User plane data processing method and device, node and equipment

By using the user plane interface transmission protocol in the 5G network to carry configuration information and finely control the integrity protection of data packets, the delay problem in DRB or PDU sessions is solved, and the network performance and data transmission efficiency are improved.

CN120614601APending Publication Date: 2025-09-09DATANG MOBILE COMM EQUIP CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410262590.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-03-07
Publication Date
2025-09-09

AI Technical Summary

Technical Problem

The latency problem caused by integrity protection processing based on DRB or PDU sessions in existing 5G networks affects data transmission efficiency, especially when the load increases under high peak data rate requirements.

Method used

By carrying configuration information in the user plane interface transmission protocol, the integrity protection of the control data packet is refined, including indicating whether to perform integrity protection, protection type and priority, etc., and using the GTP-U extension header to carry new parameters or containers, dynamic adjustment is performed in combination with the control plane interface message.

Benefits of technology

It achieves refined control of data packet integrity protection, reduces unnecessary integrity protection operations, reduces device complexity and latency, and improves network performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120614601A_ABST
    Figure CN120614601A_ABST
Patent Text Reader

Abstract

Provided are a user plane data processing method, apparatus, node and device, the method comprising: a first network node receiving a target object sent by a second network node, the target object comprising at least one of a data packet and a plurality of data packets; the first network node determines integrity protection information of the target object according to first configuration information carried in a user plane interface transmission protocol of at least one data packet in the target object; according to the embodiment of the invention, fine control on operations such as data packet integrity protection or verification can be realized, and under the condition of ensuring data transmission security, the situation that excessive integrity protection operations increase data processing flow and time delay and consume air interface resources is avoided, so that the complexity of equipment implementation is reduced, and the network performance is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technology, and in particular to a method, apparatus, node, and device for processing user plane data. Background Art

[0002] In the current network's user plane processing flow, the User Plane Function (UPF) first identifies the appropriate Packet Data Unit (PDU) session and Quality of Service (QoS) flow. The UPF then forwards the data to the 5G base station (gNodeB) using a GPRS Tunneling Protocol-Userplane (GTP-U) tunnel. Each PDU session is assigned a GTP-U tunnel, and the Tunnel Endpoint Identifier (TEID) in the GTP-U header identifies the PDU session. A "PDU Session Container" is added to the flow information in the GTP-U header.

[0003] The gNodeB Central Unit (CU) uses the GTP-U header to identify the PDU session and QoS flow associated with the packet. The packet is then processed by the Service Data Adaptation Protocol (SDAP) layer, which is responsible for mapping the packet to a specific Data Radio Bearer (DRB). The SDAP layer passes the packet to the Packet Data Convergence Protocol (PDCP) layer using its assigned DRB.

[0004] The PDCP layer provides security in terms of integrity protection and encryption. Integrity protection is achieved by calculating an authentication code (MAC-I field) and including it in the PDCP PDU (Protocol Data Unit). The receiver uses this authentication code to verify the authenticity of the data packet to prevent insertion by intruders. Generally, PDCPData PDUs carried by SRBs need to be integrity protected. For data carried by DRBs, integrity protection is determined by the RRC indicating whether integrity protection is configured for this radio bearer in the integrityProtection of the corresponding DRB in the PDCP-config configuration. Moreover, the network configures the same value for all DRBs with the same PDU session ID. After the DRB is established, the value of this field cannot be changed. MAC-I is fixed to 32 bits, or 4 bytes. For small data packets, such as industrial control, voice calls and other scenarios, this overhead cannot be ignored.

[0005] Existing networks have at least the following problems in terms of integrity protection:

[0006] 5G introduces a mechanism for DRBs to support integrity protection. Currently, PDCP integrity protection is configured by Radio Resource Control (RRC) in the radio bearer configuration. The network configures the same value for all DRBs with the same PDU session ID. This means that all packets in a DRB configured with integrity protection must be integrity protected. This causes the integrity protection processing load to increase as the UE peak data rate continues to increase. As more and more applications require higher and higher peak data rates, the load caused by integrity protection processing will become increasingly serious, causing latency issues. Summary of the Invention

[0007] The purpose of the embodiments of the present application is to provide a user plane data processing method, device, node and equipment to solve the delay problem caused by the integrity protection processing based on DRB or PDU session in the prior art.

[0008] In order to solve the above problems, an embodiment of the present application provides a method for processing user plane data, the method comprising:

[0009] The first network node receives a target object sent by the second network node, where the target object includes at least one of the following: a data packet, or multiple data packets;

[0010] The first network node determines the integrity protection information of the target object according to first configuration information carried in a user plane interface transmission protocol of at least one data packet in the target object.

[0011] The method further comprises:

[0012] In a case where the integrity protection information of the target object indicates that the target object needs to be integrity protected, integrity protection is performed on the target object.

[0013] The method further comprises:

[0014] The first network node sends one or more data packets of a target object to the terminal, where a Packet Data Convergence Protocol (PDCP) header of at least one data packet of the target object carries first indication information, where the first indication information includes at least one of the following:

[0015] First information for indicating whether integrity protection is performed on the target object;

[0016] Second information is used to indicate that integrity protection is performed on part of the data packet.

[0017] The method further comprises:

[0018] The first network node sends a non-access stratum message or an access stratum message to the terminal, where the non-access stratum message or the access stratum message carries second indication information;

[0019] The first network node sends one or more data packets of a target object to the terminal;

[0020] The second indication information includes at least one of the following:

[0021] Third information for indicating whether integrity protection is performed on the target object;

[0022] Fourth information is used to indicate that integrity protection is performed on part of the data packet.

[0023] The multiple data packets include at least one of the following:

[0024] Multiple packets in a packet set;

[0025] Multiple packets in a data burst;

[0026] Multiple packets with the same characteristics.

[0027] The first configuration information includes at least one of the following:

[0028] First identification information indicating whether integrity protection needs to be performed on the target object;

[0029] Second identification information indicating an integrity protection type of the target object; the integrity protection type includes at least one of the following: performing integrity protection, not performing integrity protection, optionally performing integrity protection, and performing integrity protection on partial data;

[0030] Priority identification information of the integrity protection of the target object; indirectly indicating whether the target object needs to be integrity protected through the integrity protection priority;

[0031] Third identification information indicating whether the integrity protection policy of the target object is updated; the integrity protection policy includes at least one of the following: performing integrity protection and not performing integrity protection.

[0032] The user plane interface transmission protocol includes at least one of the following:

[0033] GPRS Tunneling Protocol-User Plane GTP-U header;

[0034] GTP-U extension header.

[0035] The first configuration information is carried by a first parameter or a first container in the GTP-U extension header; the first parameter is a new parameter in the PDU type; and the first container includes at least one of the following:

[0036] Protocol Data Unit PDU session container;

[0037] GTP-U container;

[0038] Newly added container.

[0039] The method further comprises:

[0040] The first network node receives a control plane interface message sent by the second network node, where the control plane interface message is used to carry second configuration information;

[0041] The first network node determines, based on the second configuration information, that it is necessary to judge whether integrity protection needs to be performed on the target object based on the first configuration information carried in the user plane interface transmission protocol.

[0042] The control plane interface message includes at least one of the following:

[0043] PDU session management message;

[0044] Next Generation Application Protocol NGAP messages;

[0045] Messages related to Quality of Service (QoS) flow parameters.

[0046] The present invention also provides a method for processing user plane data, the method comprising:

[0047] The second network node determines first configuration information; the first configuration information is used to configure integrity protection information of the target object; the target object includes at least one of the following: a data packet, multiple data packets;

[0048] The second network node sends a target object to the first network node, where a user plane interface transmission protocol of at least one data packet in the target object carries the first configuration information.

[0049] The multiple data packets include at least one of the following:

[0050] Multiple packets in a packet set;

[0051] Multiple packets in a data burst;

[0052] Multiple packets with the same characteristics.

[0053] The first configuration information includes at least one of the following:

[0054] First identification information indicating whether integrity protection needs to be performed on the target object;

[0055] Second identification information indicating an integrity protection type of the target object; the integrity protection type includes at least one of the following: performing integrity protection, not performing integrity protection, optionally performing integrity protection, and performing integrity protection on partial data;

[0056] Priority identification information of the integrity protection of the target object; indirectly indicating whether the target object needs to be integrity protected through the integrity protection priority;

[0057] Third identification information indicating whether the integrity protection policy of the target object is updated; the integrity protection policy includes at least one of the following: performing integrity protection and not performing integrity protection.

[0058] The user plane interface transmission protocol includes at least one of the following:

[0059] GPRS Tunneling Protocol-User Plane GTP-U header;

[0060] GTP-U extension header.

[0061] The first configuration information is carried by a first parameter or a first container in the GTP-U extension header; the first parameter is a new parameter in the PDU type; and the first container includes at least one of the following:

[0062] Protocol Data Unit PDU session container;

[0063] GTP-U container;

[0064] Newly added container.

[0065] The method further comprises:

[0066] The second network node sends a control plane interface message to the first network node, where the control plane interface message is used to carry second configuration information, and the second configuration information is used to instruct the first network node to determine whether the target object needs to perform integrity protection based on the first configuration information carried in the user plane interface transmission protocol.

[0067] The control plane interface message includes at least one of the following:

[0068] PDU session management message;

[0069] Next Generation Application Protocol NGAP messages;

[0070] Messages related to Quality of Service (QoS) flow parameters.

[0071] An embodiment of the present application further provides a user plane data processing device, applied to a first network node, the device comprising:

[0072] A first receiving unit is configured to receive a target object sent by a second network node, wherein the target object includes at least one of the following: a data packet or multiple data packets;

[0073] The first determining unit is configured to determine the integrity protection information of the target object according to first configuration information carried in a user plane interface transmission protocol of at least one data packet in the target object.

[0074] An embodiment of the present application further provides a first network node, including a memory, a transceiver, and a processor:

[0075] A memory for storing a computer program; a transceiver for transmitting and receiving data under the control of the processor; and a processor for reading the computer program in the memory and performing the following operations:

[0076] receiving a target object sent by a second network node, where the target object includes at least one of the following: a data packet or multiple data packets;

[0077] Integrity protection information of the target object is determined according to first configuration information carried in a user plane interface transmission protocol of at least one data packet in the target object.

[0078] The processor is further configured to read the computer program in the memory and perform the following operations:

[0079] In a case where the integrity protection information of the target object indicates that the target object needs to be integrity protected, integrity protection is performed on the target object.

[0080] The processor is further configured to read the computer program in the memory and perform the following operations:

[0081] Send one or more data packets of a target object to a terminal, where a Packet Data Convergence Protocol (PDCP) header of at least one data packet of the target object carries first indication information, where the first indication information includes at least one of the following:

[0082] First information for indicating whether integrity protection is performed on the target object;

[0083] Second information is used to indicate that integrity protection is performed on part of the data packet.

[0084] The processor is further configured to read the computer program in the memory and perform the following operations:

[0085] Sending a non-access stratum message or an access stratum message to the terminal, where the non-access stratum message or the access stratum message carries second indication information;

[0086] sending one or more data packets of a target object to the terminal;

[0087] The second indication information includes at least one of the following:

[0088] Third information for indicating whether integrity protection is performed on the target object;

[0089] Fourth information is used to indicate that integrity protection is performed on part of the data packet.

[0090] The multiple data packets include at least one of the following:

[0091] Multiple packets in a packet set;

[0092] Multiple packets in a data burst;

[0093] Multiple packets with the same characteristics.

[0094] The multiple data packets include at least one of the following:

[0095] Multiple packets in a packet set;

[0096] Multiple packets in a data burst;

[0097] Multiple packets with the same characteristics.

[0098] The user plane interface transmission protocol includes at least one of the following:

[0099] GPRS Tunneling Protocol-User Plane GTP-U header;

[0100] GTP-U extension header.

[0101] The first configuration information is carried by a first parameter or a first container in the GTP-U extension header; the first parameter is a new parameter in the PDU type; and the first container includes at least one of the following:

[0102] Protocol Data Unit PDU session container;

[0103] GTP-U container;

[0104] Newly added container.

[0105] The processor is further configured to read the computer program in the memory and perform the following operations:

[0106] receiving a control plane interface message sent by the second network node, where the control plane interface message is used to carry second configuration information;

[0107] According to the second configuration information, it is determined that it is necessary to judge whether the target object needs to perform integrity protection according to the first configuration information carried in the user plane interface transmission protocol.

[0108] The control plane interface message includes at least one of the following:

[0109] PDU session management message;

[0110] Next Generation Application Protocol NGAP messages;

[0111] Messages related to Quality of Service (QoS) flow parameters.

[0112] An embodiment of the present application further provides a user plane data processing device, applied to a second network node, the device comprising:

[0113] A second determining unit is configured to determine first configuration information; the first configuration information is used to configure integrity protection information of the target object; the target object includes at least one of the following: a data packet, a plurality of data packets;

[0114] The first sending unit is configured to send a target object to a first network node, where a user plane interface transmission protocol of at least one data packet in the target object carries the first configuration information.

[0115] The embodiment of the present application further provides a second network node, including a memory, a transceiver, and a processor:

[0116] A memory for storing a computer program; a transceiver for transmitting and receiving data under the control of the processor; and a processor for reading the computer program in the memory and performing the following operations:

[0117] Determine first configuration information; the first configuration information is used to configure integrity protection information of the target object; the target object includes at least one of the following: a data packet, multiple data packets;

[0118] A target object is sent to a first network node, where a user plane interface transmission protocol of at least one data packet in the target object carries the first configuration information.

[0119] The multiple data packets include at least one of the following:

[0120] Multiple packets in a packet set;

[0121] Multiple packets in a data burst;

[0122] Multiple packets with the same characteristics.

[0123] The first configuration information includes at least one of the following:

[0124] First identification information indicating whether integrity protection needs to be performed on the target object;

[0125] Second identification information indicating an integrity protection type of the target object; the integrity protection type includes at least one of the following: performing integrity protection, not performing integrity protection, optionally performing integrity protection, and performing integrity protection on partial data;

[0126] Priority identification information of the integrity protection of the target object; indirectly indicating whether the target object needs to be integrity protected through the integrity protection priority;

[0127] Third identification information indicating whether the integrity protection policy of the target object is updated; the integrity protection policy includes at least one of the following: performing integrity protection and not performing integrity protection.

[0128] The user plane interface transmission protocol includes at least one of the following:

[0129] GPRS Tunneling Protocol-User Plane GTP-U header;

[0130] GTP-U extension header.

[0131] The first configuration information is carried by a first parameter or a first container in the GTP-U extension header; the first parameter is a new parameter in the PDU type; and the first container includes at least one of the following:

[0132] Protocol Data Unit PDU session container;

[0133] GTP-U container;

[0134] Newly added container.

[0135] The processor is further configured to read the computer program in the memory and perform the following operations:

[0136] A control plane interface message is sent to the first network node, where the control plane interface message is used to carry second configuration information, and the second configuration information is used to instruct the first network node to determine whether the target object needs to perform integrity protection based on the first configuration information carried in the user plane interface transmission protocol.

[0137] The control plane interface message includes at least one of the following:

[0138] PDU session management message;

[0139] Next Generation Application Protocol NGAP messages;

[0140] Messages related to Quality of Service (QoS) flow parameters.

[0141] An embodiment of the present application further provides a processor-readable storage medium, wherein the processor-readable storage medium stores a computer program, and the computer program is used to enable the processor to execute the method described above.

[0142] An embodiment of the present application further provides a computer program product, comprising computer instructions, which implement the steps of the above-described method when executed by a processor.

[0143] The above technical solution of the present application has at least the following beneficial effects:

[0144] In the user plane data processing method, apparatus, node and device of the embodiments of the present application, the first network node determines the integrity protection information at the data packet level based on the first configuration information carried by the upper-layer user plane interface transmission protocol, which can achieve refined control of operations such as data packet integrity protection or verification. While ensuring the security of data transmission, it avoids excessive integrity protection operations that increase data processing procedures and delays and consume air interface resources, thereby reducing the complexity of device implementation and improving network performance. BRIEF DESCRIPTION OF THE DRAWINGS

[0145] Figure 1A block diagram showing a wireless communication system to which embodiments of the present application may be applied;

[0146] Figure 2 A flowchart showing the steps of the method for processing user plane data provided in an embodiment of the present application is provided;

[0147] Figure 3 The second step flowchart of the method for processing user plane data provided in an embodiment of the present application is shown;

[0148] Figure 4 A schematic diagram showing the structure of a user plane data processing device according to an embodiment of the present application is provided;

[0149] Figure 5 A schematic diagram showing the structure of a first network node provided in an embodiment of the present application;

[0150] Figure 6 A second structural diagram of the user plane data processing device provided in an embodiment of the present application is shown;

[0151] Figure 7 A schematic diagram showing the structure of a second network node provided in an embodiment of the present application. DETAILED DESCRIPTION

[0152] In order to make the technical problems, technical solutions and advantages to be solved by this application clearer, a detailed description will be given below with reference to the accompanying drawings and specific embodiments.

[0153] Figure 1 A block diagram of a wireless communication system to which an embodiment of the present application can be applied is shown. The wireless communication system includes a terminal device 11 and a network side device 12. The terminal device 11 may also be referred to as a terminal or a user terminal (UE). It should be noted that the specific type of the terminal 11 is not limited in the embodiment of the present application. The network side device 12 may be a base station or a core network. It should be noted that in the embodiment of the present application, only the base station in the NR system is taken as an example, but the specific type of the base station is not limited.

[0154] In the embodiments of this application, the term "and / or" describes the association relationship between associated objects, indicating that three relationships can exist. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally indicates that the associated objects are in an "or" relationship.

[0155] In the embodiments of the present application, the term "plurality" refers to two or more than two, and other quantifiers are similar.

[0156] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0157] The technical solution provided in the embodiment of the present application can be applicable to a variety of systems, especially 5G systems. For example, the applicable system can be a global system of mobile communication (GSM) system, a code division multiple access (CDMA) system, a wideband code division multiple access (WCDMA) general packet radio service (GPRS) system, a long term evolution (LTE) system, a LTE frequency division duplex (FDD) system, a LTE time division duplex (TDD) system, an advanced long term evolution (LTE-A) system, a universal mobile telecommunication system (UMTS), a world-wide interoperability for microwave access (WiMAX) system, a 5G new air interface (NR) system, etc. These various systems include terminal equipment and network equipment. The system may also include a core network part, such as an evolved packet system (EPS), a 5G system (5GS), etc.

[0158] The terminal device involved in the embodiments of the present application may be a device that provides voice and / or data connectivity to a user, a handheld device with wireless connection function, or other processing device connected to a wireless modem. In different systems, the name of the terminal device may also be different. For example, in a 5G system, the terminal device may be called User Equipment (UE). A wireless terminal device can communicate with one or more core networks (CN) via a radio access network (RAN). The wireless terminal device may be a mobile terminal device, such as a mobile phone (or "cellular" phone) and a computer with a mobile terminal device. For example, it may be a portable, pocket-sized, handheld, computer-built-in or vehicle-mounted mobile device that exchanges voice and / or data with a radio access network. For example, Personal Communication Service (PCS) phones, cordless phones, Session Initiated Protocol (SIP) phones, Wireless Local Loop (WLL) stations, Personal Digital Assistants (PDAs), and other devices. The wireless terminal device may also be referred to as a system, a subscriber unit, a subscriber station, a mobile station, a mobile station, a remote station, an access point, a remote terminal device, an access terminal device, a user terminal device, a user agent, or a user device, but is not limited in the embodiments of the present application.

[0159] The network device involved in the embodiments of the present application may be a base station, which may include multiple cells providing services to terminals. Depending on the specific application scenario, the base station may also be called an access point, or may be a device in an access network that communicates with a wireless terminal device through one or more sectors on an air interface, or may be named otherwise. The network device may be used to interchange received air frames with Internet Protocol (IP) packets, acting as a router between the wireless terminal device and the rest of the access network, wherein the rest of the access network may include an Internet Protocol (IP) communication network. The network device may also coordinate attribute management of the air interface. For example, the network device involved in the embodiments of the present application may be a network device (Base Transceiver Station, BTS) in the Global System for Mobile communications (GSM) or Code Division Multiple Access (CDMA), or a network device (NodeB) in Wide-band Code Division Multiple Access (WCDMA), or an evolutionary network device (eNB or e-NodeB) in the Long Term Evolution (LTE) system, a 5G base station (gNB) in the 5G network architecture (next generation system), or a home evolved Node B (HeNB), a relay node, a home base station (femto), a pico base station (pico), etc., which is not limited in the embodiments of the present application. In some network structures, the network device may include a centralized unit (CU) node and a distributed unit (DU) node, and the centralized unit and the distributed unit may also be geographically separated.

[0160] Network devices and terminal devices can each use one or more antennas for Multiple Input Multiple Output (MIMO) transmission. MIMO transmission can be single-user MIMO (SU-MIMO) or multi-user MIMO (MU-MIMO). Depending on the configuration and number of antenna combinations, MIMO transmission can be 2D-MIMO, 3D-MIMO, FD-MIMO, or massive-MIMO. It can also use diversity transmission, precoding transmission, or beamforming transmission.

[0161] like Figure 2 As shown, an embodiment of the present application provides a method for processing user plane data, the method comprising:

[0162] Step 201: A first network node receives a target object sent by a second network node, where the target object includes at least one of the following: a data packet, or multiple data packets.

[0163] Step 202: The first network node determines integrity protection information of the target object according to first configuration information carried in a user plane interface transmission protocol of at least one data packet in the target object.

[0164] Optionally, the integrity protection information of the target object specifically includes: whether integrity protection needs to be performed on the target object, or whether integrity protection needs to be performed on part of the data in the target object.

[0165] Optionally, the first network node includes a logical entity that can perform integrity protection and / or integrity protection verification, such as a network function (service-based), an access network node (such as gNB, eNB, CU, etc.), a terminal, etc.

[0166] In one implementation, when the target object includes a data packet, the user plane interface transmission protocol of the data packet carries the first configuration information.

[0167] In another implementation, when the target object includes multiple data packets, the user plane interface transmission protocol of the multiple data packets may all carry the first configuration information, or the user plane interface transmission protocol of the first data packet among the multiple data packets may carry the first configuration information.

[0168] In particular, if the first configuration information is carried in the user plane interface transmission protocol of the first data packet in a PDU set or a data burst, it means that until the last data packet in the PDU set or Data Burst, the first configuration information is used to indicate whether to perform integrity protection.

[0169] In at least one embodiment of the present application, the method further includes:

[0170] In a case where the integrity protection information of the target object indicates that the target object needs to be integrity protected, integrity protection is performed on the target object.

[0171] In one implementation, the method further includes:

[0172] The first network node sends one or more data packets of a target object to the terminal, where a Packet Data Convergence Protocol (PDCP) header of at least one data packet of the target object carries first indication information, where the first indication information includes at least one of the following:

[0173] First information for indicating whether integrity protection is performed on the target object;

[0174] Second information is used to indicate that integrity protection is performed on part of the data packet.

[0175] In another implementation, the method further includes:

[0176] The first network node sends a non-access stratum message or an access stratum message to the terminal, where the non-access stratum message or the access stratum message carries second indication information;

[0177] The first network node sends one or more data packets of a target object to the terminal;

[0178] The second indication information includes at least one of the following:

[0179] Third information for indicating whether integrity protection is performed on the target object;

[0180] Fourth information is used to indicate that integrity protection is performed on part of the data packet.

[0181] The first indication information or the second indication information is used to assist the terminal in determining whether integrity verification is required for the data packet. If the data packet is integrity protected, the terminal performs integrity verification on the data packet. If the integrity verification fails, the data packet is discarded. If the data packet is not integrity protected, integrity verification is not performed.

[0182] It should be noted that if the first network node performs integrity protection on a portion of the data packet, the integrity-protected portion of the data packet may be of a fixed length or occupy a fixed proportion of the data length in the data packet. This fixed length or proportion is determined by the protocol or configured by signaling and is not specifically limited here. For example, the portion of the data packet may be the first 8 bits of the data packet, or the portion of the data packet may be the first half of the data packet.

[0183] In at least one embodiment of the present application, the multiple data packets include at least one of the following:

[0184] Multiple data packets in a data packet set (PDU Set);

[0185] Multiple data packets in a data burst;

[0186] Multiple data packets with the same characteristics, such as data packets belonging to the same service flow (such as IP flow), Quality of Service (QoS) flow, or the same integrity protection priority.

[0187] In at least one embodiment of the present application, the first configuration information includes at least one of the following:

[0188] First identification information indicating whether integrity protection needs to be performed on the target object; for example, adding an identification bit in the data packet transmission protocol header; when the identification bit exists (set to 1), the data packet needs to be integrity protected; otherwise (set to 0), the data packet does not need to be integrity protected;

[0189] Second identification information indicating the integrity protection type of the target object; the integrity protection type includes at least one of the following: performing integrity protection, not performing integrity protection, optionally performing integrity protection, and performing integrity protection on partial data; for example, adding identification information to a data packet transmission protocol header; when the identification information is mandatory, the data packet needs to perform integrity protection; when the identification information is not required or default, the data packet does not need to perform integrity protection; when the identification information is optional, the data packet can optionally perform integrity protection, and the first network node determines whether to perform integrity protection; for another example, adding identification information to a data packet transmission protocol header, when the identification information takes a special value, it indicates that partial data of the data packet needs to perform integrity protection, and the partial data is of a fixed length or occupies a fixed proportion of the data length in the data packet; the fixed length or fixed proportion is agreed upon by the protocol.

[0190] Priority identification information of the integrity protection of the target object; indirectly indicating whether integrity protection needs to be performed on the target object through the integrity protection priority; for example, it is pre-agreed that certain priorities of integrity protection need to be performed; or, the first network node determines that target objects with higher priorities need to be integrity protected based on the priorities; or, a correspondence between priorities and whether integrity protection needs to be performed is pre-configured, and the first network node determines whether integrity protection needs to be performed on the data packet based on the priorities and the correspondence;

[0191] Third identification information indicating whether the integrity protection policy of the target object is updated; the integrity protection policy includes at least one of the following: performing integrity protection, not performing integrity protection; for example, adding an identification bit in the data packet transmission protocol: when the identification bit exists (set to 1), the integrity protection policy of the data packet is updated (yes / no integrity protection); otherwise (set to 0), it remains unchanged; wherein, the initial integrity protection policy of the target object can be agreed upon in a predefined or preconfigured manner; for another example, the initial integrity protection policy of the data packet is to perform integrity protection, and when the identification bit is 1, the integrity protection policy of the data packet is updated, that is, integrity protection is not performed; when the identification bit is 0, the integrity protection policy of the data packet remains unchanged, that is, integrity protection is performed.

[0192] In an optional implementation, the user plane interface transmission protocol includes at least one of the following:

[0193] GPRS Tunneling Protocol - User Plane GTP-U header (GTP-U header);

[0194] GTP-U Extension Header.

[0195] It should be noted that the above-mentioned user plane interface transmission protocol includes a 5G user plane interface transmission protocol and / or a 6G user plane interface transmission protocol. The 5G user plane interface transmission protocol is specifically a GTP-U header or a GTP-U extension header. The 6G user plane interface transmission protocol is not yet named. It can still be a GTP-U header or a GTP-U extension header, or it can be other names. This application does not make specific limitations.

[0196] The first configuration information is carried by a first parameter or a first container in the GTP-U extension header; the first parameter is a new parameter in the PDU type; and the first container includes at least one of the following:

[0197] Protocol Data Unit PDU session container;

[0198] GTP-U container;

[0199] Newly added container.

[0200] For example, a new cell parameter (ie, a first parameter) in an existing or newly added PDU type carries the first configuration, such as using 1 bit or multiple bits as an integrity protection indication.

[0201] It should be noted that if the first configuration information needs to be forwarded between network nodes, the first configuration information can be carried by adding a new information element or a new PDU type to the existing PDU type through the RAN container or the NRRAN container.

[0202] In at least one embodiment of the present application, the method further includes:

[0203] The first network node receives a control plane interface message sent by the second network node, where the control plane interface message is used to carry second configuration information;

[0204] The first network node determines, based on the second configuration information, that it is necessary to judge whether integrity protection needs to be performed on the target object based on the first configuration information carried in the user plane interface transmission protocol.

[0205] Optionally, the control plane interface message includes at least one of the following:

[0206] PDU session management message, such as adding second configuration information to the PDU session management message;

[0207] Next Generation Application Protocol NGAP message, such as the NGAP message carrying the second configuration information;

[0208] The quality of service QoS flow parameter related message, such as the QoS flow parameter related message carrying the second configuration information.

[0209] It should be noted that the above control plane interface message includes a 5G control plane interface message and / or a 6G control plane interface message. The 6G control plane interface message is not yet named and may be the same as or different from the 5G control plane interface message, and this application does not make specific restrictions.

[0210] In summary, in the embodiment of the present application, the first network node determines the integrity protection information at the data packet level based on the first configuration information carried by the upper-layer user plane interface transmission protocol, which can achieve refined control of operations such as data packet integrity protection or verification. While ensuring the security of data transmission, it avoids excessive integrity protection operations that increase data processing procedures and delays, consume air interface resources, thereby reducing the complexity of device implementation and improving network performance.

[0211] like Figure 3 As shown, an embodiment of the present application also provides a method for processing user plane data, the method comprising:

[0212] Step 301: The second network node determines first configuration information; the first configuration information is used to configure integrity protection information of the target object; the target object includes at least one of the following: a data packet, a plurality of data packets;

[0213] Step 302: The second network node sends a target object to the first network node, where a user plane interface transmission protocol of at least one data packet in the target object carries the first configuration information.

[0214] Optionally, the integrity protection information of the target object specifically includes: whether integrity protection needs to be performed on the target object, or whether integrity protection needs to be performed on part of the data in the target object.

[0215] Optionally, the first network node includes a logical entity that can perform integrity protection and / or integrity protection verification, such as a network function (service-based), an access network node (such as a gNB, eNB, CU, etc.), a terminal, etc. The second network node is a logical entity that determines whether integrity protection needs to be performed, such as a core network node (such as a UPF network element).

[0216] In at least one embodiment of the present application, the multiple data packets include at least one of the following:

[0217] Multiple data packets in a data packet set (PDU Set);

[0218] Multiple data packets in a data burst;

[0219] Multiple data packets with the same characteristics, such as data packets belonging to the same service flow (such as IP flow), Quality of Service (QoS) flow, or the same integrity protection priority.

[0220] In at least one embodiment of the present application, the first configuration information includes at least one of the following:

[0221] First identification information indicating whether integrity protection needs to be performed on the target object; for example, adding an identification bit in the data packet transmission protocol header; when the identification bit exists (set to 1), the data packet needs to be integrity protected; otherwise (set to 0), the data packet does not need to be integrity protected;

[0222] Second identification information indicating the integrity protection type of the target object; the integrity protection type includes at least one of the following: performing integrity protection, not performing integrity protection, optionally performing integrity protection, and performing integrity protection on partial data; for example, adding identification information to a data packet transmission protocol header; when the identification information is mandatory, the data packet needs to perform integrity protection; when the identification information is not required or default, the data packet does not need to perform integrity protection; when the identification information is optional, the data packet can optionally perform integrity protection, and the first network node determines whether to perform integrity protection; for another example, adding identification information to a data packet transmission protocol header, when the identification information takes a special value, it indicates that partial data of the data packet needs to perform integrity protection, and the partial data is of a fixed length or occupies a fixed proportion of the data length in the data packet; the fixed length or fixed proportion is agreed upon by the protocol.

[0223] Priority identification information of the integrity protection of the target object; indirectly indicating whether integrity protection needs to be performed on the target object through the integrity protection priority; for example, it is pre-agreed that certain priorities of integrity protection need to be performed; or, the first network node determines that target objects with higher priorities need to be integrity protected based on the priorities; or, a correspondence between priorities and whether integrity protection needs to be performed is pre-configured, and the first network node determines whether integrity protection needs to be performed on the data packet based on the priorities and the correspondence;

[0224] Third identification information indicating whether the integrity protection policy of the target object is updated; the integrity protection policy includes at least one of the following: performing integrity protection, not performing integrity protection; for example, adding an identification bit in the data packet transmission protocol: when the identification bit exists (set to 1), the integrity protection policy of the data packet is updated (yes / no integrity protection); otherwise (set to 0), it remains unchanged; wherein, the initial integrity protection policy of the target object can be agreed upon in a predefined or preconfigured manner; for another example, the initial integrity protection policy of the data packet is to perform integrity protection, and when the identification bit is 1, the integrity protection policy of the data packet is updated, that is, integrity protection is not performed; when the identification bit is 0, the integrity protection policy of the data packet remains unchanged, that is, integrity protection is performed.

[0225] In an optional implementation, the user plane interface transmission protocol includes at least one of the following:

[0226] GPRS Tunneling Protocol - User Plane GTP-U header (GTP-U header);

[0227] GTP-U Extension Header.

[0228] It should be noted that the above-mentioned user plane interface transmission protocol includes a 5G user plane interface transmission protocol and / or a 6G user plane interface transmission protocol. The 5G user plane interface transmission protocol is specifically a GTP-U header or a GTP-U extension header. The 6G user plane interface transmission protocol is not yet named. It can still be a GTP-U header or a GTP-U extension header, or it can be other names. This application does not make specific limitations.

[0229] The first configuration information is carried by a first parameter or a first container in the GTP-U extension header; the first parameter is a new parameter in the PDU type; and the first container includes at least one of the following:

[0230] Protocol Data Unit PDU session container;

[0231] GTP-U container;

[0232] Newly added container.

[0233] For example, a new cell parameter (ie, a first parameter) in an existing or newly added PDU type carries the first configuration, such as using 1 bit or multiple bits as an integrity protection indication.

[0234] It should be noted that if the first configuration information needs to be forwarded between network nodes, the first configuration information can be carried by adding a new information element or a new PDU type to the existing PDU type through the RAN container or the NRRAN container.

[0235] In at least one embodiment of the present application, the method further includes:

[0236] The second network node sends a control plane interface message to the first network node, where the control plane interface message is used to carry second configuration information, and the second configuration information is used to instruct the first network node to determine whether the target object needs to perform integrity protection based on the first configuration information carried in the user plane interface transmission protocol.

[0237] Optionally, the control plane interface message includes at least one of the following:

[0238] PDU session management message, such as adding second configuration information to the PDU session management message;

[0239] Next Generation Application Protocol NGAP message, such as the NGAP message carrying the second configuration information;

[0240] The quality of service QoS flow parameter related message, such as the QoS flow parameter related message carrying the second configuration information.

[0241] It should be noted that the above control plane interface message includes a 5G control plane interface message and / or a 6G control plane interface message. The 6G control plane interface message is not yet named and may be the same as or different from the 5G control plane interface message, and this application does not make specific restrictions.

[0242] In summary, in the embodiment of the present application, the second network node determines the integrity protection information at the data packet level based on the first configuration information, which can achieve refined control of operations such as data packet integrity protection or verification. While ensuring the security of data transmission, it avoids excessive integrity protection operations that increase data processing procedures and delays, and consume air interface resources, thereby reducing the complexity of device implementation and improving network performance.

[0243] In order to more clearly describe the user plane data processing method provided in the embodiment of the present application, it is illustrated below with reference to multiple examples.

[0244] Example 1: The GTP-U header indicates whether the PDU session data packet is integrity protected.

[0245] Core network side (i.e. second network node)

[0246] Step 1: When sending downlink data, the UPF filters the data packets that need to add integrity protection indication (i.e., PDUSession User Plane PDU) according to the instructions of the control plane network function (or Mobile Edge Computing (MEC), business application).

[0247] Step 2: When organizing a data packet, the UPF sets an Extension Header with a PDUSession Container type in the GTP-U Header of the data packet. It also adds an indication bit to the PDUSession Information carried by the PDU SessionContainer to indicate whether integrity protection is required for the data packet.

[0248] Table 1 is an example of the downlink PDU session information format. In the DL PDU SESSIONINFORMATION (PDU Type 0) Format, 1 bit is used as the integrity protection indicator (IPI). An IPI of 1 indicates that the data packet needs to be integrity protected, and 0 indicates that it does not need to be protected.

[0249] Table 1

[0250]

[0251]

[0252] Base station side (i.e. first network node)

[0253] Step 1: After receiving the data packet sent by the UPF, the base station first parses the packet header to obtain the integrity protection indication.

[0254] In step 2, when sending downlink data, the base station determines whether integrity protection is required for the data packet based on the parsed integrity protection indicator. When constructing a PDCP PDU, an indicator bit (IPI) is added to the PDCP header of the PDCP data PDU to indicate whether integrity protection is implemented. Table 2 shows an example PDCP PDU format.

[0255] Table 2

[0256]

[0257] Terminal side

[0258] Step 1: Receive downlink data sent by the base station side and determine whether the PDCP PDU is integrity protected based on the IPI information in the PDCP header.

[0259] If the PDCP PDU is integrity protected, the terminal performs integrity verification on the PDCP PDU. If the integrity verification fails, the PDCP PDU is discarded. Otherwise, if the PDCP PDU carries an IPI of 0, no integrity verification is performed.

[0260] Example 2: GTP-U header indicates whether the PDU Set Information packet is integrity protected.

[0261] Core network side:

[0262] Step 1: When sending downlink data, the UPF filters the data packets that need to add integrity protection indication (i.e., PDU Set Information User Plane PDU) according to the instructions of the control plane network function (or Mobile Edge Computing (MEC), business application).

[0263] Step 2: When organizing a data packet, the UPF sets an Extension Header with the type GTP-UContainer in the GTP-U Header of the data packet and adds an indication bit in the PDU SetInformation carried by the GTP-U Container to indicate whether the data packet is integrity protected.

[0264] Table 3 is an example of the downlink PDU set information format. In the DL PDU SET INFORMATION (PDUType 0) Format, 1 bit is used as the integrity protection indicator (IPI). An IPI of 1 indicates that the data packet needs integrity protection, and 0 indicates that it does not need it.

[0265] In particular, for this type of data packet, the IPI can be used only in the first data packet header in a PDU Set or a Data Burst. This means that the IPI is used to indicate whether protection is completed until the last data packet in the PDU Set or Data Burst.

[0266] Table 3

[0267]

[0268] Base station side:

[0269] Step 1: After receiving the data packet sent by the UPF, the base station first parses the packet header to obtain the integrity protection indication.

[0270] In step 2, when sending downlink data, the base station determines whether integrity protection is required for the data packet based on the parsed integrity protection indicator. When constructing a PDCP PDU, an indicator bit (IPI) is added to the PDCP header of the PDCP data PDU to indicate whether integrity protection is implemented for the PDCP PDU. See Table 1 for an example PDCP PDU format.

[0271] a) Specifically, for this type of data packet (PDU Set Information User Plane PDU), if the IPI is detected only in the first data packet in a PDU Set or Data Burst, the same policy and PDCP header identifier are used until the last data packet in the PDU Set or Data Burst.

[0272] Terminal side

[0273] Step 1: Receive downlink data sent by the base station and determine whether the PDCP PDU is integrity protected based on the IPI information in the PDCP header. If the PDCP PDU is integrity protected, the terminal performs integrity verification on the PDCP PDU. If the integrity verification fails, the PDCP PDU is discarded. Otherwise, if the IPI carried by the PDCP PDU is 0, integrity verification is not performed.

[0274] Example 3: Carrying priority-based data integrity protection information through the NG interface control plane (optional) and user plane

[0275] Core network side:

[0276] Step 1: The control plane network function carries the integrity protection policy configuration information through the NGAP message, instructing the base station to determine whether to perform integrity protection on the data based on the integrity protection information carried by the user plane. For example, it indicates the priority level or threshold for performing integrity protection (optional).

[0277] Step 2: When sending downlink data, the UPF filters the data packets that need to add integrity protection indication (i.e., PDUSession User Plane PDU) according to the instructions of the control plane network function (or Mobile Edge Computing (MEC), business application).

[0278] Step 3: When organizing the data packet, the UPF sets an Extension Header with the PDUSession Container type in the GTP-U Header of the data packet. It also adds at least 2 bits of indication in the PDUSession Information carried by the PDU Session Container to indicate the priority level of integrity protection for the data packet.

[0279] Table 4 is an example. In the DL PDU SESSION INFORMATION (PDU Type 0) Format, 2 bits are used as the integrity protection priority (INTpri) (marked in red). The meanings of different values ​​are shown in Table 5.

[0280] Table 4

[0281]

[0282] Table 5

[0283] INTpri Value Integrity protection type 00 Not executed 01 Optional execution 10 Optional execution 11 implement

[0284] Base station side:

[0285] Step 1: Receive core network configuration information and determine the data integrity protection strategy. (Optional)

[0286] Step 2: After receiving the data packet sent by the UPF, the base station parses the INTpri information in the packet header to obtain the integrity protection indication.

[0287] Step 3. When sending downlink data, the base station first determines whether the data packet needs to be integrity protected. Then, when organizing the PDCP PDU, it adds an indication bit to the PDCP header of the PDCP data PDU to indicate whether the PDCP PDU is integrity protected.

[0288] a) For the instructions determined in INTpri, the base station executes or does not execute the full protection and organizes the PDCP PDU according to the instructions. For the instructions of optional execution, the base station makes its own judgment and organizes according to the load or other information.

[0289] b) (Optional) The base station determines, performs integrity protection, and organizes the PDCP PDU according to the integrity protection policy indicated by the core network. For example, when INTpri is 11, integrity protection is performed, and 00 does not perform integrity protection. 01 and 10 may perform integrity protection on part of the data (the part of the data has a fixed length or a fixed proportion of the data length in the PDCP PDU. This fixed length or proportion is specified by the protocol or configured by signaling).

[0290] Terminal side

[0291] Step 1: Receive downlink data sent by the base station and determine whether the PDCP PDU is integrity protected based on the IPI information in the PDCP header. If the PDCP PDU is integrity protected, the terminal performs integrity verification on the PDCP PDU. If the integrity verification fails, the PDCP PDU is discarded. Otherwise, if the IPI carried by the PDCP PDU is 0, integrity verification is not performed.

[0292] In summary, in the embodiment of the present application, the first network node and the second network node determine the integrity protection information at the data packet level based on the first configuration information carried by the user plane interface transmission protocol, which can achieve fine-grained control of operations such as data packet integrity protection or verification. While ensuring the security of data transmission, it avoids excessive integrity protection operations that increase data processing procedures and delays, consume air interface resources, thereby reducing the complexity of device implementation and improving network performance.

[0293] like Figure 4 As shown, an embodiment of the present application further provides a user plane data processing device, applied to a first network node, the device comprising:

[0294] A first receiving unit 401 is configured to receive a target object sent by a second network node, where the target object includes at least one of the following: a data packet or multiple data packets;

[0295] The first determining unit 402 is configured to determine integrity protection information of the target object according to first configuration information carried in a user plane interface transmission protocol of at least one data packet in the target object.

[0296] As an optional embodiment, the device further includes:

[0297] The integrity protection module is configured to perform integrity protection on the target object if the integrity protection information of the target object indicates that the target object needs to be integrity protected.

[0298] As an optional embodiment, the device further includes:

[0299] The second sending unit is configured to send one or more data packets of a target object to the terminal, wherein a Packet Data Convergence Protocol (PDCP) header of at least one data packet of the target object carries first indication information, and the first indication information includes at least one of the following:

[0300] First information for indicating whether integrity protection is performed on the target object;

[0301] Second information is used to indicate that integrity protection is performed on part of the data packet.

[0302] As an optional embodiment, the device further includes:

[0303] A third sending unit is configured to send a non-access layer message or an access layer message to the terminal, where the non-access layer message or the access layer message carries second indication information;

[0304] The first network node sends one or more data packets of a target object to the terminal;

[0305] The second indication information includes at least one of the following:

[0306] Third information for indicating whether integrity protection is performed on the target object;

[0307] Fourth information is used to indicate that integrity protection is performed on part of the data packet.

[0308] As an optional embodiment, the multiple data packets include at least one of the following:

[0309] Multiple packets in a packet set;

[0310] Multiple packets in a data burst;

[0311] Multiple packets with the same characteristics.

[0312] As an optional embodiment, the first configuration information includes at least one of the following:

[0313] First identification information indicating whether integrity protection needs to be performed on the target object;

[0314] Second identification information indicating an integrity protection type of the target object; the integrity protection type includes at least one of the following: performing integrity protection, not performing integrity protection, optionally performing integrity protection, and performing integrity protection on partial data;

[0315] Priority identification information of the integrity protection of the target object; indirectly indicating whether the target object needs to be integrity protected through the integrity protection priority;

[0316] Third identification information indicating whether the integrity protection policy of the target object is updated; the integrity protection policy includes at least one of the following: performing integrity protection and not performing integrity protection.

[0317] As an optional embodiment, the user plane interface transmission protocol includes at least one of the following:

[0318] GPRS Tunneling Protocol-User Plane GTP-U header;

[0319] GTP-U extension header.

[0320] As an optional embodiment, the first configuration information is carried by a first parameter or a first container in a GTP-U extension header; the first parameter is a new parameter in the PDU type; and the first container includes at least one of the following:

[0321] Protocol Data Unit PDU session container;

[0322] GTP-U container;

[0323] Newly added container.

[0324] As an optional embodiment, the device further includes:

[0325] a third receiving unit, configured to receive a control plane interface message sent by the second network node, where the control plane interface message is used to carry second configuration information;

[0326] The third determining unit is configured to determine, based on the second configuration information, whether integrity protection needs to be performed on the target object based on the first configuration information carried in the user plane interface transmission protocol.

[0327] As an optional embodiment, the control plane interface message includes at least one of the following:

[0328] PDU session management message;

[0329] Next Generation Application Protocol NGAP messages;

[0330] Messages related to Quality of Service (QoS) flow parameters.

[0331] In the embodiment of the present application, the first network node determines the integrity protection information at the data packet level based on the first configuration information carried by the upper-layer user plane interface transmission protocol, which can achieve refined control of operations such as data packet integrity protection or verification. While ensuring the security of data transmission, it avoids excessive integrity protection operations that increase data processing procedures and delays and consume air interface resources, thereby reducing the complexity of device implementation and improving network performance.

[0332] It should be noted here that the above-mentioned device provided in the embodiment of the present application can implement all the method steps implemented in the above-mentioned method embodiment and can achieve the same technical effect. The parts and beneficial effects of this embodiment that are the same as those in the method embodiment will not be described in detail here.

[0333] like Figure 5As shown, the embodiment of the present application further provides a first network node, including a memory 520, a transceiver 510, and a processor 500:

[0334] The memory 520 is used to store computer programs; the transceiver 510 is used to send and receive data under the control of the processor 500; the processor 500 is used to read the computer program in the memory 520 and perform the following operations:

[0335] receiving a target object sent by a second network node, where the target object includes at least one of the following: a data packet or multiple data packets;

[0336] Integrity protection information of the target object is determined according to first configuration information carried in a user plane interface transmission protocol of at least one data packet in the target object.

[0337] As an optional embodiment, the processor is further configured to read the computer program in the memory and perform the following operations:

[0338] In a case where the integrity protection information of the target object indicates that the target object needs to be integrity protected, integrity protection is performed on the target object.

[0339] As an optional embodiment, the processor is further configured to read the computer program in the memory and perform the following operations:

[0340] Send one or more data packets of a target object to a terminal, where a Packet Data Convergence Protocol (PDCP) header of at least one data packet of the target object carries first indication information, where the first indication information includes at least one of the following:

[0341] First information for indicating whether integrity protection is performed on the target object;

[0342] Second information is used to indicate that integrity protection is performed on part of the data packet.

[0343] As an optional embodiment, the processor is further configured to read the computer program in the memory and perform the following operations:

[0344] Sending a non-access stratum message or an access stratum message to the terminal, where the non-access stratum message or the access stratum message carries second indication information;

[0345] sending one or more data packets of a target object to the terminal;

[0346] The second indication information includes at least one of the following:

[0347] Third information for indicating whether integrity protection is performed on the target object;

[0348] Fourth information is used to indicate that integrity protection is performed on part of the data packet.

[0349] As an optional embodiment, the multiple data packets include at least one of the following:

[0350] Multiple packets in a packet set;

[0351] Multiple packets in a data burst;

[0352] Multiple packets with the same characteristics.

[0353] As an optional embodiment, the multiple data packets include at least one of the following:

[0354] Multiple packets in a packet set;

[0355] Multiple packets in a data burst;

[0356] Multiple packets with the same characteristics.

[0357] As an optional embodiment, the user plane interface transmission protocol includes at least one of the following:

[0358] GPRS Tunneling Protocol-User Plane GTP-U header;

[0359] GTP-U extension header.

[0360] As an optional embodiment, the first configuration information is carried by a first parameter or a first container in a GTP-U extension header; the first parameter is a new parameter in the PDU type; and the first container includes at least one of the following:

[0361] Protocol Data Unit PDU session container;

[0362] GTP-U container;

[0363] Newly added container.

[0364] As an optional embodiment, the processor is further configured to read the computer program in the memory and perform the following operations:

[0365] receiving a control plane interface message sent by the second network node, where the control plane interface message is used to carry second configuration information;

[0366] According to the second configuration information, it is determined that it is necessary to judge whether the target object needs to perform integrity protection according to the first configuration information carried in the user plane interface transmission protocol.

[0367] As an optional embodiment, the control plane interface message includes at least one of the following:

[0368] PDU session management message;

[0369] Next Generation Application Protocol NGAP messages;

[0370] Messages related to Quality of Service (QoS) flow parameters.

[0371] Among them, Figure 5 In the embodiment, the bus architecture may include any number of interconnected buses and bridges, specifically linking together various circuits of one or more processors represented by processor 500 and memory represented by memory 520. The bus architecture may also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are all well known in the art and, therefore, will not be described further herein. The bus interface provides an interface. The transceiver 510 may be a plurality of components, i.e., a transmitter and a receiver, providing a unit for communicating with various other devices on a transmission medium, such as a wireless channel, a wired channel, an optical cable, and the like. The processor 500 is responsible for managing the bus architecture and general processing, and the memory 520 may store data used by the processor 500 when performing operations.

[0372] The processor 500 may be a central processing unit (CPU), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or a complex programmable logic device (CPLD). The processor may also adopt a multi-core architecture.

[0373] In the embodiment of the present application, the first network node determines the integrity protection information at the data packet level based on the first configuration information carried by the upper-layer user plane interface transmission protocol, which can achieve refined control of operations such as data packet integrity protection or verification. While ensuring the security of data transmission, it avoids excessive integrity protection operations that increase data processing procedures and delays and consume air interface resources, thereby reducing the complexity of device implementation and improving network performance.

[0374] It should be noted here that the above-mentioned first network node provided in the embodiment of the present application can implement all the method steps implemented in the above-mentioned method embodiment and can achieve the same technical effects. The parts and beneficial effects of this embodiment that are the same as those in the method embodiment will not be described in detail here.

[0375] like Figure 6As shown, an embodiment of the present application further provides a user plane data processing device, applied to a second network node, the device comprising:

[0376] The second determining unit 601 is configured to determine first configuration information; the first configuration information is used to configure integrity protection information of the target object; the target object includes at least one of the following: a data packet, multiple data packets;

[0377] The first sending unit 602 is configured to send a target object to a first network node, where the user plane interface transmission protocol of at least one data packet in the target object carries the first configuration information.

[0378] As an optional embodiment, the multiple data packets include at least one of the following:

[0379] Multiple packets in a packet set;

[0380] Multiple packets in a data burst;

[0381] Multiple packets with the same characteristics.

[0382] As an optional embodiment, the first configuration information includes at least one of the following:

[0383] First identification information indicating whether integrity protection needs to be performed on the target object;

[0384] Second identification information indicating an integrity protection type of the target object; the integrity protection type includes at least one of the following: performing integrity protection, not performing integrity protection, optionally performing integrity protection, and performing integrity protection on partial data;

[0385] Priority identification information of the integrity protection of the target object; indirectly indicating whether the target object needs to be integrity protected through the integrity protection priority;

[0386] Third identification information indicating whether the integrity protection policy of the target object is updated; the integrity protection policy includes at least one of the following: performing integrity protection and not performing integrity protection.

[0387] As an optional embodiment, the user plane interface transmission protocol includes at least one of the following:

[0388] GPRS Tunneling Protocol-User Plane GTP-U header;

[0389] GTP-U extension header.

[0390] As an optional embodiment, the first configuration information is carried by a first parameter or a first container in a GTP-U extension header; the first parameter is a new parameter in the PDU type; and the first container includes at least one of the following:

[0391] Protocol Data Unit PDU session container;

[0392] GTP-U container;

[0393] Newly added container.

[0394] As an optional embodiment, the device further includes:

[0395] The fourth sending unit is used to send a control plane interface message to the first network node, where the control plane interface message is used to carry second configuration information, and the second configuration information is used to instruct the first network node to determine whether the target object needs to perform integrity protection based on the first configuration information carried in the user plane interface transmission protocol.

[0396] As an optional embodiment, the control plane interface message includes at least one of the following:

[0397] PDU session management message;

[0398] Next Generation Application Protocol NGAP messages;

[0399] Messages related to Quality of Service (QoS) flow parameters.

[0400] In the embodiment of the present application, the second network node determines the integrity protection information at the data packet level based on the first configuration information, which can achieve refined control of operations such as data packet integrity protection or verification. While ensuring the security of data transmission, it avoids excessive integrity protection operations that increase data processing procedures and delays and consume air interface resources, thereby reducing the complexity of device implementation and improving network performance.

[0401] It should be noted here that the above-mentioned device provided in the embodiment of the present application can implement all the method steps implemented in the above-mentioned method embodiment and can achieve the same technical effect. The parts and beneficial effects of this embodiment that are the same as those in the method embodiment will not be described in detail here.

[0402] like Figure 7 As shown, the embodiment of the present application further provides a second network node, including a memory 720, a transceiver 710, and a processor 700:

[0403] The memory 720 is used to store computer programs; the transceiver 710 is used to send and receive data under the control of the processor 700; the processor 700 is used to read the computer program in the memory 720 and perform the following operations:

[0404] Determine first configuration information; the first configuration information is used to configure integrity protection information of the target object; the target object includes at least one of the following: a data packet, multiple data packets;

[0405] A target object is sent to a first network node, where a user plane interface transmission protocol of at least one data packet in the target object carries the first configuration information.

[0406] As an optional embodiment, the multiple data packets include at least one of the following:

[0407] Multiple packets in a packet set;

[0408] Multiple packets in a data burst;

[0409] Multiple packets with the same characteristics.

[0410] As an optional embodiment, the first configuration information includes at least one of the following:

[0411] First identification information indicating whether integrity protection needs to be performed on the target object;

[0412] Second identification information indicating an integrity protection type of the target object; the integrity protection type includes at least one of the following: performing integrity protection, not performing integrity protection, optionally performing integrity protection, and performing integrity protection on partial data;

[0413] Priority identification information of the integrity protection of the target object; indirectly indicating whether the target object needs to be integrity protected through the integrity protection priority;

[0414] Third identification information indicating whether the integrity protection policy of the target object is updated; the integrity protection policy includes at least one of the following: performing integrity protection and not performing integrity protection.

[0415] As an optional embodiment, the user plane interface transmission protocol includes at least one of the following:

[0416] GPRS Tunneling Protocol-User Plane GTP-U header;

[0417] GTP-U extension header.

[0418] As an optional embodiment, the first configuration information is carried by a first parameter or a first container in a GTP-U extension header; the first parameter is a new parameter in the PDU type; and the first container includes at least one of the following:

[0419] Protocol Data Unit PDU session container;

[0420] GTP-U container;

[0421] Newly added container.

[0422] As an optional embodiment, the processor is further configured to read the computer program in the memory and perform the following operations:

[0423] A control plane interface message is sent to the first network node, where the control plane interface message is used to carry second configuration information, and the second configuration information is used to instruct the first network node to determine whether the target object needs to perform integrity protection based on the first configuration information carried in the user plane interface transmission protocol.

[0424] As an optional embodiment, the control plane interface message includes at least one of the following:

[0425] PDU session management message;

[0426] Next Generation Application Protocol NGAP messages;

[0427] Messages related to Quality of Service (QoS) flow parameters.

[0428] Among them, Figure 7 In the embodiment, the bus architecture may include any number of interconnected buses and bridges, specifically various circuits of one or more processors represented by processor 700 and memory represented by memory 720. The bus architecture may also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides an interface. The transceiver 710 may be a plurality of components, i.e., a transmitter and a receiver, providing a unit for communicating with various other devices on a transmission medium, such as a wireless channel, a wired channel, an optical cable, and the like. The processor 700 is responsible for managing the bus architecture and general processing, and the memory 720 may store data used by the processor 700 when performing operations.

[0429] The processor 700 may be a central processing unit (CPU), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or a complex programmable logic device (CPLD). The processor may also adopt a multi-core architecture.

[0430] In the embodiment of the present application, the second network node determines the integrity protection information at the data packet level based on the first configuration information, which can achieve refined control of operations such as data packet integrity protection or verification. While ensuring the security of data transmission, it avoids excessive integrity protection operations that increase data processing procedures and delays and consume air interface resources, thereby reducing the complexity of device implementation and improving network performance.

[0431] It should be noted that the above-mentioned second network node provided in the embodiment of the present application can implement all the method steps implemented in the above-mentioned method embodiment and can achieve the same technical effects. The parts and beneficial effects of this embodiment that are the same as those in the method embodiment will not be described in detail here.

[0432] It should be noted that the division of units in the embodiments of the present application is schematic and is merely a logical functional division. In actual implementation, other division methods may be used. Furthermore, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0433] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a processor-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) or a processor to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0434] The embodiment of the present application also provides a processor-readable storage medium, the processor-readable storage medium stores a computer program, the computer program is used to enable the processor to execute the various processes in the method embodiment described above, and can achieve the same technical effect. To avoid repetition, it is not repeated here. The processor-readable storage medium can be any available medium or data storage device that the processor can access, including but not limited to magnetic storage (such as floppy disk, hard disk, tape, magneto-optical disk (MO), etc.), optical storage (such as CD, DVD, BD, HVD, etc.), and semiconductor storage (such as ROM, EPROM, EEPROM, non-volatile memory (NAND FLASH), solid-state drive (SSD)), etc.

[0435] An embodiment of the present application also provides a computer program product, including computer instructions. When the computer instructions are executed by a processor, the various processes in the method embodiment described above are implemented and can achieve the same technical effect. To avoid repetition, they will not be described here.

[0436] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage and optical storage, etc.) that contain computer-usable program code.

[0437] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer-executable instructions. These computer-executable instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0438] These processor-executable instructions may also be stored in a processor-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the processor-readable memory produce an article of manufacture comprising an instruction device that implements the process Figure 1 a process or multiple processes and / or boxes Figure 1The function specified in one or more boxes.

[0439] These processor-executable instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are performed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for executing on the computer or other programmable device to implement the process. Figure 1 a process or multiple processes and / or boxes Figure 1 The steps for the function specified in one or more boxes.

[0440] Obviously, those skilled in the art may make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalents, this application is intended to include these modifications and variations.

Claims

1. A user plane data processing method, characterized in that: The method comprises: The first network node receives a target object sent by the second network node, where the target object includes at least one of the following: a data packet, or multiple data packets; The first network node determines the integrity protection information of the target object according to first configuration information carried in a user plane interface transmission protocol of at least one data packet in the target object.

2. The method according to claim 1, characterized in that The method further comprises: In a case where the integrity protection information of the target object indicates that the target object needs to be integrity protected, integrity protection is performed on the target object.

3. The method according to claim 1 or 2, characterized in that The method further comprises: The first network node sends one or more data packets of a target object to the terminal, where a Packet Data Convergence Protocol (PDCP) header of at least one data packet of the target object carries first indication information, where the first indication information includes at least one of the following: First information for indicating whether integrity protection is performed on the target object; Second information is used to indicate that integrity protection is performed on part of the data packet.

4. The method according to claim 1 or 2, characterized in that The method further comprises: The first network node sends a non-access stratum message or an access stratum message to the terminal, where the non-access stratum message or the access stratum message carries second indication information; The first network node sends one or more data packets of a target object to the terminal; The second indication information includes at least one of the following: Third information for indicating whether integrity protection is performed on the target object; Fourth information is used to indicate that integrity protection is performed on part of the data packet.

5. The method according to claim 1, wherein The plurality of data packets include at least one of the following: Multiple packets in a packet set; Multiple packets in a data burst; Multiple packets with the same characteristics.

6. The method according to claim 1, characterized in that The first configuration information includes at least one of the following: First identification information indicating whether integrity protection needs to be performed on the target object; Second identification information indicating an integrity protection type of the target object; the integrity protection type includes at least one of the following: performing integrity protection, not performing integrity protection, optionally performing integrity protection, and performing integrity protection on partial data; Priority identification information of the integrity protection of the target object; indirectly indicating whether the target object needs to be integrity protected through the integrity protection priority; Third identification information indicating whether the integrity protection policy of the target object is updated; the integrity protection policy includes at least one of the following: performing integrity protection and not performing integrity protection.

7. The method according to claim 1, characterized in that The user plane interface transmission protocol includes at least one of the following: GPRS Tunneling Protocol-User Plane GTP-U header; GTP-U extension header.

8. The method according to claim 7, characterized in that The first configuration information is carried by a first parameter or a first container in the GTP-U extension header; the first parameter is a new parameter in the PDU type; and the first container includes at least one of the following: Protocol Data Unit PDU session container; GTP-U container; Newly added container.

9. The method according to any one of claims 1 to 8, characterized in that The method further comprises: The first network node receives a control plane interface message sent by the second network node, where the control plane interface message is used to carry second configuration information; The first network node determines, based on the second configuration information, that it is necessary to judge whether integrity protection needs to be performed on the target object based on the first configuration information carried in the user plane interface transmission protocol.

10. The method according to claim 9, characterized in that The control plane interface message includes at least one of the following: PDU session management message; Next Generation Application Protocol NGAP messages; Messages related to Quality of Service (QoS) flow parameters.

11. A user plane data processing method, characterized in that: The method comprises: The second network node determines first configuration information; the first configuration information is used to configure integrity protection information of a target object; the target object includes at least one of the following: a data packet, a plurality of data packets; The second network node sends a target object to the first network node, where a user plane interface transmission protocol of at least one data packet in the target object carries the first configuration information.

12. The method according to claim 11, characterized in that The first configuration information includes at least one of the following: First identification information indicating whether integrity protection needs to be performed on the target object; Second identification information indicating an integrity protection type of the target object; the integrity protection type includes at least one of the following: performing integrity protection, not performing integrity protection, optionally performing integrity protection, and performing integrity protection on partial data; Priority identification information of the integrity protection of the target object; indirectly indicating whether the target object needs to be integrity protected through the integrity protection priority; Third identification information indicating whether the integrity protection policy of the target object is updated; the integrity protection policy includes at least one of the following: performing integrity protection and not performing integrity protection.

13. The method according to claim 11, characterized in that The user plane interface transmission protocol includes at least one of the following: GPRS Tunneling Protocol-User Plane GTP-U header; GTP-U extension header.

14. A user plane data processing device, applied to a first network node, characterized in that: The device comprises: A first receiving unit is configured to receive a target object sent by a second network node, wherein the target object includes at least one of the following: a data packet or multiple data packets; The first determining unit is configured to determine the integrity protection information of the target object according to first configuration information carried in a user plane interface transmission protocol of at least one data packet in the target object.

15. A first network node, characterized in that: Including memory, transceiver, processor: A memory for storing a computer program; a transceiver for transmitting and receiving data under the control of the processor; and a processor for reading the computer program in the memory and performing the following operations: receiving a target object sent by a second network node, where the target object includes at least one of the following: a data packet or multiple data packets; Integrity protection information of the target object is determined according to first configuration information carried in a user plane interface transmission protocol of at least one data packet in the target object.

16. The first network node according to claim 15, characterized in that The processor is further configured to read the computer program in the memory and perform the following operations: In a case where the integrity protection information of the target object indicates that the target object needs to be integrity protected, integrity protection is performed on the target object.

17. The first network node according to claim 15, characterized in that The processor is further configured to read the computer program in the memory and perform the following operations: Send one or more data packets of a target object to a terminal, where a Packet Data Convergence Protocol (PDCP) header of at least one data packet of the target object carries first indication information, where the first indication information includes at least one of the following: First information for indicating whether integrity protection is performed on the target object; Second information is used to indicate that integrity protection is performed on part of the data packet.

18. The first network node according to claim 15, characterized in that The processor is further configured to read the computer program in the memory and perform the following operations: Sending a non-access stratum message or an access stratum message to the terminal, where the non-access stratum message or the access stratum message carries second indication information; sending one or more data packets of a target object to the terminal; The second indication information includes at least one of the following: Third information for indicating whether integrity protection is performed on the target object; Fourth information is used to indicate that integrity protection is performed on part of the data packet.

19. The first network node according to claim 15, characterized in that The plurality of data packets include at least one of the following: Multiple packets in a packet set; Multiple packets in a data burst; Multiple packets with the same characteristics.

20. The first network node according to claim 15, characterized in that The plurality of data packets include at least one of the following: Multiple packets in a packet set; Multiple packets in a data burst; Multiple packets with the same characteristics.

21. The first network node according to claim 15, characterized in that The user plane interface transmission protocol includes at least one of the following: GPRS Tunneling Protocol-User Plane GTP-U header; GTP-U extension header.

22. The first network node according to claim 21, characterized in that The first configuration information is carried by a first parameter or a first container in the GTP-U extension header; the first parameter is a new parameter in the PDU type; and the first container includes at least one of the following: Protocol Data Unit PDU session container; GTP-U container; Newly added container.

23. The first network node according to any one of claims 15 to 22, characterized in that: The processor is further configured to read the computer program in the memory and perform the following operations: receiving a control plane interface message sent by the second network node, where the control plane interface message is used to carry second configuration information; According to the second configuration information, it is determined that it is necessary to judge whether the target object needs to perform integrity protection according to the first configuration information carried in the user plane interface transmission protocol.

24. The first network node according to claim 23, characterized in that The control plane interface message includes at least one of the following: PDU session management message; Next Generation Application Protocol NGAP messages; Messages related to Quality of Service (QoS) flow parameters.

25. A user plane data processing device, applied to a second network node, characterized in that: The device comprises: A second determining unit is configured to determine first configuration information; the first configuration information is used to configure integrity protection information of a target object; the target object includes at least one of the following: a data packet, a plurality of data packets; The first sending unit is configured to send a target object to a first network node, where a user plane interface transmission protocol of at least one data packet in the target object carries the first configuration information.

26. A second network node, characterized in that: Including memory, transceiver, processor: A memory for storing a computer program; a transceiver for transmitting and receiving data under the control of the processor; and a processor for reading the computer program in the memory and performing the following operations: Determine first configuration information; the first configuration information is used to configure integrity protection information of a target object; the target object includes at least one of the following: a data packet, multiple data packets; A target object is sent to a first network node, where a user plane interface transmission protocol of at least one data packet in the target object carries the first configuration information.

27. A processor-readable storage medium, characterized in that: The processor-readable storage medium stores a computer program, wherein the computer program is used to cause the processor to execute the method according to any one of claims 1 to 10, or the computer program is used to cause the processor to execute the method according to any one of claims 11 to 17.