Information processing method, communication system and storage medium

CN120677735APending Publication Date: 2025-09-19BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202480005598.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-01-19
Publication Date
2025-09-19

AI Technical Summary

Technical Problem

In the satellite communication scenario, how to handle the security protection of user plane data from the first terminal to the second terminal, especially in UE-SAT-UE communication, how to ensure the security and consistency protection of data transmission.

Method used

Through collaboration between the access network device and the core network device, based on the first indication information and the second indication information, a security protection policy of the UP data of the first terminal and the second terminal, including the indication of the transmission method and the security policy, is determined to realize the security protection of the UP data.

Benefits of technology

The security of communication between the first terminal and the satellite to the second terminal is improved, ensuring the consistency of security policies for data transmission and adapting to the security needs of different terminals, and preventing data leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120677735A_ABST
    Figure CN120677735A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides an information processing method, a communication system and a storage medium. The information processing method is executed by access network equipment, and comprises the following steps: determining security protection of UP data of a first terminal and a second terminal based on first indication information and second indication information; wherein the first indication information is used for indicating a transmission mode and / or a security policy of the UP data of the first terminal, and the second indication information is used for indicating a transmission mode and / or a security policy of the UP data of the second terminal; therefore, the access network equipment can determine the security protection of the UP data of the first terminal and the second terminal, and the security of communication from the first terminal to the satellite to the second terminal can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Information processing method, communication system and storage medium Technical Field

[0001] The present disclosure relates to the field of communication technology, and in particular to an information processing method, a communication system, and a storage medium. Background Art

[0002] Satellite communication technology has been introduced in the field of communications technology, enabling user equipment (UE) to communicate via satellite-based access networks. UE-to-satellite-to-UE (UE-SAT-UE) communication refers to communication between UEs (UEs) under the coverage of one or more server satellites, with user plane (UP) data exchanged locally without passing through the terrestrial network. Optionally, a UE can be a terminal.

[0003] Summary of the Invention

[0004] The embodiments of the present disclosure need to solve the problem of how to handle the security protection of UP data of the first terminal and the UP data of the second terminal in the communication scenario from the first terminal to the satellite to the second terminal (ie, UE-SAT-UE).

[0005] According to a first aspect of an embodiment of the present disclosure, an information processing method is proposed, which is executed by an access network device, including: determining the security protection of UP data of a first terminal and a second terminal based on first indication information and second indication information; wherein the first indication information is used to indicate the transmission mode and / or security policy of the UP data of the first terminal, and the second indication information is used to indicate the transmission mode and / or security policy of the UP data of the second terminal.

[0006] According to the second aspect of an embodiment of the present disclosure, an information processing method is proposed, which is executed by a core network device, including: sending first information to an access network device, the first information including first indication information; the first indication information is used to indicate the transmission method and / or security policy of the UP data of the first terminal; sending second information to the access network device, the second information including second indication information; the second indication information is used to indicate the transmission method and / or security policy of the UP data of the second terminal; wherein the first indication information and the second indication information are used by the access network device to determine the security protection of the UP data of the first terminal and the second terminal.

[0007] According to a third aspect of an embodiment of the present disclosure, an access network device is proposed, including: a first transceiver module, configured to determine the security protection of UP data of a first terminal and a second terminal based on first indication information and second indication information; wherein the first indication information is used to indicate the transmission mode and / or security policy of the UP data of the first terminal, and the second indication information is used to indicate the transmission mode and / or security policy of the UP data of the second terminal.

[0008] According to the fourth aspect of an embodiment of the present disclosure, a core network device is proposed, including: a second transceiver module, configured to send first information to an access network device, the first information including first indication information; the first indication information is used to indicate the transmission mode and / or security policy of UP data of the first terminal; the second transceiver module is also configured to send second information to the access network device, the second information including second indication information; the second indication information is used to indicate the transmission mode and / or security policy of UP data of the second terminal; wherein the first indication information and the second indication information are used by the access network device to determine the security protection of UP data of the first terminal and the second terminal.

[0009] According to a fifth aspect of an embodiment of the present disclosure, a communication device is proposed, comprising one or more processors; wherein the above-mentioned communication device is used to execute optional implementation methods such as the first aspect, the second aspect, or the first and second aspects.

[0010] According to the sixth aspect of the embodiment of the present disclosure, a communication system is proposed, including: an access network device and a core network device; wherein the above-mentioned access network device is configured to execute the method described in the optional implementation manner of the first aspect, and the above-mentioned core network device is configured to execute the method described in the optional implementation manner of the second aspect.

[0011] According to the seventh aspect of an embodiment of the present disclosure, a storage medium is proposed, which stores instructions. When the instructions are executed on a communication device, the communication device executes the method described in the first aspect, the second aspect, or the optional implementation of the first and second aspects.

[0012] The embodiments of the present disclosure can enable the access device to implement security protection of the UP data of the first terminal and the UP data of the second terminal in a communication scenario from the first terminal to the satellite to the second terminal (i.e., UE-SAT-UE). BRIEF DESCRIPTION OF THE DRAWINGS

[0013] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure, the following drawings required for describing the embodiments are introduced. The following drawings are merely some embodiments of the present disclosure and do not impose specific limitations on the protection scope of the present disclosure.

[0014] FIG1A is a schematic structural diagram of an information processing system according to an embodiment of the present disclosure.

[0015] FIG1B is a schematic diagram showing a scenario in which a UE-SAT-UE provides a service according to an exemplary embodiment.

[0016] FIG2 is an interactive schematic diagram illustrating an information processing method according to an embodiment of the present disclosure.

[0017] FIG3A is a flow chart illustrating an information processing method according to an embodiment of the present disclosure.

[0018] FIG3B is a flow chart illustrating an information processing method according to an embodiment of the present disclosure.

[0019] FIG3C is a flow chart illustrating an information processing method according to an embodiment of the present disclosure.

[0020] FIG3D is a flow chart illustrating an information processing method according to an embodiment of the present disclosure.

[0021] FIG4A is a flow chart illustrating an information processing method according to an embodiment of the present disclosure.

[0022] FIG4B is a flow chart illustrating an information processing method according to an embodiment of the present disclosure.

[0023] FIG5 is a flow chart showing an information processing method according to an embodiment of the present disclosure.

[0024] FIG6A is a schematic structural diagram of an access network device according to an embodiment of the present disclosure.

[0025] FIG6B is a schematic structural diagram of a core network device according to an embodiment of the present disclosure.

[0026] FIG7A is a schematic structural diagram of a communication device provided according to an embodiment of the present disclosure.

[0027] FIG7B is a schematic structural diagram of a chip provided according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0028] The embodiments of the present disclosure provide an information processing method, a communication system, and a storage medium.

[0029] In a first aspect, an embodiment of the present disclosure proposes an information processing method, which is executed by an access network device, including: determining the security protection of UP data of a first terminal and a second terminal based on first indication information and second indication information; wherein the first indication information is used to indicate the transmission mode and / or security policy of the UP data of the first terminal, and the second indication information is used to indicate the transmission mode and / or security policy of the UP data of the second terminal.

[0030] In the above embodiment, the access network device can determine the security protection of UP data of the first terminal and the second terminal (in the case of UE-SAT-UE communication), which can improve the security of communication between the first terminal, the satellite and the second terminal.

[0031] In combination with some embodiments of the first aspect, in some embodiments, determining the security protection of the UP data of the first terminal and the second terminal includes at least one of the following: determining whether the UP data of the first terminal and the second terminal need to be securely protected; determining whether the UP data of the first terminal and the second terminal are consistently securely protected; and determining a security policy for security protection of the UP data of the first terminal and / or the second terminal.

[0032] In the above embodiment, the access network device can determine whether the first terminal and the second terminal perform security protection, whether to perform consistent security protection and / or perform a security policy for security protection, thereby facilitating unified security protection of UP data when communicating from the first terminal to the satellite to the second terminal.

[0033] In combination with some embodiments of the first aspect, in some embodiments, the method also includes: receiving first information sent by the core network device, wherein the first information includes first indication information; receiving second information sent by the core network device, wherein the second information includes second indication information.

[0034] In the above embodiment, the access network device can receive first information of the first terminal and second information of the second terminal from the core network device, so as to facilitate the subsequent determination of security protection for UP data based on the first indication information included in the first information and the second indication information included in the second information.

[0035] In combination with some embodiments of the first aspect, in some embodiments, based on the first indication information and the second indication information, determining the security protection of the user plane UP data of the first terminal and the second terminal includes one of the following: when the transmission mode of the UP data indicated by the first indication information and the second indication information is both UE-SAT-UE local transmission, determining to enable consistency security protection for the UP data of the first terminal and the second terminal; when the security policies of the UP data indicated by the first indication information and the second indication information are the same and are first-type security policies, determining to perform consistency security protection on the UP data of the first terminal and the second terminal; when the security policies of the UP data indicated by the first indication information and the second indication information are the same and are second-type security policies, determining how to perform consistency security protection on the UP data based on the access network device; and when the security policies of the UP data indicated by the first indication information and the second indication information are different, determining whether to perform consistency protection on the UP data of the first terminal and the second terminal according to the categories of the security policies respectively indicated by the first indication information and the second indication information.

[0036] In the above embodiment, the access network device can determine whether to enable consistency protection of the UP data of the first terminal and the second terminal based on the first indication information and the second indication information, or can accurately determine whether the UP data of the first terminal and the second terminal need to be consistently protected, and the specific security policy if consistency protection is required, etc. based on the security policy indicated by the first indication information and the second indication information.

[0037] In combination with some embodiments of the first aspect, in some embodiments, the first type of security policy includes whether protection is required or not required; and / or, the second type of security policy includes preferred protection; wherein the preferred protection indicates the security protection selected by the preferred access network device.

[0038] In the above embodiment, the specific first-class security policy is defined as requiring protection or not requiring protection, and / or the specific second security policy is defined as including preferred protection, thereby facilitating the access network device to determine the security protection of UP data based on different types of security policies.

[0039] In combination with some embodiments of the first aspect, in some embodiments, determining whether the UP data of the first terminal and the second terminal are consistent with each other is determined based on the categories of security policies respectively indicated by the first indication information and the second indication information, including at least one of the following: when one of the first indication information and the second indication information indicates a first type of security policy and the other indicates a second type of security policy, determining that the UP data of the first terminal and the second terminal are consistent with each other and protected by the first type of security policy; wherein the first type of security policy includes whether protection is required or not, and the second type of security policy includes preferred protection; and when both the first indication information and the second indication information indicate the first type of security policy, and the security policies indicated by the first indication information and the second indication information are different, determining that the UP data of the first terminal and the second terminal cannot be consistently protected.

[0040] In the above embodiment, if one of the security policies of the first terminal and the second terminal indicates that security protection is required or not required and the other indicates preferred protection, it can be determined that the first terminal and the second terminal need to be consistently protected; alternatively, if one of the security policies of the first terminal and the second terminal indicates that protection is required and the other indicates that protection is not required, it is determined that consistently security protection cannot be performed; in this way, appropriate and accurate security protection can be determined for different application scenarios.

[0041] In combination with some embodiments of the first aspect, in some embodiments, the method also includes: refusing to establish a session with the first terminal and the second terminal when it is determined that the first terminal and the second terminal cannot be protected in consistency; or, when it is determined that the first terminal and the second terminal cannot be protected in consistency, performing security protection on the UP data of the first terminal based on the security policy indicated by the first indication information, and / or, performing security protection on the UP data of the second terminal based on the security policy indicated by the second indication information.

[0042] In the above embodiment, when consistent security protection cannot be performed, the established session can be rejected to reduce the possibility of data leakage caused by the inability to perform security protection in the communication between the first terminal, the satellite, and the second terminal; or, when consistent security protection cannot be performed, the first terminal and the second terminal can also be made to perform security protection according to their own security policies, thereby realizing communication between the first terminal, the satellite, and the second terminal.

[0043] In combination with some embodiments of the first aspect, in some embodiments, the method further includes: activating security protection of the UP data of the first terminal and / or the second terminal based on a security policy for the UP data of the first terminal and the second terminal.

[0044] In the above embodiment, after the security policy is configured, the security policy can be activated to perform security protection.

[0045] In combination with some embodiments of the first aspect, in some embodiments, the method also includes: sending third information to the first terminal and / or the second terminal, wherein the third information is used to indicate the security protection of UP data of the first terminal and / or the second terminal determined by the access network device; the third information is used for the first terminal and / or the second terminal to perform security protection of UP data.

[0046] In the above embodiment, the third information may be sent to the first terminal and / or the second terminal, so that the first terminal and / or the second terminal performs security protection based on the security policy configured by the access network device.

[0047] In combination with some embodiments of the first aspect, in some embodiments, the access network device includes a satellite base station; and / or the core network device includes: an access and mobility management function (AMF), or a session management function (SMF), or a policy control function (PCF).

[0048] In the second aspect, an embodiment of the present disclosure proposes an information processing method, which is executed by a core network device, including: sending first information to an access network device, the first information including first indication information; the first indication information is used to indicate the transmission method and / or security policy of the UP data of the first terminal; sending second information to the access network device, the second information including second indication information; the second indication information is used to indicate the transmission method and / or security policy of the UP data of the second terminal; wherein the first indication information and the second indication information are used by the access network device to determine the security protection of the UP data of the first terminal and the second terminal.

[0049] In combination with some embodiments of the second aspect, in some embodiments, the method further includes: receiving first information sent by the first terminal; and / or receiving second information sent by the second terminal.

[0050] In combination with some embodiments of the second aspect, in some embodiments, the access network device includes a satellite base station; and / or the core network device includes an AMF or an SMF or a PCF.

[0051] In a third aspect, an embodiment of the present disclosure proposes an access network device, comprising: a first transceiver module, configured to determine the security protection of UP data of a first terminal and a second terminal based on first indication information and second indication information; wherein the first indication information is used to indicate the transmission mode and / or security policy of the UP data of the first terminal, and the second indication information is used to indicate the transmission mode and / or security policy of the UP data of the second terminal.

[0052] In the fourth aspect, an embodiment of the present disclosure proposes a core network device, including: a second transceiver module, configured to send first information to an access network device, the first information including first indication information; the first indication information is used to indicate the transmission method and / or security policy of the UP data of the first terminal; the second transceiver module is also configured to send second information to the access network device, the second information including second indication information; the second indication information is used to indicate the transmission method and / or security policy of the UP data of the second terminal; wherein the first indication information and the second indication information are used by the access network device to determine the security protection of the UP data of the first terminal and the second terminal.

[0053] In a fifth aspect, an embodiment of the present disclosure proposes a communication device comprising one or more processors; wherein the above-mentioned communication device is used to execute optional implementation methods such as the first aspect, the second aspect, or the first and second aspects.

[0054] In the sixth aspect, a communication system is proposed in an embodiment of the present disclosure, comprising: an access network device and a core network device; wherein the above-mentioned access network device is configured to execute the method described in the optional implementation manner of the first aspect, and the above-mentioned core network device is configured to execute the method described in the optional implementation manner of the second aspect.

[0055] In the seventh aspect, an embodiment of the present disclosure proposes a storage medium, which stores instructions. When the instructions are executed on a communication device, the communication device executes the method described in the first aspect, the second aspect, or the optional implementation of the first and second aspects.

[0056] In an eighth aspect, an embodiment of the present disclosure proposes a program product. When the program product is executed by a communication device, the communication device executes the method described in the first aspect, the second aspect, or the optional implementation of the first and second aspects.

[0057] In a ninth aspect, an embodiment of the present disclosure proposes a computer program, which, when executed on a computer, enables the computer to execute the information processing method as described in the first aspect, the second aspect, or the optional implementation of the first and second aspects.

[0058] In the tenth aspect, an embodiment of the present disclosure proposes a chip or a chip system; the chip or chip system includes a processing circuit configured to execute the method described in accordance with the above-mentioned first aspect, second aspect, or optional implementation of the first and second aspects.

[0059] It is understood that the above-mentioned network device, first device, communication system, storage medium, program product, computer program, chip or chip system are all used to perform the method provided by the embodiment of the present disclosure. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects of the corresponding method and will not be repeated here.

[0060] The present disclosure provides an information processing method, device, communication system, and storage medium. In some embodiments, the terms information processing method and communication method are interchangeable, the terms information processing device and communication device are interchangeable, and the terms information processing system and communication system are interchangeable.

[0061] The embodiments of the present disclosure are not exhaustive and are merely illustrative of some embodiments, and are not intended to be a specific limitation on the scope of protection of the present disclosure. In the absence of contradiction, each step in a certain embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a certain embodiment can also be implemented as an independent embodiment, and the order of the steps in a certain embodiment can be arbitrarily exchanged. In addition, the optional implementation methods in a certain embodiment can be arbitrarily combined; in addition, the embodiments can be arbitrarily combined. For example, some or all steps of different embodiments can be arbitrarily combined, and a certain embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.

[0062] In each embodiment of the present disclosure, unless otherwise specified or provided for, the terms and / or descriptions between the embodiments are consistent and can be used interchangeably. The technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships.

[0063] The terms used in the embodiments of the present disclosure are only for the purpose of describing specific embodiments and are not intended to limit the present disclosure.

[0064] In the embodiments of the present disclosure, unless otherwise specified, elements expressed in the singular, such as "a", "an", "the", "above", "said", "the", "the", etc., may mean "one and only one", or "one or more", "at least one", etc. For example, when using articles such as "a", "an", "the" in English in translation, the noun following the article may be understood as a singular expression or a plural expression.

[0065] In the embodiments of the present disclosure, “plurality” refers to two or more.

[0066] In some embodiments, the terms "at least one," "one or more," "a plurality of," "multiple," etc. may be used interchangeably.

[0067] In some embodiments, descriptions such as "at least one of A and B," "A and / or B," "A in one case, B in another case," or "in response to one case A, in response to another case B" may include the following technical solutions depending on the situation: in some embodiments, A (A is executed independently of B); in some embodiments, B (B is executed independently of A); in some embodiments, execution is selected from A and B (A and B are selectively executed); and in some embodiments, A and B (both A and B are executed). The above is also applicable when there are more branches such as A, B, and C.

[0068] In some embodiments, "A or B" and other descriptions may include the following technical solutions depending on the situation: in some embodiments, A (A is executed independently of B); in some embodiments, B (B is executed independently of A); in some embodiments, execution is selected from A and B (A and B are selectively executed). The above is also applicable when there are more branches such as A, B, C, etc.

[0069] The prefixes such as "first" and "second" in the embodiments of the present disclosure are only used to distinguish different description objects and do not constitute any restriction on the position, order, priority, quantity or content of the description objects. For the statement of the description object, please refer to the description in the context of the claims or embodiments, and no unnecessary restriction should be constituted due to the use of prefixes. For example, if the description object is a "field", the ordinal number before the "field" in the "first field" and the "second field" does not limit the position or order between the "fields". "First" and "second" do not limit whether the "fields" they modify are in the same message, nor do they limit the order of the "first field" and the "second field". For another example, if the description object is a "level", the ordinal number before the "level" in the "first level" and the "second level" does not limit the priority between the "levels". For another example, the number of description objects is not limited by the ordinal number and can be one or more. Taking "first device" as an example, the number of "devices" can be one or more. In addition, the objects modified by different prefixes can be the same or different. For example, if the description object is "device", then the "first device" and the "second device" can be the same device or different devices, and their types can be the same or different; for another example, if the description object is "information", then the "first information" and the "second information" can be the same information or different information, and their contents can be the same or different.

[0070] In some embodiments, “including A,” “comprising A,” “used to indicate A,” and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.

[0071] In some embodiments, terms such as "in response to...", "in response to determining...", "in the case of...", "at the time of...", "when...", "if...", "if...", etc. can be used interchangeably.

[0072] In some embodiments, terms such as "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not less than", and "above" can be replaced with each other, and terms such as "less than", "less than or equal to", "not greater than", "less than", "less than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", and "below" can be replaced with each other.

[0073] In some embodiments, devices, etc. can be interpreted as physical or virtual, and their names are not limited to the names recorded in the embodiments. Terms such as "device", "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", and "subject" can be used interchangeably.

[0074] In some embodiments, "network" can be interpreted as devices included in the network (eg, access network equipment, core network equipment, etc.).

[0075] In some embodiments, the terms "access network device (AN device)", "radio access network device (RAN device)", "base station (BS)", "radio base station" "fixed station", "node", "access point", "transmission point (TP)", "reception point (RP)", "transmission / reception point (TRP)", "panel", "antenna panel", "antenna array", "cell", "macro cell", "small cell", "femto cell", "pico cell", "sector", "cell group", "carrier", "component carrier", "bandwidth part (BWP)" and the like may be used interchangeably.

[0076] In some embodiments, the terms "terminal", "terminal device", "user equipment (UE)", "user terminal", "mobile station (MS)", "mobile terminal (MT)", subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, handset, user agent, mobile client, client, etc. can be used interchangeably.

[0077] In some embodiments, the access network device, the core network device, or the network device can be replaced by a terminal. For example, the various embodiments of the present disclosure can also be applied to a structure in which the communication between the access network device, the core network device, or the network device and the terminal is replaced by communication between multiple terminals (for example, it can also be called device-to-device (D2D), vehicle-to-everything (V2X), etc.). In this case, it can also be set as a structure in which the terminal has all or part of the functions of the access network device. In addition, language such as "uplink" and "downlink" can also be replaced by language corresponding to communication between terminals (for example, "side"). For example, uplink channels, downlink channels, etc. can be replaced by side channels, and uplinks, downlinks, etc. can be replaced by side links.

[0078] In some embodiments, the terminal may be replaced by an access network device, a core network device, or a network device. In this case, the access network device, the core network device, or the network device may have a structure that has all or part of the functions of the terminal.

[0079] In some embodiments, obtaining data, information, etc. may comply with the laws and regulations of the country where the data is obtained.

[0080] In some embodiments, data, information, etc. may be obtained with the user's consent.

[0081] In addition, each element, each row, or each column in the table of the embodiment of the present disclosure can be implemented as an independent embodiment, and the combination of any elements, any rows, and any columns can also be implemented as an independent embodiment.

[0082] FIG1A is a schematic diagram showing the structure of an information processing system 100 according to an embodiment of the present disclosure. As shown in FIG1A , the information processing system 100 may include: a terminal 101 and a network device 102 .

[0083] In some embodiments, the network device 102 may include at least one of an access network device and a core network device.

[0084] In some embodiments, the terminal 101 includes, for example, a mobile phone, a wearable device, an Internet of Things (IOT) device or terminal, a car with communication function, a smart car, a tablet computer (Pad), a computer with wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in a smart grid, a wireless terminal device in transportation safety, a wireless terminal device in a smart city, and at least one of a wireless terminal device in a smart home, but is not limited thereto.

[0085] In some embodiments, the access network device is, for example, a node or device that accesses a terminal to a wireless network. The access network device may include an evolved NodeB (eNB), a next generation evolved NodeB (ng-eNB), a next generation NodeB (gNB), a node B (NB), a home node B (HNB), a home evolved nodeB (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an open base station (Open RAN), a cloud base station (Cloud RAN), a base station in other communication systems, and at least one of an access node in a wireless fidelity (WiFi) system, but is not limited thereto.

[0086] In some embodiments, the technical solution of the present disclosure can be applied to the Open RAN architecture. In this case, the interfaces between or within the access network devices involved in the embodiments of the present disclosure can be transformed into internal interfaces of the Open RAN, and the processes and information interactions between these internal interfaces can be implemented through software or programs.

[0087] In some embodiments, the access network device can be composed of a centralized unit (CU) and a distributed unit (DU), where the CU can also be called a control unit. The CU-DU structure can be used to split the protocol layer of the access network device, with the functions of some protocol layers centrally controlled by the CU, and the functions of the remaining part or all of the protocol layers distributed in the DU, which is centrally controlled by the CU, but is not limited to this.

[0088] In some embodiments, the core network device may be a device including a first device, a second device, etc., or may be a plurality of devices or a device group, each including all or part of the first device and the second device. The first device and the second device may be network elements; the network element may be virtual or physical. The core network may include, for example, at least one of an evolved packet core (EPC), a 5G core network (5GCN), and a next generation core (NGC).

[0089] It can be understood that the information processing system described in the embodiment of the present disclosure is for the purpose of more clearly illustrating the technical solution of the embodiment of the present disclosure, and does not constitute a limitation on the technical solution provided by the embodiment of the present disclosure. Ordinary technicians in this field can know that with the evolution of system architecture and the emergence of new business scenarios, the technical solution provided by the embodiment of the present disclosure is also applicable to similar technical problems.

[0090] The following embodiments of the present disclosure may be applied to the information processing system 100 shown in FIG1A , or a portion thereof, but are not limited thereto. The various entities shown in FIG1A are illustrative only. The information processing system may include all or a portion of the entities shown in FIG1A , or may include other entities other than those shown in FIG1A . The number and configuration of the entities may be arbitrary. The connection relationships between the entities are illustrative only. The entities may be connected or disconnected, and the connection may be in any manner, including direct or indirect, wired or wireless.

[0091] The embodiments of the present disclosure can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G New Radio (NR), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New Radio access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (registered trademark), Public Land Mobile Network (PLMN) networks, Device-to-Device (D2D) systems, Machine-to-Machine (M2M) systems, Internet of Things (IoT) systems, Vehicle-to-Everything (V2X), systems utilizing other communication methods, and next-generation systems based on and extending these methods. Furthermore, multiple systems may be combined (for example, a combination of LTE or LTE-A with 5G).

[0092] In some embodiments, UE-to-satellite-to-UE (UE-SAT-UE) communication refers to communication between UEs under the coverage of one or more server satellites, where user plane (UP) data is exchanged locally without passing through a terrestrial network. This UE-to-satellite-to-UE communication can be terminal-to-satellite-to-terminal communication; for example, it can be communication from a first terminal to a satellite to a second terminal.

[0093] For example, as shown in Figure 1B, a UE-SAT-UE service scenario is provided. The network system depicted in Figure 1B supports UE-SAT-UE communication and may include UE x, UE y, and a base station (e.g., gNB) on satellite (SAT) x. A feeder link exists between the gNB on satellite x and the ground, connecting the gNB on satellite x to the core network. The gNB on satellite x forms satellite cell A, which may be adjacent to a terrestrial cell. The Uu interface connection between the gNB on satellite x and UE x and UE y is a satellite link. User plane data can be transmitted between UE x and UE y via the base station on satellite x. The connection between the gNB on satellite x and the ground can be used for control plane (CP) signaling. Here, two UEs (e.g., UE x and UE y) are in communication, but this communication can involve more than two UEs. The AMF represents the network function (NF) of the 5G core network, but may also include other NFs (e.g., SMF). Here, if the satellite serves more than one cell, the two or more UEs may be in different cells.

[0094] In some embodiments, the security of user plane data on the Uu interface is activated based on a security policy sent from the core network, which is set by the Unified Data Management (UDM) or SMF based on the specific service requested by the UE. The SMF determines the UP security implementation information of the Protocol Data Unit (PDU) session based on the following factors when the PDU session is established: the subscribed security policy is part of the session management subscription information received from the UDM; or, the UP security policy locally configured in the SMF by (single data network name (DNN) or single network slice selection assistance information (S-NSSAI)) is used when the UDM does not provide the UP security policy. Here, the Uu interface is the cellular communication interface between the UE and the base station.

[0095] In some embodiments, the UP security policy indicates whether UP data security protection should be activated on the Uu interface for this PDU session. The UP security policy is used to activate confidentiality and / or integrity security protection for the PDU session. Based on the UP security policy provided by the SMF, if the UP security policy indicates "Required," the gNB uses RRC signaling to activate Uu UP security protection for each Data Radio Bearer (DRB). Alternatively, if the UP security policy indicates "Not Needed," the PDU session establishment proceeds without protection. Alternatively, if the UP security policy indicates "Preferred," the gNB can decide whether to activate Uu UP security protection. However, when the UP security policy indicates "Required" or "Not Needed," the gNB cannot overrule the UP security policy received from the SMF. Optionally, the UP data may include UP service data or UP traffic.

[0096] In some embodiments, for UE-to-UE communications over the 5G network, each UE establishes separate PDU sessions with the core network equipment via potentially independent base stations. The gNB then applies, potentially different, UE-specific UP security policies to the separate PDU sessions.

[0097] For UE-SAT-UE communication, which exchanges UP data locally without passing through the terrestrial network where core network equipment (e.g., SMF) resides, it can be assumed that UE-SAT-UE communication can be established using a single PDU session. If the gNB receives potentially different UP security policies for each UE, how the gNB should apply these UP security policies to a single PDU session to protect user plane traffic becomes a question.

[0098] Assuming that two separate PDU sessions are established for UE-SAT-UE communication, if the communicating UEs have different UP security policies, this may result in different security protection being applied to the two Uu interfaces of a single UE-SAT-UE communication session. In this case, higher security protection (e.g., integrity and confidentiality protection) on one Uu interface may be downgraded by lower security protection (e.g., integrity protection only, confidentiality protection only, or no protection) on the other Uu interface.

[0099] Therefore, for UE-SAT-UE communication, how the gNB should handle the UP security policy of the communicating UE and how Uu UP security should be activated between the transmitting UE and the gNB on the satellite and the receiving UE need to be studied.

[0100] FIG2 is an interactive diagram of an information processing method according to an embodiment of the present disclosure. As shown in FIG2 , the present disclosure embodiment relates to an information processing method for an information processing system 100, and the method includes:

[0101] Step S2101: The core network device sends first information to the access network device.

[0102] In some embodiments, the access network device receives first information sent by the core network device.

[0103] Optionally, the access network device may be a base station; for example, a satellite base station.

[0104] Optionally, the core network device can be AMF, SMF, PCF, etc.

[0105] In some embodiments, the first information includes first indication information.

[0106] Optionally, the first information may include information related to the UP security policy. Exemplarily, the first information may include at least one of the following: session management information, a first identifier of the first terminal, a service identifier of UE-SAT-UE communication, a data network name used for UE-SAT-UE communication, and auxiliary information for selecting a network slice used for UE-SAT-UE communication.

[0107] Optionally, the first identifier may be any number or string used to indicate the first terminal. Optionally, the first identifier may be a user information identifier (User Info), a subscription concealed identifier (SUCI), a user permanent identifier (SUPI), or a globally unique temporary UE identity (GUTI) of the first terminal.

[0108] Optionally, UE-SAT-UE communication may be configured with one or more services, and service traffic or service data of these services may be transmitted based on UE-SAT-UE communication.

[0109] Alternatively, UE-SAT-UE communication may refer to local communication or satellite-based local communication.

[0110] Optionally, the name of the first information may not be limited, and it may be, for example, security policy information or UP security policy information or UP security policy or Uu UP security policy, etc.

[0111] In some embodiments, the first indication information is used to indicate a transmission mode and / or security policy of UP data of the first terminal. Optionally, UP data can be replaced by UP traffic, UP service, UP service data, or UP service traffic.

[0112] Optionally, the first indication information is used to indicate a security policy of UP data of the first terminal in a UE-SAT-UE communication situation.

[0113] Optionally, the transmission mode may include UE-SAT-UE communication or non-UE-SAT-UE communication. The non-UE-SAT-UE communication may refer to communication other than UE-SAT-UE communication.

[0114] Optionally, the security policy may be the UP security policy in the previous embodiment.

[0115] Optionally, the security policy may include a first-class security policy and / or a second-class security policy. For example, the first-class security policy may include requiring protection or not requiring protection. For example, the second-class security policy may include preferred protection; the preferred protection indicates the security protection or security policy selected by the preferred access network device.

[0116] Optionally, the security policy may include requiring protection, not requiring protection, and / or prioritizing protection.

[0117] Optionally, the required protection may be “required” in the previous embodiment; the unrequired protection may be “unrequired” in the previous embodiment; and the preferred protection may be “preferred” in the previous embodiment.

[0118] Optionally, requiring protection may include requiring integrity protection and / or confidentiality protection.

[0119] Alternatively, not requiring protection may include not requiring security protection and / or not requiring confidentiality protection.

[0120] Optionally, the preferred protection may include prioritizing security protection and / or confidentiality protection selected by the access network device.

[0121] Optionally, the first indication information may include one or more bits, or one or more fields. For example, one or more bits of the first indication information may be used to indicate whether integrity protection and / or confidentiality protection is required, whether security protection and / or confidentiality protection is not required, and whether security, protection and / or confidentiality protection selected by the access network device is preferred. For another example, different fields in the first indication information may be used to indicate whether protection is required, whether protection is not required, and priority protection; for example, when the first field of the first indication information is the first value, it indicates that integrity protection is required, or when the first field of the first indication information is the second value, it indicates that confidentiality protection is required, or when the first field of the first indication information is the third value, it indicates that both integrity protection and confidentiality protection are required; for another example, when the second field of the first indication information is the first value, it indicates that integrity protection is not required, or when the second field of the first indication information is the second value, it indicates that confidentiality protection is not required, or when the second field of the first indication information is the third value, it indicates that both integrity protection and confidentiality protection are not required.

[0122] Optionally, the name of the first indication information may not be limited, and it may be, for example, UE-SAT-UE communication indication or security policy indication.

[0123] In some optional embodiments, the first information is sent by the core network device after receiving a PDU session request sent by the first terminal. Optionally, the PDU session request is used to request establishment of a PDU session. Optionally, the PDU session request may include identification information indicating the second terminal as a target terminal. Here, the first terminal may be the first UE or UE1, or UE x in the previous embodiment.

[0124] Step S2102: The core network device sends second information to the access network device.

[0125] In some embodiments, the access network device receives the second information sent by the core network device.

[0126] In some embodiments, the second information includes second indication information.

[0127] Optionally, the second information may include information related to the UP security policy. Exemplarily, the second information may include at least one of the following: session management information, a second identifier of the second terminal, a service identifier of UE-SAT-UE communication, a data network name used for UE-SAT-UE communication, and auxiliary information for selecting a network slice used for UE-SAT-UE communication.

[0128] Optionally, the second identifier may be any number or character string used to indicate the second terminal. Optionally, the second identifier may be a user information identifier (User Info), SUCI, SUPI or GUTI of the first terminal.

[0129] Optionally, the name of the second information may not be limited, and it may be, for example, security policy information or UP security policy information or UP security policy or Uu UP security policy, etc.

[0130] In some embodiments, the second indication information is used to indicate a transmission mode and / or security policy of UP data of the second terminal.

[0131] Optionally, the second indication information is used to indicate a security policy of UP data of the second terminal in a UE-SAT-UE communication situation.

[0132] Optionally, the second indication information may include one or more bits, or one or more fields. For example, one or more bits of the second indication information may be used to indicate whether integrity protection and / or confidentiality protection is required, whether security protection and / or confidentiality protection is not required, and whether security protection and / or confidentiality protection selected by the access network device is preferred. For another example, different fields in the second indication information may be used to indicate whether protection is required, whether protection is not required, and priority protection; for example, when the first field of the second indication information is the first value, it indicates that integrity protection is required, or when the first field of the second indication information is the second value, it indicates that confidentiality protection is required, or when the first field of the second indication information is the third value, it indicates that both integrity protection and confidentiality protection are required; for another example, when the second field of the second indication information is the first value, it indicates that integrity protection is not required, or when the second field of the second indication information is the second value, it indicates that confidentiality protection is not required, or when the second field of the second indication information is the third value, it indicates that both integrity protection and confidentiality protection are not required.

[0133] Optionally, the name of the second indication information may not be limited, and may be, for example, UE-SAT-UE communication indication or security policy indication.

[0134] In some optional embodiments, the second information is sent by the core network device after receiving a PDU session request sent by the second terminal. Optionally, the PDU session request is used to request establishment of a PDU session. Here, the second terminal can be a second UE or UE2 or UE y in the previous embodiment.

[0135] Step S2103: The access network device determines security protection of UP data of the first terminal and the second terminal.

[0136] Optionally, the access network device determines security protection of UP data in a first terminal to satellite to second terminal (UE-SAT-UE) communication situation.

[0137] In some embodiments, determining the security protection of the UP data of the first terminal and the second terminal includes at least one of the following: determining whether the first terminal supports the UE-SAT-UE transmission mode, determining whether to enable the judgment or decision of the consistency security protection of the UP data of the first terminal and the second terminal, and determining whether the UP data of the first terminal and the second terminal need to be securely protected; determining whether the UP data of the first terminal and the second terminal are consistently securely protected; and determining a security policy for security protection of the UP data of the first terminal and / or the second terminal.

[0138] In some embodiments, when the transmission mode of the UP data indicated by the first indication information and the second indication information is UE-SAT-UE local transmission or UE-SAT-UE communication, the access network device determines whether to enable consistent security protection for the UP data of the first terminal and the second terminal. Here, the determination of enabling consistent security protection can be: determining whether consistent security protection is performed on the UP data of the first terminal and the second terminal.

[0139] Optionally, whether to perform consistency security protection refers to whether to use the same security policy.

[0140] In some embodiments, when the security policies of the UP data indicated by the first indication information and the second indication information are the same and are first-type security policies, the access network device determines that the UP data of the first terminal and the second terminal are to be subjected to consistent security protection.

[0141] Optionally, when the security policies of the UP data indicated by the first indication information and the second indication information both require protection, the access network device determines that the UP data of the first terminal and the second terminal are subjected to consistent security protection; and can also determine that the security policies of the UP data of the first terminal and the second terminal both require protection.

[0142] Exemplarily, when the security policies of the UP data indicated by the first indication information and the second indication information both require integrity protection, it is determined that the UP data of the first terminal and the second terminal are subjected to consistent security protection; and it can also be determined that the security policies of the UP data of the first terminal and the second terminal both require integrity protection.

[0143] Exemplarily, when the security policies of the UP data indicated by the first indication information and the second indication information both require confidentiality protection, it is determined that the UP data of the first terminal and the second terminal are subjected to consistent security protection; and it can also be determined that the security policies of the UP data of the first terminal and the second terminal both require confidentiality protection.

[0144] Exemplarily, when the security policies of the UP data indicated by the first indication information and the second indication information both require integrity protection and confidentiality protection, it is determined that the UP data of the first terminal and the second terminal are subjected to consistent security protection; and it can also be determined that the security policies of the UP data of the first terminal and the second terminal both require integrity protection and confidentiality protection.

[0145] Optionally, when the security policies of the UP data indicated by the first indication information and the second indication information both do not require protection, the access network device determines that the UP data of the first terminal and the second terminal are subjected to consistent security protection; and can also determine that the security policies of the UP data of the first terminal and the second terminal both do not require protection.

[0146] Exemplarily, when the security policies of the UP data indicated by the first indication information and the second indication information do not require integrity protection, it is determined that the UP data of the first terminal and the second terminal are subjected to consistent security protection; and it can also be determined that the security policies of the UP data of the first terminal and the second terminal do not require integrity protection.

[0147] Exemplarily, when the security policies of the UP data indicated by the first indication information and the second indication information both do not require confidentiality protection, it is determined that the UP data of the first terminal and the second terminal are subjected to consistent security protection; and it can also be determined that the security policies of the UP data of the first terminal and the second terminal both do not require confidentiality protection.

[0148] Exemplarily, when the security policies of the UP data indicated by the first indication information and the second indication information both do not require integrity protection and do not require confidentiality protection, it is determined that the UP data of the first terminal and the second terminal are subjected to consistent security protection; and it can also be determined that the security policies of the UP data of the first terminal and the second terminal both do not require integrity protection and do not require confidentiality protection.

[0149] Exemplarily, when the security policies of the UP data indicated by the first indication information and the second indication information both do not require integrity protection but require confidentiality protection, it is determined that the UP data of the first terminal and the second terminal are subjected to consistent security protection; and it can also be determined that the security policies of the UP data of the first terminal and the second terminal both do not require integrity protection but require confidentiality protection.

[0150] Exemplarily, when the security policies of the UP data indicated by the first indication information and the second indication information both require integrity protection and do not require confidentiality protection, it is determined that the UP data of the first terminal and the second terminal are subjected to consistent security protection; and it can also be determined that the security policies of the UP data of the first terminal and the second terminal both require integrity protection and do not require confidentiality protection.

[0151] In some embodiments, when the security policies of the UP data indicated by the first indication information and the second indication information are the same and are second-type security policies, the access network device determines how to perform consistent security protection on the UP data based on the access network device.

[0152] Optionally, when the security policies of the UP data indicated by the first indication information and the second indication information are both preferred protection, the access network device determines how to perform consistent security protection on the UP data based on the access network device. Here, determining how to perform consistent security protection on the UP data may be determining whether to perform consistent security protection.

[0153] Exemplarily, if the security policies for UP data indicated by both the first indication information and the second indication information are preferred protection, the access network device independently determines the security policy for the UP data. In this case, the access network device may determine whether to perform consistency protection on the UP data or not. For example, the access network device may determine that both the UP data of the first terminal and the second terminal require protection, or that neither the UP data of the first terminal nor the second terminal requires protection. Alternatively, the access network device may determine that either the UP data of the first terminal or the second terminal requires protection.

[0154] In some embodiments, when the security policies of the UP data indicated by the first indication information and the second indication information are different, the access network device determines whether the UP data of the first terminal and the second terminal are consistent with each other according to the categories of the security policies indicated by the first indication information and the second indication information respectively.

[0155] Optionally, when one of the first indication information and the second indication information indicates a first type of security policy and the other indicates a second type of security policy, the access network determines that the UP data of the first terminal and the second terminal are subjected to consistency protection of the first type of security policy; wherein the first type of security policy includes whether protection is required or not required, and the second type of security policy includes preferred protection.

[0156] Exemplarily, when the first indication information indicates that protection is required and the second indication information indicates preferred protection, it is determined that the UP data of the first terminal and the second terminal are consistently protected; and it can also be determined that the security policies of the UP data of the first terminal and the second terminal both require protection.

[0157] Exemplarily, when the first indication information indicates that no protection is required and the second indication information indicates preferred protection, it is determined that the UP data of the first terminal and the second terminal are subjected to consistent security protection; and it can also be determined that the security policies of the UP data of the first terminal and the second terminal are both that no protection is required.

[0158] Exemplarily, when the first indication information indicates preferred protection and the second indication information indicates required protection, it is determined that the UP data of the first terminal and the second terminal are consistently protected; and it can also be determined that the security policies of the UP data of the first terminal and the second terminal both require protection.

[0159] Exemplarily, when the first indication information indicates preferred protection and the second indication information indicates that no protection is required, it is determined that the UP data of the first terminal and the second terminal are consistently protected; and it can also be determined that the security policies of the UP data of the first terminal and the second terminal are both that no protection is required.

[0160] Exemplarily, when both the first indication information and the second indication information indicate preferred protection, it is determined that the UP data of the first terminal and the second terminal are consistently protected; and it can also be determined that the security policies of the UP data of the first terminal and the second terminal both do not require protection or both require protection.

[0161] In some embodiments, when both the first indication information and the second indication information indicate a first type of security policy, and the first indication information and the second indication information indicate different security policies, the access network device determines that consistency protection cannot be performed on the UP data of the first terminal and the second terminal. Optionally, consistency protection cannot be performed, that is, consistency protection is not performed.

[0162] Optionally, when the first indication information indicates that protection is required and the second indication information indicates that protection is not required, the access network device determines that the UP data of the first terminal and the second terminal cannot be consistently and securely protected.

[0163] Optionally, when the first indication information indicates that protection is not required and the second indication information indicates that protection is required, the access network device determines that the UP data of the first terminal and the second terminal cannot be consistently and securely protected.

[0164] In some embodiments, the access network device refuses to establish a session with the first terminal and the second terminal when determining that consistency protection cannot be performed between the first terminal and the second terminal.

[0165] Optionally, the session is a PDU session or any other UP service-related session.

[0166] In some embodiments, when the access network device determines that the first terminal and the second terminal cannot be consistently protected, the access network device performs security protection on the UP data of the first terminal based on the security policy indicated by the first indication information, and / or performs security protection on the UP data of the second terminal based on the security policy indicated by the second indication information.

[0167] Exemplarily, when the first indication information indicates that protection is required and the second indication information indicates that protection is not required, it is determined that the UP data of the first terminal and the second terminal cannot be consistently securely protected; and it is determined that the UP data of the first terminal requires security protection and that the UP data of the second terminal does not require security protection.

[0168] Exemplarily, when the first indication information indicates that no protection is required and the second indication information indicates that protection is required, it is determined that the UP data of the first terminal and the second terminal cannot be consistently securely protected; and it is determined that the UP data of the first terminal does not require security protection and that the UP data of the second terminal requires security protection.

[0169] In some optional embodiments, the access network device activates security protection of the UP data of the first terminal and / or the second terminal based on a security policy for the UP data of the first terminal and the second terminal.

[0170] Exemplarily, if the UP data of the first terminal and the second terminal both need to be protected, the UP data of the first terminal and the second terminal are activated or determined to be security protected.

[0171] Exemplarily, if the UP data of the first terminal and the second terminal do not need to be protected, it is activated or determined that the UP data of the first terminal and the second terminal do not need security protection.

[0172] Exemplarily, if the UP data of the first terminal requires protection and the UP data of the second terminal does not require protection, the UP data of the first terminal is activated or determined to be security protected and the UP data of the second terminal is not security protected.

[0173] Exemplarily, if the UP data of the first terminal does not require protection and the UP data of the second terminal requires protection, it is activated or determined that the UP data of the first terminal does not require security protection and the UP data of the second terminal requires security protection.

[0174] In the above embodiments, requiring protection includes requiring confidentiality protection and / or requiring integrity protection; not requiring protection includes not requiring confidentiality protection and / or not requiring integrity protection.

[0175] Step S2104: The access network device sends third information to the first terminal and / or the second terminal.

[0176] In some embodiments, the first terminal and / or the second terminal receives third information sent by the access network device.

[0177] In some embodiments, the third information is used to indicate security protection of UP data of the first terminal and / or the second terminal determined by the access network device; the third information is used for the first terminal and / or the second terminal to perform security protection of UP data.

[0178] Optionally, the security protection of the UP data of the first terminal and / or the second terminal determined by the access network device may include: the access network device independently determining the security protection of the UP data of the first terminal and / or the second terminal; or the access network device determining the security protection of the UP data of the first terminal and / or the second terminal based on the first indication information and the second indication information. Here, security protection may refer to a security policy; the security protection may include whether protection is required or not required, etc.

[0179] Optionally, the third information may also include at least one of the following: the first identifier, the second identifier, the service identifier of UE-SAT-UE communication, the data network name used for UE-SAT-UE communication, and the network slice selection auxiliary information used for UE-SAT-UE communication, etc.

[0180] Optionally, the name of the third information is not limited, and it can be, for example, security policy information, UP security policy information, or security policy indication information.

[0181] In the above embodiments, requiring protection includes requiring confidentiality protection and / or requiring integrity protection; not requiring protection includes not requiring confidentiality protection and / or not requiring integrity protection.

[0182] In some optional embodiments, the first terminal performs security protection of the UP data based on the third information.

[0183] In some optional embodiments, the second terminal performs security protection of the UP data based on the third information.

[0184] In some optional embodiments, the access network device may also send the third information to the core network device.

[0185] In some embodiments, the names of information, etc. are not limited to the names described in the embodiments, and terms such as "information", "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "domain", "field", "symbol", "symbol", "codeword", "codebook", "codeword", "codepoint", "bit", "data", "program", and "chip" can be used interchangeably.

[0186] In some embodiments, "obtain", "get", "get", "receive", "transmit", "bidirectional transmission", "send and / or receive" can be interchangeable, and can be interpreted as receiving from other entities, obtaining from protocols, obtaining from higher layers, obtaining by self-processing, autonomous implementation, etc.

[0187] In some embodiments, terms such as "send", "transmit", "report", "download", "transmit", "bidirectional transmission", "send and / or receive" can be used interchangeably.

[0188] In some embodiments, terms such as "certain", "preset", "preset", "setting", "indicated", "some", "any", and "first" can be interchangeable. "Specific A", "preset A", "preset A", "setting A", "indicated A", "some A", "any A", and "first A" can be interpreted as A pre-specified in a protocol, etc., or as A obtained through setting, configuration, or indication, etc., or as specific A, some A, any A, or first A, etc., but not limited to this.

[0189] In some embodiments, the determination or judgment can be performed by a value represented by 1 bit (0 or 1), or by a true or false value (Boolean value) represented by true or false, or by comparison of numerical values ​​(for example, comparison with a predetermined value), but is not limited thereto.

[0190] The information processing method involved in the embodiments of the present disclosure may include at least one of steps S2101 to S2104. For example, step S2101 can be implemented as an independent embodiment; step S2102 can be implemented as an independent embodiment; step S2103 can be implemented as an independent embodiment; step S2104 can be implemented as an independent embodiment; the combination of step S2101 and step S2102 can be implemented as an independent embodiment; the combination of step S2101 and step S2103 can be implemented as an independent embodiment; the combination of step S2102 and step S2103 can be implemented as an independent embodiment; the combination of step S2101, step S2102, and step S2103 can be implemented as an independent embodiment; the combination of step S2103 and step S2104 can be implemented as an independent embodiment; the combination of steps S2101 to S2104 can be implemented as an independent embodiment.

[0191] In some embodiments, step S2101, step S2102, and step S2104 may be optional, and one or more of these steps may be omitted or replaced in different embodiments.

[0192] In some embodiments, step S2101 and step S2102 may be optional, and one or more of these steps may be omitted or replaced in different embodiments.

[0193] In some embodiments, step S2104 may be optional, and one or more of these steps may be omitted or replaced in different embodiments.

[0194] In the embodiments of the present disclosure, each embodiment can be implemented individually or in combination with each other, and the steps in each embodiment can be distinguished in order.

[0195] FIG3A is a flow chart of an information processing method according to an embodiment of the present disclosure. As shown in FIG3A , the present disclosure embodiment relates to an information processing method, which is executed by an access network device. The method includes:

[0196] Step S3101, obtain first information.

[0197] The optional implementation of step S3101 can refer to the optional implementation of step S2101 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.

[0198] In some embodiments, the access network device receives the first information sent by the core network device, but is not limited thereto and may also receive the first information sent by other entities.

[0199] In some embodiments, the access network device obtains first information specified by the protocol.

[0200] In some embodiments, the access network device obtains the first information from an upper layer(s).

[0201] In some embodiments, the access network device performs processing to obtain the first information.

[0202] In some embodiments, step S3101 is omitted, and the access network device autonomously implements the function indicated by the first information, or the above function is default or by default.

[0203] Step S3102, obtaining second information.

[0204] The optional implementation of step S3102 can refer to the optional implementation of step S2102 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.

[0205] In some embodiments, the access network device receives the second information sent by the core network device, but is not limited thereto and may also receive the second information sent by other entities.

[0206] In some embodiments, the access network device obtains the second information specified by the protocol.

[0207] In some embodiments, the access network device obtains the second information from an upper layer(s).

[0208] In some embodiments, the access network device performs processing to obtain the second information.

[0209] In some embodiments, step S3102 is omitted, and the access network device autonomously implements the function indicated by the second information, or the above function is default or by default.

[0210] Step S3103: Determine security protection of UP data of the first terminal and the second terminal.

[0211] The optional implementation of step S3103 can refer to the optional implementation of step S2103 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.

[0212] Step S3104, sending the third information.

[0213] The optional implementation of step S3104 can refer to the optional implementation of step S2104 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.

[0214] In some embodiments, the access network device sends the third information to the first device, but is not limited thereto and may also send the third information to other entities.

[0215] The information processing method involved in the embodiments of the present disclosure may include at least one of steps S3101 to S3104. For example, step S3101 can be implemented as an independent embodiment; step S3102 can be implemented as an independent embodiment; step S3103 can be implemented as an independent embodiment; step S3104 can be implemented as an independent embodiment; the combination of step S3101 and step S3102 can be implemented as an independent embodiment; the combination of step S3101 and step S3103 can be implemented as an independent embodiment; the combination of step S3102 and step S3103 can be implemented as an independent embodiment; the combination of step S3101, step S3102, and step S3103 can be implemented as an independent embodiment; the combination of step S3103 and step S3104 can be implemented as an independent embodiment; the combination of steps S3101 to S3104 can be implemented as an independent embodiment.

[0216] In some embodiments, step S3101, step S3102, and step S3104 may be optional, and one or more of these steps may be omitted or replaced in different embodiments.

[0217] In some embodiments, step S3101 and step S3102 may be optional, and one or more of these steps may be omitted or replaced in different embodiments.

[0218] In some embodiments, step S3104 may be optional, and one or more of these steps may be omitted or replaced in different embodiments.

[0219] In the embodiments of the present disclosure, each embodiment can be implemented individually or in combination with each other, and the steps in each embodiment can be distinguished in order.

[0220] FIG3B is a flow chart of an information processing method according to an embodiment of the present disclosure. As shown in FIG3B , the present disclosure embodiment relates to an information processing method, which is executed by an access network device. The method includes:

[0221] Step S3201: Determine security protection of UP data of the first terminal and the second terminal based on the first indication information and the second indication information.

[0222] The optional implementation of step S3201 can be found in step S2103 in FIG. 2 , or the optional implementation of step S3103 in FIG. 3A , and other related parts in the embodiments involved in FIG. 2 and FIG. 3A , which will not be described in detail here.

[0223] In some embodiments, the first indication information is used to indicate the transmission mode and / or security policy of the UP data of the first terminal, and the second indication information is used to indicate the transmission mode and / or security policy of the UP data of the second terminal.

[0224] In some embodiments, determining security protection of UP data of the first terminal and the second terminal includes at least one of the following: determining whether the UP data of the first terminal and the second terminal need to be security protected; determining whether the UP data of the first terminal and the second terminal are consistently security protected; and determining a security policy for security protection of the UP data of the first terminal and / or the second terminal.

[0225] In some embodiments, the method further includes: receiving first information sent by the core network device, wherein the first information includes first indication information; and receiving second information sent by the core network device, wherein the second information includes second indication information.

[0226] In some embodiments, based on the first indication information and the second indication information, determining the security protection of the user plane UP data of the first terminal and the second terminal includes one of the following: when the transmission mode of the UP data indicated by the first indication information and the second indication information is both UE-SAT-UE local transmission, determining to enable consistency security protection for the UP data of the first terminal and the second terminal; when the security policies of the UP data indicated by the first indication information and the second indication information are the same and are first-type security policies, determining to perform consistency security protection on the UP data of the first terminal and the second terminal; when the security policies of the UP data indicated by the first indication information and the second indication information are the same and are second-type security policies, determining how to perform consistency security protection on the UP data based on the access network device; and when the security policies of the UP data indicated by the first indication information and the second indication information are different, determining whether to perform consistency protection on the UP data of the first terminal and the second terminal according to the categories of the security policies respectively indicated by the first indication information and the second indication information.

[0227] In some embodiments, the first type of security policy includes whether protection is required or not required; and / or the second type of security policy includes preferred protection; wherein the preferred protection indicates the security protection selected by the preferred access network device.

[0228] In some embodiments, determining whether the UP data of the first terminal and the second terminal are protected for consistency is performed based on the categories of security policies indicated by the first indication information and the second indication information respectively, including at least one of the following: when one of the first indication information and the second indication information indicates a first type of security policy and the other indicates a second type of security policy, determining that the UP data of the first terminal and the second terminal are protected for consistency with the first type of security policy; wherein the first type of security policy includes whether protection is required or not, and the second type of security policy includes preferred protection; and when both the first indication information and the second indication information indicate the first type of security policy, and the security policies indicated by the first indication information and the second indication information are different, determining that the UP data of the first terminal and the second terminal cannot be protected for consistency.

[0229] In some embodiments, the method also includes: refusing to establish a session with the first terminal and the second terminal when it is determined that the first terminal and the second terminal cannot be consistently protected; or, when it is determined that the first terminal and the second terminal cannot be consistently protected, performing security protection on the UP data of the first terminal based on the security policy indicated by the first indication information, and / or, performing security protection on the UP data of the second terminal based on the security policy indicated by the second indication information.

[0230] In some embodiments, the method further includes: activating security protection of the UP data of the first terminal and / or the second terminal based on the security protection of the UP data of the first terminal and the second terminal.

[0231] In some embodiments, the method also includes: sending third information to the first terminal and / or the second terminal, wherein the third information is used to indicate the security protection of UP data of the first terminal and / or the second terminal determined by the access network device; the third information is used for the first terminal and / or the second terminal to perform security protection of UP data.

[0232] In some embodiments, the access network device includes a satellite base station; and / or, the core network device includes an AMF or an SMF or a PCF.

[0233] The above embodiments may be implemented individually or in combination with each other. For optional implementations, please refer to the optional implementations of the steps in FIG. 2 and FIG. 3A , which will not be described in detail here.

[0234] FIG3C is a flow chart of an information processing method according to an embodiment of the present disclosure. As shown in FIG3C , the present disclosure embodiment relates to an information processing method, which is executed by an access network device. The method includes:

[0235] Step S3301, receiving first information.

[0236] The optional implementation of step S3301 can be found in step S2101 in FIG. 2 , or the optional implementation of step S3101 in FIG. 3A , and other related parts in the embodiments involved in FIG. 2 and FIG. 3A , which will not be described in detail here.

[0237] Step S3302, receiving the second information.

[0238] The optional implementation of step S3302 can be found in step S2102 in FIG. 2 , or the optional implementation of step S3102 in FIG. 3A , and other related parts in the embodiments involved in FIG. 2 and FIG. 3A , which will not be described in detail here.

[0239] Step S3303: Determine security protection of UP data of the first terminal and the second terminal based on the first information and the second information.

[0240] Optionally, the first information includes first indication information; the second information includes second indication information.

[0241] The optional implementation of step S3303 can be found in step S2103 in FIG. 2 , or the optional implementation of step S3103 in FIG. 3A , and other related parts in the embodiments involved in FIG. 2 and FIG. 3A , which will not be described in detail here.

[0242] The above embodiments may be implemented individually or in combination with each other. For optional implementations, please refer to the optional implementations of the steps in FIG. 2 and FIG. 3A , which will not be described in detail here.

[0243] FIG3D is a flow chart of an information processing method according to an embodiment of the present disclosure. As shown in FIG3D , the present disclosure embodiment relates to an information processing method, which is executed by an access network device. The method includes:

[0244] Step S3401: Determine security protection of UP data of the first terminal and the second terminal.

[0245] The optional implementation of step S3401 can be found in step S2103 in FIG. 2 , or the optional implementation of step S3103 in FIG. 3A , and other related parts in the embodiments involved in FIG. 2 and FIG. 3A , which will not be described in detail here.

[0246] Step S3402: Send third information to the first terminal and / or the second terminal.

[0247] Optionally, the third information is used to indicate security protection of UP data of the first terminal and / or the second terminal determined by the access network device.

[0248] The optional implementation of step S3402 can be found in step S2104 in FIG. 2 , or the optional implementation of step S3104 in FIG. 3A , and other related parts in the embodiments involved in FIG. 2 and FIG. 3A , which will not be described in detail here.

[0249] The above embodiments may be implemented individually or in combination with each other. For optional implementations, please refer to the optional implementations of the steps in FIG. 2 and FIG. 3A , which will not be described in detail here.

[0250] FIG4A is a flow chart of an information processing method according to an embodiment of the present disclosure. As shown in FIG4A , the present disclosure embodiment relates to an information processing method, which is executed by a core network device. The method includes:

[0251] Step S4101, sending the first information.

[0252] The optional implementation of step S4101 can refer to the optional implementation of step S2101 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.

[0253] In some embodiments, the core network device sends the first information to the access network device, but is not limited thereto, and the first information may also be sent to other entities.

[0254] Step S4102, sending the second information.

[0255] The optional implementation of step S4102 can refer to the optional implementation of step S2102 in Figure 2 and other related parts in the embodiment involved in Figure 2, which will not be repeated here.

[0256] In some embodiments, the core network device sends the second information to the access network device, but is not limited thereto, and the second information may also be sent to other entities.

[0257] In some optional embodiments, before step S4101, the core network device obtains the first information.

[0258] In some embodiments, the core network device receives the first information sent by the first terminal, but is not limited thereto and may also receive the first information sent by other entities.

[0259] In some embodiments, the core network device obtains the first information specified by the protocol.

[0260] In some embodiments, the core network device obtains the first information from an upper layer(s).

[0261] In some embodiments, the core network device performs processing to obtain the first information.

[0262] In some optional embodiments, before step S4102, the core network device obtains the second information.

[0263] In some embodiments, the core network device receives the second information sent by the second terminal, but is not limited thereto and may also receive the second information sent by other entities.

[0264] In some embodiments, the core network device obtains the second information specified by the protocol.

[0265] In some embodiments, the core network device obtains the second information from an upper layer(s).

[0266] In some embodiments, the core network device performs processing to obtain the second information.

[0267] In some optional embodiments, after step S4102, the core network device may also obtain the third information.

[0268] In some embodiments, the core network device receives the third information sent by the access network device, but is not limited thereto and may also receive the third information sent by other entities.

[0269] In some embodiments, the core network device obtains the third information specified by the protocol.

[0270] In some embodiments, the core network device obtains the third information from upper layer(s).

[0271] In some embodiments, the core network device performs processing to obtain the third information.

[0272] In some embodiments, the first device sends the measurement result to the network device, but is not limited thereto and may also send the measurement result to other entities.

[0273] The information processing method involved in the embodiments of the present disclosure may include at least one of steps S4101 and S4102. For example, step S4101 may be implemented as an independent embodiment, and step S4102 may be implemented as an independent embodiment; steps S4101 and S4102 may be implemented as independent embodiments.

[0274] In some embodiments, step S4101 may be optional, and one or more of these steps may be omitted or replaced in different embodiments.

[0275] In some embodiments, step S4102 may be optional, and one or more of these steps may be omitted or replaced in different embodiments.

[0276] In the embodiments of the present disclosure, each embodiment can be implemented individually or in combination with each other, and the steps in each embodiment can be distinguished in order.

[0277] FIG4B is a flow chart of an information processing method according to an embodiment of the present disclosure. As shown in FIG4B , the present disclosure embodiment relates to an information processing method, which is executed by a core network device. The method includes:

[0278] Step S4201: Send first information and second information to an access network device.

[0279] Optionally, the first information and the second information may be sent separately or together.

[0280] The optional implementation of step S4201 can be found in step S2101 in FIG. 2 , or the optional implementation of step S4101 in FIG. 4A , and other related parts in the embodiments involved in FIG. 2 and FIG. 4A , which will not be described in detail here.

[0281] In some embodiments, the first indication information is used to indicate the transmission mode and / or security policy of the UP data of the first terminal; the second information includes the second indication information; the second indication information is used to indicate the transmission mode and / or security policy of the UP data of the second terminal; wherein the first indication information and the second indication information are used by the access network device to determine the security protection of the UP data of the first terminal and the second terminal.

[0282] In some embodiments, the method further includes: receiving first information sent by the first terminal; and / or receiving second information sent by the second terminal.

[0283] In some embodiments, the access network device includes a satellite base station; and / or, the core network device includes an AMF or an SMF or a PCF.

[0284] The above embodiments may be implemented individually or in combination with each other. For optional implementations, please refer to the optional implementations of the steps in FIG. 2 and FIG. 4A , which will not be described in detail here.

[0285] FIG5 is a flow chart of an information processing method according to an embodiment of the present disclosure. As shown in FIG5 , the embodiment of the present disclosure relates to an information processing method, which includes:

[0286] Optionally, the above method may include Case 1 or Case 2; Case 1 represents a hypothetical procedure that reuses existing mechanisms; Case 2 represents an enhanced degree of consistency protection for the entire UP data. Case 1 may include steps S5101 to S5103; step S5101 may include step S5101A and / or step S5101B; and step S5102 may include step S5102A and / or step S5102B. Case 2 may include steps S5104 to S5108.

[0287] CASE1:

[0288] Step S5101A, the PDU session of UE1 is established.

[0289] Optionally, UE1 sends a PDU session establishment process to the core network device. During this process, the core network device sends UE1's UP security policy to a base station (e.g., a gNB). The base station is a base station on a satellite, such as a satellite base station.

[0290] Optionally, UE1 may be the first terminal in the previous embodiment. The core network device may be the AMF or SMF in the previous embodiment; the AMF of UE1 may be AMF1; and the SMF of UE1 may be SMF1.

[0291] Step S5101B: The base station activates Uu UP security protection.

[0292] Optionally, the base station activates Uu UP security protection according to the received security policy of UE1. The Uu UP security protection may be security protection of UP data of a Uu interface; the Uu interface is a communication interface between UE1 and the base station.

[0293] Step S5102A, the PDU session of UE2 is established.

[0294] Optionally, when UE1 requests communication triggered by the network, UE2 sends a PDU session establishment process to the core network device; during this process, the core network device sends the UP security policy of UE2 to the base station.

[0295] Optionally, UE2 may be the second terminal in the previous embodiment. The core network device may be the AMF or SMF in the previous embodiment; the AMF of UE2 may be AMF2; and the SMF of UE2 may be SMF2.

[0296] Step S5102B: The base station activates Uu UP security protection.

[0297] Optionally, the base station activates Uu UP security protection according to the received security policy of UE2. The Uu UP security protection may be security protection of UP data of a Uu interface; the Uu interface is a communication interface between UE2 and the base station.

[0298] Optionally, the UP security policy of UE1 (UE1UP security policy) may be different from the UP security policy of UE2 (UE2UP security policy). Therefore, the Uu UP security protection activated for UE1 may be different from the Uu UP security protection activated for UE2.

[0299] In step S5103 , the UP data between UE1 and the base station and the UP data between UE2 and the base station are securely protected.

[0300] Optionally, UP data between UE1 and the base station is protected by the activated security policy of UE1, and UP data between UE2 and the base station is protected by the activated security policy of UE2.

[0301] Alternatively, if the Uu UP security policy activated for UE1 is different from the Uu UP security policy activated for UE2, the security protection applied to UP data between UE1 and the base station may be different from the protection applied to UP data between UE2 and the base station.

[0302] Alternatively, if existing mechanisms are reused, inconsistent security protection may be applied to UP data of a single UE-satellite communication session. In this case, a higher security policy protection (e.g., integrity and confidentiality protection) of one piece of UP data may be downgraded by a lower security policy protection (e.g., integrity protection only, confidentiality protection only, or no protection) of another piece of UP data.

[0303] CASE2:

[0304] Step S5104: The PDU session of UE1 is established.

[0305] Optionally, UE1 initiates a PDU session establishment process to the core network, indicating UE2 as the target UE for communication. During this process, the core network sends the UP security policy of UE1 to the base station (e.g., eNB). The UP security policy of UE1 may include a UE1-SAT-UE2 communication indication; the UE1-SAT-UE2 communication indication is also sent to the base station by the core network (e.g., SMF1 or AMF1), and the UE1-SAT-UE2 communication indication is part of the session management subscription data or session management information. After receiving the UE1-SAT-UE2 communication indication, the base station should not immediately activate the Uu UP security policy for UE1, but will wait to receive the UP security policy of UE2 during the PDU session establishment process of UE2.

[0306] Optionally, the UP security policy of UE1 may be the first information in the previous embodiment; and the UE1-SAT-UE2 communication indication of UE1 may be the first indication information in the previous embodiment.

[0307] Step S5105: The PDU session of UE2 is established.

[0308] Optionally, when UE1 requests communication triggered by the network, UE2 initiates a PDU session establishment procedure with the core network, indicating UE2 as the target UE for communication. During this procedure, the core network sends UE2's UP security policy to the base station (e.g., eNB). This UE2 UP security policy may include a UE1-SAT-UE2 communication indication; the UE1-SAT-UE2 communication indication is also sent by the core network (e.g., SMF2 or AMF2) to the base station as part of the session management subscription data or session management information.

[0309] Optionally, the UP security policy of UE2 may be the second information in the previous embodiment; and the UE1-SAT-UE2 communication indication of UE2 may be the second indication information in the previous embodiment.

[0310] Optionally, the UP security policy of UE1 (UE1UP security policy) may be different from the UP security policy of UE2 (UE2UP security policy). Therefore, the Uu UP security protection activated for UE1 may be different from the Uu UP security protection activated for UE2.

[0311] Step S5106: The base station determines how to activate security protection for UE1 and UE2.

[0312] Optionally, the base station determines how to consistently activate UP security on two Uu interfaces with UE1 and UE2 based on the received UE1 UP security policy and UE2 UP security policy; this may be as follows:

[0313] Example 1: If the UE1 UP security policy and the UE2 UP security policy are consistent (for example, both indicate "required" or both indicate "not required"), the base station uses the received UE1 UP security policy and UE2 UP security policy ("required" or "not required") to perform consistent security protection on the UP data. Here, performing consistent security protection can be understood as providing the same security protection for the UP data of the first terminal and the UP data of the second terminal; for example, using the same security policy.

[0314] Example 2: If both the UE1 UP security policy and the UE2 UP security policy indicate "preferred", the base station determines the UP security policy on its own.

[0315] Example 3: If one of the UE1 UP security policy and the UE2 UP security policy indicates "required" and the other indicates "preferred", the base station uses "required" as the consistency security protection for UP data.

[0316] Example 4: If one of the UE1 UP security policy and the UE2 UP security policy indicates "not required" and the other indicates "preferred", the base station uses "not required" as the consistency security protection for UP data.

[0317] Example 5: If one of the UE1 UP security policy and the UE2 UP security policy indicates "required" and the other indicates "not required," this means that consistent security protection cannot be provided for UP data. The base station can then decide to either refuse to establish a PDU session with UE1 and UE2, or continue to activate Uu UP security protection for UE1 and UE2 based on different security policies, i.e., activate inconsistent security protection for UP data. The inability to provide consistent security protection here can be understood as providing different security protection for the UP data of the first terminal and the UP data of the second terminal, for example, using different security policies.

[0318] Step S5107: The base station activates Uu UP security protection for UE1 and UE2.

[0319] Optionally, the gNB activates the Uu UP security protection of UE1 and UE2 based on the UP security policy determined in step S5106; this may also refer to the security state in which the base station activates the security protection of UE1 and UE2, and the security state refers to a state in which protection is required or not required.

[0320] In step S5108, the UP data exchanged between UE1 and UE2 and the base station are securely protected.

[0321] Optionally, UP data exchanged between UE1 and UE2 through the base station is always protected by the activated UP security policy.

[0322] In the above embodiments, requiring protection includes requiring confidentiality protection and / or requiring integrity protection; not requiring protection includes not requiring confidentiality protection and / or not requiring integrity protection.

[0323] In the embodiments of the present disclosure, each embodiment can be implemented individually or in combination with each other, and the steps in each embodiment can be distinguished in order.

[0324] The disclosed embodiment relates to an information processing method, the method comprising:

[0325] In some embodiments, the base station should be able to receive a UE (eg, UE1, UE2) UE1-SAT-UE2 communication indication from a core network device.

[0326] In some embodiments, the base station should be able to determine how to handle the UP security policy of the involved UEs (eg, UE1, UE2) based on the UE1-SAT-UE2 indication from the core network device.

[0327] In some embodiments, the base station should be able to determine a consistent UP security policy for UP data of UE-SAT-UE communication based on the UP security policies of the involved UEs (eg, UE1, UE2).

[0328] In some embodiments, the base station should be able to activate consistent Uu UP security protection for UP data in UE-SAT-UE communication according to its own determined UP security policy.

[0329] In some embodiments, the core network device should be able to send the UE1-SAT-UE2 communication indication as part of the session management subscription data or session management information.

[0330] In the embodiments of the present disclosure, some or all of the steps and their optional implementations may be arbitrarily combined with some or all of the steps in other embodiments, and may also be arbitrarily combined with the optional implementations of other embodiments.

[0331] The embodiments of the present disclosure further provide an apparatus for implementing any of the above methods. For example, an apparatus is provided, comprising units or modules for implementing each step performed by a terminal in any of the above methods. For another example, another apparatus is provided, comprising units or modules for implementing each step performed by a network device (e.g., an access network device, a core network function node, a core network device, etc.) in any of the above methods.

[0332] It should be understood that the division of the various units or modules in the above device is merely a division of logical functions. In actual implementation, they may be fully or partially integrated into a physical entity, or they may be physically separated. In addition, the units or modules in the device may be implemented in the form of a processor calling software: for example, the device includes a processor, the processor is connected to a memory, and the memory stores instructions. The processor calls the instructions stored in the memory to implement any of the above methods or implement the functions of the various units or modules of the above device, wherein the processor is, for example, a general-purpose processor, such as a central processing unit (CPU) or a microprocessor, and the memory is a memory within the device or a memory outside the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuits, and the functions of some or all of the units or modules can be realized by designing the hardware circuits. The above-mentioned hardware circuits can be understood as one or more processors; for example, in one implementation, the above-mentioned hardware circuit is an application-specific integrated circuit (ASIC), and the functions of some or all of the above units or modules are realized by designing the logical relationship of the components in the circuit; for example, in another implementation, the above-mentioned hardware circuit can be realized by a programmable logic device (PLD). Taking a field programmable gate array (FPGA) as an example, it can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by configuring the configuration file, thereby realizing the functions of some or all of the above units or modules. All units or modules of the above devices can be realized in the form of software called by the processor, or in the form of hardware circuits, or in part by the form of software called by the processor, and the rest by hardware circuits.

[0333] In the embodiments of the present disclosure, the processor is a circuit with signal processing capabilities. In one implementation, the processor can be a circuit with instruction reading and execution capabilities, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), or a digital signal processor (DSP); in another implementation, the processor can implement certain functions through the logical relationship of the hardware circuit, and the logical relationship of the above-mentioned hardware circuit is fixed or reconfigurable, such as a hardware circuit implemented by a processor as an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document to implement the hardware circuit configuration can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules. In addition, it can also be a hardware circuit designed for artificial intelligence, which can be understood as ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), etc.

[0334] Figure 6A is a schematic structural diagram of an access network device 6100 provided in an embodiment of the present disclosure. As shown in Figure 6A, the access network device 6100 includes: a first transceiver module 6101 and a processing module 6102. In some embodiments, the first transceiver module 6101 is used to receive the first information and / or second information sent by the core network device. Optionally, the first transceiver module 6101 is used to perform at least one of the steps of sending and / or receiving (such as steps S2101 and / or S2102 and / or step S2104, but not limited thereto) performed by the access network device in any of the above methods, which are not described in detail here. Optionally, the processing module 6102 is used to determine the security protection of the UP data of the first terminal and the second terminal. Optionally, the processing module 6102 is used to perform at least one of the steps of processing (such as steps S2103, but not limited thereto) performed by the access network device in any of the above methods, which are not described in detail here.

[0335] Figure 6B is a structural diagram of the core network device 6200 provided in an embodiment of the present disclosure. As shown in Figure 6B, the core network device 6200 includes: a second transceiver module 6201. Optionally, the second transceiver module 6201 is used to send the first information and / or the second information to the core network device. Optionally, the second transceiver module 6201 is used to execute at least one of the steps of sending and / or receiving (such as step S2101 and / or step S2102 and / or step S2104, but not limited thereto) executed by the core network device in any of the above methods, which will not be repeated here.

[0336] In some embodiments, the transceiver module may include a transmitting module and / or a receiving module. The transmitting module and the receiving module may be separate or integrated. Optionally, the transceiver module and the transceiver may be interchangeable. Exemplarily, the first transceiver module includes a first transmitting module and / or a first receiving module. Exemplarily, the second transceiver module includes a second transmitting module and / or a second receiving module.

[0337] In some embodiments, the processing module can be a single module or can include multiple submodules. Optionally, the multiple submodules respectively execute all or part of the steps required to be executed by the processing module. Optionally, the processing module can be interchangeable with the processor.

[0338] Figure 7A is a schematic diagram of the structure of a communication device 7100 proposed in an embodiment of the present disclosure. Communication device 7100 can be a network device (e.g., an access network device, a core network device, a first network element, a second network element, etc.), or a terminal (e.g., a user equipment, etc.), or a chip, chip system, or processor that supports a network device to implement any of the above methods, or a chip, chip system, or processor that supports a terminal to implement any of the above methods. Communication device 7100 can be used to implement the methods described in the above method embodiments. For details, please refer to the description of the above method embodiments.

[0339] As shown in Figure 7A, the communication device 7100 includes one or more processors 7101. The processor 7101 can be a general-purpose processor or a dedicated processor, for example, a baseband processor or a central processing unit. The baseband processor can be used to process the communication protocol and communication data, and the central processing unit can be used to control the communication device (such as a base station, a baseband chip, a terminal device, a terminal device chip, a DU or a CU, etc.), execute programs, and process program data. Optionally, the communication device 7100 is used to perform any of the above methods. Optionally, one or more processors 7101 are used to call instructions to enable the communication device 7100 to perform any of the above methods.

[0340] In some embodiments, the communication device 7100 further includes one or more transceivers 7102. When the communication device 7100 includes one or more transceivers 7102, the transceiver 7102 performs at least one of the communication steps such as sending and / or receiving in the above method (for example, step S2101 and / or step S2102, but not limited thereto), and the processor 7101 performs at least one of the other steps. In an optional embodiment, the transceiver may include a receiver and / or a transmitter, and the receiver and transmitter may be separate or integrated. Optionally, the terms transceiver, transceiver unit, transceiver, transceiver circuit, interface circuit, and interface may be interchangeable, the terms transmitter, transmitting unit, transmitter, and transmitting circuit may be interchangeable, and the terms receiver, receiving unit, receiver, and receiving circuit may be interchangeable.

[0341] In some embodiments, the communication device 7100 further includes one or more memories 7103 for storing data. Alternatively, all or part of the memories 7103 may be located outside the communication device 7100. In alternative embodiments, the communication device 7100 may include one or more interface circuits 7104. Optionally, the interface circuits 7104 are connected to the memories 7103 and may be configured to receive data from the memories 7103 or other devices, or to send data to the memories 7103 or other devices. For example, the interface circuits 7104 may read data stored in the memories 7103 and send the data to the processor 7101.

[0342] The communication device 7100 described in the above embodiment may be a network device or a terminal, but the scope of the communication device 7100 described in the present disclosure is not limited thereto, and the structure of the communication device 7100 may not be limited by FIG. 7A. The communication device may be an independent device or may be part of a larger device. For example, the communication device may be: (1) an independent integrated circuit IC, or a chip, or a chip system or subsystem; (2) a collection of one or more ICs, optionally, the above IC collection may also include a storage component for storing data or programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, a terminal device, an intelligent terminal device, a cellular phone, a wireless device, a handheld device, a mobile unit, an in-vehicle device, a network device, a cloud device, an artificial intelligence device, etc.; (7) others, etc.

[0343] 7B is a schematic diagram of the structure of a chip 7200 proposed in an embodiment of the present disclosure. If the communication device 7100 can be a chip or a chip system, please refer to the schematic diagram of the structure of the chip 7200 shown in FIG7B , but the present disclosure is not limited thereto.

[0344] The chip 7200 includes one or more processors 7201. The chip 7200 is configured to execute any of the above methods.

[0345] In some embodiments, chip 7200 further includes one or more interface circuits 7202. Alternatively, terms such as interface circuit, interface, and transceiver pins may be used interchangeably. In some embodiments, chip 7200 further includes one or more memories 7203 for storing data. Alternatively, all or part of memory 7203 may be located external to chip 7200. Optionally, interface circuit 7202 is connected to memory 7203 and may be used to receive data from memory 7203 or other devices, or may be used to send data to memory 7203 or other devices. For example, interface circuit 7202 may read data stored in memory 7203 and send the data to processor 7201.

[0346] In some embodiments, the interface circuit 7202 performs at least one of the communication steps (e.g., step S2101 and / or step S2102, but not limited thereto) of the sending and / or receiving steps in the above method. For example, the interface circuit 7202 performing the communication steps (e.g., sending and / or receiving) in the above method means that the interface circuit 7202 performs data exchange between the processor 7201, chip 7200, memory 7203, or a transceiver device. In some embodiments, the processor 7201 performs at least one of the other steps.

[0347] The modules and / or devices described in various embodiments, such as virtual devices, physical devices, and chips, can be arbitrarily combined or separated according to circumstances. Optionally, some or all steps can also be performed collaboratively by multiple modules and / or devices, which is not limited here.

[0348] The present disclosure also proposes a storage medium having instructions stored thereon. When the instructions are executed on the communication device 7100, the communication device 7100 executes any of the above methods. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer-readable storage medium, but is not limited thereto and may also be a storage medium readable by other devices. Optionally, the storage medium may be a non-transitory storage medium, but is not limited thereto and may also be a temporary storage medium.

[0349] The present disclosure also provides a program product, which, when executed by the communication device 7100, enables the communication device 7100 to perform any of the above methods. Optionally, the program product is a computer program product.

[0350] The present disclosure also proposes a computer program, which, when executed on a computer, causes the computer to perform any one of the above methods.

Claims

1. An information processing method, characterized in that, Performed by an access network device, including: Determine the security protection of the user plane (UP) data of a first terminal and a second terminal based on first indication information and second indication information; wherein, the first indication information is used to indicate the transmission mode and / or security policy of the UP data of the first terminal, and the second indication information is used to indicate the transmission mode and / or security policy of the UP data of the second terminal.

2. The method according to claim 1, wherein The determining the security protection of the UP data of the first terminal and the second terminal includes at least one of the following: Determine whether the UP data of the first terminal and the second terminal needs to be protected; Determine whether the UP data of the first terminal and the second terminal is subject to consistent security protection; Determine the security policy for protecting the UP data of the first terminal and / or the second terminal.

3. The method according to claim 1 or 2, characterized in that The method further includes: Receive first information sent by a core network device, where the first information includes the first indication information; Receive second information sent by the core network device, where the second information includes the second indication information.

4. The method according to any one of claims 1 to 3, characterized in that The determining the security protection of the UP data of the first terminal and the second terminal based on the first indication information and the second indication information includes one of the following: When the transmission modes of the UP data indicated by the first indication information and the second indication information are both UE-SAT-UE local transmission, determine the judgment of enabling consistent security protection for the UP data of the first terminal and the second terminal; When the security policies of the UP data indicated by the first indication information and the second indication information are the same and are the first type of security policy, determine that the UP data of the first terminal and the second terminal is subject to consistent security protection; When the security policies of the UP data indicated by the first indication information and the second indication information are the same and are the second type of security policy, determine how to perform consistent security protection on the UP data based on the access network device; When the security policies of the UP data indicated by the first indication information and the second indication information are different, determine whether the UP data of the first terminal and the second terminal is subject to consistent protection according to the categories of the security policies indicated by the first indication information and the second indication information respectively.

5. The method according to claim 4, wherein The first type of security policy includes need to protect or do not need to protect; And / or The second type of security policy includes preferred protection; wherein, the preferred protection indicates that the access network device is preferably selected for security protection.

6. The method according to claim 4, wherein The determining whether the UP data of the first terminal and the second terminal is subject to consistent protection according to the categories of the security policies indicated by the first indication information and the second indication information respectively includes at least one of the following: In the case that one of the first indication information and the second indication information indicates a first type of security policy and the other indicates a second type of security policy, determine that the UP data of the first terminal and the second terminal are subject to consistent protection under the first type of security policy; wherein, the first type of security policy includes being protected or not being protected, and the second type of security policy includes preferred protection. In the case that both the first indication information and the second indication information indicate the first type of security policy and the security policies indicated by the first indication information and the second indication information are different, determine that the UP data of the first terminal and the second terminal cannot be subject to consistent protection.

7. The method according to claim 4 or 6, characterized in that, The method further includes one of the following: In the case that it is determined that the first terminal and the second terminal cannot be subject to consistent protection, reject establishing a session with the first terminal and the second terminal. In the case that it is determined that the first terminal and the second terminal cannot be subject to consistent protection, perform security protection on the UP data of the first terminal based on the security policy indicated by the first indication information, and / or perform security protection on the UP data of the second terminal based on the security policy indicated by the second indication information.

8. The method according to any one of claims 1 to 7, characterized in that, The method further includes: Activate the security protection of the UP data of the first terminal and / or the second terminal based on the security policy for the UP data of the first terminal and the second terminal.

9. The method according to any one of claims 1 to 8, characterized in that, The method further includes: Send third information to the first terminal and / or the second terminal, where the third information is used to indicate the security protection of the UP data of the first terminal and the second terminal determined by the access network device; the third information is used for the first terminal and / or the second terminal to perform security protection on the UP data.

10. The method according to any one of claims 1 to 9, characterized in that, The access network device includes a satellite base station; and / or, the core network device includes: an Access and Mobility Management Function (AMF), or a Session Management Function (SMF), or a Policy Control Function (PCF).

11. An information processing method, characterized in that, Executed by the core network device, including: Send first information to the access network device, where the first information includes first indication information; the first indication information is used to indicate the transmission mode and / or security policy of the user plane (UP) data of the first terminal. Send second information to the access network device, where the second information includes second indication information; the second indication information is used to indicate the transmission mode and / or security policy of the UP data of the second terminal. Wherein, the first indication information and the second indication information are used for the access network device to determine the security protection of the UP data of the first terminal and the second terminal.

12. The method according to claim 11, wherein The method further includes: Receive the first information sent by the first terminal. And / or, Receive the second information sent by the second terminal.

13. The method according to claim 11 or 12, characterized in that, The access network device includes a satellite base station; and / or, the core network device includes: an Access and Mobility Management Function (AMF), or a Session Management Function (SMF), or a Policy Control Function (PCF).

14. An access network device, characterized in that, Includes: The first transceiver module is configured to determine the security protection of the user plane (UP) data of the first terminal and the second terminal based on the first indication information and the second indication information; wherein, the first indication information is used to indicate the transmission mode and / or security policy of the UP data of the first terminal, and the second indication information is used to indicate the transmission mode and / or security policy of the UP data of the second terminal.

15. A core network device, characterized in that, It includes: The second transceiver module is configured to send a first message to the access network device, where the first message includes the first indication information; The first indication information is used to indicate the transmission mode and / or security policy of the UP data of the first terminal; The second transceiver module is further configured to send a second message to the access network device, where the second message includes the second indication information; the second indication information is used to indicate the transmission mode and / or security policy of the UP data of the second terminal; Wherein, the first indication information and the second indication information are used by the access network device to determine the security protection of the UP data of the first terminal and the second terminal.

16. A communication device, characterized in that, It includes: One or more processors; Wherein, the communication device is used to execute the information processing method according to any one of claims 1 to 10, or claims 11 to 13.

17. A communication system, characterized in that, It includes: An access network device and a first device; wherein, the access network device is configured to implement the information processing method according to any one of claims 1 to 10, and the first device is configured to implement the information processing method according to any one of claims 11 to 13.

18. A storage medium, the storage medium stores instructions, characterized in that, When the instruction runs on the communication device, it causes the communication device to execute the information processing method according to any one of claims 1 to 10, or claims 11 to 13.