Data security processing method, communication device, communication system and storage medium
Patent Information
- Application Number
- CN202480005619.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-19
- Publication Date
- 2025-09-19
AI Technical Summary
In UE-SAT-UE communication, the security protection between UEs is inconsistent, resulting in the security of user plane services on the Uu interface and inter-star links that cannot be consistently protected, and there is a risk of malicious tampering and exposure.
By determining the first key and sending it to the first UE and the second UE, it is possible to determine the second key based on the same key, end-to-end security protection is achieved, ensuring consistent protection of user-plane services on the two Uu interfaces and inter-star links of UE-SAT-UE communication.
The end-to-end security protection of user plane services in UE-SAT-UE communication is realized, reducing communication failures due to inconsistent security protection and improving communication security.
Smart Images

Figure CN120677733A_ABST
Abstract
Description
Data security processing method, communication equipment, communication system and storage medium Technical Field
[0001] The present disclosure relates to the field of communication technology, and in particular to a data security processing method, communication equipment, a communication system, and a storage medium. Background Art
[0002] User Equipment (UE) to Satellite to User Equipment (UE-satellite-UE, UE-SAT-UE) communication refers to the transmission of User Plane (UP) services between two UEs under the coverage of one or more serving satellites through local switching without going through the User Plane Function (UPF) of the terrestrial network.
[0003] Summary of the Invention
[0004] Embodiments of the present disclosure provide a data security processing method, a communication device, a communication system, and a storage medium.
[0005] According to a first aspect of an embodiment of the present disclosure, a data security processing method is provided, wherein the method is performed by a first network device and includes:
[0006] Determine a first key; the first key is used for a first user equipment UE and a second UE to determine a second key; the second key is used for end-to-end security protection of user equipment to satellite to user equipment UE-SAT-UE communication between the first UE and the second UE;
[0007] The first key is sent to the first UE and the second UE.
[0008] According to a second aspect of an embodiment of the present disclosure, a data security processing method is provided, wherein the method is executed by a first terminal and includes:
[0009] receiving a first key sent by a first network device;
[0010] A second key is determined based on the first key; the second key is used for end-to-end security protection of user equipment to satellite to user equipment UE-SAT-UE communication between the first UE and the second UE.
[0011] According to a third aspect of an embodiment of the present disclosure, a data security processing method is provided, wherein the method is performed by a core network function, and the method includes:
[0012] First information is sent to the first network device, where the first information is used to indicate whether UE-SAT-UE communication between the first UE and the second UE requires end-to-end security protection.
[0013] According to a fourth aspect of an embodiment of the present disclosure, a data security processing method is provided, wherein the method is performed by a communication system, and the method includes:
[0014] The core network function sends first information to the first network device, where the first information is used to indicate whether UE-SAT-UE communication between the first UE and the second UE requires end-to-end security protection;
[0015] The first network device determines a first key; and sends the first key to the first UE and the second UE;
[0016] The first UE and the second UE determine a second key based on the first key; the second key is used for end-to-end security protection of user equipment to satellite to user equipment UE-SAT-UE communication between the first UE and the second UE.
[0017] According to a fifth aspect of an embodiment of the present disclosure, a first network device is provided, wherein the first network device includes:
[0018] A determination module is configured to determine a first key; the first key is used by a first user equipment UE and a second UE to determine a second key; the second key is used for end-to-end security protection of user equipment to satellite to user equipment UE-SAT-UE communication between the first UE and the second UE;
[0019] A sending module is configured to send the first key to the first UE and the second UE.
[0020] According to a sixth aspect of an embodiment of the present disclosure, a first UE is provided, wherein the first UE includes:
[0021] a receiving module, configured to receive a first key sent by a first network device;
[0022] The determination module is configured to determine a second key based on the first key; the second key is used for end-to-end security protection of user equipment to satellite to user equipment UE-SAT-UE communication between the first UE and the second UE.
[0023] According to a seventh aspect of an embodiment of the present disclosure, a core network function is provided, wherein the core network function includes:
[0024] The sending module is configured to send first information to the first network device, where the first information is used to indicate whether UE-SAT-UE communication between the first UE and the second UE requires end-to-end security protection.
[0025] According to the eighth aspect of an embodiment of the present disclosure, a communication system is provided, wherein the communication system includes a first terminal, a first network device and a core network function, the first network device is configured to implement the data security processing method provided by the first aspect, the first terminal is configured to implement the data security processing method provided by the second aspect, and the core network function is configured to implement the data security processing method provided by the third aspect.
[0026] According to a ninth aspect of an embodiment of the present disclosure, a communication device is provided, wherein the communication device includes:
[0027] one or more processors;
[0028] The processor is used to call instructions to enable the communication device to execute the data security processing method provided by the first aspect, the second aspect or the third aspect.
[0029] According to the tenth aspect of an embodiment of the present disclosure, a storage medium is provided, wherein the storage medium stores instructions, and when the instructions are executed on a communication device, the communication device executes the data security processing method provided by the first aspect, the second aspect or the third aspect.
[0030] The technical solution provided by the embodiment of the present disclosure determines a first key so that the first UE and the second UE can determine the second key based on the same first key; in this way, when the first UE and the second UE perform UE-SAT-UE communication, the first UE and the second UE can use the same second key to perform end-to-end security protection on the user plane service, so that the user plane service used for UE-SAT-UE communication between the first UE and the second UE can be consistently protected on the two Uu interfaces and / or inter-satellite links of the UE-SAT-UE communication, thereby reducing the situation where the first UE and the second UE cannot communicate due to inconsistent security protection.
[0031] It should be understood that the foregoing general description and the following detailed description are merely exemplary and explanatory and are not restrictive of the embodiments of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present invention and, together with the description, serve to explain the principles of the embodiments of the present invention.
[0033] FIG1A is a schematic diagram showing an architecture of a communication system according to an exemplary embodiment;
[0034] FIG1B is a schematic diagram 1 showing a UE-SAT-UE communication scenario according to an exemplary embodiment;
[0035] FIG1C is a second schematic diagram showing a UE-SAT-UE communication scenario according to an exemplary embodiment;
[0036] FIG2 is an interactive schematic diagram showing a data security processing method according to an exemplary embodiment;
[0037] FIG3A is a schematic flow chart showing a data security processing method according to an exemplary embodiment;
[0038] FIG3B is a schematic flow chart showing a data security processing method according to an exemplary embodiment;
[0039] FIG4A is a schematic flow chart showing a data security processing method according to an exemplary embodiment;
[0040] FIG4B is a flow chart showing a method for securely processing data according to an exemplary embodiment;
[0041] FIG4C is a schematic flow chart showing a data security processing method according to an exemplary embodiment;
[0042] FIG4D is a schematic flow chart showing a data security processing method according to an exemplary embodiment;
[0043] FIG5 is an interactive schematic diagram showing a data security processing method according to an exemplary embodiment;
[0044] FIG6 is a schematic diagram showing a flow chart of end-to-end protection of UE-SAT-UE communication according to an exemplary embodiment;
[0045] FIG7A is a schematic structural diagram of a first network device according to an exemplary embodiment;
[0046] FIG7B is a schematic structural diagram of a first UE according to an exemplary embodiment;
[0047] FIG7C is a schematic structural diagram of a core network function according to an exemplary embodiment;
[0048] FIG8A is a schematic structural diagram of a communication device according to an exemplary embodiment;
[0049] FIG8B is a schematic structural diagram of a chip according to an exemplary embodiment. DETAILED DESCRIPTION
[0050] Embodiments of the present disclosure provide a data security processing method, a communication device, a communication system, and a storage medium.
[0051] In a first aspect, an embodiment of the present disclosure provides a data security processing method, wherein the method is performed by a first network device, and the method includes:
[0052] Determine a first key; the first key is used for a first user equipment UE and a second UE to determine a second key; the second key is used for end-to-end security protection of user equipment to satellite to user equipment UE-SAT-UE communication between the first UE and the second UE;
[0053] The first key is sent to the first UE and the second UE.
[0054] In the above embodiment, the first network device determines the first key and sends the first key to the first UE and the second UE, so that the first UE and the second UE can determine the second key based on the same first key, thereby using the same second key to achieve end-to-end security protection of the UE-SAT-UE communication between the first UE and the second UE; so that the user plane service used for UE-SAT-UE communication between the first UE and the second UE can be consistently protected on the two Uu interfaces and / or inter-satellite links of the UE-SAT-UE communication, thereby reducing the situation where the first UE and the second UE cannot communicate securely due to inconsistent security protection.
[0055] In conjunction with some embodiments of the first aspect, in some embodiments, determining the first key includes:
[0056] The first key is generated according to a third key; the third key includes: an access layer AS intermediate key of the first UE and / or an AS layer intermediate key of the second UE.
[0057] In the above embodiment, the first network device can use the AS layer intermediate key of the first UE and / or the AS layer intermediate key of the second UE as the third key to generate the first key based on the third key, thereby realizing the reuse of the AS layer intermediate key of the first UE and / or the second UE, and reducing the number of keys that the first network device needs to store.
[0058] In conjunction with some embodiments of the first aspect, in some embodiments, generating the first key according to the third key includes:
[0059] Determining a fourth key according to the access layer AS intermediate key of the first UE and / or the AS layer intermediate key of the second UE;
[0060] The first key is determined according to the fourth key.
[0061] In the above embodiment, the first network device can generate a fourth key based on the AS layer intermediate key of the first UE and / or the AS layer intermediate key of the second UE, and then generate the first key based on the fourth key. In this way, by introducing the fourth key, it is possible to generate a first key that is applicable to the UEs at both ends of the communication (the first terminal and the second terminal), ensuring the applicability of the first key.
[0062] In combination with some embodiments of the first aspect, in some embodiments, determining the fourth key according to the access layer AS intermediate key of the first UE and / or the AS layer intermediate key of the second UE includes one of the following:
[0063] Performing an exclusive OR operation on the access layer AS intermediate key of the first UE and the AS layer intermediate key of the second UE to obtain the fourth key;
[0064] The access layer AS intermediate key of the first UE and the AS layer intermediate key of the second UE are concatenated to obtain the fourth key.
[0065] In the above embodiment, the AS layer intermediate key of the first UE and the AS layer intermediate key of the second UE may be cascaded or XORed to obtain a fourth key that can be used to generate the first key, thereby improving the diversity of the generated fourth key.
[0066] In conjunction with some embodiments of the first aspect, in some embodiments, the method further includes:
[0067] receiving first information sent by a core network function, where the first information is used to indicate whether to activate end-to-end security protection for UE-SAT-UE communication between the first UE and the second UE;
[0068] The determining of the first key includes:
[0069] The first information indicates activation of end-to-end security protection of UE-SAT-UE communication between the first UE and the second UE, and determination of the first key.
[0070] In the above embodiment, the first network device can receive the first information sent by the core network function to learn, based on the first information, the core network function's configuration of the end-to-end security protection policy for UE-SAT-UE communication between the first UE and the second UE. The first network device generates the first key when the first information indicates that the UE-SAT-UE communication between the first UE and the second UE requires end-to-end security protection; and does not generate the first key when the first information indicates that the UE-SAT-UE communication between the first UE and the second UE does not require end-to-end security protection. This reduces unnecessary generation of the first key by the first network device, thereby reducing power consumption.
[0071] In conjunction with some embodiments of the first aspect, in some embodiments, the method further includes:
[0072] The first information is sent to the first UE and the second UE.
[0073] In the above embodiment, the first network device may send the first information sent by the core network function to the first UE and the second UE, so that the first UE and the second UE are aware of the configuration of the core network function of the end-to-end security protection policy for the UE-SAT-UE communication between the first UE and the second UE; so that the first UE and the second UE can determine whether it is necessary to perform end-to-end security protection operations on the data of the UE-SAT-UE communication.
[0074] In conjunction with some embodiments of the first aspect, in some embodiments, the first information includes at least one of the following:
[0075] The security policy indication of the first UE is used to indicate whether a user plane of a locally transmitted protocol data unit (PDU) session between the first UE and the first network device providing service requires end-to-end security protection;
[0076] The security policy indication of the second UE is used to indicate whether the user plane of the PDU session locally transmitted between the second UE and the first network device providing service requires end-to-end security protection.
[0077] In the above embodiment, the first information may include a security policy indication of the first UE and / or a security policy indication of the second UE, thereby realizing security policy indication at the UE granularity; enabling the first network device providing services for the first UE and / or the second UE to know whether the user plane of the PDU session locally transmitted between the first UE and / or the second UE and the first network device requires end-to-end security protection, thereby determining whether it is necessary to activate the user plane end-to-end security protection of the PDU session of the first UE and / or the second UE.
[0078] In conjunction with some embodiments of the first aspect, in some embodiments, generating the first key according to the third key includes one of the following:
[0079] generating a first key according to the first information and the third key;
[0080] A first key is generated according to the first information, the length of the first information, and the third key.
[0081] In the above embodiment, the first network device can generate the first key based on the third key and the first information sent by the core network function; or generate the first key based on the third key and the first information and the length of the first information, thereby improving the diversity of the generated first key.
[0082] In conjunction with some embodiments of the first aspect, in some embodiments, the second key includes at least one of the following:
[0083] Integrity key;
[0084] Confidentiality key.
[0085] In the above embodiment, the second key may include an integrity key and / or a confidentiality key, so that the integrity of the user plane service used for UE-SAT-UE communication between the first UE and the second UE is protected by the integrity key, thereby reducing the risk of tampering with the user plane service. The confidentiality of the user plane service used for UE-SAT-UE communication between the first UE and the second UE is protected by the confidentiality key, thereby reducing the risk of exposure of the user plane service and improving communication security.
[0086] In a second aspect, an embodiment of the present disclosure provides a data security processing method, wherein the method is performed by a first UE, and the method includes:
[0087] receiving a first key sent by a first network device;
[0088] A second key is determined based on the first key; the second key is used for end-to-end security protection of user equipment to satellite to user equipment UE-SAT-UE communication between the first UE and the second UE.
[0089] In the above embodiment, the first UE can receive the first key sent by the first network device and determine the second key based on the first key, thereby using the second key to achieve end-to-end security protection of the UE-SAT-UE communication between the first UE and the second UE; so that the user plane service used for UE-SAT-UE communication between the first UE and the second UE can be consistently protected on the two Uu interfaces and / or inter-satellite links of the UE-SAT-UE communication, thereby improving communication security.
[0090] In combination with some embodiments of the second aspect, in some embodiments, the first key is generated based on the third key; the third key includes: the access layer AS intermediate key of the first UE and / or the AS layer intermediate key of the second UE.
[0091] In combination with some embodiments of the second aspect, in some embodiments, the first key is generated based on the first information and the third key; or, the first key is generated based on the first information, the length of the first information and the third key; the first information is used to indicate whether to activate end-to-end security protection of UE-SAT-UE communication.
[0092] In conjunction with some embodiments of the second aspect, in some embodiments, the first information includes at least one of the following:
[0093] The security policy indication of the first UE is used to indicate whether a user plane of a locally transmitted protocol data unit (PDU) session between the first UE and the first network device providing service requires end-to-end security protection;
[0094] The security policy indication of the second UE is used to indicate whether the user plane of the PDU session locally transmitted between the second UE and the first network device providing service requires end-to-end security protection.
[0095] In conjunction with some embodiments of the second aspect, in some embodiments, the method further includes:
[0096] Receive the first information sent by the first network device.
[0097] In conjunction with some embodiments of the second aspect, in some embodiments, the second key includes at least one of the following:
[0098] Integrity key;
[0099] Confidentiality key.
[0100] In a third aspect, an embodiment of the present disclosure provides a data security processing method, wherein the method is performed by a core network function, and the method includes:
[0101] First information is sent to the first network device, where the first information is used to indicate whether UE-SAT-UE communication between the first UE and the second UE requires end-to-end security protection.
[0102] In the above embodiment, the core network function may send first information to the first network device to inform the first network device of the core network function's configuration of the end-to-end security protection policy for UE-SAT-UE communication between the first UE and the second UE, so that the first network device determines whether to activate or deactivate end-to-end security protection for UE-SAT-UE communication between the first UE and the second UE and determines whether to generate a first key. In this way, unnecessary generation of the first key by the first network device is reduced, thereby reducing power consumption.
[0103] In conjunction with some embodiments of the third aspect, in some embodiments, the first information includes at least one of the following:
[0104] The security policy indication of the first UE is used to indicate whether a user plane of a locally transmitted protocol data unit (PDU) session between the first UE and the first network device providing service requires end-to-end security protection;
[0105] The security policy indication of the second UE is used to indicate whether the user plane of the PDU session locally transmitted between the second UE and the first network device providing service requires end-to-end security protection.
[0106] In conjunction with some embodiments of the third aspect, in some embodiments, the method further includes:
[0107] The first information is determined based on the session management information of the PDU session of the first UE and / or the second UE.
[0108] In a fourth aspect, an embodiment of the present disclosure provides a data security processing method, which is executed by a communication system and includes:
[0109] The core network function sends first information to the first network device, where the first information is used to indicate whether UE-SAT-UE communication between the first UE and the second UE requires end-to-end security protection;
[0110] The first network device determines a first key; and sends the first key to the first UE and the second UE;
[0111] The first UE and the second UE determine a second key based on the first key; the second key is used for end-to-end security protection of user equipment to satellite to user equipment UE-SAT-UE communication between the first UE and the second UE.
[0112] In a fifth aspect, an embodiment of the present disclosure provides a first network device, comprising:
[0113] A determination module is configured to determine a first key; the first key is used by a first user equipment UE and a second UE to determine a second key; the second key is used for end-to-end security protection of user equipment to satellite to user equipment UE-SAT-UE communication between the first UE and the second UE;
[0114] A sending module is configured to send the first key to the first UE and the second UE.
[0115] In a sixth aspect, an embodiment of the present disclosure provides a first UE, including:
[0116] a receiving module, configured to receive a first key sent by a first network device;
[0117] The determination module is configured to determine a second key based on the first key; the second key is used for end-to-end security protection of user equipment to satellite to user equipment UE-SAT-UE communication between the first UE and the second UE.
[0118] In a seventh aspect, an embodiment of the present disclosure provides a core network function, including:
[0119] The sending module is configured to send first information to the first network device, where the first information is used to indicate whether UE-SAT-UE communication between the first UE and the second UE requires end-to-end security protection.
[0120] In the eighth aspect, an embodiment of the present disclosure provides a communication system, wherein the communication system includes a first terminal, a first network device and a core network function, the first network device is configured to implement the data security processing method provided by the first aspect, the first terminal is configured to implement the data security processing method provided by the second aspect, and the core network function is configured to implement the data security processing method provided by the third aspect.
[0121] In a ninth aspect, an embodiment of the present disclosure provides a communication device, the communication device comprising:
[0122] one or more processors;
[0123] The processor is used to call instructions to enable the communication device to execute the data security processing method described in the optional implementation of the first aspect, the second aspect or the third aspect.
[0124] In the tenth aspect, an embodiment of the present disclosure provides a storage medium, wherein the storage medium stores instructions, which, when the instructions are executed on a communication device, enable the communication device to execute the data security processing method described in the optional implementation of the first aspect, the second aspect or the third aspect.
[0125] In the eleventh aspect, an embodiment of the present disclosure provides a program product, which, when executed by a communication device, enables the communication device to execute the data security processing method described in the optional implementation of the first aspect, the second aspect, or the third aspect.
[0126] In the twelfth aspect, an embodiment of the present disclosure provides a computer program, which, when running on a computer, enables the computer to execute the data security processing method described in the optional implementation of the first aspect, the second aspect, or the third aspect.
[0127] It is understandable that the first network device, the first UE, the core network function, the communication device, the communication system, the storage medium, the program product, and the computer program are all used to perform the method provided by the embodiment of the present disclosure. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects of the corresponding method and will not be repeated here.
[0128] The present disclosure provides a data security processing method and apparatus, a communication device, a communication system, and a storage medium. In some embodiments, the data security processing method, information processing method, and information transmission method are interchangeable, and the communication system and information processing system are interchangeable.
[0129] The embodiments of the present disclosure are not exhaustive and are merely illustrative of some embodiments, and are not intended to be a specific limitation on the scope of protection of the present disclosure. In the absence of contradiction, each step in a certain embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a certain embodiment can also be implemented as an independent embodiment, and the order of the steps in a certain embodiment can be arbitrarily exchanged. In addition, the optional implementation methods in a certain embodiment can be arbitrarily combined; in addition, the embodiments can be arbitrarily combined. For example, some or all steps of different embodiments can be arbitrarily combined, and a certain embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.
[0130] In each embodiment of the present disclosure, unless otherwise specified or provided for by logic, the terms and / or descriptions between the embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form a new embodiment based on their inherent logical relationships.
[0131] The terms used in the embodiments of the present disclosure are only for the purpose of describing specific embodiments and are not intended to limit the present disclosure.
[0132] In the embodiments of the present disclosure, unless otherwise specified, elements expressed in the singular, such as "a", "an", "the", "above", "said", "the", "the", etc., may mean "one and only one", or "one or more", "at least one", etc. For example, when using articles such as "a", "an", "the" in English in translation, the noun following the article may be understood as a singular expression or a plural expression.
[0133] In the embodiments of the present disclosure, “plurality” refers to two or more.
[0134] In some embodiments, the terms "at least one," "one or more," "a plurality of," "multiple," etc. may be used interchangeably.
[0135] In some embodiments, descriptions such as "at least one of A and B," "A and / or B," "in one case A, in another case B," or "in one case A, in another case B" may include the following technical solutions depending on the situation: in some embodiments, A (A is executed independently of B); in some embodiments, B (B is executed independently of A); in some embodiments, execution is selected from A and B (A and B are selectively executed); and in some embodiments, A and B (both A and B are executed). The same applies when there are more branches such as A, B, and C.
[0136] In some embodiments, "A or B" and other descriptions may include the following technical solutions depending on the situation: in some embodiments, A (A is executed independently of B); in some embodiments, B (B is executed independently of A); in some embodiments, execution is selected from A and B (A and B are selectively executed). The above is also applicable when there are more branches such as A, B, C, etc.
[0137] The prefixes such as "first" and "second" in the embodiments of the present disclosure are only used to distinguish different description objects and do not constitute any restriction on the position, order, priority, quantity or content of the description objects. For the statement of the description object, please refer to the description in the context of the claims or embodiments, and no unnecessary restriction should be constituted due to the use of prefixes. For example, if the description object is a "field", the ordinal number before the "field" in the "first field" and the "second field" does not limit the position or order between the "fields". "First" and "second" do not limit whether the "fields" they modify are in the same message, nor do they limit the order of the "first field" and the "second field". For another example, if the description object is a "level", the ordinal number before the "level" in the "first level" and the "second level" does not limit the priority between the "levels". For another example, the number of description objects is not limited by the ordinal number and can be one or more. Taking "first device" as an example, the number of "devices" can be one or more. In addition, the objects modified by different prefixes can be the same or different. For example, if the description object is "device", then the "first device" and the "second device" can be the same device or different devices, and their types can be the same or different; for another example, if the description object is "information", then the "first information" and the "second information" can be the same information or different information, and their contents can be the same or different.
[0138] In some embodiments, “including A,” “comprising A,” “used to indicate A,” and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.
[0139] In some embodiments, terms such as "...", "determine...", "in the case of...", "at the time of...", "when...", "if...", "if...", etc. can be used interchangeably.
[0140] In some embodiments, terms such as "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not less than", and "above" can be replaced with each other, and terms such as "less than", "less than or equal to", "not greater than", "less than", "less than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", and "below" can be replaced with each other.
[0141] In some embodiments, devices, etc. can be interpreted as physical or virtual, and their names are not limited to the names recorded in the embodiments. Terms such as "device", "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", and "subject" can be used interchangeably.
[0142] In some embodiments, "network" can be interpreted as devices included in the network (eg, access network equipment, core network equipment, etc.).
[0143] In some embodiments, the terms "access network device (AN device)", "radio access network device (RAN device)", "base station (BS)", "radio base station" "fixed station", "node", "access point", "transmission point (TP)", "reception point (RP)", "transmission / reception point (TRP)", "panel", "antenna panel", "antenna array", "cell", "macro cell", "small cell", "femto cell", "pico cell", "sector", "cell group", "serving cell", "carrier", "component carrier", "bandwidth part (BWP)" and the like may be used interchangeably.
[0144] In some embodiments, the terms "terminal", "terminal device", "user equipment (UE)", "user terminal", "mobile station (MS)", "mobile terminal (MT)", subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, handset, user agent, mobile client, client, etc. can be used interchangeably.
[0145] In some embodiments, the access network device, the core network device, or the network device can be replaced by a terminal. For example, the various embodiments of the present disclosure can also be applied to a structure in which the communication between the access network device, the core network device, or the network device and the terminal is replaced by communication between multiple terminals (for example, device-to-device (D2D), vehicle-to-everything (V2X), etc.). In this case, it is also possible to set the structure in which the terminal has all or part of the functions of the access network device. In addition, terms such as "uplink" and "downlink" can also be replaced by terms corresponding to communication between terminals (for example, "side"). For example, uplink channels, downlink channels, etc. can be replaced by side channels, and uplinks, downlinks, etc. can be replaced by side links.
[0146] In some embodiments, the terminal may be replaced by an access network device, a core network device, or a network device. In this case, the access network device, the core network device, or the network device may have a structure that has all or part of the functions of the terminal.
[0147] In some embodiments, obtaining data, information, etc. may comply with the laws and regulations of the country where the data is obtained.
[0148] In some embodiments, data, information, etc. may be obtained with the user's consent.
[0149] In addition, each element, each row, or each column in the table of the embodiment of the present disclosure can be implemented as an independent embodiment, and the combination of any elements, any rows, and any columns can also be implemented as an independent embodiment.
[0150] FIG1A is a schematic diagram showing the architecture of a communication system according to an exemplary embodiment.
[0151] As shown in FIG1A , a communication system 100 includes user equipment (UE) 101 , access network equipment 102 , and core network equipment 103 .
[0152] In some embodiments, the user equipment 101 may include: a first user equipment 1011 and a second user equipment 1012 .
[0153] In some embodiments, the user device 101 includes, for example, a mobile phone, a wearable device, an Internet of Things device, a car with communication capabilities, a smart car, a tablet computer, a computer with wireless transceiver capabilities, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in a smart grid, a wireless terminal device in transportation safety, a wireless terminal device in a smart city, and at least one of a wireless terminal device in a smart home, but is not limited thereto.
[0154] In some embodiments, the access network device 102 can be, for example, a node or device that accesses the terminal to the wireless network. The access network device may include an evolved NodeB (eNB), a next generation evolved NodeB (ng-eNB), a next generation NodeB (gNB), a node B (NB), a home node B (HNB), a home evolved nodeB (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an open base station (Open RAN), a cloud base station (Cloud RAN), a base station in other communication systems, and at least one of an access node in a Wi-Fi system, but is not limited thereto.
[0155] In some embodiments, the technical solution of the present disclosure can be applied to the Open RAN architecture. In this case, the interfaces between or within the access network devices involved in the embodiments of the present disclosure can be transformed into internal interfaces of the Open RAN, and the processes and information interactions between these internal interfaces can be implemented through software or programs.
[0156] In some embodiments, the access network device can be composed of a centralized unit (CU) and a distributed unit (DU), where the CU can also be called a control unit. The CU-DU structure can be used to split the protocol layer of the access network device, with the functions of some protocol layers centrally controlled by the CU, and the functions of the remaining part or all of the protocol layers distributed in the DU, which is centrally controlled by the CU, but is not limited to this.
[0157] In some embodiments, the access network device 102 includes a first network device 1021 and / or a second network device 1022 .
[0158] In some embodiments, the core network device 103 may be a single device including one or more core network functions 1031, or may be multiple devices or a group of devices, each including one or more core network functions 1031. The core network functions may be virtual or physical. The core network may include, for example, at least one of an evolved packet core (EPC), a 5G core network (5GCN), and a next generation core (NGC).
[0159] In some embodiments, the core network function 1031 is, for example, a session management function (SMF).
[0160] In some embodiments, the core network function 1031 is, for example, an access and mobility management function (AMF).
[0161] It can be understood that the communication system described in the embodiment of the present disclosure is for the purpose of more clearly illustrating the technical solution of the embodiment of the present disclosure, and does not constitute a limitation on the technical solution provided by the embodiment of the present disclosure. Ordinary technicians in this field can know that with the evolution of the system architecture and the emergence of new business scenarios, the technical solution provided by the embodiment of the present disclosure is also applicable to similar technical problems.
[0162] The following embodiments of the present disclosure may be applied to the communication system 100 shown in FIG1A , or a portion thereof, but are not limited thereto. The entities shown in FIG1A are illustrative only. The communication system may include all or part of the entities shown in FIG1A , or may include other entities other than those shown in FIG1A . The number and form of the entities may be arbitrary. The connection relationship between the entities is illustrative only. The entities may be connected or disconnected, and the connection may be in any manner, including direct or indirect, wired or wireless.
[0163] The embodiments of the present disclosure can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), future radio access (FRA), new radio access technology (RAT), new radio (NR), new radio access (NX), future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (registered trademark), Public Land Mobile Network (PLMN) networks, Device-to-Device (D2D) systems, Machine-to-Machine (M2M) systems, Internet of Things (IoT) systems, Vehicle-to-Everything (V2X), systems utilizing other communication methods, and next-generation systems based on and extending these methods. Furthermore, multiple systems may be combined (for example, a combination of LTE or LTE-A with 5G).
[0164] User Equipment (UE) to Satellite to User Equipment (UE-satellite-UE, UE-SAT-UE) communication is the communication between UEs under the coverage of one or more serving satellites via local switching without user plane (UP) traffic passing through the terrestrial network.
[0165] As shown in FIG1B , FIG1B is a schematic diagram illustrating a UE-SAT-UE communication scenario according to an exemplary embodiment. In FIG1B , two UEs are in communication. However, a communication session may involve more than two UEs.
[0166] In the case where the satellite serves more than one cell, the serving cells of the two UEs in Figure 1B can be different. The Access and Mobility Management Function (AMF) is the only network function (NF) represented by 5GC, but other NFs may be implicit, such as the Session Management Function (SMF).
[0167] As shown in Figure 1C, Figure 1C is a second schematic diagram illustrating a UE-SAT-UE communication scenario according to an exemplary embodiment. If the satellite is connected to an inter-satellite link, the inter-satellite link (ISL) can ensure that the terrestrial connection is always available. When local switching capabilities are distributed across more than one satellite, UE-SAT-UE communication can be extended to cover more than one satellite, and the ISL can ensure that the terrestrial connection is always available.
[0168] The security of uplink services carried by the Uu interface is activated based on the security policy sent from the core network equipment. The security policy is set by the Unified Data Management (UDM) or SMF according to the specific service requested by the UE. The SMF determines the UP security mandatory information for the PDU session based on the following when the PDU session is established:
[0169] The subscribed UP security policy, which is part of the Session Management (SM) subscription message received from the UDM; or, when the UDM does not provide the UP security policy, the UP security policy configured locally in the SMF based on (Data Network Name (DNN), Single Network Slice Selection Assistance Information (S-NSSAI)).
[0170] The UP security policy indicates whether UP security protection should be activated at the UU interface of a PDU session; used to activate UP confidentiality and / or UP integrity for a PDU session.
[0171] According to the UP security policy provided by the SMF, if the UP security policy indicates "Required", the access network equipment uses RRC signaling to activate UP security protection of the Uu interface for each data radio bearer (DRB).
[0172] If the UP security policy indicates "Not needed", the PDU session will be established without protection.
[0173] If the UP security policy indicates "Preferred", the access network device can decide whether to activate UP security protection on the Uu interface. However, when the UP security policy indicates "Required" or "Not needed", the access network device follows the UP security policy received from the SMF.
[0174] For UE-to-UE communication using the 5G network, the UE establishes a separate PDU session with the core network device through the access network device. The access network device applies the UP security policy corresponding to the UE to the UE's separate PDU session. The UP security policies corresponding to different UEs can be different.
[0175] For UE-SAT-UE communication, two separate PDU sessions for UE-SAT-UE communication can be established. However, if the two communicating UEs have different UP security policies, different security protections may be applied to the two Uu interfaces of a single UE-SAT-UE communication session. In this case, the security protections on the two Uu interfaces may be inconsistent. Higher security protection (e.g., integrity protection and confidentiality protection) on one Uu interface may be overridden by lower security protection (e.g., integrity protection only, confidentiality protection only, or no protection) on another Uu interface.
[0176] It is worth noting that the security protection on the Uu interface terminates at the access network equipment, that is, the access network equipment of the sending UE decodes the uplink UP service sent by the sending UE, and the access network equipment of the receiving UE encodes the downlink UP service sent to the receiving UE. When the UP service needs to be transmitted on the inter-satellite link between the access network equipment of the sending UE and the access network equipment of the receiving UE, the protection of the UP service through the ISL can only rely on the security of the ISL. This security may not be controlled by the operator. Therefore, the UP service carried by the two Uu interfaces and the ISL may not be consistently protected. In this case, the UP traffic may be at risk of being tampered with by a malicious / misbehaving entity (for example, an entity between the inter-satellite links), and the confidential part of the UP traffic may be at risk of being exposed to another entity (for example, an entity between the inter-satellite links).
[0177] The UP service transmitted between two UEs in UE-SAT-UE communication lacks consistent security protection, posing a significant security risk.
[0178] FIG2 is an interactive diagram illustrating a data security processing method according to an exemplary embodiment. As shown in FIG2 , the embodiment of the present disclosure relates to a data security processing method for a communication system 100, the method comprising:
[0179] Step S2101: The core network function determines the first information.
[0180] In some embodiments, the core network function may be a network function of a core network device, for example, an SMF or a UDM.
[0181] In some embodiments, the core network function determines the first information based on session management information of the PDU session of the first UE and / or the second UE.
[0182] The PDU session may be a PDU session used for UE-SAT-UE communication between the first UE and the second UE.
[0183] Here, when the first UE and the second UE are served by the same network device, the PDU session of the first UE is a PDU session locally transmitted between the first UE and the first network device providing the service; the PDU session of the second UE is a PDU session locally transmitted between the second UE and the first network device providing the service.
[0184] It should be noted that the first network device may be an access device for the first UE and the second UE to access the network.
[0185] When the first UE and the second UE are served by different network devices, the PDU session of the first UE is a PDU session transmitted locally between the first UE and the first network device providing the service; the PDU session of the second UE is a PDU session transmitted locally between the second UE and the second network device providing the service.
[0186] It should be noted that the first network device may be an access device for the first UE to access the network, and the second network device may be an access device for the second UE to access the network.
[0187] The first UE and the second UE involved in the embodiments of the present disclosure may be, but are not limited to, mobile phones, wearable devices, vehicle-mounted terminals, road side units (RSUs) and / or smart home terminals.
[0188] The first network device and the second network device may be deployed in the air, for example, on an airplane, a drone, or a satellite.
[0189] In some embodiments, the session management information of the PDU session may be used to indicate relevant parameters for establishing user plane resources for the PDU session. For example, the session management information may indicate a user plane path for the PDU session.
[0190] The core network function may determine the first information based on relevant parameters for establishing user plane resources of the PDU session indicated by the session management information of the PDU session of the first UE and / or the second UE.
[0191] In some embodiments, the core network function receives the second information, and the core network function determines the first information; the second information is used to request the establishment of a PDU session for UE-SAT-UE communication between the first UE and the second UE.
[0192] It should be noted that the second information may be sent by the first UE and forwarded to the core network function via the first network device. The first UE may be an initiating device that initiates the PDU session establishment process.
[0193] In some embodiments, the second information may be a PDU session establishment request or a PDU session update request.
[0194] In some embodiments, the first information is used to indicate whether to activate end-to-end security protection of UE-SAT-UE communication between the first UE and the second UE.
[0195] In some embodiments, the first information is used to indicate whether UE-SAT-UE communication between the first UE and the second UE requires end-to-end security protection.
[0196] It is worth noting that the PDU sessions for UE-SAT-UE communication between the first UE and the second UE are two separate PDU sessions. If the first UE and the second UE have different user plane security policies, the security protection on the Uu interface of the two PDU sessions for UE-SAT-UE communication may be inconsistent.
[0197] The core network function determines the first information so that the first UE and the second UE can determine whether the UE-SAT-UE communication between the first UE and the second UE requires end-to-end security protection based on the same first information, thereby enabling the first UE and the second UE to reach an agreement on the user plane security policy; reducing the situation where secure communication cannot be achieved due to inconsistent security protection on the Uu interface of the two PDU sessions of UE-SAT-UE communication.
[0198] Moreover, when the first UE and the second UE are served by different network devices, that is, when the user plane service for UE-SAT-UE communication between the first UE and the second UE needs to be transmitted on the ISL between the first network device and the second network device, the protection of the user plane service carried by the ISL can only depend on the security protection of the ISL; thereby, the security protection on the Uu interface and the ISL of the two PDU sessions for UE-SAT-UE communication are inconsistent.
[0199] In order to achieve consistent protection of user plane services carried on the Uu interface and / or ISL of two PDU sessions of UE-SAT-UE communication, end-to-end security protection for UE-SAT-UE communication can be applied between the first UE and the second UE.
[0200] In some embodiments, the first information includes a security policy indication, wherein the security policy indication is used to indicate whether end-to-end security protection is required for UE-SAT-UE communication between the first UE and the second UE.
[0201] Exemplarily, the security policy indication may include one or more bits. The one or more bits have a first value, indicating that UE-SAT-UE communication between the first UE and the second UE requires end-to-end security protection. The one or more bits have a second value, indicating that UE-SAT-UE communication between the first UE and the second UE does not require end-to-end security protection.
[0202] In some embodiments, the core network function determines whether the UE-SAT-UE communication between the first UE and the second UE requires end-to-end security protection based on the subscription data of the first UE, the subscription data of the second UE and / or the security requirements of the services involved in the UE-SAT-UE communication between the first UE and the second UE, obtains a determination result, and sets the first information based on the determination result.
[0203] In some embodiments, based on any one of the subscription data of the first UE and the subscription data of the second UE, it is determined that the UE-SAT-UE communication between the first UE and the second UE requires end-to-end security protection, then the first information indicates that the UE-SAT-UE communication between the first UE and the second UE requires end-to-end security protection, otherwise the first information indicates that the UE-SAT-UE communication between the first UE and the second UE does not require end-to-end security protection.
[0204] In some embodiments, according to the security requirement of the service involved in the UE-SAT-UE communication between the first UE and the second UE being the first level, the first information indicates that the UE-SAT-UE communication between the first UE and the second UE requires end-to-end security protection.
[0205] In some embodiments, according to the security requirement of the service involved in the UE-SAT-UE communication between the first UE and the second UE being the second level, the first information indicates that the UE-SAT-UE communication between the first UE and the second UE does not require end-to-end security protection.
[0206] The first level is higher than the second level.
[0207] In some embodiments, the first information includes at least one of the following:
[0208] A security policy indication of the first UE, used to indicate whether a user plane of a locally transmitted protocol data unit (PDU) session between the first UE and the first network device providing service requires end-to-end security protection;
[0209] The security policy indication of the second UE is used to indicate whether the user plane of the PDU session locally transmitted between the second UE and the first network device providing the service requires end-to-end security protection.
[0210] It is worth noting that the security policy indication of the first UE should be the same as the security policy indication of the second UE, so that the security protection of the Uu interface of the two PDU sessions for UE-SAT-UE communication between the first UE and the second UE can be consistent.
[0211] In some embodiments, when the security policy indication of the first UE carried in the first information is different from the security policy indication of the second UE, the first network device may determine to terminate the UE-SAT-UE communication between the first UE and the second UE.
[0212] In some embodiments, when the security policy indication of the first UE carried in the first information is different from the security policy indication of the second UE, the first network device can also independently determine to activate or deactivate the end-to-end security protection for UE-SAT-UE communication between the first UE and the second UE based on the security policy indication of the first UE and the security policy indication of the first UE.
[0213] Exemplarily, the first network device determining, according to the security policy indication of the first UE and the security policy of the first UE, that activating or deactivating end-to-end security protection for UE-SAT-UE communication between the first UE and the second UE may include at least one of the following:
[0214] The security policy indication of the first UE and the security policy of the second UE indicate that UE-SAT-UE communication between the first UE and the second UE requires end-to-end security protection, and determining that it is necessary to indicate that UE-SAT-UE communication between the first UE and the second UE requires end-to-end security protection;
[0215] The security policy indication of the first UE and the security policy of the second UE both indicate that UE-SAT-UE communication between the first UE and the second UE does not require end-to-end security protection, and it is determined that there is no need to indicate that UE-SAT-UE communication between the first UE and the second UE requires end-to-end security protection.
[0216] Step S2102: The core network function sends the first information.
[0217] In some embodiments, the core network function may be a network function of a core network device, for example, an SMF or a UDM.
[0218] In some embodiments, the core network device sends the first information to the first network device and / or the second network device.
[0219] In some embodiments, when the first UE and the second UE are served by the same network device, the core network function sends the first information to the first network device.
[0220] In some embodiments, when the first UE and the second UE are served by different network devices, the core network function sends the first information to the first network device and the second network device.
[0221] In some embodiments, during the PDU session establishment process, the core network function sends first information to the first network device.
[0222] In some embodiments, when the first UE and the second UE are served by the same network device, the core network function sends a security policy indication of the first UE and a security policy indication of the second UE to the first network device.
[0223] In some embodiments, when the security policy indication of the first UE and the security policy indication of the second UE carried in the first information received by the first network device are different, the first network device may determine to terminate the UE-SAT-UE communication between the first UE and the second UE; or, the first network device may also determine whether the UE-SAT-UE communication between the first UE and the second UE requires end-to-end security protection based on the security policy indication of the first UE or the security policy indication of the second UE.
[0224] It should be noted that if the security policy indication of the first UE in the first information is inconsistent with the security policy indication of the second UE, the first network device may determine to terminate the UE-SAT-UE communication between the first UE and the second UE. Alternatively, the first network device may determine whether the UE-SAT-UE communication between the first UE and the second UE requires end-to-end security protection, thereby allowing the first UE and the second UE to reach an agreement on the user plane security policy.
[0225] For example, the first network device may determine a target indication with higher security protection requirements from the security policy indication of the first UE and the security policy indication of the second UE; so as to determine whether end-to-end security protection is required for the UE-SAT-UE communication between the first UE and the second UE according to the target indication.
[0226] For another example, the first network device may determine a target indication with lower security protection requirements from the security policy indication of the first UE and the security policy indication of the second UE; so as to determine whether end-to-end security protection is required for the UE-SAT-UE communication between the first UE and the second UE according to the target indication.
[0227] In some embodiments, when the first UE and the second UE are served by different network devices, the core network function sends the first information to the first network device and the second network device respectively.
[0228] It can be understood that since the first UE and the second UE are served by different network devices respectively, in order to achieve consensus on the security protection of the two PDU sessions for UE-SAT-UE communication between the first UE and the second UE, the core network function can send first information to the first network device and the second network device respectively, so that the first network device and the second network device can determine whether the UE-SAT-UE communication between the first UE and the second UE requires end-to-end security protection based on the same first information.
[0229] In some embodiments, when the first UE and the second UE are served by different network devices, the core network function sends a security policy indication for the first UE to the first network device and sends a security policy indication for the second UE to the second network device.
[0230] It is worth noting that after receiving the security policy indication of the first UE, the first network device may obtain the security policy indication of the second UE from the second network device to determine whether the security policy indication of the first UE is consistent with the security policy indication of the first UE.
[0231] When the security policy indication of the first UE and the security policy indication of the second UE are different, the first network device may determine to terminate the UE-SAT-UE communication between the first UE and the second UE; alternatively, the first network device may also determine, based on the security policy indication of the first UE or the security policy indication of the second UE, whether the UE-SAT-UE communication between the first UE and the second UE requires end-to-end security protection.
[0232] It should be noted that when the security policy indication of the first UE determined by the core network function is inconsistent with the security policy indication of the second UE, the first network device can re-determine whether the UE-SAT-UE communication between the first UE and the second UE requires end-to-end security protection, so that the first UE and the second UE reach an agreement on the user plane security policy.
[0233] In some embodiments, when the security policy indication of the first UE is different from the security policy indication of the second UE, the first network device sends third information to the second network device; the third information is used to indicate the re-determined security policy indication of the second UE.
[0234] It can be understood that when the security policy indication of the first UE and the security policy indication of the second UE are inconsistent, the first network device redetermines the security policy indication of the first UE and the security policy indication of the second UE to unify the user plane security policies of the first UE and the second UE; and sends third information to the second network device to inform the second network device of the redetermined security policy indication of the second UE.
[0235] In some embodiments, when the security policy indication of the first UE is different from the security policy indication of the second UE, the first network device may send fourth information to the second network device and the core network function; the fourth information indicates to terminate the UE-SAT-UE communication between the first UE and the second UE.
[0236] It can be understood that when the security policy indication of the first UE and the security policy indication of the second UE are inconsistent, the first network device can determine to terminate the UE-SAT-UE communication between the first UE and the second UE, and inform the second network device and the core network function through the fourth information.
[0237] In some embodiments, when the user plane of the PDU session locally transmitted between the first UE and the first network device providing the service requires end-to-end security protection, the first network device activates security protection for the user plane service carried by the Uu interface of the PDU session of the first UE.
[0238] In some embodiments, when the user plane of the PDU session locally transmitted between the second UE and the first network device providing the service requires end-to-end security protection, the first network device activates security protection for the user plane service carried by the Uu interface of the PDU session of the second UE.
[0239] It should be noted that the Uu interface is an interface for communication between the UE and the network device providing services.
[0240] In some embodiments, security protection of user plane services carried by the Uu interface of a PDU session may include at least one of the following:
[0241] User plane confidentiality protection of the Uu interface for PDU sessions;
[0242] User plane integrity protection of the Uu interface of the PDU session.
[0243] In some embodiments, the first network device sends first information to the first UE and the second UE.
[0244] It can be understood that after the first network device receives the first information sent by the core network function, it can send the first information to the first UE and the second UE; so that the first UE and the second UE can determine whether end-to-end security protection is required for the data of UE-SAT-UE communication.
[0245] Step S2103: The first network device determines a first key.
[0246] In some embodiments, the first key is used by the first UE and the second UE to determine the second key; the second key is used for end-to-end security protection of UE-SAT-UE communication between the first UE and the second UE.
[0247] It can be understood that the first key may be a root key used to generate the second key.
[0248] In some embodiments, the first information indicates activation of end-to-end security protection for UE-SAT-UE communication between the first UE and the second UE, and the first network device determines a first key.
[0249] It should be noted that when the first information indicates activation of end-to-end security protection for UE-SAT-UE communication between the first UE and the second UE, it indicates that end-to-end security protection is required for UE-SAT-UE communication between the first UE and the second UE. The first network device should generate a first key and send it to the first UE and the second UE. This enables the first UE and the second UE to generate a second key based on the first key. In this way, the first UE and the second UE can use the same second key to achieve security protection for user plane services during UE-SAT-UE communication, thereby achieving end-to-end security protection for UE-SAT-UE communication between the first UE and the second UE.
[0250] In some embodiments, the first information indicates that end-to-end security protection of UE-SAT-UE communication between the first UE and the second UE is not activated, and the first network device does not need to determine the first key.
[0251] When the first information indicates that end-to-end security protection for UA-SAT-UE communication between the first UE and the second UE is not activated, this indicates that end-to-end security protection is not required for UE-SAT-UE communication between the first UE and the second UE, and the first network device does not need to generate a first key. In this way, when end-to-end security protection for UE-SAT-UE communication between the first UE and the second UE is not required, unnecessary generation of a first key by the first network device is reduced.
[0252] In some embodiments, the first information indicates that end-to-end security protection of UE-SAT-UE communication between the first UE and the second UE is preferentially activated, and the first network device independently determines whether to generate the first key.
[0253] It is worth noting that when the first information indicates priority activation of end-to-end security protection for UE-SAT-UE communication between the first UE and the second UE, this indicates that the UE-SAT-UE communication between the first UE and the second UE may or may not be end-to-end security protected; the first network device may determine whether to generate the first key based on certain conditions. For example, if the first network device has sufficient resources, the first network device may generate the first key; if the first network device has insufficient resources, the first network device may not generate the first key.
[0254] In some embodiments, the first network device may generate the first key based on the third key.
[0255] Here, the third key may include: an access stratum (AS) intermediate key of the first UE and / or an AS layer intermediate key of the second UE.
[0256] The AS layer intermediate key is an intermediate key for security protection between user equipment and access network equipment.
[0257] It should be noted that for the AS layer key, the Access and Mobility Management Function (AMF) first generates the AS layer intermediate key, which is the intermediate key used on the access network device side. The AS layer intermediate key is used to generate the RRC key (such as the RRC confidentiality key K) on the access network device side. RRC_enc and / or RRC integrity key K RRC_int ) and user plane security keys (e.g. user plane confidentiality keys K UP_enc and / or user plane integrity key K UP_int ) and other AS layer related keys.
[0258] When the first UE and the second UE are served by the same network device, the first network device stores the AS layer intermediate key of the first UE and the AS layer intermediate key of the second UE. The first network device can generate a first key based on the AS layer intermediate key of the first UE and the AS layer intermediate key of the second UE.
[0259] When a first UE and a second UE are served by different network devices (e.g., a first network device and a second network device), the first network device of the first UE requesting to initiate a PDU session establishment process may obtain the AS layer intermediate key of the second UE from the second network device, and generate a first key based on the AS layer intermediate key of the first UE and the AS layer intermediate key of the second UE. The first network device sends the first key to the second network device.
[0260] Alternatively, the first network device may send the AS layer intermediate key of the first UE to the second network device, and the second network device may generate a first key based on the AS layer intermediate key of the first UE and the AS layer intermediate key of the second UE; and send the generated first key to the first network device.
[0261] Alternatively, the first network device may send the AS layer intermediate key of the first UE to the second network device, and the second network device may send the AS layer intermediate key of the second UE to the first network device. In this way, both network devices can generate the first key based on the AS layer intermediate key of the first UE and the AS layer intermediate key of the second UE.
[0262] In some embodiments, generating the first key based on the third key includes:
[0263] Determining a fourth key based on the AS layer intermediate key of the first UE and / or the AS layer intermediate key of the second UE;
[0264] The first key is determined based on the fourth key.
[0265] It is understandable that the first network device can derive the first key based on the fourth key. For example, the fourth key can be used as an input key to derive the first key based on a key derivation function (KDF).
[0266] In some embodiments, determining the fourth key based on the AS layer intermediate key of the first UE and / or the AS layer intermediate key of the second UE includes at least one of the following:
[0267] Perform an XOR operation on the AS layer intermediate key of the first UE and the AS layer intermediate key of the second UE to obtain a fourth key;
[0268] The AS layer intermediate key of the first UE and the AS layer intermediate key of the second UE are concatenated to obtain a fourth key.
[0269] A concatenation result is obtained by concatenating the AS layer intermediate key of the first UE and the AS layer intermediate key of the second UE; the entire concatenation result can be determined as the fourth key; or a partial character string is selected from the concatenation result as the fourth key.
[0270] In some embodiments, the AS layer intermediate key includes: a first subkey segment and a second subkey segment; wherein each bit in the first subkey segment is higher than each bit in the second subkey segment;
[0271] The concatenating the AS layer intermediate key of the first UE and the AS layer intermediate key of the second UE to obtain the fourth key includes one of the following:
[0272] Concatenate the first subkey segment in the AS layer intermediate key of the first UE and the first subkey segment in the AS layer intermediate key of the second UE to obtain a fourth key;
[0273] Concatenate the second subkey segment in the AS layer intermediate key of the first UE and the second subkey segment in the AS layer intermediate key of the second UE to obtain a fourth key;
[0274] Concatenate the first subkey segment in the AS layer intermediate key of the first UE and the second subkey segment in the AS layer intermediate key of the second UE to obtain a fourth key;
[0275] The second subkey segment in the AS layer intermediate key of the first UE and the first subkey segment in the AS layer intermediate key of the second UE are concatenated to obtain a fourth key.
[0276] It should be noted that the number of bits included in the first subkey segment of the AS layer intermediate key is the same as the number of bits included in the second subkey segment.
[0277] By concatenating the first subkey segment or the second subkey segment of the first UE with the first subkey segment or the second subkey segment of the second UE, the length of the fourth key obtained by concatenation is made the same as the length of the AS layer intermediate key, which is beneficial for subsequent key derivation directly based on the fourth key to obtain the first key.
[0278] In some embodiments, concatenating the AS layer intermediate key of the first UE and the AS layer intermediate key of the second UE to obtain the fourth key includes:
[0279] Mapping the AS layer intermediate key of the first UE to odd bits in the fifth key respectively;
[0280] Mapping the AS layer intermediate key of the second UE to the even-numbered bits in the fifth key respectively;
[0281] A fourth key is determined based on the fifth key.
[0282] It should be noted that the fourth key can be determined by selecting a preset number of bits from the multiple bits of the fifth key and based on the preset number of bits. Here, the preset number can be set according to actual needs. For example, the preset number can be determined by the number of bits in the AS-layer intermediate key. This ensures that the length of the fourth key obtained by concatenation is the same as the length of the AS-layer intermediate key, facilitating subsequent key derivation based directly on the fourth key to obtain the first key.
[0283] In some embodiments, generating the first key based on the third key includes one of the following:
[0284] generating a first key according to the first information and the third key;
[0285] A first key is generated according to the first information, the length of the first information, and the third key.
[0286] It should be noted that the first network device can determine the fourth key according to the third key, and generate the first key based on the fourth key and the first information; or generate the first key based on the first key, the first information and the length of the first information.
[0287] The fourth key may be used as an input key of the KDF, and the first information and / or the length of the first information may be used as parameters of the KDF to derive the first key.
[0288] Step S2104: The first network device sends the first key to the first UE and the second UE.
[0289] In some embodiments, when the first UE and the second UE are served by the same network device, the first network device sends the first key to the first UE and the second UE.
[0290] In some embodiments, when the first UE and the second UE are served by different network devices, the first network device sends the first key to the first UE, and then sends the first key to the second UE through the second network device.
[0291] It should be noted that when the first UE and the second UE are served by different network devices, the first key can be generated by the first network device; the first network device can send the generated first key to the second network device, and then the second network device can send it to the second UE.
[0292] In some embodiments, when the first UE and the second UE are served by different network devices, the first network device sends the first key to the first UE, and the second network device sends the first key to the second UE.
[0293] It should be noted that when the first UE and the second UE are served by different network devices, both the first network device and the second network device can generate a first key. In this way, the first network device sends the generated first key to the first UE, and the second network device sends the generated first key to the second UE.
[0294] In some embodiments, when the first network device activates security protection of the user plane service carried by the Uu interface of the PDU session between the first UE and the second UE, the first network device sends the first key to the first UE and the second UE.
[0295] In some embodiments, sending the first key to the first UE and the second UE includes:
[0296] The first information and the first key are sent to the first UE and the second UE.
[0297] It is understandable that the first network device can send the first key and the first information together to the first UE and the second UE, so as to reduce the number of information interactions between the first network device and the first UE and the second UE, and save transmission resources.
[0298] Step S2105: The first UE determines the second key based on the first key.
[0299] In some embodiments, the second UE determines the second key based on the first key.
[0300] It is understandable that the first UE can derive the second key based on the first key. For example, the first key can be used as an input key of a KDF to derive the second key.
[0301] In some embodiments, the second key comprises at least one of: an integrity key; a confidentiality key.
[0302] It should be noted that the integrity key can be used to perform integrity protection on the UP service used for UE-SAT-UE communication between the first UE and the second UE, so as to ensure that the UP service is not tampered with or damaged during transmission.
[0303] The confidentiality key can be used to protect the confidentiality of the UP service used for UE-SAT-UE communication between the first UE and the second UE, so as to ensure that the UP service is not leaked to a third-party device other than the first UE and the second UE.
[0304] In some embodiments, when the first information indicates activation of end-to-end security protection for UE-SAT-UE communication between the first UE and the second UE, the first UE determines the second key based on the first key.
[0305] It should be noted that when the first information indicates activation of end-to-end security protection of UA-SAT-UE communication between the first UE and the second UE, the first UE and the second UE can generate a second key based on the first key, so that the first UE and the second UE can achieve end-to-end security protection of UE-SAT-UE communication between the first UE and the second UE based on the second key.
[0306] When the first information indicating activation of end-to-end security protection for UA-SAT-UE communication between the first UE and the second UE is not received, the first UE and the second UE may not generate the second key based on the first key. In this way, when end-to-end security protection for UE-SAT-UE communication between the first UE and the second UE is not required, unnecessary generation of the first key by the first UE and the second UE is reduced.
[0307] In some embodiments, the first information indicates activation of user plane confidentiality protection for UE-SAT-UE communication between the first UE and the second UE, and generates a confidentiality key based on the first key.
[0308] If the first UE and the second UE receive the first information sent by the first network device to indicate the activation of the user plane confidentiality protection of the UE-SAT-UE communication between the first UE and the second UE, it indicates that the first network device has activated the user plane confidentiality protection of the Uu interface of the PDU session used by the first UE and the second UE for UE-SAT-UE communication; the first UE and the second UE can generate a confidentiality key based on the first key, so as to use the confidentiality key to perform confidentiality protection on the UP service for UE-SAT-UE communication between the first UE and the second UE.
[0309] In some embodiments, the first information indicates activation of user plane integrity protection of UE-SAT-UE communication between the first UE and the second UE, and generates an integrity key based on the first key.
[0310] If the first UE and the second UE receive the first information sent by the first network device to indicate the activation of the user plane integrity protection of the UE-SAT-UE communication between the first UE and the second UE, it indicates that the first network device has activated the user plane integrity protection of the Uu interface of the PDU session used by the first UE and the second UE for UE-SAT-UE communication; the first UE and the second UE can generate an integrity key based on the first key, so as to use the integrity key to perform integrity protection on the UP service for UE-SAT-UE communication between the first UE and the second UE.
[0311] In some embodiments, the second UE may generate the second key based on the first key upon receiving UP data for UE-SAT-UE communication sent by the first UE.
[0312] It should be noted that since the UP data sent by the first UE for UE-SAT-UE communication is encrypted based on the second key, the second UE can generate a second key based on the first key when receiving the UP data sent by the first UE for UE-SAT-UE communication to decrypt the received UP data for UE-SAT-UE communication.
[0313] Step S2106: The first UE and the second UE perform end-to-end security protection on the UP service used for UE-SAT-UE communication based on the second key.
[0314] In some embodiments, the first UE and the second UE perform integrity protection on UP traffic for UE-SAT-UE communication between the first UE and the second UE based on the integrity key.
[0315] In some embodiments, the first UE and the second UE perform integrity protection on UP traffic for UE-SAT-UE communication between the first UE and the second UE based on a confidentiality key.
[0316] In some embodiments, the term "information" can be interchangeable with terms such as "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "field", and "data".
[0317] In some embodiments, the term "send" can be interchanged with terms such as "transmit", "report", and "transmit".
[0318] The data security processing method involved in the embodiments of the present disclosure may include at least one of steps S2101 to S2106. For example, steps S2103 to S2106 may be implemented as independent embodiments, steps S2103 to S2105 may be implemented as independent embodiments, steps S2101 to S2105 may be implemented as independent embodiments, and steps S2101 and S2102 may be implemented as independent embodiments. However, the present disclosure is not limited thereto.
[0319] In some embodiments, steps S2101 and S2102 are optional, and one or more of these steps may be omitted or replaced in different embodiments. It is understood that the first network device can independently generate a first key for the first UE and the second UE performing UE-SAT-UE communication, and send the first key to the first UE and the second UE, so that the first UE and the second UE can generate a second key based on the first key; the generation process of the first key does not need to consider the first information, so the core network function does not need to send the first information to the first network device.
[0320] In some embodiments, step S2106 is optional, and one or more of these steps may be omitted or replaced in different embodiments. It is understood that, if the UP service of the UE-SAT-UE communication between the first UE and the second UE does not require end-to-end security protection, the first UE and the second UE do not need to use the second key to securely protect the UP service of the UE-SAT-UE communication.
[0321] In some embodiments, steps S2103, S2104, S2105, and S2106 are optional, and one or more of these steps may be omitted or replaced in different embodiments. It is understood that when the first information indicates that the UE-SAT-UE communication between the first UE and the second UE does not require end-to-end security protection, the first network device does not need to determine the first key, and further does not need to send the first key to the first UE and the second UE.
[0322] FIG3A is a flow chart of a data security processing method according to an exemplary embodiment. As shown in FIG3a, the embodiment of the present disclosure relates to a data security processing method, which is executed by a first network device and includes:
[0323] Step S3101: Receive the first information sent by the core network function.
[0324] In some embodiments, the optional implementation of step S3101 can refer to the optional implementation of step S2102 in Figure 2 and other related parts of the embodiment involved in Figure 2, which will not be repeated here.
[0325] Step S3102: Determine the first key.
[0326] In some embodiments, the optional implementation of step S3102 can refer to the optional implementation of step S2103 in Figure 2 and other related parts of the embodiment involved in Figure 2, which will not be repeated here.
[0327] Step S3103: Send the first key to the first UE and the second UE.
[0328] In some embodiments, the optional implementation of step S3103 can refer to the optional implementation of step S2104 in Figure 2 and other related parts of the embodiment involved in Figure 2, which will not be repeated here.
[0329] The data security processing method involved in the embodiment of the present disclosure may include at least one of steps S3101 to S3103. For example, steps S3102 to S3103 may be implemented as independent embodiments, and step S3101 may be implemented as an independent embodiment, but is not limited thereto.
[0330] In some embodiments, step S3101 is optional, and one or more of these steps may be omitted or replaced in different embodiments. It is understood that the first network device can independently generate a first key for the first UE and the second UE performing UE-SAT-UE communication, and send the first key to the first UE and the second UE, so that the first UE and the second UE can generate a second key based on the first key; the generation process of the first key does not need to consider the first information, so the core network function does not need to send the first information to the first network device.
[0331] In some embodiments, steps S3102 and S3103 are optional, and one or more of these steps may be omitted or replaced in different embodiments. It is understood that when the first information indicates that the UE-SAT-UE communication between the first UE and the second UE does not require end-to-end security protection, the first network device does not need to determine the first key, and further does not need to send the first key to the first UE and the second UE.
[0332] FIG3B is a flow chart of a data security processing method according to an exemplary embodiment. As shown in FIG3B , the embodiment of the present disclosure relates to a data security processing method, which is executed by a first network device and includes:
[0333] Step S3201: Determine the first key;
[0334] In some embodiments, the first key is used by a first user equipment UE and a second UE to determine a second key.
[0335] In some embodiments, the second key is used for end-to-end security protection of user equipment to satellite to user equipment UE-SAT-UE communication between the first UE and the second UE.
[0336] Step S3202: Send the first key to the first UE and the second UE.
[0337] In some embodiments, determining the first key comprises:
[0338] The first key is generated according to a third key; the third key includes: an access layer AS intermediate key of the first UE and / or an AS layer intermediate key of the second UE.
[0339] In some embodiments, generating the first key according to the third key includes:
[0340] Determining a fourth key according to the access layer AS intermediate key of the first UE and / or the AS layer intermediate key of the second UE;
[0341] The first key is determined according to the fourth key.
[0342] In some embodiments, determining the fourth key according to the access stratum AS intermediate key of the first UE and / or the AS layer intermediate key of the second UE includes one of the following:
[0343] Performing an exclusive OR operation on the access layer AS intermediate key of the first UE and the AS layer intermediate key of the second UE to obtain the fourth key;
[0344] The access layer AS intermediate key of the first UE and the AS layer intermediate key of the second UE are concatenated to obtain the fourth key.
[0345] In some embodiments, the method further comprises:
[0346] receiving first information sent by a core network function, where the first information is used to indicate whether to activate end-to-end security protection for UE-SAT-UE communication between the first UE and the second UE;
[0347] The determining of the first key includes:
[0348] The first information indicates activation of end-to-end security protection of UE-SAT-UE communication between the first UE and the second UE, and determination of the first key.
[0349] In some embodiments, the method further comprises:
[0350] The first information is sent to the first UE and the second UE.
[0351] In some embodiments, the first information includes at least one of the following:
[0352] The security policy indication of the first UE is used to indicate whether a user plane of a locally transmitted protocol data unit (PDU) session between the first UE and the first network device providing service requires end-to-end security protection;
[0353] The security policy indication of the second UE is used to indicate whether the user plane of the PDU session locally transmitted between the second UE and the first network device providing service requires end-to-end security protection.
[0354] In some embodiments, generating the first key according to the third key includes one of the following:
[0355] generating a first key according to the first information and the third key;
[0356] A first key is generated according to the first information, the length of the first information, and the third key.
[0357] In some embodiments, the second key includes at least one of the following:
[0358] Integrity key;
[0359] Confidentiality key.
[0360] FIG4A is a flow chart of a data security processing method according to an exemplary embodiment. As shown in FIG4A , the embodiment of the present disclosure relates to a data security processing method, which is executed by a first UE and includes:
[0361] Step S4101: Receive a first key sent by a first network device.
[0362] In some embodiments, the optional implementation of step S4101 can refer to the optional implementation of step S2104 in Figure 2 and other related parts of the embodiment involved in Figure 2, which will not be repeated here.
[0363] Step S4102: Determine the second key based on the first key.
[0364] In some embodiments, the optional implementation of step S4102 can refer to the optional implementation of step S2105 in Figure 2 and other related parts of the embodiment involved in Figure 2, which will not be repeated here.
[0365] Step S4103: Perform end-to-end security protection on the UP service used for UE-SAT-UE communication based on the second key.
[0366] In some embodiments, the optional implementation of step S4103 can refer to the optional implementation of step S2106 in Figure 2 and other related parts of the embodiment involved in Figure 2, which will not be repeated here.
[0367] The data security processing method involved in the embodiment of the present disclosure may include at least one of steps S4101 to S4103. For example, steps S4101 to S4102 may be implemented as independent embodiments, but are not limited thereto.
[0368] In some embodiments, step S4103 is optional, and one or more of these steps may be omitted or replaced in different embodiments. It is understood that when the UP service of the UE-SAT-UE communication between the first UE and the second UE does not require end-to-end security protection, the first UE and the second UE do not need to use the second key to securely protect the UP service of the UE-SAT-UE communication.
[0369] FIG4B is a flow chart of a data security processing method according to an exemplary embodiment. As shown in FIG4B , the embodiment of the present disclosure relates to a data security processing method, which is executed by a first UE and includes:
[0370] Step S4201: Receive a first key sent by a first network device.
[0371] Step S4202: Determine a second key based on the first key.
[0372] In some embodiments, the second key is used for end-to-end security protection of user equipment to satellite to user equipment UE-SAT-UE communication between the first UE and the second UE.
[0373] In some embodiments, the first key is generated based on the third key; the third key includes: the access layer AS intermediate key of the first UE and / or the AS layer intermediate key of the second UE.
[0374] In some embodiments, the first key is generated based on the first information and the third key; or, the first key is generated based on the first information, the length of the first information and the third key; the first information is used to indicate whether to activate end-to-end security protection of UE-SAT-UE communication.
[0375] In some embodiments, the first information includes at least one of the following:
[0376] The security policy indication of the first UE is used to indicate whether a user plane of a locally transmitted protocol data unit (PDU) session between the first UE and the first network device providing service requires end-to-end security protection;
[0377] The security policy indication of the second UE is used to indicate whether the user plane of the PDU session locally transmitted between the second UE and the first network device providing service requires end-to-end security protection.
[0378] In some embodiments, the method further comprises:
[0379] Receive the first information sent by the first network device.
[0380] In conjunction with some embodiments of the second aspect, in some embodiments, the second key includes at least one of the following:
[0381] Integrity key;
[0382] Confidentiality key.
[0383] FIG4C is a flow chart of a data security processing method according to an exemplary embodiment. As shown in FIG4C , the embodiment of the present disclosure relates to a data security processing method, which is executed by a core network function and includes:
[0384] Step S4301: Determine the first information.
[0385] In some embodiments, the optional implementation of step S4301 can refer to the optional implementation of step S2101 in Figure 2 and other related parts of the embodiment involved in Figure 2, which will not be repeated here.
[0386] Step S4302: Send first information to the first network device.
[0387] In some embodiments, the optional implementation of step S4302 can refer to the optional implementation of step S2102 in Figure 2 and other related parts of the embodiment involved in Figure 2, which will not be repeated here.
[0388] FIG4D is a flow chart illustrating a data security processing method according to an exemplary embodiment. As shown in FIG4D , the embodiment of the present disclosure relates to a data security processing method, which is executed by a core network function and includes:
[0389] Step S4401: Send first information to a first network device.
[0390] In some embodiments, the first information is used to indicate whether UE-SAT-UE communication between the first UE and the second UE requires end-to-end security protection.
[0391] In some embodiments, the first information includes at least one of the following:
[0392] The security policy indication of the first UE is used to indicate whether a user plane of a locally transmitted protocol data unit (PDU) session between the first UE and the first network device providing service requires end-to-end security protection;
[0393] The security policy indication of the second UE is used to indicate whether the user plane of the PDU session locally transmitted between the second UE and the first network device providing service requires end-to-end security protection.
[0394] In some embodiments, the method further comprises:
[0395] The first information is determined based on the session management information of the PDU session of the first UE and / or the second UE.
[0396] FIG5 is an interactive diagram illustrating a data security processing method according to an exemplary embodiment. As shown in FIG5 , the embodiment of the present disclosure relates to a data security processing method for a communication system 100, and the method includes one of the following steps:
[0397] Step S5101: The core network function sends first information to the first network device.
[0398] In some embodiments, the first information is used to indicate whether to activate end-to-end security protection for UE-SAT-UE communication.
[0399] Step S5102: The first network device determines a first key.
[0400] In some embodiments, the first information indicates activation of end-to-end security protection for UE-SAT-UE communication, and determines the first key.
[0401] Step S5103: The first network device sends the first key to the first UE and the second UE.
[0402] Step S5104: The first UE and the second UE determine the second key based on the first key.
[0403] In some embodiments, the second key is used for end-to-end security protection of user equipment to satellite to user equipment UE-SAT-UE communication between the first UE and the second UE.
[0404] In some embodiments, the above method may include the methods of the above-mentioned communication system side, user equipment side, access network equipment side, core network equipment side, etc., which will not be repeated here.
[0405] In some embodiments, if end-to-end protection is applied between two communicating UEs, consistent protection of UP traffic for UE-SAT-UE communication carried on both the UU interface and the ISL can be achieved. Currently, there is no solution for end-to-end (E2E) protection of UP traffic for UE-SAT-UE communication.
[0406] As shown in FIG6 , FIG6 is a schematic diagram showing a flow chart of end-to-end protection of UE-SAT-UE communication according to an exemplary embodiment.
[0407] Step 1: UE1's PDU session establishment process.
[0408] UE1 sends a PDU session establishment request to the core network device and indicates UE2 as the target UE for communication. During this process, the core network function (e.g., SMF) sends the E2E security indication for UE-SAT-UE communication to UE1's access network device. The SMF determines the E2E security protection for UE-SAT-UE communication based on the session management subscription data or session management information.
[0409] When receiving the E2E security indication, the access network device should not understand the activation of UP security protection of the Uu interface of UE1, but will wait for receiving the UP security policy during the PDU session establishment of UE2.
[0410] Step 2: UE1's PDU session establishment process.
[0411] The network triggers the communication requested by UE1, and UE2 initiates PDU session establishment with the core network equipment. During this process, the core network function (e.g., SMF) sends the E2E security indication for UE-SAT-UE communication to UE2's access network equipment. The SMF determines the E2E security protection for UE-SAT-UE communication based on the session management subscription data or session management information.
[0412] Step 3: The access network device determines the root key K for E2E security of UE-SAT-UE communication. E2E .
[0413] The access network device determines the root key K for E2E security of UE-SAT-UE communication based on the E2E security indication E2E .
[0414] Step 4: While activating the UP security of the Uu interface for UE1 and UE2 respectively, the access network device sends the E2E security indication and root key K for UE-SAT-UE communication to UE1 and UE2. E2E .
[0415] Step 5: UE1 and UE2 determine the E2E key K for UP service based on the root key received from the access network device. UP-E2E .
[0416] Here, the E2E key K used for UP service UP-E2E May include a confidentiality key K UP-E2E-enc and the integrity key K UP-E2E-int .
[0417] Step 6: UE1 and UE2 use the E2E key K for UP service UP-E2E Protects UP services exchanged between UE1 and UE2 through access network equipment.
[0418] It is worth noting that step 5b in FIG. 6 may occur after step 6.
[0419] The root key K for E2E security E2E of confirmation.
[0420] When the access network device derives the root key K E2E The following parameters should be used to form the input parameters of the Key Derivation Function (KDF):
[0421] FC=TBD;
[0422] P0 = E2E security indication for UE-SAT-UE communication;
[0423] L0 = length of the E2E security indication used for UE-SAT-UE communication;
[0424] The input key can be:
[0425] UE1's access layer key K gNB and UE2's access layer key K gNB cascade; for example, K gNB (UE1)||K gNB (UE2); or,
[0426] UE1's access layer key K gNB and UE2's access layer key K gNB XOR of; for example
[0427] When UE1 and UE2 are served by the same access network device, the access network device also has the access layer key K of UE1. gNB and UE2's access layer key K gNB .
[0428] When UE1 and UE2 are served by different access network devices (e.g., gNB1 and gNB2), gNB1 needs to send UE1's access stratum key K to gNB2. gNB , so that both gNBs can calculate the access stratum key K of UE1 gNB and UE2's access layer key K gNB Cascade or XOR.
[0429] The embodiments of the present disclosure also provide an apparatus for implementing any of the above methods. For example, an apparatus is provided, comprising units or modules for implementing each step performed by a terminal in any of the above methods. For another example, another apparatus is provided, comprising units or modules for implementing each step performed by a network device (e.g., an access network device or a core network device) in any of the above methods.
[0430] It should be understood that the division of the various units or modules in the above devices is merely a division of logical functions. In actual implementation, they may be fully or partially integrated into a physical entity, or they may be physically separated. In addition, the units or modules in the device may be implemented in the form of a processor calling software: for example, the device includes a processor, the processor is connected to a memory, and the memory stores instructions. The processor calls the instructions stored in the memory to implement any of the above methods or implement the functions of the various units or modules of the above devices, wherein the processor is, for example, a general-purpose processor, such as a central processing unit (CPU) or a microprocessor, and the memory is a memory within the device or a memory outside the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuits, and the functions of some or all of the units or modules can be realized by designing the hardware circuits. The above-mentioned hardware circuits can be understood as one or more processors; for example, in one implementation, the above-mentioned hardware circuit is an application-specific integrated circuit (ASIC), which realizes the functions of some or all of the above units or modules by designing the logical relationship of the components in the circuit; for example, in another implementation, the above-mentioned hardware circuit can be realized by a programmable logic device (PLD). Taking a field programmable gate array (FPGA) as an example, it can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by configuring the configuration file, thereby realizing the functions of some or all of the above units or modules. All units or modules of the above devices can be realized in the form of software called by the processor, or in the form of hardware circuits, or in part by the form of software called by the processor, and the rest by hardware circuits.
[0431] In the embodiments of the present disclosure, a processor is a circuit with signal processing capabilities. In one implementation, the processor can be a circuit with instruction reading and execution capabilities, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), or a digital signal processor (DSP). In another implementation, the processor can implement certain functions through the logical relationship of a hardware circuit. The logical relationship of the above-mentioned hardware circuit is fixed or reconfigurable. For example, the processor is a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document to implement the hardware circuit configuration can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules. In addition, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), etc.
[0432] FIG7A is a schematic diagram showing the structure of a first network device according to an exemplary embodiment. As shown in FIG7A , the first network device includes:
[0433] The determining module 7101 is configured to determine a first key; the first key is used by a first user equipment UE and a second UE to determine a second key; the second key is used for end-to-end security protection of user equipment to satellite to user equipment UE-SAT-UE communication between the first UE and the second UE;
[0434] The sending module 7102 is configured to send the first key to the first UE and the second UE.
[0435] In some embodiments, the determination module may be used by the first network device to execute information determination-related steps in any data security processing method.
[0436] In some embodiments, the sending module can be used by the first network device to execute information sending related steps in any data security processing method.
[0437] In some embodiments, the first network device may further include: a receiving module.
[0438] In some embodiments, the receiving module may correspond to a network interface and / or a transceiver antenna of the first network device.
[0439] In some embodiments, the receiving module may be used by the first network device to execute steps related to information reception in any data security processing method.
[0440] In some embodiments, the determination module is configured to generate the first key according to a third key; the third key includes: an access layer AS intermediate key of the first UE and / or an AS layer intermediate key of the second UE.
[0441] In some embodiments, the determination module is configured to determine a fourth key based on the access layer AS intermediate key of the first UE and / or the AS layer intermediate key of the second UE; and determine the first key based on the fourth key.
[0442] In some embodiments, the determination module is configured to perform one of the following:
[0443] Performing an exclusive OR operation on the access layer AS intermediate key of the first UE and the AS layer intermediate key of the second UE to obtain the fourth key;
[0444] The access layer AS intermediate key of the first UE and the AS layer intermediate key of the second UE are concatenated to obtain the fourth key.
[0445] In some embodiments, the receiving module is configured to receive first information sent by a core network function, where the first information is used to indicate whether to activate end-to-end security protection for UE-SAT-UE communication between the first UE and the second UE;
[0446] The determination module is configured to determine the first key based on the first information indication to activate end-to-end security protection of UE-SAT-UE communication between the first UE and the second UE.
[0447] In some embodiments, the sending module is configured to send the first information to the first UE and the second UE.
[0448] In some embodiments, the first information includes at least one of the following:
[0449] The security policy indication of the first UE is used to indicate whether a user plane of a locally transmitted protocol data unit (PDU) session between the first UE and the first network device providing service requires end-to-end security protection;
[0450] The security policy indication of the second UE is used to indicate whether the user plane of the PDU session locally transmitted between the second UE and the first network device providing service requires end-to-end security protection.
[0451] In some embodiments, the determination module is configured to perform one of the following:
[0452] generating a first key according to the first information and the third key;
[0453] A first key is generated according to the first information, the length of the first information, and the third key.
[0454] In some embodiments, the second key includes at least one of the following:
[0455] Integrity key;
[0456] Confidentiality key.
[0457] FIG7B is a schematic diagram showing the structure of a first UE device according to an exemplary embodiment. As shown in FIG7B , the first UE includes:
[0458] The receiving module 7201 is configured to receive a first key sent by a first network device;
[0459] The determination module 7202 is configured to determine a second key based on the first key; the second key is used for end-to-end security protection of user equipment to satellite to user equipment UE-SAT-UE communication between the first UE and the second UE.
[0460] In some embodiments, the receiving module may be used by the first UE to perform steps related to information reception in any one of the data security processing methods.
[0461] In some embodiments, the receiving module may correspond to a network interface and / or a transceiver antenna of the first UE.
[0462] In some embodiments, the determination module may be used by the first UE to perform information determination-related steps in any data security processing method.
[0463] In some embodiments, the first UE may further include: a sending module.
[0464] In some embodiments, the sending module can be used by the first network device to execute information sending related steps in any data security processing method.
[0465] In some embodiments, the first key is generated based on the third key; the third key includes: the access layer AS intermediate key of the first UE and / or the AS layer intermediate key of the second UE.
[0466] In some embodiments, the first key is generated based on the first information and the third key; or
[0467] The first key is generated according to the first information, the length of the first information and the third key; the first information is used to indicate whether to activate end-to-end security protection of UE-SAT-UE communication.
[0468] In some embodiments, the first information includes at least one of the following:
[0469] The security policy indication of the first UE is used to indicate whether a user plane of a locally transmitted protocol data unit (PDU) session between the first UE and the first network device providing service requires end-to-end security protection;
[0470] The security policy indication of the second UE is used to indicate whether the user plane of the PDU session locally transmitted between the second UE and the first network device providing service requires end-to-end security protection.
[0471] In some embodiments, the receiving module is configured to receive the first information sent by the first network device.
[0472] In some embodiments, the second key includes at least one of the following:
[0473] Integrity key;
[0474] Confidentiality key.
[0475] FIG7C is a schematic diagram showing a structure of a core network function according to an exemplary embodiment. As shown in FIG7C , the core network function includes:
[0476] The sending module 7301 is configured to send first information to the first network device, where the first information is used to indicate whether UE-SAT-UE communication between the first UE and the second UE requires end-to-end security protection.
[0477] In some embodiments, the sending module can be used by the core network function to perform information sending related steps in any data security processing method.
[0478] In some embodiments, the core network function may further include: a receiving module and / or a determining module.
[0479] In some embodiments, the receiving module can be used by the core network function to perform information reception-related steps in any data security processing method.
[0480] In some embodiments, the determination module may be used by the core network function to execute information determination-related steps in any data security processing method.
[0481] In some embodiments, the first information includes at least one of the following:
[0482] The security policy indication of the first UE is used to indicate whether a user plane of a locally transmitted protocol data unit (PDU) session between the first UE and the first network device providing service requires end-to-end security protection;
[0483] The security policy indication of the second UE is used to indicate whether the user plane of the PDU session locally transmitted between the second UE and the first network device providing service requires end-to-end security protection.
[0484] In some embodiments, the determination module is configured to determine the first information based on session management information of the PDU session of the first UE and / or the second UE.
[0485] Figure 8A is a schematic diagram of the structure of a communication device according to an exemplary embodiment. Communication device 8100 can be a network device (e.g., an access network device or a core network device), a terminal (e.g., a user device), a chip, a chip system, or a processor that supports a network device to implement any of the above methods, or a chip, a chip system, or a processor that supports a terminal to implement any of the above data security processing methods. Communication device 8100 can be used to implement the data security processing method described in the above method embodiment. For details, please refer to the description of the above method embodiment.
[0486] As shown in Figure 8A, the communication device 8100 includes one or more processors 8101. The processor 8101 can be a general-purpose processor or a dedicated processor, for example, a baseband processor or a central processing unit. The baseband processor can be used to process communication protocols and communication data, and the central processing unit can be used to control the communication device (such as a base station, a baseband chip, a terminal device, a terminal device chip, a DU or a CU, etc.), execute programs, and process program data. The processor 8101 is used to call instructions to enable the communication device 8100 to perform any of the above communication methods.
[0487] In some embodiments, the communication device 8100 further includes one or more memories 8102 for storing instructions. Optionally, all or part of the memories 8102 may be located outside the communication device 8100.
[0488] In some embodiments, the communication device 8100 further includes one or more transceivers 8103. When the communication device 8100 includes one or more transceivers 8103, the communication steps such as sending and receiving in the above method are performed by the transceiver 8103, and the other steps are performed by the processor 8101.
[0489] In some embodiments, a transceiver may include a receiver and a transmitter, which may be separate or integrated. Optionally, the terms transceiver, transceiver unit, transceiver, and transceiver circuit may be used interchangeably; the terms transmitter, transmitting unit, transmitter, and transmitting circuit may be used interchangeably; and the terms receiver, receiving unit, receiver, and receiving circuit may be used interchangeably.
[0490] Optionally, the communication device 8100 further includes one or more interface circuits 8104, which are connected to the memory 8102. The interface circuits 8104 can be used to receive signals from the memory 8102 or other devices, and can be used to send signals to the memory 8102 or other devices. For example, the interface circuits 8104 can read instructions stored in the memory 8102 and send the instructions to the processor 8101.
[0491] The communication device 8100 described in the above embodiment may be a network device or a terminal, but the scope of the communication device 8100 described in the present disclosure is not limited thereto, and the structure of the communication device 8100 may not be limited by FIG. 8A. The communication device may be an independent device or may be part of a larger device. For example, the communication device may be: (1) an independent integrated circuit IC, or a chip, or a chip system or subsystem; (2) a collection of one or more ICs, optionally, the above IC collection may also include a storage component for storing data or programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, a terminal device, an intelligent terminal device, a cellular phone, a wireless device, a handheld device, a mobile unit, an in-vehicle device, a network device, a cloud device, an artificial intelligence device, etc.; (6) others, etc.
[0492] FIG8B is a schematic diagram showing the structure of a chip 8200 according to an exemplary embodiment. If the communication device 8100 can be a chip or a chip system, reference can be made to the schematic diagram of the structure of the chip 8200 shown in FIG8B , but the present invention is not limited thereto.
[0493] The chip 8200 includes one or more processors 8201 , and the processor 8201 is used to call instructions so that the chip 8200 executes any of the above communication methods.
[0494] In some embodiments, chip 8200 further includes one or more interface circuits 8202, which are connected to memory 8203. Interface circuit 8202 can be used to receive signals from memory 8203 or other devices, and can be used to send signals to memory 8203 or other devices. For example, interface circuit 8202 can read instructions stored in memory 8203 and send the instructions to processor 8201. Optionally, the terms interface circuit, interface, transceiver pin, and transceiver are interchangeable.
[0495] In some embodiments, the chip 8200 further includes one or more memories 8203 for storing instructions. Alternatively, all or part of the memories 8203 may be outside the chip 8200.
[0496] The present disclosure also provides a storage medium having instructions stored thereon, which, when executed on the communication device 8100, causes the communication device 8100 to execute any of the above methods. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer-readable storage medium, but may also be a storage medium readable by other devices. Optionally, the storage medium may be a non-transitory storage medium, but may also be a transient storage medium.
[0497] The present disclosure further provides a program product, which, when executed by the communication device 8100, enables the communication device 8100 to perform any of the above communication methods. Optionally, the program product is a computer program product.
[0498] The present disclosure also provides a computer program, which, when executed on a computer, enables the computer to execute any one of the above communication methods.
[0499] Other embodiments of the present invention will readily occur to those skilled in the art after considering the specification and practicing the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of the invention that follow from the general principles of the invention and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, with the true scope and spirit of the invention being indicated by the following claims.
[0500] It should be understood that the present invention is not limited to the exact construction described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present invention is limited only by the appended claims.
Claims
1. A data security processing method, wherein, Performed by a first network device, the method includes: Determine a first key; the first key is used by a first user equipment (UE) and a second UE to determine a second key; the second key is used for end-to-end security protection for user equipment to satellite to user equipment (UE-SAT-UE) communication between the first UE and the second UE; Send the first key to the first UE and the second UE.
2. The method according to claim 1, wherein The determining the first key includes: Generate the first key according to a third key; the third key includes: an access stratum (AS) intermediate key of the first UE and / or an AS layer intermediate key of the second UE.
3. The method according to claim 2, wherein, The generating the first key according to the third key includes: Determine a fourth key according to the access stratum (AS) intermediate key of the first UE and / or the AS layer intermediate key of the second UE; Determine the first key according to the fourth key.
4. The method according to claim 3, wherein The determining the fourth key according to the access stratum (AS) intermediate key of the first UE and / or the AS layer intermediate key of the second UE includes one of the following: Perform an exclusive OR operation on the access stratum (AS) intermediate key of the first UE and the AS layer intermediate key of the second UE to obtain the fourth key; Concatenate the access stratum (AS) intermediate key of the first UE and the AS layer intermediate key of the second UE to obtain the fourth key.
5. The method according to any one of claims 1 to 4, wherein, The method further includes: Receive first information sent by a core network function, the first information being used to indicate whether to activate end-to-end security protection for UE-SAT-UE communication between the first UE and the second UE; The determining the first key includes: When the first information indicates to activate end-to-end security protection for UE-SAT-UE communication between the first UE and the second UE, determine the first key.
6. The method according to claim 5, wherein The method further includes: Send the first information to the first UE and the second UE.
7. The method according to claim 5 or 6, wherein The first information includes at least one of the following: A security policy indication of the first UE, used to indicate whether end-to-end security protection is required for the user plane of a protocol data unit (PDU) session for local transmission between the first UE and a first network device providing services; A security policy indication of the second UE, used to indicate whether end-to-end security protection is required for the user plane of a PDU session for local transmission between the second UE and a first network device providing services.
8. The method according to any one of claims 5 to 7, wherein The generating the first key according to the third key includes one of the following: Generate a first key according to the first information and the third key; Generate a first key according to the first information, the length of the first information, and the third key.
9. The method according to any one of claims 1 to 8, wherein, The second key includes at least one of the following: An integrity key; A confidentiality key.
10. A data security processing method, wherein, Performed by a first UE, the method includes: Receive a first key sent by a first network device; Determine a second key according to the first key; the second key is used for end-to-end security protection for UE-SAT-UE communication between the first UE and the second UE.
11. The method according to claim 10, wherein, The first key is generated based on a third key; the third key includes: the access stratum (AS) intermediate key of the first UE and / or the AS layer intermediate key of the second UE.
12. The method according to claim 11, wherein the first key is generated based on first information and the third key; or the first key is generated based on the first information, the length of the first information, and the third key; the first information is used to indicate whether to activate end-to-end security protection for UE-SAT-UE communication.
13. The method according to claim 12, wherein, The first information includes at least one of the following: a security policy indication of the first UE, used to indicate whether end-to-end security protection is required for the user plane of a protocol data unit (PDU) session for local transmission between the first UE and a first network device providing services; a security policy indication of the second UE, used to indicate local transmission between the second UE and the first network device providing services whether end-to-end security protection is required for the user plane of the PDU session.
14. The method according to claim 12 or 13, wherein The method further includes: receiving the first information sent by the first network device.
15. The method according to any one of claims 10 to 14, wherein The second key includes at least one of the following: an integrity key; a confidentiality key.
16. A data security processing method, wherein, Performed by a core network function, the method includes: sending first information to a first network device, the first information being used to indicate whether end-to-end security protection is required for UE-SAT-UE communication between a first UE and a second UE.
17. The method according to claim 16, wherein, The first information includes at least one of the following: a security policy indication of the first UE, used to indicate whether end-to-end security protection is required for the user plane of a protocol data unit (PDU) session for local transmission between the first UE and a first network device providing services; a security policy indication of the second UE, used to indicate whether end-to-end security protection is required for the user plane of a PDU session for local transmission between the second UE and a first network device providing services.
18. The method according to claim 16 or 17, wherein The method further includes: determining the first information according to session management information of the PDU session of the first UE and / or the second UE.
19. A data security processing method, wherein, Performed by a communication system, the method includes: a core network function sending first information to a first network device, the first information being used to indicate whether end-to-end security protection is required for UE-SAT-UE communication between a first UE and a second UE; the first network device determining a first key; sending the first key to the first UE and the second UE; the first UE and the second UE determining a second key according to the first key; the second key is used for end-to-end security protection for user equipment to satellite to user equipment (UE-SAT-UE) communication between the first UE and the second UE.
20. A first network device, wherein, Includes: a determination module, configured to determine a first key; the first key is used for a first user equipment (UE) and a second UE to determine a second key; the second key is used for end-to-end security protection for user equipment to satellite to user equipment (UE-SAT-UE) communication between the first UE and the second UE; a sending module, configured to send the first key to the first UE and the second UE.
21. A first UE, wherein, Includes: A receiving module, configured to receive a first key sent by a first network device; A determining module, configured to determine a second key according to the first key; The second key is used for end-to-end security protection of user equipment to satellite to user equipment (UE-SAT-UE) communication between a first UE and a second UE.
22. A core network function, wherein, It includes: A sending module, configured to send first information to the first network device, where the first information is used to indicate whether end-to-end security protection is required for UE-SAT-UE communication between the first UE and the second UE.
23. A communication system, wherein, The communication system includes a first terminal, a first network device, and a core network function; the first network device is configured to implement the data security processing method described in any one of claims 1 to 9, the first terminal is configured to implement the data security processing method described in any one of claims 10 to 15, and the core network function is configured to implement the data security processing method described in any one of claims 16 to 19.
24. A communication device, wherein, The communication device includes: One or more processors; Wherein, the processor is used to call instructions to enable the communication device to execute the data security processing method described in any one of claims 1 to 9, claims 10 to 15, and claims 16 to 19.
25. A storage medium, wherein, The storage medium stores instructions, and when the instructions run on the communication device, the communication device is enabled to execute the data security processing method described in any one of claims 1 to 9, claims 10 to 15, and claims 16 to 19.
Citation Information
Patent Citations
Methods and systems for handling user equipment associated information
CN112789885A
End-to-end communication method of low-orbit satellite communication network system
CN114785399A
Satellite terminal key distribution method, device and system
CN115334497A
Secure communication method and device, communication equipment, communication system and storage medium
CN117136572A
Data transmission method, satellite base station, gateway station, and storage medium
WO2023078339A1