Communication method and device
By obtaining the required rate, residual rate and user plane security policy of the terminal equipment, accurately judge the opening conditions for user plane integrity protection, the contradiction between data transmission security and communication service requirements in 5G networks is solved, and the timeliness and security of data transmission is achieved.
Patent Information
- Application Number
- CN202510734334.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2020-04-30
- Publication Date
- 2025-08-29
AI Technical Summary
In 5G networks, the prior art cannot effectively solve the contradiction between the security of data transmission between user equipment (UE) and the network side and the communication service requirements, especially the problem of insufficient security when the maximum integrity protection rate is 64Kbps or abnormal performance when it is the full data rate.
By obtaining the required rate, residual rate and user plane security policy of the terminal device, determine whether to enable user plane integrity protection for user plane resources, and combine the used rate and maximum integrity protection rate to accurately determine whether user plane integrity protection is enabled to ensure the timeliness and security of data transmission.
It realizes that user surface integrity protection is enabled according to the UE's capabilities as needed under different speed conditions, avoiding the problems of insufficient data security or abnormal performance, and ensuring the timeliness and security of data transmission.
Smart Images

Figure CN120568331A_ABST
Abstract
Description
[0001] This application is a divisional application. The application number of the original application is 202010368371.0, and the original application date is April 30, 2020. The entire content of the original application is incorporated into this application by reference. Technical Field
[0002] The present application relates to the field of communication technology, and in particular to a communication method and device. Background Art
[0003] With the development of communication technologies, security issues in communication networks are gaining increasing attention, such as the interception, tampering, or forgery of communication content. To address these security issues, communication networks provide protection mechanisms such as confidentiality and integrity. To meet security requirements, fifth-generation (5G) networks have introduced the user plane integrity protection security feature.
[0004] Currently, the radio access network (RAN) determines whether to enable user plane integrity protection based on the maximum integrity protection rate reported by the user equipment (UE). Currently, only two values are defined for the maximum integrity protection rate reported by the UE: 64 kilobits per second (kbps) and the full-data-rate. When the maximum integrity protection rate reported by the UE is 64 Kbps, due to the low rate, user plane integrity protection cannot be enabled for data transmission between the UE and the RAN, resulting in the security of the transmitted data not being guaranteed. When the maximum integrity protection rate of the UE is the full-data-rate, user plane integrity protection may never be enabled for data transmission between the UE and the network. Uncontrolled activation of user plane integrity protection may cause UE performance anomalies, resulting in data transmission timeliness not meeting requirements.
[0005] In summary, how to ensure the security of data transmitted between the UE and the network side while taking into account the communication service needs of the UE is a technical problem that needs to be solved urgently. Summary of the Invention
[0006] The present application provides a communication method and apparatus for ensuring the security of data transmitted between a UE and a network side while taking into account the communication service needs of the UE.
[0007] In a first aspect, the present application provides a communication method, which includes obtaining a required rate, a remaining rate, and a user plane security policy of a first terminal device; determining whether to enable user plane integrity protection of a first user plane resource based on the required rate, the remaining rate, and the user plane security policy; wherein the required rate is used to indicate the rate required for the first user plane resource requested to be established by the first terminal device, the remaining rate is determined based on the used rate of the first terminal device and the maximum integrity protection rate of the first terminal device, the used rate is used to indicate the rate used by the second user plane resource established by the first terminal device, and the maximum integrity protection rate is used to indicate the maximum rate of the first terminal device after enabling user plane integrity protection; the user plane security policy includes user plane integrity protection enabled, user plane integrity protection optionally enabled, or user plane integrity protection disabled.
[0008] Based on this solution, whether to enable the user plane integrity protection of the first user plane resource is determined according to the required rate, remaining rate, and maximum integrity protection rate of the first user plane resource to be established, so that the conditions for enabling the user plane integrity protection of the first user plane resource can be determined more accurately. This ensures the timeliness and security of the transmission data of the terminal device as much as possible. That is, the user plane integrity protection of the terminal device and the network side can be enabled on demand according to the capabilities of the UE, which helps to avoid the situation where the user plane integrity protection of the terminal device and the network side is always turned off when the maximum integrity protection rate of the terminal device is 64Kpbs, resulting in the security of the transmitted data not being guaranteed, or the user plane integrity protection of the terminal device and the network side is always turned on when the maximum integrity protection rate of the terminal device is the full data rate, resulting in abnormal terminal performance.
[0009] In a possible implementation, the second user plane resource includes a user plane resource with user plane integrity protection enabled among the user plane resources established by the first terminal device.
[0010] By determining the usage rate of the second user plane resource with user plane integrity protection enabled in the established user plane resources, the remaining rate of the first terminal device can be accurately determined.
[0011] In one possible implementation, the used rate of the first terminal device can be determined based on a rate parameter; the rate parameter includes any one or a combination of any two of the following: (a) the maximum bit rate of the protocol data unit (PDU) session aggregation of the second user plane resource; (b) the maximum bit rate of the aggregation of the terminal devices of the first terminal device; (c) the maximum flow bit rate of the quality of service (QoS) Qos flow of the guaranteed bit rate (GBR) of the second user plane resource; (d) the guaranteed bit rate of the quality of service (QoS) Qos flow of the GBR of the second user plane resource; and (e) the real-time rate of the second user plane resource.
[0012] Four possible implementations of determining the used rate are shown below by way of example.
[0013] Implementation method 1: the maximum value of the used rate.
[0014] In one possible implementation, the sum of the maximum bit rate of all PDU sessions aggregated and the maximum flow bit rate of all GBR QoS flows is determined as the used rate; or the sum of the maximum bit rate of the terminal device aggregated and the maximum flow bit rate of all GBR QoS flows is determined as the used rate.
[0015] In the first implementation described above, the utilized rate is calculated based on the assumption that the second user plane resources are all transmitting data at the maximum bit rate. Therefore, the remaining rate represents the terminal's remaining data transmission capability under extreme conditions, thereby ensuring the timeliness of data transmission by the first terminal device. In other words, this first implementation determines whether to enable user plane integrity protection for the first user plane resources based on the service availability of the first terminal device.
[0016] Implementation method 2: the minimum value of the used rate.
[0017] In a possible implementation, the sum of the guaranteed bit rates of all GBR QoS flows is determined as the used rate.
[0018] In the second implementation described above, the utilized rate is calculated based on the assumption that the second user plane resources all transmit data at the minimum bit rate. This ensures the security of data transmitted by the first terminal device to the greatest extent possible. In other words, this second implementation determines whether to enable user plane integrity protection for the first user plane resources based on the security of data transmitted by the first terminal device.
[0019] Implementation method three, the used rate is between the maximum value determined in the above implementation method one and the minimum value determined in the above implementation method two.
[0020] In a possible implementation, the sum of the maximum bit rate aggregated across all PDU sessions and the guaranteed bit rates of all GBR QoS flows is determined as the used rate.
[0021] In the third implementation, the utilized rate is calculated based on the assumption that data is transmitted at a moderate rate after the second user plane resource usage is adjusted. Thus, the remaining rate represents the combined rate of the first terminal device, thereby ensuring both the availability of the first terminal device's communication services and the security of data transmitted between the first terminal device and the network.
[0022] Implementation method 4: real-time monitoring of the real-time rate of the second user plane resource.
[0023] In a possible implementation, the sum of the monitored real-time rates of all second user plane resources is determined as the used rate of the first terminal device.
[0024] With the fourth implementation, the utilized rate is calculated based on the assumption that the second user plane resource is transmitting data at the real-time rate. This means the remaining rate represents the precise rate of the terminal. This means the decision on whether to enable user plane integrity protection is based on the most accurate data. This ensures both the availability and timeliness of the data transmitted by the first terminal device and the security of the data transmitted by the first terminal device.
[0025] In one possible implementation, when the user plane security policy includes enabling or optionally enabling user plane integrity protection, if the remaining rate is greater than or equal to the required rate, a first indication message is sent to the first terminal device, and the first indication message is used to indicate enabling user plane integrity protection of the first user plane resource.
[0026] Through this communication method, the security of data transmission by the first terminal device can be guaranteed, and the timely transmission of data of the communication service can be guaranteed.
[0027] In one possible implementation, when the user plane security policy includes enabling user plane integrity protection, if the remaining rate is less than the required rate, a third user plane resource is obtained, the user plane security policy of the third user plane resource is that user plane integrity protection is optionally enabled, and user plane integrity protection has been enabled for the third user plane resource, and the used rate of the third user plane resource is greater than or equal to the difference between the required rate and the remaining rate, a second indication message is sent to the first terminal device, the second indication message is used to indicate that user plane integrity protection of the first user plane resource is enabled, and is used to indicate that user plane integrity protection of the third user plane resource is not enabled.
[0028] Through this communication method, the security of the data corresponding to the first user plane resource for which user plane integrity protection must be enabled can be guaranteed, that is, the security of the data transmitted by the first terminal device can be protected as much as possible, and the timely transmission of communication service data can be guaranteed.
[0029] In one possible implementation, when the user plane security policy includes optional activation of user plane integrity protection, if the remaining rate is less than the required rate, a third indication message is sent to the first terminal, where the third indication is used to indicate that user plane integrity protection of the first user plane resource is not activated.
[0030] Through this communication method, timely transmission of data of the communication service of the first terminal device can be guaranteed as much as possible.
[0031] In one possible implementation, the method can be applied to a wireless access network device; the wireless access network device can receive a required rate, a maximum integrity protection rate, and a user plane security policy of a first terminal device from a session management function network element; the session management function network element obtains the required rate of the first terminal device from a policy control function network element, and obtains the maximum integrity protection rate from the first terminal device; obtains the used rate from the context of the first terminal device; and determines the remaining rate based on the maximum integrity protection rate and the used rate.
[0032] In one possible implementation, the method can be applied to a dual-connected master node; the master node can obtain the required rate of the first terminal device from the policy control function network element, obtain the maximum integrity protection rate of the first terminal device from the session management function network element, and obtain the used rate from the context of the first terminal device; and determine the remaining rate based on the maximum integrity protection rate and the used rate.
[0033] Furthermore, the primary node sends fourth indication information to the dual-connected secondary node, where the fourth indication information is used by the secondary node to determine whether to enable user plane integrity protection.
[0034] Through this communication method, the secondary node can also accurately determine whether to enable user plane integrity protection for the first user plane resource.
[0035] In one possible implementation, the method can be applied to a wireless access network device during a switching process; the wireless access network device during the switching process can obtain a switching request message from a source wireless access network device, the switching request message including the required rate of the first terminal device, the user plane security policy, the maximum integrity protection rate, and the used rate; and determine the remaining rate based on the maximum integrity protection rate and the used rate.
[0036] In one possible implementation, the method can be applied to a wireless access network device during a radio resource control (RRC) connection recovery process; the wireless access network device during the RRC connection recovery process can obtain a context response message of a first terminal device from a target wireless access network device, and the context response message of the first terminal device includes the required rate, user plane security policy, maximum integrity protection rate, and used rate of the first terminal device; and determine the remaining rate based on the maximum integrity protection rate and the used rate.
[0037] In one possible implementation, the method may be applied to a dual-connected secondary node; the secondary node may receive the required rate, maximum integrity protection rate, used rate, and user plane security policy sent from the dual-connected primary node; and determine the remaining rate based on the maximum integrity protection rate and the used rate.
[0038] Through this communication method, the secondary node can also accurately determine whether to enable user plane integrity protection for the first user plane resource.
[0039] In a possible implementation, the difference between the maximum integrity protection rate and the used rate may be determined as the remaining rate.
[0040] In a possible implementation, the method may be applied to a dual-connected secondary node; the secondary node receives a required rate, a residual rate, and a user plane security policy from a primary node.
[0041] When the method is applied to a dual-connected secondary node, the secondary node may further send a rate used for enabling user plane integrity protection of the first user plane resource to the dual-connected primary node.
[0042] Through this communication method, the main node can easily obtain and record the rate used for the user plane integrity protection of the first user plane resource. When a new user plane resource is created next time, the rate used for the user plane integrity protection of the first user plane resource is the second user plane resource, thereby facilitating the determination of the used rate of the first terminal device.
[0043] In a possible implementation, the method may be applied to a second terminal device, and the second terminal device may receive the remaining rate and the user plane security policy from the first terminal device, and obtain the required rate from the context of the first terminal device.
[0044] In a second aspect, the present application provides a communication method that can be executed by a dual-connected primary node. The method includes obtaining a used rate, a required rate, a maximum integrity protection rate, and a user plane security policy of a first terminal device; the required rate is used to indicate the rate required by the first user plane resource requested to be established by the first terminal device, the used rate is used to indicate the rate used by the second user plane resource established by the first terminal device, the maximum integrity protection rate is used to indicate the maximum rate after the first terminal device turns on user plane integrity protection, and the user plane security policy includes user plane integrity protection turned on, user plane integrity protection optional turned on, or user plane integrity protection turned off; determining a remaining rate based on the maximum integrity protection rate and the used rate; and sending the remaining rate, required rate, and user plane security policy to the dual-connected secondary node.
[0045] In a possible implementation, a rate used by the secondary node to enable user plane integrity protection of the first user plane resource may also be obtained and recorded.
[0046] Through this communication method, the main node can easily obtain and record the rate used for the user plane integrity protection of the first user plane resource. When a new user plane resource is created next time, the rate used for the user plane integrity protection of the first user plane resource is the second user plane resource, thereby facilitating the determination of the used rate of the first terminal device.
[0047] In a third aspect, the present application provides a communication method, which can be executed by a first terminal device, and the method includes obtaining the used rate, maximum integrity protection rate and user plane security policy of the first terminal device; determining the remaining rate based on the maximum integrity protection rate and the used rate; sending the remaining rate and the user plane security policy to the second terminal device, the used rate is used to indicate the rate used by the second user plane resource established by the first terminal device, the maximum integrity protection rate is used to indicate the maximum rate after the first terminal device turns on user plane integrity protection, and the user plane security policy includes user plane integrity protection turned on, user plane integrity protection optional turned on, or user plane integrity protection turned off.
[0048] In a fourth aspect, the present application provides a communication device having the functionality to implement the first aspect or any one of the first aspects, or for implementing the functionality in the second aspect or any one of the second aspects. The functionality can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more units or modules corresponding to the functionality described above.
[0049] In one possible implementation, the communication device may include a transceiver and a processor. The processor may be configured to support the communication device in performing the corresponding functions of the first or second aspect described above, and the transceiver may be configured to support communication between the communication device and wireless access network equipment, terminal devices, and the like. The transceiver may be a standalone receiver, a standalone transmitter, a transceiver with integrated transceiver functions, or an interface circuit. Optionally, the communication device may also include a memory, which may be coupled to the processor and store program instructions and data necessary for the communication device.
[0050] Among them, the transceiver cooperates with the processor to obtain the required rate, remaining rate and user plane security policy of the first terminal device, the required rate is used to indicate the rate required for the first user plane resource requested to be established by the first terminal device, the remaining rate is determined based on the used rate of the first terminal device and the maximum integrity protection rate of the first terminal device, the used rate is used to indicate the rate used by the second user plane resource established by the first terminal device, and the maximum integrity protection rate is used to indicate the maximum rate of the first terminal device after turning on user plane integrity protection; the user plane security policy includes user plane integrity protection turned on, user plane integrity protection optional turned on or user plane integrity protection turned off; the processor is used to determine whether to turn on user plane integrity protection for the first user plane resource based on the required rate, remaining rate and user plane security policy.
[0051] In a possible implementation, the second user plane resource includes a user plane resource with user plane integrity protection enabled among the user plane resources established by the first terminal device.
[0052] In one possible implementation, the processor is further used to determine the used rate of the first terminal device based on a rate parameter; wherein the rate parameter includes any one or a combination of any two of the following: the maximum bit rate of the protocol data unit PDU session aggregation of the second user plane resource; the maximum bit rate of the aggregation of the terminal devices of the first terminal device; the maximum flow bit rate of the Qos flow of the GBR of the second user plane resource; the guaranteed bit rate of the Qos flow of the GBR of the second user plane resource; and the real-time rate of the second user plane resource.
[0053] In one possible implementation, the processor is specifically used to determine the maximum bit rate of all PDU sessions aggregated and the sum of the maximum flow bit rates of all GBR's QoS flows as the used rate; or, to determine the maximum bit rate of the terminal device aggregated and the sum of the maximum flow bit rates of all GBR's QoS flows as the used rate.
[0054] In a possible implementation manner, the processor is specifically configured to: determine the sum of the guaranteed bit rates of all GBR QoS flows as the used rate.
[0055] In a possible implementation manner, the processor is specifically configured to: determine the sum of the maximum bit rate of all PDU sessions aggregated and the guaranteed bit rates of all GBR QoS flows as the used rate.
[0056] In one possible implementation, when the user plane security policy includes enabling or optionally enabling user plane integrity protection, the processor is specifically used to: if the remaining rate is greater than or equal to the required rate, send a first indication message to the first terminal device, and the first indication message is used to indicate enabling user plane integrity protection of the first user plane resource.
[0057] In one possible implementation, when the user plane security policy includes enabling user plane integrity protection, the processor is specifically used to: if the remaining rate is less than the required rate, obtain a third user plane resource, the user plane security policy of the third user plane resource is that user plane integrity protection is optionally enabled, and the user plane integrity protection is enabled for the third user plane resource, and the used rate of the third user plane resource is greater than or equal to the difference between the required rate and the remaining rate, send a second indication message to the first terminal device, the second indication message is used to indicate that user plane integrity protection of the first user plane resource is enabled, and is used to indicate that user plane integrity protection of the third user plane resource is not enabled.
[0058] In one possible implementation, when the user plane security policy includes optional activation of user plane integrity protection, the processor is specifically used to: if the remaining rate is less than the required rate, send a third indication message to the first terminal, where the third indication is used to indicate that user plane integrity protection of the first user plane resource is not activated.
[0059] In one possible implementation, the communication device is applied to a wireless access network device; the transceiver is specifically used to: receive a required rate, a maximum integrity protection rate, and a user plane security policy of a first terminal device from a session management function network element; the session management function network element obtains the required rate of the first terminal device from the policy control function network element, and obtains the maximum integrity protection rate from the first terminal device; obtains the used rate from the context of the first terminal device; and the processor is specifically used to determine the remaining rate based on the maximum integrity protection rate and the used rate.
[0060] In a possible implementation, the communication device is applied to a dual-connected primary node; the transceiver is further used to: send fourth indication information to the dual-connected secondary node, and the fourth indication information is used by the secondary node to determine whether to enable user plane integrity protection.
[0061] In one possible implementation, the communication device is applied to a wireless access network device during a switching process; the transceiver is specifically used to: obtain a switching request message from a source wireless access network device, the switching request message including the required rate, user plane security policy, maximum integrity protection rate and used rate of the first terminal device; the processor is specifically used to: determine the remaining rate based on the maximum integrity protection rate and the used rate.
[0062] In one possible implementation, the communication device is applied to a wireless access network device in the RRC connection recovery process; the transceiver is specifically used to: obtain a context response message of the first terminal device from the target wireless access network device, the context response message of the first terminal device including the required rate, user plane security policy, maximum integrity protection rate and used rate of the first terminal device; the processor is specifically used to: determine the remaining rate based on the maximum integrity protection rate and the used rate.
[0063] In one possible implementation, the communication device is applied to a dual-connected secondary node; the transceiver is specifically used to: receive the required rate, maximum integrity protection rate, used rate and user plane security policy sent from the dual-connected primary node; the processor is specifically used to: determine the remaining rate based on the maximum integrity protection rate and the used rate.
[0064] In a possible implementation manner, the processor is specifically configured to: determine a difference between a maximum integrity protection rate and a used rate as a remaining rate.
[0065] In a possible implementation, the communication device is applied to a dual-connected secondary node; the transceiver is specifically configured to: the secondary node receives a required rate, a remaining rate, and a user plane security policy from the primary node.
[0066] In a possible implementation manner, the transceiver is further configured to: send, to the dual-connection master node, a rate used for enabling user plane integrity protection of the first user plane resource.
[0067] In a possible implementation, the communication apparatus is applied to the second terminal device; the transceiver is specifically used to: receive the remaining rate and user plane security policy from the first terminal device; and obtain the required rate from the context of the first terminal device.
[0068] In a fifth aspect, the present application provides a communication device for implementing the first aspect or any one of the methods in the first aspect, or for implementing the second aspect or any one of the methods in the second aspect, including corresponding functional modules, respectively used to implement the steps in the above methods. The functions can be implemented by hardware or by hardware executing corresponding software implementations. The hardware or software includes one or more modules corresponding to the above functions.
[0069] In one possible embodiment, the communication device may include a processing module and a transceiver module, wherein the transceiver module cooperates with the processing module to obtain the required rate, remaining rate and user plane security policy of the first terminal device, the required rate is used to indicate the rate required for the first user plane resource requested to be established by the first terminal device, the remaining rate is determined based on the used rate of the first terminal device and the maximum integrity protection rate of the first terminal device, the used rate is used to indicate the rate used by the second user plane resource established by the first terminal device, and the maximum integrity protection rate is used to indicate the maximum rate of the first terminal device after user plane integrity protection is turned on; the user plane security policy includes user plane integrity protection turned on, user plane integrity protection optional turned on or user plane integrity protection turned off; the processing module is used to determine whether to turn on user plane integrity protection for the first user plane resource based on the required rate, remaining rate and user plane security policy.
[0070] In a possible implementation, the second user plane resource includes a user plane resource with user plane integrity protection enabled among the user plane resources established by the first terminal device.
[0071] In one possible implementation, the processing module is also used to determine the used rate of the first terminal device based on the rate parameter; wherein the rate parameter includes any one or a combination of any two of the following: the maximum bit rate of the protocol data unit PDU session aggregation of the second user plane resource; the maximum bit rate of the aggregation of the terminal devices of the first terminal device; the maximum flow bit rate of the quality of service Qos flow with a guaranteed bit rate GBR; the guaranteed bit rate of the quality of service Qos flow with a guaranteed bit rate GBR; and the real-time rate of the second user plane resource.
[0072] In one possible implementation, the processing module is specifically used to determine the maximum bit rate of all PDU sessions aggregated and the sum of the maximum flow bit rates of all GBR's QoS flows as the used rate; or, to determine the maximum bit rate of the terminal device aggregated and the sum of the maximum flow bit rates of all GBR's QoS flows as the used rate.
[0073] In a possible implementation manner, the processing module is specifically configured to determine the sum of the guaranteed bit rates of all GBR QoS flows as the used rate.
[0074] In a possible implementation manner, the processing module is specifically configured to determine the used rate as the sum of the maximum bit rate of all PDU sessions aggregated and the guaranteed bit rates of all GBR QoS flows.
[0075] In one possible implementation, when the user plane security policy includes enabling or optionally enabling user plane integrity protection, the processing module is specifically used to: if the remaining rate is greater than or equal to the required rate, send a first indication message to the first terminal device, and the first indication message is used to indicate enabling user plane integrity protection of the first user plane resource.
[0076] In one possible implementation, when the user plane security policy includes enabling user plane integrity protection, the processing module is specifically used to: if the remaining rate is less than the required rate, obtain a third user plane resource, the user plane security policy of the third user plane resource is that user plane integrity protection is optionally enabled, and the user plane integrity protection is enabled for the third user plane resource, and the used rate of the third user plane resource is greater than or equal to the difference between the required rate and the remaining rate, send a second indication message to the first terminal device, the second indication message is used to indicate that user plane integrity protection of the first user plane resource is enabled, and is used to indicate that user plane integrity protection of the third user plane resource is not enabled.
[0077] In one possible implementation, when the user plane security policy includes optional activation of user plane integrity protection, the processing module is specifically used to: if the remaining rate is less than the required rate, send a third indication message to the first terminal, and the third indication is used to indicate that user plane integrity protection of the first user plane resource is not activated.
[0078] In one possible implementation, the communication device is applied to a wireless access network device; the transceiver module is specifically used to: receive the required rate, maximum integrity protection rate and user plane security policy of a first terminal device from a session management function network element; the session management function network element obtains the required rate of the first terminal device from the policy control function network element, and obtains the maximum integrity protection rate from the first terminal device; obtains the used rate from the context of the first terminal device; and the processing module is specifically used to: determine the remaining rate based on the maximum integrity protection rate and the used rate.
[0079] In a possible implementation, the communication device is applied to a dual-connected primary node; the transceiver module is further used to: send fourth indication information to the dual-connected secondary node, and the fourth indication information is used by the secondary node to determine whether to enable user plane integrity protection.
[0080] In one possible implementation, the communication device is applied to a wireless access network device during a switching process; the transceiver module is specifically used to: obtain a switching request message from a source wireless access network device, the switching request message including the required rate of the first terminal device, the user plane security policy, the maximum integrity protection rate and the used rate; the processing module is specifically used to: determine the remaining rate based on the maximum integrity protection rate and the used rate.
[0081] In one possible implementation, the communication device is applied to a wireless access network device in the RRC connection recovery process; the transceiver module is specifically used to: obtain a context response message of the first terminal device from the target wireless access network device, the context response message of the first terminal device including the required rate, user plane security policy, maximum integrity protection rate and used rate of the first terminal device; the processing module is specifically used to: determine the remaining rate based on the maximum integrity protection rate and the used rate.
[0082] In one possible implementation, the communication device is applied to a dual-connected secondary node; the transceiver module is specifically used to: receive the required rate, maximum integrity protection rate, used rate and user plane security policy sent from the dual-connected primary node; the processing module is specifically used to: determine the remaining rate based on the maximum integrity protection rate and the used rate.
[0083] In a possible implementation manner, the processing module is specifically configured to determine a difference between the maximum integrity protection rate and the used rate as the remaining rate.
[0084] In a possible implementation, the communication device is applied to a dual-connected secondary node; the transceiver module is specifically configured to: the secondary node receives a required rate, a remaining rate, and a user plane security policy from the primary node.
[0085] In a possible implementation, the transceiver module is further configured to: send, to the dual-connected master node, a rate used for enabling user plane integrity protection of the first user plane resource.
[0086] In one possible implementation, the communication device is applied to the second terminal device; the transceiver module is specifically used to: receive the remaining rate and user plane security policy from the first terminal device; and obtain the required rate from the context of the first terminal device.
[0087] In a sixth aspect, the present application provides a computer-readable storage medium, which stores a computer program or instruction. When the computer program or instruction is executed by a communication device, the communication device executes the method in the above-mentioned first aspect or any possible implementation of the first aspect, or the communication device executes the method in the second aspect or any possible implementation of the second aspect.
[0088] In the seventh aspect, the present application provides a computer program product, which includes a computer program or instructions. When the computer program or instructions are executed by a communication device, it implements the method in the above-mentioned first aspect or any possible implementation of the first aspect, or implements the above-mentioned second aspect or any possible implementation of the second aspect.
[0089] The technical effects that can be achieved in any of the fourth and fifth aspects can refer to the description of the beneficial effects in the first aspect, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0090] Figure 1a A schematic diagram of a communication system architecture provided for this application;
[0091] Figure 1b A schematic diagram of a communication system architecture provided for this application;
[0092] Figure 2 A schematic diagram of a communication system architecture provided for this application;
[0093] Figure 3 A flow chart of a communication method provided by this application;
[0094] Figure 4 A method flow diagram of a communication method applied to a wireless access network device provided by this application;
[0095] Figure 5 A schematic diagram of a method flow of a communication method for a wireless access network device during a handover process provided by the present application;
[0096] Figure 6 A method flow diagram of a communication method for a wireless access network device applied to an RRC connection recovery process provided by the present application;
[0097] Figure 7 A schematic diagram of a method flow of a communication method for a secondary node in dual connectivity provided by the present application;
[0098] Figure 8 A schematic diagram of a method flow chart of another communication method for a secondary node in dual connectivity provided by the present application;
[0099] Figure 9 A schematic diagram of a method flow of a communication method for a master node in dual connection provided by the present application;
[0100] Figure 10 A method flow diagram of another communication method applied to a wireless access network device provided by the present application;
[0101] Figure 11 A schematic diagram of a method flow of a communication method applied to a second terminal device provided by this application;
[0102] Figure 12 A schematic structural diagram of a communication device provided in this application;
[0103] Figure 13A schematic structural diagram of a communication device provided in this application.
[0104] Figure 14 A schematic diagram of the structure of a terminal device provided in this application;
[0105] Figure 15 A schematic diagram of the structure of a wireless access network device provided in this application. DETAILED DESCRIPTION
[0106] The embodiments of the present application will be described in detail below with reference to the accompanying drawings.
[0107] Some of the terms used in this application are explained below to facilitate understanding by those skilled in the art.
[0108] 1. Maximum Integrity Protection Rate
[0109] The maximum integrity protection rate indicates the maximum rate after user plane integrity protection is enabled on a terminal device. The maximum integrity protection rate includes the uplink maximum integrity protection rate and the downlink maximum integrity protection rate. The uplink maximum integrity protection rate indicates the maximum uplink rate after user plane integrity protection is enabled on a terminal device. The downlink maximum integrity protection rate indicates the maximum downlink rate after user plane integrity protection is enabled on a terminal device. For example, when the uplink maximum integrity protection rate is 64 kilobits per second, this means that after user plane integrity protection is enabled, the terminal device can send data to the radio access network at a maximum rate of 64 kilobits per second. When the downlink maximum integrity protection rate is 64 kilobits per second, this means that after user plane integrity protection is enabled, the terminal device can receive data from the radio access network at a maximum rate of 64 kilobits per second. For another example, when the downlink maximum integrity protection rate is the full data rate, this means that after user plane integrity protection is enabled, there is no limit on the data rate received from the radio access network. For example, the uplink maximum integrity protection rate currently includes two values: 64 kilobits per second (kbps) and the full data rate. The downlink maximum integrity protection rate value currently includes two values: 64 kilobits per second (kbps) and full-data-rate. In order to solve the problem that the user plane integrity protection between the UE and the access network device is always turned off when the maximum integrity protection rate value currently includes 64 kilobits per second (kbps), and the UE performance may be overloaded when the maximum integrity protection rate value is full-data-rate, the uplink or downlink maximum integrity protection rate in the embodiment of the present application may include more values, such as 1 gigabit per second (Gbps), 2 Gbps, etc. The uplink maximum integrity protection rate and the downlink maximum integrity protection rate may be equal or unequal, and this application does not limit this.
[0110] 2. Required Rate
[0111] The required rate is used to indicate the rate required for the terminal device to establish a new user plane resource with the wireless access network device. The required rate includes the uplink required rate and the downlink required rate. Specifically, the uplink required rate may include the maximum rate, minimum rate or average rate at which the terminal device sends data to the wireless access network device (such as a base station) on the user plane resources, and the downlink required rate includes the maximum rate, minimum rate or average rate at which the wireless access network device sends data to the terminal device on the user plane resources. Among them, the user plane resources include one or more data resource bearers (DRBs), and the DRBs define how the radio interface (Uu) handles messages.
[0112] In the 5G system, when a terminal device requests to establish or modify a protocol data unit (PDU) session, it also requests to establish one or more QoS flows. The wireless access network device can establish a new DRB or multiplex it into an existing DRB to transmit the QoS flow.
[0113] For non-guaranteed bit rate (Non-GBR) QoS flows, the required rate can be the maximum bit rate of the PDU session aggregation, that is, the PDU session Aggregate Maximum Bit Rate, which is used to limit the aggregate bit rate of all Non-GBR QoS flows of a specific PDU session. The uplink required rate can be the uplink maximum bit rate of the PDU session aggregation, and the downlink required rate can be the downlink maximum bit rate of the PDU session aggregation. The required rate can also be the aggregated maximum bit rate of the terminal device, that is, the UE Aggregate Maximum Bit Rate, which is used to limit the aggregated bit rate that can be provided by all Non-GBR QoS flows of a terminal device. The uplink required rate can be the aggregated uplink maximum bit rate of the terminal device, and the downlink required rate can be the aggregated downlink maximum bit rate of the terminal device.
[0114] For QoS flows with a guaranteed bit rate (GBR), the required rate can be the maximum flow bit rate, or Maximum Flow Bit Rate, which limits the maximum flow bit rate expected for the QoS flow. The uplink required rate can be the maximum uplink flow bit rate, and the downlink required rate can be the maximum downlink flow bit rate. The required rate can also be the guaranteed flow bit rate, or Guaranteed Flow Bit Rate, which indicates the flow bit rate that the network guarantees to provide for the QoS flow within the averaging time window. The uplink required rate can be the guaranteed uplink flow bit rate, and the downlink required rate can be the guaranteed downlink flow bit rate.
[0115] In the 4G system, when a terminal device requests to establish or modify an evolved packet system (EPS) bearer, it also requests to establish a new DRB.
[0116] For Non-GBR EPS bearers, the required rate can be the maximum bit rate aggregated by the access point name (APN), that is, per APN Aggregate Maximum Bit Rate, which is used to limit the aggregate bit rate that can be provided by all Non-GBR EPS bearers of all PDN connections of the same APN. The uplink required rate can be the uplink maximum bit rate aggregated by the APN, and the downlink required rate can be the downlink maximum bit rate aggregated by the APN. The required rate can also be the aggregated maximum bit rate of the terminal device, that is, per UE Aggregate Maximum Bit Rate, which is used to limit the aggregated bit rate that can be provided by all Non-GBR EPS bearers of a UE. The uplink required rate can be the uplink maximum bit rate aggregated by the terminal device, and the downlink required rate can be the downlink maximum bit rate aggregated by the terminal device.
[0117] For GBR EPS bearers, the required rate can be the maximum flow bit rate (Maximum Flow Bit Rate), which limits the maximum expected flow bit rate for the EPS bearer. The uplink required rate can be the maximum uplink flow bit rate, and the downlink required rate can be the maximum downlink flow bit rate. The required rate can be the guaranteed flow bit rate (Guaranteed Flow Bit Rate), which indicates the flow bit rate guaranteed by the network for the EPS bearer within the averaging time window. The uplink required rate can be the guaranteed uplink flow bit rate, and the downlink required rate can be the guaranteed downlink flow bit rate.
[0118] 3. Used Rate
[0119] The used rate is used to indicate the rate used by the user plane resources established by the terminal device. The used rate can be the real-time rate used by the user plane resources established by the terminal device. At the same time, since the real-time rate often changes, it is impossible to stably evaluate the utilization rate of the terminal at a certain moment. Therefore, the used rate can also be the estimated rate used by the user plane resources established by the terminal device. The estimated rate can be obtained based on the required rate for establishing user plane resources. The maximum integrity protection rate is used to indicate the maximum rate after the terminal device turns on the user plane integrity protection. It is an indicator used to characterize the performance of the UE, and the used rate can be used to characterize the performance that the UE has used in terms of the integrity protection rate.
[0120] It should be understood that the used rate includes the uplink used rate and the downlink used rate.
[0121] Taking the user plane resource as DRB as an example, for example, the terminal device has established DRB1, DRB2 and DRB3, the uplink rate used by DRB1 is A1, and the downlink rate is B1, the uplink rate used by DRB2 is A2, and the downlink rate is B2, the uplink rate used by DRB3 is A3, and the downlink rate is B3, then the uplink used rate of the terminal device is A1+A2+A3, and the downlink used rate is B1+B2+B3.
[0122] User Plane Security Policy
[0123] The user plane security policy includes user plane encryption protection and user plane integrity protection. User plane encryption protection can be indicated by three possible values, namely not needed, preferred and required; user plane integrity protection can also be indicated by three possible values, namely not needed, preferred and required, where not needed means that it does not need to be turned on; preferred means optional turning on, or recommended turning on, that is, it can be turned on or not; required means it must be turned on. The above three possible values can be indicated by 2 bits (bit), for example, 00 indicates that it does not need to be turned on, 01 indicates that it can be turned on or not, and 11 indicates that it must be turned on. The specific way in which the user plane encryption protection indication information and the user plane integrity protection indication information indicate the three possible values is not limited in the embodiments of the present application. Since the user plane encryption protection does not affect the communication rate, the present application does not limit the implementation of the user plane encryption protection.
[0124] Based on the above, Figure 1a This is a schematic diagram of the architecture of a communication system applicable to this application. Figure 1aAs shown, the communication system may include a data management network element, an authentication service network element, a mobility management network element, a session management network element, a policy control network element, a user plane network element, an access network device and a terminal device. Figure 1a The data management network element is unified data management (UDM), the authentication service network element is authentication server function (AUSF), the mobility management network element is access and mobility management function (AMF), the session management network element is session management function (SMF), the policy control network element is policy control function (PCF), the user plane network element is user plane function (UPF), and the terminal device is UE as an example.
[0125] The data management network element is primarily used to manage and store user data, such as contract information and authentication / authorization information. In 5G, the data management network element can be a UDM network element or a unified data repository (UDR) network element. In future communications such as the 6th generation (6G), the data management network element can still be a UDM network element or a UDR network element, or have other names, which are not limited in this application.
[0126] The authentication service network element is mainly used to verify service functions and store keys using the extensible authentication protocol (EAP) to achieve user authentication and authorization. In 5G, the authentication server network element can be an AUSF network element. In future communications such as 6G, the authentication server network element can still be an AUSF network element or have other names, which are not limited in this application.
[0127] The mobility management network element is mainly used for the registration, mobility management, and tracking area update processes of terminal devices in the mobile network. The mobility management network element terminates the non-access stratum (NAS) message, completes registration management, connection management, and reachability management, allocates the tracking area list (TA list) and mobility management, and transparently routes the session management (SM) message to the session management network element. In 5G communications, the mobility management network element can be an AMF network element. In future communications such as 6G, the mobility management network element can still be an AMF network element, or have other names, which is not limited in this application.
[0128] The session management network element is mainly used for session management and selection and control of user plane network elements in mobile networks. Among them, session management includes session creation, modification, and release. Specific functions include allocating Internet Protocol (IP) addresses to users, selecting user plane network elements that provide message forwarding functions, etc. In 5G, the session management network element can be an SMF network element. In future communications such as 6G, the session management network element can still be an SMF network element, or have other names, which are not limited in this application. The message communicated between the terminal device and the SMF is encapsulated in the SM container (container) of the NAS message. The AMF extracts the SM container content from the NAS message and sends it to the SMF.
[0129] The policy control network element is mainly used for the management of user subscription data, billing policy control, quality of service (QoS) control, etc. In 5G, the policy control network element can be a PCF network element. In future communications such as 6G, the policy control network element can still be a PCF network element or have other names, which are not limited in this application.
[0130] User plane network elements are mainly used for user plane service processing, such as data packet routing and transmission, packet detection, service usage reporting, quality of service (QoS) processing, lawful interception, uplink packet detection, downlink data packet storage, etc. In 5G, user plane network elements can be UPF network elements. In future communications such as 6G, user plane network elements can still be UPF network elements or have other names, which are not limited in this application.
[0131] Access network equipment (also known as radio access network (RAN) equipment), access network equipment is an access device that a terminal device uses to access the communication system wirelessly, and can be a base station (base station), evolved NodeB (eNB), transmission reception point (TRP), next generation NodeB (gNB) in a 5G communication system, next generation-evolved NodeB (ng-eNB) node B (node B, NB), base station controller (base station controller, BSC), base transceiver station (base transceiver station, BTS), home base station (for example, home evolved nodeB, or home node B, HNB), base station in a future communication system or access node in a wireless-fidelity (WiFi) system, etc.; it can also be a module or unit that completes part of the functions of a base station, for example, it can be a centralized unit (CU) or a distributed unit (DU). The embodiments of the present application do not limit the specific technology and specific device form adopted by the access network equipment.
[0132] Terminal devices may also be referred to as terminals, user equipment (UE), mobile stations, mobile terminals, etc. Terminal devices may include mobile phones, tablet computers, computers with wireless transceiver functions, virtual reality terminal devices, augmented reality terminal devices, wireless terminals used in industrial control, wireless terminals used in unmanned driving, wireless terminals used in remote surgery, wireless terminals used in smart grids, wireless terminals used in transportation safety, wireless terminals used in smart cities, wireless terminals used in smart homes, etc. This application does not limit the specific technologies and specific device forms used by the terminal devices.
[0133] This application can also be applied to the fourth generation (4G) communication system. Figure 1b , which is a schematic diagram of the architecture of another communication system to which the present application can be applied. Figure 1bThe data management network element is a home subscriber server (HSS), the mobility management network element is part of the functions of the mobility management entity (MME), the session management network element is part of the functions of the MME and part of the functions of the service gateway (SGW), the policy control network element is a policy and charging rules function unit (PCRF), the user plane network element is part of the functions of the packet data gateway (PGW), and the terminal device is a UE as an example.
[0134] The core network elements in this communication system are all core network elements in the LTE network. Among them, the interface between the MME and the E-UTRAN is the S1-MME interface, that is, the interface between the eNodeB and the MME, which is used to transmit user data and corresponding user plane control frames. The interface between the PGW and the SGW is the S5 / S8 interface. The S5 interface is the interface between the SGW and the PGW within the network. This interface should be able to provide the function of SGW relocation during user mobility when the SGW and the PGW are separated. S8 is the interface between the SGW and the PGW across the public land mobile network (PLMN), and has the S5 interface function in the roaming situation. The interface between the SGW and the E-UTRAN is the S1-U interface, that is, the interface between the eNodeB and the SGW, which is used to carry the user plane tunnel and the path exchange between the eNodeBs during switching. The interface between the SGW and the MME is the S11 interface, which is used to transmit information such as bearer control and session control. The interface between the HSS and the MME is the S6a interface, which is mainly used for user access authentication, inserting user subscription data, authorizing user access to the PDN, and authenticating user mobility management messages when interconnecting with non-3GPP systems.
[0135] This application can also be applied to dual-connection network architecture. Figure 2 As shown, another communication system architecture applicable to this application is shown. The communication system architecture may include a master node (MN), a secondary node (SN), a core network (CN), and a terminal device. In a dual-connection communication system, the node that initiates the dual connection is called a master node, which may also be called a master network node or a master base station. The other node selected by the master node to cooperate in serving the terminal device is called a secondary node, which may also be called a secondary network node or a secondary base station.
[0136] Five dual-connection network architectures are exemplarily shown below.
[0137] In network architecture 1, the MN is the eNB, the SN is the eNB, and the CN is the MME. The MN and SN communicate via the X2 interface, and the MN and CN communicate via the S1 interface. That is, the MN is connected to the MME in the 4G core network via the S1 interface.
[0138] In the second network architecture, the MN is the eNB, the SN is the gNB, and the CN is the MME. The MN and SN communicate via the X2 interface, and the MN and CN communicate via the S1 interface. This means the MN can connect to the MME in the 4G core network via the S1 interface. This second network architecture is also known as the Evolved Universal Terrestrial Radio Access Network and NR dual connectivity (E-UTRA-NR dual connectivity, EN-DC) network architecture.
[0139] In network architecture 3, the MN is a gNB, the SN is an ng-eNB, and the CN is an AMF. The MN communicates with the SN via the Xn interface, and the MN communicates with the CN via the N2 interface. That is, the MN can connect to the AMF of the 5G core network via the N2 interface.
[0140] In network architecture 4, the MN is the ng-eNB, the SN is the gNB, and the CN is the AMF. The MN communicates with the SN via the Xn interface, and the MN communicates with the CN via the N2 interface. That is, the MN can connect to the AMF of the 5G core network via the N2 interface.
[0141] In network architecture 5, the MN is a gNB, the SN is a gNB, and the CN is an AMF. The MN and SN communicate via the Xn interface, and the MN and CN communicate via the N2 interface. That is, the MN can connect to the AMF of the 5G core network via the N2 interface.
[0142] In the above five dual-connection network architectures, the terminal device can communicate with the MN or SN through the Uu interface. Figure 1a The introduction of the terminal equipment will not be repeated here.
[0143] It should be understood that the above Figure 1a 、 Figure 1b and Figure 2 Just a schematic diagram, Figure 1a and Figure 1b The communication system shown may also include other wireless access network devices, such as wireless relay devices and wireless backhaul devices. Figure 1a and Figure 1b This application does not limit the number of core network devices, access network devices and terminal devices included in the communication system.
[0144] It should be noted that the system architecture and application scenarios described in this application are intended to more clearly illustrate the technical solutions of this application and do not constitute a limitation on the technical solutions provided by this application. Ordinary technicians in this field can know that with the evolution of the system architecture and the emergence of new business scenarios, the technical solutions provided by this application are also applicable to similar technical problems.
[0145] Currently, when the RAN determines whether to enable integrity protection for a PDU session, it is based on the UE's maximum integrity protection rate of 64Kbps and the full data rate, as well as the user plane security policy of the PDU session. Specifically, if the UE's maximum integrity protection rate is 64Kbps and the user plane integrity protection policy of the PDU session is preferred, the RAN determines that user plane integrity protection is not enabled for this DRB; if the UE's maximum integrity protection rate is the full data rate and the user plane integrity protection policy of the PDU session is preferred, the RAN determines whether to enable user plane integrity protection for the PDU session based on its own circumstances (for example, if its own resources are sufficient, it is enabled; otherwise, it is not enabled). If the user plane integrity protection policy is not needed, the RAN directly does not enable user plane integrity protection. If the UE's maximum integrity protection rate is 64Kbps and the user plane integrity protection policy of the PDU session is required, the SMF rejects the establishment or modification of the PDU session, and there is no need to allocate DRBs on the RAN side.
[0146] However, the current standard only allows for two maximum integrity protection rates: 64Kbps and the full data rate. These are two extreme values, one infinitesimal and the other infinitely large. When the UE's maximum integrity protection rate is 64Kbps (a very small value), user plane integrity protection cannot be enabled for data transmission between the UE and the network most of the time, and the security of user data is not guaranteed. When the UE's maximum integrity protection rate is the full data rate (an infinite value), whether user plane integrity protection is enabled for data transmission between the UE and the network is entirely determined by the RAN. When the user plane integrity protection policy is preferred and RAN resources are sufficient, user plane integrity protection may be enabled for all data transmission between the UE and the network. Enabling user plane integrity protection will have a significant impact on UE performance, which may cause service anomalies on the UE. For example, due to insufficient UE performance, data transmission timeliness may not meet requirements.
[0147] In view of this, the present application proposes a communication method that, when determining whether to enable integrity protection for a first user plane resource, fully considers the maximum integrity protection rate of a terminal device and the used rate of the user plane resources on the terminal device that have integrity protection enabled, so as to ensure the timeliness and security of the terminal device's transmitted data as much as possible. For example, if the maximum integrity protection rate of a terminal device is 1000 Mbps, and the total used rate corresponding to the user plane resources on the terminal device that have user plane integrity protection enabled is 400 Mbps, then if the rate corresponding to the first user plane resource requested to be established by the terminal device is less than 600 Mbps, the terminal device may also enable user plane integrity protection for the first user plane resource. That is, user plane integrity protection on the terminal device and the network side can be enabled on demand based on the capabilities of the UE, which helps to avoid the situation where the user plane integrity protection on the terminal device and the network side is always disabled when the maximum integrity protection rate of the terminal device is 64 Kpbs, resulting in a lack of security for the transmitted data, or the situation where the user plane integrity protection on the terminal device and the network side is always enabled when the maximum integrity protection rate of the terminal device is the full data rate, resulting in abnormal terminal device performance.
[0148] Reference below Figure 3 , is a flow chart of a communication method provided by this application. The method comprises the following steps:
[0149] Step 301: The first communication device obtains the required rate, remaining rate and user plane security policy of the first terminal device.
[0150] Among them, the user plane security policy includes user plane integrity protection turned on, user plane integrity protection optionally turned on, or user plane integrity protection turned off. The required rate is used to indicate the rate required for the first user plane resource requested to be established by the first terminal device. Among them, the first user plane resource is the user plane resource to be established by the first terminal device and the first communication device. The first user plane resource may include one or more data bearers, such as DRB, sidelink radio bearer (SLRB). The remaining rate is determined based on the used rate of the first terminal device and the maximum integrity protection rate of the first terminal device. The maximum integrity protection rate is used to indicate the maximum rate after the first terminal device turns on user plane integrity protection. It should be understood that the user plane security policy is used to determine whether to turn on the integrity protection of the first user plane resource. That is, the user plane security policy is the user plane security policy corresponding to the first user plane resource to be established by the first terminal device. In addition, the first user plane resource may include one or more DRBs, and the user plane security policies of the one or more DRBs included in the first user plane resource are the same.
[0151] Here, the used rate is used to indicate the rate used by the second user plane resources established by the first terminal device and the first communication apparatus. Optionally, the second user plane resources include all established user plane resources of the first terminal device. Optionally, the second user plane resources include user plane resources with user plane integrity protection enabled among the user plane resources established by the first terminal device. Furthermore, if the first terminal device has established one second user plane resource, the used rate of the first terminal device is equal to the rate used by the second user plane resource; if the first terminal device has established multiple second user plane resources, the used rate of the first terminal device is equal to the sum of the rates used by each of the multiple established second user plane resources.
[0152] For example, taking the user plane resource as DRB as an example, the user plane resources established by the first terminal device include DRB11, DRB12, DRB13 and DRB14, wherein DRB11, DRB12 and DRB13 have all enabled user plane integrity protection, and DRB14 has not enabled user plane integrity protection, then the second user plane resources include DRB11, DRB12 and DRB13. Furthermore, the used rate is equal to the sum of the rate used by DRB11, the rate used by DRB12 and the rate used by DRB13.
[0153] In one possible implementation, the difference between the maximum integrity protection rate and the used rate can be determined as the residual rate. Furthermore, the maximum integrity protection rate includes the uplink maximum integrity protection rate and the downlink maximum integrity protection rate, the required rate includes the uplink required rate and the downlink required rate, and the residual rate includes the uplink residual rate and the downlink rate. The uplink residual rate is equal to the difference between the uplink maximum integrity protection rate and the uplink required rate, and the downlink residual rate is equal to the difference between the downlink maximum integrity protection rate and the downlink required rate.
[0154] In a possible implementation, the first communication device may be a wireless access network device. The process of the wireless access network device obtaining the required rate, the remaining rate and the user plane security policy of the first terminal device can be referred to as follows: Figure 4 Or 10; or, the first communication device may be a wireless access network device in the switching process, and the wireless access network device in the switching process obtains the required rate, the remaining rate and the user plane security policy of the first terminal device, as described below. Figure 5 Alternatively, the first communication device may be a wireless access network device in the RRC connection recovery process, and the process of the wireless access network device in the RRC connection recovery process obtaining the required rate, remaining rate and user plane security policy of the first terminal device can be referred to below Figure 6Alternatively, the first communication device may be a secondary node in a dual connection, and the secondary node obtains the required rate, the remaining rate, and the user plane security policy of the first terminal device as described below. Figure 7 or Figure 8 Alternatively, the first communication device may be a master node in a dual connection, and the process of the master node obtaining the required rate, the remaining rate, and the user plane security policy of the first terminal device may be referred to below. Figure 9 or; the first communication device may be a second terminal device, and the process of the second terminal device obtaining the required rate, the remaining rate and the user plane security policy of the first terminal device may be referred to below Figure 11 ; I will not repeat it here.
[0155] In step 302 , the first communications device may determine whether to enable user plane integrity protection of first user plane resources based on the required rate, the remaining rate, and the user plane security policy.
[0156] Here, based on the user plane security policy, possible implementation methods of determining whether to enable user plane integrity protection of the first user plane resource in three different situations are exemplified.
[0157] Scenario 1: The user plane security policy includes enabling user plane integrity protection (required).
[0158] Based on scenario 1, if the remaining rate is greater than or equal to the required rate, a first indication message is sent to the first terminal device, and the first indication message is used to indicate that the user plane integrity protection of the first user plane resource is to be enabled. Accordingly, the first terminal device receives the first indication message and enables the user plane integrity protection of the first user plane resource according to the first indication message. It should be understood that if the remaining rate is greater than or equal to the required rate, it means that even if the user plane integrity protection of the first user plane resource is enabled, it will not affect the normal communication service of the first terminal device.
[0159] Based on scenario 1, if the remaining rate is less than the required rate, obtain the third user plane resource and send a second indication message to the first terminal device, the second indication message is used to indicate that the user plane integrity protection of the first user plane resource is turned on, and is used to indicate that the user plane integrity protection of the third user plane resource is not turned on (i.e., turned off), wherein the user plane security policy of the third user plane resource is that user plane integrity protection is optionally turned on, and the user plane integrity protection of the third user plane resource is turned on, and the used rate of the third user plane resource is greater than or equal to the difference between the required rate and the remaining rate. Accordingly, the first terminal device receives the second indication message, turns on the user plane integrity protection of the first user plane resource according to the second indication message, and turns off the user plane integrity protection of the third user plane resource.
[0160] It should be noted that the third user plane resource may be one or more. That is, if the user plane security policy in the first terminal device enables optional user plane integrity protection, and there may be multiple enabled user plane resources, one user plane resource whose used rate is greater than or equal to the difference between the required rate and the remaining rate may be selected from these multiple resources. This selected user plane resource is the third user plane resource. Alternatively, multiple user plane resources may be selected from these multiple resources, and the sum of the used rates of these multiple user plane resources is greater than or equal to the difference between the required rate and the remaining rate. These selected user plane resources are the third user plane resources.
[0161] Exemplarily, the user plane security policy in the first terminal device is that the user plane resources for which user plane integrity protection is optionally enabled include: user plane resource 1, user plane resource 2, user plane resource 3, user plane resource 4, and user plane resource 5; among them, user plane integrity protection is enabled for user plane resource 1, user plane resource 2, and user plane resource 3, and user plane integrity protection is not enabled for user plane resource 4 and user plane resource 5; a third user plane resource can be selected from user plane resource 1, user plane resource 2, and user plane resource 3. For example, if the used rate of user plane resource 1 is greater than or equal to the difference between the required rate and the remaining rate, then user plane resource 1 is the third user plane resource. Of course, user plane resource 1, user plane resource 2, and user plane resource 3 can all be used as the third user plane resource; or user plane resource 1 and user plane resource 2 can both be used as the third user plane resource. For another example, if the used rates of user plane resource 1, user plane resource 2, and user plane resource 3 are all less than the difference between the required rate and the remaining rate, and the sum of the used rates of user plane resource 1 and user plane resource 2 is greater than or equal to the difference between the required rate and the remaining rate, then user plane resource 1 and user plane resource 2 are considered third user plane resources. Alternatively, user plane resource 1, user plane resource 2, and user plane resource 3 may all be considered third user plane resources. These examples are not listed here one by one.
[0162] It should be noted that if the user plane security policy in the first terminal device is to enable optional user plane integrity protection, and the sum of the used rates of all user plane resources with enabled user plane integrity protection is less than the difference between the required rate and the remaining rate, then the request of the first terminal device to establish the first user plane resource is rejected.
[0163] In one possible implementation, if the remaining rate is less than the required rate, the request of the first terminal device to establish the first user plane resource may be rejected. For example, a first message is sent to the first terminal device, and the first message is used to reject the first terminal device from establishing the first user plane resource. Alternatively, a rejection request is sent to other wireless access network devices to trigger other wireless access network devices to send a second message to the first terminal device, and the second message is used to reject the first terminal device from establishing the first user plane resource. In other words, the acceptance or rejection of the establishment of the first user plane resource can be determined based on the remaining rate and the required rate. Furthermore, after the first user plane resource is established, it is determined whether to enable the user plane integrity protection of the first user plane resource.
[0164] Scenario 2: The user plane security policy includes user plane integrity protection being optionally enabled (prefered).
[0165] In this scenario 2, if the remaining rate is greater than or equal to the required rate, a first indication message is sent to the first terminal device, where the first indication message is used to indicate that user plane integrity protection of the first user plane resource should be enabled. Accordingly, the first terminal device receives the first indication message and enables user plane integrity protection of the first user plane resource according to the first indication message.
[0166] In this scenario 2, if the remaining rate is less than the required rate, a third indication message is sent to the first terminal, where the third indication is used to indicate that user plane integrity protection for the first user plane resource is not enabled. Accordingly, the first terminal device receives the third indication message and does not enable user plane integrity protection for the first user plane resource.
[0167] Scenario 3: The user plane security policy includes that user plane integrity protection is not enabled (not needed).
[0168] Based on Scenario 3, it is determined not to enable user plane integrity protection for the first user plane resource, and a third indication message is sent to the first terminal device, where the third indication is used to indicate that user plane integrity protection for the first user plane resource is not enabled. Accordingly, the first terminal device receives the third indication message and does not enable user plane integrity protection for the first user plane resource.
[0169] It should be noted that the above-mentioned residual rate is greater than or equal to the required rate means that the uplink residual rate is greater than or equal to the uplink required rate and / or the downlink residual rate is greater than or equal to the downlink required rate. The residual rate is less than the required rate means that the uplink residual rate is less than the uplink required rate and / or the downlink residual rate is less than the downlink required rate.
[0170] In step 301, the used rate of the first terminal device may be determined by any one or a combination of the following rate parameters (a), (b), (c), (d), (e), and (f). The rate parameters may include a real-time rate, a maximum rate, a minimum rate, an average rate, etc., at which the first communication device transmits data on user plane resources.
[0171] In one possible implementation, rate parameter (a) is the maximum bit rate of the PDU session aggregation of the second user plane resource, that is, PDU session Aggregate Maximum Bit Rate. Further, the maximum bit rate of the PDU session aggregation includes the maximum bit rate of the downlink / uplink of the PDU session aggregation, that is, the PDU session Aggregate Maximum Bit Rate includes the PDU session Aggregate Maximum Bit Rate Downlink / Uplink. The rate parameter (a) can be saved in the PDU session-related policy information of the PCF. Rate parameter (b) is the maximum bit rate of the APN aggregation of the second user plane resource, that is, per APN Aggregate Maximum Bit Rate, and the maximum bit rate of the APN aggregation includes the maximum bit rate of the downlink / uplink of the APN aggregation, that is, per UE Aggregate Maximum Bit Rate Downlink / Uplink. The rate parameter (b) can be saved in the APN-related policy information of the PCRF. Rate parameter (c) is the aggregated maximum bit rate of the terminal device of the first terminal device, that is, UE Aggregate Maximum Bit Rate. Furthermore, the aggregate maximum bit rate of the terminal device includes the aggregate downlink / uplink maximum bit rate of the terminal device, that is, UE AggregateMaximum Bit Rate includes UE Aggregate Maximum Bit Rate Downlink / Uplink. The rate parameter (c) can be saved in the access and mobility-related policy control information of the PCF, or in the UE subscription information of the HSS / UDM. Rate parameter (d) is the maximum flow bit rate of the QoS flow of the GBR of the second user plane resource, that is, Maximum Flow BitRate. Further, the maximum flow bit rate of the QoS flow of the GBR includes the downlink / uplink maximum flow bit rate of the QoS flow of the GBR. That is, Maximum Flow Bit Rate includes Maximum Flow Bit Rate Downlink / Uplink. The rate parameter (d) can be saved in the policy and charging control rules (PCC) of the PCF or PCRF. Rate parameter (e) is the guaranteed flow bit rate of the QoS flow of the GBR of the second user plane resource, that is, Guaranteed Flow BitRate.Furthermore, the guaranteed flow bit rate for the GBR QoS flow includes the guaranteed flow bit rate for the downlink / uplink of the GBR QoS flow, i.e., the guaranteed flow bit rate includes the guaranteed flow bit rate downlink / uplink. This rate parameter (e) can be stored in the PCC of the PCRF or PCCF. Rate parameter (f) is the real-time rate of the second user plane resource. Furthermore, the real-time rate also includes the uplink real-time rate and the downlink real-time rate.
[0172] Exemplarily, the second user plane resources in the terminal device include DRB11, DRB12 and DRB13, the QoS flow of DRB11 is non-GBR, and the QoS flows of DRB12 and DRB13 are both GBR, then the rate parameter (a) is the maximum bit rate of the PDU session aggregation of the PDU session corresponding to DRB11. The rate parameter (b) is the maximum bit rate of the APN session aggregation of the APN corresponding to DRB11. The rate parameter (c) is the maximum bit rate of the aggregation of the terminal device. The rate parameter (d) is the maximum flow bit rate of the Qos flow contained in DRB12 and DRB13. The rate parameter (e) is the guaranteed flow bit rate of the QoS flow contained in DRB12 and DRB13.
[0173] Four possible implementations of determining the used rate are shown below by way of example.
[0174] Implementation method 1: the maximum value of the used rate.
[0175] In one possible implementation, the sum of the maximum bit rate of all PDU sessions aggregated and the maximum flow bit rate of all GBR QoS flows is determined as the used rate; or the sum of the maximum bit rate of the terminal device aggregated and the maximum flow bit rate of all GBR QoS flows is determined as the used rate.
[0176] Exemplarily, the second user plane resources may be all non-GBR or partially non-GBR. The maximum bit rate of the PDU session aggregation of all non-GBR QoS flows of the first terminal device and the maximum flow bit rate of all GBR QoS flows of the first terminal device may be determined as the used rate; or the maximum bit rate of the aggregation of all UEs of the first terminal device and the maximum flow bit rate of all GBR QoS flows of the first terminal device may be determined as the used rate.
[0177] Furthermore, the used rate includes the uplink used rate and the downlink used rate. The downlink maximum bit rate of the PDU session aggregation of all non-GBR QoS flows of the first terminal device or the aggregated downlink maximum bit rate of the UE of the first terminal device, and the sum of the downlink maximum bit rate of all GBR QoS flows of the first terminal device, are determined as the downlink used rate of the first terminal device; the uplink maximum bit rate of the PDU session aggregation of all non-GBR QoS flows of the first terminal device or the aggregated uplink maximum bit rate of the UE of the first terminal device, and the sum of the uplink maximum bit rate of all GBR QoS flows of the first terminal device are determined as the uplink used rate of the first terminal device.
[0178] In another possible implementation, the maximum bit rate of the PDU session aggregation of all non-GBR QoS flows with user plane integrity protection enabled on the first terminal device and the sum of the maximum flow bit rates of all GBR QoS flows with user plane integrity protection enabled on the first terminal device are determined as the used rate.
[0179] Furthermore, the used rate includes the uplink used rate and the downlink used rate. The downlink maximum bit rate of the PDU session aggregation of all non-GBR QoS flows with user plane integrity protection turned on by the first terminal device and the sum of the downlink maximum bit rates of all GBR QoS flows with user plane integrity protection turned on by the first terminal device are determined as the downlink used rate of the first terminal device; the uplink maximum bit rate of the PDU session aggregation of all non-GBR QoS flows with user plane integrity protection turned on by the first terminal device and the sum of the uplink maximum bit rates of all GBR QoS flows with user plane integrity protection turned on by the first terminal device are determined as the uplink used rate of the first terminal device.
[0180] In the above implementation method 1, the used rate is calculated based on the assumption that the second user plane resources are all transmitting data at the maximum bit rate. Therefore, the remaining rate represents the terminal's remaining transmission capacity under extreme conditions, thereby ensuring the communication service of the first terminal device as much as possible. In other words, this implementation method 1 determines whether to enable user plane integrity protection for the first user plane resources based on the service availability of the first terminal device.
[0181] Implementation method 2: the minimum value of the used rate.
[0182] In a possible implementation, the sum of the guaranteed bit rates of all GBR QoS flows of the first terminal device is determined as the used rate.
[0183] Furthermore, the used rate includes the uplink used rate and the downlink used rate; the sum of the guaranteed downlink bit rates of the QoS flows of all GBRs of the first terminal device is determined as the downlink used rate of the first terminal device; the sum of the guaranteed uplink bit rates of the QoS flows of all GBRs of the first terminal device is determined as the uplink used rate of the first terminal device.
[0184] In another possible implementation, the sum of the guaranteed bit rates of all GBR QoS flows of the first terminal device with user plane integrity protection enabled is determined as the used rate.
[0185] Furthermore, the used rate includes the uplink used rate and the downlink used rate; the sum of the guaranteed downlink bit rates of the QoS flows of all GBRs with user plane integrity protection enabled of the first terminal device is determined as the downlink used rate of the first terminal device; the sum of the guaranteed uplink bit rates of the QoS flows of all GBRs with user plane integrity protection enabled of the first terminal device is determined as the uplink used rate of the first terminal device.
[0186] In the second implementation described above, the utilized rate is calculated based on the assumption that the second user plane resources all transmit data at the minimum bit rate. This ensures the security of data transmitted by the first terminal device to the greatest extent possible. In other words, this second implementation determines whether to enable user plane integrity protection for the first user plane resources based on the security of data transmitted by the first terminal device.
[0187] Implementation method three, the used rate is between the maximum value determined in the above implementation method one and the minimum value determined in the above implementation method two.
[0188] In a possible implementation, the sum of the maximum bit rate aggregated across all PDU sessions and the guaranteed bit rates of all GBR QoS flows is determined as the used rate.
[0189] Exemplarily, the adjusted value of the maximum bit rate of the PDU session aggregation of all non-GBR QoS flows of the first terminal device or the adjusted value of the maximum bit rate of the aggregation of UEs of the first terminal device, and the sum of the guaranteed bit rates of all GBR QoS flows, are determined as the used rate.
[0190] The adjustment value may be obtained by lowering the maximum bit rate of the PDU session aggregation or the maximum bit rate of the UE aggregation. For example, the adjustment value may be obtained based on transmission statistics of a non-GBR QoS flow.
[0191] Furthermore, the used rate includes the uplink used rate and the downlink used rate; the downlink maximum bit rate of the PDU session aggregation of all non-GBR Qos flows of the first terminal device and the sum of the guaranteed downlink bit rates of all GBR Qos flows are determined as the downlink used rate; the uplink maximum bit rate of the PDU session aggregation of all non-GBR Qos flows of the first terminal device and the sum of the guaranteed uplink bit rates of all GBR Qos flows are determined as the uplink used rate.
[0192] In another possible implementation, the maximum bit rate of the PDU session aggregation of all non-GBR QoS flows with user plane integrity protection enabled of the first terminal device or the adjusted value of the maximum bit rate of the aggregation of UEs of the first terminal device, and the sum of the guaranteed bit rates of all GBR QoS flows with user plane integrity protection enabled are determined as the used rate.
[0193] Furthermore, the used rate includes the uplink used rate and the downlink used rate; the downlink maximum bit rate of the PDU session aggregation of all non-GBR QoS flows with user plane integrity protection enabled of the first terminal device, and the sum of the guaranteed downlink bit rates of all GBR QoS flows with user plane integrity protection enabled, are determined as the downlink used rate; the uplink maximum bit rate of the PDU session aggregation of all non-GBR QoS flows with user plane integrity protection enabled of the first terminal device, and the sum of the guaranteed uplink bit rates of all GBR QoS flows with user plane integrity protection enabled, are determined as the uplink used rate.
[0194] In the third implementation, the used rate is calculated based on the assumption that data is transmitted at a moderate rate after the second user plane resource usage is adjusted. Thus, the remaining rate represents the overall terminal rate, thereby ensuring both the availability of the communication service for the first terminal device and the security of the data transmitted by the first terminal device.
[0195] Implementation method 4: real-time monitoring of the real-time rate of the second user plane resource.
[0196] In a possible implementation, the sum of the monitored real-time rates of all second user plane resources is determined as the used rate of the first terminal device.
[0197] Furthermore, the used rate includes the uplink used rate and the downlink used rate; the sum of the monitored uplink real-time rates of the second user plane resources is determined as the uplink used rate, and the sum of the monitored downlink real-time rates of the second user plane resources is determined as the downlink used rate.
[0198] Exemplarily, the sum of the real-time rates of all monitored second user plane resources with user plane integrity protection enabled is determined as the used rate of the first terminal device.
[0199] Furthermore, the used rate includes the uplink used rate and the downlink used rate; the sum of the uplink real-time rates of the second user plane resources with user plane integrity protection enabled is determined as the uplink used rate, and the sum of the downlink real-time rates of the second user plane resources with user plane integrity protection enabled is determined as the downlink used rate.
[0200] In the fourth implementation, the used rate is calculated based on the assumption that the second user plane resource transmits data at the real-time rate. This means that the remaining rate represents the most accurate rate for the first terminal device, ensuring that decisions are based on the most accurate data. This maximizes both the availability of the first terminal device's communication services and the security of its transmitted data.
[0201] As follows, the communication method provided in this application is described in combination with possible application scenarios.
[0202] Scenario 1 can be applied to the PDU session establishment process, PDU session modification process, or EPS bearer establishment process.
[0203] See also Figure 4 , is a communication method for wireless access network equipment provided by this application. In this method, the wireless access network equipment is the above-mentioned Figure 3 The first communication device in the session management network element may be the above Figure 1a SMF in or Figure 1b The MME in the data management network element can be the above Figure 1a UDM in or Figure 1b The HSS in the policy control network element can be the above Figure 1a PCF in or Figure 1b The method comprises the following steps:
[0204] Step 401: A first terminal device sends a first request message to a session management network element. Correspondingly, the session management network element receives the first request message from the first terminal device.
[0205] Here, the first request message is used to request PDU session establishment or PDU session modification or request bearer resource change. The first request message includes the maximum integrity protection rate of the first terminal device. That is, the session management network element can obtain the maximum integrity protection rate of the first terminal device from the first terminal device. Furthermore, the maximum integrity protection rate of the first terminal device reported by the first terminal device to the session management network element can have multiple values, such as 1Gbps (i.e., 1000Mbps) and 2Gbps, etc. The specific value can be set according to the performance of the first terminal device. For example, if the performance of the first terminal device is high, a larger value can be taken; if the performance of the first terminal device is low, a smaller value can be taken. Compared with the prior art in which the maximum integrity protection rate of the terminal device has only two values of 64Kbps and full data rate, in this application, the maximum integrity protection rate of the first terminal device reported by the first terminal device can take more values and can reflect the performance of the first terminal device.
[0206] It should be noted that during the process of PDU session establishment, PDU session modification or bearer resource change, the first terminal device will eventually establish a first user plane resource with the wireless access network device. The first user plane resource can be one or more DRBs.
[0207] Step 402: The session management network element obtains a user plane security policy of the first user plane resource according to the first request message.
[0208] Here, the session management network element may obtain an identifier of the first terminal device, such as a subscriber permanent identifier (SUPI), from the context of the terminal device according to the first request message.
[0209] In one possible implementation, the session management network element sends a contract acquisition request message to the data management network element. Accordingly, the data management network element receives the contract acquisition request message from the session management network element. Here, the contract acquisition request message is used to request to obtain the user plane security policy of the first terminal device. The contract acquisition request message may include the identifier of the first terminal device, the data network name (DNN) and / or the identifier of the network slice (single network slice selection assistance information, NSSAI). The data management network element may obtain the contract information of the first terminal device according to SUPI, and then obtain the user plane security policy of the first terminal device according to DNN and / or NSSAI.
[0210] In another possible implementation, the session management network element may also obtain the user plane security policy of the first terminal device based on a local configuration. For example, when the first request message includes a DNN and / or NSSAI, the session management network element may determine the user plane security policy of the first terminal device from the local configuration based on the DNN and / or NSSAI.
[0211] It should be noted that the user plane security policy of the first terminal device obtained by the session management function will subsequently serve as the basis for the wireless access network device to determine whether integrity protection is enabled for the first user plane resource. Therefore, it can also be called the user plane security policy of the first user plane resource.
[0212] Step 403: The session management network element obtains the required rate for establishing the first user plane resource according to the first request message.
[0213] In one possible implementation, a session management network element sends a policy control creation message to a policy control network element. The policy control creation message is used to request establishment of a required rate for a first user plane resource. When the policy control creation message includes a SUPI, a DNN, and / or an NSSAI, the policy control network element may obtain policy information for the first terminal device based on the SUPI, and then obtain the required rate for establishing the first user plane resource from the policy information based on the DNN and / or NSSAI. In this case, the required rate may be the maximum bit rate for PDU session aggregation or the maximum bit rate for APN session aggregation.
[0214] In another possible implementation, when the policy control creation message includes the SUPI, DNN and / or NSSAI, and a flow template, the policy control network element may obtain policy information of the first terminal device based on the SUPI, and then obtain a required rate for establishing the first user plane resource from the policy information based on the DNN and / or NSSAI and the flow template. The flow template is used to indicate a QoS flow. In this case, the required rate may be a maximum flow bit rate or a guaranteed flow bit rate.
[0215] It should be noted that the required rate of the first terminal device obtained by the session management function will subsequently be used as a reference for the wireless access network device to establish the first user plane resource for the first terminal device, and therefore can also be called the required rate of the first user plane resource.
[0216] It should also be noted that there is no order between the above steps 402 and 403. Step 402 can be executed first and then step 403; step 403 can be executed first and then step 403; or step 402 and step 403 can be executed at the same time; this application does not limit this.
[0217] Step 404: The session management network element sends a first response message to the wireless access network device. Correspondingly, the wireless access network device receives the first response message from the session management network element.
[0218] Here, the first response message includes the user plane security policy of the first user plane resource, the maximum integrity protection rate of the first terminal device, and the required rate for establishing the first user plane resource.
[0219] Step 405: The wireless access network device obtains the used rate of the first terminal device from the locally stored context of the terminal device.
[0220] The required rate, maximum integrity protection rate, and used rate can be respectively referred to the relevant introduction of the above step 301, and will not be repeated here.
[0221] Step 406: The wireless access network device determines the remaining rate of the first terminal device according to the maximum integrity protection rate of the first terminal device and the used rate of the first terminal device.
[0222] The method for determining the remaining rate in step 301 may be referred to in step 406 , and will not be repeated here.
[0223] Step 407: The wireless access network device determines whether to enable user plane integrity protection of the first user plane resource based on the required rate for establishing the first user plane resource, the remaining rate of the first terminal device, and the user plane security policy of the first user plane resource.
[0224] For example, the maximum integrity protection rate of the first terminal device is 1000Mbps, and the rate used by the second user plane resource already established on the first terminal device is 400Mbps, that is, the used rate of the first terminal device is 400Mbps. If the required rate of the first user plane resource to be established is less than or equal to 600Mbps, it means that the first terminal device is capable of turning on the user plane integrity protection of the first user plane resource. Furthermore, if the user plane security policy of the first user plane resource is to turn on user plane integrity protection, it can be determined to turn on the user plane integrity protection of the first user plane resource. If the user plane security policy of the first user plane resource is to turn on user plane integrity protection optionally, it can also be determined to turn on the user plane integrity protection of the first user plane resource.
[0225] The step 407 can be referred to the introduction of the above step 302 and will not be repeated here.
[0226] In step 408, the radio access network device sends an RRC reconfiguration message to the first terminal device. Accordingly, the first terminal device receives the RRC reconfiguration message from the radio access network device.
[0227] In one possible implementation, the RRC reconfiguration message includes security indication information. The security indication information is used to instruct the first terminal device to turn on or off the user plane integrity protection of the first user plane resource. Furthermore, the security indication information may be the above-mentioned first indication information, or the second indication information, or the third indication information. If the security indication information is the above-mentioned third indication information, the security indication information is also used to indicate whether to turn off the user plane integrity protection of the third user plane resource. The description of the first indication information, or the second indication information, or the third indication information can be found in the introduction to the above-mentioned step 302, and will not be repeated here.
[0228] Step 409: The first terminal device sends an RRC reconfiguration completion message to the wireless access network device.
[0229] The RRC reconfiguration completion message is used to indicate whether the first terminal device has enabled or disabled user plane integrity protection for the first user plane resources.
[0230] Through steps 401 to 409, the wireless access network device can accurately determine whether to enable user plane integrity protection for the first user plane resource based on the maximum integrity protection rate, the used rate, the required rate, and the user plane security policy, thereby ensuring the timeliness and security of data transmitted by the first terminal device to the greatest extent possible. That is, user plane integrity protection on the terminal device and the network side can be enabled on demand based on the capabilities of the terminal device. This helps avoid situations where user plane integrity protection on the terminal device and the network side is always disabled when the terminal device's maximum integrity protection rate is 64 Kbps, resulting in a loss of security for transmitted data, or where user plane integrity protection on the terminal device and the network side is always enabled when the terminal device's maximum integrity protection rate is the full data rate, resulting in abnormal terminal device performance.
[0231] Scenario 2 is applied to the switching process of terminal devices between different wireless access network devices.
[0232] See Figure 5 , is a communication method provided by this application for a terminal device to be used in the switching process between wireless access network devices. In this method, the target wireless access network device is the above-mentioned Figure 3 The first communication device in the source wireless access network device is the wireless access network device currently accessed by the first terminal device. The method includes the following steps:
[0233] In step 500, the first terminal device sends a measurement report to the source radio access network device. Correspondingly, the source radio access network device receives the measurement report from the first terminal device.
[0234] In one possible implementation, the source wireless access network device may determine whether to perform a handover based on a measurement report reported by the first terminal device. If a handover is performed, the source wireless access network device executes step 501, i.e., sends a handover request message to the target wireless access network device. For example, if the measurement report indicates that the signal strength between the first terminal device and the target wireless access network device is good, but the signal strength with the source wireless access network device is poor, the source wireless access network device sends a handover request message to the target wireless access network device.
[0235] Step 501: The source wireless access network device sends a handover request message to the target wireless access network device. Correspondingly, the target wireless access network device receives the handover request message from the source wireless access network device.
[0236] The handover request message includes a required rate of the first user plane resource, a user plane security policy of the first user plane resource, and a maximum integrity protection rate of the first terminal device. The required rate of the first user plane resource, the user plane security policy of the first user plane resource, and the maximum integrity protection rate of the first terminal device are obtained by the source radio access network device from the context of the first terminal device.
[0237] In particular, since the handover process migrates all context information of the first terminal device from the source radio access network device to the target radio access network device, the required rate of the first terminal device, for the target radio access network device, includes the required rate of the user plane resources established between the source radio access network device and the first terminal device. Alternatively, it can be understood that, for the target radio access network device, the required rate of the first user plane resources includes the required rate of the user plane resources established in the source radio access network device.
[0238] For example, if the source wireless access network device has established DRB11, DRB12, and DRB13 with the first terminal device, the required rate of the first user plane resource may include the required rate for establishing DRB11, the required rate for establishing DRB12, and the required rate for establishing DRB13.
[0239] In particular, the user plane security policy may be different or the same for different user plane resources. The user plane security policy includes the user plane security policy of the user plane resource established between the source wireless access network device and the first terminal device.
[0240] Step 502: The target wireless access network device determines the remaining rate of the first terminal device according to the maximum integrity protection rate of the first terminal device and the used rate of the first terminal device.
[0241] In particular, because the target radio access network device has not yet established user plane resources with the first terminal device when it receives the handover request message, the initially used rate is 0. At this time, the remaining rate is the maximum integrity protection rate. After the target radio access network device determines to continuously enable integrity protection of user plane resources, the used rate gradually increases and the remaining rate continuously decreases.
[0242] The method for determining the remaining rate in step 301 may be referred to in step 502, and will not be repeated here.
[0243] Step 503: The target wireless access network device determines whether to enable user plane integrity protection of the first user plane resource based on the required rate of the first user plane resource, the remaining rate of the first terminal device, and the user plane security policy of the first user plane resource.
[0244] The first user plane resource includes the user plane resource established between the source wireless access network device and the first terminal device.
[0245] Optionally, the target wireless access network device preferentially determines whether to enable user plane integrity protection for user plane resources for which the user plane security policy is required, and then determines whether to enable user plane integrity protection for user plane resources for which the user plane security policy is optional (prefered).
[0246] Optionally, after the target radio access network device determines whether to enable user plane integrity protection for the user plane resources, step 503 is repeated until the determination of whether user plane integrity protection for all user plane resources included in the first user plane resources is enabled is completed.
[0247] For example, if the first user plane resource includes DRB11, DRB12, and DRB13, the user plane security policy of DRB11 indicates that user plane integrity protection is turned on, the user plane security policy of DRB12 indicates that user plane integrity protection is optionally turned on, and the user plane security policy of DRB13 indicates that user plane integrity protection is not turned on, then the target wireless access network device first determines whether the user plane integrity protection of DRB11 can be turned on based on the required rate and the remaining rate of DRB11 (the maximum integrity protection rate at this time), and the target wireless access network device then determines whether the user plane integrity protection of DRB12 can be turned on based on the required rate and the remaining rate of DRB12. The target wireless access network device does not turn on the user plane integrity protection of DRB13.
[0248] The step 503 can refer to the introduction of the above step 302 and will not be repeated here.
[0249] Step 504: The target radio access network device sends a handover response message to the source radio access network device.
[0250] The handover response message includes security indication information. The security indication information can be found in the introduction of the security indication information in step 408 above, and will not be described in detail here.
[0251] Step 505: The source radio access network device sends an RRC reconfiguration message to the first terminal device. Correspondingly, the first terminal device receives the RRC reconfiguration message from the source radio access network device.
[0252] The description of step 505 can be found in the above step 408 and will not be repeated here.
[0253] Step 506: The first terminal device sends an RRC reconfiguration completion message to the target wireless access network device.
[0254] The RRC reconfiguration completion message in step 506 can be found in the introduction of step 409 above, and will not be repeated here.
[0255] Scenario 3: Applicable to the RRC connection recovery process.
[0256] See also Figure 6 , is a communication method for RRC connection recovery process provided by this application. In this method, the target wireless access network device is the above Figure 3 The method comprises the following steps:
[0257] Step 601: The first terminal device sends an RRC recovery request message to the target radio access network device. Correspondingly, the target access network device receives the RRC recovery request message from the first terminal device.
[0258] In one possible implementation, the RRC recovery request message is used to request restoration of the RRC connection, and the RRC recovery request message may include an identifier of the first terminal device.
[0259] Step 602: The target radio access network device sends a UE context request message (UE Context Request) to the source radio access network device according to the RRC recovery request message. Correspondingly, the source access network device receives the UE context request message from the target radio access network device.
[0260] In a possible implementation manner, the context request message of the terminal device is used to request the context of the first terminal device, and the context request message of the terminal device includes an identifier of the first terminal device.
[0261] Step 603: The source wireless access network device determines the terminal device context of the first terminal device according to the context request message of the terminal device.
[0262] Here, the source wireless access network device can determine the context of the terminal device based on the identifier of the first terminal device in the context request message of the terminal device, and the context of the terminal device includes the required rate, user plane security policy and maximum integrity protection rate of the first terminal device.
[0263] Step 604: The source wireless access network device sends a UE context response message (UE Context Response) to the target wireless access network device. Correspondingly, the target wireless access network device receives the UE context response message from the source wireless access network device.
[0264] The context response message of the terminal device includes the required rate, user plane security policy and maximum integrity protection rate of the first terminal device.
[0265] For step 604 , please refer to the introduction of step 501 .
[0266] Step 605: The target wireless access network device determines the remaining rate of the first terminal device according to the maximum integrity protection rate and the used rate of the first terminal device.
[0267] The step 605 can refer to the introduction of the above step 502 and will not be repeated here.
[0268] Step 606: The target radio access network device determines whether to enable user plane integrity protection of the first user plane resource based on the required rate and user plane security policy in the context response message of the terminal device and the determined remaining rate.
[0269] The step 606 can refer to the introduction of the above step 504 and will not be repeated here.
[0270] Step 607: The target radio access network device sends an RRC reconfiguration message to the first terminal device. Correspondingly, the first terminal device receives the RRC reconfiguration message from the target radio access network device.
[0271] The description of step 607 can be found in the above step 408 and will not be repeated here.
[0272] Step 608: The first terminal device sends an RRC reconfiguration completion message to the target wireless access network device.
[0273] The step 608 can be referred to the introduction of the above step 409 and will not be repeated here.
[0274] Scenario 4 is applied to the bearer addition process or bearer modification process in a dual-connection system.
[0275] like Figure 7 As shown, this application provides a communication method for a secondary node in dual connectivity. In this method, the secondary node is the above-mentioned Figure 3 The method comprises the following steps:
[0276] Step 701: The master node obtains the required rate, maximum integrity protection rate, used rate and user plane security policy of the first terminal device.
[0277] In one possible implementation, the primary node determines to load the established first user plane resource to the secondary node, that is, the primary node determines to unload the first user plane resource and requests the secondary node to establish the first user plane resource for the first terminal. The primary node can obtain the required rate, maximum integrity protection rate, used rate and user plane security policy of the first terminal device from the context of the terminal device stored locally.
[0278] At this time, the used rate is used to indicate that the second user plane resources established between the first terminal device and the master node do not include the rate used by the first user plane resources. Optionally, the second user plane resources include all established user plane resources of the first terminal device excluding the first user plane resources. Optionally, if user plane integrity protection has been enabled for the first user plane resources, the second user plane resources include the user plane resources with user plane integrity protection enabled among the user plane resources established by the first terminal device.
[0279] For example, taking the user plane resource as DRB, the user plane resources established between the first terminal device and the master node include DRB11, DRB12, DRB13 and DRB14, among which DRB11, DRB12 and DRB13 have enabled user plane integrity protection, and DRB14 has not enabled user plane integrity protection. The master node is preparing to load DRB11 to the secondary node, then the second user plane resources include DRB12 and DRB13.
[0280] In another possible implementation, when the master node determines to request the secondary node to establish the first user plane resource for the first terminal, that is, the master node does not unload the existing user plane resource, the master node can obtain the required rate, maximum integrity protection rate, used rate and user plane security policy of the first terminal device from the context obtained by the terminal device stored locally. At this time, the acquisition of the used rate can refer to the above Figure 3 The method of determining the used rate in step 301 will not be repeated here.
[0281] Step 702: The primary node sends an SN Addition Request message or an SN Modification Request message of the first terminal device to the secondary node. Correspondingly, the secondary node receives the SN Addition Request message or the SN Modification Request message from the primary node.
[0282] Here, the SN Addition Request message or the SN Modification Request message carries the required rate, maximum integrity protection rate, used rate and user plane security policy of the first terminal device.
[0283] Step 703: The secondary node determines the remaining rate according to the maximum integrity protection rate and the used rate.
[0284] The method for determining the remaining rate in step 301 may be referred to in step 703 , and will not be repeated here.
[0285] Step 704: The secondary node determines whether to enable user plane integrity protection for the first user plane resource based on the required rate, the remaining rate, and the user plane security policy.
[0286] The step 704 can be referred to the introduction of the above step 302 and will not be repeated here.
[0287] Step 705: The secondary node sends an SN Addition Request ACK message or an SN Modification Request ACK message to the primary node.
[0288] Here, the SN Addition Request ACK message or the SN Modification Request ACK message includes security indication information. The security indication information is used to instruct the first terminal device to enable or disable user plane integrity protection of the first user plane resource.
[0289] Optionally, the SN Addition Request ACK message or the SN Modification Request ACK message includes a rate used to enable user plane integrity protection for the first user plane resource, where the rate used indicates the rate used after enabling user plane integrity protection for the first user plane resource. The secondary node may send the message to the primary node after determining to enable user plane integrity protection for the first user plane resource.
[0290] Step 706: The primary node obtains and records the rate used for enabling user plane integrity protection of the first user plane resource from the secondary node.
[0291] In one possible implementation, the master node may record the rate used for user plane integrity protection of the first user plane resource in the context of the terminal device of the first terminal device. The next time a new user plane resource is created, the rate used for enabling user plane integrity protection of the first user plane resource is used as the second user plane resource, becoming the input for obtaining the used rate.
[0292] Step 707: The master node sends an RRC reconfiguration message to the first terminal device. Correspondingly, the first terminal device receives the RRC reconfiguration message from the master node.
[0293] Step 707 is an optional step. Please refer to the introduction of step 408 above and will not be repeated here.
[0294] Step 708: The first terminal device sends an RRC reconfiguration completion message to the master node.
[0295] The step 708 can be referred to the introduction of the above step 409 and will not be repeated here.
[0296] Through the above steps 701 to 708, the master node sends the determined maximum integrity protection rate, used rate, required rate and user plane security policy of the first terminal device to the slave node. The slave node can accurately determine whether to enable user plane integrity protection of the first user plane resource based on the maximum integrity protection rate, used rate, required rate and user plane security policy, so as to ensure the timeliness and security of the terminal device's transmission data as much as possible.
[0297] Scenario 5 is applied to the bearer addition process or bearer modification process in a dual-connection system.
[0298] See Figure 8 , is a communication method for a secondary node of a dual connection provided by this application. In the method, the secondary node is the above-mentioned Figure 3 The method comprises the following steps:
[0299] Step 801: The master node obtains the used rate, required rate, maximum integrity protection rate and user plane security policy of the first terminal device.
[0300] The description of step 801 can be found in the above step 701 and will not be repeated here.
[0301] Step 802: The master node determines the remaining rate according to the maximum integrity protection rate and the used rate.
[0302] The method for determining the remaining rate in step 301 above may be referred to in step 802, and will not be repeated here.
[0303] Step 803: The primary node sends an SN Addition Request message or an SN Modification Request message to the secondary node. Correspondingly, the secondary node receives the SN Addition Request message or the SN Modification Request message from the primary node.
[0304] Here, the SN Addition Request message or the SN Modification Request message carries the required rate, remaining rate and user plane security policy of the first terminal device.
[0305] Step 804: The secondary node determines whether to enable user plane integrity protection for the first user plane resource based on the required rate, the remaining rate, and the user plane security policy.
[0306] The step 804 can be referred to the introduction of the above step 302 and will not be repeated here.
[0307] Step 805: The secondary node sends an SN Addition Request ACK message or an SN Modification Request ACK message to the primary node.
[0308] Here, the SN Addition Request ACK message or the SN Modification Request ACK message includes security indication information. The security indication information is used to instruct the first terminal device to enable or disable user plane integrity protection of the first user plane resource.
[0309] Optionally, the SN Addition Request ACK message or the SN Modification Request ACK message includes a rate used to enable user plane integrity protection for the first user plane resource, where the rate used indicates the rate used after enabling user plane integrity protection for the first user plane resource. The secondary node may send the message to the primary node after determining to enable user plane integrity protection for the first user plane resource.
[0310] Step 806: The primary node obtains and records the rate used for enabling user plane integrity protection of the first user plane resource from the secondary node.
[0311] For step 806, please refer to the introduction of step 706 above, which will not be repeated here.
[0312] Step 807: The master node sends an RRC reconfiguration message to the first terminal device. Accordingly, the first terminal device receives the RRC reconfiguration message from the master node.
[0313] Step 807 is an optional step. Please refer to the introduction of step 408 above and will not be repeated here.
[0314] Step 808: The first terminal device sends an RRC reconfiguration completion message to the master node.
[0315] Through the above steps 801 to 808, the main node sends the determined remaining rate, required rate and user plane security policy of the first terminal device to the auxiliary node. The auxiliary node can accurately determine whether to enable user plane integrity protection of the first user plane resources based on the remaining rate, required rate and user plane security policy of the first terminal device, so as to ensure the timeliness and security of the terminal device's transmission data as much as possible.
[0316] above Figure 8 With the above Figure 7 The difference is that Figure 7 The remaining rate is determined by the auxiliary node; Figure 8 The remaining rate in is determined by the master node.
[0317] Scenario 6: Applicable to the bearer addition process or bearer modification process in a dual-connection system.
[0318] See Figure 9 , is a communication method for a dual-connected master node provided by this application. In this method, the master node is the above Figure 3 The method comprises the following steps:
[0319] Step 901: The master node obtains the required rate, maximum integrity protection rate, used rate and user plane security policy of the first terminal device.
[0320] In one possible implementation, when the master node determines to establish a first user plane resource for the first terminal device, the master node may trigger acquisition of the required rate, maximum integrity protection rate, used rate, and user plane security policy of the first terminal device.
[0321] Step 902: The master node determines the remaining rate according to the maximum integrity protection rate and the used rate.
[0322] The method for determining the remaining rate in step 301 above may be referred to in step 902, and will not be repeated here.
[0323] Step 903: The master node determines whether to enable user plane integrity protection for the first user plane resource based on the required rate, the remaining rate, and the user plane security policy.
[0324] The step 903 can refer to the introduction of the above step 302 and will not be repeated here.
[0325] Step 904: The primary node sends fourth indication information to the secondary node.
[0326] Here, the fourth indication information is used to instruct the secondary node to determine whether to enable user plane integrity protection. It can also be understood that the fourth indication information is used to indicate whether the primary node has determined whether to enable user plane integrity protection for the first user plane resource. That is, the fourth indication information is used to notify the secondary node whether the primary node has enabled user plane integrity protection for the first user plane resource. The fourth indication information can also be referred to as user plane security decision information.
[0327] Step 904 is an optional step. In a possible implementation, the primary node sends an SN Addition Request message or an SN Modification Request message to the secondary node, where the SN Addition Request message or the SN Modification Request message carries the fourth indication information.
[0328] Step 905: The master node sends an RRC reconfiguration message to the first terminal device. Correspondingly, the first terminal device receives the RRC reconfiguration message from the master node.
[0329] The description of step 905 can be found in the above step 408 and will not be repeated here.
[0330] Step 906: The first terminal device sends an RRC reconfiguration completion message to the master node.
[0331] The step 906 can be referred to the introduction of the above step 409 and will not be repeated here.
[0332] It can be seen from the above steps 901 to 906 that after the primary node in the dual connection accurately determines whether to enable the user plane integrity protection of the first user plane resource, it notifies the secondary node of the judgment result, so that the secondary node can also accurately determine whether to enable the user plane integrity protection of the first user plane resource, so as to ensure the timeliness and security of the transmission data of the terminal device as much as possible.
[0333] Scenario 7: Applicable to the PDU session establishment process, PDU session modification process, or EPS bearer establishment process.
[0334] See also Figure 10 , is another communication method for wireless access network equipment provided by this application. In this method, the wireless access network equipment is the above-mentioned Figure 3 The method may include the following steps:
[0335] Step 1001: The first terminal device obtains the used rate and maximum integrity protection rate of the first terminal device.
[0336] In one possible implementation, when the first terminal device determines to request PDU session establishment or PDU session modification or EPS bearer establishment, it can trigger acquisition of the used rate and maximum integrity protection rate of the first terminal device.
[0337] In one possible implementation, the first terminal device may determine a used rate of the first terminal device based on the second user plane resources in the first terminal device; and may determine a maximum integrity protection rate of the first terminal device based on the performance of the first terminal device. For example, if the performance of the first terminal device is high, the maximum integrity protection rate may be larger; if the performance of the first terminal device is low, the maximum integrity protection rate may be smaller.
[0338] Step 1002: The first terminal device determines the remaining rate based on the maximum integrity protection rate and the used rate.
[0339] The method for determining the remaining rate in step 301 above may be referred to in step 1002, and will not be repeated here.
[0340] Step 1003: The first terminal device sends a second request message to the session management network element.
[0341] Here, the second request message is used to request PDU session establishment or PDU session modification or request bearer resource change. The second request message includes the remaining rate of the first terminal device.
[0342] Step 1004: The session management network element sends a second response message to the wireless access network device. Correspondingly, the wireless access network device receives the second response message from the session management network element.
[0343] The second response message includes the remaining rate of the first terminal device.
[0344] Step 1005: The radio access network device obtains the required rate and user plane security policy for establishing the first user plane resource.
[0345] In a possible implementation manner, the radio access network device may obtain the user plane security policy and required rate of the first user plane resource from the context information of the terminal device.
[0346] Step 1006: The wireless access network device determines whether to enable user plane integrity protection of the first user plane resource based on the required rate for establishing the first user plane resource, the remaining rate of the first terminal device, and the user plane security policy of the first user plane resource.
[0347] The step 1006 can be referred to the introduction of the above step 302 and will not be repeated here.
[0348] Step 1007: The radio access network device sends an RRC reconfiguration message to the first terminal device. Correspondingly, the first terminal device receives the RRC reconfiguration message from the radio access network device.
[0349] Step 1007 is an optional step. Please refer to the introduction of step 408 above and will not be repeated here.
[0350] Step 1008: The first terminal device sends an RRC reconfiguration completion message to the wireless access network device.
[0351] Through the above steps 1001 to 1008, the first terminal device determines the remaining rate based on the maximum integrity protection rate and the used rate, and sends the remaining rate to the wireless access network device. The wireless access network device accurately determines whether the first terminal device needs to enable user plane integrity protection of the first user plane resources based on the required rate and the remaining rate of the first terminal device, so as to ensure the timeliness and security of the terminal device's transmission data as much as possible.
[0352] Scenario 8: Applicable to vehicle to everything (V2X) scenario.
[0353] See also Figure 11 , is a communication method applied to a second terminal device provided by this application. In this method, the second terminal device is the above Figure 3 The method may include the following steps:
[0354] Step 1101: The first terminal device obtains the used rate, maximum integrity protection rate, and user plane security policy of the first terminal device.
[0355] Here, the first terminal device obtains the used rate and maximum integrity protection rate of the first terminal device. Please refer to the introduction of the above step 1001, which will not be repeated here.
[0356] In a possible implementation, when the first terminal device is about to communicate with the second terminal device, the first terminal device may trigger acquisition of the used rate and maximum integrity protection rate of the first terminal device.
[0357] Step 1102: The first terminal device determines the remaining rate of the first terminal device according to the maximum integrity protection rate and the used rate of the first terminal device.
[0358] The method for determining the remaining rate in step 301 above may be referred to in step 1102, and will not be repeated here.
[0359] Step 1103: The first terminal device sends a direct communication request message or a direct connection safety mode command message to the second terminal device. Correspondingly, the second terminal device receives the direct communication request message or the direct connection safety mode command message from the first terminal device.
[0360] In a possible implementation, the direct communication request message or the direct connection security mode command message carries the remaining rate and user plane security policy of the first terminal device.
[0361] Step 1104: The second terminal device obtains the required rate of the first user plane resource.
[0362] In one possible implementation, the second terminal device obtains the remaining rate of the first terminal device and the user plane security policy for establishing the first user plane resource from the first terminal device. Further, the second terminal device obtains the required rate for establishing the first user plane resource from the context of the second terminal device.
[0363] Step 1105: The second terminal device determines whether to enable user plane integrity protection of the first user plane resource based on the required rate for establishing the first user plane resource, the remaining rate of the first terminal device, and the user plane security policy of the first user plane resource.
[0364] Step 1106 is an optional step. Please refer to the introduction of step 302 above and will not be repeated here.
[0365] Step 1106: The second terminal device sends a direct communication response message or a direct connection security mode response message to the first terminal device. Correspondingly, the first terminal device receives a security indication message from the second terminal device.
[0366] Here, the direct connection communication response message or the direct connection security mode response message may include a security indication message. The security indication message is used to indicate whether to enable or disable user plane integrity protection of the first user plane resource.
[0367] Step 1107: The first terminal device sends a security indication completion message to the second terminal device.
[0368] Through the above steps 1101 to 1107, the first terminal device determines the remaining rate based on the maximum integrity protection rate and the used rate, and sends the remaining rate to the second terminal device. The second terminal device determines the required rate and the remaining rate of the first terminal device, and accurately judges whether the first terminal device needs to enable user plane integrity protection of the first user plane resources, so as to ensure the timeliness and security of the terminal device's transmission data as much as possible.
[0369] It should be noted that the above Figures 4 to 11The first user plane resource in may be a DRB, and the above Figure 11 The first user plane resource in the example may be an SLBR. The first user plane resource refers to a user plane resource to be established by the first terminal device; and the second user plane resource refers to a user plane resource already established by the first terminal device.
[0370] It is understood that in order to implement the functions in the above embodiments, the communication device may include hardware structures and / or software modules that perform the corresponding functions. Those skilled in the art should readily appreciate that, in combination with the modules and method steps of the various examples described in the embodiments disclosed in this application, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in hardware or in a manner driven by computer software depends on the specific application scenario and design constraints of the technical solution.
[0371] Based on the above content and the same idea, Figure 12 and Figure 13 This is a schematic diagram of the structure of a possible communication device provided by this application. These communication devices can be used to implement the functions of the wireless access network device or the primary node in the dual connection or the secondary node in the dual connection or the second terminal device or the wireless access network device in the switching process or the wireless access network device in the RRC connection recovery process in the above method embodiment, thereby also achieving the beneficial effects of the above method embodiment. In this application, the communication device can be as follows Figure 1a The access network device shown can also be Figure 1a The terminal device shown can also be the above Figure 1b The access network device in Figure 1b The terminal device in Figure 2 The master node in Figure 2 The auxiliary node in the embodiment may also be a module (such as a chip) applied to a terminal device, an access network device, a main node, or an auxiliary node.
[0372] like Figure 12 As shown, the communication device 1200 includes a processing module 1201 and a transceiver module 1202. The communication device 1200 is used to implement the above Figures 3 to 10 The method embodiment shown in the figure is a function of a radio access network device or a master node in a dual connection or a secondary node in a dual connection or a second terminal device or a radio access network device in a switching process or a radio access network device in an RRC connection recovery process.
[0373] When the communication device 1200 is used to implement Figure 3The functions of the method embodiment shown are: the transceiver module 1202 cooperates with the processing module 1201 to obtain the required rate, remaining rate and user plane security policy of the first terminal device, the required rate is used to indicate the rate required for the first user plane resource requested to be established by the first terminal device, the remaining rate is determined based on the used rate of the first terminal device and the maximum integrity protection rate of the first terminal device, the used rate is used to indicate the rate used by the second user plane resource established by the first terminal device, and the maximum integrity protection rate is used to indicate the maximum rate of the first terminal device after turning on user plane integrity protection; the user plane security policy includes user plane integrity protection turned on, user plane integrity protection optional turned on or user plane integrity protection turned off; the processing module 1201 is used to determine whether to turn on user plane integrity protection of the first user plane resource based on the required rate, the remaining rate and the user plane security policy.
[0374] For more detailed description of the processing module 1201 and the transceiver module 1202, please refer to Figure 3 The relevant descriptions in the method embodiment shown are directly obtained and will not be repeated here.
[0375] It should be understood that the processing module 1201 in the embodiment of the present application can be implemented by a processor or a processor-related circuit component, and the transceiver module 1202 can be implemented by a transceiver or a transceiver-related circuit component.
[0376] Based on the above content and the same concept, Figure 13 As shown, the present application also provides a communication device 1300. The communication device 1300 may include a processor 1301 and a transceiver 1302. The processor 1301 and the transceiver 1302 are coupled to each other. It is understood that the transceiver 1302 may be an interface circuit or an input / output interface. Optionally, the communication device 1300 may also include a memory 1303 for storing instructions executed by the processor 1301, or storing input data required by the processor 1301 to execute instructions, or storing data generated after the processor 1301 executes instructions.
[0377] When the communication device 1300 is used to implement Figure 3 When performing the method shown, the processor 1301 is used to execute the functions of the processing module 1201, and the transceiver 1302 is used to execute the functions of the transceiver module 1202.
[0378] When the communication device is a terminal device, Figure 14 The following is a simplified schematic diagram of the terminal device. Figure 14 In this article, the terminal device is a mobile phone. Figure 14As shown, the terminal device 1400 includes a processor, a memory, a radio frequency circuit, an antenna, and input and output devices. The processor is mainly used to process communication protocols and communication data, as well as to control the entire terminal device, execute software programs, and process data of software programs, for example, to support the terminal device 1400 in executing the method executed by the terminal device in any of the above embodiments. The memory is mainly used to store software programs and data. The radio frequency circuit is mainly used to convert baseband signals into radio frequency signals and to process radio frequency signals. The antenna is mainly used to transmit and receive radio frequency signals in the form of electromagnetic waves. Input and output devices, such as touch screens, display screens, keyboards, etc., are mainly used to receive data input by users and output data to users. It should be noted that some types of terminal devices may not have input and output devices.
[0379] When the terminal device is powered on, the processor reads the software program in the memory, interprets and executes the instructions of the software program, and processes the data of the software program. When data needs to be sent, the processor performs baseband processing on the data to be sent and outputs the baseband signal to the RF circuit. The RF circuit performs RF processing on the baseband signal and then transmits the RF signal to the outside in the form of electromagnetic waves via the antenna. When data is sent to the terminal device 1400, the RF circuit receives the RF signal via the antenna, converts the RF signal into a baseband signal, and outputs the baseband signal to the processor. The processor converts the baseband signal into data and processes the data.
[0380] In an optional implementation, the processor may include a baseband processor and a central processing unit. The baseband processor is mainly used to process the communication protocol and communication data, and the central processing unit is mainly used to control the entire terminal device 1400, execute software programs, and process software program data. Figure 14 The processor in the embodiment integrates the functions of a baseband processor and a central processing unit. It should be noted that the baseband processor and the central processing unit can also be independent processors interconnected via a bus or other technology. In addition, the terminal device can include multiple baseband processors to adapt to different network standards, and the terminal device 1400 can include multiple central processing units to enhance its processing capabilities. The various components of the terminal device 1400 can be connected via various buses. The baseband processor can also be expressed as a baseband processing circuit or a baseband processing chip. The central processing unit can also be expressed as a central processing circuit or a central processing chip. The function of processing communication protocols and communication data can be built into the processor or stored in a storage module in the form of a software program, which is executed by the processor to implement the baseband processing function.
[0381] In this application, the antenna and radio frequency circuit with transceiver function can be regarded as the transceiver module of the terminal device, and the processor with processing function can be regarded as the processing module of the terminal device. Figure 14As shown, the terminal device includes a processing module 1401 and a transceiver module 1402. The transceiver module may also be referred to as a transceiver, a transceiver, a transceiver device, etc., and the processing module may also be referred to as a processor, a processing board, a processing unit, a processing device, etc. Optionally, the device used to implement the receiving function in the transceiver module may be referred to as a receiving module, and the device used to implement the transmitting function in the transceiver module may be referred to as a transmitting module. That is, the transceiver module includes a receiving module and a transmitting module. For example, the receiving module may also be referred to as a receiver, a receiver, a receiving circuit, etc., and the transmitting module may be referred to as a transmitter, a transmitter, or a transmitting circuit, etc.
[0382] On the downlink, the antenna receives the downlink signal (including data and / or control information) sent by the network device, and on the uplink, the antenna sends the uplink signal (including data and / or control information) to the network device or other terminal devices. In the processor, the service data and signaling messages are processed. These modules are processed according to the wireless access technology adopted by the wireless access network (for example, LTE, NR and other evolved system access technologies). The processor is also used to control and manage the actions of the terminal device and to execute the processing performed by the terminal device in the above embodiment. The processor is also used to support the terminal device to execute Figure 3 The execution method of the terminal device is involved.
[0383] It should be noted that Figure 14 Only one memory, one processor, and one antenna are shown. In an actual terminal device, the terminal device may include any number of antennas, memories, processors, etc. The memory may also be referred to as a storage medium or storage device. Furthermore, the memory may be independent of the processor or integrated with the processor, and this is not limited in the present embodiment.
[0384] It should be understood that the transceiver module 1402 is used to perform the above Figure 3 In the method embodiment shown in FIG. 1 , the sending operation and the receiving operation on the terminal device side are performed, and the processing module 1401 is used to perform the above Figure 3 In the embodiment of the method shown, the terminal device side performs other operations besides the sending and receiving operations. For example, the sending and receiving module 1402 is used to perform Figure 3 The sending and receiving steps on the terminal device side in the embodiment shown are, for example, step 301. The processing module 1401 is used to execute Figure 3 The terminal device side in the illustrated embodiment performs other operations besides the sending and receiving operations, such as step 302 .
[0385] When the communication device is a chip-type device or circuit, the communication device may include a transceiver module and a processing module. The transceiver module may be an input / output circuit and / or an interface circuit; and the processing module may be a processor, microprocessor, or integrated circuit integrated on the chip.
[0386] When the communication device is a wireless access network device, Figure 15 The following is an example of a structural diagram of a wireless access network device provided by this application. Figure 15 As shown, the radio access network device 1500 may include one or more radio frequency units, such as a remote radio unit (RRU) 1502 and one or more baseband units (BBU) 1501. The RRU 1502 may be referred to as a transceiver module, transceiver, transceiver circuit, or transceiver, and may include at least one antenna 15021 and a radio frequency unit 15022. The RRU 1502 is primarily responsible for transmitting and receiving radio frequency signals and converting radio frequency signals into baseband signals. The BBU 1501 may be referred to as a processing module, processor, or the like, and is primarily responsible for baseband processing, such as channel coding, multiplexing, modulation, and spread spectrum, as well as controlling the radio access network device. The RRU 1502 and BBU 1501 may be physically located together, or they may be physically separated, i.e., distributed radio access network equipment.
[0387] The BBU 1501 is the control center of the base station, which can also be called a processing module. Figure 12 The processing module 1201 in the embodiment corresponds to the baseband processing module 1201, which is mainly used to perform baseband processing functions such as channel coding, multiplexing, modulation, spread spectrum, etc. For example, the BBU (processing module) can be used to control the base station to execute the operation process of the wireless access network device in the above method embodiment, for example, determining whether to enable user plane integrity protection of the first user plane resource.
[0388] As an optional implementation method, BBU1501 can be composed of one or more single boards. Multiple single boards can jointly support a wireless access network with a single access standard (such as an LTE network), or can separately support wireless access networks with different access standards (such as an LTE network, a 5G network, or other networks). BBU1501 also includes a memory 15012 and a processor 15011. The memory 15012 is used to store necessary instructions and data. The processor 15011 is used to control the wireless access network device to perform necessary actions, such as controlling the wireless access network device to execute the method executed by the wireless access network device in any of the above embodiments. The memory 15012 and the processor 15011 can serve one or more single boards. That is, a memory and a processor can be set separately on each single board. Alternatively, multiple single boards can share the same memory and processor. In addition, necessary circuits are also provided on each single board.
[0389] On the uplink, the uplink signal (including data, etc.) sent by the terminal device is received through the antenna 15021. On the downlink, the downlink signal (including data and / or control information) is sent to the terminal device through the antenna 15021. In the processor 15011, the service data and signaling messages are processed. These modules are processed according to the wireless access technology adopted by the wireless access network (for example, LTE, NR and other evolved system access technologies). The processor 15011 is also used to control and manage the actions of the wireless access network device and to execute the processing performed by the wireless access network device in the above embodiment. The processor 15011 is also used to support the wireless access network device to execute Figure 3 A method executed by a wireless access network device in the wireless access network.
[0390] It should be noted that Figure 15 Only a simplified design of a radio access network device is shown. In actual applications, the radio access network device may include any number of antennas, memories, processors, radio frequency units, RRUs, BBUs, etc., and all radio access network devices that can implement this application are within the scope of protection of this application.
[0391] It should be understood that the transceiver module 1502 is used to perform the above Figure 3 In the sending operation and receiving operation in the method embodiment shown, the processing module 1501 is used to perform the above Figure 3 In the embodiment of the method shown, other operations besides the sending and receiving operations are performed. For example, step 301. Processing module 1501 is used to perform Figure 3 Other operations besides the sending and receiving operations in the illustrated embodiment, for example, step 302 .
[0392] Based on the above content and the same concept, the present application provides a communication system. This communication system may include one or more terminal devices and one or more radio access network devices as described above. The terminal devices may execute any terminal device-side method, and the radio access network devices may execute any radio access network device-side method. Possible implementations of the radio access network devices and terminal devices can be found in the above description and will not be further elaborated here.
[0393] It is understood that the processor in the embodiments of the present application may be a central processing unit (CPU), or may be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.
[0394] The method steps in the embodiments of the present application can be implemented by hardware or by a processor executing software instructions. The software instructions can be composed of corresponding software modules, which can be stored in random access memory (RAM), flash memory, read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), registers, hard disks, mobile hard disks, CD-ROMs, or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be an integral part of the processor. The processor and storage medium can be located in an ASIC. In addition, the ASIC can be located in a network device or a terminal device. Of course, the processor and storage medium can also exist as discrete components in a network device or a terminal device.
[0395] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware or any combination thereof. When implemented using software, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the process or function described in the embodiments of the present application is performed in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device or other programmable device. The computer program or instruction can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer program or instruction can be transmitted from one website, computer, server or data center to another website, computer, server or data center via wired or wireless means. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium, such as a floppy disk, a hard disk, or a tape; it can also be an optical medium, such as a digital video disc (DVD); it can also be a semiconductor medium, such as a solid state drive (SSD).
[0396] In the various embodiments of the present application, unless otherwise specified or there is a logical conflict, the terms and / or descriptions between different embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.
[0397] In the present application, "at least one" means one or more, and "plurality" means two or more. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b or c can be represented by: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple. "And / or" describes the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can be represented by: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. In the textual description of the present application, the character " / " generally indicates that the previous and next associated objects are in an "or" relationship; in the formula of the present application, the character " / " indicates that the previous and next associated objects are in a "division" relationship.
[0398] It will be appreciated that the various numerical numbers involved in the embodiments of the present application are merely for the purpose of describing the distinctions made, and are not intended to limit the scope of the embodiments of the present application. The sequence numbers of the above-mentioned processes do not necessarily indicate the order of execution, and the order of execution of each process should be determined by its function and inherent logic. Terms such as "first" and "second" are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, including a series of steps or modules. Methods, systems, products, or devices are not necessarily limited to those steps or modules clearly listed, but may include other steps or modules that are not clearly listed or that are inherent to these processes, methods, products, or devices.
[0399] Obviously, those skilled in the art may make various modifications and variations to this application without departing from the scope of protection of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalents, this application is intended to include these modifications and variations.
Claims
1. A communication method, characterized in that: include: Obtaining a required rate, a remaining rate, and a user plane security policy of a first terminal device, where the required rate is used to indicate the rate required for the first user plane resource requested to be established by the first terminal device, the remaining rate is determined based on the used rate of the first terminal device and the maximum integrity protection rate of the first terminal device, the used rate is used to indicate the rate used by the second user plane resource established by the first terminal device, and the maximum integrity protection rate is used to indicate the maximum rate of the first terminal device after user plane integrity protection is enabled; the user plane security policy includes user plane integrity protection enabled, user plane integrity protection optional enabled, or user plane integrity protection disabled; Determine whether to enable user plane integrity protection of the first user plane resource according to the required rate, the remaining rate, and the user plane security policy.
2. The method according to claim 1, wherein The second user plane resource includes a user plane resource with user plane integrity protection enabled among the user plane resources established by the first terminal device.
3. The method according to claim 1 or 2, wherein: The method further comprises: Determine a used rate of the first terminal device according to a rate parameter; wherein the rate parameter includes any one or a combination of any two or more of the following: a maximum bit rate of protocol data unit (PDU) session aggregation for the second user plane resource; an aggregated maximum bit rate of the first terminal device; The maximum flow bit rate of the quality of service (QoS) flow of the guaranteed bit rate (GBR) of the second user plane resource; The guaranteed bit rate GBR of the second user plane resource is the guaranteed bit rate of the quality of service Qos flow; and The real-time rate of the second user plane resource.
4. The method according to claim 3, wherein The determining, according to the rate parameter, the used rate of the first terminal device includes: Determine the sum of the maximum bit rate of all the PDU sessions aggregated and the maximum flow bit rate of all the GBR QoS flows as the used rate; or, The sum of the aggregated maximum bit rate of the terminal device and the maximum flow bit rate of all the GBR QoS flows is determined as the used rate.
5. The method according to claim 3, wherein The determining, according to the rate parameter, the used rate of the first terminal device includes: The sum of the guaranteed bit rates of all the GBR QoS flows is determined as the used rate.
6. The method according to claim 3, wherein The determining, according to the rate parameter, the used rate of the first terminal device includes: The sum of the maximum bit rate aggregated by all the PDU sessions and the guaranteed bit rates of all the GBR QoS flows is determined as the used rate.
7. The method according to any one of claims 1 to 6, wherein: In a case where the user plane security policy includes enabling or optionally enabling user plane integrity protection, the determining, according to the required rate, the remaining rate, and the user plane security policy, whether to enable user plane integrity protection of the first user plane resource includes: If the remaining rate is greater than or equal to the required rate, a first indication message is sent to the first terminal device, where the first indication message is used to indicate that user plane integrity protection of the first user plane resource is to be enabled.
8. The method according to any one of claims 1 to 6, wherein: In a case where the user plane security policy includes enabling user plane integrity protection, the determining whether to enable user plane integrity protection according to the required rate, the remaining rate, and the user plane security policy includes: If the remaining rate is less than the required rate, obtain a third user plane resource, the user plane security policy of the third user plane resource is that user plane integrity protection is optionally enabled, and user plane integrity protection has been enabled for the third user plane resource, and the used rate of the third user plane resource is greater than or equal to the difference between the required rate and the remaining rate, and send a second indication message to the first terminal device, the second indication message is used to indicate that the user plane integrity protection of the first user plane resource is enabled, and is used to indicate that the user plane integrity protection of the third user plane resource is not enabled.
9. The method according to any one of claims 1 to 6, wherein: In a case where the user plane security policy includes optional enabling of user plane integrity protection, the determining, according to the required rate, the remaining rate, and the user plane security policy, whether to enable user plane integrity protection includes: If the remaining rate is less than the required rate, third indication information is sent to the first terminal, where the third indication information is used to instruct not to enable user plane integrity protection of the first user plane resource.
10. The method according to any one of claims 1 to 9, characterized in that The method is applied to wireless access network equipment; The obtaining of the required rate, the remaining rate, and the user plane security policy of the first terminal device includes: Receiving the required rate, the maximum integrity protection rate, and the user plane security policy of the first terminal device from a session management function network element; the session management function network element obtains the required rate of the first terminal device from a policy control function network element, and obtains the maximum integrity protection rate from the first terminal device; Obtaining the used rate from the context of the first terminal device; The remaining rate is determined according to the maximum integrity protection rate and the used rate.
11. The method according to claim 10, wherein The method is applied to a dual-connected master node; The method further comprises: Sending fourth indication information to the dual-connection secondary node, where the fourth indication information is used by the secondary node to determine whether to enable user plane integrity protection.
12. The method according to any one of claims 1 to 9, characterized in that The method is applied to a wireless access network device during a handover process; The obtaining of the required rate, the remaining rate, and the user plane security policy of the first terminal device includes: Receiving a handover request message from a source wireless access network device, the handover request message including a required rate of the first terminal device, the user plane security policy, the maximum integrity protection rate, and the used rate; The remaining rate is determined according to the maximum integrity protection rate and the used rate.
13. The method according to any one of claims 1 to 9, characterized in that The method is applied to a radio access network device during a radio resource control (RRC) connection recovery process; The obtaining of the required rate, the remaining rate, and the user plane security policy of the first terminal device includes: Obtaining a context response message of the first terminal device from the target radio access network device, where the context response message of the first terminal device includes the required rate of the first terminal device, the user plane security policy, the maximum integrity protection rate, and the used rate; The remaining rate is determined according to the maximum integrity protection rate and the used rate.
14. The method according to any one of claims 1 to 9, characterized in that The method is applied to a dual-connected secondary node; The obtaining of the required rate, the remaining rate, and the user plane security policy of the first terminal device includes: receiving the required rate, the maximum integrity protection rate, the used rate, and the user plane security policy sent from the dual-connected master node; The remaining rate is determined according to the maximum integrity protection rate and the used rate.
15. The method according to any one of claims 10 to 14, characterized in that The determining the remaining rate according to the maximum integrity protection rate and the used rate includes: The difference between the maximum integrity protection rate and the used rate is determined as the remaining rate.
16. The method according to any one of claims 1 to 9, characterized in that The method is applied to a dual-connected secondary node; The obtaining of the required rate, the remaining rate, and the user plane security policy of the first terminal device includes: The required rate, the remaining rate, and the user plane security policy are received from a master node.
17. The method according to any one of claims 14 to 16, characterized in that The method further comprises: Sending a rate used for enabling user plane integrity protection of the first user plane resource to the dual-connection master node.
18. The method according to any one of claims 1 to 9, characterized in that The method is applied to a second terminal device; The obtaining of the required rate, the remaining rate, and the user plane security policy of the first terminal device includes: Receiving the remaining rate and user plane security policy from the first terminal device; The required rate is obtained from the context of the first terminal device.
19. A communication device, characterized in that: Comprising means for performing the method as claimed in any one of claims 1 to 18.
20. A communication device, characterized in that: The method comprises a processor and a transceiver, wherein the transceiver is used to receive signals from other communication devices other than the communication device and transmit them to the processor, or to send signals from the processor to other communication devices other than the communication device, and the processor is used to perform the method according to any one of claims 1 to 18 through logic circuits or execution code instructions.