Security Policy Processing Method and Communication Device

The implementation of a best-effort on-demand user plane security activation mechanism in 4G networks allows for effective security protection despite the presence of non-upgraded network devices, ensuring robust security and preventing undercutting attacks.

JP7690589B2Active Publication Date: 2025-06-10HUAWEI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2023541752
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2021-01-10
Filing Date
2022-01-07
Publication Date
2025-06-10
Estimated Expiration
2042-01-07

AI Technical Summary

Technical Problem

The implementation of an on-demand user plane security protection mechanism in 4G networks is hindered by the presence of both upgraded and non-upgraded network devices, which do not support this mechanism.

Method used

A best-effort on-demand user plane security activation mechanism is implemented, where a target access network device receives messages from a core network device containing user plane security policies, allowing it to determine and activate the necessary security protections even if core network elements do not support on-demand user plane security protection.

Benefits of technology

This solution ensures that user plane security protections can be effectively implemented between access network devices and terminal devices in 4G networks, even when non-upgraded core network elements are present, thereby enhancing security and avoiding potential undercutting attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007690589000001
    Figure 0007690589000001
  • Figure 0007690589000002
    Figure 0007690589000002
  • Figure 0007690589000003
    Figure 0007690589000003
Patent Text Reader

Abstract

An embodiment of the present application discloses a security policy processing method for implementing a best-effort on-demand user plane security activation mechanism in a network in which a core network element that does not support on-demand user plane security protection exists. The security policy processing method in the embodiment of the present application includes: a target access network device receiving a message #50-2 from a core network device #30-1, where the message #50-2 includes container information from a source access network device; the target access network device determining a user plane security activation status between the target access network device and the terminal device based on the message #50-2, where the user plane security activation status indicates whether user plane encryption protection is activated and / or whether user plane integrity protection is activated.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001]

[0001] This application claims priority to Chinese Patent Application No. 202110027552.1, titled "Security Policy Processing Method and Communication Device", filed with the China National Intellectual Property Administration on January 10, 2021, the entire content of which is incorporated herein by reference.

[0002]

[0002] Technical Field Embodiments of this application are related to the communication field, and in particular, to a security policy processing method and a communication device.

Background Art

[0003]

[0003] The on-demand user plane security protection mechanism is a security mechanism in a 5th generation mobile communication technology (5G) network. On-demand user plane security protection includes user plane encryption protection and user plane integrity protection. The on-demand user plane security protection mechanism requests the access network device to determine whether to activate user plane encryption protection and / or user plane integrity protection with the terminal device according to the user plane security policy received from the core network device. The on-demand user plane security protection mechanism can provide more flexible user plane security protection for the terminal device.

[0004]

[0004] However, existing fourth-generation mobile communication technology (4G) networks do not support an on-demand user plane security protection mechanism. In a 4G network, the user plane security between an access network device and a terminal device is fixed. Specifically, user plane security always means that user plane encryption protection is activated and user plane integrity protection is not activated.

[0005]

[0005] The 4G network will not end in the short term. In this case, how to apply the aforementioned on-demand user plane security protection mechanism to the 4G network has become a research hotspot in the industry. The on-demand user plane security protection mechanism includes access network devices and related core network devices within the network (for example, a mobility management entity (MME) in a 4G network and an access and mobility management function (AMF) entity in a 5G network).

[0006]

[0006] However, there may be un-upgraded access network devices and un-upgraded core network devices in the 4G network. Un-upgraded access network devices and un-upgraded core network devices do not support on-demand user plane security protection. As a result, the purpose of implementing on-demand user plane security protection cannot be achieved.

[0007]

[0007] How to implement an on-demand user plane security protection mechanism in a 4G network where both upgraded and non-upgraded network devices / core network devices exist is an urgent issue to be resolved in the current standard.

Summary of the Invention

[0008]

[0008] Embodiments of the present application provide a security policy processing method and a communication device, and implement a best-effort on-demand user plane security activation mechanism in a network where core network elements that do not support on-demand user plane security protection exist.

[0009]

[0009] According to a first aspect, embodiments of the present application provide a security policy processing method. The method includes: a target access network device receiving a message #50-2 from a core network device #30-1, where the message #50-2 includes container information from a source access network device. The target access network device determines a user plane security activation status between the target access network device and the terminal device based on the message #50-2, where the user plane security activation status indicates whether user plane encryption protection is activated and / or whether user plane integrity protection is activated.

[0010]

[0010] In a possible implementation, the container information includes user - plane security policy #40 - 1. The target access network device determining the user - plane security activation status between the target access network device and the terminal device based on message #50 - 2 includes the following:

[0011] The target access network device determines the user - plane security activation status between the target access network device and the terminal device according to the user - plane security policy #40 - 1. The container information is generated by the source access network device and transmitted by the core network device #30 - 1 to the target access network device. The core network device #30 - 1 does not analyze the container information but transparently transmits the container information to the target access network device. Therefore, regardless of whether the core network device #30 - 1 is upgraded or not, the target access network device can ensure that it can obtain the available user - plane security policy and can ensure the implementation of on - demand user - plane security activation between the target access network device and the terminal device.

[0011]

[0012] In a possible implementation, message #50-2 further includes user plane security policy #40-2, and the container information includes user plane security policy #40-1. User plane security policy #40-2 may be a user plane security policy corresponding to the terminal device and determined by core network device #30-1 (for example, it may be a user plane security policy stored by core network device #30-1, or a user plane security policy obtained from another core network device, for example, the user plane security policy of the subscribing user of the terminal device).

[0012]

[0013] For the target access network device to determine the user plane security activation status between the target access network device and the terminal device based on message #50-2 includes: the target access network device determines the user plane security activation status between the target access network device and the terminal device according to user plane security policy #40-2.

[0013]

[0014] When the target access network device receives multiple user plane security policies, the target access network device can preferentially use the user plane security policy with a high priority / security level. In this embodiment of the present application, the target access network device determines the user plane security activation status between the target access network device and the terminal device according to the user plane security policy #40-2 from the core network device #30-1. In this way, potential race-to-the-bottom attacks can be effectively avoided.

[0014]

[0015] Furthermore, in a possible implementation, before the target access network device determines the user plane security activation status between the target access network device and the terminal device according to the user plane security policy #40-2, the method further includes the following:

[0016] The target access network device determines whether the user plane security policy #40-2 is consistent with the user plane security policy #40-1. When the user plane security policy #40-2 is consistent with the user plane security policy #40-1, the target access network device determines the user plane security activation status between the target access network device and the terminal device according to the user plane security policy #40-2.

[0015]

[0017] When User Plane Security Policy #40-2 does not match User Plane Security Policy #40-1, the target access network device determines the user plane security activation status between the target access network device and the terminal device according to User Plane Security Policy #40-2. Further, the target access network device can generate alarm information, where the alarm information indicates that the source access network device is in an insecure environment. Optionally, the target access network device sends the alarm information to Core Network Device #30-1. Thereafter, the target access network device or Core Network Device #30-1 can refer to the alarm information when performing related operations. For example, in the handover procedure, the handover to the source access network device is avoided as much as possible.

[0016]

[0018] In a possible implementation, when Message #50-2 does not carry the user plane security policy and the container information also does not carry the user plane security policy, the target access network device determines the user plane security activation status between the target access network device and the terminal device according to the pre-set User Plane Security Policy #40-3.

[0017]

[0019] In a possible implementation, Message #50-2 is a handover request message, and the handover request message is used to request the target access network device to prepare the handover resources of the terminal device.

[0018]

[0020] In a possible implementation, message #50-2 further includes instruction information. Before the target access network device determines the user plane security activation status between the target access network device and the terminal device based on message #50-2, the method further includes: the target access network device determines, based on the instruction information, that the terminal device supports on-demand user plane security protection.

[0019]

[0021] If the terminal device does not support on-demand user plane security protection, the target access network device may not need to determine the user plane security activation status between the target access network device and the terminal device.

[0020]

[0022] According to a second aspect, an embodiment of the present application provides a security policy processing method. The method includes: the source access network device obtains the user plane security policy #40-1 of the terminal device. The source access network device sends message #50-1 to the core network device #30-1, where message #50-1 includes container information, and the container information includes the user plane security policy #40-1. The core network device #30-1 does not analyze the content in the container information.

[0021]

[0023] In a possible implementation, before the source access network device obtains the user plane security policy #40-1 of the terminal device, the method further includes: the source access network device determines that the terminal device supports on-demand user plane security protection.

[0022]

[0024] The terminal device does not support on-demand user plane security protection. However, when the source access network device supports on-demand user plane security protection, the source access network device can obtain the user plane security policy of the terminal device from the core network side and store the user plane security policy in the AS context of the terminal device. When the terminal device does not support on-demand user plane security protection, the source access network device may not need to obtain the user plane security policy in the AS context. In this way, it is possible to avoid the transmission of unnecessary information in the network, and signaling is reduced.

[0023]

[0025] In a possible implementation, the method further includes: the source access network device determines that the terminal device needs to be handed over to the target access network device.

[0024]

[0026] In the foregoing aspect, in the handover situation, the message #50-2 may be a handover request message. The handover request message is used to request the target access network device to prepare the handover resources of the terminal device. The message #50-1 includes the handover request message, and the handover request message is used by the target access network device to prepare the handover resources of the terminal device.

[0025]

[0027] In a possible implementation, message #50-2 further includes indication information. Before the target access network device determines the user plane security activation status between the target access network device and the terminal device based on message #50-2, the method further includes: the target access network device determines, based on the indication information, that the terminal device supports on-demand user plane security protection. The indication information is specified by a part of the bits of the security capabilities of the terminal device, and the security capabilities of the terminal device specify at least one security algorithm that can be used by the terminal device. The security capabilities of the terminal device are UE evolved packet system security capabilities.

[0026]

[0028] According to a third aspect, an embodiment of the present application provides a communication device. The communication device has a function of implementing the corresponding method implemented by each network element in the embodiment of the present application. The function may be implemented by hardware or by hardware that executes the corresponding software. The hardware or software includes one or more modules corresponding to the function.

[0027]

[0029] According to a fourth aspect, an apparatus including a processor and a memory is provided. The memory is configured to store computer-executable instructions. When the apparatus operates, the processor executes the computer-executable instructions stored in the memory, whereby the apparatus executes a security policy processing method according to any one of the first aspect and the second aspect. Specifically, the apparatus may be a network element or a chip in the network element in any security policy processing method according to the first aspect.

[0028]

[0030] According to a fifth aspect, a computer-readable storage medium is provided. The computer-readable storage medium stores instructions. When the instructions are executed on a computer, the computer executes a security policy processing method according to any one of the first aspect and the second aspect.

[0029]

[0031] According to a sixth aspect, a computer program product including instructions is provided. When the computer program product is executed on a computer, the computer executes a security policy processing method according to any one of the first aspect or an implementation of the first aspect.

[0030]

[0032] Regarding the technical effects brought about by any of the design methods of the third aspect to the sixth aspect, refer to the technical effects brought about by various design methods of the first aspect. Details will not be described again here.

Brief Description of the Drawings

[0031]

[0033] To more clearly explain the technical solutions in the embodiments of this application, the accompanying drawings for explaining the embodiments are briefly described below. It is obvious that in the following description, the accompanying drawings only show some embodiments of this application.

Figure 1A

[0034] FIG. 1A is a diagram of a 4G network architecture to which the security policy processing method according to the embodiment of this application is applicable.

Figure 1B

[0035] FIG. 1B is a diagram of a 5G-4G interoperability architecture to which the security policy processing method according to the embodiment of this application is applicable.

Figure 2

[0036] FIG. 2 is a schematic diagram of the security policy processing method according to the embodiment of this application.

Figure 3

[0037] Figure 3 is a schematic diagram of a security policy processing method in an S1 handover scenario according to an embodiment of the present application.

Figure 4

[0038] Figure 4 is a schematic diagram of a security policy processing method in a 5GS-to-EPS handover scenario according to an embodiment of the present application.

Figure 5

[0030] Figure 5 is a schematic diagram of the structure of a communication device according to an embodiment of the present application.

Figure 6

[0040] Figure 6 is a schematic diagram of the structure of another communication device according to an embodiment of the present application.

Mode for Carrying Out the Invention

[0032]

[0041] Hereinafter, with reference to the accompanying drawings in the embodiments of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described. It is obvious that the described embodiments are only a part of the embodiments of the present application, not all of them.

[0033]

[0042] In the specification, claims, and accompanying drawings of the present application, terms such as "first", "second", "third", "fourth", and various other ordinal terms (if any) are intended to distinguish similar objects, but do not necessarily indicate a specific order or sequence. Such named data is interchangeable in appropriate circumstances, and as a result, it should be understood that the embodiments described herein can be implemented in an order other than the order illustrated or described herein. Further, the terms "including" and "having" and any other variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device including a list of steps or units is not necessarily limited to the explicitly listed steps or units, and may include other steps or units not explicitly listed, or those inherent to such a process, method, product, or device.

[0034]

[0043] The method provided in the embodiments of this application is applicable to any network in which there are core network elements that do not support on-demand user plane security protection in order to implement a best-effort on-demand user plane security activation mechanism. The network architectures and service scenarios described in the following embodiments of this application are intended to more clearly illustrate the technical solutions in the embodiments of this application and do not constitute a limitation to the technical solutions provided in the embodiments of this application. Those skilled in the art will understand that with the evolution of network architectures and the emergence of new service scenarios, the technical solutions provided in the embodiments of this application are also applicable to solving similar technical problems.

[0035]

[0044] For example, the following first describes two system architectures and application scenarios to which the security policy processing method provided in this application is applicable.

[0036]

[0045] The scenario to which the security policy processing method provided in this application is applicable is a 4G network scenario. FIG. 1A shows the network architecture of the current Long Term Evolution (LTE) / System Architecture Evolution (SAE). The core network part mainly includes a Mobility Management Entity (MME), a Serving Gateway (SGW / S-GW), a Packet Data Network Gateway (PDN GW / PGW / P-GW), a Home Subscriber Server (HSS), a Serving GPRS Support Node (SGSN), a Policy and Charging Rules Function (PCRF), the Operator's IP Service (for example, an IP Multimedia Subsystem (IMS) and a Packet Switching Service (PSS)), etc. The core network may be an Evolved Packet Core (EPC). Further, FIG. 1A further includes an access network part, that is, an Evolved UMTS Terrestrial Radio Access Network (E-UTRAN). The access network part mainly includes radio access network (RAN) devices. Further, FIG. 1A may further include a terminal device, for example, a User Equipment (UE).

[0037]

[0046] The Mobility Management Entity (MME) is responsible for the management and storage of the mobility management context of the terminal device (e.g., the identifier of the terminal device, the mobility management status, and the user security parameters), the processing of non-access stratum (NAS) signaling (e.g., attach request, update location request, service request, and Packet Data Network (PDN) connectivity request), and NAS signaling security, etc.

[0038]

[0047] The Serving Gateway (S-GW / SGW) is a gateway that terminates the user plane interface of the access network and performs functions such as lawful interception and packet data routing. The interface between the Serving Gateway (S-GW) and the Mobility Management Entity (MME) is the S11 interface, which is responsible for the exchange of session control information of the terminal device, etc.

[0039]

[0048] The Packet Data Network Gateway (P-GW) is a gateway that terminates the SGi interface to the packet data network, provides functions such as bearer control, data transfer, IP address allocation, and non-3GPP user access, and is an anchor point for 3GPP access and non-3GPP access to the public data network (PDN). The P-GW has the functions of packet routing and forwarding, and is responsible for the policy and charging enhancement function and the user-specific packet filtering function. The P-GW is connected to the S-GW via the S5 interface, transmits control information such as the setting, modification, and deletion of information, and routes packet data. Furthermore, the P-GW is further connected to the operator's IP services via the SGi interface.

[0040]

[0049] The Home Subscriber Server (HSS) is a core database that stores subscriber information within the subscriber's home network. The HSS mainly includes user profiles, user subscription data, information related to user identification, authentication and authorization, and information related to the user's physical location, etc. The HSS is connected to the MME via the S6a interface. As a result, the MME can obtain information such as the aforementioned user profiles and user subscription data from the HSS.

[0041]

[0050] The Policy and Charging Rules Function (PCRF) unit is a policy decision node for policy and charging control of service data flows and IP bearer resources. Here, the quality of service (QoS) for users can be controlled, and differentiated services may be provided to users. The PCRF is connected to the P-GW via the Gx interface and to the operator's IP services via the Rx interface.

[0042]

[0051] Furthermore, the MME is connected to the E-UTRAN via the S1-MME interface, and the S-GW is connected to the E-UTRAN and the MME via the S1-U interface and the S11 interface respectively. The MME and the S-GW are connected to the 2G / 3G and the SGSN via the S3 interface and the S4 interface respectively, and are responsible for the functions of the mobility control plane anchor and the user plane anchor of the terminal device between the corresponding networks. Furthermore, the S-GW is further connected to the evolved universal terrestrial radio access network (UTRAN) via the S12 interface.

[0043]

[0052] It should be noted that the figure of the foregoing 4G network architecture is merely an example. In an actual network, there may be multiple network elements of the same type, for example, multiple access network devices, multiple MMEs, and multiple PCRFs. Among multiple network elements of the same type, some network elements may be upgraded (in the embodiments of this application, the term "upgraded" is used to indicate that a network element supports an on-demand user plane security protection mechanism, and the details are not described below), while some network elements are not upgraded (or the network element may be called a legacy network element (legacy NE) or an NE that does not support on-demand user plane security protection). For example, an upgraded MME and an un-upgraded MME may coexist in the network.

[0044]

[0053] Another scenario where the security policy processing method provided in this application is applicable is a scenario for interworking between a 4G network and a 5G network. As shown in Figure 1B, the 4G network and the 5G network include a user plane function (UPF) entity + a PDN gateway user plane function (PGW-U) entity, a session management function (SMF) entity + a PDN gateway control plane function (PGW-C) entity, Policy control function (PCF) entity + Policy and charging rules function (PCRF) entity, and Home Subscriber Server (HSS) + Unified Data Management (UDM) entity are shared. Here, the "+" indicates co-location.

[0045] UPF is a user plane function of the 5G network, and PGW-U is a gateway user plane function of the 4G network corresponding to UPF.

[0046] SMF is a session management function of the 5G network, and PGW-C is a gateway control plane function of the 4G network corresponding to SMF.

[0047] PCF is a policy control function of the 5G network, and PCRF is a policy and charging rules function of the 4G network corresponding to PCF. Here, "co-location" may indicate that one device has the functions of two entities simultaneously. In the embodiments of this application, for ease of explanation, the HSS + UDM entity is called the user data management entity, and the PGW-C entity + SMF entity is called the control plane function entity. This is described here and will not be described again below. Of course, the aforementioned network devices obtained through co-location may alternatively use another name. This is not particularly limited in the embodiments of this application.

[0048]

[0054] Further, as shown in FIG. 1B, the architecture for the interoperability between the 4G network and the 5G network may further include an MME, a serving gateway, and an access and mobility management function (AMF) entity within the 5G network.

[0049]

[0055] The function of the MME is the same as that of the MME in the 4G network, and the details will not be described again here.

[0050]

[0056] The AMF entity is used for user access and mobility management and mainly includes user registration management, reachability management, mobility management, paging management, access authentication and authorization, encryption and integrity protection of non-access stratum signaling, etc.

[0051]

[0057] The SMF entity is used for user session management and mainly includes user session establishment, modification, and release, IP address allocation, session policy management, etc.

[0052]

[0058] The terminal device accesses the 4G network via an evolved universal terrestrial radio access network (E-UTRAN) device, and the terminal accesses the 5G network via a next generation radio access network (NG-RAN) device. The E-UTRAN device communicates with the MME via the S1-MME interface and communicates with the SGW via the S1-U interface. The MME communicates with the SGW via the S11 interface, communicates with the user data management entity via the S6a interface, and communicates with the AMF entity via the N26 interface. The SGW communicates with the PGW-U entity + UPF entity via the S5-U interface and communicates with the PGW-C entity + SMF entity via the S5-C interface. The PGW-U entity + UPF entity communicates with the NG-RAN device via the N3 interface and communicates with the PGW-C entity + SMF entity via the N4 interface. The PGW-C entity + SMF entity communicates with the PCRF entity + PCF entity via the N7 interface. The HSS + UDM entity communicates with the PGW-C entity + SMF entity via the N10 interface and communicates with the AMF entity via the N8 interface. The PCRF entity + PCF entity communicates with the AMF entity via the N15 interface. The PGW-C entity + SMF entity communicates with the AMF entity via the N11 interface. The AMF entity communicates with the NG-RAN device via the N2 interface and communicates with the terminal via the N1 interface.

[0053]

[0059] It should be noted that the names of the interfaces between network elements in FIG. 1B are merely examples. In a specific implementation, the interface names may be other names. This is not particularly limited in this embodiment of the present application.

[0054]

[0060] Certainly, there may be other network elements in the architecture for interoperability between 4G and 5G networks. For example, the 4G network may further include a serving general packet radio system (GPRS) support node (SGSN). The 5G network may potentially further include an authentication server function (AUSF) entity, a network slice selection function (NSSF) entity, etc. This is not particularly limited in this embodiment of the present application.

[0055]

[0061] It should be noted that the above architecture for interoperability between 4G and 5G networks is merely an example. In an actual network, there may be multiple network elements of the same type, such as multiple access network devices and multiple MMEs. Among the multiple network elements of the same type, some network elements may have been upgraded, while some may not have been upgraded. For example, in the architecture for interoperability between 4G and 5G networks, both upgraded and non-upgraded MMEs may exist.

[0056]

[0062] The access network device in the embodiment of this application is a bridge between a terminal device and a core network device and is used for wireless resource management and the like. The terminal device can access the network via the access network device. The access network device in this application may be a 4G wireless access network device, or may be a device that communicates with a wireless terminal device through an air interface in a 4G access network via one or more cells. For example, the access network device may be an evolved NodeB (NodeB, eNB, or e-NodeB) in a Long Term Evolution (LTE) system or a Long Term Evolution Advanced (LTE-A) system. Alternatively, the access network device may be a 5G wireless access network device, and may include, for example, an NG-RAN device, a Next Generation E-UTRAN NodeB (ng-eNB), or a 5G base station (gNodeB, gNB). It should be noted that the access network device in this application may be an upgraded access network device (for example, an access network device that supports on-demand user plane security protection) or an un-upgraded access network device (for example, an access network device that does not support on-demand user plane security protection).Furthermore, based on different sequences for providing services to the terminal device, the source access network device may be understood as the access network device that provides services to the terminal device before the handover procedure. For example, during the initial access by the terminal device, it may be the access network device that provides services to the terminal device; and the target access network device may be understood as the access network device that provides services to the terminal device after the handover procedure. Usually, the context of the terminal device is transmitted between the source access network device and the target access network device. It should be understood that the access network device in the embodiments of this application may be any one of the aforementioned devices, or a chip within the aforementioned devices. This is not particularly limited in this case. Whether it is a device or a chip, the access network device can be manufactured, sold, or used as an independent product. In this embodiment and subsequent embodiments, the access network device is used as an example for illustration.

[0057]

[0063] Furthermore, the terminal device in the embodiment of the present application includes a device that provides a voice and / or data connection to the user. For example, the terminal device may include a mobile device having a wireless connection function, or a processing device connected to a wireless modem. The terminal device can communicate with the core network via a radio access network RAN (e.g., the aforementioned source access network device or the aforementioned target access network device), and can exchange voice and / or data with the RAN. The terminal device may include a user equipment UE, a wireless terminal device, a mobile terminal device, a subscriber unit, a subscriber station, a mobile station, a mobile, a remote station, an access point (AP), a remote terminal device, an access terminal device, a user terminal device, a user agent, a user device, etc. Furthermore, the terminal device may alternatively be an in-vehicle terminal, e.g., a telematics box (T-Box), a domain controller (DC), a multi-domain controller (MDC), or an on-board unit (OBU) that is incorporated into a vehicle. The terminal device may alternatively be a wearable device such as glasses, gloves, a watch, clothing, and shoes, or other portable devices that can be directly worn on the body or incorporated into the user's clothing or accessories. This is not particularly limited in the present application. It should be understood that the terminal device in the embodiment of the present application may be any one of the aforementioned devices or chips. This is not particularly limited in this case.The terminal device can be manufactured, sold, or used as an independent product, whether it is a device or a chip. In this embodiment and subsequent embodiments, only the terminal device is used as an example for explanation.

[0058]

[0064] Since there may be core network elements in the network that do not support on-demand user plane security protection, in the on-demand user plane security protection procedure that requires the inclusion of core network elements, the access network device may not have obtained the parameters (e.g., user plane security policy) necessary to perform on-demand user plane security activation. Therefore, the function of on-demand user plane security activation between the access network device and the terminal device cannot be performed.

[0059]

[0065] Hereinafter, the names or terms used in the embodiments of this application will be described.

[0060]

[0066] The user plane security policy includes a user plane encryption protection policy and a user plane integrity protection policy. The user plane encryption protection policy indicates whether to activate user plane encryption protection. The user plane integrity protection policy indicates whether to activate user plane integrity protection. There are three possible values for the user plane encryption protection policy, namely: not required, preferred, and required. There are also three possible values for the user plane integrity protection policy, namely: not required, preferred, and required. "Not required" indicates that protection activation is not necessary, "preferred" indicates that protection may or may not be activated, and "required" indicates that protection activation is necessary. Each of the above three possible values may be specified by using 2 bits (bit). For example, 00 indicates that protection activation is not necessary, 01 indicates that protection may or may not be activated, and 11 indicates that protection activation is required. The specific method by which the three possible values are specified for the user plane encryption protection policy and the user plane integrity protection policy is not limited in the embodiments of this application.

[0061]

[0067] User plane encryption protection means protecting the confidentiality of data during transmission (thus, it may also be called user plane confidentiality protection), where confidentiality means that the actual content cannot be directly viewed. User plane integrity protection means protecting the integrity of data during transmission in the user plane, where integrity means that the data is original and has not been tampered with.

[0062]

[0068] In an on-demand user plane security protection mechanism, an access network device can determine whether to perform on-demand user plane security protection between the access network device and the terminal device according to the user plane security policy of the terminal device. When the value of the user plane encryption protection policy / user plane integrity protection policy indicates "not required", the access network device determines not to activate the user plane encryption protection / user plane integrity protection between the access network device and the terminal device according to the user plane encryption protection policy / user plane integrity protection policy. When the value of the user plane encryption protection policy / user plane integrity protection policy indicates "required", the access network device determines to activate the user plane encryption protection / user plane integrity protection between the access network device and the terminal device according to the user plane encryption protection policy / user plane integrity protection policy. When the value of the user plane encryption protection policy / user plane integrity protection policy indicates "preferred", the access network device determines whether to activate the user plane encryption protection / user plane integrity protection between the access network device and the terminal device according to the user plane encryption protection policy / user plane integrity protection policy and other information (for example, the load status of the access network device) (for example, when the load is greater than the threshold, the access network device does not activate the user plane encryption protection / user plane integrity protection; or when the load is below the threshold, the access network device activates the user plane encryption protection / user plane integrity protection).

[0063]

[0069] The user plane security activation status indicates whether user plane encryption protection and / or user plane integrity protection is activated. This may be understood as follows: The user plane security activation status may be the result of the access network device determining whether user plane encryption protection / user plane integrity protection is activated or not according to the user plane security policy of the terminal device.

[0064]

[0070] When the on-demand user plane security mechanism is applied to a 4G network, the MME needs to obtain the user plane security policy of the terminal device and may transfer the user plane security policy to the access network device. If the MME is a legacy MME, the access network device may fail to obtain the user plane security policy of the terminal device, and thus, on-demand user plane security activation cannot be implemented. In particular, in a handover scenario, there may be a problem that user plane security protection is weakened.

[0065]

[0071] As shown in FIG. 2, a security policy processing method is provided to implement a best-effort on-demand user plane security activation mechanism in a handover scenario.

[0066]

[0072] S201: The terminal device accesses Network #1 via the source access network device #10-1, and the source access network device #10-1 determines that the terminal device needs to be handed over to the target access network device #20-1.

[0067]

[0073] In particular, the handover needs to be performed via the core network device. For example, the handover may be an S1 handover or a 5GS-to-EPS handover. The source access network device can initiate the handover based on trigger conditions. For example, the conditions may include: no X2 connection to the target access network, X2 handover failure, whether the source access network device should trigger the handover based on the current execution status, insufficient current radio network status, load balance, or voice service conditions.

[0068]

[0074] If Network #1 is a 4G network, the source access network device #10-1 may be an access network device within the 4G network, for example, it may be an evolved access network eNB or an evolved universal terrestrial radio access network E-UTRAN. If Network #1 is a 5G network, the source access network device #10-1 may be an access network device within the 5G network, for example, it may be a next-generation radio access network NG-RAN.

[0069]

[0075] It should be noted that this step is optional in this embodiment of the present application.

[0070]

[0076] S202: The source access network device #10-1 sends message #50-1 to the core network device #30-1. As a result, the core network device #30-1 receives message #50-1 from the source access network device #10-1.

[0071]

[0077] Message #50-1 includes an identifier of a terminal device and container information. The identifier of the terminal device is used to identify the terminal device. As a result, the core network device #30-1 obtains the access stratum (AS) context of the terminal device based on the identifier of the terminal device. The container information is generated by the source access network device #10-1 and is finally transferred to the target access network device #20-1. The content within the container information is not parsed by intermediate network elements (e.g., core network device #2). For example, the container information may be a source eNB to target eNB transparent container. The container information may include the user plane security policy #40-1 of the terminal device.

[0072]

[0078] Message #50-1 may be, for example, a handover request message, and is also for requesting the target access network device #20-1 to prepare handover resources of the terminal.

[0073]

[0079] In a possible implementation, the source access network device #10-1 can determine whether to include the user plane security policy #40-1 in the container information according to whether the terminal device supports on-demand user plane security protection. For example, the source access network device #10-1 includes the user plane security policy #40-1 in the container information only when the terminal device supports on-demand user plane security protection. Specifically, the source access network device #10-1 determines whether the terminal device supports on-demand user plane security protection based on the AS context of the terminal device. For example, the AS context of the terminal device may include instruction information / capability information indicating whether the terminal device supports on-demand user plane security protection, or may include information regarding the current user plane security activation status between the source access network device #10-1 and the terminal device. The source access network device #10-1 can determine whether the terminal device supports on-demand user plane security protection based on the information included in the AS context of the terminal device.

[0074]

[0080] As an option, the user plane security policy #40-1 may be the user plane security policy currently used by the source access network device #10-1 together with the terminal device. For example, the user plane security policy #40-1 may be the user plane security policy in the context of the terminal device in the source access network device #10-1. In a possible implementation, when the terminal device accesses the network #1 via the source access network device #10-1, the source access network device #10-1 can obtain the user plane security policy #40-1 from the network side and store the user plane security policy #40-1 in the AS context of the terminal device. The user plane security policy #40-1 may be, for example, the subscribed user plane security policy (subscribed UP security policy) of the terminal device.

[0075]

[0081] When determining to start a handover, the source access network device can obtain the stored user plane security policy #40-1 from the AS context of the terminal device.

[0076]

[0082] S203: The core network device #30-1 obtains the user plane security policy #40-2 of the terminal device.

[0077]

[0083] The core network device #30-1 obtains the user plane security policy #40-2 from the non-access stratum (NAS) context of the terminal device based on the identifier of the terminal device in the message #50-1.

[0078]

[0084] It should be noted that S203 is optional. In a possible implementation, if the core network device #30-1 is a legacy network element, specifically, if it does not support an on-demand user plane security mechanism, this step may fail to execute.

[0079]

[0085] S204: The core network device #30-1 sends message #50-2 to the target access network device #20-1. As a result, the target access network device #20-1 receives message #50-2 from the core network device #30-1.

[0080]

[0086] Message #50-2 contains container information. Optionally, when S203 is executed, message #50-2 further includes the user plane security policy #40-2.

[0081]

[0087] Optionally, message #50-2 further includes indication information, where the indication information indicates whether the terminal device supports on-demand user plane security protection. Optionally, the indication information may be specified by a part of the bits of the security capabilities of the terminal device, and the security capabilities of the terminal device indicate at least one security algorithm that can be used by the terminal device. For example, the security capabilities of the terminal device are UE evolved packet system security capabilities (UE EPS security capabilities), and the indication information may be specified by using reserved bits in the security capabilities of the terminal device, such as EEA7 or EIA7. EEA7 represents the bits reserved for the eighth encryption algorithm in the UE evolved packet system security capabilities, and EIA7 represents the bits reserved for the eighth integrity algorithm in the UE evolved packet system security capabilities. Here, in this embodiment, the bits are used to carry an indication indicating whether the terminal device supports on-demand user plane security protection.

[0082]

[0088] Message #50-2 may be a handover request message, and the handover request message is for requesting the target access network device to prepare the handover resources of the terminal device.

[0083]

[0089] S205: The target access network device #20-1 activates user plane security protection based on message #50-2.

[0084]

[0090] Specifically, when message #50-2 does not include user plane security policy #40-2 but the container information includes user plane security policy #40-1, target access network device #20-1 determines the user plane security activation status between target access network device #20-1 and the terminal device according to user plane security policy #40-1 in the container information.

[0085]

[0091] When message #50-2 includes user plane security policy #40-2, target access network device #20-1 determines the user plane security activation status between target access network device #20-1 and the terminal device according to user plane security policy #40-2.

[0086]

[0092] Optionally, when message #50-2 includes user plane security policy #40-2 and the container information includes user plane security policy #40-1, target access network device #20-1 ignores user plane security policy #40-1 and determines the user plane security activation status between target access network device #20-1 and the terminal device according to user plane security policy #40-2.

[0087]

[0093] As an option, when message #50-2 includes user plane security policy #40-2 and the container information includes user plane security policy #40-1, target access network device #20-1 determines whether user plane security policy #40-2 matches user plane security policy #40-1. If user plane security policy #40-2 matches user plane security policy #40-1, target access network device #20-1 determines the user plane security activation status between target access network device #20-1 and the terminal device according to user plane security policy #40-2. If user plane security policy #40-2 does not match user plane security policy #40-1, any one of the following operations can be performed.

[0088] 1. Target access network device #20-1 cancels the handover procedure. Specifically, target access network device #20-1 sends a handover failure message to core network device #30-1, indicating that core network device #30-1 has failed to prepare handover resources. As an option, a cause value may be carried in the handover failure message. The cause value may indicate the cause of the handover failure, for example, an inaccurate user plane security policy or a security risk.

[0089] 2. The target access network device #20-1 determines the user plane security activation status between the target access network device #20-1 and the terminal device still according to the user plane security policy #40-2, and generates one piece of alarm information. Optionally, the target access network device #20-1 can notify the core network device #30-1 of the alarm information. The alarm information indicates the trust level of the source access network device #10-1. It can be understood that the alarm information may indicate that the source access network device #10-1 is in an unsafe environment. Then, when performing related operations, the target access network device #20-1 or the core network device #30-1 may refer to the alarm information. For example, in the handover procedure, the handover to the source access network device #10-1 is avoided as much as possible.

[0090] 3. The target access network device #20-1 selects the user plane security policy with a higher security level from the user plane security policy #40-1 and the user plane security policy #40-2, and determines the user plane security activation status between the target access network device #20-1 and the terminal device. "Required" has the highest security level, followed by "Priority", and "Not required" is considered to have the lowest security level.

[0091] 4. The target access network device #20-1 selects a user plane security policy that has the least impact on performance from the user plane security policy #40-1 and the user plane security policy #40-2, and determines the user plane security activation status between the target access network device #20-1 and the terminal device. It is considered that "not required" has the least impact on performance, followed by "priority", and "priority" has the greatest impact on performance.

[0092] 5. The target access network device #20-1 selects the most well-balanced user plane security policy from the user plane security policy #40-1 and the user plane security policy #40-2, and determines the user plane security activation status between the target access network device #20-1 and the terminal device. "Priority" is considered to be the most well-balanced.

[0093]

[0094] In another possible implementation, the message #50-2 may not include the user plane security policy #40-2, and the container information may not include the user plane security policy #40-1. In this case, the target access network device #20-1 can determine the user plane security activation status between the target access network device #20-1 and the terminal device according to a preset user plane security policy #40-3.

[0094]

[0095] In another possible implementation, the target access network device #20-1 further receives indication information from the core network device 30-1. The target access network device #20-1 further determines the user plane security activation status between the target access network device #20-1 and the terminal device in the manner described by the aforementioned methods (1) to (5) only when the indication information indicates that the terminal device supports on-demand user plane security protection.

[0095]

[0096] The user plane security activation status indicates whether user plane encryption protection and / or user plane integrity protection is activated.

[0096]

[0097] It should be noted that the core network device #30-1 in this embodiment of the present application is a general concept and may refer to one or more network elements within the core network. For example, the core network device #30-1 may include one MME in a 4G network, or may include two MMEs in a 4G network, or may include one MME in a 4G network and one AMF in a 5G network. The expression form of the core network device #30-1 is not limited in the embodiments of the present application.

[0097]

[0098] In this embodiment of the present application, if the terminal device and the target access network device #20-1 support an on-demand user plane security protection mechanism, the core network device #30-1 is upgraded (specifically, supports the on-demand user plane security protection mechanism). Regardless of whether it is upgraded or not, the target access network device #20-1 can always obtain the corresponding user plane security policy and determine the user plane security activation status between the target access network device #20-1 and the terminal device. In particular, according to the solution in this embodiment of the present application, the problem of undercutting attacks can be more effectively avoided. For example, the source access network device #10-1 may be attacked and does not send the user plane security policy #40-1 to the core network device #30-1, or sends a user plane security policy with a low security level (for example, a user plane security policy indicating that neither user plane encryption protection nor user plane integrity protection should be activated) to the core network device #30-1. In this case, the target access network device #20-1 can preferentially use the user plane security policy #40-2 from the core network device #30-1 to avoid related attacks.

[0098]

[0099] As shown in FIG. 3, based on the architecture of FIG. 1A, a security policy processing method is provided, which implements a best-effort on-demand user plane security activation mechanism in a handover scenario.

[0099]

[0100] Hereinafter, as an example of further explanation, the S1 handover procedure shown in FIG. 3 is used. The access network device in the 4G network (here, for ease of explanation, the target eNB is used as an example in this embodiment of the present application) is the implementation form of the aforementioned target access network device #20-1. Another access network device in the 4G network (for ease of explanation, the source eNB is used as an example in this embodiment of the present application) is the implementation form of the aforementioned source access network device #10-1. The target MME and the source MME are the implementation forms of the core network device #30-1. Also, assume that the target eNB is an upgraded eNB (specifically, an eNB that supports on-demand user plane security protection). The aforementioned devices perform the following steps.

[0100]

[0101] S301: The terminal device accesses the 4G network via the source eNB, and the source eNB determines to initiate an S1 interface-based handover to hand over the terminal device to the target eNB.

[0101]

[0102] In the process of the terminal device accessing the 4G network, the source eNB obtains the user plane security policy of the terminal device from the core network side, and activates the user plane security between the source eNB and the terminal device according to the user plane security policy. The source eNB further stores the obtained user plane security policy in the access stratum (AS) context of the terminal device.

[0102]

[0103] For example, the terminal device sends an attach request message to the initial MME via the initial eNB. Next, the initial MME sends the identifier of the terminal device to the HSS by using an update location request message. The HSS sends an update location request acknowledge message to the initial MME. The update location request acknowledge message carries the subscription data of the terminal device, and the subscription data includes the subscription user plane security policy of the terminal device. The initial MME stores the subscription user plane security policy in the non-access stratum (NAS) context of the terminal device. The initial MME sends the subscription user plane security policy to the initial eNB in an initial context setup request message. The initial eNB stores the subscription user plane security policy in the AS context of the terminal device.

[0103]

[0104] After the terminal device accesses the 4G network, if the access network device is not changed, the initial eNB here is the source eNB; or if the access network device is changed, the initial eNB and the source eNB here are different access network devices. In this case, the source eNB can obtain the AS context of the terminal device from the initial eNB.

[0104]

[0105] After the terminal device accesses the 4G network, if the MME is not changed, the initial MME here is the source MME; or if the MME is changed, the initial MME and the source MME here are different MMEs. In this case, the source MME can obtain the NAS context of the terminal device from the initial MME.

[0105]

[0106] If no attack has occurred or the context transfer (AS context between access network devices or NAS context between MMEs) is normal, it can be understood from the above procedure that the user plane security policy in the source eNB (i.e., user plane security policy #40-1) should match the user plane security policy in the source MME (i.e., user plane security policy #40-2). A possible cause of the abnormality is that the access network device or MME has not been upgraded.

[0106]

[0107] If the source eNB determines that the terminal device needs to be handed over to the target eNB, the S1 handover may be triggered based on the following conditions: (1) There is no X2 interface between the source eNB and the target eNB.

[0107] (2) The source eNB fails to perform an X2 handover to the target eNB and the source eNB receives an error indication from the target eNB.

[0108] (3) Information dynamically learned by the source eNB, configuration information of the source eNB, etc.

[0109]

[0108] S302: The source eNB sends a handover required message to the source MME.

[0110]

[0109] The handover required message carries the identifier of the terminal device and container information (source eNB to target eNB transparent container). The identifier of the terminal device, for example, eNB UE S1AP ID and MME UE S1AP ID, is for obtaining the context of the terminal device.

[0111]

[0110] The container information is generated by the source eNB, and finally transferred to the target eNB, and is not analyzed by intermediate network elements (such as the source MME and the target MME).

[0112]

[0111] The container information includes, as an option, the user plane security policy of the terminal device (i.e., user plane security policy #40-1) stored by the source eNB.

[0113]

[0112] For specific cases, please refer to the relevant description in S202. Details will not be described again here.

[0114]

[0113] S303: The source MME acquires the user plane security policy #40-2 of the terminal device.

[0115]

[0114] This step is the same as S203, and details will not be described again here.

[0116]

[0115] S304: The source MME sends a forward relocation request message to the target MME.

[0117]

[0116] The forward relocation request message carries the container information. In particular, the source MME does not analyze the container information and directly transfers the container information.

[0118]

[0117] The transfer relocation request message can further carry the user plane security policy of the terminal device (i.e., user plane security policy #40-2) stored by the source MME. For example, the source MME obtains the NAS context of the terminal device based on the identifier of the terminal device, and obtains the user plane security policy #40-2 from the NAS context of the terminal device.

[0119]

[0118] Optionally, the transfer relocation request message further includes indication information, where the indication information indicates whether the terminal device supports on-demand user plane security protection. Optionally, if the source MME is a legacy MME, the source MME may not locally store the user plane security policy, and thus does not send the user plane security policy to the target MME.

[0120]

[0119] For related content, such as the related description of the indication information, please refer to the related description in S204. Details are not described again here.

[0121]

[0120] S305: The target MME sends a handover request message to the target eNB.

[0122]

[0121] The handover request message is used to request the target eNB to prepare the handover resources of the terminal device.

[0123]

[0122] The handover request message carries container information. Optionally, the handover request message may further carry the user plane security policy #40-2 of the terminal device and may optionally carry indication information.

[0124]

[0123] If the target MME is a legacy MME, it should be noted that the target MME may not send the user plane security policy #40-2 to the target eNB. This is because the legacy MME may fail to identify the information element. As a result, the legacy MME discards the information element or cannot process it.

[0125]

[0124] S306: The target eNB determines the user plane security activation status, where the user plane security activation status indicates whether to activate user plane encryption protection and / or user plane integrity protection.

[0126]

[0125] In option implementation (1), when the handover request message carries the user plane security policy #40-2 of the terminal device, the target eNB determines the user plane security activation status between the target eNB and the terminal device according to the user plane security policy #40-2. It should be understood that when the handover request message carries the user plane security policy #40-2 of the terminal device, even if the container information carries the user plane security policy #40-1, the target eNB ignores the user plane security policy #40-1. The target eNB determines the user plane security activation status between the target eNB and the terminal device according to the user plane security policy #40-2.

[0127]

[0126] In the implementation of option (2), when the handover request message does not carry the user plane security policy #40-2 of the terminal device but the container information carries the user plane security policy #40-1, the target eNB determines the user plane security activation status between the target eNB and the terminal device according to the user plane security policy #40-1.

[0128]

[0127] In the implementation of option (3), when the handover request message carries the user plane security policy #40-2 of the terminal device and the container information carries the user plane security policy #40-1, the target eNB compares the user plane security policy #40-1 with the user plane security policy #40-2. When the user plane security policy #40-1 matches the user plane security policy #40-2, the target eNB determines the user plane security activation status between the target eNB and the terminal device according to the user plane security policy #40-2. Alternatively, when the user plane security policy #40-1 does not match the user plane security policy #40-2, the target eNB starts the handover cancellation procedure.

[0129]

[0128] In another implementation of option (4), if the handover request message does not carry the user plane security policy #40-2 of the terminal device, the container information does not carry the user plane security policy #40-1, and the user plane security policy #40-3 is pre-configured in the target eNB, the target eNB determines the user plane security activation status between the target eNB and the terminal device according to the user plane security policy configured in the target eNB.

[0130]

[0129] In another implementation of option (5), the target eNB further receives indication information from the target MME. The target eNB further determines the user plane security activation status between the target eNB and the terminal device by the method described in the above methods (1) to (4) only when the indication information indicates that the terminal device supports on-demand user plane security protection.

[0131]

[0130] In another implementation of option (6), if the handover request message does not carry the user plane security policy #40-2 of the terminal device and the container information does not carry the user plane security policy #40-1, the target eNB can determine the user plane security activation status of the terminal device in an un-upgraded manner. Specifically, encryption protection is always activated, but integrity protection is not activated.

[0132]

[0131] For additional methods for the target eNB to determine the user plane security policy used between the target eNB and the terminal device for the above six implementations, please further refer to the relevant description in S205. Details are not described again here.

[0133]

[0132] S307: The target eNB sends a handover request acknowledge message to the target MME.

[0134]

[0133] The handover request acknowledge message includes a radio resource control (RRC) connection reconfiguration, which is constructed by the target eNB.

[0135]

[0134] Optionally, the RRC connection reconfiguration conveys configuration information, which indicates whether the terminal device activates user-plane encryption protection and / or user-plane integrity protection. Optionally, the configuration information is determined by the user-plane security activation status in S306.

[0136]

[0135] Specifically, if the ciphering disabled field is encapsulated in the configuration information, the terminal device does not activate encryption protection; or if the ciphering disabled field is not encapsulated in the configuration information, the terminal device activates encryption protection. If the integrity protection field is encapsulated in the configuration information, the terminal device activates integrity protection; or if the integrity protection field is not encapsulated in the configuration information, the terminal device does not activate integrity protection.

[0137]

[0136] The target eNB should be understood to encapsulate the user plane security activation status within the RRC connection reconfiguration by using the configuration information, and send the RRC connection reconfiguration to the source eNB by using the handover request acknowledgement. Then, the source eNB transfers the RRC connection reconfiguration in which the user plane security activation status is encapsulated to the terminal device.

[0138]

[0137] S308: The target MME sends a forward relocation response message to the source MME.

[0139]

[0138] The forward relocation response message includes the aforementioned RRC connection reconfiguration, and the RRC connection reconfiguration carries the configuration report.

[0140]

[0139] S309: The source MME sends a handover command message to the source eNB.

[0141]

[0140] The handover command message includes the aforementioned RRC connection reconfiguration, and the RRC connection reconfiguration carries the configuration information.

[0142]

[0141] S310: The source eNB sends the RRC connection reconfiguration to the terminal device.

[0143]

[0142] In other words, the source eNB transfers the RRC connection reconfiguration received from the target eNB to the terminal device.

[0144]

[0143] Specifically, the terminal device determines whether to activate user-plane encryption protection / user-plane integrity protection between the terminal device and the target eNB based on the configuration information carried in the RRC connection reconfiguration.

[0145]

[0144] For example, the terminal device determines that the ciphering disabled field and the integrity protection field are not encapsulated in the configuration information. Therefore, the terminal device activates encryption protection but does not activate integrity protection. The terminal device determines that the ciphering disabled field is encapsulated in the configuration information, but the integrity protection field is not encapsulated in the configuration information. Therefore, the terminal device does not activate encryption protection and does not activate integrity protection either. The terminal device determines that the ciphering disabled field is not encapsulated in the configuration information, but the integrity protection field is encapsulated in the configuration information. Therefore, the terminal device activates both encryption protection and integrity protection. The terminal device determines that the ciphering disabled field and the integrity protection field are encapsulated in the configuration information. Therefore, the terminal device does not activate encryption protection but activates integrity protection.

[0146]

[0145] S311: The terminal device sends an RRC connection reconfiguration complete message to the target eNB.

[0147]

[0146] The "RRC connection reconfiguration Complete" message indicates to the target eNB that the terminal device has completed the RRC connection reconfiguration procedure and has successfully handed over from the source eNB to the target eNB. After that, the terminal device can communicate directly with the target eNB.

[0148]

[0147] In this embodiment of the present application, regardless of whether the source eNB, the source MME, or the target MME is upgraded, the target eNB can obtain an available user-plane security policy and determine the user-plane security protection status between the target eNB and the terminal device according to the obtained user-plane security policy. This avoids the problem that the on-demand user-plane security mechanism cannot be implemented because the user-plane security policy is lost due to some un-upgraded network elements in the source eNB, the source MME, or the target MME within the 4G network. Further, in this embodiment of the present application, the target eNB can further obtain a security policy with the highest possible priority and best-effort guarantee whether user-plane security protection is activated or not for the terminal device according to the most prioritized user-plane security policy in the handover process, and as a result, potential undercutting attacks are avoided.

[0149]

[0148] As shown in FIG. 4, based on the architecture of FIG. 1B, a security policy processing method is provided to implement a best-effort on-demand user-plane security activation mechanism in a 5GS-to-EPS handover scenario.

[0150]

[0149] An access network device in a 4G network (here, for ease of explanation, in this embodiment of the present application, the target eNB is used as an example and is abbreviated as eNB in the following description of this embodiment) is an implementation form of the aforementioned target access network device. An access network device in a 5G network (here, for ease of explanation, in this embodiment of the present application, the source NG-RAN is used as an example and is abbreviated as NG-RAN in the following description of this embodiment) is an implementation form of the aforementioned source access network device. A core network device in a 5G network (here, for ease of explanation, in this embodiment of the present application, the source AMF is used as an example and is abbreviated as source AMF in the following description of this embodiment) and a core network device in a 4G network (here, for ease of explanation, in this embodiment of the present application, the target MME is used as an example and is abbreviated as MME in the following description of this embodiment) are implementation forms of the aforementioned core network device #30-1. Also, assume that the eNB is an upgraded eNB (specifically, an eNB that supports on-demand user plane security protection). The aforementioned devices perform the following steps.

[0151]

[0150] S401: The terminal device accesses the 5G network via the NG-RAN, and the NG-RAN determines to initiate a 5GS-to-EPS handover to hand over the terminal device to the eNB in the 4G network.

[0152]

[0151] In the process of a terminal device accessing a 5G network, the NG-RAN obtains the user plane security policy of the terminal device from the core network side and activates the user plane security between the NG-RAN and the terminal device according to the user plane security policy. The NG-RAN further stores the obtained user plane security policy in the access stratum (AS) context of the terminal device.

[0153]

[0152] For example, the terminal device sends a protocol data unit (PDU) session setup request message to the NG-RAN. The NG-RAN sends the PDU session setup request to PWG-C+SMF via the AMF. PWG-C+SMF may obtain the subscribed user plane security policy of the terminal device from the HSS+UDM, or may obtain the user plane security policy from the local configuration information of the PWG-C+SMF. The user plane security policy obtained by the PWG-C+SMF is the user plane security policy of the terminal device, specifically, it may be the user plane security policy specific to the PDU session. The PWG-C+SMF can store the subscribed user plane security policy obtained from the HSS+UDM in the context of the terminal device. The PWG-C+SMF sends the obtained user plane security policy to the NG-RAN via the AMF. The NG-RAN stores the subscribed user plane security policy in the AS context of the terminal device.

[0154]

[0153] Therefore, in a normal case, the user plane security policy stored in the NG-RAN should be consistent with the user plane security policy stored in the PWG-C+SMF.

[0155]

[0154] If the source NG-RAN determines that the terminal device needs to be handed over to the target eNB, the 5GS-to-EPS handover may be triggered based on the following conditions.

[0156] (1) Poor current radio access state; (2) Load balancing; and (3) Voice service conditions.

[0157]

[0155] S402: The NG-RAN sends a handover required message to the AMF.

[0158]

[0156] The handover required message carries the identifier of the terminal device and container information. The identifier of the terminal device, such as the RAN UE NGAP ID and the AMF UE NGAP ID, is for obtaining the context of the terminal device.

[0159]

[0157] The container information is generated by the NG-RAN and ultimately transferred to the eNB, and is not parsed by intermediate network elements including the AMF and the MME. For related explanations, refer to the related explanations in S202 and S302. Details are not explained again here.

[0160]

[0158] S403: The AMF sends a PDU session context request message to the PGW-C + SMF.

[0161]

[0159] The PDU session context request message may include the context identifier of the terminal device, and the context identifier of the terminal device, such as the Session Management Context ID, may be obtained based on the identifier of the terminal device.

[0162]

[0160] S404: The PGW-C + SMF obtains the user plane security policy #40-3 of the terminal device.

[0163]

[0161] Specifically, the PGW-C + SMF obtains the user plane security policy #40-3 of the terminal device based on the context identifier of the terminal device. The user plane security policy #40-3 may be the user plane security policy stored in the context of the terminal device, or may be the user plane security policy obtained by mapping according to the user plane security policy stored in the context of the terminal device.

[0164]

[0162] It should be understood that if the PGW-C + SMF is a non-upgraded core network device, the PGW-C + SMF may not execute S404.

[0165]

[0163] S405: The PGW-C + SMF sends a PDU session context response message to the AMF.

[0166]

[0164] The PDU session context response message includes the user plane security policy #40-3 of the terminal device.

[0167]

[0165] It should be understood that if the PGW-C + SMF is a non-upgraded core network device, the PDU session context response message may not be carried to the user plane security policy #40-3.

[0168]

[0166] S406: The AMF sends a forward relocation request message to the MME.

[0169]

[0167] S407: The MME sends a handover request message to the eNB.

[0170]

[0168] S408: The eNB determines the user plane security activation status.

[0171]

[0169] S409: The eNB sends a handover request acknowledge message to the MME.

[0172]

[0170] S410: The MME sends a forward relocation response message to the AMF.

[0173]

[0171] S411: The AMF sends a handover command message to the eNB.

[0174]

[0172] S412: The NG-RAN sends an RRC connection reconfiguration to the terminal device.

[0175]

[0173] S413: The terminal device sends an RRC connection reconfiguration complete message to the eNB.

[0176]

[0174] The descriptions related to S406 to S413 are the same as those in S304 to S311. Please refer to the above descriptions. Details will not be elaborated here again.

[0177]

[0175] In this embodiment of the present application, regardless of whether the PGW-C + SMF and the MME are upgraded, the eNB can obtain an available user plane security policy and determine the user plane security protection status between the eNB and the terminal device according to the obtained user plane security policy. This avoids the problem that the on-demand user plane security mechanism cannot be implemented because the user plane security policy is lost due to some non-upgraded network elements in the source eNB, source MME, or target MME within the 4G network. Further, in this embodiment of the present application, the target eNB further obtains a security policy with the highest possible priority and best-effort guarantees whether user plane security protection is activated or not activated for the terminal device according to the most prioritized user plane security policy in the handover process, and as a result, potential undercutting attacks are avoided.

[0178]

[0176] FIG. 5 is a schematic diagram of the hardware structure of a communication device according to an embodiment of the present application. The communication device 500 includes at least one processor 501, a communication line 502, a memory 503, and at least one communication interface 504.

[0179]

[0177] The processor 501 may be a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to control the program execution of the solution of the present application.

[0180]

[0178] The communication line 502 may include a path through which information is transmitted between the aforementioned components.

[0181]

[0179] The communication interface 504 is a device that uses some kind of transceiver and is configured to communicate with another device or a communication network, such as Ethernet (registered trademark), a radio access network (RAN), or a wireless local area network (WLAN), etc.

[0182]

[0180] The memory 503 may be a read-only memory (ROM), another type of static storage device capable of storing static information and instructions, a random access memory (RAM), or another type of dynamic storage device capable of storing information and instructions; or it may be an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM), another compact disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), a magnetic disk storage medium, another magnetic storage device, or any other medium that can carry or store the expected program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory may exist independently and be connected to the processor via the communication line 502. Alternatively, the memory may be integrated with the processor.

[0183]

[0181] The memory 503 is configured to store computer-executable instructions for executing the solution in the present application, and the processor 501 controls the execution. The processor 501 is configured to execute the computer-executable instructions stored in the memory 503 to implement the security policy processing method provided in the foregoing embodiments of the present application.

[0184]

[0182] Optionally, the computer-executable instructions in this embodiment of the present application may also be referred to as application program code. This is not particularly limited in this embodiment of the present application.

[0185]

[0183] In a specific implementation, in the embodiment, the processor 501 may include one or more CPUs, for example, CPU 0 and CPU 1 in FIG. 5.

[0186]

[0184] In a specific implementation, in the embodiment, the communication device 500 may include a plurality of processors, for example, processor 501 and processor 508 in FIG. 5. Each processor may be a single-core (single-CPU) processor or a multi-core (multi-CPU) processor. The processor in the present case may be one or more devices, circuits, and / or processing cores configured to process data (for example, computer program instructions).

[0187]

[0185] In a particular implementation, in an embodiment, the communication device 500 may further include an output device 505 and an input device 506. The output device 505 communicates with the processor 501 and may display information in a plurality of ways. For example, the output device 505 may be a liquid crystal display (LCD), a light emitting diode (LED) display device, a cathode ray tube (CRT) display device, or a projector. The input device 506 communicates with the processor 501 and may receive user input in a plurality of ways. For example, the input device 506 may be a mouse, a keyboard, a touch screen device, or a sensor device.

[0188]

[0186] The communication device 500 may be a general-purpose device or a dedicated device. In a specific implementation, the communication device 500 may be any network element in the embodiments of FIGS. 2 to 4, for example, a source access network device, a target access network device, an AMF, an MME, or a PGW-C + SMF. The type of the communication device 500 is not limited in this embodiment of the present application.

[0189]

[0187] What has been described above with reference to FIGS. 2 to 4 mainly explains the solution provided in the embodiments of the present application from the perspective of a method. It will be understood that in order to implement the above functions, the communication device includes corresponding hardware structures and / or software modules for executing the functions. Those skilled in the art should easily recognize that in combination with the exemplary modules and algorithm steps described in the embodiments disclosed herein, the present application may be implemented by hardware or a combination of hardware and computer software. Whether the function is executed by hardware or by hardware driven by computer software depends on the specific application and design constraints of the technical solution. Those skilled in the art may use different methods to implement the described functions for each specific application, but the implementation should not be considered to go beyond the scope of the present application.

[0190]

[0188] In the embodiments of the present application, the communication device may be divided into functional modules based on the above method examples. For example, each functional module may be obtained by division based on each function, or two or more functions may be integrated into one processing module. The integrated module may be implemented in the form of hardware or in the form of a software functional module. It should be noted that in the embodiments of the present application, the module division is only an example and is merely a logical function division. In actual implementation, another division method may be used.

[0191]

[0189] Hereinafter, the communication device in this application will be described in detail. Refer to FIG. 6. FIG. 6 is a schematic diagram of an embodiment of a communication device according to an embodiment of this application. The communication device may be any network element in the embodiments of FIGS. 2 to 4, for example, a source access network device, a target access network device, an AMF, an MME, or a PGW-C + SMF. The communication device includes a communication module 601 and a processing module 602. The communication module 601 is configured to realize a message transmission and reception function, and the processing module 602 is configured to execute related processing functions.

[0192]

[0190] When the communication device is a source access network device, the communication module 601 is configured to execute the content related to S202, S302, S402, S309, S310, S411, and S412 in FIGS. 2 to 4.

[0193]

[0191] In particular, the processing module 602 is configured to obtain the user plane security policy #40-1 of the terminal device.

[0194]

[0192] Optionally, the processing module 602 is further configured to determine whether to include the user plane security policy #40-1 in the container information according to whether the terminal device supports on-demand user plane security protection.

[0195]

[0193] When the communication device is a target access network device, the communication module 601 is configured to receive message #50-2 from the core network device #30-1, where message #50-2 includes container information from the source access network device; the processing module 602 is configured to determine the user plane security activation status between the target access network device and the terminal device based on message #50-2, where the user plane security activation status indicates whether user plane encryption protection is activated and / or whether user plane integrity protection is activated.

[0196]

[0194] In a possible implementation, the container information includes the user plane security policy #40-1. The processing module 602 is specifically configured to determine the user plane security activation status between the target access network device and the terminal device according to the user plane security policy #40-1.

[0197]

[0195] In a possible implementation, message #50-2 further includes user plane security policy #40-2, and the container information includes user plane security policy #40-1. The processing module 602 is specifically configured to determine the user plane security activation status between the target access network device and the terminal device according to user plane security policy #40-2. Specifically, the processing module 602 ignores user plane security policy #40-1 and is configured to directly determine the user plane security activation status between the target access network device and the terminal device according to user plane security policy #40-2.

[0198]

[0196] In a possible implementation, the processing module 602 is further configured to determine whether user plane security policy #40-2 matches user plane security policy #40-1.

[0199]

[0197] In a possible implementation, the processing module 602 is further configured to generate alarm information, where the alarm information indicates that the source access network device #10-1 is in an insecure environment. Optionally, the communication module 601 is further configured to send the alarm information to the core network device #30-1.

[0200]

[0198] In a possible implementation, the processing module 602 is further configured to determine the user plane security activation status between the target access network device and the terminal device according to a preset user plane security policy when message #50-2 does not carry a user plane security policy and the container information also does not carry a user plane security policy.

[0201]

[0199] In a possible implementation, message #50-2 further includes instruction information. The processing module 602 is further configured to determine, based on the instruction information, that the terminal device supports on-demand user plane security protection.

[0202]

[0200] The division into modules in the embodiments of this application is only an example and is merely a division of logical functions. Other divisions may be used in actual implementation. Furthermore, the functional modules in the embodiments of this application may be integrated into one processor, or each of the modules may physically exist independently, or two or more modules may be integrated into one module. The integrated module may be implemented in the form of hardware or in the form of a software functional module.

[0203]

[0201] In one example, the unit in any one of the aforementioned communication devices is one or more integrated circuits configured to implement the aforementioned method, for example, one or more application-specific integrated circuits (ASICs), one or more digital signal processors (DSPs), one or more field programmable gate arrays (FPGAs), or a combination of at least two of these integrated circuit forms may also be used. Regarding another example, when the unit in the communication device is implemented in a form where a processing element schedules a program, the processing element may be a general-purpose processor, such as a central processing unit (CPU), or another processor capable of starting a program. Regarding still another example, the unit may be integrated and implemented in the form of a system-on-a-chip (SOC).

[0204]

[0202] This application further provides a communication system including one or more network devices or terminal devices.

[0205]

[0203] Embodiments of this application further provide a computer-readable storage medium including instructions. When the instructions are executed on a computer, the computer controls a network device or a terminal device to implement any implementation shown in the embodiments of the aforementioned method.

[0206]

[0204] Embodiments of this application further provide a computer program product. The computer program product includes computer program code. When the computer program code is executed on a computer, the computer implements any implementation shown in the embodiments of the aforementioned method.

[0207]

[0205] Embodiments of the present application further provide a chip system including a memory and a processor. The memory is configured to store a computer program, and the processor is configured to call the computer program from the memory and execute the computer program. As a result, the chip implements any implementation shown in the embodiments of the foregoing method.

[0208]

[0206] Embodiments of the present application further provide a chip system including a processor. The processor is configured to call and execute a computer program. As a result, the chip implements any implementation shown in the embodiments of the foregoing method.

[0209]

[0207] In some embodiments of this application, all or part of the technical solutions provided can be implemented by using software, hardware, firmware, or any combination thereof. When software is used to implement an embodiment, all or part of the embodiment may be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer instructions are loaded and executed on a computer, the procedures or functions according to the embodiments of the present invention will occur in whole or in part. The computer may be a general-purpose computer, a dedicated computer, a computer network, an AI node, an access network device, a terminal device, or another programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions may be transmitted from a website, a computer, a server, or a data center to another website, a computer, a server, or a data center in a wired (e.g., coaxial cable, optical fiber, or digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, or microwave) manner. The computer-readable storage medium may be any available medium accessible to a computer or a data storage device such as a server or a data center that integrates one or more available media. The available media may be a magnetic medium (e.g., a floppy disk, a hard disk, or a magnetic tape), an optical medium (e.g., a digital video disc (DVD)), a semiconductor medium, etc.

[0210]

[0208] In the embodiments of the present application, if there is no logical conflict, the embodiments may be referred to each other. For example, the methods and / or terms in the method embodiments may be referred to each other, and the functions and / or terms in the apparatus embodiments may be referred to each other. For example, the functions and / or terms may be referred to each other between the apparatus embodiments and the method embodiments.

[0211]

[0209] It is obvious that those skilled in the art can make various modifications and variations to the present application without departing from the scope of the present application. The present application is intended to cover these modifications and variations of the present application on the condition that they fall within the protection scope defined by the following claims and their equivalent technologies.

Claims

1. A security policy processing method, comprising: a step in which a target access network device receives a message (#50-2) from a core network device (#30-1), the message (#50-2) including container information from a source access network device; and a step in which the target access network device determines a user plane security activation status between the target access network device and a terminal device based on the message (#50-2), the user plane security activation status indicating whether user plane encryption protection is activated and / or whether user plane integrity protection is activated; wherein the step in which the target access network device determines a user plane security activation status between the target access network device and the terminal device based on the message (#50-2) comprises: when the message (#50-2) further includes a user plane security policy (#40-2) and the container information includes a user plane security policy (#40-1), the target access network device ignores the user plane security policy (#40-1), and the target access network device determines the user plane security activation status between the target access network device and the terminal device according to the user plane security policy (#40-2).

2. The method according to claim 1, wherein the container information is a source eNB-to-target eNB transparent container.

3. In the method according to claim 1, the message (#50-2) is a handover request message, and the handover request message is for requesting the target access network device to prepare handover resources of the terminal device.

4. In the method according to any one of claims 1 to 3, the message (#50-2) further includes indication information, and before the step of the target access network device determining the user plane security activation status between the target access network device and the terminal device based on the message (#50-2), the method further includes: The method includes a step in which the target access network device determines, based on the indication information, that the terminal device supports on-demand user plane security protection.

5. In the method according to claim 4, the indication information is specified by a part of bits of the security capability of the terminal device, and the security capability of the terminal device specifies at least one security algorithm that can be used by the terminal device.

6. In the method according to claim 5, the security capability of the terminal device is a UE evolved packet system security capability.

7. An access network device comprising: A communication module configured to receive a message (#50-2) from a core network device (#30-1), the message (#50-2) including container information from a source access network device; and A processing module configured to determine the user plane security activation status between the access network device and the terminal device based on the message (#50-2), the user plane security activation status indicating whether user plane encryption protection is activated and / or whether user plane integrity protection is activated. comprising, the processing module: When the message (#50-2) further includes a user plane security policy (#40-2) and the container information includes a user plane security policy (#40-1), the target access network device specifically ignores the user plane security policy (#40-1) and determines the user plane security activation status between the access network device and the terminal device according to the user plane security policy (#40-2). An access network device.

8. The access network device according to claim 7, wherein the container information is a source eNB to target eNB transparent container.

9. The access network device according to claim 7, wherein the message (#50-2) is a handover request message, and the handover request message is for requesting the access network device to prepare handover resources of the terminal device.

10. In the access network device according to any one of claims 7-9, the message (#50-2) further includes indication information, and the processing module further: Before determining the user plane security activation status between the access network device and the terminal device based on the message (#50-2), based on the indication information, the terminal device is configured to determine that it supports on-demand user plane security protection. An access network device.

11. The access network device according to claim 10, wherein the indication information is specified by a part of the bits of the security capabilities of the terminal device, and the security capabilities of the terminal device specify at least one security algorithm that can be used by the terminal device. An access network device.

12. The access network device according to claim 11, wherein the security capability of the terminal device is a UE evolved packet system security capability.

13. A computer-readable storage medium storing instructions, which when executed by a computer, cause the computer to be operative to perform the method according to any one of claims 1-6.

14. A computer program comprising instructions, which when executed by a computer, cause the computer to be operative to perform the method according to any one of claims 1-6.

Citation Information

Patent Citations

  • Security protection method, device and system

    JP2020536424A

  • Communication method and device thereof

    WO2020221263A1