Communication method, communication device, communication system and storage medium
Patent Information
- Application Number
- CN202480000972.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-24
- Publication Date
- 2025-12-26
AI Technical Summary
In multi-hop proximity service scenarios, the security of communication cannot be guaranteed.
The remote terminal sends a first message to the second relay device to request the establishment of a secure communication link with the first relay device, and uses the second relay device to conduct secure communication, thereby achieving end-to-end security protection.
It enables end-to-end secure communication in multi-hop communication scenarios, thereby improving communication security.
Smart Images

Figure CN121220177A_ABST
Abstract
Description
Communication methods, communication equipment, communication systems and storage media Technical Field
[0001] This disclosure relates to the field of communication technology, and in particular to communication methods, communication devices, communication systems and storage media. Background Technology
[0002] To support communication between user equipment (UE) and network devices outside network coverage, Proximity-based Services (ProSe) were introduced. In single-hop ProSe, remote UEs communicate with network devices through UE-to-Network Relay (U2N) relay equipment.
[0003] Currently, multi-hop proximity service has been introduced. Remote terminals establish connections with U2N relay devices through one or more intermediate relay devices and communicate with network devices. Intermediate relay devices are proximity service terminals (ProSe UEs) located on the path between the remote UE and the U2N relay device, providing support for ProSe UEs to connect to network devices, thereby supporting multi-hop proximity service.
[0004] Summary of the Invention
[0005] In scenarios involving multiple hops and proximity services, the security of communication cannot be guaranteed.
[0006] This disclosure provides communication methods, communication devices, communication systems, and storage media.
[0007] According to a first aspect of the present disclosure, a communication method is proposed, the method comprising: a remote terminal sending a first message to a second relay device, the first message being used to request the establishment of a first link between the remote terminal and the first relay device, the first link being used for secure communication between the remote terminal and the first relay device based on the second relay device.
[0008] According to a second aspect of the present disclosure, a communication method is provided, the method comprising: a second relay device receiving a first message sent by a remote terminal; the first message being used to request the establishment of a first link between the remote terminal and a first relay device, the first link being used for secure communication between the remote terminal and the first relay device based on the second relay device; and the second relay device sending the first message to the first relay device.
[0009] According to a third aspect of the present disclosure, a communication method is provided, the method comprising: a first relay device receiving a first message sent by a second relay device, the first message being used to request the establishment of a first link between a remote terminal and the first relay device, the first link being used for secure communication between the remote terminal and the first relay device based on the second relay device.
[0010] According to a fourth aspect of the present disclosure, a communication method is provided, the method comprising: a remote terminal sending a first message to a second relay device, the first message being used to request the establishment of a first link between the remote terminal and a first relay device, the first link being used for secure communication between the remote terminal and the first relay device based on the second relay device; the second relay device receiving the first message sent by the remote terminal; the second relay device sending the first message to the first relay device; and the first relay device receiving the first message sent by the second relay device.
[0011] According to a fifth aspect of the present disclosure, a remote terminal is provided, comprising: a transceiver module, configured to send a first message to a second relay device, the first message being configured to request the establishment of a first link between the remote terminal and the first relay device, the first link being configured for secure communication between the remote terminal and the first relay device based on the second relay device.
[0012] According to a sixth aspect of the present disclosure, a relay device is provided, comprising: a transceiver module, configured to receive a first message sent by a remote terminal; send the first message to a first relay device; the first message is configured to request the establishment of a first link between the remote terminal and the first relay device, the first link being used for secure communication between the remote terminal and the first relay device based on a second relay device.
[0013] According to a seventh aspect of the present disclosure, a relay device is provided, comprising: a transceiver module for receiving a first message sent by a second relay device, the first message being used to request the establishment of a first link between the remote terminal and the first relay device, the first link being used for secure communication between the remote terminal and the first relay device based on the second relay device.
[0014] According to an eighth aspect of the present disclosure, a remote terminal is provided, comprising: one or more processors; wherein the processors are configured to execute the first aspect and any one of the communication methods in the first aspect.
[0015] According to a ninth aspect of the present disclosure, a relay device is provided, comprising: one or more processors; wherein the processors are configured to perform the second aspect and any one of the communication methods in the second aspect.
[0016] According to a tenth aspect of the present disclosure, a relay device is provided, comprising: one or more processors; wherein the processors are configured to execute the third aspect and any one of the communication methods in the third aspect.
[0017] According to an eleventh aspect of the present disclosure, a communication system is provided, including a remote terminal, a first relay device, and a second relay device. The remote terminal is configured to implement the communication method described in the first aspect and any one thereof, the first relay device is configured to implement the communication method described in the second aspect and any one thereof, and the second relay device is configured to implement the communication method described in the third aspect and any one thereof.
[0018] According to a twelfth aspect of the present disclosure, a storage medium is provided that stores instructions, which, when executed on a communication device, cause the communication device to perform a communication method as described in the first aspect and any one of the first aspects, or the second aspect and any one of the second aspects, or the third aspect and any one of the third aspects.
[0019] According to a thirteenth aspect of the present disclosure, a program product is provided, including a computer program that, when executed by a communication device, causes the communication device to perform the method described in the first aspect and any one of the first aspects, or the second aspect and any of the second aspects, or the third aspect and any of the optional implementations of the third aspect.
[0020] This disclosure achieves end-to-end security protection between the remote terminal and the first relay device by having a remote terminal send a first message to a second relay device to request the establishment of a first secure communication link. The first link is used for secure communication between the remote terminal and the first relay device based on at least one second relay device, including the second relay device, thereby realizing communication security in multi-hop communication scenarios. Attached Figure Description
[0021] To more clearly illustrate the technical solutions in the embodiments of this disclosure, the accompanying drawings required for the description of the embodiments are introduced below. The following drawings are only some embodiments of this disclosure and do not impose specific limitations on the protection scope of this disclosure.
[0022] Figure 1a is a schematic diagram of a communication system architecture according to an embodiment of the present disclosure.
[0023] Figure 1b is a schematic diagram of a communication system architecture according to an embodiment of the present disclosure.
[0024] Figure 2 is a schematic diagram of a communication method interaction according to an embodiment of the present disclosure.
[0025] Figure 3a is a flowchart illustrating a communication method according to an embodiment of the present disclosure.
[0026] Figure 3b is a flowchart illustrating a communication method according to an embodiment of the present disclosure.
[0027] Figure 4a is a flowchart illustrating a communication method according to an embodiment of the present disclosure.
[0028] Figure 4b is a flowchart illustrating a communication method according to an embodiment of the present disclosure.
[0029] Figure 5a is a flowchart illustrating a communication method according to an embodiment of the present disclosure.
[0030] Figure 5b is a flowchart illustrating a communication method according to an embodiment of the present disclosure.
[0031] Figure 6 is a schematic diagram of the communication method interaction according to an embodiment of the present disclosure.
[0032] Figure 7 is a schematic diagram of the communication method interaction according to an embodiment of the present disclosure.
[0033] Figure 8a is a schematic diagram of the structure of the remote terminal proposed in the embodiments of this disclosure.
[0034] Figure 8b is a schematic diagram of the structure of the second relay device proposed in the embodiments of this disclosure.
[0035] Figure 8c is a schematic diagram of the structure of the first relay device proposed in the embodiments of this disclosure.
[0036] Figure 9a is a schematic diagram of the structure of a communication device proposed in an embodiment of this disclosure.
[0037] Figure 9b is a schematic diagram of the chip structure proposed in an embodiment of this disclosure. Detailed Implementation
[0038] This disclosure provides communication methods, communication devices, communication systems, and storage media.
[0039] In a first aspect, embodiments of this disclosure propose a communication method, the method comprising: a remote terminal sending a first message to a second relay device, the first message being used to request the establishment of a first link between the remote terminal and the first relay device, the first link being used for secure communication between the remote terminal and the first relay device based on the second relay device.
[0040] In the above embodiment, the remote terminal sends a first message to the second relay device to request the establishment of a first link for secure communication, thereby achieving end-to-end security protection between the remote terminal and the first relay device and realizing communication security in multi-hop communication scenarios.
[0041] In some alternative embodiments of the first aspect, the first message includes at least one of the following: an identifier related to the remote terminal; a random number; a first communication security policy between the remote terminal and the first relay device, the first communication security policy being used to determine a method for secure communication based on the first link; and a second communication security policy between the remote terminal and the second relay device, the second communication security policy being used to determine a method for secure communication based on a second link, the second link being used for secure communication between the remote terminal and the second relay device.
[0042] In the above embodiments, the first message includes at least one of the above-mentioned items to facilitate the establishment of security for the first link, thereby ensuring end-to-end communication security.
[0043] In some alternative embodiments of the first aspect, the method further includes: the remote terminal receiving a second message sent by the second relay device, the second message being determined based on the first message, the second message being used to request security for establishing the first link; the remote terminal performing security verification on the second message; the remote terminal determining that the security verification is successful; the remote terminal sending a third message to the second relay device, the third message being used to indicate that the security verification is successful; and the remote terminal receiving a fourth message sent by the second relay device, the fourth message being used to instruct the first relay device to accept the request of the first message.
[0044] In the above embodiments, the security of the first link can be determined by verifying the second message, and secure communication can be established to ensure the security of the communication.
[0045] In some alternative embodiments of the first aspect, the first message is further used to trigger the establishment of a second link between the remote terminal and the second relay device, and the method further includes: the remote terminal establishing a second link between the remote terminal and the second relay device, the second link being used for secure communication between the remote terminal and the second relay device.
[0046] In the above embodiments, the first message can be used to trigger the establishment of a second link so that there is no need to send a separate request to establish the second link, thus saving signaling consumption.
[0047] In some alternative embodiments of the first aspect, the remote terminal sending a first message to the second relay device includes: the remote terminal establishing a second link between the remote terminal and the second relay device, and sending a first message to the second relay device based on the second link, wherein the second link is used for secure communication between the remote terminal and the second relay device.
[0048] In the above embodiments, a second link can be established first, and then the first message can be sent based on the second link to improve communication efficiency.
[0049] In some alternative embodiments of the first aspect, the first message includes the first communication security policy, which includes at least one of the following: a policy indicating whether to protect signaling integrity; a policy indicating whether to protect signaling confidentiality; a policy indicating whether to protect data integrity; and a policy indicating whether to protect data confidentiality.
[0050] In the above embodiments, the first communication security strategy includes at least one of the above-mentioned measures to protect end-to-end communication security.
[0051] In some alternative embodiments of the first aspect, the first communication security policy and / or the second communication security policy are configured by the network device to the remote terminal.
[0052] In the above embodiments, the communication security policy can be configured by the network device to improve communication security.
[0053] In a second aspect, a communication method is provided, the method comprising: a second relay device receiving a first message sent by a remote terminal; the first message being used to request the establishment of a first link between the remote terminal and the first relay device, the first link being used for secure communication between the remote terminal and the first relay device based on at least one second relay device including the second relay device; and the second relay device sending the first message to the first relay device.
[0054] In some alternative embodiments of the second aspect, the first message includes at least one of the following: an identifier related to the remote terminal; a random number; a first communication security policy between the remote terminal and the first relay device, the first communication security policy being used to determine a method for secure communication based on the first link; and a second communication security policy between the remote terminal and the second relay device, the second communication security policy being used to determine a method for secure communication based on a second link, the second link being used for secure communication between the remote terminal and the second relay device.
[0055] In some alternative embodiments of the second aspect, the first message is further used to trigger the establishment of a second link between the remote terminal and the second relay device, the second link being used for secure communication between the remote terminal and the second relay device.
[0056] In some alternative embodiments of the second aspect, the second relay device receiving the first message sent by the remote terminal includes: the second relay device receiving the first message sent by the remote terminal based on the second link established by the remote terminal.
[0057] In some alternative embodiments of the second aspect, the first message is further configured to trigger the establishment of a third link between the at least one second relay device, and / or the first message is further configured to trigger the establishment of a fourth link between the second relay device and the first relay device, the method further comprising: the second relay device establishing a third link between the at least one second relay device, the third link being used for secure communication between the at least one second relay device; and / or, the second relay device establishing a fourth link between the second relay device and the first relay device, the fourth link being used for secure communication between the second relay device and the first relay device.
[0058] In some optional embodiments of the second aspect, the second relay device sending a first message to the first relay device includes: the second relay device establishing a third link between the at least one second relay device, the third link being used for secure communication between the at least one second relay device; the second relay device establishing a fourth link between the second relay device and the first relay device, the fourth link being used for secure communication between the second relay device and the first relay device; and the second relay device sending the first message to the first relay device based on the third link and the fourth link.
[0059] In some optional embodiments of the second aspect, sending the first message to the first relay device includes: sending the first message to the first relay device based on a pre-established third link and a fourth link; wherein the third link is used for secure communication between the at least one second relay device, and the fourth link is used for secure communication between the second relay device and the first relay device.
[0060] In some alternative embodiments of the second aspect, the method further includes: the second relay device receiving a second message sent by the first relay device, the second message being determined based on the first message, the second message being used for security verification; the second relay device sending the second message to the remote terminal; the second relay device receiving a third message sent by the remote terminal, the third message being used to indicate that the security verification has passed; the second relay device sending the third message to the first relay device; the second relay device receiving a fourth message sent by the first relay device, the fourth message being used to indicate that the first relay device accepts the request of the first message; and the second relay device sending the fourth message to the remote terminal.
[0061] In some alternative embodiments of the second aspect, the first message includes the first communication security policy, which includes at least one of the following: a policy indicating whether to protect signaling integrity; a policy indicating whether to protect signaling confidentiality; a policy indicating whether to protect data integrity; and a policy indicating whether to protect data confidentiality.
[0062] In some alternative embodiments of the second aspect, the first communication security policy and / or the second communication security policy are configured by the network device to the remote terminal.
[0063] Thirdly, a communication method is provided, the method comprising: a first relay device receiving a first message sent by a second relay device, the first message being used to request the establishment of a first link between the remote terminal and the first relay device, the first link being used for secure communication between the remote terminal and the first relay device based on the second relay device.
[0064] In some alternative embodiments of the third aspect, the first message includes at least one of the following: an identifier related to the remote terminal; a random number; a first communication security policy between the remote terminal and the first relay device, the first communication security policy being used to determine a method for secure communication based on the first link; and a second communication security policy between the remote terminal and the second relay device, the second communication security policy being used to determine a method for secure communication based on a second link, the second link being used for secure communication between the remote terminal and the second relay device.
[0065] In some alternative embodiments of the third aspect, the method further includes: the first relay device determining a second message based on the first message, the second message being used for security verification; the first relay device sending the second message to the second relay device; the first relay device receiving a third message sent by the second relay device, the third message being used to indicate that the security verification has passed; and the first relay device sending a fourth message to the second relay device, the fourth message being used to indicate that the first relay device accepts the request of the first message.
[0066] In some alternative embodiments of the third aspect, the first message is further used to trigger the establishment of a fourth link between the second relay device and the first relay device; wherein the fourth link is used for secure communication between the second relay device and the first relay device.
[0067] In some alternative embodiments of the third aspect, the first relay device receiving the first message sent by the second relay device includes: the first relay device receiving the first message sent by the second relay device based on a fourth link established by the second relay device; wherein the fourth link is used for secure communication between the second relay device and the first relay device.
[0068] In some alternative embodiments of the third aspect, the first relay device receiving the first message sent by the second relay device includes: the first relay device receiving the first message sent by the second relay device based on a pre-established fourth link; wherein the fourth link is used for secure communication between the second relay device and the first relay device.
[0069] In some alternative embodiments of the third aspect, the first message includes the first communication security policy, which includes at least one of the following: a policy indicating whether to protect signaling integrity; a policy indicating whether to protect signaling confidentiality; a policy indicating whether to protect data integrity; and a policy indicating whether to protect data confidentiality.
[0070] In some alternative embodiments of the third aspect, the first communication security policy and / or the second communication security policy are configured by the network device to the remote terminal.
[0071] In some alternative embodiments of the third aspect, the method further includes: sending a fifth message to a network device, the fifth message being used to report relevant information about the remote terminal.
[0072] Fourthly, a communication method is provided, the method comprising: a remote terminal sending a first message, the first message being used to request the establishment of a first link between the remote terminal and a first relay device, the first link being used for secure communication between the remote terminal and the first relay device based on at least one second relay device; the second relay device receiving the first message; the second relay device sending the first message; and the first relay device receiving the first message.
[0073] Fifthly, a remote terminal is provided, comprising: a transceiver module, configured to send a first message to a second relay device, the first message being configured to request the establishment of a first link between the remote terminal and the first relay device, the first link being configured for secure communication between the remote terminal and the first relay device based on the second relay device.
[0074] In some alternative embodiments of the fifth aspect, the first message includes at least one of the following: an identifier related to the remote terminal; a random number; a first communication security policy between the remote terminal and the first relay device, the first communication security policy being used to determine a method for secure communication based on the first link; and a second communication security policy between the remote terminal and the second relay device, the second communication security policy being used to determine a method for secure communication based on a second link, the second link being used for secure communication between the remote terminal and the second relay device.
[0075] In some optional embodiments of the fifth aspect, the transceiver module is further configured to: the remote terminal receive a second message sent by the second relay device, the second message being determined based on the first message, the second message being used to request the establishment of security for the first link; the remote terminal further includes a processing module configured to perform security verification on the second message to determine that the security verification is successful; the transceiver module is further configured to: send a third message to the second relay device, the third message being used to indicate that the security verification is successful; and receive a fourth message sent by the second relay device, the fourth message being used to instruct the first relay device to accept the request of the first message.
[0076] In some alternative embodiments of the fifth aspect, the first message is further configured to trigger the establishment of a second link between the remote terminal and the second relay device, and the processing module is further configured to: establish a second link between the remote terminal and the second relay device, the second link being used for secure communication between the remote terminal and the second relay device.
[0077] In some optional embodiments of the fifth aspect, the processing module is further configured to: establish a second link between the remote terminal and the second relay device, and the transceiver module is configured to send a first message to the second relay device in the following manner: based on the second link, send a first message to the second relay device, the second link being used for secure communication between the remote terminal and the second relay device.
[0078] In some alternative embodiments of the fifth aspect, the first message includes the first communication security policy, which includes at least one of the following: a policy indicating whether to protect signaling integrity; a policy indicating whether to protect signaling confidentiality; a policy indicating whether to protect data integrity; and a policy indicating whether to protect data confidentiality.
[0079] In some alternative embodiments of the fifth aspect, the first communication security policy and / or the second communication security policy are configured by the network device to the remote terminal.
[0080] A sixth aspect provides a relay device, comprising: a transceiver module, configured to receive a first message sent by a remote terminal; send the first message to a first relay device; the first message is configured to request the establishment of a first link between the remote terminal and the first relay device, the first link being used for secure communication between the remote terminal and the first relay device based on a second relay device.
[0081] In some alternative embodiments of the sixth aspect, the first message includes at least one of the following: an identifier related to the remote terminal; a random number; a first communication security policy between the remote terminal and the first relay device, the first communication security policy being used to determine a method for secure communication based on the first link; and a second communication security policy between the remote terminal and the second relay device, the second communication security policy being used to determine a method for secure communication based on a second link, the second link being used for secure communication between the remote terminal and the second relay device.
[0082] In some alternative embodiments of the sixth aspect, the first message is further used to trigger the establishment of a second link between the remote terminal and the second relay device, the second link being used for secure communication between the remote terminal and the second relay device.
[0083] In some alternative embodiments of the sixth aspect, the transceiver module receives the first message sent by the remote terminal in the following manner: the second relay device receives the first message sent by the remote terminal based on the second link established by the remote terminal.
[0084] In some alternative embodiments of the sixth aspect, the first message is further configured to trigger the establishment of a third link between the at least one second relay device, and / or the first message is further configured to trigger the establishment of a fourth link between the second relay device and the first relay device, wherein the second relay device further includes a processing module configured to establish a third link between the at least one second relay device, the third link being used for secure communication between the at least one second relay device; and / or to establish a fourth link between the second relay device and the first relay device, the fourth link being used for secure communication between the second relay device and the first relay device.
[0085] In some optional embodiments of the sixth aspect, the processing module is further configured to: establish a third link between the at least one second relay device, the third link being used for secure communication between the at least one second relay device; establish a fourth link between the second relay device and the first relay device, the fourth link being used for secure communication between the second relay device and the first relay device; and send the first message to the first relay device in the following manner: sending the first message to the first relay device based on the third link and the fourth link.
[0086] In some alternative embodiments of the sixth aspect, the first message is sent to the first relay device in the following manner: the first message is sent to the first relay device based on a pre-established third link and a fourth link; wherein the third link is used for secure communication between the at least one second relay device, and the fourth link is used for secure communication between the second relay device and the first relay device.
[0087] In some optional embodiments of the sixth aspect, the transceiver module is further configured to: receive a second message sent by the first relay device, the second message being determined based on the first message and used for security verification; send the second message to the remote terminal; receive a third message sent by the remote terminal, the third message being used to indicate that the security verification has passed; send the third message to the first relay device; receive a fourth message sent by the first relay device, the fourth message being used to indicate that the first relay device accepts the request of the first message; and send the fourth message to the remote terminal.
[0088] In some alternative embodiments of the sixth aspect, the first message includes the first communication security policy, which includes at least one of the following: a policy indicating whether to protect signaling integrity; a policy indicating whether to protect signaling confidentiality; a policy indicating whether to protect data integrity; and a policy indicating whether to protect data confidentiality.
[0089] In some alternative embodiments of the sixth aspect, the first communication security policy and / or the second communication security policy are configured by the network device to the remote terminal.
[0090] A seventh aspect provides a relay device, comprising: a transceiver module, configured to receive a first message sent by a second relay device, the first message being configured to request the establishment of a first link between a remote terminal and a first relay device, the first link being configured for secure communication between the remote terminal and the first relay device based on the second relay device.
[0091] In some alternative embodiments of the seventh aspect, the first message includes at least one of the following: an identifier related to the remote terminal; a random number; a first communication security policy between the remote terminal and the first relay device, the first communication security policy being used to determine a method for secure communication based on the first link; and a second communication security policy between the remote terminal and the second relay device, the second communication security policy being used to determine a method for secure communication based on a second link, the second link being used for secure communication between the remote terminal and the second relay device.
[0092] In some alternative embodiments of the seventh aspect, the first relay device further includes a processing module, configured to determine a second message based on the first message, the second message being used for security verification; the transceiver module is further configured to: send the second message to the second relay device; receive a third message sent by the second relay device, the third message being used to indicate that the security verification has passed; and send a fourth message to the second relay device, the fourth message being used to indicate that the first relay device accepts the request of the first message.
[0093] In some alternative embodiments of the seventh aspect, the first message is further configured to trigger the establishment of a fourth link between the second relay device and the first relay device; wherein the fourth link is used for secure communication between the second relay device and the first relay device.
[0094] In some alternative embodiments of the seventh aspect, the first relay device receives the first message sent by the second relay device in the following manner: the first relay device receives the first message sent by the second relay device based on a fourth link established by the second relay device; wherein the fourth link is used for secure communication between the second relay device and the first relay device.
[0095] In some alternative embodiments of the seventh aspect, the first relay device receives the first message sent by the second relay device in the following manner: the first relay device receives the first message sent by the second relay device based on a pre-established fourth link; wherein the fourth link is used for secure communication between the second relay device and the first relay device.
[0096] In some alternative embodiments of the seventh aspect, the first message includes the first communication security policy, which includes at least one of the following: a policy indicating whether to protect signaling integrity; a policy indicating whether to protect signaling confidentiality; a policy indicating whether to protect data integrity; and a policy indicating whether to protect data confidentiality.
[0097] In some alternative embodiments of the seventh aspect, the first communication security policy and / or the second communication security policy are configured by the network device to the remote terminal.
[0098] In some alternative embodiments of the seventh aspect, the transceiver module is further configured to: send a fifth message to the network device, the fifth message being used to report relevant information of the remote terminal.
[0099] Eighthly, a remote terminal is provided, comprising: one or more processors; wherein the processors are configured to execute the first aspect and any one of the communication methods in the first aspect.
[0100] A ninth aspect provides a relay device, comprising: one or more processors; wherein the processors are configured to perform the second aspect and any one of the communication methods in the second aspect.
[0101] A tenth aspect provides a relay device, comprising: one or more processors; wherein the processors are configured to execute the third aspect and any one of the communication methods in the third aspect.
[0102] Eleventhly, a communication system is provided, comprising a remote terminal, a first relay device, and a second relay device. The remote terminal is configured to implement the communication method of the first aspect and any one thereof, the first relay device is configured to implement the communication method of the second aspect and any one thereof, and the second relay device is configured to implement the communication method of the third aspect and any one thereof.
[0103] In a twelfth aspect, a storage medium is provided that stores instructions which, when executed on a communication device, cause the communication device to perform any of the communication methods described in the first aspect and any one of the first aspect, or the second aspect and any one of the second aspect, or the third aspect and any one of the third aspect.
[0104] In a thirteenth aspect, a program product is provided, comprising a computer program that, when executed by a communication device, causes the communication device to perform the method described in the first aspect and any one of the first aspects, or in the second aspect and any of the second aspects, or in the third aspect and any of the third aspects.
[0105] In a fourteenth aspect, embodiments of this disclosure provide a computer program that, when run on a computer, causes the computer to perform the methods described in an optional implementation of the first, second, or third aspect.
[0106] In a fifteenth aspect, embodiments of this disclosure provide a chip or chip system. The chip or chip system includes processing circuitry configured to perform the methods described according to optional implementations of the first, second, or third aspects above.
[0107] It is understood that the terminals, access network devices, first network elements, other network elements, core network devices, communication systems, storage media, program products, computer programs, chips, or chip systems involved in the embodiments of this disclosure are all used to execute the methods proposed in the embodiments of this disclosure. Therefore, the beneficial effects that can be achieved can be referred to the beneficial effects in the corresponding methods, and will not be repeated here.
[0108] This disclosure provides communication methods, communication devices, communication systems, and storage media. In some embodiments, the terms "communication method" and "information processing method" can be used interchangeably, as can the terms "communication device" and "information processing device" and "communication device," and the terms "information processing system" and "communication system."
[0109] The communication devices described in this disclosure may include, for example, remote terminals, relay devices, network devices, etc., but are not limited to these.
[0110] This disclosure is not exhaustive, but merely illustrative of some embodiments, and is not intended to limit the scope of protection of this disclosure. Unless otherwise specified, each step in a particular embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a particular embodiment can also be implemented as an independent embodiment, and the order of the steps in a particular embodiment can be arbitrarily interchanged. Furthermore, the optional implementation methods in a particular embodiment can be arbitrarily combined; moreover, the embodiments can be arbitrarily combined, for example, some or all steps of different embodiments can be arbitrarily combined, and a particular embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.
[0111] In each of the disclosed embodiments, unless otherwise specified or in case of logical conflict, the terminology and / or descriptions of the embodiments are consistent and can be referenced by each other. The technical environments of different embodiments can be combined to form new embodiments according to their inherent logical relationships.
[0112] The terminology used in the embodiments of this disclosure is for the purpose of describing particular embodiments only and is not intended to limit the scope of this disclosure.
[0113] In this embodiment of the disclosure, unless otherwise stated, elements expressed in the singular form, such as "a," "an," "the," "the," "the," "the," "the," "the," "this," etc., can mean "one and only one," or "one or more," "at least one," etc. For example, when using articles such as "a," "an," "the," etc. in translation, the noun following the article can be understood as either a singular expression or a plural expression.
[0114] In the embodiments disclosed herein, "multiple" refers to two or more.
[0115] In some embodiments, the terms “at least one of”, “one or more”, “a plurality of”, “multiple”, etc., may be used interchangeably.
[0116] In some embodiments, the notation "at least one of A and B", "A and / or B", "A in one case, B in another", "in response to one case A, in response to another case B", etc., may include the following technical solutions depending on the situation: in some embodiments, A (execute A regardless of B); in some embodiments, B (execute B regardless of A); in some embodiments, execution is selected from A and B (A and B are selectively executed); in some embodiments, A and B (both A and B are executed). The same applies when there are more branches such as A, B, C, etc.
[0117] In some embodiments, the notation "A or B" may include the following technical solutions, depending on the situation: in some embodiments, A (execution of A regardless of B); in some embodiments, B (execution of B regardless of A); in some embodiments, execution is selected from A and B (A and B are selectively executed). The same applies when there are more branches such as A, B, C, etc.
[0118] The prefixes "first," "second," etc., used in the embodiments of this disclosure are merely for distinguishing different descriptive objects and do not impose restrictions on the position, order, priority, quantity, or content of the descriptive objects. The description of the descriptive objects is found in the claims or the context of the embodiments, and the use of prefixes should not constitute unnecessary restrictions. For example, if the descriptive object is a "field," the ordinal numbers preceding "field" in "first field" and "second field" do not restrict the position or order of the "fields." "First" and "second" do not restrict whether the "fields" they modify are in the same message, nor do they restrict the order of "first field" and "second field." Similarly, if the descriptive object is a "level," the ordinal numbers preceding "level" in "first level" and "second level" do not restrict the priority between "levels." Furthermore, the number of descriptive objects is not limited by ordinal numbers and can be one or more. For example, in "first device," the number of "devices" can be one or more. Furthermore, the objects modified by different prefixes can be the same or different. For example, if the object being described is "device", then "first device" and "second device" can be the same device or different devices, and their types can be the same or different. Similarly, if the object being described is "information", then "first information" and "performance of each AI model" can be the same information or different information, and their content can be the same or different.
[0119] In some embodiments, “including A,” “containing A,” “for indicating A,” and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.
[0120] In some embodiments, the terms “in response to…”, “in response to determining…”, “in the case of…”, “when…”, “if…”, “if…”, etc., can be used interchangeably.
[0121] In some embodiments, the terms “greater than,” “greater than or equal to,” “not less than,” “more than,” “more than or equal to,” “not less than,” “higher than,” “higher than or equal to,” “not lower than,” and “above” can be used interchangeably, as can the terms “less than,” “less than or equal to,” “not greater than,” “less than,” “less than or equal to,” “not more than,” “lower than,” “lower than or equal to,” “not higher than,” and “below”.
[0122] In some embodiments, the apparatus and device may be interpreted as physical or virtual, and their names are not limited to the names recorded in the embodiments. In some cases, they may also be understood as "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", "body", etc.
[0123] In some embodiments, "network" can be interpreted as devices included in the network, such as access network devices, core network devices, etc.
[0124] In some embodiments, "access network device (AN device)" may also be referred to as "radio access network device (RAN device)," "base station (BS)," "radio base station," or "fixed station." In some embodiments, it may also be understood as "node," "access point," "transmission point (TP)," "reception point (RP)," "transmission / reception point (TRP)," "panel," "antenna panel," "antenna array," "cell," "macro cell," "small cell," "femto cell," "pico cell," "sector," "cell group," "serving cell," "carrier," "component carrier," or "bandwidth part (BWP)."
[0125] In some embodiments, "terminal" or "terminal device" may be referred to as "user equipment (UE)," "user terminal," "mobile station (MS)," "mobile terminal (MT)," "subscriber station," "mobile unit," "subscriber unit," "wireless unit," "remote unit," "mobile device," "wireless device," "wireless communication device," "remote device," "mobile subscriber station," "access terminal," "mobile terminal," "wireless terminal," "remote terminal," "handset," "user agent," "mobile client," "client," etc.
[0126] In some embodiments, the acquisition of data, information, etc., may comply with the laws and regulations of the country where the location is situated.
[0127] In some embodiments, data, information, etc., may be obtained with the user's consent.
[0128] Furthermore, each element, each row, or each column in the table of this disclosure can be implemented as an independent embodiment, and any combination of any element, any row, or any column can also be implemented as an independent embodiment.
[0129] To support communication between user equipment (UE) and the network outside network coverage, Proximity-based Services (ProSe) are introduced. In single-hop ProSe, remote UEs communicate with network equipment through UE-to-Network Relay (U2N) relay equipment. Here, remote UEs can also be referred to as remote terminals, which is not limited in this disclosure.
[0130] Currently, standards have discussed aspects such as the discovery, selection, authorization, connection establishment, and data transmission of U2N relay devices in single-hop proximity services. Multi-hop proximity services have also been introduced, where remote terminals establish connections with U2N relay devices through one or more intermediate relay devices and communicate with network devices. Intermediate relay devices are proximity service terminals (ProSe UEs) located on the path between the remote UE and the U2N relay device, providing support for ProSe UEs to connect to network devices, thus supporting multi-hop proximity services. Multi-hop proximity services can also be referred to as multi-hop relay services; this disclosure does not limit the terminology.
[0131] Figure 1a is a schematic diagram of a communication system architecture according to an embodiment of the present disclosure.
[0132] As shown in Figure 1a, this disclosure provides a communication system architecture, introducing a communication system in which a remote terminal communicates with network devices based on an intermediate relay device. In Figure 1a, the remote terminal communicates with a U2N relay device through at least one intermediate relay device, and the U2N relay device then communicates with the network devices, enabling communication between the remote terminal and the network devices. The network devices include access network devices, namely the next-generation radio access network (NG-RAN) in Figure 1a, core network devices, namely the 5G core network (5GCN) and data network in Figure 1a, etc.
[0133] Specifically, communication between remote terminals and intermediate relay devices, and between intermediate relay devices and U2N relay devices, can be based on proximity communication (PC5) links. Communication between U2N relay devices and network relay devices can be based on the user-to-network interface universal (Uu) interface. Communication between core network devices and the data network is based on the network 6 (N6) interface.
[0134] However, in multi-hop proximity services, the security of communication between remote terminals and U2N relay devices cannot be guaranteed. For example, if confidentiality and / or integrity protection is enabled on some links but not on others, potential security and / or privacy vulnerabilities exist. For instance, an attacker could intercept data transmitted over a PC5 link without confidentiality and / or integrity protection.
[0135] Therefore, this disclosure provides a communication method in which a remote terminal sends a first message to a first relay device through at least one second relay device to request the establishment of a first secure communication link, thereby achieving end-to-end security protection between the remote terminal and the first relay device and realizing communication security in multi-hop proximity service scenarios.
[0136] Figure 1b is a schematic diagram of a communication system architecture according to an embodiment of the present disclosure.
[0137] As shown in Figure 1b, the communication system 100 includes a remote terminal 101, a first relay device 102, and a second relay device 103.
[0138] In this system, the remote terminal 101 communicates with the first relay device 102 through at least one second relay device 103, and the first relay device 102 then establishes communication with the network device to realize communication between the remote terminal and the network device.
[0139] In some embodiments, the communication system 100 may further include a network device 104.
[0140] In some embodiments, the first relay device 102 may be, for example, an intermediate relay device. The name of the first relay device is not limited herein. The second relay device 103 may be, for example, a U2N relay device.
[0141] In some embodiments, there may be one or more second relay devices 103. That is, there may be one or more second relay devices 103 between the remote terminal 101 and the first relay device 102.
[0142] In some embodiments, the terminal includes, but is not limited to, at least one of the following: mobile phone, wearable device, Internet of Things device, car with communication function, smart car, tablet computer, computer with wireless transceiver function, virtual reality (VR) terminal device, augmented reality (AR) terminal device, wireless terminal device in industrial control, wireless terminal device in self-driving, wireless terminal device in remote medical surgery, wireless terminal device in smart grid, wireless terminal device in transportation safety, wireless terminal device in smart city, and wireless terminal device in smart home.
[0143] In some embodiments, the network device may include at least one of an access network device and a core network device.
[0144] In some embodiments, the access network device is, for example, a node or device that connects a terminal to a wireless network. The access network device may include, but is not limited to, at least one of the following in a 5G communication system: evolved Node B (eNB), next-generation eNB (ng-eNB), next-generation Node B (gNB), node B (NB), home node B (HNB), home evolved node B (HeNB), radio backhaul device, radio network controller (RNC), base station controller (BSC), base transceiver station (BTS), base band unit (BBU), mobile switching center, base station in a 6G communication system, open RAN, cloud RAN, base station in other communication systems, and access node in a Wi-Fi system.
[0145] In some embodiments, the technical solutions of this disclosure can be applied to the Open RAN architecture. In this case, the interfaces between or within access network devices involved in the embodiments of this disclosure can be transformed into internal interfaces of Open RAN. The processes and information interactions between these internal interfaces can be implemented by software or programs.
[0146] In some embodiments, the access network device may be composed of a central unit (CU) and a distributed unit (DU). The CU may also be called a control unit. The CU-DU structure can separate the protocol layer of the access network device. Some of the protocol layer functions are centrally controlled by the CU, while the remaining part or all of the protocol layer functions are distributed in the DU and centrally controlled by the CU. However, this is not the only possibility.
[0147] In some embodiments, a core network device may be a single device comprising one or more network elements, or it may be multiple devices or a group of devices, each comprising all or part of the aforementioned one or more network elements. Network elements may be virtual or physical. The core network may include, for example, at least one of an Evolved Packet Core (EPC), a 5G Core Network (5GCN), or a Next Generation Core (NGC).
[0148] It is understood that the communication system described in this disclosure is for the purpose of more clearly illustrating the technical solutions of this disclosure, and does not constitute a limitation on the technical solutions proposed in this disclosure. As those skilled in the art will know, with the evolution of system architecture and the emergence of new business scenarios, the technical solutions proposed in this disclosure are also applicable to similar technical problems.
[0149] The following embodiments of this disclosure can be applied to the communication system 100 shown in FIG1, or to some of the main bodies, but are not limited thereto. The main bodies shown in FIG1 are illustrative. The communication system may include all or some of the main bodies in FIG1, or may include other main bodies outside of FIG1. The number and form of each main body are arbitrary. Each main body may be physical or virtual. The connection relationship between the main bodies is illustrative. The main bodies may not be connected or may be connected. The connection can be in any way, it can be a direct connection or an indirect connection, it can be a wired connection or a wireless connection.
[0150] The embodiments disclosed herein can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New radio access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), and IEEE 802.20, Ultra-Wideband (UWB), Bluetooth (a registered trademark), Public Land Mobile Network (PLMN) networks, Device-to-Device (D2D) systems, Machine-to-Machine (M2M) systems, Internet of Things (IoT) systems, Vehicle-to-Everything (V2X) systems, systems utilizing other communication methods, and next-generation systems built upon them, etc. Furthermore, multiple systems can be combined (e.g., a combination of LTE or LTE-A with 5G).
[0151] Figure 2 is a schematic diagram of a communication method interaction according to an embodiment of the present disclosure. As shown in Figure 2, this embodiment of the present disclosure relates to a communication method for a communication system 100, the method including:
[0152] In step S2101, the remote terminal 101 discovers the first relay device 102 through at least one second relay device 103.
[0153] In some embodiments, a remote terminal can discover a first relay device through at least one second relay device. For example, the remote terminal discovers a second relay device that can be used for communication within its communication range, and that second relay device discovers other second relay devices within its communication range, until one of the second relay devices discovers a first relay device that can be used for communication within its communication range. As another example, if the remote terminal discovers a second relay device that can be used for communication within its communication range, and that second relay device has already established a communication link with other second relay devices, and those other second relay devices have already established a communication link with the first relay device, then the remote terminal can discover the first relay device through at least one second relay device.
[0154] In step S2102, the remote terminal 101 sends a first message to the second relay device 103.
[0155] In some embodiments, the remote terminal 101 sends a first message to the second relay device 103, and correspondingly, the second relay device 103 can receive the first message sent by the remote terminal 101.
[0156] In step S2103, the second relay device 103 sends a first message to the first relay device 102.
[0157] In some embodiments, the second relay device 103 may send the first message to the first relay device 102. Correspondingly, the first relay device 102 receives the first message sent by the second relay device 103. For example, the second relay device may directly forward the first message. When the second relay device directly forwards the first message, it can be understood that the remote terminal 101 sends the first message to the first relay device 102 through at least one second relay device 103. Correspondingly, the first relay device 102 receives the first message sent by the remote terminal 101 through at least one second relay device 103. Alternatively, the second relay device may process the first message before sending it to the first relay device.
[0158] In some embodiments, there may be one or more second relay devices. When there is only one second relay device 103, the second relay device 103 receives the first message sent by the remote terminal 101 and sends the first message to the first relay device 102. When there are multiple second relay devices 103, the remote terminal 101 can send the first message to the nearest second relay device 103 and continue to pass it on to other second relay devices 103 until it is passed on to the second relay device 103 closest to the first relay device 102, which then sends the first message to the first relay device 102.
[0159] In some embodiments, the first message is used to request the establishment of a first link between the remote terminal and the first relay device, the first link being used for secure communication between the remote terminal and the first relay device based on at least one second relay device, including a second relay device.
[0160] In some embodiments, the first message includes at least one of the following: an identifier related to the remote terminal; a random number; a first communication security policy between the remote terminal and the first relay device, the first communication security policy being used to determine the method of secure communication based on the first link; and a second communication security policy between the remote terminal and the second relay device, the second communication security policy being used to determine the method of secure communication based on the second link, the second link being used for secure communication between the remote terminal and the second relay device.
[0161] Optionally, the first message may include an identifier of the remote terminal. For example, it may include the remote user key identifier (PRUK ID), the user concealed identifier (SUCI), the relay service code (RSC), and the home public land mobile network identifier (HPLMN ID). The remote terminal identifier can be used, for example, to obtain and generate a key for security verification, or, for example, to be used by the first relay device to directly report the remote terminal's information to the network device after communication is established.
[0162] Optionally, the first message may include a random number. For example, the random number can be used to generate a key for verifying security.
[0163] Optionally, the first message may include a first communication security policy. The first communication security policy is used to determine the method of secure communication based on the first link. After receiving the first message, the first relay device can determine whether to establish end-to-end security between the remote terminal and the first relay based on the first communication security policy. For example, if the first communication security policy indicates protection of signaling integrity and confidentiality, a second message can be generated to establish end-to-end security. Here, the first link is an end-to-end logical link between the remote terminal and the first relay device, and the first communication security policy is used to establish end-to-end secure communication between the remote terminal and the first relay device.
[0164] Optionally, the first message may include a second communication security policy. The second communication security policy determines the method of secure communication based on a second link, which is used for secure communication between the remote terminal and the second relay device. The second link is a link between the remote terminal and the second relay device. The second communication security policy is used to establish non-end-to-end secure communication between the remote terminal and the second relay device.
[0165] In some embodiments, the second relay device can directly forward the first message. Alternatively, the second relay device can process the first message before sending it to the first relay device. For example, the second relay device can add information from other second relay devices to the first message before sending it. For instance, the information from the second relay device may include security algorithms supported by the second relay device. The second relay device can add these supported security algorithms to the first message to establish secure communication between the two relay devices, or to establish secure communication between the second relay device and the first relay device. That is, the second communication security policy can also be used to determine the method of secure communication based on a third link and / or a fourth link. The third link is the communication link between different second relay devices. The fourth link is the communication link between the second relay device and the first relay device. For ease of understanding, assume a remote terminal communicates with the first relay device through second relay device A and second relay device B. The remote terminal can send the first message to second relay device A, and assume that the first message can contain both the first and second communication security policies. Second relay device A can include its own information in the first message and send the first message to second relay device B. The first message received by second relay device B contains a first communication security policy, a second communication security policy, and information about second relay device A. If second relay device B includes its own information in the first message and sends the first message to the first relay device, then the first message received by the first relay device contains the first communication security policy, the second communication security policy, information about second relay device A, and information about second relay device B.
[0166] In some embodiments, the first communication security policy includes at least one of the following: a policy indicating whether to protect signaling integrity; a policy indicating whether to protect signaling confidentiality; a policy indicating whether to protect data integrity; and a policy indicating whether to protect data confidentiality.
[0167] Optionally, the first communication security policy may include a policy indicating whether to protect signaling integrity. When the first communication security policy includes a policy indicating whether to protect signaling integrity, the first relay device can correspondingly determine whether to request signaling integrity to establish the first link based on the first communication security policy. It is understood that signaling integrity is a type of security. For example, if the first communication security policy indicates protection of signaling integrity, after receiving the first message, the first relay device can generate a second message requesting the establishment of signaling integrity based on the first communication security policy included in the first message.
[0168] Optionally, the first communication security policy may include a policy indicating whether to protect signaling confidentiality. When the first communication security policy includes a policy indicating whether to protect signaling confidentiality, the first relay device can correspondingly determine whether to request signaling confidentiality for establishing the first link based on the first communication security policy. It is understood that signaling confidentiality is a type of security.
[0169] Optionally, the first communication security policy may include a policy indicating whether to protect data integrity. When the first communication security policy includes a policy indicating whether to protect signaling confidentiality, the first relay device can correspondingly determine whether to request the establishment of the first link based on the first communication security policy regarding data integrity. It is understood that data integrity is a type of security.
[0170] Optionally, the first communication security policy may include a policy indicating whether to protect data confidentiality. When the first communication security policy includes a policy indicating whether to protect data confidentiality, the first relay device can correspondingly determine whether to request the establishment of data confidentiality for the first link based on the first communication security policy. It is understood that data confidentiality is a type of security.
[0171] In some embodiments, the communication security policies may be configured by network devices. For example, a policy control function (PCF) may distribute communication security policies. For instance, the PCF may distribute a first communication security policy and / or a second communication security policy to a remote terminal. The first communication security policy is used to establish end-to-end communication security between the remote terminal and a first relay device. The second communication policy may be used to establish communication security between the remote terminal and a second relay device, and / or between different second relay devices, and / or between a second relay device and a first relay device.
[0172] In some embodiments, the name of the first message is not limited, and it may be, for example, a "request message", an "instruction message", etc.
[0173] Step S2104: Remote terminal 101 establishes a second link.
[0174] In some embodiments, the first message can be used to trigger the establishment of a second link. The second link is a communication link between the remote terminal and the second relay device. After the remote terminal 101 sends the first message to the second relay device, a second link is established between the remote terminal 101 and the second relay device. For example, the establishment of the communication link can be triggered by a direct communication request (DCR). The first message can be a DCR used to trigger the establishment of the communication link; that is, the first message can be used to trigger the establishment of the second link. In some cases, the first message can also be called a multi-hop communication request; that is, the first message can be a special type of DCR, which is not limited in this disclosure.
[0175] In some embodiments, the remote terminal may first establish a second link and then send a first message based on the second link. That is, in this embodiment, the first message may not be used to trigger the establishment of the second link. Instead, the remote terminal pre-establishes a second link with the second relay device. For example, the remote terminal may pre-send a DCR to the second relay device to establish the second link and then send the first message based on the second link.
[0176] In step S2105, the second relay device 103 establishes a third link and / or a fourth link.
[0177] In some embodiments, the third link is used for secure communication between at least one second relay device. The fourth link is used for secure communication between the second relay device and the first relay device.
[0178] In some embodiments, the first message can be used to trigger the establishment of a third link. The third link is a communication link between the second relay devices. When the remote terminal sends the first message to the nearest second relay device, the second relay device continues to send the first message to the next second relay device, until it is sent to the second relay device closest to the first relay device. The first message can be used to trigger the establishment of a third link between the first and second second relay devices. That is, after the first second relay device sends the first message to the second second relay device, a third link is established between it and the second second relay device. In this embodiment, the second relay device closest to the remote terminal is designated as the first second relay device, and the next second relay device communicating with the first relay device is designated as the second second relay device. This is similar to the second relay devices A and B in the other embodiments described above. Correspondingly, after the second second relay device sends the first message to the third second relay device, a third link is established between it and the third second relay device. This continues until the last second relay device sends the first message to the first relay device, establishing a fourth link between it and the first relay device.
[0179] In some embodiments, the second relay device may first establish a third link and / or a fourth link, and then send a first message based on the third link and / or the fourth link. For example, the first second relay device establishes a third link with the second second relay device and sends a first message to the next second relay device based on the third link. As another example, the last second relay device establishes a fourth link with the first relay device and sends a first message to the first relay device based on the fourth link.
[0180] In some embodiments, step S2105 is optional. If a third link between different second relay devices is pre-established, then the second relay device does not need to establish a third link and can send the first message to the next second relay device based on the pre-established third link. Similarly, if a fourth link between a second relay device and a first relay device is pre-established, then the second relay device does not need to establish a fourth link and can send the first message to the first relay device based on the pre-established fourth link.
[0181] In step S2106, the first relay device 102 generates a second message based on the first message.
[0182] In some embodiments, the first relay device 102 may generate a second message based on the first message. For example, the first message may include a first communication security policy, and the first communication security policy may include a policy indicating the protection of signaling integrity. Then, the second relay device may generate a second message for establishing the signaling integrity of the first link. The second message is used to request security for establishing the first link; it can be understood that signaling integrity is a type of security.
[0183] In some embodiments, the first relay device may send a key request to the network device based on the relevant identifier of the remote terminal in the first message, requesting the network device to return a key. A second message is generated according to the key and communication security policy. For example, a key to protect the second message can be generated based on parameters, and these parameters can be included in the second message. When the remote terminal receives the second message and derives the key based on the parameters in the second message, the security of the second message can be determined based on the derived key. The network device may be a policy control function (PCF), a proximity key management function (KMF), a direct discovery name management function (DDNMF), etc. Alternatively, the network device may be an authentication server function (AUSF), a policy and authentication function (PAnF), etc.
[0184] In some embodiments, the first relay device may generate a corresponding second message based on the first message. The second message is used to request the establishment of security for the first link, and may also be used to request the establishment of non-end-to-end security between the communication nodes.
[0185] In some embodiments, the second message may be, for example, a direct safe mode command.
[0186] In some embodiments, the name of the second message is not limited, and it may be, for example, a "verification message".
[0187] In step S2107, the first relay device 102 sends a second message to the second relay device 103.
[0188] In some embodiments, the first relay device 102 sends a second message to the second relay device 103. Accordingly, the second relay device 103 receives the second message sent by the first relay device 102.
[0189] In step S2108, the second relay device 103 sends a second message to the remote terminal 101.
[0190] In some embodiments, the second relay device 103 sends a second message to the remote terminal 101. Accordingly, the remote terminal 101 receives the second message sent by the second relay device 103. When the second relay device 103 directly forwards the second message, it can be understood that the first relay device 102 sends the second message to the remote terminal 101 through at least one second relay device 103. Accordingly, the remote terminal 101 receives the second message sent by the first relay device 102 through at least one second relay device 103.
[0191] In some embodiments, the second relay device 103 may be one or more, as detailed in the above embodiments, which will not be repeated here.
[0192] In some embodiments, the second message is used to request security for establishing the first link. For example, the remote terminal can deduce a key based on the parameters in the second message and determine the security of the second message based on the deduced key. If the security verification of the second message is successful, the remote terminal sends a third message to the first relay device to inform the first relay device that the verification has passed. The third message indicates that the security verification has passed. After receiving the third message, the first relay device sends a fourth message to the remote terminal to establish the first link. The fourth message indicates that the first relay device accepts the request of the first message. In addition, the first relay device may also send relevant information about the terminal to the network device.
[0193] In step S2109, the remote terminal 101 performs security verification on the second message.
[0194] In some embodiments, the remote terminal 101 can perform security verification on the second message. For example, the remote terminal can derive a key based on the parameters in the second message and the first communication security policy, and can verify the second message based on the derived key.
[0195] In step S2110, remote terminal 101 confirms that the security verification has passed.
[0196] In some embodiments, the remote terminal 101 may determine that the security verification is successful based on the security verification performed on the second message.
[0197] In step S2111, the remote terminal 101 sends a third message to the second relay device 103.
[0198] In some embodiments, the remote terminal 101 may send a third message to the second relay device 103. Accordingly, the second relay device 103 may receive the third message sent by the remote terminal 101.
[0199] In step S2112, the second relay device 103 sends a third message to the first relay device 102.
[0200] In some embodiments, the second relay device 103 may send a third message to the first relay device 102. Correspondingly, the first relay device 102 receives the third message sent by the second relay device 103. When the second relay device directly forwards the third message, it can be understood that the remote terminal 101 sends the third message to the first relay device 102 through at least one second relay device 103. Correspondingly, the first relay device 102 receives the third message sent by the remote terminal 101 through at least one second relay device 103.
[0201] In some embodiments, the second relay device 103 may be one or more, as detailed in the above embodiments, which will not be repeated here.
[0202] In some embodiments, the third message is used to indicate that the security verification has passed.
[0203] In some embodiments, the name of the third message is not limited, and it may be, for example, "security mode complete message" or "feedback message".
[0204] In step S2113, the first relay device 102 sends a fourth message to the second relay device 103.
[0205] In some embodiments, the first relay device 102 may send a fourth message to the second relay device 103. Accordingly, the second relay device 103 receives the fourth message sent by the first relay device 102.
[0206] In step S2114, the second relay device 103 sends a fourth message to the remote terminal 101.
[0207] In some embodiments, the second relay device 103 can send a fourth message to the remote terminal 101. Accordingly, the remote terminal 101 receives the fourth message sent by the second relay device 103. When the second relay device directly forwards the fourth message, it can be understood that the first relay device 102 sends the fourth message to the remote terminal 101 through at least one second relay device 103. Accordingly, the remote terminal 101 receives the fourth message sent by the first relay device 102 through at least one second relay device 103.
[0208] In some embodiments, the second relay device 103 may be one or more, as detailed in the above embodiments, which will not be repeated here.
[0209] In some embodiments, the fourth message is used to instruct the first relay device to accept the request of the first message.
[0210] In some embodiments, the name of the fourth message is not limited, and it may be, for example, "accept message".
[0211] In some embodiments, the communication system 100 may include a network device 104, and the communication method described above provided in this disclosure may further include the following step S2115.
[0212] In step S2115, the first relay device 102 sends relevant information about the remote terminal to the network device 104.
[0213] In some embodiments, network device 104 receives information about a remote terminal sent by first relay device 102. For example, information about a remote terminal can be sent via a remote terminal report.
[0214] In some embodiments, the relevant information of the remote terminal may include the user ID of the remote terminal, the HPLMN ID of the remote terminal, etc.
[0215] The communication method involved in the embodiments of this disclosure may include at least one of steps S2101 to S2115. Steps S2101 to S2115 can each be a separate embodiment, and the embodiments can be arbitrarily combined and implemented in different orders without contradiction. For example, step S2102 can be implemented as an independent embodiment, but is not limited thereto.
[0216] In some embodiments, certain steps are optional, and one or more of these steps may be omitted or substituted in different embodiments. For example, step S2105 is optional.
[0217] In some embodiments, other optional implementations described before or after the specification corresponding to FIG2 may be referred to.
[0218] Figure 3a is a flowchart illustrating a communication method according to an embodiment of the present disclosure. As shown in Figure 3a, this embodiment of the present disclosure relates to a communication method executed by a remote terminal 101, the method including:
[0219] Step S3101: The first relay device 102 is detected through at least one second relay device 103.
[0220] The optional implementation of step S3101 can be found in the optional implementation of step S2101 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.
[0221] Step S3102: Send the first message.
[0222] The optional implementation of step S3102 can be found in the optional implementation of step S2102 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.
[0223] In some embodiments, the remote terminal 101 sends a first message to the second relay device 103, but is not limited to that; it may also send the first message to other entities.
[0224] Step S3103: Establish the second link.
[0225] The optional implementation of step S3103 can be found in the optional implementation of step S2104 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.
[0226] Step S3104: Obtain the second message.
[0227] The optional implementation of step S3104 can be found in the optional implementation of step S2107 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.
[0228] In some embodiments, the remote terminal 101 receives a second message sent by the second relay device 103, but is not limited thereto; it may also receive a second message sent by other entities.
[0229] In some embodiments, the remote terminal 101 obtains a second message defined by the protocol.
[0230] In some embodiments, the remote terminal 101 obtains a second message from the upper layer(s).
[0231] In some embodiments, the remote terminal 101 processes the data to obtain the second message.
[0232] In some embodiments, step S3104 is omitted, and the remote terminal 101 autonomously implements the function indicated by the second message, or the above function is the default or default.
[0233] Step S3105: Perform security verification on the second message.
[0234] The optional implementation of step S3105 can be found in the optional implementation of step S2109 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.
[0235] Step S3106: Confirm that the security verification has passed.
[0236] The optional implementation of step S3106 can be found in the optional implementation of step S2110 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.
[0237] Step S3107: Send the third message.
[0238] The optional implementation of step S3107 can be found in the optional implementation of step S2111 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.
[0239] In some embodiments, the remote terminal 101 sends a third message to the first relay device 102, but this is not limited to that; the third message may also be sent to other entities.
[0240] Step S3108: Obtain the fourth message.
[0241] The optional implementation of step S3108 can be found in the optional implementation of step S2113 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.
[0242] In some embodiments, the remote terminal 101 receives a fourth message sent by the second relay device 103, but is not limited thereto; it may also receive a fourth message sent by other entities.
[0243] In some embodiments, the remote terminal 101 obtains a fourth message as defined by the protocol.
[0244] In some embodiments, the remote terminal 101 obtains a fourth message from the upper layer(s).
[0245] In some embodiments, the remote terminal 101 processes the data to obtain the fourth message.
[0246] In some embodiments, step S3108 is omitted, and the remote terminal 101 autonomously implements the function indicated by the fourth message, or the above function is the default or default.
[0247] The communication method involved in the embodiments of this disclosure may include at least one of steps S3101 to S3108. Each of steps S3101 to S3108 can be a separate embodiment, and the embodiments can be arbitrarily combined and their order adjusted without contradiction. For example, step S3102 can be implemented as an independent embodiment, but is not limited thereto.
[0248] In some embodiments, certain steps are optional, and one or more of these steps may be omitted or substituted in different embodiments.
[0249] In some embodiments, other alternative implementations may be described before or after the specification corresponding to FIG3a.
[0250] Figure 3b is a flowchart illustrating a communication method according to an embodiment of the present disclosure. As shown in Figure 3b, this embodiment of the present disclosure relates to a communication method executed by a remote terminal 101, the method including:
[0251] Step S3201: Send the first message.
[0252] The optional implementation of step S3201 can be found in the optional implementation of step S2102 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.
[0253] In some embodiments, the remote terminal 101 sends a first message to the second relay device 103, but is not limited to that; it may also send the first message to other entities.
[0254] Figure 4a is a flowchart illustrating a communication method according to an embodiment of the present disclosure. As shown in Figure 4a, this embodiment of the present disclosure relates to a communication method executed by a first relay device 102, the method comprising:
[0255] Step S4101: Obtain the first message.
[0256] The optional implementation of step S4101 can be found in the optional implementation of step S2102 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.
[0257] In some embodiments, the first relay device 102 receives a first message sent by the second relay device 103, but is not limited thereto; it may also receive a first message sent by other entities.
[0258] In some embodiments, the first relay device 102 receives a first message as defined by the protocol.
[0259] In some embodiments, the first relay device 102 obtains a first message from the upper layer(s).
[0260] In some embodiments, the first relay device 102 processes the data to obtain the first message.
[0261] In some embodiments, step S4101 is omitted, and the first relay device 102 autonomously implements the function indicated by the first message, or the above function is a default or default setting.
[0262] Step S4102: Generate a second message based on the first message.
[0263] The optional implementation of step S4102 can be found in the optional implementation of step S2106 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.
[0264] In some embodiments, the second message is generated based on the first message.
[0265] Step S4103: Send the second message.
[0266] The optional implementation of step S4103 can be found in the optional implementation of step S2107 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.
[0267] In some embodiments, the first relay device 102 sends a second message to the second relay device 103, but is not limited to that; it may also send a second message to other entities.
[0268] Step S4104: Obtain the third message.
[0269] The optional implementation of step S4104 can be found in the optional implementation of step S2110 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.
[0270] In some embodiments, the first relay device 102 receives a third message sent by the second relay device 103, but is not limited thereto; it may also receive a third message sent by other entities.
[0271] In some embodiments, the first relay device 102 acquires a third message defined by the protocol.
[0272] In some embodiments, the first relay device 102 obtains a third message from the upper layer(s).
[0273] In some embodiments, the first relay device 102 processes the data to obtain the third message.
[0274] In some embodiments, step S4104 is omitted, and the first relay device 102 autonomously implements the function indicated by the third message, or the above function is defaulted or set to default.
[0275] Step S4105: Send the fourth message.
[0276] The optional implementation of step S4105 can be found in the optional implementation of step S2113 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.
[0277] In some embodiments, the first relay device 102 sends a fourth message to the second relay device 103, but is not limited to that; it may also send a fourth message to other entities.
[0278] Step S4106: Send relevant information from the remote terminal.
[0279] The optional implementation of step S4106 can be found in the optional implementation of step S2115 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.
[0280] In some embodiments, the first relay device 102 sends relevant information about the remote terminal to the network device 104, but is not limited to this; it may also send relevant information about the remote terminal to other entities.
[0281] Figure 4b is a flowchart illustrating a communication method according to an embodiment of the present disclosure. As shown in Figure 4b, this embodiment of the present disclosure relates to a communication method executed by a first relay device 102, the method comprising:
[0282] Step S4201: Obtain the first message.
[0283] The optional implementation of step S4201 can be found in the optional implementation of step S2102 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.
[0284] In some embodiments, the first relay device 102 receives a first message sent by the second relay device 103, but is not limited thereto; it may also receive a first message sent by other entities.
[0285] In some embodiments, the first relay device 102 receives a first message as defined by the protocol.
[0286] In some embodiments, the first relay device 102 obtains a first message from the upper layer(s).
[0287] In some embodiments, the first relay device 102 processes the data to obtain the first message.
[0288] In some embodiments, step S4201 is omitted, and the first relay device 102 autonomously implements the function indicated by the first message, or the above function is default or default.
[0289] Figure 5a is a flowchart illustrating a communication method according to an embodiment of the present disclosure. As shown in Figure 5a, this embodiment of the present disclosure relates to a communication method executed by a second relay device 103, the method comprising:
[0290] Step S5101: Obtain the first message.
[0291] The optional implementation of step S5101 can be found in the optional implementation of step S2102 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.
[0292] In some embodiments, the second relay device 103 receives a first message sent by the remote terminal 101, but is not limited thereto; it may also receive a first message sent by other entities.
[0293] In some embodiments, the second relay device 103 acquires a first message as defined by the protocol.
[0294] In some embodiments, the second relay device 103 obtains the first message from the upper layer(s).
[0295] In some embodiments, the second relay device 103 processes the data to obtain the first message.
[0296] In some embodiments, step S5101 is omitted, and the second relay device 103 autonomously implements the function indicated by the first message, or the above function is defaulted or set to default.
[0297] Step S5102: Send the first message.
[0298] The optional implementation of step S5102 can be found in the optional implementation of step S2103 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.
[0299] In some embodiments, the second relay device 103 sends a first message to the first relay device 102, but is not limited thereto; it may also send the first message to other entities.
[0300] Step S5103: Establish the third link and / or the fourth link.
[0301] The optional implementation of step S5103 can be found in the optional implementation of step S2105 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.
[0302] Step S5104: Obtain the second message.
[0303] The optional implementation of step S5104 can be found in the optional implementation of step S2107 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.
[0304] In some embodiments, the second relay device 103 receives a second message sent by the first relay device 102, but is not limited thereto; it may also receive a second message sent by other entities.
[0305] In some embodiments, the second relay device 103 acquires a second message defined by the protocol.
[0306] In some embodiments, the second relay device 103 obtains the second message from the upper layer(s).
[0307] In some embodiments, the second relay device 103 processes the data to obtain the second message.
[0308] In some embodiments, step S5104 is omitted, and the second relay device 103 autonomously implements the function indicated by the second message, or the above function is defaulted or set to default.
[0309] Step S5105: Send the second message.
[0310] The optional implementation of step S5105 can be found in the optional implementation of step S2108 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.
[0311] In some embodiments, the second relay device 103 sends a second message to the remote terminal 101, but is not limited thereto; it may also send a second message to other entities.
[0312] Step S5106: Obtain the third message.
[0313] The optional implementation of step S5106 can be found in the optional implementation of step S2111 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.
[0314] In some embodiments, the second relay device 103 receives a third message sent by the remote terminal 101, but is not limited thereto; it may also receive a third message sent by other entities.
[0315] In some embodiments, the second relay device 103 acquires a third message defined by the protocol.
[0316] In some embodiments, the second relay device 103 obtains a third message from the upper layer(s).
[0317] In some embodiments, the second relay device 103 processes the data to obtain a third message.
[0318] In some embodiments, step S5104 is omitted, and the second relay device 103 autonomously implements the function indicated by the third message, or the above function is defaulted or set to default.
[0319] Step S5107: Send the third message.
[0320] The optional implementation of step S5107 can be found in the optional implementation of step S2112 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.
[0321] In some embodiments, the second relay device 103 sends a third message to the first relay device 102, but is not limited thereto; it may also send a third message to other entities.
[0322] Step S5108: Obtain the fourth message.
[0323] The optional implementation of step S5108 can be found in the optional implementation of step S2113 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.
[0324] In some embodiments, the second relay device 103 receives a fourth message sent by the first relay device 102, but is not limited thereto; it may also receive a fourth message sent by other entities.
[0325] In some embodiments, the second relay device 103 receives a fourth message as defined by the protocol.
[0326] In some embodiments, the second relay device 103 obtains a fourth message from the upper layer(s).
[0327] In some embodiments, the second relay device 103 processes the data to obtain the fourth message.
[0328] In some embodiments, step S5105 is omitted, and the second relay device 103 autonomously implements the function indicated by the fourth message, or the above function is defaulted or set to default.
[0329] Step S5109: Send the fourth message.
[0330] The optional implementation of step S5109 can be found in the optional implementation of step S2114 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.
[0331] In some embodiments, the second relay device 103 sends a fourth message to the remote terminal 101, but is not limited thereto; it may also send a fourth message to other entities.
[0332] Figure 5b is a flowchart illustrating a communication method according to an embodiment of the present disclosure. As shown in Figure 5b, this embodiment of the present disclosure relates to a communication method executed by a second relay device 103, the method comprising:
[0333] Step S5201: Obtain the first message.
[0334] The optional implementation of step S5201 can be found in the optional implementation of step S2102 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.
[0335] In some embodiments, the second relay device 103 receives a first message sent by the remote terminal 101, but is not limited thereto; it may also receive a first message sent by other entities.
[0336] In some embodiments, the second relay device 103 acquires a first message as defined by the protocol.
[0337] In some embodiments, the second relay device 103 obtains the first message from the upper layer(s).
[0338] In some embodiments, the second relay device 103 processes the data to obtain the first message.
[0339] In some embodiments, step S5201 is omitted, and the second relay device 103 autonomously implements the function indicated by the first message, or the above function is default or default.
[0340] Step S5202: Send the first message.
[0341] Optional implementations of step S5202 can be found in the optional implementations of step S2103 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here. In some embodiments, the second relay device 103 sends a first message to the first relay device 102, but is not limited to this; it can also send a first message to other entities.
[0342] Figure 6 is a schematic diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in Figure 6, this embodiment of the present disclosure relates to a communication method for a communication system 100, the method comprising:
[0343] In step S6101, the remote terminal 101 sends a first message to the second relay device 103.
[0344] In step S6102, the second relay device 103 receives the first message sent by the remote terminal 101.
[0345] In step S6103, the second relay device 103 sends a first message to the first relay device 102.
[0346] In step S6104, the first relay device 102 receives the first message sent by the second relay device 103.
[0347] In some embodiments, the above methods may include the methods of the embodiments related to the communication system 100, remote terminal 101, first relay device 102, second relay device 103, etc., which will not be described again here.
[0348] This disclosure takes two second relay devices, intermediate relay device 1 and intermediate relay device 2, and a first relay device as a U2N relay device. The network equipment includes PKMF / AUSF / PAnF, service management function (SMF), etc., as an example to provide a communication method as follows:
[0349] Figure 7 is a schematic diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in Figure 7, this embodiment of the present disclosure relates to a communication method for a communication system 100, the method comprising:
[0350] Step S7101: Establish PC5 links between intermediate relay device 1 and intermediate relay device 2, and between intermediate relay device 1 and U2N relay device.
[0351] In some embodiments, it is assumed that the intermediate relay device has established a PC5 link with the parent relay device (i.e., the U2N relay device or other intermediate relay devices).
[0352] However, step S7101 is optional.
[0353] In some embodiments, the PC5 link may be a third link and / or a fourth link.
[0354] Step S7102: U2N relay device detected.
[0355] In some embodiments, a remote UE discovers a U2N relay device through one or more intermediate relay devices.
[0356] Step S7103: Send a multi-hop communication request.
[0357] In some embodiments, the remote UE sends a multi-hop communication request to a selected intermediate relay device, triggering the establishment of a secure PC5 link between the remote UE and the intermediate relay device 2 in step S7104. The multi-hop communication request includes the remote UE's PRUK ID or SUCI, RSC, the remote UE's HPLMN ID, a random number (nonce) 1, and the communication security policy between the remote UE and the U2N relay device. The HPLMN ID is optional.
[0358] In some embodiments, a multi-hop communication request may be the first message in the above embodiments.
[0359] Step S7104: If there is no PC5 link between the remote terminal and the intermediate relay device 2, then establish a PC5 link between the remote terminal and the intermediate relay device 2.
[0360] In some embodiments, if no PC5 link exists between the remote UE and the intermediate relay device 2, a PC5 link establishment procedure is executed, i.e., a direct communication procedure or a U2N relay device communication procedure. Otherwise, this step is skipped. Executing the PC5 link establishment procedure establishes a PC5 link.
[0361] In some embodiments, steps S7103 and S7104 can be interchanged, i.e., the remote UE establishes a PC5 link with the intermediate relay device 2, and then sends a multi-hop communication request to the intermediate relay device 2 through the secure PC5 link.
[0362] Step S7105: Forward multi-hop communication requests.
[0363] In some embodiments, if step S7101 is not executed, i.e., no PC5 link is pre-established between intermediate relay device 1 and intermediate relay device 2, or between intermediate relay device 1 and the U2N relay device, then optionally, a multi-hop communication request can be used to trigger the establishment of PC5 links between intermediate relay device 1 and intermediate relay device 2, or between intermediate relay device 1 and the U2N relay device. Optionally, PC5 links are established between intermediate relay device 1 and intermediate relay device 2, or between intermediate relay device 1 and the U2N relay device, and multi-hop communication requests are forwarded based on the PC5 links between intermediate relay device 1 and intermediate relay device 2, or between intermediate relay device 1 and the U2N relay device.
[0364] In some embodiments, intermediate relay device 2 forwards multi-hop communication requests to the U2N relay device via (a plurality of) other intermediate relay devices (such as intermediate relay device 1).
[0365] Step S7106: Send a key request.
[0366] In some embodiments, upon receiving a multi-hop communication request, the U2N relay device sends a key request to the PKMF / AUSF / PAnF, as defined by the user plane (UP) or control plane (CP) U2N relay device security establishment procedure. The key request includes the remote UE's PRUK ID or SUCI.
[0367] Step S7107: Return the key.
[0368] In some embodiments, PKMF / AUSF / PAnF returns Knrp or Knr_prose and nonce 2 to the U2N relay device.
[0369] Step S7108: Send the direct safe mode command.
[0370] In some embodiments, the U2N relay device derives NRPEK and / or NRPIK based on Knrp or Knr_prose and according to a communication security policy (i.e., a first communication security policy) for communication between the remote UE and the U2N relay device. The U2N relay device sends a direct security mode command to the remote UE through (multiple) intermediate relay devices, and this command is protected by a key.
[0371] In some embodiments, the direct security mode command may be the second message in the above embodiments.
[0372] Step S7109: If the direct security mode command verification passes, a direct security mode completion message is sent.
[0373] In some embodiments, the remote UE generates NRPEK and NRPIK using parameters in the Direct Security Mode command according to the communication security policy (i.e., the first communication security policy). If the Direct Security Mode command verification passes, the remote UE responds to the U2N relay device with a Direct Security Mode completion message through (multiple) intermediate relay devices.
[0374] In some embodiments, the direct security mode completion message may be the third message in the above embodiments.
[0375] Step S7110: Send multi-hop communication reception information.
[0376] In some embodiments, the U2N relay device sends multi-hop communication acceptance information to the remote UE via an intermediate relay device. End-to-end security is established between the remote UE and the U2N relay device.
[0377] In some embodiments, the multi-hop communication reception information may be the fourth message in the above embodiments.
[0378] Step S7111: Report relevant information of the remote terminal.
[0379] In some embodiments, the U2N relay includes the remote user ID (i.e., the PRUK ID of the remote UE) and the HPLMN ID of the remote UE in the remote UE report, and sends relevant information of the remote terminal to the SMF of the U2N relay.
[0380] Figure 8a is a schematic diagram of the structure of the remote terminal 8100 proposed in this embodiment. As shown in Figure 8a, the remote terminal 8100 may include: a transceiver module 8101, used to send a first message to a second relay device, the first message being used to request the establishment of a first link between the remote terminal and the first relay device, the first link being used for secure communication between the remote terminal and the first relay device based on the second relay device.
[0381] In some embodiments, the first message includes at least one of the following: an identifier related to the remote terminal; a random number; a first communication security policy between the remote terminal and a first relay device, the first communication security policy being used to determine the method of secure communication based on a first link; and a second communication security policy between the remote terminal and a second relay device, the second communication security policy being used to determine the method of secure communication based on a second link, the second link being used for secure communication between the remote terminal and the second relay device.
[0382] In some embodiments, the transceiver module 8101 is further configured to: receive a second message sent by the second relay device, the second message being determined based on the first message, and the second message being used to request security for establishing the first link. The remote terminal also includes a processing module 8102, configured to perform security verification on the second message to determine that the security verification is successful. The transceiver module 8101 is further configured to: send a third message to the second relay device, the third message being used to indicate that the security verification is successful; and receive a fourth message sent by the second relay device, the fourth message being used to instruct the first relay device to accept the request of the first message.
[0383] In some embodiments, the first message is further used to trigger the establishment of a second link between the remote terminal and the second relay device, and the processing module 8102 is further used to: establish a second link between the remote terminal and the second relay device, the second link being used for secure communication between the remote terminal and the second relay device.
[0384] In some embodiments, the processing module 8102 is further configured to: establish a second link between the remote terminal and the second relay device, and the transceiver module 8101 is configured to send a first message to the second relay device in the following manner: based on the second link, send a first message to the second relay device, wherein the second link is used for secure communication between the remote terminal and the second relay device.
[0385] In some embodiments, the first message includes a first communication security policy, which includes at least one of the following: a policy indicating whether to protect signaling integrity; a policy indicating whether to protect signaling confidentiality; a policy indicating whether to protect data integrity; and a policy indicating whether to protect data confidentiality.
[0386] In some embodiments, the first communication security policy and / or the second communication security policy are configured by the network device to the remote terminal.
[0387] Figure 8b is a schematic diagram of the structure of the second relay device 8200 according to an embodiment of this disclosure. As shown in Figure 8b, the second relay device 8200 may include: a transceiver module 8201, used for...
[0388] Receive the first message sent by the remote terminal. Send the first message to the first relay device. The first message is used to request the establishment of a first link between the remote terminal and the first relay device. The first link is used for secure communication between the remote terminal and the first relay device based on the second relay device.
[0389] In some embodiments, the first message includes at least one of the following: an identifier related to the remote terminal; a random number; a first communication security policy between the remote terminal and a first relay device, the first communication security policy being used to determine the method of secure communication based on a first link; and a second communication security policy between the remote terminal and a second relay device, the second communication security policy being used to determine the method of secure communication based on a second link, the second link being used for secure communication between the remote terminal and the second relay device.
[0390] In some embodiments, the first message is further used to trigger the establishment of a second link between the remote terminal and the second relay device, the second link being used for secure communication between the remote terminal and the second relay device.
[0391] In some embodiments, the transceiver module 8201 receives the first message sent by the remote terminal in the following manner: the second relay device receives the first message sent by the remote terminal based on the second link established by the remote terminal.
[0392] In some embodiments, the first message is further used to trigger the establishment of a third link between at least one second relay device, and / or, the first message is further used to trigger the establishment of a fourth link between the second relay device and the first relay device. The second relay device further includes a processing module 8202 for establishing the third link between at least one second relay device, the third link being used for secure communication between the at least one second relay device. And / or, establishing the fourth link between the second relay device and the first relay device, the fourth link being used for secure communication between the second relay device and the first relay device.
[0393] In some embodiments, the processing module 8202 is further configured to: establish a third link between at least one second relay device, the third link being used for secure communication between the at least one second relay device; and establish a fourth link between the second relay device and the first relay device, the fourth link being used for secure communication between the second relay device and the first relay device. The transceiver module 8201 sends a first message to the first relay device in the following manner: based on the third link and the fourth link, it sends a first message to the first relay device.
[0394] In some embodiments, a first message is sent to the first relay device in the following manner: The first message is sent to the first relay device based on a pre-established third link and a fourth link. The third link is used for secure communication between at least one second relay device, and the fourth link is used for secure communication between the second relay device and the first relay device.
[0395] In some embodiments, the transceiver module 8201 is further configured to: receive a second message sent by the first relay device, the second message being determined based on the first message and used for security verification; send the second message to the remote terminal; receive a third message sent by the remote terminal, the third message being used to indicate that the security verification has passed; send the third message to the first relay device; receive a fourth message sent by the first relay device, the fourth message being used to indicate that the first relay device accepts the request of the first message; and send the fourth message to the remote terminal.
[0396] In some embodiments, the first message includes a first communication security policy, which includes at least one of the following: a policy indicating whether to protect signaling integrity; a policy indicating whether to protect signaling confidentiality; a policy indicating whether to protect data integrity; and a policy indicating whether to protect data confidentiality.
[0397] In some embodiments, the first communication security policy and / or the second communication security policy are configured by the network device to the remote terminal.
[0398] Figure 8c is a schematic diagram of the structure of the first relay device 8300 proposed in this embodiment of the present disclosure. As shown in Figure 8c, the first relay device 8300 may include: a transceiver module 8301, used to receive a first message sent by a second relay device, the first message being used to request the establishment of a first link between a remote terminal and the first relay device, the first link being used for secure communication between the remote terminal and the first relay device based on the second relay device.
[0399] In some embodiments, the first message includes at least one of the following: an identifier related to the remote terminal; a random number; a first communication security policy between the remote terminal and a first relay device, the first communication security policy being used to determine the method of secure communication based on a first link; and a second communication security policy between the remote terminal and a second relay device, the second communication security policy being used to determine the method of secure communication based on a second link, the second link being used for secure communication between the remote terminal and the second relay device.
[0400] In some embodiments, the first relay device further includes a processing module 8302, configured to determine a second message based on the first message, the second message being used for security verification. The transceiver module 8301 is further configured to: send the second message to the second relay device; receive a third message sent by the second relay device, the third message indicating that the security verification has passed; and send a fourth message to the second relay device, the fourth message indicating that the first relay device accepts the request of the first message.
[0401] In some embodiments, the first message is further used to trigger the establishment of a fourth link between the second relay device and the first relay device. The fourth link is used for secure communication between the second relay device and the first relay device.
[0402] In some embodiments, the first relay device receives the first message sent by the second relay device in the following manner: the first relay device receives the first message sent by the second relay device based on a fourth link established by the second relay device. The fourth link is used for secure communication between the second relay device and the first relay device.
[0403] In some embodiments, the first relay device receives a first message sent by the second relay device in the following manner: the first relay device receives the first message sent by the second relay device based on a pre-established fourth link. The fourth link is used for secure communication between the second relay device and the first relay device.
[0404] In some embodiments, the first message includes a first communication security policy, which includes at least one of the following: a policy indicating whether to protect signaling integrity; a policy indicating whether to protect signaling confidentiality; a policy indicating whether to protect data integrity; and a policy indicating whether to protect data confidentiality.
[0405] In some embodiments, the first communication security policy and / or the second communication security policy are configured by the network device to the remote terminal.
[0406] In some embodiments, the transceiver module 8301 is further configured to: send a fifth message to the network device, the fifth message being used to report relevant information of the remote terminal.
[0407] Figure 9a is a schematic diagram of the structure of a communication device 9100 according to an embodiment of this disclosure. The communication device 9100 can be a network device, a terminal, or a chip, chip system, or processor that supports the implementation of any of the above methods in the network device, or a chip, chip system, or processor that supports the implementation of any of the above methods in the terminal. Optionally, the network device can be an access network device, a core network device, etc. Optionally, the terminal can be a user equipment, etc. The communication device 9100 can be used to implement the methods described in the above method embodiments; for details, please refer to the descriptions in the above method embodiments.
[0408] As shown in Figure 9a, the communication device 9100 includes one or more processors 9101. The processor 9101 can be a general-purpose processor or a dedicated processor, such as a baseband processor or a central processing unit (CPU). The baseband processor can be used to process communication protocols and communication data, while the CPU can be used to control the communication device, execute programs, and process program data. The communication device 9100 is used to execute any of the above methods. Optionally, the communication device can be a base station, a baseband chip, a terminal device, a terminal device chip, a DU, or a CU, etc.
[0409] In some embodiments, the communication device 9100 further includes one or more memories 9102 for storing instructions. Optionally, all or part of the memories 9102 may also be located outside the communication device 9100.
[0410] In some embodiments, the communication device 9100 further includes one or more transceivers 9103. When the communication device 9100 includes one or more transceivers 9103, the transceivers 9103 perform communication steps S2101 such as sending and / or receiving in the above method, and the processor 9101 performs other steps.
[0411] In some embodiments, a transceiver may include a receiver and / or a transmitter, which may be separate or integrated. Optionally, the terms transceiver, transceiver unit, transceiver, transceiver circuit, etc., may be used interchangeably; the terms transmitter, transmitting unit, transmitter, transmitting circuit, etc., may be used interchangeably; and the terms receiver, receiving unit, receiver, receiving circuit, etc., may be used interchangeably.
[0412] In some embodiments, the communication device 9100 may include one or more interface circuits 9104. Optionally, the interface circuit 9104 is connected to the memory 9102, and the interface circuit 9104 can be used to receive signals from the memory 9102 or other devices, and can be used to send signals to the memory 9102 or other devices. For example, the interface circuit 9104 can read instructions stored in the memory 9102 and send the instructions to the processor 9101.
[0413] The communication device 9100 described in the above embodiments may be a network device or a terminal, but the scope of the communication device 9100 described in this disclosure is not limited thereto, and the structure of the communication device 9100 may not be limited by FIG. 91. The communication device may be a standalone device or a part of a larger device. For example, the communication device may be: (1) a standalone integrated circuit IC, or chip, or chip system or subsystem; (2) a collection of one or more ICs, optionally, the IC collection may also include storage components for storing data and programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, terminal device, smart terminal device, cellular phone, wireless device, handheld device, mobile unit, vehicle device, network device, cloud device, artificial intelligence device, etc.; (6) others, etc.
[0414] Figure 9b is a schematic diagram of the structure of chip 9200 according to an embodiment of this disclosure. For cases where the communication device 9100 can be a chip or a chip system, the schematic diagram of the structure of chip 9200 shown in Figure 9b can be referenced, but is not limited thereto.
[0415] Chip 9200 includes one or more processors 9201, which are used to perform any of the above methods.
[0416] In some embodiments, chip 9200 further includes one or more interface circuits 9202. Optionally, the interface circuit 9202 is connected to memory 9203, and the interface circuit 9202 can be used to receive signals from memory 9203 or other devices, and the interface circuit 9202 can be used to send signals to memory 9203 or other devices. For example, the interface circuit 9202 can read instructions stored in memory 9203 and send the instructions to processor 9201.
[0417] In some embodiments, the interface circuit 9202 performs communication steps S2101 such as sending and / or receiving in the above method, and the processor 9201 performs other steps.
[0418] In some embodiments, the terms interface circuit, interface, transceiver pin, transceiver, etc., can be used interchangeably.
[0419] In some embodiments, chip 9200 further includes one or more memories 9203 for storing instructions. Optionally, all or part of the memories 9203 may be located outside of chip 9200.
[0420] This disclosure also proposes a storage medium storing instructions that, when executed on the communication device 9100, cause the communication device 9100 to perform any of the above methods. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer-readable storage medium, but not limited thereto; it may also be a storage medium readable by other devices. Optionally, the storage medium may be a non-transitory storage medium, but not limited thereto; it may also be a temporary storage medium.
[0421] This disclosure also provides a program product that, when executed by the communication device 9100, causes the communication device 9100 to perform any of the above methods. Optionally, the program product is a computer program product.
[0422] This disclosure also proposes a computer program that, when run on a computer, causes the computer to perform any of the above methods.
Claims
1. A communication method, characterized in that, The method includes: The remote terminal sends a first message to the second relay device. The first message is used to request the establishment of a first link between the remote terminal and the first relay device. The first link is used for secure communication between the remote terminal and the first relay device based on the second relay device.
2. The method according to claim 1, characterized in that, The first message includes at least one of the following: The identifier related to the remote terminal; Random numbers; The first communication security policy between the remote terminal and the first relay device is used to determine the method of secure communication based on the first link; The second communication security policy between the remote terminal and the second relay device is used to determine the method of secure communication based on the second link, which is used for secure communication between the remote terminal and the second relay device.
3. The method according to any one of claims 1-2, characterized in that, The method further includes: The remote terminal receives a second message sent by the second relay device. The second message is determined based on the first message and is used to request the establishment of security for the first link. The remote terminal performs security verification on the second message; The remote terminal confirms that the security verification has passed; The remote terminal sends a third message to the second relay device, the third message being used to indicate that the security verification has passed; The remote terminal receives a fourth message sent by the second relay device, the fourth message being used to instruct the first relay device to accept the request of the first message.
4. The method according to any one of claims 1-3, characterized in that, The first message is also used to trigger the establishment of a second link between the remote terminal and the second relay device, and the method further includes: The remote terminal establishes a second link between itself and the second relay device, and the second link is used for secure communication between the remote terminal and the second relay device.
5. The method according to any one of claims 1-3, characterized in that, The remote terminal sends a first message to the second relay device, including: The remote terminal establishes a second link between itself and the second relay device, and sends a first message to the second relay device based on the second link. The second link is used for secure communication between the remote terminal and the second relay device.
6. The method according to any one of claims 2-5, characterized in that, The first message includes the first communication security policy, which includes at least one of the following: Indicates whether to protect the integrity of signaling; Indicates whether to protect the confidentiality of signaling; A policy indicating whether to protect data integrity; Indicates whether to protect data confidentiality policies.
7. The method according to any one of claims 2-6, characterized in that, The first communication security policy and / or the second communication security policy are configured by the network device to the remote terminal.
8. A communication method, characterized in that, The method includes: The second relay device receives the first message sent by the remote terminal; The first message is used to request the establishment of a first link between the remote terminal and the first relay device, and the first link is used for secure communication between the remote terminal and the first relay device based on the second relay device; The second relay device sends a first message to the first relay device.
9. The method according to claim 8, characterized in that, The first message includes at least one of the following: The identifier related to the remote terminal; Random numbers; The first communication security policy between the remote terminal and the first relay device is used to determine the method of secure communication based on the first link; The second communication security policy between the remote terminal and the second relay device is used to determine the method of secure communication based on the second link, which is used for secure communication between the remote terminal and the second relay device.
10. The method according to any one of claims 8-9, characterized in that, The first message is also used to trigger the establishment of a second link between the remote terminal and the second relay device, the second link being used for secure communication between the remote terminal and the second relay device.
11. The method according to any one of claims 8-9, characterized in that, The second relay device receives a first message sent by a remote terminal, including: The second relay device receives the first message sent by the remote terminal based on the second link established by the remote terminal.
12. The method according to any one of claims 8-11, characterized in that, The first message is also used to trigger the establishment of a third link between the second relay devices, and / or, the first message is also used to trigger the establishment of a fourth link between the second relay device and the first relay device, the method further comprising: The second relay device establishes a third link between itself and the second relay devices, the third link being used for secure communication between the second relay devices; and / or, The second relay device establishes a fourth link between itself and the first relay device, the fourth link being used for secure communication between the second relay device and the first relay device.
13. The method according to any one of claims 8-11, characterized in that, The second relay device sends a first message to the first relay device, including: The second relay device establishes a third link between itself and the second relay devices, the third link being used for secure communication between the second relay devices; and / or, The second relay device establishes a fourth link between the second relay device and the first relay device, the fourth link being used for secure communication between the second relay device and the first relay device; The second relay device sends a first message to the first relay device based on the third link and / or the fourth link.
14. The method according to any one of claims 8-11, characterized in that, The second relay device sends a first message to the first relay device, including: The second relay device sends a first message to the first relay device based on a pre-established third link and / or fourth link. The third link is used for secure communication between the second relay devices, and the fourth link is used for secure communication between the second relay device and the first relay device.
15. The method according to any one of claims 12-14, characterized in that, The method further includes: The second relay device receives a second message sent by the first relay device. The second message is determined based on the first message and is used for security verification. The second relay device sends the second message to the remote terminal; The second relay device receives a third message sent by the remote terminal, the third message indicating that the security verification has passed; The second relay device sends the third message to the first relay device; The second relay device receives a fourth message sent by the first relay device, the fourth message being used to instruct the first relay device to accept the request of the first message; The second relay device sends the fourth message to the remote terminal.
16. The method according to any one of claims 9-15, characterized in that, The first message includes the first communication security policy, which includes at least one of the following: Indicates whether to protect the integrity of signaling; Indicates whether to protect the confidentiality of signaling; A policy indicating whether to protect data integrity; Indicates whether to protect data confidentiality policies.
17. The method according to any one of claims 9-16, characterized in that, The first communication security policy and / or the second communication security policy are configured by the network device to the remote terminal.
18. A communication method, characterized in that, The method includes: The first relay device receives a first message sent by the second relay device. The first message is used to request the establishment of a first link between the remote terminal and the first relay device. The first link is used for secure communication between the remote terminal and the first relay device based on the second relay device.
19. The method according to claim 18, characterized in that, The first message includes at least one of the following: The identifier related to the remote terminal; Random numbers; The first communication security policy between the remote terminal and the first relay device is used to determine the method of secure communication based on the first link; The second communication security policy between the remote terminal and the second relay device is used to determine the method of secure communication based on the second link, which is used for secure communication between the remote terminal and the second relay device.
20. The method according to claim 19, characterized in that, The method further includes: The first relay device determines a second message based on the first message, and the second message is used for security verification. The first relay device sends the second message to the second relay device; The first relay device receives a third message sent by the second relay device, the third message being used to indicate that the security verification has passed; The first relay device sends a fourth message to the second relay device, the fourth message being used to instruct the first relay device to accept the request of the first message.
21. The method according to any one of claims 18-20, characterized in that, The first message is also used to trigger the establishment of a fourth link between the second relay device and the first relay device; The fourth link is used for secure communication between the second relay device and the first relay device.
22. The method according to any one of claims 18-20, characterized in that, The first relay device receives a first message sent by the second relay device, including: The first relay device receives the first message sent by the second relay device based on the fourth link established by the second relay device; The fourth link is used for secure communication between the second relay device and the first relay device.
23. The method according to any one of claims 18-20, characterized in that, The first relay device receives a first message sent by the second relay device, including: The first relay device receives the first message sent by the second relay device based on the pre-established fourth link; The fourth link is used for secure communication between the second relay device and the first relay device.
24. The method according to any one of claims 19-23, characterized in that, The first message includes the first communication security policy, which includes at least one of the following: Indicates whether to protect the integrity of signaling; Indicates whether to protect the confidentiality of signaling; A policy indicating whether to protect data integrity; Indicates whether to protect data confidentiality policies.
25. The method according to any one of claims 19-24, characterized in that, The first communication security policy and / or the second communication security policy are configured by the network device to the remote terminal.
26. The method according to any one of claims 18-25, characterized in that, The method further includes: A fifth message is sent to the network device, the fifth message being used to report relevant information about the remote terminal.
27. A communication method, characterized in that, include: The remote terminal sends a first message to the second relay device. The first message is used to request the establishment of a first link between the remote terminal and the first relay device. The first link is used for secure communication between the remote terminal and the first relay device based on the second relay device. The second relay device receives the first message sent by the remote terminal; The second relay device sends the first message to the first relay device; The first relay device receives the first message sent by the second relay device.
28. A remote terminal, characterized in that, include: The transceiver module is used to send a first message to the second relay device. The first message is used to request the establishment of a first link between the remote terminal and the first relay device. The first link is used for secure communication between the remote terminal and the first relay device based on the second relay device.
29. A relay device, characterized in that, include: The transceiver module is used to receive the first message sent by the remote terminal; Send the first message to the first relay device; The first message is used to request the establishment of a first link between the remote terminal and the first relay device, and the first link is used for secure communication between the remote terminal and the first relay device based on the second relay device.
30. A relay device, characterized in that, include: The transceiver module is used to receive a first message sent by the second relay device. The first message is used to request the establishment of a first link between the remote terminal and the first relay device. The first link is used for secure communication between the remote terminal and the first relay device based on the second relay device.
31. A remote terminal, characterized in that, include: One or more processors; The processor is used to execute the communication method according to any one of claims 1-7.
32. A relay device, characterized in that, include: One or more processors; The processor is used to execute the communication method according to any one of claims 8-17.
33. A relay device, characterized in that, include: One or more processors; The processor is used to execute the communication method according to any one of claims 18-26.
34. A communication system, characterized in that, include: A remote terminal, a first relay device, and a second relay device, wherein the remote terminal is configured to implement the communication method of any one of claims 1-7, the first relay device is configured to implement the communication method of any one of claims 8-17, and the second relay device is configured to implement the communication method of any one of claims 18-26.
35. A storage medium, characterized in that, include: The storage medium stores instructions that, when executed on a communication device, cause the communication device to perform the communication method as described in any one of claims 1-7, 8-17, or 18-26.
36. A program product, characterized in that, include: A computer program, when executed by a communication device, causes the communication device to perform the communication method as described in any one of claims 1-7, 8-17, or 18-26.