Security establishment method and related device

The method enables secure communication between UEs in D2D networks by selecting appropriate security mechanisms based on network coverage, addressing coverage limitations and resource wastage in existing methods.

JP2026512834APending Publication Date: 2026-04-21HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
HUAWEI TECH CO LTD
Filing Date
2024-03-21
Publication Date
2026-04-21

Smart Images

  • Figure 2026512834000001_ABST
    Figure 2026512834000001_ABST
Patent Text Reader

Abstract

A security establishment method and associated device are provided to select an appropriate security establishment mechanism for a communication device and thereby ensure communication security. In the method, a first communication device initiating a proximity service communication determines a target mechanism from a plurality of mechanisms, for example, according to a mechanism selection rule, and sends a request message requesting the receiver to establish security with the first communication device by using the target mechanism. A second communication device receiving the request message sends a first message to the first communication device based on its network coverage status to indicate whether it agrees to establish security with the first communication device by using the target mechanism. The second communication device may agree to use a security establishment mechanism without network assistance or with network assistance when it is within network coverage, or it may agree to use a security establishment mechanism without network assistance when it is not within network coverage. After negotiation between the first and second communication devices, the first and second communication devices may establish a secure connection by using a jointly supported security establishment mechanism.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] This application claims priority to Chinese Patent Application No. 202310313402.6, entitled “Security Establishment Method and Related Apparatus,” filed with the China National Intellectual Property Administration on 27 March 2023, which is incorporated herein by reference in its entirety.

[0002] This application relates to the field of wireless communications, and more particularly to a method for establishing security and related devices. [Background technology]

[0003] With the development of mobile communications, device-to-device (D2D) communication enables direct communication between user equipment (UEs). UEs can share spectral resources with other UEs within a cell under the control of the cell network to help improve the utilization of spectral resources. Proximity-based service (ProSe) communication is a type of D2D communication. User equipment with ProSe communication capabilities can communicate with each other via the PC5 interface.

[0004] When two UEs need to perform ProSe communication, if the peer UE is outside the signal coverage of the initiating UE or has a weak signal, a relay UE may be used to assist the communication. A relay UE may also be referred to as a UE-to-UE relay (U2U relay). In the following description, to distinguish it from the relay UE, the UE performing the ProSe communication will be referred to as the end UE.

[0005] Establishing security between the end UE and the U2U Relay is a crucial part of ensuring communication security. Therefore, it is expected that a mechanism can be provided that can be used for establishing security between the end UE and the U2U Relay. [Overview of the Initiative]

[0006] This application provides a security establishment method that can be used to establish security between an end UE and a U2U relay in order to guarantee communication security. [Means for solving the problem]

[0007] According to the first embodiment, a method for establishing security is provided. The method may be applied to a first communication device in ProSe communication. The first communication device may be a UE, a component configured within the UE (e.g., a chip, a chip system, or a processor), or a logic module, software, etc., capable of performing all or part of the functions of the first communication device.

[0008] For example, the method includes the steps of: determining a target mechanism from a plurality of mechanisms, wherein the plurality of target mechanisms include a security establishment mechanism with network assistance and a security establishment mechanism without network assistance; sending a request message, the request message being used to request a second communication device receiving the request message to establish security with a first communication device by using a target mechanism; and receiving a first message from the second communication device, the first message indicating whether it should agree to establish security with the first communication device by using a target mechanism.

[0009] The request message may indicate the target mechanism.

[0010] Based on the mechanism described above, the first communication device initiating ProSe communication may select a target mechanism from among several mechanisms, or it may negotiate with the second communication device receiving the request message by sending a request message indicating the target mechanism. For example, if the second communication device agrees to use the target mechanism, the first communication device may directly establish security with the second communication device by using the target mechanism, or if the second communication device does not agree to use the target mechanism, the first communication device may continue to select another mechanism as the target mechanism, send a request message, and negotiate with the second communication device. Thus, a mechanism supported by both the first and second communication devices can be determined to establish security. This facilitates the successful establishment of a secure connection.

[0011] Furthermore, multiple mechanisms include security establishment mechanisms with network assistance and security establishment mechanisms without network assistance, and different cases are considered. In one embodiment, the mechanism without network assistance is provided when the second communication device is not within network coverage, and as a result, the second communication device, which is not within network coverage, can also establish a secure connection to the first communication device even when the second communication device is not connected to the network and does not rely on network assistance. In another embodiment, the mechanism with network assistance is provided when the second communication device is within network coverage, and as a result, security establishment between the second communication device and the first network device can be performed based on the latest subscription information. This avoids the possibility of security establishment failure that may be caused by issues such as changes in authorization of the first or second communication device, and avoids the waste of resources that may be caused by the security establishment process.

[0012] When indicating whether the first message should consent to establish security with the first communication device by using the target mechanism, it should be understood that an explicit or implicit method may be used for indication. For example, when the first message indicates establishing security with the first communication device by using the target mechanism, a message in the security procedure establishment process corresponding to the target mechanism (for example, a direct security mode command message, a security mode command message, or a direct authentication and key establishment message described later) may implicitly indicate consenting to use the target mechanism. In this case, it is possible that the second communication device directly establishes security with the first communication device by using the target mechanism.

[0013] Therefore, another possible embodiment of the foregoing method is a step of determining a target mechanism from a plurality of mechanisms, where the plurality of target mechanisms includes a security establishment mechanism with network assistance and a security establishment mechanism without network assistance, a step of transmitting a request message, where the request message is used to request the second communication device receiving the request message to establish security with the first communication device by using the target mechanism, and a step of establishing security with the second communication device by using the target mechanism.

[0014] In relation to the first aspect, in some possible embodiments of the first aspect, the step of determining a target mechanism from a plurality of mechanisms includes the step of determining a target mechanism from a plurality of mechanisms according to a mechanism selection rule.

[0015] The mechanism selection rule may indicate the rule used to determine the target mechanism. The first communication device may determine the target mechanism from a plurality of mechanisms according to the mechanism selection rule, or may randomly determine the target mechanism from a plurality of mechanisms. This is not limited in this application.

[0016] Optionally, the mechanism selection rule includes a correspondence between a first RSC corresponding to ProSe communication and a first mechanism indicator, and the first mechanism indicator indicates a first mechanism among a plurality of mechanisms. The step of determining the target mechanism from a plurality of mechanisms according to the mechanism selection rule includes the step of determining, based on the correspondence, the first mechanism corresponding to the first mechanism indicator as the target mechanism.

[0017] In other words, the RSC is associated with the mechanism indicator. Different RSCs may be associated with different mechanism indicators. Each RSC may be associated with one or more mechanism indicators, or one or more mechanisms may be determined based on one or more mechanism indicators. The foregoing mechanism selection rule is not limited to including the correspondence between the first RSC and the first mechanism indicator, and may further include the correspondence between another RSC and one or more mechanism indicators. The first communication device may select the corresponding RSC to determine the target mechanism based on the type of service to be currently performed. For example, when the first communication device attempts to initiate ProSe communication, the first communication device may determine the target mechanism by using the first RSC corresponding to ProSe communication, determine the first mechanism indicator based on the first RSC and the correspondence, and further determine the target mechanism based on the first mechanism indicator.

[0018] Optionally, the mechanism selection rule includes priority information, which indicates the priority order of mechanisms among multiple mechanisms. The step of determining a target mechanism from multiple mechanisms according to the mechanism selection rule includes the step of determining a target mechanism from multiple mechanisms based on the priority order of the multiple mechanisms.

[0019] For example, a mechanism with a higher priority will be preferentially selected as the target mechanism.

[0020] In one possible design, the mechanism selection rule is a correspondence between at least one RSC and at least one mechanism indicator. In another possible design, the mechanism selection rule is priority information. In yet another possible design, the mechanism selection rule includes, but is not limited to, a correspondence between at least one RSC and at least one mechanism indicator, and priority information. The specific content of the mechanism selection rule is not limited in this application.

[0021] The mechanism selection rules may be pre-configured or obtained from the network side.

[0022] As described above, the first communication device may be a UE, or a component configured within the UE, or another logic module or software that can be configured to perform some or all of the functions of the first communication device. If the mechanism selection rules are pre-configured, the mechanism selection rules may, where possible, be pre-stored in the first communication device, or, otherwise possible, be pre-stored in memory coupled to the first communication device.

[0023] If the mechanism selection rules are obtained from the network side, the method optionally further includes the step of receiving the mechanism selection rules from a policy control function (PCF). That is, the mechanism selection rules may be obtained from a PCF.

[0024] Optionally, the mechanism selection rule is determined based on the service-specific information of the ProSe corresponding to the first communication device.

[0025] In other words, the service-specific information of the ProSe corresponding to the first communication device includes information used to determine the mechanism selection rule, or includes the mechanism selection rule itself. The PCF may determine the mechanism selection rule based on the acquired ProSe service-specific information and transmit the determined mechanism selection rule to the first communication device. Since the ProSe service-specific information comes from subscription information, the mechanism selection rule is determined based on the subscription information of the first communication device. Therefore, the determined mechanism selection rule is a rule applicable to the first communication device.

[0026] The first message received by the first communication device may vary depending on whether the second communication device agrees to use the target mechanism, or it may vary depending on the target mechanism. For example, the first message is the first message received by the first communication device after it has sent a request message. In other words, the first communication device does not receive any other message after sending a request message and before receiving the first message.

[0027] Optionally, the target mechanism is a security establishment mechanism without network assistance, the first message is a direct authentication and key establishment message, and the direct authentication and key establishment message indicates agreement to establish security with the first communication device by using a security establishment mechanism without network assistance.

[0028] Optionally, the target mechanism is a security establishment mechanism without network support, the first message is a direct security mode command message, and the direct security mode command message indicates agreement to establish security with the first communication device by using a security establishment mechanism with network support.

[0029] Optionally, the first message is a rejection message, which indicates that the user does not agree to establish security with the first communication device by using the target mechanism.

[0030] Furthermore, the rejection message will indicate one or more of the following: the reasons for not agreeing to establish security with the first communication device by using the target mechanism, the security establishment mechanism supported by the second communication device, or the security establishment mechanism not supported by the second communication device.

[0031] When the second communication device does not agree to use the target mechanism, the first message is a rejection message, which may further indicate one or more of the reasons for rejection by the second communication device, supported mechanisms, or unsupported mechanisms, so that when the first communication device next determines the target mechanism, it can determine which mechanisms are supported by the second communication device.

[0032] According to a second embodiment, a method for establishing security is provided. The method may be applied to a second communication device, which may be a communication device that receives request messages from the first communication device. The second communication device may be a UE, a component configured within the UE (e.g., a chip, a chip system, or a processor), or a logic module, software, etc., that can perform all or part of the functions of the second communication device.

[0033] For example, the method includes the steps of: receiving a request message from a first communication device, the request message being used to request a second communication device to establish security with the first communication device by using a target mechanism, the target mechanism being a network-assisted security establishment mechanism or a network-assisted security establishment mechanism; and sending a first message to the first communication device based on a network coverage status, the first message indicating whether the second communication device should agree to establish security with the first communication device by using a target mechanism, the network coverage status including being within network coverage or not being within network coverage.

[0034] The request message may indicate that the target mechanism should be determined so that the second communication device can determine the target mechanism. In other words, the request message may be used to determine the target mechanism.

[0035] Being within network coverage may mean that the device is within the base station's coverage and can successfully establish a connection to the network. Conversely, being outside network coverage may mean that the device cannot successfully establish a connection to the network, for example, being outside the base station's coverage, or being within the base station's coverage but unable to do so for reasons such as too many users accessing the network leading to weak signal quality. In other words, network coverage status may be used to determine whether a UE can successfully establish a connection to the network.

[0036] Based on the mechanism described above, a second communication device receiving a request message may, based on the request message, determine a target mechanism that the first communication device requests to use, and may further determine whether the second communication device supports the target mechanism by referring to the network coverage status of the second communication device. In this way, the determined result may be adapted to the network coverage status of the second communication device. The second communication device may provide different feedback for different target mechanisms based on different network coverage statuses. The first communication device may respond differently based on different feedback. For example, when the first message indicates agreement to use the target mechanism, the first communication device establishes a security connection with the second communication device by using the target mechanism. As another example, when the first message indicates refusal to use the target mechanism, the first communication device re-determines the target mechanism and negotiates with the second communication device. In this way, the first and second communication devices may negotiate to obtain a mechanism supported by both of them. This facilitates the successful establishment of a secure connection.

[0037] It should be understood that when the first message indicates whether to agree to establish security with the first communication device by using the target mechanism, either an explicit or implicit method may be used to indicate this. For example, when the first message indicates to establish security with the first communication device by using the target mechanism, messages in the security procedure establishment process corresponding to the target mechanism (e.g., the direct security mode command message or direct authentication and key establishment message described later) may implicitly indicate agreement to use the target mechanism. In this case, the second communication device may directly establish security with the first communication device by using the target mechanism.

[0038] Accordingly, another possible embodiment of the method described above includes the steps of: receiving a request message from a first communication device, the request message being used to request a second communication device to establish security with the first communication device by using a target mechanism, the target mechanism being a network-assisted security establishment mechanism or a network-assisted security establishment mechanism; and establishing security with the first communication device by using the target mechanism based on a network coverage status, the network coverage status including being in network coverage or not being in network coverage. The different contents indicated by the first message in different network coverage statuses are listed below.

[0039] Optionally, if the network coverage status is within network coverage, the first message indicates agreement to establish security with the first communication device by using the target mechanism.

[0040] In response to this, the step of establishing security with a first communication device by using a target mechanism based on the network coverage status includes the step of establishing security with a first communication device by using a target mechanism if the network coverage status is within network coverage.

[0041] If the second communication device is within network coverage, the second communication device may support both network-assisted and non-network-assisted mechanisms. Therefore, security establishment may be based on the target mechanism used by the first communication device.

[0042] Optionally, if the target mechanism is a network-assisted security establishment mechanism and the network coverage status is not within network coverage, the first message indicates that the user does not agree to establish security with the first communication device by using the target mechanism.

[0043] If the second communication device is not in network coverage, the second communication device may support a mechanism that does not involve network support, or it may not support a mechanism that does involve network support. If the target mechanism is a mechanism that involves network support, the second communication device may reject the target mechanism. This avoids the possibility of establishment failure that may occur when the first communication device attempts to establish security with the second communication device by using the target mechanism, but the second communication device does not support the target mechanism, thereby avoiding potential resource waste caused by the security establishment process.

[0044] Optionally, if the target mechanism is a security establishment mechanism that does not involve network support and the network coverage status is not within network coverage, the first message indicates agreement to establish security with the first communication device by using the target mechanism.

[0045] In response to this, if the target mechanism is a security establishment mechanism that does not involve network support, the step of establishing security with the first communication device by using the target mechanism based on the network coverage status includes the step of establishing security with the first communication device by using the target mechanism if the network coverage status is not within network coverage.

[0046] If the second communication device is not in network coverage, the second communication device may support a mechanism without network support, or it may not support a mechanism with network support. If the target mechanism is a mechanism without network support, the second communication device may agree to use the target mechanism. In this way, the first communication device may establish security with the second communication device without repeating procedures such as determining the target mechanism and negotiating with the second communication device, thereby reducing the signaling overhead caused by negotiation with the second communication device and reducing time consumption.

[0047] In conclusion, it can be seen that, under different network coverage statuses, the second communication device may agree to establish security with the first communication device by using different mechanisms. Thus, the security establishment mechanism does not need to be limited to a specific mechanism and may be flexibly adjusted based on the network coverage status of the second communication device. This facilitates the successful establishment of a secure connection between the first and second communication devices.

[0048] The first message transmitted by the second communication device may vary depending on whether the second communication device agrees to use the target mechanism, or it may vary depending on the target mechanism.

[0049] Optionally, the target mechanism is a security establishment mechanism without network assistance, the first message is a direct authentication and key establishment message, and the direct authentication and key establishment message indicates agreement to establish security with the first communication device by using a security establishment mechanism without network assistance.

[0050] Optionally, the target mechanism is a network-assisted security establishment mechanism, the first message is a direct security mode command message, and the direct security mode command message indicates agreement to use a network-assisted security establishment mechanism.

[0051] If the second communication device optionally does not agree to establish security with the first communication device by using the target mechanism, the first message is a denial message, and the denial message indicates that it does not agree to establish security with the first communication device by using the target mechanism.

[0052] Furthermore, the rejection message will indicate one or more of the following: the reasons for not agreeing to establish security with the first communication device by using the target mechanism, the security establishment mechanism supported by the second communication device, or the security establishment mechanism not supported by the second communication device.

[0053] When the second communication device does not agree to use the target mechanism, the first message is a rejection message, which may further indicate one or more of the reasons for rejection by the second communication device, supported mechanisms, or unsupported mechanisms, so that when the first communication device next determines the target mechanism, it can determine which mechanisms are supported by the second communication device.

[0054] In relation to the first or second aspect, in some possible embodiments, the request message is a direct communication request (DCR) message. In other words, the DCR message may indicate a target mechanism or may be used to determine a target mechanism.

[0055] As an example of a request message, please understand that the DCR message does not constitute any limitation on this application.

[0056] Where possible, the target mechanism is a security establishment mechanism that does not involve network assistance, and the request message includes key establishment information (key_est_info).

[0057] In another possible case, the target mechanism is a network-assisted security establishment mechanism, and the request message includes at least one of the following: a control plane ProSe remote user key (CP-PRUK) identifier (ID) (CP-PRUK ID), a user plane ProSe remote user key (UP-PRUK) ID, or a subscription concealed identifier (SUCI).

[0058] A comparison reveals that the information elements included in the request message differ depending on the target mechanism. Request messages for mechanisms with network support satisfy the following conditions: they include at least one of the following: CP-PRUK ID, UP-PRUK ID, or SUCI, and / or exclude key_est_info. Request messages for mechanisms without network support satisfy the following conditions: they include key_est_info, and / or exclude CP-PRUK ID, UP-PRUK ID, and SUCI.

[0059] Therefore, the specific mechanism indicated by the request message can be determined by determining whether the request message contains any one of the following: key_est_info, CP-PRUK ID, UP-PRUK ID, or SUCI.

[0060] Optionally, the network-assisted security establishment mechanism may be a control plane (CP)-based security establishment mechanism (which may be abbreviated as a control plane-based mechanism (CP-based solution)) or a user plane (UP)-based security establishment mechanism (which may be abbreviated as a user plane-based mechanism (UP-based solution)).

[0061] Both the control plane-based security establishment mechanism and the user plane-based security establishment mechanism are network-assisted security establishment mechanisms. Therefore, request messages corresponding to the two mechanisms satisfy the following conditions: they include at least one of the following: CP-PRUK ID, UP-PRUK ID, or SUCI, and / or exclude key_est_info.

[0062] Optionally, the target mechanism is a network-assisted security establishment mechanism, the request message further includes an RSC, and the RSC is used to determine whether a control plane-based or user plane-based security establishment mechanism is used.

[0063] The corresponding RSC value differs depending on whether the target mechanism is a control plane-based security establishment mechanism or a user plane-based security establishment mechanism. Therefore, a second communication device receiving a request message may determine whether the target mechanism is a control plane-based mechanism or a user plane-based mechanism based on the RSC value.

[0064] According to a third aspect, a security establishment method is provided and is applied to the PCF. The method may be performed by the PCF, by a component configured within the PCF (e.g., a chip, a chip system, or a processor), or by a logic module or software capable of performing all or part of the functions of the PCF.

[0065] For example, the method includes the steps of determining a mechanism selection rule, which is used to determine a target mechanism for establishing security between a first communication device and a second communication device from among a plurality of mechanisms, the plurality of mechanisms including a security establishment mechanism with network support and a security establishment mechanism without network support, and the first communication device is a device that initiates proximity service communication, and transmitting the mechanism selection rule to the first communication device.

[0066] Based on the mechanism described above, a mechanism selection rule is transmitted to the first communication device, and as a result, the first communication device determines a target mechanism from among several mechanisms in order to establish security with the second communication device. These mechanisms include security establishment mechanisms with network support and security establishment mechanisms without network support. Different cases are considered, and feasible mechanisms are provided to both communication devices within and outside network coverage. This facilitates the successful establishment of secure connections.

[0067] In relation to the third aspect, in some possible embodiments of the third aspect, the method further includes the step of receiving information from uniform data management (UDM), the information being used to determine mechanism selection rules.

[0068] Optionally, the information is service-specific information for the ProSe corresponding to the first communication device.

[0069] In other words, the service-specific information of ProSe corresponding to the first communication device includes information used to determine the mechanism selection rule, or includes the mechanism selection rule itself. The PCF may transmit the determined mechanism selection rule to the first communication device. Since the service-specific information of ProSe comes from subscription information, the mechanism selection rule is determined based on the subscription information of the first communication device. Therefore, the determined mechanism selection rule is a rule applicable to the first communication device.

[0070] Optionally, the mechanism selection rule includes a correspondence between a first RSC corresponding to ProSe communication and a first mechanism indicator, where the first mechanism indicator indicates a first mechanism among multiple mechanisms.

[0071] In other words, the mechanism selection rule includes a correspondence between one or more RSCs and one or more mechanism indicators in multiple mechanisms.

[0072] Optionally, the mechanism selection rule includes priority information, which indicates the priority order of multiple mechanisms.

[0073] For an explanation of the mechanism selection rules, please refer to the relevant explanation in the first aspect. Further details will not be explained again.

[0074] According to a fourth aspect, a method for establishing security is provided. The method may be applied to a first communication device in ProSe communication. The first communication device may be a UE, a component configured within the UE (e.g., a chip, a chip system, or a processor), or a logic module, software, etc., capable of performing all or part of the functions of the first communication device.

[0075] For example, the method includes the steps of sending at least one request message, wherein the request message indicates a plurality of mechanisms, the plurality of mechanisms including a security establishment mechanism with network assistance and a security establishment mechanism without network assistance, and receiving a second message from a second communication device, wherein the second message indicates establishing security with a first communication device by using one of the plurality of mechanisms.

[0076] Based on the mechanism described above, the first communication device sends at least one request message indicating multiple mechanisms, and as a result, the second communication device, which receives at least one request message, can select one mechanism from the multiple mechanisms to establish security with the first communication device. The multiple mechanisms include security establishment mechanisms with network support and security establishment mechanisms without network support. Different cases are considered, and feasible mechanisms are provided for both cases where the second communication device is within network coverage and where it is not. Thus, the second communication device may select one of the multiple mechanisms based on its network coverage status and indicate the mechanism to the first communication device via a second message. In this way, the two parties can establish security. This mechanism does not require multiple negotiations between the first and second communication devices and therefore helps to complete security establishment more quickly.

[0077] In relation to the fourth aspect, in some possible embodiments of the fourth aspect, the method includes the steps of determining a mechanism indicated by a second message as a target mechanism, and establishing security with a second communication device by using the target mechanism.

[0078] The first communication device may establish security by using a mechanism that matches the mechanism of the second communication device, by determining the mechanism indicated by the second message as the target mechanism. In other words, the second communication device may indicate the target mechanism to the first communication device via the second message. The target mechanism may be indicated explicitly or implicitly. This is not limited to the present application.

[0079] For example, the second message is from the second communication device and is the first message received by the first communication device after the first communication device has sent at least one request message. In other words, the first communication device does not receive any other message after sending at least one request message and before receiving the first message.

[0080] Optionally, the second message is a direct security mode command message, which indicates a security establishment mechanism with network assistance. The step of determining the mechanism indicated by the second message as the target mechanism includes the step of determining the security establishment mechanism with network assistance indicated by the direct security mode command message as the target mechanism.

[0081] Optionally, the second message is a direct authentication and key establishment message, which indicates a security establishment mechanism without network assistance. The step of determining the mechanism indicated by the second message as the target mechanism includes the step of determining the security establishment mechanism without network assistance indicated by the direct authentication and key establishment message as the target mechanism.

[0082] Furthermore, the step of receiving a second message from a second communication device includes the step of receiving multiple second messages from multiple second communication devices, and the step of determining a mechanism indicated by a second message as a target mechanism includes the step of determining a mechanism indicated by one of the multiple second messages as a target mechanism according to a mechanism selection rule.

[0083] The first communication device may transmit at least one request message in a broadcast manner, and there may be one or more second communication devices that receive at least one request message. Therefore, the first communication device may receive multiple second messages. In this case, the first communication device may determine a target mechanism based on the multiple second messages.

[0084] Multiple mechanisms may be determined based on multiple second messages, since the mechanisms indicated by each of the multiple second messages may be the same or different. The first communication device may determine the target mechanism according to a mechanism selection rule. The mechanism selection rule may include, but is not limited to, the rules described above with reference to the first to third embodiments. See the above description for further details. Further details are not described again herein.

[0085] According to a fifth aspect, a method for establishing security is provided. The method may be applied to a second communication device, which may be a communication device that receives request messages from the first communication device. The second communication device may be a UE, a component configured within the UE (e.g., a chip, a chip system, or a processor), or a logic module, software, etc., that can perform all or part of the functions of the second communication device.

[0086] For example, the method includes the steps of: receiving at least one request message from a first communication device, wherein the at least one request message indicates a plurality of mechanisms, the plurality of mechanisms including a security establishment mechanism with network assistance and a security establishment mechanism without network assistance; and sending a second message to the first communication device based on network coverage status, wherein the second message indicates that security establishment will be performed with the first communication device by using one of the plurality of mechanisms.

[0087] Based on the mechanism described above, the first communication device sends at least one request message indicating multiple mechanisms, and as a result, the second communication device, which receives at least one request message, can select one mechanism from the multiple mechanisms to establish security with the first communication device. The multiple mechanisms include security establishment mechanisms with network support and security establishment mechanisms without network support. Different cases are considered, and feasible mechanisms are provided for both cases where the second communication device is within network coverage and where it is not. Thus, the second communication device may select one of the multiple mechanisms based on its network coverage status and indicate the mechanism to the first communication device via a second message. In this way, the two parties can establish security. This mechanism does not require multiple negotiations between the first and second communication devices and therefore helps to complete security establishment more quickly.

[0088] In relation to the fifth aspect, in some possible embodiments of the fifth aspect, the network coverage status is that it is within network coverage, and the second message indicates that security is established with the first communication device by using a security establishment mechanism with network assistance.

[0089] Optionally, the second message is a direct security mode command message.

[0090] In relation to the fifth aspect, in some possible embodiments of the fifth aspect, the network coverage status is not in network coverage, and the second message indicates that security is established with the first communication device by using a security establishment mechanism without network assistance.

[0091] Optionally, the first message is a direct authentication and key establishment message.

[0092] In relation to the fourth or fifth aspect, in some possible embodiments, at least one request message includes multiple request messages, each of which indicates one of multiple mechanisms.

[0093] In other words, each request message indicates one mechanism, and multiple mechanisms may be indicated through multiple request messages.

[0094] In relation to the fourth or fifth aspect, in some possible embodiments, at least one request message is a single request message, and the request message indicates multiple mechanisms.

[0095] In other words, multiple mechanisms may be indicated through a single request message. In this case, the information elements in the request message may include not only information elements corresponding to network-assisted mechanisms, but also information elements corresponding to non-network-assisted mechanisms.

[0096] Optionally, the request message may include key_est_info and at least one of the following: CP-PRUK ID, UP-PRUK ID, or SUCI.

[0097] As described above, the information elements in a request message corresponding to a network-assisted mechanism include a UTC-based counter LSB and RSC, while the information elements in a request message corresponding to a non-network-assisted mechanism include a ProSe Identifier. Therefore, in this mechanism, when a single request message indicates multiple mechanisms, the request message may contain multiple information elements.

[0098] In relation to the aforementioned embodiments, in some possible embodiments, the first communication device is a first UE, the second communication device is a relay UE between the first UE and the second UE, and the second UE is a UE that performs proximity service communication with the first UE.

[0099] In other words, after security is established, the second communication device may function as a relay UE between the first UE and another UE (e.g., a third UE) for proximity service communication. In other words, the mechanism may be applied to a U2U relay service scenario. Note that the relay UE can be thought of as a potential relay before a secure connection with the first UE is established.

[0100] In a U2U relay service scenario, the relay UE may or may not be within network coverage. However, this application provides multiple mechanisms, including network-assisted and network-unassisted security establishment mechanisms, to provide different security establishment mechanisms for relay UEs in different network statuses. This facilitates the successful establishment of secure connections.

[0101] According to the sixth aspect, a communication device is provided for implementing the security establishment method in any one of the first to fifth aspects and any possible embodiments of the first to fifth aspects. The device includes one or more corresponding functional units or modules configured to perform the method described above. The functional units or modules included in the device may be implemented by software and / or hardware.

[0102] According to the seventh aspect, the present application provides a communication device including a processor, the processor configured to perform a security establishment method in any one of the first to fifth aspects and any possible embodiments of the first to fifth aspects.

[0103] Optionally, the device may further include memory configured to store instructions and data. The memory is coupled to the processor. When the processor executes instructions stored in the memory, the methods described in the preceding embodiments may be implemented.

[0104] Optionally, the device may further include a communication interface. The communication interface is used by the device to communicate with another device. For example, the communication interface may be a transceiver, circuit, bus, module, or another type of communication interface.

[0105] According to the eighth aspect, the present application provides a chip system, which includes at least one processor configured to support the implementation of a function in any one of the first to fifth aspects and any possible embodiments of the first to fifth aspects, for example, the receiving or processing of data and / or information in the aforementioned method.

[0106] In possible designs, the chip system further includes memory, which is configured to store program instructions and data, and the memory is located inside or outside the processor.

[0107] The chip system may include a chip, or it may include a chip and other separate components.

[0108] According to the ninth aspect, the application provides a computer-readable storage medium containing a computer program. When the computer program is executed on a computer, the computer is enabled to carry out a method in any one of the first to fifth aspects and any possible embodiments of the first to fifth aspects.

[0109] According to the tenth aspect, the present application provides a computer program product, which includes a computer program (which may also be called code or instructions). When the computer program is executed, the computer is enabled to perform a method in any one of the first through fifth aspects and any possible implementations of the first through fifth aspects.

[0110] According to the eleventh aspect, one embodiment of the present application provides a communication system including the aforementioned first communication device, second communication device, PCF, and / or another aforementioned device (e.g., UDM).

[0111] It should be understood that the technical mechanisms of the sixth to eleventh aspects of this application correspond to the technical mechanisms of the first to fifth aspects of this application, and that the beneficial effects achieved in the aspects and corresponding executable embodiments are similar. Further details will not be explained again. [Brief explanation of the drawing]

[0112] [Figure 1] This is a diagram illustrating a scenario applicable to a security establishment method according to one embodiment of this application. [Figure 2] This is a schematic flowchart of a security establishment method according to one embodiment of this application. [Figure 3] This is a schematic flowchart of a security establishment method according to another embodiment of the present application. [Figure 4]This is a block diagram of a communication device according to one embodiment of this application. [Figure 5] This is a block diagram of a communication device according to one embodiment of this application. [Figure 6] This is a diagram showing the structure of a terminal device according to one embodiment of this application. [Modes for carrying out the invention]

[0113] The technical mechanism in this application will be described below with reference to the attached drawings.

[0114] To facilitate understanding of the embodiments of this application, the following description is provided first.

[0115] Firstly, in the embodiments of this application, prefixes such as “first” and “second” are used merely to distinguish and describe different things belonging to the same nominal category, and are not intended to limit the order, size, or quantity of things. For example, “first communication device” and “second communication device” are simply different communication devices, and the number or priority relationship of the communication devices is not limited. In another example, “first message” and “second message” are simply different messages, and there is no chronological, size, or priority relationship between the two messages.

[0116] Secondly, the messages referred to in embodiments of this application, such as DCR messages, direct security mode command messages, direct authentication and key establishment messages, and the information elements (IEs) contained in each message, are merely examples and do not constitute any limitation to this application. This application does not preclude the possibility of replacing the aforementioned messages with other messages to perform the same or similar functions.

[0117] Thirdly, “transmit” and “receive” in the embodiments of this application indicate the direction of signal transfer. For example, “transmitting information to UE2” may be understood as UE2 being the target end of the information, or it may include direct transmission via the air interface, or it may include indirect transmission via the air interface by another unit or module. “Receiving configuration information from charging energy” may be understood as UE2 being the source end of the configuration information, or it may include direct reception from UE2 via the air interface, or it may include indirect reception from UE2 via the air interface by another unit or module. “Transmit” may also be understood as an “output” of the chip interface, and “receive” may also be understood as an “input” of the chip interface.

[0118] In other words, “transmission” and “reception” may occur between devices, for example, between UE2 and UE1, or within a device, for example, transmission or reception may occur between components, modules, chips, software modules, or hardware modules within a device via a bus, cabling, or interface.

[0119] Necessary processing such as encoding and modulation may be performed on the information between the source end and the target end from which the information is transmitted, but it will be understood that the target end may understand valid information from the source end. A similar explanation in this application can be understood in the same way. Further details will not be explained again.

[0120] Fourth, in embodiments of this application, “at least one” means one or more, and “multiple” means two or more. “And / or” describes a relationship between related objects and indicates that three relationships may exist. For example, A and / or B may mean: only A exists; both A and B exist; and only B exists, where A and B may be singular or plural. The letter “ / ” usually indicates an “or” relationship between related objects, but does not exclude an “and” relationship between related objects. The specific meaning indicated by the letter “ / ” may be understood by referring to the context. “At least one of the following (elements)” or a similar expression means any combination of these, including any single one (element) or any combination of multiple (elements). For example, at least one of a, b, or c may mean a, b, c, a and b, a and c, b and c, or a, b, and c, where a, b, and c may be singular or plural.

[0121] Fifth, the term "predefinition" in this application may be understood as definition, predefinition, memory, pre-storage, pre-negotiation, pre-configuration, solidification, or pre-combustion.

[0122] Sixth, the memory in this application may mean memory in one or more memories. One or more memories may be located separately or may be integrated into an encoder or decoder, processor or communication device. Alternatively, a portion of one or more memories may be located separately, or a portion of one or more memories may be integrated into a decoder, processor or communication device. The type of memory may be any form of storage medium; this is not limited to this application.

[0123] Seventh, in the embodiments of this application, phrases such as “when,” “in the case of,” and “if” mean that the communication device (e.g., UE1 or UE2) performs the corresponding processing in the intended situation, and are not intended to limit time, require the communication device (e.g., UE1 or UE2) to perform decision actions during implementation, or imply any other limitations.

[0124] Furthermore, "simultaneous" does not mean a time limit. In this specification, "simultaneous" may mean that multiple steps may be performed synchronously, or that multiple information elements may be included in the same message.

[0125] The technical mechanisms provided in this application may be applied to various communication systems, such as long-term evolution (LTE) systems, LTE frequency division duplex (FDD) systems, LTE time division duplex (TDD) systems, sidelink (SL) communication systems, universal mobile telecommunication systems (UMTS), worldwide interoperability for microwave access (WiMAX) communication systems, 5th generation (5G) mobile communication systems, or new radio (NR) access technologies. 5G mobile communication systems may include non-standalone (NSA) networking and / or standalone (SA) networking.

[0126] The technical mechanisms provided in this application may be further applied to future communication systems, such as 6th generation (6G) mobile communication systems. This is not limited to this application.

[0127] The radio access network (RAN) device in this application is a device having wireless transceiver functionality. The radio access network device may provide wireless communication services or connect terminals to a wireless network. The radio access network device may also be a node in the radio access network, abbreviated as a RAN node.

[0128] In possible scenarios, a RAN node may be a base station (BS), an evolved NodeB (eNodeB), a transmission reception point (TRP), a home evolved NodeB (or home Node B, HNB), a wireless fidelity (Wi-Fi) access point (AP), a mobile communication switching center, a next-generation NodeB (gNB) in a 5G mobile communication system, a next-generation NodeB in a 6G mobile communication system, or a NodeB in a future mobile communication system. Alternatively, a RAN node may function as a base station in a device-to-device (D2D) communication system, a vehicle-to-everything (V2X) communication system, a machine-to-machine (M2M) communication system, or an Internet of Things (IoT) communication system. Alternatively, a RAN node may be a RAN node in a non-terrestrial network (NTN). In other words, RAN nodes may be deployed on high-altitude platforms or satellites. RAN nodes may be macro base stations, micro base stations or indoor base stations, relay nodes or donor nodes, radio controllers in cloud radio access network (CRAN) scenarios, or nodes in open radio access network (O-RAN or ORAN) scenarios. Optionally, RAN nodes may also be servers, wearable devices, vehicles, or in-vehicle devices. For example, in V2X technology, RAN nodes may be roadside units (RSUs). Naturally, RAN nodes may also be nodes within the core network.

[0129] In another possible scenario, multiple RAN nodes cooperate to help a terminal perform radio access, while different RAN nodes perform several base station functions separately. For example, RAN nodes may include a central unit (CU), a distributed unit (DU), a CU control plane (CP), a CU user plane (UP), and a radio unit (RU). CUs and DUs may be located separately or may be included in the same network element, such as a baseband unit (BBU). RUs may be included in a radio frequency device or radio frequency unit, such as a remote radio unit (RRU), an active antenna unit (AAU), or a remote radio head (RRH).

[0130] In different systems, CU (or CU-CP and CU-UP), DU, or RU may also have different names, and a person skilled in the art will understand the meaning of the names. For example, in the ORAN system, CU may also be called open CU (O-CU), DU may be called open DU (O-DU), CU-CP may be called open CU-CP (O-CU-CP), CU-UP may be called open CU-UP (O-CU-UP), and RU may be called open RU (O-RU).

[0131] Any unit within a CU (or CU-CP or CU-UP), DU, or RU may be implemented using software modules, hardware modules, or a combination of software modules and hardware modules.

[0132] In this application, user equipment (UE) may also be referred to as terminal device, access terminal, subscriber unit, subscriber station, mobile station, mobile console, remote station, remote terminal, mobile equipment (ME), user terminal, terminal, wireless communication device, user agent, or user equipment.

[0133] The UE may be a device that provides voice / data connectivity to the user, or it may be, for example, a handheld device with wireless connectivity, an in-vehicle device, etc. Currently, some examples of UEs include mobile phones, tablet computers, computers with wireless transmission and reception capabilities (e.g., notebook computers or palmtop computers), mobile internet devices (MIDs), virtual reality (VR) devices, augmented reality (AR) devices, wireless terminals in industrial control, wireless terminals in self-driving, unmanned aerial vehicles (UAVs), wireless terminals in V2X, wireless terminals in remote medical, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, wireless terminals in smart homes, cellular phones, cordless phones, Session Initiation Protocol (SIP) phones, wireless local loop (WLL) stations, and personal digital assistants (PDIs). This may include assistants (PDAs), handheld devices with wireless communication capabilities, computing devices, other processing devices connected to wireless modems, in-vehicle devices, wearable devices, terminal devices in 5G networks, and terminal devices in future advanced public land mobile networks (PLMNs).

[0134] Wearable devices, sometimes called wearable intelligent devices, are a general term for wearable devices such as glasses, gloves, watches, clothing, and shoes, developed by applying wearable technology to the intelligent design of everyday wear. Wearable devices are portable devices that can be worn directly on the body or integrated into the user's clothing or accessories. Wearable devices are not merely hardware devices, but are used to implement powerful functionality through software support, data exchange, and cloud interaction. General-purpose wearable smart devices include full-featured large devices that can implement full or partial functionality without relying on a smartphone, such as smartwatches or smart glasses, and devices that focus only on certain application functions and need to work in conjunction with other devices such as smartphones to monitor physical symptoms, such as various smart bands or smart jewelry.

[0135] In addition, UE may further include terminal devices within the IoT system, which may also be called IoT nodes. IoT is a crucial part of future information technology development. The main technical characteristic of IoT is the use of communication technologies to connect things to a network and implement smart networks for human-machine and object-to-object interconnection. IoT technology can achieve large-scale connectivity, deep coverage, and energy savings of terminals by using narrowband (NB) technology, for example.

[0136] The UE may further include sensors such as those found in intelligent printers, train detectors, or gas stations. The main functions of the UE include collecting data (for some terminal devices), receiving control information and downlink data from network devices, transmitting electromagnetic waves, and transmitting uplink data to network devices.

[0137] Please understand that the specific forms of network devices and UEs are not limited in this application.

[0138] To facilitate understanding of the embodiments of this application, the terms used herein are first briefly explained below.

[0139] 1. D2D Communication: Communication devices (such as UEs) may perform D2D communication by sharing spectral resources under the control of a cell network to improve the utilization of spectral resources, or they may not communicate by using unauthorized spectral resources under the control of a cell network. In D2D communication, communication devices may communicate with each other via the PC5 interface, and information regarding the control plane and user plane may be transmitted between UEs via the PC5 interface. The information includes signaling and / or data. Links in which UEs communicate directly via the PC5 interface are sometimes called sidelinks (SLs). One-to-one communication and one-to-many communication may be included. One-to-one communication may correspond to unicast communication, and one-to-many communication may correspond to multicast communication and broadcast communication. In one-to-one communication, if the initiator and receiver are at a short distance, the initiator and receiver may communicate directly with each other via discovery.

[0140] 2. ProSe Communication: D2D communication is widely discussed in LTE and 5G network standards and is collectively referred to as ProSe communication. For example, in 5G, 5G ProSe Direct Communication is defined as follows: communication takes place between two or more adjacent UEs that support ProSe communication via user plane transmission using NR technology, via a path that does not pass through any network nodes.

[0141] UEs performing ProSe communication may communicate with each other via the PC5 interface, and information regarding the control plane and user plane may be transmitted between UEs via the PC5 interface. This information includes signaling and / or data. A link through which UEs communicate directly via the PC5 interface may be called a sidelink or a PC5 link. Unicast communication conducted via a PC5 link may be called PC5 unicast communication, and a PC5 link used for unicast communication may be called a PC5 unicast link.

[0142] Compared to conventional cellular network communication, UEs used for ProSe communication must have ProSe functionality, and UEs with ProSe functionality communicate with each other via the PC5 interface. In 5G, UEs with ProSe functionality and performing ProSe communication may be called source UEs and target UEs, or collectively referred to as end UEs. Source UEs and target UEs may communicate with each other with the assistance of a U2U Relay. A U2U Relay can be understood as a UE that provides functionality to support the connection between the source UE and the target UE. In this specification, a service that enables end UEs to perform ProSe communication via a U2U Relay may be referred to as a U2U Relay service.

[0143] In the process of establishing a PC5 link used for ProSe communication, a UE with ProSe capabilities must initiate the establishment of a PC5 link to another UE with ProSe capabilities. In this case, it should be noted that the roles of the two UEs can be distinguished as initiating UE and receiving UE. For example, if an end UE initiates the establishment of a PC5 link to a U2U Relay, the end UE and the U2U Relay are the initiating UE and receiving UE, respectively. Or, if an end UE initiates the establishment of a PC5 link to another end UE, the end UE and the other end UE are the initiating UE and receiving UE, respectively.

[0144] 3. Network Coverage Status: For simplicity of explanation, the term network coverage status is introduced herein to distinguish the status of different UEs. Network coverage status may include being in network coverage and not being in network coverage (or out of network coverage).

[0145] Being within network coverage may mean that the device is within the base station's coverage and can successfully establish a connection to the network. Conversely, being outside network coverage may mean that the device cannot successfully establish a connection to the network, for example, being outside the base station's coverage, or being within the base station's coverage but unable to do so for reasons such as too many users accessing the network leading to weak signal quality. In other words, network coverage status may be used to determine whether a UE can successfully establish a connection to the network.

[0146] 4. RSC: RSC may be used to identify different services. In other words, different RSCs may correspond to different services. For example, ProSe communication service A may correspond to an RSC. For example, if a device (e.g., denoted as Device A) expects to perform ProSe communication service A1 over the UE-network U2U Relay, ProSe communication service A1 may correspond to an RSC (e.g., denoted as RSC#1), or if Device A expects to perform ProSe communication service A2 over the U2U Relay, ProSe communication service A2 may correspond to a different RSC (e.g., denoted as RSC#2). Device A may, in the discovery procedure, broadcast an RSC (e.g., RSC#2) corresponding to the service it expects to be initiated, and a device receiving RSC#2 (e.g., denoted as Device B) may determine that Device A expects to perform ProSe communication over the U2U Relay.

[0147] 5. Security Establishment: The purpose of security establishment is to establish a secure connection between communication devices and thereby guarantee communication security. The security establishment procedure is briefly explained below.

[0148] In PC5 unicast communication, the initiating UE and receiving UE perform security establishment in the PC5 link establishment process, which includes negotiating whether security for the PC5 link is enabled (i.e., determining the method of security protection between the two ends), and further performing mutual authentication and key establishment. Note that the initiating UE and receiving UE may negotiate via control plane messages (also called signaling messages). For example, the initiating UE may send a Direct Communication Request (DCR) message to the receiving UE to trigger the establishment of a PC5 unicast link, or, after receiving a Direct Communication Request message from the initiating UE, the receiving UE may trigger a security establishment procedure for the PC5 unicast link. This procedure is used to perform mutual authentication and mutual authorization between the initiating UE and the receiving UE and to establish a shared key for the PC5 unicast link. The security establishment methods provided in this application may include network-assisted security establishment methods and network-assisted security establishment methods. Security establishment mechanisms that involve network support are sometimes called in-coverage mechanisms, while security establishment mechanisms that do not involve network support are sometimes called out-of-coverage mechanisms.

[0149] 6. Network-Assisted Security Establishment Mechanism: A network-assisted security establishment mechanism is a mechanism in which the network side performs security authentication, authorization, and key establishment. Network-assisted security establishment procedures require interaction with the network side to complete security establishment.

[0150] Network-assisted security establishment mechanisms may further include user-plane-based mechanisms (UP-based solutions) and control-plane-based mechanisms (CP-based solutions). User-plane-based mechanisms may be abbreviated as user-plane mechanisms or UP mechanisms, and control-plane-based mechanisms may be abbreviated as control-plane mechanisms or CP mechanisms. Furthermore, a correspondence between RSCs and Control Plane Security Indicators is configured on the UE. The correspondence may indicate whether security establishment is performed via a control-plane mechanism. In other words, the UE may further determine, based on the RSC and the correspondence, whether the RSC corresponds to a control-plane mechanism or a user-plane mechanism.

[0151] The CP mechanism is a mechanism by which relay connection keys are obtained via the network's control plane. For example, when an initiating UE needs to establish a PC5 link to a receiving UE, the initiating UE may perform ProSe discovery to find the receiving UE. The initiating UE may also send a direct communication request message to the receiving UE to initiate the establishment of the PC5 link. In the CP mechanism, the direct communication request message may include the SUCI of the initiating UE and the relay service code (RSC) of the service corresponding to the PC5 communication link. Based on the direct communication request message, the receiving UE may send a key acquisition request message to the access and mobility management function (AMF), and as a result, the AMF verifies that the receiving UE has permission to use the ProSe service. After confirming that the receiving UE has permission to use the service, the AMF may send an authentication request message to the AUSF. The authentication server function (AUSF) may obtain an authentication vector from uniform data management (UDM) based on the authentication request message to perform ProSe authentication to the initiating UE. Upon successful ProSe authentication, the initiating UE and AUSF separately generate a CP-PRUK and a CP-PRUK ID. The CP-PRUK is the root key for the PC5 link in the CP mechanism, and the CP-PRUK ID is the identifier for the root key. AUSF then uses the CP-PRUK to generate a K NR_ProSe Generate K NR_ProSe You may send this to the receiving UE. NR_ProSe This may be the key to the PC5 link in the CP mechanism. The initiating UE is based on CP-PRUK. NR_ProSe It may also be generated. In this case, both the starting UE and the receiving UE are K NR_ProSe The two parties obtain K NR_ProSe You may use this to establish a secure PC5 connection.

[0152] The AUSF may further store the CP-PRUK, CP-PRUK ID, the RSC of the service corresponding to the PC5 link, and the subscription permanent identifier (SUPI) of the ProSe anchor function (PAnF). The initiating UE may again send a direct communication request message to other receiving UEs. In this case, the CP mechanism may further include the CP-PRUK ID in the direct communication request message to indicate that the initiating UE has previously performed the ProSe authentication procedure. The AUSF may directly retrieve the corresponding CP-PRUK from the PAnF based on the service's CP-PRUK ID and RSC, and it is not necessary to perform the ProSe authentication procedure again.

[0153] For specific procedures regarding the CP mechanism, please refer to the relevant explanation in the 3rd generation partnership project (3GPP®) technical specification (TS) 33.503. Further details will not be provided again.

[0154] The UP mechanism is a mechanism by which a relay connection key is obtained via the user plane of the network. For example, the ProSe key management function (PKMF) of the initiating UE and the PKMF address of the receiving UE are pre-configured separately for the initiating UE and the receiving UE. The initiating UE may obtain the UP-PRUK and the UP-PRUK ID from the PKMF of the initiating UE via UP signaling. The UP-PRUK is the root key of the PC5 link in the UP mechanism, and the UP-PRUK ID is the identifier of the root key. When the initiating UE needs to access the network via a relay, the initiating UE may perform ProSe discovery to discover the receiving UE. The initiating UE may directly send a communication request message to the receiving UE to initiate the establishment of the PC5 link. In the UP mechanism, the direct communication request message may include the identifier of the home public land mobile network (HPLMN) of the initiating UE, for example, the HPLMN ID, and the SUCI of the initiating UE (the SUCI of the initiating UE may also be replaced by the UP-PRUK ID). Based on the direct communication request message, the receiving UE may send a key acquisition request message to the PKMF of the receiving UE, and as a result, the PKMF of the receiving UE verifies that the receiving UE has permission to use the service. In this case, the PKMF of the receiving UE may determine the PKMF of the initiating UE based on the HPLMN ID of the initiating UE and the SUCI of the initiating UE (the SUCI of the initiating UE may also be replaced by the UP-PRUK ID), or K NRP (new radio PC5, NRP) and K NRP freshness parameter (K NRP freshness parameter) may be obtained. The PKMF of the receiving UE sends K NRP and K NRP freshness parameter to the receiving UE. K NRP may be the key of the PC5 link in the UP mechanism. After obtaining K NRP , the receiving UE is K NRPFreshness parameters are sent to the start UE, and the start UE receives UP-PRUK and K NRP K based on freshness parameter NRP Determine the following. In this case, both the starting UE and the receiving UE are K. NRP The two parties obtain K NRP You may use this to establish a secure PC5 connection.

[0155] For specific procedures in the UP mechanism, it may be helpful to refer to the relevant description in 3GPP TS33.503. Further details will not be provided again.

[0156] The network can know in real time whether the communication device requiring security establishment is a subscriber and whether the communication device has permission to use the service, thus preventing unauthorized users or users whose authorization has expired from obtaining authorization. Because the network is involved in security establishment, each time security establishment is performed, the network device may decide whether to authorize the communication device based on the latest subscription information. Therefore, authorization may change with updates to subscription information, and authorization may be considered dynamic authorization. In addition, because the network is involved in security establishment, a large amount of signaling is exchanged between the communication device and the network device. In particular, in user plane-based mechanisms, further protocol data unit (PDU) sessions need to be established, and authorization takes longer.

[0157] 7. Security establishment mechanism without network support: Compared to a security establishment mechanism with network support, a security establishment mechanism without network support does not require the network to perform authentication, authorization, and key establishment, and mutual authentication and key establishment may occur between devices.

[0158] In a security establishment mechanism without network support, long-term credential information is pre-configured at the initiating UE and receiving UE, used as the root credentials for a specific PC5 unicast communication service, acting as the root credentials in the security establishment procedure within the PC5 unicast establishment procedure, and further generating the root key for the PC5 unicast link. When the initiating UE determines that a PC5 unicast link needs to be established for a specific service, the initiating UE sends a communication request message directly to the receiving UE. In response, receiving UE2 receives the communication request message directly from transmitting UE1. The direct communication request message may include information necessary for key establishment (Key_Est_Info). For example, the information necessary for key establishment may be an information container used to carry the information necessary for key establishment. The initiating UE and receiving UE exchange Key_Est_Info multiple times to complete the mutual authentication and key establishment procedure, and the root key K of the PC5 unicast link is generated. NRP You may obtain it.

[0159] Optionally, direct communication request messages include the root key identifier (K NRP It may also include ID, and K NRP ID is root key K NRP Identify K NRP This may be a shared key established in a previous mutual authentication and key establishment procedure between the initiating UE and the receiving UE. If the initiating UE can find the receiving UE's identity information and the initiating UE remembers some of the context information between the initiating UE and the receiving UE, the direct communication request message is K NRP It may also include an ID. Furthermore, a previously obtained key may be used directly without negotiating to obtain the key again using Key_Est_Info.

[0160] When establishing security without network support, communication devices need to perform mutual authentication with peer communication devices to obtain authorization from the peer end. However, since security establishment can be completed without network involvement, signaling interaction is small and highly flexible. In addition, once the two communication devices have completed mutual authentication and authorization, the peer end may be considered trusted. Since communication devices do not interact with network devices, they may not obtain the latest subscription information, and authorization may not change for a long period after it has been obtained. Therefore, authorization may be considered static authorization.

[0161] Figure 1 shows a ProSe communication scenario applicable to the security establishment method according to this application. This scenario shows an access network device 110, a number of UEs 121-125, and a core network 130.

[0162] The core network 130 may include multiple network elements having different functions in order to perform different functions. For example, the core network 110 may include, but is not limited to, network elements such as an access and mobility management function (AMF), a session management function (SMF), a user plane function (UPF), a policy control function (PCF), and uniform data management (UDM). The network elements may be configured to perform their respective functions. For example, the AMF may be configured to perform mobility management and access management. The SMF may be configured to manage sessions, assign and manage Internet Protocol (IP) addresses of terminal devices, select and manage user plane function endpoints, policy control, or billing function interfaces, and notify downlink data. The UPF may be configured to route and forward packets and perform quality of service (QoS) processing on user plane data. The PCF may be configured to provide guidance on an integrated policy framework for network behavior and to provide policy rule information for control plane functions (e.g., AMF or SMF) network elements. The UDM may be configured to store user data such as subscription information and authentication / authorization information. The specific network elements included in the core network 120, as well as the functions, number, and form of the network elements, are not limited in this application.

[0163] The access network device 110 may be connected to the core network 130 and configured to provide network access functionality to authorized terminals within its coverage, manage radio resources, and complete the transfer of control signals and user data between terminal devices and the core network 130. As shown in the figure, authorized terminals UE121 and UE122 are assumed to be within the coverage of the access network device 110 and able to successfully establish a connection to the network. UE123-UE125 are outside the coverage of the access network device 110 and are unable to successfully establish a connection to the network.

[0164] Communication between UE121 and UE122, between UE121 and UE124, between UE122 and UE123, and between UE124 and UE125 may be conducted via the PC5 interface. If UE121 expects to communicate with UE123 via the PC5 interface, but UE121 is far from UE123, and UE123 is outside of UE121's signal coverage, or the communication quality is poor, UE121 may use UE122 to assist with communication. In this case, UE122 is an example of a relay UE between UE121 and UE123, i.e., the aforementioned U2U Relay, with UE121 being an example of a source UE and UE123 being an example of a target UE. If UE121 is expected to communicate with UE125 via the PC5 interface, but UE121 is far from UE125 and UE125 is outside of UE121's signal coverage or the communication quality is poor, UE121 may use UE124 to assist with communication. In this case, UE124 is a relay UE between UE121 and UE125, i.e., another example of the U2U Relay described above, with UE121 being an example of a source UE and UE125 being another example of a target UE.

[0165] UE122 is within the coverage of access network device 110 and can successfully establish a connection to the network, while UE124 is outside the coverage of access network device 110 and cannot successfully establish a connection to the network. However, the security establishment mechanism supported by the relay UE differs depending on the network coverage status of the relay UE.

[0166] To ensure communication security, the diagram shows that secure connections must be established between UE121 and UE122, between UE122 and UE123, between UE121 and UE124, and between UE124 and UE125. However, in the U2U Relay scenario, how to establish security between the end UE and the relay UE is not specified in conventional technical standards. Therefore, how to establish security between the end UE and the relay UE remains an urgent technical issue that needs to be resolved.

[0167] With this in mind, the present application provides a method for providing a plurality of optional security establishment mechanisms to an end UE using ProSe for communication, to adapt to different network coverage statuses of a relay UE. In this way, the security establishment mechanism may be adapted to complete security establishment between the relay UE and the end UE, regardless of whether the relay UE is in or out of network coverage, thereby ensuring the security of the ProSe communication.

[0168] The method provided herein is provided for establishing security between a source UE and a relay UE for ProSe communication in a U2U relay service, but it should be understood that this does not constitute any limitation on the scope of application of the method. For example, after the establishment of security between the source UE and the relay UE for ProSe communication is completed, the relay UE may further establish security with a target UE for ProSe communication. In this case, the relay UE may also use the method provided below to establish security with the target UE. For ease of understanding and explanation, the method provided herein will be described below using the establishment of security between a source UE and a relay UE for ProSe communication as an example.

[0169] The security establishment method provided in this application will be described in detail below with reference to the attached drawings.

[0170] It should be noted that the following embodiments describe each procedure in terms of device interaction. The devices are merely examples and do not constitute any limitation to this application. For example, UE1 may be an example of a first communication device, and the components configured within UE1 (e.g., a chip, a chip system, a processor, or another logic module or software that can be configured to perform some or all of the functions of UE1) may be another example of a first communication device. UE2 may be an example of a second communication device, and the components configured within UE2 (e.g., a chip, a chip system, a processor, or another logic module or software that can be configured to perform some or all of the functions of UE2) may be another example of a second communication device.

[0171] UE1 may be the first UE that initiates ProSe communication, or it may correspond to UE121 in Figure 1, for example. UE2 may be a potential relay UE determined by UE1, or it may correspond to UE122 or UE124 in Figure 1, for example. In other words, UE1 expects to establish security with UE2, and then UE2 assists UE1 in establishing ProSe communication with a second UE (e.g., UE3) corresponding to UE123 or UE125 in Figure 1, for example.

[0172] Figure 2 is a schematic flowchart of a security establishment method according to one embodiment of the present application. In the procedure shown in Figure 2, the end UE actively selects a mechanism and negotiates with the relay UE to further determine the mechanism to be used for security establishment between the end UE and the relay UE.

[0173] As shown in Figure 2, Method 200 includes steps 210 to 250. The steps of Method 200 are described in detail below.

[0174] In step 210, UE1 determines a target mechanism from among several mechanisms, which include network-assisted security establishment mechanisms and network-assisted security establishment mechanisms.

[0175] When UE1 determines that ProSe communication with UE3 needs to be performed with the assistance of a relay UE (i.e., U2U Relay), it may choose a target mechanism from among several mechanisms. The relay UE is denoted as UE2.

[0176] For a description of network-assisted security establishment mechanisms (or in-coverage mechanisms) and network-assisted security establishment mechanisms (or out-of-coverage mechanisms), please refer to the related descriptions above. Further details will not be provided again. Please understand that network-assisted and network-assisted security establishment mechanisms are merely two examples of security establishment mechanisms and do not constitute any limitation to this application. This application does not preclude the possibility that the aforementioned mechanisms may further include other security establishment mechanisms, nor does it preclude the possibility that other mechanisms that can be used to implement the same or similar mechanisms may be defined in future technical specifications.

[0177] In this embodiment, the mechanism determined by UE1 is referred to as the target mechanism. UE1 may determine, through negotiation with another communication device (e.g., UE2), that both parties support the target mechanism, and then establish security by using the target mechanism. Therefore, the target mechanism may change during negotiation. For ease of distinction and explanation, the target mechanism determined by UE1 in this instance will be referred to as mechanism 1 below. Mechanism 1 may be an in-coverage mechanism, an out-of-coverage mechanism, or another security establishment mechanism. This is not limited to the present application.

[0178] When determining the target mechanism, it will be understood that UE1 may decide on the target mechanism by referring to information such as UE1's capabilities. Therefore, the target mechanism is a mechanism supported by UE1.

[0179] Optionally, step 210 includes UE1 determining a target mechanism from a plurality of mechanisms according to a mechanism selection rule.

[0180] A mechanism selection rule represents a rule for selecting a target mechanism from among multiple mechanisms. It should be understood that "mechanism selection rule" is merely a name and may also be called, for example, a mechanism selection indicator, selection rule, selection indicator, or pre-configuration rule. The naming of mechanism selection rules is not limited in this application and falls within the scope of protection of this application, provided that the same or similar functionality as that of the mechanism selection rule is implemented.

[0181] In one possible design, the mechanism selection rule is the correspondence between ProSe code and mechanism indicators. In another possible design, the mechanism selection rule is priority information, which indicates the priority order of mechanisms across multiple mechanisms. In yet another possible design, the mechanism selection rule includes the correspondence between RSCs and mechanism indicators, as well as priority information. Below, the correspondence between RSCs and mechanism indicators, and the priority information, will be described in detail separately.

[0182] The correspondence between ProSe code and mechanism indicators: A mechanism indicator may be an indicator used to determine a particular mechanism. Specifically, a mechanism indicator may be used to determine a particular mechanism, or it may directly correspond to a particular mechanism. For example, a mechanism indicator may be an identifier for a mechanism, and each mechanism may be indicated by using one identifier. The UE may index a particular mechanism based on the mechanism identifier. Of course, a mechanism indicator is not limited to an identifier for a mechanism, or it may be other information that can indicate a mechanism or can be used to determine a mechanism. This embodiment will then be illustrated by using an example in which a mechanism indicator is used to further determine a particular mechanism.

[0183] For example, a ProSe code may be an RSC, a ProSe application code, a ProSe discovery code, a ProSe query code, a ProSe response code, etc. This application includes, but is not limited to, these. For ease of explanation, in this embodiment, an RSC is subsequently used as an example for illustrative purposes. Specifically, a possible form of correspondence between a ProSe code and a mechanism indicator is the correspondence between an RSC and a mechanism indicator.

[0184] Each RSC may correspond to one or more mechanism indicators, and different RSCs may correspond to the same mechanism indicator or different mechanism indicators. In other words, the mechanism selection rule is the correspondence between one or more RSCs and one or more mechanism indicators, where each mechanism indicator is used to indicate or determine one of several mechanisms. RSCs may also correspond to U2U Relay services. Different RSCs may correspond to different U2U Relay services, and different RSCs may correspond to the same U2U Relay service.

[0185] In this embodiment, UE1 decides to communicate with UE3 in ProSe with the assistance of a relay UE, and UE1 determines the RSC (referred to as the first RSC for ease of distinction) corresponding to the ProSe communication. Furthermore, UE1 determines the first mechanism indicator corresponding to the first RSC based on the correspondence between the RSC and the mechanism indicator. Since the first mechanism indicator indicates the first mechanism among the aforementioned multiple mechanisms, UE1 may further determine the corresponding first mechanism based on the first mechanism indicator. The correspondence between the RSC and the mechanism indicator is assumed to include the correspondence between the first RSC and the first mechanism indicator, and the first mechanism indicator is assumed to be used to determine the first mechanism. In this case, UE1 may determine the first mechanism as the target mechanism. Note that after locally deciding to use the U2U Relay service, UE1 may further determine the first RSC corresponding to the U2U Relay service, or UE1 may obtain the first RSC from UE2 in the U2U Relay discovery procedure.

[0186] It should be noted that the correspondence between ProSe code and mechanism indicators in this mechanism may include the correspondence between RSC and control plane security mechanism indicators, or the correspondence between RSC and control plane security mechanism indicators may be reused. In other words, the control plane security mechanism indicator indicates whether security should be established by using a control plane mechanism and whether a network-assisted security establishment mechanism should be used. Specifically, if an RSC has a corresponding control plane security mechanism indicator and it is decided based on the control plane security mechanism indicator to use a control plane mechanism, it indicates that the control plane mechanism within the network-assisted security establishment mechanism should be used, or if an RSC has a corresponding control plane security mechanism indicator and it is decided based on the control plane security mechanism indicator to use a user plane mechanism, it indicates that the user plane mechanism within the network-assisted security establishment mechanism should be used. Optionally, if an RSC does not have a corresponding control plane security mechanism indicator, it indicates that a security establishment mechanism without network assistance should be used. Alternatively, the correspondence between ProSe codes and mechanism indicators may not include the correspondence between RSCs and control plane security mechanism indicators, and the correspondence between ProSe codes and mechanism indicators and the correspondence between RSCs and control plane security mechanism indicators may be independent of each other. This is not limited to the present application.

[0187] Optionally, in one embodiment, in the correspondence between the ProSe code and the mechanism indicator in this mechanism, the mechanism indicator may be an in-coverage indicator indicating that a network-assisted security establishment mechanism should be used. Specifically, if the RSC has a corresponding in-coverage indicator, it indicates that a network-assisted security establishment mechanism should be used, or if the RSC does not have a corresponding in-coverage indicator, it indicates that an unassisted security establishment mechanism should be used.

[0188] Optionally, in another embodiment, in the correspondence between the ProSe code and the mechanism indicator in this mechanism, the mechanism indicator may be an out-of-coverage indicator indicating that a network-unassisted security establishment mechanism should be used. Specifically, if the RSC has a corresponding out-of-coverage indicator, it indicates that a network-unassisted security establishment mechanism should be used, or if the RSC does not have a corresponding out-of-coverage indicator, it indicates that a network-unassisted security establishment mechanism should be used.

[0189] Priority Information: The aforementioned mechanisms may each have different priorities. For example, the priority of an in-coverage mechanism may be higher than that of an out-of-coverage mechanism. In another example, the priority of an out-of-coverage mechanism may be higher than that of an in-coverage mechanism. This is not limited to the present application.

[0190] In possible implementations, priority information may include, for example, an indicator of the priority of each mechanism. For example, the priority of each mechanism may be indicated by using different priority values. For example, a higher priority value indicates a higher priority, or a lower priority value indicates a higher priority. For example, priority information may be a priority value table, which records the priority value of each mechanism.

[0191] In another possible embodiment, the priority order of mechanisms may be reflected by the ranking of mechanisms among multiple mechanisms. For example, mechanisms with higher rankings have higher priority, or mechanisms with lower rankings have higher priority. For example, priority information may be in a priority ranking table, and multiple mechanisms may be ranked in the table in descending order of priority.

[0192] In yet another possible embodiment, priority information may include an indicator of the default mechanism, which is the mechanism that is preferentially selected. Therefore, indicating the default mechanism is equivalent to implicitly indicating the mechanism with the highest priority. When multiple mechanisms include the aforementioned in-coverage and out-of-coverage mechanisms, the priority order of two mechanisms is indicated by indicating the default mechanism. If multiple mechanisms include more other mechanisms, the mechanism with the highest priority is indicated by indicating the default mechanism, and the other mechanisms may be considered to have the same priority.

[0193] Based on priority information, UE1 may select the mechanism with the highest priority among multiple mechanisms as the target mechanism.

[0194] The aforementioned correspondence between RSC, mechanism indicators, and priority information may be used separately or in combination. For example, a first RSC corresponding to ProSe communication may correspond to multiple mechanism indicators; in other words, a first RSC may correspond to multiple mechanism indicators, and multiple mechanism indicators may be used to determine multiple first mechanisms. In this case, UE1 may refer to priority information to further determine a mechanism from the multiple first mechanisms as a target mechanism.

[0195] In another possible embodiment, UE1 determines the target mechanism based on pre-configured information, which indicates the target mechanism used by UE1 by default. It will be understood that the target mechanisms indicated by the pre-configured information on different UEs may be different mechanisms or the same mechanism.

[0196] Optionally, before step 210, the method further includes step 220: UE1 obtains the mechanism selection rule.

[0197] Step 220 may further include the following steps: Step 220a: UE1 locally obtains the mechanism selection rule, and / or Step 220b: UE1 retrieves mechanism selection rules from the core network, for example, UE1 retrieves mechanism selection rules from the PCF, which is used as an example for explanation below.

[0198] In step 220a, the mechanism selection rules obtained locally by UE1 may be pre-stored in the subscriber identity module (SIM) of UE1, or they may be pre-configured on the device before delivery.

[0199] In step 220b, UE1 may obtain the mechanism selection rules while retrieving the ProSe parameters from the PCF.

[0200] For example, the mechanism selection rule may be determined by the PCF based on indicators of the mechanism selection rule. Indicators of the mechanism selection rule may be understood as information used to determine the mechanism selection rule. For example, this information may be priority information and / or the aforementioned correspondence between the RSC and the mechanism indicator, or other information used to determine the aforementioned correspondence between the RSC and the mechanism indicator and / or the priority information. This is not limited to the present application.

[0201] In a possible design, indicators of mechanism selection rules are included in the service-specific information of the UE1's ProSe, and the PCF may obtain indicators of mechanism selection rules by obtaining the service-specific information of the ProSe to further determine the mechanism selection rules. The figure shows an example of the process by which UE1 obtains mechanism selection rules from the PCF. As shown in the figure, UE1 may send a ProSe parameter retrieval request to the PCF via the AMF, and the PCF may retrieve the service-specific information of the UE1's ProSe from the UDM based on the request. Optionally, the ProSe parameter retrieval request sent to the PCF by the AMF may carry the UE1's SUPI, and the PCF may retrieve the UE1's ProSe's service-specific information from the UDM based on the UE1's SUPI. After obtaining the ProSe's service-specific information, the PCF may determine the mechanism selection rules based on the information used to determine the mechanism selection rules within the service-specific information and send the mechanism selection rules to UE1. As shown in the figure, the PCF may send the mechanism selection rules to UE1 via a UE configuration update (UCU) procedure. In other words, the mechanism selection rules may be conveyed in UCU messages.

[0202] Optionally, before AMF sends a ProSe parameter acquisition request to PCF, the method further includes AMF determining that UE1 can perform ProSe communication. For example, UE1 may perform ProSe communication with the assistance of U2U Relay, or the U2U Relay service may be used.

[0203] Optionally, before the PCF sends the mechanism selection rules to UE1, the method further includes the PCF determining whether UE1 can perform ProSe communication. For example, UE1 may perform ProSe communication with the assistance of U2U Relay, or the U2U Relay service may be used.

[0204] The UDM stores subscription information for each subscriber UE, for example, the subscription information for UE1. The subscription information for UE1 records whether UE1 is a ProSe subscriber. It should be understood that whether a UE is a ProSe subscriber can be understood as whether the UE has ProSe functionality. If a UE is a subscriber, the UE has ProSe functionality and can obtain ProSe authorization. If a UE is not a subscriber, the UE does not have ProSe functionality and cannot obtain ProSe authorization. Furthermore, if UE1 is a ProSe subscriber, the subscription information also includes ProSe service-specific information. If UE1 is not a ProSe subscriber, the UDM may respond to the PCF with a message indicating that UE1 does not have ProSe functionality. In this case, UE1 cannot obtain mechanism selection rules from the PCF.

[0205] It should be understood that the aforementioned example with reference to Figure 2 is merely a possible design and does not constitute any limitation to this application. Alternatively, the mechanism selection rule indicator may not be included in the ProSe's service-specific information, or it may be included in other information, for example, the UE1's subscription information, or it may not be included in the UE1's subscription information. Alternatively, the PCF may send the mechanism selection rule to the UE1 via a different procedure or message.

[0206] UE1 may perform step 220a without performing step 220b, or perform step 220b without performing step 220a, or perform both steps 220a and 220b. When UE1 performs steps 220a and 220b, UE1 may obtain multiple mechanism selection rules. UE1 may use the mechanism selection rules according to a pre-configured priority order. For example, the pre-configured priority order may be such that the priority of mechanism selection rules obtained from the PCF is higher than the priority of mechanism selection rules obtained locally by UE1, and the priority of mechanism selection rules obtained from the SIM by UE1 is higher than the priority of mechanism selection rules pre-configured by UE1 before device delivery.

[0207] In step 230, UE1 sends a request message, which is used to request the communication device receiving the request message to establish a security relationship with UE1 by using the target mechanism.

[0208] In a possible embodiment of step 230, UE1 sends a request message to UE2, specifically, UE1 sends the request message to UE2 in a unicast manner.

[0209] For example, UE1 and UE2 may discover each other separately through a discovery procedure. Since UE1 expects the relay UE to assist UE1 in communicating with UE3 via ProSe, UE1 may send the aforementioned request message to UE2 after discovering UE2. The request message may be used to request UE2 to establish security with UE1 by using the target mechanism. In response, in step 220, UE2 receives the request message.

[0210] In another possible embodiment of step 230, UE1 broadcasts the request message. In other words, UE1 does not anticipate the recipient of the request message. There may be one or more communication devices that receive the request message. Correspondingly, in step 220, one or more communication devices receive the request message. In this embodiment, one or more communication devices may include UE2.

[0211] Optionally, before step 230, the method further includes UE1 and UE2 performing discovery steps.

[0212] An example of how UE1 and UE2 perform the discovery procedure is as follows: UE1 and UE2 may separately send broadcast messages on the PC5 interface, and these broadcast messages carry a first RSC. The first RSC may be a parameter obtained separately by UE1 and UE2 during the ProSe parameter configuration phase. The ProSe parameter configuration process for UE1 and UE2 may be performed during the process of UE1 and UE2 registering with the network, or after UE1 and UE2 have registered with the network. Alternatively, the ProSe parameters may be default parameters pre-configured on the device. Since both the broadcast messages from UE1 and UE2 carry the first RSC, this indicates that UE1 and UE2 have ProSe capabilities and that UE2 can provide UE1 with a U2U Relay service. Therefore, UE1 may determine UE2 to be a potential relay UE. UE2 is called a potential relay UE because, in this case, UE1 has not established a secure connection with UE2 and UE1 cannot communicate with another UE (e.g., UE3) with the assistance of UE2.

[0213] For specific details on the process by which UE1 and UE2 perform the discovery procedure, please refer to the relevant descriptions in the 3GPP technical specifications. Further details are not provided herein.

[0214] It should be understood that the discovery procedure performed by UE1 and UE2 is merely one possible embodiment of how UE1 and UE2 can discover each other. Alternatively, UE1 may directly send the aforementioned request message to discover UE2 without performing the discovery procedure.

[0215] Optionally, prior to step 230, the method further includes UE1 and UE2 performing ProSe parameter configuration to obtain ProSe parameters. The ProSe parameters include the aforementioned correspondence between ProSe code and mechanism indicators, and the correspondence between ProSe code and mechanisms may include the correspondence between the first RSC and the first mechanism indicator. Optionally, the correspondence between ProSe code and mechanism indicators may include the correspondence between the RSC and the control plane security mechanism indicator. Alternatively, in another design, the ProSe parameters include the correspondence between ProSe code and mechanism indicators and the correspondence between the RSC and the control plane security mechanism indicator. For the correspondence between the RSC and the control plane security mechanism indicator, see the relevant explanation of “Network-Assisted Security Establishment Mechanism” in the glossary above. Further details are not provided again. The ProSe parameter configuration process for UE1 and UE2 may be performed separately during the process of UE1 and UE2 registering with the network, or after UE1 and UE2 have registered with the network. Alternatively, the ProSe parameters may be pre-configured default parameters for the device (in this case, the pre-configuration process may be considered a ProSe parameter configuration process).

[0216] In this embodiment of the present application, the request message may indicate a target mechanism or may be used to determine a target mechanism.

[0217] In a possible design, the request message is a DCR message, and the information elements within the DCR correspond to the target mechanism. In other words, the DCR message may indicate the target mechanism.

[0218] Table 1 below shows examples of information elements in DCR messages corresponding to in-coverage and out-of-coverage mechanisms, respectively. Table 2 further shows examples of information elements in DCR messages corresponding to control plane mechanisms and user plane mechanisms, respectively. The first column lists the information elements currently defined in DCR messages, listing the information elements included in DCR messages corresponding to out-of-coverage mechanisms and those included in DCR messages corresponding to in-coverage mechanisms. Information elements marked "Optional" indicate that the information element is optional in the DCR message, while information elements not marked "Optional" indicate that the information element is required in the DCR message. Referring to the second and third columns, "None" in each row indicates that a DCR message corresponding to a different mechanism does not contain the information element corresponding to that row, and "Present" indicates that a DCR message corresponding to a different mechanism contains the information element corresponding to that row. The content of each row indicates that a DCR message corresponding to a different mechanism contains the information element corresponding to that row and is defined by a different type.

[0219] [Table 1]

[0220] [Table 2]

[0221] In Tables 1 and 2, source user information is source user information. Source user information may be user information of the source UE (e.g., UE1 in this embodiment), or more specifically, the application layer identifier (ID) (initiating UE's app layer ID) of the initiating UE. ProSe Identifier is the ProSe identifier, which may be the identifier of the ProSe application corresponding to the U2U Relay service (e.g., in this embodiment, UE1 uses UE2's relay service to establish the subsequent unicast link). Target user information is target user information, which may be the target UE (e.g., UE3, which UE1 expects to perform ProSe communication in this embodiment, or UE2 in this embodiment). Target UE's app layer ID is the application layer ID of the target user. User info ID is the user information ID. Key_est_info is key establishment information (key_est_info), which may be, for example, an information container used for mutual authentication and unicast key establishment. Nonce_1 and K NRP Both freshness parameter 1 values ​​are random numbers, specifically, random numbers provided by the initiator to generate the PC5 key, or defined by different names in DCR messages corresponding to different mechanisms. NRP The ID is the root key K of the link. NRP This is the ID and is only transported if the root key already exists. UE security capabilities are UE security capabilities and may specifically include PC5 security algorithms supported by the UE. MSB of K NRP-sess The ID is the session key K NRP-sessThis is the most significant bit (MSB) of the ID. The UE PC5 signaling security policy is the UE PC5 signaling security policy. The UE ID is the identifier of the UE. If a DCR message corresponding to an in-coverage mechanism does not carry the UP-PRUK ID and CP-PRUK ID (in other words, the DCR message does not include the information element User security key ID), then the SUCI of the UE sending the DCR message must carry this information element. The User security key ID is the user security key ID, which may specifically be the security key ID of the initiating UE, or it may be classified into an UP-PRUK ID and a CP-PRUK ID based on the difference between the user plane mechanism and the control plane mechanism in the in-coverage mechanism. The HPLMN ID is the ID of the home public land mobile network (HPLMN), which may specifically be the HPLMN ID of the initiating UE. MIC is the message integrity check (MIC) code. The source L2 ID is the source end Layer 2 (L2) ID, and the source end may be the device from which the DCR message originates (e.g., UE1 in this embodiment). The destination L2 ID is the peer end Layer 2 ID, and the peer end may be the device to which the DCR message is sent. In the case of unicast, the destination L2 ID may be the L2 ID of the device unicasting to UE1 (e.g., UE2 in this embodiment). In the case of broadcast or multicast, the destination L2 ID may be a dedicated default ID for broadcast or multicast.

[0222] Tables 1 and 2 show that the information elements included in DCR messages corresponding to in-coverage and out-of-coverage mechanisms are not entirely the same. For example, the DCR message corresponding to an out-of-coverage mechanism contains the following information elements: source user information, ProSe Identifier, target user information, key_est_info, Nonce_1, UE security capabilities, and MSB of K NRP-sess ID, K NRP The DCR message corresponding to the in-coverage mechanism includes one or more of the following information elements: ID, UE PC5 signaling security policy, source L2 ID, or destination L2 ID. NRP-sess This includes one or more of the following: ID, UE PC5 signaling security policy, RSC, UTC-based counter LSB, UE ID, user security key ID, HPLMN ID, MIC, source L2 ID, or destination L2 ID.

[0223] The comparison reveals that DCR messages corresponding to out-of-coverage mechanisms include the information element key_est_info and optionally further include the information element ProSe Identifier, while DCR messages corresponding to in-coverage mechanisms include the information element UE ID or user security key ID and optionally further include the information elements UTC-based counter LSB and RSC. In other words, DCR messages corresponding to out-of-coverage mechanisms do not include the information elements UE ID and user security key ID and optionally do not include the information elements UTC-based counter LSB and RSC. DCR messages corresponding to in-coverage mechanisms do not include the information element key_est_info and optionally do not include the information element ProSe Identifier.

[0224] In other words, a DCR message corresponding to an out-of-coverage mechanism satisfies the following conditions: it includes at least one of the information elements ProSe Identifier or key_est_info, and / or excludes the information elements UE ID and User security key ID. A DCR message corresponding to an in-coverage mechanism satisfies the following conditions: it includes at least one of the information elements UE ID, User security key ID, UTC-based counter LSB, or RSC, and / or excludes the information element key_est_info.

[0225] In another embodiment, the information element UE ID may be named SUCI, and the information element user security key ID may also be distinguished and named as CP-PRUK ID and UP-PRUK ID based on different mechanisms. Thus, the aforementioned information element UE ID may also be replaced with SUCI, and the information element user security key ID may also be replaced with CP-PRUK ID or UP-PRUK ID. For example, the inclusion of an information element UE ID or user security key ID in a DCR message corresponding to an in-coverage mechanism may be replaced with the inclusion of one of the information elements SUCI, CP-PRUK ID, and UP-PRUK ID in a DCR message corresponding to an in-coverage mechanism.

[0226] If UE1 needs to establish security by using an out-of-coverage mechanism, the DCR message typically carries the information element key_est_info. In other words, for an out-of-coverage mechanism, the information element key_est_info may differ from that for an in-coverage mechanism. Therefore, whether a DCR message indicates an out-of-coverage mechanism may be determined based on whether the DCR message contains key_est_info. Optionally, for an out-of-coverage mechanism, the information element ProSe Identifier is a required information element. Therefore, whether a DCR message indicates an out-of-coverage mechanism may be determined based on whether the DCR message contains ProSe Identifier.

[0227] If UE1 needs to establish security by using an in-coverage mechanism, the DCR message typically carries the information element UE ID or user security key ID. In other words, for in-coverage mechanisms, the information element UE ID or user security key ID may be distinguished from the information element UE ID or user security key ID for out-of-coverage mechanisms. Therefore, whether a DCR message indicates an in-coverage mechanism may be determined based on whether the DCR message contains the UE ID or user security key ID.

[0228] Optionally, for in-coverage mechanisms, the information elements UTC-based counter LSB and RSC are mandatory. Therefore, whether a DCR message indicates an in-coverage mechanism may be determined based on whether the DCR message contains UTC-based counter LSB and RSC. Both DCR messages corresponding to control plane mechanisms and DCR messages corresponding to user plane mechanisms contain the information element RSC, but different mechanisms correspond to different RSC values. Since RSC is a mandatory information element in DCR messages corresponding to in-coverage mechanisms, the RSC in a DCR message may be used to help the receiver determine whether the target mechanism is a control plane mechanism or a user plane mechanism. As described above, UE1 may obtain the correspondence between RSC and mechanism before step 230. Therefore, UE1 may determine the target mechanism based on the correspondence and a first RSC corresponding to ProSe communication. Correspondingly, UE2 may decide to use a control plane mechanism or a user plane mechanism based on the correspondence and RSC in the DCR message.

[0229] DCR messages corresponding to user plane mechanisms optionally include an HPLMN ID. Therefore, if a DCR message includes an HPLMN ID, it may indicate that the target mechanism is a user plane mechanism.

[0230] Furthermore, while DCR messages corresponding to different mechanisms may contain the same information elements, the types of information elements do not necessarily have to be the same. For example, in a DCR message corresponding to an out-of-coverage mechanism, the type of the information element `target user information` is the `target UE's app layer ID`, while in a DCR message corresponding to an in-coverage mechanism, the type of the information element `target user information` is the `User info ID`. In a DCR message, information elements include a `type-length-value` (TLV) field, and the `target UE's app layer ID` for out-of-coverage mechanisms and the `User info ID` for in-coverage mechanisms may be distinguished by using the `type` field. Thus, the information element `target user information` can indicate whether the target mechanism is an in-coverage or out-of-coverage mechanism.

[0231] In another example, a DCR message corresponding to an in-coverage mechanism optionally includes the information element user security key ID. In a DCR message corresponding to a control plane mechanism, the type of the information element user security key ID is CP-PRUK ID. In a DCR message corresponding to a user plane mechanism, the type of the information element user security key ID is UP-PRUK ID. In a DCR message, the information element may also include a TLV field, and the CP-PRUK ID for control plane mechanisms and the UP-PRUK ID for user plane mechanisms may be distinguished by using the type within the field. Thus, the information element user security key ID may also indicate whether the target mechanism is a control plane mechanism or a user plane mechanism.

[0232] The above describes in detail request messages corresponding to different mechanisms and the process of determining the target mechanism based on the request message, using the DCR message as an example of a request message. These examples are provided solely for the purpose of facilitating understanding. This application does not preclude the request to define a different request message in a future protocol to perform the same or similar function as the DCR message, or the possibility of defining more or fewer information elements within the request message and distinguishing different mechanisms by using other information elements.

[0233] In step 240, UE2 sends a first message to UE1 based on the network coverage status, indicating whether it should agree to establish security with UE1 by using the target mechanism. In response, UE1 receives the first message.

[0234] In this embodiment, the communication device that receives the request message may include UE2. Without loss of generality, the following steps will be described using an example in which UE2 is used as the communication device that receives the request message.

[0235] The above illustrates how a request message indicates a target mechanism, using a DCR message as an example. Based on the same principle, UE2 may determine the target mechanism based on the received request message and further decide whether it should agree to establish security with UE1 by using the target mechanism.

[0236] As described above, UE2, which has been determined to be a potential relay UE, may be within network coverage, for example UE122 in Figure 1, or it may not be within network coverage, for example UE124 in Figure 1. Based on the network coverage status, UE2 may decide whether to agree to establish security by using the target mechanism requested by UE1.

[0237] Where possible, the network coverage status of UE2 is within network coverage, and UE2 may establish security by using an in-coverage mechanism or by using an out-of-coverage mechanism. Therefore, regardless of whether the target mechanism requested by UE1 is an in-coverage mechanism or an out-of-coverage mechanism, UE2 may agree to establish security by using the target mechanism. In this case, the first message sent by UE2 may indicate that it agrees to establish security with UE1 by using the target mechanism.

[0238] In another possible case, when UE2's network coverage status is within network coverage, UE2 defaults to establishing security by using the in-coverage mechanism and not by using the out-of-coverage mechanism. Therefore, if the target mechanism requested by UE1 is an out-of-coverage mechanism, UE2 does not have to agree to establish security by using the target mechanism. In this case, the first message sent by UE2 may indicate that it does not agree to establish security with UE1 by using the target mechanism. If the target mechanism requested by UE1 is an in-coverage mechanism, UE2 may agree to establish security by using the target mechanism. In this case, the first message sent by UE2 may indicate that it agrees to establish security with UE1 by using the target mechanism.

[0239] In yet another possible case, the network coverage status of UE2 is not within network coverage, and UE2 may establish security by using an out-of-coverage mechanism, but cannot establish security by using an in-coverage mechanism. Therefore, if the target mechanism requested by UE1 is an out-of-coverage mechanism, UE2 may agree to establish security by using the target mechanism, or if the target mechanism requested by UE1 is an in-coverage mechanism, UE2 may not agree to establish security by using the target mechanism.

[0240] UE2 may use different messages to indicate whether it agrees to establish security with UE1 by using the target mechanism.

[0241] For example, the target mechanism may be an out-of-coverage mechanism, and the first message may be a direct authentication and key establishment message, which indicates agreement to establish security with UE1 by using an out-of-coverage mechanism, as shown in 240a in the figure. Since the direct authentication and key establishment message is an existing message applicable to an out-of-coverage mechanism, it can implicitly indicate agreement to establish security with UE1 by using an out-of-coverage mechanism.

[0242] In another example, the target mechanism is an in-coverage mechanism, and the first message may be a direct security mode command message, which indicates agreement to establish security with UE1 by using the in-coverage mechanism, as shown in 240b in the figure. Since the direct security mode command message is an existing message that applies to the in-coverage mechanism, the direct security mode command message can implicitly indicate agreement to establish security with UE1 by using the in-coverage mechanism.

[0243] Note that in both the current in-coverage mechanism procedure and the current out-of-coverage mechanism procedure, UE2 sends a direct security mode command message to UE1. Therefore, in this embodiment, UE2 sends a direct security mode command message to UE1 when it agrees to use an in-coverage or out-of-coverage mechanism. UE1 may decide whether to agree that UE2 will establish security with UE1 by using an in-coverage or out-of-coverage mechanism, based on a first message received from UE2 after the request message was sent in step 210. Therefore, if the target mechanism is an in-coverage mechanism and UE2 agrees to use an in-coverage mechanism, the first message may be a direct security mode command message, and UE2 does not send a direct authentication and key establishment message to UE1 before sending the first message to UE1. In this case, the direct security mode command message may implicitly indicate agreement to establish security with UE1 by using an in-coverage mechanism. As another example, as shown in 240c in the diagram, when UE2 decides, based on the network coverage status, not to agree to establish security by using the target mechanism, the first message may be a reject message, and the reject message indicates that it does not agree to use the target mechanism.

[0244] Furthermore, the rejection message may indicate the reasons for not agreeing to use the target mechanism, one or more of the security establishment mechanisms supported by UE2, or security establishment mechanisms not supported by UE2.

[0245] For example, the reason why UE2 does not agree to use the target mechanism may be indicated by using a reason value. The correspondence between each reason value and the reason it indicates may be predefined and pre-stored in UE1 and UE2. For example, reason value 1 indicates that the target mechanism is not supported, and reason value 2 indicates that it is not within network coverage.

[0246] It will be understood that if the rejection message indicates that UE2 does not support the target mechanism, UE1 may attempt to negotiate with UE2 by using a different target mechanism; if the rejection message indicates that UE2 is not within network coverage, UE1 may choose to establish PC5 link security by using an out-of-coverage mechanism; or if the rejection message indicates that UE2 is not within network coverage and UE1 needs to establish PC5 link security by using an in-coverage mechanism, UE1 may choose another potential relay UE.

[0247] For example, if UE2's network coverage status is not within network coverage and the target mechanism is an in-coverage mechanism, UE2 may carry reason value 2 in its reject message to indicate that the reason for not agreeing to use the target mechanism is that it is not within network coverage. As another example, if UE2 does not support in-coverage mechanisms and the target mechanism is an in-coverage mechanism, UE2 may carry reason value 1 in its reject message to indicate that the reason for not agreeing to use the target mechanism is that it is not supported.

[0248] Please understand that the aforementioned examples and reason values ​​for reasons for not agreeing to use the target mechanism are provided solely for the purpose of facilitating understanding. Reasons, reason values, and the correspondence between reasons and reason values ​​are not limited in this application.

[0249] UE2 may further indicate that the mechanisms supported by UE2 include out-of-coverage mechanisms by using rejection messages.

[0250] The mechanisms supported by UE2 are indicated by the use of a rejection message, and as a result, when UE1 next selects a target mechanism to negotiate with UE2, it can select a mechanism supported by UE2, allowing the two parties to complete security establishment as quickly as possible. In this way, UE1 can establish ProSe communication with UE3 as quickly as possible.

[0251] It should be understood that mechanisms supported by UE2 may be implicitly indicated by using alternative mechanisms not supported by UE2. Several security establishment mechanisms, such as the aforementioned in-coverage and out-of-coverage mechanisms, are predefined. In the case of UE2, the mechanisms supported and not supported by UE2 form a universal set of the aforementioned mechanisms. In other words, the mechanisms supported and not supported by UE2 are complementary. Therefore, mechanisms supported by UE2 may be derived from mechanisms not supported by UE2.

[0252] Optionally, rejecting the message is a message that will be protected by security measures.

[0253] For example, each piece of information carried in a rejection message may be information obtained after confidentiality and / or integrity protection has been performed, or the rejection message may be a message obtained after confidentiality and / or integrity protection has been performed. The key used for confidentiality and / or integrity protection may be a key obtained by UE2 and UE1 in the discovery procedure. Optionally, the key used for confidentiality and / or integrity protection may be determined based on long-term credentials pre-configured in UE2.

[0254] In response to this, after receiving a message to be secured, UE1 may first perform a decryption and / or integrity check, and then extract valid information from the message. It will be understood that the key used by UE1 to perform the decryption and / or integrity check may also be a key obtained by UE1 and UE2 in the discovery procedure. Optionally, the key used for the decryption and / or integrity check may be determined based on long-term credentials pre-configured in UE1.

[0255] Whether UE2 protects the confidentiality and / or integrity of each piece of information within a rejection message, or protects the confidentiality and / or integrity of the rejection message itself, may be predefined in the protocol. UE2 may decrypt and / or check the integrity of received messages according to the same rules.

[0256] Confidentiality and / or integrity protection are implemented, and as a result, the information within the rejection message is protected, preventing it from being intercepted by a third party. This prevents the secure connection subsequently established between UE1 and UE2 from being intercepted by a third party, thus providing a greater guarantee of communication security.

[0257] A rejection message indicates one or more of the aforementioned items, and as a result, UE1 can re-select a target mechanism based on the rejection message and further negotiate with UE2 to determine a security establishment mechanism. For example, UE1 may select a target mechanism by repeating step 210 above, or it may negotiate with UE2 to obtain a security establishment mechanism by repeating steps 230 and 240. When repeating step 210, it will be understood that UE1 may exclude previously used target mechanisms and select a mechanism from other mechanisms as the target mechanism. For example, the previously determined target mechanism is mechanism 1, and the currently determined target mechanism is mechanism 2. When UE1 repeats step 230, the target mechanism requested to be used is the re-selected target mechanism, e.g., mechanism 2. When UE1 repeats step 240, the message received from UE2 may also be different from the previous message. For example, UE1 may have previously received a rejection message and is now receiving a direct authentication and key establishment message or a direct security mode command message, or it may receive a rejection message. For the sake of clarity in the following explanation, we will assume that direct authentication and key establishment messages or direct security mode command messages are currently received, but rejection messages are not. In other words, UE2 agrees to establish security with UE1 by using Mechanism 2.

[0258] It should be understood that the first message described above is merely an example and does not constitute any limitation to this application. Alternatively, the first message may indicate in a different manner whether consent should be given to establishing security with UE1 by using a target mechanism. For example, an instruction field within the first message may indicate whether consent should be given to establishing security with UE1 by using a target mechanism. For example, instruction field "0" indicates that consent is not given to using a target mechanism, and instruction field "1" indicates that consent is given to using a target mechanism. In another example, instruction field "00" indicates that consent is not given to using a target mechanism, instruction field "01" indicates that consent is given to using an in-coverage mechanism as a target mechanism, and instruction field "10" indicates that consent is given to using an out-of-coverage mechanism as a target mechanism. The specific manner in which the first message indicates whether consent should be given to using a target mechanism is not limited in this application.

[0259] In step 250, UE1 establishes security with UE2.

[0260] After obtaining a security establishment mechanism through negotiation with UE2, UE1 may establish security by using the mechanism.

[0261] As described above, when performing step 240, UE2 may send a first message by performing step 240a or 240b to indicate its agreement to establish security by using mechanism 1. In this case, UE1 may establish security with UE2 by using mechanism 1. Alternatively, UE2 may send a first message by performing step 240c to indicate its disagreement with establishing security by using mechanism 1. UE1 may again send a request message to UE2 to request that security be established by using mechanism 2. When performing step 240 again, UE2 may send a first message by performing step 240a or 240b to indicate its agreement to establish security by using mechanism 2. In this case, UE1 may establish security with UE2 by using mechanism 2.

[0262] Where possible, UE1 may receive multiple first messages from multiple UEs. For example, UE1 may send a request message in a broadcast manner in step 230, and there may be multiple UEs that receive the request message. Some or all of the multiple UEs (including UE2) that receive the request message may perform step 240 and send a first message to UE1. In this case, UE1 may perform subsequent steps based on the first message received first, or based on the first message received first, such as an agreement to use the target mechanism. How UE1 handles receiving multiple first messages depends on the internal implementation of UE1, and is not limited to this application.

[0263] As described above, when the first message indicates consent to use the target mechanism, messages within the security establishment procedure corresponding to the target mechanism may implicitly indicate consent to use the target mechanism. For example, a direct security mode command message implicitly indicates a security establishment mechanism with network assistance, while a direct authentication and key establishment message implicitly indicates a security establishment mechanism without network assistance. Therefore, the transmission of the first message by the second communication device to the first communication device can also be understood as the second communication device establishing security with the first communication device by using the target mechanism. In other words, step 240 described above may be included in step 250, or either step 240 or step 250 may be performed.

[0264] In this embodiment of the present application, UE1, which initiates ProSe communication, may select a target mechanism from a plurality of mechanisms and negotiate with a communication device (e.g., UE2) that receives the request message by sending a request message indicating the target mechanism. If UE2 agrees, the target mechanism is used for security establishment. If UE2 does not agree, the target mechanism is re-determined to continue peer negotiation. Thus, the security mechanism may be a security mechanism supported by both UE1 and UE2. This facilitates the successful establishment of a secure connection.

[0265] Furthermore, this mechanism provides multiple mechanisms for UE1 and UE2 to negotiate, and different network conditions are considered in multiple mechanisms. In one embodiment, an out-of-coverage mechanism is provided for cases where UE2 is not in network coverage, and as a result, UE2, which is not in network coverage, can also establish a communication connection with UE1, without relying on network assistance. For example, in the scenario shown in Figure 1, UE121 expects UE124 to assist with communication between UE121 and UE125. However, UE124 is not in network coverage, but may establish a security connection with UE121 by using the out-of-coverage mechanism to provide strong support for communication between UE121 and UE125. In another embodiment, an in-coverage mechanism is provided when UE2 is in network coverage. The network device may establish a security connection for UE1 based on the latest subscription information to ensure the successful establishment of the security connection. For example, in the scenario shown in Figure 1, UE121 expects UE122 to assist with communication between UE121 and UE123, and UE122 is precisely within network coverage. Therefore, UE121 may establish security with UE122 by using either an in-coverage or out-of-coverage mechanism. When an in-coverage mechanism is used to establish security, the network device can decide whether to authorize UE121 and UE122 based on the most up-to-date subscription information, thus avoiding security establishment failures that could be caused by changes in authorization.

[0266] Figure 3 is a schematic flowchart of a security establishment method according to one embodiment of the present application. The procedure shown in Figure 3 describes a mechanism in which a potential relay UE selects a mechanism and provides feedback to the end UE.

[0267] Method 300, shown in Figure 3, may include steps 310 to 340. The steps of Method 300 are described in detail below.

[0268] In step 310, UE1 sends at least one request message, which indicates multiple mechanisms, including a security establishment mechanism with network assistance and a security establishment mechanism without network assistance.

[0269] Optionally, at least one request message may indicate multiple mechanisms, which include a user plane mechanism within a network-assisted security establishment mechanism, a control plane mechanism within a network-assisted security establishment mechanism, and a security establishment mechanism without network assistance.

[0270] For explanations of security establishment mechanisms with and without network support, please refer to the relevant explanations in the above glossary. Further details will not be provided again. Please understand that security establishment mechanisms with and without network support are merely two examples of security establishment mechanisms and do not constitute any limitation to this application. This application does not preclude the possibility that the aforementioned mechanisms may further include other security establishment mechanisms, nor does it preclude the possibility that other mechanisms that can be used to implement the same or similar mechanisms may be defined in future technical specifications.

[0271] Optionally, a plurality of mechanisms may correspond to a plurality of request messages, or each request message may indicate one mechanism. Correspondingly, step 310 includes step 310a, where UE1 transmits a plurality of request messages, each request message indicates one mechanism, and the mechanisms corresponding to the plurality of request messages include a security establishment mechanism with network assistance (i.e., an in-coverage mechanism) and a security establishment mechanism without network assistance (i.e., an out-of-coverage mechanism).

[0272] For example, the plurality of mechanisms include an in-coverage mechanism (e.g., a control plane mechanism or a user plane mechanism) and an out-of-coverage mechanism, and at least one request message includes a request message corresponding to the in-coverage mechanism and a request message corresponding to the out-of-coverage mechanism.

[0273] As another example, the plurality of mechanisms include a control plane mechanism, a user plane mechanism, and an out-of-coverage mechanism, and at least one request message includes a request message corresponding to the control plane mechanism, a request message corresponding to the user plane mechanism, and a request message corresponding to the out-of-coverage mechanism.

[0274] The information element in each request message may correspond to one mechanism, or each request message may indicate one mechanism. For details regarding the information element in the request message corresponding to each mechanism, refer to the aforementioned related description where the DCR message is used as an example in combination with Table 1 and Table 2. The details will not be described again.

[0275] Optionally, at least one request message is a single request message, and the request message indicates multiple mechanisms. Correspondingly, step 310 includes step 310b, in which UE1 sends a single request message, the request message indicates multiple mechanisms, and the multiple mechanisms include a security establishment mechanism with network assistance and a security establishment mechanism without network assistance. Furthermore, the multiple mechanisms may include a user plane mechanism and an out-of-coverage mechanism, or the multiple mechanisms may include a control plane mechanism and an out-of-coverage mechanism, or the multiple mechanisms may include a user plane mechanism, a control plane mechanism, and an out-of-coverage mechanism.

[0276] In a possible design, the request message contains information elements corresponding to each of the multiple mechanisms. The aforementioned DCR message is used as an example. When multiple mechanisms are indicated by using a single DCR message, the DCR message contains the following information elements: source user information, ProSe Identifier, target user information, key_est_info, Nonce_1, UE security capabilities, MSB of K NRP-sess ID, K NRPIt may include one or more of ID, UE PC5 signalling security policy, RSC, UTC-based counter LSB, UE ID, user security key ID, HPLMN ID, source L2 ID, or destination L2 ID. In other words, the DCR message may include information elements corresponding to out-of-coverage mechanisms and information elements corresponding to in-coverage mechanisms. For the correspondence between the information elements in the DCR message and the in-coverage mechanism or out-of-coverage mechanism, and the correspondence between the information elements in the DCR message and the control plane mechanism or user plane mechanism, refer to the relevant descriptions in the aforementioned method 200 in Tables 1 and 2. Details will not be described again.

[0277] Among the above-mentioned multiple information elements, the contents of some information elements are different according to different corresponding mechanisms, the contents of some information elements do not change according to different corresponding mechanisms, and some information elements may exist in the DCR message corresponding to the in-coverage mechanism, but do not exist in the DCR message corresponding to the out-of-coverage mechanism, or may exist in the DCR message corresponding to the out-of-coverage mechanism, but do not exist in the DCR message corresponding to the in-coverage mechanism. When constructing the DCR message, UE1 may carry information elements that correspond to multiple mechanisms and have different contents in multiple different fields of the DCR message, or may carry information elements that correspond to multiple mechanisms and have the same content in the same field of the DCR message.

[0278] For example, among the multiple information elements shown in Table 1, the information elements UE security capabilities, UE PC5 signaling security policy, source L2 ID, and destination L2 ID correspond to the same content in the out-of-coverage mechanism and the in-coverage mechanism, respectively. Therefore, each information element may be carried in one field. Information elements such as source user info and target user info correspond to different content in the out-of-coverage mechanism and the in-coverage mechanism, respectively. Therefore, each information element may be carried in two fields, and the content carried in two fields corresponds to the out-of-coverage mechanism and the in-coverage mechanism, respectively. The DCR message corresponding to the out-of-coverage mechanism contains the information element key_est_info, and the DCR message corresponding to the in-coverage mechanism contains the information element UE ID or user security key ID. Therefore, in this embodiment, the information elements UE ID or user security key ID and key_est_info may be carried in different fields within the same DCR message. In this way, information elements with the same content occupy the same field in the DCR message, while information elements with different content occupy multiple fields in the DCR message. This reduces unnecessary field overhead in the DCR message and thus reduces air interface overhead.

[0279] In another embodiment, when constructing a DCR message, UE1 may transport information elements corresponding to multiple mechanisms to multiple different fields, regardless of whether the content carried by the information elements is the same. In this way, the processing logic is simpler because UE1 does not need to determine which information elements have the same content when corresponding to different mechanisms and which information elements have different content when corresponding to different mechanisms.

[0280] For ease of understanding, the above merely illustrates the structural design of a request message using information elements within a DCR message as an example, and should not constitute any limitation to this application. The information elements included in a request message and the content of those information elements are not limited in this application.

[0281] As described above, UE1 may send at least one request message by unicast, multicast, or broadcast. If UE1 sends at least one request message by unicast, UE1 may send at least one request message to UE2 discovered by the discovery procedure. Correspondingly, in step 310, UE2 receives at least one request message. For example, if UE1 sends one request message, UE2 receives the request message. If UE1 sends multiple request messages, UE2 receives multiple request messages from UE1. If UE1 sends at least one request message by broadcast, there may be one or more communication devices that receive at least one request message. Correspondingly, in step 310, one or more communication devices receive at least one request message. In this embodiment, one or more communication devices may include UE2.

[0282] Optionally, prior to step 310, the method further includes UE1 and UE2 performing ProSe parameter configuration to obtain ProSe parameters. ProSe parameters may include correspondences between RSCs and control plane security mechanism indicators, and correspondences between RSCs and control plane security mechanism indicators may include correspondences between RSCs and control plane mechanism indicators. For a description of control plane mechanism indicators, see the relevant explanation of "Network-Assisted Security Establishment Mechanism" in the glossary above. Further details are not provided again. The ProSe parameter configuration process for UE1 and UE2 may be performed during the process of UE1 and UE2 registering with the network, or separately after UE1 and UE2 have registered with the network, or may be pre-configured within the device by default.

[0283] In step 320, UE2 sends a second message to UE1 based on the network coverage status, indicating that it will establish security with UE1 using one of several mechanisms. In response, UE1 receives the second message from UE2.

[0284] In this embodiment, the communication device that receives the request message may include UE2. Without loss of generality, the following steps will be described using an example in which UE2 is used as the communication device that receives at least one request message.

[0285] After receiving at least one request message, UE2 may determine one of the aforementioned mechanisms based on the information elements contained in at least one request message, or it may further select one mechanism from the multiple mechanisms based on the network coverage status, or it may send a second message to UE1 to indicate the mechanism selected by UE2.

[0286] If UE2 may select a mechanism based on its network coverage status, then UE2's network coverage status is "in network coverage". UE2 selects the "in-coverage" mechanism and therefore may send a second message to UE1 to indicate the "in-coverage" mechanism.

[0287] Another possibility for UE2 to select a mechanism based on its network coverage status is that UE2's network coverage status is not within network coverage. UE2 may select the out-of-coverage mechanism and therefore send a second message to UE1 to indicate the out-of-coverage mechanism.

[0288] Naturally, UE2 may alternatively select an out-of-coverage mechanism when it is not within network coverage. In this case, UE2 may alternatively select an out-of-coverage mechanism directly without considering the network coverage status.

[0289] For example, if UE2 selects an in-coverage mechanism, the second message may be a direct security mode command message, which indicates establishing security with UE1 by using an in-coverage mechanism, as shown in 320a in the figure. Optionally, if UE2 selects an in-coverage mechanism, the second message may be a direct security mode command message, and UE2 does not send a direct authentication and key establishment message to UE1 before sending the second message. In this case, the direct security mode command message may implicitly indicate establishing security with UE1 by using an in-coverage mechanism. If UE2 selects an out-of-coverage mechanism, the second message may be a direct authentication and key establishment message, which indicates establishing security with UE1 by using an out-of-coverage mechanism, as shown in 320b in the figure.

[0290] Since direct security mode command messages are existing messages that apply to in-coverage mechanisms, they may implicitly indicate that security will be established by using in-coverage mechanisms. Since direct authentication and key establishment messages are existing messages that apply to out-of-coverage mechanisms, they may implicitly indicate that security will be established by using out-of-coverage mechanisms.

[0291] Where possible, UE2 may refer to mechanism selection rules to further determine the target mechanism.

[0292] In other words, step 320 includes the step of determining a target mechanism according to a mechanism selection rule based on the network coverage status.

[0293] For example, after receiving at least one request message, UE2 may determine one of the aforementioned multiple mechanisms based on at least one request message, or further select one mechanism from the multiple mechanisms based on the network coverage status and according to the mechanism selection rules, and send a second message to UE1 to indicate the mechanism selected by UE2. The mechanism selection rules may be, for example, the rules enumerated in method 200 above. For example, the mechanism selection rules may be a correspondence between RSCs and mechanism indicators, or priority information, or a combination of a correspondence between RSCs and mechanism indicators and priority information. This is not limited to the present application. In addition, the mechanism selection rules may alternatively be "first come, first served," i.e., determining the mechanism indicated by the first received second message as the target mechanism, or selecting a target mechanism based on the reception quality or power of multiple second messages, etc. This application includes, but is not limited to, this.

[0294] For specific implementation logic for the second communication device to send a second message to the first communication device based on the network coverage status in step 330, please refer to the relevant description of step 240 in method 200 described above. Further details are not described herein.

[0295] In step 330, UE1 determines the mechanism indicated by the second message as the target mechanism.

[0296] In this embodiment, the target mechanism is a security establishment mechanism determined by UE1. UE1 may determine the target mechanism based on a second message received.

[0297] As described above, UE1 may directly receive a security mode command message in step 320a, or may further determine that the target mechanism is an in-coverage mechanism. Alternatively, UE1 may directly receive an authentication and key establishment message in step 320b, or may further determine that the target mechanism is an out-of-coverage mechanism. Optionally, UE1 may directly receive a security mode command message in step 320a to determine that the target mechanism is an in-coverage mechanism, and does not directly obtain an authentication and key establishment message from UE2 before step 320a. In other words, UE1 may determine the mechanism indicated by the second message as the target mechanism.

[0298] Also, the in-coverage mechanism includes a user plane mechanism and a control plane mechanism. When UE1 receives a security mode command message directly, UE1 may further determine whether the target mechanism is a user plane mechanism or a control plane mechanism based on the information element in the message.

[0299] Table 3 below shows the information elements in the direct security mode command message corresponding to the control plane mechanism and the user plane mechanism respectively.

[0300]

Table 3

[0301] In Table 3, both Nonce_2 and K NRP freshness parameter 2 are random numbers. Specifically, they may be random numbers provided by the sender of the message for generating the PC5 key, and are defined with different names in the direct security mode command messages corresponding to different mechanisms. Selected security algorithm is the selected encryption algorithm. LSB of KNRP-sess The ID is the session key K NRP-sess This is the least significant bit (LSB) of the ID. For details regarding generic bootstrapping architecture (GBA) push information, see the relevant description in 3GPP TS33.503. Further details are not provided herein. The EAP message is an extensible authentication protocol (EAP) message. For other information elements, see Tables 1 and 2 and the relevant descriptions mentioned above. Further details are again not provided.

[0302] Table 3 shows that the information elements contained in direct security mode command messages corresponding to the control plane mechanism and the user plane mechanism are not entirely the same. For example, the direct security mode command message corresponding to the control plane mechanism contains the following information elements: Nonce_2, Selected security algorithm, UE security capabilities, and MSB of K NRP ID, LSB of K NRP-sess Direct security mode command messages corresponding to the user plane mechanism include one or more of the following information elements: ID, UE PC5 signaling security policy, RSC, source L2 ID, or destination L2 ID, namely Nonce_2, Selected security algorithm, UE security capabilities, MSB of K NRP ID, LSB of K NRP-sess This includes one or more of the following: ID, UE PC5 signaling security policy, RSC, GPI, EAP message, source L2 ID, or destination L2 ID.

[0303] In comparison, direct security mode command messages corresponding to user plane mechanisms include the information elements EAP message and GPI, while direct security mode command messages corresponding to control plane mechanisms do not. The EAP message is a required information element. Therefore, whether a direct security mode command message includes the information element EAP message may be used to determine whether the message indicates a user plane mechanism or a control plane mechanism. When a direct security mode command message includes the information element EAP message, the message indicates a user plane mechanism. When a direct security mode command message does not include the information element EAP message, the message indicates a control plane mechanism. Also, GPI is an optional information element. Therefore, when a direct security mode command message includes the information element GPI, it may be determined that the message indicates a user plane mechanism.

[0304] Both direct security mode command messages corresponding to control plane mechanisms and user plane mechanisms, respectively, include the information element RSC, but different mechanisms correspond to different RSC values. Since RSC is an essential information element in direct security mode command messages corresponding to mechanisms within coverage, whether the target mechanism is a control plane mechanism or a user plane mechanism may be determined by using the RSC in the direct security mode command message. As described above, UE2 may obtain the correspondence between the RSC and the control plane security mechanism indicator before step 320. Thus, UE2 may transport the RSC corresponding to the control plane mechanism in the direct security mode command message based on the correspondence when it decides to use a control plane mechanism, or it may transport the RSC corresponding to the user plane mechanism in the direct security mode command message when it decides to use a user plane mechanism. Correspondingly, UE1 may decide to use a control plane mechanism or a user plane mechanism based on the correspondence and RSC in the direct security mode command message.

[0305] The correspondence between the RSC and the control plane security mechanism indicator is merely a possible form, and it can be understood that this correspondence may be alternatively replaced with the correspondence between the ProSe code and the mechanism in Method 200. For example, in the ProSe parameter configuration phase, UE1 and UE2 may separately obtain the ProSe parameters, and the ProSe parameters may include the correspondence between the ProSe code and the mechanism. The implementation logic for UE2 to directly generate security mode command messages based on the correspondence and the implementation logic for UE1 to directly determine the target mechanism based on the security mode command messages are the same as described above and will not be described in detail again.

[0306] Naturally, the second message may indicate the target mechanism in a different manner. For example, the second message may indicate the target mechanism by using an indicator field. For instance, "00" indicates an out-of-coverage mechanism, "01" indicates a control plane mechanism, and "10" indicates a user plane mechanism. The specific manner in which the second message indicates the target mechanism is not limited in this application.

[0307] Where possible, UE1 may receive multiple second messages from multiple UEs. For example, UE1 may send at least one request message in a broadcast manner in step 310, and there may be multiple UEs that receive at least one request message. Some or all of the multiple UEs (including UE2) that receive the request message may perform step 320 and send a second message to UE1. In this case, the mechanisms indicated by all the second messages may be the same or different. UE1 may further determine the target mechanism by referring to mechanism selection rules.

[0308] In other words, step 330 includes determining the mechanism indicated by one of a plurality of second messages as the target mechanism, in accordance with the mechanism selection rules.

[0309] For example, UE1 may determine the mechanism indicated by all of the second messages based on a plurality of second messages. If the mechanisms indicated by the plurality of second messages are multiple mechanisms, UE1 may determine a target mechanism from among the multiple mechanisms by referring to a mechanism selection rule. The mechanism selection rule may be, for example, one of the rules enumerated in Method 200 above. For example, the mechanism selection rule may be a correspondence between RSC and a mechanism indicator, or priority information, or a combination of a correspondence between RSC and a mechanism indicator and priority information. This is not limited to the present application. In addition, the mechanism selection rule may alternatively be "first come, first served," i.e., determining the mechanism indicated by the first received second message as the target mechanism, or selecting a target mechanism based on the reception quality or power of the plurality of second messages, etc. This application includes, but is not limited to, this.

[0310] In step 340, UE1 establishes security with UE2.

[0311] In this embodiment, the target mechanism determined by UE1 is assumed to be the mechanism indicated by the second message from UE2. UE1 may establish security with UE2 by using the target mechanism. For specific procedures on how UE1 establishes security with UE2, please refer to the prior art; details are not described here.

[0312] As described above, when the second message indicates a mechanism, messages within the security establishment procedure corresponding to the mechanism may implicitly indicate the mechanism. For example, a direct security mode command message implicitly indicates a security establishment mechanism with network assistance, and a direct authentication and key establishment message implicitly indicates a security establishment mechanism without network assistance. Therefore, the transmission of the second message by the second communication device to the first communication device may also be understood as the second communication device establishing security with the first communication device by using a selected mechanism, or the first communication device may also directly perform the subsequent security establishment procedure after receiving the message. In other words, step 330 described above is optional, step 320 is included in step 340, or either step 320 or step 340 may be performed.

[0313] In this embodiment of the present application, UE1 initiating ProSe communication may send at least one request message corresponding to multiple mechanisms, and a communication device (e.g., UE2) receiving at least one request message may respond to UE1 by selecting a mechanism based on the network coverage status and using the selected mechanism indicated by the second message. UE1 may determine a target mechanism based on the second message and further establish security with UE2 by using the target mechanism. Thus, the security mechanism may be a security mechanism supported by both UE1 and UE2. This facilitates the successful establishment of a secure connection.

[0314] Furthermore, this mechanism provides multiple mechanisms for UE2 to choose from, and different network conditions are considered in multiple mechanisms. In one embodiment, an out-of-coverage mechanism is provided for cases where UE2 is not in network coverage, and as a result, UE2, which is not in network coverage, can also establish a communication connection with UE1, without relying on network assistance. In another embodiment, an in-coverage mechanism is provided when UE2 is in network coverage. The network device may perform security establishment of UE1 based on the latest subscription information to ensure the successful establishment of security. In addition, the network device may decide whether to authorize UE121 and UE122 based on the latest subscription information, thereby avoiding security establishment failures that may be caused by changes in authorization. For examples of different network conditions being considered in multiple mechanisms, please refer to the relevant explanation of technical effects in Method 200. Further details will not be explained again.

[0315] In the embodiments shown in Figures 2 and 3, the specific steps by which UE1 establishes security with UE2 are described, but the process by which UE1 communicates with UE3 via UE2 in ProSe communication is not described in detail. It can be understood that if a UE is to communicate in ProSe, pre-configuration must be performed before the steps shown in Figure 2 or 3 are initiated. For example, the UE may separately obtain information such as authorizations and ProSe policies required by the U2U Relay service. Since the pre-configuration process is not the focus of this application, please refer to the prior art for specific steps of the pre-configuration process. Details are not described herein.

[0316] The above describes in detail the method provided in the embodiments of this application with reference to several attached drawings. The apparatus provided in the embodiments of this application will now be described with reference to the attached drawings.

[0317] Figures 4 to 6 illustrate possible devices according to embodiments of the present application. These devices may be configured to perform the functions of the first communication device (e.g., UE1), the second communication device (e.g., UE2), or the PCF in the method embodiments described above, and thus can also perform the beneficial effects of the method embodiments described above.

[0318] Figure 4 is a block diagram of a communication device according to one embodiment of the present application. As shown in Figure 4, the communication device 400 includes a transmitting module 410, a receiving module 420, and a processing module 430.

[0319] In one embodiment, the communication device 400 may be configured to perform the function of UE1 in the method embodiment shown in Figure 2, or to perform the function of UE2 in the method embodiment shown in Figure 2, or to perform the function of PCF in the method embodiment shown in Figure 2.

[0320] In a possible design, the communication device 400 is configured to perform the functions of UE1 in the method embodiment shown in Figure 2. In this case, the communication device 400 may be a ProSe service initiator, for example, UE121 in Figure 1.

[0321] For example, the processing module 430 is configured to determine a target mechanism from a plurality of mechanisms, the plurality of mechanisms including a security establishment mechanism with network assistance and a security establishment mechanism without network assistance; the transmitting module 410 is configured to send a request message, which is used to request a second communication device that receives the request message to establish security with the communication device 400 by using the target mechanism; the receiving module 420 is configured to receive a first message from the second communication device, which indicates whether it should agree to establish security with the communication device 400 by using the target mechanism.

[0322] Optionally, the processing module 430 is specifically configured to determine a target mechanism from a plurality of mechanisms according to a mechanism selection rule.

[0323] In one example, the mechanism selection rule includes a correspondence between a first RSC corresponding to proximity service communication and a first mechanism indicator, where the first mechanism indicator indicates a first mechanism among several mechanisms. The processing module 430 is specifically configured to determine, based on the correspondence, the first mechanism corresponding to the first mechanism indicator as the target mechanism.

[0324] In another example, the mechanism selection rule includes priority information, which indicates the priority order of mechanisms among multiple mechanisms. The processing module 430 is specifically configured to determine a target mechanism from among multiple mechanisms based on the priority order of the multiple mechanisms. For example, the mechanism with the highest priority among the multiple mechanisms is determined as the target mechanism.

[0325] Optionally, the receiving module 420 is further configured to receive mechanism selection rules from the PCF.

[0326] Furthermore, the mechanism selection rule is determined based on the service-specific information of the ProSe corresponding to the communication device 400.

[0327] Optionally, the target mechanism is a security establishment mechanism without network assistance, the first message is a direct authentication and key establishment message, and the direct authentication and key establishment message indicates agreement to establish security with communication device 400 by using a security establishment mechanism without network assistance.

[0328] Optionally, the target mechanism is a security establishment mechanism without network support, the first message is a direct security mode command message, and the direct security mode command message indicates agreement to establish security with communication device 400 by using a security establishment mechanism with network support.

[0329] Optionally, the first message is a rejection message, which indicates one or more of the following: the reasons for not agreeing to establish security with communication device 400 by using the target mechanism, the security establishment mechanism supported by the second communication device, or the security establishment mechanism not supported by the second communication device.

[0330] In another possible design, the communication device 400 is configured to perform the functions of UE2 in the method embodiment shown in Figure 2. In this case, the communication device 400 may be a U2U Relay of the ProSe service, for example, UE122 or UE124 in Figure 1.

[0331] For example, a receiving module 420 is configured to receive a request message from a first communication device, which is used to request a communication device 400 to establish security with the first communication device by using a target mechanism, which is either a network-assisted or network-unassisted security establishment mechanism; and a transmitting module 410 is configured to send a first message to the first communication device based on a network coverage status, which indicates whether the communication device should agree to establish security with the first communication device by using a target mechanism, and the network coverage status includes being within network coverage or not being within network coverage.

[0332] Optionally, the processing module 430 is configured to determine, based on the network coverage status, whether to agree to establish security with the first communication device by using the target mechanism.

[0333] Optionally, if the network coverage status of communication device 400 is within network coverage, the first message indicates agreement to establish security with the first communication device by using the target mechanism.

[0334] Optionally, if the target mechanism is a network-assisted security establishment mechanism and the network coverage status of communication device 400 is not within network coverage, the first message indicates that it does not agree to establish security with the first communication device by using the target mechanism.

[0335] Optionally, if the target mechanism is a security establishment mechanism that does not involve network support, and the network coverage status of communication device 400 is not within network coverage, the first message indicates agreement to establish security with the first communication device by using the target mechanism.

[0336] Optionally, the target mechanism is a security establishment mechanism without network assistance, the first message is a direct authentication and key establishment message, and the direct authentication and key establishment message indicates agreement to establish security with the first communication device by using a security establishment mechanism without network assistance.

[0337] Optionally, the target mechanism is a network-assisted security establishment mechanism, the first message is a direct security mode command message, and the direct security mode command message indicates agreement to establish security with the first communication device by using the network-assisted security establishment mechanism.

[0338] If, optionally, communication device 400 does not agree to establish security with first communication device by using a target mechanism, the first message is a rejection message, which indicates the reason for not agreeing to establish security with first communication device by using a target mechanism, one or more security establishment mechanisms supported by communication device 400, or security establishment mechanisms not supported by communication device 400.

[0339] In the two possible designs mentioned above, optionally, the target mechanism is a security establishment mechanism without network assistance, and the request message includes key_est_info.

[0340] In the two possible designs described above, optionally, the target mechanism is a network-assisted security establishment mechanism, and the request message includes at least one of the following: a control plane proximity service remote user key identifier CP-PRUK ID, a user plane proximity service remote user key identifier UP-PRUK ID, or a subscription concealment identifier SUCI.

[0341] Furthermore, network-assisted security establishment mechanisms are either control plane-based or user plane-based security establishment mechanisms.

[0342] In response to this, the request message further includes an RSC, which is used to determine whether the security establishment mechanism is control plane-based or user plane-based.

[0343] In yet another possible design, the communication device 400 is configured to perform the functions of the PCF in the method embodiment shown in Figure 2.

[0344] For example, the processing module 430 is configured to determine a mechanism selection rule, which is used to determine a target mechanism for establishing security between a first communication device and a second communication device from among a plurality of mechanisms, the plurality of mechanisms including a security establishment mechanism with network support and a security establishment mechanism without network support, the first communication device is a device that initiates proximity service communication, and the transmitting module 410 is further configured to transmit the mechanism selection rule to the first communication device.

[0345] Optionally, the mechanism selection rule includes a correspondence between a first RSC corresponding to proximity service communication and a first mechanism indicator, where the first mechanism indicator indicates a first mechanism among several mechanisms.

[0346] Optionally, the mechanism selection rule includes priority information, which indicates the priority order of multiple mechanisms.

[0347] Optionally, the receiving module 420 is configured to receive information from the UDM, and this information is used to determine the mechanism selection rule.

[0348] Optionally, the information is service-specific information for the ProSe corresponding to the first communication device.

[0349] In another embodiment, the communication device 400 may be configured to perform the function of UE1 in the method embodiment shown in Figure 3, or it may be configured to perform the function of UE2 in the method embodiment shown in Figure 3.

[0350] In a possible design, the communication device 400 is configured to perform the functions of UE1 in the method embodiment shown in Figure 3. In this case, the communication device 400 may be a ProSe service initiator, for example, UE121 in Figure 1.

[0351] For example, the transmitting module 410 is configured to transmit at least one request message, the request message indicating a plurality of mechanisms, the plurality of mechanisms including a security establishment mechanism with network assistance and a security establishment mechanism without network assistance, and the receiving module 420 is configured to receive a second message from a second communication device, the second message indicating that a security establishment will be made with the communication device 400 by using one of the plurality of mechanisms.

[0352] Optionally, the processing module 430 is configured to determine the mechanism indicated by the second message as the target mechanism and to establish security with the second communication device by using the target mechanism.

[0353] In one example, the second message is a direct security mode command message, which indicates a security establishment mechanism with network assistance. The processing module 430 is specifically configured to determine the security establishment mechanism with network assistance indicated by the direct security mode command message as the target mechanism.

[0354] In another example, the second message is a direct authentication and key establishment message, which indicates a security establishment mechanism without network assistance. The processing module 430 is specifically configured to determine the security establishment mechanism without network assistance, indicated by the direct authentication and key establishment message, as the target mechanism.

[0355] Furthermore, the receiving module 420 is specifically configured to receive a plurality of second messages from a plurality of second communication devices, and the processing module 430 is specifically configured to determine, according to a mechanism selection rule, the mechanism indicated by one of the plurality of second messages as the target mechanism.

[0356] In another possible design, the communication device 400 is configured to perform the functions of UE2 in the method embodiment shown in Figure 3. In this case, the communication device 400 may be a U2U Relay of the ProSe service, for example, UE122 or UE124 in Figure 1.

[0357] For example, the receiving module 420 is configured to receive at least one request message from a first communication device, the request message indicating a plurality of mechanisms, the plurality of mechanisms including a security establishment mechanism with network assistance and a security establishment mechanism without network assistance, and the processing module 430 is configured to send a second message to the first communication device based on the network coverage status, the second message indicating that security establishment will be performed with the first communication device by using one of the plurality of mechanisms.

[0358] Optionally, if the network coverage status of communication device 400 is within network coverage, the second message indicates that security establishment will be performed with the first communication device by using a security establishment mechanism with network assistance.

[0359] Furthermore, the second message is a direct security mode command message.

[0360] Optionally, if the network coverage status of communication device 400 is not within network coverage, the second message indicates that security establishment will be performed with the first communication device by using a security establishment mechanism without network assistance.

[0361] Furthermore, the second message is a direct authentication and key establishment message.

[0362] In the two possible designs described above, at an optional choice, at least one request message contains multiple request messages, and each of the multiple request messages indicates one of several mechanisms.

[0363] In the two possible designs described above, at an optional choice, at least one request message is a single request message, and a request message indicates multiple mechanisms.

[0364] Furthermore, the request message includes key_est_info and at least one of the following: CP-PRUK ID, UP-PRUK ID, or SUCI.

[0365] For a more detailed description of the transmitting module 410, the receiving module 420, and the processing module 430, please refer directly to the relevant descriptions in the method embodiments shown in Figure 2 or Figure 3. Further details are not described herein.

[0366] Figure 5 is another block diagram of a communication device according to one embodiment of the present application. As shown in Figure 5, the communication device 500 includes one or more processors 510. The processors 510 may be general-purpose processors, dedicated processors, etc., and may be, for example, baseband processors or central processing units. The baseband processor may be configured to process communication protocols and communication data. The central processing unit may be configured to control the communication device (e.g., UE1, UE2, PCF, or chip), execute software programs, and process data from the software programs.

[0367] Optionally, in one design, the processor 510 may contain a program (which may also be called code or instructions), and the program may be executed on the processor 510, so that the communication device 500 performs the method performed by UE1, UE2, or PCF in the method embodiments described above. In another possible design, the communication device 500 contains a circuit (not shown in Figure 5) configured to perform the function of UE1, UE2, or PCF in the method embodiments described above.

[0368] For example, the processor 510 may be configured to execute a computer program or instruction in memory to perform steps performed by UE1, UE2, or PCF in the embodiment shown in Figure 2, or to perform steps performed by UE1 or UE2 in the embodiment shown in Figure 3.

[0369] Optionally, the communication device 500 may include one or more memories 520 for storing a program (sometimes also called code or instructions), and the program may be executed on the processor 510, and as a result, the communication device 500 performs the method performed by UE1, UE2, or PCF in the method embodiments described above.

[0370] Optionally, the processor 510 and / or memory 520 may include an artificial intelligence (AI) module, which is configured to perform AI-related functions. The AI ​​module may be implemented using software, hardware, or a combination of software and hardware. For example, the AI ​​module may include a radio intelligent controller (RIC) module. For example, the AI ​​module may be a quasi-real-time RIC or a non-real-time RIC.

[0371] Optionally, the processor 510 and / or memory 520 may store additional data. The processor and memory may be located separately or integrated together.

[0372] Optionally, the communication device 500 may further include a communication interface 530. The processor 510 and the communication interface 530 are coupled to each other. The processor 510, sometimes called a processing unit, controls the communication device (e.g., UE1, UE2, or PCF). The communication interface 530, sometimes called a transceiver unit, transceiver machine, transceiver circuit, transceiver, etc., is configured to perform the transceiver function of the communication device. It can be understood that the communication interface 530 may be a transceiver or an input / output interface.

[0373] When the communication device 500 is configured to implement the method embodiment shown in Figure 2 or Figure 3, the processor 510 is configured to perform the functions of a processing unit, and the communication interface 530 is configured to perform the functions of a transmit module and a receive module. Whether the communication interface 530 is used for transmission or reception may be specifically determined based on whether the communication device 500 is configured to perform a transmit operation or a receive operation in the mechanism performed by the communication device 500.

[0374] When the communication device 500 is a chip used in UE1, the chip performs the functions of UE1 in the method embodiment described above. The chip in UE1 may receive a signal from another module in UE1 (e.g., a radio frequency module or an antenna) and the signal may be transmitted to UE1 by UE2, or the chip in UE1 may transmit a signal to another module in UE1 (e.g., a radio frequency module or an antenna) and the signal may be transmitted to UE2 by UE1.

[0375] When the communication device 500 is a chip used in UE2, the chip performs the functions of UE2 in the method embodiment described above. The chip in UE2 may receive a signal from another module in UE2 (e.g., a radio frequency module or an antenna) and the signal may be transmitted to UE2 by UE1, or the chip in UE2 may transmit a signal to another module in UE2 (e.g., a radio frequency module or an antenna) and the signal may be transmitted to UE1 by UE2.

[0376] When the communication device 500 is UE1 or UE2, it will be understood that the communication interface 530 may be a transceiver and may specifically include a transmitter and a receiver. The transmitter is configured to transmit a signal, and the receiver is configured to receive a signal. When the communication device 500 is a chip used in UE1 or UE2, the communication interface 530 may be an input / output circuit. The input circuit may be used for receiving, and the output interface may be used for transmitting.

[0377] Figure 6 is a diagram of the structure of a terminal device according to one embodiment of the present application. As shown in Figure 6, the terminal device 600 may be applied to the scenario shown in Figure 1 to perform the functions of UE1 or UE2 in the method embodiment described above. As shown in the figure, the terminal device 600 includes a processor 601 and a transceiver 602. Optionally, the terminal device 600 further includes a memory 603. The processor 601, transceiver 602, and memory 603 communicate with each other via an internal connection path and transfer control signals and / or data signals. The memory 603 is configured to store a computer program. The processor 601 is configured to call a computer program from memory 603, execute the computer program, and control the transceiver 602 to receive / transmit signals. Optionally, the terminal device 600 may further include an antenna 604 configured to transmit uplink data or uplink control signaling output by the transceiver 602 via radio signals.

[0378] The processor 601 and memory 603 may be integrated into a single processing unit. The processor 601 is configured to execute program code stored in memory 603 in order to perform the functions described above. In specific implementations, memory 603 may, alternatively, be integrated into the processor 601 or be independent of the processor 601. The processor 601 may correspond to the processing module in Figure 4 or the processor in Figure 5.

[0379] The transceiver 602 may correspond to the transmitting module and receiving module in Figure 4 or the communication interface in Figure 5, or it may also be called a transceiver unit. The transceiver 602 may include a receiver (or referred to as a receiving machine or receiver circuit) and a transmitter (or referred to as a transmitting machine or transmitter circuit). The receiver is configured to receive signals, and the transmitter is configured to transmit signals.

[0380] It should be understood that the terminal device 600 shown in Figure 6 can perform the process related to UE1 or UE2 in the method embodiment shown in Figure 2 or Figure 3. The operation and / or function of the modules within the terminal device 600 are separately for performing the corresponding procedures in the aforementioned method embodiments. For details, please refer to the descriptions of the aforementioned method embodiments. To avoid repetition, detailed descriptions are omitted where appropriate in this specification.

[0381] The processor 601 may be implemented within the terminal device and configured to perform the operations described in the method embodiments described above, and the transceiver 602 may be performed by the terminal device and configured to perform the operations of sending to or receiving from a network device, as described in the method embodiments described above. For further details, please refer to the description in the method embodiments described above. Further details are not described herein again.

[0382] Optionally, the terminal device 600 may further include a power supply 605 configured to supply power to various components or circuits within the terminal device.

[0383] Furthermore, in order to realize more functions of the terminal device, the terminal device 600 may further include one or more of the following: an input unit 606, a display unit 607, an audio circuit 608, a camera 609, a sensor 610, etc., and the audio circuit may further include a speaker 608a, a microphone 608b, etc.

[0384] It should be noted that the method embodiments described above may be applied to a processor or implemented by a processor. The processor may be an integrated circuit chip or have signal processing capabilities. In implementation, the steps in the method embodiments described above may be carried out by using hardware integrated logic circuits within the processor or by using instructions in the form of software.

[0385] The processor may be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or another programmable logic device, a discrete gate or transistor logic device, a discrete hardware component, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor, etc.

[0386] The steps of the methods disclosed with reference to embodiments of this application may be performed directly by a hardware decoding processor or by using a combination of hardware and software modules within the decoding processor. The software modules may be located in mature storage media in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, or registers. The storage media is located in memory, and the processor reads the information in memory and, in combination with the processor's hardware, completes the steps in the methods described above.

[0387] The memory in the embodiments of this application may be volatile memory, non-volatile memory, or may include both volatile and non-volatile memory. Non-volatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory may be random access memory (RAM) used as an external cache. Rather than being a restrictive description, many forms of RAM may be used, for example, static random access memory (static RAM, SRAM), dynamic random access memory (dynamic RAM, DRAM), synchronous dynamic random access memory (synchronous DRAM, SDRAM), double data rate synchronous dynamic random access memory (double data rate SDRAM, DDR SDRAM), enhanced synchronous dynamic random access memory (enhanced SDRAM, ESDRAM), synchlink dynamic random access memory (synchlink DRAM, SLDRAM), and direct rambus random access memory (direct rambus RAM, DR RAM). It should be noted that the memory of the systems and methods described herein includes, but is not limited to, these memories and any other suitable type of memory.

[0388] This application further provides a chip system, which includes at least one processor configured to support the implementation of the functions of UE1, UE2, or PCF in any one of the aforementioned method embodiments, for example, receiving, transmitting, or processing data and / or information in the aforementioned method.

[0389] In possible designs, the chip system further includes memory, which is configured to store program instructions and data, and the memory is located inside or outside the processor.

[0390] The chip system may include a chip, or it may include a chip and other separate components.

[0391] This application further provides a computer program product, which includes a computer program (sometimes called code or instructions). When the computer program is executed, the method performed by UE1 in the embodiment shown in Figure 2, the method performed by UE2, or the method performed by PCF is performed. Alternatively, when the computer program is executed, the method performed by UE1 or the method performed by UE2 in the embodiment shown in Figure 3 is performed.

[0392] This application further provides a computer-readable storage medium that stores a computer program (sometimes also called code or instructions). When the computer program is executed, the method performed by UE1 in the embodiment shown in Figure 2, the method performed by UE2, or the method performed by PCF is performed. Alternatively, when the computer program is executed, the method performed by UE1 or the method performed by UE2 in the embodiment shown in Figure 3 is performed.

[0393] This application further provides a communication system, which includes UE1, UE2, PCF, and / or the apparatus of the embodiments described above.

[0394] All or part of the methods provided in the embodiments described above may be implemented by software, hardware, firmware, or any combination thereof. When software is used for the embodiments, all or part of the embodiments may be implemented in the form of a computer program product. The computer program product may include one or more computer instructions. When the computer program instructions are loaded into a computer and executed, all or part of the procedures or functions according to the embodiments of this application are generated. The computer may be a general-purpose computer, a dedicated computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer instructions may be transmitted by wired (e.g., coaxial cable, optical fiber, or digital subscriber line (DSL)) or wireless (e.g., infrared, radio, or microwave) from one website, computer, server, or data center to another website, computer, server, or data center. The computer-readable storage medium may be any available medium accessible by a computer, or it may be a data storage device, such as a server or data center, incorporating one or more available media. The usable media may include magnetic media (e.g., floppy disks, hard disks, magnetic disks), optical media (e.g., DVDs), and semiconductor media (e.g., solid-state disks (SSDs)).

[0395] Those skilled in the art will notice, in combination with the examples described in the embodiments disclosed herein, that the units and algorithmic steps may be implemented by electronic hardware, or by a combination of computer software and electronic hardware. Whether the function is performed by hardware or software depends on the specific application and design constraints of the technical mechanism. Those skilled in the art may implement the functions described using various methods for specific applications, but such implementation should not be considered to exceed the scope of this application.

[0396] For the sake of brevity, it will be readily apparent to those skilled in the art that the detailed operating processes of the aforementioned systems, apparatus, and units can be described by referring to the corresponding processes in the method embodiments described above. Further details are not described herein.

[0397] It should be understood that in some embodiments provided in this application, the disclosed systems, apparatus, and methods may be implemented in other ways. For example, the apparatus embodiments described are merely examples. For example, the division into units is merely a logical division of function, and other divisions may be used in actual implementation. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not implemented. In addition, the mutual coupling, direct coupling, or communication connection shown or described may be implemented through some interfaces. Indirect coupling or communication connection between apparatus or units may be implemented in electronic, mechanical, or other forms.

[0398] Units described as separate parts may or may not be physically separate, and parts presented as units may or may not be physical units, may be located in one location, or may be distributed across multiple network units. Some or all of the units may be selected based on actual requirements to achieve the objectives of the mechanism of the embodiment.

[0399] In addition, the functional units in the embodiments of this application may be integrated into a single processing unit, each unit may exist physically independently, or two or more units may be integrated into a single unit.

[0400] When a function is implemented in the form of a software function unit and sold or used as an independent product, the function may be stored on a computer-readable storage medium. Based on such an understanding, the technical mechanism of this application, or a portion of it that contributes to the prior art, or a part of the technical mechanism may be implemented in the form of a software product. A computer software product is stored on a storage medium and includes a number of instructions for instructing a computer device (which may be a personal computer, a server, or a network device) to perform all or part of the steps of the method described in embodiments of this application. The aforementioned storage medium includes any medium capable of storing program code, such as a USB flash disk, a removable hard disk, read-only memory, random-access memory, a magnetic disk, or an optical disk.

[0401] The foregoing description represents only specific embodiments of this application, but is not intended to limit the scope of protection of this application. Any modifications or substitutions readily conceivable by a person skilled in the art within the scope of the art disclosed herein shall fall within the scope of protection of this application. Accordingly, the scope of protection of this application shall be subject to the scope of protection of the claims. [Explanation of Symbols]

[0402] 110 Access Network Devices 121 UE 122 UE 123 UE 124 UE 125 UE 130 Core Network 200 ways 300 ways 400 Communication devices 410 Transmitter Module 420 Receiver Module 430 Processing Modules 500 Communication devices 510 Processor 520 memory 530 Communication Interface 600 terminal devices 601 Processor 602 Transceiver 603 memory 604 Antenna 605 Power supply 606 Input Unit 607 Display Unit 608 Audio Circuit 608a speaker 608b Microphone 609 Camera 610 Sensor

Claims

1. A method for establishing security, A first communication device determines a first mechanism among a plurality of mechanisms as a target mechanism based on the correspondence between a first relay service code RSC corresponding to proximity service communication and a first mechanism indicator, wherein the plurality of mechanisms include a security establishment mechanism with network support and a security establishment mechanism without network support, and the first mechanism indicator indicates the first mechanism. The steps include: sending a request message by the first communication device, wherein the request message is used to request a second communication device that receives the request message to establish security with the first communication device by using the target mechanism; A step of receiving a first message from the second communication device by the first communication device, wherein the first message indicates that the first communication device agrees to establish security with the first communication device by using the target mechanism. Methods that include...

2. The method according to claim 1, wherein the first communication device is a first user equipment UE, the second communication device is a relay UE between the first UE and the second UE, and the second UE is a UE that performs proximity service communication with the first UE.

3. The method according to claim 1 or 2, wherein the target mechanism is a security establishment mechanism without network support, and the request message includes key establishment information key_est_info.

4. The method according to claim 1 or 2, wherein the target mechanism is a security establishment mechanism with network support, and the request message includes at least one of the following: a control plane proximity service remote user key identifier CP-PRUK ID, a user plane proximity service remote user key identifier UP-PRUK ID, or a subscription concealment identifier SUCI.

5. The method according to claim 4, wherein the security establishment mechanism with network support is a control plane-based security establishment mechanism or a user plane-based security establishment mechanism.

6. The method according to claim 5, wherein the request message further includes a relay service code RSC, the RSC being used to determine the control plane-based security establishment mechanism or the user plane-based security establishment mechanism.

7. The method according to any one of claims 1 to 3, wherein the target mechanism is the network-independent security establishment mechanism, the first message is a direct authentication and key establishment message, and the direct authentication and key establishment message indicates agreement to establish security with the first communication device by using the network-independent security establishment mechanism.

8. The method according to any one of claims 1, 2, or 4 to 6, wherein the target mechanism is the network-assisted security establishment mechanism, the first message is a direct security mode command message, and the direct security mode command message indicates agreement to establish security with the first communication device by using the network-assisted security establishment mechanism.

9. The aforementioned method, Steps to receive the correspondence between the first RSC and the first mechanism indicator from the policy control function PCF. The method according to any one of claims 1 to 8, further comprising:

10. The method according to any one of claims 1 to 8, wherein the correspondence between the first RSC and the first mechanism indicator is pre-configured in the first communication device.

11. The method according to any one of claims 1 to 10, wherein the correspondence between the first RSC and the first mechanism indicator is determined based on service-specific information of the proximity service corresponding to the first communication device.

12. The method according to any one of claims 1 to 11, wherein the first message is a rejection message, the rejection message indicates one or more of the following: that is, the reasons for not agreeing to establish security with the first communication device by using the target mechanism, a security establishment mechanism supported by the second communication device, or a security establishment mechanism not supported by the second communication device.

13. The aforementioned method, The second communication device receives the request message and transmits the first message. The method according to any one of claims 1 to 12, further comprising:

14. A method for establishing security applicable to a second communication device, A step of receiving a request message from a first communication device, the request message being used to request a second communication device to establish security with the first communication device by using a target mechanism, the target mechanism being a network-assisted security establishment mechanism or a network-assisted security establishment mechanism, and A step of sending a first message to the first communication device based on the network coverage status, wherein the first message indicates whether the user agrees to establish security with the first communication device by using the target mechanism, and the network coverage status includes being within network coverage or not being within network coverage. Methods that include...

15. The method according to claim 14, wherein the first communication device is a first user equipment UE, the second communication device is a relay UE between the first UE and the second UE, and the second UE is a UE that performs proximity service communication with the first UE.

16. The method according to claim 14 or 15, wherein the target mechanism is a security establishment mechanism without network support, and the request message includes key establishment information key_est_info.

17. The method according to claim 14 or 15, wherein the target mechanism is the network-assisted security establishment mechanism, and the request message includes at least one of the following: a control plane proximity service remote user key identifier CP-PRUK ID, a user plane proximity service remote user key identifier UP-PRUK ID, or a subscription concealment identifier SUCI.

18. The method according to claim 17, wherein the security establishment mechanism with network support is a control plane-based security establishment mechanism or a user plane-based security establishment mechanism.

19. The method according to claim 18, wherein the request message further includes a relay service code RSC, the RSC being used to determine the control plane-based security establishment mechanism or the user plane-based security establishment mechanism.

20. If the network coverage status is within network coverage, the first message indicates that it agrees to establish security with the first communication device by using the target mechanism. If the target mechanism is the security establishment mechanism with network support, and the network coverage status is not within network coverage, the first message indicates that the user does not agree to establish security with the first communication device by using the target mechanism. The method according to claim 14 or 15, wherein if the target mechanism is a security establishment mechanism without network support and the network coverage status is not within network coverage, the first message indicates that the user agrees to establish security with the first communication device by using the target mechanism.

21. The method according to any one of claims 14 to 16 or 20, wherein the target mechanism is the network-unassisted security establishment mechanism, the first message is a direct authentication and key establishment message, and the direct authentication and key establishment message indicates agreement to establish security with the first communication device by using the network-unassisted security establishment mechanism.

22. The method according to any one of claims 14, 15, or 17 to 20, wherein the target mechanism is the network-assisted security establishment mechanism, the first message is a direct security mode command message, and the direct security mode command message indicates agreement to establish security with the first communication device by using the network-assisted security establishment mechanism.

23. The method according to any one of claims 14 to 20, wherein when the second communication device does not agree to establish security with the first communication device by using the target mechanism, the first message is a rejection message, and the rejection message indicates one or more of the following: the reason why the second communication device does not agree to establish security with the first communication device by using the target mechanism, a security establishment mechanism supported by the second communication device, or a security establishment mechanism not supported by the second communication device.

24. A communication device comprising one or more functional units, configured to carry out the method described in any one of claims 1 to 12, or configured to carry out the method described in any one of claims 14 to 23.

25. A communication device comprising a processor, wherein the processor is configured to execute program code, and as a result, the communication device implements the method described in any one of claims 1 to 12 or the method described in any one of claims 14 to 23.

26. A computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed on a computer, the computer is capable of carrying out the method according to any one of claims 1 to 12 or the method according to any one of claims 14 to 23.

27. A computer program product comprising a computer program, wherein when the computer program is executed on a computer, the computer is capable of carrying out the method described in any one of claims 1 to 12, or the method described in any one of claims 14 to 23.

28. A communication system comprising a first communication device and a second communication device, The first communication device is configured to carry out the method described in any one of claims 1 to 12, The second communication device is configured to receive a request message and transmit a first message, forming a communication system.

29. The communication system according to claim 28, wherein the second communication device is further configured to carry out the method described in any one of claims 14 to 23.