systems such as satellite communication systems and high altitude platform (HAPS) communications. For example, integrated communication and navigation (ICaN) systems, global navigation satellite systems (GNSS), etc.
[0097] Satellite communication systems can be integrated with traditional mobile communication systems. Among them, the mobile communication system can be a 5G or NR system, a Long Term Evolution (LTE) system, an LTE Frequency Division Duplex (FDD) system, an LTE Time Division Duplex (TDD) system, a Universal Mobile Telecommunication System (UMTS), etc. The technical solution provided in this application can also be applied to future communication systems, such as the 6th Generation (6G) mobile communication system. The technical solution provided in this application can also be applied to Device-to-Device (D2D) communication, Vehicle-to-Everything (V2X) communication, Machine-to-Machine (M2M) communication, Machine Type Communication (MTC), Internet of Things (IoT) communication systems, Non-Terrestrial Network (NTN) communication systems, or other communication systems.
[0098] Figure 1 is a schematic diagram of a communication system applicable to the embodiments of this application. As Figure 1 shown, the architecture 100 may include a terminal device 110, a network device 120, a Core Network (CN) 130, an external network 140, etc.
[0099] (1) The terminal device 110 may be referred to as a user equipment UE. The terminal device 110 in this application is a device with wireless transceiver functions and can communicate with one or more CNs 130 via a network device 120. The terminal device 110 may also be referred to as an access terminal, terminal, user unit, user station, mobile station, mobile device, remote station, remote terminal, mobile device, user terminal, user agent, or user device, etc. The terminal device 110 may be deployed on land, including indoor or outdoor, handheld or vehicle-mounted; it may also be deployed on water (such as a ship, etc.); it may also be deployed in the air (such as an airplane, balloon, satellite, etc.). The terminal device 110 may be a cellular phone, cordless phone, session initiation protocol (SIP) phone, smart phone, mobile phone, wireless local loop (WLL) station, personal digital assistant (PDA), etc. Alternatively, the terminal device 110 may also be a handheld device with wireless communication functions, a computing device, or other devices connected to a wireless modem, a vehicle-mounted device, a wearable device, an unmanned aerial vehicle (UAV) / uncrewed aerial vehicle device, or a terminal in the Internet of Things (IoT), vehicle-to-everything (V2X) network, any form of terminal in a 5G network and future networks, a relay user equipment, or a terminal in an evolved future 6G network, etc. Among them, the relay user equipment may be, for example, a 5G residential gateway (RG). For example, the terminal device 110 may be a virtual reality (VR) terminal, an augmented reality (AR) terminal, a wireless terminal in industrial control, a wireless terminal in unmanned driving, a wireless terminal in remote medical treatment, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, a wireless terminal in a smart home, etc. Alternatively, the terminal device 110 may also be a logical entity, a smart device (such as a mobile phone), a smart terminal, etc., or a communication device such as a server, gateway, base station, controller, or an IoT device such as an IoT device, sensor, electric meter, water meter. The embodiments of this application do not limit the type or category of the terminal device.
[0100] In the embodiments of this application, the device for implementing the functions of the terminal device may be the terminal device or a device capable of supporting the terminal device to implement the functions, such as a chip system or a chip, and this device may be installed in the terminal device. In the embodiments of this application, the chip system may be composed of chips or may include chips and other discrete devices.
[0101] (2) The network device 120 can be any device with wireless transceiver functions for communicating with the terminal device. This network device can also be referred to as an access network device or a radio access network device. For example, the network device can be a base station. In the embodiments of this application, the network device can refer to a radio access network (RAN) node (or RAN device, or RAN entity) that connects the terminal device to the wireless network. The (R)AN can be regarded as a sub-network of the operator's network and is the implementation system between the service nodes in the operator's network and the terminal device 110. For example, when the terminal device 110 wants to access the operator's network, it first passes through the network device 120 and then can be connected to the service nodes of the operator's network through the network device 120. The above RAN can be a cellular system related to the 3rd generation partnership project (3GPP), such as a 5G mobile communication system or an evolved system for the future (such as a 6G mobile communication system). The RAN can also be an open RAN (O-RAN or ORAN), a cloud radio access network (CRAN), or a wireless fidelity (WiFi) system. The RAN can also be a communication system that integrates two or more of the above systems. The network device 120 includes but is not limited to: the next generation node base station (gNB) in the 5G system, the evolved node B (eNB) in LTE, the radio network controller (RNC), the node B (NB), the base station controller (BSC), the base transceiver station (BTS), the home base station (for example, home evolved node B, or home node B, HNB), the base band unit (BBU), the transmitting and receiving point (TRP), the transmitting point (TP), the pico small base station device, the mobile switching center, or the network device in the future network, etc. In systems using different radio access technologies, the names of the devices with access network device functions may be different. For the convenience of description, in all embodiments of this application, the device that provides wireless communication functions for the terminal device 110 is collectively referred to as an access network device or simply as RAN or AN.It should be understood that the specific type of the access network device is not limited herein.
[0102] In some deployments, multiple RAN nodes cooperate to assist a terminal in achieving wireless access, and different RAN nodes respectively implement some functions of a base station. For example, the RAN node can be a CU, a DU, a central unit control plane (CU-CP), a central unit user plane (CU-UP), or a radio unit (RU), etc. The CU and the DU can be separately provided, or can also be included in the same network element, such as in a BBU. The function of the RU can be implemented by the radio frequency device of the base station. For example, the radio frequency device of the base station can be a remote radio unit (RRU), a pico remote radio unit (pRRU), an active antenna unit (AAU), or other units, modules, or devices with radio frequency processing functions, etc. The communication interface protocol between the BBU and the radio frequency device can be a common public radio interface (CPRI) interface protocol, an enhanced common public radio interface (eCPRI) interface protocol, or a fronthaul interface protocol between the DU and the RU in the O-RAN system, etc., without limitation.
[0103] In different systems, the CU (or CU-CP and CU-UP), the DU, or the RU may also have different names, but those skilled in the art can understand their meanings. For example, in the ORAN system, the CU can also be called an O-CU (open CU), the DU can also be called an O-DU, the CU-CP can also be called an O-CU-CP, the CU-UP can also be called an O-CU-UP, and the RU can also be called an O-RU. Any one of the CU (or CU-CP, CU-UP), the DU, and the RU in this application can be implemented by a software module, a hardware module, or a combination of a software module and a hardware module. For the convenience of description, the CU, the CU-CP, the CU-UP, the DU, and the RU are used as examples in this application for description.
[0104] The network device 120 can be fixed or mobile. For example, a helicopter or a drone can be configured to act as a mobile base station, and one or more cells can move according to the position of the mobile base station. In other examples, a helicopter or a drone can be configured to be used as a device for communicating with another base station.
[0105] In the embodiments of the present application, the device for implementing the functions of an access network device may be a network device or a device capable of supporting the access network device to implement such functions, such as a chip system or a chip, and this device may be installed in the access network device. In the embodiments of the present application, the chip system may be composed of chips or may include chips and other discrete devices.
[0106] The network device and the terminal device may be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; they may also be deployed on water; they may also be deployed on airplanes, balloons, and satellites in the air. In the embodiments of the present application, the scenarios where the network device and the terminal device are located are not limited. In addition, the terminal device and the network device may be hardware devices or software functions running on dedicated hardware or software functions running on general hardware. For example, they are virtualized functions instantiated on a platform (such as a cloud platform), or entities including dedicated or general hardware devices and software functions. The present application does not limit the specific forms of the terminal device and the network device.
[0107] (3) The core network CN may include, but is not limited to, the following network functions (NFs): user plane function (UPF), network exposure function (NEF), network function repository function (NRF), policy control function (PCF), unified data management function (UDM), unified data repository function (UDR), application function (AF), authentication server function (AUSF), access and mobility management function (AMF), session management function (SMF).
[0108] The NF functions included in the CN are further briefly described below.
[0109] 1. The UPF is a gateway provided by the operator and serves as the gateway for communication between the operator's network and the DN. It is mainly responsible for packet routing and transmission, packet detection, service usage reporting, quality of service (QoS) processing, lawful interception, uplink packet detection, downlink packet storage, etc. The UPF can also be referred to as a user plane device. It can receive user data from the DN 240 and transmit it to the terminal device 110 through the network device 120. The UPF can also receive user data from the terminal device 110 through the network device 120 and forward it to the DN. The transmission resources and scheduling functions provided for the terminal device 110 in the UPF are managed and controlled by the SMF.
[0110] 2. The NEF is a control plane function provided by the operator, mainly enabling third parties to use the services provided by the network, supporting the network to open its capabilities, event and data analysis, equipping the PLMN with security information from external applications, and converting information exchanged inside and outside the PLMN, etc. The NEF can also be referred to as a network open device and can provide Nnef services.
[0111] 3. The NRF is a control plane function provided by the operator and can be used to maintain real-time information about network functions and services in the network. For example, it supports network service discovery, maintains the services supported by the NF configuration data (NF profile) of the NF instance, supports service discovery of the service communication proxy (SCP), maintains the SCP configuration data (SCPprofile) of the SCP instance, sends notifications about newly registered, deregistered, and updated NFs and SCPs, and maintains the health status of the running NFs and SCPs, etc.
[0112] 4. The PCF is a control plane function provided by the operator. It supports a unified policy framework to govern network behavior, provides policy rules and subscription information related to policy decisions to other control functions.
[0113] 5. The UDM is a control plane function provided by the operator, responsible for storing information such as the subscriber permanent identifier (SUPI), the generic public subscription identifier (GPSI) of the subscribed user, and the credential of the subscribed user in the operator network. These information can be used for the authentication and authorization of the terminal device 110 to access the operator network. Among them, the SUPI will be encrypted first during the transmission process, and the encrypted SUPI is called the subscription concealed identifier (SUCI). The UDM can also be referred to as a unified data management device, a unified data management network element, a data management device, a unified data management entity, etc.
[0114] 6. The UDR is a control plane function provided by the operator, providing functions for the UDM to store and obtain subscribed data, providing functions for the PCF to store and obtain policy data, and storing and obtaining the NF group ID (group ID) information of users, etc. The UDR can also be referred to as a user database device, a user database entity, a user database network element, etc. Among them, the user database mainly includes the following functions: the access function of data types such as subscribed data, policy data, and application data.
[0115] 7. The AF is a control plane function provided by the operator, mainly providing corresponding services by interacting with other NFs in the PLMN. For example, it provides roaming UE visited network selection information, guides the routing of data streams, and accesses the NEF, etc. The AF can be deployed by the operator inside the PLMN or outside the operator network.
[0116] 8. The AUSF is a control plane function provided by the operator, usually used for primary authentication, that is, the authentication between the terminal device 110 (subscribed user) and the operator network. After receiving the authentication request initiated by the subscribed user, the AUSF can authenticate and / or authorize the subscribed user through the authentication information and / or authorization information stored in the UDM, or generate the authentication and / or authorization information of the subscribed user through the UDM. The AUSF can feedback the authentication information and / or authorization information to the subscribed user.
[0117] 9. The AMF is a control plane network function provided by the operator network, responsible for access control and mobility management of the terminal device 110 accessing the operator network. For example, it includes functions such as mobility status management, allocation of user temporary identity identifiers, authentication and authorization of users, etc. Exemplarily, the AMF can also be referred to as an access and mobility management device, an access and mobility management function entity, an access and mobility management function network element, a mobility management device, a mobility management network element, a mobility management entity, etc., and can provide the Namf service.
[0118] 10. The SMF is a control plane network function provided by the operator network, responsible for managing the protocol data unit (PDU) session of the terminal device 110. The terminal device and the DN transmit PDUs to each other through the PDU session. The establishment, maintenance, deletion, etc. of the PDU session are the responsibilities of the SMF. The SMF includes session management (such as session establishment, modification, and release, including the maintenance of the tunnel between the user plane function UPF and the network device 120), selection and control of the UPF, service and session continuity (SSC) mode selection, roaming, and other session-related functions. The SMF can also be referred to as a session management device and can provide the Nsmf service.
[0119] (4) The external network 140 can be a data network (DN), also referred to as a packet data network (PDN), which is usually a network located outside the operator network, such as a third-party network. In some implementation manners, the DN can also be deployed by the operator, that is, the DN belongs to a part of the public land mobile network (PLMN). This application does not limit whether the DN belongs to the PLMN. Multiple services can be deployed on the DN, providing services such as data and / or voice for the terminal device 110.
[0120] It can be understood that the above network elements or functions can be either physical entities in hardware devices, software instances running on dedicated hardware, or virtualized functions instantiated on a shared platform (such as a cloud platform). Simply put, an NF can be implemented by hardware or by software.
[0121] It should be understood that the above naming is only defined for the convenience of distinguishing different functions and should not constitute any limitation to this application. This application does not exclude the possibility of using other naming in the 5G network and future other networks. For example, in the 6G network, some or all of the above network elements may continue to use the terms in 5G, or other names may be adopted.
[0122] The NTN communication system includes an integrated communication and navigation (IcaN) system, a global navigation satellite system (GNSS), a super-dense low-Earth orbit satellite communication system, etc. For example, the NTN communication system includes nodes such as satellite networks, high-altitude platforms, and unmanned aerial vehicles, and has significant advantages such as global coverage, long-distance transmission, flexible networking, convenient deployment, and being unrestricted by geographical conditions. It has been widely used in multiple fields such as maritime communication, positioning and navigation, disaster relief, scientific experiments, video broadcasting, and Earth observation. Terrestrial communication networks (such as LTE networks, 5G communication networks, future 6G communication networks, etc.) and satellite networks are integrated with each other to jointly form a seamless global coverage integrated communication network of the sea, land, air, space, and ground, which can meet the various service needs of users. The current 5G network supports the regenerative satellite mode, that is, the NTN communication system provides seamless coverage for terminal devices by deploying the functions of the access network device or part of the access network device on non-terrestrial (such as high-altitude platforms or satellites), which can also be called that the access network device uses the new radio (NR) to provide satellite access to terminal devices. For ease of description, in the embodiments of this application, the satellite deployed with the access network function is called a satellite access network device, or the base station deployed on the satellite is called a satellite base station.
[0123] Figure 2 It is a schematic diagram of the network architecture applicable to the embodiments of this application. The satellite communication system includes satellite base stations 201 and 202. Each satellite base station can provide services for terminal devices through multiple beams, such as communication services, navigation services, and positioning services, etc. The satellites in this scenario can be low-Earth orbit (LEO) satellites, medium-Earth orbit (MEO) satellites, high-elliptical orbit (HEO) satellites, geostationary Earth orbit (GEO) satellites, etc. The embodiments of this application do not make specific limitations on this. The satellite base station 202 is connected to a terrestrial gateway station (such as NTN Gateway), and the terrestrial gateway station can also be called a gateway station, a transit station, a ground station device, etc. The satellite uses multiple beams to cover the service area, and different beams can communicate through one or more of time division, frequency division, and space division.
[0124] Such as Figure 2As shown in the figure, taking the 5G network as an example, a terminal device on the ground can communicate with a satellite base station using the 5G new air interface. For example, the satellite base station can perform wireless communication with the terminal device by broadcasting communication signals, navigation signals, etc. Among them, the connection between the terminal device and the satellite base station can be called a service link. The satellite base station can perform wireless communication with a ground station (also known as a gateway station, ground gateway station, signaling gateway station, etc.) through an NG interface (for example, for interacting with NAS signaling of the core network and the service data of users), and the satellite base station can also communicate with the core network through the ground gateway station. Among them, the ground station is mainly responsible for forwarding the signaling and service data between the satellite base station and the core network, and the connection between the satellite base station and the ground station can be called a feeder link. At the same time, there is an inter-satellite link (ISL) between satellites, which is used to complete the signaling interaction and user data transmission between 5G access network devices. For example, satellite base station 201 can perform wireless communication with satellite base station 202 through an Xn interface (for example, for signaling interaction such as handover).
[0125] It should be noted that Figure 2 In the communication system shown, the satellite communication system combined with the 5G system is taken as an example for illustration. When the satellite communication system is combined with other terrestrial communication systems, the network elements and interfaces involved may have other names, and the embodiments of the present application do not make specific limitations on this.
[0126] Usually, the service link between the terminal device and the satellite base station and the feeder link between the satellite base station and the ground station are connected, that is, the uplink messages and downlink messages between the terminal device and the core network can be transmitted through the satellite base station and the ground station. Next, in combination with Figure 3 The session establishment between the terminal device and the core network will be described.
[0127] Figure 3 It is a schematic flowchart of a session establishment method for a terminal device. This method 300 can be applied to Figure 1 and Figure 2 The network architecture mainly describes the user plane session establishment process in the satellite communication system and the user plane security protection strategy indicating between the terminal device and the satellite base station in the user plane session establishment process. As Figure 3 shown, taking the terminal device as the UE, the access network device as the satellite base station, and the core network element as the session management network element, such as AMF and SMF as examples, this method includes the following multiple steps. For parts not elaborated in detail, reference can be made to existing protocols.
[0128] S301, the UE registers to the network.
[0129] Exemplarily, the UE registers to the network and completes authentication, activation of the non-access stratum (NAS) and the access stratum (AS) security.
[0130] For example, the UE sends a registration request message to the network to request registration to the network, and the registration request message includes the UEID. Further, the UE and the network perform authentication, including: the AMF triggers the authentication of the UE. For example, the AMF sends an authentication request #1 to the AUSF, and the AUSF sends an authentication request #2 to the UDM. The authentication request #1 and the authentication request #2 are used to request the authentication of the UE. The UDM generates an authentication vector and sends an authentication response #1 to the AUSF. The AUSF sends an authentication response #2 to the AMF. The authentication response #1 and the authentication response #2 include the authentication vector, such as the authentication vector of 5G-AKA or the authentication vector of EAP-AKA'. Among them, the authentication methods include but are not limited to: 5G Authentication and Key Agreement (5G-AKA) authentication method, Extensible Authentication Protocol - Authentication and Key Agreement (EAP-AKA') authentication method. Taking the authentication vector of EAP-AKA' as an example, the AMF sends an EAP Request / AKA′-Challenge message to the UE through a NAS message. After the UE completes the authentication of the network, it sends an EAP-Response / AKA'-Challenge message to the AMF through a NAS message. The AMF then sends a Nausf_UE Authentication_Authenticate Request message to the AUSF, carrying the EAP-Response / AKA'-Challenge message. The AUSF verifies the EAP-Response / AKA'-Challenge message. If the verification is passed, the authentication of the UE is completed, and an EAP Success is sent to the UE through the AMF to indicate the successful authentication. The specific implementation method of the authentication can refer to the relevant description of the existing protocol TS 33.501.
[0131] It should be understood that after the above authentication process, the UE and the AMF side usually generate or obtain a new NAS layer key (such as KAMF). Among them, the NAS layer key (such as the KAMF sub - key) is activated and used by triggering the NAS SMC process, that is, the AMF sends a NAS SMC message to the UE, and the UE sends a NAS SMP message to the AMF. Among them, the NAS SMC message includes, but is not limited to: integrity security protection algorithm identifier and / or confidentiality security protection algorithm identifier, ngKSI, replayed UE security capabilities, MAC#1. The NAS SMP message includes MAC#2. Among them, ngKSI is used to identify a specific NAS security context, and the NAS security context includes: key identifier, UE security capabilities, uplink and downlink NAS count values, confidentiality security protection key, integrity security protection key, selected integrity security protection algorithm identifier, confidentiality security protection algorithm identifier, or one or more of them.
[0132] S302, the UE sends a session establishment request message to the AMF. Correspondingly, the AMF receives the session establishment request message from the UE.
[0133] Among them, the session establishment request message includes a session identifier, which is used to identify the UE's session. Optionally, it can also carry information such as session type and / or slice. Exemplarily, the UE initiates a PDU session establishment request message to the AMF through a satellite base station, such as a PDU Session Establishment Request message. It should be understood that this session request message is a NAS message and is transparently transmitted through the satellite base station, and the satellite base station does not parse this session establishment request message.
[0134] S303, the AMF sends a session creation context request message to the SMF. Correspondingly, the SMF receives the session creation context request message from the AMF.
[0135] Among them, the session creation context request message includes a session identifier. This session creation context request message can be an Nsmf_PDUSession_createSMContext Request message. Correspondingly, based on the session identifier, the SMF can look up the corresponding user - plane security policy (which can be simply referred to as a security protection policy or a user - plane security protection policy) from the UDM or PCF or network management function network element, which is used to indicate whether security protection is required at the transport layer.
[0136] Exemplarily, the user - plane security policy includes a confidentiality security policy and / or an integrity security policy. Among them, the confidentiality security policy is used to indicate whether confidentiality security protection is required at the transport layer, and the integrity security policy is used to indicate whether integrity security protection is required at the transport layer.
[0137] In one implementation, the values of the security policy include required, preferred, and not needed. For example, when the value of the security policy is required, it means that the sender needs to perform security protection on the message and / or data to be sent; when the value of the security policy is not needed, it means that the sender does not need to perform security protection on the message and / or data to be sent; when the value of the security policy is preferred, it means that the sender can optionally perform security protection on the message and / or data to be sent, that is, the sender can perform security protection on the message and / or data to be sent, or can also not perform security protection on the message and / or data to be sent. Here, security protection includes confidentiality security protection and / or integrity security protection. For example, when the value of the integrity security policy is required, it means that integrity security protection needs to be performed on the message and / or data to be sent; when the value of the integrity security policy is not needed, it means that integrity security protection is not required for the message and / or data to be sent; when the value of the integrity security policy is preferred, it means that integrity security protection can be optionally performed on the message and / or data to be sent, that is, integrity security protection can be performed on the message and / or data to be sent, or integrity security protection can also not be performed on the message and / or data to be sent. Another example is that when the value of the confidentiality security policy is required, it means that confidentiality security protection needs to be performed on the message and / or data to be sent; when the value of the confidentiality security policy is not needed, it means that confidentiality security protection is not required for the message and / or data to be sent; when the value of the confidentiality security policy is preferred, it means that confidentiality security protection can be optionally performed on the message and / or data to be sent, that is, confidentiality security protection can be performed on the message and / or data to be sent, or confidentiality security protection can also not be performed on the message and / or data to be sent.
[0138] It should be understood that integrity protection can be achieved through physical means or cryptographic methods to ensure that information and / or data have not been tampered with or unauthorized modified during and after generation, transmission, and storage. Among them, there are various ways to perform integrity protection on information through cryptographic methods. For example, a one-way function (such as the hash function Hash) can be used, with a symmetric key (integrity protection key) and a message as input parameters to generate a message authentication code (MAC) to achieve integrity protection for the message and / or data. Exemplarily, integrity protection can refer to performing integrity protection on the message to be sent according to the selected integrity protection algorithm and integrity protection key. For example, for NAS messages, the integrity protection key can be the NAS Integrity Key (Knasint), and Knasint is used to perform integrity protection on the message to be sent; for RRC messages, the integrity protection key can be the RRC Integrity Key (Krrcint), and Krrcint is used to perform integrity protection on the message to be sent; for user plane messages and / or data, the integrity protection key can be the UP Integrity Key (Kupint), and Kupint is used to perform integrity protection on the message to be sent.
[0139] It should also be understood that confidentiality protection can refer to encrypting the message and / or data to be sent according to the confidentiality protection algorithm and confidentiality protection key.
[0140] Optionally, the security policy can be explicitly indicated, for example, using an independent information element (IE) to represent it. For example, it can be indicated by 2-bit indication information. "00" indicates that the value of the security policy is required, "01" indicates that the value of the security policy is not needed, "10" indicates that the value of the security policy is preferred; or, "true" indicates that the value of the security policy is required, "false" indicates that the value of the security policy is not needed. This application does not make any limitations in this regard.
[0141] Exemplarily, the security algorithms include integrity security algorithms and / or confidentiality security protection algorithms. Among them, the integrity security algorithms include one or more of the following: AES integrity security protection algorithm, SNOW integrity security protection algorithm, ZUC integrity security protection algorithm, or null integrity security protection algorithm, and the confidentiality security protection algorithms include one or more of the following: ZUC confidentiality security protection algorithm, AES confidentiality security protection algorithm, SNOW confidentiality security protection algorithm, or null integrity security protection algorithm.
[0142] S304, the SMF sends a session creation context response message to the AMF. Correspondingly, the AMF receives the session creation context response message from the SMF.
[0143] Among them, the session creation context response message includes a session identifier, a user plane security policy, and a session acceptance message. For example, the session creation context response message may be an Nsmf_PDUSession_createSMContextResponse message. Among them, the session acceptance message is carried in the N1 container.
[0144] S305, the AMF sends a session resource establishment request message to the satellite base station. Correspondingly, the satellite base station receives the session resource establishment request message from the AMF.
[0145] Among them, the session resource establishment request message includes a session identifier, a user plane security policy, and a session acceptance message, and the session resource establishment request message may be a PDU Session Resource Setup Request message.
[0146] S306, the satellite base station determines whether to activate the security protection of the DRB corresponding to the session according to the user plane security policy.
[0147] Among them, one session corresponds to one or more DRBs. In other words, one or more data #1 transmitted by one session can be respectively carried by the one or more DRBs. Generally, one DRB carries one data #1. It should be noted that the user plane security policy is used to indicate whether to enable the security protection of the DRB corresponding to the session.
[0148] Exemplarily, when the value of the user plane security policy is "required", the satellite base station determines that the security protection of the DRB needs to be activated, that is, configures the security protection of the DRB to be enabled; when the value of the user plane security policy is "not needed", the satellite base station determines that the security protection of the DRB does not need to be activated, that is, configures the security protection of the DRB to be disabled; when the value of the user plane security policy is "preferred", the satellite base station can determine whether to activate the security protection of the DRB according to the local policy, that is, determine whether to enable the security protection according to the local policy. For example, the local policy indicates that when the value of the user plane security policy is "preferred", the satellite base station can choose to enable the security protection, or the local policy indicates that when the value of the user plane security policy is "preferred", the satellite base station can choose to enable or disable the security protection according to its own load situation.
[0149] In one implementation, when the value of the integrity security policy is "required", the satellite base station activates the integrity security protection of the DRB corresponding to the session; when the value of the integrity security policy is "not needed", the satellite base station activates the integrity security protection of the DRB corresponding to the session; when the value of the integrity security policy is "preferred", the satellite base station activates or does not activate the integrity security protection of the DRB corresponding to the session according to the local policy.
[0150] In another implementation, when the value of the confidentiality security policy is "required", the satellite base station activates the confidentiality security protection of the DRB corresponding to the session; when the value of the confidentiality security policy is "not needed", the satellite base station activates the confidentiality security protection of the DRB corresponding to the session; when the value of the confidentiality security policy is "preferred", the satellite base station activates or does not activate the confidentiality security protection of the DRB corresponding to the session according to the local policy.
[0151] It should be noted that if the user plane security policy indicates that the integrity security protection of the DRB does not need to be activated (or enabled), the satellite base station and the UE can set the MAC to all 0, which means that the satellite base station and the UE do not perform integrity security protection on the user plane messages and / or data carried by this DRB, and there is no need to perform integrity verification on the user plane messages and / or data carried by this DRB. Optionally, the MAC can also not be put into the Packet Data Convergence Protocol (PDCP) data packet.
[0152] S307, the satellite base station sends an RRC reconfiguration message to the UE. Correspondingly, the UE receives the RRC reconfiguration message from the satellite base station.
[0153] Exemplarily, the RRC reconfiguration message may be an RRC Reconfiguration message.
[0154] Wherein, the RRC reconfiguration message includes a DRB identifier (such as a DRB ID) and its corresponding user plane security indication (UPsec indication), such as an integrity security protection indication and / or a confidentiality security protection indication. The integrity security protection indication is used to indicate whether the integrity security protection of the DRB is enabled, or in other words, whether it is necessary to activate the integrity security protection of the DRB. The confidentiality security protection indication is used to indicate whether the confidentiality security protection of the DRB is enabled, or in other words, whether it is necessary to activate the confidentiality security protection of the DRB.
[0155] In addition, the RRC reconfiguration message further includes the session acceptance message.
[0156] Optionally, the size of the integrity security protection indication and / or the confidentiality security protection indication may be 1 bit. For example, when the value of the confidentiality indication information is "1", it indicates that the confidentiality security protection of the DRB is enabled; when the value of the confidentiality indication information is "0", it indicates that the confidentiality security protection of the DRB is not enabled. Another example is that when the value of the integrity indication information is "1", it indicates that the integrity security protection of the DRB is enabled; when the value of the integrity indication information is "0", it indicates that the integrity security protection of the DRB is not enabled.
[0157] Optionally, the values of the integrity security protection indication and the confidentiality security protection indication may be determined according to the user plane security policy received by the satellite base station.
[0158] For example, if the session of the UE corresponds to two DRBs (such as DRB#1 and DRB#2), it means that the data to be transmitted in this session is carried on DRB#1 and DRB#2. For example, data#1 is carried on DRB#1 and data#2 is carried on DRB#2. Wherein, the user plane security policy indicates to activate the integrity security protection and not activate the confidentiality security protection. Then the satellite base station may set the values of the integrity security protection indications corresponding to DRB#1 and DRB#2 to "1" and the values of the confidentiality security protection indications to "0", and carry them in the RRC reconfiguration message in step S307.
[0159] Optionally, after determining whether to activate the security protection of the DRB or after determining the user plane security protection policy, the satellite base station configures the PDCP entity of the DRB corresponding to the session. Exemplarily, if the user plane security policy indicates to activate integrity security protection and not activate confidentiality security protection, the user plane security indication in the RRC reconfiguration message is used to indicate that DRB#1 and DRB#2 enable integrity security protection and do not enable confidentiality security protection. Correspondingly, the satellite base station configures the integrity security protection key and integrity security protection algorithm corresponding to DRB#1 and DRB#2 in the PDCP entity, and activates the integrity verification of the uplink user plane message and / or data on the DRB#1 and DRB#2, and activates the integrity security protection of the downlink user plane message and / or data on the DRB#1 and DRB#2.
[0160] S308, the UE performs integrity verification on the RRC reconfiguration message.
[0161] Exemplarily, the UE performs integrity verification on the received RRC reconfiguration message. For example, the UE compares the MAC#3 value carried in the RRC reconfiguration message with the MAC#4 calculated locally by the UE. If the two are the same, it can be considered that the integrity verification passes; otherwise, the integrity verification fails.
[0162] Further, in the case where the integrity verification is successful, the UE configures the PDCP entity corresponding to the DRB. Exemplarily, if the integrity security protection is activated for DRB#1 indicated in the RRC reconfiguration message, the UE configures the integrity security protection key and integrity security protection algorithm corresponding to DRB#1 in the PDCP entity, and activates the integrity security protection of the uplink user plane message on the DRB#1, and activates the integrity verification of the downlink user plane message on the DRB#1. If the confidentiality security protection is activated for DRB#2 indicated in the RRC reconfiguration message, the UE configures the confidentiality security protection key and confidentiality security protection algorithm corresponding to DRB#2 in the PDCP entity, and activates the confidentiality security protection of the uplink user plane message on the DRB#2, and activates the decryption operation of the downlink user plane message on the DRB#2.
[0163] S309, the UE sends an RRC reconfiguration complete message to the satellite base station. Correspondingly, the satellite base station receives the RRC reconfiguration complete message from the UE.
[0164] Exemplarily, if the UE successfully verifies the integrity of the RRC reconfiguration message in step S309, the UE sends an RRC reconfiguration complete message to the satellite base station. For example, the RRC reconfiguration complete message can be an RRC ReconfigurationComplete message. Optionally, if the UE fails to successfully activate the security protection of the DRB, or the UE fails to configure the PDCP entity of the DRB, the UE may send a failure cause value to the satellite base station, and the failure cause value may indicate that the integrity check of the RRC reconfiguration message fails.
[0165] S310, the satellite base station sends a session resource establishment response message to the AMF. Correspondingly, the AMF receives the session resource establishment response message from the satellite base station.
[0166] Among them, the session resource establishment response message is used to inform the session resource establishment result, such as successful establishment or failure. Exemplarily, the session resource establishment response message can be a PDU Session Resource Setup Response message. It should be understood that the technical solution of this application is based on the successful establishment of the session resource.
[0167] Optionally, in the LTE network, the core network elements in the above method 300 may be a Mobility Management Entity (MME), Serving GateWays (S-GWs), or Public Data Network (PDN GWs or P-GWs). The specific implementation methods are similar and will not be described here.
[0168] Since the ground coverage area of the satellite is limited, at some moments, the service link and the feeder link may not be in a connected state at the same time. For example, when the satellite orbits over geographical location A, a service link can be established with a UE located at geographical location B, but at this time, it may not be possible to establish a feeder link with a ground gateway station located at geographical location C. At this time, the satellite base station can perform a store-and-forward operation, that is, the satellite base station can store the received uplink message, that is, cache the uplink message on the satellite base station, and then forward the stored uplink information to the ground network after the feeder link is restored. It should be understood that the store-and-forward operation is mainly applicable to satellite services for the Internet of Things that are not sensitive to delay or non-real-time. The object of the store-and-forward operation can be signaling plane data or user plane data. For ease of description and understanding, this application takes user plane data as an example for illustration.
[0169] In the case of the store-and-forward operation scenario, if an attacker sends a large number of malicious data or messages to the satellite base station, it may cause the storage area of the satellite base station to be filled up, and then it is impossible to cache the control plane data and / or user plane data of normal UEs, posing a risk of malicious attack on the satellite base station and unable to guarantee network security. Therefore, it is urgent to take additional measures to deal with it to reduce potential security risks.
[0170] In view of this, the present application provides a secure communication method and a communication device, which can reduce the risk of malicious attack on the satellite base station and improve network communication security.
[0171] The communication method provided by the embodiments of the present application will be described in detail below with reference to the accompanying drawings. The embodiments provided by the present application can be applied to the communication scenario of communication between a sending device and a receiving device. For example, it can be applied to the communication system shown in the above Figure 1 and Figure 2 shown.
[0172] Figure 4 FIG. is a schematic flowchart of the communication method provided by the embodiments of the present application. This method 400 can be executed by the terminal device side, the network device side, and the core network side. For example, this method can be executed by the terminal device, the network device, and the core network element (such as the session management network element), or, it can also be executed by the chip or circuit of the terminal device, the network device, and the core network element (such as the session management network element), or it can also be implemented by a logic module or software that can implement all or part of the functions of the communication device. The present application does not limit this. The following will be described by taking the execution entities as the terminal device, the network device, and the session management network element as an example. As Figure 4 shown, this method includes the following multiple steps. For the parts not described in detail, reference can be made to the above method 300 or the existing protocol.
[0173] S410. During the session establishment process of the terminal device, the network device determines whether to activate the integrity security protection of the session according to the first information, and the first information is used to indicate whether the network device supports the store-and-forward operation (which can be called capability information).
[0174] It should be understood that the session is used to transmit data between the terminal device and the core network. For example, if a session corresponds to one or more DRBs, it means that the one or more data transmitted by a session can be carried by the one or more DRBs respectively. Usually, one DRB carries one data, and the DRB is used to carry data between the terminal device and the network device.
[0175] It should be noted that whether to activate the integrity security protection of the session can be understood as: whether to activate the integrity security protection of one or more DRBs corresponding to the session, or it can also be understood as: whether to enable the integrity security protection for the data transmitted between the terminal device and the network device.
[0176] Among them, for the specific implementation method of the session establishment process of the terminal device and the meaning of the store and forward operation, reference can be made to the relevant description of the above method 300, which will not be elaborated here.
[0177] Optionally, before performing step S410, the method further includes: the network device obtains first information.
[0178] Exemplarily, the first information can be predefined, or configured by signaling or pre-configured. Among them, predefined can include predefined in advance, such as protocol definition, and pre-configuration can be implemented by pre-saving corresponding codes, tables, strings or other ways that can be used to indicate the first information in the network device. The present application does not limit its specific implementation method.
[0179] Optionally, the first information can also be used to indicate whether the network device is configured to enable the store and forward operation (which can be called configuration information), and / or, the first information can also be used to indicate whether the network device is deployed on a satellite (which can be called location information). For ease of description, the network device deployed on a satellite in the present application can be called a satellite base station, and the network device not deployed on a satellite can be called a ground base station.
[0180] That is, the first information in the present application can include one or more of the capability information, configuration information, or location information of the network device.
[0181] Next, an example is given for the network device to determine whether to activate the integrity security protection of the session according to the first information, or rather, for the satellite base station to activate or not activate the integrity security protection of the session according to the first message, including one or more of the following.
[0182] (1) The network device determines whether to activate the integrity security protection of the session according to the capability information, or rather, the network device determines to activate or not activate the integrity security protection of the session according to the capability information.
[0183] For example, when the capability information indicates that the network device supports the store and forward operation, the network device determines to activate the integrity security protection of the session, that is, without considering the integrity security policy, the integrity security protection of the session can be directly activated; for another example, when the capability information indicates that the network device does not support the store and forward operation, the network device determines not to activate the integrity security protection of the session. Optionally, the network device can determine whether to activate the integrity security protection of the session according to the user plane integrity security policy obtained in step S403.
[0184] That is to say, when the network device supports the store-and-forward operation, the network device activates the integrity security protection of the session; when the network device does not support the store-and-forward operation, the network device does not activate the integrity security protection of the session, or can activate or not activate the integrity security protection of the session according to the user plane integrity security policy.
[0185] (2) The network device determines whether to activate the integrity security protection of the session according to the configuration information. Or rather, the network device activates or does not activate the integrity security protection of the session according to the configuration information.
[0186] For example, when the configuration information indicates that the network device is configured to enable the store-and-forward operation, the network device determines to activate the integrity security protection of the session, that is, without considering the integrity security policy, it can directly activate the integrity security protection of the session; for another example, when the configuration information indicates that the network device does not enable the store-and-forward operation, the network device determines not to activate the integrity security protection of the session. Optionally, the network device can determine whether to activate the integrity security protection of the session according to the user plane integrity security policy obtained in step S403.
[0187] It can be understood that when the network device is configured to enable the store-and-forward operation, the network device activates the integrity security protection of the session; when the network device is configured not to enable the store-and-forward operation, the network device does not activate the integrity security protection of the session, or can activate or not activate the integrity security protection of the session according to the user plane integrity security policy.
[0188] (3) The network device determines whether to activate the integrity security protection of the session according to the location information. Or rather, the network device activates or does not activate the integrity security protection of the session according to the location information.
[0189] For example, when the location information indicates that the network device is deployed on a satellite, that is, when the network device is a satellite base station, the network device determines to activate the integrity security protection of the session, that is, without considering the integrity security policy, it can directly activate the integrity security protection of the session; for another example, when the location information indicates that the network device is not deployed on a satellite, such as when the network device is a ground base station, the network device does not activate the integrity security protection of the session, or can determine whether to activate the integrity security protection of the session according to the user plane integrity security policy obtained in step S403.
[0190] It can be understood that when the network device is deployed on a satellite, the network device activates the integrity security protection of the session; when the network device is deployed on the ground, the network device does not activate the integrity security protection of the session, or can activate or not activate the integrity security protection of the session according to the user plane integrity security policy.
[0191] It should be understood that in the above (1)-(3), the network device determines whether to activate the integrity security protection of the session according to the first information. Or rather, the network device activates or does not activate the integrity security protection of the session according to the first information. Among them, the technical logics of the above (1)-(3) are the same, that is, the network device can activate or not activate the integrity security protection of the session according to the first information without considering the user plane integrity security policy. This method enables the user plane data to have integrity security protection as much as possible, facilitating the subsequent network device to perform integrity verification on the received uplink messages and / or data, ensuring network communication security, and at the same time reducing the risk of denial-of-service attacks.
[0192] Optionally, when determining whether to activate the integrity security protection of the session, the network device can also consider the user plane integrity security policy corresponding to the session, that is, the network device can determine whether to activate the integrity security protection of the session according to the first information and the user plane integrity security policy. In this case, the method further includes the following step S404.
[0193] S404, the network device determines whether to activate the integrity security protection of the session according to the first information and the user plane integrity security policy.
[0194] Among them, the user plane integrity security policy is used to indicate whether to activate the integrity security protection of the session. For specific interpretations, reference can be made to the relevant descriptions in the above step S410 and the above method 300.
[0195] Optionally, before executing step S404, the session management network element obtains the user plane integrity security policy of the session, for example, see the following step S403.
[0196] S403, the network device obtains the user plane integrity security policy corresponding to the session.
[0197] Exemplarily, the values of the user plane integrity security policy include required, preferred, and not needed. For example, when the value of the user plane integrity security policy is required, it means that the integrity security protection of the session is enabled; when the value of the user plane integrity security policy is not needed, it means that the integrity security protection of the session is not enabled; when the value of the user plane integrity security policy is preferred, it means that the integrity security protection of the session is optionally enabled.
[0198] Optionally, the user plane integrity security policy can be explicitly indicated, for example, represented by using an independent information element (IE). For example, it can be indicated by 2-bit indication information. "00" indicates that the value of the user plane integrity security policy is required, "01" indicates that the value of the user plane integrity security policy is not needed, and "10" indicates that the value of the user plane integrity security policy is preferred; or, "true" indicates that the value of the user plane integrity security policy is required, and "false" indicates that the value of the user plane integrity security policy is not needed. The present application does not limit its manifestation form.
[0199] In one implementation, the network device obtains the user plane integrity security policy corresponding to the session from the session management network element. For example, refer to the following step S402.
[0200] S402. The session management network element sends the user plane integrity security policy corresponding to the session to the network device. Correspondingly, the network device receives the user plane integrity security policy corresponding to the session from the session management network element.
[0201] In one example, the session management network element sends the user plane integrity security policy to the mobile access management network element (such as AMF), and then the mobile access management network element sends the user plane integrity security policy to the network device.
[0202] Optionally, the session management network element sending the user plane integrity security policy corresponding to the session to the network device can be an active send or a send based on the request of the network device. For example, the network device sends a request message to the session management network element, and this request message is used to obtain the user plane integrity security policy corresponding to the session. Correspondingly, after receiving the request message, the session management network element can send the user plane integrity security policy corresponding to the session to the network device.
[0203] Optionally, before executing step S402, the session management network element determines the user plane integrity security policy of the session. For example, the session management network element can determine the user plane integrity security policy of the session through the obtained indication information. For example, refer to the following step S401.
[0204] S401. The session management network element obtains the indication information.
[0205] Among them, this indication information is used to indicate that the network device is deployed on a satellite. Optionally, this indication information is further used to indicate that the network device supports store-and-forward operations, and / or the network device is configured to enable the store-and-forward feature.
[0206] It should be understood that the network device is deployed on the satellite, which can be understood as the network device (such as a base station) being physically deployed on the satellite, or the network device (such as a base station) and the satellite being co-located. At this time, the satellite has the capabilities of the network device. For example, the satellite supports the store-and-forward operation of the network device.
[0207] In one example, the session management network element receives indication information from the mobile access management network element (such as the AMF). For example, during the session establishment process of the terminal device, the mobile access management network element sends a session creation context request message to the session management network element, and the indication information is carried in the session creation context request message.
[0208] In another example, the session management network element obtains indication information from the Operation Administration and Maintenance (OAM) or the UDM. For example, the session management network element sends a query message to the OAM or the UDM to obtain one or more of the capability information, location information, or configuration information of the network device. Correspondingly, the OAM or the UDM sends the indication information to the session management network element. The specific interpretations of the capability information, location information, and configuration information can refer to the relevant descriptions above and will not be elaborated here.
[0209] Exemplarily, the user plane integrity security policy corresponding to the session is determined according to the indication information. Or rather, the session management network element can determine the user plane integrity security policy corresponding to the session according to the indication information. For example, when the indication information determines that the network device is deployed on the satellite, or the network device supports the store-and-forward operation, or the network device is configured to enable the store-and-forward feature, considering the limited storage resources of the network device and avoiding potential DoS risks, the session management network element can set the value of the user integrity security policy to required. That is to say, the session management network element can determine to enable or activate the integrity security protection according to the indication information, that is, the data transmitted between the subsequent terminal device and the network device is all protected by integrity security, that is, the data transmitted between the terminal device and the network device needs to be subjected to integrity verification, and then store and forward the data that passes the integrity verification.
[0210] Optionally, the user plane integrity security policy corresponding to the session may also be determined according to the subscription information. In other words, the session management network element may determine the user plane integrity security policy corresponding to the session according to the subscription information. The subscription information is used to indicate whether the terminal device subscribes to the store-and-forward operation service. For example, if the subscription information indicates that the terminal device subscribes to the store-and-forward operation service, the session management network element may set the value of the user plane integrity security policy corresponding to the session to required. That is to say, the session management network element may enable the integrity security protection of the session according to the subscription information. That is, the uplink and downlink data transmitted between the terminal device and the network device subsequently are all protected by integrity security. That is, the terminal device and the network device need to perform integrity verification on the received user plane data. For another example, if the subscription information indicates that the terminal device does not subscribe to the store-and-forward operation service, the session management network element may set the value of the user plane integrity security policy corresponding to the session to preferred. That is to say, the session management network element may determine to optionally enable the integrity security protection of the session, and then the network device determines whether to enable the integrity security protection of the session according to the local policy.
[0211] Optionally, the user plane integrity security policy corresponding to the session may also be determined according to the subscription information and the indication information. In other words, the session management network element may determine the user plane integrity security policy corresponding to the session according to the indication information and the subscription information. For example, if the indication information determines that the network device is deployed on a satellite, or the network device supports the store-and-forward operation, or the network device is configured to enable the store-and-forward feature, and at the same time, the subscription information indicates that the terminal device subscribes to the store-and-forward operation service, the session management network element may set the value of the user plane integrity security policy corresponding to the session to required, indicating to enable the integrity security protection of the session. For another example, if the indication information determines that the network device is not deployed on a satellite, or the network device does not support the store-and-forward operation, or the network device is configured not to enable the store-and-forward feature, and the subscription information indicates that the terminal device does not subscribe to the store-and-forward operation service, the session management network element may set the value of the user plane integrity security policy corresponding to the session to not needed, indicating not to enable the integrity security protection of the session. For yet another example, if the indication information determines that the network device is not deployed on a satellite, or the network device does not support the store-and-forward operation, or the network device is configured not to enable the store-and-forward feature, or the subscription information indicates that the terminal device does not subscribe to the store-and-forward operation service, the session management network element may set the value of the user plane integrity security policy corresponding to the session to preferred, indicating to optionally enable the integrity security protection of the session, and then the network device determines whether to enable the integrity security protection of the session according to the local policy.
[0212] In one implementation, the session management network element can obtain the above-mentioned subscribed information from the UDM or the PCF. For example, the session management network element sends a query message to the UDM or the PCF to obtain the subscribed information of the terminal device. Correspondingly, the UDM or the PCF sends the subscribed information of the terminal device to the session management network element.
[0213] Optionally, this application does not limit the order in which the session management network element obtains the above-mentioned subscribed information and indication information.
[0214] Next, an example is given for the network device to determine whether to activate the integrity security protection of the session according to the first information and the user plane integrity security policy in step S404 above, or in other words, the satellite base station activates or does not activate the integrity security protection of the session according to the first message and the user plane integrity security policy, including one or more of the following.
[0215] (1) The network device determines whether to activate the integrity security protection of the session according to the capability information and the user plane integrity security policy, or in other words, the network device activates or does not activate the integrity security protection of the session according to the capability information and the user plane integrity security policy.
[0216] For example, when the capability information indicates that the network device supports the store-and-forward operation and the value of the user plane integrity security policy is required or preferred, the network device determines to activate the integrity security protection of the session; for another example, when the capability information indicates that the network device supports the store-and-forward operation and the value of the user plane integrity security policy is not needed, the network device determines not to activate the integrity security protection of the session. In this implementation, the network device determines whether to activate the integrity security protection of the session mainly based on the user plane integrity security policy; for another example, when the capability information indicates that the network device supports the store-and-forward operation and the value of the user plane integrity security policy is not needed, the network device determines to activate the integrity security protection of the session. In this implementation, the network device determines whether to activate the integrity security protection of the session mainly based on whether the network device supports the store-and-forward operation; for another example, when the capability information indicates that the network device does not support the store-and-forward operation, regardless of whether the value of the user plane integrity security policy is required or preferred or not needed, the network device determines not to activate the integrity security protection of the session.
[0217] (2) The network device determines whether to activate the integrity security protection of the session according to the configuration information of the network device and the user plane integrity security policy, or in other words, the network device activates or does not activate the integrity security protection of the session according to the configuration information of the network device and the integrity security policy.
[0218] For example, when the configuration information indicates that the network device is configured to enable store-and-forward operation and the value of the user plane integrity security policy is "required" or "preferred", the network device determines to activate the integrity security protection for the session. For another example, when the configuration information indicates that the network device is configured to enable store-and-forward operation and the value of the user plane integrity security policy is "not needed", the network device determines not to activate the integrity security protection for the session. In this implementation method, whether the network device activates the integrity security protection for the session mainly depends on the user plane integrity security policy. For yet another example, when the configuration information indicates that the network device is configured to enable store-and-forward operation and the value of the user plane integrity security policy is "notneeded", the network device determines to activate the integrity security protection for the session. In this implementation method, whether the network device activates the integrity security protection for the session mainly depends on whether the network device is configured to enable store-and-forward operation. For still another example, when the configuration information indicates that the network device is not configured to enable store-and-forward operation, regardless of whether the value of the user plane integrity security policy is "required" or "preferred" or "not needed", the network device determines not to activate the integrity security protection for the session.
[0219] (3) The network device determines whether to activate the integrity security protection for the session based on the location information and the user plane integrity security policy. Or rather, the network device activates or does not activate the integrity security protection for the session based on the location information and the user plane integrity security policy.
[0220] For example, when the location information indicates that the network device is deployed on a satellite (for example, the network device is a satellite base station) and the value of the user plane integrity security policy is "required" or "preferred", the network device determines to activate the integrity security protection for the session. For another example, when the location information indicates that the network device is deployed on a satellite and the value of the user plane integrity security policy is "not needed", the network device determines not to activate the integrity security protection for the session. In this implementation method, whether the network device activates the integrity security protection for the session mainly depends on the user plane integrity security policy. For yet another example, when the location information indicates that the network device is deployed on a satellite and the value of the user plane integrity security policy is "notneeded", the network device determines not to activate the integrity security protection for the session. In this implementation method, whether the network device activates the integrity security protection for the session mainly depends on the fact that the network device is a satellite base station. For still another example, when the location information indicates that the network device is deployed on a non-satellite (for example, the network device is a ground base station), regardless of whether the value of the user plane integrity security policy is "required" or "preferred" or "not needed", the network device determines not to activate the integrity security protection for the session.
[0221] It should be understood that in the above (4)-(6), the network device determines whether to activate the integrity security protection of the session according to the first information user plane integrity security policy. Or rather, the network device activates or does not activate the integrity security protection of the session according to the first information user plane integrity security policy. Among them, the technical logics of the above (4)-(6) are the same, that is, the network device supports activating the integrity security protection of the session to the greatest extent, which can ensure that the user plane data is activated with integrity security protection to the greatest extent, facilitating the subsequent network device to perform integrity verification on the received uplink messages and / or data, guaranteeing network communication security, and at the same time reducing the risk of a denial-of-service attack.
[0222] It should be noted that this application does not specifically limit the execution sequence of the above steps S401-S404. For example, steps S401-S404 can be executed before step S410, or steps S401-S404 can also be executed after step S410, or steps S401-S403 are executed before step S410 and step S404 is completed after step S410, as long as it is ensured that steps S401-S404 are executed before the following step S420.
[0223] S420, the network device sends the first integrity security protection indication information to the terminal device. Correspondingly, the terminal device receives the first integrity security protection indication information from the network device.
[0224] Among them, the first integrity security protection indication information is used to indicate the activation result. Exemplarily, the activation result is used to indicate whether to activate the integrity security protection of the session, or rather, the activation result is used to indicate whether to activate the integrity security protection of one or more DRBs corresponding to the session. For example, the activation result includes activating the integrity security protection of the session, or not activating the integrity security protection of the session.
[0225] Optionally, the network device sends an RRC reconfiguration message to the terminal device, such as an RRC Reconfiguration message, and the first integrity security protection indication information is carried in the RRC reconfiguration message.
[0226] Optionally, the first integrity security protection indication information can be explicitly indicated. For example, it is represented by using an independent information element IE. For example, it is indicated by 1-bit indication information. "1" indicates activating the integrity security protection of the session, and "0" indicates not activating the integrity security protection of the session; or, "true" indicates activating the integrity security protection of the session, and "false" indicates not activating the integrity security protection of the session. This application does not limit its manifestation form.
[0227] In one implementation, the first integrity security protection indication information is determined according to the first information. For example, based on the above step S410, if the network device determines to activate the integrity security protection of the session according to the first information, the first integrity security protection indication information is used to indicate the activation of the integrity security protection of the session; if the network device determines not to activate the integrity security protection of the session according to the first information, the first integrity security protection indication information is used to indicate the non-activation of the integrity security protection of the session.
[0228] In another implementation, the first integrity security protection indication information is determined according to the first information and the user plane security protection policy. For example, based on the above step S404, if the network device determines to activate the integrity security protection of the session according to the first information and the user plane security protection policy, the first integrity security protection indication information is used to indicate the activation of the integrity security protection of the session; if the network device determines not to activate the integrity security protection of the session according to the first information and the user plane security protection policy, the first integrity security protection indication information is used to indicate the non-activation of the integrity security protection of the session.
[0229] Optionally, the size of the first integrity security protection indication information may be 1 bit. For example, if the value of the first integrity security protection indication information is "1", it means that the integrity security protection corresponding to the session is enabled, or in other words, the integrity security protection of one or more DRBs corresponding to the session is enabled. That is to say, one or more data carried between the terminal device and the network device on the one or more DRBs are subject to integrity security protection, and the terminal device or the network device needs to perform integrity verification after receiving the one or more data. For another example, if the value of the first integrity security protection indication information is "0", it means that the integrity security protection corresponding to the session is not enabled, or in other words, the integrity security protection of one or more DRBs corresponding to the session is not enabled. That is to say, one or more data carried between the terminal device and the network device on the one or more DRBs are not subject to integrity security protection, and the terminal device or the network device does not need to perform integrity verification after receiving the one or more data.
[0230] Optionally, after determining whether to activate the integrity security protection of the session, or after determining the first integrity security protection indication information, or after sending the first integrity security protection indication information to the terminal device, the network device may configure the PDCP entities of one or more DRBs corresponding to the session. Exemplarily, if it is determined to activate the integrity security protection of the session, the network device configures the integrity security protection key and integrity security protection algorithm of the one or more DRBs in the PDCP entity, and activates the integrity check of the uplink user plane message and / or data carried by the one or more DRBs, and activates the integrity security protection of the downlink user plane message and / or data carried by the one or more DRBs; if it is determined not to activate the integrity security protection of the session, the network device does not need to configure the integrity security protection key and integrity security protection algorithm of the one or more DRBs in the PDCP entity, and thus does not need to activate the integrity check of the uplink user plane message and / or data carried by the one or more DRBs, and does not need to activate the integrity security protection of the downlink user plane message and / or data carried by the one or more DRBs.
[0231] S430, the terminal device performs an integrity check on the first integrity security protection indication information.
[0232] Exemplarily, the terminal device may determine whether the integrity check passes by comparing the MAC value. The specific implementation method may refer to the relevant description of the above method 300 and will not be described here.
[0233] S440, when the integrity check passes, the terminal device determines whether to activate the integrity security protection of the session according to the first integrity security protection indication information.
[0234] That is to say, after receiving the first integrity security protection indication information, when the integrity check of the first integrity security protection indication information passes, the terminal device may further determine whether to enable or disable the integrity security protection of the session. For example, if the first integrity security protection indication information indicates to activate the integrity security protection of the session, the terminal device enables the integrity security protection of the session, that is, the uplink messages and / or data subsequently sent by the terminal device to the network device need to undergo integrity security protection, and the uplink messages and / or data subsequently received by the terminal device from the network device need to undergo integrity checks; for another example, if the first integrity security protection indication information indicates not to activate the integrity security protection of the session, the terminal device does not enable the integrity security protection of the session, that is, the uplink messages and / or data subsequently sent by the terminal device to the network device do not need to undergo integrity security protection, and the uplink messages and / or data subsequently received by the terminal device from the network device do not need to undergo integrity checks.
[0235] Optionally, when the integrity verification is passed, after determining whether to activate the integrity security protection of the session, the terminal device may configure the PDCP entities of one or more DRBs corresponding to the session. Exemplarily, if the first integrity security protection indication information indicates to activate the integrity security protection of the session, the terminal device configures the integrity security protection key and integrity security protection algorithm of one or more DRBs corresponding to the session in the PDCP entity, and activates the integrity security protection of the uplink user plane message and / or data carried by the one or more DRBs, and activates the integrity check of the downlink user plane message and / or data carried by the one or more DRBs; if the first integrity security protection indication information indicates not to activate the integrity security protection of the session, the terminal device does not need to configure the integrity security protection key and integrity security protection algorithm of one or more DRBs corresponding to the session in the PDCP entity, and thus does not need to activate the integrity security protection of the uplink user plane message and / or data carried by the one or more DRBs, and does not need to activate the integrity check of the downlink user plane message and / or data carried by the one or more DRBs.
[0236] Optionally, the terminal device may send a response message to the network device to indicate whether the terminal device has successfully activated the integrity security protection of the session. For example, if the terminal device successfully activates the integrity security protection of the session, the terminal device sends response message #1 to the network device to indicate that the terminal device has successfully activated the integrity security protection of the session. Optionally, if the first integrity security protection indication information in step S420 above is carried in the RRC reconfiguration message, the terminal device may send an RRC reconfiguration complete message to the network device to indicate that the terminal device has successfully activated the integrity security protection of the session, or in other words, to indicate that the terminal device has successfully configured the PDCP entities of one or more DRBs corresponding to the session. For another example, if the terminal device fails to successfully activate the integrity security protection of the session, the terminal device sends response message #2 to the network device to indicate that the terminal device has failed to successfully activate the integrity security protection of the session. Optionally, the response message #2 may carry a failure cause value. For example, the failure cause value may be used to indicate that the verification of the first integrity security protection indication information fails.
[0237] Optionally, for the scenario where the connection between the network device and the core network on the ground is disconnected, the network device can ensure network communication security and reduce the risk of being DoS attacked by performing integrity check on the received uplink message and / or data, and storing the uplink data when the integrity check is passed, and not storing or discarding the uplink data when the integrity check fails. The specific implementation method can refer to the relevant description of method 500 below and will not be elaborated here.
[0238] It should be noted that, in the above method 300, taking user plane integrity security protection, user plane integrity security policy, or integrity verification as examples for illustration is only an example given for easy understanding and does not constitute a limitation on the technical solution of this application. Optionally, the technical solution of this application is equally applicable to user plane confidentiality security protection, user plane confidentiality security policy, or decryption operations, etc. The specific implementation manner can refer to the above relevant descriptions and will not be elaborated here.
[0239] In the solution provided above in this application, the network device determines whether to activate the integrity security protection of the session according to the first information. Additionally, the user plane integrity security policy and / or the local policy of the network device can also be considered to activate or enable the integrity security protection of the session as much as possible, so that the user plane data received by the network device undergoes integrity security protection to the greatest extent. In the scenario where the feeder link is disconnected, only the user plane data that passes the integrity verification is stored, which not only mitigates the potential risk of denial-of-service (DoS) attacks but also ensures network communication security.
[0240] Figure 5 It is a schematic flowchart of the communication method 500 provided by an embodiment of this application. As Figure 5 shown, taking the terminal device as the UE, the network device as the base station, and the core network element as the AMF or SMF as the execution entity for interaction. For ease of description, this application may refer to the base station deployed on the satellite as the satellite base station, and the base station deployed on non-satellites, such as the base station deployed on the ground, as the ground base station. This method can be regarded as a further refinement of the above method 400. It should be understood that Figure 5 the embodiment shown in Figure 4 can be coupled with the embodiment shown in Figure 4 and can refer to each other. Therefore, the relevant descriptions in the above method 400 are equally applicable to this implementation manner. There may be the same or similar technical means between the two. The content already described in the embodiment shown in
[0241] S501, the UE registers to the network.
[0242] Optionally, the number of UEs registered to the same network in the embodiment of this application is not limited. It should be understood that for the scenario where multiple UEs register to the network, the process of each UE establishing a session and the specific implementation manner of activating or not activating the user plane integrity security protection of the session are similar. For ease of description, this implementation manner is described by taking one UE registering to the network, establishing a session, and determining whether to activate or not activate the user plane integrity security protection of the session as an example.
[0243] S502. The UE sends a session establishment request message to the AMF. Correspondingly, the AMF receives the session establishment request message from the UE.
[0244] Among them, one session can correspond to one or more DRBs. It should be understood that the session is used to transmit data between the UE and the core network. For example, one session is used to transmit one or more data, and the one or more data can be borne by the one or more DRBs respectively. Usually, one DRB bears one data.
[0245] S503. The AMF sends a session creation context request message to the SMF. Correspondingly, the SMF receives the session creation context request message from the AMF.
[0246] S504. The SMF sends a session creation context response message to the AMF. Correspondingly, the AMF receives the session creation context response message from the SMF.
[0247] S505. The AMF sends a session resource establishment request message to the satellite base station. Correspondingly, the satellite base station receives the session resource establishment request message from the AMF.
[0248] Among them, the specific implementation manners of the above steps S501 to S505 can refer to the relevant descriptions of the above method 300.
[0249] S506. The satellite base station determines whether to activate the integrity security protection of the session according to the first information, or rather, the satellite base station activates or does not activate the integrity security protection of the session according to the first information.
[0250] It should be understood that whether to activate the integrity security protection of the session can be understood as whether to activate the integrity security protection of one or more DRBs corresponding to the session, or it can also be understood as whether to enable the integrity security protection for the data transmitted between the terminal device and the network device.
[0251] Optionally, before executing step S506, the satellite base station obtains the first information. For example, the first information includes one or more of the capability information, configuration information, or location information of the network device. Among them, the specific implementation manner of obtaining the first information, as well as the meaning of the first information, can refer to the relevant descriptions of step S410 of the above method 400.
[0252] Next, an example is given for the satellite base station to determine whether to activate the integrity security protection of the session according to the first information, or rather, the satellite base station activates or does not activate the integrity security protection of the session according to the first information, including one or more of the following. The specific implementation manner can refer to the relevant descriptions of the above method 400.
[0253] (1) The satellite base station determines whether to activate the integrity security protection of the session according to the capability information. Or rather, the satellite base station determines to activate or not to activate the integrity security protection of the session according to the capability information.
[0254] (2) The satellite base station determines whether to activate the integrity security protection of the session according to the configuration information. Or rather, the satellite base station activates or does not activate the integrity security protection of the session according to the configuration information.
[0255] (3) The base station determines whether to activate the integrity security protection of the session according to the location information. Or rather, the base station activates or does not activate the integrity security protection of the session according to the location information.
[0256] Optionally, the satellite base station may determine whether to activate the integrity security protection of the session according to the first information and the user plane integrity security policy carried in the above step S505. Or rather, the satellite base station activates or does not activate the integrity security protection of the session according to the first information and the user plane integrity security policy. For example, it includes one or more of the following, and the specific implementation method may refer to the relevant description of step S404 of the above method 400.
[0257] (1) The satellite base station determines whether to activate the integrity security protection of the session according to the capability information and the user plane integrity security policy. Or rather, the satellite base station activates or does not activate the integrity security protection of the session according to the capability information and the user plane integrity security policy.
[0258] (2) The satellite base station determines whether to activate the integrity security protection of the session according to the configuration information and the user plane integrity security policy. Or rather, the satellite base station activates or does not activate the integrity security protection of the session according to the configuration information of the base station and the user plane integrity security policy.
[0259] (3) The base station determines whether to activate the integrity security protection of the session according to the location information and the user plane integrity security policy. Or rather, the satellite base station activates or does not activate the integrity security protection of the session according to the location information and the user plane integrity security policy.
[0260] S507. The satellite base station sends an RRC reconfiguration message to the UE. Correspondingly, the UE receives the RRC reconfiguration message from the satellite base station.
[0261] Exemplarily, the RRC reconfiguration message may be an RRC Reconfiguration message.
[0262] Among them, the RRC reconfiguration message includes one or more DRB identifiers (such as DRB ID) corresponding to the session, and an integrity security protection indication for the one or more DRBs. The integrity security protection indication is used to indicate whether integrity security protection is enabled for the one or more DRBs, or whether integrity security protection needs to be activated for the one or more DRBs.
[0263] In addition, the RRC reconfiguration message may further include the session acceptance message carried in step S505.
[0264] S508, the UE performs an integrity check on the RRC reconfiguration message.
[0265] Optionally, when the integrity check passes, the UE configures the PDCP entities of the one or more DRBs.
[0266] S509, the UE sends an RRC reconfiguration complete message to the satellite base station. Correspondingly, the satellite base station receives the RRC reconfiguration complete message from the UE.
[0267] Exemplarily, the RRC reconfiguration complete message may be an RRC Reconfiguration Complete message.
[0268] S510, the satellite base station sends a session resource establishment response message to the AMF. Correspondingly, the AMF receives the session resource establishment response message from the satellite base station.
[0269] Among them, the specific implementation manners of the above steps S509 to S510 may refer to the relevant descriptions of the above method 300.
[0270] For the following steps S511 - S514, in the scenario where the connection between the satellite base station and the terrestrial core network is disconnected, the satellite base station performs an integrity check on the received uplink data to determine whether to store the uplink data, thereby reducing the risk of being attacked by a DoS attack while ensuring network communication security.
[0271] S511, the connection between the satellite base station and the terrestrial core network is disconnected, such as the feeder link is disconnected.
[0272] Exemplarily, the triggering conditions for the feeder link disconnection include one or more of the following:
[0273] (1) The satellite base station flies to the side away from the terrestrial gateway station, that is, the terrestrial gateway station cannot receive the signal emitted by the satellite base station;
[0274] (2) The communication conditions between the satellite base station and the terrestrial gateway station deteriorate, such as encountering bad weather, or the signal quality is lower than a certain threshold, etc.;
[0275] (3) Other conditions.
[0276] S512, The UE sends uplink data to the satellite base station. Correspondingly, the satellite base station receives the uplink data from the UE.
[0277] It should be noted that if the integrity security protection indication carried in the RRC reconfiguration message in step S507 above is used to indicate that integrity security protection is enabled for one or more DRBs corresponding to the session, the UE needs to perform integrity security protection on the uplink data before sending the uplink data; or, if the integrity security protection indication carried in the RRC reconfiguration message is used to indicate that integrity security protection is not enabled for one or more DRBs corresponding to the session, the UE does not need to perform integrity security protection on the uplink data before sending the uplink data.
[0278] S513, The satellite base station performs integrity verification on the uplink data.
[0279] Exemplarily, the triggering conditions for the satellite base station to perform integrity verification on the uplink data include one or more of the following:
[0280] (1) The satellite base station supports store-and-forward operations and the feeder link is disconnected;
[0281] (2) The satellite base station enables store-and-forward operations and the feeder link is disconnected.
[0282] Optionally, the above triggering conditions may further include:
[0283] (3) The load of the satellite base station is greater than a first threshold. The first threshold can be predefined, such as protocol-defined, or the first threshold can be configured or pre-configured. This application does not make a limitation on this.
[0284] Among them, the specific implementation method of integrity verification includes any one of the following:
[0285] (1) The satellite base station performs integrity verification on all received uplink data;
[0286] (2) The satellite base station determines whether to perform integrity verification on the received uplink data on a per-session basis.
[0287] Exemplarily, if the satellite base station determines to activate the user plane integrity security protection for the session in step S506, for one or more uplink data received by the satellite base station on one or more DRBs corresponding to this session, the satellite base station needs to perform integrity verification on the one or more uplink data; or, if the satellite base station determines not to activate the user plane integrity security protection for the session in step S506, for one or more uplink data received by the satellite base station on one or more DRBs corresponding to this session, the satellite base station does not need to perform integrity verification on the one or more uplink data. Optionally, the satellite base station can directly discard the one or more uplink data.
[0288] (3) The satellite base station determines whether to perform integrity verification on the received uplink data in terms of DRBs.
[0289] Exemplarily, if the satellite base station determines to optionally activate the user plane integrity security protection for the session in step S506, further, the satellite base station can determine whether to activate the user plane integrity security protection for the one or more DRBs according to the local policy, such as its own load condition. Assume that the session corresponds to two DRBs (such as DRB#1 and DRB#2). In the case of determining to optionally enable the user plane integrity security protection for the session according to the first information and / or the user plane integrity security policy, if the satellite base station determines to enable the user plane integrity security protection for DRB#1 and not for DRB#2 according to its own load, then for the uplink data #1 received by the satellite base station on this DRB#1, the satellite base station needs to perform integrity verification on the uplink data #1, and for the uplink data #2 received by the satellite base station on this DRB#2, the satellite base station does not need to perform integrity verification on the uplink data #2. Optionally, the satellite base station can directly discard the uplink data #2.
[0290] Among them, the calculation and judgment methods of the MAC value involved in the integrity verification process can refer to the relevant description of the above method 300, which will not be elaborated here.
[0291] S514. The satellite base station determines whether to store the uplink data according to the verification result.
[0292] Among them, the verification result is used to indicate whether the integrity verification of the uplink data received by the satellite base station in the above step S513 passes, including verification success (passed), or verification failure (not passed).
[0293] Exemplarily, the satellite base station stores the uplink data with successful integrity verification, does not store or discards the uplink data without integrity security protection, or does not store or discards the uplink data with failed integrity verification.
[0294] Based on the above-provided solution, the satellite base station determines whether to activate the integrity security protection of the session based on one or more of the user plane integrity security policy, local policy, the capability information, configuration information, or location information of the satellite base station, and activates the integrity security protection of the session as much as possible, so that the user plane data received by the satellite base station is maximally protected by integrity security. This facilitates the situation where the feeder link is disconnected, and the satellite base station only stores the data that passes the integrity check, which can mitigate potential DoS risks and ensure network communication security.
[0295] It should be understood that the above Figure 4 and Figure 5 During the session establishment process of the terminal device, the satellite base station maximally activates the integrity security protection of the session according to the first information, mitigates potential DoS risks, and at the same time ensures network communication security. Compared with Figure 4 and Figure 5 , in Figure 6 and Figure 7 In the shown solution, when the feeder link is disconnected, the satellite base station and the UE reduce the processing load of the UE and the satellite base station by releasing the sessions and / or DRBs that do not activate the integrity security protection, or the satellite base station and the UE modify the integrity security protection status of the sessions and / or DRBs to the active state, avoid potential DoS risks, and ensure network communication security.
[0296] Figure 6 FIG. Figure 6 shows a schematic flowchart of the communication method provided by an embodiment of the present application. This method 600 can be executed by a terminal device, a network device, and a core network element (such as a session management network element), or alternatively, can be executed by a chip or circuit of a terminal device, a network device, and a core network element (such as a session management network element), or can also be implemented by a logic module or software that can implement all or part of the functions of the communication device. The present application does not limit this. Hereinafter, taking the execution entities as the terminal device, the network device, and the session management network element as an example for description. As
[0297] S610, the network device obtains the user plane integrity security policy corresponding to the session.
[0298] Among them, the user plane integrity security policy is used to indicate whether to activate the integrity security protection of the session, or in other words, whether to enable the integrity security protection for the data transmitted by the session. Regarding the values and specific meanings of the user plane integrity security policy, as well as the manifestation forms, reference can be made to the relevant descriptions of the above method 300 or 400, which will not be elaborated here.
[0299] In one implementation, the network device obtains the user plane integrity security policy corresponding to the session from the session management network element. For example, refer to step S602 below.
[0300] S602. The session management network element sends the user plane integrity security policy corresponding to the session to the network device. Correspondingly, the network device receives the user plane integrity security policy corresponding to the session from the session management network element.
[0301] Among them, the specific implementation method can refer to the relevant description of step S402 of the above method 400, which will not be elaborated here.
[0302] Optionally, before executing step S602, the session management network element determines the user plane integrity security policy of the session. For example, the session management network element can determine the user plane integrity security policy of the session through the obtained indication information. For example, refer to step S601 below.
[0303] S601. The session management network element obtains the indication information.
[0304] Among them, the specific meaning of the indication information and the specific implementation method of obtaining the indication information can refer to the relevant description of step S402 of the above method 400, which will not be elaborated here.
[0305] In the first implementation, the session management network element can determine the user plane integrity security policy corresponding to the session according to the indication information.
[0306] In the second implementation, the session management network element can enable the integrity security protection of the session according to the subscription information of the terminal device.
[0307] In the third implementation, the session management network element can determine the user plane integrity security policy corresponding to the session according to the indication information and the subscription information of the terminal device.
[0308] Among them, the specific meaning of the subscription information, the acquisition method of the subscription information, and the example description of the above three implementation methods can refer to the relevant description of step S401 of method 400.
[0309] S620. The network device determines the first integrity security protection indication information according to the user plane integrity security policy.
[0310] Among them, the first integrity security protection indication information is used to indicate whether to activate the integrity security protection of the first DRB. That is to say, the first integrity security protection indication information is used to indicate whether to enable the integrity security protection of the session. The first DRB corresponds to the session in the above step S610. It should be understood that the session is used to transmit data between the terminal device and the core network, and the first DRB is used to transmit data between the terminal device and the network device.
[0311] Exemplarily, the values of the user plane integrity security policy include required, preferred, and not needed. For example, when the value of the user plane integrity security policy is required, the network device may determine the first integrity security protection indication information to indicate that integrity security protection is enabled for the session; when the value of the user plane integrity security policy is not needed, the network device may determine the first integrity security protection indication information to indicate that integrity security protection is not enabled for the session; when the value of the user plane integrity security policy is preferred, the network device may determine the first integrity security protection indication information to indicate that integrity security protection for the session is optionally enabled. The specific implementation method may refer to the relevant description of the above method 300.
[0312] Optionally, the present application does not specifically limit the manifestation form of the first integrity security protection indication information. The specific implementation may refer to the relevant description of step S420 of the above method 400.
[0313] S621, the network device activates or deactivates the integrity security protection of the first DRB according to the first integrity security protection indication information.
[0314] Exemplarily, when the first integrity security protection indication information indicates that integrity security protection is enabled for the session, the network device activates the integrity security protection of the first DRB; when the first integrity security protection indication information indicates that integrity security protection is not enabled for the session, the network device does not activate the integrity security protection of the first DRB; when the first integrity security protection indication information indicates that integrity security protection for the session is optionally enabled, the network device may activate the integrity security protection of the first DRB according to the local policy. The specific implementation method may refer to the relevant description of the above method 300.
[0315] Among them, activating the integrity security protection of the first DRB can be understood as: the network device configures the PDCP entity of the first DRB, configures the integrity security protection key and integrity security protection algorithm of the first DRB in the PDCP entity, activates the integrity check of the uplink user plane message and / or data carried by the first DRB, and activates the integrity security protection of the downlink user plane message and / or data carried by the first DRB; not activating the integrity security protection of the first DRB can be understood as: the network device configures the PDCP entity of the first DRB, but there is no need to configure the integrity security protection key and integrity security protection algorithm of the first DRB in the PDCP entity, nor to activate the integrity check of the uplink user plane message and / or data carried by the first DRB, and there is no need to activate the integrity security protection of the downlink user plane message and / or data carried by the first DRB.
[0316] S630. When the first link is disconnected, the network device determines whether to release the first DRB according to whether the integrity security protection of the first DRB is activated, or the network device determines whether to modify the integrity security protection status of the first DRB according to whether the integrity security protection of the first DRB is activated.
[0317] Exemplarily, when the integrity security protection of the first DRB is activated or turned on, the network device determines that there is no need to release the session and / or the first DRB.
[0318] Exemplarily, when the integrity security protection of the first DRB is not activated or not turned on, the network device determines to release the session and / or the first DRB.
[0319] Exemplarily, when the integrity security protection of the first DRB is activated or turned on, the network device determines that there is no need to modify the integrity security protection status of the session and / or the first DRB, that is, the integrity security protection status of the session and / or the first DRB is in the activated state at this time.
[0320] Exemplarily, when the activation of the integrity security protection of the first DRB is not activated or not turned on, the network device determines to modify the integrity security protection status of the session and / or the first DRB, that is, to modify it from the non-activated state to the activated state.
[0321] Among them, the first link is the link between the network device and the core network. For example, the first link can be a feeder link. The triggering condition for the disconnection of the first link can refer to the relevant description in step S511 of the above method 500, which will not be described here.
[0322] Optionally, when the first link is disconnected, the network device determines whether to release the first DRB according to the first integrity security protection indication information, or the network device determines whether to modify the integrity security protection status of the first DRB according to the first integrity security protection indication information.
[0323] In other words, when the first link is disconnected, the network device determines whether to release the first DRB according to the first integrity security protection indication information, or the network device determines whether to modify the integrity security protection status of the first DRB according to the first integrity security protection indication information.
[0324] Exemplarily, when the first integrity security protection indication information indicates that the integrity security protection of the first DRB is not activated or not enabled, the network device determines to release the session and / or the first DRB.
[0325] Exemplarily, when the first integrity security protection indication information indicates that the integrity security protection of the first DRB is activated or enabled, the network device determines not to release the session and / or the first DRB.
[0326] Exemplarily, when the first integrity security protection indication information indicates that the integrity security protection of the first DRB is not activated or not enabled, the network device determines to modify the integrity security protection status of the session and / or the first DRB to the active state.
[0327] Exemplarily, when the first integrity security protection indication information indicates that the integrity security protection of the first DRB is activated or enabled, the network device determines to maintain the integrity security protection status of the session and / or the first DRB as the active state.
[0328] For the above network device to release the session and / or the first DRB with unactivated or optionally activated integrity security protection, or the network device to modify the integrity security protection status of the session and / or the first DRB to the active state, the corresponding triggering conditions may include one or more of the following:
[0329] (1) The network device supports store-and-forward operation and the feeder link is disconnected;
[0330] (2) The network device enables store-and-forward operation and the feeder link is disconnected.
[0331] (3) The load of the network device is greater than the first threshold, where the first threshold can be predefined, such as protocol-defined, or the first threshold can be configured or pre-configured, and the present application does not limit this.
[0332] (4) The value of the user plane integrity security policy obtained by the satellite base station is preferred.
[0333] Optionally, the network device may store the identifier of the session and / or the first DRB; and / or, record that the integrity security protection status of the session and / or the first DRB before modification is the inactive state, for targeted subsequent restoration of the session and / or the first DRB and its integrity security protection status before modification.
[0334] Optionally, this application does not limit the timing of storing the identifier of the session and / or the first DRB; and / or, recording that the integrity security protection status of the session and / or the first DRB before modification is the inactive state. For example, the network device may, after sending the first message to the terminal device, that is, after step S640, and / or the network device may, before sending the second message to the terminal device. The specific implementation method may refer to the relevant description of step S660 below and will not be elaborated here for now.
[0335] S640, the network device sends a first message to the terminal device. Correspondingly, the terminal device receives the first message from the network device.
[0336] Among them, the first message is used to indicate the release result or modification result of the session and / or the first DRB. Optionally, the first message may be an RRC reconfiguration message, such as an RRC Reconfiguration message.
[0337] Exemplarily, in the case where the first integrity security protection indication information indicates that the first DRB deactivates integrity security protection, the release result indicates the release of the session and / or the first DRB.
[0338] Exemplarily, in the case where the first integrity security protection indication information indicates that the first DRB activates integrity security protection, the release result indicates that the session and / or the first DRB is not released.
[0339] Exemplarily, in the case where the first integrity security protection indication information indicates that the first DRB deactivates integrity security protection, the modification result indicates that the integrity security protection status of the session and / or the first DRB is modified to the active state.
[0340] Exemplarily, in the case where the first integrity security protection indication information indicates that the first DRB activates integrity security protection, the modification result indicates that the integrity security protection status of the first DRB remains in the active state.
[0341] S650, the terminal device performs integrity verification on the first message.
[0342] Exemplarily, the terminal device may determine whether the integrity verification passes by comparing the MAC value. The specific implementation method may refer to the relevant description of the above method 300 and will not be elaborated here.
[0343] For S660, when the integrity check passes, the terminal device determines whether to release the first DRB according to the release result, or determines whether to modify the integrity security protection status of the first DRB according to the modification result.
[0344] That is to say, after receiving the first message, when the integrity check of the first message passes, the terminal device can further determine whether to release the session and / or the first DRB, or whether to modify the integrity security protection status of the session and / or the first DRB.
[0345] For example, if the first message indicates to release the first DRB, the terminal device releases the session and / or the first DRB. Subsequently, the terminal device cannot send uplink data through the session and / or the first DRB, and cannot receive downlink data through the session and / or the first DRB. For another example, if the first message indicates not to release the first DRB, the terminal device does not release the session and / or the first DRB. Subsequently, the terminal device can still send uplink data through the session and / or the first DRB, and receive downlink data through the session and / or the first DRB. At the same time, whether the integrity security protection is enabled for the session and / or the first DRB depends on the user plane integrity security policy. The specific implementation method can refer to the relevant description of the above method 300.
[0346] For example, if the first message indicates to modify the integrity security protection status of the first DRB to the active state, the terminal device modifies the integrity security protection status of the session and / or the first DRB to the active state. For another example, if the first message indicates to keep the integrity security protection status of the first DRB as the active state, the terminal device does not need to modify the integrity security protection status of the session and / or the first DRB. Subsequently, the terminal device can send uplink data through the session and / or the first DRB, and receive downlink data through the session and / or the first DRB. It should be noted that the uplink and downlink data carried on the first DRB are integrity security protected and need to be integrity checked.
[0347] Optionally, when the integrity verification is passed, the terminal device may reconfigure the PDCP entity of the first DRB. Exemplarily, if the first message indicates to release the first DRB, the terminal device deletes the PDCP entity of the first DRB, including deleting the integrity security protection key and integrity security protection algorithm of the first DRB; if the first message indicates to modify the integrity security protection status of the first DRB to the active state, the terminal device configures the integrity security protection key and integrity security protection algorithm in the PDCP entity corresponding to the first DRB, which means that it is necessary to activate the integrity security protection of the uplink user plane message and / or data carried by the first DRB, and activate the integrity verification of the downlink user plane message and / or data carried by the first DRB.
[0348] Optionally, the terminal device may send a response message #1 to the network device, which is used to indicate that the terminal device has successfully released the first DRB, or is used to indicate that the terminal device has successfully modified the integrity security protection status of the first DRB to the active state. Optionally, if the first message in step S640 above is carried in the RRC reconfiguration message, the terminal device may send an RRC reconfiguration complete message to the network device. If the terminal device fails to successfully release the first DRB, or the terminal device fails to successfully modify the integrity security protection status of the first DRB to the active state, the terminal device may send a response message #2 to the network device. Optionally, the response message #2 may carry a failure cause value, for example, the failure cause value may be used to indicate that the first integrity security protection indication information verification fails, etc.
[0349] Optionally, for the scenario where the connection between the network device and the ground core network is disconnected, the network device performs integrity verification on the received uplink message and / or data, and stores the uplink data when the integrity verification is passed, and does not store or discards the uplink data when the integrity verification fails, which can ensure network communication security and reduce the risk of being attacked by DoS at the same time. The specific implementation method can refer to the relevant descriptions of the following method 700 or 800, which will not be described here first.
[0350] Optionally, in one implementation, when the first link is restored, the network device may send a second message to the terminal device. The second message is used to indicate the establishment of a second DRB. The second message includes second integrity security protection indication information, and the second integrity security protection indication information is used to indicate that the second DRB does not activate integrity security protection. The second DRB is used to carry data between the terminal device and the network device.
[0351] Optionally, the second DRB may be a DRB re - established between the terminal device and the network device, or the first DRB determined to be released in step S630 above, or the first DRB whose integrity security protection status is modified to the active state. This application does not limit this, and this implementation method is for facilitating normal communication between the subsequent terminal device and the network device.
[0352] Optionally, the second message includes the identifier of the first DRB, and / or, the second integrity security protection indication information is determined according to the integrity security protection status of the first DRB before modification being the inactive state. That is to say, the network device can determine that the integrity security protection of the re - established second DRB is not activated or not enabled according to the integrity security protection status of the first DRB recorded in step S630 above being the inactive state before modification. Optionally, the network device can also determine not to activate or not to enable the integrity security protection of the second DRB according to the user plane integrity security policy of the session. This application does not limit this.
[0353] It should be noted that in the above method 600, examples are given with user plane integrity security protection, user plane integrity security policy, or integrity verification, etc., which are only examples given for easy understanding and do not constitute a limitation to the technical solution of this application. Optionally, the technical solution of this application is equally applicable to user plane confidentiality security protection, user plane confidentiality security policy, or decryption operations, etc. The specific implementation method can refer to the above - related description and will not be described here again.
[0354] Based on the above - provided solution, the network device determines whether to release the first DRB or modify the integrity security protection status of the first DRB to the active state based on the user plane integrity security policy, so that the user plane data received by the network device subsequently is all protected by integrity security. In the scenario where the feeder link is disconnected, it is convenient for the satellite base station to only store the user plane data that passes the integrity verification, which can mitigate potential DoS risks and ensure network communication security.
[0355] Figure 7 It is a schematic flowchart of the communication method 700 provided by an embodiment of this application. As Figure 7 shown, taking the terminal device as the UE, the core network element as the AMF, and the SMF as the execution entity for interaction, this method can be regarded as a further refinement of the above - mentioned method 600, mainly for explaining the satellite base station and the UE releasing the session and / or DRB with inactive integrity security protection. It should be understood that Figure 7 the embodiment shown in Figure 6 can be coupled with the embodiment shown in Figure 6The content already described in the embodiments shown will not be elaborated further. The method includes the following steps. For the parts not described in detail, reference can be made to the above method 600 or existing protocols.
[0356] S701, UE1 and UE2 register to the network.
[0357] Optionally, the number of UEs registered to the same network is not limited in the embodiments of the present application. For ease of description, this implementation is described by taking two UEs (for example, UE1 and UE2) registering to the network, establishing a session, and determining whether to activate or deactivate the user plane integrity security protection of the session as an example. Among them, the process of establishing a session for UE1 and UE2, and the specific implementation of activating or deactivating the user plane integrity security protection of the session are similar, and the repeated parts will not be elaborated further below.
[0358] S702, UE1 sends a session establishment request message to the AMF. Correspondingly, the AMF receives the session establishment request message from UE1.
[0359] S703, the AMF sends a session creation context request message to the SMF. Correspondingly, the SMF receives the session creation context request message from the AMF.
[0360] S704, the SMF sends a session creation context response message to the AMF. Correspondingly, the AMF receives the session creation context response message from the SMF.
[0361] S705, the AMF sends a session resource establishment request message to the satellite base station. Correspondingly, the satellite base station receives the session resource establishment request message from the AMF.
[0362] S706, the satellite base station sends an RRC reconfiguration message #1 to UE1. Correspondingly, UE1 receives the RRC reconfiguration message #1 from the satellite base station.
[0363] S707, UE1 performs integrity verification on the RRC reconfiguration message #1.
[0364] S708, UE1 sends an RRC reconfiguration complete message #1 to the satellite base station. Correspondingly, the satellite base station receives the RRC reconfiguration complete message #1 from UE1.
[0365] S709, the satellite base station sends a session resource establishment response message to the AMF. Correspondingly, the AMF receives the session resource establishment response message from the satellite base station.
[0366] Among them, the specific implementation of the above steps S701 to S709 can refer to the relevant description of the above method 300.
[0367] The following steps are for the satellite base station to mitigate potential DoS risks and reduce the processing loads of UE2 and the satellite base station by releasing the session and / or DRB without integrity protection between the satellite base station and UE2 after the feeder link is disconnected. Additionally, after the feeder link is reconnected, the satellite base station triggers the addition of the previously released session and / or DRB without integrity protection to ensure the communication connection between UE2 and the satellite base station.
[0368] S710, The connection between the satellite base station and the terrestrial core network is disconnected, such as when the feeder link is disconnected. The trigger condition for the disconnection of the feeder link can refer to the relevant description in step S511 of the above method 500.
[0369] S711, The satellite base station releases the session and / or DRB without activated integrity protection.
[0370] It should be understood that the session and / or DRB without activated integrity protection means that the integrity protection of the session and / or DRB is not enabled, or in other words, the user plane data carried on the session and / or DRB is not protected by security and does not require integrity verification.
[0371] Among them, the trigger condition for the satellite base station to release the session and / or DRB without activated integrity protection can refer to the relevant description of the above method 600 and will not be elaborated here.
[0372] Exemplarily, the satellite base station can determine the session and / or DRB to be released according to the user plane integrity security policy received in step S705. For example, if the user plane integrity security policy indicates that integrity protection is enabled for session #1 between UE1 and the satellite base station (or one or more DRB #1 corresponding to the session), the satellite base station does not release session #1 or the one or more DRB #1; for another example, if the user plane integrity security policy indicates that integrity protection is not enabled or optionally enabled for session #2 between UE2 and the satellite base station (or one or more DRB #2 corresponding to the session), the satellite base station releases session #2 or the one or more DRB #2.
[0373] Furthermore, after the satellite base station determines one or more DRB #2 to be released, it can release the PDCP entities corresponding to the one or more DRB #2. That is to say, all uplink data subsequently received by the satellite base station is protected by integrity security. For example, the uplink data received through one or more DRB #1, so integrity verification needs to be performed on all received uplink data.
[0374] S712, The satellite base station sends RRC reconfiguration message #2 to UE2. Correspondingly, UE2 receives RRC reconfiguration message #2 from the satellite base station.
[0375] In one example, the RRC reconfiguration message #2 includes a session ID and / or a DRB ID, for example, to identify the session #2 or the one or more DRBs #2 for which integrity security protection is not activated in step S711 above. For example, the RRC reconfiguration message #2 may carry a drb-ToReleaseList cell, and the cell includes the DRB IDs for which integrity security protection is not activated, such as the DRB #2 ID.
[0376] It should be understood that before releasing the session #2 or the one or more DRBs #2, the integrity security protection activation status of the session #2 or the one or more DRBs #2 is in an unactivated state, or rather, the integrity security protection of the session #2 or the one or more DRBs #2 is not enabled, indicating that the user plane data carried on the session #2 or the one or more DRBs #2 has not undergone integrity security protection and no integrity check is required.
[0377] Optionally, the satellite base station stores the released session #2 ID and / or DRB #2 ID. Optionally, the stored session #2 ID and / or DRB #2 ID can be used to resume the session #2 and / or DRB #2 in subsequent step S720.
[0378] S713, UE2 releases the session and / or DRB for which integrity security protection is not activated.
[0379] In one example, the UE releases the corresponding session #2 and / or DRB #2 according to the session #2 ID and / or DRB #2 ID. For example, UE2 releases the PDCP entity corresponding to the DRB #2. That is, UE2 cannot transmit user plane data with the satellite base station through the session #2 and / or DRB #2.
[0380] It should be noted that since the user plane integrity security protection of the session #2 and / or DRB #2 is not enabled before releasing the session #2 and / or DRB #2, the RRC reconfiguration message #2 in step S712 above does not need to undergo integrity security protection, and correspondingly, UE2 does not need to perform an integrity check on the RRC reconfiguration message #2.
[0381] S714, UE2 sends an RRC reconfiguration complete message #2 to the satellite base station, and correspondingly, the satellite base station receives the RRC reconfiguration complete message #2 from the UE.
[0382] Exemplarily, the RRC reconfiguration complete message #2 is used to indicate that UE2 has released the session #2 and / or DRB #2.
[0383] S715. The UE1 sends uplink data to the satellite base station. Correspondingly, the satellite base station receives the uplink data from the UE1.
[0384] It should be noted that since integrity security protection is enabled for session #1 or DRB #1 between the UE1 and the satellite base station, the UE1 needs to perform integrity security protection on the uplink data before sending the uplink data. The specific implementation method can refer to the relevant description of the above method 300.
[0385] S716. The satellite base station performs integrity verification on the uplink data.
[0386] Exemplarily, the triggering conditions for the satellite base station to perform integrity verification on the uplink data include one or more of the following:
[0387] (1) The satellite base station supports store-and-forward operation and the feeder link is disconnected;
[0388] (2) The satellite base station enables store-and-forward operation and the feeder link is disconnected.
[0389] (3) The load of the satellite base station is greater than a first threshold. The first threshold can be predefined, such as protocol-defined, or the first threshold can be configured or pre-configured. This application does not make any limitations in this regard;
[0390] (4) The value of the integrity security policy received by the satellite base station is "preferred".
[0391] It should be noted that based on the above steps S711 and S713, the satellite base station and the UE have released the sessions and / or DRBs with unactivated integrity security protection, indicating that the uplink data sent by the UE is integrity-security-protected, which also means that the satellite base station needs to perform integrity verification on all the uplink data received in the above step S715. The specific implementation method of the integrity verification can refer to the relevant description of the above method 300 and will not be elaborated here.
[0392] S717. The satellite base station determines whether to store the uplink data according to the verification result.
[0393] Among them, the verification result includes verification success (pass) or verification failure (fail). It should be understood that the satellite base station stores the uplink data with successful integrity verification and discards the uplink data with failed integrity security protection verification.
[0394] S718. The connection between the satellite base station and the terrestrial core network is restored, such as the feeder link is restored.
[0395] Among them, the triggering conditions for the restoration of the feeder link include one or more of the following:
[0396] (1) The satellite base station flies to one side close to the ground gateway station, that is, the ground gateway station can receive the signal transmitted by the satellite base station;
[0397] (2) The communication condition between the satellite base station and the ground gateway station is good.
[0398] S719, the satellite base station sends the RRC reconfiguration message #3 to UE2. Correspondingly, UE2 receives the RRC reconfiguration message #3 from the satellite base station.
[0399] Exemplarily, the RRC reconfiguration message #3 is used to instruct UE2 to add (or re - establish) session #3 and / or DRB #3, and the session #3 and / or DRB #3 are used for transmitting data between UE2 and the satellite base station. Optionally, the session #3 and / or DRB #3 may be the same as or different from the above - released session #2 and / or DRB #2. This application does not make a limitation on this. For example, the drb - ToAddModList cell is carried in the RRC reconfiguration message #3, and the cell includes the session #3 ID and / or DRB #3 ID and their corresponding integrity security protection indication.
[0400] Optionally, the DRB #3 ID may be the already - released DRB ID (such as DRB #2 ID) stored by the satellite base station in the above step S712. At this time, the RRC reconfiguration message #3 is used to instruct UE2 to re - establish the previously - released session #2 and / or DRB #2, and according to the integrity security protection indication carried in the RRC reconfiguration message #3, the integrity security protection of the session #2 and / or DRB #2 is not enabled.
[0401] Exemplarily, the triggering conditions for the satellite base station to send the RRC reconfiguration message #3 include one or more of the following:
[0402] (1) The feeder link is restored;
[0403] (2) The self - load of the satellite base station is lower than the second threshold. The second threshold may be predefined, such as defined by the protocol, or the second threshold may be configured or pre - configured.
[0404] Optionally, the second threshold may be the same as or different from the first threshold in the above step S716. This application does not make a limitation on this.
[0405] S720, UE2 establishes a session and / or DRB according to the session ID and / or DRB ID.
[0406] Exemplarily, UE2 re - establishes Session #3 according to Session #3 ID, and determines that the integrity security protection of Session #3 is not enabled according to the integrity security protection indication corresponding to this Session #3; or rather, UE2 re - establishes DRB #3 according to DRB #3 ID, and determines that the integrity security protection of DRB #3 is not enabled according to the integrity security protection indication corresponding to this DRB #3, that is, UE2 configures the PDCP entity corresponding to this DRB #3. Since the integrity security protection of this DRB #3 is not activated, UE2 does not need to configure the integrity security protection key and integrity security protection algorithm in the PDCP entity.
[0407] It should be noted that, in the case of feeder link recovery in the above steps S718 - S720, it is an optional operation for the UE and the satellite base station to re - establish the above - released sessions and / or DRBs with unactivated integrity security protection. Among them, whether the satellite base station and the UE re - establish the sessions and / or DRBs depends on the satellite base station policy, and this application does not make any limitations in this regard.
[0408] It should be noted that whether the user - plane integrity security protection of one or more DRBs corresponding to a session is enabled is consistent in the above example. Optionally, whether the user - plane integrity security protection of multiple DRBs corresponding to a session can be different. For example, if the value of the integrity security policy established between the satellite base station and UE1 for Session #a is "preferred", it means that the integrity security protection of Session #a is optionally enabled, which also means that the user - plane integrity security protection of DRB #a and DRB #b corresponding to this Session #a is optionally enabled. Further, the satellite base station can determine to enable the user - plane integrity security protection of DRB #a and not enable the user - plane integrity security protection of DRB #b according to the local policy or its own load conditions. That is to say, the satellite base station determines that DRB #b needs to be released. Further, the satellite base station can notify UE1 to release DRB #b through an RRC re - configuration message. Subsequently, UE1 and the satellite base station can transmit data through DRB #a, and the transmitted data is protected by integrity security, while DRB #b cannot be used for data transmission between UE1 and the satellite base station. Further, in the case of feeder link recovery, the satellite base station can instruct UE1 to add (or re - establish) DRB #c and the user - plane integrity security protection of this DRB #c is not enabled. Optionally, this DRB #c can be the same as or different from DRB #b. The specific implementation method can refer to the relevant descriptions of steps S710 to S714 and steps S718 to S720 of method 700. For the sake of brevity, it will not be elaborated here.
[0409] In the solution provided by this application, in the scenario where the feeder link is disconnected, the satellite base station releases sessions and / or DRBs without integrity security protection, so that the uplink data subsequently received by the satellite base station is all protected by integrity security. The satellite base station thus avoids receiving uplink data without integrity security protection, alleviates potential DoS risks, and reduces the processing loads of the UE and the satellite base station. Additionally, after the feeder link is reconnected, the satellite base station triggers the addition of sessions and / or DRBs without integrity security protection to ensure normal communication between the UE and the satellite base station.
[0410] Compared with the Figure 7 solution shown above, the following combines Figure 8 , in the case where the feeder link between the satellite base station and the UE is disconnected, the satellite base station and the UE modify the integrity security protection status of the sessions and / or DRBs without activated integrity security protection to the activated state, so that the uplink data transmitted between the UE and the satellite base station is all protected by security, avoiding potential DoS risks and ensuring normal communication between the UE and the satellite base station at the same time.
[0411] Figure 8 is a schematic flowchart of a communication method 800 provided by an embodiment of this application. As Figure 8 shown, with the terminal device being the UE and the session management network element being the SMF as the execution entity for interaction, this method can be regarded as a further refinement of the above method 400. It should be understood that Figure 8 the embodiment shown Figure 6 can be coupled with the Figure 6 or Figure 7 shown embodiment and can be referenced to each other. Therefore, the relevant descriptions in the above method 600 also apply to this implementation manner. There may be the same or similar technical means between the two, and the content already described in the
[0412] S801, the UE registers to the network.
[0413] S802, the UE sends a session establishment request message to the AMF. Correspondingly, the AMF receives the session establishment request message from the UE.
[0414] S803, the AMF sends a session creation context request message to the SMF. Correspondingly, the SMF receives the session creation context request message from the AMF.
[0415] S804, the SMF sends a session creation context response message to the AMF. Correspondingly, the AMF receives the session creation context response message from the SMF.
[0416] In S805, the AMF sends a session resource establishment request message to the satellite base station. Correspondingly, the satellite base station receives the session resource establishment request message from the AMF.
[0417] In S806, the satellite base station sends RRC Reconfiguration Message #1 to the UE. Correspondingly, the UE receives RRC Reconfiguration Message #1 from the satellite base station.
[0418] In S807, the UE performs integrity verification on RRC Reconfiguration Message #1.
[0419] In S808, the UE sends an RRC Reconfiguration Complete Message #1 to the satellite base station. Correspondingly, the satellite base station receives the RRC Reconfiguration Complete Message #1 from the UE.
[0420] In S809, the satellite base station sends a session resource establishment response message to the AMF. Correspondingly, the AMF receives the session resource establishment response message from the satellite base station.
[0421] Among them, the specific implementation manners of the above steps S801 to S809 can refer to the relevant descriptions of steps S701 to S709 of the above method 700.
[0422] The following steps are for after the feeder link is disconnected. The satellite base station modifies the session and / or DRB without integrity security protection to activate integrity security protection, alleviates potential DoS risks, and reduces the processing loads of the UE and the satellite base station. In addition, after the feeder link is reconnected, the satellite base station triggers the DRB with the above-activated integrity security protection to resume the previous state without integrity security protection, ensuring the communication connection between the UE and the satellite base station.
[0423] In S810, the connection between the satellite base station and the terrestrial core network is disconnected, such as the feeder link is disconnected. Among them, the triggering condition for the disconnection of the feeder link can refer to the relevant description of step S511 of the above method 500.
[0424] In S811, the satellite base station modifies the integrity security protection status of the session and / or DRB without activated integrity security protection to the activated state.
[0425] It should be understood that the session and / or DRB without activated integrity security protection means that the integrity security protection of the session and / or DRB is not enabled, or in other words, the user plane data carried on the session and / or DRB is not protected by security and does not require integrity verification.
[0426] Among them, the triggering condition for the satellite base station to modify the integrity security protection status of the session and / or DRB without activated integrity security protection to the activated state can refer to the relevant description of the above method 600, which will not be elaborated here.
[0427] Exemplarily, the satellite base station may determine the sessions and / or DRBs for which the integrity security protection status needs to be modified according to the user plane integrity security policy received in step S805. For example, if the user plane integrity security policy indicates that integrity security protection is enabled for the session between the UE and the satellite base station (or one or more DRBs corresponding to the session), the satellite base station does not need to modify the integrity security protection status of the session or the one or more DRBs; for another example, if the user plane integrity security policy indicates that integrity security protection is not enabled or optionally enabled for the session between the UE and the satellite base station or one or more DRBs corresponding to the session, the satellite base station may modify the integrity security protection status of the session or the one or more DRBs to the active state.
[0428] Further, after the satellite base station determines the sessions and / or DRBs for which the integrity security protection status needs to be modified to the active state, it correspondingly modifies the PDCP entity corresponding to the DRB. For example, the satellite base station configures the integrity security protection key and the integrity security protection algorithm in the PDCP entity. At the same time, the satellite base station activates the integrity security protection for the downlink data on the DRB and activates the integrity check for the uplink data on the DRB. That is to say, all uplink data received by the satellite base station through the DRB subsequently is integrity security protected, so integrity checks need to be performed on the uplink data received through the DRB.
[0429] S812, the satellite base station sends the RRC reconfiguration message #2 to the UE. Correspondingly, the UE receives the RRC reconfiguration message #2 from the satellite base station.
[0430] In one example, the RRC reconfiguration message #2 includes the session ID and / or DRB ID, and the integrity security protection activation status of the session and / or DRB corresponding to the session ID and / or DRB ID is the inactive state. In addition, the RRC reconfiguration message #2 further includes the integrity security protection indication corresponding to the session and / or DRB, and the integrity security protection indication is used to instruct the UE to activate (or enable) the integrity security protection of the session and / or DRB. That is to say, the RRC reconfiguration message #2 is used to instruct the UE to modify the integrity security protection status of the session and / or DRB, that is, from the inactive state to the active state. For example, the drb-ToAddModList cell is carried in the RRC reconfiguration message #2, and the cell includes the session ID and / or DRB ID with inactive integrity security protection.
[0431] Optionally, the satellite base station records the session ID and / or DRB ID whose integrity security protection status has been modified as described above, or records that the integrity security protection status of the session and / or DRB before modification is in the inactive state, or records that the integrity security policy of the session and / or DRB before modification indicates that integrity security protection is not enabled, etc. Optionally, the recorded session ID and / or DRB ID are used to restore the integrity security protection status of the session and / or DRB to the inactive state in subsequent step S820.
[0432] S813. The UE modifies the integrity security protection status of the session and / or DRB to the active state.
[0433] That is to say, the integrity security protection status of the session / DRB before modification is in the inactive state, and the integrity security protection status of the session / DRB after modification is in the active state.
[0434] In one example, the UE modifies the integrity security protection status of the corresponding session and / or DRB to the active state according to the session ID and / or DRB ID. For example, the UE modifies the PDCP entity corresponding to the DRB, including: configuring an integrity security protection key and an integrity security protection algorithm in the PDCP entity. At the same time, the UE activates the integrity security protection of the uplink data on the DRB and activates the integrity check of the downlink data on the DRB. That is to say, all uplink data subsequently sent by the UE through the session and / or DRB are integrity-security protected, so the satellite base station needs to perform an integrity check on the uplink data received through the session and / or DRB.
[0435] S814. The UE sends an RRC reconfiguration complete message #2 to the satellite base station. Correspondingly, the satellite base station receives the RRC reconfiguration complete message #2 from the UE.
[0436] Exemplarily, the RRC reconfiguration complete message #2 is used to indicate that the UE has modified the integrity security protection status of the session and / or DRB to the active state.
[0437] S815. The UE sends uplink data to the satellite base station. Correspondingly, the satellite base station receives the uplink data from the UE.
[0438] It should be noted that since the UE has modified the integrity security protection status of the session and / or DRB with inactive integrity security protection to the active state, before sending uplink data, the UE needs to perform integrity security protection on the uplink data. The specific implementation method can refer to the relevant description of the above method 300.
[0439] S816. The satellite base station performs an integrity check on the uplink data.
[0440] S817, the satellite base station determines whether to store the uplink data according to the verification result.
[0441] S818, the connection between the satellite base station and the ground core network is restored, such as the feeder link is restored.
[0442] Among them, for the specific implementation manners of the above steps S816 - S818, the triggering conditions for integrity verification, and the triggering conditions for feeder link restoration, reference can be made to the relevant descriptions of steps S716 - S718 of the above method 700.
[0443] S819, the satellite base station sends the RRC reconfiguration message #3 to the UE. Correspondingly, the UE receives the RRC reconfiguration message #3 from the satellite base station.
[0444] Among them, the triggering conditions for the satellite base station to send the RRC reconfiguration message #3 can be referred to the relevant descriptions of step S719 of the above method 700.
[0445] Exemplarily, the RRC reconfiguration message #3 is used to instruct the UE to add (or re - establish) a session and / or DRB, and the added or re - established session and / or DRB are used for subsequent data transmission between the UE and the satellite base station. Optionally, the added or re - established session and / or DRB may be the same as or different from the session and / or DRB whose user - plane integrity security protection status is modified to the active state above. This application does not make a limitation on this. For example, the drb - ToAddModList cell is carried in the RRC reconfiguration message #3, and the cell includes the session ID and / or DRB ID, and their corresponding integrity security protection indications.
[0446] Optionally, the session ID is the session ID recorded by the satellite base station in the above step S812 for which the integrity security protection status has been modified. At this time, the RRC reconfiguration message #3 is used to instruct the UE to modify the integrity security protection status of the session and / or DRB, that is, from the active state to the non - active state, and the integrity security protection indication is used to indicate that the integrity security protection of the session and / or DRB is not enabled.
[0447] S820, the UE modifies the integrity security protection status of the session and / or DRB to the non - active state according to the session ID and / or DRB ID.
[0448] Exemplarily, the UE modifies the integrity security protection status of the corresponding session and / or DRB to the inactive state according to the session ID and / or DRB ID, that is, the integrity security protection of the session and / or DRB is not enabled. For example, the UE modifies the PDCP entity corresponding to the DRB. Since the integrity security protection of the DRB is not enabled, the UE does not need to configure the integrity security protection key and integrity security protection algorithm in the PDCP entity. For example, the satellite base station deletes the integrity security protection key and integrity security protection algorithm corresponding to the PDCP entity.
[0449] It should be noted that in the above steps S818 - S820 for the case of feeder link recovery, the UE and the satellite base station modifying the integrity security protection status of the session and / or DRB are optional operations. Whether the satellite base station and the UE modify the integrity security protection status of the session and / or DRB to the inactive state depends on the satellite base station policy, and this application does not make any limitations in this regard.
[0450] It should be noted that in the above example, whether the user plane integrity security protection of one or more DRBs corresponding to the session is enabled is consistent. Optionally, whether the user plane integrity security protection of multiple DRBs corresponding to the session is enabled can be different. For example, if the value of the integrity security policy established between the satellite base station and the UE for session #a is preferred, it means that the integrity security protection of session #a is optionally enabled, which also means that the integrity security protection of DRB #a and DRB #b corresponding to session #a is optionally enabled. Further, the satellite base station can determine to activate the integrity security protection of DRB #a and not activate the integrity security protection of DRB #b according to the local policy or its own load condition, that is, the satellite base station determines that it is necessary to modify the integrity security protection status of DRB #b to the active state. That is to say, the modified DRB #b enables the integrity security protection. Further, the satellite base station can notify the UE to modify the integrity security protection status of DRB #b to the active state through the RRC reconfiguration message. Subsequently, the UE and the satellite base station can transmit data through DRB #a and DRB #b, and the transmitted data is integrity security protected. Further, in the case of feeder link recovery, the satellite base station can instruct the UE to modify the integrity security protection status of DRB #b to the inactive state. The specific implementation method can refer to the relevant descriptions of steps S810 to S814 and steps S818 to S820 of method 800. For the sake of brevity, it will not be elaborated here.
[0451] In the solution provided by this application, in the scenario where the feeder link is disconnected, the satellite base station modifies the integrity security protection status of the session without integrity security protection and / or the DRB to the active state, so that the uplink data subsequently received by the satellite base station is all protected by integrity security. The satellite base station thus avoids receiving uplink data without integrity security protection, alleviating the potential DoS risk. Additionally, after the feeder link is reconnected, the satellite base station triggers the restoration of the session and / or DRB modified to enable integrity security protection to the inactive state, ensuring the communication connection between the UE and the satellite base station.
[0452] Figure 9 It is a schematic flowchart of the communication method 900 provided by an embodiment of this application. As Figure 9 shown, taking the terminal device as the UE, the core network element as the AMF, and the SMF as the execution entity for interaction, this method can be regarded as a further refinement of the above method 400 or 600, mainly for the description of the SMF determining the user plane integrity security policy according to the indication information and / or subscription information. It should be understood that Figure 9 the embodiment shown in Figures 4 to 8 can be coupled with the embodiment shown in Figures 4 to 8 and can be referred to each other. Therefore, the relevant descriptions in the above methods 400 to 800 also apply to this implementation manner. There may be the same or similar technical means between the two, and the content already described in the embodiment shown in
[0453] S901, the UE registers to the network.
[0454] S902, the UE sends a session establishment request message to the AMF. Correspondingly, the AMF receives the session establishment request message from the UE.
[0455] Among them, the specific implementation manners of the above steps S901 and S902 can refer to the relevant descriptions of the above method 300.
[0456] S903, the AMF sends a session creation context request message to the SMF. Correspondingly, the SMF receives the session creation context request message from the AMF.
[0457] Among them, the session creation context request message carries indication information, which is used to indicate that the base station is deployed on a satellite (abbreviated as satellite base station). Optionally, the indication information is also used to indicate that the satellite base station supports the store-and-forward feature.
[0458] Optionally, the AMF obtains one or more of the capability information, configuration information, or location information of the base station by local query or by sending a query message to the OAM or UDM. For specific interpretations, reference can be made to the relevant descriptions in the above method 500. By querying, the AMF can determine that the base station is deployed on a satellite. Optionally, the AMF can also determine that the satellite base station supports the store-and-forward feature.
[0459] S904. The SMF determines the user plane integrity security policy for the session based on the indication information and / or subscription information.
[0460] Optionally, the indication information can be obtained by the SMF from the AMF, or from the OAM or UDM.
[0461] Optionally, the subscription information can be obtained by the SMF from the UDM or PCF.
[0462] In the first example, the SMF determines the user plane integrity security policy for the session based on the indication information.
[0463] In the second example, the SMF determines the user plane integrity security policy based on the subscription information.
[0464] Among them, the subscription information of the UE is used to indicate whether the UE subscribes to the store-and-forward operation service.
[0465] Optionally, this application does not limit the order in which the SMF obtains the subscription information and the indication information.
[0466] In the third example, the SMF determines the user plane integrity security policy based on the indication information and the subscription information.
[0467] Among them, for the specific implementation methods in the above examples, reference can be made to the relevant descriptions in step S401 of the above method 400.
[0468] S905. The SMF sends a session creation context response message to the AMF. Correspondingly, the AMF receives the session creation context response message from the SMF.
[0469] S906. The AMF sends a session resource establishment request message to the satellite base station. Correspondingly, the satellite base station receives the session resource establishment request message from the AMF.
[0470] S907. The satellite base station sends an RRC reconfiguration message to the UE. Correspondingly, the UE receives the RRC reconfiguration message from the satellite base station.
[0471] It should be noted that for the value of the integrity security policy determined in step S904 above being preferred, the satellite base station can further determine the integrity security policy as required or not needed according to the local policy. The specific implementation method can refer to the relevant description of method 300 above.
[0472] S908, the UE performs integrity verification on the RRC reconfiguration message.
[0473] S909, the UE sends an RRC reconfiguration complete message to the satellite base station. Correspondingly, the satellite base station receives the RRC reconfiguration complete message from the UE.
[0474] Among them, the specific implementation methods of the above steps S905 to S909 can refer to the relevant description of method 300 above.
[0475] S910, the satellite base station sends a session resource establishment response message to the AMF. Correspondingly, the AMF receives the session resource establishment response message from the satellite base station.
[0476] S911, the connection between the satellite base station and the terrestrial core network is disconnected, such as the feeder link is disconnected. Among them, the triggering condition for the feeder link to be disconnected can refer to the relevant description of step S511 of method 500 above.
[0477] S912, the UE sends uplink data to the satellite base station. Correspondingly, the satellite base station receives the uplink data from the UE.
[0478] S913, the satellite base station performs integrity verification on the uplink data.
[0479] Among them, the triggering condition for the satellite base station to perform integrity verification on the uplink data, and the specific implementation method for the satellite base station to perform integrity verification on the uplink data can refer to the relevant description of step S513 of method 500 above, which will not be elaborated here.
[0480] S914, the satellite base station determines whether to store the uplink data according to the verification result.
[0481] Among them, the specific implementation method can refer to the relevant description of step S514 of method 500 above.
[0482] The solution provided in this application sets the integrity security policy through indication information, enabling the user plane data subsequently received by the satellite base station to be maximally protected by integrity security, alleviating potential DoS risks, and reducing the processing loads of the UE and the base station. In the scenario where the feeder link is disconnected, the satellite base station can only store the data that passes the integrity verification to ensure network security.
[0483] As described above in conjunction with Figures 1 to 9Embodiments of the communication method of the present application are described in detail. Next, embodiments of the communication device of the present application will be described in detail with reference to Figure 10 and Figure 11 It should be understood that the description of the device embodiments corresponds to the description of the method embodiments. Therefore, for parts not described in detail, reference may be made to the previous method embodiments.
[0484] Figure 10 FIG. is a schematic diagram of a communication device provided by an embodiment of the present application. As Figure 10 shown, the communication device 1000 includes a processing module 1010 and a communication module 1020. The communication device 1000 may be a terminal device, or a communication device applied to a terminal device or used in combination with a terminal device and capable of implementing the methods executed by the terminal device, such as a chip, a chip system, or a circuit; or, the communication device 1000 may be a network device, or a communication device applied to a network device or used in combination with a network device and capable of implementing the methods executed by the network device, such as a chip, a chip system, or a circuit; or, the communication device 1000 may be a session management network element, or a communication device applied to a session management network element or used in combination with a session management network element and capable of implementing the methods executed by the session management network element, such as a chip, a chip system, or a circuit.
[0485] Among them, the communication module may also be referred to as a transceiver module, a transceiver, a transceiver, or a transceiver device, etc. The processing module may also be referred to as a processor, a processing board, a processing unit, or a processing device, etc. Optionally, the communication module is used to perform the sending and receiving operations of the terminal device and the network device in the above method. The devices used to implement the receiving function in the communication module can be regarded as the receiving unit, and the devices used to implement the sending function in the communication module can be regarded as the sending unit, that is, the communication module includes a receiving unit and a sending unit.
[0486] When the communication device 1000 is applied to a terminal device, the processing module 1010 can be used to implement the processing function of the terminal device in the above embodiments, and the communication module 1020 can be used to implement the sending and receiving functions of the terminal device in the above embodiments.
[0487] When the communication device 1000 is applied to a network device, the processing module 1010 can be used to implement the processing function of the network device in the above embodiments, and the communication module 1020 can be used to implement the sending and receiving functions of the network device in the above embodiments.
[0488] When the communication device 1000 is applied to a session management network element, the processing module 1010 can be used to implement the processing function of the session management network element in the above embodiments, and the communication module 1020 can be used to implement the sending and receiving functions of the session management network element in the above embodiments.
[0489] In addition, it should be noted that the foregoing communication module and / or processing module can be implemented by a virtual module. For example, the processing module can be implemented by a software functional unit or a virtual device, and the communication module can be implemented by a software function or a virtual device. Alternatively, the processing module or the communication module can also be implemented by a physical device. For example, if the device is implemented by a chip / circuit (such as an integrated circuit or a logic circuit, etc.). The communication module can be an input / output circuit and / or a communication interface, performing input operations (corresponding to the foregoing receiving operations) and output operations (corresponding to the foregoing sending operations); the processing module is an integrated processor or a microprocessor or a circuit (such as an integrated circuit or a logic circuit, etc.).
[0490] The division of modules in this application is illustrative, only a logical function division. In actual implementation, there may be other division methods. In addition, in each example of this application, each functional module can be integrated in a processor, can also exist physically alone, or two or more modules can be integrated in one module. The above integrated modules can be implemented in the form of hardware or in the form of software functional modules.
[0491] Figure 11 It is a schematic diagram of another communication device provided by an embodiment of the present application. As Figure 11 shown, optionally, the communication device 2000 can be the foregoing terminal device, network device, or session management network element, or a chip or chip system for the foregoing terminal device, network device, or session management network element. Optionally, in this application, the chip system can be composed of chips or can include chips and other discrete devices.
[0492] The communication device 2000 can be used to implement the functions of any device (such as a terminal device, a network device, or a session management network element) in the communication system described in the foregoing examples. The communication device 2000 can include at least one processing circuit 2010. Optionally, the processing circuit 2010 is coupled to a memory, and the memory can be located inside the device, or the memory can be integrated with the processor, or the memory can also be located outside the device. For example, the communication device 2000 can also include at least one memory 2020. The memory 2020 stores the necessary computer programs, computer programs or instructions, and / or data in implementing any of the foregoing examples; the processing circuit 2010 may execute the computer programs stored in the memory 2020 to complete the methods in any of the foregoing examples.
[0493] The communication device 2000 may further include a transceiver circuit 2030, and the communication device 2000 can interact with other devices through the transceiver circuit 2030. Exemplarily, the transceiver circuit 2030 may be a transceiver, a circuit, a bus, a module, a pin, or other types of communication interfaces. When the communication device 2000 is a chip-like device or circuit, the transceiver circuit 2030 in the device 2000 may also be an input / output circuit, or an interface circuit, which can input information (or, receive information) and output information (or, transmit information). When the communication device 2000 is a network device or a terminal device, the transceiver circuit 2030 may be a transmitter, a receiver, or a transceiver, or a communication interface, which is not limited herein.
[0494] Wherein, the processing circuit 2010 may be one or more processors, or all or part of the processing circuits in one or more processors. The processing circuit 2010 is an integrated processor, microprocessor, integrated circuit, or logic circuit, etc., and the processor can determine the output information according to the input information.
[0495] The coupling in this application is an indirect coupling or communication connection between devices, units, or modules, which can be electrical, mechanical, or other forms, and is used for information interaction between devices, units, or modules. The processing circuit 2010 may cooperate with the memory 2020 and the transceiver circuit 2030. The specific connection medium between the processing circuit 2010, the memory 2020, and the transceiver circuit 2030 is not limited in this application.
[0496] Optionally, as Figure 11 shown, the processing circuit 2010, the memory 2020, and the transceiver circuit 2030 are interconnected through a bus 2040. Optionally, the bus may include buses of types such as an address bus, a data bus, and a control bus. In addition, for the sake of convenience of representation, Figure 11 only one bus 2040 is shown in
[0497] It should be understood that the processor mentioned in the embodiments of the present application may be the following device or a partial circuit for processing functions in the following device: a central processing unit (CPU), or may also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.
[0498] It should also be understood that the memory mentioned in the embodiments of the present application may be a volatile memory and / or a non-volatile memory. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable ROM (PROM), an erasable programmable ROM (EPROM), an electrically erasable programmable ROM (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM). For example, the RAM may be used as an external cache. By way of example and not limitation, the RAM includes the following various forms: static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM).
[0499] It should be noted that when the processor is a general-purpose processor, DSP, ASIC, FPGA, or other programmable logic device, discrete gate or transistor logic device, discrete hardware component, the memory (storage module) may be integrated in the processor.
[0500] It should also be noted that the memories described herein are intended to include, but are not limited to, these and any other suitable types of memories.
[0501] An embodiment of the present application also provides a computer-readable storage medium, on which computer instructions for implementing the methods executed by at least one of a terminal device, a network device, or a session management network element in the above method embodiments are stored.
[0502] An embodiment of the present application also provides a computer program product, including code or instructions, which when executed by a computer implement the methods executed by at least one of a terminal device, a network device, or a session management network element in the above method embodiments.
[0503] An embodiment of the present application also provides a communication system, which includes at least one of a core network element, a session management network element, or a network device in the above embodiments.
[0504] Optionally, the communication system further includes a terminal device in the above embodiments.
[0505] For the explanations and beneficial effects of the relevant content in any of the above-provided devices, reference may be made to the corresponding method embodiments provided above, and details will not be elaborated herein.
[0506] To facilitate understanding of the above embodiments provided by the present application, the following points are noted:
[0507] 1) In the present application, if there is no special description and logical conflict, the terms and / or descriptions between different embodiments are consistent and can be cross-referenced. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.
[0508] 2) In the present application, "at least one" means one or more, and "a plurality" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone, where A and B can be singular or plural. In the text description of the present application, the character " / " generally represents an "or" relationship between the associated objects before and after. "At least one (item)" or its similar expression refers to any combination of these items, including any combination of single item (item) or plural items (items). For example, at least one (item) of a, b, and c can represent: a, or, b, or, c, or, a and b, or, a and c, or, b and c, or, a, b, and c. Where a, b, and c can be single or multiple respectively.
[0509] 3) In this application, "first", "second", and various numerical numbers (e.g., #1, #2, etc.) are used for distinction for the convenience of description and do not limit the scope of the embodiments of this application. For example, they are used to distinguish different messages, etc., rather than to describe a specific order or sequence. It should be understood that the objects described in this way can be interchanged under appropriate circumstances so as to be able to describe solutions other than the embodiments of this application.
[0510] 4) In this application, descriptions such as "when...", "in the case of...", and "if" all refer to that the device will perform corresponding processing under a certain objective situation, which does not limit the time, and it is not required that the device must have a judgment action when implemented, nor does it mean that there are other limitations.
[0511] 5) In this application, "indicate" or "used to indicate" may include direct indication and indirect indication. When it is described that a certain indication information is used to indicate A, it may include that the indication information directly indicates A or indirectly indicates A, and it does not mean that A must be carried in the indication information.
[0512] The indication methods involved in the embodiments of this application should be understood to cover various methods that can enable the party to be indicated to obtain the information to be indicated. The information to be indicated can be sent as a whole or divided into multiple sub-information and sent separately, and the sending periods and / or sending timings of these sub-information can be the same or different. This application does not limit, for example, the sending method.
[0513] The "indication information" in the embodiments of this application can be explicit indication, that is, directly indicated by signaling, or obtained by combining other rules or other parameters or by derivation according to the parameters indicated by the signaling. It can also be implicit indication, that is, obtained according to rules or relationships, or other parameters, or by derivation. This application does not make specific limitations on this.
[0514] 6) In this application, "protocol" may refer to standard protocols in the communication field. For example, it may include 5G protocols, NR protocols, and related protocols applied to future communication systems. This application does not make limitations on this. "Pre-defined" may include pre-definition. For example, protocol definition. "Pre-configuration" can be achieved by pre-saving corresponding codes, tables, or other ways that can be used to indicate relevant information in the device. This application does not limit, for example, its implementation method.
[0515] 7) In this application, "communication" can also be described as "data transmission", "information transmission", "data processing", etc. "Transmission" includes "sending" and "receiving".
[0516] 8) In this application, "sending information to XX (device)" can be understood as the destination of the information being the device, which may include directly or indirectly sending information to the device. "Receiving information from XX (device), or receiving information originating from XX (device)" can be understood as the source of the information being the device, which may include directly or indirectly receiving information from the device. Necessary processing may be performed on the information between the source and the destination of the information transmission, such as format conversion, etc., but the destination can understand the valid information from the source.
[0517] In various embodiments of this application, the magnitude of the sequence numbers of the above processes does not indicate the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not impose any limitation on the implementation process of the embodiments of this application.
[0518] In this application, on the premise of no logical contradiction, the examples can be cited from each other. For example, the methods and / or terms between method embodiments can be cited from each other, the functions and / or terms between device embodiments can be cited from each other, and the functions and / or terms between device examples and method examples can be cited from each other.
[0519] It should be understood that in some of the above embodiments, mainly devices in the existing network architecture are used as examples for illustrative purposes, and the specific form of the device is not limited in the embodiments of this application. For example, devices that can achieve the same functions in the future are applicable to the embodiments of this application.
[0520] Those of ordinary skill in the art can realize that the units and algorithm steps of the examples described in conjunction with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.
[0521] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be described herein again.
[0522] In several embodiments provided in the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.
[0523] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0524] In addition, in each embodiment of the present application, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit.
[0525] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present application. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, ROM, RAM, magnetic disks, or optical discs that can store program codes.
[0526] As described above, the above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed in the present application can easily think of changes or substitutions, which should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A secure communication method, which is applied to the network device side, characterized in that, including: During the session establishment process of the terminal device, determine whether to activate the integrity security protection of the session according to the first information, where the first information is used to indicate whether the network device supports store-and-forward operations, and the session is used to transmit data between the terminal device and the core network; Send the first integrity security protection indication information to the terminal device, where the first integrity security protection indication information is used to indicate the activation result.
2. The method according to claim 1, wherein The determining whether to activate the integrity security protection of the session according to the first information includes: When the first information indicates that the network device supports store-and-forward operations, determine to activate the integrity security protection of the session; and / or, When the first information indicates that the network device does not support store-and-forward operations, determine not to activate the integrity security protection of the session.
3. The method according to claim 1 or 2, characterized in that, Before the determining whether to activate the integrity security protection of the session according to the first information, it includes: Obtain the user plane integrity security policy corresponding to the session, where the user plane integrity security policy is used to indicate whether to activate the integrity security protection of the session; The determining whether to activate the integrity security protection of the session according to the first information includes: Determine whether to activate the integrity security protection of the session according to the first information and the user plane integrity security policy.
4. The method according to claim 3, characterized in that The determining whether to activate the integrity security protection of the session according to the first information and the user plane integrity security policy includes: When the first information indicates that the network device does not support store-and-forward operations, and the user plane integrity security policy indicates that the session activates or optionally activates the integrity security protection, determine to activate the integrity security protection of the session; and / or, When the first information indicates that the network device does not support store-and-forward operations, and the user plane integrity security policy indicates that the session does not activate the integrity security protection, determine not to activate the integrity security protection of the session.
5. The method according to claim 3 or 4, characterized in that, The determining whether to activate the integrity security protection of the session according to the first information and the user plane integrity security policy includes: When the first information indicates that the network device supports store-and-forward operations, and the user plane integrity security policy indicates that the session activates or optionally activates the integrity security protection, determine to activate the integrity security protection of the session; and / or, When the first information indicates that the network device supports store-and-forward operations, and the user plane integrity security policy indicates that the session does not activate the integrity security protection, determine to activate the integrity security protection of the session.
6. A secure communication method, characterized in that, including: During the session establishment process of the terminal device, receive the first integrity security protection indication information from the network device, where the first integrity security protection indication information is used to indicate whether to activate the integrity security protection of the session, and the first integrity security protection indication information is determined according to the first information, where the first information is used to indicate whether the network device supports store-and-forward operations; Determine whether to activate the integrity security protection of the session according to the first integrity security protection indication information.
7. The method according to claim 6, wherein: when the first information indicates that the network device supports store-and-forward operations, the first integrity security protection indication information is used to indicate activation of the integrity security protection for the session; and / or when the first information indicates that the network device does not support store-and-forward operations, the first integrity security protection indication information is used to indicate non-activation of the integrity security protection for the session.
8. A secure communication method, which is applied to the network device side, and is characterized in that, The method includes: during the session establishment process of the terminal device, obtaining a user plane integrity security policy corresponding to the session, where the user plane integrity security policy is used to indicate whether to activate integrity security protection for the session, and the session is used to transmit data between the terminal device and the core network; determining first integrity security protection indication information according to the user plane integrity security policy, where the first integrity security protection indication information is used to indicate whether to activate integrity security protection for a first data radio bearer (DRB), the session corresponds to the first DRB, and the first DRB is used to carry data between the terminal device and the network device; activating or non-activating the integrity security protection for the first DRB according to the first integrity security protection indication information; when a first link is disconnected, determining whether to release the first DRB according to whether the integrity security protection for the first DRB is activated, or determining whether to modify the integrity security protection state of the first DRB according to whether the integrity security protection for the first DRB is activated, where the first link is a link between the network device and the core network; sending a first message to the terminal device, where the first message is used to indicate the release result or modification result of the first DRB.
9. The method according to claim 8, wherein The determining whether to release the first DRB according to whether the integrity security protection for the first DRB is activated includes: when the integrity security protection for the first DRB is not activated, determining to release the first DRB.
10. The method according to claim 8, wherein The determining whether to modify the integrity security protection state of the first DRB according to whether the integrity security protection for the first DRB is activated includes: when the integrity security protection for the first DRB is not activated, determining to modify the integrity security protection state of the first DRB to the activated state.
11. The method according to any one of claims 11 to 10, characterized in that, The method further includes: when the first link is restored, sending a second message to the terminal device, where the second message is used to indicate that the terminal device establishes a second DRB, the second message includes second integrity security protection indication information, and the second integrity security protection indication information is used to indicate that the second DRB does not activate integrity security protection, and the second DRB is used to carry data between the terminal device and the network device.
12. The method according to claim 11, wherein The second DRB is the first DRB; before sending the second message to the terminal device, and / or after sending the first message to the terminal device, the method further includes: Store the identifier of the first DRB; and / or, record that the integrity security protection status of the first DRB before modification is the inactive state; Wherein, the second message includes the identifier of the first DRB, and / or, the second integrity security protection indication information is determined according to the integrity security protection status of the first DRB before modification being the inactive state.
13. The method according to any one of claims 8 to 12, characterized in that The method further includes: Receive first data from the terminal device through the first DRB; When the first integrity security protection indication information indicates to activate the integrity security protection of the first DRB, perform integrity verification on the first data; When the integrity verification passes and the first link is disconnected, store the first data.
14. The method according to claim 13, characterized in that, Before storing the first data, the method further includes: When the integrity verification passes, determine whether the first link is disconnected.
15. The method according to claim 13, wherein Before performing integrity verification on the first data, the method further includes: Determine whether the first link is disconnected.
16. A secure communication method, characterized in that, Includes: When the first link is disconnected, receive a first message from the network device, the first message is used to indicate the release result or modification result of the first data radio bearer DRB, the release result is used to indicate whether to activate the first DRB, the modification result is used to indicate whether to modify the integrity security protection status of the first DRB, the release result or the modification result is determined according to whether the integrity security protection of the first DRB is activated, the first DRB is used to carry data between the terminal device and the network device, and the first link is the link between the network device and the core network; Determine whether to release the first DRB according to the release result, or determine whether to modify the integrity security protection status of the first DRB according to the modification result.
17. The method according to claim 16, wherein, When the first DRB does not activate integrity security protection, the release result indicates to release the first DRB.
18. The method according to claim 16, wherein, When the first DRB does not activate integrity security protection, the modification result indicates to modify the integrity security protection status of the first DRB to the active state.
19. A secure communication method, characterized in that, Includes: During the session establishment process of the terminal device, obtain indication information, the indication information is used to indicate that the network device is deployed on a satellite; Determine the user plane integrity security policy corresponding to the session according to the indication information, the user plane integrity security policy is used to indicate that the session activates or optionally activates integrity security protection; Send the user plane integrity security policy to the network device.
20. The method according to claim 19, wherein The indication information is further used to indicate that the network device supports store-and-forward operations.
21. The method according to claim 19 or 20, characterized in that, The method further includes: Obtain subscription information, the subscription information is used to indicate whether the terminal device subscribes to the store-and-forward operation service; Determining the user plane integrity security policy according to the indication information includes: Determine the user plane integrity security policy according to the indication information and the subscription information.
22. The method according to claim 21, wherein Determining the user plane integrity security policy according to the indication information and the subscription information includes: When the subscription information indicates that the terminal device subscribes to the store-and-forward operation service, determining that the integrity security policy is used to indicate session activation integrity security protection.
23. A communication device, characterized in that, Comprising at least one module, where the at least one module is configured to execute the method according to any one of claims 1 to 22.
24. A communication device, characterized in that, Comprising: A processor, where the processor is coupled to a memory; The processor is configured to execute a computer program stored in the memory, so that the device executes the method according to any one of claims 1 to 22.
25. A computer-readable storage medium, characterized in that, Computer program code or instructions are stored on the computer-readable storage medium, and when the computer program code or instructions run on a computer, the method according to any one of claims 1 to 22 is executed.