Information processing method, communication system and storage medium

CN121646945APending Publication Date: 2026-03-10BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-07-05
Publication Date
2026-03-10

AI Technical Summary

Technical Problem

In existing technologies, the security of data plane data transmission is difficult to protect effectively, especially during data plane transmission, where existing security mechanisms cannot be reused, and the secure transmission of data plane needs to be reconsidered.

Method used

The terminal sends information indicating that data plane security protection has been implemented to the access network device. The access network device verifies the information before transmitting it to the first network element, which then further verifies it to determine the final security protection measures for the data plane data.

Benefits of technology

It improves the security of data transmission, ensures the integrity and confidentiality of data during transmission, and enhances the effectiveness of data security protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121646945A_ABST
    Figure CN121646945A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides an information processing method, a communication system and a storage medium. The information processing method is executed by a terminal, and comprises the following steps: sending a first message to an access network device, the first message comprising first information subjected to DP security protection; the first message is sent to the first network element by the access network equipment; therefore, the first information for DP security protection can be sent to the access network equipment through the terminal, so that the security of data plane transmission can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Information processing method, communication system, and storage medium TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of communication, and particularly relates to an information processing method, a communication system and a storage medium. BACKGROUND

[0002] In the technical field of communication, the plane for processing different types of traffic can include a control plane (CP), a user plane (UP) and / or a data plane (DP). When data from a terminal is transmitted in the data plane, the existing security mechanism for protecting control plane and user plane traffic cannot be reused, and the secure transmission of data in the data plane needs to be reconsidered.

[0003] SUMMARY

[0004] The embodiments of the present disclosure need to solve the problem of secure transmission of data in the data plane.

[0005] According to a first aspect of the embodiments of the present disclosure, an information processing method is provided, executed by a terminal, comprising: sending a first message to an access network device, wherein the first message comprises first information that has been subjected to data plane (DP) security protection; and the first message is used for the access network device to send to a first network element.

[0006] According to a second aspect of the embodiments of the present disclosure, an information processing method is provided, executed by an access network device, comprising: receiving a first message sent by a terminal, wherein the first message comprises first information that has been subjected to DP security protection; and sending the first information subjected to DP security verification to a first network element.

[0007] According to a third aspect of the embodiments of the present disclosure, an information processing method is provided, executed by a first network element, comprising: receiving the first information subjected to DP security verification sent by an access network device; wherein the first information subjected to DP security verification is obtained by the access network device from a first message; the first message is obtained by the access network device from a terminal, and the first message comprises first information that has been subjected to DP security protection; and sending the first information subjected to DP security verification to a third network element.

[0008] According to a fourth aspect of the embodiments of the present disclosure, an information processing method is provided, executed by a second network element, comprising: receiving a second message sent by an access network device, wherein the second message is used for requesting to establish a connection; and the connection is used for transmitting DP data, and the data comprises first information that has been subjected to DP security protection.

[0009] According to a fifth aspect of the embodiments of the present disclosure, an information processing method is provided, including: a terminal sending a first message to an access network device, wherein the first message includes first information that has been DP security protected; the access network device sending the first information that has been DP security verified to a first network element; and the first network element sending the first information that has been DP security verified to a third network element.

[0010] According to a sixth aspect of the embodiments of the present disclosure, a terminal is provided, including: a first transceiver configured to send a first message to an access network device, wherein the first message includes first information that has been DP security protected; and the first message is used by the access network device to send to a first network element.

[0011] According to a seventh aspect of the embodiments of the present disclosure, an access network device is provided, including: a second transceiver configured to receive a first message sent by a terminal, wherein the first message includes first information that has been DP security protected; and the second transceiver is further configured to send the first information that has been DP security verified to a first network element.

[0012] According to an eighth aspect of the embodiments of the present disclosure, a first network element is provided, including: a third transceiver configured to receive first information that has been DP security verified sent by an access network device; wherein the first information that has been DP security verified is obtained by the access network device from a first message; the first message is obtained by the access network device from a terminal, and the first message includes first information that has been DP security protected; and the third transceiver is further configured to send the first information that has been DP security verified to a third network element.

[0013] According to a ninth aspect of the embodiments of the present disclosure, a second network element is provided, including: a fourth transceiver configured to receive a second message sent by an access network device, wherein the second message is used to request to establish a connection; and the connection is used to transmit DP data, and the data includes first information that has been DP security protected.

[0014] According to a tenth aspect of the embodiments of the present disclosure, a communication device is provided, including one or more processors; wherein the communication device is configured to perform the method of the first aspect, the second aspect, the third aspect, the fourth aspect, the fifth aspect, or the optional implementation of the first aspect, the second aspect, the third aspect, the fourth aspect, and the fifth aspect.

[0015] According to a twelfth aspect of the embodiments of the present disclosure, a storage medium is provided, and the storage medium stores instructions, which, when executed on a communication device, cause the communication device to perform the method described in the first aspect, the second aspect, the third aspect, the fourth aspect, the fifth aspect, or the optional implementation of the first aspect, the second aspect, the third aspect, the fourth aspect, and the fifth aspect.

[0016] According to a twelfth aspect of the embodiments of the present disclosure, a storage medium is provided, and the storage medium stores instructions, which, when executed on a communication device, cause the communication device to perform the method described in the first aspect, the second aspect, the third aspect, the fourth aspect, the fifth aspect, or the optional implementation of the first aspect, the second aspect, the third aspect, the fourth aspect, and the fifth aspect.

[0017] According to a twelfth aspect of the embodiments of the present disclosure, a storage medium is provided, and the storage medium stores instructions, which, when executed on a communication device, cause the communication device to perform the method described in the first aspect, the second aspect, the third aspect, the fourth aspect, the fifth aspect, or the optional implementation of the first aspect, the second aspect, the third aspect, the fourth aspect, and the fifth aspect.

[0018] The embodiments of the present disclosure can improve the security of data plane data transmission. BRIEF DESCRIPTION OF DRAWINGS

[0019] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure, the following describes the drawings required for the embodiments, and the following drawings are only some embodiments of the present disclosure, and do not specifically limit the protection scope of the present disclosure.

[0020] FIG. 1A is a structural schematic diagram of an information processing system according to an embodiment of the present disclosure.

[0021] FIG. 1B is a schematic diagram of a 6G architecture according to an embodiment of the present disclosure.

[0022] FIG. 2 is an interaction schematic diagram of an information processing method according to an embodiment of the present disclosure.

[0023] FIG. 3A is a flow schematic diagram of an information processing method according to an embodiment of the present disclosure.

[0024] FIG. 3B is a flow schematic diagram of an information processing method according to an embodiment of the present disclosure.

[0025] FIG. 3C is a flow schematic diagram of an information processing method according to an embodiment of the present disclosure.

[0026] FIG. 4A is a flow diagram of an information processing method according to an embodiment of the present disclosure.

[0027] FIG. 4B is a flow diagram of an information processing method according to an embodiment of the present disclosure.

[0028] FIG. 4C is a flow diagram of an information processing method according to an embodiment of the present disclosure.

[0029] FIG. 5A is a flow diagram of an information processing method according to an embodiment of the present disclosure.

[0030] FIG. 5B is a flow diagram of an information processing method according to an embodiment of the present disclosure.

[0031] FIG. 6A is a flow diagram of an information processing method according to an embodiment of the present disclosure.

[0032] FIG. 6B is a flow diagram of an information processing method according to an embodiment of the present disclosure.

[0033] FIG. 7A is an interaction diagram of an information processing method according to an embodiment of the present disclosure.

[0034] FIG. 7B is a flow diagram of an information processing method according to an embodiment of the present disclosure.

[0035] FIG. 7C is a flow diagram of an information processing method according to an embodiment of the present disclosure.

[0036] FIG. 7D is a flow diagram of an information processing method according to an embodiment of the present disclosure.

[0037] FIG. 7E is a diagram of a key according to an embodiment of the present disclosure.

[0038] FIG. 8A is a structural diagram of a terminal according to an embodiment of the present disclosure.

[0039] FIG. 8B is a structural diagram of an access network device according to an embodiment of the present disclosure.

[0040] FIG. 8C is a structural diagram of a first network element according to an embodiment of the present disclosure.

[0041] FIG. 8D is a structural diagram of a second network element according to an embodiment of the present disclosure.

[0042] FIG. 9A is a structural diagram of a communication device according to an embodiment of the present disclosure.

[0043] FIG. 9B is a structural diagram of a chip according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0044] The embodiments of the present disclosure provide an information processing method, a communication system and a storage medium.

[0045] In the first aspect, the embodiments of the present disclosure provide an information processing method, executed by a terminal, comprising: sending a first message to an access network device, wherein the first message comprises first information that has been subjected to DP security protection; and the first message is used for the access network device to send to a first network element.

[0046] In the above embodiment, the terminal can send the first information subjected to DP security protection to the access network device, so as to improve the security of the data plane transmission.

[0047] In combination with some embodiments of the first aspect, in some embodiments, the first message further comprises a first identifier indicating a connection, and the connection is used for transmitting DP data; and the first identifier is used for the access network device to determine the first network element.

[0048] In the above embodiment, the first identifier can be used to determine the connection for transmitting data, and the first network element through which the connection passes can be determined.

[0049] In combination with some embodiments of the first aspect, in some embodiments, before sending the first message to the access network device, the method further comprises: sending a second message to the access network device, wherein the second message is used for requesting to establish a connection.

[0050] In the above embodiment, the terminal can send a request to the access network device before transmitting data based on the data plane, so as to facilitate establishing the connection for transmitting the data plane data.

[0051] In combination with some embodiments of the first aspect, in some embodiments, the second message further comprises at least one of: a second identifier, wherein the second identifier is used for indicating a data service; and a first indication, wherein the first indication is used for indicating that the connection type is a connection for transmitting DP data.

[0052] In the above embodiment, the terminal can inform the type of the connection to be established, and / or the data to be transmitted by the data plane is the data of which data service.

[0053] In combination with some embodiments of the first aspect, in some embodiments, the method comprises: receiving a third message sent by the access network device, wherein the third message comprises at least one of: a second indication, wherein the second indication is used for indicating whether to activate integrity protection of DP data; a third indication, wherein the third indication is used for indicating whether to activate confidentiality protection of DP data; and second information that has been subjected to DP security protection.

[0054] In the above embodiment, the terminal can receive the third message of the access network device, so as to know whether the DP security protection needs to be activated.

[0055] In some embodiments of the first aspect, in some embodiments, the second indication is applicable to each data radio bearer (DRB) or each connection; or the third indication is applicable to each DRB or each connection.

[0056] In some embodiments of the first aspect, in some embodiments, the method further comprises: generating a DP security key in a case where it is determined to activate the integrity protection and / or the confidentiality protection of the DP data, wherein the DP security key comprises a DP integrity key and / or a DP confidentiality key.

[0057] In the above embodiments, the terminal can generate the DP security key when the DP security protection is needed to be activated, so as to facilitate the DP security verification (such as decryption and / or security verification) on the data transmitted in the data plane.

[0058] In some embodiments of the first aspect, in some embodiments, the generating the DP security key comprises: generating the DP security key based on the first key and a first parameter; wherein the first parameter comprises at least one of: a first indicator, wherein the first indicator is used to indicate an algorithm; a first length, wherein the first length is used to indicate a length of the first indicator; a second indicator, wherein the second indicator is used to indicate a type of the algorithm; and a second length, wherein the second length is used to indicate a length of the second indicator.

[0059] In the above embodiments, the generation of the DP security key can be implemented.

[0060] In some embodiments of the first aspect, in some embodiments, the method further comprises: in a case where the third message is successfully verified, sending a first response to the access network device and / or determining to activate the DP security protection on the data transmitted through the DRB or the connection; wherein the data at least comprises the first information; and the first response comprises the third information which has been DP security protected based on the DP security key; or in a case where the verification of the third message fails, determining not to activate the DP security protection on the data transmitted through the DRB or the connection.

[0061] In the above embodiments, in a case where it is determined that the third message can be successfully verified based on the DP security key, the DP security protection on the data transmitted in the data plane can be activated, and the data which has been DP security protected can be sent to the access network device. Or, in a case where it is determined that the third message cannot be successfully verified based on the DP security key, the DP security protection on the data transmitted in the data plane is not activated. In this way, the security of the data transmitted in the data plane can be improved.

[0062] In some embodiments of the first aspect, in some embodiments, the method further includes receiving a second response sent by the access network device, wherein the second response is a response to the first information in the first message.

[0063] In some embodiments of the first aspect, in some embodiments, the first network element is a Data Plane Function (DPF) or a User Plane Function (UPF).

[0064] In a second aspect, the embodiments of the present disclosure provide an information processing method, performed by an access network device, including: receiving a first message sent by a terminal, wherein the first message includes first information that has been subjected to DP security protection; and sending the first information subjected to DP security verification to a first network element.

[0065] In some embodiments of the second aspect, in some embodiments, the first message includes a first identifier indicating a connection for transmitting DP data; and the method further includes determining the first network element based on the first identifier.

[0066] In some embodiments of the second aspect, in some embodiments, before receiving the first message sent by the terminal, the method further includes: receiving a second message sent by the terminal, wherein the second message is used to request establishment of a connection; and sending the second message to a second network element.

[0067] In some embodiments of the second aspect, in some embodiments, the second message further includes at least one of: a second identifier, wherein the second identifier is used to indicate a data service; and a first indication, wherein the first indication is used to indicate that the connection type is a connection for transmitting DP data.

[0068] In some embodiments of the second aspect, in some embodiments, the method further includes receiving a fourth message sent by the second network element, wherein the fourth message is used to establish the connection.

[0069] In some embodiments of the second aspect, in some embodiments, the fourth message further includes at least one of: policy information, wherein the policy information includes at least one of: a first policy indication, used to indicate whether integrity protection of DP data is activated; a second policy indication, used to indicate whether confidentiality protection of DP data is activated; the first identifier; and an address of the first network element.

[0070] In some embodiments of the second aspect, in some embodiments, the method includes, in a case where it is determined that the integrity protection and / or the confidentiality protection of the DP data is activated, generating a DP security key, wherein the DP security key includes a DP integrity key and / or a DP confidentiality key.

[0071] In some embodiments of the second aspect, in some embodiments, the generating the DP security key comprises: generating the DP security key based on the first key and the first parameter; wherein the first parameter comprises at least one of: a first indicator, wherein the first indicator is used to indicate an algorithm; a first length, wherein the first length is used to indicate a length of the first indicator; a second indicator, wherein the second indicator is used to indicate a type of the algorithm; a second length, wherein the second length is used to indicate a length of the second indicator.

[0072] In some embodiments of the second aspect, in some embodiments, the method further comprises: sending, to the terminal, a third message, wherein the third message comprises at least one of: a second indication, wherein the second indication is used to indicate whether to activate the integrity protection of the DP data; a third indication, wherein the third indication is used to indicate whether to activate the DP confidentiality protection of the DP data; and the second information that is DP security protected based on the DP security key.

[0073] In some embodiments of the second aspect, in some embodiments, the method further comprises: receiving a first response sent by the terminal, wherein the first response comprises third information that is DP security protected based on the DP security key; and the first response is sent by the terminal in a case that the terminal successfully verifies the second information that is DP security protected in the third message based on the DP security key.

[0074] In some embodiments of the second aspect, in some embodiments, the method further comprises: in a case that the first response is successfully verified, sending, to the second network element, a third response and / or determining to perform the DP security protection on the data transmitted through the DRB or the connection; wherein the third response is used to indicate that the connection between the access network device and the terminal is established and / or to indicate that the DP security protection of the connection is activated; or in a case that the verification of the first response fails, determining not to perform the DP security protection on the data transmitted through the DRB or the connection.

[0075] In some embodiments of the second aspect, in some embodiments, the method further comprises: receiving a second response sent by the first network element, wherein the second response is a response to the first information in the first message; and sending, to the terminal, the second response.

[0076] In some embodiments of the second aspect, in some embodiments, the first network element is a DPF or a UPF; and / or the second network element is an Access and Mobility Management Function (AMF) or a Session Management Function (SMF).

[0077] In a third aspect, the embodiments of the present disclosure provide an information processing method, executed by a first network element, comprising: receiving first information after DP security verification sent by an access network device; wherein the first information after DP security verification is obtained by the access network device from a first message; the first message is obtained by the access network device from a terminal, and the first message comprises the first information after DP security protection; and sending the first information after DP security verification to a third network element.

[0078] In combination with some embodiments of the third aspect, in some embodiments, the first message further comprises: a first identifier indicating the connection; and the method further comprises: determining the third network element based on the first identifier.

[0079] In combination with some embodiments of the third aspect, in some embodiments, the method further comprises: receiving a second response sent by the third network element, wherein the second response is a response to the first information in the first message; and sending the second response to the access network device.

[0080] In combination with some embodiments of the third aspect, in some embodiments, the first network element is: a DPF or a UPF; and / or, the third network element is: a network data analytics function (NWDAF) or a data plane management function (DPMF).

[0081] In a fourth aspect, the embodiments of the present disclosure provide an information processing method, executed by a second network element, comprising: receiving a second message sent by an access network device, wherein the second message is used to request to establish a connection; and the connection is used to transmit DP data, and the data comprises first information after DP security protection.

[0082] In combination with some embodiments of the fourth aspect, in some embodiments, the second message further comprises at least one of: a second identifier, wherein the second identifier is used to indicate a data service; and a first indication, wherein the first indication is used to indicate that the connection type is a connection.

[0083] In combination with some embodiments of the fourth aspect, in some embodiments, the method further comprises: obtaining subscription information and / or data service related information from a fourth network element; wherein the subscription information comprises authorization information and / or policy information; and the data service related information comprises policy information.

[0084] In the above embodiments, the authorization information can be obtained, so as to facilitate whether to authorize the terminal to access the data service, i.e., whether to authorize the terminal to perform DP security protection on the data of the data service. And / or, the policy information can be obtained, so as to facilitate to determine the specific implementation information of the DP security protection of the data plane data.

[0085] In some embodiments of the fourth aspect, in some embodiments, the method further comprises: determining whether to authorize the terminal to access the data service based on the subscription information; and determining the first network element in a case where it is determined that the terminal is authorized to access the data service.

[0086] In some embodiments of the fourth aspect, in some embodiments, the method further comprises: sending the second message in a case where it is determined that the terminal is not authorized to access the data service.

[0087] In some embodiments of the fourth aspect, in some embodiments, the method further comprises one of: generating the first identifier of the connection; obtaining the first identifier of the connection generated in history; and obtaining the first identifier of the connection stored.

[0088] In the above embodiments, the first identifier can be determined in various ways, thereby adapting to more application scenarios.

[0089] In some embodiments of the fourth aspect, in some embodiments, the method further comprises at least one of: obtaining the policy information from the subscription information; obtaining the policy information from the data service related information; and obtaining the policy information configured locally.

[0090] In the above embodiments, the policy information can be obtained in various ways, thereby adapting to more application scenarios.

[0091] In some embodiments of the fourth aspect, in some embodiments, the policy information obtained from the subscription information or the data service related information has a higher priority than the policy information configured locally.

[0092] In some embodiments of the fourth aspect, in some embodiments, the method further comprises: sending a fourth message to the access network device, wherein the fourth message is used to establish the connection; and receiving a third response sent by the access network device, wherein the third response is used to indicate that the connection between the access network device and the terminal has been established and / or to indicate that the DP security protection of the connection has been activated.

[0093] In some embodiments of the fourth aspect, in some embodiments, the fourth message further comprises at least one of: the policy information, wherein the policy information comprises at least one of: a first policy indication used to indicate whether to activate the integrity protection of the DP data; a second policy indication used to indicate whether to activate the confidentiality protection of the DP data; the first identifier; and an address of the first network element.

[0094] In some embodiments of the fourth aspect, in some embodiments, the first network element is a DPF or a UPF; and / or, the second network element is an AMF or an SMF; and / or, the fourth network element is a Unified Data Management (UDM) or a Unified Data Repository (UDR).

[0095] In the fifth aspect, the embodiments of the present disclosure provide an information processing method, including: a terminal sending a first message to an access network device, wherein the first message includes first information that has been subjected to DP security protection; the access network device sending the first information subjected to DP security verification to a first network element; and the first network element sending the first information subjected to DP security verification to a third network element.

[0096] In the sixth aspect, the embodiments of the present disclosure provide a terminal, including: a first transceiver configured to send a first message to an access network device, wherein the first message includes first information that has been subjected to DP security protection; and the first message is used for the access network device to send to a first network element.

[0097] In the seventh aspect, the embodiments of the present disclosure provide an access network device, including: a second transceiver configured to receive a first message sent by a terminal, wherein the first message includes first information that has been subjected to DP security protection; and the second transceiver is further configured to send the first information subjected to DP security verification to a first network element.

[0098] In the eighth aspect, the embodiments of the present disclosure provide a first network element, including: a third transceiver configured to receive the first information subjected to DP security verification sent by an access network device; wherein the first information subjected to DP security verification is obtained by the access network device from a first message; the first message is obtained by the access network device from a terminal, and the first message includes first information that has been subjected to DP security protection; and the third transceiver is further configured to send the first information subjected to DP security verification to a third network element.

[0099] In the ninth aspect, the embodiments of the present disclosure provide a second network element, including: a fourth transceiver configured to receive a second message sent by an access network device, wherein the second message is used for requesting to establish a connection; and the connection is used for transmitting DP data, and the data includes first information that has been subjected to DP security protection.

[0100] In the tenth aspect, the embodiments of the present disclosure provide a communication device, including one or more processors; wherein the communication device is configured to perform the first aspect, the second aspect, the third aspect, the fourth aspect, the fifth aspect, or the optional implementation manner of the first aspect, the second aspect, the third aspect, the fourth aspect, and the fifth aspect.

[0101] In an eleventh aspect, an embodiment of the present disclosure provides a communication system, comprising: a terminal, an access network device, a first network element and a second network element; wherein the terminal is configured to perform the method described in the optional implementation of the first aspect, the access network device is configured to perform the method described in the optional implementation of the second aspect, the first network element is configured to perform the method described in the optional implementation of the third aspect, and the second network element is configured to perform the method described in the optional implementation of the fourth aspect.

[0102] In a twelfth aspect, an embodiment of the present disclosure provides a storage medium, which stores instructions, when the instructions are executed on a communication device, causing the communication device to perform the method described in the first aspect, the second aspect, the third aspect, the fourth aspect, the fifth aspect, or the optional implementation of the first aspect, the second aspect, the third aspect, the fourth aspect and the fifth aspect.

[0103] In a thirteenth aspect, an embodiment of the present disclosure provides a computer program product, which comprises a computer program or instructions, and the computer program or instructions are executed by a processor to implement the method described in the first aspect, the second aspect, the third aspect, the fourth aspect, the fifth aspect, or the optional implementation of the first aspect, the second aspect, the third aspect, the fourth aspect and the fifth aspect.

[0104] In a fourteenth aspect, an embodiment of the present disclosure provides a program product, which is executed by a communication device to cause the communication device to perform the method described in the first aspect, the second aspect, the third aspect, the fourth aspect, the fifth aspect, or the optional implementation of the first aspect, the second aspect, the third aspect, the fourth aspect and the fifth aspect.

[0105] In a fifteenth aspect, an embodiment of the present disclosure provides a computer program, which, when executed on a computer, causes the computer to perform the information processing method described in the first aspect, the second aspect, the third aspect, the fourth aspect, the fifth aspect, or the optional implementation of the first aspect, the second aspect, the third aspect, the fourth aspect and the fifth aspect.

[0106] In a sixteenth aspect, an embodiment of the present disclosure provides a chip or chip system, which comprises processing circuitry configured to perform the method described in the first aspect, the second aspect, the third aspect, the fourth aspect, the fifth aspect, or the optional implementation of the first aspect, the second aspect, the third aspect, the fourth aspect and the fifth aspect.

[0107] It is understood that the aforementioned terminal, access network equipment, first network element, second network element, communication system, storage medium, program product, computer program, chip, or chip system are all used to execute the methods provided in the embodiments of this disclosure. Therefore, the beneficial effects that can be achieved can be referred to the beneficial effects in the corresponding methods, and will not be repeated here.

[0108] This disclosure provides an information processing method, a communication system, and a storage medium. In some embodiments, the terms "information processing method" and "information processing device" are interchangeable, as are "information processing system" and "communication system".

[0109] This disclosure is not exhaustive, but merely illustrative of some embodiments, and is not intended to limit the scope of protection of this disclosure. Unless otherwise specified, each step in a particular embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a particular embodiment can also be implemented as an independent embodiment, and the order of the steps in a particular embodiment can be arbitrarily interchanged. Furthermore, the optional implementation methods in a particular embodiment can be arbitrarily combined; moreover, the embodiments can be arbitrarily combined, for example, some or all steps of different embodiments can be arbitrarily combined, and a particular embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.

[0110] In each of the disclosed embodiments, unless otherwise specified or in case of logical conflict, the terminology and / or descriptions of the embodiments are consistent and can be used interchangeably. Technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships.

[0111] The terminology used in the embodiments of this disclosure is for the purpose of describing particular embodiments only and is not intended to limit the scope of this disclosure.

[0112] In this embodiment of the disclosure, unless otherwise stated, elements expressed in the singular form, such as "a," "an," "the," "the," "the," "the," "the," "the," "this," etc., can mean "one and only one," or "one or more," "at least one," etc. For example, when using articles such as "a," "an," "the," etc. in translation, the noun following the article can be understood as either a singular expression or a plural expression.

[0113] In the embodiments disclosed herein, "multiple" refers to two or more.

[0114] In some embodiments, the terms "at least one of," "one or more of," "a plurality of," "multiple," and the like can be used interchangeably.

[0115] In some embodiments, the recitations "at least one of A, B," "A and / or B," "in one case A, in another case B," "in response to a case A, in response to a case B," and the like can include the following technical solutions according to the case: in some embodiments A (A is executed regardless of B); in some embodiments B (B is executed regardless of A); in some embodiments A and B are selected from A and B (A and B are selectively executed); in some embodiments A and B (A and B are both executed). When there are more branches such as A, B, C, and the like, the above is similar.

[0116] In some embodiments, the recitations "A or B" and the like can include the following technical solutions according to the case: in some embodiments A (A is executed regardless of B); in some embodiments B (B is executed regardless of A); in some embodiments A and B are selected from A and B (A and B are selectively executed). When there are more branches such as A, B, C, and the like, the above is similar.

[0117] The prefix words "first", "second", and the like in the embodiments of the present disclosure are merely used to distinguish different description objects, and do not constitute a limitation on the position, order, priority, quantity, or content of the description objects. The description of the description objects should refer to the description in the context of the claims or embodiments, and should not constitute an additional limitation because of the use of the prefix words. For example, the description objects are "fields", and the ordinal words before "fields" in "first field" and "second field" do not limit the position or order between "fields", and "first" and "second" do not limit whether the "fields" modified thereby are in the same message or not, nor limit the order of "first field" and "second field". For another example, the description objects are "levels", and the ordinal words before "levels" in "first level" and "second level" do not limit the priority between "levels". For another example, the quantity of the description objects is not limited by the ordinal words, and can be one or more. For example, "first device", wherein the quantity of "devices" can be one or more. In addition, the objects modified by different prefix words can be the same or different, for example, the description objects are "devices", and "first device" and "second device" can be the same device or different devices, and the types thereof can be the same or different; for another example, the description objects are "information", and "first information" and "second information" can be the same information or different information, and the content thereof can be the same or different.

[0118] In some embodiments, "comprising", "including", "to indicate", "carrying", can be interpreted as directly carrying A, and can also be interpreted as indirectly indicating A.

[0119] In some embodiments, the terms "in response to", "in response to determining", "in the case of", "when", "when", "if", "if" and the like can be replaced with each other.

[0120] In some embodiments, the terms "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not lower than", "above" and the like can be replaced with each other, and the terms "less than", "less than or equal to", "not greater than", "less than", "less than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", "below" and the like can be replaced with each other.

[0121] In some embodiments, the device and the like can be interpreted as physical or virtual, and the name is not limited to the name recorded in the embodiments. The terms "device", "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", "subject" and the like can be replaced with each other.

[0122] In some embodiments, "network" can be interpreted as a device (for example, access network device, core network device, etc.) contained in the network.

[0123] In some embodiments, the terms “access network device (AN device),” “radio access network device (RAN device),” “base station (BS),” “radio base station,” “fixed station,” “node,” “access point,” “transmission point (TP),” “reception point (RP),” “transmission / reception point (TRP),” “panel,” “antenna panel,” “antenna array,” “cell,” “macro cell,” “small cell,” “femto cell,” “pico cell,” “sector,” “cell group,” “carrier,” “component carrier,” “bandwidth part (BWP),” and the like can be used interchangeably.

[0124] In some embodiments, the terms "terminal," "terminal device," "user equipment (UE)," "user terminal," "mobile station (MS)," "mobile terminal (MT)," "subscriber station," "mobile unit," "subscriber unit," "wireless unit," "remote unit," "mobile device," "wireless device," "wireless communication device," "remote device," "mobile subscriber station," "access terminal," "mobile terminal," "wireless terminal," "remote terminal," "handset," "user agent," "mobile client," "client," and so on can be replaced with each other.

[0125] In some embodiments, an access network device, a core network device, or a network device can be replaced with a terminal. For example, for a structure in which communication between an access network device, a core network device, or a network device and a terminal is replaced with communication between a plurality of terminals (for example, also referred to as device-to-device (D2D), vehicle-to-everything (V2X), and so on), embodiments of the present disclosure can also be applied. In this case, a structure in which a terminal has all or part of the functions of an access network device can also be provided. Furthermore, the language of "uplink," "downlink," and so on can also be replaced with language corresponding to communication between terminals (for example, "side"). For example, an uplink channel, a downlink channel, and so on can be replaced with a side channel, and an uplink, a downlink, and so on can be replaced with a side link.

[0126] In some embodiments, a terminal can be replaced with an access network device, a core network device, or a network device. In this case, a structure in which an access network device, a core network device, or a network device has all or part of the functions of a terminal can also be provided.

[0127] In some embodiments, obtaining data, information, and the like can comply with laws and regulations of the country where the location is.

[0128] In some embodiments, data, information, and the like can be obtained after obtaining the consent of the user.

[0129] In addition, each element, each row, or each column in the table of the embodiments of the present disclosure can be implemented as an independent embodiment, and any combination of any element, any row, or any column can also be implemented as an independent embodiment.

[0130] FIG. 1A is a structural schematic diagram of an information processing system 100 according to an embodiment of the present disclosure. As shown in FIG. 1A, the information processing system 100 can include a terminal 101 and a network device 102.

[0131] In some embodiments, the network device 102 can include at least one of an access network device and a core network device.

[0132] In some embodiments, the terminal 101 includes at least one of a mobile phone, a wearable device, an IOT device or terminal, a car with communication function, a smart car, a Pad, a computer with wireless transceiver function, a VR terminal device, an AR terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in smart grid, a wireless terminal device in transportation safety, a wireless terminal device in smart city, a wireless terminal device in smart home, and the like, but is not limited thereto.

[0133] In some embodiments, the access network device is, for example, a node or device that accesses a terminal to a wireless network, and the access network device can include at least one of an evolved NodeB (eNB) in a 5G communication system, a next generation eNB (ng-eNB), a next generation NodeB (gNB), a node B (NB), a home node B (HNB), a home evolved node B (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an open base station (Open RAN), a cloud base station (Cloud RAN), a base station in other communication systems, an access node in a wireless fidelity (WiFi) system, but is not limited thereto.

[0134] In some embodiments, the technical solutions of the present disclosure can be applied to an Open RAN architecture, at this time, the interfaces between or within the access network devices involved in the embodiments of the present disclosure can become internal interfaces of the Open RAN, and the processes and information interactions between these internal interfaces can be realized through software or programs.

[0135] In some embodiments, the access network device can be composed of a central unit (CU) and a distributed unit (DU), wherein the CU can also be referred to as a control unit. The CU-DU structure can split the protocol layers of the access network device, and the functions of part of the protocol layers are controlled by the CU, and the functions of the remaining part or all of the protocol layers are distributed in the DU and controlled by the CU, but are not limited thereto.

[0136] In some embodiments, the core network device can be one device including the first network element, the second network element, the third network element, the fourth network element, etc., or can be multiple devices or device groups, each including all or part of the above-mentioned first network element, second network element, and / or third network element, etc. The first network element, the second network element, and the third network element can each be virtual or physical. The core network includes at least one of an evolved packet core (EPC), a 5G core network (5GCN), a next-generation core (NGC), and a 6G core network (6GCN), for example.

[0137] In some embodiments, the first network element can be any network element or entity in the core network having a data forwarding capability, etc., and can also be any network element or entity in the core network having a data plane data forwarding or processing capability, etc. The name of the first network element is not limited, which is a DPF or a UPF, etc., for example.

[0138] In some embodiments, the second network element can be any network element or entity in the core network having a mobility management function or a session management function. The name of the second network element is not limited, which can be an AMF or an SMF, etc.

[0139] In some embodiments, the third network element can be any network element or entity in the network having a network analysis or data management capability, etc. The name of the third network element is not limited, which is a NWDAF or a DPMF, for example.

[0140] In some embodiments, the fourth network element can be any network element or entity in the network having a unified management or data storage function, etc. The name of the fourth network element is not limited, which can be a UDM or a UDR, etc.

[0141] It can be understood that the information processing system described in the embodiments of the present disclosure is for more clearly illustrating the technical solutions of the embodiments of the present disclosure, and does not constitute a limitation on the technical solutions provided by the embodiments of the present disclosure. It can be known by those skilled in the art that, with the evolution of system architecture and the appearance of new business scenarios, the technical solutions provided by the embodiments of the present disclosure are also applicable to similar technical problems.

[0142] The following embodiments of the present disclosure can be applied to the information processing system 100 illustrated in FIG. 1A, or part of the subjects, but are not limited thereto. The subjects illustrated in FIG. 1A are examples, and the information processing system can include all or part of the subjects in FIG. 1A, or other subjects other than those in FIG. 1A. The number and form of the subjects are arbitrary, and the connection relationship between the subjects is an example. The subjects can be connected or not connected, and the connection can be in any manner, can be direct or indirect, and can be wired or wireless.

[0143] Embodiments of the present disclosure can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 6th generation mobile communication system (6G), 5G New Radio (NR), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New Radio access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (Bluetooth (registered trademark)), Public Land Mobile Network (PLMN) network, Device-to-Device (D2D) system, Machine to Machine (M2M) system, Internet of Things (IoT) system, Vehicle-to-Everything (V2X), system using other communication methods, next-generation system expanded based thereon, and the like. Further, a plurality of systems can be applied in combination (for example, combination of LTE or LTE-A and 5G, combination of 5G and 5G, combination of 5G and 6G, and the like).

[0144] In some embodiments, in a 5G network, most of the data stored or transmitted comes from network communication operations and subscriptions. As 6G functions and services will expand from communication to sensing, computing, and / or artificial intelligence, data in the network will grow in both range and type. As an abstract function between data providers and data consumers, data services can separate data consumers and data providers. When there are multiple data providers or consumers, data services can help maintain data integrity and improve efficiency through reusability. Data services utilize data distribution / publishing frameworks to provide data as a service product to meet customers' real-time cross-system data needs, while reusing and complying with enterprise / industry regulations. Ultimately, data services need to strike a balance between data sharing and data transmission security in the data plane. 6G data services aim to efficiently support the collection, transmission, storage, and / or sharing of data. Therefore, the main problem to be solved is how to provide data to internal or external network functions in a convenient, efficient, and secure manner.

[0145] When data from a UE is transmitted in a separate data plane, existing security mechanisms for protecting control plane and user plane traffic cannot be reused. Therefore, a method is needed to protect data traffic transmitted in a separate data plane.

[0146] In some embodiments, as shown in FIG. IB, unlike the 5G architecture, the 6G architecture can include three independent planes, i.e., a control plane, a user plane, and a data plane, which handle different types of traffic. Among them, the control plane carries signaling traffic for each UE; the control plane is used to handle tasks such as authentication, authorization, and / or mobility management. The user plane carries actual data traffic for each UE. The data plane is responsible for the collection and / or management of shared data; the data in the data plane can be associated with a group of UEs of one owner, or used for one network task / service task, rather than one UE. Here, the 6G architecture can include at least one of the following: a network exposure function (NEF), a network repository function (NRF), a policy control function (PCF), a UDM, an application function (AF), an authentication server function (AUSF), an AMF, an SMF, a NWDAF, a UE, a (R)AN, a UPF, a DPF, and a data network (DN).

[0147] Some network functions in 6G can include 6G NWDAF or 6G DPMF, and / or 6G GDP. Among them, 6G NWDAF or 6G DPMF can be used to manage shared data; for example, can be used to collect and / or expose data, etc. 6G DPF can be used to forward and route shared data to target network functions (NFs); for example, can be forwarded to 6G NWDAF or 6G DPMF, etc. 6G DPF also has an anchor function in the data plane, and can be used as an interconnection point between the UE and the 6G core network (6GC) control plane / user plane / data plane.

[0148] In some embodiments, the UE can be a terminal, or the terminal can be a UE.

[0149] Figure 2 is an interaction diagram of an information processing method according to an embodiment of the present disclosure. As shown in Figure 2, the embodiment of the present disclosure relates to an information processing method for an information processing system 100, and the method comprises:

[0150] In step S2101, the terminal sends a second message to a second network element.

[0151] In some embodiments, the second network element receives the second message sent by the terminal.

[0152] In some embodiments, the terminal sends the second message to the second network element through the access network device.

[0153] In some embodiments, the second network element receives the second message sent by the terminal through the access network device.

[0154] In some embodiments, the terminal sends the second message to the access network device, and the access network device sends the second message to the second network element.

[0155] In some embodiments, the second network element receives the second message sent by the access network device, wherein the second message is sent by the terminal to the access network device.

[0156] Optionally, the second network element can be an AMF or an SMF. For example, the second network element can be a 6G AMF or a 6G SMF.

[0157] In some embodiments, the second message is used to request to establish a connection, and the connection is used to transmit data plane (DP) data.

[0158] In some embodiments, the second message further includes at least one of the following: a second identifier and / or a first indication; wherein the second identifier is used to indicate a data service; and the first indication is used to indicate that the connection type is a connection.

[0159] In some embodiments, the name of the second message is not limited, which is, for example, a connection establishment request or a data plane connection establishment request, etc.

[0160] Optionally, the connection is a first connection or a data plane connection. For example, the connection can be a data plane connection between the terminal and the access network device. For another example, the connection is a data plane connection between the terminal and the first network element; the data plane connection is from the terminal to the access network device and then to the first network element, or the data plane connection is from the first network element to the access network device and then to the terminal. For another example, the connection can be a data plane connection between the terminal and the second network element; the data plane connection is from the terminal to the access network device and then to the first network element and then to the second network element, or the data plane connection is from the second network element to the first network element and then to the access network device and then to the terminal.

[0161] Optionally, the data plane data can be any security-protected data transmitted in the data plane connection; for example, it can be any DP-encrypted data.

[0162] Optionally, the DP security protection includes DP confidentiality protection and / or DP integrity protection. For example, the DP confidentiality protection can be the confidentiality protection of the DP data; the DP integrity protection can be the integrity protection of the DP data.

[0163] Optionally, the name of the second identifier is not limited; for example, it can be a service identifier or a data service identifier, etc. The second identifier can also be a task identifier, etc. The second identifier is used to uniquely identify a data service.

[0164] Optionally, the first indication is used to indicate that the connection type is a data plane connection.

[0165] Optionally, the name of the first indication is not limited; for example, it can be a connection type identifier or a data plane connection type identifier.

[0166] Step S2102: The second network element performs a first operation.

[0167] In some embodiments, the first operation includes at least one of the following: obtaining subscription information; obtaining data service related information; determining whether to authorize the terminal to access the data service; determining the first network element; rejecting the second message; determining the first identifier; and obtaining policy information.

[0168] In some embodiments, the second network element obtains the subscription information and / or the data service related information from a fourth network element. Optionally, the fourth network element can be a UDM or a UDR, etc. For example, the fourth network element can be a 6G UDM or a 6G UDR, etc.

[0169] In some embodiments, the second network element obtains the subscription information from the fourth network element. Optionally, the second network element sends a fifth request to the fourth network element, wherein the fifth request is used to request the subscription information; and the second network element receives the subscription information sent by the fourth network element.

[0170] In some embodiments, the second network element obtains the data service related information from the fourth network element. Optionally, the second network element sends a sixth request to the fourth network element, wherein the sixth request is used to request the data service related information; and the second network element receives the data service related information sent by the fourth network element.

[0171] Optionally, the subscription information comprises authorization information and / or policy information.

[0172] Optionally, the data service related information can be any information related to the data service; for example, the data service related information can comprise policy information and / or authorization information.

[0173] Optionally, the authorization information is used to determine whether at least one terminal is authorized to access the data service. For example, the authorization information can comprise correspondence information between the second identity of at least one data service and the terminal identity of at least one terminal; for example, the second identity of data service 1 has correspondence with the terminal identity of terminal 1 and terminal 2, but the second identity of data service 1 has no correspondence with the terminal identity of terminal 3, so it is determined that terminal 1 and terminal 2 are authorized to access data service 1, but terminal 3 is not authorized to access data service 1.

[0174] Optionally, the policy information can comprise first policy information and / or second policy information; wherein the first policy indication is used to indicate whether to activate the integrity protection of DP data; and the second policy indication is used to indicate whether to activate the confidentiality protection of DP data. For example, the policy information can be used to indicate to activate the integrity protection of DP data and / or the confidentiality protection of DP data. For example, the policy information can be used to indicate not to activate the integrity protection of DP data and / or the confidentiality protection of DP data.

[0175] Optionally, the policy information can be used to indicate one of the following: the integrity protection and / or the confidentiality protection of DP data must be used; the integrity protection and / or the confidentiality protection of DP data is preferred to be used; and the integrity protection and / or the confidentiality protection of DP data is not needed to be used.

[0176] In some embodiments, the second network element determines the first network element.

[0177] In some embodiments, the second network element determines whether the terminal is authorized to access the data service based on the subscription information; and determines the first network element in case that the terminal is determined to be authorized to access the data service. Optionally, the second network element determines the first network element based on the second identifier.

[0178] In some embodiments, the second network element determines whether the terminal is authorized to access the data service based on the subscription information; and determines the first network element in case that the terminal is determined to be authorized to access the data service. Optionally, the second network element determines the first network element based on the second identifier.

[0179] In some embodiments, the second network element determines the first identifier.

[0180] Optionally, the second network element generates the first identifier of the connection. Exemplarily, the first identifier can be used to uniquely identify the connection. Exemplarily, the name of the first identifier is not limited, which is, for example, a connection identifier or a data plane identifier, etc.

[0181] Optionally, the second network element obtains the first identifier of the connection which is generated in history. Exemplarily, the first identifier can be generated by the second network element before.

[0182] Optionally, the second network element obtains the first identifier of the connection which is stored. Exemplarily, the first identifier can be obtained from other core network devices, or the first identifier can be generated by the second network element before and stored in the second network element.

[0183] In some embodiments, the second network element obtains the policy information.

[0184] Optionally, the second network element obtains the policy information from the subscription information. Exemplarily, the second network element obtains the policy information included in the subscription information.

[0185] Optionally, the second network element obtains the policy information from the data service related information. Exemplarily, the second network element obtains the policy information included in the data service related information.

[0186] Optionally, the second network element obtains the policy information configured locally. Exemplarily, the second network element configures the policy information and stores in the local storage.

[0187] Optionally, the priority of the policy information obtained from the subscription information or the data service related information is higher than the priority of the policy information configured locally.

[0188] For example, the second network element determines to use the policy information indicating to activate the integrity protection and / or the confidentiality protection of the DP as the current policy information, if the policy information obtained from the subscription information indicates to activate the integrity protection and / or the confidentiality protection of the DP and the policy information obtained from the local configuration indicates not to activate the integrity protection and / or the confidentiality protection of the DP.

[0189] For example, the second network element determines to use the policy information indicating to activate the integrity protection and / or the confidentiality protection of the DP as the current policy information, if the policy information obtained from the subscription information indicates to activate the integrity protection and / or the confidentiality protection of the DP and the policy information obtained from the local configuration indicates not to activate the integrity protection and / or the confidentiality protection of the DP.

[0190] Optionally, the priority of the policy information obtained from the subscription information is higher than the priority of the policy information obtained from the data service related information.

[0191] Optionally, the priority of the policy information obtained from the data service related information is higher than the priority of the policy information obtained from the subscription information.

[0192] Step S2103: The second network element sends a fourth message to the access network device.

[0193] In some embodiments, the access network device receives the fourth message sent by the second network element.

[0194] In some embodiments, the fourth message is used for establishing a connection.

[0195] In some embodiments, the fourth message further includes at least one of the following: the policy information, the first identifier, and the address of the first network element.

[0196] Optionally, the policy information includes the first policy indication and / or the second policy indication.

[0197] Optionally, the address of the first network element includes a DPF address or a UPF address.

[0198] In some embodiments, the name of the fourth message is not limited, which is, for example, a connection setup request or a data plane connection setup request.

[0199] Step S2104: The access network device determines a DP security key.

[0200] In some embodiments, the access network device generates a DP security key in a case where it is determined to activate the integrity protection and / or the confidentiality protection of the DP data, wherein the DP security key comprises a DP integrity key and / or a DP encryption key.

[0201] In some embodiments, the access network device generates the DP security key based on the first key and the first parameter.

[0202] Optionally, the first parameter comprises at least one of a first indicator, a first length, a second indicator and a second length. Illustratively, the first indicator is used to indicate an algorithm. Illustratively, the first length is used to indicate a length of the first indicator. Illustratively, the second indicator is used to indicate a type of the algorithm. Illustratively, the second length is used to indicate a length of the second indicator.

[0203] Optionally, the first key is a root key or a long-term credential.

[0204] Optionally, the access network device generates the DP security key based on the first key, the first indicator, the first length, the second indicator and the second length.

[0205] In some optional embodiments, the access network device obtains policy information; and the access network device determines to activate or not to activate the integrity protection and / or the confidentiality protection of the DP data in a case where the policy information indicates that the integrity protection and / or the confidentiality protection of the DP data is preferred to be used. That is, in a case where the policy information indicates that the integrity protection and / or the confidentiality protection of the DP data is preferred to be used, the access network device can select whether to activate (or whether to use) the integrity protection and / or the confidentiality protection of the DP data by itself.

[0206] In step S2105, the access network device sends a third message to the terminal.

[0207] In some embodiments, the terminal receives the third message sent by the access network device.

[0208] In some embodiments, the third message comprises at least one of a second indication, a third indication and second information that has been DP security protected.

[0209] In some embodiments, the third message can comprise an RRC message. Illustratively, the third message can be an RRC Connection Reconfiguration message.

[0210] In some embodiments, the name of the third message is not limited.

[0211] Optionally, the second indication is used to indicate whether integrity protection of the DP data is activated.

[0212] Optionally, the third indication is used to indicate whether confidentiality protection of the DP data is activated.

[0213] Optionally, the third message can comprise second information which has been DP security protected based on the DP security key. For example, the third message can comprise second information which has been integrity protected based on the DP integrity key and / or confidentiality protected based on the DP confidentiality key.

[0214] Optionally, the second information is information obtained by performing DP security protection on the third message.

[0215] Optionally, the second information can be any data.

[0216] Optionally, the second indication and the third indication can each be one or more bits.

[0217] In some embodiments, the second indication is applicable to each DRB or each connection; or the third indication is applicable to each DRB or each connection.

[0218] At step S2106, the terminal determines the DP security key.

[0219] In some embodiments, the terminal generates the DP security key in a case where it is determined that the integrity protection and / or the confidentiality protection of the DP data is activated, wherein the DP security key comprises the DP integrity key and / or the DP confidentiality key.

[0220] In some embodiments, the terminal generates the DP security key based on the first key and the first parameter. Optionally, the first parameter comprises at least one of the following: the first indicator, the first length, the second indicator and the second length. Optionally, the terminal generates the DP security key based on the first key, the first indicator, the first length, the second indicator and the second length.

[0221] In some embodiments, the terminal determines the DP security key in a similar manner to the manner in which the access network device determines the DP security key.

[0222] At step S2107, the terminal sends a first response to the access network device.

[0223] In some embodiments, the access network device receives the first response sent by the terminal.

[0224] In some embodiments, the first response comprises third information which has been DP security protected based on the DP security key. For example, the third information can be any information; for example, the third information can be data plane data.

[0225] In some embodiments, the first response can comprise an RRC message. For example, the first response can be an RRC Connection Reconfiguration Complete message.

[0226] In some embodiments, the name of the first response is not limited.

[0227] In some optional embodiments, before sending the first response, the terminal further comprises: determining, by the terminal, whether the third message is successfully verified based on the DP security key. Here, whether the third message is successfully verified refers to whether the second information in the third message that has been DP security protected is successfully verified. Whether the third message is successfully verified refers to whether the decrypted complete second information is obtained. Here, verifying the third message comprises integrity verification and / or decryption of the second information in the third message.

[0228] In some embodiments, the terminal sends the first response to the access network device in the case that the third message is successfully verified based on the DP security key. Here, the terminal receives the third message comprising the second information that has been DP security protected, and the second indication and / or the third indication; wherein the second indication is used to indicate that the integrity protection of the DP data is activated, and the third indication is used to indicate that the confidentiality protection of the DP data is activated. Here, successfully verifying the third message based on the DP security key comprises decrypting the second information of the third message based on the DP confidentiality key and / or integrity verifying the third message based on the DP integrity key, and comparing with the second information.

[0229] In some optional embodiments, in the case that the third message is successfully verified (based on the DP security key), the terminal determines to perform DP security protection on the data transmitted through the DRB or the connection; and the first response comprises the third information that has been DP security protected based on the DP security key. Here, the data can comprise the first information.

[0230] In some optional embodiments, in the case that the third message fails to be verified (based on the DP security key), the terminal determines not to perform DP security protection on the data transmitted through the DRB or the connection.

[0231] Step S2108, the access network device sends a third response to the second network element.

[0232] In some embodiments, the second network element receives the third response sent by the access network device.

[0233] In some embodiments, the third response is used to indicate that the connection between the access network device and the terminal has been established; and / or the DP security protection of the connection has been activated.

[0234] In some embodiments, the third response is not limited, which is, for example, a connection setup response or a data plane connection setup response.

[0235] In some embodiments, the third response is determined based on the fourth message.

[0236] In some optional embodiments, before the access network device sends the third response to the second network element, the access network device further comprises: determining, by the access network device, whether the third information in the first response that has been DP security protected is successfully verified based on the DP security key.

[0237] In some embodiments, the access network device sends the third response to the second network element in the case of successfully verifying the first response. Here, successfully verifying the first response comprises: successfully verifying the first response based on the DP security key. Here, successfully verifying the first response comprises: successfully verifying the first response to obtain the third information after decryption and / or integrity verification.

[0238] In some optional embodiments, the access network device determines to perform DP security protection on data transmitted through the DRB or the connection in the case of successfully verifying the first response. Here, the data can comprise the first information.

[0239] In some optional embodiments, the access network device determines not to perform DP security protection on data transmitted through the DRB or the connection in the case of failing to verify the first response. Here, failing to verify the first response can be: failing to verify the first response based on the DP security key, or unsuccessfully verifying the first response based on the DP security key. Here, failing to verify the first response comprises: unsuccessfully decrypting the third information in the first response and / or failing the integrity verification.

[0240] Step S2109, the terminal sends a first message to the access network device.

[0241] In some embodiments, the access network device receives the first message sent by the terminal.

[0242] In some embodiments, the first message comprises first information that has been DP security protected.

[0243] In some embodiments, the first message is used for the access network device to send to the first network element.

[0244] In some embodiments, the first message is used for the first network element to send the first information successfully verified from the first message to the second network element.

[0245] In some embodiments, the first message further comprises a first identifier indicating the connection, and the first identifier is used for the access network device to determine the first network element.

[0246] Optionally, the connection is for transmitting DP data.

[0247] Optionally, the first information can be any data transmitted by the data plane connection. Optionally, the data can be shared data.

[0248] Optionally, the first network element can be a DPF or a UPF. For example, the first network element can be a 6G DPF or a 6G UPF.

[0249] Optionally, the third network element can be a NWDAF or a DPMF. For example, the third network element can be a 6G NWDAF or a 6G DPMF, etc.

[0250] Optionally, the name of the first message is not limited, which is, for example, a Data Report message, etc.

[0251] In some optional embodiments, the access network device determines the first network element based on the first identifier. Here, the access network device can select the first network element of the data plane connection based on the first identifier; the first identifier is used to indicate the data plane connection, and the data plane connection has a corresponding relationship with the terminal, the access network device, the first network element, and the second network element.

[0252] In some optional embodiments, the access network device sends the first information after the DP security verification to the first network element.

[0253] In some optional embodiments, the first network element receives the first information after the DP security verification sent by the access network device.

[0254] In some optional embodiments, the access network device verifies the first information in the first message based on the DP security key to obtain the first information after the successful verification, and the access network device sends the first information after the successful verification to the first network element. Optionally, the DP security verification includes decryption and / or security verification. Optionally, the access network device sends the first information after the DP security verification based on the DP security key to the first network element. For example, the DP confidentiality key is used to decrypt the first information in the first message; and the DP integrity key is used to perform integrity verification on the first information in the first message.

[0255] In some optional embodiments, the first network element determines the third network element based on the first identifier. Here, the first network element can select the third network element of the data plane connection based on the first identifier.

[0256] In some optional embodiments, the first network element sends the first information after the DP security verification to the third network element. Optionally, the DP security verification includes decryption and / or security verification.

[0257] In some optional embodiments, the third network element receives the first information after the DP security verification from the first network element.

[0258] At step S2110, the access network device sends the second response to the terminal.

[0259] In some embodiments, the terminal receives the second response sent by the access network device.

[0260] In some embodiments, the second response is a response to the first information in the first message. For example, the second response is used to indicate that the access network device successfully obtains the first information; the second response is an acknowledgement message to the first message. For example, the second response is used to indicate that the access network device does not successfully obtain the first information.

[0261] In some embodiments, the name of the second response is not limited, for example, it is a data report response, etc.

[0262] In some optional embodiments, before the access network device sends the second response to the terminal, the method further includes: the first network element sends the second response to the access network device.

[0263] In some optional embodiments, the access network device receives the second response sent by the first network element.

[0264] In some optional embodiments, before the first network element sends the second response to the access network device, the method further includes: the third network element sends the second response to the first network element.

[0265] In some optional embodiments, the first network element receives the second response sent by the third network element.

[0266] In some optional embodiments, steps S2109 and S2110 can include: the terminal sends the first message to the access network device, wherein the first message includes the first information after the DP security protection; the access network device sends the first information after the DP security verification to the first network element; the first network element sends the first information after the DP security verification to the third network element; the third network element sends the second response to the first network element; the first network element sends the second response to the access network device; the access network device sends the second response to the terminal.

[0267] In some embodiments, the names of information and the like are not limited to the names described in the embodiments, and terms such as "information", "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "field", "symbol", "codebook", "codeword", "codepoint", "bit", "data", "program", "chip", and the like can be replaced with each other.

[0268] In some embodiments, "acquire", "obtain", "get", "receive", "transmit", "bidirectional transmission", "send and / or receive", and the like can be replaced with each other, and can be interpreted as various meanings such as reception from another subject, acquisition from a protocol, acquisition from a higher layer, self-processing, autonomous implementation, and the like.

[0269] In some embodiments, terms such as "send", "transmit", "report", "issue", "transmit", "bidirectional transmission", "send and / or receive", and the like can be replaced with each other.

[0270] In some embodiments, terms such as "certain", "preset", "pre-set", "set", "indicated", "a certain", "arbitrary", "first", and the like can be replaced with each other, and "certain A", "preset A", "pre-set A", "set A", "indicated A", "a certain A", "arbitrary A", "first A" can be interpreted as A specified in advance in a protocol and the like, A obtained by setting, configuration, or indication, and the like, A that is certain, a certain, arbitrary, or first, and the like, but are not limited thereto.

[0271] In some embodiments, determination or judgment can be performed by a value represented by 1 bit (0 or 1), by a true or false value (Boolean value) represented by true or false, by comparison of a numerical value (for example, comparison with a predetermined value), and the like, but is not limited thereto.

[0272] The information processing method related to the embodiments of the present disclosure can include at least one of steps S2101 to S2110. For example, step S2101 can be implemented as an independent embodiment; step S2102 can be implemented as an independent embodiment; the combination of step S2101 and step S2102 can be implemented as an independent embodiment; the combination of step S2101 and step S2103 can be implemented as an independent embodiment; the combination of steps S2104 to S2107 can be implemented as an independent embodiment; the combination of steps S2103 to S2107 can be implemented as an independent embodiment; the combination of step S2103 and step S2108 can be implemented as an independent embodiment; the combination of steps S2103 to S2108 can be implemented as an independent embodiment; the combination of steps S2101 to S2108 can be implemented as an independent embodiment; the combination of step S2109 and step S2110 can be implemented as an independent embodiment; the combination of steps S2104 to S2107 and step S2109 and step S2110 can be implemented as an independent embodiment; the combination of steps S2103 to S2107 and step S2109 and step S2110 can be implemented as an independent embodiment; and the combination of steps S2101 to S2110 can be implemented as an independent embodiment.

[0273] In some embodiments, steps S2102 to S2107 and steps S2109 to S2110 can be optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0274] In some embodiments, steps S2101 to S2102 and steps S2108 to S2110 can be optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0275] In some embodiments, steps S2101 to S2108 can be optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0276] In the embodiments of the present disclosure, each embodiment can be implemented independently or in combination with each other, and the steps in each embodiment can be distinguished as preceding steps and subsequent steps.

[0277] FIG. 3A is a flow diagram illustrating an information processing method according to an embodiment of the present disclosure. As shown in FIG. 3A, the embodiments of the present disclosure relate to an information processing method, which is performed by a terminal, and the above method comprises:

[0278] Step S3101, sending a second message.

[0279] The optional implementation of step S3101 can refer to the optional implementation of step S2101 in FIG. 2 and other associated parts in the embodiments related by FIG. 2, which will not be repeated here.

[0280] In some embodiments, the terminal can send the second message to the second network element, but is not limited thereto, and can send the second message to other subjects.

[0281] In some optional embodiments, the terminal sends the second message to the second network element through the access network device. For example, the terminal sends the second message to the access network device, and the access network device sends the second message to the second network element.

[0282] Step S3102, obtaining a third message.

[0283] The optional implementation of step S3102 can refer to the optional implementation of step S2105 in FIG. 2 and other associated parts in the embodiments related by FIG. 2, which will not be repeated here.

[0284] In some embodiments, the terminal can receive the third message sent by the access network device, but is not limited thereto, and can receive the third message sent by other subjects.

[0285] In some embodiments, the terminal obtains the third message specified by a protocol.

[0286] In some embodiments, the terminal obtains the third message from upper layer(s).

[0287] In some embodiments, the terminal processes to obtain the third message.

[0288] In some embodiments, step S3102 is omitted, and the terminal autonomously implements the function indicated by the third message, or the above function is default or default.

[0289] Step S3103, determining a DP security key.

[0290] The optional implementation of step S3103 can refer to the optional implementation of step S2106 in FIG. 2 and other associated parts in the embodiments related by FIG. 2, which will not be repeated here.

[0291] Step S3104, sending a first response.

[0292] The optional implementation of step S3104 can refer to the optional implementation of step S2107 in FIG. 2 and other associated parts in the embodiments related by FIG. 2, which will not be repeated here.

[0293] In some embodiments, the terminal can send the first response to the access network device, but is not limited thereto, and can send the first response to other subjects.

[0294] Step S3105: sending the first message.

[0295] The optional implementation of step S3105 can refer to the optional implementation of step S2109 in FIG. 2 and other associated parts in the embodiments involved in FIG. 2, which will not be repeated here.

[0296] In some embodiments, the terminal can send the first message to the access network device, but is not limited thereto, and can also send the first message to other subjects.

[0297] Step S3106: obtaining the second response.

[0298] The optional implementation of step S3106 can refer to the optional implementation of step S2110 in FIG. 2 and other associated parts in the embodiments involved in FIG. 2, which will not be repeated here.

[0299] In some embodiments, the terminal receives the third response sent by the access network device, but is not limited thereto, and can also receive the third response sent by other subjects.

[0300] In some embodiments, the terminal obtains the third response specified by a protocol.

[0301] In some embodiments, the terminal obtains the third response from upper layer(s).

[0302] In some embodiments, the terminal processes to obtain the third response.

[0303] In some embodiments, step S3106 is omitted, and the terminal autonomously implements the function indicated by the third response, or the above function is default or default.

[0304] The information processing method involved in the embodiments of the present disclosure can include at least one of steps S3101 to S3106. For example, step S3101 can be implemented as an independent embodiment; the combination of steps S3102 to S3104 can be implemented as an independent embodiment; the combination of steps S3101 to S3104 can be implemented as an independent embodiment; the combination of steps S3105 and S3106 can be implemented as an independent embodiment; the combination of steps S3102 to S3106 can be implemented as an independent embodiment; and the combination of steps S3101 to S3106 can be implemented as an independent embodiment.

[0305] In some embodiments, steps S3101, S3105 to S3106 can be optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0306] In some embodiments, steps S3101 to S3104 can be optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0307] In the embodiments of the present disclosure, each embodiment can be implemented independently or in combination with each other, and the steps in each embodiment can be distinguished as preceding steps or subsequent steps.

[0308] FIG. 3B is a flow diagram illustrating a method of processing information according to an embodiment of the present disclosure. As shown in FIG. 3B, the embodiment of the present disclosure relates to a method of processing information, which is performed by a terminal, and the above method comprises the following steps:

[0309] In step S3201, a first message is sent to an access network device, wherein the first message comprises first information that has been subjected to DP security protection; and the first message is used for the access network device to send to a first network element.

[0310] The optional implementation of step S3201 can refer to the optional implementation of step S2101 in FIG. 2, or the optional implementation of step S3101 in FIG. 3A, and other associated parts in the embodiments related to FIG. 2 and FIG. 3A, which will not be described here.

[0311] In some embodiments, the first message further comprises a first identifier indicating a connection, wherein the connection is used for transmitting DP data; and the first identifier is used for the access network device to determine the first network element.

[0312] In some embodiments, before the first message is sent to the access network device, the method further comprises: sending a second message to the access network device, wherein the second message is used for requesting to establish a connection.

[0313] In some embodiments, the second message further comprises at least one of the following: a second identifier, wherein the second identifier is used for indicating a data service; and a first indication, wherein the first indication is used for indicating that the connection type is a connection used for transmitting DP data.

[0314] In some embodiments, the method comprises: receiving a third message sent by the access network device, wherein the third message comprises at least one of the following: a second indication, wherein the second indication is used for indicating whether integrity protection of DP data is activated; a third indication, wherein the third indication is used for indicating whether confidentiality protection of DP data is activated; and second information that has been subjected to DP security protection.

[0315] In some embodiments, the second indication is applicable to each DRB or each connection; or the third indication is applicable to each DRB or each connection.

[0316] In some embodiments, the method further comprises: generating the DP security key in a case that it is determined to activate the integrity protection and / or the confidentiality protection of the DP data, wherein the DP security key comprises a DP integrity key and / or a DP confidentiality key.

[0317] In some embodiments, the generating the DP security key comprises: generating the DP security key based on the first key and a first parameter, wherein the first parameter comprises at least one of: a first indicator, wherein the first indicator is used to indicate an algorithm; a first length, wherein the first length is used to indicate a length of the first indicator; a second indicator, wherein the second indicator is used to indicate a type of the algorithm; and a second length, wherein the second length is used to indicate a length of the second indicator.

[0318] In some embodiments, the method further comprises: in a case that the third message is successfully verified, sending a first response to the access network device and / or determining to perform the DP security protection on data transmitted through the DRB or the connection, wherein the data comprises at least the first information; and the first response comprises third information that has been DP security protected based on the DP security key; or in a case that the verification of the third message fails, determining not to perform the DP security protection on the data transmitted through the DRB or the connection.

[0319] In some embodiments, the method further comprises: receiving a second response sent by the access network device, wherein the second response is a response to the first information in the first message.

[0320] In some embodiments, the first network element is a DPF or a UPF.

[0321] The above embodiments can be implemented independently or in combination with each other. The optional implementation manners can refer to the optional implementation manners of the steps in FIG. 2 and FIG. 3A, which are not described herein again.

[0322] FIG. 3C is a flow diagram of an information processing method according to some embodiments of the present disclosure. As shown in FIG. 3B, the embodiments of the present disclosure relate to an information processing method, which is performed by a terminal, and the above method comprises:

[0323] In step S3301, the third message is obtained. Optionally, the third message comprises second information that has been DP security protected.

[0324] The optional implementation manners of step S3301 can refer to the optional implementation manners of step S2105 in FIG. 2, or step S3102 in FIG. 3A, and other associated parts in the embodiments related to FIG. 2 and FIG. 3A, which are not described herein again.

[0325] In step S3302, the DP security key is determined.

[0326] The optional implementation of step S3302 can be found in step S2106 in Figure 2, or the optional implementation of step S3103 in Figure 3A, as well as other related parts in the embodiments involved in Figures 2 and 3A, which will not be repeated here.

[0327] Step S3303: Send the first response.

[0328] The optional implementation of step S3303 can be found in step S2107 in Figure 2 or the optional implementation of step S3104 in Figure 3A, as well as other related parts in the embodiments involved in Figures 2 and 3A, which will not be repeated here.

[0329] In some optional embodiments, a first response is sent upon successful verification of the second information in the first message that has been DP-secured based on the DP security key. Optionally, the first response includes a third information that has been DP-secured.

[0330] The above embodiments can be implemented individually or in combination with each other. Optional implementation methods can be found in the steps of Figures 2 and 3A, and will not be repeated here.

[0331] Figure 4A is a flowchart illustrating an information processing method according to an embodiment of the present disclosure. As shown in Figure 4A, the embodiment of the present disclosure relates to an information processing method executed by an access network device, the method comprising:

[0332] Step S4101: Obtain the fourth message.

[0333] The optional implementation of step S4101 can be found in the optional implementation of step S2103 in Figure 2, and other related parts in the embodiments involved in Figure 2, which will not be repeated here.

[0334] In some embodiments, the access network device receives a fourth message sent by a second network element, but is not limited thereto; it may also receive a fourth message sent by other entities.

[0335] In some embodiments, the access network device obtains the fourth message specified in the protocol.

[0336] In some embodiments, the access network device obtains a fourth message from the upper layer(s).

[0337] In some embodiments, the access network device processes the information to obtain the fourth message.

[0338] In some embodiments, step S4101 is omitted, and the access network device autonomously implements the function indicated by the fourth message, or the above function is defaulted or set to default.

[0339] Step S4102: Determine the DP security key.

[0340] The optional implementation of step S4102 can refer to the optional implementation of step S2104 in FIG. 2 and other associated parts in the embodiments related to FIG. 2, which will not be repeated here.

[0341] Step S4103: sending the third message.

[0342] The optional implementation of step S4103 can refer to the optional implementation of step S2105 in FIG. 2 and other associated parts in the embodiments related to FIG. 2, which will not be repeated here.

[0343] In some embodiments, the access network device can send the third message to the terminal, but is not limited thereto, and can send the third message to other subjects.

[0344] Step S4104: obtaining the first response.

[0345] The optional implementation of step S4104 can refer to the optional implementation of step S2107 in FIG. 2 and other associated parts in the embodiments related to FIG. 2, which will not be repeated here.

[0346] In some embodiments, the access network device receives the first response sent by the second network element, but is not limited thereto, and can receive the first response sent by other subjects.

[0347] In some embodiments, the access network device obtains the first response specified by a protocol.

[0348] In some embodiments, the access network device obtains the first response from upper layer(s).

[0349] In some embodiments, the access network device processes to obtain the first response.

[0350] In some embodiments, step S4104 is omitted, and the access network device autonomously implements the function indicated by the first response, or the above function is default or default.

[0351] Step S4105: sending the third response.

[0352] The optional implementation of step S4105 can refer to the optional implementation of step S2108 in FIG. 2 and other associated parts in the embodiments related to FIG. 2, which will not be repeated here.

[0353] In some embodiments, the access network device can send the third response to the second network element, but is not limited thereto, and can send the third response to other subjects.

[0354] Step S4106: obtaining the first message.

[0355] The optional implementation of step S4106 can refer to the optional implementation of step S2109 in FIG. 2 and other associated parts in the embodiments related to FIG. 2, which will not be repeated here.

[0356] In some embodiments, the access network device receives the first message sent by the terminal, but is not limited thereto, and can also receive the first message sent by other subjects.

[0357] In some embodiments, the access network device obtains the first message specified by the protocol.

[0358] In some embodiments, the access network device obtains the first message from the upper layer(s).

[0359] In some embodiments, the access network device processes to obtain the first message.

[0360] In some embodiments, step S4106 is omitted, and the access network device autonomously implements the function indicated by the first message, or the above function is default or default.

[0361] In some optional embodiments, the access network device performs DP security verification on the first information in the first message to obtain the first information after DP security verification.

[0362] In some optional embodiments, the access network device sends the first information after DP security verification.

[0363] In some optional embodiments, the access network device can send the first information to the first network element, but is not limited thereto, and can also send the first information to other subjects. Optionally, the first information after the DP security verification point is used for the first network element to send to the third network element.

[0364] Step S4107, obtaining the second response.

[0365] The optional implementation of step S4107 can refer to the optional implementation of step S2110 in FIG. 2 and other associated parts in the embodiments related to FIG. 2, which will not be repeated here.

[0366] In some embodiments, the access network device receives the second response sent by the first network element, but is not limited thereto, and can also receive the second response sent by other subjects. Optionally, the second response is received by the first network element from the third network element.

[0367] In some embodiments, the access network device obtains the second response specified by the protocol.

[0368] In some embodiments, the access network device obtains the second response from the upper layer(s).

[0369] In some embodiments, the access network device processes to obtain the second response.

[0370] In some embodiments, step S4107 is omitted, and the access network device autonomously implements the function indicated by the second response, or the function is default or default.

[0371] In some optional embodiments, the access network device sends the second response.

[0372] In some optional embodiments, the access network device can send the second response to the terminal, but is not limited thereto, and can also send the second response to other subjects.

[0373] The information processing method related to the embodiments of the present disclosure can include at least one of steps S4101 to S4107. For example, the combination of steps S4101 and S4105 can be implemented as an independent embodiment; the combination of steps S4102 to S4104 can be implemented as an independent embodiment; the combination of steps S4101 to S4105 can be implemented as an independent embodiment; the combination of steps S4106 and S4107 can be implemented as an independent embodiment; the combination of steps S4101 and S4106 and steps S4105 and S4107 can be implemented as an independent embodiment; and the combination of steps S4101 to S4107 can be implemented as an independent embodiment.

[0374] In some embodiments, steps S4101, S4105 to S4107 can be optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0375] In some embodiments, steps S4101 to S4105 can be optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0376] In the embodiments of the present disclosure, each embodiment can be implemented independently or in combination with each other, and the steps in each embodiment can be distinguished from the preceding and subsequent steps.

[0377] FIG. 4B is a flow diagram illustrating an information processing method according to an embodiment of the present disclosure. As shown in FIG. 4B, the embodiments of the present disclosure relate to an information processing method, which is performed by an access network device, and the above method comprises:

[0378] Step S4201, receiving a first message sent by a terminal, wherein the first message includes first information that has been subjected to DP security protection.

[0379] The optional implementation of step S4201 can refer to the optional implementation of step S2109 in FIG. 2, or the optional implementation of step S4106 in FIG. 4A, and other associated parts in the embodiments involved in FIG. 2 and FIG. 4A, which are not described here again.

[0380] In step S4202, the first information after the DP security verification is sent to the first network element.

[0381] The optional implementation of step S4202 can refer to the optional implementation in the optional embodiment of step S2109 in FIG. 2, or the optional implementation in the optional embodiment of step S4106 in FIG. 4A, and other associated parts in the embodiments involved in FIG. 2 and FIG. 4A, which are not described here again.

[0382] In some embodiments, the first message includes a first identifier indicating a connection for transmitting the DP data; and the method further includes determining the first network element based on the first identifier.

[0383] In some embodiments, before receiving the first message sent by the terminal, the method further includes receiving a second message sent by the terminal, wherein the second message is used to request to establish a connection; and sending the second message to the second network element.

[0384] In some embodiments, the second message further includes at least one of the following: a second identifier, wherein the second identifier is used to indicate a data service; and a first indication, wherein the first indication is used to indicate that the connection type is a connection for transmitting the DP data.

[0385] In some embodiments, the method further includes receiving a fourth message sent by the second network element, wherein the fourth message is used to establish the connection.

[0386] In some embodiments, the fourth message further includes at least one of the following: policy information, wherein the policy information includes at least one of the following: a first policy indication, used to indicate whether to activate integrity protection of the DP data; a second policy indication, used to indicate whether to activate confidentiality protection of the DP data; the first identifier; and an address of the first network element.

[0387] In some embodiments, the method includes generating a DP security key including a DP integrity key and / or a DP confidentiality key, in a case where it is determined to activate the integrity protection and / or the confidentiality protection of the DP data.

[0388] In some embodiments, the generating the DP security key comprises: generating the DP security key based on the first key and a first parameter; wherein the first parameter comprises at least one of: a first indicator, wherein the first indicator is used to indicate an algorithm; a first length, wherein the first length is used to indicate a length of the first indicator; a second indicator, wherein the second indicator is used to indicate a type of the algorithm; and a second length, wherein the second length is used to indicate a length of the second indicator.

[0389] In some embodiments, the method further comprises: sending, to the terminal, a third message, wherein the third message comprises at least one of: a second indication, wherein the second indication is used to indicate whether to activate the integrity protection of the DP data; a third indication, wherein the third indication is used to indicate whether to activate the DP confidentiality protection of the DP data; and second information that is DP security protected based on the DP security key.

[0390] In some embodiments, the method further comprises: receiving a first response sent by the terminal, wherein the first response comprises third information that is DP security protected based on the DP security key; and the first response is sent by the terminal in a case that the third message is successfully verified.

[0391] In some embodiments, the method further comprises: in a case that the first response is successfully verified, sending, to the second network element, a third response and / or determining to perform the DP security protection on the data transmitted through the DRB or the connection; wherein the third response is used to indicate that the connection between the access network device and the terminal is established and / or to indicate that the DP security protection of the connection is activated; or in a case that the verification of the first response fails, determining not to perform the DP security protection on the data transmitted through the DRB or the connection.

[0392] In some embodiments, the method further comprises: receiving a second response sent by the first network element, wherein the second response is a response to the first information in the first message; and sending, to the terminal, the second response.

[0393] In some embodiments, the first network element is a DPF or a UPF; and / or the second network element is an AMF or an SMF.

[0394] The above embodiments can be implemented independently or in combination with each other, and optional implementation manners can refer to the optional implementation manners of the steps of FIG. 2 and FIG. 4A, which are not described herein again.

[0395] FIG. 4C is a flow diagram of an information processing method according to some embodiments of the present disclosure. As shown in FIG. 4C, the embodiments of the present disclosure relate to an information processing method, which is performed by an access network device, and the above method comprises:

[0396] In step S4301, the DP security key is determined.

[0397] The optional implementation of step S4301 can refer to the optional implementation of step S2104 in FIG. 2, or the optional implementation of step S4102 in FIG. 4A, and other associated parts in the embodiments related to FIG. 2 and FIG. 4A, which are not described here again.

[0398] In step S4302, a third message is sent. Optionally, the second information that has been DP security protected is included in the third message.

[0399] The optional implementation of step S4302 can refer to the optional implementation of step S2105 in FIG. 2, or the optional implementation of step S4103 in FIG. 4A, and other associated parts in the embodiments related to FIG. 2 and FIG. 4A, which are not described here again.

[0400] In step S4303, a first response is obtained.

[0401] The optional implementation of step S4301 can refer to the optional implementation of step S2107 in FIG. 2, or the optional implementation of step S4104 in FIG. 4A, and other associated parts in the embodiments related to FIG. 2 and FIG. 4A, which are not described here again.

[0402] In some optional embodiments, the first response is sent by the terminal in the case that the terminal successfully verifies the second information that has been DP security protected in the first message based on the DP security key; and the third information that has been DP security protected is included in the first response.

[0403] The above embodiments can be implemented independently or in combination with each other, and the optional implementation can refer to the optional implementation of steps in FIG. 2 and FIG. 4A, which are not described here again.

[0404] FIG. 5A is a flow diagram of an information processing method according to some embodiments of the present disclosure. As shown in FIG. 5A, the embodiments of the present disclosure relate to an information processing method, which is performed by a first network element, and the method comprises the following steps:

[0405] In step S5101, first information is obtained. Optionally, the first message includes first information that has been DP security protected, and the first network element receives the first information that has been DP security verified and sent by an access network device. Optionally, the first message includes a first identifier.

[0406] The optional implementation of step S5101 can refer to the optional implementation of step S2109 in FIG. 2, and other associated parts in the embodiments related to FIG. 2, which are not described here again.

[0407] In some embodiments, the first network element receives the first information sent by the access network device, but is not limited thereto, and can also receive the first information sent by other subjects.

[0408] In some embodiments, the first network element obtains the first information specified by a protocol.

[0409] In some embodiments, the first network element obtains the first information from upper layer(s).

[0410] In some embodiments, the first network element processes to obtain the first information.

[0411] In some embodiments, step S5101 is omitted, and the first network element autonomously implements the function indicated by the first information, or the above function is default or default.

[0412] Step S5102, determining the third network element. Optionally, the third network element is determined based on the first identifier.

[0413] The optional implementation of step S5102 can refer to the optional implementation in the optional embodiment of step S2109 in FIG. 2 and other associated parts in the embodiments involved in FIG. 2, which will not be repeated here.

[0414] Step S5103, sending the first information. Optionally, the first network element sends the first information after the DP security verification.

[0415] The optional implementation of step S5103 can refer to the optional implementation in the optional embodiment of step S2109 in FIG. 2 and other associated parts in the embodiments involved in FIG. 2, which will not be repeated here.

[0416] Step S5104, obtaining the second response.

[0417] The optional implementation of step S5104 can refer to the optional implementation of step S2110 in FIG. 2 and other associated parts in the embodiments involved in FIG. 2, which will not be repeated here.

[0418] In some embodiments, the first network element receives the second response sent by the third network element, but is not limited thereto, and can also receive the second response sent by other subjects.

[0419] In some embodiments, the first network element obtains the second response specified by the protocol.

[0420] In some embodiments, the first network element obtains the second response from upper layer(s).

[0421] In some embodiments, the first network element processes to obtain the second response.

[0422] In some embodiments, step S5104 is omitted, and the first network element autonomously implements the function indicated by the second response, or the above function is default or default.

[0423] Step S5105, sending the second response.

[0424] The optional implementation of step S5105 can refer to the optional implementation in step S2110 in FIG. 2, and other related parts in the embodiments involved in FIG. 2, which will not be repeated here.

[0425] In some embodiments, the first network element can send the first response to the access network device, but is not limited thereto, and can also send the first response to other subjects.

[0426] The information processing method related to the embodiments of the present disclosure can include at least one of steps S5101 to S5105. For example, the combination of steps S5101 and S5103 can be implemented as an independent embodiment; step S5102 can be implemented as an independent embodiment; the combination of steps S5101 to S5103 can be implemented as an independent embodiment; the combination of steps S5104 and S5105 can be implemented as an independent embodiment; and the combination of steps S5101 to S5105 can be implemented as an independent embodiment.

[0427] In some embodiments, steps S5102, S5104 to S5105 can be optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0428] In the embodiments of the present disclosure, each embodiment can be implemented independently or in combination with each other, and the steps in each embodiment can be distinguished as preceding steps and subsequent steps.

[0429] FIG. 5B is a flow diagram illustrating an information processing method according to an embodiment of the present disclosure. As shown in FIG. 5B, the embodiments of the present disclosure relate to an information processing method, which is performed by a first network element, and the above method comprises:

[0430] Step S5201, receiving the first information after DP security verification sent by the access network device. Optionally, the first information after DP security verification is obtained by the access network device from the first message; the first message is obtained by the access network device from the terminal, and the first message includes the first information after DP security protection.

[0431] The optional implementation of step S5201 can refer to the optional implementation of step S2109 in FIG. 2, or the optional implementation of step S5101 in FIG. 5A, and other related parts in the embodiments involved in FIG. 2 and FIG. 5A, which will not be repeated here.

[0432] Step S5202, sending the first information after DP security verification to a third network element.

[0433] The optional implementation of step S5202 can refer to the optional implementation of step S2109 in FIG. 2, or the optional implementation of step S5101 in FIG. 5A, and other associated parts in the embodiments involved in FIG. 2 and FIG. 5A, which are not described herein again.

[0434] In some embodiments, the first message further comprises: a first identifier indicating the connection; and the method further comprises: determining the third network element based on the first identifier.

[0435] In some embodiments, the method further comprises: receiving a second response sent by the third network element, wherein the second response is a response to the first information in the first message; and sending the second response to the access network device.

[0436] In some embodiments, the first network element is a DPF or a UPF; and / or, the third network element is a NWDAF or a DPMF.

[0437] The above embodiments can be implemented alone or in combination with each other, and the optional implementation can refer to the optional implementation of steps in FIG. 2 and FIG. 5A, which are not described herein again.

[0438] FIG. 6A is a flow diagram illustrating a method of processing information according to an embodiment of the present disclosure. As shown in FIG. 6A, the embodiment of the present disclosure relates to a method of processing information, which is performed by a second network element, and the above method comprises:

[0439] Step S6101: obtaining a second message.

[0440] The optional implementation of step S6101 can refer to the optional implementation of step S2101 in FIG. 2, and other associated parts in the embodiments involved in FIG. 2, which are not described herein again.

[0441] In some embodiments, the second network element receives the second message sent by the terminal, but is not limited thereto, and can also receive the second message sent by other subjects.

[0442] In some embodiments, the second network element obtains the second message specified by a protocol.

[0443] In some embodiments, the second network element obtains the second message from an upper layer.

[0444] In some embodiments, the second network element processes to obtain the second message.

[0445] In some embodiments, step S6101 is omitted, and the second network element autonomously implements the function indicated by the second message, or the above function is default.

[0446] In some optional embodiments, the second network element receives the second message sent by the terminal through the access network device.

[0447] Step S6102, determining the first operation.

[0448] The optional implementation of step S6102 can refer to the optional implementation of step S2102 in FIG. 2 and other associated parts in the embodiments related to FIG. 2, which will not be repeated here.

[0449] In some optional embodiments, the second network element acquires the subscription information and / or the data service related information.

[0450] In some optional embodiments, the second network element determines whether to authorize the terminal to access the data service.

[0451] In some optional embodiments, the second network element determines the first network element based on the first identifier.

[0452] In some optional embodiments, the second network element rejects the second message.

[0453] In some optional embodiments, the second network element determines the first identifier.

[0454] In some optional embodiments, the second network element acquires the policy information.

[0455] Step S6103, sending a fourth message.

[0456] The optional implementation of step S6103 can refer to the optional implementation of step S2103 in FIG. 2 and other associated parts in the embodiments related to FIG. 2, which will not be repeated here.

[0457] In some embodiments, the second network element can send the fourth message to the access network device, but is not limited thereto, and can send the fourth message to other subjects.

[0458] Step S6104, acquiring a third response.

[0459] The optional implementation of step S6104 can refer to the optional implementation of step S2108 in FIG. 2 and other associated parts in the embodiments related to FIG. 2, which will not be repeated here.

[0460] In some embodiments, the second network element receives the third response sent by the access network device, but is not limited thereto, and can receive the third response sent by other subjects.

[0461] In some embodiments, the second network element acquires the third response specified by a protocol.

[0462] In some embodiments, the second network element acquires the third response from upper layer(s).

[0463] In some embodiments, the second network element processes to obtain the third response.

[0464] In some embodiments, step S6104 is omitted, and the second network element autonomously implements the function indicated by the third response, or the function is default or default.

[0465] The information processing method related to the embodiments of the present disclosure can include at least one of steps S6101 to S6104. For example, step S6101 can be implemented as an independent embodiment; step S6102 can be implemented as an independent embodiment; the combination of step S6101 and step S6102 can be implemented as an independent embodiment; the combination of steps S6103 to S6104 can be implemented as an independent embodiment; and the combination of steps S6101 to S6104 can be implemented as an independent embodiment.

[0466] In some embodiments, steps S6101, S6103 to S6104 can be optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0467] In some embodiments, steps S6101 to S6102 can be optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0468] In the embodiments of the present disclosure, each embodiment can be implemented independently or in combination with each other, and the steps in each embodiment can be distinguished as preceding steps and subsequent steps.

[0469] FIG. 6B is a flow diagram illustrating an information processing method according to an embodiment of the present disclosure. As shown in FIG. 6B, the embodiments of the present disclosure relate to an information processing method, which is performed by a second network element, and the method includes:

[0470] Step S6201, receiving a second message sent by an access network device, wherein the second message is used to request to establish a connection; the connection is used to transmit DP data, and the data includes first information that has been subjected to DP security protection.

[0471] The optional implementation of step S6201 can refer to the optional implementation of step S2101 in FIG. 2, or the optional implementation of step S6101 in FIG. 6A, and other associated parts in the embodiments related to FIG. 2 and FIG. 6A, which will not be repeated here.

[0472] In some embodiments, the second message further includes at least one of the following: a second identifier, wherein the second identifier is used to indicate a data service; and a first indication, wherein the first indication is used to indicate that the connection type is a connection.

[0473] In some embodiments, the method further comprises: obtaining the subscription information and / or the data service related information from the fourth network element; wherein the subscription information comprises authorization information and / or policy information; and the data service related information comprises the policy information.

[0474] In some embodiments, the method further comprises: determining whether the terminal is authorized to access the data service based on the subscription information; and determining the first network element in a case that the terminal is determined to be authorized to access the data service.

[0475] In some embodiments, the method further comprises: rejecting the second message in a case that the terminal is determined not to be authorized to access the data service.

[0476] In some embodiments, the method further comprises one of: generating the first identifier of the connection; obtaining the first identifier of the connection generated in history; and obtaining the first identifier of the connection stored.

[0477] In some embodiments, the method further comprises at least one of: obtaining the policy information from the subscription information; obtaining the policy information from the data service related information; and obtaining the policy information configured locally.

[0478] In some embodiments, the policy information obtained from the subscription information or the data service related information has a higher priority than the policy information configured locally.

[0479] In some embodiments, the method further comprises: sending a fourth message to the access network device, wherein the fourth message is used to establish the connection; and receiving a third response sent by the access network device, wherein the third response is used to indicate that the connection between the access network device and the terminal has been established and / or to indicate that the DP security protection of the connection has been activated.

[0480] In some embodiments, the fourth message further comprises at least one of: the policy information, wherein the policy information comprises at least one of: a first policy indication used to indicate whether to activate the integrity protection of the DP data; a second policy indication used to indicate whether to activate the confidentiality protection of the DP data; the first identifier; and an address of the first network element.

[0481] In some embodiments, the first network element is a DPF or a UPF; and / or the second network element is an AMF or an SMF; and / or the fourth network element is a UDM or a UDR.

[0482] The above embodiments can be implemented independently or in combination with each other, and optional implementation manners can refer to the optional implementation manners of the steps of FIG. 2 and FIG. 6A, which are not described herein again.

[0483] FIG. 7A is an interaction schematic diagram of an information processing method according to an embodiment of the present disclosure. As shown in FIG. 7A, the embodiment of the present disclosure relates to an information processing method, which is used for an information processing system 100, and the method comprises one of the following steps:

[0484] At step S7101, the terminal sends a first message to the access network device. Optionally, the first message includes first information that has been DP security protected.

[0485] The optional implementation of step S7101 can refer to the optional implementation in step S2109 in FIG.2, step S3105 in FIG.3A, step S4106 in FIG.4A, step S5101 in FIG.5A, and other associated parts in the embodiments related to FIG.2, FIG.3A, FIG.4A, and FIG.5A, which will not be repeated here.

[0486] At step S7102, the access network device sends the first information that has been DP security verified to the first network element.

[0487] The optional implementation of step S7102 can refer to the optional implementation in step S2109 in FIG.2, step S4106 in FIG.4A, step S5101 in FIG.5A, and other associated parts in the embodiments related to FIG.2, FIG.4A, and FIG.5A, which will not be repeated here.

[0488] At step S7103, the first network element sends the first information that has been DP security verified to the third network element.

[0489] The optional implementation of step S7103 can refer to the optional implementation in step S2109 in FIG.2, step S5103 in FIG.5A, and other associated parts in the embodiments related to FIG.2 and FIG.5A, which will not be repeated here.

[0490] In some embodiments, the above method can include the method described in the above information processing system side, terminal side, access network device side, first network element side, and / or second network element side, and so on, which will not be repeated here.

[0491] FIG.7B is a flow diagram of an information processing method according to some embodiments of the present disclosure. As shown in FIG.7B, some embodiments of the present disclosure relate to an information processing method, which includes:

[0492] Assumption: Data plane connection between UE and 6G DPF is established. During the data plane connection establishment process, the 6G DPF determines a target network function (NF) (e.g., 6G NWDAF or 6G DPMF) for the received shared data. The 6G DPF can determine the protection of the traffic via the data plane connection based on the data plane (DP) security policy.

[0493] At step S7201, the UE sends shared data to the RAN node.

[0494] Optionally, the UE sends the shared data to the RAN node through a data plane connection. The protection of the shared data is determined in a data plane connection establishment process.

[0495] Optionally, the RAN node can be a 6G RAN node or an access network device in the above embodiments; the 6G RAN node can be replaced by a 6G non-3GPP node. The UE can be a terminal in the previous embodiments. The shared data can be the first information in the previous embodiments; the data report carrying the shared data can be the first message in the previous embodiments.

[0496] In step S7202, the RAN node sends the shared data to the DPF.

[0497] Optionally, the access network device determines the corresponding DPF based on the established data plane connection; and forwards the shared data to the DPF.

[0498] Optionally, the DPF can be a 6G DPF or a first network element in the previous embodiments. The 6G UPF can function as a 6G DPF.

[0499] In step S7203, the DPF sends the shared data to the NWDAF or DPMF.

[0500] Optionally, the DPF determines the corresponding NWDAF or DPMF based on the established data plane connection; and forwards the shared data to the NWDAF or DPMF.

[0501] Optionally, the NWDAF can be a 6G NWDAF; the DPMF can be a 6G DPMF; the NWDAF or DPMF can be a third network element in the previous embodiments.

[0502] In step S7204, the NWDAF or DPMF sends a data report response to the DPF.

[0503] Optionally, the data report response can be the second response in the previous embodiments.

[0504] In step S7205, the DPF sends the data report response to the RAN node.

[0505] In step S7206, the RAN node sends the data report response to the UE.

[0506] In the embodiments of the present disclosure, part or all of the steps and optional implementation manners thereof can be combined with part or all of the steps of other embodiments, or can be combined with optional implementation manners of other embodiments.

[0507] FIG. 7C is a flow diagram of an information processing method according to an embodiment of the present disclosure. As shown in FIG. 7C, the present disclosure relates to an information processing method, which includes:

[0508] At step S7301, the UE sends a data plane connection establishment request to the AMF or SMF via the RAN node.

[0509] Optionally, the RAN node can be a 6G RAN node or the access network device in the previous embodiments; the AMF and SMF can be a 6G AMF and 6G SMF respectively; the AMF and SMF can be the second network element in the previous embodiments; and the UE can be the terminal in the previous embodiments. The data plane connection establishment request can be the second request in the previous embodiments.

[0510] Optionally, in order to establish a data plane connection for a 6G data service, the UE sends a data plane connection request to a control plane NF (e.g., a 6G AMF or a 6G SMF), which includes a service identifier or a task identifier, a connection type indication, etc.

[0511] Optionally, the service identifier or the task identifier can be the second identifier in the previous embodiments; and the connection type indication can be the first indication in the previous embodiments. The data plane connection establishment request can be the second message in the previous embodiments.

[0512] At step S7302, the AMF or SMF obtains authorization information and / or data service related information from a UDM or UDR.

[0513] Optionally, the UDM and UDR can be a 6G UDM and a 6G UDR respectively; and the UDM and UDR can be the fourth network element in the previous embodiments. The AMF or SMF can be replaced by other 6G core network (6GC) network functions (NFs). The data service related information can be 6G data service related information.

[0514] Optionally, the AMF or SMF determines whether the UE is authorized to access (consume or provide) a data service based on subscription information; for example, to provide shared data or obtain shared data. If the UE is not authorized to access the data service, the AMF or SMF rejects the data plane connection establishment request. Here, the data service can be a 6G data service.

[0515] At step S7303, the AMF or SMF selects a DPF.

[0516] Optionally, the AMF or SMF selects a DPF if it is determined that the UE is authorized to access the data service; and generates a connection identifier for the requested data plane connection. Here, the connection identifier can be the first identifier in the previous embodiments.

[0517] The AMF or SMF sends a data plane connection setup request to the RAN node, at step S7304.

[0518] Optionally, the AMF or SMF sends a data plane connection setup request to the RAN node, the data plane connection setup request including a DP security policy, a connection ID, and / or a DPF address, etc.

[0519] Optionally, the data plane connection setup request can be the fourth message in the previous embodiments; the DPF address can be a 6G DPF address; and the DP security policy can be the policy information in the previous embodiments.

[0520] Optionally, the AMF or SMF determines the DP security policy (including a confidentiality protection policy and an integrity protection policy) based on: obtaining the DP security policy from subscription information received from a UDM; obtaining the DP security policy from data service related information retrieved from a UDR; or obtaining the DP security policy from local configuration in the AMF or SMF. Here, the DP security policy obtained from local configuration is used when the DP security policy is provided in the UDM or UDR.

[0521] Optionally, the DP security policy from the UDM or UDR takes precedence over the DP security policy configured locally.

[0522] Optionally, the DP security policy includes a DP integrity inclusion policy and / or a DP confidentiality protection policy; and the DP security policy indicates one of: DP integrity protection and / or DP confidentiality protection is required for all traffic for this data plane connection; DP integrity protection and / or DP confidentiality protection is preferred for all traffic on this data plane connection; and DP integrity protection and / or DP confidentiality protection is not required for all traffic on this data plane connection. Here, the DP integrity protection can be the DP data integrity protection in the previous embodiments; and the DP confidentiality protection can be the DP data confidentiality protection in the previous embodiments.

[0523] The UE and the RAN node activate DP security protection, at step S7305.

[0524] Optionally, the RAN node determines how to implement or activate DP security protection over the air interface based on the DP security policy received from the core network device and / or a DP security policy configured locally (if configured). The RAN node can issue a specific signaling exchange with the UE that is related to the information received from the AMF or SMF. For example, the RAN node can interact with the UE through an RRC connection reconfiguration for activating DP security protection.

[0525] Step S7306, the RNA node sends a data plane connection setup response to the AMF or the SMF.

[0526] Optionally, the data plane connection setup response can be the third response in the previous embodiment.

[0527] Step S7307, the UE sends uplink data through the data plane connection.

[0528] Step S7308, the DPF sends downlink data through the data plane connection.

[0529] In the embodiments of the present disclosure, part or all of the steps, and optional implementation manners thereof, can be combined with part or all of the steps in other embodiments, or can be combined with optional implementation manners of other embodiments.

[0530] FIG. 7D is a flow diagram of an information processing method according to an embodiment of the present disclosure. As shown in FIG. 7D, the present disclosure relates to an information processing method, which comprises:

[0531] Step S7401A, the RAN node activates RRC security. That is, RRC encryption and RRC integrity protection are activated.

[0532] Optionally, the RRC connection reconfiguration procedure should be performed after the RRC security as part of the AS security mode command procedure. The RAN node can be a 6G RAN node or an access network device in the previous embodiment.

[0533] Step S7401B, the RAN node sends an RRC connection reconfiguration message to the UE.

[0534] Optionally, the RRC connection reconfiguration message is used for activation of DP security protection; the RRC connection reconfiguration message includes an indication of DP integrity protection and / or DP confidentiality protection activated for each DRB or data plane connection according to the policy information.

[0535] Optionally, the indication of DP integrity protection can be the second indication in the previous embodiment; the indication of DP confidentiality protection can be the third indication in the previous embodiment; the RRC connection reconfiguration message can be the third message in the previous embodiment. The UE can be the terminal in the previous embodiment.

[0536] Step S7401C, the RAN node generates a DP security key and starts DP security protection.

[0537] Optionally, if DP integrity protection is activated for a DRB or data plane connection and if the RAN node does not have a DP integrity key (K DPint ), the RAN node shall generate K DPint ; and DP integrity protection for this DRB or data plane connection shall start at the RAN node. And / or, if DP confidentiality protection is activated for a DRB or data plane connection and if the RAN node does not have a DP confidentiality key (K DPenc ), the RAN node shall generate K DPenc ; and DP confidentiality protection for this DRB or data plane connection shall start at the RAN node.

[0538] Step S7402A, the UE verifies the RRC connection reconfiguration message.

[0539] Optionally, if DP integrity protection is activated for a DRB or data plane connection and if the UE does not have K DPint , the UE shall generate K DPint ; and DP integrity protection for this DRB or data plane connection shall start at the UE. And / or, if DP confidentiality protection is activated for a DRB or data plane connection and if the UE does not have K DPenc , the UE shall generate K DPenc ; and DP confidentiality protection for this DRB or data plane connection shall start at the UE.

[0540] Step S7402B, the UE sends an RRC connection reconfiguration complete message to the RAN node.

[0541] Optionally, the UE shall send an RRC connection reconfiguration complete message to the RAN node if it successfully verifies the integrity of the RRC connection reconfiguration message.

[0542] Optionally, the RRC reconfiguration complete message can be the first response in the previous embodiments.

[0543] In some optional embodiments, if DP integrity protection is not activated for a DRB or data plane connection, the RAN node and the UE shall not integrity protect data of data services of such DRB or data plane connection. If DP encryption is not activated for a DRB or data plane connection, the RAN node and the UE shall not encrypt data of data services of such DRB or data plane connection.

[0544] In the embodiments of the present disclosure, part or all of the steps, and optional implementation manners thereof, can be combined with part or all of the steps in other embodiments, or can be combined with optional implementation manners of other embodiments.

[0545] FIG. 7E is a schematic diagram of a key, according to an embodiment of the present disclosure. As shown in FIG. 7E, the key (K gNB ) involved in an embodiment of the present disclosure can include: an RRC integrity key (K RRCint ), an RRC confidentiality key (K RRCenc ), a user plane integrity key (K UPint ), a user plane confidentiality key (K UPenc ), a data plane integrity key (K DPint ), and / or a data plane confidentiality key (K DPenc ).

[0546] The key for protecting DP traffic: K DPenc is a key derived by the terminal (e.g., Mobile Equipment (ME)) and the 6G RAN node from K gNB , which should only be used to protect DP traffic with a specific confidentiality algorithm between the terminal (e.g., ME) and the 6G RAN node. DPint is a key derived by the terminal (e.g., ME) and the 6G RAN node from K gNB , which should only be used to protect DP traffic with a specific integrity algorithm between the terminal (e.g., ME) and the 6G RAN node.

[0547] Algorithm key derivation function: when deriving the confidentiality key (e.g., K gNB ) and the integrity key (e.g., K DPenc ) from K DPint in the 6G RAN node and the UE, the following parameters will be used to form a string:

[0548] FC = 0x69;

[0549] P0 = algorithm type identifier;

[0550] L0 = length of the algorithm type identifier (e.g., 0x00 0x01);

[0551] P1 = algorithm identity;

[0552] L1 = length of the algorithm identity (e.g., 0x00 0x01).

[0553] Optionally, P0 can be the first indicator in the previous embodiment; L0 can be the first length in the previous embodiment; P1 can be the second indicator in the previous embodiment; and L1 can be the second length in the previous embodiment.

[0554] Optionally, the algorithm type can be as shown in Table 1, which can include a non-access stratum confidentiality algorithm (N-NAS-enc-alg), a non-access stratum integrity algorithm (N-NAS-int-alg), an RRC confidentiality algorithm (N-RRC-enc-alg), an RRC integrity algorithm (N-RRC-int-alg), a user plane confidentiality algorithm (N-UP-enc-alg), a user plane integrity algorithm (N-UP-int-alg), a data plane confidentiality algorithm (N-DP-enc-alg), and / or a data plane integrity algorithm (N-DP-int-alg).

[0555] Table 1

[0556] Embodiments of the present disclosure relate to an information processing method, comprising:

[0557] DPF (e.g., 6G DPF) side:

[0558] The 6G DPF forwards the shared data to the NWDAF (e.g., 6G NWDAF) or DPMF (e.g., 6G DPMF) through the data plane.

[0559] The 6G DPF establishes a data plane connection with the UE.

[0560] The 6G DPF determines the 6G NWDAF or 6G DPMF that sends the shared data if the shared data based on the established data plane connection is received.

[0561] AMF (e.g., 6G AMF) or SMF (e.g., 6G SMF) side:

[0562] The 6G AMF or 6G SMF obtains a DP security policy. Optionally, the DP security policy can be the policy information in the previous embodiments.

[0563] The 6G AMF or 6G SMF provides the DP security policy (or DP security implementation information) to the 6G RAN node.

[0564] The 6G AMF or 6G SMF selects a DPF to establish a DP connection between the 6G DPF and the UE.

[0565] The 6G AMF or 6G SMF determines whether the UE is authorized to use the 6G data service.

[0566] Access network device (e.g., 6G RAN node) side:

[0567] The 6G RAN node obtains the DP security policy from the 6G AMF or 6G SMF.

[0568] 6G RAN node generates DP integrity key (K DPint ) and DP confidentiality key (K DPenc ).

[0569] 6G RAN node sends RRC reconfiguration message to UE.

[0570] 6G RAN node activates DP integrity protection and DP confidentiality protection.

[0571] UDM (e.g. 6G UDM) side:

[0572] 6G UDM provides UE subscription information to 6G AMF or 6G SMF.

[0573] UE side:

[0574] UE generates DP integrity key (K DPint ) and DP confidentiality key (K DPenc ).

[0575] UE activates DP integrity protection and DP confidentiality protection.

[0576] UE sends RRC connection reconfiguration complete message.

[0577] Embodiments of the present disclosure also propose an apparatus for implementing any of the above methods, for example, an apparatus comprising units or modules for implementing the steps performed by a terminal in any of the above methods. For another example, another apparatus is also proposed, comprising units or modules for implementing the steps performed by a network device (such as an access network device, a core network function node, a core network device, etc.) in any of the above methods.

[0578] It should be understood that the division of each unit or module in the above apparatus is only a logical function division, and all or part of them can be integrated into a physical entity or physically separated in actual implementation. In addition, the units or modules in the apparatus can be implemented in the form of processor calling software: for example, the apparatus includes a processor, the processor is connected with a memory, the memory stores instructions, and the processor calls the instructions stored in the memory to realize any of the above methods or realize the functions of each unit or module of the above apparatus, wherein the processor is a general processor such as a central processing unit (CPU) or a microprocessor, and the memory is a memory in the apparatus or a memory outside the apparatus. Alternatively, the units or modules in the apparatus can be implemented in the form of hardware circuit, and the functions of part or all of the units or modules can be realized by the design of hardware circuit. The above hardware circuit can be understood as one or more processors; for example, in one implementation, the above hardware circuit is an application-specific integrated circuit (ASIC), and the functions of part or all of the units or modules are realized by the design of the logical relationship of elements in the circuit; for another example, in another implementation, the above hardware circuit is a programmable logic device (PLD), and a field programmable gate array (FPGA) is taken as an example, which can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by a configuration file, so as to realize the functions of part or all of the above units or modules. All units or modules of the above apparatus can be all implemented in the form of processor calling software, or all implemented in the form of hardware circuit, or part implemented in the form of processor calling software and the remaining part implemented in the form of hardware circuit.

[0579] In embodiments of the present disclosure, the processor is a circuit with signal processing capability. In one implementation, the processor can be a circuit with instruction reading and running capability, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), a digital signal processor (DSP), or the like. In another implementation, the processor can implement certain functions through a logical relationship of hardware circuits, and the logical relationship of the hardware circuits is fixed or can be reconfigured. For example, the processor is a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In the reconfigurable hardware circuit, the processor loads a configuration document to implement the configuration of the hardware circuit. It can be understood that the processor loads instructions to implement the functions of part or all of the units or modules described above. In addition, the hardware circuit can also be designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), or the like.

[0580] FIG. 8A is a structural schematic diagram of a terminal 8100 according to an embodiment of the present disclosure. As shown in FIG. 8A, the terminal 8100 includes a first transceiver module 8101 and a first processing module 8102. In some embodiments, the first transceiver module 8101 is configured to send a first message. Optionally, the first transceiver module 8101 is configured to perform at least one of the sending and / or receiving steps (for example, steps S2101 and / or steps S2107 and / or steps S2109 and / or steps S2110, but not limited thereto) performed by the terminal 8100 in any of the methods described above. Details are not described herein again. In some embodiments, the first processing module 8102 is configured to determine a DP security key. Optionally, the first processing module 8102 performs at least one of the processing steps (for example, steps S2106, but not limited thereto) performed by the terminal 8100 in any of the methods described above. Details are not described herein again.

[0581] FIG. 8B is a structural schematic diagram of the access network device 8200 according to an embodiment of the present disclosure. As shown in FIG. 8B, the access network device 8200 includes a second transceiver module 8201 and a second processing module 8202. In some embodiments, the second transceiver module 8201 is configured to send the first message. Optionally, the second transceiver module 8201 is configured to perform at least one of the sending and / or receiving steps (for example, steps S2105 and / or steps S2107 to S2110, but not limited to this) performed by the access network device 8200 in any of the above methods, details of which are not described herein again. In some embodiments, the second processing module 8202 is configured to determine the DP security key. Optionally, the second processing module 8202 is configured to perform at least one of the processing steps (for example, step S2104, but not limited to this) performed by the access network device 8200 in any of the above methods, details of which are not described herein again.

[0582] FIG. 8C is a structural schematic diagram of the first network element 8300 according to an embodiment of the present disclosure. As shown in FIG. 8C, the first network element 8300 includes a third transceiver module 8301. In some embodiments, the third transceiver module 8301 is configured to send the first information that has been decrypted and / or integrity-verified. Optionally, the third transceiver module 8301 is configured to perform at least one of the sending and / or receiving steps (for example, the optional embodiment of step S2109, but not limited to this) performed by the first network element 8300 in any of the above methods, details of which are not described herein again.

[0583] FIG. 8D is a structural schematic diagram of the second network element 8400 according to an embodiment of the present disclosure. As shown in FIG. 8D, the second network element 8400 includes a fourth transceiver module 8401 and a third processing module 8402. In some embodiments, the fourth transceiver module 8401 is configured to receive the first information that has been decrypted and / or integrity-verified. Optionally, the fourth transceiver module 8401 is configured to perform at least one of the sending and / or receiving steps (for example, the optional embodiment of step S2109, but not limited to this) performed by the second network element 8400 in any of the above methods, details of which are not described herein again. In some embodiments, the third processing module 8402 is configured to perform the first operation. Optionally, the third processing module 8402 is configured to perform at least one of the processing steps (for example, step S2102, but not limited to this) performed by the second network element 8400 in any of the above methods, details of which are not described herein again.

[0584] In some embodiments, the transceiving module can include a transmitting module and / or a receiving module, which can be separate or integrated together. Alternatively, the transceiving module can be replaced by a transceiver. For example, the first transceiving module includes a first transmitting module and / or a first receiving module. For example, the second transceiving module includes a second transmitting module and / or a second receiving module.

[0585] In some embodiments, the processing module can be one module or include multiple sub-modules. Alternatively, the multiple sub-modules perform all or part of the steps required to be performed by the processing module, respectively. Alternatively, the processing module can be replaced by a processor.

[0586] FIG. 9A is a structural schematic diagram of a communication device 9100 according to the embodiments of the present disclosure. The communication device 9100 can be a network device (for example, an access network device, a core network device, etc.), a terminal, a chip, a chip system, or a processor supporting the network device to implement any of the above methods, or a chip, a chip system, or a processor supporting the terminal to implement any of the above methods. The communication device 9100 can be used to implement the methods described in the above method embodiments, and details can be referred to the descriptions in the above method embodiments.

[0587] As shown in FIG. 9A, the communication device 9100 includes one or more processors 9101. The processor 9101 can be a general-purpose processor or a special-purpose processor, for example, a baseband processor or a central processing unit. The baseband processor can be used to process communication protocols and communication data, and the central processing unit can be used to control the communication device (for example, a base station, a baseband chip, a terminal device, a terminal device chip, a DU or a CU, etc.), execute programs, and process data of the programs. Alternatively, the communication device 9100 is used to execute any of the above methods. Alternatively, the one or more processors 9101 are used to call instructions to enable the communication device 9100 to execute any of the above methods.

[0588] In some embodiments, the communication device 9100 further includes one or more transceivers 9102. When the communication device 9100 includes one or more transceivers 9102, the transceiver 9102 performs at least one of the communication steps (e.g., steps S2101 and / or step S2103 and / or step S2105 and / or step S2107 and / or step S2108 and / or step S2109 and / or step S2110, etc., but not limited to) in the above-described methods, and the processor 9101 performs at least one of the other steps (e.g., steps S2102 and / or S2104 and / or step S2106, etc., but not limited to). In optional embodiments, the transceiver can include a receiver and / or a transmitter, which can be separate or integrated together. Optionally, the terms transceiver, transceiving unit, transceiver, transceiving circuit, interface circuit, interface, etc., can be replaced with each other, and the terms transmitter, transmitting unit, transmitter, transmitting circuit, etc., can be replaced with each other, and the terms receiver, receiving unit, receiver, receiving circuit, etc., can be replaced with each other.

[0589] In some embodiments, the communication device 9100 further includes one or more memories 9103 for storing data. Optionally, all or part of the memory 9103 can also be outside the communication device 9100. In optional embodiments, the communication device 9100 can include one or more interface circuits 9104. Optionally, the interface circuit 9104 is connected to the memory 9103, and the interface circuit 9104 can be used to receive data from the memory 9103 or other devices, and can be used to send data to the memory 9103 or other devices. For example, the interface circuit 9104 can read the data stored in the memory 9103 and send the data to the processor 9101.

[0590] The communication device 9100 described in the above embodiments can be a network device or a terminal, but the scope of the communication device 9100 described in the present disclosure is not limited thereto, and the structure of the communication device 9100 can not be limited by FIG. 9A. The communication device can be a standalone device or can be part of a larger device. For example, the communication device can be: (1) a standalone integrated circuit (IC), or a chip, or a chip system or subsystem; (2) a set of one or more ICs, which can optionally include storage components for storing data, programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, a terminal device, a smart terminal device, a cellular phone, a wireless device, a handset, a mobile unit, a vehicle-mounted device, a network device, a cloud device, an artificial intelligence device, etc.; (6) others, etc.

[0591] FIG. 9B is a structural schematic diagram of the chip 9200 according to an embodiment of the present disclosure. For the case that the communication device 9100 can be a chip or a chip system, the structural schematic diagram of the chip 9200 shown in FIG. 9B can be referred to, but is not limited thereto.

[0592] The chip 9200 comprises one or more processors 9201. The chip 9200 is configured to execute any of the above methods.

[0593] In some embodiments, the chip 9200 further comprises one or more interface circuits 9202. Optionally, the terms of interface circuit, interface, transceiver pin, etc. can be replaced by each other. In some embodiments, the chip 9200 further comprises one or more memories 9203 for storing data. Optionally, all or part of the memory 9203 can be outside the chip 9200. Optionally, the interface circuit 9202 is connected with the memory 9203, the interface circuit 9202 can be configured to receive data from the memory 9203 or other devices, and the interface circuit 9202 can be configured to send data to the memory 9203 or other devices. For example, the interface circuit 9202 can read the data stored in the memory 9203 and send the data to the processor 9201.

[0594] In some embodiments, the interface circuit 9202 performs at least one of the communication steps (such as steps S2101 and / or steps S2103 and / or steps S2105 and / or steps S2107 and / or steps S2108 and / or steps S2109 and / or steps S2110, etc.) of the above methods. The interface circuit 9202 performing the communication steps such as transmitting and / or receiving in the above methods means that the interface circuit 9202 performs data interaction between the processor 9201, the chip 9200, the memory 9203 or the transceiver device. In some embodiments, the processor 9201 performs at least one of other steps (such as steps S2102 and / or steps S2104 and / or steps S2106, etc., but not limited thereto).

[0595] The modules and / or devices described in each of the embodiments of the virtual device, the physical device, the chip, etc. can be combined or separated as appropriate. Optionally, part or all of the steps can also be performed by a plurality of modules and / or devices in cooperation, which is not limited herein.

[0596] The present disclosure further provides a storage medium having stored instructions which, when executed on the communication device 9100, cause the communication device 9100 to perform any of the above methods. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer-readable storage medium, but is not limited thereto and can also be a storage medium readable by other apparatuses. Optionally, the storage medium can be a non-transitory storage medium, but is not limited thereto and can also be a transitory storage medium.

[0597] The present disclosure further provides a program product which, when executed by the communication device 9100, causes the communication device 9100 to perform any of the above methods. Optionally, the program product is a computer program product.

[0598] The present disclosure further provides a computer program which, when executed on a computer, causes the computer to perform any of the above methods.

Claims

1. An information processing method characterized by comprising: The method is performed by a terminal, comprising: sending a first message to an access network device, wherein the first message comprises first information that has been subjected to data plane (DP) security protection; and the first message is used for the access network device to send to a first network element.

2. The method of claim 1, wherein, The first message further comprises a first identifier indicating a connection for transmitting DP data; and the first identifier is used for the access network device to determine the first network element.

3. The method of claim 2, wherein, Before the step of sending the first message to the access network device, the method further comprises: sending a second message to the access network device, wherein the second message is used for requesting to establish the connection.

4. The method of claim 3, wherein, The second message further comprises at least one of: a second identifier, wherein the second identifier is used for indicating a data service; and a first indication, wherein the first indication is used for indicating that a connection type is a connection for transmitting DP data.

5. The method according to claim 3 or 4, characterized in that, The method comprises: receiving a third message sent by the access network device, wherein the third message comprises at least one of: a second indication, wherein the second indication is used for indicating whether integrity protection of DP data is activated; and a third indication, wherein the third indication is used for indicating whether confidentiality protection of DP data is activated; and second information that has been subjected to DP security protection.

6. The method of claim 5, wherein, The second indication is applicable to each data radio bearer (DRB) or each connection; or the third indication is applicable to each DRB or each connection.

7. The method of claim 5, wherein, The method further comprises: in a case where it is determined that the integrity protection and / or the confidentiality protection of DP data are activated, generating a DP security key, wherein the DP security key comprises a DP integrity key and / or a DP confidentiality key.

8. The method of claim 7, wherein, The step of generating the DP security key comprises: generating the DP security key based on a first key and a first parameter, wherein the first parameter comprises at least one of: a first indicator, wherein the first indicator is used for indicating an algorithm; and a first length, wherein the first length is used for indicating a length of the first indicator; and a second indicator, wherein the second indicator is used for indicating a type of the algorithm; and a second length, wherein the second length is used for indicating a length of the second indicator.

9. The method of claim 8, wherein, The method further comprises: in a case where the third message is successfully verified, sending a first response to the access network device and / or determining to perform DP security protection on data transmitted through a DRB or a connection, wherein the data at least comprises the first information; and the first response comprises third information that has been subjected to DP security protection based on the DP security key. Or, in a case where the third message fails to be verified, determining not to perform DP security protection on data transmitted through the DRB or the connection.

10. The method according to any one of claims 1 to 9, characterized in that, The method further comprises: receiving a second response sent by the access network device, wherein the second response is a response to the first information in the first message.

11. The method of any of claims 1 to 10, wherein: the first network element is a data plane function (DPF) or a user plane function (UPF).

12. An information processing method characterized by comprising: The method is performed by an access network device, comprising: receiving a first message sent by a terminal, wherein the first message comprises first information that has been subjected to data plane (DP) security protection. sending the first information after the DP security verification to the first network element.

13. The method of claim 12, wherein, The first message includes a first identifier indicating a connection used for transmitting the DP data. The method further includes determining the first network element based on the first identifier.

14. The method of claim 13, wherein, Before the receiving of the first message sent by the terminal, the method further includes: receiving a second message sent by the terminal, wherein the second message is used for requesting to establish the connection; sending the second message to a second network element.

15. The method of claim 14, wherein, The second message further includes at least one of: a second identifier, wherein the second identifier is used for indicating a data service; a first indication, wherein the first indication is used for indicating that the connection type is a connection used for transmitting the DP data.

16. The method of claim 14, wherein, The method further includes: receiving a fourth message sent by a second network element, wherein the fourth message is used for establishing the connection.

17. The method of claim 16, wherein, The fourth message further includes at least one of: policy information, wherein the policy information includes at least one of: a first policy indication used for indicating whether to activate integrity protection of the DP data; and a second policy indication used for indicating whether to activate confidentiality protection of the DP data; the first identifier; an address of the first network element.

18. The method of claim 17, wherein, The method includes: generating a DP security key in a case where it is determined to activate the integrity protection and / or the confidentiality protection of the DP data, wherein the DP security key includes a DP integrity key and / or a DP confidentiality key.

19. The method of claim 18, wherein, The generating of the DP security key includes: generating the DP security key based on a first key and a first parameter, wherein the first parameter includes at least one of: a first indicator, wherein the first indicator is used for indicating an algorithm; a first length, wherein the first length is used for indicating a length of the first indicator; a second indicator, wherein the second indicator is used for indicating a type of the algorithm; a second length, wherein the second length is used for indicating a length of the second indicator.

20. The method of claim 17 or 18, wherein, The method further includes: sending a third message to the terminal, wherein the third message includes at least one of: a second indication, wherein the second indication is used for indicating whether to activate the integrity protection of the DP data; a third indication, wherein the third indication is used for indicating whether to activate the DP confidentiality protection of the DP data; second information subjected to DP security protection based on the DP security key.

21. The method of claim 20, wherein, The method further includes: receiving a first response sent by the terminal, wherein the first response includes third information subjected to DP security protection based on a DP security key; and the first response is sent by the terminal in a case where the third message is successfully verified.

22. The method of claim 21, wherein, The method further includes: in a case where the first response is successfully verified, sending a third response to the second network element and / or determining to perform DP security protection on data transmitted through a DRB or a connection; wherein the third response is used for indicating that the connection between the access network device and the terminal is established and / or indicating that the DP security protection of the connection is activated; or, in a case where the verification of the first response fails, determining not to perform the DP security protection on the data transmitted through the DRB or the connection.

23. The method according to any one of claims 12 to 22, characterized in that, The method further includes: receiving a second response sent by the first network element, wherein the second response is a response to the first information in the first message; sending the second response to the terminal.

24. The method of any one of claims 12-23, wherein: the first network element is a data plane function (DPF) or a user plane function (UPF); and / or the second network element is an access and mobility management function (AMF) or a session management function (SMF). The method is performed by a first network element and includes:

25. An information processing method characterized by comprising: receiving first information after data plane (DP) security verification sent by an access network device; wherein the first information after DP security verification is obtained by the access network device from a first message; the first message is obtained by the access network device from a terminal, and the first message includes first information that has been DP security protected; sending the first information after DP security verification to a third network element. The first message further includes a first identifier indicating a connection.

26. The method of claim 25, wherein, The method further includes determining the third network element based on the first identifier. The method further includes:

27. The method of claim 25 or 26, wherein, receiving a second response sent by the third network element, wherein the second response is a response to the first information; sending the second response to the access network device.

28. The method of any one of claims 25-27, wherein: the first network element is a data plane function (DPF) or a user plane function (UPF); and / or the third network element is a network data analytics function (NWDAF) or a data plane management (DPMF). The method is performed by a second network element and includes: receiving a second message sent by an access network device, wherein the second message is used to request establishment of a connection; the connection is used to transmit data plane (DP) data, and the data includes first information that has been DP security protected.

29. An information processing method characterized by comprising: The second message further includes at least one of: a second identifier, wherein the second identifier is used to indicate a data service; 30. The method of claim 29, wherein, a first indication, wherein the first indication is used to indicate that a connection type is a connection. The method further includes: obtaining subscription information and / or data service related information from a fourth network element; wherein the subscription information includes authorization information and / or policy information; and the data service related information includes the policy information.

31. The method of claim 29 or 30, wherein, The method further includes: determining whether the terminal is authorized to access a data service based on the subscription information; 32. The method of claim 31, wherein, determining a first network element in a case where it is determined that the terminal is authorized to access the data service. The method further includes: rejecting the second message in a case where it is determined that the terminal is not authorized to access the data service.

33. The method of claim 32, wherein, The method further includes one of: generating a first identifier of the connection; 34. The method of claim 32, wherein, obtaining the first identifier of the connection that has been generated historically; obtaining the first identifier of the connection that has been stored. The method further includes at least one of: obtaining the policy information from subscription information; 35. The method of any one of claims 31 to 34, wherein, obtaining the policy information from data service related information; obtaining the policy information that is locally configured. The priority of the policy information obtained from the subscription information or the data service related information is higher than the priority of the policy information obtained from the local configuration. The method further includes:

36. The method of claim 35, wherein, ​ 37. The method of claim 32, wherein, ​ sending a fourth message to the access network device, wherein the fourth message is used to establish the connection; receiving a third response sent by the access network device, wherein the third response is used to indicate that the connection between the access network device and the terminal has been established and / or to indicate that the DP security protection of the connection has been activated.

38. The method of claim 37, wherein, The fourth message further includes at least one of the following: policy information, wherein the policy information includes at least one of the following: a first policy indication used to indicate whether to activate the integrity protection of the DP data; and a second policy indication used to indicate whether to activate the confidentiality protection of the DP data; a first identifier; an address of the first network element.

39. The method of any of claims 29-38, the first network element is a data plane function (DPF) or a user plane function (UPF); and / or the second network element is an access and mobility management function (AMF) or a session management function (SMF); and / or the fourth network element is a unified data management (UDM) or a unified data repository (UDR).

40. An information processing method characterized by comprising: comprising: sending, by the terminal, a first message to an access network device, wherein the first message includes first information that has been subjected to data plane (DP) security protection; sending, by the access network device, the first information that has been subjected to DP security verification to a first network element; sending, by the first network element, the first information that has been subjected to DP security verification to a third network element.

41. A terminal, characterized by comprising: a first transceiver module configured to send a first message to an access network device, wherein the first message includes first information that has been subjected to data plane (DP) security protection; the first message is used by the access network device to send to a first network element.

42. An access network device, comprising: comprising: a second transceiver module configured to receive a first message sent by a terminal, wherein the first message includes first information that has been subjected to DP security protection; the second transceiver module is further configured to send the first information that has been subjected to DP security verification to a first network element.

43. A first network element, characterized by, comprising: a third transceiver module configured to receive first information that has been subjected to DP security verification sent by an access network device; wherein the first information that has been subjected to DP security verification is obtained by the access network device from a first message; the first message is obtained by the access network device from a terminal, and the first message includes first information that has been subjected to DP security protection; the third transceiver module is further configured to send the first information that has been subjected to DP security verification to a third network element.

44. A second network element, characterized by, comprising: a fourth transceiver module configured to receive a second message sent by an access network device, wherein the second message is used to request establishment of a connection; the connection is used to transmit data plane (DP) data, and the data includes first information that has been subjected to DP security protection.

45. A communications device, characterized by comprising: one or more processors; wherein the communication device is configured to perform the information processing method of any of claims 1-11, or 12-24, or 25-28, or 29-39, or 40.

46. A communication system, characterized by comprising: The terminal, the access network device, the first network element, and the second network element; wherein the terminal is configured to implement the information processing method of any one of claims 1 to 11, the access network device is configured to implement the information processing method of any one of claims 12 to 24, the first network element is configured to implement claims 25 to 28, and the second network element is configured to implement the information processing method of any one of claims 29 to 39.

47. A storage medium, the storage medium storing instructions, wherein, The instructions, when executed on the communication device, cause the communication device to perform the information processing method of any one of claims 1 to 11, or claims 12 to 24, or claims 25 to 28, or claims 29 to 39, or claim 40.

48. A computer program product comprising a computer program or instructions, characterized in that, The computer program or instructions, when executed by the processor, implement the information processing method of any one of claims 1 to 11, or claims 12 to 24, or claims 25 to 28, or claim 29, or claim 40.