Communication methods and devices

The communication method enhances the reliability and efficiency of device discovery in D2D communication by using a discovery key management network element to accurately determine target networks and manage security parameters, thereby reducing waste and latency.

JP2026517910APending Publication Date: 2026-06-02HUAWEI TECH CO LTD

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
HUAWEI TECH CO LTD
Filing Date
2024-05-07
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

The low reliability of the device discovery process in proximity-based service communication reduces the efficiency of the discovery process in D2D communication.

Method used

Implementing a communication method using a discovery key management network element to accurately determine the target network and obtain security parameters, reducing signaling waste and processing resources by storing correspondence relationships between identifiers and managing security parameters efficiently.

Benefits of technology

Improves the efficiency of the device discovery process by reducing signaling waste, processing resources, and latency in the security parameter acquisition process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026517910000001_ABST
    Figure 2026517910000001_ABST
Patent Text Reader

Abstract

This application provides a communication method and apparatus for improving the reliability of the device discovery process in proximity-based service communication in order to improve proximity-based service communication performance. The method can be carried out in the following steps: After receiving a security parameter acquisition request from a first communication device, a first discovery key management network element acquires a target network identifier from the first network element, the first request may include a proximity-based service identifier, the target network identifier corresponds to the proximity-based service identifier, the target network is the home network of a second communication device, and the second communication device is configured to provide proximity-based service to the first communication device. The first discovery key management network element can then send a second request to a second discovery key management network element in the target network to acquire security parameters, and can send the security parameters acquired from the second discovery key management network element to the first terminal device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Cross-reference to Related Applications This application claims priority to Chinese Patent Application No. 202310532302.2, titled "Communication Method and Apparatus", filed with the China National Intellectual Property Administration on May 11, 2023, and incorporates it herein by reference in its entirety.

[0002] This application relates to the field of mobile communication technology, and particularly to communication methods and apparatuses.

Background Art

[0003] Device-to-device (D2D) communication enables direct communication between user equipments (UEs). The user equipments can share cell users and spectrum resources under the control of the cell network, as a result, the utilization of spectrum resources is effectively improved. Currently, D2D communication is applied to the fifth-generation mobile communication (4 th generation mobile network, 4G) network system and is collectively referred to as proximity-based service (ProSe) communication service.

[0004] Currently, due to the low reliability of the device discovery process in proximity-based service communication, the efficiency of the discovery process has been reduced.

Summary of the Invention

[0005] This application provides a communication method and apparatus for improving the reliability of the device discovery process in proximity-based service communication in order to improve the efficiency of the discovery process.

[0006] According to a first embodiment, a communication method is provided. The method may be implemented by a first discovery key management network element or a component within the first discovery key management network element. The first discovery key management network element may be a discovery name management function or a proximity-based service key management function. The component in this application may include, for example, at least one of a chip, a chip system, a processor, a transceiver, a processing unit, or a transceiver unit. For example, the communication method is implemented by the first discovery key management network element. The method may be implemented in the following steps: The first discovery key management network element may receive a first request from a first communication device, the first request may be used to request security parameters used for the discovery of a terminal device. The first request may include an identifier for a proximity-based service, the proximity-based service may be a proximity-based service provided by a second communication device for the first communication device. Based on the first request, the first discovery key management network element can obtain from the first network element the identifier of a target network corresponding to the identifier of a proximity-based service, the target network being the home network of the second communication device. The first discovery key management network element can then further send a second request to a second discovery key management network element in the target network to request security parameters. The first discovery key management network element can receive the security parameters from the second discovery key management network element and send the security parameters to the first terminal device.

[0007] According to the method in the first embodiment, the identifier of the proximity-based service corresponds to the identifier of the target network. Therefore, the first discovery key management network element can obtain the identifier of the target network corresponding to the identifier of the proximity-based service from the first network element, and can send a security parameter retrieval request, i.e., a second request, to a second discovery key management network element in the target network to request security parameters for the discovery process in the proximity-based service. Thus, the first discovery key management network element can accurately and efficiently determine the second discovery key management network element. This reduces signaling waste, processing resources, and delays in the security parameter retrieval process, and improves the efficiency of the discovery process.

[0008] In one possible implementation, the first discovery key management network element may send a network identifier retrieval request to the first network element, which is used to request the identifier of a target network, and which includes the identifier of a proximity-based service. Thus, the first discovery key management network element may send the identifier of the proximity-based service carried in the first request to the first network element in order to accurately obtain the identifier of the target network.

[0009] In one possible implementation, if a first discovery key management network element obtains from a first network element at least one first network identifier, including an identifier for a target network, and the first discovery key management network element further receives at least one second network identifier from a first communication device, the first discovery key management network element may determine the target network based on the second network identifier and the at least one first network identifier. Each first network identifier corresponds to a proximity-based service identifier, and the second network identifier identifies a network that is made capable of providing proximity-based services for the first communication device.

[0010] This implementation allows for more accurate determination of the target network as the network that is both the home network of the second communication device and the network that enables proximity-based services for the first communication device, thereby avoiding cases where security parameters are requested from networks that are not enabled to provide proximity-based services for the first communication device. This increases the success rate of obtaining security parameters, further reduces signaling waste, processing resources, and delays in the security parameter acquisition process, and improves the efficiency of the discovery process.

[0011] In one possible implementation, the first discovery key management network element stores the correspondence between the identifier of the proximity-based service and the identifier of the target network.

[0012] According to this implementation, after receiving a discovery key request again carrying the identifier of a proximity-based service, the first discovery key management network element can determine at least one first network identifier corresponding to the identifier of the proximity-based service based on the stored correspondence. Therefore, the first discovery key management network element does not need to request the first network element again for the identifier of the network corresponding to the identifier of the proximity-based service. This can further reduce signaling waste, processing resources, and delays in the security parameter acquisition process and improve the efficiency of the discovery process.

[0013] In a possible implementation, the first discovery key management network element may receive a security parameter announcement message from the second discovery key management network element, the security parameter announcement message including the security parameter and the identifier of the security parameter. Correspondingly, the first discovery key management network element sends a security parameter response message to the first communication device, the security parameter response message including the security parameter and the identifier of the security parameter. It can be understood that, while the second discovery key management network element transmits to the first discovery key management network element, and / or while the first discovery key management network element transmits to the first communication device, the security parameter and the identifier of the security parameter may instead be carried in a message other than the message described, and / or the security parameter and the identifier of the security parameter may be carried in the same message or in multiple different messages.

[0014] This implementation allows security parameter identifiers to identify specific security parameters used to protect discovery messages and / or specific security parameters to be used to process protected discovery messages. Therefore, based on security parameter identifiers, a discovery message receiving device can accurately determine the specific security parameters to be used to process protected discovery messages, thus avoiding cases where the receiving device has to perform discovery procedures separately using multiple sets of security parameters in a trial-and-error manner to ensure it establishes a connection to the discovery message sending device. This reduces signaling waste, processing resources, and latency.

[0015] According to a second embodiment, a communication method is provided. The method may be carried out by a first network element. The first network element may be a core network element or a component within the core network element. The component in this application may include, for example, at least one of a chip, a chip system, a processor, a transceiver, a processing unit, or a transceiver unit. For example, the communication method is carried out by a first network element. The method may be carried out in the following steps: The first network element can determine an identifier of a target network corresponding to an identifier of a proximity-based service, the proximity-based service may be provided by a second communication device for a first communication device. The first network element transmits the identifier of the target network to a first discovery key management network element, the target network being the home network of the second communication device.

[0016] In one possible implementation, the first network element may further receive a network identifier retrieval request from the first discovery key management network element, the network identifier retrieval request is used to request the identifier of the target network, and the network identifier retrieval request includes the identifier of the proximity-based service.

[0017] In one possible implementation, the first network element may further determine at least one first network identifier corresponding to an identifier for a proximity-based service, the at least one first network identifier including an identifier for a target network. The first network element may further transmit the at least one first network identifier to the first discovery key management network element.

[0018] In one possible implementation, the first network element decides whether to assign security parameters to the proximity-based service, or whether to have the first discovery key management network element assign security parameters to the proximity-based service. Therefore, when the first discovery key management network element manages security parameters for the proximity-based service, or when the first network element does not manage security parameters, the first network element can accurately obtain the identifier of the home network of the second communication device, and as a result, the first network element can obtain security parameters from the discovery key management network element within the home network of the second communication device, thereby improving the efficiency of obtaining security parameters.

[0019] In one possible implementation, if the first network element determines that the security parameters for proximity-based services are managed by the first network element, the second discovery key management network element does not need to provide the security parameters, and the first network element can refuse to send the target network identifier to the first discovery key management network element, thereby reducing the signaling and processing overhead required to retrieve the security parameters thereafter.

[0020] In one possible implementation, the first network element stores the correspondence between the first discovery key management network element and the proximity base service identifier, and as a result, after subsequently receiving a network identifier retrieval request carrying the proximity base service identifier, the first network element determines, based on the stored proximity base service identifier, that the first network identifier corresponding to the proximity base service identifier has been requested. Thus, the first network element does not need to provide the first network identifier to the first discovery key management network element again, avoiding processing and signaling overhead caused by repeated queries, and preventing another network element from pretending to be the first discovery key management network element in order to retrieve the first network identifier. For example, the first network element may receive further network identifier retrieval requests from the first discovery key management network element, which are used to request the network identifier of a target network, and the request message includes the proximity base service identifier. Since the correspondence between the first discovery key management network element and the proximity-based service identifier is stored, the first network element may decide to reject the network identifier retrieval request based on the correspondence between the first discovery key management network element and the proximity-based service identifier. Furthermore, the first network element may send a rejection message to the first discovery key management network element in response to the network identifier retrieval request.

[0021] For the second aspect and the beneficial effects of possible implementations, please refer to the description of the first aspect and the beneficial effects of the corresponding implementation. Repeated sections will not be explained again.

[0022] According to a third aspect, a communication method is provided. This method may be implemented by a first terminal device. The first terminal device may be a terminal device or a component within such a terminal device. For example, the communication method is performed by the first terminal device. This method may be implemented in the following steps: The first communication device obtains security parameters and identifiers of security parameters from a first discovery key management network element. For a description of security parameters and identifiers of security parameters, please refer to the description in the first aspect. Repeated parts will not be described again.

[0023] In one possible implementation, the first communication device transmits a first discovery message, which is used to discover the second communication device, and the first discovery message is protected by using security parameters.

[0024] In one possible implementation, the first discovery message includes a security parameter and an identifier for the security parameter.

[0025] In one possible implementation, a first communication device receives a second discovery message, the second discovery message includes security parameters and identifiers for the security parameters, and the second discovery message is used for the discovery of the first communication device; the first communication device determines the security parameters based on the identifiers for the security parameters; and the first communication device processes the second discovery message based on the security parameters.

[0026] For the third aspect and the beneficial effects of possible implementations, please refer to the description of the first aspect and the beneficial effects of the corresponding implementation. Repeated sections will not be explained again.

[0027] According to a fourth aspect, a communication method is provided. The method may be implemented by a first discovery key management network element, or a component within the first discovery key management network element. The first discovery key management network element may be a discovery name management function or a proximity-based service key management function. For example, the communication method is executed by the first discovery key management network element. The method may be implemented in the following steps: The first discovery key management network element receives a first request from a first communication device, the first request is used to request security parameters, the security parameters are used for the discovery of the communication device, the first request includes an identifier of a proximity-based service and an identifier of a target network corresponding to the identifier of the proximity-based service, the target network is the home network of a second communication device, and the proximity-based service is a service provided by the second communication device for the first communication device. The first discovery key management network element transmits a second request to a second discovery key management network element within the target network, the second request is used to request security parameters. The first discovery key management network element receives security parameters from the second discovery key management network element. The first discovery key management network element transmits the security parameters to the first communication device.

[0028] According to the method in the fourth aspect, the first discovery key management network element may obtain a correspondence relationship between the identifier of the proximity-based service and the identifier of the target network. Therefore, the first discovery key management network element may send a security parameter acquisition request, that is, a second request, to the second discovery key management network element in the target network in order to request the security parameters of the discovery process in the proximity-based service. Therefore, the first discovery key management network element can accurately and efficiently determine the second discovery key management network element. This reduces signaling waste, processing resources, and delay in the security parameter acquisition process and improves the performance of the discovery process.

[0029] In one possible implementation, the first request includes the identifier of the proximity-based service and at least one first network identifier corresponding to the identifier of the proximity-based service, the at least one first network identifier includes the identifier of the target network, and the at least one first network identifier corresponds to the identifier of the proximity-based service. The first discovery key management network element may further receive at least one second network identifier from the first communication device, and the second network identifier identifies a network that can provide the proximity-based service for the first communication device. The first discovery key management network element may further determine the target network based on the second network identifier and the at least one first network identifier. Then, the first discovery key management network element may send the second request to the second discovery key management network element in the target network.

[0030] In one possible implementation, a first discovery key management network element may receive security parameters and identifiers of security parameters from a second discovery key management network element. The first discovery key management network element may send a security parameter response message to a first communication device, the security parameter response message including security parameters and identifiers of security parameters.

[0031] For the fourth aspect and the beneficial effects of possible implementations, please refer to the description of the first aspect and the beneficial effects of the corresponding implementation. Repeated sections will not be explained again.

[0032] According to the fifth aspect, a communication method is provided. The method may be carried out by a first terminal device. The first terminal device may be a terminal device or a component within the terminal device. For example, the communication method is carried out by a first terminal device. The method is carried out in the following steps: The first communication device sends a first request to a first discovery key management network element, the first request is used to request security parameters, the first request includes an identifier for a proximity-based service and an identifier for a target network corresponding to the identifier for the proximity-based service, the proximity-based service being a proximity-based service provided by a second communication device for the first communication device, and the target network being the home network of the second communication device. The first communication device receives security parameters from the first discovery key management network element.

[0033] According to the method in the third embodiment, the first terminal device may provide the first discovery key management network element with a correspondence between a proximity-based service identifier and a target network identifier. This helps the first discovery key management network element to efficiently determine the target network identifier, and as a result, the first discovery key management network element can send a security parameter retrieval request to a second discovery key management network element in the target network based on the correspondence in order to obtain security parameters. Thus, the method can improve the efficiency of the discovery process.

[0034] In one possible implementation, the first communication device may obtain a proximity-based service identifier and a target network identifier from the first network element.

[0035] In one possible implementation, the first communication device can obtain from the first network element a proximity-based service identifier and at least one first network identifier corresponding to the proximity-based service identifier, the at least one first network identifier including a target network identifier.

[0036] In one possible implementation, the first communication device can determine a target network based on at least one second network identifier and the at least one first network identifier, the second network identifier identifying a network on which proximity-based services are made available for the first communication device. This implementation allows for a more accurate determination of the target network as a network that is both the home network of the second communication device and a network on which proximity-based services are made available for the first communication device. This further reduces signaling waste, processing resources, and latency in the security parameter acquisition process and improves the performance of the discovery process. Alternatively, the first requirement includes a proximity-based service identifier, at least one first network identifier corresponding to the proximity-based service identifier, and at least one second network identifier. Optionally, the first discovery key management network element can determine the target network based on the at least one second network identifier and the at least one first network identifier.

[0037] In one possible implementation, the first communication device may obtain security parameters and identifiers of security parameters from the first discovery key management network element.

[0038] In one possible implementation, the first communication device may further transmit a first discovery message, which is used to discover a second communication device, and the first discovery message is protected by using security parameters.

[0039] In one possible implementation, the first discovery message includes a security parameter identifier and another security parameter identifier.

[0040] In one possible implementation, the first communication device may further receive a second discovery message, the second discovery message including a security parameter identifier and a security parameter identifier, the second discovery message being used for the discovery of the first communication device; the first communication device determining the security parameter based on the security parameter identifier; the first communication device processing the second discovery message based on the security parameter.

[0041] For the fifth aspect and the beneficial effects of possible implementations, please refer to the descriptions of the first or third aspect and the corresponding beneficial effects of the implementations of the first or third aspect. Repeated sections will not be explained again.

[0042] According to any of the first to fifth embodiments, the first discovery key management network element is a first discovery name management function network element or a first proximity-based service key management function network element, and the second discovery key management network element is a second discovery name management function network element or a second proximity-based service key management function network element.

[0043] According to any of the first to fifth embodiments, the first network element is a policy control function network element or a unified data management network element for performing unified management and centralized storage of correspondence relationships.

[0044] According to the sixth aspect, a communication device is provided. The device may implement a method according to the first to fifth aspects and any possible design of the first to fifth aspects. The device has the function of a first discovery key management network element, a first network element, or a first terminal device.

[0045] In one optional implementation, the device may include modules that perform and correspond one-to-one with the methods / operations / steps / actions described in the first to fifth embodiments. These modules may be hardware circuits, software, or a combination of hardware circuits and software. In one optional implementation, the device includes a processing unit (sometimes referred to as a processing module) and a communication unit (sometimes referred to as a transceiver module or communication module, etc.). The transceiver unit may implement both transmitting and receiving functions. When the transceiver unit implements a transmitting function, it may be referred to as a transmitting unit (sometimes referred to as a transmitting module). When the transceiver unit implements a receiving function, it may be referred to as a receiving unit (sometimes referred to as a receiving module). The transmitting and receiving units may be the same functional module, which is referred to as a transceiver unit and can implement both transmitting and receiving functions. Alternatively, the transmitting and receiving units may be different functional modules, and "transceiver unit" is a general term for these functional modules.

[0046] For example, when the device is configured to perform the methods described in the first to fifth embodiments, the device may include a communication unit and a processing unit.

[0047] According to the seventh aspect, one embodiment of the present application further provides a communication device including a processor configured to execute a computer program (or computer executable instruction) stored in memory. When the computer program (or computer executable instruction) is executed, the device is made capable of performing methods according to the first to fifth aspects and possible implementations of the first to fifth aspects.

[0048] In one possible implementation, the processor and memory are integrated.

[0049] In another possible implementation, the memory is located outside the communication device.

[0050] The communication device further includes a communication interface. The communication interface is for communication between the communication device and another device, for example, for transmitting or receiving data and / or signals. For example, the communication interface may be a transceiver, circuit, bus, module, or other type of communication interface.

[0051] According to the eighth aspect, a computer-readable storage medium is provided. The computer-readable storage medium is configured to store a computer program or instruction. When the computer program or instruction is executed, a method is performed according to the first to fifth aspects and any possible implementation of the first to fifth aspects.

[0052] According to the ninth aspect, a computer program product including instructions is provided. When the computer program product runs on a computer, a method is performed according to the first to fifth aspects and any possible implementation of the first to fifth aspects.

[0053] According to the tenth aspect, one embodiment of this application further provides a communication device configured to perform methods according to the first to fifth aspects and possible implementations of the first to fifth aspects.

[0054] According to the eleventh aspect, a chip system is provided. The chip system includes logic circuits (or the chip system may be understood to include a processor, which may include logic circuits, etc.), and may further include an input / output interface. The input / output interface may be configured to input messages or to output messages. The input / output interface may be the same interface. In other words, the same interface may implement both a transmit function and a receive function. Alternatively, the input / output interface may include an input interface and an output interface. The input interface may be configured to implement a receive function, i.e., to receive messages. The output interface may be configured to implement a transmit function, i.e., to transmit messages. The logic circuits may be configured to perform operations other than the transmit and receive functions in a manner according to the first to fifth aspects and any possible implementation of the first to fifth aspects. The logic circuits may further be configured to send messages to the input / output interface or to receive messages from another communication device to the input / output interface. The chip system may be configured to implement a method according to the first to fifth embodiments and any of the possible implementations of the first to fifth embodiments. The chip system may include a chip, or it may include a chip and another discrete device.

[0055] Optionally, the chip system may include additional memory, which may be configured to store instructions. Logic circuits can then invoke the instructions stored in memory to perform the corresponding functions.

[0056] According to the twelfth aspect, a communication system is provided. The communication system may include a device configured to perform a method according to the first aspect and any one of the possible implementations thereof, and a device configured to perform a method according to the second aspect and any one of the possible implementations thereof. Optionally, the communication system may further include a device configured to perform a method according to the third aspect and any one of the possible implementations thereof. Alternatively, the communication system may include a device configured to perform a method according to the fourth aspect and any one of the possible implementations thereof, and a device configured to perform a method according to the fifth aspect and any one of the possible implementations thereof.

[0057] For the technical effects of the 6th to 12th aspects, please refer to the description of the beneficial effects of the corresponding methods or implementations in the 1st to 5th aspects. Further details will not be provided here. [Brief explanation of the drawing]

[0058] [Figure 1] This is a diagram of the architecture of a wireless communication system according to one embodiment of this application. [Figure 2] This is a diagram of the ProSe service communication establishment process according to one embodiment of this application. [Figure 3] This is a diagram of a discovery model according to one embodiment of this application. [Figure 4] This is a diagram illustrating a discovery security parameter acquisition procedure according to one embodiment of this application. [Figure 5] This is a schematic flowchart of a communication method according to one embodiment of this application. [Figure 6A] Figures 6A and 6B are schematic flowcharts of another communication method according to one embodiment of this application. [Figure 6B] Figures 6A and 6B are schematic flowcharts of another communication method according to one embodiment of this application. [Figure 7]This is a diagram of a UE discovery procedure according to one embodiment of this application. [Figure 8] This is a schematic flowchart of another communication method according to one embodiment of this application. [Figure 9] This is a schematic flowchart of another communication method according to one embodiment of this application. [Figure 10] This is a diagram showing the configuration of a communication device according to one embodiment of this application. [Figure 11] This is a diagram showing the configuration of another communication device according to one embodiment of this application. [Modes for carrying out the invention]

[0059] Embodiments of this application provide a communication method and apparatus. The method and apparatus are based on the same inventive concept. Since the method and apparatus have similar problem-solving principles, they should refer to each other for implementation, and redundant parts will not be described again.

[0060] The technical solutions provided in the embodiments of this application can be applied to a variety of communication systems. For example, the technical solutions can be applied to LTE systems or 5G systems, or to other future-oriented new systems. This is not particularly limited to the embodiments of this application. Also, the terms “system” and “network” are interchangeable. Hereinafter, the architecture of a 5G communication system is used simply as an example for illustrative purposes.

[0061] Figure 1 shows a 5G communication system as defined in the 3rd Generation Partnership Project (3GPP) standards. This communication system includes terminal devices (e.g., user equipment (UE)), an access network (AN) (e.g., a radio access network (RAN)), and a core network (CN). Logically, in the case of a data network (DN), the network elements of the core network can be divided into two parts: the user plane and the control plane. The control plane is responsible for mobile network management, and the user plane is responsible for service data transmission.

[0062] Terminal devices serve as an entry point for interaction between mobile users and the network, providing basic computing and memory capabilities, displaying a service window to the user, and receiving user input. Next-generation terminal devices (NextGen UEs) can establish signal and data connectivity to the RAN by using new radio technology to transmit control signals and service data to the mobile network. Terminal devices may include various handheld devices, in-vehicle devices, unmanned aerial vehicles, wearable devices, or computing devices with wireless communication capabilities, or other processing devices connected to wireless modems, as well as various forms of terminals such as mobile stations (MS), terminals, and software terminals, such as water meters, electricity meters, and sensors.

[0063] A RAN (Range Area) is deployed near terminal devices, providing network access to authorized users within a specific area, and can determine transmission tunnels of different quality based on user level and service requirements to perform user data transmission. The RAN manages its resources, uses them appropriately, can provide access services to terminal devices on demand, and is responsible for transferring control signals and user data between terminal devices and the core network.

[0064] The core network is responsible for maintaining mobile network subscription data, managing the network elements of the mobile network, and providing functions to terminal devices such as session management, mobility management, policy management, and security authentication. The core network provides network access authentication to terminal devices when they are attached, allocates network resources to terminal devices when they have service requests, updates network resources to terminal devices when they move, provides terminal devices with a fast recovery mechanism when they are idle, releases network resources to terminal devices when they are detached, and provides data routing functionality to terminal devices when they have service data, such as forwarding uplink data to the data network or receiving downlink data from the data network and forwarding that downlink data to the RAN so that the RAN can send downlink data to terminal devices.

[0065] A data network (DN) is a data network that provides services to users. Generally, clients reside within terminal devices, and servers reside within the data network. A data network may be a private network, such as a local area network; an external network not managed or controlled by an operator, such as the Internet; or a dedicated network jointly deployed by an operator, such as a network providing IP multimedia core network subsystem (IMS) services.

[0066] The core network's user plane includes the user plane function (UPF). The core network's control plane includes the access and mobility management function (AMF), session management function (SMF), network exposure function (NEF), network function repository function (NRF), unified data management (UDM), policy control function (PCF), application function (AF), authentication server function (AUSF), network slice selection function (NSSF), and network slice-specific authentication and authorization function (NSSAAF).

[0067] The core network control plane uses a service-oriented architecture. The point-to-point communication mode in traditional architectures is replaced by a service call mode for interaction between control plane network elements. In a service-oriented architecture, a control plane network element exposes a service to another control plane network element for use by that other control plane functional network element. In point-to-point communication, a specific set of messages is stored in a communication interface between control plane network element stores and can only be used by the control plane network elements at both ends of the interface during communication.

[0068] The following briefly describes the functions of the functional entities within the core network.

[0069] 1. The session management network element is primarily configured for session management, IP address assignment and management of terminal devices, selection of endpoints capable of managing user device plane function interfaces and policy control or billing function interfaces, and downlink data notification. In 5G communication, the session management network element may be an SMF network element. In future communications, such as 6G communication, the session management function network element may still be an SMF network element or may have a different name. This is not limited to this application. Nsmf is a service-based interface provided by SMF. SMF can communicate with other network functions via Nsmf.

[0070] 2. Access management network elements are primarily configured for mobility management and access management. For example, an access management network element may be a mobility management entity (MME) function in a 4G communication network, or an AMF network element in a 5G network. In future communications such as 6G communications, the access management function network element may still be an AMF network element, or it may have a different name. This is not limited to this application. Namf is a service-based interface provided by AMF. AMF can communicate with other network functions via Namf.

[0071] 3. Network-exposed network elements are primarily configured to securely expose services and capabilities provided by 3GPP network functions to the outside. In 5G communications, network-exposed network elements can be NEF network elements. In future communications, such as 6G communications, network-exposed function network elements may still be NEF network elements or may have a different name. This is not limited to this application. An NEF is a service-based interface provided by an NEF. An NEF can communicate with other network functions via an NEF.

[0072] 4. The network repository network element is used for service registration, discovery, and authorization, as well as for maintaining information on available network function (NF) instances, in order to implement on-demand configuration of network functions and services and interconnection between NFs. In 5G communications, the network repository network element may be an NRF network element. In future communications, such as 6G communications, the network repository function network element may still be an NRF network element or may have a different name. This is not limited to this application. An NRF is a service-based interface provided by an NRF. An NRF may communicate with other network functions via an NRF.

[0073] 5. Policy control network elements are configured to guide a unified policy framework for network behavior and to provide policy rule information, etc., for control plane function network elements (e.g., AMF or SMF). In 5G communications, policy control network elements may be PCF network elements. In future communications, such as 6G communications, policy control network elements may still be PCF network elements or may have a different name. This is not limited to this application. Npcf is a service-based interface provided by PCF. PCF may communicate with other network functions via Npcf.

[0074] 6. Data management network elements are configured for user identifier processing, enrollment, access authentication, registration, or mobility management, etc. In 5G communications, data management network elements may be UDM network elements. In future communications, such as 6G communications, data management network elements may still be UDM network elements or may have a different name. This is not limited to this application. A NuDM is a service-based interface provided by a UDM. A UDM may communicate with other network functions via a NuDM.

[0075] 7. Application network elements are configured for application-influenced data routing, access to network exposure functions, or interaction with a policy framework for policy control. In 5G communications, application network elements may be AF network elements. In future communications, such as 6G communications, application network elements may still be AF network elements or may have a different name. This is not limited to this application. A Naf is a service-based interface provided by an AF. An AF may communicate with other network functions via a Naf.

[0076] 8. User plane network elements are used for packet routing and forwarding, or for quality of service (QoS) processing of user plane data. In 5G communication, user plane network elements may be user plane function (UPF) network elements. In future communications such as 6G communication, user plane network elements may still be UPF network elements or may have a different name. This is not limited to this application.

[0077] 9. Authentication service network elements are primarily configured for purposes such as user authentication. In 5G communication, authentication service network elements can be AUSF network elements. In future communications, such as 6G communication, authentication service network elements may still be AUSF network elements or may have a different name. This is not limited to this application. Nausf is a service-based interface provided by AUSF. AUSF can communicate with other network functions via Nausf.

[0078] 10. The network slice selection function network element is configured for selecting a network slice for a terminal device. In 5G communication, the network slice selection function network element may be an NSSF network element. In future communications, such as 6G communication, the network slice selection function network element may still be an NSSF network element or may have a different name. This is not limited to the present invention.

[0079] 11. Network slice-specific authentication and authorization function: Network elements are primarily responsible for the authentication and authorization of network slices and can interact with the authentication, authorization, and accounting server (AAA-S) via the authentication, authorization, and accounting proxy (AAA-P).

[0080] 12. The discovery key management network element is primarily responsible for managing (e.g., assigning and storing) discovery security parameters, which may be abbreviated as security parameters, and is used to protect relevant discovery messages in the UE discovery process during proximity-based service execution. Optionally, discovery security parameters may be managed by a PCF instead. In 5G communications, the discovery key management network element may be a direct discovery name management function (DDNMF) network element or a proximity-based service key management function (PKMF) network element. A DDNMF network element may also be referred to as a 5G DDNMF network element, and a PKMF network element may also be referred to as a 5G PKMF network element. In future communications, such as 6G communications, the discovery key management network element may still be a DDNMF network element or a PKMF network element, or it may have a different name. This is not limited to the present invention.

[0081] It should be understood that the xx network element in this application may be abbreviated as xx. For example, the SMF network element will be abbreviated as SMF. In other words, the SMF network element and SMF are interchangeable.

[0082] It can be understood that the core network may further include other network elements. This is not limited to the present invention.

[0083] The technical terms used in this application are explained below.

[0084] (1) ProSe service

[0085] With the rapid development of mobile communications, the widespread use of new service types, such as video chat, virtual reality (VR), and augmented reality (AR), is increasing users' bandwidth demands. D2D communication enables direct communication between UEs, allowing UEs to share spectrum resources with cell users under the control of the cell network, thereby effectively increasing the utilization of spectrum resources. Currently, D2D communication is applied to 4G network systems and is collectively referred to as ProSe services.

[0086] D2D communication includes one-to-many communication and one-to-one communication. One-to-many communication supports multicast and broadcast communication, while one-to-one communication supports unicast communication. In one-to-one communication, if the transmitting UE and receiving UE are within short range, they can communicate directly with each other after mutual discovery. In D2D communication, UEs communicate with each other via the Direct Communication Protocol (PC5) interface for information transmission on the data plane and signaling plane. A link through which UEs directly perform direct communication via PC5 is also called a sidelink (SL).

[0087] Compared to conventional cellular network communication, UEs capable of ProSe communication must possess ProSe functionality. UEs with ProSe functionality communicate with each other via the PC5 interface. For example, a 5G communication system is used as an example. The PCF network element primarily supports providing policies used for ProSe services for UEs with ProSe functionality and is responsible for obtaining UE subscription data related to policy determination for ProSe service functionality.

[0088] For example, ProSe services may include UE-to-network relay communication services, UE-to-UE relay communication services, or other PC5 interface-based communication services. Relay services may be proximity-based services provided by UE-to-network relay for remote UEs.

[0089] (2) Procedure for establishing ProSe service communication

[0090] Before the ProSe service is formally executed (i.e., before the ProSe user plane data is formally transmitted), the steps 1 through 4 shown in Figure 2 must be performed, including the ProSe parameter configuration procedure, the ProSe discovery procedure, and the ProSe PC5 unicast establishment procedure. If the ProSe service is a ProSe UE-to-network relay communication service, the remote UE then establishes communication with the network via the relay UE's communication relay. If the ProSe service is a ProSe UE-to-UE relay communication service, the end UE then establishes communication with another end UE via the relay UE's communication relay (UE-to-UE relay). It should be understood that the present invention later uses ProSe UE-to-network relay communication as an example, but should not be limited to this scenario. In practice, further UE-to-UE relay communication service scenarios or other subsequent ProSe service scenarios may be included.

[0091] (3) ProSe UE-to-Network Relay Parameter Configuration

[0092] Step 1 in Figure 2 is the ProSe parameter configuration procedure. According to the current definition in the 3GPP technical specification (TS) 23.304, the ProSe parameters obtained by the UE in Step 1 can have different sources and corresponding usage priorities. Specifically, ProSe parameters from the PCF are used preferentially, followed by ProSe parameters from the ProSe application server (ProSe App server), then ProSe parameters pre-configured in the universal subscriber identity module (UICC), and finally, ProSe parameters pre-configured in the mobile equipment (ME). The ME is a UE that does not have a UICC.

[0093] In a UE-to-network relay scenario, the pre-configured ProSe parameters for the remote UE and relay UE include one of A, B, or C.

[0094] A: This is a relay service code (RSC) that identifies a specific relay service, and the RSCs for different UE-to-network relay services are not repeated. For example, the RSC for UE-to-network relay service A in all public land mobile network (PLMN) is RSC-A, and two different services will not have the same RSC in different PLMNs or in the same PLMN.

[0095] B: A list of PLMNs that remote UEs are permitted to use the UE-to-Network Relay Service.

[0096] C: A list of PLMNs (Planned Relay Modules) that a relay UE is permitted to provide UE-to-Network relay services to another UE. This list of PLMNs may differ from the list of PLMNs that a remote UE is permitted to use for UE-to-Network relay services.

[0097] Optionally, the ProSe parameters for a remote UE can include A and B, and the ProSe parameters for a relay UE can include A and C.

[0098] (4) Overview of the ProSe Discovery Procedure

[0099] Step 2 in Figure 2 is the ProSe discovery procedure. The ProSe discovery procedure must be performed before ProSe UE-to-network relay communication in order to determine the peer end for communication. As shown in Figure 3, existing 4G ProSe standards (see, for example, 3GPP TS 23.303) have two discovery models in Step 2, namely discovery model A and discovery model B, and one of the two models is selected for execution. It can be understood that discovery model A is sometimes abbreviated as model A, and discovery model B is sometimes abbreviated as model B. Models A and B can be described separately as follows:

[0100] Model A: In the Model A discovery procedure, the UEs at both ends are classified as an announcing UE (A-UE) and a monitoring UE (M-UE). After obtaining the ProSe parameters, the announcing UE actively announces proximity-based services of interest to the announcing UE. After obtaining the ProSe parameters, the monitoring UE is configured to monitor proximity-based services of interest to the monitoring UE. The initial message in the Model A discovery procedure (e.g., the discovery announcement shown in Figure 3) is initiated by the A-UE. After receiving the message from the A-UE, the M-UE decides whether to continue with the subsequent procedure based on whether the M-UE's service request is met. The subsequent procedure is, for example, to initiate unicast communication establishment. Figure 3 illustrates Model A using an example where the relay UE is used as the A-UE and the remote UE is used as the M-UE.

[0101] Model B: In the Model B discovery procedure, the UEs at both ends are classified as the discoveree UE and the discoverer UE. The initial message in the Model B discovery procedure (for example, the discovery request shown in Figure 3) is initiated by the discoverer UE requesting the service. After receiving the request, the discoveree UE decides whether to respond to the request message or, for example, to respond with a discovery response, based on whether the discoveree UE can provide the service. After receiving the response message, the discoverer UE initiates the subsequent procedure, which is, for example, to initiate unicast communication establishment. Figure 3 illustrates Model B using an example where the remote UE is used as the discoverer UE and the relay UE is used as the discoveree UE.

[0102] (5) Procedure for obtaining parameters for ProSe UE-to-Network Relay Discovery

[0103] Figure 4 illustrates the discovery security parameter acquisition procedure using an example where the ProSe UE-to-Network Relay scenario is applicable to Model A mode. Model B mode is similar, the only difference being that the M-UE is replaced by the discovering UE and the A-UE is replaced by the discovered UE. Therefore, details will not be explained separately. The figure illustrates this using an example where DDNMF manages the discovery security parameters. In the standard, discovery security parameters may be managed by 5G PKMF instead. Details will not be explained separately. In this application, security parameter management may include steps such as assigning, maintaining, or distributing security parameters. Note that Figure 4 is an appendix drawing in standard TS 33.503. In this standard, the same flowchart is used for discovery parameter acquisition in UE-to-Network Relay scenarios and for discovery parameter acquisition in UE-to-UE direct communication. Therefore, the message names and specific procedures follow the description below.

[0104] 1. The A-UE sends a discovery key request to the 5G DDNMF within the A-UE's home public land mobile network (HPLMN) to request the acquisition of discovery security parameters used in the UE-to-network relay scenario. The discovery key request carries the RSC to identify the relevant UE-to-network relay service. The 5G DDNMF will be abbreviated as A-DDNMF below. The HPLMN may also be referred to as the home network.

[0105] 2. A-DDNMF may use UDM to check whether A-UE has permission to perform UE-to-Network Relay Discovery. Therefore, the ProSe application server in the diagram may be replaced with a UDM in A-UE's HPLMN.

[0106] 3. If A-UE is in a visited state, A-DDNMF obtains discovery permission from DDNMF within A-UE's visited PLMN (VPLMN) and determines that A-UE can perform UE-to-network relay discovery within the VPLMN.

[0107] 4. The A-DDNMF determines the security parameters to be used for UE-to-relay discovery, which is performed based on the same RSC as in step 1, and sends a discovery key response to the A-UE, which carries the RSC and the security parameters to be used for discovery. For example, if the relay UE is the A-UE, the discovery parameters are generated by the DDNMF in the relay UE's HPLMN. If there are multiple relay UEs belonging to different HPLMNs, different discovery security parameters are generated by different DDNMFs in those HPLMNs. If two relay UEs belong to the same HPLMN, the DDNMF may provide the same set of discovery security parameters for those two relay UEs.

[0108] 5. The M-UE sends a discovery key request to the DDNMF in the M-UE's HPLMN (labeled M-DDNMF in Figure 4) to request the discovery security parameters used in the UE-to-Network relay scenario. The discovery key request carries the RSC to identify the UE-to-Network relay service in question. The 5G DDNMF will be abbreviated as A-DDNMF below. In this step, the RSC in Step 1 and Step 5 are the same, as the A-UE and M-UE will subsequently need to discover each other. In this step, the M-UE may further send a list of PLMNs in which the M-UE is permitted to use the UE-to-Network relay service.

[0109] It should also be noted that the standard allows A-UE and M-UE to have different HPLMNs, and therefore, the DDNMFs corresponding to A-UE and M-UE are also different.

[0110] 6. The M-DDNMF may use the UDM to check whether the M-UE has permission to perform UE-to-Network Relay Discovery. Therefore, the ProSe App server in the diagram may be replaced with the UDM in the M-UE's HPLMN.

[0111] 7. The M-DDNMF sends a relay discovery key request to the A-DDNMF to request the discovery of the security parameters, and the relay discovery key request carries the RSC. Based on the list of PLMNs provided by the M-UE in step 5, the M-DDNMF can determine which DDNMF to which it should send the request.

[0112] 8. A-DDNMF responds to M-DDNMF with a relay discovery key response, which carries the RSC and the security parameters determined in step 4.

[0113] Additionally, it should be noted that if M-DDNMF sends requests to multiple A-DDNMFs in step 7, multiple security parameters may be obtained from multiple A-DDNMFs in step 8.

[0114] 9. The M-DDNMF sends a discovery key response to the M-UE, which carries the RSC and the security parameters obtained in step 8.

[0115] 10 and 11. The A-UE and M-UE separately protect and unprotect (or process protected discovery messages) using the acquired security parameters, thereby establishing communication between the A-UE and the M-UE. For example, in steps 10 and 11, the A-UE and M-UE may perform discovery using discovery model A or discovery model B.

[0116] 12. The communication process in a UE-to-network communication scenario is as follows: for example, an A-UE or M-UE acting as a remote UE establishes a connection to the network via an A-UE or M-UE acting as a relay UE, and transmits data to and receives data from the network. This process is not limited to this application.

[0117] It should also be noted that the discovery security parameters may be configured by the PCF for the UE without performing the procedure described above.

[0118] Based on the procedure in Figure 4, the reliability of the UE discovery process in current UE-to-network relay communication services needs to be improved. Therefore, the reliability of the device discovery process in current proximity-based service communications needs to be improved.

[0119] Remote UEs and relay UEs are each permitted to use a list of PLMNs in UE-to-Network relay services, meaning that a UE can use UE-to-Network relay services when served by a PLMN in the list. However, the lists of PLMNs for these two UEs can be different, and the HPLMNs for different relay UEs can also be different. Therefore, with respect to UE-to-Network relay services (identified by RSCs), the following cases exist (see Table 1).

[0120] The remote UEs are enabled to provide services in {PLMN-1, PLMN-2, PLMN-3, PLMN-4}. Relay UE-1 and relay UE-2 are enabled to provide services in {PLMN-2, PLMN-3, PLMN-4, PLMN-5, PLMN-6}. The HPLMN for relay UE-1 is PLMN-5, and the HPLMN for relay UE-2 is PLMN-4. [Table 1]

[0121] In this case, as explained in steps 1 to 4 of Figure 4, relay UE-1 and relay UE-2 send discovery key requests to the DDNMF in the HPLMN of relay UE-1 and the DDNMF in the HPLMN of relay UE-2, respectively, to generate security parameters used for discovery. Since the HPLMN of relay UE-1 and the HPLMN of relay UE-2 are PLMN-5 and PLMN-4, respectively, the DDNMF that generates the security parameters for relay UE-1 is different from the DDNMF that generates the security parameters for relay UE-2. In this case, the DDNMF of relay UE-1 (in PLMN-5) generates security parameter-1, and the DDNMF of relay UE-2 (in PLMN-4) generates security parameter-2.

[0122] Furthermore, as explained in step 5, the M-UE may also send a list of PLMNs in which the M-UE is permitted to use the UE-to-Network Relay Service to the M-DDNMF. In this case, the M-UE's (remote UE's) DDNMF (M-DDNMF) sends the relay discovery key request only to the DDNMFs in PLMN-1, PLMN-2, PLMN-3, and PLMN-4. As enumerated in the table above, in this case, only the DDNMF in PLMN-4 returns the RSC and security parameter-2 to the remote UE's DDNMF.

[0123] Therefore, the following problems arise with conventional technology.

[0124] 1. A DDNMF interacts with multiple potential DDNMFs, and these DDNMFs may not have the corresponding security parameters, resulting in wasted signaling and delays. For example, as shown in Table 1, a DDNMF corresponding to a remote UE attempts to obtain security parameters from DDNMFs in PLMN-1, PLMN-2, PLMN-3, and PLMN-4. However, currently, only PLMN-4 has a UE-2 capable of performing relay services. Therefore, the DDNMF performs the step of requesting (or attempting to obtain) security parameters from DDNMFs in PLMN-1, PLMN-2, and PLMN-3, but the DDNMF is unable to obtain the corresponding security parameters, resulting in wasted signaling, processing resources, and delays.

[0125] 2. The DDNMF interacts with multiple potential DDNMFs based solely on the list of PLMNs provided by the M-UE that the M-UE is permitted to use the UE-to-Network relay service. However, these PLMNs may not include the HPLMN of the relay (e.g., the HPLMN of relay UE-1). As a result, the corresponding relay may not be effectively discovered, and the subsequent normal operation of the UE-to-Network relay service may be affected. For example, as shown in Table 1, the DDNMF corresponding to a remote UE attempts to obtain security parameters from the DDNMFs in PLMN-1, PLMN-2, PLMN-3, and PLMN-4. However, currently, only UE-1 exists in PLMN-5 that can perform the relay service. Therefore, the DDNMF performs the step of requesting (or attempting to obtain) security parameters from the DDNMFs in PLMN-1, PLMN-2, PLMN-3, and PLMN-4, but the DDNMF is unable to obtain the corresponding security parameters. As a result, the corresponding relay UE cannot be effectively discovered, preventing the relay service from running properly and leading to wasted signaling, processing resources, and latency.

[0126] To improve the reliability of the device discovery process in proximity-based services and enhance the performance of proximity-based services, this application provides a communication method. In this communication method, a first communication device may send a security parameter retrieval request (which may be referred to as a first request) to a first discovery key management network element in the network (e.g., PLMN) of the first communication device in order to request security parameters. This request may carry the proximity-based service identifier (ID), e.g., RSC, of ​​the first communication device. The proximity-based service identifier corresponds to the identifier of a target network, the target network being the home network of a second terminal device that provides proximity-based services for a first terminal device. Thus, the first discovery key management network element can send a security parameter retrieval request (which may be referred to as a second request) to a second discovery key management network element in the target network in order to request security parameters, thereby enabling communication between the first communication device and the second communication device based on the security parameters and enabling proximity-based service communication between the first terminal device and the second terminal device. The first and second communication devices can each be terminal devices, such as UEs. A correspondence exists between the proximity-based service identifier and the target network identifier. Therefore, the first discovery key management network element can accurately and efficiently determine the second discovery key management network element. This reduces signaling waste, processing resources, and latency in the security parameter acquisition process, improving the performance of the discovery process.

[0127] It can be understood that, in the aforementioned process, the discovery key management network element can be DDNMF or PKMF, the network and target network can be PLMN, and the communication device can be UE.

[0128] It can be further understood that, in embodiments of this application, actions performed by a network element or device may be replaced by actions performed by a component within the network element or device. The component in this application may include, for example, at least one of a chip, a chip system, a processor, a transceiver, a processing unit, or a transceiver unit.

[0129] The method will be described below with reference to Figure 5. In the embodiment shown in Figure 5, the first discovery key management network element can obtain the identifier of the target network from the first network element. The first network element may be a core network element other than the discovery key management network element, such as a policy control network element or a data management network element. In Figure 5, the explanation will be given using an example where the first communication device and the second communication device are the first UE and the second UE, respectively, and the first discovery key management network element is the first DDNMF.

[0130] As shown in Figure 5, the communication method provided in this embodiment of the application may include steps S101-S105.

[0131] S101: The first UE sends a first request to the first DDNMF, which is used to request security parameters, and which includes an identifier for proximity-based services. The first DDNMF may be a DDNMF within the HPLMN of the first UE.

[0132] In response, the first DDNMF receives the first request.

[0133] Optionally, the first request may be a discovery key request, a discovery request, or a relay discovery key request. A discovery key request may be used to request the retrieval of one or more of the following security parameters, namely, a confidentiality key, an integrity key, a scramble-protection key, or time window information.

[0134] A proximity-based service may be a service provided by the second UE for the first UE. For example, a proximity-based service is a relay service, in which case the second UE can be used as a relay UE and the first UE can be used as a remote UE. Alternatively, a proximity-based service may be a service provided by the first UE for the second UE. For example, the first UE can be used as a relay UE and the second UE can be used as a remote UE. Alternatively, a proximity-based service may be a service for communication between the second UE and the first UE. For example, the first and second UEs establish a connection and perform data communication with each other. In the following description, for example, a proximity-based service is a service provided by the second UE for the first UE. It should be understood that in the following description, a proximity-based service may instead be a service provided by the first UE for the second UE, or a service for communication between the second UE and the first UE.

[0135] An identifier for proximity-based services may correspond to an identifier for one or more networks. A network identifier is, for example, a PLMN ID. These one or more networks may include the HPLMN of a second UE. For example, the identifier for proximity-based services may be an RSC. An RSC can identify a specific proximity-based service, such as a proximity-based service provided by a second UE for a first UE. In this application, an RSC may correspond to an identifier for one or more networks. These one or more network identifiers include the HPLMN of a second UE, where the HPLMN of the second UE is the target network. In Figure 5, for example, the second UE is a relay UE. Correspondingly, the target network is the PLMN of a second DDNMF, and is denoted as a relay HPLMN. Therefore, the identifier for the target network may be denoted as a relay HPLMN ID. Furthermore, the fact that an RSC may correspond to one or more network identifiers further includes that the one or more network identifiers include HPLMN identifiers of multiple relay UEs capable of providing services corresponding to the RSC, and that these identifiers include network identifiers of HPLMNs of a second UE.

[0136] In one embodiment, the correspondence between a proximity-based service identifier and a network identifier may be pre-configured in a core network element other than DDNMF. Thus, the core network element can store the correspondence between the proximity-based service identifier and the network identifier. For example, the proximity-based service identifier is RSC, and the corresponding network identifier is PLMN ID. The correspondence between RSC and PLMN ID is pre-configured in the core network element. The core network element may include a first network element, or it may include a first network element and a first core network element other than DDNMF. This is not particularly limited. For example, as shown in Figure 6A, the correspondence between RSC and PLMN ID is pre-configured in a first network element. The first network element is, for example, PCF or UDM. In another example, the correspondence between RSC and PLMN ID is pre-configured in a first network element and a first core network element other than DDNMF. For example, the first network element may be PCF, and the core network element may be UDM. Furthermore, the pre-configuration of the correspondence between RSC and PLMN ID in the core network element includes the pre-configuration of the correspondence between RSC and the HPLMN identifier of at least one relay UE capable of providing the service corresponding to RSC, and that this correspondence includes the correspondence between RSC and the network identifier of the HPLMN of a second UE.

[0137] It can be understood that PCF or UDM is used as a first network element and can store correspondences between a large number of proximity base service identifiers and their corresponding target network identifiers. Thus, network elements within the core network can store correspondences between proximity base service identifiers and target network identifiers in a unified manner, enabling unified management and centralized storage of these correspondences. For example, if the correspondences are pre-configured in a network element such as DDNMF or PKMF, it may be difficult to implement the aforementioned unified storage of the correspondences due to the limited capabilities and memory space of that network element, and correspondences relating to different proximity base service identifiers may need to be stored in different network elements.

[0138] Optionally, prior to S101, the first UE may obtain a ProSe parameter. The ProSe parameter may be used by the first UE to perform a discovery procedure. The ProSe parameter may include an identifier for the proximity-based service in S101, such as RSC. In addition, the ProSe parameter may further include information about PLMNs that are made available to provide proximity-based services for the first UE, such as the ID of the PLMN that is made available to provide proximity-based services for the first UE, or a list (hereinafter abbreviated as the PLMN list) containing multiple PLMN IDs that are made available to provide proximity-based services for the first UE. The ID of the PLMN that is made available to provide proximity-based services for the first UE may further mean that the first UE can use that proximity-based service when the first UE is serviced by that PLMN, or that the first UE is made available to use that proximity-based service.

[0139] For example, the first UE can send a ProSe parameter retrieval request to the network, and the AMF sends the request to the PCF. The PCF may retrieve ProSe service-related information from the UDM within the first UE's subscription information in order to determine the ProSe parameters. ProSe service-related information is, for example, ProSe service-specific information.

[0140] It can be understood that, for the sake of facilitating the following explanation, the identifiers of one or more networks corresponding to the proximity-based service identifier are referred to as the first network identifier, and the identifiers that identify the networks that are made capable of providing proximity-based services for the first UE are referred to as the second network identifier.

[0141] Optionally, the first request may further include a second network identifier, which may include, for example, the ID or list of PLMNs that enable proximity-based services for the first UE.

[0142] S102: The first DDNMF obtains the target network identifier corresponding to the proximity-based service identifier from the first network element.

[0143] Optionally, in S102, the first DDNMF may send a network identifier acquisition request to the first network element, which may carry the identifier of a proximity-based service, and as a result, the first network element may determine the identifier of the corresponding target network based on the identifier of the proximity-based service. Correspondingly, the first network element may determine the identifier of the target network corresponding to the identifier of the proximity-based service carried in the network identifier acquisition request, based on the correspondence between the identifier of the proximity-based service and the first network identifier. The identifier of a proximity-based service may correspond to at least one first network identifier, and this at least one first network identifier may include the identifier of a target network. In this case, the first network element may send this at least one first network identifier to the first DDNMF.

[0144] For example, if the identifier for the proximity base service is RSC-1, and in the correspondence between the identifier for the proximity base service and the at least one first network identifier, RSC-1 corresponds to the identifier for PLMN-4, then it can be determined that the at least one first network identifier corresponding to RSC-1 is the identifier for PLMN-4. In another example, if the identifier for the proximity base service is RSC-1, and in the correspondence between the identifier for the proximity base service and the at least one first network identifier, RSC-1 corresponds to the identifiers for PLMN-4 and PLMN-5, then it can be determined that the at least one first network identifier corresponding to RSC-1 is the identifiers for PLMN-4 and PLMN-5.

[0145] As shown in Figure 6A, when the first network element is a PCF, the process by which the first DDNMF obtains at least one first network identifier from the first network element is shown in steps 4a and 6a of Figure 6A. In step 4a, the first DDNMF can send an Npcf request to the PCF, which is used to carry the RSC and request information about the PLMN ID corresponding to the RSC. In step 6a, the PCF can send an Npcf response to the first DDNMF, which carries information about the PLMN ID corresponding to the RSC. Similarly, when the first network element is a UDM, the process by which the first DDNMF obtains at least one first network identifier from the first network element is shown in steps 4b and 6b of Figures 6A and 6B.

[0146] Optionally, before the first network element provides the target network identifier to the first DDNMF in S102, the first network element may decide that the proximity-based service security parameters are managed by the DDNMF, or the first network element may decide that the proximity-based service security parameters are not managed by the first network element. DDNMF here includes, but is not limited to, the first DDNMF. If the proximity-based service security parameters are managed by the first network element, the second DDNMF does not need to provide the security parameters, and the first network element may refuse to send the target network identifier to the first DDNMF.

[0147] For example, the first network element is a PCF. The PCF receives a network identifier retrieval request and may query whether the security parameters of the proximity-based service are managed by the first network element (i.e., the PCF) based on the proximity-based service identifier in the request. If the security parameters of the proximity-based service are managed by the PCF, the first network element may send a rejection response message to the first DDNMF to reject the request. If it is determined that the security parameters of the proximity-based service are not managed by the PCF, or if it is determined that the security parameters of the proximity-based service are managed by the DDNMF, the first network element may determine at least one corresponding first network identifier based on the proximity-based service identifier. Use Figures 6A and 6B as examples. When the PCF is used as the first network element, as shown in step 5a of Figure 6A, the PCF may determine that the security parameters of the proximity-based service are not managed by the PCF and then perform step 6a. For example, the network identifier retrieval request is, for example, a core network interface message of the first network element.

[0148] In another example, if the first network element is a UDM, the first network element may send a proximity-based service identifier to a PCF and, based on the PCF's response information, determine whether the proximity-based service security parameters are managed by the PCF. If the UDM determines that the proximity-based service security parameters are managed by the PCF, the UDM may send a rejection response message to the first DDNMF to reject the request. If the UDM determines that the proximity-based service security parameters are not managed by the PCF, or if the UDM determines that the proximity-based service security parameters are managed by the DDNMF, the UDM may determine a corresponding at least one first network identifier based on the proximity-based service identifier and send the at least one first network identifier to the first DDNMF.

[0149] Optionally, the first DDNMF may store the correspondence between the proximity-based service identifier in the first request and at least one first network identifier obtained from the first network element, so that after subsequently receiving a discovery key request carrying the proximity-based service identifier, the first DDNMF can determine, based on the stored correspondence, at least one first network identifier corresponding to the proximity-based service identifier. Thus, the first DDNMF does not need to request the first network element again for the first network identifier corresponding to the proximity-based service identifier. This can further reduce signaling waste, processing resources, and latency in the security parameter acquisition process and improve the performance of the discovery process.

[0150] For example, as shown in Figures 6A and 6B, the first DDNMF may obtain and store the correspondence between the RSC and the PLMN ID through steps 4a and 6a or steps 4b and 6b. When the third UE sends a discovery key request to the first DDNMF in step 11, carrying the same RSC, the first DDNMF may determine the target PLMN corresponding to the third UE by using the previously stored correspondence between the RSC and the PLMN ID, and then request security parameters from the relay DDNMF. It can be understood that the relay DDNMF may be the same as or different from the second DDNMF determined in step 7 of the procedure shown in Figure 6B. The second DDNMF may be based on the target PLMN corresponding to the first UE.

[0151] Prior to S102, the first DDNMF may further determine that it does not store the correspondence between the proximity-based service identifier and the first network identifier. In other words, the first DDNMF has not obtained the first network identifier from the first network element prior to S102. If the first network element has obtained the first network identifier from the first network element prior to S102 based on another network identifier acquisition request that carries the proximity-based service identifier, the first network element stores the correspondence between the proximity-based service identifier and the first network identifier. If the correspondence is stored, the first DDNMF does not need to perform S102, and the first DDNMF can determine the first network identifier corresponding to the proximity-based service identifier based on the stored correspondence.

[0152] Optionally, if the first network element has previously received a network identifier retrieval request carrying a proximity-based service identifier, sent by the first DDNMF, the first network element may store the proximity-based service identifier or the correspondence between the proximity-based service identifier and the first DDNMF. As a result, after subsequently receiving a network identifier retrieval request carrying a proximity-based service identifier, the first network element will determine, based on the stored proximity-based service identifier, that the first network identifier corresponding to the proximity-based service identifier has been requested. Therefore, the first network element does not need to provide the first network identifier to the first DDNMF again. After receiving the first request carrying a proximity-based service identifier again, the first network element can reject the first request, avoiding the processing and signaling overhead caused by repeated queries, and further preventing another network element from pretending to be the first DDNMF to retrieve the first network identifier. Use Figures 6A and 6B as examples. If PCF is used as the first network element, as shown in step 5a of Figure 6A, the PCF may determine that it has not previously received a Network Identifier Acquisition Request carrying the identifier of a proximity-based service, which was sent by the first DDNMF, and then perform step 6a. If UDM is used as the first network element, as shown in step 5b of Figure 6B, the UDM may determine that it has not previously received a Network Identifier Acquisition Request carrying the identifier of a proximity-based service, which was sent by the first DDNMF, and then perform step 6b.

[0153] In S102, after receiving the first network identifier, the first DDNMF may determine the identifier of the target network based on the first network identifier.

[0154] The target network can be one or more networks.

[0155] In one embodiment, the first DDNMF can use the first network identifier as the target network identifier, and thus the target network can be determined based on the target network identifier. For example, if the first network identifier is the identifier for PLMN-4, then the target network is PLMN-4.

[0156] In another embodiment, the first DDNMF may determine the identifier of a target network based on at least one first network identifier and at least one second network identifier. The first request may further include the at least one second network identifier, or the first DDNMF may further receive the at least one second network identifier transmitted by the first UE in a message other than the first request.

[0157] For example, the identifier for proximity-based services is RSC. The first network identifier may include one or more PLMN IDs. The first request further includes a list of PLMNs that are made capable of providing proximity-based services for the first UE. The list of PLMNs may include at least one PLMN ID, which is the second network identifier. In this case, the first DDNMF may determine the intersection of the one or more PLMN IDs included in the first network identifier and the PLMN IDs included in the list of PLMNs, and use the PLMN IDs included in that intersection as the identifier for the target network. Thus, the target network can be determined. For example, the first network identifier includes the identifiers for PLMN-4 and PLMN-5, and the second network identifier includes the identifiers for PLMN-1, PLMN-2, PLMN-3, and PLMN-4. Therefore, the first DDNMF may determine that the identifier for the target network is the identifier for PLMN-4, i.e., the target network is PLMN-4. In another example, the first network identifier includes the identifiers for PLMN-4 and PLMN-5, and the second network identifier includes the identifiers for PLMN-1, PLMN-2, PLMN-3, PLMN-4, and PLMN-5. Therefore, the first DDNMF can determine, by obtaining the common set, that the identifiers of the target network are the identifiers for PLMN-4 and PLMN-5, i.e., the target network is PLMN-4 and PLMN-5. Thus, the network that is a PLMN capable of providing proximity-based services for the first UE, along with the relay UE's home network, can be more accurately determined as the target network. This further reduces signaling waste, processing resources, and latency in the security parameter acquisition process and improves the performance of the discovery process.

[0158] Optionally, in S102, after determining the target network, the first DDNMF may further determine whether the target network includes the first DDNMF's network. If the target network includes the first DDNMF's network, it indicates that the first DDNMF manages the security parameters. In this case, the subsequent S103 and S104 are skipped, and the security parameters corresponding to the proximity-based service identifiers are determined locally and directly, and these security parameters are sent to the first UE in S105. Note that the first DDNMF's determination of whether the target network includes the first DDNMF's network can be done by determining whether the identifiers of one or more networks included in the target network include the identifiers of the first DDNMF's network. Thus, locally existing security parameters can be sent directly to the first UE. This further reduces signaling waste, processing resources, and latency in the security parameter acquisition process, improving the performance of the discovery process.

[0159] S103: The first DDNMF sends a second request to a second DDNMF in the target network, and the second request is used to request security parameters.

[0160] The second requirement may include an identifier for a proximity-based service, such as RSC.

[0161] Optionally, the second request may be a security parameter request message, such as a monitoring request, a discovery request, or a relay discovery key request.

[0162] It can be understood that in S103, the target network can be one or more networks. If there is one target network, the first DDNMF can send a second request to a second DDNMF within that target network. If there are more than one target networks, the first DDNMF separately sends a second request to multiple second DDNMFs within multiple target networks, where each second DDNMF corresponds to one target network, i.e., multiple second DDNMFs may each be located within different HPLMNs.

[0163] S104: The second DDNMF sends security parameters to the first DDNMF.

[0164] In response, the first DDNMF receives security parameters from the second DDNMF.

[0165] Optionally, the second DDNMF may send security parameters and security parameter identifiers to the first DDNMF.

[0166] The security parameter identifier identifies the security parameter. The security parameter identifier may be the ID of the PLMN of the second DDNMF, or it may be proprietary identification information. Furthermore, the security parameter identifier may be different from the proximity-based service identifier, or it may be the proximity-based service identifier.

[0167] Optionally, security parameters, or security parameters and their identifiers, can be carried within a security parameter announcement message, and the second DDNMF sends the security parameter announcement message to the first DDNMF. The security parameter announcement message can be a monitoring response, a discovery response, or a relay discovery key response.

[0168] It can be understood that if there is one target network, a second DDNMF within that target network sends security parameters to the first DDNMF. If there are more than one target network, multiple second DDNMFs within multiple target networks separately send security parameters and / or identifiers of security parameters to the first DDNMF. Thus, the first DDNMF may receive multiple (or multiple sets of) security parameters and / or identifiers of security parameters from multiple second DDNMFs.

[0169] Security parameter identifiers can identify specific security parameters used to protect discovery messages and / or specific security parameters that need to be used to process protected discovery messages. Therefore, based on security parameter identifiers, the receiving UE of a discovery message can accurately determine the specific security parameters that should be used to process the protected discovery message, thus avoiding the case where the receiving UE uses multiple sets of security parameters to separately perform discovery procedures through trial and error to ensure the receiving UE establishes a connection to the sending UE of the discovery message. This can reduce signaling waste, processing resources, and delays.

[0170] Let's use the procedure in Figure 4 as an example. Assume that both Relay UE-1 and Relay UE-2 support the same UE-to-Network relay service, and that RSC-a identifies the relay service. If the HPLMN of Relay UE-1 and the HPLMN of Relay UE-2 are different, when these two Relay UEs, acting as A-UEs, make a discovery key request using DDNMF, Relay UE-1 and Relay UE-2 will each perform steps 1 through 4 in Figure 4 using the DDNMF in Relay UE-1's HPLMN and the DDNMF in Relay UE-2's HPLMN, respectively, to generate the security parameters used for discovery. Since the HPLMN of Relay UE-1 and the HPLMN of Relay UE-2 are different, the DDNMFs that generate the security parameters will also be different. In this case, the DDNMF of Relay UE-1 generates security parameter-1, and the DDNMF of Relay UE-2 generates security parameter-2. In this case, both security parameter 1 and security parameter 2 are identified by RSC-a. Therefore, after completing the steps 5 through 10 in Figure 4, the remote UE may receive multiple sets of security parameters (security parameter-1 and security parameter-2) identified by using a unified RSC (RSC-a). In this case, during subsequent UE-to-network relay service discovery, the remote UE cannot distinguish a particular set of security parameters used to perform integrity verification and / or desecration on the discovery message by using only RSC-a in the discovery message. The remote UE would then have to perform the discovery procedure separately by trial and error using multiple sets of security parameters to ensure that the remote UE establishes a connection to the relay UE, resulting in wasted signaling, processing resources, and delay. However, in this embodiment provided in this application, different security parameters can be distinguished by using different identifiers for the security parameters.The remote UE can more accurately determine the specific set of security parameters used to protect the discovery message based on the security parameter identifier. For example, if the discovery message contains an identifier corresponding to security parameter-1, the remote UE can process the protected discovery message based solely on security parameter-1. Therefore, only the security parameters indicated by the identifier need to be used to process the protected discovery message. This can further reduce signaling waste, processing resources, and delays in the security parameter retrieval process, thereby improving the performance of the discovery process.

[0171] S105: The first DDNMF sends security parameters to the first UE. Correspondingly, the first UE receives the security parameters. The security parameters may be used by the first UE to perform UE discovery.

[0172] Security parameters can be used to protect or process discovery messages, or to receive or process protected discovery messages. Protecting or processing discovery messages can be done by using security parameters to perform at least one of the following on all or some discovery messages: confidentiality protection, integrity protection, or scrambling protection. Receiving or processing protected discovery messages can be done by using security parameters to perform at least one of the following on all or some protected discovery messages: confidentiality decryption, message integrity verification, or scrambling decryption.

[0173] Optionally, in S105, the first DDNMF may send security parameters and security parameter identifiers to the first UE. Correspondingly, the second UE receives the security parameters. The security parameters and security parameter identifiers may be used by the second UE to perform UE discovery.

[0174] It should be understood that, prior to step S104, the second UE obtains the security parameters and / or security parameter identifiers from the second DDNMF. See steps S101 and S105 for specific procedures.

[0175] It can be further understood that if the first DDNMF transmits security parameters and security parameter identifiers to the first UE, and the discovery message includes security parameter identifiers, the first UE may transmit an encrypted discovery message based on the security parameters. In addition, the first UE may further transmit security parameter identifiers. Optionally, security parameter identifiers and the discovery message may be carried in the same message. For example, the discovery message and security parameter identifiers may be carried in the same broadcast message, i.e., the security parameter identifiers are not included in the discovery message. Alternatively, the security parameter identifiers may be carried in the discovery message instead. In this case, the security parameters may be used to protect content within the security message other than the security parameter identifiers.

[0176] The possible implementations of Discovery Model A and Discovery Model B are described separately below.

[0177] In one embodiment, if the number of target networks is 1, i.e., if only one target network and one second DDNMF exist, then in S105, the security parameters sent to the first UE by the first DDNMF are one security parameter (or one set of security parameters) assigned by the second DDNMF. Thus, the first UE can use these security parameters to protect the first discovery message and broadcast the first discovery message, which may include an identifier for proximity-based services. Correspondingly, the second UE can obtain the same security parameters from the second DDNMF and, based on these security parameters, process and receive the first discovery message sent by the first UE to establish a connection between the first UE and the second UE. The process of processing the discovery message may include at least one of a confidentiality deprotection operation, a message integrity verification operation, and a scramble deprotection operation.

[0178] In one embodiment, if the number of target networks is greater than one, i.e., if there are multiple second DDNMFs located within multiple target networks, then in S105, the security parameters transmitted to the first UE by the first DDNMF are multiple (or multiple sets of) security parameters assigned by each of the multiple second DDNMFs. The first UE may separately protect multiple first discovery messages using these multiple security parameters and broadcast the multiple first discovery messages. Each discovery message may include an identifier for a proximity-based service. Correspondingly, the second UE may obtain sets of security parameters from the second DDNMFs within their respective HPLMNs and process and receive the first discovery messages transmitted by the first UE based on these security parameters. For example, UE-1 separately transmits a first discovery message protected with security parameter-1 and a first discovery message protected with security parameter-2, UE-2 is located at HPLMN-1 and UE-3 is located at HPLMN-2, UE-2 obtains security parameter-1 from DDNMF-1 in HPLMN-1 and UE-3 obtains security parameter-2 from DDNMF-2 in HPLMN-2. Based on security parameter-1, UE-2 can process and receive only the first discovery message protected by UE-1 using security parameter-1, and based on security parameter-2, UE-3 can process and receive only the first discovery message protected by UE-1 using security parameter-2. In this embodiment, UE-1 can establish separate communications with UE-2 and UE-3, and as a result, UE-2 and / or UE-3 can provide proximity-based services to UE-1.

[0179] In one embodiment, if the number of target networks is greater than one, i.e., if there are multiple second DDNMFs located within multiple target networks, and in S104, the multiple second DDNMFs transmit multiple security parameters and their respective identifiers to the first DDNMF, the first DDNMF may transmit the multiple security parameters and their respective identifiers to the first UE in S105. The first UE may separately protect multiple discovery messages using the multiple security parameters and broadcast those discovery messages. Those discovery messages may include a proximity-based service identifier and a security parameter identifier. Correspondingly, the second UE may obtain the identifiers of the security parameters carried in those discovery messages and process and receive the discovery messages using the security parameters corresponding to those identifiers. For example, as shown in Figure 7, in S105, UE-1 obtains security parameter-1, an identifier corresponding to security parameter-1 (referred to as key ID-1), security parameter-2, and an identifier corresponding to security parameter-2 (referred to as key ID-2). UE-1 then transmits key ID-1 and a first discovery message-1 protected using security parameter-1, as well as a first discovery message-2 protected using key ID-2. UE-2 is located within HPLMN-1, and UE-3 (not shown in Figure 7) is located within HPLMN-2. UE-2 obtains security parameter-1 and key ID-1 from DDNMF-1 within HPLMN-1, and UE-3 obtains security parameter-2 and key ID-2 from DDNMF-2 within HPLMN-2. UE-2 receives the first discovery information-1 and the corresponding key ID-1, as well as the first discovery message-2 and the corresponding key ID-2.UE-2 has obtained security parameter-1 and key ID-1, but has not obtained security parameter-2 and key ID-2. Therefore, in order to establish communication with UE-1, UE-2 only needs to process first discovery information-1 based on security parameter-1, which has the same security parameter identifier as security parameter-1, and does not need to process first discovery information-2. Similarly, UE-3 processes first discovery information-2 based on security parameter-2 in order to establish communication with UE-1. It can be understood that the first UE in the embodiment shown in Figure 5 can be used as UE-1 or UE-2 in Figure 8.

[0180] Similar to the discovery procedure in which the first UE sends a first discovery message, the first UE may also receive a second discovery message sent by the second UE and process the second discovery message based on security parameters to establish communication between the first and second UEs. The second discovery message may carry identifiers of security parameters, or the second discovery message may be sent together with the identifiers of security parameters.

[0181] Optionally, in this application, the first discovery message may be a discovery request in discovery model B. The second discovery message may be a discovery announcement message in discovery model A, or a discovery response message in discovery model B.

[0182] Based on the same inventive concept, this application further provides another communication method shown in Figure 8. The difference from the embodiment shown in Figure 5 is that in the embodiment shown in Figure 8, the first discovery key management network element may obtain the target network identifier from the first communication device instead of obtaining the target network identifier from the first network element. In Figure 8, the explanation is made using an example in which the first communication device and the second communication device are the first UE and the second UE, respectively, and the first discovery key management network element is the first DDNMF. As should be understood, unless otherwise noted, the explanation of technical terms in the embodiment shown in Figure 8 should be the same as the explanation of technical terms in the embodiment shown in Figure 5.

[0183] As shown in Figure 8, the communication method provided in this embodiment of the application may include the following steps.

[0184] S201: The first UE sends the first request to the first DDNMF, which is used to request security parameters, and the first request includes the identifier of the proximity-based service and the identifier of the target network corresponding to the proximity-based service identifier. Correspondingly, the first DDNMF receives the first request.

[0185] For a description of the first requirement and security parameters, please refer to the description of the first requirement and security parameters in S101 of this application, respectively. Details will not be explained again here. The difference is that the first requirement in S201 may additionally carry the target network identifier. For a description of the target network identifier, please refer to the description of the first requirement and security parameters in S102 of this application. For a correspondence between proximity-based service identifiers and network identifiers, please refer to the description in S101 of this application.

[0186] See the explanations in S101 and S102. The proximity-based service identifier corresponds to the target network identifier. In the embodiment shown in Figure 8, the first UE may determine a first network identifier corresponding to the proximity-based service identifier for UE discovery based on the correspondence between the proximity-based service identifier and the network identifier. The first network identifier may include the target network identifier. The correspondence may include the correspondence between some or all proximity-based service identifiers and the corresponding network identifiers, and some or all proximity-based services are not limited to the proximity-based services of the first UE.

[0187] The first UE may obtain the correspondence between proximity-based service identifiers and network identifiers from a first network element, and the correspondence may be pre-configured in the first network element. Alternatively, the first network element may obtain the correspondence from another core network element, i.e., the correspondence may instead be pre-configured in a core network element other than the first network element. See the description of the embodiment shown in Figure 5. The first network element may be a PCF or a UDM. For example, after deciding to perform this proximity-based service (or any proximity-based service), or after the first UE has connected to the Internet, the first UE sends a request to the first network element to obtain the correspondence between proximity-based service identifiers and network identifiers to obtain all the correspondences between proximity-based service identifiers and network identifiers, and then determines the target network identifier based on the identifiers and correspondences of the target proximity-based service to be performed.

[0188] As shown in Figure 9, for example, the first network element is a PCF. If the correspondence between RSC and PLMN ID is pre-configured in the PCF, the PCF may, after receiving a request from the first UE to retrieve the correspondence, send the correspondence between RSC and PLMN ID to the first UE. The request to retrieve the correspondence may be a ProSe parameter retrieval request. Optionally, the correspondence and ProSe parameters may be carried in the same message for transmission. In another example, if the correspondence between RSC and PLMN ID is pre-configured in the UDM, the PCF may, after receiving a request from the first UE to retrieve the correspondence, retrieve the correspondence from the UDM and then send the correspondence to the first UE. The PCF may send a UE subscription data retrieval request to the UDM to request the correspondence. The first UE may store the received correspondence.

[0189] The request to obtain the correspondence of the first UE may be a request from the first UE directly or indirectly, or it may be a request to obtain the correspondence used by a core network element, such as an AMF, to request information related to the first UE.

[0190] In addition, in the embodiment shown in Figure 8, after deciding to perform a proximity-based service, the first UE may also send a request to the first network element to obtain the identifier of the target network, which may carry the identifier of the proximity-based service. Correspondingly, after receiving the request, the first network element may determine the identifier of the target network corresponding to the proximity-based service identifier based on the correspondence between the proximity-based service identifier and the network identifier, and may include the identifier of the target network in the response message sent to the first UE. Optionally, if the first UE determines that it does not remember the correspondence and / or the identifier of the target network, the first UE requests the first network element for the correspondence between the proximity-based service identifier and the network identifier and / or the identifier of the target network.

[0191] Optionally, before the first network element provides the first UE with the correspondence between the proximity-based service identifier and the network identifier and / or the target network identifier, the first network element may decide that the proximity-based service security parameters are managed by the DDNMF, or the first network element may decide that the proximity-based service security parameters are not managed by the first network element. If the proximity-based service security parameters are managed by the first network element, the second DDNMF does not need to provide the security parameters, and the first network element may refuse to send the target network identifier to the first DDNMF.

[0192] Optionally, before requesting the first network element for the correspondence between the proximity-based service identifier and the network identifier and / or the target network identifier, the first UE may further determine that the first UE does not remember the correspondence and / or the target network identifier, in other words, that the first DDNMF has not previously obtained the correspondence and / or the target network identifier from the first network element.

[0193] In addition, the correspondence between proximity-based service identifiers and network identifiers may instead be pre-configured in the first UE. In this case, the first UE can obtain the target network identifier locally.

[0194] It can be understood that in S201, the target network identifier and the proximity-based service identifier may be carried in the same information element or in different information elements. This is not particularly limited.

[0195] Optionally, the first request may further include a second network identifier, such as the ID or list of PLMNs that enable proximity-based services for the first UE. For details regarding the ID or list of PLMNs that enable proximity-based services for the first UE, see the description in step S101. In this case, the first request sent by the first UE in S101 can be considered to include at least one first network identifier, the at least one first network identifier including the identifier of the target network. See the description in S102. The first DDNMF may determine the identifier of the target network based on the first network identifier and the second network identifier.

[0196] Alternatively, optionally, the identifier of the target network in S201 may be determined based on the first network identifier and the second network identifier. Specifically, for how the first UE determines the identifier of the target network based on the first network identifier and the second network identifier, refer to the same method by which the first DDNMF determines the identifier of the target network based on the first network identifier and the second network identifier in step S102. We will not go into detail again. In other words, after determining the identifier of the target network based on the first network identifier and the second network identifier, the first UE can avoid the case where excessive network identifiers are carried within the first request by including the identifier of the target network in the first request. This can reduce signaling overhead. Furthermore, this can avoid the acquisition of security parameters assigned by DDNMF in the network, which would not allow the first UE to use proximity-based services. The first UE can obtain from the first network element a proximity-based service identifier and at least one first network identifier corresponding to the proximity-based service identifier, that is, it can obtain a correspondence between the proximity-based service identifier and at least one first network identifier. The at least one first network identifier may include a target network identifier.

[0197] Alternatively, the first UE may send at least one first network identifier and at least one second network identifier to the first DDNMF. The first DDNMF then determines the identifier of the target network based on the at least one first network identifier and the at least one second network identifier. For example, the first UE may include in the first request a proximity-based service identifier, at least one first network identifier corresponding to the proximity-based service identifier, and at least one second network identifier.

[0198] Optionally, the first UE may obtain the ProSe parameters before S101. For details on how the first UE obtains the ProSe parameters, please refer to the explanation in S101.

[0199] In one optional implementation, the first UE may obtain ProSe parameters from the first network element and obtain a correspondence between a proximity-based service identifier and at least one first network identifier. For example, the ProSe parameters and the correspondence may be carried in the same message or in different messages.

[0200] S202: The first DDNMF sends a second request to a second DDNMF in the target network, and the second request is used to request security parameters.

[0201] Optionally, if the first request in S201 includes at least one first network identifier, and the first UE further sends a second network identifier to the first DDNMF, the first DDNMF may determine the identifier of the target network based on the first and second network identifiers. See the explanation in S102 for further details.

[0202] Optionally, prior to S202, after determining the target network, the first DDNMF may further determine whether the target network includes the first DDNMF's network. If the target network includes the first DDNMF's network, it indicates that the first DDNMF is managing the security parameters. In this case, S202 and S203 are skipped, and the security parameters corresponding to the proximity-based service identifier are determined locally and sent to the first UE in S204.

[0203] S203: The second DDNMF sends security parameters to the first DDNMF.

[0204] In response, the first DDNMF receives security parameters from the second DDNMF.

[0205] Optionally, the second DDNMF sends security parameters and security parameter identifiers to the first DDNMF. In response, the first DDNMF receives security parameters and security parameter identifiers from the second DDNMF.

[0206] S204: The first DDNMF sends security parameters to the first UE. The first UE receives the security parameters in response.

[0207] Optionally, the first DDNMF sends the security parameters and the identifiers of the security parameters to the first UE.

[0208] For the implementation of S202 to S204, please refer to S103 to S105. Repeated sections will not be explained again.

[0209] Furthermore, in the embodiment shown in Figure 8, after obtaining the security parameters, the first UE may perform UE discovery by referring to the description in the embodiment shown in Figure 5. For example, after obtaining the security parameters and the identifiers of the security parameters, the first UE performs UE discovery by referring to the procedure shown in Figure 7. The first UE can be used as UE-1 or UE-2 in Figure 7.

[0210] It can be understood that, in order to implement the functions in the embodiments described above, the first DDNMF, the first network element, and the first UE may each include a corresponding hardware configuration and / or software module for performing the functions described above. It should be readily apparent to those skilled in the art that, in this application, the units and method steps in the examples described with reference to the embodiments disclosed herein can be implemented by hardware or by a combination of hardware and computer software. Whether the functions are performed by hardware or by hardware driven by computer software depends on the specific application scenario and design constraints of the technical solution.

[0211] Figures 10 and 11, respectively, illustrate the configuration of a possible communication device according to one embodiment of this application. These communication devices can be configured to implement the functions of the first discovery key management network element, the first network element, or the first communication device in the method embodiment described above, and thus can also realize the beneficial effects of the method embodiment described above. The first discovery key management network element can be a first DDNMF or a first PKMF, the first network element can be a PCF or a UDM, and the communication device can be a first UE. In this embodiment of this application, the first UE can be the UE shown in Figure 1.

[0212] As shown in Figure 10, the communication device 1000 includes a processing unit 1010 and a transceiver unit 1020. The communication device 1000 is configured to implement the functions of the first discovery key management network element, the first network element, or the first communication device in the method embodiment shown in any one of Figures 5 to 9.

[0213] If the communication device 1000 is configured to implement the functions of the first discovery key management network element in the method embodiment shown in Figure 5, the transceiver unit 1020 may be configured to receive a first request, obtain the identifier of the target network from the first network element, send a second request to the second discovery key management network element, receive security parameters from the second discovery key management network element, and send the security parameters to the first communication device, and the processing unit 1010 may be configured to determine the identifier of the target network.

[0214] When the communication device 1000 is configured to implement the functions of the first network element in the method embodiment shown in Figure 5, the transceiver unit 1020 is configured to provide the target network identifier to the first network element, and the processing unit 1010 is configured to determine the target network identifier.

[0215] When the communication device 1000 is configured to implement the functions of the first communication device in the method embodiment shown in Figure 5, the transceiver unit 1020 is configured to send a first request to a first discovery key management network element and to receive security parameters from the first discovery key management network element.

[0216] If the communication device 1000 is configured to implement the functions of the first discovery key management network element in the method embodiment shown in Figure 8, the transceiver unit 1020 may be configured to receive a first request, transmit a second request to a second discovery key management network element, receive security parameters from the second discovery key management network element, and transmit the security parameters to the first communication device, and the processing unit 1010 may be configured to obtain the identifier of the target network from the first request.

[0217] If the communication device 1000 is configured to implement the functions of the first UE in the method embodiment shown in Figure 8, the transceiver unit 1020 may be configured to send a first request to a first discovery key management network element and to receive security parameters from the first discovery key management network element, and the processing unit 1010 may be configured to add the identifier of the target network to the first request.

[0218] For a further detailed description of the processing unit 1010 and the transceiver unit 1020, please refer to the relevant description in the method embodiment shown in any one of Figures 5 to 9. For example, for technical terms in the aforementioned actions of the processing unit 1010 and the transceiver unit 1020, please refer to the description in the aforementioned method embodiment. Further details will not be provided again.

[0219] As shown in Figure 11, the communication device 1100 includes a processor 1110 and an interface circuit 1120. The processor 1110 and the interface circuit 1120 are coupled to each other. It can be understood that the interface circuit 1120 may be a transceiver or an input / output interface. Optionally, the communication device 1100 may further include a memory 1130 configured to store instructions executed by the processor 1110, input data required by the processor 1110 to execute the instructions, or data generated after the processor 1110 has executed the instructions.

[0220] When the communication device 1100 is configured to perform the method shown in any one of Figures 5 to 9, the processor 1110 is configured to perform the functions of the processing unit 1010, and the interface circuit 1120 is configured to perform the functions of the transceiver unit 1020.

[0221] If the communication device is a chip used in the first discovery key management network element, the first network element, or the first communication device, the chip implements the functions of the first discovery key management network element, the first network element, or the first communication device in the method embodiment described above. The terminal chip receives information transmitted to the first discovery key management network element, the first network element, or the first communication device by another network element or device via another module (e.g., a radio frequency module, an antenna, or a communication interface) in the first discovery key management network element, the first network element, or the first communication device. Alternatively, the chip transmits information to another module (e.g., a radio frequency module, an antenna, or an interface) in the first discovery key management network element, the first network element, or the first communication device, and the information is transmitted to another network element or device by the first discovery key management network element, the first network element, or the first communication device.

[0222] It should be understood that the processor in the embodiments of this application may be a central processing unit (CPU), another general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), another programmable logic device, a transistor logic device, a hardware component, or any combination thereof. The general-purpose processor may be a microprocessor or any ordinary processor.

[0223] The method steps in embodiments of this application may be implemented in hardware or by software instructions that can be executed by a processor. The software instructions may include corresponding software modules. The software modules may be stored in random access memory, flash memory, read-only memory, programmable read-only memory, erasable programmable read-only memory, electrically erasable programmable read-only memory, registers, hard disk drives, removable hard disks, read-only memory (compact disc read-only memory, CD-ROM), or any other form of storage medium well known in the art. For example, the storage medium is coupled to the processor so that the processor can read information from and write information to the storage medium. The storage medium may instead be a component of the processor. The processor and storage medium may be located within an ASIC. In addition, the ASIC may be located within a first discovery key management network element, a first network element, or a first communication device. The processor and storage medium may instead exist as discrete components within the first discovery key management network element, the first network element, or the first communication device.

[0224] One embodiment of this application further provides a communication system comprising one or more network elements or devices of a first discovery key management network element, a first network element, or a first communication device configured to implement the method embodiment described above.

[0225] One embodiment of this application further provides a computer-readable storage medium configured to store a computer program or instruction. When the computer program or instruction is executed, the method of the above-described embodiment is carried out.

[0226] One embodiment of this application further provides a computer program product. When the computer program product runs on a computer, the method in the method embodiment is carried out.

[0227] All or part of the embodiments described above may be implemented by software, hardware, firmware, or any combination thereof. When software is used to implement an embodiment, all or part of the embodiment may be implemented in the form of a computer program product. A computer program product includes one or more computer programs or instructions. When a computer program or instruction is loaded onto a computer and executed, all or part of the procedures or functions in the embodiments of this application are performed. The computer may be a general-purpose computer, a dedicated computer, a computer network, a network device, user equipment, or other programmable device. The computer program or instruction may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, a computer program or instruction may be transmitted by wire or wirelessly from one website, computer, server, or data center to another website, computer, server, or data center. The computer-readable storage medium may be any available medium that can be accessed by a computer, or a data storage device such as a server or data center that integrates one or more available media. The usable media may be magnetic media such as floppy disks (registered trademark), hard disks, or magnetic tapes; optical media such as digital video discs; or semiconductor media such as solid-state drives. Computer-readable storage media may be volatile or non-volatile, or may include both volatile and non-volatile storage media.

[0228] In the description of this application, terms such as “first” and “second” are used merely for the purpose of distinguishing descriptions and should not be understood as indicating or implying relative importance, or as indicating or implying order. Furthermore, the order of “first,” “second,” etc., is not limited in this application. For example, “second” may appear first, followed by “first.” This is not limited in this application.

[0229] In this description of the application, “at least one (type)” means one (type) or more (types), and “more (types)” means two (types) or more (types). Also, “at least one of the following items” or similar expressions means any combination of those items, including one item or any combination of more items. For example, at least one of a, b, or c could be a, b, c, a and b, a and c, b and c, or a, b and c, where a, b, and c may be singular or plural. In this description of the application, “ / ” means “or”. For example, a / b means a or b.

[0230] In the embodiments of this application, unless otherwise stated or unless there is a logical conflict, the terms and / or descriptions in different embodiments may be consistent with and mutually referential, and the technical features in different embodiments may be combined based on their internal logical relationships to form new embodiments.

[0231] It should be understood that the various numbers in the embodiments of this application are used solely for the purpose of distinction to facilitate explanation and are not intended to limit the scope of the embodiments of this application. The sequence numbers of the processes described above do not imply an execution order, and the execution order of the processes should be determined based on the function and internal logic of the processes.

Claims

1. A method of communication, A first discovery key management network element receives a first request from a first communication device, the first request being used to request security parameters, and the first request having an identifier for proximity-based services provided by a second communication device for the first communication device. The first discovery key management network element obtains the identifier of the target network corresponding to the identifier of the proximity-based service, and the target network is the home network of the second communication device. The first discovery key management network element transmits a second request to a second discovery key management network element in the target network, and the second request is used to request the security parameters. The first discovery key management network element receives the security parameters from the second discovery key management network element. The first discovery key management network element transmits the security parameters to the first communication device. A method having the following characteristics.

2. The first discovery key management network element obtains the identifier of the target network corresponding to the identifier of the proximity-based service, The first discovery key management network element obtains the identifier of the target network corresponding to the identifier of the proximity-based service from the first network element, and the target network is the home network of the second communication device. The method according to claim 1, wherein the method is as follows:

3. This method further, The first discovery key management network element transmits a network identifier retrieval request to the first network element, the network identifier retrieval request is used to retrieve the identifier of the target network, and the network identifier retrieval request has the identifier of the proximity-based service. The method according to claim 2, wherein the method is as follows:

4. The first discovery key management network element obtains the identifier of the target network from the first network element, The first discovery key management network element obtains at least one first network identifier from the first network element, wherein the at least one first network identifier includes the identifier of the target network, and the at least one first network identifier corresponds to the identifier of the proximity-based service. Having, This method further, The first discovery key management network element receives at least one second network identifier from the first communication device, the second network identifier identifies a network that enables the proximity-based service for the first communication device. The first discovery key management network element determines the target network based on the at least one second network identifier and the at least one first network identifier. The method according to claim 2 or 3, wherein the above is achieved.

5. This method further, The first discovery key management network element stores the correspondence between the identifier of the proximity-based service and the identifier of the target network. The method according to any one of claims 1 to 4, wherein the method is as follows:

6. The first discovery key management network element receives the security parameters from the second discovery key management network element. The first discovery key management network element receives a security parameter announcement message from the second discovery key management network element, and the security parameter announcement message includes the security parameter and an identifier for the security parameter. Having, The first discovery key management network element transmits the security parameters to the first communication device. The first discovery key management network element transmits a security parameter response message to the first communication device, and the security parameter response message has the security parameter and the identifier of the security parameter. The method according to any one of claims 1 to 5, wherein the method is characterized by the fact that

7. The method according to claim 6, wherein the identifier of the security parameter is the identifier of the target network.

8. The method according to any one of claims 1 to 7, wherein the first discovery key management network element is a first discovery name management function network element or a first proximity-based service key management function network element, and the second discovery key management network element is a second discovery name management function network element or a second proximity-based service key management function network element.

9. The method according to any one of claims 2 to 4, wherein the first network element is a policy control function network element or a unified data management network element.

10. This method further, The first communication device obtains the security parameter and the identifier of the security parameter from the first discovery key management network element. The method according to any one of claims 1 to 9, wherein the method is as follows:

11. This method further, The first communication device transmits a first discovery message, the first discovery message is used to find the second communication device, the first discovery message is protected by using the security parameter, and the first discovery message has the identifier of the security parameter. The method according to any one of claims 1 to 10, wherein the method is as follows:

12. This method further, The first communication device receives a second discovery message, the second discovery message having the identifier of the security parameter, and the second discovery message is used to find the first communication device. The first communication device determines the security parameter based on the identifier of the security parameter, The first communication device processes the second discovery message based on the security parameters. The method according to any one of claims 1 to 10, wherein the method is as follows:

13. A method of communication, The first network element determines the identifier of the target network corresponding to the identifier of the proximity-based service, and the proximity-based service is provided by the second communication device for the first communication device. The first network element transmits the identifier of the target network to the first discovery key management network element, and the target network is the home network of the second communication device. A method having the following characteristics.

14. This method further, The first network element receives a network identifier retrieval request from the first discovery key management network element, the network identifier retrieval request is used to retrieve the identifier of the target network, and the network identifier retrieval request has the identifier of the proximity-based service, The method according to claim 13, wherein the above is achieved.

15. The first network element determines the identifier of the target network corresponding to the identifier of the proximity-based service, The first network element determines at least one first network identifier corresponding to the identifier of the proximity-based service, wherein the at least one first network identifier includes the identifier of the target network. Having, The first network element transmits the identifier of the target network to the first discovery key management network element. The first network element transmits the at least one first network identifier to the first discovery key management network element. The method according to claim 13 or 14, wherein the method is as follows:

16. This method further, The first network element determines that it does not assign security parameters to the proximity-based service, or The first network element determines that the first discovery key management network element assigns security parameters to the proximity-based service. The method according to any one of claims 13 to 15, wherein the method is as follows:

17. This method further, The first network element stores the correspondence between the first discovery key management network element and the identifier of the proximity-based service. The method according to any one of claims 13 to 16, wherein the method is as follows:

18. The method according to any one of claims 13 to 17, wherein the first network element is a policy control function network element or a unified data management network element.

19. The method according to any one of claims 13 to 18, wherein the first discovery key management network element is a discovery name management function network element or a proximity-based service key management function network element.

20. A method of communication, A first discovery key management network element receives a first request from a first communication device, the first request being used to request security parameters, the security parameters being used to discover the communication device, the first request having a proximity-based service identifier and a target network identifier corresponding to the proximity-based service identifier, the target network being the home network of the second communication device, and the proximity-based service being a service provided by the second communication device for the first communication device. The first discovery key management network element transmits a second request to a second discovery key management network element in the target network, and the second request is used to request the security parameters. The first discovery key management network element receives the security parameters from the second discovery key management network element. The first discovery key management network element transmits the security parameters to the first communication device. A method having the following characteristics.

21. The first requirement comprises the identifier of the proximity-based service and at least one first network identifier corresponding to the identifier of the proximity-based service, wherein the at least one first network identifier includes the identifier of the target network. Before sending the second request to the second discovery key management network element in the target network, the method further: The first discovery key management network element receives at least one second network identifier from the first communication device, the second network identifier identifies a network that enables the proximity-based service for the first communication device. The first discovery key management network element determines the target network based on the at least one second network identifier and the at least one first network identifier. The method according to claim 20, wherein the above is achieved.

22. The first discovery key management network element receives the security parameters from the second discovery key management network element. The first discovery key management network element receives the security parameter and the identifier of the security parameter from the second discovery key management network element. Having, The first discovery key management network element transmits the security parameters to the first communication device. The first discovery key management network element transmits a security parameter response message to the first communication device, and the security parameter response message has the security parameter and the identifier of the security parameter. The method according to claim 20 or 21, wherein the method is as follows:

23. The method according to claim 22, wherein the identifier of the security parameter is the identifier of the target network.

24. The method according to any one of claims 20 to 23, wherein the first discovery key management network element is a first discovery name management function network element or a first proximity-based service key management function network element, and the second discovery key management network element is a second discovery name management function network element or a second proximity-based service key management function network element.

25. A method of communication, A first communication device transmits a first request to a first discovery key management network element, the first request being used to request security parameters, the first request having a proximity-based service identifier and a target network identifier corresponding to the identifier of the proximity-based service, the proximity-based service being a proximity-based service provided by a second communication device for the first communication device, and the target network being the home network of the second communication device. The first communication device receives the security parameters from the first discovery key management network element. A method having the following characteristics.

26. This method further, The first communication device obtains the identifier of the proximity-based service and the identifier of the target network from the first network element. The method according to claim 25, wherein the method is as follows:

27. The first communication device obtains the identifier of the proximity-based service and the identifier of the target network from the first network element, The first communication device obtains the identifier of the proximity-based service and at least one first network identifier corresponding to the identifier of the proximity-based service from the first network element, wherein the at least one first network identifier includes the identifier of the target network. The method according to claim 26, wherein the above is achieved.

28. The first communication device determines the target network based on at least one second network identifier and the at least one first network identifier, wherein the second network identifier identifies a network that enables the first communication device to provide the proximity-based service, or In accordance with the first requirement, the proximity-based service has an identifier, at least one first network identifier corresponding to the identifier of the proximity-based service, and at least one second network identifier, the second network identifier identifying a network that enables the proximity-based service to be provided for the first communication device. The method according to claim 27, further comprising the above.

29. The method according to claim 27 or 28, wherein the first network element is a policy control function network element or a unified data management network element.

30. The first communication device receives the security parameters from the first discovery key management network element, The first communication device receives the security parameter and the identifier of the security parameter from the first discovery key management network element. The method according to any one of claims 25 to 29, wherein the method is as follows:

31. This method further, The first communication device transmits a first discovery message, the first discovery message is used to find the second communication device, the first discovery message is protected by using the security parameter, and the first discovery message has the identifier of the security parameter. The method according to claim 30, wherein the above is achieved.

32. This method further, The first communication device receives a second discovery message, the second discovery message having the identifier of the security parameter, and the second discovery message is used to find the first communication device. The first communication device determines the security parameter based on the identifier of the security parameter, The first communication device processes the second discovery message based on the security parameters. The method according to claim 30, wherein the above is achieved.

33. The method according to claim 32, wherein the identifier of the security parameter is the identifier of the target network.

34. The method according to any one of claims 25 to 33, wherein the first discovery key management network element is a discovery name management function network element or a proximity-based service key management function network element.

35. A method of communication, A first communication device transmits a first request to a first discovery key management network element, the first request is used to request security parameters for a proximity-based service, the proximity-based service being a proximity-based service provided by a second communication device for the first communication device, and the first request having an identifier for the proximity-based service. The first communication device obtains the security parameter and the identifier of the security parameter. A method having the following characteristics.

36. The first communication device can obtain the security parameter and the identifier of the security parameter, The first communication device receives the security parameter and the identifier of the security parameter from the first discovery key management network element. The method according to claim 35, wherein the above is achieved.

37. This method further, The first communication device transmits a first discovery message, the first discovery message is used to find the second communication device, and the first discovery message is protected by using the security parameters. The method according to claim 35 or 36, wherein the method is as follows:

38. The method according to claim 37, wherein the first discovery message has the identifier of the security parameter.

39. This method further, The first communication device receives a second discovery message, the second discovery message having the identifier of the security parameter, and the second discovery message is used to find the first communication device. The first communication device determines the security parameter based on the identifier of the security parameter, The first communication device processes the second discovery message based on the security parameters. The method according to any one of claims 36 to 38, wherein the method is as follows:

40. The method according to claim 38, wherein the identifier of the security parameter is the identifier of the target network.

41. A method of communication, A first discovery key management network element receives a first request from a first communication device, the first request being used to request security parameters, and the first request having an identifier for proximity-based services provided by a second communication device for the first communication device. The first discovery key management network element obtains the identifier of the target network corresponding to the identifier of the proximity-based service, and the target network is the home network of the second communication device. The first discovery key management network element transmits a second request to a second discovery key management network element in the target network, and the second request is used to request the security parameters. The second discovery key management network element receives the second request from the first discovery key management network element. The second discovery key management network element transmits the security parameters to the first discovery key management network element based on the second request. The first discovery key management network element receives the security parameters from the second discovery key management network element. The first discovery key management network element transmits the security parameters to the first communication device. A method having the following characteristics.

42. The method according to claim 41, further comprising the method according to any one of claims 2 to 12.

43. The method further comprises the method according to any one of claims 13 to 19, wherein the method is according to claim 41 or 42.

44. The method further comprises the method according to any one of claims 41 to 43, wherein the method comprises the method according to any one of claims 25 to 40.

45. A method of communication, A first discovery key management network element receives a first request from a first communication device, the first request being used to request security parameters, the security parameters being used to discover the communication device, the first request having a proximity-based service identifier and a target network identifier corresponding to the proximity-based service identifier, the target network being the home network of the second communication device, and the proximity-based service being a service provided by the second communication device for the first communication device. The first discovery key management network element transmits a second request to a second discovery key management network element in the target network, and the second request is used to request the security parameters. The second discovery key management network element receives the second request from the first discovery key management network element. The second discovery key management network element transmits the security parameters to the first discovery key management network element based on the second request. The first discovery key management network element receives the security parameters from the second discovery key management network element. The first discovery key management network element transmits the security parameters to the first communication device. A method having the following characteristics.

46. The method according to claim 45, further comprising the method according to any one of claims 21 to 24.

47. The method further comprises the method according to any one of claims 25 to 40, wherein the method is according to claim 45 or 46.

48. A communication device having a processor, wherein the processor is configured to execute a computer program or instructions to carry out the method described in any one of claims 1 to 40.

49. The apparatus according to claim 48, further comprising a memory and / or a transceiver, wherein the memory is configured to store the computer program or the instructions, and the transceiver is used by the apparatus for communication.

50. A computer-readable storage medium storing a computer program or instruction, wherein when the computer program or instruction is executed by a communication device, the method described in any one of claims 1 to 40 is performed.

51. A computer program product having a computer program or instruction, wherein when the computer program or instruction is executed by a computer, the computer is made to carry out the method described in any one of claims 1 to 40.

52. A communication system having a first discovery key management network element and a second discovery key management network element, wherein the first discovery key management network element is configured to perform the method described in any one of claims 1 to 12 and 20 to 24. The second discovery key management network element is configured to receive a second request from the first discovery key management network element and to transmit the security parameters to the first discovery key management network element based on the second request. Communication system.

53. The communication system according to claim 52, further comprising a first network element, wherein the first network element is configured to perform the method described in any one of claims 13 to 19.

54. The communication system according to claim 52 or 53, further comprising a first communication device, the first communication device being configured to perform the method described in any one of claims 25 to 40.