Security Policy Processing Method and Communication Device
Patent Information
- Application Number
- JP2023541502
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-01-08
- Publication Date
- 2025-06-02
- Estimated Expiration
- 2041-01-08
Abstract
Description
[Technical field]
[0001] TECHNICAL FIELD Embodiments of the present application relate to the field of communications, and in particular to a security policy processing method and a communications device. [Background technology]
[0002] The on-demand user plane security protection mechanism is a security mechanism in a 5th generation mobile communication technology (5G) network, and the on-demand user plane security protection includes user plane encryption protection and user plane integrity protection. The on-demand user plane security protection mechanism requires an access network device to determine whether to enable user plane encryption protection and / or integrity protection for a terminal device according to a user plane security policy received from a core network device.
[0003] Currently, the on-demand user plane security protection mechanism needs to be applied to the 4th generation mobile communication technology (4G) network. The 4G network includes non-upgraded access network devices and non-upgraded terminal devices, and the non-upgraded access network devices and non-upgraded terminal devices do not support on-demand user plane security protection. Therefore, when receiving an information element about on-demand user plane security protection (e.g., a user plane security policy), the non-upgraded access network devices and non-upgraded terminal devices cannot identify the information element about on-demand user plane security protection, and therefore may discard the information element or fail to process it.
[0004] How to realize an on-demand user plane security protection mechanism in a 4G network including both upgraded and non-upgraded access network devices / terminal devices is an issue that needs to be urgently addressed in current standards. Summary of the Invention
[0005] An embodiment of this application provides a security policy processing method and a communication device for reducing the probability that a mobility management entity sends information elements not required by an access network device to an access network device, reducing transmission complexity, and improving data transmission efficiency.
[0006] According to a first aspect, an embodiment of the present application provides a security policy processing method. For example, the security policy processing method may be applied to processes such as handover, radio resource control connection resume (RRC connection resume), RRC connection reestablishment, etc. In the method, a target access network device receives a message 001 from a source access network device, where the message 001 includes indication information 011. Then, when the indication information 011 indicates that the terminal device supports on-demand user plane security protection between the terminal device and the access network device, the target access network device sends a path switch request 031 carrying a user plane security policy 021 to a mobility management entity, where the user plane security policy 021 indicates whether to enable user plane encryption protection and / or whether to enable user plane integrity protection.
[0007] In a possible implementation manner, the source access network device may be the access network device serving the terminal device during the initial access of the terminal device, or the source access network device may be the access network device serving the terminal device before the handover, RRC connection resumption or RRC connection re-establishment process is performed. The target access network device is the access network device serving the terminal device after the handover, RRC connection resumption or RRC connection re-establishment process is performed. Usually, the context of the terminal device is transferred between the source access network device and the target access network device.
[0008] In this application, the target access network device can determine whether the terminal device supports on-demand user plane security protection based on the indication information 011, and the target access network device sends the user plane security policy 021 to the mobility management entity only when the terminal device supports on-demand user plane security protection. This avoids the following case: When the terminal device does not support on-demand user plane security protection and the mobility management entity does not receive the user plane security policy from the target access network device, the mobility management entity sends the user plane security policy to the target access network device, so that even if the target access network device receives the user plane security policy, the target access network device cannot enable on-demand user plane security protection for the terminal device. Therefore, this helps to reduce the probability that the mobility management entity sends information elements that are not required by the target access network device to the target access network device, and thus helps to reduce the complexity of transmission.
[0009] In an optional implementation manner, the target access network device and the source access network device are evolved Node B eNBs. For example, the target access network device is a target eNB, and the source access network device is a source eNB.
[0010] In an optional implementation manner, when the target access network device does not receive a user plane security policy from the source access network device, the user plane security policy 021 is the user plane security policy 021-1 established by the target access network device.
[0011] In an optional implementation manner, the method further includes: the target access network device determines that the user plane security activation state between the target access network device and the terminal device is that user plane encryption protection is enabled and user plane integrity protection is not enabled, and the target access network device establishes a user plane security policy 021-1 that is consistent with the user plane security activation state.
[0012] The target access network device does not receive an on-demand user plane security protection policy from the source access network device, but the indication information 011 indicates that the terminal device supports on-demand user plane security protection. This indicates that the source access network device does not support on-demand user plane security protection. In this case, the target access network device may determine whether to enable user plane encryption protection and / or user plane integrity protection in a default manner (which may be understood as a non-upgraded manner). For example, the default manner (or the non-upgraded manner) may indicate to enable user plane encryption protection and skip enabling user plane integrity protection for the terminal device. Therefore, if the user plane security policy 021-1 established by the target access network device can match the user plane security activation state of the terminal device, when the target access network device receives a user plane security policy that is consistent with the user plane security policy 021-1, the target access network device may not need to reactivate the terminal device.
[0013] In an optional implementation manner, the user plane security policy 021-1 includes a user plane encryption protection policy and a user plane integrity protection policy, where the user plane encryption protection policy indicates that activation is required or that activation is preferred, and the user plane integrity protection policy indicates that activation is not required or that activation is preferred.
[0014] In this realization method, a possible realization method of the user plane security policy 021-1 is provided. For example, when the user plane security policy is expressed in the form of {user plane encryption protection policy, user plane integrity protection policy}, the user plane security policy 021-1 may be specifically realized in any one of the following ways, i.e., {enabling is required, enabling is not required}, {enabling is required, enabling is preferred}, {enabling is preferred, enabling is not required}, or {enabling is preferred, enabling is preferred}.
[0015] In an optional implementation manner, when the target access network device does not receive a user plane security policy from the source access network device, the user plane security policy 021 may be a user plane security policy 021-2 pre-configured in the target access network device.
[0016] In this implementation manner, when the indication information 011 indicates that the terminal device supports on-demand user plane security protection, but the target access network device does not receive a user plane security policy from the source access network device, the target access network device may determine a user plane security policy corresponding to the terminal device according to a locally pre-configured user plane security policy.
[0017] In an optional implementation, the message 001 further includes identifiers of N evolved radio access bearers (E-UTRAN radio access bearers, E-RABs) of the terminal device, where N is an integer greater than or equal to 1, and the path switch request 031 further includes identifiers of the N E-RABs.
[0018] In this realization, the user plane security policy 021 may be a security policy at bearer granularity, for example, a security policy at E-RAB granularity. Specifically, the identifier of the E-RAB and the user plane security policy 021 corresponding to the E-RAB may be carried in a path switch request and sent to the mobility management entity. Correspondingly, when the mobility management entity receives the user plane security policy 021 and the identifier of the E-RAB, the mobility management entity may determine that the user plane security policy 021 is a security policy at E-RAB granularity and that the user plane security policy 021 is a user plane security policy corresponding to the identifier of the E-RAB. In this realization, the access network device may determine whether to enable user plane encryption protection and / or integrity protection for each E-RAB corresponding to the terminal device. This facilitates fine-grained management of the user plane security policy.
[0019] In an optional implementation, the path switch request 031 includes N user plane security policies 021-2, and each of the identifiers of the N evolved radio access bearers corresponds to one of the N user plane security policies 021-2. In this implementation, when the target access network device receives the identifiers of the N E-RABs from the source access network device, the target access network device adds N correspondences to the path switch request 031 sent to the mobility management entity, and each correspondence includes one E-RAB identifier and one user plane security policy 021-2. In this case, the mobility management device in the live network can know the user plane security policy corresponding to each E-RAB identifier without changing the mobility management entity.
[0020] In an optional implementation manner, after the target access network device sends a path switch request 031 carrying the user plane security policy 021 to the mobility management entity, the method further includes: the target access network device receives a path switch response 041 from the mobility management entity, where the path switch response 041 carries the user plane security policy 022, and the target access network device stores the user plane security policy 022 in the context of the terminal device.
[0021] In this realization manner, if the target access network device sends the user plane security policy 021 to the mobility management entity but receives the user plane security policy 022, it indicates that the user plane security policy 022 on the mobility management entity does not match the mobility management entity 021 stored on the target access network device. Therefore, the target access network device needs to update the user plane security policy 021 stored in the context of the terminal device by using the user plane security policy 022.
[0022] In an optional implementation manner, the method further includes: if the current user plane security activation state of the terminal device does not match the user plane security policy 022, the target access network device re-enables or skips enabling the user plane encryption protection and / or the user plane integrity protection for the terminal device according to the user plane security policy 022, and the current user plane security activation state is a state of whether the user plane encryption protection and / or the user plane integrity protection is currently enabled between the target access network device and the terminal device. For example, the user plane encryption protection is currently enabled between the target access network device and the terminal device, but the integrity protection is not enabled, and the user plane security policy 022 indicates that the user plane encryption protection is required to be enabled, and the user plane integrity protection is also required to be enabled. In this case, the target access network device needs to enable the user plane encryption protection and the user plane integrity protection between the target access network device and the terminal device according to the requirements of the user plane security policy 022.
[0023] In an optional implementation manner, the method further includes: when the indication information 011 indicates that the terminal device does not support on-demand user plane security protection between the terminal device and the access network device, the target access network device sends a path switch request 032 that does not carry a user plane security policy to a mobility management entity, and the target access network device receives a path switch response 042 that does not carry a user plane security policy from the mobility management entity.
[0024] In the prior art, after a mobility management entity receives a path switch request that does not carry a user plane security policy, the mobility management entity sends the user plane security policy to a target access network device to enable user plane integrity protection between the access network device and the terminal device in a 4G network, in which case the target access network device and the terminal device may not be able to use the user plane security policy.
[0025] However, in this realization manner, when the indication information 011 indicates that the terminal device supports on-demand user plane security protection, the target access network device sends the constructed user plane security policy 021-1 or the preconfigured user plane security policy 021-2 to the mobility management entity. Therefore, if the indication information 011 indicates that the terminal device does not support on-demand user plane security protection, the target access network device does not send the user plane security policy to the mobility management entity, and correspondingly, the mobility management entity knows that it cannot receive the user plane security policy from the target access network device. In this case, the mobility management entity may infer that the terminal device does not support on-demand user plane security protection, and even if the user plane security policy is provided to the target access network device, the target access network device cannot enable user plane integrity protection for the terminal device by using the user plane security policy. Therefore, in this realization manner, when the mobility management entity receives a path switch request that does not carry a user plane security policy, it is configured to send a path switch response that does not carry a user plane security policy to the target access network device, i.e., not provide the user plane security policy to the target access network device. Thus, the probability that the target access network device receives information elements that cannot be used is reduced, and the complexity of data transmission between the target access network device and the mobility management entity is reduced.
[0026] In an optional implementation manner, the method further includes: when the indication information 011 indicates that the terminal device does not support on-demand user plane security protection between the terminal device and the access network device, the target access network device sends a path switch request 033 that does not carry a user plane security policy to the mobility management entity, the path switch request 033 carries the indication information 011, the target access network device receives a path switch response 043 that carries the user plane security policy 023 from the mobility management entity, and the target access network device stores the user plane security policy 023 in a context of the terminal device.
[0027] In an optional implementation manner, the path switch response 043 carrying the user plane security policy 023 further carries indication information 012, which indicates that the terminal device supports on-demand user plane security protection between the terminal device and the access network device.
[0028] In this realization manner, if the source access network device is malicious, the source access network device may maliciously tamper with the indication information 011 to make the indication information 011 indicate that the terminal device does not support on-demand user plane security protection. As a result, the target access network device cannot send the security policy to the mobility management entity and cannot enable security protection for the terminal device. This causes a degradation attack. Therefore, after determining not to send the user plane security policy to the mobility management device, the target access network device may further send the indication information 011 so that the mobility management entity can determine whether the indication information 011 has been tampered with. After determining that the indication information 011 has been tampered with, the mobility management entity sends the user plane security policy to the target access network device. This can avoid the degradation attack.
[0029] In an optional implementation manner, the method further includes: when the indication information 011 indicates that the terminal device does not support on-demand user plane security protection between the terminal device and the access network device, the target access network device sends a path switch request 035 that does not carry a user plane security policy to a mobility management entity, the path switch request 035 carries the indication information 011, and the target access network device receives a path switch response 045 that does not carry a user plane security policy or indication information from the mobility management entity.
[0030] In this realization manner, after the target access network device sends the indication information 011 to the mobility management entity, if the path switch response 045 received by the target access network device does not carry a user plane security policy, it indicates that the indication information 011 is consistent with the indication information stored on the mobility management entity, and the indication information 011 received by the target access network device has not been tampered with. Therefore, it helps to avoid degradation attacks on the communication between the target access network device and the mobility management entity.
[0031] In an optional implementation manner, the method further includes: if the current user plane security activation state of the terminal device does not match the user plane security policy 023, the target access network device activates or skips activating user plane encryption protection and / or user plane integrity protection for the terminal device according to the user plane security policy 023, and the current user plane security activation state is a state of whether user plane encryption protection and / or user plane integrity protection is currently activated between the target access network device and the terminal device.
[0032] In the optional implementation, the following conditions are met: The user plane encryption protection policy indicates that activation is required, and the user plane security activation state of the terminal device is that encryption protection is not enabled; The user plane encryption protection policy indicates that activation is not required, and the user plane security activation state of the terminal device is that encryption protection is enabled; The user plane integrity protection policy indicates that activation is required and the user plane security activation state of the terminal device is that integrity protection is not enabled, or The user plane integrity protection policy indicates that activation is not required, and the user plane security activation state of the terminal device indicates that integrity protection is enabled. When any one of the above is satisfied, the user plane security policy does not match the user plane security activation state.
[0033] In an optional implementation manner, the indication information 011 is represented by a part of the bits of the evolved packet system security capability of the terminal device, and the evolved packet system security capability of the terminal device indicates at least one security algorithm supported by the terminal device.
[0034] In this realization manner, regardless of whether the access network device is upgraded or not (specifically, whether the access network device supports on-demand user plane security protection or not), the access network device can identify and forward the evolved packet system security capability of the terminal device (e.g., UE evolved packet system security capability). Therefore, adding the indication information 011 to the evolved packet system security capability of the terminal device can ensure that the indication information 011 is not lost during transmission between access network devices (e.g., between an access network device that supports on-demand user plane security protection and an access network device that does not support on-demand user plane security protection) or between an access network device and a core network device (between an access network device that does not support on-demand user plane security protection and a mobility management entity). However, in the prior art, the redefined indication information indicates whether the terminal device supports on-demand user plane security protection or not, and the redefined indication information cannot be identified by an access network device that is not upgraded. Specifically, an access network device that does not support on-demand user plane security protection cannot identify the redefined indication information. If an access network device that does not support on-demand user plane security protection receives the redefined indication information, the access network device that does not support on-demand user plane security protection discards the redefined indication information and cannot send the redefined indication information to other access network devices or core network devices (e.g., mobility management entities).
[0035] In an optional implementation, message 001 is a handover request or a context acquisition response.
[0036] According to a second aspect, an embodiment of the present application provides a communication device, including a receiving module, a processing module, and a sending module. The receiving module is configured to receive a message 001 from a source access network device, where the message 001 includes indication information 011. The processing module is configured to control the sending module to send a path switch request 031, carrying a user plane security policy 021, to a mobility management entity when the indication information 011 indicates that the terminal device supports on-demand user plane security protection between the terminal device and the access network device, where the user plane security policy 021 indicates whether to enable user plane encryption protection and / or whether to enable user plane integrity protection.
[0037] In an optional implementation, the access network device is an Evolved Node B eNB.
[0038] In an optional implementation manner, when the communication device does not receive a user plane security policy from the source access network device, the user plane security policy 021 is the user plane security policy 021-1 established by the communication device.
[0039] In an optional implementation manner, the processing module is further configured to determine that a user plane security activation state between the access network device and the terminal device is that user plane encryption protection is enabled and user plane integrity protection is not enabled, and to construct a user plane security policy 021-1 that matches the user plane security activation state.
[0040] In an optional implementation manner, the user plane security policy 021-1 includes a user plane encryption protection policy and a user plane integrity protection policy, where the user plane encryption protection policy indicates that activation is required or that activation is preferred, and the user plane integrity protection policy indicates that activation is not required or that activation is preferred.
[0041] In an optional implementation manner, when the communication device does not receive a user plane security policy from the source access network device, the user plane security policy 021 is a user plane security policy 021-2 pre-configured in the communication device.
[0042] In an optional implementation manner, the message 001 further includes identifiers of N evolved radio access bearers of the terminal device, where N is an integer greater than or equal to 1, and the path switch request 031 further includes identifiers of the N evolved radio access bearers.
[0043] In an optional implementation manner, the path switch request 031 includes N user plane security policies 021-2, and each of the identifiers of the N evolved radio access bearers corresponds to one user plane security policy 021-2.
[0044] In an optional implementation manner, the receiving module is further configured to receive a path switch response 041 from the mobility management entity, the path switch response 041 carrying the user plane security policy 022, and the communication device further includes a storage module, the storage module being configured to store the user plane security policy 022 in a context of the terminal device.
[0045] In an optional implementation manner, the processing module is further configured to enable or skip enabling user plane encryption protection and / or user plane integrity protection for the terminal device in accordance with the user plane security policy 022 when the current user plane security activation state of the terminal device does not match the user plane security policy 022, and the current user plane security activation state is a state of whether user plane encryption protection and / or user plane integrity protection is currently enabled between the target access network device and the terminal device.
[0046] In an optional implementation manner, the sending module is further configured to send a path switch request 032 that does not carry a user plane security policy to the mobility management entity when the indication information 011 indicates that the terminal device does not support on-demand user plane security protection between the terminal device and the access network device, and the receiving module is further configured to receive a path switch response 042 that does not carry the user plane security policy from the mobility management entity.
[0047] In an optional implementation manner, the sending module is further configured to send a path switch request 033 that does not carry a user plane security policy to the mobility management entity when the indication information 011 indicates that the terminal device does not support on-demand user plane security protection between the terminal device and the access network device, the path switch request 033 carries the indication information 011, the receiving module is further configured to receive a path switch response 043 that carries the user plane security policy 023 from the mobility management entity, and the communication device further includes a storage module, and the storage module is configured to store the user plane security policy 023 in a context of the terminal device.
[0048] In an optional implementation manner, the path switch response 043 carrying the user plane security policy 023 further carries indication information 012, which indicates that the terminal device supports on-demand user plane security protection between the terminal device and the access network device.
[0049] In an optional implementation manner, the processing module is further configured to enable or skip enabling user plane encryption protection and / or user plane integrity protection for the terminal device in accordance with the user plane security policy 023 when the current user plane security activation state of the terminal device does not match the user plane security policy 023, and the current user plane security activation state is a state of whether user plane encryption protection and / or user plane integrity protection is currently enabled between the target access network device and the terminal device.
[0050] In an optional implementation manner, the indication information 011 is represented by a part of the bits of the evolved packet system security capability of the terminal device, and the evolved packet system security capability of the terminal device indicates at least one security algorithm supported by the terminal device.
[0051] In an optional implementation, message 001 is a handover request or a context acquisition response.
[0052] According to a third aspect, an embodiment of the present application provides a security policy processing method. The security policy processing method may be applied to processes such as initial access, handover, RRC connection resumption, or RRC connection re-establishment. In the method, a mobility management entity obtains indication information 013, where the indication information 013 indicates whether a terminal device supports on-demand user plane security protection between the terminal device and an access network device, and the mobility management entity determines whether to send a user plane security policy 024 to an access network device serving the terminal device based on the indication information 013, where the user plane security policy 024 indicates whether to enable user plane encryption protection and / or whether to enable user plane integrity protection.
[0053] In this application, the mobility management entity can determine whether the terminal device supports on-demand user plane security protection based on the indication information 013, and when the terminal device supports on-demand user plane security protection, further determines whether to send a user plane security policy to the access network device serving the terminal device. Therefore, this also helps to reduce the probability that the mobility management entity sends information elements that are not required by the access network device to the access network device, and thus helps to reduce the complexity of transmission. However, in the prior art, the mobility management entity does not have a logic to make a decision based on the indication information 013. In the prior art, the mobility management entity makes a decision and decision-making based on whether the user plane security policy is received from the access network device. If the mobility management entity does not receive a user plane security policy from the access network device, the mobility management entity sends the user plane security policy to the access network device.
[0054] In an optional implementation manner, the indication information 013 is carried in the path switch request 034, and the access network device serving the terminal device is the target access network device. The mobility management entity determines whether to send a user plane security policy 024 to the access network device serving the terminal device based on the indication information 013 includes: When the indication information 013 indicates that the terminal device supports on-demand user plane security protection between the terminal device and the access network device, and the path switch request 034 does not carry a user plane security policy, the mobility management entity sends a path switch response 044 carrying the user plane security policy 024 to the target access network device.
[0055] In an optional implementation manner, the indication information 013 is carried in a non-access stratum message, the access network device serving the terminal device is a source access network device, and the mobility management entity determining whether to send a user plane security policy 024 to the access network device serving the terminal device based on the indication information 013 includes: when the indication information 013 indicates that the terminal device supports on-demand user plane security protection between the terminal device and the access network device, the mobility management entity sends the user plane security policy 024 to the source access network device.
[0056] In an optional implementation manner, before the mobility management entity determines whether to send the user plane security policy 024 to the access network device serving the terminal device based on the indication information 013, the method further includes: The mobility management entity obtains indication information 051, where the indication information 051 indicates whether the access network device serving the terminal device supports on-demand user plane security protection between the access network device and the terminal device. The mobility management entity determines whether to send the user plane security policy 024 to the access network device serving the terminal device based on the indication information 013 includes: The mobility management entity determines whether to send the user plane security policy 024 to the access network device serving the terminal device based on the indication information 013 and the indication information 051.
[0057] In an optional implementation manner, the indication information 013 is carried in a path switch request, or the indication information 013 is carried in a non-access stratum message, and the mobility management entity determining whether to send the user plane security policy 024 to the access network device serving the terminal device according to the indication information 013 and the indication information 051 includes: When the indication information 013 indicates that the terminal device supports on-demand user plane security protection, and the indication information 051 indicates that the access network device serving the terminal device supports on-demand user plane security protection between the access network device and the terminal device, the mobility management entity sends the user plane security policy 024 to the access network device.
[0058] In an optional implementation manner, the indication information 051 is indication information 051-1 received by the mobility management entity from an access network device, or the indication information 051 is indication information 051-2 obtained by the mobility management entity from a network management device.
[0059] In an optional implementation manner, after the mobility management entity obtains the indication information 013, the method further includes: the mobility management entity receives subscription data of the terminal device from a home subscriber server, and when the indication information 013 indicates that the terminal device supports on-demand user plane security protection and the subscription data includes a user plane security policy 024, the mobility management entity stores the user plane security policy 024.
[0060] In an optional implementation manner, after the mobility management entity obtains the indication information 013, the method further includes: the mobility management entity receives subscription data of the terminal device from a home subscriber server, and when the indication information 013 indicates that the terminal device supports on-demand user plane security protection between the terminal device and the access network device, and the subscription data does not include a user plane security policy, the mobility management entity determines a user plane security policy 024 according to a pre-configured user plane security policy 024-1, and stores the user plane security policy 024 in a context of the terminal device.
[0061] In an optional implementation manner, after the mobility management entity obtains the indication information 051, the method further includes: the mobility management entity receives subscription data of the terminal device from a home subscriber server, and when the indication information 013 indicates that the terminal device supports on-demand user plane security protection between the terminal device and the access network device, the indication information 051 indicates that the access network device supports on-demand user plane security protection between the access network device and the terminal device, and the subscription data includes a user plane security policy 024, the mobility management entity stores the user plane security policy 024.
[0062] In an optional implementation manner, after the mobility management entity obtains the indication information 051, the method further includes: the mobility management entity receives subscription data of the terminal device from a home subscriber server, and when the indication information 013 indicates that the terminal device supports on-demand user plane security protection between the terminal device and the access network device, and the indication information 051 indicates that the access network device supports on-demand user plane security protection between the access network device and the terminal device, and the subscription data does not include a user plane security policy, the mobility management entity determines a user plane security policy 024 according to a pre-configured user plane security policy 024-2, and stores the user plane security policy 024 in a context of the terminal device.
[0063] In an optional implementation manner, the indication information 013 is represented by a part of the bits of the evolved packet system security capability of the terminal device, and the evolved packet system security capability of the terminal device indicates at least one security algorithm supported by the terminal device.
[0064] According to a fourth aspect, an embodiment of the application provides a communications device, comprising a processing module configured to obtain indication information 013, the indication information 013 indicating whether the terminal device supports on-demand user plane security protection between the terminal device and an access network device, and configured to decide whether to send a user plane security policy 024 to an access network device serving the terminal device based on the indication information 013, the user plane security policy 024 indicating whether to enable user plane encryption protection and / or whether to enable user plane integrity protection.
[0065] In an optional implementation manner, the indication information 013 is carried in the path switch request 034, the access network device serving the terminal device is a target access network device, and the processing module is specifically configured to control the transceiver module to send a path switch response 044 carrying the user plane security policy 024 to the target access network device when the indication information 013 indicates that the terminal device supports on-demand user plane security protection between the terminal device and the access network device and the path switch request 034 does not carry a user plane security policy.
[0066] In an optional implementation manner, the indication information 013 is carried in a non-access stratum message, the access network device serving the terminal device is a source access network device, and the processing module is specifically configured to control the transceiver module to send the user plane security policy 024 to the source access network device when the indication information 013 indicates that the terminal device supports on-demand user plane security protection between the terminal device and the access network device.
[0067] In an optional implementation, the processing module comprises: and further configured to obtain indication information 051, the indication information 051 indicating whether an access network device serving the terminal device supports on-demand user plane security protection between the access network device and the terminal device; It is further configured to control the transceiver module based on the indication information 013 and the indication information 051 to decide whether to send the user plane security policy 024 to the access network device serving the terminal device.
[0068] In an optional implementation manner, the indication information 013 is carried in a path switch request, or the indication information 013 is carried in a non-access stratum message; When the indication information 013 indicates that the terminal device supports on-demand user plane security protection and the indication information 051 indicates that the access network device serving the terminal device supports on-demand user plane security protection between the access network device and the terminal device, the transceiver module is controlled to send the user plane security policy 024 to the access network device.
[0069] In an optional implementation manner, the indication information 051 is indication information 051-1 received by the mobility management entity from an access network device, or the indication information 051 is indication information 051-2 obtained by the mobility management entity from a network management device.
[0070] In an optional implementation manner, the transceiver module is configured to receive subscription data of the terminal device from a home subscriber server, and when the indication information 013 indicates that the terminal device supports on-demand user plane security protection and the subscription data includes a user plane security policy 024, the storage module stores the user plane security policy 024.
[0071] In an optional implementation manner, the transceiver module is configured to receive subscription data of the terminal device from a home subscriber server, and when the indication information 013 indicates that the terminal device supports on-demand user plane security protection between the terminal device and the access network device and the subscription data does not include a user plane security policy, the processing module determines a user plane security policy 024 according to a preconfigured user plane security policy 024-1 and stores the user plane security policy 024 in a context of the terminal device.
[0072] In an optional implementation manner, the transceiver module is configured to receive subscription data of a terminal device from a home subscriber server, and when the indication information 013 indicates that the terminal device supports on-demand user plane security protection between the terminal device and the access network device, the indication information 051 indicates that the access network device supports on-demand user plane security protection between the access network device and the terminal device, and the subscription data includes a user plane security policy 024, the storage module stores the user plane security policy 024.
[0073] In an optional implementation manner, the transceiver module is configured to receive subscription data of the terminal device from a home subscriber server, and when the indication information 013 indicates that the terminal device supports on-demand user plane security protection between the terminal device and the access network device, and the indication information 051 indicates that the access network device supports on-demand user plane security protection between the access network device and the terminal device, and the subscription data does not include a user plane security policy, the processing module determines a user plane security policy 024 according to a preconfigured user plane security policy 024-2, and stores the user plane security policy 024 in a context of the terminal device.
[0074] In an optional implementation manner, the indication information 013 is represented by a part of the bits of the evolved packet system security capability of the terminal device, and the evolved packet system security capability of the terminal device indicates at least one security algorithm supported by the terminal device.
[0075] According to a fifth aspect, an embodiment of the present application provides a communication device. The communication device may be an access network device in the above implementation manner, or may be a chip in the access network device. The communication device may include a processing module and a transceiver module. When the communication device is an access network device, the processing module may be a processor, and the transceiver module may be a transceiver. The access network device may further include a storage module. The storage module may be a memory. The storage module is configured to store instructions. The processing module executes the instructions stored in the storage module so that the access network device executes the method in the first aspect or any one of the implementation manners of the first aspect. When the communication device is a chip in the access network device, the processing module may be a processor, and the transceiver module may be an input / output interface, a pin, a circuit, etc. The processing module executes the instructions stored in the storage module so that the access network device executes the method in the first aspect or any one of the implementation manners of the first aspect. The storage module may be a storage module within the chip (eg, a register or cache) or may be a storage module within the access network device and located off-chip (eg, a read-only memory or random access memory).
[0076] According to a sixth aspect, an embodiment of the present application provides a communication device. The communication device may be a mobility management entity in the above implementation manner, or may be a chip in the mobility management entity. The communication device may include a processing module and a transceiver module. When the communication device is a mobility management entity, the processing module may be a processor and the transceiver module may be a transceiver. The mobility management entity may further include a storage module. The storage module may be a memory. The storage module is configured to store instructions. The processing module executes the instructions stored in the storage module so that the mobility management entity executes the method in the third aspect or any one of the implementation manners of the third aspect. When the communication device is a chip in the mobility management entity, the processing module may be a processor and the transceiver module may be an input / output interface, a pin, a circuit, etc. The processing module executes the instructions stored in the storage module so that the mobility management entity executes the method in the third aspect or any one of the implementation manners of the third aspect. The storage module may be a storage module within the chip (eg, a register or cache) or may be a storage module within the mobility management entity and located off-chip (eg, a read-only memory or a random access memory).
[0077] According to a seventh aspect, the application provides a communication device. The device may be an integrated circuit chip. The integrated circuit chip includes a processor. The processor is coupled to a memory. The memory is configured to store a program or instructions. When the program or instructions are executed by the processor, the communication device is enabled to perform the method of the first aspect or any one of the implementations of the first aspect.
[0078] According to an eighth aspect, the application provides a communication device. The device may be an integrated circuit chip. The integrated circuit chip includes a processor. The processor is coupled to a memory. The memory is configured to store a program or instructions. When the program or instructions are executed by the processor, the communication device is enabled to perform the method of the third aspect or any one of the implementations of the third aspect.
[0079] According to a ninth aspect, an embodiment of the present application provides a computer-readable storage medium comprising instructions which, when run on a computer, enable the computer to perform a method according to the first aspect or any one of the implementations of the first aspect.
[0080] According to a tenth aspect, an embodiment of the present application provides a computer-readable storage medium comprising instructions which, when run on a computer, enable the computer to perform a method according to the third aspect or any one of the implementations of the third aspect.
[0081] According to an eleventh aspect, an embodiment of the present application provides a computer program product comprising instructions, which when run on a computer, enable the computer to perform a method according to the first aspect or any one of the implementations of the first aspect.
[0082] According to a twelfth aspect, an embodiment of the present application provides a computer program product comprising instructions, which when run on a computer, enable the computer to perform a method according to the third aspect or any one of the implementations of the third aspect.
[0083] According to a thirteenth aspect, an embodiment of the present application provides a communication system, the communication system including a mobility management entity and a target access network device in any one of the first aspect or the implementation manners of the first aspect.
[0084] In an optional implementation, the communication system further includes a source access network device and a terminal device.
[0085] According to a fourteenth aspect, an embodiment of the present application provides a communication system, the communication system including an access network device and a mobility management entity in any one of the third aspect or the implementation manners of the third aspect.
[0086] In an optional implementation, the communication system further includes a source access network device and a terminal device.
[0087] From the above technical solutions, it can be seen that the embodiments of this application have the following advantages:
[0088] In this application, the target access network device can determine whether the terminal device supports on-demand user plane security protection based on the indication information 011, and the target access network device sends the user plane security policy 021 to the mobility management entity only when the terminal device supports on-demand user plane security protection. This avoids the following case: When the terminal device does not support on-demand user plane security protection and the mobility management entity does not receive the user plane security policy from the target access network device, the mobility management entity sends the user plane security policy to the target access network device, so that even if the target access network device receives the user plane security policy, the target access network device cannot enable on-demand user plane security protection for the terminal device. Therefore, this helps to reduce the probability that the mobility management entity sends information elements that are not required by the access network device to the target access network device, and thus helps to reduce the complexity of transmission.
[0089] In addition, the mobility management entity can determine whether the terminal device supports on-demand user plane security protection based on the indication information 013, and further determines whether to send a user plane security policy to an access network device serving the terminal device when the terminal device supports on-demand user plane security protection. Therefore, this also helps to reduce the probability that the mobility management entity sends information elements that are not needed by the access network device to the access network device, and thus helps to reduce the complexity of transmission. [Brief description of the drawings]
[0090] In order to more clearly describe the technical solutions in the embodiments of this application, the following briefly describes the accompanying drawings for describing the embodiments. Obviously, the accompanying drawings in the following description only show some embodiments of this application. [Figure 1] FIG. 1 is a diagram of the architecture of a 4G network to which the security policy processing method according to this application can be applied. [Diagram 2] 1 is a schematic diagram of an embodiment of a security policy processing method according to the present application; [Figure 3A] FIG. 2 is an exemplary diagram of a security policy processing method in a handover scenario according to the present application. [Figure 3B] FIG. 2 is an exemplary diagram of a security policy processing method in a handover scenario according to the present application. [Figure 4] 4 is a schematic diagram of another embodiment of a security policy processing method according to the present application; [Diagram 5] 4 is a schematic diagram of another embodiment of a security policy processing method according to the present application; [Figure 6A] FIG. 2 is an exemplary diagram of a security policy processing method in an RRC connection resumption scenario according to the present application. [Figure 6B] FIG. 2 is an exemplary diagram of a security policy processing method in an RRC connection resumption scenario according to the present application. [Figure 7] FIG. 2 is an exemplary diagram of a security policy processing method in an access scenario of the present application. [Figure 8] 1 is a schematic diagram of an embodiment of a communication device according to the present application; [Figure 9] 2 is a schematic diagram of another embodiment of a communication device according to the present application; [Figure 10] 2 is a schematic diagram of another embodiment of a communication device according to the present application; [Figure 11] 2 is a schematic diagram of another embodiment of a communication device according to the present application; DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0091] The following clearly and completely describes the technical solutions in the embodiments of this application with reference to the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are merely a part, but not all, of the embodiments of this application.
[0092] In the specification, claims and accompanying drawings of this application, the terms "first," "second," "third," "fourth," and their corresponding reference numerals, when present, are intended to distinguish between similar objects, but do not necessarily indicate a particular order or sequence. It should be understood that the data so used are interchangeable where appropriate, such that the embodiments described herein may be realized in orders other than those illustrated or described herein. Furthermore, the words "comprise," "include," and any variations thereof are intended to cover a non-exclusive inclusion. For example, a process, method, system, product, or device that includes a list of steps or units is not necessarily limited to the steps or units expressly listed, but may include other steps or units that are not expressly listed or that are inherent to the process, method, system, product, or device.
[0093] An embodiment of this application provides a security policy processing method and a communication device for reducing the probability that a mobility management entity sends information elements not required by an access network device to an access network device, reducing transmission complexity, and improving data transmission efficiency.
[0094] Below, we first describe a system architecture and application scenarios to which the security policy processing method provided in this application can be applied.
[0095] The security policy processing method provided in this application may be applied to 4G network architecture. Figure 1 shows the current long term evolution (LTE) / system architecture evolution (SAE) network architecture. The core network part mainly includes a mobility management entity (MME), a serving gateway (SGW / S-GW), a packet data network gateway (PDN GW, PGW / P-GW), a home subscriber server (HSS), a serving GPRS support node (SGSN), a policy and charging rules function (PCRF), an operator's IP Services (e.g. IP multimedia subsystem (IMS) or packet switching service (PSS)), etc. The core network may be an evolved packet core (EPC). In addition, Figure 1 further includes an access network part, i.e., an evolution UMTS terrestrial radio access network (E-UTRAN). The access network part mainly includes an access network (radio access network, RAN) device. In addition, Figure 1 further includes a terminal device, e.g., a user equipment (UE).
[0096] The mobility management entity MME manages and stores the mobility management context of a terminal device (e.g. terminal device identifier, mobility management state and user security parameters), processes non-access stratum (NAS) signaling (e.g. attach request, update location request, service request and packet data network connectivity request), ensures security of NAS signaling etc.
[0097] The serving gateway S-GW is a gateway that terminates the user plane interface from the access network and performs functions such as lawful interception and packet data routing. The interface between the serving gateway S-GW and the mobility management entity MME is the S11 interface, which is used to exchange session control information of terminal devices, etc.
[0098] The packet data network gateway P-GW is a gateway that terminates the SGi interface to the packet data network and is configured to provide functions such as bearer control, data forwarding, IP address allocation and non-3GPP user access, and is an anchor for 3GPP and non-3GPP access to the public data network (PDN). The P-GW has packet routing and forwarding functions, performs policy and charging enforcement functions, user-specific packet filtering functions, etc. The P-GW is connected to the S-GW through an S5 interface for transmitting control information for information establishment, modification, deletion, etc., routing packet data, etc. Furthermore, the P-GW is further connected to the operator's IP services through an SGi interface.
[0099] The Home Subscriber Server HSS is a core database that stores subscriber information in the subscriber's home network. The HSS mainly includes user profile, user subscription data, information about user identity authentication and authorization, information about the user's physical location, etc. The HSS is connected to the MME through an S6a interface, so that the MME can obtain information such as the user profile and user subscription data from the HSS.
[0100] The Policy and Charging Rules Function PCRF is a policy and charging control policy decision point for service data flows and IP bearer resources, and may control user-mode and service-mode quality of service (QoS) to provide differentiated services to users. The PCRF is connected to the P-GW through a Gx interface and to the operator's IP services through an Rx interface.
[0101] Furthermore, the MME is connected to the E-UTRAN through an S1-MME interface, and the S-GW is connected to the E-UTRAN and the MME through an S1-U interface and an S11 interface, respectively. Furthermore, the MME and the S-GW are connected to a 2G / 3G network and an SGSN through an S3 interface and an S4 interface, respectively, and provide a mobility control plane anchor function and a mobility user plane anchor function for terminal devices in the corresponding networks, respectively. Furthermore, the S-GW is further connected to an evolved universal terrestrial radio access network (UTRAN) through an S12 interface.
[0102] The access network device is a bridge between the terminal device and the core network device, and is configured to manage radio resources, select an MME in an attach process, route user data plane to an S-GW, etc. The access network device in this application may be a 4G radio access network device, or a device that communicates with a wireless terminal device over an air interface in a 4G access network through one or more cells. For example, the access network device may be an evolutional node B (NodeB, eNB, or e-NodeB) in a long term evolution LTE system or a long term evolution advanced (LTE-A) system. It should be noted that the access network device in this application may be an upgraded access network device (e.g., an access network device that supports on-demand user plane security protection) or a non-upgraded access network device (e.g., an access network device that does not support on-demand user plane security protection). Furthermore, based on different orders for serving the terminal device, the access network devices in this application may be classified into a source access network device (source evolutional node B, S-eNB) and a target access network device (target evolutional node B, T-eNB). The source access network device may be the access network device serving the terminal device during the initial access of the terminal device, or the source access network device is the access network device serving the terminal device before the handover, RRC connection resumption or RRC connection re-establishment process is performed. The target access network device is the access network device serving the terminal device after the handover, RRC connection resumption or RRC connection re-establishment process is performed.Usually, the context of the terminal device is transmitted between the source access network device and the target access network device. It should be understood that the access network device in the embodiment of this application may be any one of the above devices or chips in the above devices. This is not specifically limited here. Regardless of being a device or a chip, the access network device can be manufactured, sold or used as an independent product. In this embodiment and the following embodiments, the access network device is used as an example for explanation.
[0103] Furthermore, the terminal device includes a device that provides a voice and / or data connection to a user. For example, the terminal device may include a handheld device with wireless connectivity or a processing device connected to a wireless modem. The terminal device may communicate with a core network (e.g., a mobility management entity MME) through a radio access network RAN (e.g., a source access network device or a target access network device) and exchange voice and / or data with the RAN. The terminal device may include a user equipment UE, a wireless terminal device, a mobile terminal device, a subscriber unit, a subscriber station, a mobile station, a mobile console, a remote station, an access point (AP), a remote terminal device, an access terminal device, a user terminal device, a user agent, a user device, etc. Furthermore, the terminal device may alternatively be an on-board terminal, for example, a telematics box (T-Box), a domain controller (DC), a multi-domain controller (MDC) or an on-board unit (OBU) integrated into a vehicle. The terminal device may alternatively be a wearable device, such as glasses, gloves, a watch, clothing or shoes, or other portable devices that may be directly attached to the body or integrated into a user's clothing or accessories. This is not specifically limited in this application. It should be noted that the terminal device in this application may be an upgraded terminal device (e.g., a terminal device that supports on-demand user plane security protection) or a non-upgraded terminal device (e.g., a terminal device that does not support on-demand user plane security protection). It should be understood that the terminal device in the embodiments of this application may be any one of the above devices or chips. This is not specifically limited here. Regardless of whether it is a device or a chip, the terminal device can be manufactured, sold or used as an independent product. In this embodiment and the following embodiments, only the terminal device is used as an example for explanation.
[0104] The above 4G network architecture usually includes both upgraded access network devices (e.g., access network devices supporting on-demand user plane security protection) and non-upgraded access network devices (e.g., access network devices not supporting on-demand user plane security protection). Currently, during the application of the on-demand user plane security protection mechanism in the 4G network, in order to enable on-demand user plane security protection between a terminal device supporting on-demand user plane security protection and an access network device, a mobility management entity in the 4G network is configured to always send a user plane security policy to an access network device that communicates with the mobility management entity. For example, when the mobility management entity does not receive a user plane security policy from an access network device, the mobility management entity returns the user plane security policy to the access network device.
[0105] In the above prior art solution, an access network device that supports on-demand user plane security protection can enable on-demand user plane security protection for a terminal device by using the above information elements, but an access network device that does not support on-demand user plane security protection always receives information elements that cannot be used by the access network device, which results in an increased complexity of transmission between a mobility management entity and an access network device that does not support on-demand user plane security protection, and affects transmission efficiency.
[0106] In view of this, in the security policy processing method provided in this application, a decision logic can be added on the access network device side and / or the mobility management entity side to reduce the probability that the mobility management entity sends the user plane security policy to an access network device that does not support on-demand user plane security protection, while maximally ensuring that access network devices and terminal devices that support on-demand user plane security protection can receive the user plane security policy.
[0107] Based on the above system architecture and application scenario, the implementation manner of the security policy processing method in this application is described below. As shown in Figure 2, the access network device and the mobility management entity perform the following steps:
[0108] Step 201: A source access network device sends a message 001 including indication information 011 to a target access network device. Correspondingly, the target access network device receives a message 001 including indication information 011 from the source access network device.
[0109] In this embodiment and the following embodiments, for ease of description, based on the order of serving the terminal device, the access network device serving the terminal device from the beginning is called a source access network device, and the access network device serving the terminal device thereafter is called a target access network device. For example, the terminal device may change from accepting services provided by the source access network device to accepting services provided by the target access network device through processes such as handover, RRC connection resume, RRC connection reestablishment, etc.
[0110] In this process, the target access network device may receive a context of the terminal device from the source access network device through signaling between the target access network device and the source access network device (e.g., message 001). The context of the terminal device includes indication information 011. Optionally, if this embodiment is applied to a handover process, the message 001 is a handover request, or if this embodiment is applied to an RRC connection resumption or RRC connection re-establishment process, the message 001 is a context acquisition response.
[0111] The indication information 011 indicates whether the terminal device supports on-demand user plane security protection. Alternatively, the indication information 011 further indicates whether the terminal device supports on-demand user plane security protection between the terminal device and the access network device. Whether the terminal device supports on-demand user plane security protection may be understood as whether the terminal device supports enabling user plane encryption protection and / or whether the terminal device supports enabling user plane integrity protection, that is, the user plane encryption protection and / or the user plane integrity protection for the terminal device is not fixed. Whether the terminal device supports on-demand user plane security protection between the terminal device and the access network device may be understood as whether the terminal device supports enabling / disabling user plane encryption protection and / or user plane integrity protection under the instruction by the access network device. The access network device here may be an eNB, for example, a source eNB or a target eNB referred to in the following description. It should be understood that multiple expressions of the indication information 011 are interchangeable. In the following embodiments, the expression "the indication information 011 indicates whether the terminal device supports on-demand user plane security protection" is used as an example for explanation.
[0112] Specifically, the indication information 011 may be represented by a part of the bits of the evolved packet system security capability of the terminal device, and the evolved packet system security capability of the terminal device indicates at least one security algorithm supported by the terminal device. For example, the evolved packet system security capability of the terminal device is UE evolved packet system security capabilities (UE EPS security capabilities), and the indication information 011 may be represented by a reserved bit, for example, EEA7 or EIA7, in the evolved packet system security capability of the terminal device. EEA7 represents a bit reserved for the eighth encryption algorithm in the UE evolved packet system security capability, and EIA7 represents a bit reserved for the eighth integrity algorithm in the UE evolved packet system security capability. In this embodiment, the bit is used to carry an indication indicating whether the terminal device supports on-demand user plane security protection. Regardless of whether the access network device is upgraded (specifically, whether the access network device supports on-demand user plane security protection), the access network device can identify and forward the evolved packet system security capability of the terminal device (for example, UE evolved packet system security capability). Therefore, adding the indication information 011 to the evolved packet system security capabilities of the terminal device can ensure that the indication information 011 is not lost during transmission between access network devices (e.g., between an access network device that supports on-demand user plane security protection and an access network device that does not support on-demand user plane security protection) or between access network devices and core network devices (between an access network device that does not support on-demand user plane security protection and a mobility management entity).However, in the prior art, the redefined indication information indicates whether the terminal device supports on-demand user plane security protection, and the redefined indication information cannot be identified by an unupgraded access network device. Specifically, an access network device that does not support on-demand user plane security protection cannot identify the redefined indication information. When an access network device that does not support on-demand user plane security protection receives the redefined indication information, the access network device that does not support on-demand user plane security protection discards the redefined indication information and cannot send the redefined indication information to other access network devices or core network devices (e.g., mobility management entities).
[0113] Optionally, the message 001 further includes an identification used by the terminal device to establish a bearer, for example an identifier of an E-UTRAN radio access bearer (E-RAB), which may also be understood as the context of the terminal device further including an E-RAB identifier used to establish the bearer.
[0114] Furthermore, message 001 includes identifiers of N E-RABs of the terminal device, where N is an integer greater than or equal to 1.
[0115] Step 202: The target access network device determines whether a preset condition is met.
[0116] In this embodiment, the preset condition is a preset condition on the indication information 011. When the target access network device determines that the preset condition is met, the target access network device sequentially executes step 203a and step 203b. When the target access network device determines that the preset condition is not met, the target access network device executes step 203c or step 203d. This may be understood as the target access network device determining whether to obtain a user plane security policy and send the user plane security policy to the mobility management entity based on the preset condition on the indication information 011.
[0117] The pre-set condition may be realized in any one of the following ways:
[0118] In an optional implementation manner, the preset conditions include: the indication information 011 indicates that the terminal device supports on-demand user plane security protection.
[0119] In another optional implementation manner, the preset condition is that the indication information 011 indicates that the terminal device supports on-demand user plane security protection, and the target access network device supports on-demand user plane security protection.
[0120] It should be understood that whether the target access network device supports on-demand user plane security protection may be understood as whether the access network device supports on-demand user plane security protection between the access network device and the terminal device, or may be understood as whether the access network device supports enabling of user plane encryption protection and / or user plane integrity protection for the terminal device, or may be understood as whether the access network device can send an instruction to the terminal device so that the terminal device enables / disables user plane encryption protection and / or user plane integrity protection based on the instruction. It should be understood that the above expressions are interchangeable. In the following embodiments, the expression "the target access network device supports on-demand user plane security protection" is used as an example for explanation.
[0121] It should be understood that when the target access network device is an upgraded access network device (specifically, an access network device that supports on-demand user plane security protection), the target access network device can know that the target access network device can support on-demand user plane security protection. When the target access network device is a non-upgraded access network device (specifically, an access network device that does not support on-demand user plane security protection), the target access network device can know that the target access network device does not support on-demand user plane security protection.
[0122] In addition, when the solution of this application is applied to an upgraded access network device, it should be further understood that when the target access network device determines whether the indication information 011 indicates that the terminal device supports on-demand user plane security protection, this actually indicates that the target access network device supports on-demand user plane security protection. Therefore, optionally, the logic for determining whether the target access network device supports on-demand user plane security protection may not need to be set separately for the target access network device.
[0123] Step 203a: The target access network device obtains the user plane security policy 021.
[0124] The user plane security policy is a policy indicating whether to enable user plane encryption protection and / or user plane integrity protection. This may also be understood as the user plane security policy including a user plane encryption protection policy and a user plane integrity protection policy, the user plane encryption protection policy indicating whether to enable user plane encryption protection, and the user plane integrity protection policy indicating whether to enable user plane integrity protection. Currently, the user plane encryption protection policy and the user plane integrity protection policy each include three indications, namely, required, preferred, and not needed. Specifically, when the user plane encryption protection policy is "required", it indicates that the user plane encryption protection needs to be forcibly enabled, when the user plane encryption protection policy is "not needed", it indicates that the user plane encryption protection needs to be forcibly disabled, or when the user plane encryption protection policy is "preferred", it indicates that the user plane encryption protection may be optionally enabled based on the actual case (for example, the access network device may determine whether to enable the user plane encryption protection between the access network device and the terminal device based on the load state of the access network device, and when the load is greater than a threshold, the user plane encryption protection is not enabled, and otherwise, the user plane encryption protection is enabled). The use of the user plane integrity protection policy is the same as the use of the user plane encryption protection policy. The details will not be described again.
[0125] Specifically, the target access network device may obtain the user plane security policy 021 in several ways:
[0126] In an optional implementation manner, when the target access network device does not receive a user plane security policy from the source access network device, the user plane security policy 021 may be the user plane security policy 021-1 established by the target access network device.
[0127] In this realization manner, since the target access network device does not receive a user plane security policy from the source access network device, the target access network device may enable on-demand user plane security protection for the terminal device in a default manner (which may be understood as a non-upgraded manner). For example, the target access network device may enable user plane encryption protection and skip enabling user plane integrity protection. The user plane security policy 021-1 established by the target access network device needs to match the current user plane security activation state of the terminal device, specifically, the state in which user plane encryption protection is enabled and user plane integrity protection is not enabled. For example, the user plane security policy 021-1 established by the target access network device is a policy that matches the user plane security activation state in which user plane encryption protection is enabled and user plane integrity protection is not enabled. Specifically, the user plane security policy 021-1 includes a user plane encryption protection policy and a user plane integrity protection policy, where the user plane encryption protection policy indicates that activation is required or preferred, and the user plane integrity protection policy indicates that activation is not needed or preferred.
[0128] For example, when the user plane security policy is expressed as {user plane encryption protection policy, user plane integrity protection policy}, the user plane security policy 021-1 may be specifically realized in any one of the following manners: {activation required, activation not needed}, {activation required, activation preferred}, {activation preferred, activation not needed}, or {activation preferred, activation preferred}.
[0129] It should be understood that the user plane security policy 021-1 may be a user plane security policy at E-RAB granularity. Usually, when one terminal device corresponds to N E-RABs, the target access network device may construct a corresponding user plane security policy 021-1 for each E-RAB of the terminal device based on an E-RAB identifier obtained from the context of the terminal device. In this case, the target access network device may obtain N user plane security policies 021-1, where N is an integer equal to or greater than 1. Each E-RAB corresponds to one user plane security policy 021-1. However, the user plane security policies corresponding to different E-RABs may be the same or different.
[0130] Furthermore, when subsequently transmitting the user plane security policy, the target access network device adds the user plane security policy 021-1 and the E-RAB identifier to the signaling to indicate that the user plane security policy 021-1 is used to decide whether user plane encryption protection and / or user plane integrity protection needs to be enabled for the E-RAB corresponding to the E-RAB identifier. For details, see the description in step 203b. In this realization manner, the mobility management entity (e.g., MME) can have finer granularity when performing the decision on the user plane security policy, thereby reducing the number of user plane security policies returned by the MME when the user plane security policies corresponding to some E-RABs are different but the user plane security policies corresponding to other E-RABs are the same.
[0131] In another optional implementation manner, when the target access network device does not receive a user plane security policy from the source access network device, the user plane security policy 021 may be a user plane security policy 021-2 pre-configured in the target access network device.
[0132] In this realization manner, the user plane security policy 021-2 is pre-configured in the target access network device, and the pre-configured user plane security policy 021-2 may be a policy applicable to all terminal devices. The pre-configured user plane security policy may include a user plane encryption protection policy and / or a user plane integrity protection policy. The user plane encryption protection policy may be one of the following: required to be enabled, preferred to be enabled, or not needed to be enabled. The user plane integrity protection policy may also be one of the following: required to be enabled, preferred to be enabled, or not needed to be enabled.
[0133] Specifically, the target access network device may pre-configure only one user plane security policy applicable to all terminal devices, and then map the user plane security policy to obtain N user plane security policies 021-2 at E-RAB granularity. In this realization manner, the complexity of configuring the user plane security policy by the target access network device can be reduced. Furthermore, the mobility management entity (e.g., MME) can have finer granularity when performing a decision on the user plane security policy, thereby reducing the number of user plane security policies returned by the MME when the user plane security policies corresponding to some E-RABs are different but the user plane security policies corresponding to other E-RABs are the same.
[0134] Furthermore, the user plane security policy 021 may alternatively be a user plane security policy 021-3 obtained by the target access network device from another device.
[0135] In a possible implementation, if the source access network device supports on-demand user plane security protection, the signaling between the target access network device and the source access network device may carry the user plane security policy 021-3. In this case, the user plane security policy 021 may be the user plane security policy 021-3 received by the target access network device from the source access network device.
[0136] Step 203b: The target access network device sends a path switch request 031 carrying the user plane security policy 021 to the mobility management entity. In response, the mobility management entity receives the path switch request 031 carrying the user plane security policy 021 from the target access network device.
[0137] The user plane security policy 021 may be a user security policy determined in any one of the implementation methods in step 203a. For example, the user plane security policy 021 may be a user plane security policy 021-1, a user plane security policy 021-2, or a user plane security policy 021-3.
[0138] In an optional implementation manner, the path switch request 031 is a path switch request 031-1, and the path switch request 031-1 carries a user plane security policy 021. For example, the user plane security policy 021 is a security policy at terminal device granularity, and one terminal device corresponds to one user plane security policy. In this case, in addition to the user plane security policy 021, the path switch request 031 may further carry an identifier of the terminal device (for example, an eNB UE S1AP ID or an MME UE S1AP ID).
[0139] In another optional realization manner, the path switch request 031 is a path switch request 031-2, and the path switch request 031-2 carries N user plane security policies 021 at E-RAB granularity and N E-RAB identifiers, and each identifier of the N E-RAB identifiers corresponds to one of the N user plane security policies 021. Specifically, the target access network device adds both the E-RAB identifier and the user plane security policy corresponding to the E-RAB to the path switch request 031-2, so that both the E-RAB identifier and the user plane security policy corresponding to the E-RAB can be sent to the mobility management entity. Correspondingly, when the mobility management entity receives the path switch request 031-2 carrying both the E-RAB identifier and the user plane security policy, the mobility management entity can know the E-RAB to which the user plane security policy is applicable. Furthermore, the path switch request 031-2 may further carry an identifier of a terminal device (eg, an eNB UE S1AP ID or an MME UE S1AP ID) to indicate the terminal device corresponding to one or more of the E-RABs.
[0140] It should be noted that when the user security policy 021 carried in the path switching request 031-2 is a user plane security policy 021-1 established by the target access network device, the N user plane security policies 021-1 carried in the path switching request 031-2 may be the same or different.
[0141] For example, the implementation manner in which the path switching request 031-2 carries multiple user plane security policies 021-1 is specifically as follows, that is, {E-RAB1: user plane security policy 021-1-1}, {E-RAB2: user plane security policy 021-1-2}, and {E-RAB3: user plane security policy 021-1-3}. The contents of the user plane security policy 021-1-1, the contents of the user plane security policy 021-1-2, and the contents of the user plane security policy 021-1-3 may be the same or different.
[0142] However, when the user security policy 021 carried in the path switching request 031-2 is a plurality of user plane security policies 021-2 obtained by mapping a user plane security policy pre-configured by the target access network device and applicable to all terminal devices, the contents of all N user plane security policies 021-2 carried in the path switching request 031-2 are the same.
[0143] For example, the implementation manner in which the path switching request 031-2 carries multiple user plane security policies 021-2 is specifically as follows, that is, {E-RAB1: user plane security policy 021-2}, {E-RAB2: user plane security policy 021-2}, and {E-RAB3: user plane security policy 021-2}. The contents of the user plane security policy 021-2, the contents of the user plane security policy 021-2, and the contents of the user plane security policy 021-2 are the same.
[0144] In this implementation, the target access network device may determine whether to enable user plane encryption protection and / or user plane integrity protection for each E-RAB corresponding to the terminal device, which facilitates fine-grained management of user plane security policies and user plane security activation states.
[0145] Step 203c: The target access network device sends a path switch request 032 that does not carry a user plane security policy to the mobility management entity. In response, the mobility management entity receives a path switch request 032 that does not carry a user plane security policy from the target access network device.
[0146] In this embodiment, when the preset condition includes that the indication information 011 indicates that the terminal device supports on-demand user plane security protection, when the indication information 011 indicates that the terminal device does not support on-demand user plane security protection, the target access network device sends a path switching request 032 that does not carry a user plane security policy to the mobility management entity.
[0147] If the preset condition is that the indication information 011 indicates that the terminal device supports on-demand user plane security protection and the target access network device supports on-demand user plane security protection, when the indication information 011 indicates that the terminal device does not support on-demand user plane security protection or when the target access network device does not support on-demand user plane security protection, the target access network device sends a path switch request 032 that does not carry a user plane security policy to the mobility management entity.
[0148] Step 203d: The target access network device sends a path switch request 033 that does not carry a user plane security policy to the mobility management entity. In response, the mobility management entity receives a path switch request 033 that does not carry a user plane security policy from the target access network device.
[0149] A path switching request 033 that does not carry a user plane security policy carries indication information 011 .
[0150] In the prior art, the target access network device only determines whether a user plane security policy is received from the source access network device. If a user plane security policy is received, the target access network device sends the user plane security policy to the mobility management entity. If not, the target access network device cannot add the user plane security policy during interaction with the mobility management entity. Compared with the prior art, in this application, a logic is added to make a decision by the target access network device based on the indication information 011, so that the target access network device sends the user plane security policy to the mobility management entity only when the terminal device supports on-demand user plane security protection. In this way, the updated user plane security policy returned by the mobility management entity is applicable to the target access network device. Specifically, the target access network device can use the user plane security policy to enable or disable user plane encryption protection and / or user plane integrity protection for the terminal device. Otherwise, if the terminal device does not support on-demand user plane security protection, the target access network device cannot enable user plane encryption protection or user plane integrity protection for the terminal device even if the target access network device can obtain the user plane security policy. Thus, the probability that an access network device will receive an information element that it cannot use is reduced.
[0151] Step 204: The mobility management entity determines whether the path switch request carries a user plane security policy.
[0152] The path switching request may be any one of a path switching request 031 , a path switching request 032 and a path switching request 033 .
[0153] In an optional implementation manner, if the path switch request does not carry a user plane security policy, for example, if the path switch request is path switch request 032, the mobility management entity performs step 205a; alternatively, if the path switch request carries a user plane security policy, for example, if the path switch request is path switch request 031, the mobility management entity performs step 205b.
[0154] In another optional realization manner, if the path switch request does not carry a user plane security policy, but the switch request that does not carry a user plane security policy carries an indication information 011, i.e., when the mobility management entity receives the path switch request 033, the mobility management entity further compares the indication information 011 with the indication information 012 on the mobility management entity. If the indication information 012 on the mobility management entity indicates that the terminal device supports on-demand user plane security protection, the mobility management entity sends a path switch response 043 (not shown in the drawing) carrying the indication information 012 and the user plane security policy 023 to the target access network device. If the indication information 011 matches the indication information 012 on the mobility management entity, the mobility management entity executes step 205a. In this realization manner, if the source access network device is malicious, the source access network device may maliciously tamper with the indication information 011 to make the indication information 011 indicate that the terminal device does not support on-demand user plane security protection. As a result, the target access network device cannot send the user plane security policy to the mobility management entity and cannot enable on-demand user plane security protection for the terminal device. This causes a degradation attack. Therefore, after determining not to send the user plane security policy to the mobility management device, the target access network device may further send the indication information 011 so that the mobility management entity can determine whether the indication information 011 has been tampered with. After determining that the indication information 011 has been tampered with, the mobility management entity sends the user plane security policy to the target access network device. This can avoid the degradation attack.
[0155] The indication information 012 may come from the terminal device and may be provided by the terminal device to the mobility management entity when the terminal device is first attached to the network. For the relevant description of the user plane security policy 023, please refer to the description in step 205b. Details are not described here.
[0156] In addition, the target access network device further stores the user plane security policy 023 in the context of the terminal device. It should be understood that if a user plane security policy (e.g., the user plane security policy 023') is stored in the context of the terminal device, the target access network device updates the user plane security policy 023' stored in the context of the terminal device by using the user plane security policy 023. If the user plane security policy is not stored in the context of the terminal device, the target access network device directly stores the user plane security policy 023.
[0157] Step 205a: The mobility management entity sends a path switch request acknowledge 042 that does not carry a user plane security policy to the target access network device. In response, the target access network device receives the path switch request acknowledge 042 that does not carry a user plane security policy from the mobility management entity.
[0158] In the prior art, after a mobility management entity receives a path switch request that does not carry a user plane security policy, the mobility management entity sends the user plane security policy to a target access network device to enable user plane integrity protection between the access network device and the terminal device in a 4G network, in which case the target access network device and the terminal device may not be able to use the user plane security policy.
[0159] However, in this embodiment, in the above steps, when the indication information 011 indicates that the terminal device supports on-demand user plane security protection, the target access network device determines the user plane security policy 021 in any one of the implementation manners in step 203a, adds the user plane security policy 021 to the path switch request, and sends the user plane security policy 021 to the mobility management entity. Therefore, it can be seen that if the indication information 011 indicates that the terminal device does not support on-demand user plane security protection, the target access network device does not send the user plane security policy to the mobility management entity, and correspondingly, the mobility management entity cannot receive the user plane security policy from the target access network device. In this case, it can be inferred that the terminal device does not support on-demand user plane security protection, and even if the user plane security policy is provided to the target access network device, the target access network device cannot enable user plane integrity protection for the terminal device by using the user plane security policy. Therefore, when the mobility management entity receives a path switch request 042 that does not carry a user plane security policy, the mobility management entity is configured to send a path switch response that does not carry a user plane security policy to the target access network device, i.e., not provide the target access network device with a user plane security policy. Thus, the probability that the target access network device receives an information element that cannot be used is reduced, and the complexity of data transmission between the target access network device and the mobility management entity is reduced.
[0160] Step 205b: The mobility management entity decides whether to send a path switch response 041 carrying the user plane security policy 022 based on whether the user plane security policy 021 matches the user security policy on the mobility management entity.
[0161] Specifically, if the user plane security policy 021 matches the user security policy on the mobility management entity, the mobility management entity sends a path switch response that does not carry the user plane security policy to the target access network device.
[0162] If the user plane security policy 021 does not match the user security policy on the mobility management entity, the mobility management entity sends a path switch response 041 carrying the user plane security policy 022 to the target access network device. Then, the target access network device further stores the user plane security policy 022 in the context of the terminal device. It should be understood that if the user plane security policy (e.g., the user plane security policy 021) is stored in the context of the terminal device, the target access network device updates the user plane security policy 021 stored in the context of the terminal device by using the user plane security policy 022. If the user plane security policy is not stored in the context of the terminal device, the target access network device directly stores the user plane security policy 022.
[0163] The user plane security policy 022 may be obtained based on a user plane security policy obtained by the home subscriber server HSS, or may be obtained based on a user plane security policy pre-configured in the mobility management entity.
[0164] Optionally, the user plane security policy obtained by the mobility management entity from the HSS or pre-configured in the mobility management entity is at access point name (APN) granularity. After mapping the user plane security policy at APN granularity to the user plane security policy at E-RAB granularity, the mobility management entity obtains the user plane security policy 022 at E-RAB granularity.
[0165] Optionally, if the path switch request 031 in step 203b is a path switch request 031-1, the path switch request 031-1 carries a user plane security policy 021, and the user plane security policy 021 is a security policy at terminal device granularity, the mobility management entity compares the user plane security policy 021 with the user plane security policy at terminal device granularity on the mobility management entity. If the user plane security policy 021 matches the user security policy at terminal device granularity on the mobility management entity, the mobility management entity sends a path switch response that does not carry a user plane security policy to the target access network device. If the user plane security policy 021 does not match the user security policy at terminal device granularity on the mobility management entity, the mobility management entity sends a path switch response 041 that carries the user plane security policy 022 to the target access network device. In this case, the user plane security policy 022 is a security policy at terminal device granularity.
[0166] In particular, when described in step 205a, the mobility management entity obtains the user plane security policy 022 for all E-RABs corresponding to the terminal device. Specifically, the mobility management entity obtains identifiers of all E-RABs corresponding to the terminal device from the context of the terminal device, obtains corresponding APNs based on each of the E-RAB identifiers, and then obtains the user plane security policy 022 corresponding to each E-RAB according to the user plane security policy corresponding to the APN.
[0167] Optionally, if the path switch request in step 203b is a path switch request 031-2, and the path switch request 031-2 carries N user plane security policies 021 at E-RAB granularity, and each user plane security policy 021 is a policy at E-RAB granularity, the mobility management entity performs a comparison for the user plane security policy corresponding to each E-RAB. If the user plane security policy 021 corresponding to each E-RAB matches the user security policy corresponding to the corresponding E-RAB on the mobility management entity, the mobility management entity sends a path switch response that does not carry a user plane security policy to the target access network device. If the user plane security policy 021 corresponding to the E-RAB does not match the user security policy corresponding to the same E-RAB on the mobility management entity, the mobility management entity sends a path switch response 041 that carries the user plane security policy 022 to the target access network device. The user plane security policy 022 is a security policy at E-RAB granularity, and the user plane security policy 022 is a security policy that is inconsistent with the user plane security policy 021. In this realization manner, the user plane security policy on the mobility management entity may not be inconsistent with some or all of the multiple user plane security policies 021. This is not specifically limited here. Optionally, the path switch response carrying the user plane security policy 022 may further carry an identifier of the E-RAB corresponding to the user plane security policy 022.
[0168] In addition, the target access network device reactivates the terminal device according to the user plane security policy 022, and specifically determines whether to enable user plane encryption protection and / or user plane integrity protection for the terminal device according to the user plane security policy 022. For details, please refer to the related descriptions in steps 309b to 312 in the following embodiments corresponding to Figures 3A and 3B. Details are not described here.
[0169] In this embodiment, the target access network device can determine whether the terminal device supports on-demand user plane security protection based on the indication information 011, and the target access network device sends the user plane security policy to the mobility management entity only when the terminal device supports on-demand user plane security protection. This avoids the following case: When the terminal device does not support on-demand user plane security protection and the mobility management entity does not receive the user plane security policy from the target access network device, the mobility management entity sends the user plane security policy to the target access network device, so that even if the target access network device receives the user plane security policy, the target access network device cannot enable on-demand user plane security protection for the terminal device. Therefore, this helps to reduce the probability that the mobility management entity sends information elements that are not needed by the access network device to the target access network device, and thus helps to reduce the complexity of transmission.
[0170] The security policy processing method described in the embodiment corresponding to FIG. 2 may be applied to any one of the following processes: Handover, RRC Connection Resume, and RRC Connection Reestablishment. The handover process shown in FIG. 3A and FIG. 3B is used as an example below for further description. The target eNB is an implementation of the above target access network device, the source eNB is an implementation of the above source access network device, the MME is an implementation of the above mobility management entity, and the HSS is an implementation of the above home subscriber server. In addition, it is assumed that the target eNB is an upgraded eNB (specifically, an eNB that supports on-demand user plane security protection), and the source eNB is a non-upgraded eNB (specifically, an eNB that does not support on-demand user plane security protection). The above devices perform the following steps:
[0171] Step 301: A source eNB sends a handover request to a target eNB. In response, the target eNB receives a handover request from the source eNB.
[0172] Handover request is the implementation of message 001 in a handover scenario.
[0173] The handover request carries indication information 011 and does not carry a user plane security policy. The indication information 011 indicates whether the UE supports on-demand user plane security protection. Specifically, the indication information 011 indicates whether the UE supports user plane ciphering protection and / or user plane integrity protection. The UE is a UE that is handed over from a source eNB to a target eNB. In addition, the indication information 011 is carried in UE EPS security capabilities and is indicated by a reserved bit, such as EEA7 or EIA7, in the UE EPS security capabilities. Specifically, for the description of the indication information 011, please refer to the description in step 201. The details will not be described again here.
[0174] Step 302: The target eNB determines a user plane security activation status, where the user plane security activation status indicates whether user plane ciphering protection and / or user plane integrity protection is enabled.
[0175] The user plane security activation state includes an encryption activation state and / or an integrity activation state, where the encryption activation state indicates whether user plane encryption protection is enabled or not, and the integrity activation state indicates whether user plane integrity protection is enabled or not.
[0176] Furthermore, the user plane security activation status is data radio bearer (DRB) granularity. Usually, one UE corresponds to one or more E-RABs, and one E-RAB may be mapped to one or more DRBs. Therefore, the target eNB needs to determine whether to enable user plane ciphering protection and / or whether to enable user plane integrity protection for each DRB corresponding to the UE.
[0177] Because the handover request received by the target eNB does not carry a user security policy, the target access network device may determine the user plane security activation state for the UE in any one of the following manners.
[0178] Scheme 1: The target eNB may determine the user plane security activation state for the UE in a default manner (which may also be understood as a non-upgraded manner). Specifically, the user plane encryption protection is always enabled, but the user plane integrity protection is not enabled. Specifically, the encryption activation states corresponding to all DRBs of the UE are enabled, and the integrity activation states corresponding to the DRBs are not enabled.
[0179] Method 2: The user plane security policy is pre-configured in the target eNB, and the pre-configured user plane security policy may be a policy applicable to all UEs. If the target eNB determines based on the indication information 011 that the UE supports on-demand user plane security protection, the target eNB determines the user plane security activation state according to the pre-configured user plane security policy.
[0180] Specifically, if the user plane encryption protection policy is "required", the target eNB determines that the encryption activation states corresponding to all DRBs of the UE are enabled. If the user plane encryption protection policy is "preferred", the target eNB determines that the encryption activation states corresponding to all DRBs of the UE may be enabled or not enabled. The target eNB may make the decision according to a local policy (e.g., the operation state of the target eNB, a control policy, or a regulatory requirement). If the user plane encryption protection policy is "not needed", the target eNB determines that the encryption activation states corresponding to all DRBs of the UE are not enabled.
[0181] Correspondingly, if the user plane integrity protection policy is "required", the target eNB determines that the integrity activation states corresponding to all DRBs of the UE are enabled. If the user plane integrity protection policy is "preferred", the target eNB determines that the integrity activation states corresponding to all DRBs of the UE may be enabled or not enabled. The target eNB may make the decision according to a local policy (e.g., the operation state of the target eNB, a control policy, or a regulatory requirement). If the user plane integrity protection policy is "not needed", the target eNB determines that the integrity activation states corresponding to all DRBs of the UE are not enabled.
[0182] Step 303: The target eNB sends a handover request acknowledge to the source eNB. In response, the source eNB receives the handover request acknowledge from the target eNB.
[0183] The handover request response includes a user plane security activation state that needs to be sent to the UE. Specifically, the handover request response includes a radio resource control RRC reconfiguration (RRC connection reconfiguration), and the RRC reconfiguration is established by the target eNB. The user plane security activation state of the UE is included in the RRC reconfiguration. Specifically, the target eNB encapsulates the user plane security activation state into the RRC reconfiguration and sends the RRC reconfiguration to the source eNB by using the handover request response, and then the source eNB forwards the RRC reconfiguration with the user plane security activation state encapsulated to the UE.
[0184] The RRC reconfiguration includes DRB configuration information. The DRB configuration information indicates to the UE whether to enable user plane ciphering protection and / or user plane integrity protection for the DRB. Normally, if a ciphering disabled field is encapsulated in the DRB configuration information, the UE does not enable ciphering protection for the DRB, or if the ciphering disabled field is not encapsulated in the DRB configuration information, the UE enables ciphering protection for the DRB. If an integrity protection field is encapsulated in the DRB configuration information, the UE enables integrity protection for the DRB, and if the integrity protection field is not encapsulated in the DRB configuration information, the UE does not enable integrity protection for the DRB.
[0185] For example, when the target eNB determines that the ciphering activation states corresponding to all DRBs of the UE are enabled and the integrity activation states corresponding to the DRBs are not enabled, the RRC reconfiguration does not include DRB configuration information.
[0186] Step 304: The source eNB sends an RRC reconfiguration to the UE. Correspondingly, the UE receives an RRC reconfiguration from the source eNB.
[0187] Specifically, the source eNB forwards the RRC reconfiguration received from the target eNB to the UE, so that the UE performs RRC reconfiguration based on the content carried in the RRC reconfiguration.
[0188] In an optional implementation, the RRC reconfiguration includes a user plane security activation status indicated by the target eNB to the UE, which may be understood as the RRC reconfiguration including DRB configuration information determined by the target eNB, in which case the target eNB explicitly instructs the UE to skip enabling user plane ciphering protection and / or to enable user plane integrity protection.
[0189] For example, when the DRB configuration information carried in the RRC reconfiguration is a ciphering disabled field and an integrity protection field, this field may be understood as the target eNB explicitly sending the user plane security activation status to the UE.
[0190] In another optional realization manner, the RRC reconfiguration does not include the DRB configuration information, in which case the target eNB implicitly instructs the UE to enable user plane ciphering protection and / or to skip enabling user plane integrity protection, which may be understood as the target eNB implicitly sending the user plane security activation status to the UE.
[0191] For example, when the RRC reconfiguration does not carry a ciphering disabled field or an integrity protection field, this may be understood as the target eNB enabling user plane ciphering protection and implicitly instructing the UE to skip enabling user plane integrity protection.
[0192] Furthermore, there may be other implementations instead. For example, when the DRB configuration information carried in the RRC reconfiguration includes only a ciphering disabled field, this may be understood as the target eNB explicitly instructing the UE to skip enabling user plane ciphering protection and implicitly instructing the UE to skip enabling user plane integrity protection. In another example, when the DRB configuration information carried in the RRC reconfiguration includes only an integrity protection field, this may be understood as the target eNB implicitly instructing the UE to enable user plane ciphering protection and explicitly instructing the UE to enable user plane integrity protection.
[0193] It should be understood that other configuration information, such as a DRB ID, that needs to be transmitted to the UE may also be carried in step 303 and step 304. In this embodiment, examples are not described one by one.
[0194] Step 305: The UE sends an RRC reconfiguration complete to the target eNB. Correspondingly, the target eNB receives an RRC reconfiguration complete from the UE.
[0195] The RRC reconfiguration complete message indicates to the target eNB that the UE has completed the RRC reconfiguration and has been successfully handed over from the source eNB to the target eNB. The UE may then perform signaling interaction directly with the target eNB.
[0196] Step 306: The target eNB determines whether the UE supports on-demand user plane security protection.
[0197] It should be noted that there is no chronological order between steps 302-305 and step 306, and step 306 may be performed after step 301. Specifically, after receiving a handover request from the source eNB, the target eNB may determine the user plane security activation status of the UE based on the content of the handover request, and the target eNB also determines whether the UE supports on-demand user plane security protection based on the indication information 011 carried in the handover request.
[0198] Specifically, the target eNB determines, based on the indication information 011, whether the UE supports on-demand user security protection.
[0199] Optionally, the target eNB may further determine whether the target eNB supports on-demand user plane security protection. For details, refer to the related description in step 202. The details are not described again here.
[0200] When the target eNB determines that the UE supports on-demand user plane security protection, the target eNB executes steps 307a and 307b in sequence. When the target eNB determines that the UE does not support on-demand user plane security protection, or when the target eNB does not support on-demand user plane security protection, the target eNB executes steps 307c or 307d.
[0201] Step 307a: The target eNB obtains the user plane security policy 021.
[0202] Specifically, the target eNB may obtain the user plane security policy 021 in several ways:
[0203] Manner 1: When the target eNB does not receive a user plane security policy from the source eNB, the user plane security policy 021 may be the user plane security policy 021-1 established by the target access network device, which may also be understood as the target eNB establishing the user plane security policy 021-1.
[0204] In this realization manner, since the target eNB does not receive a user plane security policy from the source eNB, the target eNB may enable on-demand user plane security protection for the UE in a default manner (which may be understood as a non-upgraded manner). Specifically, the user plane encryption protection is enabled, but the user plane integrity protection is not enabled. The user plane security policy 021-1 established by the target eNB needs to match the current user plane security activation state of the UE, for example, a state in which the user plane encryption protection is enabled and the user plane integrity protection is not enabled. For example, the user plane security policy 021-1 established by the target eNB is a policy that matches the user plane security activation state in which the user plane encryption protection is enabled and the user plane integrity protection is not enabled. Specifically, the user plane security policy 021-1 includes a user plane encryption protection policy and a user plane integrity protection policy, where the user plane encryption protection policy indicates that activation is required or preferred, and the user plane integrity protection policy indicates that activation is not needed or preferred.
[0205] For example, when the user plane security policy is expressed as {user plane encryption protection policy, user plane integrity protection policy}, the user plane security policy 021-1 may be specifically realized in any one of the following manners: {activation required, activation not needed}, {activation required, activation preferred}, {activation preferred, activation not needed}, or {activation preferred, activation preferred}.
[0206] In addition, the user plane security policy 021-1 is a security policy at E-RAB granularity. Specifically, the target eNB obtains an E-RAB identifier, and in the subsequent process, sends the E-RAB identifier together with the user plane security policy 021 to the MME. For details, please refer to the relevant description of step 203a and step 203b. The details will not be described again here.
[0207] Manner 2: When the target eNB does not receive a user plane security policy from the source eNB, the user plane security policy 021 may be a user plane security policy 021-2 preconfigured in the target access network device, which may be understood as the target eNB determining the user plane security policy 021-2 according to the preconfigured security policy.
[0208] In this realization, a user plane security policy is pre-configured in the target eNB, and the pre-configured user plane security policy may be a policy applicable to all UEs. The pre-configured user plane security policy may include an encryption protection policy and / or an integrity protection policy. The encryption protection policy may be one of the following: required to be enabled, preferred to be enabled, or not needed to be enabled. The integrity protection policy may also be one of the following: required to be enabled, preferred to be enabled, or not needed to be enabled.
[0209] For example, when the user plane security policy is expressed as {user plane encryption protection policy, user plane integrity protection policy}, the user plane security policy 021-2 may be specifically realized in any one of the following manners: {enabled, enabled}, {enabled, enabled preferred}, {enabled, enabled not needed}, {enabled, enabled preferred}, {enabled, enabled preferred}, {enabled, enabled preferred}, {enabled, enabled not needed}, {enabled, enabled not needed}, {enabled, enabled not needed}, {enabled, enabled not needed}, {enabled, enabled preferred}, or {enabled, enabled not needed}.
[0210] For details, please refer to the related descriptions in step 203a and step 203b, and the details will not be described again here.
[0211] Step 307b: The target eNB sends a path switch request 031 to the MME, carrying the user plane security policy 021. In response, the MME receives the path switch request 031, carrying the user plane security policy 021, from the target eNB.
[0212] The user plane security policy 021 may be a user security policy determined in any one of the implementation methods in step 307a. For example, the user plane security policy 021 may be a user plane security policy 021-1 or a user plane security policy 021-2.
[0213] For details, please refer to the related description in step 203b, and the details will not be described again here.
[0214] Step 307c: The target eNB sends a path switch request 032 that does not carry a user plane security policy to the MME. In response, the MME receives a path switch request 032 that does not carry a user plane security policy from the target eNB.
[0215] The path switching request 032 does not carry the indication information 011 .
[0216] Step 307d: The target eNB sends a path switch request 033 that does not carry a user plane security policy to the MME. In response, the MME receives a path switch request 033 that does not carry a user plane security policy from the target eNB.
[0217] The path switch request 033 carries indication information 011. The indication information 011 may be indication information 011 obtained by the target eNB from the source eNB.
[0218] Step 308: The MME determines whether the path switch request carries a user plane security policy.
[0219] The path switching request may be any one of a path switching request 031 , a path switching request 032 and a path switching request 033 .
[0220] In an optional implementation manner, if the path switch request does not carry a user plane security policy, for example, if the path switch request is path switch request 032, the MME executes step 309a; alternatively, if the path switch request carries a user plane security policy, for example, if the path switch request is path switch request 031, the MME executes step 309b.
[0221] In another optional realization manner, if the path switch request does not carry a user plane security policy but the switch request that does not carry a user plane security policy carries an indication information 011, i.e., when the MME receives the path switch request 033, the MME further compares the indication information 011 with the indication information 012 on the MME. If the indication information 012 on the MME indicates that the UE supports on-demand user plane security protection, the MME sends a path switch response 043 (not shown in the drawing) carrying the indication information 012 and the user plane security policy 023 to the target eNB. If the indication information 011 matches the indication information 012 on the MME, the MME sends a path switch response 045 (not shown in the drawing) that does not carry a user plane security policy or indication information to the target eNB. In this realization manner, if the source eNB is malicious, the source eNB may maliciously tamper with the indication information 011 to make the indication information 011 indicate that the UE does not support on-demand user plane security protection. As a result, the target eNB cannot send the user plane security policy to the MME and cannot activate on-demand user plane security protection for the UE, which causes a degradation attack. Therefore, after determining not to send the user plane security policy to the mobility management device, the target eNB may further send the indication information 011 so that the MME can determine whether the indication information 011 has been tampered with. After determining that the indication information 011 has been tampered with, the MME sends the user plane security policy to the target eNB, which can avoid the degradation attack.
[0222] The indication information 012 comes from the UE and may be provided by the UE to the MME when the UE first attaches to the network.
[0223] In addition, the target eNB further stores the user plane security policy 023 in the UE context. It should be understood that if a user plane security policy (e.g., user plane security policy 023') is stored in the UE context, the target eNB updates the user plane security policy 023' stored in the UE context by using the user plane security policy 023. If a user plane security policy is not stored in the UE context, the target eNB directly stores the user plane security policy 023.
[0224] Step 309a: The MME sends a path switch request acknowledge 042 that does not carry a user plane security policy to the target eNB. In response, the target eNB receives the path switch response 042 that does not carry a user plane security policy from the MME.
[0225] In the prior art, after the MME receives a path switch request that does not carry a user plane security policy, the MME sends the user plane security policy to the target eNB to enable user plane integrity protection between the eNB and the UE in the 4G network. In this case, the target eNB and the UE may not be able to use the user plane security policy. However, in this embodiment, when the indication information 011 indicates that the UE supports on-demand user plane security protection, the target eNB sends the built or preconfigured user plane security policy 021 to the MME. Therefore, it can be seen that if the indication information 011 indicates that the UE does not support on-demand user plane security protection, the target eNB does not send the user plane security policy to the MME, and correspondingly, the MME cannot receive the user plane security policy from the target eNB. In this case, it can be inferred that the UE does not support on-demand user plane security protection, and even if the user plane security policy is provided to the target eNB, the target eNB cannot enable user plane integrity protection for the UE by using the user plane security policy. Therefore, when the MME receives a path switch request that does not carry a user plane security policy, the MME is configured to send a path switch response that does not carry a user plane security policy to the target eNB, i.e., not provide the target eNB with a user plane security policy, thereby reducing the probability that the target eNB receives an information element that cannot be used, and reducing the complexity of data transmission between the target eNB and the MME.
[0226] Step 309b: The MME determines whether the user plane security policy 021 is consistent with the user plane security policy on the MME.
[0227] If the user plane security policy 021 does not match the user plane security policy on the MME, the MME executes step 310. If the user plane security policy 021 matches the user plane security policy on the MME, the MME sends a path switch response to the target eNB that does not carry the user plane security policy.
[0228] The user plane security policy 022 may be obtained based on a user plane security policy obtained from a home subscriber server HSS, or may be obtained based on a user plane security policy pre-configured in the mobility management entity.
[0229] For example, during a UE's network access, the UE sends an attach request to the MME, where the attach request carries the UE's identifier, e.g., an international mobile subscriber identity (IMSI). The MME then sends the UE's identifier to the HSS by using an update location request, and the HSS sends an update location request acknowledge to the MME. The update location response carries the UE's subscription data, where the subscription data may include the above-mentioned user plane security policy.
[0230] In an optional implementation manner, if the path switch request 031 in step 307b carries a user plane security policy 021, and the user plane security policy 021 is a security policy at UE granularity, the MME compares the user plane security policy 021 with the user plane security policy at UE granularity on the MME. In this case, if the user plane security policy 021 matches the user security policy at UE granularity on the MME, the MME sends a path switch response to the target eNB that does not carry the user plane security policy. If the user plane security policy 021 does not match the user security policy at UE granularity on the MME, the MME executes step 310.
[0231] In another optional realization manner, if the path switch request 031 in step 307b carries one or more user plane security policies 021, and each user plane security policy 021 is a policy at E-RAB granularity, the MME performs a comparison for the user plane security policy corresponding to each E-RAB. If the user plane security policy 021 corresponding to each E-RAB matches the user security policy corresponding to the corresponding E-RAB on the MME, the MME sends a path switch response to the target eNB that does not carry a user plane security policy. If the user plane security policy 021 corresponding to at least one E-RAB does not match the user security policy corresponding to the corresponding E-RAB on the MME, the MME executes step 310.
[0232] For example, assume that the path switching request 031 in step 307b carries three user plane security policies 021, e.g., user plane security policy 021a, user plane security policy 021b and user plane security policy 021c, where user plane security policy 021a corresponds to E-RAB1, user plane security policy 021b corresponds to E-RAB2 and user plane security policy 021c corresponds to E-RAB3. If the user plane security policies stored in the MME are user plane security policy 021d corresponding to E-RAB1, user plane security policy 021b corresponding to E-RAB2, and user plane security policy 021c corresponding to E-RAB3, then since the user plane security policy 021a corresponding to E-RAB1 and carried in the path switch request does not match the user plane security policy 021d corresponding to E-RAB1 and stored in the MME, the MME returns a path switch response to the target eNB carrying the user plane security policy 021d, and the path switch response further carries an identifier of E-RAB1.
[0233] Step 310: The MME sends a path switch response 041 to the target eNB, carrying the user plane security policy 022. In response, the target eNB receives the path switch response 041, carrying the user plane security policy 022, from the MME.
[0234] Optionally, if the path switch request 033 received by the MME in step 307d does not carry a user plane security policy, but the path switch request 033 not carrying a user plane security policy carries indication information 011 and the indication information 012 indicates that the UE supports on-demand user plane security protection, the MME sends a path switch response 043 carrying the indication information 012 and the user plane security policy 023 to the target eNB.
[0235] Step 311: The target eNB stores the user plane security policy 022 in the context of the UE.
[0236] It should be understood that if a user plane security policy (e.g., user plane security policy 021) is stored in the UE context, the target eNB updates the user plane security policy 021 stored in the UE context by using the user plane security policy 022. If a user plane security policy is not stored in the UE context, the target eNB directly stores the user plane security policy 022.
[0237] Step 312: When the UE's current user plane security activation status does not match the user plane security policy 022, the target eNB activates or skips activating user plane encryption protection and / or user plane integrity protection for the UE according to the user plane security policy 022.
[0238] The user plane security policy 022 includes a user plane encryption protection policy and a user plane integrity protection policy.
[0239] The following conditions are met: The user plane security activation state of the UE indicates that encryption protection is not enabled and the user plane encryption protection policy indicates that activation is required, or The user plane security activation state of the UE indicates that encryption protection is enabled and the user plane encryption protection policy indicates that activation is not needed, or The user plane security activation state of the UE indicates that integrity protection is not enabled and the user plane integrity protection policy indicates that activation is required, or The UE's user plane security activation state indicates that integrity protection is enabled and the user plane integrity protection policy indicates that activation is not needed. When any one of the above is met, the current user plane security activation state of the UE does not match the user plane security policy 022.
[0240] Specifically, the process of enabling or disabling the encryption protection state and / or integrity protection state of the UE by the target eNB according to the user plane security policy 022 may be as follows:
[0241] When the user plane encryption protection policy indicates that activation is required and encryption protection is not activated for the UE, the target eNB instructs the UE to activate user plane encryption protection.
[0242] When the user plane encryption protection policy indicates that activation is not needed and encryption protection is activated for the UE, the target eNB instructs the UE to disable user plane protection.
[0243] When the user plane integrity protection policy indicates that activation is required and integrity protection is not enabled for the UE, the target eNB instructs the UE to enable user plane integrity protection.
[0244] When the user plane integrity protection policy indicates that activation is not needed and integrity protection is enabled for the UE, the target eNB instructs the UE to disable user plane protection.
[0245] It should be understood that the target eNB may adjust the user plane security activation state of the UE based on the state of the target eNB in the following two cases:
[0246] When the user plane encryption protection policy indicates that activation is preferred and encryption protection is not activated for the UE, the target eNB instructs the UE to activate user plane encryption protection or to skip activating user plane encryption protection.
[0247] When the user plane integrity protection policy indicates that activation is preferred and integrity protection is not enabled for the UE, the target eNB instructs the UE to either activate user plane integrity protection or to skip enabling user plane integrity protection.
[0248] In this embodiment, the target eNB can determine whether the UE supports on-demand user plane security protection based on the indication information 011, and the target eNB sends the user plane security policy to the MME only when the UE supports on-demand user plane security protection. This avoids the following case: When the UE does not support on-demand user plane security protection and the MME does not receive the user plane security policy from the target eNB, the MME sends the user plane security policy to the target eNB, so that even if the target eNB receives the user plane security policy, the target eNB cannot enable on-demand user plane security protection for the UE. Therefore, this helps to reduce the probability that the MME sends information elements that are not required by the eNB to the target eNB, and thus helps to reduce the transmission complexity.
[0249] 4 illustrates another implementation of the security policy processing method provided in this application. The access network device and the mobility management entity perform the following steps:
[0250] Step 401: The mobility management entity obtains the indication information 013.
[0251] The mobility management entity may obtain the indication information 013 in the following several implementation manners.
[0252] In a possible implementation manner, the mobility management entity obtains the indication information 013 from the terminal device through an attach process. For example, during the network access of the terminal device, the terminal device sends an attach request to the mobility management entity, and the attach request carries the indication information 013.
[0253] In another possible implementation manner, the mobility management entity obtains the indication information 013 from the terminal device through a tracking area update process. For example, the terminal device sends a tracking area update request to the mobility management entity, and the tracking area update request carries the indication information 013.
[0254] In another possible implementation manner, the mobility management entity obtains the indication information 013 from the terminal device through a packet data network connection establishment process. For example, the terminal device sends a packet data network connection request (PDN connectivity request) to the mobility management entity, and the packet data network connection request carries the indication information 013. Alternatively, after obtaining the indication information 013 from the terminal device through an attach process or a tracking area update process, the mobility management entity stores the indication information 013 in the context of the terminal device. After obtaining the context of the terminal device based on an identifier of the terminal device (e.g., eNB UE S1AP ID or MME UE S1AP ID) in the S1 message carrying the packet data network connection request, the mobility management entity obtains the indication information 013 stored in the context of the terminal device.
[0255] In another possible implementation manner, the mobility management entity obtains the indication information 013 from the target access network device through a path switch request. For example, when the access network device for the terminal device changes, specifically when the terminal device is handed over from the source access network device to the target access network device in a handover, resumption or re-establishment scenario, etc., the target access network device sends a path switch request to the mobility management entity, and the path switch request carries the indication information 013. Alternatively, after obtaining the indication information 013 from the terminal device through an attach process, a tracking area update process or a packet data network connection establishment process, the mobility management entity stores the indication information 013 in the context of the terminal device. After obtaining the context of the terminal device based on the identifier of the terminal device (e.g., eNB UE S1AP ID or MME UE S1AP ID) in the path switch request, the mobility management entity obtains the indication information 013 stored in the context of the terminal device.
[0256] In this embodiment, the indication information 013 may be obtained by the mobility management entity in any one of the above implementation manners, which is not specifically limited here.
[0257] The indication information 013 indicates whether the terminal device supports on-demand user plane security protection. Alternatively, the indication information 013 further indicates whether the terminal device supports on-demand user plane security protection between the terminal device and the access network device. Whether the terminal device supports on-demand user plane security protection may be understood as whether the terminal device supports enabling user plane encryption protection and / or whether the terminal device supports enabling user plane integrity protection, that is, the user plane encryption protection and / or the user plane integrity protection for the terminal device is not fixed. Whether the terminal device supports on-demand user plane security protection between the terminal device and the access network device may be understood as whether the terminal device supports enabling / disabling user plane encryption protection and / or user plane integrity protection under the instruction by the access network device. The access network device here may be an eNB, for example, a source eNB or a target eNB referred to in the following description. It should be understood that multiple expressions of the indication information 013 are interchangeable. In the following embodiments, the expression "the indication information 013 indicates whether the terminal device supports on-demand user plane security protection" is used as an example for explanation.
[0258] Specifically, the indication information 013 may be represented by a part of the bits of the evolved packet system security capability of the terminal device, where the evolved packet system security capability of the terminal device indicates at least one security algorithm supported by the terminal device. For example, the evolved packet system security capability of the terminal device is UE evolved packet system security capabilities, and the indication information 013 may be indicated by a reserved bit, for example, EEA7 or EIA7, in the UE security capability. EEA7 represents a bit reserved for the eighth encryption algorithm in the UE evolved packet system security capability, and EIA7 represents a bit reserved for the eighth integrity algorithm in the UE evolved packet system security capability. In this embodiment, the bit is used to carry an indication indicating whether the terminal device supports on-demand user plane security protection.
[0259] It should be noted that the indication information 013 in this implementation manner and the indication information 011 in the above implementation manner may be the same indication information or different indication information, but both the indication information 011 and the indication information 013 indicate whether the terminal device supports on-demand user plane security protection.
[0260] Regardless of whether the access network device is upgraded or not (specifically, whether the access network device supports on-demand user plane security protection or not), the access network device can identify and forward the evolved packet system security capability of the terminal device (e.g., UE evolved packet system security capability). Similarly, regardless of whether the terminal device is upgraded or not (specifically, whether the terminal device supports on-demand user plane security protection or not), the terminal device can transmit the evolved packet system security capability of the terminal device (e.g., UE evolved packet system security capability). Therefore, adding the indication information 013 to the evolved packet system security capability of the terminal device can ensure that the indication information 013 is not lost during transmission. However, in the prior art, the redefined indication information indicates whether the terminal device supports on-demand user security protection or not, and the redefined indication information cannot be identified by a non-upgraded access network device (or a non-upgraded terminal device). Specifically, an access network device that does not support on-demand user plane security protection cannot identify the redefined indication information. If an access network device that does not support on-demand user plane security protection receives the redefined indication information, the access network device that does not support on-demand user plane security protection discards the redefined indication information and cannot transmit the redefined indication information to a mobility management entity, etc. Similarly, a terminal device that does not support on-demand user plane security protection cannot identify the redefined indication information. If an access network device that does not support on-demand user plane security protection receives the redefined indication information, the access network device that does not support on-demand user plane security protection discards the redefined indication information and cannot transmit the redefined indication information to a mobility management entity, etc.
[0261] Step 402: The mobility management entity determines, based on the indication information 013, whether to send a user plane security policy 024 to the access network device serving the terminal device.
[0262] In an optional implementation manner, the indication information 013 is carried in the path switch request 034, and the access network device serving the terminal device is the target access network device. In this case, the mobility management entity determines whether to send the user plane security policy 024 to the access network device serving the terminal device based on the indication information 013, specifically may be as follows: When the indication information 013 indicates that the terminal device supports on-demand user plane security protection and the path switch request 034 does not carry a user plane security policy, the mobility management entity sends a path switch response 044 carrying the user plane security policy 024 to the target access network device.
[0263] In another optional realization manner, the indication information 013 is carried in a non-access stratum (NAS) message, and the non-access stratum message includes an attach request, an update location request, etc. The access network device serving the terminal device is a source access network device. In this case, the mobility management entity determines whether to send a user plane security policy 024 to the access network device serving the terminal device based on the indication information 013, specifically as follows: When the indication information 013 indicates that the terminal device supports on-demand user plane security protection, the mobility management entity sends the user plane security policy 024 to the source access network device.
[0264] In another optional realization manner, after obtaining the indication information 013 from the terminal device through the attach process or the tracking area update process, the mobility management entity stores the indication information 013 in the context of the terminal device. After obtaining the context of the terminal device based on the identifier of the terminal device (e.g., eNB UE S1AP ID or MME UE S1AP ID) in the S1 message carrying the packet data network connection request, the mobility management entity obtains the indication information 013 stored in the context of the terminal device. In this case, the access network device serving the terminal device is the source access network device. In this case, the mobility management entity determines whether to send the user plane security policy 024 to the access network device serving the terminal device based on the indication information 013 may be specifically as follows: When the indication information 013 stored in the MME indicates that the terminal device supports on-demand user plane security protection, the mobility management entity sends the user plane security policy 024 to the source access network device.
[0265] It should be noted that in some of the above implementations, the user plane security policy 024 sent by the mobility management entity to the access network device may come from the Home Subscriber Server HSS or may be pre-configured in the mobility management entity.
[0266] Specifically, after obtaining the indication information 013 and before sending the user plane security policy 024 to the access network device, the mobility management entity receives subscription data of the terminal device from a home subscriber server. The subscription data is data stored in the home subscriber server during subscription of the terminal device, and the subscription data may include a user plane security policy for the terminal device. It should be understood that the user plane security policy may be determined during subscription. Specifically, during subscription, the terminal device subscribes to a service that requires on-demand user plane security protection. Alternatively, the subscription data may not include a user plane security policy. This may be understood as the terminal device not subscribing to a service that requires on-demand user plane security protection during subscription.
[0267] In a possible implementation, if the subscription data includes the user plane security policy 024 and the indication information 013 indicates that the terminal device supports on-demand user plane security protection, the mobility management entity stores the user plane security policy 024. In this case, the user plane security policy sent by the mobility management entity to an access network device (source access network device or target access network device) in step 402 may be the user plane security policy 024 that reaches the home subscriber server and is stored by the mobility management entity in the mobility management entity.
[0268] In another possible implementation manner, the user plane security policy is pre-configured in the mobility management entity, and the subscription data does not include the user plane security policy, but the indication information 013 indicates that the terminal device supports on-demand user plane security protection. In this case, the mobility management entity uses the pre-configured user plane security policy as the user plane security policy 024 and stores the user plane security policy 024 in the context of the terminal device. In this case, the user plane security policy sent by the mobility management entity to the access network device (source access network device or target access network device) in step 402 may be the user plane security policy 024 configured by the mobility management entity and stored by the mobility management entity in the mobility management entity.
[0269] Optionally, the user plane security policy obtained by the mobility management entity from the HSS or pre-configured in the mobility management entity is at access point name (APN) granularity. After mapping the user plane security policy at APN granularity to the user plane security policy at E-RAB granularity, the mobility management entity obtains the user plane security policy 024 at E-RAB granularity. In this case, the user plane security policy sent by the mobility management entity to the access network device (source access network device or target access network device) in step 402 is one or more user plane security policies 024, each user plane security policy 024 corresponding to one E-RAB, i.e., each user plane security policy 024 is a security policy at E-RAB granularity. Specifically, the mobility management entity sends the user plane security policy 024 to the access network device (source access network device or target access network device) together with an identifier of the E-RAB corresponding to the user plane security policy 024.
[0270] In this embodiment, the mobility management entity can determine whether the terminal device supports on-demand user plane security protection based on the indication information 013, and further determines whether to send a user plane security policy to the access network device serving the terminal device when the terminal device supports on-demand user plane security protection. Therefore, this also helps to reduce the probability that the mobility management entity sends information elements that are not needed by the access network device to the access network device, and thus helps to reduce the complexity of transmission.
[0271] 5 illustrates another implementation of the security policy processing method provided in this application. The access network device and the mobility management entity perform the following steps:
[0272] Step 501: The mobility management entity obtains the indication information 013.
[0273] The indication information 013 indicates whether the terminal device supports on-demand user plane security protection. Specifically, the indication information 013 indicates whether the terminal device supports user plane encryption protection and / or user plane integrity protection. The indication information 013 is represented by a part of the bits of the evolved packet system security capability of the terminal device, and the evolved packet system security capability of the terminal device indicates at least one security algorithm supported by the terminal device.
[0274] In this embodiment, step 501 is similar to step 401. For details, please refer to the related description in step 401.
[0275] Step 502 : The mobility management entity obtains the indication information 051 .
[0276] The indication information 051 indicates whether the access network device serving the terminal device supports on-demand user plane security protection. Alternatively, the indication information 051 further indicates whether the access network device supports on-demand user plane security protection between the access network device and the terminal device. Whether the access network device supports on-demand user plane security protection may be understood as whether the access network device supports enabling user plane encryption protection and / or whether the access network device supports enabling user plane integrity protection, that is, the user plane encryption protection and / or the user plane integrity protection for the access network device is not fixed. Whether the access network device supports on-demand user plane security protection between the access network device and the terminal device may be understood as whether the access network device can instruct the terminal device to enable / skip enabling user plane encryption protection and / or user plane integrity protection. It should be understood that multiple expressions of the indication information 051 are interchangeable. In the following embodiments, the expression "the indication information 051 indicates whether the access network device supports on-demand user plane security protection" is used as an example for explanation.
[0277] Specifically, the mobility management entity may obtain the indication information 051 in multiple manners, specifically including several of the following implementation manners:
[0278] In an optional implementation manner, the indication information 051 is the indication information 051-1 received by the mobility management entity from the access network device. This may also be understood as the mobility management entity receiving the indication information 051-1 from the access network device. For example, if the access network device is a target access network device, the target access network device may add the indication information 051-1 to the path switch request sent to the mobility management entity. Obviously, the access network device may alternatively send the indication information 051-1 to the mobility management entity by using other signaling between the access network device and the mobility management entity. This is not specifically limited in this application.
[0279] In another optional realization manner, the indication information 051 is indication information 051-2 obtained by the mobility management entity from a network management device. This may be understood as the mobility management entity obtaining the indication information 051-2 from the network management device. The network management device is a device capable of managing relevant information of an access network device. For example, the network management device may be an operation administration and maintenance (OAM) network element.
[0280] It should be noted that there is no chronological order between step 501 and step 502. Specifically, the mobility management entity may first obtain the indication information 013 and then obtain the indication information 051, the mobility management entity may first obtain the indication information 051 and then obtain the indication information 013, or the mobility management entity may simultaneously obtain the indication information 013 and the indication information 051. This is not specifically limited here.
[0281] Step 503: The mobility management entity determines whether to send the user plane security policy 024 to the access network device serving the terminal device according to the indication information 013 and the indication information 051.
[0282] Specifically, when the indication information 013 indicates that the terminal device supports on-demand user plane security protection and the indication information 051 indicates that the access network device serving the terminal device supports on-demand user plane security protection, the mobility management entity sends the user plane security policy 024 for the terminal device to the access network device. That is, when the mobility management entity determines that both the access network device and the terminal device support on-demand user plane security protection, the mobility management entity sends the user plane security policy 024 to the access network device regardless of whether the mobility management entity receives the user plane security policy. In this case, the user plane security policy 024 sent by the mobility management entity to the access network device can be identified by the access network device. Furthermore, the access network device can determine whether to enable user plane encryption protection and / or user plane integrity protection for the terminal device according to the user plane security policy 024. Therefore, in this case, the mobility management entity sending the user plane security policy 024 to the access network device does not cause waste of information elements.
[0283] Specifically, after obtaining the indication information 051 and before sending the user plane security policy 024 to the access network device, the mobility management entity receives subscription data of the terminal device from a home subscriber server. The subscription data may be determined during subscription. For details regarding the description of the subscription data, please refer to the description in step 402. The details will not be described again here.
[0284] In a possible implementation, the subscription data includes the user plane security policy 024, the indication information 013 indicates that the terminal device supports on-demand user plane security protection, and the indication information 051 indicates that the access network device supports on-demand user plane security protection. In this case, the mobility management entity stores the user plane security policy 024. In this case, the user plane security policy sent by the mobility management entity to the access network device (source access network device or target access network device) in step 503 may be the user plane security policy 024 that reaches the home subscriber server and is stored in the mobility management entity by the mobility management entity.
[0285] In another possible implementation manner, the user plane security policy is pre-configured in the mobility management entity, the subscription data does not include the user plane security policy, but the indication information 013 indicates that the terminal device supports on-demand user plane security protection, and the indication information 015 indicates that the access network device supports on-demand user plane security protection. In this case, the mobility management entity uses the pre-configured user plane security policy as the user plane security policy 024 and stores the user plane security policy 024 in the context of the terminal device. In this case, the user plane security policy sent by the mobility management entity to the access network device (source access network device or target access network device) in step 503 may be the user plane security policy 024 configured by the mobility management entity and stored by the mobility management entity in the mobility management entity.
[0286] Optionally, the user plane security policy obtained by the mobility management entity from the HSS or pre-configured in the mobility management entity is at access point name (APN) granularity. After mapping the user plane security policy at APN granularity to the user plane security policy at E-RAB granularity, the mobility management entity obtains the user plane security policy 024 at E-RAB granularity. In this case, the user plane security policy sent by the mobility management entity to the access network device (source access network device or target access network device) in step 402 is one or more user plane security policies 024, each user plane security policy 024 corresponding to one E-RAB, i.e., each user plane security policy 024 is a security policy at E-RAB granularity. Specifically, the mobility management entity sends the user plane security policy 024 to the access network device (source access network device or target access network device) together with an identifier of the E-RAB corresponding to the user plane security policy 024.
[0287] In this embodiment, the mobility management entity can determine whether the terminal device supports on-demand user plane security protection based on the indication information 013, and can determine whether the access network device supports on-demand user plane security protection based on the indication information 051. The mobility management entity sends the user plane security policy 024 to the access network device only when both the terminal device and the access network device support on-demand user plane security protection, to ensure that the access network device can enable user plane encryption protection and / or user plane integrity protection for the terminal device by using the user plane security policy 024. Therefore, the mobility management entity can be prevented from sending the user plane security policy to an access network device that does not support on-demand user plane security protection. This helps to reduce the probability that the mobility management entity sends information elements that are not needed by the access network device to the access network device, and thus helps to reduce the complexity of transmission.
[0288] The security policy processing method described in the embodiment corresponding to FIG. 4 or FIG. 5 may be applied to any one of the following processes, namely, Handover, RRC Connection Resume, and RRC Connection Reestablishment. The RRC Connection Resume process shown in FIG. 6A and FIG. 6B is used as an example below for further description. The target eNB is an implementation of the above target access network device, the source eNB is an implementation of the above source access network device, the MME is an implementation of the above mobility management entity, and the HSS is an implementation of the above home subscriber server. In addition, it is assumed that the target eNB is an upgraded eNB (specifically, an eNB that supports on-demand user plane security protection), and the source eNB is a non-upgraded eNB (specifically, an eNB that does not support on-demand user plane security protection). The above devices perform the following steps:
[0289] Step 601: The UE sends an RRC connection resume request to a target eNB. In response, the target eNB receives an RRC connection resume request from the UE.
[0290] The RRC connection resume request carries an identifier of the UE (eg, an I-RNTI or a Resume ID), and the RRC connection resume request indicates that the UE needs to resume its connection to the target eNB.
[0291] Step 602: The target eNB sends a context retrieve request to the source eNB. In response, the source eNB receives the context retrieve request from the target eNB.
[0292] The context acquisition request carries an identifier of the UE, and the context acquisition request is used to acquire the context of the UE from the source eNB.
[0293] Step 603: The source eNB sends a context retrieve response to the target eNB. In response, the target eNB receives a context retrieve response from the source eNB.
[0294] The context acquisition response carries the indication information 013 and does not carry a user plane security policy. The indication information 013 indicates whether the UE supports on-demand user plane security protection. Alternatively, the indication information 013 further indicates whether the UE supports on-demand user plane security protection between the UE and the eNB. Whether the UE supports on-demand user plane security protection may be understood as whether the UE supports enabling user plane encryption protection and / or whether the UE supports enabling user plane integrity protection, i.e., the user plane encryption protection and / or the user plane integrity protection for the UE is not fixed. Whether the UE supports on-demand user plane security protection between the UE and the eNB may be understood as whether the UE supports enabling / disabling user plane encryption protection and / or user plane integrity protection under the instruction by the eNB. It should be understood that multiple expressions of the indication information 013 are interchangeable. In the following embodiments, the expression "the indication information 013 indicates whether the UE supports on-demand user plane security protection" is used as an example for explanation.
[0295] In addition, the indication information 013 is carried in the UE EPS security capabilities, and is indicated by a reserved bit, such as EEA7 or EIA7, in the UE security capabilities. EEA7 represents a bit reserved for the eighth encryption algorithm in the UE EPS security capabilities, and EIA7 represents a bit reserved for the eighth integrity algorithm in the UE EPS security capabilities. In this embodiment, the bit is used to carry an indication indicating whether the terminal device supports on-demand user plane security protection. For the description of the indication information 013, please refer to the description in step 201 or step 401. The details will not be described again here.
[0296] Step 604: The target eNB decides to enable user plane encryption protection and skip enabling user plane integrity protection.
[0297] The context acquisition response received by the target eNB does not carry a user security policy. Therefore, the target eNB may enable security protection for the UE in a default manner (which may be understood as a non-upgraded manner). Specifically, the user plane encryption protection is always enabled by using the same algorithm as that used for RRC protection, but the user plane integrity protection is not enabled. Normally, the state in which the user plane encryption protection is enabled and the user plane integrity protection is not enabled, which is determined by the target eNB, may be called a user plane security activation state, and the user plane security activation state is a judgment result of the target eNB on whether to enable the user plane encryption protection and / or the user plane integrity protection for the UE. The target eNB needs to transmit the judgment result to the UE, so that the UE enables the user plane encryption protection and skips enabling the user plane integrity protection based on the user plane security activation state. Thus, the target eNB executes step 605.
[0298] Step 605: The target eNB sends an RRC connection resume to the UE. In response, the UE receives an RRC connection resume from the target eNB.
[0299] The RRC Connection Resume message indicates to the UE that the target eNB agrees to the UE's RRC Connection Resume request. The RRC Connection Resume message carries the user plane security activation state, specifically, user plane ciphering protection is enabled and user plane integrity protection is not enabled.
[0300] The RRC connection resume message includes DRB configuration information. The DRB configuration information indicates to the UE whether to enable ciphering protection and / or integrity protection for the DRB. Normally, if a ciphering disabled field is encapsulated in the DRB configuration information, the UE does not enable ciphering protection for the DRB, or if the ciphering disabled field is not encapsulated in the DRB configuration information, the UE enables ciphering protection for the DRB. If an integrity protection field is encapsulated in the DRB configuration information, the UE enables integrity protection for the DRB, and if the integrity protection field is not encapsulated in the DRB configuration information, the UE does not enable integrity protection for the DRB.
[0301] For example, when the target eNB determines that the ciphering activation state corresponding to all DRBs of the UE is enabled and the integrity activation state corresponding to the DRBs is not enabled, the RRC connection resumption message does not include DRB configuration information.
[0302] In an optional implementation, the RRC connection resume message includes a user plane security activation status indicated by the target eNB to the UE, which may be understood as the RRC connection resume message including DRB configuration information determined by the target eNB, in which case the target eNB explicitly instructs the UE to skip enabling user plane ciphering protection and / or to enable user plane integrity protection.
[0303] For example, when the DRB configuration information carried in the RRC connection resumption message is a ciphering disabled field and an integrity protection field, this field may be understood as the target eNB explicitly sending the user plane security activation status to the UE.
[0304] In another optional implementation manner, the RRC connection resumption message does not include the DRB configuration information, in which case the target eNB implicitly instructs the UE to activate user plane ciphering protection and / or to skip activating user plane integrity protection, which may be understood as the target eNB implicitly sending the user plane security activation status to the UE.
[0305] For example, when the RRC connection resumption message does not carry a ciphering disabled field or an integrity protection field, this may be understood as the target eNB enabling user plane ciphering protection and implicitly instructing the UE to skip enabling user plane integrity protection.
[0306] Furthermore, there may be other implementations as alternatives. For example, when the DRB configuration information carried in the RRC connection resume message includes only a ciphering disabled field, this may be understood as the target eNB explicitly instructing the UE to skip enabling user plane encryption protection and implicitly instructing the UE to skip enabling user plane integrity protection. In another example, when the DRB configuration information carried in the RRC connection resume message includes only an integrity protection field, this may be understood as the target eNB implicitly instructing the UE to enable user plane encryption protection and explicitly instructing the UE to enable user plane integrity protection.
[0307] Step 606: The UE sends an RRC connection resume complete to the target eNB. Correspondingly, the target eNB receives an RRC connection resume complete from the UE.
[0308] After the UE receives the RRC Connection Resume message, the UE enables or disables user plane ciphering protection and / or user plane integrity protection based on the user plane security activation status carried in the RRC Connection Resume message. After the configuration is completed, the UE sends an RRC Connection Resume Complete message to the target eNB. The RRC Connection Resume Complete message indicates that the UE has performed the configuration based on the instruction in the RRC Connection Resume message and completed the RRC Connection Resume process.
[0309] Step 607: The target eNB sends a path switch request 034 that does not carry a user plane security policy to the MME. In response, the MME receives a path switch request 034 that does not carry a user plane security policy from the target eNB.
[0310] Optionally, the path switch request 034 carries indication information 013, which is received by the target eNB from the source eNB in step 603. The target eNB does not receive a user plane security policy from the source eNB. Specifically, the context acquisition response described in step 603 does not carry a user plane security policy. Therefore, the path switch request 034 does not carry a user plane security policy either. Specifically, for a description of the indication information 013, refer to step 401.
[0311] Optionally, the path switch request 034 further includes indication information 051, where the indication information 051 indicates whether the target eNB serving the UE supports on-demand user plane security protection. Specifically, see step 502 for a description of the indication information 051.
[0312] Step 608: The MME determines whether the path switch request carries a user plane security policy.
[0313] If the path switch request does not carry a user plane security policy, for example, if the path switch request is a path switch request 034, the MME executes step 609. If the path switch request carries a user plane security policy, the MME determines whether the user plane security policy on the MME is the same as the user plane security policy carried in the path switch request, and determines whether to add the user plane security policy to the path switch response sent to the target eNB based on the determination result. For details, please refer to the related descriptions in steps 309b to 312 in the embodiment corresponding to Figures 3A and 3B. The details will not be described again here.
[0314] Step 609: The MME determines whether the UE (and the target eNB) supports on-demand user plane security protection.
[0315] Specifically, the MME determines whether the UE (and the target eNB) supports on-demand user plane security protection based on the indication information 013 (and the indication information 051).
[0316] In an optional implementation manner, the MME may only determine whether the UE supports on-demand user plane security protection. Specifically, the MME determines whether the UE supports on-demand user plane security protection based on the indication information 013 received in step 607. In this case, if the UE supports on-demand user plane security protection, the MME performs step 610a; otherwise, if the UE does not support on-demand user plane security protection, the MME performs step 610b.
[0317] In another optional implementation manner, the MME needs to determine whether both the UE and the target eNB support on-demand user plane security protection. Specifically, the MME determines whether the UE supports on-demand user plane security protection based on the indication information 013, and determines whether the target eNB supports on-demand user plane security protection based on the indication information 051. In this case, if the UE and the target eNB support on-demand user plane security protection, the MME executes step 610a; otherwise, if the UE does not support on-demand user plane security protection or the target eNB does not support on-demand user plane security protection, the MME executes step 610b.
[0318] Step 610a: The MME sends a path switch response 044 to the target eNB, carrying the user plane security policy 024. In response, the target eNB receives the path switch response 044, carrying the user plane security policy 024, from the MME.
[0319] Step 610b: The MME sends a path switch response 045 that does not carry a user plane security policy to the target eNB. In response, the target eNB receives a path switch response 045 that does not carry a user plane security policy from the MME.
[0320] In this realization scheme, a decision logic is added on the MME side. Specifically, when the MME decides whether to send the user plane security policy to the eNB, the MME makes the decision based on the indication information 013. However, in the prior art, the MME makes the decision based only on whether the user plane security policy is received from the eNB. If the user plane security policy is not received from the eNB, the MME sends the user plane security policy to the eNB. In the prior art solution, the eNB may not be able to send the user plane security policy to the MME because the UE does not support on-demand user plane security protection. In this case, when the MME sends the user plane security policy to the eNB, the eNB cannot enable user plane integrity protection for the UE by using the user plane security policy. As a result, the efficiency of the signaling transmission between the MME and the eNB is reduced. However, in the solution of this application, the MME sends the user plane security policy to the eNB only when the UE supports on-demand user plane security protection. This therefore helps to reduce the probability that the MME sends information elements to the eNB that are not required by the eNB, and therefore helps to reduce the transmission complexity.
[0321] It should be further understood that after the target eNB receives the user plane security policy 024 from the MME, the target eNB stores the user plane security policy 024 in the context of the UE. Furthermore, when the user plane security activation state indicated by the user plane security policy 024 does not match the current user plane security activation state of the UE, the target eNB activates or deactivates ciphering protection and / or integrity protection for the UE according to the user plane security policy 024. For details, please refer to the related descriptions in step 311 and step 312. The details will not be described again here.
[0322] In addition, the security policy processing method described in the embodiment corresponding to Fig. 4 or Fig. 5 may alternatively be applied to the initial access process. Fig. 7 is used as an example below for further explanation. Source eNB is the realization of the above source access network device, MME is the realization of the above mobility management entity, and HSS is the realization of the above home subscriber server. The above device performs the following steps:
[0323] Step 701: The UE sends an attach request to the MME.
[0324] The attach request carries the indication information 013 and an identifier of the UE. Specifically, the indication information 013 indicates whether the UE supports user plane encryption protection and / or user plane integrity protection. The indication information 013 is represented by a part of the bits of the evolved packet system security capability of the UE, and the evolved packet system security capability of the UE indicates at least one security algorithm supported by the UE. For details, please refer to the related description in step 401.
[0325] Step 702: The MME sends a location update request to the HSS.
[0326] The location update request carries an identifier of the UE. The location update request is used to request subscription data of the UE stored in the HSS. The subscription data may include a user plane security policy for the terminal device. It should be understood that the user plane security policy may be determined during subscription. Specifically, during subscription, the terminal device subscribes to a service that requires on-demand user plane security protection. Alternatively, the subscription data may not include a user plane security policy. This may be understood as the terminal device not subscribing to a service that requires on-demand user plane security protection during subscription.
[0327] Optionally, the user plane security policy on the HSS is APN granular: one user plane security policy corresponds to an identifier of one APN.
[0328] Step 703: The HSS sends a location update response to the MME.
[0329] The location update response carries the subscription data of the UE, and the subscription data includes the user plane security policy 024 for the UE. Obviously, the subscription data further includes other information of the UE, which will not be described in detail here.
[0330] Step 704: The MME determines whether the UE (and the source eNB) supports on-demand user plane security protection.
[0331] It should be understood that there is no chronological order between steps 702-703 and step 704, provided that step 704 is performed after step 701. Specifically, after the MME receives the indication information 013 and the UE's identity carried in the attach request, the MME determines whether the UE supports on-demand user plane security protection based on the indication information 013, and sends a location update request, carrying the UE's identifier, to the HSS to obtain the subscription data of the UE.
[0332] In an optional implementation manner, the MME may only determine whether the UE supports on-demand user plane security protection. Specifically, the MME determines whether the UE supports on-demand user plane security protection according to the indication information 013 received in step 701.
[0333] In this implementation, when the UE supports on-demand user plane security protection, the MME sequentially performs step 705a and step 705b; or when the UE does not support on-demand user plane security protection, the MME performs step 705c.
[0334] In another optional realization manner, the MME needs to determine whether both the UE and the target eNB support on-demand user plane security protection. Specifically, the MME determines whether the UE supports on-demand user plane security protection based on the indication information 013, and determines whether the target eNB supports on-demand user plane security protection based on the indication information 051. The indication information 051 may be obtained by the MME through signaling interaction with the source eNB, or may be obtained by the MME from a network management device, which is not specifically limited here.
[0335] In this implementation, when both the UE and the source eNB support on-demand user plane security protection, the MME sequentially performs step 705a and step 705b; alternatively, the MME only performs step 705a, and when the UE does not support on-demand user plane security protection or the source eNB does not support on-demand user plane security protection, the MME performs step 705c.
[0336] Step 705a: The MME sends an S1 message carrying the user plane security policy 024 to the source eNB.
[0337] The S1 message carries the indication information 013 and a user plane security policy for the UE 024. The S1 message may be an initial context setup request message.
[0338] Optionally, the MME obtains a user plane security policy at APN granularity from the HSS, and after mapping the user plane security policy at APN granularity to a user plane security policy 024 at E-RAB granularity, the MME obtains one or more user plane security policies 024 at E-RAB granularity.
[0339] In this case, the user plane security policy sent by the MME to the source eNB in step 705a is one or more user plane security policies 024, each corresponding to one E-RAB, i.e. each user plane security policy 024 is a security policy at E-RAB granularity. Specifically, the MME sends the user plane security policy 024 to the source eNB together with an identifier of the E-RAB that corresponds to the user plane security policy 024.
[0340] Step 705b: The MME stores the user plane security policy 024 for the UE.
[0341] In this embodiment, step 705b is an optional step.
[0342] When the MME performs step 705b, there is no chronological order between steps 705a and 705b. Specifically, the MME may perform step 705a before step 705b, or the MME may perform step 705b before step 705a, or the MME may perform steps 705a and 705b simultaneously.
[0343] Step 705c: The MME sends an S1 message that does not carry a user plane security policy to the source eNB.
[0344] Step 706: The MME sends an attach accept to the UE.
[0345] The Attach Accept message indicates to the UE that the attach process has been completed.
[0346] In this realization, a decision logic is added on the MME side. Specifically, when the MME decides whether to send the user plane security policy to the source eNB, the MME makes the decision based on the indication information 013 (and the indication information 051). However, in the prior art, the MME makes the decision based only on whether the user plane security policy is obtained from the HSS through a query. If the location update response returned by the HSS carries the user plane security policy, the MME sends the user plane security policy to the source eNB, and if not, the MME does not send the user plane security policy to the source eNB.
[0347] Figure 8 is a schematic diagram of the structure of a communication device 80 according to this application. Both the target access network device in the method embodiment corresponding to Figure 2 and the target eNB in the method embodiment corresponding to Figures 3A and 3B may be based on the structure of the communication device 80 shown in Figure 8 in this embodiment.
[0348] The communication device 80 includes at least one processor 801, at least one memory 802, and at least one transceiver 803. Optionally, the communication device 80 may further include at least one network interface 805 and one or more antennas 804. The processor 801, the memory 802, the transceiver 803, and the network interface 805 are connected through a connection device, and the antenna 804 is connected to the transceiver 803. The connection device may include various interfaces, transmission cables, buses, etc., which are not limited in this embodiment.
[0349] The processor 801 is mainly configured to process communication protocols and communication data, control the entire network device, execute software programs, and process data of the software programs, for example, configured to enable the communication device 80 to perform the actions described in the above embodiments. The communication device 80 may include a baseband processor and a central processing unit. The baseband processor is mainly configured to process communication protocols and communication data. The central processing unit is mainly configured to control the entire communication device 80, execute software programs, and process data of the software programs. The processor 801 in FIG. 8 may integrate the functions of the baseband processor and the central processing unit. It should be understood that the baseband processor and the central processing unit may alternatively be processors independent of each other and are interconnected by using a technology such as a bus. It should be further understood that the communication device 80 may include multiple baseband processors to accommodate different network standards, the communication device 80 may include multiple central processing units to enhance the processing capabilities of the communication device 80, and the components of the communication device 80 may be connected through various buses. The baseband processor may also be expressed as a baseband processing circuit or a baseband processing chip. The central processing unit may also be expressed as a central processing circuit or a central processing chip. The function of processing the communication protocol and the communication data may be built into the processor or may be stored in the memory in the form of a software program, and the processor executes the software program to realize the baseband processing function.
[0350] Moreover, the memory 802 is mainly configured to store software programs and data. The memory 802 may exist independently and be connected to the processor 801. Optionally, the memory 802 and the processor 801 may be integrated, for example, integrated into one or more chips. The memory 802 can store program codes for executing the technical solutions in the embodiments of this application, and the processor 801 controls the execution of the program codes. Various types of executing computer program codes may also be considered as drivers of the processor 801. It should be understood that FIG. 8 in this embodiment shows only one memory and one processor. However, in practical applications, the communication device 80 may include multiple processors or multiple memories. This is not specifically limited here. Furthermore, the memory 802 may also be referred to as a storage medium, a storage device, etc. The memory 802 may be a storage element located on the same chip as the processor (i.e., an on-chip storage element), or may be an independent storage element. This is not limited in this embodiment of this application.
[0351] In this embodiment, the transceiver 803 may be configured to support reception or transmission of radio frequency signals between the communication device 80 and a terminal device (or other network device), and the transceiver 803 may be connected to an antenna 804. The transceiver 803 includes a transmitter Tx and a receiver Rx. Specifically, the one or more antennas 804 may receive radio frequency signals. The receiver Rx of the transceiver 803 is configured to receive radio frequency signals from the antenna 804, convert the radio frequency signals into digital baseband signals or digital intermediate frequency signals, and provide the digital baseband signals or digital intermediate frequency signals to the processor 801, so that the processor 801 further processes the digital baseband signals or digital intermediate frequency signals, for example, performing demodulation and decoding. Furthermore, the transmitter Tx in the transceiver 803 is further configured to receive modulated digital baseband signals or digital intermediate frequency signals from the processor 801, convert the modulated digital baseband signals or digital intermediate frequency signals into radio frequency signals, and transmit the radio frequency signals through the one or more antennas 804. Specifically, the receiver Rx may selectively perform one or more levels of frequency downmixing and analog-to-digital conversion on the radio frequency signal to obtain a digital baseband signal or a digital intermediate frequency signal, and the sequence of the frequency downmixing and analog-to-digital conversion is adjustable. The transmitter Tx may selectively perform one or more levels of frequency upmixing and digital-to-analog conversion on the modulated digital baseband signal or the digital intermediate frequency signal to obtain a radio frequency signal, and the sequence of the frequency upmixing and digital-to-analog conversion is adjustable. The digital baseband signal and the digital intermediate frequency signal may be collectively referred to as a digital signal.
[0352] It should be understood that the transceiver 803 may also be referred to as a transceiver unit, a transceiver device, a transceiver equipment, etc. Optionally, components configured to realize a receiving function and located within the transceiver unit may be considered as a receiving unit, and components configured to realize a transmitting function and located within the transceiver unit may be considered as a transmitting unit. That is, the transceiver unit includes a receiving unit and a transmitting unit. The receiving unit may also be referred to as a receiver, an input interface, a receiver circuit, etc. The transmitting unit may be referred to as a transmitting device, a transmitter, a transmitter circuit, etc.
[0353] Furthermore, the network interface 805 is configured to connect the communication device 80 to other communication devices through a communication link. Specifically, the network interface 805 may include a network interface between the communication device 80 and a core network element, for example, an S1-U interface between the communication device 80 and an MME, or an S1-MME interface between the communication device 80 and an S-GW. The network interface 805 may also include a network interface between the communication device 80 and a terminal device, for example, an LTE-Uu interface.
[0354] Specifically, the processor 801 controls the transceiver 803 to receive a message 001 from a source access network device, where the message 001 includes indication information 011. Further, when the indication information 011 indicates that the terminal device supports on-demand user plane security protection between the terminal device and the access network device, the processor 801 controls the transceiver 803 to send a path switch request 031, carrying a user plane security policy 021, to a mobility management entity, where the user plane security policy 021 indicates whether to enable user plane encryption protection and / or whether to enable user plane integrity protection.
[0355] In an optional implementation manner, the processor 801 is configured to determine that the user plane security activation state between the access network device and the terminal device is that user plane encryption protection is enabled and user plane integrity protection is not enabled, and to construct a user plane security policy 021-1 that matches the user plane security activation state.
[0356] In an optional implementation manner, the processor 801 is further configured to control the transceiver 803 to receive a path switch response 041 from the mobility management entity, the path switch response 041 carrying the user plane security policy 022, and further configured to store the user plane security policy 022 in a context of the terminal device.
[0357] In an optional implementation manner, the processor 801 is further configured to enable or skip enabling user plane encryption protection and / or user plane integrity protection for the terminal device in accordance with the user plane security policy 022 when the current user plane security activation state of the terminal device does not match the user plane security policy 022, and the current user plane security activation state is a state of whether user plane encryption protection and / or user plane integrity protection is currently enabled between the target access network device and the terminal device.
[0358] In an optional implementation manner, the processor 801 is further configured to control the transceiver 803 to send a path switch request 032 that does not carry a user plane security policy to the mobility management entity, and to control the transceiver 803 to receive a path switch response 042 that does not carry a user plane security policy from the mobility management entity, when the indication information 011 indicates that the terminal device does not support on-demand user plane security protection between the terminal device and the access network device.
[0359] In an optional implementation manner, the processor 801 is further configured to control the transceiver 803 to send a path switch request 033 that does not carry a user plane security policy to the mobility management entity when the indication information 011 indicates that the terminal device does not support on-demand user plane security protection between the terminal device and the access network device, where the path switch request 033 carries the indication information 011.
[0360] In an optional implementation manner, the processor 801 is further configured to control the transceiver 803 to receive a path switch response 043 carrying a user plane security policy 023 from the mobility management entity, and to store the user plane security policy 023 in the context of the terminal device.
[0361] In an optional implementation manner, the processor 801 is further configured to enable or skip enabling user plane encryption protection and / or user plane integrity protection for the terminal device in accordance with the user plane security policy 023 when the current user plane security activation state of the terminal device does not match the user plane security policy 023, and the current user plane security activation state is a state of whether user plane encryption protection and / or user plane integrity protection is currently enabled between the target access network device and the terminal device.
[0362] For other contents, please refer to the method for the target access network device or the target eNB in the embodiment of Figure 2 or Figure 3A and Figure 3B, and the details will not be described again here.
[0363] Figure 9 is a schematic diagram of the structure of another communication device 90 according to this application. Both the mobility management entity in the method embodiment corresponding to Figure 4 or Figure 5 and the MME in the method embodiment corresponding to Figure 6A and Figure 6B or Figure 7 may be based on the structure of the communication device 90 shown in Figure 9 in this embodiment.
[0364] 9, the communications device 90 may include a processor 910, a memory 920, and a transceiver 930. The processor 910 is coupled to the memory 920, and the processor 910 is coupled to the transceiver 930.
[0365] The transceiver 930 may also be referred to as a transceiver unit, a transceiver device, a transceiver equipment, etc. Optionally, components configured to realize a receiving function and located within the transceiver unit may be considered as a receiving unit, and components configured to realize a transmitting function and located within the transceiver unit may be considered as a transmitting unit. That is, the transceiver unit includes a receiving unit and a transmitting unit. The receiving unit may also be referred to as a receiver, an input interface, a receiver circuit, etc. The transmitting unit may be referred to as a transmitting device, a transmitter, a transmitter circuit, etc.
[0366] The processor 910 may be a central processing unit, a network processor (NP), or a combination of a CPU and a NP. The processor may alternatively be an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The PLD may be a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof. The processor 910 may be a single processor or may include multiple processors.
[0367] Moreover, the memory 920 is mainly configured to store software programs and data. The memory 920 may exist independently and be connected to the processor 910. Optionally, the memory 920 and the processor 910 may be integrated, for example, integrated into one or more chips. The memory 920 can store program codes for executing the technical solutions in the embodiments of this application, and the processor 910 controls the execution of the program codes. Various types of executable computer program codes may also be considered as drivers for the processor 910. The memory 920 may include a volatile memory, for example, a random-access memory (RAM). Alternatively, the memory may include a non-volatile memory, for example, a read-only memory (ROM), a flash memory, a hard disk drive (HDD), or a solid-state drive (SSD). Alternatively, the memory 920 may include a combination of the above types of memory. The memory 920 may be a single memory or may include multiple memories.
[0368] In an implementation, the memory 920 stores computer-readable instructions, which include a number of software modules, such as a sending module 921, a processing module 922, and a receiving module 923. After executing each software module, the processor 910 may perform a corresponding operation based on the instructions of each software module. In this embodiment, the operation performed by the software module is actually the operation performed by the processor 910 based on the instructions of the software module.
[0369] Specifically, the processing module 922 is configured to obtain the indication information 013, and determine whether to send a user plane security policy 024 to an access network device serving the terminal device based on the indication information 013. The user plane security policy 024 indicates whether to enable user plane encryption protection and / or whether to enable user plane integrity protection. The indication information 013 indicates whether the terminal device supports on-demand user plane security protection between the terminal device and the access network device.
[0370] In an optional implementation manner, the sending module 921 is configured to send a path switch response 044 carrying a user plane security policy 024 to the target access network device when the indication information 013 indicates that the terminal device supports on-demand user plane security protection between the terminal device and the access network device and the path switch request 034 does not carry a user plane security policy.
[0371] In an optional implementation manner, the sending module 921 is configured to send the user plane security policy 024 to the source access network device when the indication information 013 indicates that the terminal device supports on-demand user plane security protection between the terminal device and the access network device.
[0372] In an optional implementation manner, the processing module 922 is configured to obtain indication information 051, the indication information 051 indicating whether an access network device serving the terminal device supports on-demand user plane security protection between the access network device and the terminal device, and is configured to determine whether to send a user plane security policy 024 to the access network device serving the terminal device based on the indication information 013 and the indication information 051.
[0373] In an optional implementation manner, the sending module 921 is configured to send the user plane security policy 024 to the access network device when the indication information 013 indicates that the terminal device supports on-demand user plane security protection and the indication information 051 indicates that the access network device serving the terminal device supports on-demand user plane security protection between the access network device and the terminal device.
[0374] In an optional implementation manner, the receiving module 923 is configured to receive subscription data of the terminal device from a home subscriber server, and the processing module 922 is configured to store the user plane security policy 024 when the indication information 013 indicates that the terminal device supports on-demand user plane security protection and the subscription data includes the user plane security policy 024.
[0375] In an optional implementation manner, the receiving module 923 is configured to receive subscription data of the terminal device from a home subscriber server, and the processing module 922 is configured to determine a user plane security policy 024 according to a preconfigured user plane security policy 024-1 when the indication information 013 indicates that the terminal device supports on-demand user plane security protection between the terminal device and the access network device and the subscription data does not include a user plane security policy, and store the user plane security policy 024 in a context of the terminal device.
[0376] In an optional implementation manner, the receiving module 923 is configured to receive subscription data of the terminal device from the home subscriber server, and the processing module 922 is configured to store the user plane security policy 024 when the indication information 013 indicates that the terminal device supports on-demand user plane security protection between the terminal device and the access network device, the indication information 051 indicates that the access network device supports on-demand user plane security protection between the access network device and the terminal device, and the subscription data includes the user plane security policy 024.
[0377] In an optional implementation manner, the receiving module 923 is configured to receive subscription data of the terminal device from the home subscriber server, and the processing module 922 is configured to determine a user plane security policy 024 according to a preconfigured user plane security policy 024-2 and store the user plane security policy 024 in a context of the terminal device when the indication information 013 indicates that the terminal device supports on-demand user plane security protection between the terminal device and the access network device, the indication information 051 indicates that the access network device supports on-demand user plane security protection between the access network device and the terminal device, and the subscription data does not include a user plane security policy.
[0378] For other contents, please refer to the method for the mobility management entity or MME in the embodiment of Figure 4, Figure 5, Figure 6A and Figure 6B, or Figure 7. Details are not described again here.
[0379] As shown in Fig. 10, the embodiment further provides a communication device 100. The communication device 100 may be an access network device or a chip in an access network device. The communication device 100 includes a transceiver unit 1001 and a processing unit 1002.
[0380] 11, an embodiment further provides a communication device 110. The communication device 110 may be a mobility management entity or a chip in a mobility management entity. The communication device 110 includes a transceiver unit 1101 and a processing unit 1102.
[0381] When the communication device 100 is an access network device or eNB and the communication device 110 is a mobility management entity or MME, the transceiver unit 1001 and the transceiver unit 1101 may be a transmitting unit or a transmitter when transmitting information, and the transceiver unit 1001 and the transceiver unit 1101 may be a receiving unit or a receiver when receiving information. The transceiver unit may be a transceiver or a radio frequency circuit integrating a transmitter and a receiver. When the communication device 100 or the communication device 110 includes a storage unit, the storage unit is configured to store computer instructions. The processor is communicatively connected to the memory, and the processor executes the computer instructions stored in the memory, whereby the access network device and the mobility management entity perform the methods in the method embodiments corresponding to Figures 2, 4 and 5, and the eNB and the MME perform the methods in the method embodiments corresponding to Figures 3A and 3B, 6A and 6B, and 7. Furthermore, the processing unit 1002 and the processing unit 1102 may be a general-purpose central processing unit, a microprocessor, a digital signal processor (DSP), or a micro controller unit (MCU). The processor may be a separate semiconductor chip or may be integrated with other circuits on a semiconductor chip. For example, the processor and other circuits (e.g., codec circuits, hardware acceleration circuits, or various bus and interface circuits) may form a system-on-a-chip (SoC), or the processor may be integrated into an application-specific integrated circuit (ASIC) as an embedded processor of the ASIC.
[0382] When the communication device 100 is a chip in an access network device and when the communication device 110 is a chip in a mobility management entity, the transceiver unit 1001 and the transceiver unit 1101 may be input and / or output interfaces, pins, circuits, etc. Furthermore, the processing unit 1002 may be a processor of the chip in the access network device, and the processing unit 1102 may be a processor of the chip in the mobility management entity. The processor may execute computer-executable instructions stored in the storage unit, so that the chip in the access network device and the chip in the mobility management entity perform the method in the embodiment corresponding to FIG. 2-FIG. 7. Optionally, the storage unit is a storage unit in the chip, for example, a register or a buffer, or the storage unit may be a storage unit located in the access network device or the mobility management entity and outside the chip, for example, a read-only memory ROM, other types of static storage devices capable of storing static information and instructions, or a random access memory RAM.
[0383] For example, for the communication device 100, the transceiver unit 1001 is configured to receive a message 001 from a source access network device and send a path switch request 031 carrying a user plane security policy 021 to a mobility management entity. The processing unit 1002 is configured to control the transceiver unit 1001 to receive the message 001 from the source access network device, where the message 001 includes indication information 011. Furthermore, when the indication information 011 indicates that the terminal device supports on-demand user plane security protection between the terminal device and the access network device, the processor 801 controls the transceiver unit 1001 to send a path switch request 031 carrying a user plane security policy 021 to the mobility management entity, where the user plane security policy 021 indicates whether to enable user plane encryption protection and / or whether to enable user plane integrity protection.
[0384] For example, the processing unit 1002 is further configured to control the transceiver unit 1001 to send a path switch request 033 that does not carry a user plane security policy to the mobility management entity when the indication information 011 indicates that the terminal device does not support on-demand user plane security protection between the terminal device and the access network device, where the path switch request 033 carries the indication information 011.
[0385] For example, the processing unit 1002 is further configured to enable or skip enabling user plane encryption protection and / or user plane integrity protection for the terminal device in accordance with the user plane security policy 022 when the current user plane security activation state of the terminal device does not match the user plane security policy 022, where the current user plane security activation state is a state of whether user plane encryption protection and / or user plane integrity protection is currently enabled between the target access network device and the terminal device.
[0386] For other contents, please refer to the method for the target access network device or the target eNB in the embodiment of Figure 2 or Figure 3A and Figure 3B, and the details will not be described again here.
[0387] For example, for the communication device 110, the processing unit 1102 is configured to obtain the indication information 013, and determine whether to send a user plane security policy 024 to an access network device serving the terminal device based on the indication information 013. The user plane security policy 024 indicates whether to enable user plane encryption protection and / or whether to enable user plane integrity protection. The indication information 013 indicates whether the terminal device supports on-demand user plane security protection between the terminal device and the access network device.
[0388] For example, the transceiver unit 1101 is configured to send a path switch response 044 carrying a user plane security policy 024 to the target access network device when the indication information 013 indicates that the terminal device supports on-demand user plane security protection between the terminal device and the access network device and the path switch request 034 does not carry a user plane security policy.
[0389] For example, the transceiver unit 1101 is configured to send the user plane security policy 024 to the source access network device when the indication information 013 indicates that the terminal device supports on-demand user plane security protection between the terminal device and the access network device.
[0390] For other contents, please refer to the method for the mobility management entity or MME in the embodiment of Figure 4, Figure 5, Figure 6A and Figure 6B, or Figure 7. Details are not described again here.
[0391] It should be understood that the access network device may include functional units (means) corresponding to steps of a method or process of the access network device, and the mobility management entity may include functional units corresponding to steps of a method or process of the mobility management entity. One or more of the above modules or units may be realized by using software, hardware or a combination thereof. When any one of the above modules or units is realized by using software, the software may be in the form of computer program instructions and stored in a memory, and the processor may be configured to execute the program instructions to realize the processes of the above methods.
[0392] According to the method provided in the embodiment of this application, the embodiment of this application further provides a communication system. The communication system includes a terminal device, an access network device, and a mobility management entity. For the structure of the access network device, refer to the communication device 80 in the embodiment corresponding to FIG. 8. For the structure of the mobility management entity, refer to the communication device 90 in the embodiment corresponding to FIG. 9. Furthermore, when the access network device is a chip, for the access network device, refer to the communication device 100 in the embodiment corresponding to FIG. 10, and when the mobility management entity is a chip, for the mobility management entity, refer to the communication device 110 in the embodiment corresponding to FIG. 11.
[0393] In the implementation manner, the steps in the above method may be executed by an integrated logic circuit of hardware in a processor or through an instruction in the form of software. The steps of the method disclosed with reference to the embodiments of this application may be executed directly by a hardware processor, or may be executed by a combination of hardware and software modules in a processor. The software modules may be located in a mature storage medium in the art, such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, an electrically erasable programmable memory, or a register. The storage medium is located in the memory, and the processor reads the information in the memory and executes the steps in the above method based on the hardware of the processor. In order to avoid repetition, the details will not be described again here. It should be further understood that the "first", "second", "third", "fourth" and various numbers in this specification are used merely for distinction to facilitate the description, and are not intended to limit the scope of the embodiments of this application.
[0394] It should be understood that the term "and / or" in this specification describes only an association relationship between related objects and indicates that three relationships may exist. For example, A and / or B may indicate the following three cases: only A is present, both A and B are present, and only B is present. Furthermore, the character " / " in this specification generally indicates an "or" relationship between related objects.
[0395] It should be understood that the sequence numbers of the above processes do not mean the execution sequence in the embodiment of this application. The execution sequence of the processes should be determined based on the functions and internal logic of the processes, and should not constitute any limitation on the implementation process of the embodiment of this application.
[0396] For ease and conciseness of description, the detailed operation processes of the above systems, devices and units may be referenced to the corresponding processes in the above method embodiments, and the details will not be described again here, which can be clearly understood by those skilled in the art.
[0397] The above embodiments do not limit this application, but are merely intended to describe the technical solutions of this application. Although this application has been described in detail with reference to the above embodiments, it should be understood that those skilled in the art may still make modifications to the technical solutions described in the above embodiments, or make equivalent substitutions to some technical features thereof, without departing from the spirit and scope of the technical solutions of the embodiments of this application.
Claims
1. A security policy processing method, comprising: receiving a message 001 from a source access network device by a target access network device, the message 001 including indication information 011; sending, by the target access network device, a path switch request 031 carrying a user plane security policy 021 to a mobility management entity when the indication information 011 indicates that the terminal device supports on-demand user plane security protection between the terminal device and an access network device, the user plane security policy 021 indicating whether to enable user plane encryption protection and / or whether to enable user plane integrity protection; The method includes:
2. The method of claim 1 , wherein the access network device is an Evolved Node B eNB.
3. The method according to claim 1 or 2, wherein when the target access network device does not receive a user plane security policy from the source access network device, the user plane security policy 021 is a user plane security policy 021-1 established by the target access network device.
4. determining, by the target access network device, that a user plane security activation state between the target access network device and the terminal device is that user plane encryption protection is enabled and user plane integrity protection is not enabled; constructing, by the target access network device, the user plane security policy 021-1 that matches the user plane security activation state; The method of claim 3 further comprising:
5. The method according to claim 3 or 4, wherein the user plane security policy 021-1 includes a user plane encryption protection policy and a user plane integrity protection policy, the user plane encryption protection policy indicating that activation is required or that activation is preferred, and the user plane integrity protection policy indicating that activation is not required or that activation is preferred.
6. The method according to claim 1 or 2, wherein when the target access network device does not receive a user plane security policy from the source access network device, the user plane security policy 021 is a user plane security policy 021-2 preconfigured in the target access network device.
7. The message 001 further includes identifiers of N evolved radio access bearers of the terminal device, where N is an integer equal to or greater than 1; The method of claim 6, wherein the path switch request 031 further comprises the identifiers of the N evolved radio access bearers.
8. The method of claim 7, wherein the path switch request 031 includes N user plane security policies 021-2, and each of the identifiers of the N evolved radio access bearers corresponds to one of the N user plane security policies 021-2.
9. After sending a path switch request 031 carrying a user plane security policy 021 to a mobility management entity by the target access network device, receiving, by the target access network device, a path switch response 041 from the mobility management entity, the path switch response 041 carrying a user plane security policy 022; storing, by the target access network device, the user plane security policy 022 in the context of the terminal device; The method of claim 1 , further comprising:
10. 10. The method of claim 9, further comprising: activating or skipping activation of user plane encryption protection and / or user plane integrity protection for the terminal device in accordance with the user plane security policy 022, by the target access network device, if a current user plane security activation state of the terminal device does not match the user plane security policy 022, wherein the current user plane security activation state is a state of whether user plane encryption protection and / or user plane integrity protection is currently enabled between the target access network device and the terminal device or not.
11. sending, by the target access network device, a path switch request 032 that does not carry a user plane security policy to the mobility management entity when the indication information 011 indicates that the terminal device does not support on-demand user plane security protection between the terminal device and an access network device; receiving, by the target access network device, a path switch response 042 from the mobility management entity, the path switch response 042 not carrying a user plane security policy; The method of claim 1 further comprising:
12. sending, by the target access network device, a path switch request 033 that does not carry a user plane security policy to the mobility management entity when the indication information 011 indicates that the terminal device does not support on-demand user plane security protection between the terminal device and an access network device, the path switch request 033 carrying the indication information 011; receiving, by the target access network device, a path switch response 043 from the mobility management entity, the path switch response 043 carrying a user plane security policy 023; storing, by the target access network device, the user plane security policy 023 in the context of the terminal device; The method of claim 1 further comprising:
13. 13. The method of claim 12, wherein the path switch response 043 carrying the user plane security policy 023 further carries indication information 012, the indication information 012 indicating that the terminal device supports on-demand user plane security protection between the terminal device and an access network device.
14. The method according to claim 12 or 13, further comprising the step of: activating or skipping the activation of user plane encryption protection and / or user plane integrity protection for the terminal device in accordance with the user plane security policy 023, by the target access network device, if a current user plane security activation state of the terminal device does not match the user plane security policy 023, wherein the current user plane security activation state is a state of whether user plane encryption protection and / or user plane integrity protection is currently activated between the target access network device and the terminal device or not.
15. The method according to any one of claims 1 to 14, wherein the indication information 011 is represented by a part of bits of an evolved packet system security capability of the terminal device, and the evolved packet system security capability of the terminal device indicates at least one security algorithm supported by the terminal device.
16. The method according to claim 1 , wherein the message 001 is a handover request or a context acquisition response.
17. 1. A communications device, comprising: a receiving module configured to receive a message 001 from a source access network device, the message 001 including indication information 011; A processing module configured to control a transmission module to send a path switch request 031 carrying a user plane security policy 021 to a mobility management entity when the indication information 011 indicates that the terminal device supports on-demand user plane security protection between the terminal device and an access network device, the user plane security policy 021 indicating whether to enable user plane encryption protection and / or whether to enable user plane integrity protection. A communication device including:
18. The communications device of claim 17 , wherein the access network device is an Evolved Node B eNB.
19. 19. A communication device as described in claim 17 or 18, wherein when the communication device does not receive a user plane security policy from the source access network device, the user plane security policy 021 is a user plane security policy 021-1 established by the communication device.
20. The processing module includes: determining that a user plane security activation state between the access network device and the terminal device is that user plane encryption protection is enabled and user plane integrity protection is not enabled; The communications device of claim 19, further configured to establish the user plane security policy 021-1 consistent with the user plane security activation state.
21. The communication device according to claim 19 or 20, wherein the user plane security policy 021-1 includes a user plane encryption protection policy and a user plane integrity protection policy, the user plane encryption protection policy indicating that activation is required or that activation is preferred, and the user plane integrity protection policy indicating that activation is not required or that activation is preferred.
22. 19. The communication device of claim 17 or 18, wherein when the communication device does not receive a user plane security policy from the source access network device, the user plane security policy 021 is a user plane security policy 021-2 preconfigured in the communication device.
23. The message 001 further includes identifiers of N evolved radio access bearers of the terminal device, where N is an integer equal to or greater than 1; The communications device of claim 22, wherein the path switch request 031 further comprises the identifiers of the N evolved radio access bearers.
24. 24. The communications device of claim 23, wherein the path switch request 031 includes N user plane security policies 021-2, and each of the identifiers of the N evolved radio access bearers corresponds to one of the N user plane security policies 021-2.
25. The receiving module is further configured to receive a path switch response 041 from the mobility management entity, the path switch response 041 carrying a user plane security policy 022; The communication device further includes a storage module; 25. The communication device according to claim 17, wherein the storage module is configured to store the user plane security policy in a context of the terminal device.
26. The processing module includes:
26. The communication device of claim 25, further configured to enable or skip enabling user plane encryption protection and / or user plane integrity protection for the terminal device in accordance with the user plane security policy 022 when a current user plane security activation state of the terminal device does not match the user plane security policy 022, wherein the current user plane security activation state is a state of whether user plane encryption protection and / or user plane integrity protection is currently enabled between a target access network device and the terminal device.
27. The transmitting module includes: When the indication information 011 indicates that the terminal device does not support on-demand user plane security protection between the terminal device and an access network device, the indication information 011 is further configured to send a path switch request 032 that does not carry a user plane security policy to the mobility management entity; The communication device of claim 17, wherein the receiving module is further configured to receive a path switch response 042 from the mobility management entity that does not carry a user plane security policy.
28. The transmitting module includes: When the indication information 011 indicates that the terminal device does not support on-demand user plane security protection between the terminal device and an access network device, the path switch request 033 is further configured to send a path switch request 033 that does not carry a user plane security policy to the mobility management entity, the path switch request 033 carrying the indication information 011; The receiving module is further configured to receive a path switch response 043 carrying a user plane security policy 023 from the mobility management entity; The communication device further includes a storage module; The communication device of claim 17, wherein the storage module is configured to store the user plane security policy 023 in a context of the terminal device.
29. 29. The communications device of claim 28, wherein the path switch response 043 carrying the user plane security policy 023 further carries indication information 012, the indication information 012 indicating that the terminal device supports on-demand user plane security protection between the terminal device and an access network device.
30. The processing module includes:
30. The communication device of claim 28 or 29, further configured to enable or skip enabling user plane encryption protection and / or user plane integrity protection for the terminal device in accordance with the user plane security policy 023 when a current user plane security activation state of the terminal device does not match the user plane security policy 023, the current user plane security activation state being a state of whether user plane encryption protection and / or user plane integrity protection is currently enabled between a target access network device and the terminal device or not.
31. The communication device according to any one of claims 17 to 30, wherein the indication information 011 is represented by a portion of bits of an evolved packet system security capability of the terminal device, the evolved packet system security capability of the terminal device indicating at least one security algorithm supported by the terminal device.
32. 32. A communications device according to any one of claims 17 to 31, wherein the message 001 is a handover request or a context acquisition response.
33. 1. A communications device, comprising: The communication device includes a processor, a memory, and a transceiver, the memory storing program code, and the processor invokes the program code stored in the memory to perform the following operations: an operation of controlling the transceiver to receive a message 001 from a source access network device, the message 001 including indication information 011; and when the indication information 011 indicates that the terminal device supports on-demand user plane security protection between the terminal device and an access network device, an operation of controlling the transceiver to send a path switch request 031 carrying a user plane security policy 021 to a mobility management entity, the user plane security policy 021 indicating whether to enable user plane encryption protection and / or whether to enable user plane integrity protection.
23. A communications device configured to:
34. The communications device of claim 33 , wherein the access network device is an Evolved Node B eNB.
35. 35. A communications device as claimed in claim 33 or 34, wherein when the communications device does not receive a user plane security policy from the source access network device, the user plane security policy 021 is a user plane security policy 021-1 established by the communications device.
36. The processor, determining that a user plane security activation state between the access network device and the terminal device is that user plane encryption protection is enabled and user plane integrity protection is not enabled; 36. The communications device of claim 35, further configured to establish the user plane security policy 021-1 consistent with the user plane security activation state.
37. The communication device of claim 35 or 36, wherein the user plane security policy 021-1 includes a user plane encryption protection policy and a user plane integrity protection policy, the user plane encryption protection policy indicating that activation is required or that activation is preferred, and the user plane integrity protection policy indicating that activation is not required or that activation is preferred.
38. 35. A communication device as claimed in claim 33 or 34, wherein when the communication device does not receive a user plane security policy from the source access network device, the user plane security policy 021 is a user plane security policy 021-2 preconfigured in the communication device.
39. The message 001 further includes identifiers of N evolved radio access bearers of the terminal device, where N is an integer equal to or greater than 1; 39. The communications device of claim 38, wherein the path switch request 031 further comprises the identifiers of the N evolved radio access bearers.
40. 40. The communications device of claim 39, wherein the path switch request 031 includes N user plane security policies 021-2, and each of the identifiers of the N evolved radio access bearers corresponds to one of the N user plane security policies 021-2.
41. The processor, and further configured to control the transceiver to receive a path switch response 041 from the mobility management entity, the path switch response 041 carrying a user plane security policy 022; 41. A communications device according to any one of claims 33 to 40, further configured to store the user plane security policy in a context of the terminal device.
42. The processor, 42. The communication device of claim 41, further configured to enable or skip enabling user plane encryption protection and / or user plane integrity protection for the terminal device in accordance with the user plane security policy 022 when a current user plane security activation state of the terminal device does not match the user plane security policy 022, wherein the current user plane security activation state is a state of whether user plane encryption protection and / or user plane integrity protection is currently enabled between a target access network device and the terminal device.
43. The processor, When the indication information 011 indicates that the terminal device does not support on-demand user plane security protection between the terminal device and an access network device, control the transceiver to send a path switch request 032 that does not carry a user plane security policy to the mobility management entity; 34. The communications device of claim 33, further configured to control the transceiver to receive a path switch response 042 from the mobility management entity that does not carry a user plane security policy.
44. The processor, When the indication information 011 indicates that the terminal device does not support on-demand user plane security protection between the terminal device and an access network device, the indication information 011 is further configured to control the transceiver to send a path switch request 033 that does not carry a user plane security policy to the mobility management entity, the path switch request 033 carrying the indication information 011; Controlling the transceiver to receive a path switch response 043 carrying a user plane security policy 023 from the mobility management entity; The communication device of claim 33, further configured to store the user plane security policy 023 in a context of the terminal device.
45. 45. The communications device of claim 44, wherein the path switch response 043 carrying the user plane security policy 023 further carries indication information 012, the indication information 012 indicating that the terminal device supports on-demand user plane security protection between the terminal device and an access network device.
46. The processor, 46. The communication device of claim 44 or 45, further configured to enable or skip enabling user plane encryption protection and / or user plane integrity protection for the terminal device in accordance with the user plane security policy 023 when a current user plane security activation state of the terminal device does not match the user plane security policy 023, the current user plane security activation state being a state of whether user plane encryption protection and / or user plane integrity protection is currently enabled between a target access network device and the terminal device.
47. The communication device according to any one of claims 33 to 46, wherein the indication information 011 is represented by a portion of bits of an evolved packet system security capability of the terminal device, the evolved packet system security capability of the terminal device indicating at least one security algorithm supported by the terminal device.
48. 48. A communications device according to any one of claims 33 to 47, wherein the message 001 is a handover request or a context acquisition response.
49. 1. A computer-readable storage medium, comprising: A computer readable storage medium storing instructions which, when run on a computer, enable the computer to carry out a method according to any one of claims 1 to 16.
50. 1. A computer program product comprising instructions, A computer program product, the instructions being executable when run on a computer, to enable the computer to carry out the method of any one of claims 1 to 16.
51. A communication system a mobility management entity; A communication device according to any one of claims 17 to 32; A communication system comprising:
52. 52. The communication system of claim 51, further comprising a source access network device and / or a terminal device.