Method for determining security protection start mode, communication method and communication device

By using the identifier sent by the core network element, the terminal device determines the activation mode of the security protection policy, which solves the connection failure problem caused by policy mismatch in 5G adjacent services and improves processing efficiency and connection success rate.

CN122458028APending Publication Date: 2026-07-24HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
HUAWEI TECH CO LTD
Filing Date
2021-05-13
Publication Date
2026-07-24

Smart Images

  • Figure CN122458028A_ABST
    Figure CN122458028A_ABST
Patent Text Reader

Abstract

The application provides a method for determining a security protection starting mode, a communication method and a communication device. The method can include: a first terminal device receiving a first identifier from a core network element, the first identifier being used for modifying a security protection policy of the terminal device; in a process of establishing a connection for a service by the first terminal device and a second terminal device, the first terminal device determining whether to start security protection of the connection according to the first identifier; and the first terminal device sending first information to the second terminal device, the first information being used for indicating whether to start security protection of the connection. Based on the above method, the two terminal devices can successfully establish a connection.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application is a divisional application. The original application has the application number 202110524279.3 and the application date is May 13, 2021. The entire contents of the original application are incorporated herein by reference. Technical Field

[0002] This application relates to the field of communications, and more specifically, to a method, communication method, and communication device for determining the activation mode of a security protection system. Background Technology

[0003] For 5G proximity-based services (ProSe), the policy control function (PCF) sends security protection policies for ProSe services in different geographical locations to the terminal devices. In the ProSe process, the discovery process is only used to discover the peer terminal device; after the discovery process, the PC5 unicast connection establishment process must also be executed.

[0004] However, in the PC5 unicast connection establishment process following the discovery process, if the two terminal devices are located in different geographical locations, the security protection policies used by the two terminal devices may be incompatible. In the case of incompatible security protection policies, the receiving terminal device will refuse to establish a unicast connection, thus causing the unicast connection establishment to fail. Summary of the Invention

[0005] This application provides a method for determining the activation mode of security protection so that two terminal devices can successfully establish a connection.

[0006] In a first aspect, a method for determining the activation mode of security protection is provided. The method includes: a first terminal device receiving a first identifier from a core network element, the first identifier being used to modify the security protection policy of the terminal device; during the process of establishing a service connection between the first terminal device and a second terminal device, the first terminal device determining whether to activate the security protection of the connection based on the first identifier; and the first terminal device sending first information to the second terminal device, the first information being used to indicate whether to activate the security protection of the connection.

[0007] Based on the above technical solution, during the process of establishing a service connection between the first terminal device and the second terminal device, the first terminal device can determine whether to enable the security protection of the service connection based on the first identifier, rather than determining whether to enable the security protection of the connection based on the security protection policies of the two terminal devices. This can avoid the inability to successfully determine whether to enable the security protection of the connection when the security protection policies of the two terminal devices are mismatched, thereby avoiding signaling waste caused by connection establishment failure.

[0008] For example, core network elements include policy control function network elements, direct communication discovery name management function network elements, etc.

[0009] For example, the first identifier is one or more of the following: a new security protection policy, a new security protection activation method, or a first indication message, which is used to indicate that the security protection policy of the terminal device is allowed to be forcibly modified.

[0010] In one possible implementation, the first identifier is the first indication information, and the first terminal device determines whether to enable the security protection of the connection based on the first identifier, including: the first terminal device determines whether to enable the security protection of the connection based on the first indication information, the first security protection policy, and the security protection policy with the higher security level among the second security protection policy, where the first security protection policy is the security protection policy used by the first terminal device in the service, and the second security protection policy is the security protection policy used by the second terminal device in the service.

[0011] The second security protection strategy is sent from the second terminal device to the first terminal device. For example, during the connection establishment process, the second terminal device sends a direct connection communication request message to the first terminal device, and this message includes the second security protection strategy. As another example, during the connection establishment process, the second terminal device sends a direct connection security mode command completion message to the first terminal device, and this message also includes the second security protection strategy.

[0012] In another possible implementation, the first identifier is the first indication information, and the first terminal device determines whether to enable the security protection of the connection based on the first identifier, including: the first terminal device determines whether to enable the security protection of the connection based on the first indication information and the first security protection policy, wherein the first security protection policy is the security protection policy used by the first terminal device in the service.

[0013] Based on the above technical solution, the first terminal device determines whether to enable the security protection of the connection according to the first instruction information and the first security protection strategy, which simplifies the processing logic of the first terminal device and can improve the processing efficiency of the first terminal device.

[0014] In another possible implementation, the first identifier is the new security protection strategy, and the first terminal device determines whether to enable the security protection of the connection based on the first identifier, including: the first terminal device determines whether to enable the security protection of the connection based on the new security protection strategy.

[0015] Based on the above technical solution, the first terminal device determines whether to enable the security protection of the connection according to the first instruction information and the new security protection strategy, which simplifies the processing logic of the first terminal device and can improve the processing efficiency of the first terminal device.

[0016] In another possible implementation, the first identifier is the new security protection activation method, and the first terminal device determines whether to activate the security protection of the connection based on the first identifier, including: the first terminal device determines whether to activate the security protection of the connection based on the new security protection activation method.

[0017] Based on the above technical solution, the first terminal device determines whether to enable the security protection of the connection according to the first instruction information and the new security protection activation method, which simplifies the processing logic of the first terminal device and can improve the processing efficiency of the first terminal device.

[0018] In conjunction with the first aspect, in some implementations of the first aspect, the first terminal device determines whether to enable security protection for the connection based on the first identifier, including: if the first security protection policy and the second security protection policy do not match, the first terminal device determines whether to enable security protection for the connection based on the first identifier, wherein the first security protection policy is the security protection policy used by the first terminal device in the service, and the second security protection policy is the security protection policy used by the second terminal device in the service.

[0019] In conjunction with the first aspect, in some implementations of the first aspect, the first terminal device determines whether to enable security protection for the connection based on the first identifier, including: if it is determined that the second terminal device supports forced modification of the security protection policy, the first terminal device determines whether to enable security protection for the connection based on the first identifier.

[0020] Based on the above technical solution, if it is determined that the second terminal device supports forced modification of the security protection policy, the first terminal device determines whether to enable the security protection of the connection according to the first identifier, thereby avoiding connection establishment failure due to the second terminal device not supporting forced modification of the security protection policy.

[0021] In one possible implementation, the method for determining that the second terminal device supports forced modification of the security protection policy includes: during the service discovery process, the first terminal device receives a service discovery code from the second terminal device, the service discovery code corresponding to the first identifier; the first terminal device determines that the second terminal device supports forced modification of the security protection policy based on the service discovery code.

[0022] In another possible implementation, the method for determining that the second terminal device supports forced modification of the security protection policy includes: during the establishment of the connection, the first terminal device receives a first message from the second terminal device, the first message including the first identifier; the first terminal device determines that the second terminal device supports forced modification of the security protection policy based on the first identifier.

[0023] In conjunction with the first aspect, in some implementations of the first aspect, the core network element is a first direct-connection communication discovery name management function network element, the first identifier corresponds to the service discovery code, and the method further includes: the first terminal device receiving the service discovery code from the first direct-connection communication discovery name management function network element.

[0024] Among them, the first direct-connection communication discovery name management function network element provides services to the first terminal device.

[0025] Based on the above technical solution, the first identifier obtained by the first terminal device corresponds to the service discovery code, which helps the first terminal device determine whether the second terminal device supports the forced modification of the security protection policy based on the service discovery code.

[0026] Secondly, a method for determining the activation mode of security protection is provided. The method includes: a second terminal device receiving a first identifier from a core network element, the first identifier being used to modify the security protection policy of the terminal device; during the process of establishing a service connection between the second terminal device and the first terminal device, the second terminal device sending the first identifier to the first terminal device; the second terminal device receiving first information from the first terminal device, the first information being used to indicate whether to activate the security protection of the connection, the first information being determined by the first terminal device based on the first identifier; and the second terminal device determining whether to activate the security protection of the connection based on the first information.

[0027] Based on the above technical solution, the second terminal device sends the first identifier to the first terminal device, which helps the first terminal device determine whether the second terminal device supports the forced modification of the security protection policy based on the first identifier, thereby enabling the first terminal device to determine whether to enable the security protection of the connection based on the first identifier.

[0028] Thirdly, a method for determining the activation mode of security protection is provided. The method includes: a second terminal device receiving a first identifier from a core network element, the first identifier being used to modify the security protection policy of the terminal device, the first identifier corresponding to a service discovery code; during the service discovery process, the second terminal device sending the service discovery code to a first terminal device; during the process of the second terminal device and the first terminal device establishing a connection for the service, the second terminal device receiving first information from the first terminal device, the first information being used to indicate whether to activate the security protection of the connection, the first information being determined by the first terminal device based on the first identifier; and the second terminal device determining whether to activate the security protection of the connection based on the first information.

[0029] Based on the above technical solution, the second terminal device sends the service discovery code corresponding to the first identifier to the first terminal device, which helps the first terminal device determine whether the second terminal device supports the forced modification of the security protection policy based on the service discovery code, thereby enabling the first terminal device to determine whether to enable the security protection of the connection based on the first identifier.

[0030] For example, core network elements include policy control function network elements, direct communication discovery name management function network elements, etc.

[0031] For example, the first identifier is one or more of the following: a new security protection policy, a new security protection activation method, or a first indication message, which is used to indicate that the security protection policy of the terminal device is allowed to be forcibly modified.

[0032] In conjunction with the second or third aspect, in some implementations of the second or third aspect, the second terminal device does not check whether the security protection activation method of the connection matches the second security protection policy, which is the security protection policy used by the second terminal device in the service.

[0033] Based on the above technical solution, the second terminal device does not need to check whether the connection security protection activation method matches the local security protection policy, thereby saving the processing resources of the second terminal device.

[0034] In conjunction with the second or third aspect, in some implementations of the second or third aspect, the first information may also include the first identifier.

[0035] Based on the above technical solution, the second terminal device can determine that the security protection activation method of the connection is determined according to the first identifier included in the first information.

[0036] Fourthly, a communication method is provided, the method comprising: a first core network element determining a first identifier based on a security protection policy configuration and second indication information for a first service, the second indication information being used to indicate that the security protection policy of the first service can be forcibly modified during connection establishment, the first identifier being used to modify the security protection policy of a terminal device; the first core network element sending the first identifier to the terminal device.

[0037] Based on the above technical solution, after the core network element determines the first identifier according to the security protection policy configuration of the first service and the second instruction information, it sends the first identifier to the terminal device. This helps the terminal device modify the security protection policy according to the first identifier, thereby avoiding the failure of the connection establishment of the first service due to the mismatch of the security protection policies of the two terminal devices.

[0038] For example, the first core network element is a policy control function network element, a direct communication discovery name management function network element, etc.

[0039] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the first core network element determines the first identifier based on the security protection policy configuration and the second instruction information of the first service, including: when it is determined that the security protection policy configuration includes multiple security protection policies with different values, the first core network element determines the first identifier based on the security protection policy configuration and the second instruction information, wherein the multiple security protection policies include the security protection policies of the first service in different geographical locations.

[0040] Based on the above technical solution, when it is determined that the values ​​of multiple security protection policies included in the security protection policy configuration are different, the first core network element determines the first identifier, thereby saving the processing resources of the first core network element.

[0041] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the method further includes: the first core network element receiving the second instruction information from the second core network element.

[0042] For example, the first core network element is a policy control function network element, and the second core network element is an application function network element; or, the first core network element is a direct communication discovery name management function network element, and the second core network element is a policy control function network element.

[0043] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the method further includes: the first core network element sending a first request message to the second core network element, the first request message being used to request the second indication information.

[0044] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the first core network element sends a first request message to the second core network element, including: when it is determined that the multiple security protection policies included in the security protection policy configuration have different values, the first core network element sends the first request message to the second core network element, and the multiple security protection policies include the security protection policies of the first service in different geographical locations.

[0045] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the first core network element is a second direct communication discovery name management function network element, the terminal device is a second terminal device, and the first core network element sends the first identifier to the terminal device, including: when it is determined that the first security protection policy and the second security protection policy do not match, the second direct communication discovery name management function network element sends the first identifier to the second terminal device, the first security protection policy is the security protection policy used by the first terminal device in the first service, the second security protection policy is the security protection policy used by the second terminal device in the first service, and the first terminal device is a terminal device that establishes a connection with the second terminal device for the first service.

[0046] Among them, the second direct communication discovery name management function network element provides services to the second terminal device.

[0047] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the method further includes: the second direct communication discovery name management network element receiving the first security protection policy from the first direct communication discovery name management network element; and the second direct communication discovery name management network element determining that the first security protection policy does not match the second security protection policy.

[0048] Among them, the first direct-connection communication discovery name management function network element provides services to the first terminal device.

[0049] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the method further includes: the second direct communication discovery name management network element sending the second security protection policy to the first direct communication discovery name management network element; the second direct communication discovery name management network element receiving third indication information from the first direct communication discovery name management network element, the third indication information being used to indicate that the first security protection policy does not match the second security protection policy.

[0050] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the method further includes: the second direct communication discovery name management function network element determining the second security protection strategy based on the location information of the second terminal device.

[0051] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the method further includes: the second direct communication discovery name management function network element receiving the location information from the second terminal device.

[0052] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the method further includes: the second direct communication discovery name management function network element triggers the gateway mobile positioning center to obtain the location information using the positioning service.

[0053] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the method further includes: the second direct communication discovery name management function network element requests the location information of the second terminal device from the access and mobility management function network element serving the second terminal device.

[0054] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the first core network element is a first direct-connection communication discovery name management function network element, the terminal device is a first terminal device, and the first core network element sends the first identifier to the terminal device, including: when it is determined that the first security protection policy and the second security protection policy do not match, the first direct-connection communication discovery name management function network element sends the first identifier to the first terminal device, the first security protection policy is the security protection policy used by the first terminal device in the first service, the second security protection policy is the security protection policy used by the second terminal device in the first service, and the second terminal device is a terminal device that has established a connection with the first terminal device for the first service.

[0055] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the method further includes: the first direct-connection name discovery management network element receiving the second security protection policy from the second direct-connection name discovery management network element; the first direct-connection name discovery management network element determining that the first security protection policy and the second security protection policy do not match.

[0056] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the method further includes: the first direct-connection name discovery management network element sending the first security protection policy to the second direct-connection name discovery management network element; the first direct-connection name discovery management network element receiving third indication information from the second direct-connection name discovery management network element, the third indication information being used to indicate that the first security protection policy does not match the second security protection policy.

[0057] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the method further includes: the first direct-connection communication discovery name management function network element determining the first security protection strategy based on the location information of the first terminal device.

[0058] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the method further includes: the first direct-connection communication discovery name management function network element receiving the location information from the first terminal device.

[0059] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the method further includes: the first direct communication discovery name management function network element triggers the gateway mobile positioning center to obtain the location information using the positioning service.

[0060] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the method further includes: the first direct-connection communication discovery name management function network element requests the location information of the first terminal device from the access and mobility management function network element serving the first terminal device.

[0061] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the first core network element is a direct communication discovery name management network element, and the first identifier is carried in the direct communication discovery message.

[0062] Fifthly, a communication method is provided, the method comprising: an application function network element determining that the security protection policy configuration of a first service includes multiple security protection policies with different values, the multiple security protection policies including security protection policies of the first service in different geographical locations; the application function network element sending second indication information to a policy control function network element, the second indication information being used to indicate that the security protection policy of the first service can be forcibly modified during connection establishment.

[0063] Based on the above technical solution, the application function network element sends the second instruction information to the policy control function network element, which helps the policy control function network element determine the first identifier according to the second instruction information.

[0064] In conjunction with the fifth aspect, in some implementations of the fifth aspect, the method further includes: the application function network element receiving a first request message from the policy control function network element, the first request message being used to request the second indication information; the application function network element sending the second indication information to the policy control function network element, including: the application function network element sending the second indication information to the policy control function network element according to the first request message.

[0065] A sixth aspect provides a communication method, the method comprising: a second direct communication discovery name management network element sending a second request message to a first direct communication discovery name management network element, the second request message being used to request the acquisition of a first identifier, the first identifier being used to modify the security protection policy of a terminal device; the second direct communication discovery name management network element receiving a second message from the first direct communication discovery name management network element, the second message including the first identifier; and the second direct communication discovery name management network element sending the first identifier to a second terminal device.

[0066] The second direct-connection communication discovery name management network element provides services to the second terminal device. The first direct-connection communication discovery name management network element provides services to the first terminal device. The first terminal device is the terminal device that establishes a connection with the second terminal device.

[0067] Based on the above technical solution, after the second direct communication discovery name management function network element obtains the first identifier, it sends the first identifier to the second terminal device. This helps the terminal device modify the security protection policy according to the first identifier, thereby avoiding the failure of the first service connection establishment due to the mismatch of the security protection policies of the two terminal devices.

[0068] For example, the first identifier may be one or more of the following: a new security protection policy, a new security protection activation method, or a first indication message, wherein the first indication message is used to indicate that the security protection policy of the terminal device is allowed to be forcibly modified.

[0069] In conjunction with the sixth aspect, in some implementations of the sixth aspect, the second request message includes a second security protection policy, and the second message also includes a service discovery code and / or third indication information. The third indication information is used to indicate that the first security protection policy does not match the second security protection policy. The service discovery code corresponds to the first identifier. The first security protection policy is a security protection policy used by the first terminal device in the service. The second security protection policy is a security protection policy used by the second terminal device in the service. The first terminal device is a terminal device that establishes a connection with the second terminal device for the service.

[0070] In conjunction with the sixth aspect, in some implementations of the sixth aspect, the second direct communication discovery name management function network element sends the first identifier to the second terminal device, including: when it is determined that the first security protection policy and the second security protection policy do not match, the second direct communication discovery name management function network element sends the first identifier to the second terminal device, the first security protection policy is the security protection policy used by the first terminal device in the service, the second security protection policy is the security protection policy used by the second terminal device in the service, and the first terminal device is the terminal device that establishes a connection with the second terminal device for the service.

[0071] In conjunction with the sixth aspect, in some implementations of the sixth aspect, the method further includes: the second direct communication discovery name management network element receiving the first security protection policy from the first direct communication discovery name management network element; the second direct communication discovery name management network element determining that the first security protection policy does not match the second security protection policy.

[0072] In conjunction with the sixth aspect, in some implementations of the sixth aspect, the method further includes: the second direct communication discovery name management network element sending the second security protection policy to the first direct communication discovery name management network element; the second direct communication discovery name management network element receiving third indication information from the first direct communication discovery name management network element, the third indication information being used to indicate that the first security protection policy does not match the second security protection policy.

[0073] In conjunction with the sixth aspect, in some implementations of the sixth aspect, the method further includes: the first direct-connection communication discovery name management function network element determining the first security protection strategy based on the location information of the first terminal device.

[0074] In conjunction with the sixth aspect, in some implementations of the sixth aspect, the method further includes: the first direct-connection communication discovery name management function network element receiving the location information from the first terminal device.

[0075] In conjunction with the sixth aspect, in some implementations of the sixth aspect, the method further includes: the first direct communication discovery name management function network element triggers the gateway mobile positioning center to obtain the location information using the positioning service.

[0076] In conjunction with the sixth aspect, in some implementations of the sixth aspect, the method further includes: the first direct-connection communication discovery name management function network element requests the location information of the first terminal device from the access and mobility management function network element serving the first terminal device.

[0077] In conjunction with the sixth aspect, in some implementations of the sixth aspect, the first identifier is carried in the direct communication discovery message.

[0078] In a seventh aspect, a communication device is provided, comprising a transceiver unit and a processing unit. The transceiver unit is configured to receive a first identifier from a core network element, the first identifier being used to modify the security protection policy of a terminal device. During the process of establishing a service connection between the communication device and a second terminal device, the processing unit is configured to determine whether to enable security protection for the connection based on the first identifier. The transceiver unit is further configured to send first information to the second terminal device, the first information being used to indicate whether to enable security protection for the connection.

[0079] For example, core network elements include policy control function network elements, direct communication discovery name management function network elements, etc.

[0080] For example, the first identifier is one or more of the following: a new security protection policy, a new security protection activation method, or a first indication message, which is used to indicate that the security protection policy of the terminal device is allowed to be forcibly modified.

[0081] In one possible implementation, the first identifier is the first indication information, and the processing unit is specifically used to determine whether to enable the security protection of the connection based on the first indication information, the first security protection policy, and the security protection policy with the higher security level among the second security protection policy and the first security protection policy. The first security protection policy is the security protection policy used by the communication device in the service, and the second security protection policy is the security protection policy used by the second terminal device in the service.

[0082] In another possible implementation, the first identifier is the first indication information, and the processing unit is specifically used to determine whether to enable the security protection of the connection based on the first indication information and the first security protection policy, wherein the first security protection policy is the security protection policy used by the communication device in the service.

[0083] In another possible implementation, the first identifier is the new security protection strategy, and the processing unit is specifically used to determine whether to enable the security protection of the connection based on the new security protection strategy.

[0084] In another possible implementation, the first identifier is the new security protection activation mode, and the processing unit is specifically used to determine whether to activate the security protection of the connection based on the new security protection activation mode.

[0085] In conjunction with the seventh aspect, in some implementations of the seventh aspect, the processing unit is specifically used to determine whether to enable security protection for the connection based on the first identifier when the first security protection policy and the second security protection policy do not match. The first security protection policy is the security protection policy used by the communication device in the service, and the second security protection policy is the security protection policy used by the second terminal device in the service.

[0086] In conjunction with the seventh aspect, in some implementations of the seventh aspect, the processing unit is specifically used to determine whether to enable security protection for the connection based on the first identifier when it is determined that the second terminal device supports forced modification of the security protection policy.

[0087] In one possible implementation, the transceiver unit is further configured to, during the service discovery process, have the first terminal device receive a service discovery code from the second terminal device, the service discovery code corresponding to the first identifier; the processing unit is further configured to determine, based on the service discovery code, that the second terminal device supports forced modification of security protection policies.

[0088] In another possible implementation, the transceiver unit is further configured to receive a first message from the second terminal device during the connection establishment process, the first message including the first identifier; the processing unit is further configured to determine, based on the first identifier, that the second terminal device supports forced modification of the security protection policy.

[0089] In conjunction with the seventh aspect, in some implementations of the seventh aspect, the core network element is the first direct-connection communication discovery name management function network element, the first identifier corresponds to the service discovery code, and the transceiver unit is also used to receive the service discovery code from the first direct-connection communication discovery name management function network element.

[0090] Eighthly, a communication device is provided, comprising a transceiver unit and a processing unit. The transceiver unit is configured to receive a first identifier from a core network element, the first identifier being used to modify the security protection policy of a terminal device. During the process of establishing a service connection between the communication device and a first terminal device, the transceiver unit is further configured to send the first identifier to the first terminal device. The transceiver unit is also configured to receive first information from the first terminal device, the first information being used to indicate whether to enable security protection for the connection, the first information being determined by the first terminal device based on the first identifier. The processing unit is configured to determine whether to enable security protection for the connection based on the first information.

[0091] A ninth aspect provides a communication device comprising a transceiver unit and a processing unit. The transceiver unit is configured to receive a first identifier from a core network element, the first identifier being used to modify the security protection policy of a terminal device, the first identifier corresponding to a service discovery code. During the service discovery process, the transceiver unit is further configured to send the service discovery code to a first terminal device. During the process of establishing a connection between the communication device and the first terminal device for the service, the transceiver unit is further configured to receive first information from the first terminal device, the first information indicating whether to enable security protection for the connection, the first information being determined by the first terminal device based on the first identifier. The processing unit is configured to determine whether to enable security protection for the connection based on the first information.

[0092] For example, core network elements include policy control function network elements, direct communication discovery name management function network elements, etc.

[0093] For example, the first identifier is one or more of the following: a new security protection policy, a new security protection activation method, or a first indication message, which is used to indicate that the security protection policy of the terminal device is allowed to be forcibly modified.

[0094] In conjunction with the eighth or ninth aspect, in some implementations of the eighth or ninth aspect, the communication device does not check whether the security protection activation mode of the connection matches the second security protection strategy, which is the security protection strategy used by the second terminal device in the service.

[0095] In conjunction with the eighth or ninth aspect, in some implementations of the eighth or ninth aspect, the first information may also include the first identifier.

[0096] In a tenth aspect, a communication device is provided, comprising a transceiver unit and a processing unit, wherein the processing unit is configured to determine a first identifier based on a security protection policy configuration of a first service and second indication information, the second indication information being used to indicate that the security protection policy of the first service can be forcibly modified during connection establishment, and the first identifier being used to modify the security protection policy of a terminal device; the transceiver unit is configured to send the first identifier to the terminal device.

[0097] For example, the communication device is a policy control function network element, a direct communication discovery name management function network element, etc.

[0098] In conjunction with the tenth aspect, in some implementations of the tenth aspect, the processing unit is specifically configured to determine the first identifier based on the security protection policy configuration and the second indication information when it is determined that the multiple security protection policies included in the security protection policy configuration have different values, wherein the multiple security protection policies include the security protection policies of the first service in different geographical locations.

[0099] In conjunction with aspect ten, in some implementations of aspect ten, the transceiver unit is also used to receive the second instruction information from the second core network element.

[0100] For example, the communication device is a policy control function network element, and the second core network element is an application function network element; or, the communication device is a direct communication discovery name management function network element, and the second core network element is a policy control function network element.

[0101] In conjunction with aspect ten, in some implementations of aspect ten, the transceiver unit is further configured to send a first request message to the second core network element, the first request message being used to request the second indication information.

[0102] In conjunction with the tenth aspect, in some implementations of the tenth aspect, the transceiver unit is specifically used to send the first request message to the second core network element when it is determined that the multiple security protection policies included in the security protection policy configuration have different values, and the multiple security protection policies include the security protection policies of the first service in different geographical locations.

[0103] In conjunction with the tenth aspect, in some implementations of the tenth aspect, the communication device is a second direct communication discovery name management function network element, the terminal device is a second terminal device, and the transceiver unit is specifically used to send the first identifier to the second terminal device when it is determined that the first security protection policy and the second security protection policy do not match. The first security protection policy is the security protection policy used by the first terminal device in the first service, the second security protection policy is the security protection policy used by the second terminal device in the first service, and the first terminal device is a terminal device that establishes a connection with the second terminal device for the first service.

[0104] In conjunction with the tenth aspect, in some implementations of the tenth aspect, the transceiver unit is further configured to receive the first security protection policy from the first direct-connection communication discovery name management network element; the processing unit is further configured to determine that the first security protection policy does not match the second security protection policy.

[0105] In conjunction with the tenth aspect, in some implementations of the tenth aspect, the transceiver unit is further configured to send the second security protection policy to the first direct-connection communication discovery name management network element; the transceiver unit is further configured to receive third indication information from the first direct-connection communication discovery name management network element, the third indication information being used to indicate that the first security protection policy does not match the second security protection policy.

[0106] In conjunction with the tenth aspect, in some implementations of the tenth aspect, the processing unit is further configured to determine the second security protection strategy based on the location information of the second terminal device.

[0107] In conjunction with the tenth aspect, in some implementations of the tenth aspect, the transceiver unit is also used to receive the location information from the second terminal device.

[0108] In conjunction with aspect ten, in some implementations of aspect ten, the processing unit is also used to trigger the gateway mobile positioning center to obtain the location information using the positioning service.

[0109] In conjunction with the tenth aspect, in some implementations of the tenth aspect, the processing unit is further configured to request the location information of the second terminal device from the access and mobility management function network element serving the second terminal device.

[0110] In conjunction with the tenth aspect, in some implementations of the tenth aspect, the communication device is a first direct-connection communication discovery name management function network element, the terminal device is a first terminal device, and the transceiver unit is specifically used to send the first identifier to the first terminal device when it is determined that the first security protection policy and the second security protection policy do not match. The first security protection policy is the security protection policy used by the first terminal device in the first service, the second security protection policy is the security protection policy used by the second terminal device in the first service, and the second terminal device is a terminal device that has established a connection with the first terminal device for the first service.

[0111] In conjunction with the tenth aspect, in some implementations of the tenth aspect, the transceiver unit is further configured to receive the second security protection policy from the second direct communication discovery name management network element; the processing unit is further configured to determine that the first security protection policy and the second security protection policy do not match.

[0112] In conjunction with aspect ten, in some implementations of aspect ten, the transceiver unit is further configured to send the first security protection policy to the second direct communication discovery name management network element; the transceiver unit is further configured to receive third indication information from the second direct communication discovery name management network element, the third indication information being used to indicate that the first security protection policy does not match the second security protection policy.

[0113] In conjunction with the tenth aspect, in some implementations of the tenth aspect, the processing unit is further configured to determine the first security protection strategy based on the location information of the first terminal device.

[0114] In conjunction with the tenth aspect, in some implementations of the tenth aspect, the transceiver unit is also used to receive the location information from the first terminal device.

[0115] In conjunction with aspect ten, in some implementations of aspect ten, the processing unit is also used to trigger the gateway mobile positioning center to obtain the location information using the positioning service.

[0116] In conjunction with the tenth aspect, in some implementations of the tenth aspect, the processing unit is further configured to request the location information of the first terminal device from the access and mobility management function network element serving the first terminal device.

[0117] In conjunction with aspect ten, in some implementations of aspect ten, the communication device is a direct communication discovery name management network element, and the first identifier is carried in the direct communication discovery message.

[0118] Eleventhly, a communication device is provided, comprising a transceiver unit and a processing unit. The processing unit is configured to determine that the security protection policy configuration of a first service includes multiple security protection policy values ​​that are different, including security protection policies of the first service in different geographical locations. The transceiver unit is configured to send second indication information to a policy control function network element, the second indication information indicating that the security protection policy of the first service can be forcibly modified during connection establishment.

[0119] In conjunction with the eleventh aspect, in some implementations of the eleventh aspect, the transceiver unit is further configured to receive a first request message from the policy control function network element, the first request message being used to request the second indication information; specifically, the transceiver unit is configured to send the second indication information to the policy control function network element according to the first request message.

[0120] In a twelfth aspect, a communication apparatus is provided, comprising a transceiver unit configured to send a second request message to a first direct-connection name discovery management network element, the second request message being used to request the acquisition of a first identifier, the first identifier being used to modify the security protection policy of a terminal device; the transceiver unit is further configured to receive a second message from the first direct-connection name discovery management network element, the second message including the first identifier; and the transceiver unit is further configured to send the first identifier to a second terminal device.

[0121] For example, the first identifier may be one or more of the following: a new security protection policy, a new security protection activation method, or a first indication message, wherein the first indication message is used to indicate that the security protection policy of the terminal device is allowed to be forcibly modified.

[0122] In conjunction with the twelfth aspect, in some implementations of the twelfth aspect, the second request message includes a second security protection policy, and the second message also includes a service discovery code and / or third indication information, the third indication information being used to indicate that the first security protection policy does not match the second security protection policy, the service discovery code corresponding to the first identifier, the first security protection policy being a security protection policy used by the first terminal device in the service, the second security protection policy being a security protection policy used by the second terminal device in the service, and the first terminal device being a terminal device that establishes a connection with the second terminal device for the service.

[0123] In conjunction with the twelfth aspect, in some implementations of the twelfth aspect, the transceiver unit is specifically used to send the first identifier to the second terminal device when it is determined that the first security protection policy and the second security protection policy do not match. The first security protection policy is a security protection policy used by the first terminal device in the service, and the second security protection policy is a security protection policy used by the second terminal device in the service. The first terminal device is a terminal device that establishes a connection with the second terminal device for the service.

[0124] In conjunction with the twelfth aspect, in some implementations of the twelfth aspect, the transceiver unit is further configured to receive the first security protection policy from the first direct-connection communication discovery name management network element; the communication device further includes a processing unit configured to determine that the first security protection policy does not match the second security protection policy.

[0125] In conjunction with the twelfth aspect, in some implementations of the twelfth aspect, the transceiver unit is further configured to send the second security protection policy to the first direct-connection communication discovery name management network element; the transceiver unit is further configured to receive third indication information from the first direct-connection communication discovery name management network element, the third indication information being used to indicate that the first security protection policy does not match the second security protection policy.

[0126] In conjunction with the twelfth aspect, in some implementations of the twelfth aspect, the processing unit is further configured to determine the first security protection strategy based on the location information of the first terminal device.

[0127] In conjunction with the twelfth aspect, in some implementations of the twelfth aspect, the transceiver unit is also configured to receive the location information from the first terminal device.

[0128] In conjunction with the twelfth aspect, in some implementations of the twelfth aspect, the processing unit is also used to trigger the gateway mobile positioning center to obtain the location information using the positioning service.

[0129] In conjunction with the twelfth aspect, in some implementations of the twelfth aspect, the processing unit is further configured to request the location information of the first terminal device from the access and mobility management function network element serving the first terminal device.

[0130] In conjunction with the twelfth aspect, in some implementations of the twelfth aspect, the first identifier is carried in the direct communication discovery message.

[0131] In a thirteenth aspect, this application provides a communication device including a processor. The processor is coupled to a memory and can be used to execute instructions in the memory to implement the methods in the first aspect or any possible implementation thereof. The communication device further includes a memory. The communication device also includes a communication interface, and the processor is coupled to the communication interface.

[0132] In one implementation, the communication device is a first terminal device. When the communication device is a first terminal device, the communication interface can be a transceiver or an input / output interface.

[0133] In another implementation, the communication device is a chip or chip system configured in the first terminal device. When the communication device is a chip or chip system configured in the first terminal device, the communication interface can be an input / output interface.

[0134] The transceiver can be a transceiver circuit. The input / output interface can be an input / output circuit.

[0135] In a fourteenth aspect, this application provides a communication device including a processor. The processor is coupled to a memory and can be used to execute instructions in the memory to implement the methods in the second aspect or any possible implementation of the second aspect, or to implement the methods in the third aspect or any possible implementation of the third aspect. The communication device further includes a memory. The communication device also includes a communication interface, and the processor is coupled to the communication interface.

[0136] In one implementation, the communication device is a second terminal device. When the communication device is a second terminal device, the communication interface can be a transceiver or an input / output interface.

[0137] In another implementation, the communication device is a chip or chip system configured in the second terminal device. When the communication device is a chip or chip system configured in the second terminal device, the communication interface can be an input / output interface.

[0138] The transceiver can be a transceiver circuit. The input / output interface can be an input / output circuit.

[0139] In a fifteenth aspect, this application provides a communication device including a processor. The processor is coupled to a memory and can be used to execute instructions in the memory to implement the methods in the fourth aspect or any possible implementation of the fourth aspect. The communication device further includes a memory. The communication device also includes a communication interface, and the processor is coupled to the communication interface.

[0140] In one implementation, the communication device is a core network element. When the communication device is a core network element, the communication interface can be a transceiver or an input / output interface.

[0141] In another implementation, the communication device is a chip or chip system configured in a core network element. When the communication device is a chip or chip system configured in a core network element, the communication interface can be an input / output interface.

[0142] The transceiver can be a transceiver circuit. The input / output interface can be an input / output circuit.

[0143] In a sixteenth aspect, this application provides a communication device including a processor. The processor is coupled to a memory and can be used to execute instructions in the memory to implement the methods in the fifth aspect or any possible implementation of the fifth aspect. The communication device further includes a memory. The communication device also includes a communication interface, and the processor is coupled to the communication interface.

[0144] In one implementation, the communication device is an application function network element. When the communication device is an application function network element, the communication interface can be a transceiver or an input / output interface.

[0145] In another implementation, the communication device is a chip or chip system configured in an application function network element. When the communication device is a chip or chip system configured in an application function network element, the communication interface can be an input / output interface.

[0146] The transceiver can be a transceiver circuit. The input / output interface can be an input / output circuit.

[0147] In a seventeenth aspect, this application provides a communication device including a processor. The processor is coupled to a memory and can be used to execute instructions in the memory to implement the methods in the sixth aspect or any possible implementation thereof. The communication device further includes a memory. The communication device also includes a communication interface, and the processor is coupled to the communication interface.

[0148] In one implementation, the communication device is a direct-connection communication discovery name management function network element. When the communication device is a direct-connection communication discovery name management function network element, the communication interface can be a transceiver, or an input / output interface.

[0149] In another implementation, the communication device is a chip or chip system configured in a direct communication discovery name management function network element. When the communication device is a chip or chip system configured in a direct communication discovery name management function network element, the communication interface can be an input / output interface.

[0150] The transceiver can be a transceiver circuit. The input / output interface can be an input / output circuit.

[0151] In an eighteenth aspect, this application provides a processor, including: an input circuit, an output circuit, and a processing circuit. The processing circuit is configured to receive signals through the input circuit and transmit signals through the output circuit, causing the processor to perform the methods described in the foregoing aspects.

[0152] In specific implementation, the processor can be a chip, the input circuit can be an input pin, the output circuit can be an output pin, and the processing circuit can be a transistor, gate circuit, flip-flop, and various logic circuits. The input signal received by the input circuit can be received and input by, for example, but not limited to, a receiver, and the signal output by the output circuit can be output to, for example, but not limited to, a transmitter and transmitted by the transmitter. Furthermore, the input circuit and the output circuit can be the same circuit, which is used as the input circuit and the output circuit at different times. This application does not limit the specific implementation of the processor and various circuits.

[0153] In a nineteenth aspect, this application provides a processing apparatus including a communication interface and a processor. The communication interface is coupled to the processor. The communication interface is used for inputting and / or outputting information. The information includes at least one of instructions or data. The processor is used to execute a computer program to cause the processing apparatus to perform the methods described in the foregoing aspects.

[0154] In a twentieth aspect, this application provides a processing apparatus including a processor and a memory. The processor is configured to read instructions stored in the memory and to receive signals via a receiver and transmit signals via a transmitter, thereby causing the processing apparatus to perform the methods described in the foregoing aspects.

[0155] Optionally, there may be one or more processors. If memory is available, there may also be one or more memories.

[0156] Optionally, the memory may be integrated with the processor, or the memory may be separated from the processor.

[0157] In the specific implementation process, the memory can be a non-transitory memory, such as read-only memory (ROM), which can be integrated with the processor on the same chip or set on different chips. The embodiments of this application do not limit the type of memory or the way the memory and processor are set.

[0158] It should be understood that the relevant information exchange process, such as sending instruction information, can be a process of outputting instruction information from the processor, and receiving instruction information can be a process of inputting received instruction information into the processor. Specifically, the information output by the processor can be sent to the transmitter, and the input information received by the processor can come from the receiver. Here, the transmitter and receiver can be collectively referred to as a transceiver.

[0159] The device in the nineteenth and twentieth aspects above can be a chip. The processor can be implemented in hardware or software. When implemented in hardware, the processor can be a logic circuit, integrated circuit, etc. When implemented in software, the processor can be a general-purpose processor that reads software code stored in a memory. The memory can be integrated into the processor or located outside the processor and exist independently.

[0160] In a twentieth aspect, this application provides a computer program product comprising: a computer program (also referred to as code or instructions) that, when run, causes a computer to perform the methods described in the foregoing aspects.

[0161] In a twentieth aspect, this application provides a computer-readable storage medium storing a computer program (also referred to as code or instructions) that, when run on a computer, causes the computer to perform the methods described in the foregoing aspects.

[0162] In a twentieth aspect, this application provides a communication system, including the aforementioned first terminal device and second terminal device, or including the aforementioned first terminal device and / or second terminal device, core network elements, and application function network elements. Attached Figure Description

[0163] Figure 1 This is a schematic diagram of a network architecture applicable to embodiments of this application.

[0164] Figure 2 This is a schematic flowchart illustrating the establishment of a unicast connection between two terminal devices.

[0165] Figure 3 This is a schematic flowchart of the communication method provided in the embodiments of this application.

[0166] Figure 4 This is a schematic flowchart of a communication method provided in another embodiment of this application.

[0167] Figure 5 This is a schematic flowchart of a communication method provided in another embodiment of this application.

[0168] Figure 6This is a schematic flowchart of a communication method provided in another embodiment of this application.

[0169] Figure 7 This is a schematic flowchart of a communication method provided in another embodiment of this application.

[0170] Figure 8 This is a schematic block diagram of a communication device provided in an embodiment of this application.

[0171] Figure 9 This is a schematic block diagram of a communication device provided in an embodiment of this application. Detailed Implementation

[0172] The technical solutions in this application will now be described with reference to the accompanying drawings.

[0173] The technical solutions of this application can be applied to various communication systems, such as: Long Term Evolution (LTE) systems, LTE Frequency Division Duplex (FDD) systems, LTE Time Division Duplex (TDD) systems, Universal Mobile Telecommunication System (UMTS), Worldwide Interoperability for Microwave Access (WiMAX) systems, 5G systems or new radio (NR), 6th generation (6G) systems, or future communication systems. The 5G mobile communication system described in this application includes non-standalone (NSA) 5G mobile communication systems or standalone (SA) 5G mobile communication systems. The communication system can also be a public land mobile network (PLMN), a device-to-device (D2D) communication system, a machine-to-machine (M2M) communication system, an Internet of Things (IoT) communication system, or other communication systems.

[0174] To facilitate understanding of the technical solutions of the embodiments of this application, a brief introduction to several basic concepts involved in this application will be given first.

[0175] First, discovery type: In this application embodiment, the discovery type includes open discovery or restricted discovery. Descriptions of open discovery and restricted discovery can be found in 3GPP technical standards (TS) 23.303, v16.1.0, and will not be elaborated upon here. For example, if a terminal device is playing a game alone without a designated gaming partner, it can initiate an open discovery to "randomly" find a partner. However, if the terminal device has a designated gaming partner, it can use restricted discovery to "designate" a partner; only the partner designated by the terminal device can access the game, while others cannot.

[0176] Second, the discovery mode: The 4th generation (4G) ProSe standard (3GPP technical specification (TS) 23.303, v16.0.0) defines two discovery models: Model A and Model B. The difference between Model A and Model B lies in the different ways of initiating discovery.

[0177] Model A stands for "I am here." In the Model A discovery process, the two user equipments (UEs) are the announcing UE and the monitoring UE, respectively. The announcing UE broadcasts "I am here," and the monitoring UE, upon receiving this message, determines whether to establish a connection for a nearby service with the announcing UE based on whether it meets its own service requirements. Specifically, after obtaining the ProSe parameter, the announcing UE actively broadcasts the nearby services it is interested in. The monitoring UE, after obtaining the ProSe parameter, uses it to monitor the nearby services it is interested in. In other words, in the Model A discovery process, the first message is initiated by the announcing UE, and after receiving the message from the announcing UE, the monitoring UE determines whether to continue with the unicast connection establishment process based on whether it meets its own service requirements.

[0178] Model B stands for "Who's there? / Where are you?". In the Model B discovery process, the two UEs are the discoveree UE and the discoverer UE, respectively. In the Model B discovery process, the first message is initiated by the discoverer UE to request a nearby service. Upon receiving the request, the discoverer UE determines whether to reply to the request message based on whether it can provide the nearby service. Further, after receiving a reply message, the discoverer UE initiates a unicast establishment process.

[0179] Third, security protection strategies should be matched with security protection strategies: A security protection strategy is a policy used to describe whether or not to enable security protection, and can be used to determine the security protection method. The security protection strategies used in different scenarios in this application include at least one of the following protection strategies: Control plane confidentiality protection strategy in PC5 connectivity; Control plane integrity protection strategy in PC5 connection; User plane confidentiality protection strategy in PC5 connectivity; Alternatively, the user plane integrity protection strategy in PC5 connectivity.

[0180] Among them, control plane confidentiality protection protects the confidentiality of signaling during transmission; control plane integrity protection protects the integrity of signaling during transmission; user plane confidentiality protection protects the confidentiality of user plane data during transmission; and user plane integrity protection protects the integrity of user plane data during transmission. In this embodiment, integrity means that the acquired signaling or data is consistent with the original signaling or data and has not been modified. Therefore, integrity protection is to prevent attackers from "attacking." Confidentiality means that the true content cannot be directly seen. Therefore, confidentiality protection is to prevent attackers from "understanding." In addition, the confidentiality protection in this embodiment can also be called encryption protection, which will be uniformly explained here and will not be elaborated further below.

[0181] In this embodiment, the control plane confidentiality protection strategy and the control plane integrity protection strategy belong to the control plane security protection strategy; the user plane confidentiality protection strategy and the user plane integrity protection strategy belong to the user plane security protection strategy. They are explained uniformly here and will not be repeated below.

[0182] In this embodiment, the security protection strategy has three possible values: REQUIRED, NOT NEEDED, and PREFERRED. REQUIRED means security must be enabled, NOT NEEDED means security does not need to be enabled, and PREFERRED means security is preferred to be enabled, i.e., security can be enabled or not. This is explained uniformly here and will not be repeated below.

[0183] It should be noted that the specific value name of the security protection policy determined by the directly connected application server or application function network element according to application requirements may not be one of the three types mentioned above (REQUIRED, NOT NEEDED, and PREFERRED). However, the security protection policy determined by the directly connected server or application function network element according to application requirements will also be divided into "security needs to be enabled," "security does not need to be enabled," and "security is preferred to be enabled," and the specific names are not limited here. That is to say, in the security protection policy determined by the directly connected application server or application function network element, the value indicating that security must be enabled may not be REQUIRED, and / or the value indicating that security is preferred to be enabled may not be PREFERRED, and / or the value indicating that security does not need to be enabled may not be NOT NEEDED. The core network element will map the security protection policy determined by the directly connected application server or application function network element according to application requirements to the three values ​​mentioned above used in the network, namely REQUIRED, NOT NEEDED, and PREFERRED. In the following embodiments, for ease of distinction, the security protection policy configuration determined by the directly connected application server or application function network element according to application requirements is referred to as Security Protection Policy Configuration #1.

[0184] For example, taking the control plane confidentiality protection policy in a PC5 connection as an example, the control plane confidentiality protection policy in a PC5 connection includes: control plane confidentiality protection enabled (REQUIRED), control plane confidentiality protection disabled (NOT NEEDED), or control plane confidentiality protection optional (PREFERRED). Examples of control plane integrity protection policies, user plane confidentiality protection policies, or user plane integrity protection policies in a PC5 connection can be found in the examples of control plane confidentiality protection policies in a PC5 connection, and will not be repeated here.

[0185] It should be noted that, in the embodiments of this application, when the security protection policy is sent, generally only one of the three options (REQUIRED, NOT NEEDED, and PREFERRED) will be selected for transmission. In certain special scenarios, at least two options may be selected, with one of them being PREFERRED. For example, sending NOT NEEDED and PREFERRED indicates a preference for not enabling security protection; sending REQUIRED and PREFERRED indicates a preference for enabling security protection.

[0186] In this application embodiment, for a certain protection strategy in the security protection strategy, assuming that the protection strategy of one terminal device is REQUIRED and the protection strategy of another terminal device is NOT NEEDED, it can be considered that the protection strategies of the two terminal devices are mismatched; otherwise, it can be considered that the protection strategies of the two terminal devices are matched.

[0187] For example, taking user plane confidentiality protection in a PC5 connection as an example, assuming the user plane confidentiality protection policy of the first terminal device in the PC5 connection is NOT NEEDED, and the user plane confidentiality protection policy of the second terminal device in the PC5 connection is REQUIRED; or, assuming the user plane confidentiality protection policy of the first terminal device in the PC5 connection is REQUIRED, and the user plane confidentiality protection policy of the second terminal device in the PC5 connection is NOT NEEDED, then it can be determined that the user plane confidentiality protection policies of the first terminal device and the second terminal device in the PC5 connection do not match. If the user plane confidentiality protection policies of the first terminal device and the second terminal device in the PC5 connection are other values, it can be considered that the user plane confidentiality protection policies of the first terminal device and the second terminal device in the PC5 connection match.

[0188] In one possible implementation, in this embodiment of the application, when the security protection strategy includes a protection strategy, security protection strategy matching means that the protection strategy matches. For example, assuming that the security protection strategy only includes the user plane confidentiality protection strategy in the PC5 connection, then as long as the user plane confidentiality protection strategy in the PC5 connection matches, the security protection strategy can be considered to match.

[0189] In another possible implementation, in this embodiment of the application, when the security protection strategy includes multiple protection strategies, security protection strategy matching means that each of these multiple protection strategies matches. For example, assuming the security protection strategy includes a user plane confidentiality protection strategy and an integrity protection strategy in the PC5 connection, then when the user plane confidentiality protection strategy in the PC5 connection matches and the user plane integrity protection strategy in the PC5 connection matches, the security protection strategy is considered to match; otherwise, it is considered that the security protection strategies do not match.

[0190] It should be noted that, in the embodiments of this application, the control plane confidentiality protection strategy, the control plane integrity protection strategy, the user plane confidentiality protection strategy, or the multiple protection strategies in the PC5 connection can be the same or different, and the embodiments of this application do not make specific limitations in this regard.

[0191] Fourth, safety protection methods: The security protection methods in this application are divided into the following two categories: 1. The security protection method used in the control plane of PC5 connection is used to protect the control plane signaling of PC5 connection.

[0192] 2. Security protection methods used in the PC5 connection user plane to protect the PC5 connection user plane data.

[0193] In this application embodiment, the security protection method includes whether confidentiality protection and / or integrity protection are enabled, which will be uniformly explained here and will not be repeated below.

[0194] For example, the security protection method used by the control plane of the PC5 connection may include whether the confidentiality protection and / or integrity protection of the PC5 connection's control plane is enabled; or, the security protection method used by the user plane of the PC5 connection may include whether the confidentiality protection and / or integrity protection of the PC5 connection's user plane is enabled. It should be noted that, in this embodiment, the security protection method used by the control plane of the PC5 connection and the security protection method used by the user plane of the PC5 connection belong to the security protection methods of the PC5 connection, and will be uniformly described here, without further elaboration below.

[0195] The technical solutions of the embodiments of this application will be described below with reference to the accompanying drawings. In the description of this application, unless otherwise stated, " / " indicates that the objects before and after are in an "or" relationship. For example, A / B can represent A or B. "And / or" in this application is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, and B alone, where A and B can be singular or plural. Furthermore, in the description of this application, unless otherwise stated, "multiple" refers to two or more. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can represent: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or multiple. Furthermore, to facilitate a clear description of the technical solutions in the embodiments of this application, the terms "first" and "second" are used in the embodiments of this application to distinguish identical or similar items with substantially the same function and effect. Those skilled in the art will understand that the terms "first" and "second" do not limit the quantity or execution order, and that "first" and "second" are not necessarily different. Meanwhile, in the embodiments of this application, the terms "exemplary" or "for example" are used to indicate that something is being used as an example, illustration, or description. Any embodiment or design scheme described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design schemes. Specifically, the use of terms such as "exemplary" or "for example" is intended to present related concepts in a concrete manner for ease of understanding.

[0196] Furthermore, the network architecture and business scenarios described in the embodiments of this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided in the embodiments of this application. As those skilled in the art will know, with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.

[0197] To facilitate understanding of the embodiments of this application, firstly, in conjunction with Figure 1 This application describes in detail one application scenario of the embodiments of this application.

[0198] Figure 1 This is a schematic diagram of the network architecture applicable to the methods provided in the embodiments of this application. As shown in the figure, the network architecture may specifically include the following network elements: 1. User Equipment (UE): This can be referred to as terminal equipment, terminal, access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, wireless communication equipment, user agent, or user device. Terminal equipment can also be a cellular phone, cordless phone, session initiation protocol (SIP) phone, wireless local loop (WLL) station, personal digital assistant (PDA), handheld device with wireless communication capabilities, computing device or other processing device connected to a wireless modem, vehicle-mounted equipment, drone, wearable device, terminal equipment in a 5G network, or terminal equipment in an evolved public land mobile network (PLMN), etc. This application embodiment does not limit this. The UE can connect to next-generation radio access network (NG-RAN) equipment via the Uu interface, for example... Figure 1 UE#A and UE#D, as shown, are connected to NG-RAN via the Uu interface. Two UEs with proximity-based services application capabilities can also be connected via the PC5 interface, for example... Figure 1 As shown, UE#A and UE#B are connected via the PC5 interface, UE#B and UE#C are connected via the PC5 interface, and UE#A and UE#D are connected via the PC5 interface.

[0199] 2. Access Network (AN): Provides network access for authorized users in a specific area and can use transmission tunnels of different quality depending on the user's level and service requirements. Access networks can employ different access technologies. Current access network technologies include: radio access network technologies used in 3G systems, radio access network technologies used in 4G systems, or... Figure 1 The NG-RAN technology shown (such as the radio access technology used in 5G systems) etc.

[0200] An access network that implements access network functions based on wireless communication technology can be called a radio access network (RAN). A RAN manages radio resources, provides access services to terminals, and facilitates the forwarding of control signals and user data between terminals and the core network.

[0201] Wireless access network equipment can be, for example, a base station (NodeB), an evolved NodeB (eNB or eNodeB), a next-generation Node Base station (gNB) in a 5G mobile communication system, a base station in a 5G mobile communication system, or an access point (AP) in a wireless fidelity (WiFi) system. It can also be a wireless controller in a cloud radio access network (CRAN) scenario, or it can be a relay station, access point, vehicle-mounted equipment, drone, wearable device, or network equipment in a 5G network or an evolved PLMN. This application does not limit the specific technology or equipment form used in the wireless access network equipment.

[0202] 3. Access Management Network Element: Primarily used for mobility and access management, responsible for transmitting user policies between user equipment and policy control function (PCF) network elements. It can be used to implement functions of the mobility management entity (MME) other than session management. For example, functions such as lawful access monitoring or access authorization (or authentication).

[0203] In 5G communication systems, the access management network element can be an access and mobility management function (AMF) network element. In future communication systems, the access management network element can still be an AMF network element, or it can have other names; this application does not limit this.

[0204] 4. Session Management Network Element: Primarily used for session management, allocation and management of Internet Protocol (IP) addresses for user equipment, selection of endpoints for manageable user plane functions, policy control and charging function interfaces, and downlink data notification, etc.

[0205] In 5G communication systems, the session management network element can be a session management function (SMF) network element. In future communication systems, the session management network element can still be an SMF network element, or it can have other names; this application does not limit this.

[0206] 5. User plane network elements: used for packet routing and forwarding, quality of service (QoS) processing of user plane data, completion of user plane data forwarding, session / flow-level billing statistics, bandwidth limiting, and other functions.

[0207] In 5G communication systems, user plane network elements can be user plane function (UPF) network elements. In future communication systems, user plane network elements can still be UPF network elements, or they can have other names; this application does not limit this.

[0208] 6. Data network element: A network used to provide data transmission.

[0209] In 5G communication systems, data network elements can be data network (DN) elements. In future communication systems, data network elements can still be DN elements, or they can have other names; this application does not limit this.

[0210] 7. Policy control network element: A unified policy framework used to guide network behavior, providing policy rule information to control plane functional network elements (such as AMF, SMF, etc.).

[0211] In 4G communication systems, this policy control network element can be a policy and charging rules function (PCRF) network element. In 5G communication systems, this policy control network element can be a policy control function (PCF) network element. In future communication systems, this policy control network element can still be a PCF network element, or it can have other names; this application does not limit its scope.

[0212] 8. Data management network element: used to handle user equipment identification, access authentication, registration and mobility management, etc.

[0213] In 5G communication systems, this data management network element can be a unified data management (UDM) network element; in 4G communication systems, this data management network element can be a home subscriber server (HSS) network element. In future communication systems, the data management network element can still be a UDM network element, or it can have other names; this application does not limit this.

[0214] 9. Data warehouse network element: Used to store and retrieve data of various types, such as contract data, strategy data, and application data.

[0215] In 5G communication systems, this data warehouse network element can be a unified data repository (UDR) network element. In future communication systems, the data warehouse network element can still be a UDR network element, or it can have other names; this application does not limit this.

[0216] 10. Network Exposure Function (NEF) entity: Used to securely expose services and capabilities provided by 3GPP network functions to the outside world.

[0217] 11. ProSe Application Server: This can be a DN application function (AF). An AF with ProSe application server functionality has all the functions of an AF as defined in Release 23.501 R-15, as well as related functions for ProSe services. That is, in the user plane architecture, the ProSe application server and the UE communicate via the UE-RAN-UPF-AF path. The ProSe application server can also communicate with other network functions (NFs) in the 5G core network (5GC) in the control plane architecture via NEF. For example, it can communicate with the PCF via NEF. If the ProSe application server is a DN AF, and this AF is deployed by the 5GC operator, then the ProSe application server can also communicate directly with other NFs in the 5GC in the control plane architecture without going through NEF, such as directly communicating with the PCF.

[0218] 12. 5G Direct Discovery Name Management Function (DDNMF): This function assigns and processes the mapping between ProSe application identifiers and ProSe application codes for open ProSe discovery. In restricted ProSe direct discovery, 5G DDNMF communicates with the ProSe application server via the PC2 interface to handle discovery request authorization. It also assigns and processes the mapping between application identifiers and codes used in restricted ProSe services. The codes used in restricted ProSe services include ProSe restricted codes, ProSe query codes, and ProSe response codes.

[0219] In the current standard definition, 5G DDNMF is PLMN-level, meaning that there is only one 5G DDNMF per PLMN. A 5G DDNMF can be uniquely identified by its Mobile Country Code (MCC) and Mobile Network Code (MNC).

[0220] It is understood that the aforementioned network element or function can be a network component in a hardware device, a software function running on dedicated hardware, or a virtualization function instantiated on a platform (e.g., a cloud platform). The aforementioned network element or function can be implemented by a single device, multiple devices working together, or a functional module within a single device; this application does not specifically limit this.

[0221] It should also be understood that the above Figure 1 The network architecture shown in the embodiments of this application is merely an example. The network architecture applicable to the embodiments of this application is not limited to this. Any network architecture that can realize the functions of the above-mentioned network elements is applicable to the embodiments of this application.

[0222] For example, in some network architectures, network function elements such as AMF, SMF, PCF, and UDM are all called network function (NF) elements; or, in other network architectures, a collection of elements such as AMF, SMF, PCF, and UDM can be called control plane function elements.

[0223] For ProSe, both UEs need to perform the ProSe discovery process before establishing unicast communication to identify the other UE.

[0224] The following is combined with Figure 2 The process of establishing a unicast connection between two UEs is illustrated using the example of UE#1 and UE#2 establishing a unicast connection. In the discovery process, UE#1 and UE#2 can correspond to the monitoring UE and the broadcasting UE in model A, respectively; or, UE#1 and UE#2 can correspond to the discoverer UE and the discovered UE in model B, respectively.

[0225] S210, UE#1 sends a direct communication request (DCR) message to UE#2 to initiate the establishment of PC5 unicast communication.

[0226] The direct communication request message may include the security capabilities of UE#1 and the signaling security policy of UE#1. The security capabilities of the UE are the security protection algorithms that the UE supports, including confidentiality protection algorithms and / or integrity protection algorithms.

[0227] S220, UE#1 and UE#2 perform direct authentication and key establishment process.

[0228] S230, UE#2 sends a direct security mode (DSM) command message to UE#1.

[0229] After receiving the direct communication request message from UE#1, UE#2 will first determine whether the control plane security protection policy of UE#1 matches the control plane security protection policy of its own end.

[0230] If the control plane security protection policy of UE#1 does not match the control plane security protection policy of the local UE, UE#2 will refuse to establish a connection. If the control plane security protection policy of UE#1 matches the control plane security protection policy of the local UE, UE#2 will determine the control plane security protection activation mode based on the control plane security protection policies of the two UEs. Further, UE#2 sends a direct connection security mode command message to UE#1. This message includes the selected security protection algorithm, which includes a confidentiality protection algorithm and an integrity protection algorithm. It should be noted that the security protection algorithm included in the direct connection security mode command message is determined based on the control plane security protection activation mode determined by UE#2, the security capabilities of UE#1, and the security capabilities of UE#2.

[0231] By using the security protection algorithm carried in the direct connection security mode command message, the control plane confidentiality protection and integrity protection enabled mode selected by UE#2 can be indicated to UE#1. For example, the null algorithm indicates that the corresponding security protection is not enabled, and the non-null algorithm indicates that the corresponding security protection is enabled.

[0232] S240, UE#1 sends a direct connection security mode complete message to UE#2.

[0233] After receiving the Direct Connection Security Mode command message from UE#2, UE#1 checks whether the security protection activation method implicitly indicated by the selected security algorithm carried in the message conforms to its local control plane security protection policy. If it does not conform, UE#1 will refuse to establish a connection; if it does conform, UE#1 will send a Direct Connection Security Mode Completion message to UE#2. The Direct Connection Security Mode Completion message includes UE#1's user plane security policy.

[0234] S250, UE#2 sends a direct communication accept (DCA) message to UE#1.

[0235] After receiving the Direct Connection Security Mode Complete message from UE#1, UE#2 will first determine whether the user plane security protection policy of UE#1 matches the user plane security protection policy of its own end.

[0236] If the user plane security protection policy of UE#1 does not match the user plane security protection policy of the local UE, UE#2 will refuse to establish a connection. If the user plane security protection policy of UE#1 matches the user plane security protection policy of the local UE, UE#2 will determine the user plane security protection activation method based on the user plane security protection policies of the two UEs. Further, UE#2 sends a direct communication acceptance message to UE#1. The direct communication acceptance message includes user plane security configuration information, which is used to notify UE#1 of the selected user plane security protection activation method.

[0237] As mentioned above, during the unicast connection establishment process, the two UEs may fail to establish a unicast connection due to mismatched security protection policies at both ends. This further leads to wasted signaling in the discovery process before the unicast connection establishment process, affecting network resource efficiency and the interoperability of direct connection services.

[0238] In view of this, this application provides a method for determining the activation mode of security protection so that two UEs can successfully establish a connection.

[0239] It should be understood that the embodiments shown below do not particularly limit the specific structure of the execution subject of the method provided in the embodiments of this application. As long as a program that can run the code of the method provided in the embodiments of this application can communicate according to the method provided in the embodiments of this application, for example, the execution subject of the method provided in the embodiments of this application can be a terminal device or a core network device, or a functional module in the terminal device or core network device that can call and execute the program.

[0240] It should also be noted that the security protection strategies described in the embodiments of this application include control plane security protection strategies and / or user plane security protection strategies. Further, the control plane security protection strategies include control plane confidentiality protection strategies and / or control plane integrity protection strategies, and the user plane security protection strategies include user plane confidentiality protection strategies and / or user plane integrity protection strategies. The security protection activation methods described in the embodiments of this application include control plane security protection activation methods and / or user plane security protection activation methods. Further, the control plane security protection activation methods include control plane confidentiality protection activation methods and / or control plane integrity protection activation methods, and the user plane security protection activation methods include user plane confidentiality protection activation methods and / or user plane integrity protection activation methods.

[0241] Without loss of generality, the method for determining the activation mode of security protection provided in the embodiments of this application will be described in detail using the interaction between terminal devices or core network devices as an example.

[0242] Figure 3A schematic flowchart illustrating the method for determining the activation mode of security protection provided in an embodiment of this application is shown. Figure 3 As shown, method 300 may include steps S310 to S340, each of which is described in detail below.

[0243] S310, the first terminal device and the second terminal device respectively receive the first identifier from the core network element.

[0244] For the first terminal device, the core network element can be a first policy control function network element, a first direct connection communication discovery name management function network element, etc., which provide services to the first terminal device; this application does not limit this. For the second terminal device, the core network element can be a second policy control function network element, a second direct connection communication discovery name management function element, etc., which provide services to the second terminal device. The first terminal device and the second terminal device can obtain the first identifier from the same core network element or from different core network elements. This will be discussed in conjunction with... Figure 4 The process of how the terminal device obtains the first identifier from the policy control function network element will not be detailed here for the sake of brevity. This will be discussed further below. Figure 5 The explanation of how terminal devices obtain the first identifier from the network element discovering the name management function through direct communication will not be detailed here for the sake of brevity.

[0245] The first identifier is used to modify the security protection policy of the terminal device. Specifically, the first identifier is used to modify the security protection policy used by the terminal device in the first service, which is configured for the terminal device by the policy control function network element.

[0246] For example, the first identifier is one or more of the following: a new security protection strategy, a new security protection activation method, and indication information #1 (an example of the first indication information).

[0247] The new security protection strategy refers to the security protection strategy configured by the core network element based on the security protection strategy of the first service. The new security protection strategy may be the same as or different from the security protection strategies included in the configuration of the first security protection strategy; this embodiment does not limit this. Since the first identifier is used to modify the security protection strategy of the terminal device, the new security protection strategy can be considered as the security protection strategy used when modifying the security protection strategy of the terminal device.

[0248] The new security protection activation method refers to the security protection activation method determined by the core network element according to the security protection policy configuration of the first service. The new security protection activation method may match or not match the security protection policies included in the security protection policy configuration; this application embodiment does not limit this. Matching the security protection activation method with the security protection policy can be: the security protection activation method is enabled, and the value of the security protection policy is not NOT NEEDED; or, the security protection activation method is disabled, and the value of the security protection policy is not REQUIRED. Dismatch between the security protection activation method and the security protection policy can be: the security protection activation method is enabled, and the value of the security protection policy is NOT NEEDED; or, the security protection activation method is disabled, and the value of the security protection policy is REQUIRED. Since the first identifier is used to modify the security protection policy of the terminal device, the new security protection activation method can be considered as the security protection activation method used when modifying the security protection policy of the terminal device.

[0249] Instruction message #1 is used to indicate that the security protection policy of the terminal device may be forcibly modified. Specifically, instruction message #1 is used to indicate that the security protection policy of the terminal device may be forcibly modified during the establishment of the connection for the first service. Alternatively, instruction message #1 is used to indicate that the security protection policy used by the terminal device in the first service may be forcibly modified.

[0250] For example, the first identifier can be named the security protection policy forced modification identifier. For instance, the first identifier can be referred to as the "overrule identifier" or the "overwrite identifier".

[0251] Optionally, the first identifier can also be used to indicate the security protection activation method used by the terminal device, rather than to modify the security protection policy of the terminal device. Specifically, the first identifier is used to indicate the security protection activation method used by the terminal device in the first service.

[0252] S320, the first terminal device determines whether to enable connection security protection based on the first identifier.

[0253] Specifically, during the process of establishing a connection for the first service between the first terminal device and the second terminal device, the first terminal device determines whether to enable security protection for the connection based on a first identifier. For example, the first service is a direct connection service, and the connection for the first service is a unicast connection.

[0254] It should be noted that the first terminal device can determine whether to enable security protection for the connection based on a first identifier obtained from a core network element, or it can determine whether to enable security protection for the connection based on a first identifier obtained from a second terminal device. If the first terminal device determines whether to enable security protection for the connection based on the first identifier obtained from a core network element, it can be understood that the first terminal device can, by default, determine whether to enable security protection for the first service connection based on the first identifier, saving additional processing logic and improving the processing efficiency of the first terminal device. If the first terminal device determines whether to enable security protection for the connection based on the first identifier obtained from a second terminal device, then the first terminal device can independently choose whether to enable security protection for the first service connection based on the first identifier, providing greater flexibility.

[0255] In this context, the first terminal device and the second terminal device are respectively the broadcasting UE and the monitoring UE in discovery mode A, or the first terminal device and the second terminal device are respectively the discovering UE and the discoverer UE in discovery mode B. In the connection establishment process following the discovery process, the second terminal device is the initiating UE in the connection establishment process, and the first terminal device is the receiving UE in the connection establishment process.

[0256] Whether to enable security protection for this connection includes whether to enable control plane security protection and / or user plane security protection for this connection. Whether to enable control plane security protection for this connection includes whether to enable control plane confidentiality protection and / or control plane integrity protection for this connection. Whether to enable user plane security protection for this connection includes whether to enable user plane confidentiality protection and / or user plane integrity protection for this connection.

[0257] It is understood that whether or not connection security protection is enabled can be equated to the connection security protection enabling method. Therefore, S320 can be replaced by: the first terminal device determining the connection security protection enabling method based on the first identifier. The connection security protection enabling method includes control plane security protection enabling method and / or user plane security protection enabling method. The control plane security protection enabling method includes control plane confidentiality protection enabling method and / or control plane integrity protection enabling method. The user plane security protection enabling method includes user plane confidentiality protection enabling method and / or user plane integrity protection enabling method. The security protection enabling method includes enabling security protection or disabling security protection.

[0258] As described in S310, the first identifier can take different forms. Furthermore, for different first identifiers, the method by which the first terminal device determines whether to enable the security protection of the connection is also different, as described below.

[0259] In one possible implementation, the first identifier is the indication information #1.

[0260] As an example, the first terminal device determines whether to enable security protection for the connection based on indication information #1 and security protection policy #1 (an example of a first security protection policy). Security protection policy #1 is the security protection policy used by the first terminal device in the first service. Therefore, it can be said that when the first terminal device determines whether to enable security protection for the connection based on indication information #1, it directly determines it according to its own security protection policy. The first terminal device's decision to enable security protection for the connection based on indication information #1 and security protection policy #1 simplifies its processing logic and improves its processing efficiency.

[0261] For example, if the first terminal device receives instruction information #1, and the control plane security protection policy #1 and / or user plane security protection policy #1 included in security protection policy #1 are required to be enabled, then the first terminal device determines to enable the control plane security protection and / or user plane security protection for the connection. Specifically, determining to enable the control plane security protection for the connection includes determining to enable the control plane confidentiality protection and / or control plane integrity protection for the connection, and determining to enable the user plane security protection for the connection includes determining to enable the user plane confidentiality protection and / or user plane integrity protection for the connection.

[0262] Specifically, when the first terminal device obtains instruction information #1: if the control plane confidentiality protection policy included in control plane security protection policy #1 is valued as REQUIRED, the first terminal device determines to enable control plane confidentiality protection for the connection; if the control plane integrity protection policy included in control plane security protection policy #1 is valued as REQUIRED, the first terminal device determines to enable control plane integrity protection for the connection; if the user plane confidentiality protection policy included in user plane security protection policy #1 is valued as REQUIRED, the first terminal device determines to enable user plane confidentiality protection for the connection; if the user plane integrity protection policy included in user plane security protection policy #1 is valued as REQUIRED, the first terminal device determines to enable user plane integrity protection for the connection.

[0263] For example, if the first terminal device receives instruction information #1, and the security protection policy #1 includes control plane security protection policy #1 and / or user plane security protection policy #1, which do not require enabling security protection, then the first terminal device determines not to enable control plane security protection and / or user plane security protection for the connection. Specifically, not enabling control plane security protection for the connection includes not enabling control plane confidentiality protection and / or control plane integrity protection for the connection, and not enabling user plane security protection for the connection includes not enabling user plane confidentiality protection and / or user plane integrity protection for the connection.

[0264] Specifically, when the first terminal device obtains instruction information #1: if the control plane confidentiality protection policy included in control plane security protection policy #1 is set to NOT NEEDED, the first terminal device determines not to enable control plane confidentiality protection for the connection; if the control plane integrity protection policy included in control plane security protection policy #1 is set to NOT NEEDED, the first terminal device determines not to enable control plane integrity protection for the connection; if the user plane confidentiality protection policy included in user plane security protection policy #1 is set to NOT NEEDED, the first terminal device determines not to enable user plane confidentiality protection for the connection; if the user plane integrity protection policy included in user plane security protection policy #1 is set to NOT NEEDED, the first terminal device determines not to enable user plane integrity protection for the connection.

[0265] Optionally, when the first terminal device determines whether to enable integrity protection for the connection based on the instruction information #1 and the security protection policy #1, the integrity protection rate that the first terminal device can support may also be considered.

[0266] As another example, the first terminal device determines whether to enable integrity protection for the connection based on the instruction information #1, the security protection policy #1, and the integrity protection rate that the first terminal device can support. This allows the first terminal device to determine whether to enable integrity protection based on its own real-time processing capabilities, which is more suitable for the real-time needs of the first terminal device.

[0267] For example, if the first terminal device receives instruction information #1, indicating that the security protection strategy #1 includes control plane integrity protection strategy #1 and / or user plane integrity protection strategy #1, which need to be enabled, and the integrity protection rate supported by the first terminal device can support the enabling of control plane integrity protection and / or user plane integrity protection, then the first terminal device determines to enable control plane integrity protection and / or user plane integrity protection for this connection.

[0268] Specifically, when the first terminal device obtains instruction information #1: if the control plane integrity protection policy included in control plane security protection policy #1 is REQUIRED, and the integrity protection rate supported by the first terminal device can support the enabling of control plane integrity protection, then the first terminal device determines to enable control plane integrity protection for the connection; if the user plane integrity protection policy included in user plane security protection policy #1 is REQUIRED, and the integrity protection rate supported by the first terminal device can support the enabling of user plane integrity protection, then the first terminal device determines to enable user plane integrity protection for the connection.

[0269] For example, if the first terminal device receives instruction information #1, indicating that security protection strategy #1 includes control plane integrity protection strategy #1 and / or user plane integrity protection strategy #1 which need to be enabled, and the integrity protection rate supported by the first terminal device does not support enabling control plane integrity protection and / or user plane integrity protection, then the first terminal device determines not to enable control plane integrity protection and / or user plane integrity protection for this connection.

[0270] Specifically, when the first terminal device obtains instruction information #1: if the control plane integrity protection policy included in control plane security protection policy #1 is REQUIRED, and the integrity protection rate supported by the first terminal device does not support enabling control plane integrity protection, then the first terminal device determines not to enable control plane integrity protection for the connection; if the user plane integrity protection policy included in user plane security protection policy #1 is REQUIRED, and the integrity protection rate supported by the first terminal device does not support enabling user plane integrity protection, then the first terminal device determines not to enable user plane integrity protection for the connection.

[0271] As another example, the first terminal device determines whether to enable security protection for the connection based on instruction information #1, security protection policy #1, and security protection policy #2 (an example of the second security protection policy).

[0272] Security protection policy #2 is the security protection policy used by the second terminal device in the first service, and it is sent by the second terminal device to the first terminal device. For example, during the connection establishment process, the second terminal device sends a DCR message to the first terminal device, which includes security protection policy #2. Specifically, the DCR message includes control plane security protection policy #2 and / or user plane security protection policy #2. As another example, during the connection establishment process, the second terminal device sends a DSM completion message to the first terminal device, which includes security protection policy #2. Specifically, the DSM completion message includes control plane security protection policy #2 and / or user plane security protection policy #2.

[0273] For example, when the first terminal device receives instruction information #1, it determines whether to enable security protection for the connection based on the higher security level of security protection policy between security protection policy #1 and security protection policy #2. The security levels of the security protection policies, from highest to lowest, are: security protection policy requiring security protection, security protection policy optional, and security protection policy not requiring security protection.

[0274] For example, if the first terminal device receives instruction information #1: if security protection policy #1 includes control plane security protection policy #1 and / or user plane security protection policy #1 which does not require security protection, while security protection policy #2 includes control plane security protection policy #2 and / or user plane security protection policy #2 which requires security protection, then the first terminal device determines that security protection policy #2 has a higher security level, and the first terminal device determines to enable control plane security protection and / or user plane security protection for the connection based on security protection policy #2. As another example, if security protection policy #1 includes control plane security protection policy #1 and / or user plane security protection policy #1 which requires security protection, while security protection policy #2 includes control plane security protection policy #2 and / or user plane security protection policy #2 which does not require security protection, then the first terminal device determines that security protection policy #1 has a higher security level, and the first terminal device determines to enable control plane security protection and / or user plane security protection for the connection based on security protection policy #1. For example, if security protection strategy #1 includes control plane security protection strategy #1 and / or user plane security protection strategy #1 which require security protection to be enabled, while security protection strategy #2 includes control plane security protection strategy #2 and / or user plane security protection strategy #2 which can be enabled or disabled, then the first terminal device determines that security protection strategy #1 has a higher security level, and the first terminal device determines to enable control plane security protection and / or user plane security protection for the connection based on security protection strategy #1.

[0275] In another possible implementation, the first identifier represents the new security protection strategy. Accordingly, the first terminal device determines whether to enable security protection for the connection based on the new security protection strategy. This method simplifies the processing logic of the first terminal device and improves its processing efficiency.

[0276] For example, if the first terminal device obtains a first identifier, and the first identifier represents a new security protection policy, and the new security protection policy requires security protection to be enabled, then the first terminal device determines to enable security protection for the connection.

[0277] Specifically, the first terminal device obtains a first identifier, which represents a new security protection strategy. If the new security protection strategy includes a control plane security protection strategy that requires security protection to be enabled, then the first terminal device determines to enable the control plane security protection for the connection. If the new security protection strategy also includes a user plane security protection strategy that requires security protection to be enabled, then the first terminal device determines to enable the user plane security protection for the connection.

[0278] More specifically, the first terminal device obtains a first identifier, which represents a new security protection policy: if the control plane confidentiality protection policy included in the new security protection policy is valued as REQUIRED, then the first terminal device determines to enable control plane confidentiality protection for the connection; if the control plane integrity protection policy included in the new security protection policy is valued as REQUIRED, then the first terminal device determines to enable control plane integrity protection for the connection; if the user plane confidentiality protection policy included in the new security protection policy is valued as REQUIRED, then the first terminal device determines to enable user plane confidentiality protection for the connection; if the user plane integrity protection policy included in the new security protection policy is valued as REQUIRED, then the first terminal device determines to enable user plane integrity protection for the connection.

[0279] For example, if the first terminal device obtains a first identifier, and the first identifier represents a new security protection policy, and the new security protection policy is that security protection does not need to be enabled, then the first terminal device determines not to enable security protection for the connection.

[0280] Specifically, the first terminal device obtains a first identifier, which represents a new security protection strategy. If the new security protection strategy includes a control plane security protection strategy that does not require enabling security protection, then the first terminal device determines not to enable the control plane security protection for the connection. If the new security protection strategy also includes a user plane security protection strategy that does not require enabling security protection, then the first terminal device determines not to enable the user plane security protection for the connection.

[0281] More specifically, the first terminal device obtains a first identifier, which represents a new security protection policy: if the control plane confidentiality protection policy included in the new security protection policy is valued as NOT NEEDED, the first terminal device determines not to enable control plane confidentiality protection for the connection; if the control plane integrity protection policy included in the new security protection policy is valued as NOT NEEDED, the first terminal device determines not to enable control plane integrity protection for the connection; if the user plane confidentiality protection policy included in the new security protection policy is valued as NOT NEEDED, the first terminal device determines not to enable user plane confidentiality protection for the connection; if the user plane integrity protection policy included in the new security protection policy is valued as NOT NEEDED, the first terminal device determines not to enable user plane integrity protection for the connection.

[0282] For example, if a first terminal device obtains a first identifier, which represents a new security protection policy, and this policy allows for optional security protection, then the first terminal device can determine whether to enable or disable security protection for the connection. Alternatively, the first terminal device may determine whether to enable security protection based on its own security requirements. If the first terminal device requires security protection to be enabled, it will enable security protection for the connection; if it requires security protection to be disabled, it will disable security protection for the connection.

[0283] Specifically, the first terminal device obtains a first identifier, which represents a new security protection strategy. The new security protection strategy includes a control plane security protection strategy that can be enabled or disabled. In this case, the first terminal device can determine whether to enable the control plane security protection for the connection or not. Similarly, the new security protection strategy includes a user plane security protection strategy that can be enabled or disabled. In this case, the first terminal device can determine whether to enable the user plane security protection for the connection or not.

[0284] More specifically, the first terminal device obtains a first identifier, which represents a new security protection policy: if the control plane confidentiality protection policy included in the new security protection policy is valued as PREFERRED, the first terminal device can determine whether to enable control plane confidentiality protection for the connection or not; if the control plane integrity protection policy included in the new security protection policy is valued as PREFERRED, the first terminal device can determine whether to enable control plane integrity protection for the connection or not; if the user plane confidentiality protection policy included in the new security protection policy is valued as PREFERRED, the first terminal device can determine whether to enable user plane confidentiality protection for the connection or not; if the user plane integrity protection policy included in the new security protection policy is valued as PREFERRED, the first terminal device can determine whether to enable user plane integrity protection for the connection or not.

[0285] It should be understood that the embodiments of this application do not limit whether the values ​​of the control plane security protection strategy and the user plane security protection strategy are the same, nor do they limit whether the values ​​of the control plane confidentiality protection strategy and the control plane integrity protection strategy are the same, nor do they limit whether the values ​​of the user plane confidentiality protection strategy and the user plane integrity protection strategy are the same.

[0286] In another possible implementation, the first identifier represents a new security protection activation method. Accordingly, the first terminal device determines whether to enable security protection for the connection based on the new security protection activation method. This method simplifies the processing logic of the first terminal device and improves its processing efficiency.

[0287] For example, if the first terminal device obtains a first identifier, and the first identifier is a new security protection activation method, and the new security protection activation method is to enable security protection, then the first terminal device determines to enable the security protection for the single connection.

[0288] Specifically, if the first terminal device obtains a first identifier, and the first identifier is a new security protection activation method, and the new security protection activation method includes the control plane security protection activation method of enabling security protection, then the first terminal device determines to enable the control plane security protection of the connection; if the new security protection activation method includes the user plane security protection activation method of enabling security protection, then the first terminal device determines to enable the user plane security protection of the connection.

[0289] More specifically, the first terminal device acquires a first identifier, which represents a new security protection activation method: if the new security protection activation method includes enabling control plane confidentiality protection, the first terminal device determines to enable control plane confidentiality protection for the connection; if the new security protection activation method includes enabling control plane integrity protection, the first terminal device determines to enable control plane integrity protection for the connection; if the new security protection activation method includes enabling user plane confidentiality protection, the first terminal device determines to enable user plane confidentiality protection for the connection; if the new security protection activation method includes enabling user plane integrity protection, the first terminal device determines to enable user plane integrity protection for the connection.

[0290] For example, if the first terminal device obtains a first identifier, and the first identifier is a new security protection activation mode, and the new security protection activation mode is to disable security protection, then the first terminal device determines not to enable the security protection for this connection.

[0291] Specifically, the first terminal device obtains a first identifier, which is a new security protection activation mode. If the new security protection activation mode includes a control plane security protection activation mode of not enabling security protection, then the first terminal device determines not to enable the control plane security protection of the connection. If the new security protection activation mode includes a user plane security protection activation mode of not enabling security protection, then the first terminal device determines not to enable the user plane security protection of the connection.

[0292] More specifically, the first terminal device obtains a first identifier, which represents a new security protection activation method: if the new security protection activation method includes a control plane confidentiality protection activation method that disables confidentiality protection, then the first terminal device determines that the control plane confidentiality protection for the connection is disabled; if the new security protection activation method includes a control plane integrity protection activation method that disables integrity protection, then the first terminal device determines that the control plane integrity protection for the connection is disabled; if the new security protection activation method includes a user plane confidentiality protection activation method that disables confidentiality protection, then the first terminal device determines that the user plane confidentiality protection for the connection is disabled; if the new security protection activation method includes a user plane integrity protection activation method that disables integrity protection, then the first terminal device determines that the user plane integrity protection for the connection is disabled.

[0293] It should be understood that the embodiments of this application do not limit whether the new security protection activation method includes the control plane security protection activation method and the user plane security protection activation method are the same, nor do they limit whether the control plane confidentiality protection activation method and the control plane integrity protection activation method are the same, nor do they limit whether the user plane confidentiality protection activation method and the user plane integrity protection activation method are the same.

[0294] In another possible implementation, the first identifier represents a new security protection activation method and a new security protection strategy. Accordingly, the first terminal device determines whether to activate the security protection for the connection based on the new security protection activation method or the new security protection strategy.

[0295] In another possible implementation, the first identifier is indication information #1 and a new security protection policy. Accordingly, the first terminal device determines whether to enable security protection for the connection based on indication information #1 and / or the new security protection policy.

[0296] In another possible implementation, the first identifier is indication information #1 and a new security protection activation method. Accordingly, the first terminal device determines whether to activate the security protection for the connection based on indication information #1 and / or the new security protection activation method.

[0297] In another possible implementation, the first identifier is indication information #1, a new security protection policy, and a new security protection activation method. Accordingly, the first terminal device determines whether to enable security protection for the connection based on indication information #1, the new security protection policy, or the new security protection activation method.

[0298] In another possible implementation, the first identifier is used to indicate the security protection activation method used by the terminal device, and the first terminal device determines whether to enable the security protection for the connection based on the first identifier. Specifically, refer to the method by which the first terminal device determines whether to enable the security protection for the connection based on the new security protection activation method. The method by which the first terminal device determines whether to enable the security protection for the connection based on the first identifier simplifies the processing logic of the first terminal device and improves its processing efficiency.

[0299] As described above, when the first terminal device determines whether to enable security protection for the connection based on the first identifier, the first terminal device may disregard security protection policy #1 and / or security protection policy #2. Therefore, the security protection activation method determined by the first terminal device for the connection may not match security protection policy #1 and / or security protection policy #2. Thus, the use of the first identifier to modify the terminal device's security protection policy can be understood as determining the security protection activation method based on the first identifier, rather than according to the security protection policy configured for the terminal device by the policy control function network element.

[0300] Optionally, prior to S320, method 300 further includes: the first terminal device determining whether security protection policy #1 matches security protection policy #2.

[0301] The matching of security protection policy #1 and security protection policy #2 can be: the value of security protection policy #1 is REQUIRED, and the value of security protection policy #2 is not NOT NEEDED; or, the value of security protection policy #1 is NOT NEEDED, and the value of security protection policy #2 is not REQUIRED; or, the values ​​of both security protection policy #1 and security protection policy #2 are PREFERRED; or, the value of security protection policy #2 is REQUIRED, and the value of security protection policy #1 is not NOT NEEDED; or, the value of security protection policy #2 is NOT NEEDED, and the value of security protection policy #1 is not REQUIRED.

[0302] The mismatch between security protection policy #1 and security protection policy #2 can be caused by: security protection policy #1 being NOTNEEDED and security protection policy #2 being REQUIRED; or, security protection policy #1 being REQUIRED and security protection policy #2 being NOT NEEDED. Further, when the first terminal device determines that security protection policy #1 and security protection policy #2 do not match, it determines whether to enable security protection for the connection based on the first identifier.

[0303] As described in S320, when the first terminal device determines whether to enable the security protection of the connection based on the first identifier, it can prevent the connection establishment from failing due to the mismatch of security protection policies between the first terminal device and the second terminal device, which would further lead to wasted signaling in the discovery process before the connection establishment process and affect network resource efficiency and service interoperability.

[0304] Optionally, prior to S320, method 300 further includes: the first terminal device determining whether the second terminal device supports forcibly modifying the security protection policy.

[0305] In one possible implementation, the first terminal device determining whether the second terminal device supports forced modification of the security protection policy includes: during the discovery process of the first service, the first terminal device receives service discovery parameters from the second terminal device; the first terminal device determines whether the second terminal device supports forced modification of the security protection policy based on the service discovery parameters. Specifically, if the service discovery parameters correspond to a first identifier, the first terminal device determines that the second terminal device supports forced modification of the security protection policy; if the service discovery parameters do not correspond to the first identifier, the first terminal device determines that the second terminal device does not support forced modification of the security protection policy.

[0306] It is understood that in this implementation, the first terminal device and the second terminal device can obtain the service discovery parameter and the first identifier in advance, and there is a corresponding relationship between the service discovery parameter and the first identifier. The form of the correspondence between the service discovery parameter and the first identifier can be that the first identifier is carried in the service discovery parameter, or it can be a mapping relationship of [service discovery parameter, first identifier]. The following will explain how the terminal device obtains the service discovery parameter and the first identifier in conjunction with method 500.

[0307] For the second terminal device, if the second terminal device has pre-obtained the service discovery parameters corresponding to the first identifier, and the second terminal device supports forcibly modifying the security protection policy, then in the first service discovery process, the second terminal device sends the service discovery parameters that correspond to the first identifier. If the second terminal device does not support forcibly modifying the security protection policy, then in the first service discovery process, the second terminal device sends the service discovery parameters that do not correspond to the first identifier.

[0308] For example, the service discovery parameter mentioned above is the service discovery code.

[0309] In another possible implementation, the first terminal device determines whether the second terminal device supports forced modification of the security protection policy by: during the connection establishment process, the first terminal device receives a first message from the second terminal device; the first terminal device determines whether the second terminal device supports forced modification of the security protection policy based on the first message. Specifically, if the first message includes a first identifier, the first terminal device determines that the second terminal device supports forced modification of the security protection policy; if the first message does not include the first identifier, the first terminal device determines that the second terminal device does not support forced modification of the security protection policy.

[0310] For the second terminal device, if the second terminal device supports forced modification of the security protection policy, the second terminal device carries the first identifier in the first message; if the second terminal device does not support forced modification of the security protection policy, the second terminal device does not carry the first identifier in the first message.

[0311] For example, the first message is a DCR message, or the first message is a DSM completion message.

[0312] Further, if the first terminal device determines that the second terminal device supports forcibly modifying the security protection policy, it determines whether to enable security protection for the connection based on the first identifier. In S330, the first terminal device sends first information. Correspondingly, in S330, the second terminal device receives the first information. The first information is used to indicate whether to enable security protection for the connection.

[0313] For example, the first information includes a security protection algorithm. If the security protection algorithm is an empty algorithm, it indicates that the security protection of the connection should not be enabled; if the security protection algorithm is a non-empty algorithm, it indicates that the security protection of the connection should be enabled.

[0314] Optionally, the first information may also include a first identifier, which indicates that the security protection activation method of the connection is determined based on the first identifier.

[0315] For example, the first information is a DSM command message, or the first information is a DCA message. For instance, after receiving a DCR message from a second terminal device, the first terminal device determines whether to enable control plane security protection for the connection based on a first identifier, and sends a DSM command message to the second terminal device. The DSM command message is used to indicate whether to enable control plane security protection for the connection. Further, after receiving a DSM completion message from the second terminal device, the first terminal device determines whether to enable user plane security protection for the connection based on a first identifier, and sends a DCA message to the second terminal device. The DCA message is used to indicate whether to enable user plane security protection for the connection.

[0316] S340, the second terminal device determines whether to enable connection security protection based on the first information.

[0317] Specifically, if the first information indicates that the security protection of the connection should be enabled, then the second terminal device should enable the security protection of the connection; if the first information indicates that the security protection of the connection should not be enabled, then the second terminal device should not enable the security protection of the connection.

[0318] Optionally, if the second terminal device obtains the first identifier in advance, which means that the second terminal device supports forcibly modifying the security protection policy, then the second terminal device will not perform a security protection policy matching check. That is, the second terminal device will not check whether the security protection enabling method of the connection determined according to the first information conforms to security protection policy #2.

[0319] Optionally, if the second terminal device obtains the first identifier in advance, and carries the first identifier in the first message during the connection establishment process, indicating that the second terminal device supports forced modification of the security protection policy, then the second terminal device does not perform a security protection policy matching check. That is, the second terminal device does not check whether the security protection activation method of the connection determined based on the first information conforms to security protection policy #2. For example, the first message is a DCR message, or the first message is a DSM completion message.

[0320] Optionally, if the first information includes a first identifier, the second terminal device determines the connection's security protection activation method based on the first identifier. Further, if the second terminal device supports forcibly modifying the security protection policy, it determines whether to enable the connection's security protection based on the first information.

[0321] In this embodiment of the application, during the process of establishing a first service connection between the first terminal device and the second terminal device, the first terminal device can determine whether to enable the security protection of the connection based on the first identifier, rather than determining whether to enable the security protection of the connection based on the security protection policies of the two terminal devices. This can avoid the inability to successfully determine whether to enable the security protection of the connection when the security protection policies of the two terminal devices do not match, thereby avoiding the waste of signaling caused by connection establishment failure.

[0322] Furthermore, when the first terminal device determines whether to enable connection security protection based on the first identifier, the first terminal device may not check whether the connection security protection enabling method matches its own security protection policy, nor may it check whether the second terminal device's security protection policy matches its own security protection policy, thereby saving processing resources for the terminal device; when the second terminal device determines whether to enable connection security protection based on the first identifier, the second terminal device may not check whether the connection security protection enabling method matches its own security protection policy, thereby saving processing resources for the terminal device.

[0323] The following describes specific embodiments. Figures 4 to 7 Regarding the above Figure 3 The methods described in the text will be explained in detail. Specifically, they will be combined with... Figure 4 and Figure 5 The method for terminal equipment to receive the first identifier from core network elements is explained. (In conjunction with...) Figure 6 and Figure 7 Taking the first service as an example, and taking the first service connection as a PC5 unicast connection as an example, the above... Figure 3 The methods described in the text will be explained in detail.

[0324] Figure 4 A schematic flowchart of a communication method provided in an embodiment of this application is shown. Figure 4 As shown, method 400 may include steps S410 to S450, each of which is described in detail below. It should be understood that... Figure 4 Taking the policy control function network element of the core network as an example, this paper explains the method of receiving the first identifier from the core network element by the terminal device.

[0325] S410, the application function network element determines that the security protection policy configuration #1 of the first service includes multiple security protection policies with different values, and these multiple security protection policies include the security protection policies for the connection of the first service in different geographical locations.

[0326] Specifically, the application function network element determines the security protection policy configuration #1 for the first service based on application requirements. This configuration includes multiple security protection policies, corresponding to the control plane and / or user plane security protection policies for the first service's connection in different geographical locations. It should be noted that the security protection policies include confidentiality protection policies and / or integrity protection policies. For example, the control plane security protection policies include control plane confidentiality protection policies and / or control plane integrity protection policies, and the user plane security protection policies include user plane confidentiality protection policies and / or user plane integrity protection policies. For example, the security protection policy configuration #1 for the first service is shown in Table 1. Assume that the security protection policy configuration #1 for the first service includes three security protection policies, each corresponding to a different geographical location. In geographical location #A, the security protection policy for the first service's connection is security protection policy #A; in geographical location #B, the security protection policy for the first service's connection is security protection policy #B; and in geographical location #C, the security protection policy for the first service's connection is security protection policy #C.

[0327] Table 1

[0328] For example, the security protection policy configuration #1 for the first service is shown in Table 2. Assume that the security protection policy configuration #1 for the first service includes two security protection policies, each corresponding to one of three geographical locations. In geographical location #A, the security protection policy for the connection of the first service is security protection policy #A; in geographical locations #B and #C, the security protection policy for the connection of the first service is security protection policy #B.

[0329] Table 2

[0330] Further, the application function network element determines whether the values ​​of multiple security protection policies are the same. If the values ​​of the multiple security protection policies are different, the application function network element generates indication information #2 (an example of the second indication information). Indication information #2 is used to indicate that the security protection policy of the first service can be forcibly modified during connection establishment. Alternatively, indication information #2 is used to indicate that the security protection policy of the first service can be forcibly modified during connection establishment, and when the security protection policy of the first service is forcibly modified during connection establishment, all terminal devices using the first service use the same security protection policy. Alternatively, indication information #2 is used to indicate that the security protection policy of the first service can be forcibly modified during connection establishment, and when the security protection policy of the first service is forcibly modified during connection establishment, all terminal devices using the first service use the same security protection activation method. For example, indication information #2 can be named "Security Protection Policy Forcible Modification Indication". For example, the first identifier can be denoted as "overrule indication" or "overwrite indication".

[0331] As described above, the security protection policy configuration #1 of the first service includes multiple security protection policies corresponding to different geographical locations. If the values ​​of the multiple security protection policies are different, it means that the security protection policies for connections of the first service in different geographical locations are different. For terminal devices located in different geographical locations, different security protection policies may be used in the connection of the first service. Taking the security protection policy configuration #1 of the first service as shown in Table 1 as an example, if the values ​​of security protection policy #A and security protection policy #B are different, then terminal device #A located in geographical location #A and terminal device #B located in geographical location #B may use different security protection policies in the connection of the first service.

[0332] The different values ​​of the multiple security protection policies include: any two of the multiple security protection policies have different values, or at least two of the multiple security protection policies have different values.

[0333] As described above, the security protection strategy includes a control plane security protection strategy and / or a user plane security protection strategy. Different values ​​for the two security protection strategies include: the control plane security protection strategies and / or user plane security protection strategies included in the two security protection strategies are different. For example, different values ​​for the two security protection strategies include: different values ​​for the control plane security protection strategies included in the two security protection strategies; or, different values ​​for the user plane security protection strategies included in the two security protection strategies; or, different values ​​for both the control plane security protection strategies and the user plane security protection strategies included in the two security protection strategies are different.

[0334] Furthermore, the different security protection strategies for the two control planes include: the control plane confidentiality protection strategies and / or control plane integrity protection strategies included in the two control plane security protection strategies are different. For example, the different values ​​of the two control plane security protection strategies include: the control plane confidentiality protection strategies included in the two control plane security protection strategies are different, or the control plane integrity protection strategies included in the two control plane security protection strategies are different, or the control plane integrity protection strategies included in the two control plane security protection strategies are different, and the values ​​of the control plane integrity protection strategies included in the two control plane security protection strategies are different.

[0335] The two user plane security protection policies being different include: the two user plane security protection policies respectively including different user plane confidentiality protection policies and / or different user plane integrity protection policies. For example, the two user plane security protection policies having different values ​​include: the two user plane security protection policies including different values ​​of user plane confidentiality protection policies, or, the two user plane security protection policies including different values ​​of user plane integrity protection policies, or, the two user plane security protection policies including different values ​​of user plane integrity protection policies, and the two user plane security protection policies including different values ​​of user plane integrity protection policies.

[0336] Optionally, the application function network element can generate indication information #2 by default. That is, regardless of whether the values ​​of the multiple security protection policies included in the security protection policy configuration #1 of the first service are the same, the application function network element will generate indication information #2. Furthermore, the application function network element does not need to determine whether the values ​​of the multiple security protection policies are the same before generating indication information #2.

[0337] Optionally, prior to S410, method 400 further includes S430: the application function network element receives request message #1 (an example of a first request message). This request message #1 is used to request indication information #2. After receiving request message #1, the application function network element generates indication information #2 based on request message #1. For example, this request message #1 is sent by the policy control function network element to the application function network element through the network open function network element. Another example is that the request message #1 is sent directly by the policy control function network element to the application function network element.

[0338] In S420, the application function network element sends instruction information #2. Correspondingly, in S420, the policy control function network element (an example of a first core network element) receives instruction information #2.

[0339] The policy control function network element provides services to the first terminal device and / or the second terminal device in method 300.

[0340] For example, the application function network element sends instruction information #2 to the network open function network element, the network open function network element then sends instruction information #2 to the unified data warehouse network element, and the unified data warehouse network element then sends instruction information #2 to the policy control function network element.

[0341] For example, the application function network element directly sends the instruction information #2 to the policy control function network element.

[0342] Optionally, prior to S420, method 400 further includes S430: the policy control function network element sends a request message #1 to the application function network element, the request message #1 being used to request the acquisition of indication information #2. Correspondingly, after receiving the request message #1, the application function network element sends the indication information #2 to the policy control function network element.

[0343] Optionally, when it is determined that the values ​​of multiple security protection policies included in the security protection policy configuration of the first service are different, the policy control function network element sends a request message #1 to the application function network element. The meaning of the different values ​​of the multiple security protection policies included in the security protection policy configuration can be found in the description in S410.

[0344] The security protection policy configuration for the first service is determined based on the security protection policy configuration #1 obtained from the application function network element. It should be noted that determining the security protection policy configuration for the first service based on the security protection policy configuration #1 obtained from the application function network element can be executed by the network open function network element or by other core network elements, such as the policy function control network element. It should be understood that the security protection requirements of the multiple security protection policies included in security protection policy configuration #1 are the same as those of the multiple security protection policies included in the security protection policy configuration. The difference lies in the possible different or identical names of the security protection policy values. For example, security protection policy #A included in security protection policy configuration #1 and security protection policy #A included in the security protection policy configuration both require security to be enabled. The value of security protection policy #A included in the security protection policy configuration is REQUIRED, while the value of security protection policy #A included in security protection policy configuration #1 may not be REQUIRED.

[0345] S440, the policy control function network element determines the first identifier based on the security protection policy configuration and instruction information #2 of the first service.

[0346] The security protection policy configuration for the first service is determined based on the security protection policy configuration #1 obtained from the application function network element. It should be noted that determining the security protection policy configuration for the first service based on the security protection policy configuration #1 obtained from the application function network element can be executed by the network open function network element or by other core network elements, such as the policy function control network element.

[0347] The first identifier is used to modify the security protection policy of the terminal device. Specifically, the first identifier is used to modify the security protection policy used by the terminal device in the first service. The security protection policy used by the terminal device in the first service is configured for the terminal device by the policy control function network element.

[0348] For example, the first identifier is one or more of the following: a new security protection strategy, a new security protection activation method, or instruction information #1.

[0349] The new security protection strategy refers to the security protection strategy determined by the policy control function network element based on the security protection strategy configuration and instruction information #2 of the first service. The new security protection strategy may be the same as or different from the security protection strategies included in the security protection strategy configuration; this embodiment does not limit this. Since the first identifier is used to modify the security protection strategy of the terminal device, the new security protection strategy can be considered as the security protection strategy used when modifying the security protection strategy of the terminal device.

[0350] The new security protection activation method refers to the security protection activation method determined by the policy control function network element based on the security protection policy configuration and indication information #2 of the first service. The new security protection activation method may match or not match the security protection policies included in the security protection policy configuration; this application embodiment does not limit this. Matching the security protection activation method with the security protection policy can be: the security protection activation method is enabled, and the value of the security protection policy is not NOT NEEDED; or, the security protection activation method is disabled, and the value of the security protection policy is not REQUIRED. Dismatch between the security protection activation method and the security protection policy can be: the security protection activation method is enabled, and the value of the security protection policy is NOT NEEDED; or, the security protection activation method is disabled, and the value of the security protection policy is REQUIRED. Since the first identifier is used to modify the security protection policy of the terminal device, the new security protection activation method can be considered as the security protection activation method used when modifying the security protection policy of the terminal device.

[0351] Instruction message #1 is used to indicate that the security protection policy of the terminal device may be forcibly modified. Specifically, instruction message #1 is used to indicate that the security protection policy of the terminal device may be forcibly modified during the establishment of the connection for the first service. Alternatively, instruction message #1 is used to indicate that the security protection policy used by the terminal device in the first service may be forcibly modified.

[0352] Optionally, the first identifier can also be used to indicate the security protection activation method used by the terminal device, rather than to modify the security protection policy of the terminal device. Specifically, the first identifier is used to indicate the security protection activation method used by the terminal device in the first service.

[0353] In one possible implementation, once the policy control function network element receives the instruction information #2, it determines the first identifier based on the security protection policy configuration of the first service and the instruction information #2.

[0354] In another possible implementation, when the policy control function network element determines that the security protection policy configuration of the first service includes multiple security protection policy values ​​that are different, it determines the first identifier based on the security protection policy configuration and indication information #2. Specifically, the meaning of the multiple security protection policies and the meaning of the different values ​​of the multiple security protection policies can be found in the description in S410.

[0355] The following describes in detail how the policy control function network element determines the first identifier.

[0356] For example, the policy control function network element may determine the first identifier based on the security protection policy configuration and instruction information #2 in the following ways: Method 1: If instruction information #2 is also used to indicate that security protection needs to be enabled when the security protection policy of the first service is forcibly modified during connection establishment, then the policy control function network element determines the first identifier as the new security protection policy according to instruction information #2, and the value of the new security protection policy is REQUIRED.

[0357] Specifically, if instruction information #2 is also used to indicate that control plane security protection needs to be enabled, then the new security protection policy includes a control plane security protection policy with the value REQUIRED; if instruction information #2 is also used to indicate that user plane security protection needs to be enabled, then the new security protection policy includes a user plane security protection policy with the value REQUIRED.

[0358] More specifically, if instruction #2 is also used to indicate that control plane confidentiality protection needs to be enabled, then the new security protection policy includes a control plane confidentiality protection policy with the value REQUIRED; if instruction #2 is also used to indicate that control plane integrity protection needs to be enabled, then the new security protection policy includes a control plane integrity protection policy with the value REQUIRED; if instruction #2 is also used to indicate that user plane confidentiality protection needs to be enabled, then the new security protection policy includes a user plane confidentiality protection policy with the value REQUIRED; if instruction #2 is also used to indicate that user plane integrity protection needs to be enabled, then the new security protection policy includes a user plane integrity protection policy with the value REQUIRED.

[0359] If instruction information #2 is also used to indicate that security protection does not need to be enabled when the security protection policy of the first service is forcibly modified during connection establishment, the policy control function network element determines the first identifier according to instruction information #2 as the new security protection policy, and the value of the new security protection policy is NOT NEEDED.

[0360] Specifically, if instruction #2 is also used to indicate that control plane security protection does not need to be enabled, then the value of the control plane security protection policy included in the new security protection policy is NOT NEEDED; if instruction #2 is also used to indicate that user plane security protection does not need to be enabled, then the value of the user plane security protection policy included in the new security protection policy is NOT NEEDED.

[0361] More specifically, if instruction #2 is also used to indicate that control plane confidentiality protection is not required, then the control plane confidentiality protection policy included in the new security protection policy is set to NOT NEEDED; if instruction #2 is also used to indicate that control plane integrity protection is not required, then the control plane integrity protection policy included in the new security protection policy is set to NOT NEEDED; if instruction #2 is also used to indicate that user plane confidentiality protection is not required, then the user plane confidentiality protection policy included in the new security protection policy is set to NOT NEEDED; if instruction #2 is also used to indicate that user plane integrity protection is not required, then the user plane integrity protection policy included in the new security protection policy is set to NOT NEEDED.

[0362] Method 2: If instruction information #2 is also used to indicate that security protection needs to be enabled when the security protection policy of the first service is forcibly modified during connection establishment, then the policy control network element determines the first identifier as the new security protection enabling mode according to instruction information #2, and the new security protection enabling mode is to enable security protection.

[0363] Specifically, if instruction information #2 is also used to indicate that control plane security protection needs to be enabled, then the new security protection enabling method includes enabling security protection for control plane security protection; if instruction information #2 is also used to indicate that user plane security protection needs to be enabled, then the new security protection enabling method includes enabling security protection for user plane security protection.

[0364] More specifically, if instruction information #2 is also used to indicate that control plane confidentiality protection needs to be enabled, then the new security protection enabling method includes enabling confidentiality protection for control plane confidentiality; if instruction information #2 is also used to indicate that control plane integrity protection needs to be enabled, then the new security protection enabling method includes enabling integrity protection for control plane integrity; if instruction information #2 is also used to indicate that user plane confidentiality protection needs to be enabled, then the new security protection enabling method includes enabling confidentiality protection for user plane confidentiality; if instruction information #2 is also used to indicate that user plane integrity protection needs to be enabled, then the new security protection enabling method includes enabling integrity protection for user plane integrity.

[0365] If instruction information #2 is also used to indicate that when the security protection policy of the first service is forcibly modified during connection establishment, security protection does not need to be enabled, then the policy control function network element determines the first identifier according to instruction information #2 as the new security protection enabling mode, and the new security protection enabling mode is to disable security protection.

[0366] Specifically, if instruction information #2 is also used to indicate that control plane security protection does not need to be enabled, then the new security protection enabling method includes enabling control plane security protection without enabling security protection; if instruction information #2 is also used to indicate that user plane security protection does not need to be enabled, then the new security protection enabling method includes enabling user plane security protection without enabling security protection.

[0367] More specifically, if instruction #2 is also used to indicate that control plane confidentiality protection does not need to be enabled, then the new security protection enabling method includes enabling control plane confidentiality protection without enabling confidentiality protection; if instruction #2 is also used to indicate that control plane integrity protection does not need to be enabled, then the new security protection enabling method includes enabling control plane integrity protection without enabling integrity protection; if instruction #2 is also used to indicate that user plane confidentiality protection does not need to be enabled, then the new security protection enabling method includes enabling user plane confidentiality protection without enabling confidentiality protection; if instruction #2 is also used to indicate that user plane integrity protection does not need to be enabled, then the new security protection enabling method includes enabling user plane integrity protection without enabling integrity protection.

[0368] Optionally, in Method 2, the first identifier determined by the policy control function network element is used to indicate the security protection activation method used by the terminal device, without modifying the security protection policy of the terminal device. Specifically, the security protection activation method used by the terminal device indicated by the first identifier is the same as the new security protection activation method mentioned above, and will not be repeated here.

[0369] Method 3: If indication information #2 is used to indicate that the security protection policy of the first service can be forcibly modified during connection establishment, or if indication information #2 is used to indicate that all terminal devices using the first service use the same security protection policy, then the first identifier determined by the policy control function network element is indication information #1.

[0370] Method 4: If indication information #2 is used to indicate that the security protection policy of the first service can be forcibly modified during connection establishment, or if indication information #2 is used to indicate that the security protection policy of the first service can be forcibly modified during connection establishment, and when the security protection policy of the first service is forcibly modified during connection establishment, all terminal devices using the first service use the same security protection policy, then the policy control function network element determines the first identifier according to the security protection policy configuration of the first service, and the first identifier is the new security protection policy.

[0371] For example, if at least one of the multiple security protection policies included in the security protection policy configuration of the first service has a value of REQUIRED, then the value of the new security protection policy is REQUIRED.

[0372] Specifically, if the value of the control plane security protection policy included in at least one of the multiple security protection policies is REQUIRED, then the value of the control plane security protection policy included in the new security protection policy is REQUIRED; if the value of the user plane security protection policy included in at least one of the multiple security protection policies is REQUIRED, then the value of the user plane security protection policy included in the new security protection policy is REQUIRED.

[0373] More specifically, if the control plane confidentiality protection policy included in at least one of the multiple security protection policies has a value of REQUIRED, then the control plane confidentiality protection policy included in the new security protection policy has a value of REQUIRED; if the control plane integrity protection policy included in at least one of the multiple security protection policies has a value of REQUIRED, then the control plane integrity protection policy included in the new security protection policy has a value of REQUIRED; if the user plane confidentiality protection policy included in at least one of the multiple security protection policies has a value of REQUIRED, then the user plane confidentiality protection policy included in the new security protection policy has a value of REQUIRED; if the user plane integrity protection policy included in at least one of the multiple security protection policies has a value of REQUIRED, then the user plane integrity protection policy included in the new security protection policy has a value of REQUIRED.

[0374] For example, if the value of any one of the multiple security protection policies is not REQUIRED, then the value of the new security protection policy is NOT NEEDED.

[0375] Specifically, if the value of the control plane security protection policy included in any of the multiple security protection policies is not REQUIRED, then the value of the control plane security protection policy included in the new security protection policy is NOT NEEDED; if the value of the user plane security protection policy included in any of the multiple security protection policies is not REQUIRED, then the value of the user plane security protection policy included in the new security protection policy is NOT NEEDED.

[0376] More specifically, if the control plane confidentiality protection policy included in any of the multiple security protection policies is not REQUIRED, then the control plane confidentiality protection policy included in the new security protection policy is NOT NEEDED; if the control plane integrity protection policy included in any of the multiple security protection policies is not REQUIRED, then the control plane integrity protection policy included in the new security protection policy is NOT NEEDED; if the user plane confidentiality protection policy included in any of the multiple security protection policies is not REQUIRED, then the user plane confidentiality protection policy included in the new security protection policy is NOT NEEDED; if the user plane integrity protection policy included in any of the multiple security protection policies is not REQUIRED, then the user plane integrity protection policy included in the new security protection policy is NOT NEEDED.

[0377] Method 5: If instruction information #2 is used to indicate that the security protection policy of the first service can be forcibly modified during connection establishment, or if instruction information #2 is used to indicate that the security protection policy of the first service can be forcibly modified during connection establishment, and when the security protection policy of the first service is forcibly modified during connection establishment, all terminal devices using the first service use the same security protection policy, then the policy control function network element determines the first identifier according to the security protection policy configuration of the first service, and the first identifier is the new security protection enabling method.

[0378] For example, if the value of at least one of the multiple security protection policies included in the security protection policy configuration of the first service is REQUIRED, then the new security protection activation method is to enable security protection.

[0379] Specifically, if the value of the control plane security protection policy included in at least one of the multiple security protection policies is REQUIRED, then the new security protection activation method includes the control plane security protection activation method as "Enable Security Protection"; if the value of the user plane security protection policy included in at least one of the multiple security protection policies is REQUIRED, then the new security protection activation method includes the user plane security protection activation method as "Enable Security Protection".

[0380] More specifically, if the value of the control plane confidentiality protection policy included in at least one of the multiple security protection policies is REQUIRED, then the new security protection enabling method includes enabling confidentiality protection for control plane confidentiality protection; if the value of the control plane integrity protection policy included in at least one of the multiple security protection policies is REQUIRED, then the new security protection enabling method includes enabling integrity protection for control plane integrity protection; if the value of the user plane confidentiality protection policy included in at least one of the multiple security protection policies is REQUIRED, then the new security protection enabling method includes enabling confidentiality protection for user plane confidentiality protection; if the value of the user plane integrity protection policy included in at least one of the multiple security protection policies is REQUIRED, then the new security protection enabling method includes enabling integrity protection for user plane integrity protection.

[0381] For example, if the value of any of the multiple security protection policies is not REQUIRED, then the new security protection activation method is to disable security protection.

[0382] Specifically, if the value of the control plane security protection policy included in any of the multiple security protection policies is not REQUIRED, then the control plane security protection enabling method of the new security protection enabling method is to disable security protection; if the value of the user plane security protection policy included in any of the multiple security protection policies is not REQUIRED, then the user plane security protection enabling method of the new security protection enabling method is to disable security protection.

[0383] More specifically, if the value of the control plane confidentiality protection policy included in any of the multiple security protection policies is not REQUIRED, then the new security protection enabling method includes enabling confidentiality protection in the control plane confidentiality protection mode; if the value of the control plane integrity protection policy included in any of the multiple security protection policies is not REQUIRED, then the new security protection enabling method includes disabling integrity protection in the control plane integrity protection mode; if the value of the user plane confidentiality protection policy included in any of the multiple security protection policies is not REQUIRED, then the new security protection enabling method includes disabling confidentiality protection in the user plane confidentiality protection mode; and if the value of the user plane integrity protection policy included in any of the multiple security protection policies is not REQUIRED, then the new security protection enabling method includes disabling integrity protection in the user plane integrity protection mode.

[0384] Optionally, in Method 5, the first identifier determined by the policy control function network element is used to indicate the security protection activation method used by the terminal device, without modifying the security protection policy of the terminal device. Specifically, the security protection activation method used by the terminal device indicated by the first identifier is the same as the new security protection activation method mentioned above, and will not be repeated here.

[0385] Optionally, the policy control function network element can determine the first identifier based on the security protection policy configuration of the first service. That is, even if the policy control function network element does not receive indication information #2, it can still determine the first identifier based on the security protection policy configuration of the first service. Specifically, when the policy control function network element determines that the security protection policy of the first service includes multiple security protection policies with different values, it determines the first identifier based on the security protection policy configuration of the first service. The method by which the policy control function network element determines the first identifier based on the security protection policy configuration of the first service can be referred to methods four and five above; for simplicity, it will not be detailed here.

[0386] Optionally, the policy control function network element can also receive the first identifier from the network development function network element or the unified data warehouse network element. That is, the network development function network element or the unified data warehouse network element determines the first identifier and then sends the first identifier to the policy control function network element. Specifically, the method by which the network development function network element or the unified data warehouse network element determines the first identifier is the same as the method by which the policy control function network element determines the first identifier, and for the sake of simplicity, it will not be described in detail here.

[0387] In S450, the policy control function network element sends the first identifier. Correspondingly, in S450, the terminal device receives the first identifier.

[0388] For example, when the policy control function network element sends the security protection policy configuration for the first service to the terminal device, it may also send the first identifier to the terminal device. In other words, the policy control function network element may send the security protection policy configuration for the first service and the first identifier in the same signaling message to the terminal device.

[0389] In this embodiment, after the policy control function network element determines the first identifier based on the security protection policy configuration and instruction information #2 of the first service, it sends the first identifier to the terminal device. This helps the terminal device modify the security protection policy based on the first identifier, thereby avoiding the failure of the connection establishment of the first service due to the mismatch of the security protection policies of the two terminal devices.

[0390] Figure 5 A schematic flowchart of a communication method provided in an embodiment of this application is shown. Figure 5 As shown, method 500 may include steps S510 and S520, which are described in detail below. It should be understood that... Figure 4Taking the core network element of China-Israel as an example of a network element with direct communication discovery and name management functions, this paper explains the method by which a terminal device receives the first identifier from a core network element.

[0391] S510, the direct communication discovery name management function network element #A (an example of the first core network element) obtains the first identifier.

[0392] In this context, the direct communication discovery name management function network element #A provides services to terminal device #A, where terminal device #A is either the first terminal device or the second terminal device in method 300. A description of the first identifier can be found in S440 above; for brevity, it will not be elaborated upon here.

[0393] For example, the direct communication discovery name management function network element #A obtains the first identifier in the following ways: Method 1: Direct communication discovery name management function network element #A receives the first identifier from policy control function network element #A. Policy control function network element #A provides services to terminal device #A.

[0394] For example, by default, policy control function network element #A sends the first identifier to direct communication discovery name management function network element #A. For instance, when policy control function network element #A sends the security protection policy configuration for the first service to direct communication discovery name management function network element #A, it sends the first identifier to direct communication discovery name management function network element #A by default.

[0395] The first identifier is determined by the policy control function network element #A, or it is received by the policy control function network element #A from the network open function network element, or it is received by the policy control function network element #A from the unified data warehouse network element. Specifically, the method by which the policy control function network element #A determines the first identifier can be referred to in S440 above, and will not be described in detail here for the sake of brevity.

[0396] Optionally, method 500 further includes: the direct communication discovery name management function network element #A sending a request message #2 to the policy control function network element #A, the request message #2 being used to request the acquisition of a first identifier. Correspondingly, after receiving the request message #2, the policy control function network element #A sends the first identifier to the direct communication discovery name management function network element #A.

[0397] Optionally, after receiving request message #2, policy control function network element #A determines the first identifier based on the security protection policy configuration and indication information #2 of the first service, and then sends the first identifier to the direct communication discovery name management function network element #A. A description of indication information #2 can be found in S420 above; for brevity, it will not be detailed here.

[0398] Optionally, after receiving request message #2, policy control function network element #A sends request message #1 to application function network element, request message #1 being used to request obtaining indication information #2. Further, after receiving indication information #2 from application function network element #A, policy control function network element #A determines a first identifier based on the security protection policy configuration of the first service and indication information #2, and then sends the first identifier to direct communication discovery name management function network element #A.

[0399] Optionally, when the direct communication discovery name management function network element #A determines that the security protection policy configuration of the first service includes multiple security protection policy values ​​that are different, it sends a request message #2 to the policy control function network element #A to request the acquisition of the first identifier. The security protection policy configuration of the first service is obtained by the direct communication discovery name management function network element #A from the policy control function network element #A. Specifically, the meaning of multiple security protection policies and the meaning of different security protection policy values ​​can be referred to the description in S410 above, which will not be elaborated here for the sake of brevity.

[0400] Method 2 The direct communication discovery name management function network element #A determines the first identifier based on the security protection policy configuration and instruction information #2 of the first service.

[0401] Among them, the security protection policy configuration and instruction information #2 of the first service is obtained by the direct communication discovery name management function network element #A from the policy control function network element #A.

[0402] For example, by default, policy control function network element #A sends indication information #2 to direct communication discovery name management function network element #A. For instance, when policy control function network element #A sends the security protection policy configuration for the first service to direct communication discovery name management function network element #A, it sends indication information #2 to direct communication discovery name management function network element #A by default.

[0403] Optionally, method 500 further includes: the direct communication discovery name management function network element #A sending a request message #1 to the policy control function network element #A, the request message #1 being used to request the acquisition of indication information #2. Accordingly, after receiving the request message #1, the policy control function network element #A sends the indication information #2 to the direct communication discovery name management function network element #A.

[0404] Optionally, after receiving request message #1, policy control function network element #A sends request message #1 to application function network element #A, whereby request message #1 is used to request instruction information #2. Further, after receiving instruction information #2 from application function network element #A, policy control function network element #A sends instruction information #2 to direct communication discovery name management function network element #A.

[0405] Optionally, when the direct communication discovery name management function network element #A determines that the security protection policy configuration of the first service includes multiple security protection policies with different values, it sends a request message #1 to the policy control function network element #A to request instruction information #2. The security protection policy configuration of the first service is obtained by the direct communication discovery name management function network element #A from the policy control function network element #A. Specifically, the meaning of multiple security protection policies and the meaning of different values ​​of multiple security protection policies can be referred to the description in S410 above, which will not be elaborated here for the sake of brevity.

[0406] After obtaining instruction information #2, the direct communication discovery name management function network element #A determines the first identifier based on the security protection policy configuration of the first service and instruction information #2. Specifically, the method by which the direct communication discovery name management function network element #A determines the first identifier can be referred to in methods one to five of S440 above, and will not be described in detail here for the sake of brevity.

[0407] Method 3 The direct communication discovery name management function network element #A obtains the first identifier from the direct communication discovery name management function network element #B. The direct communication discovery name management function network element #B provides services to terminal device #B. Terminal device #B is either the first terminal device or the second terminal device in method 300 above, and terminal device #B is different from terminal device #A. For example, terminal device #A is the first terminal device in method 300 above, and terminal device #B is the second terminal device in method 300 above. Or, for another example, terminal device #A is the second terminal device in method 300 above, and terminal device #B is the first terminal device in method 300 above.

[0408] Specifically, if the direct communication discovery name management function network element #A and the direct communication discovery name management function network element #B are not in the same PLMN, then the direct communication discovery name management function network element #A can obtain the first identifier from the direct communication discovery name management function network element #B.

[0409] For example, when the direct communication discovery name management function network element #A obtains the service discovery parameters of the first service from the direct communication discovery name management function network element #B, it obtains the first identifier from the direct communication discovery name management function network element. Specifically, the direct communication discovery name management function network element #A sends a request message #3 (an example of a second request message) to the direct communication discovery name management function network element #B. Request message #3 is used to request the service discovery parameters of the first service, or, request message #3 is used to request the service discovery parameters and the first identifier of the first service. Further, after receiving request message #3, the direct communication discovery name management function network element #B sends a second message to the direct communication discovery name management function network element #A. The second message includes the service discovery parameters and the first identifier of the first service.

[0410] For example, the service discovery parameter mentioned above is the service discovery code.

[0411] Optionally, the service discovery parameters and the first identifier sent by the direct communication discovery name management function network element #B have a corresponding relationship. This correspondence can take the form that the first identifier is carried within the service discovery parameter, or it can be a mapping relationship of [service discovery parameter, first identifier]. The correspondence between the service discovery parameters and the first identifier indicates that the service discovery parameter can be indexed based on the first identifier, and vice versa.

[0412] Optionally, the request message #3 sent by the direct communication discovery name management function network element #A includes a security protection policy #A, which is the security protection policy used by the terminal device #A in the first service. Correspondingly, after receiving the request message #3, the direct service discovery name management function network element #B determines whether security protection policy #A matches security protection policy #B, which is the security protection policy used by the terminal device #B in the first service.

[0413] Security protection policy #A and security protection policy #B can match in the following ways: the value of security protection policy #A is REQUIRED, and the value of security protection policy #B is not NOT NEEDED; or, the value of security protection policy #A is NOT NEEDED, and the value of security protection policy #B will not be REQUIRED; or, the values ​​of both security protection policy #A and security protection policy #B are PREFERRED; or, the value of security protection policy #B is REQUIRED, and the value of security protection policy #A is not NOT NEEDED; or, the value of security protection policy #B is NOT NEEDED, and the value of security protection policy #A will not be REQUIRED.

[0414] Security protection policy #A and security protection policy #B may be mismatched if: security protection policy #A is set to NOTNEEDED and security protection policy #B is set to REQUIRED; or, security protection policy #A is set to REQUIRED and security protection policy #B is set to NOT NEEDED.

[0415] If security protection policy #A matches security protection policy #B, then the direct communication discovery name management function network element #B does not send the first identifier to the direct communication discovery name management function network element #A; or, the second message sent by the direct communication discovery name management function network element #B to the direct communication discovery name management function network element #A includes the first identifier and indication information #3 (an example of third indication information); or, the second message includes the first identifier, service discovery parameters, and indication information #3. Indication information #3 is used to indicate that security protection policy #A matches security protection policy #B.

[0416] If security protection policy #A and security protection policy #B do not match, the second message sent by the direct communication discovery name management function network element #B to the direct communication discovery name management network element #A includes the first identifier, or the second message includes the first identifier and service discovery parameters, or the second message includes the first identifier and indication information #3, or the second message includes the first identifier, service discovery parameters, and indication information #3. Indication information #3 is used to indicate that security protection policy #A and security protection policy #B do not match.

[0417] Specifically, security protection policy #A is determined by the direct communication discovery name management function network element #A based on the location information of terminal device #A. That is, based on the location information of terminal device #A, the direct communication discovery name management function network element #A can determine security protection policy #A from the security protection policy configuration of the first service. For example, the location information of terminal device #A is sent by terminal device #A to the direct communication discovery name management function network element #A. For instance, terminal device #A sends its location information in a discovery request message to the direct communication discovery name management function network element #A, which is used to request service discovery parameters. Alternatively, the location information of terminal device #A is obtained by the gateway mobile location center (GMLC) using location services (LCS) triggered by the direct communication discovery name management function network element #A. Or, the location information of terminal device #A is obtained by the direct communication discovery name management function network element #A from the access and mobility management function network element #A, where the access and mobility management function network element #A is a network element serving terminal device #A.

[0418] Similarly, the Direct Communication Discovery Name Management Function (DCM) network element #B can obtain the location information of terminal device #B from terminal device #B. Alternatively, DCM triggers GMLC to use LCS to obtain the location information of terminal device #B. Or, the location information of terminal device #B is obtained by DCM from Access and Mobility Management Function (AMM) network element #B, where AMM is a network element serving terminal device #B. Further, based on the location information of terminal device #B, DCM can determine security protection policy #B from the security protection policy configuration of the first service.

[0419] Optionally, prior to S510, method 500 further includes: the direct communication discovery name management function network element #A determining whether security protection policy #A matches security protection policy #B. If security protection policy #A does not match security protection policy #B, then the direct communication discovery name management function network element #A obtains the first identifier using methods one to three in S510. If security protection policy #A matches security protection policy #B, then the direct communication discovery name management function network element #A does not obtain the first identifier.

[0420] For example, the direct communication discovery name management function network element #A determines whether security protection policy #A matches security protection policy #B in the following two ways: Method 1: Direct communication discovery name management function network element #A sends security protection policy #A to direct communication discovery name management function network element #B. Direct communication discovery name management function network element #A receives indication information #3 from direct communication discovery name management function network element #B. Indication information #3 indicates whether security protection policy #A matches security protection policy #B. Further, direct communication discovery name management function network element #A determines whether security protection policy #A matches security protection policy #B based on indication information #3. If indication information #3 indicates that security protection policy #A matches security protection policy #B, then direct communication discovery name management function network element #A determines that security protection policy #A matches security protection policy #B; if indication information #3 indicates that security protection policy #A does not match security protection policy #B, then direct communication discovery name management function network element #A determines that security protection policy #A does not match security protection policy #B.

[0421] Alternatively, if the direct communication discovery name management function network element #B determines that security protection policy #A matches security protection policy #B, it will not send indication information #3 to the direct communication discovery name management function network element #A. If the direct communication discovery name management function network element #B determines that security protection policy #A does not match security protection policy #B, it will send indication information #3 to the direct communication discovery name management function network element #A. Indication information #3 is used to indicate that security protection policy #A does not match security protection policy #B. Further, after receiving indication information #3, the direct communication discovery name management function network element #B determines that security protection policy #A does not match security protection policy #B.

[0422] Method 2: The network element #A, which is responsible for the direct communication discovery name management function, receives the security protection policy #B from the network element #B. The network element #A then determines whether the security protection policy #A matches the security protection policy #B.

[0423] In S520, the network element #A, which performs the direct communication discovery name management function, sends the first identifier. Correspondingly, in S520, the terminal device #A receives the first identifier.

[0424] For example, the network element #A, which is responsible for the direct communication discovery name management function, sends the first identifier to the terminal device #A in the direct communication discovery message.

[0425] Optionally, after obtaining the first identifier, the direct communication discovery name management function network element #A associates the first identifier with the service discovery parameters of the first service, and sends the first identifier and the service discovery parameters to the terminal device #A. It can be understood that after the direct communication discovery name management function network element #A associates the first identifier with the service discovery parameters, the first identifier and the service discovery parameters have a corresponding relationship.

[0426] Optionally, the direct communication discovery name management function network element #A can associate the first identifier with all service discovery parameters, or it can associate the first identifier with some service discovery parameters. This application embodiment does not limit this.

[0427] Optionally, prior to S520, method 500 further includes: the direct communication discovery name management function network element #A determining whether security protection policy #A matches security protection policy #B. If security protection policy #A does not match security protection policy #B, then the direct communication discovery name management function network element #A sends a first identifier to the terminal device #A. If security protection policy #A matches security protection policy #B, then the direct communication discovery name management function network element #A does not send the first identifier to the terminal device #A.

[0428] In this embodiment, after the direct communication discovery name management function network element obtains the first identifier, it sends the first identifier to the terminal device. This helps the terminal device modify the security protection policy according to the first identifier, thereby avoiding the failure of the first service connection establishment due to the mismatch of the security protection policies of the two terminal devices.

[0429] The following is combined with Figure 6 and Figure 7 This application describes the method for determining the activation mode of security protection provided in its embodiments.

[0430] It should be noted that in the following embodiments, the first terminal device is A-UE, the second terminal device is M-UE, the first service is ProSe service, and the connection of the first service is PC5 unicast connection. Furthermore, in the following embodiments, A-PCF and A-5G DDNMF provide services to A-UE, and M-PCF and M-5G DDNMF provide services to M-UE.

[0431] Figure 6 A schematic flowchart illustrating the method for determining the activation mode of security protection provided in an embodiment of this application is shown. Figure 6 As shown, method 600 may include steps S601 to S609, each of which is described in detail below.

[0432] S601, AF determines that the multiple PC5 unicast security protection policies included in ProSe service security protection policy configuration #1 have different values.

[0433] Specifically, AF determines the security protection policy configuration #1 for the ProSe service based on application requirements. This configuration includes multiple PC5 unicast security protection policies. These policies encompass control plane and / or user plane security protection policies for ProSe service PC5 unicast connections in different geographical locations. It should be noted that these security protection policies include confidentiality protection policies and / or integrity protection policies. For example, the control plane security protection policies include control plane confidentiality protection policies and / or control plane integrity protection policies, and the user plane security protection policies include user plane confidentiality protection policies and / or user plane integrity protection policies.

[0434] For more details on the security protection policy configuration #1 for the ProSe service, please refer to the description of the security protection policy configuration #1 for the first service in S410 above. For more details on the meaning of different values ​​for multiple PC5 unicast security protection policies, please refer to the description of the meaning of different values ​​for multiple security protection policies in S410 above.

[0435] Furthermore, if the AF determines that the values ​​of the multiple PC5 unicast security protection policies included in the ProSe service security protection policy configuration #1 are different, the AF generates indication information #2. Indication information #2 is used to indicate that the security protection policy of the ProSe service can be forcibly modified during the establishment of a PC5 unicast connection. Alternatively, indication information #2 is used to indicate that all terminal devices using the ProSe service use the same security protection policy.

[0436] Optionally, AF can generate indication information #2 by default. That is, AF will generate indication information #2 regardless of whether the values ​​of the multiple PC5 unicast security protection policies are the same. Furthermore, AF does not need to check whether the values ​​of the multiple PC5 unicast security protection policies are the same before generating indication information #2.

[0437] Optionally, after receiving request message #1 from A-PCF / M-PCF, AF generates indication information #2 based on request message #1. Request message #1 is used to request indication information #2. For example, request message #1 is sent by A-PCF / M-PCF to AF via NEF. Another example is that request message #1 is sent directly by A-PCF / M-PCF to AF.

[0438] S602a, AF sends the security protection policy configuration #1 for the ProSe service to A-PCF.

[0439] A-PCF determines the security protection policy configuration of the ProSe service based on the security protection policy configuration #1 of the ProSe service obtained from AF. The security protection policy configuration of the ProSe service includes the values ​​of multiple PC5 unicast security protection policies.

[0440] S602b, AF sends the security protection policy configuration #1 for the ProSe service to M-PCF.

[0441] M-PCF determines the security protection policy configuration of the ProSe service based on the security protection policy configuration #1 of the ProSe service obtained from AF. The security protection policy configuration of the ProSe service includes the values ​​of multiple PC5 unicast security protection policies.

[0442] Optionally, when the AF sends the security protection policy configuration #1 for the ProSe service to the A-PCF / M-PCF, it also sends indication information #2 to the A-PCF / M-PCF. That is, the AF carries the security protection policy configuration #1 and indication information #2 for the ProSe service in the same signaling message and sends them to the A-PCF / M-PCF.

[0443] Optionally, after receiving request message #1, the AF sends instruction message #2 to the A-PCF / M-PCF.

[0444] Optionally, when A-PCF / M-PCF determines that the values ​​of multiple PC5 unicast security protection policies are different, it sends a request message #1 to AF.

[0445] S603, A-PCF / M-PCF determines the first identifier.

[0446] Specifically, the method by which A-PCF / M-PCF determines the first identifier can be referred to in the description in S440 above, and will not be elaborated here for the sake of brevity.

[0447] S604a, A-PCF sends multiple PC5 unicast security protection policies and the first identifier to A-UE.

[0448] Specifically, the A-PCF can instruct the AMF to trigger the UE configuration update procedure to send multiple PC5 unicast security protection policies and first identifiers to the A-UE. That is, the A-PCF sends multiple PC5 unicast security protection policies and first identifiers to the AMF, and the AMF then sends multiple PC5 unicast security protection policies and first identifiers to the A-UE.

[0449] S604b, M-PCF sends multiple PC5 unicast security protection policies and the first identifier to M-UE.

[0450] Specifically, the M-PCF can instruct the AMF to trigger the UE configuration update process to send multiple PC5 unicast security protection policies and first identifiers to the M-UE. That is, the M-PCF sends multiple PC5 unicast security protection policies and first identifiers to the AMF, and the AMF then sends multiple PC5 unicast security protection policies and first identifiers to the M-UE.

[0451] S605, A-UE and M-UE perform the ProSe service discovery process.

[0452] Specifically, A-UE and M-UE can execute either the model A discovery process or the model B discovery process. This application embodiment does not limit this.

[0453] Optionally, A-UE carries a first identifier in the message of the model A discovery process.

[0454] Optionally, A-UE and / or M-UE carry a first identifier in the message of the model B discovery process.

[0455] S606, M-UE sends a DCR / DSM completion message to A-UE.

[0456] The DCR / DSM completion message includes Security Protection Policy #2, which is the security protection policy used by the M-UE in the PC5 unicast connection of the ProSe service. Security Protection Policy #2 is determined by the M-UE from multiple PC5 unicast security protection policies based on its geographical location. Security Protection Policy #2 includes Control Plane Security Protection Policy #2 and / or User Plane Security Protection Policy #2. Control Plane Security Protection Policy #2 includes Control Plane Confidentiality Protection Policy and / or Control Plane Integrity Protection Policy. User Plane Security Protection Policy #2 includes User Plane Confidentiality Protection Policy and / or User Plane Integrity Protection Policy.

[0457] For example, the M-UE sends a DCR message to the A-UE, the DCR message including control plane security protection policy #2.

[0458] For example, M-UE sends a DCR message to A-UE, which includes control plane security protection policy #2 and user plane security protection policy #2.

[0459] For example, M-UE sends a DSM completion message to A-UE, which includes User Plane Security Protection Policy #2.

[0460] For example, M-UE sends a DSM completion message to A-UE, which includes control plane security protection policy #2 and user plane security protection policy #2.

[0461] Optionally, the M-UE carries the first identifier in the DCR / DSM completion message.

[0462] S607, A-UE determines the security protection activation mode of PC5 unicast connection based on the first identifier.

[0463] Specifically, the method for A-UE to determine the security protection enabling mode of PC5 unicast connection can be found in S320 above.

[0464] Optionally, if the DCR / DSM completes the message carrying the first identifier, the A-UE determines the security protection activation mode of the PC5 unicast connection based on the first identifier.

[0465] Optionally, if the DCR / DSM completes the message carrying the first identifier, the A-UE may not need to check whether the security protection policy #2 matches the local security protection policy, thereby saving the processing resources of the terminal device.

[0466] S608, A-UE sends a DSM command / DCA message to M-UE. The DSM command / DCA message includes the security protection activation method for the PC5 unicast connection.

[0467] Security protection for PC5 unicast connections includes control plane security protection and / or user plane security protection. Control plane security protection includes control plane confidentiality protection and / or control plane integrity protection. User plane security protection includes user plane confidentiality protection and / or user plane integrity protection.

[0468] For example, if A-UE receives a DCR message in S606, and the DCR message includes control plane security protection policy #2, then in S607, A-UE determines the control plane security protection enabling mode for the PC5 unicast connection. Further, in S608, A-UE sends a DSM command message to M-UE, the DSM command message including the control plane security protection enabling mode.

[0469] For example, if in S606, M-UE sends a DCR message to A-UE, and the DCR message includes control plane security protection policy #2 and user plane security protection policy #2, then in S607, A-UE determines the control plane security protection activation mode and user plane security protection activation mode for the PC5 unicast connection. Further, in S608, A-UE sends a DSM command message to M-UE, and the DSM command message includes the control plane security protection activation mode and user plane security protection activation mode.

[0470] For example, if in S606, M-UE sends a DSM completion message to A-UE, and the DSM completion message includes user plane security protection policy #2, then in S607, A-UE determines the user plane security protection enabling mode for the PC5 unicast connection. Further, in S608, A-UE sends a DCA message to M-UE, and the DCA message includes the user plane security protection enabling mode.

[0471] For example, if in S606, M-UE sends a DSM completion message to A-UE, and the DSM completion message includes control plane security protection policy #2 and user plane security protection policy #2, then in S607, A-UE determines the control plane security protection activation mode and user plane security protection activation mode for the PC5 unicast connection. Further, in S608, A-UE sends a DCA message to M-UE, and the DCA message includes the control plane security protection activation mode and user plane security protection activation mode.

[0472] Optionally, the A-UE carries the first identifier in the DSM command / DCA message.

[0473] S609, M-UE enables / disables security protection.

[0474] For example, if the M-UE receives a DSM command / DCA message that includes the PC5 unicast connection security protection activation mode, the M-UE determines whether to enable or disable PC5 unicast connection security protection based on this mode. If the PC5 unicast connection security protection activation mode is enabled, the M-UE determines to enable PC5 unicast connection security protection; if the PC5 unicast connection security protection activation mode is disabled, the M-UE determines to disable PC5 unicast connection security protection.

[0475] Optionally, M-UE does not check whether the security protection activation method matches security protection policy #2.

[0476] Optionally, if the DSM command / DCA message carries the first identifier, the M-UE does not check whether the security protection activation method matches security protection policy #2.

[0477] Figure 7 A schematic flowchart illustrating the method for determining the activation mode of security protection provided in an embodiment of this application is shown. Figure 7 As shown, method 700 may include steps S701 to S711, each of which is described in detail below.

[0478] S701, AF determines that the multiple PC5 unicast security protection policies included in ProSe service security protection policy configuration #1 have different values.

[0479] and Figure 6 The same applies to S601, so for the sake of brevity, it will not be described in detail here.

[0480] S702a, AF sends the security protection policy configuration #1 for ProSe service to A-PCF.

[0481] A-PCF determines the security protection policy configuration of the ProSe service based on the security protection policy configuration #1 of the ProSe service obtained from AF. The security protection policy configuration of the ProSe service includes the values ​​of multiple PC5 unicast security protection policies.

[0482] S702b, AF sends the security protection policy configuration #1 for the ProSe service to M-PCF.

[0483] M-PCF determines the security protection policy configuration of the ProSe service based on the security protection policy configuration #1 of the ProSe service obtained from AF. The security protection policy configuration of the ProSe service includes the values ​​of multiple PC5 unicast security protection policies.

[0484] Optionally, when the AF sends the security protection policy configuration #1 for the ProSe service to the A-PCF / M-PCF, it also sends indication information #2 to the A-PCF / M-PCF. That is, the AF carries the security protection policy configuration #1 and indication information #2 for the ProSe service in the same signaling message and sends them to the A-PCF / M-PCF.

[0485] Optionally, after receiving request message #1, the AF sends instruction message #2 to the A-PCF / M-PCF.

[0486] Optionally, when A-PCF / M-PCF determines that the values ​​of multiple PC5 unicast security protection policies are different, it sends a request message #1 to AF.

[0487] Optionally, after receiving request message #1 from A-5G DDNMF, A-PCF sends request message #1 to AF.

[0488] S703a, A-PCF sends multiple PC5 unicast security protection policies to A-UE.

[0489] Optionally, before sending multiple PC5 unicast security protection policies to A-UE, A-PCF may determine a first identifier. If A-PCF determines the first identifier, then A-PCF sends the multiple PC5 unicast security protection policies and the first identifier to A-UE.

[0490] Specifically, the method by which A-PCF determines the first identifier can be referred to in the description in S440 above, and will not be elaborated here for the sake of brevity.

[0491] S703b, M-PCF sends multiple PC5 unicast security protection policies to M-UE.

[0492] Optionally, before sending multiple PC5 unicast security protection policies to the M-UE, the M-PCF may determine a first identifier. If the M-PCF determines the first identifier, then the M-PCF sends the multiple PC5 unicast security protection policies and the first identifier to the M-UE.

[0493] Specifically, the method by which M-PCF determines the first identifier can be referred to in the description in S440 above, and will not be elaborated here for the sake of brevity.

[0494] S704a, A-UE sends a discovery request message to A-5G DDNMF.

[0495] The discovery request message is used to request service discovery parameters for the ProSe service. The discovery request message includes the application identifier of the ProSe service to identify the ProSe service.

[0496] Optionally, the discovery request message includes the location information of A-UE.

[0497] S704b, M-UE sends a discovery request message to M-5G DDNMF.

[0498] The discovery request message is used to request service discovery parameters for the ProSe service. The discovery request message includes the application identifier of the ProSe service to identify the ProSe service.

[0499] Optionally, the discovery request message includes the location information of the M-UE.

[0500] S705, A-5G DDNMF / M-5G DDNMF obtains the first identifier.

[0501] Specifically, the method by which A-5G DDNMF / M-5G DDNMF determines the first identifier can be referred to the description in S510 above, and will not be elaborated here for the sake of brevity.

[0502] It is understood that in S705, A-5G DDNMF / M-5G DDNMF also determines service discovery parameters, which include ProSe code. ProSe code includes one or more of the following: ProSe application code, ProSe discovery code, ProSe query code, or ProSe response code.

[0503] Optionally, after the A-5G DDNMF / M-5G DDNMF obtains the first identifier, it can associate the first identifier with the ProSe code. It can be understood that after the A-5G DDNMF / M-5G DDNMF associates the first identifier with the ProSe code, the first identifier and the ProSe code have a corresponding relationship.

[0504] It should be noted that if the A-5G DDNMF and M-5G DDNMF are not in the same PLMN, the M-5G DDNMF will request the ProSe code from the A-5G DDNMF. Optionally, the M-5G DDNMF may also request the first identifier from the A-5G DDNMF.

[0505] If A-5G DDNMF and M-5G DDNMF are in the same PLMN, then M-5G DDNMF and A-5G DDNMF are the same network element, and M-5G DDNMF can obtain the ProSe code locally.

[0506] Optionally, the M-5G DDNMF can obtain a first identifier if it determines that security protection policy #1 and security protection policy #2 do not match. Security protection policy #1 is the security protection policy used by the A-UE in the PC5 unicast connection served by ProSe. Security protection policy #1 is determined by the A-5G DDNMF based on the A-UE's location information. The A-UE's location information can be received by the A-5G DDNMF from the A-UE; or, the A-UE's location information can be obtained by the A-5G DDNMF triggering GMLC to use LCS; or, the A-UE's location information can be obtained by the A-5G DDNMF from the A-AMF, where the A-AMF is the network element serving the A-UE. The A-5G DDNMF can directly obtain the A-UE's location information from the A-AMF, or the A-PCF can obtain the A-UE's location information from the A-AMF and then send it to the A-5G DDNMF. Security protection policy #2 is the security protection policy used by the M-UE in the PC5 unicast connection served by ProSe. Security protection strategy #2 is determined by the M-5G DDNMF based on the location information of the M-UE. The location information of the M-UE can be received by the M-5G DDNMF from the M-UE; or, the location information of the M-UE can be obtained by the M-5G DDNMF triggering GMLC to use LCS; or, the location information of the M-UE can be obtained by the M-5G DDNMF from the M-AMF, where the M-AMF is a network element serving the A-UE. The M-5G DDNMF can directly obtain the location information of the M-UE from the M-AMF, or the M-PCF can obtain the location information of the A-UE from the M-AMF and then send it to the M-5G DDNMF.

[0507] M-5G DDNMF can determine the following ways in which security protection policy #1 and security protection policy #2 are mismatched: Method 1: The M-5G DDNMF sends a request message #3 to the A-5G DDNMF. Request message #3 is used to request the service discovery parameters for the ProSe service. Request message #3 includes security protection policy #2. After determining that security protection policy #1 and security protection policy #2 do not match, the A-5G DDNMF sends the service discovery parameters and a first identifier to the M-5G DDNMF. Alternatively, the A-5G DDNMF sends the service discovery parameters, the first identifier, and indication information #3 to the M-5G DDNMF. Indication information #3 is used to indicate that security protection policy #1 and security protection policy #2 do not match.

[0508] Optionally, the ProSe code in the service discovery parameters corresponds to the first identifier.

[0509] Method 2: The M-5G DDNMF sends a request message #2 to the A-5G DDNMF, which requests a first identifier. The request message #3 includes security protection policy #2. After determining that security protection policy #1 and security protection policy #2 do not match, the A-5G DDNMF sends the first identifier to the M-5G DDNMF. Alternatively, the A-5G DDNMF sends the first identifier and indication information #3 to the M-5G DDNMF, where the indication information #3 indicates that security protection policy #1 and security protection policy #2 do not match.

[0510] Method 3: The M-5G DDNMG sends security protection policy #1 to the A-5G DDNMF; after the A-5G DDNMF determines that security protection policy #1 does not match security protection policy #2, it sends indication information #3 to the M-5G DDNMG. Indication information #3 is used to indicate that security protection policy #1 does not match security protection policy #2.

[0511] After receiving instruction message #3, the M-5G DDNMF uses method one and method two in S510 to obtain the first identifier.

[0512] Method 4: The A-5G DDNMG sends security protection policy #1 to the M-5G DDNMF; after the M-5G DDNMF determines that security protection policy #1 does not match security protection policy #2, it uses methods one to three in S510 to obtain the first identifier.

[0513] In S706a, the A-5G DDNMF sends a discovery response message to the A-UE.

[0514] The discovery response message includes service discovery parameters and a first identifier. Optionally, the ProSecode in the service discovery parameters corresponds to the first identifier.

[0515] S706b, M-5G DDNMF sends a discovery response message to M-UE.

[0516] The discovery response message includes service discovery parameters. If the M-5G DDNMG obtains the first identifier, the discovery response message also includes the first identifier. Optionally, the ProSe code in the service discovery parameters corresponds to the first identifier.

[0517] S707, A-UE and M-UE perform the ProSe service discovery process.

[0518] Specifically, A-UE and M-UE can execute either the model A discovery process or the model B discovery process. This application embodiment does not limit this.

[0519] Optionally, if A-UE receives the ProSe code corresponding to the first identifier from A-5G DDNMF, and A-UE allows forced modification of the security protection policy, then A-UE carries the ProSe code corresponding to the first identifier in the discovery message during the discovery process. Correspondingly, if M-UE receives the ProSe code corresponding to the first identifier, then M-UE determines that A-UE allows forced modification of the security protection policy.

[0520] Optionally, if the M-UE receives the ProSe code corresponding to the first identifier from the M-5G DDNMF, and the M-UE allows forced modification of the security protection policy, then the M-UE carries the ProSe code corresponding to the first identifier in the discovery message during the discovery process. Correspondingly, if the A-UE receives the ProSe code corresponding to the first identifier, then the A-UE determines that the M-UE allows forced modification of the security protection policy.

[0521] S708, M-UE sends a DCR / DSM completion message to A-UE.

[0522] and Figure 6 The same applies to S606, so for the sake of brevity, it will not be described in detail here.

[0523] S709, A-UE determines the security protection activation mode of PC5 unicast connection based on the first identifier.

[0524] Specifically, the method for A-UE to determine the security protection enabling mode of PC5 unicast connection can be found in S320 above.

[0525] Optionally, if the DCR / DSM completes the message carrying the first identifier, the A-UE determines the security protection activation mode of the PC5 unicast connection based on the first identifier.

[0526] Optionally, if A-UE receives a ProSe code corresponding to the first identifier during the discovery process, A-UE determines the security protection activation mode for the PC5 unicast connection based on the first identifier.

[0527] Optionally, if the DCR / DSM completes the message carrying the first identifier, the A-UE may not need to check whether the security protection policy #2 matches the local security protection policy, thereby saving the processing resources of the terminal device.

[0528] S710, A-UE sends a DSM command / DCA message to M-UE. The DSM command / DCA message includes the security protection activation method for the PC5 unicast connection.

[0529] and Figure 6 The same as S608 in the previous version, so for the sake of brevity, it will not be described in detail here.

[0530] S711, M-UE: Enable / Disable security protection.

[0531] For example, if the M-UE receives a DSM command / DCA message that includes the PC5 unicast connection security protection activation mode, the M-UE determines whether to enable or disable PC5 unicast connection security protection based on this mode. If the PC5 unicast connection security protection activation mode is enabled, the M-UE determines to enable PC5 unicast connection security protection; if the PC5 unicast connection security protection activation mode is disabled, the M-UE determines to disable PC5 unicast connection security protection.

[0532] Optionally, M-UE does not check whether the security protection activation method matches security protection policy #2.

[0533] Optionally, if the DSM command / DCA message carries the first identifier, the M-UE does not check whether the security protection activation method matches the security protection policy #2, thereby saving the processing resources of the terminal device.

[0534] Optionally, during the discovery process, if the M-UE receives a ProSe code corresponding to the first identifier, the M-UE does not check whether the security protection activation method matches the security protection policy #2, thereby saving the processing resources of the terminal device.

[0535] The above, combined with Figures 3 to 7 The methods provided in the embodiments of this application are described in detail below. Figures 8 to 9 This application provides a detailed description of the communication device provided in its embodiments. It should be understood that the descriptions of the device embodiments correspond to the descriptions of the method embodiments; therefore, any content not described in detail here will be referred to the method embodiments above, and for the sake of brevity, will not be repeated here.

[0536] This application embodiment can divide the transmitting or receiving device into functional modules according to the above method examples. For example, each function can be divided into its own functional modules, or two or more functions can be integrated into one processing module. The integrated module can be implemented in hardware or as a software functional module. It should be noted that the module division in this application embodiment is illustrative and only represents one logical functional division; other division methods may be used in actual implementation. The following description uses the division of functional modules according to each function as an example. Figure 8 This is a schematic block diagram of a communication device 800 provided in an embodiment of this application. As shown in the figure, the communication device 800 may include a transceiver unit 810 and a processing unit 820.

[0537] In one possible design, the communication device 800 can be the first terminal device in the above method embodiment, or it can be a chip used to implement the functions of the first terminal device in the above method embodiment.

[0538] It should be understood that the communication device 800 may correspond to the first terminal device in methods 300 to 700 according to embodiments of this application, and the communication device 800 may include functions for performing... Figure 3 Method 300 Figure 4 Method 200 Figure 5 Method 500 Figure 6 Method 600 and Figure 7 The method 700 is a unit that executes the method in the first terminal device. Furthermore, each unit in the communication device 800 and the aforementioned other operations and / or functions are respectively for implementing... Figure 3 Method 300 Figure 4 Method 200 Figure 5 Method 500 Figure 6 Method 600 and Figure 7 The corresponding process of method 700 is described above. It should be understood that the specific process of each unit performing the above-mentioned corresponding steps has been described in detail in the above method embodiments, and will not be repeated here for the sake of brevity.

[0539] In another possible design, the communication device 800 can be the second terminal device in the above method embodiment, or it can be a chip used to implement the functions of the second terminal device in the above method embodiment.

[0540] It should be understood that the communication device 800 may correspond to the second terminal device in methods 300 to 700 according to embodiments of this application, and the communication device 800 may include tools for performing... Figure 3 Method 300 Figure 4 Method 200 Figure 5 Method 500 Figure 6 Method 600 and Figure 7 The second terminal device in method 700 is a unit that executes the method. Furthermore, each unit in the communication device 800 and the aforementioned other operations and / or functions are respectively for implementing... Figure 3 Method 300 Figure 4 Method 200 Figure 5 Method 500 Figure 6 Method 600 and Figure 7 The corresponding process of method 700 is described above. It should be understood that the specific process of each unit performing the above-mentioned corresponding steps has been described in detail in the above method embodiments, and will not be repeated here for the sake of brevity.

[0541] In another possible design, the communication device 800 can be the policy control function network element in the above method embodiment, or it can be a chip used to implement the function of the policy control function network element in the above method embodiment.

[0542] It should be understood that the communication device 800 may correspond to the policy control function network element in methods 400, 600 and 700 according to embodiments of this application, and the communication device 800 may include functions for... Figure 4 Method 400 Figure 6 Method 600 and Figure 7 The method 700 is a unit that executes the policy control function network element of the method. Furthermore, each unit in the communication device 800 and the aforementioned other operations and / or functions are respectively for implementing... Figure 4 Method 400 Figure 6 Method 600 and Figure 7 The corresponding process of method 700 is described above. It should be understood that the specific process of each unit performing the above-mentioned corresponding steps has been described in detail in the above method embodiments, and will not be repeated here for the sake of brevity.

[0543] In another possible design, the communication device 800 can be the direct communication discovery name management function network element in the above method embodiment, or it can be a chip used to implement the function of the direct communication discovery name management function network element in the above method embodiment.

[0544] It should be understood that the communication device 800 may correspond to the direct communication discovery name management function network element in methods 500 to 700 according to embodiments of this application, and the communication device 800 may include functions for... Figure 5 Method 500 Figure 6 Method 600 and Figure 7 The method 700 in the communication device 800 is a unit that executes the method of the direct communication discovery name management function network element. Furthermore, each unit in the communication device 800 and the other operations and / or functions described above are respectively for implementing... Figure 5 Method 500 Figure 6 Method 600 and Figure 7 The corresponding process of method 700 is described above. It should be understood that the specific process of each unit performing the above-mentioned corresponding steps has been described in detail in the above method embodiments, and will not be repeated here for the sake of brevity.

[0545] In another possible design, the communication device 800 can be an application function network element in the above method embodiment, or it can be a chip used to implement the function of the application function network element in the above method embodiment.

[0546] It should be understood that the communication device 800 may correspond to the application function network element in methods 400, 600 and 700 according to the embodiments of this application, and the communication device 800 may include functions for... Figure 4 Method 400 Figure 6 Method 600 and Figure 7 The application function network element in method 700 is a unit that executes the method. Furthermore, each unit in the communication device 800 and the aforementioned other operations and / or functions are respectively for implementing... Figure 4 Method 400 Figure 6 Method 600 and Figure 7 The corresponding process of method 700 is described above. It should be understood that the specific process of each unit performing the above-mentioned corresponding steps has been described in detail in the above method embodiments, and will not be repeated here for the sake of brevity.

[0547] It should also be understood that the transceiver unit 810 in the communication device 800 may correspond to Figure 9 The transceiver 920 in the communication device 900 shown in the figure, the processing unit 820 in the communication device 800 may correspond to Figure 9 The processor 910 in the communication device 900 shown in the figure.

[0548] It should also be understood that when the communication device 800 is a chip, the chip includes a transceiver unit and a processing unit. The transceiver unit can be an input / output circuit or a communication interface; the processing unit can be a processor, microprocessor, or integrated circuit integrated on the chip.

[0549] The transceiver unit 810 is used to implement the signal transmission and reception operations of the communication device 800, and the processing unit 820 is used to implement the signal processing operations of the communication device 800.

[0550] Optionally, the communication device 800 further includes a storage unit 830 for storing instructions.

[0551] Figure 9 This is a schematic block diagram of a communication device 900 provided in an embodiment of this application. As shown, the communication device 900 includes at least one processor 910 and a transceiver 920. The processor 910 is coupled to a memory and is used to execute instructions stored in the memory to control the transceiver 920 to transmit and / or receive signals. Optionally, the communication device 900 also includes a memory 930 for storing instructions.

[0552] It should be understood that the processor 910 and memory 930 described above can be combined into a single processing device, with the processor 910 executing the program code stored in the memory 930 to achieve the aforementioned functions. In specific implementations, the memory 930 can be integrated into the processor 910 or independent of the processor 910.

[0553] It should also be understood that transceiver 920 may include a receiver (or receiver unit) and a transmitter (or transmitter unit). Transceiver 920 may further include antennas, and the number of antennas may be one or more. Transceiver 920 may have a communication interface or interface circuitry.

[0554] When the communication device 900 is a chip, the chip includes a transceiver unit and a processing unit. The transceiver unit can be an input / output circuit or a communication interface; the processing unit can be a processor, microprocessor, or integrated circuit integrated on the chip. This application also provides a processing apparatus, including a processor and an interface. The processor can be used to execute the methods described in the above method embodiments.

[0555] It should be understood that the aforementioned processing device can be a chip. For example, the processing device can be a field-programmable gate array (FPGA), an application-specific integrated circuit (ASIC), a system-on-chip (SoC), a central processor unit (CPU), a network processor (NP), a digital signal processor (DSP), a microcontroller unit (MCU), a programmable logic device (PLD), or other integrated chips.

[0556] In implementation, each step of the above method can be completed by integrated logic circuits in the processor's hardware or by instructions in software. The steps of the method disclosed in the embodiments of this application can be directly implemented by a hardware processor, or by a combination of hardware and software modules in the processor. The software modules can reside in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. This storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method. To avoid repetition, detailed descriptions are omitted here.

[0557] It should be noted that the processor in the embodiments of this application can be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method embodiments can be completed by the integrated logic circuitry in the processor's hardware or by instructions in software form. The processor can be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this application can be directly embodied as execution by a hardware decoding processor, or as a combination of hardware and software modules in the decoding processor. The software modules can be located in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. This storage medium is located in memory, and the processor reads the information in the memory and, in conjunction with its hardware, completes the steps of the above methods.

[0558] It is understood that the memory in the embodiments of this application can be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous linked dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM). It should be noted that the memory used in the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.

[0559] According to the method provided in the embodiments of this application, this application also provides a computer program product, which includes: computer program code, which, when run on a computer, causes the computer to execute... Figures 3 to 7 The method of any one of the embodiments shown.

[0560] According to the method provided in the embodiments of this application, this application also provides a computer-readable medium storing program code, which, when run on a computer, causes the computer to perform... Figures 3 to 7 The method of any one of the embodiments shown.

[0561] According to the method provided in the embodiments of this application, this application also provides a system, which includes the aforementioned first terminal device and second terminal device.

[0562] According to the method provided in the embodiments of this application, this application also provides a system, which includes the aforementioned first terminal device, second terminal device, policy control function network element, direct communication discovery name management function network element, and application function network element.

[0563] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer instructions. When the computer instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device such as a server or data center that integrates one or more available media. The available media may be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., high-density digital video discs (DVDs)), or semiconductor media (e.g., solid-state disks (SSDs)).

[0564] In the above-described device embodiments, the network-side devices correspond to the terminal devices and the network-side devices or terminal devices in the method embodiments. Corresponding modules or units execute corresponding steps. For example, the communication unit (transceiver) executes the receiving or sending steps in the method embodiments, while other steps besides sending and receiving can be executed by the processing unit (processor). The specific functions of each unit can be found in the corresponding method embodiments. There can be one or more processors.

[0565] The terms “component,” “module,” “system,” etc., used in this specification are used to refer to computer-related entities, hardware, firmware, combinations of hardware and software, software, or software in execution. For example, a component can be, but is not limited to, a process running on a processor, a processor, an object, an executable file, an execution thread, a program, and / or a computer. As illustrated, applications running on computing devices and computing devices can both be components. One or more components may reside in a process and / or an execution thread, and components may be located on a single computer and / or distributed among two or more computers. Furthermore, these components can be executed from various computer-readable media on which various data structures are stored. Components can communicate, for example, via local and / or remote processes based on signals having one or more data packets (e.g., data from two components interacting with another component between a local system, a distributed system, and / or a network, such as the Internet interacting with other systems via signals).

[0566] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0567] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0568] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0569] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0570] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0571] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0572] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A communication method, characterized in that, include: Receive a first discovery request sent by a first terminal, wherein the first discovery request is used to request the service discovery parameters of a first service; Determine the service discovery parameters assigned to the first service and obtain the security protection policy corresponding to the first service; Associate the service discovery parameters with the security protection policy; A discovery response is sent to the first terminal, the discovery response including the service discovery parameters and the security protection policy, wherein the security protection policy is used by the first terminal to establish a secure connection of the first service with the second terminal.

2. The method according to claim 1, characterized in that, The step of obtaining the security protection policy corresponding to the first service includes: Receive the security protection policy corresponding to the first service from the policy control function network element.

3. The method according to claim 1, characterized in that, The method further includes: Receive a request message from a second network element serving the second terminal, the request message being used to request service discovery parameters from the first service; A response message is returned to the second network element, the response message containing the service discovery parameters and the security protection policy.

4. The method according to any one of claims 1 to 3, characterized in that, The first service is the Prose service for neighboring businesses, and the service discovery parameter of the first service is the Prose code for neighboring businesses.

5. The method according to claim 4, characterized in that, The Prose code includes one or more of the following: ProSe application code, ProSe discovery code, ProSe query code, or ProSe response code.

6. A communication method, characterized in that, include: The first terminal receives multiple security protection policies from the policy control network element, the multiple security protection policies including security protection policies for the first service in different geographical locations; The first terminal sends a first discovery request to the first network element, the first discovery request being used to request the service discovery parameters of the first service; The first terminal receives a first discovery response from the first network element, the first discovery response including the service discovery parameters and the security protection policy corresponding to the first service; The first terminal establishes a secure connection with the second terminal for the first service based on the security protection policy corresponding to the first service in the first discovery response.

7. The method according to claim 6, characterized in that, The method further includes: The first terminal sends a second discovery request to the first network element, the second discovery request being used to request the service discovery parameters; The first terminal receives a second discovery response from the first network element, the second discovery response including the service discovery parameters; The first terminal establishes a secure connection for the first service with the second terminal according to one of the multiple security protection policies.

8. The method according to claim 6 or 7, characterized in that, The security protection policy corresponding to the first service in the first discovery response has a corresponding relationship with the service discovery parameters.

9. The method according to any one of claims 6 to 8, characterized in that, The first terminal establishes a secure connection with the second terminal for the first service based on the security protection policy corresponding to the first service in the first discovery response, including: The first terminal receives a first message from the second terminal, the first message including the security protection policy corresponding to the first service; The first terminal determines the security protection to enable the secure connection based on the security protection policy corresponding to the first service.

10. The method according to any one of claims 6 to 9, characterized in that, The first service is the Prose service for neighboring businesses, and the service discovery parameter of the first service is the Prose code for neighboring businesses.

11. The method according to claim 10, characterized in that, The Prose code includes one or more of the following: ProSe application code, ProSe discovery code, ProSe query code, or ProSe response code.

12. A communication device, characterized in that, include: The memory is used to store computer programs; A transceiver, the transceiver being used to perform the sending and receiving steps; A processor for calling and running the computer program from the memory, causing the communication device to perform the method of any one of claims 1 to 11.

13. A computer-readable storage medium, characterized in that, include: The computer-readable medium stores a computer program; when the computer program is run on a computer, it causes the computer to perform the method of any one of claims 1 to 11.